ctipilot.ch

2026-08-01T0409Z-intel

One pipeline fire, in full · intel run of 2026-08-01 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-01/2026-08-01T0409Z-intel.md.

Run telemetry

2026-08-01T0409Z-intel intel prompt v3.29 publish ok
2h 41m duration 8 published 2 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
19m 26s
Tool calls
33 WebFetch4 WebSearch15 bridge
Cited sources
5 of 30 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
14m 55s
Tool calls
20 WebFetch15 WebSearch9 bridge
Cited sources
1 of 19 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
13m 39s
Tool calls
34 WebFetch8 WebSearch11 bridge
Cited sources
5 of 26 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
7m 20s
Tool calls
9 WebFetch4 WebSearch12 bridge
Cited sources
6 of 14 in slice

Verification

✓ double-CLEAN · Opus 5 + Sonnet 5 #? NEEDS_FIXES · Opus 5 · t=8 e=5 a=0 #? NEEDS_FIXES · Sonnet 5 · t=1 e=1 a=0 #? NEEDS_FIXES · Opus 5 · t=6 e=0 a=0 #? NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=3 e=1 a=0 #? NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=0 #? CLEAN · Opus 5 · t=0 e=0 a=0 #? CLEAN · Sonnet 5 · t=0 e=0 a=0

Deep dive

2026-08-01/captivecrunch-storm-2945-hospitality-captive-portal-rat

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 added as candidate.

SourceChangeFrom → ToReason
fbi-cyber-alertsadded as candidate— → —This run's single new candidate. The FBI/EPA joint announcement was the only source for the seven-state victim count, the naming of the MicroLogix 1100 series alongside the 1400, and the modified-ladder-logic finding in the water-sector PLC campaign; the parallel CISA alert names Rockwell, Siemens and Schneider Electric equipment but carries none of those three facts, and no FBI source was tracked. A working retrieval recipe is recorded in its notes.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Bridge invocations (this run)

11 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

11 ok
  • bridge: ×10
  • api: ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? NEEDS_FIXES · 15 findings (truth=8, editorial=5, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
A single trailing citation covered two interim-fix identifiers, but the bulletin cited names only one of them; the other appears solely in the companion bulletin.Clause split so each identifier is cited to the bulletin that actually names it.
F3
claim-not-supported
The entry said federal and state officials are examining an Iranian nexus. The cited report states the opposite of both: the bureau declined to say who it thought was responsible, and state officials Rewritten to what the report states, with the two actual origins of the Iran framing named and quoted, and the sourcing note corrected the same way. The most co
F3
claim-not-supported
A clause credited one outlet with observing that the alert names no actor; the outlet makes no such observation, it simply never mentions one. The underlying fact is true but was cited to the wrong paReworded so the absence is attributed to the alert itself, with the outlet cited only for what it does say.
F3
claim-not-supported
The entry said the second vendor declines to attribute its cases to this cluster. It in fact assesses them as resembling a different Russian service's tradecraft and never evaluated this cluster at alRewritten to the vendor's actual assessment, with the campaign it declines identified and the sourcing note corrected.
F4
hallucinated-fact
The sourcing note claimed the fix predated the advisory. The vendor's own release notes give a release date a week AFTER the advisory, which inverts the entry's freshness argument in the entry's favouChronology corrected from the vendor's release notes, which were added as a source; the summary and body now carry the correct sequence, and the patch being day
F4
hallucinated-fact
The headline, summary, body and defender takeaway all asserted that all three of the ministry's 2026 incidents began with a compromised account. No cited source states the access path of the two earliThe shared-root-cause claim was removed from all four places; the entry now says explicitly that no source states how the earlier two began, and the takeaway re
F4
hallucinated-fact
The body ranked one flaw as more severe than the other; no source ranks them and the entry's own frontmatter gives both the same score and the same vector.Comparative dropped.
F14
?
The headline and summary said reputation scoring never flags the provider. The cited source says researchers have frequently flagged its addresses, and closes that the provider is not bad forever; itsAbsolute removed from the headline and summary and replaced with the source's own narrower framing; the body now carries the counter-quote.
F8
needs-more-research
The vendor shipped a wider batch of bulletins the same day, including another authentication bypass, that the entry never acknowledged — so an operator working the single action item would apply two iA paragraph now scopes the entry to the trio the national CERT carried and points at the rest of the batch, and the action item says to check it. The additional
F8
needs-more-research
The companion denial-of-service flaw was excluded on the grounds that no vendor authority carried it. The vendor's release notes do carry it, with a description, a score and a credit.The flaw is now a full CVE record sourced to the release notes, and the sourcing note states where its score comes from.
F8
needs-more-research
The entry argues its relevance comes from the extension-vulnerability wave it sits in, but shipped with no entity link to that wave and no references, so it would not have appeared in the wave's timelWave entity linked and the two in-window entries on the same wave added as references.
F8
needs-more-research
The prior sector advisory that both a cited source and this store already carry was never named, which is what separates the Iran framing from press speculation.Named in the attribution paragraph, with the cited report's own reference to it.
F9
surface-contradiction
The two cited vendors point at two different Russian services for the same attack surface, and the primary source explicitly addresses and overrides the alternative reading. For a government audience A dedicated passage now surfaces the divergence, quotes both vendors and the primary source's own rejection of the alternative, and states plainly that the surf
F11
editorial-advisory
Advisory: the run record used workflow-internal vocabulary in reader-facing notes.Reworded to plain language throughout.
F11
editorial-advisory
Advisory: a tag claimed a public proof-of-concept, but the working exploit is a module in the discloser's commercial product; the body was already correct.Tag dropped and the distinction stated in the body.

Iteration #? NEEDS_FIXES · 2 findings (truth=1, editorial=1, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F14
?
The unsupported absolute about reputation scoring, removed from the headline and summary in the previous iteration, survived unfixed in the title field — a required reader-facing field the earlier pasTitle reworded to the same hedge already carried by the headline and summary, so all three now match the source's actual claim.
F8
needs-more-research
The gate's standing request to confirm a deliberate non-update decision on a shared wave entity was not answered anywhere in the notes. The underlying editorial call was found correct — different CVE,A line naming the decision and its reasoning added to the coverage notes.

Iteration #? NEEDS_FIXES · 6 findings (truth=6, editorial=0, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F1
broken-url
The denial-of-service flaw added in the previous iteration was bound to the wrong release: the vendor's notes place its fix in the preceding version and say the later release merely carries those fixeAffected range and fixed release corrected to the earlier version, with the carry-forward stated in the body and the sourcing note. An estate already on that re
F2
generic-url
The body claimed the announcement named the targeted hardware for the first time; two of the entry's own cited sources show the parallel alert named one of the two controller series as well.Quantifier dropped; the entry now states what the announcement names without the first-ness claim.
F3
claim-not-supported
The published coverage notes still said investigators are examining an Iranian nexus — the exact framing iteration 1 overturned in the entry, and which the cited report contradicts. The record disagreNotes rewritten to match the corrected entry: the investigating bodies declined to attribute, and the Iran framing traces to a prior sector advisory and a named
F4
hallucinated-fact
Same failure mode on the deep dive: the notes still described the second vendor as declining to attribute its cases to the primary vendor's cluster, wording removed from the entry two iterations earliNotes aligned with the entry's corrected sourcing note, including the service-level divergence.
F5
missing-citation
The justification for adding the new candidate source claimed the parallel alert carried none of the facts that motivated it; two cited sources show it named vendor equipment, including one of the conJustification narrowed to the three facts that genuinely are unique to the announcement, in the run record and in the source record's own notes.
F6
strengthen-primary-source
The paragraph on the wider bulletin batch attributed a publication date to a page that dates none of the bulletins it lists.Date qualifier removed throughout, with an explicit note that the cited article does not date those bulletins.

Iteration #? NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
A coverage-notes bullet still said the companion denial-of-service flaw's identifier and score do not enter the entry's structured records. Verification had reinstated exactly that record two iteratioBullet rewritten to record all three states of the decision — the original exclusion, the reinstatement on the release notes, and the version correction — rathe
F4
hallucinated-fact
Both CVE records carry the same authentication and interaction values, but the vendor publishes a CVSS vector only for the authentication bypass; for the denial-of-service flaw the release notes give The sourcing note now states the difference in grounding explicitly and warns that the denial-of-service record's values are the schema's closest fit rather tha

Iteration #? NEEDS_FIXES · 4 findings (truth=3, editorial=1, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
The previous iteration's disclosure that the denial-of-service record's authentication and interaction values were unsourced inference is false: the vendor publishes a dedicated advisory for that flawThe owning advisory added as a source, the disclosure removed, and the sourcing note rewritten to state that both records now rest on vendor-published vectors.
F9
surface-contradiction
Two vendor pages disagree on where the denial-of-service flaw was fixed — its own advisory names the later release, the release notes list it among fixes carried in from the earlier one — and the entrReverted to the owning advisory's version and affected range, with the divergence stated in the body, both pages cited, and the unsupported all-clear removed. A
F3
claim-not-supported
The sourcing note called the discloser the CVE-assigning party; the advisory's own timeline records the identifier as published by the affected project's CNA.Restated to match the timeline — disclosed and reported by one party, identifier published by the project's own CNA.
F14
?
The body, headline and takeaway asserted flatly that no vulnerability was exploited. The primary source says only that the access did not necessarily require exploiting a complex technical vulnerabiliAll three softened to the sources' register, keeping the access-path claim while dropping the exclusive negative.

Iteration #? NEEDS_FIXES · 2 findings (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
A coverage-notes bullet still said a later pass had bound the companion denial-of-service flaw to the earlier release on the release notes' phrasing. The following pass reversed exactly that, and the Bullet rewritten to record all four states of the decision, including both reversals and the reason for each — twice a source assumed not to exist turned out to
F11
editorial-advisory
Advisory: the extension-vulnerability wave record described a single arbitrary-file-upload flaw class surfaced by one researcher, but three linked entries — a cookie-forgery authentication bypass, an Summary broadened to describe the wave as it now stands, naming the newer flaw classes and the second discloser, and stating that the through-line is the under-

Iteration #? CLEAN · 2 findings (truth=0, editorial=0, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
Advisory: the preceding iteration's record carried a truth counter of one against a truth value of zero, and the run's residual count had not been re-derived.Counters reconciled to the finding's actual class; the residual count is re-derived when this iteration is stamped.
F11
editorial-advisory
Advisory: the companion advisory is cited to its last-updated date rather than its first-published date. Defensible, since the fixed-release value taken from it reflects the updated page, but undiscloThe sourcing note now states which of the two dates the citation carries and why.

Iteration #? CLEAN · 1 finding (truth=0, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
Advisory, cosmetic: the extension-vulnerability wave record's display name still describes the single flaw class the summary was broadened away from in the preceding iteration.Not applied, deliberately. The display name mirrors a permanent registry key, and renaming it would leave the visible name disagreeing with the key every future

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-01T0409Z-intel · Claude Opus 5 · window 26 h · 8 entries published

Verification & coverage notes

Window: 26 h, derived from a 24.0 h gap to the previous run (2026-07-31T0409Z-intel). Standard window; no catch-up disclosure required. No closed-source drops were present — intel/ holds only its README — so no intake pass ran. The previous run's record shows publish status ok on main, so no missed publish to report.

Eight entries published, two of them updates to existing coverage. The window held three vulnerability disclosures that demand action ahead of the routine patch cycle, one state-actor campaign against a target population this constituency has a lot of, one confirmed European public-sector incident, one macOS supply-chain malware analysis, and two updates where a tracked story materially moved.

Deep dive: the captive-portal campaign entry. It was selected on active in-the-wild operation combined with direct exposure for the profiled constituency — an SVR-attributed sub-cluster running since May 2026 against travelling corporate and government personnel, with government and diplomatic entities named as the parent actor's primary targets. Its category, state-actor campaign, was also used on 25 and 31 July, which would normally demote it one rank in the rotation; the demotion is waived because the item independently satisfies the top selection criterion. No earlier run published a deep dive today.

Borderline drops, each recoverable from this line:

  • borderline-drop: CosmosEscape (Azure Cosmos DB cross-tenant sandbox escape, Wiz Research) — genuinely novel research, but the provider fixed it server-side roughly eight months before disclosure, no CVE was assigned, the provider reports no evidence of unauthorized activity, and no customer-side action is possible or required. Nothing a responder would do differently in the next seven days, so it fails the actionability limb despite its technical interest.
  • borderline-drop: Kaspersky's published KATA network-anomaly correlation rules for Kerberoasting and DNS tunnelling — concrete and vendor-portable, but unique-service-principal-name thresholding per account and volumetric subdomain-plus-TXT thresholding are established practice for the detection engineers this brief is written for, and the piece is the vendor's own product documentation. Dropped as not materially improving what this audience can already do.
  • borderline-drop: Amgen's 8-K disclosing exfiltration of proprietary data and patient health information from third-party-hosted cloud environments — a US-headquartered company with no confirmed European victim data, and the filing names no vendor, no vector, no actor and no scale, so there is no transferable technical lesson beyond a third-party-cloud exposure pattern this brief covered three times in the past fortnight. It does not clear the out-of-nexus breach gate. Worth revisiting if the promised amendment names a vector or a shared provider.
  • The incident tracker and leak-site sweeps surfaced only uncorroborated listings for already-tracked actors (a German solar-technology firm, Spanish, Belgian, Dutch and German victims across three groups) with no victim statement, regulator filing or high-reliability journalism; all dropped on the fake-news gate.
  • NCSC-CH's newest incident post (2026-07-31, a QR-code crypto-wallet phishing letter) is a citizen-facing scam warning with no Tier 2/3 content and was judged below the inclusion bar rather than treated as a coverage gap.

Two entries were kept whose vendor advisories predate the window: the application-server pair (vendor bulletins 2026-07-28) and the helpdesk authentication bypass (vendor advisory 2026-07-23). In both cases the freshest available source is in-window — the Swiss national CERT published advisories for both on 2026-07-31 — and that national-CERT publication is the operational trigger for this constituency. Each entry's event_date records the underlying disclosure date rather than the date this pipeline surfaced it, so the reader is not misled about freshness.

Corrections applied during the editorial read of the primary sources, each of which had propagated into the initial research and would otherwise have shipped:

  • The interim-fix identifiers for the application-server flaws were wrong in the initial research. The bulletins name one identifier for the console flaw and a different one for the deserialization and log-disclosure pair; neither matches what was returned. Both were read from the bulletins' own remediation sections and corrected.
  • The helpdesk advisory's companion denial-of-service flaw initially carried an identifier and a severity score sourced only to a press article, and was cut from the entry's structured records because the vendor's advisory page for the authentication bypass does not mention it. Verification then found that the vendor's release notes do carry it with a description, a score and a credit, so it was reinstated as a full structured record. A later pass then rebound it to 2026.2 on the release notes' phrasing, and a further pass reversed that too, after finding that the vendor publishes a dedicated advisory for the flaw which carries its own CVSS vector and names 2026.2.1 as the fixed release. The entry now follows that advisory, and the disagreement between the two vendor pages is stated rather than resolved. All four states of the decision are recorded here rather than only the last, because the reasoning changed three times on new evidence — twice because a source assumed not to exist turned out to.
  • The device-code phishing wave was initially written up as the tracked campaign having moved hosting in July. The source in fact describes a second, parallel wave that began in April and ran alongside the first, with the July figures being a later slice of it. The entry was reframed accordingly.
  • The plugin advisory's own introduction and its structured severity block disagree by one day on the fix release date. The structured block's date is used and the discrepancy is recorded in the entry's sourcing note.

Single-source items and carve-outs: the macOS supply-chain analysis, the Joomla plugin disclosure and the device-code phishing wave are each single-source, marked as such, with the researcher's own hedges preserved. The captive-portal entry is marked multi-source for the attack surface but its sourcing note is explicit that the actor attribution and every malware detail rest on one vendor, while the second vendor cited assesses its own overlapping cases as resembling the tradecraft of a different Russian service, never evaluates the cluster the primary vendor names, and declines attribution only to one specific named campaign. That divergence is surfaced in the entry rather than smoothed over.

Attribution held open, not resolved: the water-sector campaign. Neither the federal announcement nor the parallel national alert names an actor, and the investigating bodies have actively declined to offer one — the cited news report states that the bureau declined to say who it thought was responsible and that state officials had not identified anyone either. The Iran framing in circulation traces to two other things entirely: a prior sector-wide advisory about Iranian targeting of water utilities, and a named outside expert quoted in the same report. The entry says so explicitly, carries no attribution, and no actor entity was created.

A duplicate entity key was avoided: one research return proposed registering a new incident entity for the water-utility attacks, which the registry already carries from the 29 July coverage. The existing key is used and the entry ships as an update rather than as new coverage.

Contradiction surfaced rather than resolved: the two SolarWinds pages disagree on where the companion denial-of-service flaw was fixed. Its own advisory names 2026.2.1 as the fixed release; the 2026.2.1 release notes list the same flaw among fixes the release carries in from 2026.2. The entry records the advisory's version, because that is the record owning the identifier, and states the divergence in the body so an operator sitting on 2026.2 does not read the release-notes phrasing as clearance. Both pages are cited.

Deliberate non-update decision, flagged by the gate for confirmation: the Joomla anti-spam plugin entry shares the extension-vulnerability wave entity with an entry from 26 July. It is a new entry rather than a delta because it is a different CVE in a different vendor's plugin, disclosed by a different researcher, and a different vulnerability class — object injection through a deserialised token, where the earlier item was a forged identity cookie. The shared entity is the wave they both belong to, which is the point of linking it.

Watchlist: no product or supplier watchlist is configured in the organization profile, so both sweeps are no-ops and no counts are reported.

Coverage gaps: sysdig (no transport succeeded — the blog is an unhydrated shell to a direct fetch and the metered reader returned a payment error); ccn-cert-es (same reader-credit exhaustion, and its direct bridge is known to return only a navigation shell); cisa-directives (no bridge subcommand exists for the directives listing and the landing page renders as an overview shell — a recipe gap, not a transport failure); msrc-blog and 0patch-blog (both redirect to single-page-application shells with no dated post listing in the fetched body); group-ib (transport succeeded, but the listing carries no publication dates in static HTML and the newest identifiable post predates the window); safeonweb-be (homepage shell without a dated listing); apple-security, cert-pl, cert-at, enisa, ncsc-ch-focus, redcanary, swisspost-cybersecurity, kommunaler-notbetrieb-de (all reachable, nothing inside the window); cryptotimes and project-discovery (not swept, low expected yield against the time budget).

Essential-coverage: all 15 essential sources attempted.

Transport note: the metered reader pool started this run on a single live credential with a low-balance warning and was fully exhausted by the end of it. It cost two sources their sweep during research, and by the final verification pass two government hosts had become unreachable on every transport, so that pass corroborated their quotes against independent secondary reporting rather than leaving them unchecked. The direct ladder carried everything else. This is now an operator action item: the reader pool needs new credentials before a run hits a host that only the reader can reach.

Wall clock: this run took substantially longer than a typical fire, almost entirely in the verification loop, which ran the full eight iterations. That was a deliberate choice rather than a stall — the loop kept returning real defects, including two occasions where a later pass overturned an earlier verifier's own finding, and it converged on a confirmed clean verdict rather than a fail-open. The run stayed inside the wall-clock watchdog and no later fire was pending.

← Operations dashboard · run-record contract: docs/pipeline.md