CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
‹Thu · 08 Oct 2026
All daily briefs →
Daily brief · UTC day

Thursday, 8 October 2026

4 verified findings from 1 run · 5 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

CriticalUpgrade every self-managed FortiMail to a fixed build now: the zero-day is exploited and fixes have shippedCVE-2026-104286 · exploited · improved 08 Oct 04:59Z
Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01SonicWall patches a third pre-auth CVSS 10.0 SMA1000 SSRF; the September hotfix builds are affected. SonicWall's advisory SNWLID-2026-0017 (2026-10-06) fixes four SMA1000 flaws, led by CVE-2026-102255, a pre-authentication server-side request forgery in the Work Place interface (CVSS 3.0 10.0) that affects 12.4.3-03526 and 12.5.0-02952, the hotfixes issued for the September zero-days. SonicWall reports no exploitation, but the two earlier unauthenticated Work Place SSRF flaws this year were exploited, each paired with an administrator-only command-execution flaw; fixed builds are 12.4.3-03670 and 12.5.0-03082. →
  2. 02A Defender bypass that needs no vulnerability: fill the disk during every update and the engine stays up, stale. LevelBlue SpiderLabs reproduced BigDiskBuster, a proof of concept published on GitHub on 2026-09-19 by the actor known as MSNightmare, which watches the C: volume for Defender update activity and claims the free space so each update fails while the Defender service keeps running and real-time protection stays on. It runs from a standard account and has no CVE or patch; Microsoft says Defender Antivirus detects the proof of concept, and no use in attacks is reported. →
  3. 03Huntress: a Power BI-hosted phishing link installs rogue ScreenConnect clients; in one case a script removed the first. Huntress describes a phishing campaign seen since 2026-09-10 in which an Outlook email links to a fake reference document on a legitimate Power BI domain; a "Download Reference" button opens an attacker page that fingerprints the visitor and then downloads a ScreenConnect installer. The installer deploys a rogue ScreenConnect client that establishes a second one, and in one incident a PowerShell script removed the first; Huntress could not obtain the original email, and the configuration of one of the rogue clients also appeared on 22 other endpoints. →

01Active threats, incidents & disclosures2 items

NOTABLENATOB2

Ixa Systems, a Vaud security integrator serving police, prisons and banks: camera locations, plans and some passwords that TheGentlemen claimed to have stolen are reported on sale on the darknet

Le Temps reports that data stolen in a ransomware attack on a Vaud security-technology firm is now on sale on the darknet, and that the loot includes the locations of surveillance cameras, passwords and plans of security installations (Le Temps, 2026-10-06). The AWP agency names the firm as Ixa Systems of Crissier, which specialises in video surveillance, access control and burglary protection and whose customers include police authorities, banks, hospitals, schools and prisons (AWP via cash.ch, 2026-10-07). ICTjournal lists the Établissements de la plaine de l'Orbe and other judicial entities, gendarmerie premises, several banks including the Banque cantonale vaudoise and several dozen companies among the organisations concerned, and says exposure varies: for some clients the documents are limited to tenders or consultations, for others they give the location of cameras or the layout of alert buttons (ICTjournal, 2026-10-07).

Le Temps says the group TheGentlemen announced and claimed the theft on the darknet at the end of August (Le Temps, 2026-10-06). Inside IT dates the claim to 28 August and says the group made good on its threat to publish the data at the end of September (Inside IT, 2026-10-07), while ICTjournal says the documents were put on sale on 25 September and that, according to an expert's analysis seen by Le Temps, some of the data has begun to circulate (ICTjournal, 2026-10-07). The firm says it never lost use of its data, paid no ransom and that the attack gave no direct access to camera images; the canton's cybersecurity delegate says checks so far have found nothing that would compromise the security of the establishments concerned or give access to the State's IT environment, and that knowing a camera model is not enough to exploit it because the device must be reachable (ICTjournal, 2026-10-07). None of the reports states how the attackers got in.

incident08 Oct 04:52Zmulti-sourceOpen finding →
NOTABLENATOB2

A phishing link on Microsoft's own Power BI domain slips past mail filters and installs rogue ScreenConnect clients, then, in one incident, a script replaces the first remote-management tool with a second

Huntress describes a phishing campaign it has seen since 2026-09-10 in which an Outlook email carries a link that leads to a fake reference document on a legitimate Power BI domain (Huntress, 2026-10-07). Huntress notes that threat actors have previously abused Power BI in this way, building a real dashboard under an account of their own (usually compromised or throwaway), embedding a malicious link and setting its sharing to public, and that because the link points to Microsoft's real domain it passes Microsoft 365 mail filters and other gateways that trust that domain; it does not say how this campaign's page was set up (Huntress, 2026-10-07). A "Download Reference" button opens a new tab on an attacker domain that fingerprints the visitor (operating system, browser, automation indicators, cloud-provider cookies), reports victims to a Telegram bot and redirects visitors who fail its checks; after a delay a script clicks a hidden download link for a ScreenConnect installer (Huntress, 2026-10-07).

The installer deploys a first rogue ScreenConnect client, which establishes a second one pointed at different infrastructure (Huntress, 2026-10-07). In one incident the first client ran a command-shell script that launched a PowerShell script from the temp directory; that script downloaded and ran the installer for the second client and uninstalled the first, in a likely effort to evade detection, and a scheduled task re-ran it every two minutes before the attack was shut down (Huntress, 2026-10-07). After deployment the clients also ran a tool Huntress assessed as designed to hide the attacker's activity from the user and security software (Huntress, 2026-10-07). A handful of endpoints were hit from 2026-09-10, and the configuration of one of the rogue clients also appeared on 22 other endpoints in separate incidents (Huntress, 2026-10-07). The original email and lure wording are unknown.

Triage: ScreenConnect is legitimate where the organisation runs it; the discriminators are an instance that is not the organisation's own and an installer that arrived through a browser download from a web page rather than through IT's deployment tooling (Huntress, 2026-10-07).

Because the link points to Microsoft's real Power BI domain, it skirts through Microsoft 365 mail filters and other security gateways that trust this domain.

the PowerShell script also resulted in the uninstallation of the first ScreenConnect instance, in a likely effort to evade detection

Huntress 2026-10-07
threat08 Oct 04:53Zsingle-sourceOpen finding →
Sources: Huntress

CVE-2026-102255, SonicWall SMA1000: a third unauthenticated CVSS 10.0 Work Place SSRF this year, and it affects the hotfix builds that closed the September zero-days (no exploitation reported)

SonicWall's advisory SNWLID-2026-0017 of 2026-10-06 fixes four flaws in the SMA1000 secure remote-access appliances (models 6210, 7210 and 8200v). CVE-2026-102255 (CVSS 3.0 10.0) is a pre-authentication server-side request forgery in the Work Place interface, attributed to an unintended alternate access path, through which a remote unauthenticated attacker can direct the appliance to issue requests on their behalf, reach internal functionality and perform unauthorized operations (SonicWall PSIRT, 2026-10-06). The other three flaws need a login: an OS command injection that lets an administrator execute commands (CVE-2026-102256, 7.8), a Zip Slip in the Appliance Management Console that leads to code execution (CVE-2026-102257, 7.2) and a stored cross-site scripting flaw in that console (CVE-2026-102258, 5.5) (SonicWall PSIRT, 2026-10-06). SonicWall says there is currently no evidence that any of them is exploited (SonicWall PSIRT, 2026-10-06).

The pre-authentication flaw is not routine because of what came before it. The Hacker News counts it as the third time this year that SonicWall has fixed a 10.0-rated Work Place SSRF that needs no login; in July and September SonicWall said it had investigated attacks on the earlier pairs ("multiple cases" and "a case"), each pair combining an SSRF that needs no login with a second flaw that lets a logged-in administrator run commands (The Hacker News, 2026-10-07). CERT-FR notes that such pairs have been actively exploited several times this year on this product (CERT-FR, 2026-10-07). The affected builds include 12.4.3-03526 and 12.5.0-02952, the hotfixes SonicWall named on 1 September for the two exploited flaws, so an appliance patched against that chain is still affected (The Hacker News, 2026-10-07). Fixed builds are 12.4.3-03670 and 12.5.0-03082 and higher (The Hacker News, 2026-10-07; CERT-FR, 2026-10-07), whereas the Canadian Cyber Centre's bulletin lists the same two builds as affected "and prior" (Canadian Cyber Centre, 2026-10-07). Shadowserver tracks over 400 internet-exposed SMA1000 appliances, some of which may already be patched, and BleepingComputer says government agencies and managed service providers use the product to give VPN access to internal applications (BleepingComputer, 2026-10-07). NCSC Switzerland published an advisory on 2026-10-07 and lists the exploitation status as unknown (NCSC Switzerland, 2026-10-07).

There is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild.

SonicWall PSIRT (advisory SNWLID-2026-0017) 2026-10-06

It is the third time this year that SonicWall has fixed a 10.0-rated SSRF flaw in WorkPlace that needs no login.

12.4.3-03670 and higher versions are fixed.

12.5.0-03082 and higher versions are fixed.

The Hacker News 2026-10-07

Builds on: SonicWall confirms active exploitation of an unauthenticated SMA1000 SSRF chained to code… · The second SonicWall SMA1000 zero-day chain in seven weeks, and this time the vendor's own…

vulnerability08 Oct 04:50Zmulti-sourceOpen finding →

03Research, reports & policy1 item

NOTABLENATOB2

BigDiskBuster: a roughly 300-line Windows proof of concept keeps Microsoft Defender from updating by claiming all free disk space, with no CVE and no patch

LevelBlue SpiderLabs reproduced BigDiskBuster, a proof of concept published on GitHub on 2026-09-19 by the actor known as MSNightmare (Nightmare Eclipse) that needs no vulnerability to keep Microsoft Defender from updating (LevelBlue SpiderLabs, 2026-10-05). It watches the C: volume for Defender update activity and, when an update begins, creates a hidden file whose allocation claims essentially all free space; the update runs out of room and fails, Defender cleans up its staging directory and the tool repeats the process on the next attempt (LevelBlue SpiderLabs, 2026-10-05). The Defender service keeps running and real-time protection stays on; in LevelBlue's lab no alert appeared, and the only visible artifact was a stale security-intelligence version and the generic update error 0x80070643 (LevelBlue SpiderLabs, 2026-10-05). The roughly 300 lines of C++ use no memory corruption or kernel component: a raw handle on the volume device, a file opened relative to that handle, a recursive watch of the volume and an oversized allocation, with the file hidden and deleted on close (LevelBlue SpiderLabs, 2026-10-05). It ran under a standard user account on a default Defender installation (Dark Reading, 2026-10-06).

No CVE, patch or Microsoft advisory exists; a Microsoft spokesperson told Dark Reading that Defender Antivirus includes detections and preventions against the proof of concept and that customers should keep security intelligence and platform updates current (Dark Reading, 2026-10-06). The GitHub repository has been taken down, and Dark Reading notes that the technique could in theory extend the life of malicious tooling already on a machine by withholding new detections (Dark Reading, 2026-10-06). No source reports use in an attack.

Triage: a handle on the volume device alone is low-specificity because svchost, SearchIndexer, dllhost and TiWorker hold the same kind of handle in normal operation; in LevelBlue's tested environment only the Defender service processes and TrustedInstaller legitimately held a handle on MRT.exe (LevelBlue SpiderLabs, 2026-10-05).

At the time of publication, BigDiskBuster has no assigned CVE, available patch, or Microsoft advisory.

LevelBlue SpiderLabs 2026-10-05

a Microsoft spokesperson tells Dark Reading that Microsoft Defender Antivirus includes detections and preventions against the PoC

Dark Reading 2026-10-06

a process holding both of these handles simultaneously has no ordinary reason to exist on a stock Windows endpoint

LevelBlue SpiderLabs 2026-10-05
research08 Oct 04:54Zmulti-sourceOpen finding →

04Updates to prior coverage5 items

HIGHCVE-2026-83548 +1exploitedupdatedNATOB1

CVE-2026-83548 / CVE-2026-83549, SonicWall SMA1000: a pre-auth SSRF through an unintended alternate Work Place access path chains into post-auth command injection in the Management Console, both under active exploitation

First published 2026-09-03 · open finding →

Improvementrun 2026-10-08T0404Z-inteltitlesummarycvesactionssourcessourcing_notebody

SonicWall's advisory of 2026-10-06 fixes a third pre-authentication Work Place SSRF, CVE-2026-102255, and its affected builds include 12.4.3-03526 and 12.5.0-02952, the hotfixes named here as the fix for these two flaws. Appliances on those builds need the later hotfix, 12.4.3-03670 or 12.5.0-03082.

SonicWall's advisory SNWLID-2026-0017 of 2026-10-06 fixes CVE-2026-102255, a third pre-authentication Work Place SSRF this year, and lists 12.4.3-03526 and 12.5.0-02952, the hotfixes named above as the fix for CVE-2026-83548 and CVE-2026-83549, among the affected builds; the fixed builds for the new flaw are 12.4.3-03670 and 12.5.0-03082 and higher (The Hacker News, 2026-10-07). The hotfixes above still fix the two flaws described here, but an appliance on them needs the later hotfix as well.

CRITICALCVE-2026-104286exploitedupdatedNATOA2

CVE-2026-104286, Fortinet FortiMail: unauthenticated path traversal file write exploited as a zero-day, fixed in 8.0.2, 7.6.7 and 7.4.9 (CVSS 9.8)

First published 2026-10-02 · open finding →

Improvementrun 2026-10-08T0404Z-intelsummaryimmediate_actionactionsevidencebody

Fortinet's revision of 2026-10-07 states that it remediated FortiMail Cloud on 2026-10-05 by updating all firmware to 7.6.7 or 8.0.2, so FortiMail Cloud customers need take no action; the upgrade instruction now applies to self-managed appliances. Fixed builds, workarounds and compromise artifacts are unchanged.

Fortinet's revision of 2026-10-07 adds a FortiMail Cloud clarification to the advisory: Fortinet remediated the issue on 2026-10-05 in FortiMail Cloud by updating all firmware to 7.6.7 or 8.0.2, so FortiMail Cloud customers need not perform any action (Fortinet PSIRT, 2026-10-01). The upgrade and workaround instructions above therefore apply to self-managed appliances; the advisory still shows the flaw as exploited in the wild and its fixed builds, workarounds and compromise artifacts are unchanged (Fortinet PSIRT, 2026-10-01).

HIGHexploitedupdatedNATOA1

FortiBleed: an active credential-compromise campaign against internet-facing FortiGate firewalls, now locking administrators out and supplying ransomware affiliates

First published 2026-06-18 · open finding →

Updaterun 2026-10-08T0404Z-inteltitleheadlinesummarytagsentitiestechniquesaffected_productsclassificationsourcesevidencesourcing_noteactionsbody

A joint FBI and U.S. Secret Service advisory of 2026-10-06 says FortiBleed is still active: the operators create administrator accounts on compromised FortiGates and in some cases delete or change the original accounts, locking owners out, and access brokers using the chain have supplied INC/Lynx and Payload ransomware affiliates. It cites SOCRadar for more than 86,644 compromised devices and adds firewall, VPN and domain controller log review, REST API key review and PBKDF2 enforcement to the response.

A joint advisory of the FBI and the U.S. Secret Service (JCSA-20261006-01, 2026-10-06) calls FortiBleed an active, global credential-compromise campaign against internet-facing FortiGate firewalls and SSL VPN gateways, cites SOCRadar for more than 86,644 compromised devices in 194 countries, and says attackers are continuing to scan exposed devices with previously obtained credentials (FBI and U.S. Secret Service, 2026-10-06). The operators scan exposed SSL VPN portals, run credential stuffing and password spraying from earlier Fortinet leak dumps and infostealer logs, pull password hashes and session tokens from compromised devices and crack the hashes offline with Hashcat and Hashtopolis on a rented GPU cluster; the advisory ties the success to reused or leaked credentials and a legacy SHA-256 password storage (FBI and U.S. Secret Service, 2026-10-06).

What the advisory adds is the lockout. On a compromised firewall the actors create administrator accounts that were not there before and, in some cases, delete existing accounts or change their passwords, so the owners cannot log in and recovery needs steps beyond patching and password resets (FBI and U.S. Secret Service, 2026-10-06; BleepingComputer, 2026-10-07). Cracked credentials are enriched and validated by scripts that filter out honeypots and rank targets by revenue and network structure; with verified credentials the attackers enumerate Active Directory accounts and spray passwords to find privileged users, and the operation packages working VPN configurations and target lists for sale, the role of an initial-access broker (FBI and U.S. Secret Service, 2026-10-06). The advisory says the chain has been an initial entry point for ransomware affiliates, currently INC/Lynx and Payload (FBI and U.S. Secret Service, 2026-10-06); SOCRadar had linked FortiBleed to INC and Lynx in July after reaching both groups' negotiation panels on a server used in the campaign (BleepingComputer, 2026-10-07).

The advisory's measures: restrict external management through trusted hosts, a local-in policy or no internet administration at all; terminate all administrative and VPN sessions and reset all Fortinet VPN and administrator passwords; require phishing-resistant MFA on remote access and administrator accounts; review users, configuration and REST API keys for entries nobody created, removing unknown keys and refreshing the legitimate ones; enforce PBKDF2 for administrator password storage per Fortinet's guidance for FortiOS 7.2.11 and later; and review firewall, VPN, authentication and domain controller logs for lateral movement (FBI and U.S. Secret Service, 2026-10-06). On a FortiGate the matching telemetry is the configuration and administrator audit log (administrator accounts created or deleted, passwords changed, new REST API keys); behind the VPN it is the domain controller authentication log, for lateral movement (FBI and U.S. Secret Service, 2026-10-06).

HIGHCVE-2026-102489 +1exploitedupdatedNATOA2

CVE-2026-102489 / CVE-2026-102490, Zammad helpdesk: a session-hijack remote code execution and a zammad-to-root escalation, both reported exploited since 21 September, with no fix named for the root flaw

First published 2026-10-02 · open finding →

Updaterun 2026-10-08T0404Z-intelheadlinesummarytagstechniquescvessourcesevidencesourcing_noteactionsbody

Horizon3 published the root cause of CVE-2026-102489 and a working exploit on 2026-10-07: a single unauthenticated WebSocket request makes Zammad return an error carrying every active user's session cookies, and a leaked administrator session writes a mail template through the package installation endpoint that runs code as the zammad user. The exploited flaw now has a public exploit, and Horizon3 says the root escalation remains unpatched.

Horizon3 published a reverse-engineering of CVE-2026-102489 on 2026-10-07, with a proof-of-concept repository (Horizon3, 2026-10-07). Zammad keeps the state of every connected WebSocket client, including the session Cookie header, in a class-level registry that is passed to every event; a single request to the /ws WebSocket endpoint carrying the event name base makes the dispatcher instantiate an event class that has no implementation, and the resulting error message, which includes the object's full representation, is returned to the caller together with the cookies of all active users (Horizon3, 2026-10-07). With a leaked administrator session an attacker writes files into the application directory through the package installation endpoint, overrides the built-in password-reset email view with a malicious template and triggers a password reset for any user, which executes the template as the zammad user (Horizon3, 2026-10-07).

Horizon3 says it believes the privilege escalation is CVE-2026-102490, that it remains unpatched, and that it is withholding those details (Horizon3, 2026-10-07). Horizon3's write-up names no Zammad version; Zammad's advisory of 2026-10-05 says CVE-2026-102489 is exploitable only on 6.5 and earlier (Zammad, 2026-10-05).

HIGHCVE-2026-21589exploitedupdatedNATOA1

CVE-2026-21589, Atlassian Data Center: unauthenticated arbitrary file access in every version of eight self-managed products, patch or take them off the internet (CVSS 4.0 9.3)

First published 2026-10-06 · open finding →

Updaterun 2026-10-08T0404Z-intelheadlinesummarytagstechniquescvessourcesevidencesourcing_noteactionsbody

Exploitation attempts began on 2026-10-06, the day watchTowr published its write-up and proof of concept: Previdian's sensors have recorded at least 129 attempts from at least 22 addresses in eight countries, SANS ISC recorded similar attempts against Jira, Confluence and Bitbucket on its own honeypots, all from one cloud provider, and a Nuclei template exists; the Canadian Cyber Centre's bulletin now cites open-source reporting of in-the-wild exploitation. The status moves from patch-available to exploited, with no compromise reported and the flaw not listed in CISA's KEV catalog on Previdian's page.

Exploitation attempts began on 2026-10-06, the day watchTowr published. Previdian, which runs a honeypot network, told BleepingComputer that its sensors began recording attempts within two hours of that publication, and that a Nuclei template has since been released that makes scanning for vulnerable systems easier; it expects exploitation to rise significantly over the coming days and weeks (BleepingComputer, 2026-10-07). Its telemetry page, updated 2026-10-08, shows at least 129 attempts from at least 22 source addresses in eight countries across three sensors, first observed on 2026-10-06 (its timeline lists the first sensor observation at 20:52 UTC on 2026-10-06, about four hours after watchTowr's post of 17:01 UTC, which is later than the two-hours figure; Previdian, 2026-10-08; watchTowr Labs, 2026-10-06) and last on 2026-10-08, and lists the flaw as not in CISA's KEV catalog (Previdian, 2026-10-08). The SANS Internet Storm Center says its own honeypots began receiving attempts on 2026-10-06 with the URLs from watchTowr's write-up against Jira, Confluence and Bitbucket resource paths, that every source address belongs to one cloud hosting provider, and that it believes a single actor is behind them (SANS ISC, 2026-10-07).

Neither honeypot operator reports a successful compromise. The Canadian Cyber Centre updated its bulletin on 2026-10-07 to say that open-source reporting indicates the flaw is being exploited in the wild (Canadian Cyber Centre, 2026-10-07), while NCSC Switzerland's advisory, edited on 2026-10-07 to add the public proof of concept, lists the status as proof of concept available and does not report exploitation (NCSC Switzerland, 2026-10-07).

05Action items11 items

Verification & coverage notes1 run

2026-10-08T0404Z-intel · Sonnet 5.5 · window 26 h · 4 entries published

Verification & coverage notes

  • Window: 26 h (gap 24.0 h to 2026-10-07T0404Z-intel). Four new entries and five changelog records (three update, two improvement). No deep dive: no candidate cleared the Phase 3 bar.
  • KEV sweep (work/2026-10-08T0404Z-intel/kev-window.txt): no CISA KEV addition inside the window (catalog 2026.10.04, newest addition CVE-2026-88779, covered); S1 read the catalog independently and agreed. The ransomware-flag cross-check printed no row.
  • Backlog (state/coverage_backlog.md, six open rows, all re-gated on today's facts, all held, none struck, none published): IBM MQ CVE-2026-10747 and the Langflow CVEs (S1: still not in KEV, no exploitation report or PoC; expiry 2026-10-11 stands); MikroTik CVE-2026-84411 (S1: MikroTik still names no fixed build, no KEV; expiry 2026-10-14); IBM Guardium CVE-2026-85542 (S1: not in KEV, no IBM confirmation of exploitation, no constituency deployment; expiry 2026-10-14); SafePay on ARA-Region Lyss-Limpachtal and Payload on Netech (S4: tracker records unchanged, no victim statement or press report; expiry 2026-10-14); Beyond Gravity (S2 and S4: still no vector, actor or data named; an FDP release suspecting a state actor and Netzwoche's "highly professional actor" are not findings; expiry 2026-10-20). No state change on those rows, so nothing was appended to them.
  • Updates: Atlassian CVE-2026-21589 (update: exploitation attempts from 2026-10-06, 129 attempts from 22 addresses on Previdian's page, SANS ISC honeypots, Nuclei template, CCCS "exploited"; status moves to exploited; priority stays high because the evidence is attempts and no compromise is reported, critical was considered); Zammad (update: Horizon3's root cause and public exploit for CVE-2026-102489); FortiBleed (update: FBI and U.S. Secret Service JCSA-20261006-01; lockouts and ransomware supply; the legacy entry also gained entity links, ATT&CK ids, an Admiralty rating and a do-now action in the same record); FortiMail CVE-2026-104286 (improvement: FortiMail Cloud remediated by Fortinet, so the upgrade instruction applies to self-managed appliances); SonicWall CVE-2026-83548 and CVE-2026-83549 (improvement: the September hotfix builds are themselves affected by CVE-2026-102255, so the entry's summary and a new Improvement section point on to the later hotfix; found by the first verifier pass).
  • New entries: SonicWall SMA1000 CVE-2026-102255 (high; PD-11 (b) otherwise limb: pre-authentication CVSS 10.0 SSRF on an internet-facing remote-access gateway whose two earlier sibling flaws this year were exploited, and it affects the September hotfix builds), Ixa Systems (notable; PD-11 (c): Vaud supplier to police, prisons, hospitals and banks; the strongest home-region item of the window), Power BI public-dashboard phishing delivering rogue ScreenConnect (notable; PD-11 (d)), BigDiskBuster (notable; PD-11 (d): Defender update starvation with a concrete detection anchor, no use in attacks reported).
  • Single-source: the Power BI entry rests on Huntress alone (single-source, medium confidence); the SonicWall entry's fixed-build figures come from The Hacker News and CERT-FR because the vendor page read through the reader omits the table, and the Canadian Cyber Centre bulletin lists the same builds as "and prior" (stated in the entry).
  • Contradiction: Inside IT says the Ixa data was published at the end of September; ICTjournal says it was put on sale on 25 September, and AWP says about a month after the end-of-August claim without giving a date; the entry reports each as its source words it.
  • Dedup: the Ixa entry keys actor:thegentlemen, as the 2026-10-02 FTAPI entry does; deliberate, a distinct victim and a distinct story, so the gate's entity-overlap warning stays and is explained here.
  • borderline-drop: HPE ClearPass and AOS-Switch HPESBNW05158 and HPESBNW05156 (seven unauthenticated CVSS 9.8 flaws on an internal network-access-control management plane, no exploitation or PoC, vendor release 2026-10-06T16:00Z, regular cycle under PD-11 (b)).
  • borderline-drop: Splunk Enterprise CVE-2026-76268 (needs network reach to the search-head-cluster Patroni API, internal, not exploited).
  • borderline-drop: Cisco 2026-10-07 batch (NX-OS NX-API, MPLS OAM and NGOAM feature-gated and off by default; unconditional NX-OS, APIC and License On-Prem findings are management-plane, none exploited, no PoC, no KEV; Cisco's disclosure cadence is first and third Wednesday, next batch 2026-10-21). Consistent with the August IOS XE entry only in kind; the bar applied today is the strict PD-11 (b) one. Flagged for the audit's calibration check.
  • borderline-drop: ILIAS 9.24, 10.12 and 11.5 (RCE paths need authentication, no CVE ids, no exploitation; earlier ILIAS entries exist), Veeam KB4934 (authenticated Backup Viewer role, no CVE mapping published, no exploitation), Rejetto HFS CVE-2026-61500 canary attempts (honeypot-only, dropped by the 2026-10-06 fire), OrdaSoft Joomla extensions (niche, single source, no deployment shown; dropped by the 2026-10-06 fire), LibreOffice and OpenOffice CVE-2026-63277 and CVE-2026-59265 (needs Java and a user opening the file; dropped by the 2026-10-06 fire), Ghostscript CVE-2026-101258 (local, user interaction, CVSS 7.8, no exploitation).
  • borderline-drop: Sungrow iSolarCloud (vendor-side fix, nothing for an owner to patch, no Swiss footprint), Microsoft .msix default block in Outlook (preventive default change), PoeLLM (cryptomining botnet on exposed AI services, single source, no public-sector context), CrocoRat (infrastructure down by late September, fourth ClickFix variant in the store), the .gh, .sl and .as registry hijacks (no Swiss nexus, generic CT-monitoring and CAA advice; dropped by the 2026-10-06 fire), ClingSTUN (IoT botnet, no public-sector targeting), ARTEX and CyberXero (no detection-grade behaviour; reliability C single report with Korean and Ukrainian victimology), Wikimedia and OpenAI agents (no compromise, no government nexus; dropped by the 2026-10-06 fire).
  • borderline-drop: IDC Frontier cloud ransomware in Japan (no vector or actor, generic takeaway), Silent Ransom Group chat leak (law-firm victimology, unverified claims), ASOS push-notification extortion (retailer, no platform or vector named). Claim-only watch for the next fire: T-Systems (SafePay, 2026-10-05), Leadec (Anubis) and University of Rostock (Panzer), both listed 2026-10-07.
  • Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0 (the profile configures none).
  • Coverage gaps: ssd-disclosure (robot challenge on every transport); esentire (listing renders client-side); morphisec (bylines without titles); depthfirst (undated listing); kommunaler-notbetrieb-de (nothing newer than 2026-09-21); letemps-ch (hard paywall, lead only).
  • Source rotation: the previous two fires' attempts (18 standard records) were excluded from the S1, S2 and S3 slices; S4's pool of 19 breach sources was allocated whole because excluding the last two fires' attempts would have left it empty. S1, S2 and S4 returned complete ledgers (22, 29 and 15 rows); S3 returned 18 of 18. No continuation was needed. Promotions: patchstack and nextgov-fcw (promotion_due). Candidates added: cccs-alerts, sonicwall-psirt, previdian.
  • For the audit: S2 reports netzwoche now reads direct as RSS (https://www.netzwoche.ch/rss.xml, 20 items) where the record has fetch_method: webfetch and no rss_url, and a lazy regex over the 557 KB bacs-press listing backtracks catastrophically (split the HTML on identifier="teaser-item-nsb" instead); neither record was edited this fire. cert.gov.ua article pages are an SPA (feed https://cert.gov.ua/api/articles/rss 8 gives dated titles). The CISA ICS release of 2026-10-06 (six advisories) fell outside the window and was not read. The Atlassian and SonicWall entries cite the Canadian Cyber Centre bulletins as relays; both restate the vendor and the open-source reporting.
  • Verification: the loop ran to the eight-iteration cap without a double CLEAN (every pass returned NEEDS_FIXES, findings falling from 21 to 5), so the run publishes fail-open. Each pass's truth and editorial findings were fixed in place and re-gated; four of the last pass's five findings were fixed afterwards without a ninth pass (the advisory on live Atlassian counters was not), so the recorded residual count of 4 is the last pass's own count and not a measure of what still stands. Left as judgement calls: the Atlassian entry quotes Previdian's live counters (the entry says at least), the FortiMail Cloud correction stays an improvement so a critical entry does not re-float, and the earlier SonicWall entry's first action now names the later hotfix as the end state.
  • Backlog corrections: a first-draft Guardium note that read an unrelated EUVD record (EUVD-2026-84275, a WordPress plugin flaw whose id collides with the CVE number) as IBM's CVE-2026-84275 was caught by the verifier and never reached main; IBM's own score for that flaw is 9.8 and the 2026-10-07 note stands.