ctipilot.ch

2026-07-20T0409Z-intel

One pipeline fire, in full · intel run of 2026-07-20 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-20/2026-07-20T0409Z-intel.md.

Run telemetry

2026-07-20T0409Z-intel intel prompt v3.28 publish ok
51m 40s duration 2 published 0 updates
Claude Opus 4.8 (claude-opus-4-8) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
14m 13s
Tool calls
24 WebFetch9 WebSearch14 bridge
Cited sources
2 of 22 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
8m 56s
Tool calls
12 WebFetch12 WebSearch11 bridge
Cited sources
0 of 14 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
10m 13s
Tool calls
24 WebFetch5 WebSearch9 bridge
Cited sources
2 of 30 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
9m 09s
Tool calls
11 WebFetch12 WebSearch9 bridge
Cited sources
0 of 8 in slice

Verification

✓ double-CLEAN · Sonnet 5 + Claude Opus 4.8 #1 NEEDS_FIXES · Claude Opus 4.8 · t=1 e=0 a=1 #2 CLEAN · Sonnet 5 · t=0 e=0 a=0 #3 CLEAN · Claude Opus 4.8 · t=0 e=0 a=0

Deep dive

2026-07-20/cve-2026-42533-nginx-pcre-capture-clobber-preauth-rce

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

No source-list edits recorded for this run.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Bridge invocations (this run)

9 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

9 ok
  • bridge:feed ×2
  • bridge:ncsc-csh.recent ×1
  • bridge:cisa-kev ×1
  • bridge:cert-fr.avis/actu-recent ×1
  • bridge:enisa-euvd.recent ×1
  • bridge:url ×1
  • jina (article 6318437 body — S3) ×1
  • url (nginx-rce deep-read, main-agent Phase 4) ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 2 findings (truth=1, editorial=0, advisory=1) · Claude Opus 4.8 · 4m 42s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Run-record notes said UAC-0145 was registered with a `part-of` relation to actor:sandworm, but the registry deliberately records `related-to` (the vocabulary has no actor→actor subcluster edge). The eCorrected the run-record note to `related-to` and stated why (no actor→actor subcluster edge in the typed vocabulary; the CERT-UA subcluster hierarchy is captur
F11
editorial-advisory
Advisory: the 'F5 frames real-world risk as primarily denial-of-service' clause was inline-cited to SecurityWeek, which supports it only weakly; THN/cyberstan attest F5's DoS framing more directly.Re-cited: CVSS/patch stays on SecurityWeek; the DoS-framing clause now cites Stan Shaw (cyberstan) + The Hacker News, which directly discuss and dispute F5's fr

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-07-20T0409Z-intel · Claude Opus 4.8 · window 24 h · 2 entries published

Verification & coverage notes

Intraday fire — 5 h gap to the previous run (the 2026-07-19T2310Z-weekly), 24 h window (hard floor). The prior 24 h were already worked by the 2026-07-19T0408Z-intel run, the 2026-07-19T1308Z-audit, and the W29 weekly, so the genuinely-new slice was small and most of the landscape was already covered; dedup carried the load. Two entries published from three real candidates; the national-CERT/government and incident/breach source layers were genuinely quiet (weekend), with S2 and S4 returning honest empties after thorough sweeps.

Published

  • 2026-07-20/cve-2026-42533-nginx-pcre-capture-clobber-preauth-rce — deep dive (category network-stack-rce). New in-window pre-auth heap overflow in nginx / NGINX Plus's script engine, patched out-of-band by F5 on 2026-07-15/16; the credited discoverer disputes F5's DoS-only framing and demonstrates a reliable pre-auth RCE (single-GET ASLR defeat + control-flow hijack). Clears the vulnerability gate on the out-of-band-patch / pre-auth-RCE-on-exposed-edge criterion (action beyond the regular patch cycle) despite no public exploit PoC (author withholding ~21 days) and no in-the-wild exploitation yet. Priority high, not critical — no public PoC, no verified scanning, not in KEV. CVE id, CVSS (4.0 9.2 / 3.1 8.1), affected/fixed versions and CWE-122 verified against the F5-sourced NVD record; F5's own advisory page (K000162097) is JS-gated and not directly citable, so cited via SecurityWeek + the credited researcher. Deep dive earned on the "substantive new technical analysis, actionable" criterion — the two-pass capture-clobber mechanism, the specific vulnerable config pattern, and the scan-before-patch exposure-enumeration workflow give a skilled responder something to act on.
  • 2026-07-20/uac-0145-sandworm-clickfix-etherhiding-android-backdoor — threat, notable. CERT-UA's disclosure of Sandworm subcluster UAC-0145 pairing ClickFix fake-CAPTCHA drive-by with on-chain C2 resolution (EtherHiding via a bespoke SMARTAXE injector) and a Signal-delivered Android backdoor (COWARDDUCK). Primary targeting is Ukraine, so it clears the gate on the same-actor read (Sandworm/GRU is a standing threat to European CI + government) plus transferable TTPs — framed around the technique stack, not the victims. New entity actor:uac-0145 registered with a related-to relation to actor:sandworm — the typed relationship vocabulary has no actor→actor subcluster edge, so related-to records CERT-UA's stated subcluster hierarchy (captured in the edge's note) without overclaiming a specialized type.

Single-source / carve-outs

  • The UAC-0145 entry is single-source-national-cert: CERT-UA is the primary disclosing authority for its own jurisdiction; The Hacker News (2026-07-19) corroborates in English but derives its facts from the same CERT-UA advisory, so it is effectively single-origin. Noted in the entry's sourcing_note. CERT-UA's page carries a Published Time metadata artefact (2026-03-10) contradicting its own June–July 2026 activity dates — treated as a site artefact, freshness anchored to the 2026-07-19 disclosure.

Borderline drops (recoverable)

  • borderline-drop: SANS ISC Hikvision ISAPI /ISAPI/System/status reconnaissance scanning (S3) — single-source (SANS ISC handler diary, reliability B), reconnaissance-only with no confirmed exploitation, a narrow product footprint, and the only action it implies (don't expose camera management interfaces to the internet; use HTTPS + non-Basic auth) is standing hygiene rather than a task derived from this observation. Fails the actionability bar. Recover if exploitation of the endpoint (post-recon credential brute-forcing or a specific CVE) is confirmed.
  • borderline-drop: Abbott LabCentral / ShadowByt3$ second incident (S4) — the in-window source is a verbatim recap of 2026-07-17 reporting; no fresh delta to anchor an update, and the ShinyHunters half is already covered (2026-07-18 Abbott entry).
  • borderline-drop: assorted out-of-nexus / stale S4 leads — River Financial Corp 8-K/A (out-of-nexus US community bank), Clover Health 8-K (out-of-nexus US health insurer, routine ATO), Coca-Cola/fairlife ransomware (out-of-nexus US food manufacturing, no fresh delta), ViPNet "HelloNet" repackaging (already covered 2026-07-17), Bluebell Group leak-site claim (unconfirmed, no nexus). All logged with reasons in findings.S4.yaml.

Coverage gaps: trellix (JS-SPA shell, no listing content recoverable — flag for a structured-endpoint recipe), huntress (partial/cached listing, latest dated item outside window), securelist (landing-nav only, no per-article dates; visible titles already covered), cert-eu (curated advisory list on a low, non-daily cadence — newest 2026-06-10). None are unrecovered fetch failures; all are "checked, nothing in-window" against a quiet weekend.

Watchlist: not configured for this deployment (product and supplier watchlists empty) — sweep is a no-op; line omitted from telemetry.

Essential-coverage: all essential national-CERT/government/KEV sources (CISA KEV, ENISA EUVD, NCSC-CH, NCSC-NL, BSI, ANSSI/CERT-FR, CERT-EU, CERT-PL, NCSC-UK, CISA advisories/directives) attempted and reachable; no misses. CISA KEV catalog carried no new additions inside the window (newest entries dated 2026-07-16, already covered).

Deep-dive rotation: category network-stack-rce — not used in the trailing 7 days (recent picks: other, firewall-vpn-rce, apt-campaign, identity-infra, linux-lpe). No prior deep dive today (deep_dives_today: 0).

Verification. Three iterations (Opus / Sonnet / Opus rotation); confirmed CLEAN published under the double-CLEAN gate (iteration 2 Sonnet CLEAN + iteration 3 Opus CLEAN — two consecutive CLEANs on two different models). Iteration 1 (Opus, cold) found one truth defect and one advisory: the run-record notes described the new UAC-0145→Sandworm edge as part-of while the registry deliberately used related-to (the typed vocabulary has no actor→actor subcluster edge), and the nginx body's "F5 frames risk as DoS-primary" clause was weakly cited to SecurityWeek. Both fixed (run-record note corrected to related-to with the reason; DoS-framing clause re-cited to cyberstan + The Hacker News, SecurityWeek kept for CVSS/patch). Iterations 2 and 3 independently re-read both entries + the run record cold against freshly-fetched sources and confirmed every evidence quote verbatim, every quantifier and CVSS/version sourced, all seven ATT&CK ids active in v19.1 and body-supported, no IOCs, and correct classification/priority/action-item discipline. entries_dropped_by_verification: 0; verification_residual_count: 0.

Data-model note (surfaced for the operator / weekly audit): the typed relationship vocabulary (docs/pipeline.md § Relationships, enforced by site/content_model.py) has no actor→actor containment edge, so a declared actor subcluster (UAC-0145 is a CERT-UA-declared subcluster of UAC-0002/Sandworm) can only be recorded as related-to with the hierarchy in the edge note, or folded into aliases (as UAC-0113 was on actor:sandworm). A dedicated subcluster-of / actor-scoped part-of edge would model the recurring APT-umbrella / UAC-subcluster pattern more faithfully; noted here rather than changing the normative model in a routine intel run.

← Operations dashboard · run-record contract: docs/pipeline.md