ctipilot.ch

2026-08-15T0412Z-intel

One pipeline fire, in full · intel run of 2026-08-15 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-15/2026-08-15T0412Z-intel.md.

Run telemetry

2026-08-15T0412Z-intel intel prompt v3.31 publish ok
2h 37m duration 14 published 5 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
12
Duration
19m 30s
Tool calls
14 WebFetch13 WebSearch28 bridge
Cited sources
5 of 24 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
18m 59s
Tool calls
26 WebFetch24 WebSearch14 bridge
Cited sources
1 of 20 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
14m 13s
Tool calls
39 WebFetch5 WebSearch6 bridge
Cited sources
4 of 22 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
6
Duration
16m 02s
Tool calls
18 WebFetch20 WebSearch14 bridge
Cited sources
5 of 12 in slice
followup-deepread Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
16m 20s
Tool calls
3 WebFetch2 WebSearch11 bridge
Cited sources
7 of 8 in slice

Verification

#1 NEEDS_FIXES · Opus 5 · t=5 e=4 a=2 #2 NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=0 #3 NEEDS_FIXES · Opus 5 · t=4 e=4 a=1 #4 NEEDS_FIXES · Sonnet 5 · t=3 e=0 a=0 #5 NEEDS_FIXES · Opus 5 · t=5 e=2 a=3 #6 NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=0

Deep dive

2026-08-15/netscaler-saml-signedinfo-overflow-preauth-root-rce-not-dos

Entries published (this run)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

8 notes-appended · 3 fetch-method-corrected.

SourceChangeFrom → ToReason
censys-blogfetch-method-correctedblocked → webfetchthe feed answered the direct transport again this run after being pinned as blocked on 2026-08-01 — a metadata-drift correction, re-pin only on regression
chrome-releasesnotes-appended— → dated-archive recipethe default feed path has returned an empty result for four consecutive runs; the dated archive page is the working recipe and was used this run
ransom-isacnotes-appended— → feed.xml recipethe blog path is a client-rendered shell with no server-side post list; the site's own feed works cleanly and should be the recipe
venarixnotes-appended— → needs dated recipelisting is a client-filtered single-page app with no per-post dates in the served HTML
sygniafetch-method-correctedwebfetch → bridgethe direct-transport 403 that has blocked this source for two runs is bypassed by the bridge, which returned the full blog index when tried during the source-health repair pass — recipe fixed rather than logged again
adobe-psirtfetch-method-correctedwebfetch → bridgehealth probe reported the source unreachable on the direct transport; the bridge returned the full bulletin index, so the recipe is repaired rather than demoted
fbi-cyber-alertsnotes-appended— → no transport availablethe host refuses the direct transport and the bridge falls through to the reader, which was exhausted all run; not demoted — an access wall, not content death
ccn-cert-esnotes-appended— → reader-pinnedhealth-probe failure is an artifact of the exhausted reader pool rather than a recipe defect; not demoted
ico-uknotes-appended— → reader-pinnedhealth-probe failure is an artifact of the exhausted reader pool rather than a recipe defect; not demoted
prodaftnotes-appended— → reader-pinned, unreachablefetch_method is pinned to the reader, which was unavailable all run; seven consecutive runs without a contribution
siemens-productcert-csafnotes-appended— → CSAF mirror covers the index 403CISA's mirror carried six in-window Siemens advisories with full structured data, so the vendor portal's 403 cost no coverage

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
jina-reader-poolhttps://r.jina.ai/ (all configured keys)jina402 transport-block
every one of the 7 configured reader API keys returned HTTP 402 balance-exhausted and the anonymous tier returned HTTP 403, so the last rung of the fetch ladder
worked around per host — CISA's CSAF JSON mirror replaced the reader-only HTML advisory path, the CNA records stood in for the unreadable Citrix knowledge-base
gbhackershttps://gbhackers.com/likho-hijacks-microphones/webfetchbridge:url202 transport-block
anti-bot interstitial returned in place of the article body; reader fallback unavailable
none — the item it would have corroborated was dropped on relevance grounds, so no entry depends on it
cybersecuritynewshttps://cybersecuritynews.com/armored-likho-still-toolkit-steals/webfetch200
HTTP 200 with an empty body — a client-rendered shell the summariser could not hydrate
none — same dropped item as above; no entry depends on it

Bridge invocations (this run)

23 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

20 ok3 other
  • url ×16
  • api ×2
  • rss ×2
  • csaf-recent ×1
  • csaf ×1
  • jina ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 11 findings (truth=5, editorial=4, advisory=2) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F1
claim-not-supported
CVE-2026-70466 fixed version given as 7.6.7; the advisory says 7.6.6, and the 7.4/7.2 branches have no fixed build at allcorrected the cves[] record against the vendor's own version table, added mitigation-only status and a body paragraph stating the two branches must be migrated
F2
quantifier-without-source
'Fortinet published three advisories' against the co-cited source's 'eight vulnerabilities across its products'rewritten to the source's own count with the citation attached
F3
hallucinated-fact
'Two days after MyDr confirmed' — the confirmation and the ministerial briefing fall on the same daychanged to 'On the same day'
F4
hallucinated-fact
Metabase precedent described as nine days ago; the entry is 2026-08-09, six days before this runcorrected to six days
F5
hallucinated-fact
single-source line named a non-existent entry id and labelled the Haiwell entry a national-CERT carve-out its own sourcing note declinesentry id corrected and the carve-out label removed, with the reason stated
F6
missing-citation
uncited claim that NCSC-NL relayed the advisories, with no NCSC-NL source in sources[]clause dropped
F7
missing-citation
claim of a separate cadastral-registry compromise was uncited and misread the cited reporting, which frames the larger figure as the same advertised datasetrewritten to report the actor's 2-million figure against the government's confirmed 678,000, cited to The Register; the registry entity summary was corrected th
F8
surface-contradiction
action item silently adopted the PostGIS/Oracle reading while a co-cited source locates the code-execution path in H2 deploymentsaction now names both readings and attributes each to the source that gives it
F9
missed-angle
CVE-2026-70465, a FortiClient for Windows pre-auth RCE reachable by anyone able to craft DNS responses, was in the same batch and named in the entry's own source but neither published nor droppedresearched from Fortinet's own advisory and added: cves[] record, evidence quote, a body paragraph and a do-now action for the teleworker fleet
F10
editorial-advisory
three paraphrases shifted completion state or agency against the cited wordingall three rewritten to the sources' own framing
F11
editorial-advisory
Defender exclusions carried the triage discriminator but were unmapped in techniques[]mapping added (the active id superseding the revoked one)

Iteration #2 NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
the CVSS carried for CVE-2026-70465 — the flaw added by the previous iteration's own missed-angle remediation — was 8.1 in three places, against the 7.3 in the assigning authority's advisory and CSAF corrected to 7.3 in all three locations against the vendor's CSAF, verified independently by the main agent, with the divergence from the NVD score stated in th

Iteration #3 NEEDS_FIXES · 9 findings (truth=4, editorial=4, advisory=1) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F1
claim-not-supported
the entry asserted the FortiWeb 7.0 branch was absent from the vendor's affected list for CVE-2026-26035; the vendor's CSAF lists 7.0.0-7.0.12 affected with only an upcoming fixverified the CSAF independently and rewrote the affected/fixed strings and the body from the structured record — 7.0 restored as affected, and 7.2.13/7.0.13 sta
F2
claim-not-supported
CVE-2026-70466's no-fix branch list omitted FortiWeb 7.0, which the CSAF lists affected at all versions7.0 added to the affected string and to the body sentence enumerating the unfixed branches
F3
quantifier-without-source
'None of the three is reported exploited' survived the addition of a fourth flawrewritten to the batch-wide statement its source actually makes
F4
analytical-link-as-fact
a China nexus was asserted in the summary and tagged, though neither cited source states onedescriptor and tag removed from the entry and the nexus field cleared on the registry record; the sourcing note now states what the source does and does not say
F5
single-source-flag-missing
the sixth single-source entry was missing from the run record's listline added
F6
needs-more-research
the FIPS and NDcPP builds carry a different fixed version, so the verify-your-version action gave those operators a boundary that does not exist on their trainFIPS/NDcPP ranges and the 13.1-37.272 fixed build added to both CVE records and to the action
F7
needs-more-research
the entry said 'under active exploitation' where all three sources describe scanning and probing with no confirmed compromisessummary and body now carry the sources' own qualifier and state why the distinction changes the triage
F8
missed-angle
an in-window re-attribution of the 2,500-organisation LiteLLM compromise to the upstream Trivy build compromise was neither published nor logged as a dropresearched with a scoped follow-up sub-agent and published as 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection
F11
editorial-advisory
the scoring note implied the assigning authority and the aggregator disagreed, when the two figures are the same vector at different metric setsnote rewritten to say so

Iteration #4 NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F1
hallucinated-fact
asserted that no FortiWeb 7.0 branch exists in this batch and that 7.2.13 is already released, and asked for the previous iteration's correction to be revertedREJECTED on primary evidence, in part. The vendor's CSAF record for FG-IR-26-158 was re-fetched twice by the main agent and lists FortiWeb 7.0.0-7.0.12 under kn
F2
hallucinated-fact
carried a geopolitical nexus tag where the cited source states only that operator-console strings are in Simplified Chinese and makes no state attributiontag removed and the sourcing note now records what the source does and does not claim — the same defect class corrected on another entry an iteration earlier
F3
claim-not-supported
the CERT-EU source was dated nine days before its own published bylinedate corrected against the page's byline in frontmatter and both inline citations; the Docker citation was re-checked the same way and corrected to its own publ

Iteration #5 NEEDS_FIXES · 10 findings (truth=5, editorial=2, advisory=3) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F1
analytical-link-as-fact
the nexus descriptor removed an iteration earlier had survived in the summary, contradicting the entry's own sourcing noteremoved; no nexus claim now appears in the entry or its registry record
F2
hallucinated-fact
an action told operators to upgrade to a build the same entry states is not released, and omitted the 7.0 branch entirely; this iteration also independently confirmed the CSAF reading that settled theaction rewritten to the three released builds, with the configuration change named as the whole remediation on the two branches that have none
F3
hallucinated-fact
an evidence quote carried a leading word absent from the sourceword removed so the quote is a contiguous substring
F4
claim-not-supported
a citation used a post's last-updated date rather than its published datecorrected in frontmatter and inline
F5
claim-not-supported
the clause reporting that the government disputes the retained-access claim was cited to the government statement, which does not address itre-attributed to the outlet that carries it; the government citation now covers only what its own statement says, and the sourcing note was corrected to match
F6
missed-angle
an in-window exploitation-status change on a SharePoint CVE this store already carries as not-exploited, with two Swiss government SharePoint intrusions in the same storenot published — surfaced too late to research and verify inside the wall-clock guard; queued in state/coverage_backlog.md as an update_of delta for the next fir
F7
missed-angle
in-window vendor research on a browser-extension framework reaching outside the sandbox via native messaging, against government webmailnot published — the publisher is in no research slice this run, so it is a source-coverage gap; queued in state/coverage_backlog.md with the mechanism to verify
F8
editorial-advisory
workflow-internal wording reached the published notesrewritten in plain operational register
F9
editorial-advisory
the interim mitigation named the wrong vendor database and dropped the version a defender would act onnow names the virtual patch and the signature-database update that carries it
F10
editorial-advisory
the FIPS/NDcPP version ranges and both CVSS figures come from the vendor's CVE records, which neither cited page carriessourcing note now states that provenance; the records themselves are not citable under the source-pattern rule

Iteration #6 NEEDS_FIXES cap-breach · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F1
hallucinated-fact
the nexus scrub applied an iteration earlier reached the actor record and two of the three malware records added this run, but missed the third — a registry summary still described the implant as usedclause removed; the record now states only what the cited analysis supports. Seven of the eight prior fixes were independently re-verified correct in the same p

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-15T0412Z-intel · Opus 5 · window 50 h · 14 entries published

Verification & coverage notes

Coverage window: catch-up of 48 h (previous run 2026-08-13T0412Z-intel) — the scheduled 2026-08-14 fire did not run, so nothing published after 2026-08-13T04:13Z had been swept before this run. Because the gap exceeded a day, the research pass covering vendor and independent labs additionally walked publisher listing pages filtered to the gap dates rather than relying on advisory and catalogue feeds alone; that sweep is where the Kaspersky, Talos and SentinelLabs items came from, none of which route through a CVE or catalogue path.

Reader transport unavailable for the whole run. All seven configured keys for the last-resort reader returned a balance-exhausted error and the anonymous tier refused, so every research pass lost the bottom rung of the fetch ladder. Three consequences are visible in this run's output: Citrix's own knowledge-base article for the NetScaler bulletin could not be read (its page serves an empty client-rendered shell rather than an access error, so no fallback triggers), and the CVE descriptions and scores in the deep dive are taken from the CNA records instead; one research source stayed blocked behind a 403; and two corroboration attempts for a dropped item could not be adjudicated. No published entry rests on an unread source, but the operator should top up or rotate the key pool — this is a standing capability loss, not a one-off failure.

  • Single-source: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit — Kaspersky's own first-hand analysis, with trade-press coverage that re-reports rather than independently observes; rated on one assessor.
  • Single-source: 2026-08-15/jwr-phishing-framework-realtime-operator-websocket-mfa — Cisco Talos's own analysis; no independent second party has published on this framework.
  • Single-source: 2026-08-15/cve-2026-73487-flowise-prompt-injection-rce-fix-exists — the assigning CNA is the only party with a technical description; the vendor advisory was not reachable from this environment.
  • Single-source: 2026-08-15/cve-2026-19188-haiwell-hmi-gateway-unauth-root-rce — CISA is the disclosing authority and no vendor advisory could be located. The entry does not claim the national-CERT carve-out, because the advisory was read from CISA's structured mirror rather than from the authority's own domain.
  • Single-source: 2026-08-15/nhsbt-transplant-data-unencrypted-pager-network — the BBC's investigation is the only first-hand account and carries the organisation's, the network operator's and the regulator's statements directly; other coverage re-reports it.
  • Single-source (victim's own disclosure): 2026-08-15/threema-nine-colocation-ddos-swiss-messenger-outage — the operator's own account of its own outage; the corroborating outlet derives from the same post.
  • Correction to this pipeline's own record: the 2026-07-01 NetScaler entry stated that no in-the-wild exploitation of CVE-2026-8451 was confirmed. Switzerland's NCSC has carried that flaw as actively exploited with a public proof of concept since its advisory of 2026-07-03, and this pipeline never picked the status change up. The correction ships inside this run's deep dive rather than as a separate entry, because the same entry carries the in-window research that prompted the re-check.
  • Identifier hedged, deliberately: the exploitation chain in the deep dive is attributed to the bug the researchers analysed, not asserted as CVE-2026-8452. The researchers say they cannot confirm the mapping and Switzerland's NCSC calls the analysis "likely related" to that identifier; the remediation is identical either way.
  • Claim-versus-fact separation held in two incident entries: the French tax authority's confirmed figure of 678,000 records is kept apart from the same actor's unverified claims of a second, larger compromise and of retained access, which the government disputes; and the extortion group's stated exfiltration volumes for the two newly-confirmed victims are reported as the attackers' own claims relayed by a leak-site monitor that cautions they are unverified.
  • Deliberate non-update decision: 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection shares the TeamPCP actor key with an entry from 2026-08-08, but that entry is a vendor threat report profiling the actor among others, and this one is a re-attribution of a specific compromise's blast radius. It is a distinct story rather than a delta on that report, so it ships as a new entry; the shared key is co-occurrence, which the renderer already surfaces.
  • The claim that the actor behind the French tax-authority intrusion had separately compromised a cadastral registry did not survive a re-read of the cited reporting: the larger figure it rests on is that actor's own description of the same advertised dataset, and the entry now reports it that way.
  • One claim in a research return was left out of the Polish healthcare update as unadjudicable: a report that the breached processor cannot lawfully supply its data to the national breach-checking portal without regulator authorisation sits in tension with the minister's statement that the information will be available there. Neither was published.
  • The Fortinet entry's version data is read from the vendor's CSAF records, not its rendered advisory tables: the tables omit the FortiWeb 7.0 branch that the structured records list as affected, and present two builds as available that the records mark as upcoming. An earlier draft of the entry followed the rendered tables and told a 7.0 estate it was out of scope; the verifier caught it against the CSAF and the entry now carries the structured data throughout.

Borderline drops, each researched and verified before being dropped:

  • borderline-drop: IBM i August patch cycle (CVE-2026-16860 at 9.9 plus a Debug Server bundle topping out at 9.8) — a coordinated quarterly PTF cadence with no exploitation and no exposure-driven urgency; the normal patch process already covers it.
  • borderline-drop: Siemens Siveillance Video CVE-2026-3014 (9.1 command injection) — the structured advisory carries no vulnerability narrative beyond the weakness class and version ranges, the authentication prerequisite is unstated, and the vendor's own advisory could not be located; not enough to write an entry a responder could act on.
  • borderline-drop: GitLab 19.2.2 / 19.1.4 / 19.0.6, fourteen flaws including an authenticated package-registry path-traversal RCE — authenticated, unexploited, and handled by the normal self-managed upgrade cadence.
  • borderline-drop: Johnson Controls Metasys CVE-2026-34491 (persistent cross-site scripting, government-facilities sector) — requires an authenticated low-privilege account and supported versions are already patched; the end-of-support branches that will never be fixed are a lifecycle problem rather than this week's decision.
  • borderline-drop: Hitachi Energy APM Edge (CVE-2026-43284, CVE-2026-43500) — kernel-inherited flaws whose only stated remediation is disabling the affected modules, no exploitation, thin advisory narrative.
  • borderline-drop: ANDRITZ HIPASE-250, four flaws including a fleet-wide hard-coded remote-desktop password — the fixes shipped in December 2024 and July 2026, so the disclosure is catching up to a long-available remedy.
  • borderline-drop: Johnson Controls Airwall (CVE-2026-64887, CVE-2026-34492) — a hard-coded key in an OT remote-access gateway is conceptually worse than its 6.4–6.8 scores suggest, but there is no exploitation and no out-of-band response to take.
  • borderline-drop: Flow Neuroscience FL-100 brain-stimulation device (CVE-2026-18164) — a consumer home-use medical device reachable only within Bluetooth range; outside this constituency's estate even under the healthcare lens.
  • borderline-drop: Kaspersky's Armored Likho "Still Toolkit" — the campaign targets Russian individuals and organisations through a Russian-language donation-app lure, and the transferable lesson (a stolen desktop-messenger session survives a password reset) is generic and not tied to this constituency's platforms.
  • borderline-drop: Gambit Security on attacker use of AI coding assistants across three intrusions — the report's own conclusion is that the entry vector is unchanged exposed-service exploitation, so nothing here changes what this constituency patches, hunts, blocks or detects.
  • borderline-drop: Operation Klonen arrests over a 2023 payment-processor fraud that drained roughly €30 million from German bank accounts — a law-enforcement outcome on a three-year-old incident whose third-party-risk lesson is generic.
  • borderline-drop: two Swiss leak-site listings surfaced from a ransomware tracker — uncorroborated claims with no victim statement and no high-reliability reporting; dropped under the fake-news gate.

Identifier conflict logged for the quality audit rather than resolved here: the CVE that the reporting attaches to the Trivy ecosystem compromise is recorded in this pipeline's own CVE index against a different TeamPCP supply-chain incident. The two cannot both be right. The new entry therefore carries no CVE in its metadata, so nothing unverified reaches the store's CVE surface, and the reconciliation is left to the audit with both readings on the record.

Coverage backlog: one row open (an AI-generated-patch study surfaced 2026-08-10). Re-reviewed against today's facts and held open unpublished for the same reason the surfacing run gave — it is a study statistic about AI-assisted patching rather than tradecraft a Tier 2/3 responder acts on. It remains inside the retention period the file itself sets.

Coverage gaps: paradigm-shift-research (no dated listing or feed exists and no in-window article surfaced); sygnia (403, reader unavailable); prodaft (pinned to the unavailable reader; seventh consecutive run without a contribution); venarix (single-page-app listing with no per-post dates); cnil-fr (news page fetched cleanly but the sanctions sub-page was not drilled); cert-eu, cert-pl, kela-cyber, ox-security, seqrite-labs, xlab-qianxin, dfirreport, akamai-sirt, hunt-io (fetched cleanly, no in-window content); csa-labs (heavy in-window output, all of it consolidation of items already covered here or of pre-window primaries — dropped as re-reporting); ncsc-uk (in-window publication was guidance rather than advisory content); cert-fr (a large 2026-08-14 advisory batch was drilled; the flaws are bundled dependency updates without exploitation or severity signal, so none cleared the bar against stronger candidates).

Watchlist: no product or supplier watchlist is configured for this deployment, so both sweeps are no-ops and no entry carries a watchlist flag.

← Operations dashboard · run-record contract: docs/pipeline.md