CTIPilot
Sun · 30 Aug 2026
All daily briefs ↗
Daily brief · UTC day

Sunday, 30 August 2026

3 verified findings from 2 runs · 13 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01Applying the same patch twice writes an executable into $GIT_DIR of a bare clone, and Git then runs it as the Gitea user. CISA added CVE-2026-60004 (CVSS 9.8) to the Known Exploited Vulnerabilities catalog on 2026-08-25. Gitea's diffpatch endpoint applies attacker-controlled patches inside a shared bare temporary clone; submitting the same patch twice forces a three-way merge fallback that checks the indexed path out even under --cached, and because a bare clone's repository root is $GIT_DIR, an executable entry named as a hook path becomes a live hook that Git invokes while writing the index. Exploitation needs only ordinary repository write access, which default open registration hands to any visitor. Fixed in Gitea 1.27.1. A compromised self-hosted instance was reached end to end by an automated scanner that registered, created a repository and dropped a shell loader and a miner.
  2. 02The DMZ component enterprises trust as their gateway to WebLogic has been exploited since January; CISA listed it on 24 August. CISA added CVE-2026-21962 (CVSS 3.1 base 10.0) to the Known Exploited Vulnerabilities catalog on 2026-08-24. The flaw sits in the request-handling logic of the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and Microsoft IIS, and in Oracle HTTP Server, which bundles it. A remote attacker with no credentials, no privileges and no user interaction gains unauthorized read and write access to data the proxy handles, plus a pivot path into backend WebLogic clusters. Oracle fixed it in the January 2026 Critical Patch Update; CloudSEK honeypots recorded exploitation from 22 January, and SOCRadar's July analysis of an exposed China-nexus staging server lists it among the CVEs weaponised in a campaign focused on government infrastructure.
  3. 03Berlin confirms extortion after a phishing click reaches the shared state network; media reports name Rhysida. Germany's Berlin state administration confirmed on 2026-08-28 that it faces an active extortion attempt following a compromise of its shared Landesnetz government network first disclosed on 2026-08-17; media reporting attributes the attack to the ransomware group Rhysida, which separately claimed it on its own leak site. Investigative reporting states an employee's phishing-email click opened the network to attackers who exfiltrated 5.7 to 5.8 terabytes of data, including critical-infrastructure and emergency-planning material, before detection; Berlin's government has publicly refused the roughly EUR 2 million ransom demand.

01Active threats, incidents & disclosures1 item

HIGHupdatedNATOB2

Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida

Germany's Berlin state administration is the target of a live extortion attempt following a compromise of its Landesnetz, the shared network serving every Senate department and state agency; the attack became public knowledge on 2026-08-14 (translated from German) (Berliner Zeitung, 2026-08-28), the same day the two affected departments were disconnected from the network as a containment measure (Der Tagesspiegel, 2026-08-28). Investigative reporting, not an official technical disclosure, is the first to name a mechanism: the attackers apparently gained access to the Landesnetz through an employee's click on a phishing email (translated from German) (Der Tagesspiegel, 2026-08-28). Forensic investigators found the actual data exfiltration ran between 2026-08-07 and 2026-08-12 (Security Affairs, 2026-08-29), several days before the two affected departments were disconnected.

Der Spiegel reported, citing security-industry sources, that the ransomware group Rhysida is behind the attack (heise online, 2026-08-29), an attribution Berlin's Senate administration has declined to confirm, citing investigative-tactical reasons (heise online, 2026-08-29). Rhysida's own dark-web leak site independently posted an entry titled "Berlin, Germany" on 2026-08-28 claiming 5.79 terabytes of data across roughly 1.44 million files, including personal data on 12,076 individuals, more than 5,000 personnel files, plaintext credentials for internal systems, disciplinary and court records, Bundesrat committee protocols, and vulnerability analyses concerning Berlin's water supply (Security Affairs, 2026-08-29). Rhysida demanded 30 Bitcoin, about EUR 2 million (translated from German) (heise online, 2026-08-29), with a one-week ultimatum running from 2026-08-28 (translated from German) (Der Tagesspiegel, 2026-08-28); Berlin's Governing Mayor Kai Wegner and Interior Senator Iris Spranger jointly confirmed the extortion attempt and publicly refused to pay, stating the state of Berlin will not submit to extortion (Security Affairs, 2026-08-29). Whether the affected systems were also encrypted, not only exfiltrated, is disputed: one outlet attributes to unnamed "experts" the claim that the Rhysida ransomware was the tool used to both encrypt the systems and steal the data (translated from German) (BornCity, 2026-08-29), while every other cited source describes only data theft and extortion without confirming encryption; this entry does not assert that encryption occurred.

CrowdStrike is conducting a forensic investigation across every Senate department and state agency network-wide, an effort Tagesspiegel's sources expect to take several more days (Der Tagesspiegel, 2026-08-28). The department networks disconnected on 2026-08-14 were reconnected on 2026-08-23, but staff report continuing operational degradation days later, with many now working over private internet connections because the corporate network remains impaired; the same reporting flags that workaround as a new, self-inflicted security exposure (Der Tagesspiegel, 2026-08-28). Rhysida has run this extortion pattern against public-sector targets before, including an earlier 2026 claim against the city of Stuttgart (translated from German) (heise online, 2026-08-29); per the joint CISA/FBI/Multi-State ISAC advisory on the group, current as of its 2025-04-30 update, its initial-access techniques include compromising internal VPN access points using valid credentials at organizations lacking multi-factor authentication, and separately deploying Gootloader malware (CISA, 2025-04-30).

Triage: the confirmed mechanism, a user-driven phishing-email click followed by multi-day bulk data exfiltration, surfaces at the point of delivery in mail-flow and attachment-sandboxing logs, and in network-egress and data-loss-prevention telemetry as a sustained high-volume outbound transfer from a single department's network segment; neither cited source states what executed after the click, so no process-level discriminator is offered here.

The attackers apparently gained access to the Landesnetz through an employee's click on a phishing email.

Der Tagesspiegel 2026-08-28

“The state of Berlin will not submit to extortion,” Berlin Mayor Kai Wegner and Berlin's interior senator, Iris Spranger, said in a joint statement on Friday, before the ransomware group claimed the attack on their Tor data leak site.

The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included.

Security Affairs 2026-08-29

Experts identified the ransomware Rhysida as the tool with which the systems were encrypted and the data stolen.

BornCity 2026-08-29

All files have been uploaded to the publicly accessible area, have fun browsing, data hunters!

Rhysida leak-site posting, via heise online

Based on what I can see here now, they have put the complete dataset online for everyone to view

Joachim Selzer, Chaos Computer Club spokesperson, via heise online (dpa)

Among the data that is viewable is, for example, the application for a new phone, including the signature of the administrative employee.

heise online (dpa)

the ministry points only to the existing constitutional framework.

heise online, citing the Federal Interior Ministry's (BMI) written reply

Until now, the BSI has only been constitutionally permitted to assist the states in defending against serious cyberattacks after an explicit request for administrative assistance. In addition, lengthy bilateral agreements had to be concluded, and these still do not exist with all 16 federal states today.

heise online 2026-08-29
Updaterun 2026-09-05T0409Z-intelupdated_atsourcesevidencebody

Rhysida's one-week ultimatum expired on 2026-09-04 at roughly 15:35 local time; the Berlin Senate had publicly committed not to pay, and about an hour after the deadline the group published the full stolen dataset on its darknet leak site, replacing the prior partial "auction" listing (heise online, 2026-09-04). Chaos Computer Club spokesperson Joachim Selzer confirmed the complete dataset (including personnel files and documents Selzer describes seeing directly, such as employment references) is now publicly accessible to anyone. Whether the dataset actually contains the drinking-water vulnerability analyses and administration credentials the group had earlier claimed remains unverified by any party this entry cites: Left-party parliamentary faction leader Tobias Schulze stated the Senate now has the opportunity to check whether the prior assumptions about the leaked data are accurate, and should notify affected individuals and organizations as quickly as possible once it does. No further technical root-cause detail beyond the phishing vector has been disclosed by the Senate.

Updaterun 2026-09-06T0409Z-intelupdated_atsourcesevidencebody

A structural consequence of this incident has now surfaced at the federal level. Asked in a Bundestag inquiry whether, given ongoing severe attacks on states and municipalities, the government would bring forward a constitutional amendment planned earlier by the previous coalition to make the BSI a true central authority for cyber incidents, the Federal Interior Ministry pointed only to the existing constitutional framework (heise online, 2026-09-03). Under that framework, the BSI may assist a state in defending against a serious cyberattack only after that state explicitly requests administrative assistance, and durable bilateral cooperation agreements (a precondition the ministry itself confirms do not yet exist with all 16 federal states) still gate faster support; in practice the BSI has repeatedly had to help first and formalise the legal basis afterward (heise online, 2026-09-03). The ministry points instead to its 14 existing cooperation agreements, its NIS2-transposition-driven expansion of BSI's powers, and increased staffing and budget as sufficient. Green-faction deputy chair Konstantin von Notz, who filed the inquiry, called the reversal "devastating for Germany's IT security" (translated from German) given the still-unfolding fallout from this exact incident. The tension is directly transferable to any federated cyber-incident-response model, including Switzerland's own federal/cantonal/communal cooperation structure with BACS: a central technical authority's ability to help is gated by a request-and-agreement process rather than by its own capacity to act.

Separately, on the incident itself, the Chaos Computer Club's Joachim Selzer identified specific record types now visible in the fully-published leak beyond the personnel-and-employment-reference material already recorded here: an internal request form for a new mobile phone bearing the requesting employee's handwritten signature, which Selzer noted gives a criminal a usable signature sample (heise online, 2026-09-04).

incident30 Aug 04:35Zmulti-sourceOpen finding ↗
HIGHCVE-2026-21962exploitedNATOB1

CVE-2026-21962: an unauthenticated request bypasses access control in the Oracle WebLogic Server Proxy Plug-in, CISA KEV-listed on 24 August with exploitation running since January

CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog on 2026-08-24, with a CVSS 3.1 base score of 10.0. The flaw is in the request-handling logic of the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and Microsoft IIS, and in Oracle HTTP Server, which bundles the same component. It is reachable over HTTP with no authentication, no privileges and no user interaction, and it yields unauthorized read and write access to the data the proxy handles plus a route into the backend WebLogic clusters the proxy fronts: "this vulnerability allows an unauthenticated remote attacker to bypass security controls and potentially gain unauthorized access to backend WebLogic systems. Because these proxy plugins often sit in DMZ environments, the exposure is significant" (NetSPI, 2026-01-22).

That last point is the whole finding. The proxy plug-in is not an application server; it is the component an estate deploys specifically to be the trusted boundary in front of one, which means the flaw does not sit behind the perimeter, it is the perimeter. Confirmed affected: Oracle HTTP Server and its proxy plug-in at 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, and the WebLogic Server Proxy Plug-in for Microsoft IIS at 12.2.1.4.0 (same source). Oracle shipped the fix in its January 2026 Critical Patch Update.

Exploitation is not new, only the listing is. CloudSEK's honeypots recorded exploitation attempts from 22 January 2026, immediately after a public proof-of-concept appeared, and CISA has not said what prompted the August listing: "the vulnerability has been exploited since January", and "it’s unclear which attacks triggered CISA’s alert for CVE-2026-21962" (SecurityWeek, 2026-08-25). For a defender that inverts the usual reading of a KEV addition: this is not a newly weaponised flaw to get ahead of, it is confirmation that anything still unpatched has been reachable by a public exploit for seven months.

There is a targeting signal, and it is worth stating precisely, because it is one vendor's characterisation of a different dataset rather than an authority's account of this exploitation. SOCRadar's July analysis of an exposed staging server belonging to a China-nexus operator tracked as UNC5174 and UNC6586, associated with the SNOWLIGHT malware family, lists CVE-2026-21962 among the vulnerabilities weaponised in a campaign whose reconnaissance list SOCRadar says resolved overwhelmingly to government domains across more than a hundred countries (SOCRadar, 2026-07-31). SOCRadar's victimology table is more specific than that summary suggests, and it cuts both ways: against 119 raw list entries and 91 unique hosts for the WebLogic-class campaign, it records exactly one confirmed compromise, with the confirmation method given as "Blind RCE via DNS/HTTP out-of-band callback" (same report). So this operator did use the exploit and got in once that SOCRadar can prove, on a target list that is overwhelmingly governmental, but it converted only about one host in ninety, against 80 of 80 for the same operator's Confluence campaign in that table. The cPanel campaign sits at a comparable per-host rate (16 of 1,563) on a far larger footprint, so the honest reading is that WebLogic was a low-yield line of effort by confirmed-compromise count, not that the exploit failed. Its six-week staging-server window is also a different dataset from CloudSEK's seven months of honeypot telemetry, so the exploitation observed since January is not established to be this operator's.

Where the activity surfaces. Exploitation is HTTP traffic to a proxy tier, so the telemetry is the proxy's own request logs rather than anything on the WebLogic host. Look for malformed or structurally anomalous requests aimed at the plug-in's forwarding path, and for forwarded requests reaching backend WebLogic contexts that the proxy's own routing rules should never produce. Because the flaw grants unauthorized read and write access at the proxy rather than code execution on the origin, backend application logs may show requests that are individually well-formed and correctly authenticated from the backend's point of view: the discriminator is the mismatch between what the front-end received and what the back-end was asked to do, not a malformed request arriving at the application.

Triage: a benign lookalike is a misconfigured client or scanner producing malformed forwarding requests against the same path, which is common on an internet-facing proxy. What separates the two is what follows: a benign malformed request produces an error and stops, while exploitation is followed by backend access to data the requesting session was never entitled to. Correlate the proxy log with the backend access it produced rather than triaging the proxy log alone.

This vulnerability allows an unauthenticated remote attacker to bypass security controls and potentially gain unauthorized access to backend WebLogic systems. Because these proxy plugins often sit in DMZ environments, the exposure is significant.

NetSPI 2026-01-22

The vulnerability has been exploited since January

It’s unclear which attacks triggered CISA’s alert for CVE-2026-21962.

SecurityWeek 2026-08-25

Builds on: 2026-08-05/cve-2026-34486-tomcat-encryptinterceptor-fail-open-kev

vulnerability30 Aug 13:12Zmulti-sourceOpen finding ↗
HIGHCVE-2026-60004exploitedNATOA1

CVE-2026-60004: Gitea's diffpatch endpoint turns an attacker-supplied patch into a live Git hook, giving command execution as the service account; KEV-listed after miner deployment

CISA added CVE-2026-60004 to the Known Exploited Vulnerabilities catalog on 2026-08-25. The flaw is in services/repository/files/patch.go, the code behind Gitea's diffpatch endpoint, which applies an attacker-controlled patch inside a shared bare temporary clone. The maintainers describe the chain precisely: "submitting the same patch twice creates an add/add collision. Git's three-way fallback checks the indexed path out even though the operation is performed with --cached" (Gitea maintainers, 2026-07-28). In a bare clone the repository root is $GIT_DIR, so a checked-out executable entry whose path matches a Git hook name is not a file sitting next to the hooks directory, it is a hook. Git then invokes it while writing the index, and it runs as the Gitea OS account.

The precondition is the part worth reading twice. The advisory states it plainly: "an attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository" (same advisory). Ordinary write access is not a privileged role, it is what every user of a Git forge has by definition, and Gitea's shipped default hands it to anyone who can reach the login page. So on a default-configured instance this is a pre-authentication flaw in every sense that matters operationally, separated from an anonymous visitor only by a registration form. Fixed in Gitea 1.27.1. The advisory carries a working proof-of-concept, which arrived with it.

Exploitation is opportunistic and automated. Help Net Security reports the incident write-up of an operator whose self-hosted instance was compromised: "because the server ran an outdated version of Gitea, with open user registration and no email confirmation or CAPTCHA, an automated scanner was able to register an account, create its own repository, and trigger the exploit chain" (Help Net Security, 2026-08-26). The chain wrote a proof of execution into a Git branch, then pulled a shell loader followed by a miner; the operator was alerted not by security tooling but by the hosting provider flagging sustained CPU. That is a mass-scanning profile against a default configuration, not targeted intrusion, and it means exposure is a function of being reachable rather than being interesting.

The blast radius is broader than the payload suggests. Depending on container isolation and the privileges of the Gitea OS user, exploitation can expose the main configuration file, application and process-environment secrets, database credentials and contents, and OAuth and integration credentials (same reporting). A miner is the noisy outcome; the quiet one is a set of credentials into whatever the forge is wired to, which for a public-sector development estate typically means CI runners, artefact registries and identity providers.

Where the activity surfaces. The exploitation itself looks like ordinary API traffic, so the durable signal is what the service account does immediately afterwards. Watch for the Gitea service account spawning a shell or an interpreter within seconds of a patch or diff API call, on a host whose normal process tree is a Go binary plus git. On the repository side, the artefact is a Git hook whose content arrived through patch application rather than through an administrator action, so an executable object at a hook path in a repository nobody manages is the thing to hunt for. Registration and repository-creation events are the leading indicator: on an instance with real users, a self-registered account creating a single repository and immediately exercising the diff endpoints is not a normal usage pattern.

Triage: the benign lookalike is a legitimate developer using diffpatch to apply a patch, which is what the endpoint is for and which will be the overwhelming majority of hits on that route. Two things separate exploitation from it. First, the same patch applied twice in quick succession, which is the collision the attack requires and which a human working normally has no reason to produce. Second, and more reliably, what happens next: a legitimate patch application ends with a commit, while this one ends with the service account executing something. Alert on the process behaviour, use the endpoint traffic to explain it.

An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository.

Submitting the same patch twice creates an add/add collision. Git's three-way fallback checks the indexed path out even though the operation is performed with --cached.

Gitea maintainers (GitHub Security Advisory) 2026-07-28

Because the server ran an outdated version of Gitea, with open user registration and no email confirmation or CAPTCHA, an automated scanner was able to register an account, create its own repository, and trigger the exploit chain.

Help Net Security 2026-08-26
vulnerability30 Aug 13:12Zmulti-sourceOpen finding ↗

03Updates to prior coverage13 items

HIGHupdatedNATOC2

Unisoc T612 modem (and other devices on shared Unisoc modem firmware): a single answered video call can escalate from modem-level RCE to full Android kernel access via an ARM Memory Protection Unit isolation bypass; no CVE, no patch, vendor unresponsive

First published 2026-08-28 · open finding →

Correctionrun 2026-08-30T1312Z-audittitlesummaryaffected_productssourcing_notebody

The chipset scope was overstated. This entry named Unisoc T606, T612 and T7250 as affected and mapped the three test devices one to one onto them (Motorola E13 to T606, Xiaomi Redmi A5 to T7250). Neither reachable source contains the strings T606 or T7250 anywhere: Dark Reading and Infosecurity name only the T612, and only the Realme C33 is tied to a chipset at all. The SSD Secure Disclosure primary remains behind an anti-bot challenge on every transport, so the wider chipset list cannot be traced to any readable source and has been removed from the title, summary, affected products and body.

This entry named Unisoc T606, T612 and T7250 as the affected chipsets and paired each with one of the three test devices. That pairing is not in any source this entry can cite. Dark Reading and Infosecurity Magazine both name only the T612, and only for the Realme C33: "Researchers at SSD Secure Disclosure... demonstrated the attack chain in a controlled setting against a Realme C33 smartphone... SSD confirmed the vulnerability on a Xiaomi Redmi A5 running the January 2026 Android security patch and a Motorola E13 running the February 2025 patch" (Dark Reading, 2026-08-17), with no chipset given for the latter two. The SSD Secure Disclosure write-up itself is still unreachable, so nothing wider can be confirmed. Operationally the exposure is unchanged and if anything less bounded: the flaw sits in modem firmware shared across a product line, and an asset owner should scope by device model against the vendor's own advisory rather than by the three part numbers this entry previously listed.

NOTABLEupdatedNATOB2

La Protection Civile (France): eProtec volunteer-management platform breach, 525,000+ profiles including minors, intrusion dated to March 2026 discovered mid-August

First published 2026-08-28 · open finding →

Correctionrun 2026-08-30T1312Z-auditevidencesourcing_notebody

Two fixes. The claim that neither passwords nor banking details appear in the leak was attributed to the FNPC; the federation's statement never mentions either, and the finding is FrenchBreaches' own hedged reading of exfiltrated samples, which says the available elements do not allow it to establish their presence. That is an absence of evidence in what one tracker saw, not an organisational assurance, and it is now attributed and hedged as such. The awareness date is also given as a single date, 17 August, matching the source, rather than as a 17-18 August range.

The statement that neither passwords nor banking details appear in the leak was attributed here to the FNPC. The federation says no such thing. The source of that claim is FrenchBreaches, which analysed samples of the exfiltrated data and reports a hedged non-finding: "the currently available elements do not allow us to establish the presence of passwords, banking details or ID documents in the exfiltrated data" (translated from French) (FrenchBreaches, 2026-08). For anyone reasoning about credential-reuse or fraud exposure for the affected volunteers, that is a materially weaker basis than a federation assurance, and it should be read as what one tracker did not find in the sample it obtained. The date the federation became aware of the breach is also stated as a single date, 17 August, matching the source.

HIGHCVE-2023-49105 +1exploitedupdatedNATOB1

A 2023 ownCloud auth-bypass CVE re-enters CISA KEV because Hunt.io caught a suspected Chinese-speaking operator's open staging server using it to steal nuclear-research and naval-contractor data from two Philippine organisations

First published 2026-08-28 · open finding →

Correctionrun 2026-08-30T1312Z-auditcvesbody

The EPSS value carried for CVE-2023-49105 was wrong and had no source. It was recorded as "11.07" while none of the three cited sources mentions EPSS at all, and the live FIRST EPSS API returns 0.43205 for this CVE, about four times higher on any reading of the published figure. The field is set to null rather than to today's score, because no source this entry cites publishes one and a probability that moves daily does not belong in a static record. The same pass added the third class of stolen data on the operator's staging server, which Hunt.io lists among its own key findings and this entry had omitted.

The EPSS figure this entry carried for CVE-2023-49105 was wrong and unsourced, and has been removed. It read 11.07; the FIRST EPSS API returns 0.43205 for this CVE as of 2026-08-29, and none of the sources cited here publishes an EPSS score at all. Nothing else in the assessment turned on it: the CVE is CISA KEV-listed and the exploitation evidence in this entry comes from observed activity, not from a probability estimate.

Hunt.io's own key findings also name a third class of stolen data recovered from the same staging server, which this entry had left out: "A 192 MB SQL dump from a ZKTeco BioTime attendance and personnel database, recovered from the same server, referenced multiple related Philippine science and research organizations, indicating a possible focus on tracking individuals working for these institutions" (Hunt.io, 2026-08-27). That broadens the read on this operator: alongside the nuclear-agency and shipbuilder material already described, it was holding an HR and biometric attendance database spanning several institutions, which points at personnel tracking as an objective and at a workforce-management integrator as a likely additional access path.

HIGHupdatedNATOA2

Manchester Airports Group confirms a breach touching roughly 8.7 million customers across Manchester, Stansted and East Midlands, car-park, lounge and airport-WiFi sign-up data taken; FulcrumSec later claims credit and a client-side API-credential access vector

First published 2026-08-28 · open finding →

Correctionrun 2026-08-30T1312Z-auditsummarybody

The claim that the UK ICO had confirmed receipt of a breach report and was assessing it is not stated by any source this entry cites and has been removed from the summary and the body. What the reporting does establish is narrower: The Register says the ICO asked MAG not to disclose details of the ransom note, the demands or the group name, and MAG's own statement names no regulator at all. Regulator engagement is real; a confirmed filing is not on the record.

This entry stated that the UK Information Commissioner's Office had confirmed receipt of a breach report and was assessing it. No source cited here says that. MAG's own statement names no regulator, saying only that it has "informed and are working with the relevant authorities" (Manchester Airports Group, 2026-08-27), and the closest the reporting comes is The Register's account that the ICO "asked MAG not to share details of the ransom note, the extortion demands, or the group name" (The Register, 2026-08-27). The distinction matters for anyone reading this as a regulatory-timeline signal: engagement is on the record, a confirmed statutory filing is not.

NOTABLEupdatedNATOB2

Kudelski Security: North Korean IT-worker infrastructure overlaps a Bismarck-linked gambling-platform operation and the FakeCalls Android banking trojan

First published 2026-08-28 · open finding →

Correctionrun 2026-08-30T1312Z-auditbody

This entry said Kudelski's report treats Bismarck as distinct from the already-tracked PurpleDelta IT-worker cluster rather than as an alias. Kudelski's report never mentions PurpleDelta at all, so it makes no such judgement in either direction, and presenting a silence as a stated analytic position is a claim the source does not support. Replaced with what the report does and does not say.

Kudelski's report does not distinguish Bismarck from the PurpleDelta IT-worker cluster, because it never mentions PurpleDelta. This entry previously presented that distinction as the source's own analytic position. The report names Bismarck, the DPRK universities behind it and the "Base" system, and draws no comparison to any other tracked cluster (Kudelski Security, 2026-08-26). Whether Bismarck overlaps an existing cluster is therefore an open question, not one this reporting answers.

HIGHCVE-2026-19912 +1updatedNATOB2

Kaltura mwEmbed/html5lib video player: unauthenticated RCE and arbitrary file read via an undocumented ServiceUrl parameter; patched for legacy Player V2 after months of no vendor response, 630+ exposed instances found by the discoverer

First published 2026-08-28 · open finding →

Updaterun 2026-08-30T1312Z-audittitlesummarytagscvessourcing_noteevidencebodyupdated_at

Kaltura has patched. CERT/CC updated VU#308749 on 2026-08-28 at 19:59 UTC, after this entry was written, to state that patches now exist for every affected legacy Player V2 version, and to scope the flaws to that legacy line only: the currently supported Player V7 is not affected. Both CVE records move from no-patch to patched with the fixed release named, and the title, tags, summary and body no longer present this as an unpatched exposure.

Kaltura has released patches. CERT/CC updated VU#308749 on 2026-08-28 at 19:59 UTC, hours after this entry was published, and now states: "Kaltura has released new patches to remediate these vulnerabilities in all affected legacy Player V2 versions. Customers using legacy players, including self-hosted legacy player deployments (html5lib v2.x), should update to the patched version or, preferably, migrate to the newer and currently supported Kaltura Player V7 platform" (CERT/CC, VU#308749, updated 2026-08-28).

The same update narrows the affected estate, which this entry had left open: "only versions of the legacy player (Player V2) are vulnerable; these issues do not affect any versions of the currently supported Kaltura Player V7" (same advisory). So the scoping question for an institution running Kaltura is which player line its deployment sits on, not whether it is on a current server release, and self-hosted html5lib v2.x deployments are explicitly in scope. The 630+ internet-facing instances the discoverer found do not become safe by the patch existing; each still has to be updated or migrated.

HIGHupdatedNATOA1

DOJ/FBI seize domains behind QScan and QTRouter, the hacking-as-a-service platforms a PRC contractor sold to China's MSS and PLA, NASA, the Federal Reserve, DOJ, HHS, NIH and the US Senate named among the targets of QTFY, which DOJ separately dates to at least 2018; European infrastructure appears among Lumen's own profiled targets

First published 2026-08-28 · open finding →

Correctionrun 2026-08-30T1312Z-audittitleevidencebody

The quotation attributed to the Department of Justice was not what the release says. It was published as "Among the victims of QTFY computer intrusion activity are..."; the release reads "Among the targets of QTFY are...", and the phrase "computer intrusion activity" appears nowhere on the page. Naming an organisation a target of a platform is a weaker claim than naming it a confirmed intrusion victim, so the quotation, the sentence introducing it and the title have all been moved to what DOJ actually states. The title also no longer reads as though the 2018 dating attaches to that list: DOJ gives that date for QTFY activity generally, in the sentence announcing the FBI/NSA advisory.

The US agencies listed here are named by the Department of Justice as targets of QTFY, not as confirmed intrusion victims, and the quotation reproduced in this entry was not verbatim. The release reads: "Among the targets of QTFY are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate" (U.S. Department of Justice, 2026-08-26). The words "victims" and "computer intrusion activity" appear nowhere in that sentence. DOJ states the 2018 dating separately, about QTFY activity in general: "the FBI and National Security Agency published a cybersecurity advisory providing indicators-of-compromise by QTFY based on their analysis of QTFY malicious cyber activity dating back to at least 2018" (same release). For a defender reading this as a scoping signal the distinction matters: a target list says where the platform was pointed, not which of those organisations it got into.

NOTABLECVE-2026-53362exploitedupdatedNATOA2

Linux kernel IPv6 UDP fraggap accounting bug (CVE-2026-53362) added to CISA KEV, an unprivileged local heap overflow via MSG_SPLICE_PAGES, no exploitation narrative published

First published 2026-08-28 · open finding →

Correctionrun 2026-08-30T1312Z-auditcvessourcing_notebody

The CVE record said pre-auth while the entry's own quoted CVSS vector says otherwise. The vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H: local attack vector, low privileges required, meaning an unprivileged local user who can already open a UDPv6 socket, not an unauthenticated actor. Corrected to post-auth. This narrows who can reach the flaw but not its severity: the KEV listing and the local privilege-escalation impact are unchanged, and on a multi-tenant or shell-accessible host the prerequisite is trivially met.

This CVE was recorded as pre-auth, which contradicts the CVSS vector the entry itself quotes: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, score 7.8. PR:L means the attacker must already hold an unprivileged local account, and the trigger is a local user opening a UDPv6 socket with MSG_MORE and MSG_SPLICE_PAGES set together (upstream kernel fix commit 14200d43). It is a local privilege-escalation primitive, not a remotely reachable one. For scoping, that puts the exposure on hosts where untrusted code already runs, containers, shared shells, CI runners and multi-tenant systems, rather than on the network perimeter.

NOTABLEupdatedNATOB2

CNCMachineRMS, an undocumented remote-access trojan delivered through a four-stage BabaDeda loader chain that smuggles shellcode via a benign Windows date-formatting API

First published 2026-08-28 · open finding →

Correctionrun 2026-08-30T1312Z-auditevidencesourcing_notebody

Two quotations attributed to LevelBlue were not verbatim. The first dropped the executable name and reshaped the sentence; the second was a composite, splicing a bullet about screenshot-and-beacon behaviour together with a phrase about seven persistence mechanisms taken from a different paragraph, presented as one continuous quoted sentence. Both are replaced with the source's own contiguous wording, and the persistence-mechanism count is now quoted from the sentence that actually states it. No described behaviour changes: the facts were right, the quotation marks were not.

Two quotations here were not verbatim. The delivery quote is: "Infection starts with a ClickFix lure that launches a legitimately signed IBM SPSS IDE executable, WinWrapIDE.exe, whose scripting engine is abused to load a malicious DLL" (LevelBlue SpiderLabs, 2026-08-10); the executable is named in the source and was dropped here. The second was a composite that does not exist as a sentence anywhere in the article: LevelBlue writes "It takes a screenshot on first contact, then beacons every 600 seconds" as its own bullet, and separately that the decoded strings describe "a local account backdoor, seven persistence mechanisms, and twenty typed commands for staging and running whatever the operator sends next" (same article). Every behaviour this entry describes is still what LevelBlue reports; what was wrong was presenting two passages as one quotation.

HIGHCVE-2026-25085 +19updatedNATOB2

Claroty Team82: 23 vulnerabilities in Copeland XWEB Pro supervisory refrigeration controllers chain to unauthenticated root RCE; a deterministic admin password derived from the device's own MAC address is one of THREE independent pre-auth paths

First published 2026-08-28 · open finding →

Correctionrun 2026-08-30T1312Z-auditcvessourcing_noteactionsbody

This entry stated that CVE-2026-21718 is the deterministic admin-password flaw. Claroty does not say that. Its per-CVE table text for that identifier is generic ("an authentication bypass vulnerability... enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution", CVSS v3 10.0), and the narrative section that describes the MAC-address-and-date key derivation names no CVE id at all. The binding was an inference by elimination rather than a stated attribution, and a defender tracing the identifier to a patch note would have been misled. The mechanism description stands as reported; the id binding is removed from the title-adjacent claim, the CVE record's affected text, the body and the action, and the sourcing note now states what Claroty does and does not attribute.

Which CVE identifier covers the deterministic admin-password path is not something Claroty states, and this entry previously asserted it. Claroty's per-CVE table describes CVE-2026-21718 only as "an authentication bypass vulnerability... enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution" with a CVSS v3 of 10.0, while the section walking through the MAC-address-and-date key derivation attaches no identifier to it (Claroty Team82, 2026-08-09). The three pre-auth paths and the mechanism of each are unchanged, and so is the remediation: firmware v1.13 fixes the disclosed set. What changes is that an operator matching a specific identifier against a vendor patch note or an asset-management ticket should not expect CVE-2026-21718 to be documented anywhere as the password-derivation bug.

NOTABLECVE-2026-66747updatedNATOB2

ENDLESSDOORS (CVE-2026-66747); twenty Zbtlink router models ship from the factory with an unauthenticated root-command backdoor, and the discloser's remedy is replacement

First published 2026-08-06 · open finding →

Correctionrun 2026-08-30T1312Z-auditsummaryevidencebody

This entry said Zbtlink "has offered nothing", and the 2026-08-29 update called VulnCheck's device-replacement guidance "the only remediation position on record". Both are wrong, and the contradicting fact was in a source this entry already cites: heise reports that Zbtlink publicly announced it would suspend sales of the affected routers and take the affected firmware offline while working on updates. The vendor's position is now stated where those claims stood. The defender guidance does not change: no update has shipped, the statement does not cover DARKLANTERN or SPEAKINGSTONE, and deployed units still need replacement or strict egress control.

Zbtlink did respond publicly, and this entry said it had not. heise reports that the vendor announced an intention "to suspend sales of affected routers and take the affected software offline while updates are being worked on" (translated from German) (heise, 2026-08-28) - and that article is one this entry already cited. The 2026-08-29 update compounded it by calling VulnCheck's device-replacement guidance the only remediation position on record.

What this changes for a defender is small but real: there is a vendor engaged with the problem and a stated intent to ship firmware updates, so an asset owner has someone to press for a timeline. What it does not change is the guidance. No update has been published, the statement addresses ENDLESSDOORS and says nothing about DARKLANTERN or SPEAKINGSTONE, and a backdoor shipped in the factory image is not remediated by a sales pause. Deployed units still need replacement, or strict egress control with their LAN treated as untrusted.

NOTABLECVE-2025-8088exploitedupdatedNATOB2

Sekoia consolidates Gamaredon tooling under GammaPhish / GammaWorm, details an NTFS-ADS USB+network worm

First published 2026-06-02 · open finding →

Improvementrun 2026-08-30T1312Z-auditactionsclassificationtechniquesevidence

Four repairs: a first Admiralty rating, an evidence citation replaced, the ATT&CK mapping filled in, and a serialization fix. The single action string was a double-quoted YAML scalar holding a Windows path, so the backslash read as an escape and a standards-compliant parser rejected the whole frontmatter document; re-quoted single, stored value byte-identical. Added the Admiralty rating this entry predates: B2, matching its sourcing, since Sekoia TDR is an original research lab and the two corroborating outlets republish that report rather than assessing independently. Mapped the tradecraft the body already describes, which had been left empty: WinRAR CVE-2025-8088 exploitation, Startup-folder and scheduled-task and Run-key persistence, NTFS Alternate Data Stream hiding, dead-drop resolvers on legitimate web services, and script obfuscation. Propagation is mapped as tainting shared content on USB and network drives, which is what the report describes, rather than as credentialed access to remote shares, which it does not. Replaced the single evidence record, whose "quote" was a migration artefact reproducing an earlier summary of this entry's own update and attributing it to a publisher that never wrote it, with two verbatim passages re-read from Sekoia's report covering the initial-access and persistence mechanics the body describes. No claim in the entry changed.

Three things on this entry are now right that were not.

It carries a source-reliability rating it predated: B2. Sekoia TDR is an original research lab, and the two outlets alongside it republish that report rather than assessing the campaign independently, so corroboration does not lift the credibility number.

Its cited evidence was wrong. The single evidence record reproduced an earlier summary of this entry's own update and attributed it to a publisher that never wrote it. It is replaced with two passages quoted directly from Sekoia's report: "This archive exploits the CVE-2025-8088 vulnerability to extract a hidden HTA file directly into the user's Windows Startup directory. Upon execution, the HTA file leverages mshta.exe to call a remote payload hosted on a C2 server", and "Forensic analysis of compromised hosts revealed a highly obfuscated VBScript worm. It establishes persistence via scheduled tasks and actively conceals its core modules within NTFS Alternate Data Streams (ADS)" (Sekoia TDR, 2026-06-01).

Its ATT&CK mapping was empty despite a body describing a full chain, so nothing in this entry reached the technique matrix or the actor profile. It now maps the WinRAR exploitation, the Startup-folder and scheduled-task persistence, the Alternate Data Stream concealment, the dead-drop resolvers on legitimate web services (the exact sub-technique, not the parent web-service class), the tainting of USB and network-drive content, and the script obfuscation. No claim in the analysis changed.

CRITICALCVE-2026-42897exploitedupdatedNATOA1

CVE-2026-42897 Exchange OWA, EM Service auto-mitigation depends on outbound connectivity to officemitigations.microsoft.com

First published 2026-05-18 · open finding →

Improvementrun 2026-08-30T1312Z-auditactionsclassification

A first source-reliability rating, plus a serialization repair. The first action string was written as a double-quoted YAML scalar containing both a Windows-style path and escaped inner quotes, so a standards-compliant YAML parser rejected the whole frontmatter document; this repo's own lenient parser had always read the intended value. Re-quoted single so the backslash and the inner quotes stay literal. The stored value is byte-identical before and after, and no reader-facing text, claim or field value changed. The entry also carried no Admiralty rating, predating the always-classified gate; A1 is recorded, matching its sourcing: Microsoft's own advisory for its own product is A, and Proofpoint's independent analysis of the implant alongside Microsoft's disclosure is two parties who looked, so credibility 1.

This entry now carries a source-reliability rating, which it predates: A1 on the NATO Admiralty scale. The letter reflects Microsoft's own advisory for its own product, the number reflects independent corroboration, since Proofpoint analysed the implant separately from Microsoft's disclosure and NCSC-CH restated that analysis for its own constituency. Nothing in the assessment or the remediation guidance changes; the rating makes explicit what the sourcing already supported.

04Action items4 items

Verification & coverage notes2 runs

2026-08-30T1312Z-audit · audit · Opus 5 · window 47.7 h · 2 entries published

Verification & coverage notes

Duplicate-audit guard: overridden, and why. The gap to the previous audit record is 47.7 h, inside the 72 h guard. The guard was not applied because the record it measures against is not a quality audit: 2026-08-28T1500Z-audit was an operator-directed interactive editorial session on a sandbox with no external network. It ran no truth passes and no coverage re-sweeps, its own report states that URL-level re-verification of the entries it touched falls to the next network-enabled audit, and it left a named backlog for this fire. The last audit that did this work was 2026-08-24T0902Z-audit, six days ago. Standing down would have left 39 edited entries unverified against their sources and seven flagged residuals unadjudicated.

Window. 2026-08-28T13:30Z (the previous audit record's started) → now. 44 entries in scope: 8 published new by the 08-29 and 08-30 fires, 36 carrying a changelog record inside the window. The coverage re-sweeps used a wider 150 h window, back to the last independent re-sweep on 08-24, because the 08-28 session performed none.

Soundness: 19 of 44 entries clean. 11 factual errors, 14 imprecisions. Every factual error is addressed through that entry's changelog this fire, ten as corrections and one (Kaltura) as an update because the fact changed after publication; the imprecisions are documented in the report without records, per the rule against manufacturing improvements. The dominant defect class is quotation and attribution drift, six of the eleven: a word substituted in a DOJ quote that changes "targets" into "victims", a LevelBlue quote spliced from two paragraphs, a tracker's hedged non-finding restated as a federation's assurance, an analytic position attributed to a report that never mentions the actor in question. Three more are the entry disagreeing with its own evidence: an uncited EPSS figure roughly four times the live value, a CVE-to-mechanism binding reached by elimination and presented as the vendor's, and a cves[].auth field contradicting the CVSS vector the same entry quotes.

Two of the eleven turned on facts that changed or were unreachable when the entries were written, not on composition defects, Kaltura (CERT/CC published patches at 19:59 UTC on 08-28, hours after the fire and after the no-network session) and Zbtlink (a vendor statement present in a source the entry already cited). The Kaltura fix ships as an update rather than a correction and re-floats the entry: it had been telling readers there was nothing to install.

All seven residuals handed over by 2026-08-28T0409Z-intel are adjudicated. Four stand and are now fixed or documented (Claroty CVE binding, confirmed an undisclosed inference, corrected; Hunt.io ZKTeco finding, confirmed present and omitted, added; Unit 42 telemetry windows, confirmed over a year stale, documented; miniOrange third vulnerability; confirmed to exist but the source publishes no CVE id or CVSS for it, so nothing citable to add). One was wrong in a way the residual did not anticipate: the DOJ quote itself was fabricated, not merely spliced. One is resolved (the YOOtheme quote is now contiguous and verbatim). One is unresolvable (the SSD Secure Disclosure primary is still behind an anti-bot challenge) and redirecting it to the secondaries surfaced the Unisoc chipset error.

Completeness: eight items cleared the gate and are in no entry. Two are CISA KEV additions with confirmed exploitation, CVE-2026-21962 (Oracle HTTP Server / WebLogic Proxy Plug-in, CVSS 10.0, unauthenticated, exploited since January, government-sector target profile) and CVE-2026-60004 (Gitea, CVSS 9.8, effectively unauthenticated on a default install). The 08-28 fire read the KEV feed and surfaced four other additions from it; these two appear nowhere in that run, not even as drops. The other six are WatchGuard Fireware OS (two pre-auth RCEs in the IKE daemon, vendor "immediate action"), two Microsoft Threat Intelligence research posts, a Huntress DPRK-worker forensics post, the Norway ID-porten identity-gateway DDoS, and an unresolved Swiss lead blocked by an unreadable source.

Published this run (2 recovered entries, 13 changelog records, 0 deep dives, 0 critical):

  • 2026-08-30/cve-2026-21962-oracle-http-server-weblogic-proxy-plugin-kev (high) - CISA KEV 2026-08-24, CVSS 10.0, unauthenticated access-control bypass in the WebLogic Server Proxy Plug-in and Oracle HTTP Server, exploited since 22 January per CloudSEK honeypot telemetry, with SOCRadar placing it in a China-nexus operator's government-focused campaign. Clears PD-11(b) on confirmed exploitation of a pre-auth flaw on the DMZ tier.
  • 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev (high) - CISA KEV 2026-08-25, CVSS 9.8, Git-hook code injection via the diffpatch endpoint, effectively unauthenticated wherever Gitea's default open registration is left on, confirmed exploited by automated scanning. Clears PD-11(b) on the same ground.

Two of the eight are recovered as entries in this fire; six stay backlogged. The two KEV-confirmed exploited vulnerabilities are the case PD-11 says must never be deferred into invisibility, so they are composed and published here through the normal gates. The other six are recorded as open rows in state/coverage_backlog.md with primary sources and gate reasoning, which exempts them from the recency gate and puts each in front of the next fire; the priority order puts the truth passes and their eleven corrections first, and six further compositions would have pushed this run past its wall-clock guard. If the six are still open at the next audit, the fix below did not work.

Root cause of the KEV misses, and the fix. Sweeping the KEV catalogue was purely attentional, a research sub-agent read the feed and returned what it noticed, and nothing downstream could tell a considered drop from an unseen row. v4.8 adds tools/kev_window_diff.py and Phase 0 step 6b: every KEV addition inside the window is listed mechanically and marked against the store, and every uncovered row must end the run with a disposition, an entry, an update record, or an explicit borderline-drop: line. Judgement stays with the agent; not knowing the row existed does not.

The tool was run live this fire (work/2026-08-30T1312Z-audit/kev-window.txt): 11 KEV additions since 08-24, 6 not covered. Two are the gaps above; the other four are the legacy UAT-10147 batch, which the two 2026-08-23 UAT-10147 entries discuss in prose without carrying cves[] records, so they are covered for a reader and invisible to every machine surface built on that field. Surfaced, not fixed this fire; it belongs with the next audit's pass over that cohort.

Second systemic finding: ATT&CK mapping density on threat entries fell from 12.6 and 11.1 ids per entry over the two preceding windows to 4.3 in this one, while incident and vulnerability stayed roughly flat. Two changes landed together on 08-28 (the first Sonnet 5 fires, and the v4.2 brevity hardening), so causation cannot be separated from three fires of data and is not claimed. What is stated is a mechanism the prompt contained: the anti-hallucination rule binds techniques[] to behaviours the body describes, and v4.2 shortened bodies, which made prose length a cap on the mapping surface. v4.8 decouples them; the mapping is bound to what the sources describe, and the evidence floor is restated as source evidence rather than body length.

Previous fixes: all took, with one leak and one half. The 08-24 audit's completed-stamp fix holds on every subsequent record. The 08-28 session's internals-out-of-reader-text fix holds in bodies but leaked into one sourcing_note on the very next fire; its English-only-quotations fix and its model pins hold cleanly; its source promotions are half successful (heise contributes, inside-it.ch 403s on every transport). Full table in the report.

Reduced-confidence note (aggregator-only): 2026-08-28/unisoc-volte-mpu-isolation-bypass-android-kernel still rests on two news-aggregator sources. The SSD Secure Disclosure primary was re-attempted on every transport this fire and is still behind an anti-bot challenge, so no re-pivot was possible. The correction this fire applied narrows the entry to exactly what those two secondaries state, and its confidence stays medium.

Legacy debt cleared where the portability fix surfaced it. Re-quoting a non-portable frontmatter scalar pulls the entry into run scope, and two of the three then failed checks that pre-date them. Both were repaired in the same changelog record rather than deferred: 2026-05-18/cve-2026-42897-… gained its first Admiralty rating (A1), and 2026-06-02/sekoia-consolidates-gamaredon-… gained a rating (B2), an evidence-bound techniques[] mapping of the tradecraft its body already described, and two verbatim Sekoia passages replacing an evidence[] record whose "quote" was a migration artefact reproducing this pipeline's own update summary under a publisher byline that never wrote it.

Watchlist: no product or supplier watchlist configured; both sweeps were no-ops and the sector/region lens was applied in their place.

Coverage gaps: ssd-disclosure and inside-it-ch unreachable on every transport, both for the second consecutive fire. google-tag's recipe gap persists.

Essential-coverage: 16 of 17 essential-tier sources contributed cited URLs since 08-24; inside-it-ch is the exception and is a new watch item.

Warning sweep to zero. Nine warnings at Phase 0, all settled run-record history, all acknowledged in state/warning_acknowledgments.json with reasons and each explicitly declining the code change that would weaken the check: seven runaway duration_seconds and two unconfirmed final CLEANs. Three of the seven durations are one story, the 08-21, 08-22 and 08-23 containers stalled and were all finished on 08-24, so those figures are elapsed container lifetime rather than work. The existing 16 rows were reviewed and all still silence a live warning; none pruned. A tenth warning class was introduced by this fire's own new frontmatter-yaml check and fixed rather than acknowledged: three entries carried frontmatter only this repo's lenient parser could read. All three are re-quoted, and the two that turned out to carry further pre-v3.18 debt once the fix pulled them into run scope were repaired in the same record rather than deferred. check_run.py --all ends 0 warn · 0 fail (25 acknowledged).

ATT&CK pin: attack_data.py --check reports local v19.2 == upstream latest v19.2. No drift, no update needed.

Priority calibration: not due; the 2026-08-02 report carries this calendar month's. The high share of operational entries rose to 59.0 % this window against 46.2 % last and 51.1 % store-wide, a 13-point single-window jump; recorded for the September fire to judge rather than adjudicated here.

Notification: none sent. No priority: critical finding and no pipeline breakage, per the operator's standing order.

2026-08-30T0410Z-intel · Sonnet 5, session-configured value (no harness self-ID line or env var available to the main agent this run) · window 26 h · 1 entry published

Verification & coverage notes

Coverage window: standard cadence (gap_hours 24.01 since the previous run, 2026-08-29T0409Z-intel; window_hours 26 per the hard 24h floor plus overlap). 2026-08-29/30 fell on a weekend, visibly suppressing publishing cadence across every source slice relative to the preceding Friday; the active-threats/vulnerabilities sweep and the research/investigative sweep both independently confirmed a genuine quiet window rather than a transport or recipe failure.

Published this run (1 new, 0 updates, 0 deep dives, 0 critical):

  • 2026-08-30/berlin-landesnetz-rhysida-extortion-phishing-vector (high), closes a coverage-backlog item open since 2026-08-20 (seven consecutive prior fires blocked on the same ground): Rhysida ransomware named as the actor behind the Berlin state-government Landesnetz compromise, and investigative journalism (Der Tagesspiegel) names the first access vector of any kind, a phishing-email click. Clears the relevance gate on a direct primary-sector nexus (a public-sector/government-administration incident, matching this deployment's own primary sector) and, independently, on the actor: Rhysida is a documented, sustained DACH public-sector extortion operator (nine prior German victims, an earlier Stuttgart claim already in the registry) that plausibly also targets this constituency's core. The home-region/sector sweep and the incidents/disclosures sweep independently surfaced the same story; composed from the union of both findings plus a direct deep read of the Tagesspiegel, heise, Security Affairs, BornCity and CISA primaries. Registered under the existing registry stub incident:berlin-landesnetz-compromise-2026-08 (no entry file had ever been composed for it) rather than a new entity key.

Borderline drops:

  • borderline-drop: McKesson (US pharmaceutical distributor) ShinyHunters breach, no direct Swiss/EU public-sector nexus (US healthcare business units); the disclosed technique (vishing into Okta SSO, then Salesforce/Snowflake exfiltration) is not new or materially evolved; this store already carries the same ShinyHunters vishing-to-SSO-to-SaaS chain against Odido, Madison Square Garden, Brinks Home, EY and NAIC among others, and McKesson adds no lesson those entries do not already teach for this constituency. The actor is already tracked with confirmed EU targeting, but a same-actor read alone does not by itself clear the out-of-nexus breach gate absent a new angle.

Contradiction: 2026-08-30/berlin-landesnetz-rhysida-extortion-phishing-vector; Security Affairs states Berlin first disclosed the compromise on 2026-08-17; Berliner Zeitung, Der Tagesspiegel and rbb24 (all independently fetched and cited in the same entry) converge on 2026-08-14 for both public disclosure and department isolation. The entry follows the three-source consensus and records the discrepancy in its sourcing_note.

Coverage-backlog re-check: all six previously-open rows re-gated on today's facts. Struck: the Berlin Landesnetz row (published, see above). Stayed open, untouched or lightly re-checked at low cost: Zurich District Court verdict (not due until 2026-09-10); Siemens S7 joint-advisory re-read (low priority, not re-probed); CVE-2026-16242 OpenShift/HyperShift (still out of window); the Keycloak Red Hat product-state correction (low priority, meta-fact only); Boston Scientific cybersecurity incident (re-checked news.bostonscientific.com's 2026-08-29 update, CrowdStrike now named as the IR firm, scope confirmed on-premise-only, but still no attacker attribution, vector, or ransom claim from any party; the blocking condition, no evidence-bound ATT&CK mapping possible, has not resolved).

Single-source items: none; the one published entry is multi-source (six independent outlets fetched and cited).

Watchlist: no product or supplier watchlist configured for this deployment (config/org-profile.yaml); the product and supplier sweeps were no-ops as a result; the sector/region lens was applied in their place.

Coverage gaps: schneier (Atom feed returned zero items via the jina fallback transport); inside-it.ch's "Insel Gruppe verschiebt Wechsel zu ServiceNow" article (403 on every transport tried, flagged as a lead pointing to a possible Bern-hospital-group security incident, not corroborated); cisa-advisories, cisa-directives (reachable, but no server-rendered listing content this run; two consecutive runs now, per the state digest's fetch_gaps_in_window; KEV JSON and CSAF mirror covered the exploited-vulnerability and ICS surfaces in their place); edpb, us-treasury-ofac (bridge returned page chrome without the actual listing; no lead pointed to either source this run).

Essential-coverage: no misses; all essential-tier sources across all four domains were attempted and returned content (even where that content held no in-window item).