CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

SOCRadar (Threat Research Unit)

socradar · C · active

https://socradar.io/blog/

researchlang: enfetch failures: 0quiet periods: 1last fetch: 2026-09-08

Discovered 2026-07-03 via S3: primary source for the FortiBleed campaign (this brief's own long-running thread) and its exposure-checker/whitepaper research; repeatedly cited by press covering a thread this brief tracks. Single-vendor investigative claims should be corroborated. Candidate; promote to active after 3 runs with content contribution. | 2026-07-05 admiralty audit: C (MEDIUM->C), CTI blog mostly aggregation with occasional original TRU research; corroborate single-vendor claims. Keep candidate. | 2026-07-26 weekly quality audit: promoted candidate → active on the documented lifecycle bar (cited by published entries from 6 distinct runs; the bar is 3). The promotion had never been executed because nothing counted contributing runs, the digest now emits sources.promotion_due (tools/run_summary.py). | 2026-09-13 quality audit (G3 broken-recipe duty, closing 2026-09-06 recommendation 3): RECIPE FIXED, with a caveat that matters. VERIFIED WORKING: `python3 tools/fetch_source.py extract https://socradar.io/blog/` returns clean titles/links/summaries. CAVEAT: the LISTING page's own date metadata is stale and wrong, always drill to the per-article URL and read its date there (verified: the ShieldCrash article extracts with its true date, 2026-09-10). fetch_method webfetch -> bridge (the `extract` subcommand).

Cited in 13 entries

Citation cadence

Citation days per ISO week (17 weeks of coverage span, total 12).