CTIPilot

2026-09-12T0409Z-intel

One pipeline fire, in full · intel run of 2026-09-12 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-12/2026-09-12T0409Z-intel.md.

Run telemetry

2026-09-12T0409Z-intel intel prompt v4.9 publish ok
2h 02m duration 4 published 2 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
7m 51s
Tool calls
0 WebFetch6 WebSearch16 bridge
Cited sources
4 of 25 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
7m 00s
Tool calls
8 WebFetch15 WebSearch14 bridge
Cited sources
2 of 29 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
8m 42s
Tool calls
6 WebFetch11 WebSearch11 bridge
Cited sources
1 of 16 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
5m 04s
Tool calls
0 WebFetch15 WebSearch19 bridge
Cited sources
1 of 19 in slice

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=3 e=6 a=1 #2 NEEDS_FIXES · Sonnet 5 · t=3 e=2 a=0 #3 NEEDS_FIXES · Sonnet 5 · t=4 e=1 a=0 #4 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #5 CLEAN · Sonnet 5 · t=0 e=0 a=0 #6 NEEDS_FIXES · Sonnet 5 · t=3 e=1 a=0 #7 NEEDS_FIXES · Sonnet 5 · t=1 e=3 a=0 #8 NEEDS_FIXES · Sonnet 5 · t=0 e=1 a=0

Deep dive

2026-09-12/jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

No source-list edits recorded for this run.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 8 findings (truth=3, editorial=6, advisory=1) · Claude Sonnet 5 · 10m 49s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F2
generic-url
·jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover
Replaced the single combined JFrog advisory-listing URL with the two working per-CVE anchors (dated 2026-07-27 / 2026-08-13 matching each CVE's own disclosure d
F3
claim-not-supported
·sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited
Removed the 'independently reproduces' framing for OffSeq Threat Radar (an AI-generated summary tracker relaying the same Hunt.io report, not independent resear
F4
hallucinated-fact
·japan-digital-agency-gss-vpn-breach-maintenance-account
Removed the specific 'risk-based rather than bare-CVSS-based' framing not supported by either source; replaced with the sources' own vaguer 'will review its vul
F5
missing-citation
·cve-2026-84869-connectwise-screenconnect-worm-file-transfer
Added a CISA KEV catalog source record and inline citation for the KEV-addition claim.
F5
missing-citation
·cve-2026-85706-gitlab-unauth-path-traversal-file-read
Added CISA KEV and NCSC Switzerland source records and inline citations for both previously-uncited claims.
F5
missing-citation
·japan-digital-agency-gss-vpn-breach-maintenance-account
Added a Piyolog citation for the account-disable/connectivity-cut/patch clause; corrected the investigation-duration estimate from 'two months' to 'roughly two
F11
editorial-advisory
·cve-2026-84869-connectwise-screenconnect-worm-file-transfer
Tightened the body's T1543.003 traceability by naming the concealment mechanism (hidden Windows service, removed Uninstall registry entry, restrictive service s
F16
org-triage
·cve-2026-84869-connectwise-screenconnect-worm-file-transfer / cve-2026-85706-git
Reviewed against the critical bar and store precedent (2026-08-04 Cisco FMC CVSS 10.0 KEV-confirmed stayed 'high'); kept both at 'high', declined, not asserted

Iteration #2 NEEDS_FIXES · 5 findings (truth=3, editorial=2, advisory=0) · Claude Sonnet 5 · 7m 34s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·eu-cra-reporting-obligation-ncsc-fi-checklist
Reworded 'A same-day Bitkom survey' to 'A Bitkom survey, relayed the same day by heise online' in both the body and the changelog summary; removes the ambiguity
F3
claim-not-supported
·jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover
Softened the sourcing_note's claim about BSI/ENISA's exact dating and content (unconfirmable by the verifier's JS-SPA fetch); now states only that they track th
F4
hallucinated-fact
·jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover
Restored Wiz's own hedge ('likely due to') on the patching-velocity attribution claim, previously dropped into a firmer direct-attribution statement.
F5
missing-citation
·jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover
Added a CISA KEV source record and an inline citation for the cves[].status cisa-kev tag, matching the other three new entries this run.
F16
org-triage
·jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover
Upgraded priority from 'high' to 'critical' with an immediate_action block, confirmed ongoing exploitation reaching full admin takeover with backdoors already d

Iteration #3 NEEDS_FIXES · 5 findings (truth=4, editorial=1, advisory=0) · Claude Sonnet 5 · 11m 31s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover
immediate_action's 'Patch to >= 7.133.11 today' gave a false all-clear for CVE-2026-42018 on later branches (its fix is branch-specific: 7.111.20/7.117.27/7.125
F4
hallucinated-fact
·jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover
Removed the unsupported 'internet-reachable instances' qualifier from immediate_action; Wiz's cited figures are 'organizations running Artifactory' with a vulne
F3
claim-not-supported
·cve-2026-85706-gitlab-unauth-path-traversal-file-read
Softened 'the same day GitLab published the patch' (watchTowr's post is dated one day after GitLab's release, with no same-day timestamp) to 'within roughly a d
F4
hallucinated-fact
·eu-cra-reporting-obligation-ncsc-fi-checklist
Removed 'summary' from the 2026-09-12 updates[] record's fields list; git diff confirms the top-level frontmatter summary field was not changed by this run.
F16
org-triage
·jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover
Considered the CISA KEV due-date gap (14 days vs. 3 days for this run's other two vulnerability entries) explicitly requested as a sanity-check. Per PD-13, the

Iteration #4 NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 6m 35s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover
immediate_action and actions[] both instructed rotating the JFrog cluster join key as a response to this chain's compromise, but Wiz's report documents join-key
F3
claim-not-supported
·sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited
The 2026-09-12 update section inverted Hunt.io's stated condition for the pass-the-hash DCSync fallback; the source states operators used it precisely WHEN LDAP

Iteration #6 NEEDS_FIXES · 4 findings (truth=3, editorial=1, advisory=0) · Claude Sonnet 5 · 7m 27s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover
cves[].cvss values 8.1/7.5 were unsupported by any cited source (JFrog's own advisory gives only a 'High' label, no number). Added the MITRE CVE Record for each
F4
hallucinated-fact
·japan-digital-agency-gss-vpn-breach-maintenance-account
'Minister Motohisa Matsumoto'; no cited source gives a given name (Piyolog says only '松本大臣'/'Minister Matsumoto'), and the given name asserted does not match th
F3
claim-not-supported
·cve-2026-84869-connectwise-screenconnect-worm-file-transfer
event_date matched only the corroborating CISA KEV date (2026-09-11), not either primary source's own publication date. Corrected to 2026-09-08 (ConnectWise's o
F5
missing-citation
·jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover
sourcing_note referenced 'the matching ENISA EUVD listings' with no corresponding sources[] record. Removed the unsupported clause; the sentence stands on the B

Iteration #7 NEEDS_FIXES · 4 findings (truth=1, editorial=3, advisory=0) · Claude Sonnet 5 · 8m 07s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·japan-digital-agency-gss-vpn-breach-maintenance-account
The per-category breakdown (236,000/231,000/94,000/1,000) was attributed to Jiji Press, which gives only the 246,000 aggregate; the breakdown is Piyolog's. Spli
F5
missing-citation
·japan-digital-agency-gss-vpn-breach-maintenance-account
The VPN-appliance root-cause sentence had no citation (Jiji Press never mentions VPN); added the Piyolog citation, which does state it.
F5
missing-citation
·japan-digital-agency-gss-vpn-breach-maintenance-account
The 'no National ID/bank-account/pension data' sentence had no citation; added the Rocket Boys citation, which states it.
F5
missing-citation
·cve-2026-85706-gitlab-unauth-path-traversal-file-read
The CVE-2026-87719 sentence had no citation between two unrelated flanking citations; added the GitLab release-notes citation, already a sources[] record.

Iteration #8 NEEDS_FIXES cap-breach · 1 finding (truth=0, editorial=1, advisory=0) · Claude Sonnet 5 · 7m 38s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F5
missing-citation
·japan-digital-agency-gss-vpn-breach-maintenance-account
'No secondary misuse has been confirmed as of the disclosure date' had no inline citation (true and supported by already-cited sources, just uncited). Added a P

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-12T0409Z-intel · Sonnet 5 · window 26 h · 4 entries published

Verification & coverage notes

Coverage window: standard (gap_hours=23.98 since 2026-09-11T0410Z-intel, window_hours=26). No outage-backfill duty.

Mechanical KEV sweep (v4.8), all 4 in-window additions dispositioned. tools/kev_window_diff.py found four CISA KEV additions dated 2026-09-11 uncovered by the store: CVE-2026-42016 and CVE-2026-42018 (JFrog Artifactory), CVE-2026-84869 (ConnectWise ScreenConnect), CVE-2026-85706 (GitLab CE/EE). All four published as new entries this run. CVE-2026-42016/-42018 were confirmed via JFrog's own advisory to be distinct root causes, disclosure dates and affected-version ranges from the already-tracked CVE-2026-82329 (2026-09-01 entry) (not a same-flaw re-numbering) so they ship as a separate entry with references[] pointing at the existing one, per the single-report-covers-three-CVEs judgment call the researching sub-agent flagged; the two entries are not merged.

New entries (4):

  • 2026-09-12/cve-2026-84869-connectwise-screenconnect-worm-file-transfer (vulnerability, high), worm-like exploitation from 2026-08-20, patch 2026-09-08, KEV 2026-09-11.
  • 2026-09-12/cve-2026-85706-gitlab-unauth-path-traversal-file-read (vulnerability, high), patch-to-honeypot-probe in ~24h, KEV 2026-09-11.
  • 2026-09-12/jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover (vulnerability, critical, deep dive, category supply-chain, not used in the last 30 days), confirmed wide-scale admin-takeover chain against two previously-patched, low-attention CVEs, with backdoors already dropped and the majority of installs still vulnerable six weeks post-disclosure; raised from high to critical on iteration-2 verifier calibration flag, consistent with store precedent (the 2026-09-01 CVE-2026-82329 entry, same product, same admin-takeover outcome, critical). Single-source (Wiz Research is the sole assessor of the exploitation claim; JFrog's own advisories corroborate only the underlying flaws, not the exploitation).
  • 2026-09-12/japan-digital-agency-gss-vpn-breach-maintenance-account (incident, notable), clears the PD-11 breach gate on limb (b): a materially transferable lesson (detection via anomalous maintenance-account file-access volume rather than the initial exploit; a shift from CVSS-severity-based to risk-based patch prioritization after losing the race to an exploit on a bug rated only "Medium") on a structurally close foreign analogue (a national government's own shared multi-agency IT-services platform).

Updated entries (2):

  • 2026-08-29/eu-cra-reporting-obligation-ncsc-fi-checklist, update, floats updated_at. ENISA confirmed 2026-09-11 the CRA Single Reporting Platform has deployed initial operating capability, resolving the prior fire's open point; a same-day Bitkom survey (via heise) adds a preparedness data point.
  • 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited, update, floats updated_at. Hunt.io (via Security Affairs; OffSeq's AI-generated Threat Radar reposts the same figures, not an independent source) names a first confirmed victim of a materially wider, distinct mass-exploitation wave against the same CVE (UK council; secretsdump run directly on the compromised appliance reaching DCSync in 5/250 environments), explicitly not attributed to UTA0533 or INC Ransom.

Borderline drop: Anthropic's "distillation attacks" report (hydra-cluster fraudulent-account networks used by DeepSeek/Moonshot/MiniMax to scrape Claude), substantive primary technical research (Anthropic's own telemetry) with a transferable fraudulent-account-network detection technique, but the underlying subject is an AI-industry IP/competitive dispute under an active US-China export-control policy backdrop, with no direct Swiss public-sector nexus beyond a generic account-fraud/API-abuse technique-class analogy. Relevance doubt resolved toward drop per PD-11/v4.2 calibration. Not registered to the entity registry.

Single-source / carve-out items: jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover (single-source, reliability B / credibility 2; Wiz Research is the sole assessor of the active-exploitation chain; sourcing_note explains why BSI/ENISA's same-day postings are not counted as independent corroboration).

Coverage gaps: inside-it-ch (whole-host "Vercel Security Checkpoint" 429 on specific article bodies, the long-carried Insel Gruppe/ServiceNow backlog row plus two further articles this run, a 14th+ consecutive fire unable to read this class of article; RSS and general listing access stayed healthy throughout); cert-pl (/en/posts/ news listing 403'd this run; its vuln-advisory RSS feed, the source's primary recipe, was not re-tried as duplicative of S1's own essential-tier coverage of the same source, covered_anyway: true); cert-at (reachable, no in-window items, latest post dated 2026-08-26, outside the 26h window).

Coverage backlog: all 11 open rows in state/coverage_backlog.md re-checked this run (S1–S4); every one carries a 2026-09-12 dated note, no change on any, no row struck.

No contradictions found this run. No product/supplier watchlist configured (sweep is a no-op per the profile). No closed-source intake (no intel/ drops in-window).

Verification loop, 8 iterations, fail-open at the cap (never reached a confirmed CLEAN). The loop ran the full 8-iteration cap: iteration 1 NEEDS_FIXES (truth 3, editorial 6), 2 NEEDS_FIXES (3+2), 3 NEEDS_FIXES (4+1), 4 NEEDS_FIXES (2+0), 5 CLEAN, 6 (the confirmation pass) NEEDS_FIXES (3+1), restarting the chain per decision rule 2, 7 NEEDS_FIXES (1+3), 8 NEEDS_FIXES (0+1). Every iteration's findings were genuine and were remediated (see verification.iterations[] above and work/2026-09-12T0409Z-intel/verification.iter{1..8}.md); no finding was declined without a stated reason. Per the cap fail-open rule, this run publishes on iteration 8's NEEDS_FIXES verdict with verification_residual_count: 1 (one small, evidenced missing-citation finding, fixed) rather than a ninth iteration. This is an unusually long loop for what were, in aggregate, narrow and progressively smaller defects (import citation gaps, one inverted causal clause, one unsupported given name, a few CVSS/date sourcing gaps), every one caught by a genuinely independent cold read finding something the previous seven passes missed, which is the loop working as designed rather than a sign the content is unsound. The one substantive editorial judgment call (raising jfrog-artifactory-cve-2026-42016-42018-token-chain-takeover from priority: high to critical on iteration 2's flag) was independently sanity-checked by iteration 3 and not contested by any later iteration.

← Operations dashboard · run-record contract: docs/pipeline.md