CTIPilot

2026-09-10T0410Z-intel

One pipeline fire, in full · intel run of 2026-09-10 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-10/2026-09-10T0410Z-intel.md.

Run telemetry

2026-09-10T0410Z-intel intel prompt v4.9 publish ok
2h 25m duration 5 published 5 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
5
Duration
11m 24s
Tool calls
6 WebFetch11 WebSearch26 bridge
Cited sources
6 of 25 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
9m 04s
Tool calls
6 WebFetch17 WebSearch14 bridge
Cited sources
1 of 29 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
11m 57s
Tool calls
4 WebFetch14 WebSearch28 bridge
Cited sources
3 of 14 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
7m 56s
Tool calls
10 WebFetch18 WebSearch16 bridge
Cited sources
3 of 18 in slice

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=4 e=2 a=1 #2 NEEDS_FIXES · Sonnet 5 · t=3 e=1 a=0 #3 NEEDS_FIXES · Sonnet 5 · t=3 e=4 a=4 #4 NEEDS_FIXES · Sonnet 5 · t=1 e=1 a=2 #5 NEEDS_FIXES · Sonnet 5 · t=2 e=1 a=3 #6 NEEDS_FIXES · Sonnet 5 · t=1 e=0 a=2 #7 NEEDS_FIXES · Sonnet 5 · t=3 e=0 a=1 #8 NEEDS_FIXES · Sonnet 5 · t=1 e=1 a=2

Deep dive

·

Entries this run published (5) and updated (5)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 fetch_method.

SourceChangeFrom → ToReason
ssd-disclosurefetch_methodblocked → jinaconfirmed reachable via jina fallback by both S1 and S3 this run

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
fortiguard-fortinet-psirt
covered via alternate · should NOT be in this list
https://fortiguard.fortinet.com/psirt/FG-IR-25-084extracturljinaNone anti-bot-block
direct anti-bot challenge; trafilatura returned no readable body; jina reader relayed an upstream block
corroborated fixed-version data via SentinelOne and SOCRadar's own citations of the advisory
tp-link-omada-psirthttps://support.omadanetworks.com/us/security-advisory/bridge404 url-moved
Nuxt app 'page404' response; URL appears to have moved or been retired
flagged in sources.json notes for a future canonical-URL probe; no replacement found this run

Bridge invocations (this run)

2 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

2 other
  • bridge ×1
  • jina ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 7 findings (truth=4, editorial=2, advisory=1) · Claude Sonnet 5 · 9m 31s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat
epss 0.76 was ENISA EUVD's percentage-scaled value copied unconverted; FIRST.org's own API gives 0.00759.corrected epss to 0.0076
F4
hallucinated-fact
·cve-2026-87491-chrome-v8-oob-write-seventh-2026-zero-day
epss 0.29 was the same ENISA percentage-vs-decimal conflation; FIRST.org gives 0.00291.corrected epss to 0.0029
F4
hallucinated-fact
·entities/registry.yaml tool:hardbreacher (low confidence)
curated summary asserted an unsourced specific patch date (2026-08-31) neither cited source states.removed the specific date; summary now states Kaspersky's actual fix mechanism (automatic/manual database update) per the sources
F3
claim-not-supported
·bluemoon-exploit-kit-four-state-actors-chrome-windows-chain
cves[CVE-2026-85880].affected omitted Windows 11 21H2 (build 22000), which Proofpoint's own cited table lists as a targeted build; also inconsistent with the referenced 2026-09-09 entry's Microsoft-socorrected the affected field to Proofpoint's own build table, added a body Contradiction note and a sourcing_note clause flagging (not resolving) the discrepanc
F5
missing-citation
·cve-2026-87491-chrome-v8-oob-write-seventh-2026-zero-day
the ENISA EUVD CVSS 8.8 claim had no inline link and ENISA was not in sources[].added ENISA EUVD to sources[] and an inline citation
F17
classification
·cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat (low confidence)
credibility 1 was an outlier, the entry's single-assessor (SOCRadar-only) exploitation narrative matches the pattern this run's other entries (SAP, Check Point, BlueMoon) all rated credibility 2.corrected credibility to 2; sourcing_note updated to state the single-assessor basis
F11
editorial-advisory
·checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (low confidence)
Forkast News (corroborating role) reads as formulaic aggregator content across unrelated CVEs; facts verified correct.none, advisory only, role is corroborating and the two Check Point vendor advisories are the solid primaries

Iteration #2 NEEDS_FIXES · 4 findings (truth=3, editorial=1, advisory=0) · Claude Sonnet 5 · 8m 24s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat (low confidence)
sourcing_note claimed SOCRadar's 9.8 matched neither NVD nor GHSA, but NVD's own analyst score is in fact 9.8 (matching SOCRadar), only the CNA/GHSA score is 8.1.corrected sourcing_note to state all three scores accurately: NVD 9.8, CNA/GHSA 8.1, ENISA EUVD 7.4
F4
hallucinated-fact
·cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat
T1055 mapped in techniques[] with no process-injection behavior described in the body, though SOCRadar's own report and ATT&CK table document one (run.ps1 -> OpenProcess/VirtualAllocEx/WriteProcessMemnarrowed T1055 to the source-mapped T1055.002, added T1059.001, and extended the body's pivoting sentence to describe the run.ps1/svchost.exe injection with an
F5
missing-citation
·cve-2026-87491-chrome-v8-oob-write-seventh-2026-zero-day
the CISA KEV due-date clause had no inline citation and CISA was absent from sources[].added the CISA alert URL (the same 2026-09-09 four-addition alert already used in the Fortinet entry, since this CVE was one of the four) to sources[] and cited
F11
editorial-advisory
·2026-08-30/berlin-landesnetz-rhysida-extortion-phishing-vector
three sources[] entries added this run (rbb24, Berlin DPA, and (found on re-inspection) the heise Kommentar) were never used as an inline citation target anywhere in the body; only the main heise artiremoved all three uncited source records, keeping only the inline-cited heise article

Iteration #3 NEEDS_FIXES · 10 findings (truth=3, editorial=4, advisory=4) · Claude Sonnet 5 · 9m 33s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·cve-2026-87491-chrome-v8-oob-write-seventh-2026-zero-day
iteration 2's own fix cited the CISA alert page for the KEV due date, but that page states no due date at all, only the four added CVE names and BOD 26-04 boilerplate.added the CISA KEV JSON feed (a per-CVE-queryable data endpoint) as a second source and re-pointed the due-date citation to it; confirmed the 2026-09-23 due dat
F3
claim-not-supported
·2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce (low confidence
GreyNoise's own text says domain admin was reached against '12 victim organizations', not '12 of the 440 instances' as the update section said.corrected the denominator to the 395 compromised organizations, matching GreyNoise's own wording
F4
hallucinated-fact
·sap-september-2026-overpass-s4get-preauth-rce (low-moderate confidence)
CERT-EU's advisory lists KRNL64NUC only at 7.22/7.22EXT (not 7.53/8.04); only KRNL64UC extends to 7.53/8.04. The entry's condensed notation had merged the two into one range, overstating KRNL64NUC's asplit the affected field into the four component lines exactly as CERT-EU's advisory states them
F9
surface-contradiction
·cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat
GHSA states FortiSASE 25.1.a.2/25.2.b; SentinelOne (also cited as corroborating) independently states FortiSASE 25.1.39/25.1.51, a different version-naming scheme for the same product, carried silentladded an explicit Contradiction clause to sourcing_note disclosing both version accounts rather than silently following one
F10
missed-angle
·whole-run, entries/2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-h
the same 2026-09-09 CISA alert cited twice this run for other CVEs also added CVE-2026-20079 (Cisco FMC) and CVE-2026-19490 (Citrix NetScaler) to KEV; both already-covered CVEs whose existing entries CVE-2026-20079 (previously patch-available-only, Cisco reporting no known malicious use): added a type:update record; this is a material exploitation-status cha
F17
classification
·cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat
reliability B overstated the source basis, the substantive narrative rests solely on SOCRadar, which sources.json itself rates reliability C; CISA (A) supports only the KEV-addition fact, not the campcorrected reliability to C to match SOCRadar's own rated reliability
F5
missing-citation
·cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat
the ENISA EUVD 7.4 temporal-score claim in sourcing_note had no citation and ENISA was not in sources[].added ENISA EUVD to sources[]
F11
editorial-advisory
·cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat (low confidence, x2)
T1555 (Credentials from Password Stores) had no distinct supporting behavior beyond the already-present T1552.001; separately, the body's XOR-decryption detail (T1027, Obfuscated Files or Information)removed T1555, added T1027
F11
editorial-advisory
·checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (carried forward from iteration 1
Forkast News re-confirmed as formulaic aggregator content; facts still check out.none, advisory only, role remains corroborating
F11
editorial-advisory
·2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops (low confid
HardBreacher's session-namespace symlink DLL-load-path redirect may fit T1574.008 better than the mapped T1574.001; verifier itself flagged this as uncertain.declined; the verifier's own finding was explicitly low-confidence and uncertain between two imperfect-fit sub-techniques, and T1574.001 (DLL search-order/path

Iteration #4 NEEDS_FIXES · 4 findings (truth=1, editorial=1, advisory=2) · Claude Sonnet 5 · 9m 42s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·bluemoon-exploit-kit-four-state-actors-chrome-windows-chain entities[] tool:ghos
'GhostChrome' only appears inside a Proofpoint hyperlink's URL slug pointing to Rubrik Zero Labs' own blog (uncited in this entry's sources[]); Proofpoint's own visible text never names the technique,removed tool:ghostchrome-x from the entry's entities[], from entities_added in the run record, and retired the registry entity entirely; reworded the tool:gemst
F6
strengthen-primary-source
·sap-september-2026-overpass-s4get-preauth-rce (low confidence)
CERT-EU was listed first with role:primary though the entry's own sourcing_note says it only relays SAP/Onapsis's findings; the two genuine Onapsis research-lab primaries sat later in the list.reordered sources[] so the two Onapsis primaries lead; CERT-EU moved to role:corroborating
F11
editorial-advisory
·checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (carried forward)
Forkast News independently re-confirmed as aggregator content; facts still check out.none, advisory only
F11
editorial-advisory
·2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops (carried fo
T1574.001 vs T1574.008 uncertainty for HardBreacher re-confirmed as a genuine imperfect-fit case.none, advisory only, concurs with iteration 3's decline

Iteration #5 NEEDS_FIXES · 6 findings (truth=2, editorial=1, advisory=3) · Claude Sonnet 5 · 6m 43s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix
the main-analysis paragraph still asserted, present-tense, 'Cisco states it is not aware of any public announcements or malicious use' (unedited by this run's own update despite the record declaring fedited the stale sentence in place to state Cisco's original position in the past tense and point to the KEV confirmation, resolving the contradiction between t
F3
claim-not-supported
·2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops (+ registry
body, changelog summary, and registry all claimed CrowdStrike's cloud ML detection catches the FalconFlank artifact 'in default configurations' / 'default test conditions', LevelBlue's cited post nevereworded all three locations (body, changelog record summary, registry summary) to state LevelBlue's own lab testing observed the detection catch and quarantine
F5
missing-citation
·sap-september-2026-overpass-s4get-preauth-rce
the RECON/CVE-2020-6287/CVE-2025-31324 historical-precedent sentence had no inline citation, though its content matches Onapsis's own already-cited OVERPASS post almost verbatim.added an inline citation to the Onapsis OVERPASS post at the end of the sentence
F11
editorial-advisory
·2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops (low confid
questioned whether the 2026-09-10 changelog record should have been typed improvement (no float) rather than update (floats updated_at), since its content is independent confirmation + deeper mechanisdeclined, the record's substance (a second independent lab confirming the findings with materially deeper, actionable detection guidance) is treated as a genuin
F11
editorial-advisory
·checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (carried forward, reconfirmed)
Forkast News re-fetched and re-confirmed as aggregator content; quote still checks out, role remains corroborating.none, advisory only
F11
editorial-advisory
·2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops (carried fo
T1574.001 vs T1574.008 mapping for HardBreacher re-confirmed as a genuine imperfect-fit case.none, advisory only, concurs with prior iterations' decline

Iteration #6 NEEDS_FIXES · 3 findings (truth=1, editorial=0, advisory=2) · Claude Sonnet 5 · 8m 25s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops
LevelBlue's own 'Key Takeaways' section (already cited by this run's update) states both PrettyPrague and FalconFlank had already received vendor remediation as of 2026-09-09 ('prior to remediation' /updated title, headline, summary, tags (no-patch -> patch-available), body (three sentences reframed to past-tense-at-disclosure plus a forward pointer to the u
F11
editorial-advisory
·checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (carried forward, reconfirmed 4th
Forkast News re-confirmed as aggregator content; new observation that it is entirely unregistered in sources/sources.json and this is its first-ever use in the store.none, advisory only; not promoted to a tracked source given the repeated aggregator-content characterization
F11
editorial-advisory
·bluemoon-exploit-kit-four-state-actors-chrome-windows-chain (reopens iteration 4
low-confidence note that iteration 4's removal of tool:ghostchrome-x may have rested on an incomplete source check: The Hacker News (already cited in this entry's sources[]) names 'GhostChrome-X' direverified directly against the cited Hacker News article, confirmed it names 'GhostChrome-X' in visible text, properly attributed and linked. Restored tool:ghost

Iteration #7 NEEDS_FIXES · 4 findings (truth=3, editorial=0, advisory=1) · Claude Sonnet 5 · 5m 56s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·2026-09-06/chaotic-eclipse-falconflank-prettyprague-edr-av-lpe-drops
the entry's own already-cited primary (The Hacker News) states, in an Update section, an exact named Avast fix (26.7.11086 fix 992 / 26.8.11125 fix 993, released 2026-09-04), but the entry's summary, rewrote the summary, Defender takeaway, and update-section text to state the named Avast fix versions and date precisely, distinguishing that CrowdStrike/Falcon
F4
hallucinated-fact
·2026-09-10/bluemoon-exploit-kit-four-state-actors-chrome-windows-chain
actions[] and the Defender takeaway both said 'Chrome ≥153', that is this run's other new entry's (CVE-2026-87491) fix version, not this entry's own CVE-2026-85046 fix version (Chrome 152.0.7977.82/.8corrected both instances to 'Chrome ≥152.0.7977.82', matching this entry's own frontmatter.
F4
hallucinated-fact
·entities/registry.yaml tool:prettyprague
registry summary still said 'remediation in development by Gen Digital,' stale relative to the entry it's drawn from now that the entry records a named, shipped Avast fix.updated the registry summary to state the shipped fix versions and date, citing The Hacker News.
F11
editorial-advisory
·checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (carried forward, reconfirmed 5th
Forkast News re-confirmed as formulaic aggregator content; quoted fact still verbatim-correct.none, advisory only, role remains corroborating behind two solid Check Point vendor primaries

Iteration #8 NEEDS_FIXES cap-breach · 4 findings (truth=1, editorial=1, advisory=2) · Claude Sonnet 5 · 7m 25s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·2026-09-10/bluemoon-exploit-kit-four-state-actors-chrome-windows-chain
the body attached 'is MSRC-confirmed exploited' to The Hacker News citation, but that article states only that the CVE was patched in September Patch Tuesday; it never uses 'MSRC' or states MSRC confireworded the clause to state only what the Hacker News citation supports (patched in September Patch Tuesday) and attributed the MSRC exploited-in-the-wild conf
F5
missing-citation
·2026-08-20/cve-2026-19490-netscaler-gateway-aaa-auth-bypass
cves[CVE-2026-19490].epss: 0.0337 had no supporting source in sources[], the entry's only FIRST.org EPSS citation is scoped to CVE-2026-19489. Figure independently re-verified correct against FIRST.oradded a FIRST.org EPSS source entry scoped to CVE-2026-19490, folded into this run's existing 2026-09-10 correction record (fields[] extended to include sources
F11
editorial-advisory
·cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat
the SentinelOne CVE-database page used as a corroborating source for the FortiSASE version contradiction carries an explicit AI-generated-content disclaimer and is a different site section from the renone, advisory only, facts independently reconfirmed correct
F11
editorial-advisory
·checkpoint-quantum-vpn-cert-preauth-rce-cvss98 (carried forward, reconfirmed 6th
Forkast News re-confirmed as formulaic aggregator content; quoted fact still verbatim-correct.none, advisory only, role remains corroborating behind two solid Check Point vendor primaries

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-10T0410Z-intel · Sonnet 5 · window 24 h · 5 entries published

Verification & coverage notes

Intraday fire (gap_hours 10.72, window_hours 24 floor). Mechanical KEV sweep (tools/kev_window_diff.py) flagged 2 not-yet-covered CISA KEV additions in-window (CVE-2025-25249 Fortinet, CVE-2026-87491 Chrome); both fully researched and published as new entries. 5 new entries, 3 changelog updates.

  • borderline-drop: Veradigm (formerly Allscripts) vendor-API credential breach, US-domiciled healthcare-technology vendor, disputed scale (victim's own SEC 8-K says "a small number of customers" against the actor's claimed 3.5M records); the actor (actor:thegentlemen) carries an established European leak-site pattern and an uncorroborated current Swiss claim (Ixa Systems SA, tracked in coverage_backlog.md), but neither that actor-nexus argument nor the vendor-API-scoping lesson (standard practice, not a novel TTP) clears the stricter out-of-nexus breach gate on their own. Relevance-doubt resolves toward drop (v4.2).
  • borderline-drop: Mantax Otax, Indonesian consumer Android ransomware/spyware hybrid (Zimperium zLabs, single-source). No Swiss/EU/public-sector nexus; the constituency's device fleets are MDM-managed, making a sideload-only consumer-Android technique class a poor transferability fit. Does not clear PD-11(d).
  • Coverage backlog (state/coverage_backlog.md) worked this run: Boston Scientific struck (operationally concluded, "fully restored," no mechanism ever disclosed across 10 checks over two weeks); Zurich verdict, inside-it.ch Insel Gruppe, Ixa Systems SA, UICC (Krybit), Kairos/Ville de Libercourt, VMware VMSA-2026-0007, and the Spring Ring NTLM-relay row all re-checked with no change; dated notes appended to each. Three new backlog rows opened: Medela AG (ShinyHunters claim, Swiss home-region, uncorroborated), reichenau.at (SafePay claim, Austrian municipality, uncorroborated), and Ville du Tampon (France, victim-confirmed incident, no mechanism disclosed).
  • Dedup: 2026-09-10/bluemoon-exploit-kit-four-state-actors-chrome-windows-chain shares CVE-2026-85046 with 2026-09-04/cve-2026-85046-chrome-v8-type-confusion-exploited and CVE-2026-85880 with 2026-09-09/windows-september-2026-two-exploited-lpe-zero-days-kev, both declared in references[] as a genuinely distinct finding (a named exploit kit + four actor clusters) building on the covered CVEs, not a duplicate.
  • Watchlist: no watchlists configured (documented no-op on all four domains).
  • Essential-coverage: cisa-advisories 403'd for a 2nd consecutive run (transport block, never demotes; tools/fetch_source.py bridge already in use).
  • Coverage gaps: ccb-belgium (fetched, advisory list not confirmed present/absent); reliaquest, group-ib, ibm-xforce (all reached, newest content outside the 24h window); ransom-isac, venarix, zaufana-trzecia-strona, cyberinsider (all reached, no in-window content).

← Operations dashboard · run-record contract: docs/pipeline.md