2026-08-22T0410Z-intel
One pipeline fire, in full · intel run of 2026-08-22 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-22/2026-08-22T0410Z-intel.md.
Run telemetry
- Items returned
- 9
- Duration
- 20m 22s
- Tool calls
- 26 WebFetch12 WebSearch24 bridge
- Cited sources
- 6 of 21 in slice
- Items returned
- 3
- Duration
- 16m 11s
- Tool calls
- 28 WebFetch16 WebSearch15 bridge
- Cited sources
- 6 of 22 in slice
- Items returned
- 6
- Duration
- 15m 29s
- Tool calls
- 42 WebFetch8 WebSearch17 bridge
- Cited sources
- 5 of 34 in slice
- Items returned
- 1
- Duration
- 14m 47s
- Tool calls
- 12 WebFetch16 WebSearch22 bridge
- Cited sources
- 2 of 21 in slice
- Items returned
- 5
- Duration
- 16m 14s
- Tool calls
- 11 WebFetch6 WebSearch19 bridge
- Cited sources
- 12 of 13 in slice
- Items returned
- 4
- Duration
- 14m 12s
- Tool calls
- 0 WebFetch4 WebSearch23 bridge
- Cited sources
- 11 of 13 in slice
Claude Sonnet 5
Past the 30-min wall-clock cap; abandoned.
- Items returned
- 2
- Duration
- 17m 50s
- Tool calls
- 0 WebFetch0 WebSearch4 bridge
- Cited sources
- 3 of 3 in slice
- Items returned
- 3
- Duration
- 15m 40s
- Tool calls
- 0 WebFetch0 WebSearch4 bridge
- Cited sources
- 4 of 4 in slice
- Items returned
- 1
- Duration
- 9m 48s
- Tool calls
- 0 WebFetch4 WebSearch16 bridge
- Cited sources
- 6 of 8 in slice
Verification
Deep dive
—
Entries published (this run)
- CVE-2026-19586 — TP-Link Omada gateways: attacker-supplied data during OpenVPN connection establishment reaches command execution before authentication completes (CVSS 4.0 9.3) vulnerability high
- Zoomsday — the Zoom client build that closes the first two annotation flaws leaves the third open, and the national advisory that raised the alarm covers only one of the three vulnerability notable
- SPIP shipped two emergency releases in three days, each fixing an unconditional pre-authentication RCE the vendor says is already being exploited — and only the first one has a CVE vulnerability high
- UPDATE — GitLab's unauthenticated GraphQL flaw is being exploited two days after its patch, reproduced from the advisory and the patch alone, and Switzerland's NCSC has flipped its status to actively exploited vulnerability high update
- Kairos claims 77.6 GB from a second Madrid-region municipality in three months, and the town hall confirms a security incident while stating it cannot yet confirm that any data was actually accessed or taken incident notable
- A malware stager is reading its next instruction out of an FTP server's pre-login greeting — and the researchers who found it point out this is the rare command channel that is easier to catch, not harder threat notable
- Three new PTC Windchill and FlexPLM CVEs land on the product line already under mass extortion — all three unauthenticated and flagged red by the vendor, and only one has a fixed version anyone outside PTC's login wall can find vulnerability high
- Cisco Crosswork and Secure Workload ship nine CVEs where each identifier stands for a whole class of bugs — six reachable unauthenticated, three at low privilege, and no workaround for any of them vulnerability notable update
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
25 bookkeeping · 2 notes-updated · 1 added-as-candidate · 1 promoted-to-active.
| Source | Change | From → To | Reason |
|---|---|---|---|
| tp-link-omada-psirt | added-as-candidate | — → candidate | this run's single new candidate, and a discovery gap the run hit directly: the Omada gateway line is a common European small-business, branch-office and public-sector edge device, and its August advisory reached this pipeline only through a German CERT relay with the vendor's own per-model firmware table unread — the first pass concluded the advisory was unreachable and composed from the CVE records instead. The landing and search pages are a JavaScript-only application, but the per-advisory document path is server-rendered and reads cleanly through the direct bridge. The reusable half is how to find the document id: the referencing national-CERT CSAF record's external-reference field carries it, which beats crawling the vendor's own single-page application. |
| cert-lv | promoted-to-active | candidate → active | the state digest counted three contributing runs, meeting the promotion bar. Added as a candidate two fires ago to close a genuine gap — an EU member-state national CERT carrying the authoritative record of a published entry while untracked — and its per-article direct-bridge path has worked on every attempt since. |
| zaufana-trzecia-strona | notes-updated | recorded Cloudflare challenge / 403 → flag cleared, direct bridge returns a clean 200 | the recorded block did not reproduce: the direct bridge returned the full body of the 2026-08-21 roundup. A rotation-priority miss cleared without a recipe change. |
| ssd-disclosure | notes-updated | — → substitute primaries recorded | fifth consecutive transport failure, but resolved in substance rather than transport — two outlets were identified that read the advisory directly, so a future fire uses those instead of re-probing a host whose only working rung is the exhausted reader pool. The underlying story is out of window in any case. |
| cisa-kev | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | catalogue version 2026.08.21 carried this run's two new exploited additions, the TrueConf Server chain |
| bsi-de | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | surfaced both the TP-Link and the PTC disclosures, and its structured advisory yielded the one fixed version obtainable for the PTC set |
| anssi-fr | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | carried the SPIP advisory that anchors this run's highest-value vulnerability entry, and the still-unrevised Entra ID advisory the correction entry turns on |
| ncsc-ch-security-hub | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | its own status change from unknown to actively exploited is the Swiss half of the GitLab update, and it relayed the Cisco cycle |
| enisa-euvd | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | its record is one of the two European authority feeds shown still carrying a vendor-retracted exploitation claim |
| advisories-ncsc-nl | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | independent structured record corroborating Cisco's own per-CVE vectors |
| kaspersky-securelist | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | sole source of the TrueConf exploitation account and both discovering advisories |
| mandiant-gtig | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | sole source for this run's deep dive |
| talos | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | two companion posts behind the SPECTRE entry |
| checkpoint-research | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | sole source for the Defender driver research |
| socradar | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | originating research behind the FTP-banner entry — and the run corrected an earlier pass that had credited the relaying outlet instead |
| unit42 | bookkeeping | — → last_successful_fetch 2026-08-22, quiet period unchanged | fetched and read; its collaboration-platform item did not clear the gate — see the dropped-item notes |
| bleepingcomputer | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | relaying publisher on the FTP-banner research, cited as such |
| securityweek | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | carried the GitLab exploitation claim on the record |
| ccb-belgium | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | its Patch Immediately advisory is the in-window trigger for the Zoom entry; second consecutive fire reached through the direct transport since that record came off its reader pin |
| ransomware-live | bookkeeping | — → last_successful_fetch 2026-08-22, counters reset | leak-site tracker that surfaced both the Spanish municipal claim and the Swiss claim that was withheld for want of corroboration |
| cert-pl | bookkeeping | — → last_successful_fetch 2026-08-22, quiet period unchanged | fetched clean, nothing in-window beyond routine coordinated-disclosure posts |
| cert-at | bookkeeping | — → last_successful_fetch 2026-08-22, quiet period unchanged | fetched clean, newest item predates the window |
| enisa | bookkeeping | — → last_successful_fetch 2026-08-22, quiet period unchanged | fetched clean, nothing in-window |
| edpb | bookkeeping | — → last_successful_fetch 2026-08-22, quiet period unchanged | fetched clean, nothing in-window |
| ico-uk | bookkeeping | — → last_successful_fetch 2026-08-22, quiet period unchanged | enforcement listing fetched clean; newest action already covered |
| sec-disclosures-edgar | bookkeeping | — → last_successful_fetch 2026-08-22, quiet period unchanged | full-text search for cyber-incident 8-K filings in window returned nothing |
| us-treasury-ofac | bookkeeping | — → last_successful_fetch 2026-08-22, quiet period unchanged | recent-actions listing fetched clean; the two in-window designations have no cyber nexus |
| databreaches-net | bookkeeping | — → last_successful_fetch 2026-08-22, quiet period unchanged | fetched clean, nothing in-window that cleared the breach gate |
| cnil-fr | bookkeeping | — → notes-pending | the news listing fetched clean but its newest item is dated 29 June 2026, which looks like a stale render of that listing rather than a quiet source; worth a recipe check on a future fire rather than being recorded as a quiet period |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| jina-reader-pool covered via alternate · should NOT be in this list | https://r.jina.ai/ (all configured keys) | jina | 402 transport-block seventh consecutive fire with the reader pool credit-exhausted, so the last rung of the documented fetch ladder was unavailable to every pass. A standing capabi | every pass planned around it from the spawn message onward. The direct bridge carried the entire published surface this run, including four hosts that had previ |
| cisa-advisories | https://www.cisa.gov/news-events/cybersecurity-advisories | webfetch → bridge:cisa page → bridge:url → websearch | 403 transport-403 eighth consecutive unreachable run; HTTP 403 to every user agent with the reader fallback exhausted. Essential-tier miss. | the KEV JSON feed is unaffected by the HTML refusal and carried catalogue version 2026.08.21, which is where this run's TrueConf entry comes from. The advisory |
| cisa-directives | https://www.cisa.gov/news-events/directives | bridge:url → websearch | 403 transport-403 seventh consecutive unreachable run, same condition; essential-tier miss and a rotation-priority source. | no evidence from any other source that a directive published in-window |
| siemens-productcert-csaf | https://cert-portal.siemens.com/productcert/csaf/ | bridge:url → bridge:url ssa-list → websearch | 403 transport-403 fifth consecutive unreachable run for this rotation-priority source; vendor portal refuses the direct transport with the reader exhausted | search surfaced only the already-covered August cycle; no in-window Siemens advisory is known lost |
| ccn-cert-es | https://www.ccn-cert.cni.es/en/updated-security/ccn-news.html | bridge:url | 403 transport-403 not attempted this run — the rotation-priority slot was spent on the Berlin standing-item chase and the three composed home-region items, and the record is pinn | a Spanish municipal incident published this run rests on the victim's own statement plus a Spanish outlet; no CCN-CERT or INCIBE statement on it was located, so |
| ncsc-uk | https://www.ncsc.gov.uk/section/keep-up-to-date/all-reports | rss | None not-attempted essential-tier source not reached: the sub-agent spent its clock on the Berlin standing-item chase and its three composed items | none — this is a genuine essential-coverage miss, disclosed rather than papered over |
| ssd-disclosure covered via alternate · should NOT be in this list | https://ssd-disclosure.com/unisoc-t612-rce | bridge:url → google cache → archive availability probe | 202 transport-block fifth consecutive failure on the open backlog item — HTTP 202 with a 187-byte JavaScript shell to the direct bridge, and the only rung that has ever worked for | resolved in substance rather than transport: two outlets were found that read the advisory directly and can serve as substitute primaries, recorded in the sourc |
| paradigm-shift-research | https://paradigmshift.tech/research | bridge:url | 200 recipe-gap persistent client-rendered application shell; the reader escalation that would hydrate it is credit-exhausted | none; carried forward |
| acronis-tru | https://www.acronis.com/en/tru/ | webfetch → bridge:url | 403 transport-403 direct fetch 403; the bridge returned the full page but as a client-rendered shell whose post titles are absent from the server-rendered text, so an in-window p | none needed — this publisher's 2026-08-20 item was already covered by the previous fire |
| ahnlab-asec | https://asec.ahnlab.com/en/ | webfetch | 403 transport-403 HTTP 403 to the direct transport, not retried per the one-retry rule | none; low likelihood of unique in-window content for this constituency |
| ptc-support-portal | https://www.ptc.com/en/support/article/CS474826 | bridge:url → webfetch → osv lookup | 403 transport-block the vendor's own support articles carry the fixed builds for two of the three new Windchill CVEs and sit behind an authentication wall; the reader fallback was | BSI's structured advisory yielded the fixed version for one of the three CVEs; the entry states plainly that the other two have no obtainable version range and |
| github-advisories covered via alternate · should NOT be in this list | https://github.com/advisories/GHSA-pqpx-w6cx-7q9c | bridge:url → bridge:url (api path) → webfetch | 403 transport-403 the direct transport is anti-bot-blocked on both the HTML advisory pages and the advisory API, and the reader fallback was exhausted. The harness's own fetch to | the two entries resting on these records carry no unverifiable quotations: the misp-stix entry quotes only the CVE record it could literal-check and paraphrases |
Bridge invocations (this run)
40 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- url ×18
- cisa-kev api ×1
- bsi-csaf WID-SEC-2026-2963 ×1
- bsi-csaf WID-SEC-2026-2964 ×1
- bsi-rss ×1
- cert-fr avis-recent ×1
- ncsc-csh recent ×1
- ncsc-csh post 12856 ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 27 findings (truth=17, editorial=6, advisory=4) · Claude Opus 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | the action item, the body and the cves[] fixed field all gave ER706W-4G v1 the build that belongs to ER706W v1 — 1.2.11 Build 20260723 Rel.41567 instead of 1.2.6 Build 20260723 Rel.41321. An operator | corrected in all three places against the vendor's own table, re-read from the saved body this run. | |
| F14 quantifier-without-source | — | 'nineteen rows across seventeen model names' — the table is nineteen rows across eighteen names, only one of which repeats. | corrected in the summary, the headline framing and the body. | |
| F4 hallucinated-fact | — | the summary and cves[] bound CVE-2026-77645 to Windchill PDMLink; PTC's own record and the German CERT's structured copy bind PDMLink to CVE-2026-77646. The body had it right, which is worse — the mac | product bindings corrected in the summary and in both cves[] records. | |
| F14 quantifier-without-source | — | 'two unauthenticated' in the title, summary, body and an action item, where PTC's own CVSS 4.0 vectors carry no-privileges-required on all three and the entry's own cves[] marked all three pre-auth. | corrected to three throughout; the internal contradiction with the entry's own metadata is gone. | |
| F12 single-source-flag-missing | — | the only entry in the run with no verification field at all, while its own sourcing note gave the one-assessor-two-publishers reasoning the run used elsewhere to mark an item single-source. | set to single-source with the reasoning stated, and added to the single-source list in these notes. | |
| F4 hallucinated-fact | — | three evidence quotes retyped the page's non-breaking spaces as ordinary spaces, so none was a contiguous verbatim substring of the source. | all three restored to the page's own bytes, non-breaking spaces included, and re-checked literally against the saved body. | |
| F4 hallucinated-fact | — | the systemd-ordering quote substituted straight single quotes for the page's curly double quotes. | restored to the page's own characters and literal-checked. | |
| F4 hallucinated-fact | — | the affected-systems quote spliced a heading onto a list item, producing a string the advisory page does not contain as written. | shortened to the list item alone. | |
| F3 claim-not-supported | — | the entry generalised the residential-proxy finding onto all three clusters; the report states that one of them uses dedicated infrastructure rather than residential proxies. | scoped to the clusters the report groups together, with the exclusion stated, and the over-broad evidence quote removed. | |
| F3 claim-not-supported | — | the AI-authorship finding was flattened twice over — the source assesses at medium confidence a combination of AI-assisted development and human expertise, scoped to the rootkit component, and the ent | both qualifiers restored in the summary and body, and the actor-naming overlap the note claimed was carried is now actually in the body at the source's own conf | |
| F4 hallucinated-fact | — | the sourcing note claimed the body carried the actor-naming overlap the source reports; the body carried no naming overlap at all. | the overlap is now in the body, and iteration 3 tightened its scope further — the source's medium-confidence association with the handle covers several search-r | |
| F3 claim-not-supported | — | the entry reported a vendor-versus-researcher discrepancy on the affected range that does not exist — the vendor's 'below 5.3.9' has no lower bound and already covers the pre-5.3 releases — and the cv | range corrected to all versions before 5.3.9 and the false discrepancy replaced with what the two published ranges actually say. | |
| F3 claim-not-supported | — | the overwritten file was described as a JavaScript file; it is a PHP file that happens to sit in the directory holding the interface JavaScript, so a hunt keyed on script extensions would miss it. | corrected in the body and in the hunt guidance, which now says explicitly that an extension-keyed search misses it. | |
| F3 claim-not-supported | — | the earlier Spanish municipal claim's volume and detection date came from an article that was in no sources[] record. | that article added to sources[] and cited at the claims it carries. | |
| F4 hallucinated-fact | — | the sourcing note claimed the body surfaced the outlet's ransomware-versus-encryption-free contradiction; the body never mentioned it. | the contradiction is now stated in the body where the note promised it. | |
| F5 missing-citation | — | half the entry's finding rested on an EU vulnerability-database record that had no sources[] entry and was referred to only as having been retrieved during the run. | the record added to sources[] as a primary and cited at the claim it supports. | |
| F5 missing-citation | — | the paragraphs covering two of the three flaws carried no inline citation at all, though both advisory records were in sources[] and every claim checked out against them. | citations added at the three load-bearing claims. | |
| F5 missing-citation | — | the opening paragraph's victimology and target-list figures come from the companion post, which was in sources[] but never cited inline. | both claims now cite the companion post. | |
| F4 hallucinated-fact | — | ten entries carried a discovered_at later than the run's own recorded completion, five of them still in the future at verification time — a synthetic five-minute ladder rather than recorded observatio | every value reset to the actual composition window, all inside the run. | |
| F4 hallucinated-fact | — | the action-item paragraph said three entries ship none and mis-stated the totals; four ship none and there are sixteen actions across eleven entries. | recounted from the entry files and corrected. The recovered crates.io entry's three actions later moved the same figures to nineteen across twelve, which is wha | |
| F4 hallucinated-fact | — | the single-source list named an entry id that does not exist, carrying a slug from before the length correction. | corrected to the published id. | |
| F17 classification | — | rated reliability B on a source the pipeline's own source registry rates C, with the corroborating publisher already demoted to a second publisher — so the rating rested on a C-rated single source. | set to C, with the reasoning stated: one piece of original work does not re-letter a record whose rating tracks its track record. | |
| F11 editorial-advisory | — | 'five of them scored 10.0 or 9.9' undercounts — five are 10.0 and two more are 9.9. | corrected in the body; the summary's own wording was already exact. | |
| F11 editorial-advisory | — | the mapping used the Windows-event-log-clearing sub-technique for deletion of the product's own application event-log records. | replaced with the parent indicator-removal technique, which is what the described behaviour supports. | |
| F11 editorial-advisory | — | an entity in entities[] appeared nowhere in the body. | the body now names it, which is also what the registry edge citing this entry as its evidence needs. | |
| F11 editorial-advisory | — | the registry edge was typed attributed-to where only the actor's own claim connects the incident to the actor. | retyped related-to with the basis stated on the edge. | |
| F10 missed-angle | — | a build-time supply-chain compromise of three Rust crates on crates.io, disclosed 2026-08-20 and entirely absent from the store — no surfacing pass saw it. Build scripts execute during compilation wit | recovered by a scoped research pass and published as 2026-08-22/crates-io-build-script-dropper-yank-lure-arrayref. Two further items the same pass assessed as w |
Iteration #2 NEEDS_FIXES · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | — | the priority-calibration paragraph enumerated seven high entries and said the remaining eight were notable — 7 + 8 = 15 against entries_published: 16. Counting priority fields across the entry files g | recounted from the sixteen entry files and rewritten to eight high, naming the crates.io build-script dropper as the eighth. The per-day comparison is now state |
Iteration #3 CLEAN · 3 findings (truth=0, editorial=0, advisory=3) · Claude Opus 5 · —
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | — | iteration 1's recorded counts total 27 while its findings list held 26 records — two UAT-10147 defects had been collapsed into one entry, so the telemetry under-reported what the loop actually caught. | the merged sourcing-note defect restored as its own record; the list now matches the counts. | |
| F11 editorial-advisory | — | the body said the source associates the actor with a handle at medium confidence; the source scopes that association to several search-ranking-fraud components used in the campaign, on the basis of em | rescoped to the components with the basis stated and the hedge kept — the third correction this run to a claim that had widened a source's subject. | |
| F11 editorial-advisory | — | the per-day rate divided by gap_hours 48 while the frontmatter records window_hours 50, and the two comparison figures used their own fires' 26 h windows — every figure correct, the basis unstated. | the basis is now named (each fire normalised on its own window_hours) and the figure corrected to 3.8; the conclusion holds on either basis. |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-08-22T0410Z-intel · Opus 5 · window 50 h · 8 entries published
Verification & coverage notes
This run was overtaken, and eight of its sixteen verified entries were stood down at publish time rather than published. That is the single most important fact in this record, and everything below is scoped by it.
The fire opened at 2026-08-22T04:10Z, composed sixteen entries from twenty candidates across four surfacing passes, four scoped deep reads and one scoped recovery pass, took them through the mechanical gate and three verifier iterations, and reached its publishing chain — where the pre-push sync found that origin/main had advanced by three fires while this one sat unpublished. Wall clock from open to that discovery: about 53 hours. The container survived across two calendar days, which is why every file mtime and the composition timestamps in this record read 2026-08-22 while the publish actually happened on 2026-08-24.
By the time the merge was finished the count had risen to five: 2026-08-23T0409Z-intel, 2026-08-23T2311Z-weekly, 2026-08-24T0110Z-weekly, and then — landing while this record was being rewritten — 2026-08-21T0410Z-intel and 2026-08-24T0906Z-intel. Two of those need naming. The 2026-08-21 fire did run. This run's window was computed on the premise that it had not (hence gap_hours: 48 against a 2026-08-20 predecessor), and that premise was wrong: the 08-21 fire was itself stalled, published five entries today, and none of them overlaps the eight published here — checked on CVE ids and entity keys. The window figures in this frontmatter are left as the run computed them, because they are what it actually used; the true gap to the preceding fire was 24 h, not 48. And 2026-08-24T0906Z-intel stood itself down to zero entries for a stale clock, which is the same family of fault as this run's, caught earlier and handled better. The first of them matters most: it computed a 74 h window precisely because this fire had never published, so its window fully contained this one, and it covered eleven entries of the same ground. The W34 weekly then covered more of it again. The pipeline's own guard for this case is explicit — the overtaken run publishes only the delta the newer fires did not surface — so that is what happened here, mechanically rather than by judgement.
The dedup, and what it cost. Every one of the sixteen entries was checked against all twenty-five entries the three overtaking fires published, on CVE identifiers and on entity-registry keys, and then read where the keys were absent. Eight were duplicates and are gone:
trueconf-server-preauth-sandbox-escape-kev-installer→ both CVEs and both entities already on2026-08-23/trueconf-server-kev-head-mare-trojanized-installergtig-three-russian-clusters-authentication-flow-abuse→ six shared entities with2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking. This was the run'sdeep_dive, so the run now ships without onemisp-stix-trust-decision-bypass-no-released-fix→ all three CVEs on2026-08-23/misp-stix-import-trust-boundary-dos-parser-stateuat-10147-spectre-callback-unlinking-linux-rootkit→ both CVEs and the actor on2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink, with a companion entry covering the AI halfcrates-io-build-script-dropper-yank-lure-arrayref→2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk. This is the entry the verification loop recovered as a coverage gap inside this run, and a later fire found it independentlycve-2026-69836-entra-id-exploited-flag-retracted-feeds-stale→ same CVE on2026-08-23/cve-2026-69836-entra-id-exploited-flag-correctedbtr-defender-remediation-driver-ring0-primitive-absence-tell→ same research, same finding, on2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive. Neither entry carried a CVE and this run's carried no entity either, so no structured key caught it; it was caught by reading bothmartigny-combe-valais-secretariat-mailbox-contact-fan-out→ same incident, same dates, same contact count, on2026-08-23/martigny-combe-valais-communal-mailbox-compromise. Again no key overlap: this run had registeredincident:martigny-combe-email-compromise-2026-08and the overtaking fire registered nothing, so the registry key this run created has been dropped with the entry rather than left orphaned
Two of the eight had no structured overlap at all. A CVE-and-entity dedup pass would have shipped both as duplicates; what caught them was reading the candidate against the store. That is worth carrying into the prompt, because the mechanical index is exactly what a rushed run leans on.
The eight that ship are the delta, and one of them is the reason this record is worth reading. Six are first coverage that no overtaking fire carried, and two are updates:
spip-two-unconditional-preauth-rce-releases-three-days-apart— untouched by any of the three fires, and the strongest item here. SPIP shipped two critical releases three days apart, each fixing an unconditional pre-authentication RCE the vendor describes in identical language, each explicitly outside the coverage of its own request-filtering layer, and each with exploitation attempts the vendor states are already being seen. Only the first has a CVE. A vulnerability-management process keyed on CVE identifiers reports the estate clean at 4.4.20 while the newer flaw is open — and 4.4.20 is precisely the release the vendor names as affected. For a French-language public-administration CMS in this constituency's region, this sitting uncovered for two days is the real cost of the stallptc-windchill-three-new-cves-unauth-rce-no-fixed-version— the W34 weekly covers the exploited older Windchill flaw and the Cl0p campaign around it; these are three new CVEs, all three requiring no privileges, with no obtainable fixed version for two of them. No overlapcve-2026-19586-tp-link-omada-openvpn-preauth-injection— untouched. Pre-authentication OS command injection on an internet-facing SMB and branch-office edge line, with the vendor's own nineteen-row per-hardware-revision firmware table that no CVE record reproduceszoomsday-cve-2026-53415-higher-patch-floor-than-siblings— untouched, and the finding is the patch floor: the third flaw needs a higher fixed version than the two beside it, so patching to the obvious floor leaves it openftp-banner-dead-drop-resolver-e4del-pinhole— untouched by any entry, and it was sitting on the coverage backlog, queued there by the 2026-08-24 weekly. Publishing it discharges that row, which is now annotated as suchkairos-velilla-san-antonio-second-madrid-municipality— untouchedcve-2026-19478-gitlab-honeypot-exploitation-confirmed— ships as anupdate_ofon2026-08-19/cve-2026-19478-gitlab-graphql-unauth-data-destruction, which is the shape it was composed in2026-08-24/cisco-crosswork-secure-workload-nine-cwe-grouped-cves— the one entry that does not live in this run's own date folder, because itsdiscovered_atis the day the stand-down happened rather than the day the advisories were read. Reshaped during the stand-down from first coverage into anupdate_ofon2026-08-23/weekly-w34-vuln-status-rollup, because the weekly reached the same two advisories from a national-CERT relay and covered them CVE by CVE while this fire was unpublished. It still ships because three things in that account need correcting from the vendor's own CSAF data: the set is nine CVEs and not eight (CVE-2026-20319 is absent from the rollup's enumeration), the characterisation of the whole set as unauthenticated holds for six of the nine and not for the three carryingPR:L, and the rollup records exploitation status as unknown where Cisco states it is not aware of malicious use. The per-CVE affected and fixed release strings appear in neither the rollup nor the relay
What the verification loop is worth here, and what it is not. All three iterations ran against the full sixteen, so the eight that ship carry the same scrutiny the run recorded: three iterations across two models, twenty-eight defects found and every one remediated. What the loop cannot vouch for is the stand-down itself, which happened after the last verifier returned — no verifier read the reshaped Cisco entry in its update_of form, and no verifier checked the dedup that dropped the other eight. Both are this agent's work alone, and both are on the weekly quality audit's surface.
The publish gate was not met, and the honest version is worth stating plainly. Iteration 3 ran on Opus, re-derived iteration 2's fix independently against the entry files and the two prior run records, took a fresh read of the entries, and returned the run's first CLEAN — no truth defects, no editorial defects, three advisory items, all three of which were applied rather than left. A confirmed CLEAN needs that verdict repeated on the other model, which would have been a fourth iteration. By then the run was already hours past its guard, and the guard's instruction at that point is to land rather than spend more clock proving a verdict. So confirmation_waived is set and this run publishes without a two-model agreement on its final verdict.
The rotation pass, and an operational mistake worth writing down. Iteration 2 ran on the other model and did the two jobs the rotation exists for: it gave the recovered crates.io entry its first cold read — iteration 1 had never seen that entry, because it was composed in answer to iteration 1's own coverage finding — and it re-checked all twenty-five iteration-1 remediations against primaries it fetched again itself rather than trusting the run directory's saved copies. No remediation had regressed. It found one defect, in this record: the priority-calibration paragraph enumerated seven high entries and eight notable against an entries_published of sixteen, because it was written before the recovery and never revisited.
The mistake is mine and it belongs here. While iteration 2 was finishing I checked the run directory for its report, found a stub transcript and no findings file, concluded from that filesystem evidence that the spawn had been blocked the way the alternate verifier has been blocked on two earlier fires, and started a retry on the rotation-recovery ladder. The check had raced the agent's final writes by under a minute: iteration 2 was healthy and delivered a full report. The retry was stopped as soon as that was clear, but it had already spent several minutes of the run's clock re-verifying material iteration 2 had just verified, and it was pinned to the same model, so it could not have served as the second half of a two-model agreement even if it had finished. Two lessons: absence of output files is not evidence of a dead sub-agent while its wall-clock cap has not expired, and a recovery spawn must be checked against the rotation it is meant to preserve before it is worth starting.
The deep reads earned their cost, and two of the three findings that survive the stand-down are in entries that ship. Every published item was re-read against its primary before composition, and the four follow-up passes returned thirty-five corrections between them. The SPIP item was surfaced as one emergency release fixing one unnumbered flaw; the deep read established there were two critical releases three days apart, with the earlier one carrying CVE-2026-77647 and the later one carrying no identifier at all. The Zoom item was surfaced with a single combined patch table; the deep read found the vendor publishes one bulletin per identifier and that the third flaw needs a higher fixed version than its two siblings, so the entry's whole point became that the obvious patch floor is the wrong one. The Cisco item was surfaced as a uniformly unauthenticated set; the vendor's own CSAF vectors show six of nine unauthenticated and three requiring low privilege, and that correction is now the reason that entry ships at all.
Sourcing and single-source items (for the eight that ship):
- Single-source, and corrected in the direction that costs a rating rather than gains one:
2026-08-22/ftp-banner-dead-drop-resolver-e4del-pinhole. The surfacing pass had this as multi-source with the relaying outlet as the researcher and the researcher as corroboration. The deep read established the opposite — the research unit did the original hunting, reverse engineering and naming, and the outlet says in its own text it is working from a report shared with it and adds no independent analysis. Two publishers of one assessment is not two sources, so the entry is single-source with the relaying outlet cited as such, and reliability follows the registry's C rating for that publisher rather than the quality of this one output. 2026-08-22/ptc-windchill-three-new-cves-unauth-rce-no-fixed-versionships with an empty evidence block, deliberately and with the reason stated in the entry. The advisory records could only be read through a transport that summarises rather than returning raw text, so no quotation could be literal-checked as a contiguous substring; the entry paraphrases instead of quoting.- Contradictions carried rather than resolved: the Zoom flaws' provenance is contradicted three ways between the vendor's credit and two passages of the researcher's own write-up, so the entry attributes that flaw to nobody, and the vendor's own CVSS vector records user interaction as required while the national advisory's title and the researcher's framing both say zero-click — the entry states the tension rather than picking a side. For the Spanish municipal item the outlet's May reporting describes the same actor's earlier case as ransomware while its own background material describes the actor as encryption-free, and the entry says so.
- One quote failed its own check during this run's main-agent read and is recorded because the failure mode is the pipeline's most persistent: a French quotation that looked correct had been retyped with an ordinary space where the page carries a non-breaking one, so it was not a verbatim substring. It was shortened to the fragment that literally matches. A deep-read pass independently found four more of the same class in the surfacing returns — two ellipsis splices, one tense change and one paraphrase inside quotation marks — none of which reached an entry.
Borderline drops. Each was researched and verified; each is dropped for a stated reason, not for space.
borderline-drop: Unit 42 identity abuse through trusted communication channels— the mechanism families it documents are ground this store already holds, and its headline content is vendor-telemetry share-of-alerts percentages of the kind this pipeline does not publish. What remains is standing hardening advice rather than something that changes a decision in the next seven days.borderline-drop: leak-site claim against a Swiss datacenter naming a Zurich university of applied sciences— no victim statement, no high-reliability journalism, and every corroborating hit is another aggregator mirroring the same post. Held as a watch item rather than published on an extortion claim alone. Note for the operator: an overtaking fire published2026-08-23/payload-zurich-it-provider-hwz-student-data, so this item did get coverage two days later from a fire that reached what this one could not.out-of-window: SSD Secure Disclosure Unisoc baseband-to-application-processor chain— freshest source 2026-08-17 against a 50 h window. The transport problem that blocked it on three previous fires was solved in substance, with two outlets identified that read the advisory directly, and that is recorded in the source's notes.
Priority calibration. Of the eight that ship, four are high — SPIP's two exploited unconditional pre-auth RCEs, GitLab's move from disclosed to exploited inside two days, the PTC set with no obtainable fixed version for two of three, and the pre-authentication command injection on the internet-facing edge line — and four are notable. No entry is critical; nothing here meets that bar. The high count is not a judgement about a quieter window: it is what survived a dedup against three later fires, and the twelve-entry difference between what this fire verified and what it published is a publishing artefact, not an editorial one.
Action items. Fourteen actions across seven of the eight entries; the Spanish municipal claim ships none, carried for the pattern rather than a task. Several of them exist only because the deep reads found the obvious answer was wrong: the Zoom floor is 7.1.5 rather than 7.1.0, the SPIP floor is 4.4.21 rather than 4.4.20, and the TP-Link table is keyed on hardware revision rather than model name.
Backlog. Five rows were open when this run started and all five were worked; three overtaking fires have since added their own, and this run's late landing has been reconciled against them rather than overwriting them. The FTP-banner row the 2026-08-24 weekly opened is discharged by this run's entry and annotated in place. The two rows this run added — an npm wave whose implant triggers on module load rather than on install, and a sandbox-escape advisory in the isolation library that AI-agent platforms use to run untrusted code — stay open; both needed a primary this run never reached. The Siemens S7 row is partly discharged: this run added the standard-library PDF text-extraction path that was the row's second instruction, so re-reading that advisory's own text is now a one-command operation. On merge, entities/registry.yaml, state/cves_seen.json, state/source_health.json and sources/sources.json were taken from main rather than from this run, and only this run's genuinely-new records were re-applied on top — three registry records, eleven CVE index records and one candidate source. Resolving those files the usual way would have discarded three fires of accumulated work.
Sub-agent loss and recovery. One deep-read pass was terminated by the content-safety classifier mid-read on kernel-driver abuse material and wrote no findings. Rather than composing from surfacing summaries, it was re-spawned as two smaller passes with an explicit model override to the other model and with the defensive framing declared in the tasking before the first fetch — observability and discriminators only, no offensive procedure, no indicators. Both completed and returned 131 literal-verified quotes between them. This is a recurring rather than exceptional condition: the same class of block has cost this pipeline four research spawns on 2026-08-03 and every alternate verifier spawn on two earlier fires. The model-override ladder worked again.
Tooling: this run shipped nothing, and that is the finding. Every tooling and prompt change it made was discarded at merge time as a rediscovery of work main already carried — better, in both cases, and published while this fire sat unpublished.
It had added a standard-library PDF text-extraction path to the fetch bridge, discharging a standing backlog instruction, and bumped all three prompt banners plus a changelog entry to v3.32 for it. main's own v3.32, dated 2026-08-21 and titled for the same problem, already had one — selected on content type rather than as a fallback after failure, with ToUnicode CMap handling, extraction scoring, mirror counting, a --json mode, and explicit reporting that an image-only PDF has no text objects (which is not extractable, never says nothing). main's version was kept and this run's discarded, along with its banner bumps and its changelog entry.
The auto-merge of those two implementations produced a completely broken tools/fetch_source.py, and it looked clean. Git merged both without a single conflict marker, and the file still parsed — but it now defined pdf_text twice and registered a pdf subparser twice, so argparse raised on setup and every subcommand of the fetch bridge crashed before doing anything. Had this landed, the next fire would have had no bridge at all: no KEV, no CSAF, no PDF, no url. It was caught by running fetch_source.py pdf --help after the merge rather than by reading the diff. A clean auto-merge of two independent implementations of the same feature is not a merge, and a Python file that parses is not a working one — run the CLI.
The same pattern, one file over: this run had also fixed tools/source_health.py, where a bridge recipe's health was judged by output byte count so a valid zero-result JSON envelope read as a dead source. main already carried a fix for that defect too, from the same sec-disclosures-edgar case, published 2026-08-23 and handling three more list keys than this one. Kept main's, discarded ours.
What this run did contribute to the repo, after all that: two .gitignore rules, added when the staging review found roughly 10 MB of raw fetched bodies about to be committed under names the existing rules did not match — work/**/*.clean and work/**/kev*.json. Both names were this run's own invention, so both were its own leak to close. Plus one candidate source (tp-link-omada-psirt, with the reusable recipe for reaching a vendor SPA's per-advisory path through a national-CERT CSAF record's external-reference field), three registry records, eleven CVE-index records, and its memory notes.
Two fires independently building the same PDF transport, and two fires independently fixing the same probe defect, inside three days, is not luck — it is the backlog and the source-health sweep each describing a problem well enough that any run picks it up, with nothing anywhere saying it is already being worked. A claim mechanism on backlog rows would have saved both.
Watchlist. The profile configures no product or supplier watchlist, so both sweeps are documented no-ops and the parseable line is omitted. The region and sector lens was applied throughout, and it is what carried the SPIP disclosure and both municipal items — one of which was then stood down as a duplicate.
For the operator, two questions this run cannot answer for itself. A 53-hour container lifetime on a fire budgeted for about three is not a scope problem, and the run's own watchdog fired correctly and was obeyed; something outside the run's control kept the container alive across two days. Whether that is a scheduler condition, a container stall or a session-resume artefact is visible in infrastructure this run cannot see. And the overtake was discovered only at the pre-push sync, by which point sixteen entries had been composed, gated and verified three times — twelve of those entry-verifications were spent on material that could not publish. A cheap gap check against origin/main at each phase boundary, rather than only at Phase 6, would have caught it hours earlier.
Coverage gaps: cisa-advisories (HTTP 403, eighth consecutive run; the KEV feed covered the exploited-vulnerability surface, the advisory surface again not); cisa-directives (HTTP 403, seventh consecutive run); ncsc-uk (essential-tier source not reached — the home-region pass spent its clock on the Berlin chase and its three composed items); ccn-cert-es (rotation-priority source not attempted, and a Spanish municipal incident published this run, so the gap had a cost); siemens-productcert-csaf (HTTP 403, fifth consecutive run; CSAF mirror checked, nothing in-window lost); ssd-disclosure (anti-bot shell, fifth consecutive failure, resolved in substance via substitute primaries); github-advisories (anti-bot on both the HTML and API paths); ptc-support-portal (login-gated, and it holds the fixed builds for two published CVEs); acronis-tru, ahnlab-asec (HTTP 403); paradigm-shift-research (client-rendered shell, reader-dependent); cnil-fr (listing renders stale rather than quiet — flagged for a recipe check).
Essential-coverage: missed=cisa-advisories (HTTP 403 on every transport), cisa-directives (HTTP 403 on every transport), ncsc-uk (not attempted — sub-agent clock).
← Operations dashboard · day page 2026-08-22 · run-record contract: docs/pipeline.md