2026-10-06T0405Z-intel
One pipeline fire, in full · intel run of 2026-10-06 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-10-06/2026-10-06T0405Z-intel.md.
Run telemetry
- Items returned
- 9
- Duration
- 38m 55s
- Tool calls
- 9 WebFetch27 WebSearch150 bridge
- Cited sources
- 4 of 28 in slice
- Items returned
- 4
- Duration
- 22m 54s
- Tool calls
- 7 WebFetch33 WebSearch70 bridge
- Cited sources
- 1 of 21 in slice
- Items returned
- 5
- Duration
- 18m 24s
- Tool calls
- 1 WebFetch15 WebSearch190 bridge
- Cited sources
- 0 of 16 in slice
- Items returned
- 6
- Duration
- 24m 06s
- Tool calls
- 4 WebFetch27 WebSearch85 bridge
- Cited sources
- 0 of 18 in slice
Verification
Deep dive
·
Entries this run published (2) and updated (4)
- CVE-2026-0257, Palo Alto PAN-OS GlobalProtect: pre-auth authentication bypass via certificate reuse, marked by CISA as used in ransomware campaigns
- CVE-2026-73570, Zimbra Collaboration: a pre-auth command injection patched without a CVE in July is exploited, with probing before disclosure and root escalation, secret theft and cluster-wide movement observed
- CVE-2026-104286, Fortinet FortiMail: unauthenticated path traversal file write exploited as a zero-day, fixed in 8.0.2, 7.6.7 and 7.4.9 (CVSS 9.8)
- CVE-2026-102489 / CVE-2026-102490, Zammad helpdesk: a session-hijack remote code execution and a zammad-to-root escalation, both reported exploited since 21 September, with no fix named for the root flaw
- CVE-2026-21589, Atlassian Data Center: unauthenticated arbitrary file access in every version of eight self-managed products, patch or take them off the internet (CVSS 4.0 9.3)
- Denmark's CPR population register: unauthorised parties abused one private company's lawful lookup access for about ten days and obtained names, addresses and CPR numbers of 8.8 million people
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
14 notes · 3 last_successful_fetch · 3 added · 3 content_scope · 1 fetch_method.
| Source | Change | From → To | Reason |
|---|---|---|---|
| cisa-kev | last_successful_fetch | 2026-10-05 → 2026-10-06 | fetched and used (cited in an entry updated this run) |
| fortinet-psirt | last_successful_fetch | 2026-10-03 → 2026-10-06 | fetched and used (cited in an entry updated this run) |
| csirt-acn-it | last_successful_fetch | 2026-09-13 → 2026-10-06 | the ACN Zimbra bulletin was fetched and cited in an entry updated this run |
| atlassian-security-advisories | added | · → status: candidate | Added 2026-10-06: first-party PSIRT for seven products none of which had a source record; its out-of-band CVE-2026-21589 advisory reached the pipeline only through EUVD and GitHub |
| theregister-security-feed | added | · → status: candidate | Added 2026-10-06: dated Atom feed that surfaced the Atlassian advisory hours ahead of any national-CERT relay; discovery lead only |
| swissinfo-ger | added | · → status: candidate | Added 2026-10-06: Keystone-SDA / AWP wire text of Swiss incident statements within hours (Beyond Gravity); article pages read with extract |
| fortinet-psirt | notes | · → recipe note appended | CSAF link and Timeline block expose advisory revisions the RSS pubDate misses; the main agent verified it on FG-IR-26-175 |
| msrc-update-guide | notes | · → recipe note appended | S1 found msrc cvrf returns KB numbers and fixed builds |
| github-advisory | notes | · → recipe note appended | S1 found the REST advisories endpoint returns the newest critical advisories in one call |
| chrome-releases | notes | · → recipe note appended | S1 found the Stable updates label page carries the Security Fixes sections |
| mikrotik-routeros-changelog | notes | · → recipe note appended | S1 found plain-text changelogs and the NEWESTa7 channel pointers read directly |
| ssd-disclosure | notes | · → recipe note appended | S1 found the advisories listing reads through extract while a direct GET still answers the captcha |
| searchlight-cyber | notes | · → recipe note appended | S1 found the research-center listing reads with extract |
| inside-it-ch | notes | · → recipe note appended | S2 and S4 read article pages without the 429 this fire |
| senthorus-ch | notes | · → recipe note appended | S2 found WebFetch rewrites article hrefs to a non-resolving host and extract works |
| sygnia | notes | · → recipe note appended | S3 found the sitemap lastmod values are not publication dates |
| fortinet-fortiguard-blog | notes | · → recipe note appended | S3 found the raw card list pairs dates off by one |
| msft-ti | notes | · → recipe note appended | S3 found the topic page misses News-type posts such as the Digital Defense Report |
| eset | notes | · → recipe note appended | S3 found a parseable RSS feed that could be pinned |
| ncsc-ch-focus | notes | · → recipe note appended | S2 found the BACS weekly review appears on Tuesdays |
| ssd-disclosure | fetch_method | blocked → bridge | source_health under an interpreter with trafilatura reads the homepage directly and the advisories listing through the reader fallback; the blocked label no longer holds |
| next-ink | content_scope | · → general-news | source_health flagged the general-news feed as having no security vocabulary |
| rts-info-regions-rss | content_scope | · → general-news | source_health flagged the regional news feed as having no security vocabulary |
| swissinfo-ger | content_scope | · → general-news | source_health flagged the new wire-news candidate as having no security vocabulary |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| citrix-techzone-blog | https://community.citrix.com/techzone-blogs/110_security-updates/understanding-a | webfetch → extract | 403 waf-block WebFetch returned 403 and extract reported all transports failed (S1); the page is cited by the existing CVE-2026-88779 entry and was not needed for a record this fire | read the same facts from the CTX697174 bulletin on support.citrix.com; not retried |
| reuters-shinyhunters-rey | https://www.reuters.com/ | extract → bridge:jina | 403 captcha CAPTCHA wall through extract and the reader (S4); the ShinyHunters Rey detention report was cited through BleepingComputer and DataBreaches.net, and the item was dropped | item dropped as an unconfirmed single-outlet report; not retried |
Bridge invocations (this run)
11 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- extract ×5
- url --direct ×2
- url ×2
- cisa-kev ×1
- msrc ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 26 findings (truth=9, editorial=6, advisory=11) · Claude Sonnet 5.5 · 17m 08s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | The advisory page has no end-of-life sentence. | · | |
| F3 claim-not-supported | · | The entry said protected persons are outside the exposed data. | · | |
| F3 claim-not-supported | · | PSIRT cited for public-key extraction and 'operationally common'. | · | |
| F3 claim-not-supported | · | Rapid7 never says the MAC was deliberately spoofed. | · | |
| F4 hallucinated-fact | · | '12.1.4-h6+ and subsequent maintenance releases' marked affected builds as fixed. | · | |
| F4 hallucinated-fact | · | The Rapid7 evidence quote was not verbatim. | · | |
| F4 hallucinated-fact | · | (low confidence) unsupported detection clauses. | · | |
| F4 hallucinated-fact | · | (low confidence) 'since June' is in no cited source. | · | |
| F14 quantifier-without-source | · | (low confidence) 'nearly four weeks' for a 24-day gap. | · | |
| F5 missing-citation | · | Body paragraph stated facts with no inline link. | · | |
| F8 needs-more-research | · | No labelled lines. | · | |
| F8 needs-more-research | · | (low confidence) no Exposure or Detection labels. | · | |
| F9 surface-contradiction | · | The entry followed the advisory silently. | · | |
| F7 drop | · | (low confidence) out-of-nexus breach at notable. | · | |
| F18 action-item-discipline | · | (low confidence) actions restate body content. | · | |
| F11 editorial-advisory | · | Em dashes left in reader-facing body. | · | |
| F11 editorial-advisory | · | Title implied current use while the Arctic Wolf report is from July. | · | |
| F11 editorial-advisory | · | Record summary narrated metadata upkeep. | · | |
| F11 editorial-advisory | · | techniques[] missed RDP and backup targeting. | · | |
| F11 editorial-advisory | · | Registered product keys referenced by no entry. | · | |
| F11 editorial-advisory | · | Vector summary omitted SC/SI/SA High. | · | |
| F11 editorial-advisory | · | Process narration in reader-facing body. | · | |
| F11 editorial-advisory | · | Stale 'no technical details' quote. | · | |
| F11 editorial-advisory | · | Singular attacker wording and event_date. | · | |
| F11 editorial-advisory | · | Fold the duplicate now. | · | |
| F11 editorial-advisory | · | (low confidence) device-name indicators. | · |
Iteration #2 NEEDS_FIXES · 9 findings (truth=6, editorial=1, advisory=2) · Claude Sonnet 5.5 · 15m 21s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Exposure cited Zammad for a DIVD statement. | · | |
| F3 claim-not-supported | · | (low confidence) summary attributed confirmed exploitation to the PSIRT. | · | |
| F3 claim-not-supported | · | (low confidence) legacy section text outside the ledger. | · | |
| F3 claim-not-supported | · | (low confidence) 'any person in the register'. | · | |
| F4 hallucinated-fact | · | (low confidence) run-record note said the fix has existed since June. | · | |
| F5 missing-citation | · | (low confidence) takeaway attributions without links. | · | |
| F11 editorial-advisory | · | Second sentence narrated metadata. | · | |
| F11 editorial-advisory | · | (low confidence, optional) ENISA's CNA data gives Crowd 7.1.1. | · | |
| F14 quantifier-without-source | · | (low confidence) unsourced negative in the sourcing note. | · |
Iteration #3 NEEDS_FIXES · 6 findings (truth=2, editorial=0, advisory=4) · Claude Sonnet 5.5 · 16m 32s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | (low confidence) lineage alone would fire on every SNMP notification. | · | |
| F3 claim-not-supported | · | NCSC-NL credited for DIVD's version scope. | · | |
| F11 editorial-advisory | · | Prisma Access key registered but not linked. | · | |
| F11 editorial-advisory | · | (low confidence) possible duplicate product key. | · | |
| F11 editorial-advisory | · | (low confidence) composition-rationale phrasing. | · | |
| F11 editorial-advisory | · | (low confidence) EPSS values without an as-of date. | · |
Iteration #4 NEEDS_FIXES · 3 findings (truth=1, editorial=0, advisory=2) · Claude Sonnet 5.5 · 12m 26s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | (low confidence) 'immediately after inbound SMTP' has no source. | · | |
| F11 editorial-advisory | · | (low confidence) rationale clause in the sourcing note. | · | |
| F11 editorial-advisory | · | (low confidence) IRC egress item had no stated basis. | · |
Iteration #5 CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Sonnet 5.5 · 12m 55s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | · | (low confidence) Detection clause credited ACN with an outbound-connection check. | · |
Iteration #6 CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Sonnet 5.5 · 14m 23s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | · | (low confidence) record summary wording about egress. | · |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-10-06T0405Z-intel · Sonnet 5.5 · window 26 h · 2 entries published
Verification & coverage notes
- Window: 26 h (gap to the previous intel run 24.0 h, standard window). Thin day by design: two new entries, four changelog records on covered findings; the research returned 24 items and most failed the relevance gate.
- Backlog (state/coverage_backlog.md): IBM MQ CVE-2026-10747 and Langflow: held to 2026-10-11, dated footprint correction appended (the MQ bulletin covers the whole MQ Server line; IBM's 2026-10-02 bulletin adds 25 Langflow CVEs fixed in 1.12.3 incl. unauthenticated CVE-2026-104334; still no exploitation, PoC or KEV). MikroTik CVE-2026-84411: held to 2026-10-14, no state change. IBM Guardium CVE-2026-85542: held to 2026-10-14, no state change. SafePay ARA-Region Lyss-Limpachtal and Payload/Netech: held to 2026-10-14, S4 re-searched, no victim statement or press. New row: Beyond Gravity (held on a named condition, expires 2026-10-20).
- KEV sweep (kev-window.txt): 0 additions since 2026-10-05 (catalog 2026.10.04). RANSOMWARE row CVE-2026-0257 (PAN-OS): shipped as an
updaterecord on 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen (KEV flag plus Arctic Wolf's Qilin intrusions; priority moved from critical to high because fixed builds are listed in Palo Alto's table and the decision is now a compromise assessment). For the audit: entries/2026-05-30/cve-2026-0257-pan-os-globalprotect-pre-auth-vpn-authenticati.md is a v2-migrated duplicate of the same finding and should be folded into the survivor. - Priority notes: Atlassian CVE-2026-21589 is
high: vendor-forced out-of-band response (patch immediately or take internet-facing instances offline, WAF/Tomcat stop-gap) on every version of eight self-managed products, unauthenticated, default configuration; not exploited, so not critical. Whether the constituency runs these products is not stated by any source and the entry does not claim it. Denmark CPR isnotable: sector nexus (national population register) and a transferable lesson (abuse of delegated lawful lookup access, per-party volume alerting); it clears the breach gate on limb (b). - Single-source: Atlassian entry (vendor and CNA, A2; The Register restates it); Denmark CPR (victim-side authority disclosure,
single-source-victim). - borderline-drop: Citrix CVE-2026-88779 NCSC-CH advisory and watchTowr quotes: source addition with no reader-facing delta on an entry that already says exploited.
- borderline-drop: Rejetto HFS CVE-2026-61500 canary-observed attempts (VulnCheck, single China Telecom address, small-scale reconnaissance): low constituency exposure, honeypot-only evidence.
- borderline-drop: IBM Langflow OSS CVE-2026-104334 (25 CVEs, 1.12.3): unauthenticated RCE with no exploitation, PoC or KEV and no established exposure; folded into the held backlog row.
- borderline-drop: Microsoft Exchange CVE-2026-96940 (authenticated cross-mailbox elevation, not exploited, not disclosed, vendor release 2026-10-02, outside the window); Apache Struts S2-075 (Moderate, deprecated non-default mapper).
- borderline-drop: Korea financial-sector wave (Shinhan, KB Kookmin, Hana, Yegaram): no Swiss nexus, AI-agent use unconfirmed; the transferable lookup-abuse lesson is carried by the Denmark CPR entry. Hauts-de-France Atexo/Docaposte: no vector, actor or behaviour (incident floor). Fakturownia/VosFactures: Polish SaaS, no Swiss nexus, attacker route claim-only. ShinyHunters 'Rey' detained: anonymously sourced single-outlet report with no defender decision.
- borderline-drop: Microsoft Digital Defense Report 2026 and Zscaler ThreatLabz 2026 Ransomware Report: vendor-telemetry statistics, awareness only. Cling/ClingSTUN IoT botnet: opportunistic, no stated public-sector targeting. HSLU/Uni Fribourg measurement of Swiss municipal mail authentication (DMARC enforced on 13.4%): hardening baseline, no incident, not a near-term decision.
- out-of-window: LevelBlue THOR NetScaler CVE-2026-88771 artefacts (primary 2026-09-30, outside the 72 h developing window); ENISA Threat Landscape 2026 (primary 2026-09-22). Both are for the audit's re-sweep: the NetScaler artefacts would sharpen the compromise check on the critical NetScaler entry, and ENISA ranks public administration the most targeted EU sector.
- Seen but never assessed (S1, outside every window, offered to the audit's G1 re-sweep): GitLab CVE-2026-89078 and CVE-2026-93577 (CVSS 9.9, 2026-09-23); OpenBao/HashiCorp Vault authentication bypass flaws (2026-09-23); HPE Aruba Instant On CVE-2026-76723/76724/76725 (9.6, 2026-09-29); Zimbra CVE-2026-66912/66911 (NCSC-CH 13022); a WatchGuard bundle of 2026-09-28 to 2026-10-01 (about 15 CVEs; CVE-2026-81433 needs adjacent-network access). Also BACS weekly review 26w39 (ClickFix to ransomware warning, 2026-09-29) and the SRG/SRF employee-data theft (2026-09-28), both flagged by S2.
- Tooling defect hit this fire:
python3resolves to /usr/local/bin/python3, which cannot import trafilatura, while the session hook installs it for /usr/bin/python3.fetch_source.py extracttherefore returned raw HTML to all four sub-agents; the main agent ran extract with /usr/bin/python3. Fix: setup-deps.sh now installs withpython3 -m pip(committed with this run). - Candidates considered but not added: Nozomi Networks Labs (no feed), bluewin.ch (Keystone-SDA wire, no listing recipe), KISA Boho Nara.
- Coverage gaps: ssd-disclosure (direct GET answers the captcha; listing read through the reader, newest advisory 2026-09-10); golem-security (feed titles only, article pages hit the consent wall); swisspost-cybersecurity (undated promotional items); community.citrix.com techzone blog (403); the Exchange team blog (JS-rendered, covered by the MSRC CVRF); Reuters (CAPTCHA); datatilsynet.dk (script-loaded archive); BACS weekly review 26w40 (not yet published at 04:22Z, expected on a later Tuesday fire).
- Verification: six iterations. Iterations 1 to 4 returned NEEDS_FIXES (26, 9, 6 and 3 findings), most of them on the v2-migrated PAN-OS entry whose old body had unverified claims (wrong fixed-build list, non-verbatim Rapid7 quote, unsupported detection clauses) and which was rewritten from the PSIRT, Rapid7 and Arctic Wolf pages. Iterations 5 and 6 returned CLEAN, confirmed. Declined with rebuttal: F7 Denmark (specific mechanism stated), F18 Atlassian actions, the fold of the v2 duplicate PAN-OS entry (deferred to the audit), ENISA's Crowd 7.1.1 figure, the product:atlassian-confluence-data-center key. Residual advisory left for the audit: the Zimbra record summary lists egress among ACN's host checks (ACN gives egress only as hardening).
- Notes for the audit: fold entries/2026-05-30/cve-2026-0257-pan-os-globalprotect-pre-auth-vpn-authenticati.md into the surviving PAN-OS entry after reviewing its deep-dive content; an earlier record of that survivor still carries an em dash in its summary (append-only).
← Operations dashboard · run-record contract: docs/pipeline.md