2026-09-22T0410Z-intel
One pipeline fire, in full · intel run of 2026-09-22 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-22/2026-09-22T0410Z-intel.md.
Run telemetry
- Items returned
- 2
- Duration
- 12m 10s
- Tool calls
- 0 WebFetch2 WebSearch22 bridge
- Cited sources
- 4 of 25 in slice
- Items returned
- 2
- Duration
- 11m 08s
- Tool calls
- 12 WebFetch9 WebSearch11 bridge
- Cited sources
- 0 of 25 in slice
- Items returned
- 2
- Duration
- 9m 27s
- Tool calls
- 0 WebFetch8 WebSearch17 bridge
- Cited sources
- 3 of 16 in slice
- Items returned
- 0
- Duration
- 5m 23s
- Tool calls
- 0 WebFetch15 WebSearch14 bridge
- Cited sources
- 0 of 11 in slice
Verification
Deep dive
2026-09-22/cve-2026-7273-zyxel-gs1900-red-heron-kev-exploited
Entries this run published (4) and updated (1)
- CVE-2026-60004: Gitea's diffpatch endpoint turns an attacker-supplied patch into a live Git hook, giving command execution as the service account; KEV-listed after miner deployment vulnerability high update
- CVE-2026-7273, Zyxel GS1900 switches: pre-auth stack overflow reaches CISA KEV after GreyNoise catches an actor overlapping Red Heron exfiltrating configs and hashed root credentials from 996 devices in 48 countries vulnerability high
- CVE-2026-13684 / CVE-2026-13639, Synology DSM: two unauthenticated CVSS 9.8 flaws (SCGI output-encoding bug, login-logic entropy weakness) allow remote arbitrary file read/write and denial-of-service with no credentials vulnerability high
- Plugin4Shell: a zero-click design flaw breaks plugin SHA-pinning identically across Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI vulnerability high
- CVE-2026-66804, Windows Cross Device Service: a dangling COM registration reaches SYSTEM privilege escalation, and Google Project Zero publishes a general method to hunt for others vulnerability notable
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
8 bookkeeping · 4 fetch_failure_increment · 1 status · 1 added · 1 notes.
| Source | Change | From → To | Reason |
|---|---|---|---|
| cisa-kev | bookkeeping | last_successful_fetch=2026-09-18 → 2026-09-22 | fetched and used (Zyxel GS1900 KEV disposition, mandatory sweep) |
| enisa-euvd | bookkeeping | last_successful_fetch=2026-09-18 → 2026-09-22 | fetched and used (corroborated CVE-2026-7273 exploitedSince) |
| ncsc-ch-security-hub | bookkeeping | last_successful_fetch=2026-09-18 → 2026-09-22 | fetched and used (Synology DSM entry, discovery route) |
| anssi-fr | bookkeeping | last_successful_fetch=2026-09-18 → 2026-09-22 | fetched and used (corroborated Synology DSM entry) |
| heise-sec | bookkeeping | last_successful_fetch=2026-09-18 → 2026-09-22 | fetched and used (Plugin4Shell discovery route; corroborated Synology DSM risk framing) |
| projectzero | bookkeeping | last_successful_fetch=2026-09-13 → 2026-09-22 | fetched and used (CVE-2026-66804 entry) |
| hackernews | bookkeeping | last_successful_fetch=2026-09-14 → 2026-09-22 | fetched and used (corroborated Plugin4Shell scope caveat) |
| malware-news | status | candidate → active | promoted per tools/run_summary.py sources.promotion_due, 3 contributing runs, 2026-09-21T0410Z-intel among them |
| air-security | added | · → candidate | this run's one new candidate (S3), Plugin4Shell primary; listing URL corrected during Phase 5 from /blog-posts (404s) to /blog (confirmed live) |
| cnil-fr | notes | · → · | French sanctions path 404s, see fetch_failures[] |
| cert-at | fetch_failure_increment | · → · | empty listing, see fetch_failures[] |
| group-ib | fetch_failure_increment | · → · | content-free extract, see fetch_failures[] |
| bitdefender-threat-debrief | fetch_failure_increment | · → · | JS-rendered listing, see fetch_failures[] |
| inside-it-ch | fetch_failure_increment | · → · | article-page 429 rate-limit, see fetch_failures[] (covered_anyway: true) |
| acronis-tru | bookkeeping | last_successful_fetch=2026-09-11 → 2026-09-22 | fetched and used (Zyxel entry citation; changelog update to the existing Gitea CVE-2026-60004 entry) |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| cert-at | https://www.cert.at/de/meldungen | bridge | None empty-listing no drillable dated entries surfaced via bridge url or WebSearch fallback this run | none |
| group-ib | https://www.group-ib.com/blog/ | bridge:url | 200 content-free-extract listing returned a static/near-empty template shell (wordCount:1 in embedded JSON-LD; dateModified stuck at 2025-02-28), no dated post list surfaced | none |
| bitdefender-threat-debrief | https://www.bitdefender.com/en-us/blog/businessinsights/ | extract | 200 js-rendered-listing extract returned only bare dates with no post titles/links; JS-rendered listing not fully hydrated by trafilatura | none |
| cnil-fr | https://www.cnil.fr/fr/sanctions-prononcees-par-la-cnil | webfetch | 404 dead-path French-language sanctions listing path now 404s (recipe drift, page moved/renamed); the English /en/news mirror is unaffected but carries nothing newer than 202 | sources.json notes updated flagging the drift for a recipe review |
| inside-it-ch covered via alternate · should NOT be in this list | https://www.inside-it.ch/kein-beweis-fuer-datenabfluss-beim-nachrichtendienst-20 | bridge:extract → bridge:jina → webfetch | 429 rate-limited every individual article-detail page returned HTTP 429 'Vercel Security Checkpoint' on both extract/jina and plain WebFetch this run; the RSS listing itself sta | both leads reconstructed via corroborating outlets (SRF/watson.ch; NBC/SecurityWeek/TheHackerNews) |
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 9 findings (truth=7, editorial=2, advisory=0) · Claude Sonnet 5 · 10m 52s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Acronis Threat Research Unit's 2026-09-13 profiling date was cited to GreyNoise's blog, which never states it. | Re-cited to Acronis's own page (fetched and confirmed dated 2026-09-13), added as a corroborating source. | |
| F3 claim-not-supported | · | CVE-2026-6205 described as reaching arbitrary file read/write; Synology and NCSC-CH both state write-only for this CVE. | Corrected to write-only in the body; the store's cves_seen.json title already had this right. | |
| F3 claim-not-supported | · | (low confidence) 'CrossDevice.Streaming.Source' named as the COM class; Project Zero states this is the DLL filename, and calls the class 'the CrossDevice COM object' (CLSID {E9F83CF2-E0C0-4CA7-AF01-E | Corrected to name the class 'CrossDevice', its CLSID, and the DLL filename separately, matching the source exactly. | |
| F4 hallucinated-fact | · | sourcing_note credited 'CERT-FR' with relaying the advisory, but no CERT-FR source appeared anywhere in the entry. | Fetched and confirmed live CERT-FR's own advisory (CERTFR-2026-AVI-1209); added as a corroborating source and cited inline. | |
| F4 hallucinated-fact | · | All four cves[].type set to rce and tags[] included rce, but no cited source describes code execution, only arbitrary file read/write and DoS. | Corrected cves[].type to path-traversal (×3) / logic-flaw (×1) per each CVE's actual mechanism; tags[] rce replaced with path-traversal. | |
| F4 hallucinated-fact | · | heise evidence[] record put the German original in quote: with the English translation folded into publisher:, not the documented quote:(English)+original:(source-language) schema. | Corrected to quote: (English translation) + original: (verbatim German), matching the schema the body text already used correctly. | |
| F4 hallucinated-fact | · | The deep-dive rotation note's 30-day category tally was wrong against the actual 13 deep-dive entries on disk (undercounted two categories, omitted three). | Run-record note corrected to the actual tally (annual-report/identity-infra/web-app-rce/apt-campaign ×2 each, supply-chain/firewall-vpn-rce/cloud-saas/other/win | |
| F10 missed-angle | · | (low confidence) suggested the existing 2026-08-30 Gitea entry might owe a changelog note for the new Red Heron actor-overlap finding. | Declined, that entry's own facts (Gitea exploitation) are unchanged by GreyNoise's separate assessment linking a different campaign to the same actor; the regis | |
| F16 ? | · | (low confidence) priority: high questioned given the corrected non-RCE classification and no confirmed exploitation, resting on heise's editorial framing. | Kept at high, the body's own cited facts (unauthenticated arbitrary file read/write, no mitigation, full write access on an internet-reachable NAS class) indepe |
Iteration #2 NEEDS_FIXES · 9 findings (truth=2, editorial=6, advisory=1) · Claude Sonnet 5 · 9m 50s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | The 'three-day remediation deadline' clause was cited to the CISA alert page, which never states it (the fact is real but lives only in the KEV JSON's dueDate field, not linked). | Removed the clause entirely; CISA KEV remediation deadlines are US-FCEB-specific and PD-13 states they are never operational signal for this audience, so the fa | |
| F14 ? | · | (low confidence) frontmatter summary said the actor was exploiting 'since at least 17 August 2026'; GreyNoise states a single dated event, 'on or about 17 August'; the body already had this right. | Summary corrected to 'on or about 17 August 2026', matching the body and the source. | |
| F5 missing-citation | · | The AIR-disclosure-timeline clause (May test attack, June disclosure to the vendors) carried no citation; true per AIR's own timeline table but uncited as written. | Re-cited to The Hacker News, which is the actual source of the May/June dates (AIR's own blog does not state them). | |
| F5 missing-citation | · | The 'enterprise access via Gemini Code Assist is unaffected, and Antigravity CLI has no comparable SHA-pinning mechanism' clause was cited to AIR, but that fact is stated only by heise, not by AIR. | Re-cited to heise online (translated from German), the actual source of the Gemini Code Assist/Antigravity detail. | |
| F5 missing-citation | · | The trailing 'no CVE identifier has been assigned...no source reports exploitation' sentence carried no citation of its own; the nearest citation terminates the prior sentence. | Cited to The Hacker News's own 2026-09-18 checks, which state both facts directly. | |
| F5 missing-citation | · | 'NVD's SSVC assessment recorded exploitation status as none as of 2026-09-18' carried no citation; NVD per-CVE pages are blocked as citable sources by this pipeline's own rules, so the fact had no cit | Removed the NVD SSVC clause; the sentence now rests entirely on the two already-cited, citable national-CERT sources (NCSC Switzerland, CERT-FR), which independ | |
| F9 surface-contradiction | · | (low confidence) CERT-FR's advisory lists 'remote code execution' among its risk categories for the full 8-CVE bundle, in tension with this entry's file-read/write-only characterization of its four co | sourcing_note extended to disclose the tension explicitly: the four covered CVEs are typed from their own per-flaw descriptions, and the RCE risk category likel | |
| F10 missed-angle | · | Elevated over iteration 1's decline of the same suggestion: having read the Acronis Red Heron post in full, it documents a second, distinct, PRC-linked targeted campaign against this entry's own CVE ( | Appended an `update` changelog record and a matching body section to the existing entry, citing Acronis directly; registered `malware:jitterly` and `malware:six | |
| F11 editorial-advisory | · | (advisory) flagged literal instances of workflow-internal language ('Phase 0 rule 4', 'sub_agents.*.sources_attempted', 'Phase 2, caught before composition', etc.) in the run record's own Verification | DECLINED, per the settled precedent from the 2026-09-21 run's own iteration 4 (same finding, same disposition): `check_reader_text_internals` in tools/check_run |
Iteration #3 NEEDS_FIXES · 9 findings (truth=5, editorial=4, advisory=0) · Claude Sonnet 5 · 12m 12s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | sourcing_note's iteration-2 fix speculated the CERT-FR RCE risk category 'likely applies to one of the four CVEs this entry does not cover'; none of those four excluded CVEs (info-disclosure/XSS/SQLi/ | Speculative claim dropped; sourcing_note now states plainly that no source this entry cites establishes a basis for the RCE risk category. | |
| F3 claim-not-supported | · | Named 'Bitbucket, GitLab, self-hosted git' as at-risk marketplace hosts under a Hacker News citation; Hacker News names only Bitbucket/self-hosted git, and AIR's own primary never mentions GitLab, onl | Rewrote the clause to attribute Bitbucket/self-hosted git to Hacker News and GitLab specifically to heise online, with both citations. | |
| F4 hallucinated-fact | · | (low confidence) 'SSH keys, cloud credentials, internal repositories and secrets' list cited to AIR, which only states a generic 'everything the agent can reach.' | Replaced with AIR's own verbatim phrase, quoted: 'full access to every asset and every piece of data the agent can reach.' | |
| F3 claim-not-supported | · | (low confidence) Update section paraphrased Acronis's 'gets no error' as 'reports success' for SIXZUT's kill-hiding behavior, subtle drift from the source's own wording. | Corrected to 'returns with no error', matching Acronis's exact phrasing. | |
| F14 ? | · | (low confidence) upgraded GreyNoise's own hedge 'possibly working in UTC+8' to 'likely operating in UTC+8.' | Reverted to 'possibly working in UTC+8', matching the source verbatim. | |
| F5 missing-citation | · | 'fixed in the July 2026 cumulative update' and 'researcher group Calif' sat inside a Project-Zero-only citation; Project Zero states neither the date nor 'group'; Calif's own write-up is un-cited and | Added Microsoft Security Response Center's own CVE-2026-50343 page (Released: Jul 14, 2026, fetched via jina) and Calif's own write-up as corroborating sources; | |
| F5 missing-citation | · | The DSM-7.4.1-90080/'several readers noted' detail in the Detection/Hardening paragraph traces verbatim to heise but heise was not cited in that paragraph. | Added the heise citation (translated from German) directly to that clause. | |
| F5 missing-citation | · | (low confidence) the QuickConnect-specific exposure claim was uncited generic context; none of the four cited sources mention QuickConnect by name. | Generalized to 'remote or WAN-facing access' / 'remote-access configuration', removing the unsupported product-name specificity. | |
| F16 ? | · | (low confidence) flagged priority: high for reconsideration against a possible critical read, given the fresh KEV listing and confirmed at-scale exploitation; not a confirmed miscalibration. | Kept at high, considered and declined: the critical bar requires defender action time-critical to the hour or day, and a vulnerability patched for three months |
Iteration #4 NEEDS_FIXES · 6 findings (truth=5, editorial=0, advisory=1) · Claude Sonnet 5 · 8m 06s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | Iteration 3's own fix ('researcher Calif', singular) introduced a new defect: Calif's write-up ('We reported it to Microsoft') and calif.io ('We're the hacker team that industry titans call first') bo | Corrected to 'the security research team Calif'. | |
| F3 claim-not-supported | · | Opening sentence stated '(CVSS 8.8, CWE-121)' under a Zyxel-advisory citation; Zyxel's advisory states neither figure, and none of the entry's four sources states both together (CVSS/CWE come only fro | Removed the parenthetical from the body; CVSS 8.8 remains in the entry's cves[] frontmatter (a structured field, not inline prose bound by the citation rule), a | |
| F3 claim-not-supported | · | 'CERT-FR's advisory... record[s] exploitation status as unknown', checked CERT-FR's advisory (including raw HTML): it never mentions exploitation status at all, only NCSC Switzerland does. | Split the sentence: NCSC Switzerland alone is cited for the exploitation-status-unknown claim; CERT-FR is now cited only for relaying the same affected-version | |
| F3 claim-not-supported | · | (low confidence) 'Google confirmed on 2026-08-04' sat inside an AIR-only citation span; only heise states that specific date (AIR's own post gives no date for Google's confirmation). | Moved the 2026-08-04 date to its own sentence under the heise citation, which is the only source that states it. | |
| F3 claim-not-supported | · | (low confidence) 'letting the same tool be re-targeted across the whole vulnerable firmware range' overgeneralizes GreyNoise's own statement, which names the tool as explicitly targeting one model (GS | Rewritten to state GreyNoise's own two-part claim exactly: explicit targeting of GS1900-24 2.10-2.90, plus CLI options GreyNoise says could extend to other in-s | |
| F11 editorial-advisory | · | (advisory) cves[].type: path-traversal questioned against the actual CWEs (CWE-116, CWE-331, CWE-732, CWE-73), none of which is textbook path traversal. | DECLINED, considered in iteration 1's own remediation: the taxonomy's cve_types enum has no better fit for an 'arbitrary file read/write via a non-injection log |
Iteration #5 NEEDS_FIXES · 5 findings (truth=3, editorial=0, advisory=2) · Claude Sonnet 5 · 10m 31s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Detection paragraph asserted 'the CVSS vector (AV:A)' with no citation, the identical uncited-CVSS-notation defect iteration 4 removed from this entry's opening sentence, but the sweep didn't cover th | Replaced the CVSS-notation reference with Zyxel's own plain-language 'LAN-based' framing, cited to Zyxel's advisory, which states the same access requirement wi | |
| F3 claim-not-supported | · | (low confidence) Update section said the actor used a 'stolen' Proxmox authentication ticket; Acronis's report states only 'obtained', with no stated mechanism. | Corrected to 'obtained', matching Acronis exactly. | |
| F3 claim-not-supported | · | (low confidence) 'Google's own security researchers confirmed this on 2026-08-04' reversed the agency in heise's German original, where Google's researchers are the ones who RECEIVED confirmation ('er | Corrected to 'Google's security researchers received confirmation of this', matching the source's own grammar. | |
| F11 editorial-advisory | · | (advisory) entities[] omitted product:zyxel-gs1900-series-switches, the object of the entry's own new actor:red-heron relation edge; legal per docs/pipeline.md but worth adding. | Added to entities[]. | |
| F11 editorial-advisory | · | (advisory, low confidence) the Antigravity/no-SHA-pinning fact is cited to heise (corroborating) when AIR's own primary states nearly the same fact one sentence after the passage already quoted in evi | DECLINED; heise's citation is accurate and sufficient; no correctness issue, so left as-is. |
Iteration #6 CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Sonnet 5 · 8m 47s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | · | (advisory) entities: [] while affected_products[] names four products with existing registry keys; no schema violation, no relation edge depends on it. | DECLINED, same weight as the analogous Zyxel finding iteration 5 already acted on; left as-is per the verifier's own framing ("the main agent may leave it"). |
Iteration #7 CLEAN · 2 findings (truth=0, editorial=0, advisory=2) · Claude Sonnet 5 · 8m 13s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | · | (advisory) entities: [] despite affected_products[] naming four products with existing registry keys, noted as a minor completeness opportunity, not a defect. | DECLINED, same disposition as iterations 5-6; no schema or relation impact. | |
| F11 editorial-advisory | · | (advisory, low confidence) the update's added nation-state/espionage tags aren't verbatim in Acronis's report (which states 'moderate confidence... PRC-linked context' plus strategic-sector targeting) | DECLINED; the verifier itself did not escalate this to F4; the tags summarize facts the entry's own cited evidence supports. |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-22T0410Z-intel · Sonnet 5 · window 26 h · 4 entries published
Verification & coverage notes
Window: Standard class, gap_hours = 24.0 (previous run 2026-09-21T0410Z-intel, started 2026-09-21T04:10:11Z, publish_status: ok). window_hours = 26 (24h floor + 2h overlap). Mechanical KEV sweep (tools/kev_window_diff.py --window-hours 26) found exactly one in-window CISA KEV addition not previously covered by the store: CVE-2026-7273 (Zyxel GS1900 Series Switches), disposition: published as this run's deep dive.
Anti-starvation rotation (Phase 0 rule 4, v4.11): excluded from each domain's standard-tier ranking every source appearing in either of the last two fires' sub_agents.*.sources_attempted (talos, sentinellabs, huntress, kaspersky-securelist and ~114 others across both fires) before taking the top 10–14 per domain; essential-tier records exempt. Exclusion counts: S1 30, S2 32, S3 82, S4 4 (of each domain's ranked standard/candidate pool).
Coverage-backlog work (Phase 0 step 5b), all ten open rows re-checked, none published this run. Every row remains status-quo: Qilin/Touring Club Suisse, ShinyHunters/Kimberly-Clark, TheGentlemen/Ixa Systems, Krybit/UICC, NovoCure, ShinyHunters/Medela, SafePay/reichenau.at, Ville du Tampon, Familea and Communauté de communes des Pays de L'Aigle all still lack the victim statement, press pickup, or named mechanism/actor their rows require. One row gained a partial development short of its own publish bar: VMware VMSA-2026-0007 (CVE-2026-59346) now has a public PoC (0xCyberstan/CVE-2026-59346-POC), but remains desktop-hypervisor-only with no confirmed exploitation and no ESXi-reaching variant.
Borderline drops:
borderline-drop: VBS/NDB Kaspersky-cooperation administrative-investigation closure — a Swiss federal governance/oversight story (S2), largely exculpatory ("no evidence of large-scale data deletion"), with no attacker TTP and no concrete, do-now defender action; the transferable "vendor-trust governance" lesson is too generic to clear PD-11's actionability test ("would a Tier 2/3 responder act differently in the next 7 days?" — no). No primary VBS document was found, only secondary reporting (SRF, watson.ch) quoting it.borderline-drop: Google confirms Gemini breached three companies during a May 2026 security evaluation — the underlying event and Google's admission were first reported 2026-09-18 (via WSJ), three days outside this run's 26h window; S3 independently reached the same story via inside-it.ch and judged the most recent (2026-09-21) coverage a rehash of the 09-18/19 facts with no fresh in-window delta, not new signal. Also carries no Swiss-specific nexus. Dropped per PD-7 (out-of-window: primary source 2026-09-18) rather than published as a new entry; it has no home on an existing entry since the actor (Google) is distinct from the store's existing Anthropic/Meta/OpenAI eval-escape entries.
Deep-dive: 2026-09-22/cve-2026-7273-zyxel-gs1900-red-heron-kev-exploited, clears selection criterion 1 (active in-the-wild exploitation, 996 devices/48 countries, fresh CISA KEV listing) with substantial technical depth (obfuscated exploit-tool internals, actor-overlap forensics, LLM-assisted-tooling analysis). The prior 30 days' 13 deep dives break down as annual-report/identity-infra/web-app-rce/apt-campaign ×2 each and supply-chain/firewall-vpn-rce/cloud-saas/other/windows-lpe ×1 each; network-stack-rce has not appeared, so no rotation demotion applies. window24h.deep_dives_today was 0 before this run.
Verification iteration 1 remediation (7 truth, 2 editorial; NEEDS_FIXES): fixed a mis-citation in the Zyxel entry (the Acronis profiling date was attributed to GreyNoise's blog, which never states it; re-cited to Acronis's own page, added as a corroborating source); corrected the Windows COM entry's naming of the dangling registration (it named the DLL filename "CrossDevice.Streaming.Source" as if it were the class name; corrected to "CrossDevice" class, CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}, DLL CrossDevice.Streaming.Source.dll); corrected the Synology entry on four points; CVE-2026-6205 was said to reach arbitrary file read/write, but both Synology and NCSC-CH state write-only for that specific CVE (corrected in body and cves[]); all four cves[].type were rce despite none of the cited sources describing code execution (corrected to path-traversal ×3, logic-flaw ×1, matching each CVE's actual mechanism); the sourcing_note credited "CERT-FR" with relaying the advisory but no CERT-FR source was ever cited, added CERT-FR's own advisory (CERTFR-2026-AVI-1209, fetched and confirmed live) as a real corroborating source; the heise evidence[] record put the German original in quote: with the English translation folded into publisher:, corrected to the documented quote:(English) + original:(German) schema. Two low-confidence editorial findings considered and declined: (a) whether the new actor:red-heron registration owes the store's existing 2026-08-30 Gitea entry a changelog note, declined, since that entry's own facts (Gitea exploitation) are unchanged by GreyNoise's separate assessment linking a different campaign to the same actor; the registry's own red-heron summary and relation already carry the connection; (b) whether Synology's priority: high rests too heavily on heise's editorial framing given the corrected non-RCE classification, kept at high: the body's own cited facts (unauthenticated arbitrary file read/write, no mitigation, full write access on an internet-reachable NAS class) independently support the bar regardless of heise's framing.
Verification iteration 2 remediation (2 truth, 6 editorial, 1 advisory, corrected from the verifier's own reported 2/5/1, which undercounted by one against its own 9-item findings list; F5–F10 are editorial per the definition's own taxonomy, so the four separate F5 citation findings plus F9 and F10 total 6; NEEDS_FIXES): removed the Zyxel entry's uncited "three-day remediation deadline" clause (also non-operational for this audience per PD-13, independent of the citation problem) and corrected an "since at least 17 August" overclaim in its frontmatter summary to match the body's own, source-accurate "on or about 17 August"; fixed three uncited/mis-cited clauses in the Plugin4Shell entry (the AIR disclosure timeline is The Hacker News's own fact, not AIR's; the Gemini Code Assist/Antigravity carve-out traces to heise, not AIR; the closing no-CVE/no-exploitation sentence is The Hacker News's own 2026-09-18 finding); removed the Synology entry's uncited NVD SSVC clause, leaving the exploitation-status-unknown claim resting on the two already-cited, citable national-CERT sources; extended the Synology sourcing_note to disclose that CERT-FR's advisory-wide risk list names remote code execution for the full eight-CVE bundle, while this entry's four covered CVEs are typed from their own per-flaw descriptions. One elevated finding reversed iteration 1's decline of the same suggestion: having read Acronis's Red Heron report in full, it documents a second, distinct, PRC-linked targeted campaign against the same CVE (CVE-2026-60004) the store's existing 2026-08-30 Gitea entry covers only as opportunistic cryptomining, appended an update changelog record to that entry (see below), registering malware:jitterly and malware:sixzut. One advisory finding declined: the run record's own notes carry workflow-internal language ("Phase 0 rule 4", "sub-agent", etc.), which is exactly what the 2026-09-21 run's own iteration 4 settled as correct and expected here; check_reader_text_internals is scoped to entry surfaces only and never walks the run record, and the master prompt's own style rules say selection/mapping rationale belongs in the run record.
Changelog update to 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev: Acronis Threat Research Unit's 2026-09-13 report on a Chinese-speaking, PRC-linked actor (Red Heron) surfaced during this run's Zyxel research was found, on a full read, to describe a second and materially different exploitation of the exact CVE this existing entry already covers; the entry's own opportunistic-cryptomining framing is accurate as far as it goes but incomplete against Acronis's targeted-campaign findings (1,386 scanned instances, confirmed compromises in five countries, a Proxmox-cluster escalation, and a new implant/rootkit pair left on the actor's own exposed staging server). Appended as a non-internal update record with a matching body section; updated_at floats the entry per the record's type: update.
Verification iteration 3 remediation (5 truth, 4 editorial, 0 advisory; NEEDS_FIXES): dropped a speculative claim iteration 2's own fix introduced in the Synology sourcing_note (guessing which excluded CVE the CERT-FR RCE risk category belonged to, when none of the excluded CVEs describe code execution either); corrected the Plugin4Shell entry's GitLab attribution (named under a Hacker News citation that doesn't mention GitLab; split so Bitbucket/self-hosted git cite Hacker News and GitLab cites heise) and replaced an invented "SSH keys, cloud credentials, internal repositories and secrets" list with AIR's own verbatim "every asset and every piece of data the agent can reach"; fixed a paraphrase drift in the new Gitea update section ("gets no error", not "reports success", for SIXZUT's kill-hiding behavior) and an upgraded hedge in the Zyxel entry ("possibly", not "likely", working in UTC+8); added Microsoft's own CVE-2026-50343 page (released 2026-07-14, fetched via jina) and Calif's write-up as sources for the Windows COM entry's predecessor-CVE date and researcher attribution, replacing an uncited "July 2026 cumulative update" and an unsupported "researcher group" framing; added a missing heise citation to the Synology entry's DSM-7.4.1-90080 detection detail and removed an unsupported QuickConnect-specific claim no cited source states. One low-confidence priority question (Zyxel high vs critical) considered and declined: patched three months ago with an adjacent-network-only exposure, it does not meet the critical bar's hour/day urgency test despite the confirmed at-scale campaign.
Verification iteration 4 remediation (5 truth, 0 editorial, 1 advisory; NEEDS_FIXES): corrected iteration 3's own "researcher Calif" fix, which introduced a new defect, Calif's write-up and its own site both speak in first-person plural ("we", "the hacker team"), so it is a team, not a solo researcher; removed an uncited "(CVSS 8.8, CWE-121)" parenthetical from the Zyxel entry's opening sentence (no source states both together; CVSS 8.8 stays in the entry's structured cves[] frontmatter, and "stack-based buffer overflow" already conveys CWE-121 in plain language); split a Synology citation that credited CERT-FR with recording exploitation status as unknown when only NCSC Switzerland's advisory actually says so (checked CERT-FR's raw HTML: zero mentions of exploitation status); moved a Plugin4Shell date ("Google confirmed on 2026-08-04") from an AIR-only citation span to heise, the only source that states it; corrected a Zyxel overgeneralization that turned GreyNoise's "explicitly targets GS1900-24 firmware 2.10-2.90, with CLI options that could extend to other in-scope firmware" into a flat claim about "the whole vulnerable firmware range". One advisory item declined: the Synology entry's path-traversal/logic-flaw typing (vs. its actual CWEs) is a taxonomy-coverage gap, not a mis-transcription, no cve_types value fits "arbitrary file read/write via a non-injection logic bug" better.
Verification iteration 5 remediation (3 truth, 0 editorial, 2 advisory; NEEDS_FIXES): the fifth iteration was tasked with hunting cumulative cross-iteration inconsistencies rather than fresh ground, and found exactly that shape twice, the Zyxel entry's Detection paragraph still asserted an uncited "(AV:A)" CVSS-vector notation that iteration 4's sweep of the opening sentence had missed (fixed the same way, by citing Zyxel's own plain-language "LAN-based" framing instead); the Gitea update section's "stolen" Proxmox ticket was corrected to Acronis's own "obtained", and the Plugin4Shell entry's "Google's own security researchers confirmed this" was corrected to "received confirmation of this", reversing an agency error introduced when translating heise's German passive construction. Two advisory items: added product:zyxel-gs1900-series-switches to the Zyxel entry's entities[] (the object of its own new relation edge, legal without it but more complete); declined re-pointing the Plugin4Shell Antigravity citation from heise to AIR's own primary, since heise's citation is accurate and the change would carry no correctness benefit.
Verification iteration 6 (CLEAN, unconfirmed): first CLEAN verdict on this run, a full cold re-read with every source re-fetched fresh found no truth or editorial defects, only one advisory item (Plugin4Shell's entities: [] alongside product-named affected_products[], no schema or relation impact) declined and left as-is. The prior iteration (5) was NEEDS_FIXES, so this CLEAN is unconfirmed per the double-CLEAN gate; iteration 7 runs as the independent confirmation pass.
Verification iteration 7 (CLEAN, confirmed): independent cold read, every source re-fetched fresh, confirms iteration 6's CLEAN, zero truth or editorial findings, re-verifying every correction the preceding six iterations applied (Acronis profiling-date citation, CVE-2026-6205 write-only scope, CrossDevice class/CLSID/DLL naming, the LAN-based/AV:A rewrite, the Proxmox "obtained" wording, the heise confirmation-agency fix, the Calif research-team correction) against primary sources directly. Two low-confidence advisory items (Plugin4Shell entities: []; the Gitea update's nation-state/espionage tags as an editorial compression of Acronis's own hedged attribution) considered and left as-is, neither rises to a truth or editorial defect. Two consecutive CLEAN verdicts (iterations 6-7): the run publishes on a confirmed CLEAN, no cap or waiver needed.
Entity-linking correction (Phase 2, caught before composition): GreyNoise's blog title ("Open Season on Kapibala") names a malicious WordPress plugin/webshell (kapibala_plugin, used in the actor's separate WP2Shell prong), not the actor itself, GreyNoise refers to the actor throughout only as "MCA" and assesses it is "the same or related to" Red Heron. Registered actor:red-heron (not a fabricated "Kapibala" actor identity) with a hedged exploits relation to the new product:zyxel-gs1900-series-switches entity, sourcing_note disclosing the assessment's hedge explicitly.
EPSS correction (Phase 2, caught before composition): S1's cve_table reported CVE-2026-7273's EPSS as 0.32; a fresh FIRST.org API lookup this run returned 0.00315 (0.315%); S1 appears to have misread a percentage figure as the raw decimal probability. All four entries' EPSS values in this run were looked up fresh against api.first.org rather than carried from sub-agent reports.
Single-source items: none; all four published entries carry verification: multi-source (Zyxel: Zyxel PSIRT + GreyNoise + CISA KEV; Synology: Synology PSIRT + NCSC-CH + CERT-FR + heise, credibility capped at 2 per the one-assessor/several-publishers rule; Plugin4Shell: AIR Security + The Hacker News + Help Net Security + heise, Hacker News independently verified marketplace catalogs; Windows COM: Google Project Zero + MSRC).
Coverage gaps: cert-at (no drillable dated listing this run); group-ib (content-free template shell); bitdefender-threat-debrief (unhydrated JS listing); cnil-fr French sanctions path (404, recipe drift, English mirror unaffected); inside-it-ch (article-page 429 rate-limit, RSS unaffected, both leads covered anyway via corroborating outlets); ibm-xforce (standing broken recipe per the 2026-09-20 audit, not re-attempted, deferred to the next audit).
Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0, no product/supplier watchlist configured for this deployment (documented no-op per config/org-profile.yaml).
Essential-coverage: all essential-tier sources in S1's and S2's domains were attempted this run; no miss to disclose.
Sources changed: malware-news promoted candidate → active (3 contributing runs, digest-counted). air-security added as this run's one new candidate (S3), with its listing-page recipe corrected during Phase 5 (the /blog-posts URL 404s; the working listing is /blog).
← Operations dashboard · run-record contract: docs/pipeline.md