CISA BOD 26-02, EOS, and runZero

|
Updated

Hey internet! Back in early February, we told you about CISA's new BOD 26-02 on end-of-support (EOS) devices on federal networks – specifically, edge devices, like firewalls, VPNs, routers, switches, proxies, all that. You know, the first (and often last) line of defense you have standing between the world's criminal masterminds and super-spies, which really, really should be getting regular care and feeding.

At first, we were all very excited about this BOD. It reads a whole lot like BOD 22-01, which is the binding operational directive that spawned the KEV, which is one of the most useful, free-to-use vulnerability intelligence resources the US Government has ever produced (of course, only if you use it correctly).

Alas, CISA has decided to make their list of identified EOL edge devices private, rather than blasting it out to the world. This is a real bummer, but it really does highlight how special the CISA KEV really is. As a former federal employee, I am here to tell you that when it comes to civilian government (and most other large enterprises), the default stance is to keep your mouth shut. Even in the best of times, cybersecurity people are often stingy with any scrap of intelligence, lest you accidentally inform the enemy on what's up with your infrastructure, and the federal government, doubly so.

I do expect that the list that CISA is compelled to produce in the BOD will get out regardless, since they've already committed to share it privately with state, local, tribal, and territorial governments (SLTT) and critical infrastructure providers (CI), but it won't be published in a formal or referenceable (or remixable or collidable) as the KEV.

Find EOL/EOS devices with one simple query #

But in the meantime, we wanted to let runZero customers know how you can approximate the spirit, if not the letter, of what BOD 26-02 is after. It comes down to a fairly straightforward asset query:

os_eol_extended:<=now AND has_public:t AND NOT (type:Server OR type:Desktop OR type:Laptop)

What this does is go over your already-collected inventory and looks for those devices that are a) in "EOL Extended" state, which is runZero's tag for those devices that are so end-of-life/end-of-service they will never see another security fix, b) exposed to the internet, and c) isn't a normal server, desktop or laptop.

Now, excluding (c) there is a little bit dubious – you probably also don't want EOS stuff that people are actually using to type email and surf the web, all naked and exposed to the wild and woolly internet – but this gets you to a place where you can seek out all those "devices" discussed on BOD 26-02, like so:

(This is a particularly dirty network, and yours is certainly not this awful, but you get the idea.)

At any rate, we'll be fiddling with this over the next couple of weeks, and have a pretty self-contained single push-button thing to get you ahead of any BOD 26-02 worries, much like how we do with Section 889 compliance. And if you don't already know about Section 889… the feds certainly do, so you probably should too.

Try runZero now!

Written by todb

Tod Beardsley is VP of Security Research at runZero, where he "kicks assets and fakes frames." Prior to 2025, he was the Section Chief for the Vulnerability Response section for CSD/VM/VRC at CISA, the Cybersecurity and Infrastructure Security Agency, part of the US government, and a seasonal Travis County Election Judge in Texas. He's also a founder and CNA point of contact for AHA!. Tod spends much of his time involved in vulnerability research and coordinated vulnerability disclosure (CVD). He has over 30 years of hands-on security experience, stretching from in-band telephony switching to modern ICS/OT implementations. He has held IT ops, security, software engineering, and management positions in large organizations such as the US Government, Rapid7, 3Com, Dell, and Westinghouse, as both an offensive and defensive practitioner. Tod is a CVE Board member, has authored several research papers, and is an internationally-tolerated horror fiction expert.

More about todb

Written by Colin Dupreay

Colin is a Federal Solutions Engineer at runZero. With almost a decade of experience supporting Public Sector customers, Colin is passionate about protecting and securing our nations networks.

More about Colin Dupreay

Written by Matthew Kienow

Matthew Kienow is a software engineer and security researcher. Matthew previously worked on the Recog recognition framework, AttackerKB as well as Metasploit's MSF 5 APIs. He has also designed, built, and successfully deployed many secure software solutions; however, often he enjoys breaking them instead. He has presented his research at various security conferences including DerbyCon, Hack In Paris, and CarolinaCon. His research has been cited by CSO, Threatpost and SC Magazine.

More about Matthew Kienow
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
Announcing runZero 4.9: Unmask attack paths and segmentation gaps with advanced topology and deep OT device intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
Webcasts
runZero Hour, Ep. 30: Segmentation - stop assuming & start verifying with runZero 4.9
See runZero 4.9 in action! Join HD Moore and Tod Beardsley to learn how interactive attack path mapping and advanced OT intelligence expose hidden...
Product Videos
runZero 4.9: Advanced topology, attack path mapping, & deep OT intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
runZero Hour, Ep. 31: The New Rules of Risk: EPSS v5 and Agentic Adversaries
In this episode, learn how your security team can use EPSS v5 to inform daily risk decisions in a world increasingly targeted by the apex agentic...
Webcasts
Beyond the Zero-Day: Mapping the network attackers actually see
Breaches are inevitable. Learn from HD Moore how attackers exploit the seams between IT, IoT, and OT networks — and how to fix the segmentation...
Podcasts
Risky Biz Interview: Navigating the AI vibe shift with HD Moore
runZero Founder and CEO HD Moore drops by in this week's Risky Biz sponsor interview to talk about the concerning AI vibe shift and what to do...
Podcasts
From two weeks to three days: The KEV deadline debate
Former CISA insider Todd Beardsley joins Greg to reveal what it takes to land on the KEV catalog and why ultra-short patching deadlines might...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.