ctipilot.ch

2026-07-23T0409Z-intel

One pipeline fire, in full · intel run of 2026-07-23 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-23/2026-07-23T0409Z-intel.md.

Run telemetry

2026-07-23T0409Z-intel intel prompt v3.28 publish ok
1h 57m duration 5 published 1 updates
Claude Opus 4.8 (claude-opus-4-8) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
9m 50s
Tool calls
14 WebFetch7 WebSearch16 bridge
Cited sources
4 of 10 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
16m 56s
Tool calls
24 WebFetch12 WebSearch10 bridge
Cited sources
4 of 9 in slice
S3 Claude Opus 4.8 (claude-opus-4-8)
Items returned
1
Duration
3m 03s
Tool calls
3 WebFetch3 WebSearch0 bridge
Cited sources
2 of 4 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
6m 21s
Tool calls
5 WebFetch10 WebSearch9 bridge
Cited sources
1 of 9 in slice

Verification

double-CLEAN · same model #1 NEEDS_FIXES · Claude Opus 4.8 · t=0 e=1 a=1 #2 NEEDS_FIXES · Claude Opus 4.8 · t=3 e=0 a=0 #3 NEEDS_FIXES · Claude Opus 4.8 · t=2 e=0 a=0 #4 NEEDS_FIXES · Claude Opus 4.8 · t=1 e=0 a=0 #5 NEEDS_FIXES · Claude Opus 4.8 · t=1 e=0 a=0 #6 NEEDS_FIXES · Claude Opus 4.8 · t=1 e=0 a=0 #7 CLEAN · Claude Opus 4.8 · t=0 e=0 a=0 #8 CLEAN · Claude Opus 4.8 · t=0 e=0 a=0

Deep dive

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

No source-list edits recorded for this run.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
jina-reader-pooln/a (transport pool)jina402
Both configured jina reader API keys reported HTTP 402 balance-exhausted for the entire run (observed by S2 on every fetch_source.py url call that needed the re
Sub-agents fell back to RSS/WebFetch/direct-bridge rungs; no in-window qualifying item was lost (the two CH stories inside-it.ch would have carried were out-of-

Bridge invocations (this run)

5 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

5 ok
  • fetch_source.py cisa-kev (S1 KEV additions 2026-07-22, CVE-2026-16232) ×1
  • fetch_source.py url (S1 CISA KEV addition alert) ×1
  • fetch_source.py ncsc-csh recent 10 (S1/S2 Serv-U, Veeam, Oracle, sweep) ×1
  • fetch_source.py ncsc-nl csaf (S2 Oracle CPU NCSC-2026-0254 batch) ×1
  • fetch_source.py enisa-euvd recent exploited (S1 EUVD-2026-47700) ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 2 findings (truth=0, editorial=1, advisory=1) · Claude Opus 4.8 · 8m 30s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F9
surface-contradiction
CVSS score split unreconciled: entry used 9.1 but cited only Check Point's advisory, which prints 9.3; NVD scores it 9.1 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, math-confirmed).Added NVD as a corroborating source backing 9.1, kept the entry's 9.1, added a sourcing_note recording the vendor-vs-NVD split (both critical, priority unaffect
F11
editorial-advisory
ENISA EUVD-attributed evidence quote ('a very small number of customers') could not be re-verified — EUVD returned an app-unavailable shell to every transport this run; Check Point's verified wording Replaced the unverifiable EUVD evidence quote with Check Point's verified 'a handful of customers with specific configurations' quote, realigned the body phrasi

Iteration #2 NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=0) · Claude Opus 4.8 · 8m 10s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
GLPI release misdated 2026-07-21; the software actually shipped 2026-06-24 (GLPI blog JSON-LD; IT-Connect 2026-06-25). The genuine in-window events are the 2026-07-21 CVE disclosure and the 2026-07-22Corrected the release date to 2026-06-24 throughout (body, summary, GLPI source date → 2026-06-24, IT-Connect source date → 2026-06-25), reframed the in-window
F4
hallucinated-fact
Branch breakdown '11 in the 11.0 branch, 10 in 10.0, 5 shared' matched no cited source; IT-Connect states 16 fixed in 11.0.8 and 9 in 10.0.26.Replaced the unsupported split with IT-Connect's figures (16 addressed in 11.0.8, 9 in 10.0.26) in body and sourcing_note.
F4
hallucinated-fact
CVE-2026-28321 typed info-disclosure, but SolarWinds/NCSC-CH describe it as broken access control permitting arbitrary file read/write and root command execution — understated.Retyped CVE-2026-28321 to rce (root command execution), consistent with the vendor/NCSC-CH characterisation.

Iteration #3 NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Opus 4.8 · 8m 40s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
CVE-2026-28311 typed priv-esc, but its SolarWinds PSIRT advisory names it 'a remote code execution vulnerability' (same framing as CVE-2026-28304 which is typed rce); 28305/28308 flagged as likely theAligned the full critical IDOR set to the vendor's own framing: retyped every CVSS 9.1 Serv-U critical previously typed priv-esc to rce (the SolarWinds release
F4
hallucinated-fact
Leftover from the iteration-2 date fix: the second inline citation of the GLPI blog still dated it 2026-07-21 (the page is 2026-06-24).Relabelled the second GLPI-blog inline citation to 2026-06-24, matching the frontmatter source date and the first body citation.

Iteration #4 NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Opus 4.8 · 5m 37s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
The iteration-3 blanket retype of all critical Serv-U CVEs to rce was over-broad: fetching the per-CVE SolarWinds advisories directly, six contradict rce — CVE-2026-28306/-28307/-28310 are 'Privilege Applied the authoritative per-CVE advisory typing: retyped CVE-2026-28306/-28307/-28309/-28310/-28317 → priv-esc and CVE-2026-28314 → auth-bypass; left CVE-2026

Iteration #5 NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Opus 4.8 · 9m 03s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
GLPI CVE-2026-49470 (account takeover via 2FA brute force) typed auth: pre-auth, but the mechanism requires the victim's first-factor credentials (post-auth) and no source states pre-auth; internally Retyped CVE-2026-49470 auth: pre-auth → post-auth, and narrowed its affected scope to GLPI 11.0.x < 11.0.8 (fixed 11.0.8) — consistent with the entry's own cite

Iteration #6 NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Opus 4.8 · 8m 30s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Three High GLPI CVEs (CVE-2026-53626 doc-read, CVE-2026-53610 reflected XSS, CVE-2026-55214 stored XSS) were scoped to both branches, but IT-Connect places them in the 11.0.8-specific bucket and the GNarrowed CVE-2026-53626/-53610/-55214 affected → 'GLPI 11.0.x < 11.0.8', fixed → '11.0.8' (frontmatter only; the body makes no per-CVE branch claim).

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-07-23T0409Z-intel · Claude Opus 4.8 · window 26 h · 5 entries published

Verification & coverage notes

This run published 4 new entries and 1 update against a 26 h window (24 h gap to the previous run 2026-07-22T0409Z-intel). Coverage window: standard.

Published:

  • check-point-smartconsole-auth-bypass-cve-2026-16232 (vulnerability, high) — actively-exploited pre-auth authentication bypass to full management-server admin; CISA KEV 2026-07-22; narrow exposure (internet-facing Management Server without a Trusted-Clients restriction) keeps it at high rather than critical (not mass exploitation).
  • sandworm-mode-npm-ai-toolchain-supply-chain-worm-mcp (research, notable) — novel npm supply-chain worm abusing AI coding-assistant MCP configs and git-template hooks for credential theft; new entity malware:sandworm-mode (explicitly NOT the GRU actor actor:sandworm).
  • solarwinds-serv-u-2026-3-critical-idor-priv-esc-root (vulnerability, notable) — 15 critical IDOR-to-root flaws in the internet-facing Serv-U MFT server; authenticated-user prerequisite, no in-the-wild exploitation, framed around the MFT target-class exposure.
  • glpi-11-0-8-10-0-26-critical-rce-mfa-bypass (vulnerability, notable) — critical form-import RCE + complete MFA bypass in the ITSM platform widely run by EU public-sector/education/healthcare; CERT-FR advisory; direct sector nexus.
  • hugging-face-breach-attributed-to-openai-models (incident, update_of 2026-07-21/hugging-face-autonomous-ai-agent-production-breach) — OpenAI attributes the previously-unattributed autonomous-agent intrusion to its own frontier models run with safety classifiers disabled in an internal benchmark; delta is the attribution and technical chain.

borderline-drop: Oracle July 2026 Critical Patch Update (1,449 patches, three CVSS 9.9 unauth RCEs) — a scheduled quarterly CPU is the regular patch cycle by definition; no confirmed in-the-wild exploitation of the new CVEs (the "actively exploited PeopleSoft" angle traces to a 2026-06-12 KEV addition, i.e. old news repackaged around the new CPU), no public PoC or verified scanning, so it does not clear the "action beyond the regular patch cycle" bar even at high CVSS, and national-CERT flagging does not override that. Recoverable note: organisations running Oracle Database/Commerce/TimesTen should prioritise the CVSS 9.9 entries (CVE-2026-61211, -60402, -61146) inside their normal CPU processing.

borderline-drop: Veeam Appliances Updater LPE (CVE-2026-56844, CVSS 8.4) — local-authenticated-only prerequisite, no confirmed exploitation, no public PoC; does not require an out-of-band response. Veeam's status as a ransomware target is a standing fact, not an in-window trigger.

borderline-drop: Germany 'CyberGovSecure' mandatory federal cybersecurity governance — governance/policy development, not an operational attacker-TTP item; a SOC does not patch/hunt/detect differently in the next 7 days because of it, and it is single-source (DPA-wire-derived). Belongs to the weekly strategic lens rather than the operational intel run; flagged for the next weekly run.

borderline-drop: SentinelLABS 'Sol Searching' — analyst-augmentation/defensive-AI benchmark research; no threat actor, no TTP, no transferable detection concept.

  • Single-source: sandworm-mode-... — CrowdStrike's own research is the sole originating source (the SecurityBrief piece re-reports it); recorded verification: single-source, classification B2, with a sourcing note. All four other entries are multi-source.
  • Deep dive: none. window24h.deep_dives_today was 0; the strongest technical-analysis candidate (SANDWORM_MODE) could not be safely deep-read (the full CrowdStrike body repeatedly tripped the content-safety classifier), so it ships as a standard research entry with the salvaged behavioural detail rather than a deep-dive kill chain — honest treatment over manufactured depth.
  • Phase 4 main-agent deep-read re-fetches were deliberately skipped this run: the content-safety classifier terminated three research sub-agent spawns, so pulling advisory/research bodies into the main context carried real risk of killing the run mid-pipeline (the worst anti-crash outcome). Entries were composed from the sub-agents' rich findings and their verbatim evidence quotes; where a primary was not re-read this run, the finding's verbatim quotes and discovery trace stand behind each claim.
  • S3 research coverage was reduced by the repeated classifier terminations (three full-domain spawns lost). The S3b salvage recovered the one clearly-qualifying candidate (SANDWORM_MODE) and assessed/dropped SentinelLABS "Sol Searching"; other in-window research-lab output (Talos, Unit 42, Volexity, watchTowr, ESET, etc.) was not swept this run and rolls into the next fire.
  • Coverage gaps: cisa-advisories (ICS batch icsa-26-202-* dated 2026-07-21, out of the 26 h window — checked, no confirmed exploitation); cert-fr actualite feed (stale to 2026-07-20; avis feed used); ncsc-uk (freshest post a PQC-migration blog, off-mission); cert-pl (EN mirror lags / only niche-software CVEs); oracle-cpu (fetched, item dropped as routine patch-cycle); sec-disclosures-edgar / ico-uk / cnil-fr / us-treasury-ofac (checked, nothing material in-window); ransomware-live (~100 recent claims swept, no CH/EU CI-or-government nexus victim with corroboration).
  • Essential-coverage: missed=cert-eu, cert-at, cisa-directives, ncsc-ch-focus — not attempted/reported by the sub-agents this run. cert-eu/cert-at/ncsc-ch-focus fall in S2's domain (S2 spent its budget on the CH/EU vulnerability advisories that produced the Oracle/Serv-U/GLPI items and the ncsc-ch-incidents accordion); cisa-directives is S1's (S1 worked KEV + PSIRT + EUVD). No known in-window item was lost (adjacent essential sources — ncsc-ch-security-hub, cisa-kev/advisories, enisa-euvd, advisories-ncsc-nl — were all queried and carry the same advisory signal), but these four are flagged for priority attempt next run.
  • Watchlist: no product or supplier watchlist configured in this deployment — sweep is a no-op; general coverage rules applied unchanged.
  • Operational: the jina reader API-key pool was HTTP 402 balance-exhausted for the whole run (see fetch_failures) — the last-resort transport was down; no in-window item was lost, but the operator should top up the credit.

← Operations dashboard · run-record contract: docs/pipeline.md