Audit run, 2026-07-26
Full report: docs/audits/2026-07-26-weekly-quality-audit.md.
Scope and method
Window 2026-07-18T12:08Z → 2026-07-26T13:08Z (~193 h), anchored at the last audit that actually audited, the 2026-07-19 audit record stood down as a duplicate at a 25 h gap and covered nothing. Audited 57 published entries (43 operational, 14 W29 weekly strategic), carrying 10 distinct run ids, across the 11 run records whose start timestamp falls inside the window. Four retrospective truth passes fetched ~181 primary and authority URLs; three coverage re-sweeps re-researched the window independently. July's monthly priority-calibration duty was already discharged by the 2026-07-18 report, so no calibration section appears in this one.
Soundness
32 of 57 entries fully clean. No machine-surface defect survived review. Stating the artifact accurately: three of the four batches recorded machine_surface: false on all 43 of their records, including their 20 non-clean ones; the fourth wrote the field with inverted polarity and is unusable as reported, so the audit reviewed its one non-clean record directly and rejected it, because the entry concerned carries no CVE records at all. Every CVE id and CVSS matched its owning authority, every ATT&CK id checked is active in the pinned v19.1 dataset, every registry key resolves, no indicators leaked. Zero hallucinated facts and zero broken URLs.
Three factual errors. One is defender-consequential and is corrected by a published update this run: the 2026-07-22 Langflow entry advised upgrading to 1.10.1, which leaves CVE-2026-14499 (CVSS 8.8, authenticated command injection) open (the vendor bulletin names 1.10.2) and it attached an AUTO_LOGIN precondition and a "no version patch" status to CVE-2026-0770 that the discloser's own advisory contradicts. The audit re-verified both legs directly against the vendor bulletin and the discloser's advisory before correcting. The other two are attribution errors in W29 strategic entries where the underlying facts are true.
The other 22 findings are precision defects. The largest single group (9 of those imprecisions plus 2 of the 3 factual errors, 11 in all) is one class: a true fact cited to a co-cited source that does not carry it. That class is now the dominant residual defect in the pipeline, present in operational entries and the weekly alike, and it survived verification loops of three to eight iterations because those loops confirmed the fact was true rather than that the cited page said it. The remaining 10 split between version-boundary and scope precision (six) and novelty or quote-fidelity precision (four).
The clean rate is lower than the previous audit's, and part of that is measurement rather than regression: three of four passes ran on Opus 5 at maximum scrutiny against a 2:2 split last time, and the adjacency standard applied is stricter than earlier passes enforced. Every batch independently found the same class, which is evidence about the pipeline rather than about one verifier.
No in-place repairs were warranted, nothing in the window touches the narrow metadata class the immutability exception covers. One verifier proposed a machine-surface repair; the audit checked and rejected it, because the entry in question carries no CVE records at all, so nothing propagated to a machine surface.
Completeness
Nine genuine gaps, all recovered and published here through dedup, the mechanical gate and the verification loop.
The most serious: the WordPress WP2Shell chain moved to confirmed in-the-wild exploitation and was added to the CISA catalog on 2026-07-21, and no entry recorded the change, while the store's existing entry says in its own words that there was no confirmed exploitation. The 2026-07-22 fire saw that catalog batch and correctly published a different vulnerability from it, then dropped the WordPress pair on two compounding errors: it applied a rule about foreign-jurisdiction remediation deadlines to the exploitation-confirmation flag, which the same rule defines as operational signal; and it justified the drop by asserting the vulnerabilities were already reported as exploited, which its own prior entry contradicts, a decision made against a remembered entry rather than a re-read one. That fire's own verifier flagged the gap and the drop reasoning overrode it. Both causes are fixed in this run's prompt changes.
Two more were follow-through failures on stories the pipeline was already tracking rather than discovery failures: Romania's national cybersecurity authority published an interim technical report that supersedes the "databases not affected" position the store carried on the ANCPI land-registry attack, confirming roughly two million exfiltrated payment-platform user records and a virtualization-plane intrusion; and the Geneva adult-education institute's stolen data was actually published, including student examination results the institute had said were unaffected. Both are Swiss- or Europe-relevant public-sector stories with an open clock that nothing re-checked.
The rest: a malvertising campaign that hosted its lure page on a vendor's own trusted domain and hit at least 29 organisations; an exposed delivery lab showing industrialised shortcut-and-WebDAV lure testing; a Joomla extension flaw where one anonymous request becomes full administrator on an internet-facing site; the unauthenticated maximum-severity concentration in Oracle's July middleware release that two national authorities escalated; and a government-espionage toolkit whose final implant decrypts only on the target machine.
Seven further items were examined and correctly dropped, each with its reason recorded in the report, a catalog addition over already-exploited ground, a vulnerability needing a non-default configuration, a municipal ransomware case with no attacker-behaviour content to describe, a vendor naming-taxonomy announcement, a strategic assessment belonging to the weekly rather than an intel run, an uncorroborated wave of criminal claims against French government platforms, and a political doxing assembled from older breaches. Two of those became watch items rather than clean drops.
One judgement was reversed during the audit: the government-espionage toolkit was initially set aside as out-of-nexus, then published, because the previous audit recovered a materially identical case and no principled distinction separated them. The reversal is recorded because it is more useful to the next audit than a tidy verdict.
Machinery
Two fixes shipped last week are measurably working. The verifier iteration-cap raise turned the fail-open from the common path into the exception: seven of ten fires since it landed reached a genuine two-model confirmed agreement, and the single waiver in this window was not a cap problem at all. The weekly citation-date duty eliminated its target defect outright, every one of 52 citation dates in the W29 batch matches its source's own publication metadata, against nearly every entry drifting a week earlier. That same fix had a second half about per-fact attribution which did not move at all, and the contrast between the mechanically-checkable half working completely and the judgement-call half not moving is the clearest evidence in this audit for how to fix the dominant defect class: mechanise it, on both the composing and the verifying side. Both are done in this run's prompt changes.
One rule was found dead on arrival. The source list documents promoting a candidate source to active after three contributing runs, but nothing ever counted, and a single fire cannot remember earlier fires, so eleven candidates sat unpromoted, one of them cited by entries from eleven separate runs. Because candidate records are also absent from the digest list the fires build their slices from, a newly added candidate is effectively unreachable, which is why the previous audit's own new source (added specifically to close the discovery gap behind its WP2Shell miss) was never fetched once in eight runs. Fixed at the root: the state digest now computes the count, acting on it is a preflight duty, candidates rotate explicitly, and all eleven are promoted here.
Source health surfaced a concrete instance of reachability not meaning readability: an essential source probes green because the health tool uses a working feed recipe that exists only inside that tool, while the record points at an HTML listing the CDN refuses, so two fires logged failures against a record that looked healthy. The feed is now on the record, and two other recipe corrections ship with it.
The reader pool of last resort was exhausted for four consecutive days and was refilled by the operator about twenty minutes before this audit fired. That outage is the direct cause of one national-CERT source going unreachable mid-window. It is now healthy, but this is the second refill in nine days and each has lasted about five days, which is an operator decision about funding and monitoring rather than something the audit can fix.
Content-safety classifier trips on sub-agent spawns are now a recurring reality rather than a one-off: they cost one fire its entire model rotation, three of four research spawns and its deep-reads, and they cost this audit two spawns for one batch. The existing handling (retry, then fall back and record the exception) is correct and worked both times, so no rule changes; the mitigation that got the batch through is recorded in memory instead, along with the warning not to misread a uniform-model verifier chain as a rotation failure.
Telemetry is otherwise clean. No runaway runs against the three-hour threshold. Publish follow-through complete across all eleven in-window records. Gap-derived windows self-healed across every fire including two off-cadence gaps, with no coverage hole between them. Discipline held or improved: action items sit at 38 empty of 57 entries with none above two, every entry carries a valid reliability rating, empty technique mappings appear only on the two kinds that legitimately allow it, and the high-priority share continued its deflationary trend. The 26-day gap without a critical-priority entry was checked against the window's real exploitation pressure and reflects the bar rather than under-alerting.
Zero-warning sweep
The store-wide check ends 0 warn · 0 fail · 9 acknowledged and the site build emits no self-check warnings. One acknowledgment was added, for the fire whose confirming verification pair ran on the same model because every alternate-model spawn was blocked by the content classifier after a retry: the run recorded that exception as policy requires, both passes were genuine independent confirmations, and the record is immutable. A code change that auto-passed this shape whenever a waiver is present was considered and deliberately rejected; it would let any future run silence the rotation check by writing its own waiver, which is precisely the self-serve exemption the discipline forbids. No acknowledgments were pruned; all nine still silence a live warning.
Notes
- Recovered entries and their sourcing posture: seven multi-source, two single-source with the value set and a sourcing note naming the situation (the Joomla extension batch, where the discloser is the only publisher and withholds proof-of-concept detail; and the espionage toolkit, whose originating lab is the sole source and labels the post part one of a series).
- Single-source carve-outs: none of the nine relies on a national-CERT or victim-own-disclosure carve-out.
- Reduced-confidence inclusions: two entries carry
confidence: medium, the Geneva incident (the publication event rests on one Swiss outlet relaying another) and the Joomla batch (no independent corroboration yet). - Out-of-window handling: the Oracle release advisory predates the window; the entry anchors on the two in-window national-CERT advisories and records the earlier vendor date explicitly, so it makes no false freshness claim. The corrected Langflow record likewise carries the vendor bulletin's own mid-July date.
- Borderline drops are enumerated with reasons in the report's completeness section rather than repeated here.
- Non-update decision, confirmed deliberate (the gate asks for this confirmation, and it is the only warning this run leaves standing): the Joomla recovery shares the tracked extension-wave entity with a W29-preceding weekly synthesis entry, but it ships as a new entry rather than a delta. It is a distinct technical finding (a cookie-forgery authentication bypass reaching full administrator, not the file-upload pattern the tracked wave describes) on a different extension, with six CVE identifiers none of which appear in prior coverage. The prior operational entries in that series cover individual file-upload flaws that this one neither supersedes nor extends, and an intel-class entry never posts a delta against a strategic synthesis entry in any case. The shared entity key is what groups them for the reader at render time, which is the intended mechanism. The warning cannot be cleared without making a wrong update decision, and a run never self-acknowledges its own fresh warnings, so it stays visible with this explanation.
- Coverage gaps: three research publishers could not be read this run; one blog is JS-rendered and returned no article content on either the bridge or the reader, one feed transport is broken with nothing found by search either, and two feeds are dead but were recovered via their HTML listings. Two further listings need canonical-path updates. None cost a recovery this window; all are logged in the G3 findings file for the next fire's rotation.