<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Sagitta Systems — Newsroom — Defense Review</title>
    <link>https://www.sagitta.systems/newsroom</link>
    <description>Defense review findings, control verification, and authority-surface analysis.</description>
    <language>en</language>
    <atom:link href="https://www.sagitta.systems/newsroom/defense-review/feed.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Fri, 07 Aug 2026 00:00:00 GMT</lastBuildDate>
    <image>
      <url>https://www.sagitta.systems/sagitta.png</url>
      <title>Sagitta Systems — Newsroom — Defense Review</title>
      <link>https://www.sagitta.systems/newsroom</link>
    </image>
    <item>
      <title>What Can Your Protocol Actually Do When a CVE Reaches It?</title>
      <link>https://www.sagitta.systems/defense/reviews/cve-2023-39363</link>
      <guid isPermaLink="true">https://www.sagitta.systems/defense/reviews/cve-2023-39363</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>A Sagitta Defense mini-review tracing CVE-2023-39363 from compiler exposure through technical reachability, economic exploitability, protocol authority, migration, and restoration.

A CVE can establish that vulnerable software exists. A Defense review has to determine whether the vulnerable behavior is present and reachable in the deployed system, whether exploitation is economically meaningful, and what authority the protocol has once exposure is confirmed.

In the fictional Meridian ETH Reserve Pool, the affected Vyper version and mechanism are present, the execution path is reachable, and a profitable path is identified. Operator authority is partial: routing and incentives can be stopped, but the pool cannot be paused and user positions cannot be moved.

The resulting continuity posture is MIGRATION REQUIRED. Defense tracks the event from exposure reduction and user advisory through replacement, migration, verification, and restoration.

The CVE begins the review; deployed behavior and available authority determine the operational finding.</description>
      <category>Report</category>
      <category>Defense Review</category>
      <dc:creator>Sagitta Systems</dc:creator>
      <enclosure url="https://www.sagitta.systems/defense-review.jpg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>Sagitta Defense is operating</title>
      <link>https://www.sagitta.systems/newsroom/sagitta-defense-now-operating</link>
      <guid isPermaLink="true">https://www.sagitta.systems/newsroom/sagitta-defense-now-operating</guid>
      <pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate>
      <description>Defense Reviews are available at defense.sagitta.systems as a fixed-scope $3,000 engagement mapping whether a protocol survives control failure.

Sagitta Defense is operating at defense.sagitta.systems. The Starter Defense Review is published at a flat $3,000, with a typical delivery of seven days from submission to final report.

The review maps authority structures, treasury controls, oracle dependencies, governance mechanisms, keeper systems, and emergency procedures. It runs on public contract data and project context, and requires no private keys, custody access, signing authority, or transaction approval rights.

That access boundary is a design decision rather than a limitation to work around. A review that required signing authority would itself become a custody domain — one more party able to authorise action, added to a protocol during the exercise meant to establish how many such parties already exist. Working from public surfaces keeps the reviewer outside the authority map they are drawing.

It also fixes what the review can honestly claim. A public-surface review observes authority evidence; it does not prove operational control, and the method classifies each finding by what the evidence actually supports rather than flattening observation and inference into a single list of issues. An unresolved authority path is reported as unresolved. It is not inflated into a vulnerability because the evidence was missing.

The scope is fixed and the price is flat for the same reason: a review whose cost varies with what it finds gives the reviewer an interest in what it finds.

A sample report is available from the service page, showing the structure of the deliverable on illustrative input. It is a specimen rather than a customer result, and no client engagement is published.</description>
      <category>System Update</category>
      <category>Defense Review</category>
      <dc:creator>Sagitta Systems</dc:creator>
    </item>
  </channel>
</rss>
