ctipilot.ch

2026-07-21T0409Z-intel

One pipeline fire, in full · intel run of 2026-07-21 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-21/2026-07-21T0409Z-intel.md.

Run telemetry

2026-07-21T0409Z-intel intel prompt v3.28 publish ok
1h 29m duration 8 published 4 updates
Claude Opus 4.8 (claude-opus-4-8) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
10m 30s
Tool calls
12 WebFetch8 WebSearch14 bridge
Cited sources
4 of 13 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
10m 54s
Tool calls
20 WebFetch22 WebSearch13 bridge
Cited sources
0 of 13 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
6
Duration
17m 09s
Tool calls
26 WebFetch1 WebSearch24 bridge
Cited sources
7 of 25 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
13m 49s
Tool calls
12 WebFetch7 WebSearch14 bridge
Cited sources
2 of 9 in slice

Verification

✓ double-CLEAN · Claude Opus 4.8 + Sonnet 5 #1 NEEDS_FIXES · Opus 4.8 · t=3 e=0 a=0 #2 NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=0 #3 CLEAN · Claude Opus 4.8 · t=0 e=0 a=0 #4 CLEAN · Sonnet 5 · t=0 e=0 a=1

Deep dive

2026-07-21/hollowgraph-m365-calendar-graph-api-c2-cavern

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

No source-list edits recorded for this run.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Bridge invocations (this run)

6 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

6 ok
  • bridge:ncsc-csh.recent ×1
  • webfetch/rss (dnsmasq exploit-dev write-up — S1) ×1
  • url→reader (HOLLOWGRAPH deep-read, main-agent Phase 4) ×1
  • url (Cruciferra deep-read, main-agent Phase 4) ×1
  • url (ServiceNow ITW deep-read, main-agent Phase 4) ×1
  • url (Hugging Face disclosure deep-read, main-agent Phase 4 — untracked first-party source) ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=0) · Claude Opus 4.8 · 9m 07s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Two evidence[] quotes labelled publisher Proofpoint were verbatim from Infosecurity Magazine, not Proofpoint; the inline body attribution also credited Proofpoint. Underlying facts (IAT unhooking, cleReplaced both evidence quotes with Proofpoint's own verbatim text (the clean-ntdll stub-pointer sentence; 'Proofpoint observed four campaigns attributed to Chin
F4
hallucinated-fact
evidence[] quote used '...' to elide a full intervening source sentence — not a contiguous verbatim substring.Replaced with the single contiguous first sentence ('The root cause of the vulnerability is an unsafe strcpy() when a domain name is cached.'), verified against
F4
hallucinated-fact
Two evidence[] quotes silently dropped a mid-sentence parenthetical (no ellipsis); quote 1's elision was also reproduced in the body.Restored the parenthetical in quote 1 (evidence + body) and re-quoted quote 2 as a contiguous fragment ('executing many thousands of individual actions across a

Iteration #2 NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · 6m 51s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
A new, previously-uncaught instance of the same defect class: evidence[] quote 2 spliced two non-adjacent Group-IB sentences across an ellipsis (eliding two intervening sentences). Underlying fact (loReplaced with a single contiguous Group-IB sentence ('we cannot confidently attribute this activity to any previously identified threat actor.'), verified again

Iteration #4 CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Sonnet 5 · 7m 38s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
Advisory only: the deep-dive body parenthetically referenced the frontmatter field name techniques[] in reader-facing prose (schema self-reference, § Style rules). Not a truth/editorial defect.Reworded the kill-chain sentence to plain analyst language ('the Graph-API calendar dead-drop is bidirectional web-service command-and-control and the credentia

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-07-21T0409Z-intel · Claude Opus 4.8 · window 26 h · 8 entries published

Verification & coverage notes

Standard-cadence fire — a clean 24 h gap to the previous run (2026-07-20T0409Z-intel), 26 h window. A genuinely eventful window: eight entries cleared the gate — four new and four updates to developing stories — with no critical and one high (an exploitation-status flip on an already-tracked pre-auth RCE). Volume tracks the window's real signal, not cadence; the four updates are delta-only against prior coverage.

Published — new (4)

  • cve-2026-2291-dnsmasq-heap-overflow-rce-exodus — vulnerability, notable. Exodus Intelligence's exploit-dev write-up demonstrates the CVSS-7.3 dnsmasq DNS-cache heap overflow is a pre-auth RCE, not the DoS/cache-poisoning NVD frames — a triage-recalibration item for the broad OpenWrt/embedded/OT-adjacent install base. Patched upstream 2026-05-11; no ITW. Clears the vulnerability gate on the substantive-new-technical-analysis criterion (the impact reframing changes patch prioritisation).
  • cruciferra-crypter-as-a-service-process-ghosting-byovd — threat, notable. Proofpoint's analysis of a commercial crypter (process ghosting + memory/hotpatch tampering + indirect syscalls + BYOVD via GoFlyDrv.sys) used across many groups and attributed (four AsyncRAT campaigns) to China-nexus TA4922, whose tax-themed lures target finance/healthcare/government — sectors central to this constituency.
  • hollowgraph-m365-calendar-graph-api-c2-cavern — threat, notable, deep dive (category identity-infra). Group-IB's Cavern-framework component that uses a compromised M365 mailbox calendar as a Graph-API dead-drop C2 with DNS-tunneled Entra credential refresh. Currently narrow (Israeli targets) but the technique is transferable to any M365 tenant, the platform at the centre of most CH/EU public-sector estates.
  • hugging-face-autonomous-ai-agent-production-breach — incident, notable. Hugging Face's first-party disclosure of a weekend-long intrusion driven end-to-end by an autonomous AI-agent framework (17,000+ actions, self-migrating swarm C2, credential harvesting) — the second concrete July-2026 case after Sygnia's AWS intrusion. Included on the materially-new-TTP criterion; also surfaces a "guardrail asymmetry" defenders can act on (pre-provision an open-weight forensic model).

Published — updates (4, delta-only)

  • servicenow-ai-platform-cve-2026-6875-active-exploitationhigh. Exploitation-status flip: NCSC-CH's 2026-07-20 advisory marks CVE-2026-6875 (covered 2026-07-13) "Actively exploited"; Defused reports ITW from ~2026-07-18. Self-hosted/partner-managed instances without hotfix KB3137947 are now an out-of-band item. The only high this run.
  • jadepuffer-encforge-ai-model-destroying-ransomwarenotable (updates 2026-07-04). Same operator returned to the same Langflow instance with ENCFORGE, a Go ransomware purpose-built to encrypt ~180 ML-artifact file types and co-located training data — recovery cannot come from a patch or decryptor.
  • gpt56-autonomous-wordpress-wp2shell-exploit-chain — research, notable (updates 2026-07-18). Searchlight Cyber drove GPT5.6 to autonomously rediscover and weaponise the patched WP2Shell chain in ~10 h for ~$25 — a capability marker compressing the "patched-but-not-applied" safe window. CVEs/patch unchanged.
  • ancpi-romania-cadastre-databases-not-affected-update — incident, notable (updates 2026-07-19). ANCPI says its databases were NOT affected, contradicting ByteToBreach's backup-wipe claim; Gov Cloud migration to complete 22 July; KELA profiles the operator. Marked verification: contradicted — both claims held, neither resolved.

Contradiction

  • ANCPI: the agency's "technical and legal databases have not been affected" (Digi24, 2026-07-20) directly contradicts ByteToBreach's "wiped systems and backups" claim (relayed by Risky Business News). Reported both ways; entry carries verification: contradicted, confidence: medium, credibility 3.

Single-source / carve-outs

  • Hugging Face is anchored on the victim's own first-party disclosure (2026-07-16) with two independent outlets (BleepingComputer, SecurityWeek) reporting on 2026-07-20; treated as multi-source. In-window on the 2026-07-20 broad-pickup date per the freshest-available-source rule.
  • dnsmasq CVE-2026-2291: Exodus is the single origin for the working RCE chain; NVD corroborates the CVE/CVSS/patch but frames impact lower — the discrepancy is stated in the entry (verification: multi-source with an explicit sourcing_note).

Borderline drops (recoverable)

  • borderline-drop: Craneware plc healthcare-billing vendor breach (S2 + S4) — Edinburgh-domiciled/AIM-listed (a thin home-region nexus) but the customer base is exclusively US healthcare billing/pharmacy with no plausible Swiss/EU customer exposure; the RNS filing discloses no access vector (no transferable TTP), the incident is contained, and the company assesses the taken data as largely non-sensitive. Only a generic supply-chain-awareness lesson remains — fails the actionability bar for this constituency. Recover if a Swiss/EU Trisus/Sentry customer or a forensic post-mortem surfaces.
  • borderline-drop: Estée Lauder / Clop Oracle EBS breach (CVE-2025-61882) (S4) — out-of-nexus US retail victim disclosure of the August-2025 Clop Oracle EBS mass-exploitation campaign; CVE-2025-61882 was patched October 2025 (no action beyond a 9-month-old patch cycle) and the campaign-longevity lesson is generic and already thematically covered by the W29 weekly. Note for the weekly/strategic lens: Clop's Oracle EBS campaign reportedly includes a Swiss victim (Logitech); worth a strategic entry if fresh in-window CH/EU-specific reporting appears.
  • borderline-drop: Coca-Cola / fairlife ransomware (S4) — out-of-nexus US food/beverage manufacturing; the Anubis leak-site claim is unconfirmed by Coca-Cola (fake-news guard) and adds no new TTP; already borderline-dropped 2026-07-20.
  • borderline-drop: Ostium DeFi $23.7M off-chain oracle manipulation (S4) — out-of-nexus crypto/DeFi, a well-established attack class (no novel TTP), single-sourced.
  • borderline-drop: Amatera Stealer via Ren'Py/MSBuild fake game downloads (S3) — single-source (Malwarebytes); payload (Amatera) and C2 (EtherHiding) already heavily covered this window, and the novel Ren'Py-engine delivery vector alone did not clear the bar against repeat-theme fatigue.

Completeness sweep: re-read all four sub-agents' full returns including every borderline-flagged item; the five drops above are the only in-scope-adjacent items not published, each recorded with a reason. No genuinely-relevant in-window item the run surfaced was left unpublished.

Deep-dive rotation: category identity-infra — last used 2026-07-09; the trailing 7 days used network-stack-rce (2026-07-20), other (2026-07-19) and firewall-vpn-rce (2026-07-18), so identity-infra is a fresh pick. No prior deep dive today (deep_dives_today: 0). HOLLOWGRAPH earns it on the substantive-new-technical-analysis criterion with maximal M365/Entra relevance for this constituency; the medium-confidence actor attribution is bounded (the entry is framed on the technique, which Group-IB analyses at high confidence, not on the low-confidence Lyceum overlap).

Coverage gaps: cert-eu (advisory feed stale since 2026-06-10 — long-standing, not a fresh failure); several S3 standard-tier research slices not exhaustively drilled under the time budget (trustwave-spiderlabs, synacktiv, withsecure-labs, csa-labs, zimperium-zlabs, sansec-research, infoguard-labs) — no confirmed in-window miss; expel — the CylindricalCanine/GoldenEyeDog DigiCert research (2026-07-15) fell outside both the 26 h window and the 72 h developing-story extension and was dropped on recency. None are unrecovered fetch failures.

Essential-coverage: all essential national-CERT/government/KEV sources (CISA KEV, ENISA EUVD, NCSC-CH, NCSC-NL, BSI, ANSSI/CERT-FR, CERT-EU, CERT-PL, NCSC-UK, CISA advisories/directives) attempted and reachable; no misses. CISA KEV carried no new in-window additions (newest dated 2026-07-16, already covered).

Watchlist: not configured for this deployment (product and supplier watchlists empty) — sweep is a no-op; line omitted.

Verification. Four iterations (Opus / Sonnet / Opus / Sonnet rotation); confirmed CLEAN published under the double-CLEAN gate (iteration 3 Opus CLEAN + iteration 4 Sonnet CLEAN — two consecutive CLEANs on two different models). Every finding across the loop was the same class: F4 evidence-quote fidelity (quote misattribution, ellipsis-splicing, silently-dropped parentheticals) — no factual, analytical, sourcing, priority, classification, or coverage defect was found in any pass. Iteration 1 (Opus) flagged three (Cruciferra's two quotes were Infosecurity-Magazine phrasing mislabelled to Proofpoint; dnsmasq's quote elided a sentence; Hugging Face's two quotes dropped parentheticals); iteration 2 (Sonnet) confirmed all three fixes and caught a fourth of the same class (HOLLOWGRAPH's Group-IB attribution quote spliced two non-adjacent sentences); all four were remediated by requoting contiguous verbatim substrings from the correct fetched source. Iterations 3 (Opus, cold) and 4 (Sonnet, cold confirmation) both returned CLEAN against freshly-fetched primaries. Iteration 4's single advisory (F11 — the HOLLOWGRAPH body referenced the techniques[] field name in reader-facing prose) was fixed cosmetically post-pass (plain-language rewording; no claim/quote/source/fact changed). entries_dropped_by_verification: 0; verification_residual_count: 0.

Data-model note (dedup WARN, deliberate): check_run.py WARNs that the HOLLOWGRAPH entry shares entity tool:cavern-c2-framework with the 2026-07-09 Cavern Manticore entry. This is a deliberate non-update_of decision confirmed by both verifiers: HOLLOWGRAPH is a materially distinct new implant/technique (a Graph-API-calendar dead-drop variant), not a delta on the framework write-up, and the relationship is captured as a typed variant-of edge on the new tool:hollowgraph-malware record. The WARN is inherent to any new entry that correctly references a recurring entity; it is not a defect to fix.

Operator-facing tooling findings (surfaced for the weekly quality audit, not fixed this run):

  • jina reader-pool credit: S2 observed HTTP 402 (balance exhausted) on one key (suffix ...MrZOsc) during two bridge invocations before the tool auto-rotated to the next credential. Not source-specific; the pool may need a top-up or the exhausted key removed. No content was lost this run (auto-rotation + direct transports covered it).
  • WebFetch PDF summarisation reliability: S4 found WebFetch hallucinated the Estée Lauder California-AG breach-notification PDF as belonging to an unrelated company ("Sprinklr, Inc.", Jan 2024) when summarised; the raw PDF read directly confirmed it is Estée Lauder's own 2026-07-17 letter. Load-bearing PDF claims should be spot-checked against raw content, not trusted from the summariser — a candidate note for prompts/ / agent guidance.

← Operations dashboard · run-record contract: docs/pipeline.md