2026-10-03T0404Z-intel
One pipeline fire, in full · intel run of 2026-10-03 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-10-03/2026-10-03T0404Z-intel.md.
Run telemetry
- Items returned
- 4
- Duration
- 23m 25s
- Tool calls
- 14 WebFetch22 WebSearch110 bridge
- Cited sources
- 2 of 18 in slice
- Items returned
- 7
- Duration
- 21m 39s
- Tool calls
- 10 WebFetch46 WebSearch75 bridge
- Cited sources
- 5 of 27 in slice
- Items returned
- 8
- Duration
- 19m 41s
- Tool calls
- 1 WebFetch11 WebSearch160 bridge
- Cited sources
- 4 of 14 in slice
- Items returned
- 7
- Duration
- 22m 48s
- Tool calls
- 11 WebFetch46 WebSearch80 bridge
- Cited sources
- 4 of 12 in slice
Verification
Deep dive
·
Entries this run published (1) and updated (3)
- CVE-2026-104286, Fortinet FortiMail: unauthenticated path traversal file write exploited as a zero-day, no fixed build yet (CVSS 9.8)
- CVE-2026-76504, Cisco Catalyst SD-WAN Manager: one percent-encoded character in the login path skips the password check and mints an admin API session, exploited in the wild (CVSS 9.8)
- Belnet, the Belgian government and research network, confirms a supplier zero-day let attackers copy all incoming mail to Belnet-owned domains and the transfer links its FileSender and FedSender services sent directly for 65 days
- Longlegs (Storm-2603), the developer of Warlock ransomware, still enters through on-premises SharePoint: a water utility, a telecom, a regional government body and a university hit in two months
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
12 notes · 6 last_successful_fetch · 3 added · 3 recipe · 2 status.
| Source | Change | From → To | Reason |
|---|---|---|---|
| bleepingcomputer | last_successful_fetch | 2026-10-02 → 2026-10-03 | fetched and used (cited in a published or updated entry this run) |
| fortinet-psirt | last_successful_fetch | 2026-10-02 → 2026-10-03 | fetched and used (cited in a published or updated entry this run) |
| cisco-psirt | last_successful_fetch | 2026-10-02 → 2026-10-03 | fetched and used (cited in a published or updated entry this run) |
| ncsc-ch-security-hub | last_successful_fetch | 2026-10-02 → 2026-10-03 | fetched and used (cited in a published or updated entry this run) |
| advisories-ncsc-nl | last_successful_fetch | 2026-10-02 → 2026-10-03 | fetched and used (cited in a published or updated entry this run) |
| symantec-security-com | last_successful_fetch | 2026-09-14 → 2026-10-03 | fetched and used (cited in a published or updated entry this run) |
| bleepingcomputer | notes | · → recipe note appended | S4 verified the direct feed works |
| fortinet-psirt | notes | · → recipe note appended | S1 verified a direct dated RSS recipe |
| enisa-euvd | notes | · → recipe note appended | S1 verified the EUVD search API sweep |
| yeswehack | notes | · → recipe note appended | S1 verified a working feed |
| censys-blog | notes | · → recipe note appended | S1 verified a working feed |
| bsi-de | notes | · → recipe note appended | S2 found the non-WID news listing recipe |
| news-admin-ch | notes | · → recipe note appended | S2 confirmed the recipe |
| ransom-isac | notes | · → recipe note appended | S4 verified a working feed |
| cloudflare-cf1 | notes | · → recipe note appended | S3 verified a working feed |
| elttam-blog | notes | · → recipe note appended | S3 verified the feed recipe |
| ssd-disclosure | notes | · → recipe note appended | S1 re-probed; unchanged |
| ransomware-live | notes | · → recipe note appended | S4 verified additional endpoints |
| it-connect | added | · → status: candidate | Added 2026-10-03: French-language security news with a working direct RSS (dated, 15 items) and fast in-language readings of ANSSI/CERT-FR documents; it carried the ANSSI innovation-lab and DINUM Metabase compromises from the REAC |
| mikrotik-routeros-changelog | added | · → status: candidate | Added 2026-10-03: first-party, plain-text and dated; NEWESTa7.stable / .long-term / .testing return '<version> <epoch>' and https://upgrade.mikrotik.com/routeros/<version>/CHANGELOG returns the release notes (verified 7.23.4 to 7. |
| parlament-ch-curia-vista-odata | added | · → status: candidate | Added 2026-10-03: the standing policy watch needs dated parliamentary status (motion adopted, referred, bill stages); the Curia Vista pages are a JS template no transport reads, but the OData service answers with status, status da |
| ibm-support-security-bulletins | status | candidate → active | promotion_due: cited by published entries from at least 3 distinct runs (state digest) |
| europol-newsroom | status | candidate → active | promotion_due: cited by published entries from at least 3 distinct runs (state digest) |
| mikrotik-routeros-changelog | recipe | · → health_cmd, content_scope | NEWESTa7.stable returns only '<version> <epoch>', so the health check reads the 7.24 CHANGELOG instead (verdict relevant: 13.7k characters, 'security'); release notes are legitimately mostly non-security (general-news scope). |
| news-admin-ch | recipe | · → health_cmd, content_scope | the bare /de/newnsb page carries no security vocabulary; the date-filtered listing recipe reads 12 dated federal items (verdict relevant, newest 2026-10-03); a general federal news listing is legitimately mostly non-security (general-news scope). Move start_date forward when the probe turns stale. |
| parlament-ch-curia-vista-odata | recipe | · → url, health_cmd, content_scope | the unfiltered OData entity set is too large to probe; the record URL now returns one business ($top=1) and the health check reads motion 24.4393 (verdict relevant: phishing, malware terms); parliamentary data is legitimately mostly non-security (general-news scope). |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| ssd-disclosure | https://ssd-disclosure.com/advisories/ | url --direct → webfetch → websearch | 202 captcha SiteGround captcha: HTTP 202 with an empty body on every direct GET; WebFetch returns an empty body; WebSearch site: queries return only old advisories | recorded as a coverage gap; recipe unchanged (blocked on every transport) |
| inside-it-ch | https://www.inside-it.ch/ (article pages) | bridge:feed → webfetch | 429 vercel-checkpoint article pages return the Vercel security checkpoint (HTTP 429) to extract, WebFetch and the reader; RSS teasers are readable | RSS teasers used as leads only; the lead (Swiss motion 24.4393) was traced to the parliament primary and then dropped |
Bridge invocations (this run)
10 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- extract ×8
- url ×1
- ncsc-csh ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 13 findings (truth=7, editorial=3, advisory=3) · Claude Sonnet 5.5 · 12m 35s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | The Fortinet page as read on 2026-10-03 (extract, raw url, WebFetch) has no file table: its IoC section lists two IPs, system event logs and encryption logs only; WebFetch: 'No table of added/modified | Fortinet attribution split: the cron, archive-account and IBE-log clauses stay cited to Fortinet; the file list is attributed to BleepingComputer (which says Fortinet published the table) and NCSC Switzerland, the body… | |
| F4 hallucinated-fact | · | 'Corrected' (also the record summary 'restated as written', the body's 'which is not Fortinet's wording', and the run-record note 'the earlier text had ... management interface where Fortinet's adviso | Reframed: the update and record summary now say Fortinet's advisory as read on 2026-10-03 words the workaround as the webmail interface and adds the WAF option, that press and NCSC Switzerland say management interface… | |
| F4 hallucinated-fact | · | Not a substring of the live Fortinet page, which reads 'Disable the IBE feature support via the GUI ( Encryption -> IBE -> IBE Service 'off' ) or with the following CLI command:' (extract, raw and the | evidence[1] replaced with the sentence now on the Fortinet page (quote checked verbatim against the saved body) | |
| F3 claim-not-supported | · | 2026-10-03 is the pipeline fetch date. The page's visible dateline is 'Updated: July 1, 2026' (<div id=documentInfo>) and its meta date is 'Tue Aug 04 22:51:17 PDT 2026'. Use the page's own date. The | Live Protect source dated by the page's own dateline (2026-07-01) in sources[] and inline | |
| F3 claim-not-supported | · | (low confidence) Symantec does not recommend replacing machine keys; the entry's own Exposure paragraph says 'Symantec does not address key replacement', and the same recommendation sits in actions[0] | Microsoft's ToolShell guidance (read, quote confirmed on the page) added as a source and cited for key rotation; Symantec no longer carries that advice (final wording set in iteration 2) | |
| F4 hallucinated-fact | · | (low confidence) Symantec installs the tunnel (code-insiders.exe tunnel service install, from the Windows debug folder) on 'Computer 4', one of the three 'further hosts' where SPSEPRDSetup was added t | Triage reworded to 'a host in a domain already showing SharePoint exploitation or an unexpected administrator account' | |
| F5 missing-citation | · | (low confidence) Both sentences carry no inline link; each is supported by Symantec (first activity July 22 via PowerShell WriteAllBytes into the layouts directory; a.exe on at least 40 hosts; 'The id | Symantec link added to the web-shell sentence and to the K7RKScan sentence | |
| F9 surface-contradiction | · | (low confidence) A source the entry cites for the IBE condition states fixes were released ('Betreft: Kwetsbaarheid verholpen in Fortinet FortiMail'; 'Fortinet heeft een kwetsbaarheid verholpen'), con | Contradiction added next to the NCSC-NL citation in the Exposure line: NCSC-NL says fixes were released, Fortinet's table lists them as upcoming, Fortinet's table is followed | |
| F2 generic-url | · | (low confidence) The whole-catalog KEV JSON feed (1,733 records) is cited for 'CISA added the CVE to its KEV catalog on 2026-10-01'; it is a listing, not a per-event page, and predates this run. A per | Source replaced by the per-event CISA alert page (https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog), cited inline | |
| F8 needs-more-research | · | (low confidence) The cited Live Protect page states the support rule that answers the question left open: 'Cisco creates Vulnerability Shields for the SD-WAN release that is current when the shield is | Shield support rule added from the Live Protect page (current release plus the two immediately preceding in each supported train that includes Live Protect; older releases may have no shield); the 'advisory does not… | |
| F11 editorial-advisory | · | The main body deliberately describes the artifacts without names; this section (and the verbatim NCSC-CH evidence quote) names attacker-added binaries `webconsole` and `mailservice`, which are file-na | File-name indicators removed from the Update section and the NCSC-CH evidence quote cut to a fragment without names; the narration sentence reduced to which text the reader should trust | |
| F11 editorial-advisory | · | The analysis was rewritten to the new state, so the changelog sections restate facts the reader has just read. Keep the delta only (Belnet: CCB engaged, 2026-09-29 link removal and disabled transfers, | Belnet Update section cut to the delta (CCB, 2026-09-29 link removal and disabled transfers, new transfers needed); the Cisco Update keeps the revision wording, side effect, modes and support rule; the FortiMail Update… | |
| F11 editorial-advisory | · | Symantec states the SPSEPRDSetup account name 'is likely an attempt at masquerading' ('SharePoint commonly provisions service accounts with names following an SPS/SP-prefixed setup'); T1036.010 (Masqu | T1036.010 added to techniques[] (setup-lookalike domain account, which Symantec calls likely masquerading); id checked active in the pinned dataset |
Iteration #2 NEEDS_FIXES · 8 findings (truth=4, editorial=1, advisory=3) · Claude Sonnet 5.5 · 10m 30s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Remediation #5 is incomplete. The takeaway still places key rotation inside a clause terminated by the Symantec link, and the Symantec report carries no rotate/replace/restart-IIS advice (it only says | Takeaway now cites Symantec only for the web shell and setup-lookalike accounts, and cites Microsoft's ToolShell guidance for rotating the machine keys and restarting IIS on all SharePoint servers; the action matches… | |
| F4 hallucinated-fact | · | (low confidence) 'then' places DLL sideloading and domain account/trust enumeration after the 2026-07-28 exploitation chain. Symantec dates both to 2026-07-24 ('Malicious activity resumed on July 24 w | 'then' changed to 'also' so the sideloading and enumeration sentence no longer implies an order after 2026-07-28 | |
| F3 claim-not-supported | · | (low confidence) The cited Belnet notice does not describe Belnet as a government and research network. The only cited page that does is Risky Bulletin ('a government-funded internet provider that cat | Risky Bulletin (the cited page that describes Belnet) added to the FortiMail sources and cited at the first mention of Belnet in the Update | |
| F14 quantifier-without-source | · | (low confidence) No cited source says the workarounds are the only control; Fortinet's page lists three workarounds and 'Virtual Patch: No', BleepingComputer says 'apply the shared workarounds until a | 'the only control' reworded to 'the available mitigation' in the summary | |
| F18 action-item-discipline | · | Fails check 10b(c): the task is not executable without re-reading the entry ('the compromise check described in the body'). Name the check in the action (audit serviceproxy-access.log for POSTs to the | actions[1] now names the checks: serviceproxy-access.log for POSTs to the login path with a percent-encoded character from unknown addresses, vmanage-server.log for login-path requests tied to viptela-reserved- user… | |
| F11 editorial-advisory | · | After the Update section was cut to the delta, the record summary states more than the section: the 2026-09-25 remediation (already in the main analysis), 'the FortiMail path traversal ... without nam | Belnet record summary cut to what the Update section states (supplier named, advisory linked, Centre for Cybersecurity Belgium assisting, transfers disabled on 2026-09-29, new transfers needed) | |
| F11 editorial-advisory | · | (low confidence) The cited page and BleepingComputer give only the path '/migadmin' (cron 'O=/migadmin ...') and 'migadmin.tar.gz'; 'migration' is the entry's expansion of the abbreviation and no sour | 'migration directory' and 'admin-migration archive' replaced by the sources' own strings: a cron command referencing the /migadmin path and a modified migadmin archive | |
| F11 editorial-advisory | · | Composition narration rather than a finding for the reader; the preceding sentence already states which wording the Fortinet page carries. Drop it (advisory). | closing narration sentence removed from the FortiMail Update |
Iteration #3 NEEDS_FIXES cap-breach · 4 findings (truth=2, editorial=0, advisory=2) · Claude Sonnet 5.5 · 10m 18s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | (low confidence) The BleepingComputer file table lists `/data/lib/liblog.so` Added and `/data/etc/ld.so.preload` Added as two separate rows and never says the library is registered through the preload | FortiMail BleepingComputer clause reworded to what the table shows: a library added under the data partition, an added ld.so.preload file, a modified system binary, two added binaries, a modified web server… | |
| F3 claim-not-supported | · | (low confidence) Cisco's page reads 'For help determining if Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco Technical Assistance Center (TAC). Cisco TAC c | Cisco Detection reworded to Cisco's wording: customers may open a Severity 3 TAC case with the CVE id in the title and are encouraged to run request admin-tech first | |
| F11 editorial-advisory | · | (low confidence, advisory) Microsoft's step reads 'After applying the latest security updates above or enabling AMSI, it is critical that customers rotate SharePoint server ASP.NET machine keys and re | Warlock takeaway and action now carry the sequencing from Microsoft's guidance (once patched, rotate the machine keys and restart IIS on all SharePoint servers) | |
| F11 editorial-advisory | · | (low confidence, advisory) 'now' asserts that Fortinet changed its wording, but the Update section only says the advisory 'as read on 2026-10-03' words it that way and the page's timeline lists only ' | 'now' dropped from the FortiMail record summary |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-10-03T0404Z-intel · Sonnet 5.5 · window 26 h · 1 entry published
Verification & coverage notes
Coverage window: standard fire. The previous intel fire started 2026-10-02T04:04Z, so gap_hours=24.0 and window_hours=26; the developing-story window was 72 hours. The container clock was cross-checked against an external date header (skew 0 s) and origin/main was fresh at preflight.
Mechanical KEV sweep: tools/kev_window_diff.py --window-hours 26 found two CISA KEV additions in the window, Zammad CVE-2026-102489 and CVE-2026-102490 (added 2026-10-02), both COVERED by the existing Zammad entry; no row was NOT COVERED, MENTION-ONLY or COVERED-STALE (work/2026-10-03T0404Z-intel/kev-window.txt). S1 confirmed catalog version 2026.10.02 and found every EUVD-exploited record already covered.
New entry (1): Longlegs (Storm-2603) and the Warlock ransomware, still entering through on-premises SharePoint (threat, high; Symantec's report of 2026-10-01 with same-day-plus-one relays by BleepingComputer, The Record and SecurityWeek; single assessor, so verification is single-source and credibility 2). It was surfaced by two domains independently (S3 and S4); the primary is a day older than the window start, and it passed the recency rule because the freshest sources are the in-window relays and nothing in the store covered it. Priority is high because on-premises SharePoint is the entry technology of two Swiss breaches already in the store and the machine-key theft means patching alone does not close the exposure. No CVE record is carried: Symantec names the ToolShell CVEs only as likely still in the arsenal.
Updates (3): FortiMail CVE-2026-104286 (update: Belnet's notice, which links this advisory, puts exploitation from 2026-07-22; NCSC Switzerland's note on the artifacts; the entry now follows Fortinet's advisory as read on 2026-10-03, which words the second workaround as the webmail interface and adds a WAF rule on POST /ibe, while BleepingComputer and NCSC Switzerland say management interface; the previous fire's verifier read Fortinet's page with the management-interface wording and a file table, and the page's timeline lists only the initial publication, so Fortinet appears to have revised it without a timeline entry; the file list is now attributed to BleepingComputer and NCSC Switzerland and the CISA citation points to the per-event alert); Belnet incident (update: supplier named as Fortinet, FG-IR-26-175 linked, Centre for Cybersecurity Belgium engaged, transfers disabled on 2026-09-29; priority raised from routine to notable because a vector class is now known; the first evidence quote no longer matched the page and was replaced); Cisco Catalyst SD-WAN Manager CVE-2026-76504 (update: advisory revision 1.1 adds a Live Protect shield, temporary and partial, with a login side effect and a support rule limited to the current and two preceding releases of trains that include Live Protect).
Contradictions: NCSC-NL (NCSC-2026-0398) says Fortinet released security updates for FortiMail while Fortinet's table lists 8.0.2, 7.6.7 and 7.4.9 as upcoming; the FortiMail entry follows Fortinet and states the contradiction. BleepingComputer and NCSC Switzerland say management interface for the second workaround where Fortinet's current page says webmail interface; the entry follows the Fortinet page and says so.
Backlog (7 open rows, all held, none changed): S1 re-gated IBM MQ CVE-2026-10747 with the three Langflow CVEs, MikroTik CVE-2026-84411 and IBM Guardium CVE-2026-85542; S4 re-gated Qilin/Touring Club Suisse, Everest/Securitas, SafePay/ARA-Region Lyss-Limpachtal and Payload/Netech. Every stated hold condition is unmet (no KEV listing, exploitation report or public PoC; no victim statement or press confirmation; ZATAZ analysed the Everest file tree but states origin and access are unconfirmed). No row text was appended, per the no-carry-forward rule. Nearest expiry is Qilin/TCS on 2026-10-05.
borderline-drop / out-of-window:
- borderline-drop: OrdaSoft OS CCK for Joomla CVE-2026-102427 (unauthenticated PHP upload, CVSS 4.0 10.0, fixed in 8.3.16 but the vendor updater still offers 8.3.14): not exploited, not in KEV, niche extension with no constituency deployment evidenced, single source (mySites.guru); below the PD-11(b) bar.
- out-of-window: tac_plus pre-auth format string (elttam, primary 2026-09-23, beyond the source's 168 h lookback, CVE pending, internal management plane, no exploitation); Huntress municipal recreation-platform web shell (2026-09-30, US platform, no CVE).
- borderline-drop: NeedyMantis (Microsoft, 2026-09-28), already dropped by the 2026-09-30 and 2026-10-02 fires; TA419 (Proofpoint, 2026-10-01: adversary-in-the-middle phishing of US/Japan policy and defense staff, technique not new, indirect relevance); Microsoft Digital Defense Report 2026 (vendor telemetry shares read from PDF chart text, no defender decision); DragonForce Lab52/Seqrite (2026-10-01: a second backdoor with an MQTT fallback resting on one lab's artifact-overlap attribution, on a legacy entry whose guidance already covers TURN egress and side-loading); Sysdig's Zammad hunts (same signals as the entry's Detection line).
- borderline-drop: CERT-FR/CERT Santé health-software report CERTFR-2026-CTI-007 (no vendor, no CVE, French health sector); Swiss motion 24.4393 on .ch/.swiss domain-holder identification (a mandate to draft law, the text finally referred is not stated); BSI's Classic McEliece notice (cryptographic-baseline advice, not a SOC decision); SRG/SRF employee data (2020 contact data, no vector); ATEXO/Region Hauts-de-France, Svedala kommun and the US municipal incidents (incident floor: no vector, no actor, no behavior beyond impact; no Swiss nexus).
- borderline-drop: OpenAI's count of over 100 notified organizations (scope statement, no decision for the constituency, five entries already carry the saga); VOISING/ApplyNow Metabase fallout (the Metabase link is Piyolog's inference, Japan); the ANSSI REACTIV lab/DINUM details (read by eye from an image-only PDF, no new decision); the ShinyHunters arrest statements (vanity figures, no defender action); the Censys exposure share for NetScaler (improvement-only).
- borderline-drop: WatchGuard AP CVE-2026-101891 and CVE-2026-86102 (9.3, no exploitation, access-point management network), Zimbra 10.1.21 CVEs CVE-2026-66911 and CVE-2026-66912 (reserved, no exploitation; the fix is already carried by the CVE-2026-73570 entry), Dell CSM, GitLab AI Gateway, Apache httpd 2.4.69 (Apache rates all 20 as low or moderate), Joomla core 5.4.9/6.1.4, Chrome 154, Exchange CVE-2026-96940, Palo Alto CVE-2026-0250: patch-cycle items with no exploitation.
Single-source / reduced confidence: the Warlock entry rests on Symantec alone (relays add nothing); the Belnet-to-FortiMail link is Belnet's own pointer to the advisory, and Belnet does not name the product, which the entry states.
Sources: 26 changes in sources_changed: last-success dates for the six sources cited, recipe notes verified by the sub-agents (BleepingComputer and Fortinet direct feeds, the EUVD search API, YesWeHack, Censys, BSI's news listing, news.admin.ch, ransom-isac, Cloudflare Cloudforce One, elttam, ransomware.live endpoints), three new candidates (it-connect, mikrotik-routeros-changelog, parlament-ch-curia-vista-odata) the two due promotions (ibm-support-security-bulletins, europol-newsroom) and the health recipes for the three records the health check flagged (news-admin-ch, mikrotik-routeros-changelog, parlament-ch-curia-vista-odata: each now carries a tested health_cmd and content_scope: general-news). ssd-disclosure stays blocked on every transport.
Tool findings for the next audit (not fixed here): fetch_source.py pdf on an image-only PDF (CERTFR-2026-CTI-006) exits 0 and prints binary noise instead of reporting that the file has no text objects (S4's workaround: download the file and read rendered pages); fetch_source.py extract on theregister.com returns navigation boilerplate instead of the article body; the rapid7-research feed returned HTTP 404 (S3). The S1 sub-agent spent 7 unintended reader-pool fall-throughs (extract and feed auto-fallback), no deliberate reader use.
Coverage gaps: ssd-disclosure (blocked on every transport); inside-it-ch (article pages HTTP 429, RSS teasers only); ncsc-ch-incidents (undated listing, no in-window addition can be dated); anssi-fr (CERT-FR timestamps are flat 00:00 UTC); europol-newsroom (SPA shell, not in a slice); rapid7-research (feed HTTP 404, not in a slice).
Verification: three iterations, none CLEAN. Iteration 1 (truth 7, editorial 3) found the Fortinet file-table attribution, a wrong 'corrected' framing, a stale evidence quote and attribution slips; iteration 2 (truth 4, editorial 1) found a partly fixed rotation attribution and wording slips; iteration 3 (truth 2, editorial 0, no F1 or F4) found two low-confidence wording points and two advisories, so the early-exit rule applied: all four were fixed after the iteration and the run published without a fourth pass. verification_residual_count is 2, the final iteration's truth plus editorial count, although both findings are remediated on disk. The first-iteration finding on the Fortinet page is worth the audit's attention: Fortinet changed the advisory text (management interface to webmail interface, a file table dropped) without a timeline entry, so a vendor revision can be invisible to a check that trusts the page's own revision history.
← Operations dashboard · run-record contract: docs/pipeline.md