2026-09-16T0409Z-intel
One pipeline fire, in full · intel run of 2026-09-16 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-16/2026-09-16T0409Z-intel.md.
Run telemetry
- Items returned
- 3
- Duration
- 9m 42s
- Tool calls
- 0 WebFetch5 WebSearch45 bridge
- Cited sources
- 2 of 25 in slice
- Items returned
- 2
- Duration
- 6m 21s
- Tool calls
- 0 WebFetch7 WebSearch27 bridge
- Cited sources
- 2 of 29 in slice
- Items returned
- 2
- Duration
- 9m 49s
- Tool calls
- 8 WebFetch12 WebSearch14 bridge
- Cited sources
- 2 of 16 in slice
- Items returned
- 2
- Duration
- 8m 02s
- Tool calls
- 0 WebFetch12 WebSearch22 bridge
- Cited sources
- 1 of 16 in slice
Verification
Deep dive
·
Entries this run published (2) and updated (2)
- CVE-2026-85706, GitLab CE/EE: unauthenticated path traversal in the repository commits API reads arbitrary server files, and honeypots caught exploitation attempts one day after the patch (CVSS 10.0) vulnerability high update
- Revolut discloses a customer KYC data breach after fulfilling a fraudulent request sent from inside a genuine government agency's own email domain incident notable update
- CHOSEN BRICK; Iranian state cyber actors run Telegram-C2 Windows spyware against dissidents, activists and journalists, per joint NCSC-UK/FBI/AIVD advisory threat notable
- BambooToken, a previously undocumented MQTT-based malware framework sideloads via a signed Chinese hardware-token utility to control Windows and Linux hosts threat notable
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
5 last_successful_fetch bumped + failure/quiet counters reset · 1 consecutive_fetch_failures incremented (404 on every attempted path).
| Source | Change | From → To | Reason |
|---|---|---|---|
| ncsc-ch-security-hub | last_successful_fetch bumped + failure/quiet counters reset | 2026-09-14 → 2026-09-16 | primary source of the CVE-2026-85706/87719 GitLab update record |
| ncsc-uk | last_successful_fetch bumped + failure/quiet counters reset | 2026-09-14 → 2026-09-16 | primary source of the published CHOSEN BRICK entry |
| databreaches-net | last_successful_fetch bumped + failure/quiet counters reset | 2026-09-11 → 2026-09-16 | primary source of the Revolut extortion-escalation update record |
| bleepingcomputer | last_successful_fetch bumped + failure/quiet counters reset | 2026-09-10 → 2026-09-16 | corroborating source for the published BambooToken entry |
| therecord | last_successful_fetch bumped + failure/quiet counters reset | 2026-09-13 → 2026-09-16 | corroborating source for the published CHOSEN BRICK entry |
| tp-link-omada-psirt | consecutive_fetch_failures incremented (404 on every attempted path) | 4 → 5 | S1's 4th/5th consecutive miss; the vendor's Nuxt SPA support portal appears to have moved its advisory-index route to a locale-prefixed path this recipe does not resolve, needs a recipe review, not yet demoted (candidate status, no working recipe ever established) |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 8 findings (truth=5, editorial=2, advisory=1) · Claude Sonnet 5 · 7m 29s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware | Body claimed the additional-malware drop path's deliberate space was 'created to look plausible while evading path-matching detections'; NCSC UK's own text only says it was 'specifically created by th | Rephrased to state only what NCSC UK's advisory says, dropping the invented evasion rationale. |
| F3 claim-not-supported | · | 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload | Body/summary attached the campaign's July 2026 end-date to 'a July 2026 Linux variant'; Lumen dates the Linux sample to December 2025, and July 2026 belongs to the overall campaign window only. | Corrected frontmatter summary, registry entity summary and body to separate the campaign's July 2026 end-date from the Linux sample's December 2025 first-observ |
| F4 hallucinated-fact | · | 2026-09-12/cve-2026-85706-gitlab-unauth-path-traversal-file-read | Main-analysis paragraph still said CVE-2026-87719 'is not KEV-listed or confirmed exploited' after the new Update section and cves[].status both recorded it as exploited, an uncorrected internal contr | Edited the original paragraph's sentence to reflect the current state and note the thinner evidentiary basis; declared in the record's fields. |
| F4 hallucinated-fact | · | 2026-09-12/cve-2026-85706-gitlab-unauth-path-traversal-file-read | The 2026-09-16 update record's fields list omitted sources and evidence, both of which the record actually changed (two new sources[] records, two new evidence[] quotes). | Added sources and evidence to the record's fields list. |
| F14 quantifier-without-source | · | 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload | Body said 'a dozen ... across Asia and one in South America'; Lumen's own text says 'a handful' in South America and names two distinct victims (Argentina, Chile). | Corrected to 'a handful' and named the two South American victims Lumen's report gives. |
| F5 missing-citation | · | 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload | Two body paragraphs of specific technical/telemetry claims carried no inline citation to Lumen's report. | Added inline citations throughout both paragraphs. |
| F8 needs-more-research | · | 2026-09-12/cve-2026-85706-gitlab-unauth-path-traversal-file-read | CVE-2026-87719's exploited status rests solely on an 8-word NCSC-CH edit-history annotation with no elaboration, no KEV listing and no second source, materially thinner support than CVE-2026-85706's o | Made the evidentiary asymmetry explicit in both the main analysis and the Update section rather than presenting both CVEs' exploited status as equally well-esta |
| F11 editorial-advisory | · | 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware | Non-deep-dive entry inlines roughly 15 bare ATT&CK ids into prose, mirroring NCSC's own table rather than keeping ids in techniques[] metadata. | Left as-is per the verifier's own note that this is advisory-only and mirrors the primary source's own table structure. |
Iteration #2 NEEDS_FIXES · 3 findings (truth=2, editorial=1, advisory=0) · Claude Sonnet 5 · 9m 18s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload | 'BIOS' was spliced into the initial WMI-enumeration clause; Lumen's text lists BIOS only under the separate ONLINE handler's heartbeat parameters. | Restored the initial WMI-enumeration clause to Lumen's own list (OS info, computer system product details, product key, serial number, licensing information) an |
| F3 claim-not-supported | · | 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload | 'mostly MikroTik and DrayTek devices in Singapore, Cambodia and Vietnam' was generalized to the full 150-router population; Lumen attributes that device-type/geo detail only to 'a handful' of those IP | Rewrote the sentence to scope the MikroTik/DrayTek/geo detail to the handful with persistent connections, not the full 150-router population. |
| F10 missed-angle | · | 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware | (low confidence) The Record, already cited, carries MOIS/Handala Hack/Homeland Justice attribution context via an FBI March 2026 flash warning that the entry omitted entirely. | Added a sourced sentence citing The Record's account of the FBI's MOIS attribution and the Handala Hack/Homeland Justice connection, verified verbatim against t |
Iteration #3 CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Sonnet 5 · 8m 27s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | · | runs/2026-09-16/2026-09-16T0409Z-intel.md | The run record's own Verification & coverage notes body used workflow-internal shorthand (S1/S2/S3/S5 sub-agent labels) in reader-facing prose. | Rewrote the body in plain language ("the active-threats/vulns pass", "the home-region/sector pass", etc.) matching the 2026-09-15 run record's precedent; no fac |
Iteration #4 NEEDS_FIXES · 4 findings (truth=3, editorial=0, advisory=1) · Claude Sonnet 5 · 7m 34s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware | Entry attached NCSC's 'in at least one sample' hedge to the additional-malware drop path clause; NCSC's own text attaches that hedge to the data-wiping-functionality clause and separately calls the dr | Rewrote the sentence so the drop path is described as the most commonly observed one, and the 'at least one sample' hedge attaches only to the data-wiping paylo |
| F3 claim-not-supported | · | 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware | (low confidence) Entry stated the mutex's purpose was 'to prevent re-infecting an already-compromised host'; NCSC's advisory states only that CHOSEN BRICK registers mutexes, without stating this purpo | Removed the unsupported purpose clause; the sentence now states only that a mutex is registered, per NCSC's own ATT&CK-table procedure text. |
| F3 claim-not-supported | · | 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload | The claim that researchers 'could not confirm whether these modules were ever operational or remain under development' was cited to Lumen alone; that exact framing is BleepingComputer's, not Lumen's o | Re-attributed the claim to BleepingComputer, keeping the Lumen citation only for the dead-code strings themselves. |
| F11 editorial-advisory | · | 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware | Reconfirms iteration 1's F11 (bare ATT&CK ids inlined in prose); no new content. | None, already reviewed and deliberately left as-is per iteration 1. |
Iteration #5 NEEDS_FIXES cap-breach · 3 findings (truth=0, editorial=2, advisory=1) · Claude Sonnet 5 · 6m 53s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F5 missing-citation | · | 2026-09-12/cve-2026-85706-gitlab-unauth-path-traversal-file-read | (low confidence) The HackerOne/s3ntago attribution sentence carried no inline citation; the preceding citation in the paragraph is watchTowr, which does not mention it. | Added the GitLab citation to the sentence, independently re-verified against GitLab's own release notes (the 's3ntago' credit line is present under CVE-2026-857 |
| F10 missed-angle | · | (candidate flagged by the verifier) Swiss Bitcoin Pay internal-systems breach | (moderate confidence) Verifier flagged a same-window dailyhodl.com article on a Neuchatel fintech breach as apparently unconsidered. | DECLINED as a false positive; this incident is not a new candidate; it is already published as entries/2026-09-15/swiss-bitcoin-pay-neuchatel-internal-systems-b |
| F11 editorial-advisory | · | 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware | Reconfirms iterations 1/4's advisory finding on inline ATT&CK ids; no new content. | None, already reviewed and deliberately left as-is. |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-16T0409Z-intel · Sonnet 5 · window 26 h · 2 entries published
Verification & coverage notes
Standard window (gap_hours=24, window_hours=26). All four research passes returned within the 45-minute cap; no closed-source intake this run (no intel/ drops). CHOSEN BRICK (the joint NCSC UK/FBI/AIVD Iranian-spyware advisory) was independently surfaced by three of the four research passes (the active-threats/vulns pass, the home-region/sector pass, and the research/investigative-reporting pass), composed once as a single entry from the converged findings, citing NCSC UK as the primary (single-source-national-cert carve-out; FBI and AIVD co-authored the same joint publication rather than three independent assessments).
Two new entries: CHOSEN BRICK (threat, notable) and BambooToken (threat, notable, Lumen Black Lotus Labs' previously-undocumented MQTT-C2 malware framework). Two changelog updates: the GitLab CVE-2026-85706 entry (NCSC Switzerland's posting confirmed the sibling CVE-2026-87719 now exploited and linked a public PoC for the original flaw) and the Revolut KYC-breach entry (an extortion/ransom-demand escalation, sourced to an aggregator relay after the originating outlet, Computing.co.uk, 403'd on every transport).
No deep-dive this run: CHOSEN BRICK's apt-campaign category was demoted one rank per the 7-day category-rotation rule (GTG-20006 published 2026-09-13 already used that category), and neither new item independently clears criterion 1 (no active exploitation/vulnerability involved in either).
borderline-drop: Delinea Secret Server three new PAM CVEs (CVE-2026-15638/15639/15640, CVSS 9.1-9.5), no confirmed exploitation, no public PoC, and two of the three require CVSS4 attack-complexity High/attack-requirements Present rather than a trivial pre-auth path; does not clear PD-11(b)'s out-of-band bar (routine patch cycle applies).
borderline-drop: CenterPoint Energy (US electric/gas utility) customer-data breach via unthrottled public-API sequential-ID enumeration, ~7.49M records claimed, out-of-nexus (US utility, no Swiss/EU angle), and the access technique (unrated public API without rate-limiting/WAF) is a well-known, not novel or evolved, class; does not independently clear the breach-gate's (a)-(d) criteria.
borderline-drop (added to coverage backlog, not dropped outright): AFPA (French national vocational-training agency) ~971,000-record leak-site claim, single C-reliability tracker, no victim confirmation, no Admiralty A/B journalism; added as a new open row to re-check on a later fire.
Coverage-backlog rows re-checked this run: Kimberly-Clark/ShinyHunters, Ixa Systems/TheGentlemen, UICC/Krybit, Ville de Libercourt/Kairos, Medela/ShinyHunters, reichenau.at/SafePay, the AA26-231A Siemens S7 PLC re-read, and the inside-it.ch Insel Gruppe article (17th+ consecutive fire blocked on the same host-level rate limit), no change on any. Ville du Tampon (La Réunion), no change, still no named mechanism/actor. Familea (French municipal family-services SaaS), material scope-expansion delta (now confirmed across five communes in four departments, not just Bruguières) recorded on the open row, but still no named mechanism, actor or data-theft claim, so it stays below the publish bar under the same precedent as Ville du Tampon/Boston Scientific/NovoCure.
Single-source: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware, single-source-national-cert (NCSC UK, with FBI/AIVD as joint co-authors of the same publication, not independent assessments; The Record's reporting relays the same advisory). 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload, single-source (BleepingComputer's article relays Lumen Black Lotus Labs' own findings rather than independently assessing them). 2026-09-13/revolut-fake-government-request-kyc-breach's 2026-09-16 update, single-source-other equivalent via aggregator: the originating outlet (Computing.co.uk) 403'd on every transport tried; sourced to DataBreaches.net's direct relay, confidence lowered to medium for the entry as a whole.
Mechanical KEV sweep (tools/kev_window_diff.py --window-hours 26): 0 CISA KEV additions since 2026-09-15; no disposition needed this run.
Essential-coverage: all essential-tier sources attempted across the active-threats/vulns and home-region/sector passes with no misses; the research and incidents passes' essential slice (heise-sec, inside-it-ch) both attempted and returned RSS content with no in-window relevant item.
Declined verifier finding: the verifier's iteration-5 pass flagged a Neuchâtel-based Swiss Bitcoin Pay breach disclosure (dailyhodl.com, 2026-09-15) as an apparently-unconsidered candidate. Declined as a false positive; this incident is already published as 2026-09-15/swiss-bitcoin-pay-neuchatel-internal-systems-breach by the prior day's fire and already carried in this run's dedup index; the flagged article is same-day reporting on that same already-covered disclosure, not a fresh delta.
Coverage gaps: tp-link-omada-psirt (5th consecutive 404; vendor Nuxt SPA support portal appears to have moved its advisory-index route; needs a recipe review); zdi, watchtowr, shadowserver, hadrian-labs, vulncheck, sonatype, jpcert, esentire, sansec-research, socket-dev-blog, snyk-research, trail-of-bits (all fetched cleanly, no in-window item, active-threats/vulns pass); cert-at, ccb-belgium (404 on the specific advisory/news path attempted, home-region/sector pass); unit42, akamai-sirt, dfirreport, crowdstrike, elastic-seclabs, vulncheck, eset, esentire, csa-labs, gambit-security, paradigm-shift-research (JS shell, no listing), sygnia, trellix (JS shell, no listing), all fetched, no in-window item, research pass; helpnetsecurity (JS-rendered homepage, no listing), ico-uk (raw HTML only, not reviewed this run), incidents pass.
← Operations dashboard · day page 2026-09-16 · run-record contract: docs/pipeline.md