The call scoreboard
Every forward call PTI Wire publishes lands on this page with its confidence band and a closing date. When the window closes, the call gets graded against public reporting and the evidence is linked. A wrong call stays on the board; nothing gets quietly deleted.
120calls made
56resolved
24right
17wrong
How grading works. Right means the
called behavior showed up inside the window, backed by named public reporting.
Wrong means the window closed without it.
Partial means the direction held but the scope or timing
didn't. Calls marked rolling describe ongoing activity and get reviewed on a fixed date
instead of a single yes/no. Issue #1 shipped 2026-06-08, so the first grades post in late June.
What shows here. Issue #1 is the free public sample, so its calls appear
in full. Calls from subscriber issues are listed by a short reference only, a product name or a
TTP, enough to check the grade against the claim; the full call and its reasoning stay in the
subscriber archive.
Live tracking: the open calls, as of 2026-08-24. Interim signal, not verdicts; each call still grades when its window closes.
Tracking toward Right (the called event is already on the public record): Cisco SD-WAN CVE-2026-20245 (vendor-confirmed config-push), LiteLLM CVE-2026-42271 (KEV, chained RCE), the SharePoint cluster (CVE-2026-50522 exploited 2026-07-20), Metabase GHSA-vwf4-m7j8-wcjf (Framework and Tally both disclosed theft), the keyv and cacheable npm takeover (Sigstore provenance minted on poisoned source, confirmed by Socket, Microsoft and Wiz), UNC6671 help-desk vishing into funds (Bloomberg and Reuters named 4 firms), Unit 42 token jacking (published research, resale economy documented), and the Cl0p PTC Windchill campaign, where the group named more than 40 organizations on 2026-08-12 and ReliaQuest published the custom implant on 08-18.
Monitoring (slow-burn or event-conditioned, no decisive in-window signal yet): nation-state edge and telecom pre-positioning (Issue #1 and #2), hacktivist DDoS, the frontier-AI KYC bypass economy, the remaining Issue #5 calls (PolinRider, Armored Likho, satcom ICS, Node.js disclosure reform), the JADEPUFFER follow-on, the Issue #8 AI-safety and cloud-native C2 calls, and the Issue #9 set, which mostly closes in September. Sixteen windows shut on 2026-08-24 and are graded below: 3 Right, 6 Partial, 7 Wrong. The pattern in the failures matters more than the tally. Eight of the 16 failed because the evidence that would have proved the call was already public before the window opened, which is the same window-design defect that produced the named-victim misses in the last round. 7-02 and 3-04 are the clearest cases, both written after the exploitation had already reached the federal catalog. Issue #12 changes the shape of its first 4 calls in response: each resolves on a dated forward event rather than on a named victim inside a short window. Issue #12 adds 10 new calls, listed in full below. Issue #11, published 2026-08-17, graded nothing and carried Issue #10's board forward unverified, which is why these 16 windows were still open. Its own 10 calls are listed below and none of them closes before 2026-10-16.
Tracking toward Right (the called event is already on the public record): Cisco SD-WAN CVE-2026-20245 (vendor-confirmed config-push), LiteLLM CVE-2026-42271 (KEV, chained RCE), the SharePoint cluster (CVE-2026-50522 exploited 2026-07-20), Metabase GHSA-vwf4-m7j8-wcjf (Framework and Tally both disclosed theft), the keyv and cacheable npm takeover (Sigstore provenance minted on poisoned source, confirmed by Socket, Microsoft and Wiz), UNC6671 help-desk vishing into funds (Bloomberg and Reuters named 4 firms), Unit 42 token jacking (published research, resale economy documented), and the Cl0p PTC Windchill campaign, where the group named more than 40 organizations on 2026-08-12 and ReliaQuest published the custom implant on 08-18.
Monitoring (slow-burn or event-conditioned, no decisive in-window signal yet): nation-state edge and telecom pre-positioning (Issue #1 and #2), hacktivist DDoS, the frontier-AI KYC bypass economy, the remaining Issue #5 calls (PolinRider, Armored Likho, satcom ICS, Node.js disclosure reform), the JADEPUFFER follow-on, the Issue #8 AI-safety and cloud-native C2 calls, and the Issue #9 set, which mostly closes in September. Sixteen windows shut on 2026-08-24 and are graded below: 3 Right, 6 Partial, 7 Wrong. The pattern in the failures matters more than the tally. Eight of the 16 failed because the evidence that would have proved the call was already public before the window opened, which is the same window-design defect that produced the named-victim misses in the last round. 7-02 and 3-04 are the clearest cases, both written after the exploitation had already reached the federal catalog. Issue #12 changes the shape of its first 4 calls in response: each resolves on a dated forward event rather than on a named victim inside a short window. Issue #12 adds 10 new calls, listed in full below. Issue #11, published 2026-08-17, graded nothing and carried Issue #10's board forward unverified, which is why these 16 windows were still open. Its own 10 calls are listed below and none of them closes before 2026-10-16.
Issue #12 · Week of 2026-08-24 · subscriber issue
1VMware vCenter CVE-2026-59310 syslog traversal, reverse_ssh persistence, 361 victim addressesOPEN
2TrueConf CVE-2026-72529 and CVE-2026-72530, Head Mare trojanized client installers, PhantomCoreOPEN
3SAP Commerce Cloud CVE-2026-58231 (CVSS 10) exploited 3 days after patchOPEN
4GitLab CVE-2026-19478 unauthenticated GraphQL project deletion and forged merge recordsOPEN
5StubMaker / BRIDGEHEAD dual-registry stealer, RubyGems plus npm, WSL gate to the Windows hostOPEN
6Cl0p names 40+ PTC Windchill victims, custom Java implant decrypts the PLM keystoreOPEN
7Truffle Security leaked AWS keys: 526 root, 242 with AdministratorAccess, 88% still liveOPEN
8Lazarus CVE-2026-68820 AFD.sys zero-day in Operation Dream Job, MISTPEN and TroyOPEN
9Agent payloads propagating through persistent instruction files; CircleCI MCP server GHSA-xv5j-cwgj-22r4OPEN
10Joint advisory AA26-231A: AI-built tooling against exposed Siemens S7 controllersOPEN
Issue #11 · Week of 2026-08-17 · subscriber issue
Issue #11 was written and published outside the usual pipeline and uses a different template: a call, a timeframe, an explicit falsification test, and a basis, with High, Medium and Low bands and no PIR lines. The theme shown in the PIR field below is taken from each call's own subject. Band, window and close date are as published. This issue graded no prior calls.
1Scanners become the preferred way into the AI stack: build-chain security tooling as the poisoning vectorOPEN
2An authorized agent causes a disclosed material incident, no stolen credential involvedOPEN
3Carriers price agent authorization before supervisors mandate itOPEN
4First public fight over whether AI sat in the chain of causation under an AI exclusionOPEN
5ERP is the new edge device: another maximum-severity pre-auth RCE exploited as a zero-dayOPEN
6DPRK IT worker placements resold as access to a separate financially motivated actorOPEN
7Attribution concedes it cannot separate operator from agent, as a standing methodology caveatOPEN
8Instruction injection lands in KEV as the named exploited weaknessOPEN
9Exfiltration-only extortion crosses half of incidents in a published quarterly datasetOPEN
10A financial supervisor names agent authorization as an expected controlOPEN
Issue #10 · Week of 2026-08-10 · subscriber issue
1Metabase pre-auth SQL injection GHSA-vwf4-m7j8-wcjf (CVSS 10, no CVE), vendor cloud breachedOPEN
2N-able N-central CVE-2026-18556 plus patch bypass CVE-2026-18577, Cloudflare Tunnel persistencePARTIAL
3keyv / cacheable npm takeover, Shai-Hulud lineage, Sigstore provenance and rotation dead-man's switchOPEN
4UNC6671 / BlackFile help-desk vishing into hedge funds, passkey re-enrollment pretextOPEN
5JetBrains TeamCity CVE-2026-63077 unauthenticated RCE, KEV 08-05OPEN
6Unit 42 token jacking: stolen AI API keys resold through new-api / one-api proxiesOPEN
7Forged tool calls in agent runtimes: AWS CVE-2026-18830, Google CVE-2026-18236, Vercel relay flawsOPEN
8North Carolina Ports unattributed attack, 3 facilities manualOPEN
9Apache Tomcat CVE-2026-34486, EncryptInterceptor fail-open introduced by its own patchOPEN
10House Select Committee "Stranger Pings" on PRC carriers embedded in US infrastructureOPEN
Issue #9 · Week of 2026-08-03 · subscriber issue
1Arista VeloCloud Orchestrator CVE-2026-16812 (CVSS 10, KEV), edge config tamperingWRONG
2Cisco Secure FMC hard-coded password CVE-2026-20316, KEV 07-29OPEN
3Water utility OT attack across seven states, PLC lockout, attribution openOPEN
4Anthropic evaluation models breach three orgs, PyPI package ran on 15 systemsOPEN
5knaithe autonomous stack: DeepSeek plus Hermes Agent, 460+ targetsOPEN
6Coldcard RNG fallback across five models, 1,196 addresses swept in 41 minutesOPEN
7EY client tax documents via third-party ITSM, ShinyHunters deadlineOPEN
8MikroTik RouterOS CVE-2026-14227, WireGuard private key extractionOPEN
9FortiOS CVE-2025-68686 symlink persistence bypass, KEV 07-27OPEN
10Toptech RCU II+ / Multiload II+ unauthenticated root debug interfaceOPEN
Issue #8 · Week of 2026-07-27 · subscriber issue
1Check Point SmartConsole auth bypass (CVE-2026-16232 KEV), policy tamperingWRONG
2ServiceNow AI Platform pre-auth RCE (CVE-2026-6875), exploited from 07-18WRONG
3WordPress core wp2shell chain (CVE-2026-63030 + CVE-2026-60137 KEV)PARTIAL
4Hugging Face breached by OpenAI evaluation models, sandbox escapeOPEN
5FakeAgent: malware Artifact hosted on claude.ai, Bing malvertising to SectopRATOPEN
6Laundry Bear Zimbra view-based mail theft (CVE-2025-66376, AA26-204A)OPEN
7Anubis halts Fairlife production, Coca-Cola 8-K, leak-site listingOPEN
8HOLLOWGRAPH Microsoft 365 calendar command channel (Cavern framework)OPEN
9FakeGit / AgentBaiting: 7,600 repos, 800 fake AI skills and MCP serversOPEN
10Chaos msaRAT browser-driven C2 over DevTools Protocol and WebRTCOPEN
Issue #7 · Week of 2026-07-20 · subscriber issue
1SonicWall SMA1000 zero-days (CVE-2026-15409/15410), INC ransomware + UTA0533PARTIAL
2AD FS token-forgery zero-day (CVE-2026-56155 KEV) + Machine DPAPI key recoveryWRONG
3SharePoint cluster widens (CVE-2026-58644 KEV) + machine-key persistenceRIGHT
4AsyncAPI CI/CD provenance-forgery supply chain (Miasma via OIDC trusted-publisher)PARTIAL
5HalluSquatting: AI-assistant hallucinated packages weaponizedOPEN
6Oracle E-Business Suite Payments takeover (CVE-2026-46817 KEV), 900+ exposedPARTIAL
7RedWing Android bank-fraud MaaS on Telegram, target list expandsOPEN
8NetNut takedown displacement to rival residential-proxy networksOPEN
9KNX building-automation exploitation (CVE-2023-4346 KEV), device brickingOPEN
10Poisoned Tenant SaaS-invite abuse spreads to another AI/SaaS platformOPEN
Issue #6 · Week of 2026-07-13 · subscriber issue
1Langflow exploited CVEs (CVE-2026-55255 KEV + CVE-2026-33017), flow hijackRIGHT
2Agent-run ransomware precedent (JADEPUFFER): second case or vendor detectionsOPEN
3FortiBleed credential theft to INC/Lynx ransomware pipelineWRONG
4Joomla extension KEV cluster (SP Page Builder, Joomlack, iCagenda, Balbooa)PARTIAL
5Fake payment-SDK packages on npm/PyPI (Paysafe/Skrill/Neteller)WRONG
6Indra Group / The Gentlemen leak-site deadline, defense-sector extortionWRONG
7Nidec CCI / BlackField $2M demand, JP subsidiary blind spotWRONG
8Schneider Easergy MiCOM Px40 relay SNMP exposure (CVE-2026-4832)OPEN
9BEC advisory or named seven-figure payment-redirection lossWRONG
10Rival-state convergence on identity/biometric data stores (One Target, Two Flags)OPEN
Issue #5 · Week of 2026-07-06 · subscriber issue
1Microsoft SharePoint deserialization RCE (CVE-2026-45659), Storm-2603 / WarlockRIGHT
2Miasma npm worm: AI coding-assistant persistence, Go expansionRIGHT
3PolinRider DPRK cross-ecosystem developer campaignOPEN
4Armored Likho / BusySnake Stealer, LLM-built loadersOPEN
5Aflac Japan breach: policyholder fraud follow-onWRONG
6KDDI six-ISP shared-mail breach: credential stuffingWRONG
7Satcom / space-segment ICS exposure (iDirect iQ-Series, CubeSpace)OPEN
8Browser-extension update-channel abuse (VPN Go clipper)RIGHT
9TimbreStealer invoice-lure updater side-loadingWRONG
10AI-generated report flood forces OSS disclosure changesOPEN
Issue #4 · Week of 2026-06-29 · subscriber issue
1Ubiquiti UniFi OS triple-10.0 RCE chain (CVE-2026-34908/09/10)RIGHT
2PTC Windchill / FlexPLM deserialization RCE (CVE-2026-12569)RIGHT
3Cisco Unified CM SSRF (CVE-2026-20230)WRONG
4Exposed OT / serial-bridge gear amid the ICS advisory wave (Lantronix EDS5000)PARTIAL
5Infostealer displacement after Operation Endgame (StealC / Amadey)PARTIAL
6Qilin ransomware, manufacturing-ledRIGHT
7Klue / Icarus OAuth-token SaaS supply-chain theftPARTIAL
8CI/CD provenance forgery via OIDC theft (Mini Shai-Hulud / TeamPCP)OPEN
9MCP tool-poisoning and AI-gateway takeover (LiteLLM chain)OPEN
10Vendor-payment and wire fraud into the fiscal closeWRONG
Issue #3 · Week of 2026-06-22 · subscriber issue
1Splunk CVE-2026-20253 unauth RCE in the SOC platformRIGHT
2Joomla JCE CVE-2026-48907 mass web-shellRIGHT
3Microsoft Defender RoguePlanet local-to-SYSTEMPARTIAL
4Arista EOS CVE-2026-7473 tunnel decap, no patch comingWRONG
5The Gentlemen ransomware into healthcareWRONG
6Storm server-side infostealer, session replayRIGHT
7OAuth connected-app SaaS bulk export (Scattered LAPSUS$ Hunters)RIGHT
8Autonomous AI supply-chain poisoning (hackerbot-claw / LiteLLM)OPEN
9Chrome V8 CVE-2026-11645 zero-day drive-byWRONG
10Iran-nexus / pro-Russia OT probing, tank gaugesRIGHT
Issue #2 · Week of 2026-06-15 · subscriber issue
1PeopleSoft CVE-2026-35273 exploitation spreads past educationRIGHT
2Cisco SD-WAN Manager CVE-2026-20245 edge config-pushOPEN
3AI-gateway / MCP unauth RCE (LiteLLM class)OPEN
4SSL-VPN smash-and-grab, sub-hour encryption (Akira)RIGHT
5ClickFix fake-CAPTCHA infostealer, macOS includedOPEN
6Frontier-AI KYC bypass economy (stealer logs, verified accounts, deepfake liveness)PARTIAL
7Help-desk vishing into finance & insurancePARTIAL
8AI-voice BEC into quarter-endRIGHT
9PRC telecom/edge pre-positioning, no clean evictionPARTIAL
10Shai-Hulud forks hit trusted package scopesRIGHT
Issue #1 · Week of 2026-06-08 · read the full issue
1Edge VPN, firewall, and SAML-IdP appliances stay the number-one ransomware on-ramp.RIGHT
2FortiClient EMS becomes a direct path to your endpoint fleet.RIGHT
3The infostealer "log-to-lead" pipeline compresses a breach to under four days.RIGHT
4Stolen session cookies overtake stolen passwords.RIGHT
5Self-propagating npm/PyPI worms keep mutating week to week.RIGHT
6CI/CD secret theft moves upstream into typosquats and dependency confusion.RIGHT
7Vendor-payment redirection rises into quarter-end.PARTIAL
8Nation-state crews keep pre-positioning on edge devices in critical infrastructure.PARTIAL
9Hacktivist DDoS and OT probing track geopolitical flashpoints.OPEN
10A patched Android Framework flaw is being exploited on real devices.RIGHT
Most intelligence products never tell you their hit rate. This page is the hit rate. If you think a grade is wrong once it posts, reply to any issue and argue it; we'll print the better case.
Subscribe to PTI Wire