CTIPilot

2026-08-30T1312Z-audit

One pipeline fire, in full · audit run of 2026-08-30 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-30/2026-08-30T1312Z-audit.md.

Run telemetry

2026-08-30T1312Z-audit audit prompt v4.8 publish ok
2h 49m duration 2 published 13 updates
Claude Opus 5 (claude-opus-5) main agent
B1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
15
Duration
9m 38s
Tool calls
not reported
Cited sources
none
B2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
15
Duration
12m 02s
Tool calls
not reported
Cited sources
none
B3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
14
Duration
14m 22s
Tool calls
not reported
Cited sources
none
G1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
7m 50s
Tool calls
3 WebFetch6 WebSearch22 bridge
Cited sources
none
G2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
11m 39s
Tool calls
9 WebFetch20 WebSearch24 bridge
Cited sources
none
G3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
8m 47s
Tool calls
12 WebSearch35 bridge
Cited sources
none

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=2 #2 NEEDS_FIXES · Sonnet 5 · t=5 e=2 a=11 #3 NEEDS_FIXES · Sonnet 5 · t=4 e=1 a=2 #4 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=1 #5 NEEDS_FIXES · Sonnet 5 · t=3 e=0 a=1 #6 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=1 #7 CLEAN · Sonnet 5 · t=0 e=0 a=2 #8 NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=0

Deep dive

·

Entries this run published (2) and updated (13)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 added as candidate (this run's one candidate slot) with the working recipe `extract https://www.security.com/threat-intelligence`, confirmed by G3, discharges recommendation 5 of the 2026-08-24 audit.

SourceChangeFrom → ToReason
symantec-security-comadded as candidate (this run's one candidate slot) with the working recipe `extract https://www.security.com/threat-intelligence`, confirmed by G3, discharges recommendation 5 of the 2026-08-24 audit· → ·

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
ssd-disclosure
covered via alternate · should NOT be in this list
https://ssd-disclosure.com/bridge:extractbridge:urlbridge:jinawebfetch200 anti-bot-challengeverified the entry's technical claims against the two secondaries that quote and link the primary (Dark Reading, Infosecurity Magazine) instead
inside-it-chhttps://www.inside-it.ch/bridge:extractbridge:urlbridge:jinawebfetch403 http-403logged the blocked Insel Gruppe lead as an open coverage-backlog row with its blocking condition; no corroborating publisher found

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 4 findings (truth=2, editorial=0, advisory=2) · Claude Sonnet 5 · 15m 27s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
Verdict counts: the report and this record said 19 clean / 11 factual-error / 14 imprecision in some places and 20/10/14 in others, because the Kaltura entry is
F4
hallucinated-fact
·
The Linux-kernel KEV entry's correction record declared fields [cves] while the diff also appended its Correction section; corrected to [cves, body], matching t
F11
editorial-advisory
·
Two rendered changelog summaries carried pipeline-internal text: the Copeland record said the CVE binding was 'this pipeline's own inference' (rewritten as 'an
F11
editorial-advisory
·
DECLINED, with reason. The pass flagged 'sub-agent' and 'Phase 0 step 6b' in these very notes as forbidden internal jargon. The rule names the reader-facing ent

Iteration #2 NEEDS_FIXES · 9 findings (truth=5, editorial=2, advisory=11) · Claude Sonnet 5 · 11m 57s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
The Oracle entry's title read 'KEV-listed after seven months of exploitation against government infrastructure', splicing CloudSEK's seven-month untargeted expl
F4
hallucinated-fact
·
The Oracle entry linked product:oracle-weblogic-server, the backend the flaw only pivots into, while the two product entities this run registered for its actual
F4
hallucinated-fact
·
The Gitea entry mapped T1543 (Create or Modify System Process), which its own cited source affirmatively negates: Help Net Security reports no persistence via c
F4
hallucinated-fact
·
The Oracle entry mapped T1090 (Proxy), matching the word rather than the behaviour: the proxy here is the vulnerable target component, not attacker C2 infrastru
F3
claim-not-supported
·
The Gitea entry dated the 1.27.1 fix to 2026-07-28, which no source read states in extractable text and which the vendor's own release blog contradicts by a day
F9
surface-contradiction
·
The Oracle entry's two sources characterise the flaw differently, SecurityWeek calling it a remote code execution flaw and NetSPI describing only unauthorized r
F18
?
·
The Oracle entry's second action restated the body's own exposure argument. Rewritten as a distinct task: pull proxy access logs back to 22 January and reconcil
F11
editorial-advisory
·
The largest finding, and a correction to this audit's own reporting. The pass re-scanned sourcing_note across the whole store rather than across this run's diff
F11
editorial-advisory
·
NOTED, no change. The pass independently re-read the style rule and agreed the run record is outside the fields it binds, while flagging that its own verifier c

Iteration #3 NEEDS_FIXES · 6 findings (truth=4, editorial=1, advisory=2) · Claude Sonnet 5 · 16m 16s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
Confirmed all eight iteration-2 remediations correct against freshly fetched sources, then caught a mapping error this fire had introduced: the Gamaredon entry'
F4
hallucinated-fact
·
Two translated quotations this fire added to correction sections had no evidence record carrying the untranslated original, unlike every other translated quote
F3
claim-not-supported
·
The Oracle entry's sourcing note said the January 2026 fix was stated consistently by both sources; NetSPI directs readers to the Critical Patch Update without
F11
editorial-advisory
·
Numbered-list ordering glitch in the audit report, introduced when the new systemic finding was inserted: the systemic sections read 1,2,3,4,6,5 and the recomme
F11
editorial-advisory
·
NOTED, not fixed. A pre-existing 'this pipeline registers as LAUNDRY BEAR' in the Exchange entry's body, untouched by this fire's diff and outside the new check
F18
?
·
NOTED, not changed. The Oracle entry's first action mirrors its defender takeaway, flagged low confidence. It names the three affected version strings and the b

Iteration #4 NEEDS_FIXES · 3 findings (truth=2, editorial=0, advisory=1) · Claude Sonnet 5 · 12m 27s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
The Oracle entry said SOCRadar ties no specific intrusion to this CVE. Its victimology table does: against 119 raw list entries and 91 unique hosts for the WebL
F4
hallucinated-fact
·
The Zbtlink correction claimed the vendor statement was carried in wire coverage around 2026-08-06, before the entry was first written. The located wire report
F11
editorial-advisory
·
Added the advisory references[] link from the Oracle entry to 2026-08-05/cve-2026-34486-tomcat-encryptinterceptor-fail-open-kev: same SOCRadar staging-server ca

Iteration #5 NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=1) · Claude Sonnet 5 · 13m 11s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
The Kaltura entry quoted CERT/CC saying it had been unable to reach the vendor to coordinate. That sentence is no longer on the page: the 2026-08-28 revision re
F4
hallucinated-fact
·
Two changelog records this fire wrote were marked internal while adding a NATO Admiralty rating to entries that had none, and the site renders that rating as a
F11
editorial-advisory
·
The Oracle entry called the operator's WebLogic success rate far below its Confluence and cPanel campaigns. True against Confluence at 80 of 80, but cPanel is 1

Iteration #6 NEEDS_FIXES · 3 findings (truth=2, editorial=0, advisory=1) · Claude Sonnet 5 · 10m 31s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Fourteen of fifteen entries clean. The Kaltura repair from the previous iteration had only reached the evidence records: the body still quoted the withdrawn CER
F4
hallucinated-fact
·
The same entry's update record listed every field it touched except evidence, which it had changed. Added.
F11
editorial-advisory
·
NOTED, not fixed. The pre-existing self-reference in the Exchange entry body, already carried as part of the historical sweep in recommendation 6.

Iteration #7 CLEAN · 2 findings (truth=0, editorial=0, advisory=2) · Claude Sonnet 5 · 12m 51s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
·
Applied: the Gamaredon mapping carried the parent T1102 where Sekoia describes dead-drop resolvers specifically, which is T1102.001. Narrowed to the sub-techniq
F11
editorial-advisory
·
Applied: the French original on the Protection Civile evidence record used straight apostrophes where the source page uses typographic ones, so it was not a byt

Iteration #8 NEEDS_FIXES cap-breach · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · 9m 30s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
The confirming pass refused iteration 7's CLEAN over one byte: the Franceinfo original on the Protection Civile evidence record used a plain space where the pag

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-30T1312Z-audit · audit · Opus 5 · window 47.7 h · 2 entries published

Verification & coverage notes

Duplicate-audit guard: overridden, and why. The gap to the previous audit record is 47.7 h, inside the 72 h guard. The guard was not applied because the record it measures against is not a quality audit: 2026-08-28T1500Z-audit was an operator-directed interactive editorial session on a sandbox with no external network. It ran no truth passes and no coverage re-sweeps, its own report states that URL-level re-verification of the entries it touched falls to the next network-enabled audit, and it left a named backlog for this fire. The last audit that did this work was 2026-08-24T0902Z-audit, six days ago. Standing down would have left 39 edited entries unverified against their sources and seven flagged residuals unadjudicated.

Window. 2026-08-28T13:30Z (the previous audit record's started) → now. 44 entries in scope: 8 published new by the 08-29 and 08-30 fires, 36 carrying a changelog record inside the window. The coverage re-sweeps used a wider 150 h window, back to the last independent re-sweep on 08-24, because the 08-28 session performed none.

Soundness: 19 of 44 entries clean. 11 factual errors, 14 imprecisions. Every factual error is addressed through that entry's changelog this fire, ten as corrections and one (Kaltura) as an update because the fact changed after publication; the imprecisions are documented in the report without records, per the rule against manufacturing improvements. The dominant defect class is quotation and attribution drift, six of the eleven: a word substituted in a DOJ quote that changes "targets" into "victims", a LevelBlue quote spliced from two paragraphs, a tracker's hedged non-finding restated as a federation's assurance, an analytic position attributed to a report that never mentions the actor in question. Three more are the entry disagreeing with its own evidence: an uncited EPSS figure roughly four times the live value, a CVE-to-mechanism binding reached by elimination and presented as the vendor's, and a cves[].auth field contradicting the CVSS vector the same entry quotes.

Two of the eleven turned on facts that changed or were unreachable when the entries were written, not on composition defects, Kaltura (CERT/CC published patches at 19:59 UTC on 08-28, hours after the fire and after the no-network session) and Zbtlink (a vendor statement present in a source the entry already cited). The Kaltura fix ships as an update rather than a correction and re-floats the entry: it had been telling readers there was nothing to install.

All seven residuals handed over by 2026-08-28T0409Z-intel are adjudicated. Four stand and are now fixed or documented (Claroty CVE binding, confirmed an undisclosed inference, corrected; Hunt.io ZKTeco finding, confirmed present and omitted, added; Unit 42 telemetry windows, confirmed over a year stale, documented; miniOrange third vulnerability; confirmed to exist but the source publishes no CVE id or CVSS for it, so nothing citable to add). One was wrong in a way the residual did not anticipate: the DOJ quote itself was fabricated, not merely spliced. One is resolved (the YOOtheme quote is now contiguous and verbatim). One is unresolvable (the SSD Secure Disclosure primary is still behind an anti-bot challenge) and redirecting it to the secondaries surfaced the Unisoc chipset error.

Completeness: eight items cleared the gate and are in no entry. Two are CISA KEV additions with confirmed exploitation, CVE-2026-21962 (Oracle HTTP Server / WebLogic Proxy Plug-in, CVSS 10.0, unauthenticated, exploited since January, government-sector target profile) and CVE-2026-60004 (Gitea, CVSS 9.8, effectively unauthenticated on a default install). The 08-28 fire read the KEV feed and surfaced four other additions from it; these two appear nowhere in that run, not even as drops. The other six are WatchGuard Fireware OS (two pre-auth RCEs in the IKE daemon, vendor "immediate action"), two Microsoft Threat Intelligence research posts, a Huntress DPRK-worker forensics post, the Norway ID-porten identity-gateway DDoS, and an unresolved Swiss lead blocked by an unreadable source.

Published this run (2 recovered entries, 13 changelog records, 0 deep dives, 0 critical):

  • 2026-08-30/cve-2026-21962-oracle-http-server-weblogic-proxy-plugin-kev (high) - CISA KEV 2026-08-24, CVSS 10.0, unauthenticated access-control bypass in the WebLogic Server Proxy Plug-in and Oracle HTTP Server, exploited since 22 January per CloudSEK honeypot telemetry, with SOCRadar placing it in a China-nexus operator's government-focused campaign. Clears PD-11(b) on confirmed exploitation of a pre-auth flaw on the DMZ tier.
  • 2026-08-30/cve-2026-60004-gitea-diffpatch-git-hook-rce-kev (high) - CISA KEV 2026-08-25, CVSS 9.8, Git-hook code injection via the diffpatch endpoint, effectively unauthenticated wherever Gitea's default open registration is left on, confirmed exploited by automated scanning. Clears PD-11(b) on the same ground.

Two of the eight are recovered as entries in this fire; six stay backlogged. The two KEV-confirmed exploited vulnerabilities are the case PD-11 says must never be deferred into invisibility, so they are composed and published here through the normal gates. The other six are recorded as open rows in state/coverage_backlog.md with primary sources and gate reasoning, which exempts them from the recency gate and puts each in front of the next fire; the priority order puts the truth passes and their eleven corrections first, and six further compositions would have pushed this run past its wall-clock guard. If the six are still open at the next audit, the fix below did not work.

Root cause of the KEV misses, and the fix. Sweeping the KEV catalogue was purely attentional, a research sub-agent read the feed and returned what it noticed, and nothing downstream could tell a considered drop from an unseen row. v4.8 adds tools/kev_window_diff.py and Phase 0 step 6b: every KEV addition inside the window is listed mechanically and marked against the store, and every uncovered row must end the run with a disposition, an entry, an update record, or an explicit borderline-drop: line. Judgement stays with the agent; not knowing the row existed does not.

The tool was run live this fire (work/2026-08-30T1312Z-audit/kev-window.txt): 11 KEV additions since 08-24, 6 not covered. Two are the gaps above; the other four are the legacy UAT-10147 batch, which the two 2026-08-23 UAT-10147 entries discuss in prose without carrying cves[] records, so they are covered for a reader and invisible to every machine surface built on that field. Surfaced, not fixed this fire; it belongs with the next audit's pass over that cohort.

Second systemic finding: ATT&CK mapping density on threat entries fell from 12.6 and 11.1 ids per entry over the two preceding windows to 4.3 in this one, while incident and vulnerability stayed roughly flat. Two changes landed together on 08-28 (the first Sonnet 5 fires, and the v4.2 brevity hardening), so causation cannot be separated from three fires of data and is not claimed. What is stated is a mechanism the prompt contained: the anti-hallucination rule binds techniques[] to behaviours the body describes, and v4.2 shortened bodies, which made prose length a cap on the mapping surface. v4.8 decouples them; the mapping is bound to what the sources describe, and the evidence floor is restated as source evidence rather than body length.

Previous fixes: all took, with one leak and one half. The 08-24 audit's completed-stamp fix holds on every subsequent record. The 08-28 session's internals-out-of-reader-text fix holds in bodies but leaked into one sourcing_note on the very next fire; its English-only-quotations fix and its model pins hold cleanly; its source promotions are half successful (heise contributes, inside-it.ch 403s on every transport). Full table in the report.

Reduced-confidence note (aggregator-only): 2026-08-28/unisoc-volte-mpu-isolation-bypass-android-kernel still rests on two news-aggregator sources. The SSD Secure Disclosure primary was re-attempted on every transport this fire and is still behind an anti-bot challenge, so no re-pivot was possible. The correction this fire applied narrows the entry to exactly what those two secondaries state, and its confidence stays medium.

Legacy debt cleared where the portability fix surfaced it. Re-quoting a non-portable frontmatter scalar pulls the entry into run scope, and two of the three then failed checks that pre-date them. Both were repaired in the same changelog record rather than deferred: 2026-05-18/cve-2026-42897-… gained its first Admiralty rating (A1), and 2026-06-02/sekoia-consolidates-gamaredon-… gained a rating (B2), an evidence-bound techniques[] mapping of the tradecraft its body already described, and two verbatim Sekoia passages replacing an evidence[] record whose "quote" was a migration artefact reproducing this pipeline's own update summary under a publisher byline that never wrote it.

Watchlist: no product or supplier watchlist configured; both sweeps were no-ops and the sector/region lens was applied in their place.

Coverage gaps: ssd-disclosure and inside-it-ch unreachable on every transport, both for the second consecutive fire. google-tag's recipe gap persists.

Essential-coverage: 16 of 17 essential-tier sources contributed cited URLs since 08-24; inside-it-ch is the exception and is a new watch item.

Warning sweep to zero. Nine warnings at Phase 0, all settled run-record history, all acknowledged in state/warning_acknowledgments.json with reasons and each explicitly declining the code change that would weaken the check: seven runaway duration_seconds and two unconfirmed final CLEANs. Three of the seven durations are one story, the 08-21, 08-22 and 08-23 containers stalled and were all finished on 08-24, so those figures are elapsed container lifetime rather than work. The existing 16 rows were reviewed and all still silence a live warning; none pruned. A tenth warning class was introduced by this fire's own new frontmatter-yaml check and fixed rather than acknowledged: three entries carried frontmatter only this repo's lenient parser could read. All three are re-quoted, and the two that turned out to carry further pre-v3.18 debt once the fix pulled them into run scope were repaired in the same record rather than deferred. check_run.py --all ends 0 warn · 0 fail (25 acknowledged).

ATT&CK pin: attack_data.py --check reports local v19.2 == upstream latest v19.2. No drift, no update needed.

Priority calibration: not due; the 2026-08-02 report carries this calendar month's. The high share of operational entries rose to 59.0 % this window against 46.2 % last and 51.1 % store-wide, a 13-point single-window jump; recorded for the September fire to judge rather than adjudicated here.

Notification: none sent. No priority: critical finding and no pipeline breakage, per the operator's standing order.

← Operations dashboard · day page 2026-08-30 · run-record contract: docs/pipeline.md