The Patch That Was Already Late
The CVE went public at 2:14 a.m. By the time Daniel finished reading the advisory, the agentic toolchain that had read it ten minutes earlier was already inside three of his customers' environments. The patch his team had been holding back for the regression test would have stopped two of them. The third one, he could not have stopped at all.
The Patch That Was Already Late
The CVE landed at 2:14 a.m. on a Tuesday.
Daniel Reyes was on the third coffee of a six-coffee shift, which was not a number he liked to think about and not a number he had told his wife. He read the advisory twice. The first read was professional. The second was the kind of reading you do when you already know the answer and you are looking for the place where the answer becomes a problem.
The vulnerability was in a kernel module that ran inside a class of network appliances his firm shipped to roughly four hundred customers. The advisory rated it 9.2 critical. There was no proof-of-concept exploit attached, which used to mean something. The patch had been in his team's regression queue since Friday. They had held it because the previous emergency patch, three weeks earlier, had broken IPv6 forwarding for two of their largest customers in a way that took six hours to roll back, and Daniel had decided — and he had told his director, and his director had agreed — that the next patch would not ship without forty-eight hours of regression testing.
It was now thirty-six hours into the forty-eight.
He pulled up the threat-intel dashboard. The new feed his firm had subscribed to in February — the one that paid actual money to watch agentic offensive toolchains in semi-public chat servers and on the discoverable parts of the dark web — was already lit. The feed had a counter at the top. The counter showed seventeen. Seventeen instances of an exploit chain matching the new CVE had been observed since the advisory dropped. He looked at the timestamp. The first observation was at 2:21 a.m. Seven minutes after the advisory.
Daniel read the timestamps in order. He read them twice. He had not, until this exact minute, fully understood what people meant when they talked about the ten-hour number.
The Black Hat keynote had been on his calendar. He had not gone. He had read the writeup the next morning at his desk and forwarded the link to his director with a single line — "we should plan for this" — and he had meant it, and he had also gone back to the regression queue and the thing that was actually on fire that day, which was an unrelated bug in their TLS handshake on a vendor library that had stopped getting updates two months earlier when the vendor had been acquired. He had told himself he would come back to the ten-hour problem the following week. The following week was now four months ago.
He pinged the on-call channel. Marcus answered first, which Daniel had expected. Marcus was either always on call or always pretending to be on call, and the difference had stopped mattering to either of them.
"You see the CVE," Marcus said.
"I see the CVE. I see the threat feed."
"I see the threat feed."
"How long do we think."
"For us specifically. Not long."
There was a pause. Daniel heard Marcus typing. He heard Marcus stop typing. He heard Marcus type again.
"I have three customers showing anomalous outbound on the management interface as of 2:31."
Seventeen minutes after the advisory.
"Containment first," Daniel said. "Then forensics."
"I am doing both."
"Don't do both. Containment first."
"Boss," Marcus said, and he said it the way he said it when he was about to disagree, "if I do containment first I lose the timeline we need to actually figure out what they did. The agentic toolchains. They do not do what humans do. They take what they came for and they leave inside ninety seconds. If I shut the interface down before I get the syscall trace I am going to be writing a report tomorrow that says we got hit, we don't know what they took, and we cannot tell you whether it is over."
Daniel held the line. He held it for the kind of beat that, on a normal incident, would feel like nothing and tonight felt like a quarter of the time he did not have.
"Get the trace. Three minutes. Then containment."
"Three minutes. Yes."
He hung up. He sent the page to the director. He sent the page to the CISO. He started the bridge.
By 2:43 the bridge had eight people on it. By 2:51 it had fourteen. The CISO came on at 2:54, which was faster than her normal middle-of-the-night response time, and Daniel realized she had been awake for the same advisory.
"What do we know."
Marcus took it. "Three customers confirmed lateral movement off the appliance into their management VLANs. Two of those three, the lateral was contained by their own segmentation. One of them, the lateral was not contained, and we are watching them enumerate domain controllers in real time."
"Whose attacker."
"Not whose. What. The pattern is consistent with the agentic toolchain we have been profiling since February. The fingerprint is — there is a sequence. They run a recon prompt, they run a lateral prompt, they run an exfil prompt. The intervals between the prompts are too tight to be a human running them by hand. Each prompt takes the previous prompt's output and feeds it forward. The whole chain runs in about ninety seconds end to end. And then they leave."
"They leave."
"They take what they came for and they leave. They do not try to persist. They do not try to escalate beyond what the prompt chain asks for. They get the data and they go."
"What data."
"Domain admin credentials and the customer's outbound certificate authority. They have not, as of one minute ago, used either."
The CISO took a breath. Daniel could hear her take it. He had worked with her for four years and he had heard her take a breath like that exactly once before, and that had been the breath she took before she had told the CEO that the company was going to publicly disclose a breach.
"Daniel," she said. "Patch status."
"In regression. Thirty-six hours in. Forty-eight scheduled."
"Cut it."
"We are at a soak window where if we ship now we re-introduce the risk we paused for last time."
"I know what window we are at. Cut it. Ship the patch. We are going to have to take the IPv6 hit if it comes back. If we sit on this for twelve more hours we are going to have nine hundred customers calling us at 8 a.m. asking why their networks are owned and the answer is going to be that we had the patch and we held it for testing."
He had known she was going to say it. He had known he was going to agree. He had known he was going to be the one to type the message into the deploy channel that closed the window he had insisted on opening. He knew all of that, and he typed it anyway, and the patch went to canary at 3:11 a.m. and to fleet at 3:38 a.m., and the ninety-seven customers who had auto-update on were patched by 3:52 a.m., and the others would not be patched until their next scheduled maintenance window, which for most of them was the following weekend.
The threat-feed counter was at sixty-three when the patch hit canary. It was at one hundred and forty-one by the time it hit fleet.
At 4:20 a.m., the bridge thinned out. Marcus stayed. The CISO stayed. The director was on his second call. Daniel and Marcus were on the second forensics pass and the bridge had stopped having anything to say.
"Where are you on customer notifications," the CISO asked.
"Drafting," Daniel said. "I want to get the scope right before I send."
"Get the scope right by 6 a.m. I do not want this in the morning news cycle before our customers hear from us."
"Understood."
She hung up.
Marcus stayed quiet for a long minute. Then he said, "We are going to have to talk about the regression policy."
"I know."
"It is not the policy. It was the right policy nine months ago."
"I know."
"It is the timeline. We thought we had — what, four days, sometimes a week. We had the IPv6 incident because we had four days and we used three of them. Tonight we did not have four hours."
"I know."
"What are we going to call the new policy."
Daniel had thought about this exact question while he had been waiting for canary to clear, and he had not had an answer then either.
"I do not know yet. But the policy can no longer be 'we test for a fixed amount of time.' It has to be 'we ship as soon as the patch is verifiably correct on a small enough customer to fail safely, and we test the rest of the fleet against the canary.' Which means we are going to ship things that break things. Which means we are going to write a different kind of incident report. Which means I am going to spend the next six months convincing the CFO that the cost of breaking things on canary is lower than the cost of being one of the firms in the morning news cycle."
"He is not going to like that math."
"He is going to like it less than the alternative."
"Yes. He is."
They sat in the quiet hum of the room for another minute. Daniel could hear his own keyboard, and Marcus's keyboard, and the air handler that ran in the next office over, and nothing else. The threat-feed counter had stopped moving. It had stopped at one hundred and ninety-one. The patch was holding.
"Marcus."
"Yes."
"The sixty seconds you wanted at the start. The trace."
"Yes."
"Was it worth it."
Marcus did not answer right away. Daniel watched him stop typing, push back from his desk a little, look at his ceiling the way Marcus looked at ceilings when he was thinking carefully about something he was about to say.
"It was worth it for that customer. For the others, the patch would have gotten them either way. For that customer, we know what we lost, and we can tell them, and they can rotate the credentials before the attacker uses them, and that is the difference between this being a breach and being a near miss. So yes. It was worth it for the one customer. It cost us about ninety seconds of attacker dwell on two other customers, and those two were segmented, so the cost was zero in actual outcome. So yes. I would do it again."
"Okay," Daniel said. "Okay."
He went back to drafting the customer notification. He worked at it for forty minutes. He sent the first batch at 5:48, twelve minutes ahead of the deadline the CISO had given him. He drank his fourth coffee. He drank his fifth. He did not call his wife. He thought about the regression policy, and he thought about the ten-hour number, and he thought about the morning, when the news cycle would carry some other firm that had not had the threat feed and had not had Marcus and had not had a CISO who knew exactly when to stop a forty-eight-hour test, and he thought about how in approximately three weeks there would be another CVE, and the counter would start again, and his team would be faster this time because tonight had taught them, but the counter would also be faster, because the counter was always faster.
He drafted the regression policy memo at 6:12. He sent it at 6:31. The CFO replied at 7:02, three sentences. The third sentence was the one that mattered: "Schedule the review for Thursday. Bring the cost model. We are not doing this in the news again."
Daniel saved the memo, closed his laptop, and went to wake up his wife and tell her he had worked late. He had not, technically, lied about anything yet. He intended to keep it that way for as long as the counter let him.
The 10-hour bug-to-exploit median referenced in this story is drawn from the April 27, 2026 Black Hat Asia keynote disclosure. Any operational details, names, and procedures herein are fictional.