CTIPilot

NCSC Switzerland, Aktuelle Vorfälle

ncsc-ch-incidents · A · active

https://www.bacs.admin.ch/de/aktuelle-vorfaelle

ch-eugovlang: defetch failures: 0quiet periods: 7last fetch: 2026-09-14

Swiss NCSC current incidents page (German). Translate findings to English in the brief. | 2026-05-08 audit: WebFetch returned 5 dated incidents incl. e-vignette phishing 2026-04-07. Page mostly carries consumer-fraud advisories; operational/sector incidents are normally on Im Fokus or the Cyber Security Hub instead. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → bridge `python3 tools/fetch_source.py url https://www.ncsc.admin.ch/ncsc/de/home/aktuell/aktuelle-vorfaelle.html` (incidents are inline dated accordion entries with full body text, no per-incident detail URLs); WebFetch also works on this page. AVOID: This is the CONSUMER-fraud page, it lags (most recent entry 07.04.2026, no May/June items) and carries phishing/extortion/fake-call advisories, not operational sector incidents. For operational/sector incidents use the Cyber Security Hub (ncsc-csh) or Im Fokus instead. Note: unlike the CSH, this admin.ch page does NOT 403 the bridge.. | 2026-07-05 admiralty audit: A (HIGH->A) status active->active, Swiss national authority first-party fraud/incident reporting; live but slow-cadence (latest 07.04.2026, expected). Use CSH/Im Fokus for operational items. Justified A: primary government authority. | 2026-07-06 drift correction: latest dated entry on the Aktuelle Vorfälle page is now 01.07.2026 (SwissNovaChat/SwissNovaCare fake-subscription scam warning), not 07.04.2026 as the 2026-06-20 note states. Consumer-fraud-only classification unchanged; use CSH/Im Fokus for operational/sector incidents. | 2026-07-18 weekly audit (G2): page fetches 200 but content observed stale, consumer-phishing warnings through Oct 2025, no current government/CI incident bulletins. Reachable-but-not-readable suspect: verify whether NCSC-CH moved current incident comms to the Security Hub API / im-Fokus paths (both healthy) and whether this record's URL still points at the right surface. | 2026-07-18 operator-directed re-verification, G2 reachable-but-stale suspect RESOLVED, false alarm: the documented bridge fetch (`python3 tools/fetch_source.py url <page URL>`) returns the FULL accordion, 10 dated entries newest-first, latest 01.07.2026 13:22 (SwissNovaChat/SwissNovaCare fake-subscription warning; operator-confirmed as the page's latest content), then 07.04.2026, 28.02.2026 and a 2025 tail. The Oct-2025-only observation was a truncated/summarized read: 4 of 10 entries cluster in Oct 2025, so a partial fetch that misses the top of the accordion reads as stale, always read the raw bridge body and scan EVERY dated entry before judging freshness. Page stays consumer-fraud-only by design (slow cadence expected); operational/sector incidents live on the Cyber Security Hub (ncsc-csh) / Im Fokus. No demotion, recipe unchanged. | 2026-08-06: the shared NCSC CSH API moved to /api/v1/ (see ncsc-ch-security-hub notes); tools/fetch_source.py ncsc-csh recipe fixed and re-tested this run. | 2026-08-16: source_health flagged needs-demote, but a serial re-probe this run returned the full 51 KB listing through the generic `url` bridge with every dated accordion entry present (newest 31.07.2026, out of window, which is the expected slow cadence for this consumer-fraud page). The sweep result is a parallel-contention artifact under a dead reader pool, not a recipe defect. NOT demoted, recipe unchanged. | 2026-08-23: BACS rebrand, incidents page moved to bacs.admin.ch/de/aktuelle-vorfaelle; legacy path redirects. FETCH -> Nuxt SPA, WebFetch renders it, the bridge's direct GET returns a JS-only shell. | 2026-09-13 quality audit (G2 spot-check, carry-forward watch item 2 from the 2026-09-06 report): RECIPE WAS BROKEN AND IS NOW FIXED. The recorded `bridge` transport is the one this record's own 2026-08-23 note already described as returning 'a JS-only shell' after the BACS rebrand, and it was never switched, so the page has been fetching green and empty for three weeks. VERIFIED WORKING this run: `python3 tools/fetch_source.py jina https://www.bacs.admin.ch/de/aktuelle-vorfaelle` hydrates the accordion. fetch_method bridge -> jina on that basis. Content check: genuinely quiet in-window (newest post 18.08.2026) so the 6 quiet periods are mostly this page's expected slow consumer-fraud cadence, not the transport alone. Same cost tradeoff as ncsc-ch-focus: an empty reader pool makes this page a disclosed gap, never a demotion.

Cited in 1 entry

Citation cadence

Citation days per ISO week (1 weeks of coverage span, total 1).