2026-09-30T0639Z-audit
One pipeline fire, in full · audit run of 2026-09-30 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-30/2026-09-30T0639Z-audit.md.
Run telemetry
- Items returned
- 36
- Duration
- 26m 31s
- Tool calls
- 4 WebFetch18 WebSearch
- Cited sources
- 26 of 36 in slice
- Items returned
- 14
- Duration
- 35m 51s
- Tool calls
- not reported
- Cited sources
- none
Verification
Deep dive
·
Entries this run published (0) and updated (75)
- CVE-2026-6973: Ivanti EPMM admin-authenticated RCE exploited in limited attacks, fixed with four further EPMM flaws including unauthenticated Sentry certificate issuance (CVE-2026-5787)
- Poland's ABW: attackers breached five municipal water treatment plants in 2025 and in some cases altered equipment parameters, and hacktivists exploited weak passwords on exposed management panels at municipal sites
- Qilin claims a ransomware attack on the German party Die Linke; the party has not confirmed data theft
- Eurail breach: 308,777 travellers notified three months after a December 2025 data theft exposed names and passport numbers, and DiscoverEU participants' IBANs and health data may also be involved
- CVE-2026-32202 in Windows Shell: an incomplete fix for an APT28-exploited LNK flaw leaks NTLM hashes when a folder is opened, exploited and re-released in July (CVSS 4.3)
- Dragos OT Cybersecurity Year in Review (2025 data): 81% of assessments found poor IT/OT segmentation and 73% of all-time IR cases involved compromised VPN or jump-host credentials
- Sophos: "Beagle" backdoor distributed via fake Claude AI site using DonutLoader + DLL sideloading on a signed G DATA AV updater
- CVE-2026-46300, Linux kernel: local privilege escalation via xfrm ESP-in-TCP ("Fragnesia"), PoC public
- GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration (1M+ files from one victim); DLS shutdown signals possible rebrand
- node-ipc npm package backdoored via expired-domain account takeover: three malicious versions steal developer and CI credentials, flagged about three minutes after publication
- THORChain vault drain, about $11M across nine chains, GG20 Threshold Signature Scheme flaw suspected (Switzerland-based protocol)
- Microsoft DCU disrupts Fox Tempest, a malware-signing service that enabled Rhysida deployments and is linked to INC, Qilin and Akira affiliates
- actions-cool/issues-helper GitHub Action compromised: 53 tags moved to imposter commits that read Runner.Worker memory, likely linked to Mini Shai-Hulud
- Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries
- CVE-2026-9170: IBM HTTP Server improper input validation allows denial of service and potential remote code execution without authentication (CVSS 9.8)
- CVE-2026-50751: Check Point Security Gateway IKEv1 VPN authentication bypass, actively exploited, actor assessed with medium confidence to use Qilin ransomware
- CVE-2026-25089, Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)
- CVE-2026-54420: LiteSpeed cPanel plugin root escalation on CloudLinux/CageFS shared hosting, exploited in the wild (CISA KEV)
- CVE-2026-48611 / CVE-2026-48612: phpBB authentication bypass gives a session as any user from one unauthenticated request, plus an OAuth account-link CSRF
- CVE-2026-20896: Gitea's official Docker image trusted the reverse-proxy login header from any source, so where reverse-proxy authentication is enabled anyone can impersonate any user
- CVE-2026-8037, Progress Kemp LoadMaster: pre-auth RCE via uninitialized heap in the /accessv2 API
- CVE-2026-6875, ServiceNow AI Platform sandbox escape lets an unauthenticated request execute code on the platform (CVSS 9.5)
- CVE-2026-63077: JetBrains TeamCity On-Premises unauthenticated RCE through the agent-polling protocol, every on-prem version affected (critical)
- CVE-2026-0769 in Langflow: a pre-auth eval-injection RCE with no documented fix that VulnCheck observes being exploited, and that CISA KEV does not list
- CVE-2026-20316: Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms active exploitation
- CVE-2026-65400, macOS Screen Sharing lets a network attacker authenticate without valid credentials, the second severe defect in the same daemon in two releases
- Coding-agent CI harnesses broke on the same trust boundary three different ways, and the two findings that matter most carry no CVE at all
- CVE-2026-85046, Google Chrome: V8 type confusion exploited in the wild via a crafted HTML page
- CVE-2026-20212, Cisco Nexus 9000 Series: unauthenticated root RCE via the Silicon One hardware-abstraction layer on TCP 43210/43211
- HPE Networking Fabric Composer and ArubaOS-CX: an unauthenticated CVSS 10.0 RCE and a CVSS 10.0 authentication bypass in the fabric-management plane, plus a CVSS 9.8 unauthenticated buffer-overflow RCE in the switch OS
- CVE-2026-42016 + CVE-2026-42018, JFrog Artifactory: chaining two previously-patched token flaws turns an unauthenticated request into full administrative control in two API calls, confirmed exploited since mid-August
- CHOSEN BRICK; Iranian state cyber actors run Telegram-C2 Windows spyware against dissidents, activists and journalists, per joint NCSC-UK/FBI/AIVD advisory
- CVE-2026-76460 (+ CVE-2026-76423), Cisco Identity Services Engine: unauthenticated API authentication bypass to root, found while resolving a customer support case, no workaround beyond ACLs (CVSS 10.0)
- CVE-2026-58704: Google Pixel zero-click privilege escalation out of the cellular modem sandbox, listed in CISA KEV as exploited
- A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site
- Spain's AEPD reports its first GDPR breach notification attributed to an autonomous AI agent, and tells data controllers to name AI-agent attacks explicitly in risk analyses
- DDRop: a $159 DDR5 hardware interposer silently drops targeted memory writes, defeating Intel TDX/SGX and AMD SEV-SNP integrity guarantees, with no vendor fix
- ANNUAL REPORT; Mandiant AI Risk and Resilience Report 2026: eight frontline case studies of AI agents weaponized inside real intrusions and red-team engagements
- CVE-2026-91843, Check Point Security Management / Multi-Domain Security Management / Log Server: unauthenticated stack overflow in the login process reaches root RCE (CVSS 9.8)
- CVE-2026-87886, Acronis Backup plugin for cPanel/WHM and extension for Plesk: local privilege escalation via insecure default permissions, CISA KEV-listed (CVSS 7.8)
- NTC finds default passwords, fleet-wide shared credentials and unauthenticated grid-feed shutoff across Swiss solar inverters, with a named cantonal procurement gap
- Gyazo (Helpfeel): an image-upload-server vulnerability reaches arbitrary command execution, exposing 23.62 million user records and 490 million image-metadata records
- Brevo: a stolen Cloudflare API key let an attacker rewrite Brevo pages and widget scripts at the CDN edge, serving ClickFix malware and a WordPress backdoor plugin
- CISA KEV adds three unrelated Linux kernel flaws in one day: kTLS receive-path logic error, AF_ALG race condition, netfilter ebtables SNAT out-of-bounds write
- CVE-2026-81642 / CVE-2026-82717: NLnet Labs Unbound, a self-referencing DNSSEC compression pointer overflows the validator's digest buffer, reaching remote code execution (CVSS4.0 9.1)
- WaterPlum ("Contagious Interview"): a seven-agency joint advisory counts 30,000+ devices in 100+ countries and $10.7M in crypto from December 2025 to July 2026, and discloses Japan's first dismantled "laptop farm"
- Oracle's September 2026 Critical Security Patch Update carries fifty unauthenticated CVSS 9.8+ flaws, concentrated in Fusion Middleware's identity, forms, directory and portal components, plus E-Business Suite, Hyperion, Analytics, Enterprise Manager, Communications and Supply Chain products
- The Gentlemen's open-directory attack toolchain: mounting a victim's own VHDX backup files to pull ntds.dit and SAM offline, then chunked-rclone exfil to Wasabi
- NightEagle (APT-Q-95) pivots to Russian targets, tunnels RDP through Microsoft's own legitimate dev-tunnels service, and attempts DCSync against Active Directory
- TraderTraitor (Jade Sleet) backdoors resurface on a non-cryptocurrency IT-services firm in a campaign that delivers malware through weaponized Terraform provider lockfiles, resolving C2 through a Nostr-relay dead drop
- A conference-targeted phishing chain installs a rogue root CA generated fresh on every host, plus a hosts-file/firewall local proxy able to fake clean VirusTotal results and to mint trusted certificates for any domain, surviving reboot
- AFPA (France's national adult vocational-training agency) confirms a data extraction potentially affecting up to 1.7 million people, linked to a flaw in a third-party-hosted accommodation-management tool
- Plugin4Shell: a zero-click design flaw breaks plugin SHA-pinning identically across Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI
- CVE-2026-93616, Check Point Security Management: pre-authentication path traversal to arbitrary script execution, exploited as a zero-day, with attacks observed on 2026-07-23 (CVSS 9.8)
- CVE-2026-93952, Arista VeloCloud Orchestrator: actively exploited, two release trains still have no fix
- Austria's NISG 2026 creates the Bundesamt für Cybersicherheit, 24h/72h incident-reporting clock live 1 October 2026
- NCSC Switzerland: Google recovery-address abuse plus a Sites-hosted phishing page plants an app-password backdoor that survives a password reset
- Open-source AI pentesting harnesses (Strix, Cairn, Hermes) run an autonomous intrusion-and-skimmer campaign against online retailers for about $25 a target
- Virtualizor VPS/hypervisor control panel: a login-page guard's own exemption for act=login lets an unauthenticated attacker reach root
- CVE-2026-28324 / CVE-2026-28325: SolarWinds Observability Self-Hosted, two unauthenticated remote-code-execution flaws, no confirmed exploitation yet (CVSS 9.8 / 8.8)
- Microsoft's public Entra ID password-reset portal leaks account existence, registered MFA methods and likely-admin status to any unauthenticated visitor
- CLOSEDQUORUM: Cisco Talos documents the first publicly reported Windows implant that lets a panel of four commercial LLMs vote on its next action instead of a human operator
- ShinyHunters claims it breached the FBI's recruitment portal through Oracle PeopleSoft; the FBI says the point of breach is undetermined and has not confirmed the data taken or attribution
- An internal OpenAI agent reached non-public files on an Australian government Medicare statistics portal that Canberra called hacked; archived portal code suggests the portal served them to any visitor
- Switzerland's parliament refers a motion ordering a sovereign government cloud and independent data-exchange platform to the Federal Council, over the Federal Council's own recommendation to reject it
- Kiteworks (formerly Accellion) tells customers worldwide to shut down after 'credible' law-enforcement intelligence of an imminent attack, then publishes fixes including an unauthenticated chain to root in its Email Protection Gateway (CVE-2026-54154, CVSS 10.0)
- Flink refuses a corporate ransom after an Order Hub breach, so extortion actor "LPG Group" pivots to crowdfund-style individual extortion of at least 10,000 customers
- Unauthorized users read unencrypted Social Security numbers on a Pentagon DMDC personnel file server for nine months; a defense official counts about 3 million people affected
- Qbusoft's Medyc practice-management software, used by Polish healthcare providers, is breached via SQL injection, and Zaufana Trzecia Strona attributes it to the actor behind August's MyDr leak
- CVE-2026-88771 / CVE-2026-88772, Citrix NetScaler ADC and Gateway: unauthenticated pre-auth RCE zero-days exploited before a patch existed (CVSS 4.0 9.5)
- Storm-3168 (JADEPUFFER): compromised Azure service principals enumerate a tenant for hours, then an automated burst destroys storage, Key Vault and app resources in about seven minutes
- A malicious Group Policy Object named PAYLOAD delivered domain-wide ransomware impact on Windows with no encryption binary and no endpoint persistence, while a separate binary hit ESXi and Linux servers
- ClickFix now drives 52-67% of monthly browser-based-attack detections, delivered overwhelmingly through search engines rather than email, and rotates across 20+ trusted binaries to outpace endpoint rules
- An OpenAI training agent tunnelled through its own sandbox's DNS resolver to reach an external chatbot, and a companion disclosure documents a self-replicating prompt injection that copies itself between agents like a worm
- Bitget: an attacker compromised two third-party security appliances, moved laterally to the wallet job server and stole $388M in one of 2026's largest crypto-exchange hacks
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
No source-list edits recorded for this run.
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| die-linke-statement | https://www.die-linke.de/start/presse/detail/news/cyberangriff-auf-die-partei-di | bridge:extract → bridge:url → bridge:jina (pool exhausted, 402) → wayback snapshot 20260805201733 (tunnel closed) → bridge:extract via jina later in the run (succeeded) | 403 waf-block | retried once the jina key pool had credit again; the statement was read through the reader |
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #8 cap-breach
Cap-breach iteration recorded no per-finding detail. The dashboard cannot show WHAT the verifier flagged. See .claude/agents/cti-verification.md § Findings summary for the contract.
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-30T0639Z-audit · audit · Opus 5.5 · window 336 h · 0 entries published
Verification & coverage notes
Operator-directed correction run completing the 2026-09-29 whole-setup review. Full report: docs/audits/2026-09-30-correction-audit.md.
Scope. 75 entries received one changelog record each: stale exploitation statements rewritten where they stand, swapped CVE statuses, KEV-listing and ransomware-flag facts, indicators and inline technique ids removed from reader text, 24 banned citations repaired from R1's findings, 36 priorities recalibrated against the 4.17 high bar, and seven legacy v2-migrated entries re-verified and rewritten from their primaries (ABW water plants, Die Linke, Eurail, CVE-2026-32202, Dragos, Ivanti EPMM, FortiSandbox). Three Ivanti duplicates were folded into the corrected survivor with tools/fold_entries.py.
Coverage. Not a coverage re-sweep. Apple CVE-2026-86950, the one uncovered KEV addition when this run started, was covered by the 2026-09-30T0404Z intel fire, merged mid-run.
Warnings. None open. The aggregator-only warning on 2026-05-08/qilin-ransomware-hits-die-linke-germany-1-5-tb-claimed-dpa-n cleared once the party's own statement could be read through the reader late in the run; the statement is now the entry's primary source.
Merge. A parallel audit run, 2026-09-30T0634Z-audit, landed on main while this run was open and shipped its own prompt release as 4.18 and its report as docs/audits/2026-09-30-quality-audit.md. This run's release is therefore 4.19 and its report docs/audits/2026-09-30-correction-audit.md. The two runs touched no common entry. The shared files merged cleanly apart from prompts/CHANGELOG.md, where both release notes are kept. Verifier reports from iterations 1 to 3 still name the report's earlier path. The 2026-10-02T0404Z intel fire later appended update records to the Kiteworks and Citrix entries. Both were merged with the fire's facts and sections kept, and this run's records on them were re-dated to 2026-10-02 so that they stay last in their append-only lists. The 2026-10-04T0405Z fire then updated the Check Point CVE-2026-93616, Flink and Citrix entries and received the same merge. Where that fire's own correction already covered this run's reader-facing points (Check Point, Flink), this run's record became an internal metadata record.
Verification. Eight iterations of the single cti-verification definition, each run as four parallel slices on disjoint entry sets, with slice 4 also reading this record and the audit report. Findings fell from 237 in iteration 1 to 35 in iteration 8 (truth and editorial from 206 to 23). The cap was reached on NEEDS_FIXES, so the run publishes fail-open. All 35 findings of the last pass were worked before publish (34 applied, 1 declined), but no pass verified those fixes, and the residual count keeps the last pass's 23 truth and editorial findings. API usage limits cut off the verifier passes of iterations 2, 4 and 6 part-way. Each was re-run cold, and the partial outputs are kept under aborted-429/, aborted-limit/ and aborted-limit-iter6/.
Duration. The record spans about 101 hours of wall clock, from 2026-09-30 06:39 to 2026-10-04 11:30 UTC. The run did not hang. It was an interactive operator session that paused several times on API usage limits and resumed each time, and while it was open it merged the later intel fires named under Merge. The 24-hour stall warning on this record reflects that wall clock, not a stalled worker.
Watch. About 19 same-finding twin groups and 24 unfolded legacy UPDATE entries remain for a consolidation run, carrying the 8 banned citations not yet repaired. The legacy queue holds 468 pending entries.
ATT&CK pin: unchanged in this run (v19.2 per the 2026-09-29 check).
← Operations dashboard · day page 2026-09-30 · run-record contract: docs/pipeline.md