The call scoreboard
Every forward call PTI Wire publishes lands on this page with its confidence band and a closing date. When the window closes, the call gets graded against public reporting and the evidence is linked. A wrong call stays on the board; nothing gets quietly deleted.
70calls made
16resolved
15right
0wrong
How grading works. Right means the
called behavior showed up inside the window, backed by named public reporting.
Wrong means the window closed without it.
Partial means the direction held but the scope or timing
didn't. Calls marked rolling describe ongoing activity and get reviewed on a fixed date
instead of a single yes/no. Issue #1 shipped 2026-06-08, so the first grades post in late June.
What shows here. Issue #1 is the free public sample, so its calls appear
in full. Calls from subscriber issues are listed by a short reference only, a product name or a
TTP, enough to check the grade against the claim; the full call and its reasoning stay in the
subscriber archive.
Live tracking — the 54 open calls, as of 2026-07-20. Interim signal, not verdicts; each call still grades when its window closes.
Tracking toward Right (the called event is already on the public record): Cisco SD-WAN CVE-2026-20245 (vendor-confirmed config-push), LiteLLM CVE-2026-42271 (KEV, chained RCE), Arista EOS CVE-2026-7473 (KEV), Chrome V8 CVE-2026-11645 (KEV), PTC Windchill CVE-2026-12569 (KEV), Cisco CUCM CVE-2026-20230 (KEV), SharePoint CVE-2026-45659 (KEV, Storm-2603/Warlock), Qilin ransomware (assessed Q2's most active, manufacturing-led), Klue/Icarus OAuth SaaS theft (breach confirmed), Defender RoguePlanet (public exploit), ClickFix and help-desk vishing (both dominant), and the Aflac Japan (4.38M) and KDDI six-ISP (14.2M) breaches (disclosed; policyholder/credential-stuffing fraud is the window).
Monitoring (slow-burn or event-conditioned, no decisive in-window signal yet): nation-state edge and telecom pre-positioning (Issue #1 and #2), Iran-nexus OT probing, hacktivist DDoS, the frontier-AI KYC bypass economy, Operation Endgame stealer displacement, and the Issue #5 calls (PolinRider, Armored Likho, satcom ICS, the VPN-Go clipper, TimbreStealer, Node.js disclosure reform), which remain early in their windows. Issues #6 and #7 add newer calls still (Langflow flow-hijack, FortiBleed, the AsyncAPI CI/CD compromise, SonicWall SMA1000, AD FS token forgery), listed in full below.
Tracking toward Right (the called event is already on the public record): Cisco SD-WAN CVE-2026-20245 (vendor-confirmed config-push), LiteLLM CVE-2026-42271 (KEV, chained RCE), Arista EOS CVE-2026-7473 (KEV), Chrome V8 CVE-2026-11645 (KEV), PTC Windchill CVE-2026-12569 (KEV), Cisco CUCM CVE-2026-20230 (KEV), SharePoint CVE-2026-45659 (KEV, Storm-2603/Warlock), Qilin ransomware (assessed Q2's most active, manufacturing-led), Klue/Icarus OAuth SaaS theft (breach confirmed), Defender RoguePlanet (public exploit), ClickFix and help-desk vishing (both dominant), and the Aflac Japan (4.38M) and KDDI six-ISP (14.2M) breaches (disclosed; policyholder/credential-stuffing fraud is the window).
Monitoring (slow-burn or event-conditioned, no decisive in-window signal yet): nation-state edge and telecom pre-positioning (Issue #1 and #2), Iran-nexus OT probing, hacktivist DDoS, the frontier-AI KYC bypass economy, Operation Endgame stealer displacement, and the Issue #5 calls (PolinRider, Armored Likho, satcom ICS, the VPN-Go clipper, TimbreStealer, Node.js disclosure reform), which remain early in their windows. Issues #6 and #7 add newer calls still (Langflow flow-hijack, FortiBleed, the AsyncAPI CI/CD compromise, SonicWall SMA1000, AD FS token forgery), listed in full below.
Issue #7 · Week of 2026-07-20 · subscriber issue
1SonicWall SMA1000 zero-days (CVE-2026-15409/15410), INC ransomware + UTA0533OPEN
2AD FS token-forgery zero-day (CVE-2026-56155 KEV) + Machine DPAPI key recoveryOPEN
3SharePoint cluster widens (CVE-2026-58644 KEV) + machine-key persistenceOPEN
4AsyncAPI CI/CD provenance-forgery supply chain (Miasma via OIDC trusted-publisher)OPEN
5HalluSquatting: AI-assistant hallucinated packages weaponizedOPEN
6Oracle E-Business Suite Payments takeover (CVE-2026-46817 KEV), 900+ exposedOPEN
7RedWing Android bank-fraud MaaS on Telegram, target list expandsOPEN
8NetNut takedown displacement to rival residential-proxy networksOPEN
9KNX building-automation exploitation (CVE-2023-4346 KEV), device brickingOPEN
10Poisoned Tenant SaaS-invite abuse spreads to another AI/SaaS platformOPEN
Issue #6 · Week of 2026-07-13 · subscriber issue
1Langflow exploited CVEs (CVE-2026-55255 KEV + CVE-2026-33017), flow hijackOPEN
2Agent-run ransomware precedent (JADEPUFFER): second case or vendor detectionsOPEN
3FortiBleed credential theft to INC/Lynx ransomware pipelineOPEN
4Joomla extension KEV cluster (SP Page Builder, Joomlack, iCagenda, Balbooa)OPEN
5Fake payment-SDK packages on npm/PyPI (Paysafe/Skrill/Neteller)OPEN
6Indra Group / The Gentlemen leak-site deadline, defense-sector extortionOPEN
7Nidec CCI / BlackField $2M demand, JP subsidiary blind spotOPEN
8Schneider Easergy MiCOM Px40 relay SNMP exposure (CVE-2026-4832)OPEN
9BEC advisory or named seven-figure payment-redirection lossOPEN
10Rival-state convergence on identity/biometric data stores (One Target, Two Flags)OPEN
Issue #5 · Week of 2026-07-06 · subscriber issue
1Microsoft SharePoint deserialization RCE (CVE-2026-45659), Storm-2603 / WarlockOPEN
2Miasma npm worm: AI coding-assistant persistence, Go expansionOPEN
3PolinRider DPRK cross-ecosystem developer campaignOPEN
4Armored Likho / BusySnake Stealer, LLM-built loadersOPEN
5Aflac Japan breach: policyholder fraud follow-onOPEN
6KDDI six-ISP shared-mail breach: credential stuffingOPEN
7Satcom / space-segment ICS exposure (iDirect iQ-Series, CubeSpace)OPEN
8Browser-extension update-channel abuse (VPN Go clipper)OPEN
9TimbreStealer invoice-lure updater side-loadingOPEN
10AI-generated report flood forces OSS disclosure changesOPEN
Issue #4 · Week of 2026-06-29 · subscriber issue
1Ubiquiti UniFi OS triple-10.0 RCE chain (CVE-2026-34908/09/10)RIGHT
2PTC Windchill / FlexPLM deserialization RCE (CVE-2026-12569)OPEN
3Cisco Unified CM SSRF (CVE-2026-20230)OPEN
4Exposed OT / serial-bridge gear amid the ICS advisory wave (Lantronix EDS5000)OPEN
5Infostealer displacement after Operation Endgame (StealC / Amadey)OPEN
6Qilin ransomware, manufacturing-ledOPEN
7Klue / Icarus OAuth-token SaaS supply-chain theftOPEN
8CI/CD provenance forgery via OIDC theft (Mini Shai-Hulud / TeamPCP)OPEN
9MCP tool-poisoning and AI-gateway takeover (LiteLLM chain)OPEN
10Vendor-payment and wire fraud into the fiscal closeOPEN
Issue #3 · Week of 2026-06-22 · subscriber issue
1Splunk CVE-2026-20253 unauth RCE in the SOC platformRIGHT
2Joomla JCE CVE-2026-48907 mass web-shellRIGHT
3Microsoft Defender RoguePlanet local-to-SYSTEMOPEN
4Arista EOS CVE-2026-7473 tunnel decap, no patch comingOPEN
5The Gentlemen ransomware into healthcareOPEN
6Storm server-side infostealer, session replayRIGHT
7OAuth connected-app SaaS bulk export (Scattered LAPSUS$ Hunters)OPEN
8Autonomous AI supply-chain poisoning (hackerbot-claw / LiteLLM)OPEN
9Chrome V8 CVE-2026-11645 zero-day drive-byOPEN
10Iran-nexus / pro-Russia OT probing, tank gaugesOPEN
Issue #2 · Week of 2026-06-15 · subscriber issue
1PeopleSoft CVE-2026-35273 exploitation spreads past educationRIGHT
2Cisco SD-WAN Manager CVE-2026-20245 edge config-pushOPEN
3AI-gateway / MCP unauth RCE (LiteLLM class)OPEN
4SSL-VPN smash-and-grab, sub-hour encryption (Akira)RIGHT
5ClickFix fake-CAPTCHA infostealer, macOS includedOPEN
6Frontier-AI KYC bypass economy (stealer logs, verified accounts, deepfake liveness)OPEN
7Help-desk vishing into finance & insuranceOPEN
8AI-voice BEC into quarter-endRIGHT
9PRC telecom/edge pre-positioning, no clean evictionOPEN
10Shai-Hulud forks hit trusted package scopesRIGHT
Issue #1 · Week of 2026-06-08 · read the full issue
1Edge VPN, firewall, and SAML-IdP appliances stay the number-one ransomware on-ramp.RIGHT
2FortiClient EMS becomes a direct path to your endpoint fleet.RIGHT
3The infostealer "log-to-lead" pipeline compresses a breach to under four days.RIGHT
4Stolen session cookies overtake stolen passwords.RIGHT
5Self-propagating npm/PyPI worms keep mutating week to week.RIGHT
6CI/CD secret theft moves upstream into typosquats and dependency confusion.RIGHT
7Vendor-payment redirection rises into quarter-end.PARTIAL
8Nation-state crews keep pre-positioning on edge devices in critical infrastructure.OPEN
9Hacktivist DDoS and OT probing track geopolitical flashpoints.OPEN
10A patched Android Framework flaw is being exploited on real devices.RIGHT
Most intelligence products never tell you their hit rate. This page is the hit rate. If you think a grade is wrong once it posts, reply to any issue and argue it; we'll print the better case.
Subscribe to PTI Wire