ctipilot.ch

2026-08-02T2311Z-weekly

One pipeline fire, in full · weekly run of 2026-08-02 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-02/2026-08-02T2311Z-weekly.md.

Run telemetry

2026-08-02T2311Z-weekly weekly prompt v3.30 publish ok
54m 45s duration 15 published 3 updates
Claude Opus 5 (claude-opus-5) main agent
W1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
7
Duration
14m 19s
Tool calls
12 WebFetch16 WebSearch4 bridge
Cited sources
7 of 16 in slice
W2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
8m 54s
Tool calls
12 WebFetch24 WebSearch5 bridge
Cited sources
3 of 18 in slice

Verification

#? NEEDS_FIXES · Opus 5 · t=6 e=3 a=2 #? NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=9 e=6 a=1 #? NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=1

Deep dive

Entries published (this run)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

No source-list edits recorded for this run.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
consilium-eu-forward-lookhttps://www.consilium.europa.eu/en/press/press-releases/2026/07/17/forward-look-webfetchbridge:urlbridge:jina403 transport-403
HTTP 403 Forbidden direct; fetch_source.py url reported both transports failed (direct 403; reader proxy relayed an upstream block/challenge)
W2 confirmed via search that no cyber/sanctions-relevant EU Council press release fell in-window beyond the already-tracked 2026-07-13 sanctions package.
sekoiahttps://www.sekoia.io/en/blog/webfetch404 dead-url
sekoia.io/en/blog/ redirects to sekoia.com, whose /en/blog/ listing path then returned 404 to a plain WebFetch; not retried per the single-retry rule
None this run. tools/source_health.py subsequently probed the configured sekoia recipe successfully, so the source record is healthy and the failure was specifi

Bridge invocations (this run)

1 bridge call this run · these are successful bridge fetches (separate from "Coverage gaps" above).

1 other
  • fetch_source.py ncsc-csh recent 20 (bridge) ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? NEEDS_FIXES · 11 findings (truth=6, editorial=3, advisory=2) · Claude Opus 5 · 15m 21s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
The Cisco quote the entry's headline thesis rested on is absent from the cited advisory. A bridge fetch of cisco-sa-fmc-static-cred-BET3Cjh (v1.2) found zero occurrences of 'rotate', 'certificate', 'ARemoved the fabricated evidence[] record and replaced it with the verified sentence 'In July 2026, the Cisco PSIRT became aware of active exploitation of this v
F4
nonverbatim-quote
evidence[] and body quote ended '...to Attacked with an unusual confirmation'; the source reads '...to Attacked with an urgency of Red, which is the CVE record's own way of recording that this is beinReplaced the invented tail with the source's real one in both the evidence[] record and the body quote.
F3
claim-not-supported
Entry claimed the vendor-commissioned audit 'found 23 further vulnerabilities'. The cited page states the opposite about the 23rd — 'Number 23 is not from the audit. It surfaced alongside the active eSummary and body corrected to 22 from the audit plus a 23rd that surfaced alongside the live exploitation, with the researcher's 'Number 23 is not from the audi
F3
claim-not-supported
Entry said the confirmed impact spanned 'both autonomous and manual attempts' and the sourcing_note asserted Unit 42 apportions 'without apportioning between them'. Unit 42 apportions explicitly and tRestored the apportionment in summary, body and sourcing_note — the autonomous campaigns achieved full compromise of no intended target and the confirmed four-C
F14
quantifier-without-source
'one of them is the only member of the group with confirmed exploitation' is false — the co-cited Rapid7 page records CVE-2026-16232 as reported exploited in the wild as a zero-day at disclosure, and Rewritten to name the Balbooa Gridbox pair as the only member with server-log-level exploitation evidence, while stating that it is not the only one exploited a
F14
quantifier-without-source
'ExfilSquad's site was five days old when it named fifteen victims' contradicted the entry's own paragraph 2 and SOCRadar, both of which record the site first appearing 2026-07-26 with 15 named victimRewritten to 'named fifteen victims on the very day it appeared, with no prior operating history behind the brand', which is both accurate and the stronger vers
F5
missing-citation
The public-chain and critical-tail paragraphs carried roughly 35 CVE identifiers plus CVSS scores and version- and deployment-scope claims with no inline citations, and TeamCity, VMware, Adobe, SolarWExtended references[] by 12 operational entries so every product named, including each critical-tail item, has its owning entry linked; sourcing_note rewritten
F5
missing-citation
The axios three-hour removal window was uncited in the body and repeated inside actions[] item 2, and the release-age cooldown was presented as the entry's own analysis. GTIG states both explicitly, iAdded both GTIG sentences to evidence[] and quoted and cited them in the body, so the action item's premise is sourced rather than asserted; sourcing_note recor
F17
classification
Four entries carried reliability A while resting on primaries that sources.json rates B (rapid7-research, proofpoint, msft-ti, unit42, vulncheck, mysites-guru, elastic-seclabs), and the structurally iReliability lowered to B on exploited-management-planes, russian-state-nexus, ai-measured and vuln-status-rollup, taking the weakest load-bearing primary as the
F11
editorial-advisory
'corroborated by' overstated independence — Dark Reading attributes the automotive-manufacturer finding to Lava's own CTO, so it is the same source speaking again. The Dark Reading URL was also inlineReworded to name it as Lava's CTO expanding on Lava's own finding rather than independent corroboration, and added the URL to sources[] as corroborating. The Ru
F11
editorial-advisory
The CISA source record's publisher field read 'CISA (with EPA and FBI)'; the alert is CISA-authored and claims no joint authorship, merely referencing the FBI PSA and EPA's assistance programme.Publisher field changed to plain 'CISA'; inline citations already read CISA.

Iteration #? NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 10m 05s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F14
quantifier-without-source
The frontmatter summary's 'a detailed annex running to roughly 80 pages' is unsupported: the page count appears in neither the European Commission library page nor the corroborating legal analysis, boDropped the page count; the summary now reads 'a detailed annex carrying 67 worked examples', which is the supported figure.
F4
hallucinated-fact
The run record's own note on the surviving dedup warnings claimed 'Eight are overlaps with prior weekly strategic entries' and 'Three are prior-week operational entries', while the mechanical gate outCorrected to nine weekly and two operational, derived by filtering the gate's own dedup lines rather than counted by hand: `check_run.py … | grep '^ - dedup'`

Iteration #? NEEDS_FIXES · 16 findings (truth=9, editorial=6, advisory=1) · Claude Opus 5 · 31m 40s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Elastic quote's final five words were substituted: entry read '...native OS user rather than by an obvious external intruder.' where the page reads '...rather than by an obviously malicious account orRestored the source's real tail in both places.
F4
hallucinated-fact
T1539 (Steal Web Session Cookie) named no behaviour the body describes and no source supports — zero occurrences of 'cookie' or 'session' in the body, and none of 'session cookie' across the seven citDropped T1539. The bearer-token and API-key exposure the body does describe is already carried by T1552 and T1552.001.
F3
claim-not-supported
A trailing IBM citation claimed two CVSS 9.8 flaws, an unsafe deserialization and APAR PH72166; the cited bulletin is single-CVE (CVE-2026-14446, CWE-306) naming only APAR DT496500, with zero occurrenSplit the claim across IBM's two same-day bulletins, added node/7281649 to sources[], and cited each flaw and APAR to the bulletin that carries it; sourcing_not
F3
claim-not-supported
The same IBM adjacency defect in a second file — two CVSS 9.8 flaws and APAR PH72166 attributed to the single-CVE bulletin. The Fix Pack numbers and 3Q2026 target were correct.Same split applied; second bulletin added to sources[] and cited at the deserialization/PH72166 clause.
F4
hallucinated-fact
The SonicWall credential-stuffing campaign was counted as one of 'five European incidents' with no source support: Huntress attaches no geography and CyberScoop states the attacks were broad and opporRecounted the European set without SonicWall, which now appears explicitly as the un-localised instance of the same mechanism at remote-access scale, with Cyber
F3
claim-not-supported
The 92-account total was attributed to Huntress, whose page never states it (only per-day counts and the 30-organisation figure); the figure is verbatim on the co-cited CyberScoop page, which also givRe-cited the 92-account total and the 41-hour window to CyberScoop verbatim; dropped 'three-day run' from the summary in favour of 41 hours.
F3
claim-not-supported
'impact falling on field equipment ... rather than treatment processes' was generalised across 30-plus communities; StateScoop scopes that to Plymouth only and its Braham example is a plant outage. WhAttributed the field-equipment scoping to Plymouth by name, added Braham's plant outage as the contrasting case, and led with the claim that does generalise (wa
F3
claim-not-supported
'mySites.guru disclosed five issues in JoomShaper SP Page Builder' — the page states it found and reported four, and says of the fifth that it was not among them and was not tested; 6.7.1 fixes five iCorrected to four reported by the discloser with 6.7.1 closing five, naming the fifth as one the discloser neither reported nor tested.
F4
hallucinated-fact
The run record still asserted that Unit 42's confirmed-impact sentence spans autonomous and manual attempts 'without apportioning between them' — the exact claim iteration 1 had established as false aRewrote the paragraph to record what actually happened: the superseded quote avoided, the corrected sentence used, this run's own over-correction in removing th
F5
missing-citation
The 24-hour Article 14 notification duty appeared in title, headline, summary and body twice, and neither cited source carries it — zero hits for '24 hour', '24-hour', 'Article 14' or 'actively exploiDropped the notification window and the article number throughout, retitling the entry and rewriting the headline, summary and both body occurrences to state on
F5
missing-citation
The same uncited 24-hour duty in a second file, placed immediately after a citation carrying neither the figure nor the article number, and repeated in the frontmatter summary.Reduced to the reporting obligations beginning 2026-09-11, with an explicit note that the notification window and article number are not stated because no sourc
F5
missing-citation
The entry's headline thesis turns on SAPPHIRE SLEET being UNC1069, which neither primary states: GTIG names MIDNIGHT NEPTUNE (formerly UNC1069) and never says SAPPHIRE SLEET; Amazon never says UNC1069Cited CyberScoop inline at the alias clause with its verbatim multi-name sentence, and named GTIG's current cryptonym as MIDNIGHT NEPTUNE with UNC1069 as its fo
F8
needs-more-research
T1204.004 and T1539 named behaviours the body never described, while Microsoft supplies both with detection-grade depth the entry had dropped — the paste-and-run script-host invocation, and CornFlake'Described both in the Triage line with Microsoft cited: the script-host lineage after a captive-portal association, and a non-browser process reading a browser'
F9
surface-contradiction
CISA KEV-listed FortiOS CVE-2025-68686 on stated evidence of active exploitation while Fortinet's own advisory metadata records severity Medium, 'Known Exploited: No' and CVSSv3 5.3 — two cited sourceAdded a Contradiction line to the run record's verification notes recording the disagreement. The entry's 'newly KEV-listed' wording was already the correct hed
F17
classification
Reliability A contradicted the weakest-load-bearing-primary rule this run adopted in iteration 1: the Cl0p strand that supplies the entry's own headline rests entirely on ransom-isac, rated C in sourcReliability lowered to B. The rest of the spread was explicitly judged defensible and is unchanged: A1 on the water entry, A2 on the Commission entry, B1 on the
F11
editorial-advisory
The cited Censys post self-describes part of its content as paraphrased from user-supplied material and not independently re-fetched; the entry correctly uses it only for its own scan output, but a reAdded a sourcing_note clause stating Censys is cited only for its scan counts, never for its restatement of the CISA alert.

Iteration #? NEEDS_FIXES cap-breach · 2 findings (truth=1, editorial=0, advisory=1) · Claude Sonnet 5 · 6m 31s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Iteration 3's Elastic quote-tail remediation was only half-applied: it corrected the evidence[] record but left the identical quotation in the body's Triage paragraph still reading '...rather than by Replaced every occurrence across all of this run's entry files and the run record with a global replace rather than a first-occurrence replace, then grep-confir
F11
editorial-advisory
The title characterised the week's European set as 'public-sector' while one of its members, Stadler Rail, is a private rolling-stock manufacturer rather than a public-sector body.Title and body opening widened to 'public-sector and critical-infrastructure', which covers a rolling-stock maker supplying rail operators without over-claiming

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-02T2311Z-weekly · weekly · Claude Opus 5 · 15 entries published

Verification & coverage notes

ISO week 2026-W31 (2026-07-27 00:00 UTC → 2026-08-02 24:00 UTC). Gap to the previous weekly run record (2026-07-27T0110Z-weekly, which stood down on W30 as a duplicate week) = 7 days; window_days = 7. Duplicate-week guard: no -weekly record on origin/main carries week: 2026-W31 — proceeded.

ATT&CK pin freshness (weekly maintenance duty): tools/attack_data.py --check → up to date, local v19.1 == upstream latest v19.1. No update required.

Closed-source intake: intel/ carries only README (no in-window drops) — no W3 spawned.

Phase 1 week-in-review working lists persisted to work/2026-08-02T2311Z-weekly/week-review.json; 56 operational W31 entries synthesised. Triage outcome in triage.json.

Strategic output: 15 entries — top-stories: 3 (exploited management planes where the patch is not the remediation; water-sector PLC lockouts with quantified European exposure; two Russian state clusters converging on government mail and government travel) · multi-day: 2 (authentication bypasses from code trusting an attacker-supplied identity value; both KEV-driven and patch-driven prioritisation failing in the same window) · vuln-rollup: 1 · sector-patterns: 1 (European public-sector incidents entered through an already-valid credential and the platform's own export function) · incidents-recap: 1 (criminal claims outrunning confirmation in both directions) · research: 2 (tradecraft keyed to the victim host; the AI delta, as update_of the W30 strategic entry) · annual-reports: 0 · long-running: 3 (Joomla extension wave; open-source supply-chain wave; ShinyHunters status) · policy: 1 · outlook: 1. Empty sections left empty.

No critical priority this week, deliberately. The week's genuine stop-and-act item — Arista VeloCloud Orchestrator CVE-2026-16812, CVSS 10.0, exploited and KEV-listed the day of disclosure — already shipped as priority: critical in its operational entry on 2026-07-28, which is where an hours-to-days action belongs. Re-flagging it critical in a Sunday-night strategic synthesis would page on-call about a five-day-old advisory.

Weekly dedup (against prior strategic entries). Ran against the W29 (2026-07-19) and W30 (2026-07-26) strategic entries. Three already-consolidated arcs return only as status deltas: the AI-and-attackers thread as update_of 2026-07-26/weekly-w30-ai-autonomous-operator-and-target, the Joomla extension wave as update_of 2026-07-26/weekly-w30-joomla-extension-wave-status, and the open-source supply-chain wave as update_of 2026-07-26/weekly-w30-npm-ai-toolchain-supply-chain-status. The ShinyHunters status entry carries no update_of because no prior weekly held a dedicated ShinyHunters status record — W29 carried the actor as one strand of a broader identity-abuse entry, and a weekly-long-running status entry is the sanctioned form for an already-consolidated arc. The recurring top-story and roll-up sections carry only W31's own crossings.

Corrections applied to W1's returns before composition. W1 returned useful horizon framing with four defects that were caught and fixed rather than carried: (1) its item-5 title read "TA458/LAUNDRY BEAR", conflating two actors this pipeline holds distinct — LAUNDRY BEAR carries TA488 as an alias, while TA458 is the separate Operation RoundPress actor, a distinction W30's own record established on Proofpoint's statement; (2) an evidence record inserted "SVR-attributed" into a Microsoft sentence that actually ends at "sub-cluster of Midnight Blizzard based on distinctive technical and operational overlaps", so no service attribution is asserted from that source; (3) it dated the Proofpoint OWA post and the mySites.guru Gridbox audit 2026-07-31 when both are 2026-07-29; (4) it proposed T1190 for the water-utility PLC activity, which the referenced operational entries deliberately do not map because the announcement records reachability and credential control rather than exploitation of a flaw — the mapping used here is T1133/T1078.001/T1531/T1565.001, taken from those entries. Several of W1's evidence records were its own prose or a paraphrase rather than verbatim source text, and W1 labelled them as such; none was used as a quotation.

One superseded quote avoided, and one over-correction reversed. The 2026-07-31 Unit 42 operational entry carries an evidence quote that a later correction established Unit 42 never wrote, together with an impact count that understated the campaign. This weekly's AI entry quotes the corrected sentence instead, naming both the three NetScaler exfiltrations and command execution on 11 marimo endpoints. Reading that correction, this run initially also removed the earlier entry's autonomous-versus-manual framing, on the view that Unit 42 did not apportion — which verifier iteration 1 established was wrong. Unit 42 apportions twice, recording that the autonomous campaigns achieved full compromise of none of their intended targets and that the confirmed impact came from separate manual operations, while separately assessing autonomous attack cycles operationally viable with a narrow margin of failure. The entry now carries the apportionment in both directions. The correction entry had fixed only the count, not the split, and conflating the two is what produced the over-correction.

Citation dates and per-fact attribution re-verified at composition. Every inline citation date was taken from the referenced operational entry's own verified sources[] record or from a source W1/W2 fetched this run — never from a discovery timestamp. That check caught four dates drafted from memory: the Apache Airflow oss-sec post (2026-07-28, not 07-27), the SolarWinds CVE-2026-28323 advisory (2026-07-23, not 07-30), the Siemens Desigo CC CSAF (2026-07-14, with CISA's ICSA-26-209-01 republication on 2026-07-28 being the in-window event), and the Searchlight Cyber research (2026-07-20, carried explicitly as out-of-window background rather than an in-window development). Quoted text was taken from the referenced entries' verifier-confirmed evidence[] blocks; one Amazon quote available only as a mid-word-truncated extract was trimmed back to its last clean word boundary and the alias list moved outside the quotation marks.

Registry maintenance — GTIG cryptonym aliases (no new entities). Google's threat-intelligence group's two-word actor-naming schema was not published as an entry: its primary is dated 2026-07-24 (outside this week), and it is a supplementary naming layer that explicitly preserves previous names, ATT&CK mappings and vendor aliases, so it changes how a defender searches rather than what they patch, hunt, block or detect. It was applied as registry hygiene instead — aliases appended to five existing records where the source states the mapping unambiguously: actor:oilrig += SOLAR ION, actor:secretblizzard += TURLA RELIC, actor:midnight-blizzard += ICE RELIC, actor:apt42 += CALANQUE ION, actor:sapphire-sleet += MIDNIGHT NEPTUNE. actor:sandworm already carried SANDWORM RELIC. Deliberately not applied: MUDDY ION → actor:muddywater, which W1 flagged as an unconfirmed mapping, and MASAN, whose relationship to UNC1069 is not stated as an alias. Separately, the actor:sapphire-sleet summary asserted the Amazon attribution "has not been independently corroborated by another vendor"; that clause is now factually wrong and was corrected, because GTIG credited the axios compromise to UNC1069 — already an alias on that record — on 2026-07-30.

An initial scripted attempt at those alias additions matched on an assumed inline aliases: [...] form and silently wrote into the wrong records for the two that use block-form lists, overwriting one record's aliases and appending MIDNIGHT NEPTUNE to actor:knaithe-knyuan. The registry was reverted with git checkout and the edit redone with record-scoped bounds handling both forms; the final diff touches five alias lines, entity count is unchanged at 512, and the alias-collision check is clean.

Gate tooling — the entity-overlap dedup warning was weekly-blind, and is now weekly-aware. The first pre-verify pass raised 29 dedup entity-overlap warnings, every one of them a strategic entry sharing an entity key with an operational entry it explicitly lists in references[]. That is the weekly's design — synthesising those entries is the job — so the warning was firing as a structural false positive on every weekly run. tools/check_run.py now treats a declared references[] link on a horizon: strategic entry as the dedup declaration for that pair, exactly as it already treats update_of. CVE-level overlap is deliberately still reported, because per-CVE metadata belongs to the operational entry that owns it and must never be duplicated upward. The change is scoped to the entity warning only; check_run.py --all re-run store-wide shows no new failure and no lost warning elsewhere, and site/test_build.py passes.

Remaining entity-overlap warnings (11) — confirmed deliberate. Nine are overlaps with prior weekly strategic entries (W29's identity-abuse, third-party-breach and CH/EU incident entries; W30's webmail-espionage and CH/EU incident entries). Those are the weekly-dedup-against-prior-weeklies case this run's dedup section documents: each is a new lens on a tracked entity, not a re-run, and references[] is reserved for the operational entries a strategic entry synthesises rather than for prior strategic entries. The remaining two are prior-week operational entries deliberately not synthesised here — the 2026-07-24 LAUNDRY BEAR Zimbra entry (this week's entry covers the Exchange OWA campaign and the travel vector, a different platform and a different CVE) and the 2026-07-26 Gridbox cookie-forgery entry (superseded within the wave's own long-running status entry). Three warnings from the first pass were resolved properly rather than suppressed, by adding to references[] the older operational entries this run genuinely does synthesise: the original Ernst & Young disclosure that the actor's reach claim is measured against, and the original Stadler Rail breach entry whose vendor statement is quoted here.

A prompt-versus-gate conflict for the audit, not silently resolved. prompts/weekly-summary.md Phase 4 directs that weekly-vuln-rollup entries "carry per-CVE cves[] records with the CURRENT status", but check_run.py's cross-run dedup FAILs exactly that, because every CVE in a weekly roll-up is by definition already covered by the operational entry that first carried it. Every prior weekly roll-up (W27 through W30) shipped with cves: [], so the established practice contradicts the prompt text. This run followed the established practice and the gate: all 15 strategic entries carry cves: [], with identifiers, scores and version boundaries stated in the bodies and owned by the referenced operational entries. The prompt wording is the defect and it recurs every week, but fixing it requires a banner bump across all three lockstep master prompts plus a CHANGELOG entry, which is a change that deserves its own focused pass rather than being wedged in ahead of a verifier loop. Flagged here for the weekly quality audit.

  • Contradiction: FortiOS CVE-2025-68686 exploitation status — CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-27 on stated evidence of active exploitation, while Fortinet's own advisory FG-IR-25-934 metadata (last updated 2026-03-12) records severity Medium, "Known Exploited: No" and CVSSv3 5.3. The management-planes entry carries the hedged wording "newly KEV-listed" rather than asserting vendor-confirmed exploitation, and this line records that the two cited sources disagree rather than silently taking CISA's side.
  • borderline-drop: GTIG two-word actor-naming schema — primary out of window (2026-07-24) and a naming layer that preserves prior identifiers; applied as registry aliases rather than spending reader attention on an entry.
  • borderline-drop: Garante fine against Città Metropolitana di Sassari (EUR 12,000, decision 2026-06-11, disclosed via the 2026-07-29 newsletter) — fails all three weekly inclusion limbs: not on fire, not a cross-day pattern, and a small fine against one Italian metropolitan body is not a horizon shift changing defender obligations, unlike the BaFin/TeamViewer disclosure precedent a prior weekly carried. Single-source on Garante's own newsletter and decision page with no independent pickup, and Garante is not on this deployment's carve-out list. A Tier 2/3 responder would do nothing differently in the next seven days — role-drift in a document-protocol system is data-governance work. No registry entity created. W2 itself flagged it borderline.
  • Single-source: 2026-08-02/weekly-w31-commission-cra-application-guidance draws its scope clarifications from the Commission's own publication page with corroborating legal analysis for the obligation dates — multi-source overall. The Commission communication C(2026) 5252 and its annex are reachable from that page only via newsroom redirection-tracked document links rather than stable direct URLs, so the citable source is the library entry.
  • Out-of-window sources carried deliberately, each labelled in its entry: Fortinet PSIRT FG-IR-25-934 (2026-02-10 — the advisory for a flaw CISA KEV-listed in-window on 2026-07-27); Zero Day Initiative ZDI-26-035 (2026-01-09 — the advisory for the Langflow flaw VulnCheck reported exploited in-window); Siemens SSA-734552 (2026-07-14 — republished in-window by CISA); Health-ISAC advisory (2026-07-24 — reported in-window on 2026-07-29); Searchlight Cyber (2026-07-20 — background to the AI capability assessment, not an in-window development); Ransom-ISAC (2026-07-22 — the as-of date for the Cl0p victim-listing status, stated as such).
  • No standalone OT/ICS entry this week: the thread (Phoenix Contact CHARX with 20 CVEs and no firmware at disclosure, Siemens Desigo CC V7 with no fix, the water PLC campaign, Mendix Runtime) is carried on its most defender-relevant axis by the no-fix multi-day entry and the water top-story. A separate advisory-wave entry would restate the roll-up without adding a lens.
  • Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0 (none configured — sweep is a no-op).
  • Coverage gaps: consilium.europa.eu forward-look (403 on every transport including the reader; not in the source slice, logged as a fetch failure and an editorial gap); sekoia (blog listing path 404 after redirect — the configured recipe probes healthy); group-ib and recordedfuture-insikt (JS-rendered shells via the direct transport; W1 chose not to spend metered reader credit on them given the in-window leads already secured); zdi, aikido-security, onapsis (rotational-staleness picks, oldest last_successful_fetch 2026-07-14, not attempted — rolled to the next rotation); cert-at, cert-pl (no in-window policy-specific content found); finma (news listing is JS-rendered; no cyber item published in-window, most recent was the 2026-07-09 quantum-computing Aufsichtsmitteilung); edpb (most recent substantive output traces to the 2026-07-07 plenary, out of window).
  • Source health: tools/source_health.py probed 172/172 sources in 92 s — 101 ok, 71 bridge-ok, zero UNSOLVED and no repair orders outstanding.
  • Four of the six regulatory clocks prior weeklies recorded had no fresh in-window development and were deliberately not restated (Dutch NIS2 Cyberbeveiligingswet, ENISA managed-security-services consultation, German KRITIS-Dachgesetz registration window, ENISA Health Action Plan). Carrying them forward without a fresh source would be recycling rather than tracking.

← Operations dashboard · day page 2026-08-02 · run-record contract: docs/pipeline.md