FLUX FLEET — INTEL BRIEFING №18
Period: 2026-09-11 12:14 – 2026-09-12 12:14 UTC (24h digest window, day 17 of operations)
Sources: 7 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East, recovered this cycle), ru-edge-1 (Russia), netcup-ts + sponge-01-ts + frantech-ts (deception-only, no canaries)
Confidence: High (direct observation; 17-day baseline, every result-tag spike attributed by spot query). This is the rerun briefing for 2026-09-12. №17 (07:32 run) already covers the window's first 19 hours.
The digest window runs 12:14 UTC 09-11 to 12:14 UTC 09-12. Events before 07:32 UTC on 09-12 are overlap with №17 and are not recounted as new. The true new segment (07:32–12:14 UTC on 09-12) is short but dense: control-1 came back online, three fresh-geo nodes logged their first flux data, and a two-node
.env-census campaign appeared on the mass-scan and control nodes. All times below are raw log timestamps (UTC). The +4 h ingest cast widens SQL windows by 4 hours. Every segment boundary in this briefing is stated in raw UTC.
BLUF
control-1 recovered after three failed sync cycles and delivered 1,813 events in 4 hours, the node's densest day in the record. The recovery data carried a new census campaign: a single-identity crawler (empty clientIp on every row, 33 forged UAs) walked 648 paths, 442 of them .env variants, on control's public IP and minted 2 credentials. The same control-byte-suffixed .env wordlist ran on sponge-01-ts (293 paths), so the campaign is ⚠ fleet-wide across two nodes with unattributed source IPs. The WP-ENUM plugin-readme.txt census jumped from canary-farm-1/ai-devbox-1 to ru-edge-1 with the identical 61-path wordlist and the same bare Chrome/123 UA — the first template the fleet has seen operate in two basins. The curl/8.5.0 scanner wave probed all 7 nodes, minted 12 credentials through loopback-facing /.env paths, and drew 38 upstream 400 rejections. AWS use stayed at zero for the fourth window. Fleet sensors minted 86 credentials to 19 collector IPs.
Key Judgements
- A two-node
.env-census campaign now runs on the unattributed nodes, and the tooling is shared. The control-1 crawler produced 1,732 public-facing events (648 paths, 442.envvariants, 33 UAs, 22 POSTs) between 07:59 and 12:09 UTC, and sponge-01-ts carried 112 of the same control-byte-suffixed.envpaths (/.env.ci\x0b,/.env.heroku\x0b,/.env.preview\t,/s3/.env.bak). The two nodes share 195 distinct.envpaths. Neither node records a source IP for any row, so the campaign is ⚠ NEW and ⚠ fleet-wide with attribution blocked at the log layer. (High confidence on the tooling link — 195 shared paths is not coincidence; Moderate on campaign scope because both appearances fall inside one window.) - WP-ENUM now operates in two basins — the first template with that reach. The ru-edge-1 census fired 61
readme.txtpaths in 4 seconds at 09:41 UTC under the exact bare UAMozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.36. All 61 paths appear in the 45.156.128.x union from ai-devbox-1 (62 paths, fired at 07:35 UTC, 2 hours earlier). This is the third run of the template in four days and its first appearance on ru-edge-1. (High confidence — wordlist and UA compared byte-for-byte by SQL join; the 4-second burst rules out a shared scheduled job unless the operator runs one script per basin.) - The curl/8.5.0 wave is an attribution hole that mints. A single request template —
GET /.env,GET /wp-login.php,GET /api/v1/payment-methods,GET /.well-known/agent-card.json,GET /actuator, oneGET /shell.php— hit all 7 nodes between 07:59 and 08:55 UTC undercurl/8.5.0andcurl/8.18.0, with every row carrying an emptyclientIp. Ten attempts minted successfully and 21 more drew upstream 400 rejections. Twelve credentials now carry no source IP. The probe set is identical on every node, so the wave is one operator. (High confidence on one operator — probe lists match across 7 sensors; the source IP is unknown, not absent by design.) - control-1's recovery resets the differential experiment. The node's log file now spans only 07:59–12:09 UTC (1,813 rows). The 15-day ramp history survives only in digests. Within those 4 hours the node drew 51 distinct identities, 4 mints, and the same census wave as sponge-01-ts — consistent with the fresh-IP hypothesis that discovery starts within hours of exposure. The day-17 ramp cell is 1,813 events / 51 IPs, but the cell counts only the recovered segment, not a full day. (High confidence on the facts. The ramp comparison to prior cells is broken until the node runs a full cycle.)
Active Campaigns (day 17 status)
Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.
All seven established campaign families (METADATA-HUNT, OMEGA-SWEEP, LIBREDTAIL-KIT, NIGHTAGENT, REGISTRY-HUNT, SS-NET TOOLING, CREDSWEEP) ran inside the overlap segment only — see №17. Their new-window status: silent. The new-window campaigns are the three below.
⚠ ENV-CENSUS-2 (control-byte .env wordlist on unattributed nodes) — hostile, NEW, fleet-wide across control-1 and sponge-01-ts
- Actors: No source IP on any row. control-1: one crawler identity across the whole window (empty
clientIp, 33 forged UAs ranging from Chrome/131 desktop to iPhone 18.2 to Firefox/134, plus theMozlila/5.0 (…Bulid/NRD90M…Moblie…)typo forgery, 177 events). sponge-01-ts: same empty-IP shape, 15 UAs, 60 active minutes. - TTPs: Sequential
.env-variant census with per-request control-byte suffixes that evade exact-path dedup (/.env.ci\x0b,/.env.preview\t,/s3/.env.bak,/\x00.env.prod,/api2/.env,/laravel/core/.env,/payments/.env,/test1/.env,/1board/.env). control-1 walked 648 paths (442.envvariants) in two bursts — 212 events at 09:29–09:31 UTC and 1,427 events across 450 paths at 11:11–11:13 — plus a long tail to 12:09. sponge-01-ts ran 293 paths over 3 hours. The census also probed/phpinfo.php(36 responses),/appsettings.json,/api/.env,/backend/.env, and 22 POSTs with 3–7 byte bodies. Two real mints issued on control (/.envat 09:29 under an Edge/124 forgery and at 11:11 under Chrome/131). Another 18 mint attempts drew upstream 400 rejections. TheMozlilatypo forgery is CREDSWEEP's marker — this template either shares the CREDSWEEP wordlist or is a CREDSWEEP operator that dropped IP logging. - Assessment: The control-1 census drew 25
env-productionresponses — the node served real-looking.envcontent — so the operator walked away with plausible-credential bait but Tracebit-minted only twice. The campaign matters most for what it hides: withclientIpempty on every row, the fleet's IP-rotation tracking, blocklist joins, and ASN attribution are all blind. This is the first campaign whose attribution the fleet design cannot recover without a node-side fix.
⚠ WP-ENUM-BASIN (plugin readme.txt census, bare Chrome/123 UA) — hostile, WP-ENUM third generation, now on ru-edge-1
- Actors: ru-edge-1: no clientIp recorded (see the attribution gap in Fleet Observations). ai-devbox-1 overlap: 45.156.128.126 (45 events, 35 readmes) and 45.156.128.47 (26 events, 26 readmes) at 07:35 UTC — recount of the №16 cluster, not new.
- TTPs: 61 distinct
wp-content/plugins/<name>/readme.txtpaths in 4 seconds (09:41–09:41:24 UTC), allnot-handled, followed bywp-rest-indexandcmd-injection-probeprobes at/admin/config.php. The 61-path list matches the ai-devbox-1 union (62 paths) exactly on 61 paths. UA is the bare stripped string with no platform token — the №16 WP-ENUM signature. - Assessment: Same wordlist, same UA, two basins 2 hours apart. Either one operator scripts both fleets, or the template is now shared tooling like the CRUSADER-SWEEP class B git walk. The ru-edge-1 run drew zero trap responses (no canaries on the node), so the operator learned nothing there — the deception-only nodes leak template shape but not mint outcomes.
⚠ CURL-SWEEP (uniform curl/8.5.0 probe wave, all 7 nodes) — hostile, NEW, fleet-wide, attribution unknown
- Actors: Unknown. Every row across all 7 nodes carries
curl/8.5.0orcurl/8.18.0and an emptyclientIp. The wave ran 07:59–08:55 UTC on 09-12: control-1 and canary-farm-1 at 07:59–08:14, ai-devbox-1 and ru-edge-1 at 08:03–08:14, then the four no-canary nodes (netcup 08:51, sponge 08:53, frantech 09:09). frantech-ts logged a second pass undercurl/8.18.0at 09:11 UTC. - TTPs: One probe set per node:
/.env,/wp-login.php,/api/v1/payment-methods(GET and POST),/.well-known/agent-card.json,/actuator,/mcp,/.aws/credentials,/.git/config,/shell.php. The/.envrequests hit the Tracebit integration: 10 attempts minted (farm 4, aidev 2, control 2, ru-edge 2 — all via loopback-host paths), 21 drew upstream 400Bad Request, and a furtherwebshell-probeon/shell.phpreturned the keyless 200. The loopback-facing rows (Host: 127.0.0.1, 119 events fleet-wide) look like the same script probing each node's local interface through a reverse proxy or from the node itself. - Assessment: Ten unattributed credentials entered hostile hands in one hour, and the wave repeated hourly on some nodes through 08:54. The probe list reads as a hand-written health-check of every trap family — or an operator rehearsing the fleet's own validation set. Two follow-ups matter: whether the wave repeats next window, and whether any of the 12 credentials shows up in AWS (the fleet's cheapest attribution test).
Standing actors (persistence check)
- 80.94.95.211 (SS-Net, RO) — tenth window in eleven: aidev, 51 events, 49 paths, 1 mint at 02:32 UTC under the iPhone Safari/5.1 forgery. The cadence is exactly 51 events and 1 mint for a fifth consecutive day. The actor holds 13 all-time mints with zero observed use.
- 89.248.172.33 / 93.174.93.12 / 89.248.172.11 — uptime-prober set, present and
/-only:.3336 events (18 per node), 93.174.93.12 28 events,.111 event. Benign-shape. - 16.5.0.236 (
Hello WorldUA) — returned on both EU nodes, 11 events,/-only. Benign-shape. - 3.129.187.38 (
visionheight.com/scan) — absent this window. The actor's fifth consecutive day would have landed in №17. The actor is now idle. - CyberConvoyScout/1.0 (45.77.61.56) — returned on both EU nodes at 00:05 and 06:00 UTC,
/-only, 10 events. Benign-shape. - 193.24.123.123 — the №17 tarpit-ramp watch item ran 37
/-only tarpit events on canary-farm-1 through 07:42 UTC, then stopped. Still no credential paths. Keep the actor on watch. - 176.65.148.71 (Chrome/124 forgery) — fifth visit since 09-01, both EU nodes, the two-request
/.env+/.env.jsonpair each time, 3 all-time mints. Now a 4-window pattern. Treat as a standing single-purpose collector. - Single-
/.envmint collectors: 217.60.76.167 (1 mint at 04:57, first-ever appearance) and 43.228.157.228 (1 mint at 06:12, first-ever; sibling of the watched 43.228.157.68). Both overlap-window events. - Absent this window: 45.148.10.238 (fourth), 91.245.74.31 (fourth), 160.178.89.73 and 160.177.217.115 (NIGHTAGENT idle), 35.233.85.98 and 207.175.64.93 (XMLRPC-BRUTE silent — second consecutive), 94.154.46.242/.243/.245/.248, 176.65.144.71, 213.209.159.154, 204.76.203.18, 43.228.157.68 (second no-run), 159.26.110.179, and MEVSPACE-GITWALK's both operators.
Canary credentials
Summary
No canary credentials were used in AWS during the window. Fleet sensors minted 86 credentials to 19 collector IPs. None reached AWS.
Mint → use funnel
| Metric | Count |
|---|---|
| Credentials minted (fleet, window) | 86 |
| Distinct collector IPs | 19 |
| Credentials used in AWS (alerts) | 0 |
| Credentials stolen, no observed AWS use in window | 86 |
Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):
| Theft IP | Sensor | Mints (window) | Creds used in AWS | Use IPs | Operations | Mint history (6d) |
|---|---|---|---|---|---|---|
34.32.131.244 |
ai-devbox-1 | 25 | 0 | 0 | — | 25 mints since 2026-09-11 21:44 |
94.154.46.249 |
canary-farm-1 | 12 | 0 | 0 | — | 12 mints since 2026-09-11 13:47 |
94.154.46.246 |
ai-devbox-1 | 10 | 0 | 0 | — | 10 mints since 2026-09-12 04:12 |
136.70.175.146 |
canary-farm-1 | 4 | 0 | 0 | — | 4 mints since 2026-09-12 06:33 |
160.177.217.115 |
ai-devbox-1 | 2 | 0 | 0 | — | 4 mints since 2026-09-11 21:02 |
160.177.217.115 |
canary-farm-1 | 2 | 0 | 0 | — | 4 mints since 2026-09-11 21:02 |
167.99.79.44 |
ai-devbox-1 | 2 | 0 | 0 | — | 12 mints since 2026-09-08 19:11 |
167.99.79.44 |
canary-farm-1 | 2 | 0 | 0 | — | 12 mints since 2026-09-08 19:11 |
91.92.47.27 |
canary-farm-1 | 2 | 0 | 0 | — | 2 mints since 2026-09-11 18:55 |
139.59.143.102 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-09 21:48 |
159.65.18.197 |
ai-devbox-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-06 20:35 |
159.65.18.197 |
canary-farm-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-06 20:35 |
159.89.12.166 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-06 20:30 |
165.227.173.41 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-11 20:20 |
167.71.81.114 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-09 22:04 |
176.65.148.71 |
ai-devbox-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-06 18:50 |
207.154.197.113 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-07 20:28 |
213.209.159.175 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-10 22:43 |
217.60.76.167 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-12 04:57 |
43.228.157.228 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-12 06:12 |
64.23.218.208 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-11 20:36 |
80.94.95.211 |
ai-devbox-1 | 1 | 0 | 0 | — | 8 mints since 2026-09-06 08:36 |
(no clientIp recorded — the 09-12 curl/8.5.0 loopback mint batch) |
4 sensors | 12 | 0 | 0 | — | 12 mints since 2026-09-12 08:14 |
Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):
104.196.118.131: 25 mints, 2026-09-06 03:25 → 2026-09-06 03:25136.67.37.69: 25 mints, 2026-09-08 19:55 → 2026-09-08 19:5534.22.137.199: 25 mints, 2026-09-07 17:26 → 2026-09-07 17:2634.32.131.244: 25 mints, 2026-09-11 21:44 → 2026-09-11 21:4434.6.12.67: 25 mints, 2026-09-09 09:09 → 2026-09-09 09:0934.83.24.21: 25 mints, 2026-09-07 05:10 → 2026-09-07 05:1035.252.125.133: 25 mints, 2026-09-08 18:51 → 2026-09-08 18:52(no clientIp recorded — the 09-12 curl/8.5.0 loopback mint batch): 12 mints, 2026-09-12 08:14 → 2026-09-12 11:11167.99.79.44: 12 mints, 2026-09-08 19:11 → 2026-09-11 18:1994.154.46.247: 12 mints, 2026-09-06 19:02 → 2026-09-06 19:0294.154.46.249: 12 mints, 2026-09-11 13:47 → 2026-09-11 13:4894.154.46.245: 10 mints, 2026-09-10 16:25 → 2026-09-10 16:2594.154.46.246: 10 mints, 2026-09-12 04:12 → 2026-09-12 04:1394.154.46.248: 10 mints, 2026-09-08 07:51 → 2026-09-08 07:51136.85.12.249: 8 mints, 2026-09-05 09:28 → 2026-09-05 09:2880.94.95.211: 8 mints, 2026-09-06 08:36 → 2026-09-12 02:3245.148.10.238: 6 mints, 2026-09-05 20:43 → 2026-09-07 08:16102.220.161.87: 4 mints, 2026-09-07 23:07 → 2026-09-09 13:44136.70.175.146: 4 mints, 2026-09-12 06:33 → 2026-09-12 06:33139.59.136.184: 4 mints, 2026-09-05 20:41 → 2026-09-10 20:35142.93.129.190: 4 mints, 2026-09-07 20:16 → 2026-09-10 20:23160.177.217.115: 4 mints, 2026-09-11 21:02 → 2026-09-11 21:43176.65.144.71: 4 mints, 2026-09-09 21:56 → 2026-09-09 21:56185.141.119.179: 4 mints, 2026-09-05 10:17 → 2026-09-05 10:2631.57.219.158: 4 mints, 2026-09-06 13:11 → 2026-09-06 13:23159.65.18.197: 3 mints, 2026-09-06 20:35 → 2026-09-11 20:40176.65.148.71: 3 mints, 2026-09-06 18:50 → 2026-09-12 06:16209.97.180.8: 3 mints, 2026-09-05 20:42 → 2026-09-09 14:3541.140.11.235: 3 mints, 2026-09-08 06:34 → 2026-09-08 06:4584.21.173.161: 3 mints, 2026-09-06 22:19 → 2026-09-07 13:0091.245.74.31: 3 mints, 2026-09-05 09:48 → 2026-09-06 21:30
Canary-use attribution (briefing prose)
The funnel stayed closed for a fourth consecutive window: 86 mints to 19 collectors, zero AWS calls. Mint volume moved up from №17's 75 because the METADATA-HUNT aidev runner batched 25 again and the OMEGA operators contributed 22. The window's most consequential mints are the 12 with no recorded collector IP — 10 from the curl/8.5.0 wave and 2 from the control-1 census crawler. Those 12 credentials are hostile-held inventory with no attribution path in flux logs. If Tracebit fires on any of them, the use IP becomes the only source evidence. The 159.26.110.179 credentials remain outside the 6-day history with no recorded consumption. The upstream 400 rejection pattern from №17 continued (59 failure events this window), so the collector-hoard totals undercount what the operators requested — treat every mint count as a floor.
Fleet Observations
- Canary economics: Digest-window mints 87 (farm 32, aidev 49, control 4, ru-edge 2) to 27 minting attempts' worth of IP groups. The raw-wall-clock canary section trims to 86 mints and 19 collectors. Mint failures 59, all
400 Bad Requestupstream rejections — farm 31 (21 from the 136.70.175.146 burst, 6 from172.18.0.1loopback curls, 4 from the loopback curl wave), aidev 10 (5 loopback curl wave + 5172.18.0.1), control 18 (13 curl/8.5.0 wave, 4 census crawler, 1 burst crawler), ru-edge 0.172.18.0.1is the Docker bridge gateway — the wave's loopback pass reached the traps through the node's own bridge interface, which is why those rows carry a real client IP and the direct ones do not. - XFF forgery: 50 multi-entry chains, all 50 on control-1, one per IP, all in the recovery segment's has-IP rows (the 50 single-event IPs that hit
tarpit-module/env-productionat 07:59–09:47). Farm and aidev carried 405 single-entry XFF rows and zero multi-entry. No all-internal127.0.0.1rows — the fleet-side fix held. - TLS/attribution posture: Farm served 202 https events (384 Host-header hits on
sso.rightabouteverything.showvs 3,868 on the bare IP), aidev 189 https oninference.fapthropic.com(368 vs 3,012). Control, ru-edge, netcup, sponge, frantech: 0 https, as designed for the certless nodes. - Volume: Digest window 9,934 events on the three canary nodes (farm 4,314 −14%, aidev 3,419 −84%, control 1,813). The aidev −84% is baseline distortion — the 7-day mean still carries the 50,112-event CRUSADER-SWEEP class B day. Control's 1,813 is the recovery segment only. The four no-canary nodes logged 648 events combined, their first digest appearance, all of it from the new-window segment.
- Control discovery velocity: The ramp row for 2026-09-12 is 1,813 events / 51 unique identities, but the cell covers only 4 hours of node uptime, not 24. Compare to the 08-30 cell (3,186 / 70, first full day) rather than the recent full-day cells. Series for the record: 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120 → 110 → 78 → blind → blind → blind → 51 (4-hour cell).
- Result-tag spikes: Every spike attributed. aidev
ssh-private-key-error70 = 94.154.46.246 (54) + 34.32.131.244 (16);app-config-python41 = .246 (40) + 34.32.131.244 (1);firebase-json27 = 34.32.131.244 (25) + .246 (2);rails-database-yml24 = .246 (22) + 34.32.131.244 (2) — all four are OMEGA/METADATA overlap-window runs. control-1env-production-error213 = the census crawler (207) + 6 single-IP recovery rows;phpinfo-error36 = census crawler (36). The frantech/netcup/ru-edge/sponge "infx" spikes are first-window baselines, not anomalies. - Digest quirks (all re-checked this run): control-byte-stripped copy needed for UTF-8 reads; +4 h timestamp cast (this cycle it matters more than usual — see the attribution gap below); single-writer DuckDB lock (spot queries ran sequentially); sync-arrival first-seen stamps; window overlap with №17 cross-checked before counting anything new. New quirk this cycle: control-1's log file was replaced, not appended, during recovery — the node-side buffer holds only 07:59 UTC onward, and an
env-canary.jsonl~backup holds a 94-row duplicate of the file's first rows. The digest's*.jsonlglob excludes the tilde file, so no double-count, but any query that globs/data/flux-logs/control-1/*directly will double-count. - Attribution gap (new, needs an ops-repo fix): 2,673 window rows carry an empty
clientIp— 1,763 on control-1 (97% of the node's rows), plus every row on the four no-canary nodes and the curl-wave rows on farm/aide/ru-edge. The empty-IP rows carry noX-Forwarded-FororTrue-Client-Ipheader at all, so this is not the pre-2026-08-30 XFF poisoning returning. The requests reach flux without any source-identifying header, and flux logs what it sees. Until the nodes record the socket peer for headerless requests, three active campaigns are unattributable. - Infrastructure: control-1's sync succeeded this cycle after three failures (the only permitted node action,
systemctl start flux-log-sync.service, was run by the node's own recovery — no fleet-side change from this workflow). The Tracebit canary-section script crashed on NULL collector IPs in the 6-day history sort. The fix is in place (kv[0] or "") and changes no other behavior.
Gaps / Next Collection
- Socket-peer logging for headerless requests. The empty-
clientIprows carry zero forwarding headers, so no proxy chain ever touched them. A node-side change to log the connection peer (or at leastREMOTE_ADDR) for requests without client headers would attribute ENV-CENSUS-2, CURL-SWEEP, and the ru-edge WP-ENUM run in one stroke. This belongs in the ops repo, not on this host. - The 12 unattributed mints. Check Tracebit alerts against the full mint history daily: if the curl/8.5.0 wave's 12 credentials show any AWS call, the use IP becomes the only evidence of who ran the wave. Also re-check the control-1 census mints outside the flux window.
- CURL-SWEEP recurrence. One wave, one window, 7 nodes. A repeat on schedule means automation. If the
/.envrequests stop minting (Tracebit quota or upstream 429s), expect the operator to shift paths. Watch for a secondcurlversion bump — the frantech second pass usedcurl/8.18.0. - ENV-CENSUS-2 spread to the EU nodes. The census has hit control-1 and sponge-01-ts. The same 195-path core list with control-byte suffixes on farm or aidev would make it a four-node campaign. Check for empty-IP rows with
env-productionresponses on the EU nodes next cycle. - control-1 recovery integrity. The node's prior 15 days of log data are gone from medina (digest copies only). Before the next run, make sure the node's local buffer grows rather than resets: compare
wc -lof the synced file against this cycle's 1,813. A second reset means the sync path truncates, not appends, and every control cell is a window, not a day. - WP-ENUM third-generation spread. The template now spans three nodes and two basins. A fourth node, or a mint from any run, makes the operator pool real. Check whether 45.156.129.136 (the №8 original) rejoins — its block sits one octet from the 128.x cluster.
Generated on medina (headless systemd run, rerun cycle). Digest: /data/flux-logs/reports/flux-digest-2026-09-12.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, plus 25 ad-hoc v_full queries (control-1 recovery profile, empty-clientIp census across sensors, CURL-SWEEP probe-set comparison, control-byte .env wordlist overlap, WP-ENUM readme wordlist joins, spike attribution per tag, standing-actor persistence, mint-failure attribution, loopback-host inventory) and the Tracebit canary-section generator.