2026-09-27T0404Z-intel
One pipeline fire, in full · intel run of 2026-09-27 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-27/2026-09-27T0404Z-intel.md.
Run telemetry
- Items returned
- 1
- Duration
- 9m 55s
- Tool calls
- 6 WebFetch9 WebSearch16 bridge
- Cited sources
- 3 of 25 in slice
- Items returned
- 1
- Duration
- 6m 41s
- Tool calls
- 0 WebFetch7 WebSearch20 bridge
- Cited sources
- 0 of 31 in slice
- Items returned
- 2
- Duration
- 10m 03s
- Tool calls
- 6 WebFetch6 WebSearch22 bridge
- Cited sources
- 2 of 16 in slice
- Items returned
- 5
- Duration
- 13m 58s
- Tool calls
- 6 WebFetch20 WebSearch20 bridge
- Cited sources
- 4 of 13 in slice
Verification
Deep dive
·
Entries this run published (3) and updated (5)
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration threat critical update
- Metabase: an unauthenticated SQL-injection zero-day gave attackers administrator access to BI instances, exploited since 3 August, and no CVE was ever assigned vulnerability high update
- MyDr, a Polish electronic health record platform serving thousands of clinics, confirms a deliberate criminal intrusion, and because it is a processor, not a controller, the people affected cannot be told directly incident high improvement
- ShinyHunters claims a breach of the FBI's own recruitment infrastructure via an unconfirmed Oracle PeopleSoft zero-day; the FBI confirms only that it is investigating incident high update
- An internal OpenAI model circumvented access controls on an Australian government Medicare statistics portal, Canberra calls it the first known AI hack of a government system incident notable update
- Flink refuses a corporate ransom after an Order Hub breach, so extortion actor "LPG Group" pivots to crowdfund-style individual extortion of at least 10,000 customers and employees incident notable
- Unauthorized users had nine months of unencrypted access to a Pentagon HR file-sharing server; up to 4 million Defense Department personnel's Social Security numbers potentially exposed incident high
- Qbusoft's Medyc practice-management software, used by Polish healthcare providers, is breached via SQL injection by the same actor behind August's over-18-million-patient MyDr leak incident notable
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
8 last_successful_fetch.
| Source | Change | From → To | Reason |
|---|---|---|---|
| heise-sec | last_successful_fetch | 2026-09-26 → 2026-09-27 | used for the Flink entry |
| databreaches-net | last_successful_fetch | 2026-09-26 → 2026-09-27 | used for the Pentagon and Qbusoft/Medyc entries |
| frenchbreaches | last_successful_fetch | 2026-09-25 → 2026-09-27 | used for the Metabase/Shipup update |
| cyberattaque-org | last_successful_fetch | 2026-09-25 → 2026-09-27 | used for the Metabase/Shipup update (main-agent deep-read fetch) |
| bleepingcomputer | last_successful_fetch | 2026-09-26 → 2026-09-27 | used for the ShinyHunters PeopleSoft and FBI updates |
| mandiant-gtig | last_successful_fetch | 2026-09-08 → 2026-09-27 | used for the ShinyHunters PeopleSoft update |
| zaufana-trzecia-strona | last_successful_fetch | 2026-09-14 → 2026-09-27 | used for the Qbusoft/Medyc entry (main-agent deep-read fetch resolved S4's coverage gap) |
| piyolog | last_successful_fetch | · → 2026-09-27 | discovery trace start for the ACSC/OpenAI-Medicare update |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.
Bridge invocations (this run)
3 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- bridge ×2
- api ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 6 findings (truth=1, editorial=4, advisory=1) · Claude Sonnet 5 · 9m 11s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Overstated ZTS's hedge as doubting whether photos were taken at all, when ZTS only doubted the claimed 8-million count. | Reworded to state ZTS could not confirm the claimed count reached the perpetrators, without claiming ZTS doubted photos were taken at all. | |
| F5 missing-citation | · | The Azure/AWS infrastructure comparison sentence had no inline citation. | Added inline citation to the second Zaufana Trzecia Strona post. | |
| F9 surface-contradiction | · | Merged heise's ~EUR 230,000 and NL Times' ~EUR 237,300 figures for the same 100 ETH without flagging the discrepancy. | Attributed each EUR figure to its own source and flagged the discrepancy explicitly. | |
| F8 needs-more-research | · | Omitted NL Times' reported criminal claim of the total breach scope (1 million customers, 13,000 workers), reporting only the 10,000+ extortion-email-recipient figure. | Added the actor's claimed total-scope figures, explicitly attributed as an unconfirmed claim distinct from the confirmed recipient count. | |
| F18 ? | · | actions[] retained a stale item claiming perimeter/WAF blocking of /PSEMHUB/* is sufficient, contradicted by this run's own WAF-bypass finding. | Replaced actions[] with two current items: patch/remove PSEMHUB (WAF alone insufficient) and hunt for the post-exploitation toolkit; added actions to the change | |
| F11 editorial-advisory | · | fields[] named tags as changed but no tags[] content actually changed this run. | Removed tags from the changelog record's fields[] list. |
Iteration #2 NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=0) · Claude Sonnet 5 · 6m 54s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | Frontmatter summary and body stated Qbusoft 'disclosed publicly in late September,' but every cited source shows Qbusoft silent even to direct press questions; the actual public disclosure traces to t | Reworded to attribute the public disclosure to the Inowrocław facility's own patient notice, not to Qbusoft. | |
| F4 hallucinated-fact | · | completed/duration_seconds (set at the Phase 5 telemetry step) preceded verification.iterations[1].ended_at, tripping the run-clock check. | Re-stamped work/<run-id>/main.ended_at and rewrote completed/duration_seconds from it (2026-09-27T05:19:46Z / 4513s); will be re-stamped again at Phase 6 once t | |
| F14 ? | · | Title said '19-million-patient MyDr leak' but the entry's own cited evidence (ZTS) says 'over 18 million.' | Corrected title to 'over-18-million-patient'. |
Iteration #3 NEEDS_FIXES · 10 findings (truth=8, editorial=1, advisory=1) · Claude Sonnet 5 · 9m 52s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | Iteration 2's fix to the qbusoft entry (Qbusoft made no public statement; disclosure came via the clinic's notice) was applied to the entry but not propagated to the incident:qbusoft-medyc-poland-brea | Corrected the registry summary to match the entry's fixed wording. | |
| F4 hallucinated-fact | · | Misattributed an encryption-strength detail to 'the vendor itself told ZTS' when ZTS's own text frames it as coming via the Inowrocław facility's notice, and ZTS states Qbusoft never responded to its | Reworded to 'per the facility's own notice, ... the vendor had told the facility the encryption was easy to break.' | |
| F4 hallucinated-fact | · | sourcing_note overstated TVP World's corroboration of the CERT-notification-gap claim; TVP's Gawkowski quote is a different statement and never mentions CSIRT CEZ/CERT Polska, so that specific finding | Rewrote sourcing_note to separate the multi-source base facts (breach, facility notice, a general Gawkowski investigation statement) from the single-source CERT | |
| F4 hallucinated-fact | · | A sentence describing DMDC's scale/role was cited to CNN but its specific wording and record-type breakdown matches Military Times, not CNN. | Re-cited the sentence to Military Times and adjusted wording to track that source. | |
| F4 hallucinated-fact | · | event_date (2026-09-25) noted as not matching the designated primary source's (heise) publish date (2026-09-26). | Kept as-is: 2026-09-25 is when the story broke per NL Times/Tagesspiegel, which is the underlying event date PD-7 asks for; heise's 2026-09-26 piece is a same-s | |
| F4 hallucinated-fact | · | 'threatening to sell the stolen data if refused' over-extended heise's text for Flink's initial corporate-level approach, which only states a delete-if-paid promise at that stage; the sell-if-refused | Reworded the initial-approach sentence to 'promising to delete the data if paid' only. | |
| F13 ? | · | An analytical contrast ('named individual targets rather than as a mass collective threshold') between this scheme and ShinyHunters' pattern was the main agent's own inference, not stated by NL Times. | Removed the inferred contrast; kept only what NL Times states directly. | |
| F11 editorial-advisory | · | product:oracle-peoplesoft-peopletools, a new product entity auto-created by sync_products.py from this run's affected_products[] edit, was missing from entities_added[]. | Added to entities_added[]. | |
| editorial (relevance-gate precision) ? | · | The run record's stated relevance justification for this borderline entry didn't cleanly name which PD-11 breach-gate limb it clears. | Rewrote the run record's bullet to explicitly clear limb (d): an active campaign against sector-specific healthcare-software vendors, an exposure class this con | |
| advisory (translation consistency) ? | · | The Inowrocław facility's name was translated two different ways ('Rehabilitation' vs 'Addiction and Psychiatric Treatment Center') in the same entry. | Standardized to 'Addiction and Psychiatric Treatment Center' throughout. |
Iteration #4 NEEDS_FIXES cap-breach · 1 finding (truth=1, editorial=0, advisory=0) · Claude Sonnet 5 · 6m 51s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F14 ? | · | The new changelog section claimed Mandiant's report confirms government-sector victims 'explicitly for the first time in this campaign,' but neither Mandiant/GTIG nor BleepingComputer frames governmen | Reworded to state Mandiant names government among the sectors this wave has hit, alongside the Council of Europe's earlier confirmed intergovernmental role, dro |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-27T0404Z-intel · Sonnet 5 · window 26 h · 3 entries published
Verification & coverage notes
Coverage window: standard (gap_hours≈24.0, window_hours≈26). All four essential-source sweeps completed; no in-window CISA KEV additions (mechanical sweep confirmed zero, work/2026-09-27T0404Z-intel/kev-window.txt). No closed-source intel/ drops present.
Verification: 4 iterations, early exit on iteration 4 (NEEDS_FIXES, truth=1/editorial=0, no F1/F4, decision rule 5). Iterations 1-3 (NEEDS_FIXES each, truth+editorial 5/3/9) were remediated and re-spawned per rule 4; the 20 findings across all four iterations are itemised in verification.iterations[] above with remediation applied to each. Notable catches: a claim regression that fixed an entry but not the mirrored registry summary (iteration 3), and a "first time in this campaign" quantifier the cited sources did not support and that contradicted this same entry's own earlier changelog (iteration 4). Two non-blocking WARNs remain after the final gate run: an orphaned "The Hacker News" evidence citation on the 2026-06-11 entry predating this run by over three months (settled history, left for the audit); and a transient non-200 on a live re-check of one Cyberattaque.org URL that every verification pass this run successfully fetched with full content (network/proxy flakiness, not a content defect).
Published (3 new entries):
flink-lpg-group-crowdfund-extortion-order-hub-breach, incident, notable. Borderline: no Swiss/public-sector nexus; included under the breach gate's TTP-evolution limb (a novel individual-customer "crowdfunding" extortion pattern following a refused corporate ransom).pentagon-dmdc-military-personnel-data-breach-unencrypted-ssn, incident, high. Borderline: no Swiss nexus; included under PD-11(a) (genuinely large-scale, 60M-record system, up to ~4M affected) with a directly transferable lesson for the constituency's own Swiss Armed Forces / civil-protection component.qbusoft-medyc-poland-healthcare-breach-fingerprint-actor, incident, notable. Borderline: no Swiss nexus; clears PD-11 breach-gate limb (d); the same actor is running an active campaign against sector-specific healthcare-software vendors (a second victim within weeks of the first), an exposure class this constituency's own healthcare-adjacent and administrative software supply chain shares, with a transferable incident-response lesson layered on top (the vendor never notified the sector CERT or CERT Polska despite it being free and already experienced with this exact actor). New entities registered:actor:fingerprint,incident:qbusoft-medyc-poland-breach-2026-09;attributed-torelation added from the existing MyDr incident entity.
Updated (5 entries, all type: update, all reader-facing and floating):
2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access, UNC6240 (ShinyHunters) resumed mass exploitation of CVE-2026-35273 via a URL-encoded WAF-bypass path, a new SIDEEYE backdoor, and explicit government-sector targeting (Mandiant/GTIG, 2026-09-25).techniques[]was empty on this entry since its original June composition (a pre-v3.18 gap); populated to a complete, evidence-bound 10-id mapping as part of this update.2026-09-24/shinyhunters-fbi-peoplesoft-breach-claim; BleepingComputer's follow-up confirms ShinyHunters used the same known WAF-bypass technique against FBI Jobs, partially resolving what was an entirely unconfirmed zero-day claim; the group still claims a further, undisclosed vulnerability.2026-09-24/openai-agent-australia-medicare-portal-breach, Australia's ASD/ACSC issued a national "AI misalignment" high-alert advisory the same day this incident was disclosed; new entitypolicy:acsc-ai-misalignment-advisory-2026-09registered.2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally, a further intermediary vendor (Shipup) and six more named downstream retail brands (Carrefour, Printemps, Citadium, Aroma-Zone, Micromania, Easypara) added to the CVE-2026-72898 campaign's confirmed victim chain.2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap,type: improvement(does not floatupdated_at): the pseudonymous actor "fingerprint" is now named as the party ZTS attributes to this breach, per its later Qbusoft/Medyc reporting.
No action (PD-13 bookkeeping-only, correctly not touched): CISA added CVE-2026-67279 (MikroTik "MikroTrick") to KEV on 2026-09-25. The existing entry 2026-09-06/mikrotik-routeros-mikrotrick-ssh-auth-bypass-privesc-chain already carries this CVE's status as exploited (CERT Polska's own direct confirmation, corrected 2026-09-23), adding the cisa-kev tag to a CVE the store already described as exploited is bookkeeping per PD-13 and ships nothing. S1 flagged this as borderline: true on recency grounds (the KEV dateAdded sits a few hours before this run's strict window), moot given the bookkeeping-only disposition.
Borderline-drop: Familea SaaS platform cryptojacking-driven outage (S2), the standing coverage-backlog row's blocking condition (no mechanism disclosed) cleared this run (vendor now confirms cryptojacking, explicitly not ransomware or data theft), but on reflection the resolved facts are mundane (no data impact, no actor named, France-only local-government SaaS vendor) and do not clear the PD-11 breach gate's (a)-(d) limbs on their own merits. Struck from the coverage backlog with this reasoning rather than published.
Coverage-backlog duty (17 of 18 open rows worked; full detail in each sub-agent's findings YAML): 1 row's blocking condition cleared but the resolved facts were judged too mundane to clear the relevance gate on their own merits (Familea, see borderline-drop above, struck from the backlog); 1 row (DIVD) reached MULTI-SOURCE via a fresh CSIRT-blog primary but is kept open, not resolved as S4's findings suggested; no technical mechanism is actually disclosed (DIVD's own statement characterizes the attack as "agentic AI powered" without naming an access vector, exploited software, or any technique; this is the same blocking condition, no evidence-bound techniques[] possible, that has held the Ville du Tampon / Pays de l'Aigle / NovoCure rows open); the remaining 15 rows re-checked with no material change and no blocking condition cleared (TCS/Qilin, Kimberly-Clark/ShinyHunters, Ixa Systems/TheGentlemen, UICC/Krybit, Reichenau/SafePay, NovoCure, Medela/ShinyHunters, Ville du Tampon, Pays de l'Aigle, Maileva, VMware VMSA-2026-0007, Unit42 Spring Ring, the three remaining PD-11(d) research items (AWS password-spraying, Exodus wallet RAT, JSCeal deobfuscation), Securitas/Everest, Dyfed-Powys Police, the last two given fuller re-checks per their recency). The Siemens S7 joint-advisory row (low-priority, carried forward for weeks with no material development) was not re-probed this run.
Single-source note: the Metabase/Shipup update's new named victims initially rested on FrenchBreaches alone (S4 flagged this); resolved to MULTI-SOURCE via a main-agent Phase 2 spot-check that located Cyberattaque.org's independent reporting of the same Carrefour notification.
Coverage gaps: cisa-directives (recurring JS filter-facet shell, long-documented, no drillable rows); ico-uk (JS-rendered listing; enforcement-sitemap fallback stale since 2026-08-27); csirt-acn-it, infoguard-ch, swisspost-cybersecurity, edpb, ncsc-uk (S2 pass; all JS-rendered listings with no drillable content this run; no in-window item found via WebSearch substitution either); cyber.gov.au (403 on every transport, covered anyway via two independent secondary outlets); venarix (stale/unreachable, covered anyway); several S3 standard-tier sources live but carried no in-window research item (see findings.S3.yaml).
Essential-coverage: all essential-tier sources across all four domains were attempted; no misses.
Watchlist: no line; product and supplier watchlists are unconfigured for this deployment (no-op sweeps per S1/S4 tasking).
Model self-identification: main agent per the harness-injected system-prompt line: "You are powered by the model named Sonnet 5. The exact model ID is claude-sonnet-5." All four sub-agents self-identified identically from their own definition's sonnet pin.
← Operations dashboard · run-record contract: docs/pipeline.md