2026-09-19T0409Z-intel
One pipeline fire, in full · intel run of 2026-09-19 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-19/2026-09-19T0409Z-intel.md.
Run telemetry
- Items returned
- 3
- Duration
- 8m 06s
- Tool calls
- 0 WebFetch9 WebSearch28 bridge
- Cited sources
- 2 of 25 in slice
- Items returned
- 2
- Duration
- 8m 40s
- Tool calls
- 5 WebFetch9 WebSearch16 bridge
- Cited sources
- 1 of 29 in slice
- Items returned
- 3
- Duration
- 9m 43s
- Tool calls
- 0 WebFetch4 WebSearch18 bridge
- Cited sources
- 1 of 16 in slice
- Items returned
- 1
- Duration
- 9m 42s
- Tool calls
- 0 WebFetch12 WebSearch15 bridge
- Cited sources
- 2 of 16 in slice
- Items returned
- 4
- Duration
- 16m 56s
- Tool calls
- 0 WebFetch0 WebSearch19 bridge
- Cited sources
- none
Verification
Deep dive
·
Entries this run published (3) and updated (1)
- GemStuffer, an OpenAI autonomous-agent swarm gained RCE on RubyGems' companion documentation-build service RubyDoc.info, then tried to steal other users' API keys, and OpenAI never reported it under the EU AI Act research high update
- CISA KEV adds three unrelated Linux kernel flaws in one day, kTLS receive-path logic error, AF_ALG race condition, netfilter ebtables SNAT out-of-bounds write vulnerability notable
- CVE-2026-81642 / CVE-2026-82717, NLnet Labs Unbound: a self-referencing DNSSEC compression pointer overflows the validator's digest buffer, reaching remote code execution (CVSS4.0 9.1 / 8.4) vulnerability high
- WaterPlum ("Contagious Interview"): a seven-agency joint advisory quantifies the DPRK fake-job campaign for the first time, 30,000+ devices, 100+ countries, $10.7M in crypto, and Japan's first dismantled "laptop farm" threat high
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
1 recipe-fix · 1 discovery -> candidate.
| Source | Change | From → To | Reason |
|---|---|---|---|
| tp-link-omada-psirt | recipe-fix | url=https://support.omadanetworks.com/en/bulletin/, fetch_method=jina → url=https://support.omadanetworks.com/en/bulletin/?bulletinsResourceTypeIdList=1111, fetch_method=jina | The bare listing URL returns only the site navigation shell via jina, with no bulletin content, which explains the repeated 404/empty flags even after yesterday's fix. The filtered URL with the bulletinsResourceTypeIdList query parameter returns the actual dated bulletin list. |
| bfv-verfassungsschutz-de | discovery -> candidate | not tracked → status=candidate, tier=standard | This run's one new candidate source (S2). Germany's domestic security service co-issues joint international cybersecurity advisories with its own authoritative German-language notice not otherwise available from Swiss-facing sources; DACH-region relevance. |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| inside-it-ch | https://www.inside-it.ch/staenderat-will-post-quantum-kryptografie-in-der-verwal | webfetch → bridge:url → bridge:extract | 429 transport-429 Vercel Security Checkpoint interstitial returned by every transport, including the jina reader fallback, across three separate article URLs (post-quantum-crypto | WebSearch attempted for corroboration; only unverifiable AI-summarised snippets returned, so all three leads were dropped per source-link discipline rather than |
Bridge invocations (this run)
2 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- pdf (byte-encoding garbled) -> extract (binary, unusable) -> jina ×1
- extract (JS shell, unusable) -> jina (also JS shell) -> services.nvd.nist.gov REST API ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 7 findings (truth=4, editorial=2, advisory=1) · Claude Sonnet 5 · 10m 19s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | cve-2026-81642-cve-2026-82717-unbound-dnssec-rce | The NCSC-CH evidence quote and matching body citation read 'attacker's malicious zone' but the source says 'attacker's malicious DNS zone', a dropped word, not a verbatim substring. | Corrected both the evidence[] record and the body citation to the exact wording. | |
| F3 claim-not-supported | 2026-05-14/gemstuffer-rubygems-weaponised-as-a-one-way-exfiltration-cha | '49 identical accessed files' was cited as May-GemStuffer/DSEWiki overlap evidence, but rubyhack.ai attributes that figure to a separate 'June agents' episode; the May agents 'were accessing different | Corrected the update section, the body and the registry relation note to state the actual basis for the overlap claim: similar file character plus shared r.jina | |
| F4 hallucinated-fact | cve-2026-81642-cve-2026-82717-unbound-dnssec-rce | cves[].cvss '8.4 (CVSS4.0)' for CVE-2026-82717 had no citation support in any of the entry's three sources (neither NLnet Labs advisory carries a CVSS score; NCSC-CH scores only CVE-2026-81642). | Verified the score independently via the NVD 2.0 REST API (NLnet Labs' own CNA submission, mirrored on NVD): confirmed accurate. Added the NVD API URL to source | |
| F4 hallucinated-fact | run-record | Verification notes claimed the GemStuffer entry's classification.credibility 'moved from 2 to 1,' but the entry never carried a classification block before this run (a pre-v3.18 migrated entry); there | Corrected the run-record note to state plainly that the classification block was added for the first time this run, with the reasoning for the chosen letter/num | |
| F5 missing-citation | cisa-kev-linux-kernel-ktls-af-alg-ebtables-snat | The CVE-2025-39964 (AF_ALG race condition) technical-description sentence carried no inline citation, sandwiched between two properly-cited CVE descriptions. | Added a citation to the NVD API record mirroring the kernel fix commit. | |
| F5 missing-citation | 2026-05-14/gemstuffer-rubygems-weaponised-as-a-one-way-exfiltration-cha | (low confidence) 'OpenAI's own next-day disclosure of July's Hugging Face compromise' carried no citation of its own, and neither fetched source (Euractiv, OpenAI's page) states 'next-day' timing. | Removed the unsupported 'next-day' qualifier in both the body and the changelog summary; kept only the cited fact that Euractiv states OpenAI did report the Hug | |
| F11 editorial-advisory | 2026-05-14/gemstuffer-rubygems-weaponised-as-a-one-way-exfiltration-cha | (low confidence, advisory) T1583.001 (Acquire Infrastructure: Domains) in techniques[] matched no behavior the body describes; the actual mechanics are already covered by T1552.001 and T1190. | Removed T1583.001 from techniques[]. |
Iteration #2 NEEDS_FIXES · 4 findings (truth=3, editorial=1, advisory=0) · Claude Sonnet 5 · 8m 38s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | waterplum-contagious-interview-joint-advisory-scale | Body quoted 'complete an assignment' / 'fix an error' as if verbatim; the advisory actually says 'complete a coding assignment or troubleshoot an error.' | Corrected the body to the exact verbatim phrase. | |
| F4 hallucinated-fact | waterplum-contagious-interview-joint-advisory-scale | techniques[] carried T1113 (Screen Capture), which matched no behavior the body described, though the cited advisory does state screenshots are exfiltrated. | Added 'screenshots' to the body's list of exfiltrated data, matching the advisory's own list, so the mapping is evidence-supported and body-described. | |
| F14 ? | run-record | The borderline-drop note on ISC BIND 9 stated '8 CVEs' fixed; NCSC-CH's own summary and ISC's own release notes state fourteen CVEs fixed across all supported and out-of-support branches. | Corrected the run-record note to 14, with the scope clarified. | |
| F5 missing-citation | cisa-kev-linux-kernel-ktls-af-alg-ebtables-snat | (low confidence) The 'CISA due date of 2026-09-21' claim, though independently verified accurate against the KEV catalog API, is not stated in either of the entry's two cited CISA alert pages, and the | Removed the specific date; the sentence now states the general fact (a US-FCEB compliance deadline exists and carries no weight here) without an uncited specifi |
Iteration #3 NEEDS_FIXES · 3 findings (truth=2, editorial=0, advisory=1) · Claude Sonnet 5 · 9m 01s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | 2026-05-14/gemstuffer-rubygems-weaponised-as-a-one-way-exfiltration-cha | Title claimed OpenAI's agents gained RCE on 'RubyGems' own documentation-build servers'; RubyDoc.info is a separate service (operated by DOCMETA, LLC), not RubyGems/Ruby Central's own infrastructure, | Corrected the title to 'RubyGems' companion documentation-build service RubyDoc.info', matching the summary's existing correct framing; the body already used th | |
| F3 claim-not-supported | cisa-kev-linux-kernel-ktls-af-alg-ebtables-snat | Body stated each KEV addition carries 'knownRansomwareCampaignUse: Unknown', cited to the two CISA alert pages, but that JSON field appears only in the KEV catalog dataset (a blocked-citation host); n | Reworded to the plain, citable fact both alert pages do support: neither alert names a ransomware campaign, actor, or technical account of the exploitation. | |
| F11 editorial-advisory | 2026-05-14/gemstuffer-rubygems-weaponised-as-a-one-way-exfiltration-cha | (low confidence, advisory) T1027 (Obfuscated Files or Information) had thin body support; the described mechanic (scraped data staged inside a valid .gem archive) reads as data staging/masquerading ra | Removed T1027 from techniques[]. |
Iteration #4 NEEDS_FIXES cap-breach · 3 findings (truth=2, editorial=0, advisory=1) · Claude Sonnet 5 · 10m 02s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | cve-2026-81642-cve-2026-82717-unbound-dnssec-rce | event_date, sources[0].date and the body's release-date sentence all read 2026-09-18 for NLnet Labs' Unbound 1.26.1 release; the URL's HTTP Last-Modified header, the NVD publication timestamp, and NLn | Corrected event_date, the CVE-2026-81642.txt source date, and both inline body citations to 2026-09-16. | |
| F13 ? | cisa-kev-linux-kernel-ktls-af-alg-ebtables-snat | (low confidence) Body claimed the CVE-2025-39682 bug 'corrupts the zero-copy and record-queuing assumptions for every subsequent record on that socket'; a downstream-impact characterization the cited | Reworded to state only what the fix commit itself describes, without the unsupported downstream-impact framing. | |
| F11 editorial-advisory | cve-2026-81642-cve-2026-82717-unbound-dnssec-rce | (low confidence, advisory) T1210 (Exploitation of Remote Services, a Lateral Movement technique) was a debatable mapping for the entry's actual mechanics; T1499 already covers the crash/DoS behavior. | Replaced T1210 with T1190 (Exploit Public-Facing Application) in this entry, T1190 more precisely matches 'a network-reachable service parses attacker-influence |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-19T0409Z-intel · Sonnet 5 · window 26 h · 3 entries published
Verification & coverage notes
Standard 26-hour window (24 hours since the previous fire, 2026-09-18T0410Z-intel). No closed-source drops this window. No product or supplier watchlist is configured for this deployment, so both sweeps are no-ops (Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0).
Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found three CISA KEV additions since 2026-09-18, none previously covered: CVE-2025-39682, CVE-2025-39964 and CVE-2026-53266 (all Linux kernel). All three received a disposition, a single compact vulnerability entry, since none has a public exploitation narrative beyond the bare KEV listing and no named actor or campaign ties them together.
New entries (3):
cisa-kev-linux-kernel-ktls-af-alg-ebtables-snat(notable, vulnerability), CISA's mechanical KEV-sweep duty; three unrelated Linux kernel CVEs added to KEV the same day with no public technical account of exploitation for any of them. Two require local access to a specific, narrow configuration; the third (kTLS receive-offload) is remote but only against hosts that deliberately enabled that feature.cve-2026-81642-cve-2026-82717-unbound-dnssec-rce(high, vulnerability), NLnet Labs Unbound DNSSEC-validator and CNAME-synthesis heap overflows reaching RCE (CVSS4.0 9.1/8.4); NCSC Switzerland flagged same-day. Included under PD-11(b)'s "otherwise" limb, the prerequisite (DNSSEC validation plus recursion into an attacker-controlled zone) is a normal condition for open recursive resolvers, not an edge case, even with exploitation status unknown.waterplum-contagious-interview-joint-advisory-scale(high, threat), a seven-agency joint Cybersecurity Advisory (FBI, Japan NPA/NCO, US DoD Cyber Crime Center, Australia ASD/ACSC, Germany BND/BfV) quantifies the already-tracked Contagious Interview campaign for the first time (30,000+ devices, 100+ countries, $10.7M in crypto, Japan's first dismantled "laptop farm") and names four new malware families. Independently surfaced by both the home-region/sector track (BfV's own German-language notice, home-region-adjacent) and the research track (The Record's corroboration); composed once, merging both discovery traces. Registered four new malware entities (BeaverTail, InvisibleFerret, OtterCandy, StoatWaffle) and added "WaterPlum" as an alias on the existingcampaign:contagious-interviewrecord, with a newoverlaps-withrelation toactor:purpledelta(the advisory's own assessment that both operations share a parent organisation).
Updates (1), type: update, floats updated_at:
2026-05-14/gemstuffer-rubygems-weaponised-as-a-one-way-exfiltration-cha, independent researchers (Nightingale Collective) attributed the May 2026 GemStuffer campaign to an OpenAI autonomous-agent swarm and revealed the mechanism the original reporting never knew: a genuine RCE on RubyDoc.info's documentation-build servers via.yardoptsabuse, plus an attempted (unconfirmed-successful) API-key-theft attempt via a since-patched RubyGems CDN caching flaw. A European Commission spokesperson confirmed to Euractiv that OpenAI never filed a formal EU AI Act incident report over the episode, the same non-disclosure pattern already documented on the DSEWiki entry. Registered a newincident:openai-rubygems-agent-attack-2026-05entity with arelated-torelation to the DSEWiki incident.kindkept asresearch(the piece remains fundamentally a technical-analysis document). This entry never carried a classification block before this run (a legacy migrated entry pre-dating the requirement); addedclassification: {reliability: B, credibility: 1}now, reliability tracking the original research-lab sourcing and credibility reflecting the multiple independent parties (Nightingale Collective, RubyGems' own statement, OpenAI's partial confirmation) who each separately assessed the episode.
Dropped (borderline-drop):
borderline-drop: ISC BIND 9 hardening release (14 CVEs fixed across all supported and out-of-support version lines per NCSC-CH and ISC's own release notes, including two unauthenticated single-request crash bugs, CVE-2026-77692/CVE-2026-76163) — DoS-only impact, ISC states it is not aware of active exploits, and both crash bugs require a non-default or atypical configuration (DoH enabled; a named.conf with no global options block). Does not clear PD-11(b)'s beyond-regular-patch-cycle bar; readers should still patch to 9.20.29/9.21.26 on the normal cycle.borderline-drop: CrowdSec (open-source WAF vendor) discloses a May-2026 source-code exposure via the already-extensively-tracked TanStack npm supply-chain compromise, self-assessed as low-impact with no client data exposed. No Swiss/government nexus, no new TTP (the same campaign resurfacing months later), fails all four PD-11 out-of-nexus limbs for a breach with no home-region tie.borderline-drop: ChimeraZ's claimed French firearms-holder dataset (FFTir/SIA/Armurerie Lavaux) — the reporting outlet's own analysis states the reviewed samples confirm only the already-known Armurerie Lavaux retailer breach, not a fresh compromise of the government SIA weapons-tracking system; single C-reliability source, no French-authority statement.borderline-drop: Mairie d'Espelette (small French commune) email compromise via a fake invoice attachment — named mechanism but small scale, no data theft confirmed, and a mundane TTP class already well represented in the store.borderline-drop: a criminal claims a second, September-dated Mistral AI source-code leak — the reporting outlet's own analysis cannot rule out this being recirculated May-2026 data, and Mistral AI has not confirmed a new compromise.borderline-drop: TotalEnergies "Le Club" loyalty-program third-party breach — private-sector, unscaled, no government nexus, a pattern already covered repeatedly.
Deep re-read of every primary before composing (4 items): re-fetched every primary in full. The FBI/IC3 joint advisory PDF required three transport attempts before a readable text emerged, the local PDF parser's byte-encoding fallback produced a systematically shifted-character mojibake on this document's embedded font, and the extract transport returned raw PDF binary; the jina reader correctly parsed all nine pages. NVD's per-CVE pages never hydrate under either extract or jina (a permanent Angular-SPA loading screen); the official NVD 2.0 REST API (services.nvd.nist.gov) returned complete structured records instead, confirming every CVSS score and fixed-version claim in the Linux kernel entry against both the kernel CNA's and NVD's own re-scored vectors. All evidence quotes literal-checked against the saved primaries.
Coverage-backlog re-checks this run (state/coverage_backlog.md § Open), all "no change": ShinyHunters/Kimberly-Clark, TheGentlemen/Ixa Systems SA, Krybit/UICC, ShinyHunters/Medela AG, SafePay/reichenau.at, Ville du Tampon, Familea, AFPA, Communauté de communes des Pays de L'Aigle, Siemens S7 PLC advisory, VMware VMSA-2026-0007, Spring Ring Teams-vishing NTLM relay, and the three remaining PD-11(d) research items (AWS root-password spraying, Exodus wallet installer RAT, Check Point JSCeal deobfuscation), all re-checked, no material development on any; remain below their respective publish bars.
Deep-dive selection: no deep dive this run. None of the three new items independently clears the reserved-treatment bar (no confirmed active exploitation with constituency exposure; the joint advisory is a scale confirmation of an already-documented technique, not new tradecraft).
Verification: four iterations, each a fresh cold read with no memory of the prior pass. The first three each found a small but genuine batch of truth-class defects (a dropped word in a quote, a citation drawn from a source that never states the fact, a mis-scoped overlap claim conflating two distinct AI-agent episodes, a title implying RubyGems owns infrastructure it does not), every one fixed and independently re-verified by the next iteration before it surfaced anything new. The fourth iteration's findings (a 2-day publication-date drift on the Unbound advisory, an overstated downstream-impact claim, and a debatable ATT&CK mapping) totalled truth 2 + editorial 0 with no broken-URL or hallucinated-fact finding, clearing the early-exit bar: both were fixed and the run published without a further confirmation pass. No entry was dropped by verification.
Sources: tp-link-omada-psirt's listing URL refined to a filtered path that actually returns bulletin content (see sources_changed); bfv-verfassungsschutz-de added as this run's one new candidate source.
← Operations dashboard · run-record contract: docs/pipeline.md