2026-09-15T0410Z-intel
One pipeline fire, in full · intel run of 2026-09-15 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-15/2026-09-15T0410Z-intel.md.
Run telemetry
- Items returned
- 1
- Duration
- 5m 25s
- Tool calls
- 3 WebFetch3 WebSearch26 bridge
- Cited sources
- 3 of 23 in slice
- Items returned
- 1
- Duration
- 5m 21s
- Tool calls
- 0 WebFetch9 WebSearch22 bridge
- Cited sources
- 1 of 27 in slice
- Items returned
- 1
- Duration
- 6m 13s
- Tool calls
- 0 WebFetch6 WebSearch19 bridge
- Cited sources
- 1 of 14 in slice
- Items returned
- 3
- Duration
- 10m 45s
- Tool calls
- 20 WebFetch23 WebSearch13 bridge
- Cited sources
- 5 of 14 in slice
Verification
Deep dive
·
Entries this run published (3) and updated (1)
- CVE-2026-82329, JFrog Artifactory: an unauthenticated attacker gets administrative access under default configuration (CVSS 9.8) vulnerability critical update
- CVE-2026-76461: Cisco Secure Email Gateway unauthenticated SQL injection in email parsing reaches root command execution, exploited before disclosure (CVSS 9.8) vulnerability critical
- Salt confirms misuse of an existing access credential to an unnamed 'peripheral system', up to 1.09 million Swiss mobile customers' records reportedly at risk incident notable
- Swiss Bitcoin Pay (Neuchâtel) shuts down its servers after a suspected intrusion, saying IBANs, wallet addresses and hashed passwords may have been accessed incident notable
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
7 consecutive_quiet_periods incremented · 2 last_successful_fetch bumped + counters reset · 1 last_successful_fetch bumped + failure/quiet counters reset · 1 consecutive_fetch_failures incremented.
| Source | Change | From → To | Reason |
|---|---|---|---|
| cisco-psirt | last_successful_fetch bumped + failure/quiet counters reset | 2026-09-07 → 2026-09-15 | primary source of the published Cisco Secure Email Gateway entry |
| cisa-kev | last_successful_fetch bumped + counters reset | 2026-09-14 → 2026-09-15 | primary source (KEV addition) of the published Cisco Secure Email Gateway entry |
| advisories-ncsc-nl | last_successful_fetch bumped + counters reset | 2026-09-14 → 2026-09-15 | corroborating source of the published Cisco Secure Email Gateway entry |
| tp-link-omada-psirt | consecutive_fetch_failures incremented | 3 → 4 | fresh extract recipe tried; advisory listing page now returns a site-rendered soft-404, not a transport failure; likely moved, no replacement URL found via WebSearch |
| cert-at | consecutive_quiet_periods incremented | 9 → 10 | cert.at/en/ returned only a JS-shell/navigation page via direct bridge fetch; no structured recipe yet |
| enisa | consecutive_quiet_periods incremented | 5 → 6 | enisa.europa.eu/news returned only a JS-shell Drupal SPA listing; no structured recipe yet |
| vulncheck | consecutive_quiet_periods incremented | 1 → 2 | vulncheck.com/blog served a stale cached snapshot (2022 page metadata) |
| zdi | consecutive_quiet_periods incremented | 1 → 2 | listing returned only out-of-window patch-Tuesday roundups |
| trellix | consecutive_quiet_periods incremented | 2 → 3 | trellix.com/blogs/ is JS-rendered with no article listing recoverable |
| gambit-security | consecutive_quiet_periods incremented | 1 → 2 | gambit.security news/blog pages are JS-rendered with no article listing recoverable |
| paradigm-shift-research | consecutive_quiet_periods incremented | 2 → 3 | ps.tc is a client-side-rendered SPA shell; no content recoverable |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.
Bridge invocations (this run)
18 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- bridge:feed ×6
- bridge:extract ×3
- bridge:url ×3
- bridge:jina ×2
- bridge:ncsc-csh.recent ×1
- bridge:cert-fr.avis-recent ×1
- bridge:cert-fr.actu-recent ×1
- bridge:cert-eu.recent ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 9 findings (truth=6, editorial=3, advisory=0) · Claude Sonnet 5 · 6m 10s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | The internal-vs-external 'peripheral system' ambiguity was attributed to Blick, but that detail is stated only by 20 Minuten. | Re-attributed to 20 Minuten with a verbatim-checked evidence quote; Blick citation removed from that clause. | |
| F3 claim-not-supported | · | The 'late August 2026' date for Brinztech's dark-web report was attributed to Blick, but only watson.ch states that date. | Re-attributed to watson.ch with a verbatim-checked evidence quote. | |
| F4 hallucinated-fact | · | Headline and body called Salt Switzerland's 'second-largest' mobile operator; the only source giving a rank (watson.ch) calls it the third-largest. | Corrected to third-largest throughout (title unaffected, headline/summary/body), cited to watson.ch with a verbatim quote. | |
| F4 hallucinated-fact | · | The entry asserted Salt is designated critical infrastructure subject to a BACS 24-hour reporting obligation; none of the five cited sources states this. | Unsupported regulatory claim removed from the opening sentence and the Defender takeaway; Defender takeaway rewritten around what the sources do establish. | |
| F4 hallucinated-fact | · | CVE-2026-76443 was typed sqli, but Cisco's advisory only assigns it to the broader CWE-707 grouping (command, SQL, code/eval injection, or XSS) without committing to SQL injection specifically. | Type changed to rce (impact-level, non-overstated) and the affected field now states the CWE-707 ambiguity explicitly. | |
| F4 hallucinated-fact | · | (low confidence) CVE-2026-20353 was typed dos, but its CWE-664 grouping also covers deserialization, a more severe category the source does not rule out; independently, its CVSS vector (full confident | Type changed to rce (impact-level, non-overstated, matching the observed full-impact CVSS vector) and the affected field states the CWE-664 ambiguity explicitly | |
| F5 missing-citation | · | The unsupported BACS 24-hour reporting claim also carried no inline citation. | Resolved by removing the claim (see the paired F4 finding). | |
| F8 needs-more-research | · | affected_products[] omitted Cisco Secure Email and Web Manager, which the body and five of six cves[] records establish is affected. | Added to affected_products[]. | |
| F11 editorial-advisory | · | The run record's Verification & coverage notes leaked workflow-internal language: literal 'sub-agent', bare S1-S4 labels, and PD-code shorthand (PD-7, PD-8, PD-11(d)). | Rewritten in plain language: sub-agent roles described by their research domain, PD-code references replaced with plain descriptions of the rule being applied. |
Iteration #2 NEEDS_FIXES · 7 findings (truth=6, editorial=0, advisory=1) · Claude Sonnet 5 · 7m 34s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | 'NCSC-NL's own advisory independently confirms observed exploitation' overstated the source: NCSC-NL relays Cisco's own exploitation claim rather than independently confirming it. | Reworded to state NCSC-NL relays the same claim, with a verbatim-checked translated quote and original Dutch text added to evidence[] (fetched fresh via the NCS | |
| F4 hallucinated-fact | · | The iteration-1 fix for CVE-2026-20353's type introduced an uncited claim attributing a specific CVSS vector to NVD, which is not among the entry's sources[]. | The NVD-attributed clause removed; the affected field now states only the CWE-664 grouping ambiguity, without citing an uncited authority. | |
| F4 hallucinated-fact | · | CVE-2026-76441 was left typed auth-bypass despite Cisco's advisory only committing to the broader CWE-284 grouping, the same overstatement class already fixed for two sibling CVEs and now inconsistent | Type changed to rce for consistency with the sibling fixes; the affected field states the CWE-284 grouping ambiguity explicitly. | |
| F14 ? | · | (low confidence) An unsourced 'KEV's typical two-to-three weeks' comparison baseline; no cited source states a typical deadline range. | Comparison removed; body now states only the sourced facts (added 2026-09-14, due 2026-09-17) without an uncited baseline. | |
| F3 claim-not-supported | · | An 'as of 2026-09-14' framing was attached to a clause cited only to a 2026-09-11 source; no cited source is dated that late. | Date qualifier removed. | |
| F3 claim-not-supported | · | 'Referencing their personal details' overstated watson.ch's cited Reddit quotes, which describe a rise in fraud calls but do not state the callers referenced specific personal data. | Reworded to describe the reported rise in fraud calls without asserting the unsupported detail; the entry now states explicitly that no source establishes that | |
| F11 editorial-advisory | · | ad-hoc-news.de was listed as a corroborating source but never cited in-body; a low-quality aggregator rehash with embedded lead-gen content, adding no support beyond Blick/20 Minuten/watson.ch. | Removed from sources[]. |
Iteration #3 NEEDS_FIXES · 5 findings (truth=4, editorial=1, advisory=0) · Claude Sonnet 5 · 7m 59s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | cves[0].status and tags[] both carried no-patch for the exploited CVE-2026-76461, contradicting the same record's own fixed field (concrete patched releases exist) and the body text; Cisco's advisory | Status changed to patch-available in cves[0].status and tags[]; the fixed field's trailing clause reworded to 'no workaround exists short of upgrading' to remov | |
| F4 hallucinated-fact | · | CVE-2026-76441 and CVE-2026-20353 were typed rce (iteration 2's fix), which contradicted the entry's own neutral body wording ('an improper-access-control grouping', 'an uncontrolled-resource-consumpt | Reverted CVE-2026-76441 to auth-bypass (matching CWE-284's own framing and the body wording) and CVE-2026-20353 to dos (matching CWE-664's own framing and the b | |
| F14 ? | · | (low confidence) 'Unusually short'/'unusually high urgency' quantifiers survived in the summary and immediate_action after the same unsourced comparison was removed from the body in iteration 2. | Both instances reworded to state only the sourced facts (three-day deadline, due 2026-09-17) without an uncited baseline comparison. | |
| F4 hallucinated-fact | · | (low confidence) The body's in-text translation of the NCSC-NL quote used a different verb ('states') than the entry's own evidence[] canonical translation of the identical Dutch sentence ('reports'). | Body wording changed to 'reports', matching the evidence[] record. | |
| F10 missed-angle | · | (low-moderate confidence) A same-day, home-region incident (Swiss Bitcoin Pay, Neuchâtel, disclosed 2026-09-14) was absent from the run's coverage; independent verification confirmed it is real and cl | Investigated and confirmed via the company's own statement and two independent outlets relaying it (Bitcoin Magazine, Bitcoin.com News); composed and published |
Iteration #4 NEEDS_FIXES · 5 findings (truth=2, editorial=3, advisory=0) · Claude Sonnet 5 · 8m 43s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | techniques[] carried T1530 (Data from Cloud Storage Object), which no cited source states or implies; the entry's own body states no access vector or mechanism has been disclosed. | Changed to T1213 (Data from Information Repositories), a more generic collection technique matching what the sources actually describe (specific customer-data c | |
| F4 hallucinated-fact | · | The title and headline stated access and exposure as settled fact ('accesses internal systems, exposing...') while both cited sources hedge ('likely gained access', 'believes...may have accessed') and | Title and headline reworded to hedge consistently with the sources and the summary ('after a suspected intrusion, saying...may have been accessed'). | |
| F12 single-source-flag-missing | · | verification was set to single-source-victim for a one-assessor/two-publisher pattern structurally identical to this same run's Salt Mobile entry, which uses multi-source + sourcing_note for the same | Aligned to multi-source + sourcing_note, matching the Salt entry's already-verified convention (credibility held at 2, reflecting one assessor across several pu | |
| F6 strengthen-primary-source | · | Both cited articles link the company's own statement directly rather than citing it; a stronger primary exists. | Fetched the company's own statement directly (x.com/SwissBitcoinPay/status/2099473448162488618) and re-sourced the entry around it as primary, with the two pres | |
| F7 drop | · | (low-moderate confidence) Thin public-sector nexus (private crypto processor, no disclosed mechanism, no named actor); suggested considering priority: routine or a shorter treatment, or dropping. | Declined: home-region nexus (a Swiss-domiciled company) is an independent, sufficient inclusion ground under the relevance gate's criterion for a confirmed inci |
Iteration #5 NEEDS_FIXES · 9 findings (truth=3, editorial=4, advisory=2) · Claude Sonnet 5 · 8m 58s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | A 'more than 1,000 merchants across 21 countries' clause was cited to the X-post source, but the post carries no such figure; the fact belongs to the co-cited Bitcoin.com News article, a citation-adja | Re-attributed the clause to Bitcoin.com News and reworded to 'whose website claims...' to match how that outlet frames the figure. | |
| F4 hallucinated-fact | · | Headline stated 'confirms customer data exposure' as settled fact while every cited source, including a fresh fetch of Salt's own notice, hedges it as only possible; the same overstatement class was a | Headline reworded to 'says customer data may be exposed', matching the entry's own already-hedged summary and body. | |
| F4 hallucinated-fact | · | (low-moderate confidence) The registry entity's summary asserted settled 'exposing...hashed passwords' after the entry itself was hedged in iteration 4; the registry record was not updated to match. | Registry summary reworded to 'may have been accessed', matching the entry's current hedging. | |
| F12 single-source-flag-missing | · | verification was multi-source for a pattern the entry's own sourcing_note describes as one assessor (Salt) relayed by several publishers; store precedent for this exact shape uses single-source-victim | Changed to single-source-victim. | |
| F12 single-source-flag-missing | · | The same misclassification, propagated here in iteration 4 by matching it to the Salt entry's (incorrect) convention. | Changed to single-source-victim, matching the corrected Salt entry. | |
| F8 needs-more-research | · | Cisco's own hardening advisory states the identical 9.8 scores across four CWE groupings are an assigned ceiling per category ('the single most impactful underlying vulnerability within that specific | Added the caveat, quoting Cisco's own table description, plus a new evidence[] record. | |
| F17 ? | · | (low confidence) Reliability differed (B vs C) between two entries resting on the same sourcing shape (a single victim's own statement, relayed by several publishers) with no stated rationale for trea | Aligned both to reliability B (a company's own formal public statement about its own incident). | |
| F11 editorial-advisory | · | Literal tool-script and repo config/state file paths (tools/kev_window_diff.py, state/coverage_backlog.md, config/org-profile.yaml) leaked into the published Verification & coverage notes, the same de | Rewritten in plain operational language with no file paths. | |
| F11 editorial-advisory | · | Internal pipeline-process narration ('the verification loop's third pass') leaked into reader-facing notes. | Removed; reworded to state only that later verification caught the gap. |
Iteration #6 NEEDS_FIXES cap-breach · 3 findings (truth=0, editorial=2, advisory=1) · Claude Sonnet 5 · 7m 35s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F10 missed-angle | · | An in-window NCSC Switzerland advisory update (2026-09-14) relaying Wiz Research's confirmation of exploitation and detection detail for CVE-2026-82329 was fetched by this run's own research but never | Investigated both entries: the 2026-09-12 entry already fully covers Wiz's findings (cited as primary since its own composition). The 2026-09-01 entry did not y | |
| F5 missing-citation | · | (low confidence) The Familea/Bruguières and Revolut-update-candidate paragraphs asserted facts with no inline citation; independently confirmed accurate via a web search, so not hallucinated, but unci | Added inline citations (Cyberattaque.org for Familea; BleepingComputer for the Revolut corroboration). | |
| F11 editorial-advisory | · | A further instance of workflow-internal jargon (frontmatter field-name syntax, 'no-ops', pipeline source-tiering/recipe terminology, raw source-ID slugs) survived in sentences the iteration 1 and iter | Reworded the sourcing-note, watchlist and coverage-gaps paragraphs in plain language with human-readable source names and no field-name backticks. |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-15T0410Z-intel · Sonnet 5 · window 26 h · 3 entries published
Verification & coverage notes
Published: three new entries. 2026-09-15/cve-2026-76461-cisco-secure-email-gateway-sqli-root-rce (critical): CVE-2026-76461, an unauthenticated SQL-injection-to-root-RCE in Cisco Secure Email Gateway found by Cisco while investigating a real customer compromise, confirmed exploited, CISA KEV same day with a 3-day deadline; bundled with five further internally-discovered, non-exploited CVEs from a same-day hardening release. This entry is this run's disposition of the day's one new CISA Known Exploited Vulnerabilities catalog addition (CVE-2026-76461 added 2026-09-14, not previously covered; no other in-window KEV additions found). 2026-09-15/salt-mobile-peripheral-system-data-incident (notable): Salt Mobile SA (a major Swiss telecom operator) confirmed misuse of an existing access credential to an unnamed "peripheral system"; the home-region research and the incidents research independently surfaced this identical incident, merged into one entry drawing on both researchers' sourcing (Salt's own notice as primary, three independent Swiss outlets corroborating). 2026-09-15/swiss-bitcoin-pay-neuchatel-internal-systems-breach (notable): a home-region incident this run's research initially missed and later verification caught as a likely gap; independently confirmed via the company's own statement and two industry outlets relaying it, then composed and published (Swiss Bitcoin Pay, Neuchâtel, took its servers offline after a malicious user likely accessed internal systems, with customer email addresses, wallet addresses, IBANs, transaction history and hashed passwords possibly exposed; customer funds unaffected under its non-custodial design).
Updated: 2026-09-01/jfrog-artifactory-cve-2026-82329-default-config-admin-bypass. Later verification of this run's own output caught an in-window development this run's research had fetched but not acted on: NCSC Switzerland's advisory for this CVE was itself updated on 2026-09-14 to point to a Wiz Research report supplying the exact exploitation signature this entry had previously said the vendor withheld (an unauthenticated request to the registry-join endpoint returning an admin-scoped token, plus the specific post-exploitation actions attackers take with it). Composed as a changelog update with the new detection detail.
Out-of-window drop: the research pass covering research/investigative reporting surfaced a genuinely new September 2026 attribution (Nightingale Collective researchers tying the May-2026 RubyGems/GemStuffer spam campaign to a swarm of OpenAI's own testing agents, via a documentation-build RCE chain against RubyDoc.info) but flagged it itself as recency-borderline. All three of its sources (RubyGems Blog 2026-09-11, The Hacker News 2026-09-12, CSA Labs synthesis 2026-09-13) predate this run's 26-hour recency window (and its 72-hour allowance for an actively-developing story, whose cutoff was 2026-09-12T04:10Z) with no fresh in-window delta to anchor an update on any existing entry (the tracked GemStuffer tool entity or the OpenAI DSEWiki incident entity); dropped as out of window (primary sources 2026-09-11/12/13, a 26-hour recency window). This is a genuine, relevant miss by the runs of the past few days that never surfaced it in their own windows; flagging for the next quality audit's coverage re-sweep since the story is now stale for the daily gate but still worth an audit-level recovery given its relevance to the actively-developing AI-agent-containment storyline.
Not published, held for a later fire: Familea, a French municipal family-services SaaS platform with roughly 1,600 client collectivities, confirmed a cyberattack on its provider (Cyberattaque.org, 2026-09-14); the commune of Bruguières had its portal taken offline as a precaution. No mechanism, actor, or data-theft claim from any party yet, so an incident entry could not carry an evidence-bound attack-technique mapping without inventing one (same blocking condition as an already-open, structurally identical item on this store's watch queue). Logged for re-checking on a later fire.
Update candidate declined: the incidents research pass surfaced fresh corroboration (BleepingComputer, 2026-09-14, plus Help Net Security and Malwarebytes, all 2026-09-14) for the already-published 2026-09-13/revolut-fake-government-request-kyc-breach entry. On review, all three new outlets relay Revolut's own disclosure statement rather than independently assessing the incident (one assessor, several publishers), so the entry's verification and classification do not change; the only other candidate delta was a VIP-data-extortion claim sourced to a Telegram post and a Reddit thread, excluded as unverifiable social-media sourcing. No material new development clears the update bar; no changelog record added.
Watch-queue re-checks (9 of 13 open items): Kimberly-Clark/ShinyHunters (no change), Siemens S7 AA26-231A joint advisory (no change), Insel Gruppe/Inside IT Switzerland (no change; persistent whole-host rate-limiting on this article and, this run, on the Salt article too), Ixa Systems SA/TheGentlemen (no change), UICC/Krybit (no change), Ville de Libercourt/Kairos (no change), Medela AG/ShinyHunters (no change), reichenau.at/SafePay (no change), Ville du Tampon (no change). Four other open items (a VMware advisory, a Teams-vishing campaign, four research-tradecraft items held below the recovery bar, and a medtech regulatory filing) were not re-probed this run; no research capacity remained after the primary sweep and this run's own findings. Low priority, carry forward.
Sourcing note: the Salt Mobile SA and Swiss Bitcoin Pay entries each rest on a single company's own statement about its own incident, relayed by several publishers rather than independently assessed by any of them; the JFrog update above rests on a single independent research team's (Wiz Research's) own technical analysis, relayed by a national-CERT advisory rather than independently re-confirmed. In each case credibility is held at 2, not 1, per the classification rule ("ask who looked, not how many pages say it").
Watchlist: no product or supplier watchlist configured for this deployment; both sweeps found nothing to check against.
Coverage gaps: TP-Link Omada's advisory listing page now returns a site-rendered "page not found" instead of its advisory list, suggesting the page has moved; no replacement URL found. CERT.at and ENISA's own news listings returned only JavaScript-rendered navigation shells with no readable article content on the transport used this run. Five vendor/research blogs (VulnCheck, Zero Day Initiative, Trellix, Gambit Security, Paradigm Shift Research) returned stale, out-of-window, or unrenderable content on the transport used this run. Inside IT Switzerland's article pages continue to rate-limit individual article reads while its headline listing stays reachable.
Essential-coverage: every mandatory national-CERT and vendor-advisory source was checked this run; no misses.
← Operations dashboard · run-record contract: docs/pipeline.md