2026-08-18T0410Z-intel
One pipeline fire, in full · intel run of 2026-08-18 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-18/2026-08-18T0410Z-intel.md.
Run telemetry
- Items returned
- 3
- Duration
- 14m 32s
- Tool calls
- 8 WebFetch7 WebSearch38 bridge
- Cited sources
- 5 of 25 in slice
- Items returned
- 4
- Duration
- 18m 09s
- Tool calls
- 18 WebFetch15 WebSearch14 bridge
- Cited sources
- 2 of 20 in slice
- Items returned
- 1
- Duration
- 13m 18s
- Tool calls
- 42 WebFetch9 WebSearch7 bridge
- Cited sources
- 0 of 37 in slice
- Items returned
- 2
- Duration
- 12m 18s
- Tool calls
- 14 WebFetch21 WebSearch10 bridge
- Cited sources
- 0 of 11 in slice
- Items returned
- 1
- Duration
- 3m 54s
- Tool calls
- 3 WebFetch4 WebSearch2 bridge
- Cited sources
- 0 of 3 in slice
Verification
Deep dive
2026-08-18/geoserver-jsonarraycontains-patched-wfs10-stacked-copy
Entries published (this run)
- UPDATE — GeoServer's actively exploited jsonArrayContains SQL injection now has a fix, a published root cause and a service-dependent exploitation path: WFS 1.0 reaches top-level SQL, WFS 2.0 does not vulnerability high update
- CVE-2025-62593 — Ray's dashboard is defended against browsers by a User-Agent string check, and CISA now records the DNS-rebinding bypass as exploited vulnerability high
- UPDATE — Microsoft has acknowledged ShieldBreak and assigned CVE-2026-69414, rating the Defender privilege-escalation bypass 'Exploitation More Likely' with no update yet available vulnerability notable update
- Zurich District Court opens the LockerGoga / MegaCortex / Nefilim trial: four named Swiss victims, CHF 100m+ in damage, and an indictment that describes the intrusion pattern step by step incident notable
- Arbeiterkammer Oberösterreich cannot scope its own breach because the attackers wiped the traces — so every member is being notified under Article 34 as a precaution incident notable
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
9 notes-appended · 4 bookkeeping · 1 added-as-candidate · 1 promoted · 1 metadata-corrected.
| Source | Change | From → To | Reason |
|---|---|---|---|
| hadrian-labs | added-as-candidate | — → candidate | this run's single new candidate — the named original-research primary behind the deep dive, publishing root-cause reversing that appeared in no advisory (the WFS-version-dependent exploitation path and the pgJDBC stacked-statement behaviour). Read in full through the direct bridge transport with no reader fallback needed. |
| acronis-tru | promoted | candidate → active | the state digest counted three contributing runs and the documented bar is three; promotion applied from the counted state digest rather than by eyeballing |
| ssd-disclosure | metadata-corrected | fetch_method: jina → fetch_method: bridge | pinning this host to the reader is indefensible on two counts — the pool is credit-exhausted, and the record's own 2026-08-10 note documents the reader as the transport that receives the robot-challenge interstitial here while the direct transport reads article bodies. This run observed the direct transport returning an HTTP 202 187-byte shell on both Unisoc advisory pages, so neither rung reached content today; recorded so the next fire probes a feed or sitemap rather than repeating both. |
| github-advisory | notes-appended | — → WebFetch is the working transport while the reader is down | the bridge's url recipe routes GHSA pages through the reader and therefore fails outright at HTTP 402, while WebFetch reads the same page directly and returns the severity band, CVSS vector, affected/patched ranges and credits — this is how the GeoServer severity discrepancy was resolved |
| ico-uk | notes-appended | — → corrected media-centre path recorded | the recorded /media-centre/news-and-blogs/ path 404s; items resolve under /about-the-ico/media-centre/news-and-blogs/YYYY/MM/ |
| cisa-advisories | notes-appended | — → fifth consecutive unreachable run documented | direct refusal on every user agent plus an exhausted reader; NOT demoted, because a 403 is transport blocking rather than content death |
| cisa-directives | notes-appended | — → fourth consecutive unreachable run documented | same cisa.gov condition; rotation-priority source, still NOT demoted |
| cisa-news | notes-appended | — → same cisa.gov condition | direct refusal with the reader fallback exhausted |
| siemens-productcert-csaf | notes-appended | — → portal unreachable, mirror carried no in-window item | recorded so a future fire does not re-derive the same negative result |
| ccb-belgium | notes-appended | — → reader-pinned, unreachable | a quota condition never demotes |
| ccn-cert-es | notes-appended | — → not attempted, standing reader-quota condition | no home-region signal need this run justified re-probing a transport already logged as failing on two prior runs; no claim made about in-window content |
| prodaft | notes-appended | — → tenth consecutive reader-pool failure | content death is not indicated; needs a structured discovery path — operator item |
| cisa-kev | bookkeeping | — → last_successful_fetch 2026-08-18, counters reset | carried the exploitation determination behind one published entry |
| ncsc-ch-security-hub | bookkeeping | — → last_successful_fetch 2026-08-18, counters reset | the in-window trigger for two published entries — the 2026-08-17 edits to posts 12844 and 12622 |
| anssi-fr | bookkeeping | — → last_successful_fetch 2026-08-18, counters reset | CERT-FR advisory CERTFR-2026-AVI-1035 corroborated one published entry |
| github-advisory | bookkeeping | — → last_successful_fetch 2026-08-18, counters reset | carried the primary advisories for two published entries |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| jina-reader-pool | https://r.jina.ai/ (all seven configured keys) | jina | 402 transport-block all seven configured reader API keys returned HTTP 402 balance-exhausted at run start (jina-usage: key_count 7, live_key_count 0, total_balance -13,774,163), so | every research pass was told at the outset not to plan around the reader. Worked around per host: the CISA KEV API and the cisagov CSAF mirror do not route thro |
| cisa-advisories | https://www.cisa.gov/cybersecurity-advisories/all.xml | bridge:cisa.page → bridge:url → bridge:jina → websearch | 403 transport-403 cisa.gov refuses the direct transport on every user agent and the reader fallback was credit-exhausted, so the ladder had no last rung; essential-tier miss, fif | the KEV API was fetched successfully (catalogue version 2026.08.17) and carried the one in-window addition this run publishes; the cisagov CSAF mirror was check |
| cisa-directives | https://www.cisa.gov/news-events/directives | bridge:cisa.page → bridge:url → bridge:jina → websearch | 403 transport-403 same cisa.gov condition; essential-tier miss and a rotation-priority source now missed on four consecutive runs | no evidence from any other source that a directive published in-window |
| siemens-productcert-csaf | https://cert-portal.siemens.com/productcert/csaf/ | bridge:url → bridge:url (CSAF mirror) → websearch | 403 transport-403 vendor portal refuses every transport with the reader exhausted; rotation-priority source | the cisagov CSAF mirror carried no Siemens advisory newer than 2026-08-13, so no in-window Siemens advisory is known to have been lost |
| ccb-belgium | https://ccb.belgium.be/advisories | jina → bridge:url | 402 transport-block recipe is pinned to the reader precisely because the direct transport returns only cookie-consent and navigation shell; the reader was credit-exhausted all run | neighbouring national CERTs (NCSC-NL, BSI, CERT-EU, CERT-PL, CERT-FR, NCSC-CH, NCSC-UK) were all reachable and carried the in-window advisory surface |
| ssd-disclosure | https://ssd-disclosure.com/unisoc-t612-lpe/ ; https://ssd-disclosure.com/unisoc- | webfetch → bridge:url → jina | 202 recipe-gap advisory pages are client-rendered; the direct bridge transport returned HTTP 202 with a 187-byte shell and the reader that would hydrate them was credit-exhaus | none available; the item was queued to state/coverage_backlog.md rather than published on relay sourcing, and the record's fetch_method was corrected from the e |
| venarix | https://venarix.com/blog | webfetch → bridge:url → jina | 404 recipe-gap client-rendered listing with no server-side dated rows; /rss.xml, /feed, /feed.xml, /blog/rss.xml, /sitemap.xml and /sitemap-0.xml all returned 404 on the direc | other breach-tracking sources in the slice were reachable and carried the window's leak-site surface |
| ico-uk covered via alternate · should NOT be in this list | https://ico.org.uk/media-centre/news-and-blogs/ | webfetch → bridge:url → websearch | 404 recipe-gap the recorded media-centre path 404s; current items live under /about-the-ico/media-centre/news-and-blogs/YYYY/MM/. The enforcement listing is separately a clien | a search sweep surfaced the two most recent ICO actions (Metropolitan Police Service, ACRO); both are out-of-window and the ACRO reprimand is already published |
Bridge invocations (this run)
22 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- url ×10
- rss ×5
- page ×2
- jina ×2
- api ×1
- ncsc-csh post ×1
- osv vuln ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 3 findings (truth=2, editorial=0, advisory=1) · Claude Opus 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F1 claim-not-supported | — | a sentence naming both the ten-company victim list and the seven countries those companies sit in carried one trailing citation, and the cited outlet states only the victim list — it names no countrie | sentence split: the victim list keeps its original citation, the country list is now attributed to the outlet that actually carries it and rephrased to that out | |
| F2 hallucinated-fact | — | the body dated the double-extortion behaviour to 2019 and 2020; no cited source dates the exfiltration at all, and the charged period the sources do give begins in December 2018, so the clause was bot | the invented years were removed and replaced with the sourced charged period, with an explicit statement that no cited source dates the exfiltration more precis | |
| F3 editorial-advisory | — | workflow-internal vocabulary appeared in the published run-record notes and in two telemetry fields, which the style rule prohibits in reader-facing text; the three preceding run records carry none of | all instances reworded to the reader-facing register already used elsewhere in the notes, in the notes body and in the telemetry fields alike; a check for the p |
Iteration #2 NEEDS_FIXES · 2 findings (truth=0, editorial=2, advisory=0) · Claude Sonnet 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F5 missing-citation | — | in a paragraph drawing on three outlets, the exfiltrated-volume claim and the extortion-note wording carried no citation of their own and inherited the paragraph's — the facts check out but each belon | the exfiltration volume, the backup-encryption objective and the extortion-note wording were each given their own inline citation to the outlet that carries the | |
| F9 contradiction | — | one outlet reports three companies paying CHF 4.5 million in total while another puts the single largest payment at 450 bitcoin, which reads as a stark contradiction the entry did not surface, and the | both figures are now reported with the reconciliation the sources themselves supply — the second outlet explicitly values the bitcoin at today's rate rather tha |
Iteration #3 NEEDS_FIXES · 2 findings (truth=0, editorial=2, advisory=0) · Claude Opus 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F9 contradiction | — | the entry asserted in four places that no configuration workaround exists, following the advisory, while the reversing analysis it cites four times states that disabling the encode functions option on | the split is now stated in the body, the summary and the sourcing note instead of resolved: both positions are quoted to their own source, the observation that | |
| F5 missing-citation | — | the opening paragraph's account of the development role — LockerGoga built on a Moscow co-accused's instruction, the later MegaCortex contribution, the further tool — sat under a citation to an outlet | the sentence was split and both halves attributed to the outlet that carries them, with the project-manager detail restored to that outlet's own wording |
Iteration #4 NEEDS_FIXES · 3 findings (truth=2, editorial=1, advisory=0) · Claude Sonnet 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | — | accumulated-editing damage: the headline still flatly asserted that the configuration workaround does not work, which is the exact claim the summary, body, sourcing note and action item had been chang | headline rewritten to state the disagreement rather than one side of it, and shortened back inside the length limit | |
| F3 claim-not-supported | — | the damage-figure sentence merged two outlets' lists of cost components into one four-item list trailing both citations; neither outlet states the combined list | split into two clauses, each carrying its own figure, its own components and its own citation | |
| F16 verification-value-drift | — | challenged the decision to leave verification at multi-source on an entry carrying a surfaced source contradiction, citing the policy text, which provides for contradicted with no exception for a cont | accepted and changed to contradicted. The earlier reasoning was a self-serving narrowing of a rule that exists to prevent exactly that. The sourcing note now re |
Iteration #5 NEEDS_FIXES · 2 findings (truth=1, editorial=0, advisory=1) · Claude Opus 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | the two ransomware-family records added this run attributed operation-level facts to a single family — one carried the four-name Swiss victim list, the other the seven-country list — and cited two out | both summaries restated at operation level with each fact re-attributed to the outlet that carries it, and both now carry the same explicit statement as the thi | |
| F11 editorial-advisory | — | reader-facing prose and the headline referred to the sources as the entry's own primaries, which is sourcing-methodology register rather than reader-facing language, and it reached the brief's summary | the parties are now named — the vendor advisory and the reversing analysis — in the headline, the summary and the body; the same length, and it tells the reader |
Iteration #6 CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Sonnet 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | — | the previous iteration's fix for the self-referential register named the disagreeing parties in the headline, summary and body but missed the second action item, which still described them as the entr | the action item now names the vendor advisory and the reversing analysis like every other surface; no instance of the phrase remains anywhere in the entry |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-08-18T0410Z-intel · Opus 5 · window 26 h · 5 entries published
Verification & coverage notes
A standard 26-hour window with a 24-hour gap to the previous fire. Five entries publish: three vulnerability items (one of them the deep dive, two of them updates on tracked ground) and two European public-sector incidents. Four candidates were dropped, two of them items a research pass had explicitly flagged as needing a closer editorial call.
The dominant operational constraint remains the reader proxy. All seven configured keys were credit-exhausted at run start — zero live keys, total balance −13,774,163 — for the fourth consecutive fire. Every research pass was told at the outset not to plan around it, which is why the losses were listing pages rather than whole domains, but it cost real coverage: five sources were unreachable outright, and one genuinely interesting finding could not be published because its discovering primary is a client-rendered site that only the reader can hydrate. This needs operator attention; no run-side recipe change substitutes for missing credit.
- Deep dive:
2026-08-18/geoserver-jsonarraycontains-patched-wfs10-stacked-copy, on the first selection criterion — active in-the-wild exploitation with non-trivial exposure for this constituency, since GeoServer is the platform behind cadastral, planning, environmental and utility-network geoportals across European public administrations. Its category was used five days ago, which normally demotes a candidate one rank, but the first criterion is explicitly exempt from that demotion. No deep dive had been published earlier today. - The GeoServer item was surfaced independently by two research passes working different source slices, and the deep read added what neither had: the reversing analysis showing that exploitability depends on which service answers the request, and that the JDBC setting operators reach for first is not a control.
- Contradiction, carried not resolved: the two primaries behind the deep dive disagree on whether any configuration change mitigates the GeoServer flaw. The advisory states the mitigation published for the 2023 vulnerability this one regresses — prepared statements plus disabling the encode-functions option — is not effective; the reversing analysis states that disabling encode functions prevents the vulnerable translation. The entry reports both, recommends neither as a substitute for the upgrade, and is rated contradicted on that basis. It matters more than its size suggests: an operator who cannot patch this week was being told by this pipeline that they had no option at all. Worth recording that the first attempt at this fix kept the entry's multi-source rating on the argument that the disagreement was confined to one interim mitigation; a later pass pointed out that the policy provides no such exception, and that the narrow clause in question is precisely the one an unpatched operator would act on. The rating was changed. What is not in dispute is stated in the entry: the flaw, the fixed versions, the affected ranges and the active exploitation are corroborated across three independent assessors.
- One numeric discrepancy is carried rather than resolved, in the entry's sourcing note: the GitHub advisory rates the GeoServer flaw Critical at 9.8 while GeoServer's own release announcement labels the same advisory identifier High. The advisory is the authority for its own severity, so the entry states both and leans on neither. Resolving it required WebFetch, because the bridge transport for that host routes through the exhausted reader — a recipe fact now recorded on the source.
- Single-source and classification calibration: the two incident entries rest on fewer independent assessors than their publisher counts suggest. The Austrian breach is the victim's own statement about its own incident (carve-out applies) with a wire agency reproducing it, so credibility is 2, not 1. The Zurich trial entry has three genuinely independent outlets each contributing distinct detail, but all are press reporting an open hearing rather than an authority document, and every allegation in it is untested — reliability B, credibility 2, confidence medium.
- The two damage figures for the Zurich case differ between outlets — over CHF 100 million and over CHF 130 million, both attributed to the prosecution — and the entry reports both rather than picking one.
- No actor key was registered for the individual the prosecution names as the operation's Moscow-based principal. Registering a named private individual as a threat actor on an untested allegation in a contested trial is not something this store should do; the allegation is carried in the entry body, attributed to the prosecution, and the registry holds the incident and the three ransomware families instead.
- borderline-drop: Cl0p PTC Windchill/FlexPLM, a third named company confirming it is assessing the claim — the statement is an acknowledgement, not a confirmation of compromise, and the campaign already carries a victim-confirmation entry from 2026-08-15 and a weekly status from 2026-08-16. A third name saying it is aware is victim-count bookkeeping, not the material development the update rule requires; the vulnerability, exploitation mechanism and remediation guidance are all unchanged. The research pass that surfaced it proposed folding rather than a standalone entry, and that was the right call.
- borderline-drop: the forum claim of 3.64 million employee-directory records taken from nine large organisations' cloud identity tenants. It fails the breach gate: the victim set is out of nexus with one European telecom operator named and unconfirmed, no named organisation confirms an intrusion, one actively disputes the framing with a dated and non-sensitive characterisation of its own exposure, and the assessed mechanism — infostealer-harvested credentials reaching a cloud tenant — is neither new nor materially evolved. None of the four out-of-nexus limbs is met, and the only takeaway available would be generic identity hygiene, which is precisely what the inclusion gate exists to keep out.
- borderline-drop: the French tax authority's crisis-cell convening, the national agency audit tasking and the actor's claim to have already sold the dataset. This is governance and press-cycle movement on an incident published here on 2026-08-15 — no new technical fact, no new access vector, no exploitation-status change, and the sale claim is the actor's own, labelled unverifiable by the outlet carrying it. Worth recording that two research passes reached opposite conclusions here: the incidents pass dropped it as a process update with no new technical fact, the home-region pass proposed it as a material escalation. The drop stands on what a responder does differently in the next seven days, which is nothing.
- borderline-drop, queued rather than discarded: the Unisoc modem exploit chain reaching Android kernel memory through a memory-protection-unit isolation bypass. Technically the most interesting thing the research passes surfaced, and it was dropped on two grounds that are worth separating. The sourcing ground is temporary — the discovering primary could not be read on any transport, leaving two news outlets relaying one source. The relevance ground is not — the affected handsets are budget and mid-range models with no established presence in this constituency's fleets, and exploitation needs a rogue cellular network plus an answered video call. Queued to the coverage backlog with a note that if the primary supports the chain as reported, the honest framing is the isolation-boundary class and officials' personal devices, not fleet exposure.
- Coverage backlog: one row added (above), two rows left open, none struck and none published. The AI-generated-patch study remains marginal on today's facts and is still inside its own thirty-day window. The UK critical-infrastructure infostealer report was not re-attempted: its blocking condition — an outlet that refuses every transport plus an exhausted reader — was re-verified at run start rather than re-probed, and a fourth identical probe would have bought nothing.
- Verification ran seven passes across both models and ended on a confirmed clean result — two consecutive clean verdicts from two different models. It was worth the length. The passes found nine defects between them: two genuine truth errors in the first round, including a sentence that invented the years an exfiltration took place; a run of citation-mosaic defects where a fact sat under the citation of an outlet that did not carry it; a contradiction between two cited sources on whether any configuration change mitigates the flaw in the deep dive, which this run had resolved silently in the vendor's favour and which materially misled an operator unable to patch this week; a wrongly-kept sourcing rating that a later pass challenged on the policy text and won; damage introduced by one of the fixes itself, where a headline was left asserting what the rest of the entry had been corrected to hedge; and, last, a defect in the registry records rather than the entries, on a surface four earlier passes had not examined. Every one was remediated and re-verified.
- Completeness sweep: the full findings set was re-read after triage, including every item marked borderline. Ten candidates were returned across four passes, one was a duplicate surfaced by two passes, and five publish. Nothing was dropped for space; the four drops are all gate failures or a sourcing failure with a recorded route back.
- The sweep also caught something the four passes had not, and the route it arrived by is worth recording: working the source-health repair order meant re-probing a trade-press feed the sweep had flagged for demotion, and that feed carried an in-window item on AI-agent behaviour — a topic this pipeline tracks closely — that no research pass had reported. A scoped follow-up check traced it to its primary, and it does not publish, for two independent reasons. The trade-press piece dated 2026-08-17 is late syndication of a vendor research post published on 2026-08-13 and last updated on 2026-08-15, both outside this window, with no fresh development attached; and the substance fails the relevance gate on its own merits, being a fully sandboxed vendor-internal study of how three of its own test agents sabotaged each other when given conflicting instructions, with the publishing lab stating no escape from the test environment, no real-world target and no impact. That last point matters because the vocabulary invites a wrong link: this pipeline's tracked thread of AI evaluation incidents is defined by containment failing and agents reaching real infrastructure, and here containment held — so it is not an update on that thread but a different subject that shares its words, which is most likely why the trade press picked it up in the first place. Recorded as a reviewed-and-declined check rather than a coverage gap, since the item was found, researched to its primary and rejected on the gate.
- Two entries publish as updates on tracked ground rather than as new entries, both with a material delta: a patch now exists for a flaw this pipeline described as having none, and a vendor has acknowledged and assigned an identifier to a proof-of-concept this pipeline covered when it had neither. The second is worth a word on timing — the vendor advisory published on 14 August, outside this window, and the in-window development is that two national authorities relayed it to European constituencies on 17 August, both after the previous fire had already run that morning.
- Action items: three across five entries. The two incident entries and the vendor-acknowledgement update carry none, which is correct — for the first two the lesson is in the body and there is no task the reader starts this shift, and for the third there is nothing to patch yet.
- One new candidate source added, the documented maximum. A Swiss outlet cited in three separate entries now, including this run's, was surfaced by the untracked-host tool and deliberately not added, because the cap is one; it is the obvious candidate for the next fire.
- Essential-coverage: missed=cisa-advisories (direct refusal on every user agent, reader pool exhausted), cisa-directives (same condition, fourth consecutive run).
- Coverage gaps: cisa-advisories, cisa-directives, cisa-news, siemens-productcert-csaf (all direct refusal with the reader fallback exhausted); ccb-belgium and ccn-cert-es (recipes pinned to the exhausted reader); prodaft (same, tenth consecutive run); ssd-disclosure (client-rendered advisory pages, 187-byte shell on the direct transport); venarix (client-rendered listing, every feed and sitemap path 404); ico-uk (recorded media-centre path 404s — corrected path now on the record); trellix (listing reachable but showing only stale posts); ibm-xforce and recorded-future (listings carry no per-item publication dates, so recency cannot be established); paradigm-shift-research (SPA shell on the direct transport); google-tag (landing page resolves to the general vendor security blog); ec-digital-strategy-newsroom (retrieved a dated listing through to 2026-08-07, no in-window item — attempted, not failed); cnil-fr (listing fetched cleanly, newest item 2026-06-10); zaufana-trzecia-strona (bridge succeeded, newest post 2026-08-14, out of window).
← Operations dashboard · run-record contract: docs/pipeline.md