361 hosts in 47 countries, and 95% of them taken inside two days of the first exploitation.
Rotating the stolen key is the fix. It is also what erases the proof anyone used it.
An authentication bypass on the appliance that decides who is inside. The intruder inherits every assumption built on it.
Exploitation is arriving before organisations can deploy. Patching in twenty days is worth less than surviving a compromised appliance.
A backup does not help an attacker. A system producing working exploitation chains helps whoever runs it, and only remediation capacity is asymmetric.
Four vendors, one campaign. Largest attack surface, least visibility, highest trust — and both states and criminals use the same door.
A person reading a hostile page is not compromised by reading it. An agent is deciding what to do next on the basis of what the page says.
For most of the interval the company was the victim of an incident that had already happened and had not yet surfaced.
The window between disclosure and exploitation is shortest exactly where the ability to respond is slowest.
Five months quiet, ten days of theft. A single dwell-time figure conflates the two, and organisations optimise against the wrong phase.
Recruiting an insider costs money, time and exposure to prosecution. Persuading an agent costs a paragraph and works every time.
Self-hosting transfers the patch obligation. In a window measured in days, that transfer decides the outcome.
A sequel name is a judgement that this is the same mistake in the same place. Session tokens leak past authentication entirely.
A webshell is the least sophisticated technique in this database. That it worked against the system of record is the finding.
A product that is exposed, trusted and full is not an unfortunate combination. It is the specification.
A privately held operator using the same product would have had the same exposure and, quite possibly, produced no public record at all.
An organisation appears on the list because it did not pay, or paid late. An organisation absent from the list may have paid.
Internet-facing, authentication-heavy, holding the files too sensitive for email. Managed file transfer keeps producing portfolios of victims.
Patch windows are argued about as though the attacker learns of a flaw when the defender does. Here the advisory was not the starting gun.
The identity boundary expressed as hardware. And a vendor exploited recently is more likely, not less, to be exploited again.
The first flaw supplies the authentication the second one requires. A pair of medium problems is not a medium problem.
No vendor to patch and no version to check. Every implementation had to fix it separately.
A decision made years earlier for classification reasons turned out to be the security control.
The vendor did not tell customers to update the appliance. It told them to throw it away.
High privilege, low attention, reachable. The vulnerable thing is rarely the one anyone would name.
The patch had existed for two years. The campaign needed no new capability, only servers nobody had looked at.
Blocking a URL pattern encodes the exploit you have seen, not the defect that allows it.
Ten years of telling people not to enable macros, and this one did not ask.