CTIPilot

2026-09-29T0405Z-intel

One pipeline fire, in full · intel run of 2026-09-29 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-29/2026-09-29T0405Z-intel.md.

Run telemetry

2026-09-29T0405Z-intel intel prompt v4.12 publish ok
3h 04m duration 5 published 4 updates
Claude Sonnet 5 (claude-sonnet-5) main agent
S1 Claude Sonnet 5 (claude-sonnet-5)
Items returned
3
Duration
11m 33s
Tool calls
0 WebFetch11 WebSearch34 bridge
Cited sources
5 of 25 in slice
S2 Claude Sonnet 5 (claude-sonnet-5)
Items returned
4
Duration
12m 58s
Tool calls
2 WebFetch11 WebSearch30 bridge
Cited sources
4 of 27 in slice
S3 Claude Sonnet 5 (claude-sonnet-5)
Items returned
6
Duration
9m 52s
Tool calls
3 WebFetch8 WebSearch22 bridge
Cited sources
5 of 16 in slice
S4 Claude Sonnet 5 (claude-sonnet-5)
Items returned
2
Duration
14m 21s
Tool calls
6 WebFetch20 WebSearch22 bridge
Cited sources
3 of 18 in slice

Verification

#1 NEEDS_FIXES · Sonnet 5 · t=5 e=0 a=2 #2 NEEDS_FIXES · Sonnet 5 · t=7 e=5 a=0 #3 NEEDS_FIXES · Sonnet 5 · t=5 e=2 a=1 #4 NEEDS_FIXES · Sonnet 5 · t=3 e=1 a=2 #5 NEEDS_FIXES · Sonnet 5 · t=3 e=0 a=0 #6 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #7 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=0 #8 NEEDS_FIXES · Sonnet 5 · t=2 e=1 a=0

Deep dive

2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware

Entries this run published (5) and updated (4)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

11 last_successful_fetch · 1 consecutive_quiet_periods.

SourceChangeFrom → ToReason
ncsc-ch-security-hublast_successful_fetch2026-09-26 → 2026-09-29fetched and used (Citrix root-cause + Kiteworks component-naming corroboration)
ncsc-uklast_successful_fetch2026-09-16 → 2026-09-29fetched and used (Citrix corroboration)
cert-eulast_successful_fetch2026-09-28 → 2026-09-29fetched and used (Citrix corroboration, already-cited advisory re-confirmed)
anssi-frlast_successful_fetch2026-09-22 → 2026-09-29fetched and used (CERT-FR CERTFR-2026-AVI-1235)
bsi-delast_successful_fetch2026-09-18 → 2026-09-29fetched and used (WID-SEC-2026-3602, Kiteworks component naming)
ncsc-ch-focuslast_successful_fetch2026-09-23 → 2026-09-29fetched and used (Störfallbetriebe pilot article, not published, borderline-drop, source still counts as fetched)
heise-seclast_successful_fetch2026-09-27 → 2026-09-29fetched and used (OpenAI misalignment story, BDBOS Digitalfunk item)
kaspersky-securelistlast_successful_fetch2026-09-21 → 2026-09-29fetched and used (PAYLOAD GPO ransomware deep dive)
huntressconsecutive_quiet_periods· → 1fetched but not used; the WWAHost item re-surfaced was already published 2026-09-27; correctly not re-published as a duplicate
krebslast_successful_fetch2026-09-14 → 2026-09-29fetched and used (ShinyHunters/FBI update, Dutch arrest, SLSH)
cyberscooplast_successful_fetch2026-09-24 → 2026-09-29fetched and used (ShinyHunters/FBI update)
hackernewslast_successful_fetch2026-09-22 → 2026-09-29fetched and used (Bitget theft corroboration)

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
fbi-gov-press-release
covered via alternate · should NOT be in this list
https://www.fbi.gov/news/press-releases/fbi-statement-on-compromise-of-fbijobsgodirect → trafilatura → jina403 all-transports-failed
direct=403; trafilatura=no readable body; jina=balance exhausted on all rotated keys (HTTP 402)
composed from Krebs on Security and CyberScoop, both of which quote the release directly and consistently
databreaches-net-silent-ransom-hogan-lovellshttps://databreaches.net (Hogan Lovells/Cadwalader Silent Ransom Group re-attackbridge:extract403 all-transports-failed
bridge:extract's internal ladder, direct=403; trafilatura=no readable body; jina=balance exhausted; Dark Reading's companion piece also 403'd via the same bridg
item dropped, not published, only aggregator reprints of a single Admiralty-C original found, no victim confirmation or A/B journalism reachable

Bridge invocations (this run)

16 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

16 other
  • extract ×16

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 7 findings (truth=5, editorial=0, advisory=2) · Claude Sonnet 5 · 12m 25s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
evidence[] quote was a reworded/truncated splice of Microsoft's sentence, not a contiguous verbatim substringre-fetched the primary; replaced with the full contiguous verbatim sentence
F4
hallucinated-fact
·
evidence[] quote spliced two separate bolded sentences into one reworded string with no ellipsisre-fetched the primary; split into two separate verbatim evidence[] records
F4
hallucinated-fact
·
sourcing_note/body quote dropped the word 'yet' from TRM Labs' actual sentence, hardening TRM's hedgere-fetched the primary; corrected to 'has not yet definitively attributed'
F3
claim-not-supported
·
psychiatric/medical/SSN/5,000-personnel/Remote-Operations-Unit facts were cited to CyberScoop, which does not state them; Reuters/BBC were named as the source but neither is in sources[]re-fetched Nextgov/FCW's two articles (416280 and 416182), which are the actual origin (relaying Reuters/BBC for the medical-file facts, and Nextgov's own repor
F14
quantifier-without-source
·
(low confidence) 'second or third publicly disclosed training halt in three months' had no citationreplaced with OpenAI's own stated framing: the first pause since post-Hugging-Face-incident hardening
F11
editorial-advisory
·
(low confidence) entities[] omitted incident:openai-unctad-agent-scan-2026-04 despite references[] and body coverageadded the entity key
F11
editorial-advisory
·
(low confidence) overgeneralized a source sentence specific to EtherHiding/blockchain-hosted kit configuration into a broader claim about 'the major kits' fetching from 'a remote endpoint'rewrote to name the EtherHiding/smart-contract mechanism specifically, matching the source

Iteration #2 NEEDS_FIXES · 12 findings (truth=7, editorial=5, advisory=0) · Claude Sonnet 5 · 12m 06s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
the UN/DOE/SEC paragraph was unsupported by its cited TechCrunch/WaPo sources and the DOE detail was actively wrong (Nextgov names Census Bureau keys, not DOE, and Education was a failed attempt); there-fetched TechCrunch and WaPo/AP directly; rewrote the paragraph using only what those two primaries state (GitHub-token-smuggling incident, image-posting inci
F4
hallucinated-fact
·
frontmatter summary field still carried the uncited 'second/third training pause in three months' phrase after the body was fixed in iteration 1corrected summary and title to match the body's OpenAI-sourced framing; downgraded classification credibility 1->2 given the sourcing gaps this iteration found
F3
claim-not-supported
·
inline citation on the Nextgov/FCW 416182 URL was dated 2026-09-28; the article's own dateline (and this entry's sources[] record for the same URL) is 2026-09-24corrected the inline date label
F3
claim-not-supported
·
claimed the September arrest was 'tied to' a February 2026 Odido intrusion; Krebs treats the Odido voice-identification effort as separate and explicitly unresolved ('it remains unclear if the Dutch prewrote to describe the Odido voice-identification effort as a separate, unresolved Dutch police matter, not connected to the September arrest
F14
quantifier-without-source
·
(low confidence) title claimed 'confirmed government-sector victims across six countries'; Microsoft's sentence lists six countries and a separate aggregate sector list, not per-country confirmed govereworded the title to state the aggregate facts as the source presents them
F9
surface-contradiction
·
(low confidence) entry's original six-hour shutdown-window figure (Heise/BleepingComputer) was never reconciled against Kiteworks' own press release, which this run's update section cites and which stadded a sentence in the update section surfacing the discrepancy explicitly rather than silently picking one figure
F5
missing-citation
·
second body paragraph (loss estimate, User Protection Fund, forensics engagement) carried no inline citationadded a citation to Bitget's own incident page
F11
editorial-advisory
·
wallpaper/lock-screen-hijack behavior described in the body had no matching techniques[] id; T1491.001 (Internal Defacement) names this exact behavioradded T1491.001
F11
editorial-advisory
·
Anubis and BERT (two of the four RaaS brands Storm-2570 deploys per the primary) had no entity mentionlinked the pre-existing actor:anubis-raas registry entity; registered a new actor:bert-raas entity; added collaborates-with relations from actor:storm-2570 to b
F11
editorial-advisory
·
NCSC-CH source record carried a bare-year date ('2026') rather than the page's actual datelinecorrected to 2026-08-07
F11
editorial-advisory
·
mechanical duplicate migrated_from: null key introduced by this run's edits in both files' frontmatterremoved the duplicate line from both files
F11
editorial-advisory
·
internal sub-agent identifier ('S3') appeared in the run record's reader-facing coverage notesreworded to describe the domain instead of naming the sub-agent code

Iteration #3 NEEDS_FIXES · 8 findings (truth=5, editorial=2, advisory=1) · Claude Sonnet 5 · 11m 59s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
entry's absolute 'no malware binary resident on disk anywhere in the environment' / 'entirely through a malicious GPO' framing contradicted the primary's own statement that a PAYLOAD ransomware binaryre-fetched the primary; rewrote title, summary, body, Triage and Defender-takeaway sections to scope the no-binary/no-encryption finding to Windows specifically
F4
hallucinated-fact
·
registry entity summary, registered by this run, still carried the 'second/third training pause' and UN/DOE/US-government-scan claims that iterations 1-2 already found unsupported and removed from therewrote the registry summary to match the twice-corrected entry
F3
claim-not-supported
·
iteration-1's fix ('the first such pause since... hardening') itself overread OpenAI's actual text, which says only 'it's the first one [incident]' since hardening, not 'the first pause'reworded to 'the first incident of its kind' and added OpenAI's own qualifier that it is 'a lot less severe' than prior incidents, in both body and frontmatter
F14
quantifier-without-source
·
(low confidence) title's 'six countries' miscounted Puerto Rico as a country separate from the USreworded the title to drop the country-count claim entirely, stating only that government agencies are among the confirmed victims (also resolves the paired F11
F14
quantifier-without-source
·
(low confidence) frontmatter summary applied '5,000+' to both the SSN claim and the psychiatric/medical-file claim; Krebs ties the count only to the personal-info sample, not the medical-file findingreworded the summary to state the medical-file finding and the ~5,000-entry sample as separate facts
F9
surface-contradiction
·
(low-to-medium confidence) two unreconciled causal narratives for the same training pause: OpenAI's own report ties it to the DNS-tunnel incident, the entry's cited WaPo/AP text ties the same pause diadded a clause noting AP's account may describe the pause being disclosed together with, rather than caused by, the summer incidents, rather than asserting eith
F8
needs-more-research
·
entry omitted that an actual ransomware binary executed on ESXi/Linux servers and that exfiltrated data was later published on the dark web, both stated plainly by the primarysee F3 remediation above, both facts now in the entry
F11
editorial-advisory
·
iteration-2's title reword ('victims spanning six countries including government agencies and services') still read ambiguously, as if government agencies were one of the six countriessee F14 remediation above; the country-count clause was dropped entirely

Iteration #4 NEEDS_FIXES · 6 findings (truth=3, editorial=1, advisory=2) · Claude Sonnet 5 · 12m 51s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
(low confidence) T1046 (Network Service Discovery) mapped in techniques[] but no discovery/scanning behavior described anywhere in the body, even though Microsoft's blog covers NetScan/SoftPerfect/Nmare-fetched the primary; added a discovery-tooling clause (NetScan, SoftPerfect Network Scanner Portable, Nmap, native discovery commands) to the toolkit paragra
F4
hallucinated-fact
·
frontmatter summary conflated the roughly 5,000-entry PII sample (names/addresses/phones/relatives) with the separate counterintelligence-role finding (intelligence analysts, Remote Operations Unit pereworded the frontmatter summary to state the two facts separately, matching the body's own structure
F14
quantifier-without-source
·
'are all present across every Storm-2570 engagement Microsoft documents' overclaimed universality; Microsoft frames the Cloudflared persistent-service detail as observed 'in one intrusion' and MeshAgereworded to attribute the behaviors to what Microsoft's reporting documents/keys on across engagements, scoped the Cloudflared detail to 'in one intrusion', and
F5
missing-citation
·
(low confidence) the CEO's 'very likely' North Korean-involvement quote carried no inline citation of its own; the paragraph's only citation terminated the following, differently-scoped TRM Labs senteadded an inline citation to the already-listed 2026-09-25 Hacker News source directly after the CEO quote
F11
editorial-advisory
·
workflow-internal language ('sub-agents') survived in the reader-facing run-record notes, the same defect class iteration 2 already found and fixed once this run for a different notes linereworded 'across all four sub-agents this run' to 'across every research domain this fire covered'
F11
editorial-advisory
·
(low confidence) entry stated the no-encryption finding as settled without Kaspersky's own two-hypothesis hedge on why no encryption occurred; minor optional analytical depth, not a misstatementadded a sentence and a second verbatim evidence[] quote stating Kaspersky's own moderate-confidence two-hypothesis hedge (deliberate restraint vs. an interrupte

Iteration #5 NEEDS_FIXES · 3 findings (truth=3, editorial=0, advisory=0) · Claude Sonnet 5 · 9m 02s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
frontmatter summary attributed ransom notes, Administrator-account disablement, wallpaper hijack AND Windows Firewall disablement to a single GPO; Kaspersky's own primary states the firewall change careworded the summary to attribute the firewall change to a second, independently deployed GPO, matching the body
F3
claim-not-supported
·
iteration 4's own remediation of a prior missing-citation finding pointed the CEO 'very likely'/VPN-services quote at the wrong already-listed source (The Hacker News, which does not contain that phrarepointed the inline citation to the TRM Labs URL
F4
hallucinated-fact
·
(low confidence) body asserted the training run 'did not auto-stop and was halted manually 2.5 hours after the flag'; OpenAI's own report states only that the run was killed 2.5 hours later, without sreworded to state the 2.5-hour kill timing without asserting how the stop was triggered

Iteration #6 NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 11m 27s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
iteration 5's own remediation over-corrected: OpenAI's 'Investigation and response' section (not read by iteration 5, which only checked the Summary paragraph) explicitly states 'the run did not stop re-fetched the primary's full 'Investigation and response' section; restored 'did not stop automatically as expected and was manually stopped two and a half hou
F4
hallucinated-fact
·
registry summary still read 'its first training pause since post-Hugging-Face-incident hardening', the exact 'first pause' overread iteration 3 already found and fixed in the entry itself ('the first reworded the registry summary to match the entry's corrected phrasing

Iteration #7 NEEDS_FIXES · 2 findings (truth=2, editorial=0, advisory=0) · Claude Sonnet 5 · 9m 40s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
(low confidence) 'BNB Smart Chain' dropped the 'testnet' qualifier; Push Security's source specifies 'BNB Smart Chain testnet... with most of the traffic on testnets'added the testnet qualifier to BNB Smart Chain and a clause noting most observed traffic is on testnets
F4
hallucinated-fact
·
quoted fragment swapped Krebs' em dash for a colon and attributed to 'sources' what Krebs specifically attributes to 'experts' ('which experts say is an amalgamation of three hacking groups, Scatteredre-fetched the primary; corrected the quote to match Krebs' exact wording and punctuation

Iteration #8 NEEDS_FIXES cap-breach · 3 findings (truth=2, editorial=1, advisory=0) · Claude Sonnet 5 · 8m 59s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F4
hallucinated-fact
·
this run's own 'eight further CVEs, fourteen total' update itself undercounted: an independent full pass of Oracle's own September 2026 risk matrix (every row with Access Vector Network, Privileges Reindependently re-fetched and parsed Oracle's full risk matrix (confirmed 50 qualifying CVEs by programmatic cross-check of Access Vector/Privileges Required/Use
F14
quantifier-without-source
·
title/summary said the affiliate reuses 'an identical' toolkit; Microsoft's own post says only 'consistent tradecraft'/'largely uniform tradecraft', and the entry's own body already hedges per-tool (Mreworded title and summary from 'an identical' to 'a consistent'/'reusing a consistent' toolkit, matching the body's own hedged framing
F17
editorial-advisory
·
cross-entry reliability-letter inconsistency: OpenAI's and Bitget's own first-party incident accounts were rated reliability A while Microsoft's (Storm-2570) and Kiteworks' structurally identical firsdowngraded OpenAI and Bitget from reliability A to B, aligning with Microsoft/Kiteworks and the sources.json precedent for vendor/company self-reporting on thei

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-29T0405Z-intel · Sonnet 5 · window 26 h · 5 entries published

Verification & coverage notes

Run duration: 11083 s (~3.1 h), exceeding the 3 h runaway threshold. Cause: the verification loop ran all eight permitted iterations (none reached CLEAN), each a genuine independent cold-reader pass (~9-13 min) followed by main-agent remediation of real findings between iterations, including one substantial truth-gate fix (the Oracle CSPU CVE recount below) that required independently re-fetching and parsing Oracle's full risk matrix. No stall or infrastructure issue; the loop functioned as designed and simply exhausted its cap on a run with an unusually persistent stream of low-but-nonzero-confidence findings.

Verification loop outcome: iteration 8 (the cap) reached without a confirmed double-CLEAN; fail-open applies per decision rule 6. All eight iterations returned NEEDS_FIXES; finding counts across iterations 1-8: 5, 12 (corrected), 7, 6, 3, 2, 2, 3. verification_residual_count: 3 records iteration 8's own truth+editorial counts as found, per the fail-open rule. Despite the cap, all three of iteration 8's findings were remediated before publish (unconfirmed by a further independent pass, since none remains): the most significant was a genuine truth-gate failure in 2026-09-20/oracle-september-2026-cspu-five-unauthenticated-cvss-10, this run's own "eight further CVEs, fourteen total" update itself undercounted Oracle's September 2026 risk matrix by 36 CVEs (true total 50); the main agent independently re-fetched and programmatically parsed Oracle's full risk matrix to confirm the corrected count before rewriting the entry. The next quality audit should give this run's five most-revised entries (the Oracle CSPU update above, the OpenAI DNS-tunnel entry, the Kaspersky PAYLOAD entry, the ShinyHunters update and the Bitget entry) an independent cold pass, since each went through several rounds of self-correction without a final confirming CLEAN.

Coverage window: standard (gap_hours=24.02, window_hours=26), no catch-up disclosure required.

Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found zero CISA KEV additions since 2026-09-28; no KEV-addition disposition duty this run (see work/2026-09-29T0405Z-intel/kev-window.txt).

New entries (5): Microsoft Storm-2570 cross-RaaS ransomware toolkit (threat, high); Kaspersky PAYLOAD GPO-based encryptionless ransomware technique (threat, high, this run's deep dive, recovered from the 2026-09-27 audit's G3 gap list); Push Security ClickFix H2 2026 detection-data review (research, high, corroborated by a live NCSC-CH/BACS advisory); OpenAI DNS-tunnelling sandbox escape and self-replicating prompt injection (research, notable, OpenAI's own primary disclosures; the contemporaneous AP/WSJ reporting of agents scanning UN/Australian/US government sites is covered by reference to the already-tracked entities, not re-reported in detail); Bitget $388M hot-wallet theft (incident, high, clears the PD-11 breach gate on genuinely global scale/significance, one of 2026's largest crypto-exchange hacks, despite no direct Swiss public-sector nexus).

Updates (4): watchTowr's root-cause analysis (vulnerable component ns_monuploadd_err.pl, not nsppe; public detection tool) folded into 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev; Oracle CSPU broadening (8 further unauthenticated CVSS 9.8 CVEs across E-Business Suite, Business Intelligence, Enterprise Manager, Communications) folded into 2026-09-20/oracle-september-2026-cspu-five-unauthenticated-cvss-10, resolving the open backlog row; ShinyHunters/FBI breach escalation (FBI's own confirmation, Dutch arrest, ScatteredLapsussHunters brand-takeover reporting) folded into 2026-09-24/shinyhunters-fbi-peoplesoft-breach-claim; Kiteworks shutdown lifted + vulnerable component named (BSI/NCSC-CH) folded into 2026-09-26/kiteworks-precautionary-shutdown-imminent-zero-day-warning, priority moved high → notable.

Name-collision avoided (F15): Kaspersky's GPO-based "PAYLOAD" ransomware technique is unrelated to the pre-existing registry entity actor:payload-ransomware (a Zurich-area data-centre leak-site extortion group, unrelated victim/mechanism). No entity key was registered for the GPO technique to avoid conflating the two; the entry's sourcing_note states the disambiguation explicitly.

Duplicate correctly not republished: the research/investigative-reporting domain independently re-surfaced Huntress's WWAHost.exe AppX/OAuth-token-theft technique from the 2026-09-27 audit's gap list; cross-checked against the prior-coverage index and found already published as 2026-09-27/wwahost-appx-webauthbroker-oauth-token-theft. Dropped, not duplicated.

Backlog work (state/coverage_backlog.md): the Oracle CSPU row struck (published as the update above). Re-checked with "no change" notes appended: IBM MQ/Langflow bundle, Adobe September cycle, VMware VMSA-2026-0007, Unit42 Spring Ring, Boston Scientific, Qilin/TCS, ShinyHunters/Kimberly-Clark, TheGentlemen/Ixa Systems, Krybit/UICC, SafePay/Reichenau, Everest/Securitas, ShinyHunters/Medela, NovoCure, Dyfed-Powys Police, Ville du Tampon, Pays de l'Aigle, Maileva, DIVD (DIVD's own promised 2026-09-28 technical follow-up had still not been published as of this run; DIVD separately told Krebs its own internal incident is unrelated to ShinyHunters). Of the sixteen research-blog items on the "further publications" row, three published this run (Storm-2570, PAYLOAD GPO, ClickFix); thirteen remain open. A new row opened for the SRG/SRF employee-data breach (Swiss home-region, but no mechanism/actor named by any party, held per the same evidence-bound-techniques[] precedent as the Ville du Tampon/NovoCure/Boston Scientific rows).

  • borderline-drop: NCSC-CH/BAFU Störfallbetriebe cyber-resilience oversight pilot (CyRA) for Swiss major-accident-hazard facilities, a voluntary pilot with no new binding obligation and no concrete near-term defender action; does not clear PD-11(c)'s "changes what the constituency is obliged or advised to do" bar.
  • borderline-drop: Germany's BDBOS TETRA-to-5G/LTE Digitalfunk migration plan, a foreign-jurisdiction infrastructure roadmap with no incident, vulnerability, or concrete Swiss-actionable delta within the next 7 days; the Polycom-modernisation angle is background context, not an immediate decision point.
  • Single-source: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit, SINGLE-SOURCE, Microsoft's own XDR-telemetry blog; Microsoft is uniquely positioned to correlate this cross-RaaS-brand behavior from its own endpoint telemetry.
  • Single-source: 2026-09-29/kaspersky-payload-gpo-encryptionless-ransomware, SINGLE-SOURCE, Kaspersky GERT's own IR engagement.
  • Contradiction: none this run.
  • Coverage gaps: cisa-advisories (403 on the native advisory feed; jina reader pool exhausted on all rotated keys, substance not lost, cross-corroborated via cisa-kev + CERT-EU/NCSC-CH/CERT-FR/CCB Belgium); cisa-directives (long-documented JS-filter-shell recipe gap, no directive-specific content this run); reliaquest, jamf-threat-labs, team-cymru, air-security, depthfirst (S3 slice, all JS-shell/empty-listing recipe gaps, no in-window content recoverable via any transport tried); cert-at (stale-cached page title reproducing a documented 2026-09-20 audit finding); inside-it-ch (essential feed healthy, but two article-detail pages 429'd with the jina pool exhausted, one item recovered via its own primary + a corroborating outlet, one dropped for lack of independent corroboration).
  • The jina reader credential pool was exhausted (HTTP 402 on all rotated keys) across every research domain this fire covered, a normal, disclosed condition per operator directive; no substance was lost that could not be recovered via a direct/trafilatura transport or an alternate corroborating source, per the coverage gaps above.
  • Essential-coverage: none missed; all essential-tier records in each domain's slice were attempted.
  • Acknowledged WARN (not fixed, by design): reader-text-internals flags "The run" in 2026-09-29/openai-dns-tunnel-sandbox-escape-self-replicating-injection. Both occurrences are inside a verbatim evidence[] quote and its matching inline body quote of OpenAI's own sentence about its own training run ("The run was killed 2.5 hours later"), not a pipeline self-reference; altering the wording would violate the evidence-quote verbatim-fidelity rule (PD-1/PD-2). The surrounding prose was reworded to avoid the ambiguous phrase everywhere it is not a direct quote.

← Operations dashboard · run-record contract: docs/pipeline.md