ctipilot.ch

2026-08-04T0411Z-intel

One pipeline fire, in full · intel run of 2026-08-04 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-04/2026-08-04T0411Z-intel.md.

Run telemetry

2026-08-04T0411Z-intel intel prompt v3.30 publish ok
43m 31s duration 7 published 2 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
13m 35s
Tool calls
12 WebFetch9 WebSearch28 bridge
Cited sources
2 of 31 in slice
S2 Claude Opus 5 (claude-opus-5)
Items returned
4
Duration
19m 22s
Tool calls
5 WebFetch8 WebSearch33 bridge
Cited sources
4 of 26 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
11m 13s
Tool calls
24 WebFetch8 WebSearch9 bridge
Cited sources
2 of 33 in slice
S4 Claude Opus 5 (claude-opus-5)
Items returned
4
Duration
10m 00s
Tool calls
2 WebFetch5 WebSearch17 bridge
Cited sources
4 of 22 in slice

Verification

#? NEEDS_FIXES · Opus 5 · t=4 e=0 a=4 #? CLEAN · Sonnet 5 · t=0 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=1 e=1 a=0 #? NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=1 #? NEEDS_FIXES · Opus 5 · t=2 e=0 a=1 #? NEEDS_FIXES · Sonnet 5 · t=0 e=1 a=0 #? CLEAN · Opus 5 · t=0 e=0 a=1 #? NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=0

Deep dive

2026-08-04/unit42-pass-ta-key-chrome-synced-passkey-forgery-sds-theft

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

5 recipe note · 3 recipe-gap note · 1 status demoted -> active; fetch_method rss -> bridge · 1 added as candidate · 1 fetch_method jina -> rss; rss_url set · 1 recipe note (supersedes stale note).

SourceChangeFrom → ToReason
csirt-acn-itstatus demoted -> active; fetch_method rss -> bridge— → —The demotion premise (no method yields drillable content) is demonstrably false — the bridge `url` recipe returned the full server-rendered body on the per-publication slug path /portale/{w,en/w}/<slug>. Italy is a major EU jurisdiction and the S2 slice otherwise carries no Italian authority. Recipe recorded on the record.
venarixadded as candidate— → —The one new candidate of this run. Primary source for the ExfilSquad Power Pages / Dataverse access-path analysis cited by this run's PNLD entry; no tracked source covered it.
cert-plrecipe note— → —The tracked /en/news/ path does not list CERT-PL coordinated-disclosure CVE advisories at all — an essential-tier source was effectively dark for advisory discovery. Advisories live at /en/posts/<YYYY>/<MM>/<CVE-ID>/.
cert-atrecipe note— → —All three tracked news paths return no drillable dated rows; the bare homepage is the working discovery surface.
sysdigfetch_method jina -> rss; rss_url set— → —The reader returns only the cookie-consent shell on the HTML index; a direct fetch of blog/rss.xml returns 20 dated items. Stops spending reader credit on an unreadable listing.
edpbrecipe note (supersedes stale note)— → —The earlier 'navigation chrome only' note is stale — the bridge now returns the dated news listing correctly.
cisa-directivesrecipe note— → —`cisa page` on the directives listing works and returns drillable per-directive URLs; the listing carries no per-item dates, so recency must come from the drilled page.
cisa-advisoriesrecipe note— → —The advisories feed returns items with an empty `published` field; in-window filtering requires the date path in the alert URL or the ICS day-of-year id.
prodaftrecipe note— → —The reader now hydrates the reports listing (superseding the earlier client-shell note) but renders no publication dates; per-report dates require drilling /report/<slug>.
google-tagrecipe-gap note— → —The tracked URL resolves to Google's general security blog rather than a dated TAG listing; recency of TAG research cannot be established through it.
claroty-team82recipe-gap note— → —The research listing returns titles with no publication dates; needs a dated feed or per-post drill recipe.
recordedfuture-insiktrecipe-gap note— → —The tracked URL is a landing page with no dated article listing.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Bridge invocations (this run)

21 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

18 ok2 empty feed1 item not found
  • bridge:url ×6
  • bridge:feed ×3
  • bridge:jina ×2
  • bridge:ncsc-csh.recent ×1
  • bridge:cert-fr.avis-recent ×1
  • bridge:cert-fr.actu-recent ×1
  • bridge:bsi-rss ×1
  • bridge:bsi-csaf ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? NEEDS_FIXES · 8 findings (truth=4, editorial=0, advisory=4) · Claude Opus 5 · 14m 18s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
Cisco CVE-2026-20079
compromise check revised three times after v2.0, not twice
F3
claim-not-supported
CrowdStrike Threat Hunting Report
report covers the 12 months to 2026-06-30, not January-June 2026
F4
hallucinated-fact
Cisco CVE-2026-20079
body quotation pulled 'because' inside the quote marks
F4
hallucinated-fact
SQLite withdrawal entry
BSI title transliterated as ZURUECKGEZOGEN; both pages render ZURÜCKGEZOGEN
F11
editorial-advisory
Cisco CVE-2026-20079
'only available response was detection' contradicts the preceding clause
F11
editorial-advisory
CrowdStrike Threat Hunting Report
publication-process meta-sentence, and empty references[] the body points at
F11
editorial-advisory
SQLite withdrawal entry
'fabricated' applied to the one id JFrog did not reproduction-test
F11
editorial-advisory
CrowdStrike Threat Hunting Report
vendor-telemetry figure density in the rendered summary, incl. an adversary count

Iteration #? NEEDS_FIXES · 2 findings (truth=1, editorial=1, advisory=0) · Claude Opus 5 · 17m 20s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
CrowdStrike Threat Hunting Report
the '12 months to 30 June 2026' window was cited to the CrowdStrike blog, which says only 'the past year'; the end-dated window comes from SiliconANGLE
F10
missed-angle
INC Ransom / SonicWall SMA 1000 exploit chain
in-window reporting (THN 2026-08-03 on Resecurity 2026-08-01) on a CVE pair the store already covers, adding actor attribution and reported Swiss victims — absent from the entries, from triage.json an

Iteration #? NEEDS_FIXES · 2 findings (truth=1, editorial=0, advisory=1) · Claude Sonnet 5 · 8m 08s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F16
?
INC Ransom / SonicWall SMA 1000 delta
the patch-rollback behaviour was mapped to T1601.001 Patch System Image, which covers introducing new capability into an image; the sourced behaviour is installing an older weaker image, which is T160
F11
editorial-advisory
CrowdStrike Threat Hunting Report
the corrected two-source citation split read awkwardly

Iteration #? NEEDS_FIXES · 3 findings (truth=2, editorial=0, advisory=1) · Claude Opus 5 · 12m 33s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
PNLD update
a limitation clause and its quote were attributed to VenariX, which never mentions PNLD at all; both are The Hacker News's words, as the entry's own evidence[] already credited
F4
hallucinated-fact
state/cves_seen.json record for CVE-2026-51294
the record's title asserted JFrog reproduction-tested this id, which JFrog never mentions — contradicting the entry's own corrected hedge — and attributed the NCSC-NL withdrawal to it when that adviso
F11
editorial-advisory
SonicWall SMA 1000 delta
T1539 and T1111 were source-supported but the behaviour behind them appeared nowhere in the body

Iteration #? NEEDS_FIXES · 1 finding (truth=0, editorial=1, advisory=0) · Claude Sonnet 5 · 4m 14s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
SonicWall SMA 1000 delta
the clause added in the previous round was accurate and correctly attributed in prose but carried no inline citation, breaking the entry's own per-claim citation pattern

Iteration #? CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Opus 5 · 16m 57s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
inline-citation density, 3 instances across three entries
prose-attributed quotes and facts whose publisher is in sources[] but which carry no inline link at the point of claim; all verified accurate

Iteration #? NEEDS_FIXES cap-breach · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · 5m 10s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Liechtenstein VwbP register breach
carried tags: [data-breach, phishing] while the entry itself states no initial-access vector has been disclosed and maps no access-vector technique; neither government primary mentions phishing, so th

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-04T0411Z-intel · Claude Opus 5 · window 26 h · 7 entries published

Verification & coverage notes

Window: 26 h derived from a 24 h gap to the previous fire (2026-08-03T0409Z-intel), standard window class. That run's publish_status was ok, so no carried-over publishing failure. No intel/ drop directories in window, so no closed-source intake agent was spawned.

Two research agents were terminated mid-run by a model-specific content classifier, and both were recovered. The S2 (home region) and S4 (incidents) agents each died twice on Sonnet with an API safeguards error, in both cases early in the run shortly after loading the dedup context. Re-spawning them on a different model with the lean keys-only dedup index instead of the full-summary index worked first time, and both returned complete: S2 ran 19 minutes and returned four items, S4 ran 10 minutes and returned four. No coverage was lost — every source in both slices was attempted — but the run's own telemetry records the two agents as Opus rather than the definition's Sonnet pin, which is why their model lines differ from S1 and S3. Worth an operator note because the trigger looks like accumulated breach and exploitation content in the agent's context rather than anything in the spawn message, and the lean-index mitigation is cheap enough to consider as the default for these two domains.

A finding was corrected against its own primary source during the pre-publication deep read. S1 reported that Cisco shipped the first permanent hot fixes for CVE-2026-20079 on 2026-08-03 and that the same-day sibling advisory newly documented the chaining relationship. Re-reading both advisories in full shows neither claim holds: the hot fixes and the compromise-check guidance were added in advisory version 2.0 on 2026-07-31, the 2026-08-03 revision (v2.3) only updated the indicator-of-compromise CLI command, and the Security Impact Rating note about chaining was present in the sibling advisory from its initial release on 2026-07-29. The published entry states the correct dates and does not claim the fix or the chaining note as in-window news; the in-window development it rests on is the revised compromise check, and the reason the item is published at all is that a CVSS 10.0 authentication bypass on this product had never been covered here while its 5.3 sibling was.

Two further claims were corrected in the PNLD update. The researching agent's summary presented per-department figures (108,429 police registrations plus CPS, Home Office, NCA and MoD counts) as quantified breach scope; the cited reporting states explicitly that the 108,429 figure is PNLD's registered user base, not a victim count, and that PNLD has published no victim total at all. The same agent's framing had the Power Pages / Dataverse path as the PNLD access route; the reporting is explicit that it remains a campaign-level hypothesis with no PNLD-specific endpoint, permission setting, API route or log identified. The entry carries both corrections, and also revises the earlier entry's "probably fabricated" read on the ExfilSquad victim list to the narrower position the new evidence supports.

Every evidence[] quote was literal-substring-checked against the re-fetched page before the entry was written, with tag stripping replacing tags with the empty string rather than a space so the check ran against an uncorrupted copy. The fetched bodies were working scratch and are deliberately not committed — around 3 MB of raw advisory and article HTML has no forensic value once the quotes are verified, and the standing rule is to drop raw page text after extraction. That check was not as complete as first recorded here, and the verifier caught the gap: it covered the frontmatter quotes and a selected set of body quotations, not every quoted fragment in every body. Two body quotes drifted and were fixed in remediation — a Cisco sentence that pulled the word "because" inside the quotation marks, and the BSI advisory title transliterated as "MELDUNG ZURUECKGEZOGEN" where both cited pages render "MELDUNG ZURÜCKGEZOGEN". The lesson for the next fire is to run the literal check over every quoted span in the body, not only over evidence[].

  • borderline-drop: PaperCut NG/MF CVE-2026-8793 / CVE-2026-8794 (CERT-FR AVI-0959, 2026-08-03) — a missing brute-force limit and a login timing oracle, both CVSS 4.0 6.9, no code execution, no reported exploitation, fixed by upgrading to 26.0.3. Heavy public-administration, education and healthcare deployment argued for it, but a normal patch cycle handles it and the inclusion bar for a vulnerability is action beyond that cycle.
  • borderline-drop: ShinyHunters leak-site listings naming Alcon (Swiss-domiciled) and Questel (France), with a stated leak deadline of 2026-08-04 — a criminal claim and nothing more. No statement from either organisation and no high-reliability journalism on either listing could be found, so it cannot be reported as fact however well the claim shape matches this actor's confirmed activity. Worth a re-check next fire now the stated deadline has passed.
  • borderline-drop: Garante per la protezione dei dati personali fines TIM EUR 9,516,000 over unlawfully acquired telemarketing consents (2026-08-03) — a real enforcement action in a profiled sector, but a consent decision with no intrusion, no telemetry and nothing a Tier 2/3 responder would do differently this week.
  • borderline-drop: leak-site listings of CEN and CENELEC (coinbasecartel, 2026-08-01) and of the Mairie de Rinxent (krybit, 2026-08-02) — unconfirmed claims with no victim statement and no high-reliability reporting. The European standards bodies would be materially notable if confirmed; carried forward for a re-check.
  • out-of-window: unmaintained cJSON — CERT Polska's unpatched integer-overflow-to-heap-overflow advisory for CVE-2026-16554 (2026-07-27) plus a researcher's 33-issue disclosure relayed to OSS-Security (2026-07-30), primary sources outside window_hours=26. This one deserves the operator's attention rather than a quiet drop: cJSON is vendored into ESP-IDF and a great deal of embedded firmware, there is no maintainer and no patched version to point at, and the exposure lands in the device layer of energy, water, transport and building-automation estates. It is absent from all 129 entries in the 14-day index and fell into the gap between successive 24 h windows rather than being assessed and rejected. Handed to the next weekly for its periodic sweep.
  • out-of-window: ACN / CSIRT Italia operational summary for H1 2026 (2026-07-24) — an unprocessed periodic national-authority report squarely in region and sector, eleven days outside the window. Also handed to the weekly. Its most transferable findings are that NIS2 notifications inflate reported event counts without inflating threat, and that new CVE volume rose 54% year on year.
  • out-of-window: Atlassian Jira CVE-2022-37601 and CVE-2026-42581, both rated 9.8 by CERT-FR (CERTFR-2026-AVI-0934, 2026-07-27); Ransom-ISAC's "Weaponizing Exposed Data" analysis of extortion groups indexing and pricing stolen data before publication (2026-07-31); CISA BOD 26-04 on risk-based update prioritisation (2026-06-10, and a US federal mandate rather than a Swiss or EU obligation). All absent from prior coverage; recorded so they are recoverable.
  • Completeness sweep ran over all four findings files including every item the agents marked borderline, plus their own post-review drop lists. Nothing genuinely relevant fell out for any reason other than failing the gate or the recency rule; the two out-of-window items with real merit are named above with an explicit hand-off rather than dropped silently.
  • The seven fabricated SQLite identifiers are deliberately absent from the frontmatter cves[] of the entry that reports them: no cve_status value describes a withdrawn record, and populating a record's type, vector and auth fields would assert a flaw class that does not exist. They are instead recorded in state/cves_seen.json, which carries only an id, a title and a source URL, each titled as fabricated and pointing at the retraction so that a scanner lookup or a future run resolves the id to the correction. That reasoning was too confident about the index being unfalsifiable, and the verifier proved it: the free-text title on one of those records asserted that JFrog had reproduction-tested the id when JFrog never mentions it, so the state index briefly contradicted the entry it was written alongside. The title has been rewritten. A field with no schema is still a field that can carry a wrong claim. The ATT&CK mapping on that entry is empty and stays empty: the finding is a vulnerability-data-integrity failure with no attacker behaviour to map, and bolting on a technique to clear the warning would be exactly the invention the mapping rules forbid. This is the run's one surviving warning and it is deliberate.

The confirmation pass earned its keep — it found a real coverage miss, and the miss was ours twice over. Iteration 3 (Opus, the confirmation pass after iteration 2's CLEAN) refused to confirm and flagged in-window reporting this run had not assessed at all: The Hacker News, SecurityWeek and SC Media all covered Resecurity's SonicWall SMA 1000 research on 2026-08-03, on a CVE pair this store has carried since 2026-07-14. A scoped follow-up research agent verified it, and its conclusions reshaped the entry substantially from the verifier's own framing of the lead: the actor attribution is not new (Rapid7 named INC Ransom on 2026-07-17, published by Dark Reading the same day, hours before this pipeline's 2026-07-18 entry, which missed it), and the Swiss-victim element is a single-vendor characterisation of criminal leak-site postings with no named organisation, no confirmation and no stated link between any individual listing and the exploit chain. So the entry ships as a tightly-scoped escalation delta whose defender value is elsewhere: Rapid7 observed the actor rolling an applied patch back to a vulnerable state, which means version-checking is not an eviction test, and the required credential-rotation scope is wider than the 2026-07-18 entry stated. The Swiss claim is recorded as unverified and drives neither the framing nor the regions field. Two process points for the operator: the follow-up also caught Resecurity overstating the attribution chain ("Volexity and Rapid7 have since linked…" — Volexity has published no INC link at all), and it noted that the 2026-07-18 entry cites its Rapid7 source by last-modified rather than first-publication date, a cosmetic artefact on an immutable record.

  • Deliberate non-update decision: the CrowdStrike Threat Hunting Report entry shares the entity actor:sapphire-sleet with the 2026-07-30 Amazon DPRK-attribution entry, and the gate rightly asks whether that should have been a delta. It should not. The two are different stories: the earlier entry is Amazon's medium-confidence attribution of the axios, debug and chalk compromises to that cluster; this one is a newly published annual report whose own subject is exploitation velocity and supply-chain concentration, and which happens to add one new tradecraft detail on the same actor (the June 2026 injection into 131+ Mastra AI framework packages). The report is covered once as its own annual-report entry per the periodic-report rule and referenced thereafter. The actor is named in the body only to stop a reader treating CrowdStrike's STARDUST CHOLLIMA cryptonym as a new adversary — it is already an alias on the existing record.
  • Coverage gaps: cert-pl (essential tier — advisory discovery through the tracked /en/news/ path is dark; the working path is now recorded on the record); cert-at (tracked news paths return no dated rows; homepage recipe recorded); google-tag, claroty-team82, recordedfuture-insikt (listings carry no publication dates or resolve to the wrong feed — recency unverifiable this run); prodaft (reader hydrates the listing but renders no dates); siemens-productcert-csaf (CSAF directory 403s every UA and no fresh Siemens ICS CVE surfaced to supply an ssa- id); depthfirst (homepage teasers carry no dates); chrome-releases (feed returned 0 items, cross-checked against the blog — no Stable Channel security release in range, so the empty feed hid nothing).
  • Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0 — no product or supplier watchlist is configured in the organization profile, so both sweeps are no-ops and the general coverage rules applied unchanged. No entry this run carries watchlist_hit.
  • Essential-coverage: all 15 essential-tier records were attempted across S1 and S2 and all returned content on some transport rung; fetch_failures[] is empty because nothing was unreachable on every rung. tools/source_health.py probed 174/174 sources in 96 s with zero UNSOLVED flags, so no repair order was outstanding this run.
  • Two of the five live jina reader credentials returned HTTP 402 balance-exhausted on every call, with automatic rotation to a working key each time. No fetch was lost, but the pool has less headroom than its aggregate balance suggests; both S2 and S3 flagged it independently.
  • One source-record duplication was caught and reverted before commit: the S2 agent proposed ACN / CSIRT Italia as a new candidate on the basis that Italy had no record in the source list, which was wrong — csirt-acn-it already existed, demoted since 2026-06-20 for having no readable transport. The health probe surfaced the collision. The duplicate was removed and the existing record recovered to active instead, carrying the working per-publication-slug recipe this run verified. VenariX took the single candidate slot.

← Operations dashboard · day page 2026-08-04 · run-record contract: docs/pipeline.md