2026-09-10T0410Z-intel
One pipeline fire, in full · intel run of 2026-09-10 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-10/2026-09-10T0410Z-intel.md.
Run telemetry
- Items returned
- 5
- Duration
- 11m 24s
- Tool calls
- 6 WebFetch11 WebSearch26 bridge
- Cited sources
- 6 of 25 in slice
- Items returned
- 1
- Duration
- 9m 04s
- Tool calls
- 6 WebFetch17 WebSearch14 bridge
- Cited sources
- 1 of 29 in slice
- Items returned
- 3
- Duration
- 11m 57s
- Tool calls
- 4 WebFetch14 WebSearch28 bridge
- Cited sources
- 3 of 14 in slice
- Items returned
- 1
- Duration
- 7m 56s
- Tool calls
- 10 WebFetch18 WebSearch16 bridge
- Cited sources
- 3 of 18 in slice
Verification
Deep dive
·
Entries this run published (5) and updated (5)
- CVE-2026-20079, Cisco Secure Firewall Management Center: unauthenticated authentication bypass to root, unpatched for five months and only exploitable in a post-boot window (CVSS 10.0) vulnerability high update
- CVE-2026-19490, Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed vulnerability high correction
- CVE-2026-82078 / CVE-2026-81578, PaperCut NG/MF: an Apache Tapestry request-routing confusion chains an unauthenticated config rewrite to arbitrary code execution, exploited before a patch existed vulnerability critical update
- Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida incident high update
- Chaotic Eclipse turns its zero-day drops on third-party security products: local privilege escalation in CrowdStrike Falcon and Avast, with working proof-of-concept code public; all three vendors have since remediated vulnerability high update
- CVE-2025-25249, Fortinet FortiOS/FortiSwitchManager: unauthenticated CAPWAP heap overflow added to CISA KEV, actively exploited since July via the PivotC2 RAT vulnerability high
- CVE-2026-87491, Google Chrome: V8 out-of-bounds write exploited in the wild, patched in Chrome 153 (seventh exploited Chrome zero-day of 2026) vulnerability high
- SAP September 2026 Patch Day: OVERPASS (CVE-2026-44756, CVSS 10.0) and S4GET (CVE-2026-58240, CVSS 9.8), two unauthenticated pre-auth RCE flaws in shared SAP kernel components reachable through ports that cannot be firewalled without breaking normal SAP GUI/RFC use vulnerability high
- Check Point Quantum Security Gateway / Management Server / Spark Firewall: two unauthenticated CVSS 9.8 pre-auth RCE flaws in VPN certificate processing (CVE-2026-85103 heap overflow, CVE-2026-85102 improper cert validation) vulnerability high
- BlueMoon: four separate state-nexus actor clusters independently weaponize a shared Chrome V8 + Windows kernel zero-day chain within one week threat high
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
1 fetch_method.
| Source | Change | From → To | Reason |
|---|---|---|---|
| ssd-disclosure | fetch_method | blocked → jina | confirmed reachable via jina fallback by both S1 and S3 this run |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| fortiguard-fortinet-psirt covered via alternate · should NOT be in this list | https://fortiguard.fortinet.com/psirt/FG-IR-25-084 | extract → url → jina | None anti-bot-block direct anti-bot challenge; trafilatura returned no readable body; jina reader relayed an upstream block | corroborated fixed-version data via SentinelOne and SOCRadar's own citations of the advisory |
| tp-link-omada-psirt | https://support.omadanetworks.com/us/security-advisory/ | bridge | 404 url-moved Nuxt app 'page404' response; URL appears to have moved or been retired | flagged in sources.json notes for a future canonical-URL probe; no replacement found this run |
Bridge invocations (this run)
2 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- bridge ×1
- jina ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 7 findings (truth=4, editorial=2, advisory=1) · Claude Sonnet 5 · 9m 31s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat | epss 0.76 was ENISA EUVD's percentage-scaled value copied unconverted; FIRST.org's own API gives 0.00759. | corrected epss to 0.0076 |
| F4 hallucinated-fact | · | cve-2026-87491-chrome-v8-oob-write-seventh-2026-zero-day | epss 0.29 was the same ENISA percentage-vs-decimal conflation; FIRST.org gives 0.00291. | corrected epss to 0.0029 |
| F4 hallucinated-fact | · | entities/registry.yaml tool:hardbreacher (low confidence) | curated summary asserted an unsourced specific patch date (2026-08-31) neither cited source states. | removed the specific date; summary now states Kaspersky's actual fix mechanism (automatic/manual database update) per the sources |
| F3 claim-not-supported | · | bluemoon-exploit-kit-four-state-actors-chrome-windows-chain | cves[CVE-2026-85880].affected omitted Windows 11 21H2 (build 22000), which Proofpoint's own cited table lists as a targeted build; also inconsistent with the referenced 2026-09-09 entry's Microsoft-so | corrected the affected field to Proofpoint's own build table, added a body Contradiction note and a sourcing_note clause flagging (not resolving) the discrepanc |
| F5 missing-citation | · | cve-2026-87491-chrome-v8-oob-write-seventh-2026-zero-day | the ENISA EUVD CVSS 8.8 claim had no inline link and ENISA was not in sources[]. | added ENISA EUVD to sources[] and an inline citation |
| F17 classification | · | cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat (low confidence) | credibility 1 was an outlier, the entry's single-assessor (SOCRadar-only) exploitation narrative matches the pattern this run's other entries (SAP, Check Point, BlueMoon) all rated credibility 2. | corrected credibility to 2; sourcing_note updated to state the single-assessor basis |
| F11 editorial-advisory | · | checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (low confidence) | Forkast News (corroborating role) reads as formulaic aggregator content across unrelated CVEs; facts verified correct. | none, advisory only, role is corroborating and the two Check Point vendor advisories are the solid primaries |
Iteration #2 NEEDS_FIXES · 4 findings (truth=3, editorial=1, advisory=0) · Claude Sonnet 5 · 8m 24s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat (low confidence) | sourcing_note claimed SOCRadar's 9.8 matched neither NVD nor GHSA, but NVD's own analyst score is in fact 9.8 (matching SOCRadar), only the CNA/GHSA score is 8.1. | corrected sourcing_note to state all three scores accurately: NVD 9.8, CNA/GHSA 8.1, ENISA EUVD 7.4 |
| F4 hallucinated-fact | · | cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat | T1055 mapped in techniques[] with no process-injection behavior described in the body, though SOCRadar's own report and ATT&CK table document one (run.ps1 -> OpenProcess/VirtualAllocEx/WriteProcessMem | narrowed T1055 to the source-mapped T1055.002, added T1059.001, and extended the body's pivoting sentence to describe the run.ps1/svchost.exe injection with an |
| F5 missing-citation | · | cve-2026-87491-chrome-v8-oob-write-seventh-2026-zero-day | the CISA KEV due-date clause had no inline citation and CISA was absent from sources[]. | added the CISA alert URL (the same 2026-09-09 four-addition alert already used in the Fortinet entry, since this CVE was one of the four) to sources[] and cited |
| F11 editorial-advisory | · | 2026-08-30/berlin-landesnetz-rhysida-extortion-phishing-vector | three sources[] entries added this run (rbb24, Berlin DPA, and (found on re-inspection) the heise Kommentar) were never used as an inline citation target anywhere in the body; only the main heise arti | removed all three uncited source records, keeping only the inline-cited heise article |
Iteration #3 NEEDS_FIXES · 10 findings (truth=3, editorial=4, advisory=4) · Claude Sonnet 5 · 9m 33s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | cve-2026-87491-chrome-v8-oob-write-seventh-2026-zero-day | iteration 2's own fix cited the CISA alert page for the KEV due date, but that page states no due date at all, only the four added CVE names and BOD 26-04 boilerplate. | added the CISA KEV JSON feed (a per-CVE-queryable data endpoint) as a second source and re-pointed the due-date citation to it; confirmed the 2026-09-23 due dat |
| F3 claim-not-supported | · | 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce (low confidence | GreyNoise's own text says domain admin was reached against '12 victim organizations', not '12 of the 440 instances' as the update section said. | corrected the denominator to the 395 compromised organizations, matching GreyNoise's own wording |
| F4 hallucinated-fact | · | sap-september-2026-overpass-s4get-preauth-rce (low-moderate confidence) | CERT-EU's advisory lists KRNL64NUC only at 7.22/7.22EXT (not 7.53/8.04); only KRNL64UC extends to 7.53/8.04. The entry's condensed notation had merged the two into one range, overstating KRNL64NUC's a | split the affected field into the four component lines exactly as CERT-EU's advisory states them |
| F9 surface-contradiction | · | cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat | GHSA states FortiSASE 25.1.a.2/25.2.b; SentinelOne (also cited as corroborating) independently states FortiSASE 25.1.39/25.1.51, a different version-naming scheme for the same product, carried silentl | added an explicit Contradiction clause to sourcing_note disclosing both version accounts rather than silently following one |
| F10 missed-angle | · | whole-run, entries/2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-h | the same 2026-09-09 CISA alert cited twice this run for other CVEs also added CVE-2026-20079 (Cisco FMC) and CVE-2026-19490 (Citrix NetScaler) to KEV; both already-covered CVEs whose existing entries | CVE-2026-20079 (previously patch-available-only, Cisco reporting no known malicious use): added a type:update record; this is a material exploitation-status cha |
| F17 classification | · | cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat | reliability B overstated the source basis, the substantive narrative rests solely on SOCRadar, which sources.json itself rates reliability C; CISA (A) supports only the KEV-addition fact, not the camp | corrected reliability to C to match SOCRadar's own rated reliability |
| F5 missing-citation | · | cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat | the ENISA EUVD 7.4 temporal-score claim in sourcing_note had no citation and ENISA was not in sources[]. | added ENISA EUVD to sources[] |
| F11 editorial-advisory | · | cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat (low confidence, x2) | T1555 (Credentials from Password Stores) had no distinct supporting behavior beyond the already-present T1552.001; separately, the body's XOR-decryption detail (T1027, Obfuscated Files or Information) | removed T1555, added T1027 |
| F11 editorial-advisory | · | checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (carried forward from iteration 1 | Forkast News re-confirmed as formulaic aggregator content; facts still check out. | none, advisory only, role remains corroborating |
| F11 editorial-advisory | · | 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops (low confid | HardBreacher's session-namespace symlink DLL-load-path redirect may fit T1574.008 better than the mapped T1574.001; verifier itself flagged this as uncertain. | declined; the verifier's own finding was explicitly low-confidence and uncertain between two imperfect-fit sub-techniques, and T1574.001 (DLL search-order/path |
Iteration #4 NEEDS_FIXES · 4 findings (truth=1, editorial=1, advisory=2) · Claude Sonnet 5 · 9m 42s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | bluemoon-exploit-kit-four-state-actors-chrome-windows-chain entities[] tool:ghos | 'GhostChrome' only appears inside a Proofpoint hyperlink's URL slug pointing to Rubrik Zero Labs' own blog (uncited in this entry's sources[]); Proofpoint's own visible text never names the technique, | removed tool:ghostchrome-x from the entry's entities[], from entities_added in the run record, and retired the registry entity entirely; reworded the tool:gemst |
| F6 strengthen-primary-source | · | sap-september-2026-overpass-s4get-preauth-rce (low confidence) | CERT-EU was listed first with role:primary though the entry's own sourcing_note says it only relays SAP/Onapsis's findings; the two genuine Onapsis research-lab primaries sat later in the list. | reordered sources[] so the two Onapsis primaries lead; CERT-EU moved to role:corroborating |
| F11 editorial-advisory | · | checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (carried forward) | Forkast News independently re-confirmed as aggregator content; facts still check out. | none, advisory only |
| F11 editorial-advisory | · | 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops (carried fo | T1574.001 vs T1574.008 uncertainty for HardBreacher re-confirmed as a genuine imperfect-fit case. | none, advisory only, concurs with iteration 3's decline |
Iteration #5 NEEDS_FIXES · 6 findings (truth=2, editorial=1, advisory=3) · Claude Sonnet 5 · 6m 43s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix | the main-analysis paragraph still asserted, present-tense, 'Cisco states it is not aware of any public announcements or malicious use' (unedited by this run's own update despite the record declaring f | edited the stale sentence in place to state Cisco's original position in the past tense and point to the KEV confirmation, resolving the contradiction between t |
| F3 claim-not-supported | · | 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops (+ registry | body, changelog summary, and registry all claimed CrowdStrike's cloud ML detection catches the FalconFlank artifact 'in default configurations' / 'default test conditions', LevelBlue's cited post neve | reworded all three locations (body, changelog record summary, registry summary) to state LevelBlue's own lab testing observed the detection catch and quarantine |
| F5 missing-citation | · | sap-september-2026-overpass-s4get-preauth-rce | the RECON/CVE-2020-6287/CVE-2025-31324 historical-precedent sentence had no inline citation, though its content matches Onapsis's own already-cited OVERPASS post almost verbatim. | added an inline citation to the Onapsis OVERPASS post at the end of the sentence |
| F11 editorial-advisory | · | 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops (low confid | questioned whether the 2026-09-10 changelog record should have been typed improvement (no float) rather than update (floats updated_at), since its content is independent confirmation + deeper mechanis | declined, the record's substance (a second independent lab confirming the findings with materially deeper, actionable detection guidance) is treated as a genuin |
| F11 editorial-advisory | · | checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (carried forward, reconfirmed) | Forkast News re-fetched and re-confirmed as aggregator content; quote still checks out, role remains corroborating. | none, advisory only |
| F11 editorial-advisory | · | 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops (carried fo | T1574.001 vs T1574.008 mapping for HardBreacher re-confirmed as a genuine imperfect-fit case. | none, advisory only, concurs with prior iterations' decline |
Iteration #6 NEEDS_FIXES · 3 findings (truth=1, editorial=0, advisory=2) · Claude Sonnet 5 · 8m 25s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops | LevelBlue's own 'Key Takeaways' section (already cited by this run's update) states both PrettyPrague and FalconFlank had already received vendor remediation as of 2026-09-09 ('prior to remediation' / | updated title, headline, summary, tags (no-patch -> patch-available), body (three sentences reframed to past-tense-at-disclosure plus a forward pointer to the u |
| F11 editorial-advisory | · | checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (carried forward, reconfirmed 4th | Forkast News re-confirmed as aggregator content; new observation that it is entirely unregistered in sources/sources.json and this is its first-ever use in the store. | none, advisory only; not promoted to a tracked source given the repeated aggregator-content characterization |
| F11 editorial-advisory | · | bluemoon-exploit-kit-four-state-actors-chrome-windows-chain (reopens iteration 4 | low-confidence note that iteration 4's removal of tool:ghostchrome-x may have rested on an incomplete source check: The Hacker News (already cited in this entry's sources[]) names 'GhostChrome-X' dire | verified directly against the cited Hacker News article, confirmed it names 'GhostChrome-X' in visible text, properly attributed and linked. Restored tool:ghost |
Iteration #7 NEEDS_FIXES · 4 findings (truth=3, editorial=0, advisory=1) · Claude Sonnet 5 · 5m 56s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | 2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops | the entry's own already-cited primary (The Hacker News) states, in an Update section, an exact named Avast fix (26.7.11086 fix 992 / 26.8.11125 fix 993, released 2026-09-04), but the entry's summary, | rewrote the summary, Defender takeaway, and update-section text to state the named Avast fix versions and date precisely, distinguishing that CrowdStrike/Falcon |
| F4 hallucinated-fact | · | 2026-09-10/bluemoon-exploit-kit-four-state-actors-chrome-windows-chain | actions[] and the Defender takeaway both said 'Chrome ≥153', that is this run's other new entry's (CVE-2026-87491) fix version, not this entry's own CVE-2026-85046 fix version (Chrome 152.0.7977.82/.8 | corrected both instances to 'Chrome ≥152.0.7977.82', matching this entry's own frontmatter. |
| F4 hallucinated-fact | · | entities/registry.yaml tool:prettyprague | registry summary still said 'remediation in development by Gen Digital,' stale relative to the entry it's drawn from now that the entry records a named, shipped Avast fix. | updated the registry summary to state the shipped fix versions and date, citing The Hacker News. |
| F11 editorial-advisory | · | checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (carried forward, reconfirmed 5th | Forkast News re-confirmed as formulaic aggregator content; quoted fact still verbatim-correct. | none, advisory only, role remains corroborating behind two solid Check Point vendor primaries |
Iteration #8 NEEDS_FIXES cap-breach · 4 findings (truth=1, editorial=1, advisory=2) · Claude Sonnet 5 · 7m 25s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | 2026-09-10/bluemoon-exploit-kit-four-state-actors-chrome-windows-chain | the body attached 'is MSRC-confirmed exploited' to The Hacker News citation, but that article states only that the CVE was patched in September Patch Tuesday; it never uses 'MSRC' or states MSRC confi | reworded the clause to state only what the Hacker News citation supports (patched in September Patch Tuesday) and attributed the MSRC exploited-in-the-wild conf |
| F5 missing-citation | · | 2026-08-20/cve-2026-19490-netscaler-gateway-aaa-auth-bypass | cves[CVE-2026-19490].epss: 0.0337 had no supporting source in sources[], the entry's only FIRST.org EPSS citation is scoped to CVE-2026-19489. Figure independently re-verified correct against FIRST.or | added a FIRST.org EPSS source entry scoped to CVE-2026-19490, folded into this run's existing 2026-09-10 correction record (fields[] extended to include sources |
| F11 editorial-advisory | · | cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat | the SentinelOne CVE-database page used as a corroborating source for the FortiSASE version contradiction carries an explicit AI-generated-content disclaimer and is a different site section from the re | none, advisory only, facts independently reconfirmed correct |
| F11 editorial-advisory | · | checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (carried forward, reconfirmed 6th | Forkast News re-confirmed as formulaic aggregator content; quoted fact still verbatim-correct. | none, advisory only, role remains corroborating behind two solid Check Point vendor primaries |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-10T0410Z-intel · Sonnet 5 · window 24 h · 5 entries published
Verification & coverage notes
Intraday fire (gap_hours 10.72, window_hours 24 floor). Mechanical KEV sweep (tools/kev_window_diff.py) flagged 2 not-yet-covered CISA KEV additions in-window (CVE-2025-25249 Fortinet, CVE-2026-87491 Chrome); both fully researched and published as new entries. 5 new entries, 3 changelog updates.
- borderline-drop: Veradigm (formerly Allscripts) vendor-API credential breach, US-domiciled healthcare-technology vendor, disputed scale (victim's own SEC 8-K says "a small number of customers" against the actor's claimed 3.5M records); the actor (
actor:thegentlemen) carries an established European leak-site pattern and an uncorroborated current Swiss claim (Ixa Systems SA, tracked in coverage_backlog.md), but neither that actor-nexus argument nor the vendor-API-scoping lesson (standard practice, not a novel TTP) clears the stricter out-of-nexus breach gate on their own. Relevance-doubt resolves toward drop (v4.2). - borderline-drop: Mantax Otax, Indonesian consumer Android ransomware/spyware hybrid (Zimperium zLabs, single-source). No Swiss/EU/public-sector nexus; the constituency's device fleets are MDM-managed, making a sideload-only consumer-Android technique class a poor transferability fit. Does not clear PD-11(d).
- Coverage backlog (state/coverage_backlog.md) worked this run: Boston Scientific struck (operationally concluded, "fully restored," no mechanism ever disclosed across 10 checks over two weeks); Zurich verdict, inside-it.ch Insel Gruppe, Ixa Systems SA, UICC (Krybit), Kairos/Ville de Libercourt, VMware VMSA-2026-0007, and the Spring Ring NTLM-relay row all re-checked with no change; dated notes appended to each. Three new backlog rows opened: Medela AG (ShinyHunters claim, Swiss home-region, uncorroborated), reichenau.at (SafePay claim, Austrian municipality, uncorroborated), and Ville du Tampon (France, victim-confirmed incident, no mechanism disclosed).
- Dedup:
2026-09-10/bluemoon-exploit-kit-four-state-actors-chrome-windows-chainshares CVE-2026-85046 with2026-09-04/cve-2026-85046-chrome-v8-type-confusion-exploitedand CVE-2026-85880 with2026-09-09/windows-september-2026-two-exploited-lpe-zero-days-kev, both declared inreferences[]as a genuinely distinct finding (a named exploit kit + four actor clusters) building on the covered CVEs, not a duplicate. - Watchlist: no watchlists configured (documented no-op on all four domains).
- Essential-coverage: cisa-advisories 403'd for a 2nd consecutive run (transport block, never demotes;
tools/fetch_source.pybridge already in use). - Coverage gaps: ccb-belgium (fetched, advisory list not confirmed present/absent); reliaquest, group-ib, ibm-xforce (all reached, newest content outside the 24h window); ransom-isac, venarix, zaufana-trzecia-strona, cyberinsider (all reached, no in-window content).
← Operations dashboard · run-record contract: docs/pipeline.md