CTIPilot

2026-09-15T0410Z-intel

One pipeline fire, in full · intel run of 2026-09-15 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-15/2026-09-15T0410Z-intel.md.

Run telemetry

2026-09-15T0410Z-intel intel prompt v4.10 publish ok
1h 50m duration 3 published 1 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
5m 25s
Tool calls
3 WebFetch3 WebSearch26 bridge
Cited sources
3 of 23 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
5m 21s
Tool calls
0 WebFetch9 WebSearch22 bridge
Cited sources
1 of 27 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
6m 13s
Tool calls
0 WebFetch6 WebSearch19 bridge
Cited sources
1 of 14 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
10m 45s
Tool calls
20 WebFetch23 WebSearch13 bridge
Cited sources
5 of 14 in slice

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=6 e=3 a=0 #2 NEEDS_FIXES · Sonnet 5 · t=6 e=0 a=1 #3 NEEDS_FIXES · Sonnet 5 · t=4 e=1 a=0 #4 NEEDS_FIXES · Sonnet 5 · t=2 e=3 a=0 #5 NEEDS_FIXES · Sonnet 5 · t=3 e=4 a=2 #6 NEEDS_FIXES · Sonnet 5 · t=0 e=2 a=1

Deep dive

·

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

7 consecutive_quiet_periods incremented · 2 last_successful_fetch bumped + counters reset · 1 last_successful_fetch bumped + failure/quiet counters reset · 1 consecutive_fetch_failures incremented.

SourceChangeFrom → ToReason
cisco-psirtlast_successful_fetch bumped + failure/quiet counters reset2026-09-07 → 2026-09-15primary source of the published Cisco Secure Email Gateway entry
cisa-kevlast_successful_fetch bumped + counters reset2026-09-14 → 2026-09-15primary source (KEV addition) of the published Cisco Secure Email Gateway entry
advisories-ncsc-nllast_successful_fetch bumped + counters reset2026-09-14 → 2026-09-15corroborating source of the published Cisco Secure Email Gateway entry
tp-link-omada-psirtconsecutive_fetch_failures incremented3 → 4fresh extract recipe tried; advisory listing page now returns a site-rendered soft-404, not a transport failure; likely moved, no replacement URL found via WebSearch
cert-atconsecutive_quiet_periods incremented9 → 10cert.at/en/ returned only a JS-shell/navigation page via direct bridge fetch; no structured recipe yet
enisaconsecutive_quiet_periods incremented5 → 6enisa.europa.eu/news returned only a JS-shell Drupal SPA listing; no structured recipe yet
vulncheckconsecutive_quiet_periods incremented1 → 2vulncheck.com/blog served a stale cached snapshot (2022 page metadata)
zdiconsecutive_quiet_periods incremented1 → 2listing returned only out-of-window patch-Tuesday roundups
trellixconsecutive_quiet_periods incremented2 → 3trellix.com/blogs/ is JS-rendered with no article listing recoverable
gambit-securityconsecutive_quiet_periods incremented1 → 2gambit.security news/blog pages are JS-rendered with no article listing recoverable
paradigm-shift-researchconsecutive_quiet_periods incremented2 → 3ps.tc is a client-side-rendered SPA shell; no content recoverable

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Bridge invocations (this run)

18 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

14 ok3 item not found1 other
  • bridge:feed ×6
  • bridge:extract ×3
  • bridge:url ×3
  • bridge:jina ×2
  • bridge:ncsc-csh.recent ×1
  • bridge:cert-fr.avis-recent ×1
  • bridge:cert-fr.actu-recent ×1
  • bridge:cert-eu.recent ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 9 findings (truth=6, editorial=3, advisory=0) · Claude Sonnet 5 · 6m 10s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
The internal-vs-external 'peripheral system' ambiguity was attributed to Blick, but that detail is stated only by 20 Minuten.Re-attributed to 20 Minuten with a verbatim-checked evidence quote; Blick citation removed from that clause.
F3
claim-not-supported
·
The 'late August 2026' date for Brinztech's dark-web report was attributed to Blick, but only watson.ch states that date.Re-attributed to watson.ch with a verbatim-checked evidence quote.
F4
hallucinated-fact
·
Headline and body called Salt Switzerland's 'second-largest' mobile operator; the only source giving a rank (watson.ch) calls it the third-largest.Corrected to third-largest throughout (title unaffected, headline/summary/body), cited to watson.ch with a verbatim quote.
F4
hallucinated-fact
·
The entry asserted Salt is designated critical infrastructure subject to a BACS 24-hour reporting obligation; none of the five cited sources states this.Unsupported regulatory claim removed from the opening sentence and the Defender takeaway; Defender takeaway rewritten around what the sources do establish.
F4
hallucinated-fact
·
CVE-2026-76443 was typed sqli, but Cisco's advisory only assigns it to the broader CWE-707 grouping (command, SQL, code/eval injection, or XSS) without committing to SQL injection specifically.Type changed to rce (impact-level, non-overstated) and the affected field now states the CWE-707 ambiguity explicitly.
F4
hallucinated-fact
·
(low confidence) CVE-2026-20353 was typed dos, but its CWE-664 grouping also covers deserialization, a more severe category the source does not rule out; independently, its CVSS vector (full confidentType changed to rce (impact-level, non-overstated, matching the observed full-impact CVSS vector) and the affected field states the CWE-664 ambiguity explicitly
F5
missing-citation
·
The unsupported BACS 24-hour reporting claim also carried no inline citation.Resolved by removing the claim (see the paired F4 finding).
F8
needs-more-research
·
affected_products[] omitted Cisco Secure Email and Web Manager, which the body and five of six cves[] records establish is affected.Added to affected_products[].
F11
editorial-advisory
·
The run record's Verification & coverage notes leaked workflow-internal language: literal 'sub-agent', bare S1-S4 labels, and PD-code shorthand (PD-7, PD-8, PD-11(d)).Rewritten in plain language: sub-agent roles described by their research domain, PD-code references replaced with plain descriptions of the rule being applied.

Iteration #2 NEEDS_FIXES · 7 findings (truth=6, editorial=0, advisory=1) · Claude Sonnet 5 · 7m 34s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
'NCSC-NL's own advisory independently confirms observed exploitation' overstated the source: NCSC-NL relays Cisco's own exploitation claim rather than independently confirming it.Reworded to state NCSC-NL relays the same claim, with a verbatim-checked translated quote and original Dutch text added to evidence[] (fetched fresh via the NCS
F4
hallucinated-fact
·
The iteration-1 fix for CVE-2026-20353's type introduced an uncited claim attributing a specific CVSS vector to NVD, which is not among the entry's sources[].The NVD-attributed clause removed; the affected field now states only the CWE-664 grouping ambiguity, without citing an uncited authority.
F4
hallucinated-fact
·
CVE-2026-76441 was left typed auth-bypass despite Cisco's advisory only committing to the broader CWE-284 grouping, the same overstatement class already fixed for two sibling CVEs and now inconsistentType changed to rce for consistency with the sibling fixes; the affected field states the CWE-284 grouping ambiguity explicitly.
F14
?
·
(low confidence) An unsourced 'KEV's typical two-to-three weeks' comparison baseline; no cited source states a typical deadline range.Comparison removed; body now states only the sourced facts (added 2026-09-14, due 2026-09-17) without an uncited baseline.
F3
claim-not-supported
·
An 'as of 2026-09-14' framing was attached to a clause cited only to a 2026-09-11 source; no cited source is dated that late.Date qualifier removed.
F3
claim-not-supported
·
'Referencing their personal details' overstated watson.ch's cited Reddit quotes, which describe a rise in fraud calls but do not state the callers referenced specific personal data.Reworded to describe the reported rise in fraud calls without asserting the unsupported detail; the entry now states explicitly that no source establishes that
F11
editorial-advisory
·
ad-hoc-news.de was listed as a corroborating source but never cited in-body; a low-quality aggregator rehash with embedded lead-gen content, adding no support beyond Blick/20 Minuten/watson.ch.Removed from sources[].

Iteration #3 NEEDS_FIXES · 5 findings (truth=4, editorial=1, advisory=0) · Claude Sonnet 5 · 7m 59s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
cves[0].status and tags[] both carried no-patch for the exploited CVE-2026-76461, contradicting the same record's own fixed field (concrete patched releases exist) and the body text; Cisco's advisory Status changed to patch-available in cves[0].status and tags[]; the fixed field's trailing clause reworded to 'no workaround exists short of upgrading' to remov
F4
hallucinated-fact
·
CVE-2026-76441 and CVE-2026-20353 were typed rce (iteration 2's fix), which contradicted the entry's own neutral body wording ('an improper-access-control grouping', 'an uncontrolled-resource-consumptReverted CVE-2026-76441 to auth-bypass (matching CWE-284's own framing and the body wording) and CVE-2026-20353 to dos (matching CWE-664's own framing and the b
F14
?
·
(low confidence) 'Unusually short'/'unusually high urgency' quantifiers survived in the summary and immediate_action after the same unsourced comparison was removed from the body in iteration 2.Both instances reworded to state only the sourced facts (three-day deadline, due 2026-09-17) without an uncited baseline comparison.
F4
hallucinated-fact
·
(low confidence) The body's in-text translation of the NCSC-NL quote used a different verb ('states') than the entry's own evidence[] canonical translation of the identical Dutch sentence ('reports').Body wording changed to 'reports', matching the evidence[] record.
F10
missed-angle
·
(low-moderate confidence) A same-day, home-region incident (Swiss Bitcoin Pay, Neuchâtel, disclosed 2026-09-14) was absent from the run's coverage; independent verification confirmed it is real and clInvestigated and confirmed via the company's own statement and two independent outlets relaying it (Bitcoin Magazine, Bitcoin.com News); composed and published

Iteration #4 NEEDS_FIXES · 5 findings (truth=2, editorial=3, advisory=0) · Claude Sonnet 5 · 8m 43s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
techniques[] carried T1530 (Data from Cloud Storage Object), which no cited source states or implies; the entry's own body states no access vector or mechanism has been disclosed.Changed to T1213 (Data from Information Repositories), a more generic collection technique matching what the sources actually describe (specific customer-data c
F4
hallucinated-fact
·
The title and headline stated access and exposure as settled fact ('accesses internal systems, exposing...') while both cited sources hedge ('likely gained access', 'believes...may have accessed') andTitle and headline reworded to hedge consistently with the sources and the summary ('after a suspected intrusion, saying...may have been accessed').
F12
single-source-flag-missing
·
verification was set to single-source-victim for a one-assessor/two-publisher pattern structurally identical to this same run's Salt Mobile entry, which uses multi-source + sourcing_note for the same Aligned to multi-source + sourcing_note, matching the Salt entry's already-verified convention (credibility held at 2, reflecting one assessor across several pu
F6
strengthen-primary-source
·
Both cited articles link the company's own statement directly rather than citing it; a stronger primary exists.Fetched the company's own statement directly (x.com/SwissBitcoinPay/status/2099473448162488618) and re-sourced the entry around it as primary, with the two pres
F7
drop
·
(low-moderate confidence) Thin public-sector nexus (private crypto processor, no disclosed mechanism, no named actor); suggested considering priority: routine or a shorter treatment, or dropping.Declined: home-region nexus (a Swiss-domiciled company) is an independent, sufficient inclusion ground under the relevance gate's criterion for a confirmed inci

Iteration #5 NEEDS_FIXES · 9 findings (truth=3, editorial=4, advisory=2) · Claude Sonnet 5 · 8m 58s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
A 'more than 1,000 merchants across 21 countries' clause was cited to the X-post source, but the post carries no such figure; the fact belongs to the co-cited Bitcoin.com News article, a citation-adjaRe-attributed the clause to Bitcoin.com News and reworded to 'whose website claims...' to match how that outlet frames the figure.
F4
hallucinated-fact
·
Headline stated 'confirms customer data exposure' as settled fact while every cited source, including a fresh fetch of Salt's own notice, hedges it as only possible; the same overstatement class was aHeadline reworded to 'says customer data may be exposed', matching the entry's own already-hedged summary and body.
F4
hallucinated-fact
·
(low-moderate confidence) The registry entity's summary asserted settled 'exposing...hashed passwords' after the entry itself was hedged in iteration 4; the registry record was not updated to match.Registry summary reworded to 'may have been accessed', matching the entry's current hedging.
F12
single-source-flag-missing
·
verification was multi-source for a pattern the entry's own sourcing_note describes as one assessor (Salt) relayed by several publishers; store precedent for this exact shape uses single-source-victimChanged to single-source-victim.
F12
single-source-flag-missing
·
The same misclassification, propagated here in iteration 4 by matching it to the Salt entry's (incorrect) convention.Changed to single-source-victim, matching the corrected Salt entry.
F8
needs-more-research
·
Cisco's own hardening advisory states the identical 9.8 scores across four CWE groupings are an assigned ceiling per category ('the single most impactful underlying vulnerability within that specific Added the caveat, quoting Cisco's own table description, plus a new evidence[] record.
F17
?
·
(low confidence) Reliability differed (B vs C) between two entries resting on the same sourcing shape (a single victim's own statement, relayed by several publishers) with no stated rationale for treaAligned both to reliability B (a company's own formal public statement about its own incident).
F11
editorial-advisory
·
Literal tool-script and repo config/state file paths (tools/kev_window_diff.py, state/coverage_backlog.md, config/org-profile.yaml) leaked into the published Verification & coverage notes, the same deRewritten in plain operational language with no file paths.
F11
editorial-advisory
·
Internal pipeline-process narration ('the verification loop's third pass') leaked into reader-facing notes.Removed; reworded to state only that later verification caught the gap.

Iteration #6 NEEDS_FIXES cap-breach · 3 findings (truth=0, editorial=2, advisory=1) · Claude Sonnet 5 · 7m 35s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F10
missed-angle
·
An in-window NCSC Switzerland advisory update (2026-09-14) relaying Wiz Research's confirmation of exploitation and detection detail for CVE-2026-82329 was fetched by this run's own research but neverInvestigated both entries: the 2026-09-12 entry already fully covers Wiz's findings (cited as primary since its own composition). The 2026-09-01 entry did not y
F5
missing-citation
·
(low confidence) The Familea/Bruguières and Revolut-update-candidate paragraphs asserted facts with no inline citation; independently confirmed accurate via a web search, so not hallucinated, but unciAdded inline citations (Cyberattaque.org for Familea; BleepingComputer for the Revolut corroboration).
F11
editorial-advisory
·
A further instance of workflow-internal jargon (frontmatter field-name syntax, 'no-ops', pipeline source-tiering/recipe terminology, raw source-ID slugs) survived in sentences the iteration 1 and iterReworded the sourcing-note, watchlist and coverage-gaps paragraphs in plain language with human-readable source names and no field-name backticks.

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-15T0410Z-intel · Sonnet 5 · window 26 h · 3 entries published

Verification & coverage notes

Published: three new entries. 2026-09-15/cve-2026-76461-cisco-secure-email-gateway-sqli-root-rce (critical): CVE-2026-76461, an unauthenticated SQL-injection-to-root-RCE in Cisco Secure Email Gateway found by Cisco while investigating a real customer compromise, confirmed exploited, CISA KEV same day with a 3-day deadline; bundled with five further internally-discovered, non-exploited CVEs from a same-day hardening release. This entry is this run's disposition of the day's one new CISA Known Exploited Vulnerabilities catalog addition (CVE-2026-76461 added 2026-09-14, not previously covered; no other in-window KEV additions found). 2026-09-15/salt-mobile-peripheral-system-data-incident (notable): Salt Mobile SA (a major Swiss telecom operator) confirmed misuse of an existing access credential to an unnamed "peripheral system"; the home-region research and the incidents research independently surfaced this identical incident, merged into one entry drawing on both researchers' sourcing (Salt's own notice as primary, three independent Swiss outlets corroborating). 2026-09-15/swiss-bitcoin-pay-neuchatel-internal-systems-breach (notable): a home-region incident this run's research initially missed and later verification caught as a likely gap; independently confirmed via the company's own statement and two industry outlets relaying it, then composed and published (Swiss Bitcoin Pay, Neuchâtel, took its servers offline after a malicious user likely accessed internal systems, with customer email addresses, wallet addresses, IBANs, transaction history and hashed passwords possibly exposed; customer funds unaffected under its non-custodial design).

Updated: 2026-09-01/jfrog-artifactory-cve-2026-82329-default-config-admin-bypass. Later verification of this run's own output caught an in-window development this run's research had fetched but not acted on: NCSC Switzerland's advisory for this CVE was itself updated on 2026-09-14 to point to a Wiz Research report supplying the exact exploitation signature this entry had previously said the vendor withheld (an unauthenticated request to the registry-join endpoint returning an admin-scoped token, plus the specific post-exploitation actions attackers take with it). Composed as a changelog update with the new detection detail.

Out-of-window drop: the research pass covering research/investigative reporting surfaced a genuinely new September 2026 attribution (Nightingale Collective researchers tying the May-2026 RubyGems/GemStuffer spam campaign to a swarm of OpenAI's own testing agents, via a documentation-build RCE chain against RubyDoc.info) but flagged it itself as recency-borderline. All three of its sources (RubyGems Blog 2026-09-11, The Hacker News 2026-09-12, CSA Labs synthesis 2026-09-13) predate this run's 26-hour recency window (and its 72-hour allowance for an actively-developing story, whose cutoff was 2026-09-12T04:10Z) with no fresh in-window delta to anchor an update on any existing entry (the tracked GemStuffer tool entity or the OpenAI DSEWiki incident entity); dropped as out of window (primary sources 2026-09-11/12/13, a 26-hour recency window). This is a genuine, relevant miss by the runs of the past few days that never surfaced it in their own windows; flagging for the next quality audit's coverage re-sweep since the story is now stale for the daily gate but still worth an audit-level recovery given its relevance to the actively-developing AI-agent-containment storyline.

Not published, held for a later fire: Familea, a French municipal family-services SaaS platform with roughly 1,600 client collectivities, confirmed a cyberattack on its provider (Cyberattaque.org, 2026-09-14); the commune of Bruguières had its portal taken offline as a precaution. No mechanism, actor, or data-theft claim from any party yet, so an incident entry could not carry an evidence-bound attack-technique mapping without inventing one (same blocking condition as an already-open, structurally identical item on this store's watch queue). Logged for re-checking on a later fire.

Update candidate declined: the incidents research pass surfaced fresh corroboration (BleepingComputer, 2026-09-14, plus Help Net Security and Malwarebytes, all 2026-09-14) for the already-published 2026-09-13/revolut-fake-government-request-kyc-breach entry. On review, all three new outlets relay Revolut's own disclosure statement rather than independently assessing the incident (one assessor, several publishers), so the entry's verification and classification do not change; the only other candidate delta was a VIP-data-extortion claim sourced to a Telegram post and a Reddit thread, excluded as unverifiable social-media sourcing. No material new development clears the update bar; no changelog record added.

Watch-queue re-checks (9 of 13 open items): Kimberly-Clark/ShinyHunters (no change), Siemens S7 AA26-231A joint advisory (no change), Insel Gruppe/Inside IT Switzerland (no change; persistent whole-host rate-limiting on this article and, this run, on the Salt article too), Ixa Systems SA/TheGentlemen (no change), UICC/Krybit (no change), Ville de Libercourt/Kairos (no change), Medela AG/ShinyHunters (no change), reichenau.at/SafePay (no change), Ville du Tampon (no change). Four other open items (a VMware advisory, a Teams-vishing campaign, four research-tradecraft items held below the recovery bar, and a medtech regulatory filing) were not re-probed this run; no research capacity remained after the primary sweep and this run's own findings. Low priority, carry forward.

Sourcing note: the Salt Mobile SA and Swiss Bitcoin Pay entries each rest on a single company's own statement about its own incident, relayed by several publishers rather than independently assessed by any of them; the JFrog update above rests on a single independent research team's (Wiz Research's) own technical analysis, relayed by a national-CERT advisory rather than independently re-confirmed. In each case credibility is held at 2, not 1, per the classification rule ("ask who looked, not how many pages say it").

Watchlist: no product or supplier watchlist configured for this deployment; both sweeps found nothing to check against.

Coverage gaps: TP-Link Omada's advisory listing page now returns a site-rendered "page not found" instead of its advisory list, suggesting the page has moved; no replacement URL found. CERT.at and ENISA's own news listings returned only JavaScript-rendered navigation shells with no readable article content on the transport used this run. Five vendor/research blogs (VulnCheck, Zero Day Initiative, Trellix, Gambit Security, Paradigm Shift Research) returned stale, out-of-window, or unrenderable content on the transport used this run. Inside IT Switzerland's article pages continue to rate-limit individual article reads while its headline listing stays reachable.

Essential-coverage: every mandatory national-CERT and vendor-advisory source was checked this run; no misses.

← Operations dashboard · run-record contract: docs/pipeline.md