2026-09-13T0409Z-intel
One pipeline fire, in full · intel run of 2026-09-13 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-13/2026-09-13T0409Z-intel.md.
Run telemetry
- Items returned
- 2
- Duration
- 6m 29s
- Tool calls
- 0 WebFetch3 WebSearch27 bridge
- Cited sources
- 1 of 25 in slice
- Items returned
- 0
- Duration
- 5m 06s
- Tool calls
- 9 WebFetch9 WebSearch8 bridge
- Cited sources
- 0 of 29 in slice
- Items returned
- 1
- Duration
- 6m 08s
- Tool calls
- 0 WebFetch5 WebSearch30 bridge
- Cited sources
- 1 of 16 in slice
- Items returned
- 1
- Duration
- 9m 11s
- Tool calls
- 3 WebFetch15 WebSearch15 bridge
- Cited sources
- 1 of 16 in slice
- Items returned
- 2
- Duration
- 7m 38s
- Tool calls
- 0 WebFetch10 WebSearch20 bridge
- Cited sources
- none
Verification
Deep dive
2026-09-13/gtg-20006-anthropic-russia-ai-orchestrated-espionage
Entries this run published (2) and updated (3)
- CVE-2026-20079, Cisco Secure Firewall Management Center: unauthenticated authentication bypass to root, unpatched for five months and only exploitable in a post-boot window (CVSS 10.0) vulnerability high update
- BlueMoon: five separate state-nexus actor clusters independently weaponize a shared Chrome V8 + Windows kernel zero-day chain within one week threat high update
- CVE-2026-85706, GitLab CE/EE: unauthenticated path traversal in the repository commits API reads arbitrary server files, and honeypots caught exploitation attempts one day after the patch (CVSS 10.0) vulnerability high update
- GTG-20006: a Russian espionage cluster runs AI-orchestrated intrusions and autonomously rebuilds detected malware across 20+ government, military and drone-supply-chain targets threat high
- Revolut discloses a customer KYC data breach after fulfilling a fraudulent request sent from inside a genuine government agency's own email domain incident notable
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
1 status: candidate -> active.
| Source | Change | From → To | Reason |
|---|---|---|---|
| offseq | status: candidate -> active | candidate → active | promotion_due: cited by published entries from 3 distinct runs, bar met (Phase 0 allocation rule 4). |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| cisa-directives | https://www.cisa.gov/news-events/directives | bridge:cisa page → bridge:jina | None js-shell Bridge and jina both return only the site's filter-facet JS shell; no structured feed exists for this listing. | none |
| tp-link-omada-psirt | https://support.omadanetworks.com/us/security-advisory/ | bridge | 404 moved-or-retired URL now 404s (Nuxt page404 response); no replacement URL found this run. | none |
| reliaquest | https://reliaquest.com/blog/ | extract → jina | None client-rendered Trafilatura extract returned only nav chrome; jina reader resolved to an unrelated ad-tracker pixel URL rather than blog content. | none |
| fortiguard-fg-ir-2026-164-174 | https://www.fortiguard.com/psirt/FG-IR-26-164 (and eight sibling advisories) | direct → extract → jina | None anti-bot-challenge Direct GET returned an anti-bot/challenge body, trafilatura had no readable body, jina relayed an upstream block/challenge. CERT-FR's own advisory (CERTFR-2026- | none |
Bridge invocations (this run)
4 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- ncsc-csh recent 20 ×1
- cisa feed .../all.xml ×1
- KEV JSON feed ×1
- cert-eu recent N ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 10 findings (truth=6, editorial=2, advisory=1) · Claude Sonnet 5 · 10m 27s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | BlueMoon update wrongly generalized Cloudflare Tunnel delivery to 'the other three clusters' when only JungleBamboo's domains use it, fixed. | Rephrased to attribute Cloudflare Tunnel delivery to JungleBamboo specifically. | |
| F4 hallucinated-fact | · | UTA0560 called 'a fourth operator' when it is the fifth actor cluster on this entry, fixed. | Corrected 'fourth' to 'fifth' in the changelog summary and body. | |
| F4 hallucinated-fact | · | CVE-2026-87719/CVE-2026-88765 wrongly carried vector: user-interaction despite UI:N CVSS vectors and self-triggered exploitation, fixed. | Changed both records to vector: zero-click. | |
| F4 hallucinated-fact | · | (low confidence) Ellipsis-spliced Talos quote on Qilin-affiliate TTPs was not a contiguous substring, fixed. | Rewrote to use a contiguous verbatim quote fragment. | |
| F4 hallucinated-fact | · | (low confidence) GRIMWEDGE dropper called 'signed-binary' when Volexity never confirms signing, fixed. | Removed the unconfirmed 'signed-binary' qualifier. | |
| F13 ? | · | Storm-2945/CaptiveCrunch attribution in the GTG-20006 entry was uncited to any of its three sources. | Rephrased to attribute the claim to the referenced CaptiveCrunch entry and added it to references[]. | |
| F5 missing-citation | · | Revolut entry's 'fake Emergency Data Request' comparison (Discord/Apple/Meta/Snap) carried no citation. | Removed the uncited named pattern and company list; kept the sourced mechanism description. | |
| F17 ? | · | (low confidence) GTG-20006 classification credibility:1 overstated corroboration that is really one assessor (Anthropic) relayed by two outlets. | Changed credibility to 2 and verification from multi-source to single-source, with a sourcing_note. | |
| F11 editorial-advisory | · | Run record's verification notes used workflow-internal language (sub-agent, spawned, bare S1-S4 labels) barred from reader-facing text. | Rewrote the run record's Verification & coverage notes section in reader-facing terms. | |
| F11 editorial-advisory | · | (low confidence) GTG-20006's empty references[] should likely declare the CaptiveCrunch entry given the Storm-2945 dependency. | Added the CaptiveCrunch entry to references[] (same fix as the F13 finding above). |
Iteration #2 NEEDS_FIXES · 6 findings (truth=2, editorial=3, advisory=1) · Claude Sonnet 5 · 10m 14s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | Cisco Secure FMC entry's evidence[] still quoted the pre-revision 'not aware of any...malicious use' line, which the cited advisory (now v2.5) no longer carries. | Removed the stale evidence line, added the current v2.5 quote already used in the update section, and declared evidence in the update record's fields. | |
| F5 missing-citation | · | GTG-20006's hospitality-WiFi-vendor sentence carried no inline citation, only an internal reference to the CaptiveCrunch entry. | Added an inline Anthropic citation to that sentence. | |
| F8 needs-more-research | · | (low confidence) Two source-supported deep-dive details (WhatsApp companion-device takeover, camera-streaming token harvesting) were missing. | Re-fetched the Anthropic primary, confirmed both quotes verbatim, and added both to the body and evidence[]. | |
| F15 ? | · | (low confidence) BlueMoon's GemStone/GhostChrome-X (Proofpoint) and SUPERSTOMP/LONGTALE (Volexity) may describe the same artifact under different vendor names, unflagged. | Added a sentence noting the possible same-artifact overlap without merging the entities, since neither vendor confirms it directly. | |
| F17 ? | · | (low confidence) BlueMoon's classification/sourcing_note were not revisited after Volexity became a second independent primary corroborating Proofpoint's same-kit conclusion. | Raised credibility from 2 to 1 and updated the sourcing_note to reflect Volexity's independent corroboration; declared classification and sourcing_note in the u | |
| F11 editorial-advisory | · | Registry gap: no typed relation from actor:gtg-20006 to actor:storm-2945 despite the entry's own entities[] tag and body text. | Added an overlaps-with relation (technique-level, not a same-entity claim) sourced to the GTG-20006 entry. |
Iteration #3 NEEDS_FIXES · 3 findings (truth=2, editorial=1, advisory=0) · Claude Sonnet 5 · 8m 54s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | BlueMoon's Triage line misattributed GRIMWEDGE's own C2 (a fixed URL) to the per-hostname beacon, which actually belongs to the earlier wsc.dll dropper stage. | Rewrote the body and Triage discriminator to separate the wsc.dll dropper's per-hostname beacon from GRIMWEDGE's own fixed-URL POST-based C2, with two new verba | |
| F4 hallucinated-fact | · | (low confidence) BlueMoon's title/headline/summary still said 'four' clusters after the changelog documented a fifth (UTA0560). | Updated title, headline and summary to 'five' and named UTA0560; declared title/headline/summary in the update record's fields. | |
| F5 missing-citation | · | (low confidence) Cisco Secure FMC entry's 'not aware of any...malicious use' quote had no adjacent citation. | Added the Cisco PSIRT advisory citation immediately after the quote. |
Iteration #4 NEEDS_FIXES · 5 findings (truth=4, editorial=1, advisory=0) · Claude Sonnet 5 · 10m 36s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | Cisco Secure FMC entry's 2026-09-13 update cites two new URLs (Talos, Cisco advance notification) inline but never added them to frontmatter sources[], and the record's fields omitted 'sources'. | Appended both URLs to sources[] and added 'sources' to the update record's fields. | |
| F3 claim-not-supported | · | Iteration 3's citation fix for the 'not aware of any...malicious use' quote pointed at a URL that, on re-fetch, no longer contains that text (superseded by the same advisory's v2.5 revision). | Rewrote the sentence as indirect/reported speech (no quotation marks, no claim of live verifiability) rather than a citable direct quote, since no dated/archiva | |
| F4 hallucinated-fact | · | GTG-20006 body/techniques[] asserted an 'adversary-in-the-middle session capture' mechanism and T1557 that belongs to a different, unrelated case study in the same Anthropic report, not to GTG-20006. | Replaced the claim with the source-supported browser-credential-theft detail and removed T1557 from techniques[]. | |
| F5 missing-citation | · | Revolut entry's detailed exposed-data-category sentence (including the Bitcoin/IBAN specifics) carried no citation of its own under the adjacency rule. | Added an inline Security Affairs citation directly to that sentence. | |
| F14 ? | · | (low confidence) BlueMoon's 'five clusters ... within two weeks'/'same fortnight' language was unsupported, all five clusters' own dated first-activity spans only six days (2026-08-28 to 2026-09-03), | Reverted title to 'within one week' and corrected the body to state UTA0560 started 2026-09-01, within that same one-week span. |
Iteration #5 NEEDS_FIXES cap-breach · 2 findings (truth=0, editorial=2, advisory=0) · Claude Sonnet 5 · 10m 23s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F5 missing-citation | · | Cisco Secure FMC entry's rewritten (iteration-4) main-analysis sentence about what Cisco's original advisory said carried no inline citation at all. | Added a dated citation ('as first published on 2026-08-03') to the same Cisco PSIRT advisory URL, framing it explicitly as the historical revision that carried | |
| F5 missing-citation | · | (low confidence) The entry's 2026-09-10 update body section still quoted 'not aware of any malicious use' in quotation marks, a phrase that no longer appears verbatim anywhere in the entry after this | Rephrased the 2026-09-10 update section's cross-reference to indirect speech ('the no-known-malicious-use framing'), declared under this run's own already-liste |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-13T0409Z-intel · Sonnet 5 · window 26 h · 2 entries published
Verification & coverage notes
Standard window (gap since the previous run about 24.0 hours, 26-hour recency window); today (2026-09-13) is a Sunday and the general threat-research publishing landscape was genuinely quiet in-window across the home-region/sector, research and incident domains, most sources' newest items clustered 2026-09-09 through 2026-09-11, confirmed by broad supplementary searches, not a fetch-tooling failure. No closed-source intake drops this run. No product/supplier watchlist configured in this deployment; the sector lens and general relevance discipline were applied throughout.
Two updates recover apparent gaps from the last three daily fires, disclosed transparently. A sweep of NCSC Switzerland's Cyber Security Hub surfaced two in-window (2026-09-11/2026-09-12) NCSC-CH advisories whose own cited primaries (Cisco Talos, Volexity) were dated 2026-09-09, a day or two outside the strict 26-hour window on their own. Given the NCSC-CH advisories themselves are in-window, the underlying material is a material development on two already-critical/high-severity, actively-exploited entries already carried here (the Cisco Secure FMC auth-bypass chain and the BlueMoon exploit kit) rather than a new, isolated finding, and leaving a verified, high-severity gap unrecovered when it is already in hand would be a blind spot on critical/high signal, both were composed as update records rather than held. A third update (GitLab CVE-2026-87719 / CVE-2026-88765) closes a narrower gap: CVE-2026-87719 was already named in the existing entry's own analysis but had never carried its own CVE record, and CVE-2026-88765 is a genuinely new same-release finding, both independently confirmed by NCSC Switzerland (for the former) and GitLab's own release notes.
One new entry rides the wider window this pipeline allows for an actively developing story, disclosed for the same reason. Anthropic's own GTG-20006 threat-intelligence report (published 2026-09-10, with edits as late as 19:29Z the same day) sits inside that wider window but outside the strict 26-hour one; it was fully verified against Anthropic's own primary plus two independent secondaries (The Hacker News, 2026-09-11; UNITED24 Media, 2026-09-12), confirming continued press attention through 2026-09-12 as the in-window hook. This is a globally significant, fully-verified nation-state AI-misuse campaign (Russia-linked, Midnight Blizzard overlap, 20+ government/military/diplomatic/drone-supply-chain targets) with no existing coverage here, and was selected as today's deep dive (category: apt-campaign) given its technical depth and defender-relevance to any organization's AI-agentic threat model.
- borderline-drop: Peter Gutmann's heise online interview naming "stunt cryptography" (CVE disclosures engineered for academic/media visibility over real exploitability), a genuinely interesting, single-source commentary/analysis piece on the CVE-disclosure ecosystem itself, not a technical vulnerability or threat-actor finding; it does not clear the relevance gate as tradecraft or detection-relevant analysis, and the quality-over-quantity bar resolves this doubt toward drop.
- Coverage-backlog: all twelve open rows re-checked this run at the standing low/cheap-recheck budget (Siemens S7 PLC advisory, Insel Gruppe/ServiceNow, Ixa Systems/TheGentlemen, UICC/Krybit, Kairos/Ville de Libercourt, VMware VMSA-2026-0007, Spring Ring, three residual research items, NovoCure, Medela/ShinyHunters, SafePay/reichenau.at, Ville du Tampon); no row cleared its blocking condition this run. One new row opened: GTG-27005 (same Anthropic report as today's deep dive, a freelance Russia-based team's autonomous drone-swarm targeting software), noted but not yet verified to full primary-source depth.
- Essential-coverage: missed=cisa-directives (persistent recipe gap, every transport tried returns only the site's filter-facet shell; no structured CISA directives feed exists yet).
- Aggregator-only sourcing (acknowledged, not fixed): the Revolut entry cites TechCrunch and Security Affairs only. The entry's actual primary is Revolut's own customer notification and spokesperson statement, quoted independently by both outlets; Revolut has published no reachable newsroom statement of its own (checked: revolut.com/newsroom/ 404s). This is the established single-source-victim carve-out; the entry already carries the corresponding verification value and a sourcing note naming the gap; not re-pivoted or dropped.
- Coverage gaps: reliaquest (client-rendered blog, the reader fallback resolved to an unrelated ad-tracker pixel); ssd-disclosure (individual advisory pages returned a browser-challenge page this run, though the listing itself was readable); tp-link-omada-psirt (URL now 404s, needs a canonical-URL probe); fortiguard.com FG-IR-26-164 through -174 (anti-bot challenge on every transport; CERT-FR's own advisory confirms the CVE list but carries no CVSS or exploitation-status detail).
← Operations dashboard · run-record contract: docs/pipeline.md