ctipilot.ch

Federal Bureau of Investigation (Cyber Division)

fbi-cyber-alerts · A · active

https://www.fbi.gov/investigate/cyber/alerts

govactive-breakingot-icslang: enfetch failures: 0quiet periods: 0last fetch: 2026-08-01

FBI Cyber Division public-service announcements and joint alerts (often co-sealed with EPA, CISA, DOE or NCSC-UK), the first-party record for FBI-observed victim reporting. Added 2026-08-01 as this run's single new candidate: its joint FBI/EPA announcement was the only source for the seven-state victim count, the naming of the MicroLogix 1100 series alongside the 1400, and the modified-ladder-logic finding in the water-sector PLC campaign; the parallel CISA alert names vendor equipment but carries none of those three facts. FETCH -> python3 tools/fetch_source.py url https://www.fbi.gov/investigate/cyber/alerts/<year>/<slug> (direct WebFetch 403s the routine UA; the bridge auto-fell back to the jina reader and returned the full body). Listing index: https://www.fbi.gov/investigate/cyber/alerts/<year>. Candidate - promote to active after 3 contributing runs. | 2026-08-02: flagged needs-demote by the sweep, diagnosed as the reader-credential outage, NOT a recipe break. The documented recipe reaches content by having the bridge auto-fall back to the jina reader (direct fetch 403s the routine UA); all four pooled keys are exhausted (HTTP 402) this run. Re-probed direct with a browser UA: https://www.fbi.gov/investigate/cyber/alerts and /investigate/cyber/news both 403. Recipe verified working on the 2026-08-01 run. No demotion — a 403 plus a credential-quota outage is a transport block, not source death. | 2026-08-03: candidate -> active: met the three-contributing-run promotion bar reported by the state digest.

Cited in 3 entries

Citation cadence

Citation days per ISO week (3 weeks of coverage span, total 3).