OPERATION INDEXOP-001 / July 20 - August 20, 2026
OPERATION

TARGET SET03 FRONTS
01CitadelIDENTITY /
02BastionIDENTITY /
03VanguardIDENTITY /
DISCLOSUREHigh-impact zero-day researchHybrid human / Proteus
OPENING BRIEF

A high-impact zero-day research operation combining independent human analysis with Proteus-assisted source mapping, validation and attack-chain development across three complex software systems.

This page records only information safe for public release. It does not expose active hypotheses, report details or unpatched behavior.

TARGET MATRIX / IDENTITIES WITHHELD

THREE INDEPENDENT RESEARCH FRONTS.

FRONT / 01

Citadel

System boundaries / enterprise services

PUBLIC IDENTITY / 03 FINDINGS
FRONT / 02

Bastion

Access boundaries / analysis workflows

PUBLIC IDENTITY / 03 FINDINGS
FRONT / 03

Vanguard

Runtime behavior / application resilience

PUBLIC IDENTITY / 02 FINDINGS
PUBLIC SCOPE

RESEARCH SURFACES

  1. 01Repository and collaboration surfaces
  2. 02Automation and CI/CD workflows
  3. 03Identity and authorization boundaries
  4. 04Enterprise-facing integrations
RESEARCH DIRECTIVES

OPERATING RULES

  1. D-01Prioritize cross-boundary behavior with realistic attacker reachability.
  2. D-02Validate impact against documented product behavior and supported configurations.
  3. D-03Keep active hypotheses and disclosure-sensitive details outside the public log.
REPORTED FINDINGS / DETAILS CONTROLLED

FINDING REGISTER

01 CRITICAL02 HIGH05 MEDIUM
ACR-001
CITADEL / SERVER COMPROMISE / COMPLEX CHAINCRITICAL

Sophisticated server compromise chain

A critical multi-stage chain with system-level impact was reported. Technical details remain restricted during coordinated disclosure.

DUPLICATE
ACR-002
CITADEL / SSRF / FILE DISCLOSURE / COMPLEX CHAINHIGH

File disclosure via SSRF chain

A high-severity multi-stage chain resulting in restricted file disclosure was reported. Technical details remain restricted during coordinated disclosure.

IN REVIEW
ACR-003
CITADEL / APPLICATION-LAYER DOSMEDIUM

Authenticated application-layer DoS

A medium-severity availability issue reachable by an ordinary authenticated user was reported. Technical details remain restricted during coordinated disclosure.

IN REVIEW
ACR-004
VANGUARD / SERVER OOM / UNAUTHENTICATEDHIGH

Unauthenticated server OOM

A high-severity server availability issue reachable without authentication was reported. Technical details remain restricted during coordinated disclosure.

REPORTED
ACR-005
BASTION / ACCESS CONTROL / DATA EXPOSUREMEDIUM

Unauthenticated analysis-data exposure

A medium-severity access-control issue exposing restricted analysis data was reported. Technical details remain restricted during coordinated disclosure.

REPORTED
ACR-006
VANGUARD / ACCESS CONTROL / CONTENT EXPOSUREMEDIUM

Unauthenticated protected-content exposure

A medium-severity access-control issue exposing protected server-rendered content without authentication was reported. Technical details remain restricted during coordinated disclosure.

REPORTED
ACR-007
BASTION / CI/CD / DEPLOYMENT INTEGRITYMEDIUM

Protected deployment integrity issue

A medium-severity CI/CD integrity issue affecting a protected deployment workflow was reported. Technical details remain restricted during coordinated disclosure.

REPORTED
ACR-008
BASTION / CI/CD / TRUST BOUNDARYMEDIUM

Cross-group CI trust-boundary issue

A medium-severity cross-boundary CI/CD trust issue affecting protected jobs was reported. Technical details remain restricted during coordinated disclosure.

REPORTED

Titles describe only the broad impact area without naming affected products or exposing reproduction details.

CHRONOLOGICAL RECORD

OPERATIONAL LOG

12 public entries / latest first

12
UPDATE

Operation Acheron concluded

Active research under Acheron has ended. The operation now awaits program results and coordinated disclosure outcomes while the next operation is planned.

11
UPDATE

Two Citadel reports advanced to program review

The Citadel file-disclosure chain and application-layer denial-of-service report advanced to program review. Technical details remain restricted while assessment continues.

10
REPORT

Cross-group CI trust-boundary issue reported

The Bastion front produced a medium-severity cross-boundary CI/CD trust issue affecting protected jobs. Technical details remain restricted during coordinated disclosure.

09
REPORT

Protected deployment integrity issue reported

The Bastion front produced a medium-severity CI/CD integrity issue affecting a protected deployment workflow. Technical details remain restricted during coordinated disclosure.

08
RESULT

Server compromise chain marked duplicate

The Citadel server compromise chain was marked as a duplicate. Publication of Vyntra's exploit variant and technical writeup will wait until the original issue is patched.

07
REPORT

Sophisticated server compromise chain reported

The Citadel front produced a critical multi-stage server compromise chain with system-level impact. Technical details remain restricted during coordinated disclosure.

06
REPORT

Authenticated application-layer DoS reported

The Citadel front produced a medium-severity application-layer denial-of-service issue reachable by an ordinary authenticated user. Technical details remain restricted during coordinated disclosure.

05
REPORT

Unauthenticated server OOM reported

The Vanguard front produced a high-severity server out-of-memory issue reachable without authentication. Technical details remain restricted during coordinated disclosure.

04
REPORT

File disclosure via SSRF chain reported

The Citadel front produced a high-severity multi-stage SSRF chain resulting in restricted file disclosure. Technical details remain restricted during coordinated disclosure.

03
REPORT

Unauthenticated analysis-data exposure reported

The Bastion front produced a medium-severity access-control issue exposing restricted analysis data without authentication. Technical details remain restricted during coordinated disclosure.

02
REPORT

Unauthenticated protected-content exposure reported

The Vanguard front produced a medium-severity access-control issue exposing protected server-rendered content without authentication. Technical details remain restricted during coordinated disclosure.

01
UPDATE

Operation Acheron opened

The scope and research heuristics were defined, and construction of the Proteus research corpus began under operation identifier OP-001.

PUBLIC OUTCOMES

NO RELEASED RESULTS YET.

Public CVEs, advisories and writeups will be linked here after disclosure.

VYNTRA RESEARCH