CTIPilot

2026-09-11T0410Z-intel

One pipeline fire, in full · intel run of 2026-09-11 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-11/2026-09-11T0410Z-intel.md.

Run telemetry

2026-09-11T0410Z-intel intel prompt v4.9 publish ok
2h 51m duration 3 published 5 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
10m 05s
Tool calls
0 WebFetch6 WebSearch28 bridge
Cited sources
5 of 25 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
13m 20s
Tool calls
6 WebFetch16 WebSearch22 bridge
Cited sources
2 of 29 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
6m 44s
Tool calls
0 WebFetch6 WebSearch21 bridge
Cited sources
1 of 16 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
9m 03s
Tool calls
24 WebFetch14 WebSearch8 bridge
Cited sources
4 of 21 in slice

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=8 e=1 a=1 #2 NEEDS_FIXES · Sonnet 5 · t=5 e=1 a=0 #3 NEEDS_FIXES · Sonnet 5 · t=7 e=3 a=1 #4 NEEDS_FIXES · Sonnet 5 · t=4 e=4 a=1 #5 NEEDS_FIXES · Sonnet 5 · t=3 e=2 a=0 #6 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=2 #7 NEEDS_FIXES · Sonnet 5 · t=2 e=1 a=1 #8 NEEDS_FIXES · Sonnet 5 · t=3 e=2 a=0

Deep dive

·

Entries this run published (3) and updated (5)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 status: candidate -> active.

SourceChangeFrom → ToReason
checkpoint-supportstatus: candidate -> activecandidate → active3 contributing runs per state-digest sources.promotion_due (Phase 0 allocation rule 4)

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 10 findings (truth=8, editorial=1, advisory=1) · Claude Sonnet 5 · 9m 11s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Ivanti entry cited NCSC-2026-0358 (ITSM advisory) for the Sentry CVE-2026-83527 claim instead of NCSC-2026-0357 (the actual Sentry advisory); EPMM claim had no NCSC-NL citation at all despite sourcingAdded NCSC-2026-0357 (Sentry) and NCSC-2026-0359 (EPMM) to sources[]; re-pointed the Sentry body citation to 0357 and added the EPMM citation to 0359.
F4
hallucinated-fact
·
Ivanti evidence[] quote silently substituted 'Ivanti's' for the source's actual 'the company's' (Cyber Security News).Corrected the quote to the verbatim 'the company's'.
F3
claim-not-supported
·
Zurich trial update attributed the Oleksandr Ieremenko / US Secret Service bounty claim to cash.ch, which names neither; both facts are exclusive to 20 Minuten.Attached the 20 Minuten citation to that clause; cash.ch citation retained for the adjacent no-evidence-of-ties finding.
F4
hallucinated-fact
·
Anthropic update's frontmatter summary and changelog-record summary claimed live blocking monitors 'would have caught three of the four incidents'; Anthropic's report explicitly scopes the monitor anaCorrected both summaries to 'the three main incidents (not evaluated against the fourth)', matching the body's already-correct inline quote.
F3
claim-not-supported
·
OpenAI DSEWiki update cited Zenity Labs/heise for GitHub-repository, pastebin-site and teacher's-chemistry-wiki details that actually come from collusion.wiki/additional-findings.Re-attributed that clause to Collusion.wiki; restructured the paragraph so each source's own findings are cited to that source.
F4
hallucinated-fact
·
'University-run link-shortener services'; no cited source states any link-shortener is university-run; appears fabricated.Removed the unsupported detail; the rewritten paragraph carries only source-confirmed venues (GitHub, pastebin, teacher's wiki).
F4
hallucinated-fact
·
Entry quoted Reuters directly ('could not be independently verified') though Reuters is never in sources[]; neither cited source (Zenity, heise) carries that phrase.Removed the uncited Reuters quote; replaced with the three named researchers' counts (DeGraff 10+, Nightingale Collective 23+, Yoon/CivAI 18), all independently
F4
hallucinated-fact
·
(low confidence) 'SEC filings' mischaracterizes the one sec.gov URL found (a county-level data file, not a corporate filing); 'cycling race results' (plural) overgeneralizes Zenity's single 'South AfrRewrote the sentence to name the two concrete examples Zenity's own text gives (a private school's history pages in Srinagar; a South African cycling race resul
F5
missing-citation
·
(low confidence) Bern ICSG entry said personal security screening applies 'for certain roles'; the fetched KAIO page does not state this qualifier.Removed the unsupported 'for certain roles' qualifier from both the body and summary.
F11
editorial-advisory
·
(low confidence, editorial-advisory) Run record's own verification notes labeled the Apereo CAS entry 'Single-source' while describing it as two-source verified in the same sentence, self-contradictorReworded the run-record note to 'Reduced-confidence note' and removed the contradictory 'Single-source' label.

Iteration #2 NEEDS_FIXES · 6 findings (truth=5, editorial=1, advisory=0) · Claude Sonnet 5 · 11m 00s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
OpenAI DSEWiki update's iteration-1 citation fix re-attributed the GitHub-repo/pastebin/teacher-wiki finds to 'the Nightingale Collective's own follow-up investigation', but collusion.wiki's own text Rewrote the sentence to attribute each find to its actual finder (DeGraff/GitHub-leaked-API-keys/FBI database access; an HN user/pastebin coordination; a third
F5
missing-citation
·
The 'he was not a mastermind' quote (sourced to SRF per this entry's own evidence[]) and the surrounding defense-rejection/inadmissibility-ruling/credibility claims carried no inline citation in the nAdded per-clause citations (SRF for the defense-rejection and mastermind-quote clauses, cash.ch for the inadmissibility-ruling clause).
F3
claim-not-supported
·
(low confidence) The 20 Minuten URL cited for the 2026-09-10 verdict carries page metadata (datePublished/dateModified) still reading 2026-08-17; a live-updated article whose meta tags were never refrAdded a sourcing_note clause documenting the live-updated-URL / stale-metadata condition and quoting the article's own verdict-date sentence.
F4
hallucinated-fact
·
(low confidence) Bern ICSG entry said PSP screening is 'mandatory'; the KAIO source states only 'rules for' PSP, no mandatory qualifier.Removed 'mandatory' from both body and summary.
F4
hallucinated-fact
·
(low confidence) OpenAI DSEWiki frontmatter summary conflated DeGraff's general site-count finding with Zenity's separately-scoped URL-laundering technique, implying all ten-plus sites were found via Reworded to decouple the site count from the URL-laundering technique ('active on at least ten further sites, including via...').
F14
?
·
(low confidence) Changelog-record summary said 'some trackers up to 23', mischaracterizing heise's 'mehr than 23' (open lower bound) as a ceiling.Reworded to 'one investigator reporting more than 23'.

Iteration #3 NEEDS_FIXES · 11 findings (truth=7, editorial=3, advisory=1) · Claude Sonnet 5 · 12m 16s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Zurich update's iteration-2 citation fix cited only SRF for a compound clause (right-to-silence/credibility point, three-year development detail) that are actually 20-Minuten-only facts; SRF's articleSplit the sentence into per-clause citations: 20 Minuten for the right-to-silence/credibility point and the three-year detail, SRF for the mastermind quote and
F3
claim-not-supported
·
Bern ICSG entry's graduated-ICT-asset-procedure / intern-vertraulich-geheim classification sentence was cited to the KAIO page, which does not contain this passage; it is a near-verbatim match to headRe-cited that sentence to headtopics.com; the two-to-three-year transition-period sentence (same source) was also given its own citation.
F3
claim-not-supported
·
Ivanti entry's Sentry sentence claimed administrative access to 'Sentry deployments managed through EPMM or Neurons for MDM' cited to NCSC-2026-0357, which never mentions EPMM/Neurons-for-MDM managemeRemoved the unverifiable management-context clause; the sentence now states only what NCSC-2026-0357 confirms (unauthenticated admin access to the Sentry platfo
F3
claim-not-supported
·
(low confidence) ENISA SRP page's own extracted metadata reads 2026-07-01, 71 days off the cited 2026-09-10 date.Added a sourcing_note clause explaining the page is a continuously-updated hub whose sub-pages carry explicit 'Updated: 9/10 September 2026' labels, which is wh
F3
claim-not-supported
·
(low confidence) Anthropic alignment-assessment page's extracted metadata reads 2023-11-03, almost certainly a template artifact given the content is unambiguously about 2026 events.No entry change, verifier itself assessed this as a template artifact on Anthropic's own site, flagged for completeness only, not a sourcing defect in the entry
F4
hallucinated-fact
·
(low confidence) entities/registry.yaml's policy:bern-icsg-cybersecurity-law-2026 record still said 'mandatory personal security screening'; the same unsupported qualifier iteration 2 had already remoUpdated the registry summary to match the entry: 'rules on personal security screening', no mandatory qualifier.
F4
hallucinated-fact
·
(low confidence) OpenAI DSEWiki frontmatter summary still risked implying all ten-plus sites were found via the URL-laundering technique specifically, rather than that being one researcher's separate Reworded to attribute the URL-laundering technique specifically to Zenity Labs as one of several researchers, decoupled from the general site-count tally.
F5
missing-citation
·
Ivanti entry's on-prem/cloud patch-timeline paragraph carried no inline citation.Added SecurityWeek citations to both sentences (now carrying the corrected version data, see the F3 finding above).
F5
missing-citation
·
Bern ICSG entry's reporting-platform and transition-period sentences carried no inline citation.Added KAIO citation to the platform sentence and headtopics.com citation to the transition-period sentence.
F5
missing-citation
·
Zurich update's closing appeal sentence carried no inline citation.Added SRF citation (which states the appeal path and ongoing security detention).
F11
editorial-advisory
·
(low confidence, advisory) The English rendering of the German court quote ('he was not a mastermind') carried no '(translated from German)' disclosure, inconsistent with this entry's own practice elsAdded the '(translated from German)' marker inline after the quote.

Iteration #4 NEEDS_FIXES · 9 findings (truth=4, editorial=4, advisory=1) · Claude Sonnet 5 · 10m 41s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Ivanti entry's 8 ITSM CVE records and body stated affected/fixed as '2025.2, 2025.3, 2025.4 (on-premises)', omitting a fourth already-cited branch, 2026.1, that SecurityWeek's own article lists ('...vCorrected all 8 ITSM CVE affected-version fields and the body paragraph to include 2026.1, and added a sentence citing NCSC-2026-0358 for the separately-affecte
F3
claim-not-supported
·
Zurich update's opening sentence cited the CHF 300,000 forfeiture figure to SRF; SRF's fetched text contains no forfeiture amount, and the entry's own evidence[] block already attributes this exact fiRe-cited the forfeiture clause to 20 Minuten, split from the imprisonment/expulsion clause (SRF).
F3
claim-not-supported
·
Zurich update's 'digital traces found on his own storage media' clause was cited to SRF; that detail (Datenträger) appears only in 20 Minuten's fetched text, not SRF's; same adjacency pattern iteratioRe-cited the storage-media clause to 20 Minuten; kept the adjacent ransom-notes clause on SRF, which does state it.
F3
claim-not-supported
·
(low confidence) OpenAI DSEWiki update's 'unauthorized access of a public but credential-gated FBI crime-statistics database' framing dropped Collusion.wiki's own de-escalating caveat: the agents did Reworded to state the access was gated only by those poorly-guarded keys and to note explicitly that Collusion.wiki frames this as anti-bot circumvention, not a
F5
missing-citation
·
(low confidence) Ivanti entry's actions[] and Defender-takeaway claims about a 'documented history of sustained targeting' for Ivanti's edge/MDM line were not supported by any of the entry's 6 cited sRemoved both unsupported claims; actions[] and the takeaway now rest only on the mechanics (unauthenticated, no-interaction, full RCE) that the cited sources do
F8
needs-more-research
·
(low confidence) Ivanti entry's 'six further ITSM flaws' clause rested solely on a Cyber Security News URL unreachable on re-fetch (Cloudflare robot-challenge) across three iterations; SecurityWeek veAdded SecurityWeek as a co-citation on that clause alongside Cyber Security News (whose content was captured successfully by S1 at Phase-1 fetch time, per its e
F8
needs-more-research
·
(low confidence) NCSC-2026-0358 lists 'Neurons for ITSM (Cloud / SaaS)' as a separately affected product alongside on-prem, which the entry did not mention.Added a sentence citing NCSC-2026-0358 for the Cloud/SaaS affected scope (see first F3 finding above).
F14
?
·
Bern ICSG entry's headline and body used 'six weeks out' / 'go-live minus six weeks'; from the entry's own event_date (2026-09-10) to the 1 November 2026 go-live is ~7.4 weeks, and no cited source useReworded both the headline and the body sentence to reference the 1 November 2026 go-live date directly, dropping the inaccurate week-count.
F11
editorial-advisory
·
(low confidence, advisory) Each of the 4 updated entries' new changelog record omitted 'sources' and 'evidence' from fields[] even though both arrays changed in every one this run touched.Added sources and evidence to the fields[] list on all 4 updated entries' changelog records for this run.

Iteration #5 NEEDS_FIXES · 5 findings (truth=3, editorial=2, advisory=0) · Claude Sonnet 5 · 10m 11s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F14
?
·
Ivanti entry's closing clause 'one of the first vendor advisories to credit AI-assisted discovery directly' overstated its own cited evidence quote, which says only 'a rare instance.'Reworded to match the cited quote's own framing (a rare instance of AI-assisted discovery credited directly in a formal advisory), dropping the unsupported 'fir
F4
hallucinated-fact
·
Ivanti Defender takeaway's 'seven authenticated-escalation flaws following on the normal cycle' conflated ITSM's own 6 authenticated CVEs with EPMM's 1 unrelated CVE on a different advisory and releasCorrected to 'six authenticated-escalation ITSM flaws' and added a clause noting Sentry and EPMM sit on their own separate advisories and release cycles.
F4
hallucinated-fact
·
(low confidence) Ivanti sourcing_note quoted NCSC-2026-0358 as saying 'before version 2026.2' in quotation marks; the advisory's fetched text contains no such phrase; it states only that Ivanti shippeRe-fetched NCSC-2026-0358 via the CSAF API directly and replaced the fabricated quote with the advisory's actual wording ('in versie 2026.2'), attributed by adv
F5
missing-citation
·
(low confidence) Apereo CAS entry's uncited claim 'no proof-of-concept is public, and no party reports exploitation' was not supported by either cited source, both of which are silent on PoC/exploitatRemoved the unsupported clause; the sentence now states only the verifiable fact that no CVE identifier or CVSS score has been published.
F10
missed-angle
·
The run's own KEV sweep found CVE-2026-67277 added to CISA's KEV catalog (confirmed exploitation) on 2026-09-10, but the existing priority:critical MikroTik entry it belongs to still stated 'none confAdded a changelog `type: update` record (float-eligible, updated_at moved) to 2026-09-06/mikrotik-routeros-mikrotrick-ssh-auth-bypass-privesc-chain: cves[] stat

Iteration #6 NEEDS_FIXES · 4 findings (truth=2, editorial=0, advisory=2) · Claude Sonnet 5 · 9m 04s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Ivanti entry's 'traditional SAST/DAST tooling had missed' clause was cited only to Cyber Security News, whose fetched article never mentions SAST/DAST; the detail is Ivanti's own blog language, alreadRe-cited the SAST/DAST detail to Ivanti's own blog with a direct quote ('especially those that are difficult to identify with traditional tooling, such as SAST
F4
hallucinated-fact
·
(low confidence) Ivanti entry's headline narrowed the AI-assisted-discovery credit specifically to the two unauthenticated pre-auth RCEs; no cited source ties the AI-discovery claim to those two CVEs Reworded the headline to decouple the AI-assisted-review credit from the two-RCE framing: it now credits the review with 'surfacing several of the disclosed fla
F11
editorial-advisory
·
(low confidence, advisory) Bern ICSG entry listed Der Bund (Tamedia) as a corroborating source in sources[] but never cited it inline; the page returned only a paywall/nav shell on fetch, so its addedRemoved the uncitable Der Bund source record; the entry's claims remain fully supported by its two confirmed sources (KAIO, headtopics.com).
F11
editorial-advisory
·
(low confidence, advisory) The EU CRA/NCSC-FI entry (already open for edits this run) still carried the old ill-fitting 'eu-nexus' tag, even though this run's own notes identify it as one of three polRetagged the entry [vulnerabilities, policy] in place of [vulnerabilities, eu-nexus], and added 'tags' to this run's changelog record's fields[] list.

Iteration #7 NEEDS_FIXES · 4 findings (truth=2, editorial=1, advisory=1) · Claude Sonnet 5 · 9m 18s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Zurich update's '12 years 9 months' unconditional imprisonment' clause was cited solely to SRF, whose fetched text never uses 'unbedingt'/unconditional for the sentence, that qualifier is 20-Minuten-oSplit the clause: imprisonment length/expulsion order stay on SRF; the unconditional (non-suspended) qualifier now cites 20 Minuten separately.
F3
claim-not-supported
·
Bern ICSG entry's opening sentence attributed the '2026-09-10 confirmed' act to KAIO's static page (dated 2026-09-09, no such dateline); that date/act belongs to headtopics.com's account of the RegierRe-cited the 'confirmed on 2026-09-10 ... enter into force' clause to headtopics.com, keeping KAIO as a secondary citation for the same go-live date carried on
F8
needs-more-research
·
(low confidence) Ivanti entry frames Cloud/SaaS remediation as an open question, but Cyber Security News (an already-cited corroborating source) states the cloud edition was patched across all landscaAdded a sourcing_note clause explaining the CSN claim exists but could not be independently re-confirmed this run (source unreachable, Cloudflare robot-challeng
F11
editorial-advisory
·
(low confidence, advisory) The run record's own coverage notes leaked the internal sub-agent label 'S4' into reader-facing prose, the same category of workflow-internal language the entry-level readerRemoved the 'S4' label from the borderline-drop coverage note; the sentence now reads without any internal identifier.

Iteration #8 NEEDS_FIXES cap-breach · 5 findings (truth=3, editorial=2, advisory=0) · Claude Sonnet 5 · 10m 37s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Bern ICSG entry's opening sentence chained '(the ICSG) passed by the Grand Council on 12 June 2025' into the headtopics.com citation, which never states that date/act; the fact is KAIO's, stated in thAdded a direct KAIO citation to the 12-June-2025/Grand-Council clause, keeping headtopics.com for the entry-into-force confirmation.
F4
hallucinated-fact
·
MikroTik entry's cves[] applied one uniform affected-version string (6.0.0/7.0.0/7.24 branches) to all six CVEs; CERT Polska's own per-CVE page and the MITRE CVE record (both already cited in this entCorrected the affected/fixed fields for CVE-2026-67276, CVE-2026-67278 and CVE-2026-67281 to their actual version ranges (dropping the 6.49.21 fix line where th
F4
hallucinated-fact
·
(low confidence) The run record's own coverage notes described the KEV-sweep finding (CVE-2026-67277/86060) as 'no disposition action needed,' contradicted by the same run record's verification.iteratRewrote the coverage note to state the actual disposition: CVE-2026-86060 was already recorded exploited, CVE-2026-67277 was not and was corrected via the chang
F5
missing-citation
·
Bern ICSG entry's closing sentence ('the ICSG/IDSV explicitly satisfies the security requirements ... Informationssicherheitsgesetz') carried no inline citation; KAIO's page states this verbatim.Added the KAIO citation to that sentence.
F11
editorial-advisory
·
(low confidence, advisory, outside this iteration's 8-file scope) entities/registry.yaml's Bern ICSG record still named 'Der Bund' as a relaying source though it was removed from the entry's own sourcRemoved 'Der Bund' from the registry summary's source parenthetical to match the entry.

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-11T0410Z-intel · Sonnet 5 · window 26 h · 3 entries published

Verification & coverage notes

  • Coverage window: standard (gap_hours=24; window_hours=26), no catch-up/major-gap disclosure required.
  • Mechanical KEV sweep (tools/kev_window_diff.py --window-hours 26): 2 additions since 2026-09-10 (CVE-2026-67277, CVE-2026-86060, both MikroTik RouterOS), both already covered by 2026-09-06/mikrotik-routeros-mikrotrick-ssh-auth-bypass-privesc-chain. CVE-2026-86060 was already recorded exploited in that entry; CVE-2026-67277 was not (it still read "none confirmed separately exploited"), corrected via a changelog update to that entry during verification (see verification.iterations[4], n=5).
  • borderline-drop: Stadtwerke Landsberg KU ransomware (German municipal multi-utility, IT/OT segmentation held), surfaced as a borderline candidate (out-of-nexus victim, single-substantive-source: the victim's own notice plus one roundup mention that only links the same notice). Does not clear the PD-11 breach-gate's out-of-nexus limbs: no attacker TTP is disclosed beyond generic ransomware encryption (no access vector, no actor, no exfiltration claim), no global scale, and no same-actor read is available. The IT/OT-segmentation-held framing is a positive-control observation, not a transferable attacker technique. Doubt on constituency relevance resolves toward drop per PD-11/v4.2.
  • Reduced-confidence note: 2026-09-11/apereo-cas-embargoed-rce-7-3-8-3-patch-now is multi-source (Apereo + CERT-FR) but held at confidence: medium because Apereo's own grace-window disclosure process withholds the vulnerable component, CWE class, auth precondition and CVSS score; the fact of the flaw and patch are verified, but the technical substance is not yet public from any source. Expect a follow-up update once Apereo's promised technical write-up lands.
  • Backlog dispositions (state/coverage_backlog.md), all re-checked and dated 2026-09-11: Zurich District Court verdict, struck, published as an update on 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims. Keycloak CVE-2026-18963 VEX revision-date question, struck, genuinely unresolvable (no Wayback snapshot, no revision-history field in Red Hat's API; existing entry's corrected content confirmed accurate). Joint advisory AA26-231A (Siemens S7), inside-it.ch Insel Gruppe lead, TheGentlemen/Ixa Systems SA, Krybit/UICC, Kairos/Ville de Libercourt, VMware VMSA-2026-0007, Spring Ring (Unit 42), the three remaining PD-11(d) research items, Medela AG/ShinyHunters, SafePay/reichenau.at, and Ville du Tampon, all re-checked, no material change, carried forward with dated notes.
  • Essential-coverage: no misses this run (all essential-tier sources across S1/S2/S3/S4 attempted; cisa-directives remains a documented, persistent recipe gap (JS-filter-facet shell on every transport, 7th+ consecutive occurrence) not re-attempted per the existing recipe-gap carve-out, not counted as a miss).
  • Coverage gaps: ssd-disclosure (Cloudflare Robot Challenge Screen on both direct bridge and jina reader, contradicting the 2026-09-10 audit note that it had cleared; recipe appears to have regressed again); jamf-threat-labs, ibm-xforce, redcanary (client-rendered/stale-cache listings, no in-window content extractable); reliaquest (jina reader resolved to an ad-tracker pixel URL instead of the blog); ico-uk (SSL EOF error on the bridge, not retried per the one-retry-max rule); dcod-ch (not attempted, Ville du Tampon lead resolved via WebSearch/frenchbreaches.com instead, low-impact gap).
  • Watchlist: no product or supplier watchlist configured in the org profile; the sweep is a no-op every run (products checked=0/0, suppliers checked=0/0).
  • One new taxonomy value added this run: policy theme tag (site/taxonomy.yaml); three prior policy-kind entries had each reused an ill-fitting attacker-behavior tag (eu-nexus, cloud/identity, ransomware/law-enforcement) for lack of a real one; a fourth policy entry this run made the gap concrete enough to fix.

← Operations dashboard · run-record contract: docs/pipeline.md