Severity Daily

IT and AI security incidents, checked against the primary source

Corrections

Severity Daily corrects errors in public, on the record, and with a timestamp.

When we publish something wrong, three things happen:

  1. The original story is updated with a dated note at the point of the error, stating what it said before and what changed. Nothing is quietly edited.
  2. The correction is logged on this page.
  3. If the error went out on X, the correction goes out on X as a reply to the original post, not as a deletion.

A correction is not an update. A correction means we published something that was wrong. An update means the story moved — a patch shipped, a victim count was confirmed, an attribution was substantiated. Updates are noted on the story itself but do not appear here.

Log

28 August 2026, 4:03 p.m. Central“A 2023 ownCloud auth bypass is on a three-day federal clock ending Sunday, and the evidence is the attacker’s own open directory”, published the same day at 3:56 p.m. Central. The error was found in the same check that published the story.

What we published: that the KEV entry’s citation of CISA’s “Forensics Triage Requirements” indicated CVE-2023-49105 sits in BOD 26-04’s three-day-plus-forensic-triage band, and that for FCEB agencies “the triage is not optional.”

What is correct: the citation is boilerplate and carries no information about the band. The identical required-action string appears on entries CISA added in the same 26–27 August window with 14-day due dates — CVE-2021-23758 and CVE-2022-0995, both due 9 September — as on the three-day entries. Nothing in the catalog record discloses whether a given asset owes a forensic triage.

What is unaffected: the 30 August due date, the affected version range, and the exploitation reporting. The underlying finding is reported separately.

Report an error

Send the URL and what you believe is wrong to webmaster@severitydaily.com. Every report is checked and answered, whether or not it results in a change.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *