Wegweiser
All notes

What is being exploited, and where it reaches

The tenant page is rebuilt around what your clients' machines already tell us. The Stack reads your RMM, remote access, endpoint protection, backup, monitoring and VPN tools off every machine and measures each client against your standard. The Security briefing matches the vulnerabilities attackers are exploiting this week against the software on those machines, and says how each one reaches them.

The tenant page used to open with a questionnaire: which RMM do you use, which antivirus, which backup. Almost nobody filled it in, and the analyses built on the answers were no better than the answers. Everything it asked is something the agents already see. So the questionnaire is gone, and the page now reads what the machines say, in chapters, the same way a client page does.

Two of those chapters are new.

The Stack

The Stack reads your tooling off each machine's own inventory: the RMM agent, remote access, endpoint protection, backup, monitoring and VPN. It matches products by their exact names, never by a fragment of one, so a package called ninja-build is not mistaken for NinjaOne. A product it does not know shows as nothing recognised, which is not the same as nothing installed, and the page says so in those words.

For each category it compares every client with your standard. Until you choose one, the standard is the product on the most machines across all your clients, and the page says it is inferred. Choose it once and every client is measured against it, including the one you onboarded yesterday. That matters most on onboarding day: a client that arrives with a previous provider's RMM agent on every machine sees that agent as not yours, never as its norm, and a remote access tool that is not your standard is called out as what it is, a way into a client machine that you may not control.

The Security briefing

The Security briefing reads CISA's Known Exploited Vulnerabilities catalogue: the flaws attackers are using right now, a few a week, each one checked by people before it is listed. It is read every six hours and matched against the software on your clients' machines, by exact name again.

A flaw can reach a machine in four ways, and the briefing says which, because each asks for something different:

  • The software is installed. A Chromium flaw reaches Chrome, Edge, Brave, Opera and Vivaldi, and the card lists the machines and the versions seen on them.
  • The machine runs an agent whose server has the flaw. Remote access and RMM tools are usually exploited at the server, and every machine with the agent answers to that server. If the tool is your standard, the briefing says to patch your server. If it is not, it says what that means: somebody else's server can reach these machines.
  • The machine has the VPN client for an affected firewall. No agent can see a FortiGate or a NetScaler, but a machine with the FortiClient or the NetScaler Gateway's own client installed says the client almost certainly runs one.
  • The flaw is in the operating system. Windows and Linux flaws reach every machine running them, and the fix is the vendor's regular update.

The briefing says where software is installed, never that a machine is vulnerable. Most vendors fix these quickly and many machines update themselves, so the versions seen are there for you to check. CISA's own description is quoted as CISA wrote it. Its advice is too, except where it is written for US federal agencies, where it is shortened to the part that applies to everyone.

Flaws that name something no agent can see, a router or a web application, are listed as exactly that, and so are those that name software we look for and found on none of your machines. Neither is a claim that a client is safe.

When a new entry first reaches one of your clients' machines, you are told once, through your notification channels. Every Monday morning the week's briefing goes to the same channels, including the weeks when nothing reaches you. Both can be subscribed to separately under Settings, Notifications.

The same reading sits on the tenant overview, on each client's page, and in the chat, so "does anything we manage run the software CISA listed this week?" has an answer that matches the page.

One reading passes up

The weekly roll-up that turns device readings into a group, client and tenant view used to need two readings at every level before it would write anything. A client with a single device that had a reading therefore never got one, and neither did the tenant. A single reading is now passed up as it is, marked as the only one so far, and the model is only asked when there is something to put together.

More notes

  1. Website security with nothing to set up

  2. What only goes wrong the first time

  3. Agent release log