ctipilot.ch

2026-07-25T0409Z-intel

One pipeline fire, in full · intel run of 2026-07-25 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-25/2026-07-25T0409Z-intel.md.

Run telemetry

2026-07-25T0409Z-intel intel prompt v3.28 publish ok
36m 57s duration 7 published 2 updates
Claude Opus 4.8 (claude-opus-4-8) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
14m 30s
Tool calls
9 WebFetch15 WebSearch28 bridge
Cited sources
5 of 14 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
14m 21s
Tool calls
15 WebFetch20 WebSearch12 bridge
Cited sources
0 of 19 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
11m 00s
Tool calls
17 WebFetch2 WebSearch9 bridge
Cited sources
2 of 18 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
10m 08s
Tool calls
12 WebFetch15 WebSearch8 bridge
Cited sources
2 of 9 in slice

Verification

✓ double-CLEAN · Claude Opus 4.8 + Sonnet 5 #1 NEEDS_FIXES · Claude Opus 4.8 · t=1 e=1 a=0 #2 NEEDS_FIXES · Sonnet 5 · t=2 e=4 a=0 #3 CLEAN · Claude Opus 4.8 · t=0 e=0 a=0 #4 NEEDS_FIXES · Sonnet 5 · t=2 e=1 a=0 #5 CLEAN · Claude Opus 4.8 · t=0 e=0 a=0 #6 CLEAN · Sonnet 5 · t=0 e=0 a=1

Deep dive

2026-07-25/ta458-roundpress-webmail-zero-days-sogo-cve-2026-8496

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

No source-list edits recorded for this run.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
jina-reader-pooln/a (transport pool)jina402
The configured jina reader API keys reported HTTP 402 (balance exhausted) for the whole run, observed independently by S1, S2, S3 and S4. Any host requiring the
Direct/RSS/bridge transports (WebFetch, fetch_source.py cisa page / msrc cve / ncsc-csh / cisa-kev) and WebSearch covered the in-window landscape; no qualifying
cisa-advisorieshttps://www.cisa.gov/news-events/cybersecurity-advisoriesbridge:cisajina403 http_client
The CISA cybersecurity-advisories listing page rendered only its JS filter UI via the bridge and Akamai-403s every UA; the jina reader (which routes cisa.gov de
cisa page detail-fetch + cisa-kev api + ncsc-uk RSS (co-signed joint advisories) as substitutes; no in-window qualifying CISA item missed.

Bridge invocations (this run)

4 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

4 other
  • ×4

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 2 findings (truth=1, editorial=1, advisory=0) · Claude Opus 4.8 · 8m 45s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Binary/function names (certpdef.dll, _LoadPrincipalObject, certsrv.exe) as the vulnerable code path appear in neither cited source (MSRC nor CybersecurityNews); likely carried from the dropped researcRemoved the binary/function-name parenthetical; the chase / cdc / rmd mechanism, DCSync-krbtgt outcome and SERVER_TRUST_ACCOUNT patch gate are retained as Cyber
F5
missing-citation
The 'Lynx rebrand / FortiGate credential-theft overlap' attribution driving a FortiGate-edge recommendation carried no inline citation (registry-documented via SOCRadar 2026-07-01 but not fetched thisRemoved the uncited Lynx/FortiGate specifics and the FortiGate recommendation; kept the target-class relevance and the network-isolation/backup lesson the victi

Iteration #2 NEEDS_FIXES · 7 findings (truth=2, editorial=4, advisory=0) · Claude Sonnet 5 · 11m 21s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
iter1-confirm
?
Both iteration-1 fixes verified good — Certighost binary-name removal confirmed against the CybersecurityNews article; Autismuslink Lynx/FortiGate removal confirmed against the decompressed victim PDFn/a — confirmation only.
F3
claim-not-supported
Body carried a quoted phrase ('obscured true destination from scanners and recipients') that is not verbatim in the cited Microsoft source.Removed the quotation marks and reworded as a paraphrase supported by the source's description of the OAuth redirect chain.
F4
hallucinated-fact
An evidence[] quote spliced two Proofpoint sentences with an ellipsis and dropped the hedge 'While it cannot be confirmed,'.Replaced with the single contiguous first sentence ('Proofpoint has not observed TA458 using CVE-2025-66376, despite the group's regular access to webmail XSS z
F9
surface-contradiction
Unsurfaced attribution divergence — ESET's original Operation RoundPress reporting associated the activity with Sednit/APT28, while Proofpoint's TA458 disclaims overlap with TA422/APT28.Surfaced the divergence in both sourcing_note and body: the TA458 and RoundPress labels are overlapping tracking, not a confirmed single actor, and the GRU unit
F17
?
credibility: 1 on headline claims that are single-vendor-sourced (Proofpoint) per the entry's own sourcing note.Lowered classification.credibility 1 -> 2 (reliability B retained).
F17
?
credibility: 1 on the mechanics/persistence delta that is single-vendor-sourced (Proofpoint).Lowered classification.credibility 1 -> 2 (reliability B retained).
F18
?
A TA458 action item partially restated the body's compensating-WAF hardening guidance.Rewrote the action to the do-now inventory/patch-prioritization task; the WAF-coverage restatement was dropped (it remains only in the body hardening).

Iteration #4 NEEDS_FIXES · 3 findings (truth=2, editorial=1, advisory=0) · Claude Sonnet 5 · 10m 53s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
CVE-2026-62144 was scored 'Check Point CVSS 9.3' in four places, but no cited source states 9.3 — Check Point's advisory carries only a qualitative 'High' (no numeric CVSS 3.1), and the numeric score Set frontmatter cvss to the NCSC-NL CVSS v4 10.0 (the only numeric score its cited sources carry) and reworded summary, body and sourcing_note to attribute it t
F4
hallucinated-fact
Body stated 'the NCSC was notified'; the cited victim PDF names only unspecified federal authorities, not the NCSC.Reworded to 'the relevant authorities were notified and a criminal complaint filed with the police' to match the PDF.
F5
missing-citation
Uncited claim that INC Ransom has 'a documented focus on exactly those sectors' (social-services/education) — not in the registry summary or any cited source.Removed the sector-focus claim; the Defender takeaway now rests on the victim's own exposure profile and INC Ransom's sourced encrypt-and-exfiltrate double-exto

Iteration #6 CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Sonnet 5 · 13m 15s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
Advisory-level: the SOGo 5.12.8 release corroborating source was dated '2026-07' in frontmatter, but the GitHub release page shows it was released 12 May 2026. Does not touch any claim, quote, or the Corrected the source date to 2026-05-12.

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-07-25T0409Z-intel · Claude Opus 4.8 · window 26 h · 7 entries published

Verification & coverage notes

Standard 26 h window (gap 24 h to the previous run 2026-07-24T0409Z-intel; previous run published ok). No scheduler outage, no S5 (empty intel/). Seven entries published (three vulnerability/threat at high, four at notable), two of them updates; one deep dive; zero critical.

Deep-dive selection. TA458/Operation RoundPress was taken as the day's deep dive under selection criterion 1 (active in-the-wild exploitation of half-click webmail zero-days, including a fresh SOGo zero-day CVE-2026-8496, plus non-trivial exposure — self-hosted webmail is common in EU/CH public-sector estates). Its category (apt-campaign) also carried yesterday's deep dive (Laundry Bear/Zimbra), which would normally demote it one rank; criterion 1 exempts that demotion, and the item is a distinct actor with a materially broader five-platform zero-day supply, so it independently earns the treatment rather than repeating yesterday's story. window24h.deep_dives_today was 0 before this run.

Update decisions. Two update_of entries carry genuine deltas, not recaps: the Check Point siblings (CVE-2026-62144 unauthenticated management command execution, CVE-2026-62145 Gaia Portal read-only-to-root) sit on the same actively-attacked management surface as the previously-covered CVE-2026-16232; the LAUNDRY BEAR/ZimReaper entry adds the CSS-@import sanitizer-bypass mechanics, DNS-tunnelled exfil, and — the load-bearing delta — a "ZimbraWeb" application-specific password that survives a password reset and the patch, changing the remediation. ZimReaper is already registered as an alias of tool:ulej-flowerbed; no new malware entity was created.

Dedup notes. The Thailand AI-agent incident's LinPEAS-probed Linux-kernel LPE CVEs (CVE-2026-43503/31431/43284) and Roundcube's CVE-2025-49113 are all already in the store; those CVEs were reconnaissance probes / chain context, not the finding, so the Thailand and RoundPress entries carry only genuinely-new CVEs in cves[] (RoundPress: CVE-2026-8496 only; Thailand: none) to avoid re-asserting covered ground.

Borderline drops (recoverable):

  • borderline-drop: Flare EMEA-healthcare ransomware supply-chain landscape (Kazu) — single-source (the underlying Flare post could not be located; only Help Net Security relaying it), a leak-site-derived victimology/actor census with no intrusion vector, CVE or detection concept; strategic-landscape framing belongs to the weekly, and its defender takeaway is generic vendor-risk practice. New actor "Kazu" not registered (only entities referenced by a published entry are added).
  • borderline-drop: GTIG cryptonym actor-naming taxonomy change — first-party methodology announcement, no attacker tradecraft or detection/hunt value; a Tier 2/3 SOC would not act differently in the next 7 days.

Out-of-window / dropped-by-S1 (logged for awareness): ManageEngine ADAudit Plus CVE-2026-6516 (vendor advisory actually April 2026, NCSC-NL merely re-cataloguing); Bing/XBOW ImageMagick SVG RCE (Microsoft-side already fixed, no customer action); Azure Portal CVE-2026-62835 (Microsoft-mitigated); Johnson Controls C-CURE 9000 ICSA-26-204-01 (same 204-XX batch already surfaced 2026-07-24, no fresh delta); Synacktiv Argo CD unauthenticated RCE (24 days old, no in-window development — flagged for the weekly W1 as a still-open high-severity unpatched issue); Cisco SD-WAN CVE-2026-20245 (published ~84 h before run, outside the developing-window allowance).

Single-source / carve-outs: microsoft-email-threat-landscape-q2-2026 is single-source by nature (first-party vendor threat-landscape report on Microsoft's own telemetry); thailand-finance-ministry-hermes-ai-agent is single-source (Hunt.io is the sole primary investigation; BleepingComputer re-reports it) with compromise unconfirmed by the victim — framed as a targeting/tradecraft disclosure, not a confirmed breach. stiftung-autismuslink rests on a first-party victim statement (Admiralty A for its own incident) corroborated by the INC Ransom leak-site claim; the INC Ransom attribution is leak-site-based, not victim-confirmed.

Verification-fix telemetry robustness: first-attempt S1 and S2 spawns terminated immediately on the Sonnet real-time cyber-safeguard classifier ("Sonnet 5's safeguards flagged this message"); both were re-spawned once with reframed defender-vantage tasking and returned normally. This is a spawn-time classifier false positive on legitimate defensive CTI research, not a research failure; recorded here for operator awareness of the safeguard-interruption pattern on the pinned Sonnet research role.

  • Coverage gaps: cisa-advisories (JS listing + Akamai-403, jina pool exhausted — detail pages reachable via cisa page); cert-pl (403 to the Phase-1 sub-agents on direct/jina, but recovered on a Phase-5 re-check via fetch_source.py url https://cert.pl/en/news/ returning HTTP 200 — no in-window item clearing the action-required bar); jina-reader-pool (HTTP 402 balance exhausted, third consecutive run — operator top-up needed); sekoia, recordedfuture-insikt, huntress, group-ib (jina-402 / no in-window content); volexity, horizon3-ai, eset, crowdstrike, withsecure-labs, lab52, intrinsec, cert-at (reachable, no in-window items).
  • Watchlist: no watchlists configured — sweep is a no-op (S1 products, S4 suppliers both 0/0).
  • Essential-coverage: the cisa-advisories listing was not enumerable directly (Akamai-403 + jina-402) but detail pages, cisa-kev and the ncsc-uk co-signed feed substituted with no in-window qualifying item lost; cert-pl recovered via the url bridge on re-check (no qualifying item). All 15 essential sources attempted.

← Operations dashboard · run-record contract: docs/pipeline.md