2026-08-28T1500Z-audit
One pipeline fire, in full · audit run of 2026-08-28 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-28/2026-08-28T1500Z-audit.md.
Run telemetry
- Items returned
- 18
- Duration
- 2m 13s
- Tool calls
- not reported
- Cited sources
- none
- Items returned
- 17
- Duration
- 2m 01s
- Tool calls
- not reported
- Cited sources
- none
Verification
Deep dive
—
Entries this run published (0) and updated (39)
- Internet-facing enterprise software moved from 'at risk' to 'under attack' across the week — SonicWall SMA1000, Progress ShareFile, Oracle E-Business Suite and on-prem SharePoint all crossed into confirmed exploitation synthesis high improvement
- Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory — the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent threat high improvement
- CVE-2026-17583 — Thermo Fisher Applied Biosystems genetic analyzers write DNA result files with no integrity checking, so results can be altered after the run and no vendor fix is offered vulnerability high improvement
- Coding-agent CI harnesses broke on the same trust boundary three different ways — and the two findings that matter most carry no CVE at all research notable improvement
- Lazarus burned a Windows AFD.sys zero-day (CVE-2026-68820) on European defence targets — FudModule v3.1 blinds the endpoint, and the C2 is other people's Roundcube and WordPress servers threat high improvement
- CVE-2026-58231 — SAP Commerce Cloud: an unauthenticated request to the Data Hub Adapter import endpoint reaches arbitrary code execution (CVSS 10.0), and the fix needs a rebuild and redeploy vulnerability high improvement
- 2026-W33 vulnerability status roll-up — eight flaws crossed into confirmed exploitation or the federal catalogue this week, two of them within seventy-two hours of their own disclosure, against a critical tail led by two unauthenticated CVSS 10.0 flaws in industrial edge devices vulnerability high improvement
- CVE-2026-18963 — Keycloak's password-reset flow can be driven to completion without the verification email being clicked, handing an unauthenticated attacker any account including administrators (CVSS 9.1) vulnerability high improvement
- Five CVEs this week where the exploitation flag came apart — four where two authorities disagree outright, in both directions and once in this constituency's own national feed, and one where no feed had a flag to disagree about synthesis high improvement
- Berlin's state network was compromised on 14 August and both isolated Senate departments came back online on 23 August — nine days in which housing benefit stopped for more than 50,000 households and no named authority stated how the attackers got in synthesis high improvement
- Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release vulnerability high improvement
- Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included vulnerability high improvement
- YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all — three releases in three days, and the 3.x line has no fix vulnerability high improvement
- iCagenda Calendar module for Joomla: unauthenticated SQL injection via com_ajax needs no session, token or account (CVE-2026-67365, CVSS 9.2) — and the vulnerable module's own version number does not track the package version vulnerability notable improvement
- Unisoc T606/T612/T7250 modems: a single answered video call can escalate from modem-level RCE to full Android kernel access via an ARM Memory Protection Unit isolation bypass — no CVE, no patch, vendor unresponsive vulnerability high improvement
- JFrog Artifactory: authenticated Docker-cache path traversal (CVE-2026-66384) added to CISA KEV — a CI/CD artifact-store write primitive with no published exploitation narrative vulnerability notable improvement
- A 2023 ownCloud auth-bypass CVE re-enters CISA KEV because Hunt.io caught a suspected Chinese-speaking operator's open staging server using it to steal nuclear-research and naval-contractor data from two Philippine organisations threat high improvement
- miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products — one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line vulnerability high improvement
- Kaltura mwEmbed/html5lib video player: unauthenticated RCE and arbitrary file read via an undocumented ServiceUrl parameter — no vendor response, no patch, 630+ exposed instances found by the discoverer vulnerability high improvement
- Linux kernel IPv6 UDP fraggap accounting bug (CVE-2026-53362) added to CISA KEV — an unprivileged local heap overflow via MSG_SPLICE_PAGES, no exploitation narrative published vulnerability notable improvement
- DOJ/FBI seize domains behind QScan and QTRouter, the hacking-as-a-service platforms a PRC contractor sold to China's MSS and PLA — NASA, the Federal Reserve, DOJ, HHS, NIH and the US Senate named among the victims of activity DOJ dates to at least 2018, with European infrastructure among Lumen's own profiled targets threat high improvement
- AFP-FBI-WAPF disrupt TeamPCP: two Western Australia men charged over the npm/GitHub supply-chain worm operation AFP estimates compromised 1,000+ organisations, 500,000+ credentials and 300+ GB of data incident notable improvement
- Manchester Airports Group confirms a breach touching roughly 8.7 million customers across Manchester, Stansted and East Midlands — car-park, lounge and airport-WiFi sign-up data taken, no operational or payment-card impact, no actor named incident high improvement
- A near-autonomous, multi-agent AI framework compromised Taiwanese government infrastructure over four days — cracking 85 accounts, exfiltrating 2,564+ personnel records, and bypassing its own safety guardrails by reframing itself as 'authorized penetration testing' incident high improvement
- Nimbus Manticore (Iranian IRGC-affiliated APT, aka Tortoiseshell/UNC1549/Smoke Sandstorm/Mirage Kitten) deploys a third 2026 toolset refresh — a TWOSTROKE-like backdoor abusing DLL search-order hijacking, paired with a reverse SSH tunneler — with confirmed expansion into the UK, France, Albania and Belarus threat high improvement
- CNCMachineRMS — an undocumented remote-access trojan delivered through a four-stage BabaDeda loader chain that smuggles shellcode via a benign Windows date-formatting API threat notable improvement
- Kudelski Security: North Korean IT-worker infrastructure overlaps a Bismarck-linked gambling-platform operation and the FakeCalls Android banking trojan threat notable improvement
- Wiz's autonomous AI red-teaming agent found and exploited a GitHub Actions command-injection flaw in Snowflake's public connector repo, exfiltrating live Jira credentials via an out-of-band callback research notable improvement
- GTIG Agentic Vulnerability Discovery Harness (AVDH): Mandiant's multi-agent pipeline found 100+ true-positive critical vulnerabilities in a stolen corporate source-code repository within two days research notable improvement
- TA4922 adds PackClient, a Telegram-sold modular RAT/C2 framework, to its toolkit — dual-channel C2, registry-resident configuration, and tax-themed lures against mainland China and India threat notable improvement
- Unit 42's dataset of 405 AI-enabled malware samples finds 97% never leave sandboxes, and every sample that reached a production environment was caught by existing behavioural detection with no novel approach required research notable improvement
- Martigny-Combe (Valais) municipal email account compromised and used to send a fraudulent message to administration contacts — second Valais municipality hit in 2026 incident notable improvement
- La Protection Civile (France): eProtec volunteer-management platform breach, 525,000+ profiles including minors, intrusion dated to March 2026 discovered mid-August incident notable improvement
- SUEZ Eau France notifies customers of a technical service provider's breach — identity, contract and, for some customers, bank and identity-document data exposed incident notable improvement
- Nozomi Networks/CBC: Winnipeg's largest hospital network loses HVAC and door-access central monitoring to a ransomware incident with no named actor, access vector, or ransomware family disclosed 18 days later incident notable improvement
- Troy Hunt: a 24.9M-address ShinyHunters/Carhartt breach-claim collapses to 12.9M real records once TPC-DS synthetic benchmark data and several duplicate/test-account patterns are filtered out — a reusable methodology for verifying inflated breach-claim record counts research notable improvement
- Claroty Team82: 23 vulnerabilities in Copeland XWEB Pro supervisory refrigeration controllers chain to unauthenticated root RCE — a deterministic admin password derived from the device's own MAC address is one of THREE independent pre-auth paths vulnerability high improvement
- Claroty Team82: Danfoss AK-SM 800A refrigeration system managers — undocumented 'code-of-the-day' authentication bypass and post-authentication command-injection RCE across thousands of internet-exposed devices vulnerability notable improvement
- NCSC UK advisory: increased targeting of internet-exposed OT and edge devices globally, including the UK, by state and non-state actors, with 'some limited real-world disruption' threat high improvement
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
2 tier standard -> essential (operator-named critical source; not attempted by the 2026-08-28 fire under rotation).
| Source | Change | From → To | Reason |
|---|---|---|---|
| heise-sec | tier standard -> essential (operator-named critical source; not attempted by the 2026-08-28 fire under rotation) | — → — | |
| inside-it-ch | tier standard -> essential (operator-named critical source; not attempted by the 2026-08-28 fire under rotation) | — → — |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-08-28T1500Z-audit · audit · "Fable 5" # Anthropic Claude Fable 5 (Mythos-class, above Opus) — self-identified from the harness model line; correct, not a Series-5 Sonnet/Opus · window 17 h · 0 entries published
Operator-directed review session — 2026-08-28 (v4.2)
This record books an operator-directed interactive session (Claude Code, sandboxed container, read-only git — the operator stages and commits on the host), not a scheduled fire. The operator's directive: review the latest fire's findings; stop pinning the two agent definitions to a dated model id; keep pipeline internals out of reader-facing text (note them in the changelog with no user-facing message and no new timestamp); rebalance the inclusion/length discipline toward quality over quantity; and confirm the operator-named critical sources (NCSC-CH, Heise Security, Inside-IT) actually deliver article detail, not just headlines.
What changed
- v4.2 lifecycle mechanics (
site/content_model.py,site/build.py,docs/pipeline.md, both master prompts,.claude/agents/cti-verification.md,CLAUDE.md):updates[]records may carryinternal: true— changelog-only, no body section, never rendered;updated_atnow mirrors only the last non-internaltype: updaterecord, so corrections and improvements no longer re-float entries in /live/. Store migration: 8 entries'updated_atrecomputed; the Lazarus CVE-2025-49113 metadata correction converted to internal (its reader-facing section removed); the Gemini CLI CVSS-divergence correction section rewritten reader-facing. - Editorial pass over the 2026-08-28T0409Z fire's 36 entries (two read-only review passes, fixes applied centrally): composition-rationale narration ("actions[] is empty because…", "techniques[] maps only…", "per this pipeline's house rules", registry keys in prose, "this pipeline/store/run" self-references) removed from bodies and sourcing notes; the worst verbosity cut (Manchester Airports technique-mapping justification; Suez sourcing-difficulty paragraph; NCSC-UK generic OT-hardening list compressed; Taiwan attribution paragraph compressed; Winnipeg redundant closer; protection-civile null closer; Copeland inline 17-CVE re-list; JFrog KEV-exposition; Danfoss restatement; GTIG cross-entry comparison; kernel-KEV meta-discussion). One wording fix: the redundant "chipset-free," deleted from "a chipset-free, purely configuration-driven authentication bypass" (ownCloud entry). No factual claim changed; every touched entry carries one internal
improvementrecord with run_id 2026-08-28T1500Z-audit. - Model pins:
cti-researchandcti-verificationfrontmattermodel:changedclaude-sonnet-5->sonnet(generic alias tracks the current Sonnet generation). - Sources:
heise-secandinside-it-chpromoted totier: essential— neither was attempted by the 2026-08-28 fire (rotation), heise last contributed 2026-06-20. Known constraint surfaced to the operator: the jina reader pool was fully exhausted (7/7 keys) during the 2026-08-28 fire; heise article bodies arefetch_method: jina-dependent, so until keys are refilled heise coverage is headline-only even on the essential floor. NCSC-CH coverage is healthy (essential tier, attempted and used by the fire via the Security Hub API recipe). - Prompt/CHANGELOG: v4.2 entry; PD-11 rebalanced (sound throughout; complete on critical/high signal; below that, quality over quantity — shorter or not at all).
Governance note (both verifier iterations flagged it; acknowledged, not fixed). This session edited already-published changelog-section prose and record summaries in place in five entries (Lazarus, Thermo Fisher, SAP, Unit 42 autonomous-AI, Keycloak) to remove pipeline jargon and translate quotes — in tension with the "earlier records are never edited" invariant. This was operator-directed (the 2026-08-28 directive explicitly covers retrofitting internals out of reader-facing text), is fully visible in the commit diff, and is a one-time migration; routine fires must never do this.
The 0409Z fire's 7 verification residuals — disposition. Two resolved this session offline (DOJ QScan 2018-dating sentence splice; YOOtheme spliced evidence quote). Five remain for the next audit with network access: Unisoc device/CWE/date details vs the unreachable Dark Reading source; Copeland CVE-2026-21718 mechanism mapping (entry's own inference); ownCloud/Hunt.io ZKTeco BioTime personnel-surveillance angle (missed coverage); Unit 42 AI-malware telemetry-window staleness caveat; miniOrange third WordPress-side CVE in the same disclosure.
For the next audit's warning sweep. Two warnings are this run's own telemetry facts, left for the audit per the no-self-acknowledgment rule: (a) duration_seconds ~7.2 h — an operator-interactive session paced by human turns and four verification iterations, not a stalled routine fire; (b) the recorded confirmation waiver above. Also for awareness: the editorial quality review used two general-purpose read-only passes rather than the named definitions — deliberate (the task was editorial review of published text, not source research or Phase 5.7 verification, and the named definitions embed duties that do not apply), surfaced here because iteration 4's verifier flagged the tension with the named-sub-agent rule.
Coverage gaps: none newly identified beyond the reader-pool exhaustion above (operator action: refill JINA_API_KEYS).
← Operations dashboard · run-record contract: docs/pipeline.md