ctipilot.ch

2026-08-10T0411Z-intel

One pipeline fire, in full · intel run of 2026-08-10 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-10/2026-08-10T0411Z-intel.md.

Run telemetry

2026-08-10T0411Z-intel intel prompt v3.31 publish ok
51m 43s duration 18 published 5 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
10m 22s
Tool calls
6 WebFetch6 WebSearch28 bridge
Cited sources
0 of 26 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
9m 08s
Tool calls
4 WebFetch14 WebSearch20 bridge
Cited sources
0 of 17 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
10m 24s
Tool calls
18 WebFetch12 WebSearch22 bridge
Cited sources
0 of 26 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
14m 47s
Tool calls
14 WebFetch22 WebSearch20 bridge
Cited sources
0 of 20 in slice
B1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
22m 19s
Tool calls
0 WebFetch6 WebSearch28 bridge
Cited sources
5 of 6 in slice
B2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
6
Duration
21m 27s
Tool calls
8 WebFetch7 WebSearch11 bridge
Cited sources
5 of 5 in slice
B3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
18m 30s
Tool calls
12 WebFetch5 WebSearch14 bridge
Cited sources
10 of 12 in slice
B4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
27m 33s
Tool calls
4 WebFetch4 WebSearch24 bridge
Cited sources
9 of 11 in slice

Verification

#? NEEDS_FIXES · Opus 5 · t=12 e=9 a=0 #? NEEDS_FIXES · Sonnet 5 · t=1 e=1 a=0 #? NEEDS_FIXES · Opus 5 · t=4 e=2 a=2 #? NEEDS_FIXES · Sonnet 5 · t=5 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=3 e=1 a=3

Deep dive

2026-08-10/freebsd-ctl-ha-three-preauth-kernel-rce-primitives-port-999

Entries published (this run)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 status candidate -> active · 1 added as candidate · 1 last_successful_fetch bumped to 2026-08-10, failure counters reset, recipe note corrected · 1 recipe note added · 1 recipe-drift note added; NOT demoted · 1 consecutive_quiet_periods incremented; NOT demoted.

SourceChangeFrom → ToReason
ec-digital-strategy-newsroomstatus candidate -> active— → —The state digest counted 5 distinct contributing runs, past the 3-run promotion bar. Promoted from the counted evidence rather than by eyeball, per the allocation rule.
novee-securityadded as candidate— → —One new candidate this run. Original technical research: its Black Hat USA 2026 write-up root-caused three coding-agent CI harness trust-boundary failures across three vendors, one previously undocumented and carrying no CVE, each reproduced against the vendor's own public repository.
ssd-disclosurelast_successful_fetch bumped to 2026-08-10, failure counters reset, recipe note corrected— → —Recovered this run. The transport polarity was recorded backwards before: per-article advisory bodies fetch cleanly on the direct transport, and it is the reader path that returns the robot-challenge interstitial.
github-advisoryrecipe note added— → —Empirical finding that decides CVE-id provenance on GHSA pages — the markdown render drops the sidebar where the CVE ID lives, so the HTML variant is required whenever a GHSA page is the per-CVE authority.
chrome-releasesrecipe-drift note added; NOT demoted— → —Feed subcommand returned zero items on a live source.
prodaftconsecutive_quiet_periods incremented; NOT demoted— → —Sixth run with no contribution against a frozen client-rendered snapshot.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
prodafthttps://www.prodaft.com/reportsbridge:urlbridge:jina200 stale-cache
Sixth consecutive run without a contribution, independently re-confirmed by S1, S2 and S3. The page returns 200 as a client-side-rendered shell serving the same
Quiet-period counter incremented and the note updated. Deliberately not demoted: transport is healthy and a stale upstream cache is not evidence the source stop
chrome-releaseshttps://chromereleases.googleblog.com/bridge:feed200 recipe-drift
The feed subcommand returned zero items for S1 despite the source being live — a listing-extraction defect rather than a transport block.
Recorded against the source record for a recipe pass. Not demoted; the content axis is unaffected and no Chrome release fell in this window through any other ro
git-kernel-org
covered via alternate · should NOT be in this list
https://git.kernel.org/bridge:urlbridge:jina403 blocked
An anti-bot interstitial refused every transport tried by B4, including the reader, when fetching the upstream fix commit for the Linux bridge STP use-after-fre
Recovered through a source-code mirror of the same commit, which is cited in the entry instead. A 403 is a transport block and never a demotion trigger.

Bridge invocations (this run)

7 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

7 other
  • bridge:url ×4
  • bridge:jina-html ×1
  • bridge:osv ×1
  • bridge:api ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? NEEDS_FIXES · 21 findings (truth=12, editorial=9, advisory=0) · Claude Opus 5 · 25m 37s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
CVE-2026-54316 was bound to the quote-stripping validator and the read-only path exemption; the owning advisory assigns it to the pre-approved bare hostname in the fetch-tool allowlist. The two more iEntry rewritten. The identifier is now bound to the allowlist-scoping round with the advisory quoted for it, the other two rounds are stated to carry no CVE, an
F3
claim-not-supported
CVE-2026-12537 was attributed to Google's advisory record, whose CVE field reads 'No known CVE'; the alias and the affected ranges live in the OSV record instead.The OSV record replaced the Google advisory as the cited source for that identifier and its version ranges, and the sourcing note states where the mapping actua
F3
claim-not-supported
The entry said the first compromised host was not running endpoint protection; Sophos states Patient Zero WAS a Defender-managed endpoint, and the unprotected-endpoint observation is about the estate Clause corrected to the estate-level statement Sophos actually makes, and the host is now described as Defender-managed.
F3
claim-not-supported
Body and action item told readers patching closes the Linux hijack path; the researcher states the Linux change 'is not a complete fix but does increase attack complexity'.Reframed throughout as a partial mitigation, the researcher's sentence added as evidence, the CVE status changed to mitigation-only, and the action item rewritt
F3
claim-not-supported
Attribution inverted: the claim that the proof of concept can cover the whole ephemeral port range in seconds is the researcher's rebuttal, whereas Microsoft cited ephemeral-port dependence as a mitigRe-attributed to the researcher and framed explicitly as a rebuttal of Microsoft's rating rather than a vendor statement.
F3
claim-not-supported
The outlet's 'we guess' quote was cited inline to Sekurak but appears only in Niebezpiecznik, contradicting the entry's own evidence record.Inline citation re-pointed to Niebezpiecznik, matching the evidence block.
F3
claim-not-supported
The br_topology_change_detection sentence was attributed to the SSD advisory; it is the upstream commit message, and the advisory never mentions that function.Evidence publisher changed to the Linux kernel, the body reworded to 'The upstream fix commit identifies', and the commit cited at that clause.
F3
claim-not-supported
The commit source was dated 2026-08-05; it was authored 2026-06-29 and committed 2026-06-30 — 36 days late.Source date corrected to 2026-06-30, and the six-week lead over the advisory added to the body and takeaway because it materially changes the backport question
F3
claim-not-supported
The March 2017 provenance was cited to the researcher's post, which contains no occurrence of 2017; the supporting fact is the manpage date line in the FreeBSD commit diff.Clause re-cited to the FreeBSD commit and reworded to describe the manpage date line the diff actually changes.
F4
hallucinated-fact
CVE-2026-45798's affected range was widened to >= 4.0.0; its own advisory records >= 4.5.0 and states the reachability path was not separately verified for the 4.x line.Range corrected to >= 4.5.0, the blanket summary sentence replaced with per-flaw ranges, and the advisory's own caution about 4.x reachability added to the sour
F4
hallucinated-fact
The sourcing note claimed no CVSS was available for CVE-2026-56181; Microsoft's own record supplies 8.3, from the same structured API this run's telemetry says it used.CVSS 8.3 populated from Microsoft's record, the score and its Moderate rating stated in the body, and the sourcing note corrected.
F4
hallucinated-fact
Run record said 12 entries carry no action items; the true count is 10 of 17 (later 11 of 17 after a duplicate action was dropped).Corrected to 6 action items across 17 entries with 11 carrying none, recomputed from the files.
F5
missing-citation
The KEV listing, EPSS score and CVSS for CVE-2026-31431 are true but appear in neither cited source, and the KEV status is the entry's stated basis for its action item.KEV listing cited to the catalog itself (verified live, dateAdded 2026-05-01, CWE-669) and the flaw to the kernel's own CVE announcement, both added as sources;
F5
missing-citation
The entire capability and namespace precondition paragraph — which sets the entry's priority and drives its takeaway — appears in neither cited source.Paragraph rewritten to separate what the sources establish (the exploit's own privileged bridge-management steps) from what is this entry's assessment (the rout
F5
missing-citation
The vulnerability class and firmware boundary for CVE-2017-16740 are not on the Forescout page, which names the identifier and nothing more.Unsourced class and version detail removed; the entry now states only that Forescout names the CVE without describing it further.
F14
?
The source enumerates five named primitives; the entry silently merged upstream spoofing into the downstream primitive and counted four throughout.Recount to the source's five, with upstream spoofing named as its own primitive in the title, headline, summary and body.
F14
?
Said eight stable/LTS point releases in addition to mainline 7.1; the announcement lists eight fixed-in lines total, of which seven are point releases and one is mainline.Corrected to seven stable and long-term point releases plus mainline.
F14
?
Claimed the statement was reproduced by four outlets while citing three, and carried the unsourced superlative 'Poland's largest convenience-store franchise chain'.Count reduced to the three outlets actually cited and the superlative dropped to 'a Polish convenience-store franchise chain'.
F17
?
Credibility 1 is unsupported: the two primaries carry disjoint facts and corroborate nothing of each other's, as the entry's own sourcing note concedes.Credibility lowered to 2, with the reasoning added to the sourcing note, matching the convention this run applied to the single-assessor entries.
F18
?
The action item duplicates tasks already carried by both in-window predecessor entries; the delta raises urgency but does not change the task.Action item removed; the entry now carries none, and the upgrade-and-rotate guidance stays in the body where the predecessors already own it as tasks.
F10
missed-angle
Coverage gap: the run published three items dated 2026-08-05/06 as recovered coverage gaps while deferring Retelit/Qilin to the backlog — the most constituency-relevant of the four, a European telecomAccepted. A scoped follow-up research sub-agent (B5) was spawned to deep-read the primary, establish per-fact attribution and check for a company statement and

Iteration #? NEEDS_FIXES · 2 findings (truth=1, editorial=1, advisory=0) · Claude Sonnet 5 · 11m 07s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
techniques[] carried T1078 and T1486 while the body described neither behaviour — it covered the extortion claim, the disclosure timeline and the scope dispute but omitted the mechanism entirely, so bAdded a paragraph carrying the mechanism the primary actually reports — credential capture from a system administrator's workstation enabling lateral movement,
F8
needs-more-research
The primary supplied an observable attack sequence — credential theft from an administrator endpoint, lateral movement, encryption undetected until too late — and the entry reduced the incident to disThe same new paragraph now names the three telemetry classes the sequence surfaces in (credential access on administrator workstations, authentication fan-out f

Iteration #? NEEDS_FIXES · 8 findings (truth=4, editorial=2, advisory=2) · Claude Opus 5 · 13m 12s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The trade outlet was described as corroborating the leak-site listing the next day; the primary credits it as having reported the attack first, so 'corroborated' inverts the relationship.Rewritten to credit the trade blog as the first outlet to report it, quoting the primary's own phrase, and to draw the consequence the corrected order supports
F4
hallucinated-fact
A body quote ended '...would simply regenerate.' with a fabricated full stop; Group-IB writes '...regenerate from the shadowed accounts.' A milder instance in the same entry dropped '(RAM)' from a quoBoth quotes restored to their full contiguous form. This is the same defect class the run repaired earlier in the Forescout and CISA quotes, reintroduced by a l
F3
claim-not-supported
Body said the flaw was 'found by two researchers independently'; the advisory describes two independent researchers making one joint submission, which is a different claim.Reworded to 'submitted by two researchers to its TyphoonPWN 2026 competition', matching the advisory and the entry's own summary.
F4
hallucinated-fact
Run-record notes said a quiet window produced seventeen entries while the frontmatter and the rest of the notes record eighteen.Corrected to eighteen, with the backlog framing amended to note the sixteenth row opened and resolved inside this run.
F9
surface-contradiction
Retelit's claim that it promptly informed affected customers is contradicted in the same primary's 6 August update, where numerous customers report writing to ask why no communication had arrived; theBoth accounts now sit adjacent, each attributed and quoted, with the entry explicitly declining to adjudicate between them.
F8
needs-more-research
The public-administration notification path was dropped: Italy's CERT for public administration learned of the incident only on 30 July and began warning the security officers of every potentially affAdded as its own paragraph — the most directly consequential public-sector fact in the entry — with the recipients stated as recipients of a precautionary warni
F11
editorial-advisory
Advisory: the ClickFix paste-and-run step is described in both summary and body but T1204.004, active in the pinned dataset, was not mapped.T1204.004 added to techniques[] after confirming it is active at ATT&CK v19.2.
F11
editorial-advisory
Advisory: the headline still carried the market-leader superlative that iteration 1 removed from the summary, and the iteration-1 remediation note was therefore inaccurate about its own scope.Superlative removed from the headline so it matches the summary, and the iteration-1 note corrected to record that the summary was fixed at iteration 1 and the

Iteration #? NEEDS_FIXES · 5 findings (truth=5, editorial=0, advisory=0) · Claude Sonnet 5 · 13m 27s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
techniques[] carried T1036.005 — correctly substituted for the source's stale T1564.013 — but the body never described the process-masquerading behaviour that id maps to.Rather than drop a valid mapping, the behaviour was added to the body from the source: Group-IB records that the malware masquerades its process name via a cust
F4
hallucinated-fact
The frontmatter evidence record for the persistence quote was still truncated at '...regenerate from' after the body copy of the same quote was repaired at iteration 3 — frontmatter and body disagreedFrontmatter record completed to the full contiguous sentence so both now match the source.
F4
hallucinated-fact
Two evidence quotes carried backticks around code spans that are not present at those positions in the cited advisory text — cosmetic, with no change of meaning, but not verbatim.Backticks removed from both. Re-verification against the authoritative HTML capture surfaced a third instance in the same entry, which was removed as well; the
F3
claim-not-supported
Described the warned organisations as including 'two regional digital-service providers'; one of them is national rather than regional.Reworded to distinguish the regional digital-service agency from the national digital-services company owned by the Italian chambers of commerce.
F4
hallucinated-fact
Run-record notes dated all three recovered coverage gaps to 2026-08-06; two of the three are 2026-08-05.Corrected in both places the dates appear: NatJack 2026-08-06, the coding-agent CI research and the Linux bridge use-after-free 2026-08-05.

Iteration #? NEEDS_FIXES cap-breach · 5 findings (truth=3, editorial=1, advisory=3) · Claude Opus 5 · 14m 11s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F1
broken-url
BLOCKING. The evidence record and body sentence attributed to Anthropic's GitHub advisory quoted wording that appears on NVD, not on that advisory — a live fetch of the advisory contains neither 'agenThe advisory was re-fetched and both the evidence record and the body now carry its own Description verbatim, with the affected range and fix version stated as
F3
claim-not-supported
'Thirteen seconds after that' misread Sophos's absolute timeline offsets: the clipboard read is at five seconds and the paste at thirteen, so the interval is eight seconds, not thirteen.Reworded to give both the interval and the absolute offset, matching the source's own timeline.
F3
claim-not-supported
The iteration-4 correction re-broke the same clause in the other direction: neither 'regional' nor 'chambers of commerce' appears in the article, which says only that the two organisations provide ItaReduced to exactly what the source states, dropping both characterisations. This clause has now been wrong twice in opposite directions, which is itself the arg
F9
surface-contradiction
'Mandiant tracks the cluster as UNC5537' appears in neither cited source — both the DOJ release and the Krebs report contain zero occurrences of either name.Removed from the summary and body. The cluster designation survives only where it is legitimate — as the registry entity key and in the registry record, which c
F12
single-source-flag-missing
Advisory, not changed: the WordPress XSS2Shell entry cross-references the tracked WP2Shell chain in prose without a references[] link; the run record's 'thirty-four evidence quotes' figure describes tLeft as recorded observations. The first is a rendering nicety, the second is accurate about the pass it describes, and the third is intentional — the absence o

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-10T0411Z-intel · Claude Opus 5 · window 24 h · 18 entries published

Verification & coverage notes

This run's shape: an empty discovery window and a fully drained coverage backlog. All four window sweeps (S1–S4) returned zero publishable items against a 24 h window — the previous fire was the 0110Z weekly, which stood down as a duplicate week and published nothing, so the last content-publishing fire was 2026-08-09. Every national authority in the home-region slice has been silent since Friday 2026-08-07, and this year's Black Hat and DEF CON research wave was already absorbed by the 2026-08-08 and 2026-08-09 fires. Three independent sweeps agreeing on zero is a genuine quiet weekend, not a search failure.

Everything published here therefore comes from two places: the fifteen open rows of state/coverage_backlog.md (plus a sixteenth opened and resolved inside this run), and three uncovered items this run's own completeness sweep recovered. That is why a quiet window produced eighteen entries, and it is not a volume increase — dedup guarantees a re-scan republishes only the delta, and each of these items was researched and verified by an earlier fire that could not publish it. All fifteen backlog rows are now resolved: fourteen published, one struck on relevance. The backlog file records each resolution with its publishing entry id.

Backlog framing corrected before publication — the reason the deep read is mandatory. The queue row for CVE-2026-66066 asserted that "Rapid7 confirms active exploitation". A raw-body search of both Rapid7 posts for "wild", "exploited" and "scanning" found no such claim anywhere, and Rapid7's own tracker states the opposite: it is not aware of exploitation in the wild. What actually happened is Rapid7 reproducing the chain across five Rails version lines and shipping a public Metasploit module. The entry publishes that as weaponisation and stays at high; publishing the row as written would have been a fabricated escalation inherited from a note nobody had re-checked.

Two further attribution corrections applied at composition. The Żabka entry is composed strictly on what Żabka itself confirms — a compromised external service-provider account reaching the ticketing system — with the 541,000-ticket and 89-repository scope attributed to a criminal-forum seller and the Jira-to-production mechanism attributed to the reporting outlet's own explicitly stated guess. And in the Moucka entry, the platform's name, the absence of enforced multi-factor authentication, both of Moucka's aliases and the co-conspirator's identity are all attributed to KrebsOnSecurity, because none of those words appears anywhere in the Department of Justice release, which was verified directly.

Quote fidelity: on the first pass, twenty of the then thirty-four evidence quotes failed a literal substring check (the run finished with 66 records across 18 entries, all verified). Most failures were extraction artefacts — the saved bodies are raw HTML, so tags and entities sit inside otherwise-genuine prose — and resolved once the bodies were stripped with empty-string replacement rather than whitespace. Four were real defects and were fixed against primaries re-fetched for this run: a Forescout sentence beginning "Although we cannot confirm…" had been turned into a standalone de-hedged assertion by dropping the subordinating conjunction; a second Forescout sentence was cut mid-clause with a fabricated full stop; and both CISA quotes ended in a comma inside a larger sentence rather than a period. One further "quote" was a composite of a vendor page's headline copy and was replaced with the contiguous sentence that actually exists. The Forescout and Nextgov bodies had never been saved by the sub-agent, so those eight quotes were unverifiable until the main agent re-fetched both primaries — which also surfaced a fact the relay reporting had lost: 19 of the 22 exposed controllers in attacked cities sat on the same mobile carrier network via cellular routers, a finding distinct from the 19-of-22 firmware-susceptibility figure despite sharing the ratio. The entry keeps them separate.

Item granularity and dedup. Five entries ship as update_of deltas against tracked ground rather than as new stories: the Rails weaponisation, the ikeext root cause, the Forescout census, the BINDCLOAK teardown (Part 2 of a series whose Part 1 is already published) and wp2root. The store-wide CVE index was checked for every identifier; CVE-2026-31431, CVE-2026-66066 and CVE-2026-33824 were already present and all three ship as updates accordingly, while the nine new identifiers were absent store-wide.

CVE provenance. Each of the four Wazuh identifiers was read off its own advisory record — which required forcing the HTML render, because a GHSA page's markdown variant drops the sidebar panel where the CVE ID lives — and then cross-checked against BSI's independently published list, where all four matched. This is precisely the pairing that the 2026-08-09 audit declined to publish on, and it is now resolved rather than guessed. None of the four had propagated to NVD or MITRE at composition time; that is propagation lag, and it is stated in the entry rather than papered over. For NatJack, the mapping of two CVEs to two platforms was taken from the researcher's explicit statement, not inferred by position: both identifiers name the downstream-spoofing TCP-hijack primitive, one per platform, and the other three primitives carry no identifier and therefore no vendor fix.

Absences confirmed rather than filled. Three published items carry no CVE at all, and in each case the absence was verified rather than assumed: the FreeBSD CTL HA primitives (no identifier from the project or the researchers), the Linux bridge STP use-after-free (absent from both the advisory and the fix commit), and the PHP unserialize use-after-free underlying wp2root (consistent with PHP's own position that such bugs are not treated as security issues). No identifier was invented for any of them.

  • borderline-drop: Université libre de Bruxelles Qilin leak-site listing — S4 surfaced it and recommended against publishing. Single-source from an Admiralty-C tracker, no victim statement, no Belgian federal notice, and nothing in French- or Dutch-language press despite a targeted search. A leak-site claim needs victim disclosure or high-reliability journalism before it can be stated as fact.
  • borderline-drop: Intrinsec Enterprise LLM Threat Atlas — a methodology and reference document restating widely known LLM threat categories, with a risk ranking whose basis is unquantified in the reachable text. Does not change what an already-highly-skilled responder detects, hunts or hardens. Struck from the backlog with this reason.
  • borderline-drop: 1Password Off-by-1 Labs "FLAWED" study (54% of 6,080 LLM-generated patches failed to fully remediate or introduced new bugs) — a study statistic about AI-assisted patching rather than tradecraft a responder acts on, and the pipeline has already published a concrete instance of the same lesson. Carried to the backlog rather than discarded, in case a future fire covers AI-assisted remediation practice.
  • borderline-drop: several unconfirmed single-source leak-site claims against French private-sector SMEs, associations and sports clubs, and a claimed listing against a French municipality — none clears the public-sector or critical-infrastructure relevance bar, and all fail the fake-news scrutiny bar.
  • borderline-drop: recycled Coldcard "insider" reporting dated 2026-08-09 — re-framed 2026-08-04 news with no new fact; the underlying incident is already covered.
  • out-of-window, then published: Retelit (Italy) Qilin compromise — primary dated 2026-08-04, updated 2026-08-06, outside window_hours=24. Initially deferred to the backlog; published in this run instead after verification iteration 1 flagged the inconsistency (see above). Its event_date is the confirmed incident date of 2026-06-08, which is honest about the item's age.
  • out-of-window: NatJack traces to 2026-08-06, and the Novee coding-agent CI research and the Linux bridge STP use-after-free both to 2026-08-05 — all outside both the 24 h and 72 h windows. Rather than let them fall through a second time they were treated as recovered coverage gaps: S3 verified all three were absent from both the 14-day coverage index and the entity registry, a scoped follow-up sub-agent deep-read and verified them, and they are published here with honest event_date values under the same reasoning the coverage backlog applies to verified-but-unpublished items. This is disclosed deliberately because it stretches the recency gate, and the verifier should challenge it.
  • Single-source: 2026-08-10/interlock-volatility3-winpmem-credential-theft, 2026-08-10/esxi-busybox-ash-command-obfuscation-21-techniques, 2026-08-10/pam-rootok-identity-shuffle-as-anti-forensics-xmrig and 2026-08-10/coding-agent-forensic-artefacts-opencode-codex-credentials — each a single originating research or incident-response publication with no independent second assessor. Where a vendor published two documents on the same finding, that is recorded as one assessor with two publishers and credibility stays at 2.
  • Single-source: 2026-08-10/cve-2026-33824-ikeext-double-free-root-cause-published — 0patch is neither the vendor nor a national CERT, so no carve-out applies to its root-cause analysis. Microsoft's own record corroborates the CVE, its CWE-415 classification, its CVSS, its patch date and the affected range, but not the module- and function-level detail.
  • Reduced confidence: 2026-08-10/zabka-supplier-account-jira-access-confirmed and 2026-08-10/pam-rootok-identity-shuffle-as-anti-forensics-xmrig carry confidence: medium — the first because the operationally interesting scope is unconfirmed attacker claim, the second because a single incident-response account describes an engagement no second party has reported.
  • Deep dive: 2026-08-10/freebsd-ctl-ha-three-preauth-kernel-rce-primitives-port-999, category network-stack-rce, selected on criterion 3 (substantive new technical analysis with enough public detail to act on). No deep dive had been published today. Category rotation applied: web-app-rce, the category the alternative candidate would have taken, was used on 2026-08-05 and is therefore demoted.
  • Action-item discipline: 6 action items across 18 entries, with 12 entries carrying none. Every action names a specific product, version boundary or configuration surface derived from that finding's own mechanics; none restates the body's detection guidance.
  • ATT&CK mapping: every id validated against the pinned dataset at ATT&CK v19.2 before composition. One revoked id was caught and replaced — T1070.002 is superseded by T1685.006. Group-IB's own cited T1564.013 was deliberately not carried: it resolves in the pinned dataset to "Bind Mounts", which does not describe the behaviour reported, so the source-supported mappings were used instead.
  • Retelit published within this run after the verifier challenged its deferral. The out-of-window note below was written when this run intended to defer the item to the backlog. Verification iteration 1 flagged that as inconsistent — the run was publishing three items of the same 2026-08-05 and 2026-08-06 vintage as recovered coverage gaps while deferring the one its own notes called relevant and uncovered, and the deferred item was the most constituency-relevant of the four. That criticism was accepted: a scoped follow-up sub-agent (B5) deep-read the primary, and the item published as 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector. The backlog row was therefore opened and struck inside the same run. The deep read also changed the story materially — Retelit had in fact given its own account, in a right-of-reply to the investigating outlet rather than through its own press channel, which this run confirmed carries no statement about the incident.
  • Dedup confirmation (gate warning, deliberate): 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector shares actor:qilin with a Romanian university incident of 2026-07-29 and with a W31 weekly entry. Neither is a predecessor: this is a separate victim, a separate country, a separate sector and a victim-confirmed intrusion rather than a leak-site claim. Not an update.
  • Dedup confirmation (gate warning, deliberate): 2026-08-10/esxi-busybox-ash-command-obfuscation-21-techniques shares the entity actor:akira with 2026-08-05/vbs-ruag-akira-ransom-payment-review-governance. The non-update decision is deliberate and the two share nothing but the actor key — one is a governance review of a ransom payment at a Swiss defence subsidiary, the other a catalogue of shell-obfuscation techniques in which CrowdStrike names Akira only as one of several operators that reach the hypervisor layer. Neither is a delta on the other. The entity link is kept because the prose names the group and every named actor is linked by registry key.
  • Source-URL liveness (gate warning, transient): the abbreviated upstream commit URL returned HTTP 403 to the gate's own re-check while resolving normally when fetched during the run — an anti-bot response to the checker's user agent, on a URL this run verified live and whose page title matches the cited commit.
  • Coverage gaps: prodaft (frozen client-rendered snapshot, sixth quiet run); chrome-releases (feed subcommand returned zero items on a live source — recipe drift); csirt-acn-it (listing returned no date-bearing rows); git.kernel.org (anti-bot interstitial on every transport — recovered via a source-code mirror, no coverage lost); typhoonpwn (fetched cleanly but carries no per-category privilege-level text).
  • Essential-coverage: no misses. All 11 S1 essential-tier records and all 13 S2 essential-tier records were attempted.
  • Source health: 181/181 probed in 101s, no source flagged for action; no UNSOLVED entries to repair this run.
  • Wall-clock: this run overran its own soft watchdog. It completed the publishing chain at roughly 2h55m against the ~3h guidance. The cause was scope rather than a stall: an empty discovery window turned the run into a sixteen-item backlog drain, and the verifier loop then ran five iterations because each pass kept finding real defects in a batch of eighteen entries — 21 findings, then 2, 6, 5 and 4, every one of them remediated. The final iteration's CLEAN confirmation was waived under the watchdog rather than delaying the run record, and the residual is recorded. Nothing was carried unverified: the last iteration re-checked 42 URLs live and confirmed no truth-critical defect beyond the four it reported, all of which were fixed before commit.

← Operations dashboard · run-record contract: docs/pipeline.md