we_are_coded.by CODE · The world, decoded
БГ
Basic

Who protects you

The BasicsUpdated on 16 August 2026we are coded

Every time you read "the company patched a critical vulnerability," it sounds like an admission of failure. The opposite is true. It's proof that somebody is actually watching the door. Below I explain exactly who guards it, what the hole is called before it gets plugged, and why a patch story is the good news, not the bad one.

Checked on16 August 2026
In short: every program is written by people, and people make mistakes. The mistake sometimes opens a small door that someone can walk through without permission. That door gets a registration number, as if it were issued a birth certificate, so everyone can talk about the same thing. If someone is already walking through that door to steal, a US agency puts it on a list marked "urgent". Most breaches don't happen because the hacker is a genius. They happen because someone didn't shut a door that had long been known not to lock.

The opposite of failure is true here. A patch means somebody was actually watching the door. Below I explain exactly who guards it, what the hole is called before it gets plugged, and why a patch story is the good news, not the bad one.

The hole has a name before it gets plugged

Picture a building with a new front door: the locksmith mounts the lock, but assembles it crooked. From outside it looks locked, but with the right push the door opens without a key. Nobody did it on purpose, it just happened that way during installation. In software it's the same: the program is written fast, by many people, and somewhere a gap remains, one an uninvited guest can slip through. That gap is called a vulnerability. It isn't a virus, and it isn't an attack by itself, just an oversight waiting for someone to find it.

Once someone finds it, the world needs a shared language for it. So every such hole gets a number, as if it were issued a national ID. The system is called CVE, short for an English phrase that roughly means "known breaches in systems". It's international, and mostly kept in the United States. Thanks to it, when your antivirus company says "we closed the issue" and another system's vendor says "so did we", everyone is sure they're talking about the same hole, not something described in different words.

There's a worse version too: a hole already in use before a patch for it even exists. In the trade it's called a zero-day, because defenders don't have a single day left to prepare. It's like the caretaker finding the warehouse door open and empty, and only then realizing the lock had been broken for a while. There was never a moment when he could have fixed it beforehand.

Who sounds the alarm

In the United States there's an agency that doesn't write software and doesn't sell anything. It tracks which holes in the real world are already being used to break in, not which theoretically could be. It's called CISA, short for the American Cybersecurity and Infrastructure Security Agency. Its job is like a caretaker who walks the buildings across the whole neighborhood: doesn't build the building or install the locks, but checks which ones have already been broken into, so the owners know where to put a bolt first.

The list it keeps is called KEV, which comes from "known exploited vulnerabilities". The difference from an ordinary registry of holes matters. An ordinary registry says "here's a gap, theoretically dangerous". KEV says "people are going through this gap right now and stealing". The second is a priority. The first is for later.

Vulnerabilities aren't surprises. They're locks everyone has long known creak, but nobody hurries to change until the thief shows up at the door.

Why most breaches aren't the work of geniuses

When you hear about a hacked site or a leaked database, the image is a hoodie-wearing hacker cracking impossible code in a dark room. In most real cases the truth is duller and more unpleasant. Someone knew about the hole for months. A patch shipped. Nobody installed it. Like knowing the warehouse padlock has been broken for a month, having a new padlock in the drawer, and just never finding the half hour to swap it. The thief wasn't a genius. He just walked past the open door while looking for the next one.

Why the patch is the good news

Security isn't a state you reach once and finish. It's more like maintaining a building: the roof gets checked every year, because we know it will leak sooner or later, not because it's already caved in. Nobody thinks it's a scandal that the caretaker changes a padlock. The alarming thing is the opposite: a building where nobody touches anything for twenty years, because either nobody's watching, or something's being hidden.

So when you read that some company patched a vulnerability, it means someone there is working, watching the lists, reading what the agency across the way publishes, and doing the maintenance. Silence is the worse signal, not the patch.

What's new

I no longer ask "did the company get hacked". I ask "how long did they know, and how slowly did they react". The difference between the two questions is the difference between bad luck and bad maintenance. I forgive the first. Not the second.

The visual is generated code art. No third-party images.
Official primary sources
→CISA: the KEV catalog (Known Exploited Vulnerabilities)→CVE Program: about the program (MITRE)

Down, to the specifics

the finer detail
Who's who

CISA

CISA is the US agency that keeps an official list of software holes with proof that someone is already using them to att...

Concept

Zero-day

A hole the vendor itself doesn't even know about yet - which is exactly why it's the most dangerous kind. Zero days mean...

Concept

CVSS

CVSS gives every hole in software a number from 0 to 10 - but the ten is for the potential, not for whether anyone is at...

Concept

CVE

The number every discovered hole in software gets, so the whole world can talk about the same thing - from the researche...

Concept

The European AI Act

The first major law in the world that tells artificial intelligence what it's not allowed to do. It applies to anyone se...

Concept

How the system knows it's you

Authentication is the moment a system asks you "are you really you" and demands proof. Here's exactly what happens then.

Concept

Bypassing the check

An attacker rarely cracks a password. They just find the door nobody realized was a door at all.

Concept

DDoS (flooding)

A crowd blocking a shop's entrance. It steals nothing - it just doesn't let anyone else in.

Concept

Ransomware

The thief who changes the lock on your home while you're out. Then leaves you a note on the door.

Concept

Patch (update)

Once a patch ships, the hole isn't secret anymore. It's an announcement.

Concept

Europe's cyber and AI rules

Five acronyms, one logic behind them: Europe checks the product before it reaches you - it doesn't judge it afterward.

Concept

Memory bugs

Behind most "critical vulnerability discovered" headlines sits the same old trick - as old as software itself.

Concept

Attacks by name (path traversal, symlink, social engineering)

Three attacks where nobody breaks anything - they just walk through a door someone left unlocked.

Concept

VPN, air-gap, and how a network is guarded

The tunnel, the moat, and the bridge - three ways to guard what shouldn't be reached from outside.

Concept

WAF (web application firewall)

A WAF is a filter in front of the site - it watches incoming requests and stops the harmful ones before they reach the a...

Who's who

ECH (the hidden site name)

Even over HTTPS, the name of the site you open travels in the open. ECH hides it.

Who's who

Zero Trust

The rule that the internal network is not safe by itself. Every request is checked as if it came from outside.

Concept

DNS and DNSSEC (the internet's directory and the seal on it)

Every time you type a name into the browser, someone has to tell you exactly which computer to knock on. That simple ser...

Who's who

Code signing

The wax seal of software. It proves the program comes from who it claims to, and that nobody touched it on the way.

Concept

Supply-chain attack

They don't break your door. They break the door of whoever sells you the lock. That's why one poisoned package can reach...