THE ECHO

One story. Gone deep.

Someone with no account and no password could run their own code inside the service that decides whether you are you. That was the flaw Microsoft found in Entra ID this month. CVE-2026-69836.

You did nothing about it.

Doing nothing was correct. There was no package to install and no window to schedule. Microsoft found it in its own infrastructure and fixed its own infrastructure. Whatever your team was doing that week, they kept doing it.

Then it got stranger. Microsoft first said the flaw was being exploited in the wild. Then it reversed and said it had not been.

That is not a breach that got walked back. It is a claim about a breach that got walked back. The flaw was found, and it was fixed.

The one fact a founder would have used to decide whether to care changed after the fact, and it changed nothing. There was no action available either way.

Mostly this is a good deal. A lot of what your company runs gets patched by somebody else while you sleep, and that is the whole reason a twelve-person company can operate infrastructure that used to need a team of specialists.

But notice what it means. A flaw that could have handed your identity system to a stranger left no trace inside your company. No ticket. No maintenance window. No line on any invoice.

Nothing happened to anybody, and that was the good outcome.

You keep an inventory of what you bought. The laptops. The software subscriptions. The vendors who touch customer data. Every row on that list is a decision somebody made on purpose.

Everything that took somebody down this month was sitting underneath that list. That is true whether you own a rack of servers or nothing but browser tabs.

Broadcom disclosed a flaw in VMware vCenter on July 29. CVE-2026-59310. Attackers were exploiting it by August 3. Five days.

Five days is not a patch cycle. It is not even a change window.

And the attackers landed one level below every application, in the hypervisor, the one machine that runs all the other machines. Ransomware was chained onto the campaign, and ransomware on ESXi does not encrypt a server. It encrypts everything standing on that server.

Researchers put the campaign at 361 compromised addresses across 47 countries. Not 361 companies. 361 addresses.

The thing that selected them was the software. Not the company.

Nobody looked up a name and decided it was worth the trouble. Something scanned for a version string and found one. They were standing on the same floor, and the floor went.

So much for "we're too small to be a target." They don't check your financials before hacking you. There is no step in any of this where somebody weighs you up at all.

Size was never the exposure. The layer under you is.

Your monthly bill has a line for the CRM. A line for email. A line for payroll. It has no line for the thing all three of those are standing on, because nobody bills you for that. It arrived underneath something you did buy.

And if you run nothing but SaaS, this is not the week to feel lucky. You do not have a vCenter. You have Entra, or Google, or Okta, and you do not own that either. Somebody else runs it. Somebody else patches it. And you will find out the way you found out about Entra this month. From a headline, or not at all.

The difference is not whether you have a floor. It is whether you can see it.

SIGNAL CHECK

What else matters this week.

It Was Already In Use

CISA added a flaw in Oracle's web server software to its Known Exploited Vulnerabilities catalog on August 24. CVE-2026-21962. No account needed, straight over the web. Federal agencies were given until August 27 to fix it.

Here is the number that carries the story. SOCRadar and CloudSEK both reported exploitation attempts starting January 22, right after a public proof of concept. Seven months of active use before it made the authoritative list.

Put that beside the Echo. There, the clock ran five days from disclosure to exploitation. Here, the clock ran seven months from exploitation to catalog. Those are the two ends of the same timeline. The attacker's clock runs in days. The authoritative list runs in months. A founder waiting for the official signal is working off a calendar seven months behind the one the attacker is on.

That is not a knock on the catalog. It does what it says. It records what has already happened to somebody. But a record is not a warning, and this one arrived seven months into the thing it was recording.

If the plan for finding out about a problem is that an authority publishes it, that is the plan. January to August is what that looks like.

It Installed Correctly

Somebody at your company is going to search for a piece of software this week and install the first result.

FortiGuard Labs has been tracking a group called Storm-2561 pushing spoofed enterprise VPN clients: fake Pulse Secure, fake Ivanti, fake Fortinet. Separately, researchers counted more than 90 spoofed domains across 10 languages delivering a remote access trojan through ScreenConnect while dressed up as ordinary tools. Parallel campaigns are using fake AI coding assistant installers to take credentials, session cookies and VPN keys.

Here is the detail that makes it work. The installer contains the real software. The app installs. It runs. It does what the person wanted it to do. They see exactly what they expected to see, because they got exactly what they went looking for, plus something else.

Nothing about that moment feels wrong, so nothing about that moment gets reported to anybody.

The laptop was never the target. The session cookie and the VPN key are. One convenience download becomes the credential that walks in your front door and authenticates correctly on the way through.

Ask whoever runs your systems one question this week: how would we know?

THE NOISE

Not every signal needs action.

17 Iranians Charged. 31 Terabytes Stolen.

A 14-count superseding indictment was unsealed in Manhattan this month charging 17 Iranian nationals tied to the Tehran-based Mabna Institute. The Justice Department says the campaign has been running since at least 2013 on behalf of the Islamic Revolutionary Guard Corps. The indictment says it took more than 31 terabytes from 144 US universities and 178 more abroad, at least 42 US private companies, and at least five federal and state agencies.

Charged. Not convicted. That word is going to fall out of most of the coverage this week. It is the only part of the story that is not yet settled.

It is the most-covered security story of the week and the least relevant one on this list. Dismiss the coverage, not the case.

Nation-state headlines are the biggest generator of "are we a target?" anxiety in a founder's week. And the whole argument of this issue is that targeting is not the mechanism that gets you. A decade-long operation against research universities tells a twelve-person company nothing about Monday.

Notice which story this week came with a fix-by date and which one came with a terabyte count. Only one of them was written for you.

ONE QUESTION

No answer. Just the question.

Name the layer your CRM is standing on. Not the vendor you bought it from. The thing underneath that came bundled with something else, that nobody put on a list, that you could not patch if you wanted to. If naming it took more than a sentence, you have found the gap.

Where to Start

No link this week. Ten minutes and one email.

Send it to whoever runs your systems, in house or outsourced, and ask two things. What are we running that we did not buy on purpose, meaning the layer that came bundled underneath something we did buy. And which of our vendors patches us without telling us.

The first answer is the floor you cannot see. The second is the floor you cannot touch. Both of them are load-bearing, and neither one is on your bill.

Prefer audio? Jane reads every Pulse edition on the Signal vs. Noise podcast. Five minutes, same signal, no scrolling. Find it wherever you listen.

Michael Faas is a fractional CTO/CISO who translates technical complexity into business decisions. echocyber.io