2026-08-06T0411Z-intel
One pipeline fire, in full · intel run of 2026-08-06 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-06/2026-08-06T0411Z-intel.md.
Run telemetry
- Items returned
- 4
- Duration
- 16m 48s
- Tool calls
- 10 WebFetch12 WebSearch32 bridge
- Cited sources
- 6 of 24 in slice
- Items returned
- 2
- Duration
- 10m 59s
- Tool calls
- 11 WebFetch12 WebSearch9 bridge
- Cited sources
- 3 of 17 in slice
- Items returned
- 3
- Duration
- 10m 11s
- Tool calls
- 34 WebFetch2 WebSearch16 bridge
- Cited sources
- 4 of 34 in slice
- Items returned
- 3
- Duration
- 12m 03s
- Tool calls
- 8 WebFetch20 WebSearch15 bridge
- Cited sources
- 3 of 8 in slice
Verification
Deep dive
2026-08-06/chaindrop-shai-hulud-npm-worm-onchain-c2-resolver
Entries published (this run)
- Canton Graubünden discloses a SharePoint server breach a day after the Confederation did — the on-premises wave has reached Swiss cantonal government incident high
- CHAINDROP — the Shai-Hulud npm worm returns through the keyv maintainer, backdoors 400+ packages, and resolves its exfiltration endpoint from an Ethereum smart contract threat high
- CVE-2026-58048 — cPanel & WHM: renaming a database drops the SQL mode that contains a tenant, handing any hosting customer database-root (CVSS 9.4) vulnerability notable
- CVE-2026-63077 — TeamCity On-Premises moves to confirmed exploitation on the CISA KEV catalog, nine days after JetBrains said it had seen none vulnerability high update
- ENDLESSDOORS (CVE-2026-66747) — twenty Zbtlink router models ship from the factory with an unauthenticated root-command backdoor, and the discloser's remedy is replacement vulnerability notable
- CVE-2026-63455 / CVE-2026-63456 — HPE Aruba Networking SD-WAN Orchestrator: spoofed HTTP headers bypass REST API authentication (CVSS 9.8), with the vendor and CERT-FR scoping the affected branches differently vulnerability notable
- LiteLLM callback hooks let an attacker who already holds gateway admin forge tool calls after inference — downstream of every prompt-level defence research notable
- Veeam Service Provider Console and Veeam ONE — ten CVEs, headed by an unauthenticated CVSS 10.0 remote code execution on the Veeam ONE agent host vulnerability notable
- Water-utility PLC lockouts reach at least twelve US states, and Clayton County publicly confirms a distribution-side consequence as its own incident high update
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
1 recipe fixed (endpoints moved to /api/v1/) · 1 recipe note · 1 recovered — jina recipe works again · 1 quiet-period note.
| Source | Change | From → To | Reason |
|---|---|---|---|
| ncsc-ch-security-hub | recipe fixed (endpoints moved to /api/v1/) | — → — | tier=essential source was dark for structured discovery. GET on the unversioned /api/posts/** tree now returns 405 across the whole subtree; the public read API is /api/v1/posts/dashboard and /api/v1/posts/{id}/details, both confirmed working. tools/fetch_source.py patched and re-tested; the bundle-derived recovery procedure recorded in the code comment. |
| ncsc-ch-incidents | recipe note | — → — | Shares the CSH API fixed above; note added so the next run does not re-derive it. |
| ccn-cert-es | recovered — jina recipe works again | — → — | Rotation-priority source recorded as 404 on its last attempt; the documented jina recipe now returns a full dated listing. Kept as candidate. No in-window security content this run (latest item 2026-07-28), so this is a genuine quiet period rather than a gap. |
| prodaft | quiet-period note | — → — | Rotation-priority source flagged for 3 runs without contributing. The jina fetch succeeded and returned a hydrated report listing this run; there is simply no in-window report. Recorded so the flag is not misread as a transport failure. |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| ncsc-ch-security-hub covered via alternate · should NOT be in this list | https://security-hub.ncsc.admin.ch/api/posts/dashboard?pageSize=10&pageIndex=0 | bridge:ncsc-csh → bridge:jina | 405 recipe-drift The unversioned /api/posts/** tree stopped serving GET. Every path beneath it — including paths that never existed — answers HTTP 405 with `Allow: DELETE, PUT`, | Root cause found and fixed this run: the public read API moved under /api/v1/. Recovered the current route table from the SPA bundle (main-*.js), confirmed GET |
| enisa-euvd covered via alternate · should NOT be in this list | https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-49369 | webfetch → bridge:jina | 200 The human-readable advisory detail page returned an 'application could not be loaded' shell on both WebFetch and the jina reader — a site-side outage rather tha | The underlying JSON API answered normally and supplied the corroborating exploitation data; per citation discipline the API URL is not cited as a reader-facing |
Bridge invocations (this run)
11 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- bridge:jina ×3
- bridge:api ×2
- bridge:cisa-kev ×1
- bridge:cisa.page ×1
- bridge:enisa-euvd.advisory ×1
- bridge:feed ×1
- bridge:cert-fr.avis-recent ×1
- bridge:ncsc-csh ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #? NEEDS_FIXES · 9 findings (truth=6, editorial=2, advisory=0) · Claude Opus 5 · 12m 19s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F14 ? | — | The 'first consumer-facing impact' framing in title, headline, summary and body was contradicted by two sources cited on the entry itself — the FBI had already reported pressure loss and flooding amon | Reframed to the supportable delta: Clayton County is the first named utility to publicly attach its own name to a distribution-side consequence. Title, headline | |
| F17 ? | — | credibility 1 contradicted the entry's own sourcing note, which disclaims independent corroboration of the twelve-state figure — the one-assessor-several-publishers case. | credibility lowered to 2. | |
| F3 claim-not-supported | — | The 'offline for several hours' detail was cited to persoenlich.com, which does not carry it; it is in the co-cited cantonal press release. Separately, 'run on separate infrastructure' was an inferenc | Citation re-attached to the cantonal press release; the separate-infrastructure inference replaced with what the release actually says — the systems were unaffe | |
| F3 claim-not-supported | — | The entry said CERT-FR and NCSC-NL both carried the ten CVEs across both products. NCSC-2026-0276 is scoped to Service Provider Console and its four CVEs, and does not mention Veeam ONE or the CVSS 10 | Summary, body and sourcing note corrected to state each CERT's actual scope, with inline citations added to the body sentence that previously had none. The dive | |
| F4 hallucinated-fact | — | The entry named the researcher by real name; neither cited source does — both use the handle the work is published under. | All four occurrences replaced with the byline the sources use, including the sources[] publisher field. | |
| F14 ? | — | 'twenty-plus' and 'more than twenty' models overstated VulnCheck, which says twenty consistently and explicitly hedges the larger population as a possibility rather than asserting it. The entry's own | Title, summary, body and the CVE affected field corrected to twenty, with VulnCheck's own hedge about the true population carried as the hedge it is. The regist | |
| F14 ? | — | 'ten days after JetBrains said it had seen none' — the interval between the 2026-07-27 advisory and the 2026-08-05 KEV addition is nine days. | Corrected to nine in both the title and the sourcing note. | |
| F5 missing-citation | — | The entry's entire home-region nexus — stated in the headline and the body — rested on an NCSC-CH advisory that appeared in neither sources[] nor any inline link. The verifier independently confirmed | The Cyber Security Hub post added to sources[] as corroborating and cited inline at the claim. The claim itself stands. | |
| F11 editorial-advisory | — | Advisory: three ATT&CK mappings were imprecise — a web-protocols id on a custom binary protocol over a non-standard port, a modify-authentication id on a behaviour no source describes, and a dropped c | All three applied rather than left: the router entry moved to the non-standard-port technique, the gateway entry adopted the adversary-in-the-middle and transmi |
Iteration #? NEEDS_FIXES · 4 findings (truth=3, editorial=0, advisory=0) · Claude Opus 5 · 13m 38s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F14 ? | — | The iteration-1 fix narrowed the unsourced superlative instead of grounding it — title and summary still called Clayton County the *first* named utility, which no cited source supports; SecurityWeek c | Superlative dropped from title, headline and summary, which now use the body's framing. The attributable-confirmation-versus-aggregate-reporting delta is unchan | |
| F4 hallucinated-fact | — | Title and summary asserted a breach-to-breach interval ('breached a day after the Confederation's') that no source states — the sources give BIT's disclosure date, not its breach date. The body and th | Title and summary rewritten to the disclosure-to-disclosure framing the sources support. | |
| F14 ? | — | Residual of the iteration-1 TeamCity fix: the entry was corrected to nine days but the run record's own notes still said 'ten-day-old snapshot', so the record contradicted the entry on the very figure | Corrected to nine-day-old on the narrative line. The occurrences inside verification.iterations[0].findings[] are left as they are — they quote what was flagged | |
| F11 editorial-advisory | — | Advisory: techniques[] retained an ingress-tool-transfer id with no basis in the body or the single cited source, which describes only command execution and a reverse shell. | Dropped rather than left. techniques[] is the evidence-bound surface the ATT&CK matrix and Navigator exports derive from, and a root shell merely enabling trans |
Iteration #? NEEDS_FIXES · 4 findings (truth=2, editorial=2, advisory=0) · Claude Opus 5 · 12m 31s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | — | The title credited the replacement remedy to the vendor. Zbtlink has offered no remedy at all — the discloser recommends replacement and states it deliberately never notified the vendor, because there | Title re-attributed to the discloser; the no-notification decision and its stated reasoning added to the body; the cves[].fixed field extended with the disclose | |
| F3 claim-not-supported | — | The body attributed the deserialization characterisation to the vendor advisory, which never uses the word; it is CISA's catalog wording, cited a paragraph earlier. | Split into two attributed claims — the vendor's own description of the flaw, then the deserialization characterisation attributed to CISA, with a note that the | |
| F9 surface-contradiction | — | The entry's headline scoping fact followed the vendor silently. HPE states no branches outside 9.6.x.x are affected; the co-cited CERT-FR advisory additionally lists 9.7.0.x builds below 9.7.0.43264. | Divergence surfaced in title, summary, body, both cves[].affected fields and the sourcing note, and the action item widened to include 9.7.0.x builds below the | |
| F9 surface-contradiction | — | Both cited sources were carried but not their disagreement: OX Security reports a trigger that deletes the machine when the stolen GitHub token is revoked, while Elastic advises revoking GitHub tokens | The disagreement stated plainly in the body as an uncorroborated single-vendor claim, with the asymmetric-cost reasoning for sequencing around it anyway, and th |
Iteration #? NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Opus 5 · 9m 51s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | — | The iteration-3 fix over-corrected. Saying the deserialization characterisation is the catalog's 'rather than the vendor's' is wrong: the vendor is the CNA for its own product and assigned the deseria | The false contrast removed. The sentence now states only what the two cited sources support: the catalog names the flaw a deserialization of untrusted data vuln |
Iteration #? NEEDS_FIXES cap-breach · 1 finding (truth=1, editorial=0, advisory=0) · Claude Opus 5 · 14m 01s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F14 ? | — | Reported that the 1.3-billion-monthly-downloads total is not in the Elastic report and is the pipeline's own sum of per-package figures. | REJECTED as a false positive, not applied. The figure is Elastic's own: its article standfirst reads 'a worm that uses stolen npm credentials to backdoor co-own |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-08-06T0411Z-intel · Claude Opus 5 · window 26 h · 9 entries published
Verification & coverage notes
Window: 26 h, derived from a 24.0 h gap to the previous run (2026-08-05T0412Z-intel), which published successfully. Standard window class — no catch-up disclosure required. Four research domains ran; two of them had to be respawned after provider-side content safeguards terminated the first attempt before any findings were written (see below). Twelve candidates were returned, nine published, two dropped at the relevance gate and one folded into tooling work.
Sub-agent interruptions
Both the first S3 spawn (04:15Z) and the first S2 spawn (04:14Z) were terminated mid-flight by provider-side content safeguards, each before writing a findings file. Both were respawned once and completed normally. The common factor in the two failed spawn messages was a long enumeration of breach, actor and ransomware names carried as dedup context; the respawns replaced that enumeration with a pointer to the coverage file on disk and both completed without incident. The respawned agents were also told to write findings incrementally so a further interruption could not discard confirmed work. No research domain was lost and no coverage was abandoned — but note that the two respawned domains each ran a shorter clock than a first-spawn agent would have, which is a coverage risk worth watching if this recurs.
Borderline drops
- borderline-drop: Snowflake mass-extortion actor pleads guilty (US DOJ, 2026-08-05) — a retrospective law-enforcement outcome on a 2024 intrusion campaign. The only transferable lesson is generic multi-factor hygiene on SaaS platforms, which is exactly the class of advice the inclusion gate excludes, and no responder at this organization would act differently in the next seven days because of the plea. The European bank named among the original victims is a victim of the 2024 campaign, not a current home-region development.
- borderline-drop: Cl0p's PTC Windchill / FlexPLM extortion moving to mass leak-site publication — the campaign trajectory would be publishable, but the phase change rests solely on one leak-site observatory's scrape of the group's own site, with no victim disclosure and no corroborating journalism. A spot-check of the reporting on this campaign still records that victims had not been listed. Extortion-site claims need victim disclosure or high-reliability reporting behind them, so this is not publishable as sourced. It is a live thread for the next run rather than a rejected story.
Out-of-window items surfaced but not published
Four research publications dated 2026-08-04 fall outside this run's 26 h window and outside the previous run's window as well, so they are recorded here rather than silently dropped: Sophos X-Ops on DFIR-tool abuse by an extortion group (not previously covered — flagged for the weekly sweep), Unit 42's analysis of malware communicating directly to IP addresses, and CrowdStrike's agent-harness escape research. A Cloud Security Alliance note on an MCP-bridge flaw was also dropped because it repackages a disclosure from 2026-07-29 that this pipeline already covered on 2026-07-30.
One item was published despite an out-of-window primary, with the reasoning stated in the entry: the LiteLLM callback-hook technique was originally disclosed on 2026-08-03, with the in-window Cloud Security Alliance research note of 2026-08-05 as the freshest source. It has never been covered here, is not tied to a patch cycle, and its event_date records the original disclosure so the reader is not misled about freshness. Dropping it purely on the date of the first write-up would have left a permanent blind spot on a technique with no CVE and no fixed version to catch it later.
Sourcing and verification
- Single-source: 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor — VulnCheck is the only party reporting this vendor-shipped backdoor and the manufacturer has said nothing. Carried at high confidence on the strength of first-hand reverse-engineering and an assigned CVE identifier, with the single-source position stated in the entry. No CVSS is published by the discloser and none is invented here.
- Single-source (national-CERT carve-out): 2026-08-06/cve-2026-63077-teamcity-kev-confirmed-exploited — the exploitation finding rests on CISA alone as the authority for its own catalog. The vendor advisory is cited only to establish its position at disclosure; it has not been revised, so it is a nine-day-old snapshot rather than a contradiction.
- Single-source (victim carve-out): 2026-08-06/canton-graubuenden-sharepoint-server-breach — every substantive fact traces to the canton as the disclosing victim, with the additional timeline detail coming from its own IT-office head via a news agency. Several outlets carry the story but all republish that one account, so this is one assessor with several publishers and the credibility rating reflects that rather than the publisher count.
- The same one-assessor-several-publishers reasoning sets credibility 2 rather than 1 on the Veeam and HPE Aruba entries, where CERT-FR and NCSC-NL restate vendor advisories for their constituencies without independent assessment.
- Attribution restraint: the water-sector entry does not adopt the Iran attribution some coverage carries, because the same reporting records that federal agencies have declined to attribute the campaign publicly and no authority has connected the newly-reported Georgia incident to any actor. The twelve-state figure originates with a broadcaster and is reported as such rather than as an agency count.
- The link between the two Swiss SharePoint incidents is recorded as the cantonal IT chief's stated possibility, not as a confirmed technical finding, and the registry edge between them is typed
related-torather than anything stronger. Neither Swiss disclosure names a CVE and none is asserted here. - Contradiction: HPE Aruba SD-WAN Orchestrator affected-version scope — the vendor advisory states that no branches outside 9.6.x.x are affected, while CERT-FR's advisory covering the same two CVEs additionally lists 9.7.0.x builds below 9.7.0.43264 in its systems-affected list. Neither side is suppressed: the entry carries both, notes that the vendor is authoritative for its own product, and points out that the upgrade target is the same either way, so an operator on a 9.7.0 build below 9.7.0.43264 acts on the wider scope at no extra cost. The entry's action item was widened to match.
- Contradiction: CHAINDROP containment sequencing — OX Security reports a trigger that deletes the machine when the stolen GitHub token is revoked; Elastic advises revoking all GitHub tokens on impacted machines and does not mention such a trigger. One first-hand analysis reports it, the other neither corroborates nor denies it. The entry states the disagreement plainly rather than picking a side, and its action item now tells responders to isolate and image before revoking — the sequence that costs nothing if the claim is wrong and saves the host if it is right.
- Deliberate non-update decision, confirmed: the Graubünden entry references the federal BIT incident that an entry from 2026-08-05 already covers, which is flagged for confirmation because a shared entity normally means a candidate should ship as a delta. It ships as a new entry instead because it is a different victim organisation, a different intrusion on a different date, with its own disclosure and its own outcome — the canton reports planted files and no account compromise, where the Confederation reported roughly 200 compromised accounts and no planted-file finding. It is not a delta on the federal story, and the federal entry is referenced only because the canton's own statement invokes it. The sourced connection between them lives on the registry as a typed relation.
Composition checks applied
Every quotation intended for publication was literal-substring-checked against the fetched page before the entry was written, with tags stripped to the empty string rather than to whitespace. That caught four defects in the returned findings that would otherwise have shipped: a dropped leading word in a German-language quote from the Graubünden press release; a Veeam advisory sentence rewritten from "allowing … obtain" to "enables … acquire"; a quote spanning a hard line-wrap in the plain-text HPE Aruba CSAF advisory, which is not a contiguous substring and is therefore not carried as evidence at all; and a cPanel root-cause sentence attributed to the vendor that does not appear on either vendor advisory — it comes from the CVE record via the reporting outlet, and is now attributed there. The Veeam per-CVE scores, affected builds and fixed builds were transcribed from the vendor's own two bulletins rather than from any roundup, and the cPanel CVSS was confirmed against the CNA-assigned score.
Two IOC classes present in the source material were deliberately excluded from entries: the Ethereum contract address CHAINDROP resolves its endpoint from, and the hardcoded command-and-control hosts and payload hash in the ENDLESSDOORS research. Both entries describe the behaviour instead.
A dormant validator check, surfaced for the audit
The residual arithmetic in site/content_model.py reads truth and editorial off the final verification iteration, but the run-record skeleton and every historical record write truth_count and editorial_count. With the keys absent the validator computes an expected residual of zero, so the check has been silently passing on every run rather than validating anything — a record could have declared any residual it liked. It surfaced here only because this run is the first to carry a non-zero residual, which made the mismatch fail loudly instead of quietly.
This run's iteration records now carry both spellings, so the arithmetic is genuinely enforced for this record and the residual of 1 is validated rather than assumed. That is a local workaround, not the fix. The proper repair is to settle on one spelling across the validator, the skeleton in prompts/entry-template.md and the writers, and it should be done by the weekly quality audit rather than mid-run on the publishing path: making a dormant check live can retroactively fail historical records, and that needs a store-wide --all pass to assess rather than a five-minute change with a run waiting to publish.
Coverage and tooling
- Coverage gaps: enisa (latest item 2026-07-24, slow policy cadence); cert-at (latest item 2026-06-01, sparse cadence); ncsc-ch-focus (latest post 2026-08-04, outside the window and consumer-awareness material); ccn-cert-es, prodaft (both reachable this run, no in-window content); kela-cyber, push-security, gambit-security (quiet in-window); google-tag (no dated 2026 posts surfaced; broken feed persists); trellix (SPA shell returned no article links this pass); team-cymru, project-discovery, sans-ics (no dated in-window posts enumerable).
- Essential-coverage: no misses. All eleven S1 essential-tier sources and all four S2 essential-tier sources were attempted; the one essential source that failed transport (ncsc-ch-security-hub) was recovered within the run by fixing its recipe.
- Watchlist: no product or supplier watchlist is configured in the organization profile, so both sweeps are no-ops and the anti-overshoot guideline does not apply. S1 and S4 reported checked=0, hits=0 as instructed.
- ATT&CK dataset: the pinned release is v19.1 and upstream v19.2 published inside this window (2026-08-05). The pin is not stale enough to fail validation and every technique id used this run validates as active against v19.1, so the update is left to the weekly run that owns it rather than changed mid-intel-run. Recorded here so the weekly does not have to rediscover it.
- Source health: 175/175 sources probed in 82 s, 99 direct-ok, 75 bridge-ok, 1 client-error, and zero sources flagged as needing a bridge or a demotion. No unsolved repair items outstanding at the end of this run.
- No new candidate source was added this run; no sub-agent proposed one, and no candidate met the promotion bar in the state digest.
← Operations dashboard · run-record contract: docs/pipeline.md