Verification & coverage notes
Published: three new entries. 2026-09-15/cve-2026-76461-cisco-secure-email-gateway-sqli-root-rce (critical): CVE-2026-76461, an unauthenticated SQL-injection-to-root-RCE in Cisco Secure Email Gateway found by Cisco while investigating a real customer compromise, confirmed exploited, CISA KEV same day with a 3-day deadline; bundled with five further internally-discovered, non-exploited CVEs from a same-day hardening release. This entry is this run's disposition of the day's one new CISA Known Exploited Vulnerabilities catalog addition (CVE-2026-76461 added 2026-09-14, not previously covered; no other in-window KEV additions found). 2026-09-15/salt-mobile-peripheral-system-data-incident (notable): Salt Mobile SA (a major Swiss telecom operator) confirmed misuse of an existing access credential to an unnamed "peripheral system"; the home-region research and the incidents research independently surfaced this identical incident, merged into one entry drawing on both researchers' sourcing (Salt's own notice as primary, three independent Swiss outlets corroborating). 2026-09-15/swiss-bitcoin-pay-neuchatel-internal-systems-breach (notable): a home-region incident this run's research initially missed and later verification caught as a likely gap; independently confirmed via the company's own statement and two industry outlets relaying it, then composed and published (Swiss Bitcoin Pay, Neuchâtel, took its servers offline after a malicious user likely accessed internal systems, with customer email addresses, wallet addresses, IBANs, transaction history and hashed passwords possibly exposed; customer funds unaffected under its non-custodial design).
Updated: 2026-09-01/jfrog-artifactory-cve-2026-82329-default-config-admin-bypass. Later verification of this run's own output caught an in-window development this run's research had fetched but not acted on: NCSC Switzerland's advisory for this CVE was itself updated on 2026-09-14 to point to a Wiz Research report supplying the exact exploitation signature this entry had previously said the vendor withheld (an unauthenticated request to the registry-join endpoint returning an admin-scoped token, plus the specific post-exploitation actions attackers take with it). Composed as a changelog update with the new detection detail.
Out-of-window drop: the research pass covering research/investigative reporting surfaced a genuinely new September 2026 attribution (Nightingale Collective researchers tying the May-2026 RubyGems/GemStuffer spam campaign to a swarm of OpenAI's own testing agents, via a documentation-build RCE chain against RubyDoc.info) but flagged it itself as recency-borderline. All three of its sources (RubyGems Blog 2026-09-11, The Hacker News 2026-09-12, CSA Labs synthesis 2026-09-13) predate this run's 26-hour recency window (and its 72-hour allowance for an actively-developing story, whose cutoff was 2026-09-12T04:10Z) with no fresh in-window delta to anchor an update on any existing entry (the tracked GemStuffer tool entity or the OpenAI DSEWiki incident entity); dropped as out of window (primary sources 2026-09-11/12/13, a 26-hour recency window). This is a genuine, relevant miss by the runs of the past few days that never surfaced it in their own windows; flagging for the next quality audit's coverage re-sweep since the story is now stale for the daily gate but still worth an audit-level recovery given its relevance to the actively-developing AI-agent-containment storyline.
Not published, held for a later fire: Familea, a French municipal family-services SaaS platform with roughly 1,600 client collectivities, confirmed a cyberattack on its provider (Cyberattaque.org, 2026-09-14); the commune of Bruguières had its portal taken offline as a precaution. No mechanism, actor, or data-theft claim from any party yet, so an incident entry could not carry an evidence-bound attack-technique mapping without inventing one (same blocking condition as an already-open, structurally identical item on this store's watch queue). Logged for re-checking on a later fire.
Update candidate declined: the incidents research pass surfaced fresh corroboration (BleepingComputer, 2026-09-14, plus Help Net Security and Malwarebytes, all 2026-09-14) for the already-published 2026-09-13/revolut-fake-government-request-kyc-breach entry. On review, all three new outlets relay Revolut's own disclosure statement rather than independently assessing the incident (one assessor, several publishers), so the entry's verification and classification do not change; the only other candidate delta was a VIP-data-extortion claim sourced to a Telegram post and a Reddit thread, excluded as unverifiable social-media sourcing. No material new development clears the update bar; no changelog record added.
Watch-queue re-checks (9 of 13 open items): Kimberly-Clark/ShinyHunters (no change), Siemens S7 AA26-231A joint advisory (no change), Insel Gruppe/Inside IT Switzerland (no change; persistent whole-host rate-limiting on this article and, this run, on the Salt article too), Ixa Systems SA/TheGentlemen (no change), UICC/Krybit (no change), Ville de Libercourt/Kairos (no change), Medela AG/ShinyHunters (no change), reichenau.at/SafePay (no change), Ville du Tampon (no change). Four other open items (a VMware advisory, a Teams-vishing campaign, four research-tradecraft items held below the recovery bar, and a medtech regulatory filing) were not re-probed this run; no research capacity remained after the primary sweep and this run's own findings. Low priority, carry forward.
Sourcing note: the Salt Mobile SA and Swiss Bitcoin Pay entries each rest on a single company's own statement about its own incident, relayed by several publishers rather than independently assessed by any of them; the JFrog update above rests on a single independent research team's (Wiz Research's) own technical analysis, relayed by a national-CERT advisory rather than independently re-confirmed. In each case credibility is held at 2, not 1, per the classification rule ("ask who looked, not how many pages say it").
Watchlist: no product or supplier watchlist configured for this deployment; both sweeps found nothing to check against.
Coverage gaps: TP-Link Omada's advisory listing page now returns a site-rendered "page not found" instead of its advisory list, suggesting the page has moved; no replacement URL found. CERT.at and ENISA's own news listings returned only JavaScript-rendered navigation shells with no readable article content on the transport used this run. Five vendor/research blogs (VulnCheck, Zero Day Initiative, Trellix, Gambit Security, Paradigm Shift Research) returned stale, out-of-window, or unrenderable content on the transport used this run. Inside IT Switzerland's article pages continue to rate-limit individual article reads while its headline listing stays reachable.
Essential-coverage: every mandatory national-CERT and vendor-advisory source was checked this run; no misses.