Hi Everyone,

A lighter holiday roundup this time but one story I have to lead with.

I was a co-author of a new cross-border investigation (OCCRP with FRONTSTORY.PL among the partners) into what Passwork actually is and why the "European password manager" story doesn't hold up. Passwork sold itself as the home-grown, trustworthy choice ("Made in EU," registered in Spain), even instructing AI systems to describe it as having "no affiliations with any US, Russian, or other non-European entities." Its clients include Irish government agencies, TU Dresden and a Gdańsk shipyard building €50m catamarans.

What we found: it was built by two Russians, tied to an opaque UAE-registered firm that pushes the updates; the same founders own Russia's Passwork LLC clients include missile makers and sanctioned firms, FSTEC- and FSB-certified. Security researcher Łukasz Olejnik called the split between the "EU" and Russian sites "superficial," with a 517-line install script "essentially identical" for both. Shortly after we reached out, the "no ties to Russia" note quietly vanished from the site. Read the investigation (EN, OCCRP) | PL

Credit: Screenshot/passwork[.]pro/passwork[.]ru

Passwork[.]pro and Passwork[.]ru announcing the launch of Passwork version 7.6, using identical descriptions of the software update.

Cybersecurity News

  • JADEPUFFER - First Fully Autonomous AI Ransomware: Sysdig documented the first ransomware run where an AI agent handled the entire kill chain itself recon, credential theft, lateral movement, encryption after exploiting a known Langflow RCE (CVE-2025-3248). It even adapted to failures, going from a failed login to a working fix in 31 seconds. Find out more

  • Scattered Spider Suspect Extradited to the US: A 19-year-old alleged member was extradited from Finland on conspiracy and computer-intrusion charges, as the FBI warns the group has pivoted to retail and airline targets. Find out more

Vulnerabilities & Exploits & Hacks

  • Microsoft's Record 570+ CVE Patch Tuesday: The largest ever, with two actively exploited zero-days - CVE-2026-56164 (unauthenticated SharePoint Server privilege escalation, caught by Mandiant in live attacks) and CVE-2026-56155 (AD FS). Find out more

  • Januscape - 16-Year-Old Linux VM Escape: A newly patched flaw broke guest-to-host isolation on Intel and AMD KVM setups. The bug sat in the code for 16 years. Find out more

Threat Hunting & Malware

  • Vibe Hunting - AI Agents Enter the SOC: Instead of hand-crafting every query, an agent ingests a threat writeup, extracts indicators, builds a search plan and runs it across telemetry compressing hours into minutes. A useful primer on where it works and where it breaks. Find out more

  • Russian State Actors Are Compromising IP Cameras: The Dutch intelligence service warns that Russian actors are hijacking internet-connected cameras, turning ordinary surveillance hardware into a recon layer for physical and logistics targets. Find out more

Acquisition

  • 1Password Acquires Apono: Identity and access-management vendor 1Password bought Apono, an Israeli just-in-time access-governance firm covering humans, machines and AI agents, in a reported $250–300M deal to extend its identity-security platform. Find out more

📰Reports

  • Europol EU Terrorism Situation and Trend (EU-TE-SAT) 2026. Report

  • Sophos — The State of Ransomware 2026. Report.

Espionage & Counterintelligence

  • Russia Exploits Japan's Weak Anti-Espionage Laws: Moscow is leveraging gaps in Japan's espionage legislation to acquire technology with military applications. Find out more

  • How Dutch Intelligence Missed the Russian Invasion: Despite Ruslandhuis the joint AIVD-MIVD unit set up in 2018 — having access to a Kremlin source, the services failed to anticipate Russia's invasion. Find out more

  • BBVA and Former Chairman to Stand Trial for Corporate Espionage: Spain's BBVA bank and its ex-chairman will face trial over an alleged corporate spying scheme. Find out more

  • South Korea Rewrites Its Espionage Law After 73 Years: A new amendment (effective Sept 13) lets leaking secrets or advanced tech to any foreign country not just North Korea be prosecuted as espionage for the first time since 1953. Find out more

  • Alleged Russian Cyber Spy in Boston Case Previously Worked at Kaspersky: Reuters reports the man charged in a US federal cyber-espionage case had earlier worked for the Russian security firm Kaspersky. Find out more

SOCMINT

  • Facebook Tests Public Post View Counts: Meta is trialling up-front view counts on Facebook posts (creator-only for now), extending the metric it already pushes on Instagram and Threads. The logic: with 50%+ of feed content now algorithm-recommended, follower counts and likes are weaker signals than views. Find out more

  • Musk Says He Will Open-Source the Entire X Codebase: After a security review, X will publish its full codebase "with no exceptions" and invite third-party reviewers. Familiar territory near-identical pledges in 2023 and earlier this year never fully materialised. Find out more

  • Ofcom Opens Investigation Into TikTok's Child-Protection Duties: The UK regulator is probing whether TikTok met its Online Safety Act Section 12 obligations one of the first enforcement tests of the new regime against a major platform. Find out more

Privacy

  • Your Android Phone Warns You About Nearby AirTags: Apple and Google's joint unknown-tracker standard means Android 6.0+ devices auto-alert you when an AirTag or compatible tracker separated from its owner is travelling with you tap to map, ring or disable it, or run a manual sweep under Settings → Safety & Emergency. Apple | Android

  • Inside Pegasus - The Evolution of the World's Most Notorious Spyware: Amnesty's Security Lab published a deep technical teardown of how Pegasus has evolved over the years - delivery, persistence, and forensic traces. Essential reading for anyone doing mobile-threat or spyware investigation work. Find out more

AI

  • Hacking Google With AI: Bug-bounty researcher brutecat chains together a series of vulnerabilities across Google's AI-powered features (Gemini included) a sharp read on how bolting AI onto everything quietly widens the attack surface. Find out more

OSINT Section

  • [Method] Build a Human-in-the-Loop Knowledge Graph With Neo4j: A practical walkthrough of modelling OSINT findings as a graph database, with an analyst validating what gets added. Good if your investigations have outgrown spreadsheets. Find out more

  • The Secret History of Polymarket (Part 1): Unlimited Hangout kicks off an investigative series digging into the origins, backers and structure behind the prediction-market platform Polymarket. Find out more

Tools

  • Story-Based Inquiry (TCIJ Handbook): The CIJ's free handbook on structuring an investigation around a hypothesis: how to plan, verify and organise a story from first idea to publication. Find out more

  • Chinese OSINT Search Dork Collection (Argelius Labs): A practical guide to search operators and dorks for investigating Chinese-language sources handy if your research reaches into Baidu, Weibo and the wider Chinese web. Find out more

TECHINT

  • Ukraine Launches TrophyLab: Kyiv's MoD opened a secure platform giving allied governments, labs and defence manufacturers access to technical data, reports and vulnerabilities from captured Russian missiles, drones and vehicles. Partners can even request physical hardware for testing to speed up countermeasure development. Find out more

Google Updates

  • Google Images Turns 25 and Goes Full Pinterest: Marking its 25th anniversary, Google Images rolled out a redesigned "immersive" gallery with a Pinterest-style masonry layout and collections for saving images, plus AI image generation (Nano Banana model) directly in Search. Find out more

Darkweb

  • De-anonymising Tor Hidden Services: SOS Intelligence walks through how onion services blow their own cover through misconfiguration — exposed Apache mod_status, leftover phpinfo() pages, SSL certs logged in Certificate Transparency, and EXIF metadata — plus hardening tips for anyone running one. Find out more

Upcoming CyberSec / OSINT Events

Free

Virtual

  • Digital Threats in the Age of AI (Free, 6-week virtual): Craig Silverman is once again recruiting a new cohort of journalists for this free six-week course, which has already trained 100+ reporters worldwide to investigate online platforms, disinformation, trolling, inauthentic activity and deceptive websites. This year's trainers include Jane Lytvynenko, Etienne Maynier and Luis Assardo. Open to staff and freelance journalists everywhere; applications due August 7.

    • I'm a last-year alum and HIGHLY recommend applying to join this year's cohort.

CTF

Onsite

  • US OSINT Symposium 2026 - Aug 5-6: Opening networking reception on Aug 5, followed by a full day of practitioner-led sessions on Aug 6, themed "Decision Advantage with OSINT" - moving open-source intelligence beyond collection into real impact. Register here

  • IJ Masterclass (AIJC × DW Akademie × Bellingcat): Three-day investigative journalism masterclass covering digital forensics, verification, and OSINT tools, held ahead of AIJC2026. November 7-9, Kenya. Apply by July 31. Apply

CFP

  • [Poland] The Hack Summit 2026 - Call for Papers: Tracks include Security in Software Development & DevSecOps. Submissions open until August 2. Event runs November 5 (online) and November 6 at PGE Narodowy in Warsaw. Submit

Found this helpful? Forward it to someone who’d enjoy it.

Keep Reading