2026-08-29T0409Z-intel
One pipeline fire, in full · intel run of 2026-08-29 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-29/2026-08-29T0409Z-intel.md.
Run telemetry
- Items returned
- 3
- Duration
- 8m 58s
- Tool calls
- 0 WebFetch6 WebSearch30 bridge
- Cited sources
- 4 of 11 in slice
- Items returned
- 2
- Duration
- 12m 21s
- Tool calls
- 1 WebFetch19 WebSearch37 bridge
- Cited sources
- 1 of 15 in slice
- Items returned
- 3
- Duration
- 10m 56s
- Tool calls
- 0 WebFetch2 WebSearch24 bridge
- Cited sources
- 1 of 11 in slice
- Items returned
- 3
- Duration
- 10m 10s
- Tool calls
- 1 WebFetch18 WebSearch22 bridge
- Cited sources
- 2 of 6 in slice
Verification
Deep dive
2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce
Entries this run published (7) and updated (1)
- ENDLESSDOORS (CVE-2026-66747) — twenty Zbtlink router models ship from the factory with an unauthenticated root-command backdoor, and the discloser's remedy is replacement vulnerability notable update
- Finland's NCSC-FI publishes an operational manufacturer checklist for the EU Cyber Resilience Act's 24h/72h/14-day/1-month reporting clock, two weeks before the 11 September 2026 go-live policy notable
- CVE-2026-62911 — Microsoft Exchange Server MRSProxy: a missing channel-binding check lets a relayed Negotiate authentication take over every mailbox, public exploit code now live sixteen days after the patch vulnerability high
- German mobile carriers leaked callees' IMEI, device model and OS version to callers during call setup — GSMA confirmed the flaw and warned its 1,000+ member operators worldwide research high
- CVE-2026-82078 / CVE-2026-81578 — PaperCut NG/MF: an Apache Tapestry request-routing confusion chains an unauthenticated config rewrite to arbitrary code execution, exploited before a patch existed vulnerability critical
- Fourteen trojanized npm packages drop RedC2 4.0's RedShell Linux implant from a module-load-time loader that needs no install hook, defeating --ignore-scripts entirely threat notable
- CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876 — ServiceNow AI Platform: three unauthenticated CVSS 10.0 flaws plus a related Now Platform sandbox escape vulnerability high
- Six Swiss cantons disclose bulk-harvesting of vehicle-owner data after an unknown actor bypassed per-person rate limits on public lookup portals, with extortion attempts against the platform operator and canton Vaud incident high
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
1 status.
| Source | Change | From → To | Reason |
|---|---|---|---|
| hunt-io | status | candidate → active | 3 contributing runs — promotion_due bar met per state-summary digest (sources.promotion_due) |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| searchlight-cyber | https://slcyber.io/research-center/ | webfetch → jina → bridge-extract | None consent-wall Cookiebot consent overlay returned instead of article listing on webfetch, jina, and bridge extract | none |
| team-cymru | https://www.team-cymru.com/blog | webfetch → jina | 200 ad-redirect Resolves through match.adsrvr.org ad-tracking redirect; only a 1x1 tracking pixel returned via direct fetch and jina | none |
| paradigm-shift-research | https://ps.tc/ | bridge | None spa-stub Client-side SPA returns only a meta-refresh redirect stub via the bridge's raw fetch; no server-rendered content or feed | none |
| sans-ics | https://www.sans.org/blog/?focus-area=industrial-control-systems-ics | webfetch → jina | 200 ad-redirect Resolves through the same ad-tracking redirect as team-cymru; only a 1x1 tracking pixel returned via jina | none |
| inside-it-ch | https://www.inside-it.ch/insel-gruppe-verschiebt-wechsel-zu-servicenow | rss → webfetch → extract → bridge:url → jina | 403 http-403 Article 'Insel Gruppe verschiebt Wechsel zu ServiceNow' (citing 'einen Sicherheitsvorfall') 403'd on direct fetch, trafilatura extraction, jina fallback, and th | none |
Bridge invocations (this run)
5 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- cisa page / feed ×1
- cisa page ×1
- ncsc-csh recent 20 ×1
- bacs.admin.ch aktuelle-vorfaelle ×1
- jina (JS-rendered Framer site) ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 13 findings (truth=10, editorial=2, advisory=2) · Claude Sonnet 5 · 10m 43s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F2 generic-url | — | Exchange entry's NCSC-NL source corrected from the RSS feed listing to the specific advisory NCSC-2026-0289 (fetched via the bridge's ncsc-nl csaf recipe); body | ||
| F3 claim-not-supported | — | PaperCut: Home-page-bypass claim re-cited from PaperCut Software to Rapid7, the source that actually states it. | ||
| F3 claim-not-supported | — | ServiceNow: GraphQL/image-upload/ORDER BY mechanism specifics and the CVSS vector string re-cited from ServiceNow to The Hacker News, the source that actually s | ||
| F3 claim-not-supported | — | German IMEI entry: Wireshark-capture detail and the Karsten Nohl/SRLabs quote re-cited from BR24 to heise, the source that actually states them (re-fetched heis | ||
| F4 hallucinated-fact | — | ServiceNow CVE-2026-18886 affected/product field corrected from 'Now Platform' to 'AI Platform', matching ServiceNow's own advisory text; title/summary/body rew | ||
| F4 hallucinated-fact | — | ENDLESSDOORS update: removed unsupported T1090 (Proxy) technique — grepped both VulnCheck posts and heise's article for proxy/pivot/socks with zero matches. | ||
| F4 hallucinated-fact | — | ENDLESSDOORS update: corrected the WiFlyer rebrand pairing from WE826-T2 (only Deep Orange is demonstrated on that platform) to WG3526, per VulnCheck's own text | ||
| F4 hallucinated-fact | — | Swiss-cantons evidence[] quote de-ellipsised into one contiguous, verbatim substring of the cash.ch article (previously spliced two non-adjacent sentences). | ||
| F5 missing-citation | — | Swiss-cantons entry: added the missing inline citation to cash.ch on the closing fraud-vector paragraph. | ||
| F9 surface-contradiction | — | ServiceNow entry: added a sourcing_note and a run-record Contradiction line naming the ServiceNow-vs-The-Hacker-News disagreement on CVE-2026-18886's class/prod | ||
| F11 editorial-advisory | — | Run-record notes reworded to remove workflow-internal shorthand ('Phase 0', S1/S2/S4 domain labels, 'tasking'). | ||
| F15 ? | — | Added mutual disambiguation between tool:redc2's 'Red Agent' component and tool:wiz-red-agent ('Wiz Red Agent') in both registry summaries and the RedC2 entry b | ||
| F16 ? | — | Declined (low-confidence advisory, not a truth defect): priority: high retained on the German IMEI entry given Germany's BfV explicitly classifying the finding |
Iteration #2 NEEDS_FIXES · 7 findings (truth=4, editorial=2, advisory=0) · Claude Sonnet 5 · 7m 50s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | ServiceNow: the CVE-2026-6876 sentence (CVE-2026-6875/Searchlight Cyber link, the 8.7 score, the PR:L-vs-'unauthenticated' inconsistency) re-cited from ServiceN | ||
| F3 claim-not-supported | — | ServiceNow: the numeric 'CVSS4.0 10.0' score for the three maximum-severity flaws re-cited from ServiceNow to The Hacker News — ServiceNow's own advisory gives | ||
| F3 claim-not-supported | — | Exchange: removed the uncited 'Trend Micro's' qualifier before Zero Day Initiative — Franky's Web names only the Zero Day Initiative, not its corporate parent. | ||
| F3 claim-not-supported | — | Citation-date drift corrected across three entries: RedC2 (every citation moved from 2026-08-29 to the article's own 2026-08-20 dateline, resolving a self-contr | ||
| F5 missing-citation | — | German-carriers entry: added the missing inline citation to heise on the RFC 7254/7255 sentence. | ||
| F17 ? | — | Swiss-cantons entry: credibility lowered from 1 to 2 and a sourcing_note added, reflecting that three of four cited outlets trace to the same Keystone-ATS wire | ||
| F9 surface-contradiction | — | Run-record Contradiction line corrected: removed the overstated 'in a Now Platform' qualifier not actually stated by The Hacker News's CVE-2026-18886 bullet; ad |
Iteration #3 NEEDS_FIXES · 7 findings (truth=6, editorial=1, advisory=0) · Claude Sonnet 5 · 11m 53s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | ServiceNow entry: the CVE-2026-6875 date was corrected from a spliced 'disclosed in July 2026' framing to the accurate two dates — reported to ServiceNow 1 Apri | ||
| F3 claim-not-supported | — | ServiceNow entry: CVE-2026-18886's own description no longer says 'execute arbitrary code' (only 18885/74820 do per ServiceNow's own text); it now reads 'create | ||
| F3 claim-not-supported | — | Exchange entry: MSRC citation date corrected from the processing date to the advisory's own initial-publication date, 2026-08-11 (its revision history carries n | ||
| F3 claim-not-supported | — | Exchange entry: NCSC-NL citation date corrected from 2026-08-29 to the advisory's own revision date, 2026-08-28. | ||
| F3 claim-not-supported | — | Swiss-cantons entry: the 'which they did not act on' extortion clause re-cited from cash.ch (which never states it) to Blick, the source that actually states it | ||
| F3 claim-not-supported | — | ENDLESSDOORS update: 'sold to Western consumers' corrected to VulnCheck's own wording, 'sold to Americans through Amazon'; added an explicit hedge that VulnChec | ||
| F11 editorial-advisory | — | Run-record notes reworded to remove residual workflow-internal jargon: 'gate FAIL' and 'PD-1 violation' replaced with plain-language explanation; the literal fi |
Iteration #4 NEEDS_FIXES · 5 findings (truth=4, editorial=1, advisory=0) · Claude Sonnet 5 · 10m 30s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | ServiceNow entry: the hosted/self-hosted/partner-hosted affected-population sentence re-cited from ServiceNow to The Hacker News, the source that actually uses | ||
| F3 claim-not-supported | — | Exchange entry: the 'no Emergency Mitigation workaround, ESU-gated' sentence re-cited from MSRC to Franky's Web, the source that actually states both facts; MSR | ||
| F3 claim-not-supported | — | Swiss-cantons entry: split the cantons-filed/Valais-hardened sentence — the five-canton complaint-filing and Viacar access-restriction facts stay cited to cash. | ||
| F4 hallucinated-fact | — | ENDLESSDOORS update: removed 'MOFI Networks MOFI4500-4GXeLTE' from affected_products entirely — VulnCheck's own text states the MOFI firmware it examined contai | ||
| F17 ? | — | ServiceNow entry: classification reliability lowered from A to B and sourcing_note extended — the entry's most load-bearing technical content (CVSS vectors/scor |
Iteration #5 NEEDS_FIXES · 7 findings (truth=3, editorial=3, advisory=1) · Claude Sonnet 5 · 13m 31s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | German IMEI entry: split the soldier/Lithuania scenario away from the BfV's own 'near-certain' statement — BR24 sources that scenario to the Bundeswehr's own ma | ||
| F4 hallucinated-fact | — | German IMEI entry: the first evidence[] quote field translated to English ('In the networks of Telekom and Telefonica (O2), IMEI numbers reached the caller in s | ||
| F4 hallucinated-fact | — | ServiceNow entry: CVE-2026-18886 cves[].type corrected from rce to priv-esc, matching both ServiceNow's own KB text and The Hacker News, neither of which descri | ||
| F8 needs-more-research | — | ServiceNow entry: CVE-2026-18886's affected field extended to note Australia Patch 5's status is recorded as unknown rather than affected, per The Hacker News's | ||
| F10 missed-angle | — | ServiceNow entry: added references: [2026-07-13/servicenow-ai-platform-sandbox-escape-cve-2026-6875], the store's existing entry for the sibling flaw (CVE-2026- | ||
| F11 editorial-advisory | — | Swiss-cantons entry: techniques corrected from T1213 (Data from Information Repositories) to T1119 (Automated Collection), the better fit for automated rate-lim | ||
| F17 ? | — | PaperCut entry: classification reliability lowered from A to B and a sourcing_note added — PaperCut's own bulletin confirms the vulnerability and active exploit |
Iteration #6 NEEDS_FIXES · 6 findings (truth=3, editorial=0, advisory=3) · Claude Sonnet 5 · 11m 52s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F14 ? | — | Exchange entry: title/headline corrected from 'three weeks after the patch' to 'sixteen days after the patch', matching the body's own, correct computation (MSR | ||
| F3 claim-not-supported | — | EU-CRA entry: sourcing_note corrected — ENISA's SRP page confirms only the 2026-09-11 go-live date, not the 24h/72h/14-day/1-month notification clock, which is | ||
| F4 hallucinated-fact | — | ENDLESSDOORS update: added an explicit 'rebrand lineage match — implant presence unconfirmed' qualifier directly in affected_products[] for Digineo, ALLNET and | ||
| F11 editorial-advisory | — | RedC2 entry: added T1090.001 (Internal Proxy) — SOCKS5 proxying and TCP port forwarding is explicitly described in the body but had no Proxy-class ATT&CK id map | ||
| F11 editorial-advisory | — | ServiceNow entry: summary's 'No exploitation or public proof-of-concept is reported' corrected to scope the PoC clause to the three maximum-severity flaws only, | ||
| F11 editorial-advisory | — | Declined (low confidence, no confirmed defect): the run record's model: field phrase 'the main agent' was traced through site/build.py's render paths; every pat |
Iteration #7 NEEDS_FIXES · 5 findings (truth=1, editorial=1, advisory=3) · Claude Sonnet 5 · 13m 44s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | — | ENDLESSDOORS update: the closing sentence and matching updates[].summary clause claiming 'no CVE assigned' and 'did not notify Zbtlink' as if stated by the 2026 | ||
| F5 missing-citation | — | Swiss-cantons entry: added the missing inline citation (cash.ch + Blick) to the closing sentence on unknown actor identity/count and no core-system exploitation | ||
| F11 editorial-advisory | — | Declined (low confidence, judgment call): Swiss-cantons T1119 vs a possible T1596 (Search Open Websites/Domains) mapping — neither is a clean fit for unauthenti | ||
| F11 editorial-advisory | — | Declined (low confidence, judgment call): ServiceNow entry — an additional T1068 (Exploitation for Privilege Escalation) mapping for CVE-2026-18886 was consider | ||
| F17 ? | — | Declined (low confidence, judgment call): German-carriers entry — credibility 2 vs a possible upgrade to 1 given BR24/heise/GSMA/BfV's on-record multi-party con |
Iteration #8 NEEDS_FIXES cap-breach · 2 findings (truth=1, editorial=0, advisory=3) · Claude Sonnet 5 · 9m 27s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | — | Swiss-cantons entry: removed the unsupported 'built on standard software from' claim about eAutoIndex — cash.ch (and every other fetched source) states only tha | ||
| F11 editorial-advisory | — | Declined (low confidence, residual — iteration cap reached): an ambiguous ENISA citation date, an unverifiable BSI CERT-Bund corroborating-source SPA shell not |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-08-29T0409Z-intel · Sonnet 5 — session-configured value (no harness self-ID line or env var available to the main agent this run; see notes) · window 24 h · 7 entries published
Verification & coverage notes
Coverage window: standard (13.16 hours since the previous run, 2026-08-28T1500Z-audit; that record's own publish outcome is still recorded as pending on main, with its own explanatory note that it was an operator-interactive session with no automated publish step — not an operational failure, so no action taken here beyond noting it).
Published this run (7 new, 1 update, 1 deep dive, 1 critical):
2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce(critical, deep dive) — PaperCut NG/MF pre-auth RCE chain, actively exploited before a patch existed.2026-08-29/servicenow-ai-platform-four-unauth-cvss10-flaws(high) — three unauthenticated CVSS4.0 10.0 flaws plus a related sandbox escape.2026-08-29/exchange-mrsproxy-auth-bypass-cve-2026-62911-poc(high) — public exploit code for an Exchange MRSProxy relay flaw, MSRC rating unrevised.2026-08-29/swiss-cantons-eautoindex-vehicle-registry-data-harvesting(high) — six Swiss cantons, rate-limit bypass on public vehicle-registry lookups, extortion attempts.2026-08-29/eu-cra-reporting-obligation-ncsc-fi-checklist(notable) — NCSC-FI's operational CRA reporting-clock checklist ahead of the 11 September go-live.2026-08-29/redc2-npm-supply-chain-redshell-linux-implant(notable) — closes a coverage-backlog item open since 2026-08-22; TrendAI's vendor primary replaces the aggregator-only sourcing that blocked it.2026-08-29/german-carriers-imei-leak-call-setup-signaling(high) — BR/heise investigation, GSMA-confirmed device-fingerprinting leak in call setup.- Update on
2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor— two new pre-installed implants (DARKLANTERN, SPEAKINGSTONE), a domestic-China surveillance-deployment finding via sinkhole, and a German OEM-rebrand extension.
Borderline drops:
- borderline-drop: Minea (Swiss ad-intelligence platform) 533K-profile breach claim — single Admiralty-C source (cyberattaque.org) reporting an unverified hacker claim; the outlet's own reporting doubts the data's currency (records stop in August 2024 despite a claimed August 2026 compromise), no victim confirmation, and the affected business (ad-intelligence/dropshipping SaaS) has no nexus to the profiled constituency's sectors. Dropped for insufficient verification, not held at low priority.
- borderline-drop: Qare (French telemedicine) hacker disclosure claiming exposed patient photographs including children — single Admiralty-C source, no victim statement, no independent corroboration despite a search attempt. Sensitive subject matter argues for more caution, not less, absent a second source.
- borderline-drop: Boston Scientific cybersecurity incident (global medtech manufacturer, three Irish/EU plants idled) — genuinely clears the relevance bar on EU/healthcare nexus alone, but no source (including a named commentator quoted by Industrial Cyber) states any attacker behaviour, access vector, or mechanism; an incident entry needs a genuine, evidence-supported ATT&CK mapping, and none exists yet to compose one honestly. Logged in the coverage backlog for publication the moment a vector is disclosed — the same disposition already applied to the Berlin Landesnetz compromise.
Contradiction: 2026-08-29/servicenow-ai-platform-four-unauth-cvss10-flaws — ServiceNow's own advisory classifies CVE-2026-18886 as a code-injection flaw in its AI Platform; The Hacker News, reporting on the same advisory, classifies it as an improper-access-control flaw in a system-configuration image-upload processor. A second, related disagreement on the same entry: ServiceNow's own prose describes CVE-2026-6876 as reachable by an "unauthenticated user," while the CVSS4.0 vector ServiceNow itself assigned to that CVE (per The Hacker News's reporting) specifies PR:L — low privileges required. The entry carries all of these readings, attributed to their respective source, with the vendor's own classification treated as authoritative for the frontmatter cves[] records.
Single-source items: 2026-08-29/redc2-npm-supply-chain-redshell-linux-implant — TrendAI Research is the sole discloser; no independent lab has corroborated it. Update on 2026-08-06/endlessdoors-... — VulnCheck remains the sole discloser for both the original ENDLESSDOORS finding and this run's DARKLANTERN/SPEAKINGSTONE follow-up; heise's coverage is journalism relaying VulnCheck's research, not independent technical corroboration.
Verification loop: 8 iterations, every one independently spawned and cold-reading fresh from disk. Iterations 1-8 all returned NEEDS_FIXES; every truth- and editorial-class finding across all eight was remediated (a running per-fact citation-attribution defect was the dominant pattern, plus one classification recalibration each on the ServiceNow and PaperCut entries, three technique-mapping corrections, and one hallucinated-fact removal each on the ENDLESSDOORS update, the ServiceNow entry, and the Swiss-cantons entry). The loop reached its 8-iteration cap without a confirmed CLEAN; publishing anyway is the documented fail-open (never a blocking condition). Three low-confidence advisory items from iteration 8 remain as residuals, none rising to a confirmed defect: an ambiguous ENISA citation date on the EU-CRA entry, an unverifiable BSI CERT-Bund corroborating-source page on the ServiceNow entry not tied to any specific claim, and a stretch-case missing ATT&CK mapping for SPEAKINGSTONE's PPPoE-credential exfiltration on the ENDLESSDOORS update. verification_residual_count: 1 reflects iteration 8's final truth+editorial count (1+0).
Coverage-backlog re-check: all five previously-open rows re-gated on today's facts. Struck: the RedC2 npm row (published). Stayed open, untouched or lightly re-checked at low cost: Zurich District Court verdict (not due until 2026-09-10), Berlin Landesnetz (re-confirmed no vector named by any authority, seventh consecutive fire blocked on the same ground), Siemens S7 joint-advisory re-read (low priority, not re-probed), CVE-2026-16242 OpenShift/HyperShift (still out of window), the Keycloak Red Hat product-state correction (low priority, meta-fact only). One row added: Boston Scientific (see borderline-drops above).
Watchlist: no product or supplier watchlist configured for this deployment (config/org-profile.yaml); the product and supplier sweeps were no-ops as a result; the sector/region lens was applied in their place.
Coverage gaps: searchlight-cyber (Cookiebot consent wall defeats every transport); team-cymru, sans-ics (both resolve through an ad-tracking redirect returning only a 1×1 pixel); paradigm-shift-research (client-side SPA stub, no server-rendered content); inside-it.ch's "Insel Gruppe verschiebt Wechsel zu ServiceNow" article (403 on every transport — flagged as a lead, not corroborated, plausibly but not confirmably related to the ServiceNow CVEs published the same day); cisa-advisories, cisa-directives (reachable, but no in-window item on either listing); cert-pl (newest item just outside the 24h window).
Essential-coverage: no misses — all essential-tier sources were attempted and returned content (even where that content held no in-window item).
← Operations dashboard · run-record contract: docs/pipeline.md