ctipilot.ch

2026-08-03T0409Z-intel

One pipeline fire, in full · intel run of 2026-08-03 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-03/2026-08-03T0409Z-intel.md.

Run telemetry

2026-08-03T0409Z-intel intel prompt v3.30 publish ok
42m 04s duration 3 published 0 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
19m 51s
Tool calls
27 WebFetch8 WebSearch22 bridge
Cited sources
3 of 17 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
10m 29s
Tool calls
14 WebFetch10 WebSearch16 bridge
Cited sources
0 of 24 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
10m 24s
Tool calls
27 WebFetch10 WebSearch10 bridge
Cited sources
0 of 28 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
13m 14s
Tool calls
14 WebFetch15 WebSearch16 bridge
Cited sources
0 of 10 in slice

Verification

✓ double-CLEAN · Opus 5 + Sonnet 5 #? NEEDS_FIXES · Opus 5 · t=5 e=4 a=0 #? NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=3 e=3 a=0 #? NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=1 e=0 a=0 #? NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=0 #? CLEAN · Opus 5 · t=0 e=0 a=0 #? CLEAN · Sonnet 5 · t=0 e=0 a=0

Deep dive

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

2 candidate -> active · 2 successful fetch recorded; last_successful_fetch bumped · 2 contributing run recorded; last_successful_fetch bumped · 1 404 rotation priority resolved; url + fetch_method updated, failure counters reset · 1 added as candidate.

SourceChangeFrom → ToReason
fbi-cyber-alertscandidate -> active— → —Met the three-contributing-run promotion bar the state digest reported.
technaducandidate -> active— → —Met the three-contributing-run promotion bar the state digest reported.
ccn-cert-es404 rotation priority resolved; url + fetch_method updated, failure counters reset— → —Carried into this run as the rotation priority after two failing runs with a 404. The old landing path is dead; the English news listing (ccn-news.html) and alert listing (alertas-ccn-cert.html) both resolve through the reader bridge and returned 200 this run. No in-window item, so this is a recipe repair rather than a content contribution.
cisa-kevsuccessful fetch recorded; last_successful_fetch bumped— → —KEV catalog retrieved and checked against both published entries; no additions since 2026-07-29, which independently corroborates the quiet window.
enisa-euvdcontributing run recorded; last_successful_fetch bumped— → —Surfaced the four CVSS 9.3 Bouncy Castle criticals that anchored the Bouncy Castle entry.
huntresscontributing run recorded; last_successful_fetch bumped— → —Corroborating primary for the N-able N-central entry — independent IR telemetry confirming active exploitation.
bleepingcomputersuccessful fetch recorded; last_successful_fetch bumped— → —Fetched during incident research; no item survived triage this run.
swisscybersecurity-netadded as candidate— → —This run's single new candidate. Swiss-German cybersecurity news outlet covering the CH market and cantonal/communal incidents, filling a home-region press gap. Feed returned 200; the outlet notes an editorial summer break through 2026-08-03, so no in-window item yet.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
sysdighttps://www.sysdig.com/blog/feedrsswebfetchbridge:feedbridge:jina402none available this run
prodafthttps://www.prodaft.com/reportsbridge:urlbridge:jina402none — no alternate transport documented for this JS-shell host
cisa-directiveshttps://www.cisa.gov/news-events/directiveswebfetchbridge:urlbridge:jina403 transport-403CISA KEV reached through its separate api subcommand, so exploited-vulnerability ground truth was not lost
claroty-team82https://claroty.com/team82/researchrsswebfetchbridge:url200 parsenone this run — OT/ICS research coverage relied on sans-ics and the CISA ICS advisory path instead
ssd-disclosurehttps://ssd-disclosure.com/advisories/webfetchbridge:url200 parsenone this run — in-window items from this source could be neither confirmed nor ruled out

Bridge invocations (this run)

9 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

9 ok
  • bridge: ×6
  • api: ×3

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? NEEDS_FIXES · 11 findings (truth=5, editorial=4, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Title, headline, summary and body all framed the four critical flaws as certificate-validation bypasses, but the Diffie-Hellman flaw involves no certificate, chain or PKIX path — it is static private-Reframed throughout as three certificate-validation bypasses plus one static-DH key-recovery flaw, and the body now says the fourth is grouped with the others o
F4
hallucinated-fact
Headline claimed two patches in 48 hours and the summary dated the first fix to 1 August. Only the hotfix falls in that window; the earlier fix shipped in 2026.2 months before, and 1 August carried anHeadline and summary rewritten to the body's correct sequence: an earlier fix that proved incomplete, an advisory on 1 August, the hotfix on 2 August.
F4
hallucinated-fact
The run notes said the Bouncy Castle entry cites six URLs; it cites four, after two blocked per-CVE data-sheet references were removed during composition.Count corrected to four.
F3
claim-not-supported
The immediate-action block and the first action item stated that hosted instances had been upgraded automatically. The cited status page puts it in the future — the upgrade will be applied, and those Both rewritten to the source's tense, with an added instruction to confirm the upgrade has actually landed rather than assume it.
F3
claim-not-supported
The FIPS fixed-build list omitted bc-fips 1.0.2.7, which the cited advisory page names alongside 2.0.2 and 2.1.3 — so a 1.0.x estate would read the entry as offering it no fix for one of the critical 1.0.2.7 added to the list.
F5
missing-citation
31 July was used twice as the compromise-assessment boundary without ever being cited or explained, though the vendor advisory supports it — that is the date the vendor saw the licensing-issue spike tThe basis is now stated once in the body with the vendor quote and citation attached.
F5
missing-citation
The paragraph naming two configuration mitigations was uncited, and one of them is promoted to a do-now action item.Each mitigation now carries the citation that names it — the per-flaw page for the hostname fallback, the release notes for the strict-DigestInfo property.
F9
surface-contradiction
The vendor's status page and its security blog disagree by one digit on the affected boundary (not running 2026.3.1 versus prior to 2026.3.1.7). The entry silently adopted the correct reading and paraThe discrepancy is now stated explicitly in the body, with the reading the blog and the CVE record agree on, and is recorded as a contradiction in these notes.
F10
missed-angle
Gladinet CentreStack (CVE-2026-54363 and siblings) verified uncovered store-wide and left to the trailing-window audit, which leaves the reader blind for another week. Recommended publishing with honePublished as a third entry with the real 2026-07-30 dates and a sourcing note stating it is first coverage rather than fresh news. Verification of the bundle fo
F11
editorial-advisory
Workflow-internal vocabulary in the published run notes, against this record's own house style elsewhere.Rewritten in the plain-language register used in the rest of the notes.
F11
editorial-advisory
Both N-able records stored a per-CVE data-sheet URL as primary_source_url while the entry deliberately cites the vendor advisory instead — drift rather than convention, since the 32 Bouncy Castle recoBoth re-pointed to the vendor advisory.

Iteration #? NEEDS_FIXES · 3 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The entry asserted in the present tense that the maintainer's advisory index misfiles one identifier's write-up under another's page; re-fetched live, both pages now show their own content.Independently re-fetched and confirmed the correction, then rewrote the paragraph in the past tense, saying why it still matters to anyone who triaged the batch
F14
?
Said four earlier CentreStack flaws had reached the exploited-vulnerabilities catalog; the catalog carries four entries for the vendor but one is scoped to a different product, so only three name CentRe-checked the catalog directly and corrected to three, in the entry summary, the entry body and these notes.
F11
editorial-advisory
Advisory: the mapping carried a resource-development technique about an adversary creating its own certificates, which no flaw in the batch does.Dropped; the mapping now carries only the two techniques the sources support.

Iteration #? NEEDS_FIXES · 9 findings (truth=3, editorial=3, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
These notes still described the Bouncy Castle batch as four certificate-validation bypasses after iteration 1 had corrected exactly that framing in the entry, so the record contradicted both the entryCorrected to three certificate-validation bypasses plus a static Diffie-Hellman key-recovery flaw.
F4
hallucinated-fact
All 32 CVE records carried an identical long-term-support version range, but four of the flaws do not affect that distribution at all per the maintainer's per-flaw pages and the numbering-authority reThose four records now carry their own affected/fixed ranges, one of them naming the OpenPGP FIPS module instead; each says explicitly that LTS is unaffected. T
F4
hallucinated-fact
The sourcing note claimed the cited advisory pages carry mechanics but not scores. That is true of the other vulnerability entry's sources and false here — all six pages display severity, score and veClause inverted to state that the scores are displayed on the cited pages.
F5
missing-citation
The paragraph carrying the OCSP flaw's mechanics was uncited, and the page holding those mechanics was not in the source list at all.That page added as a primary source and cited at both places that rely on it.
F5
missing-citation
The sentence listing long-term-support and FIPS fixed builds was uncited, and the source cited elsewhere for the identifier list carries none of those version numbers.Each set of build numbers now cites the per-flaw page that actually carries it.
F5
missing-citation
The entry's whole justification for publishing a three-day-old disclosure — the count of earlier flaws in this product that reached the exploited-vulnerabilities catalog — was a bare numeral with no cThe three identifiers are now named inline in both places, so a reader can check the claim without taking the number on trust.
F11
editorial-advisory
Advisory: the corroborating analysis gained an update after the research pass closed, carrying two indicator-free facts bearing directly on detection and triage — the vendor's published network indicaBoth added, plus the update's unpatched-population figure. The triage line now leads with the false-positive trap in the vendor's own indicator list.
F11
editorial-advisory
Advisory: the FIPS fixed-build sentence named two module families where the batch touches at least three, so a FIPS estate could conclude its exposure was covered when it was not.The OpenPGP FIPS module named, and the sentence now says a FIPS estate must resolve exposure per module rather than per product.
F11
editorial-advisory
Advisory: the iteration counter read two while the iterations list held only the first record — the iteration-2 block had silently failed to insert — and the residual count was stale.Both later iterations recorded in full and the counters recomputed.

Iteration #? NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The sentence carrying the earlier fix version and the 1 August upgrade recommendation was cited only to the corroborating analysis at its end, which states neither fact — both come from the vendor's oThe clause is now cited to the vendor blog and the attribution clause to the analysis that actually makes it.
F4
hallucinated-fact
Reported the service name used in the detection, triage and action guidance as invented specificity, on the basis that neither the vendor blog nor the corroborating analysis contains that string.REJECTED as reported, after checking directly. The name is stated by the vendor's status page — the entry's third cited source, which this pass did not search.

Iteration #? NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
The closing Defender takeaway still described the batch as four independent ways to make a certificate chain validate when it should not. The first pass corrected that framing in the title, headline, Corrected to three certificate-chain flaws plus a fourth that recovers a static Diffie-Hellman private key. Every remaining use of the word in the entry was the

Iteration #? NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Reported the entry's exploitation-status quote, used both as evidence and inline, as a splice of three sentences drawn from two different sections of the corroborating post rather than a contiguous veREJECTED, on evidence, and the rejection was then upheld by the next pass. In the page's markup the quote sits inside a single paragraph element of the summary

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-03T0409Z-intel · Claude Opus 5 · window 24 h · 3 entries published

Verification & coverage notes

A quiet window with two genuinely new items. The gap to the previous run (a weekly, 2026-08-03T01:10Z) was three hours, so the 24-hour floor set the window; the previous intel run fired 2026-08-02T04:09Z, which is the boundary the new signal actually tracks. Three of the four research domains returned nothing in-window, and the CISA KEV catalog has had no addition since 2026-07-29 — an independent corroboration that the window really is quiet rather than under-swept.

Published

  • N-able N-central authentication bypass (CVE-2026-18556 / CVE-2026-18577) — critical. Confirmed in-the-wild exploitation by the vendor, independently corroborated by Huntress IR telemetry, on a remote monitoring and management platform whose compromise reaches every downstream managed endpoint. It clears the critical bar on all three elements: disclosed inside the window, exploited right now, and time-critical to the day — sharpened by the fact that the 1 August fix was itself bypassable, so organisations that patched on day one stayed exposed for roughly another 24 hours. Scale is reported as bounded (the vendor says a limited number of customers; Huntress says one organisation in its own base) and the entry says so rather than implying a mass event; the rating rests on the blast radius and the persistence that survives the patch, not on a victim count.
  • Bouncy Castle for Java 1.85 — 32 CVEs, four at CVSS 9.3 — high. Not exploited and no proof-of-concept exists, so it clears the vulnerability gate on the other limb: the fixed binaries shipped 2026-07-12, and today's publication put the full root-cause detail and the fix commits in public while unpatched estates stayed unpatched. Three independent certificate-validation bypasses plus a static Diffie-Hellman key-recovery flaw, in a library that is almost always a transitive dependency, is exactly the shape a defender cannot act on without being told.

Deep dive: none. No earlier run published one today, so the slot was open, but neither candidate earned the treatment. The N-able story has confirmed exploitation but thin public mechanics — the vendor has not published root-cause detail and the corroborating analysis says so explicitly — and the Bouncy Castle batch, though technically deep, is vendor advisory detail rather than new attack-technique research, with no exploitation and no attacker tradecraft to trace. Depth was not manufactured to fill the slot.

Priority calibration: one critical this window, which is the first since 2026-07-28. Every element of the bar is independently satisfied and stated in the entry.

Borderline drops

  • borderline-drop: Amgen SEC Form 8-K Item 1.05 material cybersecurity incident — dropped on two independent grounds. The filing and its corroborating coverage are both dated 2026-07-31, roughly 53 hours before this run and outside the 24-hour window; and on the merits it does not clear the actionability bar, since the filing names no vendor, no access vector, no CVE and no actor, leaving a reader with nothing to patch, hunt or block. The victim also carries no stated nexus to this constituency. Recoverable from this line if a later disclosure adds substance.
  • borderline-drop: Alcon Inc. extortion-site listing — a Geneva-headquartered company, so the home-region nexus is real and the item was searched deliberately rather than skimmed. Dropped because the only source is a leak-site tracker: no company statement, no regulatory filing, and no high-reliability journalism reporting the claim. Standing policy requires victim disclosure or high-reliability reporting before an extortion claim can be published, and neither exists yet. Worth re-checking next run.
  • borderline-drop: CEN and CENELEC extortion-site listing — same shape and the strongest nexus of the three, since these are EU-level standardisation institutions whose work underpins the regulatory timelines this constituency tracks. Dropped for the same reason: a single leak-site tracker, with the only other hits being aggregation sites republishing that tracker. The research pass fetched CEN-CENELEC's own news listing directly and found no statement either way, which is documented absence rather than a denial. Also worth re-checking next run.

Published out of window as a deliberate editorial decision — Gladinet CentreStack

  • Gladinet CentreStack, six CVEs (CVE-2026-54363 through -54368), primary sources dated 2026-07-30 and therefore three days outside this run's 24-hour window. The default handling would have been to drop and log it, and this run initially did exactly that. It is published instead, and the decision is deliberate rather than an oversight of the recency rule.
  • The reasoning: the product is absent from the entry store, the CVE index and the 14-day coverage index — checked directly, twice — so three consecutive intel runs passed over it and the next scheduled sweep of the trailing window is a week away. The lead flaw derives the key protecting access tickets from a value identical in every installation, which yields an anonymous single-request path to a domain-administrator ticket on internet-facing infrastructure, and three earlier flaws in this same product reached the exploited-vulnerabilities catalog. On the merits it clears the inclusion gate comfortably; only its age argued against it, and age is the one objection that gets worse by waiting. Leaving a reader who relies on this site alone blind to it for another week was the worse of the two failures available.
  • Honesty controls applied: event_date is the real disclosure date, the sourcing note states in terms that this is first coverage rather than fresh news, and the body opens by saying so. Nothing here is presented as having happened today.
  • The initial dismissal is worth recording as a process fault in its own right. The home-region pass set the item aside as a national-CERT advisory restating something already covered; the "already covered" half of that was simply wrong, and no one checked it until the completeness sweep did. The recency rule would have dropped the item anyway, so the wrong reason produced the right disposition by accident — which is exactly the kind of near-miss that hides a real gap.
  • Scope correction found while verifying: the bundle is six CVEs, not the three first surfaced. CVE-2026-54364, -54365 and -54366 were missed on the first pass and are in the published entry.

Contradiction: N-able affected-version boundary. The vendor's status notice describes the issue as affecting every N-central instance not running 2026.3.1; its security blog says the attacker reached all servers running a version prior to 2026.3.1.7, and the published CVE description gives the affected range as through 2026.3.1. The blog and the CVE record agree, so the entry treats 2026.3.1 as affected and 2026.3.1.7 as the fixed build, and states the disagreement rather than resolving it silently — for an operator sitting on 2026.3.1 the single digit decides whether they act.

Verification: confirmed clean after eight iterations. The loop ran the full eight, alternating models, with defect counts of 9, 3, 9, 2, 1, 1, 0, 0 — the last two both clean, on different models, which is the publish gate. Two of the findings raised against this run were assessed and rejected rather than applied, each time after checking the source directly, and each rejection was then independently adjudicated and upheld by the following pass. Both concerned the same entry, and chasing the first one down surfaced a detection artifact the composition read had missed, which is now published. The most valuable catch of the whole loop was a templated version range that was wrong on four of thirty-two records — invisible precisely because it was uniform. A tooling note worth carrying forward: the final pass diagnosed why one page kept producing phantom quote failures — two of the three fetch transports silently omit that publisher's summary-list block, so a quote taken from it looks fabricated to anyone checking through those transports and verbatim to anyone using the raw fetch. That is a false-negative generator for future runs, not a one-off.

Recycled-news traps avoided. Two separate items looked in-window and were not: an article dated 2026-08-02 about a ransomware "manhunt" traced back to a reward announcement and arrest warrant from September 2025, and two search results that appeared to corroborate the N-able story but described an unrelated 2025 incident against the same product under different CVEs. Both were checked against their original event dates and dropped.

Sourcing notes. The Bouncy Castle entry ships as single-source despite citing four URLs, because the maintainer is both the vendor and the numbering authority for this batch — the national vulnerability databases republish those same records rather than assessing independently, which is several publishers rather than several assessors. The entry says so in its sourcing note and its credibility rating reflects it. Separately, the maintainer's advisory index was for a time filing one identifier's write-up under another's page — confirmed against the release notes and two vulnerability databases while researching, and corrected by the maintainer before this run published. The entry records it in the past tense, because anyone who triaged the batch from that index in its first hours would have read its most serious flaw as a denial-of-service bug.

Operational note — the first research attempt was cut short by a content safeguard. All four research passes terminated on a safeguard error within about a minute, before any had fetched a source. Each had been handed a long inline recap of already-covered vulnerabilities, actors and campaigns as its deduplication context. Moving that context out of the instructions and into a file the research passes read for themselves — a trimmed index of identifiers, titles and entity keys rather than 128 narrative summaries — worked immediately, and all four then completed normally. The lesson generalises the rule this pipeline already applies to its own working context: pass accumulated threat content by reference, not inline. Roughly ten minutes of wall-clock was lost.

  • Coverage gaps: sysdig (RSS empty, HTTP 503 direct, reader credential pool exhausted); prodaft (JS shell, reader 402); cisa-directives (403 to every agent, stale cached shell); claroty-team82, team-cymru, trellix, project-discovery (client-rendered listings with no recoverable dates); ssd-disclosure, depthfirst, yeswehack, searchlight-cyber (no extractable post dates, so in-window status was indeterminable); ico-uk and cnil-fr reached but carrying nothing newer than 2026-07-22.
  • Essential-coverage: complete — all 15 essential sources attempted, cisa-directives reached only as a stale shell (KEV ground truth covered through its own API path).
  • Reader-credential pressure is now a recurring cause rather than an incident: three separate sources failed this run only because the metered reader pool is exhausted. The pool is the last rung of the fetch ladder by design, but several source records are pinned to it as their only transport. That is a standing repair order for the next audit.

← Operations dashboard · run-record contract: docs/pipeline.md