ctipilot.ch

2026-07-27T0409Z-intel

One pipeline fire, in full · intel run of 2026-07-27 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-27/2026-07-27T0409Z-intel.md.

Run telemetry

2026-07-27T0409Z-intel intel prompt v3.29 publish ok
31m 58s duration 3 published 1 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
13m 16s
Tool calls
20 WebFetch20 WebSearch12 bridge
Cited sources
0 of 26 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
10m 10s
Tool calls
12 WebFetch4 WebSearch11 bridge
Cited sources
1 of 17 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
8m 34s
Tool calls
14 WebFetch8 WebSearch12 bridge
Cited sources
0 of 34 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
12m 27s
Tool calls
16 WebFetch20 WebSearch8 bridge
Cited sources
2 of 8 in slice

Verification

✓ double-CLEAN · Sonnet 5 + Opus 5 #? NEEDS_FIXES · Opus 5 · t=0 e=0 a=0 #? NEEDS_FIXES · Sonnet 5 · t=0 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=0 e=0 a=0 #? NEEDS_FIXES · Sonnet 5 · t=0 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=0 e=0 a=0 #? CLEAN · Sonnet 5 · t=0 e=0 a=0 #? CLEAN · Opus 5 · t=0 e=0 a=0

Deep dive

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

2 notes only — recipe-quality gap documented. No status change. · 1 status candidate -> active. The state digest reported it in sources.promotion_due with 3 contributing runs (most recent 2026-07-26T2309Z-weekly), meeting the three-contributing-run promotion bar. · 1 ADDED as candidate — this run's one new candidate (hard cap respected). French security-journalism outlet (Damien Bancal); corroborating primary for the Chat Control doxing entry. Rated B: it originates France-nexus reporting rather than re-reporting. fetch_method bridge — direct WebFetch returns 403. · 1 last_successful_fetch -> 2026-07-27 (in-window primary for the Chat Control doxing entry); failure and quiet counters reset. · 1 last_successful_fetch -> 2026-07-27 (primary for the Windchill extortion-wave update entry); counters reset. · 1 last_successful_fetch -> 2026-07-27 (corroborating source for the Windchill extortion-wave update entry); counters reset. · 1 last_successful_fetch null -> 2026-07-27 — first successful fetch since the source was added, clearing the rotation-priority flag it had carried for eight runs. Fetch succeeded via the documented feed but returned nothing in-window, so it is recorded as 200-but-quiet: consecutive_quiet_periods incremented to 1. · 1 notes only — recipe-quality gap documented (stale/cached listing index). No status change..

SourceChangeFrom → ToReason
zscaler-threatlabzstatus candidate -> active. The state digest reported it in sources.promotion_due with 3 contributing runs (most recent 2026-07-26T2309Z-weekly), meeting the three-contributing-run promotion bar.— → —
zatazADDED as candidate — this run's one new candidate (hard cap respected). French security-journalism outlet (Damien Bancal); corroborating primary for the Chat Control doxing entry. Rated B: it originates France-nexus reporting rather than re-reporting. fetch_method bridge — direct WebFetch returns 403.— → —
cyberattaque-orglast_successful_fetch -> 2026-07-27 (in-window primary for the Chat Control doxing entry); failure and quiet counters reset.— → —
ransom-isaclast_successful_fetch -> 2026-07-27 (primary for the Windchill extortion-wave update entry); counters reset.— → —
bleepingcomputerlast_successful_fetch -> 2026-07-27 (corroborating source for the Windchill extortion-wave update entry); counters reset.— → —
wordpress-org-newslast_successful_fetch null -> 2026-07-27 — first successful fetch since the source was added, clearing the rotation-priority flag it had carried for eight runs. Fetch succeeded via the documented feed but returned nothing in-window, so it is recorded as 200-but-quiet: consecutive_quiet_periods incremented to 1.— → —
paradigm-shift-researchnotes only — recipe-quality gap documented. No status change.— → —
reliaquestnotes only — recipe-quality gap documented. No status change.— → —
trellixnotes only — recipe-quality gap documented (stale/cached listing index). No status change.— → —

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
inside-it-chhttps://www.inside-it.ch/rssrsswebfetchjinabridge:url403 http_client
The RSS feed and individual article URLs both returned HTTP 403 to the direct fetch, and the jina-reader fallback was blocked as well. The bridge was re-attempt
WebSearch snippets substituted for the listing sweep, and the independent Swiss/EU sweep (NCSC-CH Im Fokus, Aktuelle Vorfälle, cyberattaque.org, swisspost-cyber

Bridge invocations (this run)

5 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

5 other
  • url (fetch_source.py) ×4
  • url (fetch_source.py, auto reader-fallback) ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? NEEDS_FIXES · 4 findings (truth=0, editorial=0, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
The entry treated 11.0 M030 as a fix floor in four places (cves[].affected, cves[].fixed, body paragraph 3, and the action item). PTC's own advisory lists 11.0 M030 among the versions that RECEIVE a pConfirmed against PTC's advisory directly (fetched via the bridge). Corrected all four loci: cves[].affected now states the NVD vulnerable range and points at P
F3
claim-not-supported
The opening sentence cited only Cyberattaque.org, but the figure 24, the term 'Chat Control 1.0' and the ePrivacy-derogation description appear solely in ZATAZ. On the Cyberattaque page '24' occurs onRewrote the opening so each fact is attributed to the source that carries it: the Chat Control 1.0 characterisation and the count to ZATAZ, the actor handle and
F9
surface-contradiction
Title, headline, summary and the registry record all asserted 24 targets, but Cyberattaque.org enumerates a second group of officials and states explicitly that the total is not specified — a contradiDropped the bare count from the title and headline and made the disagreement explicit in the summary, the body and the actor:cybernox registry summary: ZATAZ co
F11
editorial-advisory
Advisory: the sectors list carried `defense`, which neither cited source states — Ransom-ISAC names Manufacturing, Automotive, Aerospace and Retail/Apparel. Inherited from the June parent entry.Removed `defense` from sectors; the remaining values all trace to the cited advisory.

Iteration #? NEEDS_FIXES · 2 findings (truth=0, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The iteration-1 F4 remediation over-corrected: it attributed a vulnerable range starting at 11.0 M030 to NVD, but NVD's own record states the flaw 'also impacts Windchill and FlexPLM releases prior toRe-fetched the NVD CPE configuration directly. It confirms the alternate model: the Windchill PDMLink match set covers everything below 11.0 M030 plus each name
F14
?
The correction paragraph claimed 'the first four weeks of confirmed exploitation'. From the 2026-06-25 KEV confirmation to the 2026-07-14 SUP release is 19 days — a quantifier no source states and theRemoved the derived duration entirely and replaced it with the two cited dates, so the reader computes the gap from facts the entry already carries.

Iteration #? NEEDS_FIXES · 4 findings (truth=0, editorial=0, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The body claimed a current 13.1.x release had no patch between the 25 June KEV confirmation and 14 July, contradicting the PTC change log cited in the same sentence chain — PTC shipped a 13.1.1 patch Body paragraph 3 now names the 19 June Windchill 13.1.1 patch explicitly and narrows the exposure claim to estates on 13.1.2 or 13.1.3, noting a 13.1.1 estate c
F3
claim-not-supported
The affected range attributed to NVD was still not what NVD publishes: NVD carries two per-product sets — a contiguous span below 11.0 M030 plus discrete enumerated releases — and FlexPLM tops out at Re-fetched the NVD CPE configuration independently to confirm. cves[].affected and the body now state the no-lower-bound fact with NVD's verbatim clause, then d
F11
editorial-advisory
Advisory: 'third-party' described the compromised sender accounts as external to the victim, which neither source states — both say only that the accounts were compromised.Accepted rather than left. Dropped 'third-party'; the Triage discriminator now rests on 'a compromised account with no prior relationship' and 'a previously-uns
F11
editorial-advisory
Advisory: the body describes filesystem enumeration and data staging that techniques[] did not map.Accepted. Added T1083 and T1074 after confirming both active in the pinned v19.1 dataset; techniques[] is the canonical mapping surface, so evidence-bound compl

Iteration #? NEEDS_FIXES · 3 findings (truth=0, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
The registry summary still described the extortion mail as coming from 'compromised third-party accounts' — the exact unsupported claim removed from the entry body one iteration earlier. The registry Struck 'third-party' from the registry summary to match the entry body. This defect was self-inflicted: the previous iteration's fix was applied to one surface
F14
?
The Defender takeaway said identifiers now circulate 'for these 24 people', re-asserting 24 as a closed total two paragraphs after the entry established that no source gives a total — silently undoingReworded to 'every official named in these dossiers — the 24 ZATAZ counts plus an unquantified second group', keeping the operational point without inventing a
F11
editorial-advisory
Advisory: the notes body used sub-agent shorthand ('sub-agents', S1-S4) in text that renders verbatim as the published Verification Notes, against the rule barring prompt jargon from reader-facing outAccepted and fixed rather than deferred. The notes now describe four parallel research tracks by subject rather than by agent label, and two prose strings insid

Iteration #? NEEDS_FIXES · 5 findings (truth=0, editorial=0, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
Asserted that Windchill 13.0.2 appears in none of PTC's June change-log entries and was first patched on 14 July, which would have made the entry's 18-19 June framing wrong and its exposed set incomplREJECTED on evidence, not applied. Re-parsing the saved PTC advisory body against its change-log date headings shows a 6/18/2026 10:25 AM ET entry reading 'Patc
F14
?
The previous round's rewording implied two disjoint groups totalling more than 24, but the sources overlap — ZATAZ names Glucksmann inside its 24 and Cyberattaque.org lists him again in the second groOverlap confirmed directly in both saved source bodies. Took the churn-free fix and deleted the appositive so the clause ends at 'every official named in these
F11
editorial-advisory
Advisory: workflow vocabulary survived in the fetch-failure message and five bridge-use notes, both of which the operations page renders.Accepted; all six strings reworded neutrally with no factual change. Verified against the site build that the iteration-level note field is not rendered, so the
F11
editorial-advisory
Advisory: the published notes re-asserted 24 as a settled total after the entry had deliberately stopped doing so, and widened ZATAZ's 'French political figures' to 'French and EU'.Accepted; the bullet now attributes the count to ZATAZ and records that a further group exists with no stated total.
F11
editorial-advisory
Advisory: the TA505 alias is carried by no source cited in this run and is a contested equivalence that would silently pull future TA505 reporting into this key.Accepted; TA505 removed. The five remaining aliases are exactly those the cited advisory states. Aliases drive dedup and registry keys are permanent, so an unso

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-07-27T0409Z-intel · Claude Opus 5 · window 24 h · 3 entries published

Run record — 2026-07-27T0409Z-intel

Monday-morning UTC fire, 3 h after the 01:10Z weekly and ~24 h after the previous intel run. The window is the 24 h floor. The active source surface was swept across four parallel research tracks — active threats and vulnerabilities, home region and sector, research and investigative reporting, and incidents and disclosures. The research track returned nothing, a genuine weekend-to-Monday publishing lull in which every major lab's newest post was dated 2026-07-24 or earlier; the other three returned one, two and two items respectively. Three entries published: two new and one update. No deep dive.

Verification & coverage notes

  • Published (3). An exploited, unpatchable-in-1.x remote code execution flaw in Alibaba fastjson (CVE-2026-16723, high); a delta update on the PTC Windchill / FlexPLM campaign now running a mass extortion-email phase attributed to Cl0p affiliates (high, update_of the 2026-06-27 entry); and a hacktivist doxing operation against French political figures over the Chat Control file — 24 by ZATAZ's count, with a further group and no stated total (notable).
  • Sourcing correction caught before composition. The fastjson research return stated that "ThreatBook and Imperva independently confirmed" in-the-wild exploitation. A direct read of the Imperva post found no mention of ThreatBook anywhere in it, and no other fetched source carried that attribution. The ThreatBook claim was dropped and the exploitation evidence is attributed solely to Imperva's own telemetry, which is also why the entry's credibility rating is 2 rather than 1.
  • An apparent contradiction that is not one. CISA's SSVC record for CVE-2026-16723 scores exploitation as none, but it is timestamped 2026-07-23 and Imperva's exploitation report is dated 2026-07-24. The entry states both dates rather than picking a side, and the sourcing note explains the ordering.
  • CVSS discrepancy resolved to the owning records. Reporting on CVE-2026-12569 splits between 9.3 and 9.8. Both are correct on different scales: 9.8 is NVD's primary CVSS v3.1 score, 9.3 is the CVSS v4.0 score PTC assigned as CNA and the figure this store's June entries carry. The update entry uses 9.8 and states the split in its sourcing note. For CVE-2026-16723 the only published score is the 9.0 Alibaba assigned as CNA.
  • Cross-track recovery. The vulnerability track investigated the Cl0p / Windchill story and dropped it as three days stale; the incidents track surfaced it independently with the extortion-phase development the first had not seen. The completeness check recovered it, and it publishes as an update carrying only the delta — the actor attribution and the extortion wave — not a recap of the June exploitation coverage.
  • Attribution kept split where the sources split. The joint Ransom-ISAC / eCrime.ch / DEFUSED advisory frames the Windchill campaign as Cl0p affiliate activity; ReliaQuest, quoted by BleepingComputer, holds the actor unconfirmed on tradecraft overlap. Both framings appear in the entry, and the registry relation carries the same caveat in its note. Similarly, the handle "Cybernox" is named only by Cyberattaque.org — ZATAZ reports the same operation without naming the actor — so the entry attributes the handle to the source that supplies it.
  • Indicators withheld. The Ransom-ISAC advisory publishes command-and-control IP addresses, a file hash, a distinctive attacker request-header value and a web-shell filename pattern. None of these appear in the entry; the behaviour is described instead.
  • borderline-drop: CuteSec / "misère" claim of a 111,528-record French Interior Ministry and Gendarmerie personnel leak — a single hacker post relayed by two lower-reliability outlets with no independent verification of the data's origin, no ministry confirmation or denial, and no high-reliability journalism. Scale and the shared Chat Control campaign link argued for inclusion; corroboration is simply absent. Recoverable as a watch item if the ministry or a stronger outlet confirms.
  • borderline-drop: Deadlock leak-site listing of Schaad, Balass, Menzl & Partner AG, a Zurich and Winterthur intellectual-property law boutique (2026-07-25). Home-region nexus and real client-confidentiality stakes, but the only sources are a leak-site tracker and an aggregator mirror of the same post. The previous fire dropped this item for the same reason and logged it for follow-up; 24 h later it is still uncorroborated, so it stays out.
  • borderline-drop: ExfilSquad claims against the UK Department for Education, the Police National Legal Database and Newcastle University — direct public-sector nexus, but multiple write-ups document this brand posting fourteen victim claims in a single day including implausible entries, with no official confirmation. Publishing would amplify what looks like a fabricated-claim campaign.
  • out-of-window: Deutsche Bank third-party extortion claim (event 2026-07-04, denied by the company); Netze BW / Stuttgart Netze smart-meter third-party breach (freshest source 2026-07-16); SentinelOne Kubernetes CSI path-traversal research (2026-07-23 13:00, roughly 15 h outside the 72 h developing window). Also dropped as stale with no fresh delta: Windows LegacyHive/BlueHammer proof-of-concept activity, Windmill CVE-2026-29059, an OpenSSL denial-of-service issue, Ubuntu snap-confine CVE-2026-8933.
  • Recency disclosure. Two of the three entries rest on sources inside the 72 h developing window rather than the strict 24 h window. The Chat Control entry has an in-window primary (Cyberattaque.org, 2026-07-26 13:12 UTC) alongside a ZATAZ piece published three hours before the window opened. The fastjson entry's substantive sources are the 2026-07-21 vendor advisory and the 2026-07-24 exploitation report; it is carried as an actively developing story because exploitation is ongoing and expanding, no 1.x patch exists, and no national CERT in Switzerland, the Netherlands, Germany, France, Poland or at EU level had published on it. The Windchill entry is an update whose delta dates from 20-25 July. A search for fresher reporting on both stories found nothing newer.
  • No deep dive. No earlier run published one today, so the slot was open, but nothing earned it. The fastjson flaw has confirmed exploitation but reported targeting is almost entirely US-based and constituency exposure is unestablished, so it fails the "non-trivial exposure" half of the first criterion. The Windchill item is a delta on a CVE already deep-dived in June, and the doxing item is not technical. No depth was manufactured to fill the slot.
  • Verification took seven passes, and the loop earned them. Five rounds returned fixes before two consecutive clean reads on different models closed it. The substantive work concentrated on one paragraph of the Windchill entry: the first pass found it treating a version as a patch floor when the vendor lists that version among those receiving a patch, and the correction for that error then over-stated the affected range in the other direction, which the next pass caught. Between them the rounds also removed an unsourced actor alias, a count asserted as settled that the sources leave open, and a claim about compromised sender accounts that neither source makes. One finding was rejected rather than applied: a pass reported that a version had gone unpatched until mid-July when the vendor's own change log records it patched on 18 June, and a later pass re-derived the change log independently and upheld the rejection. The residual count is zero.
  • Source health: clean. The full probe covered 166 of 166 sources in 108 s with no source classed as needing a bridge or a demotion — no standing repair order this run. Three sources nonetheless have a recipe-quality gap the reachability probe cannot see: ps.tc, ReliaQuest and Trellix all answer at the transport layer but their listing pages return only navigation markup or a stale index, so their post content is not actually reachable. Documented in their records for a future run to fix; none is a demotion, since none is a transport failure.
  • Jina reader pool: recovered, with one dead key. The previous four consecutive runs reported the pool exhausted at HTTP 402. It now carries a working balance and served every fetch it was asked for this run, including the github.com-hosted fastjson advisory that no direct transport could reach. One credential in the rotation still returns 402 and the fetcher rotates past it automatically, so the correct read is a partially-degraded but functioning pool, not an outage — a change from how the last four records described it.
  • Coverage gaps: inside-it-ch (403 to every transport — see fetch_failures); ransom-isac blog listing (403 on the index; the specific advisory was reachable via the bridge, so only the sweep of that outlet's other recent posts was lost); apple-security (client-side-rendered advisory table returns no rows to WebFetch or the bridge — a recipe gap, not escalated to the reader because nothing suggested an in-window Apple advisory); cisa-directives (not separately fetched — the advisories and ICS listings showed no in-window CISA activity at all); mysites-guru, kudelski-security, withsecure-labs (not reached inside the 45-minute budget); ccn-cert-es (reader returned a stale 2023 snapshot); le-monde-info (fetch returned apparently mis-cached 2025 content); ncc-research (listing returns boilerplate with a stale date meta).
  • Watchlist: not reported — the organization profile configures no product or supplier watchlists, so both sweeps are no-ops.
  • Essential-coverage: all essential-tier sources in the vulnerability and home-region slices were attempted and answered. The CISA advisories listing was enumerable this run via the bridge and carried no in-window addition; the KEV catalog's newest entry is still dated 2026-07-22.

← Operations dashboard · run-record contract: docs/pipeline.md