CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
‹Sat · 10 Oct 2026
All daily briefs →
Daily brief · UTC day

Saturday, 10 October 2026

3 verified findings from 1 run · 5 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01GhostAction: fake security workflows now harvest whole git histories; rotating Actions secrets is not enough. StepSecurity and Socket report that on 2026-10-08 the GhostAction campaign used the GitHub credentials of two open-source maintainers to commit a workflow disguised as a security audit straight to the default branch of 345 to 346 repositories, including one of an Uber-owned organisation, and that the workflow now sends the credentials found in the working tree and in the entire git history, besides the named Actions secrets, to a hardcoded address over plain HTTP. StepSecurity read a run log showing the exfiltration was acknowledged four seconds after the run started; no malicious package release from the stolen credentials has been seen yet. →
  2. 02Huntress: AhsayCBS flaws are exploited for SYSTEM-level code execution, and 10.3.4 is also affected. Huntress observed from 2026-10-07 23:20 UTC attackers chaining two AhsayCBS flaws, CVE-2026-105133 (authentication bypass) and CVE-2026-105134 (code execution as SYSTEM through the Replication Receiver API), against internet-exposed servers of the backup management console that managed service providers and system integrators mainly use, dropping JSP webshells and an XMRig cryptominer; BleepingComputer reports at least five organizations targeted and a public exploit for the first flaw. Public records listed versions up to 10.3.2 as affected, but Huntress found on 2026-10-08 that 10.3.4, which BleepingComputer calls the latest version, is also affected, and no fixed release is named, so restricting the management interface is the interim control. →

01Active threats, incidents & disclosures1 item

NOTABLENATOB1

GhostAction returns: stolen maintainer credentials push a fake security-audit workflow into the victims' own GitHub repositories, which now harvests credentials from the entire git history

StepSecurity reports that on 2026-10-08 the GhostAction GitHub Actions credential-theft campaign used the accounts of two open-source maintainers to push a workflow disguised as a security improvement to 345 repositories in two automated sweeps, among them an Uber-owned repository that one maintainer could still write to (StepSecurity, 2026-10-09); Socket's independent analysis counts 346 (Socket, 2026-10-09). The operator holds a maintainer's GitHub credential, which StepSecurity assesses as most plausibly a personal access token leaked through infostealer logs or credential dumps, then commits a workflow titled to look like a security audit straight to the default branch under the victim's own identity, unsigned and without a pull request; that push runs it, and nothing in an audit log looks anomalous unless the content is read (StepSecurity, 2026-10-09). GitGuardian says the technique was later reused in the Shai-Hulud campaigns and remains at the core of the Mini Shai-Hulud malware family (GitGuardian, 2026-10-07).

The newer payload sends the named Actions secrets and every cloud, AI-provider and SaaS credential pattern found in the working tree and the entire git history to a hardcoded address over plain HTTP, so no DNS lookup occurs (StepSecurity, 2026-10-09). StepSecurity saw the attacker's server acknowledge the request four seconds into the run at the Uber-owned repository (StepSecurity, 2026-10-09); neither it nor Socket has seen a malicious package release from the stolen credentials yet (Socket, 2026-10-09; StepSecurity, 2026-10-09). A Socket update line claims more than 500 accounts and tens of thousands of repositories since 7 October without a method, against 346 for the 8 October burst in its own body and 378 live-workflow repositories across all waves in StepSecurity's code search of 2026-10-09, so the larger figure stays unconfirmed (Socket, 2026-10-09; StepSecurity, 2026-10-09).

Triage: the audit-log pattern separates this from a team adding a scanning workflow: no pull request, unsigned commits across many repositories, and a manual dispatch right after creation (StepSecurity, 2026-10-09).

confirms the exfiltration completed successfully: the attacker's server acknowledged receipt four seconds after the workflow started

Nothing in an audit log looks anomalous unless the workflow content itself is inspected

The approval gate is worth singling out: it is the single control observed stopping this campaign's exfiltration this week.

StepSecurity 2026-10-09

Socket has observed no malicious package versions published to PyPI or crates.io as a result of this activity at the time of writing.

Socket 2026-10-09

Rotating the secrets exfiltrated by the malicious workflow is not enough. The GitHub credential that allowed the injection in the first place must be found and revoked too, or someone else will use it again.

GitGuardian 2026-10-07

Builds on: CloudSEK: a Gentlemen affiliate reached victims through stolen GitLab CI/CD secrets and drove… · Megalodon mass-poisons 5,561 GitHub repos in a 6-hour window; SysDiag + Optimize-Build…

threat10 Oct 03:52Zmulti-sourceOpen finding →
NOTABLECVE-2026-105133 +1exploitedNATOB2

CVE-2026-105133 / CVE-2026-105134, AhsayCBS backup management console: an unauthenticated authentication-bypass and code-execution chain exploited since 7 October to drop webshells and a cryptominer, with 10.3.4 also affected and no fixed release named

Huntress reports that from 2026-10-07 23:20 UTC attackers exploited two flaws in AhsayCBS, the management console of Ahsay's backup software that managed service providers and system integrators mainly use, to gain unauthenticated remote code execution and deploy webshells on exposed servers (Huntress, 2026-10-08). CVE-2026-105133, an improper-authentication flaw in the checkSysPwd function of the API, is used first to bypass authentication; CVE-2026-105134, in the /rps/api/json/UpdateReceivers.do endpoint of the Replication Receiver component, then gives code execution as NT AUTHORITY\SYSTEM, after which the attacker configured a malicious receiver and dropped a JSP webshell into the directory the application serves (Huntress, 2026-10-08). BleepingComputer reports that the activity targeted at least five organizations on 7 October and that CVE-2026-105133 has a public exploit (BleepingComputer, 2026-10-09).

Follow-on activity, per Huntress: commands spawned by the AhsayCBS service process fetch payloads over HTTP from cloud object storage into a Temp folder with curl and certutil; an XMRig Monero miner renamed to look like a Microsoft Edge binary runs as SYSTEM through a service that mimics the Edge updater and a renamed copy of the NSSM service manager, and reaches its mining pool on a non-standard port; and a PowerShell script that Huntress assesses as AI-assisted checks whether Task Manager is running, uses the host's local time to decide when to close it, and stops the miner while it is open (Huntress, 2026-10-08). The patch position is contested: public records listed AhsayCBS up to 10.3.2 as affected (SecurityWeek, 2026-10-09), while Huntress's update of 2026-10-08 says 10.3.4 is also affected, that it has told Ahsay, and that owners should restrict the management interface until a patch is available (Huntress, 2026-10-08), and BleepingComputer calls 10.3.4 the latest version (BleepingComputer, 2026-10-09); Ahsay's release notes for 10.3.4 list no security fix (Ahsay, 2026-08-05).

Triage: AhsayCBS legitimately spawns its own startup and maintenance commands, so a child process alone is weak; the discriminators Huntress gives are a child of the service that downloads files into a Temp folder, and an Edge-named binary run as SYSTEM from a Temp folder under a service that mimics the Edge updater (Huntress, 2026-10-08).

Starting 2026-10-07 23:20:15 UTC, Huntress observed threat actors exploiting the vulnerabilities to gain unauthenticated remote code execution and deploy webshells on exposed systems.

After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities.

Until a patch is available, we recommend restricting access to the management interface and investigating for signs of compromise.

Huntress 2026-10-08

The malicious activity was observed on October 7, and targeted at least five organizations.

BleepingComputer 2026-10-09
vulnerability10 Oct 03:51Zsingle-sourceOpen finding →
ROUTINECVE-2026-84411NATOA2

CVE-2026-84411, MikroTik RouterOS: one unauthenticated request to the web management service can run code as root; 7.24 fixes the v7 stable channel and the long-term releases are pending (CVSS 3.1 9.8)

MikroTik's notice of 2026-10-06 describes an integer underflow in HTTP request body handling of the RouterOS web management service, the service behind WebFig on the www and www-ssl ports: a single specially crafted request sent without logging in could crash the service or let an attacker execute code on the router with full privileges, and MikroTik rates the flaw critical as CVE-2026-84411 (MikroTik, 2026-10-06). CISA's advisory ICSA-26-272-06 describes the same flaw as reachable before authentication, scores it CVSS 3.1 9.8 and records no known public exploitation reported to it (CISA, 2026-09-30). RouterOS versions before 7.24, v6 included, are affected on devices where the attacker can reach the web interface; 7.24 fixes the v7 stable channel, while the v7 long-term and v6 long-term releases were still pending when MikroTik wrote (MikroTik, 2026-10-06). BleepingComputer notes that hackers and botnet malware often target MikroTik flaws and recalls a recent CERT Polska warning of an exploit chain against devices with SSH exposed to the internet (BleepingComputer, 2026-09-30).

A single specially crafted HTTP request, sent without logging in, could crash the service or allow an attacker to execute code on the router with full privileges.

Note that in the default configuration the firewall already blocks the web interface from the internet, so a device with default firewall rules is only reachable from the local network.

v7 long-term - release pending

MikroTik

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.

CISA

Builds on: CERT Polska confirms active exploitation of an unauthenticated SSH takeover chain against…

vulnerability10 Oct 03:50Zmulti-sourceOpen finding →

03Updates to prior coverage5 items

NOTABLEupdatedNATOA2

PK Softech, software supplier of Swiss pension funds: malware and a data outflow at Publica, with the Bernese funds BPK and BLVK and Pensionskasse Post also reporting the supplier incident, and the Federal Prosecutor's Office investigating

First published 2026-10-09 · open finding →

Updaterun 2026-10-10T0255Z-inteltitleheadlinesummaryprioritysourcesevidencesourcing_noteactionsbody

The supplier's customers are now named: the Bernische Pensionskasse (canton of Bern staff and three cantonal universities) says its supplier is the same company that serves Publica, the Bernische Lehrerversicherungskasse and Pensionskasse Post report the supplier incident, and Inside IT lists Migros-Pensionskasse and Syngenta Pensionskasse among the customers. None of the funds has confirmed which member data left.

The supplier's customer base is now partly public and includes cantonal-level institutions. The Bernische Pensionskasse (BPK) states in a notice dated 2026-10-09 that an external software supplier of the BPK suffered a cyberattack at the end of September 2026 and that this is "the same company that also supplies the federal pension fund Publica" (translated from German); the supplier filed a criminal complaint, informed the relevant federal bodies and its affected customers, various federal bodies are clarifying with it which data is affected, and the Federal Prosecutor's Office has opened an investigation (BPK, 2026-10-09). The BPK says there are currently no indications that its data was stolen but that this cannot be entirely excluded, and that insured persons are being informed (BPK, 2026-10-09). Netzwoche reports that the Canton of Bern's own notice names the BPK and the Bernische Lehrerversicherungskasse (BLVK) as concretely affected, that the BPK insures canton staff and the personnel of the three cantonal universities (42,145 active insured and 18,321 pensioners on 31 December 2025) and that the BLVK insures 21,417 active Bernese teachers (Netzwoche, 2026-10-08). The BLVK's own notice does not name its supplier; it says the supplier took the affected environment off the network, brought in external specialists, informed the authorities and filed a criminal complaint, and that the supplier and the BLVK are still checking whether and to what extent BLVK data is affected (BLVK, 2026-10-08). Pensionskasse Post, the occupational pension fund of Swiss Post, names PK Softech and says whether and to what extent its insured persons' data is affected is under review; it states that its data at PK Softech is anonymised and holds no particularly sensitive personal data such as IV disability-insurance files, a claim that is the fund's own and not independently verified (Pensionskasse Post, 2026-10-09). Inside IT, working from the AWP agency, lists the BLVK, the BPK, Migros-Pensionskasse, Pensionskasse Post and Syngenta Pensionskasse as customers of the manufacturer "among others" and says each is checking with PK Softech for a possible data outflow (Inside IT, 2026-10-09). PK Softech says it has been fully available to its customers again since 2 October 2026 (PK Softech, 2026-10-08). The access vector, the actor, which data belongs to which fund and whether a ransom was demanded are still not public in any source read.

HIGHCVE-2026-44756 +1updatedNATOB2

SAP September 2026 Patch Day: OVERPASS (CVE-2026-44756, CVSS 10.0) and S4GET (CVE-2026-58240, CVSS 9.8), two unauthenticated pre-auth RCE flaws in shared SAP kernel components reachable through ports that cannot be firewalled without breaking normal SAP GUI/RFC use

First published 2026-09-10 · open finding →

Updaterun 2026-10-10T0255Z-intelsummarytagscvessourcesevidenceactionssourcing_notebody

An open-source SAP exploitation toolkit, SAPMAP, publicly released on 2026-09-15, carries proof-of-concept exploits for both flaws, including OVERPASS exploits that the maintainers first said they were withholding. Onapsis had not observed attackers using it when it wrote, and no exploitation is reported. The OVERPASS routes were re-cited to Onapsis and an unsupported discriminator in the triage line was removed.

Onapsis Research Labs reports that on 2026-09-15 a group of researchers publicly released SAPMAP, an open-source (GPL 3.0) SAP discovery and exploitation toolkit that contains proof-of-concept exploits for both flaws, alongside ten standalone pre-authentication exploit files, post-authentication modules including an SAP ransomware proof of concept, and an automation loop that chains scanning, exploitation, enrichment and propagation (Onapsis, 2026-09-18). The maintainers first indicated that the OVERPASS exploits were being withheld, but Onapsis found them in the repository commits, says every clone since the original publication includes them and tells defenders to assume the OVERPASS proofs of concept are public (Onapsis, 2026-09-18). Onapsis had not observed threat actors using the toolkit when it wrote, and notes that public proof-of-concept releases can often jumpstart attack campaigns within days or weeks (Onapsis, 2026-09-18). Senthorus assesses on 2026-10-06 that packaging the capabilities together could reduce the preparation an intrusion needs, and separates that from evidence of use, which would need incident reporting (Senthorus, 2026-10-06). No source read reports exploitation of either flaw, and the fixes are unchanged: SAP Security Notes 3747649 and 3759472.

HIGHCVE-2026-81578 +2exploitedupdatedNATOB1

CVE-2026-82078 / CVE-2026-81578, PaperCut NG/MF: an Apache Tapestry request-routing confusion chains an unauthenticated config rewrite to arbitrary code execution, exploited before a patch existed

First published 2026-08-29 · open finding →

Updaterun 2026-10-10T0255Z-intelprioritysummaryimmediate_actiontagscvesactionssourcesevidencesourcing_notebody

watchTowr published on 2026-10-09 how the emergency patches were bypassed in turn: the 28 August emergency build could still be taken without authentication through the Setup Wizard forms, and a new administrator-only Scan-to-Fax code-execution flaw, CVE-2026-82077, is fixed only in 26.0.5 and 25.0.13, not in the emergency builds. No source names exploitation of either, though PaperCut says Emergency Patch Release 3 closes off further attack vectors it has seen exploited. Earlier statements the cited sources do not support were corrected where they stood: the 2023 precedent, the university-customer statement, the emergency-patch chronology and the detection wording.

watchTowr Labs published a write-up on 2026-10-09 that follows the emergency patches build by build (watchTowr, 2026-10-09). Its timeline: the patch released on 28 August (26.0.4-PO build 76508) fixed two bypasses watchTowr had reported; watchTowr then bypassed the fix for the authentication bypass again (tracked internally as WT-2026-0143, no CVE assigned) and found a new post-authentication code-execution flaw in Scan-to-Fax (WT-2026-0144, now CVE-2026-82077), which together gave a full unauthenticated chain against build 76508; the patch released on 1 September (build 76530) fixes WT-2026-0143, and 26.0.5, released on 10 September, fixes CVE-2026-82077 (watchTowr, 2026-10-09). The authentication bypass abuses the Setup Wizard forms, which the earlier patches had ignored: every stage can be reached through the Home page even after setup is complete, and watchTowr shows it modifies the administrator password (watchTowr, 2026-10-09). watchTowr also publishes a Detection Artefact Generator that tests a server's exposure to the authentication bypasses but does not run the full chain (watchTowr, 2026-10-09).

PaperCut's September security bulletin lists CVE-2026-82077 as a code-execution flaw in the Scan-to-Fax component that needs an authenticated administrator, rated CVSS 4.0 7.3, fixed in 26.0.5 and 25.0.13, and says servers already on the latest release are covered (PaperCut Software, 2026-09-24); it names no 24.x release and no emergency build. The unauthenticated chain watchTowr describes is closed by the 1 September patch, but an administrator-level foothold still reaches code execution through Scan-to-Fax until the maintenance release is installed. No source names exploitation of CVE-2026-82077 or of the Setup Wizard bypass. PaperCut says Emergency Patch Release 3 closes off additional attack vectors it has observed being exploited in the wild, without naming them (PaperCut Software, 2026-09-10).

HIGHCVE-2026-102255 +3updatedNATOA2

CVE-2026-102255, SonicWall SMA1000: a third unauthenticated CVSS 10.0 Work Place SSRF this year, affecting the hotfix builds that closed the September zero-days, with exploitation attempts reported that SonicWall has not confirmed

First published 2026-10-08 · open finding →

Updaterun 2026-10-10T0255Z-inteltitleheadlinesummarysourcesevidencesourcing_noteactionsbody

Previdian, a honeypot operator, reported exploitation attempts against CVE-2026-102255 on 2026-10-09, three days after the patch: crafted OPTIONS requests to the Work Place interface that try to reach the appliance's internal CouchDB service. Previdian has not established whether any attempt would have compromised a system, and SonicWall's advisory still says it has no evidence of exploitation.

Previdian, which runs a honeypot network, told BleepingComputer on 2026-10-09 that its sensors had detected exploitation attempts consistent with CVE-2026-102255, three days after the patch (BleepingComputer, 2026-10-09). The requests targeted the Work Place Extraweb interface with a crafted OPTIONS request meant to reach the appliance's internal CouchDB service on the loopback address, port 5984, traverse into a design document and invoke its _rewrite function while carrying an HTTP Basic Authorization header with a default-style administrator credential (BleepingComputer, 2026-10-09). Previdian's page counts 135 attempts from two source addresses between 2026-10-09 and 2026-10-10 (Previdian, 2026-10-10). Previdian has not established whether any of the attempts would have compromised a system (BleepingComputer, 2026-10-09), and SonicWall's advisory, as of 2026-10-10, still says there is currently no evidence that any of the flaws in the release is exploited (SonicWall PSIRT, 2026-10-06), so Previdian is the only observer named in the sources read; the Canadian Centre for Cyber Security's bulletin AV26-1017, updated on 2026-10-09, now says open source reporting indicates the flaw is being exploited in the wild without naming it (Canadian Cyber Centre, 2026-10-07). BleepingComputer adds that the product is often targeted because managed service providers, large corporations and government agencies use it for VPN access to internal applications, and that Shadowserver tracks more than 400 exposed SMA1000 appliances, a count that includes some that may be honeypots or already patched (BleepingComputer, 2026-10-09).

HIGHCVE-2026-102489 +1exploitedupdatedNATOA2

CVE-2026-102489 / CVE-2026-102490, Zammad helpdesk: a session-hijack remote code execution and a zammad-to-root escalation, both reported exploited since 21 September; 7.2.2 fixes the root flaw on DEB and RPM installs

First published 2026-10-02 · open finding →

Updaterun 2026-10-10T0255Z-inteltitleheadlinesummarytagscvessourcesevidencesourcing_noteactionsbody

Zammad 7.2.2 (2026-10-08) fixes the local escalation from the zammad account to root that no vendor fix covered before, in DEB and RPM (packager.io) installations only; installations from source and the official container images were never affected. The exploited code-execution flaw and its public exploit are unchanged.

Zammad released 7.2.2 on 2026-10-08 as an important security update that addresses a vulnerability affecting only DEB and RPM packages built with packager.io; SaaS customers need take no action and self-hosted installations are told to upgrade immediately (Zammad, 2026-10-08). Its GitHub advisory GHSA-p97w-927q-8vxq describes a local privilege escalation to root: services started as root and executed files that the unprivileged zammad account owned and could write before dropping privileges, and that account could write to the installation directory, so an attacker already running code as zammad could have reached root within seconds because the services restarted automatically whenever they stopped; installations from source or the official container images were not affected and every released packaged version was (Zammad advisory GHSA-p97w-927q-8vxq, 2026-10-08). The advisory record lists CVE-2026-102490, names 7.2.2 as the patched version and versions up to 7.2.1 as vulnerable (Zammad advisory GHSA-p97w-927q-8vxq, 2026-10-08), and DIVD's case page says Zammad has fixed the first flaw in release 7.2 and the second in release 7.2.2 (DIVD CSIRT, 2026-10-09). Zammad's advisory page of 2026-10-05 still says its team is working on a solution (Zammad, 2026-10-05), so the vendor's own pages disagree on status. Nothing changes for the code-execution flaw: it stays exploitable only on 6.5 and older, which receive no security fixes.

04Action items14 items

Verification & coverage notes1 run

2026-10-10T0255Z-intel · Sonnet 5.5 · window 26 h · 3 entries published

Verification & coverage notes

Coverage window: standard fire. The previous intel fire started 2026-10-09T02:55:59Z, so gap_hours=24.0 and window_hours=26; the developing-story window was 72 hours. The clock cross-check against the network date agreed (skew 0 s) and the fresh fetch showed the newest run record of 2026-10-09T0255Z.

Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found no KEV addition since 2026-10-09 (catalog 2026.10.08, released 2026-10-08T20:09Z; the five old CVEs added on 2026-10-08 are inside the AA26-281A entry) and no RANSOMWARE row. S1 confirmed it through the cisa-kev recipe and found no ransomware-flag flip on a covered CVE. The 2026-10-10 re-read of the catalogue shows none of CVE-2026-84411, -102255, -105133, -105134 or -82077 listed. No scheduled multi-product release fell in the window (Microsoft, SAP and Fortinet on 2026-10-13, Oracle on 2026-10-20, Cisco on 2026-10-21).

Verification: five cold iterations, each a fresh cti-verification pass over the full ledger (204 to 214 claims, all checked). Iterations 1 to 4 returned NEEDS_FIXES (truth 20, 7, 5 and 4; editorial 5, 2, 2 and 1) and every truth finding was remediated and re-checked by the next pass. Iteration 5 returned NEEDS_FIXES with truth 0 and editorial 2 (both F8: a third disguise name missing from the GhostAction hunt scope, an Exposure line missing from the SAP entry) and no F1 or F4, so the low-residual early exit applies: both were fixed after the pass and the run publishes without a sixth iteration. The residual count is the final iteration's two editorial findings. Standing advisories, unfixed on purpose: em dashes in older PaperCut and SAP text this fire did not touch, and the missing Exposure line on the PaperCut entry.

New entries (3):

  • MikroTik RouterOS CVE-2026-84411 (vulnerability, routine after verifier iteration 1; pre-auth web-management RCE, MikroTik's own notice now names the fix; PD-11(b) on its own mechanics, a single unauthenticated request to root on an edge router class that botnets target, with the default firewall keeping the interface off the internet and no exploitation, which holds it at routine; resolves the backlog row).
  • AhsayCBS CVE-2026-105133 / CVE-2026-105134 (vulnerability, notable; exploited from 2026-10-07 with webshells and a miner, 10.3.4 also affected and no fixed release named; PD-11(b); the nexus is the managed-service-provider and integrator class that serves public bodies, so it is notable and not high; single-source on Huntress, Admiralty B2).
  • GhostAction (threat, notable; stolen maintainer credentials, confirmed exfiltration at an Uber-owned repository, history-wide credential sweep that makes secret rotation insufficient; PD-11(a) and (d): an organisation-scoped search and an audit-log query take minutes; no public-sector victim is named, the ground is GitHub-hosted developer estates of public bodies and their suppliers; Admiralty B1 from three independent analyses; the "tens of thousands" figure in one vendor's update line is not carried).

Updates (5): Publica / PK Softech (update: the Bernische Pensionskasse's own notice says its supplier is Publica's, the Bernische Lehrerversicherungskasse and Pensionskasse Post report the supplier incident, Inside IT lists two more funds; priority moves routine to notable because cantonal public-law institutions are now directly involved); Zammad (update: 7.2.2 fixes the zammad-to-root escalation on DEB and RPM installs, no-patch leaves the CVE record and the tags, title, headline, summary, actions and the two body paragraphs that said no fix was named were rewritten where they stood); SonicWall SMA1000 CVE-2026-102255 (update: single-source honeypot-operator report of exploitation attempts, success unknown, vendor still says no evidence; the CVE status is deliberately left at patch-available because the exploitation claim rests on one observer, and the Canadian Cyber Centre's update of 2026-10-09 says open source reporting indicates exploitation); PaperCut NG/MF (update; priority moves from critical to high after verifier iteration 2 because the in-window weaponisation the critical bar needs has passed and the delta is not time-critical, with immediate_action cleared: watchTowr's write-up of the bypasses of the emergency builds and CVE-2026-82077, an administrator-only Scan-to-Fax RCE that the vendor's September bulletin lists as fixed only in 26.0.5 and 25.0.13; read from the vendor bulletin, the CVE added to the record and the immediate action reworded); SAP September Patch Day (update, PD-7(d) lookback: Onapsis reports SAPMAP, an open-source toolkit public since 2026-09-15 that carries proof-of-concept exploits for OVERPASS and S4GET; status moves to poc-public; the freshest source, Senthorus of 2026-10-06, sits at the edge of its 96 h lookback and the Onapsis article was published on 2026-09-18 (modified 2026-09-24), so the audit should treat the item as a late recovery of a development the store missed for three weeks).

Source allocation: slices S1 29, S2 19, S3 14, S4 10 records (S1: 14 essential plus 13 rotation plus Citrix and SonicWall PSIRT added by hand; S4's pool was refilled from the previous two fires' attempts because every record in the domain had been attempted in them; 19 records were excluded as recent attempts elsewhere), every record with a ledger row, so no continuation was needed. One scoped follow-up spawn, FU1, took three cross-domain leads S1 and S3 had not researched (GhostAction, P7 DarkSword, NVIDIA DCGM) plus a bounded headline sweep; it returned one item, and the other two leads and the sweep failed the gate.

Backlog work (state/coverage_backlog.md): six open rows were dispositioned under Phase 0 step 5b. Published: MikroTik CVE-2026-84411 (struck with the entry id). Held with the condition and expiry unchanged and no append: IBM MQ and Langflow (expiry 2026-10-11; S1 re-checked: none is in KEV, no exploitation report, no public proof of concept; the next fire strikes it), IBM Guardium CVE-2026-85542 (expiry 2026-10-14; not in KEV, no IBM confirmation), ARA Lyss and Netech (expiry 2026-10-14; S4 re-checked the tracker records, claim-only, no press) and Beyond Gravity (expiry 2026-10-20; S2 found no new technique, actor, vector or BACS/Mandiant statement).

  • borderline-drop: Cisco 2026-10-07 security release (NX-OS, APIC, License On-Prem, Meraki, IOS XE): feature-gated or management-plane flaws, Cisco knows of no exploitation, assessed and dropped by two earlier fires; the only new fact is NCSC Switzerland's advisory of 2026-10-09 (post 13044), which restates the vendor bulletin.
  • borderline-drop: Veeam Backup & Replication CVE-2025-64393 (KB4934): needs the Backup Viewer role, nothing exploited; NCSC Switzerland advisory of 2026-10-09 is a restatement.
  • borderline-drop: Splunk Enterprise CVE-2026-76268 (SVD-2026-1001): CVSS 9.8 but reachable through the Patroni REST API on search head cluster members only (internal cluster interface), versions 10.2.0-10.2.6 and 10.4.0-10.4.2, nothing exploited.
  • borderline-drop: AnyDesk for Linux 8.0.2 AnyPwn exploit: Linux-only, probabilistic, tuned to one build, fixed silently in June (no CVE), no exploitation reported.
  • borderline-drop: Contao comments-bundle CVE-2026-107845: needs a back-end user to open the Comments module, nothing exploited, no Swiss deployment shown.
  • borderline-drop: Ricardo / SMG, 890,000 accounts (names, postal addresses, phone numbers): Swiss but private-sector consumer platform, no vector or actor, no public-sector decision (incident floor).
  • borderline-drop: P7 DarkSword iOS exploit kit (iVerify, Censys): the 18.x chains are patched in iOS 18.7.3 and 26.3 and the store's CVE-2026-86950 entry already carries the move to iOS 26.7.1; observed victims are Chinese-language wallet-theft operations.
  • borderline-drop: NVIDIA DCGM Exporter CVE-2026-47483: CVSS 8.2 resource-exhaustion DoS, no exploitation, not in KEV.
  • borderline-drop: Chrome 155 (no exploited flaw reported), Drupal contrib batch SA-CONTRIB-2026-192 to 217, WordPress 7.1.3, Nextcloud 2026-10-08 bulletins, Keycloak WID-SEC-2026-3849, WatchGuard 22-CVE bundle (CVE-2026-86131 needs control of the remote VPN server), ILIAS fixes, ICS advisories ICSA-26-281-01 to 03 (outside the window, niche): routine, authenticated, unexploited or out of window.
  • borderline-drop: Modat and NCSC-NL wind and solar exposure study (8,547 systems): no Swiss or EFTA breakdown in any outlet; FINMA video-identification circular and the Dutch tax authority's M365 pause (S2): bind banks or are sovereignty decisions, no obligation for the constituency.
  • out-of-window: the SAPMAP toolkit's Onapsis analysis (published 2026-09-18) is carried only through the PD-7(d) lookback route described above.
  • Single-source: the AhsayCBS entry (Huntress is the only observer; BleepingComputer and SecurityWeek relay it, single-source); the SonicWall exploitation claim (Previdian only, attributed). single-source-national-cert and victim carve-outs: none new.
  • Contradiction: the patch position on AhsayCBS 10.3.4 (public records imply 10.3.4 is not affected; Huntress says it is affected and has told Ahsay; Ahsay's 10.3.4 release notes list no security fix). The Zammad vendor pages also disagree: the advisory page of 2026-10-05 still says the team is working on a solution while the 7.2.2 release notes and the GitHub advisory of 2026-10-08 describe the fix; the advisory record lists CVE-2026-102490 with 7.2.2 as the patched version and DIVD's case page says the second flaw is fixed in 7.2.2. A third scale conflict is recorded on the GhostAction entry (Socket's "tens of thousands of repositories" against its own 346).
  • Coverage gaps: chrome-releases (desktop post unreachable), consilium.europa.eu cyber-sanctions pages (403 on every transport; the sanctions watch ran at snippet depth), blvk.ch and be.ch for the other sub-agents (the Canton of Bern's own release was not located; its content is known through Netzwoche and the BPK notice), ara-lyss.ch (403), swisspost-cybersecurity (no dated posts in the horizon), kommunaler-notbetrieb-de (nothing newer than 2026-09-21).
  • Essential-coverage: none missed; every essential record in the four slices was attempted.
  • The jina reader served a few S1 and S2 fetches (SonicWall PSIRT pages, one NCSC-NL advisory page that reported the key balance exhausted, blvk.ch); extract, pdf and the structured recipes covered everything else on this fire.
  • Candidate sources: two added with their reasons in sources_changed[]: stepsecurity-blog and zammad-github-advisories. modat was proposed by S3 and not added (one research report in a month, low priority). citrix-netscaler-security-bulletins is promoted to active.
  • Store observations for the next audit: the SAP September entry went three weeks without the SAPMAP development (see above); the earlier fires' borderline-drops of the Cisco and Veeam items rest on exploitation absence and the Swiss advisories now exist, a third look only if exploitation appears; the Langflow flaws CVE-2026-105697 (unauthenticated on a default-auto-login instance, fixed 1.10.3) and CVE-2026-8505 are in the held IBM MQ row's context and are not in the store.
  • Watchlist: none configured (the supplier and product sweeps are no-ops for this deployment).