2026-10-07T0404Z-intel
One pipeline fire, in full · intel run of 2026-10-07 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-10-07/2026-10-07T0404Z-intel.md.
Run telemetry
- Items returned
- 9
- Duration
- 31m 23s
- Tool calls
- 4 WebFetch9 WebSearch140 bridge
- Cited sources
- 3 of 29 in slice
- Items returned
- 6
- Duration
- 20m 02s
- Tool calls
- 8 WebFetch24 WebSearch85 bridge
- Cited sources
- 1 of 21 in slice
- Items returned
- 6
- Duration
- 18m 17s
- Tool calls
- 5 WebFetch18 WebSearch92 bridge
- Cited sources
- 3 of 16 in slice
- Items returned
- 9
- Duration
- 25m 24s
- Tool calls
- 3 WebFetch41 WebSearch110 bridge
- Cited sources
- 1 of 12 in slice
Verification
Deep dive
·
Entries this run published (3) and updated (6)
- Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution
- The FBI says the incident at its recruitment portal resulted from a contractor failing to apply an issued security patch on a third-party-managed platform; sources name PeopleSoft, and ShinyHunters claimed the breach
- CVE-2019-18935, Progress Telerik UI for ASP.NET AJAX: a patched-since-2020 deserialization RCE still exploited, now via an in-memory Godzilla web shell registered on ASP.NET's VirtualPathProvider
- CVE-2026-102489 / CVE-2026-102490, Zammad helpdesk: a session-hijack remote code execution and a zammad-to-root escalation, both reported exploited since 21 September, with no fix named for the root flaw
- CVE-2026-21589, Atlassian Data Center: unauthenticated arbitrary file access in every version of eight self-managed products, patch or take them off the internet (CVSS 4.0 9.3)
- Denmark's CPR population register: unauthorised parties abused one private company's lawful lookup access for about ten days and obtained names, addresses and CPR numbers of 8.8 million people
- CVE-2026-94504 / CVE-2026-93836, Ninja Forms and WPC Product Bundles for WooCommerce: stored XSS exploited to plant a hidden WordPress administrator and four persistence routes that survive the update
- A Gentlemen ransomware affiliate ran his own leak site and reached his victims through stolen CI/CD secrets, with attack commands driven through an MCP server (CloudSEK)
- CL-STA-1178 (Blinder Tunnel): an Iranian-nexus recruitment lure delivers a Visual Studio project that runs code when it is opened, then hijacks the .NET AppDomainManager, disables ETW and takes tasking from GitHub
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
13 notes · 6 last_successful_fetch · 3 added · 1 status.
| Source | Change | From → To | Reason |
|---|---|---|---|
| unit42 | last_successful_fetch | 2026-10-02 → 2026-10-07 | fetched and used (primary of a new entry) |
| watchtowr | last_successful_fetch | 2026-09-30 → 2026-10-07 | fetched and used (cited in an entry updated this run) |
| bleepingcomputer | last_successful_fetch | 2026-10-03 → 2026-10-07 | fetched and used (cited in a new entry) |
| securityweek | last_successful_fetch | 2026-09-30 → 2026-10-07 | fetched and used (cited in an entry updated this run) |
| inside-it-ch | last_successful_fetch | 2026-09-26 → 2026-10-07 | fetched and used (cited in an entry updated this run) |
| cisa-kev | last_successful_fetch | 2026-10-06 → 2026-10-07 | fetched and used (cited in an entry updated this run) |
| theregister-security-feed | status | candidate → active | promotion_due: cited by published entries from 27 distinct runs |
| patchstack | added | · → status: candidate | Added 2026-10-07: first-party exploitation telemetry for WordPress plugin flaws; its analysis is the primary of a new entry and the feed reads directly |
| cloudsek-triad | added | · → status: candidate | Added 2026-10-07: adversary-intelligence lab that reads exposed attacker infrastructure first-hand; its Gentlemen affiliate report is the primary of a new entry and the feed is verified working |
| nextgov-fcw | added | · → status: candidate | Added 2026-10-07: original US public-sector breach reporting that carries agency statements given to it directly (the FBI cyber chief on the fbijobs.gov breach) |
| ransomware-live | notes | · → recipe note appended | S4 found the API endpoints read with url --direct |
| piyolog | notes | · → recipe note appended | S4 found the homepage lists entries and extract reads each |
| vulncheck | notes | · → recipe note appended | S1 found WebFetch of /blog works while extract returns a stale 2022 snapshot |
| flatt-security | notes | · → recipe note appended | S1 found the feed undated |
| sentinellabs | notes | · → recipe note appended | S3 found a WebFetch recipe that returns dated posts with hrefs |
| ahnlab-asec | notes | · → recipe note appended | S3 found per-post extract works |
| cloudflare-cf1 | notes | · → recipe note appended | S3 found threat reports live outside the blog feed |
| cyberattaque-org | notes | · → recipe note appended | S2 found the feed falls back to the reader and is undated |
| ssd-disclosure | notes | · → recipe note appended | S1 found the CAPTCHA wall again, contradicting the 2026-10-06 note |
| sekoia | notes | · → recipe note appended | S2 found a WebFetch listing gives dated posts |
| cisa-news | notes | · → recipe note appended | S2 found a WebFetch listing gives dated items |
| parlament-ch-curia-vista-odata | notes | · → recipe note appended | S2 found the OData endpoint works and the geschaeft pages are client-rendered |
| inside-it-ch | notes | · → recipe note appended | S2 found article pages read without the 429 again |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| reuters-fbi-contractor-report | https://www.reuters.com/technology/accenture-contractor-removed-fbi-following-da | extract → bridge:url → webfetch | 403 captcha Reuters article pages return a CAPTCHA stub or a JS shell on every transport (S1, S2, S3, S4); the report was cited through Nextgov/FCW and SecurityWeek, which relay it | Reuters-derived claims are attributed to Reuters as relayed and carry no Reuters link; the FBI statement is read from Nextgov/FCW |
| cert-ua-lunex-clickfix | https://cert.gov.ua/ | extract → webfetch | 200 js-shell CERT-UA primary is an Angular SPA that returned an empty shell to extract and WebFetch (S3) | item dropped; a structured CERT-UA recipe is needed before it can be a source |
| fsc-go-kr-notice | https://www.fsc.go.kr/ | extract → bridge:url → bridge:jina | 0 all-transports-failed connection reset on every direct transport and the reader pool was dead (S4); the South Korean bank-breach item was dropped on other grounds | not needed for a published record |
| liechtenstein-landtag-answer | https://www.landtag.li/ | extract → websearch | 404 dead-path the Head of Government answer to the Landtag question (2026-10-06) could not be located on llv.li, volksblatt.li or the Landtag site (S2, S4) | the status delta is cited to Inside IT's report of the answer |
| ssd-disclosure-listing | https://ssd-disclosure.com/advisories/ | extract → bridge:url → webfetch | 202 captcha the listing and advisory pages answered a CAPTCHA on every transport and WebFetch returned an empty body (S1); only undated homepage titles read | noted on the source record; no item depended on it |
Bridge invocations (this run)
13 bridge calls this run · these are successful bridge fetches (separate from "Coverage gaps" above).
- extract ×9
- url ×2
- cisa-kev ×1
- url --direct ×1
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 24 findings (truth=17, editorial=3, advisory=4) · Claude Sonnet 5.5 · 18m 36s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Crowd ticket CWD-6610 lists 7.1.7 as fixed; 7.1.6 is only an affected version. | · | |
| F3 claim-not-supported | · | SaaS clause cited to the advisory records, which do not carry it. | · | |
| F3 claim-not-supported | · | Release page names no affected versions. | · | |
| F4 hallucinated-fact | · | (low confidence) 'no fix exists yet' goes beyond the sources. | · | |
| F4 hallucinated-fact | · | (low confidence) 'needs public sign-up enabled' is in no cited source. | · | |
| F4 hallucinated-fact | · | Present-tense unavailability overtaken by the reopening. | · | |
| F4 hallucinated-fact | · | (low confidence) unsourced 'no per-account rate limit ... no alert'. | · | |
| F4 hallucinated-fact | · | (low confidence) present-tense statement overtaken by the new Update. | · | |
| F13 analytical-link-as-fact | · | (low confidence) the Jordan detainee equated with Krebs's Rey without a source. | · | |
| F3 claim-not-supported | · | (low confidence) watchTowr verified crowd.properties on Jira only. | · | |
| F4 hallucinated-fact | · | (low confidence) discriminator not supported by the cited mechanism. | · | |
| F13 analytical-link-as-fact | · | (low confidence) single-actor reading is BleepingComputer's inference. | · | |
| F3 claim-not-supported | · | (low confidence) paraphrase looser than the source. | · | |
| F4 hallucinated-fact | · | (low confidence) 'a decrypted configuration key' inverts CloudSEK. | · | |
| F14 quantifier-without-source | · | (low confidence) first-use claim stronger than the source. | · | |
| F13 analytical-link-as-fact | · | (low confidence) 'the flag means a possible staging point' was the entry's inference. | · | |
| F2 generic-url | · | (low confidence) raw JSON listing cited. | · | |
| F5 missing-citation | · | (low confidence) takeaway fact without a citation. | · | |
| F18 action-item-discipline | · | (low confidence) action restates the Detection line. | · | |
| F18 action-item-discipline | · | (low confidence) stale action wording. | · | |
| F11 editorial-advisory | · | Reader-facing provenance narrates fetch outcomes. | · | |
| F11 editorial-advisory | · | Main analysis repeats a fact from the new section. | · | |
| F11 editorial-advisory | · | The Gentlemen group is not keyed in entities. | · | |
| F11 editorial-advisory | · | (low confidence) record type improvement versus update. | · |
Iteration #2 NEEDS_FIXES · 11 findings (truth=6, editorial=1, advisory=4) · Claude Sonnet 5.5 · 20m 59s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F13 analytical-link-as-fact | · | (low confidence) anonymous sources named a platform and a contractor, not a CVE. | · | |
| F3 claim-not-supported | · | (low confidence) SecurityWeek never names Reuters for the Jordan detention. | · | |
| F4 hallucinated-fact | · | (low confidence) 'an empty decoy' is wrong for the dropper file. | · | |
| F14 quantifier-without-source | · | (low confidence) CloudSEK's hedge turned into an absolute. | · | |
| F4 hallucinated-fact | · | (low confidence) 'single-record' overstated the government's wording. | · | |
| F4 hallucinated-fact | · | (low confidence) mitigation text referred to a sourcing-note sentence that was removed. | · | |
| F16 priority-miscalibration | · | (low confidence) high for a 68-day-old incident whose newest news is a closure status. | · | |
| F11 editorial-advisory | · | Record-keeping narration. | · | |
| F11 editorial-advisory | · | Keyed entities never named in the text. | · | |
| F11 editorial-advisory | · | (low confidence) earlier-voice wording and German originals in the body. | · | |
| F11 editorial-advisory | · | SaaS sentence not scoped to the 7.2.1 fixes. | · |
Iteration #3 NEEDS_FIXES · 6 findings (truth=2, editorial=3, advisory=1) · Claude Sonnet 5.5 · 16m 36s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | (low confidence) scope claim cited to a CVE record that gives a narrower range. | · | |
| F3 claim-not-supported | · | (low confidence) no successful crack is stated. | · | |
| F5 missing-citation | · | (low confidence) dated facts without an inline citation. | · | |
| F9 surface-contradiction | · | (low confidence) text and chart disagree. | · | |
| F10 missed-angle | · | (low confidence) the FBI's on-record arrests statement was missing. | · | |
| F11 editorial-advisory | · | Entry metadata narrated to the reader. | · |
Iteration #4 NEEDS_FIXES · 5 findings (truth=3, editorial=1, advisory=1) · Claude Sonnet 5.5 · 20m 53s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | (low confidence) ASEC dates neither case nor calls them unrelated. | · | |
| F4 hallucinated-fact | · | (low confidence) uncited 'signature' claim. | · | |
| F4 hallucinated-fact | · | (low confidence) 'every victim' contradicts the entry's own body. | · | |
| F18 action-item-discipline | · | (low confidence) an action to start now contradicts the Improvement's closing statement. | · | |
| F11 editorial-advisory | · | Run-on sentence with a citation gap. | · |
Iteration #5 NEEDS_FIXES · 5 findings (truth=4, editorial=0, advisory=1) · Claude Sonnet 5.5 · 18m 11s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | (low confidence) the cited release gives no day for the shutdown. | · | |
| F4 hallucinated-fact | · | (low confidence) the sentence overreached Inside IT and contradicted the unretracted takeaway. | · | |
| F3 claim-not-supported | · | (low confidence) NZZ does not attribute the mechanism to Schmid. | · | |
| F4 hallucinated-fact | · | Run-record notes said the Telerik record is an improvement. | · | |
| F11 editorial-advisory | · | (low confidence) the section narrated an edit and named fields. | · |
Iteration #6 CLEAN · 2 findings (truth=0, editorial=0, advisory=2) · Claude Sonnet 5.5 · 18m 34s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | · | (low confidence) an earlier record summary still attributes the mechanism to Schmid. | · | |
| F11 editorial-advisory | · | (low confidence) record summary narrated the edit. | · |
Iteration #7 CLEAN · 5 findings (truth=0, editorial=0, advisory=5) · Claude Sonnet 5.5 · 16m 26s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F11 editorial-advisory | · | (low confidence) 'self-hosted' and 'unmasked or unprotected' are inferred from the mitigations. | · | |
| F11 editorial-advisory | · | (low confidence) the 22 TB vault figure is not mentioned. | · | |
| F11 editorial-advisory | · | (low confidence) actor:thegentlemen not in entities. | · | |
| F11 editorial-advisory | · | (low confidence) the earlier record summary attributes the mechanism to Schmid. | · | |
| F11 editorial-advisory | · | (low confidence) KEV ransomware flag not stated. | · |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-10-07T0404Z-intel · Sonnet 5.5 · window 26 h · 3 entries published
Verification & coverage notes
- Window: 26 h (gap 24.0 h to
2026-10-06T0405Z-intel). A quiet, update-heavy window: three new entries and six changelog records. - KEV sweep: catalog 2026.10.04 carries no addition inside the window (the last, Citrix CVE-2026-88779, is covered). The ransomware-flag cross-check found one 14-day covered CVE with the flag Known and a silent entry, CVE-2019-18935, which ships on the Telerik entry inside a
correctionrecord (the catalog does not date the flag, so it is not anupdate; the same record fixes the entry's 'unrelated' and '2026' wording, which AhnLab's article does not support). For the audit: S1 lists thirteen older entries that carry a KEV-Known CVE without mentioning ransomware (CVE-2026-63077 in2026-09-06/jetbrains-cadence-teamcity-cve-2026-63077-breach, CVE-2026-45659 in the 2026-07-14 Patch Tuesday entry, CVE-2026-12569 in the 2026-08-22 PTC Windchill entry, CVE-2026-35273 in the 2026-06-28 NAIC PeopleSoft entry, CVE-2026-41940 in the 2026-05-10 cPanel entry, CVE-2025-8088 in three 2026-06 entries, CVE-2022-26134 and CVE-2022-29464 in the 2026-08-16 evooo1bot entry, CVE-2020-0688 and CVE-2019-0708 in the 2026-09-21 NightEagle entry, and a second entry file for CVE-2026-0257). - Backlog (
state/coverage_backlog.md, six open rows, all re-gated on today's facts and all held, none struck, none published): IBM MQ CVE-2026-10747 and the Langflow CVEs (condition unmet; new Langflow CVEs and IBM bulletins noted on the row; expiry 2026-10-11 stands); MikroTik CVE-2026-84411 (no revision of CISA's advisory and MikroTik still names no fixed build; expiry 2026-10-14); IBM Guardium CVE-2026-85542 (not in KEV; IBM's bulletin of 2026-09-17 also carries an unauthenticated CVSS 9.8 flaw in the same product, noted on the row; expiry 2026-10-14); SafePay on ARA-Region Lyss-Limpachtal and Payload on Netech (no victim statement or press report found by S4; expiry 2026-10-14); Beyond Gravity (S2 and S4: still no vector, actor or data named, and neither BACS nor Mandiant has published; expiry 2026-10-20). - Updates: Atlassian CVE-2026-21589 (
update: watchTowr root cause, checker and Crowd chain), Denmark CPR register (update: Datatilsynet's automated-lookups description and the 2026-10-06 press briefing), Zammad (update: 7.2.1 with 27 advisories replaces 7.2.0 as the target; read from the repository's advisory records through the GitHub API), FBI/ShinyHunters (update: the FBI cyber chief's statement of a contractor's missed patch), Liechtenstein VwbP (improvement: the government's 2026-08-19 root-cause statement and the 2026-10-05 reopening), Telerik CVE-2019-18935 (correction: the 'unrelated' and '2026' wording removed, plus the KEV listing and ransomware flag). - New entries: the WordPress stored-XSS hidden-administrator campaign (Ninja Forms, WPC Product Bundles; exploited,
high), CL-STA-1178 Blinder Tunnel (Unit 42; PD-11 (d) technique value,notable), and the Gentlemen affiliate Azazel (CloudSEK; CI/CD secrets and MCP,notable). - Single-source: the three new entries rest on one vendor each (Patchstack, Unit 42, CloudSEK); BleepingComputer restates Patchstack and adds nothing. The FBI update's product and contractor names come from anonymous sources relayed by Nextgov/FCW and SecurityWeek (Reuters not readable).
- Contradiction: BleepingComputer says the two WordPress plugin flaws need an authenticated session; Patchstack and the CNA records describe an unauthenticated attacker and an administrator's session being ridden, and the entry follows Patchstack.
- borderline-drop: Wikimedia statement on OpenAI-operated agents (2026-10-05), no compromise found, same blind-proxy lesson already in the UNCTAD entry updated on 2026-10-02.
- borderline-drop: LibreOffice CVE-2026-63277 and Apache OpenOffice CVE-2026-59265 (public proof of concept, 2026-10-05), needs Java enabled and a user opening a document, no exploitation reported, fixed in LibreOffice by the normal update, no constituency estate shown; re-gate if exploitation appears or OpenOffice 4.1.17 slips.
- borderline-drop: Hitachi Energy RTU500 CVE-2026-8065 / 8066 (end-of-life firmware, CVSS 9.1, SSVC exploitation none), ASUSTOR ADM CVE-2026-105324 (single EUVD record, no fix stated),
@subql/commonnpm compromise (50-minute window, Web3 package), Harbor webhook SSRF (CVSS 6.4, no CVE, no exploitation), Chrome's response to the .gh/.sl/.as registry hijacks (no Swiss nexus; generic CT-monitoring and CAA advice), Microsoft Digital Defense Report 2026 Swiss readings (primary published 2026-10-01; country rankings are context, not a decision, and four earlier fires dropped it), motion 24.4393 on .ch domain abuse (no obligation changes), the communal e-mail authentication paper (DMARC enforcement is generic hardening), ASOS push-notification extortion (no nexus, no vector), Qilin developer extradition (no defender decision), Osaka Metropolitan University ransomware (no actor or vector), South Korean bank breaches and ARTEX (thin freshness, out of region), ShinyHunters member detained in Jordan (single Reuters relay; folded into the FBI update only as context), Stadt Wien AI-scanner suspicion (2026-09-30, a suspicion; left to the audit as a possibleimprovement), WordPress 7.1.3, Microsoft Exchange CVE-2026-96940, Outlook CVE-2026-100208, HPE iLO 7 CVE-2026-79820, Rejetto HFS CVE-2026-61500 (probing only), Dell System Update CVE-2026-86360, OpenSSL 2026-09-29. - For the audit: GitLab CE/EE CVE-2026-89078 and CVE-2026-93577 (CVSS 9.9, fixed in 19.0.9 on 2026-09-23, exploitation "no information") and HPE Aruba Instant On CVE-2026-76723/76724/76725 sit outside every window and were never assessed. Cisco's PSIRT bundle announced for 2026-10-07 (APIC, Finesse, License On-Prem, Meraki, NX-OS hardening releases) was not yet published at 04:30 UTC; the next fire reads it.
- Source-tooling notes from S1:
fetch_source.py urlsilently falls back to the metered reader on non-HTML replies, so a JSON or plain-text endpoint needs--direct; the GitHub repository advisory records (api.github.com/repos/<org>/<repo>/security-advisories) read directly and are the better recipe for projects that publish GHSA advisories. S2 fetched one guessed URL (beyondgravity.com/en/press) through the reader and it returned 404; one reader fetch spent. - For the next fire and the audit: NCSC-CH published an advisory for SonicWall SMA1000 CVE-2026-102255 at 2026-10-07T05:47Z, after this run's research (the vendor reports no exploitation); the KEV catalog marks CVE-2026-35273 as used in ransomware campaigns and the ShinyHunters/FBI entry does not say so; CloudSEK's Gentlemen report describes a 22 TB long-term vault, and its text and chart disagree on the victim count (the entry carries the contradiction in its sourcing note); the 2026-09-01 Liechtenstein record summary still attributes the access mechanism to the head of the Office for IT, which NZZ does not support (the body and sourcing note are corrected, the record is append-only).
- Coverage gaps: ssd-disclosure (CAPTCHA on every transport), Reuters article pages (CAPTCHA or JS shell), CERT-UA (Angular SPA, no structured recipe), fsc.go.kr (connection reset), the Liechtenstein Landtag answer text (not found).
- Essential-coverage: all 21 essential sources attempted.
← Operations dashboard · run-record contract: docs/pipeline.md