CTIPilot

2026-09-25T0404Z-intel

One pipeline fire, in full · intel run of 2026-09-25 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-25/2026-09-25T0404Z-intel.md.

Run telemetry

2026-09-25T0404Z-intel intel prompt v4.11 publish ok
2h 12m duration 2 published 2 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
10m 33s
Tool calls
8 WebFetch11 WebSearch22 bridge
Cited sources
2 of 11 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
10m 23s
Tool calls
2 WebFetch8 WebSearch22 bridge
Cited sources
2 of 17 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
1
Duration
5m 39s
Tool calls
0 WebFetch13 WebSearch18 bridge
Cited sources
1 of 16 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
9m 21s
Tool calls
0 WebFetch9 WebSearch21 bridge
Cited sources
3 of 8 in slice

Verification

✓ double-CLEAN · Sonnet 5 ×2 #1 NEEDS_FIXES · Sonnet 5 · t=7 e=2 a=1 #2 NEEDS_FIXES · Sonnet 5 · t=2 e=4 a=0 #3 NEEDS_FIXES · Sonnet 5 · t=1 e=1 a=0 #4 NEEDS_FIXES · Sonnet 5 · t=2 e=3 a=1 #5 NEEDS_FIXES · Sonnet 5 · t=4 e=2 a=0 #6 CLEAN · Sonnet 5 · t=0 e=0 a=0 #7 CLEAN · Sonnet 5 · t=0 e=0 a=0

1 entry dropped by verification this run (recorded in the verification & coverage notes).

Deep dive

2026-09-25/cve-2026-5430-wso2-jwt-algorithm-confusion-admin-bypass

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

No source-list edits recorded for this run.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 10 findings (truth=7, editorial=2, advisory=1) · Claude Sonnet 5 · 13m 59s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
WSO2 entry: 'reproduced the flaw itself by diffing WSO2's patch against the vulnerable code path' cited to SecurityWeek, which only says watchTowr 'easily reproduced the vulnerability based on the venremoved the invented 'diffing' mechanism detail; sentence now says only what SecurityWeek states
F3
claim-not-supported
·
WSO2 entry: 'unrestricted file upload'/RCE phrase cited to the CISA alert page, which doesn't carry that phrase (it's in the separate KEV catalog JSON record, a blocked-source landing page)removed the uncitable elaboration; kept only the title-mismatch claim ('WSO2 Multiple Products Path Traversal Vulnerability'), which the alert page does support
F3
claim-not-supported
·
Policy entry: 'adopted ... on 2026-09-23' cited to Laux Lawyers AG, whose own fetched text describes the motion as still pending before the National Council, not adoptedre-cited the adoption-date claim to the Swiss parliament's own Curia Vista OData BusinessStates record (BusinessStatusName 'Überwiesen an den Bundesrat', dated
F4
hallucinated-fact
·
WSO2 entry: entities[] carried only the generic 'product:wso2-products' bucket key, not the 4 specific product registry keys this run's sync_products.py pass created from its own affected_products[]added product:wso2-api-manager, product:wso2-api-control-plane, product:wso2-traffic-manager, product:wso2-universal-gateway to entities[]
F4
hallucinated-fact
·
ASP France entry: sourcing_note claimed both Clubic and Cyberattaque.org cite FrenchBreaches as their source; only Clubic does, Cyberattaque.org states it examined leaked samples directlycorrected sourcing_note to reflect Cyberattaque.org's independent review of the leaked samples rather than a FrenchBreaches relay
F4
hallucinated-fact
·
ASP France entry: 'paid ... between 2023 and 2024' misstated the subsidy disbursement window (Clubic: July-October 2023 only); 2023-2024 describes the stolen documents' dates, not the payment windowcorrected the disbursement window to July-October 2023, re-cited to Clubic (the clause had been trailing a Cyberattaque.org citation that doesn't support it), k
F4
hallucinated-fact
·
ASP France entry: tags: [data-breach, path-traversal] mislabels an IDOR/broken-access-control finding, no source mentions path traversalcorrected to tags: [data-breach, auth-bypass, info-disclosure]
F9
surface-contradiction
·
ASP France entry: 'roughly 19 million French citizens' for the 2025 ANTS breach (Clubic's own figure) contradicts the store's own ANTS registry entry (11.7M citizen records confirmed), undisclosedattributed the 19M figure explicitly and solely to Clubic, noting it is not independently re-verified, without asserting it as an agreed figure
F7
drop
·
(low confidence) ASP France entry borderline against the stricter breach/incident relevance bar (no Swiss nexus, unconfirmed mechanism, IDOR not a novel/evolved TTP)reviewed against this store's own precedent (the AFPA and Japan Digital Agency entries: non-home-region public-sector breaches published on primary-sector nexus
F11
editorial-advisory
·
(low confidence, advisory) Gambit update's sourcing_note wasn't revisited after this run added Computing UK as a new source, stale relative to the new citationupdated sourcing_note to note Computing UK independently corroborates the Anthropic-ban/Cloudflare-takedown facts (citing Forbes/Gambit directly, not relaying C

Iteration #2 NEEDS_FIXES · 6 findings (truth=2, editorial=4, advisory=0) · Claude Sonnet 5 · 9m 11s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
Gambit update's own iteration-1 sourcing_note fix hallucinated a new detail: 'cites Forbes/Gambit directly', Computing UK's article never mentions Forbescorrected to 'whose own article cites Gambit Security directly', dropping the unsupported Forbes claim
F3
claim-not-supported
·
WSO2 entry asserted 'the assigned CWE-347 (Improper Verification of Cryptographic Signature)' with no support in any of the entry's 4 cited sources (CWE-347 is real, per the KEV catalog JSON, but thatremoved the CWE-347 clause; the title-mismatch sentence now rests only on what the cited sources support
F5
missing-citation
·
ASP France entry: 'payment notices issued in 2023 and 2024' carried no inline citation of its ownmoot; the ASP France entry was dropped this iteration (see below)
F5
missing-citation
·
(low confidence) Policy entry: the Federal-Council-rejection-basis sentence (EMBAG, Swiss Government Cloud, AI regulation) carried no inline citationadded a Netzwoche citation, which states the same EMBAG/existing-work rejection reasoning
F7
drop
·
Independent cold re-read of the ASP France entry finds it does not clearly clear the stricter incident/breach relevance bar's four named grounds (no Swiss nexus; IDOR not a novel/evolved TTP; no nameddropped the entry (git rm), on two independent cold-reader reads flagging the same relevance doubt; removed its registry entity (incident:france-asp-coup-de-pou
F8
needs-more-research
·
(advisory) Policy entry's Inside IT Switzerland source hit the site's own Vercel Security Checkpoint 429 block on all 3 fetch rungs this iteration too; could not independently confirm or deny that pagdeclined, a disclosed, unrecoverable coverage gap (also hit by S2 during research); the entry does not depend on this source for any uncorroborated claim (Curia

Iteration #3 NEEDS_FIXES · 2 findings (truth=1, editorial=1, advisory=0) · Claude Sonnet 5 · 5m 58s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
Gambit update's sourcing_note claimed Computing UK's article 'does not relay Cybersecuritynews.com' as a categorical statement; Computing UK's own text does relay Cybersecuritynews.com once, for the snarrowed the claim: Computing UK is now credited only for the Anthropic-ban/Cloudflare-takedown facts specifically, with an explicit acknowledgement that it doe
F9
surface-contradiction
·
(low confidence) Gambit's own primary post is internally inconsistent (summary says skimmers on 'five' sites, body says '19' confirmed); the entry follows '19' without disclosing the source's own incodeclined, this figure and its sourcing predate this run's update (published 2026-09-23, not touched by this fire's changelog record); the verifier itself calls

Iteration #4 NEEDS_FIXES · 6 findings (truth=2, editorial=3, advisory=1) · Claude Sonnet 5 · 10m 05s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
Gambit update's sourcing_note excluded the 'Kimi' model detail as solely a Cybersecuritynews.com addition 'that do not appear anywhere in Gambit's own primary text'; Computing UK's own fetched text incorrected sourcing_note: the Kimi detail is now disclosed as independently repeated by Computing UK (not solely a Cybersecuritynews.com addition), still exclude
F3
claim-not-supported
·
(low confidence) Roundcube update: 'extending exposure into hosting-provider-run mail used by smaller public-sector bodies and their suppliers' is an inference chained onto a BleepingComputer citationremoved the invented victim-class specifics; kept only the cited cPanel-bundling fact plus a generic, source-supported consequence (any organization whose mail
F5
missing-citation
·
(low confidence) Policy entry: 'the status a motion reaches only once its second, deciding chamber has also adopted it' is an unsourced procedural inference about Swiss parliamentary process, not statremoved the procedural-rule assertion; body now states only the dated facts the Curia Vista record and Netzwoche actually carry (committee-deliberation-conclude
F8
needs-more-research
·
(low confidence) Policy entry's sources[] listed Inside IT Switzerland (role: corroborating) but the body never cites it inline; its article page was never readable (Vercel 429 on all fetch rungs), soremoved Inside IT Switzerland from sources[], it never contributed a citable claim to the body; the entry's three remaining sources (Curia Vista OData, Laux Law
F17
?
·
(low confidence) Policy entry's classification.reliability: B likely under-rates the primary source, which is the Swiss Federal Assembly's own official parliamentary record, a first-party, primary govcorrected reliability B -> A
F11
editorial-advisory
·
(advisory) Run record's published notes use 'S2'/'S3' sub-agent shorthanddeclined; the run record is an internal operator artifact, never rendered to readers; the reader-text-internals ban on pipeline shorthand applies to entry bodie

Iteration #5 NEEDS_FIXES · 6 findings (truth=4, editorial=2, advisory=0) · Claude Sonnet 5 · 9m 24s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
Roundcube update's changelog record `fields` list omitted `sources`, though git diff shows 2 new source records (CCCS, BleepingComputer) added this runadded sources to the fields list
F4
hallucinated-fact
·
(moderate confidence) Gambit sourcing_note claimed Computing UK 'cites Gambit Security directly' for both the Anthropic-ban AND Cloudflare-takedown facts; Computing UK's own text shows Gambit attributcorrected to describe the two sentences precisely: the Cloudflare sentence follows Computing UK's own account of Gambit's takedown efforts; the Anthropic-ban se
F3
claim-not-supported
·
(moderate confidence) Policy entry's 'the National Council's own subsequent adoption ... means both chambers have now passed it' asserted a specific National-Council floor-vote outcome the Curia Vistaattempted a targeted WebSearch + fetch for independent confirmation of a National Council floor vote (datenrecht.ch's dedicated motion tracker, 403-blocked); re
F14
?
·
(low confidence) WSO2 entry's 'every currently-supported release line' characterised the advisory's listed versions as necessarily the current support matrix, which the advisory does not itself stateremoved the characterisation; states only that the bug reaches the release lines the advisory lists
F9
surface-contradiction
·
(moderate confidence) Gambit entry: Computing UK's own text states total campaign cost as ~USD 8,000; the entry's body (following Gambit) states USD 12,000-18,000, two cited sources disagree, undisclodisclosed the discrepancy in sourcing_note: Computing UK's own figure is lower than Gambit's; the entry follows Gambit's primary as the source that actually rev
F9
surface-contradiction
·
(low confidence, re-confirmation) Gambit's own ORIGINAL primary post (2026-09-23, not touched by this run) remains internally inconsistent ('five' vs '19' sites), verifier re-confirmed presence, flaggdeclined again, same rebuttal as iteration 3: outside this run's declared changelog scope

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-25T0404Z-intel · Sonnet 5 · window 26 h · 2 entries published

Verification & coverage notes

2 new entries (vulnerability: 1 deep-dive, policy: 1), 2 updates, 1 deep dive, critical: 0. Standard-cadence window (gap 24.0h, window 26.0h), no catch-up disclosure required.

Dropped by verification (iteration 2): an ASP France ("Coup de pouce énergie" payment-notice IDOR breach) incident entry was composed in Phase 4 and survived Phase 5.5, but two independent cold-reader passes (iteration 1's low-confidence editorial flag, iteration 2's full independent re-read) both found it does not clearly clear the stricter incident/breach relevance bar: no home-region nexus (France, not Switzerland), no named actor, an IDOR is not a novel or materially evolved TTP, and the incident's scale (143,518 records) is not globally significant. Iteration 1's disposition leaned on this store's own precedent for non-home-region public-sector breaches (the AFPA and Japan Digital Agency entries); iteration 2's independent read did not find that precedent persuasive for this specific item. Dropped rather than force a marginal call past two independent challenges, quality over quantity resolves this doubt toward drop.

Mechanical KEV sweep: tools/kev_window_diff.py found 2 in-window CISA KEV additions (2026-09-24): CVE-2026-5430 (WSO2, NOT COVERED, composed as this run's deep dive) and CVE-2026-71362 (Adobe Commerce, COVERED by 2026-08-16/cve-2026-71362-adobe-commerce-customer-account-takeover, whose own cves[].status already read [exploited, patch-available] before this run; the KEV addition is bookkeeping on an already-exploited CVE per PD-13 and ships nothing).

Borderline-drop: Adobe Campaign Classic APSB26-142 revision (18 CVEs, 8 at CVSS 10.0), single-sourced (Adobe's own bulletin plus an NCSC-NL RSS mention only; no second named outlet found), no confirmed exploitation, no PoC, no exposure-forcing mechanic beyond the CVSS score itself. Routine patch-cycle per PD-11(b); does not clear the beyond-normal-cadence bar.

Borderline-drop: IBM MQ (CVE-2026-10747) + Langflow OSS (11 further CVEs, incl. 3× CVSS 9.8), both fixed, no exploitation reported, no PoC, no forcing mechanic beyond severity. Routine patch-cycle per PD-11(b).

Borderline-drop: Recorded Future Insikt Group's "Russia New Generation Warfare" hybrid-campaign update (S3), single-source analytic synthesis with forward-looking indicators; no Switzerland-specific nexus stated (Europe-wide framing only); reads as strategic-level trend/outlook content rather than technical, actionable tradecraft. The retired synthesis/outlook kinds existed for exactly this shape; declined per PD-11 and the v4.0 scope narrowing.

Not published, added to state/coverage_backlog.md: Maileva (Docaposte/La Poste dematerialised-mail brand), confirmed service disruption since 2026-09-23 after unauthorized account-access attempts, but no party names a mechanism, actor, or confirmed data theft; same blocking shape as the Ville du Tampon/Familea/Pays de l'Aigle rows already on the backlog. No evidence-bound techniques[] could be composed without inventing one.

Coverage backlog: all 9 open rows re-checked on today's facts (S1 for the VMware row, S3 for Spring Ring and the three remaining PD-11(d) research items, S4 for the six leak-site/blocked-mechanism rows); all nine: no change. One new row added (Maileva, above).

Cross-domain overlap (deliberate, resolved): S3 independently surfaced Recorded Future's Russia hybrid-warfare update and flagged it as potentially overlapping S2's home-region/policy mission; S2 did not independently surface the same story. Composed as a single disposition (borderline-drop, above) rather than two.

Deep dive: 2026-09-25/cve-2026-5430-wso2-jwt-algorithm-confusion-admin-bypass. Selected under deep-dive criterion 1 (active in-the-wild exploitation with non-trivial exposure, an admin-bypass on API-gateway infrastructure watchTowr characterises as "Lateral-Movement-as-a-Service"). No deep dive published elsewhere today; category identity-infra does not appear in the prior 30 days' rotation.

Notable sourcing finding, main-agent verified: CISA's own alert for CVE-2026-5430 titles it "WSO2 Multiple Products Path Traversal Vulnerability," matching neither WSO2's advisory nor any researcher account, all of which agree on a JWT algorithm-confusion authentication bypass. Confirmed directly against CISA's alert page; disclosed in the entry body so readers searching KEV by category are not misled. (The KEV catalog's own JSON record elaborates further with an "unrestricted file upload"/RCE description and a CWE-347 assignment, but that record is a blocked-source landing-page pattern this pipeline never cites; the entry states only what the cited alert page supports.)

Single-source entries: none. The Swiss sovereign-digital-infrastructure motion traces to the Swiss parliament's own Curia Vista OData record (primary), plus Netzwoche's March 2026 reporting of the Council of States vote and a Laux Lawyers AG legal roundup (both corroborating), genuinely multi-source, not a single first-party record standing alone.

Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0, no product or supplier watchlist configured this deployment.

Coverage gaps: several S3 rotation-source listing pages (volexity, bitdefender-threat-debrief, group-ib, hunt-io, resecurity, pwn-ai) returned 200 but client-side-rendered/stale content with no drillable in-window post list, recipe gaps, not transport failures, logged in work/2026-09-25T0404Z-intel/findings.S3.yaml. S4's ico-uk and cnil-fr listing pages fetched cleanly but surfaced no on-point in-window enforcement notice through the listing alone; venarix.com is a JS-driven SPA with no working recipe. S1 did not sweep its 14-source rotation slice this run (essential-tier + the two mandatory KEV-diff priority pulls consumed the productive research budget); no gap serious enough to have missed a qualifying item, per S1's own assessment.

Essential-coverage: all essential-tier sources across all four domains fetched successfully this run (no misses to disclose).

← Operations dashboard · run-record contract: docs/pipeline.md