ctipilot.ch

2026-07-26T1308Z-audit

One pipeline fire, in full · audit run of 2026-07-26 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-26/2026-07-26T1308Z-audit.md.

Run telemetry

2026-07-26T1308Z-audit audit prompt v3.29 publish ok
2h 33m duration 9 published 4 updates
Claude Opus 5 (claude-opus-5) main agent
G1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
12m 24s
Tool calls
14 WebFetch11 WebSearch22 bridge
Cited sources
none
G2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
18m 02s
Tool calls
30 WebFetch20 WebSearch10 bridge
Cited sources
none
G3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
15m 08s
Tool calls
20 WebFetch16 WebSearch14 bridge
Cited sources
none
truth-B1 Claude Opus 5 (claude-opus-5)
Items returned
15
Duration
26m 37s
Tool calls
not reported
Cited sources
none
truth-B2 Claude Opus 5 (claude-opus-5)
Items returned
15
Duration
28m 38s
Tool calls
not reported
Cited sources
none
truth-B3 Claude Opus 5 (claude-opus-5)
Items returned
13
Duration
22m 49s
Tool calls
not reported
Cited sources
none
truth-B4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
14
Duration
16m 27s
Tool calls
not reported
Cited sources
none

Verification

unconfirmed CLEAN · waived: Single CLEAN at the wall-clock watchdog, and that CLEAN was a SCOPED re-check ra #1 NEEDS_FIXES · Opus 5 · t=12 e=2 a=2 #2 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #3 NEEDS_FIXES · Opus 5 · t=10 e=0 a=3 #4 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #5 CLEAN · Opus 5 · t=0 e=0 a=0

Deep dive

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

11 status · 2 notes · 1 fetch_method+notes · 1 added-candidate.

SourceChangeFrom → ToReason
proofpointstatus— → —candidate → active: cited by published entries from 11 distinct runs (bar is 3); promotion had never been executed because nothing counted contributing runs
sysdigstatus— → —candidate → active: 7 contributing runs
socradarstatus— → —candidate → active: 6 contributing runs
mysites-gurustatus— → —candidate → active: 5 contributing runs
swisscybersecurity-netstatus— → —candidate → active: 5 contributing runs
jamf-threat-labsstatus— → —candidate → active: 4 contributing runs
onapsisstatus— → —candidate → active: 4 contributing runs
reliaqueststatus— → —candidate → active: 4 contributing runs
searchlight-cyberstatus— → —candidate → active: 4 contributing runs
netzwochestatus— → —candidate → active: 3 contributing runs
ox-securitystatus— → —candidate → active: 3 contributing runs
cisa-advisoriesnotes— → —fires logged HTTP 403 sweeping the HTML listing in the url field even though the working feed URL was already on the record as rss_url and a 2026-07-10 note already said to prefer it — an ignored-recipe problem, not a missing one; the note now says so in the imperative
ncsc-uknotes— → —the 2026-07-13 note calling the combined feed path unresolved is stale — the feed resolved cleanly this run
ccb-belgiumfetch_method+notes— → —bridge → jina: WebFetch and the generic url bridge return only cookie-consent boilerplate; the reader returns the full dated advisory listing
zscaler-threatlabzadded-candidate— → —a major research lab absent from the slice entirely — its in-window government-espionage toolkit analysis had no curated discovery path (this run's one new candidate)

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 16 findings (truth=12, editorial=2, advisory=2) · Claude Opus 5 · 16m 54s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
Adjacency defect. Fetched the full NCSC-2026-0252 advisory (jina, 7355 chars) and its CSAF (https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0252-0.json): none of the four version strings 12.2.1.4.0 Re-attributed every Data Integrator / Coherence version string and component name to Oracle's own risk matrix with a separate Oracle citation; cves[].affected n applied
F4
hallucinated-fact
Fabricated quotation. Fetched https://www.csoonline.com/article/4200184/... in full: this sentence does not appear. CSOonline's actual text is 'Fusion Middleware was particularly hard hit, with new seRemoved the fabricated quotation; the entry now quotes CSOonline's actual sentence and Oracle's own sentence, both verbatim. applied
F14
quantifier-without-source
The entry's own primary source contradicts the count: NCSC-2026-0252 states 'De ernstigste kwetsbaarheden, 9 stuks, hebben de hoogste score van 10.0 gekregen' and its CSAF lists exactly nine CVEs (470Corrected to nine distinct CVEs in title, summary and body, and added a paragraph stating the divergence explicitly (ten matrix rows because CVE-2026-60365 is d applied
F3
claim-not-supported
Adjacency defect. Fetched the BleepingComputer article in full via the jina reader (15,620 chars): 'blockchain' 0 occurrences, 'autofill' 0, 'payment' 0 (it does carry 'hands-on', 'credential', 'cookiRe-attributed the autofill / payment-data / Ethereum-blockchain-C2 clause to Huntress with its own citation; BleepingComputer now carries only the SectopRAT ide applied
F3
claim-not-supported
Adjacency defect. Fetched the cited Hacker News article: 'invoice' 0 occurrences, 'salary' 0 (it does carry the Rapid7 quote — 'Rapid7's summary is blunt: "the attacker used LLMs to operate more like Split the citation: the LLM quote keeps its Hacker News citation (THN does quote it), and the invoice / salary lure-theme specifics are attributed to Rapid7 wit applied
F4
hallucinated-fact
Spliced quote, not a contiguous substring. The Zscaler post contains two DIFFERENT sentences: (a) 'TELESHIM abused the Telegram API for C2 communication to blend in with legitimate internet traffic.' Replaced the hybrid with the C2-section sentence verbatim in both evidence[] and the body. applied
F3
claim-not-supported
The cited source states the opposite premise. 20 minutes (fetched in full via jina, 38,950 chars): 'La fondation avait aussi affirmé qu'elle n'avait pas reçu de demande de rançon, mais que, le cas échRemoved the 'declined to pay' causation everywhere and added a paragraph giving IFAGE's actual position with the French verbatim, stating that publication canno applied
F3
claim-not-supported
Date off by one against the cited source. The 20 minutes article is itself timestamped 'Publié 24. juillet 2026, 14:22' and says of the publication: 'C'est chose faite depuis jeudi, selon «Le Temps»' Corrected the publication date to 2026-07-23 ('depuis jeudi') in summary, body and event_date; the 20 minutes article's own 2026-07-24 date stays in sources[]. applied
F4
hallucinated-fact
Word substituted inside a verbatim quote. The source sentence begins 'Leur divulgation par les cybercriminels concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etRestored 'Leur divulgation…' as the verbatim opening. applied
F4
hallucinated-fact
The artifact contradicts this: work/2026-07-26T1308Z-audit/truth-B4.yaml carries machine_surface: true on entries/2026-07-19/weekly-w29-exploited-internet-facing-enterprise-software.md (24 records falRephrased in the report and aligned the run record and B4 telemetry: 56 of 57 records returned machine_surface false; the single flag was reviewed and rejected applied
F4
hallucinated-fact
Overstated against the report's own breakdown and against the run record. § Imprecisions splits the 22 into 'Per-fact attribution (12)', 'Boundary and scope precision (6)' and 'Novelty and quote fidelCorrected to 9 imprecisions plus 2 of the 3 factual errors (11 in all) in the report Verdict, and aligned the run record and the CHANGELOG 3.29 entry to the sam applied
F4
hallucinated-fact
No truth-pass artifact supports this item: grep for 'cve.org' across work/2026-07-26T1308Z-audit/*.yaml returns zero matches, and none of the 22 imprecision `defect` strings describes it. Related aritRemoved the unsupported cve.org item and re-derived the three shape counts from the truth-pass YAMLs so they sum to 22 (9 attribution + 6 boundary/scope + 7 nov applied
F5
missing-citation
True but uncited — verified independently against the KEV catalog via tools/fetch_source.py cisa-kev (record CVE-2026-0770, dateAdded 2026-07-21, notes field: 'https://github.com/langflow-ai/langflow/Dropped both uncited claims. The paragraph now states only that ZDI's 'restrict interaction' mitigation reflects its January date, so the entry's 'no version pa applied
F17
classification
Reliability letter above the cited source's own letter and internally inconsistent within this run. The primary is Rapid7's ETR blog; sources/sources.json rates rapid7-research reliability B, and thisclassification.reliability A → B, matching sources/sources.json and this run's other Rapid7-primary entry. applied
F11
editorial-advisory
Advisory only — four evidence[] quotes whose sole deviation from the source is the initial letter's case (sources read 'Potrivit raportului, infrastructura ANCPI nu beneficia...', 'nu există indicii cNormalised four evidence quotes to the source's exact casing and continuation. Also self-caught a defect this finding did not name: several English translations applied
F11
editorial-advisory
Advisory. The first two sentences of the note are reader-useful (sole source, Part 1 of a series); the trailing clause is run-process provenance that tells a Tier 2 responder nothing about how far to Trimmed the run-process provenance clause from the TELESHIM sourcing note. applied

Iteration #2 NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 8m 36s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The body's CVE-to-product pairing (CVE-2026-47056 in Oracle Data Integrator, CVE-2026-60217 in Oracle Coherence) was cited solely to NCSC-2026-0252, which lists CVE ids with scores in one section and Re-attributed the pairing, component names and versions to Oracle's risk matrix; the NCSC-NL citation now claims only that its advisory lists the maximum-severi applied
F4
hallucinated-fact
The Fixes section claimed 11 new state/cves_seen.json records; the actual diff carries 12, because iteration 1's own F14 remediation added CVE-2026-60365 after the count was written.Corrected to 12, verified against git diff HEAD -- state/cves_seen.json. applied

Iteration #3 NEEDS_FIXES · 13 findings (truth=10, editorial=0, advisory=3) · Claude Opus 5 · 18m 36s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
BleepingComputer cited as 2026-07-25; the article metadata gives datePublished 2026-07-23. Two-day drift.Corrected sources[].date and the inline citation to 2026-07-23; the audit report's completeness item was corrected the same way. applied
F3
claim-not-supported
"Publication therefore cannot be read as retaliation for a refused payment" is contradicted by 20 minutes' own lede framing publication as the consequence of an unpaid demand, and by ICTjournal reportReplaced the causal claim with an explicit Contradiction paragraph carrying both sides verbatim, and set verification: contradicted. applied
F4
hallucinated-fact
"56 of 57 records returned machine_surface: false" is unsupported: the YAMLs carry 46 false and 11 true, all 11 in truth-B4, ten of them on clean/defect-null records (inverted polarity). Iteration 1'sRewrote the passage to state the artifact as it is — three batches false on all 43 records, the fourth unusable through inverted polarity, and the conclusion re applied
F4
hallucinated-fact
The actions[] item named seven product families as the families carrying the nine CVSS-10.0 fixes; Oracle's CSAF spreads them across nine, and the body names all nine correctly — so the frontmatter coAdded both missing families to the action; it now names all nine. applied
F4
hallucinated-fact
The three EasyStore CVE-to-class mappings were rotated against the discloser: 65759 is the order forgery, 65760 the cross-customer invoice IDOR, 65761 the unauthenticated SQL injection. state/cves_seeRe-derived all three from the discloser page, which the main agent re-fetched raw to confirm independently: corrected type and auth on each record in the entry applied
F4
hallucinated-fact
CVE-2026-62415 shipped fixed: "not stated in the cited disclosure" when the disclosure says "Update to 4.6.2" — the same defect class this audit documents elsewhere in the window and ships a v3.29 PhaSet fixed to Membership Pro 4.6.2 and affected to before 4.6.2; body and cves_seen title updated. applied
F4
hallucinated-fact
The sole cited source never states the binary is code-signed — it says "a legitimate RegSchdTask.exe file from ASUSTek". Signing was asserted in title, summary, body and the Triage line, and carried tRemoved every signing assertion including from the title, restated the mechanism as a legitimate vendor binary, and moved the rename to the staging step with th applied
F4
hallucinated-fact
The sourcing note claimed CVSS values were left unset except where stated, but four of the six CVEs have a stated score that was dropped (Gridbox 10.0 CVSS 4.0 discloser assessment; EasyStore 9.3/9.2/Carried all four scores into cves[], labelled the Gridbox figure as the discloser's own assessment rather than a CNA score, and rewrote the sourcing note. applied
F4
hallucinated-fact
"12 run records" and "publish follow-through 12/12": exactly 11 records have started inside the stated window and all 11 are ok; the 57 audited entries carry 10 distinct run_ids.Corrected to 11 records and 11/11 in the report and the run record, and recorded that the entries carry 10 distinct run ids. applied
F4
hallucinated-fact
The cisa-advisories finding claimed the feed URL "is now recorded as rss_url" and that the working recipe existed only inside source_health.py; git shows the rss_url was already on the record unchangeRestated as an ignored-recipe rather than missing-recipe problem, corrected the change type to notes in both the report and the run record's sources_changed ent applied
F11
editorial-advisory
Advisory: five named clusters (FakeAgent, SectopRAT/ArechClient2, TELESHIM, MIXEDKEY, BINDCLOAK) enter the store with no registry key, and the audit's own Part-2 watch item depends on the TELESHIM entDeliberate decision recorded rather than acted on: registering five clusters under watchdog time pressure risked exactly the hasty-metadata defects this iterati recorded-as-decision
F11
editorial-advisory
Advisory: the VM deletion the body describes is Data Destruction and was unmapped, while T1490 has no matching body behaviour.Added T1485 to techniques[]; T1490 kept, since hypervisor-level deletion of guests is a defensible reading. recorded-as-decision
F11
editorial-advisory
Advisory: one French evidence quote normalises a typographic apostrophe to a straight one, so it is not byte-identical to the page. No fact affected.Left as-is on the verifier's own recommendation; recorded here for completeness of the quote-fidelity sweep. recorded-as-decision

Iteration #4 NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 4m 19s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
The signing claim was removed from the title, summary, first body mention and Triage opener but survived in the Defender takeaway ("a signed binary and its planted DLL") and the second Triage sentenceRewrote both survivors to "a legitimate vendor binary" and "that vendor executable"; the file now contains no occurrence of "signed". applied
F4
hallucinated-fact
The report and run record were correctly rewritten to say the change was notes-only, but the note text appended to the source record still asserted "The feed URL is now recorded as rss_url on the recoRewrote the note: it now states this is an ignored-recipe rather than missing-recipe problem, records that the URL was already the record's rss_url and that the applied

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-07-26T1308Z-audit · audit · Opus 5 · window 193 h · 9 entries published

Audit run — 2026-07-26

Full report: docs/audits/2026-07-26-weekly-quality-audit.md.

Scope and method

Window 2026-07-18T12:08Z → 2026-07-26T13:08Z (~193 h), anchored at the last audit that actually audited — the 2026-07-19 audit record stood down as a duplicate at a 25 h gap and covered nothing. Audited 57 published entries (43 operational, 14 W29 weekly strategic), carrying 10 distinct run ids, across the 11 run records whose start timestamp falls inside the window. Four retrospective truth passes fetched ~181 primary and authority URLs; three coverage re-sweeps re-researched the window independently. July's monthly priority-calibration duty was already discharged by the 2026-07-18 report, so no calibration section appears in this one.

Soundness

32 of 57 entries fully clean. No machine-surface defect survived review. Stating the artifact accurately: three of the four batches recorded machine_surface: false on all 43 of their records, including their 20 non-clean ones; the fourth wrote the field with inverted polarity and is unusable as reported, so the audit reviewed its one non-clean record directly and rejected it, because the entry concerned carries no CVE records at all. Every CVE id and CVSS matched its owning authority, every ATT&CK id checked is active in the pinned v19.1 dataset, every registry key resolves, no indicators leaked. Zero hallucinated facts and zero broken URLs.

Three factual errors. One is defender-consequential and is corrected by a published update this run: the 2026-07-22 Langflow entry advised upgrading to 1.10.1, which leaves CVE-2026-14499 (CVSS 8.8, authenticated command injection) open — the vendor bulletin names 1.10.2 — and it attached an AUTO_LOGIN precondition and a "no version patch" status to CVE-2026-0770 that the discloser's own advisory contradicts. The audit re-verified both legs directly against the vendor bulletin and the discloser's advisory before correcting. The other two are attribution errors in W29 strategic entries where the underlying facts are true.

The other 22 findings are precision defects. The largest single group — 9 of those imprecisions plus 2 of the 3 factual errors, 11 in all — is one class: a true fact cited to a co-cited source that does not carry it. That class is now the dominant residual defect in the pipeline, present in operational entries and the weekly alike, and it survived verification loops of three to eight iterations because those loops confirmed the fact was true rather than that the cited page said it. The remaining 10 split between version-boundary and scope precision (six) and novelty or quote-fidelity precision (four).

The clean rate is lower than the previous audit's, and part of that is measurement rather than regression: three of four passes ran on Opus 5 at maximum scrutiny against a 2:2 split last time, and the adjacency standard applied is stricter than earlier passes enforced. Every batch independently found the same class, which is evidence about the pipeline rather than about one verifier.

No in-place repairs were warranted — nothing in the window touches the narrow metadata class the immutability exception covers. One verifier proposed a machine-surface repair; the audit checked and rejected it, because the entry in question carries no CVE records at all, so nothing propagated to a machine surface.

Completeness

Nine genuine gaps, all recovered and published here through dedup, the mechanical gate and the verification loop.

The most serious: the WordPress WP2Shell chain moved to confirmed in-the-wild exploitation and was added to the CISA catalog on 2026-07-21, and no entry recorded the change — while the store's existing entry says in its own words that there was no confirmed exploitation. The 2026-07-22 fire saw that catalog batch and correctly published a different vulnerability from it, then dropped the WordPress pair on two compounding errors: it applied a rule about foreign-jurisdiction remediation deadlines to the exploitation-confirmation flag, which the same rule defines as operational signal; and it justified the drop by asserting the vulnerabilities were already reported as exploited, which its own prior entry contradicts — a decision made against a remembered entry rather than a re-read one. That fire's own verifier flagged the gap and the drop reasoning overrode it. Both causes are fixed in this run's prompt changes.

Two more were follow-through failures on stories the pipeline was already tracking rather than discovery failures: Romania's national cybersecurity authority published an interim technical report that supersedes the "databases not affected" position the store carried on the ANCPI land-registry attack, confirming roughly two million exfiltrated payment-platform user records and a virtualization-plane intrusion; and the Geneva adult-education institute's stolen data was actually published, including student examination results the institute had said were unaffected. Both are Swiss- or Europe-relevant public-sector stories with an open clock that nothing re-checked.

The rest: a malvertising campaign that hosted its lure page on a vendor's own trusted domain and hit at least 29 organisations; an exposed delivery lab showing industrialised shortcut-and-WebDAV lure testing; a Joomla extension flaw where one anonymous request becomes full administrator on an internet-facing site; the unauthenticated maximum-severity concentration in Oracle's July middleware release that two national authorities escalated; and a government-espionage toolkit whose final implant decrypts only on the target machine.

Seven further items were examined and correctly dropped, each with its reason recorded in the report — a catalog addition over already-exploited ground, a vulnerability needing a non-default configuration, a municipal ransomware case with no attacker-behaviour content to describe, a vendor naming-taxonomy announcement, a strategic assessment belonging to the weekly rather than an intel run, an uncorroborated wave of criminal claims against French government platforms, and a political doxing assembled from older breaches. Two of those became watch items rather than clean drops.

One judgement was reversed during the audit: the government-espionage toolkit was initially set aside as out-of-nexus, then published, because the previous audit recovered a materially identical case and no principled distinction separated them. The reversal is recorded because it is more useful to the next audit than a tidy verdict.

Machinery

Two fixes shipped last week are measurably working. The verifier iteration-cap raise turned the fail-open from the common path into the exception: seven of ten fires since it landed reached a genuine two-model confirmed agreement, and the single waiver in this window was not a cap problem at all. The weekly citation-date duty eliminated its target defect outright — every one of 52 citation dates in the W29 batch matches its source's own publication metadata, against nearly every entry drifting a week earlier. That same fix had a second half about per-fact attribution which did not move at all, and the contrast between the mechanically-checkable half working completely and the judgement-call half not moving is the clearest evidence in this audit for how to fix the dominant defect class: mechanise it, on both the composing and the verifying side. Both are done in this run's prompt changes.

One rule was found dead on arrival. The source list documents promoting a candidate source to active after three contributing runs, but nothing ever counted, and a single fire cannot remember earlier fires — so eleven candidates sat unpromoted, one of them cited by entries from eleven separate runs. Because candidate records are also absent from the digest list the fires build their slices from, a newly added candidate is effectively unreachable, which is why the previous audit's own new source — added specifically to close the discovery gap behind its WP2Shell miss — was never fetched once in eight runs. Fixed at the root: the state digest now computes the count, acting on it is a preflight duty, candidates rotate explicitly, and all eleven are promoted here.

Source health surfaced a concrete instance of reachability not meaning readability: an essential source probes green because the health tool uses a working feed recipe that exists only inside that tool, while the record points at an HTML listing the CDN refuses — so two fires logged failures against a record that looked healthy. The feed is now on the record, and two other recipe corrections ship with it.

The reader pool of last resort was exhausted for four consecutive days and was refilled by the operator about twenty minutes before this audit fired. That outage is the direct cause of one national-CERT source going unreachable mid-window. It is now healthy, but this is the second refill in nine days and each has lasted about five days, which is an operator decision about funding and monitoring rather than something the audit can fix.

Content-safety classifier trips on sub-agent spawns are now a recurring reality rather than a one-off: they cost one fire its entire model rotation, three of four research spawns and its deep-reads, and they cost this audit two spawns for one batch. The existing handling — retry, then fall back and record the exception — is correct and worked both times, so no rule changes; the mitigation that got the batch through is recorded in memory instead, along with the warning not to misread a uniform-model verifier chain as a rotation failure.

Telemetry is otherwise clean. No runaway runs against the three-hour threshold. Publish follow-through complete across all eleven in-window records. Gap-derived windows self-healed across every fire including two off-cadence gaps, with no coverage hole between them. Discipline held or improved: action items sit at 38 empty of 57 entries with none above two, every entry carries a valid reliability rating, empty technique mappings appear only on the two kinds that legitimately allow it, and the high-priority share continued its deflationary trend. The 26-day gap without a critical-priority entry was checked against the window's real exploitation pressure and reflects the bar rather than under-alerting.

Zero-warning sweep

The store-wide check ends 0 warn · 0 fail · 9 acknowledged and the site build emits no self-check warnings. One acknowledgment was added, for the fire whose confirming verification pair ran on the same model because every alternate-model spawn was blocked by the content classifier after a retry: the run recorded that exception as policy requires, both passes were genuine independent confirmations, and the record is immutable. A code change that auto-passed this shape whenever a waiver is present was considered and deliberately rejected — it would let any future run silence the rotation check by writing its own waiver, which is precisely the self-serve exemption the discipline forbids. No acknowledgments were pruned; all nine still silence a live warning.

Notes

  • Recovered entries and their sourcing posture: seven multi-source, two single-source with the value set and a sourcing note naming the situation (the Joomla extension batch, where the discloser is the only publisher and withholds proof-of-concept detail; and the espionage toolkit, whose originating lab is the sole source and labels the post part one of a series).
  • Single-source carve-outs: none of the nine relies on a national-CERT or victim-own-disclosure carve-out.
  • Reduced-confidence inclusions: two entries carry confidence: medium — the Geneva incident (the publication event rests on one Swiss outlet relaying another) and the Joomla batch (no independent corroboration yet).
  • Out-of-window handling: the Oracle release advisory predates the window; the entry anchors on the two in-window national-CERT advisories and records the earlier vendor date explicitly, so it makes no false freshness claim. The corrected Langflow record likewise carries the vendor bulletin's own mid-July date.
  • Borderline drops are enumerated with reasons in the report's completeness section rather than repeated here.
  • Non-update decision, confirmed deliberate (the gate asks for this confirmation, and it is the only warning this run leaves standing): the Joomla recovery shares the tracked extension-wave entity with a W29-preceding weekly synthesis entry, but it ships as a new entry rather than a delta. It is a distinct technical finding — a cookie-forgery authentication bypass reaching full administrator, not the file-upload pattern the tracked wave describes — on a different extension, with six CVE identifiers none of which appear in prior coverage. The prior operational entries in that series cover individual file-upload flaws that this one neither supersedes nor extends, and an intel-class entry never posts a delta against a strategic synthesis entry in any case. The shared entity key is what groups them for the reader at render time, which is the intended mechanism. The warning cannot be cleared without making a wrong update decision, and a run never self-acknowledges its own fresh warnings, so it stays visible with this explanation.
  • Coverage gaps: three research publishers could not be read this run — one blog is JS-rendered and returned no article content on either the bridge or the reader, one feed transport is broken with nothing found by search either, and two feeds are dead but were recovered via their HTML listings. Two further listings need canonical-path updates. None cost a recovery this window; all are logged in the G3 findings file for the next fire's rotation.

← Operations dashboard · run-record contract: docs/pipeline.md