2026-09-30T0404Z-intel
One pipeline fire, in full · intel run of 2026-09-30 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-30/2026-09-30T0404Z-intel.md.
Run telemetry
- Items returned
- 6
- Duration
- 19m 55s
- Tool calls
- 14 WebFetch30 WebSearch95 bridge
- Cited sources
- 4 of 17 in slice
- Items returned
- 5
- Duration
- 27m 53s
- Tool calls
- 3 WebFetch52 WebSearch115 bridge
- Cited sources
- 3 of 24 in slice
- Items returned
- 15
- Duration
- 27m 04s
- Tool calls
- 0 WebFetch9 WebSearch
- Cited sources
- 1 of 18 in slice
- Items returned
- 7
- Duration
- 28m 27s
- Tool calls
- 2 WebFetch52 WebSearch118 bridge
- Cited sources
- 4 of 13 in slice
- Items returned
- 1
- Duration
- 6m 03s
- Tool calls
- 1 WebFetch9 WebSearch25 bridge
- Cited sources
- 1 of 2 in slice
Verification
Deep dive
·
Entries this run published (4) and updated (5)
- France's tax authority says it cut the intruders' accounts in June and July and found no data theft; it took the criminal's sale listing two months later to establish that 678,000 records had already gone
- CVE-2026-94127, F5 BIG-IP APM: unauthenticated heap overflow in OAuth-profile processing reaches RCE on the TMM data plane (CVSS 9.8)
- Kiteworks (formerly Accellion) tells customers worldwide to shut down every server for six hours after 'credible' law-enforcement intelligence of an imminent attack, no CVE assigned
- Unauthorized users had nine months of unencrypted access to a Pentagon HR file-sharing server; a defense official counts 2.76 million living and 294,000 deceased people affected, with Social Security numbers exposed
- CVE-2026-88771 / CVE-2026-88772, Citrix NetScaler ADC and Gateway: unauthenticated pre-auth RCE zero-days exploited before a patch existed (CVSS 4.0 9.5)
- CVE-2026-86950, Apple iOS, iPadOS and macOS CoreGraphics: out-of-bounds write exploited in an extremely sophisticated attack on targeted iOS users, CISA KEV-listed (CVSS 8.8)
- Swiss commune Manno (TI) confirms a cyberattack that encrypted part of its servers on 4 August 2026; SafePay is recorded listing the commune on a leak site on 28 September
- Star Blizzard's RedFlick: mass-mailed think-tank event invitations, compromised-website senders and a single-click scheduled-task chain to the CosmicPulse backdoor
- Storm-3068: a successful self-service password reset became Azure DevOps pipeline abuse and stolen Kubernetes credentials, with no malware or exploit
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
34 None.
| Source | Change | From → To | Reason |
|---|---|---|---|
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · | |
| ? | ? | · → · |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| openai-australia-post | https://openai.com/index/how-we-will-do-better-for-australia/ | direct → trafilatura → jina | 403 all-transports-failed direct 403; trafilatura no readable body; jina reader pool exhausted (HTTP 402) | item dropped (borderline-drop): only second-hand relays of the post were readable |
| inside-it-ch-article-pages | https://www.inside-it.ch/tessiner-gemeinde-wird-opfer-von-cyberkriminellen-20260 | direct → bridge:url → webfetch → jina | 429 bot-challenge Vercel Security Checkpoint on direct, bridge and WebFetch transports; jina pool exhausted (402); only RSS teasers readable | Manno entry composed from the commune's own notice; only the feed teaser and lead paragraph of the Inside IT article were readable and are cited under the article URL; Sesamvote lead dropped for lack of a readable source |
| lore-kernel-org-cve-announce | https://lore.kernel.org/linux-cve-announce/ | direct → trafilatura | None anubis-proof-of-work linux-cve-announce pages behind an Anubis challenge | VUSec BTR item dropped (borderline-drop); CVE ids were known only from VUSec and The Hacker News |
| computerweekly-de-weekly-overview | https://www.computerweekly.com/de/news/366651276/Die-Cyberangriffe-der-KW39-2026 | webfetch → trafilatura → jina | 403 all-transports-failed WebFetch 403; extract no readable body; reader pool dead | weekly DACH incident overview skipped; incidents swept through primary trackers instead |
| cybersecuritynews-langflow | https://cybersecuritynews.com/ (Langflow exploited-RCE article surfaced by searc | trafilatura → webfetch | 202 cloudflare-challenge Cloudflare 202 challenge on extract, empty WebFetch | used only as a search lead; Langflow backlog row unchanged |
Bridge invocations (this run)
16 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- ×16
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 22 findings (truth=9, editorial=7, advisory=6) · Claude Sonnet 5.5 · 17m 13s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | CISA/FSB Centre 18 attribution cited to CyberScoop, which carries only the FSB affiliation and the alias list | clause split: Microsoft cited for the CISA / FSB Centre 18 attribution, CyberScoop for the aliases | |
| F4 hallucinated-fact | · | update section claimed the defense official gave "the first scale figure that does not rest on unnamed sources"; ABC's official is unnamed too | claim removed; the section now says a U.S. defense official told ABC News the figure | |
| F4 hallucinated-fact | · | cves[] status and tags lacked poc-public although NCSC-CH and Help Net Security report public PoCs | poc-public added to both exploited CVE records and the tags; tags and cves added to the record fields | |
| F4 hallucinated-fact | · | title said the commune confirmed ransomware; its notice says only a cyberattack that encrypted data | title, headline and registry name/summary reworded; Inside IT teaser (calls it ransomware) added as a cited source after the follow-up read | |
| F4 hallucinated-fact | · | techniques[] T1027.003 (steganography) had no body sentence | sentence added, cited to Microsoft (mid-August campaign used steganography to conceal identifiers) | |
| F4 hallucinated-fact | · | main analysis said DGFiP cut every account and "the containment step worked", contradicted by the new section's sources | sentence attributed to the ministry and qualified with ANSSI's finding and the open-session gap, both cited | |
| F4 hallucinated-fact | · | (low confidence) affected_products named Microsoft Entra ID, which neither Microsoft page names | Microsoft Entra ID removed from affected_products and entities | |
| F14 quantifier-without-source | · | "two interim controls": GTIG lists three network restrictions | rewritten to name all three and which are CVE-2026-88772-specific | |
| F14 quantifier-without-source | · | (low confidence) "seven weeks" is 55 days (4 August to 28 September) | replaced with 55 days in title, headline, body and takeaway | |
| F8 needs-more-research | · | (low confidence) unreadable Inside IT article reportedly carries a stolen-data claim and a 3-4 day deadline | scoped follow-up read: article still unreadable, no second outlet found; theft claim and deadline left out and the sourcing note says so; Inside IT teaser cited | |
| F8 needs-more-research | · | linked full report adds MFA-method deletion, kubeconfigs folder, hours-scale expansion | report read; those artefacts added to the body and the report added to sources[] | |
| F9 surface-contradiction | · | (low confidence) Help Net Security says no public PoC for CVE-2026-88772 while NCSC-CH lists one | contradiction stated with attribution in the exploit-availability paragraph and as a run-record Contradiction line | |
| F5 missing-citation | · | (low confidence) "Citrix lists no workaround" uncited | cited to the watchTowr FAQ, which states Citrix has published no workaround | |
| F18 action-item-discipline | · | compound action restated the body's hunting and containment paragraphs | reduced to the task: run Mandiant's compromise checks on every exposed appliance since early September, isolate hits and halt HA sync | |
| F10 missed-angle | · | Kiteworks says the shutdown led to a previously unknown critical vulnerability found and fixed; not on the entry | update record added from Kiteworks's own release (summary, sources, evidence, actions, body) | |
| F10 missed-angle | · | (low confidence) dropped as out-of-window but inside the previous run's window | declined: primary 2026-09-28T15:00Z is outside window_hours=26 and the nexus is generic to this constituency; rebuttal in the notes | |
| F11 editorial-advisory | · | record summary carried record-keeping narration | sentence removed from the improvement record summary | |
| F11 editorial-advisory | · | workflow-internal language (sub-agent, phase plan, TodoWrite, S1-S4) in the notes | TodoWrite line removed; sub-agent and S1-S4 wording kept, operator-facing and consistent with prior run records | |
| F11 editorial-advisory | · | WatchGuard drop reason unsourced | reason restated from WatchGuard PSIRT (no known exploitation, attacker needs network access to the AP) | |
| F11 editorial-advisory | · | headline "a crafted file is enough for code execution" stronger than Apple's wording | changed to "can lead to code execution" | |
| F11 editorial-advisory | · | (low confidence) poc-public label vs a published trigger and prose exploitation path | kept: the label fits a public trigger with a described route to command execution; wording in the body says exactly that | |
| F11 editorial-advisory | · | triage sentence named three log lines but said two; record summary omitted heise caveat | triage rewritten to GTIG's two artifacts; record summary now says heise links the shutdown to the updates while the operators name no vendor |
Iteration #2 NEEDS_FIXES · 10 findings (truth=2, editorial=2, advisory=6) · Claude Sonnet 5.5 · 13m 08s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F2 source-quality | · | Inside IT cited as a rolling feed URL that will drop the item | source URL changed to the article page the feed item links to; the feed lead paragraph is what was read, and the source publisher says so | |
| F4 hallucinated-fact | · | Contradiction line said NCSC-CH edited its advisory after Help Net Security wrote; the edit (14:41:57Z) preceded the article (14:59:06Z) | ordering claim removed; the line now states the disagreement and the two timestamps as recorded | |
| F8 needs-more-research | · | entry omitted the leak-post countdown (about 3d 11h at capture, expiry around 1 October) that the follow-up read established | countdown added to the body with a hedged reading and a citation to the tracker record; sourcing note says it is read from a screenshot | |
| F10 missed-angle | · | (low confidence) drop rested on an unread primary; ACN alert reports active exploitation | primary read in full; held with page-derived reasons in the backlog row and the run-record drop line (authenticated, footprint unestablished, out-of-window, not KEV) | |
| F11 editorial-advisory | · | notes still carry workflow-internal wording (verifier iteration, sub-agent, S1-S4) | declined: operator-facing run record, consistent with prior records | |
| F11 editorial-advisory | · | summaries said the shutdown led Kiteworks to the discovery; the release credits its engineering and security activity | summary, record summary and body now say the engineering and security work during the shutdown led to the discovery | |
| F11 editorial-advisory | · | title and summary state "cut the accounts" in the entry voice | both now attribute it ("says it cut"); title and summary added to the record fields | |
| F11 editorial-advisory | · | (low confidence) summary linked "over 100 affected" to governments | summary now says Microsoft names governments and diplomatic bodies among the targets | |
| F11 editorial-advisory | · | (low confidence) takeaway treated the SafePay listing as the event's extortion phase | takeaway now calls it a listing the commune has not confirmed | |
| F11 editorial-advisory | · | (low confidence) actions[0] said the upgrade "removes" forensic evidence | changed to "can remove" |
Iteration #3 NEEDS_FIXES · 6 findings (truth=2, editorial=0, advisory=4) · Claude Sonnet 5.5 · 12m 01s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | "deletions of the existing ones" in the where-it-surfaces clause cited only to the blog, which does not mention deleting methods | clause split with clause-level citations: registrations cited to the blog, deletion of legitimate methods cited to the Q3 2026 report | |
| F4 hallucinated-fact | · | fetch_failures mitigation said the Inside IT article is not cited, but the Manno entry now cites its URL | mitigation text now says only the feed teaser and lead paragraph were readable and are cited under the article URL | |
| F11 editorial-advisory | · | summary and takeaway omitted the countdown; (low confidence) title and headline tied the listing to the 4 August event in the entry voice | summary and takeaway now carry the countdown (about 1 October); title and headline now say SafePay was recorded listing the commune on 28 September | |
| F11 editorial-advisory | · | notes keep workflow-internal wording; Kiteworks line keeps "the shutdown led it" | Kiteworks line corrected to the release wording; operator wording kept (declined, operator-facing record) | |
| F11 editorial-advisory | · | (low confidence) "decoy PDF" in the July chain is not in Microsoft's text | "decoy" removed | |
| F11 editorial-advisory | · | (low confidence) "reads iOS 27 ... as unaffected" dropped SecurityWeek's hedge | rewritten to SecurityWeek's "do not appear to be affected" |
Iteration #4 NEEDS_FIXES · 4 findings (truth=3, editorial=0, advisory=1) · Claude Sonnet 5.5 · 13m 31s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | techniques T1119 (Automated Collection) added with no sentence describing automated collection | Update section now states, cited to The Hacker News, that data was pulled through the second portal using automated scraping tools that copy data page by page | |
| F3 claim-not-supported | · | (low confidence) "the first message carries no attachment" overstates Microsoft's "usually without an attachment"; Triage opener uncited | wording restored to "usually" with a clause on the attachment-first campaigns; the uncited Triage opener removed | |
| F4 hallucinated-fact | · | (low confidence) takeaway said "tested backup"; the notice says existing backups | changed to "existing backups" | |
| F11 editorial-advisory | · | notes keep workflow-internal wording (sub-agent, S1-S4, verifier iteration) | declined, operator-facing record consistent with prior records |
Iteration #5 CLEAN · 5 findings (truth=0, editorial=0, advisory=5) · Claude Sonnet 5.5 · 12m 14s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | · | (low confidence) sentence said all 22 backlog rows were re-gated, but three carry no dated note and one says not worked | sentence corrected to nineteen of 22 re-gated, naming the rows not re-read | |
| F11 editorial-advisory | · | (low confidence) "custom request headers" may steer hunters away from NSC-style header names | reworded to "HTTP request headers, including NSC-prefixed ones" | |
| F11 editorial-advisory | · | (low confidence) two related SSPR entries not linked in references[] | both added to references[] (the Storm-2949 SSPR kill chain and the Entra ID SSPR enumeration entry) | |
| F11 editorial-advisory | · | (low confidence) alias list folds the downloader public names into the backdoor key | kept: the key covers the family and the registry summary states the split; left for the audit | |
| F11 editorial-advisory | · | workflow-internal wording in run-record notes (raised in iterations 1 to 4) | declined, operator-facing record consistent with prior records |
Iteration #6 CLEAN · 5 findings (truth=0, editorial=0, advisory=5) · Claude Sonnet 5.5 · 13m 06s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | · | (low confidence) "replacing free Proton and Microsoft consumer mailboxes" and the summary's "sent from compromised websites" overgeneralise the compromised-website senders, which Microsoft scopes to t | left as advisory; no truth or editorial finding, entry unchanged after the confirmed CLEAN | |
| F11 editorial-advisory | · | (low confidence) "build-agent egress" cited to Microsoft is the entry's own inference | left as advisory | |
| F11 editorial-advisory | · | vendor's 27 September notice that self-hosted Advanced Forms customers should contact Support is not mentioned, though the action item points the same way | left as advisory | |
| F11 editorial-advisory | · | workflow-internal wording in run-record notes (raised in iterations 1 to 5) | declined, operator-facing record | |
| F11 editorial-advisory | · | (low confidence) alias list folds the downloader public names into the backdoor key | left for the audit, as in iteration 5 |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-30T0404Z-intel · Sonnet 5.5 · window 26 h · 4 entries published
Verification & coverage notes
Coverage window: standard (gap_hours=23.98, window_hours=26); no catch-up disclosure required.
Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 --run-id found one CISA KEV addition not covered by the store, CVE-2026-86950 (Apple CoreGraphics, added 2026-09-29). It is published as a new entry (2026-09-30/cve-2026-86950-apple-coregraphics-zero-day-kev); S1 confirmed catalog version 2026.09.29 is the latest and no addition followed it (work/2026-09-30T0404Z-intel/kev-window.txt).
New entries (4): Apple CoreGraphics CVE-2026-86950 (vulnerability, high; exploited against targeted iOS users, KEV-listed); Manno (TI) commune ransomware (incident, notable; Swiss communal administration, victim's own notice, SafePay claim attributed only); Star Blizzard RedFlick (threat, notable; Russian state actor, governments and diplomatic bodies among named targets, new single-click delivery chain); Storm-3068 SSPR to Azure DevOps to Kubernetes credentials (threat, notable; Microsoft DART first-party case).
Updates (5): Citrix NetScaler CVE-2026-88771/88772 (update, priority stays critical): Google GTIG/Mandiant campaign since early September, post-exploitation persistence, exploit availability for 88772, interim controls for 88772 only, EOL branches, and the Rhineland-Palatinate municipal shutdown with heise's link to NetScaler kept as heise's assessment; F5 BIG-IP APM CVE-2026-94127 (improvement, no float): watchTowr's public trigger of 2026-09-23 that the entry never recorded (a store gap found by S1, dated outside the window, so it ships as an improvement and not as news); DGFiP tax-authority intrusion (update): ANSSI's own incident report of 2026-09-29; Pentagon DMDC breach (update): a defense official's figure of 2.76 million living and 294,000 deceased replaces the earlier estimate of about four million; Kiteworks shutdown warning (update, added after verifier iteration 1): Kiteworks's own release of 2026-09-28 says its engineering and security work during the shutdown led to a previously unknown critical vulnerability being found and fixed in a capability used by under 1% of customers, with no indication of exploitation.
Source allocation: 97 sources attempted by the previous two fires were excluded from the rotational slices as belt-and-braces (state-summary.json rotation cursor built normally). S1 and S4 fell back to cursor-only ranking because the exclusion would have left them empty (every breaches source had been attempted in both prior fires); S4 was also given the six unallocated breaches-tagged sources (bleepingcomputer, piyolog, ransom-isac, troyhunt, venarix, zaufana-trzecia-strona). Slices: S1 17, S2 24, S3 18, S4 13; every record has a ledger row, so no continuation was needed.
Backlog work (state/coverage_backlog.md): nineteen of the 22 open rows were re-gated on today's facts and no row was struck (the Siemens S7 advisory AA26-231A row, the Spring Ring row and the four-item PD-11(d) row were not re-read, and the research-blog row was not worked). No change on seventeen; DIVD shows a partial development (technical vulnerability, not NetScaler, and an AI-agent post-exploitation phase; product and class undisclosed; fuller update promised 2026-10-01) and is held one cycle. Four new rows opened: MikroTik RouterOS CVE-2026-84411, IBM Guardium CVE-2026-85542, ARA-Region Lyss-Limpachtal (SafePay claim), Netech AG (Payload claim). Manno (TI), previously tracked only through a leak-site claim in S2/S4 leads, is published now that the commune's own notice was read.
- borderline-drop: MikroTik RouterOS CVE-2026-84411 (pre-auth integer underflow, CVSS 9.8): CISA-only, no known exploitation, and CISA's text contradicts itself on the fixed build while MikroTik does not name the CVE; regular-cycle at this evidence (backlog row opened).
- borderline-drop: WatchGuard AP below 3.4.8 (CVE-2026-101891 / CVE-2026-86102, CVSS 4.0 9.3): NCSC-CH advisory 13007 exists, but WatchGuard's PSIRT says it is not aware of exploitation and the attacker needs network access to the AP; regular patch cycle.
- borderline-drop: Zimbra Collaboration 10.1.21: the headline password-recovery flaw has no CVE yet, nothing is exploited, and the store already carries the exploited SNMP flaw fixed in 10.1.20; regular patch cycle.
- borderline-drop: IBM Guardium Data Protection CVE-2026-85542 (CVSS 3.1 8.8): ACN's alert AL04/260928/CSIRT-ITA reports active exploitation of a patched flaw (needs an authenticated remote user; GIM bundle import injects arguments into
tar), but the alert is dated 2026-09-28 (outside the window), the flaw is not KEV-listed and the product's footprint in the constituency is unestablished; the primary was read in full after verifier iteration 2 and the backlog row now carries its facts. - borderline-drop: Ticino eAutoindex delta (Ticino as a further victim of the vehicle-lookup scraping, paid lookups from 2026-11-01): out-of-window, primary 2026-09-28, and the delta is one more canton disclosed around 2026-09-03 plus a fee control.
- borderline-drop: FTAPI (Munich secure file-exchange vendor) ransomware: the vendor states its platform and customer systems were unaffected, no Swiss customer link is established, no access vector is stated; the fraud caution for customers is its own.
- borderline-drop: ENISA Threat Landscape 2026: out-of-window (published 2026-09-22) and an awareness and statistics report with no change to what a responder does in the next seven days.
- borderline-drop: Lomazzo (IT) commune mailbox takeover used to send fake fines: small foreign commune, vector and scale unstated; the trusted-sender pattern is already carried by the Martigny-Combe and Revolut entries.
- borderline-drop: DIVD agentic-AI breach: held in the backlog until DIVD's promised 2026-10-01 update names the product or class.
- borderline-drop: Fakturownia.pl breach (the same actor's third Polish victim): Polish SME invoicing SaaS, no Swiss or public-sector link, exploit chain is the actor's claim relayed by one outlet.
- borderline-drop: ShinyHunters/FBI Dutch-police and FBI-video delta: law-enforcement colour, not defender-relevant; the arrest is already recorded.
- borderline-drop: OpenAI's four Australian incidents: Australian agencies, second-hand (the OpenAI post returns 403 to every transport), and the AI-agent thread already has seven entries.
- out-of-window: NeedyMantis (Microsoft Threat Intelligence, primary 2026-09-28T15:00Z) and the ChatGPT Custom-GPT ClickFix campaign (Huntress, primary 2026-09-28T20:00Z), window_hours=26; both are also generic-relevance items, so neither is a backlog row.
- borderline-drop: MSP360-to-ScreenConnect RMM phishing (unattributed, generic RMM hardening); VUSec Branch Target Reuse (academic Spectre-v2 variant, kernel mitigations merged, needs local code); DarkSword iPhone Duo lure (consumer scam lure for a chain Apple patched in March); MCP Python SDK OAuth flaw (library flaw, no CVE, no exploitation).
- borderline-drop: Junta de Andalucía (MedusaLocker), Alaxione (ChimeraZ), CENELEC/CEN (Everest), Netech, ARA Lyss and SafePay's other Swiss listings: claim-only under PD-6 or out of nexus; the last two are backlog rows.
- borderline-drop: CISA ICS advisories of 2026-09-29 other than MikroTik, ENISA EUVD criticals (AiSOC, GLPI, Ziroom), Mozilla MFSA 2026-97 to 100, Chrome 154.0.8037.92/.93, PyJWT and decompress advisories: regular patch cycle, none exploited.
- Single-source:
2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chainand2026-09-30/storm-3068-sspr-azure-devops-kubeconfig-theft: Microsoft's own telemetry and casework (Admiralty B, original vendor research); no independent second observation exists.2026-09-30/manno-ti-commune-ransomware-safepay-claim:single-source-victim, the commune's own notice; SafePay's role is a tracker-recorded claim. - Contradiction:
2026-08-15/france-dgfip-tax-authority-credential-intrusion: the ministry's August statement attributed the missed detection to the attack's sophistication, while The Hacker News reports that ANSSI's report calls the attack unsophisticated; the update states both with attribution and the earlier statement stays attributed to the ministry. - Coverage gaps: inside-it-ch (essential; article pages return a Vercel checkpoint 429 on every transport and the reader pool is exhausted, so only RSS teasers were readable; the Manno and Sesamvote articles were not read); openai.com (403); lore.kernel.org (Anubis); computerweekly.com/de (403); cybersecuritynews.com (Cloudflare 202); cyberattaque-org (connection reset); securityaffairs and proofpoint (S3 slice: no drill-down URLs on any transport tried); msrc-blog (SPA shell after a 301); wiz-blog (feed live, newest item 2026-09-01); ncc-research and prodaft (listings carry no dated posts); censys.com/advisory listing (timeout; per-advisory pages read fine).
- Essential-coverage: none missed; all 17 essential records were attempted (inside-it-ch as noted above).
- The jina reader credential pool was exhausted (HTTP 402 on all keys) across every domain this fire, a normal condition;
extractand the bridge recipes covered every source that mattered. - Candidate sources: added
anssi-cyber-gouv-actualites(ANSSI now publishes incident reports under cyber.gouv.fr/actualites; RSS works) andfuitesinfos(French breach tracker already cited in standing backlog rows). Not added for lack of a working recipe:censys-advisories(S1: per-CVE advisories with exposure by country, listing times out) andrsi-info-ticino(S2: Ticino regional broadcaster, no RSS). - Recipe fixes applied from the sub-agent reports: rss_url set for volexity, zscaler-threatlabz, talos, group-ib and infoguard-ch; recipe notes for technadu, cnil-fr, ransomware-live, inside-it-ch, venarix, ec-digital-strategy-newsroom, enisa, zaufana-trzecia-strona and ico-uk (
sources_changed[]). - Store observation for the next audit (S4):
entries/2026-08-23/martigny-combe-valais-communal-mailbox-compromise.mdandentries/2026-08-28/martigny-combe-valais-municipal-email-compromise.mdappear to describe the same Martigny-Combe mailbox compromise, a one-entry-per-finding violation to merge through changelog records. - Store observation for the next audit (S1/S2): the F5 BIG-IP APM entry lacked the public-trigger fact until this fire; Austria's NISG procedural detail (USP registration by 2027-01-01) sits on a page dated 2026-09-08 and could support a later update on
2026-09-23/austria-nisg-2026-bcs-transposition. - Source health (
tools/source_health.py): three records remain on the UNSOLVED list, all reader-dependent and already documented by the 2026-09-29 audit:cisa-directivesandcisa-news(www.cisa.gov returns an Akamai 403 to every free transport) andssd-disclosure(HTTP 202 JavaScript challenge; candidate). Re-probed this fire: no free transport reads any of the three, and the reader pool is empty. The agent-side WebFetch reads the CISA pages, so they are neither demoted nor re-pinned; the health check exercises onlyfetch_source.py, so the flag stays a false positive until reader credit is refilled. - Contradiction:
2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev: Help Net Security's text (2026-09-29) says there was no public proof of concept for CVE-2026-88772, while NCSC-CH's advisory history records an edit adding a PoC for CVE-2026-88772 at 14:41Z the same day (watchTowr's tool is a detection-artifact generator); the update states both with attribution and the CVE records carrypoc-public. - Verifier iteration 1 (declined, low confidence): the NeedyMantis out-of-window drop stands (Microsoft primary 2026-09-28T15:00Z, window_hours=26). The nexus argument (China-aligned implant in telecom, intergovernmental and government-contractor intrusions, pivoted from the DAEMON Tools compromise) is real but generic to this constituency, so the audit can recover it if it judges otherwise. Run-record wording about sub-agents and S1-S4 ids is kept: this record is operator-facing and prior records use the same ids.
- Essential-source coverage: five sources (
bacs-press,fortinet-psirt,msrc-update-guide,paloalto-psirt,watchtowr) entered the source list as essential through the v4.17 review that merged tomainafter this fire had sliced its sources, so no sub-agent was assigned them; the merge at publication carries them, and the next fire's allocation includes them. No finding of this run depends on a first-party Palo Alto, Fortinet, MSRC or BACS feed. - Verification outcome: six iterations. Iterations 1 to 4 returned NEEDS_FIXES (22, 10, 6 and 4 findings) and every truth and editorial finding was remediated or declined with a recorded reason; iterations 5 and 6 were consecutive cold CLEAN passes with advisories only, so the run publishes on a confirmed CLEAN with no residuals. The verifier's advisories left open are listed under iteration 6 for the next audit.
← Operations dashboard · run-record contract: docs/pipeline.md