2026-07-21T0409Z-intel
One pipeline fire, in full · intel run of 2026-07-21 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-21/2026-07-21T0409Z-intel.md.
Run telemetry
- Items returned
- 2
- Duration
- 10m 30s
- Tool calls
- 12 WebFetch8 WebSearch14 bridge
- Cited sources
- 4 of 13 in slice
- Items returned
- 1
- Duration
- 10m 54s
- Tool calls
- 20 WebFetch22 WebSearch13 bridge
- Cited sources
- 0 of 13 in slice
- Items returned
- 6
- Duration
- 17m 09s
- Tool calls
- 26 WebFetch1 WebSearch24 bridge
- Cited sources
- 7 of 25 in slice
- Items returned
- 5
- Duration
- 13m 49s
- Tool calls
- 12 WebFetch7 WebSearch14 bridge
- Cited sources
- 2 of 9 in slice
Verification
Deep dive
2026-07-21/hollowgraph-m365-calendar-graph-api-c2-cavern
Entries published (this run)
- CVE-2026-6875 — ServiceNow AI Platform: pre-auth sandbox-escape RCE now under active exploitation (CVSS 9.5) vulnerability high update
- CVE-2026-2291 — dnsmasq DNS-cache heap overflow is a pre-auth RCE, not just a DoS (Exodus exploit-dev write-up) vulnerability notable
- JADEPUFFER returns with ENCFORGE — a Go ransomware built to destroy AI/ML model artifacts, not just extort data threat notable update
- Cruciferra: a crypter-as-a-service using kernel-aware process ghosting and BYOVD EDR termination, tied to China-nexus TA4922 threat notable
- HOLLOWGRAPH: a Cavern-framework backdoor that turns a compromised Microsoft 365 calendar into a Graph-API dead-drop C2 threat notable
- AI-accelerated exploit dev: GPT5.6 autonomously rediscovers and weaponises the WP2Shell WordPress RCE chain in ~10h for ~$25 research notable update
- ANCPI (Romania cadastre): agency says core databases were NOT compromised, contradicting ByteToBreach's destruction claim; Gov Cloud migration to complete 22 July incident notable update
- Hugging Face: a fully autonomous AI agent breached production, ran 17,000+ actions before detection incident notable
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
No source-list edits recorded for this run.
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.
Bridge invocations (this run)
6 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- bridge:ncsc-csh.recent ×1
- webfetch/rss (dnsmasq exploit-dev write-up — S1) ×1
- url→reader (HOLLOWGRAPH deep-read, main-agent Phase 4) ×1
- url (Cruciferra deep-read, main-agent Phase 4) ×1
- url (ServiceNow ITW deep-read, main-agent Phase 4) ×1
- url (Hugging Face disclosure deep-read, main-agent Phase 4 — untracked first-party source) ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=0) · Claude Opus 4.8 · 9m 07s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | — | Two evidence[] quotes labelled publisher Proofpoint were verbatim from Infosecurity Magazine, not Proofpoint; the inline body attribution also credited Proofpoint. Underlying facts (IAT unhooking, cle | Replaced both evidence quotes with Proofpoint's own verbatim text (the clean-ntdll stub-pointer sentence; 'Proofpoint observed four campaigns attributed to Chin | |
| F4 hallucinated-fact | — | evidence[] quote used '...' to elide a full intervening source sentence — not a contiguous verbatim substring. | Replaced with the single contiguous first sentence ('The root cause of the vulnerability is an unsafe strcpy() when a domain name is cached.'), verified against | |
| F4 hallucinated-fact | — | Two evidence[] quotes silently dropped a mid-sentence parenthetical (no ellipsis); quote 1's elision was also reproduced in the body. | Restored the parenthetical in quote 1 (evidence + body) and re-quoted quote 2 as a contiguous fragment ('executing many thousands of individual actions across a |
Iteration #2 NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · 6m 51s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | — | A new, previously-uncaught instance of the same defect class: evidence[] quote 2 spliced two non-adjacent Group-IB sentences across an ellipsis (eliding two intervening sentences). Underlying fact (lo | Replaced with a single contiguous Group-IB sentence ('we cannot confidently attribute this activity to any previously identified threat actor.'), verified again |
Iteration #4 CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Sonnet 5 · 7m 38s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | — | Advisory only: the deep-dive body parenthetically referenced the frontmatter field name techniques[] in reader-facing prose (schema self-reference, § Style rules). Not a truth/editorial defect. | Reworded the kill-chain sentence to plain analyst language ('the Graph-API calendar dead-drop is bidirectional web-service command-and-control and the credentia |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-07-21T0409Z-intel · Claude Opus 4.8 · window 26 h · 8 entries published
Verification & coverage notes
Standard-cadence fire — a clean 24 h gap to the previous run (2026-07-20T0409Z-intel), 26 h window. A genuinely eventful window: eight entries cleared the gate — four new and four updates to developing stories — with no critical and one high (an exploitation-status flip on an already-tracked pre-auth RCE). Volume tracks the window's real signal, not cadence; the four updates are delta-only against prior coverage.
Published — new (4)
cve-2026-2291-dnsmasq-heap-overflow-rce-exodus— vulnerability,notable. Exodus Intelligence's exploit-dev write-up demonstrates the CVSS-7.3 dnsmasq DNS-cache heap overflow is a pre-auth RCE, not the DoS/cache-poisoning NVD frames — a triage-recalibration item for the broad OpenWrt/embedded/OT-adjacent install base. Patched upstream 2026-05-11; no ITW. Clears the vulnerability gate on the substantive-new-technical-analysis criterion (the impact reframing changes patch prioritisation).cruciferra-crypter-as-a-service-process-ghosting-byovd— threat,notable. Proofpoint's analysis of a commercial crypter (process ghosting + memory/hotpatch tampering + indirect syscalls + BYOVD via GoFlyDrv.sys) used across many groups and attributed (four AsyncRAT campaigns) to China-nexus TA4922, whose tax-themed lures target finance/healthcare/government — sectors central to this constituency.hollowgraph-m365-calendar-graph-api-c2-cavern— threat,notable, deep dive (categoryidentity-infra). Group-IB's Cavern-framework component that uses a compromised M365 mailbox calendar as a Graph-API dead-drop C2 with DNS-tunneled Entra credential refresh. Currently narrow (Israeli targets) but the technique is transferable to any M365 tenant, the platform at the centre of most CH/EU public-sector estates.hugging-face-autonomous-ai-agent-production-breach— incident,notable. Hugging Face's first-party disclosure of a weekend-long intrusion driven end-to-end by an autonomous AI-agent framework (17,000+ actions, self-migrating swarm C2, credential harvesting) — the second concrete July-2026 case after Sygnia's AWS intrusion. Included on the materially-new-TTP criterion; also surfaces a "guardrail asymmetry" defenders can act on (pre-provision an open-weight forensic model).
Published — updates (4, delta-only)
servicenow-ai-platform-cve-2026-6875-active-exploitation—high. Exploitation-status flip: NCSC-CH's 2026-07-20 advisory marks CVE-2026-6875 (covered 2026-07-13) "Actively exploited"; Defused reports ITW from ~2026-07-18. Self-hosted/partner-managed instances without hotfix KB3137947 are now an out-of-band item. The onlyhighthis run.jadepuffer-encforge-ai-model-destroying-ransomware—notable(updates 2026-07-04). Same operator returned to the same Langflow instance with ENCFORGE, a Go ransomware purpose-built to encrypt ~180 ML-artifact file types and co-located training data — recovery cannot come from a patch or decryptor.gpt56-autonomous-wordpress-wp2shell-exploit-chain— research,notable(updates 2026-07-18). Searchlight Cyber drove GPT5.6 to autonomously rediscover and weaponise the patched WP2Shell chain in ~10 h for ~$25 — a capability marker compressing the "patched-but-not-applied" safe window. CVEs/patch unchanged.ancpi-romania-cadastre-databases-not-affected-update— incident,notable(updates 2026-07-19). ANCPI says its databases were NOT affected, contradicting ByteToBreach's backup-wipe claim; Gov Cloud migration to complete 22 July; KELA profiles the operator. Markedverification: contradicted— both claims held, neither resolved.
Contradiction
- ANCPI: the agency's "technical and legal databases have not been affected" (Digi24, 2026-07-20) directly contradicts ByteToBreach's "wiped systems and backups" claim (relayed by Risky Business News). Reported both ways; entry carries
verification: contradicted,confidence: medium, credibility 3.
Single-source / carve-outs
- Hugging Face is anchored on the victim's own first-party disclosure (2026-07-16) with two independent outlets (BleepingComputer, SecurityWeek) reporting on 2026-07-20; treated as multi-source. In-window on the 2026-07-20 broad-pickup date per the freshest-available-source rule.
- dnsmasq CVE-2026-2291: Exodus is the single origin for the working RCE chain; NVD corroborates the CVE/CVSS/patch but frames impact lower — the discrepancy is stated in the entry (
verification: multi-sourcewith an explicit sourcing_note).
Borderline drops (recoverable)
- borderline-drop: Craneware plc healthcare-billing vendor breach (S2 + S4) — Edinburgh-domiciled/AIM-listed (a thin home-region nexus) but the customer base is exclusively US healthcare billing/pharmacy with no plausible Swiss/EU customer exposure; the RNS filing discloses no access vector (no transferable TTP), the incident is contained, and the company assesses the taken data as largely non-sensitive. Only a generic supply-chain-awareness lesson remains — fails the actionability bar for this constituency. Recover if a Swiss/EU Trisus/Sentry customer or a forensic post-mortem surfaces.
- borderline-drop: Estée Lauder / Clop Oracle EBS breach (CVE-2025-61882) (S4) — out-of-nexus US retail victim disclosure of the August-2025 Clop Oracle EBS mass-exploitation campaign; CVE-2025-61882 was patched October 2025 (no action beyond a 9-month-old patch cycle) and the campaign-longevity lesson is generic and already thematically covered by the W29 weekly. Note for the weekly/strategic lens: Clop's Oracle EBS campaign reportedly includes a Swiss victim (Logitech); worth a strategic entry if fresh in-window CH/EU-specific reporting appears.
- borderline-drop: Coca-Cola / fairlife ransomware (S4) — out-of-nexus US food/beverage manufacturing; the Anubis leak-site claim is unconfirmed by Coca-Cola (fake-news guard) and adds no new TTP; already borderline-dropped 2026-07-20.
- borderline-drop: Ostium DeFi $23.7M off-chain oracle manipulation (S4) — out-of-nexus crypto/DeFi, a well-established attack class (no novel TTP), single-sourced.
- borderline-drop: Amatera Stealer via Ren'Py/MSBuild fake game downloads (S3) — single-source (Malwarebytes); payload (Amatera) and C2 (EtherHiding) already heavily covered this window, and the novel Ren'Py-engine delivery vector alone did not clear the bar against repeat-theme fatigue.
Completeness sweep: re-read all four sub-agents' full returns including every borderline-flagged item; the five drops above are the only in-scope-adjacent items not published, each recorded with a reason. No genuinely-relevant in-window item the run surfaced was left unpublished.
Deep-dive rotation: category identity-infra — last used 2026-07-09; the trailing 7 days used network-stack-rce (2026-07-20), other (2026-07-19) and firewall-vpn-rce (2026-07-18), so identity-infra is a fresh pick. No prior deep dive today (deep_dives_today: 0). HOLLOWGRAPH earns it on the substantive-new-technical-analysis criterion with maximal M365/Entra relevance for this constituency; the medium-confidence actor attribution is bounded (the entry is framed on the technique, which Group-IB analyses at high confidence, not on the low-confidence Lyceum overlap).
Coverage gaps: cert-eu (advisory feed stale since 2026-06-10 — long-standing, not a fresh failure); several S3 standard-tier research slices not exhaustively drilled under the time budget (trustwave-spiderlabs, synacktiv, withsecure-labs, csa-labs, zimperium-zlabs, sansec-research, infoguard-labs) — no confirmed in-window miss; expel — the CylindricalCanine/GoldenEyeDog DigiCert research (2026-07-15) fell outside both the 26 h window and the 72 h developing-story extension and was dropped on recency. None are unrecovered fetch failures.
Essential-coverage: all essential national-CERT/government/KEV sources (CISA KEV, ENISA EUVD, NCSC-CH, NCSC-NL, BSI, ANSSI/CERT-FR, CERT-EU, CERT-PL, NCSC-UK, CISA advisories/directives) attempted and reachable; no misses. CISA KEV carried no new in-window additions (newest dated 2026-07-16, already covered).
Watchlist: not configured for this deployment (product and supplier watchlists empty) — sweep is a no-op; line omitted.
Verification. Four iterations (Opus / Sonnet / Opus / Sonnet rotation); confirmed CLEAN published under the double-CLEAN gate (iteration 3 Opus CLEAN + iteration 4 Sonnet CLEAN — two consecutive CLEANs on two different models). Every finding across the loop was the same class: F4 evidence-quote fidelity (quote misattribution, ellipsis-splicing, silently-dropped parentheticals) — no factual, analytical, sourcing, priority, classification, or coverage defect was found in any pass. Iteration 1 (Opus) flagged three (Cruciferra's two quotes were Infosecurity-Magazine phrasing mislabelled to Proofpoint; dnsmasq's quote elided a sentence; Hugging Face's two quotes dropped parentheticals); iteration 2 (Sonnet) confirmed all three fixes and caught a fourth of the same class (HOLLOWGRAPH's Group-IB attribution quote spliced two non-adjacent sentences); all four were remediated by requoting contiguous verbatim substrings from the correct fetched source. Iterations 3 (Opus, cold) and 4 (Sonnet, cold confirmation) both returned CLEAN against freshly-fetched primaries. Iteration 4's single advisory (F11 — the HOLLOWGRAPH body referenced the techniques[] field name in reader-facing prose) was fixed cosmetically post-pass (plain-language rewording; no claim/quote/source/fact changed). entries_dropped_by_verification: 0; verification_residual_count: 0.
Data-model note (dedup WARN, deliberate): check_run.py WARNs that the HOLLOWGRAPH entry shares entity tool:cavern-c2-framework with the 2026-07-09 Cavern Manticore entry. This is a deliberate non-update_of decision confirmed by both verifiers: HOLLOWGRAPH is a materially distinct new implant/technique (a Graph-API-calendar dead-drop variant), not a delta on the framework write-up, and the relationship is captured as a typed variant-of edge on the new tool:hollowgraph-malware record. The WARN is inherent to any new entry that correctly references a recurring entity; it is not a defect to fix.
Operator-facing tooling findings (surfaced for the weekly quality audit, not fixed this run):
- jina reader-pool credit: S2 observed HTTP 402 (balance exhausted) on one key (suffix ...MrZOsc) during two bridge invocations before the tool auto-rotated to the next credential. Not source-specific; the pool may need a top-up or the exhausted key removed. No content was lost this run (auto-rotation + direct transports covered it).
- WebFetch PDF summarisation reliability: S4 found
WebFetchhallucinated the Estée Lauder California-AG breach-notification PDF as belonging to an unrelated company ("Sprinklr, Inc.", Jan 2024) when summarised; the raw PDF read directly confirmed it is Estée Lauder's own 2026-07-17 letter. Load-bearing PDF claims should be spot-checked against raw content, not trusted from the summariser — a candidate note forprompts// agent guidance.
← Operations dashboard · run-record contract: docs/pipeline.md