CTIPilot

2026-09-01T0411Z-intel

One pipeline fire, in full · intel run of 2026-09-01 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-01/2026-09-01T0411Z-intel.md.

Run telemetry

2026-09-01T0411Z-intel intel prompt v4.8 publish ok
3h 01m duration 3 published 4 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
12m 01s
Tool calls
3 WebFetch10 WebSearch28 bridge
Cited sources
1 of 25 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
10m 13s
Tool calls
14 WebFetch15 WebSearch12 bridge
Cited sources
2 of 20 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
13m 42s
Tool calls
15 WebSearch22 bridge
Cited sources
2 of 20 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
7m 03s
Tool calls
5 WebFetch10 WebSearch14 bridge
Cited sources
2 of 19 in slice

Verification

unconfirmed CLEAN · waived: Iteration 8 (the 8-iteration cap) returned CLEAN following iteration 7's NEEDS_F #1 NEEDS_FIXES · Sonnet 5 · t=6 e=2 a=2 #2 NEEDS_FIXES · Sonnet 5 · t=4 e=4 a=0 #3 NEEDS_FIXES · Sonnet 5 · t=0 e=3 a=1 #4 NEEDS_FIXES · Sonnet 5 · t=2 e=4 a=0 #5 NEEDS_FIXES · Sonnet 5 · t=3 e=2 a=1 #6 NEEDS_FIXES · Sonnet 5 · t=3 e=4 a=0 #7 NEEDS_FIXES · Sonnet 5 · t=2 e=1 a=0 #8 CLEAN · Sonnet 5 · t=0 e=0 a=1

Deep dive

·

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 status: candidate -> active · 1 consecutive_fetch_failures/consecutive_quiet_periods reset to 0; last_successful_fetch bumped.

SourceChangeFrom → ToReason
zatazstatus: candidate -> activecandidate → activePromotion bar met per tools/run_summary.py sources.promotion_due (3 contributing runs: 2026-07-27, 2026-08-24-window, 2026-08-31).
inside-it-chconsecutive_fetch_failures/consecutive_quiet_periods reset to 0; last_successful_fetch bumpedconsecutive_fetch_failures=1 (standing 3-consecutive-failure note) → consecutive_fetch_failures=0, last_successful_fetch=2026-09-01The source resolved cleanly this run (RSS 200, article-detail extract worked to the paywall boundary); the prior whole-host block did not recur a 4th time.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
ssd-disclosurehttps://ssd-disclosure.com/bridge:extractwebsearchNone robots-blocked
Site-wide Cloudflare/SiteGround 'Robot Challenge Screen' interstitial on every rung; no in-window item recoverable via WebSearch either.
none, coverage gap

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 10 findings (truth=6, editorial=2, advisory=2) · Claude Sonnet 5 · 10m 50s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·CVE-2026-82329 JFrog Artifactory entry
cves[0].epss listed 0.377 (37.7%) instead of the FIRST.org value 0.00377 (0.377%), 100x overstatement.Corrected epss to "0.00377". fixed
F4
hallucinated-fact
·CVE-2026-42271 LiteLLM entry
This run's own correction record relabeled an evidence[] quote as a verbatim GHSA excerpt; the quoted sentence is the entry's own migrated prose, not GHSA text.Replaced with a genuine verbatim excerpt from GHSA-v4p8-mg3p-g94g describing the subprocess-spawn mechanism. fixed
F5
missing-citation
·CVE-2026-82329 JFrog Artifactory entry
Uncited claim that CISA's SSVC assessment records exploitation as none; the underlying NVD API field is not a citable source under the hard-blocked-pattern rule.Removed the uncited SSVC clause from the body. fixed
F5
missing-citation
·ValleyRAT entry
Sentence on Silver Fox's recurring DLL-sideloading tradecraft carried no citation of its own.Added an inline citation to The Hacker News' sentence on the established tradecraft, naming the Cato Networks precedent. fixed
F3
claim-not-supported
·CVE-2026-82329 JFrog Artifactory entry
Entry stated the 7.146 branch affected range as up to 7.146.37, but the cited JFrog advisory table says up to 7.146.36, and the vendor's own release notes confirm no 7.146.37 build exists (the sequencCorrected the affected range (frontmatter cves[] and body prose) to 7.146.0-7.146.36. fixed
F17
classification
·ValleyRAT entry
classification.reliability was A; sources/sources.json rates the entry's only primary, kaspersky-securelist, as B.Corrected reliability to B. fixed
F11
editorial-advisory
·ValleyRAT entry
Defender-disabling and security-tooling-detection behaviors were described and cited but not mapped in techniques[].Added T1685 (Disable or Modify Tools) and T1518.001 (Security Software Discovery), both active ids in the pinned dataset. fixed
F11
editorial-advisory
·runs/2026-09-01/2026-09-01T0411Z-intel.md notes
Internal sub-agent domain codes (S1-S4) appeared in the published run-record notes body.Rephrased the four affected lines in plain, non-internal language. fixed
F11
editorial-advisory
·CVE-2026-82329 JFrog Artifactory entry
(low confidence) 'signing keys' in the body's risk-framing clause is not stated by any cited source.Removed 'signing keys' from the clause, leaving only source-supported facts. fixed
F11
editorial-advisory
·CVE-2026-42271 LiteLLM entry
(low confidence) The cited GHSA text also supports T1059 (arbitrary command execution) in addition to T1190.Added T1059 to techniques[]. fixed

Iteration #2 NEEDS_FIXES · 8 findings (truth=4, editorial=4, advisory=0) · Claude Sonnet 5 · 13m 43s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·CVE-2026-82329 JFrog Artifactory entry
Iteration 1's own epss remediation was wrong: the store's convention is a percentage number (confirmed by a pre-existing entry with epss: "1.37", impossible as a raw 0-1 probability), so the correct vReverted epss to "0.377"; confirmed the percentage convention independently via FIRST.org API and a store precedent. fixed
F11
editorial-advisory
·runs/2026-09-01/2026-09-01T0411Z-intel.md notes
Iteration 1's internal-language fix was incomplete: 'S5 not spawned' survived in the notes' opening sentence.Rephrased to 'No closed-source intake this run.' fixed
F3
claim-not-supported
·ValleyRAT entry
The 100,000-detection figure was presented as if characterizing this specific campaign; the co-cited Hacker News source states it spans all of 2026's ValleyRAT activity.Rewrote to state the figure covers all of 2026 rather than this campaign, and added Kaspersky's own single-sample basis and no-victim-count caveat for this camp fixed
F3
claim-not-supported
·Anthropic entry
(low confidence) 'the week of 2026-08-24' was cited to BleepingComputer, which states no specific week; only Help Net Security's 'last week' (published 2026-08-31) supports the timing.Rephrased to 'in the days before 2026-08-31' / 'last week, according to Help Net Security's 2026-08-31 report' with the correct citation. fixed
F4
hallucinated-fact
·2026-08-23/payload-zurich-it-provider-hwz-student-data update
Netzwoche was inline-cited in the changelog section and declared in the record's fields:[sources], but never added to the entry's sources[] frontmatter array.Added the Netzwoche URL/publisher/date record to sources[]. fixed
F5
missing-citation
·Anthropic entry
(low confidence) The session-theft-vs-credential-theft analytical sentence had no citation; it tracks Dark Reading's own analysis.Added an inline citation to Dark Reading's framing of the credential-to-session-theft shift. fixed
F8
needs-more-research
·ValleyRAT entry
Kaspersky's finding is based on a single customer-submitted sample and states no victim count for the adware route; not reflected in the entry.Added the single-sample basis and no-victim-count caveat to the body (folded into the same edit as the 100,000-detection scope fix). fixed
F8
needs-more-research
·ValleyRAT entry
(low confidence) Process-critical marking, svchost watchdog injection, and security-tool window enumeration are each gated by a configuration key (bh/sh/ll) per Kaspersky, not unconditional as the entRewrote the runtime-protections paragraph, Defender takeaway and Triage line to state these are independently-configurable options, not constant behavior. fixed

Iteration #3 NEEDS_FIXES · 4 findings (truth=0, editorial=3, advisory=1) · Claude Sonnet 5 · 11m 26s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F12
single-source-flag-missing
·Anthropic entry
Single underlying source (Anthropic's own email) reproduced by three outlets with no independent confirmation matches the store's single-source-victim pattern; verification was multi-source, should beChanged verification to single-source-victim; rewrote sourcing_note to name the carve-out explicitly. fixed
F17
classification
·Anthropic entry
credibility: 1 is inconsistent with the actual single-source-victim corroboration; store precedent for this pattern uses credibility 2.Changed credibility to 2. fixed
F17
classification
·CVE-2026-62911 Exchange MRSProxy entry
(low confidence, advisory) This run's added CERT-Bund/heise corroboration could arguably support credibility 1 instead of 2, though the verifier itself states 2 remains defensible.None, left at credibility 2. The entry's own sourcing_note documents an unresolved interpretive tension between MSRC's and Franky's Web's readings of the precon skipped
F11
editorial-advisory
·runs/2026-09-01/2026-09-01T0411Z-intel.md notes
Internal pipeline-policy shorthand (PD-11, PD-6, PD-7, 'limb (b)/(c)') survived two prior internal-language cleanup passes in the published coverage notes.Rewrote all three affected lines in plain language with no policy-code references. fixed

Iteration #4 NEEDS_FIXES · 7 findings (truth=2, editorial=4, advisory=0) · Claude Sonnet 5 · 12m 52s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F9
surface-contradiction
·CVE-2026-62911 Exchange MRSProxy entry
Three of five cited sources (CERT-Bund/BSI, heise relaying CERT-Bund, NCSC-NL, two of them national CERTs) explicitly state the flaw is exploitable by an unauthenticated attacker; the entry's cves[].aCorrected cves[].auth to pre-auth; added CERT-Bund and NCSC-NL evidence[] quotes stating unauthenticated exploitation; rewrote sourcing_note and the body's auth fixed
F9
surface-contradiction
·CVE-2026-82329 JFrog Artifactory entry
The 7.111 branch affected/fixed numbers matched the corroborating IONIX source and the vendor's own per-release notes, but not JFrog's own summary advisory table, which (inconsistently with its other Added a sentence explaining that JFrog's summary table displays the 7.111 (and 7.146) ranges inconsistently with itself, and that the affected/fixed boundaries fixed
F4
hallucinated-fact
·runs/2026-09-01/2026-09-01T0411Z-intel.md; Aggregator-only sourcing note
The note still asserted the Anthropic entry carries verification: multi-source / credibility: 1, stale since iteration 3 changed both fields on the entry itself.Updated the note to state the entry's current single-source-victim / credibility: 2 values and that they were corrected during this run's own verification loop. fixed
F12
single-source-flag-missing
·2026-08-23/payload-zurich-it-provider-hwz-student-data.md
(low confidence) Whether this entry's plain single-source value should instead be single-source-victim, for consistency with the Anthropic entry's fix.None, left as single-source. The entry blends a genuine victim disclosure (HWZ's own statement) with an unconfirmed leak-site attacker claim for the provider's no_change_needed
F3
claim-not-supported
·2026-08-23/payload-zurich-it-provider-hwz-student-data.md, 2026-09-01 update
The update framed HWZ's 'personal data among stolen data' confirmation as a new, firmer statement superseding the school's earlier position, but Inside IT's own 2026-08-31 article attributes that exacRewrote the changelog summary and body Update section to attribute the supersession correctly to the data-publication fact alone, and to state plainly that the fixed
F11
editorial-advisory
·2026-08-04/liechtenstein-vwbp-beneficial-ownership-register-breach.md
(low confidence) T1136 (Create Account), added this run, is canonically a Persistence-tactic technique for maintaining access after compromise; here the account registration is the initial-access stepRemoved T1136 from techniques[]; also fixed an unrelated but co-located defect found while editing (the entry's sourcing_note referenced the techniques[] field fixed
F8
needs-more-research
·state/cves_seen.json, CVE-2026-42271 record
(low confidence, minor) This run's own correction of the LiteLLM entry's cves[].cvss to 8.7 was not mirrored into this dedup-index record's title, which still read CVSS 8.8.Corrected the title string to CVSS 8.7. fixed

Iteration #5 NEEDS_FIXES · 6 findings (truth=3, editorial=2, advisory=1) · Claude Sonnet 5 · 13m 59s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·CVE-2026-82329 JFrog Artifactory entry
Frontmatter summary and body both called CVE-2026-66384 a 'critical-severity' flaw alongside CVE-2026-82329; JFrog's own table and this store's own existing entry for it rate it Medium (CVSS 5.3).Rewrote both the frontmatter summary and the body's closing sentence to name CVE-2026-66384 as Medium-severity and KEV-listed, and to state CVE-2026-82329 is th fixed
F4
hallucinated-fact
·Anthropic entry
(low confidence) Title said Anthropic 'mass-revokes accounts' when every cited source and the entry's own body/summary/headline say sessions were revoked, not accounts.Changed 'accounts' to 'sessions' in the title. fixed
F3
claim-not-supported
·ValleyRAT entry
(low confidence) 'a child svchost.exe ... shortly after creation' asserted process-lineage and timing specifics (newly-spawned child process, quick timing) that Kaspersky's source does not state, it sRewrote the Defender-takeaway and Triage sentences to describe code injected into svchost with a roughly-one-minute delay before the memory-permission change, d fixed
F5
missing-citation
·Anthropic entry
A verbatim Anthropic quote ('refilled and then drained') appeared in the Triage line with no inline citation and was absent from evidence[].Added the inline citation and a matching evidence[] record; removed an adjacent uncited 'unexpected device or location' clause no source states. fixed
F10
missed-angle
·Liechtenstein VwbP entry / whole-run coverage
2026-08-31 reporting that Switzerland's Federal Council will proceed with its own 2026-10-01 Transparency Register launch despite wealth-manager delay requests following the Liechtenstein breach; not Researched substantively (domain-b.com, byline, 2026-08-31, names the Swiss Association of Wealth Managers' 2026-08-24 letter and the Federal Council's decision skipped
F11
editorial-advisory
·ValleyRAT entry
(low confidence) T1055.012 (Process Hollowing) was doing double duty for two distinct behaviors, the source explicitly names 'process hollowing' only for the shellcode-module-loading path, not the sepAdded bare T1055 (Process Injection) alongside T1055.012, so the watchdog-injection behavior maps to the parent technique rather than overclaiming the hollowing fixed

Iteration #6 NEEDS_FIXES · 7 findings (truth=3, editorial=4, advisory=0) · Claude Sonnet 5 · 12m 15s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·CVE-2026-82329 JFrog Artifactory entry
Entry claimed JFrog's advisory table shows both the 7.111 and 7.146 branch ranges as internally inconsistent; a live re-fetch shows only 7.111 is inconsistent (7.146.0 > 7.146.36, fix 7.146.38, is finRewrote the sourcing sentence to name only the 7.111 branch as inconsistent. fixed
F3
claim-not-supported
·2026-08-23/payload-zurich-it-provider-hwz-student-data.md update
(low confidence) The entry states the ransomware-gang attribution for the provider-side intrusion as settled fact; Inside IT's own page hedges it with 'offenbar' (apparently).Rewrote the changelog summary and body Update section to attribute the data-publication fact plainly but hedge the ransomware-gang attribution per Inside IT's o fixed
F8
needs-more-research
·CVE-2026-62911 Exchange MRSProxy entry
A detailed third-party technical write-up (MB VRED, found via a Franky's Web reader comment) shows real-world exploitation needs an internal domain-joined foothold, PetitPotam-style MS-EFSR coercion, Fetched and grep-verified the MB VRED write-up; added it as a corroborating source with two evidence quotes, and added a body paragraph plus sourcing_note claus fixed
F8
needs-more-research
·ValleyRAT entry
(low confidence) The Hacker News documents a `runas` UAC-elevation relaunch behavior omitted from the entry.Added a verbatim evidence quote and a body clause describing the runas relaunch. fixed
F8
needs-more-research
·ValleyRAT entry
(low confidence) Securelist documents a third, always-on process-resilience technique (restart on unhandled exception) alongside the two configuration-gated ones the entry describes.Added a verbatim evidence quote and a body clause naming this fourth, always-active resilience mechanism. fixed
F10
missed-angle
·ValleyRAT entry / actor:silver-fox
Entry doesn't connect Kaspersky's 2026-wide detection count to the registry's existing incident:silver-fox-arrests-china-2026 record (67 operators arrested, June 2026).Researched the angle (WebSearch + fetched Risky Bulletin's original 2026-06-17 arrest report); added it as a corroborating source with an evidence quote and a b fixed
F14
quantifier-without-source
·Anthropic entry
(low confidence) 'mass-revokes' in the title and the campaign registry summary isn't supported, Dark Reading says Anthropic signed out 'an unknown number' of users.Changed 'mass-revokes' to 'revokes' in the entry title and the entities/registry.yaml campaign summary. fixed

Iteration #7 NEEDS_FIXES · 3 findings (truth=2, editorial=1, advisory=0) · Claude Sonnet 5 · 8m 44s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F8
needs-more-research
·CVE-2026-62911 Exchange MRSProxy entry
The new MB VRED paragraph omitted the source's own explicit real-world-exploitability caveats ('It requires lot of non-realistic conditions to be exploited in the real world... So, for the defensive gAdded MB VRED's caveat and risk-downplaying conclusion as two new evidence[] quotes and rewrote the body paragraph and sourcing_note to present them alongside t fixed
F13
analytical-link-as-fact
·CVE-2026-62911 Exchange MRSProxy entry
(low confidence) MB VRED never mentions MSRC/CVSS/PR:L; the entry's 'consistent with MSRC's PR:L' claim is this entry's own unstated synthesis, and MB VRED calls the domain-joined-PC requirement 'the Same edit as the F8 fix above: rewrote the paragraph to attribute the domain-joined-PC precondition to MB VRED's own hypothesis framing, softened the PR:L-consi fixed
F13
analytical-link-as-fact
·ValleyRAT entry
Kaspersky's report never dates the QN Wallpaper campaign itself (only its 2026-08-31 publication date is established), so stating that campaign 'postdate[s]' the 17 June arrests was an unstated infereRewrote the body sentence and the entities/registry.yaml relation note to attribute the postdate-the-arrests finding to the Cato/Japan campaign only, and to sta fixed

Iteration #8 CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Sonnet 5 · 12m 24s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
·CVE-2026-62911 Exchange MRSProxy entry
The non-internal 2026-09-01T04:40:00Z update record's changelog summary contained a raw frontmatter field-path reference ('the entry's cves[].auth field is corrected from post-auth to pre-auth') that Rewrote the phrase in plain language ('this entry now describes the flaw as exploitable pre-authentication, corrected from an earlier post-auth framing') withou fixed

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-01T0411Z-intel · Sonnet 5 · window 26 h · 3 entries published

Verification & coverage notes

Standard window (gap_hours=24.0, window_hours=26). No closed-source intake this run. Mechanical KEV sweep (tools/kev_window_diff.py) found 2 in-window additions (CVE-2026-81578, CVE-2026-82078, both PaperCut), both already covered.

New entries (3): CVE-2026-82329 (JFrog Artifactory default-config admin bypass, high), ValleyRAT/Winos4.0 via a re-signed QN Wallpaper installer (Kaspersky, notable), Anthropic Claude session-hijacking via commodity infostealers (notable). Updates (4): CVE-2026-42271 LiteLLM (internal metadata correction, cvss/vector fixed to match the entry's own already-cited GHSA), the Liechtenstein VwbP breach (NZZ names the access vector, portal-interface vulnerability, new-account registration, one-by-one enumeration), the HWZ/Payload provider breach (data now published; HWZ confirms personal data), and CVE-2026-62911 Exchange MRSProxy (BSI: ~85% of German on-prem Exchange servers still unpatched two weeks after the fix, with public exploit code live).

  • Run duration (~3.0 h) exceeds the normal runaway threshold: the cause is an unusually productive verification loop, not a stall or a broken step. Eight verification iterations ran back-to-back (the pipeline's iteration cap), together surfacing and fixing over twenty genuine truth and editorial defects across the new and updated entries, including a material auth-precondition correction on the Exchange MRSProxy entry (post-auth to pre-auth, later refined with a third-party technical caveat), an EPSS-convention self-correction, a chronology error on the HWZ update, and a severity-overstatement fix on the JFrog entry. The final iteration (8) returned CLEAN, but because the prior iteration (7) had returned NEEDS_FIXES, this is a CLEAN-but-unconfirmed result published under the fail-open cap rule rather than a double-CLEAN confirmation (see verification.confirmation_waived above). No step stalled or errored; every phase completed normally, just slower than usual given how much the verifier found to fix.
  • borderline-drop: McKesson/ShinyHunters healthcare data-theft extortion (US, 284M claimed records, $55.2M demand), no home-region or sector nexus for this constituency; the transferable lesson (the <company>.claims vishing-domain pattern) is real but not novel to this incident (ReliaQuest had already flagged the pattern), the claimed scale is the actor's own unconfirmed figure, and the case that this actor also plausibly targets this constituency is thin. Dropped on balance of doubt.
  • borderline-drop: Ixa Systems SA (Crissier, VD) / TheGentlemen leak-site listing, a small Swiss physical-security integrator naming police/prison/hospital clients, but a bare single-source leak-site claim with no victim confirmation and no reputable independent journalism does not meet the bar to publish. Held open in state/coverage_backlog.md given the sensitivity of the claimed client base; re-check on a later fire.
  • Aggregator-only sourcing (checked, unfixable today): the Anthropic Claude session-hijacking entry's three sources are all press outlets (BleepingComputer, Dark Reading, Help Net Security), a fair-attempt search of anthropic.com/news, trust.anthropic.com and support.claude.com found no independent Anthropic post or advisory on this campaign; the primary is genuinely Anthropic's direct user-facing email to its own affected users, reproduced with consistent wording by three separate outlets with no independent confirmation. verification: single-source-victim and classification: {reliability: B, credibility: 2} reflect that reality (corrected from an initial multi-source/credibility-1 miscalibration during this run's own verification loop); check_run.py's aggregator-only WARN is expected to persist until Anthropic publishes something more official.
  • Coverage gap: research this run identified four substantive stories (Aurora ransomware operators' use of Cursor AI per CloudSEK/Gambit Security; ReliaQuest's Gryxa AI-built toolkit; Sygnia's Fire Ant actor profile; a Team Cymru Cl0p retrospective) published 2026-08-27 through 2026-08-30 that correctly fall outside this run's 26-hour recency window, but none appears in prior_coverage.json either, meaning they fell through the gap between two consecutive same-day-lookback windows. This is a structural artifact of back-to-back daily windows on stories that broke mid-window, not a research miss this run could have closed without publishing stale material. Flagging for the next quality audit's coverage re-sweep to assess whether any are still worth publishing today.
  • Registry hygiene: incident:silver-fox-arrests-china-2026 (first_seen 2026-06-18) had no entry file referencing it, an apparent orphan from the v4.0 weekly-routine purge (2026-08-29). This run's own verification loop surfaced a genuine connection to the new ValleyRAT/Silver Fox entry (both that entry and the July 2026 Japanese-manufacturer campaign postdate the June 2026 arrests): added a sourced related-to relation from actor:silver-fox to the incident record, closing the orphan.
  • Source health: inside-it-ch resolved cleanly on the first attempt this run after three consecutive whole-host failures (2026-08-29 through 2026-08-31), see sources_changed[]. Separately, the long-standing state/coverage_backlog.md row for the Insel Gruppe/ServiceNow lead is now diagnosed as a subscriber-paywall problem rather than a transport block: the specific article (inside-it.ch/insel-gruppe-verschiebt-wechsel-zu-servicenow-20260828, dated 2026-08-28) fetches cleanly at the metadata level but its body remains paywalled; no corroborating Swiss outlet was found on a targeted search.
  • zataz promoted candidate→active per the promotion rule (3 contributing runs).
  • Essential-coverage: all essential-tier sources in the vulnerability/exploitation and home-region domains were attempted and reachable this run; no miss.
  • Coverage gaps (non-essential, quiet or thin this run, no fetch failure beyond ssd-disclosure): govcert-at, infoguard-ch, oneconsult-ch, compass-security (time-budgeted), paradigm-shift-research, trellix, fox-it-blog, sans-newsbites, csa-labs (low-cadence/stale/secondary), ico-uk, venarix, cnil-fr, ransom-isac (reachable but no in-window item).

← Operations dashboard · day page 2026-09-01 · run-record contract: docs/pipeline.md