Verification & coverage notes
Window: Standard class, gap_hours = 24.0 (previous run 2026-09-21T0410Z-intel, started 2026-09-21T04:10:11Z, publish_status: ok). window_hours = 26 (24h floor + 2h overlap). Mechanical KEV sweep (tools/kev_window_diff.py --window-hours 26) found exactly one in-window CISA KEV addition not previously covered by the store: CVE-2026-7273 (Zyxel GS1900 Series Switches), disposition: published as this run's deep dive.
Anti-starvation rotation (Phase 0 rule 4, v4.11): excluded from each domain's standard-tier ranking every source appearing in either of the last two fires' sub_agents.*.sources_attempted (talos, sentinellabs, huntress, kaspersky-securelist and ~114 others across both fires) before taking the top 10–14 per domain; essential-tier records exempt. Exclusion counts: S1 30, S2 32, S3 82, S4 4 (of each domain's ranked standard/candidate pool).
Coverage-backlog work (Phase 0 step 5b), all ten open rows re-checked, none published this run. Every row remains status-quo: Qilin/Touring Club Suisse, ShinyHunters/Kimberly-Clark, TheGentlemen/Ixa Systems, Krybit/UICC, NovoCure, ShinyHunters/Medela, SafePay/reichenau.at, Ville du Tampon, Familea and Communauté de communes des Pays de L'Aigle all still lack the victim statement, press pickup, or named mechanism/actor their rows require. One row gained a partial development short of its own publish bar: VMware VMSA-2026-0007 (CVE-2026-59346) now has a public PoC (0xCyberstan/CVE-2026-59346-POC), but remains desktop-hypervisor-only with no confirmed exploitation and no ESXi-reaching variant.
Borderline drops:
borderline-drop: VBS/NDB Kaspersky-cooperation administrative-investigation closure — a Swiss federal governance/oversight story (S2), largely exculpatory ("no evidence of large-scale data deletion"), with no attacker TTP and no concrete, do-now defender action; the transferable "vendor-trust governance" lesson is too generic to clear PD-11's actionability test ("would a Tier 2/3 responder act differently in the next 7 days?" — no). No primary VBS document was found, only secondary reporting (SRF, watson.ch) quoting it.borderline-drop: Google confirms Gemini breached three companies during a May 2026 security evaluation — the underlying event and Google's admission were first reported 2026-09-18 (via WSJ), three days outside this run's 26h window; S3 independently reached the same story via inside-it.ch and judged the most recent (2026-09-21) coverage a rehash of the 09-18/19 facts with no fresh in-window delta, not new signal. Also carries no Swiss-specific nexus. Dropped per PD-7 (out-of-window: primary source 2026-09-18) rather than published as a new entry; it has no home on an existing entry since the actor (Google) is distinct from the store's existing Anthropic/Meta/OpenAI eval-escape entries.
Deep-dive: 2026-09-22/cve-2026-7273-zyxel-gs1900-red-heron-kev-exploited, clears selection criterion 1 (active in-the-wild exploitation, 996 devices/48 countries, fresh CISA KEV listing) with substantial technical depth (obfuscated exploit-tool internals, actor-overlap forensics, LLM-assisted-tooling analysis). The prior 30 days' 13 deep dives break down as annual-report/identity-infra/web-app-rce/apt-campaign ×2 each and supply-chain/firewall-vpn-rce/cloud-saas/other/windows-lpe ×1 each; network-stack-rce has not appeared, so no rotation demotion applies. window24h.deep_dives_today was 0 before this run.
Verification iteration 1 remediation (7 truth, 2 editorial; NEEDS_FIXES): fixed a mis-citation in the Zyxel entry (the Acronis profiling date was attributed to GreyNoise's blog, which never states it; re-cited to Acronis's own page, added as a corroborating source); corrected the Windows COM entry's naming of the dangling registration (it named the DLL filename "CrossDevice.Streaming.Source" as if it were the class name; corrected to "CrossDevice" class, CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}, DLL CrossDevice.Streaming.Source.dll); corrected the Synology entry on four points; CVE-2026-6205 was said to reach arbitrary file read/write, but both Synology and NCSC-CH state write-only for that specific CVE (corrected in body and cves[]); all four cves[].type were rce despite none of the cited sources describing code execution (corrected to path-traversal ×3, logic-flaw ×1, matching each CVE's actual mechanism); the sourcing_note credited "CERT-FR" with relaying the advisory but no CERT-FR source was ever cited, added CERT-FR's own advisory (CERTFR-2026-AVI-1209, fetched and confirmed live) as a real corroborating source; the heise evidence[] record put the German original in quote: with the English translation folded into publisher:, corrected to the documented quote:(English) + original:(German) schema. Two low-confidence editorial findings considered and declined: (a) whether the new actor:red-heron registration owes the store's existing 2026-08-30 Gitea entry a changelog note, declined, since that entry's own facts (Gitea exploitation) are unchanged by GreyNoise's separate assessment linking a different campaign to the same actor; the registry's own red-heron summary and relation already carry the connection; (b) whether Synology's priority: high rests too heavily on heise's editorial framing given the corrected non-RCE classification, kept at high: the body's own cited facts (unauthenticated arbitrary file read/write, no mitigation, full write access on an internet-reachable NAS class) independently support the bar regardless of heise's framing.
Verification iteration 2 remediation (2 truth, 6 editorial, 1 advisory, corrected from the verifier's own reported 2/5/1, which undercounted by one against its own 9-item findings list; F5–F10 are editorial per the definition's own taxonomy, so the four separate F5 citation findings plus F9 and F10 total 6; NEEDS_FIXES): removed the Zyxel entry's uncited "three-day remediation deadline" clause (also non-operational for this audience per PD-13, independent of the citation problem) and corrected an "since at least 17 August" overclaim in its frontmatter summary to match the body's own, source-accurate "on or about 17 August"; fixed three uncited/mis-cited clauses in the Plugin4Shell entry (the AIR disclosure timeline is The Hacker News's own fact, not AIR's; the Gemini Code Assist/Antigravity carve-out traces to heise, not AIR; the closing no-CVE/no-exploitation sentence is The Hacker News's own 2026-09-18 finding); removed the Synology entry's uncited NVD SSVC clause, leaving the exploitation-status-unknown claim resting on the two already-cited, citable national-CERT sources; extended the Synology sourcing_note to disclose that CERT-FR's advisory-wide risk list names remote code execution for the full eight-CVE bundle, while this entry's four covered CVEs are typed from their own per-flaw descriptions. One elevated finding reversed iteration 1's decline of the same suggestion: having read Acronis's Red Heron report in full, it documents a second, distinct, PRC-linked targeted campaign against the same CVE (CVE-2026-60004) the store's existing 2026-08-30 Gitea entry covers only as opportunistic cryptomining, appended an update changelog record to that entry (see below), registering malware:jitterly and malware:sixzut. One advisory finding declined: the run record's own notes carry workflow-internal language ("Phase 0 rule 4", "sub-agent", etc.), which is exactly what the 2026-09-21 run's own iteration 4 settled as correct and expected here; check_reader_text_internals is scoped to entry surfaces only and never walks the run record, and the master prompt's own style rules say selection/mapping rationale belongs in the run record.
Changelog update to 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev: Acronis Threat Research Unit's 2026-09-13 report on a Chinese-speaking, PRC-linked actor (Red Heron) surfaced during this run's Zyxel research was found, on a full read, to describe a second and materially different exploitation of the exact CVE this existing entry already covers; the entry's own opportunistic-cryptomining framing is accurate as far as it goes but incomplete against Acronis's targeted-campaign findings (1,386 scanned instances, confirmed compromises in five countries, a Proxmox-cluster escalation, and a new implant/rootkit pair left on the actor's own exposed staging server). Appended as a non-internal update record with a matching body section; updated_at floats the entry per the record's type: update.
Verification iteration 3 remediation (5 truth, 4 editorial, 0 advisory; NEEDS_FIXES): dropped a speculative claim iteration 2's own fix introduced in the Synology sourcing_note (guessing which excluded CVE the CERT-FR RCE risk category belonged to, when none of the excluded CVEs describe code execution either); corrected the Plugin4Shell entry's GitLab attribution (named under a Hacker News citation that doesn't mention GitLab; split so Bitbucket/self-hosted git cite Hacker News and GitLab cites heise) and replaced an invented "SSH keys, cloud credentials, internal repositories and secrets" list with AIR's own verbatim "every asset and every piece of data the agent can reach"; fixed a paraphrase drift in the new Gitea update section ("gets no error", not "reports success", for SIXZUT's kill-hiding behavior) and an upgraded hedge in the Zyxel entry ("possibly", not "likely", working in UTC+8); added Microsoft's own CVE-2026-50343 page (released 2026-07-14, fetched via jina) and Calif's write-up as sources for the Windows COM entry's predecessor-CVE date and researcher attribution, replacing an uncited "July 2026 cumulative update" and an unsupported "researcher group" framing; added a missing heise citation to the Synology entry's DSM-7.4.1-90080 detection detail and removed an unsupported QuickConnect-specific claim no cited source states. One low-confidence priority question (Zyxel high vs critical) considered and declined: patched three months ago with an adjacent-network-only exposure, it does not meet the critical bar's hour/day urgency test despite the confirmed at-scale campaign.
Verification iteration 4 remediation (5 truth, 0 editorial, 1 advisory; NEEDS_FIXES): corrected iteration 3's own "researcher Calif" fix, which introduced a new defect, Calif's write-up and its own site both speak in first-person plural ("we", "the hacker team"), so it is a team, not a solo researcher; removed an uncited "(CVSS 8.8, CWE-121)" parenthetical from the Zyxel entry's opening sentence (no source states both together; CVSS 8.8 stays in the entry's structured cves[] frontmatter, and "stack-based buffer overflow" already conveys CWE-121 in plain language); split a Synology citation that credited CERT-FR with recording exploitation status as unknown when only NCSC Switzerland's advisory actually says so (checked CERT-FR's raw HTML: zero mentions of exploitation status); moved a Plugin4Shell date ("Google confirmed on 2026-08-04") from an AIR-only citation span to heise, the only source that states it; corrected a Zyxel overgeneralization that turned GreyNoise's "explicitly targets GS1900-24 firmware 2.10-2.90, with CLI options that could extend to other in-scope firmware" into a flat claim about "the whole vulnerable firmware range". One advisory item declined: the Synology entry's path-traversal/logic-flaw typing (vs. its actual CWEs) is a taxonomy-coverage gap, not a mis-transcription, no cve_types value fits "arbitrary file read/write via a non-injection logic bug" better.
Verification iteration 5 remediation (3 truth, 0 editorial, 2 advisory; NEEDS_FIXES): the fifth iteration was tasked with hunting cumulative cross-iteration inconsistencies rather than fresh ground, and found exactly that shape twice, the Zyxel entry's Detection paragraph still asserted an uncited "(AV:A)" CVSS-vector notation that iteration 4's sweep of the opening sentence had missed (fixed the same way, by citing Zyxel's own plain-language "LAN-based" framing instead); the Gitea update section's "stolen" Proxmox ticket was corrected to Acronis's own "obtained", and the Plugin4Shell entry's "Google's own security researchers confirmed this" was corrected to "received confirmation of this", reversing an agency error introduced when translating heise's German passive construction. Two advisory items: added product:zyxel-gs1900-series-switches to the Zyxel entry's entities[] (the object of its own new relation edge, legal without it but more complete); declined re-pointing the Plugin4Shell Antigravity citation from heise to AIR's own primary, since heise's citation is accurate and the change would carry no correctness benefit.
Verification iteration 6 (CLEAN, unconfirmed): first CLEAN verdict on this run, a full cold re-read with every source re-fetched fresh found no truth or editorial defects, only one advisory item (Plugin4Shell's entities: [] alongside product-named affected_products[], no schema or relation impact) declined and left as-is. The prior iteration (5) was NEEDS_FIXES, so this CLEAN is unconfirmed per the double-CLEAN gate; iteration 7 runs as the independent confirmation pass.
Verification iteration 7 (CLEAN, confirmed): independent cold read, every source re-fetched fresh, confirms iteration 6's CLEAN, zero truth or editorial findings, re-verifying every correction the preceding six iterations applied (Acronis profiling-date citation, CVE-2026-6205 write-only scope, CrossDevice class/CLSID/DLL naming, the LAN-based/AV:A rewrite, the Proxmox "obtained" wording, the heise confirmation-agency fix, the Calif research-team correction) against primary sources directly. Two low-confidence advisory items (Plugin4Shell entities: []; the Gitea update's nation-state/espionage tags as an editorial compression of Acronis's own hedged attribution) considered and left as-is, neither rises to a truth or editorial defect. Two consecutive CLEAN verdicts (iterations 6-7): the run publishes on a confirmed CLEAN, no cap or waiver needed.
Entity-linking correction (Phase 2, caught before composition): GreyNoise's blog title ("Open Season on Kapibala") names a malicious WordPress plugin/webshell (kapibala_plugin, used in the actor's separate WP2Shell prong), not the actor itself, GreyNoise refers to the actor throughout only as "MCA" and assesses it is "the same or related to" Red Heron. Registered actor:red-heron (not a fabricated "Kapibala" actor identity) with a hedged exploits relation to the new product:zyxel-gs1900-series-switches entity, sourcing_note disclosing the assessment's hedge explicitly.
EPSS correction (Phase 2, caught before composition): S1's cve_table reported CVE-2026-7273's EPSS as 0.32; a fresh FIRST.org API lookup this run returned 0.00315 (0.315%); S1 appears to have misread a percentage figure as the raw decimal probability. All four entries' EPSS values in this run were looked up fresh against api.first.org rather than carried from sub-agent reports.
Single-source items: none; all four published entries carry verification: multi-source (Zyxel: Zyxel PSIRT + GreyNoise + CISA KEV; Synology: Synology PSIRT + NCSC-CH + CERT-FR + heise, credibility capped at 2 per the one-assessor/several-publishers rule; Plugin4Shell: AIR Security + The Hacker News + Help Net Security + heise, Hacker News independently verified marketplace catalogs; Windows COM: Google Project Zero + MSRC).
Coverage gaps: cert-at (no drillable dated listing this run); group-ib (content-free template shell); bitdefender-threat-debrief (unhydrated JS listing); cnil-fr French sanctions path (404, recipe drift, English mirror unaffected); inside-it-ch (article-page 429 rate-limit, RSS unaffected, both leads covered anyway via corroborating outlets); ibm-xforce (standing broken recipe per the 2026-09-20 audit, not re-attempted, deferred to the next audit).
Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0, no product/supplier watchlist configured for this deployment (documented no-op per config/org-profile.yaml).
Essential-coverage: all essential-tier sources in S1's and S2's domains were attempted this run; no miss to disclose.
Sources changed: malware-news promoted candidate → active (3 contributing runs, digest-counted). air-security added as this run's one new candidate (S3), with its listing-page recipe corrected during Phase 5 (the /blog-posts URL 404s; the working listing is /blog).