THE ECHO

One story. Gone deep.

On September 2, CISA, the federal cybersecurity agency, added seven entries to its Known Exploited Vulnerabilities catalog. That is the government's list of what is actually being broken into, right now, in the world. Seven entries, six products, because one of them is on there twice.

Switchvox, which is a phone system. SonicWall SMA1000, the box people log into when they work from home, and that is the one that appears twice. Artifactory, where a development team keeps the parts your software gets built out of. Then Kestra, Starlette and LiteLLM, three pieces of other people's code that nobody at your company ever bought or signed for.

You can read all seven and not know whether a single one of them is yours.

That is not a competence problem. You are not confused because you are non-technical. The list is accurate, and accurate is all it is.

Because every entry on it came with a deadline. And the deadlines are not the same.

Five had to be fixed by September 5. The other two got until September 16. Those dates bind federal civilian agencies, and only federal civilian agencies. Nobody sent you one.

But somebody sat down and decided which ones could wait, and then published that decision in the same document as the warning.

It came out of a directive called BOD 26-04. The rule ranks on four questions, and two of them are already answered for you. Is the thing on the list of what is actually being exploited, which it is, because that is what the list is. And can the whole attack be run by a machine, with nobody driving it. CISA publishes that answer too.

Which leaves two questions, and they are the two about your own company.

  1. Can somebody reach this thing from the internet.

  2. And if they got in, do they get part of the thing, or all of it.

That is the federal government's triage rule. Two questions, in words a founder can hold in their head.

The new directive did not add to the old rule. It completely revoked it.

The old one told federal agencies to go hard at everything on that list. Fix all of it, on a clock. The new one keeps the list. The catalog is still published, still free, still updated. What changed is the order. Fix the ones that are reachable. Fix the ones that hand over everything. And defer action on the low risk ones.

Defer is their word. Not ignore. Not skip. Later. It is not permission to skip anything. It is an order of operations, written down by the people who keep the list.

The agency that publishes the list of what is being broken into just told the people who have to act on it, in writing, that not everything on it goes first.

Count how many times a security vendor has told you that something on your list could wait.

There is no product in fewer things. The rule is free, it is public, and nobody has a reason to walk it over to you.

You do not need to know what any of those names mean. You need somebody who can tell you which ones are yours, and which one of those is the one that ruins the week.

That is not a technical skill. It is a translation, and it is somebody's job.

That is the whole difference between a list and a decision.

SIGNAL CHECK

What else matters this week.

Your Website Is Production Software

Wordfence has logged more than 440,000 attempts to exploit two WordPress plugin flaws. Attempts, not sites taken. That distinction tends to fall out of the coverage.

The plugins are Super Forms, fixed in 6.3.314, and Elementor Pro, fixed in 4.2.2. Both let somebody with no account upload a file that the site will then run. Which is another way of saying somebody who has never logged in gets to decide what your website does.

Here is why it belongs beside the Echo. Run those two questions across your marketing site. Can somebody reach it from the internet. Yes, that is its entire purpose. If they got in, do they get part of it or all of it. All of it.

Then go down the list of everything else your company owns and find the other thing that answers both questions the same way. There may not be one.

The site is not marketing. It is software, running in public, with a maintenance obligation attached, and it usually belongs to whoever built it two years ago.

Ask that person what version those plugins are on.

The Thirty Second One

Google shipped an emergency Chrome update on September 3 for a flaw the company says is already being exploited. The fix is in 152.0.7977.82.

If you are reading this in Chrome, check the version and restart the browser. That is the whole fix. This is the only item in the issue where you personally are the one who does it, and it takes less time than the paragraph that told you about it.

One more detail, because it is the sharpest fact in the issue. The researcher who found it, Salvatore Gulizia, reported it to Google on August 4 and was paid a thousand dollars. A flaw Google says is being exploited, in Chrome, for a thousand dollars.

That is the whole comment. Make of it what you want.

THE NOISE

Not every signal needs action.

A Model That Scores 100 On Writing Exploits

OpenAI announced a model it calls GPT-6 Astra and says it scores 100 percent on ExploitBench, a benchmark for writing working exploits. The figure is the company's own, on a benchmark the company chose to report.

Take it at face value. Say it is exactly as good as claimed.

Now look at what actually happened this week. Somebody with no account could upload a file to a WordPress site and take the whole thing. A phone system, a remote access box and a code repository went onto the government's list of what is being broken into today.

None of that needed a model. It needed a plugin that had not been updated.

This will be the most-covered security story of the week and the least useful one on this list. Your week does not change because a benchmark got saturated. Your week changes because of a version number, and you can go look at that version number right now.

Dismiss the coverage. Keep the version number.

ONE QUESTION

No answer. Just the question.

When something like that list lands, somebody in your company decides which parts of it can wait. Name them. Not the person who does the patching. The person who decides it does not get patched this week. And if that is nobody, it is still getting decided. Just not by anyone you could ask.

Where to Start

The Echo gave you two questions. They work on one thing at a time, and only after somebody has already put that thing in front of you.

The Signal Score is thirty seven questions, already sorted, across the parts of a company that tend to fail together. It comes back as a letter grade, a risk range and a breakdown by category. Something you can forward to a co-founder and have an argument about.

It will not tell you whether Starlette is yours. It will tell you which of these questions you cannot answer alone, and that is the more useful list.

Prefer audio? Jane reads every Pulse edition on the Signal vs. Noise podcast. Five minutes, same signal, no scrolling. Find it wherever you listen.

Michael Faas is a fractional CTO/CISO who translates technical complexity into business decisions. echocyber.io