ctipilot.ch

2026-07-24T0409Z-intel

One pipeline fire, in full · intel run of 2026-07-24 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-24/2026-07-24T0409Z-intel.md.

Run telemetry

2026-07-24T0409Z-intel intel prompt v3.28 publish ok
1h 44m duration 7 published 0 updates
Claude Opus 4.8 (claude-opus-4-8) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
15m 01s
Tool calls
4 WebFetch5 WebSearch27 bridge
Cited sources
6 of 14 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
12m 26s
Tool calls
14 WebFetch15 WebSearch12 bridge
Cited sources
3 of 16 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
16m 12s
Tool calls
30 WebFetch4 WebSearch9 bridge
Cited sources
6 of 15 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
15m 04s
Tool calls
10 WebFetch9 WebSearch22 bridge
Cited sources
5 of 14 in slice

Verification

#1 NEEDS_FIXES · Claude Opus 4.8 · t=2 e=2 a=0 #2 NEEDS_FIXES · Sonnet 5 · t=0 e=1 a=0 #3 NEEDS_FIXES · Claude Opus 4.8 · t=1 e=1 a=0 #4 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #5 NEEDS_FIXES · Claude Opus 4.8 · t=1 e=0 a=0

Deep dive

2026-07-24/laundry-bear-zimbra-zero-click-cve-2025-66376

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

No source-list edits recorded for this run.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
jina-reader-pooln/a (transport pool)jina402
Three of the four configured jina reader API keys reported HTTP 402 (balance exhausted) for the whole run, observed independently by S1, S2 and S4. As a result,
Sub-agents fell back to RSS-direct/WebFetch/bridge rungs and WebSearch; no in-window qualifying item was lost to the reader outage (the affected feeds surfaced
cert-plhttps://cert.pl/en/posts/webfetchjinabridge:url403 http_client
cert.pl returned HTTP 403 to direct WebFetch, the jina-reader fallback (S1), and the main-agent bridge attempt (fetch_source.py url, also 403 via the reader). T
WebSearch substitute; no qualifying in-window CERT-PL item identified.

Bridge invocations (this run)

8 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

8 ok
  • fetch_source.py cisa page (AA26-204A LAUNDRY BEAR; AA26-097A CyberAv3ngers PLC; ICSA-26-204-06/-07 MZ Automation) ×1
  • fetch_source.py cisa-kev (KEV sweep) ×1
  • fetch_source.py enisa-euvd (CVE-2025-66376 EPSS/exploited-since) ×1
  • fetch_source.py ncsc-csh recent (home-region sweep) ×1
  • fetch_source.py bridge (all-rss-feed; LAUNDRY BEAR advisory) ×1
  • fetch_source.py cert-fr feed (CERTFR-2026-AVI-0911 Mitel) ×1
  • fetch_source.py bridge (news.xml; CyberAv3ngers PLC update) ×1
  • feed (S4 CyberAv3ngers relay) ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 4 findings (truth=2, editorial=2, advisory=0) · Claude Opus 4.8 · 9m 17s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F14
?
Entry said 'six-agency' update and listed six, but AA26-097A names seven authoring agencies (omitted the Department of the Treasury).Reworded to 'Seven US federal agencies (CISA, FBI, NSA, EPA, the Department of Energy, US Cyber Command's Cyber National Mission Force and the Treasury)'.
F4
hallucinated-fact
'largely disruption-free 2023 Unitronics campaign' contradicts the advisory (the 2023 activity caused disruptive effects).Reworded to contrast the 2023 HMI-defacement activity with the current campaign's direct control-logic manipulation and confirmed disruption, without claiming 2
F5
missing-citation
Uncited specific claim that Tycoon2FA 'resurged via OAuth device-authorization-grant abuse' — not in either cited source (BKA, Trend Micro).Removed the specific Tycoon2FA/OAuth mechanism; kept the general resurgence-after-takedown pattern that follows from the affiliate-base-outlasts-infrastructure
F5
missing-citation
Load-bearing 'October 2021' historical recurrence comparison carried no citation and is not in the cited Le Temps / 24 heures articles.Removed the specific 2021 comparison; kept the structural-exposure lesson framed from this incident's own mechanics.

Iteration #2 NEEDS_FIXES · 1 finding (truth=0, editorial=1, advisory=0) · Claude Sonnet 5 · 5m 57s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F5
missing-citation
All four iteration-1 findings confirmed remediated with no regressions. One new: the BravoX 'RAMP forum, January 2026, avoids CIS victims' background clause rode on the Le Temps citation but is a SOCRAdded SOCRadar (role: corroborating, https://socradar.io/blog/dark-web-profile-bravox-ransomware/, fetched this run) to sources[] and cited it inline for the RA

Iteration #3 NEEDS_FIXES · 2 findings (truth=1, editorial=1, advisory=0) · Claude Opus 4.8 · 9m 05s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F14
?
The '20-nation' / '~20 agencies' count (title, summary, body, source publisher label) matched neither the advisory's 16 nations nor its 27 co-sealing agencies; the sub-agents themselves disagreed on tReworded all count references (title, headline, summary, body, three source-publisher labels, registry summary, run-record note) to 'agencies from 16 nations',
F5
missing-citation
The MISA-2026-0007 / OpenScape UC aside (CVSS 8.0, authenticated reflected XSS) rode on the CERT-FR citation, which lists 0007 but gives no CVSS/XSS/product detail; the specifics traced only to the unRemoved the MISA-2026-0007/OpenScape UC sentence and dropped 'Mitel OpenScape UC' from affected_products — the entry is about the MiCollab AWV command injection

Iteration #4 NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 8m 38s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
Both iteration-3 fixes confirmed. New: the '2023 Unitronics defacing HMIs' comparison sat under a CISA-News citation that never discusses 2023 (the fact is Trend Micro's, cited elsewhere) — a citationRemoved the 2023 Unitronics comparison clause entirely (twice-flagged, non-load-bearing); the sentence now states only the current campaign's direct control-log
F3
claim-not-supported
The 'evolved from Sneaky2FA' clause in the first sentence sat under the BKA citation, which never mentions Sneaky2FA (the lineage is Trend Micro's, correctly cited in the following sentence) — a citatRemoved the 'that evolved from the earlier Sneaky2FA kit and' clause from the BKA-cited first sentence; the Sneaky2FA-to-Kratos lineage remains established in t

Iteration #5 NEEDS_FIXES cap-breach · 1 finding (truth=1, editorial=0, advisory=0) · Claude Opus 4.8 · 11m 38s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F14
?
Incomplete iteration-1 remediation: the frontmatter summary still read 'A six-agency US update' while the body had been corrected to seven; the source/evidence publisher label also listed 6 of 7 (omitCorrected the frontmatter summary to 'A seven-agency US update' and added the Treasury to the source/evidence publisher label, matching the already-correct body

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-07-24T0409Z-intel · Claude Opus 4.8 · window 26 h · 7 entries published

Verification & coverage notes

Seven entries published, zero updates. The window was genuinely eventful, led by a marquee espionage story that all four research sub-agents surfaced independently. No critical this run and no more than one deep dive.

Marquee item — quadruple corroboration. The 16-nation joint advisory AA26-204A on the Russian actor LAUNDRY BEAR (Void Blizzard / CL-STA-1114 / TA488) exploiting a view-based Zimbra webmail flaw (CVE-2025-66376) was returned by S1, S2, S3 and S4. CVE-2025-66376 is new to the store (it was KEV-listed in March 2026 but never carried an entry) and is a distinct flaw from the two other 2026 Zimbra Classic Web Client issues already tracked (the no-CVE code-exec fixed in 10.1.19 and the SNMP command-injection RCE fixed in 10.1.20); confirmed not a duplicate. Published as the day's deep dive (apt-campaign) at high — not critical: the patch is >1 week old and this is covert espionage exfiltration rather than an hour-critical RCE wave. The entry carries the two-jobs framing (patch AND evict, because the app-specific passcode survives the patch).

  • Priority calibration: one deep dive, no criticals. The espionage campaign is high (TL;DR-worthy, active exploitation of unpatched instances) but does not clear the extreme critical bar (no in-window new weaponisation; patch long available). The remaining six are notable.

Single-source items and carve-outs:

  • Single-source (national-CERT carve-out): mz-automation-libiec61850-lib60870-ot-preauth-rce — CISA ICS-CERT is the sole authority for ICSA-26-204-06/-07 (Admiralty A). cyberav3ngers-plc-aa26-097a-schneider-siemens-expansion reaches multi-source (CISA advisory + CISA News + Trend Micro).
  • Single-source (research lab): msarat-chaos-cdp-webrtc-covert-c2 — Cisco Talos only (Admiralty B), included on detection value with the status recorded in sourcing_note.

Borderline drops (recoverable):

  • borderline-drop: Exploitarium / libssh2 CVE-2026-55200 (LevelBlue SpiderLabs) — the flagship libssh2 pre-auth OOB write is ALREADY covered store-wide (entries 2026-06-28 through 2026-07-05, including the public-PoC entry), so this is a dedup collision; also single-source and the finding carried an internal CVE-id inconsistency (2025 vs 2026-55200). Dropped.
  • borderline-drop: Saxony-Anhalt state administration incident statistics (heise, 2026-07-23) — fresh and on-lens (EU state administration) but below the Tier 2/3 technical bar: no named actor, no CVE, no TTP beyond generic phishing/DDoS categories; the holiday-staffing-timing lesson is generic. Dropped.
  • borderline-drop: Origin Energy (AU) ~5M-customer breach — no actor/TTP named, no Swiss/EU nexus; scale alone short of "genuinely global significance." (S4)
  • borderline-drop: Upbound Group 8-K (US) — US consumer-finance fraud, company-assessed not material, no transferable TTP or nexus. (S4)
  • borderline-drop: "The Gentlemen" mass leak-site postings (~10 EU claimed victims incl. Czech Philharmonic, Raben Group) — zero per-victim corroboration on any individual claim (fake-news guard requires victim disclosure or high-reliability journalism); the one CH claim in the same pull was a different, also-uncorroborated group. Actor already registered; flagged for awareness, not published. (S4)
  • borderline-drop: Jscrambler EU/US bank tracking-pixel research (darkreading) — ~41 h stale, outside the 26 h window and not a developing continuation. (S4)
  • borderline-drop: Lampion banking-trojan campaign vs Portugal (Acronis/darkreading) — a continuing campaign report, not a specific incident/victim disclosure; no distinct new TTP surfaced. (S4)

Completeness sweep: re-read all four findings sets including every borderline item; the two included borderline items (CyberAv3ngers PLC as multi-source; Mitel MiCollab on the exposed-appliance profile) were promoted with their rationale, and the drops above are all either duplicates, thin, out-of-window, or uncorroborated — no genuinely-relevant in-window item was left unpublished.

  • Coverage gaps: cert-pl (403, transport block — WebSearch substitute found nothing qualifying); chrome-releases, keycloak, sansec-research, msrc-blog (feed 0-items via jina-fallback bug — MSRC CVE checks compensated via the msrc cve API subcommand); csirt-acn-it, ccb-belgium (jina-key-exhaustion, no in-window items found via substitutes); apple-security (JS-rendered release table not extractable); sysdig (503, single-retry budget); group-ib, recordedfuture-insikt, google-tag, claroty-team82, nozomi-networks (listing pages without visible dates within time budget).
  • Essential-coverage: all essential sources attempted. cert-eu and cisa-directives were under-covered by the sub-agents and backfilled by the main agent at Phase 5 (both reachable, no in-window qualifying item). cert-pl was the only essential-tier failure (403 transport block via WebFetch, jina, and the bridge; no in-window qualifying item lost).
  • Tooling note for the operator / weekly audit: (1) refresh the jina reader API-key pool — 3 of 4 keys are balance-exhausted (HTTP 402); (2) the bridge feed subcommand silently returns 0 items when it falls through to the jina reader for a feed URL, because it does not parse the reader's markdown — recommend a raw-HTML index fallback or restricting jina to url fetches.

Watchlists: none configured in this deployment — product and supplier sweeps are no-ops (line omitted from the standard telemetry as unconfigured).

← Operations dashboard · run-record contract: docs/pipeline.md