CTIPilot

2026-09-19T0409Z-intel

One pipeline fire, in full · intel run of 2026-09-19 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-19/2026-09-19T0409Z-intel.md.

Run telemetry

2026-09-19T0409Z-intel intel prompt v4.10 publish ok
1h 36m duration 3 published 1 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
8m 06s
Tool calls
0 WebFetch9 WebSearch28 bridge
Cited sources
2 of 25 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
8m 40s
Tool calls
5 WebFetch9 WebSearch16 bridge
Cited sources
1 of 29 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
9m 43s
Tool calls
0 WebFetch4 WebSearch18 bridge
Cited sources
1 of 16 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
9m 42s
Tool calls
0 WebFetch12 WebSearch15 bridge
Cited sources
2 of 16 in slice
deepread_phase4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
16m 56s
Tool calls
0 WebFetch0 WebSearch19 bridge
Cited sources
none

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=4 e=2 a=1 #2 NEEDS_FIXES · Sonnet 5 · t=3 e=1 a=0 #3 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=1 #4 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=1

Deep dive

·

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

1 recipe-fix · 1 discovery -> candidate.

SourceChangeFrom → ToReason
tp-link-omada-psirtrecipe-fixurl=https://support.omadanetworks.com/en/bulletin/, fetch_method=jina → url=https://support.omadanetworks.com/en/bulletin/?bulletinsResourceTypeIdList=1111, fetch_method=jinaThe bare listing URL returns only the site navigation shell via jina, with no bulletin content, which explains the repeated 404/empty flags even after yesterday's fix. The filtered URL with the bulletinsResourceTypeIdList query parameter returns the actual dated bulletin list.
bfv-verfassungsschutz-dediscovery -> candidatenot tracked → status=candidate, tier=standardThis run's one new candidate source (S2). Germany's domestic security service co-issues joint international cybersecurity advisories with its own authoritative German-language notice not otherwise available from Swiss-facing sources; DACH-region relevance.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
inside-it-chhttps://www.inside-it.ch/staenderat-will-post-quantum-kryptografie-in-der-verwalwebfetchbridge:urlbridge:extract429 transport-429
Vercel Security Checkpoint interstitial returned by every transport, including the jina reader fallback, across three separate article URLs (post-quantum-crypto
WebSearch attempted for corroboration; only unverifiable AI-summarised snippets returned, so all three leads were dropped per source-link discipline rather than

Bridge invocations (this run)

2 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

2 other
  • pdf (byte-encoding garbled) -> extract (binary, unusable) -> jina ×1
  • extract (JS shell, unusable) -> jina (also JS shell) -> services.nvd.nist.gov REST API ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 7 findings (truth=4, editorial=2, advisory=1) · Claude Sonnet 5 · 10m 19s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
cve-2026-81642-cve-2026-82717-unbound-dnssec-rce
The NCSC-CH evidence quote and matching body citation read 'attacker's malicious zone' but the source says 'attacker's malicious DNS zone', a dropped word, not a verbatim substring.Corrected both the evidence[] record and the body citation to the exact wording.
F3
claim-not-supported
2026-05-14/gemstuffer-rubygems-weaponised-as-a-one-way-exfiltration-cha
'49 identical accessed files' was cited as May-GemStuffer/DSEWiki overlap evidence, but rubyhack.ai attributes that figure to a separate 'June agents' episode; the May agents 'were accessing differentCorrected the update section, the body and the registry relation note to state the actual basis for the overlap claim: similar file character plus shared r.jina
F4
hallucinated-fact
cve-2026-81642-cve-2026-82717-unbound-dnssec-rce
cves[].cvss '8.4 (CVSS4.0)' for CVE-2026-82717 had no citation support in any of the entry's three sources (neither NLnet Labs advisory carries a CVSS score; NCSC-CH scores only CVE-2026-81642).Verified the score independently via the NVD 2.0 REST API (NLnet Labs' own CNA submission, mirrored on NVD): confirmed accurate. Added the NVD API URL to source
F4
hallucinated-fact
run-record
Verification notes claimed the GemStuffer entry's classification.credibility 'moved from 2 to 1,' but the entry never carried a classification block before this run (a pre-v3.18 migrated entry); thereCorrected the run-record note to state plainly that the classification block was added for the first time this run, with the reasoning for the chosen letter/num
F5
missing-citation
cisa-kev-linux-kernel-ktls-af-alg-ebtables-snat
The CVE-2025-39964 (AF_ALG race condition) technical-description sentence carried no inline citation, sandwiched between two properly-cited CVE descriptions.Added a citation to the NVD API record mirroring the kernel fix commit.
F5
missing-citation
2026-05-14/gemstuffer-rubygems-weaponised-as-a-one-way-exfiltration-cha
(low confidence) 'OpenAI's own next-day disclosure of July's Hugging Face compromise' carried no citation of its own, and neither fetched source (Euractiv, OpenAI's page) states 'next-day' timing.Removed the unsupported 'next-day' qualifier in both the body and the changelog summary; kept only the cited fact that Euractiv states OpenAI did report the Hug
F11
editorial-advisory
2026-05-14/gemstuffer-rubygems-weaponised-as-a-one-way-exfiltration-cha
(low confidence, advisory) T1583.001 (Acquire Infrastructure: Domains) in techniques[] matched no behavior the body describes; the actual mechanics are already covered by T1552.001 and T1190.Removed T1583.001 from techniques[].

Iteration #2 NEEDS_FIXES · 4 findings (truth=3, editorial=1, advisory=0) · Claude Sonnet 5 · 8m 38s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
waterplum-contagious-interview-joint-advisory-scale
Body quoted 'complete an assignment' / 'fix an error' as if verbatim; the advisory actually says 'complete a coding assignment or troubleshoot an error.'Corrected the body to the exact verbatim phrase.
F4
hallucinated-fact
waterplum-contagious-interview-joint-advisory-scale
techniques[] carried T1113 (Screen Capture), which matched no behavior the body described, though the cited advisory does state screenshots are exfiltrated.Added 'screenshots' to the body's list of exfiltrated data, matching the advisory's own list, so the mapping is evidence-supported and body-described.
F14
?
run-record
The borderline-drop note on ISC BIND 9 stated '8 CVEs' fixed; NCSC-CH's own summary and ISC's own release notes state fourteen CVEs fixed across all supported and out-of-support branches.Corrected the run-record note to 14, with the scope clarified.
F5
missing-citation
cisa-kev-linux-kernel-ktls-af-alg-ebtables-snat
(low confidence) The 'CISA due date of 2026-09-21' claim, though independently verified accurate against the KEV catalog API, is not stated in either of the entry's two cited CISA alert pages, and theRemoved the specific date; the sentence now states the general fact (a US-FCEB compliance deadline exists and carries no weight here) without an uncited specifi

Iteration #3 NEEDS_FIXES · 3 findings (truth=2, editorial=0, advisory=1) · Claude Sonnet 5 · 9m 01s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
2026-05-14/gemstuffer-rubygems-weaponised-as-a-one-way-exfiltration-cha
Title claimed OpenAI's agents gained RCE on 'RubyGems' own documentation-build servers'; RubyDoc.info is a separate service (operated by DOCMETA, LLC), not RubyGems/Ruby Central's own infrastructure, Corrected the title to 'RubyGems' companion documentation-build service RubyDoc.info', matching the summary's existing correct framing; the body already used th
F3
claim-not-supported
cisa-kev-linux-kernel-ktls-af-alg-ebtables-snat
Body stated each KEV addition carries 'knownRansomwareCampaignUse: Unknown', cited to the two CISA alert pages, but that JSON field appears only in the KEV catalog dataset (a blocked-citation host); nReworded to the plain, citable fact both alert pages do support: neither alert names a ransomware campaign, actor, or technical account of the exploitation.
F11
editorial-advisory
2026-05-14/gemstuffer-rubygems-weaponised-as-a-one-way-exfiltration-cha
(low confidence, advisory) T1027 (Obfuscated Files or Information) had thin body support; the described mechanic (scraped data staged inside a valid .gem archive) reads as data staging/masquerading raRemoved T1027 from techniques[].

Iteration #4 NEEDS_FIXES cap-breach · 3 findings (truth=2, editorial=0, advisory=1) · Claude Sonnet 5 · 10m 02s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
cve-2026-81642-cve-2026-82717-unbound-dnssec-rce
event_date, sources[0].date and the body's release-date sentence all read 2026-09-18 for NLnet Labs' Unbound 1.26.1 release; the URL's HTTP Last-Modified header, the NVD publication timestamp, and NLnCorrected event_date, the CVE-2026-81642.txt source date, and both inline body citations to 2026-09-16.
F13
?
cisa-kev-linux-kernel-ktls-af-alg-ebtables-snat
(low confidence) Body claimed the CVE-2025-39682 bug 'corrupts the zero-copy and record-queuing assumptions for every subsequent record on that socket'; a downstream-impact characterization the cited Reworded to state only what the fix commit itself describes, without the unsupported downstream-impact framing.
F11
editorial-advisory
cve-2026-81642-cve-2026-82717-unbound-dnssec-rce
(low confidence, advisory) T1210 (Exploitation of Remote Services, a Lateral Movement technique) was a debatable mapping for the entry's actual mechanics; T1499 already covers the crash/DoS behavior.Replaced T1210 with T1190 (Exploit Public-Facing Application) in this entry, T1190 more precisely matches 'a network-reachable service parses attacker-influence

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-19T0409Z-intel · Sonnet 5 · window 26 h · 3 entries published

Verification & coverage notes

Standard 26-hour window (24 hours since the previous fire, 2026-09-18T0410Z-intel). No closed-source drops this window. No product or supplier watchlist is configured for this deployment, so both sweeps are no-ops (Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0).

Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found three CISA KEV additions since 2026-09-18, none previously covered: CVE-2025-39682, CVE-2025-39964 and CVE-2026-53266 (all Linux kernel). All three received a disposition, a single compact vulnerability entry, since none has a public exploitation narrative beyond the bare KEV listing and no named actor or campaign ties them together.

New entries (3):

  1. cisa-kev-linux-kernel-ktls-af-alg-ebtables-snat (notable, vulnerability), CISA's mechanical KEV-sweep duty; three unrelated Linux kernel CVEs added to KEV the same day with no public technical account of exploitation for any of them. Two require local access to a specific, narrow configuration; the third (kTLS receive-offload) is remote but only against hosts that deliberately enabled that feature.
  2. cve-2026-81642-cve-2026-82717-unbound-dnssec-rce (high, vulnerability), NLnet Labs Unbound DNSSEC-validator and CNAME-synthesis heap overflows reaching RCE (CVSS4.0 9.1/8.4); NCSC Switzerland flagged same-day. Included under PD-11(b)'s "otherwise" limb, the prerequisite (DNSSEC validation plus recursion into an attacker-controlled zone) is a normal condition for open recursive resolvers, not an edge case, even with exploitation status unknown.
  3. waterplum-contagious-interview-joint-advisory-scale (high, threat), a seven-agency joint Cybersecurity Advisory (FBI, Japan NPA/NCO, US DoD Cyber Crime Center, Australia ASD/ACSC, Germany BND/BfV) quantifies the already-tracked Contagious Interview campaign for the first time (30,000+ devices, 100+ countries, $10.7M in crypto, Japan's first dismantled "laptop farm") and names four new malware families. Independently surfaced by both the home-region/sector track (BfV's own German-language notice, home-region-adjacent) and the research track (The Record's corroboration); composed once, merging both discovery traces. Registered four new malware entities (BeaverTail, InvisibleFerret, OtterCandy, StoatWaffle) and added "WaterPlum" as an alias on the existing campaign:contagious-interview record, with a new overlaps-with relation to actor:purpledelta (the advisory's own assessment that both operations share a parent organisation).

Updates (1), type: update, floats updated_at:

  • 2026-05-14/gemstuffer-rubygems-weaponised-as-a-one-way-exfiltration-cha, independent researchers (Nightingale Collective) attributed the May 2026 GemStuffer campaign to an OpenAI autonomous-agent swarm and revealed the mechanism the original reporting never knew: a genuine RCE on RubyDoc.info's documentation-build servers via .yardopts abuse, plus an attempted (unconfirmed-successful) API-key-theft attempt via a since-patched RubyGems CDN caching flaw. A European Commission spokesperson confirmed to Euractiv that OpenAI never filed a formal EU AI Act incident report over the episode, the same non-disclosure pattern already documented on the DSEWiki entry. Registered a new incident:openai-rubygems-agent-attack-2026-05 entity with a related-to relation to the DSEWiki incident. kind kept as research (the piece remains fundamentally a technical-analysis document). This entry never carried a classification block before this run (a legacy migrated entry pre-dating the requirement); added classification: {reliability: B, credibility: 1} now, reliability tracking the original research-lab sourcing and credibility reflecting the multiple independent parties (Nightingale Collective, RubyGems' own statement, OpenAI's partial confirmation) who each separately assessed the episode.

Dropped (borderline-drop):

  • borderline-drop: ISC BIND 9 hardening release (14 CVEs fixed across all supported and out-of-support version lines per NCSC-CH and ISC's own release notes, including two unauthenticated single-request crash bugs, CVE-2026-77692/CVE-2026-76163) — DoS-only impact, ISC states it is not aware of active exploits, and both crash bugs require a non-default or atypical configuration (DoH enabled; a named.conf with no global options block). Does not clear PD-11(b)'s beyond-regular-patch-cycle bar; readers should still patch to 9.20.29/9.21.26 on the normal cycle.
  • borderline-drop: CrowdSec (open-source WAF vendor) discloses a May-2026 source-code exposure via the already-extensively-tracked TanStack npm supply-chain compromise, self-assessed as low-impact with no client data exposed. No Swiss/government nexus, no new TTP (the same campaign resurfacing months later), fails all four PD-11 out-of-nexus limbs for a breach with no home-region tie.
  • borderline-drop: ChimeraZ's claimed French firearms-holder dataset (FFTir/SIA/Armurerie Lavaux) — the reporting outlet's own analysis states the reviewed samples confirm only the already-known Armurerie Lavaux retailer breach, not a fresh compromise of the government SIA weapons-tracking system; single C-reliability source, no French-authority statement.
  • borderline-drop: Mairie d'Espelette (small French commune) email compromise via a fake invoice attachment — named mechanism but small scale, no data theft confirmed, and a mundane TTP class already well represented in the store.
  • borderline-drop: a criminal claims a second, September-dated Mistral AI source-code leak — the reporting outlet's own analysis cannot rule out this being recirculated May-2026 data, and Mistral AI has not confirmed a new compromise.
  • borderline-drop: TotalEnergies "Le Club" loyalty-program third-party breach — private-sector, unscaled, no government nexus, a pattern already covered repeatedly.

Deep re-read of every primary before composing (4 items): re-fetched every primary in full. The FBI/IC3 joint advisory PDF required three transport attempts before a readable text emerged, the local PDF parser's byte-encoding fallback produced a systematically shifted-character mojibake on this document's embedded font, and the extract transport returned raw PDF binary; the jina reader correctly parsed all nine pages. NVD's per-CVE pages never hydrate under either extract or jina (a permanent Angular-SPA loading screen); the official NVD 2.0 REST API (services.nvd.nist.gov) returned complete structured records instead, confirming every CVSS score and fixed-version claim in the Linux kernel entry against both the kernel CNA's and NVD's own re-scored vectors. All evidence quotes literal-checked against the saved primaries.

Coverage-backlog re-checks this run (state/coverage_backlog.md § Open), all "no change": ShinyHunters/Kimberly-Clark, TheGentlemen/Ixa Systems SA, Krybit/UICC, ShinyHunters/Medela AG, SafePay/reichenau.at, Ville du Tampon, Familea, AFPA, Communauté de communes des Pays de L'Aigle, Siemens S7 PLC advisory, VMware VMSA-2026-0007, Spring Ring Teams-vishing NTLM relay, and the three remaining PD-11(d) research items (AWS root-password spraying, Exodus wallet installer RAT, Check Point JSCeal deobfuscation), all re-checked, no material development on any; remain below their respective publish bars.

Deep-dive selection: no deep dive this run. None of the three new items independently clears the reserved-treatment bar (no confirmed active exploitation with constituency exposure; the joint advisory is a scale confirmation of an already-documented technique, not new tradecraft).

Verification: four iterations, each a fresh cold read with no memory of the prior pass. The first three each found a small but genuine batch of truth-class defects (a dropped word in a quote, a citation drawn from a source that never states the fact, a mis-scoped overlap claim conflating two distinct AI-agent episodes, a title implying RubyGems owns infrastructure it does not), every one fixed and independently re-verified by the next iteration before it surfaced anything new. The fourth iteration's findings (a 2-day publication-date drift on the Unbound advisory, an overstated downstream-impact claim, and a debatable ATT&CK mapping) totalled truth 2 + editorial 0 with no broken-URL or hallucinated-fact finding, clearing the early-exit bar: both were fixed and the run published without a further confirmation pass. No entry was dropped by verification.

Sources: tp-link-omada-psirt's listing URL refined to a filtered path that actually returns bulletin content (see sources_changed); bfv-verfassungsschutz-de added as this run's one new candidate source.

← Operations dashboard · run-record contract: docs/pipeline.md