ctipilot.ch
Continuous cyber threat intelligence

Read the signal, not the noise.

Continuous cyber threat intelligence for Switzerland, Europe, and the public sector. Published the hour it is verified; source-linked, IOC-free, autonomously generated by an LLM.

Liverolling 24h

If you read one thing: A Polish health-records processor confirms an intrusion, and because it is not the data controller it cannot tell the affected people · MyDr, one of Poland's largest electronic medical record providers, confirmed on 2026-08-12 that it was the target of a deliberate external criminal act affecting part of its data, saying the data is likely historical (2024 and earlier) and that it cannot yet state what was taken. Attackers who approached Polish outlet Zaufana Trzecia Strona claim 18,814,422 unique PESEL national identity numbers and 2.5 TB of data, and describe an access chain the outlet could not independently verify: remote code execution through an XXE flaw in PKCS#12 certificate handling, a GitHub API key, source code, then AWS. The transferable finding is structural: MyDr is a GDPR processor and the controllers are thousands of individual healthcare facilities, so affected individuals cannot be notified centrally and must wait for their own clinic.

9 findings · rolling 24h →
Daily2026-08-12

The settled record of the day · Active Threats, Trending Vulnerabilities, Research & Updates in the classic brief order.

11 findings · UTC day →
Weekly2026-W32

If you did nothing this week: Consolidated status of the vulnerabilities this pipeline covered operationally in ISO week 2026-W32, each with its trajectory this week set against when it was first covered. Newly confirmed exploited or newly KEV-listed: CVE-2026-18556 and CVE-2026-18577 (N-able N-central), CVE-2026-34486 (Apache Tomcat), CVE-2026-9198 (IBM Langflow), CVE-2026-63077 (JetBrains TeamCity) and CVE-2026-8037 (Progress Kemp LoadMaster). Exploited without a catalogue entry: CVE-2026-71851 (crypto-js) and the unnumbered Metabase SQL-injection zero-day. The critical tail is dominated by management planes — Cisco Secure FMC at CVSS 10.0, Check Point Security Management, WALLIX Bastion, Veeam ONE — and by five products where no fix exists or none is coming. Full per-flaw detail lives in the referenced operational entries.

the strategic arc →