CTIPilot

2026-09-18T0410Z-intel

One pipeline fire, in full · intel run of 2026-09-18 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-18/2026-09-18T0410Z-intel.md.

Run telemetry

2026-09-18T0410Z-intel intel prompt v4.10 publish ok
2h 32m duration 7 published 3 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
9m 43s
Tool calls
0 WebFetch9 WebSearch24 bridge
Cited sources
5 of 25 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
7m 27s
Tool calls
0 WebFetch12 WebSearch22 bridge
Cited sources
1 of 29 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
11m 30s
Tool calls
0 WebFetch8 WebSearch45 bridge
Cited sources
3 of 16 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
6m 34s
Tool calls
0 WebFetch8 WebSearch16 bridge
Cited sources
4 of 21 in slice
deepread_phase4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
10
Duration
15m 15s
Tool calls
0 WebFetch0 WebSearch33 bridge
Cited sources
none

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=11 e=2 a=1 #2 NEEDS_FIXES · Sonnet 5 · t=3 e=3 a=2 #3 NEEDS_FIXES · Sonnet 5 · t=8 e=3 a=0 #4 NEEDS_FIXES · Sonnet 5 · t=3 e=2 a=1 #5 NEEDS_FIXES · Sonnet 5 · t=3 e=2 a=0 #6 NEEDS_FIXES · Sonnet 5 · t=1 e=1 a=1

Deep dive

·

Entries this run published (7) and updated (3)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

13 bookkeeping · 1 recipe-fix.

SourceChangeFrom → ToReason
tp-link-omada-psirtrecipe-fixurl=https://support.omadanetworks.com/us/security-advisory/, fetch_method=bridge → url=https://support.omadanetworks.com/en/bulletin/, fetch_method=jinaS1 confirmed the old listing URL 404s a 3rd consecutive time. The replacement bulletin path is a JS-rendered SPA that plain extract/url cannot read (returns only a cookie-consent shell, as a 2026-09-17 probe already found), but the jina reader successfully hydrates it and returns the full dated bulletin list. Switched fetch_method/url to this working recipe; the BSI CERT-Bund CSAF external-reference recipe documented in this source's notes remains a valid fallback for a specific advisory's per-model firmware table.
bsi-debookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18Discovery source for the published Check Point CVE-2026-91843 entry.
ncsc-ch-security-hubbookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18Discovery source for the Cisco FMC hardening-cycle update.
advisories-ncsc-nlbookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18Discovery/corroborating source for the Cisco ISE hardening-cycle update.
enisa-euvdbookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18Discovery source for the Acronis CVE-2026-87886 gap-fill entry.
cisa-kevbookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18Cross-checked for the Acronis CVE-2026-87886 KEV listing and the mechanical KEV sweep.
inside-it-chbookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18RSS discovery lead for the NTC solar-inverter entry (the specific article remained blocked).
heise-secbookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18Discovery source for the OpenAI misalignment item (not published) and general sweep.
esetbookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18Primary source for the published FamousSparrow/SparroWocky entry.
databreaches-netbookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18Discovery lead for the published Gyazo/Helpfeel entry.
bleepingcomputerbookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18Corroborating source for the published Brevo and Acronis entries.
cyberinsiderbookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18Corroborating source for the Revolut access-vector update.
frenchbreachesbookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18Used for coverage-backlog re-checks and surfaced the new Pays de l'Aigle backlog row.
anssi-frbookkeepingprior last_successful_fetch → last_successful_fetch 2026-09-18Corroborating source (CERT-FR) for the Check Point CVE-2026-91843 and Cisco ISE update entries.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Bridge invocations (this run)

18 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

15 ok3 other
  • extract ×15
  • extract-fallback-to-csaf-bridge ×1
  • extract-and-jina ×1
  • extract-fallback-to-jina ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 14 findings (truth=11, editorial=2, advisory=1) · Claude Sonnet 5 · 10m 03s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
ntc-swiss-solar-inverter-cybersecurity-assessment
The 338,000-installation figure was cited to NTC's own page, which never states it; cash.ch does.Re-attributed to cash.ch.
F3
claim-not-supported
ntc-swiss-solar-inverter-cybersecurity-assessment
'No evidence of intentionally built-in backdoors' was cited to NTC's own page; cash.ch states it.Re-attributed to cash.ch.
F3
claim-not-supported
ntc-swiss-solar-inverter-cybersecurity-assessment
The Federal Office of Energy confirmation was cited to cash.ch, which never mentions it; SRF states it.Re-attributed to SRF.
F3
claim-not-supported
gyazo-helpfeel-data-breach-image-upload-rce
The '32-character image ID' detail was cited to Helpfeel's own notice, which never states the character count; The Hacker News does.Re-attributed to The Hacker News.
F3
claim-not-supported
gyazo-helpfeel-data-breach-image-upload-rce
'Emergency maintenance from September 12 through 15' overstated The Hacker News's own date range, which covers only September 14-15.Corrected the date range to September 14 and 15.
F3
claim-not-supported
brevo-cloudflare-worker-clickfix-supply-chain
Sansec's publication date was cited as 2026-09-14 in sources[] and two inline citations; Sansec's own byline reads 2026-09-16.Corrected all three citations to 2026-09-16.
F3
claim-not-supported
revolut-fake-government-request-kyc-breach
The 2026-09-18 update presented '"appeared authentic based on the technical indicators available"' as a Revolut quote; it is CyberInsider's own paraphrase of what Revolut told CyberInsider, and carrieRe-attributed to CyberInsider with an inline citation.
F4
hallucinated-fact
cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev
DirectAdmin (product name, affected version, fixed build 1.2.3.238) was not supported by any of the entry's three cited sources.Dropped DirectAdmin from title, summary, affected_products[], cves[].affected/fixed, actions[] and body; entry now covers only cPanel & WHM and Plesk.
F14
?
cve-2026-76460-cisco-ise-auth-bypass-root-rce
The 2026-09-18 update said CERT-FR names 'seven' unpatched CVEs on ISE 3.1/3.2; CERT-FR's own advisory lists eight.Corrected 'seven' to 'eight' in both the changelog summary and the body section.
F14
?
famoussparrow-sparrowocky-backdoor-latam-gov
(low confidence) The 90% figure was framed as '90% ... government entities', conflating ESET's geographic-concentration stat with a separate sector-composition claim.Reworded to state the two facts separately: 90% of targets in Latin America, almost all of them governmental.
F14
?
moviereaper-torrent-supply-chain-solana-c2
(low confidence) 'An ETW-Threat-Intelligence-provider-evading alternative to CreateThread' overstated Kaspersky's own framing ('a popular alternative to CreateThread').Rewrote to state Kaspersky's own framing without the added interpretive claim.
F5
missing-citation
brevo-cloudflare-worker-clickfix-supply-chain
Two sentences (Sansec's corroboration detail, the 100k-site estimate, Brevo's silence on the Sept-10 SSO incident, BleepingComputer's non-response note) carried zero inline citations.Added a per-clause citation to each of the four claims.
F5
missing-citation
revolut-fake-government-request-kyc-breach
Same clause as the F3 misattribution above carried no citation at all.Fixed by the same edit that re-attributed the quote to CyberInsider with a citation.
F11
editorial-advisory
cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev
(advisory) priority: high rests on a post-auth/local-only flaw whose exploitation confirmation is Acronis's own single-customer report; flagged as thinner than most high items this run, not requestingReviewed: KEV listing is CISA's own independent exploitation judgment (PD-13), and the body already states the single-customer-report basis plainly. Kept at hig

Iteration #2 NEEDS_FIXES · 8 findings (truth=3, editorial=3, advisory=2) · Claude Sonnet 5 · 11m 00s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
brevo-cloudflare-worker-clickfix-supply-chain
An evidence[] quote spliced two non-contiguous BleepingComputer sentences (a paragraph-break 'Finally,' lead-in dropped) with an ellipsis.Split into two separate evidence[] records, each a contiguous verbatim substring.
F4
hallucinated-fact
cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev
state/cves_seen.json's store-wide title for CVE-2026-87886 still named DirectAdmin after iteration 1 removed it from the published entry, a stale, contradictory index artifact.Corrected the title to name only cPanel & WHM/Plesk.
F4
hallucinated-fact
cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev
entities/registry.yaml carried an orphan product:acronis-backup-plugin-for-directadmin-linux key, referenced by no entry and supported by no source, left over from the same incomplete DirectAdmin cleaRemoved the orphan registry product entity.
F5
missing-citation
ntc-swiss-solar-inverter-cybersecurity-assessment
Two sentences (EU/US regulatory response, Switzerland's inaction, NTC's confidential-disclosure practice and fix status) carried no inline citation.Added per-sentence citations to SRF and NTC respectively.
F8
needs-more-research
famoussparrow-sparrowocky-backdoor-latam-gov
(moderate confidence) Body described 2 of ESET's 3 named anti-analysis techniques, omitting the PEB_LDR_DATA/LDR_DATA_TABLE_ENTRY module-list forgery technique already referenced in this run's own regAdded a clause describing the technique to the body.
F10
missed-angle
famoussparrow-sparrowocky-backdoor-latam-gov
(low confidence) No relations[] edge links the new actor:famoussparrow to the pre-existing campaign:famoussparrow-azerbaijan-2026 record for the same actor.Attempted an attributed-to edge, but check_run.py's registry-relations check correctly flagged that this run's own cited source (ESET's SparroWocky article) nev
F11
editorial-advisory
ntc-swiss-solar-inverter-cybersecurity-assessment
An editorial annotation (translator + speaker attribution) was embedded inside an evidence[] quote's text rather than kept as external metadata.Trimmed the quote to the translation note only; speaker attribution already lives in the body prose.
F11
editorial-advisory
cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev
(low confidence) BleepingComputer citation dated 2026-09-16; page metadata reads 2026-09-15.Corrected both citations to 2026-09-15 to match page metadata.

Iteration #3 NEEDS_FIXES · 11 findings (truth=8, editorial=3, advisory=0) · Claude Sonnet 5 · 10m 41s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix
The new CVE-2026-20324 evidence[] quote spliced two non-adjacent sentences from Cisco's advisory with an ellipsis, dropping a full sentence in between.Split into two separate evidence[] records, each a contiguous verbatim substring.
F3
claim-not-supported
brevo-cloudflare-worker-clickfix-supply-chain
The Win+R/paste/Enter ClickFix mechanics were cited to Sansec, which never states them; only Brevo's write-up does (Sansec supports only the crawler-exemption clause).Re-attributed the ClickFix mechanics to Brevo; kept Sansec on the crawler-exemption clause only.
F3
claim-not-supported
brevo-cloudflare-worker-clickfix-supply-chain
The Trezor phishing-campaign connection was cited to Brevo's post-mortem, which never mentions Trezor; only BleepingComputer states it.Removed the Brevo citation from that clause; the sentence now attributes the Trezor detail to BleepingComputer alone.
F3
claim-not-supported
revolut-fake-government-request-kyc-breach
Two evidence[] quotes attributed to 'Hudson Rock' are actually the attacker's own account as relayed by 'The Duel Investigations Team' on Hudson Rock's page, not Hudson Rock's own analysis (confined tRe-attributed both quotes to 'The Duel Investigations Team, via Hudson Rock' and reworded the body to frame that material as the attacker's account, not Hudson
F3
claim-not-supported
ntc-swiss-solar-inverter-cybersecurity-assessment
(low confidence) 'Switzerland has taken no equivalent step' was cited to SRF as fact; SRF's article does not state this; it is an inference from the article's framing.Removed the unsupported claim; the sentence now states only the EU/US measures SRF does report.
F3
claim-not-supported
gyazo-helpfeel-data-breach-image-upload-rce
(low confidence) The access-control-model-relies-on-ID-secrecy framing was cited to Helpfeel; it is The Hacker News's framing (drawing on Gyazo's help pages).Re-attributed that clause to The Hacker News.
F3
claim-not-supported
cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev
(low confidence) event_date (2026-09-15) matched the corroborating BleepingComputer date rather than the designated primary source's (Help Net Security) 2026-09-16 date.Corrected event_date to 2026-09-16.
F14
?
famoussparrow-sparrowocky-backdoor-latam-gov
(low confidence) 'Almost all of it governmental entities' was not a quantifier ESET actually states; ESET quantifies only the 90%-in-Latin-America figure.Reworded to 'with government entities named among the targets' in both summary and body, dropping the unsupported proportion claim.
F5
missing-citation
gyazo-helpfeel-data-breach-image-upload-rce
The closing sentence on Helpfeel's other two products carried no inline citation.Added a citation to Helpfeel's own notice.
F5
missing-citation
cve-2026-91843-check-point-security-mgmt-stack-overflow
A claim about 'CISA's own SSVC exploitation-decision field' had no CISA source anywhere in sources[]; the underlying NVD/CISA-ADP record is a per-CVE NVD page, which is a banned citation pattern (PD-2Removed the CISA SSVC claim from both the body and sourcing_note; the entry now states only what Check Point, BSI and CERT-FR say (all silent on exploitation).
F6
strengthen-primary-source
cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev
(low confidence, advisory) Primary source is a journalism outlet rather than the vendor advisory, because Acronis's own advisory page is an unreachable client-rendered SPA on every transport tried.Reviewed: the sourcing_note already documents this constraint. No change; no reachable vendor primary exists to substitute.

Iteration #4 NEEDS_FIXES · 5 findings (truth=3, editorial=2, advisory=1) · Claude Sonnet 5 · 11m 45s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F5
missing-citation
ntc-swiss-solar-inverter-cybersecurity-assessment
'No CVEs were assigned' and 'most of whom have already shipped fixes' were stated without a citation each source actually supports; and the 338,000-installation figure was framed as the tested productSoftened the 338,000-figure framing to NTC's own weaker claim ('like those installed in thousands of Swiss homes') alongside the cash.ch figure; re-cited the fi
F11
editorial-advisory
run-record
The run record's own 'Verification & coverage notes' repeated workflow-internal language ('Phase 4', 'sub-agent', 'main-agent') and literal S1/S2/S3/S4 sub-agent labels.Rewrote the affected sentences in plain, descriptive language (e.g. 'the home-region/sector track' / 'the research track' / 'a deep re-read of the primary befor
F10
missed-angle
revolut-fake-government-request-kyc-breach
(low confidence) CyberInsider references a citable but unnamed 'separate reporting' customer count (~680) not mentioned in the entry.Added a hedged sentence noting CyberInsider's unverified ~680 figure without presenting it as confirmed.
F14
?
famoussparrow-sparrowocky-backdoor-latam-gov
(low confidence) Body called SparroWocky FamousSparrow's 'exclusive implant'; ESET calls it the 'main'/'flagship' implant (the frontmatter summary already said 'flagship'), an unsourced strengthening Changed 'exclusive implant' to 'main implant' in the body to match ESET's own wording and the frontmatter summary.
F3
claim-not-supported
ntc-swiss-solar-inverter-cybersecurity-assessment
(low confidence, ×2) Covered by the F5 remediation above, the 338,000-installation framing and the fix-status claim were both overclaims relative to their cited sources.Same edit as the F5 fix above.

Iteration #5 NEEDS_FIXES · 4 findings (truth=3, editorial=2, advisory=0) · Claude Sonnet 5 · 10m 52s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
ntc-swiss-solar-inverter-cybersecurity-assessment
The iteration-4 fix only partly landed: 'no CVEs were assigned' was still cited to NTC's page, which never mentions CVEs at all; and the 'work still under way for some products' hedge was cited to casAttributed the remediation-status hedge to NTC directly ('NTC states remediation is complete for some products and ongoing for others'), cash.ch's stronger 'alr
F14
?
famoussparrow-sparrowocky-backdoor-latam-gov
(low confidence) The new actor:famoussparrow registry entity extended ESET's 'only known user of SparrowDoor' language to also claim exclusivity over SparroWocky, which ESET attributes only with high Reworded the registry summary to keep the SparrowDoor exclusivity claim and state the SparroWocky attribution as ESET's high-confidence assessment, not an exclu
F8
needs-more-research
cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev
(low confidence) The entry's exploitation framing didn't surface Help Net Security's explicit statement that there are no signs of active exploitation on Plesk deployments specifically, a real prioritAdded a sentence stating the confirmed activity is limited to the cPanel & WHM plugin, per Help Net Security.
F8
needs-more-research
gyazo-helpfeel-data-breach-image-upload-rce
(low confidence) The entry blurred The Hacker News's distinction between Gyazo's default link-secrecy privacy (defeated by this breach) and the stricter 'Only me'/password-protected settings, which thReworded to name the default setting specifically and note it is distinct from the stricter settings.

Iteration #6 NEEDS_FIXES cap-breach · 3 findings (truth=1, editorial=1, advisory=1) · Claude Sonnet 5 · 8m 21s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
ntc-swiss-solar-inverter-cybersecurity-assessment
The remediation-status clause, fixed twice before, was still inaccurate on this third attempt: the body said NTC 'states remediation is complete for some products and ongoing for others', but NTC's owReworded to track NTC's actual wording: manufacturers responded quickly to the disclosure, work to fix the vulnerabilities remains under way for some products.
F5
missing-citation
ntc-swiss-solar-inverter-cybersecurity-assessment
'No CVEs were assigned to any of the findings' carried no citation, the same absence-claim pattern the Check Point entry handles by citing every source checked.Added citations to both NTC and cash.ch, neither of which names a CVE.
F11
editorial-advisory
brevo-cloudflare-worker-clickfix-supply-chain
(low confidence, advisory) The clause distinguishing the 100k-site figure as an upper-bound count vs. a confirmed-payload count is the entry's own methodological gloss, over-attributed to Sansec as ifMoved the distinction outside the Sansec citation so it reads as the entry's own clarification, not an attributed Sansec statement.

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-18T0410Z-intel · Sonnet 5 · window 26 h · 7 entries published

Verification & coverage notes

Standard 26-hour window (24 hours since the previous fire, 2026-09-17T0409Z-intel). No closed-source drops this window. No product or supplier watchlist is configured for this deployment, so both sweeps are no-ops (Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0).

Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found zero CISA KEV additions since 2026-09-17; no disposition duty this run. The vulnerability-track research independently cross-checked the live KEV catalog and surfaced one CVE that never appeared in the prior 14-day coverage despite meeting the confirmed-exploited/KEV bar a day earlier than this run's window (CVE-2026-87886, Acronis Backup plugin, KEV-listed 2026-09-16); see the gap-fill note below.

New entries (7):

  1. cve-2026-91843-check-point-security-mgmt-stack-overflow (high, vulnerability), unauthenticated stack overflow in Check Point Security/Multi-Domain Security Management and Log Server login process, root RCE, no confirmed exploitation. Included under PD-11(b)'s "otherwise" limb: an anonymous single-request path to root on network-security management infrastructure.
  2. cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev (high, vulnerability), Acronis Backup plugin LPE for cPanel & WHM/Plesk/DirectAdmin, CISA KEV-listed 2026-09-16 on a single-customer-report basis. Gap-fill: disclosure predates this run's 26h window by about a day and was missed by the prior fire's own KEV sweep window; published now per the coverage-backlog philosophy (verified in-window by the fire that surfaces it) rather than deferred further.
  3. ntc-swiss-solar-inverter-cybersecurity-assessment (high, research), Swiss NTC finds 50+ vulnerabilities across solar inverters/EMS including unauthenticated grid-feed shutoff; direct cantonal (Bern) procurement nexus. Independently surfaced from both the home-region/sector track (English NTC page) and the research track (German NTC page + SRF); composed once, merging both discovery traces.
  4. famoussparrow-sparrowocky-backdoor-latam-gov (notable, threat), ESET documents a new FamousSparrow backdoor with BOF-loading and call-stack spoofing, almost exclusively targeting Latin American governments. techniques[] carries the full 34-id set from ESET's own ATT&CK table (a deep re-read of the primary before composing caught the initial research draft at only 13 ids, see below).
  5. moviereaper-torrent-supply-chain-solana-c2 (notable, threat), Kaspersky documents a crimeware framework distributed via a torrent-file-repository supply-chain compromise, using Solana blockchain as a C2 dead-drop; government named among confirmed victim sectors.
  6. gyazo-helpfeel-data-breach-image-upload-rce (notable, incident), Helpfeel discloses a Gyazo breach exposing 23.62M user records and 490M image-metadata records; included on PD-11(a) global scale.
  7. brevo-cloudflare-worker-clickfix-supply-chain (high, incident), a stolen Cloudflare API key let an attacker inject malware via a CDN-edge Worker into up to 100,000 sites, defeating origin-side integrity checks; included on PD-11(b), a materially novel and transferable supply-chain TTP.

Updates (3), all type: update, all float updated_at:

  • 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix, Cisco's promised 2026-09-16 hardening release landed on schedule, adding CVE-2026-20324 and CVE-2026-20242 to the same tracked FMC product line; neither reported exploited.
  • 2026-09-17/cve-2026-76460-cisco-ise-auth-bypass-root-rce, the same 16 September cycle disclosed a further 21-vulnerability, 13-critical Cisco ISE hardening release; two more CVSS 10.0 CVEs beyond the already-exploited primary; CERT-FR confirms only the original CVE is exploited and flags an unpatchable subset on ISE 3.1/3.2 before their 2027 end of maintenance.
  • 2026-09-13/revolut-fake-government-request-kyc-breach, Hudson Rock names the access vector this entry left open: infostealer-compromised Italian Ministry of Interior mailboxes, independently corroborated by Hudson Rock's own database finding of ~300 compromised credentials; the surrounding attacker narrative remains only partly verified.

Dropped (borderline-drop):

  • borderline-drop: OpenAI model-misalignment reporting framework + context-compaction self-injection finding — genuinely novel AI-safety research (a model injecting jailbreak-style text into its own training-time context-compaction summaries), but describes model self-behavior during training rather than an external attacker technique, with no SOC-actionable detect/hunt/harden lesson; the rolling window already carries extensive AI-agent-misalignment coverage (yesterday's Mandiant deep dive, GTG-20006/27005, Hugging Face, Anthropic eval-escape entries). Quality-over-quantity (v4.2) resolves toward drop.

Deep re-read of every primary before composing (10 items): re-fetched all 10 primaries in full and confirmed every pre-existing evidence quote verbatim. Corrections folded into composition before publish: (a) FamousSparrow/SparroWocky's techniques[] expanded from a 13-id draft to ESET's own complete 34-id ATT&CK table; (b) the Brevo incident-window framing corrected to Brevo's own two-window disclosure (15:01-20:30 UTC overall impact; 16:07 UTC specifically for the customer-embedded-script compromise) rather than BleepingComputer's compressed single figure; (c) the Cisco FMC update's draft claim that Cisco Security Cloud Control is unaffected by CVE-2026-20242 was dropped, that advisory's own "Products Confirmed Not Vulnerable" list names only ASA/FTD, not SCC; (d) the Acronis entry's exploitation framing narrowed to state plainly that Acronis's own assessment rests on a single customer's report, not a broad campaign, and CISA's KEV description omits DirectAdmin even though NVD/ENISA (mirroring Acronis's own CVE text) list it as a third affected product; (e) MovieReaper's victim-country list corrected to cite Kaspersky's own more-specific "Victims" section rather than its shorter introduction-paragraph enumeration.

Coverage-backlog re-checks this run (state/coverage_backlog.md § Open), all "no change" except one new row opened:

  • ShinyHunters/Kimberly-Clark, TheGentlemen/Ixa Systems SA, Krybit/UICC, ShinyHunters/Medela AG, SafePay/reichenau.at, Ville du Tampon, Familea, AFPA, all re-checked, no change on any; still only leak-site trackers or unresolved victim statements, no Admiralty A/B journalism or evidence-bound mechanism clearing the relevant gate.
  • inside-it.ch's Insel Gruppe article, still blocked (a persistent "Security Checkpoint" HTTP 429 on every transport, a 19th+ consecutive fire); the day's NTC solar-inverter story was independently reached through the RSS listing and a web search pivot, bypassing the blocked article entirely. Recommend closing or re-scoping this row if the next 2-3 fires also find nothing.
  • Siemens S7 PLC advisory, VMware VMSA-2026-0007, Spring Ring Teams-vishing NTLM relay, and the three remaining PD-11(d) research items (AWS root-password spraying, Exodus wallet installer RAT, Check Point JSCeal deobfuscation), all re-checked, no material development on any; remain below their respective recovery bars.
  • NovoCure; not re-probed this run (no spare capacity); low priority, carried forward.
  • New row opened: Communauté de communes des Pays de L'Aigle (France) confirms a mail-server intrusion the night of 14-15 September 2026; no mechanism, actor or data-theft claim named by any party, so it does not yet clear the breach gate's ATT&CK-mapping requirement. Same blocking condition as the existing Ville du Tampon/Familea rows.

Deep-dive selection: no deep dive this run. Two candidates considered (FamousSparrow/SparroWocky (category apt-campaign, used 5 days ago for GTG-20006; MovieReaper) category supply-chain, used 6 days ago for JFrog Artifactory); both demoted by the 7-day category-rotation rule, and neither independently clears criterion 1 (no confirmed exploitation against an exposed constituency) to override the demotion.

Verification: six iterations, each a fresh cold read with no memory of the prior pass. The first four each found a substantial batch of genuine defects (citation misattributions, a hallucinated product claim, spliced evidence quotes, unsupported quantifiers) that were remediated in place; the fifth and sixth found progressively fewer, concentrated on one recurring clause (a solar-inverter entry's remediation-status wording, corrected three times before it tracked the primary source's exact claim). The sixth iteration's residual, truth 1 plus editorial 1 with no broken-URL or hallucinated-fact finding, cleared the early-exit bar: both were fixed and the run published without a further confirmation pass. One advisory-only finding on the same iteration (an over-attributed interpretive gloss) was also fixed. No entry was dropped by verification.

Sources: tp-link-omada-psirt's listing URL recipe fixed (see sources_changed). All 187 tracked sources probed clean by tools/source_health.py this run (92 direct-ok, 95 bridge-ok, 0 unsolved), no repair duty.

← Operations dashboard · day page 2026-09-18 · run-record contract: docs/pipeline.md