Verification & coverage notes
Standard 26 h window (gap 24 h to the previous run 2026-07-24T0409Z-intel; previous run published ok). No scheduler outage, no S5 (empty intel/). Seven entries published (three vulnerability/threat at high, four at notable), two of them updates; one deep dive; zero critical.
Deep-dive selection. TA458/Operation RoundPress was taken as the day's deep dive under selection criterion 1 (active in-the-wild exploitation of half-click webmail zero-days, including a fresh SOGo zero-day CVE-2026-8496, plus non-trivial exposure; self-hosted webmail is common in EU/CH public-sector estates). Its category (apt-campaign) also carried yesterday's deep dive (Laundry Bear/Zimbra), which would normally demote it one rank; criterion 1 exempts that demotion, and the item is a distinct actor with a materially broader five-platform zero-day supply, so it independently earns the treatment rather than repeating yesterday's story. window24h.deep_dives_today was 0 before this run.
Update decisions. Two update_of entries carry genuine deltas, not recaps: the Check Point siblings (CVE-2026-62144 unauthenticated management command execution, CVE-2026-62145 Gaia Portal read-only-to-root) sit on the same actively-attacked management surface as the previously-covered CVE-2026-16232; the LAUNDRY BEAR/ZimReaper entry adds the CSS-@import sanitizer-bypass mechanics, DNS-tunnelled exfil, and (the load-bearing delta) a "ZimbraWeb" application-specific password that survives a password reset and the patch, changing the remediation. ZimReaper is already registered as an alias of tool:ulej-flowerbed; no new malware entity was created.
Dedup notes. The Thailand AI-agent incident's LinPEAS-probed Linux-kernel LPE CVEs (CVE-2026-43503/31431/43284) and Roundcube's CVE-2025-49113 are all already in the store; those CVEs were reconnaissance probes / chain context, not the finding, so the Thailand and RoundPress entries carry only genuinely-new CVEs in cves[] (RoundPress: CVE-2026-8496 only; Thailand: none) to avoid re-asserting covered ground.
Borderline drops (recoverable):
- borderline-drop: Flare EMEA-healthcare ransomware supply-chain landscape (Kazu), single-source (the underlying Flare post could not be located; only Help Net Security relaying it), a leak-site-derived victimology/actor census with no intrusion vector, CVE or detection concept; strategic-landscape framing belongs to the weekly, and its defender takeaway is generic vendor-risk practice. New actor "Kazu" not registered (only entities referenced by a published entry are added).
- borderline-drop: GTIG cryptonym actor-naming taxonomy change, first-party methodology announcement, no attacker tradecraft or detection/hunt value; a Tier 2/3 SOC would not act differently in the next 7 days.
Out-of-window / dropped-by-S1 (logged for awareness): ManageEngine ADAudit Plus CVE-2026-6516 (vendor advisory actually April 2026, NCSC-NL merely re-cataloguing); Bing/XBOW ImageMagick SVG RCE (Microsoft-side already fixed, no customer action); Azure Portal CVE-2026-62835 (Microsoft-mitigated); Johnson Controls C-CURE 9000 ICSA-26-204-01 (same 204-XX batch already surfaced 2026-07-24, no fresh delta); Synacktiv Argo CD unauthenticated RCE (24 days old, no in-window development, flagged for the weekly W1 as a still-open high-severity unpatched issue); Cisco SD-WAN CVE-2026-20245 (published ~84 h before run, outside the developing-window allowance).
Single-source / carve-outs: microsoft-email-threat-landscape-q2-2026 is single-source by nature (first-party vendor threat-landscape report on Microsoft's own telemetry); thailand-finance-ministry-hermes-ai-agent is single-source (Hunt.io is the sole primary investigation; BleepingComputer re-reports it) with compromise unconfirmed by the victim, framed as a targeting/tradecraft disclosure, not a confirmed breach. stiftung-autismuslink rests on a first-party victim statement (Admiralty A for its own incident) corroborated by the INC Ransom leak-site claim; the INC Ransom attribution is leak-site-based, not victim-confirmed.
Verification-fix telemetry robustness: first-attempt S1 and S2 spawns terminated immediately on the Sonnet real-time cyber-safeguard classifier ("Sonnet 5's safeguards flagged this message"); both were re-spawned once with reframed defender-vantage tasking and returned normally. This is a spawn-time classifier false positive on legitimate defensive CTI research, not a research failure; recorded here for operator awareness of the safeguard-interruption pattern on the pinned Sonnet research role.
- Coverage gaps: cisa-advisories (JS listing + Akamai-403, jina pool exhausted, detail pages reachable via
cisa page); cert-pl (403 to the Phase-1 sub-agents on direct/jina, but recovered on a Phase-5 re-check via fetch_source.py url https://cert.pl/en/news/ returning HTTP 200, no in-window item clearing the action-required bar); jina-reader-pool (HTTP 402 balance exhausted, third consecutive run, operator top-up needed); sekoia, recordedfuture-insikt, huntress, group-ib (jina-402 / no in-window content); volexity, horizon3-ai, eset, crowdstrike, withsecure-labs, lab52, intrinsec, cert-at (reachable, no in-window items). - Watchlist: no watchlists configured; sweep is a no-op (S1 products, S4 suppliers both 0/0).
- Essential-coverage: the cisa-advisories listing was not enumerable directly (Akamai-403 + jina-402) but detail pages, cisa-kev and the ncsc-uk co-signed feed substituted with no in-window qualifying item lost; cert-pl recovered via the
url bridge on re-check (no qualifying item). All 15 essential sources attempted.