ctipilot.ch

2026-07-30T0409Z-intel

One pipeline fire, in full · intel run of 2026-07-30 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-07-30/2026-07-30T0409Z-intel.md.

Run telemetry

2026-07-30T0409Z-intel intel prompt v3.29 publish ok
48m 42s duration 8 published 1 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
12m 27s
Tool calls
6 WebFetch2 WebSearch28 bridge
Cited sources
4 of 24 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
7m 24s
Tool calls
11 WebFetch12 WebSearch11 bridge
Cited sources
0 of 16 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
7
Duration
18m 05s
Tool calls
24 WebFetch6 WebSearch14 bridge
Cited sources
7 of 30 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
11m 09s
Tool calls
10 WebFetch8 WebSearch9 bridge
Cited sources
1 of 8 in slice
DR1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
11m 00s
Tool calls
0 WebFetch0 WebSearch13 bridge
Cited sources
9 of 9 in slice
DR2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
15m 16s
Tool calls
0 WebFetch4 WebSearch24 bridge
Cited sources
9 of 9 in slice

Verification

#? NEEDS_FIXES · Opus 5 · t=12 e=2 a=0 #? NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=2 e=1 a=0 #? NEEDS_FIXES · Sonnet 5 · t=0 e=1 a=0

Deep dive

2026-07-30/cve-2013-4786-exposed-bmc-ipmi-rakp-hash-disclosure

Entries published (this run)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

2 fetch_method bridge -> jina · 1 status candidate -> active · 1 added as candidate · 1 fetch_method webfetch -> rss, rss_url set.

SourceChangeFrom → ToReason
siemens-productcert-csafstatus candidate -> active— → —The state digest counted 3 distinct contributing runs, meeting the promotion bar.
prodaftfetch_method bridge -> jina— → —HTTP 200 but a pure client-hydrated Next.js shell with no server-rendered listing and no embedded JSON island, so no dated report is extractable without already knowing a slug. Transport repair, not a demotion.
ico-ukfetch_method bridge -> jina— → —HTTP 200 but the enforcement-action list sits behind a JS-hydrated block grid exposing no dated action hrefs in the raw body. Transport repair, not a demotion.
hunt-ioadded as candidate— → —This run's single new candidate, surfaced by S3. Threat-infrastructure research blog already cited by a published entry on 2026-07-25, so it was already contributing as a citation without being tracked as a source.
truesecfetch_method webfetch -> rss, rss_url set— → —The source-health sweep flagged this needs-demote on HTTP 502 from the webfetch listing path. Not demoted — a 5xx is transport failure, not source death. Probed the ladder and found a cheaper working rung: the blog's WordPress feed returns dated items, verified in-run against posts dated 2026-07-28, 2026-07-20 and 2026-07-16. The direct bridge also reaches the HTML listing with HTTP 200, so the 502 was transient at the origin.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Bridge invocations (this run)

6 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

6 ok
  • bridge: ×4
  • api: ×2

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? NEEDS_FIXES · 18 findings (truth=12, editorial=2, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The entry credited a Broadcom bug-bounty programme as the reporting channel; the word bounty appears nowhere in the cited advisory, which says only that the flaws were privately reported and names PwnSummary and body reworded to privately reported to Broadcom, with Pwn2Own named for the one report the advisory attributes to it, and the credits listed as the
F3
claim-not-supported
An uncited closing sentence attributed management-segmentation hardening guidance to Broadcom and to both NCSC-CH and NCSC-NL; the verifier fetched all three and found it only in NCSC-NL's advisory.Rewritten to attribute the guidance to NCSC-NL alone with an inline citation, and to state that Broadcom's advisory carries no hardening section and records no
F4
hallucinated-fact
The CVE-2026-41703 fixed-version record assigned build 5.2.3 to the Workstation and Fusion tracks; the advisory's response matrix gives 5.2.3 as the Cloud Foundation 5.x ESX fix, with Workstation and Corrected in the CVE record. A version mis-assignment of exactly the kind an automated triage consumer would act on wrongly.
F3
claim-not-supported
The entry stated the proof-of-concept was not released. The cited research post makes no such statement and in fact publishes a complete copy-pasteable single request that reaches code execution; onlySummary, sourcing note and body rewritten to say that the single unauthenticated request reaching code execution was published in full and only the eight-step c
F3
claim-not-supported
A 2026-06-30 disclosure date and a claim that the researchers independently verified the fix were both attributed to the cited post, which carries neither.Both removed. The timeline now uses the researchers' own wording about a fix merged within a few hours, plus the maintainer advisory's own publication date, eac
F4
hallucinated-fact
The product was described as formerly Claude Flow in both the summary and the body's first sentence; neither cited source supports the former name.The rename clause was dropped and the opening sentence rebuilt on what the sources do support — that the platform orchestrates agent swarms for Claude Code and
F3
claim-not-supported
The Coinspect researcher was credited with all three CVEs; the cited bulletin credits him with CVE-2026-16496 only and states the other two were identified by an internal team.Credit restricted to CVE-2026-16496, with the internal-team attribution quoted for the other two.
F4
hallucinated-fact
The sourcing note claimed the per-CVE scores live in structured metadata rather than as body claims, while the body stated five of them in prose — the note contradicted its own entry.The numeric scores were removed from the body prose, leaving them in the CVE metadata where the note says they are, and the note's claim is now accurate. The ni
F14
?
The compromises were said to span eighteen months; no source states it and the entry's own dates give twelve months from March 2025 to March 2026.Replaced with the date range itself rather than a computed span.
F14
?
The entry asserted no other vendor has published a matching assessment. The cited post says the opposite for one of the four packages: the axios compromise had already been publicly attributed to thisBody and sourcing note both narrowed to the vendor's own framing, with its sentence on which links are new quoted directly.
F4
hallucinated-fact
The rehearsal package was described as a typosquat in the title, the summary and the body; the word appears in neither cited source and both describe a package compromise into which a trojanised file Corrected to a package compromise in the title, summary and body, and the registry record for the actor was corrected in the same pass.
F14
?
The entry stated no vendor patch exists or can exist. Neither cited source makes that absolute claim, and the research post's own prior-work section links a hardware vendor advisory covering the same Softened in both the summary and the CVE record to what the sources carry — no vendor patch is offered, remediation is exposure removal and credential replaceme
F5
missing-citation
A 150-word paragraph asserting nine CVE ids, five scores, six fixed builds, the assigning authority and a publication date carried no inline citation. The verifier independently confirmed every fact iThe vendor release-notes citation attached to the ids, the builds and the branch scoping, and the numeric scores moved out of prose into the CVE metadata.
F9
surface-contradiction
The vendor's bulletin and the vendor's own per-CVE records give different affected lower bounds — 0.2.1 versus 0.3.0 — and the entry silently kept the bulletin's without surfacing the discrepancy.Both positions now stated in the body and the sourcing note, with the wider lower bound retained so the entry cannot under-scope an operator on a 0.2.x build, a
F11
editorial-advisory
Workflow-internal language leaked into reader-facing run-record text: phase numbering in three places and a sub-agent reference in a fourth.All four reworded to plain description — the deep read, the incident-domain research pass — per the no-internal-jargon rule.
F11
editorial-advisory
A phishing theme tag had no basis in either cited source, on an entry whose own sourcing note stresses that the credential-origin hypotheses are hedged speculation.Tag removed, keeping the site's phishing list page honest. The infostealer tag was retained because it traces to the analyst's stealer-log hypothesis.
F11
editorial-advisory
Timing claims of all the same day and the following day were asserted more precisely than the German CERT datelines support, both of which carry a 2026-07-28 date.Both softened to the date range the datelines actually support, with the German advisory's revision date stated explicitly.
F11
editorial-advisory
The body deliberately withheld two malware constants but a frontmatter evidence quote printed one of them verbatim, undoing the entry's own discipline. Not a hard IOC breach, but inconsistent.That evidence record was replaced with a constant-free quote describing the same second-stage behaviour.

Iteration #? NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
The remediation for the earlier unsupported product-rename claim replaced it with a description naming Claude Code and Codex. Codex appears in neither cited source; it traces only to the per-CVE databThe opening sentence now describes the platform only as an open-source AI agent orchestration platform shipping a chat interface, agent swarms, persistent memor
F4
hallucinated-fact
The notes stated four entries at high and four at notable; the entries' own priority fields carry five high and three notable, so the run record misdescribed the composition of its own brief.Corrected to five at high and three at notable, verified against the priority field of all eight entry files rather than from recollection.

Iteration #? NEEDS_FIXES · 3 findings (truth=2, editorial=1, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The iteration-1 fix said the researchers withheld their automated eight-step impact chain. The cited post says it built that chain and then publishes all eight steps in detail, so the correction had oBody, summary and sourcing note now state that both the single unauthenticated request and the full eight-step chain were published, and that the reproduction b
F4
hallucinated-fact
The coverage-gaps line named sekoia, swisscybersecurity-net and netzwoche as not fetched in this run, while the home-region research return records dated content from all three.Corrected to state that all three were fetched and were quiet or out-of-window, with the dates the research pass recorded, and that us-treasury-ofac was the one
F11
editorial-advisory
The entry omitted VMware Telco Cloud Platform and VMware Telco Cloud Infrastructure, which Broadcom's advisory lists as impacted with their own knowledge-base fix path rather than the vSphere build nuBoth products added to affected_products and a paragraph added stating that they take a separate fix path, so a telco operator does not assume the vCenter and E

Iteration #? NEEDS_FIXES cap-breach · 1 finding (truth=0, editorial=1, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F17
?
The entry carried Admiralty credibility 1 while its verification value is single-source. Credibility 1 is defined in the organization profile as corroborated by other independent sources, and the storCredibility changed from 1 to 2, with the reasoning added to the sourcing note: reliability stays A because the vendor PSIRT is the first-party authority for it

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-07-30T0409Z-intel · Claude Opus 5 · window 26 h · 8 entries published

Verification & coverage notes

This was a standard 26-hour window derived from a 24-hour gap to the previous fire, with no scheduler outage and no catch-up backfill required. Thirteen candidates were surfaced across four research domains; eight were published and five were dropped.

The home-region and sector domain returned nothing. All four of its essential sources were swept — CERT.at, ENISA, and both NCSC-CH surfaces — along with ten rotational records including inside-it-ch, which recovered from the 403 that had blocked it on the two previous runs. Every Swiss, German, French and Italian public-sector and critical-infrastructure lead resolved to either already-covered ground with no material delta, or to items whose publication dates fell outside the window. Two recycled stories were caught and dropped on date checks: a January 2025 article and a March 2026 breach report, both surfacing in search results as though current. A genuinely quiet day for the home region is a normal outcome, not a coverage failure, and nothing was withheld to keep the count down.

Five drops, each recoverable from this record:

  • borderline-drop: Health-ISAC ShinyHunters healthcare advisory — the vishing-to-helpdesk-reset-to-SSO-takeover chain it describes is already published here three times inside the window, and all four healthcare victims it names already have their own entries. Its mitigations read identically whether or not this advisory existed. A sector-wide restatement of already-covered tradecraft belongs to the weekly lens rather than an operational entry.
  • borderline-drop: Flying Eagle and Night Dragon Android malware-builder service — targeting is China-domestic and the overlays impersonate Chinese payment and state banking apps, which this constituency does not defend. The portable elements do not change what a defender here patches, hunts, blocks or detects.
  • borderline-drop: Operation Double Barrel — victimology is confined to Korean citizens and businesses, initial access ran through Korean financial-security software and Korean watering-hole sites, and the publishing lab states it cannot establish whether the state-actor and ransomware-crew relationship is operational collaboration or shared tooling. The observation is about attribution rather than about anything a reader here would hunt.
  • borderline-drop: Operation Talked — this one was reversed late, and the reversal is worth recording. It initially cleared the inclusion bar on a stated Swiss nexus. The deep read established that Switzerland appears only as a bare secondary geography inside a mass-scanning footprint of more than 1.1 million internet-facing hosts, with no Swiss victim, sector or organisation named anywhere in the report — which is a property of indiscriminate scanning rather than a nexus. What remained was a single-source report, with no second-party corroboration found, describing a Russia-nexus actor scanning a set of already-known older edge flaws. The report's full vulnerability list and per-target volumes exist only as an unextractable chart image, so the arsenal could not have been reported completely even if the item had shipped. Russia-nexus targeting of the European defence-industrial base remains a legitimate strategic thread for the weekly.
  • Already covered, no material delta: the Check Point SmartConsole authentication bypass. A research lab's technical analysis and proof-of-concept for this flaw was published on 2026-07-28 and is already the subject of yesterday's entry, which carries the public-proof-of-concept status and quotes the lab's own statement about it. The only genuinely new element this window was a national CERT editing its existing advisory to link that analysis, which is an advisory edit rather than a development.

The deep read changed four of the eight published items, which is the clearest argument for keeping that step:

  • The Hugging Face update was expected to carry one verified vulnerability identifier. All eight of the identifiers the research pass proposed resolved in full against the vendor's own numbering-authority records, and a ninth belonging to the same disclosure batch was found missing from the research return. The entry therefore ships nine verified records rather than one, with two of them correctly marked as affecting a narrower set of release branches than the rest.
  • The Hugging Face entry was also corrected on scope. The research return attributed a "no customer data was exfiltrated" statement to the model vendor; that statement does not appear in its disclosure, and the breached platform's own post-mortem documents an outbound data-theft phase covering environment variables and secrets. The entry now carries the platform's own narrower scope statement instead, sourced to the platform.
  • The SonicWall credential-stuffing entry had "pre-positioning" re-attributed. That characterisation is the reporting outlet's inference and the word appears nowhere in the security vendor's own post; the vendor states only that it observed no post-compromise activity. The two readings imply different urgency, so the entry keeps them apart, and the hypotheses about where the credentials came from are presented as an analyst's explicitly hedged speculation rather than as a finding.
  • The npm supply-chain attribution entry had two unsupported claims removed. The publishing vendor gives no affected or fixed version numbers for the three compromised packages, and issues no dependency-audit recommendation; the entry no longer implies either, and the attribution is carried throughout as that vendor's own medium-confidence assessment rather than as established authorship.

One further correction came out of the vulnerability deep read: the affected-version range initially recorded for the AI-agent-platform flaw had been carried across from an unrelated product's advisory. The published entry uses the range stated by the vulnerability database and the maintainer's own advisory.

Single-source and reduced-confidence items: the npm attribution entry rests on one vendor's medium-confidence assessment with no corroborating attribution published by any second party, and ships at medium confidence with that stated in its sourcing note. The SonicWall entry is multi-source in publication but single-origin in telemetry — every count and the infrastructure characterisation come from one vendor — and it ships at medium confidence with that recorded. The exposed-management-controller deep dive is multi-source for the underlying protocol flaw, which the vulnerability database has documented since 2013, but its exposure statistics and both exploitation observations originate with the single research lab; the corroborating outlet's account derives from its own interview with that lab rather than from separate telemetry, and the entry says so.

Contradiction carried rather than resolved: HashiCorp documents its own Terraform MCP Server affected range two different ways. The security bulletin gives 0.2.1 up to and including 1.0.0; the vendor's own per-CVE records for all three flaws give 0.3.0 up to below 1.1.0. Same vendor, two lower bounds, which means an operator on a 0.2.x build gets a different answer depending on which HashiCorp document they read. Both positions are stated in the entry and neither is silently preferred; the entry keeps the wider lower bound so it cannot under-scope someone on 0.2.x. The flaws themselves are not in dispute, so the entry stays multi-source rather than contradicted.

One priority note for transparency: no entry reached critical. Two candidates were actively exploited — a firewall-management static credential and the management-controller exposure — and both ship at high. Neither meets the stop-and-act bar: the firewall-management flaw exposes a low-privileged account whose value is as a chaining primitive rather than as immediate full compromise, and the management-controller exposure is a thirteen-year-old specification flaw whose remediation is network and credential work rather than an emergency patch. Five entries at high and three at notable is what the cited facts support.

A note on one drop class that is deliberately not silent: this run published no vulnerability entry merely because it carried a high score. Items dropped for that reason included a file-transfer product's CVEs disclosed six days earlier, a backup-appliance flaw from mid-month, a hypervisor vendor's routine patch batch, and a creative-software plugin set — all either outside the window or handled by the normal patch cadence with no exploitation and no exposure-driven urgency.

Coverage gaps: prodaft (client-hydrated single-page index returned no extractable dated report; fetch method switched to the reader this run); ico-uk (JS-hydrated enforcement grid exposed no dated action links; fetch method switched to the reader this run); edpb (recipe works, listing returned in full, but every item predates the window); cisa-directives (no dedicated listing subcommand attempted separately, and the day's CISA content surfaced through the advisories and catalogue feeds); certvde (candidate-tier operational-technology CERT not swept, research budget went to the essential tier); eset, reliaquest, akamai-sirt, dfirreport, fox-it-blog, sygnia, group-ib — swept and clean of in-window items; sekoia (newest post 2026-07-23), swisscybersecurity-net (newest post 2026-07-29, off-topic) and netzwoche — all three fetched and quiet or out-of-window rather than unswept; us-treasury-ofac — the one source genuinely not fetched, deprioritised as low home-region yield once the rest of the slice had produced no in-window signal. One unresolved lead is recorded rather than published: the incident-domain research pass mentioned a possible webmail zero-day attributed to a Russian state actor already covered by two entries this window, but supplied no source trace and no research pass surfaced a primary for it, so it is logged here instead of becoming an unsourced entry.

One repository defect was found and fixed while staging this run, and it is worth recording because it was silent and would have recurred. The secret-blocking rules in .gitignore match on filename substrings, and one of them excludes anything containing the word "credential". Two of this run's eight entries have that word in their slug — the Cisco hardcoded-credential advisory and the SonicWall credential-stuffing campaign — so both were being quietly dropped from the commit. The run record would have claimed eight published entries while six reached the site, and the mechanical gate could not have caught it because the gate reads the filesystem rather than the git index. Negations for the content-store paths were added to .gitignore in this commit, with a comment recording the cause, so a future entry about credentials or secrets cannot disappear the same way. The raw fetched page bodies the deep read wrote to the run's work directory are deliberately not committed — roughly ten megabytes of regenerable extraction scratch — while the findings files, verification reports, triage record, liveness ledger, checkpoints and coverage snapshot all are.

Essential-coverage: no misses. All eleven essential records in the active-threats and vulnerability domain and all four in the home-region domain were attempted and reached.

← Operations dashboard · run-record contract: docs/pipeline.md