Verification & coverage notes
Coverage window: standard fire. The previous intel fire started 2026-10-02T04:04Z, so gap_hours=24.0 and window_hours=26; the developing-story window was 72 hours. The container clock was cross-checked against an external date header (skew 0 s) and origin/main was fresh at preflight.
Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found two CISA KEV additions in the window, Zammad CVE-2026-102489 and CVE-2026-102490 (added 2026-10-02), both COVERED by the existing Zammad entry; no row was NOT COVERED, MENTION-ONLY or COVERED-STALE (work/2026-10-03T0404Z-intel/kev-window.txt). S1 confirmed catalog version 2026.10.02 and found every EUVD-exploited record already covered.
New entry (1): Longlegs (Storm-2603) and the Warlock ransomware, still entering through on-premises SharePoint (threat, high; Symantec's report of 2026-10-01 with same-day-plus-one relays by BleepingComputer, The Record and SecurityWeek; single assessor, so verification is single-source and credibility 2). It was surfaced by two domains independently (S3 and S4); the primary is a day older than the window start, and it passed the recency rule because the freshest sources are the in-window relays and nothing in the store covered it. Priority is high because on-premises SharePoint is the entry technology of two Swiss breaches already in the store and the machine-key theft means patching alone does not close the exposure. No CVE record is carried: Symantec names the ToolShell CVEs only as likely still in the arsenal.
Updates (3): FortiMail CVE-2026-104286 (update: Belnet's notice, which links this advisory, puts exploitation from 2026-07-22; NCSC Switzerland's note on the artifacts; the entry now follows Fortinet's advisory as read on 2026-10-03, which words the second workaround as the webmail interface and adds a WAF rule on POST /ibe, while BleepingComputer and NCSC Switzerland say management interface; the previous fire's verifier read Fortinet's page with the management-interface wording and a file table, and the page's timeline lists only the initial publication, so Fortinet appears to have revised it without a timeline entry; the file list is now attributed to BleepingComputer and NCSC Switzerland and the CISA citation points to the per-event alert); Belnet incident (update: supplier named as Fortinet, FG-IR-26-175 linked, Centre for Cybersecurity Belgium engaged, transfers disabled on 2026-09-29; priority raised from routine to notable because a vector class is now known; the first evidence quote no longer matched the page and was replaced); Cisco Catalyst SD-WAN Manager CVE-2026-76504 (update: advisory revision 1.1 adds a Live Protect shield, temporary and partial, with a login side effect and a support rule limited to the current and two preceding releases of trains that include Live Protect).
Contradictions: NCSC-NL (NCSC-2026-0398) says Fortinet released security updates for FortiMail while Fortinet's table lists 8.0.2, 7.6.7 and 7.4.9 as upcoming; the FortiMail entry follows Fortinet and states the contradiction. BleepingComputer and NCSC Switzerland say management interface for the second workaround where Fortinet's current page says webmail interface; the entry follows the Fortinet page and says so.
Backlog (7 open rows, all held, none changed): S1 re-gated IBM MQ CVE-2026-10747 with the three Langflow CVEs, MikroTik CVE-2026-84411 and IBM Guardium CVE-2026-85542; S4 re-gated Qilin/Touring Club Suisse, Everest/Securitas, SafePay/ARA-Region Lyss-Limpachtal and Payload/Netech. Every stated hold condition is unmet (no KEV listing, exploitation report or public PoC; no victim statement or press confirmation; ZATAZ analysed the Everest file tree but states origin and access are unconfirmed). No row text was appended, per the no-carry-forward rule. Nearest expiry is Qilin/TCS on 2026-10-05.
borderline-drop / out-of-window:
- borderline-drop: OrdaSoft OS CCK for Joomla CVE-2026-102427 (unauthenticated PHP upload, CVSS 4.0 10.0, fixed in 8.3.16 but the vendor updater still offers 8.3.14): not exploited, not in KEV, niche extension with no constituency deployment evidenced, single source (mySites.guru); below the PD-11(b) bar.
- out-of-window: tac_plus pre-auth format string (elttam, primary 2026-09-23, beyond the source's 168 h lookback, CVE pending, internal management plane, no exploitation); Huntress municipal recreation-platform web shell (2026-09-30, US platform, no CVE).
- borderline-drop: NeedyMantis (Microsoft, 2026-09-28), already dropped by the 2026-09-30 and 2026-10-02 fires; TA419 (Proofpoint, 2026-10-01: adversary-in-the-middle phishing of US/Japan policy and defense staff, technique not new, indirect relevance); Microsoft Digital Defense Report 2026 (vendor telemetry shares read from PDF chart text, no defender decision); DragonForce Lab52/Seqrite (2026-10-01: a second backdoor with an MQTT fallback resting on one lab's artifact-overlap attribution, on a legacy entry whose guidance already covers TURN egress and side-loading); Sysdig's Zammad hunts (same signals as the entry's Detection line).
- borderline-drop: CERT-FR/CERT Santé health-software report CERTFR-2026-CTI-007 (no vendor, no CVE, French health sector); Swiss motion 24.4393 on .ch/.swiss domain-holder identification (a mandate to draft law, the text finally referred is not stated); BSI's Classic McEliece notice (cryptographic-baseline advice, not a SOC decision); SRG/SRF employee data (2020 contact data, no vector); ATEXO/Region Hauts-de-France, Svedala kommun and the US municipal incidents (incident floor: no vector, no actor, no behavior beyond impact; no Swiss nexus).
- borderline-drop: OpenAI's count of over 100 notified organizations (scope statement, no decision for the constituency, five entries already carry the saga); VOISING/ApplyNow Metabase fallout (the Metabase link is Piyolog's inference, Japan); the ANSSI REACTIV lab/DINUM details (read by eye from an image-only PDF, no new decision); the ShinyHunters arrest statements (vanity figures, no defender action); the Censys exposure share for NetScaler (improvement-only).
- borderline-drop: WatchGuard AP CVE-2026-101891 and CVE-2026-86102 (9.3, no exploitation, access-point management network), Zimbra 10.1.21 CVEs CVE-2026-66911 and CVE-2026-66912 (reserved, no exploitation; the fix is already carried by the CVE-2026-73570 entry), Dell CSM, GitLab AI Gateway, Apache httpd 2.4.69 (Apache rates all 20 as low or moderate), Joomla core 5.4.9/6.1.4, Chrome 154, Exchange CVE-2026-96940, Palo Alto CVE-2026-0250: patch-cycle items with no exploitation.
Single-source / reduced confidence: the Warlock entry rests on Symantec alone (relays add nothing); the Belnet-to-FortiMail link is Belnet's own pointer to the advisory, and Belnet does not name the product, which the entry states.
Sources: 26 changes in sources_changed: last-success dates for the six sources cited, recipe notes verified by the sub-agents (BleepingComputer and Fortinet direct feeds, the EUVD search API, YesWeHack, Censys, BSI's news listing, news.admin.ch, ransom-isac, Cloudflare Cloudforce One, elttam, ransomware.live endpoints), three new candidates (it-connect, mikrotik-routeros-changelog, parlament-ch-curia-vista-odata) the two due promotions (ibm-support-security-bulletins, europol-newsroom) and the health recipes for the three records the health check flagged (news-admin-ch, mikrotik-routeros-changelog, parlament-ch-curia-vista-odata: each now carries a tested health_cmd and content_scope: general-news). ssd-disclosure stays blocked on every transport.
Tool findings for the next audit (not fixed here): fetch_source.py pdf on an image-only PDF (CERTFR-2026-CTI-006) exits 0 and prints binary noise instead of reporting that the file has no text objects (S4's workaround: download the file and read rendered pages); fetch_source.py extract on theregister.com returns navigation boilerplate instead of the article body; the rapid7-research feed returned HTTP 404 (S3). The S1 sub-agent spent 7 unintended reader-pool fall-throughs (extract and feed auto-fallback), no deliberate reader use.
Coverage gaps: ssd-disclosure (blocked on every transport); inside-it-ch (article pages HTTP 429, RSS teasers only); ncsc-ch-incidents (undated listing, no in-window addition can be dated); anssi-fr (CERT-FR timestamps are flat 00:00 UTC); europol-newsroom (SPA shell, not in a slice); rapid7-research (feed HTTP 404, not in a slice).
Verification: three iterations, none CLEAN. Iteration 1 (truth 7, editorial 3) found the Fortinet file-table attribution, a wrong 'corrected' framing, a stale evidence quote and attribution slips; iteration 2 (truth 4, editorial 1) found a partly fixed rotation attribution and wording slips; iteration 3 (truth 2, editorial 0, no F1 or F4) found two low-confidence wording points and two advisories, so the early-exit rule applied: all four were fixed after the iteration and the run published without a fourth pass. verification_residual_count is 2, the final iteration's truth plus editorial count, although both findings are remediated on disk. The first-iteration finding on the Fortinet page is worth the audit's attention: Fortinet changed the advisory text (management interface to webmail interface, a file table dropped) without a timeline entry, so a vendor revision can be invisible to a check that trusts the page's own revision history.