Verification & coverage notes
Window: 26 h, derived from a 24.0 h gap to 2026-08-11T0411Z-intel, which published ok. Standard window class. The window's dominant event was Microsoft's August Patch Tuesday together with three CISA KEV additions on the same day, so this run carries more vulnerability-kind entries than a typical fire; every one of them was put to the beyond-the-patch-cycle test individually rather than admitted as a bundle.
Corrections applied during composition. Re-reading the primary sources in full before writing contradicted several claims in the research returns, and the primaries won in each case:
- The Check Point analysis does not state that victims were approached via LinkedIn. It says the exact approach method in this wave remains unclear and only assesses, from earlier campaigns, that professional networking platforms were likely used. The research return had carried it as observed fact; the entry carries it as the assessment it is.
- Two of the returned evidence quotes failed a literal-substring check against the fetched page, the source uses non-breaking spaces and a curly apostrophe where the returned quotes used ordinary characters. Both were replaced with contiguous fragments that do match byte-for-byte. Four further quotes across other items failed the same check for the same reason and were shortened.
- The Storm-1175 item as returned stated healthcare, professional services and finance in Australia, the UK and the US as confirmed victim sectors of this campaign. The source describes those as the actor's prior Medusa victim set. The entry says so, and also carries Microsoft's own hedge that it has not formally confirmed the access vector.
- The SAP item as returned omitted that a vendor-side interim control exists (a Commerce Cloud IP filter set restricting access to the vulnerable endpoint). It is now the second half of that entry's action item.
- Two of the proposed ATT&CK ids are revoked in the pinned v19.2 dataset, DLL Side-Loading and Disable or Modify Tools both moved. The surviving ids were used instead. No dead id shipped.
Completeness sweep. Re-reading the full research returns surfaced one item none of them had flagged: a Rapid7 aside in its Patch Tuesday write-up recording that the Nightmare Eclipse persona published ShieldBreak, an unpatched proof-of-concept described as a full bypass of Microsoft's July fix for RoguePlanet. That was corroborated to a second outlet and published, because a public working exploit for SYSTEM on fully patched Windows with no vendor fix is exactly the shape the inclusion gate's "otherwise requires an out-of-band response" limb exists to catch. It would have been a silent miss.
A second completeness recovery came out of the verification pass rather than the research returns: Rapid7's Patch Tuesday write-up, already cited three times in this run for other CVEs, also discloses a coordinated SharePoint Server release, CVE-2026-63520 plus a published technical analysis and proof-of-concept for CVE-2026-55040, the first link of a chain Rapid7 states is a critical unauthenticated remote code execution. Against a constituency that disclosed two on-premises SharePoint compromises in the preceding nine days, that is not an item to leave for the next fire, and it is now published.
Borderline drops.
- borderline-drop: Liechtenstein VwbP register, reported root cause (broken object-level authorization), the only source carrying the claim, an Inside IT article of 2026-08-10, returned 403 on direct WebFetch, on the bridge and on the bridge's jina-reader fallback, in both the sub-agent's attempts and the main agent's. The one page that was fetchable is a reader's letter to a Liechtenstein paper that quotes the article on a different point (the register's outsourced development and the contractor's contractual security responsibility) and not on the mechanism. Publishing the root cause would have meant citing a page that does not carry the claim. Dropped rather than mis-sourced; the transport fix is recorded against the source records, and the story remains open for a future fire if the article becomes reachable or a sibling publication republishes it.
- borderline-drop: "Cybernox" claim against a Santé publique France platform, an unconfirmed criminal claim relayed by a single Admiralty-C aggregator, with no victim confirmation, no national-authority statement and no second outlet. Fails the fake-news guard on its own terms. The described mechanism (a client-supplied role change accepted without a permission check, then a bulk export) is worth revisiting if the agency or CNIL/ANSSI says anything.
- Chrome's 2026-08-11 stable release fixed five high-severity use-after-free flaws with no exploitation flag; it does not clear the beyond-the-patch-cycle bar and ships nothing.
- Dropped by S4 after investigation and not revisited: a Newcastle University ExfilSquad story resting on a late-July disclosure, two leak-site-only ransomware claims with no victim or journalism corroboration, a May 2026 Hungarian story, and a US local-government ransomware wave with no European nexus and no transferable new tradecraft.
Single-source items and carve-outs. Three entries ship single-source with the reason stated in their own sourcing_note: the Storm-1175 attribution (Microsoft Threat Intelligence is one assessor; the outlets carrying it are publishers of that one assessment, not independent corroboration), the Wesco confirmation (one outlet holds the company's on-record statement), and the CAV3RN update (Kaspersky is the only party publishing on this framework). The ShieldBreak entry is multi-source on the existence of the release but its technical claims (the 100 percent success rate, the Windows Server 2025 coverage) trace to the researcher and no vendor has reproduced them, which is why it carries credibility 2 and says so in the body.
Recency exception. The Storm-1175 entry's primary reporting is dated 2026-08-10, outside the 26 h window and inside the 72 h developing-story allowance. It is carried as an update to an incident this pipeline has tracked since 2026-08-03 and which the vendor states is still active; the previous fire's window covered 2026-08-10 and did not surface it, so this is gap recovery rather than a re-run of covered ground.
Coverage backlog. One row was open (state/coverage_backlog.md): the 1Password "FLAWED" study on LLM-generated patches, carried since 2026-08-10 as a marginal drop. Re-put to the gate on today's facts, it still does not clear it; it is a study statistic about AI-assisted patching rather than tradecraft a Tier 2/3 responder acts on, and this run published no AI-remediation-practice entry it could support. Left open rather than struck; it is two days old against the file's ~30-day rule.
Deliberate non-update decisions (gate warnings confirmed). The ShieldBreak entry shares the actor:nightmare-eclipse entity with the 2026-07-29 LegacyHive entry and is deliberately a new entry rather than an update to it. They are different flaws in different products (LegacyHive is a hive-mount race in the Windows User Profile Service, ShieldBreak is a bypass of the July fix for a Microsoft Malware Protection Engine flaw) and share only the disclosing persona. A stream of separate disclosures from one researcher is many stories from one publisher, not one story recurring, and the separate LegacyHive update this run publishes covers its own delta.
The SharePoint entry is likewise a new entry and not an update to either Swiss SharePoint breach entry. It concerns a different vulnerability chain entirely; the two July intrusions are named in its body purely as estate context, and it says explicitly that neither involves these CVEs. Its registry links were removed for the same reason, asserting an entity relationship there would imply a connection no source makes.
Verification outcome. Two iterations, on two different models. The first (Opus) returned 11 truth and 3 editorial findings, all remediated, including one that would have shipped a fabricated affected-version matrix on the Metabase entry, one triage discriminator naming a value that is not observable where the entry said to look for it, and one missed story that became this run's eleventh entry. The second (Sonnet) walked every one of those remediations against its cited source, confirmed all 17, gave the two newest entries an adversarial re-read and found them clean, and returned a single further finding: a temporal clause attributed to a source that does not carry it. That was fixed the same way as the others; the claim now sits with the publisher that makes it. The run publishes on the low-residual early exit with a residual count of 1, which reflects the final iteration's own finding rather than anything left unrepaired. The second reviewer also noted, and this run confirms, that the cached plain-text extraction of the Metabase advisory garbles its version table; the correction was made against the raw HTML, and anyone re-checking that entry should do the same.
No entry reached the critical bar this run. The two actively exploited flaws with the widest estate are a local privilege escalation requiring an existing foothold (CVE-2026-68820) and a denial-of-service on a VPN gateway with no confidentiality or integrity impact in the vendor's own vector string (CVE-2026-20349). Both are high.
Coverage gaps: cert-at (landing page, no dated in-window advisories reachable); enisa (freshest item 2026-08-06); ncsc-ch-focus (freshest substantive item is a public-awareness quiz); ncsc-ch-incidents (ticker unchanged since 31 July); prodaft (rotation priority, reachable, no dated content newer than 2026-07-08); ssd-disclosure (rotation priority, reachable, freshest 2026-08-05, out of window); chrome-releases (rotation priority, reached, no exploited CVEs); siemens-productcert-csaf (403 on every transport); inside-it-ch (article bodies 403 on every transport); google-tag (HTTP 503, not retried); paradigm-shift-research (blog route serves a placeholder); sygnia, csa-labs, ox-security (JS-rendered listings did not hydrate via the direct bridge); trendmicro-research (jina key pool reported balance-exhausted before one succeeded, returned 0 items); lab52, ncc-research, swisspost-cybersecurity, dcod-ch (not fetched, S2 time allocation); cert-pl, cert-eu, ncsc-uk, watchtowr, redcanary, reliaquest, zdi, kommunaler-notbetrieb-de, ico-uk, cnil-fr, venarix, us-treasury-ofac, ransom-isac, sec-disclosures-edgar, all checked, nothing in window.
Essential-coverage: no miss; all 15 essential-tier sources were attempted.
Watchlist: this deployment configures no product or supplier watchlist; both sweeps are no-ops and no entry carries watchlist_hit.
One operational note for the next audit: swisscybersecurity-net was proposed as a new candidate source during research without checking the source list, where it has been status: active since June. No candidate was added this run. The record now carries a note describing its role as the fallback transport for Inside IT article bodies, which is the actual fix for the gap that dropped the Liechtenstein item.