2026-07-20T0409Z-intel
One pipeline fire, in full · intel run of 2026-07-20 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-20/2026-07-20T0409Z-intel.md.
Run telemetry
- Items returned
- 1
- Duration
- 14m 13s
- Tool calls
- 24 WebFetch9 WebSearch14 bridge
- Cited sources
- 2 of 22 in slice
- Items returned
- 0
- Duration
- 8m 56s
- Tool calls
- 12 WebFetch12 WebSearch11 bridge
- Cited sources
- 0 of 14 in slice
- Items returned
- 2
- Duration
- 10m 13s
- Tool calls
- 24 WebFetch5 WebSearch9 bridge
- Cited sources
- 2 of 30 in slice
- Items returned
- 0
- Duration
- 9m 09s
- Tool calls
- 11 WebFetch12 WebSearch9 bridge
- Cited sources
- 0 of 8 in slice
Verification
Deep dive
2026-07-20/cve-2026-42533-nginx-pcre-capture-clobber-preauth-rce
Entries published (this run)
- CVE-2026-42533 — nginx / NGINX Plus: PCRE capture-clobber pre-auth heap overflow, researcher demonstrates RCE beyond F5's DoS-only framing (CVSS 9.2) vulnerability high
- CERT-UA: Sandworm subcluster UAC-0145 pairs ClickFix fake-CAPTCHA with Ethereum-smart-contract C2 resolution and a Signal-delivered Android backdoor threat notable
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
No source-list edits recorded for this run.
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.
Bridge invocations (this run)
9 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- bridge:feed ×2
- bridge:ncsc-csh.recent ×1
- bridge:cisa-kev ×1
- bridge:cert-fr.avis/actu-recent ×1
- bridge:enisa-euvd.recent ×1
- bridge:url ×1
- jina (article 6318437 body — S3) ×1
- url (nginx-rce deep-read, main-agent Phase 4) ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 2 findings (truth=1, editorial=0, advisory=1) · Claude Opus 4.8 · 4m 42s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | — | Run-record notes said UAC-0145 was registered with a `part-of` relation to actor:sandworm, but the registry deliberately records `related-to` (the vocabulary has no actor→actor subcluster edge). The e | Corrected the run-record note to `related-to` and stated why (no actor→actor subcluster edge in the typed vocabulary; the CERT-UA subcluster hierarchy is captur | |
| F11 editorial-advisory | — | Advisory: the 'F5 frames real-world risk as primarily denial-of-service' clause was inline-cited to SecurityWeek, which supports it only weakly; THN/cyberstan attest F5's DoS framing more directly. | Re-cited: CVSS/patch stays on SecurityWeek; the DoS-framing clause now cites Stan Shaw (cyberstan) + The Hacker News, which directly discuss and dispute F5's fr |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-07-20T0409Z-intel · Claude Opus 4.8 · window 24 h · 2 entries published
Verification & coverage notes
Intraday fire — 5 h gap to the previous run (the 2026-07-19T2310Z-weekly), 24 h window (hard floor). The prior 24 h were already worked by the 2026-07-19T0408Z-intel run, the 2026-07-19T1308Z-audit, and the W29 weekly, so the genuinely-new slice was small and most of the landscape was already covered; dedup carried the load. Two entries published from three real candidates; the national-CERT/government and incident/breach source layers were genuinely quiet (weekend), with S2 and S4 returning honest empties after thorough sweeps.
Published
2026-07-20/cve-2026-42533-nginx-pcre-capture-clobber-preauth-rce— deep dive (categorynetwork-stack-rce). New in-window pre-auth heap overflow in nginx / NGINX Plus's script engine, patched out-of-band by F5 on 2026-07-15/16; the credited discoverer disputes F5's DoS-only framing and demonstrates a reliable pre-auth RCE (single-GET ASLR defeat + control-flow hijack). Clears the vulnerability gate on the out-of-band-patch / pre-auth-RCE-on-exposed-edge criterion (action beyond the regular patch cycle) despite no public exploit PoC (author withholding ~21 days) and no in-the-wild exploitation yet. Priorityhigh, notcritical— no public PoC, no verified scanning, not in KEV. CVE id, CVSS (4.0 9.2 / 3.1 8.1), affected/fixed versions and CWE-122 verified against the F5-sourced NVD record; F5's own advisory page (K000162097) is JS-gated and not directly citable, so cited via SecurityWeek + the credited researcher. Deep dive earned on the "substantive new technical analysis, actionable" criterion — the two-pass capture-clobber mechanism, the specific vulnerable config pattern, and the scan-before-patch exposure-enumeration workflow give a skilled responder something to act on.2026-07-20/uac-0145-sandworm-clickfix-etherhiding-android-backdoor— threat,notable. CERT-UA's disclosure of Sandworm subcluster UAC-0145 pairing ClickFix fake-CAPTCHA drive-by with on-chain C2 resolution (EtherHiding via a bespoke SMARTAXE injector) and a Signal-delivered Android backdoor (COWARDDUCK). Primary targeting is Ukraine, so it clears the gate on the same-actor read (Sandworm/GRU is a standing threat to European CI + government) plus transferable TTPs — framed around the technique stack, not the victims. New entityactor:uac-0145registered with arelated-torelation toactor:sandworm— the typed relationship vocabulary has no actor→actor subcluster edge, sorelated-torecords CERT-UA's stated subcluster hierarchy (captured in the edge's note) without overclaiming a specialized type.
Single-source / carve-outs
- The UAC-0145 entry is
single-source-national-cert: CERT-UA is the primary disclosing authority for its own jurisdiction; The Hacker News (2026-07-19) corroborates in English but derives its facts from the same CERT-UA advisory, so it is effectively single-origin. Noted in the entry's sourcing_note. CERT-UA's page carries aPublished Timemetadata artefact (2026-03-10) contradicting its own June–July 2026 activity dates — treated as a site artefact, freshness anchored to the 2026-07-19 disclosure.
Borderline drops (recoverable)
- borderline-drop: SANS ISC Hikvision ISAPI
/ISAPI/System/statusreconnaissance scanning (S3) — single-source (SANS ISC handler diary, reliability B), reconnaissance-only with no confirmed exploitation, a narrow product footprint, and the only action it implies (don't expose camera management interfaces to the internet; use HTTPS + non-Basic auth) is standing hygiene rather than a task derived from this observation. Fails the actionability bar. Recover if exploitation of the endpoint (post-recon credential brute-forcing or a specific CVE) is confirmed. - borderline-drop: Abbott LabCentral / ShadowByt3$ second incident (S4) — the in-window source is a verbatim recap of 2026-07-17 reporting; no fresh delta to anchor an update, and the ShinyHunters half is already covered (2026-07-18 Abbott entry).
- borderline-drop: assorted out-of-nexus / stale S4 leads — River Financial Corp 8-K/A (out-of-nexus US community bank), Clover Health 8-K (out-of-nexus US health insurer, routine ATO), Coca-Cola/fairlife ransomware (out-of-nexus US food manufacturing, no fresh delta), ViPNet "HelloNet" repackaging (already covered 2026-07-17), Bluebell Group leak-site claim (unconfirmed, no nexus). All logged with reasons in findings.S4.yaml.
Coverage gaps: trellix (JS-SPA shell, no listing content recoverable — flag for a structured-endpoint recipe), huntress (partial/cached listing, latest dated item outside window), securelist (landing-nav only, no per-article dates; visible titles already covered), cert-eu (curated advisory list on a low, non-daily cadence — newest 2026-06-10). None are unrecovered fetch failures; all are "checked, nothing in-window" against a quiet weekend.
Watchlist: not configured for this deployment (product and supplier watchlists empty) — sweep is a no-op; line omitted from telemetry.
Essential-coverage: all essential national-CERT/government/KEV sources (CISA KEV, ENISA EUVD, NCSC-CH, NCSC-NL, BSI, ANSSI/CERT-FR, CERT-EU, CERT-PL, NCSC-UK, CISA advisories/directives) attempted and reachable; no misses. CISA KEV catalog carried no new additions inside the window (newest entries dated 2026-07-16, already covered).
Deep-dive rotation: category network-stack-rce — not used in the trailing 7 days (recent picks: other, firewall-vpn-rce, apt-campaign, identity-infra, linux-lpe). No prior deep dive today (deep_dives_today: 0).
Verification. Three iterations (Opus / Sonnet / Opus rotation); confirmed CLEAN published under the double-CLEAN gate (iteration 2 Sonnet CLEAN + iteration 3 Opus CLEAN — two consecutive CLEANs on two different models). Iteration 1 (Opus, cold) found one truth defect and one advisory: the run-record notes described the new UAC-0145→Sandworm edge as part-of while the registry deliberately used related-to (the typed vocabulary has no actor→actor subcluster edge), and the nginx body's "F5 frames risk as DoS-primary" clause was weakly cited to SecurityWeek. Both fixed (run-record note corrected to related-to with the reason; DoS-framing clause re-cited to cyberstan + The Hacker News, SecurityWeek kept for CVSS/patch). Iterations 2 and 3 independently re-read both entries + the run record cold against freshly-fetched sources and confirmed every evidence quote verbatim, every quantifier and CVSS/version sourced, all seven ATT&CK ids active in v19.1 and body-supported, no IOCs, and correct classification/priority/action-item discipline. entries_dropped_by_verification: 0; verification_residual_count: 0.
Data-model note (surfaced for the operator / weekly audit): the typed relationship vocabulary (docs/pipeline.md § Relationships, enforced by site/content_model.py) has no actor→actor containment edge, so a declared actor subcluster (UAC-0145 is a CERT-UA-declared subcluster of UAC-0002/Sandworm) can only be recorded as related-to with the hierarchy in the edge note, or folded into aliases (as UAC-0113 was on actor:sandworm). A dedicated subcluster-of / actor-scoped part-of edge would model the recurring APT-umbrella / UAC-subcluster pattern more faithfully; noted here rather than changing the normative model in a routine intel run.
← Operations dashboard · run-record contract: docs/pipeline.md