CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

2026-10-09T0255Z-intel

One pipeline fire, in full · intel run of 2026-10-09 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-10-09/2026-10-09T0255Z-intel.md.

Run telemetry

2026-10-09T0255Z-intel intel prompt v4.19 publish ok
3h 22m duration 5 published 3 updates
Claude Sonnet 5.5 (claude-sonnet-5-5) main agent
S1 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
8
Duration
31m 36s
Tool calls
7 WebFetch16 WebSearch130 bridge
Cited sources
6 of 25 in slice
S2 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
4
Duration
21m 44s
Tool calls
0 WebFetch25 WebSearch90 bridge
Cited sources
3 of 18 in slice
S3 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
10
Duration
21m 37s
Tool calls
6 WebFetch11 WebSearch145 bridge
Cited sources
5 of 14 in slice
S4 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
4
Duration
18m 34s
Tool calls
4 WebFetch29 WebSearch62 bridge
Cited sources
2 of 12 in slice

Verification

✓ double-CLEAN · Sonnet 5.5 ×2 #1 NEEDS_FIXES · Sonnet 5.5 · t=7 e=7 a=5 #2 NEEDS_FIXES · Sonnet 5.5 · t=4 e=1 a=4 #3 NEEDS_FIXES · Sonnet 5.5 · t=1 e=2 a=5 #4 NEEDS_FIXES · Sonnet 5.5 · t=3 e=4 a=2 #5 CLEAN · Sonnet 5.5 · t=0 e=0 a=5 #6 NEEDS_FIXES · Sonnet 5.5 · t=1 e=0 a=5 #7 CLEAN · Sonnet 5.5 · t=0 e=0 a=5 #8 CLEAN · Sonnet 5.5 · t=0 e=0 a=8

Deep dive

·

Entries this run published (5) and updated (3)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

11 last_successful_fetch · 9 notes · 2 status · 2 added · 1 rss_url · 1 fetch_method · 1 alias.

SourceChangeFrom → ToReason
cccs-alertsstatuscandidate → activepromotion_due: cited by published entries from 7 distinct runs
sonicwall-psirtstatuscandidate → activepromotion_due: cited by published entries from 3 distinct runs
citrix-netscaler-security-bulletinslast_successful_fetch2026-10-04 → 2026-10-09fetched and used (primary of a new entry and cited in two updates); recipe note added: /external/article/CTX<id>/ reads with extract
news-admin-chlast_successful_fetch· → 2026-10-09fetched and used (the federal release is the primary of a new entry)
inside-it-chlast_successful_fetch2026-10-08 → 2026-10-09fetched and used (cited in a new entry)
netzwocherss_url· → https://www.netzwoche.ch/rss.xmlS2 verified the feed (dated items, direct transport) and the main agent re-read it; last_successful_fetch moves to 2026-10-09 (cited in a new entry); fetch_method unchanged
taloslast_successful_fetch2026-10-02 → 2026-10-09fetched and used (primary of a new entry)
esetlast_successful_fetch2026-09-18 → 2026-10-09fetched and used (cited in a new entry)
reliaquestlast_successful_fetch2026-09-20 → 2026-10-09fetched and used (primary of a new entry)
zscaler-threatlabzlast_successful_fetch2026-09-08 → 2026-10-09fetched and used (cited in an entry updated this run)
ncsc-uklast_successful_fetch2026-09-29 → 2026-10-09fetched and used (cited in a new entry)
fbi-cyber-alertslast_successful_fetch2026-10-08 → 2026-10-09fetched and used (the joint advisory PDF is the primary of a new entry)
cisa-kevlast_successful_fetch2026-10-07 → 2026-10-09fetched and used (catalogue records cited in a new entry)
cisa-advisorieslast_successful_fetch2026-10-02 → 2026-10-09fetched and used (AA26-281A, cited in a new entry)
splunk-advisoriesadded· → status: candidateAdded 2026-10-09: first-party per-CVE disclosure tables for the SIEM many SOCs run; the primary of the 2026-10-07 release S1 returned
hpe-networking-psirtadded· → status: candidateAdded 2026-10-09: first-party signed CSAF advisories for ClearPass and AOS (37 CVEs on 2026-10-06); discovery so far only through CERT-FR
ssd-disclosurefetch_methodblocked → bridgesource_health flagged needs-content-fix: extract read the advisories listing directly this fire (relevant summaries, no dates); the record is intermittent and the note says so
tool:macos-gaslightalias· → FLATROOFSentinelLabs names FLATROOF as macOS.Gaslight; the TraderTraitor entry now keys the existing record instead of a second key
enisa-euvdnotes· → recipe note appendedthe EUVD search API with a score floor surfaced NetScaler CVE-2026-107406 about five hours after Citrix published it, before any outlet or CERT
bsi-denotes· → recipe note appendedthe RSS cap was filled by a bulk [UPDATE] refresh; fine for a 25 h window, truncated for 48 h
malware-newsnotes· → recipe note appendedlatest.rss caps at 30 items; ?page=1..9 reaches back about a week
edpbnotes· → recipe note appendedlisting via url and items via extract read this run
vaud-soc-cyber-threat-reviewnotes· → recipe note appendedhttps://www.vd.ch/cybersecurite is a listing route
bitdefender-threat-debriefnotes· → recipe note appendedextract returns raw HTML; WebFetch reads it
reliaquestnotes· → recipe note appendedsitemap must be filtered to /blog/
ransomware-livenotes· → recipe note appendedcountry and search endpoints of the v2 API read with url --direct
ncsc-uknotes· → recipe note appendedextract returns the raw HTML page; text reads after tag stripping

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
ilias-vendor-security-bloghttps://docu.ilias.de/go/blog/15821/951extract → bridge:jina200 captcha
the session-bound blog URL named by NCSC-CH post 13035 answers 404 on extract and the reader, and the permanent form answers a captcha page (S1); the vendor text was not read
fixed versions 9.24, 10.12 and 11.5 came from BSI WID-SEC-2026-3783 and the GitHub release; the item was borderline-dropped, so nothing depended on the vendor page
watchguard-psirt-cve-2026-86106https://psirt.watchguard.com/CVE-2026-86106extract → bridge:jina403 waf-block
AccessDenied on extract and the reader for one per-CVE page; the other four WatchGuard pages read (S1)
the WatchGuard release was borderline-dropped on the pages that read, so nothing depended on this one

Bridge invocations (this run)

7 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

7 other
  • jina ×2
  • extract ×2
  • pdf ×1
  • cisa-kev ×1
  • url --direct (EUVD search API) ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 19 findings (truth=7, editorial=7, advisory=5) · Claude Sonnet 5.5 · 19m 35s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F1
broken-url
·
Cited ACSC path returns upstream HTTP 404 (python3 tools/fetch_source.py url --direct, repeated; other old-style cyber.gov.au paths still resolve). The alert lives at https://www.cyber.gov.au/alert/cr·
F3
claim-not-supported
·
AA26-281A names only 'conhost.exe or dllhost.exe' for the SoftEther installers; DiagTrack.exe is the process started by the XSS-delivered executable live700_v1.exe (mailbox-targeting malware with its ·
F3
claim-not-supported
·
The single Zscaler citation terminates a sentence that chains SentinelLabs-only lockfile-redirect advice with Zscaler's provider-binary advice; Zscaler's page carries only the latter ('restrict the us·
F4
hallucinated-fact
·
Zscaler (https://www.zscaler.com/blogs/security-research/suspected-tradertraitor-group-uses-trojanized-terraform-provider-deliver) never says 'moderate'; it titles the post 'Suspected TraderTraitor Gr·
F4
hallucinated-fact
·
AA26-281A Appendix B lists 'GNU Bash | Through 4.3 bash43-026' (affected through patch level 026) and the CISA KEV notes link bash43-027, which the same record gives as the fix; 'before patch bash43-0·
F4
hallucinated-fact
·
The ReliaQuest post names Apache Tomcat, Spring Batch, Microsoft SQL Server, PrintSpoofer and GodPotato, and the entry lists three of them in affected_products[]; only the vulnerable application's ven·
F15
name-collision-unflagged
·
The store already carries tool:cairn-exploitation-engine (Gambit's open-source autonomous exploitation harness 'Cairn', entry 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes) and·
F8
needs-more-research
·
The related Citrix blog that the bulletin links ('Protecting Customers: Immediate Guidance for CVE-2026-107406 ...', published 2026-10-08, readable via https://community.citrix.com/rss/3-citrix-tech-z·
F16
org-triage
·
prompts/cti-run.md `high` disqualifiers include 'an unexploited flaw reachable only in a non-default configuration' and 'Doubt resolves to notable'. The flaw is unexploited (Citrix blog: 'not aware of·
F7
drop
·
cti-run.md 'The incident floor': an incident whose sources give no access vector, no actor and no behaviour beyond the impact 'is `routine` and at most two sentences plus its transfer ground, or it is·
F5
missing-citation
·
All four are supported by AA26-281A (verified) but only the paragraph's last sentence carries a citation, unlike every other paragraph of the entry. Add the advisory citation to each sentence.·
F8
needs-more-research
·
The CISA KEV notes for CVE-2016-3081 link Apache's S2-032 bulletin, which states the fix ('upgrade to Apache Struts versions 2.3.20.3, 2.3.24.3 or 2.3.28.1' or disable Dynamic Method Invocation; fetch·
F18
action-item-discipline
·
The update deleted this KEV-listed, exploited flaw's own start-now task (find SAML SP/IdP matches and upgrade to 14.1-73.41/13.1-64.28 incl. appliances on .37/.23). The replacement in the CVE-2026-107·
F9
surface-contradiction
·
Talos' own headline bullet says the technique is 'inconsistently impactful: the best techniques steered the outcome in the attacker's favor in about 35% of test runs' (net rate: pairs shifted toward b·
F11
editorial-advisory
·
Rule: no em dash in reader-facing entry text (only the '## <Type>; <at>' heading is exempt). The Defender takeaway line was rewritten by this run's update and still carries one; the Triage line carrie·
F11
editorial-advisory
·
updates[].summary is rendered; 'this entry keeps ...' narrates how actions[] was edited and the Update section says nothing about actions (4c(d): record summary states more than the section). Drop the·
F11
editorial-advisory
·
Zscaler's ATT&CK table also maps T1059.006, T1082, T1057, T1083, T1518, T1518.001, T1217, T1071.001 and T1573.001 (Python stealer, discovery, web-protocol and AES C2), all behaviours the update sectio·
F11
editorial-advisory
·
Citrix's fixed build is '13.1.37.283' (as the same entry's fixed field and body write it); the action uses a hyphen form, which a defender comparing build strings would not match.·
F11
editorial-advisory
·
T1199 (Trusted Relationship) describes an adversary using a third party's access to reach the target; the sources say only that the supplier's own infrastructure was breached by malware and that Publi·

Iteration #2 NEEDS_FIXES · 9 findings (truth=4, editorial=1, advisory=4) · Claude Sonnet 5.5 · 13m 48s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
The cited watson.ch page (and Netzwoche) says 'Sie versichert unter anderem Mitarbeitende der Bundesverwaltung und des ETH-Bereichs. Ende 2025 zählte sie rund 70'000 aktive Versicherte und 41'600 Rent·
F3
claim-not-supported
·
The live page's only visible dateline reads 'modified on Feb 13, 2021' (Confluence last-modified marker) and the bulletin concerns CVE-2016-3081; 2020-03-02 appears nowhere on the page. The citation d·
F3
claim-not-supported
·
AA26-281A: 'a malicious application known as MicroScan. This Python-based web application contains over 1,300 penetration testing scripts'. The advisory says the application is Python-based, not that ·
F14
quantifier-without-source
·
The cited advisory lists victim sectors and the regions 'Southeast Asia, Africa, and North America' but does not say that no victim is Swiss, and the DOJ release lists Polish airports among MicroScan ·
F9
surface-contradiction
·
CISA KEV says the flaw 'could allow attackers with access to the admin panel to discover sensitive user details via the query filter', but the Strapi disclosure the entry now cites for the fix gives '·
F11
editorial-advisory
·
After remediation 13 the 88779 entry keeps its own upgrade task (actions[0]: 'Upgrade every SAML-configured NetScaler ... to at least those builds; identity providers then need the builds named for CV·
F11
editorial-advisory
·
The Talos entry keys tool:cairn-talos but its prose never mentions CAIRN, so the entity page lists a finding that does not describe it. In the ReliaQuest entry the disambiguation names Talos' defender·
F11
editorial-advisory
·
The incident floor allows at most two sentences plus the transfer ground. The cut is real (routine, about 290 words) but paragraph 1 still has three sentences and the Exposure and Detection lines; the·
F11
editorial-advisory
·
immediate_action now sends identity providers on to 14.1-73.46 / 13.1-64.29 (CVE-2026-107406) but actions[0] still stops at the CVE-2026-88779 builds, which are affected for identity providers; the 88·

Iteration #3 NEEDS_FIXES · 8 findings (truth=1, editorial=2, advisory=5) · Claude Sonnet 5.5 · 15m 44s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Minor hedge loss: PK Softech writes that it 'must be assumed' data left (watson/Netzwoche: Publica says whether and which data left is still unclear); the body turns the assumption into the supplier's·
F9
surface-contradiction
·
Conflict is surfaced but the closing clause misleads: the public CVE/NVD record (https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2023-22894, fetched this iteration) says 'allows attackers (·
F8
needs-more-research
·
(low confidence) The update documents Linux and Windows payloads and the Update section says so, but affected_products (not named in the record's fields) still lists only Terraform and macOS, so the e·
F11
editorial-advisory
·
Advisory. 'the reason this belongs here' is a composition-rationale phrase aimed at the pipeline, not the reader; state the ground in the reader's terms (supplier to the Confederation's pension fund, ·
F11
editorial-advisory
·
Advisory. The advisory (and the NCSC UK sentence the entry quotes in evidence) leaves the alias list open with 'among others'; the body closes it. No decision turns on it. May be left.·
F11
editorial-advisory
·
Advisory, judged acceptable. Inside this entry actions[0] stops at the 88779 builds while immediate_action carries the .46/.29 builds; the entry is not re-floated (improvement record) and the 88779 an·
F11
editorial-advisory
·
Advisory, left on purpose per the run record. T1199 (Trusted Relationship) describes using a third party's access to reach the target; no cited source says the attackers used PK Softech's access to en·
F11
editorial-advisory
·
Advisory. The parenthetical sits inside a ReliaQuest-cited clause but names Gambit's and Talos' projects without a citation; neither is on the ReliaQuest page. Gambit's description (autonomous engine ·

Iteration #4 NEEDS_FIXES · 9 findings (truth=3, editorial=4, advisory=2) · Claude Sonnet 5.5 · 15m 39s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Same hedge loss the entry itself had at iteration 3 (fixed there, still standing in the registry text readers see on the entity page): PK Softech says only that it must be assumed data left; the Confe·
F3
claim-not-supported
·
(low confidence) The advisory makes the command-line exploit utilities the primary access route and XSS an additional one; the sentence puts both under 'mostly' and the January 2021 date. Reword to 'p·
F9
surface-contradiction
·
(low confidence) Sources differ in confidence and the entry picks the strong reading in its most visible fields: admin.ch is headlined 'Datenabfluss bestätigt' and Netzwoche's lead says 'Dabei sind Da·
F5
missing-citation
·
(low confidence) The ground clause added at iteration 3 is uncited and states more than the sources: admin.ch says the extent of Publica data affected is still being clarified and watson/Netzwoche say·
F8
needs-more-research
·
(low confidence) The Confederation's statement that no other federal body deals with PK Softech scopes the Exposure for a federal, cantonal and communal readership and bears on action 2 ('If your orga·
F8
needs-more-research
·
(low confidence) Iteration 3 asked for the Linux and Windows platforms the update documents; Windows was added, Linux was not. The Update section, summary and record all say macOS, Linux and Windows. ·
F15
name-collision-unflagged
·
(low confidence) Talos' CAIRN is a distinct Cisco toolkit, but 'other projects of that name' also asserts that Gambit's Cairn is a different project, which neither source establishes: Gambit (https://·
F11
editorial-advisory
·
Advisory. The subject malware families have no registry record or key: FLATROOF and ROOFDECK (the update now gives them a second publisher, so entity pages cannot aggregate the Zscaler reporting) and ·
F11
editorial-advisory
·
Advisory, judged as asked: T1199 (Trusted Relationship) describes using a third party's access to reach the target, and no cited source says the attackers did that against Publica or the federal bodie·

Iteration #5 CLEAN · 5 findings (truth=0, editorial=0, advisory=5) · Claude Sonnet 5.5 · 15m 34s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
·
Advisory, may be left. (a) The single admin.ch citation closes a clause chain whose first part ('no ... ransom demand is public') admin.ch does not carry; only watson does (Publica 'wollte ... nicht s·
F11
editorial-advisory
·
Advisory, may be left. The iteration-4 fix is accurate (ReliaQuest: 'a legitimate open-source orchestration platform for coordinating AI agents on multi-step tasks'; Talos' CAIRN is Cisco-Talos/CAIRN ·
F11
editorial-advisory
·
Advisory. The store already carries 2026-06-26/macos-gaslight-a-dprk-aligned-rust-backdoor-that-targets-the (macOS.Gaslight, a DPRK backdoor whose blob of fabricated system messages is aimed at LLM tr·
F11
editorial-advisory
·
Judged: accept and leave. The attackers breached a supplier that holds the target's pension-administration data, which is the situation T1199 (Trusted Relationship: breach or leverage organizations wh·
F11
editorial-advisory
·
Judged: acceptable. The entry is a class-level study of one technique across four Talos-named families plus ESET's loader context; keying five malware records from one clause each would create registr·

Iteration #6 NEEDS_FIXES · 6 findings (truth=1, editorial=0, advisory=5) · Claude Sonnet 5.5 · 17m 17s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
Contradicted by the published entries and by the record's own Single-source bullet. entries/2026-10-09/cve-2026-107406-citrix-netscaler-saml-idp-overflow.md lists the community blog (.../protecting-cu·
F11
editorial-advisory
·
(low confidence) ASD's ACSC alert already cited by the 88779 entry (https://www.cyber.gov.au/alert/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products) now carries a·
F11
editorial-advisory
·
(low confidence) The Confederation release the entry lists as its first primary is headlined 'Cyberangriff auf Softwarelieferant von Publica: Datenabfluss bestätigt' and says 'Publica informierte die ·
F11
editorial-advisory
·
(low confidence) cti-run.md 'The incident floor': an incident with no access vector, no actor and no behavior beyond the impact is 'routine and at most two sentences plus its transfer ground'. Priorit·
F11
editorial-advisory
·
(low confidence) SentinelLabs describes ROOFDECK resolving C2 from Nostr first ('it reads the website field of the profile and uses that as its C2 URL') with pastebin_key as a 'secondary resolver'; Zs·
F11
editorial-advisory
·
(low confidence) AA26-281A lists ten EBurst interfaces; the entry's list omits 'Application Programming Interface (API)'. Not a false statement, an incomplete list.·

Iteration #7 CLEAN · 5 findings (truth=0, editorial=0, advisory=5) · Claude Sonnet 5.5 · 14m 16s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
·
(low confidence) Left-on-purpose length judged: the incident floor allows two sentences plus the transfer ground; the narrative paragraph still holds three fact-bearing sentences (event; population an·
F11
editorial-advisory
·
(low confidence) Cite placement: the sentence's single citation is the blog, which carries only the second half; the first half is a statement about the bulletin CTX697191 itself (true: the bulletin t·
F11
editorial-advisory
·
(low confidence) Optional corroboration for a Swiss readership: NCSC-CH published an advisory on CVE-2026-107406 at 2026-10-09T05:42Z (fetched this iteration via ncsc-csh recent; exploitation status U·
F11
editorial-advisory
·
(low confidence) Pre-existing text, unchanged by this run: the heise citation carries the request-volume rationale and 'massive spontaneous reboots' but not the nsaaad service or the failovers, which ·
F11
editorial-advisory
·
(low confidence) After iteration 6 the entry cites ASD's ACSC alert update of 2026-10-09 (checked this iteration: 'Recent update 9 October 2026 ... Previous patches ... are insufficient') as a restati·

Iteration #8 CLEAN · 8 findings (truth=0, editorial=0, advisory=8) · Claude Sonnet 5.5 · 16m 27s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
·
(low confidence) The entry's 'every internet-facing appliance' drops CERT-EU's 'running an affected build' qualifier; wording only.·
F11
editorial-advisory
·
(low confidence) The improvement record type could arguably be an update for a new CVE in the chain; the two other entries already float for the development.·
F11
editorial-advisory
·
(low confidence) T1055.012, T1115 and T1560.001 are mapped from Zscaler's table but the Update section does not describe process hollowing, clipboard reads or archiving.·
F11
editorial-advisory
·
(low confidence) 'No independent report of exploitation had surfaced as of 2026-10-09' is an uncited absence claim.·
F11
editorial-advisory
·
(low confidence) The narrative paragraph has three fact sentences against the incident-floor wording of two plus the transfer ground.·
F11
editorial-advisory
·
(low confidence) The Detection-line heise citation carries the request-volume rationale; the nsaaad and failover details come from Cyber Press.·
F11
editorial-advisory
·
(low confidence) The Justice Department release states the announcement date, not the date of the seizures.·
F11
editorial-advisory
·
(low confidence) Optional corroboration for a Swiss readership; not an omission.·

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-10-09T0255Z-intel · Sonnet 5.5 · window 25 h · 5 entries published

Verification & coverage notes

  • Window: 25 h (gap 22.9 h to 2026-10-08T0404Z-intel), a standard window. Five new entries and three changelog records (two update, one improvement). No deep dive: no candidate cleared the Phase 3 bar (exploitation with constituency exposure, or substantive analysis of extreme relevance).
  • KEV sweep (work/2026-10-09T0255Z-intel/kev-window.txt): five additions dated 2026-10-08, all NOT COVERED at the start of the run (ProFTPD CVE-2015-3306, ISC BIND CVE-2015-5477, Apache Struts CVE-2016-3081, ONLYOFFICE Docs CVE-2021-3199, Strapi CVE-2023-22894). All five are listed as successfully exploited in joint advisory AA26-281A (Appendix B), which is the "what changed"; each is carried in the 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft entry's cves[] as exploited and cisa-kev, together with the advisory's three older listed CVEs. No KEV addition dated 2026-10-09 existed at 03:30 UTC (catalog 2026.10.08). The ransomware-flag cross-check printed no row.
  • Backlog (state/coverage_backlog.md, six open rows, all re-gated on today's facts, all held, none struck, none published): IBM MQ CVE-2026-10747 and the Langflow CVEs (S1: none in KEV catalog 2026.10.08, no exploitation report or PoC; expiry 2026-10-11 stands); MikroTik CVE-2026-84411 (S1: CISA now says "<7.24 / update to 7.24 or later", MikroTik's changelogs still do not name the CVE, no KEV; expiry 2026-10-14); IBM Guardium CVE-2026-85542 (S1: three further unauthenticated 9.8 Guardium CVEs published 2026-10-08, still no KEV or IBM exploitation statement, dated note appended; expiry 2026-10-14); SafePay ARA-Region Lyss-Limpachtal and Payload Netech (S4: no victim statement or press report; no note appended, nothing changed; expiry 2026-10-14); Beyond Gravity (S2: neither BACS, the company nor any report names a vector, an actor or the data affected; nothing changed; expiry 2026-10-20).
  • Updates: NetScaler CVE-2026-88779 (update: Citrix bulletin CTX697191 lists the .41 and .28 builds that fix it as affected by CVE-2026-107406 on SAML identity-provider appliances; summary, actions, references, sources and the takeaway moved; the entry keeps its own SAML upgrade task and points identity providers to the new builds); NetScaler CVE-2026-88771 (improvement: pointers to the SAML builds now carry the later flaw; no float); TraderTraitor Terraform entry (update: Zscaler ThreatLabz independently describes a trojanized provider binary that executes at plugin load and delivers FLATROOF and ROOFDECK on macOS, Linux and Windows; a second delivery form and a second publisher).
  • New entries: Publica and PK Softech (routine, trimmed to the incident floor after verifier iteration 1; PD-11 (c): confirmed supplier intrusion and data outflow touching the staff of the federal administration and the ETH domain, Federal Prosecutor's Office investigating, the strongest home-region item of the window, but no vector, actor or behaviour is public; its two actions and the Defender takeaway carry the decision; mapped to T1199 as the closest available id, which describes use of a trusted third party that no source says the attackers made against Publica), Citrix CVE-2026-107406 (notable after iteration 1: pre-authentication code-execution-capable memory overflow on an internet-facing SAML gateway that reaches the builds Citrix named as the fix five days earlier, but unexploited per Citrix's own blog, AC:H and a SAML precondition, so the high disqualifiers apply), AA26-281A (notable; PD-11 (c) and (d): a joint advisory on a China-linked enabler whose actors spray Exchange and Microsoft 365 and steal mail from government, law-enforcement and healthcare targets; no Swiss victim named), Talos AI-analysis evasion (notable; PD-11 (d): a detection surface and a pipeline-hardening rule for SOCs that use LLM triage; Talos itself calls the effect mixed), ReliaQuest agent-driven intrusion (notable; PD-11 (d): detection-grade mechanics on an unauthenticated job-submission feature on Tomcat; the agent-driven reading is ReliaQuest's assessment).
  • Single-source: Citrix CVE-2026-107406 rests on the vendor bulletin and Citrix's own blog (single-source, A2; no CERT or outlet had covered it when composed, and ASD's ACSC has since restated the disclosure without adding an observation); ReliaQuest rests on ReliaQuest alone (single-source, medium confidence, lookback item: published 2026-10-07 and first coverage from a rotational record); AA26-281A is single-source-national-cert because the advisory, the Justice Department release and the NCSC UK page all rest on the FBI's investigations.
  • Dedup: the AA26-281A entry references 2026-08-28/doj-fbi-qscan-qtrouter-prc-hacking-as-a-service-takedown (an earlier PRC enabler takedown; no CVE overlap). The ReliaQuest entry deliberately does not key tool:cairn-exploitation-engine: that record is Gambit's Cairn and neither source links the two projects that share the name.
  • borderline-drop: Cisco 2026-10-07 batch (35 CVEs; NX-API, NGOAM and MPLS OAM RCE flaws are feature-gated, License On-Prem is a management server, none exploited, no KEV, regular cycle under PD-11 (b)); HPE ClearPass and AOS-S HPESBNW05156 and -05158 (unauthenticated 9.8 flaws on management planes, no exploit code, regular cycle); IBM Verify Access, DataPower and Guardium bulletins of 2026-09-18 to 2026-10-08 (unauthenticated 9.8 flaws, no exploitation statement, no constituency deployment shown); Splunk Enterprise SVD-2026-1001 and -1002 (CVE-2026-76268 needs reach to the Patroni REST API of a search-head-cluster member, 10.4 and 10.2 only, internal); ILIAS 9.24, 10.12 and 11.5 (RCE paths need authentication, no CVE ids, no exploitation; published 19 h before the window and dropped by the previous fire).
  • borderline-drop: WatchGuard Fireware 2026-09-29 builds (every pre-auth item needs attacker control of a VPN peer, adjacency or prior write access), Veeam Backup and Replication 12.3.2 P4 (needs the Backup Viewer role), Exchange out-of-band CVE-2026-96940 (needs a click, not exploited, dated 2026-10-02), Microsoft cloud-service CVEs of 2026-10-08 (no customer action), Android bulletin 2026-10-01, OpenSSH 10.6, Ollama CVE-2026-103663 (CERT Polska, no exploitation, ambiguous range), HPE IMC CVE-2026-79842, Hazelcast, fast-jwt, SGLang, Jackrabbit, Movable Type and Tenable Identity Exposure (no exploitation signal or constituency nexus).
  • borderline-drop: ChainDrop npm worm reaches the tensorlake package (a new, low-footprint package in a covered campaign; the existing entry already carries the dead-man-switch and rotation guidance), Talos UAT-11985 (Taiwan research bodies, a Google-themed relay kit, technique class only), .gh, .sl and .as registry hijacks (no Swiss nexus, previously dropped), DNSSEC root KSK rollover of 2026-10-11 (an operational deadline and not threat activity; ICANN reports more than 95 percent of reporting resolvers ready, no Swiss authority notice; returned by S2 and S3, dropped as a considered borderline), KrebsOnSecurity on the ShinyHunters suspect in Jordan (the Jordan detention is already carried in the FBI entry), CrowdStrike ARTEX (South Korean banks, infrastructure and prompt history only), EDPB publication of the Miljodata and E.E.T.A.A. decisions (GDPR does not bind Swiss bodies; decisions dated 22 September and 28 July), Fox-IT Cobalt Strike Beacon corpus (research dataset, no Swiss nexus), Kiteworks NCSC-NL bundle of 61 CVE ids (improvement-only: no exploitation or fix change, most need administrator authentication).
  • borderline-drop: IDC Frontier cloud ransomware in Japan (no vector or actor), ASOS push-notification extortion (UK retailer, vector now stated but no public-sector nexus), T-Systems and SafePay (a victim statement now exists: a small test system, nothing sensitive; below the incident floor), Arizona courts, France Travail sale claim, Saint-Pierre-des-Corps, AP-HP and Dedalus, Eau Coeur d'Essonne and other claim-only French items, the Polish FELG breach (outside window, nexus or both). Claim-only watch for the next fire: Leadec and the University of Rostock, still no notice or press.
  • Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0 (the profile configures none).
  • Coverage gaps: ilias-vendor-security-blog (captcha; versions read from BSI), citrix-community-blog-permalinks (403 on the direct transports, read through the reader and cited), watchguard-psirt (one per-CVE page 403), cisa.gov AA26-281A PDF (403, read through the FBI IC3 mirror), cyberinsider (undated listing), ssd-disclosure not in this slice.
  • Source rotation: the previous two fires' attempts (111 records) were excluded from the S1, S2 and S3 slices as a belt-and-braces measure and the cursor-ranked pool supplied the slices; S4's pool of 19 breach sources was allocated oldest-cursor first without that exclusion because every breach source had been attempted by the previous two fires. S1, S2, S3 and S4 returned complete ledgers (25, 18, 14 and 12 rows); no continuation was needed. Promotions: cccs-alerts and sonicwall-psirt (promotion_due). Candidates added: splunk-advisories and hpe-networking-psirt (first-party vendor PSIRT tables).
  • For the audit: S3 reports natto-thoughts (Natto Team: China commercial-hacking analysis) as a candidate, not added this fire; CERT-UA article pages are an SPA (feed https://cert.gov.ua/api/articles/rss works); the bsi-rss cap is flooded by bulk [UPDATE] refreshes; the Kiteworks entry carries 8 of NCSC-NL's 61 CVE ids (nine rated 9.1 to 9.8, none exploited, most administrator-authenticated), an improvement-only enrichment no reader decision turns on.

← Operations dashboard · run-record contract: docs/pipeline.md