Elektrine lite

← Feed

@sawaba@infosec.exchange

2026-09-16 23:36 UTC

OKAY. Next paragraph. SC-2026-006 · Exploitation Precedes Defender Awareness: rating under review after the criterion supporting this cycle's scheduled upgrade failed construct validation. The upgrade action is voided. Prior state, STRENGTHENING, stands. I got nothing. Why is STRENGTHENING in all caps, like it is one of several selectable states? How would I know this? Who scheduled what upgrade? What criterion failed construct validation? FML, let’s move on to the next paragraph.

Replies (1)

  • @sawaba@infosec.exchange 2026-09-16 23:43

    A Fortinet flaw that entered the exploited catalog on September 9 had carried its identifier since February 2025. A ha! A Fortinet flaw! We’re talking about vulnerabilities! Finally, a shred of context. The Fortinet vulnerability “entered the exploited catalog” <- maybe we’re talking about CISA KEV? Maybe CHQ has its own catalog? Maybe it’s in the Structural Conditions Registry? I’ve got to make a lot of assumptions here, but the next bit mentions an identifier from Feb 2025. The only explanation I can think of is that there’s a Fortinet vulnerabilities with a CVE coined in Feb 2025, but is just now getting actively exploited. So we’re talking about a 19 month gap between disclosure and exploitation? Nineteen months separate the reservation of the identifier from federal confirmation of exploitation, and this board's published test was twelve. Ah ha, yes! 19 months. We’re onto something. I have no idea what “this board’s published test was twelve” means. The rule ran, and the rating moved. I have no idea.

    Open ##4731971