CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

2026-10-03T0404Z-intel

One pipeline fire, in full · intel run of 2026-10-03 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-10-03/2026-10-03T0404Z-intel.md.

Run telemetry

2026-10-03T0404Z-intel intel prompt v4.18 publish ok
1h 21m duration 1 published 3 updates
Claude Sonnet 5.5 (claude-sonnet-5-5) main agent
S1 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
4
Duration
23m 25s
Tool calls
14 WebFetch22 WebSearch110 bridge
Cited sources
2 of 18 in slice
S2 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
7
Duration
21m 39s
Tool calls
10 WebFetch46 WebSearch75 bridge
Cited sources
5 of 27 in slice
S3 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
8
Duration
19m 41s
Tool calls
1 WebFetch11 WebSearch160 bridge
Cited sources
4 of 14 in slice
S4 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
7
Duration
22m 48s
Tool calls
11 WebFetch46 WebSearch80 bridge
Cited sources
4 of 12 in slice

Verification

#1 NEEDS_FIXES · Sonnet 5.5 · t=7 e=3 a=3 #2 NEEDS_FIXES · Sonnet 5.5 · t=4 e=1 a=3 #3 NEEDS_FIXES · Sonnet 5.5 · t=2 e=0 a=2

Deep dive

·

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

12 notes · 6 last_successful_fetch · 3 added · 3 recipe · 2 status.

SourceChangeFrom → ToReason
bleepingcomputerlast_successful_fetch2026-10-02 → 2026-10-03fetched and used (cited in a published or updated entry this run)
fortinet-psirtlast_successful_fetch2026-10-02 → 2026-10-03fetched and used (cited in a published or updated entry this run)
cisco-psirtlast_successful_fetch2026-10-02 → 2026-10-03fetched and used (cited in a published or updated entry this run)
ncsc-ch-security-hublast_successful_fetch2026-10-02 → 2026-10-03fetched and used (cited in a published or updated entry this run)
advisories-ncsc-nllast_successful_fetch2026-10-02 → 2026-10-03fetched and used (cited in a published or updated entry this run)
symantec-security-comlast_successful_fetch2026-09-14 → 2026-10-03fetched and used (cited in a published or updated entry this run)
bleepingcomputernotes· → recipe note appendedS4 verified the direct feed works
fortinet-psirtnotes· → recipe note appendedS1 verified a direct dated RSS recipe
enisa-euvdnotes· → recipe note appendedS1 verified the EUVD search API sweep
yeswehacknotes· → recipe note appendedS1 verified a working feed
censys-blognotes· → recipe note appendedS1 verified a working feed
bsi-denotes· → recipe note appendedS2 found the non-WID news listing recipe
news-admin-chnotes· → recipe note appendedS2 confirmed the recipe
ransom-isacnotes· → recipe note appendedS4 verified a working feed
cloudflare-cf1notes· → recipe note appendedS3 verified a working feed
elttam-blognotes· → recipe note appendedS3 verified the feed recipe
ssd-disclosurenotes· → recipe note appendedS1 re-probed; unchanged
ransomware-livenotes· → recipe note appendedS4 verified additional endpoints
it-connectadded· → status: candidateAdded 2026-10-03: French-language security news with a working direct RSS (dated, 15 items) and fast in-language readings of ANSSI/CERT-FR documents; it carried the ANSSI innovation-lab and DINUM Metabase compromises from the REAC
mikrotik-routeros-changelogadded· → status: candidateAdded 2026-10-03: first-party, plain-text and dated; NEWESTa7.stable / .long-term / .testing return '<version> <epoch>' and https://upgrade.mikrotik.com/routeros/<version>/CHANGELOG returns the release notes (verified 7.23.4 to 7.
parlament-ch-curia-vista-odataadded· → status: candidateAdded 2026-10-03: the standing policy watch needs dated parliamentary status (motion adopted, referred, bill stages); the Curia Vista pages are a JS template no transport reads, but the OData service answers with status, status da
ibm-support-security-bulletinsstatuscandidate → activepromotion_due: cited by published entries from at least 3 distinct runs (state digest)
europol-newsroomstatuscandidate → activepromotion_due: cited by published entries from at least 3 distinct runs (state digest)
mikrotik-routeros-changelogrecipe· → health_cmd, content_scopeNEWESTa7.stable returns only '<version> <epoch>', so the health check reads the 7.24 CHANGELOG instead (verdict relevant: 13.7k characters, 'security'); release notes are legitimately mostly non-security (general-news scope).
news-admin-chrecipe· → health_cmd, content_scopethe bare /de/newnsb page carries no security vocabulary; the date-filtered listing recipe reads 12 dated federal items (verdict relevant, newest 2026-10-03); a general federal news listing is legitimately mostly non-security (general-news scope). Move start_date forward when the probe turns stale.
parlament-ch-curia-vista-odatarecipe· → url, health_cmd, content_scopethe unfiltered OData entity set is too large to probe; the record URL now returns one business ($top=1) and the health check reads motion 24.4393 (verdict relevant: phishing, malware terms); parliamentary data is legitimately mostly non-security (general-news scope).

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
ssd-disclosurehttps://ssd-disclosure.com/advisories/url --direct → webfetch → websearch202 captcha
SiteGround captcha: HTTP 202 with an empty body on every direct GET; WebFetch returns an empty body; WebSearch site: queries return only old advisories
recorded as a coverage gap; recipe unchanged (blocked on every transport)
inside-it-chhttps://www.inside-it.ch/ (article pages)bridge:feed → webfetch429 vercel-checkpoint
article pages return the Vercel security checkpoint (HTTP 429) to extract, WebFetch and the reader; RSS teasers are readable
RSS teasers used as leads only; the lead (Swiss motion 24.4393) was traced to the parliament primary and then dropped

Bridge invocations (this run)

10 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).

10 other
  • extract ×8
  • url ×1
  • ncsc-csh ×1

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #1 NEEDS_FIXES · 13 findings (truth=7, editorial=3, advisory=3) · Claude Sonnet 5.5 · 12m 35s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
The Fortinet page as read on 2026-10-03 (extract, raw url, WebFetch) has no file table: its IoC section lists two IPs, system event logs and encryption logs only; WebFetch: 'No table of added/modifiedFortinet attribution split: the cron, archive-account and IBE-log clauses stay cited to Fortinet; the file list is attributed to BleepingComputer (which says Fortinet published the table) and NCSC Switzerland, the body…
F4
hallucinated-fact
·
'Corrected' (also the record summary 'restated as written', the body's 'which is not Fortinet's wording', and the run-record note 'the earlier text had ... management interface where Fortinet's advisoReframed: the update and record summary now say Fortinet's advisory as read on 2026-10-03 words the workaround as the webmail interface and adds the WAF option, that press and NCSC Switzerland say management interface…
F4
hallucinated-fact
·
Not a substring of the live Fortinet page, which reads 'Disable the IBE feature support via the GUI ( Encryption -> IBE -> IBE Service 'off' ) or with the following CLI command:' (extract, raw and theevidence[1] replaced with the sentence now on the Fortinet page (quote checked verbatim against the saved body)
F3
claim-not-supported
·
2026-10-03 is the pipeline fetch date. The page's visible dateline is 'Updated: July 1, 2026' (<div id=documentInfo>) and its meta date is 'Tue Aug 04 22:51:17 PDT 2026'. Use the page's own date. The Live Protect source dated by the page's own dateline (2026-07-01) in sources[] and inline
F3
claim-not-supported
·
(low confidence) Symantec does not recommend replacing machine keys; the entry's own Exposure paragraph says 'Symantec does not address key replacement', and the same recommendation sits in actions[0]Microsoft's ToolShell guidance (read, quote confirmed on the page) added as a source and cited for key rotation; Symantec no longer carries that advice (final wording set in iteration 2)
F4
hallucinated-fact
·
(low confidence) Symantec installs the tunnel (code-insiders.exe tunnel service install, from the Windows debug folder) on 'Computer 4', one of the three 'further hosts' where SPSEPRDSetup was added tTriage reworded to 'a host in a domain already showing SharePoint exploitation or an unexpected administrator account'
F5
missing-citation
·
(low confidence) Both sentences carry no inline link; each is supported by Symantec (first activity July 22 via PowerShell WriteAllBytes into the layouts directory; a.exe on at least 40 hosts; 'The idSymantec link added to the web-shell sentence and to the K7RKScan sentence
F9
surface-contradiction
·
(low confidence) A source the entry cites for the IBE condition states fixes were released ('Betreft: Kwetsbaarheid verholpen in Fortinet FortiMail'; 'Fortinet heeft een kwetsbaarheid verholpen'), conContradiction added next to the NCSC-NL citation in the Exposure line: NCSC-NL says fixes were released, Fortinet's table lists them as upcoming, Fortinet's table is followed
F2
generic-url
·
(low confidence) The whole-catalog KEV JSON feed (1,733 records) is cited for 'CISA added the CVE to its KEV catalog on 2026-10-01'; it is a listing, not a per-event page, and predates this run. A perSource replaced by the per-event CISA alert page (https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog), cited inline
F8
needs-more-research
·
(low confidence) The cited Live Protect page states the support rule that answers the question left open: 'Cisco creates Vulnerability Shields for the SD-WAN release that is current when the shield isShield support rule added from the Live Protect page (current release plus the two immediately preceding in each supported train that includes Live Protect; older releases may have no shield); the 'advisory does not…
F11
editorial-advisory
·
The main body deliberately describes the artifacts without names; this section (and the verbatim NCSC-CH evidence quote) names attacker-added binaries `webconsole` and `mailservice`, which are file-naFile-name indicators removed from the Update section and the NCSC-CH evidence quote cut to a fragment without names; the narration sentence reduced to which text the reader should trust
F11
editorial-advisory
·
The analysis was rewritten to the new state, so the changelog sections restate facts the reader has just read. Keep the delta only (Belnet: CCB engaged, 2026-09-29 link removal and disabled transfers,Belnet Update section cut to the delta (CCB, 2026-09-29 link removal and disabled transfers, new transfers needed); the Cisco Update keeps the revision wording, side effect, modes and support rule; the FortiMail Update…
F11
editorial-advisory
·
Symantec states the SPSEPRDSetup account name 'is likely an attempt at masquerading' ('SharePoint commonly provisions service accounts with names following an SPS/SP-prefixed setup'); T1036.010 (MasquT1036.010 added to techniques[] (setup-lookalike domain account, which Symantec calls likely masquerading); id checked active in the pinned dataset

Iteration #2 NEEDS_FIXES · 8 findings (truth=4, editorial=1, advisory=3) · Claude Sonnet 5.5 · 10m 30s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
Remediation #5 is incomplete. The takeaway still places key rotation inside a clause terminated by the Symantec link, and the Symantec report carries no rotate/replace/restart-IIS advice (it only saysTakeaway now cites Symantec only for the web shell and setup-lookalike accounts, and cites Microsoft's ToolShell guidance for rotating the machine keys and restarting IIS on all SharePoint servers; the action matches…
F4
hallucinated-fact
·
(low confidence) 'then' places DLL sideloading and domain account/trust enumeration after the 2026-07-28 exploitation chain. Symantec dates both to 2026-07-24 ('Malicious activity resumed on July 24 w'then' changed to 'also' so the sideloading and enumeration sentence no longer implies an order after 2026-07-28
F3
claim-not-supported
·
(low confidence) The cited Belnet notice does not describe Belnet as a government and research network. The only cited page that does is Risky Bulletin ('a government-funded internet provider that catRisky Bulletin (the cited page that describes Belnet) added to the FortiMail sources and cited at the first mention of Belnet in the Update
F14
quantifier-without-source
·
(low confidence) No cited source says the workarounds are the only control; Fortinet's page lists three workarounds and 'Virtual Patch: No', BleepingComputer says 'apply the shared workarounds until a'the only control' reworded to 'the available mitigation' in the summary
F18
action-item-discipline
·
Fails check 10b(c): the task is not executable without re-reading the entry ('the compromise check described in the body'). Name the check in the action (audit serviceproxy-access.log for POSTs to theactions[1] now names the checks: serviceproxy-access.log for POSTs to the login path with a percent-encoded character from unknown addresses, vmanage-server.log for login-path requests tied to viptela-reserved- user…
F11
editorial-advisory
·
After the Update section was cut to the delta, the record summary states more than the section: the 2026-09-25 remediation (already in the main analysis), 'the FortiMail path traversal ... without namBelnet record summary cut to what the Update section states (supplier named, advisory linked, Centre for Cybersecurity Belgium assisting, transfers disabled on 2026-09-29, new transfers needed)
F11
editorial-advisory
·
(low confidence) The cited page and BleepingComputer give only the path '/migadmin' (cron 'O=/migadmin ...') and 'migadmin.tar.gz'; 'migration' is the entry's expansion of the abbreviation and no sour'migration directory' and 'admin-migration archive' replaced by the sources' own strings: a cron command referencing the /migadmin path and a modified migadmin archive
F11
editorial-advisory
·
Composition narration rather than a finding for the reader; the preceding sentence already states which wording the Fortinet page carries. Drop it (advisory).closing narration sentence removed from the FortiMail Update

Iteration #3 NEEDS_FIXES cap-breach · 4 findings (truth=2, editorial=0, advisory=2) · Claude Sonnet 5.5 · 10m 18s

F-codeSectionItem · URL/quoteVerifier summaryRemediation · outcome
F3
claim-not-supported
·
(low confidence) The BleepingComputer file table lists `/data/lib/liblog.so` Added and `/data/etc/ld.so.preload` Added as two separate rows and never says the library is registered through the preloadFortiMail BleepingComputer clause reworded to what the table shows: a library added under the data partition, an added ld.so.preload file, a modified system binary, two added binaries, a modified web server…
F3
claim-not-supported
·
(low confidence) Cisco's page reads 'For help determining if Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco Technical Assistance Center (TAC). Cisco TAC cCisco Detection reworded to Cisco's wording: customers may open a Severity 3 TAC case with the CVE id in the title and are encouraged to run request admin-tech first
F11
editorial-advisory
·
(low confidence, advisory) Microsoft's step reads 'After applying the latest security updates above or enabling AMSI, it is critical that customers rotate SharePoint server ASP.NET machine keys and reWarlock takeaway and action now carry the sequencing from Microsoft's guidance (once patched, rotate the machine keys and restart IIS on all SharePoint servers)
F11
editorial-advisory
·
(low confidence, advisory) 'now' asserts that Fortinet changed its wording, but the Update section only says the advisory 'as read on 2026-10-03' words it that way and the page's timeline lists only ''now' dropped from the FortiMail record summary

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-10-03T0404Z-intel · Sonnet 5.5 · window 26 h · 1 entry published

Verification & coverage notes

Coverage window: standard fire. The previous intel fire started 2026-10-02T04:04Z, so gap_hours=24.0 and window_hours=26; the developing-story window was 72 hours. The container clock was cross-checked against an external date header (skew 0 s) and origin/main was fresh at preflight.

Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found two CISA KEV additions in the window, Zammad CVE-2026-102489 and CVE-2026-102490 (added 2026-10-02), both COVERED by the existing Zammad entry; no row was NOT COVERED, MENTION-ONLY or COVERED-STALE (work/2026-10-03T0404Z-intel/kev-window.txt). S1 confirmed catalog version 2026.10.02 and found every EUVD-exploited record already covered.

New entry (1): Longlegs (Storm-2603) and the Warlock ransomware, still entering through on-premises SharePoint (threat, high; Symantec's report of 2026-10-01 with same-day-plus-one relays by BleepingComputer, The Record and SecurityWeek; single assessor, so verification is single-source and credibility 2). It was surfaced by two domains independently (S3 and S4); the primary is a day older than the window start, and it passed the recency rule because the freshest sources are the in-window relays and nothing in the store covered it. Priority is high because on-premises SharePoint is the entry technology of two Swiss breaches already in the store and the machine-key theft means patching alone does not close the exposure. No CVE record is carried: Symantec names the ToolShell CVEs only as likely still in the arsenal.

Updates (3): FortiMail CVE-2026-104286 (update: Belnet's notice, which links this advisory, puts exploitation from 2026-07-22; NCSC Switzerland's note on the artifacts; the entry now follows Fortinet's advisory as read on 2026-10-03, which words the second workaround as the webmail interface and adds a WAF rule on POST /ibe, while BleepingComputer and NCSC Switzerland say management interface; the previous fire's verifier read Fortinet's page with the management-interface wording and a file table, and the page's timeline lists only the initial publication, so Fortinet appears to have revised it without a timeline entry; the file list is now attributed to BleepingComputer and NCSC Switzerland and the CISA citation points to the per-event alert); Belnet incident (update: supplier named as Fortinet, FG-IR-26-175 linked, Centre for Cybersecurity Belgium engaged, transfers disabled on 2026-09-29; priority raised from routine to notable because a vector class is now known; the first evidence quote no longer matched the page and was replaced); Cisco Catalyst SD-WAN Manager CVE-2026-76504 (update: advisory revision 1.1 adds a Live Protect shield, temporary and partial, with a login side effect and a support rule limited to the current and two preceding releases of trains that include Live Protect).

Contradictions: NCSC-NL (NCSC-2026-0398) says Fortinet released security updates for FortiMail while Fortinet's table lists 8.0.2, 7.6.7 and 7.4.9 as upcoming; the FortiMail entry follows Fortinet and states the contradiction. BleepingComputer and NCSC Switzerland say management interface for the second workaround where Fortinet's current page says webmail interface; the entry follows the Fortinet page and says so.

Backlog (7 open rows, all held, none changed): S1 re-gated IBM MQ CVE-2026-10747 with the three Langflow CVEs, MikroTik CVE-2026-84411 and IBM Guardium CVE-2026-85542; S4 re-gated Qilin/Touring Club Suisse, Everest/Securitas, SafePay/ARA-Region Lyss-Limpachtal and Payload/Netech. Every stated hold condition is unmet (no KEV listing, exploitation report or public PoC; no victim statement or press confirmation; ZATAZ analysed the Everest file tree but states origin and access are unconfirmed). No row text was appended, per the no-carry-forward rule. Nearest expiry is Qilin/TCS on 2026-10-05.

borderline-drop / out-of-window:

  • borderline-drop: OrdaSoft OS CCK for Joomla CVE-2026-102427 (unauthenticated PHP upload, CVSS 4.0 10.0, fixed in 8.3.16 but the vendor updater still offers 8.3.14): not exploited, not in KEV, niche extension with no constituency deployment evidenced, single source (mySites.guru); below the PD-11(b) bar.
  • out-of-window: tac_plus pre-auth format string (elttam, primary 2026-09-23, beyond the source's 168 h lookback, CVE pending, internal management plane, no exploitation); Huntress municipal recreation-platform web shell (2026-09-30, US platform, no CVE).
  • borderline-drop: NeedyMantis (Microsoft, 2026-09-28), already dropped by the 2026-09-30 and 2026-10-02 fires; TA419 (Proofpoint, 2026-10-01: adversary-in-the-middle phishing of US/Japan policy and defense staff, technique not new, indirect relevance); Microsoft Digital Defense Report 2026 (vendor telemetry shares read from PDF chart text, no defender decision); DragonForce Lab52/Seqrite (2026-10-01: a second backdoor with an MQTT fallback resting on one lab's artifact-overlap attribution, on a legacy entry whose guidance already covers TURN egress and side-loading); Sysdig's Zammad hunts (same signals as the entry's Detection line).
  • borderline-drop: CERT-FR/CERT Santé health-software report CERTFR-2026-CTI-007 (no vendor, no CVE, French health sector); Swiss motion 24.4393 on .ch/.swiss domain-holder identification (a mandate to draft law, the text finally referred is not stated); BSI's Classic McEliece notice (cryptographic-baseline advice, not a SOC decision); SRG/SRF employee data (2020 contact data, no vector); ATEXO/Region Hauts-de-France, Svedala kommun and the US municipal incidents (incident floor: no vector, no actor, no behavior beyond impact; no Swiss nexus).
  • borderline-drop: OpenAI's count of over 100 notified organizations (scope statement, no decision for the constituency, five entries already carry the saga); VOISING/ApplyNow Metabase fallout (the Metabase link is Piyolog's inference, Japan); the ANSSI REACTIV lab/DINUM details (read by eye from an image-only PDF, no new decision); the ShinyHunters arrest statements (vanity figures, no defender action); the Censys exposure share for NetScaler (improvement-only).
  • borderline-drop: WatchGuard AP CVE-2026-101891 and CVE-2026-86102 (9.3, no exploitation, access-point management network), Zimbra 10.1.21 CVEs CVE-2026-66911 and CVE-2026-66912 (reserved, no exploitation; the fix is already carried by the CVE-2026-73570 entry), Dell CSM, GitLab AI Gateway, Apache httpd 2.4.69 (Apache rates all 20 as low or moderate), Joomla core 5.4.9/6.1.4, Chrome 154, Exchange CVE-2026-96940, Palo Alto CVE-2026-0250: patch-cycle items with no exploitation.

Single-source / reduced confidence: the Warlock entry rests on Symantec alone (relays add nothing); the Belnet-to-FortiMail link is Belnet's own pointer to the advisory, and Belnet does not name the product, which the entry states.

Sources: 26 changes in sources_changed: last-success dates for the six sources cited, recipe notes verified by the sub-agents (BleepingComputer and Fortinet direct feeds, the EUVD search API, YesWeHack, Censys, BSI's news listing, news.admin.ch, ransom-isac, Cloudflare Cloudforce One, elttam, ransomware.live endpoints), three new candidates (it-connect, mikrotik-routeros-changelog, parlament-ch-curia-vista-odata) the two due promotions (ibm-support-security-bulletins, europol-newsroom) and the health recipes for the three records the health check flagged (news-admin-ch, mikrotik-routeros-changelog, parlament-ch-curia-vista-odata: each now carries a tested health_cmd and content_scope: general-news). ssd-disclosure stays blocked on every transport.

Tool findings for the next audit (not fixed here): fetch_source.py pdf on an image-only PDF (CERTFR-2026-CTI-006) exits 0 and prints binary noise instead of reporting that the file has no text objects (S4's workaround: download the file and read rendered pages); fetch_source.py extract on theregister.com returns navigation boilerplate instead of the article body; the rapid7-research feed returned HTTP 404 (S3). The S1 sub-agent spent 7 unintended reader-pool fall-throughs (extract and feed auto-fallback), no deliberate reader use.

Coverage gaps: ssd-disclosure (blocked on every transport); inside-it-ch (article pages HTTP 429, RSS teasers only); ncsc-ch-incidents (undated listing, no in-window addition can be dated); anssi-fr (CERT-FR timestamps are flat 00:00 UTC); europol-newsroom (SPA shell, not in a slice); rapid7-research (feed HTTP 404, not in a slice).

Verification: three iterations, none CLEAN. Iteration 1 (truth 7, editorial 3) found the Fortinet file-table attribution, a wrong 'corrected' framing, a stale evidence quote and attribution slips; iteration 2 (truth 4, editorial 1) found a partly fixed rotation attribution and wording slips; iteration 3 (truth 2, editorial 0, no F1 or F4) found two low-confidence wording points and two advisories, so the early-exit rule applied: all four were fixed after the iteration and the run published without a fourth pass. verification_residual_count is 2, the final iteration's truth plus editorial count, although both findings are remediated on disk. The first-iteration finding on the Fortinet page is worth the audit's attention: Fortinet changed the advisory text (management interface to webmail interface, a file table dropped) without a timeline entry, so a vendor revision can be invisible to a check that trusts the page's own revision history.

← Operations dashboard · run-record contract: docs/pipeline.md