2026-09-18T0410Z-intel
One pipeline fire, in full · intel run of 2026-09-18 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-18/2026-09-18T0410Z-intel.md.
Run telemetry
- Items returned
- 4
- Duration
- 9m 43s
- Tool calls
- 0 WebFetch9 WebSearch24 bridge
- Cited sources
- 5 of 25 in slice
- Items returned
- 1
- Duration
- 7m 27s
- Tool calls
- 0 WebFetch12 WebSearch22 bridge
- Cited sources
- 1 of 29 in slice
- Items returned
- 4
- Duration
- 11m 30s
- Tool calls
- 0 WebFetch8 WebSearch45 bridge
- Cited sources
- 3 of 16 in slice
- Items returned
- 3
- Duration
- 6m 34s
- Tool calls
- 0 WebFetch8 WebSearch16 bridge
- Cited sources
- 4 of 21 in slice
- Items returned
- 10
- Duration
- 15m 15s
- Tool calls
- 0 WebFetch0 WebSearch33 bridge
- Cited sources
- none
Verification
Deep dive
·
Entries this run published (7) and updated (3)
- CVE-2026-20079, Cisco Secure Firewall Management Center: unauthenticated authentication bypass to root, unpatched for five months and only exploitable in a post-boot window (CVSS 10.0) vulnerability high update
- Revolut discloses a customer KYC data breach after fulfilling a fraudulent request sent from inside a genuine government agency's own email domain incident notable update
- CVE-2026-76460 (+ CVE-2026-76423), Cisco Identity Services Engine: unauthenticated API authentication bypass to root, found while resolving a customer support case, no workaround beyond ACLs (CVSS 10.0) vulnerability critical update
- CVE-2026-91843, Check Point Security Management / Multi-Domain Security Management / Log Server: unauthenticated stack overflow in the login process reaches root RCE (CVSS 9.8) vulnerability high
- CVE-2026-87886, Acronis Backup plugin for cPanel/WHM and extension for Plesk: local privilege escalation via insecure default permissions, CISA KEV-listed (CVSS 7.8) vulnerability high
- NTC finds default passwords, fleet-wide shared credentials and unauthenticated grid-feed shutoff across Swiss solar inverters, with a named cantonal procurement gap research high
- FamousSparrow retires SparrowDoor for SparroWocky, a modular backdoor with BOF-loading and call-stack spoofing, deployed almost exclusively against Latin American governments threat notable
- MovieReaper: a modular crimeware framework distributed via a torrent-file-repository supply-chain compromise, using the Solana blockchain as a C2 dead-drop resolver threat notable
- Gyazo (Helpfeel): an image-upload-server vulnerability reaches arbitrary command execution, exposing 23.62 million user records and 490 million image-metadata records incident notable
- Brevo: a stolen, hardcoded Cloudflare API key let an attacker inject ClickFix malware and a WordPress backdoor plugin via a CDN-edge Worker into up to 100,000 customer sites, defeating origin-side integrity checks incident high
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
13 bookkeeping · 1 recipe-fix.
| Source | Change | From → To | Reason |
|---|---|---|---|
| tp-link-omada-psirt | recipe-fix | url=https://support.omadanetworks.com/us/security-advisory/, fetch_method=bridge → url=https://support.omadanetworks.com/en/bulletin/, fetch_method=jina | S1 confirmed the old listing URL 404s a 3rd consecutive time. The replacement bulletin path is a JS-rendered SPA that plain extract/url cannot read (returns only a cookie-consent shell, as a 2026-09-17 probe already found), but the jina reader successfully hydrates it and returns the full dated bulletin list. Switched fetch_method/url to this working recipe; the BSI CERT-Bund CSAF external-reference recipe documented in this source's notes remains a valid fallback for a specific advisory's per-model firmware table. |
| bsi-de | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | Discovery source for the published Check Point CVE-2026-91843 entry. |
| ncsc-ch-security-hub | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | Discovery source for the Cisco FMC hardening-cycle update. |
| advisories-ncsc-nl | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | Discovery/corroborating source for the Cisco ISE hardening-cycle update. |
| enisa-euvd | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | Discovery source for the Acronis CVE-2026-87886 gap-fill entry. |
| cisa-kev | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | Cross-checked for the Acronis CVE-2026-87886 KEV listing and the mechanical KEV sweep. |
| inside-it-ch | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | RSS discovery lead for the NTC solar-inverter entry (the specific article remained blocked). |
| heise-sec | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | Discovery source for the OpenAI misalignment item (not published) and general sweep. |
| eset | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | Primary source for the published FamousSparrow/SparroWocky entry. |
| databreaches-net | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | Discovery lead for the published Gyazo/Helpfeel entry. |
| bleepingcomputer | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | Corroborating source for the published Brevo and Acronis entries. |
| cyberinsider | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | Corroborating source for the Revolut access-vector update. |
| frenchbreaches | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | Used for coverage-backlog re-checks and surfaced the new Pays de l'Aigle backlog row. |
| anssi-fr | bookkeeping | prior last_successful_fetch → last_successful_fetch 2026-09-18 | Corroborating source (CERT-FR) for the Check Point CVE-2026-91843 and Cisco ISE update entries. |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.
Bridge invocations (this run)
18 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- extract ×15
- extract-fallback-to-csaf-bridge ×1
- extract-and-jina ×1
- extract-fallback-to-jina ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 14 findings (truth=11, editorial=2, advisory=1) · Claude Sonnet 5 · 10m 03s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | ntc-swiss-solar-inverter-cybersecurity-assessment | The 338,000-installation figure was cited to NTC's own page, which never states it; cash.ch does. | Re-attributed to cash.ch. | |
| F3 claim-not-supported | ntc-swiss-solar-inverter-cybersecurity-assessment | 'No evidence of intentionally built-in backdoors' was cited to NTC's own page; cash.ch states it. | Re-attributed to cash.ch. | |
| F3 claim-not-supported | ntc-swiss-solar-inverter-cybersecurity-assessment | The Federal Office of Energy confirmation was cited to cash.ch, which never mentions it; SRF states it. | Re-attributed to SRF. | |
| F3 claim-not-supported | gyazo-helpfeel-data-breach-image-upload-rce | The '32-character image ID' detail was cited to Helpfeel's own notice, which never states the character count; The Hacker News does. | Re-attributed to The Hacker News. | |
| F3 claim-not-supported | gyazo-helpfeel-data-breach-image-upload-rce | 'Emergency maintenance from September 12 through 15' overstated The Hacker News's own date range, which covers only September 14-15. | Corrected the date range to September 14 and 15. | |
| F3 claim-not-supported | brevo-cloudflare-worker-clickfix-supply-chain | Sansec's publication date was cited as 2026-09-14 in sources[] and two inline citations; Sansec's own byline reads 2026-09-16. | Corrected all three citations to 2026-09-16. | |
| F3 claim-not-supported | revolut-fake-government-request-kyc-breach | The 2026-09-18 update presented '"appeared authentic based on the technical indicators available"' as a Revolut quote; it is CyberInsider's own paraphrase of what Revolut told CyberInsider, and carrie | Re-attributed to CyberInsider with an inline citation. | |
| F4 hallucinated-fact | cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev | DirectAdmin (product name, affected version, fixed build 1.2.3.238) was not supported by any of the entry's three cited sources. | Dropped DirectAdmin from title, summary, affected_products[], cves[].affected/fixed, actions[] and body; entry now covers only cPanel & WHM and Plesk. | |
| F14 ? | cve-2026-76460-cisco-ise-auth-bypass-root-rce | The 2026-09-18 update said CERT-FR names 'seven' unpatched CVEs on ISE 3.1/3.2; CERT-FR's own advisory lists eight. | Corrected 'seven' to 'eight' in both the changelog summary and the body section. | |
| F14 ? | famoussparrow-sparrowocky-backdoor-latam-gov | (low confidence) The 90% figure was framed as '90% ... government entities', conflating ESET's geographic-concentration stat with a separate sector-composition claim. | Reworded to state the two facts separately: 90% of targets in Latin America, almost all of them governmental. | |
| F14 ? | moviereaper-torrent-supply-chain-solana-c2 | (low confidence) 'An ETW-Threat-Intelligence-provider-evading alternative to CreateThread' overstated Kaspersky's own framing ('a popular alternative to CreateThread'). | Rewrote to state Kaspersky's own framing without the added interpretive claim. | |
| F5 missing-citation | brevo-cloudflare-worker-clickfix-supply-chain | Two sentences (Sansec's corroboration detail, the 100k-site estimate, Brevo's silence on the Sept-10 SSO incident, BleepingComputer's non-response note) carried zero inline citations. | Added a per-clause citation to each of the four claims. | |
| F5 missing-citation | revolut-fake-government-request-kyc-breach | Same clause as the F3 misattribution above carried no citation at all. | Fixed by the same edit that re-attributed the quote to CyberInsider with a citation. | |
| F11 editorial-advisory | cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev | (advisory) priority: high rests on a post-auth/local-only flaw whose exploitation confirmation is Acronis's own single-customer report; flagged as thinner than most high items this run, not requesting | Reviewed: KEV listing is CISA's own independent exploitation judgment (PD-13), and the body already states the single-customer-report basis plainly. Kept at hig |
Iteration #2 NEEDS_FIXES · 8 findings (truth=3, editorial=3, advisory=2) · Claude Sonnet 5 · 11m 00s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | brevo-cloudflare-worker-clickfix-supply-chain | An evidence[] quote spliced two non-contiguous BleepingComputer sentences (a paragraph-break 'Finally,' lead-in dropped) with an ellipsis. | Split into two separate evidence[] records, each a contiguous verbatim substring. | |
| F4 hallucinated-fact | cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev | state/cves_seen.json's store-wide title for CVE-2026-87886 still named DirectAdmin after iteration 1 removed it from the published entry, a stale, contradictory index artifact. | Corrected the title to name only cPanel & WHM/Plesk. | |
| F4 hallucinated-fact | cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev | entities/registry.yaml carried an orphan product:acronis-backup-plugin-for-directadmin-linux key, referenced by no entry and supported by no source, left over from the same incomplete DirectAdmin clea | Removed the orphan registry product entity. | |
| F5 missing-citation | ntc-swiss-solar-inverter-cybersecurity-assessment | Two sentences (EU/US regulatory response, Switzerland's inaction, NTC's confidential-disclosure practice and fix status) carried no inline citation. | Added per-sentence citations to SRF and NTC respectively. | |
| F8 needs-more-research | famoussparrow-sparrowocky-backdoor-latam-gov | (moderate confidence) Body described 2 of ESET's 3 named anti-analysis techniques, omitting the PEB_LDR_DATA/LDR_DATA_TABLE_ENTRY module-list forgery technique already referenced in this run's own reg | Added a clause describing the technique to the body. | |
| F10 missed-angle | famoussparrow-sparrowocky-backdoor-latam-gov | (low confidence) No relations[] edge links the new actor:famoussparrow to the pre-existing campaign:famoussparrow-azerbaijan-2026 record for the same actor. | Attempted an attributed-to edge, but check_run.py's registry-relations check correctly flagged that this run's own cited source (ESET's SparroWocky article) nev | |
| F11 editorial-advisory | ntc-swiss-solar-inverter-cybersecurity-assessment | An editorial annotation (translator + speaker attribution) was embedded inside an evidence[] quote's text rather than kept as external metadata. | Trimmed the quote to the translation note only; speaker attribution already lives in the body prose. | |
| F11 editorial-advisory | cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev | (low confidence) BleepingComputer citation dated 2026-09-16; page metadata reads 2026-09-15. | Corrected both citations to 2026-09-15 to match page metadata. |
Iteration #3 NEEDS_FIXES · 11 findings (truth=8, editorial=3, advisory=0) · Claude Sonnet 5 · 10m 41s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix | The new CVE-2026-20324 evidence[] quote spliced two non-adjacent sentences from Cisco's advisory with an ellipsis, dropping a full sentence in between. | Split into two separate evidence[] records, each a contiguous verbatim substring. | |
| F3 claim-not-supported | brevo-cloudflare-worker-clickfix-supply-chain | The Win+R/paste/Enter ClickFix mechanics were cited to Sansec, which never states them; only Brevo's write-up does (Sansec supports only the crawler-exemption clause). | Re-attributed the ClickFix mechanics to Brevo; kept Sansec on the crawler-exemption clause only. | |
| F3 claim-not-supported | brevo-cloudflare-worker-clickfix-supply-chain | The Trezor phishing-campaign connection was cited to Brevo's post-mortem, which never mentions Trezor; only BleepingComputer states it. | Removed the Brevo citation from that clause; the sentence now attributes the Trezor detail to BleepingComputer alone. | |
| F3 claim-not-supported | revolut-fake-government-request-kyc-breach | Two evidence[] quotes attributed to 'Hudson Rock' are actually the attacker's own account as relayed by 'The Duel Investigations Team' on Hudson Rock's page, not Hudson Rock's own analysis (confined t | Re-attributed both quotes to 'The Duel Investigations Team, via Hudson Rock' and reworded the body to frame that material as the attacker's account, not Hudson | |
| F3 claim-not-supported | ntc-swiss-solar-inverter-cybersecurity-assessment | (low confidence) 'Switzerland has taken no equivalent step' was cited to SRF as fact; SRF's article does not state this; it is an inference from the article's framing. | Removed the unsupported claim; the sentence now states only the EU/US measures SRF does report. | |
| F3 claim-not-supported | gyazo-helpfeel-data-breach-image-upload-rce | (low confidence) The access-control-model-relies-on-ID-secrecy framing was cited to Helpfeel; it is The Hacker News's framing (drawing on Gyazo's help pages). | Re-attributed that clause to The Hacker News. | |
| F3 claim-not-supported | cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev | (low confidence) event_date (2026-09-15) matched the corroborating BleepingComputer date rather than the designated primary source's (Help Net Security) 2026-09-16 date. | Corrected event_date to 2026-09-16. | |
| F14 ? | famoussparrow-sparrowocky-backdoor-latam-gov | (low confidence) 'Almost all of it governmental entities' was not a quantifier ESET actually states; ESET quantifies only the 90%-in-Latin-America figure. | Reworded to 'with government entities named among the targets' in both summary and body, dropping the unsupported proportion claim. | |
| F5 missing-citation | gyazo-helpfeel-data-breach-image-upload-rce | The closing sentence on Helpfeel's other two products carried no inline citation. | Added a citation to Helpfeel's own notice. | |
| F5 missing-citation | cve-2026-91843-check-point-security-mgmt-stack-overflow | A claim about 'CISA's own SSVC exploitation-decision field' had no CISA source anywhere in sources[]; the underlying NVD/CISA-ADP record is a per-CVE NVD page, which is a banned citation pattern (PD-2 | Removed the CISA SSVC claim from both the body and sourcing_note; the entry now states only what Check Point, BSI and CERT-FR say (all silent on exploitation). | |
| F6 strengthen-primary-source | cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev | (low confidence, advisory) Primary source is a journalism outlet rather than the vendor advisory, because Acronis's own advisory page is an unreachable client-rendered SPA on every transport tried. | Reviewed: the sourcing_note already documents this constraint. No change; no reachable vendor primary exists to substitute. |
Iteration #4 NEEDS_FIXES · 5 findings (truth=3, editorial=2, advisory=1) · Claude Sonnet 5 · 11m 45s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F5 missing-citation | ntc-swiss-solar-inverter-cybersecurity-assessment | 'No CVEs were assigned' and 'most of whom have already shipped fixes' were stated without a citation each source actually supports; and the 338,000-installation figure was framed as the tested product | Softened the 338,000-figure framing to NTC's own weaker claim ('like those installed in thousands of Swiss homes') alongside the cash.ch figure; re-cited the fi | |
| F11 editorial-advisory | run-record | The run record's own 'Verification & coverage notes' repeated workflow-internal language ('Phase 4', 'sub-agent', 'main-agent') and literal S1/S2/S3/S4 sub-agent labels. | Rewrote the affected sentences in plain, descriptive language (e.g. 'the home-region/sector track' / 'the research track' / 'a deep re-read of the primary befor | |
| F10 missed-angle | revolut-fake-government-request-kyc-breach | (low confidence) CyberInsider references a citable but unnamed 'separate reporting' customer count (~680) not mentioned in the entry. | Added a hedged sentence noting CyberInsider's unverified ~680 figure without presenting it as confirmed. | |
| F14 ? | famoussparrow-sparrowocky-backdoor-latam-gov | (low confidence) Body called SparroWocky FamousSparrow's 'exclusive implant'; ESET calls it the 'main'/'flagship' implant (the frontmatter summary already said 'flagship'), an unsourced strengthening | Changed 'exclusive implant' to 'main implant' in the body to match ESET's own wording and the frontmatter summary. | |
| F3 claim-not-supported | ntc-swiss-solar-inverter-cybersecurity-assessment | (low confidence, ×2) Covered by the F5 remediation above, the 338,000-installation framing and the fix-status claim were both overclaims relative to their cited sources. | Same edit as the F5 fix above. |
Iteration #5 NEEDS_FIXES · 4 findings (truth=3, editorial=2, advisory=0) · Claude Sonnet 5 · 10m 52s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | ntc-swiss-solar-inverter-cybersecurity-assessment | The iteration-4 fix only partly landed: 'no CVEs were assigned' was still cited to NTC's page, which never mentions CVEs at all; and the 'work still under way for some products' hedge was cited to cas | Attributed the remediation-status hedge to NTC directly ('NTC states remediation is complete for some products and ongoing for others'), cash.ch's stronger 'alr | |
| F14 ? | famoussparrow-sparrowocky-backdoor-latam-gov | (low confidence) The new actor:famoussparrow registry entity extended ESET's 'only known user of SparrowDoor' language to also claim exclusivity over SparroWocky, which ESET attributes only with high | Reworded the registry summary to keep the SparrowDoor exclusivity claim and state the SparroWocky attribution as ESET's high-confidence assessment, not an exclu | |
| F8 needs-more-research | cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev | (low confidence) The entry's exploitation framing didn't surface Help Net Security's explicit statement that there are no signs of active exploitation on Plesk deployments specifically, a real priorit | Added a sentence stating the confirmed activity is limited to the cPanel & WHM plugin, per Help Net Security. | |
| F8 needs-more-research | gyazo-helpfeel-data-breach-image-upload-rce | (low confidence) The entry blurred The Hacker News's distinction between Gyazo's default link-secrecy privacy (defeated by this breach) and the stricter 'Only me'/password-protected settings, which th | Reworded to name the default setting specifically and note it is distinct from the stricter settings. |
Iteration #6 NEEDS_FIXES cap-breach · 3 findings (truth=1, editorial=1, advisory=1) · Claude Sonnet 5 · 8m 21s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | ntc-swiss-solar-inverter-cybersecurity-assessment | The remediation-status clause, fixed twice before, was still inaccurate on this third attempt: the body said NTC 'states remediation is complete for some products and ongoing for others', but NTC's ow | Reworded to track NTC's actual wording: manufacturers responded quickly to the disclosure, work to fix the vulnerabilities remains under way for some products. | |
| F5 missing-citation | ntc-swiss-solar-inverter-cybersecurity-assessment | 'No CVEs were assigned to any of the findings' carried no citation, the same absence-claim pattern the Check Point entry handles by citing every source checked. | Added citations to both NTC and cash.ch, neither of which names a CVE. | |
| F11 editorial-advisory | brevo-cloudflare-worker-clickfix-supply-chain | (low confidence, advisory) The clause distinguishing the 100k-site figure as an upper-bound count vs. a confirmed-payload count is the entry's own methodological gloss, over-attributed to Sansec as if | Moved the distinction outside the Sansec citation so it reads as the entry's own clarification, not an attributed Sansec statement. |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-18T0410Z-intel · Sonnet 5 · window 26 h · 7 entries published
Verification & coverage notes
Standard 26-hour window (24 hours since the previous fire, 2026-09-17T0409Z-intel). No closed-source drops this window. No product or supplier watchlist is configured for this deployment, so both sweeps are no-ops (Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0).
Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found zero CISA KEV additions since 2026-09-17; no disposition duty this run. The vulnerability-track research independently cross-checked the live KEV catalog and surfaced one CVE that never appeared in the prior 14-day coverage despite meeting the confirmed-exploited/KEV bar a day earlier than this run's window (CVE-2026-87886, Acronis Backup plugin, KEV-listed 2026-09-16); see the gap-fill note below.
New entries (7):
cve-2026-91843-check-point-security-mgmt-stack-overflow(high, vulnerability), unauthenticated stack overflow in Check Point Security/Multi-Domain Security Management and Log Server login process, root RCE, no confirmed exploitation. Included under PD-11(b)'s "otherwise" limb: an anonymous single-request path to root on network-security management infrastructure.cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev(high, vulnerability), Acronis Backup plugin LPE for cPanel & WHM/Plesk/DirectAdmin, CISA KEV-listed 2026-09-16 on a single-customer-report basis. Gap-fill: disclosure predates this run's 26h window by about a day and was missed by the prior fire's own KEV sweep window; published now per the coverage-backlog philosophy (verified in-window by the fire that surfaces it) rather than deferred further.ntc-swiss-solar-inverter-cybersecurity-assessment(high, research), Swiss NTC finds 50+ vulnerabilities across solar inverters/EMS including unauthenticated grid-feed shutoff; direct cantonal (Bern) procurement nexus. Independently surfaced from both the home-region/sector track (English NTC page) and the research track (German NTC page + SRF); composed once, merging both discovery traces.famoussparrow-sparrowocky-backdoor-latam-gov(notable, threat), ESET documents a new FamousSparrow backdoor with BOF-loading and call-stack spoofing, almost exclusively targeting Latin American governments.techniques[]carries the full 34-id set from ESET's own ATT&CK table (a deep re-read of the primary before composing caught the initial research draft at only 13 ids, see below).moviereaper-torrent-supply-chain-solana-c2(notable, threat), Kaspersky documents a crimeware framework distributed via a torrent-file-repository supply-chain compromise, using Solana blockchain as a C2 dead-drop; government named among confirmed victim sectors.gyazo-helpfeel-data-breach-image-upload-rce(notable, incident), Helpfeel discloses a Gyazo breach exposing 23.62M user records and 490M image-metadata records; included on PD-11(a) global scale.brevo-cloudflare-worker-clickfix-supply-chain(high, incident), a stolen Cloudflare API key let an attacker inject malware via a CDN-edge Worker into up to 100,000 sites, defeating origin-side integrity checks; included on PD-11(b), a materially novel and transferable supply-chain TTP.
Updates (3), all type: update, all float updated_at:
2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix, Cisco's promised 2026-09-16 hardening release landed on schedule, adding CVE-2026-20324 and CVE-2026-20242 to the same tracked FMC product line; neither reported exploited.2026-09-17/cve-2026-76460-cisco-ise-auth-bypass-root-rce, the same 16 September cycle disclosed a further 21-vulnerability, 13-critical Cisco ISE hardening release; two more CVSS 10.0 CVEs beyond the already-exploited primary; CERT-FR confirms only the original CVE is exploited and flags an unpatchable subset on ISE 3.1/3.2 before their 2027 end of maintenance.2026-09-13/revolut-fake-government-request-kyc-breach, Hudson Rock names the access vector this entry left open: infostealer-compromised Italian Ministry of Interior mailboxes, independently corroborated by Hudson Rock's own database finding of ~300 compromised credentials; the surrounding attacker narrative remains only partly verified.
Dropped (borderline-drop):
borderline-drop: OpenAI model-misalignment reporting framework + context-compaction self-injection finding — genuinely novel AI-safety research (a model injecting jailbreak-style text into its own training-time context-compaction summaries), but describes model self-behavior during training rather than an external attacker technique, with no SOC-actionable detect/hunt/harden lesson; the rolling window already carries extensive AI-agent-misalignment coverage (yesterday's Mandiant deep dive, GTG-20006/27005, Hugging Face, Anthropic eval-escape entries). Quality-over-quantity (v4.2) resolves toward drop.
Deep re-read of every primary before composing (10 items): re-fetched all 10 primaries in full and confirmed every pre-existing evidence quote verbatim. Corrections folded into composition before publish: (a) FamousSparrow/SparroWocky's techniques[] expanded from a 13-id draft to ESET's own complete 34-id ATT&CK table; (b) the Brevo incident-window framing corrected to Brevo's own two-window disclosure (15:01-20:30 UTC overall impact; 16:07 UTC specifically for the customer-embedded-script compromise) rather than BleepingComputer's compressed single figure; (c) the Cisco FMC update's draft claim that Cisco Security Cloud Control is unaffected by CVE-2026-20242 was dropped, that advisory's own "Products Confirmed Not Vulnerable" list names only ASA/FTD, not SCC; (d) the Acronis entry's exploitation framing narrowed to state plainly that Acronis's own assessment rests on a single customer's report, not a broad campaign, and CISA's KEV description omits DirectAdmin even though NVD/ENISA (mirroring Acronis's own CVE text) list it as a third affected product; (e) MovieReaper's victim-country list corrected to cite Kaspersky's own more-specific "Victims" section rather than its shorter introduction-paragraph enumeration.
Coverage-backlog re-checks this run (state/coverage_backlog.md § Open), all "no change" except one new row opened:
- ShinyHunters/Kimberly-Clark, TheGentlemen/Ixa Systems SA, Krybit/UICC, ShinyHunters/Medela AG, SafePay/reichenau.at, Ville du Tampon, Familea, AFPA, all re-checked, no change on any; still only leak-site trackers or unresolved victim statements, no Admiralty A/B journalism or evidence-bound mechanism clearing the relevant gate.
- inside-it.ch's Insel Gruppe article, still blocked (a persistent "Security Checkpoint" HTTP 429 on every transport, a 19th+ consecutive fire); the day's NTC solar-inverter story was independently reached through the RSS listing and a web search pivot, bypassing the blocked article entirely. Recommend closing or re-scoping this row if the next 2-3 fires also find nothing.
- Siemens S7 PLC advisory, VMware VMSA-2026-0007, Spring Ring Teams-vishing NTLM relay, and the three remaining PD-11(d) research items (AWS root-password spraying, Exodus wallet installer RAT, Check Point JSCeal deobfuscation), all re-checked, no material development on any; remain below their respective recovery bars.
- NovoCure; not re-probed this run (no spare capacity); low priority, carried forward.
- New row opened: Communauté de communes des Pays de L'Aigle (France) confirms a mail-server intrusion the night of 14-15 September 2026; no mechanism, actor or data-theft claim named by any party, so it does not yet clear the breach gate's ATT&CK-mapping requirement. Same blocking condition as the existing Ville du Tampon/Familea rows.
Deep-dive selection: no deep dive this run. Two candidates considered (FamousSparrow/SparroWocky (category apt-campaign, used 5 days ago for GTG-20006; MovieReaper) category supply-chain, used 6 days ago for JFrog Artifactory); both demoted by the 7-day category-rotation rule, and neither independently clears criterion 1 (no confirmed exploitation against an exposed constituency) to override the demotion.
Verification: six iterations, each a fresh cold read with no memory of the prior pass. The first four each found a substantial batch of genuine defects (citation misattributions, a hallucinated product claim, spliced evidence quotes, unsupported quantifiers) that were remediated in place; the fifth and sixth found progressively fewer, concentrated on one recurring clause (a solar-inverter entry's remediation-status wording, corrected three times before it tracked the primary source's exact claim). The sixth iteration's residual, truth 1 plus editorial 1 with no broken-URL or hallucinated-fact finding, cleared the early-exit bar: both were fixed and the run published without a further confirmation pass. One advisory-only finding on the same iteration (an over-attributed interpretive gloss) was also fixed. No entry was dropped by verification.
Sources: tp-link-omada-psirt's listing URL recipe fixed (see sources_changed). All 187 tracked sources probed clean by tools/source_health.py this run (92 direct-ok, 95 bridge-ok, 0 unsolved), no repair duty.
← Operations dashboard · day page 2026-09-18 · run-record contract: docs/pipeline.md