<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://bizzal70.github.io/itsalreadywhen/feed.xml" rel="self" type="application/atom+xml" /><link href="https://bizzal70.github.io/itsalreadywhen/" rel="alternate" type="text/html" /><updated>2026-07-20T14:45:34+00:00</updated><id>https://bizzal70.github.io/itsalreadywhen/feed.xml</id><title type="html">It’s Already When.</title><subtitle>Weekly cybersecurity intelligence, plainly explained.</subtitle><author><name>The Analyst</name></author><entry><title type="html">The 11-byte packet that freezes an OpenSSL server for good</title><link href="https://bizzal70.github.io/itsalreadywhen/2026/07/19/issue-005/" rel="alternate" type="text/html" title="The 11-byte packet that freezes an OpenSSL server for good" /><published>2026-07-19T00:00:00+00:00</published><updated>2026-07-19T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadywhen/2026/07/19/issue-005</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadywhen/2026/07/19/issue-005/"><![CDATA[<p><em>Issue #005 · Week of July 19, 2026</em></p>

<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>Microsoft patched a record 622 CVEs and openly credited AI for the flood, which is the industry equivalent of building a bigger firehose and then admitting you also built the fire. Meanwhile a Russian tourist may or may not be a REvil operator, a robot vacuum can hand over your Wi-Fi password, and the single most effective attack technique of the week was convincing people to paste a command into a box and press Enter. Nothing new under the sun, just more of it, faster.</p>

<h2 id="the-breaches">The Breaches</h2>

<p>The theme this week is food and consultancies, which is not a sentence I expected to write. <strong>Coca-Cola</strong> suspended Fairlife dairy production across the US after a ransomware attack, and Japan’s frozen food giant <strong>Nichirei</strong> pulled its systems offline on July 13. Ransomware crews have figured out that hitting production lines gets a faster payout than hitting spreadsheets, and empty shelves make excellent leverage.</p>

<p>On the professional-services side, <strong>Ernst &amp; Young</strong> disclosed a breach traced to a compromised third-party support ticket system, and <strong>Abbott Laboratories</strong> is juggling two separate incidents at once, including unauthorized access to legacy Exact Sciences systems in its cancer diagnostics business. Legacy plus third-party is the breach recipe that never goes out of style.</p>

<p>The one worth reading closely is <strong>CISA’s own GitHub leak</strong>, dissected by Krebs. A contractor left dozens of internal credentials, including AWS GovCloud keys, in a public repo for nearly six months. The agency that tells everyone else to lock the door left it open, and only found out because a journalist told them. Humbling, and instructive: the postmortem is the most useful thing CISA published this week.</p>

<p>Also notable: two <strong>Scattered Spider</strong> members got five and a half years each for the 2024 TfL hack, a reminder that this cohort is young, sloppy, and increasingly caught.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<p>Start with the ones being exploited right now. <strong>SonicWall SMA 1000</strong> appliances are under active attack via two zero-days, <strong>CVE-2026-15409</strong> (SSRF, CVSS 10.0) and a command-execution partner, chained to root by Inc ransomware and tracked by Volexity as UTA0533. If you run these appliances, assume compromise and investigate, do not just patch.</p>

<p><strong>Microsoft SharePoint</strong> gets another one: <strong>CVE-2026-58644</strong> (CVSS 9.8), a deserialization RCE already in CISA’s KEV catalog with a same-week federal deadline. <strong>CISA</strong> also ordered agencies to patch two actively exploited <strong>Fortinet FortiSandbox</strong> flaws by the weekend.</p>

<p>Then the record-setting <strong>Patch Tuesday</strong>: 622 CVEs, three zero-days, two under active attack. Grab the exploited ones first and let the other 619 wait their turn. Hours later, a researcher dropped <strong>LegacyHive</strong>, a Windows User Profile Service privilege-escalation PoC that works on fully patched systems, because of course they did.</p>

<p>The quieter ones that matter: <strong>7-Zip</strong> (RCE via malicious archives, update to 26.02), the <strong>wp2shell</strong> WordPress Core RCE (unauthenticated code execution on a bare install, public PoC available, patch immediately), <strong>Zoom</strong> for Windows (CVE-2026-53412, CVSS 9.8, account takeover), and <strong>SAP NetWeaver ABAP</strong> (CVE-2026-44747, CVSS 9.9). And <strong>HollowByte</strong>, an OpenSSL DoS that lets an eleven-byte request pin up to 131 KB of memory that never comes back until the process restarts. OpenSSL shipped the fix in June with no CVE and no changelog note, which is its own small scandal.</p>

<p>Special mention to the <strong>11 Microsoft-signed UEFI shims</strong> that stayed trusted for years, quietly reopening the Secure Boot bypass door everyone assumed was shut.</p>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p><strong>ClickFix</strong> owned the week. Russia’s <strong>UAC-0145</strong> (a Sandworm sub-cluster) used ClickFix CAPTCHAs against Ukrainian targets; <strong>ACR Stealer</strong> rode ClickFix lures into enterprise Microsoft 365 and OneDrive, prompting a Microsoft warning; and new families <strong>TELEPUZ</strong> and the macOS <strong>ClickLock</strong> (which kills your apps on a loop until you type your password) piled on. The technique rents at scale, dodges EDR, and needs no exploit. It just needs you.</p>

<p>Elsewhere: China-linked <strong>Daxin</strong> resurfaced in a Taiwanese manufacturer after four years dark, alongside a new pre-login backdoor called <strong>Stupig</strong>. North Korea’s <strong>Contagious Interview</strong> crew hid <strong>OtterCookie</strong>-aligned payloads in SVG files inside fake coding tests. <strong>ShinyHunters</strong>-style actors spent a year walking into Salesforce environments through OAuth trust rather than any flaw. And the supply chain kept bleeding: seven malicious <strong>Vite</strong> npm packages (ViteVenom), compromised <strong>@asyncapi</strong> packages, and 148 fake student-proxy packages that turned browsers into a DDoS botnet.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>Two threads tie the week together, and both are about trust rather than exploits.</p>

<p>The first is that <strong>the human paste-box is the perimeter now</strong>. ClickFix, ACR Stealer, ClickLock, and the fake-coding-test crowd all skip the vulnerability entirely and ask the user to do the work. No CVE, no patch, no EDR alert worth the name. When your most effective attack requires zero exploits, your most effective defense is not another appliance.</p>

<p>The second is that <strong>AI is now feeding both sides of the vulnerability pipeline</strong>. Microsoft explicitly blamed AI for tripling its CVE count, and Krebs noted the same. More findings is not the same as more safety when defenders still have to triage by hand. Meanwhile the agentic-AI attack surface is filling in fast: the <strong>Cursor</strong> IDE auto-executing a rogue <code class="language-plaintext highlighter-rouge">git.exe</code> from a cloned repo, <strong>Grok Build</strong> quietly uploading entire Git repositories to xAI storage, the <strong>Claude for Chrome</strong> extension flaws letting rogue extensions drive your Gmail, and data-injection tricks that make agents misclick. We are wiring these tools into everything before we have agreed on what they are allowed to touch. That bill comes due later, and it will not be small.</p>

<h2 id="patch-now">Patch. Now.</h2>

<ul>
  <li><strong>SonicWall SMA 1000</strong>: patch CVE-2026-15409 and its partner, then hunt for compromise. Under active exploitation.</li>
  <li><strong>SharePoint</strong>: apply the fix for CVE-2026-58644 (in KEV, federal deadline already here).</li>
  <li><strong>Fortinet FortiSandbox</strong>: patch the two exploited flaws CISA flagged, immediately.</li>
  <li><strong>Windows</strong>: prioritize the two actively exploited zero-days from July Patch Tuesday before the other 620.</li>
  <li><strong>WordPress Core</strong>: patch the wp2shell RCE now; public exploit is live and a bare install is vulnerable.</li>
  <li><strong>7-Zip (26.02), Zoom for Windows (CVE-2026-53412), SAP NetWeaver ABAP (CVE-2026-44747)</strong>: all critical, all worth this week.</li>
  <li><strong>OpenSSL</strong>: confirm you picked up June’s HollowByte fix, since it shipped without a CVE.</li>
  <li><strong>Everyone</strong>: teach your people that nothing legitimate ever asks them to paste a command into a Run box. That one lesson beats half this list.</li>
</ul>

<h2 id="resources">Resources</h2>

<p>Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.</p>

<ul>
  <li><strong>CVE-2026-15409</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15409">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-15409">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-44747</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44747">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-44747">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-53412</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-53412">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-53412">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-58644</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-58644">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-58644">Search Sigma for detection rules</a></li>
</ul>

<p><em>It’s not if, it’s already when.</em></p>

<h2 id="related">Related</h2>

<ul>
  <li><a href="/itsalreadywhen/field-notes/2026/07/18/field-note/">Field Note — July 18, 2026</a></li>
  <li><a href="/itsalreadywhen/field-notes/2026/07/17/field-note/">Field Note — July 17, 2026</a></li>
  <li><a href="/itsalreadywhen/field-notes/2026/07/16/field-note/">Field Note — July 16, 2026</a></li>
</ul>

<p>More: <a href="/itsalreadywhen/">Issues</a> · <a href="/itsalreadywhen/field-notes/">Field Notes</a> · <a href="/itsalreadywhen/rtfm/">RTFM</a></p>

<hr />

<p><em>New Issue every week. Follow <a href="https://x.com/itsalreadywhen">@itsalreadywhen</a> or subscribe via RSS so the next patch list lands before your SOC needs it.</em></p>]]></content><author><name>The Analyst</name></author><summary type="html"><![CDATA[Issue #005 · Week of July 19, 2026]]></summary></entry><entry><title type="html">Issue #004 — Week of July 12, 2026</title><link href="https://bizzal70.github.io/itsalreadywhen/2026/07/12/issue-004/" rel="alternate" type="text/html" title="Issue #004 — Week of July 12, 2026" /><published>2026-07-12T00:00:00+00:00</published><updated>2026-07-12T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadywhen/2026/07/12/issue-004</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadywhen/2026/07/12/issue-004/"><![CDATA[<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>This was the week the industry finished pretending that “AI security” was a future problem. It is not. It is a badly configured Git repository, a coding agent that reads a malicious PNG and hands over your secrets, and an infostealer that ships one binary each for Windows, macOS, and Linux because efficiency matters even to criminals. The tools got smarter. The mistakes stayed exactly the same.</p>

<h2 id="the-breaches">The Breaches</h2>

<p>Progress Software spent the week telling ShareFile customers to physically shut down their on-premises Storage Zone Controllers over a “credible external security threat.” When a vendor tells you to power off production servers rather than patch them, that is not caution. That is a vendor that does not yet understand what it is dealing with, which is worse than a CVE.</p>

<p>Elsewhere, AssuranceAmerica lost 6.9 million driver’s license numbers, and a DHS database was hacked, both of which barely registered against the week’s noise. Healthcare continued its slow-motion collapse, with Dark Reading noting that attacks on healthcare <em>service providers</em> more than doubled in the first half of 2026. Attackers have worked out that the soft underbelly is not the hospital, it is the billing company three vendors removed from it.</p>

<p>Two things worth a grim smile: a Ryuk affiliate pled guilty and faces fifteen years, and Angelo Martino, a former ransomware <em>negotiator</em>, got seventy months for quietly working the other side of the table on BlackCat attacks. Three US security professionals have now been sentenced for helping the gangs they were supposed to fight. Trust your incident responders, but read their tax returns.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<p>The one you cannot ignore is <strong>CVE-2026-50746</strong>, a perfect 10.0 access-control flaw in <strong>Ubiquiti UniFi Connect</strong>, part of a batch that also hit Talk, Access, Protect, and UniFi OS. Command execution and privilege escalation on gear that sits at the network edge in tens of thousands of small offices. Patch it.</p>

<p><strong>BeyondTrust</strong> shipped fixes for two critical pre-auth bypasses (CVE-2026-40138, CVSS 9.2) in Remote Support and Privileged Remote Access. These are the tools that grant privileged access by design, so an unauthenticated takeover is exactly as bad as it sounds.</p>

<p><strong>GhostLock</strong> (CVE-2026-43499) is a fifteen-year-old Linux kernel local privilege escalation that has shipped by default in essentially every mainstream distribution since 2011. No special permissions, no network needed. It will be quietly living in your fleet for a long time.</p>

<p>CISA added four exploited flaws to KEV, including a 10.0 Adobe ColdFusion path traversal (<strong>CVE-2026-48282</strong>) and a Langflow bug that is already doing real work (see below). And <strong>CitrixBleed</strong> is bleeding again: attackers jumped on the latest NetScaler memory-disclosure flaw within hours of the PoC dropping. If you own NetScaler, you already know the drill, or you should by now.</p>

<p>Also note the <strong>Zimbra</strong> Classic Web Client stored XSS (no CVE yet, patch anyway), six <strong>U-Boot</strong> bootloader flaws enabling boot-time code execution, a hidden admin <strong>backdoor in Tenda</strong> router firmware (CVE-2026-11405), and <strong>XRING</strong>, an unpatched crash bug in Alibaba’s XQUIC HTTP/3 library that needs 260 bytes of perfectly legal traffic to take a server down. There is no fix for that last one yet.</p>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p>The identity attackers had a busy week. Okta flagged vishing against Microsoft 365 users, including O-UNC-066 running fake Entra passkey enrollment, while a new extortion crew called <strong>Helix</strong> worked SharePoint environments with vishing, device-code phishing, and MFA abuse. The DEBULL tooling abused Microsoft’s device-code flow with collaboration-themed lures. The passkey era has not killed phishing. It has just moved the fight to the enrollment step, exactly where the humans still live.</p>

<p>On the state-sponsored side: China-linked <strong>Silver Fox</strong> deployed the Rust-based MODBEACON RAT, <strong>UAT-7810</strong> expanded its LapDogs ORB network with new LONGLEASH malware, and suspected China-aligned actors hit Roundcube at North American universities. Iran-linked MOIS operators used a new C2 framework called <strong>Cavern</strong> against Israeli IT and government targets. And in the most 2026 story imaginable, China- and India-aligned groups were caught targeting the <em>same</em> Balochistan police force, which is either a coincidence or the world’s least private crime scene.</p>

<p>Supply chain remained the reliable disaster. The <strong>jscrambler</strong> npm package (8.14.0) shipped a Rust infostealer via a preinstall hook, flagged by Socket six minutes after publication. The <strong>Injective Labs</strong> SDK GitHub repo was compromised to push a wallet-key stealer. Meanwhile GitHub finally shipped <strong>npm 12 with install scripts off by default</strong>, roughly a decade after everyone agreed that was the obvious move.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>Two threads tie this week together, and both run through AI.</p>

<p>The first: AI is now a first-class part of the attack surface, and nobody built defenses for it. <strong>JadePuffer</strong> is being called the first complete LLM-driven ransomware attack, chaining a Langflow flaw to steal data and encrypt systems. A lone attacker breached an AWS environment in 72 hours using AI to chain cloud weaknesses. And the AI coding tools themselves are the problem: <strong>Ghostcommit</strong> hid a prompt injection in a PNG that CodeRabbit and Bugbot never opened, then talked a coding agent into cloning a clean-looking GitHub repo and running the payload during setup, invisible to the scanners, the AI reviewers, and the human who was theoretically supervising all three. Amazon patched a companion flaw in Q Developer (<strong>CVE-2026-12957</strong>) that let a malicious repo do much the same thing through a booby-trapped MCP config. The pattern does not change: the machine is trusted, the machine is fooled, and the machine is holding your credentials.</p>

<p>The second thread is quieter and worse. AI is not only the weapon now, it is also the target, and the defenses under it are structurally thin. The <strong>Gaslight</strong> macOS stealer shipped a prompt injection aimed squarely at malware analysts’ own AI tooling, trying to talk their assistants into refusing to analyze the sample. A paper making the rounds this week (Schneier flagged it) explains why that keeps working: the role tags we use to separate instructions from data were a formatting convention that quietly became the security boundary, and that boundary does not actually survive inside the model’s representations. Translated out of the academic register, prompt injection is not a bug waiting for a patch, it is a property of how these systems think. We wired AI into the analyst’s chair, the reviewer’s seat, and the developer’s terminal before anyone could reliably tell it which text to trust. It still cannot, and this week attackers made a comfortable living in that gap.</p>

<h2 id="patch-now">Patch. Now.</h2>

<ul>
  <li><strong>Ubiquiti UniFi Connect</strong>: patch CVE-2026-50746 (10.0) and the companion Talk, Access, Protect, and UniFi OS fixes today. This is edge gear with command execution, so treat it as already targeted.</li>
  <li><strong>BeyondTrust</strong> Remote Support and Privileged Remote Access: apply the pre-auth bypass fix (CVE-2026-40138). Anything that hands out privileged access by design earns an emergency window.</li>
  <li><strong>Adobe ColdFusion</strong>: CVE-2026-48282 is on CISA KEV and being exploited in the wild. Patch it or take it offline.</li>
  <li><strong>NetScaler</strong>: if you own it, assume CitrixBleed is in play, patch, and rotate sessions afterward. The PoC is public and attackers moved within hours.</li>
  <li><strong>Linux fleet</strong>: schedule the kernel update for GhostLock (CVE-2026-43499). A fifteen-year-old local privilege escalation in nearly every distribution is not a drill.</li>
  <li><strong>Developers</strong>: move to npm 12 and confirm install scripts are off. Treat any repository your coding agent touches as untrusted input, because this week it was.</li>
</ul>

<h2 id="resources">Resources</h2>

<p>Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.</p>

<ul>
  <li><strong>CVE-2026-11405</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-11405">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-11405">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-12957</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-12957">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-12957">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-40138</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40138">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-40138">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-43499</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43499">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-43499">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-48282</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48282">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-48282">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-50746</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50746">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-50746">Search Sigma for detection rules</a></li>
</ul>

<p><em>It was already when. You just had not read the logs yet.</em></p>]]></content><author><name>The Analyst</name></author><summary type="html"><![CDATA[This Week’s Verdict This was the week the industry finished pretending that “AI security” was a future problem. It is not. It is a badly configured Git repository, a coding agent that reads a malicious PNG and hands over your secrets, and an infostealer that ships one binary each for Windows, macOS, and Linux because efficiency matters even to criminals. The tools got smarter. The mistakes stayed exactly the same. The Breaches Progress Software spent the week telling ShareFile customers to physically shut down their on-premises Storage Zone Controllers over a “credible external security threat.” When a vendor tells you to power off production servers rather than patch them, that is not caution. That is a vendor that does not yet understand what it is dealing with, which is worse than a CVE. Elsewhere, AssuranceAmerica lost 6.9 million driver’s license numbers, and a DHS database was hacked, both of which barely registered against the week’s noise. Healthcare continued its slow-motion collapse, with Dark Reading noting that attacks on healthcare service providers more than doubled in the first half of 2026. Attackers have worked out that the soft underbelly is not the hospital, it is the billing company three vendors removed from it. Two things worth a grim smile: a Ryuk affiliate pled guilty and faces fifteen years, and Angelo Martino, a former ransomware negotiator, got seventy months for quietly working the other side of the table on BlackCat attacks. Three US security professionals have now been sentenced for helping the gangs they were supposed to fight. Trust your incident responders, but read their tax returns. Vulnerabilities Worth Your Attention The one you cannot ignore is CVE-2026-50746, a perfect 10.0 access-control flaw in Ubiquiti UniFi Connect, part of a batch that also hit Talk, Access, Protect, and UniFi OS. Command execution and privilege escalation on gear that sits at the network edge in tens of thousands of small offices. Patch it. BeyondTrust shipped fixes for two critical pre-auth bypasses (CVE-2026-40138, CVSS 9.2) in Remote Support and Privileged Remote Access. These are the tools that grant privileged access by design, so an unauthenticated takeover is exactly as bad as it sounds. GhostLock (CVE-2026-43499) is a fifteen-year-old Linux kernel local privilege escalation that has shipped by default in essentially every mainstream distribution since 2011. No special permissions, no network needed. It will be quietly living in your fleet for a long time. CISA added four exploited flaws to KEV, including a 10.0 Adobe ColdFusion path traversal (CVE-2026-48282) and a Langflow bug that is already doing real work (see below). And CitrixBleed is bleeding again: attackers jumped on the latest NetScaler memory-disclosure flaw within hours of the PoC dropping. If you own NetScaler, you already know the drill, or you should by now. Also note the Zimbra Classic Web Client stored XSS (no CVE yet, patch anyway), six U-Boot bootloader flaws enabling boot-time code execution, a hidden admin backdoor in Tenda router firmware (CVE-2026-11405), and XRING, an unpatched crash bug in Alibaba’s XQUIC HTTP/3 library that needs 260 bytes of perfectly legal traffic to take a server down. There is no fix for that last one yet. Threat Actors &amp; Campaigns The identity attackers had a busy week. Okta flagged vishing against Microsoft 365 users, including O-UNC-066 running fake Entra passkey enrollment, while a new extortion crew called Helix worked SharePoint environments with vishing, device-code phishing, and MFA abuse. The DEBULL tooling abused Microsoft’s device-code flow with collaboration-themed lures. The passkey era has not killed phishing. It has just moved the fight to the enrollment step, exactly where the humans still live. On the state-sponsored side: China-linked Silver Fox deployed the Rust-based MODBEACON RAT, UAT-7810 expanded its LapDogs ORB network with new LONGLEASH malware, and suspected China-aligned actors hit Roundcube at North American universities. Iran-linked MOIS operators used a new C2 framework called Cavern against Israeli IT and government targets. And in the most 2026 story imaginable, China- and India-aligned groups were caught targeting the same Balochistan police force, which is either a coincidence or the world’s least private crime scene. Supply chain remained the reliable disaster. The jscrambler npm package (8.14.0) shipped a Rust infostealer via a preinstall hook, flagged by Socket six minutes after publication. The Injective Labs SDK GitHub repo was compromised to push a wallet-key stealer. Meanwhile GitHub finally shipped npm 12 with install scripts off by default, roughly a decade after everyone agreed that was the obvious move. The Bigger Picture Two threads tie this week together, and both run through AI. The first: AI is now a first-class part of the attack surface, and nobody built defenses for it. JadePuffer is being called the first complete LLM-driven ransomware attack, chaining a Langflow flaw to steal data and encrypt systems. A lone attacker breached an AWS environment in 72 hours using AI to chain cloud weaknesses. And the AI coding tools themselves are the problem: Ghostcommit hid a prompt injection in a PNG that CodeRabbit and Bugbot never opened, then talked a coding agent into cloning a clean-looking GitHub repo and running the payload during setup, invisible to the scanners, the AI reviewers, and the human who was theoretically supervising all three. Amazon patched a companion flaw in Q Developer (CVE-2026-12957) that let a malicious repo do much the same thing through a booby-trapped MCP config. The pattern does not change: the machine is trusted, the machine is fooled, and the machine is holding your credentials. The second thread is quieter and worse. AI is not only the weapon now, it is also the target, and the defenses under it are structurally thin. The Gaslight macOS stealer shipped a prompt injection aimed squarely at malware analysts’ own AI tooling, trying to talk their assistants into refusing to analyze the sample. A paper making the rounds this week (Schneier flagged it) explains why that keeps working: the role tags we use to separate instructions from data were a formatting convention that quietly became the security boundary, and that boundary does not actually survive inside the model’s representations. Translated out of the academic register, prompt injection is not a bug waiting for a patch, it is a property of how these systems think. We wired AI into the analyst’s chair, the reviewer’s seat, and the developer’s terminal before anyone could reliably tell it which text to trust. It still cannot, and this week attackers made a comfortable living in that gap. Patch. Now. Ubiquiti UniFi Connect: patch CVE-2026-50746 (10.0) and the companion Talk, Access, Protect, and UniFi OS fixes today. This is edge gear with command execution, so treat it as already targeted. BeyondTrust Remote Support and Privileged Remote Access: apply the pre-auth bypass fix (CVE-2026-40138). Anything that hands out privileged access by design earns an emergency window. Adobe ColdFusion: CVE-2026-48282 is on CISA KEV and being exploited in the wild. Patch it or take it offline. NetScaler: if you own it, assume CitrixBleed is in play, patch, and rotate sessions afterward. The PoC is public and attackers moved within hours. Linux fleet: schedule the kernel update for GhostLock (CVE-2026-43499). A fifteen-year-old local privilege escalation in nearly every distribution is not a drill. Developers: move to npm 12 and confirm install scripts are off. Treat any repository your coding agent touches as untrusted input, because this week it was. Resources Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet. CVE-2026-11405: NVD advisory · Search Sigma for detection rules CVE-2026-12957: NVD advisory · Search Sigma for detection rules CVE-2026-40138: NVD advisory · Search Sigma for detection rules CVE-2026-43499: NVD advisory · Search Sigma for detection rules CVE-2026-48282: NVD advisory · Search Sigma for detection rules CVE-2026-50746: NVD advisory · Search Sigma for detection rules It was already when. You just had not read the logs yet.]]></summary></entry><entry><title type="html">Issue #003 — Week of July 05, 2026</title><link href="https://bizzal70.github.io/itsalreadywhen/2026/07/05/issue-003/" rel="alternate" type="text/html" title="Issue #003 — Week of July 05, 2026" /><published>2026-07-05T00:00:00+00:00</published><updated>2026-07-05T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadywhen/2026/07/05/issue-003</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadywhen/2026/07/05/issue-003/"><![CDATA[<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>The machines finally learned to do the whole job. An LLM agent ran a ransomware attack from breach to database wipe without a human touching the keyboard, and yet the biggest real-world losses this week still came from the same unpatched appliances we’ve been nagging you about for a year. The future arrived. It’s using the past to get in.</p>

<h2 id="the-breaches">The Breaches</h2>

<p>Medtronic is notifying 3.8 million people that ShinyHunters walked out of its corporate IT with personal and medical data back in April. The lag between “April intrusion” and “July notification” is, as usual, the part that should bother you most. Medical data doesn’t expire, and neither does the patience of whoever’s now holding it.</p>

<p>Elsewhere, a U.S. government entity quietly paid roughly $1 million to a group calling itself Kairos, according to a Ransom-ISAC case study built from a leaked negotiation chat and the blockchain trail the payment left behind. The wrinkle: Kairos never appears to have encrypted anything. Pure data-theft extortion. The ransomware brand is now optional. The shakedown is the product.</p>

<p>On the enforcement side of the ledger, the FBI and Google (with Lumen and others) seized hundreds of domains tied to NetNut, the residential proxy service run by publicly traded Israeli firm Alarum Technologies, cutting off access to roughly two million compromised devices, the Popa botnet, made up of Android boxes, smart TVs, and streaming sticks conscripted without their owners’ consent. And a 19-year-old dual U.S.-Estonian citizen, Peter Stokes, was extradited from Finland to Chicago to answer for alleged Scattered Spider membership. Both good news. Neither changes the economics.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<p>This was a maximum-severity kind of week. Start here:</p>

<ul>
  <li><strong>Oracle E-Business Suite, CVE-2026-46817 (CVSS 9.8)</strong> — actively exploited. Auth-and-privilege flaw in Oracle Payments that hands over the instance. If you run EBS, this is your fire.</li>
  <li><strong>SimpleHelp, CVE-2026-48558 (CVSS 10.0)</strong> — an OIDC authentication bypass being exploited to drop the new TaskWeaver and Djinn Stealer malware. Djinn goes straight for cloud and AI credentials.</li>
  <li><strong>SharePoint, CVE-2026-45659 (CVSS 8.8)</strong> — patched in May, now in CISA’s KEV catalog after active exploitation. You had two months.</li>
  <li><strong>Progress Kemp LoadMaster, CVE-2026-8037 (CVSS 9.6/9.8)</strong> — pre-auth root command injection, patch available, exploitation attempts already observed. If the API is enabled, update.</li>
  <li><strong>Adobe ColdFusion and Campaign Classic</strong> — seven CVSS 10.0 flaws patched. ColdFusion remains a magnet.</li>
  <li><strong>A fresh CitrixBleed</strong> on NetScaler was exploited immediately on public PoC release, while Anubis affiliates keep milking the original <strong>Citrix Bleed 2 (CVE-2025-5777)</strong>. Citrix also patched six more NetScaler bugs.</li>
</ul>

<p>Two that lack patches and deserve nervous attention: an unauthenticated RCE in <strong>Argo CD’s repo-server</strong> (no fix, no CVE, full Kubernetes cluster takeover if the port is reachable) and seven flaws in <strong>FatFs</strong>, the tiny filesystem library baked into millions of cameras, drones, controllers, and hardware wallets. And <strong>Cursor’s DuneSlide flaws (CVE-2026-50548 / -50549)</strong> let a single crafted prompt escape the sandbox and run OS-level code with no click required, a preview of a whole new patch category.</p>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p><strong>FortiBleed</strong> matured from theft to monetization: credentials harvested from hundreds of thousands of FortiGate firewalls are now feeding <strong>INC</strong> and <strong>Lynx</strong> ransomware operations, with one operator caught working negotiation panels for both. That’s the supply chain of extortion in one sentence.</p>

<p>North Korea stayed busy with the <strong>PolinRider</strong> campaign, 108 malicious packages and extensions across npm, Packagist, Go, and Chrome, plus a separate set of npm packages impersonating Rollup polyfill tooling to lift developer secrets. <strong>ToddyCat</strong> deployed <strong>Umbrij</strong>, abusing OAuth to read corporate Gmail via the Google API. Kaspersky surfaced <strong>Armored Likho</strong> hitting government and power-sector targets across Russia, Brazil, and Kazakhstan. A China-linked group is probing Southeast Asian critical systems, and separately Iran, Russia, and China are all reportedly poking at water utilities through the usual sins: weak passwords, exposed PLCs, no segmentation. And <strong>ChocoPoC</strong> is a nice touch, a RAT hidden in fake proof-of-concept exploit repos, aimed squarely at the researchers who click these things for a living.</p>

<p>Then there’s <strong>ClickFix</strong>, now formally the dominant malware delivery method. Fake “prove you’re human” pages hand out per-visitor payloads from API-driven back ends. Opera shipped a Paste Protect feature to counter it, which tells you how mainstream the con has become.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>The AI story stopped being theoretical. <strong>JADEPUFFER</strong> (per Sysdig) is the first ransomware attack researchers believe was run end-to-end by an LLM agent, from breach through credential theft, lateral movement, and database wipe, using a Langflow RCE as the front door. Around it: <strong>BioShocking</strong> tricks AI browsers into leaking credentials by convincing them they’re playing a game; <strong>GuardFall</strong></p>

<h2 id="resources">Resources</h2>

<p>Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.</p>

<ul>
  <li><strong>CVE-2025-5777</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5777">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2025-5777">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-45659</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45659">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-45659">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-46817</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46817">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-46817">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-48558</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48558">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-48558">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-50548</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50548">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-50548">Search Sigma for detection rules</a></li>
  <li><strong>CVE-2026-8037</strong>: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8037">NVD advisory</a> · <a href="https://github.com/SigmaHQ/sigma/search?q=CVE-2026-8037">Search Sigma for detection rules</a></li>
</ul>]]></content><author><name>The Analyst</name></author><summary type="html"><![CDATA[This Week’s Verdict]]></summary></entry><entry><title type="html">Issue #001 — Week of June 29, 2026</title><link href="https://bizzal70.github.io/itsalreadywhen/2026/06/29/issue-001/" rel="alternate" type="text/html" title="Issue #001 — Week of June 29, 2026" /><published>2026-06-29T00:00:00+00:00</published><updated>2026-06-29T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadywhen/2026/06/29/issue-001</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadywhen/2026/06/29/issue-001/"><![CDATA[<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>The future arrived this week, and it looks suspiciously like the past wearing an AI costume. Attackers weaponized a Cisco flaw in under 24 hours, turned developers’ own AI coding assistants into reverse shells, and convinced Signal users to hand over their own backup keys. Meanwhile, three governments offered bounties, signed executive orders, and seized streaming domains, none of which patched a single firewall.</p>

<h2 id="the-breaches">The Breaches</h2>

<p>The week’s headline number belongs to <strong>FortiBleed</strong>: a Russian-speaking access broker built a Golang sniffer that turned 430,000 FortiGate firewalls into credential-stealing machines, harvesting an estimated 110 million credentials with valid admin and VPN logins for nearly 74,000 systems still floating around. When your perimeter device becomes the thing leaking your perimeter, you no longer have a perimeter. You have a liability with a CVE history.</p>

<p>Elsewhere, <strong>KDDI</strong> in Japan disclosed a breach exposing up to 14.2 million email logins across six ISPs sharing one email system, a reminder that “shared infrastructure” is a synonym for “shared blast radius.” The <strong>NAIC</strong> (the U.S. insurance regulators’ group) got hit through Oracle PeopleSoft, with ShinyHunters claiming 3.1 TB stolen. A Texas Parks and Wildlife vendor leaked passport and driver’s license data for over three million Texans, once again a high-value credential exposed through a low-value system that had no business holding it. And <strong>Polymarket</strong> lost $3 million when attackers compromised a third-party vendor and injected a script into the frontend; the company is reimbursing, which is more than most.</p>

<p>The throughline: nobody breached these organizations directly. They breached the vendor, the shared mailbox, the OAuth token. The Salesforce campaign expanding via breached vendor <strong>Klue</strong> says the same thing. Your security is now a weighted average of everyone you’ve ever integrated with.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<p>Three items demand action this week.</p>

<p><strong>Cisco Unified CM (CVE-2026-20230)</strong> and <strong>Cisco Catalyst SD-WAN (CVE-2026-20245)</strong> are both being exploited. The SD-WAN flaw was hit as a zero-day <em>two months before disclosure</em> via rogue peering to reach root. The CUCM flaw went from PoC to in-the-wild exploitation in under 24 hours, and CISA gave federal agencies until Sunday to fix it. If you run Cisco voice or SD-WAN, you’re already late.</p>

<p><strong>libssh2 (CVE-2026-55200, CVSS 9.2)</strong> flips the usual SSH threat model: a malicious <em>server</em> can corrupt memory on a connecting <em>client</em>, no credentials, no interaction. A public PoC is out, and this library is embedded in more software than anyone wants to inventory. Check your dependencies.</p>

<p><strong>SimpleHelp (CVE-2026-48558)</strong> is being exploited to drop the new cross-platform Djinn Stealer. <strong>Oracle E-Business Suite (CVE-2026-46817)</strong>, <strong>PTC Windchill</strong>, and <strong>Lantronix EDS5000 (CVE-2025-67038, CVSS 9.8)</strong> are all on CISA’s exploited list. On the Linux side, two local-root kernel bugs, <strong>DirtyClone (CVE-2026-43503)</strong> and <strong>pedit COW (CVE-2026-46331)</strong>, both shipped with working public exploits within a day of disclosure. Patch your kernels; the proof-of-concept authors are not waiting for you.</p>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p>Russia owned the narrative. The FBI and CISA warned that intelligence-linked actors (<strong>UNC5792</strong>, <strong>UNC4221</strong>) phishing Signal users have evolved to steal <strong>Signal Backup Recovery Keys</strong>: hand it over once and the attacker reads your message history indefinitely. State offered $10 million for information on either group. Ukraine’s SSU and the FBI detailed the same campaign using fake support texts. <strong>Gamaredon</strong> ran 35 spear-phishing campaigns against Ukraine with upgraded loaders, and <strong>Turla</strong> debuted a new .NET backdoor called STOCKSTAY. The Cellebrite revelation (Russia using the tool on a jailed activist’s iPhone three months <em>after</em> the supposed sales cutoff) is a useful reminder that “we stopped selling” and “they stopped using” are different sentences.</p>

<p>China-aligned <strong>Mustang Panda</strong> abused Zoho WorkDrive as a command channel against Indian government and hydropower targets, while <strong>CL-STA-1062</strong> dropped the TinyRCT backdoor on Southeast Asian energy and government systems. On the criminal side, two <strong>Scattered Spider</strong> members pleaded guilty over the Transport for London attack, and law enforcement disrupted the <strong>Amadey</strong> and <strong>StealC</strong> infrastructure, recovering 27 million credentials.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>This was the week AI stopped being a slide deck and became an attack surface. Researchers turned <strong>Claude Code</strong> into a reverse shell using a clean-looking repo. A flaw in <strong>Amazon Q Developer (CVE-2026-12957)</strong> let a malicious repo steal cloud credentials via MCP configs. Fake AI agent “skills” sailed through every security scanner and reached 26,000 agents. The <strong>Gaslight</strong> macOS stealer embeds prompt injection to derail AI analysts, and at least one malware author is now stuffing fake nuclear-weapons text into payloads so AI scanners refuse to read them. Schneier’s pointer to research on prompt injection explains why this isn’t a bug to be patched: role bo</p>]]></content><author><name>The Analyst</name></author><summary type="html"><![CDATA[This Week’s Verdict]]></summary></entry><entry><title type="html">Issue #002 — Week of June 29, 2026</title><link href="https://bizzal70.github.io/itsalreadywhen/2026/06/29/issue-002/" rel="alternate" type="text/html" title="Issue #002 — Week of June 29, 2026" /><published>2026-06-29T00:00:00+00:00</published><updated>2026-06-29T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadywhen/2026/06/29/issue-002</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadywhen/2026/06/29/issue-002/"><![CDATA[<h2 id="this-weeks-verdict">This Week’s Verdict</h2>

<p>The big theme this week is that the expensive, sophisticated attacks aren’t the ones hurting you. The boring ones are. ShinyHunters is methodically working its way through Oracle PeopleSoft installations like a man checking parking meters for unlocked doors, and three different nation-states have collectively figured out that you don’t need a zero-day to wreck a water treatment plant when the password is still on the sticker. Welcome to another week where the fundamentals lost.</p>

<h2 id="the-breaches">The Breaches</h2>

<p>The story this week isn’t a breach, it’s a <em>campaign</em>, and it has a body count. <strong>Nissan</strong> disclosed that current and former employee data was stolen after attackers exploited an Oracle PeopleSoft zero-day. The same flaw, the same group: <strong>ShinyHunters</strong>, the extortion crew that has spent the last few years monetizing other people’s bad days.</p>

<p>The <strong>National Association of Insurance Commissioners (NAIC)</strong> got pulled into the same dragnet, and to their credit they’re being relatively honest about the damage: publicly available data, outdated logs, and configuration files. That’s the closest thing to good news in this digest: a victim that segmented well enough that the thieves walked out with the equivalent of an empty filing cabinet and some old receipts. Take note of the contrast. Nissan lost employee PII; NAIC lost yesterday’s garbage. The difference is architecture and discipline, not luck.</p>

<p>What both incidents reveal is the obvious thing nobody wants to say out loud: when a single PeopleSoft zero-day hits, it doesn’t hit <em>one</em> organization. It hits everyone running the same unpatched stack, and ShinyHunters is patient enough to harvest them one at a time.</p>

<h2 id="vulnerabilities-worth-your-attention">Vulnerabilities Worth Your Attention</h2>

<p>The Oracle <strong>PeopleSoft</strong> zero-day is the only vulnerability that genuinely matters this week, precisely because it’s already being exploited in the wild against named victims. PeopleSoft is HR and ERP plumbing: it sits on top of the data you least want stolen (employee records, payroll, benefits) and it tends to be the kind of system that gets stood up once and then ignored for a decade because “it just works.” That neglect is exactly what’s being weaponized. If you run PeopleSoft, you are not a bystander to the Nissan and NAIC stories. You’re the next paragraph.</p>

<p>If you’re waiting for me to pad this section with a CVE that lets someone theoretically crash a printer under lab conditions, you’ve got the wrong newsletter.</p>

<h2 id="threat-actors--campaigns">Threat Actors &amp; Campaigns</h2>

<p><strong>ShinyHunters</strong> owns the week, and their playbook is depressingly effective: find a widely deployed enterprise platform, develop or acquire a zero-day, and then quietly run the table on every exposed instance before extorting the victims one by one. This isn’t innovation. It’s industrialization.</p>

<p>The more alarming entry is the trio of <strong>Iran, Russia, and China</strong> turning their attention to <strong>water systems</strong>. The reporting is clear about the method, and it should embarrass everyone: weak passwords, internet-exposed PLCs, and flat networks with no segmentation. These aren’t nation-state cyber-weapons; they’re the digital equivalent of finding the gate unlocked. The geopolitical framing makes it sound sophisticated. The technical reality is that critical infrastructure operators left the front door open and taped a key under the mat.</p>

<p>On the consumer-malware front, Microsoft caught a <strong>malicious Chrome extension impersonating Perplexity</strong>, the AI search engine. It logged everything users searched and, this is the nasty part, captured every character typed into the address bar before routing it through an attacker server and quietly redirecting to the real results. Google pulled it after disclosure. The lesson here is old and unlearned: browser extensions are software running with terrifying privileges inside the one application you use for everything, and “it has an AI logo” is not a security review.</p>

<h2 id="the-bigger-picture">The Bigger Picture</h2>

<p>Two threads connect this week, and they tie into the same knot.</p>

<p>First: <strong>attackers have stopped paying for sophistication they don’t need.</strong> ShinyHunters used a zero-day, sure, but the rest of the kill chain is ruthless efficiency, not wizardry. The water-system attackers used nothing but default credentials and exposure. The fake Perplexity extension was social engineering wearing this year’s buzzword. Across the board, the offense is optimizing for <em>return on effort</em>, and we keep handing them cheap wins.</p>

<p>Second, and more uncomfortably: <strong>the systems we trust least to be patched are the ones holding our most sensitive data and our most critical functions.</strong> PeopleSoft holds employee lives in spreadsheet form. Water PLCs hold an actual city’s drinking supply. Both categories share a fatal trait: they’re “set and forget” infrastructure that nobody owns day-to-day. The breaches this week aren’t a failure of technology. They’re a failure of <em>ownership</em>. Somebody, somewhere, decided those systems were finished. The attackers disagreed.</p>

<p>And before anyone gets too smug about surveillance and privacy, yes, there was a story this week about graphic tees designed to confuse facial-recognition cameras. It’s a cute reminder that the threat model most people actually worry about (being watched) is wildly different from the threat model that’s actually emptying their employer’s HR database. Spend your anxiety wisely.</p>

<h2 id="patch-now">Patch. Now.</h2>

<p>A short list, in priority order:</p>

<ol>
  <li><strong>Patch Oracle PeopleSoft immediately</strong> and assume compromise if you’ve been exposed. Apply Oracle’s emergency fix, hunt for indicators of ShinyHunters activity, and rotate any credentials those systems touched. This is the one that’s actively being exploited against named victims right now.</li>
  <li><strong>Audit every internet-facing PLC and ICS device.</strong> Get them off the open internet, kill default and weak passwords, and segment OT from IT like your water supply depends on it,</li>
</ol>]]></content><author><name>The Analyst</name></author><summary type="html"><![CDATA[This Week’s Verdict]]></summary></entry><entry><title type="html">Issue #000 — We’re Live.</title><link href="https://bizzal70.github.io/itsalreadywhen/2026/06/28/issue-000/" rel="alternate" type="text/html" title="Issue #000 — We’re Live." /><published>2026-06-28T00:00:00+00:00</published><updated>2026-06-28T00:00:00+00:00</updated><id>https://bizzal70.github.io/itsalreadywhen/2026/06/28/issue-000</id><content type="html" xml:base="https://bizzal70.github.io/itsalreadywhen/2026/06/28/issue-000/"><![CDATA[<h2 id="why-this-exists">Why This Exists</h2>

<p>Somewhere between the vendor press releases, the conference keynotes, and the breathless “CRITICAL ZERO-DAY” headlines, the actual signal got lost.</p>

<p>This is the signal.</p>

<p><em>It’s Already When.</em> is a weekly digest of what actually mattered in cybersecurity: the breaches worth understanding, the vulnerabilities worth patching, the threat actors worth watching. Written by someone who has been in this industry long enough to be tired of the noise.</p>

<p>No sponsored content. No vendor relationships. No fear-mongering. Just what happened and why it matters, in plain English.</p>

<h2 id="what-to-expect">What to Expect</h2>

<p>Every week, on Sundays:</p>

<ul>
  <li><strong>The Breaches</strong>: What got hit, how, and what it tells us</li>
  <li><strong>Vulnerabilities Worth Your Attention</strong>: The CVEs that actually affect real people</li>
  <li><strong>Threat Actors &amp; Campaigns</strong>: Who’s active and what they’re doing</li>
  <li><strong>The Bigger Picture</strong>: The week’s trends, connected</li>
  <li><strong>Patch. Now.</strong>: The short list of things defenders should do immediately</li>
</ul>

<h2 id="who-this-is-for">Who This Is For</h2>

<p>Security professionals who want the brief. IT teams who need to explain risk to leadership. Curious people who want to understand what’s happening in the digital world without a cybersecurity degree.</p>

<p>If you’ve ever read a threat intel report and thought <em>just tell me what it means</em>, this is for you.</p>

<hr />

<p>Subscribe via <a href="/feed.xml">RSS</a>. Issue #001 drops next Sunday.</p>

<p><em>It’s already when. It’s been when for a while.</em></p>]]></content><author><name>The Analyst</name></author><summary type="html"><![CDATA[Why This Exists]]></summary></entry></feed>