|
Bayou Bytes // Issue #11 · Exposed Edge Week
Come, Take Your First Byte.
Three sections, twelve minutes. Starting now.
|
|
|
The Pulse
|
|
Every Tuesday: the threats that actually moved, one fix you can ship before lunch, and the plain-English version your non-technical CEO needs to hear. Eight of the eighteen CVEs CISA added to the exploited-vulnerability catalog in the first ten days of September were edge kit — firewalls, VPN gateways, routers, and the console an MSP runs an entire client book through.
Now, this week:
|
|
🔴 Threat level: elevated — and this week the story isn’t the severity score. It’s that the severity score couldn’t agree with itself.
Two authoritative records score the same flaw 7.4 and 9.8. On Sep 9 CISA added four vulnerabilities to the Known Exploited Vulnerabilities catalog, three of them edge kit: CVE-2026-20079, a Cisco Secure Firewall Management Center authentication bypass; CVE-2026-19490, a Citrix NetScaler ADC/Gateway authentication bypass; and CVE-2025-25249, a Fortinet heap-based buffer overflow. Federal civilian agencies had until Sep 12 on all three. Now try to rank them. Fortinet’s own advisory calls the Fortinet flaw high severity and scores it 7.4; NVD scores the same bug 9.8, critical. One flaw, two records, a spread that crosses a severity boundary — and it is the one carrying a documented mass campaign. SOCRadar reported an attack chain delivering a Node.js remote-access trojan named PivotC2: more than 30,000 IP addresses targeted, 178 devices exploited and infected, mainly US entities, with exploitation seen since July 2026. Cisco separately updated its advisory to say it became aware of active exploitation in August, and Cisco Talos published three clusters of post-compromise activity deploying web shells and malware. If two authorities can’t agree on the number, the number is not your sort key.
If you are an MSP, your management plane spent the week on that list. On Sep 8 CISA added CVE-2026-86218 in N-able N-central, in CISA’s own words a static code injection vulnerability “that could allow for pre-authentication remote code execution” — federal due date Sep 11. (No CVSS figure here on purpose: CISA publishes none, N-able’s own advisory rates it 10.0 and NVD rates the same CVE 9.8. Same problem as above.) N-able patched it in N-central 2026.3 Hotfix 4 on Sep 5 and told customers it “has been observed being exploited in the wild,” while its public release notes said there were no confirmations of exploitation in production environments — read both halves. Two details make this worth more than a patch note. Huntress said it opened an investigation after the compromise of a customer’s fully patched N-central production environment on Sep 4, and stated it could not definitively confirm which exploit was used — in part because of limited historical logging available on the appliance. And watchTowr, which reproduced the flaw, made the structural point: N-central is used by MSPs, MSSPs and large IT organizations to manage entire customer estates, so compromising it reaches every connected system downstream. Patch it. Then ask the other question: is that console reachable from the open internet, and is it on anybody’s asset list as such?
CISA quietly re-cut its insider-threat guidance for the way people actually work now. On Sep 9 CISA released an updated Insider Threat Mitigation Guide — new case studies and statistics, a streamlined structure, and new guidance on three things the original barely covered: hybrid and remote work, artificial intelligence, and adverse employee separations. CISA frames it for security and HR professionals and says any organization can use it regardless of security maturity. If you ran the offboarding afternoon a fortnight ago, this is the free companion reading — and the adverse-separation section is the hour worth booking, because that is the departure where the identity list and the exposure list stop being separate problems.
|
|
|
The Hardened Stack
Deep Dive: you know what your stack would notice. Do you know what answers strangers?
|
|
Last week’s afternoon produced a coverage record — five events, three questions each, times written down. This week flips the telescope around, because the ranking most of us use to decide what to fix first is demonstrably the wrong one. In June, CISA’s Binding Operational Directive 26-04 replaced both BOD 19-02 and BOD 22-01 and re-sorted federal patching around four variables: is the asset publicly exposed; is the CVE on the KEV catalog; can exploitation be automated; and does it yield partial or total control. Severity score is not one of the four.
Two honest notes before you take that anywhere. First, a Binding Operational Directive is compulsory only for the Federal Civilian Executive Branch agencies it names — it does not bind your company, your MSP, or your clients. CISA’s wording for the rest of us is the softer verb: it “encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.” A recommendation, not an obligation. Second, the directive’s day-count table is published as an image on CISA’s page, so we are not quoting numbers from it. Neither of those weakens the useful part, which is free: the schema. Here’s the afternoon:
|
THE EXPOSED EDGE REVIEW — ONE AFTERNOON
1 LIST four routes, because you have four lists:
inbound from the firewall NAT rules
outward from DNS (every domain you own)
across cloud tenants (public endpoints)
through vendor consoles (RMM, EDR, backup)
2 TAG org · prod-or-dev · public-or-internal ·
server-app-or-device — plus the fifth field
that decides everything: the NAMED human.
3 CHECK KEV, by PRODUCT name, not by CVSS score.
Read the version off the HOST, not the
dashboard. Dashboards report what they
were told.
4 RANK exposed + on KEV beats a higher-scored
internal finding. Every time.
5 ATTEST date it, sign it, note what was ADDED and
REMOVED since last quarter. Then diary the
next one before you close the laptop.
|
|
|
Step 1 is where the finding actually lives, and it lives in the disagreement. DNS knows about hostnames the firewall has never seen; the firewall knows about a port-forward from 2019 nobody will admit to; neither knows about the cloud deployment that published its own endpoint; and none of the three know about the vendor console that reaches your whole estate and that you cannot patch, log, or even see. The overlap between the four lists is comforting. The non-overlap is the week’s work. Step 2’s four tags are lifted straight from the directive — organization, environment, exposure, asset type — and the fifth is ours, because an asset with no named owner is an asset whose alerts do not survive triage. Step 5 is what turns a spreadsheet into a control: a list you rewrite every quarter tells you nothing, but a list plus a delta tells you how fast your own attack surface is growing and who is growing it. The rule stays the rule: every claim gets a NUMBER and a DATE. “Our perimeter is locked down” is a mood; “41 externally reachable assets confirmed Sep 17 from off-network, 6 on KEV, 5 patched, 1 mitigated by source restriction, 3 dangling DNS records removed, next attestation Dec 17” is an artifact.
|
|
GB013: four routes, four tags, the KEV cross-check →
|
|
⚠️ Confirm “public or internal” from OUTSIDE your own network, not from a config page — and only against systems you own or are authorised to test. For anything that was exposed and on KEV before you patched it, record whether you looked for signs it had already been used: patching closes a door, it does not tell you who came through it. If you find evidence of that, follow your incident-response plan and engage counsel and your insurer per its terms. The kit is a review format and a starting point, not managed security or penetration-testing services, and not legal, compliance, or audit advice.
|
|
|
The Boardroom Bridge
Asking for the afternoon without the fear budget
|
|
The talking point (a literal script for non-technical execs — steal it)
|
|
“We patch on severity, which sounds responsible and is the wrong order. The federal government stopped doing it that way in June — their first question is now whether the box can be reached from the internet at all, and the second is whether somebody is already exploiting it in the wild. I want one afternoon to produce the list we have never actually written down: everything of ours that answers the internet, who owns each one, and which of them run something on the known-exploited list today. Best case, I hand you a dated register with nothing open on it. Worst case, we find the forgotten one ourselves — and re-sorting the patch queue costs nothing.”
|
|
|
Boards don’t fund fear. They fund an afternoon that ends in a one-page dated record either way it lands. And the re-ordering itself is free: it is a change of sort order, not a change of budget.
|
|
|
|
Next week’s Reader Q&A answers the winning option.
|
|
This week’s tool — AxiomLens
|
|
The afternoon gives you the register; keeping it true as the estate changes is the grind. That rhythm — re-attesting on a schedule, evidence tied to controls, a board-readable report — is what AxiomLens systemizes: a local compliance engine over all 106 NIST CSF 2.0 subcategories that reports your coverage as a number and writes a board-ready report on demand. Built to be owned, not rented — one-time license, per named user, node-locked, and after a one-time activation it runs fully offline. It supports compliance documentation and audit-prep workflows; a tool, not a certification, and not legal, compliance, or audit advice.
One-time license — check the store for current pricing.
|
|
|
|
Sources:
CISA BOD 26-04 — “Prioritizing Security Updates Based on Risk” (Jun 10) |
CISA (KEV alert, Sep 8 — N-able N-central) |
CISA (KEV alert, Sep 9 — Cisco / Citrix / Fortinet) |
CISA KEV catalog |
CISA Insider Threat Mitigation Guide (updated Sep 9)
|
|
THE SECURITY GATOR // BAYOU BYTES // EVERY TUESDAY
|
|