CTIPilot
Tue · 01 Sep 2026
All daily briefs ↗
Daily brief · UTC day

Tuesday, 1 September 2026

3 verified findings from 1 run · 3 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

ACT NOW · CRITICALCVE-2026-82329 · exploited · 7 sources · 01 Sep 04:11Z

JFrog patches a default-configuration authentication bypass that hands an unauthenticated network attacker full Artifactory admin

JFrog disclosed CVE-2026-82329 on 2026-08-28, a Critical (CVSS 9.8) authentication weakness in Artifactory that, under default configuration, lets an unauthenticated attacker with only network access obtain administrative privileges. Self-hosted branches across six release lines are affected; JFrog-hosted cloud instances were already remediated. The flaw is now confirmed under active exploitation, with attackers minting administrator tokens within days of the patch.

CVE-2026-82329 (CVSS 9.8) is a pre-auth authentication bypass that hands an unauthenticated network attacker full administrative access to Artifactory under default configuration, and watchTowr's Attacker Eye honeypot network has recorded real-world exploitation since 1 September, attackers minting admin tokens and enumerating users, groups, credential sets and federated access topologies within days of the 28 August patch. Any unpatched, self-hosted, internet-reachable instance should be treated as already probed: patch to the fixed build for its branch immediately, then inspect JFrog Access and audit logs for admin-scoped tokens minted without a preceding interactive admin login and rotate every credential the instance held; an admin-compromised Artifactory instance is a software-supply-chain pivot point.

Open the full advisory to act →
Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01JFrog patches a default-configuration authentication bypass that hands an unauthenticated network attacker full Artifactory admin. JFrog disclosed CVE-2026-82329 on 2026-08-28, a Critical (CVSS 9.8) authentication weakness in Artifactory that, under default configuration, lets an unauthenticated attacker with only network access obtain administrative privileges. Self-hosted branches across six release lines are affected; JFrog-hosted cloud instances were already remediated. The flaw is now confirmed under active exploitation, with attackers minting administrator tokens within days of the patch.
  2. 02Kaspersky documents ValleyRAT distributed through a trojanized adware installer that disables Defender before loading the backdoor via DLL sideloading. Kaspersky's Securelist documents a ValleyRAT (Winos 4.0) distribution chain hidden inside a re-signed copy of QN Wallpaper, a genuine Chinese desktop-wallpaper adware tool. The installer disables Windows Defender via the registry before a signed process sideloads a malicious DLL that decrypts and launches the backdoor, which can optionally mark itself a critical process and inject a self-restoring watchdog into svchost. Kaspersky attributes the campaign to Silver Fox and separately recorded over 100,000 detections of ValleyRAT across all of 2026, concentrated in China and India.
  3. 03Anthropic force-revokes Claude sessions hijacked by infostealer-harvested cookies, bypassing password and 2FA entirely. Anthropic began emailing affected users in the days before 2026-08-31 after finding that a threat actor was picking stolen Claude (claude.ai) login sessions out of commodity infostealer logs and replaying them to access accounts and consume paid usage. The malware families named are Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs; because a stolen session cookie authenticates as an already-logged-in user, the technique bypasses password and 2FA entirely. Anthropic revoked affected sessions, stripped saved payment methods, and refunded unauthorized charges.

01Active threats, incidents & disclosures2 items

NOTABLENATOB2

Infostealers now specifically monetize hijacked Claude sessions: Anthropic revokes sessions compromised via Vidar, LummaC2, StealC, RedLine, Acreed and AMOS

Anthropic sent emails to affected users last week, according to Help Net Security's 2026-08-31 report, to say a threat actor had stolen active Claude (claude.ai) login sessions using general-purpose infostealer malware already resident on those users' machines, then replayed the stolen session cookies to access the accounts and consume paid usage (Help Net Security, 2026-08-31; Anthropic, via BleepingComputer, 2026-08-30). Anthropic names the malware families involved as Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs (Anthropic, via Help Net Security, 2026-08-31); all commodity infostealers whose logs are traded on criminal markets. Anthropic states the infection vector is unrelated to Claude itself, typically an unofficial download or a malicious app; the case that surfaced publicly traced to a pirated-game download (BleepingComputer, 2026-08-30).

Because a stolen browser session cookie authenticates as an already-logged-in user, the attacker bypasses password and two-factor authentication entirely; Dark Reading frames the incident as part of a broader shift, as stronger password policies and wider MFA adoption make traditional credential theft harder, toward attackers targeting session cookies and tokens to hijack already-authenticated sessions instead (Dark Reading, 2026-08-31). Anthropic's remediation was to invalidate the stolen sessions, strip saved payment methods from affected accounts, and refund unauthorized charges; it explicitly warns that signing a user out does not remove the infostealer itself, so an unremediated host will have its next session stolen the same way (Anthropic, via BleepingComputer, 2026-08-30).

Triage: the discriminating signal Anthropic itself points users to is a usage allotment that "refilled and then drained" while the subscriber was not using Claude (Anthropic, via BleepingComputer, 2026-08-30). A legitimate usage spike correlates with the account owner's own activity; a drained allotment with no corresponding use by the account owner is the anomaly infostealer-driven session replay produces.

We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage

Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware,

If it's still on your computer, your next login session could be stolen the same way.

Anthropic (email to affected users, via BleepingComputer)

The malware identified in this campaign so far include Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs

Anthropic (email to affected users, via Help Net Security)

If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause,

Anthropic (email to affected users, via BleepingComputer)
threat01 Sep 04:11Zsingle-source · victim disclosureOpen finding ↗
NOTABLENATOB1

ValleyRAT (Winos 4.0) hides inside a re-signed Chinese wallpaper app: DLL sideloading, a self-restoring svchost injection, and a Windows Defender kill switch

Kaspersky's Securelist published an analysis on 2026-08-31 of a ValleyRAT (Winos 4.0) distribution chain hidden inside a re-signed copy of QN Wallpaper, a genuine Chinese desktop-wallpaper and adware-bundling tool. The installer drops a modified QN Wallpaper build and adds it to autorun; before launching the adware, it flips the DisableAntiSpyware registry key to disable Windows Defender, relaunching itself via runas first if the logged-in user lacks administrator rights (Kaspersky Securelist, 2026-08-31; The Hacker News, 2026-08-31). QnWallpaper.exe then loads a malicious libcef.dll placed alongside it (DLL sideloading through a signed, trusted process) which decrypts an AES-encrypted ValleyRAT payload and hands it control via DllMain; the backdoor's own command-and-control configuration is stored as a reversed key:value string to defeat static string scanning (Kaspersky Securelist, 2026-08-31).

Runtime protections are read from the malware's own configuration and each can be switched on or off independently: marking the process critical (so killing it forces a system crash), injecting a watchdog into svchost that toggles its memory region from no-access to fully executable to relaunch the implant if interrupted, and enumerating open windows to detect security or traffic-analysis tooling before proceeding; a fourth resilience mechanism (restarting the backdoor on an unhandled exception) is always active regardless of that configuration (Kaspersky Securelist, 2026-08-31). Spyware functions run through DirectInput8 hooks for keystroke capture and a separate clipboard-capture routine, both writing collected data to disk; on operator command the backdoor can pull and execute additional modules, using process hollowing into svchost when a module arrives as raw shellcode. Kaspersky's account of this specific campaign is based on one installer submitted by a customer, and its report stops short of attaching a victim count to this adware-distribution route; separately, and across all of 2026 rather than this campaign alone, Kaspersky recorded over 100,000 detections of ValleyRAT and associated malware affecting more than 1,500 unique users, concentrated in China and India (The Hacker News, 2026-08-31). Kaspersky attributes the campaign to Silver Fox, an established ValleyRAT operator, on geography and payload grounds (Kaspersky Securelist, 2026-08-31). DLL sideloading through signed, legitimate software is an established part of Silver Fox's toolkit, previously documented by Cato Networks against a Japanese manufacturer roughly five weeks earlier (The Hacker News, 2026-08-31). That campaign postdates a June 2026 Chinese police crackdown that arrested 67 people linked to Silver Fox across five provinces, evidence the group's operations continued despite the arrests; this QN Wallpaper campaign's own timing is not independently established beyond Kaspersky's 2026-08-31 publication date, so it cannot be dated relative to the arrests with the same confidence (Risky Bulletin, 2026-06-17).

Triage: genuine Chromium Embedded Framework processes (many legitimate desktop apps embed CEF) load libcef.dll from their own install directory and never inject code into svchost that toggles between no-access and executable memory states; that combination (a wallpaper or adware-class binary invoking CEF at all, paired with the svchost memory-protection change) is what separates this chain from ordinary CEF usage when that optional watchdog is present in the sample.

Over the course of 2026, we detected the ValleyRAT backdoor and its associated malware more than 100,000 times, with more than 1500 unique users affected, primarily in China and India.

After unpacking, the installer uses the DisableAntiSpyware registry key to disable Windows Defender and then launches QnWallpaper.exe.

This attack geography, combined with the use of the ValleyRAT backdoor, points to Silver Fox, a known operator of this malware family, as the likely group behind the campaign.

Kaspersky Securelist 2026-08-31

When the logged-in user lacks administrator rights, the malware relaunches itself with runas to acquire them.

The Hacker News 2026-08-31

Restarting on an unhandled exception. This protection mechanism is always active, regardless of the backdoor’s configuration.

Kaspersky Securelist 2026-08-31

Arrests took place across five provinces and targeted everyone from developers to phishing site operators and various affiliates.

Risky Bulletin 2026-06-17
threat01 Sep 04:11Zmulti-sourceOpen finding ↗
CRITICALCVE-2026-82329exploitedupdatedNATOA2

CVE-2026-82329, JFrog Artifactory: an unauthenticated attacker gets administrative access under default configuration (CVSS 9.8)

JFrog disclosed CVE-2026-82329 on 2026-08-28: an authentication weakness in Artifactory, its widely deployed CI/CD binary and artifact repository, that under default configuration lets an unauthenticated attacker with only network access obtain full administrative privileges (GitHub Advisory Database, 2026-08-28). CVSS 3.1 base score is 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and the flaw carries CWE-287, Improper Authentication. JFrog has not published the specific request path or authentication defect being bypassed, so defenders cannot yet reason about a concrete exploitation signature beyond the precondition: a self-hosted, network-reachable instance still on its default configuration (IONIX Threat Center, 2026-08-31).

Self-hosted branches 7.111.4 through 7.111.20, 7.117.0 through 7.117.27, 7.125.0 through 7.125.19, 7.133.0 through 7.133.28, 7.146.0 through 7.146.36 and 7.161.0 through 7.161.19 are affected; fixes shipped the same day in 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20 respectively, per each fixed release's own "CVEs Addressed" listing (JFrog Artifactory Self-Managed Release Notes, 2026-08-28). JFrog's summary advisory table names the same six fixed versions but its "Versions" column is internally inconsistent for the 7.111 branch alone (it prints the fixed version, 7.111.21, as the range's own end rather than the last affected build) so the affected/fixed boundaries above are drawn from the per-release notes, the more granular and internally consistent source, rather than that summary column (JFrog Security Advisories, 2026-08-28). JFrog-hosted cloud environments were already remediated before disclosure and need no customer action (JFrog Security Advisories, 2026-08-28). No party reported observed in-the-wild exploitation at disclosure, but the flaw's own mechanics (pre-auth, no user interaction, network-reachable, full admin takeover) put it in the imminent-exploitation risk class for any instance an attacker could reach, particularly since Artifactory instances custody CI/CD credentials and build artifacts; a risk the update below confirms materialized within days. This is a distinct vulnerability from CVE-2026-66384, the Medium-severity, KEV-listed Docker-cache path-traversal bug on the same product already covered separately (patched 12 August); this critical-severity flaw is the more severe of the two Artifactory vulnerabilities to surface within the same August 2026 release cycle.

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

GitHub Advisory Database (NVD mirror) 2026-08-28

The flaw carries a CVSS v3.1 base score of 9.8 (Critical) and requires no authentication, privileges, or user interaction to exploit.

IONIX Threat Center 2026-08-31

Current exploitation status: Actively Exploited

NCSC Switzerland (GovCERT.ch) Cyber Security Hub 2026-09-01

Instances without an additional join key configured receive a 'phantom' join key that attackers can abuse to forge access and mint administrator-level credentials.

The Hacker News, quoting Yordan Ganchev (watchTowr)

Data from watchTowr's global Attacker Eye honeypot network shows attackers minting administrator tokens and enumerating users, groups, credential sets and federated access topologies.

SecurityWeek, quoting Yordan Ganchev (watchTowr)
Updaterun 2026-09-02T0411Z-intelcvestagstechniquesactionspriorityimmediate_actionsummarysourcesevidenceclassificationsourcing_note

CVE-2026-82329 has moved from disclosed to actively exploited. NCSC Switzerland's advisory, created 2026-09-01, records the current exploitation status as "Actively Exploited" (NCSC Switzerland Cyber Security Hub, 2026-09-01), and watchTowr's own telemetry independently caught the same activity: "this moved from disclosure to real-world exploitation with uncomfortable efficiency," per watchTowr's Yordan Ganchev (The Hacker News, 2026-09-01). Data from watchTowr's global Attacker Eye honeypot network shows attackers minting administrator tokens and enumerating users, groups, credential sets and federated access topologies (SecurityWeek, 2026-09-01). watchTowr names the mechanism: the flaw sits in JFrog Access, the component that issues and validates Artifactory credentials, and an instance with no additional join key configured receives a default "phantom" join key that an unauthenticated attacker can abuse to forge access and mint administrator-level credentials (The Hacker News, 2026-09-01), reconnaissance consistent with staging a software-supply-chain pivot into the binaries and containers Artifactory distributes downstream. As of 1 September, CISA had not yet added CVE-2026-82329 to its Known Exploited Vulnerabilities catalog (SecurityWeek, 2026-09-01).

Given confirmed active exploitation of a pre-auth, no-interaction path to full administrative control of a system that custodies CI/CD credentials and build artifacts, this entry's priority moves to critical.

Defender takeaway (updated): treat any unpatched, internet-reachable, self-hosted instance as already probed. Beyond patching, inspect Artifactory audit logs and JFrog Access logs for admin-scoped tokens minted with no preceding interactive admin login, review newly created or modified users, groups and permission targets, and rotate every credential the instance held.

Builds on: 2026-08-28/cve-2026-66384-jfrog-artifactory-docker-cache-traversal-kev

vulnerability01 Sep 04:11Zmulti-sourceOpen finding ↗

03Updates to prior coverage3 items

HIGHCVE-2026-62911updatedNATOB2

CVE-2026-62911, Microsoft Exchange Server MRSProxy: a missing channel-binding check lets a relayed Negotiate authentication take over every mailbox, public exploit code now live sixteen days after the patch

First published 2026-08-29 · open finding →

Updaterun 2026-09-01T0411Z-intelsourcesevidenceactionscvessourcing_notebody

Germany's CERT-Bund (BSI) disclosed on 2026-08-28 that roughly 85% of on-premises Exchange servers in Germany remain vulnerable to CVE-2026-62911 despite the patch having shipped over two weeks earlier and public exploit code being live; BSI has been proactively notifying network operators since 2026-08-14. For Exchange 2016/2019, now supported only through paid Extended Security Updates, BSI knows of just nine German servers with the ESU patch installed. Separately, CERT-Bund and NCSC-NL (both independently, and neither cited for this point before now) explicitly describe the flaw as exploitable without authentication at all, against MSRC's own CVSS vector alone (PR:L/UI:R, "authorized attacker"); this entry now describes the flaw as exploitable pre-authentication, corrected from an earlier post-auth framing, to follow that weight of evidence. A third-party technical write-up (MB VRED) offers its own hypothesis, not a confirmed finding, narrowing what that "unauthenticated" characterization might mean in practice: an attacker with an existing foothold on the internal domain network coercing one Exchange server's machine-account authentication via MS-EFSR/PetitPotam and relaying it to a second Exchange server's MRSProxy endpoint, needing at least two Exchange servers in the environment, presented alongside, not overriding, this entry's national-CERT-weighted auth:pre-auth determination. MB VRED's own caveat that real-world exploitation needs "lot of non-realistic conditions" is included for balance.

Following a press inquiry, Germany's CERT-Bund (part of the BSI) disclosed on 2026-08-28 that most of the country's on-premises Exchange population had still not applied the August patch: "Currently, however, around 85% of on-premises Exchange servers in Germany are still vulnerable to this vulnerability" (translated from German) (CERT-Bund, 2026-08-28). BSI states it has been proactively notifying German network operators about still-vulnerable systems in their networks since 2026-08-14 (heise Security, 2026-08-31). For the small population of Exchange 2016/2019 installs still supported only through the paid Extended Security Updates program, BSI says it is aware of only nine servers in Germany with the ESU patch installed (BSI, via heise Security, 2026-08-31). BSI's standing advice is unchanged: restrict internet-facing access to an Exchange server's web-based services to trusted source IP ranges, or place it behind a VPN.

This is the operationally important delta for any DACH-region on-prem Exchange operator, including Swiss cantonal and communal administrations running Exchange on-premises: German telemetry indicates that most operators in a comparable environment have not applied a two-week-old patch against a pre-auth, mailbox-wide takeover chain with public exploit code. "We applied the August patch" should be verified against the actual installed build number, not assumed from a routine patch-cycle checklist.

NOTABLEupdatedNATOC2

A Zurich business school tells students their bank details and sick-leave records were stolen, not from its own systems, but through the infrastructure of an IT service provider whose leak-site listing names seven other Swiss customers alongside it, and does not close the list

First published 2026-08-23 · open finding →

Updaterun 2026-09-01T0411Z-intelsummarysourcesevidencebody

Inside IT reported on 2026-08-31 that data from the breach has been published on the dark web, attributing the provider-side intrusion to a ransomware group with its own "offenbar" (apparently) hedge, superseding HWZ's 2026-08-26 position, given to Netzwoche, that it had no indication the stolen data had been published or misused. The provider's identity remains unnamed by any source other than the leak-site listing.

Inside IT reported on 2026-08-31, under the headline "HWZ-Daten landen im Darkweb" ("HWZ data lands on the dark web"), that data from the breach has been published; the outlet attributes the provider-side intrusion to a ransomware group but hedges that attribution itself with "offenbar" (apparently) (Inside IT, 2026-08-31). That supersedes the position HWZ gave Netzwoche on 2026-08-26, when the school stated there were no indications the stolen data had been published or misused (Netzwoche, 2026-08-26). HWZ's confirmation that personal data are among the stolen records (quoted by Inside IT in the same article, but itself given to a separate Inside IT report the prior week) restates rather than extends what this entry already established from HWZ's original letter to students. The named provider's identity is still established only by the extortion group's own leak-site listing, and no source has named it independently.

HIGHupdatedNATOA1

Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution

First published 2026-08-04 · open finding →

Updaterun 2026-09-01T0411Z-intelsummarytechniquessourcing_notesourcesevidencebody

NZZ reporting from the government's own 2026-08-04 press briefing, sourced to Liechtenstein IT-office director Fabian Schmid, names the access mechanism this entry previously recorded as undisclosed: the attackers reached the register through a vulnerability in its reporting portal rather than the database directly, registered a new user account, and queried every record individually; the interface has no bulk-query function, so downloading all 31,000 records took several hours.

The access vector this entry previously recorded as undisclosed is now named. Reporting from the Neue Zürcher Zeitung, sourced to Liechtenstein's Office for IT director Fabian Schmid speaking at the government's 2026-08-04 press briefing, states that the attackers did not reach the register's database directly: they exploited a vulnerability in the register's reporting portal, or in the interface between that portal and the database, to scrape the complete dataset (Neue Zürcher Zeitung, 2026-08-07). To do so, they registered a new user account on the portal and then queried every one of the roughly 31,000 records individually; the interface has no bulk-query function, which is why the download took several hours (Neue Zürcher Zeitung, 2026-08-07).

04Action items1 item

Verification & coverage notes1 run

2026-09-01T0411Z-intel · Sonnet 5 · window 26 h · 3 entries published

Verification & coverage notes

Standard window (gap_hours=24.0, window_hours=26). No closed-source intake this run. Mechanical KEV sweep (tools/kev_window_diff.py) found 2 in-window additions (CVE-2026-81578, CVE-2026-82078, both PaperCut), both already covered.

New entries (3): CVE-2026-82329 (JFrog Artifactory default-config admin bypass, high), ValleyRAT/Winos4.0 via a re-signed QN Wallpaper installer (Kaspersky, notable), Anthropic Claude session-hijacking via commodity infostealers (notable). Updates (4): CVE-2026-42271 LiteLLM (internal metadata correction, cvss/vector fixed to match the entry's own already-cited GHSA), the Liechtenstein VwbP breach (NZZ names the access vector, portal-interface vulnerability, new-account registration, one-by-one enumeration), the HWZ/Payload provider breach (data now published; HWZ confirms personal data), and CVE-2026-62911 Exchange MRSProxy (BSI: ~85% of German on-prem Exchange servers still unpatched two weeks after the fix, with public exploit code live).

  • Run duration (~3.0 h) exceeds the normal runaway threshold: the cause is an unusually productive verification loop, not a stall or a broken step. Eight verification iterations ran back-to-back (the pipeline's iteration cap), together surfacing and fixing over twenty genuine truth and editorial defects across the new and updated entries, including a material auth-precondition correction on the Exchange MRSProxy entry (post-auth to pre-auth, later refined with a third-party technical caveat), an EPSS-convention self-correction, a chronology error on the HWZ update, and a severity-overstatement fix on the JFrog entry. The final iteration (8) returned CLEAN, but because the prior iteration (7) had returned NEEDS_FIXES, this is a CLEAN-but-unconfirmed result published under the fail-open cap rule rather than a double-CLEAN confirmation (see verification.confirmation_waived above). No step stalled or errored; every phase completed normally, just slower than usual given how much the verifier found to fix.
  • borderline-drop: McKesson/ShinyHunters healthcare data-theft extortion (US, 284M claimed records, $55.2M demand), no home-region or sector nexus for this constituency; the transferable lesson (the <company>.claims vishing-domain pattern) is real but not novel to this incident (ReliaQuest had already flagged the pattern), the claimed scale is the actor's own unconfirmed figure, and the case that this actor also plausibly targets this constituency is thin. Dropped on balance of doubt.
  • borderline-drop: Ixa Systems SA (Crissier, VD) / TheGentlemen leak-site listing, a small Swiss physical-security integrator naming police/prison/hospital clients, but a bare single-source leak-site claim with no victim confirmation and no reputable independent journalism does not meet the bar to publish. Held open in state/coverage_backlog.md given the sensitivity of the claimed client base; re-check on a later fire.
  • Aggregator-only sourcing (checked, unfixable today): the Anthropic Claude session-hijacking entry's three sources are all press outlets (BleepingComputer, Dark Reading, Help Net Security), a fair-attempt search of anthropic.com/news, trust.anthropic.com and support.claude.com found no independent Anthropic post or advisory on this campaign; the primary is genuinely Anthropic's direct user-facing email to its own affected users, reproduced with consistent wording by three separate outlets with no independent confirmation. verification: single-source-victim and classification: {reliability: B, credibility: 2} reflect that reality (corrected from an initial multi-source/credibility-1 miscalibration during this run's own verification loop); check_run.py's aggregator-only WARN is expected to persist until Anthropic publishes something more official.
  • Coverage gap: research this run identified four substantive stories (Aurora ransomware operators' use of Cursor AI per CloudSEK/Gambit Security; ReliaQuest's Gryxa AI-built toolkit; Sygnia's Fire Ant actor profile; a Team Cymru Cl0p retrospective) published 2026-08-27 through 2026-08-30 that correctly fall outside this run's 26-hour recency window, but none appears in prior_coverage.json either, meaning they fell through the gap between two consecutive same-day-lookback windows. This is a structural artifact of back-to-back daily windows on stories that broke mid-window, not a research miss this run could have closed without publishing stale material. Flagging for the next quality audit's coverage re-sweep to assess whether any are still worth publishing today.
  • Registry hygiene: incident:silver-fox-arrests-china-2026 (first_seen 2026-06-18) had no entry file referencing it, an apparent orphan from the v4.0 weekly-routine purge (2026-08-29). This run's own verification loop surfaced a genuine connection to the new ValleyRAT/Silver Fox entry (both that entry and the July 2026 Japanese-manufacturer campaign postdate the June 2026 arrests): added a sourced related-to relation from actor:silver-fox to the incident record, closing the orphan.
  • Source health: inside-it-ch resolved cleanly on the first attempt this run after three consecutive whole-host failures (2026-08-29 through 2026-08-31), see sources_changed[]. Separately, the long-standing state/coverage_backlog.md row for the Insel Gruppe/ServiceNow lead is now diagnosed as a subscriber-paywall problem rather than a transport block: the specific article (inside-it.ch/insel-gruppe-verschiebt-wechsel-zu-servicenow-20260828, dated 2026-08-28) fetches cleanly at the metadata level but its body remains paywalled; no corroborating Swiss outlet was found on a targeted search.
  • zataz promoted candidate→active per the promotion rule (3 contributing runs).
  • Essential-coverage: all essential-tier sources in the vulnerability/exploitation and home-region domains were attempted and reachable this run; no miss.
  • Coverage gaps (non-essential, quiet or thin this run, no fetch failure beyond ssd-disclosure): govcert-at, infoguard-ch, oneconsult-ch, compass-security (time-budgeted), paradigm-shift-research, trellix, fox-it-blog, sans-newsbites, csa-labs (low-cadence/stale/secondary), ico-uk, venarix, cnil-fr, ransom-isac (reachable but no in-window item).