What We're Watching
Three incidents that show how quickly attackers can turn trusted systems against their users.
Attack probes arrived 10 minutes after an OCaml fix became public
Ten minutes after an OCaml cohttp path-traversal fix became public, the maintainer saw matching probes; separately, an AI agent found related weaknesses and built an exploit in under a minute.
Attackers hijacked internet routes to deliver a malicious Virtualizor update
In a BGP hijack, attackers redirected Virtualizor traffic and used a valid certificate, allowing some customers to download a malicious update without seeing a warning.
A fully patched N-central server was compromised as new zero-days emerged
After a fully patched N-able N-central production server was compromised, Huntress reproduced a new authentication-bypass chain. N-able then disclosed a separate, actively exploited pre-authentication RCE rated CVSS 10.0.
Our Take
These stories show how attackers can turn trusted systems into shortcuts. The OCaml case shows that publishing a fix can also reveal the weakness, giving attackers a head start. The Virtualizor incident shows that redirected internet traffic and a valid-looking certificate can make a malicious update appear legitimate. The N-able N-central compromise shows how one remote-management console can expose every computer it controls.
Teams need protection across the full path software takes, from published fixes to downloads and administrative access. That means knowing where vulnerable components are running, verifying updates before installation, watching for unexpected routing or certificate changes, limiting access to remote-management tools, and keeping enough history to investigate suspicious activity.
After deploying a fix, teams should test the original attack path again. Clear evidence that the weakness is no longer reachable and that no unauthorized access remains provides confidence that the remediation worked.
Updates from Casco
Casco for Government is now listed on the FedRAMP Marketplace.
FedRAMPCasco is now listed on the FedRAMP Marketplace.
Federal agencies were not part of Casco's original roadmap. That changed when government security teams began asking for continuous testing that could keep pace with growing software and AI-assisted attackers.
Casco for Government is now listed on the FedRAMP Marketplace. Based on a review of the Marketplace's public listings on August 31, Casco is the first standalone listing for an agentic offensive-security platform. This is the first step toward FedRAMP 20x Class C certification.
FedRAMP 20x emphasizes continuous, machine-readable evidence and evaluates whether vulnerabilities are reachable and likely to be exploited. That fits how Casco already tests: reproduce real attack paths, show their impact, and replay them to verify the fix.
Read the full announcement
A practical next step
Seeing this with open vulnerabilities?
See how Casco continuously verifies the attack paths that matter in your application.
Casconaut Highlight
One small recommendation from the people behind Casco.

This issue's Casconaut
René Brandel
Cofounder and CEO
Currently recommending
Can Do Writing
I recommend Can Do Writing by Daniel and Judith Graham. It gives you a practical ten-step system for making business and technical writing faster, clearer, and more useful.
I especially like it for complicated subjects: the reader should not have to work hard to understand what you mean.