2026-10-10T0255Z-intel
One pipeline fire, in full · intel run of 2026-10-10 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-10-10/2026-10-10T0255Z-intel.md.
Run telemetry
- Items returned
- 12
- Duration
- 31m 04s
- Tool calls
- 6 WebFetch19 WebSearch115 bridge
- Cited sources
- 7 of 29 in slice
- Items returned
- 3
- Duration
- 17m 47s
- Tool calls
- 3 WebFetch30 WebSearch78 bridge
- Cited sources
- 2 of 19 in slice
- Items returned
- 0
- Duration
- 10m 29s
- Tool calls
- 0 WebFetch19 WebSearch85 bridge
- Cited sources
- 0 of 14 in slice
- Items returned
- 1
- Duration
- 19m 02s
- Tool calls
- 7 WebFetch31 WebSearch90 bridge
- Cited sources
- 1 of 10 in slice
- Items returned
- 1
- Duration
- 7m 32s
- Tool calls
- 0 WebFetch12 WebSearch18 bridge
- Cited sources
- 2 of 4 in slice
Verification
Deep dive
·
Entries this run published (3) and updated (5)
- CVE-2026-82078 / CVE-2026-81578, PaperCut NG/MF: an Apache Tapestry request-routing confusion chains an unauthenticated config rewrite to arbitrary code execution, exploited before a patch existed
- SAP September 2026 Patch Day: OVERPASS (CVE-2026-44756, CVSS 10.0) and S4GET (CVE-2026-58240, CVSS 9.8), two unauthenticated pre-auth RCE flaws in shared SAP kernel components reachable through ports that cannot be firewalled without breaking normal SAP GUI/RFC use
- CVE-2026-102489 / CVE-2026-102490, Zammad helpdesk: a session-hijack remote code execution and a zammad-to-root escalation, both reported exploited since 21 September; 7.2.2 fixes the root flaw on DEB and RPM installs
- CVE-2026-102255, SonicWall SMA1000: a third unauthenticated CVSS 10.0 Work Place SSRF this year, affecting the hotfix builds that closed the September zero-days, with exploitation attempts reported that SonicWall has not confirmed
- PK Softech, software supplier of Swiss pension funds: malware and a data outflow at Publica, with the Bernese funds BPK and BLVK and Pensionskasse Post also reporting the supplier incident, and the Federal Prosecutor's Office investigating
- CVE-2026-84411, MikroTik RouterOS: one unauthenticated request to the web management service can run code as root; 7.24 fixes the v7 stable channel and the long-term releases are pending (CVSS 3.1 9.8)
- CVE-2026-105133 / CVE-2026-105134, AhsayCBS backup management console: an unauthenticated authentication-bypass and code-execution chain exploited since 7 October to drop webshells and a cryptominer, with 10.3.4 also affected and no fixed release named
- GhostAction returns: stolen maintainer credentials push a fake security-audit workflow into the victims' own GitHub repositories, which now harvests credentials from the entire git history
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
13 last_successful_fetch · 9 notes · 2 added · 1 status · 1 rss_url.
| Source | Change | From → To | Reason |
|---|---|---|---|
| citrix-netscaler-security-bulletins | status | candidate → active | promotion_due: cited by published entries from 3 distinct runs |
| stepsecurity-blog | added | · → status: candidate | Added 2026-10-10: CI/CD and GitHub Actions supply-chain research with run-log forensics; the primary of the GhostAction entry |
| zammad-github-advisories | added | · → status: candidate | Added 2026-10-10: Zammad publishes advisories as GitHub security advisories since April 2026; the primary of the 7.2.2 update |
| scip-ch | rss_url | · → https://www.scip.ch/?rss.labs | S2 found the feed and the main agent verified it parses with dated items on the direct transport |
| mikrotik-routeros-changelog | last_successful_fetch | · → 2026-10-10 | fetched and used (the MikroTik notice is the primary of a new entry); recipe note added: notices live at mikrotik.com/supportsec/cve-<year>-<id> |
| huntress | last_successful_fetch | 2026-10-08 → 2026-10-10 | fetched and used (primary of the AhsayCBS entry) |
| watchtowr | last_successful_fetch | 2026-10-07 → 2026-10-10 | fetched and used (cited in the PaperCut update) |
| senthorus-ch | last_successful_fetch | 2026-09-13 → 2026-10-10 | fetched and used (cited in the SAP update) |
| onapsis | last_successful_fetch | 2026-09-14 → 2026-10-10 | fetched and used (cited in the SAP update) |
| socket-dev-blog | last_successful_fetch | 2026-09-07 → 2026-10-10 | fetched and used (cited in the GhostAction entry) |
| previdian | last_successful_fetch | 2026-10-08 → 2026-10-10 | fetched and used (cited in the SonicWall update) |
| bleepingcomputer | last_successful_fetch | 2026-10-08 → 2026-10-10 | fetched and used (cited in the SonicWall update, the AhsayCBS and MikroTik entries) |
| securityweek | last_successful_fetch | 2026-10-07 → 2026-10-10 | fetched and used (cited in the AhsayCBS entry) |
| inside-it-ch | last_successful_fetch | 2026-10-09 → 2026-10-10 | fetched and used (cited in the Publica update) |
| netzwoche | last_successful_fetch | 2026-10-09 → 2026-10-10 | fetched and used (cited in the Publica update) |
| cisa-kev | last_successful_fetch | 2026-10-09 → 2026-10-10 | fetched and used (catalogue cited in the MikroTik entry) |
| cisa-advisories | last_successful_fetch | 2026-10-09 → 2026-10-10 | fetched and used (ICSA-26-272-06 is cited in the MikroTik entry) |
| netcraft | notes | · → recipe note appended | extract returns navigation text only; url on the blog listing returns the card HTML |
| swarmcha-se | notes | · → recipe note appended | use url --direct for the listing; extract spends reader credit |
| helpnetsecurity | notes | · → recipe note appended | extract returns raw HTML for the front page |
| kela-cyber | notes | · → recipe note appended | the research listing page carries the titles |
| ransomware-live | notes | · → recipe note appended | v2 API endpoints countryvictims, countrycyberattacks and searchvictims read with url --direct |
| ncsc-ie | notes | · → recipe note appended | extract of the news page returns the dated advisory list |
| cisa-advisories | notes | · → recipe note appended | feed on all.xml spends reader credit and lists ICS items only |
| chrome-releases | notes | · → recipe note appended | no working command for desktop stable posts |
| mozilla-mfsa | notes | · → recipe note appended | extract drops list items; WebFetch of the index works |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| chrome-releases | https://chromereleases.googleblog.com/ | feed → extract → bridge:jina | 302 redirect the feed answers HTTP 302 on direct fetch and the reader returns no items; extract of the label page returns only the newest post (ChromeOS), so the desktop Chrome 155 post was not read from Google (S1) | dates and the no-exploitation statement for Chrome 155 came from a third-party report and a search; the item was borderline-dropped, so nothing depended on the Google page |
| consilium-eu-cyber-sanctions | https://www.consilium.europa.eu/en/policies/sanctions-against-cyber-attacks/ | extract → bridge:jina → webfetch | 403 waf-block consilium.europa.eu pages answer 403 on direct, extract, the reader and WebFetch, so the EU cyber-sanctions watch relied on search snippets (S2) | no EU cyber-sanctions designation surfaced in the window through search; the standing policy-watch line for sanctions is covered only at snippet depth |
| ara-lyss-ch | https://www.ara-lyss.ch/ | url | 403 waf-block the victim site of the held SafePay claim answers 403 to the bridge, so no victim-side notice could be read (S4) | the backlog row stays held on the tracker record, which carries no press confirmation |
Bridge invocations (this run)
7 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- pdf ×1
- cisa csaf ×1
- cisa-kev ×1
- url (CVE record API, read only, never cited) ×1
- url --direct ×1
- bsi-csaf ×1
- extract ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 31 findings (truth=20, editorial=5, advisory=6) · Claude Sonnet 5.5 · 19m 40s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | claims f2e531b28b/e08e502feb/b2d4026edc/e720599f34: "in seconds", segmentation, volunteer-data exfiltration, agent "justifies its own actions", "no link to a known threat actor" are not on the cited c | · | |
| F3 claim-not-supported | · | (low confidence) GHSA-p97w-927q-8vxq: "could have escalated within seconds"; hedge dropped. | · | |
| F3 claim-not-supported | · | claim 45ccc53ea4: restart/no-workaround are in The Hacker News 2026-10-07 only; the BC 2026-10-09 article does not carry them. Cite THN for that clause. | · | |
| F3 claim-not-supported | · | claim 7464bf51ee (low confidence): page shows 135 attempts, 2 unique attacker IPs, 1 attacker country, "US" under Sensors observed; never says one sensor. | · | |
| F3 claim-not-supported | · | claims 73c84e5727/b796aa609e/585cfd2b3e + run-record notes: JSON-LD datePublished is 2026-09-18 (dateModified 2026-09-24); citation date six days off. Content otherwise supported. | · | |
| F3 claim-not-supported | · | claim 54a9d6ff32: CERT-EU 2026-011 does not name the ICM/Web Dispatcher, SAP Dispatcher and RFC routes; they are in Onapsis sap-overpass-remediation. | · | |
| F3 claim-not-supported | · | claim c30041cde8: Rapid7 says only "broadly exploited in the wild by multiple threat-actor groups, including ransomware operators"; "authentication-bypass", "before a patch existed", "incident-respons | · | |
| F3 claim-not-supported | · | claim 8eac31d683 (low confidence): live PaperCut bulletin (updated 10 Sept) has no university/reproduction text; Rapid7 carries it. Cite Rapid7. | · | |
| F3 claim-not-supported | · | claims e676765f4b, 9fdb6088a2 (low confidence): Huntress has no absence statement; the bulletin does not say EPR2 closed the Home-page bypass (Rapid7 does). | · | |
| F3 claim-not-supported | · | claim 459b76a711 (low confidence): BC says "Recently"; no month. | · | |
| F3 claim-not-supported | · | claim 5254281c0d (low confidence): MikroTik says "could crash the service or allow ... code"; no failed-attempt outcome or restart telemetry stated; analyst inference cited to vendor. | · | |
| F3 claim-not-supported | · | claim 1730640578: GitGuardian supports only "rotating the secrets ... is not enough. The GitHub credential ... must be found and revoked too"; scan-history/treat-each-run guidance is StepSecurity. | · | |
| F3 claim-not-supported | · | claim 5f53d8a02e (low confidence): StepSecurity's 378 is a cumulative live-workflow count for the C2 address across all waves (endpoint seen since 5 Sept), not a since-7-October figure. | · | |
| F3 claim-not-supported | · | claim 8a2ec2e4aa (low confidence): admin.ch says "weitere Kunden informiert" and names none of them. | · | |
| F4 hallucinated-fact | · | claim aac577f8c8: superseded by Zammad 7.2.2 (2026-10-08) per https://zammad.com/en/product/releases/7-2-2 and this run's own section. Update the field. | · | |
| F4 hallucinated-fact | · | claim 75bcd3abb9: vendor GHSA-p97w-927q-8vxq lists CVE-2026-102490 (HTML and API cve_id; cvss_v4 8.5; vulnerable <= 7.2.1; patched 7.2.2) and DIVD-2026-00014 states the second flaw is fixed in 7.2.2. | · | |
| F4 hallucinated-fact | · | claim dd16a61aaa (low confidence): not in Onapsis (OVERPASS/S4GET) or CERT-EU; Onapsis mechanism is IP-trust abuse then Gateway access; uncited Triage discriminator. | · | |
| F4 hallucinated-fact | · | claim dcc41e4981: PaperCut Sept bulletin lists CVE-2026-82077 fixed only in 26.0.5 and 25.0.13; no 24.x release named (the entry's own actions[0] says so). | · | |
| F14 quantifier-without-source | · | claim a52918fec6 (low confidence): GreyNoise "at least 440 instances ... 395 identified victim organizations ... other real victims"; "at least" dropped. | · | |
| F14 quantifier-without-source | · | claim d881c75093 (low confidence): no source states the absolute. | · | |
| F5 missing-citation | · | claims 863c8f0e41, 9f87404e7b (low confidence): scores match VulDB CNA records but no sources[] record carries them; cite a VulDB per-vuln page or reduce to the Huntress severity wording. | · | |
| F9 surface-contradiction | · | PaperCut bulletin (cited) FAQ: "Emergency Patch Release 3 ... closes off additional attack vectors we have observed being exploited in the wild"; watchTowr: build 76530 (EPR3) fixes WT-2026-0143; Rapi | · | |
| F7 drop | · | (low confidence) no exploitation, no public PoC, not KEV, default-firewall blocks exposure, no constituency footprint shown; consider routine / two sentences. | · | |
| F8 needs-more-research | · | (low confidence) Previdian honeypot first-observation (09 Oct 08:49 UTC) does not bound real-world probing; advisory public since 2026-10-06. Start at 2026-10-06 or earliest retained log. | · | |
| F18 action-item-discipline | · | (low confidence) each restates body Detection/hardening guidance; keep the compromise-check task, drop restated clauses. | · | |
| F11 editorial-advisory | · | Style rule 12: no em dash in reader-facing text. | · | |
| F11 editorial-advisory | · | attacker file/service-name indicators (style rule 12 IOC list). | · | |
| F11 editorial-advisory | · | workflow-internal / composition-rationale language in reader-facing fields. | · | |
| F11 editorial-advisory | · | source-mapped behaviours without ids. | · | |
| F11 editorial-advisory | · | cited page carries stronger wording than the entry; derivative of BC/Previdian, mention or note. | · | |
| F11 editorial-advisory | · | a cited page already states the fix; entry frames it as resting on the CVE record alone (see F4 above). | · |
Iteration #2 NEEDS_FIXES · 14 findings (truth=7, editorial=2, advisory=5) · Claude Sonnet 5.5 · 16m 11s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Iteration-1 finding not remediated (claim text and citation are unchanged). The cited case page has no segmentation text (0 hits for "segment" in the raw HTML and the extract); "Thanks to proper netwo | · | |
| F3 claim-not-supported | · | Citation date does not match the page: dateline "Last modified 09 Oct 2026 20:01 CEST", timeline "29 Sep 2026 Publication of casefile"; neither is 2026-10-01. The sentence this fire added ("DIVD's cas | · | |
| F3 claim-not-supported | · | The Huntress page says "Ahsay 10.3.4 is also affected" but never calls 10.3.4 the latest version; that is BleepingComputer ("currently the latest version") and SecurityWeek ("the latest AhsayCBS versi | · | |
| F3 claim-not-supported | · | Huntress carries only "for which no patch is currently available" (dated 28 Aug) and the 47% figure; the upgrade-to-a-supported-line guidance is in PaperCut's bulletin FAQ ("There are no emergency pat | · | |
| F3 claim-not-supported | · | StepSecurity's org-scoped queries search for content markers (AKIA_CTX_START, c=monami, the C2 address), not for file names; the two file names appear in its "treat as confirmed breach" callout and So | · | |
| F13 analytical-link-as-fact | · | AV26-1017 Update 1 says only "Open source reporting indicates that CVE-2026-102255 is being exploited in the wild." and names no source. Equating it with the Previdian/BleepingComputer report is the e | · | |
| F14 quantifier-without-source | · | GreyNoise: fastest domain admin five minutes, longest 144 minutes, and "multiple-day delays between initial access and achievement of domain admin" for some victims, and only 12 of the victims reached | · | |
| F16 org-triage | · | The update's delta (watchTowr bypass analysis of superseded emergency builds; CVE-2026-82077 is admin-only; "No source names exploitation of CVE-2026-82077 or of the Setup Wizard bypass") is not time- | · | |
| F18 action-item-discipline | · | Four tasks in one action; the log-script, package and template clauses restate the body Detection paragraph. Keep the upgrade and the compromise check as two short actions (or one), drop the restated | · | |
| F11 editorial-advisory | · | Style rule 12 (no em dash in reader-facing text). Declined for settled text in iteration 1; noted again because the SAP paragraph rewritten this fire still contains them. | · | |
| F11 editorial-advisory | · | Rule 12 lists "mutex or file-name indicators" among the IOC classes to exclude; these are attacker-chosen file and service names. Declined once as behaviour-level hunting artifacts; the main agent dec | · | |
| F11 editorial-advisory | · | Rule 12: sourcing_note is two sentences of provenance; Admiralty letters, "sources.json" and credibility wording are workflow-internal. Zammad and Publica carry dispute analysis and per-source comment | · | |
| F11 editorial-advisory | · | Metadata narration about the entry's own priority in a reader-facing changelog summary; the delta is the customers and funds, not the rating. | · | |
| F11 editorial-advisory | · | Check 4c(f): rewrites of previously shipped text are corrections. `body` is named in fields so the gate passes, but the record summary tells readers only about the new delta; consider a separate `corr | · |
Iteration #3 NEEDS_FIXES · 10 findings (truth=5, editorial=2, advisory=3) · Claude Sonnet 5.5 · 16m 05s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Citation date is neither the page's publication date (27 Aug 2026) nor its visible dateline ("Last updated September 10, 2026"). The clauses report events the page's Updates table dates 1 Sept ("Publi | · | |
| F4 hallucinated-fact | · | The release triple appears in none of the pages fetched this iteration (PaperCut bulletin of 2026-09-10, Huntress, Rapid7, watchTowr, GreyNoise, CERT-FR): 24.1.9 occurs nowhere; Huntress ties 25.0.12 | · | |
| F3 claim-not-supported | · | The summary, actions and body now attribute "latest version" to BleepingComputer, but the headline still puts it under the "Huntress:" prefix. The Huntress page says only "Ahsay 10.3.4 is also affecte | · | |
| F13 analytical-link-as-fact | · | AV26-1017 Update 1 says only "Open source reporting indicates that CVE-2026-102255 is being exploited in the wild." and names no source, so "rests on one observer" / "single-source" is the entry's inf | · | |
| F3 claim-not-supported | · | StepSecurity's callout names two workflows: "If a workflow named “Security Audit” (security-audit.yml) or “Github Actions Security” (github_actions_security.yml) appeared in any repository you maintai | · | |
| F5 missing-citation | · | Only the BPK notice says it ("Zum jetzigen Zeitpunkt gibt es keine Hinweise, dass Daten der BPK gestohlen wurden. Jedoch kann dies nicht restlos ausgeschlossen werden"). The BLVK notice the body cites | · | |
| F18 action-item-discipline | · | Still a compound of four clauses that restate the body Detection paragraph (log script, package and template artifacts, root-owned files). Iteration 2 asked to keep the compromise check as a short tas | · | |
| F11 editorial-advisory | · | Rule 12: two sentences of provenance. These four notes still run to three sentences and carry dispute and count analysis that the bodies already state; SAP's note still uses the Admiralty word "credib | · | |
| F11 editorial-advisory | · | Narration about the entry's own rating in a reader-facing changelog summary (the same shape as the Publica sentence removed after iteration 2); "stop-and-act bar" is pipeline priority vocabulary. `pri | · | |
| F11 editorial-advisory | · | Declined twice for settled text; noted unchanged. The SAP opening paragraph was re-edited this fire (Onapsis citation added) and still carries the dashes. Advisory. | · |
Iteration #4 NEEDS_FIXES · 7 findings (truth=4, editorial=1, advisory=2) · Claude Sonnet 5.5 · 16m 43s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Iteration-3 remediation only half-applied. https://www.stepsecurity.io/blog/ghostaction-returns says: "If a workflow named “Security Audit” (security-audit.yml) or “Github Actions Security” (github_ac | · | |
| F3 claim-not-supported | · | Huntress states the output-file and server.log deletion only for the 26 August incident: "After exploitation, the .class file deletes its own `Udydn.out` file, as well as the server's `server.log` fil | · | |
| F3 claim-not-supported | · | The feed read this iteration has catalogVersion 2026.10.08 and dateReleased 2026-10-08T20:09:18Z, so the citation date (2026-10-10, the day the pipeline read it) is two days off the source's own date | · | |
| F3 claim-not-supported | · | The cited Onapsis page describes: "With a specially crafted packet sent to the Message Server’s public port, an unauthenticated attacker can have an IP treated as trusted ... The attacker then connect | · | |
| F8 needs-more-research | · | Actionability contract (prompts/cti-run.md Phase 4): a labelled line its sources clearly support and that is missing is F8. Onapsis supports SAP **Exposure:** (kernel release and patch-level check via | · | |
| F11 editorial-advisory | · | Style rule 12. Declined as settled text in iterations 1 to 3; noted unchanged, advisory only. The cves[].fixed and the SAP paragraph were edited this fire and still carry the dash. | · | |
| F11 editorial-advisory | · | The BLVK notice says "ob und in welchem Umfang" (whether and to what extent), not "how". Also consider the incident floor (Phase 4): sources give no access vector and no actor, so a routine rating at | · |
Iteration #5 NEEDS_FIXES cap-breach · 3 findings (truth=0, editorial=2, advisory=1) · Claude Sonnet 5.5 · 14m 14s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F8 needs-more-research | · | The hunt scope the entry hands the reader omits a third disguise its own sources list. StepSecurity (https://www.stepsecurity.io/blog/ghostaction-returns) IOC table, "Workflow files": security-audit.y | · | |
| F8 needs-more-research | · | Onapsis (https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/) states the exposure check the entry never gives: "The check is a single data point: your kernel release and | · | |
| F11 editorial-advisory | · | Style rule 12. Declined as settled text in iterations 1 to 4. None of the text this fire added or rewrote carries a dash (checked in git diff HEAD); the remaining dashes sit in text this fire did not | · |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-10-10T0255Z-intel · Sonnet 5.5 · window 26 h · 3 entries published
Verification & coverage notes
Coverage window: standard fire. The previous intel fire started 2026-10-09T02:55:59Z, so gap_hours=24.0 and window_hours=26; the developing-story window was 72 hours. The clock cross-check against the network date agreed (skew 0 s) and the fresh fetch showed the newest run record of 2026-10-09T0255Z.
Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found no KEV addition since 2026-10-09 (catalog 2026.10.08, released 2026-10-08T20:09Z; the five old CVEs added on 2026-10-08 are inside the AA26-281A entry) and no RANSOMWARE row. S1 confirmed it through the cisa-kev recipe and found no ransomware-flag flip on a covered CVE. The 2026-10-10 re-read of the catalogue shows none of CVE-2026-84411, -102255, -105133, -105134 or -82077 listed. No scheduled multi-product release fell in the window (Microsoft, SAP and Fortinet on 2026-10-13, Oracle on 2026-10-20, Cisco on 2026-10-21).
Verification: five cold iterations, each a fresh cti-verification pass over the full ledger (204 to 214 claims, all checked). Iterations 1 to 4 returned NEEDS_FIXES (truth 20, 7, 5 and 4; editorial 5, 2, 2 and 1) and every truth finding was remediated and re-checked by the next pass. Iteration 5 returned NEEDS_FIXES with truth 0 and editorial 2 (both F8: a third disguise name missing from the GhostAction hunt scope, an Exposure line missing from the SAP entry) and no F1 or F4, so the low-residual early exit applies: both were fixed after the pass and the run publishes without a sixth iteration. The residual count is the final iteration's two editorial findings. Standing advisories, unfixed on purpose: em dashes in older PaperCut and SAP text this fire did not touch, and the missing Exposure line on the PaperCut entry.
New entries (3):
- MikroTik RouterOS CVE-2026-84411 (vulnerability, routine after verifier iteration 1; pre-auth web-management RCE, MikroTik's own notice now names the fix; PD-11(b) on its own mechanics, a single unauthenticated request to root on an edge router class that botnets target, with the default firewall keeping the interface off the internet and no exploitation, which holds it at routine; resolves the backlog row).
- AhsayCBS CVE-2026-105133 / CVE-2026-105134 (vulnerability, notable; exploited from 2026-10-07 with webshells and a miner, 10.3.4 also affected and no fixed release named; PD-11(b); the nexus is the managed-service-provider and integrator class that serves public bodies, so it is notable and not high; single-source on Huntress, Admiralty B2).
- GhostAction (threat, notable; stolen maintainer credentials, confirmed exfiltration at an Uber-owned repository, history-wide credential sweep that makes secret rotation insufficient; PD-11(a) and (d): an organisation-scoped search and an audit-log query take minutes; no public-sector victim is named, the ground is GitHub-hosted developer estates of public bodies and their suppliers; Admiralty B1 from three independent analyses; the "tens of thousands" figure in one vendor's update line is not carried).
Updates (5): Publica / PK Softech (update: the Bernische Pensionskasse's own notice says its supplier is Publica's, the Bernische Lehrerversicherungskasse and Pensionskasse Post report the supplier incident, Inside IT lists two more funds; priority moves routine to notable because cantonal public-law institutions are now directly involved); Zammad (update: 7.2.2 fixes the zammad-to-root escalation on DEB and RPM installs, no-patch leaves the CVE record and the tags, title, headline, summary, actions and the two body paragraphs that said no fix was named were rewritten where they stood); SonicWall SMA1000 CVE-2026-102255 (update: single-source honeypot-operator report of exploitation attempts, success unknown, vendor still says no evidence; the CVE status is deliberately left at patch-available because the exploitation claim rests on one observer, and the Canadian Cyber Centre's update of 2026-10-09 says open source reporting indicates exploitation); PaperCut NG/MF (update; priority moves from critical to high after verifier iteration 2 because the in-window weaponisation the critical bar needs has passed and the delta is not time-critical, with immediate_action cleared: watchTowr's write-up of the bypasses of the emergency builds and CVE-2026-82077, an administrator-only Scan-to-Fax RCE that the vendor's September bulletin lists as fixed only in 26.0.5 and 25.0.13; read from the vendor bulletin, the CVE added to the record and the immediate action reworded); SAP September Patch Day (update, PD-7(d) lookback: Onapsis reports SAPMAP, an open-source toolkit public since 2026-09-15 that carries proof-of-concept exploits for OVERPASS and S4GET; status moves to poc-public; the freshest source, Senthorus of 2026-10-06, sits at the edge of its 96 h lookback and the Onapsis article was published on 2026-09-18 (modified 2026-09-24), so the audit should treat the item as a late recovery of a development the store missed for three weeks).
Source allocation: slices S1 29, S2 19, S3 14, S4 10 records (S1: 14 essential plus 13 rotation plus Citrix and SonicWall PSIRT added by hand; S4's pool was refilled from the previous two fires' attempts because every record in the domain had been attempted in them; 19 records were excluded as recent attempts elsewhere), every record with a ledger row, so no continuation was needed. One scoped follow-up spawn, FU1, took three cross-domain leads S1 and S3 had not researched (GhostAction, P7 DarkSword, NVIDIA DCGM) plus a bounded headline sweep; it returned one item, and the other two leads and the sweep failed the gate.
Backlog work (state/coverage_backlog.md): six open rows were dispositioned under Phase 0 step 5b. Published: MikroTik CVE-2026-84411 (struck with the entry id). Held with the condition and expiry unchanged and no append: IBM MQ and Langflow (expiry 2026-10-11; S1 re-checked: none is in KEV, no exploitation report, no public proof of concept; the next fire strikes it), IBM Guardium CVE-2026-85542 (expiry 2026-10-14; not in KEV, no IBM confirmation), ARA Lyss and Netech (expiry 2026-10-14; S4 re-checked the tracker records, claim-only, no press) and Beyond Gravity (expiry 2026-10-20; S2 found no new technique, actor, vector or BACS/Mandiant statement).
- borderline-drop: Cisco 2026-10-07 security release (NX-OS, APIC, License On-Prem, Meraki, IOS XE): feature-gated or management-plane flaws, Cisco knows of no exploitation, assessed and dropped by two earlier fires; the only new fact is NCSC Switzerland's advisory of 2026-10-09 (post 13044), which restates the vendor bulletin.
- borderline-drop: Veeam Backup & Replication CVE-2025-64393 (KB4934): needs the Backup Viewer role, nothing exploited; NCSC Switzerland advisory of 2026-10-09 is a restatement.
- borderline-drop: Splunk Enterprise CVE-2026-76268 (SVD-2026-1001): CVSS 9.8 but reachable through the Patroni REST API on search head cluster members only (internal cluster interface), versions 10.2.0-10.2.6 and 10.4.0-10.4.2, nothing exploited.
- borderline-drop: AnyDesk for Linux 8.0.2 AnyPwn exploit: Linux-only, probabilistic, tuned to one build, fixed silently in June (no CVE), no exploitation reported.
- borderline-drop: Contao comments-bundle CVE-2026-107845: needs a back-end user to open the Comments module, nothing exploited, no Swiss deployment shown.
- borderline-drop: Ricardo / SMG, 890,000 accounts (names, postal addresses, phone numbers): Swiss but private-sector consumer platform, no vector or actor, no public-sector decision (incident floor).
- borderline-drop: P7 DarkSword iOS exploit kit (iVerify, Censys): the 18.x chains are patched in iOS 18.7.3 and 26.3 and the store's CVE-2026-86950 entry already carries the move to iOS 26.7.1; observed victims are Chinese-language wallet-theft operations.
- borderline-drop: NVIDIA DCGM Exporter CVE-2026-47483: CVSS 8.2 resource-exhaustion DoS, no exploitation, not in KEV.
- borderline-drop: Chrome 155 (no exploited flaw reported), Drupal contrib batch SA-CONTRIB-2026-192 to 217, WordPress 7.1.3, Nextcloud 2026-10-08 bulletins, Keycloak WID-SEC-2026-3849, WatchGuard 22-CVE bundle (CVE-2026-86131 needs control of the remote VPN server), ILIAS fixes, ICS advisories ICSA-26-281-01 to 03 (outside the window, niche): routine, authenticated, unexploited or out of window.
- borderline-drop: Modat and NCSC-NL wind and solar exposure study (8,547 systems): no Swiss or EFTA breakdown in any outlet; FINMA video-identification circular and the Dutch tax authority's M365 pause (S2): bind banks or are sovereignty decisions, no obligation for the constituency.
- out-of-window: the SAPMAP toolkit's Onapsis analysis (published 2026-09-18) is carried only through the PD-7(d) lookback route described above.
- Single-source: the AhsayCBS entry (Huntress is the only observer; BleepingComputer and SecurityWeek relay it,
single-source); the SonicWall exploitation claim (Previdian only, attributed).single-source-national-certand victim carve-outs: none new. - Contradiction: the patch position on AhsayCBS 10.3.4 (public records imply 10.3.4 is not affected; Huntress says it is affected and has told Ahsay; Ahsay's 10.3.4 release notes list no security fix). The Zammad vendor pages also disagree: the advisory page of 2026-10-05 still says the team is working on a solution while the 7.2.2 release notes and the GitHub advisory of 2026-10-08 describe the fix; the advisory record lists CVE-2026-102490 with 7.2.2 as the patched version and DIVD's case page says the second flaw is fixed in 7.2.2. A third scale conflict is recorded on the GhostAction entry (Socket's "tens of thousands of repositories" against its own 346).
- Coverage gaps: chrome-releases (desktop post unreachable), consilium.europa.eu cyber-sanctions pages (403 on every transport; the sanctions watch ran at snippet depth), blvk.ch and be.ch for the other sub-agents (the Canton of Bern's own release was not located; its content is known through Netzwoche and the BPK notice), ara-lyss.ch (403), swisspost-cybersecurity (no dated posts in the horizon), kommunaler-notbetrieb-de (nothing newer than 2026-09-21).
- Essential-coverage: none missed; every essential record in the four slices was attempted.
- The jina reader served a few S1 and S2 fetches (SonicWall PSIRT pages, one NCSC-NL advisory page that reported the key balance exhausted, blvk.ch);
extract,pdfand the structured recipes covered everything else on this fire. - Candidate sources: two added with their reasons in
sources_changed[]:stepsecurity-blogandzammad-github-advisories.modatwas proposed by S3 and not added (one research report in a month, low priority).citrix-netscaler-security-bulletinsis promoted to active. - Store observations for the next audit: the SAP September entry went three weeks without the SAPMAP development (see above); the earlier fires' borderline-drops of the Cisco and Veeam items rest on exploitation absence and the Swiss advisories now exist, a third look only if exploitation appears; the Langflow flaws CVE-2026-105697 (unauthenticated on a default-auto-login instance, fixed 1.10.3) and CVE-2026-8505 are in the held IBM MQ row's context and are not in the store.
- Watchlist: none configured (the supplier and product sweeps are no-ops for this deployment).
← Operations dashboard · run-record contract: docs/pipeline.md