Investigated recent Telegram alerts - no intrusion, both new hits trace to benign one-offs: calibre's linuxserver.io s6-init NOPASSWD setup (same pattern already whitelisted for obsidian) and lsyncd truncating its own status log (not evidence-clearing).