01SonicWall patches a third pre-auth CVSS 10.0 SMA1000 SSRF; the September hotfix builds are affected. SonicWall's advisory SNWLID-2026-0017 (2026-10-06) fixes four SMA1000 flaws, led by CVE-2026-102255, a pre-authentication server-side request forgery in the Work Place interface (CVSS 3.0 10.0) that affects 12.4.3-03526 and 12.5.0-02952, the hotfixes issued for the September zero-days. SonicWall reports no exploitation, but the two earlier unauthenticated Work Place SSRF flaws this year were exploited, each paired with an administrator-only command-execution flaw; fixed builds are 12.4.3-03670 and 12.5.0-03082. →
02A Defender bypass that needs no vulnerability: fill the disk during every update and the engine stays up, stale. LevelBlue SpiderLabs reproduced BigDiskBuster, a proof of concept published on GitHub on 2026-09-19 by the actor known as MSNightmare, which watches the C: volume for Defender update activity and claims the free space so each update fails while the Defender service keeps running and real-time protection stays on. It runs from a standard account and has no CVE or patch; Microsoft says Defender Antivirus detects the proof of concept, and no use in attacks is reported. →
03Huntress: a Power BI-hosted phishing link installs rogue ScreenConnect clients; in one case a script removed the first. Huntress describes a phishing campaign seen since 2026-09-10 in which an Outlook email links to a fake reference document on a legitimate Power BI domain; a "Download Reference" button opens an attacker page that fingerprints the visitor and then downloads a ScreenConnect installer. The installer deploys a rogue ScreenConnect client that establishes a second one, and in one incident a PowerShell script removed the first; Huntress could not obtain the original email, and the configuration of one of the rogue clients also appeared on 22 other endpoints. →
Le Temps reports that data stolen in a ransomware attack on a Vaud security-technology firm is now on sale on the darknet, and that the loot includes the locations of surveillance cameras, passwords and plans of security installations (Le Temps, 2026-10-06). The AWP agency names the firm as Ixa Systems of Crissier, which specialises in video surveillance, access control and burglary protection and whose customers include police authorities, banks, hospitals, schools and prisons (AWP via cash.ch, 2026-10-07). ICTjournal lists the Établissements de la plaine de l'Orbe and other judicial entities, gendarmerie premises, several banks including the Banque cantonale vaudoise and several dozen companies among the organisations concerned, and says exposure varies: for some clients the documents are limited to tenders or consultations, for others they give the location of cameras or the layout of alert buttons (ICTjournal, 2026-10-07).
Le Temps says the group TheGentlemen announced and claimed the theft on the darknet at the end of August (Le Temps, 2026-10-06). Inside IT dates the claim to 28 August and says the group made good on its threat to publish the data at the end of September (Inside IT, 2026-10-07), while ICTjournal says the documents were put on sale on 25 September and that, according to an expert's analysis seen by Le Temps, some of the data has begun to circulate (ICTjournal, 2026-10-07). The firm says it never lost use of its data, paid no ransom and that the attack gave no direct access to camera images; the canton's cybersecurity delegate says checks so far have found nothing that would compromise the security of the establishments concerned or give access to the State's IT environment, and that knowing a camera model is not enough to exploit it because the device must be reachable (ICTjournal, 2026-10-07). None of the reports states how the attackers got in.
Huntress describes a phishing campaign it has seen since 2026-09-10 in which an Outlook email carries a link that leads to a fake reference document on a legitimate Power BI domain (Huntress, 2026-10-07). Huntress notes that threat actors have previously abused Power BI in this way, building a real dashboard under an account of their own (usually compromised or throwaway), embedding a malicious link and setting its sharing to public, and that because the link points to Microsoft's real domain it passes Microsoft 365 mail filters and other gateways that trust that domain; it does not say how this campaign's page was set up (Huntress, 2026-10-07). A "Download Reference" button opens a new tab on an attacker domain that fingerprints the visitor (operating system, browser, automation indicators, cloud-provider cookies), reports victims to a Telegram bot and redirects visitors who fail its checks; after a delay a script clicks a hidden download link for a ScreenConnect installer (Huntress, 2026-10-07).
The installer deploys a first rogue ScreenConnect client, which establishes a second one pointed at different infrastructure (Huntress, 2026-10-07). In one incident the first client ran a command-shell script that launched a PowerShell script from the temp directory; that script downloaded and ran the installer for the second client and uninstalled the first, in a likely effort to evade detection, and a scheduled task re-ran it every two minutes before the attack was shut down (Huntress, 2026-10-07). After deployment the clients also ran a tool Huntress assessed as designed to hide the attacker's activity from the user and security software (Huntress, 2026-10-07). A handful of endpoints were hit from 2026-09-10, and the configuration of one of the rogue clients also appeared on 22 other endpoints in separate incidents (Huntress, 2026-10-07). The original email and lure wording are unknown.
Triage: ScreenConnect is legitimate where the organisation runs it; the discriminators are an instance that is not the organisation's own and an installer that arrived through a browser download from a web page rather than through IT's deployment tooling (Huntress, 2026-10-07).
Because the link points to Microsoft's real Power BI domain, it skirts through Microsoft 365 mail filters and other security gateways that trust this domain.
the PowerShell script also resulted in the uninstallation of the first ScreenConnect instance, in a likely effort to evade detection
SonicWall's advisory SNWLID-2026-0017 of 2026-10-06 fixes four flaws in the SMA1000 secure remote-access appliances (models 6210, 7210 and 8200v). CVE-2026-102255 (CVSS 3.0 10.0) is a pre-authentication server-side request forgery in the Work Place interface, attributed to an unintended alternate access path, through which a remote unauthenticated attacker can direct the appliance to issue requests on their behalf, reach internal functionality and perform unauthorized operations (SonicWall PSIRT, 2026-10-06). The other three flaws need a login: an OS command injection that lets an administrator execute commands (CVE-2026-102256, 7.8), a Zip Slip in the Appliance Management Console that leads to code execution (CVE-2026-102257, 7.2) and a stored cross-site scripting flaw in that console (CVE-2026-102258, 5.5) (SonicWall PSIRT, 2026-10-06). SonicWall says there is currently no evidence that any of them is exploited (SonicWall PSIRT, 2026-10-06).
The pre-authentication flaw is not routine because of what came before it. The Hacker News counts it as the third time this year that SonicWall has fixed a 10.0-rated Work Place SSRF that needs no login; in July and September SonicWall said it had investigated attacks on the earlier pairs ("multiple cases" and "a case"), each pair combining an SSRF that needs no login with a second flaw that lets a logged-in administrator run commands (The Hacker News, 2026-10-07). CERT-FR notes that such pairs have been actively exploited several times this year on this product (CERT-FR, 2026-10-07). The affected builds include 12.4.3-03526 and 12.5.0-02952, the hotfixes SonicWall named on 1 September for the two exploited flaws, so an appliance patched against that chain is still affected (The Hacker News, 2026-10-07). Fixed builds are 12.4.3-03670 and 12.5.0-03082 and higher (The Hacker News, 2026-10-07; CERT-FR, 2026-10-07), whereas the Canadian Cyber Centre's bulletin lists the same two builds as affected "and prior" (Canadian Cyber Centre, 2026-10-07). Shadowserver tracks over 400 internet-exposed SMA1000 appliances, some of which may already be patched, and BleepingComputer says government agencies and managed service providers use the product to give VPN access to internal applications (BleepingComputer, 2026-10-07). NCSC Switzerland published an advisory on 2026-10-07 and lists the exploitation status as unknown (NCSC Switzerland, 2026-10-07).
There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild.
LevelBlue SpiderLabs reproduced BigDiskBuster, a proof of concept published on GitHub on 2026-09-19 by the actor known as MSNightmare (Nightmare Eclipse) that needs no vulnerability to keep Microsoft Defender from updating (LevelBlue SpiderLabs, 2026-10-05). It watches the C: volume for Defender update activity and, when an update begins, creates a hidden file whose allocation claims essentially all free space; the update runs out of room and fails, Defender cleans up its staging directory and the tool repeats the process on the next attempt (LevelBlue SpiderLabs, 2026-10-05). The Defender service keeps running and real-time protection stays on; in LevelBlue's lab no alert appeared, and the only visible artifact was a stale security-intelligence version and the generic update error 0x80070643 (LevelBlue SpiderLabs, 2026-10-05). The roughly 300 lines of C++ use no memory corruption or kernel component: a raw handle on the volume device, a file opened relative to that handle, a recursive watch of the volume and an oversized allocation, with the file hidden and deleted on close (LevelBlue SpiderLabs, 2026-10-05). It ran under a standard user account on a default Defender installation (Dark Reading, 2026-10-06).
No CVE, patch or Microsoft advisory exists; a Microsoft spokesperson told Dark Reading that Defender Antivirus includes detections and preventions against the proof of concept and that customers should keep security intelligence and platform updates current (Dark Reading, 2026-10-06). The GitHub repository has been taken down, and Dark Reading notes that the technique could in theory extend the life of malicious tooling already on a machine by withholding new detections (Dark Reading, 2026-10-06). No source reports use in an attack.
Triage: a handle on the volume device alone is low-specificity because svchost, SearchIndexer, dllhost and TiWorker hold the same kind of handle in normal operation; in LevelBlue's tested environment only the Defender service processes and TrustedInstaller legitimately held a handle on MRT.exe (LevelBlue SpiderLabs, 2026-10-05).
At the time of publication, BigDiskBuster has no assigned CVE, available patch, or Microsoft advisory.
SonicWall's advisory of 2026-10-06 fixes a third pre-authentication Work Place SSRF, CVE-2026-102255, and its affected builds include 12.4.3-03526 and 12.5.0-02952, the hotfixes named here as the fix for these two flaws. Appliances on those builds need the later hotfix, 12.4.3-03670 or 12.5.0-03082.
SonicWall's advisory SNWLID-2026-0017 of 2026-10-06 fixes CVE-2026-102255, a third pre-authentication Work Place SSRF this year, and lists 12.4.3-03526 and 12.5.0-02952, the hotfixes named above as the fix for CVE-2026-83548 and CVE-2026-83549, among the affected builds; the fixed builds for the new flaw are 12.4.3-03670 and 12.5.0-03082 and higher (The Hacker News, 2026-10-07). The hotfixes above still fix the two flaws described here, but an appliance on them needs the later hotfix as well.
Fortinet's revision of 2026-10-07 states that it remediated FortiMail Cloud on 2026-10-05 by updating all firmware to 7.6.7 or 8.0.2, so FortiMail Cloud customers need take no action; the upgrade instruction now applies to self-managed appliances. Fixed builds, workarounds and compromise artifacts are unchanged.
Fortinet's revision of 2026-10-07 adds a FortiMail Cloud clarification to the advisory: Fortinet remediated the issue on 2026-10-05 in FortiMail Cloud by updating all firmware to 7.6.7 or 8.0.2, so FortiMail Cloud customers need not perform any action (Fortinet PSIRT, 2026-10-01). The upgrade and workaround instructions above therefore apply to self-managed appliances; the advisory still shows the flaw as exploited in the wild and its fixed builds, workarounds and compromise artifacts are unchanged (Fortinet PSIRT, 2026-10-01).
A joint FBI and U.S. Secret Service advisory of 2026-10-06 says FortiBleed is still active: the operators create administrator accounts on compromised FortiGates and in some cases delete or change the original accounts, locking owners out, and access brokers using the chain have supplied INC/Lynx and Payload ransomware affiliates. It cites SOCRadar for more than 86,644 compromised devices and adds firewall, VPN and domain controller log review, REST API key review and PBKDF2 enforcement to the response.
A joint advisory of the FBI and the U.S. Secret Service (JCSA-20261006-01, 2026-10-06) calls FortiBleed an active, global credential-compromise campaign against internet-facing FortiGate firewalls and SSL VPN gateways, cites SOCRadar for more than 86,644 compromised devices in 194 countries, and says attackers are continuing to scan exposed devices with previously obtained credentials (FBI and U.S. Secret Service, 2026-10-06). The operators scan exposed SSL VPN portals, run credential stuffing and password spraying from earlier Fortinet leak dumps and infostealer logs, pull password hashes and session tokens from compromised devices and crack the hashes offline with Hashcat and Hashtopolis on a rented GPU cluster; the advisory ties the success to reused or leaked credentials and a legacy SHA-256 password storage (FBI and U.S. Secret Service, 2026-10-06).
What the advisory adds is the lockout. On a compromised firewall the actors create administrator accounts that were not there before and, in some cases, delete existing accounts or change their passwords, so the owners cannot log in and recovery needs steps beyond patching and password resets (FBI and U.S. Secret Service, 2026-10-06; BleepingComputer, 2026-10-07). Cracked credentials are enriched and validated by scripts that filter out honeypots and rank targets by revenue and network structure; with verified credentials the attackers enumerate Active Directory accounts and spray passwords to find privileged users, and the operation packages working VPN configurations and target lists for sale, the role of an initial-access broker (FBI and U.S. Secret Service, 2026-10-06). The advisory says the chain has been an initial entry point for ransomware affiliates, currently INC/Lynx and Payload (FBI and U.S. Secret Service, 2026-10-06); SOCRadar had linked FortiBleed to INC and Lynx in July after reaching both groups' negotiation panels on a server used in the campaign (BleepingComputer, 2026-10-07).
The advisory's measures: restrict external management through trusted hosts, a local-in policy or no internet administration at all; terminate all administrative and VPN sessions and reset all Fortinet VPN and administrator passwords; require phishing-resistant MFA on remote access and administrator accounts; review users, configuration and REST API keys for entries nobody created, removing unknown keys and refreshing the legitimate ones; enforce PBKDF2 for administrator password storage per Fortinet's guidance for FortiOS 7.2.11 and later; and review firewall, VPN, authentication and domain controller logs for lateral movement (FBI and U.S. Secret Service, 2026-10-06). On a FortiGate the matching telemetry is the configuration and administrator audit log (administrator accounts created or deleted, passwords changed, new REST API keys); behind the VPN it is the domain controller authentication log, for lateral movement (FBI and U.S. Secret Service, 2026-10-06).
Horizon3 published the root cause of CVE-2026-102489 and a working exploit on 2026-10-07: a single unauthenticated WebSocket request makes Zammad return an error carrying every active user's session cookies, and a leaked administrator session writes a mail template through the package installation endpoint that runs code as the zammad user. The exploited flaw now has a public exploit, and Horizon3 says the root escalation remains unpatched.
Horizon3 published a reverse-engineering of CVE-2026-102489 on 2026-10-07, with a proof-of-concept repository (Horizon3, 2026-10-07). Zammad keeps the state of every connected WebSocket client, including the session Cookie header, in a class-level registry that is passed to every event; a single request to the /ws WebSocket endpoint carrying the event name base makes the dispatcher instantiate an event class that has no implementation, and the resulting error message, which includes the object's full representation, is returned to the caller together with the cookies of all active users (Horizon3, 2026-10-07). With a leaked administrator session an attacker writes files into the application directory through the package installation endpoint, overrides the built-in password-reset email view with a malicious template and triggers a password reset for any user, which executes the template as the zammad user (Horizon3, 2026-10-07).
Horizon3 says it believes the privilege escalation is CVE-2026-102490, that it remains unpatched, and that it is withholding those details (Horizon3, 2026-10-07). Horizon3's write-up names no Zammad version; Zammad's advisory of 2026-10-05 says CVE-2026-102489 is exploitable only on 6.5 and earlier (Zammad, 2026-10-05).
Exploitation attempts began on 2026-10-06, the day watchTowr published its write-up and proof of concept: Previdian's sensors have recorded at least 129 attempts from at least 22 addresses in eight countries, SANS ISC recorded similar attempts against Jira, Confluence and Bitbucket on its own honeypots, all from one cloud provider, and a Nuclei template exists; the Canadian Cyber Centre's bulletin now cites open-source reporting of in-the-wild exploitation. The status moves from patch-available to exploited, with no compromise reported and the flaw not listed in CISA's KEV catalog on Previdian's page.
Exploitation attempts began on 2026-10-06, the day watchTowr published. Previdian, which runs a honeypot network, told BleepingComputer that its sensors began recording attempts within two hours of that publication, and that a Nuclei template has since been released that makes scanning for vulnerable systems easier; it expects exploitation to rise significantly over the coming days and weeks (BleepingComputer, 2026-10-07). Its telemetry page, updated 2026-10-08, shows at least 129 attempts from at least 22 source addresses in eight countries across three sensors, first observed on 2026-10-06 (its timeline lists the first sensor observation at 20:52 UTC on 2026-10-06, about four hours after watchTowr's post of 17:01 UTC, which is later than the two-hours figure; Previdian, 2026-10-08; watchTowr Labs, 2026-10-06) and last on 2026-10-08, and lists the flaw as not in CISA's KEV catalog (Previdian, 2026-10-08). The SANS Internet Storm Center says its own honeypots began receiving attempts on 2026-10-06 with the URLs from watchTowr's write-up against Jira, Confluence and Bitbucket resource paths, that every source address belongs to one cloud hosting provider, and that it believes a single actor is behind them (SANS ISC, 2026-10-07).
Neither honeypot operator reports a successful compromise. The Canadian Cyber Centre updated its bulletin on 2026-10-07 to say that open-source reporting indicates the flaw is being exploited in the wild (Canadian Cyber Centre, 2026-10-07), while NCSC Switzerland's advisory, edited on 2026-10-07 to add the public proof of concept, lists the status as proof of concept available and does not report exploitation (NCSC Switzerland, 2026-10-07).
Install SonicWall's platform hotfix 12.4.3-03670 or 12.5.0-03082 (or higher) on every SMA1000 6210, 7210 and 8200v, including appliances already on the 12.4.3-03526 or 12.5.0-02952 hotfix from September; the appliance restarts when the installation finishes and no workaround is listed.
Find every self-hosted Zammad instance, copy its application and network logs before changing anything, upgrade to Zammad 7.2.1 (7.2.0 is affected by the 27 advisories Zammad published on 2026-10-06, two of them critical; 6.5 and older receive no security fixes), or take it offline if it cannot be upgraded, and run DIVD's log-check script against the logs for the code-execution flaw; also check the application directory for packages installed through the admin interface that you did not install and for a mail view template that overrides the built-in password-reset email, the route Horizon3's public exploit takes.
Until Zammad ships a fix for CVE-2026-102490, restrict access to the Zammad server to trusted administrators, as Zammad advises (the flaw needs prior access to the host), keep Zammad off the internet or behind an authenticating reverse proxy or VPN and segment the ticket host from other internal services.
Bring every SMA1000 6210/7210/8200v appliance to hotfix 12.4.3-03526 or 12.5.0-02952 now and then to 12.4.3-03670 or 12.5.0-03082 or higher, because the first pair is itself affected by CVE-2026-102255 (SonicWall's advisory SNWLID-2026-0017); if immediate patching is not possible, remove the appliance from internet exposure entirely rather than relying on network-layer filtering alone, since the SSRF reaches internal functionality through the appliance's own Work Place interface.
Where indicators of compromise are found, follow SonicWall's own remediation position: re-image or re-deploy the appliance, rotate every user and administrator password, and reset TOTP seeds, since that guidance implies that stored credentials and MFA seeds are compromised along with the appliance.
On every internet-facing FortiGate, terminate all administrator and VPN sessions, reset every administrator and VPN password, review the local administrator list and the REST API keys for entries nobody created (the actors add administrator accounts for persistence and may delete or lock the original ones), restrict management access to trusted hosts or a local-in policy, and enforce PBKDF2 for administrator password storage as Fortinet's guidance describes for FortiOS 7.2.11 and later.
If your organisation bought video-surveillance, alarm or access-control installation or maintenance from Ixa Systems, ask the firm in writing which of your sites and credentials are in the stolen data and rotate every camera, alarm, intercom and remote-maintenance credential it held.
Upgrade every self-managed FortiMail to the fixed build for its branch (8.0.2, 7.6.7 or 7.4.9; 7.2 moves to branch 7.4 or above, which means 7.4.9 or later; FortiMail Cloud customers need not act); until each appliance is upgraded, disable IBE support (config system encryption ibe, set status disable) or, as Fortinet's alternatives, cut the webmail interface off from the internet or block POST requests to /ibe containing '../' at a web application firewall in front of it.
Check every FortiMail that was internet-reachable before the workaround against the cron, CLI-audit and log artifacts in FG-IR-26-175 and the file artifacts that BleepingComputer and NCSC Switzerland describe, looking back to at least 2026-07-22, including a mail archive account that sends to a remote host and mail copied to destinations outside the organization.
Upgrade every Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd Data Center installation to a fixed version of its line (Bitbucket 9.4.26, 10.2.8 or 10.5.1; Confluence 9.2.26 or 10.2.19; Jira Service Management 5.12.40, 10.3.26 or 11.3.12; Jira Software 9.12.40, 10.3.26 or 11.3.12; Bamboo 10.2.24 or 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7 or 7.2.4) and Crucible and Fisheye to 4.9.15, internet-reachable instances first; until each is upgraded, take it off the internet or put Atlassian's web application firewall or Tomcat rewrite rule in front of it.
On every Jira instance that was internet-reachable and unpatched and is integrated with Crowd, treat the Crowd application password in its WEB-INF/classes/crowd.properties as readable: rotate it after the upgrade and review Crowd for user accounts created or group memberships changed since the exposure began; on every affected instance search the web server and proxy logs back to 2026-10-05, the day the advisory published (honeypots recorded the first attempts on 2026-10-06), for '..' next to '/', '\\' or '::'.
2026-10-08T0404Z-intel· Sonnet 5.5 · window 26 h · 4 entries published
Verification & coverage notes
Window: 26 h (gap 24.0 h to 2026-10-07T0404Z-intel). Four new entries and five changelog records (three update, two improvement). No deep dive: no candidate cleared the Phase 3 bar.
KEV sweep (work/2026-10-08T0404Z-intel/kev-window.txt): no CISA KEV addition inside the window (catalog 2026.10.04, newest addition CVE-2026-88779, covered); S1 read the catalog independently and agreed. The ransomware-flag cross-check printed no row.
Backlog (state/coverage_backlog.md, six open rows, all re-gated on today's facts, all held, none struck, none published): IBM MQ CVE-2026-10747 and the Langflow CVEs (S1: still not in KEV, no exploitation report or PoC; expiry 2026-10-11 stands); MikroTik CVE-2026-84411 (S1: MikroTik still names no fixed build, no KEV; expiry 2026-10-14); IBM Guardium CVE-2026-85542 (S1: not in KEV, no IBM confirmation of exploitation, no constituency deployment; expiry 2026-10-14); SafePay on ARA-Region Lyss-Limpachtal and Payload on Netech (S4: tracker records unchanged, no victim statement or press report; expiry 2026-10-14); Beyond Gravity (S2 and S4: still no vector, actor or data named; an FDP release suspecting a state actor and Netzwoche's "highly professional actor" are not findings; expiry 2026-10-20). No state change on those rows, so nothing was appended to them.
Updates: Atlassian CVE-2026-21589 (update: exploitation attempts from 2026-10-06, 129 attempts from 22 addresses on Previdian's page, SANS ISC honeypots, Nuclei template, CCCS "exploited"; status moves to exploited; priority stays high because the evidence is attempts and no compromise is reported, critical was considered); Zammad (update: Horizon3's root cause and public exploit for CVE-2026-102489); FortiBleed (update: FBI and U.S. Secret Service JCSA-20261006-01; lockouts and ransomware supply; the legacy entry also gained entity links, ATT&CK ids, an Admiralty rating and a do-now action in the same record); FortiMail CVE-2026-104286 (improvement: FortiMail Cloud remediated by Fortinet, so the upgrade instruction applies to self-managed appliances); SonicWall CVE-2026-83548 and CVE-2026-83549 (improvement: the September hotfix builds are themselves affected by CVE-2026-102255, so the entry's summary and a new Improvement section point on to the later hotfix; found by the first verifier pass).
New entries: SonicWall SMA1000 CVE-2026-102255 (high; PD-11 (b) otherwise limb: pre-authentication CVSS 10.0 SSRF on an internet-facing remote-access gateway whose two earlier sibling flaws this year were exploited, and it affects the September hotfix builds), Ixa Systems (notable; PD-11 (c): Vaud supplier to police, prisons, hospitals and banks; the strongest home-region item of the window), Power BI public-dashboard phishing delivering rogue ScreenConnect (notable; PD-11 (d)), BigDiskBuster (notable; PD-11 (d): Defender update starvation with a concrete detection anchor, no use in attacks reported).
Single-source: the Power BI entry rests on Huntress alone (single-source, medium confidence); the SonicWall entry's fixed-build figures come from The Hacker News and CERT-FR because the vendor page read through the reader omits the table, and the Canadian Cyber Centre bulletin lists the same builds as "and prior" (stated in the entry).
Contradiction: Inside IT says the Ixa data was published at the end of September; ICTjournal says it was put on sale on 25 September, and AWP says about a month after the end-of-August claim without giving a date; the entry reports each as its source words it.
Dedup: the Ixa entry keys actor:thegentlemen, as the 2026-10-02 FTAPI entry does; deliberate, a distinct victim and a distinct story, so the gate's entity-overlap warning stays and is explained here.
borderline-drop: HPE ClearPass and AOS-Switch HPESBNW05158 and HPESBNW05156 (seven unauthenticated CVSS 9.8 flaws on an internal network-access-control management plane, no exploitation or PoC, vendor release 2026-10-06T16:00Z, regular cycle under PD-11 (b)).
borderline-drop: Splunk Enterprise CVE-2026-76268 (needs network reach to the search-head-cluster Patroni API, internal, not exploited).
borderline-drop: Cisco 2026-10-07 batch (NX-OS NX-API, MPLS OAM and NGOAM feature-gated and off by default; unconditional NX-OS, APIC and License On-Prem findings are management-plane, none exploited, no PoC, no KEV; Cisco's disclosure cadence is first and third Wednesday, next batch 2026-10-21). Consistent with the August IOS XE entry only in kind; the bar applied today is the strict PD-11 (b) one. Flagged for the audit's calibration check.
borderline-drop: ILIAS 9.24, 10.12 and 11.5 (RCE paths need authentication, no CVE ids, no exploitation; earlier ILIAS entries exist), Veeam KB4934 (authenticated Backup Viewer role, no CVE mapping published, no exploitation), Rejetto HFS CVE-2026-61500 canary attempts (honeypot-only, dropped by the 2026-10-06 fire), OrdaSoft Joomla extensions (niche, single source, no deployment shown; dropped by the 2026-10-06 fire), LibreOffice and OpenOffice CVE-2026-63277 and CVE-2026-59265 (needs Java and a user opening the file; dropped by the 2026-10-06 fire), Ghostscript CVE-2026-101258 (local, user interaction, CVSS 7.8, no exploitation).
borderline-drop: Sungrow iSolarCloud (vendor-side fix, nothing for an owner to patch, no Swiss footprint), Microsoft .msix default block in Outlook (preventive default change), PoeLLM (cryptomining botnet on exposed AI services, single source, no public-sector context), CrocoRat (infrastructure down by late September, fourth ClickFix variant in the store), the .gh, .sl and .as registry hijacks (no Swiss nexus, generic CT-monitoring and CAA advice; dropped by the 2026-10-06 fire), ClingSTUN (IoT botnet, no public-sector targeting), ARTEX and CyberXero (no detection-grade behaviour; reliability C single report with Korean and Ukrainian victimology), Wikimedia and OpenAI agents (no compromise, no government nexus; dropped by the 2026-10-06 fire).
borderline-drop: IDC Frontier cloud ransomware in Japan (no vector or actor, generic takeaway), Silent Ransom Group chat leak (law-firm victimology, unverified claims), ASOS push-notification extortion (retailer, no platform or vector named). Claim-only watch for the next fire: T-Systems (SafePay, 2026-10-05), Leadec (Anubis) and University of Rostock (Panzer), both listed 2026-10-07.
Coverage gaps: ssd-disclosure (robot challenge on every transport); esentire (listing renders client-side); morphisec (bylines without titles); depthfirst (undated listing); kommunaler-notbetrieb-de (nothing newer than 2026-09-21); letemps-ch (hard paywall, lead only).
Source rotation: the previous two fires' attempts (18 standard records) were excluded from the S1, S2 and S3 slices; S4's pool of 19 breach sources was allocated whole because excluding the last two fires' attempts would have left it empty. S1, S2 and S4 returned complete ledgers (22, 29 and 15 rows); S3 returned 18 of 18. No continuation was needed. Promotions: patchstack and nextgov-fcw (promotion_due). Candidates added: cccs-alerts, sonicwall-psirt, previdian.
For the audit: S2 reports netzwoche now reads direct as RSS (https://www.netzwoche.ch/rss.xml, 20 items) where the record has fetch_method: webfetch and no rss_url, and a lazy regex over the 557 KB bacs-press listing backtracks catastrophically (split the HTML on identifier="teaser-item-nsb" instead); neither record was edited this fire. cert.gov.ua article pages are an SPA (feed https://cert.gov.ua/api/articles/rss 8 gives dated titles). The CISA ICS release of 2026-10-06 (six advisories) fell outside the window and was not read. The Atlassian and SonicWall entries cite the Canadian Cyber Centre bulletins as relays; both restate the vendor and the open-source reporting.
Verification: the loop ran to the eight-iteration cap without a double CLEAN (every pass returned NEEDS_FIXES, findings falling from 21 to 5), so the run publishes fail-open. Each pass's truth and editorial findings were fixed in place and re-gated; four of the last pass's five findings were fixed afterwards without a ninth pass (the advisory on live Atlassian counters was not), so the recorded residual count of 4 is the last pass's own count and not a measure of what still stands. Left as judgement calls: the Atlassian entry quotes Previdian's live counters (the entry says at least), the FortiMail Cloud correction stays an improvement so a critical entry does not re-float, and the earlier SonicWall entry's first action now names the later hotfix as the end state.
Backlog corrections: a first-draft Guardium note that read an unrelated EUVD record (EUVD-2026-84275, a WordPress plugin flaw whose id collides with the CVE number) as IBM's CVE-2026-84275 was caught by the verifier and never reached main; IBM's own score for that flaw is 9.8 and the 2026-10-07 note stands.