2026-10-09T0255Z-intel
One pipeline fire, in full · intel run of 2026-10-09 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-10-09/2026-10-09T0255Z-intel.md.
Run telemetry
- Items returned
- 8
- Duration
- 31m 36s
- Tool calls
- 7 WebFetch16 WebSearch130 bridge
- Cited sources
- 6 of 25 in slice
- Items returned
- 4
- Duration
- 21m 44s
- Tool calls
- 0 WebFetch25 WebSearch90 bridge
- Cited sources
- 3 of 18 in slice
- Items returned
- 10
- Duration
- 21m 37s
- Tool calls
- 6 WebFetch11 WebSearch145 bridge
- Cited sources
- 5 of 14 in slice
- Items returned
- 4
- Duration
- 18m 34s
- Tool calls
- 4 WebFetch29 WebSearch62 bridge
- Cited sources
- 2 of 12 in slice
Verification
Deep dive
·
Entries this run published (5) and updated (3)
- TraderTraitor (Jade Sleet) backdoors resurface on a non-cryptocurrency IT-services firm in a campaign that delivers malware through weaponized Terraform provider lockfiles, resolving C2 through a Nostr-relay dead drop
- CVE-2026-88771 / CVE-2026-88772, Citrix NetScaler ADC and Gateway: unauthenticated pre-auth RCE zero-days exploited before a patch existed (CVSS 4.0 9.5)
- CVE-2026-88779, Citrix NetScaler ADC and Gateway: a SAML-triggered memory overflow still hits appliances on the September fixed builds, and Citrix confirms targeted attacks (CVSS 4.0 8.7)
- Publica, the Confederation's pension fund: malware at its administration-software supplier PK Softech and a data outflow the Confederation reports, with the Federal Prosecutor's Office investigating
- CVE-2026-107406, Citrix NetScaler ADC and Gateway: a SAML-path memory overflow that can lead to code execution still affects the 2026-10-03 fixed builds on identity-provider appliances (CVSS 4.0 9.5)
- AA26-281A: China-linked actors enabled by Integrity Technology Group scan with MicroScan, spray Exchange and Microsoft 365 passwords and steal mail, and five old flaws from the scanner's scripts enter CISA KEV
- Cisco Talos: malware now embeds natural-language instructions aimed at LLM triage pipelines, from a copied comment to template-sprayed prompts across four families, and a Russia-aligned group uses it too
- ReliaQuest: LLM-driven agents run most of an intrusion through one unauthenticated Spring Batch job-submission feature on Apache Tomcat, from in-process JavaScript to SYSTEM in under 24 hours
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
11 last_successful_fetch · 9 notes · 2 status · 2 added · 1 rss_url · 1 fetch_method · 1 alias.
| Source | Change | From → To | Reason |
|---|---|---|---|
| cccs-alerts | status | candidate → active | promotion_due: cited by published entries from 7 distinct runs |
| sonicwall-psirt | status | candidate → active | promotion_due: cited by published entries from 3 distinct runs |
| citrix-netscaler-security-bulletins | last_successful_fetch | 2026-10-04 → 2026-10-09 | fetched and used (primary of a new entry and cited in two updates); recipe note added: /external/article/CTX<id>/ reads with extract |
| news-admin-ch | last_successful_fetch | · → 2026-10-09 | fetched and used (the federal release is the primary of a new entry) |
| inside-it-ch | last_successful_fetch | 2026-10-08 → 2026-10-09 | fetched and used (cited in a new entry) |
| netzwoche | rss_url | · → https://www.netzwoche.ch/rss.xml | S2 verified the feed (dated items, direct transport) and the main agent re-read it; last_successful_fetch moves to 2026-10-09 (cited in a new entry); fetch_method unchanged |
| talos | last_successful_fetch | 2026-10-02 → 2026-10-09 | fetched and used (primary of a new entry) |
| eset | last_successful_fetch | 2026-09-18 → 2026-10-09 | fetched and used (cited in a new entry) |
| reliaquest | last_successful_fetch | 2026-09-20 → 2026-10-09 | fetched and used (primary of a new entry) |
| zscaler-threatlabz | last_successful_fetch | 2026-09-08 → 2026-10-09 | fetched and used (cited in an entry updated this run) |
| ncsc-uk | last_successful_fetch | 2026-09-29 → 2026-10-09 | fetched and used (cited in a new entry) |
| fbi-cyber-alerts | last_successful_fetch | 2026-10-08 → 2026-10-09 | fetched and used (the joint advisory PDF is the primary of a new entry) |
| cisa-kev | last_successful_fetch | 2026-10-07 → 2026-10-09 | fetched and used (catalogue records cited in a new entry) |
| cisa-advisories | last_successful_fetch | 2026-10-02 → 2026-10-09 | fetched and used (AA26-281A, cited in a new entry) |
| splunk-advisories | added | · → status: candidate | Added 2026-10-09: first-party per-CVE disclosure tables for the SIEM many SOCs run; the primary of the 2026-10-07 release S1 returned |
| hpe-networking-psirt | added | · → status: candidate | Added 2026-10-09: first-party signed CSAF advisories for ClearPass and AOS (37 CVEs on 2026-10-06); discovery so far only through CERT-FR |
| ssd-disclosure | fetch_method | blocked → bridge | source_health flagged needs-content-fix: extract read the advisories listing directly this fire (relevant summaries, no dates); the record is intermittent and the note says so |
| tool:macos-gaslight | alias | · → FLATROOF | SentinelLabs names FLATROOF as macOS.Gaslight; the TraderTraitor entry now keys the existing record instead of a second key |
| enisa-euvd | notes | · → recipe note appended | the EUVD search API with a score floor surfaced NetScaler CVE-2026-107406 about five hours after Citrix published it, before any outlet or CERT |
| bsi-de | notes | · → recipe note appended | the RSS cap was filled by a bulk [UPDATE] refresh; fine for a 25 h window, truncated for 48 h |
| malware-news | notes | · → recipe note appended | latest.rss caps at 30 items; ?page=1..9 reaches back about a week |
| edpb | notes | · → recipe note appended | listing via url and items via extract read this run |
| vaud-soc-cyber-threat-review | notes | · → recipe note appended | https://www.vd.ch/cybersecurite is a listing route |
| bitdefender-threat-debrief | notes | · → recipe note appended | extract returns raw HTML; WebFetch reads it |
| reliaquest | notes | · → recipe note appended | sitemap must be filtered to /blog/ |
| ransomware-live | notes | · → recipe note appended | country and search endpoints of the v2 API read with url --direct |
| ncsc-uk | notes | · → recipe note appended | extract returns the raw HTML page; text reads after tag stripping |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| ilias-vendor-security-blog | https://docu.ilias.de/go/blog/15821/951 | extract → bridge:jina | 200 captcha the session-bound blog URL named by NCSC-CH post 13035 answers 404 on extract and the reader, and the permanent form answers a captcha page (S1); the vendor text was not read | fixed versions 9.24, 10.12 and 11.5 came from BSI WID-SEC-2026-3783 and the GitHub release; the item was borderline-dropped, so nothing depended on the vendor page |
| watchguard-psirt-cve-2026-86106 | https://psirt.watchguard.com/CVE-2026-86106 | extract → bridge:jina | 403 waf-block AccessDenied on extract and the reader for one per-CVE page; the other four WatchGuard pages read (S1) | the WatchGuard release was borderline-dropped on the pages that read, so nothing depended on this one |
Bridge invocations (this run)
7 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- jina ×2
- extract ×2
- pdf ×1
- cisa-kev ×1
- url --direct (EUVD search API) ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 19 findings (truth=7, editorial=7, advisory=5) · Claude Sonnet 5.5 · 19m 35s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F1 broken-url | · | Cited ACSC path returns upstream HTTP 404 (python3 tools/fetch_source.py url --direct, repeated; other old-style cyber.gov.au paths still resolve). The alert lives at https://www.cyber.gov.au/alert/cr | · | |
| F3 claim-not-supported | · | AA26-281A names only 'conhost.exe or dllhost.exe' for the SoftEther installers; DiagTrack.exe is the process started by the XSS-delivered executable live700_v1.exe (mailbox-targeting malware with its | · | |
| F3 claim-not-supported | · | The single Zscaler citation terminates a sentence that chains SentinelLabs-only lockfile-redirect advice with Zscaler's provider-binary advice; Zscaler's page carries only the latter ('restrict the us | · | |
| F4 hallucinated-fact | · | Zscaler (https://www.zscaler.com/blogs/security-research/suspected-tradertraitor-group-uses-trojanized-terraform-provider-deliver) never says 'moderate'; it titles the post 'Suspected TraderTraitor Gr | · | |
| F4 hallucinated-fact | · | AA26-281A Appendix B lists 'GNU Bash | Through 4.3 bash43-026' (affected through patch level 026) and the CISA KEV notes link bash43-027, which the same record gives as the fix; 'before patch bash43-0 | · | |
| F4 hallucinated-fact | · | The ReliaQuest post names Apache Tomcat, Spring Batch, Microsoft SQL Server, PrintSpoofer and GodPotato, and the entry lists three of them in affected_products[]; only the vulnerable application's ven | · | |
| F15 name-collision-unflagged | · | The store already carries tool:cairn-exploitation-engine (Gambit's open-source autonomous exploitation harness 'Cairn', entry 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes) and | · | |
| F8 needs-more-research | · | The related Citrix blog that the bulletin links ('Protecting Customers: Immediate Guidance for CVE-2026-107406 ...', published 2026-10-08, readable via https://community.citrix.com/rss/3-citrix-tech-z | · | |
| F16 org-triage | · | prompts/cti-run.md `high` disqualifiers include 'an unexploited flaw reachable only in a non-default configuration' and 'Doubt resolves to notable'. The flaw is unexploited (Citrix blog: 'not aware of | · | |
| F7 drop | · | cti-run.md 'The incident floor': an incident whose sources give no access vector, no actor and no behaviour beyond the impact 'is `routine` and at most two sentences plus its transfer ground, or it is | · | |
| F5 missing-citation | · | All four are supported by AA26-281A (verified) but only the paragraph's last sentence carries a citation, unlike every other paragraph of the entry. Add the advisory citation to each sentence. | · | |
| F8 needs-more-research | · | The CISA KEV notes for CVE-2016-3081 link Apache's S2-032 bulletin, which states the fix ('upgrade to Apache Struts versions 2.3.20.3, 2.3.24.3 or 2.3.28.1' or disable Dynamic Method Invocation; fetch | · | |
| F18 action-item-discipline | · | The update deleted this KEV-listed, exploited flaw's own start-now task (find SAML SP/IdP matches and upgrade to 14.1-73.41/13.1-64.28 incl. appliances on .37/.23). The replacement in the CVE-2026-107 | · | |
| F9 surface-contradiction | · | Talos' own headline bullet says the technique is 'inconsistently impactful: the best techniques steered the outcome in the attacker's favor in about 35% of test runs' (net rate: pairs shifted toward b | · | |
| F11 editorial-advisory | · | Rule: no em dash in reader-facing entry text (only the '## <Type>; <at>' heading is exempt). The Defender takeaway line was rewritten by this run's update and still carries one; the Triage line carrie | · | |
| F11 editorial-advisory | · | updates[].summary is rendered; 'this entry keeps ...' narrates how actions[] was edited and the Update section says nothing about actions (4c(d): record summary states more than the section). Drop the | · | |
| F11 editorial-advisory | · | Zscaler's ATT&CK table also maps T1059.006, T1082, T1057, T1083, T1518, T1518.001, T1217, T1071.001 and T1573.001 (Python stealer, discovery, web-protocol and AES C2), all behaviours the update sectio | · | |
| F11 editorial-advisory | · | Citrix's fixed build is '13.1.37.283' (as the same entry's fixed field and body write it); the action uses a hyphen form, which a defender comparing build strings would not match. | · | |
| F11 editorial-advisory | · | T1199 (Trusted Relationship) describes an adversary using a third party's access to reach the target; the sources say only that the supplier's own infrastructure was breached by malware and that Publi | · |
Iteration #2 NEEDS_FIXES · 9 findings (truth=4, editorial=1, advisory=4) · Claude Sonnet 5.5 · 13m 48s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | The cited watson.ch page (and Netzwoche) says 'Sie versichert unter anderem Mitarbeitende der Bundesverwaltung und des ETH-Bereichs. Ende 2025 zählte sie rund 70'000 aktive Versicherte und 41'600 Rent | · | |
| F3 claim-not-supported | · | The live page's only visible dateline reads 'modified on Feb 13, 2021' (Confluence last-modified marker) and the bulletin concerns CVE-2016-3081; 2020-03-02 appears nowhere on the page. The citation d | · | |
| F3 claim-not-supported | · | AA26-281A: 'a malicious application known as MicroScan. This Python-based web application contains over 1,300 penetration testing scripts'. The advisory says the application is Python-based, not that | · | |
| F14 quantifier-without-source | · | The cited advisory lists victim sectors and the regions 'Southeast Asia, Africa, and North America' but does not say that no victim is Swiss, and the DOJ release lists Polish airports among MicroScan | · | |
| F9 surface-contradiction | · | CISA KEV says the flaw 'could allow attackers with access to the admin panel to discover sensitive user details via the query filter', but the Strapi disclosure the entry now cites for the fix gives ' | · | |
| F11 editorial-advisory | · | After remediation 13 the 88779 entry keeps its own upgrade task (actions[0]: 'Upgrade every SAML-configured NetScaler ... to at least those builds; identity providers then need the builds named for CV | · | |
| F11 editorial-advisory | · | The Talos entry keys tool:cairn-talos but its prose never mentions CAIRN, so the entity page lists a finding that does not describe it. In the ReliaQuest entry the disambiguation names Talos' defender | · | |
| F11 editorial-advisory | · | The incident floor allows at most two sentences plus the transfer ground. The cut is real (routine, about 290 words) but paragraph 1 still has three sentences and the Exposure and Detection lines; the | · | |
| F11 editorial-advisory | · | immediate_action now sends identity providers on to 14.1-73.46 / 13.1-64.29 (CVE-2026-107406) but actions[0] still stops at the CVE-2026-88779 builds, which are affected for identity providers; the 88 | · |
Iteration #3 NEEDS_FIXES · 8 findings (truth=1, editorial=2, advisory=5) · Claude Sonnet 5.5 · 15m 44s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Minor hedge loss: PK Softech writes that it 'must be assumed' data left (watson/Netzwoche: Publica says whether and which data left is still unclear); the body turns the assumption into the supplier's | · | |
| F9 surface-contradiction | · | Conflict is surfaced but the closing clause misleads: the public CVE/NVD record (https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2023-22894, fetched this iteration) says 'allows attackers ( | · | |
| F8 needs-more-research | · | (low confidence) The update documents Linux and Windows payloads and the Update section says so, but affected_products (not named in the record's fields) still lists only Terraform and macOS, so the e | · | |
| F11 editorial-advisory | · | Advisory. 'the reason this belongs here' is a composition-rationale phrase aimed at the pipeline, not the reader; state the ground in the reader's terms (supplier to the Confederation's pension fund, | · | |
| F11 editorial-advisory | · | Advisory. The advisory (and the NCSC UK sentence the entry quotes in evidence) leaves the alias list open with 'among others'; the body closes it. No decision turns on it. May be left. | · | |
| F11 editorial-advisory | · | Advisory, judged acceptable. Inside this entry actions[0] stops at the 88779 builds while immediate_action carries the .46/.29 builds; the entry is not re-floated (improvement record) and the 88779 an | · | |
| F11 editorial-advisory | · | Advisory, left on purpose per the run record. T1199 (Trusted Relationship) describes using a third party's access to reach the target; no cited source says the attackers used PK Softech's access to en | · | |
| F11 editorial-advisory | · | Advisory. The parenthetical sits inside a ReliaQuest-cited clause but names Gambit's and Talos' projects without a citation; neither is on the ReliaQuest page. Gambit's description (autonomous engine | · |
Iteration #4 NEEDS_FIXES · 9 findings (truth=3, editorial=4, advisory=2) · Claude Sonnet 5.5 · 15m 39s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Same hedge loss the entry itself had at iteration 3 (fixed there, still standing in the registry text readers see on the entity page): PK Softech says only that it must be assumed data left; the Confe | · | |
| F3 claim-not-supported | · | (low confidence) The advisory makes the command-line exploit utilities the primary access route and XSS an additional one; the sentence puts both under 'mostly' and the January 2021 date. Reword to 'p | · | |
| F9 surface-contradiction | · | (low confidence) Sources differ in confidence and the entry picks the strong reading in its most visible fields: admin.ch is headlined 'Datenabfluss bestätigt' and Netzwoche's lead says 'Dabei sind Da | · | |
| F5 missing-citation | · | (low confidence) The ground clause added at iteration 3 is uncited and states more than the sources: admin.ch says the extent of Publica data affected is still being clarified and watson/Netzwoche say | · | |
| F8 needs-more-research | · | (low confidence) The Confederation's statement that no other federal body deals with PK Softech scopes the Exposure for a federal, cantonal and communal readership and bears on action 2 ('If your orga | · | |
| F8 needs-more-research | · | (low confidence) Iteration 3 asked for the Linux and Windows platforms the update documents; Windows was added, Linux was not. The Update section, summary and record all say macOS, Linux and Windows. | · | |
| F15 name-collision-unflagged | · | (low confidence) Talos' CAIRN is a distinct Cisco toolkit, but 'other projects of that name' also asserts that Gambit's Cairn is a different project, which neither source establishes: Gambit (https:// | · | |
| F11 editorial-advisory | · | Advisory. The subject malware families have no registry record or key: FLATROOF and ROOFDECK (the update now gives them a second publisher, so entity pages cannot aggregate the Zscaler reporting) and | · | |
| F11 editorial-advisory | · | Advisory, judged as asked: T1199 (Trusted Relationship) describes using a third party's access to reach the target, and no cited source says the attackers did that against Publica or the federal bodie | · |
Iteration #5 CLEAN · 5 findings (truth=0, editorial=0, advisory=5) · Claude Sonnet 5.5 · 15m 34s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | · | Advisory, may be left. (a) The single admin.ch citation closes a clause chain whose first part ('no ... ransom demand is public') admin.ch does not carry; only watson does (Publica 'wollte ... nicht s | · | |
| F11 editorial-advisory | · | Advisory, may be left. The iteration-4 fix is accurate (ReliaQuest: 'a legitimate open-source orchestration platform for coordinating AI agents on multi-step tasks'; Talos' CAIRN is Cisco-Talos/CAIRN | · | |
| F11 editorial-advisory | · | Advisory. The store already carries 2026-06-26/macos-gaslight-a-dprk-aligned-rust-backdoor-that-targets-the (macOS.Gaslight, a DPRK backdoor whose blob of fabricated system messages is aimed at LLM tr | · | |
| F11 editorial-advisory | · | Judged: accept and leave. The attackers breached a supplier that holds the target's pension-administration data, which is the situation T1199 (Trusted Relationship: breach or leverage organizations wh | · | |
| F11 editorial-advisory | · | Judged: acceptable. The entry is a class-level study of one technique across four Talos-named families plus ESET's loader context; keying five malware records from one clause each would create registr | · |
Iteration #6 NEEDS_FIXES · 6 findings (truth=1, editorial=0, advisory=5) · Claude Sonnet 5.5 · 17m 17s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | Contradicted by the published entries and by the record's own Single-source bullet. entries/2026-10-09/cve-2026-107406-citrix-netscaler-saml-idp-overflow.md lists the community blog (.../protecting-cu | · | |
| F11 editorial-advisory | · | (low confidence) ASD's ACSC alert already cited by the 88779 entry (https://www.cyber.gov.au/alert/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products) now carries a | · | |
| F11 editorial-advisory | · | (low confidence) The Confederation release the entry lists as its first primary is headlined 'Cyberangriff auf Softwarelieferant von Publica: Datenabfluss bestätigt' and says 'Publica informierte die | · | |
| F11 editorial-advisory | · | (low confidence) cti-run.md 'The incident floor': an incident with no access vector, no actor and no behavior beyond the impact is 'routine and at most two sentences plus its transfer ground'. Priorit | · | |
| F11 editorial-advisory | · | (low confidence) SentinelLabs describes ROOFDECK resolving C2 from Nostr first ('it reads the website field of the profile and uses that as its C2 URL') with pastebin_key as a 'secondary resolver'; Zs | · | |
| F11 editorial-advisory | · | (low confidence) AA26-281A lists ten EBurst interfaces; the entry's list omits 'Application Programming Interface (API)'. Not a false statement, an incomplete list. | · |
Iteration #7 CLEAN · 5 findings (truth=0, editorial=0, advisory=5) · Claude Sonnet 5.5 · 14m 16s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | · | (low confidence) Left-on-purpose length judged: the incident floor allows two sentences plus the transfer ground; the narrative paragraph still holds three fact-bearing sentences (event; population an | · | |
| F11 editorial-advisory | · | (low confidence) Cite placement: the sentence's single citation is the blog, which carries only the second half; the first half is a statement about the bulletin CTX697191 itself (true: the bulletin t | · | |
| F11 editorial-advisory | · | (low confidence) Optional corroboration for a Swiss readership: NCSC-CH published an advisory on CVE-2026-107406 at 2026-10-09T05:42Z (fetched this iteration via ncsc-csh recent; exploitation status U | · | |
| F11 editorial-advisory | · | (low confidence) Pre-existing text, unchanged by this run: the heise citation carries the request-volume rationale and 'massive spontaneous reboots' but not the nsaaad service or the failovers, which | · | |
| F11 editorial-advisory | · | (low confidence) After iteration 6 the entry cites ASD's ACSC alert update of 2026-10-09 (checked this iteration: 'Recent update 9 October 2026 ... Previous patches ... are insufficient') as a restati | · |
Iteration #8 CLEAN · 8 findings (truth=0, editorial=0, advisory=8) · Claude Sonnet 5.5 · 16m 27s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | · | (low confidence) The entry's 'every internet-facing appliance' drops CERT-EU's 'running an affected build' qualifier; wording only. | · | |
| F11 editorial-advisory | · | (low confidence) The improvement record type could arguably be an update for a new CVE in the chain; the two other entries already float for the development. | · | |
| F11 editorial-advisory | · | (low confidence) T1055.012, T1115 and T1560.001 are mapped from Zscaler's table but the Update section does not describe process hollowing, clipboard reads or archiving. | · | |
| F11 editorial-advisory | · | (low confidence) 'No independent report of exploitation had surfaced as of 2026-10-09' is an uncited absence claim. | · | |
| F11 editorial-advisory | · | (low confidence) The narrative paragraph has three fact sentences against the incident-floor wording of two plus the transfer ground. | · | |
| F11 editorial-advisory | · | (low confidence) The Detection-line heise citation carries the request-volume rationale; the nsaaad and failover details come from Cyber Press. | · | |
| F11 editorial-advisory | · | (low confidence) The Justice Department release states the announcement date, not the date of the seizures. | · | |
| F11 editorial-advisory | · | (low confidence) Optional corroboration for a Swiss readership; not an omission. | · |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-10-09T0255Z-intel · Sonnet 5.5 · window 25 h · 5 entries published
Verification & coverage notes
- Window: 25 h (gap 22.9 h to
2026-10-08T0404Z-intel), a standard window. Five new entries and three changelog records (twoupdate, oneimprovement). No deep dive: no candidate cleared the Phase 3 bar (exploitation with constituency exposure, or substantive analysis of extreme relevance). - KEV sweep (
work/2026-10-09T0255Z-intel/kev-window.txt): five additions dated 2026-10-08, all NOT COVERED at the start of the run (ProFTPD CVE-2015-3306, ISC BIND CVE-2015-5477, Apache Struts CVE-2016-3081, ONLYOFFICE Docs CVE-2021-3199, Strapi CVE-2023-22894). All five are listed as successfully exploited in joint advisory AA26-281A (Appendix B), which is the "what changed"; each is carried in the2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theftentry'scves[]as exploited andcisa-kev, together with the advisory's three older listed CVEs. No KEV addition dated 2026-10-09 existed at 03:30 UTC (catalog 2026.10.08). The ransomware-flag cross-check printed no row. - Backlog (
state/coverage_backlog.md, six open rows, all re-gated on today's facts, all held, none struck, none published): IBM MQ CVE-2026-10747 and the Langflow CVEs (S1: none in KEV catalog 2026.10.08, no exploitation report or PoC; expiry 2026-10-11 stands); MikroTik CVE-2026-84411 (S1: CISA now says "<7.24 / update to 7.24 or later", MikroTik's changelogs still do not name the CVE, no KEV; expiry 2026-10-14); IBM Guardium CVE-2026-85542 (S1: three further unauthenticated 9.8 Guardium CVEs published 2026-10-08, still no KEV or IBM exploitation statement, dated note appended; expiry 2026-10-14); SafePay ARA-Region Lyss-Limpachtal and Payload Netech (S4: no victim statement or press report; no note appended, nothing changed; expiry 2026-10-14); Beyond Gravity (S2: neither BACS, the company nor any report names a vector, an actor or the data affected; nothing changed; expiry 2026-10-20). - Updates: NetScaler CVE-2026-88779 (
update: Citrix bulletin CTX697191 lists the .41 and .28 builds that fix it as affected by CVE-2026-107406 on SAML identity-provider appliances; summary, actions, references, sources and the takeaway moved; the entry keeps its own SAML upgrade task and points identity providers to the new builds); NetScaler CVE-2026-88771 (improvement: pointers to the SAML builds now carry the later flaw; no float); TraderTraitor Terraform entry (update: Zscaler ThreatLabz independently describes a trojanized provider binary that executes at plugin load and delivers FLATROOF and ROOFDECK on macOS, Linux and Windows; a second delivery form and a second publisher). - New entries: Publica and PK Softech (
routine, trimmed to the incident floor after verifier iteration 1; PD-11 (c): confirmed supplier intrusion and data outflow touching the staff of the federal administration and the ETH domain, Federal Prosecutor's Office investigating, the strongest home-region item of the window, but no vector, actor or behaviour is public; its two actions and the Defender takeaway carry the decision; mapped to T1199 as the closest available id, which describes use of a trusted third party that no source says the attackers made against Publica), Citrix CVE-2026-107406 (notableafter iteration 1: pre-authentication code-execution-capable memory overflow on an internet-facing SAML gateway that reaches the builds Citrix named as the fix five days earlier, but unexploited per Citrix's own blog, AC:H and a SAML precondition, so thehighdisqualifiers apply), AA26-281A (notable; PD-11 (c) and (d): a joint advisory on a China-linked enabler whose actors spray Exchange and Microsoft 365 and steal mail from government, law-enforcement and healthcare targets; no Swiss victim named), Talos AI-analysis evasion (notable; PD-11 (d): a detection surface and a pipeline-hardening rule for SOCs that use LLM triage; Talos itself calls the effect mixed), ReliaQuest agent-driven intrusion (notable; PD-11 (d): detection-grade mechanics on an unauthenticated job-submission feature on Tomcat; the agent-driven reading is ReliaQuest's assessment). - Single-source: Citrix CVE-2026-107406 rests on the vendor bulletin and Citrix's own blog (
single-source, A2; no CERT or outlet had covered it when composed, and ASD's ACSC has since restated the disclosure without adding an observation); ReliaQuest rests on ReliaQuest alone (single-source, medium confidence, lookback item: published 2026-10-07 and first coverage from a rotational record); AA26-281A issingle-source-national-certbecause the advisory, the Justice Department release and the NCSC UK page all rest on the FBI's investigations. - Dedup: the AA26-281A entry references
2026-08-28/doj-fbi-qscan-qtrouter-prc-hacking-as-a-service-takedown(an earlier PRC enabler takedown; no CVE overlap). The ReliaQuest entry deliberately does not keytool:cairn-exploitation-engine: that record is Gambit's Cairn and neither source links the two projects that share the name. - borderline-drop: Cisco 2026-10-07 batch (35 CVEs; NX-API, NGOAM and MPLS OAM RCE flaws are feature-gated, License On-Prem is a management server, none exploited, no KEV, regular cycle under PD-11 (b)); HPE ClearPass and AOS-S HPESBNW05156 and -05158 (unauthenticated 9.8 flaws on management planes, no exploit code, regular cycle); IBM Verify Access, DataPower and Guardium bulletins of 2026-09-18 to 2026-10-08 (unauthenticated 9.8 flaws, no exploitation statement, no constituency deployment shown); Splunk Enterprise SVD-2026-1001 and -1002 (CVE-2026-76268 needs reach to the Patroni REST API of a search-head-cluster member, 10.4 and 10.2 only, internal); ILIAS 9.24, 10.12 and 11.5 (RCE paths need authentication, no CVE ids, no exploitation; published 19 h before the window and dropped by the previous fire).
- borderline-drop: WatchGuard Fireware 2026-09-29 builds (every pre-auth item needs attacker control of a VPN peer, adjacency or prior write access), Veeam Backup and Replication 12.3.2 P4 (needs the Backup Viewer role), Exchange out-of-band CVE-2026-96940 (needs a click, not exploited, dated 2026-10-02), Microsoft cloud-service CVEs of 2026-10-08 (no customer action), Android bulletin 2026-10-01, OpenSSH 10.6, Ollama CVE-2026-103663 (CERT Polska, no exploitation, ambiguous range), HPE IMC CVE-2026-79842, Hazelcast, fast-jwt, SGLang, Jackrabbit, Movable Type and Tenable Identity Exposure (no exploitation signal or constituency nexus).
- borderline-drop: ChainDrop npm worm reaches the tensorlake package (a new, low-footprint package in a covered campaign; the existing entry already carries the dead-man-switch and rotation guidance), Talos UAT-11985 (Taiwan research bodies, a Google-themed relay kit, technique class only), .gh, .sl and .as registry hijacks (no Swiss nexus, previously dropped), DNSSEC root KSK rollover of 2026-10-11 (an operational deadline and not threat activity; ICANN reports more than 95 percent of reporting resolvers ready, no Swiss authority notice; returned by S2 and S3, dropped as a considered borderline), KrebsOnSecurity on the ShinyHunters suspect in Jordan (the Jordan detention is already carried in the FBI entry), CrowdStrike ARTEX (South Korean banks, infrastructure and prompt history only), EDPB publication of the Miljodata and E.E.T.A.A. decisions (GDPR does not bind Swiss bodies; decisions dated 22 September and 28 July), Fox-IT Cobalt Strike Beacon corpus (research dataset, no Swiss nexus), Kiteworks NCSC-NL bundle of 61 CVE ids (improvement-only: no exploitation or fix change, most need administrator authentication).
- borderline-drop: IDC Frontier cloud ransomware in Japan (no vector or actor), ASOS push-notification extortion (UK retailer, vector now stated but no public-sector nexus), T-Systems and SafePay (a victim statement now exists: a small test system, nothing sensitive; below the incident floor), Arizona courts, France Travail sale claim, Saint-Pierre-des-Corps, AP-HP and Dedalus, Eau Coeur d'Essonne and other claim-only French items, the Polish FELG breach (outside window, nexus or both). Claim-only watch for the next fire: Leadec and the University of Rostock, still no notice or press.
- Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0 (the profile configures none).
- Coverage gaps: ilias-vendor-security-blog (captcha; versions read from BSI), citrix-community-blog-permalinks (403 on the direct transports, read through the reader and cited), watchguard-psirt (one per-CVE page 403), cisa.gov AA26-281A PDF (403, read through the FBI IC3 mirror), cyberinsider (undated listing), ssd-disclosure not in this slice.
- Source rotation: the previous two fires' attempts (111 records) were excluded from the S1, S2 and S3 slices as a belt-and-braces measure and the cursor-ranked pool supplied the slices; S4's pool of 19 breach sources was allocated oldest-cursor first without that exclusion because every breach source had been attempted by the previous two fires. S1, S2, S3 and S4 returned complete ledgers (25, 18, 14 and 12 rows); no continuation was needed. Promotions: cccs-alerts and sonicwall-psirt (
promotion_due). Candidates added: splunk-advisories and hpe-networking-psirt (first-party vendor PSIRT tables). - For the audit: S3 reports natto-thoughts (Natto Team: China commercial-hacking analysis) as a candidate, not added this fire; CERT-UA article pages are an SPA (
feed https://cert.gov.ua/api/articles/rssworks); the bsi-rss cap is flooded by bulk [UPDATE] refreshes; the Kiteworks entry carries 8 of NCSC-NL's 61 CVE ids (nine rated 9.1 to 9.8, none exploited, most administrator-authenticated), an improvement-only enrichment no reader decision turns on.
← Operations dashboard · run-record contract: docs/pipeline.md