ctipilot.ch

2026-08-09T0412Z-intel

One pipeline fire, in full · intel run of 2026-08-09 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-09/2026-08-09T0412Z-intel.md.

Run telemetry

2026-08-09T0412Z-intel intel prompt v3.30 publish ok
35m 51s duration 4 published 1 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
13m 05s
Tool calls
15 WebFetch24 WebSearch20 bridge
Cited sources
2 of 15 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
8m 24s
Tool calls
6 WebFetch11 WebSearch16 bridge
Cited sources
1 of 13 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
12m 51s
Tool calls
16 WebFetch25 WebSearch14 bridge
Cited sources
0 of 13 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
12m 07s
Tool calls
16 WebFetch14 WebSearch10 bridge
Cited sources
3 of 17 in slice

Verification

#? NEEDS_FIXES · Opus 5 · t=2 e=3 a=2 #? NEEDS_FIXES · Sonnet 5 · t=1 e=1 a=2

Deep dive

2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 status candidate -> active · 1 fetch_method webfetch -> rss; rss_url https://labs.infoguard.ch/rss.xml added · 1 consecutive_quiet_periods incremented; note corrected to the live URL; NOT demoted · 1 consecutive_fetch_failures incremented; anti-bot regression noted; NOT demoted · 1 last_successful_fetch bumped to 2026-08-09, failure counters reset.

SourceChangeFrom → ToReason
nl-timesstatus candidate -> active— → —The state digest's promotion_due list recorded 7 distinct contributing runs, well past the 3-run bar. Left uncounted the promotion rule is dead letter, so it is acted on from the counted evidence rather than eyeballed.
infoguard-labsfetch_method webfetch -> rss; rss_url https://labs.infoguard.ch/rss.xml added— → —S3 discovered a working dated feed, resolving a standing recipe gap that had hidden this source's publication dates from every prior run. The first fetch through the fixed recipe surfaced a 22-CVE Swiss original-research disclosure the pipeline had never covered — see the coverage note below.
prodaftconsecutive_quiet_periods incremented; note corrected to the live URL; NOT demoted— → —Fifth run with no contribution. The note pointed at a subdomain that no longer resolves, which is a separate defect from the stale cache and is now fixed.
ssd-disclosureconsecutive_fetch_failures incremented; anti-bot regression noted; NOT demoted— → —Landing page now serves a robot-challenge interstitial where the same recipe worked a day earlier. A 403/anti-bot block never demotes.
35 recordslast_successful_fetch bumped to 2026-08-09, failure counters reset— → —Every source a sub-agent reached with a 2xx and usable content this run.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
ssd-disclosurehttps://ssd-disclosure.com/bridge:urlbridge:jina200
The reader returned a Cloudflare-style robot-challenge interstitial instead of the advisory listing, independently observed by S1 and S3. This is a regression:
None available this run. Note updated and the fetch-failure counter incremented; not demoted, because an anti-bot block is a transport problem and never a conte
prodafthttps://www.prodaft.com/reportsbridge:urlbridge:jina200 stale-cache
Fifth consecutive run without a contribution, re-confirmed independently by S1 and S3. Two distinct problems separated this run: resources.prodaft.com — the sub
Source note corrected to point future runs at www.prodaft.com/reports rather than the dead subdomain, and flagged as needing a structured-endpoint recipe. Quiet
csirt-acn-ithttps://www.acn.gov.it/portale/en/csirt-italia/alert-e-bollettinibridge:url200 recipe-drift
The bridge returned a body with no date-bearing rows, so no in-window content could be confirmed either way. A listing-extraction problem rather than a transpor
None this run; logged for a recipe pass. No coverage loss identified — no Italian in-window item surfaced through any other route either.

Bridge invocations (this run)

7 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

7 other
  • bridge:url ×4
  • bridge:cisa-kev ×1
  • bridge:jina ×1
  • bridge:osv ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? NEEDS_FIXES · 7 findings (truth=2, editorial=3, advisory=2) · Claude Opus 5 · 14m 09s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
Body said three buffer overflows, two unauthenticated; the cited post and the CVE records describe four, three of them unauthenticated, and CVE-2026-54211 sat in cves[] without appearing in the body.Rewritten to four overflows with the authentication precondition stated per flaw and CVE-2026-54211 named as the authenticated one. The (editini) overflow is no
F15
?
LexisNexis's "Metabase API" is LexisNexis's own news-aggregation product, not a Metabase BI deployment; carried unqualified inside a Metabase entry it invited the inference of a third victim. The accoThe LexisNexis clause and its attribution were removed entirely rather than disambiguated, and the entry now states that Framework and Tally are the only confir
F9
surface-contradiction
The entry carried only one side of the cited recommendation block: the same source says the two endpoint flaws the entry leads on seem to be fixed in the newest version, and the disclosure timeline reBoth facts added to the Defender takeaway with citations, alongside the unchanged point that no published build number maps to a fixed flaw.
F10
missed-angle
Missed in-window angle: N-able N-central Hotfix 2 (build 2026.3.1.10) is required even for instances that applied Hotfix 1, which this pipeline's earlier entries named as the fix, and the attackers rePublished as a new update_of entry against 2026-08-05/n-able-n-central-post-exploitation-rmm-tunnel-driver, from the vendor status page and in-window reporting,
F10
missed-angle
Head Mare trojanizing TrueConf client installers had no recorded disposition anywhere in the run.Recorded as a borderline-drop with its constituency-relevance reasoning and its transferable mechanic named, per the coverage-notes audit trail.
F11
editorial-advisory
Advisory: the entry located the injection point in the password-reset endpoint more firmly than either cited source does.Accepted and softened. The title, summary and body now say the sources do not locate the injection point, while keeping the vendor's workaround and its publishe
F11
editorial-advisory
Advisory: pipeline-internal vocabulary (sub-agent designators) in the run-record notes.Not applied, on the verifier's own reasoning: the same style runs through the recent run records, so a unilateral change here would create inconsistency rather

Iteration #? NEEDS_FIXES cap-breach · 4 findings (truth=1, editorial=1, advisory=2) · Claude Sonnet 5 · 11m 28s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F15
?
The registry record this run created for the Metabase incident still carried the LexisNexis clause the entry had just removed as a name-collision risk, and that summary renders verbatim on the public Clause removed from the registry summary, which now ends the same way the entry does: Framework and Tally confirmed, no other organisation reported.
F16
?
Argued that priority should be critical with an immediate_action block, on the store's own precedent: every sampled critical entry shares this shape (unauthenticated, CVSS ~10, confirmed exploitation,Considered and declined, with reasons recorded in the coverage notes. The critical bar requires every one of its elements, and the first — newly disclosed or ne
F11
editorial-advisory
Advisory: the run record justified the TeamDavid out-of-window inclusion at length but said nothing about the Metabase sources, which sit further outside the same window — an asymmetric disclosure staAccepted. The entry's sourcing note now states the developing-window basis for its inclusion explicitly.
F11
editorial-advisory
Advisory: sectors[] left empty although the body argues DACH public-sector relevance as the sharpest reading.Accepted. sectors set to [public-sector].

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-09T0412Z-intel · Claude Opus 5 · window 26 h · 4 entries published

Verification & coverage notes

A quiet weekend window. The gap to the previous fire was 24 h, giving a 26 h window that covers Saturday 2026-08-08 and the small hours of Sunday 2026-08-09. Every national authority in the essential floor — the CISA KEV catalog and advisory feeds, ENISA EUVD, NCSC-NL, BSI CERT-Bund, ANSSI/CERT-FR, CERT-EU, CERT-PL, NCSC-CH, NCSC-UK, CERT.at — was fetched and confirmed to have published nothing after Friday 2026-08-07. That is normal business-day cadence, not a coverage failure, and the KEV catalog has added nothing since Progress Kemp LoadMaster on 2026-08-07, which the previous run already covered. Four entries publish — three new findings and one update, the last of them recovered by the verification pass rather than by the research sweep.

Out-of-window inclusion, stated openly. The TeamDavid entry was published on 2026-08-07 and therefore sits roughly a day outside this run's window. It is included as first coverage anyway, and the reason is a defect in this pipeline rather than a judgement about the item: the InfoGuard Labs source record carried a listing-extraction fault that hid every publication date on that site, so no previous run could ever have seen it. The research sub-agent found and fixed the feed recipe during this fire and flagged the disclosure explicitly rather than letting it disappear behind the recency rule. Dropping it would have left a silent blind spot on roughly 12,000 internet-facing instances of a collaboration suite sold specifically to German-speaking organisations that want to avoid a hyperscale cloud — which is the home region and, for many public bodies, the estate itself. The entry carries event_date: 2026-08-07 and a sourcing note stating the lag, so no reader is misled about freshness.

A name collision, caught late, that would have manufactured a third victim. One research agent reported LexisNexis as a third confirmed Metabase data-theft victim; another traced the same thread to an unrelated earlier breach and dropped it. A re-read of BleepingComputer supported neither: it reports LexisNexis warning customers about a cyberattack at a third-party vendor affecting its Diligence, Metabase API and Newsdesk services, without stating a link to the Metabase flaw and without establishing whether customer data was exposed. The first draft of the entry carried that as a carefully hedged clause. Verification then established the fact that changes the disposition entirely: LexisNexis's "Metabase API" is LexisNexis's own news-aggregation product, which shares nothing with Metabase the business-intelligence platform except the word, and the two sibling services named alongside it in the same sentence are LexisNexis products too. Even hedged, the clause invited a reader to infer a third compromised Metabase instance from what is a coincidence of naming. It has been removed rather than disambiguated, and the entry now names Framework and Tally as the only confirmed victims. The source sentence is also self-contradictory on its face — it says the company did not specifically state a link to the Metabase API and then that it did say its Metabase API was impacted — so the original entry's "BleepingComputer is explicit that…" attribution claimed more than the sentence can carry, and is gone with it.

Sourcing corrections made during composition. The Metabase GitHub security advisory is quoted second-hand through BleepingComputer rather than cited directly: GHSA-vwf4-m7j8-wcjf is absent from OSV and github.com is not reachable from this environment, so the advisory page was never fetched and is not listed in sources[]. The CVSS 10.0 rating and the active-exploitation wording rest on BleepingComputer's reproduction of it, which the entry states. For the TeamDavid entry, the discloser groups several CVE identifiers under single headings without saying which identifier names which flaw; pairing them by position would have been a guess, so every identifier, base score, per-flaw mapping and the affected bound were read from the individual published CVE records instead. Those records are the same researchers' findings with a second publisher, not an independent assessment, so the entry is marked single-source and its credibility stays at 2 rather than being lifted to 1 by republication. One internal inconsistency is disclosed in the entry: the record for CVE-2026-54211 describes an authenticated attacker while its own CVSS vector carries PR:N, and the entry follows the description, which agrees with the discloser.

One verification finding was considered and declined. The second verification pass argued the Metabase entry should be critical with an immediate-action block, on the strength of this store's own precedent: the criticals it sampled all share the same shape — unauthenticated, CVSS around 10, confirmed exploitation, patch available. The argument is a good one and the precedent is real, but the bar for that priority requires every one of its elements to hold, and the first does not: the flaw was disclosed on 2026-08-06, outside this run's window, and this entry is late first coverage carried under the developing-window allowance rather than a fresh disclosure or a fresh weaponisation. Where the remaining doubt sits — is the action time-critical to the hour or the day, three days after a fix shipped and with no reporting of ongoing mass exploitation — the rule resolves it downward, not upward. It stays high. The disagreement is recorded here rather than resolved silently, because the next audit should be able to see that the question was asked and on what grounds it was answered.

The CERT Polska deep dive is single-source under the national-CERT carve-out — the national CSIRT reporting its own forensic investigation in its own jurisdiction. Its report makes no actor attribution, and the entry says so rather than importing the contested cluster labelling attached to the wider December 2025 campaign from the pipeline's earlier coverage. The report PDF could not be read usefully by local text extraction, which silently truncated sentences mid-clause; the reader transport returned it intact, and every quote was checked as a literal substring of the fetched text before the entry was written.

  • borderline-drop: MSI Radix AXE6600 Wi-Fi router command-injection CVEs (CVE-2026-71990 / -71991 / -71992 / -71993, EUVD-listed 2026-08-08/09 at CVSS 9.3) — consumer and gaming SOHO networking hardware sits outside the critical-infrastructure, government and public-sector asset profile, and no exploitation is reported that would override that.
  • out-of-window: Retelit SpA compromise claimed by Qilin (IrpiMedia investigation) — underlying compromise early June 2026, leak-site claim 2026-07-11, investigative article 2026-08-04; outside even the 72 h developing window, with no fresher development found.
  • borderline-drop: Head Mare trojanizing TrueConf client installers (Kaspersky, reported 2026-08-08) — unauthenticated access to TrueConf Server over a port open by default, ending with the legitimate client installer on the server replaced by a backdoored build served to participants as an update. Dropped on constituency relevance: the reported victimology is Russian organisations and TrueConf has effectively no footprint in Swiss or EU government estates. The transferable mechanic is named here rather than lost, because it generalises past the product: an organisation that does not run the compromised conferencing server can still be infected by joining a compromised counterparty's server and accepting its installer.
  • No delta: Phoenix Contact CHARX SEC-3xxx firmware 1.9.1, checked deliberately because the vendor committed to shipping it no later than 2026-08-12. Still unreleased, advisory unchanged since 2026-07-30. Worth re-checking before the deadline.
  • Not carried: InfoGuard Labs' TeamDavid disclosure was initially dropped by the research sub-agent on the recency gate and restored by the completeness sweep. See the note above.
  • Coverage gaps: ssd-disclosure (robot-challenge interstitial on both transports — regression from 2026-08-08); prodaft (fifth stale run; dead subdomain in the source note now corrected); csirt-acn-it (listing returned no date-bearing rows); technadu (JS-rendered homepage, no dated listing); sans-newsbites (no August issue indexed yet); cisa-news (feed items carry no dates); paradigm-shift-research (SPA shell, no server-rendered listing); siemens-productcert-csaf (directory index 403s as documented — the per-advisory recipe works but no Siemens advisory surfaced this run to exercise it); trellix (index stale since April–May 2026); flatt-security (genuinely monthly cadence, newest item 2026-06-01); claroty-team82 (listing carries no dates; both plausibly-recent titles drilled and dated June 2026).
  • Essential-coverage: no misses. All 15 active essential sources were attempted across the S1 and S2 slices.

No watchlists are configured for this deployment, so the product and supplier sweeps are no-ops and no Watchlist: line is reported. No closed-source drops were present under intel/, so no intake ran.

← Operations dashboard · run-record contract: docs/pipeline.md