2026-08-02T0409Z-intel
One pipeline fire, in full · intel run of 2026-08-02 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-02/2026-08-02T0409Z-intel.md.
Run telemetry
- Items returned
- 1
- Duration
- 8m 41s
- Tool calls
- 15 WebFetch14 WebSearch11 bridge
- Cited sources
- 2 of 24 in slice
- Items returned
- 2
- Duration
- 14m 06s
- Tool calls
- 15 WebFetch26 WebSearch11 bridge
- Cited sources
- 0 of 17 in slice
- Items returned
- 1
- Duration
- 13m 57s
- Tool calls
- 38 WebFetch8 WebSearch6 bridge
- Cited sources
- 1 of 27 in slice
- Items returned
- 2
- Duration
- 13m 48s
- Tool calls
- 15 WebFetch15 WebSearch9 bridge
- Cited sources
- 3 of 14 in slice
Verification
Deep dive
—
Entries published (this run)
- Adform: the shared tracking script every customer site embeds was trojanised with a clipboard-rewriting crypto-clipper, and no antivirus engine flagged it incident high
- CCI Nice Côte d'Azur: a compromised administrator account on the chamber's jobseeker platform was used to run the platform's own export function incident notable
- COLDCARD: a preprocessor guard that tested whether a macro was defined rather than what it was set to routed key generation to a software PRNG for five years, and the keys are now being emptied vulnerability notable
- CVE-2026-66066 (Rails Active Storage) — the withheld attack chain is public four weeks early, and Rails has shipped forensic tooling to answer 'was I exploited?' vulnerability high update
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
2 diagnosis recorded in notes; not demoted · 1 candidate -> active · 1 contributing run recorded; last_successful_fetch bumped · 1 recovered; failure counters reset · 1 fetch_method 'rss' -> 'webfetch'; stale recipe documented · 1 added probe_url pointing at a per-advisory CSAF document.
| Source | Change | From → To | Reason |
|---|---|---|---|
| cyberattaque-org | candidate -> active | — → — | Met the three-contributing-run promotion bar the state digest reported, and contributed again this run as the primary source for the CCI Nice Cote d'Azur breach entry. |
| cryptotimes | contributing run recorded; last_successful_fetch bumped | — → — | Supplied the in-window anchor for the COLDCARD entry — the relayed Galaxy Research third-wave estimate. |
| inside-it-ch | recovered; failure counters reset | — → — | Carried into this run as a rotation priority after two failing runs. Its RSS feed returned 200 with 20 items and the earlier 403 did not recur. No in-window item, so a quiet period was counted. |
| govcert-at | fetch_method 'rss' -> 'webfetch'; stale recipe documented | — → — | The record described an RSS recipe while carrying a null feed URL. Probing found no feed at any standard path, no feed link declared on the homepage, and a sitemap listing only 25 static institutional pages with no advisory stream — GovCERT Austria's advisories reach readers through cert.at, already tracked at essential tier. Not demoted; this is a content-model correction. |
| siemens-productcert-csaf | added probe_url pointing at a per-advisory CSAF document | — → — | The health sweep had been probing the CSAF directory index, which returns 403 to every user agent along with all four CSAF discovery files, and reporting a recipe break that did not exist. The documented per-advisory retrieval was re-verified working this run. tools/source_health.py now honours probe_url; the source re-probes healthy. |
| ico-uk | diagnosis recorded in notes; not demoted | — → — | Flagged by the health sweep, but the cause is the exhausted reader-credential pool rather than a recipe break. Direct alternatives were probed this run and none exposes the enforcement listing. |
| fbi-cyber-alerts | diagnosis recorded in notes; not demoted | — → — | Same cause — its recipe reaches content only through the reader fallback, and every pooled credential is exhausted. Direct paths re-probed and both return 403. |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| cisa-advisories | https://www.cisa.gov/news-events/cybersecurity-advisories | rss → webfetch → bridge:url → bridge:jina | 402 | CISA KEV reached through its separate api subcommand, so exploited-vulnerability ground truth was not lost; only the general advisories listing was unreachable |
| cisa-directives | https://www.cisa.gov/news-events/directives | webfetch → bridge:url → bridge:jina | 402 | none available this run |
| ico-uk | https://ico.org.uk/action-weve-taken/enforcement/ | bridge:jina → webfetch → websearch | 402 | WebSearch fallback surfaced only pre-window enforcement coverage |
| ccn-cert-es | https://www.ccn-cert.cni.es/en/ | bridge:jina → bridge:url --direct → websearch | 402 | WebSearch fallback surfaced no in-window content |
| prodaft | https://www.prodaft.com/reports | bridge:jina | 402 | none — no alternate transport documented for this JS-shell host |
| cisa-news | https://www.cisa.gov/news.xml | bridge:feed | 402 | deprioritised — largely US advisory content already covered by the KEV path |
| sysdig | https://www.sysdig.com/blog | rss → webfetch → bridge:url → bridge:jina | 402 | none available this run |
| trellix | https://www.trellix.com/blogs/research/ | bridge:url → bridge:jina | 402 | none available this run |
| group-ib-blog | https://www.group-ib.com/blog/ | webfetch → bridge:url → websearch | 503 transport-5xx | WebSearch surfaced three recent posts, none confirmed in-window |
Bridge invocations (this run)
8 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- bridge: ×6
- api: ×2
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #? NEEDS_FIXES · 10 findings (truth=6, editorial=0, advisory=0) · Claude Opus 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | The summary and opening sentence credited the vendor with confirming the compromised file name, the host serving it and the append-to-end-of-library detail. The vendor's notice names none of the three | Opening rewritten so the vendor is credited only with what it actually said and the asset identification is attributed to the reporting; the summary reworded th | |
| F3 claim-not-supported | — | Two published artifacts were described as scripts. The source calls both agent skills — tools intended to be driven by an AI coding agent, not standalone command-line programs — and the entry never na | Body and action item corrected to the source's own term, the operational difference stated in one clause, and the repository named. | |
| F4 hallucinated-fact | — | The headline asserted no vulnerability was involved and the body repeated it as fact. No source establishes that: the relayed notification says the takeover method is not specified and lists session h | Headline reworded to say the takeover route is undisclosed; the body now scopes the no-exploitation observation to the post-authentication activity and states e | |
| F4 hallucinated-fact | — | The summary dropped the configuration precondition the advisory states and the original entry carried — the flaw reaches only applications using the libvips variant processor. As written it would have | Precondition restored in the summary and in the defender takeaway, with an explicit clause stating that an application on the other processor is outside the vec | |
| F4 hallucinated-fact | — | The technique mapping claimed an adversary searching a compromised host for stored private-key material. The described attack involves no host access at all — the keys are reconstructed offline from a | Mapping replaced with the brute-force technique the body actually describes; the financial-theft mapping stands. | |
| F14 ? | — | An uncited superlative calling this the largest disclosed compromise of its kind on record. None of the three cited sources makes any comparative claim, and the superlative was load-bearing — one of t | Superlative removed and the inclusion re-grounded on the sourced exploitation figures; the same correction applied to the run record's borderline-include note. | |
| F11 editorial-advisory | — | Advisory: the action item scoped the exposure check to the two-day evidence-anchored range while the entry's own body warns against resolving the disputed duration in the vendor's favour, so a team wo | Action widened to the researcher's week-long window, with the disagreement named in the action itself. | |
| F11 editorial-advisory | — | Advisory: a workflow-internal sub-agent identifier appeared in the reader-facing notes. | Rephrased in plain language. | |
| F11 editorial-advisory | — | Advisory: the notes invoked a first-party carve-out that the verification policy does not define, contradicting the entry's own sourcing note, which correctly says a maintainer statement is not one of | Notes rewritten to match the entry: graded plain single-source, with the reason stated. | |
| F11 editorial-advisory | — | Advisory: the registry summary dated the start of exploitation, which no cited source does. | Reworded to say exploitation was confirmed under way by the date the independent analysis published, and that no source dates its start. |
Iteration #? NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Opus 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | — | The coverage notes said nine sources were lost to the exhausted reader-credential pool. The record's own failure block shows eight with that status; the ninth failed with a server error on a host wher | Count corrected to eight in the notes, the ninth source split out with its actual cause, and the coverage-gaps line rewritten to match. |
Iteration #? NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=0) · Claude Opus 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | The vendor's incident notice was cited with the date the vendor says it detected the activity rather than the date the page was published. The page's own content-management payload gives a publication | Source date corrected to the page's own published date in the entry and in the registry record; the detection date stands unchanged in the body and in event_dat | |
| F3 claim-not-supported | — | An observation that nothing disclosed supports a conclusion that the chamber's wider IT estate was compromised was attributed to the chamber. The relaying site makes that observation in its own voice, | Re-attributed explicitly to the relaying site and marked as its own assessment rather than a statement from the organisation. | |
| F4 hallucinated-fact | — | The body and the action item described the exposed secret as decrypting the application's encrypted credentials. It does not — a separate master key does — and the advisory names a wider set of secret | Both the takeaway and the action now name the full set the advisory covers: the session-signing secret, the master key, and every credential reachable through t |
Iteration #? NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | The paragraph quoting a forum reply from a Discourse maintainer dated 1 August cited it to the framework security team and dated it 31 July — the other post in the same thread. The prose named the spe | Citation relabelled to the maintainer's reply with its own date, in both places the reply is used. |
Iteration #? NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Opus 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | The entry said the published forensic material came from an analysis the security team performed on its own applications. The author describes it as work he did at a named company on that company's ap | Rewritten to the author's own words and framing, which is also the stronger claim: the tooling comes out of a real incident response rather than being written f | |
| F4 hallucinated-fact | — | These notes said the advertising-platform compromise was first reported about five hours before this window opened. The discovering researcher published it on 2026-07-30, roughly 36 hours earlier and | Corrected to name both dates and the two-run gap, and to record why it was missed: the researcher publishes on a platform this pipeline does not track, and the |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-08-02T0409Z-intel · Claude Opus 5 · window 26 h · 4 entries published
Verification & coverage notes
The window ran 26 hours against a 24-hour gap to the previous run, and it covered a Saturday into a Sunday. That shape explains most of what follows: three of the four research domains found their sources' freshest substantive publications dated 29 to 31 July — inside yesterday's window, not this one. Publication timestamps were read directly on two of those candidates rather than trusting date-only summaries, so the quiet result is a measured one rather than a collection failure.
Four entries published, one of them an update. No entry was dropped.
The verification loop ran to its cap, and that is the most operationally interesting thing about this run. Eight passes, alternating between two models. Every cold pass overturned the clean verdict before it — four separate times a pass that had been handed a clean predecessor found real defects anyway. Thirteen truth findings were fixed across the loop and none was rejected. What is notable is where they clustered: after the first pass, essentially nothing further was wrong with the content, the quotes, the links or the vulnerability data, all of which were re-checked repeatedly and held every time. The later findings were almost entirely about attribution precision — a source cited with the date the vendor detected an incident rather than the date it published, an observation credited to a victim organisation that its relaying source had actually made in its own voice, a quoted forum reply labelled with the wrong speaker and date, published tooling credited to a project when its author describes it as his own work at a different company, and two claims in these notes that contradicted the record's own structured fields. Each is individually small and every one would have misled a reader about who stands behind a claim. The final pass returned clean, but at the cap, so the second confirming pass the publish gate normally requires had no room to run; the run publishes on that single clean verdict with the waiver recorded above.
The reader transport is down, and it cost this run real coverage. Every one of the four pooled reader-proxy credentials reports an exhausted, negative balance, so the last-resort rung of the fetch ladder was unavailable for the entire run. Eight sources failed as a direct consequence and are recorded above with the transports attempted for each. (A ninth, a threat-intelligence vendor's blog, also went uncovered, but for an unrelated reason — its host returned a server error and its listing came back unrendered; the reader was never reached for it.) The two that matter most are the CISA advisories and directives listings, which refuse every direct user agent and are reachable only through that proxy; the KEV catalogue has its own retrieval path and was fetched normally, so confirmation of which vulnerabilities are being exploited was not lost, but the general advisory channel was dark. This needs an operator to restore credit — no in-pipeline fix reaches it.
Health-sweep repairs. The sweep flagged three sources as needing a recipe fix or demotion, and all three were worked this run rather than deferred. One was a genuine, repeatable defect and is now fixed: the Siemens CSAF probe had been aimed at a directory index that returns 403 to every user agent, while the per-advisory retrieval the runs actually use works fine — the source record now carries an explicit probe target and the health script honours it, so the source probes healthy again. The other two are consequences of the credential outage rather than broken recipes; direct alternatives were probed for both and none exists, so both were documented and left in rotation. Neither is demoted, because a refused request and an exhausted credential are transport problems, not evidence that a source has stopped publishing.
Separately, the Austrian government CERT record was corrected: it claimed a feed-based retrieval while carrying no feed address, and probing established that the site publishes no advisory stream at all — its operational content reaches readers through the Austrian national CERT, which this pipeline already tracks at the highest tier. The record now describes what the site actually is.
Deep dive: none. Neither item with confirmed active exploitation earns the long-form treatment — one is a consumer hardware-wallet defect whose relevance here is indirect, and the other is a third-party-script compromise whose published analysis fits a standard entry without padding.
Borderline calls and drops.
- borderline-drop: EU AI Act Article 50 transparency obligations become enforceable today — real, in-window, and sourced to the European Commission, but it changes nothing a Tier 2/3 responder patches, hunts, blocks or detects in the next week. It is a compliance duty on the providers and deployers of AI systems, and it belongs with the weekly's policy coverage, where this pipeline's other regulatory milestones sit.
- borderline-drop: an extortion group's claim against the two European standards bodies that produce the harmonised standards behind CE marking. Two research domains investigated it independently and reached the same conclusion: the only sources are leak-site mirrors, with no statement from either body, no national-CERT advisory and no reliable journalism. It fails this pipeline's bar for extortion claims. The target class is relevant enough to re-check next run if it develops.
- borderline-include: the COLDCARD hardware-wallet entry. A consumer Bitcoin device is outside this constituency's usual scope, and the entry says so in its first line. It is carried on the confirmed scale of the exploitation now under way — a running estimate of 1,367.05 BTC across 4,585 addresses over three waves — and on a root cause that generalises directly to embedded and operational-technology firmware assurance, which is squarely in scope. Its action list is deliberately empty; there is no task here for this constituency, only a review criterion.
- borderline-include: the French chamber-of-commerce breach. Direct home-region public-sector nexus and a confirmed victim notification, but thin technically because the organisation has not disclosed how the account was taken over, and both citing sites reproduce the same underlying notification rather than reporting independently. Graded and framed accordingly, and the missing access vector is stated as missing rather than guessed at.
- Dropped without further work: a Spanish biopharmaceutical extortion claim (out of window and unconfirmed), three low-significance unconfirmed leak-site listings, and a large French fitness-platform leak with no public-sector, critical-infrastructure or new-technique angle.
- out-of-window: two substantive research posts — an agentic technique-extraction detection study and a network-anomaly-detection write-up with concrete Kerberoasting and DNS-tunnelling heuristics — both dated 31 July, before this window opened, with no fresh development to anchor them. Left for a future run rather than stretched into this one.
Single-source and sourcing notes.
- The Rails update is graded single-source. It rests on the framework's own security team announcing a change to its own advisory, so the maintainer is the only party who can attest to it and no independent corroboration exists or is expected — but a first-party maintainer statement is not one of this pipeline's two named carve-outs, so it takes the plain single-source grade rather than a carve-out value.
- The French chamber-of-commerce entry is marked single-source: two breach-notification sites carry it, but both reproduce the same notification, so they are two write-ups of one document rather than independent confirmation. No official page from the organisation and no mainstream pickup was found.
- The COLDCARD theft figures come from a blockchain research firm's estimate as relayed by one outlet; the firm's own post was not fetched, so the numbers are attributed to that relay and stated as estimates rather than counts.
Contradictions carried, not resolved. The advertising-platform entry holds two open disagreements between the vendor and the researcher who found the compromise, and reports both rather than picking a side. On duration, the company names a single affected day while the researcher describes about a week and an archived copy predates the company's date; on data egress, the company reports no evidence that visitor addresses or browsing information left, while conceding such transmission may have been possible, and the analysed sample contains a request built to send exactly that. Neither is settled, and a defender sizing exposure should assume the longer window until the company reconciles the two.
First coverage of a story two earlier runs could have caught. The advertising-platform compromise was first published by the researcher who found it on 2026-07-30, roughly 36 hours before this window opened and inside the window of the run before last; the first mainstream pickup followed on 2026-07-31, about five hours before this window opened. It surfaced here only through in-window follow-up reporting that added the payload mechanics, so it publishes as first coverage rather than an update. That is a two-run discovery gap rather than a dedup decision, and it is worth the operator's attention: the researcher publishes on a platform this pipeline does not track, and the story reached the tracked sources a day later.
Coverage gaps: cisa-advisories, cisa-directives, ico-uk, ccn-cert-es, prodaft, cisa-news, sysdig, trellix (all eight blocked by the exhausted reader-credential pool, detailed above); group-ib-blog (unrelated cause — HTTP 503 on the direct fetch and an unrendered listing through the bridge); cert-at, enisa, ncsc-ch-focus, ncsc-ch-incidents, edpb, ncc-research (fetched successfully, nothing published in-window); govcert-at (no advisory stream exists on the host — record corrected).
← Operations dashboard · run-record contract: docs/pipeline.md