2026-10-04T0405Z-intel
One pipeline fire, in full · intel run of 2026-10-04 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-10-04/2026-10-04T0405Z-intel.md.
Run telemetry
- Items returned
- 6
- Duration
- 23m 23s
- Tool calls
- 9 WebFetch20 WebSearch130 bridge
- Cited sources
- 1 of 27 in slice
- Items returned
- 3
- Duration
- 20m 47s
- Tool calls
- 5 WebFetch39 WebSearch105 bridge
- Cited sources
- 1 of 20 in slice
- Items returned
- 4
- Duration
- 15m 26s
- Tool calls
- 2 WebFetch8 WebSearch85 bridge
- Cited sources
- 1 of 14 in slice
- Items returned
- 5
- Duration
- 15m 06s
- Tool calls
- 2 WebFetch26 WebSearch85 bridge
- Cited sources
- 0 of 12 in slice
- Items returned
- 1
- Duration
- 5m 11s
- Tool calls
- 0 WebFetch8 WebSearch22 bridge
- Cited sources
- 0 of 8 in slice
Verification
Deep dive
·
Entries this run published (3) and updated (4)
- CVE-2026-93616, Check Point Security Management: pre-authentication path traversal to arbitrary script execution, exploited as a zero-day, with attacks observed on 2026-07-23 (CVSS 9.8)
- Flink refuses a corporate ransom after an Order Hub breach, so extortion actor "LPG Group" pivots to crowdfund-style individual extortion of at least 10,000 customers
- CVE-2026-88771 / CVE-2026-88772, Citrix NetScaler ADC and Gateway: unauthenticated pre-auth RCE zero-days exploited before a patch existed (CVSS 4.0 9.5)
- CVE-2026-102489 / CVE-2026-102490, Zammad helpdesk: a session-hijack remote code execution and a zammad-to-root escalation, both reported exploited since 21 September, with no fix named for the root flaw
- CVE-2026-88779, Citrix NetScaler ADC and Gateway: a SAML-triggered memory overflow still hits appliances on the September fixed builds, and Citrix confirms targeted attacks (CVSS 4.0 8.7)
- A malicious ChatGPT Custom GPT sends users to a Google Sites ClickFix page that installs a sideloaded, in-memory RAT
- A self-registered account and an unrestricted upload turn a shared recreation-management platform into a webshell and card-data foothold, and the actor returns after cleanup
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
12 notes · 3 last_successful_fetch · 3 recipe · 3 added.
| Source | Change | From → To | Reason |
|---|---|---|---|
| heise-sec | last_successful_fetch | 2026-10-02 → 2026-10-04 | fetched and used (cited in a published or updated entry this run) |
| cisa-kev | last_successful_fetch | 2026-10-02 → 2026-10-04 | fetched and used (cited in a published or updated entry this run) |
| huntress | last_successful_fetch | 2026-09-21 → 2026-10-04 | fetched and used (cited in a published or updated entry this run) |
| acronis-tru | recipe | bridge / None → fetch_method rss, rss_url https://www.acronis.com/en-us/tru/feed.xml | S3 verified the feed parses directly (12 dated items, newest 2026-09-16) |
| dcod-ch | recipe | webfetch / None → fetch_method rss, rss_url https://dcod.ch/feed/ | S2 verified the feed over the direct transport (15 dated items) |
| intrinsec | recipe | webfetch / None → fetch_method rss, rss_url https://www.intrinsec.com/feed/ | S2 verified the feed over the direct transport (10 dated items); extract on /blog/ returns only the cookie banner |
| acronis-tru | notes | · → recipe note appended | S3 verified the feed |
| dcod-ch | notes | · → recipe note appended | S2 verified the feed |
| intrinsec | notes | · → recipe note appended | S2 verified the feed |
| le-monde-info | notes | · → recipe note appended | S2 found the section path drift |
| jamf-threat-labs | notes | · → recipe note appended | S3 verified a working listing recipe |
| crowdstrike | notes | · → recipe note appended | S3 found the date caveat |
| hunt-io | notes | · → recipe note appended | S3 found the date caveat |
| gambit-security | notes | · → recipe note appended | S3 verified the listing recipe |
| huntress | notes | · → recipe note appended | S3 found the stale-date caveat |
| enisa-euvd | notes | · → recipe note appended | S1 verified the exploited-list recipe |
| fbi-cyber-alerts | notes | · → recipe note appended | S1 found the working reader |
| depthfirst | notes | · → recipe note appended | S1 found the cheaper recipe |
| citrix-netscaler-security-bulletins | added | · → status: candidate | Added 2026-10-04: first-party NetScaler PSIRT feed; two exploited zero-day bulletins in a week and no record in the store |
| vaud-soc-cyber-threat-review | added | · → status: candidate | Added 2026-10-04: cantonal government SOC monthly public threat review (Swiss canton level); S2 surfaced it, no feed route yet |
| bishopfox-blog | added | · → status: candidate | Added 2026-10-04: weaponization write-ups with public patch-state tools for KEV-class edge products; cited by the Check Point changelog record this run |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| ssd-disclosure | https://ssd-disclosure.com/advisories/ | extract → url --direct → webfetch → websearch | 202 captcha SiteGround captcha: extract returns the captcha shell, url --direct gets HTTP 202 on /feed/ and the wp-json posts endpoint, WebFetch returns an empty body, WebSearch site: finds no hits | recorded as a coverage gap; recipe unchanged (blocked on every transport) |
| inside-it-ch | https://www.inside-it.ch/ (article pages) | bridge:feed → extract | 429 vercel-checkpoint article bodies return the Vercel security checkpoint to extract, WebFetch and the reader; RSS teasers are readable | RSS teasers used as leads only (nothing in the window); not retried |
Bridge invocations (this run)
18 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- extract ×12
- jina ×3
- url ×1
- cisa-kev ×1
- pdf ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 23 findings (truth=14, editorial=4, advisory=5) · Claude Sonnet 5.5 · 14m 24s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Cyber Press (published 2026-10-03T05:36Z) says appliances 'running patched releases, including version 14.1-73.37' and gives no start time. 'Since the evening of October 2, 2026' is heise's sentence. | · | |
| F3 claim-not-supported | · | (low confidence) CTX697174 says only 'must be configured as a SAML SP OR SAML IdP'. 'Gateway or AAA virtual server' appears in the two community blogs (not in the cited bulletin). Add the blog citatio | · | |
| F3 claim-not-supported | · | (low confidence) Cyber Press carries nsaaad crashes, failovers and reboots only. 'Watchdog restarts' and 'bursts of inbound SAML requests in gateway access and firewall logs' are on no cited page (hei | · | |
| F4 hallucinated-fact | · | (low confidence) Citrix SAML guidance: 'If you are currently experiencing the impact from this issue, please contact Citrix support'; Cyber Press: 'preserve logs and crash artifacts before restarting' | · | |
| F14 quantifier-without-source | · | (low confidence) KEV 2026.10.02 (fetched live 2026-10-04) lacks CVE-2026-88779, so the KEV half holds. The absolute 'no vendor, authority or research lab' is carried by no cited page (heise: watchTowr | · | |
| F3 claim-not-supported | · | heise carries the Order Hub and under-30-minutes detail but nothing on German headquarters, Dutch operations or Austria/France; those are NL Times ('started up and wound down operations in both Austri | · | |
| F3 claim-not-supported | · | heise: case reported ('angezeigt'), Berlin data protection officer informed, external forensics; 'police in both Germany and the Netherlands' is NL Times ('filed reports with police there and in the N | · | |
| F3 claim-not-supported | · | (low confidence) heise: 'bei mindestens 10.000 Kunden' (customers only). NL Times frames the 100 ETH as a demand the group will accept 'if the company itself pays', heise as customers pooling it; the | · | |
| F3 claim-not-supported | · | (low confidence) Only heise comments, and only 'sodass diese wohl leicht verunsichert werden könnten'. NL Times says nothing on it and no outlet makes the generic-phishing comparison. | · | |
| F3 claim-not-supported | · | (low confidence) Huntress: 'taken down as of September 25' (not 'on'); the per-request obfuscation applies to the second script a tiny stager pulls ('freshly obfuscated on every request'), not to the | · | |
| F3 claim-not-supported | · | (low confidence) Huntress's carry-over list is: PowerShell launching msiexec on a GUID-named MSI in %TEMP%; a signed app started by msiexec from a fake product folder under %LOCALAPPDATA%\Programs; a | · | |
| F3 claim-not-supported | · | (low confidence) Huntress scopes this to 'In some of the incidents that we investigated'; only two of 40+ incidents are confirmed through a Custom GPT. The hedge is dropped in the body and summary. | · | |
| F14 quantifier-without-source | · | (low confidence) Huntress shows card-data hunting on server 1 and payment-module probing on server 3; for server 2 it describes 'only a few enumeration commands targeting the host and web directories' | · | |
| F3 claim-not-supported | · | (low confidence) DIVD-2026-00015 carries only the log-check script for IoCs; the process, privilege-change and lateral-connection signals are the entry's own inference (DIVD-2026-00014 says only 'coul | · | |
| F9 surface-contradiction | · | Zammad's statement (cited in the new update) says of CVE-2026-102489: 'We first received a report about this issue in August 2026 and analysed it then.' DIVD's timeline says it reported to Zammad on 2 | · | |
| F5 missing-citation | · | After this run's edit the sentence follows the RETAIL-NEWS sentence, so 'It' reads as Flink's customer notice. The notice says only 'der betreffende Zugang deaktiviert'; the Order Hub instance stateme | · | |
| F10 missed-angle | · | Bishop Fox (2026-10-01, fetched this pass) reproduced the pre-auth root chain end to end over TCP 19009 (write to /etc/cron.d), published a patch-state detection tool, and states the vendor's second i | · | |
| F18 action-item-discipline | · | The updated 2026-09-28 Citrix entry's actions[0] now also tells readers to move SAML-configured appliances to 14.1-73.41 / 13.1-64.28 / 13.1-37.282; both entries are in the same window, so the aggrega | · | |
| F11 editorial-advisory | · | Composition language: a reader-facing pointer to another entry with no link (use references[] or a cited link), and a record summary that narrates frontmatter field names ('immediate action', 'first a | · | |
| F11 editorial-advisory | · | The section restates the sentence the main body already carries and narrates the entry's edit history and its ATT&CK mapping rationale in reader-facing text; the sourcing_note grows to three sentences | · | |
| F11 editorial-advisory | · | (low confidence) Huntress calls the technique 'DLL sideloading' (a signed host loads a patched DLL planted beside it); the pinned ATT&CK 19.2 has T1574.002 DLL Side-Loading as the exact id (T1574.001 | · | |
| F11 editorial-advisory | · | (low confidence) Title states the root flaw as unfixed in the feed's voice; NCSC-NL says so, DIVD's case page lists patch status Available, and Zammad says it cannot confirm the flaw. The body surface | · | |
| F11 editorial-advisory | · | (low confidence) The Cyber Press body (deep/cyberpress.md; re-fetched this pass: '# extract: served via jina') and the SAML-guidance blog capture (raw/citrix-saml-guidance.md, reader format) came thro | · |
Iteration #2 NEEDS_FIXES · 15 findings (truth=7, editorial=4, advisory=4) · Claude Sonnet 5.5 · 13m 53s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | sk1000171 (fetched, and the gate's saved body) has no such wording; it says 'allows an unauthenticated attacker to upload and execute arbitrary scripts on the Check Point Management Server'. The quote | · | |
| F3 claim-not-supported | · | (low confidence) The guidance blog says only 'This issue is independent of the vulnerabilities disclosed in CTX697096.' 'Eight' (ACSC: '8 new vulnerabilities') and '2026-09-27' (CTX697096's own date) | · | |
| F3 claim-not-supported | · | (low confidence) CTX697096 says only 'Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.' 'Zero-days' and 'before any fix existed' are watchTowr's F | · | |
| F3 claim-not-supported | · | (low confidence) Huntress scopes the ad route to 'In some of the incidents that we investigated ... A sponsored result then led them to the Custom GPT page'. The body and summary now carry 'in some in | · | |
| F14 quantifier-without-source | · | (low confidence) KEV half verified live (catalogVersion 2026.10.02, no CVE-2026-88779). The absolute covers heise, whose headline is 'Zero-day causes crashes and code execution' and which says 'an exp | · | |
| F14 quantifier-without-source | · | (low confidence) NL Times: 'The LPG Group is not particularly well-known, and their origins have not yet been reported'; heise: 'eine bisher recht unbekannte Bande'. 'Previously undocumented' is an ab | · | |
| F4 hallucinated-fact | · | The same record's frontmatter says entries_updated: 4 and lists four updated_entry_ids, and the next bullet reads 'Updated (changelog): 4 entries'. The opening count was not updated when the Check Poi | · | |
| F5 missing-citation | · | (low confidence) The whole paragraph, including the Bishop Fox attribution added this run, carries no inline link; the indicator details are sk1000171's. The sentence on CVE-2026-85102 ('now confirmed | · | |
| F9 surface-contradiction | · | (low confidence) The newest section says Bishop Fox calls the first indicator 'the crash signature of the separate CVE-2026-91843 and not evidence of this traversal'. The main Triage line still states | · | |
| F9 surface-contradiction | · | (low confidence) The new update says Zammad 'first received a report about this issue in August 2026 and analysed it then' (before the exploitation DIVD dates to 2026-09-21), so 'zero-day' for CVE-202 | · | |
| F18 action-item-discipline | · | (low confidence) Restates the update section's hunting paragraph and the immediate_action's own 'check scheduled-task directories and the other paths' clause (clause b), and 'plan ... rotation' is not | · | |
| F11 editorial-advisory | · | Narrates frontmatter edits (immediate action, actions, technique mapping) that the section does not state; the same composition-language defect iteration 1 raised on the 88771 record. State only what | · | |
| F11 editorial-advisory | · | 'Fixed-build fields' narrates frontmatter field names, which the section does not state; same defect class as above. | · | |
| F11 editorial-advisory | · | Em dashes in reader-facing text (title, immediate_action title and body, actions[0], cves.fixed, body paragraphs 1 to 3). Legacy text, but the entry was edited this run; the other six entries in scope | · | |
| F11 editorial-advisory | · | (low confidence) The guidance blog's own Published Time is 2026-10-02T15:35:00-04:00 (heise reports the exploit circulating from the evening of 2 October and Citrix 'commented surprisingly quickly in | · |
Iteration #3 NEEDS_FIXES · 9 findings (truth=2, editorial=0, advisory=7) · Claude Sonnet 5.5 · 14m 25s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F14 quantifier-without-source | · | (low confidence) Check Point Research (https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cv | · | |
| F4 hallucinated-fact | · | (low confidence) sk1000171 (https://support.checkpoint.com/results/sk/sk1000171/) says 'This problem was fixed.' with a downloadable R82.20 Security Hotfix and Jumbo Hotfix takes; the entry's own fixe | · | |
| F11 editorial-advisory | · | (low confidence) sk1000171 carries 'allows an unauthenticated attacker to upload and execute arbitrary scripts on the Check Point Management Server'; 'Management web service' and 'arbitrary path' are | · | |
| F11 editorial-advisory | · | (low confidence) sk1000171 lists the TCP/19009 restriction as its mitigation but never says 'only'; Bishop Fox calls it 'Check Point's primary mitigation'. Say 'the mitigation Check Point names' or dr | · | |
| F11 editorial-advisory | · | (low confidence) Huntress gives no registration-to-upload timing ('After registering a new account on the platform, the attacker was able to upload malicious files'). 'Within minutes' is the entry's o | · | |
| F11 editorial-advisory | · | (low confidence) The same Huntress page description that supplies 'municipal' reads 'breach 3 municipal servers and steal payment data'. The entry cites the summary for one word and says the post is s | · | |
| F11 editorial-advisory | · | (low confidence) Huntress writes 'The behaviors (so far) carry over:' (https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat). The hedge '(so far)' is dropped in the Triage and Detection sent | · | |
| F11 editorial-advisory | · | (low confidence) Huntress scopes the sponsored-result route to 'In some of the incidents that we investigated'; the entry's title, summary and body were corrected for it in iteration 2 but the registr | · | |
| F11 editorial-advisory | · | (low confidence) The quoted words translate heise's German 'im deep web verkauft'; the body quotation carries no '(translated from German)' marker (the evidence record does). Mark it or drop the quota | · |
Iteration #4 NEEDS_FIXES · 11 findings (truth=4, editorial=2, advisory=5) · Claude Sonnet 5.5 · 14m 16s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | (low confidence) claim 05b2a64afd. The cited CERT.at page (dated 27. September 2026) carries only CERT.at's own advisory; it has no perimeter-VPN / remote-access statement (that is the watchTowr FAQ: | · | |
| F3 claim-not-supported | · | (low confidence) claim 8bb8cf5ba6. The cited NL Times page carries its half ('The LPG Group is not particularly well-known'); the heise half ('eine bisher recht unbekannte Bande') is on https://www.he | · | |
| F3 claim-not-supported | · | (low confidence) claim 30f64b4568. The NL Times page carries only NL Times' reading ('delete all user data' if 'the company itself pays' 100 ETH); heise's reading (customers raise 100 ETH in 0.005 ETH | · | |
| F3 claim-not-supported | · | (low confidence) claim 38e5f00699. The Zammad statement carries 'Exploitation is only possible on Zammad 6.5 and older' and 'Zammad 7.0 and later are not affected' but not the 6.3.0 to 6.5.4 range att | · | |
| F9 surface-contradiction | · | (low confidence) The run added RETAIL-NEWS (https://retail-news.de/flink-datenschutzvorfall-kundendaten-phishing/), which reports Flink's own customer notice of 2026-09-25: data 'könnten' have reached | · | |
| F8 needs-more-research | · | (low confidence) The entry names the script but not what it detects, so a hunter writing their own SIEM rule cannot reproduce it. The script linked from the cited page (https://csirt.divd.nl/downloads | · | |
| F11 editorial-advisory | · | (low confidence) After this run's Improvement the body says the outlets read the 100 ETH differently: only heise has the sell-on-the-deep-web threat if the pool is not reached; NL Times has 'delete al | · | |
| F11 editorial-advisory | · | (low confidence) heise: the attacked system is 'ein eigenes, eigentlich internes Bestellsystem ... in den Order Hubs ... genutzt. Das sind kleine, dezentrale Lager in Städten ... Durch diese Strukture | · | |
| F11 editorial-advisory | · | (low confidence) The no-patch value is explained in the entry only by the missing LivePatch. The sources give the reason that matters to an estate owner: Bishop Fox, 'If the method dispatches, the bui | · | |
| F11 editorial-advisory | · | (low confidence) claim be9c65fc4d. The negative claim about Citrix is true of the Citrix bulletin and blogs read this pass (they say only to follow standard incident-response processes) but it is carr | · | |
| F11 editorial-advisory | · | (low confidence) The Triage line repeats the Detection list instead of naming the benign lookalike; Huntress's IOC table flags the Canon and Stardock host binaries as 'Legitimate ... (do not block glo | · |
Iteration #5 NEEDS_FIXES cap-breach · 5 findings (truth=1, editorial=0, advisory=4) · Claude Sonnet 5.5 · 17m 20s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F14 quantifier-without-source | · | (low confidence) 'the only way' is an absolute no cited page states. The watchTowr FAQ cited for the sentence carries only 'Citrix warns that the IOCs do not cover every technique, so a clean result i | · | |
| F11 editorial-advisory | · | (low confidence) The remediation of the iteration-4 finding left a broken sentence boundary: a lowercase 'the Citrix pages...' follows a full stop, and the first sentence (nsaaad crashes, failovers, r | · | |
| F11 editorial-advisory | · | (low confidence) 'later' is a chronology no cited page states. RETAIL-NEWS (2026-09-25) reports the notice sent on Friday; NL Times is dated the same day (2026-09-25) and only heise (2026-09-26) postd | · | |
| F11 editorial-advisory | · | (low confidence) The record reverses a claim the entry made (git diff HEAD: the old body said 'The company has not disclosed the initial-access vector' and the old sourcing_note said 'No party has dis | · | |
| F11 editorial-advisory | · | (low confidence) The only source is the Huntress post dated 2026-09-30; docs/pipeline.md anchors event_date on the underlying event or primary publication, and the store convention (Check Point 2026-0 | · |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-10-04T0405Z-intel · Sonnet 5.5 · window 26 h · 3 entries published
Verification & coverage notes
Coverage window: 26 h (gap 24.0 h to 2026-10-03T0404Z-intel), a standard window. Sunday; the vendor calendar was quiet and the only fresh high-value item was the NetScaler SAML zero-day that S1 and S2 reached independently (via the ENISA EUVD sweep and a heise lead). Published 3 new entries and appended changelog records to 4 existing ones. Mechanical KEV sweep (kev-window.txt): 0 additions dated in the window (catalogue 2026.10.02); S1's store-wide KEV cross-check found two gaps, handled below. No intel/ drops (README only), so no S5.
- Verification: five iterations. Iterations 1 to 4 each returned NEEDS_FIXES with 18, 11, 2 and 6 truth plus editorial findings, all remediated and re-gated; the 2 of iteration 3 included an F4 on a legacy status field, so a further pass followed. Iteration 5 (all 184 claims answered, all
ok) returned NEEDS_FIXES with one low-confidence truth finding (an unsourced 'only way' in the 88771 Detection paragraph) and four advisories; the run ended on decision rule 5 (truth plus editorial of at most 2, no F1 or F4): the five remediations were applied and the gate re-run (57 pass, 0 warn, 0 fail), with no further verifier pass, so the final text of those three edits (88771 Detection paragraph, 88779 Detection line, Flink correction record) was checked by the gate and not by a verifier. Residual: 1. The next audit should re-read them. One advisory (the recreation entry'sevent_date) was declined with its reason. - Updated (changelog): 4 entries. The fourth,
2026-09-23/cve-2026-93616-check-point-security-mgmt-path-traversal(type update), came from verifier iteration 1's missed-angle finding: Bishop Fox's 2026-10-01 end-to-end exploit method, patch-state scanner and its reading that Check Point's indicators miss the route; S1 had logged no delta after reading only sk1000171, and a scoped follow-up (FU2) found the delta. The other three:2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev(type update: the fixed-build floor for SAML-configured appliances moves to 14.1-73.41 / 13.1-64.28 because CVE-2026-88779 is not fixed by the September builds);2026-10-02/zammad-cve-2026-102489-102490-exploited-divd-breach(type update: Zammad's own statement names 7.2.0 as the target, says 6.5 and older receive no fixes and that it cannot confirm the root flaw; both CVEs now carry the KEV listing of 2026-10-02);2026-09-27/flink-lpg-group-crowdfund-extortion-order-hub-breach(type improvement: Flink's customer notice names compromised credentials, so the earlier "vector not disclosed" statement was corrected and T1078 added). - Contradiction: Zammad. Zammad's own statement says it first received a report about CVE-2026-102489 in August 2026, which contests DIVD's framing of two previously unknown flaws exploited from 2026-09-21 (DIVD's timeline shows its report to Zammad on 2026-09-24); the entry carries both and attributes each (sourcing_note, update section).
- Contradiction: Flink data scope. Flink's own customer notice of 2026-09-25 (RETAIL-NEWS) says the additional order details (floor, doorbell name, delivery notes) may have been affected but gives no concrete indication of actual access, while heise quotes Flink saying delivery notes leaked in individual cases; the entry carries both and attributes each.
- Contradiction: CVE-2026-88779. Citrix scopes the impact to denial of service with no integrity impact; heise relays a researcher's report of a downloaded binary on a patched honeypot and a watchTowr reproduction, and ACSC says "potential exploitation". The entry carries both and states that code execution is unconfirmed (
sourcing_note), priorityhigh, notcritical. - Single-source:
2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-ratand2026-10-04/recreation-platform-upload-webshell-card-data-foothold(Huntress first-hand SOC telemetry and sample analysis; no independent confirmation found; the second names no vendor, CVE or victim, confidence medium). Lookback inclusion (PD-7 d): both Huntress posts (2026-09-28, 2026-09-30) were first coverage from the huntress record's rotational lookback. - Reduced reading: the community.citrix.com blog pages (403 to extract and WebFetch) and the Cyber Press page were read through the reader proxy; the Citrix bulletin, heise, ACSC and every other cited page were read directly.
- borderline-drop: Exchange Server September SU V2 / CVE-2026-96940, authenticated cross-mailbox read, no exploitation or PoC, regular patch cycle; published about 7 h before the window.
- borderline-drop: Dolibarr CVE-2026-89013 (CSIRT Italia reports exploitation), niche open-source ERP/CRM with no constituency deployment evidenced and no scale stated; same footing as the held IBM Guardium row.
- borderline-drop: Microsoft Digital Defense Report 2026 (annual report, found late via the msft-secblog pass, published 2026-10-01), vendor statistics and a policy piece with no defender decision; the Swiss ransomware table's caption and unit are unreadable in the PDF text (29 to 59, +103% could not be assigned a meaning), leaving only a 2% Russia-nexus notification share for Switzerland. Flagged to the audit as an annual-report calendar miss, not a recovery request.
- borderline-drop: SConnect (Thales) CVE-2026-18397, fixed since August, end of life, no exploitation, no Swiss deployment evidenced.
- borderline-drop: DTU (Denmark) breach, out of nexus, no actor, no technique beyond compromised profiles (PD-11 breach gate fails).
- borderline-drop: Oxygen Forensics DOJ complaint, provenance and ownership allegation about police forensic tooling; no adversary behavior (no evidence-bound
techniques[]for an incident entry), Swiss use unverified by any source, first reported 2026-09-24. Re-open if a Swiss licensee or authority guidance surfaces. - borderline-drop: OpenAI notices to over 100 organizations and the California AG subpoena, awareness; documents dated 2026-09-30 to 10-02 and the three covered OpenAI entries already hold the substance.
- borderline-drop: ShinyHunters "Rey" detention report, unconfirmed by any authority (Reuters via two relays), no defender consequence; revisit on an authority confirmation.
- borderline-drop: DragonForce second-stage backdoor (Lab52, 2026-10-01), single-source loader and MQTT-fallback analysis on a legacy-shape entry, no victim, sector or initial-access context.
- borderline-drop: Kiteworks "over 100 advisories" scale note (SecurityWeek roundup); MFT Server could not be confirmed from the vendor's advisory listing read this fire; the covered entry already carries the 9.5.1 floor.
- borderline-drop: WordPress CVE-2026-87902 KEV listing of 2026-09-25, the covered entry already says exploited (PD-13 bookkeeping, nothing shipped).
- borderline-drop (S1, S4 exclusions, all with reasons in the findings files): Fortra BoKS, GitLab AI Gateway CVE-2026-90970, Dell CSM, Chrome 154.0.8037.97, Mozilla MFSA 2026-97 to 103, Zimbra 10.1.21 (watch for a PoC), WatchGuard AP, OpenAM CVE-2026-105115 (watch for a PoC), Digi / cPanel / UTMStack EUVD items, Foreman, PAN GlobalProtect App, 0patch WalletService, FUJIFILM/Sharp MFP; Bundesagentur fuer Arbeit outage (agency rules out an attack), IFAPME re-post, STMicroelectronics / Neff Drexel and the Gentlemen 2026-10-03 batch (leak-site claims only), Epic Systems pause, Frontline Education, Vicksburg, LDLC, Zenfirst, ICO reprimands, Garante IQVIA fine, Polish healthcare claims.
- Backlog (
state/coverage_backlog.md): all six open rows re-gated on today's facts by S1, S2 and S4; none clears the gate, none was struck, none published. IBM MQ / Langflow: dated note appended (IBM's bulletin covers IBM MQ Appliance only); held to 2026-10-11. MikroTik CVE-2026-84411, IBM Guardium CVE-2026-85542, ARA-Region Lyss-Limpachtal, Netech: no change, held to 2026-10-14. Qilin / Touring Club Suisse: no change; strikes on 2026-10-05 as scheduled. Securitas / Everest: no change; held to 2026-10-10. No row added. - Rotation: the digest's
sources.rotationcursor ranked each domain; 49 records attempted by the previous two fires were excluded as the belt-and-braces rule says, except that S4's pool (12 breach sources, all attempted by those fires) was ranked on the cursor alone.ssd-disclosure(3 consecutive failures) was promoted to the S1 slice as a fetch-gap record and failed again. - Leads for the audit, not recovered here: ENISA Threat Landscape 2026 (published 2026-09-22, no store entry; public administration the most targeted sector), Zscaler ThreatLabz 2026 Ransomware Report (2026-09-30, listing only), Sophos "TerminalFix and Lorem Ipsum Loader" (2026-09-30, possible changelog record on the 2026-08-31 TerminalFix entry).
- Candidate sources added:
citrix-netscaler-security-bulletins(first-party NetScaler PSIRT, feed verified; S1 recommends essential tier on promotion),vaud-soc-cyber-threat-review(cantonal government SOC monthly review, no feed route yet). Recipe fixes: acronis-tru, dcod-ch and intrinsec feeds pinned (verified by S3 and S2), plus recipe notes on ten records. Surfaced but not added: IAPP news, Cybernews (feed 403; extract falls to the metered reader), Bay Area Labs. - Reader-pool use: a handful of calls to read community.citrix.com pages (S1, S2) and one Cyber Press page (this fire); no other metered fetch.
- Coverage gaps: ssd-disclosure (captcha on every transport), inside-it-ch (article bodies behind the Vercel checkpoint; teasers only), msrc-blog (landing shell, no dated posts; msrc-update-guide carried the CVE data), fbi-cyber-alerts (extract returns the terms modal; WebFetch of /PSA works, no in-window PSA), depthfirst, pwn-ai (dormant), bsi-de (weekend quiet), cert-at (quiet); Reuters, justice.gov and Telegraph pages unreachable on every transport (read through relays for dropped items only).
- Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0
← Operations dashboard · run-record contract: docs/pipeline.md