ctipilot.ch

2026-08-13T0412Z-intel

One pipeline fire, in full · intel run of 2026-08-13 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-13/2026-08-13T0412Z-intel.md.

Run telemetry

2026-08-13T0412Z-intel intel prompt v3.31 publish ok
41m 16s duration 8 published 4 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
11m 00s
Tool calls
9 WebFetch5 WebSearch28 bridge
Cited sources
5 of 24 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
10m 23s
Tool calls
14 WebFetch24 WebSearch7 bridge
Cited sources
0 of 17 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
12m 18s
Tool calls
20 WebFetch15 WebSearch24 bridge
Cited sources
1 of 39 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
6
Duration
11m 31s
Tool calls
11 WebFetch8 WebSearch17 bridge
Cited sources
4 of 11 in slice

Verification

#1 NEEDS_FIXES · Opus 5 · t=4 e=3 a=1 #2 NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=0

Deep dive

2026-08-13/sharepoint-cve-2026-55040-jwt-forgery-exploited-root-cause

Entries published (this run)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

8 notes-appended · 1 added-candidate.

SourceChangeFrom → ToReason
zaufana-trzecia-stronaadded-candidate— → candidatethis run's single new candidate — broke the MyDr electronic-health-record intrusion with original first-hand investigation and unusually disciplined separation of verified fact from claimant assertion
siemens-productcert-csafnotes-appended— → per-advisory recipeindividual ssa-<id>.html pages fetch directly even while the CSAF index returns 403 — recovers a source that has been logged as a gap for several runs
databreaches-netnotes-appended— → article-body recipearticle URLs 403 raw WebFetch; feed for listing plus url bridge for bodies works
technadunotes-appended— → site-wide 401 findingrecords that the 2026-08-11 feed recipe no longer works and queues a reader re-test; explicitly not demoted
chrome-releasesnotes-appended— → feed-empty fallbackthird consecutive empty feed; dated listing page is the working fallback
ssd-disclosurenotes-appended— → Cloudflare challengeHTTP 202 robot challenge on direct and reader transports
tenable-researchnotes-appended— → recipe gapfeed parses empty and listing is a JS shell
sygnianotes-appended— → 403 regressiondiffers from the prior live-and-drillable note; reader re-test queued
group-ibnotes-appended— → working recipeRSS plus url bridge both clean this run

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
technaduhttps://www.technadu.com/feed/webfetchbridge:feedbridge:urlbridge:jina401 transport-block
site-wide HTTP 401 on the direct transport (homepage, /feed/ and /sitemap_index.xml all return a 24-byte 401); the jina reader could not adjudicate because the
none available this run — not demoted (401 is an access wall, not content death) and not marked blocked, because blocked asserts unreachability by every transpo
siemens-productcert-csaf
covered via alternate · should NOT be in this list
https://cert-portal.siemens.com/productcert/csaf/webfetchbridge:urlbridge:jina403 transport-block
S3 AccessDenied on the CSAF index and ssa-list.html across direct fetch, WebFetch and the reader
recovered — individual advisory pages at /productcert/html/ssa-<id>.html are directly fetchable even while the index 403s; SSA-834709 was read that way and the

Bridge invocations (this run)

11 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

10 ok1 other
  • url ×8
  • api ×3

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 8 findings (truth=4, editorial=3, advisory=1) · Claude Opus 5 · 16m 39s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
the '26-minute burst' in title, headline, summary and body was the leak-site tracker's own crawl cadence (records spaced 33-40 s apart), not a property of Cl0p's posting behaviour, and no source stateevery claim about a publication window removed; the entry now says only that all 44 records appear as one contiguous ingest batch bracketed by other groups' rec
F5
missing-citation
the entry's whole delta — count, timestamps, country codes, the two European victims — rested on a tracker endpoint that appeared in neither sources[] nor any inline link; separately, 'Dutch health-tethe tracker endpoint added as a sources[] record and cited inline; victims now characterised only by the tracker's own country and activity fields (healthcare,
F3
claim-not-supported
the appointment and prescription volume figures were cited to MyDr's own incident page, which carries no such figures; they come from the Polish outletthe volume clause is now a separate sentence cited to Zaufana Trzecia Strona, and the company statement carries only what it actually says
F3
claim-not-supported
'the reason the outcome was a reprimand rather than a fine' converted one weighed mitigating factor into a counterfactual penalty the ICO never mentionsreworded in both summary and body to the regulator's own strength — one of the factors it took into account in deciding to issue a reprimand
F4
hallucinated-fact
technique T1505.003 (Web Shell) named a behaviour the body never describes and neither cited source supportsremoved; T1190 remains and the mapping stays non-empty
F17
?
credibility 1 overstated the corroboration — every source traces to QUIRSO as the single assessor, with the news outlet and the Swiss advisory both reporting its findingslowered to credibility 2 and the sourcing note now states the several-publishers-one-assessor reasoning explicitly
F12
single-source-flag-missing
run-record notes described the ICO entry as single-source-national-cert, contradicting the entry itself, which ships plain single-source and expressly rejects the carve-outrun-record line corrected to single-source with the reasoning
F11
editorial-advisory
advisory — the corrections paragraph said three failed quote checks and then listed fourcorrected to four

Iteration #2 NEEDS_FIXES cap-breach · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · 7m 39s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
the replacement framing said the 44 records form one contiguous block bracketed in ingest order by other groups' records — true when the endpoint response is ordered by the tracker's own discovery timthe contiguity and bracketing claim was removed entirely rather than qualified — it was decoration, not operational content. The entry now carries only that the

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-13T0412Z-intel · Opus 5 · window 26 h · 8 entries published

Verification & coverage notes

Window: 26 h, derived from a 24.0 h gap to 2026-08-12T0411Z-intel, which published ok. Standard window class. The window's own signal was thin — the home-region domain returned nothing at all — but two tracked stories crossed exploitation thresholds and a third vendor advisory landed at the maximum score, so this run is dominated by status changes on ground the store already holds rather than by new discoveries.

Corrections applied during composition. Re-reading every primary in full before writing contradicted the research returns in several places, and the primary won each time:

  • The QUIRSO post on vCenter exploitation is dated 2026-08-10, not 2026-08-12 as returned. It therefore sits outside the 26 h window and inside the 72 h developing-story allowance; the in-window developments are The Hacker News coverage of 12 August and Switzerland's NCSC updating its own advisory the same day. The entry says so rather than implying the research is fresh today.
  • Four of the returned evidence quotes failed a literal-substring check against the fetched pages. One had a full stop where the source has a comma; one contained a non-breaking space the quote rendered as an ordinary space; one used typographic quotation marks where the Polish source uses straight ones; and a fourth used a straight apostrophe where the regulator's page uses a curly one. All four were corrected against the fetched bytes before any entry was written. The QUIRSO post additionally writes its CVE identifiers with en-dashes rather than hyphens, which silently breaks naive matching — no quote from that page is used in a form that depends on it.
  • A returned quote presented as QUIRSO's fixed-version list is a bulleted list on the page, not contiguous prose. It is not quoted; the versions are stated in the entry's own words and in the CVE record.
  • The Hacker News adds a fact the return omitted and that materially changes the picture: the scanning spike reported by Defused Cyber concerns CVE-2026-59309, a different flaw in the same advisory, and QUIRSO's co-founder states on the record that there is not enough evidence to correlate it with the intrusion set behind CVE-2026-59310. The entry keeps the two separate rather than merging them into one exploitation narrative.
  • The ICO's exposed-data list is considerably broader than the return described — National Insurance numbers, passport and driving licence details, bank account information, biometric data and criminal-offence records, for up to 10,920 people. The formal reprimand is dated 7 August and was announced on 12 August; event_date records the reprimand date. The full reprimand document is published only as a scanned PDF with no extractable text, so nothing is cited from it.
  • The MyDr return described the company as unable to notify CERT Polska's breach portal. That framing belongs to the reporting outlet's analysis of the processor/controller split, not to MyDr's statement, which says it will support its clients in reporting to the data-protection authorities and that no reports from facilities are required at present. Both are now carried at their own strength and attributed to the right party.
  • The Cl0p item as returned asserted that the 12 August listing wave is the Windchill campaign entering its publication phase. No source says that. Foresiet analysed a different, earlier batch of 42 masked listings and assesses only a possible relationship, stating explicitly that leak-site information alone cannot establish the access route for any listed organisation. The entry carries the listing wave as a verified fact about the leak site, the campaign linkage as Foresiet's hedged assessment of a different batch, and no claim that any named company was breached.

Completeness sweep. Re-reading the full research returns and the primaries surfaced one item none of the sub-agents flagged: an aside in the BleepingComputer SharePoint article recording that CISA had confirmed CVE-2026-45659 — a SharePoint deserialization flaw this pipeline covered on 2026-07-02 and which has been catalogued as exploited since 1 July — is now also being used in ransomware attacks. Checked directly against the exploited-vulnerabilities catalogue at version 2026.08.11, that record now carries "Known" in its ransomware-campaign-use field. Against a constituency with two disclosed on-premises SharePoint compromises in the preceding nine days, a change in the expected outcome of an unpatched farm is worth publishing, so it ships as its own short update rather than being folded into the deep dive — the two flaws are unrelated beyond sharing a product, and binding them together in one entry is exactly the mistake that leaves a reader attributing one CVE's facts to the other.

Deep dive. One, on CVE-2026-55040, category web-app-rce (the category was last used on 5 August, outside the demotion window; identity-infra, the nearest alternative, was used on 7 August). It earns the treatment on two counts. Yesterday's entry on the same CVE stated in its own body that it did not have Rapid7's technical analysis in hand and that behavioural detail beyond the advisories would therefore be invention — that gap is now closed, and the analysis yields a specific server-side artefact rather than generic advice. And the exploitation picture moved within a day of the proof-of-concept publishing. The entry is deliberate about what it does not do: it describes the four validation failures and the reconnaissance step in prose, and does not reproduce the forged token, the request sequence or any of the sample values the analysis prints.

Borderline drops.

  • borderline-drop: FulcrumSec's second-stage release of Novo Nordisk's internal machine-learning platform contents — a real event on a tracked incident, but the delta is what was in the dump rather than anything that changes what a responder detects, hunts or hardens. The one arguably-actionable idea it supports (inventory internal AI/ML platforms as data repositories in breach-scope planning) is generic advice rather than something this finding's mechanics produce, and the store already carries stronger coverage of the AI toolchain as a target. Single-source on the dump itself.
  • borderline-drop: ransomware disabling doors and heating at a Canadian hospital — the sub-agent proposed it as a transferable evolved technique for healthcare defenders. On reading the sourcing it does not hold: no actor, no initial-access vector, no description of what was encrypted beyond "certain facility maintenance systems", and the "attackers are pivoting to building systems" framing comes from quoted commentators speculating about motive rather than from documented tradecraft. The hardening prescriptions offered are textbook OT segmentation advice. Out-of-nexus with no verified new technique, so it fails the breach gate.
  • borderline-drop: the claimed intrusion at Santé publique France attributed to the "cybernox" handle — still a single hacktivist forum claim relayed by one outlet, still no agency confirmation, and the same claimant's previous publication was assessed by that same outlet as recycled from earlier unrelated breaches. Yesterday's run dropped this story for the same reasons; a day later nothing has been added to it. The described defect class (a server accepting a client-supplied role value without validating it) is mechanically coherent and worth hunting for regardless, but it is not a basis for publishing an unconfirmed breach.
  • Two further Swiss organisations appeared on unrelated extortion leak sites in the same 48 hours with nothing beyond a bare victim listing — no technical detail, no confirmation, no transferable lesson. Not published; noted here as a volume signal only.

Single-source items and carve-outs. Three entries ship without independent corroboration and each says why in its own sourcing note. The ICO reprimand is single-source: the regulator is publishing its own enforcement decision, so it is both primary and sole assessor, but a data-protection authority acting against a third party is not the national-CERT carve-out and the entry deliberately does not claim it. The Group-IB NFC-relay research is single-source because no second lab has written up this family; the older relay lineage that Group-IB cites as background is not treated as corroboration of the new one. The Cl0p listing wave is single-source because the listings were read from one leak-site mirror and no mainstream outlet was found reporting the named wave — its classification is the run's lowest at C3, and the entry states plainly that no named victim has confirmed anything.

Recency exceptions. Two entries rest on primaries dated 2026-08-10, inside the 72 h developing-story allowance rather than the 26 h window: the vCenter exploitation report and the Polish outlet's MyDr investigation. Both are carried because an in-window development moved them — Switzerland's NCSC flipping its advisory to actively exploited and The Hacker News adding an on-record statement in the first case, MyDr's own confirmation statement of 12 August in the second. Neither was surfaced by the preceding fire, so this is gap recovery rather than re-publication.

Coverage backlog. One row remains open in state/coverage_backlog.md: the 1Password study on machine-generated patches, carried since 2026-08-10 as a marginal drop. Put to the gate again on today's facts it still does not clear it, for the reason recorded then — it is a study statistic about assisted patching rather than tradecraft a responder acts on, and this run published nothing it could support. Left open rather than struck; it is three days old against the file's roughly thirty-day rule.

Verification outcome. Two iterations, on two different models. The first (Opus) returned four truth and three editorial findings plus one advisory, all remediated. The most consequential was a fabrication of my own making: the Cl0p entry's "26-minute burst" — carried in its title, headline, summary and body — was the leak-site tracker's own crawl cadence rather than anything Cl0p did, a distinction I had not tested before writing it. That entry also had its entire delta resting on an endpoint that appeared in no source list, volume figures on the Polish incident were attributed to the company page that does not carry them, the regulator's weighing of one mitigating factor had been inflated into a counterfactual fine, and one technique id named a behaviour no source supports. The second iteration (Sonnet) re-verified all eight remediations against their sources, confirmed them, and found one further defect in my own replacement text: the corrected Cl0p framing still claimed the listings formed a contiguous block, which holds only under one of the two orderings the cited endpoint supports. That claim was removed rather than qualified — it was decoration, and an entry whose whole point is disciplined claim boundaries should not carry a fact that flips depending on how the reader sorts the data. The run publishes on the low-residual early exit with a residual count of 1, which is that final finding rather than anything left unrepaired.

Operational finding the operator should see: the last-resort reader transport is nearly out of credit. The key pool behind tools/fetch_source.py jina reports one live key of seven, with a large negative aggregate balance; the reader returned HTTP 422 on the key and 403 anonymously on every attempt this run. Nothing published here depended on it — the direct transports and the bridge covered every primary — but it is the universal fallback for hosts that block our egress, and its loss is why one source's status could not be adjudicated today (see below). Two sources whose recipes were recovered in earlier runs by the reader would not be recoverable now.

Source-health repair. The sweep probed 182 of 182 sources and returned a single unsolved flag, technadu, which now returns HTTP 401 site-wide on the direct transport — homepage, feed and sitemap alike, so the feed recipe recorded on 11 August no longer works either. It was not demoted, because an access wall is not content death and a 401 is not the anti-bot 403 that never demotes anyway; it was also not marked unreachable-by-every-transport, because that assertion requires testing the reader and the exhausted key pool made that impossible today. The finding, the evidence and the specific re-test to run next time are recorded on the source. In the other direction the sweep produced a genuine recovery: individual Siemens advisory pages turn out to be directly fetchable even while the CSAF index and advisory list return 403, which is how this run read SSA-834709 and is now the recorded recipe for a source that has been logged as a coverage gap for several consecutive runs.

No entry reached the critical bar this run. The closest is the Siemens gateway flaw at CVSS 10.0 — unauthenticated, no interaction, maximum privileges — but nothing is reported exploited and no proof-of-concept is public, so it fails the "actively exploited right now or mass exploitation imminent" element. The vCenter flaw has confirmed compromises but the patch has been available for two weeks and the campaign's observed footprint saturated eight days ago, which is a compromise-assessment problem rather than an act-within-the-hour one. Both are high.

Coverage gaps: prodaft (rotation priority — frozen, undated listing, eighth consecutive run with no contribution); govcert-at (homepage carries no dated advisory content); inside-it-ch (403 on WebFetch and bridge); chrome-releases (rotation priority — feed empty for the third run; the dated listing page was reached and the 11 August stable release fixes five high-severity bugs with no exploitation claimed, outside the window); ssd-disclosure (rotation priority — HTTP 202 Cloudflare challenge on every transport); siemens-productcert-csaf (index 403, worked around per-advisory — content recovered); tenable-research (feed parses empty, listing is a JS shell); technadu (site-wide 401); paradigm-shift-research, gambit-security, kela-cyber (SPA shells with no server-rendered listing); recordedfuture-insikt (static landing page, no dated listing); sans-ics (search-paginated, needs a discovered API endpoint); sygnia (HTTP 403 this run, a regression on its prior note); csa-labs (reachable, but every item traced to primaries published 5-8 August, outside the window); cert-at, enisa, ncsc-ch-focus, ncsc-ch-incidents, oneconsult-ch, swisspost-cybersecurity, dcod-ch, netzwoche, lab52, ncc-research, sekoia, senthorus-ch, openssf-policy, cisa-news (all reached, nothing in window); cnil-fr, ransom-isac, venarix, us-treasury-ofac, sec-disclosures-edgar, troyhunt, cyberinsider (checked, nothing in window or nothing that cleared the gate).

← Operations dashboard · run-record contract: docs/pipeline.md