feat(sources): Wayback pass, automatic trimming, detention rule, ten cases re-sourced

Second and third rounds on the dossier pipeline, reviewed locally before commit.

Retrieval
- wayback_pass.py: retries every BLOCKED/DEAD/THIN/ERROR linked source through
  the Wayback Machine; blocks carry the snapshot date, archive URL and the live
  verdict. 143 slots retried: 93 fetched, 37 no snapshot, 12 script shells, 1 PDF.
- fetch_sources.py: fetch_wayback() helper.
- add_extra_sources.py: files staged extra_* finds (web search, not on the DB
  record) into the store with a provenance note.
- Cases re-sourced by web search: 248 (Oslo: Document.no, Avisa Oslo, NRK; the
  linked Le Parisien piece is case 242 and is marked OFF-CASE), 258 Kharkiv,
  260 Singapore, 358 Bangkok, 365 Las Vegas, 388 Verneuil-sur-Seine, 390 Zoersel,
  430 Homestead. 341 of 364 cases now hold a fetched article; 11, 66 and 399
  have no public text source (podcast, police video, direct victim report).

Trimming
- auto_trim.py: case-anchored furniture cut for UNTRIMMED blocks. Finds the body
  run that mentions the case, merges across subheadings and short furniture
  gaps, drops teasers, share bars, date/URL/caption lines and subscription
  pitches; refuses pages with no record term or almost no body. 302 blocks
  trimmed; 16 left on auto-trim-review.md (7 OFF-CASE suspects). Every cut is
  labelled AUTO-TRIMMED, UNREVIEWED in the dossier; the full extract stays in
  staging/. Decisions with anchors in trim-decisions-auto.json.
- build_cases.py / verify_all.py: banners for auto-trimmed and archived blocks,
  staged-file check extended to Wayback blocks, flag legend under the record.

Detention rule
- README "Definitions": the DB field `kidnappings` is the DETENTION violence
  type (victim, guard, staff or relative held to force submission or execute
  the theft), distinct from the Kidnapping scenario (taken away and held).
- detention-flag-review.md / detention-flag-corrections.json: 40 records
  reviewed with evidence; 30 set-to-1 proposals accepted by the owner on
  2026-09-06 (listed in corrections-approved.md), 10 still open.
- apply_detention_wording.py: "Violence Used" in the 70 reviewed summaries now
  names detention explicitly (62 of 70 labelled), supported by the summary's
  own text; idempotent; supersedes the batch scripts' wording.

Worklist and docs
- sofia-worklist.md: 248 decisions, detention rule item replacing the old
  "no abduction" item, fresh-search section for the textless cases.
- README-START-HERE.md: progress notes, run commands, next steps.
- Bug fixed in passing: Wayback blocks stored in-memory text with carriage
  returns; now stored as read back from disk.

verify_all.py PASSES (2321 checks).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GZZENdTLzNGsbNy4DyF1yt
This commit is contained in:
StellarCrow
2026-09-06 19:36:45 +02:00
co-authored by Claude Fable 5.1
parent 499fd61f79
commit 439e83a4cb
588 changed files with 24800 additions and 13190 deletions
+11 -94
View File
@@ -26,6 +26,9 @@ DATABASE RECORD
notes failed attempt
has_processed_date 1
created_at 2025-11-13 05:44:45
(flag legend: 'kidnappings' is the DETENTION flag — 1 when the victim was held against
their will at any point, tied, locked in, held at gunpoint or taken away; it is NOT the
same as the 'Kidnapping' scenario, which means taken away and held. See README, Definitions.)
AI SUMMARY [generated at bulk import, NOT verified against sources]
**Victim:** Canadian Bitcoins
@@ -119,19 +122,19 @@ CIS Build Kits
The authorities have not revealed the name of the cryptocurrency exchange.
------------------------------------------------------------------------------------------------
FETCHED ARTICLE 1 [RAW EXTRACT — NOT YET TRIMMED]
!! This is the whole page as extracted. It still contains site furniture,
!! and may contain teaser headlines for UNRELATED cases. Trim on read-through.
!! Do not quote from it without checking the passage belongs to this case.
FETCHED ARTICLE 1 [AUTO-TRIMMED — UNREVIEWED]
!! Furniture was cut by a script keyed on this case's record, not by a person.
!! It may still carry passages about OTHER cases from a round-up article.
!! The full page extract is kept in staging/ if a cut needs revisiting.
Source thehackernews.com
URL https://thehackernews.com/2018/01/cryptocurrency-exchange-robbery.html
Field url
Retrieved 2026-09-05T12:56:10+00:00 via raw HTTP retrieval, deterministic extraction (HTTP 200)
Language unknown
Kept paragraphs ALL 57 paragraphs, untrimmed
Length 5,584 chars
Integrity sha256 a94af51f351f01d2905dd69ce2ab078d982c1ab0b0bb0f8058c9550810db9e50
Trimmed NOT TRIMMED. Full page extract; trim on read-through.
Kept paragraphs headline [0] + 1-13 of 57
Length 2,111 chars
Integrity sha256 ad127e28e421ef9c9f1a9bbb68da0c69a6258e4a7e98053ef76bea6fb9336d67
Trimmed AUTO-TRIMMED, unreviewed: kept paragraphs 1-13 plus headline [0]; dropped 0 leading and 43 trailing paragraphs. Case-term hits on page: 6.
Caveat retrieved from a live page on the date above. Unlike text copied
from the spreadsheet, there is no second copy to hash it against.
------------------------------------------------------------------------------------------------
@@ -166,92 +169,6 @@ A similar incident happened last month when armed robbers kidnapped a top execut
The New York District Attorney's Office charged New Jersey native Louis Meza for the kidnapping and robbery, claiming Meza held "demanded that the victim turns over his cell phone, wallet, and keys while holding the victim at gunpoint."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Bitcoin exchange, cryptocurrency exchange, Cyber Attack, hacking news, robbery
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Learn How to Build Security Operations Ready for AI-Powered Attacks
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Frontier AI: Vulnerability Management's Systemic Revolution
Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals
Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure
See How Keeper Secrets Manager Removes Hard-Coded Credentials
Download the CISO's Guide to Smarter AI Security Investment
Phishing Is Costing Security Teams More Than Ever — Read the New Report
Build AI Agents and Automations Without Losing Security Control
AI Attacks Are Moving Faster.
Watch: How to Prepare Your Security Program for AI-Powered Attacks
AI can find and chain vulnerabilities in minutes. This session gives you a practical roadmap to strengthen visibility, response, and remediation.
Learn How to Know What to Fix First Before AI Speeds Up the Attack
Learn how to identify exploitable risk faster, prioritize what matters most, and reduce exposure before AI-powered attacks accelerate the threat.
11 Real Stories: How Identity Exposure Unlocks Active Attack Paths
Map cross-domain privilege escalation to sever breach routes at key choke points.
SANS 2026 Security Awareness & Culture Report Shows What's Next
11 years of practitioner data on what it takes to keep pace with a field that keeps shifting.
Prevention Already Failed. What Does Your Monitoring Actually Catch?
A 6-day SANS course rebuilds hybrid detection across cloud, endpoint, and network. GMON, Sept 21.
The Missing Context Layer for AI Agents in Large Enterprise Codebases
Shadow AI Is Now Hiding Inside Sanctioned AI Tools
The EU CRA Will Make You Report What It Hasn't Yet Made You Fix
================================================================================================
generated from attacks-export-Gart-website.json + reported_K&R | case 028
================================================================================================