ctipilot.ch

2026-08-29T0409Z-intel

One pipeline fire, in full · intel run of 2026-08-29 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-29/2026-08-29T0409Z-intel.md.

Run telemetry

2026-08-29T0409Z-intel intel prompt v4.3 publish ok
2h 52m duration 7 published 1 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
8m 58s
Tool calls
0 WebFetch6 WebSearch30 bridge
Cited sources
4 of 11 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
12m 21s
Tool calls
1 WebFetch19 WebSearch37 bridge
Cited sources
1 of 15 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
10m 56s
Tool calls
0 WebFetch2 WebSearch24 bridge
Cited sources
1 of 11 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
10m 10s
Tool calls
1 WebFetch18 WebSearch22 bridge
Cited sources
2 of 6 in slice

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=10 e=2 a=2 #2 NEEDS_FIXES · Sonnet 5 · t=4 e=2 a=0 #3 NEEDS_FIXES · Sonnet 5 · t=6 e=1 a=0 #4 NEEDS_FIXES · Sonnet 5 · t=4 e=1 a=0 #5 NEEDS_FIXES · Sonnet 5 · t=3 e=3 a=1 #6 NEEDS_FIXES · Sonnet 5 · t=3 e=0 a=3 #7 NEEDS_FIXES · Sonnet 5 · t=1 e=1 a=3 #8 NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=3

Deep dive

2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce

Entries this run published (7) and updated (1)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 status.

SourceChangeFrom → ToReason
hunt-iostatuscandidate → active3 contributing runs — promotion_due bar met per state-summary digest (sources.promotion_due)

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
searchlight-cyberhttps://slcyber.io/research-center/webfetchjinabridge-extractNone consent-wall
Cookiebot consent overlay returned instead of article listing on webfetch, jina, and bridge extract
none
team-cymruhttps://www.team-cymru.com/blogwebfetchjina200 ad-redirect
Resolves through match.adsrvr.org ad-tracking redirect; only a 1x1 tracking pixel returned via direct fetch and jina
none
paradigm-shift-researchhttps://ps.tc/bridgeNone spa-stub
Client-side SPA returns only a meta-refresh redirect stub via the bridge's raw fetch; no server-rendered content or feed
none
sans-icshttps://www.sans.org/blog/?focus-area=industrial-control-systems-icswebfetchjina200 ad-redirect
Resolves through the same ad-tracking redirect as team-cymru; only a 1x1 tracking pixel returned via jina
none
inside-it-chhttps://www.inside-it.ch/insel-gruppe-verschiebt-wechsel-zu-servicenowrsswebfetchextractbridge:urljina403 http-403
Article 'Insel Gruppe verschiebt Wechsel zu ServiceNow' (citing 'einen Sicherheitsvorfall') 403'd on direct fetch, trafilatura extraction, jina fallback, and th
none

Bridge invocations (this run)

5 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

5 other
  • cisa page / feed ×1
  • cisa page ×1
  • ncsc-csh recent 20 ×1
  • bacs.admin.ch aktuelle-vorfaelle ×1
  • jina (JS-rendered Framer site) ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 13 findings (truth=10, editorial=2, advisory=2) · Claude Sonnet 5 · 10m 43s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F2
generic-url
Exchange entry's NCSC-NL source corrected from the RSS feed listing to the specific advisory NCSC-2026-0289 (fetched via the bridge's ncsc-nl csaf recipe); body
F3
claim-not-supported
PaperCut: Home-page-bypass claim re-cited from PaperCut Software to Rapid7, the source that actually states it.
F3
claim-not-supported
ServiceNow: GraphQL/image-upload/ORDER BY mechanism specifics and the CVSS vector string re-cited from ServiceNow to The Hacker News, the source that actually s
F3
claim-not-supported
German IMEI entry: Wireshark-capture detail and the Karsten Nohl/SRLabs quote re-cited from BR24 to heise, the source that actually states them (re-fetched heis
F4
hallucinated-fact
ServiceNow CVE-2026-18886 affected/product field corrected from 'Now Platform' to 'AI Platform', matching ServiceNow's own advisory text; title/summary/body rew
F4
hallucinated-fact
ENDLESSDOORS update: removed unsupported T1090 (Proxy) technique — grepped both VulnCheck posts and heise's article for proxy/pivot/socks with zero matches.
F4
hallucinated-fact
ENDLESSDOORS update: corrected the WiFlyer rebrand pairing from WE826-T2 (only Deep Orange is demonstrated on that platform) to WG3526, per VulnCheck's own text
F4
hallucinated-fact
Swiss-cantons evidence[] quote de-ellipsised into one contiguous, verbatim substring of the cash.ch article (previously spliced two non-adjacent sentences).
F5
missing-citation
Swiss-cantons entry: added the missing inline citation to cash.ch on the closing fraud-vector paragraph.
F9
surface-contradiction
ServiceNow entry: added a sourcing_note and a run-record Contradiction line naming the ServiceNow-vs-The-Hacker-News disagreement on CVE-2026-18886's class/prod
F11
editorial-advisory
Run-record notes reworded to remove workflow-internal shorthand ('Phase 0', S1/S2/S4 domain labels, 'tasking').
F15
?
Added mutual disambiguation between tool:redc2's 'Red Agent' component and tool:wiz-red-agent ('Wiz Red Agent') in both registry summaries and the RedC2 entry b
F16
?
Declined (low-confidence advisory, not a truth defect): priority: high retained on the German IMEI entry given Germany's BfV explicitly classifying the finding

Iteration #2 NEEDS_FIXES · 7 findings (truth=4, editorial=2, advisory=0) · Claude Sonnet 5 · 7m 50s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
ServiceNow: the CVE-2026-6876 sentence (CVE-2026-6875/Searchlight Cyber link, the 8.7 score, the PR:L-vs-'unauthenticated' inconsistency) re-cited from ServiceN
F3
claim-not-supported
ServiceNow: the numeric 'CVSS4.0 10.0' score for the three maximum-severity flaws re-cited from ServiceNow to The Hacker News — ServiceNow's own advisory gives
F3
claim-not-supported
Exchange: removed the uncited 'Trend Micro's' qualifier before Zero Day Initiative — Franky's Web names only the Zero Day Initiative, not its corporate parent.
F3
claim-not-supported
Citation-date drift corrected across three entries: RedC2 (every citation moved from 2026-08-29 to the article's own 2026-08-20 dateline, resolving a self-contr
F5
missing-citation
German-carriers entry: added the missing inline citation to heise on the RFC 7254/7255 sentence.
F17
?
Swiss-cantons entry: credibility lowered from 1 to 2 and a sourcing_note added, reflecting that three of four cited outlets trace to the same Keystone-ATS wire
F9
surface-contradiction
Run-record Contradiction line corrected: removed the overstated 'in a Now Platform' qualifier not actually stated by The Hacker News's CVE-2026-18886 bullet; ad

Iteration #3 NEEDS_FIXES · 7 findings (truth=6, editorial=1, advisory=0) · Claude Sonnet 5 · 11m 53s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
ServiceNow entry: the CVE-2026-6875 date was corrected from a spliced 'disclosed in July 2026' framing to the accurate two dates — reported to ServiceNow 1 Apri
F3
claim-not-supported
ServiceNow entry: CVE-2026-18886's own description no longer says 'execute arbitrary code' (only 18885/74820 do per ServiceNow's own text); it now reads 'create
F3
claim-not-supported
Exchange entry: MSRC citation date corrected from the processing date to the advisory's own initial-publication date, 2026-08-11 (its revision history carries n
F3
claim-not-supported
Exchange entry: NCSC-NL citation date corrected from 2026-08-29 to the advisory's own revision date, 2026-08-28.
F3
claim-not-supported
Swiss-cantons entry: the 'which they did not act on' extortion clause re-cited from cash.ch (which never states it) to Blick, the source that actually states it
F3
claim-not-supported
ENDLESSDOORS update: 'sold to Western consumers' corrected to VulnCheck's own wording, 'sold to Americans through Amazon'; added an explicit hedge that VulnChec
F11
editorial-advisory
Run-record notes reworded to remove residual workflow-internal jargon: 'gate FAIL' and 'PD-1 violation' replaced with plain-language explanation; the literal fi

Iteration #4 NEEDS_FIXES · 5 findings (truth=4, editorial=1, advisory=0) · Claude Sonnet 5 · 10m 30s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
ServiceNow entry: the hosted/self-hosted/partner-hosted affected-population sentence re-cited from ServiceNow to The Hacker News, the source that actually uses
F3
claim-not-supported
Exchange entry: the 'no Emergency Mitigation workaround, ESU-gated' sentence re-cited from MSRC to Franky's Web, the source that actually states both facts; MSR
F3
claim-not-supported
Swiss-cantons entry: split the cantons-filed/Valais-hardened sentence — the five-canton complaint-filing and Viacar access-restriction facts stay cited to cash.
F4
hallucinated-fact
ENDLESSDOORS update: removed 'MOFI Networks MOFI4500-4GXeLTE' from affected_products entirely — VulnCheck's own text states the MOFI firmware it examined contai
F17
?
ServiceNow entry: classification reliability lowered from A to B and sourcing_note extended — the entry's most load-bearing technical content (CVSS vectors/scor

Iteration #5 NEEDS_FIXES · 7 findings (truth=3, editorial=3, advisory=1) · Claude Sonnet 5 · 13m 31s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
German IMEI entry: split the soldier/Lithuania scenario away from the BfV's own 'near-certain' statement — BR24 sources that scenario to the Bundeswehr's own ma
F4
hallucinated-fact
German IMEI entry: the first evidence[] quote field translated to English ('In the networks of Telekom and Telefonica (O2), IMEI numbers reached the caller in s
F4
hallucinated-fact
ServiceNow entry: CVE-2026-18886 cves[].type corrected from rce to priv-esc, matching both ServiceNow's own KB text and The Hacker News, neither of which descri
F8
needs-more-research
ServiceNow entry: CVE-2026-18886's affected field extended to note Australia Patch 5's status is recorded as unknown rather than affected, per The Hacker News's
F10
missed-angle
ServiceNow entry: added references: [2026-07-13/servicenow-ai-platform-sandbox-escape-cve-2026-6875], the store's existing entry for the sibling flaw (CVE-2026-
F11
editorial-advisory
Swiss-cantons entry: techniques corrected from T1213 (Data from Information Repositories) to T1119 (Automated Collection), the better fit for automated rate-lim
F17
?
PaperCut entry: classification reliability lowered from A to B and a sourcing_note added — PaperCut's own bulletin confirms the vulnerability and active exploit

Iteration #6 NEEDS_FIXES · 6 findings (truth=3, editorial=0, advisory=3) · Claude Sonnet 5 · 11m 52s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F14
?
Exchange entry: title/headline corrected from 'three weeks after the patch' to 'sixteen days after the patch', matching the body's own, correct computation (MSR
F3
claim-not-supported
EU-CRA entry: sourcing_note corrected — ENISA's SRP page confirms only the 2026-09-11 go-live date, not the 24h/72h/14-day/1-month notification clock, which is
F4
hallucinated-fact
ENDLESSDOORS update: added an explicit 'rebrand lineage match — implant presence unconfirmed' qualifier directly in affected_products[] for Digineo, ALLNET and
F11
editorial-advisory
RedC2 entry: added T1090.001 (Internal Proxy) — SOCKS5 proxying and TCP port forwarding is explicitly described in the body but had no Proxy-class ATT&CK id map
F11
editorial-advisory
ServiceNow entry: summary's 'No exploitation or public proof-of-concept is reported' corrected to scope the PoC clause to the three maximum-severity flaws only,
F11
editorial-advisory
Declined (low confidence, no confirmed defect): the run record's model: field phrase 'the main agent' was traced through site/build.py's render paths; every pat

Iteration #7 NEEDS_FIXES · 5 findings (truth=1, editorial=1, advisory=3) · Claude Sonnet 5 · 13m 44s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
ENDLESSDOORS update: the closing sentence and matching updates[].summary clause claiming 'no CVE assigned' and 'did not notify Zbtlink' as if stated by the 2026
F5
missing-citation
Swiss-cantons entry: added the missing inline citation (cash.ch + Blick) to the closing sentence on unknown actor identity/count and no core-system exploitation
F11
editorial-advisory
Declined (low confidence, judgment call): Swiss-cantons T1119 vs a possible T1596 (Search Open Websites/Domains) mapping — neither is a clean fit for unauthenti
F11
editorial-advisory
Declined (low confidence, judgment call): ServiceNow entry — an additional T1068 (Exploitation for Privilege Escalation) mapping for CVE-2026-18886 was consider
F17
?
Declined (low confidence, judgment call): German-carriers entry — credibility 2 vs a possible upgrade to 1 given BR24/heise/GSMA/BfV's on-record multi-party con

Iteration #8 NEEDS_FIXES cap-breach · 2 findings (truth=1, editorial=0, advisory=3) · Claude Sonnet 5 · 9m 27s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
Swiss-cantons entry: removed the unsupported 'built on standard software from' claim about eAutoIndex — cash.ch (and every other fetched source) states only tha
F11
editorial-advisory
Declined (low confidence, residual — iteration cap reached): an ambiguous ENISA citation date, an unverifiable BSI CERT-Bund corroborating-source SPA shell not

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-29T0409Z-intel · Sonnet 5 — session-configured value (no harness self-ID line or env var available to the main agent this run; see notes) · window 24 h · 7 entries published

Verification & coverage notes

Coverage window: standard (13.16 hours since the previous run, 2026-08-28T1500Z-audit; that record's own publish outcome is still recorded as pending on main, with its own explanatory note that it was an operator-interactive session with no automated publish step — not an operational failure, so no action taken here beyond noting it).

Published this run (7 new, 1 update, 1 deep dive, 1 critical):

  • 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce (critical, deep dive) — PaperCut NG/MF pre-auth RCE chain, actively exploited before a patch existed.
  • 2026-08-29/servicenow-ai-platform-four-unauth-cvss10-flaws (high) — three unauthenticated CVSS4.0 10.0 flaws plus a related sandbox escape.
  • 2026-08-29/exchange-mrsproxy-auth-bypass-cve-2026-62911-poc (high) — public exploit code for an Exchange MRSProxy relay flaw, MSRC rating unrevised.
  • 2026-08-29/swiss-cantons-eautoindex-vehicle-registry-data-harvesting (high) — six Swiss cantons, rate-limit bypass on public vehicle-registry lookups, extortion attempts.
  • 2026-08-29/eu-cra-reporting-obligation-ncsc-fi-checklist (notable) — NCSC-FI's operational CRA reporting-clock checklist ahead of the 11 September go-live.
  • 2026-08-29/redc2-npm-supply-chain-redshell-linux-implant (notable) — closes a coverage-backlog item open since 2026-08-22; TrendAI's vendor primary replaces the aggregator-only sourcing that blocked it.
  • 2026-08-29/german-carriers-imei-leak-call-setup-signaling (high) — BR/heise investigation, GSMA-confirmed device-fingerprinting leak in call setup.
  • Update on 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor — two new pre-installed implants (DARKLANTERN, SPEAKINGSTONE), a domestic-China surveillance-deployment finding via sinkhole, and a German OEM-rebrand extension.

Borderline drops:

  • borderline-drop: Minea (Swiss ad-intelligence platform) 533K-profile breach claim — single Admiralty-C source (cyberattaque.org) reporting an unverified hacker claim; the outlet's own reporting doubts the data's currency (records stop in August 2024 despite a claimed August 2026 compromise), no victim confirmation, and the affected business (ad-intelligence/dropshipping SaaS) has no nexus to the profiled constituency's sectors. Dropped for insufficient verification, not held at low priority.
  • borderline-drop: Qare (French telemedicine) hacker disclosure claiming exposed patient photographs including children — single Admiralty-C source, no victim statement, no independent corroboration despite a search attempt. Sensitive subject matter argues for more caution, not less, absent a second source.
  • borderline-drop: Boston Scientific cybersecurity incident (global medtech manufacturer, three Irish/EU plants idled) — genuinely clears the relevance bar on EU/healthcare nexus alone, but no source (including a named commentator quoted by Industrial Cyber) states any attacker behaviour, access vector, or mechanism; an incident entry needs a genuine, evidence-supported ATT&CK mapping, and none exists yet to compose one honestly. Logged in the coverage backlog for publication the moment a vector is disclosed — the same disposition already applied to the Berlin Landesnetz compromise.

Contradiction: 2026-08-29/servicenow-ai-platform-four-unauth-cvss10-flaws — ServiceNow's own advisory classifies CVE-2026-18886 as a code-injection flaw in its AI Platform; The Hacker News, reporting on the same advisory, classifies it as an improper-access-control flaw in a system-configuration image-upload processor. A second, related disagreement on the same entry: ServiceNow's own prose describes CVE-2026-6876 as reachable by an "unauthenticated user," while the CVSS4.0 vector ServiceNow itself assigned to that CVE (per The Hacker News's reporting) specifies PR:L — low privileges required. The entry carries all of these readings, attributed to their respective source, with the vendor's own classification treated as authoritative for the frontmatter cves[] records.

Single-source items: 2026-08-29/redc2-npm-supply-chain-redshell-linux-implant — TrendAI Research is the sole discloser; no independent lab has corroborated it. Update on 2026-08-06/endlessdoors-... — VulnCheck remains the sole discloser for both the original ENDLESSDOORS finding and this run's DARKLANTERN/SPEAKINGSTONE follow-up; heise's coverage is journalism relaying VulnCheck's research, not independent technical corroboration.

Verification loop: 8 iterations, every one independently spawned and cold-reading fresh from disk. Iterations 1-8 all returned NEEDS_FIXES; every truth- and editorial-class finding across all eight was remediated (a running per-fact citation-attribution defect was the dominant pattern, plus one classification recalibration each on the ServiceNow and PaperCut entries, three technique-mapping corrections, and one hallucinated-fact removal each on the ENDLESSDOORS update, the ServiceNow entry, and the Swiss-cantons entry). The loop reached its 8-iteration cap without a confirmed CLEAN; publishing anyway is the documented fail-open (never a blocking condition). Three low-confidence advisory items from iteration 8 remain as residuals, none rising to a confirmed defect: an ambiguous ENISA citation date on the EU-CRA entry, an unverifiable BSI CERT-Bund corroborating-source page on the ServiceNow entry not tied to any specific claim, and a stretch-case missing ATT&CK mapping for SPEAKINGSTONE's PPPoE-credential exfiltration on the ENDLESSDOORS update. verification_residual_count: 1 reflects iteration 8's final truth+editorial count (1+0).

Coverage-backlog re-check: all five previously-open rows re-gated on today's facts. Struck: the RedC2 npm row (published). Stayed open, untouched or lightly re-checked at low cost: Zurich District Court verdict (not due until 2026-09-10), Berlin Landesnetz (re-confirmed no vector named by any authority, seventh consecutive fire blocked on the same ground), Siemens S7 joint-advisory re-read (low priority, not re-probed), CVE-2026-16242 OpenShift/HyperShift (still out of window), the Keycloak Red Hat product-state correction (low priority, meta-fact only). One row added: Boston Scientific (see borderline-drops above).

Watchlist: no product or supplier watchlist configured for this deployment (config/org-profile.yaml); the product and supplier sweeps were no-ops as a result; the sector/region lens was applied in their place.

Coverage gaps: searchlight-cyber (Cookiebot consent wall defeats every transport); team-cymru, sans-ics (both resolve through an ad-tracking redirect returning only a 1×1 pixel); paradigm-shift-research (client-side SPA stub, no server-rendered content); inside-it.ch's "Insel Gruppe verschiebt Wechsel zu ServiceNow" article (403 on every transport — flagged as a lead, not corroborated, plausibly but not confirmably related to the ServiceNow CVEs published the same day); cisa-advisories, cisa-directives (reachable, but no in-window item on either listing); cert-pl (newest item just outside the 24h window).

Essential-coverage: no misses — all essential-tier sources were attempted and returned content (even where that content held no in-window item).

← Operations dashboard · run-record contract: docs/pipeline.md