2026-08-16T2315Z-weekly
One pipeline fire, in full · weekly run of 2026-08-16 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-16/2026-08-16T2315Z-weekly.md.
Run telemetry
- Items returned
- 5
- Duration
- 19m 15s
- Tool calls
- 24 WebFetch20 WebSearch9 bridge
- Cited sources
- 4 of 26 in slice
- Items returned
- 3
- Duration
- 14m 16s
- Tool calls
- 24 WebFetch24 WebSearch21 bridge
- Cited sources
- 2 of 29 in slice
Verification
Deep dive
—
Entries published (this run)
- The gap between public disclosure and working exploitation closed to days or hours across five unrelated products — a patch day, a proof-of-concept, a researcher's post and a binary diff each turned public information into a working attack inside a week synthesis high
- Two espionage toolsets shipped kernel-mode rootkits in the same week whose job is to edit what Windows reports to the defender's own tools — and one of them arrived on a zero-day that was patched on Tuesday synthesis high
- Three unrelated intrusions and one research publication worked this week attacked the evidence a responder reconstructs afterwards rather than the sensor watching at the time — and two of the week's victims proved the same point from the defending side synthesis high
- A third party was on the access path or holding the data in all six European public-sector and critical-infrastructure disclosures this week — and where the third party held the data, the duty to notify landed on organisations with no facts to write synthesis high
- 2026-W33 vulnerability status roll-up — eight flaws crossed into confirmed exploitation or the federal catalogue this week, two of them within seventy-two hours of their own disclosure, against a critical tail led by two unauthenticated CVSS 10.0 flaws in industrial edge devices vulnerability high
- Cl0p PTC Windchill campaign status: the extortion wave crossed from leak-site assertion to partial victim corroboration this week — Philips and Shell responded, European organisations appeared among the named listings, and a second vendor confirmed the webshell artefact PTC had already documented synthesis notable
- Three developer-credential findings this week each show an estate auditing the wrong thing — the wrong package, the wrong incident class, and repositories nobody counted as company assets at all research notable
- UPDATE — the Dutch NIS2 clock the prior weekly recorded as forthcoming started on 15 August, and the national CERT confirms the registration duty applies from the entry-into-force date itself with no transition window policy notable update
- UPDATE — the Cyber Resilience Act's conformity route entered formal approval this week: ETSI put 17 draft product-category standards out for Public Enquiry, and the procedure runs past the regulation's first reporting deadline policy notable update
- ExfilSquad status: a vendor validated the group's published data across 13 victim organisations and put the access path on misconfigured Power Pages portals — reversing the assessment, recorded here two weeks ago, that its victim list was more likely fabricated synthesis notable
- 2026-W33 looking ahead — items already in motion: a CRA reporting clock at four weeks, standards approval that will not beat it, an exploited flaw with no patch in existence, seven further flaws with no fix coming, and twelve thousand Polish clinics who each owe a notification outlook notable
- UPDATE — the fourth passkey attack thread this pipeline could not source last week is now documented, and it closed: Windows cached YubiKey assertions in cleartext where any authenticated user could read them, and the July updates broke the chain research notable update
- Two independent Q2 2026 ransomware reports published three days apart agree the ecosystem is fragmenting without de-concentrating — and the industrial one carries a negative finding OT operators should plan against: no Q2 case reached control-system manipulation annual-report notable
- Russia's campaign against Europe's Ukraine defence supply chain is assessed to have widened from collection and sabotage to pressuring the people and firms behind it — and the cyber half is aimed at logistics data, not at the manufacturers research notable
- UPDATE — water-sector PLC lockout status: an OT vendor's decade retrospective attributes the Minnesota controller intrusions to a CVE whose own record names a different Rockwell product family, and the campaign still has no CVE and no actor named by any investigating body synthesis notable update
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
1 recipe fix — rss_url set to https://www.recordedfuture.com/feed and fetch_method webfetch -> rss; resolves the discovery-path gap logged on 2026-08-04 (the /research/rss.xml path 404s and the landing page carries no dated listing) · 1 candidate -> active; the state digest counted 10 distinct contributing runs against a 3-run promotion bar · 1 recipe fix — fetch_method jina -> bridge; the reader pin was the cause of the recurring needs-demote flag, and the generic bridge reaches the host directly · 1 recipe fix — url https://www.fbi.gov/investigate/cyber/alerts -> https://www.ic3.gov/PSA, fetch_method bridge; the IC3 public service announcement listing is the reachable publication surface · 1 note only — re-probed on three paths, all unreachable on the direct transport with the reader at HTTP 402; NOT demoted (a quota condition never demotes) and deliberately not muted · 1 note only — ninth consecutive run without a contribution, all reader-pool failures; NOT demoted, flagged as an operator item · 1 note only — discovery should lead with the recorded RSS feed; the HTML listing exposes no titles or dates to WebFetch.
| Source | Change | From → To | Reason |
|---|---|---|---|
| recordedfuture-insikt | recipe fix — rss_url set to https://www.recordedfuture.com/feed and fetch_method webfetch -> rss; resolves the discovery-path gap logged on 2026-08-04 (the /research/rss.xml path 404s and the landing page carries no dated listing) | — → — | |
| fortinet-fortiguard-blog | candidate -> active; the state digest counted 10 distinct contributing runs against a 3-run promotion bar | — → — | |
| ico-uk | recipe fix — fetch_method jina -> bridge; the reader pin was the cause of the recurring needs-demote flag, and the generic bridge reaches the host directly | — → — | |
| fbi-cyber-alerts | recipe fix — url https://www.fbi.gov/investigate/cyber/alerts -> https://www.ic3.gov/PSA, fetch_method bridge; the IC3 public service announcement listing is the reachable publication surface | — → — | |
| ccn-cert-es | note only — re-probed on three paths, all unreachable on the direct transport with the reader at HTTP 402; NOT demoted (a quota condition never demotes) and deliberately not muted | — → — | |
| prodaft | note only — ninth consecutive run without a contribution, all reader-pool failures; NOT demoted, flagged as an operator item | — → — | |
| intel471 | note only — discovery should lead with the recorded RSS feed; the HTML listing exposes no titles or dates to WebFetch | — → — |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| quirso-medium covered via alternate · should NOT be in this list | https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-i | webfetch → url → jina | 402 reader-quota | Recovered the same QUIRSO figures from The Hacker News, which quotes QUIRSO directly and was already a source record on the referenced operational entry; cited |
| cisa-aa26-222a covered via alternate · should NOT be in this list | https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a | url → bridge → jina | 403 anti-bot-block | cisa.gov hard-403s every direct UA and routes through the reader, which is at HTTP 402 on all keys. The Gunra detail is carried narrowly, exactly as the verifie |
Bridge invocations (this run)
8 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- url ×5
- bridge ×3
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #? NEEDS_FIXES · 20 findings (truth=12, editorial=7, advisory=1) · Claude Opus 5 · 20m 36s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F2 generic-url | — | The 44-listing count was cited to ransomware.live's rolling /v2/recentvictims API endpoint, which returns only the 100 most recent victims and today carries no Cl0p records at all, so the citation can | Removed the API endpoint from sources[]; the count is now attributed to the operational entry that recorded it on 13 August, with BleepingComputer's divergent c | |
| F3 claim-not-supported | — | The Swiss hook claimed NCSC-CH advisories on vCenter, SharePoint, NetScaler and GeoServer inside the week, cited to one post; the hub's own post list shows only SAP, Microsoft Patch Tuesday, Adobe and | Narrowed the summary and the takeaway to the GeoServer advisory the citation actually carries, with the in-week SAP advisory named as the only other hub publica | |
| F3 claim-not-supported | — | The 13-organisation finding and the archive figures were co-cited to Cybersecurity Dive, which carries none of them and says about 15 organisations instead. | Re-cited the finding to Infosecurity Magazine alone, added the divergent count as its own sentence cited to Cybersecurity Dive, and rewrote the sourcing note, w | |
| F3 claim-not-supported | — | The DGFiP press release records the actor claiming access on 12 and 13 August; it says nothing about the dataset being advertised for sale on 12 August. | Rewrote the clause to what the release states — the actor publicly claimed the access on 12 and 13 August. | |
| F3 claim-not-supported | — | SOCRadar says collection activity began before the poisoned packages reached PyPI; the entry said it ended before they were published, which is a stronger claim than the source makes. | Changed to the source's own framing in both the summary and the body. | |
| F3 claim-not-supported | — | The Hacker News gives an unordered enumeration of victim geographies; both entries rendered it as a ranking with Germany largest. | Replaced with the source's enumeration in both entries. | |
| F4 hallucinated-fact | — | Framed as four disclosures inside 2026-W33; three of the four sources are dated 2026-08-07, 2026-07-30 and 2026-08-07, i.e. before the week. | Reframed the title, summary and body as four disclosures this pipeline worked during the week, three published just before it. No fact changed. | |
| F4 hallucinated-fact | — | cves[] carried patch-available and a fixed field asserting a Rockwell fix; the entry's own cited CISA advisory records that the flaw cannot be mitigated with a patch and every remediation is a mitigat | Changed status to no-patch plus mitigation-only, replaced the fixed field with CISA's own statement, and added the point to the body — a reader who took the ret | |
| F4 hallucinated-fact | — | The note asserting W1's 514 figure does not appear in the Dragos report was false: 514 is the report's North America regional total. | Rewrote the note. The outcome stands (the entry needed a country figure and uses the report's US figure of 431 / 38%); the stated reason was wrong and is correc | |
| F14 quantifier-without-source | — | The claim that ReliaQuest published the first post-exploitation detail is refuted by the entry's own cited Foresiet source, which records PTC documenting JSP webshells under the Windchill login direct | Removed the first framing from the title, headline, summary and body; recast as independent corroboration and cited Foresiet for PTC's prior documentation. The | |
| F14 quantifier-without-source | — | The headline said two flaws exploited with no identifier; the body names exactly one. | Corrected to one. | |
| F14 quantifier-without-source | — | The summary said two researchers rebuilt the macOS exploits; the source's two is the number of exploits, produced by one team. | Rewrote as one team rebuilding two exploits from the binary diffs. | |
| F5 missing-citation | — | The load-bearing product-category list is carried by neither cited source; the press release names only the consumer subset. | Added ETSI's own open document store to sources[] and cited the list to it, with a note that the press release carries only the shorter list. | |
| F5 missing-citation | — | The Cl0p bullet was the only one with no inline citation, against the entry's own stated contract that every item carries a source and a date. | Added the BleepingComputer citation and the source record, and folded in the divergent victim count. | |
| F9 surface-contradiction | — | Dragos gives CVE-2021-22681 a CVSS of 9.8 and CISA's advisory 10.0; the entry silently took CISA's number. | Surfaced the discrepancy in the body and the sourcing note — it belongs in an entry whose whole thesis is checking a vendor's CVE detail against the CVE's own r | |
| F9 surface-contradiction | — | Two co-cited sources give 44 and 43 victims and the entry stated 44 without noting it. | Both counts now stated, with the note that neither is a count of confirmed victims. | |
| F10 missed-angle | — | No Russia-nexus content anywhere in the week's output, though a Truesec assessment of 2026-08-14 on GRU Unit 26165 targeting Europe's Ukraine defence supply chain including logistics was fetched by a | Published as a fifteenth entry, weekly-w33-russia-europe-ukraine-defence-supply-chain, framed honestly as an assessment resting on reporting Truesec cites rathe | |
| F17 classification | — | Reliability A sits above the B and C outlets carrying the entry's load-bearing exploitation findings, and above the sibling entry built on the same source set. | Lowered to B. | |
| F17 classification | — | Reliability A is contradicted by a no-fix bullet resting on an aggregator blog that is not tracked in sources.json at all. | Lowered to B. | |
| F11 editorial-advisory | — | The six-flaws-with-no-fix count did not match either entry's own enumeration, which adds to eight. | Corrected both entries to eight so the number and the enumeration agree. |
Iteration #? NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=0) · Claude Sonnet 5 · 6m 03s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | — | Fabricated quotation in the entry added after iteration 1: Truesec was quoted as assessing the published addresses as enabling "physical action", where the page reads "possible enabling of future targ | Replaced with the source's actual wording, confirmed by literal-substring check against the saved body. Every remaining quoted passage in the entry was re-check | |
| F11 editorial-advisory | — | Residual frontmatter/body contradiction from iteration 1's fix: the summary still said six flaws with no fix while the headline and body had been corrected to eight. | Summary corrected to eight; the entry now uses one figure in all three places. | |
| F11 editorial-advisory | — | Iteration 1's uniform six-to-eight correction was applied to this entry without checking its own arithmetic, leaving three different counts: title and summary said six, the bullet header said eight, a | Set to seven in title, summary and bullet header, with the bullet explicitly scoped as further flaws beyond the GeoServer item above it. The two entries now dif |
Iteration #? NEEDS_FIXES · 10 findings (truth=6, editorial=1, advisory=3) · Claude Opus 5 · 9m 11s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F1 hallucinated-fact | — | Headline and summary asserted a universal three-days-or-less interval across all five products; the entry's own summary states vCenter at five days, and that interval (29 July to 3 August) falls outsi | Headline rescoped to four inside three days and a fifth inside five; the summary's opening sentence now says the five were reported under exploitation close beh | |
| F2 quantifier-without-source | — | The title's and headline's count of ten flaws crossing into exploitation or the catalogue is not what the entry enumerates: its own list names eight, CVE-2026-45659 is explicitly excluded by the summa | Both corrected to eight. This is the third derived count in this entry to have failed its own enumeration, after the no-identifier count and the no-fix count. | |
| F3 quantifier-without-source | — | A body paragraph announced four items and then enumerated five, the fifth being CVE-2026-71362. | Corrected to five. | |
| F4 hallucinated-fact | — | The title, headline and opening sentence claimed that in every case the compromised organisation and the notifying organisation were different bodies; four of the entry's own seven cases refute it — D | Retitled and rewritten to the pattern the evidence actually establishes: a third party on the access path, holding the data, or owning the outsourced control in | |
| F5 hallucinated-fact | — | Two derived counts in the published notes were wrong: the citation-discipline assertion covered fourteen entries when fifteen published, and the excluded one was the entry whose quotation the second i | Both corrected, and the citation-discipline paragraph now states plainly that the literal-substring check ran before composition for the first fourteen entries | |
| F6 hallucinated-fact | — | The drop note claimed the ICO/ACRO reprimand and the UNC5537 guilty plea were both carried inside the sector-patterns entry; UNC5537 appears in no entry of this run. | Rewritten: ACRO is carried there, and the UNC5537 guilty plea is recorded as a straight drop with its own reason — a law-enforcement outcome on a 2024 campaign | |
| F7 missing-citation | — | The entry's only home-region hook — that Switzerland's NCSC advised its constituency on the same Power Pages configuration class on 4 August — was asserted twice with no citation, no source record and | Cited inline to the NCSC-CH Cyber Security Hub advisory, added to sources[] and to references[] via the operational entry that covered it, with the sourcing not | |
| F8 editorial-advisory | — | The BleepingComputer SAP article carrying the entry's first evidence quote was cited inline but absent from sources[], understating the machine-consumed source list. | Source record added. | |
| F9 editorial-advisory | — | Both entries derive a load-bearing count from the NatJack operational entry without referencing it, though both reference every other contributing entry. | Added to both references[] lists. | |
| F10 editorial-advisory | — | Workflow-internal language in a sourcing note, which the site build renders verbatim to readers. | Rephrased without the pipeline mechanics, and the body's opening sentence — which addressed the week's other entries rather than the subject and read oddly on a |
Iteration #? NEEDS_FIXES · 3 findings (truth=2, editorial=1, advisory=0) · Claude Sonnet 5 · 6m 49s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F14 quantifier-without-source | — | The corrected headline still conflated two different clocks. CVE-2026-65400 was counted among the products exploited inside three days, but Apple patched it out of band on 6 August and NCSC-NL confirm | Rewritten to separate the two clocks the entry had been merging: time from disclosure to observed exploitation, and time from disclosure to a working exploit. T | |
| F14 quantifier-without-source | — | The same conflation recurred independently here: the title said three flaws crossed into exploitation within seventy-two hours and the body named CVE-2026-65400 as one of them. | Corrected to two, with the macOS case restated in the same sentence as the third whose exploit was rebuilt from the patch diff in four hours but whose confirmed | |
| F11 editorial-advisory | — | The body prose named 16 of the 17 draft standard categories, folding two distinct smart-home standards into one; the frontmatter count of 17 is correct. | Both smart-home categories now named separately, so the prose list reconciles with the count. |
Iteration #? NEEDS_FIXES · 10 findings (truth=9, editorial=1, advisory=1) · Claude Opus 5 · 17m 32s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | Two facts in the MyDr paragraph were attributed to the wrong co-cited outlet in both directions: the 2 TB figure and the Deputy Prime Minister title belong to Gazeta Prawna but were cited to Notes fro | Both citations swapped and the clause split so each figure sits with the outlet that carries it. | |
| F14 quantifier-without-source | — | Summary and body said seven European disclosures; the entry enumerates six and carries six incident keys. The apparent seventh, bol.com, is a downstream notification arising from the CEVA intrusion ra | Corrected to six in the title, summary and body. | |
| F4 hallucinated-fact | — | The 12,000-facility count, which the title, headline and a bullet all turn on, was cited to a source that does not carry it, and the source that does was not among the entry's sources at all. | Notes from Poland added to sources[] and the count cited to it, with the regulator's notification-duty finding left with Gazeta Prawna. | |
| F14 quantifier-without-source | — | Both entries described CVE-2026-68820 as the sole exploitation-detected flaw in August's Microsoft updates; the only source cited on the clause is the Check Point analysis, which says nothing about th | The quantifier dropped in both entries; each now states only that the flaw was exploitation-detected and fixed in those updates, which the cited source supports | |
| F3 claim-not-supported | — | The Adobe Commerce exploitation clause was cited to Adobe's own bulletin, which states Adobe is not aware of any exploits in the wild; the blocking observation is Sansec's, and Sansec was not in the e | Sansec added to sources[] and the clause attached to it, with Adobe's own not-aware-of-exploits statement now carried explicitly alongside so the divergence is | |
| F3 claim-not-supported | — | The BleepingComputer quotation was not a contiguous substring of the page and dropped the outlet's hedge, converting a qualified attribution into a flat one — in the entry whose subject is the gap bet | Replaced with the outlet's verbatim sentence, retaining 'likely'. | |
| F14 quantifier-without-source | — | The summary said two in-window deltas over a body, title and structure that all carry three. | Corrected to three. | |
| F3 claim-not-supported | — | The four-hour exploit build was dated six days before the exploitation confirmation; the researchers' own timeline puts the work on 8 August, four days before it. Six days before the confirmation is t | Corrected to four days, with the date stated explicitly so the two clocks cannot be re-merged. | |
| F5 missing-citation | — | The claim that the SAP fix only takes effect after a rebuild and redeploy carried no citation; neither the NCSC-NL advisory nor the BleepingComputer article mentions it, and the vendor analysis that d | Onapsis added to sources[] and the claim cited to it. | |
| F11 editorial-advisory | — | The summary's assertion that the trigger differed every time is an absolute the entry's own enumeration refutes — it names four trigger types across five products, and two of them are the same class. | Softened to no two triggers being quite the same. |
Iteration #? NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 3m 47s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | The previous iteration's citation swap was applied to the figures but not to the ministerial title: 'Deputy Prime Minister' remained bound to the Notes from Poland citation, which only ever calls Gawk | The title dropped and the minister named as Notes from Poland describes him, so the clause matches the outlet cited on it. | |
| F4 hallucinated-fact | — | The previous iteration's four-days correction was applied to the summary but not to the body, leaving the entry self-contradicting: the summary said four days before the confirmation and the body stil | Body corrected to four days, so summary and body now agree and both match the sources. |
Iteration #? NEEDS_FIXES cap-breach · 3 findings (truth=2, editorial=0, advisory=1) · Claude Opus 5 · 3m 45s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | The previous iteration moved the minister's title but left the 19-million figure attributed to him. Notes from Poland quotes Gawkowski on the incident's significance, not its size; the figure is the o | Body, summary and sourcing note rewritten so the figure is the reporting outlets' and the minister is quoted on significance only. | |
| F14 quantifier-without-source | — | The seven-to-six disclosure correction from iteration 5 was not carried into the count derived from it: headline, summary and body still said the notification duty was displaced in three cases, while | Corrected to two in the headline, summary and body, with the bol.com relationship stated as downstream of CEVA rather than as a third case. | |
| F11 editorial-advisory | — | The four-day interval had no anchor date in the body, so body-only arithmetic against the preceding citation label gave the wrong endpoint. The fact itself is correct. | Anchor date added — the sentence now names 12 August explicitly. |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-08-16T2315Z-weekly · weekly · Opus 5 · 15 entries published
Verification & coverage notes
Week covered. ISO week 2026-W33, Monday 2026-08-10 through Sunday 2026-08-16, seven days since the previous weekly record. The week's operational output was 61 entries across six run days — 26 vulnerability, 15 threat, 14 incident, 6 research, of which 24 were updates and 6 were deep dives; 28 carried high priority and none carried critical. No run record exists for 2026-08-14 and no entry carries that discovery date; the fire of 2026-08-15 covered the gap with a widened window.
Duplicate-week guard. Run at preflight and again before the first verifier spawn, against origin/main and against every unpromoted claude/** feature branch. No -weekly record carrying week: 2026-W33 exists on either surface. This run is the primary for the week.
ATT&CK pin. tools/attack_data.py --check reports: up to date, local v19.2 equals upstream latest v19.2. No update required and none performed.
Sub-agent research. Both W1 and W2 returned inside the 45-minute cap. Both reported running on Sonnet 5 from the model line in their own system prompts, consistent with the research definition's pin. No W3: intel/ carries no dated drop directories.
Three sub-agent findings were corrected against their own primaries before composition. Each is recorded because the correction, not the finding, is what shipped.
- W1 reported that the SpecterOps Entra ID replay weakness "persists". The cited write-up says the opposite: SpecterOps has not retested since June but "now considers the full Windows-to-Entra vulnerability chain broken" because Microsoft's July 2026 updates make event-log assertions unusable for replay, and Microsoft told the outlet it has also applied mitigations on the relay-assertion side. The entry was composed as a closure, not an open exposure, and its priority set accordingly.
- W1 reported "North America still the largest absolute total (514)". The 514 figure is genuine — it is the report's North America regional total — but the surrounding claim is not: Dragos records North America as the second-most impacted region, and the entry needed a country figure, which the report gives as the United States at 431 incidents, or 38%. The entry uses 431 / 38%. (This note itself was corrected after the first verification iteration, which caught the original wording asserting the 514 figure did not appear in the report at all.)
- W1's framing implied a European nexus for the Jewelbug watering hole. Symantec states the campaign reached more than 15 government webmail tenants "in a Middle Eastern country". The planned entry lens was re-scoped from geography to technique class, with the European nexus carried only by the Lazarus case, where Check Point states successful targeting in France and Germany.
A fourth, smaller correction: W2 wrote that ETSI submitted the draft standards to "all 41 European Economic Area member organisations"; the press release says "41 member organisations across Europe, including the national standardisation bodies of the European Economic Area", and the entry uses the source's phrasing.
A published vendor claim is reported as contradicted rather than resolved. Dragos's 2026-08-13 water-sector retrospective attributes the Minnesota MicroLogix intrusions to CVE-2021-22681. The catalogue date it gives is correct — CISA added that CVE on 2026-03-05 — but the CVE's own National Vulnerability Database record enumerates CompactLogix, ControlLogix, DriveLogix, Compact GuardLogix, GuardLogix and SoftLogix controllers reached through Studio 5000 Logix Designer or RSLogix 5000, and the string "MicroLogix" does not appear in it. Both records were fetched directly this run. The entry states the discrepancy from the primary records, carries verification: contradicted, does not assert what actually happened in Minnesota, and notes that Dragos has not been asked for comment and may hold information not in the published piece.
Entity-overlap confirmations (the gate asks for these explicitly). Twelve of the fifteen entries carry entity keys at all, and the gate flagged fourteen overlaps among them against earlier strategic or operational entries. Every one is a deliberate new-story decision, not a missed update_of, and the weekly dedup rule sanctions a weekly-long-running status entry as the alternative to an update note:
actor:clop/campaign:clop-windchill-flexplm-extortion-2026on the Windchill status entry, against the W31 and W32 looking-ahead entries — an outlook bullet listing a campaign as pending is not a treatment of it. No prior weekly carried a Windchill status entry, and this one has two deltas (first victim responses, first post-exploitation detail).actor:exfilsquadandincident:uk-dfe-exfilsquad-breach-2026-07on the ExfilSquad status entry, against W31's incidents recap — that entry covered four actors' claims collectively and recorded a fabrication assessment; this is a dedicated status entry reporting that a different vendor validated the data at file level. The delta is the reversal.policy:eu-cyber-resilience-act,policy:netherlands-nis2-cyberbeveiligingswet-2026,policy:switzerland-isv-federal-isms-deadline-2026,incident:mydr-poland-ehr-breach-2026and the Cl0p keys on the looking-ahead entry — the outlook is a watch list by construction and necessarily re-references entities treated elsewhere in the same week. It carries no new claim about any of them.actor:qilinandactor:akiraon the Q2 reports entry, against the W31 incidents recap and two operational entries — the reports are a landscape treatment naming these actors as volume leaders in a quarterly count, which is not the same story as any incident they appear in.actor:qilinon the sector-patterns entry, against W31's incidents recap — Qilin appears there only as the claimant of the Retelit intrusion, which is one of seven cases in a pattern about processor and supplier position.actor:teampcpon the developer-credentials entry, against the Wiz H1 report entry of 2026-08-08 — the shared key is incidental; the new story is SOCRadar's re-attribution of the victim population to the Trivy compromise.
Borderline drops.
- borderline-drop: Recorded Future — malware crypting-service market survey (24 named providers, tiered pricing) — a survey of criminal service pricing whose defender-facing conclusion, prefer behavioural indicators to static signatures, does not change what an already-highly-skilled Tier 2/3 responder detects, hunts or hardens. Single-source, and the named-vendor and pricing detail is inventory rather than tradecraft.
- borderline-drop: NCSC UK — water-sector worked example added to the Secure Connectivity Principles for OT — voluntary guidance carrying no obligation and dating no compliance clock, which is this domain's own stated inclusion bar; the sub-agent flagged it borderline on the same grounds. A prior weekly already carried the four-nation OT isolation guidance in the same lane, and NCSC UK states the example is not intended to prescribe an architecture.
- borderline-drop: a separate incidents-recap entry pairing the ICO/ACRO reprimand with the UNC5537 guilty plea as retrospective accountability — two items is too thin a pattern to carry a section. ACRO is carried inside the sector-patterns entry, where its outsourced-patching-without-an-owner root cause is the strongest single instance of that entry's own lens. The UNC5537 guilty plea is a straight drop: it is a law-enforcement outcome on a 2024 campaign whose operational lesson — SaaS tenants reachable with valid credentials and no enforced multi-factor authentication — this store already carries, and it adds no in-window defender decision.
weekly-incidents-recapis legitimately empty this week. (This note was corrected at the third verification iteration, which found it asserting a disposition the output did not implement.)
Tracked waves that produced no in-window delta and therefore ship nothing: the Joomla third-party extension disclosure wave (no in-window disclosure found), the npm and developer-ecosystem supply-chain wave including Shai-Hulud/CHAINDROP (no in-window delta beyond the Trivy re-attribution, which is carried in the developer-credentials research entry), and ShinyHunters (no in-window development). Recording these explicitly so their absence reads as a checked result rather than an unswept domain.
Single-source items and carve-outs.
- Single-source:
weekly-w33-passkey-fourth-thread-documented-and-closed— one outlet's write-up, which quotes SpecterOps and carries Microsoft's response directly. The researcher's own talk page was located but no publication date could be established from its metadata, so it was not cited rather than being cited with an inferred date. This is the deliberate opposite of the prior weekly's handling, which dropped the thread entirely for want of any citable source. - Single-source-national-cert:
weekly-w33-dutch-nis2-in-force-no-transition— NCSC-NL is the first-party authority for the legal-effect date in its own jurisdiction; Dutch compliance press corroborates the date independently. The absence of a transition window is stated as an absence in the guidance, not as a positive ruling-out.
Contradiction: weekly-w33-water-plc-lockout-status — Dragos names CVE-2021-22681 as the Minnesota exploitation vector; the NVD record and the CISA catalogue entry for that CVE name a different Rockwell controller family. The entry reports both and resolves neither.
Reduced-confidence inclusions. The Cl0p Windchill status entry and the ExfilSquad status entry both carry confidence: medium. In the first, the 44 named listings are the actor's claims and neither responding organisation attributes its incident to the Windchill flaw; the possible link between an earlier masked batch and this campaign is one vendor's assessment from advertised data categories, and that vendor states leak-site data cannot establish an access route. In the second, the Power Pages access path is explicitly Fortra's leading theory and no named victim has confirmed it as its own entry point.
Citation-date and per-fact attribution discipline. Every inline citation date in the fifteen entries is either the publication date read from a source fetched by this run or the date recorded verbatim in a referenced operational entry's own source record; no date was taken from a discovery timestamp. Twenty primaries were fetched and written to work/2026-08-16T2315Z-weekly/raw/ this run, and every quoted passage was literal-substring-checked against the saved body. That check was applied to the first fourteen entries before they were written and to the fifteenth only after composition — which is how a spliced quotation reached it, caught at the second verification iteration and repaired; every quotation in that entry was then re-checked, and the third iteration re-checked them again against the live page.
Two primaries could not be re-fetched and both are recorded in fetch_failures above with the substitute path taken. Neither left a claim unsourced.
Watchlist. The organization profile configures no product and no supplier watchlist, so both sweeps are no-ops and no watchlist line is emitted.
Coverage gaps: prodaft (reader pool at HTTP 402, ninth consecutive run; direct fetch returns a JS-only shell); ccn-cert-es (unreachable on three probed paths, reader exhausted); ec-digital-strategy-newsroom (reader-pinned, not attempted beyond the pool probe); cisa-directives and eurojust and consilium-eu-cyber-sanctions (direct 403 plus exhausted reader — searches found no in-window publication for any of the three); edpb, ccb-belgium, cert-at (reachable, but no items published inside the window); sans-ics, searchlight-cyber, team-cymru, withsecure-labs, nozomi-networks, claroty-team82, shadowserver, citizen-lab, esentire, google-tag (swept, no in-window items).
The reader credit pool is exhausted and it is now shaping coverage. All seven keys returned HTTP 402 throughout. This run converted two of the resulting failures into permanent fixes rather than logging them again — ico-uk was pinned to the reader when the generic bridge reaches it directly, and fbi-cyber-alerts pointed at a path that no longer resolves when the IC3 public service announcement listing does. Both were re-probed after the change and both return content. ccn-cert-es and prodaft remain genuinely reader-dependent and are left flagged rather than muted: restoring reader credit is an operator item, and acknowledging these warnings is the quality audit's decision, not this run's.
← Operations dashboard · day page 2026-08-16 · run-record contract: docs/pipeline.md