CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
‹Wed · 07 Oct 2026
All daily briefs →
Daily brief · UTC day

Wednesday, 7 October 2026

3 verified findings from 1 run · 6 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01Exploited WordPress plugin XSS ends in a hidden admin and persistence that patching does not remove. Patchstack reports that since 2026-10-04 one campaign has been exploiting two unrelated stored cross-site scripting flaws, CVE-2026-93836 in WPC Product Bundles for WooCommerce up to 8.6.6 and CVE-2026-94504 in Ninja Forms up to 3.15.3, by planting a script in an order or a form submission that runs when a logged-in administrator opens it. The script uses the administrator's own session to install a malicious plugin and create administrators, one of them hidden from the Users screen, and leaves four independent ways back in, so updating to Ninja Forms 3.15.4 or WPC Product Bundles 8.6.7 stops new injections but does not evict an implant. Patchstack says exploitation volume is limited so far and that the second stage works with any stored XSS that reaches an administrator. →
  2. 02Unit 42: a coding-test Visual Studio project executes on open, then disables ETW and takes tasking from GitHub. Unit 42 describes a March 2026 campaign by an Iranian-nexus cluster it calls CL-STA-1178 against an individual in Iraqi critical infrastructure, in which a recruiter persona impersonating Dubai Airports IT sent a coding-test Visual Studio project whose project file runs code during the design-time build, before any compile. The chain then hijacks the .NET AppDomainManager through a configuration file that disables ETW, sideloads a DLL, and uses the GitHub API and issue comments for command and control, with PowerShell run inside the hijacked process so no powershell.exe starts. No Swiss or European target is reported and Unit 42 is the only source. →
  3. 03CloudSEK: a Gentlemen affiliate reached victims through stolen GitLab CI/CD secrets and drove attacks over MCP. CloudSEK analysed two exposed servers of "Azazel", a Russian-speaking affiliate of the Gentlemen ransomware group who also ran his own leak site, and reports about 6 TB of stolen data from some two dozen organisations, among them government-adjacent infrastructure. It says every confirmed victim was reached through stolen CI/CD secrets, mainly GitLab variable stores and git history, that one deeper intrusion into an AI platform chained server-side request forgery, a recovered master key that decrypted the configuration and a token recovered from git history, and that Azazel drove attack commands through an MCP server on a local port. The report is a single source and names no victim. →

01Active threats, incidents & disclosures2 items

NOTABLENATOB2

CL-STA-1178 (Blinder Tunnel): an Iranian-nexus recruitment lure delivers a Visual Studio project that runs code when it is opened, then hijacks the .NET AppDomainManager, disables ETW and takes tasking from GitHub

Unit 42 tracks an Iranian state-aligned cluster as CL-STA-1178 and names its March 2026 campaign against an individual in Iraqi critical infrastructure "Blinder Tunnel"; the infrastructure was staged from November 2025, and the same actor ran conflict-themed Google Drive credential phishing against an Israeli entity in May and June 2026 (Unit 42, 2026-10-06). A recruiter persona impersonating the Dubai Airports IT department sent a decoy career-portal installer and then a weaponised C# Visual Studio project as an at-home coding test (Unit 42, 2026-10-06). When a developer opens a project, Visual Studio runs a design-time build in the background, and the project file overrides one of the targets that step runs, so the payload executes at project load, before any compile; it copies binaries into a folder under the user profile and launches one of them (Unit 42, 2026-10-06).

The launched binary is a renamed, signed Microsoft Visual Studio hosting process. A configuration file beside it replaces the .NET application's default app-domain manager with a malicious one and sets the ETW enable flag to false, which Unit 42 says could impair detection, and the loader, ShelbyLoader V2, then arrives through DLL sideloading (Unit 42, 2026-10-06). The loader persists through a current-user startup registry value, authenticates to the GitHub API with a hard-coded personal access token for tasking, and falls back to encrypted routing data in comments on GitHub issues; a follow-on module hooks the PowerShell engine inside the hijacked process, so commands run without starting powershell.exe, and a second loader, Blackwood, runs the open-source Chisel tunnelling tool in memory to give a reverse SOCKS proxy into the victim's network (Unit 42, 2026-10-06). GitHub removed the malicious infrastructure Unit 42 identified, and Unit 42 is not aware of any breach of Dubai Airports (Unit 42, 2026-10-06).

Triage: developers legitimately build projects and call GitHub, so the discriminators are that execution starts at project open rather than at a build the developer chose to run, a DLL beside a renamed signed host binary that does not belong to it, and a configuration file that changes ETW or app-domain settings.

We discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets.

the attackers defined a custom XML target with this exact name in their malicious .csproj file, overriding the safe Microsoft default behavior.

Because Event Tracing for Windows (ETW) is critical for monitoring execution and detecting in-memory threats, this flag could impair detection capabilities.

This allowed the attacker's script to execute without spawning PowerShell.exe.

Palo Alto Networks Unit 42 2026-10-06
threat07 Oct 04:47Zsingle-sourceOpen finding →
NOTABLENATOB2

A Gentlemen ransomware affiliate ran his own leak site and reached his victims through stolen CI/CD secrets, with attack commands driven through an MCP server (CloudSEK)

CloudSEK reports that an exposed open directory and a misconfigured storage server revealed the operation of "Azazel", a Russian-speaking affiliate of the Gentlemen ransomware group, who used the group's tooling, negotiation channels and ransom-note template but published victims on a leak site of his own and kept the proceeds, so the Gentlemen operator lost the revenue (CloudSEK, 2026-10-05). Two servers held about 6 TB of stolen data from some two dozen victims, spanning logistics, insurance, pharmaceutical, AI, medical-device and government-adjacent organisations (CloudSEK, 2026-10-05).

Every victim outside one deeper intrusion was reached the same way: GitLab CI/CD variable stores and git history were mined for tokens, database credentials, API keys and SSH private keys with enumeration and secret-scanning tools, and one GitLab instance that served two unrelated organisations gave footholds at both (CloudSEK, 2026-10-05). From one CI/CD token the actor reached more than 150 databases, payment gateways and hundreds of source repositories across a SaaS platform and its clients, and at a platform hosting a government-linked financial registry it exfiltrated more than 120,000 records and then killed the PostgreSQL process and deleted the production data directory (CloudSEK, 2026-10-05). The deeper intrusion, into an AI platform, ran for weeks: an API that fetches user-supplied URLs server-side gave an unauthenticated route into the internal network, a recovered master key decrypted every secret in the cluster configuration, a hardcoded authentication-bypass token that had been removed from the code but stayed in git history gave lasting access, offline cracking was run against administrator hashes from the monitoring stack, and an object-storage bucket was mirrored continuously (CloudSEK, 2026-10-05). Ransom notes were pushed to eight surfaces, among them the login message, the SSH banner, a database configuration parameter, a database-admin login template, a repository README and an issue opened against the victim's project, and CloudSEK reports that the verification script drove these checks through an MCP server bound to a local port, an operational use of MCP as an attack execution channel of which CloudSEK has not identified earlier public reporting (CloudSEK, 2026-10-05).

Triage: legitimate backup jobs also mirror object storage to remote destinations, so the discriminator is the destination and the source host, not the copy command itself (CloudSEK, 2026-10-05).

Every confirmed victim was reached through stolen CI/CD secrets.

Azazel registered a reverse shell handler as a tool inside an AI coding assistant via MCP, then drove attack execution through it.

Azazel recovered credentials from commits that appeared removed from the current branch.

CloudSEK TRIAD 2026-10-05
threat07 Oct 04:46Zsingle-sourceOpen finding →
HIGHCVE-2026-94504 +1exploitedNATOB2

CVE-2026-94504 / CVE-2026-93836, Ninja Forms and WPC Product Bundles for WooCommerce: stored XSS exploited to plant a hidden WordPress administrator and four persistence routes that survive the update

Patchstack reports two unrelated stored cross-site scripting flaws that deliver the same second-stage script, first seen on 2026-10-04 against WPC Product Bundles for WooCommerce (CVE-2026-93836) and on 2026-10-05 against Ninja Forms (CVE-2026-94504) (Patchstack, 2026-10-06). No account is needed: a numeric-prefixed quantity keeps attacker markup in WooCommerce order data, and a textarea submission sent through the normal form endpoint is stored and rendered without safe encoding in the legacy Ninja Forms submission editor (Patchstack, 2026-10-06). The script runs when a logged-in administrator opens the order or submission, rides that session in wp-admin without reading the cookie, so HttpOnly does not help (Patchstack, 2026-10-06).

With that session it uploads a plugin through WordPress' own installer, creates an administrator and calls a persistence installer (Patchstack, 2026-10-06). Patchstack counts four ways back in: the visible administrator; a second administrator that a dropped must-use plugin hides from the Users list, its filters and its role counts; a login URL, backed by another must-use plugin, that authenticates as the site's oldest administrator; and an unauthenticated file manager in the uploaded plugin that runs only on a direct request and can write files anywhere writable (Patchstack, 2026-10-06). The must-use plugins are backdated to the oldest file time in the WordPress root, so a search for recently changed files misses them (Patchstack, 2026-10-06).

Both flaws were disclosed on 2026-09-22; Patchstack says exploitation volume is limited and that the second stage works with any stored XSS that reaches an administrator (Patchstack, 2026-10-06). The fixed versions are Ninja Forms 3.15.4 and WPC Product Bundles 8.6.7, and updating does not clean an existing infection (BleepingComputer, 2026-10-06).

Triage: a legitimate administrator installing a plugin from a ZIP produces the same plugin-install and user-creation events; the discriminators are that they follow an administrator opening a stored submission or order, that the installed plugin poses as a thumbnail cache and does nothing when WordPress loads it, and that the new administrator is missing from the Users list.

exploitation volume remains limited in our telemetry

It is a fully privileged administrator the site owner cannot see.

Removing the vulnerable plugin, or even the malicious one, closes none of the last three.

Patchstack 2026-10-06

Updating the vulnerable plugin prevents further exploitation but does not clean an existing infection.

BleepingComputer 2026-10-06
vulnerability07 Oct 04:45Zsingle-sourceOpen finding →

03Updates to prior coverage6 items

NOTABLECVE-2019-18935exploitedupdatedNATOB2

CVE-2019-18935, Progress Telerik UI for ASP.NET AJAX: a patched-since-2020 deserialization RCE still exploited, now via an in-memory Godzilla web shell registered on ASP.NET's VirtualPathProvider

First published 2026-09-28 · open finding →

Correctionrun 2026-10-07T0404Z-intelheadlinesummarytagscvessourcesevidencesourcing_notebody

AhnLab presents two separate attack cases in Korea and does not date the intrusions or call them unrelated; the wording is corrected to match, and the shell's request header is stated as ASEC states it. CISA's Known Exploited Vulnerabilities catalog has listed CVE-2019-18935 since 2021-11-03 and, in version 2026.10.04, marks it as used in known ransomware campaigns; the catalog does not date that flag, so a server found exploited warrants a check for follow-on activity as a precaution, not only the patch.

AhnLab's article of 2026-09-27 presents two separate attack cases in Korea and does not date the intrusions or call them unrelated; the wording above now follows it (AhnLab ASEC, 2026-09-27). ASEC says the first case's shell tells its actions apart by the request's Type header.

CISA's Known Exploited Vulnerabilities catalog has listed CVE-2019-18935 since 2021-11-03, and in catalog version 2026.10.04 its record marks the flaw as used in known ransomware campaigns; the catalog does not say when that flag was set (CISA KEV catalog, 2026-10-04). Because the CVE has been used in ransomware campaigns, a Telerik server where the web shell or the reconnaissance scanner turns up deserves a check for follow-on activity: assess what the w3wp.exe account and the SYSTEM-level escalation could reach, in addition to patching.

NOTABLEupdatedNATOA1

Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution

First published 2026-08-04 · open finding →

Improvementrun 2026-10-07T0404Z-intelsummaryprioritysourcesevidencesourcing_noteactionsbody

The government's release of 2026-08-19 states the cause as faulty authorisation-checking logic abused through repeated individual API requests, not a classic software vulnerability, and adds an upstream eID step to account verification and wider monitoring; the Head of Government told the Landtag the weaknesses are fixed, data integrity was checked and the register resumed in restricted form on 2026-10-05, with no sign of misuse of the copied data.

The government's release of 2026-08-19 gives its own account of the cause: Fabian Schmid, head of the Office of Information Technology, said the security analysis showed the unauthorised access was possible "due to faulty authorisation-checking logic", which allowed the application programming interface to be exploited "through repeated individual requests in a manner that was not intended", and that it was "not a classic software vulnerability" (Liechtenstein Government, 2026-08-19). The fixes it announced are an upstream eID step in the requirements for verifying user accounts and checking identity, and wider monitoring and detection so that unauthorised access is noticed earlier (Liechtenstein Government, 2026-08-19).

On 2026-10-06 Inside IT reported the Head of Government's answer to a Landtag question: the identified weaknesses have been fixed, a check of data integrity found no sign that register data was altered, the register resumed operation in restricted form on 5 October, there is still no indication of concrete misuse of the copied data, and an external IT review is expected to report in the first half of 2027 (translated from German) (Inside IT, 2026-10-06). The perpetrators remain unknown (Inside IT, 2026-10-06).

NOTABLECVE-2026-35273exploitedupdatedNATOB2

The FBI says the incident at its recruitment portal resulted from a contractor failing to apply an issued security patch on a third-party-managed platform; sources name PeopleSoft, and ShinyHunters claimed the breach

First published 2026-09-24 · open finding →

Updaterun 2026-10-07T0404Z-inteltitleheadlinesummaryclassificationsourcesevidencesourcing_notebody

The FBI's cyber chief said on 2026-10-06 that the incident resulted from a security failure of a platform managed by a third-party organization after a contractor failed to implement a security patch explicitly issued to secure it, and that the FBI removed the contractor; Reuters' sources, as relayed by SecurityWeek, name Oracle PeopleSoft and Accenture. This replaces the 2026-09-23 position that the point of breach was undetermined. Nextgov/FCW also relays Reuters' report of a suspected member of the group detained in Jordan and helping investigators.

FBI cybersecurity chief Brett Leatherman gave Nextgov/FCW the bureau's clearest account of the cause so far: "the incident occurred as the result of a security failure of a platform managed by a third-party organization", because "a contractor failed to implement a security patch explicitly issued to secure the platform", and the FBI has removed the contractor (Nextgov/FCW, 2026-10-06). A person with knowledge of the matter told Nextgov/FCW that Accenture is responsible for software patch management and maintaining custom code at the FBI, and that Oracle, whose PeopleSoft platform ShinyHunters claimed as the initial access point, provided the security patches that were not integrated (Nextgov/FCW, 2026-10-06). SecurityWeek, citing Reuters' sources, says the system is Oracle's PeopleSoft human resources platform and the outside organization is Accenture; Accenture did not answer questions about the patching failure and said only that it is proud to support the mission of the FBI (SecurityWeek, 2026-10-06).

This replaces the FBI's statement of 2026-09-23 that the point of breach, a third party or its own enterprise, was undetermined: the failure is now placed at a third-party-managed platform. The FBI's statement names neither the product, the contractor nor a CVE, and Nextgov/FCW notes it does not say why the patch was missed (Nextgov/FCW, 2026-10-06). The link to CVE-2026-35273 stays ShinyHunters' account, given to BleepingComputer (BleepingComputer, 2026-09-26).

Nextgov/FCW relays Reuters' report of 2026-10-03 that a suspected ShinyHunters member had been detained in Jordan and was helping investigators (Nextgov/FCW, 2026-10-06). SecurityWeek says this is the member known as Rey (SecurityWeek, 2026-10-06). An FBI spokesperson told The Register on 2026-10-05 that the bureau has "already worked with partners to arrest multiple subjects" while declining to comment on specific arrests (The Register, 2026-10-05). SecurityWeek adds that a post urging organizations to pay has been removed from the group's site while its most recent victim post is dated 2026-09-22 (SecurityWeek, 2026-10-06).

HIGHCVE-2026-102489 +1exploitedupdatedNATOA2

CVE-2026-102489 / CVE-2026-102490, Zammad helpdesk: a session-hijack remote code execution and a zammad-to-root escalation, both reported exploited since 21 September, with no fix named for the root flaw

First published 2026-10-02 · open finding →

Updaterun 2026-10-07T0404Z-intelheadlinesummarytagstechniquescvessourcesevidencesourcing_noteactionsbody

Zammad released 7.2.1 on 2026-10-06 with 27 security advisories, two rated critical (a public sign-up path to other customers' tickets and a multi-factor bypass in the email-verification flow), all affecting 7.2.0 and earlier; 7.2.0 is therefore no longer the release to install. None of the advisories carries a CVE id, none is reported exploited, and no source says whether 7.2.1 fixes the exploited root escalation CVE-2026-102490.

Zammad released 7.2.1 on 2026-10-06 as an important security update that addresses critical vulnerabilities, with no action needed for SaaS customers and an immediate upgrade advised for self-hosted installations (Zammad, 2026-10-06). The release comes with 27 security advisories published the same day, rated by Zammad as two critical, twelve high, ten medium and three low (Zammad advisory records, 2026-10-06); every affected range ends at 7.2.0 and none carries a CVE id yet (Zammad advisory records, 2026-10-06). 7.2.0, the release Zammad recommended on 2026-10-01, is therefore affected itself.

The two critical advisories: the public sign-up form accepted account fields it should have ignored, so an attacker without any account could register on an email address they did not own, have that account treated as already confirmed and add it to any organization, then read and reply to other customers' tickets in those organizations, with a second flaw letting a customer change fields of another customer's ticket in the same organization (Zammad advisory GHSA-79wh-8g2f-xj2c, 2026-10-06); and the email-verification flow established a fully authenticated session for an account that had never completed email verification and had multi-factor authentication configured, without the second factor, which needs possession of the account's verification email but no password and carries the account's permissions up to administrator (Zammad advisory GHSA-f3qr-94c2-7mx2, 2026-10-06). Among the high-rated advisories are a remote code execution through a template sanitizer bypass in automation configuration, a session identifier disclosed in an authenticated configuration response that enabled off-host session takeover, and a second-order SQL injection in ticket overview sorting (Zammad advisory records, 2026-10-06).

No source reports exploitation of any of the 27 flaws. Zammad's advisory of 2026-10-05 still says its team is working on a solution for CVE-2026-102490 and none of the 27 titles names that flaw, so whether 7.2.1 closes the exploited root escalation is not stated (Zammad, 2026-10-05; Zammad advisory records, 2026-10-06).

NOTABLEupdatedNATOA2

Denmark's CPR population register: unauthorised parties abused one private company's lawful lookup access for about ten days and obtained names, addresses and CPR numbers of 8.8 million people

First published 2026-10-06 · open finding →

Updaterun 2026-10-07T0404Z-intelsummarytechniquessourcesevidencesourcing_notebody

Datatilsynet's notice says the register reported a very large number of automated lookups made to identify valid CPR numbers, and at the 2026-10-06 press briefing the authorities said a costly invoice rather than systematic alarms hinted at the breach, that police visited a smaller company in person and contacted foreign police, and that the CPR number can no longer be used to authenticate a person. Police are examining whether an algorithm or AI was used; the actor, the company and how the access was obtained are still not public.

Datatilsynet said on 2026-10-05 that it received the register's notification on Sunday 2026-10-04 and that the notification describes a very large number of automated lookups against the CPR system to identify valid CPR numbers (translated from Danish) (Datatilsynet, 2026-10-05).

At the press briefing of 2026-10-06, DR reports, the authorities said an expensive invoice, not systematic alarms, hinted that a breach had happened, that police have been to a smaller company in person to collect traces, and that foreign police have been contacted in case foreign actors are behind it; the director of the agency for societal security (Styrelsen for Samfundssikkerhed) said the CPR number can no longer be used to authenticate a person (translated from Danish) (DR Nyheder, 2026-10-06). A head of centre at the national police unit NSK said police are looking at whether an algorithm was used, as a hypothesis, because so many lookups were made in a short time, and could not say more (DR Nyheder, 2026-10-06). The authorities did not say who is behind the breach, how it happened or whose access was misused (DR Nyheder, 2026-10-06).

HIGHCVE-2026-21589exploitedupdatedNATOA1

CVE-2026-21589, Atlassian Data Center: unauthenticated arbitrary file access in every version of eight self-managed products, patch or take them off the internet (CVSS 4.0 9.3)

First published 2026-10-06 · open finding →

Updaterun 2026-10-07T0404Z-intelheadlinesummarytagstechniquescvessourcesevidenceverificationsourcing_noteclassificationactionsbody

watchTowr Labs published the root cause (a path-separator substitution in the web-resource library shared by Jira, Confluence and Bitbucket), the request shape and a runnable checker on 2026-10-06, and shows that where Jira is integrated with Crowd the file read exposes a plaintext Crowd application password that gives administrator access to Crowd for that application. The flaw moves from a patch-now issue with unpublished mechanics to one with public mechanics and a Crowd credential to rotate; no exploitation is reported. Atlassian's Crowd ticket lists the same fixed builds as the advisory.

watchTowr Labs published the root cause on 2026-10-06 after comparing a vulnerable and a fixed build of the web-resource library that Jira, Confluence and Bitbucket share: its router converts a double colon in a request path into a slash before it resolves a plugin resource, so a traversal written with double colons leaves the resource directory through a deprecated relative-path resolver that is still reachable (watchTowr Labs, 2026-10-06). watchTowr says it cannot leave the Tomcat context but can read any file within the application server, and it shows working requests against Jira, Confluence and Bitbucket, with Bitbucket blocking one configuration file but not another under WEB-INF (watchTowr Labs, 2026-10-06).

The impact it demonstrates depends on the configuration: where Jira is integrated with Crowd, the crowd.properties file under WEB-INF stores the application name and its password in plaintext, and with those watchTowr reached Crowd's REST interface in its lab, created a user and added it to the Jira administrators group; it adds that a Crowd IP allow-list would make this harder (watchTowr Labs, 2026-10-06). watchTowr also published a Detection Artifact Generator on GitHub that sends the traversal to Jira, Confluence and Bitbucket hosts to test whether they are vulnerable (watchTowr Labs on GitHub, 2026-10-06). Neither watchTowr's post nor Atlassian's advisory of 2026-10-05 reports exploitation in the wild. Atlassian's Crowd ticket lists the same fixed builds as the advisory, 7.1.7 for the 7.1 line (Atlassian, 2026-10-02).

04Action items6 items

Verification & coverage notes1 run

2026-10-07T0404Z-intel · Sonnet 5.5 · window 26 h · 3 entries published

Verification & coverage notes

  • Window: 26 h (gap 24.0 h to 2026-10-06T0405Z-intel). A quiet, update-heavy window: three new entries and six changelog records.
  • KEV sweep: catalog 2026.10.04 carries no addition inside the window (the last, Citrix CVE-2026-88779, is covered). The ransomware-flag cross-check found one 14-day covered CVE with the flag Known and a silent entry, CVE-2019-18935, which ships on the Telerik entry inside a correction record (the catalog does not date the flag, so it is not an update; the same record fixes the entry's 'unrelated' and '2026' wording, which AhnLab's article does not support). For the audit: S1 lists thirteen older entries that carry a KEV-Known CVE without mentioning ransomware (CVE-2026-63077 in 2026-09-06/jetbrains-cadence-teamcity-cve-2026-63077-breach, CVE-2026-45659 in the 2026-07-14 Patch Tuesday entry, CVE-2026-12569 in the 2026-08-22 PTC Windchill entry, CVE-2026-35273 in the 2026-06-28 NAIC PeopleSoft entry, CVE-2026-41940 in the 2026-05-10 cPanel entry, CVE-2025-8088 in three 2026-06 entries, CVE-2022-26134 and CVE-2022-29464 in the 2026-08-16 evooo1bot entry, CVE-2020-0688 and CVE-2019-0708 in the 2026-09-21 NightEagle entry, and a second entry file for CVE-2026-0257).
  • Backlog (state/coverage_backlog.md, six open rows, all re-gated on today's facts and all held, none struck, none published): IBM MQ CVE-2026-10747 and the Langflow CVEs (condition unmet; new Langflow CVEs and IBM bulletins noted on the row; expiry 2026-10-11 stands); MikroTik CVE-2026-84411 (no revision of CISA's advisory and MikroTik still names no fixed build; expiry 2026-10-14); IBM Guardium CVE-2026-85542 (not in KEV; IBM's bulletin of 2026-09-17 also carries an unauthenticated CVSS 9.8 flaw in the same product, noted on the row; expiry 2026-10-14); SafePay on ARA-Region Lyss-Limpachtal and Payload on Netech (no victim statement or press report found by S4; expiry 2026-10-14); Beyond Gravity (S2 and S4: still no vector, actor or data named, and neither BACS nor Mandiant has published; expiry 2026-10-20).
  • Updates: Atlassian CVE-2026-21589 (update: watchTowr root cause, checker and Crowd chain), Denmark CPR register (update: Datatilsynet's automated-lookups description and the 2026-10-06 press briefing), Zammad (update: 7.2.1 with 27 advisories replaces 7.2.0 as the target; read from the repository's advisory records through the GitHub API), FBI/ShinyHunters (update: the FBI cyber chief's statement of a contractor's missed patch), Liechtenstein VwbP (improvement: the government's 2026-08-19 root-cause statement and the 2026-10-05 reopening), Telerik CVE-2019-18935 (correction: the 'unrelated' and '2026' wording removed, plus the KEV listing and ransomware flag).
  • New entries: the WordPress stored-XSS hidden-administrator campaign (Ninja Forms, WPC Product Bundles; exploited, high), CL-STA-1178 Blinder Tunnel (Unit 42; PD-11 (d) technique value, notable), and the Gentlemen affiliate Azazel (CloudSEK; CI/CD secrets and MCP, notable).
  • Single-source: the three new entries rest on one vendor each (Patchstack, Unit 42, CloudSEK); BleepingComputer restates Patchstack and adds nothing. The FBI update's product and contractor names come from anonymous sources relayed by Nextgov/FCW and SecurityWeek (Reuters not readable).
  • Contradiction: BleepingComputer says the two WordPress plugin flaws need an authenticated session; Patchstack and the CNA records describe an unauthenticated attacker and an administrator's session being ridden, and the entry follows Patchstack.
  • borderline-drop: Wikimedia statement on OpenAI-operated agents (2026-10-05), no compromise found, same blind-proxy lesson already in the UNCTAD entry updated on 2026-10-02.
  • borderline-drop: LibreOffice CVE-2026-63277 and Apache OpenOffice CVE-2026-59265 (public proof of concept, 2026-10-05), needs Java enabled and a user opening a document, no exploitation reported, fixed in LibreOffice by the normal update, no constituency estate shown; re-gate if exploitation appears or OpenOffice 4.1.17 slips.
  • borderline-drop: Hitachi Energy RTU500 CVE-2026-8065 / 8066 (end-of-life firmware, CVSS 9.1, SSVC exploitation none), ASUSTOR ADM CVE-2026-105324 (single EUVD record, no fix stated), @subql/common npm compromise (50-minute window, Web3 package), Harbor webhook SSRF (CVSS 6.4, no CVE, no exploitation), Chrome's response to the .gh/.sl/.as registry hijacks (no Swiss nexus; generic CT-monitoring and CAA advice), Microsoft Digital Defense Report 2026 Swiss readings (primary published 2026-10-01; country rankings are context, not a decision, and four earlier fires dropped it), motion 24.4393 on .ch domain abuse (no obligation changes), the communal e-mail authentication paper (DMARC enforcement is generic hardening), ASOS push-notification extortion (no nexus, no vector), Qilin developer extradition (no defender decision), Osaka Metropolitan University ransomware (no actor or vector), South Korean bank breaches and ARTEX (thin freshness, out of region), ShinyHunters member detained in Jordan (single Reuters relay; folded into the FBI update only as context), Stadt Wien AI-scanner suspicion (2026-09-30, a suspicion; left to the audit as a possible improvement), WordPress 7.1.3, Microsoft Exchange CVE-2026-96940, Outlook CVE-2026-100208, HPE iLO 7 CVE-2026-79820, Rejetto HFS CVE-2026-61500 (probing only), Dell System Update CVE-2026-86360, OpenSSL 2026-09-29.
  • For the audit: GitLab CE/EE CVE-2026-89078 and CVE-2026-93577 (CVSS 9.9, fixed in 19.0.9 on 2026-09-23, exploitation "no information") and HPE Aruba Instant On CVE-2026-76723/76724/76725 sit outside every window and were never assessed. Cisco's PSIRT bundle announced for 2026-10-07 (APIC, Finesse, License On-Prem, Meraki, NX-OS hardening releases) was not yet published at 04:30 UTC; the next fire reads it.
  • Source-tooling notes from S1: fetch_source.py url silently falls back to the metered reader on non-HTML replies, so a JSON or plain-text endpoint needs --direct; the GitHub repository advisory records (api.github.com/repos/<org>/<repo>/security-advisories) read directly and are the better recipe for projects that publish GHSA advisories. S2 fetched one guessed URL (beyondgravity.com/en/press) through the reader and it returned 404; one reader fetch spent.
  • For the next fire and the audit: NCSC-CH published an advisory for SonicWall SMA1000 CVE-2026-102255 at 2026-10-07T05:47Z, after this run's research (the vendor reports no exploitation); the KEV catalog marks CVE-2026-35273 as used in ransomware campaigns and the ShinyHunters/FBI entry does not say so; CloudSEK's Gentlemen report describes a 22 TB long-term vault, and its text and chart disagree on the victim count (the entry carries the contradiction in its sourcing note); the 2026-09-01 Liechtenstein record summary still attributes the access mechanism to the head of the Office for IT, which NZZ does not support (the body and sourcing note are corrected, the record is append-only).
  • Coverage gaps: ssd-disclosure (CAPTCHA on every transport), Reuters article pages (CAPTCHA or JS shell), CERT-UA (Angular SPA, no structured recipe), fsc.go.kr (connection reset), the Liechtenstein Landtag answer text (not found).
  • Essential-coverage: all 21 essential sources attempted.