The archive
Writing
Every essay. New work on the 1st and 15th.
-
The Patch Landed. The Keys Were Already Copied.
INC ransomware stole MFA seeds from SonicWall VPN gear before the fix shipped. Patching closed the door — it didn't change the locks on what's inside.
-
17,000 Actions, One Weekend, Zero Humans
Hugging Face's breach disclosure confirms an intrusion run end-to-end by an autonomous AI agent. The lateral movement pattern is familiar — the pace isn't, and that changes what segmentation has to do.
-
What Actually Changes About vDefend Licensing in 9.1
The 25-character license key you've been using since NSX won't work on 9.1. Here's what you need in place before you upgrade.
-
Before the Patch Window Opens: Segmenting Your Backup Infrastructure
Any domain account can RCE your Veeam backup server right now. The Distributed Firewall is how you limit the blast radius while you wait for the patch.
-
Avi Load Balancer 32.1.1: VCF 9.1, MCP Traffic, and the Licensing Shift
Avi 32.1.1 lands native VCF 9.1 integration, MCP load balancing for AI agent workloads, and the same licensing model change shipping in SSP 5.1.2. Here's what it means in practice.
-
SSP 5.1.2 and the License Hub: What the Licensing Shift Actually Means
SSP 5.1.2 ships License Hub — a centralized licensing layer for vDefend and Avi that replaces 25-character keys with subscription files. Here's what's changing and what it requires if you're planning an SSP 5.1.2 upgrade.
-
When the Patch Window Is Thirty Days and the Change Board Meets Fridays
A messaging broker RCE hit CISA's actively-exploited list in April with a 30-day patch window. Here's what happens when you won't make it — and where vDefend virtual patching fills the gap.
-
Ten Hours
On the shrinking gap between disclosure and exploitation — and what vDefend's April update actually means for the people running the change board.