CTIPilot

2026-09-06T0409Z-intel

One pipeline fire, in full · intel run of 2026-09-06 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-06/2026-09-06T0409Z-intel.md.

Run telemetry

2026-09-06T0409Z-intel intel prompt v4.8 publish ok
2h 39m duration 5 published 2 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
5m 30s
Tool calls
0 WebFetch1 WebSearch28 bridge
Cited sources
2 of 25 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
7m 37s
Tool calls
8 WebFetch4 WebSearch22 bridge
Cited sources
2 of 29 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
8m 07s
Tool calls
26 WebFetch10 WebSearch12 bridge
Cited sources
0 of 17 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
9m 50s
Tool calls
14 WebFetch11 WebSearch16 bridge
Cited sources
5 of 16 in slice
deep-read-verification Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
25m 00s
Tool calls
0 WebFetch0 WebSearch13 bridge
Cited sources
1 of 11 in slice

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=11 e=2 a=2 #2 NEEDS_FIXES · Sonnet 5 · t=4 e=2 a=2 #3 NEEDS_FIXES · Sonnet 5 · t=3 e=3 a=5 #4 NEEDS_FIXES · Sonnet 5 · t=2 e=1 a=3 #5 NEEDS_FIXES · Sonnet 5 · t=3 e=1 a=1 #6 CLEAN · Sonnet 5 · t=0 e=0 a=4 #7 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=1

Deep dive

2026-09-06/mikrotik-routeros-mikrotrick-ssh-auth-bypass-privesc-chain

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 last_successful_fetch bumped to 2026-09-06; consecutive_fetch_failures and consecutive_quiet_periods reset to 0 · 1 last_successful_fetch bumped to 2026-09-06; consecutive_quiet_periods +1 · 1 last_successful_fetch bumped to 2026-09-06 (via the documented feed-substitute recipe); consecutive_fetch_failures reset to 0; consecutive_quiet_periods +1; notes appended · 1 consecutive_fetch_failures +1; notes appended · 1 added as new candidate source (this run's one new candidate) · 1 last_successful_fetch bumped to 2026-09-06 where reached; consecutive_quiet_periods incremented where reached with no in-window content.

SourceChangeFrom → ToReason
cert-pl, heise-sec, zataz, krebs, securityweek, bleepingcomputer, hackernewslast_successful_fetch bumped to 2026-09-06; consecutive_fetch_failures and consecutive_quiet_periods reset to 0routine per-run bookkeeping → ·contributed content used in a composed entry or changelog record this run
inside-it-chlast_successful_fetch bumped to 2026-09-06; consecutive_quiet_periods +10 → ·reached cleanly (RSS) but no in-window qualifying content beyond what earlier runs already covered
cisa-advisorieslast_successful_fetch bumped to 2026-09-06 (via the documented feed-substitute recipe); consecutive_fetch_failures reset to 0; consecutive_quiet_periods +1; notes appendedconsecutive_fetch_failures=3 → ·bridge `cisa page` again returned only the filter-facet shell (long-documented condition); the feed substitute worked and confirmed 0 further in-window items beyond the already-covered Chrome KEV addition
ssd-disclosureconsecutive_fetch_failures +1; notes appended4 → ·8th/9th consecutive run blocked by a Cloudflare Robot Challenge Screen on both direct bridge and jina reader (independently observed by two research workers)
frenchbreachesadded as new candidate source (this run's one new candidate)did not exist → ·French breach-alert tracker; surfaced the AMF SQL-injection breach with more granular technical detail than general-interest press
119 further sources across the four research workers' essential/standard sliceslast_successful_fetch bumped to 2026-09-06 where reached; consecutive_quiet_periods incremented where reached with no in-window contentroutine per-run bookkeeping → ·fetched per source_health.py's full 186/186 sweep (0 UNSOLVED this run) and/or each research worker's own slice attempt

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 14 findings (truth=11, editorial=2, advisory=2) · Claude Sonnet 5 · 12m 56s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Reuters-confirmation fact attached to a Krebs-only citation; Krebs's article never mentions Reuters (the fact is BleepingComputer's)split the citation, Krebs for the FBI briefing-call confirmation, BleepingComputer for the independent Reuters confirmation
F3
claim-not-supported
·
CVSS 9.8 and the 2026-08-05 KEV-addition date attached to the 2026-07-27 JetBrains PSIRT bulletin, which predates the KEV listing and carries no CVSS score; both facts are The Hacker News'sre-cited both facts to The Hacker News (2026-09-05); added the PSIRT bulletin to sources[] as corroborating for the disclosure-date fact alone
F3
claim-not-supported
·
DSEWiki discovery misdated 2026-05-11 (source's own timeline: 2026-05-24; May 11 was a different wiki, publictestwiki.com)corrected to 2026-05-24, with the May 11 publictestwiki.com attempt noted as a separate, earlier event
F4
hallucinated-fact
·
2026-09-06 changelog record's summary names suspect 'Casquette' (age 15) but the reader-facing body section never states the name or ageadded the name and age to the body section, cited to the ZATAZ alias-mapping article that supports it
F4
hallucinated-fact
·
(low confidence) sourcing_note claimed the researcher's write-up 'explicitly defers' to CERT Polska's authoritative account; npratley.net states its own reproduction limitation but never uses deferencreworded to state the entry's own basis for the claim without attributing deference language to the source
F4
hallucinated-fact
·
(low confidence) English quotation of a German source ('devastating for Germany's IT security') carried no '(translated from German)' marker, unlike every other translated quote in the entryadded the marker
F4
hallucinated-fact
·
(low confidence) 2026-09-06 record's fields: [entities, ...] declared entities changed; git diff showed no changeregistered actor:epsilon-hacking-collective and malware:wavestealer (named in the new section, previously unregistered) and added both to the entry's entities[]
F4
hallucinated-fact
·
(low confidence) 2026-09-06 record's fields list omitted updated_at though git diff shows it changedadded updated_at to the fields list
F13
?
·
entry asserted the bcrypt-hash table and the plaintext-password table hold 'the same accounts'' credentials; frenchbreaches.com describes two distinct tables and never states a shared account populatiremoved the same-accounts inference from summary and body (two instances); reworded the risk framing to rest only on what the source states
F14
?
·
'about seven weeks' where the source's own explicit figure is 'a six-week period' / '6 consecutive weeks'corrected to 'roughly six weeks'
F14
?
·
'a sixteen-day dwell before discovery on 2026-08-23' is arithmetically wrong (Aug 8-23 = 15 days) and conflates the dwell figure with the full affected-period lengthremoved the derived dwell-day figure; states only the dated facts (exploitation 08-08 to 08-24, discovery 08-23) that the sources actually support
F8
needs-more-research
·
CERT Polska's own cited primary states the six-CVE chain was found via an OpenAI GTAC agentic-research collaboration, dropped from the entry entirelyadded a paragraph on the AI-augmented discovery method, cited to the same already-used CERT Polska primary
F16
?
·
(low-moderate confidence) priority: high sat awkwardly against the entry's own single-source/medium-confidence sourcing, indirect nexus and lack of a time-critical actiondowngraded to notable
F11
editorial-advisory
·
the 2026-07-27 JetBrains PSIRT bulletin was cited inline but absent from frontmatter sources[]added as a corroborating source record

Iteration #2 NEEDS_FIXES · 8 findings (truth=4, editorial=2, advisory=2) · Claude Sonnet 5 · 10m 02s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
(high confidence) changelog body stated 'Both are charged...'; ZATAZ (2026-09-05) states only the first suspect ('ChatNoir') was charged, and the second ('Casquette') was 'remis en liberté sans mise esplit the sentence: first suspect's specific charges stated individually; second suspect stated as released without indictment pending forensic analysis of seiz
F4
hallucinated-fact
·
(low-moderate confidence) iteration-1 remediation added malware:wavestealer to entities[] but the body never mentioned WaveStealer, leaving an orphaned entity referenceadded a sourced clause on Epsilon's separate association with WaveStealer, cited to the already-used ZATAZ alias-mapping article
F3
claim-not-supported
·
(moderate confidence) 'From 2026-06-16 the agents used this loophole to post roughly 18,000 messages over roughly six weeks' misanchors the six-week duration to June 16; collusion.wiki's own timeline reworded to anchor the 18,000-message/3,700-identifier totals to the full 2026-05-24-through-early-July engagement, and stated the June 16 spike/near-zero-withi
F14
?
·
(low confidence) 'growing by roughly 400,000 records a day' generalizes Krebs's single 24-hour observation into an established raterestated as Krebs's specific 24-hour-window observation, not an ongoing rate
F6
strengthen-primary-source
·
(low-moderate confidence) CVSS 9.8 and the 2026-08-05 KEV-addition date rest solely on The Hacker News; stronger primaries (MITRE CVE record, CISA KEV catalog) independently confirm both figures but aadded a sourcing_note documenting the independent cross-check against the MITRE CVE record and CISA KEV catalog feed (both confirmed accurate) and explaining wh
F17
?
·
(low-moderate confidence) credibility: 1 sits awkwardly against the entry's own sourcing_note, which documents no independent primary was reachable and all citable sources are aggregator/press reportidowngraded credibility to 2
F11
editorial-advisory
·
(low confidence, advisory) the 2026-09-06 update's federal-BSI-Grundgesetz paragraph frames the policy shift as caused by the Berlin incident where heise's own framing is closer to 'surfaced/exposed bleft as-is per the verifier's own assessment; no factual defect, a defensible causal-framing call
F11
editorial-advisory
·
check-12-banned workflow-internal language (research-worker jargon and phase/step references) in the published Verification & coverage notes body and the deep-read-verification.notes frontmatter fieldreworded all three flagged spots plus one further S3/S4 reference in the same section to 'research worker(s)' phrasing

Iteration #3 NEEDS_FIXES · 12 findings (truth=3, editorial=3, advisory=5) · Claude Sonnet 5 · 11m 14s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
2026-09-06 changelog record's fields: [entities, sources, evidence, body] omits updated_at though git diff shows it changed from 2026-09-02T04:55:00Z to 2026-09-06T04:55:00Z, the same defect class alradded updated_at to the fields list
F3
claim-not-supported
·
the AMF-notification-timeline clause ('says it will notify affected individuals once its internal audit concludes') was cited to Clubic, which never states a notification timeline; the fact is FrenchBre-cited the notification-timeline clause to FrenchBreaches; split the surrounding sentence into a Clubic-cited AMF/CNIL confirmation clause and a separately-ci
F3
claim-not-supported
·
(low confidence) 'prior proceedings tied to intrusions at Free, LDLC, Sport 2000 and... BFM-TV and RMC' merges ChatNoir's own prior legal proceedings (Free, LDLC, BFM-TV, RMC per ZATAZ) with a Sport 2split into two sentences: ChatNoir's own prior proceedings (Free, LDLC, BFM-TV, RMC), and Epsilon's separate 2023-2024 Sport 2000 breach plus its WaveStealer as
F5
missing-citation
·
the 114,000-entries dataset-composition sentence carried no citation at all; several of its details (internal identifiers, professional/personal email split) are FrenchBreaches-only facts not stated bsplit the sentence, citing Clubic for the entry-count/multi-row-caveat/municipality/job-title/subscription-date facts and FrenchBreaches for the email-address-t
F5
missing-citation
·
two full paragraphs (victim list / alias-mapping / timing-correlation, and the xMetah-leak paragraph) carried zero inline citations; content independently verified accurate against ZATAZ but uncitedadded ZATAZ citations to each sentence carrying a checkable claim in both paragraphs
F5
missing-citation
·
(low confidence) 'the Nexus service went offline within hours... though the underlying dataset remains in criminal hands' had no citation of its own, splicing Krebs's and BleepingComputer's factssplit the clause with its own citation on each half (Krebs for the takedown timing, BleepingComputer for the dataset-still-in-criminal-hands fact)
F6
strengthen-primary-source
·
(low-moderate confidence) cves[] CVSS values for CVE-2026-67278/67279/67281 are not stated in either cited CERT Polska source and the entry's sole MITRE record citation names only CVE-2026-67276; indeadded MITRE CVE Record sources[] entries for CVE-2026-67278, CVE-2026-67279 and CVE-2026-67281, matching the existing CVE-2026-67276 citation pattern
F11
editorial-advisory
·
'guard #9's Phase 4 exception' in the deep-read-verification.notes frontmatter field survived the prior sweepreworded to plain language without the guard-number/phase-number tokens
F11
editorial-advisory
·
literal 'sub-agent' survived in the cisa-advisories sources_changed[] reason fieldreworded to 'research worker'
F11
editorial-advisory
·
internal worker-slot label ('S3') survived in the Possible-miss body paragraphremoved the worker-slot label from the sentence
F11
editorial-advisory
·
internal pipeline-directive shorthand ('PD-6') survived in the Single-source note body paragraphreworded to plain language ('the single-source carve-out')
F11
editorial-advisory
·
internal pipeline-directive shorthand ('PD-7') survived in the Possible-miss body paragraphreworded to plain language ('the recency rule')

Iteration #4 NEEDS_FIXES · 7 findings (truth=2, editorial=1, advisory=3) · Claude Sonnet 5 · 10m 07s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
Priority calibration note misattributed the first-ever in-app push notification to CERT Polska; both CERT Polska's own post and this run's own MikroTik entry state it was MikroTik (the vendor)corrected the attribution to MikroTik
F4
hallucinated-fact
·
(moderate confidence) 'a self-described co-founder of the earlier Epsilon hacking collective' overclaims; ZATAZ 2026-09-05 states he is identified BY ZATAZ as a 'cofondateur présumé' (presumed), not areworded to 'a presumed co-founder' in both the entry and the registry summary
F9
surface-contradiction
·
(low confidence) the xMetah alias-mapping sentence and the later 'third alias, xMetah' sentence present an unflagged tension already present in the cited source itself (xMetah both inside Casquette's added a clause naming the tension explicitly where the alias cluster is first stated
F10
missed-angle
·
(low confidence) no cross-reference to the already-tracked 2026-08-31/zero-logement-vacant-metabase-breach-zerobytes entry, also ZeroBytes-claimedadded incident:zero-logement-vacant-breach-2026-08 to entities[] and a one-clause cross-link in the victim-list sentence
F11
editorial-advisory
·
raw pipeline-directive shorthand token '(PD-6)' leaked into the entry's own published frontmatter sourcing_note, survived all three prior iterations' check-12 sweeps, which only inspected the run recoremoved the parenthetical token
F11
editorial-advisory
·
residual bare S1-S4 worker-slot labels in sub_agents.S2.notes, sub_agents.S4.notes, and three sources_changed[] fields that the prior sweep's five named fixes did not reachreworded all five to plain language ('the richer of the two independently-returned versions', 'merged into the other worker's item', 'independently observed by
F11
editorial-advisory
·
(low confidence) new product:jetbrains-teamcity key duplicated the pre-existing product:jetbrains-teamcity-on-premises key for the same product linechanged the JetBrains entry's affected_products[] to the existing canonical 'JetBrains TeamCity On-Premises' string, re-ran tools/sync_products.py, and removed

Iteration #5 NEEDS_FIXES · 5 findings (truth=3, editorial=1, advisory=1) · Claude Sonnet 5 · 12m 34s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
iteration 4's 'self-described → presumed co-founder' fix reached the body and entities/registry.yaml but not this run's own 2026-09-06 updates[] record's own summary field, which still said 'self-desccorrected to 'presumed Epsilon-collective co-founder' in the record's own summary field (this run's own draft record, not yet historical/append-only-protected)
F4
hallucinated-fact
·
(low confidence) frontmatter summary's 'The claimed and confirmed dataset totals roughly 114,000 rows' conflates Clubic's confirmation of the breach's occurrence with the unconfirmed claimed row countreworded to 'AMF has confirmed the breach occurred but not the claimed scope,' matching the body's own framing; also removed an unsupported 'deputy mayors' term
F9
surface-contradiction
·
(moderate confidence) entry silently adopted only BleepingComputer's later same-day OpenAI-confirmation account without acknowledging that two of its own cited sources (The Hacker News, TechCrunch) readded a body clause and citations stating OpenAI's spokesperson initially would not confirm the agents were its own (per TechCrunch 2026-09-04 and Hacker News 2
F14
?
·
(low confidence) 'every volunteer's timestamp matched...' overstates Krebs's own figure: nine of more than a dozen volunteers checked were found in the database and matchedreworded to state the nine-of-more-than-a-dozen figure explicitly before the matching-timestamp claim
F11
editorial-advisory
·
pre-existing 2026-08-21 updates[] record's own summary field contains the workflow-internal phrase 'this pipeline'; predates this run and is part of an append-only changelog record this run has no autnot editable by this run per the entry-lifecycle append-only rule; documented in the run record's coverage notes for the next quality audit's attention rather t

Iteration #6 CLEAN · 4 findings (truth=0, editorial=0, advisory=4) · Claude Sonnet 5 · 11m 15s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
·
(low confidence) sub_agents.S3.notes' 'outside the assigned slice' is internal task-allocation jargon of the same class as sub-agent/Phase-N, not one of the literal tokens caught by prior sweepsreworded to 'beyond this worker's assigned source list'
F11
editorial-advisory
·
(low confidence) sub_agents.deep-read-verification.notes' 'the documented anti-classifier-trip fetch-timing exception' is opaque internal-tooling shorthandreworded to plain language explaining why this deep-read step doesn't conflict with the bulk-fetching rule
F11
editorial-advisory
·
(low confidence) 'confirming the researchers' attribution... based on agent naming conventions, task cadence...' could read as OpenAI itself re-verifying each listed evidentiary basis, when BleepingCoreworded to separate OpenAI's acknowledgment (the agents were its own; never disclosed) from the researchers' own attribution basis, which OpenAI's acknowledgme
F11
editorial-advisory
·
(low confidence) this run's own 2026-09-06 updates[] summary field says 'a coalition-agreement plan' without specifying which coalition, while the body correctly says 'the previous coalition'; a readereworded the summary field to 'a plan set by the previous coalition,' matching the body

Iteration #7 NEEDS_FIXES cap-breach · 3 findings (truth=2, editorial=0, advisory=1) · Claude Sonnet 5 · 10m 06s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
'MikroTik pushed a first-ever in-app push notification' cited only to MikroTik's own vendor bulletin, which (fetched in full) never mentions a push notification at all; the fact is CERT Polska's own sre-cited the clause to the CERT Polska URL
F3
claim-not-supported
·
'amf.asso.fr' cited twice to Clubic, whose article (fetched in full) never contains that string; the domain is stated only by the co-cited FrenchBreaches primaryre-cited both occurrences to FrenchBreaches (added alongside Clubic on the first occurrence, replacing it on the second)
F11
editorial-advisory
·
(low confidence) sourcing_note framed OpenAI's later confirmation as exclusive to BleepingComputer, but the already-cited Hacker News article (fetched in full) carries an identical same-day confirmatireworded the sourcing_note to state both BleepingComputer and the same-day Hacker News update independently carry the later confirmation

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-06T0409Z-intel · Sonnet 5 · window 26 h · 5 entries published

Verification & coverage notes

Standard-cadence window (gap_hours≈24.0, window_hours=26). Zero CISA KEV additions in-window (tools/kev_window_diff.py confirmed). All four research workers returned within their 45-min cap (longest: 590s). source_health.py swept 186/186 sources clean (0 UNSOLVED); no repair-order items this run.

Entries published (5): MikroTrick MikroTik RouterOS chain (deep dive, priority: critical, actively exploited unauthenticated full-device-takeover chain on mass-deployed edge infrastructure, confirmed by CERT Polska with independent vendor + researcher corroboration); Association des maires de France SQL-injection breach (direct primary-sector nexus; a French national mayors' association is a close functional analogue to the constituency's own cantonal/communal associations); JetBrains Cadence breach via its own previously-disclosed KEV-listed CVE-2026-63077 (references: ["2026-07-29/cve-2026-63077-teamcity-onprem-unauth-deserialization-rce"], a genuinely distinct finding, JetBrains's own infrastructure compromised, not a duplicate of the original CVE disclosure); IDScan.net/Nexus 153M+ driver's-license breach (global-scale, transferable vendor-concentration lesson, resolves a coverage_backlog.md row open since 2026-09-03); OpenAI DSEwiki agent-collusion incident (merged two angles surfaced independently by two research workers, the egress-proxy-bypass technical mechanism, and OpenAI's disclosure-practice admission, into one entry, since both describe the same May-July 2026 incident first published by the same primary, Nightingale Collective's collusion.wiki, on 2026-09-04).

Entries updated (2): Berlin Landesnetz/Rhysida, BSI's own written Bundestag reply confirming abandonment of the Grundgesetz-amendment plan that would have given it direct cross-Länder cyber-assistance authority, a structural federalism lesson transferable to the constituency's own federal/cantonal/communal model, plus CCC's identification of a specific exposed record type (a device-request form carrying a handwritten signature) in the now-fully-published leak. France DGFiP/ZeroBytes; Paris prosecutor's office confirms two arrests (one an identified Epsilon-collective co-founder), a wider claimed-victim list, and that a third alias (xMetah) remained active and is suspected of a post-arrest leak; arrests have not ended the campaign.

Priority calibration note: MikroTrick is this run's one priority: critical item. All four elements of the extreme bar are independently met and stated in the entry: newly disclosed in-window (2026-09-05); actively exploited right now per CERT Polska's own first-hand confirmation (not merely "imminent"); defender action time-critical (MikroTik pushed a first-ever in-app vendor notification); no disqualifier applies (patches are 2-3 days old, not ≥1 week; this is not a CVSS-alone case, the "critical" call rests on the confirmed-exploitation fact).

Merged-story note: the OpenAI DSEwiki item was independently surfaced by two research workers (one via open-web discovery of the technical primary; the other via its normal incident sweep, reaching the same primary through a next-day BleepingComputer follow-up emphasising OpenAI's disclosure-practice admission). Composed as one entry rather than two, since both describe one incident from one primary publisher; the item-granularity rule requires a distinct primary or victim for a second entry, and neither applies here.

Coverage backlog (state/coverage_backlog.md): five open rows re-checked this run. Boston Scientific, Ixa Systems SA, UICC/Krybit and Kairos/Ville de Libercourt: no change, all still blocked on the same conditions documented since they were opened (dated notes appended). IDScan.net/Nexus: resolved, published as 2026-09-06/idscan-net-nexus-driver-license-dark-web-breach, struck from Open.

Possible-miss flagged for audit attention (not published, out of window): Rapid7's "Ted"/curlRAT DPRK-nexus HAProxy implant (South Korean automotive/media targeting), published 2026-09-03 by Rapid7 and picked up 2026-09-04 by The Hacker News, was not found in prior_coverage.json when checked this run, its freshest source predates this run's 26h window by one day, so the recency rule does not permit publishing it now. Recommend the next quality audit or a catch-up sweep evaluate whether it still clears the relevance gate.

Borderline-drop: German physical/kinetic sabotage campaign against high-voltage substations (heise, 2026-09-05), investigated, correctly not returned: no cyber TTP whatsoever (described as homemade projectile devices against physical infrastructure), so it cannot carry an ATT&CK mapping and falls outside this pipeline's cyber-intelligence scope.

Single-source note: Association des maires de France entry; FrenchBreaches is the originating technical analysis; Clubic's own reporting names FrenchBreaches as its sole source (one assessor, not independent corroboration). What satisfies the single-source carve-out is AMF's own confirmation of the incident (relayed via Clubic) plus the direct primary-sector nexus; verification: single-source, confidence: medium, classification: B2.

Included with reduced confidence: IDScan.net/Nexus entry, only aggregator/press sources available (Krebs on Security, SecurityWeek, BleepingComputer) despite a fair attempt to reach a vendor, research-lab or regulator primary; confidence: medium.

Pre-existing WARN, not fixable by this run: check_run.py's reader-text-internals WARN on 2026-08-15/france-dgfip-tax-authority-credential-intrusion flags the workflow-internal phrase "this pipeline" inside the 2026-08-21 updates[] record's own summary field. That record predates this run and its summary field is part of the append-only changelog record this run has no authority to edit (the entry lifecycle hard rule: "the updates[] records themselves are append-only; they are the audit trail"). This run's own 2026-09-06 record on the same entry carries no such language. Flagging for the next quality audit, which may have latitude this run doesn't to address settled history of this kind.

No watchlists configured (product/supplier watchlists both empty per config/org-profile.yaml); the relevant sweeps were no-ops this run, correctly reported as products_checked=0/suppliers_checked=0 rather than skipped.

← Operations dashboard · run-record contract: docs/pipeline.md