Verification & coverage notes
A 24-hour gap to the previous fire, so a 26-hour window and a standard-window disposition. Four entries cleared the
inclusion gate, one of them an update. The window was genuinely thin on new signal, the previous fire published
eighteen entries while draining a fifteen-row backlog, and much of the Black Hat and DEF CON output it absorbed is
now settled ground, so this run's work was as much about confirming that nothing relevant was left behind as about
what it published. A scoped follow-up sweep was run specifically to test that, and it came back with two clean
negatives and one substantive correction.
Verification outcome. Three passes, alternating models, each of which found something the previous one had
not, and every finding remediated before commit. The first found four sourcing-attribution defects concentrated in a
single entry. The second, on the other model, confirmed those fixes held and then caught a defect of a different
shape entirely: a catalogue-listing status flag on two vulnerability records that no cited source asserts, true in
the world, but recalled rather than read, and invisible to a pass reading for narrative plausibility because no
sentence in the entry depended on it. The third verified both remediations left no orphaned claims and reduced to two
citation-placement findings, both fixed. The run publishes on the low-residual early exit: the final verdict carries
two findings, neither a broken link nor an invented fact, and both were repaired before this commit. Residual count is
recorded as two rather than zero, which is the honest reading of a final pass that still had findings.
Contradiction: macOS Screen Sharing, CVE-2026-65400 root cause. Huntress attributes the CVE to the Secure Remote
Password frame-length validator returning a stale success status. Calif assigns that same stale-return mechanism to a
separate pre-authentication bug that Apple closed silently on 2026-07-27 with no CVE, and describes CVE-2026-65400
as a distinct state-machine desync whose details it is deliberately withholding. The entry reports both attributions
and adopts neither, and carries verification: contradicted for that reason. Both sources agree on everything that
drives action, pre-authentication, the daemon runs as root, working exploits exist, and 26.6.1 / 15.7.9 / 14.8.9 is
the fix, so the remediation is unaffected. The disagreement is worth surfacing rather than smoothing over: a reader
who saw only the first account would believe the mechanism behind the flaw patched this month is already public.
Contradiction: CEVA Logistics, data provenance. Dutch reporting relays a claim that a dataset of retail customer
records offered for sale on a criminal forum came from a CEVA break-in in early May 2026; CEVA maintains that dataset
is old data from a separate 2025 incident. The entry states the dispute and adopts neither the May date nor the
attribution, and does not treat the offered data as this incident's proceeds.
Mapping restraint on the CEVA entry. No source anywhere, not CEVA's statement, not the six downstream victims'
notices, not the Dutch regulator, states an initial-access vector, a malware family or an actor. The follow-up sweep
was sent to establish exactly that and confirmed it as a real gap in public reporting rather than a research miss. The entry therefore maps only the collection of data from the compromised order-processing systems,
which its sources do state (in their own hedged terms), and maps no access vector at all. A trusted-relationship
mapping was considered and rejected: the adversary reached the downstream organisations' data by compromising their
processor, but never entered any downstream network, which is what that technique describes.
Borderline drops: recorded so a wrong call is recoverable:
- borderline-drop: Liechtenstein takes its Commercial Register offline as a precaution, the only in-window
Liechtenstein development is that a fifth government system joined the precautionary shutdown programme, with the
government explicitly stating there are no indications of an attack on it and disclosing no new forensic detail on
the original register intrusion: no actor, no vector, no exfiltration scope. It is an availability and compliance
fact for downstream fiduciaries, not a decision a Tier 2/3 responder makes differently. The tracked incident stays
open for a genuine forensic delta.
- borderline-drop: two React hook packages backdoored via a compromised maintainer's GitHub credentials
(CVE-2026-48159 / CVE-2026-48158); the disclosure is fresh (2026-08-10) but the incident is not: the malicious
commits were force-pushed away in May 2026 after roughly 23 hours, the packages never reached the npm registry, and
the residual exposure is confined to anyone still pinning a direct commit reference to two specific packages. The
technique class (maintainer workstation compromise to push credentials to install-hook execution) is already
covered in depth by this store's coverage of the current npm wave. Sourcing is also two advisories by the same
maintainer, i.e. one assessor.
- borderline-drop: ClamAV denial-of-service fixes (CVE-2026-20337 / CVE-2026-20338), surfaced by the Italian CSIRT
and CERT-FR the same day, rated below their top severity, no exploitation. A routine patch-cycle item that does not
demand action beyond it.
- borderline-drop: Elixi International SA (Chiasso, Switzerland), a Space Bears leak-site listing with a strong
home-region and healthcare-supply-chain nexus, which is why it was chased twice. The company's own site carries no
notice, Ticino and wider Swiss press carry nothing, and the national authority's recent publications do not mention
it; the only corroboration is dark-web-monitoring aggregators restating the listing. Unconfirmed extortion claims
do not ship. Flagged for the next fire in case victim confirmation lands.
- borderline-drop: Université Libre de Bruxelles, a Qilin listing against a Belgian public university. The
university's own channels and IT status page are silent, Belgian press coverage found is from an unrelated 2020
incident, and the Belgian centre publishes only a generic actor profile. Same disposition, same follow-up flag.
- borderline-drop: Quironsalud (Spain) and Statista (Germany), two further extortion-site listings from the same
sweep, both dropped on the same basis as the two above: no victim statement and no high-reliability reporting
found. Recorded here rather than only in the research return because the first is a hospital group, i.e. one of
this deployment's additional sectors, and a wrongly-dropped healthcare item is exactly what this list exists to
make recoverable. All four listings are flagged for the next fire in case confirmation lands.
- borderline-drop: Gagny (France) municipal breach and an unconfirmed claim against a French vocational-training
agency; the first pre-dates even the developing-story window and was recycled by a tracker with no new fact; the
second is an actor claim the reporting outlet itself records as unconfirmed by the named organisation.
Coverage backlog. One row was open (an AI-generated-patch study retained by the previous fire as possible
supporting material). Re-assessed against today's facts: it remains a statistic about AI-assisted remediation
practice rather than tradecraft a responder acts on, and this store already carries a concrete instance of the same
lesson. Left open rather than struck; it has been queued for one day, and its stated purpose is to be available to a
future entry on AI-assisted remediation. It will be published or struck with a reason well inside the thirty-day
limit the backlog sets.
Completeness check. The research return was unusually thin, one research strand returned a single item, and it
duplicated another strand's find, so a scoped follow-up sweep re-checked for any substantive technical publication
dated 2026-08-10 or 2026-08-11 that the earlier passes had missed, biased toward incident-response case studies,
operational-technology research and identity-infrastructure tradecraft. It found none, and rejected the near-misses
for stated reasons (a general-awareness piece with no original technical content; several items dated outside the
window; publishers already covered this fortnight). Three independent passes converging on the same negative is the
basis for reporting this as a genuinely quiet window rather than an incomplete one.
Coverage gaps: prodaft (seventh run against a frozen undated snapshot, recency unestablishable, escalated on the
record); ssd-disclosure (listing page challenge-blocked on both transports, so no discovery entry point);
chrome-releases (feed extraction returns zero items from a live source, second consecutive run); mysites-guru
(listing renders without publication dates); siemens-productcert-csaf (standing 403 across all transports);
paradigm-shift-research (single-page-application shell with no listing path); sans-newsbites (semiweekly cadence, last
issue outside the window); the Ajax and Ace & Tate customer notices were not fetched first-hand and are described
only from Dutch trade-press summaries; the original broadcaster report behind the disputed CEVA data-provenance claim
sits behind a consent gate and was corroborated through two secondary quotations instead of its own page.
Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0; no watchlists are configured for this
deployment, so both sweeps are no-ops and the general coverage rules applied unchanged.
Essential-coverage: all fifteen essential sources attempted; none missed.
Source health: the sweep flagged one source for demotion. It was repaired in-run rather than deferred, the failing
probe was a publisher homepage that now returns a placeholder body, while the publisher's feed fetches directly with
dated, drillable items, so the record was switched to the feed. The re-probe returns an empty unsolved list across all
181 sources.