The Patch Notes Nobody Reads
When vendors stop publishing what they fixed, marketers lose one of the few visible signals of vendor trustworthiness they had left.
Two hundred and seventy Zimbra servers are currently compromised in an ongoing campaign, according to BleepingComputer. Somewhere in that number are marketing teams, agencies, and small businesses running their email through a platform they chose partly because it looked well maintained. The problem is that "well maintained" is getting harder to verify, because the thing that used to prove it, the changelog, is going quiet.
The Changelog as a Business Document
Patch notes read like technical trivia, but they have always done a second job. When a vendor tells you exactly what they fixed, they are handing procurement and marketing ops a data point they can actually act on: this company finds problems and admits to them in public. WhatsApp's update this week, adding multiple passkeys and stronger two-step verification, is a clean example. It is specific, it is dated, and it is written for the people who will use it, not just the engineers who shipped it. Anyone deciding whether to trust the platform with client communications now has something concrete to point to.
SecurityWeek ran a piece this week with a headline that says the quiet part out loud: silent patches don't stop attackers, they blind defenders. That's true for security teams staring at logs. It's also true for the marketing and agency side of the business, which almost never gets consulted on vendor risk until something already broke and someone is asking why nobody flagged it sooner.
Two Ways to Handle a Vulnerability This Week
Put the WhatsApp announcement next to the Zimbra story and you get a clean contrast in disclosure styles, playing out in the same news cycle:
- Visible: a named feature, a named improvement, a public writeup that lets customers update their own security posture in response, on their own schedule.
- Invisible: a server platform under active attack, with the scale of compromise (270 servers and counting) surfaced by outside researchers rather than the vendor itself.
Neither approach is unusual by itself. What's changing is how normal the second one is becoming across the vendors marketing teams actually depend on for email, CRM, ad platforms, and creative tooling. Mirage2FA, a phishing kit abusing Microsoft 365 login flows, is reportedly hitting 4,500 companies across the US and EU right now, per The Hacker News. If your team runs campaign files, client decks, or shared calendars through M365, that figure is not background noise. It's your own login screen.
Attackers are also getting creative about where they hide, in ways that make silence even more costly. Researchers described E4del and PINHOLE RATs using FTP banners as dead drops for malware commands, turning a boring piece of server infrastructure into a covert channel. Separately, 24 npm packages were found abusing unpkg mirrors to host fake Cloudflare CAPTCHA pages, borrowing the visual trust of a familiar security prompt to slip past exactly the kind of scrutiny a changelog is supposed to invite.
When the Supplier List Itself Goes Dark
The UK government is now seeking powers to block risky tech suppliers in secret, according to The Record. Set aside the national security argument for a moment and look at the mechanic: a government body decides a vendor is unsafe, and doesn't have to say why, or even that it happened at all. That's the same silent-patch logic applied one level up the supply chain, from a single product to an entire company's eligibility to sell.
A business that unknowingly relies on a blocked supplier finds out not from a notice, but from a service that stops working, or a contract that quietly can't be renewed, or a procurement portal that just stops returning that vendor's listings. Agencies build vendor stacks the same way governments build supplier lists: layer on layer, mostly on trust, rarely audited until something forces the question. If the audit trail disappears at the top of that chain, it disappears for everyone downstream too, and nobody downstream gets a vote on it.
The Vendors Who Talk About Talking
Schneier on Security's rundown of the Black Hat State of Security Vendors made a point worth sitting with: there is now an entire layer of the industry whose job is describing what other security tools do, rather than doing the securing itself. That's not a criticism on its own, translation work has value, but it means the actual signal (what got fixed, what got missed, what got left open on purpose) can get diluted somewhere between the vendor's internal ticket and the marketing copy that describes the fix.
The Hacker News piece on frontier AI and what it called vulnerability management's systemic revolution points at the same tension from the other direction. If AI tools start finding and patching vulnerabilities faster than humans can write them up, the pressure to skip the writeup entirely only grows. Speed and disclosure have always pulled against each other a little. Automating the speed side without a matching push on the disclosure side just tips the balance further toward silence.
Not everything in the trade is heading that way, worth saying plainly. SecurityWeek also reported that hands-on cyber-physical systems training is returning to the ICS Cybersecurity Conference, which is the opposite instinct: get practitioners in a room, physically working through a failure, rather than reading a summary of one after the fact. It's a small data point, but it says the industry still knows the value of showing your work when it wants to.
What Changes for the People Who Buy the Tools, Not the People Who Build Them
None of this requires a security background to act on. It requires treating disclosure itself as a vendor selection criterion, not an IT afterthought bolted onto a renewal call:
- Ask vendors directly whether they publish patch notes, and how often. A vague answer is itself information worth writing down.
- Treat "we handled it internally, no need to worry" as a yellow flag rather than a reassurance, especially from any platform holding client data or campaign assets.
- Keep an eye on attack surfaces that don't look marketing-adjacent until they suddenly are. SecurityWeek reported the first malware built specifically for car head units, feeding a botnet, this week. Nobody budgeted for that risk last quarter, and it's exactly the kind of thing that only becomes visible through outside reporting rather than a vendor notice.
- Remember that availability is a marketing metric too. A large DDoS attack knocked Norwegian public services offline this week, per The Record; the same tactic against a hosting provider or a campaign landing page reads, from the outside, like a failed launch rather than an attack, and gets treated that way in the post-mortem.
Police did arrest dozens of suspects in a global cybercrime crackdown this week, according to BleepingComputer, which is a reminder that enforcement still works when the activity in question is visible enough to build a case around. The Zimbra campaign and the UK's proposed secret veto point in the opposite direction, toward outcomes decided quietly, discovered late, and explained never. For anyone buying tools rather than building them, that's the whole risk worth tracking, and it starts with the simple question of whether a vendor still bothers to tell you what they fixed.