ctipilot.ch

2026-08-02T0409Z-intel

One pipeline fire, in full · intel run of 2026-08-02 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-02/2026-08-02T0409Z-intel.md.

Run telemetry

2026-08-02T0409Z-intel intel prompt v3.29 publish ok
2h 06m duration 4 published 1 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
8m 41s
Tool calls
15 WebFetch14 WebSearch11 bridge
Cited sources
2 of 24 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
14m 06s
Tool calls
15 WebFetch26 WebSearch11 bridge
Cited sources
0 of 17 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
13m 57s
Tool calls
38 WebFetch8 WebSearch6 bridge
Cited sources
1 of 27 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
13m 48s
Tool calls
15 WebFetch15 WebSearch9 bridge
Cited sources
3 of 14 in slice

Verification

unconfirmed CLEAN · waived: single CLEAN at iteration cap — iteration 8 returned CLEAN with zero findings, a #? NEEDS_FIXES · Opus 5 · t=6 e=0 a=0 #? CLEAN · Sonnet 5 · t=0 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=1 e=0 a=0 #? CLEAN · Sonnet 5 · t=0 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=3 e=0 a=0 #? NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=2 e=0 a=0 #? CLEAN · Sonnet 5 · t=0 e=0 a=0

Deep dive

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

2 diagnosis recorded in notes; not demoted · 1 candidate -> active · 1 contributing run recorded; last_successful_fetch bumped · 1 recovered; failure counters reset · 1 fetch_method 'rss' -> 'webfetch'; stale recipe documented · 1 added probe_url pointing at a per-advisory CSAF document.

SourceChangeFrom → ToReason
cyberattaque-orgcandidate -> active— → —Met the three-contributing-run promotion bar the state digest reported, and contributed again this run as the primary source for the CCI Nice Cote d'Azur breach entry.
cryptotimescontributing run recorded; last_successful_fetch bumped— → —Supplied the in-window anchor for the COLDCARD entry — the relayed Galaxy Research third-wave estimate.
inside-it-chrecovered; failure counters reset— → —Carried into this run as a rotation priority after two failing runs. Its RSS feed returned 200 with 20 items and the earlier 403 did not recur. No in-window item, so a quiet period was counted.
govcert-atfetch_method 'rss' -> 'webfetch'; stale recipe documented— → —The record described an RSS recipe while carrying a null feed URL. Probing found no feed at any standard path, no feed link declared on the homepage, and a sitemap listing only 25 static institutional pages with no advisory stream — GovCERT Austria's advisories reach readers through cert.at, already tracked at essential tier. Not demoted; this is a content-model correction.
siemens-productcert-csafadded probe_url pointing at a per-advisory CSAF document— → —The health sweep had been probing the CSAF directory index, which returns 403 to every user agent along with all four CSAF discovery files, and reporting a recipe break that did not exist. The documented per-advisory retrieval was re-verified working this run. tools/source_health.py now honours probe_url; the source re-probes healthy.
ico-ukdiagnosis recorded in notes; not demoted— → —Flagged by the health sweep, but the cause is the exhausted reader-credential pool rather than a recipe break. Direct alternatives were probed this run and none exposes the enforcement listing.
fbi-cyber-alertsdiagnosis recorded in notes; not demoted— → —Same cause — its recipe reaches content only through the reader fallback, and every pooled credential is exhausted. Direct paths re-probed and both return 403.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
cisa-advisorieshttps://www.cisa.gov/news-events/cybersecurity-advisoriesrsswebfetchbridge:urlbridge:jina402CISA KEV reached through its separate api subcommand, so exploited-vulnerability ground truth was not lost; only the general advisories listing was unreachable
cisa-directiveshttps://www.cisa.gov/news-events/directiveswebfetchbridge:urlbridge:jina402none available this run
ico-ukhttps://ico.org.uk/action-weve-taken/enforcement/bridge:jinawebfetchwebsearch402WebSearch fallback surfaced only pre-window enforcement coverage
ccn-cert-eshttps://www.ccn-cert.cni.es/en/bridge:jinabridge:url --directwebsearch402WebSearch fallback surfaced no in-window content
prodafthttps://www.prodaft.com/reportsbridge:jina402none — no alternate transport documented for this JS-shell host
cisa-newshttps://www.cisa.gov/news.xmlbridge:feed402deprioritised — largely US advisory content already covered by the KEV path
sysdighttps://www.sysdig.com/blogrsswebfetchbridge:urlbridge:jina402none available this run
trellixhttps://www.trellix.com/blogs/research/bridge:urlbridge:jina402none available this run
group-ib-bloghttps://www.group-ib.com/blog/webfetchbridge:urlwebsearch503 transport-5xxWebSearch surfaced three recent posts, none confirmed in-window

Bridge invocations (this run)

8 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

8 ok
  • bridge: ×6
  • api: ×2

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? NEEDS_FIXES · 10 findings (truth=6, editorial=0, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The summary and opening sentence credited the vendor with confirming the compromised file name, the host serving it and the append-to-end-of-library detail. The vendor's notice names none of the threeOpening rewritten so the vendor is credited only with what it actually said and the asset identification is attributed to the reporting; the summary reworded th
F3
claim-not-supported
Two published artifacts were described as scripts. The source calls both agent skills — tools intended to be driven by an AI coding agent, not standalone command-line programs — and the entry never naBody and action item corrected to the source's own term, the operational difference stated in one clause, and the repository named.
F4
hallucinated-fact
The headline asserted no vulnerability was involved and the body repeated it as fact. No source establishes that: the relayed notification says the takeover method is not specified and lists session hHeadline reworded to say the takeover route is undisclosed; the body now scopes the no-exploitation observation to the post-authentication activity and states e
F4
hallucinated-fact
The summary dropped the configuration precondition the advisory states and the original entry carried — the flaw reaches only applications using the libvips variant processor. As written it would havePrecondition restored in the summary and in the defender takeaway, with an explicit clause stating that an application on the other processor is outside the vec
F4
hallucinated-fact
The technique mapping claimed an adversary searching a compromised host for stored private-key material. The described attack involves no host access at all — the keys are reconstructed offline from aMapping replaced with the brute-force technique the body actually describes; the financial-theft mapping stands.
F14
?
An uncited superlative calling this the largest disclosed compromise of its kind on record. None of the three cited sources makes any comparative claim, and the superlative was load-bearing — one of tSuperlative removed and the inclusion re-grounded on the sourced exploitation figures; the same correction applied to the run record's borderline-include note.
F11
editorial-advisory
Advisory: the action item scoped the exposure check to the two-day evidence-anchored range while the entry's own body warns against resolving the disputed duration in the vendor's favour, so a team woAction widened to the researcher's week-long window, with the disagreement named in the action itself.
F11
editorial-advisory
Advisory: a workflow-internal sub-agent identifier appeared in the reader-facing notes.Rephrased in plain language.
F11
editorial-advisory
Advisory: the notes invoked a first-party carve-out that the verification policy does not define, contradicting the entry's own sourcing note, which correctly says a maintainer statement is not one ofNotes rewritten to match the entry: graded plain single-source, with the reason stated.
F11
editorial-advisory
Advisory: the registry summary dated the start of exploitation, which no cited source does.Reworded to say exploitation was confirmed under way by the date the independent analysis published, and that no source dates its start.

Iteration #? NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
The coverage notes said nine sources were lost to the exhausted reader-credential pool. The record's own failure block shows eight with that status; the ninth failed with a server error on a host wherCount corrected to eight in the notes, the ninth source split out with its actual cause, and the coverage-gaps line rewritten to match.

Iteration #? NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The vendor's incident notice was cited with the date the vendor says it detected the activity rather than the date the page was published. The page's own content-management payload gives a publicationSource date corrected to the page's own published date in the entry and in the registry record; the detection date stands unchanged in the body and in event_dat
F3
claim-not-supported
An observation that nothing disclosed supports a conclusion that the chamber's wider IT estate was compromised was attributed to the chamber. The relaying site makes that observation in its own voice,Re-attributed explicitly to the relaying site and marked as its own assessment rather than a statement from the organisation.
F4
hallucinated-fact
The body and the action item described the exposed secret as decrypting the application's encrypted credentials. It does not — a separate master key does — and the advisory names a wider set of secretBoth the takeaway and the action now name the full set the advisory covers: the session-signing secret, the master key, and every credential reachable through t

Iteration #? NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The paragraph quoting a forum reply from a Discourse maintainer dated 1 August cited it to the framework security team and dated it 31 July — the other post in the same thread. The prose named the speCitation relabelled to the maintainer's reply with its own date, in both places the reply is used.

Iteration #? NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The entry said the published forensic material came from an analysis the security team performed on its own applications. The author describes it as work he did at a named company on that company's apRewritten to the author's own words and framing, which is also the stronger claim: the tooling comes out of a real incident response rather than being written f
F4
hallucinated-fact
These notes said the advertising-platform compromise was first reported about five hours before this window opened. The discovering researcher published it on 2026-07-30, roughly 36 hours earlier and Corrected to name both dates and the two-run gap, and to record why it was missed: the researcher publishes on a platform this pipeline does not track, and the

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-02T0409Z-intel · Claude Opus 5 · window 26 h · 4 entries published

Verification & coverage notes

The window ran 26 hours against a 24-hour gap to the previous run, and it covered a Saturday into a Sunday. That shape explains most of what follows: three of the four research domains found their sources' freshest substantive publications dated 29 to 31 July — inside yesterday's window, not this one. Publication timestamps were read directly on two of those candidates rather than trusting date-only summaries, so the quiet result is a measured one rather than a collection failure.

Four entries published, one of them an update. No entry was dropped.

The verification loop ran to its cap, and that is the most operationally interesting thing about this run. Eight passes, alternating between two models. Every cold pass overturned the clean verdict before it — four separate times a pass that had been handed a clean predecessor found real defects anyway. Thirteen truth findings were fixed across the loop and none was rejected. What is notable is where they clustered: after the first pass, essentially nothing further was wrong with the content, the quotes, the links or the vulnerability data, all of which were re-checked repeatedly and held every time. The later findings were almost entirely about attribution precision — a source cited with the date the vendor detected an incident rather than the date it published, an observation credited to a victim organisation that its relaying source had actually made in its own voice, a quoted forum reply labelled with the wrong speaker and date, published tooling credited to a project when its author describes it as his own work at a different company, and two claims in these notes that contradicted the record's own structured fields. Each is individually small and every one would have misled a reader about who stands behind a claim. The final pass returned clean, but at the cap, so the second confirming pass the publish gate normally requires had no room to run; the run publishes on that single clean verdict with the waiver recorded above.

The reader transport is down, and it cost this run real coverage. Every one of the four pooled reader-proxy credentials reports an exhausted, negative balance, so the last-resort rung of the fetch ladder was unavailable for the entire run. Eight sources failed as a direct consequence and are recorded above with the transports attempted for each. (A ninth, a threat-intelligence vendor's blog, also went uncovered, but for an unrelated reason — its host returned a server error and its listing came back unrendered; the reader was never reached for it.) The two that matter most are the CISA advisories and directives listings, which refuse every direct user agent and are reachable only through that proxy; the KEV catalogue has its own retrieval path and was fetched normally, so confirmation of which vulnerabilities are being exploited was not lost, but the general advisory channel was dark. This needs an operator to restore credit — no in-pipeline fix reaches it.

Health-sweep repairs. The sweep flagged three sources as needing a recipe fix or demotion, and all three were worked this run rather than deferred. One was a genuine, repeatable defect and is now fixed: the Siemens CSAF probe had been aimed at a directory index that returns 403 to every user agent, while the per-advisory retrieval the runs actually use works fine — the source record now carries an explicit probe target and the health script honours it, so the source probes healthy again. The other two are consequences of the credential outage rather than broken recipes; direct alternatives were probed for both and none exists, so both were documented and left in rotation. Neither is demoted, because a refused request and an exhausted credential are transport problems, not evidence that a source has stopped publishing.

Separately, the Austrian government CERT record was corrected: it claimed a feed-based retrieval while carrying no feed address, and probing established that the site publishes no advisory stream at all — its operational content reaches readers through the Austrian national CERT, which this pipeline already tracks at the highest tier. The record now describes what the site actually is.

Deep dive: none. Neither item with confirmed active exploitation earns the long-form treatment — one is a consumer hardware-wallet defect whose relevance here is indirect, and the other is a third-party-script compromise whose published analysis fits a standard entry without padding.

Borderline calls and drops.

  • borderline-drop: EU AI Act Article 50 transparency obligations become enforceable today — real, in-window, and sourced to the European Commission, but it changes nothing a Tier 2/3 responder patches, hunts, blocks or detects in the next week. It is a compliance duty on the providers and deployers of AI systems, and it belongs with the weekly's policy coverage, where this pipeline's other regulatory milestones sit.
  • borderline-drop: an extortion group's claim against the two European standards bodies that produce the harmonised standards behind CE marking. Two research domains investigated it independently and reached the same conclusion: the only sources are leak-site mirrors, with no statement from either body, no national-CERT advisory and no reliable journalism. It fails this pipeline's bar for extortion claims. The target class is relevant enough to re-check next run if it develops.
  • borderline-include: the COLDCARD hardware-wallet entry. A consumer Bitcoin device is outside this constituency's usual scope, and the entry says so in its first line. It is carried on the confirmed scale of the exploitation now under way — a running estimate of 1,367.05 BTC across 4,585 addresses over three waves — and on a root cause that generalises directly to embedded and operational-technology firmware assurance, which is squarely in scope. Its action list is deliberately empty; there is no task here for this constituency, only a review criterion.
  • borderline-include: the French chamber-of-commerce breach. Direct home-region public-sector nexus and a confirmed victim notification, but thin technically because the organisation has not disclosed how the account was taken over, and both citing sites reproduce the same underlying notification rather than reporting independently. Graded and framed accordingly, and the missing access vector is stated as missing rather than guessed at.
  • Dropped without further work: a Spanish biopharmaceutical extortion claim (out of window and unconfirmed), three low-significance unconfirmed leak-site listings, and a large French fitness-platform leak with no public-sector, critical-infrastructure or new-technique angle.
  • out-of-window: two substantive research posts — an agentic technique-extraction detection study and a network-anomaly-detection write-up with concrete Kerberoasting and DNS-tunnelling heuristics — both dated 31 July, before this window opened, with no fresh development to anchor them. Left for a future run rather than stretched into this one.

Single-source and sourcing notes.

  • The Rails update is graded single-source. It rests on the framework's own security team announcing a change to its own advisory, so the maintainer is the only party who can attest to it and no independent corroboration exists or is expected — but a first-party maintainer statement is not one of this pipeline's two named carve-outs, so it takes the plain single-source grade rather than a carve-out value.
  • The French chamber-of-commerce entry is marked single-source: two breach-notification sites carry it, but both reproduce the same notification, so they are two write-ups of one document rather than independent confirmation. No official page from the organisation and no mainstream pickup was found.
  • The COLDCARD theft figures come from a blockchain research firm's estimate as relayed by one outlet; the firm's own post was not fetched, so the numbers are attributed to that relay and stated as estimates rather than counts.

Contradictions carried, not resolved. The advertising-platform entry holds two open disagreements between the vendor and the researcher who found the compromise, and reports both rather than picking a side. On duration, the company names a single affected day while the researcher describes about a week and an archived copy predates the company's date; on data egress, the company reports no evidence that visitor addresses or browsing information left, while conceding such transmission may have been possible, and the analysed sample contains a request built to send exactly that. Neither is settled, and a defender sizing exposure should assume the longer window until the company reconciles the two.

First coverage of a story two earlier runs could have caught. The advertising-platform compromise was first published by the researcher who found it on 2026-07-30, roughly 36 hours before this window opened and inside the window of the run before last; the first mainstream pickup followed on 2026-07-31, about five hours before this window opened. It surfaced here only through in-window follow-up reporting that added the payload mechanics, so it publishes as first coverage rather than an update. That is a two-run discovery gap rather than a dedup decision, and it is worth the operator's attention: the researcher publishes on a platform this pipeline does not track, and the story reached the tracked sources a day later.

Coverage gaps: cisa-advisories, cisa-directives, ico-uk, ccn-cert-es, prodaft, cisa-news, sysdig, trellix (all eight blocked by the exhausted reader-credential pool, detailed above); group-ib-blog (unrelated cause — HTTP 503 on the direct fetch and an unrendered listing through the bridge); cert-at, enisa, ncsc-ch-focus, ncsc-ch-incidents, edpb, ncc-research (fetched successfully, nothing published in-window); govcert-at (no advisory stream exists on the host — record corrected).

← Operations dashboard · run-record contract: docs/pipeline.md