Breakglass
Incidents
Dashboard · Mercy Valley Community Hospital Simulated hospital Connecting…

What's exposed right now, and what's already closed

Exceptions first: anything still open sits at the top with its exposure clock running.

KEV 1,739 entries · polled 13:37 PDTRecorded
ProblemAttackers use flaws before a fix can be installed; one IT person can't react the same day.
SolutionBreakglass watches the exploited-flaw list, proves each match matters here, and applies one reversible control.
Why it mattersEvery minute a reachable, actively-hit route stays open is exposure a 25-bed hospital can't afford.
How it's usedGlance here; open an incident to see its evidence, the refusal, the decision and the proof.
Open now
0
nothing exposed and unhandled
Contained
6
verified: exposure 0, patient journey passing
Median time to contain
0:41
from ingest to verified close
KEV entries watched
1,739
0 new since start · catalog 2026.10.08

Needs attention

Open incidents, oldest first
Nothing open. Last contained: INC-0015 (CVE-2025-55182) in 1:26.

Recent incidents

All incidents →
IncidentAssetStateClock
INC-0006
CVE-2025-55182
Patient portal✓ CONTAINED0:40
INC-0015
CVE-2025-55182
Patient portal✓ CONTAINED1:26
INC-0012
CVE-2025-55182
Patient portal✓ CONTAINED0:41
INC-0007
CVE-2026-88779
Remote access gateway✓ CONTAINED0:51
INC-0008
CVE-2026-102489
Patient help desk✓ CONTAINED0:33
INC-0011
CVE-2025-55182
Patient portal✓ CONTAINED1:03

The exploited-flaw feed

CISA KEV, newest first
CVE-2023-22894 · added Oct 8, 2026 · due Oct 11, 2026
Strapi Strapi
Not in estate
CVE-2021-3199 · added Oct 8, 2026 · due Oct 11, 2026
ONLYOFFICE Docs
Not in estate
CVE-2016-3081 · added Oct 8, 2026 · due Oct 11, 2026
Apache Struts
Not in estate
CVE-2015-5477 · added Oct 8, 2026 · due Oct 11, 2026
ISC BIND
Not in estate
CVE-2015-3306 · added Oct 8, 2026 · due Oct 11, 2026
ProFTPD ProFTPD
Not in estate
CVE-2026-88779 · added Oct 4, 2026 · due Oct 7, 2026
Citrix NetScaler
CVE-2026-102490 · added Oct 2, 2026 · due Oct 5, 2026
Zammad GmbH Zammad
Matched
CVE-2026-102489 · added Oct 2, 2026 · due Oct 5, 2026
Zammad GmbH Zammad

Polled every 60s; last change at CISA .

Request analytics · ClickHouse

Every query →
Requests stored
3.57M
Ingest / min
250
Last decision query
9.5 ms

INC-0015: one query read 8,207 rows and found the route under attack. 3.5M of the stored rows are replayed public logs (labelled); Measured on the ClickHouse Cloud (recorded); times are ClickHouse's own.

Partners and fallbacks

Settings →
CISA KEV feed
At recording (13:38 PDT): LIVE. 1,739 entries, catalog 2026.10.08, last poll unchanged since the previous poll (HTTP 304)
RECORDED
Guild AI
At recording (13:38 PDT): GUILD SESSION. Agent sessions run in Guild; its credential proxy enforces the policy (local loop on any Guild failure).
RECORDED
OpenAI
At recording (13:38 PDT): gpt-6.1-sol. Responses API, strict tool schemas; every call logged to .data/llm-calls.jsonl.
RECORDED
Semgrep
At recording (13:38 PDT): SEMGREP CE (no account). Semgrep Community Edition runs Breakglass's custom rules over the portal source and the reverse-proxy config, for real, on every incident.
RECORDED
ClickHouse
At recording (13:38 PDT): CLICKHOUSE CLOUD. Every edge request, journeys, verification and the A/B.
RECORDED
MongoDB
At recording (13:38 PDT): ATLAS. Inventory, catalog with outcomes, advisories; change stream on new advisories.
RECORDED
ElevenLabs + Twilio
At recording (13:38 PDT): APPROVAL CALLS OFF. Outbound approval call on a denied action (SMS fallback). Off by default: live calls cost money.
RECORDED