CTIPilot

2026-09-17T0409Z-intel

One pipeline fire, in full · intel run of 2026-09-17 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-17/2026-09-17T0409Z-intel.md.

Run telemetry

2026-09-17T0409Z-intel intel prompt v4.10 publish ok
1h 56m duration 7 published 0 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
7m 08s
Tool calls
0 WebFetch6 WebSearch22 bridge
Cited sources
2 of 25 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
9m 07s
Tool calls
0 WebFetch11 WebSearch25 bridge
Cited sources
3 of 29 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
12m 05s
Tool calls
9 WebFetch10 WebSearch22 bridge
Cited sources
2 of 16 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
6m 42s
Tool calls
0 WebFetch15 WebSearch19 bridge
Cited sources
1 of 16 in slice

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=7 e=3 a=1 #2 NEEDS_FIXES · Sonnet 5 · t=6 e=1 a=4 #3 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=1 #4 NEEDS_FIXES · Sonnet 5 · t=3 e=3 a=2 #5 CLEAN · Sonnet 5 · t=0 e=0 a=1 #6 NEEDS_FIXES · Sonnet 5 · t=0 e=1 a=1

Deep dive

2026-09-17/mandiant-ai-risk-resilience-report-2026

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

5 bookkeeping · 1 note.

SourceChangeFrom → ToReason
tp-link-omada-psirtnote· → ·S1 reconfirmed the listing URL still 404s; main agent probed the candidate replacement URL directly and found it returns only a cookie-consent shell, not an advisory listing, not applied. Documented recipe (BSI CERT-Bund CSAF external-reference → per-advisory document id) remains the only confirmed-working path.
cisa-kevbookkeepinglast_successful_fetch 2026-09-15 → last_successful_fetch 2026-09-17Contributed the mandatory KEV-sweep disposition for three in-window additions.
cisco-psirtbookkeepinglast_successful_fetch (stale) → last_successful_fetch 2026-09-17Primary source for the published Cisco ISE entry.
crowdstrikebookkeepinglast_successful_fetch 2026-09-07 → last_successful_fetch 2026-09-17Primary source for the published PhantomRaven entry.
heise-secbookkeepinglast_successful_fetch 2026-09-14 → last_successful_fetch 2026-09-17Discovery source for the DDRop and AEPD entries.
frenchbreachesbookkeepinglast_successful_fetch (stale) → last_successful_fetch 2026-09-17Primary source for the published Kairos/Libercourt entry.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Bridge invocations (this run)

7 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

7 ok
  • extract ×6
  • extract/jina ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 11 findings (truth=7, editorial=3, advisory=1) · Claude Sonnet 5 · 12m 13s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
cve-2026-76460-cisco-ise-auth-bypass-root-rce
CVE-2026-76423 fixed field wrongly carried the 'must migrate' caveat that applies only to the advisory's other five CVEs; Cisco's own fixed-release table shows it on the same schedule as CVE-2026-7646Corrected affected/fixed fields to the accurate per-CVE schedule from the advisory's own table.
F3
claim-not-supported
cve-2026-58704-google-pixel-modem-zero-click-eop
A sentence attributed to 'ENISA EUVD' hyperlinked to Google's own bulletin page, which does not carry that description.Re-attributed the description to the MITRE CVE record (the actual source of that text) and added it to sources[].
F5
missing-citation
kairos-libercourt-commune-ransomware-confirmed
The Kairos leak-site claim (817 GB, 2026-09-02) was uncited; the entry's sole source (the commune's own statement) never mentions Kairos or a data volume, and no volume claim exists on the leak-site lAdded the leak-site listing as a corroborating source, removed the unsupported data-volume figure, and rewrote the claim to state exactly what the listing suppo
F4
hallucinated-fact
kairos-libercourt-commune-ransomware-confirmed
Title/summary read as though the commune confirmed Kairos as the intruder; the body correctly hedged this, but the frontmatter overstated it.Rewrote title, headline and summary to state plainly that the ransomware attack and data theft are victim-confirmed while the Kairos link remains an unattribute
F14
?
kairos-libercourt-commune-ransomware-confirmed
'Second small municipality in six weeks' is contradicted by the store's own dates (about 3.5 weeks between the two confirmations).Removed the unsupported duration claim; replaced with the verifiable 13-day gap between the leak-site claim and the commune's confirmation.
F13
?
kairos-libercourt-commune-ransomware-confirmed
The relevance rationale rested on the now-corrected attribution and timing claims.Rewrote the rationale to state the target-profile pattern as a hedged observation, not an established fact.
F4
hallucinated-fact
mandiant-ai-risk-resilience-report-2026
Case study 5's GitHub-exfiltration behavior was mapped to T1567.002 (Exfiltration to Cloud Storage); the pinned dataset's correct id for exfiltration to a code repository is T1567.001.Corrected the id in both techniques[] and the inline prose reference.
F17
?
mandiant-ai-risk-resilience-report-2026
classification.reliability was A; the cited primary source is rated B in the source catalogue.Corrected reliability to B.
F14
?
phantomraven-npm-llm-generated-infostealer
The '86,000+ downloads' figure was real but cited to neither of the entry's two sources.Added the originating research (Endor Labs) as a corroborating source and re-attributed the figure to it.
F11
editorial-advisory
run-record
The published verification-notes body used internal workflow labels ('sub-agents', 'S1-S4', 'spawn instructions').Rewrote the notes body in plain language with no internal labels.
F12
single-source-flag-missing
aepd-first-ai-agent-breach-notification
(low confidence, advisory) flagged the national-authority carve-out extension to aepd.es for explicit confirmation rather than as an error.Reviewed and confirmed: consistent with the existing cnil.fr precedent and PD-5's own wording (a government authority as primary disclosing party for its own ju

Iteration #2 NEEDS_FIXES · 11 findings (truth=6, editorial=1, advisory=4) · Claude Sonnet 5 · 8m 30s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
cve-2026-76460-cisco-ise-auth-bypass-root-rce
The EOL/migration claim co-cited the MITRE CVE record, which carries no such statement (Cisco PSIRT alone states it); the MITRE URL was also cited inline but absent from sources[].Removed the MITRE co-citation from that sentence; the claim now cites Cisco PSIRT alone.
F3
claim-not-supported
cve-2026-76460-cisco-ise-auth-bypass-root-rce
The 'three-day remediation deadline' cited the CISA alert-announcement page, which names no due date.Added the CISA KEV JSON feed as a source and re-attributed the specific due-date figure to it, keeping the alert page for the KEV-addition fact alone.
F3
claim-not-supported
cve-2026-58704-google-pixel-modem-zero-click-eop
Same defect: the 'three-day remediation deadline' cited the CISA alert page, which names no due date.Same fix, added the KEV JSON feed as a source and re-attributed the due-date figure to it.
F4
hallucinated-fact
cve-2026-58704-google-pixel-modem-zero-click-eop
(low confidence) sourcing_note attributed the 8.8 CVSS figure to ENISA EUVD, which could not be independently re-confirmed this pass; the MITRE CVE record's own CISA-ADP metrics block was confirmed toRe-attributed the sourcing_note to the CISA-ADP Vulnrichment block inside the MITRE CVE record, already cited in sources[].
F3
claim-not-supported
ddrop-dram-interposer-defeats-confidential-computing
The body attached 'even under Cryptographic Integrity mode' to both the attestation-forging AND the debug-mode-dump attacks; the source scopes the debug-mode attack to Logical Integrity mode only.Rewrote the sentence to scope each attack to the mode the source actually states.
F4
hallucinated-fact
kairos-libercourt-commune-ransomware-confirmed
entities/registry.yaml's incident record (added this run) still carried the '817 GB' figure iteration 1 had already removed from the entry itself.Corrected the registry summary to match the entry's remediated text.
F17
?
mandiant-ai-risk-resilience-report-2026
classification.credibility: 1 overstated corroboration, the only corroborating source (Help Net Security) restates Mandiant's report with no independent fact added.Corrected credibility to 2 and verification to single-source, with a sourcing_note explaining why.
F11
editorial-advisory
mandiant-ai-risk-resilience-report-2026
(low confidence, advisory) Case study 1's poisoned-PyPI-package behavior was mapped to T1195.002 (Compromise Software Supply Chain); T1195.001 (Compromise Software Dependencies and Development Tools, Corrected to T1195.001.
F11
editorial-advisory
mandiant-ai-risk-resilience-report-2026
(low confidence, advisory) Case study 4's runtime command-string rewriting was mapped to the bare parent T1027; the active sub-technique T1027.010 (Command Obfuscation) matches the described behavior Corrected to T1027.010 in both techniques[] and the inline prose reference.
F11
editorial-advisory
mandiant-ai-risk-resilience-report-2026
(low confidence, advisory) Case study 8 mapped T1068 (Exploitation for Privilege Escalation) to a source sentence that names privilege escalation generically without stating an exploited-vulnerabilityRemoved T1068; the prose now states the privilege escalation was by an unstated mechanism.
F11
editorial-advisory
phantomraven-npm-llm-generated-infostealer
(low confidence, advisory) CI/CD environment-variable harvesting was mapped to the bare parent T1552; CrowdStrike's own ATT&CK table for this exact malware maps it to T1552.001 (Credentials In Files, Adopted CrowdStrike's own two-id mapping in place of the bare parent.

Iteration #3 NEEDS_FIXES · 3 findings (truth=2, editorial=0, advisory=1) · Claude Sonnet 5 · 11m 48s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
cve-2026-76460-cisco-ise-auth-bypass-root-rce
Title and headline asserted a causal narrative ('found via a real customer compromise', 'discovered from a live customer breach') the advisory does not support; it states only that the flaw was found Rewrote title and headline to state exactly what the advisory says (found while resolving a customer support case).
F4
hallucinated-fact
kairos-libercourt-commune-ransomware-confirmed
The Velilla de San Antonio comparison sentence was uncited and overstated that municipality's own confirmation; its statement says data access/extraction 'cannot yet be confirmed', not that it was indAdded the Velilla municipality's own statement as a source, added the store's Velilla entry to references[], and rewrote the sentence to state the narrower, acc
F11
editorial-advisory
phantomraven-npm-llm-generated-infostealer
(advisory) techniques[] used only 4 of the ~10 behaviors CrowdStrike's own ATT&CK table maps for this malware, omitting several the entry's own body already describes (external-IP lookup, system-info Added T1016.001, T1082, T1036.005, T1072 and T1027.009 from CrowdStrike's own table, matching what the body already describes.

Iteration #4 NEEDS_FIXES · 8 findings (truth=3, editorial=3, advisory=2) · Claude Sonnet 5 · 9m 57s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
cve-2026-76460-cisco-ise-auth-bypass-root-rce
Body claimed 'a bundled nine-advisory Cisco ISE disclosure'; Cisco's own advance-notification page (uncited) lists 15 distinct ISE advisories that day, not nine.Corrected the count to 15 and added the advance-notification page as a cited source.
F11
editorial-advisory
phantomraven-npm-llm-generated-infostealer
(advisory) Two more CrowdStrike-mapped behaviors the body already describes (LLM-based malware development, HTTP GET/POST exfiltration) remained unmapped after iteration 3's partial fix.Added T1587.001 and T1041.
F11
editorial-advisory
kairos-libercourt-commune-ransomware-confirmed
(advisory, low confidence) T1486 maps the ransomware label; the one behavior actually confirmed by the source, data exfiltration, has no exfiltration technique mapped.Reviewed: no source states an exfiltration channel or mechanism, so no specific exfiltration sub-technique can be mapped without inventing one; left as T1486 on
F10
missed-angle
mandiant-ai-risk-resilience-report-2026
(low confidence) The new actor:dark-castle registry entity carried nexus: null despite the store's own May 2026 GTIG entry already naming UNC2814 (the same cluster's prior alias) a PRC state actor.Updated the registry entity's nexus to china-nexus and added the cross-reference to its summary.
F9
surface-contradiction
kairos-libercourt-commune-ransomware-confirmed
(low confidence) Pairing 'ransomware attack' with Kairos in the title/headline sits in tension with the store's own actor:kairos-extortion profile (data-theft-only, no encryptor ever linked to it) witAdded an explicit sentence naming the tension directly, so a reader familiar with the actor's tracked profile is not left to notice the mismatch unaided.
F5
missing-citation
aepd-first-ai-agent-breach-notification
(low confidence) The 'AEPD's deputy director, Francisco Pérez Bes' clause carried no inline citation.Added the heise online citation to that specific clause.
F3
claim-not-supported
ddrop-dram-interposer-defeats-confidential-computing
(low confidence) 'no timing signature to flag the tampering' goes beyond what the source states; the source instead contrasts DDRop's native-speed operation with earlier interposers that had to slow tRewrote the sentence to state exactly the source's own contrast.
F3
claim-not-supported
mandiant-ai-risk-resilience-report-2026
(low confidence) Case study 1 called the AI assistant a 'code-review interpreter'; Mandiant's report calls it a 'trusted interpreter', with 'code review' appearing only in the unrelated case study 3.Corrected to the source's own phrasing.

Iteration #5 CLEAN · 1 finding (truth=0, editorial=0, advisory=1) · Claude Sonnet 5 · 7m 21s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F11
editorial-advisory
phantomraven-npm-llm-generated-infostealer
(advisory) techniques[] still omitted T1005 (Data from Local System) despite CrowdStrike's own ATT&CK table mapping it to system/env/config-file collection the body already describes.Added T1005.

Iteration #6 NEEDS_FIXES cap-breach · 2 findings (truth=0, editorial=1, advisory=1) · Claude Sonnet 5 · 8m 57s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F5
missing-citation
ddrop-dram-interposer-defeats-confidential-computing
The sentence on Intel evaluating next-generation memory-encryption schemes carried no citation; that specific framing comes from heise's reporting (already in sources[]), not from the Intel PSIRT pageSplit the sentence and cited each clause to its actual source (Intel PSIRT for Platform Owner Endorsements, heise for the memory-encryption framing).
F11
editorial-advisory
phantomraven-npm-llm-generated-infostealer
(advisory) CrowdStrike's own ATT&CK table still mapped techniques the entry omitted: T1083 (File and Directory Discovery, matching the already-described Git/npm config-file reading) and T1104 (Multi-SAdded T1083 and T1104, and added one clause to the body describing the WebSocket fallback so the T1104 mapping is grounded in prose. The four low-support ids ar

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-17T0409Z-intel · Sonnet 5 · window 26 h · 7 entries published

Verification & coverage notes

Standard 26-hour window (24 hours since the previous fire). No closed-source drops this window. No product or supplier watchlist is configured for this deployment, so both sweeps are no-ops (Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0).

Every CISA KEV addition since the previous fire got a disposition:

  • CVE-2026-58704 (Google Pixel modem, zero-click privilege escalation) → published: 2026-09-17/cve-2026-58704-google-pixel-modem-zero-click-eop (priority: high).
  • CVE-2026-76460 / CVE-2026-76423 (Cisco ISE auth bypass) → published: 2026-09-17/cve-2026-76460-cisco-ise-auth-bypass-root-rce (priority: critical, newly disclosed, confirmed actively exploited, no workaround beyond ACLs).
  • borderline-drop: CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM / Plesk extension) — KEV-listed and confirmed exploited, but the attack surface (Linux shared-hosting backup tooling requiring an existing low-privilege tenant account) is narrow and not confirmed to run on any platform a Swiss federal/cantonal/communal administration would itself operate; relevance is indirect (smaller hosting providers hosting public-sector sites).

New entries (7):

  1. cve-2026-76460-cisco-ise-auth-bypass-root-rce (critical, vulnerability), unauthenticated Cisco ISE API auth bypass, confirmed exploited, found via a customer support case.
  2. cve-2026-58704-google-pixel-modem-zero-click-eop (high, vulnerability), Pixel modem zero-click privilege escalation, CISA KEV, exploited in limited targeted attacks per Google/TechCrunch.
  3. kairos-libercourt-commune-ransomware-confirmed (notable, incident); a small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site; out-of-nexus, included for the target-profile pattern this actor has now shown twice against small municipal administrations.
  4. aepd-first-ai-agent-breach-notification (notable, policy), Spain's data protection authority discloses the first GDPR breach notification attributed to an autonomous AI agent. aepd.es was added to tools/check_run.py's national-authority carve-out list this run, matching the existing precedent for France's CNIL.
  5. ddrop-dram-interposer-defeats-confidential-computing (notable, research), a DDR5 hardware interposer defeats Intel TDX/SGX and AMD SEV-SNP confidential-computing guarantees; no CVE, no vendor fix (a physical-access class of attack).
  6. phantomraven-npm-llm-generated-infostealer (notable, threat), CrowdStrike attributes an LLM-generated npm infostealer to a self-described bug-bounty hunter.
  7. mandiant-ai-risk-resilience-report-2026 (high, annual-report, deep dive); Mandiant's second annual AI Risk and Resilience report; eight case studies of AI-agent abuse in real intrusions and red-team engagements. No deep dive had published yet today, so this is the day's single deep dive.

The AEPD story was found independently from two directions (the home-region/sector track and the research track), tracing to the same primary, the authority's own blog post, picked up by heise online. It was composed once, citing both, rather than as two entries.

Coverage-backlog re-checks this run, all "no change" except one resolution:

  • Kairos/Ville de Libercourt, resolved, published as entry 3 above.
  • ShinyHunters/Kimberly-Clark, no change (leak-site/aggregator only; the actor's own negotiation deadline passed 2026-09-16 with still no victim statement or reputable independent journalism).
  • inside-it.ch's Insel Gruppe article, still blocked (a persistent "Security Checkpoint" HTTP 429 on every transport tried, an 18th+ consecutive fire).
  • TheGentlemen/Ixa Systems SA, Krybit/UICC, ShinyHunters/Medela AG, SafePay/reichenau.at, no change (leak-site-tracker-only, no victim statement, no reputable independent journalism).
  • NovoCure, no new Swiss public-sector nexus found; not republished.
  • The Siemens S7 PLC advisory and three lower-priority research items held in the backlog (AWS credential-stuffing, an Exodus wallet installer RAT, a JSCeal deobfuscation pipeline), checked, no material development; remain below the bar for their own entry.
  • Ville du Tampon and Familea (French municipal incidents), re-checked, still no named mechanism, actor or data-theft claim from any party.

New in-window lead, held for further corroboration (not published): AFPA (France's national vocational-training agency), a third data-theft claim in a month, from two named criminal handles against two distinct claimed datasets, one with a claimed access-control mechanism, examined by two independent breach trackers. Still no statement from AFPA and no reputable independent journalism found despite a targeted search, so it does not yet clear the bar for inclusion. Logged for re-check on a later fire.

Verification: six iterations. The first four each found genuine truth or editorial defects (citation mismatches, an inflated advisory count, an uncited and overstated comparison claim, ATT&CK mapping precision) and were remediated in place. The fifth returned clean on everything but one minor ATT&CK-completeness point; the sixth, an independent cold-confirmation pass, found one further missing citation and a handful of additional ATT&CK ids a vendor's own mapping table names, both fixed. With the sixth iteration's residual at truth 0 / editorial 1, both fixed, this closes the loop without a further confirmation pass. One acknowledged residual: four low-support ATT&CK ids from CrowdStrike's PhantomRaven mapping table (domain registration, the scripting-interpreter execution technique, system locale discovery, automated collection) were judged too granular relative to that entry's own descriptive depth to add without overstating precision, and are left unmapped by deliberate choice rather than oversight.

Sources: changes listed above; the tp-link-omada-psirt listing page remains unreachable (a candidate replacement URL was checked and rejected this run, it returns only a cookie-consent shell, not an advisory listing).

← Operations dashboard · day page 2026-09-17 · run-record contract: docs/pipeline.md