THE ECHO

One story. Gone deep.

One person. A laptop, an AI chatbot, and addresses pulled from a scanning service.

From an empty laptop to the first real break-in took under four hours. Then 395 organizations in 48 countries, most of them schools. Once the full run started, eleven of them fell in the first 26 seconds.

They had one thing in common. The same printing software, a product called PaperCut, sitting on the network where the internet could reach it. Not the newest thing on the network. Not the most valuable. The one that prints.

Here is the part that is about you. In twelve of the 395, the attacker ended up holding the keys to the whole network. In the other 383, the attacker got the print server and the passwords stored on it, and that is where it stopped.

The difference between the twelve and the 383 was not budget, and it was not headcount. The researchers who tracked it said ordinary hardening still worked, even against this. It was what the printing server was allowed to reach. In twelve places, it could reach everything.

You do not have that software. You have something like it.

The thing your IT company installed to manage your computers. The box that runs your backups. The printer server nobody has logged into since the day it went in. It sits on your network. It has more access than anyone has thought about since it was installed. Nobody calls it security. It has a job, it does the job, and it is boring.

Boring is where this happens.

By the time the software company warned its customers, on August 27, the flaw was already being used against them. The fix landed the next day. This campaign came on the 31st. The fix needed fixing until September 1. Patched, it turns out, is a date, not a checkbox.

Your IT company patches on a cycle. Probably monthly. That is not a criticism of them. It is the reason patching cannot be the whole plan. The warning, the fix, this campaign and the fix to the fix all landed inside one week. There was never a window. And the other side works in seconds.

You do not win that race by getting faster. You win it by making the box it lands on not matter.

Which brings you to the question. Not "are we patched." That one has a date for an answer, and your provider can give it to you. This one:

If that box got hit tonight, what could it reach?

Ask it in those words. If your IT company answers in one sentence, you are in the 383. If the answer is "let me get back to you," that is the finding. It is a finding about the setup, not about them.

Your provider sells you management, and backups, and support. Every one of those comes with a box. Nobody sells a print server that reaches less. There is no product in it. So nobody has asked the question on your behalf.

Answering it is a tracing exercise. It takes about two weeks and produces a map you can hand to your IT company and to your insurer.

You do not need to know what the box is called. You need somebody who can tell you what it can reach, in a sentence, before the day that matters.

The numbers are from GreyNoise, published September 9. The dates are from PaperCut's own advisory and from Rapid7.

SIGNAL CHECK

What else matters this week.

The Two Tools Your IT Company Uses to Reach You

Two of the tools an IT provider uses to run a company like yours went onto the government's list of what is actually being broken into right now. Both in the last two weeks.

N-able N-central is the console a provider uses to manage your computers from their office. The flaw was being used before a fix existed. N-able shipped its fourth hotfix in five weeks on September 5. The government listed it on September 8.

ConnectWise ScreenConnect is the tool a provider uses to get onto your screen when you call for help. Its flaw has been in use since August 20, and once an attacker is inside one machine the tool supports, it spreads to the next. Listed September 11.

Federal agencies got three days on each. You got no deadline, just a monthly invoice from somebody who uses one of these.

Not a reason to change providers. A reason for one email.

"Are ours patched, and how do you know?" The answer you want has a date in it.

The Router in the Closet

A brand of office router, MikroTik, had two flaws added to the same list on September 10. Used together, they hand an attacker full control of any router that can be managed from the internet. The fixes are out. The Canadian Centre for Cyber Security put out its own alert on the same pair.

You may not know what brand your router is. That is the point.

The router is the box everything in your company passes through on its way to the internet. It came with the internet service, or the IT company put it in, or it has been in the closet since before either of them. Nobody logs into it. It is the most boring thing you own that touches everything.

Whatever brand yours is: who updates it, and when was the last time? If nobody can say, it has never happened.

THE NOISE

Not every signal needs action.

974

Microsoft fixed at least 974 security holes this month. Brian Krebs counted them. The number ran in every headline, and the number is the noise.

Two of the 974 were already being used when the fixes shipped. Two.

More holes get found every month. Satnam Narang at Tenable, which tracks these counts for a living, put it in one sentence: it is "creating larger haystacks, but it isn't finding more needles."

The 974 measures how many people are looking, not how much danger you are in.

Your IT company will apply all of them on its cycle, and that is fine. The cycle is built for the haystack. A big number in a headline is not a reason to call anyone. Two holes already being used is.

If your IT company says "we patched everything," the useful follow-up is: which two, and when.

ONE QUESTION

No answer. Just the question.

What is the boring box in your company, the one nobody calls security, and who could tell you today what it can reach? Not who installed it. Not who sends the invoice for it. Who could answer, in a sentence, if you asked this afternoon.

Where to Start

The Echo's question has a one-sentence answer. If nobody has given you that sentence yet, start here.

Hit reply and tell me what your boring box is. I'll tell you what I'd trace first.

Prefer audio? Jane reads every Pulse edition on the Signal vs. Noise podcast. Five minutes, same signal, no scrolling. Find it wherever you listen.

Michael Faas is a fractional CTO/CISO who translates technical complexity into business decisions. echocyber.io