# A-002

- **Artifact ID:** A-002
- **Status:** ACTIVE
- **Public record:** https://record.cybersecurityhq.com/assumptions#A-002
- **Machine-record SHA-256:** `386ff4c1c7d63be4b399ad60b6d19e7ccd45f6cd736b1e612d7a1a96b84804a9`

## Complete structured record

```json
{
  "id": "A-002",
  "statement": "Remediation closes the exposure surface it addresses",
  "status": "ACTIVE",
  "category": "Under Pressure",
  "ledger_references": [
    "2026-06-09 — Azure Durable Task recompromise (source: CHQ-EX-2026-021): The repository at the root of a May 2026 supply chain compromise was the hub of a June 2026 campaign reaching 73 repositories across four organizations. The May incident was treated as remediated. The access established in May persisted through that remediation and was the entry point for the June campaign. The remediation closed the visible credential; it did not close the access relationship.",
    "2026-06-09 — Red Hat namespace pre-positioned credential (source: CHQ-EX-2026-021): A developer account credential was harvested by an infostealer in mid-April 2026 and held in adversarial infrastructure until June, six to seven weeks later, when it was used to compromise packages. The remediation interval (if any) did not correspond to the actual exposure window, which began at harvest and extended until use. The credential persisted across the full interval regardless of any intervening remediation actions.",
    "2026-07-24 — Collaboration server zero-day exploited before patch existed (July 2026): A widely deployed collaboration server had a zero-day confirmed exploited before any patch existed. The remediation control had no material to act on; the exposure window was defined entirely by attacker possession. Remediation was not a viable response — the fix had not yet been authored.",
    "2026-07-24 — SIEM unauthenticated flaw exploited within days of patch (July 2026): A widely deployed SIEM received its first-ever KEV listing through an unauthenticated flaw exploited within days of the patch becoming available. The practical remediation window was measured in days, compressing the assumption's implicit window to near zero for organizations on standard patch cadences.",
    "2026-07-24 — Eighteen-year-old router flaw under active exploitation (July 2026): A router vulnerability from 2008 was confirmed under active exploitation eighteen years post-patch. The remediation was available and applied long ago in maintained environments; confirmed exploitation documents that the fix does not retroactively close the window for assets where remediation was not applied, and that old remediations do not retire the exposure class."
  ],
  "evidence_count": 5,
  "last_updated": "2026-07-24",
  "related_positions": []
}
```
