2026-07-24T0409Z-intel
One pipeline fire, in full · intel run of 2026-07-24 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-24/2026-07-24T0409Z-intel.md.
Run telemetry
- Items returned
- 3
- Duration
- 15m 01s
- Tool calls
- 4 WebFetch5 WebSearch27 bridge
- Cited sources
- 6 of 14 in slice
- Items returned
- 2
- Duration
- 12m 26s
- Tool calls
- 14 WebFetch15 WebSearch12 bridge
- Cited sources
- 3 of 16 in slice
- Items returned
- 5
- Duration
- 16m 12s
- Tool calls
- 30 WebFetch4 WebSearch9 bridge
- Cited sources
- 6 of 15 in slice
- Items returned
- 3
- Duration
- 15m 04s
- Tool calls
- 10 WebFetch9 WebSearch22 bridge
- Cited sources
- 5 of 14 in slice
Verification
Deep dive
2026-07-24/laundry-bear-zimbra-zero-click-cve-2025-66376
Entries published (this run)
- BravoX ransomware leaks 220 GB from a Vaud fiduciary, exposing ~15 municipalities' data and a cantonal minister's tax file incident notable
- US agencies expand the Iranian PLC-intrusion advisory (AA26-097A) to Schneider Electric and Siemens controllers, with new project-file tampering detection threat notable
- German BKA dismantles Kratos, the Sneaky2FA-derived AiTM phishing-as-a-service platform behind ~15,000 monthly Microsoft 365 credential-theft campaigns threat notable
- Russian state actor LAUNDRY BEAR weaponised a Zimbra webmail zero-click (CVE-2025-66376) for mailbox exfiltration — now exposed in a 16-nation joint advisory threat high
- Mitel MiCollab AWV: unauthenticated command injection to full system compromise (CVSS 9.8, MTLVULN-1694, CVE pending) vulnerability notable
- msaRAT: Chaos ransomware's Rust RAT builds C2 through the Chrome DevTools Protocol so the malware process never opens a socket research notable
- MZ Automation libIEC61850: unauthenticated heap-overflow RCE via crafted MMS Initiate (CVE-2026-49035) plus four sibling OT-library flaws vulnerability notable
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
No source-list edits recorded for this run.
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| jina-reader-pool | n/a (transport pool) | jina | 402 Three of the four configured jina reader API keys reported HTTP 402 (balance exhausted) for the whole run, observed independently by S1, S2 and S4. As a result, | Sub-agents fell back to RSS-direct/WebFetch/bridge rungs and WebSearch; no in-window qualifying item was lost to the reader outage (the affected feeds surfaced |
| cert-pl | https://cert.pl/en/posts/ | webfetch → jina → bridge:url | 403 http_client cert.pl returned HTTP 403 to direct WebFetch, the jina-reader fallback (S1), and the main-agent bridge attempt (fetch_source.py url, also 403 via the reader). T | WebSearch substitute; no qualifying in-window CERT-PL item identified. |
Bridge invocations (this run)
8 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- fetch_source.py cisa page (AA26-204A LAUNDRY BEAR; AA26-097A CyberAv3ngers PLC; ICSA-26-204-06/-07 MZ Automation) ×1
- fetch_source.py cisa-kev (KEV sweep) ×1
- fetch_source.py enisa-euvd (CVE-2025-66376 EPSS/exploited-since) ×1
- fetch_source.py ncsc-csh recent (home-region sweep) ×1
- fetch_source.py bridge (all-rss-feed; LAUNDRY BEAR advisory) ×1
- fetch_source.py cert-fr feed (CERTFR-2026-AVI-0911 Mitel) ×1
- fetch_source.py bridge (news.xml; CyberAv3ngers PLC update) ×1
- feed (S4 CyberAv3ngers relay) ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 4 findings (truth=2, editorial=2, advisory=0) · Claude Opus 4.8 · 9m 17s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F14 ? | — | Entry said 'six-agency' update and listed six, but AA26-097A names seven authoring agencies (omitted the Department of the Treasury). | Reworded to 'Seven US federal agencies (CISA, FBI, NSA, EPA, the Department of Energy, US Cyber Command's Cyber National Mission Force and the Treasury)'. | |
| F4 hallucinated-fact | — | 'largely disruption-free 2023 Unitronics campaign' contradicts the advisory (the 2023 activity caused disruptive effects). | Reworded to contrast the 2023 HMI-defacement activity with the current campaign's direct control-logic manipulation and confirmed disruption, without claiming 2 | |
| F5 missing-citation | — | Uncited specific claim that Tycoon2FA 'resurged via OAuth device-authorization-grant abuse' — not in either cited source (BKA, Trend Micro). | Removed the specific Tycoon2FA/OAuth mechanism; kept the general resurgence-after-takedown pattern that follows from the affiliate-base-outlasts-infrastructure | |
| F5 missing-citation | — | Load-bearing 'October 2021' historical recurrence comparison carried no citation and is not in the cited Le Temps / 24 heures articles. | Removed the specific 2021 comparison; kept the structural-exposure lesson framed from this incident's own mechanics. |
Iteration #2 NEEDS_FIXES · 1 finding (truth=0, editorial=1, advisory=0) · Claude Sonnet 5 · 5m 57s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F5 missing-citation | — | All four iteration-1 findings confirmed remediated with no regressions. One new: the BravoX 'RAMP forum, January 2026, avoids CIS victims' background clause rode on the Le Temps citation but is a SOCR | Added SOCRadar (role: corroborating, https://socradar.io/blog/dark-web-profile-bravox-ransomware/, fetched this run) to sources[] and cited it inline for the RA |
Iteration #3 NEEDS_FIXES · 2 findings (truth=1, editorial=1, advisory=0) · Claude Opus 4.8 · 9m 05s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F14 ? | — | The '20-nation' / '~20 agencies' count (title, summary, body, source publisher label) matched neither the advisory's 16 nations nor its 27 co-sealing agencies; the sub-agents themselves disagreed on t | Reworded all count references (title, headline, summary, body, three source-publisher labels, registry summary, run-record note) to 'agencies from 16 nations', | |
| F5 missing-citation | — | The MISA-2026-0007 / OpenScape UC aside (CVSS 8.0, authenticated reflected XSS) rode on the CERT-FR citation, which lists 0007 but gives no CVSS/XSS/product detail; the specifics traced only to the un | Removed the MISA-2026-0007/OpenScape UC sentence and dropped 'Mitel OpenScape UC' from affected_products — the entry is about the MiCollab AWV command injection |
Iteration #4 NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 8m 38s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | Both iteration-3 fixes confirmed. New: the '2023 Unitronics defacing HMIs' comparison sat under a CISA-News citation that never discusses 2023 (the fact is Trend Micro's, cited elsewhere) — a citation | Removed the 2023 Unitronics comparison clause entirely (twice-flagged, non-load-bearing); the sentence now states only the current campaign's direct control-log | |
| F3 claim-not-supported | — | The 'evolved from Sneaky2FA' clause in the first sentence sat under the BKA citation, which never mentions Sneaky2FA (the lineage is Trend Micro's, correctly cited in the following sentence) — a citat | Removed the 'that evolved from the earlier Sneaky2FA kit and' clause from the BKA-cited first sentence; the Sneaky2FA-to-Kratos lineage remains established in t |
Iteration #5 NEEDS_FIXES cap-breach · 1 finding (truth=1, editorial=0, advisory=0) · Claude Opus 4.8 · 11m 38s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F14 ? | — | Incomplete iteration-1 remediation: the frontmatter summary still read 'A six-agency US update' while the body had been corrected to seven; the source/evidence publisher label also listed 6 of 7 (omit | Corrected the frontmatter summary to 'A seven-agency US update' and added the Treasury to the source/evidence publisher label, matching the already-correct body |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-07-24T0409Z-intel · Claude Opus 4.8 · window 26 h · 7 entries published
Verification & coverage notes
Seven entries published, zero updates. The window was genuinely eventful, led by a marquee espionage story that all four research sub-agents surfaced independently. No critical this run and no more than one deep dive.
Marquee item — quadruple corroboration. The 16-nation joint advisory AA26-204A on the Russian actor LAUNDRY BEAR (Void Blizzard / CL-STA-1114 / TA488) exploiting a view-based Zimbra webmail flaw (CVE-2025-66376) was returned by S1, S2, S3 and S4. CVE-2025-66376 is new to the store (it was KEV-listed in March 2026 but never carried an entry) and is a distinct flaw from the two other 2026 Zimbra Classic Web Client issues already tracked (the no-CVE code-exec fixed in 10.1.19 and the SNMP command-injection RCE fixed in 10.1.20); confirmed not a duplicate. Published as the day's deep dive (apt-campaign) at high — not critical: the patch is >1 week old and this is covert espionage exfiltration rather than an hour-critical RCE wave. The entry carries the two-jobs framing (patch AND evict, because the app-specific passcode survives the patch).
- Priority calibration: one deep dive, no criticals. The espionage campaign is
high(TL;DR-worthy, active exploitation of unpatched instances) but does not clear the extreme critical bar (no in-window new weaponisation; patch long available). The remaining six arenotable.
Single-source items and carve-outs:
- Single-source (national-CERT carve-out):
mz-automation-libiec61850-lib60870-ot-preauth-rce— CISA ICS-CERT is the sole authority for ICSA-26-204-06/-07 (Admiralty A).cyberav3ngers-plc-aa26-097a-schneider-siemens-expansionreaches multi-source (CISA advisory + CISA News + Trend Micro). - Single-source (research lab):
msarat-chaos-cdp-webrtc-covert-c2— Cisco Talos only (Admiralty B), included on detection value with the status recorded insourcing_note.
Borderline drops (recoverable):
- borderline-drop: Exploitarium / libssh2 CVE-2026-55200 (LevelBlue SpiderLabs) — the flagship libssh2 pre-auth OOB write is ALREADY covered store-wide (entries 2026-06-28 through 2026-07-05, including the public-PoC entry), so this is a dedup collision; also single-source and the finding carried an internal CVE-id inconsistency (2025 vs 2026-55200). Dropped.
- borderline-drop: Saxony-Anhalt state administration incident statistics (heise, 2026-07-23) — fresh and on-lens (EU state administration) but below the Tier 2/3 technical bar: no named actor, no CVE, no TTP beyond generic phishing/DDoS categories; the holiday-staffing-timing lesson is generic. Dropped.
- borderline-drop: Origin Energy (AU) ~5M-customer breach — no actor/TTP named, no Swiss/EU nexus; scale alone short of "genuinely global significance." (S4)
- borderline-drop: Upbound Group 8-K (US) — US consumer-finance fraud, company-assessed not material, no transferable TTP or nexus. (S4)
- borderline-drop: "The Gentlemen" mass leak-site postings (~10 EU claimed victims incl. Czech Philharmonic, Raben Group) — zero per-victim corroboration on any individual claim (fake-news guard requires victim disclosure or high-reliability journalism); the one CH claim in the same pull was a different, also-uncorroborated group. Actor already registered; flagged for awareness, not published. (S4)
- borderline-drop: Jscrambler EU/US bank tracking-pixel research (darkreading) — ~41 h stale, outside the 26 h window and not a developing continuation. (S4)
- borderline-drop: Lampion banking-trojan campaign vs Portugal (Acronis/darkreading) — a continuing campaign report, not a specific incident/victim disclosure; no distinct new TTP surfaced. (S4)
Completeness sweep: re-read all four findings sets including every borderline item; the two included borderline items (CyberAv3ngers PLC as multi-source; Mitel MiCollab on the exposed-appliance profile) were promoted with their rationale, and the drops above are all either duplicates, thin, out-of-window, or uncorroborated — no genuinely-relevant in-window item was left unpublished.
- Coverage gaps: cert-pl (403, transport block — WebSearch substitute found nothing qualifying); chrome-releases, keycloak, sansec-research, msrc-blog (feed 0-items via jina-fallback bug — MSRC CVE checks compensated via the msrc
cveAPI subcommand); csirt-acn-it, ccb-belgium (jina-key-exhaustion, no in-window items found via substitutes); apple-security (JS-rendered release table not extractable); sysdig (503, single-retry budget); group-ib, recordedfuture-insikt, google-tag, claroty-team82, nozomi-networks (listing pages without visible dates within time budget). - Essential-coverage: all essential sources attempted. cert-eu and cisa-directives were under-covered by the sub-agents and backfilled by the main agent at Phase 5 (both reachable, no in-window qualifying item). cert-pl was the only essential-tier failure (403 transport block via WebFetch, jina, and the bridge; no in-window qualifying item lost).
- Tooling note for the operator / weekly audit: (1) refresh the jina reader API-key pool — 3 of 4 keys are balance-exhausted (HTTP 402); (2) the bridge
feedsubcommand silently returns 0 items when it falls through to the jina reader for a feed URL, because it does not parse the reader's markdown — recommend a raw-HTML index fallback or restricting jina tourlfetches.
Watchlists: none configured in this deployment — product and supplier sweeps are no-ops (line omitted from the standard telemetry as unconfigured).
← Operations dashboard · run-record contract: docs/pipeline.md