ctipilot.ch

2026-08-24T0410Z-intel

One pipeline fire, in full · intel run of 2026-08-24 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-24/2026-08-24T0410Z-intel.md.

Run telemetry

2026-08-24T0410Z-intel intel prompt v3.31 publish ok
11h 16m duration 7 published 1 updates
Claude Opus 5 (claude-opus-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
10m 21s
Tool calls
15 WebFetch8 WebSearch12 bridge
Cited sources
6 of 22 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
11m 58s
Tool calls
24 WebFetch12 WebSearch9 bridge
Cited sources
4 of 14 in slice
S3 stalled

unknown

Past the 30-min wall-clock cap; abandoned.

S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
9m 51s
Tool calls
4 WebFetch14 WebSearch16 bridge
Cited sources
2 of 13 in slice
DR1 Claude Opus 5 (claude-opus-5)
Items returned
8
Duration
12m 00s
Tool calls
0 WebFetch0 WebSearch8 bridge
Cited sources
8 of 8 in slice

Verification

#1 NEEDS_FIXES · Opus 5 · t=7 e=6 a=1 #2 NEEDS_FIXES · Sonnet 5 · t=3 e=0 a=1 #3 NEEDS_FIXES · Opus 5 · t=6 e=0 a=2

Deep dive

2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job

Entries published (this run)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 status candidate -> active. Promoted on the digest's own promotion_due count (3 contributing runs, most recent 2026-08-23T2311Z-weekly), not on eyeball. · 1 fetch_method jina -> bridge. The direct browser-UA GET returned the full article body while the reader pool was fully credit-exhausted, so the reader pin was spending metered credit on content the cheapest transport already reaches. · 1 fetch_method bridge -> webfetch. The site has migrated to bacs.admin.ch as a Nuxt single-page application: the bridge's direct GET returns only the JavaScript shell, while WebFetch's renderer surfaces the listing. · 1 fetch_method bridge -> webfetch. Same Nuxt-SPA migration. · 1 ADDED as this run's single new candidate (status: candidate). Maintainers of the TruffleHog scanner; their research arm publishes methodology-stated, large-scale measurements of live leaked cloud credentials and where they leak from. Primary for this run's AWS-key entry..

SourceChangeFrom → ToReason
venarixstatus candidate -> active. Promoted on the digest's own promotion_due count (3 contributing runs, most recent 2026-08-23T2311Z-weekly), not on eyeball.— → —
reliaquestfetch_method jina -> bridge. The direct browser-UA GET returned the full article body while the reader pool was fully credit-exhausted, so the reader pin was spending metered credit on content the cheapest transport already reaches.— → —
ncsc-ch-focusfetch_method bridge -> webfetch. The site has migrated to bacs.admin.ch as a Nuxt single-page application: the bridge's direct GET returns only the JavaScript shell, while WebFetch's renderer surfaces the listing.— → —
ncsc-ch-incidentsfetch_method bridge -> webfetch. Same Nuxt-SPA migration.— → —
truffle-securityADDED as this run's single new candidate (status: candidate). Maintainers of the TruffleHog scanner; their research arm publishes methodology-stated, large-scale measurements of live leaked cloud credentials and where they leak from. Primary for this run's AWS-key entry.— → —

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
cisa-advisorieshttps://www.cisa.gov/news-events/cybersecurity-advisorieswebfetchbridge:urlbridge:feedbridge:cisa pagebridge:jina403 transport-403
ninth consecutive unreachable run. HTTP 403 to every user agent on the HTML listing and on the RSS fallback at /cybersecurity-advisories/all.xml, with the reade
the KEV JSON feed under the /sites/default/files/feeds/ path is unaffected by the HTML refusal and was read successfully, which is how this run established that
cisa-directiveshttps://www.cisa.gov/news-events/directiveswebfetchbridge:cisa pagebridge:jina403 transport-403
eighth consecutive unreachable run, same condition, with the reader fallback also credit-exhausted.
no substitute transport exists for the directives listing, which is not CSAF-structured; a search pass surfaced no in-window directive.
siemens-productcert-csafhttps://cert-portal.siemens.com/productcert/csaf/webfetchbridge:urlbridge:jina403 transport-403
403 on both direct WebFetch and the bridge's direct GET; reader fallback credit-exhausted.
substituted CISA's own OT/ICS CSAF mirror via `cisa csaf-recent`, a partial substitute that carries Siemens advisories only where CISA co-publishes them; its ne
ssd-disclosurehttps://ssd-disclosure.com/webfetch0
empty body returned; this source's only working transport has ever been the reader pool, which is credit-exhausted.
none. This is the same condition that has kept the Unisoc VoLTE backlog row blocked since 2026-08-18; no new transport was invented this run.
ccn-cert-eshttps://www.ccn-cert.cni.es/en/updated-security/ccn-news.htmlbridge:jina402 transport-402
source is pinned fetch_method=jina and the pool is credit-exhausted on all seven keys; not retried on a transport already known to fail.
none — Spanish national CERT content not covered this run.
databreaches-net
covered via alternate · should NOT be in this list
https://databreaches.net/2026/08/23/shinyhunters-claims-hack-of-reliaquest-but-pbridge:urlwebfetch403 transport-403
front-page listing fetched successfully and carried the lead, but the article URL 403'd on the direct bridge with the reader fallback credit-exhausted.
the victim's own incident write-up was used as the primary instead, which is the stronger source; the aggregator was needed only to confirm the leak-site listin
ico-ukhttps://ico.org.uk/about-the-ico/media-centre/news-and-blogs/bridge:url200
HTTP 200 but the listing is client-rendered, so the direct-GET body carried navigation chrome and no dated enforcement entries; the reader needed to hydrate it
a search fallback surfaced only already-covered or out-of-window enforcement actions. Recipe gap recorded for a run with reader credit available.
ncsc-ukhttps://www.ncsc.gov.uk/section/keep-up-to-date/reports-advisoriesbridge:url200
page shell only (client-rendered listing); the transport ladder was not fully exhausted before the sub-agent returned under wall-clock pressure.
none. Logged as an essential-tier gap rather than a failure, since a structured recipe was not attempted.

Bridge invocations (this run)

10 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

10 other
  • ×10

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 14 findings (truth=7, editorial=6, advisory=1) · Claude Opus 5 · 21m 06s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
An authenticator-enrolment attempt was asserted as an observed step of this incident when the source names it only as an element of the industry playbook the attempt is consistent with — and the TriagBoth fixed. The enrolment step is now explicitly attributed to the playbook framing with a sentence saying it should not be read as an observed action, and the
F4
hallucinated-fact
The entry's leak-site claims — an extortion brand, a listing date, three screenshots, no data samples — were unsupported by its only cited source, whose article text never mentions any of them; the soIndependently confirmed (zero occurrences in the stripped body, two in the raw HTML, both inside meta/JSON-LD keywords). Every leak-site specific was removed fr
F3
claim-not-supported
The 25-keys / 0.9% figure was attached to the 64,024-key population when the source states it against the 2,903-key enumerable subset; the arithmetic confirms it (0.9% of 2,903 is ~26, of 64,024 is 57Re-derived from the fetched body and fixed: the figure is now stated against the enumerable subset, and the sourcing note names it alongside the other narrow-de
F14
?
The title and headline implied a four-way ranking of leak surfaces and silently dropped package registries; the source names five surfaces and ranks only one.Title and headline rewritten to say 'the measured leak surfaces' and to list all five; the body now states that only one surface is ranked and that no ordering
F3
claim-not-supported
'Held roughly steady quarter over quarter' added a comparison period the source does not state, and contradicted the entry's own year-on-year title framing.Fixed: the entry now quotes the source's bare 'held roughly steady (40)' and says explicitly that the report names no comparison period, in a paragraph whose pr
F3
claim-not-supported
E4del's authentication token was described as extracted from its own command line; the source places it in the operator's C2 command string.Fixed to 'takes an authentication token out of the operator's own command string'.
F17
?
Reliability was set to B while this publisher's own record in sources/sources.json is C, with a note that its single-vendor investigative claims should be corroborated — on a single-source entry with Reliability lowered to C to match the source record, with the sourcing note explaining that the letter tracks the source rather than the apparent quality of one
F8
needs-more-research
The entry dropped the persistence module's COM-based scheduled-task installation and the evasion rationale the source gives for it, which is detection-relevant: the technique exists specifically to avVerified verbatim on the fetched page before accepting, then added — including the point that the usual high-value signal is exactly what this build avoids prod
F11
editorial-advisory
The source's hedge on the indicator file was removed and its scope widened: it says the file 'is not expected to exist natively on supported Windows versions', the entry said it exists on no Windows vThe hedge restored in all three places, including the action item, with a note that the source's wording is what it will bear.
F11
editorial-advisory
The source publishes its own ATT&CK table including T1218 for the signed error-reporting binary used as the SYSTEM execution vehicle, a behaviour the body already described; T1218 was absent from techT1218 added, and the body now names the trusted-binary proxy-execution role explicitly rather than only describing the load.
F4
hallucinated-fact
The run record's single-source paragraph contradicted the entries it described: it claimed the Keycloak entry carried the national-CERT carve-out (the entry rejects it), said 'four entries' and then lParagraph rewritten from the entries' actual frontmatter, verified by re-reading all nine verification values: two carve-outs (BACS national-CERT, ReliaQuest vi
F11
editorial-advisory
The record said 'all sixteen carried quotes' were machine-checked; the will-publish set carried 22 evidence quotes at that point, of which 16 were in the checked file (the published set is 19 after thCorrected to the real figures — 22 carried, 16 in the machine-checked set, three ReliaQuest quotes verified but omitted from that file, six German fragments che
F11
editorial-advisory
Title and headline framed the public sector's top reporting share as a change; the report's own word is 'weiterhin' — continuing — so the ranking is persistent, not new. Body was already accurate.Title, headline and summary reworded to 'still' / 'remains' / 'continues to', and the body now names the report's own 'weiterhin' so the reader can see it is a
F11
editorial-advisory
The headline led with the two command-and-control channels and the AI tells, both of which in-window strategic entries had already published; the genuinely new material is the five named families and Headline re-led on the pairing discriminator and the named families; the two prior strategic entries added to references[], and the sourcing note now states whi

Iteration #2 NEEDS_FIXES · 4 findings (truth=3, editorial=0, advisory=1) · Claude Sonnet 5 · 6m 56s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The reframed entry and its sourcing note both said the article 'opens with' its denial of the compromise claim. It does not: the denial sits about 64% of the way through the body, after the investigatIndependently confirmed by locating the sentence in the fetched body (character 5,258 of 8,263). Body and sourcing note rewritten to say the article states the
F4
hallucinated-fact
The run record's entities_added still listed the pre-rename ReliaQuest entity key.Already corrected before this iteration reported, and re-verified after it: all 11 entities_added keys now resolve against the registry. Recorded here because t
F4
hallucinated-fact
The quote-count breakdown added under iteration 1's F11 fix did not sum: '16 machine-checked + 3 ReliaQuest + six German fragments' against a stated total of 22.Re-counted from the entries themselves — 22 carried quotes, 19 English and 3 German, of which 16 English were in quotes.json and 3 ReliaQuest verified separatel
F11
editorial-advisory
Advisory: the Defender-takeaway paragraph still read 'the public sector is now the largest reporting share' — the precise novelty framing the title, headline, summary and intro had all been corrected Changed to 'remains'. Grep confirms no residual novelty framing anywhere in the entry.

Iteration #3 NEEDS_FIXES cap-breach · 8 findings (truth=6, editorial=0, advisory=2) · Claude Opus 5 · 25m 30s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
The registry record added by this run still said the source article 'opens by denying' the compromise claim — the same error corrected in the entry and the run record one round earlier, on a surface tRegistry summary rewritten to match the article's actual structure: it describes the attempt, sets out the investigation findings, and then states the claims ar
F4
hallucinated-fact
The notes body still described the ReliaQuest entry as covering a leak-site listing alongside the victim's write-up, and as resting the connection between them on timing — an entry that no longer exisParagraph rewritten to describe what actually happened: the claim's specifics were removed because the only cited source would not bear them, rather than proppe
F4
hallucinated-fact
The correction's product-state table is right, but its stated cause was not: it blamed reading vendor prose rather than structured data, while the entry being corrected says in its own sourcing note tThe causal claim was removed and replaced with what is actually known — including the fact this iteration established, that Red Hat's machine-readable VEX docum
F4
hallucinated-fact
techniques[] still asserted T1098.005 (Device Registration) — the one behaviour the body and sourcing note both explicitly say was NOT observed in this incident. The prose was de-asserted one round eaT1098.005 removed, and the sourcing note now states that the mapping surface must not assert what the prose de-asserts, so the reason survives the next edit.
F11
editorial-advisory
Advisory: the notes body carried 15 occurrences of workflow-internal vocabulary against zero in the four preceding intel records, making this record an outlier against the house style and against the All 15 reworded to reader-facing language (the research stage, the research workers, that work, restarted) with every disclosure preserved intact. A programmati
F11
editorial-advisory
The summary said the Poland sabotage was 'attributed by CERT.PL to Static Tundra'. The report attributes the attack INFRASTRUCTURE to that actor and then adds its own hedge about the operation — a disSummary and body both corrected to attribute the infrastructure, with BACS's separate hedge about the operation carried as its own.
F14
?
The summary universalised where the source hedges — 'entry in every documented case is DLL side-loading' against the source's 'most consistent detection surface' and 'most of the toolset'. The page alSummary and body corrected to the source's own quantifier, initial access stated as a malicious Office document, and the Defender takeaway now says the pairing
F14
?
'Two declines are attributed rather than merely observed' preceded a list of three declines, and the report attributes a cause to only one of them.Rewritten to say three categories fell and exactly one is given a cause, with an explicit note that the other two should not be read as evidence a control worke

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-24T0410Z-intel · Opus 5 · window 24 h · 7 entries published

Verification & coverage notes

This fire ran 4 h 47 min behind itself before it did any research. The container stalled between preparation and the start of research — the run's own start stamp reads 04:10:43Z while the four research workers did not begin until 08:54–08:55Z — so the wall-clock watchdog was already tripped before a single source was fetched, without a minute of research time having been lost. The run was landed under that constraint: the research stage was allowed to finish because it had only just started and was the run's entire research surface, but no scope was widened afterwards, no research was restarted when one domain died, and composition ran in a single pass. The duration_seconds recorded above is the honest wall clock and is not a measure of work performed.

The stall had one fortunate consequence. Switzerland's federal cyber authority published its half-year threat report under an embargo lifting at 09:00 UTC, and the coverage-backlog row for it existed precisely because both the weekly that surfaced it (research window closed 01:15 UTC) and this scheduled fire (nominal start 04:10 UTC) were expected to miss it. The stall put the research window on top of the publication instead. The home-region research was re-tasked mid-flight and caught the report minutes after it went live, and it became this run's deep dive.

Coverage gaps. The research and investigative-reporting sweep did not happen. That work was terminated about twelve minutes in by a content-classifier trip rather than by its time cap, so it wrote no findings file and its domain — vendor and independent threat-research labs, OT/ICS research, investigative reporting — has no sweep behind it this run. It was deliberately not restarted, because the watchdog forbids starting new research that far past the start, and because six of this run's seven published entries are research-domain material worked from the coverage backlog and re-verified directly against the primaries. This is a real hole in the window's completeness and is recorded as one, not softened: genuinely new research published on 2026-08-22 to 2026-08-24 by a lab outside those six primaries would not have been seen. The other gaps are transport, and all seven are logged in full above. Seven sources remain reachable only through the metered reader, whose pool is exhausted on all seven keys — which is what blocked the Spanish national CERT and the vulnerability-disclosure programme behind a standing backlog row, and what left two client-rendered regulator listings unread.

Coverage gaps: cisa-advisories (403, ninth consecutive run, all transports incl. reader); cisa-directives (403, eighth consecutive run); siemens-productcert-csaf (403, partial CSAF-mirror substitute); ssd-disclosure (empty body, reader-only source, pool exhausted); ccn-cert-es (reader-pinned, pool exhausted); ico-uk (200 but client-rendered, reader needed); ncsc-uk (200 but page shell, ladder not exhausted under wall-clock pressure); research-domain sweep (terminated by a classifier trip — no sweep performed).

Essential-coverage: missed=ncsc-uk (client-rendered listing, structured recipe not attempted before that work returned), cisa-advisories (403 on every transport), cisa-directives (403 on every transport).

This fire was overtaken, and the window was re-deduplicated on sync. Three other fires landed on main while this one sat mid-pipeline through a container stall and an account session limit. The 2026-08-24T0906Z-intel fire published the Cisco Secure Workload and Crosswork critical tail — the very item this run had recorded as a coverage-backlog row because it failed only the recency gate — so that row was struck before it was ever committed. More consequentially, the long-delayed 2026-08-22T0410Z-intel fire finally landed its own treatment of the SOCRadar FTP-banner dead-drop research, which this run had also composed from the same primary. That entry was dropped rather than published alongside the earlier one: same source, same event date, no material delta, and the earlier treatment is the fuller of the two. The entity namespace was reconciled the same way — the earlier fire had registered the two malware families as malware:e4del and malware:pinhole-rat, and this run's proposed malware:pinhole would have been a second key for a family that already had one, so it was removed before commit rather than becoming a duplicate the registry would have to tombstone later. The third overtake cost a second entry on the same grounds. The 2026-08-23T1311Z-audit fire's own retrospective truth pass had independently reached the same finding about Red Hat's product-state table for the Keycloak account-takeover flaw and published its correction as 2026-08-24/cve-2026-18963-keycloak-no-red-hat-product-unfixed, so this run's correction of the same record for the same CVE was dropped rather than published beside it. One fact from this run's own parse of that data is not carried by the surviving entry and is not being lost: the vendor's machine-readable product-state document for the flaw was revised on 2026-08-20, the day after this store's erroneous entry was written, which bears directly on the surviving correction's statement that there is no evidence the product state ever read differently. That is a fact about how this pipeline erred rather than something a defender acts on, so it is recorded as a correction owed on the surviving entry in state/coverage_backlog.md and left for the weekly audit to weigh, not published as a third entry on one CVE. What this run published is therefore seven entries, not the nine it composed. The same sync also revealed that main had independently gained a PDF-extraction recipe in the fetch bridge, better than the one written here (it selects on content type, tries mirrors, and distinguishes an image-only PDF from an empty one), so this run's version was discarded in favour of it and only the carve-out host-list fix was kept.

What was published, and why seven. Six of the seven entries clear the backlog the weekly stand-down of 01:10Z handed over — items that fire had already researched, deep-read and quote-verified but could not publish. Backlog rows are exempt from the recency gate because each was verified in-window by the fire that surfaced it and its age reflects a pipeline race rather than staleness; every one was still put to the relevance gate on today's facts and deduplicated against the fourteen-day index. Working that queue down is why this window is longer than the day's genuinely-new signal would suggest, and it is not volume inflation: the alternative was a silent hole, which is exactly what happened to the nine verified items a weekly stand-down listed on 2026-08-03 and never published. One of the seven is a mechanism update on ground the store already holds. A second correction — of a published error of this pipeline's own that overstated exposure on a CVSS 9.1 unauthenticated account-takeover flaw, and could have led a reader to defer it as unpatchable — was composed here and then dropped, because another fire had reached and published the same correction while this one was mid-pipeline; the fix is in the store either way.

Two entries carry a sourcing caveat worth restating here because both were near-misses for a fabricated link. The ShieldBreak mechanism entry ties its research to CVE-2026-69414, but the research names no CVE anywhere — re-confirmed this run by a case-insensitive search of the freshly fetched page body — so the linkage is this pipeline's reading of two accounts of the same named technique and the entry says so rather than implying the researcher made the connection. The ReliaQuest entry began as a piece about a circulating compromise claim set against the victim's own account of what happened, and the review pass established that its only cited source never mentions that claim at all — no extortion brand, no listing, no screenshots. Everything the source would not bear was removed rather than propped up with a weaker second source, so what publishes is the victim's own disclosure and the control lesson in it; the entity key was renamed for the same reason.

Entity-overlap decisions, confirmed deliberate. Two of this run's entries share entity keys with earlier in-window coverage and were still published as new entries rather than deltas; both calls were made knowingly. The half-year report entry links the Dream Job campaign key, which also appears on the 2026-08-12 entry about a Windows zero-day used by a state actor and on a weekly synthesis piece — but this entry is not a development in that campaign, it is the first coverage of a national authority's periodic report, whose Dream Job chapter contributes something neither earlier entry could: Swiss case counts, Swiss loss figures and the authority's own reporting-behaviour finding. Making it an update of a zero-day entry would have buried the report. The SilkParasite entry shares its campaign key with two 2026-08-23 weekly synthesis entries that name the cluster in passing; neither is an operational entry about it, none of its five newly named malware families was registered, and the reusable detection formulation appears in neither — so this is first dedicated coverage, not a delta, and the strategic-to-operational direction is the one the division of labour permits.

Single-source items and carve-outs. Every one of the seven entries is single-source, which is unusual for this pipeline and is stated plainly rather than smoothed over: this window's publishable signal was, almost entirely, individual parties reporting their own work or their own incident. Exactly two carry a carve-out value. The half-year report entry is single-source-national-cert — BACS is the disclosing authority for its own assessment and the report was minutes old, so no independent pickup existed; where it relies on another party's work (the Polish CERT's incident analysis and Static Tundra attribution, a vendor's Teams help-desk research, a national test institute's photovoltaic study) the entry attributes it there rather than to BACS. The ReliaQuest entry is single-source-victim. The remaining five are plain single-source: the ShieldBreak mechanism, SynkLoader, the Rapid7 quarterly, the AWS-key measurement and SilkParasite. One carve-out boundary was tested and got recorded wrong here before it was caught, and is worth restating because the entry that carried it was the one later dropped as a duplicate: a vendor's own product-security team is a first-party authority on its own products, but it is not one of the two carve-outs the policy defines — a national CERT or government authority for its own jurisdiction, and a victim's own disclosure — so vendor-only sourcing is plain single-source, never a carve-out. Each of the five carries its limitation in its own note rather than borrowing confidence from corroboration it does not have.

One internal tension in the half-year report is carried in the entry rather than resolved: its management summary describes reporting as having stabilised at a high level, while its first chapter states the voluntary total as a decline against the prior year's figure. Both are the report's own statements and the entry says so.

Borderline drops.

  • borderline-drop: Berlin Landesnetz compromise — fifth consecutive fire blocked on the same ground. The home-region research was tasked to establish one thing only: whether any named authority has since stated an access vector, product or CVE. None has, and the sole vector-adjacent claim in circulation is still an unattributed broadcaster characterisation. An incident entry needs an evidence-bound technique mapping and there is no attacker behaviour to map; inventing one is the defect class a prior audit repaired. The backlog row stays open.
  • borderline-drop: Cisco Secure Workload / Crosswork critical tail — eight critical flaws, five at CVSS 10.0, which the W34 weekly roll-up itself flagged as covered by no earlier fire. Relevant and uncovered, but the underlying disclosure is dated 2026-08-19/21 with no in-window delta, so it fails recency for a fresh item today. Recorded as a coverage-backlog row so a later fire publishes it as first coverage rather than losing it.
  • borderline-drop: CVE-2026-16242, Red Hat OpenShift / HyperShift Konnectivity proxy — an unauthenticated path into the control-plane-to-node channel, CVSS 9.4, fixed in 4.22.8, and never given a dedicated entry. Dropped on recency: published 2026-07-20 with the vulnerability database's dateUpdated bump being a resync rather than new disclosure. Also recorded as a backlog row.
  • borderline-drop: Zoom annotator buffer overwrite CVE-2026-53413 — out-of-window (primary sources 2026-08-11 to 2026-08-20), no in-window delta, dropped despite an eye-catching name.
  • borderline-drop: DJI consumer drone CVEs, a Turkish smart-meter authentication bypass, a GNU gzip local decompression overflow — off-scope for this constituency: physical-proximity or local vectors, no exploitation, no evidenced European public-sector or critical-infrastructure deployment.
  • borderline-drop: Japanese domestic-market product advisories — fresh but with no evidenced Swiss or European deployment base.
  • borderline-drop: three leak-site-only listings naming one Swiss and two German organisations — fake-news guard: attacker assertions with no victim, regulator or high-reliability corroboration.
  • borderline-drop: five vendor OSS-mirror CVE records published 2026-08-23 — exploitation and public-disclosure fields both null, no action beyond the regular patch cycle.

Out-of-window drops. out-of-window: Cisco Secure Workload / Crosswork tail — primary source 2026-08-19/21, window_hours=24. out-of-window: CVE-2026-16242 — primary source 2026-07-20, window_hours=24. out-of-window: CVE-2026-53413 — primary source 2026-08-11, window_hours=24.

A note on the version recorded above. prompt_version says v3.31 because that is the prompt this fire actually read and executed. While it was mid-pipeline an overtaking fire bumped the master prompts to v3.32, so the changelog on main now leads this record by one version. The gate's cross-check treats a trailing version as a versioning-rule breach — a prompt edit shipped without its changelog entry — and flagged it, which in this case would only have been "fixable" by claiming to have run a version this fire never saw. The check was therefore taught the distinction rather than satisfied with a false value: it now compares the working tree's prompts against origin/main, and a trailing version reports as informational when this run edited no prompt or agent definition. A genuine prompt edit shipped without a changelog bump still fails exactly as before.

State and tooling. Two tooling defects were fixed rather than logged for later. The half-year report's PDF as first fetched was corrupted — 2,840,294 bytes of mangled content against 1,733,418 bytes on a clean binary re-fetch — and every PDF library in this container fails to import because the pre-installed cryptography package is missing its _cffi_backend binding; stubbing that broken import chain made all 23 pages extractable, which is why the deep dive is composed from the report body rather than its press release. Both worked, so the deep-dive entry rests on the primary. The PDF workaround was then made permanent rather than left as a run anecdote: tools/fetch_source.py gained a pdf <URL> recipe that fetches in binary, refuses a non-PDF body with a clear message, survives a single unreadable page and raises a distinct error on an image-only document, verified against the same 23-page report. That closes the half of the standing Siemens S7 backlog row which asked for a working extraction path to be recorded in the bridge — a row opened because the 2026-08-20 run had to compose a five-agency advisory single-source from an outlet's reading for want of exactly this. It is deliberately NOT yet referenced from the research agents' fetch-tooling section: that would be an agent-definition edit, which must ship a banner bump across all three master prompts, a CHANGELOG entry and a byte-identical regeneration of the alternate verifier in the same commit, and this run is too far past its watchdog to take that on safely. The recipe is discoverable via --help and is recorded in .claude/memory/source-fetch-blocks.md, which every future fire loads; a run with headroom should do the definition edit. The source-health sweep probed 191 of 191 sources in 127 s and returned no unsolved repair order, which is consistent with the three recipe corrections this run made rather than deferred: a reader-pinned source proven reachable by the cheapest transport, and both Swiss authority records moved off a transport their site migration broke.

Watchlist: the organization profile configures no product and no supplier watchlist, so both sweeps were no-ops and neither agent spent time on them.

← Operations dashboard · run-record contract: docs/pipeline.md