Verification & coverage notes
Coverage window: standard (gap_hours=23.98 since 2026-09-11T0410Z-intel, window_hours=26). No outage-backfill duty.
Mechanical KEV sweep (v4.8), all 4 in-window additions dispositioned. tools/kev_window_diff.py found four CISA KEV additions dated 2026-09-11 uncovered by the store: CVE-2026-42016 and CVE-2026-42018 (JFrog Artifactory), CVE-2026-84869 (ConnectWise ScreenConnect), CVE-2026-85706 (GitLab CE/EE). All four published as new entries this run. CVE-2026-42016/-42018 were confirmed via JFrog's own advisory to be distinct root causes, disclosure dates and affected-version ranges from the already-tracked CVE-2026-82329 (2026-09-01 entry) (not a same-flaw re-numbering) so they ship as a separate entry with references[] pointing at the existing one, per the single-report-covers-three-CVEs judgment call the researching sub-agent flagged; the two entries are not merged.
New entries (4):
2026-09-12/cve-2026-84869-connectwise-screenconnect-worm-file-transfer (vulnerability, high), worm-like exploitation from 2026-08-20, patch 2026-09-08, KEV 2026-09-11.2026-09-12/cve-2026-85706-gitlab-unauth-path-traversal-file-read (vulnerability, high), patch-to-honeypot-probe in ~24h, KEV 2026-09-11.2026-09-12/jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover (vulnerability, critical, deep dive, category supply-chain, not used in the last 30 days), confirmed wide-scale admin-takeover chain against two previously-patched, low-attention CVEs, with backdoors already dropped and the majority of installs still vulnerable six weeks post-disclosure; raised from high to critical on iteration-2 verifier calibration flag, consistent with store precedent (the 2026-09-01 CVE-2026-82329 entry, same product, same admin-takeover outcome, critical). Single-source (Wiz Research is the sole assessor of the exploitation claim; JFrog's own advisories corroborate only the underlying flaws, not the exploitation).2026-09-12/japan-digital-agency-gss-vpn-breach-maintenance-account (incident, notable), clears the PD-11 breach gate on limb (b): a materially transferable lesson (detection via anomalous maintenance-account file-access volume rather than the initial exploit; a shift from CVSS-severity-based to risk-based patch prioritization after losing the race to an exploit on a bug rated only "Medium") on a structurally close foreign analogue (a national government's own shared multi-agency IT-services platform).
Updated entries (2):
2026-08-29/eu-cra-reporting-obligation-ncsc-fi-checklist, update, floats updated_at. ENISA confirmed 2026-09-11 the CRA Single Reporting Platform has deployed initial operating capability, resolving the prior fire's open point; a same-day Bitkom survey (via heise) adds a preparedness data point.2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited, update, floats updated_at. Hunt.io (via Security Affairs; OffSeq's AI-generated Threat Radar reposts the same figures, not an independent source) names a first confirmed victim of a materially wider, distinct mass-exploitation wave against the same CVE (UK council; secretsdump run directly on the compromised appliance reaching DCSync in 5/250 environments), explicitly not attributed to UTA0533 or INC Ransom.
Borderline drop: Anthropic's "distillation attacks" report (hydra-cluster fraudulent-account networks used by DeepSeek/Moonshot/MiniMax to scrape Claude), substantive primary technical research (Anthropic's own telemetry) with a transferable fraudulent-account-network detection technique, but the underlying subject is an AI-industry IP/competitive dispute under an active US-China export-control policy backdrop, with no direct Swiss public-sector nexus beyond a generic account-fraud/API-abuse technique-class analogy. Relevance doubt resolved toward drop per PD-11/v4.2 calibration. Not registered to the entity registry.
Single-source / carve-out items: jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover (single-source, reliability B / credibility 2; Wiz Research is the sole assessor of the active-exploitation chain; sourcing_note explains why BSI/ENISA's same-day postings are not counted as independent corroboration).
Coverage gaps: inside-it-ch (whole-host "Vercel Security Checkpoint" 429 on specific article bodies, the long-carried Insel Gruppe/ServiceNow backlog row plus two further articles this run, a 14th+ consecutive fire unable to read this class of article; RSS and general listing access stayed healthy throughout); cert-pl (/en/posts/ news listing 403'd this run; its vuln-advisory RSS feed, the source's primary recipe, was not re-tried as duplicative of S1's own essential-tier coverage of the same source, covered_anyway: true); cert-at (reachable, no in-window items, latest post dated 2026-08-26, outside the 26h window).
Coverage backlog: all 11 open rows in state/coverage_backlog.md re-checked this run (S1–S4); every one carries a 2026-09-12 dated note, no change on any, no row struck.
No contradictions found this run. No product/supplier watchlist configured (sweep is a no-op per the profile). No closed-source intake (no intel/ drops in-window).
Verification loop, 8 iterations, fail-open at the cap (never reached a confirmed CLEAN). The loop ran the full 8-iteration cap: iteration 1 NEEDS_FIXES (truth 3, editorial 6), 2 NEEDS_FIXES (3+2), 3 NEEDS_FIXES (4+1), 4 NEEDS_FIXES (2+0), 5 CLEAN, 6 (the confirmation pass) NEEDS_FIXES (3+1), restarting the chain per decision rule 2, 7 NEEDS_FIXES (1+3), 8 NEEDS_FIXES (0+1). Every iteration's findings were genuine and were remediated (see verification.iterations[] above and work/2026-09-12T0409Z-intel/verification.iter{1..8}.md); no finding was declined without a stated reason. Per the cap fail-open rule, this run publishes on iteration 8's NEEDS_FIXES verdict with verification_residual_count: 1 (one small, evidenced missing-citation finding, fixed) rather than a ninth iteration. This is an unusually long loop for what were, in aggregate, narrow and progressively smaller defects (import citation gaps, one inverted causal clause, one unsupported given name, a few CVSS/date sourcing gaps), every one caught by a genuinely independent cold read finding something the previous seven passes missed, which is the loop working as designed rather than a sign the content is unsound. The one substantive editorial judgment call (raising jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover from priority: high to critical on iteration 2's flag) was independently sanity-checked by iteration 3 and not contested by any later iteration.