2026-07-26T1308Z-audit
One pipeline fire, in full · audit run of 2026-07-26 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-26/2026-07-26T1308Z-audit.md.
Run telemetry
- Items returned
- 4
- Duration
- 12m 24s
- Tool calls
- 14 WebFetch11 WebSearch22 bridge
- Cited sources
- none
- Items returned
- 5
- Duration
- 18m 02s
- Tool calls
- 30 WebFetch20 WebSearch10 bridge
- Cited sources
- none
- Items returned
- 5
- Duration
- 15m 08s
- Tool calls
- 20 WebFetch16 WebSearch14 bridge
- Cited sources
- none
- Items returned
- 15
- Duration
- 26m 37s
- Tool calls
- not reported
- Cited sources
- none
- Items returned
- 15
- Duration
- 28m 38s
- Tool calls
- not reported
- Cited sources
- none
- Items returned
- 13
- Duration
- 22m 49s
- Tool calls
- not reported
- Cited sources
- none
- Items returned
- 14
- Duration
- 16m 27s
- Tool calls
- not reported
- Cited sources
- none
Verification
Deep dive
—
Entries published (this run)
- CVE-2026-63030 / CVE-2026-60137 (WP2Shell) — WordPress Core pre-auth RCE chain moves to confirmed in-the-wild exploitation and CISA KEV vulnerability high update
- ANCPI Romania — DNSC interim report confirms vCenter-to-ESXi ransomware and exfiltration of ~2 million ePayment user records incident notable update
- IFAGE Geneva — DragonForce publishes the stolen data, exposing student exam results the institute had said were unaffected incident notable update
- FakeAgent — malvertising hosts a fake AI-desktop-app download page on the vendor's own trusted domain, delivering SectopRAT by DLL side-loading threat notable
- An exposed WebDAV delivery lab shows industrialised .url/.lnk lure testing against CVE-2025-33053, with LLM-written tooling and ClickFix pages research notable
- Langflow correction — 1.10.1 is not the endpoint: CVE-2026-14499 needs 1.10.2, and CVE-2026-0770 has no AUTO_LOGIN precondition vulnerability notable update
- CVE-2026-61425 — Balbooa Gridbox for Joomla: a client-supplied cookie is accepted as proof of identity, giving anonymous Super User access vulnerability notable
- Oracle July 2026 CPU — nine unauthenticated CVSS 10.0 flaws in Fusion Middleware, with NCSC-NL assessing large-scale abuse as very likely in the short term vulnerability notable
- TELESHIM / MIXEDKEY / BINDCLOAK — DLL side-loading under a legitimate vendor binary, Telegram-API C2 and volume-serial environmental keying against government networks research notable
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
11 status · 2 notes · 1 fetch_method+notes · 1 added-candidate.
| Source | Change | From → To | Reason |
|---|---|---|---|
| proofpoint | status | — → — | candidate → active: cited by published entries from 11 distinct runs (bar is 3); promotion had never been executed because nothing counted contributing runs |
| sysdig | status | — → — | candidate → active: 7 contributing runs |
| socradar | status | — → — | candidate → active: 6 contributing runs |
| mysites-guru | status | — → — | candidate → active: 5 contributing runs |
| swisscybersecurity-net | status | — → — | candidate → active: 5 contributing runs |
| jamf-threat-labs | status | — → — | candidate → active: 4 contributing runs |
| onapsis | status | — → — | candidate → active: 4 contributing runs |
| reliaquest | status | — → — | candidate → active: 4 contributing runs |
| searchlight-cyber | status | — → — | candidate → active: 4 contributing runs |
| netzwoche | status | — → — | candidate → active: 3 contributing runs |
| ox-security | status | — → — | candidate → active: 3 contributing runs |
| cisa-advisories | notes | — → — | fires logged HTTP 403 sweeping the HTML listing in the url field even though the working feed URL was already on the record as rss_url and a 2026-07-10 note already said to prefer it — an ignored-recipe problem, not a missing one; the note now says so in the imperative |
| ncsc-uk | notes | — → — | the 2026-07-13 note calling the combined feed path unresolved is stale — the feed resolved cleanly this run |
| ccb-belgium | fetch_method+notes | — → — | bridge → jina: WebFetch and the generic url bridge return only cookie-consent boilerplate; the reader returns the full dated advisory listing |
| zscaler-threatlabz | added-candidate | — → — | a major research lab absent from the slice entirely — its in-window government-espionage toolkit analysis had no curated discovery path (this run's one new candidate) |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 16 findings (truth=12, editorial=2, advisory=2) · Claude Opus 5 · 16m 54s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | Adjacency defect. Fetched the full NCSC-2026-0252 advisory (jina, 7355 chars) and its CSAF (https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0252-0.json): none of the four version strings 12.2.1.4.0 | Re-attributed every Data Integrator / Coherence version string and component name to Oracle's own risk matrix with a separate Oracle citation; cves[].affected n applied | |
| F4 hallucinated-fact | — | Fabricated quotation. Fetched https://www.csoonline.com/article/4200184/... in full: this sentence does not appear. CSOonline's actual text is 'Fusion Middleware was particularly hard hit, with new se | Removed the fabricated quotation; the entry now quotes CSOonline's actual sentence and Oracle's own sentence, both verbatim. applied | |
| F14 quantifier-without-source | — | The entry's own primary source contradicts the count: NCSC-2026-0252 states 'De ernstigste kwetsbaarheden, 9 stuks, hebben de hoogste score van 10.0 gekregen' and its CSAF lists exactly nine CVEs (470 | Corrected to nine distinct CVEs in title, summary and body, and added a paragraph stating the divergence explicitly (ten matrix rows because CVE-2026-60365 is d applied | |
| F3 claim-not-supported | — | Adjacency defect. Fetched the BleepingComputer article in full via the jina reader (15,620 chars): 'blockchain' 0 occurrences, 'autofill' 0, 'payment' 0 (it does carry 'hands-on', 'credential', 'cooki | Re-attributed the autofill / payment-data / Ethereum-blockchain-C2 clause to Huntress with its own citation; BleepingComputer now carries only the SectopRAT ide applied | |
| F3 claim-not-supported | — | Adjacency defect. Fetched the cited Hacker News article: 'invoice' 0 occurrences, 'salary' 0 (it does carry the Rapid7 quote — 'Rapid7's summary is blunt: "the attacker used LLMs to operate more like | Split the citation: the LLM quote keeps its Hacker News citation (THN does quote it), and the invoice / salary lure-theme specifics are attributed to Rapid7 wit applied | |
| F4 hallucinated-fact | — | Spliced quote, not a contiguous substring. The Zscaler post contains two DIFFERENT sentences: (a) 'TELESHIM abused the Telegram API for C2 communication to blend in with legitimate internet traffic.' | Replaced the hybrid with the C2-section sentence verbatim in both evidence[] and the body. applied | |
| F3 claim-not-supported | — | The cited source states the opposite premise. 20 minutes (fetched in full via jina, 38,950 chars): 'La fondation avait aussi affirmé qu'elle n'avait pas reçu de demande de rançon, mais que, le cas éch | Removed the 'declined to pay' causation everywhere and added a paragraph giving IFAGE's actual position with the French verbatim, stating that publication canno applied | |
| F3 claim-not-supported | — | Date off by one against the cited source. The 20 minutes article is itself timestamped 'Publié 24. juillet 2026, 14:22' and says of the publication: 'C'est chose faite depuis jeudi, selon «Le Temps»' | Corrected the publication date to 2026-07-23 ('depuis jeudi') in summary, body and event_date; the 20 minutes article's own 2026-07-24 date stays in sources[]. applied | |
| F4 hallucinated-fact | — | Word substituted inside a verbatim quote. The source sentence begins 'Leur divulgation par les cybercriminels concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, et | Restored 'Leur divulgation…' as the verbatim opening. applied | |
| F4 hallucinated-fact | — | The artifact contradicts this: work/2026-07-26T1308Z-audit/truth-B4.yaml carries machine_surface: true on entries/2026-07-19/weekly-w29-exploited-internet-facing-enterprise-software.md (24 records fal | Rephrased in the report and aligned the run record and B4 telemetry: 56 of 57 records returned machine_surface false; the single flag was reviewed and rejected applied | |
| F4 hallucinated-fact | — | Overstated against the report's own breakdown and against the run record. § Imprecisions splits the 22 into 'Per-fact attribution (12)', 'Boundary and scope precision (6)' and 'Novelty and quote fidel | Corrected to 9 imprecisions plus 2 of the 3 factual errors (11 in all) in the report Verdict, and aligned the run record and the CHANGELOG 3.29 entry to the sam applied | |
| F4 hallucinated-fact | — | No truth-pass artifact supports this item: grep for 'cve.org' across work/2026-07-26T1308Z-audit/*.yaml returns zero matches, and none of the 22 imprecision `defect` strings describes it. Related arit | Removed the unsupported cve.org item and re-derived the three shape counts from the truth-pass YAMLs so they sum to 22 (9 attribution + 6 boundary/scope + 7 nov applied | |
| F5 missing-citation | — | True but uncited — verified independently against the KEV catalog via tools/fetch_source.py cisa-kev (record CVE-2026-0770, dateAdded 2026-07-21, notes field: 'https://github.com/langflow-ai/langflow/ | Dropped both uncited claims. The paragraph now states only that ZDI's 'restrict interaction' mitigation reflects its January date, so the entry's 'no version pa applied | |
| F17 classification | — | Reliability letter above the cited source's own letter and internally inconsistent within this run. The primary is Rapid7's ETR blog; sources/sources.json rates rapid7-research reliability B, and this | classification.reliability A → B, matching sources/sources.json and this run's other Rapid7-primary entry. applied | |
| F11 editorial-advisory | — | Advisory only — four evidence[] quotes whose sole deviation from the source is the initial letter's case (sources read 'Potrivit raportului, infrastructura ANCPI nu beneficia...', 'nu există indicii c | Normalised four evidence quotes to the source's exact casing and continuation. Also self-caught a defect this finding did not name: several English translations applied | |
| F11 editorial-advisory | — | Advisory. The first two sentences of the note are reader-useful (sole source, Part 1 of a series); the trailing clause is run-process provenance that tells a Tier 2 responder nothing about how far to | Trimmed the run-process provenance clause from the TELESHIM sourcing note. applied |
Iteration #2 NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 8m 36s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | The body's CVE-to-product pairing (CVE-2026-47056 in Oracle Data Integrator, CVE-2026-60217 in Oracle Coherence) was cited solely to NCSC-2026-0252, which lists CVE ids with scores in one section and | Re-attributed the pairing, component names and versions to Oracle's risk matrix; the NCSC-NL citation now claims only that its advisory lists the maximum-severi applied | |
| F4 hallucinated-fact | — | The Fixes section claimed 11 new state/cves_seen.json records; the actual diff carries 12, because iteration 1's own F14 remediation added CVE-2026-60365 after the count was written. | Corrected to 12, verified against git diff HEAD -- state/cves_seen.json. applied |
Iteration #3 NEEDS_FIXES · 13 findings (truth=10, editorial=0, advisory=3) · Claude Opus 5 · 18m 36s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | BleepingComputer cited as 2026-07-25; the article metadata gives datePublished 2026-07-23. Two-day drift. | Corrected sources[].date and the inline citation to 2026-07-23; the audit report's completeness item was corrected the same way. applied | |
| F3 claim-not-supported | — | "Publication therefore cannot be read as retaliation for a refused payment" is contradicted by 20 minutes' own lede framing publication as the consequence of an unpaid demand, and by ICTjournal report | Replaced the causal claim with an explicit Contradiction paragraph carrying both sides verbatim, and set verification: contradicted. applied | |
| F4 hallucinated-fact | — | "56 of 57 records returned machine_surface: false" is unsupported: the YAMLs carry 46 false and 11 true, all 11 in truth-B4, ten of them on clean/defect-null records (inverted polarity). Iteration 1's | Rewrote the passage to state the artifact as it is — three batches false on all 43 records, the fourth unusable through inverted polarity, and the conclusion re applied | |
| F4 hallucinated-fact | — | The actions[] item named seven product families as the families carrying the nine CVSS-10.0 fixes; Oracle's CSAF spreads them across nine, and the body names all nine correctly — so the frontmatter co | Added both missing families to the action; it now names all nine. applied | |
| F4 hallucinated-fact | — | The three EasyStore CVE-to-class mappings were rotated against the discloser: 65759 is the order forgery, 65760 the cross-customer invoice IDOR, 65761 the unauthenticated SQL injection. state/cves_see | Re-derived all three from the discloser page, which the main agent re-fetched raw to confirm independently: corrected type and auth on each record in the entry applied | |
| F4 hallucinated-fact | — | CVE-2026-62415 shipped fixed: "not stated in the cited disclosure" when the disclosure says "Update to 4.6.2" — the same defect class this audit documents elsewhere in the window and ships a v3.29 Pha | Set fixed to Membership Pro 4.6.2 and affected to before 4.6.2; body and cves_seen title updated. applied | |
| F4 hallucinated-fact | — | The sole cited source never states the binary is code-signed — it says "a legitimate RegSchdTask.exe file from ASUSTek". Signing was asserted in title, summary, body and the Triage line, and carried t | Removed every signing assertion including from the title, restated the mechanism as a legitimate vendor binary, and moved the rename to the staging step with th applied | |
| F4 hallucinated-fact | — | The sourcing note claimed CVSS values were left unset except where stated, but four of the six CVEs have a stated score that was dropped (Gridbox 10.0 CVSS 4.0 discloser assessment; EasyStore 9.3/9.2/ | Carried all four scores into cves[], labelled the Gridbox figure as the discloser's own assessment rather than a CNA score, and rewrote the sourcing note. applied | |
| F4 hallucinated-fact | — | "12 run records" and "publish follow-through 12/12": exactly 11 records have started inside the stated window and all 11 are ok; the 57 audited entries carry 10 distinct run_ids. | Corrected to 11 records and 11/11 in the report and the run record, and recorded that the entries carry 10 distinct run ids. applied | |
| F4 hallucinated-fact | — | The cisa-advisories finding claimed the feed URL "is now recorded as rss_url" and that the working recipe existed only inside source_health.py; git shows the rss_url was already on the record unchange | Restated as an ignored-recipe rather than missing-recipe problem, corrected the change type to notes in both the report and the run record's sources_changed ent applied | |
| F11 editorial-advisory | — | Advisory: five named clusters (FakeAgent, SectopRAT/ArechClient2, TELESHIM, MIXEDKEY, BINDCLOAK) enter the store with no registry key, and the audit's own Part-2 watch item depends on the TELESHIM ent | Deliberate decision recorded rather than acted on: registering five clusters under watchdog time pressure risked exactly the hasty-metadata defects this iterati recorded-as-decision | |
| F11 editorial-advisory | — | Advisory: the VM deletion the body describes is Data Destruction and was unmapped, while T1490 has no matching body behaviour. | Added T1485 to techniques[]; T1490 kept, since hypervisor-level deletion of guests is a defensible reading. recorded-as-decision | |
| F11 editorial-advisory | — | Advisory: one French evidence quote normalises a typographic apostrophe to a straight one, so it is not byte-identical to the page. No fact affected. | Left as-is on the verifier's own recommendation; recorded here for completeness of the quote-fidelity sweep. recorded-as-decision |
Iteration #4 NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 4m 19s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | — | The signing claim was removed from the title, summary, first body mention and Triage opener but survived in the Defender takeaway ("a signed binary and its planted DLL") and the second Triage sentence | Rewrote both survivors to "a legitimate vendor binary" and "that vendor executable"; the file now contains no occurrence of "signed". applied | |
| F4 hallucinated-fact | — | The report and run record were correctly rewritten to say the change was notes-only, but the note text appended to the source record still asserted "The feed URL is now recorded as rss_url on the reco | Rewrote the note: it now states this is an ignored-recipe rather than missing-recipe problem, records that the URL was already the record's rss_url and that the applied |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-07-26T1308Z-audit · audit · Opus 5 · window 193 h · 9 entries published
Audit run — 2026-07-26
Full report: docs/audits/2026-07-26-weekly-quality-audit.md.
Scope and method
Window 2026-07-18T12:08Z → 2026-07-26T13:08Z (~193 h), anchored at the last audit that actually audited — the 2026-07-19 audit record stood down as a duplicate at a 25 h gap and covered nothing. Audited 57 published entries (43 operational, 14 W29 weekly strategic), carrying 10 distinct run ids, across the 11 run records whose start timestamp falls inside the window. Four retrospective truth passes fetched ~181 primary and authority URLs; three coverage re-sweeps re-researched the window independently. July's monthly priority-calibration duty was already discharged by the 2026-07-18 report, so no calibration section appears in this one.
Soundness
32 of 57 entries fully clean. No machine-surface defect survived review. Stating the artifact accurately: three of the four batches recorded machine_surface: false on all 43 of their records, including their 20 non-clean ones; the fourth wrote the field with inverted polarity and is unusable as reported, so the audit reviewed its one non-clean record directly and rejected it, because the entry concerned carries no CVE records at all. Every CVE id and CVSS matched its owning authority, every ATT&CK id checked is active in the pinned v19.1 dataset, every registry key resolves, no indicators leaked. Zero hallucinated facts and zero broken URLs.
Three factual errors. One is defender-consequential and is corrected by a published update this run: the 2026-07-22 Langflow entry advised upgrading to 1.10.1, which leaves CVE-2026-14499 (CVSS 8.8, authenticated command injection) open — the vendor bulletin names 1.10.2 — and it attached an AUTO_LOGIN precondition and a "no version patch" status to CVE-2026-0770 that the discloser's own advisory contradicts. The audit re-verified both legs directly against the vendor bulletin and the discloser's advisory before correcting. The other two are attribution errors in W29 strategic entries where the underlying facts are true.
The other 22 findings are precision defects. The largest single group — 9 of those imprecisions plus 2 of the 3 factual errors, 11 in all — is one class: a true fact cited to a co-cited source that does not carry it. That class is now the dominant residual defect in the pipeline, present in operational entries and the weekly alike, and it survived verification loops of three to eight iterations because those loops confirmed the fact was true rather than that the cited page said it. The remaining 10 split between version-boundary and scope precision (six) and novelty or quote-fidelity precision (four).
The clean rate is lower than the previous audit's, and part of that is measurement rather than regression: three of four passes ran on Opus 5 at maximum scrutiny against a 2:2 split last time, and the adjacency standard applied is stricter than earlier passes enforced. Every batch independently found the same class, which is evidence about the pipeline rather than about one verifier.
No in-place repairs were warranted — nothing in the window touches the narrow metadata class the immutability exception covers. One verifier proposed a machine-surface repair; the audit checked and rejected it, because the entry in question carries no CVE records at all, so nothing propagated to a machine surface.
Completeness
Nine genuine gaps, all recovered and published here through dedup, the mechanical gate and the verification loop.
The most serious: the WordPress WP2Shell chain moved to confirmed in-the-wild exploitation and was added to the CISA catalog on 2026-07-21, and no entry recorded the change — while the store's existing entry says in its own words that there was no confirmed exploitation. The 2026-07-22 fire saw that catalog batch and correctly published a different vulnerability from it, then dropped the WordPress pair on two compounding errors: it applied a rule about foreign-jurisdiction remediation deadlines to the exploitation-confirmation flag, which the same rule defines as operational signal; and it justified the drop by asserting the vulnerabilities were already reported as exploited, which its own prior entry contradicts — a decision made against a remembered entry rather than a re-read one. That fire's own verifier flagged the gap and the drop reasoning overrode it. Both causes are fixed in this run's prompt changes.
Two more were follow-through failures on stories the pipeline was already tracking rather than discovery failures: Romania's national cybersecurity authority published an interim technical report that supersedes the "databases not affected" position the store carried on the ANCPI land-registry attack, confirming roughly two million exfiltrated payment-platform user records and a virtualization-plane intrusion; and the Geneva adult-education institute's stolen data was actually published, including student examination results the institute had said were unaffected. Both are Swiss- or Europe-relevant public-sector stories with an open clock that nothing re-checked.
The rest: a malvertising campaign that hosted its lure page on a vendor's own trusted domain and hit at least 29 organisations; an exposed delivery lab showing industrialised shortcut-and-WebDAV lure testing; a Joomla extension flaw where one anonymous request becomes full administrator on an internet-facing site; the unauthenticated maximum-severity concentration in Oracle's July middleware release that two national authorities escalated; and a government-espionage toolkit whose final implant decrypts only on the target machine.
Seven further items were examined and correctly dropped, each with its reason recorded in the report — a catalog addition over already-exploited ground, a vulnerability needing a non-default configuration, a municipal ransomware case with no attacker-behaviour content to describe, a vendor naming-taxonomy announcement, a strategic assessment belonging to the weekly rather than an intel run, an uncorroborated wave of criminal claims against French government platforms, and a political doxing assembled from older breaches. Two of those became watch items rather than clean drops.
One judgement was reversed during the audit: the government-espionage toolkit was initially set aside as out-of-nexus, then published, because the previous audit recovered a materially identical case and no principled distinction separated them. The reversal is recorded because it is more useful to the next audit than a tidy verdict.
Machinery
Two fixes shipped last week are measurably working. The verifier iteration-cap raise turned the fail-open from the common path into the exception: seven of ten fires since it landed reached a genuine two-model confirmed agreement, and the single waiver in this window was not a cap problem at all. The weekly citation-date duty eliminated its target defect outright — every one of 52 citation dates in the W29 batch matches its source's own publication metadata, against nearly every entry drifting a week earlier. That same fix had a second half about per-fact attribution which did not move at all, and the contrast between the mechanically-checkable half working completely and the judgement-call half not moving is the clearest evidence in this audit for how to fix the dominant defect class: mechanise it, on both the composing and the verifying side. Both are done in this run's prompt changes.
One rule was found dead on arrival. The source list documents promoting a candidate source to active after three contributing runs, but nothing ever counted, and a single fire cannot remember earlier fires — so eleven candidates sat unpromoted, one of them cited by entries from eleven separate runs. Because candidate records are also absent from the digest list the fires build their slices from, a newly added candidate is effectively unreachable, which is why the previous audit's own new source — added specifically to close the discovery gap behind its WP2Shell miss — was never fetched once in eight runs. Fixed at the root: the state digest now computes the count, acting on it is a preflight duty, candidates rotate explicitly, and all eleven are promoted here.
Source health surfaced a concrete instance of reachability not meaning readability: an essential source probes green because the health tool uses a working feed recipe that exists only inside that tool, while the record points at an HTML listing the CDN refuses — so two fires logged failures against a record that looked healthy. The feed is now on the record, and two other recipe corrections ship with it.
The reader pool of last resort was exhausted for four consecutive days and was refilled by the operator about twenty minutes before this audit fired. That outage is the direct cause of one national-CERT source going unreachable mid-window. It is now healthy, but this is the second refill in nine days and each has lasted about five days, which is an operator decision about funding and monitoring rather than something the audit can fix.
Content-safety classifier trips on sub-agent spawns are now a recurring reality rather than a one-off: they cost one fire its entire model rotation, three of four research spawns and its deep-reads, and they cost this audit two spawns for one batch. The existing handling — retry, then fall back and record the exception — is correct and worked both times, so no rule changes; the mitigation that got the batch through is recorded in memory instead, along with the warning not to misread a uniform-model verifier chain as a rotation failure.
Telemetry is otherwise clean. No runaway runs against the three-hour threshold. Publish follow-through complete across all eleven in-window records. Gap-derived windows self-healed across every fire including two off-cadence gaps, with no coverage hole between them. Discipline held or improved: action items sit at 38 empty of 57 entries with none above two, every entry carries a valid reliability rating, empty technique mappings appear only on the two kinds that legitimately allow it, and the high-priority share continued its deflationary trend. The 26-day gap without a critical-priority entry was checked against the window's real exploitation pressure and reflects the bar rather than under-alerting.
Zero-warning sweep
The store-wide check ends 0 warn · 0 fail · 9 acknowledged and the site build emits no self-check warnings. One acknowledgment was added, for the fire whose confirming verification pair ran on the same model because every alternate-model spawn was blocked by the content classifier after a retry: the run recorded that exception as policy requires, both passes were genuine independent confirmations, and the record is immutable. A code change that auto-passed this shape whenever a waiver is present was considered and deliberately rejected — it would let any future run silence the rotation check by writing its own waiver, which is precisely the self-serve exemption the discipline forbids. No acknowledgments were pruned; all nine still silence a live warning.
Notes
- Recovered entries and their sourcing posture: seven multi-source, two single-source with the value set and a sourcing note naming the situation (the Joomla extension batch, where the discloser is the only publisher and withholds proof-of-concept detail; and the espionage toolkit, whose originating lab is the sole source and labels the post part one of a series).
- Single-source carve-outs: none of the nine relies on a national-CERT or victim-own-disclosure carve-out.
- Reduced-confidence inclusions: two entries carry
confidence: medium— the Geneva incident (the publication event rests on one Swiss outlet relaying another) and the Joomla batch (no independent corroboration yet). - Out-of-window handling: the Oracle release advisory predates the window; the entry anchors on the two in-window national-CERT advisories and records the earlier vendor date explicitly, so it makes no false freshness claim. The corrected Langflow record likewise carries the vendor bulletin's own mid-July date.
- Borderline drops are enumerated with reasons in the report's completeness section rather than repeated here.
- Non-update decision, confirmed deliberate (the gate asks for this confirmation, and it is the only warning this run leaves standing): the Joomla recovery shares the tracked extension-wave entity with a W29-preceding weekly synthesis entry, but it ships as a new entry rather than a delta. It is a distinct technical finding — a cookie-forgery authentication bypass reaching full administrator, not the file-upload pattern the tracked wave describes — on a different extension, with six CVE identifiers none of which appear in prior coverage. The prior operational entries in that series cover individual file-upload flaws that this one neither supersedes nor extends, and an intel-class entry never posts a delta against a strategic synthesis entry in any case. The shared entity key is what groups them for the reader at render time, which is the intended mechanism. The warning cannot be cleared without making a wrong update decision, and a run never self-acknowledges its own fresh warnings, so it stays visible with this explanation.
- Coverage gaps: three research publishers could not be read this run — one blog is JS-rendered and returned no article content on either the bridge or the reader, one feed transport is broken with nothing found by search either, and two feeds are dead but were recovered via their HTML listings. Two further listings need canonical-path updates. None cost a recovery this window; all are logged in the G3 findings file for the next fire's rotation.
← Operations dashboard · run-record contract: docs/pipeline.md