Verification & coverage notes
Intraday fire — 5 h gap to the previous run (the 2026-07-19T2310Z-weekly), 24 h window (hard floor). The prior 24 h were already worked by the 2026-07-19T0408Z-intel run, the 2026-07-19T1308Z-audit, and the W29 weekly, so the genuinely-new slice was small and most of the landscape was already covered; dedup carried the load. Two entries published from three real candidates; the national-CERT/government and incident/breach source layers were genuinely quiet (weekend), with S2 and S4 returning honest empties after thorough sweeps.
Published
2026-07-20/cve-2026-42533-nginx-pcre-capture-clobber-preauth-rce — deep dive (category network-stack-rce). New in-window pre-auth heap overflow in nginx / NGINX Plus's script engine, patched out-of-band by F5 on 2026-07-15/16; the credited discoverer disputes F5's DoS-only framing and demonstrates a reliable pre-auth RCE (single-GET ASLR defeat + control-flow hijack). Clears the vulnerability gate on the out-of-band-patch / pre-auth-RCE-on-exposed-edge criterion (action beyond the regular patch cycle) despite no public exploit PoC (author withholding ~21 days) and no in-the-wild exploitation yet. Priority high, not critical — no public PoC, no verified scanning, not in KEV. CVE id, CVSS (4.0 9.2 / 3.1 8.1), affected/fixed versions and CWE-122 verified against the F5-sourced NVD record; F5's own advisory page (K000162097) is JS-gated and not directly citable, so cited via SecurityWeek + the credited researcher. Deep dive earned on the "substantive new technical analysis, actionable" criterion — the two-pass capture-clobber mechanism, the specific vulnerable config pattern, and the scan-before-patch exposure-enumeration workflow give a skilled responder something to act on.2026-07-20/uac-0145-sandworm-clickfix-etherhiding-android-backdoor — threat, notable. CERT-UA's disclosure of Sandworm subcluster UAC-0145 pairing ClickFix fake-CAPTCHA drive-by with on-chain C2 resolution (EtherHiding via a bespoke SMARTAXE injector) and a Signal-delivered Android backdoor (COWARDDUCK). Primary targeting is Ukraine, so it clears the gate on the same-actor read (Sandworm/GRU is a standing threat to European CI + government) plus transferable TTPs — framed around the technique stack, not the victims. New entity actor:uac-0145 registered with a related-to relation to actor:sandworm — the typed relationship vocabulary has no actor→actor subcluster edge, so related-to records CERT-UA's stated subcluster hierarchy (captured in the edge's note) without overclaiming a specialized type.
Single-source / carve-outs
- The UAC-0145 entry is
single-source-national-cert: CERT-UA is the primary disclosing authority for its own jurisdiction; The Hacker News (2026-07-19) corroborates in English but derives its facts from the same CERT-UA advisory, so it is effectively single-origin. Noted in the entry's sourcing_note. CERT-UA's page carries a Published Time metadata artefact (2026-03-10) contradicting its own June–July 2026 activity dates — treated as a site artefact, freshness anchored to the 2026-07-19 disclosure.
Borderline drops (recoverable)
- borderline-drop: SANS ISC Hikvision ISAPI
/ISAPI/System/status reconnaissance scanning (S3) — single-source (SANS ISC handler diary, reliability B), reconnaissance-only with no confirmed exploitation, a narrow product footprint, and the only action it implies (don't expose camera management interfaces to the internet; use HTTPS + non-Basic auth) is standing hygiene rather than a task derived from this observation. Fails the actionability bar. Recover if exploitation of the endpoint (post-recon credential brute-forcing or a specific CVE) is confirmed. - borderline-drop: Abbott LabCentral / ShadowByt3$ second incident (S4) — the in-window source is a verbatim recap of 2026-07-17 reporting; no fresh delta to anchor an update, and the ShinyHunters half is already covered (2026-07-18 Abbott entry).
- borderline-drop: assorted out-of-nexus / stale S4 leads — River Financial Corp 8-K/A (out-of-nexus US community bank), Clover Health 8-K (out-of-nexus US health insurer, routine ATO), Coca-Cola/fairlife ransomware (out-of-nexus US food manufacturing, no fresh delta), ViPNet "HelloNet" repackaging (already covered 2026-07-17), Bluebell Group leak-site claim (unconfirmed, no nexus). All logged with reasons in findings.S4.yaml.
Coverage gaps: trellix (JS-SPA shell, no listing content recoverable — flag for a structured-endpoint recipe), huntress (partial/cached listing, latest dated item outside window), securelist (landing-nav only, no per-article dates; visible titles already covered), cert-eu (curated advisory list on a low, non-daily cadence — newest 2026-06-10). None are unrecovered fetch failures; all are "checked, nothing in-window" against a quiet weekend.
Watchlist: not configured for this deployment (product and supplier watchlists empty) — sweep is a no-op; line omitted from telemetry.
Essential-coverage: all essential national-CERT/government/KEV sources (CISA KEV, ENISA EUVD, NCSC-CH, NCSC-NL, BSI, ANSSI/CERT-FR, CERT-EU, CERT-PL, NCSC-UK, CISA advisories/directives) attempted and reachable; no misses. CISA KEV catalog carried no new additions inside the window (newest entries dated 2026-07-16, already covered).
Deep-dive rotation: category network-stack-rce — not used in the trailing 7 days (recent picks: other, firewall-vpn-rce, apt-campaign, identity-infra, linux-lpe). No prior deep dive today (deep_dives_today: 0).
Verification. Three iterations (Opus / Sonnet / Opus rotation); confirmed CLEAN published under the double-CLEAN gate (iteration 2 Sonnet CLEAN + iteration 3 Opus CLEAN — two consecutive CLEANs on two different models). Iteration 1 (Opus, cold) found one truth defect and one advisory: the run-record notes described the new UAC-0145→Sandworm edge as part-of while the registry deliberately used related-to (the typed vocabulary has no actor→actor subcluster edge), and the nginx body's "F5 frames risk as DoS-primary" clause was weakly cited to SecurityWeek. Both fixed (run-record note corrected to related-to with the reason; DoS-framing clause re-cited to cyberstan + The Hacker News, SecurityWeek kept for CVSS/patch). Iterations 2 and 3 independently re-read both entries + the run record cold against freshly-fetched sources and confirmed every evidence quote verbatim, every quantifier and CVSS/version sourced, all seven ATT&CK ids active in v19.1 and body-supported, no IOCs, and correct classification/priority/action-item discipline. entries_dropped_by_verification: 0; verification_residual_count: 0.
Data-model note (surfaced for the operator / weekly audit): the typed relationship vocabulary (docs/pipeline.md § Relationships, enforced by site/content_model.py) has no actor→actor containment edge, so a declared actor subcluster (UAC-0145 is a CERT-UA-declared subcluster of UAC-0002/Sandworm) can only be recorded as related-to with the hierarchy in the edge note, or folded into aliases (as UAC-0113 was on actor:sandworm). A dedicated subcluster-of / actor-scoped part-of edge would model the recurring APT-umbrella / UAC-subcluster pattern more faithfully; noted here rather than changing the normative model in a routine intel run.