PTI Wire · validation

The call scoreboard

Every forward call PTI Wire publishes lands on this page with its confidence band and a closing date. When the window closes, the call gets graded against public reporting and the evidence is linked. A wrong call stays on the board; nothing gets quietly deleted.

70calls made
16resolved
15right
0wrong
How grading works. Right means the called behavior showed up inside the window, backed by named public reporting. Wrong means the window closed without it. Partial means the direction held but the scope or timing didn't. Calls marked rolling describe ongoing activity and get reviewed on a fixed date instead of a single yes/no. Issue #1 shipped 2026-06-08, so the first grades post in late June.
What shows here. Issue #1 is the free public sample, so its calls appear in full. Calls from subscriber issues are listed by a short reference only, a product name or a TTP, enough to check the grade against the claim; the full call and its reasoning stay in the subscriber archive.
Live tracking — the 54 open calls, as of 2026-07-20. Interim signal, not verdicts; each call still grades when its window closes.

Tracking toward Right (the called event is already on the public record): Cisco SD-WAN CVE-2026-20245 (vendor-confirmed config-push), LiteLLM CVE-2026-42271 (KEV, chained RCE), Arista EOS CVE-2026-7473 (KEV), Chrome V8 CVE-2026-11645 (KEV), PTC Windchill CVE-2026-12569 (KEV), Cisco CUCM CVE-2026-20230 (KEV), SharePoint CVE-2026-45659 (KEV, Storm-2603/Warlock), Qilin ransomware (assessed Q2's most active, manufacturing-led), Klue/Icarus OAuth SaaS theft (breach confirmed), Defender RoguePlanet (public exploit), ClickFix and help-desk vishing (both dominant), and the Aflac Japan (4.38M) and KDDI six-ISP (14.2M) breaches (disclosed; policyholder/credential-stuffing fraud is the window).

Monitoring (slow-burn or event-conditioned, no decisive in-window signal yet): nation-state edge and telecom pre-positioning (Issue #1 and #2), Iran-nexus OT probing, hacktivist DDoS, the frontier-AI KYC bypass economy, Operation Endgame stealer displacement, and the Issue #5 calls (PolinRider, Armored Likho, satcom ICS, the VPN-Go clipper, TimbreStealer, Node.js disclosure reform), which remain early in their windows. Issues #6 and #7 add newer calls still (Langflow flow-hijack, FortiBleed, the AsyncAPI CI/CD compromise, SonicWall SMA1000, AD FS token forgery), listed in full below.

Issue #7 · Week of 2026-07-20 · subscriber issue

1SonicWall SMA1000 zero-days (CVE-2026-15409/15410), INC ransomware + UTA0533OPEN
PIR: Edge / Ransomware Access · Confidence: High · Window: 2 weeks · Closes: 2026-08-03
2AD FS token-forgery zero-day (CVE-2026-56155 KEV) + Machine DPAPI key recoveryOPEN
PIR: Identity / Federation · Confidence: Medium-High · Window: 4 weeks · Closes: 2026-08-17
3SharePoint cluster widens (CVE-2026-58644 KEV) + machine-key persistenceOPEN
PIR: Collaboration / Persistence · Confidence: Medium-High · Window: 3 weeks · Closes: 2026-08-10
4AsyncAPI CI/CD provenance-forgery supply chain (Miasma via OIDC trusted-publisher)OPEN
PIR: Supply Chain / CI-CD · Confidence: Medium-High · Window: 5 weeks · Closes: 2026-08-24
5HalluSquatting: AI-assistant hallucinated packages weaponizedOPEN
PIR: AI Dev Tooling / Supply Chain · Confidence: Medium · Window: 8 weeks · Closes: 2026-09-14
6Oracle E-Business Suite Payments takeover (CVE-2026-46817 KEV), 900+ exposedOPEN
PIR: ERP / Financial Systems · Confidence: Medium-High · Window: 4 weeks · Closes: 2026-08-17
7RedWing Android bank-fraud MaaS on Telegram, target list expandsOPEN
PIR: Fraud / Mobile Banking · Confidence: Medium · Window: 6 weeks · Closes: 2026-08-31
8NetNut takedown displacement to rival residential-proxy networksOPEN
PIR: Criminal Infrastructure / Attribution · Confidence: Medium · Window: 8 weeks · Closes: 2026-09-14
9KNX building-automation exploitation (CVE-2023-4346 KEV), device brickingOPEN
PIR: OT / Building Automation · Confidence: Low (high-impact) · Window: 6 weeks · Closes: 2026-08-31
10Poisoned Tenant SaaS-invite abuse spreads to another AI/SaaS platformOPEN
PIR: Fraud / SaaS Abuse · Confidence: Medium · Window: 7 weeks · Closes: 2026-09-07

Issue #6 · Week of 2026-07-13 · subscriber issue

1Langflow exploited CVEs (CVE-2026-55255 KEV + CVE-2026-33017), flow hijackOPEN
PIR: AI Infrastructure / Initial Access · Confidence: High · Window: 2 weeks · Closes: 2026-07-27
2Agent-run ransomware precedent (JADEPUFFER): second case or vendor detectionsOPEN
PIR: AI / Ransomware Tradecraft · Confidence: Medium · Window: 8–10 weeks · Closes: 2026-09-21
3FortiBleed credential theft to INC/Lynx ransomware pipelineOPEN
PIR: Edge / Ransomware · Confidence: Medium-High · Window: 4 weeks · Closes: 2026-08-10
4Joomla extension KEV cluster (SP Page Builder, Joomlack, iCagenda, Balbooa)OPEN
PIR: Web / CMS Exposure · Confidence: Medium-High · Window: 4 weeks · Closes: 2026-08-10
5Fake payment-SDK packages on npm/PyPI (Paysafe/Skrill/Neteller)OPEN
PIR: Supply Chain / Fintech · Confidence: Medium-High · Window: 5 weeks · Closes: 2026-08-17
6Indra Group / The Gentlemen leak-site deadline, defense-sector extortionOPEN
PIR: Defense / Extortion · Confidence: Medium-High · Window: 3 weeks · Closes: 2026-08-03
7Nidec CCI / BlackField $2M demand, JP subsidiary blind spotOPEN
PIR: Manufacturing / Extortion · Confidence: Medium · Window: 5 weeks · Closes: 2026-08-17
8Schneider Easergy MiCOM Px40 relay SNMP exposure (CVE-2026-4832)OPEN
PIR: OT / Grid Protection · Confidence: Low (high-impact) · Window: 7 weeks · Closes: 2026-08-31
9BEC advisory or named seven-figure payment-redirection lossOPEN
PIR: Fraud / Finance Ops · Confidence: Medium · Window: 6 weeks · Closes: 2026-08-24
10Rival-state convergence on identity/biometric data stores (One Target, Two Flags)OPEN
PIR: Nation-state / Identity Records · Confidence: Medium · Window: 7 weeks · Closes: 2026-08-31

Issue #5 · Week of 2026-07-06 · subscriber issue

1Microsoft SharePoint deserialization RCE (CVE-2026-45659), Storm-2603 / WarlockOPEN
PIR: Collaboration / Initial Access · Confidence: High · Window: 1–2 weeks · Closes: 2026-07-20
2Miasma npm worm: AI coding-assistant persistence, Go expansionOPEN
PIR: Supply Chain / AI Dev Tooling · Confidence: High · Window: 2–6 weeks · Closes: 2026-08-17
3PolinRider DPRK cross-ecosystem developer campaignOPEN
PIR: Nation-state / Dev Supply Chain · Confidence: Medium-High · Window: 6–8 weeks · Closes: 2026-08-31
4Armored Likho / BusySnake Stealer, LLM-built loadersOPEN
PIR: Nation-state / Energy · Confidence: Medium · Window: 4–8 weeks · Closes: 2026-08-31
5Aflac Japan breach: policyholder fraud follow-onOPEN
PIR: Insurance / Fraud · Confidence: Medium-High · Window: 4–6 weeks · Closes: 2026-08-17
6KDDI six-ISP shared-mail breach: credential stuffingOPEN
PIR: Identity / Telecom · Confidence: Medium-High · Window: 4–5 weeks · Closes: 2026-08-10
7Satcom / space-segment ICS exposure (iDirect iQ-Series, CubeSpace)OPEN
PIR: OT / Space & Satcom · Confidence: Low, high-impact · Window: 6–8 weeks · Closes: 2026-08-31
8Browser-extension update-channel abuse (VPN Go clipper)OPEN
PIR: Browser / Endpoint · Confidence: Medium · Window: 4–8 weeks · Closes: 2026-08-24
9TimbreStealer invoice-lure updater side-loadingOPEN
PIR: Fraud / Finance Ops · Confidence: Medium · Window: 4–5 weeks · Closes: 2026-08-10
10AI-generated report flood forces OSS disclosure changesOPEN
PIR: AI / OSS Governance · Confidence: Medium · Window: this quarter · Closes: 2026-09-28

Issue #4 · Week of 2026-06-29 · subscriber issue

1Ubiquiti UniFi OS triple-10.0 RCE chain (CVE-2026-34908/09/10)RIGHT
PIR: Network / Edge · Confidence: High · Window: 1–2 weeks · Closed: 2026-07-13
Graded 2026-07-20: CISA added the UniFi OS chain (CVE-2026-34908/09/10, three CVSS 10.0 flaws) to its exploited catalog on 2026-06-23 after confirmed in-the-wild exploitation by a Mirai/Gafgyt botnet; PwnDefend documented the CVE-2026-34910 to Mirai-loader chain on 06-09 and roughly 100,000 endpoints stayed exposed into July. The Hacker News.
2PTC Windchill / FlexPLM deserialization RCE (CVE-2026-12569)OPEN
PIR: Manufacturing / PLM · Confidence: High · Window: 2–3 weeks · Closes: 2026-07-20
3Cisco Unified CM SSRF (CVE-2026-20230)OPEN
PIR: Comms / Unified Communications · Confidence: Medium-High · Window: 2–4 weeks · Closes: 2026-07-27
4Exposed OT / serial-bridge gear amid the ICS advisory wave (Lantronix EDS5000)OPEN
PIR: OT / ICS · Confidence: Low, high-impact · Window: 6–8 weeks · Closes: 2026-08-17
5Infostealer displacement after Operation Endgame (StealC / Amadey)OPEN
PIR: Identity / Infostealer · Confidence: Medium · Window: 4–8 weeks · Closes: 2026-08-24
6Qilin ransomware, manufacturing-ledOPEN
PIR: Ransomware / Manufacturing · Confidence: High · Window: 2–6 weeks · Closes: 2026-08-10
7Klue / Icarus OAuth-token SaaS supply-chain theftOPEN
PIR: SaaS / Identity · Confidence: Medium-High · Window: 4–6 weeks · Closes: 2026-08-10
8CI/CD provenance forgery via OIDC theft (Mini Shai-Hulud / TeamPCP)OPEN
PIR: Supply Chain / CI-CD · Confidence: High · Window: this quarter · Closes: 2026-09-28
9MCP tool-poisoning and AI-gateway takeover (LiteLLM chain)OPEN
PIR: AI / Agent Tooling · Confidence: Medium, high-impact · Window: this quarter · Closes: 2026-09-21
10Vendor-payment and wire fraud into the fiscal closeOPEN
PIR: Fraud / BEC · Confidence: Medium-High · Window: 2–4 weeks · Closes: 2026-07-27

Issue #3 · Week of 2026-06-22 · subscriber issue

1Splunk CVE-2026-20253 unauth RCE in the SOC platformRIGHT
PIR: Security Tooling / SOC · Confidence: High · Window: 1–2 weeks · Closed: 2026-07-06
Graded 2026-07-07: CISA added Splunk CVE-2026-20253 (CVSS 9.8 unauthenticated RCE) to its exploited catalog on 2026-06-18 with a three-day deadline; SecurityWeek reported exploitation days after disclosure and WatchTowr published a working exploit, confirming the SOC platform itself as an active entry point. SecurityWeek.
2Joomla JCE CVE-2026-48907 mass web-shellRIGHT
PIR: Web / CMS · Confidence: High · Window: 2–3 weeks · Closes: 2026-07-13
Resolved early 2026-07-07 — RIGHT: CISA added Joomla JCE CVE-2026-48907 (CVSS 10.0 unauth RCE) to its exploited catalog on 2026-06-16 with automated web-shell attacks confirmed and public exploit code out. The Hacker News.
3Microsoft Defender RoguePlanet local-to-SYSTEMOPEN
PIR: Endpoint / EDR · Confidence: High · Window: 2–4 weeks · Closes: 2026-07-20
4Arista EOS CVE-2026-7473 tunnel decap, no patch comingOPEN
PIR: Network / Edge · Confidence: Medium-High · Window: 4–8 weeks · Closes: 2026-08-17
5The Gentlemen ransomware into healthcareOPEN
PIR: Ransomware / Healthcare · Confidence: High · Window: 2–6 weeks · Closes: 2026-08-03
6Storm server-side infostealer, session replayRIGHT
PIR: Identity / Session · Confidence: High · Window: ongoing · Closes: 2026-07-20
Resolved early 2026-07-07 — RIGHT: Varonis and BleepingComputer documented the Storm server-side stealer decrypting harvested cookies on the operator server to restore authenticated sessions, the called capability, in active use. Varonis.
7OAuth connected-app SaaS bulk export (Scattered LAPSUS$ Hunters)OPEN
PIR: SaaS / Identity · Confidence: Medium-High · Window: 4–6 weeks · Closes: 2026-08-03
8Autonomous AI supply-chain poisoning (hackerbot-claw / LiteLLM)OPEN
PIR: AI / Agent Supply Chain · Confidence: Medium · Window: this quarter · Closes: 2026-09-21
9Chrome V8 CVE-2026-11645 zero-day drive-byOPEN
PIR: Browser / Endpoint · Confidence: Medium · Window: 4–6 weeks · Closes: 2026-08-03
10Iran-nexus / pro-Russia OT probing, tank gaugesOPEN
PIR: OT / Geopolitics · Confidence: Low, high-impact · Window: 6–8 weeks · Closes: 2026-08-17

Issue #2 · Week of 2026-06-15 · subscriber issue

1PeopleSoft CVE-2026-35273 exploitation spreads past educationRIGHT
PIR: Initial Access / ERP · Confidence: High · Window: 2–4 weeks · Closed: 2026-07-13
Graded 2026-07-20: The ShinyHunters PeopleSoft campaign (CVE-2026-35273) spread well past education: the NAIC insurance regulator confirmed a breach on 2026-06-29 and Nissan disclosed an employee-data breach tied to the same Oracle zero-day, both outside the education sector where the campaign began. BleepingComputer.
2Cisco SD-WAN Manager CVE-2026-20245 edge config-pushOPEN
PIR: Network / Edge · Confidence: Medium-High · Window: this quarter · Closes: 2026-09-15
3AI-gateway / MCP unauth RCE (LiteLLM class)OPEN
PIR: AI Infra / Supply Chain · Confidence: Medium · Window: this quarter · Closes: 2026-09-15
4SSL-VPN smash-and-grab, sub-hour encryption (Akira)RIGHT
PIR: Ransomware / Access · Confidence: High · Window: 2–4 weeks · Closes: 2026-07-13
Resolved early 2026-07-07 — RIGHT: Arctic Wolf, Rapid7, and Huntress all tracked the Akira SonicWall SSL-VPN campaign as active through the window, dwell from VPN login to encryption near an hour, MFA bypassed with pre-harvested credentials. Arctic Wolf.
5ClickFix fake-CAPTCHA infostealer, macOS includedOPEN
PIR: Identity / Cred theft · Confidence: High · Window: rolling · Reviewed: 2026-07-27
6Frontier-AI KYC bypass economy (stealer logs, verified accounts, deepfake liveness)OPEN
PIR: Identity / AI Access · Confidence: Medium-High · Window: 4–8 weeks · Closes: 2026-08-10
7Help-desk vishing into finance & insuranceOPEN
PIR: Identity / Social eng · Confidence: Medium-High · Window: 4–6 weeks · Closes: 2026-07-27
8AI-voice BEC into quarter-endRIGHT
PIR: Fraud / BEC · Confidence: High · Window: 2–3 weeks · Closed: 2026-07-06
Graded 2026-07-07: AI-generated voice, video, or text now features in roughly 40% of BEC attempts (up from under 5% in 2023), with per-incident losses near $4.1M and a reported $25.6M executive-impersonation case, aimed at wire and vendor-payment approvals. The quarter-end timing specifically is the softer edge of the call. AI-BEC 2026.
9PRC telecom/edge pre-positioning, no clean evictionOPEN
PIR: Geopolitics / Telecom · Confidence: Low, high-impact · Window: 6–8 weeks · Closes: 2026-08-10
10Shai-Hulud forks hit trusted package scopesRIGHT
PIR: Supply Chain / CI-CD · Confidence: High · Window: 2–6 weeks · Closes: 2026-07-27
Resolved early 2026-07-07 — RIGHT: forks hit trusted scopes repeatedly in-window: Miasma compromised @redhat-cloud-services npm packages, then LeoPlatform and @immobiliarelabs, with TrapDoor and Hades alongside. Socket.

Issue #1 · Week of 2026-06-08 · read the full issue

1Edge VPN, firewall, and SAML-IdP appliances stay the number-one ransomware on-ramp.RIGHT
PIR: Ransomware / Initial Access · Confidence: High · Window: 2–4 weeks · Closed: 2026-07-06
Graded 2026-07-07: Verizon's 2026 DBIR put edge-device and VPN exploitation at 22% of breaches (up ~7x) and named vulnerability exploitation the top initial-access vector for the first time; PAN-OS CVE-2026-0257 and the FortiBleed operation (73,000+ devices) kept the called appliances in active abuse. DBIR 2026.
2FortiClient EMS becomes a direct path to your endpoint fleet.RIGHT
PIR: Initial Access / Endpoint Management · Confidence: High · Window: rolling · Reviewed: 2026-07-06
Graded 2026-07-07: Arctic Wolf documented an active cluster exploiting FortiClient EMS CVE-2026-35616 to push the EKZ infostealer, disguised as a Fortinet patch, onto EMS-managed endpoints, the controller-to-fleet path this call described; CISA KEV-listed. Arctic Wolf.
3The infostealer "log-to-lead" pipeline compresses a breach to under four days.RIGHT
PIR: Identity / Credential Theft · Confidence: High · Window: rolling · Reviewed: 2026-07-06
Graded 2026-07-07: The infostealer-to-access-to-ransomware pipeline held and intensified: June's Operation Endgame disrupted StealC and Amadey as the "assembly lines" for ransomware and fraud (326 servers, 27M credentials), and server-side stealers like Storm kept turning one infection into authenticated access. Operation Endgame.
4Stolen session cookies overtake stolen passwords.RIGHT
PIR: Identity / Session Security · Confidence: Medium-High · Window: this quarter · Closed: 2026-06-30
Graded 2026-07-06: 2026 reporting put stolen session cookies and tokens at the center of intrusions inside the window: Huntress tracked session theft in 86% of breaches, and June's 24-billion-record dump circulated with live session data.
5Self-propagating npm/PyPI worms keep mutating week to week.RIGHT
PIR: Supply Chain · Confidence: High · Window: 2–6 weeks · Closes: 2026-07-20
Resolved early 2026-07-07 — RIGHT: the weekly worm cadence is on the record: the Mastra easy-day-js typosquat hit 140+ npm packages on June 17, the Miasma / Mini Shai-Hulud family pushed fresh waves June 24-26, with TrapDoor and Hades alongside. The called behavior has already occurred, ahead of the window. Socket.
6CI/CD secret theft moves upstream into typosquats and dependency confusion.RIGHT
PIR: Supply Chain / Cloud · Confidence: Medium · Window: this quarter · Closed: 2026-06-30
Graded 2026-07-06: the June 17 Mastra compromise planted the typosquat easy-day-js as a dependency across 140+ npm packages to steal credentials (Microsoft, Socket); Miasma waves stole registry and CI/CD tokens through June.
7Vendor-payment redirection rises into quarter-end.PARTIAL
PIR: Fraud / BEC · Confidence: High · Window: 2–3 weeks · Closed: 2026-06-29
Graded 2026-07-06: the direction held on trend data (AFP: wires most-targeted, BEC at roughly three in four organizations), but no named, dated vendor-redirection incident inside the window surfaced in public reporting; our bar for Right requires one.
8Nation-state crews keep pre-positioning on edge devices in critical infrastructure.OPEN
PIR: Geopolitics / OT · Confidence: Low, high-impact · Window: 6–8 weeks · Closes: 2026-08-03
9Hacktivist DDoS and OT probing track geopolitical flashpoints.OPEN
PIR: Geopolitics / DDoS · Confidence: Medium, event-conditioned · Window: rolling · Reviewed: 2026-08-03
10A patched Android Framework flaw is being exploited on real devices.RIGHT
PIR: Mobile / Endpoint · Confidence: Medium · Window: 4–6 weeks · Closes: 2026-07-20
Resolved early 2026-07-07 — RIGHT: CISA added Android Framework CVE-2025-48595 to its exploited-vulnerabilities catalog on 2026-06-02, confirming in-the-wild exploitation on real devices, the exact claim. CISA KEV.

Most intelligence products never tell you their hit rate. This page is the hit rate. If you think a grade is wrong once it posts, reply to any issue and argue it; we'll print the better case.

Subscribe to PTI Wire