Verification & coverage notes
Coverage window: standard fire. The previous intel fire started 2026-10-09T02:55:59Z, so gap_hours=24.0 and window_hours=26; the developing-story window was 72 hours. The clock cross-check against the network date agreed (skew 0 s) and the fresh fetch showed the newest run record of 2026-10-09T0255Z.
Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found no KEV addition since 2026-10-09 (catalog 2026.10.08, released 2026-10-08T20:09Z; the five old CVEs added on 2026-10-08 are inside the AA26-281A entry) and no RANSOMWARE row. S1 confirmed it through the cisa-kev recipe and found no ransomware-flag flip on a covered CVE. The 2026-10-10 re-read of the catalogue shows none of CVE-2026-84411, -102255, -105133, -105134 or -82077 listed. No scheduled multi-product release fell in the window (Microsoft, SAP and Fortinet on 2026-10-13, Oracle on 2026-10-20, Cisco on 2026-10-21).
Verification: five cold iterations, each a fresh cti-verification pass over the full ledger (204 to 214 claims, all checked). Iterations 1 to 4 returned NEEDS_FIXES (truth 20, 7, 5 and 4; editorial 5, 2, 2 and 1) and every truth finding was remediated and re-checked by the next pass. Iteration 5 returned NEEDS_FIXES with truth 0 and editorial 2 (both F8: a third disguise name missing from the GhostAction hunt scope, an Exposure line missing from the SAP entry) and no F1 or F4, so the low-residual early exit applies: both were fixed after the pass and the run publishes without a sixth iteration. The residual count is the final iteration's two editorial findings. Standing advisories, unfixed on purpose: em dashes in older PaperCut and SAP text this fire did not touch, and the missing Exposure line on the PaperCut entry.
New entries (3):
- MikroTik RouterOS CVE-2026-84411 (vulnerability, routine after verifier iteration 1; pre-auth web-management RCE, MikroTik's own notice now names the fix; PD-11(b) on its own mechanics, a single unauthenticated request to root on an edge router class that botnets target, with the default firewall keeping the interface off the internet and no exploitation, which holds it at routine; resolves the backlog row).
- AhsayCBS CVE-2026-105133 / CVE-2026-105134 (vulnerability, notable; exploited from 2026-10-07 with webshells and a miner, 10.3.4 also affected and no fixed release named; PD-11(b); the nexus is the managed-service-provider and integrator class that serves public bodies, so it is notable and not high; single-source on Huntress, Admiralty B2).
- GhostAction (threat, notable; stolen maintainer credentials, confirmed exfiltration at an Uber-owned repository, history-wide credential sweep that makes secret rotation insufficient; PD-11(a) and (d): an organisation-scoped search and an audit-log query take minutes; no public-sector victim is named, the ground is GitHub-hosted developer estates of public bodies and their suppliers; Admiralty B1 from three independent analyses; the "tens of thousands" figure in one vendor's update line is not carried).
Updates (5): Publica / PK Softech (update: the Bernische Pensionskasse's own notice says its supplier is Publica's, the Bernische Lehrerversicherungskasse and Pensionskasse Post report the supplier incident, Inside IT lists two more funds; priority moves routine to notable because cantonal public-law institutions are now directly involved); Zammad (update: 7.2.2 fixes the zammad-to-root escalation on DEB and RPM installs, no-patch leaves the CVE record and the tags, title, headline, summary, actions and the two body paragraphs that said no fix was named were rewritten where they stood); SonicWall SMA1000 CVE-2026-102255 (update: single-source honeypot-operator report of exploitation attempts, success unknown, vendor still says no evidence; the CVE status is deliberately left at patch-available because the exploitation claim rests on one observer, and the Canadian Cyber Centre's update of 2026-10-09 says open source reporting indicates exploitation); PaperCut NG/MF (update; priority moves from critical to high after verifier iteration 2 because the in-window weaponisation the critical bar needs has passed and the delta is not time-critical, with immediate_action cleared: watchTowr's write-up of the bypasses of the emergency builds and CVE-2026-82077, an administrator-only Scan-to-Fax RCE that the vendor's September bulletin lists as fixed only in 26.0.5 and 25.0.13; read from the vendor bulletin, the CVE added to the record and the immediate action reworded); SAP September Patch Day (update, PD-7(d) lookback: Onapsis reports SAPMAP, an open-source toolkit public since 2026-09-15 that carries proof-of-concept exploits for OVERPASS and S4GET; status moves to poc-public; the freshest source, Senthorus of 2026-10-06, sits at the edge of its 96 h lookback and the Onapsis article was published on 2026-09-18 (modified 2026-09-24), so the audit should treat the item as a late recovery of a development the store missed for three weeks).
Source allocation: slices S1 29, S2 19, S3 14, S4 10 records (S1: 14 essential plus 13 rotation plus Citrix and SonicWall PSIRT added by hand; S4's pool was refilled from the previous two fires' attempts because every record in the domain had been attempted in them; 19 records were excluded as recent attempts elsewhere), every record with a ledger row, so no continuation was needed. One scoped follow-up spawn, FU1, took three cross-domain leads S1 and S3 had not researched (GhostAction, P7 DarkSword, NVIDIA DCGM) plus a bounded headline sweep; it returned one item, and the other two leads and the sweep failed the gate.
Backlog work (state/coverage_backlog.md): six open rows were dispositioned under Phase 0 step 5b. Published: MikroTik CVE-2026-84411 (struck with the entry id). Held with the condition and expiry unchanged and no append: IBM MQ and Langflow (expiry 2026-10-11; S1 re-checked: none is in KEV, no exploitation report, no public proof of concept; the next fire strikes it), IBM Guardium CVE-2026-85542 (expiry 2026-10-14; not in KEV, no IBM confirmation), ARA Lyss and Netech (expiry 2026-10-14; S4 re-checked the tracker records, claim-only, no press) and Beyond Gravity (expiry 2026-10-20; S2 found no new technique, actor, vector or BACS/Mandiant statement).
- borderline-drop: Cisco 2026-10-07 security release (NX-OS, APIC, License On-Prem, Meraki, IOS XE): feature-gated or management-plane flaws, Cisco knows of no exploitation, assessed and dropped by two earlier fires; the only new fact is NCSC Switzerland's advisory of 2026-10-09 (post 13044), which restates the vendor bulletin.
- borderline-drop: Veeam Backup & Replication CVE-2025-64393 (KB4934): needs the Backup Viewer role, nothing exploited; NCSC Switzerland advisory of 2026-10-09 is a restatement.
- borderline-drop: Splunk Enterprise CVE-2026-76268 (SVD-2026-1001): CVSS 9.8 but reachable through the Patroni REST API on search head cluster members only (internal cluster interface), versions 10.2.0-10.2.6 and 10.4.0-10.4.2, nothing exploited.
- borderline-drop: AnyDesk for Linux 8.0.2 AnyPwn exploit: Linux-only, probabilistic, tuned to one build, fixed silently in June (no CVE), no exploitation reported.
- borderline-drop: Contao comments-bundle CVE-2026-107845: needs a back-end user to open the Comments module, nothing exploited, no Swiss deployment shown.
- borderline-drop: Ricardo / SMG, 890,000 accounts (names, postal addresses, phone numbers): Swiss but private-sector consumer platform, no vector or actor, no public-sector decision (incident floor).
- borderline-drop: P7 DarkSword iOS exploit kit (iVerify, Censys): the 18.x chains are patched in iOS 18.7.3 and 26.3 and the store's CVE-2026-86950 entry already carries the move to iOS 26.7.1; observed victims are Chinese-language wallet-theft operations.
- borderline-drop: NVIDIA DCGM Exporter CVE-2026-47483: CVSS 8.2 resource-exhaustion DoS, no exploitation, not in KEV.
- borderline-drop: Chrome 155 (no exploited flaw reported), Drupal contrib batch SA-CONTRIB-2026-192 to 217, WordPress 7.1.3, Nextcloud 2026-10-08 bulletins, Keycloak WID-SEC-2026-3849, WatchGuard 22-CVE bundle (CVE-2026-86131 needs control of the remote VPN server), ILIAS fixes, ICS advisories ICSA-26-281-01 to 03 (outside the window, niche): routine, authenticated, unexploited or out of window.
- borderline-drop: Modat and NCSC-NL wind and solar exposure study (8,547 systems): no Swiss or EFTA breakdown in any outlet; FINMA video-identification circular and the Dutch tax authority's M365 pause (S2): bind banks or are sovereignty decisions, no obligation for the constituency.
- out-of-window: the SAPMAP toolkit's Onapsis analysis (published 2026-09-18) is carried only through the PD-7(d) lookback route described above.
- Single-source: the AhsayCBS entry (Huntress is the only observer; BleepingComputer and SecurityWeek relay it,
single-source); the SonicWall exploitation claim (Previdian only, attributed). single-source-national-cert and victim carve-outs: none new. - Contradiction: the patch position on AhsayCBS 10.3.4 (public records imply 10.3.4 is not affected; Huntress says it is affected and has told Ahsay; Ahsay's 10.3.4 release notes list no security fix). The Zammad vendor pages also disagree: the advisory page of 2026-10-05 still says the team is working on a solution while the 7.2.2 release notes and the GitHub advisory of 2026-10-08 describe the fix; the advisory record lists CVE-2026-102490 with 7.2.2 as the patched version and DIVD's case page says the second flaw is fixed in 7.2.2. A third scale conflict is recorded on the GhostAction entry (Socket's "tens of thousands of repositories" against its own 346).
- Coverage gaps: chrome-releases (desktop post unreachable), consilium.europa.eu cyber-sanctions pages (403 on every transport; the sanctions watch ran at snippet depth), blvk.ch and be.ch for the other sub-agents (the Canton of Bern's own release was not located; its content is known through Netzwoche and the BPK notice), ara-lyss.ch (403), swisspost-cybersecurity (no dated posts in the horizon), kommunaler-notbetrieb-de (nothing newer than 2026-09-21).
- Essential-coverage: none missed; every essential record in the four slices was attempted.
- The jina reader served a few S1 and S2 fetches (SonicWall PSIRT pages, one NCSC-NL advisory page that reported the key balance exhausted, blvk.ch);
extract, pdf and the structured recipes covered everything else on this fire. - Candidate sources: two added with their reasons in
sources_changed[]: stepsecurity-blog and zammad-github-advisories. modat was proposed by S3 and not added (one research report in a month, low priority). citrix-netscaler-security-bulletins is promoted to active. - Store observations for the next audit: the SAP September entry went three weeks without the SAPMAP development (see above); the earlier fires' borderline-drops of the Cisco and Veeam items rest on exploitation absence and the Swiss advisories now exist, a third look only if exploitation appears; the Langflow flaws CVE-2026-105697 (unauthenticated on a default-auto-login instance, fixed 1.10.3) and CVE-2026-8505 are in the held IBM MQ row's context and are not in the store.
- Watchlist: none configured (the supplier and product sweeps are no-ops for this deployment).