THE DEEP TAKE
The federal list tells you what was exploited. It does not tell you when.
On Tuesday, CISA added four actively exploited flaws to its catalog. Three sit in the gear that guards the front door: two in Check Point, one in F5's BIG-IP access manager. The fourth is in Arista's VeloCloud orchestrator. Federal agencies were given until today to patch. Most enterprise teams will read that list the way they always do. It went on the list, so it goes to the top of the queue.
The dates underneath tell a different story. F5 disclosed its flaw as an exploited zero-day on the same day CISA listed it. No lag. Check Point shipped the fix for its VPN flaw on September 9. It then saw a wave of exploitation attempts against its Spark firewalls starting September 12. The listing came ten days after that. The second Check Point flaw, in the management server, is older still. Check Point's own researchers saw targeted attempts against it on July 23, while it was still a zero-day. That is two months before the listing.
So one Tuesday list carried three different clocks: zero days, ten days and about sixty. The catalog is an honest record of what has been exploited. It is not a record of when exploitation started. For firewalls and VPNs, that gap is the whole game. Those boxes sit on the internet, hold credentials and see every session. An attacker who got in during the gap does not leave when you patch.
That changes two things next week. First, the trigger. For your perimeter and security vendors, the patch clock should start at the vendor's own exploitation notice, not at the federal listing. Check Point said "exploited" on September 12. Anyone who waited for CISA gave away ten days. Second, the hunt window. Patching closes the door. It does not tell you who walked through. Start the hunt at the vendor's first-attempt date, not your patch date: July 23 for the management servers and September 12 for the gateways. CISA's own directive now expects federal agencies to check for compromise before the patch date. That is a sound standard for everyone else too.
One detail worth passing to whoever runs the firewalls. The two Check Point fixes are separate. The quick hotpatch that closes the VPN flaw does not fix the management flaw. That one needs its own hotfix on every management, log and event server. A team that applied one fix and closed the ticket is half patched. Check Point also published the certificate names seen in the VPN attacks. Ask for a search of Mobile Access logins since September 12 for any certificate-based login that looks wrong.
The question for your next staff meeting is simple. Who watches vendor advisories for the word "exploited", and how fast does that reach a change window? If the honest answer is "we wait for CISA," the list is working as designed. It is just working ten days behind the attackers.
From the people who send this
CXO Brief is published by DoGood. More than seventy enterprise vendors are currently paying for 30-minute briefings with IT and security leaders on AI governance, third-party risk, identity, observability and infrastructure. You choose which vendors to meet, if any. Every completed briefing pays you up to $500, as a premium gift card, cash, or a donation to a charity you pick if your employer restricts gifts. Membership is free and by invitation.
Or reply to this email with the word "briefing" and Ryan will set you up personally.
QUICK HITS
A recruiting portal was the way in
ShinyHunters says it broke into the FBI through an unknown flaw in Oracle PeopleSoft, entering through the bureau's jobs site. On September 23 the FBI said it is investigating claims of a compromise of FBIJobs.gov that affects employee data. It has not confirmed the zero-day. Reuters verified personal details for more than 22 people in a sample the group released. The enterprise lesson holds whether or not the zero-day does. Careers portals face the internet by design, and they often sync straight into core HR. A 2022 Justice Department privacy filing described the FBI's hiring gateway feeding its internal HR system. Yours probably does the same. This week, list every internet-facing PeopleSoft or candidate portal you run, including any a recruiting vendor hosts for you. Confirm who patches it and what it can reach. Until a patch exists, limiting that reach is the control.
A cheaper model is a bigger bill
Anthropic released Claude Opus 5.5 on September 22 and cut its API price 20%, to $4 per million input tokens and $20 per million output tokens. Reading that as a saving is a mistake. In a July Accenture survey of 750 executives, 42% said they would expand existing AI workloads if token prices fell 25% or more. The same report found only about 10% of workloads need frontier-level reasoning. Employees default to the most capable model because they cannot see the cost difference. So price cuts mostly raise usage, and the usage flows to the top tier. Before this cut reaches your budget, decide which workloads get the frontier model and route the rest to cheaper ones. Otherwise this quarter's discount becomes next year's overrun.
THE NUMBER: 10,000
That is how many organizations one AI-assisted phishing service reached before Microsoft took it down this week. EvilTokens launched in February, sold on Telegram for a $1,500 buy-in, and compromised more than 12,000 inboxes. Microsoft seized 50 sites, and partners pulled more than 150 more domains. Twelve thousand inboxes across ten thousand organizations is barely more than one mailbox per victim. That is not targeted work. It is volume. The service ran on device-code phishing, which gets past a normal MFA prompt because the victim signs in on a real Microsoft page. If you have not limited the device-code sign-in flow to the few devices that need it, this number is the case for doing it.
Third-party risk and identity are among the topics enterprise vendors are paying to brief leaders in the DoGood network on right now. You decide which of those 30 minutes are worth your time.
The CXO Brief is published by DoGood, the network where enterprise IT leaders are paid for 30-minute vendor briefings.
Know a CIO who needs this? Forward it and they can subscribe here.
Run IT or security at a $100M+ company? Claim your invite.
