ctipilot.ch

2026-07-28T0409Z-intel

One pipeline fire, in full · intel run of 2026-07-28 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-28/2026-07-28T0409Z-intel.md.

Run telemetry

2026-07-28T0409Z-intel intel prompt v3.29 publish ok
1h 54m duration 6 published 1 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
15m 31s
Tool calls
14 WebFetch6 WebSearch32 bridge
Cited sources
2 of 25 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
14m 47s
Tool calls
16 WebFetch12 WebSearch14 bridge
Cited sources
1 of 24 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
17m 21s
Tool calls
33 WebFetch11 WebSearch6 bridge
Cited sources
2 of 38 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
12m 32s
Tool calls
9 WebFetch10 WebSearch12 bridge
Cited sources
2 of 10 in slice

Verification

✓ double-CLEAN · Sonnet 5 + Opus 5 #? NEEDS_FIXES · Opus 5 · t=0 e=0 a=0 #? NEEDS_FIXES · Sonnet 5 · t=0 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=0 e=0 a=0 #? CLEAN · Sonnet 5 · t=0 e=0 a=0 #? CLEAN · Opus 5 · t=0 e=0 a=0

Deep dive

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 status candidate -> active. The state digest reported it in sources.promotion_due with 3 contributing runs (most recent 2026-07-27T0409Z-intel), meeting the three-contributing-run promotion bar. · 1 ADDED as candidate — this run's one new candidate (hard cap respected). Coordinated-disclosure programme publishing original root-cause analyses and working proof-of-concept code; primary source for the vBulletin entry. Rated B: original vulnerability research, not a first-party vendor authority. fetch_method jina — direct WebFetch returns a partial render. · 1 last_successful_fetch -> 2026-07-28 (primary discovery path for both KEV additions this run); counters reset. · 1 last_successful_fetch -> 2026-07-28 (discovery path for the vBulletin advisory WID-SEC-2026-2528, cited as a corroborating source); counters reset. · 1 last_successful_fetch -> 2026-07-28 (primary for the EY update entry, corroborating for the Dysphoria entry); counters reset. · 1 20 essential and rotation sources were fetched successfully but carried nothing in-window: last_successful_fetch -> 2026-07-28 and consecutive_quiet_periods incremented on advisories-ncsc-nl, anssi-fr, cert-eu, cert-at, cert-pl, enisa, ncsc-ch-focus, ncsc-ch-incidents, ncsc-ch-security-hub, ncsc-uk, cisa-advisories, enisa-euvd, sans-isc, lab52, truesec, infoguard-labs, senthorus-ch, swisspost-cybersecurity, infoguard-ch, kommunaler-notbetrieb-de. · 1 consecutive_fetch_failures incremented; reader returned HTTP 402 and the direct fallback returned a navigation shell. No demotion — transport block, not content death. · 1 consecutive_fetch_failures incremented (HTTP 403 to every available transport). No demotion — 403 is an anti-bot block. · 1 consecutive_fetch_failures incremented (reader returned navigation chrome only). No demotion. · 1 consecutive_fetch_failures incremented (client-side-rendered advisory table returns no rows). No demotion; recipe gap documented. · 1 consecutive_fetch_failures incremented (bridge returned the JS-rendered page shell with no dated listing). No demotion; recipe gap documented..

SourceChangeFrom → ToReason
ransom-isacstatus candidate -> active. The state digest reported it in sources.promotion_due with 3 contributing runs (most recent 2026-07-27T0409Z-intel), meeting the three-contributing-run promotion bar.— → —
ssd-disclosureADDED as candidate — this run's one new candidate (hard cap respected). Coordinated-disclosure programme publishing original root-cause analyses and working proof-of-concept code; primary source for the vBulletin entry. Rated B: original vulnerability research, not a first-party vendor authority. fetch_method jina — direct WebFetch returns a partial render.— → —
cisa-kevlast_successful_fetch -> 2026-07-28 (primary discovery path for both KEV additions this run); counters reset.— → —
bsi-delast_successful_fetch -> 2026-07-28 (discovery path for the vBulletin advisory WID-SEC-2026-2528, cited as a corroborating source); counters reset.— → —
bleepingcomputerlast_successful_fetch -> 2026-07-28 (primary for the EY update entry, corroborating for the Dysphoria entry); counters reset.— → —
multiple20 essential and rotation sources were fetched successfully but carried nothing in-window: last_successful_fetch -> 2026-07-28 and consecutive_quiet_periods incremented on advisories-ncsc-nl, anssi-fr, cert-eu, cert-at, cert-pl, enisa, ncsc-ch-focus, ncsc-ch-incidents, ncsc-ch-security-hub, ncsc-uk, cisa-advisories, enisa-euvd, sans-isc, lab52, truesec, infoguard-labs, senthorus-ch, swisspost-cybersecurity, infoguard-ch, kommunaler-notbetrieb-de.— → —
ccn-cert-esconsecutive_fetch_failures incremented; reader returned HTTP 402 and the direct fallback returned a navigation shell. No demotion — transport block, not content death.— → —
inside-it-chconsecutive_fetch_failures incremented (HTTP 403 to every available transport). No demotion — 403 is an anti-bot block.— → —
mysites-guruconsecutive_fetch_failures incremented (reader returned navigation chrome only). No demotion.— → —
apple-securityconsecutive_fetch_failures incremented (client-side-rendered advisory table returns no rows). No demotion; recipe gap documented.— → —
ico-ukconsecutive_fetch_failures incremented (bridge returned the JS-rendered page shell with no dated listing). No demotion; recipe gap documented.— → —

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
ccn-cert-eshttps://www.ccn-cert.cni.es/en/jinabridge:url402 http_client
The record pins the reader proxy as its transport because the host blocks direct egress. The reader returned HTTP 402 — the metered credit pool is exhausted — a
The other national-CERT surfaces in the home-region slice (NCSC-NL, CERT-FR, BSI, CERT-AT, CERT-PL, CERT-EU, NCSC-CH, NCSC-UK, ENISA) were all reached and swept
inside-it-chhttps://www.inside-it.ch/rsswebfetchbridge:urljina403 http_client
HTTP 403 to the direct fetch again this run, the same block recorded on 2026-07-27. The bridge was re-attempted explicitly at 2026-07-28T04:52Z: `python3 tools/
The home-region sweep covered the same ground through NCSC-CH's three surfaces, swisspost-cybersecurity, senthorus, infoguard and targeted German- and French-la
apple-securityhttps://support.apple.com/en-us/100100webfetch200 content_shape
The fetch succeeded at the transport layer but the summariser returned only a truncation notice — the advisory table is client-side rendered and no advisory row
Not escalated: no signal from any other source pointed at an in-window Apple advisory, and the rotation will pick the source up again. Logged so a future run au

Bridge invocations (this run)

10 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

10 other
  • url (fetch_source.py) ×7
  • cisa-kev (fetch_source.py) ×1
  • cisa page (fetch_source.py) ×1
  • url (fetch_source.py, auto reader-fallback) ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? NEEDS_FIXES · 12 findings (truth=0, editorial=0, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
Patch dates, the 6.2.2 reference and the Cloud-already-patched statement were cited to the SSD advisory, whose Vendor Response section is two bare links and carries none of them.Fetched the vBulletin security announcement directly and added it as a primary source; re-attributed every fact to it across the summary, body, cves[].fixed and
F3
claim-not-supported
"BSI rates the advisory critical" was cited to the rendered HTML advisory, which displays no severity word.Partially rejected, then fixed for precision. BSI's structured CSAF for that advisory id does carry aggregate_severity kritisch, so the characterisation is BSI'
F3
claim-not-supported
The sourcing note claimed the vendor page shows 5.3 with no vector and framed 5.3-vs-5.9 as an inconsistency in Fortinet's own records. The 5.3 hyperlinks to the same base vector with temporal metricscves[].cvss changed 5.3 -> 5.9 and the note rewritten to explain the base/temporal relationship so a reader who sees 5.3 on the vendor page can reconcile it. Th
F4
hallucinated-fact
The sourcing note described leak-site listings naming two further organisations in the same wave. The entry is single-source on BleepingComputer, which reports only EY; the names came from a tracker tSentence deleted from the entry and the equivalent claim deleted from the run-record notes. Citing the tracker was rejected: the run had already decided not to
F4
hallucinated-fact
The body claimed the detection date and the 24 months of identity monitoring were details not in the original filings. Both are already published in the 2026-07-19 entry this one updates, and the deteRewritten to claim only what is genuinely new — that the report names Experian as the monitoring provider the original coverage recorded without naming. An upda
F4
hallucinated-fact
Two statements in the notes were false about this run's own entries — that the FortiOS entry used 5.9 (it carried 5.3 at the time) and that the vBulletin entry recorded both 9.8 and 9.3 (it records onBoth rewritten to describe what the entries actually carry after the scoring remediation. The notes render to the site, so these were reader-visible falsehoods.
F13
?
An assessment that the relay pivot was a resilience response to a March 2026 law-enforcement disruption was attributed to XLab, which makes no motive assessment and mentions no takedown.Attribution clause removed. The sentence now states only what the source supports — the 2026-06-25 dating and XLab's own relay-transformation term — and says XL
F14
?
"a maintained set of thirteen known IoT remote-code-execution flaws" hardened into a set size what the source introduces as a partial list. The wording had propagated into the registry record.Entry body and registry summary now say XLab names thirteen identifiers and presents them explicitly as only part of the observed set.
F5
missing-citation
The SSL-VPN language-file-directory detail — which the entry's first action item turns on — appeared in three places with no citation carrying it; the PSIRT advisory never names the directory.Fetched Fortinet's own 2025 PSIRT blog, already referenced from the advisory, added it as a corroborating source, quoted it verbatim in the body and added it as
F10
missed-angle
Flagged a 2026-07-27 Zscaler post on a government-targeting campaign as an in-window item the run left behind.REJECTED on evidence, not applied. The exact URL proposed is already the primary source of the 2026-07-26 TELESHIM entry, published two days earlier and present
F11
editorial-advisory
Advisory: techniques[] mapped a defence-evasion id for a behaviour the body never described.Accepted. A body clause now describes the seller's advertised in-memory execution feature with its AMSI patch and ETW bypass, flagged as marketplace-claimed rat
F11
editorial-advisory
Advisory: three evidence quotes were not byte-exact substrings — straight quotes for the source's curly ones, a dropped leading word, two adjacent list items joined, and a truncated clause.Accepted and normalised rather than deferred; the joined quote was split into two records. Verbatim means a contiguous substring, so these are worth fixing even

Iteration #? NEEDS_FIXES · 2 findings (truth=0, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F8
needs-more-research
The entry hedged that no cited source dates the 6.2.2 release, but the date was available and had already been fetched by three of the four research tracks.Accepted, with a more primary source than the one suggested: the discloser's own advisory carries a dated disclosure timeline recording the vendor patch on 2026
F11
editorial-advisory
Advisory: two evidence quotes were not byte-exact — a straight apostrophe where the source has a curly one, and a stray space introduced by de-tagging. Same fidelity class fixed elsewhere one iteratioAccepted; both byte-checked against the fetched page and corrected.

Iteration #? NEEDS_FIXES · 9 findings (truth=0, editorial=0, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F14
?
The immediate_action block called network restriction the only mitigation the vendor offers; the advisory's Mitigation section lists four controls. The body already worded it correctly.Reworded to the only exposure-reducing control, noting the other three are monitoring measures — keeping the substantive point without the false absolute.
F12
single-source-flag-missing
The entry claimed independent corroboration from a press article that attributes every technical and scale claim back to the single research report and performs no first-hand observation. Independenceverification changed multi-source -> single-source, credibility lowered 1 -> 2, sourcing note rewritten to describe the article as a same-day press account, and
F12
single-source-flag-missing
Same defect on the second threat entry: every technical element the second outlet carries belongs to the primary research, and the entry's own body already said as much, contradicting its sourcing notSame four changes. The outlet's observation about the base rate of legitimate hidden-desktop use is retained as an attributed editorial point, which is what it
F8
needs-more-research
The triage discriminator told the reader that a process presenting the malware's masquerade name is the artifact, but never stated the name, leaving it unusable by a human responder or an automated coThe triage line now names the string. Judged not an indicator: it is a fixed behavioral masquerade name of the same class as the trusted-binary name this run's
F11
editorial-advisory
Advisory: formatting characters had been inserted inside a quoted string whose source carries none.Removed from both the evidence record and the body's rendering of the same quote.
F11
editorial-advisory
Advisory: an infostealer theme tag with no credential or data theft described anywhere in the entry or its sources.Tag dropped.
F11
editorial-advisory
Advisory: a phishing theme tag when no cited source names a delivery vector.Tag dropped.
F11
editorial-advisory
Advisory: the critical-priority justification claimed no exploitation precondition an operator can remove, but network reachability is removable by placement — as the entry itself says.Softened to no precondition removable in configuration, leaving network placement as the only lever. The rating stands on its other grounds.
F11
editorial-advisory
Advisory: a research sub-agent left its findings file truncated mid-string, so it failed to parse. It ships with the run as the operator's forensic surface.Unterminated quote closed; the file now parses.

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-07-28T0409Z-intel · Claude Opus 5 · window 26 h · 6 entries published

Run record — 2026-07-28T0409Z-intel

Tuesday-morning UTC fire, 24 hours after the previous intel run, so the window sits exactly on the 24-hour floor and widens to 26 hours for overlap. Four parallel research tracks covered active threats and vulnerabilities, the home region and sector, research and investigative reporting, and incidents and disclosures. All four returned inside the cap. Six entries published: five new and one update. No deep dive. The fire ran just under two hours end to end, most of it in a five-iteration verification loop.

Verification & coverage notes

  • Published (6). Two vulnerabilities that CISA confirmed as exploited on the same day — an unauthenticated OS command-injection flaw in Arista's on-prem VeloCloud Orchestrator (critical) and a FortiOS SSL-VPN flaw that defeats the vendor's own fix for the symlink-persistence technique (high); a vBulletin pre-authentication code-execution flaw whose working exploit went public four weeks after the patch (notable); an update on the Ernst & Young support-platform breach now claimed by an extortion group (notable); and two threat entries, an IoT botnet that moved its command-and-control addressing onto blockchain name services (notable) and a malware-as-a-service trojan that drives the victim's own logged-in browser on a hidden Windows desktop (notable).
  • One critical this window, and why it clears a bar nothing has cleared in fourteen days. The store has published no critical entry in the trailing fortnight, and comparable items — including a CVSS 10.0 actively-exploited SonicWall appliance flaw on 2026-07-14 — shipped at high. The Arista item is rated higher on facts the vendor states rather than on severity score. Exploitation is asserted by the vendor itself, not inferred from a catalog listing. There is no exploitation precondition an operator can remove in configuration: the advisory says the interface is exposed by default, that no configuration can prevent the exposure, and that no credentials are required, leaving network placement as the only lever — where the SonicWall comparison required the appliance to be internet-facing. And the affected component is a management plane whose compromise the vendor says may extend to the managed Edge fleet, so the blast radius is not one host. Disclosure, patch and exploitation confirmation all landed inside this window.
  • A vendor field and a government catalog disagree, and the entry says so. As fetched during this run, Fortinet's FG-IR-25-934 still displays "Known Exploited: No" with a timeline whose last update is 2026-03-12, while CISA added the same CVE to the Known Exploited Vulnerabilities catalog on 2026-07-27. This is not treated as a contradiction between two claims about the world — the vendor field appears simply not to have been refreshed since March — but the entry records both states rather than quietly presenting the catalog listing as vendor-confirmed.
  • A CVSS figure that looked like a vendor contradiction and was not. The research return carried CVSS 5.3 for the FortiOS flaw from the FortiGuard advisory page, while the vector Fortinet submitted as CNA computes to 5.9. Composition initially recorded that as an inconsistency inside Fortinet's own records. Verification found the actual explanation: the 5.3 on the advisory hyperlinks to the same base vector with temporal metrics appended, so 5.3 is the temporal-adjusted score of the 5.9 base. The entry now carries 5.9 — the rest of the store's CVE records carry base scores, and mixing a temporal one in would have quietly corrupted comparison — and explains the relationship so a reader who sees 5.3 on the vendor page can reconcile the two. Separately, the vBulletin score is the 9.3 the CNA publishes on its own advisory.
  • An affected range widened by reading the owning record. Two research tracks reported the vBulletin flaw as affecting the 6.x branches only, following the discloser's advisory. The NVD record states 5.x through 5.7.5 as well, and no fixed 5.x build is named anywhere — a materially larger and less remediable exposed population than the advisory's own summary implies. The entry carries the wider range and flags that 5.x operators need a migration plan rather than a patch.
  • A claimed intrusion, framed as a claim throughout. The Ernst & Young update rests entirely on assertions an extortion group made to one outlet, which states plainly that it cannot verify them and that the victim has not confirmed the attribution. Every element — the supply-chain credential theft, the reach into issue tracking, source control and a cloud tenant, the deadline — is attributed rather than asserted, the entry's confidence is low and its credibility rating is 3. The transferable lesson is written so it holds whether or not the claim is true.
  • A relationship recorded at the strength the source supports. The registry now carries an attributed-to edge from the Ernst & Young incident to the claiming group, with a note stating in the edge itself that the basis is a leak-site self-claim the reporting outlet could not verify and the victim has not confirmed. The edge exists because the claim is the news; the note exists so no downstream reader mistakes it for an established attribution.
  • An alias deliberately not created. The research return proposed registering the two predecessor malware families as aliases of the new botnet key. They are ancestors in a code lineage, not other names for the same thing, and aliases drive dedup on permanent keys — an incorrect one would silently pull future reporting on those families into this record. The lineage is described in the registry summary instead.
  • A revoked ATT&CK id caught before it shipped. The technique planned for the advertised defence-evasion feature of the hidden-desktop trojan is revoked in the pinned v19.1 dataset in favour of a successor id. The mapping was validated against the pin on disk before composition and the successor used. All mapped ids across the six entries were checked the same way.
  • Indicators withheld. Four of this run's primaries publish indicators: the Arista advisory names attacker source addresses, the botnet report publishes hashes, conventional domains, blockchain names and infrastructure addresses, and the hidden-desktop analysis names a hardcoded command-and-control endpoint and the sample's dropped file names. None appears in any entry; the behaviour is described instead, and each entry's sourcing note points the reader at the vendor page for the indicators themselves.
  • A vendor pitch stripped from a primary. The hidden-desktop analysis closes by recommending its publisher's own product. Only the non-promotional part of its detection reasoning is carried, and the entry's triage discriminators are derived from the mechanics the analysis documents rather than from its remediation section.
  • Two entries corrected from multi-source to single-source. Verification found that the second source on the botnet and hidden-desktop entries was in each case a same-day press write-up of the single research report the entry already cited, attributing every technical claim back to it and adding no first-hand observation. Independence is about first-hand observation rather than count, so both entries were reclassified single-source and their credibility ratings lowered from 1 to 2. The reporting is still cited — it is simply not corroboration.
  • borderline-drop: internet-wide scanning for a Spring Boot Actuator heap-dump endpoint using default admin:admin credentials, reported by a single handler diary. The one genuinely new detail is that the scanner probes a relocated management base path rather than the default, which retires path-obscurity as a control. That is a real but small refinement to a misconfiguration class this audience already inventories, it is single-sourced, and the honest answer to whether a Tier 2/3 responder would act differently in the next seven days is no. Recoverable if exploitation or a named victim emerges.
  • borderline-drop: leak-site listings for roughly six small and mid-sized German organisations and one French brokerage. Home-region nexus, but leak-site claims only, with no victim confirmation and no high-reliability journalism — the corroboration bar for extortion claims is not met.
  • borderline-drop: a third breach claim against a US airline. No home-region or sector nexus, thin transferable technique content (a previously-disclosed unpatched flaw re-exploited by a second opportunistic actor), and the primary was unreachable on every transport, so it could not have been cited even if it had cleared the gate.
  • out-of-window: macOS trusted-application code-replacement research (primary 2026-07-23, with a 2026-07-27 pickup that added no technical delta); a fake-Teams-update multi-RMM phishing campaign (primary 2026-07-21, outside even the 72-hour developing window); a Council of Europe extortion case; a hotel Wi-Fi DNS campaign; and a beverage-sector extortion claim. Also dropped as too thin a delta: a French advisory adding one CVE to an already-covered June batch of an IT-asset-management platform.
  • A duplicate correctly caught rather than re-published. The home-region track investigated the sixteen-nation joint advisory on Russian webmail espionage in full technical depth before confirming, against the coverage index and the registry, that it is the same advisory at the same URL already used as the primary for entries published on 2026-07-24 and 2026-07-25. It was dropped as a genuine duplicate rather than reframed as an update, which is the correct disposition when there is no delta.
  • Recency disclosure. Five of the six entries rest on primaries published inside the strict 26-hour window. The botnet entry does not: its technical primary is dated 2026-07-25, two days before the window opened, and the in-window fact is the first independent security-press coverage on 2026-07-27. It is carried on the 72-hour developing-story window with event_date set to the research publication date, and the sourcing note states the framing so no reader is misled about freshness.
  • No deep dive. No earlier run published one today, so the slot was open, and it was left empty deliberately. The highest-urgency item is the Arista flaw, but its advisory describes the vulnerability only as reachable "privileged internal functionality" with no component path, no exploitation mechanics and no kill chain — there is not enough public technical substance to sustain long-form treatment without padding it. The FortiOS item has the better hunt story but its advisory runs to four sentences, and the background material predates the window by more than a year. The botnet report is by far the most technically substantive primary in the window, but its measured footprint sits largely outside the constituency and its actionable surface for this audience is bounded. No depth was manufactured to fill the slot.
  • Verification took five passes and closed on two consecutive clean reads from different models. Eleven truth defects were found and fixed across the first three rounds, and the two most consequential were both about sourcing rather than facts. The first: an apparent contradiction between two Fortinet scores — 5.3 on the advisory page, 5.9 from the vector — was written up as an inconsistency in the vendor's own records, when the 5.3 is simply the temporal-adjusted view of the same 5.9 base. Two later rounds re-derived the arithmetic independently and agreed. The entry now carries the base score, because every other record in this store does. The second: two threat entries claimed independent corroboration from a second outlet that had, in each case, done no first-hand work and attributed everything back to the single research report already cited. Both were reclassified single-source with their credibility ratings lowered. Also removed along the way: a motive assessment credited to researchers who never made it, a count that hardened a source's explicitly partial list, an absolute about vendor mitigations the advisory contradicts, and a claimed delta an update entry's own parent had already published. One finding was rejected rather than applied — a pass reported a research publication as a missed angle when that exact source is already the primary of an entry published two days earlier, and two later passes confirmed the rejection. The residual count is zero.
  • Source health: clean. The full probe covered 168 of 168 sources in 93 seconds with nothing classed as needing a bridge or a demotion, so there is no standing repair order this run. Three recipe-quality gaps are recorded against their source records for a future run: an Apple advisory table and a UK regulator listing that both render client-side and return no rows to the current transport, and a Spanish national-CERT listing in the same condition.
  • Reader-proxy credit pool still exhausted. The metered reader proxy returned HTTP 402 again this run, the fourth consecutive fire to record it. It is the pinned transport for the Spanish national CERT and the documented fallback for several anti-bot-blocked hosts, so its absence is what turned two of this run's three fetch failures into hard gaps rather than recoverable ones. Direct transports carried every source that could be reached without it.
  • Coverage gaps: ccn-cert-es, inside-it-ch, apple-security (see fetch_failures); ico-uk (listing renders client-side, no dated items reachable); mysites-guru (reader returned navigation chrome only); cisa-directives (listing page returns navigation markup with no drillable content, and no in-window directive activity surfaced elsewhere); group-ib (blog index returns an alphabetical archive with no date ordering — an RSS recipe would fix it); sysdig (JS-rendered shell, newest identifiable post predates the window); intrinsec (listing resolved but the drilled article URL 404'd); kudelski-security, synacktiv, le-monde-info, jpcert (not reached inside the 45-minute research budget; rotation priority next fire).
  • Watchlist: not reported — the organization profile configures no product or supplier watchlists, so both sweeps are no-ops and both tracks correctly reported zero checked and zero hits.
  • Essential-coverage: all essential-tier sources in the vulnerability and home-region slices were attempted and answered. The KEV catalog returned catalogVersion 2026.07.27 carrying both of this run's additions; the CISA advisories listing was enumerable and showed no other in-window item.

← Operations dashboard · run-record contract: docs/pipeline.md