Risky Business · Friday, August 14, 2026
Patrick Gray asserts that organizations running services like Citrix or using firewalls from Fortinet and Palo Alto on the internet edge cannot outrun attackers by relying solely on patching. He suggests that a mitigation like Knockknock is necessary to extend the usable life of these assets by hiding them and reducing attack surface.
“So stuff like if you're running stuff like Citrix, if you're running Fortinet on the edge. You are not going to be able to outrun attackers with patching, right? That is just not going to happen.”
“So you've got a couple of options. You can apply a mitigation like Knockknock, which is going to extend the life you get out of that stuff. But there you options. Patching, it ain't going to do it.”
“So again, patching isn't going to work.”