ctipilot.ch

2026-08-17T0413Z-intel

One pipeline fire, in full · intel run of 2026-08-17 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-17/2026-08-17T0413Z-intel.md.

Run telemetry

2026-08-17T0413Z-intel intel prompt v3.31 publish ok
28m 11s duration 2 published 0 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
9m 25s
Tool calls
14 WebFetch8 WebSearch18 bridge
Cited sources
0 of 26 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
12m 24s
Tool calls
5 WebFetch6 WebSearch35 bridge
Cited sources
0 of 32 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
10m 47s
Tool calls
22 WebFetch12 WebSearch6 bridge
Cited sources
1 of 33 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
9m 53s
Tool calls
12 WebFetch8 WebSearch18 bridge
Cited sources
2 of 22 in slice

Verification

✓ double-CLEAN · Sonnet 5 + Opus 5 #1 NEEDS_FIXES · Opus 5 · t=2 e=0 a=3 #2 CLEAN · Sonnet 5 · t=0 e=0 a=0 #3 CLEAN · Opus 5 · t=0 e=0 a=1

Deep dive

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

9 notes-appended · 4 bookkeeping · 1 added-as-candidate.

SourceChangeFrom → ToReason
acronis-truadded-as-candidate— → candidatethis run's single new candidate — the named original-research primary behind one of the two published entries, cited by earlier fires only through republishers; the generic bridge transport reads its post pages in full where a direct fetch is refused
cisa-advisoriesnotes-appended— → reader-pool dependency documentedfourth consecutive run unreachable — direct refusal on every user agent plus an exhausted reader pool; NOT demoted, because a 403 is transport blocking rather than content death and the KEV endpoint carries the exploited-vulnerability surface meanwhile
cisa-directivesnotes-appended— → reader-pool dependency documentedsame condition; rotation-priority source now missed on three consecutive runs, still NOT demoted
cisa-newsnotes-appended— → reader-pool dependency documentedsame cisa.gov condition
siemens-productcert-csafnotes-appended— → mirror path returns 404the documented alternate path through the public CSAF mirror did not resolve the directory the recipe expects; recorded so a future fire re-derives the mirror layout rather than re-probing the same path
ccb-belgiumnotes-appended— → reader-pinned, unreachablepinned to the reader, which was credit-exhausted all run; a quota condition never demotes
venarixnotes-appended— → feed path 404 with reader unavailableclient-rendered listing and a 404 feed; the recipe needs a working reader or a new path, not a demotion
ncsc-ch-focusnotes-appended— → sweep flag is a contention artifacthealth sweep flagged needs-demote as unreachable, but a serial re-probe returned the full listing with dated entries and a research pass had already read the same page directly earlier in the run; NOT demoted
swisscybersecurity-netnotes-appended— → sweep flag is a contention artifactflagged needs-demote after a probe timeout and a stub response through the bridge, but a research pass fetched the listing and drilled a same-day article body in full through the transport already pinned on the record; NOT demoted
ccn-cert-esnotes-appended— → reader-quota casualty reconfirmedevery direct transport returned an empty body this run — the advisories listing, three candidate feed paths and the site root — and the reader that historically works was credit-exhausted; a quota condition never demotes, and the record is deliberately not muted to a blocked method because the host returns the moment credit does
huntressbookkeeping— → last_successful_fetch 2026-08-17, quiet counter resetcontributed the primary source for one published entry
bleepingcomputerbookkeeping— → last_successful_fetch 2026-08-17, quiet counter resetcontributed a corroborating source
securityaffairsbookkeeping— → last_successful_fetch 2026-08-17, quiet counter resetcontributed a corroborating source
hackernewsbookkeeping— → last_successful_fetch 2026-08-17, quiet counter resetcontributed a corroborating source

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
jina-reader-poolhttps://r.jina.ai/ (all seven configured keys)jina402 transport-block
every one of the seven configured reader API keys returned HTTP 402 balance-exhausted and the anonymous tier returned HTTP 403, so the last rung of the fetch la
worked around per host — CISA KEV and the ENISA EUVD endpoints do not route through the reader and carried the exploited-vulnerability surface, and the generic
cisa-advisorieshttps://www.cisa.gov/cybersecurity-advisories/all.xmlbridge:cisa.pagebridge:urlbridge:jinawebsearch403 transport-403
cisa.gov refuses the direct transport on every user agent and the reader fallback was exhausted, so the documented ladder had no last rung; essential-tier miss,
CISA KEV was fetched successfully and its catalogue version showed no new additions since the previous run's coverage; a targeted search sweep surfaced no advis
cisa-directiveshttps://www.cisa.gov/news-events/directivesbridge:cisa.pagebridge:urlbridge:jinawebsearch403 transport-403
same condition as cisa-advisories — direct refusal plus an exhausted reader pool; essential-tier miss and a rotation-priority source now missed on three consecu
no evidence from any other source that a new directive published in-window
siemens-productcert-csafhttps://cert-portal.siemens.com/productcert/csaf/bridge:urlbridge:url (CSAF mirror)websearch403 transport-403
direct refusal with the reader fallback exhausted; the documented alternate path through the public CSAF mirror returned 404 for the directory the recipe expect
a search sweep surfaced only Siemens advisories already four days old and already covered; no in-window Siemens advisory is known to have been lost
ccb-belgiumhttps://ccb.belgium.be/advisoriesjinabridge:url402 transport-block
the source's pinned recipe is the reader, which was credit-exhausted all run; the direct fallback returned cookie-consent and script-shell markup with no dated
no alternate source for this national CERT's advisories in the slice; neighbouring national CERTs were reachable and carried no in-window item this one would ha
cisa-newshttps://www.cisa.gov/news.xmlbridge:urlbridge:jina403 transport-403
same cisa.gov refusal plus the exhausted reader pool
the KEV and EUVD endpoints carried the exploited-vulnerability surface independently
venarixhttps://venarix.com/blogwebfetchbridge:urljina404 recipe-gap
the listing renders client-side with no server-side dated rows, matching the existing recipe note, and the feed path returned 404; the reader escalation that wo
other breach-tracking sources in the slice were reachable and carried the window's leak-site surface

Bridge invocations (this run)

19 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

13 ok6 other
  • url ×12
  • page ×2
  • jina ×2
  • api ×1
  • rss ×1
  • ncsc-csh recent ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 5 findings (truth=2, editorial=0, advisory=3) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
a corroborating source was dated two days earlier than the page's own structured publication stamp, and a second corroborator was dated one day later than its visible datelineboth dates re-read from the run's saved captures — the structured publication stamp and the article dateline — and corrected in sources[]
F3
claim-not-supported
the March 2026 energy-sector campaign was described as later than the Afghan telecom wave, inverting the chronology the cited page states, which also reversed the tooling-evolution reading a responderboth rewritten to the lab's own framing — a different variant used in what the lab calls an earlier campaign, carrying an anti-analysis suite the Afghan-telecom
F11
editorial-advisory
a source-supported behaviour the body describes twice — the implant hiding its console window, and the startup script launching it with a hidden window — had no id in the technique mappingT1564.003 added after confirming it is active in the pinned dataset
F11
editorial-advisory
one sentence said named victims where the cited page states targeting and names no compromised organisation — the organisations it names are impersonation themesrewritten to the source's own framing
F11
editorial-advisory
the store already documented the same actor cluster against the same country in an existing campaign record, with no edge connecting it to the actor key registered this runthe existing campaign entry's own cited reporting states the attribution explicitly, so an attributed-to edge was added on the campaign record sourced to that e

Iteration #3 CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
the decode-and-decrypt stage the body describes ahead of the in-memory execution path had no technique id, though the behaviour is stated by the cited pageT1140 added after confirming it is active in the pinned dataset; the addition is metadata for a behaviour already present in the verified body text, applied aft

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-17T0413Z-intel · Opus 5 · window 24 h · 2 entries published

Verification & coverage notes

A genuinely quiet window. Two of the four research passes returned nothing at all: the vulnerability and national-CERT surface carried no in-window disclosure that was not already published here, and the Swiss and European home-region sweep found no new incident, advisory or regulator action in the last 24 hours. The two entries this run publishes both come from the coverage backlog — verified items an earlier fire surfaced but could not publish — and both were re-researched and re-read from their primaries before composition rather than carried over on the earlier fire's word.

Both are recency-exempt backlog rows, which is why entries dated today rest on sources published on 12 and 13 August: the reason they were unpublished is a pipeline race, not staleness, and each carries its own event date so the reader is not misled about freshness.

  • Coverage backlog: two rows published, three struck, two left open. Published — the Safe Mode ransomware case as 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn, and the Google Sheets command-and-control cluster as 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack. Struck — the ransomware-as-a-service brand row, on relevance after re-reading its primary (claimed victims are concentrated in the United States and Turkey in dental practices, technology and financial services, with no home-region, coverage-focus or profiled-sector nexus; its named tradecraft is ground this store already holds, and its residual insight is an analytic caveat the store's own campaign coverage already carries). The other two struck rows were struck per their own instructions — the operational-technology edge-gateway framing belongs to the weekly's strategic lens with both component vulnerabilities already published, and the browser trust-bridge class row's only concrete step is already published in the 2026-08-16 browser-extension entry.
  • Backlog rows still open: the AI-generated-patch study, still marginal on today's facts and inside its own thirty-day window; and the UK critical-infrastructure infostealer report, retried this run without success — the reporting outlet refuses every transport, the reader proxy is still credit-exhausted, and the vendor's own site carries no matching publication, so the victim count and sector breakdown remain unverifiable. It is not published on headline-level specifics.
  • borderline-drop: French software-as-a-service enterprise-resource-planning vendor cascading extortion campaign — the regional nexus is real but there is no public-sector, government or critical-infrastructure victim, and none of the four out-of-nexus limbs is met: the scale is one vendor's customer base rather than global significance; the mechanism is a vendor-side authorization defect exposed while an old and a new version of a customer portal ran in parallel during a migration, which is a product defect rather than new or materially evolved attacker tradecraft; the extortion handles have no reported targeting of European government or critical infrastructure; and there is no shared imminent exposure. A responder here has no product to patch, no telemetry to hunt and no decision to change. Sourcing is also two lower-reliability breach trackers quoting the vendor's own statement.
  • Both published entries carry single-source rather than multi-source. Each rests on one assessor — an incident-response team and a malware-analysis lab respectively — with two further publishers reporting that same research rather than observing independently. The credibility number is set to 2 for the same reason: extra publishers do not corroborate an assessment, only republish it.
  • Deep dive: none. No candidate reached active in-the-wild exploitation with exposure for this constituency. The strongest candidate clears only the substantive-new-analysis criterion, and its category was used on 2026-08-11, inside the seven-day rotation window, which demotes it a rank and below the bar. Depth was not manufactured to fill an open slot.
  • Two corrections applied during the deep read of the malware-cluster primary, both against the surfacing pass's own summary: the first implant hijacks three browsers through component-object-model interfaces and runs commands through the Windows command interpreter, while the second widens the hijack to six browsers using a generated script and runs commands through PowerShell — the surfacing summary had transposed these. The deep read also recovered a third implant the backlog row did not name, which moves the same tasking into a developer code-sharing service, giving the cluster three distinct command-and-control channels rather than two.
  • Attribution is carried at the level the discovering lab states: a moderate-confidence overlap with a named espionage cluster or a closely related actor, recorded as an overlap edge in the entity registry rather than an attribution. A separate infrastructure fingerprint the lab explicitly declines to treat as an attribution link is reported as such and creates no edge.
  • The reader proxy was credit-exhausted for the third consecutive fire, with all seven configured keys returning a balance error and the anonymous tier refused. This is now the dominant coverage constraint: it is the last rung of the documented fetch ladder, and four sources were lost outright because their recipes depend on it. Both primaries this run publishes were reached through the generic bridge transport instead. This needs operator attention — no run-side recipe change can substitute for the missing credit.
  • The ransomware entry shares its actor key with three earlier in-window entries — a review of a ransom payment at a defence-industry subsidiary, a catalogue of shell command obfuscation on virtualisation hosts, and a quarterly ransomware report. The non-update decision is deliberate and confirmed here: none of the three describes this intrusion, this initial-access route or this evasion step, so a delta note would have had nothing to be a delta on. The shared key is co-occurrence, which the site derives at render time; it is not duplicated coverage.
  • Verification ran three iterations across both models and ended on a confirmed clean result — two consecutive clean verdicts from two different models. The first iteration caught two real defects in the espionage entry, both in the same direction of carelessness about what a source actually says: a citation dated two days off its own publication stamp, and a sentence that inverted the chronology of two campaigns, which would have told a reader the operator's newer samples carry an anti-analysis suite the lab in fact places in the older one. Both were corrected against the saved captures, and the inverted wording was corrected in the entity registry in the same edit. The remaining fixes were a missing technique id for a behaviour the body already described, a sentence saying victims where the source says targeting and names no compromised organisation, and a graph edge connecting an existing campaign record to the actor key registered this run.
  • Source-health sweep: 185 sources probed, three flagged for repair, none demoted. Two were probe artefacts — the Swiss national authority's focus page and a Swiss trade-press site both returned full content to a serial re-probe or to a research pass in the same run, through the transport already recorded on each. The third is the Spanish national CERT, whose every direct transport returned an empty body and whose working transport is the credit-exhausted reader; that is a quota condition, which never demotes. Eight further sources were classed reader-quota by the sweep, the same root cause.
  • Essential-coverage: missed=cisa-advisories (direct refusal, reader pool exhausted), cisa-directives (same condition, third consecutive run).
  • Coverage gaps: cisa-advisories, cisa-directives, cisa-news, siemens-productcert-csaf (all direct refusal with the reader fallback exhausted); ccb-belgium (recipe pinned to the exhausted reader); venarix (client-rendered listing, feed path 404); swisspost-cybersecurity (listing renders to a video asset with no dated articles); group-ib, nozomi-networks, claroty-team82 (listing pages returned content but carry no per-item publication dates, so recency could not be established — a recipe gap, not a transport failure); google-tag (landing page resolves to the general vendor security blog, a known recipe gap); ec-digital-strategy-newsroom (the direct transport succeeded this run, contradicting its reader-only pin, but the listing carries no per-item dates).

← Operations dashboard · run-record contract: docs/pipeline.md