CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
‹Tue · 06 Oct 2026
All daily briefs →
Daily brief · UTC day

Tuesday, 6 October 2026

2 verified findings from 1 run · 4 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

CriticalUpgrade every FortiMail to a fixed build now: the zero-day is exploited and fixes have shippedCVE-2026-104286 · exploited · updated 06 Oct 04:59Z
Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01Atlassian file-read flaw: root cause and checker now public; on Crowd-integrated Jira it ends in admin access. Atlassian's advisory of 2026-10-05 fixes CVE-2026-21589, an unauthenticated arbitrary file access flaw in every version of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center, plus Crucible and Fisheye (CVSS 4.0 9.3); Atlassian found no evidence of exploitation as of 2026-10-05 and tells customers to patch immediately or take internet-facing instances off the internet. watchTowr Labs published the root cause, the request shape and a runnable checker on 2026-10-06, and shows that where Jira is integrated with Crowd the file read exposes a plaintext Crowd application password that gives access to Crowd as an administrator of that application. →
  2. 02A Danish company's legitimate register access, abused, exposed 8.8 million people's names, addresses and CPR numbers. Denmark's CPR administration says unauthorised parties used a private Danish company's lawful right to search the Central Person Register to obtain names, addresses and CPR numbers of about 8.8 million of its roughly 11 million records (living, deceased and emigrated persons); the ministry says the access does not cover the names and addresses of people with name-and-address protection. The minister told Ritzau the access lasted about ten days in September through a smaller company whose security around that access had not been good enough, in her words. Datatilsynet's notice describes a very large number of automated lookups to identify valid CPR numbers; the actor, the company and how the access was obtained are not public. →

01Active threats, incidents & disclosures1 item

NOTABLEupdatedNATOA2

Denmark's CPR population register: unauthorised parties abused one private company's lawful lookup access for about ten days and obtained names, addresses and CPR numbers of 8.8 million people

Denmark's CPR administration noticed irregular behaviour in the register on the evening of Friday 2026-10-02, learned over the weekend that unauthorised parties had obtained names, addresses and CPR numbers of about 8.8 million registered persons, and says the access worked by misusing a Danish private company's lawful right to search the register, within the scope of data that private companies may access (translated from Danish) (Danish Ministry of Research, Education and Digitalisation, 2026-10-05). The register holds about 11 million records, covering living, deceased and emigrated persons, and the ministry says the unauthorised access does not cover the names and addresses of people registered with name-and-address protection; CPR stopped the company's access, reported the incident to the Danish data protection authority, and the police are investigating, with no statement yet on who is behind it (Danish Ministry of Research, Education and Digitalisation, 2026-10-05). Under section 38 of the CPR Act a private company with a legitimate interest may receive information on a larger delimited group of persons that it has identified individually in advance, by CPR number, date of birth and name, or by name and address (Danish Ministry of Research, Education and Digitalisation, 2026-10-05).

The digitalisation minister told Ritzau the access lasted about ten days in September and ran through a smaller Danish company, that an employee of the CPR administration spotted the unusual activity on 2 October, and that red lights should have lit when it went on for so long; she declined to say whether the investigation sees criminal intent at the company (Faglig Senior (Ritzau), 2026-10-05). Datatilsynet, the Danish data protection authority, says the register's notification describes a very large number of automated lookups made to identify valid CPR numbers (translated from Danish) (Datatilsynet, 2026-10-05). No source names the company or says how the access was taken over.

By abusing a Danish company's lawful access to search for information in the CPR system, unauthorised parties have obtained names, addresses, CPR numbers and more on about 8.8 million registered citizens in the CPR system. (translated from Danish)

Danish Ministry of Research, Education and Digitalisation 2026-10-05

It is clear to me that the security measures around this company's access to CPR have not been good enough. (translated from Danish)

Faglig Senior (Ritzau) 2026-10-05

The notification states that a very large number of automated lookups were made against the CPR system in order to identify valid CPR numbers. (translated from Danish)

Datatilsynet (Danish Data Protection Agency) 2026-10-05

It was an expensive invoice that hinted a breach had happened, not systematic alarms. (translated from Danish)

DR Nyheder 2026-10-06
Updaterun 2026-10-07T0404Z-intelsummarytechniquessourcesevidencesourcing_notebody

Datatilsynet said on 2026-10-05 that it received the register's notification on Sunday 2026-10-04 and that the notification describes a very large number of automated lookups against the CPR system to identify valid CPR numbers (translated from Danish) (Datatilsynet, 2026-10-05).

At the press briefing of 2026-10-06, DR reports, the authorities said an expensive invoice, not systematic alarms, hinted that a breach had happened, that police have been to a smaller company in person to collect traces, and that foreign police have been contacted in case foreign actors are behind it; the director of the agency for societal security (Styrelsen for Samfundssikkerhed) said the CPR number can no longer be used to authenticate a person (translated from Danish) (DR Nyheder, 2026-10-06). A head of centre at the national police unit NSK said police are looking at whether an algorithm was used, as a hypothesis, because so many lookups were made in a short time, and could not say more (DR Nyheder, 2026-10-06). The authorities did not say who is behind the breach, how it happened or whose access was misused (DR Nyheder, 2026-10-06).

incident06 Oct 04:57Zsingle-source · victim disclosureOpen finding →
HIGHCVE-2026-21589updatedNATOA1

CVE-2026-21589, Atlassian Data Center: unauthenticated arbitrary file access in every version of eight self-managed products, patch or take them off the internet (CVSS 4.0 9.3)

Atlassian's advisory of 2026-10-05 says every version of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center, and of Crucible and Fisheye, is affected by CVE-2026-21589, an arbitrary file access flaw that lets an unauthenticated attacker access specific files within the web application root directory (Atlassian, 2026-10-05). The attacker needs the target file's exact name and path and cannot enumerate or list directory contents, and Atlassian adds that in some configurations sensitive files are present that increase the risk (Atlassian, 2026-10-05). Atlassian's public ticket for Confluence Data Center labels the weakness "Path Traversal (Arbitrary Read/Write)" (Atlassian, 2026-10-02), while the advisory's CVSS 4.0 vector (9.3, Critical: network, low complexity, no privileges, no user interaction) rates the confidentiality impact high and the integrity and availability impact none on the vulnerable system, with high confidentiality, integrity and availability impact on subsequent systems (Atlassian, 2026-10-05). Atlassian Cloud is already patched and Atlassian says its investigation found no evidence of exploitation (Atlassian, 2026-10-05); The Register reports that Atlassian emailed customers on Monday pointing to the advisory (The Register, 2026-10-06).

The fixed versions are Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1; Confluence Data Center 9.2.26 and 10.2.19; Jira Service Management Data Center 5.12.40, 10.3.26 and 11.3.12; Jira Software Data Center 9.12.40, 10.3.26 and 11.3.12; Bamboo Data Center 10.2.24 and 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7 and 7.2.4; and Crucible and Fisheye 4.9.15 (Atlassian, 2026-10-05). Atlassian's Confluence ticket adds that versions past end of life may also be affected (Atlassian, 2026-10-02), and its Crowd ticket lists the same fixed Crowd builds (Atlassian, 2026-10-02). Until a patch is applied, Atlassian says to remove the instance from the internet where possible, including instances that require user authentication, or to block at a web application firewall or proxy any URL that carries '..' directly next to a slash, backslash or '::' in plain or percent-encoded form; it also gives a Tomcat RewriteValve rule for Confluence, Jira Service Management, Jira Software, Bamboo and Crowd and a urlrewrite.xml rule for Bitbucket (Atlassian, 2026-10-05).

This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions.

Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents.

Affected Atlassian Cloud products have been patched, and our investigation has not found evidence of exploitation.

Remove your instance from the internet until you can patch or apply mitigations, if possible.

Atlassian 2026-10-05

While we are not able to traverse outside of the Tomcat context, we discovered it is possible to read any file within the application server itself.

The password for the application, in plaintext.

watchTowr Labs 2026-10-06
Updaterun 2026-10-07T0404Z-intelheadlinesummarytagstechniquescvessourcesevidenceverificationsourcing_noteclassificationactionsbody

watchTowr Labs published the root cause on 2026-10-06 after comparing a vulnerable and a fixed build of the web-resource library that Jira, Confluence and Bitbucket share: its router converts a double colon in a request path into a slash before it resolves a plugin resource, so a traversal written with double colons leaves the resource directory through a deprecated relative-path resolver that is still reachable (watchTowr Labs, 2026-10-06). watchTowr says it cannot leave the Tomcat context but can read any file within the application server, and it shows working requests against Jira, Confluence and Bitbucket, with Bitbucket blocking one configuration file but not another under WEB-INF (watchTowr Labs, 2026-10-06).

The impact it demonstrates depends on the configuration: where Jira is integrated with Crowd, the crowd.properties file under WEB-INF stores the application name and its password in plaintext, and with those watchTowr reached Crowd's REST interface in its lab, created a user and added it to the Jira administrators group; it adds that a Crowd IP allow-list would make this harder (watchTowr Labs, 2026-10-06). watchTowr also published a Detection Artifact Generator on GitHub that sends the traversal to Jira, Confluence and Bitbucket hosts to test whether they are vulnerable (watchTowr Labs on GitHub, 2026-10-06). Neither watchTowr's post nor Atlassian's advisory of 2026-10-05 reports exploitation in the wild. Atlassian's Crowd ticket lists the same fixed builds as the advisory, 7.1.7 for the 7.1 line (Atlassian, 2026-10-02).

vulnerability06 Oct 04:56Zmulti-sourceOpen finding →

03Updates to prior coverage4 items

HIGHCVE-2026-0257exploitedupdatedNATOA1

CVE-2026-0257, Palo Alto PAN-OS GlobalProtect: pre-auth authentication bypass via certificate reuse, marked by CISA as used in ransomware campaigns

First published 2026-05-30 · open finding →

Updaterun 2026-10-06T0405Z-inteltitleheadlinesummarypriorityimmediate_actiontagsentitiestechniquesaffected_productssourcesevidencesourcing_noteclassificationactionsbody

CISA's KEV catalog (version 2026.10.04) now marks CVE-2026-0257 as used in known ransomware campaigns, and Arctic Wolf's report of 2026-07-20 describes June 2026 intrusions in which Qilin ransomware deployment began with the bypass, so an exposed, unpatched gateway needs a compromise assessment of the network behind it as well as the patch.

CISA's Known Exploited Vulnerabilities catalog (version 2026.10.04) now marks CVE-2026-0257 as used in known ransomware campaigns; the record names no group and its date of addition remains 2026-05-29 (CISA KEV catalog, 2026-10-04). Arctic Wolf Labs' report of 2026-07-20 says it investigated multiple distinct intrusions in June 2026 that ended in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewalls, and that the post-exploitation tradecraft ranged from rapid encryption-only operations to double extortion, possibly suggesting several affiliates of the Qilin ransomware-as-a-service operation (Arctic Wolf, 2026-07-20).

The chain Arctic Wolf describes starts with a GlobalProtect VPN session obtained through the cookie bypass, in some cases from systems that identified themselves as kali, and continues with registry Run-key persistence that points at a ransomware payload staged under C:\PerfLogs, remote-access tools (AnyDesk, Ngrok, LogMeIn and, in one case, a scheduled task consistent with MeshAgent), LSASS credential theft through rundll32 and comsvcs.dll into a file with an .odt extension, a full copy of the Active Directory database with ntdsutil, lateral movement with PsExec over administrative shares and RDP, a PowerShell routine that clears every Windows event log with records, and Microsoft Defender real-time protection disabled in some cases (Arctic Wolf, 2026-07-20). In the double-extortion cases data went to the MEGA cloud storage service with Rclone before encryption, and the attackers targeted the Veeam backup infrastructure before deploying the ransomware; some intrusions involved no data theft before encryption (Arctic Wolf, 2026-07-20). A gateway that was reachable and unpatched therefore needs a compromise assessment of the Windows estate behind it, not only the patch and a forced re-authentication.

HIGHCVE-2026-73570exploitedupdatedNATOA1

CVE-2026-73570, Zimbra Collaboration: a pre-auth command injection patched without a CVE in July is exploited, with probing before disclosure and root escalation, secret theft and cluster-wide movement observed

First published 2026-08-20 · open finding →

Updaterun 2026-10-06T0405Z-intelsummarytagsentitiestechniquessourcesevidencesourcing_noteactionsbody

CSIRT Italia's bulletin of 2026-10-05 reports compromises of exposed Zimbra servers through CVE-2026-73570 that ended in ELock-family ransomware, cryptomining, web shells with theft of the LDAP database and credential hashes, and a 48-hour mail outage for more than 6,000 mailboxes, and found no intrusion on regularly updated instances. Its host checks (the zimbra user's crontab and authorized_keys, JSP files in the Jetty public directory, droppers in temporary directories, egress) are added to the compromise check.

CSIRT Italia reports, in bulletin BL01/261005/CSIRT-ITA, multiple compromises of internet-exposed Zimbra servers handled in the Italian national context, mostly through CVE-2026-73570 and to a lesser extent through older flaws on unpatched or end-of-life instances (ACN / CSIRT Italia, 2026-10-05). In two CVE-2026-73570 cases exploitation ended in ransomware: on an 8.7.11 instance the attacker opened an interactive reverse shell and irreversibly encrypted many files on one node, and in a second case of unspecified version an ELock-family ransomware executable was dropped; both servers had the optional zimbra-snmp package, and the evidence does not tie the two cases to one actor or payload (ACN / CSIRT Italia, 2026-10-05). Three further cases installed cryptominers, one on 10.1.19 with a crontab entry for the zimbra user that ran a payload from a temporary directory (ACN / CSIRT Italia, 2026-10-05). In one case the exploit fetched a payload from external staging infrastructure and ran a Perl script directly in memory without writing files, with an attempted connection to a presumed IRC command-and-control server and no post-compromise activity found (ACN / CSIRT Italia, 2026-10-05). In two cases web shells were planted in the directories the web service exposes: on a 10.1.4 instance the attackers left JSP web shells, including ones managed with Behinder, and exfiltrated the LDAP database, the mailbox list and the credential hashes, and on another instance several JSP web shells took mail down for 48 hours for more than 6,000 mailboxes with no data theft documented (ACN / CSIRT Italia, 2026-10-05). The two cases share five command-and-control addresses and similar JSP constructs, but ACN says the evidence does not let it attribute both to the same actor (ACN / CSIRT Italia, 2026-10-05). ACN also describes a CentOS server turned into an SSH brute-force source after a write test in the Jetty public directory, with CVE-2026-73570 as the presumed but unconfirmed entry, and an end-of-life server whose mailbox passwords were all reset by the attacker through an undetermined vector (ACN / CSIRT Italia, 2026-10-05). Older flaws (CVE-2024-45519, CVE-2022-41352, CVE-2022-27925, CVE-2022-37042 and CVE-2023-38750) account for the remaining cases on unpatched or unsupported lines, including a further ransomware case on an 8.8.15 instance (ACN / CSIRT Italia, 2026-10-05).

ACN says nearly all affected systems lacked applicable patches or ran unsupported branches, that in several cases the attackers persisted without root by staying in the zimbra application user's context, and that it found no evidence of successful intrusions on regularly updated instances (ACN / CSIRT Italia, 2026-10-05). Its mitigations are to update, to disable or remove the zimbra-snmp package where patching has to wait, to inspect the zimbra user's crontab and /opt/zimbra/.ssh/authorized_keys, to look for SNMP exploit scripts under /opt/zimbra/data/tmp and for JSP files or stray text files in the Jetty public directory, to check /tmp and /var/tmp for droppers, miners and ransomware payloads, to rotate all mailbox and administrative credentials where web shells or anomalies are found, to keep the administrative port TCP 7071 and unneeded SOAP interfaces off the public internet, and to filter egress from the Zimbra servers, including IRC and TCP 8801 (ACN / CSIRT Italia, 2026-10-05).

CRITICALCVE-2026-104286exploitedupdatedNATOA2

CVE-2026-104286, Fortinet FortiMail: unauthenticated path traversal file write exploited as a zero-day, fixed in 8.0.2, 7.6.7 and 7.4.9 (CVSS 9.8)

First published 2026-10-02 · open finding →

Updaterun 2026-10-06T0405Z-inteltitleheadlinesummaryimmediate_actiontagscvessourcesevidencesourcing_noteactionsbody

Fortinet revised FG-IR-26-175 on 2026-10-05 and now names the fixed builds 8.0.2, 7.6.7 and 7.4.9 (7.2 users move to branch 7.4 or above), so the remediation moves from workaround only to upgrade; the workarounds and the compromise artifacts are unchanged.

Fortinet revised advisory FG-IR-26-175 on 2026-10-05: its timeline now lists a solution update and its solution table names fixed builds for every affected branch, 8.0.2 for 8.0.0 through 8.0.1, 7.6.7 for 7.6.0 through 7.6.6 and 7.4.9 for 7.4.0 through 7.4.8, with FortiMail 7.2.0 through 7.2.9 told to upgrade to branch 7.4 or above (Fortinet PSIRT, 2026-10-01). The advisory's structured record is dated 2026-10-05 and lists 8.0.2, 7.6.7 and 7.4.9 as not affected (Fortinet PSIRT CSAF record, 2026-10-05). The workarounds, the compromise artifacts and the lookback to 2026-07-22 are unchanged, so a workaround remains the interim control for any appliance that cannot be upgraded at once (Fortinet PSIRT, 2026-10-01).

HIGHCVE-2026-102489 +1exploitedupdatedNATOA2

CVE-2026-102489 / CVE-2026-102490, Zammad helpdesk: a session-hijack remote code execution and a zammad-to-root escalation, both reported exploited since 21 September, with no fix named for the root flaw

First published 2026-10-02 · open finding →

Updaterun 2026-10-06T0405Z-intelsummarycvessourcesevidencesourcing_noteactionsbody

Zammad's own advisory of 2026-10-05 says it now has DIVD's technical details for CVE-2026-102490, assesses it as a local escalation that needs prior access to the server, ties it to a confirmed vulnerability in packager.io and is working on a solution; no fix is named yet. Zammad advises restricting access to the underlying server to trusted administrators.

Zammad published its own security advisory for both CVEs on 2026-10-05 (Zammad, 2026-10-05). For CVE-2026-102490 it now says it has received DIVD's technical details and is analysing the issue as a high-priority item, assesses it as a local privilege escalation that cannot be exploited remotely on its own because an attacker would need access to the underlying server beforehand, and says the issue is related to a confirmed vulnerability in packager.io and that its team is working on a solution (Zammad, 2026-10-05). The advisory names no fixed release for it. Zammad recommends that administrators still on 6.5 or older update immediately, since those versions no longer receive security updates, and that access to the underlying server be restricted to trusted administrators (Zammad, 2026-10-05).

04Action items10 items

Verification & coverage notes1 run

2026-10-06T0405Z-intel · Sonnet 5.5 · window 26 h · 2 entries published

Verification & coverage notes

  • Window: 26 h (gap to the previous intel run 24.0 h, standard window). Thin day by design: two new entries, four changelog records on covered findings; the research returned 24 items and most failed the relevance gate.
  • Backlog (state/coverage_backlog.md): IBM MQ CVE-2026-10747 and Langflow: held to 2026-10-11, dated footprint correction appended (the MQ bulletin covers the whole MQ Server line; IBM's 2026-10-02 bulletin adds 25 Langflow CVEs fixed in 1.12.3 incl. unauthenticated CVE-2026-104334; still no exploitation, PoC or KEV). MikroTik CVE-2026-84411: held to 2026-10-14, no state change. IBM Guardium CVE-2026-85542: held to 2026-10-14, no state change. SafePay ARA-Region Lyss-Limpachtal and Payload/Netech: held to 2026-10-14, S4 re-searched, no victim statement or press. New row: Beyond Gravity (held on a named condition, expires 2026-10-20).
  • KEV sweep (kev-window.txt): 0 additions since 2026-10-05 (catalog 2026.10.04). RANSOMWARE row CVE-2026-0257 (PAN-OS): shipped as an update record on 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen (KEV flag plus Arctic Wolf's Qilin intrusions; priority moved from critical to high because fixed builds are listed in Palo Alto's table and the decision is now a compromise assessment). For the audit: entries/2026-05-30/cve-2026-0257-pan-os-globalprotect-pre-auth-vpn-authenticati.md is a v2-migrated duplicate of the same finding and should be folded into the survivor.
  • Priority notes: Atlassian CVE-2026-21589 is high: vendor-forced out-of-band response (patch immediately or take internet-facing instances offline, WAF/Tomcat stop-gap) on every version of eight self-managed products, unauthenticated, default configuration; not exploited, so not critical. Whether the constituency runs these products is not stated by any source and the entry does not claim it. Denmark CPR is notable: sector nexus (national population register) and a transferable lesson (abuse of delegated lawful lookup access, per-party volume alerting); it clears the breach gate on limb (b).
  • Single-source: Atlassian entry (vendor and CNA, A2; The Register restates it); Denmark CPR (victim-side authority disclosure, single-source-victim).
  • borderline-drop: Citrix CVE-2026-88779 NCSC-CH advisory and watchTowr quotes: source addition with no reader-facing delta on an entry that already says exploited.
  • borderline-drop: Rejetto HFS CVE-2026-61500 canary-observed attempts (VulnCheck, single China Telecom address, small-scale reconnaissance): low constituency exposure, honeypot-only evidence.
  • borderline-drop: IBM Langflow OSS CVE-2026-104334 (25 CVEs, 1.12.3): unauthenticated RCE with no exploitation, PoC or KEV and no established exposure; folded into the held backlog row.
  • borderline-drop: Microsoft Exchange CVE-2026-96940 (authenticated cross-mailbox elevation, not exploited, not disclosed, vendor release 2026-10-02, outside the window); Apache Struts S2-075 (Moderate, deprecated non-default mapper).
  • borderline-drop: Korea financial-sector wave (Shinhan, KB Kookmin, Hana, Yegaram): no Swiss nexus, AI-agent use unconfirmed; the transferable lookup-abuse lesson is carried by the Denmark CPR entry. Hauts-de-France Atexo/Docaposte: no vector, actor or behaviour (incident floor). Fakturownia/VosFactures: Polish SaaS, no Swiss nexus, attacker route claim-only. ShinyHunters 'Rey' detained: anonymously sourced single-outlet report with no defender decision.
  • borderline-drop: Microsoft Digital Defense Report 2026 and Zscaler ThreatLabz 2026 Ransomware Report: vendor-telemetry statistics, awareness only. Cling/ClingSTUN IoT botnet: opportunistic, no stated public-sector targeting. HSLU/Uni Fribourg measurement of Swiss municipal mail authentication (DMARC enforced on 13.4%): hardening baseline, no incident, not a near-term decision.
  • out-of-window: LevelBlue THOR NetScaler CVE-2026-88771 artefacts (primary 2026-09-30, outside the 72 h developing window); ENISA Threat Landscape 2026 (primary 2026-09-22). Both are for the audit's re-sweep: the NetScaler artefacts would sharpen the compromise check on the critical NetScaler entry, and ENISA ranks public administration the most targeted EU sector.
  • Seen but never assessed (S1, outside every window, offered to the audit's G1 re-sweep): GitLab CVE-2026-89078 and CVE-2026-93577 (CVSS 9.9, 2026-09-23); OpenBao/HashiCorp Vault authentication bypass flaws (2026-09-23); HPE Aruba Instant On CVE-2026-76723/76724/76725 (9.6, 2026-09-29); Zimbra CVE-2026-66912/66911 (NCSC-CH 13022); a WatchGuard bundle of 2026-09-28 to 2026-10-01 (about 15 CVEs; CVE-2026-81433 needs adjacent-network access). Also BACS weekly review 26w39 (ClickFix to ransomware warning, 2026-09-29) and the SRG/SRF employee-data theft (2026-09-28), both flagged by S2.
  • Tooling defect hit this fire: python3 resolves to /usr/local/bin/python3, which cannot import trafilatura, while the session hook installs it for /usr/bin/python3. fetch_source.py extract therefore returned raw HTML to all four sub-agents; the main agent ran extract with /usr/bin/python3. Fix: setup-deps.sh now installs with python3 -m pip (committed with this run).
  • Candidates considered but not added: Nozomi Networks Labs (no feed), bluewin.ch (Keystone-SDA wire, no listing recipe), KISA Boho Nara.
  • Coverage gaps: ssd-disclosure (direct GET answers the captcha; listing read through the reader, newest advisory 2026-09-10); golem-security (feed titles only, article pages hit the consent wall); swisspost-cybersecurity (undated promotional items); community.citrix.com techzone blog (403); the Exchange team blog (JS-rendered, covered by the MSRC CVRF); Reuters (CAPTCHA); datatilsynet.dk (script-loaded archive); BACS weekly review 26w40 (not yet published at 04:22Z, expected on a later Tuesday fire).
  • Verification: six iterations. Iterations 1 to 4 returned NEEDS_FIXES (26, 9, 6 and 3 findings), most of them on the v2-migrated PAN-OS entry whose old body had unverified claims (wrong fixed-build list, non-verbatim Rapid7 quote, unsupported detection clauses) and which was rewritten from the PSIRT, Rapid7 and Arctic Wolf pages. Iterations 5 and 6 returned CLEAN, confirmed. Declined with rebuttal: F7 Denmark (specific mechanism stated), F18 Atlassian actions, the fold of the v2 duplicate PAN-OS entry (deferred to the audit), ENISA's Crowd 7.1.1 figure, the product:atlassian-confluence-data-center key. Residual advisory left for the audit: the Zimbra record summary lists egress among ACN's host checks (ACN gives egress only as hardening).
  • Notes for the audit: fold entries/2026-05-30/cve-2026-0257-pan-os-globalprotect-pre-auth-vpn-authenticati.md into the surviving PAN-OS entry after reviewing its deep-dive content; an earlier record of that survivor still carries an em dash in its summary (append-only).