ctipilot.ch

2026-08-16T2315Z-weekly

One pipeline fire, in full · weekly run of 2026-08-16 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-16/2026-08-16T2315Z-weekly.md.

Run telemetry

2026-08-16T2315Z-weekly weekly prompt v3.31 publish ok
52m 30s duration 15 published 4 updates
Claude Opus 5 (claude-opus-5) main agent
W1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
19m 15s
Tool calls
24 WebFetch20 WebSearch9 bridge
Cited sources
4 of 26 in slice
W2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
14m 16s
Tool calls
24 WebFetch24 WebSearch21 bridge
Cited sources
2 of 29 in slice

Verification

#? NEEDS_FIXES · Opus 5 · t=12 e=7 a=1 #? NEEDS_FIXES · Sonnet 5 · t=3 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=6 e=1 a=3 #? NEEDS_FIXES · Sonnet 5 · t=2 e=1 a=0 #? NEEDS_FIXES · Opus 5 · t=9 e=1 a=1 #? NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #? NEEDS_FIXES · Opus 5 · t=2 e=0 a=1

Deep dive

Entries published (this run)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 recipe fix — rss_url set to https://www.recordedfuture.com/feed and fetch_method webfetch -> rss; resolves the discovery-path gap logged on 2026-08-04 (the /research/rss.xml path 404s and the landing page carries no dated listing) · 1 candidate -> active; the state digest counted 10 distinct contributing runs against a 3-run promotion bar · 1 recipe fix — fetch_method jina -> bridge; the reader pin was the cause of the recurring needs-demote flag, and the generic bridge reaches the host directly · 1 recipe fix — url https://www.fbi.gov/investigate/cyber/alerts -> https://www.ic3.gov/PSA, fetch_method bridge; the IC3 public service announcement listing is the reachable publication surface · 1 note only — re-probed on three paths, all unreachable on the direct transport with the reader at HTTP 402; NOT demoted (a quota condition never demotes) and deliberately not muted · 1 note only — ninth consecutive run without a contribution, all reader-pool failures; NOT demoted, flagged as an operator item · 1 note only — discovery should lead with the recorded RSS feed; the HTML listing exposes no titles or dates to WebFetch.

SourceChangeFrom → ToReason
recordedfuture-insiktrecipe fix — rss_url set to https://www.recordedfuture.com/feed and fetch_method webfetch -> rss; resolves the discovery-path gap logged on 2026-08-04 (the /research/rss.xml path 404s and the landing page carries no dated listing)— → —
fortinet-fortiguard-blogcandidate -> active; the state digest counted 10 distinct contributing runs against a 3-run promotion bar— → —
ico-ukrecipe fix — fetch_method jina -> bridge; the reader pin was the cause of the recurring needs-demote flag, and the generic bridge reaches the host directly— → —
fbi-cyber-alertsrecipe fix — url https://www.fbi.gov/investigate/cyber/alerts -> https://www.ic3.gov/PSA, fetch_method bridge; the IC3 public service announcement listing is the reachable publication surface— → —
ccn-cert-esnote only — re-probed on three paths, all unreachable on the direct transport with the reader at HTTP 402; NOT demoted (a quota condition never demotes) and deliberately not muted— → —
prodaftnote only — ninth consecutive run without a contribution, all reader-pool failures; NOT demoted, flagged as an operator item— → —
intel471note only — discovery should lead with the recorded RSS feed; the HTML listing exposes no titles or dates to WebFetch— → —

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
quirso-medium
covered via alternate · should NOT be in this list
https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-iwebfetchurljina402 reader-quotaRecovered the same QUIRSO figures from The Hacker News, which quotes QUIRSO directly and was already a source record on the referenced operational entry; cited
cisa-aa26-222a
covered via alternate · should NOT be in this list
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222aurlbridgejina403 anti-bot-blockcisa.gov hard-403s every direct UA and routes through the reader, which is at HTTP 402 on all keys. The Gunra detail is carried narrowly, exactly as the verifie

Bridge invocations (this run)

8 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

8 other
  • url ×5
  • bridge ×3

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? NEEDS_FIXES · 20 findings (truth=12, editorial=7, advisory=1) · Claude Opus 5 · 20m 36s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F2
generic-url
The 44-listing count was cited to ransomware.live's rolling /v2/recentvictims API endpoint, which returns only the 100 most recent victims and today carries no Cl0p records at all, so the citation canRemoved the API endpoint from sources[]; the count is now attributed to the operational entry that recorded it on 13 August, with BleepingComputer's divergent c
F3
claim-not-supported
The Swiss hook claimed NCSC-CH advisories on vCenter, SharePoint, NetScaler and GeoServer inside the week, cited to one post; the hub's own post list shows only SAP, Microsoft Patch Tuesday, Adobe andNarrowed the summary and the takeaway to the GeoServer advisory the citation actually carries, with the in-week SAP advisory named as the only other hub publica
F3
claim-not-supported
The 13-organisation finding and the archive figures were co-cited to Cybersecurity Dive, which carries none of them and says about 15 organisations instead.Re-cited the finding to Infosecurity Magazine alone, added the divergent count as its own sentence cited to Cybersecurity Dive, and rewrote the sourcing note, w
F3
claim-not-supported
The DGFiP press release records the actor claiming access on 12 and 13 August; it says nothing about the dataset being advertised for sale on 12 August.Rewrote the clause to what the release states — the actor publicly claimed the access on 12 and 13 August.
F3
claim-not-supported
SOCRadar says collection activity began before the poisoned packages reached PyPI; the entry said it ended before they were published, which is a stronger claim than the source makes.Changed to the source's own framing in both the summary and the body.
F3
claim-not-supported
The Hacker News gives an unordered enumeration of victim geographies; both entries rendered it as a ranking with Germany largest.Replaced with the source's enumeration in both entries.
F4
hallucinated-fact
Framed as four disclosures inside 2026-W33; three of the four sources are dated 2026-08-07, 2026-07-30 and 2026-08-07, i.e. before the week.Reframed the title, summary and body as four disclosures this pipeline worked during the week, three published just before it. No fact changed.
F4
hallucinated-fact
cves[] carried patch-available and a fixed field asserting a Rockwell fix; the entry's own cited CISA advisory records that the flaw cannot be mitigated with a patch and every remediation is a mitigatChanged status to no-patch plus mitigation-only, replaced the fixed field with CISA's own statement, and added the point to the body — a reader who took the ret
F4
hallucinated-fact
The note asserting W1's 514 figure does not appear in the Dragos report was false: 514 is the report's North America regional total.Rewrote the note. The outcome stands (the entry needed a country figure and uses the report's US figure of 431 / 38%); the stated reason was wrong and is correc
F14
quantifier-without-source
The claim that ReliaQuest published the first post-exploitation detail is refuted by the entry's own cited Foresiet source, which records PTC documenting JSP webshells under the Windchill login directRemoved the first framing from the title, headline, summary and body; recast as independent corroboration and cited Foresiet for PTC's prior documentation. The
F14
quantifier-without-source
The headline said two flaws exploited with no identifier; the body names exactly one.Corrected to one.
F14
quantifier-without-source
The summary said two researchers rebuilt the macOS exploits; the source's two is the number of exploits, produced by one team.Rewrote as one team rebuilding two exploits from the binary diffs.
F5
missing-citation
The load-bearing product-category list is carried by neither cited source; the press release names only the consumer subset.Added ETSI's own open document store to sources[] and cited the list to it, with a note that the press release carries only the shorter list.
F5
missing-citation
The Cl0p bullet was the only one with no inline citation, against the entry's own stated contract that every item carries a source and a date.Added the BleepingComputer citation and the source record, and folded in the divergent victim count.
F9
surface-contradiction
Dragos gives CVE-2021-22681 a CVSS of 9.8 and CISA's advisory 10.0; the entry silently took CISA's number.Surfaced the discrepancy in the body and the sourcing note — it belongs in an entry whose whole thesis is checking a vendor's CVE detail against the CVE's own r
F9
surface-contradiction
Two co-cited sources give 44 and 43 victims and the entry stated 44 without noting it.Both counts now stated, with the note that neither is a count of confirmed victims.
F10
missed-angle
No Russia-nexus content anywhere in the week's output, though a Truesec assessment of 2026-08-14 on GRU Unit 26165 targeting Europe's Ukraine defence supply chain including logistics was fetched by a Published as a fifteenth entry, weekly-w33-russia-europe-ukraine-defence-supply-chain, framed honestly as an assessment resting on reporting Truesec cites rathe
F17
classification
Reliability A sits above the B and C outlets carrying the entry's load-bearing exploitation findings, and above the sibling entry built on the same source set.Lowered to B.
F17
classification
Reliability A is contradicted by a no-fix bullet resting on an aggregator blog that is not tracked in sources.json at all.Lowered to B.
F11
editorial-advisory
The six-flaws-with-no-fix count did not match either entry's own enumeration, which adds to eight.Corrected both entries to eight so the number and the enumeration agree.

Iteration #? NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=0) · Claude Sonnet 5 · 6m 03s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Fabricated quotation in the entry added after iteration 1: Truesec was quoted as assessing the published addresses as enabling "physical action", where the page reads "possible enabling of future targReplaced with the source's actual wording, confirmed by literal-substring check against the saved body. Every remaining quoted passage in the entry was re-check
F11
editorial-advisory
Residual frontmatter/body contradiction from iteration 1's fix: the summary still said six flaws with no fix while the headline and body had been corrected to eight.Summary corrected to eight; the entry now uses one figure in all three places.
F11
editorial-advisory
Iteration 1's uniform six-to-eight correction was applied to this entry without checking its own arithmetic, leaving three different counts: title and summary said six, the bullet header said eight, aSet to seven in title, summary and bullet header, with the bullet explicitly scoped as further flaws beyond the GeoServer item above it. The two entries now dif

Iteration #? NEEDS_FIXES · 10 findings (truth=6, editorial=1, advisory=3) · Claude Opus 5 · 9m 11s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F1
hallucinated-fact
Headline and summary asserted a universal three-days-or-less interval across all five products; the entry's own summary states vCenter at five days, and that interval (29 July to 3 August) falls outsiHeadline rescoped to four inside three days and a fifth inside five; the summary's opening sentence now says the five were reported under exploitation close beh
F2
quantifier-without-source
The title's and headline's count of ten flaws crossing into exploitation or the catalogue is not what the entry enumerates: its own list names eight, CVE-2026-45659 is explicitly excluded by the summaBoth corrected to eight. This is the third derived count in this entry to have failed its own enumeration, after the no-identifier count and the no-fix count.
F3
quantifier-without-source
A body paragraph announced four items and then enumerated five, the fifth being CVE-2026-71362.Corrected to five.
F4
hallucinated-fact
The title, headline and opening sentence claimed that in every case the compromised organisation and the notifying organisation were different bodies; four of the entry's own seven cases refute it — DRetitled and rewritten to the pattern the evidence actually establishes: a third party on the access path, holding the data, or owning the outsourced control in
F5
hallucinated-fact
Two derived counts in the published notes were wrong: the citation-discipline assertion covered fourteen entries when fifteen published, and the excluded one was the entry whose quotation the second iBoth corrected, and the citation-discipline paragraph now states plainly that the literal-substring check ran before composition for the first fourteen entries
F6
hallucinated-fact
The drop note claimed the ICO/ACRO reprimand and the UNC5537 guilty plea were both carried inside the sector-patterns entry; UNC5537 appears in no entry of this run.Rewritten: ACRO is carried there, and the UNC5537 guilty plea is recorded as a straight drop with its own reason — a law-enforcement outcome on a 2024 campaign
F7
missing-citation
The entry's only home-region hook — that Switzerland's NCSC advised its constituency on the same Power Pages configuration class on 4 August — was asserted twice with no citation, no source record andCited inline to the NCSC-CH Cyber Security Hub advisory, added to sources[] and to references[] via the operational entry that covered it, with the sourcing not
F8
editorial-advisory
The BleepingComputer SAP article carrying the entry's first evidence quote was cited inline but absent from sources[], understating the machine-consumed source list.Source record added.
F9
editorial-advisory
Both entries derive a load-bearing count from the NatJack operational entry without referencing it, though both reference every other contributing entry.Added to both references[] lists.
F10
editorial-advisory
Workflow-internal language in a sourcing note, which the site build renders verbatim to readers.Rephrased without the pipeline mechanics, and the body's opening sentence — which addressed the week's other entries rather than the subject and read oddly on a

Iteration #? NEEDS_FIXES · 3 findings (truth=2, editorial=1, advisory=0) · Claude Sonnet 5 · 6m 49s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F14
quantifier-without-source
The corrected headline still conflated two different clocks. CVE-2026-65400 was counted among the products exploited inside three days, but Apple patched it out of band on 6 August and NCSC-NL confirmRewritten to separate the two clocks the entry had been merging: time from disclosure to observed exploitation, and time from disclosure to a working exploit. T
F14
quantifier-without-source
The same conflation recurred independently here: the title said three flaws crossed into exploitation within seventy-two hours and the body named CVE-2026-65400 as one of them.Corrected to two, with the macOS case restated in the same sentence as the third whose exploit was rebuilt from the patch diff in four hours but whose confirmed
F11
editorial-advisory
The body prose named 16 of the 17 draft standard categories, folding two distinct smart-home standards into one; the frontmatter count of 17 is correct.Both smart-home categories now named separately, so the prose list reconciles with the count.

Iteration #? NEEDS_FIXES · 10 findings (truth=9, editorial=1, advisory=1) · Claude Opus 5 · 17m 32s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
Two facts in the MyDr paragraph were attributed to the wrong co-cited outlet in both directions: the 2 TB figure and the Deputy Prime Minister title belong to Gazeta Prawna but were cited to Notes froBoth citations swapped and the clause split so each figure sits with the outlet that carries it.
F14
quantifier-without-source
Summary and body said seven European disclosures; the entry enumerates six and carries six incident keys. The apparent seventh, bol.com, is a downstream notification arising from the CEVA intrusion raCorrected to six in the title, summary and body.
F4
hallucinated-fact
The 12,000-facility count, which the title, headline and a bullet all turn on, was cited to a source that does not carry it, and the source that does was not among the entry's sources at all.Notes from Poland added to sources[] and the count cited to it, with the regulator's notification-duty finding left with Gazeta Prawna.
F14
quantifier-without-source
Both entries described CVE-2026-68820 as the sole exploitation-detected flaw in August's Microsoft updates; the only source cited on the clause is the Check Point analysis, which says nothing about thThe quantifier dropped in both entries; each now states only that the flaw was exploitation-detected and fixed in those updates, which the cited source supports
F3
claim-not-supported
The Adobe Commerce exploitation clause was cited to Adobe's own bulletin, which states Adobe is not aware of any exploits in the wild; the blocking observation is Sansec's, and Sansec was not in the eSansec added to sources[] and the clause attached to it, with Adobe's own not-aware-of-exploits statement now carried explicitly alongside so the divergence is
F3
claim-not-supported
The BleepingComputer quotation was not a contiguous substring of the page and dropped the outlet's hedge, converting a qualified attribution into a flat one — in the entry whose subject is the gap betReplaced with the outlet's verbatim sentence, retaining 'likely'.
F14
quantifier-without-source
The summary said two in-window deltas over a body, title and structure that all carry three.Corrected to three.
F3
claim-not-supported
The four-hour exploit build was dated six days before the exploitation confirmation; the researchers' own timeline puts the work on 8 August, four days before it. Six days before the confirmation is tCorrected to four days, with the date stated explicitly so the two clocks cannot be re-merged.
F5
missing-citation
The claim that the SAP fix only takes effect after a rebuild and redeploy carried no citation; neither the NCSC-NL advisory nor the BleepingComputer article mentions it, and the vendor analysis that dOnapsis added to sources[] and the claim cited to it.
F11
editorial-advisory
The summary's assertion that the trigger differed every time is an absolute the entry's own enumeration refutes — it names four trigger types across five products, and two of them are the same class.Softened to no two triggers being quite the same.

Iteration #? NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 3m 47s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The previous iteration's citation swap was applied to the figures but not to the ministerial title: 'Deputy Prime Minister' remained bound to the Notes from Poland citation, which only ever calls GawkThe title dropped and the minister named as Notes from Poland describes him, so the clause matches the outlet cited on it.
F4
hallucinated-fact
The previous iteration's four-days correction was applied to the summary but not to the body, leaving the entry self-contradicting: the summary said four days before the confirmation and the body stilBody corrected to four days, so summary and body now agree and both match the sources.

Iteration #? NEEDS_FIXES cap-breach · 3 findings (truth=2, editorial=0, advisory=1) · Claude Opus 5 · 3m 45s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The previous iteration moved the minister's title but left the 19-million figure attributed to him. Notes from Poland quotes Gawkowski on the incident's significance, not its size; the figure is the oBody, summary and sourcing note rewritten so the figure is the reporting outlets' and the minister is quoted on significance only.
F14
quantifier-without-source
The seven-to-six disclosure correction from iteration 5 was not carried into the count derived from it: headline, summary and body still said the notification duty was displaced in three cases, while Corrected to two in the headline, summary and body, with the bol.com relationship stated as downstream of CEVA rather than as a third case.
F11
editorial-advisory
The four-day interval had no anchor date in the body, so body-only arithmetic against the preceding citation label gave the wrong endpoint. The fact itself is correct.Anchor date added — the sentence now names 12 August explicitly.

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-16T2315Z-weekly · weekly · Opus 5 · 15 entries published

Verification & coverage notes

Week covered. ISO week 2026-W33, Monday 2026-08-10 through Sunday 2026-08-16, seven days since the previous weekly record. The week's operational output was 61 entries across six run days — 26 vulnerability, 15 threat, 14 incident, 6 research, of which 24 were updates and 6 were deep dives; 28 carried high priority and none carried critical. No run record exists for 2026-08-14 and no entry carries that discovery date; the fire of 2026-08-15 covered the gap with a widened window.

Duplicate-week guard. Run at preflight and again before the first verifier spawn, against origin/main and against every unpromoted claude/** feature branch. No -weekly record carrying week: 2026-W33 exists on either surface. This run is the primary for the week.

ATT&CK pin. tools/attack_data.py --check reports: up to date, local v19.2 equals upstream latest v19.2. No update required and none performed.

Sub-agent research. Both W1 and W2 returned inside the 45-minute cap. Both reported running on Sonnet 5 from the model line in their own system prompts, consistent with the research definition's pin. No W3: intel/ carries no dated drop directories.

Three sub-agent findings were corrected against their own primaries before composition. Each is recorded because the correction, not the finding, is what shipped.

  • W1 reported that the SpecterOps Entra ID replay weakness "persists". The cited write-up says the opposite: SpecterOps has not retested since June but "now considers the full Windows-to-Entra vulnerability chain broken" because Microsoft's July 2026 updates make event-log assertions unusable for replay, and Microsoft told the outlet it has also applied mitigations on the relay-assertion side. The entry was composed as a closure, not an open exposure, and its priority set accordingly.
  • W1 reported "North America still the largest absolute total (514)". The 514 figure is genuine — it is the report's North America regional total — but the surrounding claim is not: Dragos records North America as the second-most impacted region, and the entry needed a country figure, which the report gives as the United States at 431 incidents, or 38%. The entry uses 431 / 38%. (This note itself was corrected after the first verification iteration, which caught the original wording asserting the 514 figure did not appear in the report at all.)
  • W1's framing implied a European nexus for the Jewelbug watering hole. Symantec states the campaign reached more than 15 government webmail tenants "in a Middle Eastern country". The planned entry lens was re-scoped from geography to technique class, with the European nexus carried only by the Lazarus case, where Check Point states successful targeting in France and Germany.

A fourth, smaller correction: W2 wrote that ETSI submitted the draft standards to "all 41 European Economic Area member organisations"; the press release says "41 member organisations across Europe, including the national standardisation bodies of the European Economic Area", and the entry uses the source's phrasing.

A published vendor claim is reported as contradicted rather than resolved. Dragos's 2026-08-13 water-sector retrospective attributes the Minnesota MicroLogix intrusions to CVE-2021-22681. The catalogue date it gives is correct — CISA added that CVE on 2026-03-05 — but the CVE's own National Vulnerability Database record enumerates CompactLogix, ControlLogix, DriveLogix, Compact GuardLogix, GuardLogix and SoftLogix controllers reached through Studio 5000 Logix Designer or RSLogix 5000, and the string "MicroLogix" does not appear in it. Both records were fetched directly this run. The entry states the discrepancy from the primary records, carries verification: contradicted, does not assert what actually happened in Minnesota, and notes that Dragos has not been asked for comment and may hold information not in the published piece.

Entity-overlap confirmations (the gate asks for these explicitly). Twelve of the fifteen entries carry entity keys at all, and the gate flagged fourteen overlaps among them against earlier strategic or operational entries. Every one is a deliberate new-story decision, not a missed update_of, and the weekly dedup rule sanctions a weekly-long-running status entry as the alternative to an update note:

  • actor:clop / campaign:clop-windchill-flexplm-extortion-2026 on the Windchill status entry, against the W31 and W32 looking-ahead entries — an outlook bullet listing a campaign as pending is not a treatment of it. No prior weekly carried a Windchill status entry, and this one has two deltas (first victim responses, first post-exploitation detail).
  • actor:exfilsquad and incident:uk-dfe-exfilsquad-breach-2026-07 on the ExfilSquad status entry, against W31's incidents recap — that entry covered four actors' claims collectively and recorded a fabrication assessment; this is a dedicated status entry reporting that a different vendor validated the data at file level. The delta is the reversal.
  • policy:eu-cyber-resilience-act, policy:netherlands-nis2-cyberbeveiligingswet-2026, policy:switzerland-isv-federal-isms-deadline-2026, incident:mydr-poland-ehr-breach-2026 and the Cl0p keys on the looking-ahead entry — the outlook is a watch list by construction and necessarily re-references entities treated elsewhere in the same week. It carries no new claim about any of them.
  • actor:qilin and actor:akira on the Q2 reports entry, against the W31 incidents recap and two operational entries — the reports are a landscape treatment naming these actors as volume leaders in a quarterly count, which is not the same story as any incident they appear in.
  • actor:qilin on the sector-patterns entry, against W31's incidents recap — Qilin appears there only as the claimant of the Retelit intrusion, which is one of seven cases in a pattern about processor and supplier position.
  • actor:teampcp on the developer-credentials entry, against the Wiz H1 report entry of 2026-08-08 — the shared key is incidental; the new story is SOCRadar's re-attribution of the victim population to the Trivy compromise.

Borderline drops.

  • borderline-drop: Recorded Future — malware crypting-service market survey (24 named providers, tiered pricing) — a survey of criminal service pricing whose defender-facing conclusion, prefer behavioural indicators to static signatures, does not change what an already-highly-skilled Tier 2/3 responder detects, hunts or hardens. Single-source, and the named-vendor and pricing detail is inventory rather than tradecraft.
  • borderline-drop: NCSC UK — water-sector worked example added to the Secure Connectivity Principles for OT — voluntary guidance carrying no obligation and dating no compliance clock, which is this domain's own stated inclusion bar; the sub-agent flagged it borderline on the same grounds. A prior weekly already carried the four-nation OT isolation guidance in the same lane, and NCSC UK states the example is not intended to prescribe an architecture.
  • borderline-drop: a separate incidents-recap entry pairing the ICO/ACRO reprimand with the UNC5537 guilty plea as retrospective accountability — two items is too thin a pattern to carry a section. ACRO is carried inside the sector-patterns entry, where its outsourced-patching-without-an-owner root cause is the strongest single instance of that entry's own lens. The UNC5537 guilty plea is a straight drop: it is a law-enforcement outcome on a 2024 campaign whose operational lesson — SaaS tenants reachable with valid credentials and no enforced multi-factor authentication — this store already carries, and it adds no in-window defender decision. weekly-incidents-recap is legitimately empty this week. (This note was corrected at the third verification iteration, which found it asserting a disposition the output did not implement.)

Tracked waves that produced no in-window delta and therefore ship nothing: the Joomla third-party extension disclosure wave (no in-window disclosure found), the npm and developer-ecosystem supply-chain wave including Shai-Hulud/CHAINDROP (no in-window delta beyond the Trivy re-attribution, which is carried in the developer-credentials research entry), and ShinyHunters (no in-window development). Recording these explicitly so their absence reads as a checked result rather than an unswept domain.

Single-source items and carve-outs.

  • Single-source: weekly-w33-passkey-fourth-thread-documented-and-closed — one outlet's write-up, which quotes SpecterOps and carries Microsoft's response directly. The researcher's own talk page was located but no publication date could be established from its metadata, so it was not cited rather than being cited with an inferred date. This is the deliberate opposite of the prior weekly's handling, which dropped the thread entirely for want of any citable source.
  • Single-source-national-cert: weekly-w33-dutch-nis2-in-force-no-transition — NCSC-NL is the first-party authority for the legal-effect date in its own jurisdiction; Dutch compliance press corroborates the date independently. The absence of a transition window is stated as an absence in the guidance, not as a positive ruling-out.

Contradiction: weekly-w33-water-plc-lockout-status — Dragos names CVE-2021-22681 as the Minnesota exploitation vector; the NVD record and the CISA catalogue entry for that CVE name a different Rockwell controller family. The entry reports both and resolves neither.

Reduced-confidence inclusions. The Cl0p Windchill status entry and the ExfilSquad status entry both carry confidence: medium. In the first, the 44 named listings are the actor's claims and neither responding organisation attributes its incident to the Windchill flaw; the possible link between an earlier masked batch and this campaign is one vendor's assessment from advertised data categories, and that vendor states leak-site data cannot establish an access route. In the second, the Power Pages access path is explicitly Fortra's leading theory and no named victim has confirmed it as its own entry point.

Citation-date and per-fact attribution discipline. Every inline citation date in the fifteen entries is either the publication date read from a source fetched by this run or the date recorded verbatim in a referenced operational entry's own source record; no date was taken from a discovery timestamp. Twenty primaries were fetched and written to work/2026-08-16T2315Z-weekly/raw/ this run, and every quoted passage was literal-substring-checked against the saved body. That check was applied to the first fourteen entries before they were written and to the fifteenth only after composition — which is how a spliced quotation reached it, caught at the second verification iteration and repaired; every quotation in that entry was then re-checked, and the third iteration re-checked them again against the live page.

Two primaries could not be re-fetched and both are recorded in fetch_failures above with the substitute path taken. Neither left a claim unsourced.

Watchlist. The organization profile configures no product and no supplier watchlist, so both sweeps are no-ops and no watchlist line is emitted.

Coverage gaps: prodaft (reader pool at HTTP 402, ninth consecutive run; direct fetch returns a JS-only shell); ccn-cert-es (unreachable on three probed paths, reader exhausted); ec-digital-strategy-newsroom (reader-pinned, not attempted beyond the pool probe); cisa-directives and eurojust and consilium-eu-cyber-sanctions (direct 403 plus exhausted reader — searches found no in-window publication for any of the three); edpb, ccb-belgium, cert-at (reachable, but no items published inside the window); sans-ics, searchlight-cyber, team-cymru, withsecure-labs, nozomi-networks, claroty-team82, shadowserver, citizen-lab, esentire, google-tag (swept, no in-window items).

The reader credit pool is exhausted and it is now shaping coverage. All seven keys returned HTTP 402 throughout. This run converted two of the resulting failures into permanent fixes rather than logging them again — ico-uk was pinned to the reader when the generic bridge reaches it directly, and fbi-cyber-alerts pointed at a path that no longer resolves when the IC3 public service announcement listing does. Both were re-probed after the change and both return content. ccn-cert-es and prodaft remain genuinely reader-dependent and are left flagged rather than muted: restoring reader credit is an operator item, and acknowledging these warnings is the quality audit's decision, not this run's.

← Operations dashboard · day page 2026-08-16 · run-record contract: docs/pipeline.md