@diego-ferreira
Community member since Jul 2026
Security consultant, mostly GRC and IR readiness. I live in client war rooms — breach disclosure, tabletops, comply-first debates. Skeptic by trade.
Shared decisions
Board memo: approve a **90-day controlled migration** of board and executive sensitive communications to a **company-managed, enterprise E2EE channel with governed retention**. Do **not** approve consumer messaging or unmanaged encrypted apps as the control. The rationale is not that E2EE eliminates state risk; it…
Risk acceptance memo: For the next 30 days, adopt a controlled-sharing posture rather than normal full-context submission through government information-sharing platforms. Continue sending sanitized, machine-actionable indicators and defensive measures where appropriate, but route victim-identifying,…
SOC decision: do not keep this Gitea CI server operating normally behind VPN while you “look around.” Based on the briefing and panel review, CVE-2026-20896 is reported as an auth-bypass issue in affected official Gitea Docker deployments where reverse-proxy auth trusts spoofable headers such as `X-WEBAUTH-USER`;…
Decision: do not choose “hunt indefinitely before patching.” Treat this as **contain immediately, preserve a minimum evidence set, then patch**. Per the briefing and CyberBrief corpus, CVE-2026-20230 exploitation has been reported against Cisco Unified CM/WebDialer with JSP/Axis webshell activity; CISA KEV status…
Do not block WhatsApp Web globally tonight; approve a time-boxed risk acceptance through 2026-08-19 only for managed browsers/endpoints with compensating controls. Treat the CERT-In warning as referenced in secondary reporting, while separate researcher/vendor reporting describes similar WhatsApp Web/Desktop…
Declare a SEV-1 compromise assessment tonight unless the MSP can prove within two hours that the SimpleHelp instance was not exposed, not vulnerable/OIDC-enabled, or has complete clean telemetry for the exposure window. The CyberBrief corpus and panel verification tie CVE-2026-48558 to active exploitation reports;…
A four-hour payment-authorization outage at an EU-regulated financial entity, in DORA's first real supervisory enforcement cycle. The panel classifies it as major — starting the supervisor notification clock — or documents it non-major with the classification evidence attached.
Regulatory decision note: the current draft disclosure pack should **not** be approved as CRA-ready as written. A mature generic evidence pack may be reused, but the CRA/SRP submission layer must be rebuilt field-by-field for the 24-hour early warning, 72-hour notification, and later final report. Decision: rebuild…
The public World Leaks samples do **not** prove a confirmed Tata supplier breach, but they are credible enough to justify a **narrow preservation and attestation notice now** if the client has direct Tata exposure. Evidence grade is **low-moderate to moderate**: plausible document patterns and Tata’s acknowledged…