ctipilot.ch

2026-08-11T0411Z-intel

One pipeline fire, in full · intel run of 2026-08-11 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-11/2026-08-11T0411Z-intel.md.

Run telemetry

2026-08-11T0411Z-intel intel prompt v3.31 publish ok
36m 58s duration 4 published 1 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
15m 11s
Tool calls
12 WebFetch9 WebSearch22 bridge
Cited sources
4 of 19 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
16m 43s
Tool calls
9 WebFetch14 WebSearch22 bridge
Cited sources
0 of 18 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
15m 21s
Tool calls
34 WebFetch17 WebSearch9 bridge
Cited sources
1 of 13 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
13m 59s
Tool calls
24 WebFetch19 WebSearch19 bridge
Cited sources
1 of 11 in slice
B1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
8m 55s
Tool calls
9 WebFetch15 WebSearch8 bridge
Cited sources
5 of 15 in slice

Verification

#? NEEDS_FIXES · Opus 5 · t=4 e=0 a=2 #? NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=2 #? NEEDS_FIXES · Opus 5 · t=1 e=1 a=2

Deep dive

2026-08-11/gunra-raas-fortios-mfa-backdoor-linux-prng-recoverable

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 fetch_method bridge -> rss; rss_url pinned; last_successful_fetch bumped; failure counters reset · 1 consecutive_quiet_periods incremented; note escalated; NOT demoted · 1 recipe note corrected · 1 recipe-drift note extended with two concrete next recipes; NOT demoted · 1 note added on the undated listing; NOT demoted.

SourceChangeFrom → ToReason
technadufetch_method bridge -> rss; rss_url pinned; last_successful_fetch bumped; failure counters reset— → —The health sweep flagged needs-demote. Root cause is the pinned homepage, which now returns a near-empty placeholder body (the reader renders literally 'test') — the discovery surface, not the publisher. The WordPress feed fetches direct with dated, drillable items. Standing repair order discharged in-run; the UNSOLVED list is empty on the re-probe.
prodaftconsecutive_quiet_periods incremented; note escalated; NOT demoted— → —Seventh consecutive run against a frozen client-rendered snapshot with no dates. Recorded that the pinned URL can no longer establish recency at all, so the next audit has a decision to make rather than an eighth identical log line.
ssd-disclosurerecipe note corrected— → —The 2026-08-10 note recorded the transport polarity for article pages; this run establishes the complementary fact that neither transport reaches the listing page, which is what actually blocks discovery.
chrome-releasesrecipe-drift note extended with two concrete next recipes; NOT demoted— → —Second consecutive zero-item fetch from a live source — the previous note recorded the defect, this one records what to try next so the third run does not re-derive it.
mysites-gurunote added on the undated listing; NOT demoted— → —Two independent passes could not establish in-window status for any listed item; recording it prevents a future run from including speculatively.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
prodafthttps://www.prodaft.com/reportsbridge:urlbridge:jina200 stale-cache
Seventh consecutive run without a contribution, independently re-confirmed by two separate passes. The pinned reports page returns 200 as a client-rendered shel
Quiet-period counter incremented and the note updated with an explicit escalation: the pinned URL can no longer establish recency at all, so the next audit shou
ssd-disclosurehttps://ssd-disclosure.com/bridge:urlbridge:jina202 blocked
The listing page returned a Cloudflare-style robot-challenge interstitial to BOTH the direct transport and the reader, on two independent passes. This inverts t
Recipe note corrected to record the listing-versus-article-page asymmetry and to name the next thing to try (a feed or sitemap path for discovery). A challenge
chrome-releaseshttps://chromereleases.googleblog.com/feeds/posts/defaultbridge:feedbridge:url200 recipe-drift
Second consecutive run in which the feed subcommand returns zero items from a live source; a direct GET of the listing returns the Blogger shell with no posts i
Note extended with two concrete next recipes to try (the explicit RSS alias on the feed path, or a dated archive path). Not demoted — an extraction defect, not
mysites-guruhttps://mysites.guru/blog/bridge:jina200 recipe-drift
The reader returns the CMS-extension vulnerability post listing but with no per-item publication dates, so in-window status could not be established for any lis
Items excluded on recency-uncertainty rather than included speculatively, and the note records that a dated feed path is the open recipe question. Not demoted.
siemens-productcert-csafhttps://cert-portal.siemens.com/productcert/csaf/bridge:urlbridge:jina403 blocked
The CSAF directory and its discovery files 403 every transport including the reader, consistent with the standing 2026-08-02 note.
No change — this is already-documented, non-actionable host behaviour rather than new information, and a 403 never demotes. Left as a known limitation rather th

Bridge invocations (this run)

4 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

4 other
  • bridge:url ×1
  • bridge:feed ×1
  • bridge:sitemap ×1
  • bridge:jina ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? NEEDS_FIXES · 6 findings (truth=4, editorial=0, advisory=2) · Claude Opus 5 · 12m 45s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
CEVA's ownership by CMA CGM and the European scoping of the affected Steam buyers were both cited to a source containing neither; both facts belong to the co-cited Dutch trade report.Both clauses re-cited to the source that carries them. The ownership fact now reads as the Dutch report states it (part of the group since 2019), and the Steam-
F3
claim-not-supported
An early-May 2026 break-in date for the data offered on a criminal forum was attributed to a source carrying no such date; none of the entry's three sources carries it.The date was dropped from the body and the sourcing note. The provenance dispute is retained in the form the cited source actually supports — data attributed to
F4
hallucinated-fact
The frontmatter summary placed six named companies inside the set of ten organisations that filed with the Dutch authority; no source identifies any filer, and only one of the six confirms its own filSummary rewritten to separate the two facts: the regulator has received ten reports, and the named parties are those whose customers' shipping data was affected
F14
?
An uncited count — that two affected organisations' notices did not name CEVA — which no source characterises and which the entry's own primary contradicts, since that notice names CEVA explicitly.Replaced with the sourced version: early customer-facing notices from affected retailers referred to a security incident at an external logistics partner rather
F16
?
Advisory. The frontmatter summary fused two separate statements — an exposure count across hosted bare-metal providers, and a note that some of those providers had not yet updated their base images — Fixed rather than left, per the zero-warning discipline: the summary now states the count and the stale-base-image observation as the two separate findings they
F16
?
Advisory, and a recurrence in this store: pipeline-internal vocabulary in the published run-record notes, against the rule that workflow-internal language never appears in reader-facing text.All four occurrences rewritten in plain language ('a scoped follow-up sweep', 'research strand', 'three independent passes'). Only the structural frontmatter ke

Iteration #? NEEDS_FIXES · 3 findings (truth=1, editorial=0, advisory=2) · Claude Sonnet 5 · 9m 31s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Both CVE records carried a `cisa-kev` status that neither cited source states for those identifiers; the advisory's only catalogue-adjacent text is generic remediation boilerplate and a footer navigat`cisa-kev` removed from both CVE status arrays. The `exploited` status stays — the advisory does state the FBI observed exploitation of both flaws as this actor
F16
?
Advisory. The entry's own 'most impactful' finding — the native host loading an attacker-named library from a relative path — had no corresponding technique id in the mapping.Fixed rather than left: T1129 added, which the body already describes in prose. The mapping now covers all three disclosed flaws rather than two.
F16
?
Advisory, and the same vocabulary defect class the first iteration fixed in the notes body — a fifth instance survived in a structured reason field that the public operations dashboard also renders veFixed: that field and three sibling occurrences in the failure records rewritten in plain language. The internal term now survives only in the structural frontm

Iteration #? NEEDS_FIXES cap-breach · 4 findings (truth=1, editorial=1, advisory=2) · Claude Opus 5 · 16m 33s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
A trailing citation claimed two clauses, but only the second — the spokesperson declining questions — is carried by the cited outlet; the statement that the compromised company has published nothing iSentence split. The no-public-reaction clause now carries the Dutch report's citation and the spokesperson clause keeps its own; this was the same adjacency def
F5
missing-citation
The exposure figure carried in the headline and summary had no inline link in the body; the nearest citation belonged to the following sentence and carries a different figure for a different populatioThe originating source's citation added to that sentence. The figure was correct throughout — this was a missing link against the entry's own citation-per-claus
F16
?
Advisory, no change requested: a third independent reader weighed the dropped home-region government item and judged the drop defensible on this audience's technical gate, while recording that it is tLeft as decided, and recorded here so the operator can see three readers weighed it rather than one.
F16
?
Advisory. The borderline-drops list named two of the four unconfirmed extortion-site listings the sweep dropped, omitting one against a Spanish hospital group — a sector on this deployment's profile —Fixed rather than left: both are now named with their shared drop reason, since a wrongly-dropped healthcare item is precisely what that list exists to make rec

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-11T0411Z-intel · Claude Opus 5 · window 26 h · 4 entries published

Verification & coverage notes

A 24-hour gap to the previous fire, so a 26-hour window and a standard-window disposition. Four entries cleared the inclusion gate, one of them an update. The window was genuinely thin on new signal — the previous fire published eighteen entries while draining a fifteen-row backlog, and much of the Black Hat and DEF CON output it absorbed is now settled ground — so this run's work was as much about confirming that nothing relevant was left behind as about what it published. A scoped follow-up sweep was run specifically to test that, and it came back with two clean negatives and one substantive correction.

Verification outcome. Three passes, alternating models, each of which found something the previous one had not, and every finding remediated before commit. The first found four sourcing-attribution defects concentrated in a single entry. The second, on the other model, confirmed those fixes held and then caught a defect of a different shape entirely: a catalogue-listing status flag on two vulnerability records that no cited source asserts — true in the world, but recalled rather than read, and invisible to a pass reading for narrative plausibility because no sentence in the entry depended on it. The third verified both remediations left no orphaned claims and reduced to two citation-placement findings, both fixed. The run publishes on the low-residual early exit: the final verdict carries two findings, neither a broken link nor an invented fact, and both were repaired before this commit. Residual count is recorded as two rather than zero, which is the honest reading of a final pass that still had findings.

Contradiction: macOS Screen Sharing, CVE-2026-65400 root cause. Huntress attributes the CVE to the Secure Remote Password frame-length validator returning a stale success status. Calif assigns that same stale-return mechanism to a separate pre-authentication bug that Apple closed silently on 2026-07-27 with no CVE, and describes CVE-2026-65400 as a distinct state-machine desync whose details it is deliberately withholding. The entry reports both attributions and adopts neither, and carries verification: contradicted for that reason. Both sources agree on everything that drives action — pre-authentication, the daemon runs as root, working exploits exist, and 26.6.1 / 15.7.9 / 14.8.9 is the fix — so the remediation is unaffected. The disagreement is worth surfacing rather than smoothing over: a reader who saw only the first account would believe the mechanism behind the flaw patched this month is already public.

Contradiction: CEVA Logistics, data provenance. Dutch reporting relays a claim that a dataset of retail customer records offered for sale on a criminal forum came from a CEVA break-in in early May 2026; CEVA maintains that dataset is old data from a separate 2025 incident. The entry states the dispute and adopts neither the May date nor the attribution, and does not treat the offered data as this incident's proceeds.

Mapping restraint on the CEVA entry. No source anywhere — not CEVA's statement, not the six downstream victims' notices, not the Dutch regulator — states an initial-access vector, a malware family or an actor. The follow-up sweep was sent to establish exactly that and confirmed it as a real gap in public reporting rather than a research miss. The entry therefore maps only the collection of data from the compromised order-processing systems, which its sources do state (in their own hedged terms), and maps no access vector at all. A trusted-relationship mapping was considered and rejected: the adversary reached the downstream organisations' data by compromising their processor, but never entered any downstream network, which is what that technique describes.

Borderline drops — recorded so a wrong call is recoverable:

  • borderline-drop: Liechtenstein takes its Commercial Register offline as a precaution — the only in-window Liechtenstein development is that a fifth government system joined the precautionary shutdown programme, with the government explicitly stating there are no indications of an attack on it and disclosing no new forensic detail on the original register intrusion: no actor, no vector, no exfiltration scope. It is an availability and compliance fact for downstream fiduciaries, not a decision a Tier 2/3 responder makes differently. The tracked incident stays open for a genuine forensic delta.
  • borderline-drop: two React hook packages backdoored via a compromised maintainer's GitHub credentials (CVE-2026-48159 / CVE-2026-48158) — the disclosure is fresh (2026-08-10) but the incident is not: the malicious commits were force-pushed away in May 2026 after roughly 23 hours, the packages never reached the npm registry, and the residual exposure is confined to anyone still pinning a direct commit reference to two specific packages. The technique class — maintainer workstation compromise to push credentials to install-hook execution — is already covered in depth by this store's coverage of the current npm wave. Sourcing is also two advisories by the same maintainer, i.e. one assessor.
  • borderline-drop: ClamAV denial-of-service fixes (CVE-2026-20337 / CVE-2026-20338) — surfaced by the Italian CSIRT and CERT-FR the same day, rated below their top severity, no exploitation. A routine patch-cycle item that does not demand action beyond it.
  • borderline-drop: Elixi International SA (Chiasso, Switzerland) — a Space Bears leak-site listing with a strong home-region and healthcare-supply-chain nexus, which is why it was chased twice. The company's own site carries no notice, Ticino and wider Swiss press carry nothing, and the national authority's recent publications do not mention it; the only corroboration is dark-web-monitoring aggregators restating the listing. Unconfirmed extortion claims do not ship. Flagged for the next fire in case victim confirmation lands.
  • borderline-drop: Université Libre de Bruxelles — a Qilin listing against a Belgian public university. The university's own channels and IT status page are silent, Belgian press coverage found is from an unrelated 2020 incident, and the Belgian centre publishes only a generic actor profile. Same disposition, same follow-up flag.
  • borderline-drop: Quironsalud (Spain) and Statista (Germany) — two further extortion-site listings from the same sweep, both dropped on the same basis as the two above: no victim statement and no high-reliability reporting found. Recorded here rather than only in the research return because the first is a hospital group, i.e. one of this deployment's additional sectors, and a wrongly-dropped healthcare item is exactly what this list exists to make recoverable. All four listings are flagged for the next fire in case confirmation lands.
  • borderline-drop: Gagny (France) municipal breach and an unconfirmed claim against a French vocational-training agency — the first pre-dates even the developing-story window and was recycled by a tracker with no new fact; the second is an actor claim the reporting outlet itself records as unconfirmed by the named organisation.

Coverage backlog. One row was open (an AI-generated-patch study retained by the previous fire as possible supporting material). Re-assessed against today's facts: it remains a statistic about AI-assisted remediation practice rather than tradecraft a responder acts on, and this store already carries a concrete instance of the same lesson. Left open rather than struck — it has been queued for one day, and its stated purpose is to be available to a future entry on AI-assisted remediation. It will be published or struck with a reason well inside the thirty-day limit the backlog sets.

Completeness check. The research return was unusually thin — one research strand returned a single item, and it duplicated another strand's find — so a scoped follow-up sweep re-checked for any substantive technical publication dated 2026-08-10 or 2026-08-11 that the earlier passes had missed, biased toward incident-response case studies, operational-technology research and identity-infrastructure tradecraft. It found none, and rejected the near-misses for stated reasons (a general-awareness piece with no original technical content; several items dated outside the window; publishers already covered this fortnight). Three independent passes converging on the same negative is the basis for reporting this as a genuinely quiet window rather than an incomplete one.

Coverage gaps: prodaft (seventh run against a frozen undated snapshot — recency unestablishable, escalated on the record); ssd-disclosure (listing page challenge-blocked on both transports, so no discovery entry point); chrome-releases (feed extraction returns zero items from a live source, second consecutive run); mysites-guru (listing renders without publication dates); siemens-productcert-csaf (standing 403 across all transports); paradigm-shift-research (single-page-application shell with no listing path); sans-newsbites (semiweekly cadence, last issue outside the window); the Ajax and Ace & Tate customer notices were not fetched first-hand and are described only from Dutch trade-press summaries; the original broadcaster report behind the disputed CEVA data-provenance claim sits behind a consent gate and was corroborated through two secondary quotations instead of its own page.

Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0 — no watchlists are configured for this deployment, so both sweeps are no-ops and the general coverage rules applied unchanged.

Essential-coverage: all fifteen essential sources attempted; none missed.

Source health: the sweep flagged one source for demotion. It was repaired in-run rather than deferred — the failing probe was a publisher homepage that now returns a placeholder body, while the publisher's feed fetches directly with dated, drillable items, so the record was switched to the feed. The re-probe returns an empty unsolved list across all 181 sources.

← Operations dashboard · run-record contract: docs/pipeline.md