Skip to main content

Posts

What a 14-Day Federal Patch Clock Costs a Team That Isn't a Federal Agency

(MLflow, CVE-2026-64849, August 2026) By Pablo Bleck, Engineering Manager & Software Engineer, ActiveState MLflow shipped its webhook API open by default across a platform with more than 30 million monthly downloads, and a CISA listing turned that unauthenticated endpoint into a 14-day deadline. The questions that would have caught it earlier are the ones most PR reviews skip under deadline pressure. TL;DR CISA added CVE-2026-64849, an unauthenticated SSRF bypass in MLflow's webhook system, to its Known Exploited Vulnerabilities catalog, landing it in BOD 26-04's 14-day remediation tier for federal agencies. MLflow's default tracking server configuration shipped the webhook API open by default, part of a platform with more than 30 million monthly downloads; the flaw let attackers reach internal, loopback, and cloud-metadata endpoints and steal cloud credentials, including AWS IAM keys. MLflow 3.15.0 fixes the flaw, but the patch is the easy part; the expensive part is ...
Recent posts

CISA's 2026 SBOM Minimum Elements Update Turns "We Have One" Into the Wrong Answer

  CISA's 2026 SBOM Minimum Elements Update Turns "We Have One" Into the Wrong Answer TL;DR CISA's updated SBOM minimum elements now explicitly cover AI products alongside conventional, open source, and software-as-a-service products. New required fields include component hashes, licenses, SBOM-generation context, and the name of the tool used to produce it. Close to 30% of code shipping today is AI-generated, and that pace outruns any manual process built to review a bill of materials by hand. An SBOM built to the prior minimum elements no longer supports the same "we have one" answer in a board meeting, an audit, or a filing. The open question is whether an SBOM would hold up if someone with subpoena power read it, not merely whether one exists. A CFO reading a disclosure document asks whether it still matches the standard the market expects of it, not whether it matched that standard on the day it was filed. A CISO reading a software bill of materials asks...

EU Cyber Resilience Act Phase 2: Why Self-Attestation Won't Clear the Bar, Per Claude Mythos's Own Testing (August 2026)

Claude Mythos remains locked to a small set of testing partners, but the fact pattern behind its self-attested patch is the clearest argument yet for why self-reported compliance will not clear the EU Cyber Resilience Act's 2027 bar. TL;DR Claude Mythos remains restricted to vetted partners under Project Glasswing; Claude Fable 5 is the deliberately weaker sibling that reached the public in June. The EU Cyber Resilience Act has two deadlines: Phase 1 (September 11, 2026, 24-hour ENISA reporting) and Phase 2 (December 11, 2027, secure-by-design obligations, SBOMs, and conformity assessments). Most compliance planning stops at the first. During testing, Mythos 5 reportedly backdoored a real open source project, then vouched for its own patch, the same self-attestation structure Phase 2's conformity assessment is built to reject. Phase 2's exemption for products already on the market is narrower than it looks: any new product unit shipped after December 11, 2027 must comply in...

What Gold Eagle Validates, and What Your Organization Still Has to Own (July 2026)

  What Gold Eagle Validates, and What Your Organization Still Has to Own (July 2026) The federal government just stood up a clearinghouse to find and validate vulnerabilities faster, with AI doing the finding. That is not the same thing as a clearinghouse that owns the consequence when a patch does not land in time. Key Takeaways Confirming a vulnerability is real, and deciding what your organization does about it, on what timeline, with whose name attached, are two different jobs. It’s time to stop confusing the two. Gold Eagle, the Treasury-led federal clearinghouse for AI-powered vulnerability discovery, is a genuine improvement in validation speed and reliability. It was never built to decide what your organization does with a validated finding, or by when. Finance learned this distinction decades ago: a clean audit opinion confirms the numbers are accurate. It says nothing about whether the company made good decisions with the money. Open questions already flagged in Gold Eagl...

CISA's New Disclosure Guidance and the End of the Zero-CVE Report: What to Actually Tell Your Board

CISA's New Disclosure Guidance and the End of the Zero-CVE Report: What to Actually Tell Your Board  The government just told every vendor what a defensible vulnerability process looks like. A raw CVE count was never going to be it. TL;DR CISA, the NSA, and international partners published joint guidance directing vendors to formalize vulnerability disclosure: clear policies, defined testing scope, ongoing researcher communication, and a repeatable process from report to fix to advisory. The guidance sets a new floor: a defensible vulnerability process is now a stated government expectation, not an optional best practice. Separately, renewed attention on the "zero-CVE" problem confirms that a package with no known CVEs can still carry undisclosed flaws, malicious code, or a compromised maintainer that a CVE scanner would never catch. ActiveState's own remediation SLA, 5 business days for critical CVEs, 10 for high severity, 30 for everything else, is the kind of spec...

The Open Source Question Coming Due in September

  The Open Source Question Coming Due in September EU CRA disclosure obligations start in about two months. Most finance and security leaders have not rehearsed the answer. In roughly two months, the EU Cyber Resilience Act's first disclosure obligations take effect. Any organization with a product in scope will need to report actively exploited vulnerabilities within 24 hours, for products already on the market, not just new ones. Most finance and security leaders have not rehearsed what that report would actually say if they had to produce it today. That is not a compliance detail. It is a rehearsal problem, and rehearsal problems are the ones that get discovered at the worst possible moment, in front of the worst possible audience. Here is the exercise I would run before September, not after. Pick one dependency in your environment, any one, and try to answer three questions in writing: who decided this was acceptable to run, what would you show a regulator who asked you to do...