CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

2026-10-10T0255Z-intel

One pipeline fire, in full · intel run of 2026-10-10 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-10-10/2026-10-10T0255Z-intel.md.

Run telemetry

2026-10-10T0255Z-intel intel prompt v4.19 publish ok
2h 48m duration 3 published 5 updates
Claude Sonnet 5.5 (claude-sonnet-5-5) main agent
S1 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
12
Duration
31m 04s
Tool calls
6 WebFetch19 WebSearch115 bridge
Cited sources
7 of 29 in slice
S2 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
3
Duration
17m 47s
Tool calls
3 WebFetch30 WebSearch78 bridge
Cited sources
2 of 19 in slice
S3 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
0
Duration
10m 29s
Tool calls
0 WebFetch19 WebSearch85 bridge
Cited sources
0 of 14 in slice
S4 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
1
Duration
19m 02s
Tool calls
7 WebFetch31 WebSearch90 bridge
Cited sources
1 of 10 in slice
FU1 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
1
Duration
7m 32s
Tool calls
0 WebFetch12 WebSearch18 bridge
Cited sources
2 of 4 in slice

Verification

#1 NEEDS_FIXES · Sonnet 5.5 · t=20 e=5 a=6 #2 NEEDS_FIXES · Sonnet 5.5 · t=7 e=2 a=5 #3 NEEDS_FIXES · Sonnet 5.5 · t=5 e=2 a=3 #4 NEEDS_FIXES · Sonnet 5.5 · t=4 e=1 a=2 #5 NEEDS_FIXES · Sonnet 5.5 · t=0 e=2 a=1

Deep dive

·

Entries this run published (3) and updated (5)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

13 last_successful_fetch · 9 notes · 2 added · 1 status · 1 rss_url.

SourceChangeFrom → ToReason
citrix-netscaler-security-bulletinsstatuscandidate → activepromotion_due: cited by published entries from 3 distinct runs
stepsecurity-blogadded· → status: candidateAdded 2026-10-10: CI/CD and GitHub Actions supply-chain research with run-log forensics; the primary of the GhostAction entry
zammad-github-advisoriesadded· → status: candidateAdded 2026-10-10: Zammad publishes advisories as GitHub security advisories since April 2026; the primary of the 7.2.2 update
scip-chrss_url· → https://www.scip.ch/?rss.labsS2 found the feed and the main agent verified it parses with dated items on the direct transport
mikrotik-routeros-changeloglast_successful_fetch· → 2026-10-10fetched and used (the MikroTik notice is the primary of a new entry); recipe note added: notices live at mikrotik.com/supportsec/cve-<year>-<id>
huntresslast_successful_fetch2026-10-08 → 2026-10-10fetched and used (primary of the AhsayCBS entry)
watchtowrlast_successful_fetch2026-10-07 → 2026-10-10fetched and used (cited in the PaperCut update)
senthorus-chlast_successful_fetch2026-09-13 → 2026-10-10fetched and used (cited in the SAP update)
onapsislast_successful_fetch2026-09-14 → 2026-10-10fetched and used (cited in the SAP update)
socket-dev-bloglast_successful_fetch2026-09-07 → 2026-10-10fetched and used (cited in the GhostAction entry)
previdianlast_successful_fetch2026-10-08 → 2026-10-10fetched and used (cited in the SonicWall update)
bleepingcomputerlast_successful_fetch2026-10-08 → 2026-10-10fetched and used (cited in the SonicWall update, the AhsayCBS and MikroTik entries)
securityweeklast_successful_fetch2026-10-07 → 2026-10-10fetched and used (cited in the AhsayCBS entry)
inside-it-chlast_successful_fetch2026-10-09 → 2026-10-10fetched and used (cited in the Publica update)
netzwochelast_successful_fetch2026-10-09 → 2026-10-10fetched and used (cited in the Publica update)
cisa-kevlast_successful_fetch2026-10-09 → 2026-10-10fetched and used (catalogue cited in the MikroTik entry)
cisa-advisorieslast_successful_fetch2026-10-09 → 2026-10-10fetched and used (ICSA-26-272-06 is cited in the MikroTik entry)
netcraftnotes· → recipe note appendedextract returns navigation text only; url on the blog listing returns the card HTML
swarmcha-senotes· → recipe note appendeduse url --direct for the listing; extract spends reader credit
helpnetsecuritynotes· → recipe note appendedextract returns raw HTML for the front page
kela-cybernotes· → recipe note appendedthe research listing page carries the titles
ransomware-livenotes· → recipe note appendedv2 API endpoints countryvictims, countrycyberattacks and searchvictims read with url --direct
ncsc-ienotes· → recipe note appendedextract of the news page returns the dated advisory list
cisa-advisoriesnotes· → recipe note appendedfeed on all.xml spends reader credit and lists ICS items only
chrome-releasesnotes· → recipe note appendedno working command for desktop stable posts
mozilla-mfsanotes· → recipe note appendedextract drops list items; WebFetch of the index works

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
chrome-releaseshttps://chromereleases.googleblog.com/feed → extract → bridge:jina302 redirect
the feed answers HTTP 302 on direct fetch and the reader returns no items; extract of the label page returns only the newest post (ChromeOS), so the desktop Chrome 155 post was not read from Google (S1)
dates and the no-exploitation statement for Chrome 155 came from a third-party report and a search; the item was borderline-dropped, so nothing depended on the Google page
consilium-eu-cyber-sanctionshttps://www.consilium.europa.eu/en/policies/sanctions-against-cyber-attacks/extract → bridge:jina → webfetch403 waf-block
consilium.europa.eu pages answer 403 on direct, extract, the reader and WebFetch, so the EU cyber-sanctions watch relied on search snippets (S2)
no EU cyber-sanctions designation surfaced in the window through search; the standing policy-watch line for sanctions is covered only at snippet depth
ara-lyss-chhttps://www.ara-lyss.ch/url403 waf-block
the victim site of the held SafePay claim answers 403 to the bridge, so no victim-side notice could be read (S4)
the backlog row stays held on the tracker record, which carries no press confirmation

Bridge invocations (this run)

7 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

7 other
  • pdf ×1
  • cisa csaf ×1
  • cisa-kev ×1
  • url (CVE record API, read only, never cited) ×1
  • url --direct ×1
  • bsi-csaf ×1
  • extract ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 31 findings (truth=20, editorial=5, advisory=6) · Claude Sonnet 5.5 · 19m 40s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
claims f2e531b28b/e08e502feb/b2d4026edc/e720599f34: "in seconds", segmentation, volunteer-data exfiltration, agent "justifies its own actions", "no link to a known threat actor" are not on the cited c·
F3
claim-not-supported
·
(low confidence) GHSA-p97w-927q-8vxq: "could have escalated within seconds"; hedge dropped.·
F3
claim-not-supported
·
claim 45ccc53ea4: restart/no-workaround are in The Hacker News 2026-10-07 only; the BC 2026-10-09 article does not carry them. Cite THN for that clause.·
F3
claim-not-supported
·
claim 7464bf51ee (low confidence): page shows 135 attempts, 2 unique attacker IPs, 1 attacker country, "US" under Sensors observed; never says one sensor.·
F3
claim-not-supported
·
claims 73c84e5727/b796aa609e/585cfd2b3e + run-record notes: JSON-LD datePublished is 2026-09-18 (dateModified 2026-09-24); citation date six days off. Content otherwise supported.·
F3
claim-not-supported
·
claim 54a9d6ff32: CERT-EU 2026-011 does not name the ICM/Web Dispatcher, SAP Dispatcher and RFC routes; they are in Onapsis sap-overpass-remediation.·
F3
claim-not-supported
·
claim c30041cde8: Rapid7 says only "broadly exploited in the wild by multiple threat-actor groups, including ransomware operators"; "authentication-bypass", "before a patch existed", "incident-respons·
F3
claim-not-supported
·
claim 8eac31d683 (low confidence): live PaperCut bulletin (updated 10 Sept) has no university/reproduction text; Rapid7 carries it. Cite Rapid7.·
F3
claim-not-supported
·
claims e676765f4b, 9fdb6088a2 (low confidence): Huntress has no absence statement; the bulletin does not say EPR2 closed the Home-page bypass (Rapid7 does).·
F3
claim-not-supported
·
claim 459b76a711 (low confidence): BC says "Recently"; no month.·
F3
claim-not-supported
·
claim 5254281c0d (low confidence): MikroTik says "could crash the service or allow ... code"; no failed-attempt outcome or restart telemetry stated; analyst inference cited to vendor.·
F3
claim-not-supported
·
claim 1730640578: GitGuardian supports only "rotating the secrets ... is not enough. The GitHub credential ... must be found and revoked too"; scan-history/treat-each-run guidance is StepSecurity.·
F3
claim-not-supported
·
claim 5f53d8a02e (low confidence): StepSecurity's 378 is a cumulative live-workflow count for the C2 address across all waves (endpoint seen since 5 Sept), not a since-7-October figure.·
F3
claim-not-supported
·
claim 8a2ec2e4aa (low confidence): admin.ch says "weitere Kunden informiert" and names none of them.·
F4
hallucinated-fact
·
claim aac577f8c8: superseded by Zammad 7.2.2 (2026-10-08) per https://zammad.com/en/product/releases/7-2-2 and this run's own section. Update the field.·
F4
hallucinated-fact
·
claim 75bcd3abb9: vendor GHSA-p97w-927q-8vxq lists CVE-2026-102490 (HTML and API cve_id; cvss_v4 8.5; vulnerable <= 7.2.1; patched 7.2.2) and DIVD-2026-00014 states the second flaw is fixed in 7.2.2. ·
F4
hallucinated-fact
·
claim dd16a61aaa (low confidence): not in Onapsis (OVERPASS/S4GET) or CERT-EU; Onapsis mechanism is IP-trust abuse then Gateway access; uncited Triage discriminator.·
F4
hallucinated-fact
·
claim dcc41e4981: PaperCut Sept bulletin lists CVE-2026-82077 fixed only in 26.0.5 and 25.0.13; no 24.x release named (the entry's own actions[0] says so).·
F14
quantifier-without-source
·
claim a52918fec6 (low confidence): GreyNoise "at least 440 instances ... 395 identified victim organizations ... other real victims"; "at least" dropped.·
F14
quantifier-without-source
·
claim d881c75093 (low confidence): no source states the absolute.·
F5
missing-citation
·
claims 863c8f0e41, 9f87404e7b (low confidence): scores match VulDB CNA records but no sources[] record carries them; cite a VulDB per-vuln page or reduce to the Huntress severity wording.·
F9
surface-contradiction
·
PaperCut bulletin (cited) FAQ: "Emergency Patch Release 3 ... closes off additional attack vectors we have observed being exploited in the wild"; watchTowr: build 76530 (EPR3) fixes WT-2026-0143; Rapi·
F7
drop
·
(low confidence) no exploitation, no public PoC, not KEV, default-firewall blocks exposure, no constituency footprint shown; consider routine / two sentences.·
F8
needs-more-research
·
(low confidence) Previdian honeypot first-observation (09 Oct 08:49 UTC) does not bound real-world probing; advisory public since 2026-10-06. Start at 2026-10-06 or earliest retained log.·
F18
action-item-discipline
·
(low confidence) each restates body Detection/hardening guidance; keep the compromise-check task, drop restated clauses.·
F11
editorial-advisory
·
Style rule 12: no em dash in reader-facing text.·
F11
editorial-advisory
·
attacker file/service-name indicators (style rule 12 IOC list).·
F11
editorial-advisory
·
workflow-internal / composition-rationale language in reader-facing fields.·
F11
editorial-advisory
·
source-mapped behaviours without ids.·
F11
editorial-advisory
·
cited page carries stronger wording than the entry; derivative of BC/Previdian, mention or note.·
F11
editorial-advisory
·
a cited page already states the fix; entry frames it as resting on the CVE record alone (see F4 above).·

Iteration #2 NEEDS_FIXES · 14 findings (truth=7, editorial=2, advisory=5) · Claude Sonnet 5.5 · 16m 11s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Iteration-1 finding not remediated (claim text and citation are unchanged). The cited case page has no segmentation text (0 hits for "segment" in the raw HTML and the extract); "Thanks to proper netwo·
F3
claim-not-supported
·
Citation date does not match the page: dateline "Last modified 09 Oct 2026 20:01 CEST", timeline "29 Sep 2026 Publication of casefile"; neither is 2026-10-01. The sentence this fire added ("DIVD's cas·
F3
claim-not-supported
·
The Huntress page says "Ahsay 10.3.4 is also affected" but never calls 10.3.4 the latest version; that is BleepingComputer ("currently the latest version") and SecurityWeek ("the latest AhsayCBS versi·
F3
claim-not-supported
·
Huntress carries only "for which no patch is currently available" (dated 28 Aug) and the 47% figure; the upgrade-to-a-supported-line guidance is in PaperCut's bulletin FAQ ("There are no emergency pat·
F3
claim-not-supported
·
StepSecurity's org-scoped queries search for content markers (AKIA_CTX_START, c=monami, the C2 address), not for file names; the two file names appear in its "treat as confirmed breach" callout and So·
F13
analytical-link-as-fact
·
AV26-1017 Update 1 says only "Open source reporting indicates that CVE-2026-102255 is being exploited in the wild." and names no source. Equating it with the Previdian/BleepingComputer report is the e·
F14
quantifier-without-source
·
GreyNoise: fastest domain admin five minutes, longest 144 minutes, and "multiple-day delays between initial access and achievement of domain admin" for some victims, and only 12 of the victims reached·
F16
org-triage
·
The update's delta (watchTowr bypass analysis of superseded emergency builds; CVE-2026-82077 is admin-only; "No source names exploitation of CVE-2026-82077 or of the Setup Wizard bypass") is not time-·
F18
action-item-discipline
·
Four tasks in one action; the log-script, package and template clauses restate the body Detection paragraph. Keep the upgrade and the compromise check as two short actions (or one), drop the restated ·
F11
editorial-advisory
·
Style rule 12 (no em dash in reader-facing text). Declined for settled text in iteration 1; noted again because the SAP paragraph rewritten this fire still contains them.·
F11
editorial-advisory
·
Rule 12 lists "mutex or file-name indicators" among the IOC classes to exclude; these are attacker-chosen file and service names. Declined once as behaviour-level hunting artifacts; the main agent dec·
F11
editorial-advisory
·
Rule 12: sourcing_note is two sentences of provenance; Admiralty letters, "sources.json" and credibility wording are workflow-internal. Zammad and Publica carry dispute analysis and per-source comment·
F11
editorial-advisory
·
Metadata narration about the entry's own priority in a reader-facing changelog summary; the delta is the customers and funds, not the rating.·
F11
editorial-advisory
·
Check 4c(f): rewrites of previously shipped text are corrections. `body` is named in fields so the gate passes, but the record summary tells readers only about the new delta; consider a separate `corr·

Iteration #3 NEEDS_FIXES · 10 findings (truth=5, editorial=2, advisory=3) · Claude Sonnet 5.5 · 16m 05s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Citation date is neither the page's publication date (27 Aug 2026) nor its visible dateline ("Last updated September 10, 2026"). The clauses report events the page's Updates table dates 1 Sept ("Publi·
F4
hallucinated-fact
·
The release triple appears in none of the pages fetched this iteration (PaperCut bulletin of 2026-09-10, Huntress, Rapid7, watchTowr, GreyNoise, CERT-FR): 24.1.9 occurs nowhere; Huntress ties 25.0.12 ·
F3
claim-not-supported
·
The summary, actions and body now attribute "latest version" to BleepingComputer, but the headline still puts it under the "Huntress:" prefix. The Huntress page says only "Ahsay 10.3.4 is also affecte·
F13
analytical-link-as-fact
·
AV26-1017 Update 1 says only "Open source reporting indicates that CVE-2026-102255 is being exploited in the wild." and names no source, so "rests on one observer" / "single-source" is the entry's inf·
F3
claim-not-supported
·
StepSecurity's callout names two workflows: "If a workflow named “Security Audit” (security-audit.yml) or “Github Actions Security” (github_actions_security.yml) appeared in any repository you maintai·
F5
missing-citation
·
Only the BPK notice says it ("Zum jetzigen Zeitpunkt gibt es keine Hinweise, dass Daten der BPK gestohlen wurden. Jedoch kann dies nicht restlos ausgeschlossen werden"). The BLVK notice the body cites·
F18
action-item-discipline
·
Still a compound of four clauses that restate the body Detection paragraph (log script, package and template artifacts, root-owned files). Iteration 2 asked to keep the compromise check as a short tas·
F11
editorial-advisory
·
Rule 12: two sentences of provenance. These four notes still run to three sentences and carry dispute and count analysis that the bodies already state; SAP's note still uses the Admiralty word "credib·
F11
editorial-advisory
·
Narration about the entry's own rating in a reader-facing changelog summary (the same shape as the Publica sentence removed after iteration 2); "stop-and-act bar" is pipeline priority vocabulary. `pri·
F11
editorial-advisory
·
Declined twice for settled text; noted unchanged. The SAP opening paragraph was re-edited this fire (Onapsis citation added) and still carries the dashes. Advisory.·

Iteration #4 NEEDS_FIXES · 7 findings (truth=4, editorial=1, advisory=2) · Claude Sonnet 5.5 · 16m 43s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Iteration-3 remediation only half-applied. https://www.stepsecurity.io/blog/ghostaction-returns says: "If a workflow named “Security Audit” (security-audit.yml) or “Github Actions Security” (github_ac·
F3
claim-not-supported
·
Huntress states the output-file and server.log deletion only for the 26 August incident: "After exploitation, the .class file deletes its own `Udydn.out` file, as well as the server's `server.log` fil·
F3
claim-not-supported
·
The feed read this iteration has catalogVersion 2026.10.08 and dateReleased 2026-10-08T20:09:18Z, so the citation date (2026-10-10, the day the pipeline read it) is two days off the source's own date ·
F3
claim-not-supported
·
The cited Onapsis page describes: "With a specially crafted packet sent to the Message Server’s public port, an unauthenticated attacker can have an IP treated as trusted ... The attacker then connect·
F8
needs-more-research
·
Actionability contract (prompts/cti-run.md Phase 4): a labelled line its sources clearly support and that is missing is F8. Onapsis supports SAP **Exposure:** (kernel release and patch-level check via·
F11
editorial-advisory
·
Style rule 12. Declined as settled text in iterations 1 to 3; noted unchanged, advisory only. The cves[].fixed and the SAP paragraph were edited this fire and still carry the dash.·
F11
editorial-advisory
·
The BLVK notice says "ob und in welchem Umfang" (whether and to what extent), not "how". Also consider the incident floor (Phase 4): sources give no access vector and no actor, so a routine rating at ·

Iteration #5 NEEDS_FIXES cap-breach · 3 findings (truth=0, editorial=2, advisory=1) · Claude Sonnet 5.5 · 14m 14s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F8
needs-more-research
·
The hunt scope the entry hands the reader omits a third disguise its own sources list. StepSecurity (https://www.stepsecurity.io/blog/ghostaction-returns) IOC table, "Workflow files": security-audit.y·
F8
needs-more-research
·
Onapsis (https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/) states the exposure check the entry never gives: "The check is a single data point: your kernel release and ·
F11
editorial-advisory
·
Style rule 12. Declined as settled text in iterations 1 to 4. None of the text this fire added or rewrote carries a dash (checked in git diff HEAD); the remaining dashes sit in text this fire did not ·

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-10-10T0255Z-intel · Sonnet 5.5 · window 26 h · 3 entries published

Verification & coverage notes

Coverage window: standard fire. The previous intel fire started 2026-10-09T02:55:59Z, so gap_hours=24.0 and window_hours=26; the developing-story window was 72 hours. The clock cross-check against the network date agreed (skew 0 s) and the fresh fetch showed the newest run record of 2026-10-09T0255Z.

Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found no KEV addition since 2026-10-09 (catalog 2026.10.08, released 2026-10-08T20:09Z; the five old CVEs added on 2026-10-08 are inside the AA26-281A entry) and no RANSOMWARE row. S1 confirmed it through the cisa-kev recipe and found no ransomware-flag flip on a covered CVE. The 2026-10-10 re-read of the catalogue shows none of CVE-2026-84411, -102255, -105133, -105134 or -82077 listed. No scheduled multi-product release fell in the window (Microsoft, SAP and Fortinet on 2026-10-13, Oracle on 2026-10-20, Cisco on 2026-10-21).

Verification: five cold iterations, each a fresh cti-verification pass over the full ledger (204 to 214 claims, all checked). Iterations 1 to 4 returned NEEDS_FIXES (truth 20, 7, 5 and 4; editorial 5, 2, 2 and 1) and every truth finding was remediated and re-checked by the next pass. Iteration 5 returned NEEDS_FIXES with truth 0 and editorial 2 (both F8: a third disguise name missing from the GhostAction hunt scope, an Exposure line missing from the SAP entry) and no F1 or F4, so the low-residual early exit applies: both were fixed after the pass and the run publishes without a sixth iteration. The residual count is the final iteration's two editorial findings. Standing advisories, unfixed on purpose: em dashes in older PaperCut and SAP text this fire did not touch, and the missing Exposure line on the PaperCut entry.

New entries (3):

  • MikroTik RouterOS CVE-2026-84411 (vulnerability, routine after verifier iteration 1; pre-auth web-management RCE, MikroTik's own notice now names the fix; PD-11(b) on its own mechanics, a single unauthenticated request to root on an edge router class that botnets target, with the default firewall keeping the interface off the internet and no exploitation, which holds it at routine; resolves the backlog row).
  • AhsayCBS CVE-2026-105133 / CVE-2026-105134 (vulnerability, notable; exploited from 2026-10-07 with webshells and a miner, 10.3.4 also affected and no fixed release named; PD-11(b); the nexus is the managed-service-provider and integrator class that serves public bodies, so it is notable and not high; single-source on Huntress, Admiralty B2).
  • GhostAction (threat, notable; stolen maintainer credentials, confirmed exfiltration at an Uber-owned repository, history-wide credential sweep that makes secret rotation insufficient; PD-11(a) and (d): an organisation-scoped search and an audit-log query take minutes; no public-sector victim is named, the ground is GitHub-hosted developer estates of public bodies and their suppliers; Admiralty B1 from three independent analyses; the "tens of thousands" figure in one vendor's update line is not carried).

Updates (5): Publica / PK Softech (update: the Bernische Pensionskasse's own notice says its supplier is Publica's, the Bernische Lehrerversicherungskasse and Pensionskasse Post report the supplier incident, Inside IT lists two more funds; priority moves routine to notable because cantonal public-law institutions are now directly involved); Zammad (update: 7.2.2 fixes the zammad-to-root escalation on DEB and RPM installs, no-patch leaves the CVE record and the tags, title, headline, summary, actions and the two body paragraphs that said no fix was named were rewritten where they stood); SonicWall SMA1000 CVE-2026-102255 (update: single-source honeypot-operator report of exploitation attempts, success unknown, vendor still says no evidence; the CVE status is deliberately left at patch-available because the exploitation claim rests on one observer, and the Canadian Cyber Centre's update of 2026-10-09 says open source reporting indicates exploitation); PaperCut NG/MF (update; priority moves from critical to high after verifier iteration 2 because the in-window weaponisation the critical bar needs has passed and the delta is not time-critical, with immediate_action cleared: watchTowr's write-up of the bypasses of the emergency builds and CVE-2026-82077, an administrator-only Scan-to-Fax RCE that the vendor's September bulletin lists as fixed only in 26.0.5 and 25.0.13; read from the vendor bulletin, the CVE added to the record and the immediate action reworded); SAP September Patch Day (update, PD-7(d) lookback: Onapsis reports SAPMAP, an open-source toolkit public since 2026-09-15 that carries proof-of-concept exploits for OVERPASS and S4GET; status moves to poc-public; the freshest source, Senthorus of 2026-10-06, sits at the edge of its 96 h lookback and the Onapsis article was published on 2026-09-18 (modified 2026-09-24), so the audit should treat the item as a late recovery of a development the store missed for three weeks).

Source allocation: slices S1 29, S2 19, S3 14, S4 10 records (S1: 14 essential plus 13 rotation plus Citrix and SonicWall PSIRT added by hand; S4's pool was refilled from the previous two fires' attempts because every record in the domain had been attempted in them; 19 records were excluded as recent attempts elsewhere), every record with a ledger row, so no continuation was needed. One scoped follow-up spawn, FU1, took three cross-domain leads S1 and S3 had not researched (GhostAction, P7 DarkSword, NVIDIA DCGM) plus a bounded headline sweep; it returned one item, and the other two leads and the sweep failed the gate.

Backlog work (state/coverage_backlog.md): six open rows were dispositioned under Phase 0 step 5b. Published: MikroTik CVE-2026-84411 (struck with the entry id). Held with the condition and expiry unchanged and no append: IBM MQ and Langflow (expiry 2026-10-11; S1 re-checked: none is in KEV, no exploitation report, no public proof of concept; the next fire strikes it), IBM Guardium CVE-2026-85542 (expiry 2026-10-14; not in KEV, no IBM confirmation), ARA Lyss and Netech (expiry 2026-10-14; S4 re-checked the tracker records, claim-only, no press) and Beyond Gravity (expiry 2026-10-20; S2 found no new technique, actor, vector or BACS/Mandiant statement).

  • borderline-drop: Cisco 2026-10-07 security release (NX-OS, APIC, License On-Prem, Meraki, IOS XE): feature-gated or management-plane flaws, Cisco knows of no exploitation, assessed and dropped by two earlier fires; the only new fact is NCSC Switzerland's advisory of 2026-10-09 (post 13044), which restates the vendor bulletin.
  • borderline-drop: Veeam Backup & Replication CVE-2025-64393 (KB4934): needs the Backup Viewer role, nothing exploited; NCSC Switzerland advisory of 2026-10-09 is a restatement.
  • borderline-drop: Splunk Enterprise CVE-2026-76268 (SVD-2026-1001): CVSS 9.8 but reachable through the Patroni REST API on search head cluster members only (internal cluster interface), versions 10.2.0-10.2.6 and 10.4.0-10.4.2, nothing exploited.
  • borderline-drop: AnyDesk for Linux 8.0.2 AnyPwn exploit: Linux-only, probabilistic, tuned to one build, fixed silently in June (no CVE), no exploitation reported.
  • borderline-drop: Contao comments-bundle CVE-2026-107845: needs a back-end user to open the Comments module, nothing exploited, no Swiss deployment shown.
  • borderline-drop: Ricardo / SMG, 890,000 accounts (names, postal addresses, phone numbers): Swiss but private-sector consumer platform, no vector or actor, no public-sector decision (incident floor).
  • borderline-drop: P7 DarkSword iOS exploit kit (iVerify, Censys): the 18.x chains are patched in iOS 18.7.3 and 26.3 and the store's CVE-2026-86950 entry already carries the move to iOS 26.7.1; observed victims are Chinese-language wallet-theft operations.
  • borderline-drop: NVIDIA DCGM Exporter CVE-2026-47483: CVSS 8.2 resource-exhaustion DoS, no exploitation, not in KEV.
  • borderline-drop: Chrome 155 (no exploited flaw reported), Drupal contrib batch SA-CONTRIB-2026-192 to 217, WordPress 7.1.3, Nextcloud 2026-10-08 bulletins, Keycloak WID-SEC-2026-3849, WatchGuard 22-CVE bundle (CVE-2026-86131 needs control of the remote VPN server), ILIAS fixes, ICS advisories ICSA-26-281-01 to 03 (outside the window, niche): routine, authenticated, unexploited or out of window.
  • borderline-drop: Modat and NCSC-NL wind and solar exposure study (8,547 systems): no Swiss or EFTA breakdown in any outlet; FINMA video-identification circular and the Dutch tax authority's M365 pause (S2): bind banks or are sovereignty decisions, no obligation for the constituency.
  • out-of-window: the SAPMAP toolkit's Onapsis analysis (published 2026-09-18) is carried only through the PD-7(d) lookback route described above.
  • Single-source: the AhsayCBS entry (Huntress is the only observer; BleepingComputer and SecurityWeek relay it, single-source); the SonicWall exploitation claim (Previdian only, attributed). single-source-national-cert and victim carve-outs: none new.
  • Contradiction: the patch position on AhsayCBS 10.3.4 (public records imply 10.3.4 is not affected; Huntress says it is affected and has told Ahsay; Ahsay's 10.3.4 release notes list no security fix). The Zammad vendor pages also disagree: the advisory page of 2026-10-05 still says the team is working on a solution while the 7.2.2 release notes and the GitHub advisory of 2026-10-08 describe the fix; the advisory record lists CVE-2026-102490 with 7.2.2 as the patched version and DIVD's case page says the second flaw is fixed in 7.2.2. A third scale conflict is recorded on the GhostAction entry (Socket's "tens of thousands of repositories" against its own 346).
  • Coverage gaps: chrome-releases (desktop post unreachable), consilium.europa.eu cyber-sanctions pages (403 on every transport; the sanctions watch ran at snippet depth), blvk.ch and be.ch for the other sub-agents (the Canton of Bern's own release was not located; its content is known through Netzwoche and the BPK notice), ara-lyss.ch (403), swisspost-cybersecurity (no dated posts in the horizon), kommunaler-notbetrieb-de (nothing newer than 2026-09-21).
  • Essential-coverage: none missed; every essential record in the four slices was attempted.
  • The jina reader served a few S1 and S2 fetches (SonicWall PSIRT pages, one NCSC-NL advisory page that reported the key balance exhausted, blvk.ch); extract, pdf and the structured recipes covered everything else on this fire.
  • Candidate sources: two added with their reasons in sources_changed[]: stepsecurity-blog and zammad-github-advisories. modat was proposed by S3 and not added (one research report in a month, low priority). citrix-netscaler-security-bulletins is promoted to active.
  • Store observations for the next audit: the SAP September entry went three weeks without the SAPMAP development (see above); the earlier fires' borderline-drops of the Cisco and Veeam items rest on exploitation absence and the Swiss advisories now exist, a third look only if exploitation appears; the Langflow flaws CVE-2026-105697 (unauthenticated on a default-auto-login instance, fixed 1.10.3) and CVE-2026-8505 are in the held IBM MQ row's context and are not in the store.
  • Watchlist: none configured (the supplier and product sweeps are no-ops for this deployment).

← Operations dashboard · run-record contract: docs/pipeline.md