2026-09-16 23:36 UTC
Replies (1)
-
@sawaba@infosec.exchange 2026-09-16 23:43
A Fortinet flaw that entered the exploited catalog on September 9 had carried its identifier since February 2025. A ha! A Fortinet flaw! We’re talking about vulnerabilities! Finally, a shred of context. The Fortinet vulnerability “entered the exploited catalog” <- maybe we’re talking about CISA KEV? Maybe CHQ has its own catalog? Maybe it’s in the Structural Conditions Registry? I’ve got to make a lot of assumptions here, but the next bit mentions an identifier from Feb 2025. The only explanation I can think of is that there’s a Fortinet vulnerabilities with a CVE coined in Feb 2025, but is just now getting actively exploited. So we’re talking about a 19 month gap between disclosure and exploitation? Nineteen months separate the reservation of the identifier from federal confirmation of exploitation, and this board's published test was twelve. Ah ha, yes! 19 months. We’re onto something. I have no idea what “this board’s published test was twelve” means. The rule ran, and the rating moved. I have no idea.