ctipilot.ch

2026-07-22T0409Z-intel

One pipeline fire, in full · intel run of 2026-07-22 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-22/2026-07-22T0409Z-intel.md.

Run telemetry

2026-07-22T0409Z-intel intel prompt v3.28 publish ok
2h 13m duration 7 published 2 updates
Claude Opus 4.8 (claude-opus-4-8) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
11m 32s
Tool calls
20 WebFetch3 WebSearch14 bridge
Cited sources
6 of 13 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
16m 21s
Tool calls
16 WebFetch19 WebSearch14 bridge
Cited sources
2 of 13 in slice
S3 Claude Opus 4.8 (claude-opus-4-8)
Items returned
3
Duration
10m 24s
Tool calls
8 WebFetch3 WebSearch6 bridge
Cited sources
3 of 11 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
15m 05s
Tool calls
17 WebFetch16 WebSearch14 bridge
Cited sources
4 of 9 in slice

Verification

#1 NEEDS_FIXES · Claude Opus 4.8 · t=1 e=2 a=0 #2 CLEAN · Sonnet 5 · t=0 e=0 a=0 #3 NEEDS_FIXES · Claude Opus 4.8 · t=1 e=1 a=0 #4 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #5 NEEDS_FIXES · Claude Opus 4.8 · t=1 e=0 a=0 #6 NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=0 #7 CLEAN · Claude Opus 4.8 · t=0 e=0 a=0 #8 NEEDS_FIXES · Sonnet 5 · t=3 e=1 a=0

Deep dive

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

No source-list edits recorded for this run.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
chrome-releaseshttps://chromereleases.googleblog.com/feeds/posts/defaultbridge:feedjinaNone
S1: jina reader fallback returned 0 items (two jina credentials reported HTTP 402 balance-exhausted before a working credential rotated in); possible feed-path
none — coverage gap; general Chrome/Edge CVE coverage this run came via other channels, no material loss

Bridge invocations (this run)

9 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

9 ok
  • fetch_source.py cisa-kev (S1 KEV additions 2026-07-21) ×1
  • fetch_source.py url (S1 CISA KEV alert deep-read, main-agent Phase 4) ×1
  • fetch_source.py ncsc-csh recent 30 (S1/S2 Zimbra + sweep) ×1
  • fetch_source.py ncsc-nl csaf NCSC-2026-0251 / NCSC-2026-0237 (S1/S2 + main-agent deep-read) ×1
  • url (Langflow ZDI-26-036 deep-read, main-agent Phase 4 — untracked primary) ×1
  • url (SharePoint machine-key deep-read, main-agent Phase 4) ×1
  • url (XEntry + Cavern deep-read, main-agent Phase 4) ×1
  • url (Stadler Rail deep-read, main-agent Phase 4 — untracked primary) ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 3 findings (truth=1, editorial=2, advisory=0) · Claude Opus 4.8 · 10m 29s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Overstated Kaspersky's OilRig link: Kaspersky retains only a LOW-confidence assessment associating Project CAV3RN with OilRig (first made in a prior report; new module adds supporting evidence but no Reworded title, headline, summary, body and sourcing_note to a low-confidence association (analytic lead, not settled attribution), noting the prior-report orig
F5
missing-citation
Actor-background paragraph (founding date, IAB/insider model, RDP/VPN vectors, airport/grid/telecom claims) carried no inline citation ('Per third-party actor tracking'); the two cited sources cover oAdded the Halcyon threat-actor profile as a corroborating source and re-fetched it to confirm every background claim (Dec 2020 emergence, BlackByte code lineage
F5
missing-citation
'A public proof-of-concept is available on GitHub' was uncited; none of the three cited sources (CISA KEV alert, ZDI-26-036, NCSC-2026-0251) mention a public PoC, and the frontmatter carried status/taRemoved the uncited PoC sentence and removed poc-public from the tags and from CVE-2026-0770's status[] (kept exploited, cisa-kev — both cited). Active exploita

Iteration #3 NEEDS_FIXES · 2 findings (truth=1, editorial=1, advisory=0) · Claude Opus 4.8 · 8m 08s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F14
?
Body's '~10,000 records ... reported as roughly 2,500 diplomats posted worldwide and 350 serving overseas officials' breakdown appears in none of the three cited sources (Korea Herald has no such figuDropped the '2,500 / 350' breakdown clause; the body now states only 'up to ~10,000 records', which all three sources support (Seoul Shinmun '최대 1만명').
F10
missed-angle
The cited 2026-07-21 CISA KEV alert added four CVEs; the run triaged Langflow (published) and DD-WRT (dropped) but did not name the two WordPress Core CVEs in the same batch — CVE-2026-63030 and CVE-2No new entry: CVE-2026-63030 + CVE-2026-60137 ARE the WP2Shell pre-auth RCE chain already covered on 2026-07-18 (entry wordpress-core-wp2shell-preauth-rce-chain

Iteration #4 NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 5m 42s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F13
?
Entry and registry presented two separate Kaspersky incidents (Colombia/RDP, unnamed actor; Mexico/MSSQL-RMM-GPO, 'Hacked by XEntry Team') as one confirmed crew's playbook, an analytical link KasperskRewrote the entry to describe a two-incident BitLocker-extortion technique cluster, attributing the 'XEntry Team' name to the Mexico case only and reporting Kas
F4
hallucinated-fact
Stale run-record narrative left from before iteration 1's fix: § Published still said Kaspersky 'attributes it to OilRig' and listed relations 'oilrig uses cavern; oilrig overlaps-with cavern-manticorUpdated the § Published CAV3RN bullet to match the corrected entry and registry — low-confidence association (analytic lead), single related-to edge to tool:cav

Iteration #5 NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Opus 4.8 · 8m 10s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Body and sourcing_note asserted CVE-2026-10631 = EWS-extension access control and CVE-2026-50054 = mailbox-delegation authorization 'confirmed via BSI's CSAF record', but BSI's CSAF carries only threeReworded body and sourcing_note: BSI lists the three IDs (no per-CVE descriptions), only The Hacker News maps CVE-2026-50055 to the mail-forwarding bypass, and

Iteration #6 NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · 7m 39s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Iteration 5's Zimbra fix confirmed resolved. New residual: the registry actor:everest-ransomware summary still attributed the Everest airport/grid/telecom victim claims to swissinfo.ch / Swiss IT MagaRewrote the registry summary to attribute the founding/BlackByte-lineage/IAB/insider/RDP-VPN background and the Oct 2025 airport/grid/telecom leak-site claims t

Iteration #8 NEEDS_FIXES cap-breach · 4 findings (truth=3, editorial=1, advisory=0) · Claude Sonnet 5 · 9m 42s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
'Lyceum' was listed as a flat OilRig alias; MITRE ATT&CK G0049's alias list does not include it and the cited Check Point source frames Lyceum as a subgroup claim, not an identity.Removed 'Lyceum' from actor:oilrig aliases (kept APT34, Helix Kitten, Evasive Serpens, Hazel Sandstorm).
F4
hallucinated-fact
'third distinct Langflow CVE ... in roughly two weeks (after CVE-2026-33017 and CVE-2026-55255 on 2026-07-07)' was wrong: CISA's KEV catalog shows CVE-2026-33017 was added 2026-03-25, not 2026-07-07.Removed the incorrect 'two weeks / 2026-07-07' framing; the body now states Langflow has repeatedly drawn CISA KEV listings in 2026 (earlier additions include C
F3
claim-not-supported
The 'Janggggg' PowerShell-PoC researcher attribution was cited to Security Affairs, which does not mention that name; the fact is supported by the already-cited BleepingComputer article.Re-attributed the Janggggg/PoC + honeypot facts to BleepingComputer inline; kept Security Affairs as corroboration of the escalation only.
F6
strengthen-primary-source
The CVE-2026-10631 / CVE-2026-50054 issue mapping left 'unattributed' could be resolved by SecurityWeek's article (not currently cited), which maps both IDs to specific issues.Not applied — cap reached (fail-open). The entry's hedge is accurate (BSI carries only bare IDs; only The Hacker News maps CVE-2026-50055 to an issue). Left the

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-07-22T0409Z-intel · Claude Opus 4.8 · window 26 h · 7 entries published

Verification & coverage notes

Standard 26 h window (gap 24 h to the previous fire 2026-07-21T0409Z-intel, which published ok). Seven entries published — five new, two updates — from 12 candidate items across S1–S4. No deep dive this run: the strongest technical candidate (SharePoint CVE-2026-50522) is an escalation of an already-covered July cluster, so it ships as a richly-detailed high update rather than a fresh deep-dive treatment of well-trodden ground.

Published

  • high new — Langflow CVE-2026-0770 actively exploited (CISA KEV 2026-07-21) plus the 15-CVE NCSC-NL batch fixed in 1.10.1. Multi-source (CISA + ZDI per-CVE advisory + NCSC-NL/IBM). Distinct from prior Langflow coverage (CVE-2026-55255 IDOR 2026-07-08, CVE-2025-34291 2026-05-22) — new CVEs, so a new entry, not an update.
  • notable new — Zimbra 10.1.20 SNMP command-injection RCE + 4 stored-XSS; NCSC-CH and BSI dual-flag. No confirmed ITW; three CVEs RESERVED on NVD, headline SNMP RCE carries no CVE. Included on home-region relevance (self-hosted CH/EU webmail) + dual national-CERT flag; priority held at notable because no exploitation is confirmed.
  • notable new — Everest ransomware / Stadler Rail supplier-platform breach. Direct Swiss home-region hit (transport manufacturer, Thurgau); trusted-relationship vector (T1199); Stadler's own systems/production unaffected, refused CHF 10M.
  • high update — SharePoint CVE-2026-50522 escalates to active ITW exploitation via public PoC (machine-key theft → forged auth surviving patch); update_of 2026-07-15 July-cluster entry. Actions left empty: the patch and evict-then-rotate-keys tasks are already carried in-window by the 2026-07-15 and 2026-07-17 SharePoint entries — repeating them would duplicate the aggregated Action Items list.
  • notable new — XEntry Team living-off-the-land BitLocker extortion (Kaspersky GERT). Single-source (reputable lab); strong behavioural-detection value, no IOCs.
  • notable update — Project CAV3RN / Cavern: Kaspersky independently corroborates the Cavern/HOLLOWGRAPH cluster and adds a DNS AAAA-record C2 config-recovery fallback; on attribution it retains only a LOW-confidence association with OilRig (APT34) — first drawn in a prior report, no direct code reuse or infrastructure overlap — reported as an analytic lead, not a settled attribution; update_of the 2026-07-21 HOLLOWGRAPH entry. Registered actor:oilrig with a single related-to edge to tool:cavern-c2-framework (low-confidence note).
  • notable new — South Korea KNDA diplomatic-academy e-learning zero-day breach. Out-of-home-region but government-sector with a transferable exposure-class lesson (externally-reachable staff training platforms; cross-agency detection). Cleared the breach gate on scale (a) + transferable shared threat (d).

Borderline drops

  • borderline-drop: DD-WRT CVE-2021-27137 / C0XMO botnet KEV listing — dedup. C0XMO/DD-WRT was already covered on 2026-06-08; the only in-window fact is the CISA KEV listing, which is jurisdiction-agnostic exploitation confirmation but on its own never opens a new/update entry for this audience. Recorded cisa-kev awareness only.
  • borderline-drop: WordPress Core CVE-2026-63030 + CVE-2026-60137 (same 2026-07-21 CISA KEV batch as Langflow/DD-WRT) — dedup. These two CVEs are the WP2Shell pre-auth RCE chain already covered on 2026-07-18 and updated 2026-07-21 (the GPT5.6 autonomous-exploit-chain entry); they were already reported as actively exploited. The 2026-07-21 KEV listing confirms that exploitation but, per policy, a KEV listing alone does not open a new or update entry over already-covered ground. WordPress Core is highly relevant to the constituency, but the operational signal (patch/hunt WP2Shell) is already published — no blind spot.
  • borderline-drop: SentinelLABS Iran War midyear assessment — strategic-leaning periodic assessment (weekly-run territory); the CH/EU nexus is indirect (US/Israel/Middle East targeting) and its defender priorities are generic hardening. Logged for possible weekly pickup.
  • borderline-drop: Estée Lauder Cl0p Oracle EBS breach (CVE-2025-61882) — out-of-nexus (US cosmetics), and the underlying campaign/CVE is from 2025 (patched Oct 2025, KEV since Oct 2025). Disclosure of another victim of a known campaign is awareness, not a near-term decision change for the constituency.
  • borderline-drop: Anubis ransomware / Coca-Cola fairlife — out-of-nexus (US food/beverage); the distinctive claim (full Nutanix HCI encryption, ~1 TB) is Anubis's own unverified leak-site assertion, and the confirmed baseline (a production-halt ransomware incident via SEC 8-K) carries no new/materially-evolved transferable TTP.

Recency / out-of-window

  • Two S3 leads dropped on recency (source publication outside the 26 h/72 h window), logged for the next run: Expel "CylindricalCanine" (DigiCert code-signing theft, published 2026-07-15) and Symantec "Spirals" Rust ransomware (published 2026-07-16).

Other

  • Verification: 8 iterations (Opus/Sonnet rotation), reaching the iteration cap without a confirmed double-CLEAN — published under the v3.27 fail-open. The loop was genuinely productive: iterations 1/3/4/5/6/8 each surfaced real truth/editorial defects that were remediated (Cavern OilRig over-attribution → low-confidence; Everest background → Halcyon-cited; Langflow uncited PoC removed and a wrong KEV-date framing corrected; KNDA unsupported diplomat-count dropped; XEntry two-incident conflation corrected; Zimbra CVE→issue mapping hedged; OilRig 'Lyceum' alias removed; SharePoint 'Janggggg' re-cited to BleepingComputer). Iterations 2 and 7 returned CLEAN but each was refuted by the next model's confirmation pass — exactly the blind-spot catch the double-CLEAN gate exists for. Of iteration 8's four findings, three (the two F4s and the F3) were remediated post-verdict; one (F6, Zimbra CVE-2026-10631/-50054 issue mapping) was left as an accurate hedge rather than re-sourced from an unverified new source at the cap. verification_residual_count is recorded as 4 per the fail-open rule (final verifier verdict's truth+editorial), acknowledging the post-cap fixes were not independently re-verified; the weekly quality audit should confirm them and add SecurityWeek to resolve the Zimbra mapping.
  • Single-source: 2026-07-22/xentry-team-bitlocker-lotl-extortion-rmm-gpo — first-hand Kaspersky GERT IR analysis (reputable lab); credibility held at 2 pending corroboration.
  • Sub-agent note: the first S3 (research) spawn terminated early on the content-safety classifier before writing any findings; re-spawned with an Opus model override, which completed cleanly and returned three items. No S3 coverage lost.
  • Coverage gaps: cert-eu (feed low-cadence, latest 2026-06-10); cert-pl (latest 2026-06-12, already covered); ncsc-uk (latest 2026-07-15); cert-at (latest 2026-06-01); enisa (latest 2026-07-14, non-advisory); ncsc-ie (2026-07-20 Citrix/WordPress already KEV-covered); chrome-releases (feed returned 0 items — jina credit exhausted mid-run, recipe re-verification flagged); keycloak (fetched, no security items in window); crowdstrike / trellix / withsecure-labs / infoguard-labs / shadowserver / zimperium-zlabs (quiet in-window).
  • Watchlist: no product or supplier watchlists configured in this deployment — sweeps are no-ops (products checked=0, hits=0; suppliers checked=0, hits=0).
  • Essential-coverage: all essential-tier sources attempted; cert-eu, cert-pl, cert-at, ncsc-uk, enisa returned no in-window items (low-cadence feeds, not failures).

← Operations dashboard · run-record contract: docs/pipeline.md