CTIPilot

2026-09-13T0409Z-intel

One pipeline fire, in full · intel run of 2026-09-13 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-13/2026-09-13T0409Z-intel.md.

Run telemetry

2026-09-13T0409Z-intel intel prompt v4.9 publish ok
1h 54m duration 2 published 3 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
6m 29s
Tool calls
0 WebFetch3 WebSearch27 bridge
Cited sources
1 of 25 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
0
Duration
5m 06s
Tool calls
9 WebFetch9 WebSearch8 bridge
Cited sources
0 of 29 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
6m 08s
Tool calls
0 WebFetch5 WebSearch30 bridge
Cited sources
1 of 16 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
9m 11s
Tool calls
3 WebFetch15 WebSearch15 bridge
Cited sources
1 of 16 in slice
FOLLOWUP1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
7m 38s
Tool calls
0 WebFetch10 WebSearch20 bridge
Cited sources
none

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=6 e=2 a=1 #2 NEEDS_FIXES · Sonnet 5 · t=2 e=3 a=1 #3 NEEDS_FIXES · Sonnet 5 · t=2 e=1 a=0 #4 NEEDS_FIXES · Sonnet 5 · t=4 e=1 a=0 #5 NEEDS_FIXES · Sonnet 5 · t=0 e=2 a=0

Deep dive

2026-09-13/gtg-20006-anthropic-russia-ai-orchestrated-espionage

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 status: candidate -> active.

SourceChangeFrom → ToReason
offseqstatus: candidate -> activecandidate → activepromotion_due: cited by published entries from 3 distinct runs, bar met (Phase 0 allocation rule 4).

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
cisa-directiveshttps://www.cisa.gov/news-events/directivesbridge:cisa pagebridge:jinaNone js-shell
Bridge and jina both return only the site's filter-facet JS shell; no structured feed exists for this listing.
none
tp-link-omada-psirthttps://support.omadanetworks.com/us/security-advisory/bridge404 moved-or-retired
URL now 404s (Nuxt page404 response); no replacement URL found this run.
none
reliaquesthttps://reliaquest.com/blog/extractjinaNone client-rendered
Trafilatura extract returned only nav chrome; jina reader resolved to an unrelated ad-tracker pixel URL rather than blog content.
none
fortiguard-fg-ir-2026-164-174https://www.fortiguard.com/psirt/FG-IR-26-164 (and eight sibling advisories)directextractjinaNone anti-bot-challenge
Direct GET returned an anti-bot/challenge body, trafilatura had no readable body, jina relayed an upstream block/challenge. CERT-FR's own advisory (CERTFR-2026-
none

Bridge invocations (this run)

4 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

4 ok
  • ncsc-csh recent 20 ×1
  • cisa feed .../all.xml ×1
  • KEV JSON feed ×1
  • cert-eu recent N ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 10 findings (truth=6, editorial=2, advisory=1) · Claude Sonnet 5 · 10m 27s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
BlueMoon update wrongly generalized Cloudflare Tunnel delivery to 'the other three clusters' when only JungleBamboo's domains use it, fixed.Rephrased to attribute Cloudflare Tunnel delivery to JungleBamboo specifically.
F4
hallucinated-fact
·
UTA0560 called 'a fourth operator' when it is the fifth actor cluster on this entry, fixed.Corrected 'fourth' to 'fifth' in the changelog summary and body.
F4
hallucinated-fact
·
CVE-2026-87719/CVE-2026-88765 wrongly carried vector: user-interaction despite UI:N CVSS vectors and self-triggered exploitation, fixed.Changed both records to vector: zero-click.
F4
hallucinated-fact
·
(low confidence) Ellipsis-spliced Talos quote on Qilin-affiliate TTPs was not a contiguous substring, fixed.Rewrote to use a contiguous verbatim quote fragment.
F4
hallucinated-fact
·
(low confidence) GRIMWEDGE dropper called 'signed-binary' when Volexity never confirms signing, fixed.Removed the unconfirmed 'signed-binary' qualifier.
F13
?
·
Storm-2945/CaptiveCrunch attribution in the GTG-20006 entry was uncited to any of its three sources.Rephrased to attribute the claim to the referenced CaptiveCrunch entry and added it to references[].
F5
missing-citation
·
Revolut entry's 'fake Emergency Data Request' comparison (Discord/Apple/Meta/Snap) carried no citation.Removed the uncited named pattern and company list; kept the sourced mechanism description.
F17
?
·
(low confidence) GTG-20006 classification credibility:1 overstated corroboration that is really one assessor (Anthropic) relayed by two outlets.Changed credibility to 2 and verification from multi-source to single-source, with a sourcing_note.
F11
editorial-advisory
·
Run record's verification notes used workflow-internal language (sub-agent, spawned, bare S1-S4 labels) barred from reader-facing text.Rewrote the run record's Verification & coverage notes section in reader-facing terms.
F11
editorial-advisory
·
(low confidence) GTG-20006's empty references[] should likely declare the CaptiveCrunch entry given the Storm-2945 dependency.Added the CaptiveCrunch entry to references[] (same fix as the F13 finding above).

Iteration #2 NEEDS_FIXES · 6 findings (truth=2, editorial=3, advisory=1) · Claude Sonnet 5 · 10m 14s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
Cisco Secure FMC entry's evidence[] still quoted the pre-revision 'not aware of any...malicious use' line, which the cited advisory (now v2.5) no longer carries.Removed the stale evidence line, added the current v2.5 quote already used in the update section, and declared evidence in the update record's fields.
F5
missing-citation
·
GTG-20006's hospitality-WiFi-vendor sentence carried no inline citation, only an internal reference to the CaptiveCrunch entry.Added an inline Anthropic citation to that sentence.
F8
needs-more-research
·
(low confidence) Two source-supported deep-dive details (WhatsApp companion-device takeover, camera-streaming token harvesting) were missing.Re-fetched the Anthropic primary, confirmed both quotes verbatim, and added both to the body and evidence[].
F15
?
·
(low confidence) BlueMoon's GemStone/GhostChrome-X (Proofpoint) and SUPERSTOMP/LONGTALE (Volexity) may describe the same artifact under different vendor names, unflagged.Added a sentence noting the possible same-artifact overlap without merging the entities, since neither vendor confirms it directly.
F17
?
·
(low confidence) BlueMoon's classification/sourcing_note were not revisited after Volexity became a second independent primary corroborating Proofpoint's same-kit conclusion.Raised credibility from 2 to 1 and updated the sourcing_note to reflect Volexity's independent corroboration; declared classification and sourcing_note in the u
F11
editorial-advisory
·
Registry gap: no typed relation from actor:gtg-20006 to actor:storm-2945 despite the entry's own entities[] tag and body text.Added an overlaps-with relation (technique-level, not a same-entity claim) sourced to the GTG-20006 entry.

Iteration #3 NEEDS_FIXES · 3 findings (truth=2, editorial=1, advisory=0) · Claude Sonnet 5 · 8m 54s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
BlueMoon's Triage line misattributed GRIMWEDGE's own C2 (a fixed URL) to the per-hostname beacon, which actually belongs to the earlier wsc.dll dropper stage.Rewrote the body and Triage discriminator to separate the wsc.dll dropper's per-hostname beacon from GRIMWEDGE's own fixed-URL POST-based C2, with two new verba
F4
hallucinated-fact
·
(low confidence) BlueMoon's title/headline/summary still said 'four' clusters after the changelog documented a fifth (UTA0560).Updated title, headline and summary to 'five' and named UTA0560; declared title/headline/summary in the update record's fields.
F5
missing-citation
·
(low confidence) Cisco Secure FMC entry's 'not aware of any...malicious use' quote had no adjacent citation.Added the Cisco PSIRT advisory citation immediately after the quote.

Iteration #4 NEEDS_FIXES · 5 findings (truth=4, editorial=1, advisory=0) · Claude Sonnet 5 · 10m 36s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
Cisco Secure FMC entry's 2026-09-13 update cites two new URLs (Talos, Cisco advance notification) inline but never added them to frontmatter sources[], and the record's fields omitted 'sources'.Appended both URLs to sources[] and added 'sources' to the update record's fields.
F3
claim-not-supported
·
Iteration 3's citation fix for the 'not aware of any...malicious use' quote pointed at a URL that, on re-fetch, no longer contains that text (superseded by the same advisory's v2.5 revision).Rewrote the sentence as indirect/reported speech (no quotation marks, no claim of live verifiability) rather than a citable direct quote, since no dated/archiva
F4
hallucinated-fact
·
GTG-20006 body/techniques[] asserted an 'adversary-in-the-middle session capture' mechanism and T1557 that belongs to a different, unrelated case study in the same Anthropic report, not to GTG-20006.Replaced the claim with the source-supported browser-credential-theft detail and removed T1557 from techniques[].
F5
missing-citation
·
Revolut entry's detailed exposed-data-category sentence (including the Bitcoin/IBAN specifics) carried no citation of its own under the adjacency rule.Added an inline Security Affairs citation directly to that sentence.
F14
?
·
(low confidence) BlueMoon's 'five clusters ... within two weeks'/'same fortnight' language was unsupported, all five clusters' own dated first-activity spans only six days (2026-08-28 to 2026-09-03), Reverted title to 'within one week' and corrected the body to state UTA0560 started 2026-09-01, within that same one-week span.

Iteration #5 NEEDS_FIXES cap-breach · 2 findings (truth=0, editorial=2, advisory=0) · Claude Sonnet 5 · 10m 23s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F5
missing-citation
·
Cisco Secure FMC entry's rewritten (iteration-4) main-analysis sentence about what Cisco's original advisory said carried no inline citation at all.Added a dated citation ('as first published on 2026-08-03') to the same Cisco PSIRT advisory URL, framing it explicitly as the historical revision that carried
F5
missing-citation
·
(low confidence) The entry's 2026-09-10 update body section still quoted 'not aware of any malicious use' in quotation marks, a phrase that no longer appears verbatim anywhere in the entry after this Rephrased the 2026-09-10 update section's cross-reference to indirect speech ('the no-known-malicious-use framing'), declared under this run's own already-liste

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-13T0409Z-intel · Sonnet 5 · window 26 h · 2 entries published

Verification & coverage notes

Standard window (gap since the previous run about 24.0 hours, 26-hour recency window); today (2026-09-13) is a Sunday and the general threat-research publishing landscape was genuinely quiet in-window across the home-region/sector, research and incident domains, most sources' newest items clustered 2026-09-09 through 2026-09-11, confirmed by broad supplementary searches, not a fetch-tooling failure. No closed-source intake drops this run. No product/supplier watchlist configured in this deployment; the sector lens and general relevance discipline were applied throughout.

Two updates recover apparent gaps from the last three daily fires, disclosed transparently. A sweep of NCSC Switzerland's Cyber Security Hub surfaced two in-window (2026-09-11/2026-09-12) NCSC-CH advisories whose own cited primaries (Cisco Talos, Volexity) were dated 2026-09-09, a day or two outside the strict 26-hour window on their own. Given the NCSC-CH advisories themselves are in-window, the underlying material is a material development on two already-critical/high-severity, actively-exploited entries already carried here (the Cisco Secure FMC auth-bypass chain and the BlueMoon exploit kit) rather than a new, isolated finding, and leaving a verified, high-severity gap unrecovered when it is already in hand would be a blind spot on critical/high signal, both were composed as update records rather than held. A third update (GitLab CVE-2026-87719 / CVE-2026-88765) closes a narrower gap: CVE-2026-87719 was already named in the existing entry's own analysis but had never carried its own CVE record, and CVE-2026-88765 is a genuinely new same-release finding, both independently confirmed by NCSC Switzerland (for the former) and GitLab's own release notes.

One new entry rides the wider window this pipeline allows for an actively developing story, disclosed for the same reason. Anthropic's own GTG-20006 threat-intelligence report (published 2026-09-10, with edits as late as 19:29Z the same day) sits inside that wider window but outside the strict 26-hour one; it was fully verified against Anthropic's own primary plus two independent secondaries (The Hacker News, 2026-09-11; UNITED24 Media, 2026-09-12), confirming continued press attention through 2026-09-12 as the in-window hook. This is a globally significant, fully-verified nation-state AI-misuse campaign (Russia-linked, Midnight Blizzard overlap, 20+ government/military/diplomatic/drone-supply-chain targets) with no existing coverage here, and was selected as today's deep dive (category: apt-campaign) given its technical depth and defender-relevance to any organization's AI-agentic threat model.

  • borderline-drop: Peter Gutmann's heise online interview naming "stunt cryptography" (CVE disclosures engineered for academic/media visibility over real exploitability), a genuinely interesting, single-source commentary/analysis piece on the CVE-disclosure ecosystem itself, not a technical vulnerability or threat-actor finding; it does not clear the relevance gate as tradecraft or detection-relevant analysis, and the quality-over-quantity bar resolves this doubt toward drop.
  • Coverage-backlog: all twelve open rows re-checked this run at the standing low/cheap-recheck budget (Siemens S7 PLC advisory, Insel Gruppe/ServiceNow, Ixa Systems/TheGentlemen, UICC/Krybit, Kairos/Ville de Libercourt, VMware VMSA-2026-0007, Spring Ring, three residual research items, NovoCure, Medela/ShinyHunters, SafePay/reichenau.at, Ville du Tampon); no row cleared its blocking condition this run. One new row opened: GTG-27005 (same Anthropic report as today's deep dive, a freelance Russia-based team's autonomous drone-swarm targeting software), noted but not yet verified to full primary-source depth.
  • Essential-coverage: missed=cisa-directives (persistent recipe gap, every transport tried returns only the site's filter-facet shell; no structured CISA directives feed exists yet).
  • Aggregator-only sourcing (acknowledged, not fixed): the Revolut entry cites TechCrunch and Security Affairs only. The entry's actual primary is Revolut's own customer notification and spokesperson statement, quoted independently by both outlets; Revolut has published no reachable newsroom statement of its own (checked: revolut.com/newsroom/ 404s). This is the established single-source-victim carve-out; the entry already carries the corresponding verification value and a sourcing note naming the gap; not re-pivoted or dropped.
  • Coverage gaps: reliaquest (client-rendered blog, the reader fallback resolved to an unrelated ad-tracker pixel); ssd-disclosure (individual advisory pages returned a browser-challenge page this run, though the listing itself was readable); tp-link-omada-psirt (URL now 404s, needs a canonical-URL probe); fortiguard.com FG-IR-26-164 through -174 (anti-bot challenge on every transport; CERT-FR's own advisory confirms the CVE list but carries no CVSS or exploitation-status detail).

← Operations dashboard · run-record contract: docs/pipeline.md