ctipilot.ch

2026-08-28T0409Z-intel

One pipeline fire, in full · intel run of 2026-08-28 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-28/2026-08-28T0409Z-intel.md.

Run telemetry

2026-08-28T0409Z-intel intel prompt v4.1 publish ok
3h 29m duration 36 published 7 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
21
Duration
25m 14s
Tool calls
24 WebFetch14 WebSearch38 bridge
Cited sources
4 of 25 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
11m 12s
Tool calls
0 WebFetch13 WebSearch30 bridge
Cited sources
1 of 27 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
14
Duration
15m 43s
Tool calls
33 WebFetch6 WebSearch4 bridge
Cited sources
2 of 17 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
7
Duration
16m 41s
Tool calls
8 WebFetch10 WebSearch28 bridge
Cited sources
3 of 16 in slice

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=3 e=0 a=3 #2 NEEDS_FIXES · Sonnet 5 · t=3 e=2 a=0 #3 CLEAN · Sonnet 5 · t=0 e=0 a=1 #4 NEEDS_FIXES · Sonnet 5 · t=5 e=2 a=2 #5 NEEDS_FIXES · Sonnet 5 · t=5 e=2 a=0 #6 NEEDS_FIXES · Sonnet 5 · t=10 e=3 a=1

Deep dive

2026-08-28/taiwan-agentic-ai-intrusion-openclaw-hermes-guardrail-bypass

Entries this run published (36) and updated (7)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

5 status · 1 added.

SourceChangeFrom → ToReason
symantec-broadcomstatuscandidate → activepromotion_due: >=3 contributing runs
bitdefender-threat-debriefstatuscandidate → activepromotion_due: >=3 contributing runs
forescout-vederestatuscandidate → activepromotion_due: >=3 contributing runs
venarixstatuscandidate → activepromotion_due: >=3 contributing runs
wordfencestatuscandidate → activepromotion_due: >=3 contributing runs
offseqadded— → candidatethis run's one new candidate source — discoverer of CVE-2026-59109 (Zalktis) and other Baltic/EU CERT.LV-coordinated vulnerability disclosures

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 6 findings (truth=3, editorial=0, advisory=3) · Claude Sonnet 5 · 9m 16s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Three evidence[] quotes were attributed to publisher "Troy Hunt" but are verbatim output from "PwnedClaw," Hunt's AI chat assistant, inside a reproduced chat transcript in his own post — not statementRe-attributed all three evidence[] quotes to "PwnedClaw, quoted by Troy Hunt (Have I Been Pwned)"; rewrote the body to attribute each quoted analytical conclusi
F3
claim-not-supported
Entry's headline/body figure "roughly 13.3M" real records was an intermediate step in Hunt's own cleanup; his own final published/tweeted figure is 12,933,413 (12.9M), after removing further MicrosoftRewrote title, summary and body to state the correct final figure (12,933,413 / 12.9M), added the additional cleanup steps (5,736 Microsoft-365 alias triplicate
F3
claim-not-supported
The correction record added this run inverts NVD's own "Primary"/"Secondary" designation between the CVSS 3.1 (7.8) and CVSS 4.0 (10.0) scores for CVE-2026-12537 — confirmed directly against the NVD CRe-verified directly against the live NVD CVE 2.0 API (confirmed the verifier's finding exactly). Corrected the frontmatter cvss field and both body mentions (t
F14
?
(low confidence) Fetched Splunk advisory (SVD-2026-0801) table lists 60 distinct CVE ids, not ~55 — a ~9% undercount on the entry's own headline scope claim.Re-fetched the advisory directly and counted 60 distinct CVE-2026-* ids in the extracted text, confirming the finding. Changed "roughly 55 CVEs" to "60 CVEs" in
F16
?
(low confidence) T1078 (Valid Accounts) is mapped from the advisory's generic credential-hardening recommendation, not from any described access technique in the disruptive activity the advisory reporAgreed with the finding on re-read of the entry's own cited evidence: the default/shared-credential language appears only in mitigation guidance, not as a descr
F17
?
(low confidence) Credibility 1 rests on NVD/MITRE corroboration that confirms only the CVE id/range/coordinating authority, not the entry's substantive technical claims (all from OffSeq alone); credibAgreed with the finding: NVD/MITRE independently confirms only the CVE's existence/range/coordinating authority, not the four vulnerable code paths, the missing

Iteration #2 NEEDS_FIXES · 6 findings (truth=3, editorial=2, advisory=0) · Claude Sonnet 5 · 11m 20s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
Frontmatter title stated 24.8M as the initial address count; the entry's own summary/body and the source's own figure (24,876,077) round to 24.9M — an internal numeric contradiction introduced alongsiChanged title's "24.8M-address" to "24.9M-address" to match the summary/body and the source figure.
F14
?
"A further nine CVEs score 9.9–9.8" undercounts by one; the entry's own cited primary (NCSC-CH post 12880) lists ten CVEs at that band.Re-fetched the NCSC-CH advisory directly, counted ten CVEs at 9.9–9.8, confirmed the finding. Changed "nine" to "ten" in the summary and body (two mentions).
F14
?
(low confidence) "12+ assigned CVEs" mildly overstates; the cited Mandiant blog states exactly 12 assigned, with a further dozen explicitly not-yet-assigned ("in active disclosure").Agreed with the finding. Changed "12+ assigned CVEs" to "12 assigned CVEs, with a further dozen in active disclosure" in the summary and both body mentions.
F5
missing-citation
A CERT/CC quote in the body carried no inline citation, and kb.cert.org/vuls/id/308749 was not listed in sources[] — the entry's sole listed source never mentions CERT/CC, despite the sourcing_note exAdded CERT/CC (kb.cert.org/vuls/id/308749) to sources[] as a corroborating source (confirmed live, HTTP 200, despite the corrupted-body extraction issue this ru
F5
missing-citation
"...counts former PLA members among its staff" carried no inline citation; DOJ's and Lumen's own material (the entry's stated primaries) do not state this — it traces only to BleepingComputer's reportRe-fetched BleepingComputer's article directly and confirmed the verbatim quote ("Court documents reveal that the threat group includes former members of the Ch
F7
drop
(low confidence) Relevance judgment call: out-of-nexus victim (Canada), no named actor, and the BMS/HVAC segmentation lesson, while real, is an already-well-established OT/IT segmentation pattern rathDeclined. Rebuttal: sectors[] includes healthcare, which is within this constituency's extended remit regardless of home-region nexus (established practice this

Iteration #3 CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Sonnet 5 · 6m 08s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
(advisory, low confidence) CVE-2026-75114 is named in the body with citation ("CVE-2026-75114 (CVSS 5.1) is a lower-severity open redirect in the Twitter comment callback") but omitted from frontmatteAgreed. Added a CVE-2026-75114 record to cves[] (open-redirect, CVSS 5.1, pre-auth/user-interaction, YOOtheme ZOO Twitter comment callback, fixed in 4.1.64/supe

Iteration #4 NEEDS_FIXES · 9 findings (truth=5, editorial=2, advisory=2) · Claude Sonnet 5 · 16m 45s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
"Roughly 2,765 internet-exposed devices" (title, summary, body, an action item) does not appear anywhere in the cited Claroty article, which states only "thousands of publicly accessible management inRe-fetched the Claroty article directly and confirmed it never states a precise count. Replaced "roughly 2,765" with "thousands of" throughout (title, summary,
F4
hallucinated-fact
CVE-2026-48273 is called "unauthenticated" (frontmatter auth: pre-auth) but Adobe's own CVSS vector for it is PR:L (low privileges required), contradicting the framing.Re-fetched Adobe's APSB26-90 table directly and confirmed PR:L on CVE-2026-48273's CVSS 3.1 vector. Changed frontmatter auth from pre-auth to post-auth for this
F4
hallucinated-fact
Two evidence[] quotes silently drop articles (the/a/an) from Arctic Wolf's actual sentences and splice two non-adjacent sentences together with an ellipsis — not verbatim contiguous substrings.Re-fetched Arctic Wolf's post directly. Split both spliced quotes into 4 separate verbatim evidence[] records (two for the blockchain-C2 mechanism, two for the
F4
hallucinated-fact
An evidence[] quote ("Walk 1's IsArrayBuffer() check says nothing about the value walk 2 receives, and As<ArrayBuffer>() is an unchecked reinterpret-cast, not a conversion") does not exist verbatim anRe-fetched Endor Labs' post directly and located the actual sentence. Replaced the fabricated quote with the verbatim text ("As <ArrayBuffer>() is not a checked
F4
hallucinated-fact
A bracketed redaction in an evidence[] quote substitutes the wrong referent — states the IPs overlap with "the gambling-platform operation" when Kudelski's actual text says they overlap with FakeCallsRe-fetched Kudelski's article directly and confirmed the actual sentence contains no literal indicator needing redaction at all. Replaced the miswritten bracket
F8
needs-more-research
sourcing_note incorrectly states Splunk's advisory does not describe any CVE reaching "the credential store" via privileged SPL escalation; CVE-2026-76253 (CVSS 8.8) does exactly that and is omitted fRe-fetched the Splunk advisory directly and confirmed CVE-2026-76253's description verbatim. Added it to cves[], added its quote to evidence[], added body cover
F11
editorial-advisory
(low confidence) Quote truncated at "...alongside Middle Eastern regions." where Group-IB's sentence continues "...including Israel, Turkey, and GCC member states," with no ellipsis marking the cut. SRe-fetched both Group-IB's and Proofpoint's articles directly and confirmed both truncations. Extended the Nimbus Manticore quote (evidence[] and body) to the f
F11
editorial-advisory
(low confidence) Body/frontmatter state PR:H as "the accurate"/"confirmed" vector for CVE-2026-76613, but mySites.guru's own post flags an unresolved mismatch between PR:H and the still-published "conRe-fetched mySites.guru's post directly and confirmed the unresolved-mismatch framing verbatim. Reworded the frontmatter cves[].affected field and the body sent
F17
?
Both entries use an identical sourcing shape (vendor/technical primary + CISA KEV feed as second primary) but the run rated one single-source and the other multi-source with no stated basis for the diAgreed: CISA KEV independently confirms exploitation, a distinct fact from the technical mechanism only the vendor/upstream source describes, so the same reason

Iteration #5 NEEDS_FIXES · 7 findings (truth=5, editorial=2, advisory=0) · Claude Sonnet 5 · 12m 09s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
sourcing_note falsely claims no 1:1 CVE-to-endpoint mapping exists for the remaining 18 CVEs; the same Claroty page (re-fetched) lists 20 of 23 CVEs individually with CVSS scores and per-endpoint descRe-fetched Claroty's article directly and extracted all 20 individually-described CVE records. Rewrote cves[] to carry all 20 (was 2) with correct CVSS/auth/per
F4
hallucinated-fact
Claims Vétroz (April) was an "account-compromise-class incident"; the entry's own cited source article only says Vétroz was "lahmgelegt" (disabled/paralysed) by a cyberattack, with no incident-type deRe-fetched the SwissCybersecurity.net article directly and confirmed it states no incident type for Vétroz. Changed "account-compromise-class incident" to "cybe
F3
claim-not-supported
Folds a CSRF finding into the successful kill-chain narrative though Tenable's own article states it "was not among the confirmed breach vectors in this campaign (the actual compromises came from servRe-fetched Tenable's article directly and confirmed the caveat verbatim. Added the caveat as its own cited sentence immediately after the CSRF-discovery sentenc
F3
claim-not-supported
Attributes the "state-adjacent contractor" confidence assessment to Dream Security's linguistic analysis when it is Tenable's own separate hypothesis-evaluation, not Dream Security's.Re-fetched Tenable's article directly and confirmed the hypothesis-evaluation is Tenable's own (three competing hypotheses: state-sponsored, state-adjacent cont
F4
hallucinated-fact
An evidence[] quote splices two verbatim bullet-list fragments with a paraphrased, non-verbatim closing clause ("and successfully received the out-of-band callback") presented as one continuous quote;Re-fetched Wiz's article directly and confirmed both issues. Split the first quote into two separate verbatim bullet-fragment quotes and rewrote the body citati
F8
needs-more-research
Source documents a second, independent detection trap (iCagenda's own update feed not yet listing 4.0.12, so an automated update-status check reports a vulnerable site as current) beyond the module-vsRe-fetched mySites.guru's article directly and confirmed the second detection trap verbatim. Added it to evidence[] and the body as a second, independent trap,
F14
?
(low confidence) Summary states "seven energy companies" as an exact figure; Dream Security's own source (cited for that sentence) states "7+ energy sector companies", a floor not an exact count.Fixed together with the F3 finding above on the same entry — changed to "7+" in both summary and body.

Iteration #6 NEEDS_FIXES cap-breach · 13 findings (truth=10, editorial=3, advisory=1) · Claude Sonnet 5 · 14m 45s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
evidence[] quote and matching body quote fabricated the sentence's closing clause ("a site can show iCagenda 4.0.11 while the vulnerable module reports 4.0.7") in place of the source's actual text ("tRe-fetched mySites.guru's article directly and confirmed the actual sentence. Replaced the fabricated clause with the verbatim text in both evidence[] and the b
F4
hallucinated-fact
"PCPJack" named as a Shai-Hulud copycat variant; does not appear anywhere in either cited source (KrebsOnSecurity, AFP release) for this entry. (PCPJack is a real, separately-tracked entity in this stRe-fetched KrebsOnSecurity's article directly and confirmed no mention of PCPJack or any copycat-variant claim. Removed the unsupported clause entirely rather t
F9
surface-contradiction
sourcing_note states The Register's "a hack, not a lapse" characterisation is the outlet's own framing, contradicting the entry's own body text (correct) that attributes it to MAG's spokesperson.Reworded sourcing_note to match the body's (correct) attribution to MAG's spokesperson rather than The Register's own voice.
F14
?
(low confidence) Title states "~6M installs"; neither cited source (Patchstack, The Hacker News) states an install-base figure.Removed the unsupported install-count parenthetical from the title.
F14
?
(low confidence) States paid Joomla editions "were fixed 26 August, two days after the free-line fix"; mySites.guru's own timeline puts the free-line CVE publish and paid-edition fix one day apart (25Corrected "two days after the free-line fix" to "the day after the free-line CVE was published".
F4
hallucinated-fact
(low confidence) updates[] record's fields[] lists only [evidence, techniques, body], but git diff shows this run's update also changed sources[] (2 new records) and actions[] (merged/reworded).Added sources and actions to the update record's fields[] list to match what was actually changed.
F4
hallucinated-fact
(low confidence) Device-to-chipset mapping, a CWE-674 label for 'stage two', and a March 2026 stage-one disclosure date are not stated in the one reachable primary (Infosecurity Magazine); the entry'sLanded as a residual — the entry's own sourcing_note already discloses SSD Secure Disclosure's original posts were unreachable this run and the entry is compose
F13
?
(low confidence) Mapping CVE-2026-21718 specifically to the narratively-described deterministic-password-generator mechanism is this entry's own inference by elimination; Claroty's per-CVE table descrLanded as a residual — the mapping is a reasonable inference (it is the only pre-auth, non-command-injection CVE among the 20 confirmed records that isn't CVE-2
F3
claim-not-supported
(low confidence) "Named victims since at least 2018 include NASA..." splices DOJ's named-victims sentence with a separately-stated activity-dating sentence as if the date applies specifically to thoseLanded as a residual given the watchdog — the underlying facts (the victim list and the 2018 activity-start date) are each independently DOJ-stated, and the spl
F8
needs-more-research
Hunt.io's own article headlines a personnel-surveillance angle (ZKTeco BioTime biometric/attendance database referencing multiple Philippine science/research orgs) via a dedicated Key Findings bullet Landed as a residual — a genuine missed angle worth a fresh read and possible body addition, but incorporating it correctly needs a full re-read of Hunt.io's ZK
F8
needs-more-research
Unit 42's own telemetry windows (Cortex XDR, December 2024-June 2025) are over a year old at publication; the entry presents the findings without this staleness caveat, material to a thesis about currLanded as a residual — a valid editorial point but not a factual error; flagged for the quality audit to add a caveat sentence.
F8
needs-more-research
(low confidence) Patchstack documents a third, separate WordPress-side vulnerability in the same disclosure this entry otherwise covers exhaustively; omitted entirely.Landed as a residual given the watchdog — would need a fresh fetch and a full new CVE record rather than a quick patch; flagged for the quality audit.
F11
editorial-advisory
(low confidence, advisory) The first evidence[] quote splices three non-contiguous but individually verbatim fragments with two ellipses — not deceptive (no fact altered) but not a contiguous substrinLanded as a residual — advisory-only and non-deceptive; flagged for the quality audit to split into separate verbatim quotes.

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-28T0409Z-intel · Sonnet 5 · window 94 h · 36 entries published

Verification & coverage notes

Wall-clock watchdog (anti-crash guard #10). This run's Phase 5.7 verification loop found genuine, substantive defects on four of its five iterations (1, 2, 4, 5 all NEEDS_FIXES; only iteration 3 returned CLEAN, and it was not confirmed by iteration 4's cold re-read) — every remediation was independently re-verified against a live re-fetch of the cited source before being recorded, so the loop's cost bought real correctness, not busywork. By the end of iteration 5 the run had crossed the ~3 h wall-clock mark (main.started_at 04:09:50Z; iteration 5 ended 07:05:58Z, ~2h56m elapsed at that point, and fix/re-verification work pushed the clock past 3h before the next spawn). Per the watchdog rule, iteration 6 is being run as the final iteration regardless of outcome: a CLEAN publishes on verification.confirmation_waived (this note) rather than requiring a second confirming CLEAN; a NEEDS_FIXES with truth+editorial ≤2 and no F1/F4 publishes on the standing early-exit rule with residuals documented; anything worse is landed with residuals rather than extending the loop further. duration_seconds genuinely exceeds the 3h/10800s runaway threshold as a result — that is the watchdog functioning as designed on a run whose entry volume and multi-day catch-up window made an unusually long verification tail likely from the outset, not a stall.

Coverage window: catch-up of 91 h (previous run 2026-08-24T0906Z-intel, which stood down on a stale-clock detection with zero substantive research). The prior genuinely substantive fire was 2026-08-24T0410Z-intel; the gap therefore spans nearly four days, most of it already covered by the 2026-08-23/24 audit and weekly runs whose entries load into the 14-day dedup window. This run's job was the new signal since the last fire, worked exploitation-first per the catch-up-class table, plus systematic clearance of the coverage backlog accumulated across that gap (state/coverage_backlog.md carried 8 open rows from the 2026-08-23T1311Z audit and 12 from the 2026-08-24T0902Z audit at the start of this run).

Backlog clearance. 24 of the 26 open coverage-backlog rows at the start of this run were resolved: 20 published (14 as new entries, plus the two-part Joomla wave and Copeland/Danfoss OT pair counted individually — see the full breakdown in the backlog file itself), 3 published as correction changelog records against existing entries, 1 struck as already-covered with no material delta (DGCCRF Bloctel), 1 struck as stale (1Password FLAWED study), and 1 struck on relevance after re-verification reversed the earlier framing (TheHatman — Unit 42 explicitly declines to verify the actor's claimed vector and the named victim TCS denies the breach). One row (GreenPlasma) was newly re-gated and struck this run as not clearing the bar (local-only LPE, PoC already deleted, no exploitation). 5 rows remain open and are carried forward unchanged or with a brief re-check note: the Zurich trial verdict (not due until 2026-09-10), the Siemens S7 PDF residual quotes (low priority), the npm RedC2 aggregator-only gap, the out-of-window OpenShift CVE, and the Keycloak VEX meta-correction (not defender-facing on its own).

Berlin Landesnetz — sixth consecutive fire with no named vector. S2's re-check found two genuine authority-sourced deltas (the intrusion is now dated to 7 August rather than 14 August, and the Senate's own data-exposure assessment has widened to being unable to rule out personal data) plus an unconfirmed press ransom-demand claim, all folded into an update record on the existing strategic-synthesis entry rather than a new operational entry — no authority has yet named an access vector, product or CVE, so an incident entry with an evidence-bound technique mapping still cannot be composed without fabrication.

Two additional corrections found and fixed outside the tasked backlog. While reviewing entries for the tasked corrections, a third machine-surface defect was found in 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule: the cves[] record for CVE-2025-49113 carried auth: pre-auth/vector: zero-click, inverting the flaw's actual credential-gated access path — a defect the entry's own body text had already correctly described. Corrected in the same pattern as the two backlog-tasked corrections (Gemini CLI CVSS/vector; SAP CVE-2026-44772 remedy).

Volume note. 36 new entries and 7 updated entries is well above a typical single-fire count. This reflects the mechanics of the window, not a relaxed gate: a 91-hour gap concentrated three audits' worth of deferred-on-wall-clock backlog items, plus a mandatory outage-backfill sweep (S3) that is specifically designed to catch vendor research-blog publications a normal recency-gated sweep misses across a multi-day gap. Every item was still put to the full PD-11 relevance/actionability gate individually; items that did not clear it (GreenPlasma, TheHatman, the 1Password study) were dropped or struck regardless of how long they had sat in the backlog.

Single-assessor caveats (PD-5). CVE-2026-59310's newly-reported China-nexus attribution and Babuk-ransomware finding — both surfaced by this run's research — duplicate CVE coverage already carried by 2026-07-30/vmware-vmsa-2026-0006-vcenter-auth-bypass-vmxnet3-escape (PD-8 dedup), so they were folded into a new update changelog record on that existing entry rather than published as a standalone entry. The record explicitly flags that both findings trace to one incident-response firm's (QUIRSO) investigation of one incident, not to cross-corroborated intelligence, despite two press outlets reporting it; the entry's overall A/1 classification is left untouched since it reflects the multi-CERT-corroborated vulnerability and initial-exploitation facts, not these two single-assessor additions. 2026-08-28/suez-eau-france-supplier-breach is published under the single-source-victim carve-out — three independent trackers each state they obtained SUEZ's own customer notification letter directly, but none is itself an Admiralty B+ outlet, so credibility is held at 2.

Shared-entity new-entry decisions confirmed deliberate. 2026-08-28/teampcp-afp-fbi-disruption-shai-hulud-arrests shares actor:teampcp with 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection and 2026-08-16/weekly-w33-developer-credential-audits-wrong-artefact, but those two entries are SOCRadar's technical re-scoping of the LiteLLM credential-collection timeline, not the actor's legal status — a law-enforcement disruption and criminal charges are a distinct event class that does not belong in either entry's changelog, so a new entry is correct. 2026-08-28/kudelski-bismarck-dprk-it-worker-gambling-fakecalls-overlap shares actor:purpledelta with 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection and 2026-08-23/weekly-w34-ai-bought-throughput-not-capability, but Kudelski's finding is about a separately-designated actor ("Bismarck") whose infrastructure overlaps PurpleDelta's, not new information about PurpleDelta's own fraudulent-hiring operation — the entity link is an overlap finding, not a delta on the existing entry's subject, so a new entry is correct here too.

Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0 — no product or supplier watchlists are configured on this deployment; the sweep is a no-op per policy.

Essential-coverage: no essential-tier source miss this run beyond the standing rotation-priority gaps already logged (cisa-advisories/cisa-directives 403, ssd-disclosure and fox-it-blog/ibm-xforce reader-quota/JS-shell — all pre-existing, unresolved by this run's transport ladder, covered_anyway via alternate primaries where the item was published).

Coverage gaps: cisa-advisories (403, recovered via CSAF GitHub mirror); ssd-disclosure (reader-quota, all 7 keys exhausted — covered via two independent secondaries for the Unisoc item); fox-it-blog, ibm-xforce (JS-shell/no structured feed); community.ui.com (JS SPA, recovered via NCSC-CH's own transcription); kb.cert.org (corrupted binary body on the Kaltura CERT/CC note, one quote carried at reduced confidence via prior WebFetch summarization).

← Operations dashboard · run-record contract: docs/pipeline.md