CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
‹Wed · 30 Sep 2026
All daily briefs →
Daily brief · UTC day

Wednesday, 30 September 2026

4 verified findings from 2 runs · 9 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01Apple patches a CoreGraphics zero-day exploited against targeted iPhone users; a crafted file can lead to code execution. Apple's 2026-09-28 updates (iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1) fix CVE-2026-86950, a CoreGraphics out-of-bounds write that can run arbitrary code when a crafted file is processed. Apple says it may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, and CISA added it to the KEV catalog on 2026-09-29. No source states how the file is delivered. Since 2026-09-30 a public proof of concept crashes unpatched devices with a crafted PDF font. →
  2. 02Microsoft DART: one reset-compromised identity became a malicious pipeline that harvested Kubernetes credentials. Microsoft's incident-response team describes an intrusion by Storm-3068 that began when the actor gained a user account through a successful self-service password reset and registered its own authentication methods. It then enumerated Azure DevOps, created a malicious pipeline that collected kubeconfig files, added Atera and Chisel through modified pipeline scripts, and committed seven stolen kubeconfig files to a repository. Microsoft names no victim, sector or date, and no source says how the reset was completed. →
  3. 03Microsoft: Star Blizzard adds mass mailings and a one-click scheduled-task chain to its CosmicPulse backdoor delivery. Microsoft Threat Intelligence reports that the Russian state actor Star Blizzard has moved from purely targeted spear-phishing to at least 13 large-scale campaigns since January 2026, sent from accounts on compromised WordPress and cPanel websites and lured with closed-door think-tank event invitations. Its new RedFlick delivery chain needs one user interaction and installs the CosmicPulse Python backdoor through scheduled tasks; Microsoft counts over 100 affected organizations, primarily in the US and UK, and names governments and diplomatic and multilateral bodies among the targets. →

01Active threats, incidents & disclosures3 items

NOTABLENATOA2

Swiss commune Manno (TI) confirms a cyberattack that encrypted part of its servers on 4 August 2026; SafePay is recorded listing the commune on a leak site on 28 September

The Ticino commune of Manno stated in a signed notice dated 2026-09-16 that on 4 August 2026 part of its servers suffered an attack that encrypted data (Comune di Manno, 2026-09-16). The commune isolated the affected server immediately and, per the notice, restored data and operations from existing backups in the course of the afternoon (Comune di Manno, 2026-09-16). It reported the case to the competent authorities, filed a criminal complaint against persons unknown, and told residents to distrust unexpected letters or e-mails that demand urgent payments or personal or financial data and to verify through official channels (Comune di Manno, 2026-09-16). The notice names no actor, no intrusion vector, and does not say whether data left the network. Inside IT's teaser of 2026-09-29 calls it a ransomware attack and says a backup allowed a quick return to normal operation (Inside IT, 2026-09-29). The tracker's leak-post screenshot shows a countdown timer of about three days eleven hours when it was captured on 2026-09-28, which points to expiry around 1 October; the post describes no dataset (Ransomware.live, 2026-09-28).

On 2026-09-28, 55 days after the encryption, Ransomware.live recorded that the ransomware group SafePay had listed manno.ch on its leak site (Ransomware.live, 2026-09-28). That is the group's claim as recorded by a tracker: the commune has not confirmed it, and the record shows neither what data the listing claims nor that it concerns the 4 August event.

on 4 August 2026 part of the commune's servers suffered an attack (translated from Italian)

which resulted in the encryption of the data (translated from Italian)

subsequently a complaint was lodged against (translated from Italian)

the population is urged to pay attention to unexpected communications (translated from Italian)

Comune di Manno (Municipio) 2026-09-16

Ransomware.live discovered on 2026-09-28 that manno.ch has been claimed by Safepay ransomware group

Ransomware.live

A ransomware gang attacked servers of the Manno municipal administration and encrypted part of the data (translated from German)

Inside IT
incident30 Sep 04:41Zsingle-source · victim disclosureOpen finding →
NOTABLENATOB2

Storm-3068: a successful self-service password reset became Azure DevOps pipeline abuse and stolen Kubernetes credentials, with no malware or exploit

Microsoft's Defender Experts incident-response team (DART) describes a malware-free, exploit-free intrusion by the actor it designates Storm-3068 that began when the actor gained access to a user account through a self-service password reset and took full control of the identity by registering its own authentication methods (Microsoft Defender Experts, 2026-09-29). Microsoft does not say how the reset challenge was passed. With that persistent access, the actor used legitimate administrative tools and automated scripts to enumerate Azure DevOps repositories, projects, pipelines and deployment environments, then created a malicious pipeline that deployed a kube agent and ran jobs to collect kubeconfig files; that pipeline inherited the compromised account's permissions and was authorized to access more than 50 resources (Microsoft Defender Experts, 2026-09-29). The actor also modified pipeline scripts to install the Atera remote-management agent and download the Chisel tunneling utility, and ran Chisel to open a reverse tunnel to an external address, which Microsoft describes as an attempt at alternative remote access and at exposing the Kubernetes API server (Microsoft Defender Experts, 2026-09-29). Investigators rebuilt the sequence from Azure DevOps audit logs and Git version history and found seven stolen kubeconfig files committed to a repository (Microsoft Defender Experts, 2026-09-29). The full report adds that the actor registered a new MFA method and deleted the account's legitimate MFA methods, started the kube agent by downloading and running a third-party script with several jobs, saved the kubeconfig files into an existing kubeconfigs folder of the target repository (each holding a cluster API endpoint, certificate-authority data and a service-account token), and expanded access in a matter of hours rather than days (Microsoft Defender Experts, Cyberattack Series report Q3 2026, 2026-09-29).

Where it surfaces: identity-provider audit logs show a completed password reset followed by new authentication-method registrations on the same account (Microsoft Defender Experts, 2026-09-29), and the full report's attack flow adds deletion of the legitimate methods (Microsoft Defender Experts, Cyberattack Series report Q3 2026, 2026-09-29), while Microsoft advises watching for repeated resets or resets against many users; DevOps audit logs show one identity enumerating repositories and pipelines and then creating or modifying pipelines; Git history shows pipeline scripts that install a remote-management agent or download a tunneling tool, and kubeconfig files committed to a repository; build-agent egress shows a reverse tunnel to an external address (Microsoft Defender Experts, 2026-09-29). Microsoft's recommended controls are to keep privileged accounts out of self-service password reset or protect them with phishing-resistant multifactor authentication, enforce branch protection and approvals for code changes, restrict direct commits to critical branches, limit who can create, modify or run pipelines, and apply least privilege across identity, DevOps and cloud (Microsoft Defender Experts, 2026-09-29).

Triage: a user completing a password reset and then registering authentication methods is routine. The sequence that separates this activity is the same identity, right after the reset, enumerating Azure DevOps repositories and pipelines in bulk and then creating or editing a pipeline.

The intrusion began with Storm-3068 gaining access to a user account through a self-service password reset process and then taking full control of the identity by registering its own authentication methods.

The threat actor added seven stolen kubeconfig files to a repository, providing the credentials needed to access targeted Kubernetes clusters.

Using Azure DevOps audit logs and Git version history, investigators reconstructed the next stage of the intrusion.

Microsoft Defender Experts (DART) 2026-09-29

Builds on: Storm-2949 SSPR-to-Key-Vault Azure kill chain · A public tool automates bulk enumeration of Entra ID accounts, their MFA methods and their…

threat30 Sep 04:43Zsingle-sourceOpen finding →
NOTABLENATOB2

Star Blizzard's RedFlick: mass-mailed think-tank event invitations, compromised-website senders and a single-click scheduled-task chain to the CosmicPulse backdoor

Microsoft Threat Intelligence reports that Star Blizzard, which CISA attributes to Russia's FSB Centre 18 (Microsoft Threat Intelligence, 2026-09-29) and which CyberScoop lists under the names SEABORGIUM, Callisto Group, TA446 and COLDRIVER (CyberScoop, 2026-09-29), has since January 2026 added large-scale phishing to its targeted spear-phishing: at least 13 distinct campaigns of tens to hundreds of emails each, aimed primarily at NGOs, think tanks and government organizations, with Ukrainian individuals and institutions, diplomatic and multilateral bodies and financial organizations also named (Microsoft Threat Intelligence, 2026-09-29). Microsoft counts over 100 affected organizations, primarily in the United States and United Kingdom, and infers the actor now uses a mass-mailing platform (Microsoft Threat Intelligence, 2026-09-29). The lures are invitations to closed-door roundtables that borrow the names of real think tanks, often written to look like internal mail from the target's own organization; the first message is usually without an attachment, and a reply is answered with a password-protected RAR or ZIP archive whose password is shown as an image, although the Ukraine-focused campaigns and a few later ones attached the lure directly (Microsoft Threat Intelligence, 2026-09-29). Since March the sending accounts sit on WordPress and cPanel websites, replacing free Proton and Microsoft consumer mailboxes, and Microsoft assesses with high confidence that Star Blizzard compromised those sites (Microsoft Threat Intelligence, 2026-09-29). One March campaign instead gave respondents a link to the DarkSword iOS backdoor installation, which Microsoft says Proofpoint reported, and a mid-August campaign employed steganography to conceal identifiers (Microsoft Threat Intelligence, 2026-09-29).

The delivery chain changed three times in 2026 and replaced the ClickFix flow of earlier campaigns with one that needs a single user interaction (Microsoft Threat Intelligence, 2026-09-29). From mid-January, a virtual hard disk file in the archive held a shortcut disguised as a PDF that started a hidden console window and a batch script; the script opened a decoy PDF and ran the SSH client with PermitLocalCommand enabled to download and run a remote MSI, which created a scheduled task that used control.exe to fetch the CosmicPulse downloader disguised as a Control Panel applet (Microsoft Threat Intelligence, 2026-09-29). From April the MSI created three scheduled tasks named like network components: one beaconing host and user names to the command server and running a remote DLL through a WebDAV path, one preparing WebDAV support, and one running control.exe against a remote path to execute the next stage (Microsoft Threat Intelligence, 2026-09-29). From July, a shortcut used conhost.exe and curl to download a PDF, and PowerShell then searched that file for a marker, decoded the Base64 blob that follows it and ran the result to fetch another MSI (Microsoft Threat Intelligence, 2026-09-29). The downloader fetches two ZIP archives, stores an encrypted AES key in a registry key under HKCU\Software\Classes, and a Python bootstrapper decrypts and runs the CosmicPulse payload, which is publicly tracked as YESROBOT (Microsoft Threat Intelligence, 2026-09-29).

Where each step surfaces: mail-flow logs show bulk initial-contact invitations and a follow-up with a password-protected archive; process-creation telemetry with parent lineage shows a hidden console window spawning a command shell that runs an SSH client, msiexec started from a script, control.exe loading a remote path, and conhost.exe with curl downloading a PDF that PowerShell then parses; scheduled-task creation events show tasks named like network components, one pointing at a WebDAV path; registry telemetry shows a key written under HKCU\Software\Classes. Microsoft's recommended controls include phishing-resistant authentication, Conditional Access, Safe Links and Safe Attachments with zero-hour auto purge, EDR in block mode, and Windows Firewall rules restricting outbound SSH connection attempts to what the business needs (Microsoft Threat Intelligence, 2026-09-29).

Triage: Microsoft's discriminators for this actor are a sender whose organization name appears only in the local part of the address on an unrelated domain, bulk delivery, an initial message that is usually without an attachment and a follow-up archive after a reply (Microsoft Threat Intelligence, 2026-09-29).

Since January 2026, Microsoft observed at least 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide.

By contrast, the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process.

Microsoft Threat Intelligence assesses with high confidence that these websites have been compromised by Star Blizzard for this purpose.

The emails in these RedFlick campaigns are often sent in bulk.

Microsoft Threat Intelligence 2026-09-29
threat30 Sep 04:42Zsingle-sourceOpen finding →
HIGHCVE-2026-86950exploitedupdatedNATOA2

CVE-2026-86950, Apple iOS, iPadOS and macOS CoreGraphics: out-of-bounds write exploited in an extremely sophisticated attack on targeted iOS users, CISA KEV-listed (CVSS 8.8)

CVE-2026-86950 is an out-of-bounds write in CoreGraphics, the graphics component shared by iOS, iPadOS and macOS, and processing a maliciously crafted file can lead to arbitrary code execution (Apple, 2026-09-28). Apple states that it "is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27" (Apple, 2026-09-28). The fix, "improved bounds checking", ships in iOS and iPadOS 26.7.1 (Apple, 2026-09-28), macOS Tahoe 26.7.1 (Apple, 2026-09-28) and macOS Sequoia 15.8.1 (Apple, 2026-09-28); Meta Product Security is credited with the report. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-09-29 and attached its forensic-triage requirements to the listing (CISA, 2026-09-29). ENISA's vulnerability database scores it CVSS 3.1 8.8, network vector with user interaction required (ENISA EUVD, 2026-09-29). The macOS advisories repeat Apple's iOS-scoped exploitation sentence, so Apple does not claim exploitation on macOS.

Nothing about the attack itself is public: Apple gave no details on how many people were targeted, whether any attempt succeeded, or when exploitation began (The Hacker News, 2026-09-29), and no delivery mechanism is stated. SecurityWeek reads the component's role in 2D graphics and PDF rendering as meaning a file could arrive through web pages, email attachments or messaging apps, where automatic previews could allow zero-click exploitation; that is SecurityWeek's inference, and it also notes Meta would not say whether WhatsApp was involved (SecurityWeek, 2026-09-29). It also says iOS 27 and macOS Golden Gate 27 do not appear to be affected. No indicators or behavioural detections have been published by Apple, Meta or CISA, so version compliance is the only measurable lever: device-management inventory of iPhones and iPads still on the iOS 26 branch below 26.7.1, and of Macs on Tahoe or Sequoia below the fixed builds.

Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

An out-of-bounds write issue was addressed with improved bounds checking.

Apple Security

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

CISA Known Exploited Vulnerabilities Catalog 2026-09-29

the company offered no details on how many individuals were targeted, if any of those attempts were successful, or when the first instance of CVE-2026-86950 exploitation occurred

The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs.

The published analysis does not describe or test a WhatsApp delivery path.

The Hacker News 2026-09-29
Updaterun 2026-10-02T0404Z-intelsummarytagscvessourcesevidencebody

Researchers at Calif published a public proof of concept for CVE-2026-86950 on 2026-09-30, built from a public binary comparison of iOS 26.7 and 26.7.1: a PDF with a crafted TrueType font that triggers a controlled out-of-bounds write in CoreGraphics and crashes unpatched iPhones and Macs, with generation scripts and a sample PDF in a public GitHub repository (The Hacker News, 2026-10-01). Calif demonstrates a crash and a controlled write to two adjacent 16-bit values, not code execution, did not obtain the in-the-wild sample and cannot say how the attacker completed the chain (The Hacker News, 2026-10-01). The harness reaches the flaw through the ImageIO thumbnail path an app uses to preview a received attachment (The Hacker News, 2026-10-01). Calif pointed to new font-checking code in WhatsApp's attachment scanner as circumstantial evidence of a possible delivery path; the published analysis does not describe or test that path, a WhatsApp sentence in the first version was removed after publication, and WhatsApp has published no advisory linking the flaw to its products (The Hacker News, 2026-10-01).

vulnerability30 Sep 04:40Zmulti-sourceOpen finding →

03Updates to prior coverage9 items

NOTABLEupdatedNATOA2

NCSC-CH: Microsoft 365 "voicemail" phishing wave delivers malware such as infostealers and harvests M365 credentials

First published 2026-06-25 · open finding →

Correctionrun 2026-09-30T0634Z-auditsourcesevidencetechniquesclassificationtitleheadlinesummaryprioritysectorsentitiesbody

NCSC does not describe forwarding rules or account manipulation, says genuine voicemails are usually rather than never audio files and harvested data may rather than frequently be resold, names no sector and gives the infostealer only as an example of the malware, so the title and analysis now follow the page and the entry moves from high to notable priority. The citation follows the page to its new address on bacs.admin.ch.

NCSC Switzerland's Week 25 review describes what attackers do with a compromised mailbox: they send phishing to the victim's contacts ("chain phishing") and read business communications to prepare CEO fraud and business email compromise (NCSC-CH, 2026-06-23). It does not describe forwarding rules or account manipulation, which the analysis had mapped. It also says genuine voicemails are usually sent as audio files rather than ZIP archives, and that data an infostealer harvests may be resold, where the analysis had said never and frequently. The analysis now follows the page, and the hunt for inbox and forwarding rules is marked as an inference from the mailbox monitoring NCSC describes. NCSC gives the infostealer only as an example of the malware the ZIP installs, and it names no sector and no Swiss public-sector recipients, so the title and analysis now say so and the entry's priority is notable rather than high. The citation now points at the page's new address on bacs.admin.ch, after the old ncsc.admin.ch page went dead.

NOTABLEupdatedNATOA2

NCSC-CH Week 23: three job-seeker scams, a fake interview login, reshipping identity theft and LinkedIn-to-GitHub infostealer delivery

First published 2026-06-10 · open finding →

Correctionrun 2026-09-30T0634Z-auditsourcestechniquesclassificationtitleheadlinesummarysectorsbody

NCSC presents three reported cases rather than a coordinated campaign, and none of the Swiss-employer emails, onboarding repository or PowerShell the analysis described, so the title, summary and analysis now follow the page. The citation follows the page to its new address on bacs.admin.ch.

NCSC Switzerland's Week 23 review presents three reported cases, not a coordinated campaign (NCSC-CH, 2026-06-09). The fake interview was a phone-interview slot confirmed through a Google Calendar entry, which opened a counterfeit Google login. The recruiter case was a technical interview in which the candidate downloaded a private GitHub repository and ran a small programming task, and running its commands installed the infostealer. The analysis had described interview-confirmation emails from Swiss employers, an onboarding or technical-assessment repository and PowerShell, which the page does not say, and it now follows the page. The citation now points at the page's new address on bacs.admin.ch, after the old ncsc.admin.ch page went dead.

NOTABLEupdatedNATOA2

NCSC Switzerland: WhatsApp hotel-booking phishing in two variants, one fed by the April Booking.com data leak

First published 2026-06-04 · open finding →

Correctionrun 2026-09-30T0634Z-auditsourcestechniquesclassificationtitleheadlinesummaryprioritysectorsbody

NCSC ties only the refund variant to the April 2026 Booking.com data leak and does not rank the two variants, so the entry now says so, marks the ranking as analyst judgement and moves from high to notable priority. The citation follows the page to its new address on bacs.admin.ch.

NCSC Switzerland ties only the first variant, the WhatsApp refund scam, to the April 2026 Booking.com data leak. It calls the second, the takeover of hotel booking-system accounts, long-known, and it does not rank the two (NCSC-CH, 2026-06-02). The title, summary and analysis now say so, and the view that the second is the harder one to spot is marked as analyst judgement. The phishing pages imitate TWINT and a bank, and NCSC speaks of victims generally without narrowing them to Switzerland or to a sector, so the entry's priority is notable rather than high. The citation now points at the page's new address on bacs.admin.ch, after the old ncsc.admin.ch page went dead.

HIGHupdatedNATOA3

NCSC Switzerland warns of cyber operations around the G7 Évian summit (15–17 June)

First published 2026-06-03 · open finding →

Correctionrun 2026-09-30T0634Z-auditsourcestechniquesclassificationsummaryentitiesbody

ZENDATA's risk map names social engineering of hotel help desks, not of event staff, and is the source of the Geneva arrivals claim, so the analysis now says so and cites it. NCSC warns that such events are often used for cyberattacks rather than calling the summit a high-value target, and the analysis now quotes it and marks the exposure of Swiss administrations and suppliers as analyst judgement. The NCSC citation follows the page to its new address on bacs.admin.ch.

ZENDATA's risk map for the summit names social engineering of hotel help desks among the plausible vectors, not social engineering of event staff, and the analysis now says so (ZENDATA Cybersecurity, 2026-05-03). The observation that most delegations arrive through Geneva and stay on the Swiss side comes from the same map and now cites it. NCSC Switzerland's advisory warns that large events and conferences are "often used as an opportunity to stage a cyberattack", not that the summit is a high-value target, and the analysis now quotes it. Neither source says that the Swiss administrations, suppliers and telecom operators the analysis places in the blast radius will be targeted at Évian, so that exposure is now marked as analyst judgement. The advisory is cited at its new address on bacs.admin.ch (NCSC Switzerland, 2026-06-01).

HIGHCVE-2026-54154 +7updatedNATOB2

Kiteworks (formerly Accellion) tells customers worldwide to shut down after 'credible' law-enforcement intelligence of an imminent attack, then publishes fixes including an unauthenticated chain to root in its Email Protection Gateway (CVE-2026-54154, CVSS 10.0)

First published 2026-09-26 · open finding →

Updaterun 2026-09-30T0404Z-intelsummarysourcesevidenceactionsbody

Kiteworks's own release of 2026-09-28 says its engineering and security work during the customer-wide shutdown led to the discovery of a previously unknown critical vulnerability in a capability enabled for under 1% of its customers, that it deployed a fix during the window and an extra protective layer across all environments, and that it has no indication the vulnerability was exploited. The release names no component or CVE.

Kiteworks's own release, dated 2026-09-28, reports the outcome of the shutdown: the threat window "passed without incident", and the company has no indication that any Kiteworks or customer system was compromised (Kiteworks, 2026-09-28). It adds that its engineering and security activity during the shutdown led to the discovery of "a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base", that Kiteworks developed and deployed a fix during the window and applied an additional protective layer across all environments, and that it has no indication the vulnerability was ever exploited; all other Kiteworks products were unaffected (Kiteworks, 2026-09-28). The release names no component and no CVE; whether it is the Advanced Forms flaw that BSI listed on 2026-09-27 is not stated. The vendor's own statements are the only source for the discovery, the fix and the absence of exploitation, and customers with questions are pointed to Kiteworks Technical Support (Kiteworks, 2026-09-28).

HIGHupdatedNATOB1

Unauthorized users had nine months of unencrypted access to a Pentagon HR file-sharing server; a defense official counts 2.76 million living and 294,000 deceased people affected, with Social Security numbers exposed

First published 2026-09-27 · open finding →

Updaterun 2026-09-30T0404Z-inteltitlesummarysourcesevidencebody

A U.S. defense official told ABC News on 2026-09-29 that the DMDC breach affected 2.76 million living people and another 294,000 who are deceased, replacing the earlier estimate of about four million from two unnamed people. The official's statement describes unauthorized access by a small number of unauthorized users between October 2025 and July 2026 and says the vulnerability was remediated on discovery.

A U.S. defense official told ABC News that the breach affected 2.76 million living people and another 294,000 who are deceased, about 3.05 million in all, against the roughly four million the earlier reporting carried (ABC News, 2026-09-29). The official's statement says a DMDC information system experienced unauthorized access to personally identifiable information by "a small number of unauthorized users" between October 2025 and July 2026, and that DMDC remediated the vulnerability on discovery (ABC News, 2026-09-29). Defense officials told ABC they have found no evidence so far that the exposed information has been misused and are offering identity-protection and credit-monitoring resources (ABC News, 2026-09-29). The statement still names no vulnerability class, access vector or actor.

HIGHupdatedNATOA1

France's tax authority says it cut the intruders' accounts in June and July and found no data theft; it took the criminal's sale listing two months later to establish that 678,000 records had already gone

First published 2026-08-15 · open finding →

Updaterun 2026-09-30T0404Z-inteltitlesummaryentitiestechniquessourcesevidencebody

ANSSI published its incident report on the DGFiP intrusions on 2026-09-29. It names three failures: staff credentials stolen from personal equipment and used on portals with no strong authentication, sensitive applications reachable from the inter-ministry network without segmentation, and detection gaps at both DGFiP and ANSSI; The Hacker News, reading the full report, adds that the attack was unsophisticated, which is the opposite of the ministry's August explanation for the missed theft.

France's ANSSI delivered its incident report on the DGFiP intrusions to the Prime Minister on 2026-09-24 and published it on 2026-09-29. It reconstructs two exfiltration waves between May and August 2026, one against the impots.gouv.fr platform and one against land-registry data, and names three failures (ANSSI, 2026-09-29).

Identity. The attackers stole and used legitimate DGFiP staff credentials; ANSSI ties the theft to those credentials having been used on personal equipment, combined with the absence of strong authentication on the portals that reach sensitive resources (ANSSI, 2026-09-29). The Hacker News, reading the full report, adds that the passwords were probably taken by infostealer malware from computers DGFiP did not manage, that two portals asked for a password only, and that the accounts held no special privileges yet could reach a large amount of data (The Hacker News, 2026-09-29).

Architecture. Sensitive applications were exposed on the Internet, or reachable from the inter-ministry network without segmentation, which allowed lateral movement from a third-party body's resources, in this case the Education ministry (ANSSI, 2026-09-29).

Detection. Neither wave was detected by DGFiP's or ANSSI's monitoring: DGFiP's teams did not supervise one of the portals used to exfiltrate and nothing correlated the suspicious signals, and ANSSI's sensors sit only at the inter-ministry network's entry and exit points and the Internet, without access to application logs (ANSSI, 2026-09-29). The Hacker News reports that the data was pulled from the E-Contact tool through the second portal using automated scraping tools that copy data page by page (The Hacker News, 2026-09-29), that a June password reset addressed the alert on the first portal but did not end the attacker's open session on the second, so data kept flowing for almost 16 more hours, and that no alert fired on data volume or per-user request counts, including the 11 GB moved in three days (The Hacker News, 2026-09-29). It adds that the land-registry route went through a partner portal whose emailed one-time code was bypassed after a land surveyor's computer at a private firm was possibly compromised (The Hacker News, 2026-09-29). It also reports that ANSSI's report calls the attack unsophisticated, which contrasts with the ministry's August statement that the theft escaped detection because of the attack's sophistication (The Hacker News, 2026-09-29).

Recommendations. As summarised by The Hacker News, ANSSI recommends revoking every active session on all applications whenever a password is reset, reviewing a compromised account's activity from the likely date of compromise, using multifactor authentication whose second factor survives password theft (an emailed code is not enough if the same password opens the mailbox), monitoring every business application in a SIEM with quotas on records, requests and data volume, and refusing personal devices for work resources (The Hacker News, 2026-09-29). ANSSI's own page says an action plan addressing the exploited failures has been agreed with DGFiP (ANSSI, 2026-09-29).

Triage: night-time logins, VPN or foreign-address connections and large volumes each cause false alarms alone; The Hacker News reports ANSSI's view that combined with a per-user request count they could have raised an alert (The Hacker News, 2026-09-29).

CRITICALCVE-2026-94127exploitedupdatedNATOA1

CVE-2026-94127, F5 BIG-IP APM: unauthenticated heap overflow in OAuth-profile processing reaches RCE on the TMM data plane (CVSS 9.8)

First published 2026-09-23 · open finding →

Improvementrun 2026-09-30T0404Z-inteltagscvessourcesevidencebody

watchTowr Labs published a patch-diff analysis on 2026-09-23 that makes the trigger public: an Authorization header longer than 0x4100 bytes sent to the OAuth UserInfo path overflows a fixed heap buffer and crashes the traffic-management process, and watchTowr shows a route from that crash to command execution.

watchTowr Labs published a patch-diff analysis of CVE-2026-94127 on 2026-09-23 that makes the trigger public. The fix adds a size check before an Authorization header is copied into a heap buffer allocated at 0x4100 bytes on the OAuth UserInfo path; before the patch there was no check, so a longer header overflows the buffer (watchTowr Labs, 2026-09-23). In watchTowr's lab a single GET request to the OAuth userinfo endpoint, carrying a Bearer Authorization header larger than 0x4100 bytes, crashed the traffic-management process (watchTowr Labs, 2026-09-23). watchTowr found that the process binary is not position-independent and that an object holding a function pointer usually landed just past the overflowed buffer in its runs, which lets the overflow redirect execution; SELinux blocked direct process execution, so it turned to the hook script the appliance runs each time the traffic-management process crashes and appended a command to it (watchTowr Labs, 2026-09-23). The request-side signal to add to the authentication-log signals above is therefore an Authorization header far larger than a normal Bearer token sent to the OAuth UserInfo path, followed by a crash and restart of the traffic-management process.

CRITICALCVE-2026-88771 +7exploitedupdatedNATOA1

CVE-2026-88771 / CVE-2026-88772, Citrix NetScaler ADC and Gateway: unauthenticated pre-auth RCE zero-days exploited before a patch existed (CVSS 4.0 9.5)

First published 2026-09-28 · open finding →

Updaterun 2026-09-30T0404Z-intelsummaryimmediate_actiontagscvesentitiestechniquessourcesevidenceactionsbody

Google's Mandiant and GTIG report the exploitation campaign has run since at least early September, with government among the impacted sectors in North America and Europe, and describe post-exploitation web-server-configuration persistence, the WHIPSHOT web shell and the SLAPSHOT tunneler; eSentire places CVE-2026-88771 exploitation from 5 September. watchTowr published the CVE-2026-88772 root cause and NCSC Switzerland now lists a proof of concept for both flaws. Mandiant's interim controls (disable DTLS, block UDP/443 upstream) cover CVE-2026-88772 only, NetScaler 12.1 and 13.0 are end of life with no fix, and a shared municipal operator in Rhineland-Palatinate shut down citizen-service systems statewide as a precaution, a shutdown heise links to these NetScaler updates while the operators name no vendor.

Exploitation predates the bulletin. Google's Mandiant and Threat Intelligence Group identified in-the-wild exploitation of CVE-2026-88772 and report that the campaign has run since at least early September, with organizations in North America and Europe in government, financial services, technology, education, and legal and professional services likely impacted (GTIG/Mandiant, 2026-09-29). eSentire independently reports CVE-2026-88771 exploited against internet-facing NetScaler Gateway appliances as early as 5 September (eSentire, 2026-09-29), and GreyNoise recorded a failed pre-disclosure attempt on 24 September that already used the setuid-and-handler playbook described below (GreyNoise, 2026-09-28). GTIG and GreyNoise name no actor. CERT-EU traced the activity through NetScaler logs from the European Court of Auditors and the European Central Bank, which showed requests carrying Base64-encoded shell commands in the HTTP User-Agent header (CERT-EU, 2026-09-28). An appliance upgraded after the 27 September bulletin may therefore already have been compromised: "Patching does not remove persistence an attacker already installed" (Censys, 2026-09-30).

What the actor leaves behind. After the DTLS exploit runs shellcode as root, a first-stage web shell rewrites the appliance web-server configuration so that files with non-script extensions run as PHP; in one variant an alias maps requests for image files under the VPN media path onto a staged shell, so the traffic looks like image fetches, and the shells answer with HTTP 404 while taking Base64 commands from HTTP request headers, including NSC-prefixed ones (GTIG/Mandiant, 2026-09-29). The installer sets the setuid bit on /bin/sh so later web requests run as root, scrubs its staging path from /etc/crontab and reboots the appliance to apply the change (GTIG/Mandiant, 2026-09-29). The PHP shell WHIPSHOT relays requests over loopback to SLAPSHOT, a Python TCP tunneler that Mandiant saw used for internal reconnaissance and credential theft in at least one intrusion (GTIG/Mandiant, 2026-09-29).

Exploit availability for CVE-2026-88772. GTIG states it holds no exploit code (GTIG/Mandiant, 2026-09-29). watchTowr published a root-cause analysis and a detection-artifact generator on 29 September: DTLS handshake reassembly keeps almost the whole record for each one-byte fragment, so after 120 records the buffer chain holds about 174 KB, which a packet-engine function copies into a 35,840-byte scratch buffer without a size check (watchTowr Labs, 2026-09-29). NCSC Switzerland's advisory now lists a proof of concept for both CVEs (NCSC-CH, 2026-09-29), and Help Net Security reports the activity turned into opportunistic mass exploitation after a public root-cause analysis and proof of concept for CVE-2026-88771, while its text says there was no public proof of concept for CVE-2026-88772 (Help Net Security, 2026-09-29).

Interim controls and containment. For appliances that cannot be patched at once Mandiant lists three network restrictions: disabling DTLS on internet-facing Gateway virtual servers where it is not needed and blocking inbound UDP/443 at an upstream firewall or edge router (local ACLs let the traffic reach the packet engine first) are specific to CVE-2026-88772 and "should not be relied on to mitigate CVE-2026-88771", while upstream IP allow-listing, where source ranges are predictable, is not scoped to one CVE and may be impractical for large remote workforces (GTIG/Mandiant, 2026-09-29). For a suspected compromise it advises isolating the node, halting high-availability configuration sync until both nodes are validated because a compromised node can replicate a modified web-server configuration to the standby, restricting appliance egress, and, after patching, rotating appliance and integration credentials and terminating Gateway and ICA sessions (GTIG/Mandiant, 2026-09-29). NetScaler 12.1 and 13.0 are end of life and no longer receive security updates, and Citrix has not said whether they are affected (Tenable, 2026-09-27). Censys counts 42,735 exposed NetScaler ADC and Gateway hosts, with Switzerland among the countries at roughly 4% each; these are exposed instances, not confirmed-vulnerable ones (Censys, 2026-09-30).

Hunting. By telemetry class: appliance web-server configuration containing handler or alias directives that point public paths at script directories; script content in the client plug-in and media directories, which should hold compiled clients and static assets; 404 responses with multi-kilobyte bodies or long processing times on media paths; the setuid bit on /bin/sh; lock and port-pointer files in the temp directory; and, for CVE-2026-88772, a DTLS handshake-failure "Internal Error" line in the syslog together with a packet-engine termination line and a watchdog "NOT restarting" line in the FreeBSD system log, which NetScaler does not forward to a SIEM by default (GTIG/Mandiant, 2026-09-29). Triage: GTIG lists the handshake-failure line and the packet-engine termination with its watchdog line as the two log artifacts of successful exploitation, so look for them together and pair them with a check for configuration drift.

A shared municipal operator shut down as a precaution. The two municipal data centres of the Rhineland-Palatinate association ZIDKOR shut down centrally hosted specialist applications on Sunday 27 September after a security vulnerability became known, taking resident-registration, ID-card, vehicle-registration and civil-registry services offline across all 194 full-time administered municipalities, cities and counties while they installed the vendor's patches; the operators say no successful cyberattack occurred, and each administration ran its own continuity plan with no central instruction (ZIDKOR release via AK-Kurier, 2026-09-28). Mainz and Kaiserslautern reported regular service again on the morning of 29 September (dpa via Rhein-Zeitung, 2026-09-29). The operators name no vendor; heise assesses that the trigger was probably the NetScaler updates released that weekend, a link it added to its article after publication (heise online, 2026-09-29). Cantonal and communal IT providers that host citizen services behind a shared NetScaler front end face the same trade-off between shutting down to patch and staying reachable.

04Action items1 item

Verification & coverage notes2 runs

2026-09-30T0634Z-audit · audit · Opus 5.5 (1M context) · window 9 h · 0 entries published

Verification & coverage notes

Operator-directed follow-up to the 2026-09-29 audit (2026-09-30): use WebFetch where it makes sense for the sources the container cannot read, change CLAUDE.md to match, cover the missing Apple CVE-2026-86950 entry, and repoint the four entries whose NCSC-CH citations had gone dead. Report: docs/audits/2026-09-30-quality-audit.md.

Fetch policy (v4.18). CLAUDE.md, both agent definitions, cti-run.md and quality-audit.md now sanction WebFetch for hosts the container is walled out of, as the fetch ladder's fourth rung ahead of the metered reader. cisa-kev, cisa csaf-recent and ncsc-csh stay on the bridge. v4.17's setup review, which landed on main during this run, had already moved the three records to fetch_method: webfetch, so this release aligns the rules and the health check with them. Tested before the change: WebFetch read the cisa.gov news listing and the cybersecurity-advisories listing with dates and item URLs, and the directives list with item URLs, and read an ssd-disclosure.com advisory page. An independent source-recipe pass (SR1) confirmed the three CISA recipes down to drilled pages. ssd-disclosure.com did not hold up: WebFetch read one of its advisory pages once, then SR1's 26 calls over 18 URLs returned 24 empty bodies and 2 replays of that cached read, and once the reader pool was refilled (about 07:40Z) the funded reader got the same SiteGround captcha on every try, so no transport reads SSD and it goes to fetch_method: blocked, a documented coverage gap served by WebSearch leads. source_health.py gives such records, when the container is actually walled out, the verdict webfetch-only (handled) instead of unreadable or needs-bridge, retries a walled, undated or failed-feed read up to twice before flagging it, and the Ops panel lists the webfetch-only records separately. A 404 or parked page is not a wall, so it still surfaces. Most of the 83 fetch_method: webfetch records predate extract and read cleanly with it, so the agents try extract first there.

Apple CVE-2026-86950. This run composed an entry from Apple's three security notes, the KEV record and three outlets, then found on syncing that the 2026-09-30T0404Z intel fire, which landed on main at about 06:45Z, had already published one (entries/2026-09-30/cve-2026-86950-apple-coregraphics-zero-day-kev.md) carrying the same facts plus CVSS and EPSS. This run's draft was dropped as a duplicate, with its registry and state rows, so the item is closed by the intel fire.

Repointed citations. Four June entries cited ncsc.admin.ch pages that now answer 404 after the agency's move to bacs.admin.ch. Each now cites the same page on bacs.admin.ch. Re-reading each page against its entry also found wording the page does not support (a "coordinated surge" of three reported cases, both scam variants tied to the Booking.com leak, mailbox forwarding rules the page never mentions, hardened hedges, a misnamed ZENDATA vector), so each change is a correction record with its own section. The week 22 and week 25 entries move from high to notable priority, since NCSC names no sector and no constituency exposure for either. Each record also adds the ATT&CK mapping, limited to what the page supports, and the Admiralty rating those pre-v3.18 entries lacked. The week 25 entry's spliced evidence quote is now verbatim quotations.

Registry. The names and summaries of campaign:ncsc-ch-jobseeker-targeting-2026 and incident:ncsc-ch-booking-hotel-phishing-2026 and the summaries of report:g7-evian-2026 and campaign:ncsc-ch-m365-voicemail-phishing-week25 follow the corrected entries, and the G7 and week 25 entries now link report:g7-evian-2026 and campaign:ncsc-ch-m365-voicemail-phishing-week25.

Sub-agent models. Recorded per sub-agent and verifier iteration above.

2026-09-30T0404Z-intel · Sonnet 5.5 · window 26 h · 4 entries published

Verification & coverage notes

Coverage window: standard (gap_hours=23.98, window_hours=26); no catch-up disclosure required.

Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 --run-id found one CISA KEV addition not covered by the store, CVE-2026-86950 (Apple CoreGraphics, added 2026-09-29). It is published as a new entry (2026-09-30/cve-2026-86950-apple-coregraphics-zero-day-kev); S1 confirmed catalog version 2026.09.29 is the latest and no addition followed it (work/2026-09-30T0404Z-intel/kev-window.txt).

New entries (4): Apple CoreGraphics CVE-2026-86950 (vulnerability, high; exploited against targeted iOS users, KEV-listed); Manno (TI) commune ransomware (incident, notable; Swiss communal administration, victim's own notice, SafePay claim attributed only); Star Blizzard RedFlick (threat, notable; Russian state actor, governments and diplomatic bodies among named targets, new single-click delivery chain); Storm-3068 SSPR to Azure DevOps to Kubernetes credentials (threat, notable; Microsoft DART first-party case).

Updates (5): Citrix NetScaler CVE-2026-88771/88772 (update, priority stays critical): Google GTIG/Mandiant campaign since early September, post-exploitation persistence, exploit availability for 88772, interim controls for 88772 only, EOL branches, and the Rhineland-Palatinate municipal shutdown with heise's link to NetScaler kept as heise's assessment; F5 BIG-IP APM CVE-2026-94127 (improvement, no float): watchTowr's public trigger of 2026-09-23 that the entry never recorded (a store gap found by S1, dated outside the window, so it ships as an improvement and not as news); DGFiP tax-authority intrusion (update): ANSSI's own incident report of 2026-09-29; Pentagon DMDC breach (update): a defense official's figure of 2.76 million living and 294,000 deceased replaces the earlier estimate of about four million; Kiteworks shutdown warning (update, added after verifier iteration 1): Kiteworks's own release of 2026-09-28 says its engineering and security work during the shutdown led to a previously unknown critical vulnerability being found and fixed in a capability used by under 1% of customers, with no indication of exploitation.

Source allocation: 97 sources attempted by the previous two fires were excluded from the rotational slices as belt-and-braces (state-summary.json rotation cursor built normally). S1 and S4 fell back to cursor-only ranking because the exclusion would have left them empty (every breaches source had been attempted in both prior fires); S4 was also given the six unallocated breaches-tagged sources (bleepingcomputer, piyolog, ransom-isac, troyhunt, venarix, zaufana-trzecia-strona). Slices: S1 17, S2 24, S3 18, S4 13; every record has a ledger row, so no continuation was needed.

Backlog work (state/coverage_backlog.md): nineteen of the 22 open rows were re-gated on today's facts and no row was struck (the Siemens S7 advisory AA26-231A row, the Spring Ring row and the four-item PD-11(d) row were not re-read, and the research-blog row was not worked). No change on seventeen; DIVD shows a partial development (technical vulnerability, not NetScaler, and an AI-agent post-exploitation phase; product and class undisclosed; fuller update promised 2026-10-01) and is held one cycle. Four new rows opened: MikroTik RouterOS CVE-2026-84411, IBM Guardium CVE-2026-85542, ARA-Region Lyss-Limpachtal (SafePay claim), Netech AG (Payload claim). Manno (TI), previously tracked only through a leak-site claim in S2/S4 leads, is published now that the commune's own notice was read.

  • borderline-drop: MikroTik RouterOS CVE-2026-84411 (pre-auth integer underflow, CVSS 9.8): CISA-only, no known exploitation, and CISA's text contradicts itself on the fixed build while MikroTik does not name the CVE; regular-cycle at this evidence (backlog row opened).
  • borderline-drop: WatchGuard AP below 3.4.8 (CVE-2026-101891 / CVE-2026-86102, CVSS 4.0 9.3): NCSC-CH advisory 13007 exists, but WatchGuard's PSIRT says it is not aware of exploitation and the attacker needs network access to the AP; regular patch cycle.
  • borderline-drop: Zimbra Collaboration 10.1.21: the headline password-recovery flaw has no CVE yet, nothing is exploited, and the store already carries the exploited SNMP flaw fixed in 10.1.20; regular patch cycle.
  • borderline-drop: IBM Guardium Data Protection CVE-2026-85542 (CVSS 3.1 8.8): ACN's alert AL04/260928/CSIRT-ITA reports active exploitation of a patched flaw (needs an authenticated remote user; GIM bundle import injects arguments into tar), but the alert is dated 2026-09-28 (outside the window), the flaw is not KEV-listed and the product's footprint in the constituency is unestablished; the primary was read in full after verifier iteration 2 and the backlog row now carries its facts.
  • borderline-drop: Ticino eAutoindex delta (Ticino as a further victim of the vehicle-lookup scraping, paid lookups from 2026-11-01): out-of-window, primary 2026-09-28, and the delta is one more canton disclosed around 2026-09-03 plus a fee control.
  • borderline-drop: FTAPI (Munich secure file-exchange vendor) ransomware: the vendor states its platform and customer systems were unaffected, no Swiss customer link is established, no access vector is stated; the fraud caution for customers is its own.
  • borderline-drop: ENISA Threat Landscape 2026: out-of-window (published 2026-09-22) and an awareness and statistics report with no change to what a responder does in the next seven days.
  • borderline-drop: Lomazzo (IT) commune mailbox takeover used to send fake fines: small foreign commune, vector and scale unstated; the trusted-sender pattern is already carried by the Martigny-Combe and Revolut entries.
  • borderline-drop: DIVD agentic-AI breach: held in the backlog until DIVD's promised 2026-10-01 update names the product or class.
  • borderline-drop: Fakturownia.pl breach (the same actor's third Polish victim): Polish SME invoicing SaaS, no Swiss or public-sector link, exploit chain is the actor's claim relayed by one outlet.
  • borderline-drop: ShinyHunters/FBI Dutch-police and FBI-video delta: law-enforcement colour, not defender-relevant; the arrest is already recorded.
  • borderline-drop: OpenAI's four Australian incidents: Australian agencies, second-hand (the OpenAI post returns 403 to every transport), and the AI-agent thread already has seven entries.
  • out-of-window: NeedyMantis (Microsoft Threat Intelligence, primary 2026-09-28T15:00Z) and the ChatGPT Custom-GPT ClickFix campaign (Huntress, primary 2026-09-28T20:00Z), window_hours=26; both are also generic-relevance items, so neither is a backlog row.
  • borderline-drop: MSP360-to-ScreenConnect RMM phishing (unattributed, generic RMM hardening); VUSec Branch Target Reuse (academic Spectre-v2 variant, kernel mitigations merged, needs local code); DarkSword iPhone Duo lure (consumer scam lure for a chain Apple patched in March); MCP Python SDK OAuth flaw (library flaw, no CVE, no exploitation).
  • borderline-drop: Junta de Andalucía (MedusaLocker), Alaxione (ChimeraZ), CENELEC/CEN (Everest), Netech, ARA Lyss and SafePay's other Swiss listings: claim-only under PD-6 or out of nexus; the last two are backlog rows.
  • borderline-drop: CISA ICS advisories of 2026-09-29 other than MikroTik, ENISA EUVD criticals (AiSOC, GLPI, Ziroom), Mozilla MFSA 2026-97 to 100, Chrome 154.0.8037.92/.93, PyJWT and decompress advisories: regular patch cycle, none exploited.
  • Single-source: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain and 2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft: Microsoft's own telemetry and casework (Admiralty B, original vendor research); no independent second observation exists. 2026-09-30/manno-ti-commune-ransomware-safepay-claim: single-source-victim, the commune's own notice; SafePay's role is a tracker-recorded claim.
  • Contradiction: 2026-08-15/france-dgfip-tax-authority-credential-intrusion: the ministry's August statement attributed the missed detection to the attack's sophistication, while The Hacker News reports that ANSSI's report calls the attack unsophisticated; the update states both with attribution and the earlier statement stays attributed to the ministry.
  • Coverage gaps: inside-it-ch (essential; article pages return a Vercel checkpoint 429 on every transport and the reader pool is exhausted, so only RSS teasers were readable; the Manno and Sesamvote articles were not read); openai.com (403); lore.kernel.org (Anubis); computerweekly.com/de (403); cybersecuritynews.com (Cloudflare 202); cyberattaque-org (connection reset); securityaffairs and proofpoint (S3 slice: no drill-down URLs on any transport tried); msrc-blog (SPA shell after a 301); wiz-blog (feed live, newest item 2026-09-01); ncc-research and prodaft (listings carry no dated posts); censys.com/advisory listing (timeout; per-advisory pages read fine).
  • Essential-coverage: none missed; all 17 essential records were attempted (inside-it-ch as noted above).
  • The jina reader credential pool was exhausted (HTTP 402 on all keys) across every domain this fire, a normal condition; extract and the bridge recipes covered every source that mattered.
  • Candidate sources: added anssi-cyber-gouv-actualites (ANSSI now publishes incident reports under cyber.gouv.fr/actualites; RSS works) and fuitesinfos (French breach tracker already cited in standing backlog rows). Not added for lack of a working recipe: censys-advisories (S1: per-CVE advisories with exposure by country, listing times out) and rsi-info-ticino (S2: Ticino regional broadcaster, no RSS).
  • Recipe fixes applied from the sub-agent reports: rss_url set for volexity, zscaler-threatlabz, talos, group-ib and infoguard-ch; recipe notes for technadu, cnil-fr, ransomware-live, inside-it-ch, venarix, ec-digital-strategy-newsroom, enisa, zaufana-trzecia-strona and ico-uk (sources_changed[]).
  • Store observation for the next audit (S4): entries/2026-08-23/martigny-combe-valais-communal-mailbox-compromise.md and entries/2026-08-28/martigny-combe-valais-municipal-email-compromise.md appear to describe the same Martigny-Combe mailbox compromise, a one-entry-per-finding violation to merge through changelog records.
  • Store observation for the next audit (S1/S2): the F5 BIG-IP APM entry lacked the public-trigger fact until this fire; Austria's NISG procedural detail (USP registration by 2027-01-01) sits on a page dated 2026-09-08 and could support a later update on 2026-09-23/austria-nisg-2026-bcs-transposition.
  • Source health (tools/source_health.py): three records remain on the UNSOLVED list, all reader-dependent and already documented by the 2026-09-29 audit: cisa-directives and cisa-news (www.cisa.gov returns an Akamai 403 to every free transport) and ssd-disclosure (HTTP 202 JavaScript challenge; candidate). Re-probed this fire: no free transport reads any of the three, and the reader pool is empty. The agent-side WebFetch reads the CISA pages, so they are neither demoted nor re-pinned; the health check exercises only fetch_source.py, so the flag stays a false positive until reader credit is refilled.
  • Contradiction: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev: Help Net Security's text (2026-09-29) says there was no public proof of concept for CVE-2026-88772, while NCSC-CH's advisory history records an edit adding a PoC for CVE-2026-88772 at 14:41Z the same day (watchTowr's tool is a detection-artifact generator); the update states both with attribution and the CVE records carry poc-public.
  • Verifier iteration 1 (declined, low confidence): the NeedyMantis out-of-window drop stands (Microsoft primary 2026-09-28T15:00Z, window_hours=26). The nexus argument (China-aligned implant in telecom, intergovernmental and government-contractor intrusions, pivoted from the DAEMON Tools compromise) is real but generic to this constituency, so the audit can recover it if it judges otherwise. Run-record wording about sub-agents and S1-S4 ids is kept: this record is operator-facing and prior records use the same ids.
  • Essential-source coverage: five sources (bacs-press, fortinet-psirt, msrc-update-guide, paloalto-psirt, watchtowr) entered the source list as essential through the v4.17 review that merged to main after this fire had sliced its sources, so no sub-agent was assigned them; the merge at publication carries them, and the next fire's allocation includes them. No finding of this run depends on a first-party Palo Alto, Fortinet, MSRC or BACS feed.
  • Verification outcome: six iterations. Iterations 1 to 4 returned NEEDS_FIXES (22, 10, 6 and 4 findings) and every truth and editorial finding was remediated or declined with a recorded reason; iterations 5 and 6 were consecutive cold CLEAN passes with advisories only, so the run publishes on a confirmed CLEAN with no residuals. The verifier's advisories left open are listed under iteration 6 for the next audit.