ctipilot.ch

2026-08-22T0410Z-intel

One pipeline fire, in full · intel run of 2026-08-22 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-22/2026-08-22T0410Z-intel.md.

Run telemetry

2026-08-22T0410Z-intel intel prompt v3.32 publish ok
53h 09m duration 8 published 2 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
9
Duration
20m 22s
Tool calls
26 WebFetch12 WebSearch24 bridge
Cited sources
6 of 21 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
16m 11s
Tool calls
28 WebFetch16 WebSearch15 bridge
Cited sources
6 of 22 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
6
Duration
15m 29s
Tool calls
42 WebFetch8 WebSearch17 bridge
Cited sources
5 of 34 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
14m 47s
Tool calls
12 WebFetch16 WebSearch22 bridge
Cited sources
2 of 21 in slice
F1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
16m 14s
Tool calls
11 WebFetch6 WebSearch19 bridge
Cited sources
12 of 13 in slice
F2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
14m 12s
Tool calls
0 WebFetch4 WebSearch23 bridge
Cited sources
11 of 13 in slice
F3 stalled

Claude Sonnet 5

Past the 30-min wall-clock cap; abandoned.

F3a Claude Opus 5 (claude-opus-5)
Items returned
2
Duration
17m 50s
Tool calls
0 WebFetch0 WebSearch4 bridge
Cited sources
3 of 3 in slice
F3b Claude Opus 5 (claude-opus-5)
Items returned
3
Duration
15m 40s
Tool calls
0 WebFetch0 WebSearch4 bridge
Cited sources
4 of 4 in slice
R1 Claude Opus 5 (claude-opus-5)
Items returned
1
Duration
9m 48s
Tool calls
0 WebFetch4 WebSearch16 bridge
Cited sources
6 of 8 in slice

Verification

unconfirmed CLEAN · waived: wall-clock watchdog overrun — iteration 3's CLEAN went unconfirmed because the r #1 NEEDS_FIXES · Opus 5 · t=17 e=6 a=4 #2 NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=0 #3 CLEAN · Opus 5 · t=0 e=0 a=3

Deep dive

Entries published (this run)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

25 bookkeeping · 2 notes-updated · 1 added-as-candidate · 1 promoted-to-active.

SourceChangeFrom → ToReason
tp-link-omada-psirtadded-as-candidate— → candidatethis run's single new candidate, and a discovery gap the run hit directly: the Omada gateway line is a common European small-business, branch-office and public-sector edge device, and its August advisory reached this pipeline only through a German CERT relay with the vendor's own per-model firmware table unread — the first pass concluded the advisory was unreachable and composed from the CVE records instead. The landing and search pages are a JavaScript-only application, but the per-advisory document path is server-rendered and reads cleanly through the direct bridge. The reusable half is how to find the document id: the referencing national-CERT CSAF record's external-reference field carries it, which beats crawling the vendor's own single-page application.
cert-lvpromoted-to-activecandidate → activethe state digest counted three contributing runs, meeting the promotion bar. Added as a candidate two fires ago to close a genuine gap — an EU member-state national CERT carrying the authoritative record of a published entry while untracked — and its per-article direct-bridge path has worked on every attempt since.
zaufana-trzecia-stronanotes-updatedrecorded Cloudflare challenge / 403 → flag cleared, direct bridge returns a clean 200the recorded block did not reproduce: the direct bridge returned the full body of the 2026-08-21 roundup. A rotation-priority miss cleared without a recipe change.
ssd-disclosurenotes-updated— → substitute primaries recordedfifth consecutive transport failure, but resolved in substance rather than transport — two outlets were identified that read the advisory directly, so a future fire uses those instead of re-probing a host whose only working rung is the exhausted reader pool. The underlying story is out of window in any case.
cisa-kevbookkeeping— → last_successful_fetch 2026-08-22, counters resetcatalogue version 2026.08.21 carried this run's two new exploited additions, the TrueConf Server chain
bsi-debookkeeping— → last_successful_fetch 2026-08-22, counters resetsurfaced both the TP-Link and the PTC disclosures, and its structured advisory yielded the one fixed version obtainable for the PTC set
anssi-frbookkeeping— → last_successful_fetch 2026-08-22, counters resetcarried the SPIP advisory that anchors this run's highest-value vulnerability entry, and the still-unrevised Entra ID advisory the correction entry turns on
ncsc-ch-security-hubbookkeeping— → last_successful_fetch 2026-08-22, counters resetits own status change from unknown to actively exploited is the Swiss half of the GitLab update, and it relayed the Cisco cycle
enisa-euvdbookkeeping— → last_successful_fetch 2026-08-22, counters resetits record is one of the two European authority feeds shown still carrying a vendor-retracted exploitation claim
advisories-ncsc-nlbookkeeping— → last_successful_fetch 2026-08-22, counters resetindependent structured record corroborating Cisco's own per-CVE vectors
kaspersky-securelistbookkeeping— → last_successful_fetch 2026-08-22, counters resetsole source of the TrueConf exploitation account and both discovering advisories
mandiant-gtigbookkeeping— → last_successful_fetch 2026-08-22, counters resetsole source for this run's deep dive
talosbookkeeping— → last_successful_fetch 2026-08-22, counters resettwo companion posts behind the SPECTRE entry
checkpoint-researchbookkeeping— → last_successful_fetch 2026-08-22, counters resetsole source for the Defender driver research
socradarbookkeeping— → last_successful_fetch 2026-08-22, counters resetoriginating research behind the FTP-banner entry — and the run corrected an earlier pass that had credited the relaying outlet instead
unit42bookkeeping— → last_successful_fetch 2026-08-22, quiet period unchangedfetched and read; its collaboration-platform item did not clear the gate — see the dropped-item notes
bleepingcomputerbookkeeping— → last_successful_fetch 2026-08-22, counters resetrelaying publisher on the FTP-banner research, cited as such
securityweekbookkeeping— → last_successful_fetch 2026-08-22, counters resetcarried the GitLab exploitation claim on the record
ccb-belgiumbookkeeping— → last_successful_fetch 2026-08-22, counters resetits Patch Immediately advisory is the in-window trigger for the Zoom entry; second consecutive fire reached through the direct transport since that record came off its reader pin
ransomware-livebookkeeping— → last_successful_fetch 2026-08-22, counters resetleak-site tracker that surfaced both the Spanish municipal claim and the Swiss claim that was withheld for want of corroboration
cert-plbookkeeping— → last_successful_fetch 2026-08-22, quiet period unchangedfetched clean, nothing in-window beyond routine coordinated-disclosure posts
cert-atbookkeeping— → last_successful_fetch 2026-08-22, quiet period unchangedfetched clean, newest item predates the window
enisabookkeeping— → last_successful_fetch 2026-08-22, quiet period unchangedfetched clean, nothing in-window
edpbbookkeeping— → last_successful_fetch 2026-08-22, quiet period unchangedfetched clean, nothing in-window
ico-ukbookkeeping— → last_successful_fetch 2026-08-22, quiet period unchangedenforcement listing fetched clean; newest action already covered
sec-disclosures-edgarbookkeeping— → last_successful_fetch 2026-08-22, quiet period unchangedfull-text search for cyber-incident 8-K filings in window returned nothing
us-treasury-ofacbookkeeping— → last_successful_fetch 2026-08-22, quiet period unchangedrecent-actions listing fetched clean; the two in-window designations have no cyber nexus
databreaches-netbookkeeping— → last_successful_fetch 2026-08-22, quiet period unchangedfetched clean, nothing in-window that cleared the breach gate
cnil-frbookkeeping— → notes-pendingthe news listing fetched clean but its newest item is dated 29 June 2026, which looks like a stale render of that listing rather than a quiet source; worth a recipe check on a future fire rather than being recorded as a quiet period

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
jina-reader-pool
covered via alternate · should NOT be in this list
https://r.jina.ai/ (all configured keys)jina402 transport-block
seventh consecutive fire with the reader pool credit-exhausted, so the last rung of the documented fetch ladder was unavailable to every pass. A standing capabi
every pass planned around it from the spawn message onward. The direct bridge carried the entire published surface this run, including four hosts that had previ
cisa-advisorieshttps://www.cisa.gov/news-events/cybersecurity-advisorieswebfetchbridge:cisa pagebridge:urlwebsearch403 transport-403
eighth consecutive unreachable run; HTTP 403 to every user agent with the reader fallback exhausted. Essential-tier miss.
the KEV JSON feed is unaffected by the HTML refusal and carried catalogue version 2026.08.21, which is where this run's TrueConf entry comes from. The advisory
cisa-directiveshttps://www.cisa.gov/news-events/directivesbridge:urlwebsearch403 transport-403
seventh consecutive unreachable run, same condition; essential-tier miss and a rotation-priority source.
no evidence from any other source that a directive published in-window
siemens-productcert-csafhttps://cert-portal.siemens.com/productcert/csaf/bridge:urlbridge:url ssa-listwebsearch403 transport-403
fifth consecutive unreachable run for this rotation-priority source; vendor portal refuses the direct transport with the reader exhausted
search surfaced only the already-covered August cycle; no in-window Siemens advisory is known lost
ccn-cert-eshttps://www.ccn-cert.cni.es/en/updated-security/ccn-news.htmlbridge:url403 transport-403
not attempted this run — the rotation-priority slot was spent on the Berlin standing-item chase and the three composed home-region items, and the record is pinn
a Spanish municipal incident published this run rests on the victim's own statement plus a Spanish outlet; no CCN-CERT or INCIBE statement on it was located, so
ncsc-ukhttps://www.ncsc.gov.uk/section/keep-up-to-date/all-reportsrssNone not-attempted
essential-tier source not reached: the sub-agent spent its clock on the Berlin standing-item chase and its three composed items
none — this is a genuine essential-coverage miss, disclosed rather than papered over
ssd-disclosure
covered via alternate · should NOT be in this list
https://ssd-disclosure.com/unisoc-t612-rcebridge:urlgoogle cachearchive availability probe202 transport-block
fifth consecutive failure on the open backlog item — HTTP 202 with a 187-byte JavaScript shell to the direct bridge, and the only rung that has ever worked for
resolved in substance rather than transport: two outlets were found that read the advisory directly and can serve as substitute primaries, recorded in the sourc
paradigm-shift-researchhttps://paradigmshift.tech/researchbridge:url200 recipe-gap
persistent client-rendered application shell; the reader escalation that would hydrate it is credit-exhausted
none; carried forward
acronis-truhttps://www.acronis.com/en/tru/webfetchbridge:url403 transport-403
direct fetch 403; the bridge returned the full page but as a client-rendered shell whose post titles are absent from the server-rendered text, so an in-window p
none needed — this publisher's 2026-08-20 item was already covered by the previous fire
ahnlab-asechttps://asec.ahnlab.com/en/webfetch403 transport-403
HTTP 403 to the direct transport, not retried per the one-retry rule
none; low likelihood of unique in-window content for this constituency
ptc-support-portalhttps://www.ptc.com/en/support/article/CS474826bridge:urlwebfetchosv lookup403 transport-block
the vendor's own support articles carry the fixed builds for two of the three new Windchill CVEs and sit behind an authentication wall; the reader fallback was
BSI's structured advisory yielded the fixed version for one of the three CVEs; the entry states plainly that the other two have no obtainable version range and
github-advisories
covered via alternate · should NOT be in this list
https://github.com/advisories/GHSA-pqpx-w6cx-7q9cbridge:urlbridge:url (api path)webfetch403 transport-403
the direct transport is anti-bot-blocked on both the HTML advisory pages and the advisory API, and the reader fallback was exhausted. The harness's own fetch to
the two entries resting on these records carry no unverifiable quotations: the misp-stix entry quotes only the CVE record it could literal-check and paraphrases

Bridge invocations (this run)

40 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

33 ok7 other
  • url ×18
  • cisa-kev api ×1
  • bsi-csaf WID-SEC-2026-2963 ×1
  • bsi-csaf WID-SEC-2026-2964 ×1
  • bsi-rss ×1
  • cert-fr avis-recent ×1
  • ncsc-csh recent ×1
  • ncsc-csh post 12856 ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 27 findings (truth=17, editorial=6, advisory=4) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
the action item, the body and the cves[] fixed field all gave ER706W-4G v1 the build that belongs to ER706W v1 — 1.2.11 Build 20260723 Rel.41567 instead of 1.2.6 Build 20260723 Rel.41321. An operator corrected in all three places against the vendor's own table, re-read from the saved body this run.
F14
quantifier-without-source
'nineteen rows across seventeen model names' — the table is nineteen rows across eighteen names, only one of which repeats.corrected in the summary, the headline framing and the body.
F4
hallucinated-fact
the summary and cves[] bound CVE-2026-77645 to Windchill PDMLink; PTC's own record and the German CERT's structured copy bind PDMLink to CVE-2026-77646. The body had it right, which is worse — the macproduct bindings corrected in the summary and in both cves[] records.
F14
quantifier-without-source
'two unauthenticated' in the title, summary, body and an action item, where PTC's own CVSS 4.0 vectors carry no-privileges-required on all three and the entry's own cves[] marked all three pre-auth.corrected to three throughout; the internal contradiction with the entry's own metadata is gone.
F12
single-source-flag-missing
the only entry in the run with no verification field at all, while its own sourcing note gave the one-assessor-two-publishers reasoning the run used elsewhere to mark an item single-source.set to single-source with the reasoning stated, and added to the single-source list in these notes.
F4
hallucinated-fact
three evidence quotes retyped the page's non-breaking spaces as ordinary spaces, so none was a contiguous verbatim substring of the source.all three restored to the page's own bytes, non-breaking spaces included, and re-checked literally against the saved body.
F4
hallucinated-fact
the systemd-ordering quote substituted straight single quotes for the page's curly double quotes.restored to the page's own characters and literal-checked.
F4
hallucinated-fact
the affected-systems quote spliced a heading onto a list item, producing a string the advisory page does not contain as written.shortened to the list item alone.
F3
claim-not-supported
the entry generalised the residential-proxy finding onto all three clusters; the report states that one of them uses dedicated infrastructure rather than residential proxies.scoped to the clusters the report groups together, with the exclusion stated, and the over-broad evidence quote removed.
F3
claim-not-supported
the AI-authorship finding was flattened twice over — the source assesses at medium confidence a combination of AI-assisted development and human expertise, scoped to the rootkit component, and the entboth qualifiers restored in the summary and body, and the actor-naming overlap the note claimed was carried is now actually in the body at the source's own conf
F4
hallucinated-fact
the sourcing note claimed the body carried the actor-naming overlap the source reports; the body carried no naming overlap at all.the overlap is now in the body, and iteration 3 tightened its scope further — the source's medium-confidence association with the handle covers several search-r
F3
claim-not-supported
the entry reported a vendor-versus-researcher discrepancy on the affected range that does not exist — the vendor's 'below 5.3.9' has no lower bound and already covers the pre-5.3 releases — and the cvrange corrected to all versions before 5.3.9 and the false discrepancy replaced with what the two published ranges actually say.
F3
claim-not-supported
the overwritten file was described as a JavaScript file; it is a PHP file that happens to sit in the directory holding the interface JavaScript, so a hunt keyed on script extensions would miss it.corrected in the body and in the hunt guidance, which now says explicitly that an extension-keyed search misses it.
F3
claim-not-supported
the earlier Spanish municipal claim's volume and detection date came from an article that was in no sources[] record.that article added to sources[] and cited at the claims it carries.
F4
hallucinated-fact
the sourcing note claimed the body surfaced the outlet's ransomware-versus-encryption-free contradiction; the body never mentioned it.the contradiction is now stated in the body where the note promised it.
F5
missing-citation
half the entry's finding rested on an EU vulnerability-database record that had no sources[] entry and was referred to only as having been retrieved during the run.the record added to sources[] as a primary and cited at the claim it supports.
F5
missing-citation
the paragraphs covering two of the three flaws carried no inline citation at all, though both advisory records were in sources[] and every claim checked out against them.citations added at the three load-bearing claims.
F5
missing-citation
the opening paragraph's victimology and target-list figures come from the companion post, which was in sources[] but never cited inline.both claims now cite the companion post.
F4
hallucinated-fact
ten entries carried a discovered_at later than the run's own recorded completion, five of them still in the future at verification time — a synthetic five-minute ladder rather than recorded observatioevery value reset to the actual composition window, all inside the run.
F4
hallucinated-fact
the action-item paragraph said three entries ship none and mis-stated the totals; four ship none and there are sixteen actions across eleven entries.recounted from the entry files and corrected. The recovered crates.io entry's three actions later moved the same figures to nineteen across twelve, which is wha
F4
hallucinated-fact
the single-source list named an entry id that does not exist, carrying a slug from before the length correction.corrected to the published id.
F17
classification
rated reliability B on a source the pipeline's own source registry rates C, with the corroborating publisher already demoted to a second publisher — so the rating rested on a C-rated single source.set to C, with the reasoning stated: one piece of original work does not re-letter a record whose rating tracks its track record.
F11
editorial-advisory
'five of them scored 10.0 or 9.9' undercounts — five are 10.0 and two more are 9.9.corrected in the body; the summary's own wording was already exact.
F11
editorial-advisory
the mapping used the Windows-event-log-clearing sub-technique for deletion of the product's own application event-log records.replaced with the parent indicator-removal technique, which is what the described behaviour supports.
F11
editorial-advisory
an entity in entities[] appeared nowhere in the body.the body now names it, which is also what the registry edge citing this entry as its evidence needs.
F11
editorial-advisory
the registry edge was typed attributed-to where only the actor's own claim connects the incident to the actor.retyped related-to with the basis stated on the edge.
F10
missed-angle
a build-time supply-chain compromise of three Rust crates on crates.io, disclosed 2026-08-20 and entirely absent from the store — no surfacing pass saw it. Build scripts execute during compilation witrecovered by a scoped research pass and published as 2026-08-22/crates-io-build-script-dropper-yank-lure-arrayref. Two further items the same pass assessed as w

Iteration #2 NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
the priority-calibration paragraph enumerated seven high entries and said the remaining eight were notable — 7 + 8 = 15 against entries_published: 16. Counting priority fields across the entry files grecounted from the sixteen entry files and rewritten to eight high, naming the crates.io build-script dropper as the eighth. The per-day comparison is now state

Iteration #3 CLEAN · 3 findings (truth=0, editorial=0, advisory=3) · Claude Opus 5 · —

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
iteration 1's recorded counts total 27 while its findings list held 26 records — two UAT-10147 defects had been collapsed into one entry, so the telemetry under-reported what the loop actually caught.the merged sourcing-note defect restored as its own record; the list now matches the counts.
F11
editorial-advisory
the body said the source associates the actor with a handle at medium confidence; the source scopes that association to several search-ranking-fraud components used in the campaign, on the basis of emrescoped to the components with the basis stated and the hedge kept — the third correction this run to a claim that had widened a source's subject.
F11
editorial-advisory
the per-day rate divided by gap_hours 48 while the frontmatter records window_hours 50, and the two comparison figures used their own fires' 26 h windows — every figure correct, the basis unstated.the basis is now named (each fire normalised on its own window_hours) and the figure corrected to 3.8; the conclusion holds on either basis.

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-22T0410Z-intel · Opus 5 · window 50 h · 8 entries published

Verification & coverage notes

This run was overtaken, and eight of its sixteen verified entries were stood down at publish time rather than published. That is the single most important fact in this record, and everything below is scoped by it.

The fire opened at 2026-08-22T04:10Z, composed sixteen entries from twenty candidates across four surfacing passes, four scoped deep reads and one scoped recovery pass, took them through the mechanical gate and three verifier iterations, and reached its publishing chain — where the pre-push sync found that origin/main had advanced by three fires while this one sat unpublished. Wall clock from open to that discovery: about 53 hours. The container survived across two calendar days, which is why every file mtime and the composition timestamps in this record read 2026-08-22 while the publish actually happened on 2026-08-24.

By the time the merge was finished the count had risen to five: 2026-08-23T0409Z-intel, 2026-08-23T2311Z-weekly, 2026-08-24T0110Z-weekly, and then — landing while this record was being rewritten — 2026-08-21T0410Z-intel and 2026-08-24T0906Z-intel. Two of those need naming. The 2026-08-21 fire did run. This run's window was computed on the premise that it had not (hence gap_hours: 48 against a 2026-08-20 predecessor), and that premise was wrong: the 08-21 fire was itself stalled, published five entries today, and none of them overlaps the eight published here — checked on CVE ids and entity keys. The window figures in this frontmatter are left as the run computed them, because they are what it actually used; the true gap to the preceding fire was 24 h, not 48. And 2026-08-24T0906Z-intel stood itself down to zero entries for a stale clock, which is the same family of fault as this run's, caught earlier and handled better. The first of them matters most: it computed a 74 h window precisely because this fire had never published, so its window fully contained this one, and it covered eleven entries of the same ground. The W34 weekly then covered more of it again. The pipeline's own guard for this case is explicit — the overtaken run publishes only the delta the newer fires did not surface — so that is what happened here, mechanically rather than by judgement.

The dedup, and what it cost. Every one of the sixteen entries was checked against all twenty-five entries the three overtaking fires published, on CVE identifiers and on entity-registry keys, and then read where the keys were absent. Eight were duplicates and are gone:

  • trueconf-server-preauth-sandbox-escape-kev-installer → both CVEs and both entities already on 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer
  • gtig-three-russian-clusters-authentication-flow-abuse → six shared entities with 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking. This was the run's deep_dive, so the run now ships without one
  • misp-stix-trust-decision-bypass-no-released-fix → all three CVEs on 2026-08-23/misp-stix-import-trust-boundary-dos-parser-state
  • uat-10147-spectre-callback-unlinking-linux-rootkit → both CVEs and the actor on 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink, with a companion entry covering the AI half
  • crates-io-build-script-dropper-yank-lure-arrayref2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk. This is the entry the verification loop recovered as a coverage gap inside this run, and a later fire found it independently
  • cve-2026-69836-entra-id-exploited-flag-retracted-feeds-stale → same CVE on 2026-08-23/cve-2026-69836-entra-id-exploited-flag-corrected
  • btr-defender-remediation-driver-ring0-primitive-absence-tell → same research, same finding, on 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive. Neither entry carried a CVE and this run's carried no entity either, so no structured key caught it; it was caught by reading both
  • martigny-combe-valais-secretariat-mailbox-contact-fan-out → same incident, same dates, same contact count, on 2026-08-23/martigny-combe-valais-communal-mailbox-compromise. Again no key overlap: this run had registered incident:martigny-combe-email-compromise-2026-08 and the overtaking fire registered nothing, so the registry key this run created has been dropped with the entry rather than left orphaned

Two of the eight had no structured overlap at all. A CVE-and-entity dedup pass would have shipped both as duplicates; what caught them was reading the candidate against the store. That is worth carrying into the prompt, because the mechanical index is exactly what a rushed run leans on.

The eight that ship are the delta, and one of them is the reason this record is worth reading. Six are first coverage that no overtaking fire carried, and two are updates:

  • spip-two-unconditional-preauth-rce-releases-three-days-apart — untouched by any of the three fires, and the strongest item here. SPIP shipped two critical releases three days apart, each fixing an unconditional pre-authentication RCE the vendor describes in identical language, each explicitly outside the coverage of its own request-filtering layer, and each with exploitation attempts the vendor states are already being seen. Only the first has a CVE. A vulnerability-management process keyed on CVE identifiers reports the estate clean at 4.4.20 while the newer flaw is open — and 4.4.20 is precisely the release the vendor names as affected. For a French-language public-administration CMS in this constituency's region, this sitting uncovered for two days is the real cost of the stall
  • ptc-windchill-three-new-cves-unauth-rce-no-fixed-version — the W34 weekly covers the exploited older Windchill flaw and the Cl0p campaign around it; these are three new CVEs, all three requiring no privileges, with no obtainable fixed version for two of them. No overlap
  • cve-2026-19586-tp-link-omada-openvpn-preauth-injection — untouched. Pre-authentication OS command injection on an internet-facing SMB and branch-office edge line, with the vendor's own nineteen-row per-hardware-revision firmware table that no CVE record reproduces
  • zoomsday-cve-2026-53415-higher-patch-floor-than-siblings — untouched, and the finding is the patch floor: the third flaw needs a higher fixed version than the two beside it, so patching to the obvious floor leaves it open
  • ftp-banner-dead-drop-resolver-e4del-pinhole — untouched by any entry, and it was sitting on the coverage backlog, queued there by the 2026-08-24 weekly. Publishing it discharges that row, which is now annotated as such
  • kairos-velilla-san-antonio-second-madrid-municipality — untouched
  • cve-2026-19478-gitlab-honeypot-exploitation-confirmed — ships as an update_of on 2026-08-19/cve-2026-19478-gitlab-graphql-unauth-data-destruction, which is the shape it was composed in
  • 2026-08-24/cisco-crosswork-secure-workload-nine-cwe-grouped-cves — the one entry that does not live in this run's own date folder, because its discovered_at is the day the stand-down happened rather than the day the advisories were read. Reshaped during the stand-down from first coverage into an update_of on 2026-08-23/weekly-w34-vuln-status-rollup, because the weekly reached the same two advisories from a national-CERT relay and covered them CVE by CVE while this fire was unpublished. It still ships because three things in that account need correcting from the vendor's own CSAF data: the set is nine CVEs and not eight (CVE-2026-20319 is absent from the rollup's enumeration), the characterisation of the whole set as unauthenticated holds for six of the nine and not for the three carrying PR:L, and the rollup records exploitation status as unknown where Cisco states it is not aware of malicious use. The per-CVE affected and fixed release strings appear in neither the rollup nor the relay

What the verification loop is worth here, and what it is not. All three iterations ran against the full sixteen, so the eight that ship carry the same scrutiny the run recorded: three iterations across two models, twenty-eight defects found and every one remediated. What the loop cannot vouch for is the stand-down itself, which happened after the last verifier returned — no verifier read the reshaped Cisco entry in its update_of form, and no verifier checked the dedup that dropped the other eight. Both are this agent's work alone, and both are on the weekly quality audit's surface.

The publish gate was not met, and the honest version is worth stating plainly. Iteration 3 ran on Opus, re-derived iteration 2's fix independently against the entry files and the two prior run records, took a fresh read of the entries, and returned the run's first CLEAN — no truth defects, no editorial defects, three advisory items, all three of which were applied rather than left. A confirmed CLEAN needs that verdict repeated on the other model, which would have been a fourth iteration. By then the run was already hours past its guard, and the guard's instruction at that point is to land rather than spend more clock proving a verdict. So confirmation_waived is set and this run publishes without a two-model agreement on its final verdict.

The rotation pass, and an operational mistake worth writing down. Iteration 2 ran on the other model and did the two jobs the rotation exists for: it gave the recovered crates.io entry its first cold read — iteration 1 had never seen that entry, because it was composed in answer to iteration 1's own coverage finding — and it re-checked all twenty-five iteration-1 remediations against primaries it fetched again itself rather than trusting the run directory's saved copies. No remediation had regressed. It found one defect, in this record: the priority-calibration paragraph enumerated seven high entries and eight notable against an entries_published of sixteen, because it was written before the recovery and never revisited.

The mistake is mine and it belongs here. While iteration 2 was finishing I checked the run directory for its report, found a stub transcript and no findings file, concluded from that filesystem evidence that the spawn had been blocked the way the alternate verifier has been blocked on two earlier fires, and started a retry on the rotation-recovery ladder. The check had raced the agent's final writes by under a minute: iteration 2 was healthy and delivered a full report. The retry was stopped as soon as that was clear, but it had already spent several minutes of the run's clock re-verifying material iteration 2 had just verified, and it was pinned to the same model, so it could not have served as the second half of a two-model agreement even if it had finished. Two lessons: absence of output files is not evidence of a dead sub-agent while its wall-clock cap has not expired, and a recovery spawn must be checked against the rotation it is meant to preserve before it is worth starting.

The deep reads earned their cost, and two of the three findings that survive the stand-down are in entries that ship. Every published item was re-read against its primary before composition, and the four follow-up passes returned thirty-five corrections between them. The SPIP item was surfaced as one emergency release fixing one unnumbered flaw; the deep read established there were two critical releases three days apart, with the earlier one carrying CVE-2026-77647 and the later one carrying no identifier at all. The Zoom item was surfaced with a single combined patch table; the deep read found the vendor publishes one bulletin per identifier and that the third flaw needs a higher fixed version than its two siblings, so the entry's whole point became that the obvious patch floor is the wrong one. The Cisco item was surfaced as a uniformly unauthenticated set; the vendor's own CSAF vectors show six of nine unauthenticated and three requiring low privilege, and that correction is now the reason that entry ships at all.

Sourcing and single-source items (for the eight that ship):

  • Single-source, and corrected in the direction that costs a rating rather than gains one: 2026-08-22/ftp-banner-dead-drop-resolver-e4del-pinhole. The surfacing pass had this as multi-source with the relaying outlet as the researcher and the researcher as corroboration. The deep read established the opposite — the research unit did the original hunting, reverse engineering and naming, and the outlet says in its own text it is working from a report shared with it and adds no independent analysis. Two publishers of one assessment is not two sources, so the entry is single-source with the relaying outlet cited as such, and reliability follows the registry's C rating for that publisher rather than the quality of this one output.
  • 2026-08-22/ptc-windchill-three-new-cves-unauth-rce-no-fixed-version ships with an empty evidence block, deliberately and with the reason stated in the entry. The advisory records could only be read through a transport that summarises rather than returning raw text, so no quotation could be literal-checked as a contiguous substring; the entry paraphrases instead of quoting.
  • Contradictions carried rather than resolved: the Zoom flaws' provenance is contradicted three ways between the vendor's credit and two passages of the researcher's own write-up, so the entry attributes that flaw to nobody, and the vendor's own CVSS vector records user interaction as required while the national advisory's title and the researcher's framing both say zero-click — the entry states the tension rather than picking a side. For the Spanish municipal item the outlet's May reporting describes the same actor's earlier case as ransomware while its own background material describes the actor as encryption-free, and the entry says so.
  • One quote failed its own check during this run's main-agent read and is recorded because the failure mode is the pipeline's most persistent: a French quotation that looked correct had been retyped with an ordinary space where the page carries a non-breaking one, so it was not a verbatim substring. It was shortened to the fragment that literally matches. A deep-read pass independently found four more of the same class in the surfacing returns — two ellipsis splices, one tense change and one paraphrase inside quotation marks — none of which reached an entry.

Borderline drops. Each was researched and verified; each is dropped for a stated reason, not for space.

  • borderline-drop: Unit 42 identity abuse through trusted communication channels — the mechanism families it documents are ground this store already holds, and its headline content is vendor-telemetry share-of-alerts percentages of the kind this pipeline does not publish. What remains is standing hardening advice rather than something that changes a decision in the next seven days.
  • borderline-drop: leak-site claim against a Swiss datacenter naming a Zurich university of applied sciences — no victim statement, no high-reliability journalism, and every corroborating hit is another aggregator mirroring the same post. Held as a watch item rather than published on an extortion claim alone. Note for the operator: an overtaking fire published 2026-08-23/payload-zurich-it-provider-hwz-student-data, so this item did get coverage two days later from a fire that reached what this one could not.
  • out-of-window: SSD Secure Disclosure Unisoc baseband-to-application-processor chain — freshest source 2026-08-17 against a 50 h window. The transport problem that blocked it on three previous fires was solved in substance, with two outlets identified that read the advisory directly, and that is recorded in the source's notes.

Priority calibration. Of the eight that ship, four are high — SPIP's two exploited unconditional pre-auth RCEs, GitLab's move from disclosed to exploited inside two days, the PTC set with no obtainable fixed version for two of three, and the pre-authentication command injection on the internet-facing edge line — and four are notable. No entry is critical; nothing here meets that bar. The high count is not a judgement about a quieter window: it is what survived a dedup against three later fires, and the twelve-entry difference between what this fire verified and what it published is a publishing artefact, not an editorial one.

Action items. Fourteen actions across seven of the eight entries; the Spanish municipal claim ships none, carried for the pattern rather than a task. Several of them exist only because the deep reads found the obvious answer was wrong: the Zoom floor is 7.1.5 rather than 7.1.0, the SPIP floor is 4.4.21 rather than 4.4.20, and the TP-Link table is keyed on hardware revision rather than model name.

Backlog. Five rows were open when this run started and all five were worked; three overtaking fires have since added their own, and this run's late landing has been reconciled against them rather than overwriting them. The FTP-banner row the 2026-08-24 weekly opened is discharged by this run's entry and annotated in place. The two rows this run added — an npm wave whose implant triggers on module load rather than on install, and a sandbox-escape advisory in the isolation library that AI-agent platforms use to run untrusted code — stay open; both needed a primary this run never reached. The Siemens S7 row is partly discharged: this run added the standard-library PDF text-extraction path that was the row's second instruction, so re-reading that advisory's own text is now a one-command operation. On merge, entities/registry.yaml, state/cves_seen.json, state/source_health.json and sources/sources.json were taken from main rather than from this run, and only this run's genuinely-new records were re-applied on top — three registry records, eleven CVE index records and one candidate source. Resolving those files the usual way would have discarded three fires of accumulated work.

Sub-agent loss and recovery. One deep-read pass was terminated by the content-safety classifier mid-read on kernel-driver abuse material and wrote no findings. Rather than composing from surfacing summaries, it was re-spawned as two smaller passes with an explicit model override to the other model and with the defensive framing declared in the tasking before the first fetch — observability and discriminators only, no offensive procedure, no indicators. Both completed and returned 131 literal-verified quotes between them. This is a recurring rather than exceptional condition: the same class of block has cost this pipeline four research spawns on 2026-08-03 and every alternate verifier spawn on two earlier fires. The model-override ladder worked again.

Tooling: this run shipped nothing, and that is the finding. Every tooling and prompt change it made was discarded at merge time as a rediscovery of work main already carried — better, in both cases, and published while this fire sat unpublished.

It had added a standard-library PDF text-extraction path to the fetch bridge, discharging a standing backlog instruction, and bumped all three prompt banners plus a changelog entry to v3.32 for it. main's own v3.32, dated 2026-08-21 and titled for the same problem, already had one — selected on content type rather than as a fallback after failure, with ToUnicode CMap handling, extraction scoring, mirror counting, a --json mode, and explicit reporting that an image-only PDF has no text objects (which is not extractable, never says nothing). main's version was kept and this run's discarded, along with its banner bumps and its changelog entry.

The auto-merge of those two implementations produced a completely broken tools/fetch_source.py, and it looked clean. Git merged both without a single conflict marker, and the file still parsed — but it now defined pdf_text twice and registered a pdf subparser twice, so argparse raised on setup and every subcommand of the fetch bridge crashed before doing anything. Had this landed, the next fire would have had no bridge at all: no KEV, no CSAF, no PDF, no url. It was caught by running fetch_source.py pdf --help after the merge rather than by reading the diff. A clean auto-merge of two independent implementations of the same feature is not a merge, and a Python file that parses is not a working one — run the CLI.

The same pattern, one file over: this run had also fixed tools/source_health.py, where a bridge recipe's health was judged by output byte count so a valid zero-result JSON envelope read as a dead source. main already carried a fix for that defect too, from the same sec-disclosures-edgar case, published 2026-08-23 and handling three more list keys than this one. Kept main's, discarded ours.

What this run did contribute to the repo, after all that: two .gitignore rules, added when the staging review found roughly 10 MB of raw fetched bodies about to be committed under names the existing rules did not match — work/**/*.clean and work/**/kev*.json. Both names were this run's own invention, so both were its own leak to close. Plus one candidate source (tp-link-omada-psirt, with the reusable recipe for reaching a vendor SPA's per-advisory path through a national-CERT CSAF record's external-reference field), three registry records, eleven CVE-index records, and its memory notes.

Two fires independently building the same PDF transport, and two fires independently fixing the same probe defect, inside three days, is not luck — it is the backlog and the source-health sweep each describing a problem well enough that any run picks it up, with nothing anywhere saying it is already being worked. A claim mechanism on backlog rows would have saved both.

Watchlist. The profile configures no product or supplier watchlist, so both sweeps are documented no-ops and the parseable line is omitted. The region and sector lens was applied throughout, and it is what carried the SPIP disclosure and both municipal items — one of which was then stood down as a duplicate.

For the operator, two questions this run cannot answer for itself. A 53-hour container lifetime on a fire budgeted for about three is not a scope problem, and the run's own watchdog fired correctly and was obeyed; something outside the run's control kept the container alive across two days. Whether that is a scheduler condition, a container stall or a session-resume artefact is visible in infrastructure this run cannot see. And the overtake was discovered only at the pre-push sync, by which point sixteen entries had been composed, gated and verified three times — twelve of those entry-verifications were spent on material that could not publish. A cheap gap check against origin/main at each phase boundary, rather than only at Phase 6, would have caught it hours earlier.

Coverage gaps: cisa-advisories (HTTP 403, eighth consecutive run; the KEV feed covered the exploited-vulnerability surface, the advisory surface again not); cisa-directives (HTTP 403, seventh consecutive run); ncsc-uk (essential-tier source not reached — the home-region pass spent its clock on the Berlin chase and its three composed items); ccn-cert-es (rotation-priority source not attempted, and a Spanish municipal incident published this run, so the gap had a cost); siemens-productcert-csaf (HTTP 403, fifth consecutive run; CSAF mirror checked, nothing in-window lost); ssd-disclosure (anti-bot shell, fifth consecutive failure, resolved in substance via substitute primaries); github-advisories (anti-bot on both the HTML and API paths); ptc-support-portal (login-gated, and it holds the fixed builds for two published CVEs); acronis-tru, ahnlab-asec (HTTP 403); paradigm-shift-research (client-rendered shell, reader-dependent); cnil-fr (listing renders stale rather than quiet — flagged for a recipe check).

Essential-coverage: missed=cisa-advisories (HTTP 403 on every transport), cisa-directives (HTTP 403 on every transport), ncsc-uk (not attempted — sub-agent clock).

← Operations dashboard · day page 2026-08-22 · run-record contract: docs/pipeline.md