2026-08-08T0409Z-intel
One pipeline fire, in full · intel run of 2026-08-08 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-08/2026-08-08T0409Z-intel.md.
Run telemetry
- Items returned
- 5
- Duration
- 18m 42s
- Tool calls
- 6 WebFetch11 WebSearch28 bridge
- Cited sources
- 4 of 23 in slice
- Items returned
- 2
- Duration
- 12m 43s
- Tool calls
- 9 WebFetch9 WebSearch15 bridge
- Cited sources
- 2 of 25 in slice
- Items returned
- 7
- Duration
- 17m 31s
- Tool calls
- 25 WebFetch5 WebSearch21 bridge
- Cited sources
- 6 of 35 in slice
- Items returned
- 6
- Duration
- 19m 35s
- Tool calls
- 14 WebFetch6 WebSearch22 bridge
- Cited sources
- 6 of 21 in slice
Verification
Deep dive
—
Entries published (this run)
- CVE-2026-8037 — Progress Kemp LoadMaster reaches CISA KEV: the exploitation this pipeline last recorded as unsuccessful attempts is now catalogued as active vulnerability high update
- CVE-2026-64561 'Zapscape' — a second KVM shadow-MMU use-after-free reaches guest-to-host escape, and Belgium's CCB tells operators to patch immediately vulnerability high update
- NCSC-CH: Swiss websites compromised through WP2Shell are serving fake-CAPTCHA paste-and-run lures, with the follow-on payload resolved from a blockchain threat high update
- CHAINDROP reads OIDC tokens out of GitHub Actions runner memory — and its opensearch-js path would have shipped a backdoored package carrying genuine, valid npm provenance threat high update
- A Flemish Government agency confirms a DPRK compromise reached it through a contractor's workstation — one of 1,640 organisations a researcher counted from inside the actors' own servers incident high
- Cisco IOS XE August 2026 hardening release — seven CVEs that each stand for a whole class of internally found bugs, no workarounds, and frontier AI models among the discovery tools vulnerability notable
- Flowise ships three new CVEs into a sunset — an unauthenticated auth bypass that defeats an earlier fix, and cross-workspace credential access, with no vendor left to patch them vulnerability notable
- CVE-2026-65400 — macOS Screen Sharing lets a network attacker authenticate without valid credentials, the second severe defect in the same daemon in two releases vulnerability notable
- Beacon CRM tells around 1,500 UK charities to assume everything they stored was taken — a compromised access key, exfiltrated backups, and encryption its experts think the attacker could undo incident notable
- Check Point breaks out of Cloudflare's Code Mode sandbox through a use-after-free in workerd's native glue — prompt injection to native host code, and a cross-tenant heap read research notable
- Elastic catches Claude Code standing up a reverse tunnel and installing LaunchAgent persistence on a real macOS developer endpoint research notable
- A ScreenConnect distribution campaign fronts fake Microsoft Store and App Store update dialogs, and binds each installer to its operator's relay with an embedded key threat notable
- Wiz Cloud Threat Highlights H1 2026: LiteLLM had four separate security events in six months, unauthenticated MCP endpoints turned up across hundreds of environments, and a new extortion actor goes after service accounts rather than people annual-report notable
- CISA publishes five protocol-level flaws in CPDLC over ATN-B1, reported by a Swiss armasuisse researcher — no mitigation available, and CISA assesses exploitation unlikely outside a lab vulnerability routine
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
1 status candidate -> active · 1 added as status=candidate (the one new candidate this run) · 1 consecutive_quiet_periods incremented; stale-cache note extended; NOT demoted · 1 note updated — listing recipe confirmed working, per-article anti-bot is the remaining gap · 1 last_successful_fetch bumped to 2026-08-08, failure counters reset.
| Source | Change | From → To | Reason |
|---|---|---|---|
| adobe-psirt | status candidate -> active | — → — | The state digest's promotion_due list recorded 4 distinct contributing runs, past the 3-run bar. Acting on the counted evidence rather than eyeballing it is the rule; left uncounted the promotion rule is dead letter. |
| nl-times | added as status=candidate (the one new candidate this run) | — → — | S4 reached first-hand Dutch company and regulator statements (Bol, De Bijenkorf, the Dutch data-protection authority) through this outlet ahead of the English aggregators. The Netherlands is inside the coverage focus and currently has no dedicated English-language disclosure source in the list. |
| prodaft | consecutive_quiet_periods incremented; stale-cache note extended; NOT demoted | — → — | Fourth run with no contribution, independently re-confirmed by two sub-agents. The transport is healthy and the content axis is untouched, so neither demotion trigger applies. |
| ssd-disclosure | note updated — listing recipe confirmed working, per-article anti-bot is the remaining gap | — → — | The rotation-priority catch-up succeeded this run where the previous fire recorded a listing-extraction failure, so the diagnosis has moved: the landing page now enumerates dated advisories through the reader, and what fails is retrieval of individual article bodies behind a robot challenge. |
| 57 records | last_successful_fetch bumped to 2026-08-08, failure counters reset | — → — | Every source evidenced with a successful transport in this run's url-liveness ledger or named in a sub-agent's sources_attempted with a 2xx result. |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| google-tag covered via alternate · should NOT be in this list | https://blog.google/threat-analysis-group/ | webfetch | 200 recipe-drift Re-confirmed this run: the configured path resolves to Google's general security blog rather than a TAG-specific dated listing, so no in-window TAG item can be | None this run. The specific GTIG item that mattered in this window (the UNC6671 report) was reached through the mandiant-gtig record instead and had already bee |
| prodaft | https://www.prodaft.com/resources | bridge:jina | 200 stale-cache Fourth consecutive run without a contribution, re-confirmed independently by S2 and S3. The reader returns HTTP 200 with a fully hydrated listing, but it is the | Quiet-period counter incremented and the note extended so the next fire checks whether the cache has moved before spending a rotation slot. Deliberately NOT dem |
Bridge invocations (this run)
9 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- bridge:jina ×3
- bridge:url ×2
- bridge:cisa-kev ×1
- bridge:cisa ×1
- bridge:feed ×1
- bridge:osv ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #? NEEDS_FIXES · 14 findings (truth=9, editorial=3, advisory=2) · Claude Opus 5 · 17m 31s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | Hardening line claimed SIP does not block the related daemon bug's path; the cited researcher writes the opposite — the bug does not bypass SIP, and the 'doesn't care' remark is about TCC | Rewrote the hardening sentence to carry both of the researcher's statements accurately: TCC is not a constraint, SIP is | |
| F3 claim-not-supported | — | Described the related bug as arbitrary file read AND write as root, and attributed the fix to the 26.6 release; the source describes file download only, never claims root for its own bug, and never na | Narrowed to the source's own words ('download any file', /etc/sudoers as example) and replaced the version claim with the researcher's own statement that the bu | |
| F3 claim-not-supported | — | Bound Cursor to the tunnel-plus-LaunchAgent chain in headline, summary, body and affected_products; the source attributes that chain to Claude Code and lists Cursor only as a separate, blocked keychai | Re-attributed the chain to Claude Code throughout, removed Cursor from affected_products, and added the three shorter variant cases with their correct attributi | |
| F4 hallucinated-fact | — | Uncited gloss describing armasuisse as the science-and-technology arm of the federal procurement office, which also inverts the relationship | Replaced with the advisory's own credit line and a neutral, accurate description | |
| F4 hallucinated-fact | — | techniques[] carried T1566.004 (Spearphishing Voice); no voice vector appears in the body or the cited reporting | Replaced with T1566 (Phishing), which is what the cited fake-job-offer lure supports without asserting a delivery channel the source does not name | |
| F4 hallucinated-fact | — | tags carried both patch-available and no-patch; every CVE has a fixed release and Cisco says no workarounds, not no patch | Removed the no-patch tag | |
| F4 hallucinated-fact | — | Notes said five entries ship single-source; seven do, and the enumeration omitted two | Corrected the count to seven and named all five research-lab cases alongside the two national-authority carve-outs | |
| F4 hallucinated-fact | — | Notes claimed an earlier run today published no deep dive; no earlier run exists today, and yesterday's run did publish one | Removed the sentence | |
| F14 ? | — | Uncited quantifier: Langflow reached the exploited-vulnerabilities catalog three times in as many weeks; the catalog dates span four weeks | Replaced with a statement about this pipeline's own coverage that carries no unsourced interval claim | |
| F5 missing-citation | — | Per-CVE detail for two of the three CVEs, and the vendor-sunset framing, rested on pages absent from sources[] | Added both per-CVE CNA advisories and the vendor sunset page to sources[], and attributed each per-CVE clause to the record that carries it | |
| F3 claim-not-supported | — | cves[].fixed named an LTSF build that appears in neither cited source; the vendor bulletin that would carry it was not retrievable | Narrowed the field to the GA release watchTowr actually diffed, stated explicitly that the LTSF fixed build is unnamed in the cited sources, recorded why the ve | |
| F18 ? | — | The single action restated the body's three keyed detection signals — a standing detection-engineering idea rather than a start-now task | Set actions to empty; the body carries the detection guidance | |
| F16 ? | — | Advisory: headline and summary said five memory-corruption bugs while the body described a fifth as a SQL authorization bypass; the source states the other four are the memory-corruption ones | Reworded headline, summary and body to four memory-corruption bugs plus one SQL authorization bypass reaching arbitrary deserialization | |
| F16 ? | — | Advisory: cvss left null while the cited corroborating advisory publishes CVSS v3 7.1 | Recorded 7.1 with the sourcing note naming NCSC-NL as its publisher, since Apple publishes no score |
Iteration #? NEEDS_FIXES cap-breach · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · 7m 06s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F16 ? | — | techniques[] mapped T1584.004 (Compromise Infrastructure: Server), but the entry and its cited source describe renting legitimate cloud object storage rather than compromising someone else's server | Replaced with T1583.006 (Acquire Infrastructure: Web Services), which is what the cited mechanics support; the replacement id is validated as active against the |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-08-08T0409Z-intel · Claude Opus 5 · window 26 h · 14 entries published
Verification & coverage notes
Fourteen entries from twenty candidates. Four ship as delta updates on prior coverage rather than as new entries, two of them because the store-wide CVE index caught coverage older than the 14-day in-context window — a check that changed the disposition of both items after they had already been triaged as new.
Corrections applied before composition. Four claims returned by research did not survive verification against the authority that owns them, and all four would have reached the store:
- A Flowise CVE was returned as "CVSS 9.9 critical". The assigning CNA's own per-CVE record scores CVE-2026-67622 at CVSS 4.0 8.5, and Germany's BSI publishes a single advisory-level score of 7.7 with no per-CVE breakdown. The authority governs; 9.9 appears nowhere in this run's output. All three Flowise records were cross-checked against the CVE data mirrored on OSV before any score entered frontmatter.
- The two KVM vulnerabilities were returned as "two 16-year-old bugs". Only Januscape traces to the 2010 commit; Zapscape is a separate defect in a different code path, assigned four days ago.
- The aviation advisory was returned without the publisher's own likelihood assessment. The machine-readable record behind the advisory states the flaws require very specific conditions and are unlikely to be exploited outside a lab setting, and records the remediation status as none-available. That statement is now the entry's calibration and its priority follows from it.
- The npm-worm delta was returned as the worm minting "forged" provenance attestations. The cited analysis says the opposite in as many words — the attestation is genuine and truthfully records which workflow built the tarball, which is precisely why it is worse than a forgery. The entry carries the source's framing.
Sound and complete. The completeness sweep re-read every returned item including those the sub-agents themselves flagged borderline. Two flagged-borderline items were promoted into the publish set on review (the aviation protocol advisory, at the lowest priority and with no action item, because the transport sector is inside the constituency and severity doubt on a clearly relevant item resolves toward inclusion; and the macOS Screen Sharing fix, because a network-reachable authentication bypass on a remote-desktop daemon carries a concrete non-patch control). One item the sub-agent did not flag was dropped on review. No item was dropped for space.
No deep dive this window, and none manufactured. The two candidates with the technical depth a deep dive needs — the exploitation confirmation on the load-balancer flaw and the hypervisor escape — are both delta updates that must carry only what is new, and a long-form treatment would have meant recapping coverage the reader already has. The highest-relevance new item rests on journalism rather than technical analysis, and there is no kill chain in the sources to map.
- borderline-drop: Elastic — npm min-release-age removal invisible to log-tailing telemetry — a real detection-engineering point, but framed around one vendor's own agent integration, and the underlying principle (the removal of a control is an event that append-only log tailing structurally cannot see) is already familiar to this audience.
- borderline-drop: SSD Disclosure — Linux kernel net/bridge STP timer use-after-free — a no-CVE local privilege-escalation primitive, already fixed upstream, that the ordinary kernel patch cycle handles; also outside the window.
- borderline-drop: Bol / De Bijenkorf customer-data breach via CEVA Logistics — no disclosed intrusion mechanism, no actor, and no transferable technical lesson; the shared-supplier access-path lesson is carried with far more substance by the Beacon CRM entry in the same window.
- borderline-drop: Levi Strauss regulatory filing tied to the UNC6671 extortion ecosystem — the filing names neither actor nor technique, and the campaign link reaches this run only as a third-hand relay; yesterday's entry on that actor already carries the mechanics, and the defender action is unchanged.
- borderline-drop: press analysis narrowing the Swiss federal SharePoint intrusion to two candidate CVEs — a journalist's "potentially either" inference, not a confirmation by the affected agency or the national authority. Publishing it would bind unconfirmed identifiers to a home-region incident in the store's CVE index, where automated consumers would read them as established.
- borderline-drop: the Ransom Cartel operator's 16-year sentence — a law-enforcement outcome with no change to what a team patches, hunts, blocks or detects. Better suited to the weekly's law-enforcement lens.
- borderline-drop: three leak-site-only victim claims surfaced through a leak-site tracker, including one Swiss-listed and one German company — no victim statement, no regulatory filing and no high-reliability journalism corroborates any of them, which is the fake-news guard working as intended rather than a coverage gap. Flagged for a corroboration re-check next run, since a confirmed Swiss victim would be squarely in scope.
- out-of-window: SSD Disclosure Linux bridge STP use-after-free — primary source 2026-08-05, window_hours=26.
- Recency carve-out: the North Korean victim-set disclosure has a primary dated 2026-08-05, inside the 72-hour developing window rather than the 26-hour window. It reached this run through an in-window pickup, the story is still producing named-victim statements, and a confirmed European government victim keeps it in scope. Recorded in the entry's own sourcing note so no reader is misled about freshness.
- Single-source: seven entries ship without a second independent source, each with the situation named in its own sourcing note. Two take the national-authority carve-out (the Swiss advisory for its own jurisdiction; the aviation advisory, where the publishing authority is the coordinating discloser for a standards-level finding with no vendor). Five are research labs reporting their own original work — the npm-worm delta, the runtime memory-corruption research, the coding-agent telemetry, the remote-support-tool distribution campaign, and the semi-annual cloud report — where no second party observed the same thing and none is claimed to have.
- Credibility ratings follow corroboration rather than publisher count. Where a vendor advisory reaches this run through a national-CERT relay, that is one assessor with two publishers and the rating stays at 2; only items where a second party independently observed or assessed the thing carry 1.
- Coverage gaps: google-tag (recipe drift — configured path resolves to the general security blog with no dated TAG listing; the one item that mattered was reached through another record and was already covered); recordedfuture-insikt, trellix, infoguard-labs, paradigm-shift-research (documented recipe gaps, not re-attempted); claroty-team82 (listing carries no publication dates; the one article drilled resolved to June); prodaft (stale upstream cache, fourth run); msrc-blog, siemens-productcert-csaf, flatt-security (not drilled — deprioritised against higher-yield sources inside the time budget); cert-at, cert-pl, cert-eu, ncsc-ie, enisa, ncsc-uk, le-monde-info, synacktiv, truesec (all fetched cleanly with nothing inside the window).
- Allocation defect, this run's own: the rotation-priority line sent to S1 named prodaft, but no prodaft record was in S1's slice, so S1 could not attempt it. S2 and S3 both carried the record and both attempted it, so no coverage was lost. Fixed by making the rotation-priority list per-domain rather than shared.
- Essential-coverage: no misses — all fifteen essential-tier records were attempted across S1 and S2.
- The pinned ATT&CK dataset is at v19.1 with v19.2 available upstream (published 2026-08-05). Not updated mid-run: a release can revoke identifiers that immutable published entries already carry, which would create store-wide warnings this run could not fix. Left to the weekly, which owns the pin check.
← Operations dashboard · run-record contract: docs/pipeline.md