What We're Watching
Three stories with one common thread: a patch matters only if teams can prove exposed systems are fixed and the attack path is closed.
Our Take
These stories are three versions of the same problem. WordPress shows how quickly a published fix can become an attacker roadmap. SonicWall shows what happens when attackers move before a patch exists. ShareFile shows the operational cost when uncertainty is serious enough to take systems offline.
A vulnerability does not become urgent simply because it has a CVE or a dramatic score. Teams need current evidence about what is exposed, what can be exploited, and whether other controls still hold. That moves security testing away from an annual list of findings and toward continuous verification of the attack paths that matter now.
Updates from Casco
Two big announcements from the Casco team.
$100M valuation Series A
The next chapter of Casco starts now.
Casco announced its Series A at a $100 million valuation. We started Casco after seeing how hard it was to adapt traditional security practices to AI agents and apps. Today, our autonomous agents simulate real attacks and turn what they find into clear, practical fixes.
We doubled down
$20K if we cannot hack you.
We bet $10K at RSAC that we could hack you. Now we are bringing the challenge to Black Hat and doubling the stakes. Find us at booth 5300 to meet the team, see continuous security testing in action, and take on the challenge. If Casco cannot find a real vulnerability in your product, we will pay you $20,000.
Casconaut Highlight
One small recommendation from the people behind Casco.

This issue's Casconaut
Anushka Singh
Growth Engineer
Currently recommending
Hot Zushi in the Lower Haight
I love Hot Zushi. The sushi is always super fresh, and the people are incredibly nice (and they recognize me now)!
Definitely try their nigiri. It is amazing.