Home › Blog

No Customer Action Is Required

NINJASIGNAL MIC DROPS Hey, my graph is full of TI intel you wont get anywhere else :-)

On Wednesday, five agencies of the United States government told you that the cost of attacking a water treatment plant has collapsed.

On Thursday, Microsoft told you that the identity layer underneath your entire organisation had been remotely code-executable by an unauthenticated stranger, that somebody had already used it, and that you would not be told anything further.

These are the same story. Nobody is filing them that way.


Wednesday

Advisory AA26-231A. NSA, CISA, FBI, Department of Energy, Environmental Protection Agency. Five badges on one document, which is not something that happens because someone had a spare afternoon.

The finding: threat actors are using AI to write exploitation scripts against internet-exposed Siemens S7 Series programmable logic controllers. Not proof-of-concept. Not a tabletop. The advisory's own phrasing is that this is not theoretical — it is an active threat.

The method is almost insultingly cheap. Open-source industrial automation libraries — snap7.dll, python-snap7 — bolted to an AI coding assistant. Output: custom tools that impersonate legitimate OT monitoring software and hold read/write access to PLC memory, configuration data and ladder logic over S7comm. Target acquisition via public internet scanning services. Port 102. Devices running out-of-service firmware, or default credentials, or both.

Named sectors: critical manufacturing, energy, water and wastewater, chemical, food and agriculture, commercial facilities.

That is the list of things that have to keep working for a country to remain a country.

The agencies add a line that most coverage skipped. The Siemens content is one subset of a wider landscape. All PLC operators should apply the mitigations. Translation: we picked a vendor to name because naming a vendor generates action, and the actual scope is every controller you own.

The capability that used to require a specialist, a lab, a copy of the hardware and eighteen months now requires a laptop and a subscription.

Thursday

CVE-2026-69836. Microsoft Entra ID. CVSS 10.0.

Deserialization of untrusted data. Unauthenticated. No user interaction. Remote code execution against the service that authenticates your staff into Microsoft 365, into Azure, and into whichever forty-odd SaaS platforms you federated in 2022 and have not audited since.

Exploited in the wild. Confirmed. Before disclosure.

And then the sentence. Fully mitigated. No customer action is required.

Read that again with a security architect's eyes rather than a communications team's.

No indicators of compromise. No description of observed attacker activity. No timeline for when exploitation began, or whether it stopped. No affected components. No attack prerequisites. No detail on how it was discovered.

There is nothing for you to patch, because there is nothing you own. There is also nothing for you to hunt, because you have been issued no signature to hunt with.

Every CISO who reads that advisory now has a board question they cannot answer: were we in scope?

The honest answer is: I don't know, I can't know, and I am not permitted to find out.

The convergence

Put the two documents side by side.

Attack cost is falling. Defender visibility is being withdrawn.

Not lost. Not degraded. Withdrawn — as a deliberate service posture, by the vendors, and described as reassurance.

For thirty years the industry sold a bargain: give up ownership, gain expertise. You do not need to run identity, we run identity, and we run it better than you ever could. Which was true. It was and remains operationally true.

What was never priced into that bargain is that when the thing goes wrong, you do not get told. You are not the customer of the incident. You are the environment the incident happened in.

You did not lose the ability to defend yourself. You lost the ability to know. Those are different failures and only one of them appears on a risk register.

Meanwhile the other side has been handed a productivity tool. The asymmetry everyone keeps attributing to AI is not really about AI. AI just made the exploit cheap. The asymmetry is that one party to this arrangement gets full telemetry and the other party gets a status page.

The Institute of Things That Are Probably Fine issues a statement

Niko took the call. Niko is very good on calls. Niko explained that the platform is a managed service, that managed means the provider manages it, and that this is precisely the value proposition. Someone asked what "fully mitigated" covers. Niko said it covers the vulnerability. Someone asked whether it covers anything an attacker did before the mitigation. Niko said that was a great question and moved to the next slide. Niko is the mouth. Niko has never been the brain.

Maureen received the advisory at 09:14. Maureen located the relevant line on the risk register — Cloud Identity Provider — Third Party Assurance — read the words "no customer action required," marked it green, and went to lunch. Maureen has done nothing wrong. Maureen has done exactly what the process instructed her to do. The process is the defect.

Martin approved the internet-facing exception on the S7 estate. The audit trail is immaculate. Date, justification, secondary sign-off, review scheduled for a quarter that has since occurred twice. Martin has never worked here. Nobody has been able to establish that Martin has ever worked anywhere. The exception remains live because rescinding it would require finding Martin.

Dave clicked the link. Dave always clicks the link. Dave is not the problem in this story and it is important to say so, because for twenty years we have built an entire industry on the premise that Dave is the problem, and this week neither the PLC nor the identity plane required Dave's participation at all.

Kev left in March. Kev is in Portugal. Kev has a boat.


What this actually costs you

Nothing, on Friday. That is the design.

The bill arrives the day you need to reconstruct what happened, and discover that the reconstruction is not yours to perform. Your logs stop at the tenant boundary. The interesting part happened on the other side of it. Your incident response plan has a step that reads "engage vendor," and the vendor has already published the conclusion.

Two documents this week. One says the attacker's job got easier. The other says your visibility into whether that mattered is now a vendor discretion.

Both are correct. Both are public. Neither is a surprise.

The controller was on the internet because someone made a decision. The identity plane was a black box because someone made a decision. Nobody hacked the decisions.

No customer action is required.

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing