Verification & coverage notes
This run was suspended mid-pipeline for roughly three days and was overtaken. Read the rest of these notes in that light. The fire started 2026-08-21T04:10:40Z and completed its research, composition, mechanical gate and one verifier iteration inside 93 minutes. The container was then suspended; the session resumed on 2026-08-24, with real elapsed time at ~76.8 h. duration_seconds records that honestly and will trip the runaway-duration warning — it is a telemetry fact about this fire, not drift to fix.
What the overrun cost, and what was done about it. Scheduled fires on 2026-08-23 (intel and weekly) and 2026-08-24 (weekly) published while this run sat mid-pipeline. Per the overtaken-run rule, origin/main was re-fetched before any commit and every not-yet-committed candidate was re-deduplicated against what those fires published. Six of the eleven composed entries were removed as duplicates:
- the Defender boot-time remediation driver research — the 2026-08-23 fire published it as
2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive - the three Russian-nexus authentication-abuse clusters — published as
2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking - the crates.io build-script supply-chain attack — published as
2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk - the SPECTRE / kernel-callback-unlinking implant — published as
2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink, with the agentic-AI half as a second entry - the TrueConf Server exploitation chain — published as
2026-08-23/trueconf-server-kev-head-mare-trojanized-installer - the Berlin state-network compromise — carried by that fire as a strategic synthesis,
2026-08-23/weekly-w34-berlin-landesnetz-nine-days-no-vector
On Berlin specifically, the later fire made the better call and this run defers to it. This run published an operational incident entry mapping a spearphishing attachment and user execution, on the strength of a wire agency citing unnamed security circles. The 2026-08-23 fire, working the same story three days later, declined to publish an operational entry at all and said why: no named authority had stated a vector, an unattributed source describes no attacker behaviour to map, and it "maps no ATT&CK technique rather than invent one" — carrying the incident as a synthesis entry instead, which is exactly the disposition the original backlog row had suggested as the alternative. That is the more disciplined reading of the same evidence, and it is now the published one. The registry keeps only that fire's entity key for the incident; this run's duplicate key was dropped rather than left as a second key for a known entity.
The four surviving entities and the state rebase. Because the later fires had already registered their own keys for all six dropped topics, entities/registry.yaml, state/cves_seen.json, state/source_health.json, sources/sources.json and state/coverage_backlog.md were each rebased on origin/main and only this run's still-needed additions re-applied — four entity keys, thirteen ATutor CVE records plus one bumped last_seen, one new candidate source, and one backlog row. That avoids both duplicate keys and the deletion of the later fires' records that a blind ours-wins resolution would have caused. Two source changes this run had made independently — promoting the Latvian national CERT to active, and migrating both NCSC-CH records to the new bacs.admin.ch domain — turned out to have been made identically by a later fire, so main's versions stand.
What actually publishes: five entries, four of them updates. One new entry (the ATutor disclosure) and four updates (ShieldBreak's independent reproduction, the ITG27 Havencode/Toneshell delta, the ZeroBytes French-government footprint, and the Siemens S7 advisory's own detection and hardening sections read from the primary PDF). All five were checked against the later fires' output and none is covered by them. Priorities: one notable × five — no high, no critical, which is the honest reading of a delta set this narrow.
Verification. One iteration, on Opus, verdict NEEDS_FIXES (truth 3, editorial 4, advisory 5), run against the full eleven-entry set before the reconciliation. It fetched all 31 inline source URLs fresh, tested all 33 evidence quotes as literal contiguous substrings — all 33 passed — and upheld every judgement call it was asked to challenge, including both contested drops. Two of its three truth findings applied to surviving entries and were fixed: an ATutor CVE typed as information disclosure where the advisory describes permanent deletion of an administrator's data, and a wrong parameter name on another ATutor CVE. The third applied to an entry the reconciliation removed and is recorded on the iteration rather than lost. Its editorial finding on the ShieldBreak entry — a "roughly ten seconds" figure no source states — was also fixed to the source's eight-to-twelve-second range. No confirmation pass ran: the double-CLEAN gate is waived under the wall-clock watchdog, with the reason recorded in verification.confirmation_waived.
The verifier's headline finding was completeness, and it stands as an open item rather than a fixed one. An in-window, pre-authentication file-upload-to-remote-code-execution flaw in very widely deployed WordPress tooling was deferred to the coverage backlog on the ground that its fields were unobtainable — the article body is unreachable on every transport here and the feed carries only a teaser. The verifier established that the flaw carries CVE-2026-32475 and that both the CNA's own research post and the ENISA vulnerability API — transports this run used successfully elsewhere — carry every missing field, and separately corrected this run's framing: for that item the assigning CNA and originating discloser is Patchstack, not the publisher this run added as a candidate. It was still not published, deliberately: by the time the finding could be acted on the run was ~76 h overrun and two later fires had published. The backlog row is upgraded with the CVE id, the reachable transports and the Patchstack correction so the next fire lands it directly. Patchstack is untracked and could not be added under the one-candidate-per-run cap; it is named in the row.
A capability gap closed, and the bug a real document found. The 2026-08-20 fire published the Siemens S7 joint advisory from an outlet's reading because the advisory ships as a PDF only, nothing here could extract PDF text, and its backlog row asked a later fire to record a working extraction path in the fetch bridge. That is done: the bridge gained a stdlib-only PDF text extractor covering Flate content streams, PDF string-escape and nesting rules, simple fonts and CID fonts via their ToUnicode CMap, with an offline test suite and two deliberate honesty properties — an image-only PDF reports that it found no text objects rather than looking like an empty document, and a CMap-approximated decode is labelled an approximation. Reading the real 333 KB advisory then found a genuine bug in it: a marked-content property dictionary was being mis-parsed as a hex string. Fixed, with a regression test. The advisory yielded 62,519 characters and carries detection and hardening detail no prior entry had, which is why the S7 update survives the dedup.
Composition and window, as researched. Gap of 24.0 h to 2026-08-20T0409Z-intel at the time of research, so a 26 h window — Standard class. The research itself was sound and is not in question: four domain sub-agents plus two scoped Phase 4 deep-read follow-ups, and those follow-ups caught six defects before the verifier ever saw them, including a CVE scoped to one package presented as covering three, a download figure conflating one package's count with a family total, an enumeration that silently dropped one of thirteen CVEs, and — the most consequential — the establishment, by following a citation chain to its source rather than trusting a summary, that no source attributes the Bloctel breach to the actor behind the two other French government intrusions and that no source states a unified investigation across all three. Both of those claims were in the surfacing pass; neither is in the published entry.
borderline-drop lines (as judged at research time, all still standing).
borderline-drop: Operation ASTERIX (fake hardware-wallet applications, seed-phrase theft) — no home-region, coverage-focus or sector nexus; the victims are individual cryptocurrency holders.borderline-drop: mercenary-spyware notification volume across 110 countries — a count with no named spyware family, no attack vector and no defender takeaway.borderline-drop: Cisco Crosswork and Secure Workload hardening releases — internally discovered, not known to be exploited; the routine-patch-cycle exclusion, and the store already published this grouped-hardening-release pattern on 2026-08-08. Both advisories were fetched before the drop; the verifier upheld it.borderline-drop: extortion ultimatum against a Swiss-headquartered manufacturer, deadline 2026-08-21 — leak-site claim only, no victim statement, no samples. The verifier upheld it. NOTE: the deadline has since passed and no later fire appears to have revisited it; worth a look.borderline-drop: three further leak-site listings naming a Swiss data-centre operator, a Spanish municipality and an engineering firm — claims only, no victim statement, no regulator notice, no press.borderline-drop: four out-of-nexus incidents (a healthcare-billing platform, a telecoms provider, a hosting company, a restaurant franchisee) — no nexus and no transferable TTP.borderline-drop: an investment-fraud ecosystem study — US and Australian consumer fraud, no constituency nexus.borderline-drop: a vendor CVE set whose primary could not be reached on any transport — aggregator-only.borderline-drop: an open-redirect advisory with no CVE and vendor detail pending, and an industrial advisory at moderate severity, local-only, patched, unexploited — both below the actionability bar.
Single-source items and carve-outs (surviving entries). single-source-national-cert on the ATutor entry (the coordinating national CSIRT for its own advisory) and on the Siemens S7 update (the authoring agencies' own document). single-source on the ITG27 update — one lab's own deception-environment telemetry, with a note that the lab states no European targeting for the campaign. multi-source on the ShieldBreak update (an independent reproduction plus Microsoft's own record, queried directly) and on the ZeroBytes update (the education ministry's own office, the consumer-protection directorate's own release, and a reporting chain traced to its origin).
Coverage gaps: cisa-advisories (HTTP 403, eighth consecutive run, essential-tier); cisa-directives (HTTP 403, seventh consecutive, essential-tier); ccn-cert-es (403 with the pinned reader transport credit-exhausted); siemens-productcert-csaf (403, fifth consecutive, checked against the CSAF mirror instead); ssd-disclosure (client-rendered shell, reader-only host, fifth consecutive); venarix (client-rendered listing, fourth consecutive); zaufana-trzecia-strona (Cloudflare challenge, RSS readable but pre-window); ccb-belgium (direct path returned no advisory rows after the prior fire reported the recipe fixed — needs a re-check); trellix (stale served index, standing defect); sans-ics (focus-area filter honoured by no transport); paradigm-shift-research (client-rendered shell, top rotation priority); wordfence (feed works, article body unreachable — new record, needs an article-body recipe); jina-reader-pool (seventh consecutive credit exhaustion, 7/7 keys HTTP 402).
Essential-coverage: missed=cisa-advisories (HTTP 403, eighth consecutive run), cisa-directives (HTTP 403, seventh consecutive run).
Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0 — the profile configures no product or supplier watchlist, so both sweeps are no-ops.
Two things the operator should see.
- The container suspension is the story of this fire, not the content. A ~3-day mid-pipeline suspension is a different failure mode from the multi-hour stalls the wall-clock watchdog was built for, and the watchdog cannot detect it from inside — the run had already passed its own gate before the clock jumped. The salvage worked (nothing wrong was published, and the reconciliation caught all six duplicates), but the cost was six entries of composition and verification work, and a 24 h reader window that went uncovered on 2026-08-21 and 2026-08-22 with no run record for either date.
- Seven consecutive fires have now run with the reader pool fully exhausted, and this is the first where it demonstrably cost a publishable item — the WordPress file-upload flaw above was blocked on exactly that rung. Several source records are pinned to the reader exclusively.