ctipilot.ch

2026-08-16T0411Z-intel

One pipeline fire, in full · intel run of 2026-08-16 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-16/2026-08-16T0411Z-intel.md.

Run telemetry

2026-08-16T0411Z-intel intel prompt v3.31 publish ok
35m 50s duration 6 published 3 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
8m 01s
Tool calls
4 WebFetch8 WebSearch20 bridge
Cited sources
4 of 24 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
12m 28s
Tool calls
18 WebFetch28 WebSearch7 bridge
Cited sources
1 of 18 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
8m 18s
Tool calls
9 WebFetch7 WebSearch18 bridge
Cited sources
1 of 30 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
11m 33s
Tool calls
16 WebFetch18 WebSearch19 bridge
Cited sources
4 of 18 in slice
followup-completeness Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
6m 29s
Tool calls
10 WebFetch7 WebSearch2 bridge
Cited sources
3 of 7 in slice

Verification

#1 NEEDS_FIXES · Opus 5 · t=2 e=2 a=1 #2 NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=0 #3 NEEDS_FIXES · Opus 5 · t=0 e=1 a=3 #4 NEEDS_FIXES · Sonnet 5 · t=0 e=1 a=1 #5 NEEDS_FIXES · Opus 5 · t=2 e=2 a=4 #6 NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=1

Deep dive

2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

8 notes-appended · 1 fetch-method-corrected · 1 added-as-candidate.

SourceChangeFrom → ToReason
cisa-advisoriesnotes-appended— → reader-pool dependency documentedthird consecutive run unreachable — Akamai 403 on every direct UA plus an exhausted reader pool; NOT demoted, since a 403 is transport blocking rather than content death, and the KEV/CSAF endpoints carry the CISA surface meanwhile
cisa-directivesnotes-appended— → reader-pool dependency documentedsame condition as cisa-advisories; NOT demoted
fbi-cyber-alertsfetch-method-correctedbridge → bridgethe 2026-08-15 note recorded no transport available; a serial re-probe this run returned 45 KB through the generic bridge, so that assessment is superseded — metadata-drift correction, not a demotion
ncsc-ch-incidentsnotes-appended— → sweep flag is a contention artifactsource_health flagged needs-demote, but a serial re-probe returned the full 51 KB listing with every dated entry present; the flag is parallel-contention under a dead reader pool, not a recipe defect
ico-uknotes-appended— → sweep flag is a contention artifactflagged needs-demote by the sweep; a serial re-probe returned 50 KB through the generic bridge
ccn-cert-esnotes-appended— → reader-quota casualtydirect transport fails and the fetch falls through to the reader, where all seven keys return 402; a quota condition never demotes
netzwochenotes-appended— → transient 503server error on the listing page this run; transient, no recipe change
paradigm-shift-researchnotes-appended— → reader-dependent, unrecoveredstill SPA-shell only on the direct transport and the reader escalation was unavailable all run
prodaftnotes-appended— → reader-pinned, unreachableeighth consecutive run without a contribution, every one of them a reader-pool failure rather than content death
fortinet-fortiguard-blogadded-as-candidate— → candidatethis run's single new candidate — the named original-research primary behind the botnet entry published here, and the originating lab for several earlier fires' citations without the publisher ever being tracked

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
jina-reader-poolhttps://r.jina.ai/ (all seven configured keys)jina402 transport-block
every one of the seven configured reader API keys returned HTTP 402 balance-exhausted and the anonymous tier returned HTTP 403, so the last rung of the fetch la
worked around per host — CISA KEV and the CISA CSAF mirror do not route through the reader and carried the CISA advisory surface; the generic bridge transport r
cisa-advisorieshttps://www.cisa.gov/cybersecurity-advisories/all.xmlbridge:cisa.feedbridge:url --directwebsearch403 transport-403
cisa.gov Akamai-403s the direct transport on every UA and the reader fallback was exhausted, so the full documented ladder failed; essential-tier miss
CISA KEV and the CISA CSAF mirror were fetched successfully and showed no new in-window KEV additions or ICS advisories; a WebSearch sweep surfaced nothing beyo
cisa-directiveshttps://www.cisa.gov/news-events/directivesbridge:cisa.pagewebsearch403 transport-403
same condition as cisa-advisories — direct 403 plus an exhausted reader pool; essential-tier miss
no evidence from any other source that a new directive published in-window
netzwochehttps://www.netzwoche.ch/webfetch503 transport-5xx
server error on the listing page; single-attempt rule applied
other Swiss trade-press sources in the slice covered the window's home-region signal; no item is known to have been lost
fortra
covered via alternate · should NOT be in this list
https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-webfetchbridge:url403 transport-403
vendor blog refuses the direct transport and the reader fallback was exhausted, so the primary research post behind the ExfilSquad entry could not be read first
the entry is composed from two independent outlets quoting Fortra directly, and its sourcing note records that the primary was unreachable

Bridge invocations (this run)

24 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

20 ok4 other
  • url ×18
  • rss ×1
  • api ×1
  • csaf-recent ×1
  • feed ×1
  • page ×1
  • jina ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 5 findings (truth=2, editorial=2, advisory=1) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
the sentence reporting scanning for vulnerable systems was cited to the trade-press article, which never mentions scanning; that fact belongs to the national-CERT advisory cited two paragraphs earlierthe advisory is now cited alongside the article on that sentence, each clause attributed to the source that carries it
F5
missing-citation
the rebuild-and-redeploy remediation and the interim IP-filter control appear five times across the entry but in neither cited source; both are stated verbatim by the research firm that works with thethat firm's analysis was fetched and read independently, added as a sources[] record and cited at the point of claim in the hardening sentence
F10
missed-angle
an unauthenticated customer account takeover in a widely deployed commerce platform, judged relevant by this run and described in its own notes as a miss by an earlier fire, was queued to the coveragepublished as 2026-08-16/cve-2026-71362-adobe-commerce-customer-account-takeover after re-reading all three sources; scores, affected and fixed version lines tra
F11
editorial-advisory
workflow-internal vocabulary reached the published record in two placesboth rewritten in plain operational register
F13
analytical-link-as-fact
the Defender takeaway hardened the research firm's leading theory into a validated link between the exposure count and the 27 million records, contradicting the entry's own third paragraph and sourcinthe takeaway now separates what was validated (the data is genuine across 13 victims) from what remains an assessment (the access path), and the summary carries

Iteration #2 NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
the CVE record's affected and fixed strings spliced Adobe Commerce's version floor onto Magento Open Source, telling a 2.4.5 or 2.4.4 Magento Open Source operator they were in scope when the vendor's the vendor's affected-versions and solution tables were re-read cell by cell and both strings rewritten per product — Commerce 2.4.9 to 2.4.4, Commerce B2B 1.5.

Iteration #3 NEEDS_FIXES · 4 findings (truth=0, editorial=1, advisory=3) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F10
missed-angle
a Mirai-derived Linux botnet reported in-window on a source this run fetched and used was neither published nor recorded as a drop — silently absent rather than decided, on untracked groundresearched with a scoped follow-up pass that pivoted to the originating research lab's own write-up, and published as 2026-08-16/evooo1bot-mirai-derivative-ente
F11
editorial-advisory
two entries in the same window resolved evidentially equivalent attempts-only facts to opposite machine-readable exploitation values, so a consumer filtering on that flag would get one and not the othharmonised — both now carry the flag, and both sourcing notes state the rule explicitly: it marks observed exploitation activity in the wild reported by a named
F11
editorial-advisory
the only out-of-window entry whose sourcing note did not disclose its recency basis, while the run's other two didclause added naming the basis — an evidentiary delta on tracked ground that the fire whose window covered it did not publish
F11
editorial-advisory
Browser Session Hijacking was absent from an otherwise thirteen-deep mapping despite the body describing exactly that behaviour and the source calling it interacting with the browser as if sitting at T1185 added after confirming it is active in the pinned dataset

Iteration #4 NEEDS_FIXES · 2 findings (truth=0, editorial=1, advisory=1) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F12
single-source-flag-missing
carried multi-source while its own sourcing note described one assessor with two republishing outlets — structurally identical to this window's espionage deep dive, which correctly carries single-sourchanged to single-source, with the note now saying so explicitly and pointing at the parallel entry so the two are calibrated the same way
F11
editorial-advisory
the notes still opened by counting five entries and omitted the sixth from the single-assessor list, stale since the previous iteration's remediation added itopening sentence recounted and a bullet added for the sixth entry's sourcing situation, including that its regional-spread figure comes only from the secondary

Iteration #5 NEEDS_FIXES · 8 findings (truth=2, editorial=2, advisory=4) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
the two named ciphers were bound to the command-and-control channel; the researchers attribute them to compile-time string obfuscation and name no cipher for the channel itself, though the port and thre-read the primary and rewrote the sentence — the channel is described as encrypted on the port the researchers name, and the ciphers now sit where the source
F4
hallucinated-fact
three specific product names were listed for one vendor where every cited source says only 'WSO2 products', with the same shape on the Confluence editionsboth reduced to exactly what the sources name, in the product list and in the action item
F10
missed-angle
an incident-response case documenting an actor blinding endpoint tooling by rebooting into Safe Mode, on tracked ground and inside the previous fire's window, is absent store-wide and from every drop not published — surfaced at the fifth iteration with the run near its wall-clock guard, and composing it properly needs a research pass its own verification rou
F12
single-source-flag-missing
carried multi-source while its own sourcing note called the second source a non-independent restatement; the national-CERT carve-out is the correct valuechanged to the carve-out value and the note now says the entry claims it rather than two independent assessments. Deliberately NOT cascaded to the SAP entry, wh
F11
editorial-advisory
the body named four persistence mechanisms but only two were mappedthe shell-configuration and rc-script ids added after confirming both are active in the pinned dataset
F11
editorial-advisory
a 2026-05-04 entry already records this actor's name among tooling-overlap clusters for an actor covered against southeastern European government victims, which is the European thread this entry argueadded to references[]. No registry edge and no attribution claim in prose — the overlap is one lab's tracking note, not an attribution
F11
editorial-advisory
two sole-assessor primaries this window come from publishers absent from the source list, and two telemetry ids named registry records that do not existthe research lab behind the botnet entry added as this run's single candidate source; the two non-existent ids corrected or removed from the telemetry
F11
editorial-advisory
the headline dropped the 'potential' qualifier the source attaches to its exposure count, which the summary and body both keephedge restored in the headline and in the takeaway

Iteration #6 NEEDS_FIXES cap-breach · 2 findings (truth=1, editorial=0, advisory=1) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
the body gave the Kubernetes flaw a campaign name and cited it to the research lab, but none of the three cited sources uses that name — only the identifier is sourcedthe name removed from the body and from the CVE index record written this run; the identifier and the description of what the flaw reaches both stand on the sou
F11
editorial-advisory
the telemetry still named a retired source id in two places, the same defect class the previous iteration reported as fully correctedboth occurrences corrected to the current registry id

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-16T0411Z-intel · Opus 5 · window 26 h · 6 entries published

Verification & coverage notes

Standard 26 h window against a 24 h gap to the previous fire, which published cleanly. Six entries: two exploitation-status changes on ground the store already carried, one independent confirmation of an extortion group's claims, one deep dive on newly published espionage tradecraft, one unauthenticated account-takeover flaw recovered from an earlier fire's blind spot, and one newly documented Linux botnet recovered by the review loop.

Reader transport unavailable for the whole run, for the second fire running. All seven configured keys for the last-resort reader returned a balance-exhausted error and the anonymous tier refused. The cost this run was concrete rather than theoretical: two essential-tier CISA sources (the advisories feed and the directives listing) went fully unreachable because cisa.gov refuses every direct user agent and the reader is the documented recovery path, and the vendor research post behind the ExfilSquad entry could not be read first-hand. Nothing published rests on an unread source — the CISA KEV and structured-advisory endpoints do not route through the reader and covered that surface, and the ExfilSquad entry is built from two outlets quoting the research directly, with the gap recorded in its sourcing note. This is a standing capability loss the operator needs to clear, not a one-off.

A completeness sweep of the fetch ledger recovered an item all four research passes missed. Cross-checking the run's URL-liveness ledger against the returned findings surfaced a page one pass had fetched but never reported. That page was itself four months old and irrelevant, but its sidebar named three stories worth checking, and a scoped follow-up pass established that one of them was a genuine exploitation-status change on tracked ground: the macOS Screen Sharing flaw this pipeline covered twice as unexploited is now confirmed exploited, with root obtained and a cryptocurrency miner planted. It is published as this run's fourth entry. The other two were verified stale and are recorded below. Reconciling the fetch ledger against the findings set is worth keeping as a standing step — it is what turned a silent miss into an entry.

  • Single source of assessment, two publishers: 2026-08-16/cve-2026-58231-sap-commerce-cloud-exploitation-attempts — the exploitation observation is one firm's honeypot telemetry, carried by a national CERT advisory and by trade reporting. Rated credibility 2 on that basis.
  • Single source of assessment, two publishers: 2026-08-16/cve-2026-65400-screen-sharing-confirmed-exploited-monero — the exploitation report is the Dutch national centre's, based on a notification it received; the corroborating outlet reports that advisory rather than observing the activity.
  • Single-source: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole — the investigating lab is the only party with first-hand visibility, having worked from the group's own control panel and victim database; the second outlet reproduces that research.
  • Single-source: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay — the same shape: the research lab that found the botnet is the only assessor, and both corroborating outlets restate its blog and its telemetry rather than observing the activity themselves. One regional-spread figure appears only in the secondary reporting and is attributed there, not to the lab.
  • Primary unreachable, disclosed on the entry: 2026-08-16/exfilsquad-fortra-confirms-13-victims-power-pages-anon-role — the research firm's own post refuses every transport available this run, so both cited sources are outlets quoting it. They agree and neither contradicts the other.
  • Status calibrated down on the SAP entry. The research pass described confirmed opportunistic exploitation; what the sources actually support is exploitation attempts against honeypot sensors plus a national advisory recording active scanning, with no confirmed compromise of a production instance and no public proof-of-concept. The entry says that, and the CVE record carries exploited because the attempts are real and in the wild, not because a production estate is known to have fallen.
  • Priority calibrated down on the macOS entry. A case exists for treating a confirmed pre-authentication path to root on an internet-exposed service as critical, and the research pass suggested it. It ships at high instead: the patch has been available since 2026-08-06 and this pipeline has already twice told readers to apply it, the observed outcome is cryptomining rather than destruction or theft, and the critical bar is reserved for items where the reader has not already been given the action.
  • Deep-dive category rotation noted rather than clean: the espionage deep dive is filed under the same category as the 2026-08-12 deep dive, four days earlier. The rotation rule demotes a recently used category by one rank, but this was the only candidate that cleared the deep-dive bar this run, so demotion changes nothing. Flagged so the pattern is visible if it repeats.
  • No historical-context paragraph on the deep dive despite the actor having older prior reporting under three other vendor names. The investigating lab states those alternate names; the predecessor reports themselves were not fetched in this run, so nothing is claimed about their content. Writing a background paragraph from names alone would be invention.

Verification loop: six iterations, landed on the low-residual early exit rather than a confirmed double-CLEAN. The rotation held throughout — three passes on each model, alternating, with no same-model pair. Every finding raised across all six was remediated, including two entries the loop itself recovered: the account-takeover flaw an earlier fire had missed, and the Linux botnet that four research passes had left unrecorded. The final pass returned a single truth finding, an unsourced campaign name in one clause, which was removed; that is what the residual count records. The run lands there rather than spending two further passes chasing a confirmed CLEAN, because at just over two hours elapsed the wall-clock guard leaves room for the publishing chain and not much more, and the last two passes found only a naming slip and a stale source id between them.

Borderline drops, each researched before being dropped:

  • borderline-drop: FINMA chair's interview statement that cyberattacks on supervised banks and insurers are up roughly a third, and that frontier AI models are a sector-wide risk — a regulator's risk commentary with no technique, no incident and no action; the percentage is the kind of figure this pipeline does not carry, and nothing in it changes what a responder does in the next week.
  • borderline-drop: Check Point's July 2026 telemetry pickup reporting a 35% year-on-year rise in attacks on Swiss organisations and naming three ransomware brands by share of published victims — aggregate vendor statistics rather than an incident or a technique, with the Switzerland-specific sector line resting on a single trade-press rendering of a vendor country data cut. The two named brands already tracked here gain nothing from a share figure; the third is a name attached to a percentage.
  • borderline-drop: Scottish prosecution service third-party survey breach, roughly 300 staff names, roles and work email addresses exposed via an unnamed supplier running a centrally procured assessment — a European public-sector incident with a real third-party-procurement lesson, but no disclosed vector, no named supplier, no actor and no technique the reporting supports. The tell was the mapping: an honest technique list for it would be empty, which is the signal that the entry would be describing too little to publish rather than a reason to invent a mapping. Its freshest source also predates this window.
  • borderline-drop: German and Brazilian arrests over a 2023 fraud that drained roughly €30 million from bank customers through a payment provider's faulty booking-logic update — the previous fire already considered and dropped this on the same reasoning, a law-enforcement outcome on a three-year-old incident whose third-party lesson is generic. Dropping it again keeps the two fires consistent.
  • borderline-drop: Iran-linked attribution reporting on the US water-utility campaign naming two further states — checked specifically because it would be a material change to heavily tracked ground where every prior entry records that no authority has attributed the campaign. It is not one: the underlying incidents and the intelligence-assessment reporting all date to five and six days ago, the freshest touching source is a recap that itself states the government has still not named a culprit, and the strongest attribution claim available is one newspaper's unnamed-source reporting. The store's existing framing remains accurate.
  • borderline-drop: a consumer-grade router authentication bypass carrying a high score and a public exploit, single-sourced to one vulnerability database with no vendor or national-CERT confirmation reachable, and no plausible nexus to this constituency.
  • borderline-drop: unconfirmed leak-site listings and a stale unverified public-health data-leak claim, all failing the fake-news gate for want of a victim statement or high-reliability reporting.

Coverage backlog: three rows were resolved and two opened. The espionage research queued by the previous fire is published as this run's deep dive. The row for a SharePoint exploitation-status change is struck as already covered — the store carried that development on 2026-08-13, two days before the row was written against reporting of the same event. The study on AI-generated patches stays open, unchanged, inside its retention period. Two new rows: a malware cluster using a cloud spreadsheet API as its command-and-control transport against critical-infrastructure telecom, out of window by three days; and a critical-infrastructure infostealer study that no available transport could reach.

The unauthenticated account-takeover flaw in a widely deployed commerce platform was initially queued to the backlog on recency alone and is instead published as this run's fifth entry. The review pass was right to refuse the deferral: this run had already judged the item relevant and described it in these same notes as a genuine miss by an earlier fire, so queueing it rather than publishing it was inconsistent on its own terms — and the backlog's rule exempts exactly this shape, an item lost to a pipeline race rather than to staleness, from the recency gate. All three of its sources were re-read and the scores, affected and fixed version lines transcribed from the vendor's own table before it shipped.

Source-health repair, acted on this run rather than deferred: the sweep flagged four sources for demotion. Three of them returned full content when re-probed one at a time immediately afterwards, so the flag is contention under a dead reader pool rather than a broken recipe, and one of those corrections supersedes a previous run's conclusion that the source had no working transport at all. The fourth genuinely depends on the exhausted reader. None was demoted; a transport block is not content death. The underlying weakness is in the probe rather than the sources — a parallel sweep with the reader unavailable produces false demotion candidates — and is left flagged here for the weekly audit rather than changed mid-run.

Coverage gaps: cisa-advisories, cisa-directives (essential tier — direct 403 plus an exhausted reader; see above); paradigm-shift-research (client-rendered shell, reader unavailable); prodaft (pinned to the unavailable reader, eighth consecutive contribution-free run); netzwoche (transient server error); anssi-fr, bsi-de, cert-eu, cert-pl, ncsc-uk, cert-at, enisa, govcert-at (fetched cleanly, nothing new inside the window); the research slice including the major labs (fetched; the only in-window hit duplicated an entry published yesterday); ico-uk, cnil-fr, sec-disclosures-edgar (fetched, no in-window enforcement or filing that cleared the gate).

Essential-coverage: missed=cisa-advisories (Akamai 403 on every direct transport, reader pool exhausted), cisa-directives (same condition).

Watchlist: no product or supplier watchlist is configured for this deployment, so both sweeps are no-ops and no entry carries a watchlist flag.

← Operations dashboard · run-record contract: docs/pipeline.md