CTIPilot

2026-09-07T0411Z-intel

One pipeline fire, in full · intel run of 2026-09-07 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-07/2026-09-07T0411Z-intel.md.

Run telemetry

2026-09-07T0411Z-intel intel prompt v4.9 publish ok
2h 33m duration 4 published 1 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
12m 04s
Tool calls
3 WebFetch6 WebSearch28 bridge
Cited sources
1 of 24 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
10m 42s
Tool calls
8 WebFetch10 WebSearch20 bridge
Cited sources
1 of 18 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
10m 48s
Tool calls
2 WebFetch10 WebSearch28 bridge
Cited sources
0 of 16 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
7m 34s
Tool calls
0 WebFetch14 WebSearch22 bridge
Cited sources
3 of 17 in slice

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=4 e=2 a=3 #2 NEEDS_FIXES · Sonnet 5 · t=1 e=2 a=1 #3 NEEDS_FIXES · Sonnet 5 · t=4 e=3 a=0 #4 NEEDS_FIXES · Sonnet 5 · t=6 e=3 a=0 #5 NEEDS_FIXES · Sonnet 5 · t=3 e=3 a=1 #6 NEEDS_FIXES · Sonnet 5 · t=2 e=3 a=0 #7 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #8 NEEDS_FIXES · Sonnet 5 · t=1 e=4 a=1

Deep dive

2026-09-07/cve-2026-86206-86207-86218-n-able-n-central-third-chain

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 status: candidate -> active · 1 fetch_method: jina -> blocked.

SourceChangeFrom → ToReason
frenchbreachesstatus: candidate -> activecandidate → activepromotion_due (3 contributing runs per state digest); contributed again this run as primary for the ChimeraZ/Aveyron entry
ssd-disclosurefetch_method: jina -> blockedjina → blockedGenuinely unreachable by every transport including the jina reader for 10+ consecutive runs; documented per the blocked-source rule rather than re-flagged as unsolved every run

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
ssd-disclosurehttps://ssd-disclosure.com/bridge:urlbridge:jinaNone
Cloudflare Robot Challenge Screen returned on both direct bridge fetch and jina reader fallback (S1 and S3 independently); GitHub advisories mirror checked as a
none; genuinely unreachable by every transport this run; fetch_method set to blocked to stop re-flagging as unsolved every run

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 9 findings (truth=4, editorial=2, advisory=3) · Claude Sonnet 5 · 8m 24s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·N-able entry, evidence[].publisher misattributed Jason Murphy's (N-able) own quo
publisher changed to 'Jason Murphy, N-able, via Huntress (Threat Response Unit)' on both quotes
F4
hallucinated-fact
·N-able entry; CVE-2026-86206 cvss stated 'n/a' and sourcing_note claimed no publ
cvss set to 6.9; sourcing_note corrected; the OffSeq CVE-2026-86206 record added to sources[]
F4
hallucinated-fact
·N-able entry title asserted 'confirmed-exploited' for CVE-2026-86218 despite the
title reworded to 'a pre-auth CVSS 10.0 zero-day N-able says is already exploited', attributed to the vendor rather than asserted as independently confirmed
F4
hallucinated-fact
·Berlin update record's fields list omitted updated_at despite it changing this r
added updated_at to the record's fields list
F5
missing-citation
·N-able entry sourcing_note cited an OffSeq CVSS claim with no corresponding sour
the OffSeq CVE-2026-86206 record added to sources[] (same fix as the F4 CVSS finding)
F10
missed-angle
·Recorded Future entry links campaign:strikeshark-sharkloader with no references[
added references[] entry and a body clause cross-referencing the prior Kaspersky StrikeShark coverage
F11
editorial-advisory
·Run record notes used the workflow-internal term 'sub-agents'
reworded to 'research workers', matching established house style in prior run records
F11
editorial-advisory
·Recorded Future entry's affected_products[] omitted GeoServer and Apache Shiro,
both added to affected_products[]
F11
editorial-advisory
·Stylistic suggestion to use the store's bolded Contradiction: line convention fo
left as prose; both contradictions are already transparently surfaced and attributed; not a defect per the verifier's own note

Iteration #2 NEEDS_FIXES · 4 findings (truth=1, editorial=2, advisory=1) · Claude Sonnet 5 · 8m 14s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·N-able entry, CVE-2026-86207's fixed field carried '/ 2026.4', a fix-version cla
fixed field for CVE-2026-86207 corrected to '2026.3.1.13 (HF3)' only
F9
surface-contradiction
·N-able HF3 blog describes both CVE-2026-86206/86207 jointly as 'high-CVSS-rated'
sourcing_note extended with a one-clause note stating the entry follows the per-CVE CNA score over the vendor blog's joint characterization
F17
classification
·ChimeraZ entry's classification.reliability: C sits below co-primary source fren
sourcing_note extended with a one-clause rationale: the blended sourcing for this specific contested-mechanism item is weaker than frenchbreaches' general track
F11
editorial-advisory
·Rapid7 entry does not carry The Hacker News' own disambiguation of curlRAT from
added a parenthetical disambiguation clause at curlRAT's first mention in the body

Iteration #3 NEEDS_FIXES · 7 findings (truth=4, editorial=3, advisory=0) · Claude Sonnet 5 · 10m 33s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·N-able entry, sources[]/evidence[] labelled Huntress '(Threat Response Unit)', a
'(Threat Response Unit)' removed everywhere; publisher fields now read plain 'Huntress' / 'Jason Murphy, N-able, via Huntress'
F5
missing-citation
·Recorded Future entry, only the first body sentence carried an inline citation;
inline citations to the Recorded Future primary added at each remaining clause carrying a specific figure, throughout paragraphs 2-3
F5
missing-citation
·Recorded Future entry's SharkLoader/'Perfect DLL Hijacking' clause was sourced o
added the Kaspersky Securelist StrikeShark article to sources[] (corroborating) and an inline citation to it at that clause
F14
quantifier-without-source
·ChimeraZ entry claimed ChimeraZ specifically was tied to 'five ... SDIS hit in J
reworded to state ChimeraZ is tied by name to five of seven SDIS in the August wave, with the July wave described accurately as a collective three-handle attrib
F9
surface-contradiction
·Berlin entry's existing sourcing_note claims a 'three-source consensus' disclosu
added a reconciling paragraph to this run's update section: 2026-08-14 was the internal containment/isolation date, 2026-08-17 was the Senate chancellery's publ
F3
claim-not-supported
·ChimeraZ entry title said 'a partner account without MFA'; FrenchBreaches' own t
title reworded to 'a customer account without MFA', matching the body's existing hedge and the source's own wording
F3
claim-not-supported
·N-able entry stated the compromised customer's server was 'already patched to th
reworded to 'a customer's fully patched N-central production server', matching Huntress's own wording without the unstated HF2 inference

Iteration #4 NEEDS_FIXES · 9 findings (truth=6, editorial=3, advisory=0) · Claude Sonnet 5 · 9m 31s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·N-able entry cited N-able Status (vendor blog) for CVE-2026-86206/86207's specif
added a per-CVE OffSeq citation at each specific technical-description clause, alongside the existing N-able Status citation for the shared hotfix-shipment fact
F3
claim-not-supported
·ChimeraZ entry's body/summary still said 'partner or customer account' / 'partne
all remaining 'partner' references to the specific compromised-account claim changed to 'customer account' throughout summary and body (the Defender takeaway's
F3
claim-not-supported
·Recorded Future entry's SharkLoader clause said Kaspersky profiled it 'against g
reworded to state the campaign's confirmed victims spanned government/diplomatic entities, software developers and organizations in several other sectors and re
F3
claim-not-supported
·Recorded Future entry's Kaspersky Securelist source record carried date 2026-06-
sources[] date corrected to 2026-06-24; the inline citation date updated to match
F4
hallucinated-fact
·Berlin entry, iteration 3's F9 fix added a reconciling paragraph (08-14=containm
main analysis's opening sentence rewritten to state the containment/isolation fact (2026-08-14) and the Senate's public press disclosure (2026-08-17) directly,
F5
missing-citation
·Rapid7 entry; the claim that a recompiled HAProxy binary still reports the same
added an inline citation to The Hacker News, which states this fact
F5
missing-citation
·N-able entry, the CVE-2026-86218 sentence naming CWE-96/static-code-injection ca
added an inline citation to the OffSeq CVE-2026-86218 CNA record at that sentence
F5
missing-citation
·Recorded Future entry, iteration 3's citation pass missed one figure-heavy sente
added the missing inline citation to that sentence
F14
quantifier-without-source
·ChimeraZ entry title said 'exposing 20,000+ job candidates' CVs' (low confidence
title reworded to 'exposing 20,000+ people's data including 1,499 CVs', separating the two counts (the headline and summary already made this distinction correc

Iteration #5 NEEDS_FIXES · 7 findings (truth=3, editorial=3, advisory=1) · Claude Sonnet 5 · 10m 09s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·Berlin entry, iterations 3/4's date reconciliation ('isolation 08-14, disclosure
re-fetched all three primaries (Security Affairs, Berliner Zeitung, Der Tagesspiegel) plus the heise retrospective and confirmed the genuine, unresolved cross-s
F4
hallucinated-fact
·Rapid7 entry maps T1497.001 (virtualization/sandbox evasion) in techniques[] wit
added a clause to the watchdog-thread sentence describing the anti-analysis virtualization check (generically, no file path/IOC) that the mapped technique names
F4
hallucinated-fact
·entities/registry.yaml's pre-existing summary for campaign:strikeshark-sharkload
registry summary rewritten to match the corrected, source-accurate targeting characterization
F11
editorial-advisory
·Recorded Future entry's techniques[] carried 5 ids (T1082, T1005, T1105, T1071.0
added one dense clause naming the corresponding behaviors (system-information discovery, local-system data collection, tool transfer, C2/exfiltration channel) i
F5
missing-citation
·Berlin entry's 2026-09-07 update section, the clause attributing a financial-mot
added a second, clause-adjacent citation to the same heise/BSI source at that specific sentence
F5
missing-citation
·N-able entry's absence claim ('no public proof-of-concept... has been published'
reworded to 'no source cited in this entry describes a public proof-of-concept', scoping the absence claim to what the entry's own sources do and do not state r
F17
classification
·N-able entry's classification.credibility: 1 may overstate confidence given the
credibility changed to 2; sourcing_note extended with a one-clause rationale distinguishing the solidly multi-source-corroborated surrounding facts from the ven

Iteration #6 NEEDS_FIXES · 5 findings (truth=2, editorial=3, advisory=0) · Claude Sonnet 5 · 10m 25s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F5
missing-citation
·Rapid7 entry's curlRAT/stager/sshd paragraph carried zero inline citations despi
added inline Rapid7 citations at each sentence throughout the paragraph
F5
missing-citation
·Rapid7 entry's initial-access-hypothesis/attribution-reasoning paragraph carried
added inline Rapid7 citations to both sentences
F9
surface-contradiction
·Berlin entry, this run's own heise 09-06 source dates full network reconnection
added a Contradiction line to the 2026-09-07 update section disclosing the one-day reconnection-date gap between the two sources
F3
claim-not-supported
·Berlin entry stated Der Tagesspiegel AND Berliner Zeitung both explicitly date t
reworded to state Der Tagesspiegel explicitly dates the disconnection to 08-14, while Berliner Zeitung independently dates the attack becoming publicly known to
F4
hallucinated-fact
·N-able entry presented 'has been exploited in the wild' as a phrase N-able's own
reworded to attribute the 'conveys...exploited in the wild' characterization to Huntress's report rather than presenting it as an independently-verified verbati

Iteration #7 NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 8m 07s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·CVE-2026-86206 / CVE-2026-86207 / CVE-2026-86218, N-able N-central: a third, unr
reworded all three instances ('engineer Jason Murphy', immediate_action's 'a company engineer', and 'the engineer's on-record statement') to neutral 'N-able's J
F3
claim-not-supported
·Berlin entry, 'two independent German-language outlets' claim (Der Tagesspiegel
re-fetched rbb24's own article, confirmed it explicitly states disconnection on 14 August, and added it as a second inline citation alongside Der Tagesspiegel i

Iteration #8 NEEDS_FIXES cap-breach · 6 findings (truth=1, editorial=4, advisory=1) · Claude Sonnet 5 · 11m 01s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·CVE-2026-86207's cves[] auth field said pre-auth, but its own cited CNA record (
corrected CVE-2026-86207's auth field to post-auth and added a sourcing_note clause disclosing the CNA vector's AT:P/PR:L reading distinct from its two pre-auth
F5
missing-citation
·N-able entry's 'Across both the August and September chains...force multiplier'
added inline Huntress citations to the privilege-level and capability-list sentences
F5
missing-citation
·ChimeraZ entry's exposed-field list and profile-freshness sentences carried no i
added inline FrenchBreaches citation to the exposed-field-list sentence and Cyberattaque.org citation to the profile-freshness sentence
F5
missing-citation
·(low confidence) Berlin entry's 2026-09-07 update BSI paragraph: the targeted-ph
added inline heise online citations to both clauses for consistency with the paragraph's other cited clause
F8
needs-more-research
·(low confidence) N-able entry's Triage note blended the August chain's 'MSP Supp
reworded the Triage note to scope the API/log-anomaly discriminator to the September chain this entry covers and the Take Control discriminator explicitly to th
F11
editorial-advisory
·Rapid7 entry's techniques[] included T1102 and T1568 (backup-C2 failover; hashed
added one clause describing curlRAT's secondary-C2 fallback and its host-derived victim-tracking-identifier hash, generically and without naming the actual C2 h

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-07T0411Z-intel · Sonnet 5 · window 24 h · 4 entries published

Verification & coverage notes

A standard-cadence fire (gap_hours ≈ 15, window_hours = 24; no catch-up disclosure required). Four new entries published, one existing entry updated through its changelog.

New entries:

  • 2026-09-07/cve-2026-86206-86207-86218-n-able-n-central-third-chain (priority: critical, this run's deep dive, category identity-infra), a third, unrelated N-able N-central auth-bypass/RCE chain in five weeks; CVE-2026-86218 confirmed exploited per N-able's own Active Incident dashboard and an on-record staff quote, though the vendor's own HF4 release notes carry a conflicting hedge (both statements carried, weighted per the entry's sourcing_note). References the existing 2026-08-03/cve-2026-18577-n-able-n-central-auth-bypass-exploited entry (distinct CVEs, same product).
  • 2026-09-07/rapid7-ted-backdoor-curlrat-dprk-haproxy (priority: notable), coverage-backlog recovery (row surfaced by the 2026-09-06T1308Z audit, exempt from the recency gate per its own header): a DPRK-nexus actor compiles a custom C2 filter into a victim's own HAProxy source tree. Attribution carried as three only-partially-reconciled evidentiary threads (APT37/C2 infra, Lazarus/delivery model, Kimsuky/initial-access hypothesis) rather than a single confirmed cluster, per the source's own caveat.
  • 2026-09-07/recordedfuture-h1-2026-tool-stack-reuse (kind: annual-report, priority: notable), PD-9 periodic-report treatment; another coverage-backlog composition item (row surfaced 2026-09-06T1308Z-audit), composed narrowly around the genuinely actionable tool-stack-reuse-across-CVEs finding rather than the report's vanity-metric headline figures.
  • 2026-09-07/chimeraz-aveyron-onrecrute-breach (priority: notable), French departmental (Aveyron) employment-platform breach, actor already tracked for the SDIS fire-and-rescue campaign; genuinely distinct victim type, so a new entry referencing the SDIS entry rather than an update. Access-vector claim single-sourced to one of two independent reviewers and explicitly contradicted by the second; both accounts held and attributed.

Update: 2026-08-30/berlin-landesnetz-rhysida-extortion-phishing-vector, type: update (floats). Full leak scope confirmed to include CI/defense-industrial records (heating/power plants, fuel depots, substations, prisons, Bundeswehr-related material); BSI public warning of elevated phishing and hack-and-leak risk ahead of Berlin's 20 September election; new BSI/BKA/BfV coordination unit and citizen-notification process; an independent expert's "gross negligence" accusation.

Dropped: German homemade-wire-slinging substation sabotage (S2), borderline-drop: physical/kinetic sabotage against German HV substations — no cyber intrusion, no digital access vector, no ATT&CK mapping possible; unlike the BACS-covered Poland grid sabotage (named cyber actor, Static Tundra, and attack infrastructure), no actor or cyber angle is stated here, so it cannot carry the evidence-bound techniques[] mapping check_run.py requires on an incident/threat entry. Out of scope for a cyber-CTI pipeline.

Coverage-backlog dispositions (all six re-checked rows: no change):

  • Boston Scientific incident (2026-08-25), still no attacker attribution/vector/mechanism from any party.
  • TheGentlemen/Ixa Systems SA listing, still only the original ransomware.live listing, no victim statement or Swiss press pickup.
  • Krybit/UICC listing, still only leak-site trackers repeat the claim.
  • Kairos/Ville de Libercourt listing, still no commune statement.
  • NovoCure incident (2026-09-01), still no attacker attribution/vector/mechanism.
  • VMSA-2026-0007/CVE-2026-59346, confirmed scoped to VMware Workstation/Fusion only (no ESXi row), no exploitation reports found; does not clear the recovery bar.

Backlog row struck: AA26-231A Siemens S7 joint-advisory re-read, S1 re-fetched the full PDF; prior updates already captured essentially all quotable substance; the only new detail (ICS-only MITRE ATT&CK for ICS ids T0834/T1694) is not mappable onto the Enterprise-only pinned dataset, so no changelog action follows. No further action needed.

Backlog row opened: ShinyHunters lists Medela AG (Baar, Zug) on its leak site (discovered <3h before this run), bare, uncorroborated claim whose own scope numbers read like a surface-scan result rather than confirmed data theft; fails PD-6 as it stands. Stated deadline 2026-09-08 makes a press pickup or statement plausible within 1-2 fires.

Backlog rows not addressed this run (no tasking): the Zurich District Court verdict row (correctly skipped, not due until 2026-09-10); the Keycloak-entry meta-fact correction (low priority); the Spring Ring Teams-vishing/NTLM-relay watch item; three of the four PD-11(d) research items held below the recovery bar (AWS root-password-spray, Exodus wallet installer, JSCeal deobfuscation); only the Ted backdoor/curlRAT portion of that bundled row was actioned this run.

Candidate sources: two research workers (S1, S4) each independently proposed a "new" candidate source (huntress-blog, cyberattaque-org); both were already tracked in sources/sources.json under existing ids (huntress, cyberattaque-org, the latter active since 2026-08-02); no duplicate added, so this run's one-new-candidate-source slot was not consumed.

Source lifecycle: frenchbreaches promoted candidate → active (promotion_due, 3 contributing runs). ssd-disclosure set to fetch_method: blocked after 10+ consecutive runs unreachable by every transport including the jina reader (confirmed independently by S1 and S3 this run); source_health.py's full 186-source sweep this run reported zero UNSOLVED sources.

Coverage gaps: cisa-directives (JS-shell listing shell persists, 6th+ consecutive occurrence, a recipe gap, not an anti-bot block; needs a structured-feed/API recipe on a future run); inside-it-ch (the Insel Gruppe/ServiceNow-migration backlog article now blocked even via the jina reader for the first time, worse than the prior subscriber-paywall condition, no corroborating outlet found on any transport).

← Operations dashboard · run-record contract: docs/pipeline.md