Dashboard · Mercy Valley Community Hospital Simulated hospital Connecting…
What's exposed right now, and what's already closed
Exceptions first: anything still open sits at the top with its exposure clock running.
ProblemAttackers use flaws before a fix can be installed; one IT person can't react the same day.
SolutionBreakglass watches the exploited-flaw list, proves each match matters here, and applies one reversible control.
Why it mattersEvery minute a reachable, actively-hit route stays open is exposure a 25-bed hospital can't afford.
How it's usedGlance here; open an incident to see its evidence, the refusal, the decision and the proof.
Open now
0
nothing exposed and unhandled
Contained
6
verified: exposure 0, patient journey passing
Median time to contain
0:41
from ingest to verified close
KEV entries watched
1,739
0 new since start · catalog 2026.10.08
Needs attention
Open incidents, oldest firstNothing open. Last contained: INC-0015 (CVE-2025-55182) in 1:26.
Recent incidents
All incidents →| Incident | Asset | State | Clock |
|---|---|---|---|
| INC-0006 CVE-2025-55182 | Patient portal | ✓ CONTAINED | 0:40 |
| INC-0015 CVE-2025-55182 | Patient portal | ✓ CONTAINED | 1:26 |
| INC-0012 CVE-2025-55182 | Patient portal | ✓ CONTAINED | 0:41 |
| INC-0007 CVE-2026-88779 | Remote access gateway | ✓ CONTAINED | 0:51 |
| INC-0008 CVE-2026-102489 | Patient help desk | ✓ CONTAINED | 0:33 |
| INC-0011 CVE-2025-55182 | Patient portal | ✓ CONTAINED | 1:03 |
The exploited-flaw feed
CISA KEV, newest firstCVE-2023-22894 · added Oct 8, 2026 · due Oct 11, 2026
Not in estate
CVE-2021-3199 · added Oct 8, 2026 · due Oct 11, 2026
Not in estate
CVE-2016-3081 · added Oct 8, 2026 · due Oct 11, 2026
Not in estate
CVE-2015-5477 · added Oct 8, 2026 · due Oct 11, 2026
Not in estate
CVE-2015-3306 · added Oct 8, 2026 · due Oct 11, 2026
Not in estate
CVE-2026-88779 · added Oct 4, 2026 · due Oct 7, 2026
CVE-2026-102490 · added Oct 2, 2026 · due Oct 5, 2026
Matched
CVE-2026-102489 · added Oct 2, 2026 · due Oct 5, 2026
Polled every 60s; last change at CISA .
Request analytics · ClickHouse
Every query →Requests stored
3.57M
Ingest / min
250
Last decision query
9.5 ms
INC-0015: one query read 8,207 rows and found the route under attack. 3.5M of the stored rows are replayed public logs (labelled); Measured on the ClickHouse Cloud (recorded); times are ClickHouse's own.
Partners and fallbacks
Settings →CISA KEV feed
At recording (13:38 PDT): LIVE. 1,739 entries, catalog 2026.10.08, last poll unchanged since the previous poll (HTTP 304)
Guild AI
At recording (13:38 PDT): GUILD SESSION. Agent sessions run in Guild; its credential proxy enforces the policy (local loop on any Guild failure).
OpenAI
At recording (13:38 PDT): gpt-6.1-sol. Responses API, strict tool schemas; every call logged to .data/llm-calls.jsonl.
Semgrep
At recording (13:38 PDT): SEMGREP CE (no account). Semgrep Community Edition runs Breakglass's custom rules over the portal source and the reverse-proxy config, for real, on every incident.
ClickHouse
At recording (13:38 PDT): CLICKHOUSE CLOUD. Every edge request, journeys, verification and the A/B.
MongoDB
At recording (13:38 PDT): ATLAS. Inventory, catalog with outcomes, advisories; change stream on new advisories.
ElevenLabs + Twilio
At recording (13:38 PDT): APPROVAL CALLS OFF. Outbound approval call on a denied action (SMS fallback). Off by default: live calls cost money.