2026-09-08T0411Z-intel
One pipeline fire, in full · intel run of 2026-09-08 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-08/2026-09-08T0411Z-intel.md.
Run telemetry
- Items returned
- 2
- Duration
- 8m 38s
- Tool calls
- 0 WebFetch6 WebSearch24 bridge
- Cited sources
- 3 of 25 in slice
- Items returned
- 3
- Duration
- 14m 43s
- Tool calls
- 2 WebFetch11 WebSearch34 bridge
- Cited sources
- 4 of 29 in slice
- Items returned
- 3
- Duration
- 9m 01s
- Tool calls
- 0 WebFetch8 WebSearch32 bridge
- Cited sources
- 2 of 16 in slice
- Items returned
- 3
- Duration
- 10m 03s
- Tool calls
- 0 WebFetch6 WebSearch26 bridge
- Cited sources
- 2 of 16 in slice
Verification
Deep dive
2026-09-08/stylesmuggler-cve-2026-75650-magento-adobe-commerce-rce
Entries this run published (4) and updated (3)
- CVE-2026-19490, Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed vulnerability high update
- Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida incident high update
- TerminalFix: a ClickFix variant that pastes into Terminal or PowerShell instead of Windows' Run dialog, then chains DLL sideloading, steganographic payload delivery and a custom reverse-tunnel implant threat high update
- CVE-2026-75650 ("StyleSmuggler"), Magento/Adobe Commerce: unauthenticated CVSS 10.0 RCE via template-engine injection, exploited three days before Adobe's hotfix existed vulnerability critical
- Sekoia and Kudelski Security split the 'Lazarus umbrella' into six named DPRK clusters, and document two of them adopting commodity ransomware-as-a-service within two months of each other research notable
- France's Ministry of Ecological Transition confirms a 'sophisticated' attack on mail systems; a criminal separately claims 22,000+ records via an IDOR flaw in its inspection-oversight tool incident notable
- BigBear 2.0, an Evilginx2-based Microsoft 365 phishing-as-a-service panel that JavaScript-disables FIDO2/WebAuthn to force victims onto phishable MFA, leased to at least five affiliates threat high
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
No source-list edits recorded for this run.
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 12 findings (truth=7, editorial=4, advisory=1) · Claude Sonnet 5 · 7m 16s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | NetScaler update said six distinct source IPs; the cited source and this entry's own evidence[] quote say three | corrected to three; retargeted the ongoing-activity claim to Previdian's own tracker (fetched directly, confirms last-observed 2026-09-07) | |
| F3 claim-not-supported | · | continued activity through 2026-09-07 was cited to a 2026-09-04 BleepingComputer article that does not state it | re-cited to Previdian's own page, fetched directly, which states first/last-observed dates | |
| F3 claim-not-supported | · | Field Effect described as independent telemetry; its own post relays BleepingComputer's reporting | reworded to 'separately reported on the same activity' | |
| F4 hallucinated-fact | · | Berlin sourcing_note dated the BSI Mastodon confirmation 2026-09-07; the post itself is dated 2026-09-04 | corrected in the entry and in two registry.yaml records to 'the same day' | |
| F4 hallucinated-fact | · | (low confidence) Berlin incident entry's techniques[] carried mechanism-level ids the entry's own body does not describe | trimmed to T1566/T1657/T1567.002, which the body does describe; full mechanism stays on the sibling campaign entry | |
| F3 claim-not-supported | · | StyleSmuggler's 'a system log' alternate poisoning location was cited to Sansec; it is Disrex's finding, via The Hacker News | re-attributed to The Hacker News/Disrex; fetched the article directly and added further verified Disrex detail (eComscan scope miss, TypeError success tell, the | |
| F4 hallucinated-fact | · | France entry's Lecornu/EUR200M/ANSSI-statistics paragraph cited to the wrong Le Monde Informatique URL (the one about this specific breach), which does not contain these facts | fetched the correct Le Monde Informatique article (Lecornu's 15-day-deadline piece) directly, confirmed every figure, added it as a source, and re-cited the par | |
| F8 needs-more-research | · | StyleSmuggler entry omitted Disrex's independently-confirmed detail available in the cited Hacker News source | added a paragraph on Disrex's independent compromises, the eComscan scope-miss lesson, and the TypeError success indicator | |
| F8 needs-more-research | · | BigBear entry omitted the cited BleepingComputer source's own 258/461-organization compromise counts | added, fetched BleepingComputer directly to confirm | |
| F9 surface-contradiction | · | BigBear: CloudSEK's 'still active' and BleepingComputer's 'offline for nearly three weeks' were not reconciled | fetched BleepingComputer directly; added CloudSEK's own VPS-node-deletion detail and BleepingComputer's panel-vs-infrastructure distinction, reconciling rather | |
| F16 ? | · | (low-moderate confidence) NetScaler update's unchanged priority:high considered against the critical bar given PoC-public + sensor-confirmed traffic + NCSC-NL's imminent-exploitation assessment | declined, the weaponisation event (PoC going public) fell outside this run's window and the vector is auth-bypass, not RCE; priority stays high, noted here for | |
| F14 ? | · | (low confidence, advisory) StyleSmuggler's 'every 2026 security patch' overstated Sansec's 'July and August 2026 patches' | corrected to match the source's own wording |
Iteration #2 NEEDS_FIXES · 6 findings (truth=3, editorial=2, advisory=1) · Claude Sonnet 5 · 9m 35s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | NetScaler update's git diff changed classification.credibility (2→1) and sourcing_note text, neither named in the record's fields: | added classification and sourcing_note to fields: [...]; added one sentence to the record's summary noting the credibility change and why | |
| F3 claim-not-supported | · | Berlin/TerminalFix entries framed the Berlin-specific TerminalFix link as BSI's own explicit Mastodon statement; the post's actual text only states BSI's Berlin-incident involvement plus a link to its | reworded both entries to attribute the specific linkage to heise's reporting on BSI's juxtaposition, not to an explicit BSI statement; also removed residual sel | |
| F5 missing-citation | · | France entry's AMF/Zéro Logement Vacant aside carried no citation | removed the uncited sentence; the entities[] link to the trend entity (which carries its own citation) is sufficient | |
| F14 ? | · | (low confidence) StyleSmuggler called Store A's Magento 2.4.8 install 'fully current'; the cited source never says that | removed the unsupported qualifier, kept the sourced facts (version, Shield-licensed status) | |
| F11 editorial-advisory | · | Run record's published verification notes used workflow-internal shorthand ('sub-agents', 'S1'/'S2'/'S3'/'S4', 'PD-8') | rewrote the whole Verification & coverage notes section in plain language with no internal labels | |
| F17 ? | · | (low-moderate confidence) BigBear's classification.credibility of 1 overstated corroboration; BleepingComputer's account substantially relays CloudSEK's own report rather than independently corroborat | credibility 1→2; added a sourcing_note explaining the single-assessor basis |
Iteration #3 NEEDS_FIXES · 9 findings (truth=5, editorial=2, advisory=2) · Claude Sonnet 5 · 12m 05s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | StyleSmuggler entry's 'statically linked' Rust-binary detail was cited to Sansec, which never uses that phrase; it is Disrex's characterization, relayed by The Hacker News | re-attributed 'stripped and statically linked' to Disrex via The Hacker News citation | |
| F3 claim-not-supported | · | (low confidence) StyleSmuggler's claim that Sansec blocked a 2.4.7-p10 probe 'after the hotfix existed' has the sequence backwards, Sansec's own timeline logs that probe at 17:30 UTC, three hours befo | corrected to state the probe was blocked at 17:30 UTC, less than three hours before the hotfix shipped | |
| F3 claim-not-supported | · | France entry's 'mondial' pseudonym and 2026-09-02 post date were cited to Le Monde Informatique, which never states either fact; both trace to French Breaches, not in the entry's sources[] | added French Breaches as a primary source, fetched directly to confirm; re-cited the pseudonym/date to it and added a matching evidence[] quote | |
| F4 hallucinated-fact | · | NetScaler entry's evidence[] quote 'First observed 03 Sep 2026 · Last observed 07 Sep 2026' attributed to Previdian is a spliced synthesis of two separate label/value pairs, not a contiguous verbatim | replaced with a genuinely contiguous verbatim quote from the page's own JSON-LD (`sensor_telemetry` object) and updated the Previdian source date to 2026-09-08 | |
| F8 needs-more-research | · | NetScaler entry re-fetched Previdian's live dashboard but did not surface its current top-line figures (18 attempts, 9 unique attacker IPs, 5 countries), leaving a stale 3-IP/3-country snapshot as the | re-fetched previdian.com/CVE-2026-19490, confirmed the current figures, and updated the Update section to state them (18 attempts / 9 IPs / 5 countries: AU, DE, | |
| F13 ? | · | (low confidence) DPRK entry's 'The authors read this timing as a pattern rather than coincidence' oversells the source's narrower observation that the two clusters adopted RaaS 'within two months of e | reworded to attribute only the narrower observation to the authors, with the broader reading held as this entry's own inference rather than the authors' stated | |
| F17 ? | · | TerminalFix campaign entry's classification.credibility was left at 2 despite the update record itself stating verification moved single-source to multi-source on the same BSI national-CERT corroborat | credibility 2→1 for consistency with the Berlin entry; added classification to the update record's fields: and a sentence to its summary; sourcing_note cross-re | |
| F11 editorial-advisory | · | Residual self-referential phrasing ('this store has carried' in the NetScaler entry, 'this store follows' in the DPRK entry) | removed both phrases, rewritten in plain third-person description | |
| F11 editorial-advisory | · | (low confidence) StyleSmuggler's regions: [global] did not reflect its NCSC-CH citation and Swiss-constituency closing paragraph | added europe and switzerland to regions[], matching the convention used by other national-CERT-anchored entries |
Iteration #4 NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=0) · Claude Sonnet 5 · 9m 19s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | StyleSmuggler entry's iteration-3 fix moved the defect rather than resolving it: 'Shield blocked a probe... at 17:30 UTC' spliced an untimed Sansec statement about the primary StyleSmuggler actor onto | removed the fabricated timestamp and 'before the hotfix shipped' framing; restated the untimed fact as Sansec's prose actually gives it (Shield blocked a probe | |
| F3 claim-not-supported | · | Berlin entry's Update section opening sentence states BSI's advisory itself says the technique matches 'this compromise' (Berlin); the fetched BSI PDF only ever describes an anonymized 'einer staatlic | reworded the opening sentence to state the advisory describes an anonymized 'state institution' and never names Berlin, leaving the heise-inference sentence tha | |
| F3 claim-not-supported | · | Same defect mirrored in the TerminalFix campaign entry's Update section opening sentence | same fix applied: reworded to state the advisory describes an anonymized 'state institution' and never names Berlin |
Iteration #5 NEEDS_FIXES · 4 findings (truth=2, editorial=0, advisory=2) · Claude Sonnet 5 · 10m 42s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | DPRK entry's 2018-2023 date range was attached to the APT38→CryptoCore/Jade Sleet split; the source attaches that date range to the earlier Lazarus-umbrella→sub-clusters reorganization that produced A | reworded to date the Lazarus-umbrella reorganization (out of which APT38 emerged) to 2018-2023, and state explicitly that the authors do not date the more recen | |
| F4 hallucinated-fact | · | DPRK entry's techniques: [T1657, T1199, T1486] included T1199 (Trusted Relationship), which names no behavior described anywhere in the entry's body | removed T1199; techniques: [T1657, T1486] | |
| F11 editorial-advisory | · | (low confidence) DPRK entry's entities[] carries actor:kimsuky, never named in the body; registry linkage (TEMP.Hermit inherits Lazarus/Kimsuky lineage per the cited source) is plausible but unexplain | added a sourced clause naming Kimsuky and its lineage relationship to the GRIB-affiliated espionage clusters (TEMP.Hermit among them), matching the source's own | |
| F11 editorial-advisory | · | (low confidence) Run record's verification notes use 'stream' language ('the active-threats/vulnerabilities stream...') bordering on workflow-internal framing | declined at iteration 5, reversed at iteration 6 (see below): the cti-verification agent definition's own check 12 explicitly extends the workflow-internal-lang |
Iteration #6 NEEDS_FIXES · 3 findings (truth=2, editorial=0, advisory=1) · Claude Sonnet 5 · 10m 13s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | NetScaler entry's cves[1].epss: 0.00388 (CVE-2026-19489) traced to none of the entry's six cited sources; Previdian's own on-page EPSS figure is for CVE-2026-19490 only | verified the figure is accurate via FIRST.org's own EPSS API (api.first.org/data/v1/epss?cve=CVE-2026-19489 returns epss: 0.00388, date 2026-09-07) and added it | |
| F4 hallucinated-fact | · | (low confidence, registry file) entities/registry.yaml's new trend:france-public-sector-breach-wave-2026 summary cited a single trailing 2026-09-04 Le Monde Informatique reference for a sentence that | restructured the summary so the citation attaches only to the Lecornu-deadline/ANSSI-statistics clause it actually supports, not to the incident list | |
| F11 editorial-advisory | · | (low confidence) Re-raised: iteration 5's declined rebuttal on 'stream' language was itself incorrect, the cti-verification agent definition's check 12 explicitly bans workflow-internal language 'in a | accepted the correction; reworded the Verification & coverage notes section to describe findings by topic (vulnerability-focused coverage, investigative-journal |
Iteration #7 NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=0) · Claude Sonnet 5 · 10m 53s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | BigBear entry mapped T1566.002 (Spearphishing Link) but the body never described any phishing-delivery mechanism (no email/link/lure/delivered anywhere), even though the cited CloudSEK source does des | added a sourced sentence describing the phishing-link/email delivery mechanism (CloudSEK: victims click a phishing link typically delivered via email, proxied t | |
| F3 claim-not-supported | · | (low confidence) StyleSmuggler entry attributed 'Adobe states older versions in those branches are affected too, but the patch is unverified there' to Adobe while citing only Sansec, whose own article | removed the 'Adobe states' framing; reworded to attribute the unverified-patch-status observation to Sansec's own reporting | |
| F13 ? | · | (low confidence) DPRK entry stated FinCEN 'has flagged' Huione Group 'for direct ties to North Korean actors'; the cited Kudelski article's own hedged claim is that Huione's executives 'have shown ind | reworded to separate the two facts: FinCEN's own finding (primary money-laundering concern) and the authors' own hedged claim about Huione executives' indicatio |
Iteration #8 NEEDS_FIXES cap-breach · 3 findings (truth=2, editorial=1, advisory=0) · Claude Sonnet 5 · 11m 56s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F14 ? | · | DPRK entry's frontmatter summary asserted DPRK units 'increasingly rent' ransomware infrastructure; the source documents a single two-cluster timing overlap, and the entry's own body already correctly | reworded the frontmatter summary to match the body's own hedge (a single observed timing overlap the authors call notable, not a claimed trend) | |
| F8 needs-more-research | · | StyleSmuggler entry never named the primary chain's actual delivery vector (a POST /graphql request carrying the malicious styles parameter) or Sansec's own documented interim mitigation (temporarily | added the GraphQL request-path detail to the main analysis, and Sansec's interim GraphQL-disable mitigation (with the headless/PWA-storefront caveat) to immedia | |
| F4 hallucinated-fact | · | (low confidence) France entry's 'filed a criminal complaint' overstated the source's own quoted statement ('Un signalement au parquet a été fait'; a report/referral to the prosecutor), inconsistent wi | reworded 'filed a criminal complaint' to 'filed a report with the public prosecutor' throughout (summary and body), matching the entry's own evidence-quote tran |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-08T0411Z-intel · Sonnet 5 · window 26 h · 4 entries published
Verification & coverage notes
Standard window (gap_hours ≈ 24.0, all research completed within its time budget). Four new entries published, three existing entries updated through their changelog.
Cross-domain merges: the StyleSmuggler/CVE-2026-75650 finding surfaced independently from both vulnerability-focused and investigative-journalism coverage, composed as one entry from both. The same BSI advisory confirming TerminalFix/Rhysida attribution surfaced independently across home-region, research and incident coverage, composed as two update records (one per affected entry: the Berlin Landesnetz incident and the TerminalFix campaign), since this is one source pivoted onto two entries it materially updates, not duplicate research. The France Ministry of Ecological Transition breach surfaced independently from both home-region and incident coverage, composed as one entry.
Store-wide dedup catch (outside the 14-day in-context window): the Citrix NetScaler finding (CVE-2026-19490/CVE-2026-19489) matched an existing entry from 2026-08-20, caught via the store-wide CVE index rather than the 14-day coverage read. Composed as an update record (exploitation-status change: patch-available-only → poc-public + exploited) rather than a new entry.
Deep dive: StyleSmuggler (CVE-2026-75650), category web-app-rce, criterion 1 (active in-the-wild exploitation + non-trivial exposure for any public-sector storefront/ticketing portal on Magento/Adobe Commerce). Category not used in the prior 7 days (last web-app-rce deep dive: 2026-08-29).
Single-source item: the Sekoia/Kudelski Security DPRK six-cluster-split entry is verification: single-source, the two firms co-published identical content the same day, so this is one assessor's own novel clustering framework, not independent corroboration.
Reduced-confidence inclusion: the France Ministry of Ecological Transition entry holds confidence: medium despite multi-source confirmation of the underlying incident (ministry + ANSSI both independently confirmed to AFP), the claimed mechanism (IDOR flaw, specific record counts) is a single uncorroborated criminal claim relayed by French Breaches.
Coverage-backlog work this run (state/coverage_backlog.md): re-checked and unchanged (still blocked), Boston Scientific (no named mechanism), Insel Gruppe/inside-it.ch (whole-host 429 after initial RSS success), Ixa Systems/TheGentlemen, UICC/Krybit, Ville de Libercourt/Kairos (all still bare leak-site claims, no victim confirmation or Admiralty A/B journalism), NovoCure 8-K (confirmed access but no named mechanism). Struck as published-elsewhere: the Rapid7 Ted backdoor/curlRAT item (one of a four-item row) as 2026-09-07/rapid7-ted-backdoor-curlrat-dprk-haproxy, and the Recorded Future H1 2026 Malware and Vulnerability Trends row as 2026-09-07/recordedfuture-h1-2026-tool-stack-reuse, both published by the prior day's fire.
Coverage gaps: ssd-disclosure (fetch_method already blocked, confirmed still unreachable on every transport, 5th consecutive run, a further search corroboration found nothing new); cisa-directives (bridge/reader returned only nav chrome, no listing content); several standard-tier research-lab listing pages returned stale or JS-rendered-empty content with no in-window items (trendmicro-research, yeswehack, hadrian-labs, prodaft, google-tag, intrinsec, cert-lv, mandiant-gtig, sysdig, sentinellabs, volexity, zscaler-threatlabz, proofpoint, jamf-threat-labs, novee-security, dcod-ch, openssf-policy, jpcert, nl-times, safeonweb-be), all reachable (200), genuinely quiet in-window, not transport failures; sans-newsbites and cisa-news not directly attempted this run (cross-checked indirectly via other sources).
Essential-coverage: all essential-tier sources attempted; no misses.
No borderline drops this run, the completeness sweep found every returned item (including the cross-domain-flagged StyleSmuggler item) already accounted for in a disposition above.
← Operations dashboard · run-record contract: docs/pipeline.md