Hi Everyone,

This is our latest investigation. Together with OCCRP, we mapped where SAFE (the State Administration of Foreign Exchange, the agency that manages China's foreign-exchange reserves) quietly holds assets across Europe. Through British Virgin Islands shell companies and Luxembourg holding firms, we traced Beijing's stakes in European critical infrastructure, utilities and real estate, among them a police headquarters, wind farms and natural gas. In Poland, that footprint runs through property and land interests tied to logistics centres.

Cybersecurity News

  • Arch Linux Pauses AUR Package Takeovers After Malware Wave: The Arch User Repository lets users "adopt" abandoned software packages. Attackers abused this to grab existing packages and slip in malware hidden inside files named "linter," "hasher" and "minifier." It's the third attack like this since June, so Arch switched the adoption feature off while it cleans up. Find out more

  • Bugtraq Is Back: The original full-disclosure mailing list, founded in 1993 and dark since 2021, was relaunched at DEF CON 34 by researcher Jonathan Brossard (endrazine). It's independently run, with no paywall and no corporate filter; DEF CON's Jeff Moss welcomed it with "the bug belongs to the finder." Find out more

Vulnerabilities & Exploits & Hacks

  • Vatican's Click To Pray App Exposed 700,000+ Users: An IDOR flaw in the official prayer app of the Pope's Worldwide Prayer Network let anyone pull names, emails, countries and birth dates via sequential IDs. Researcher BobDaHacker reported it in January 2026 but got no response for six months, leaving the data exposed the whole time. Find out more

  • I Quit Full-Time Bug Bounty Hunting: AppSec engineer Arian Gharedaghi reflects on walking away from full-time hunting, the 99% failure rate, the $0 months, the isolation and burnout, and how moving into pentesting and fintech AppSec made him a better hacker. A candid watch for anyone romanticising the bounty grind. Watch

Threat Hunting & Malware

  • Alviva Holding, Russian Shell Companies Behind Cybercrime Infrastructure: The Raven File traces how Alviva Holding (ASNs registered in Vanuatu and the Seychelles) underpins criminal infrastructure: heavily relied on by Clop ransomware, serving Cobalt Strike since 2009, and hosting the Verdina booter/DDoS-for-hire platform. Find out more

  • TweetFeed, a Free Real-Time IoC Feed from X: A handy early-warning tool (by Daniel López) that aggregates indicators of compromise shared by researchers on X in real time.

📰Reports

  • INTERPOL African Cyberthreat Assessment 2026. Report

  • Bank of Russia, Information Security Review, Q2 2026. Report

Espionage & Counterintelligence

  • Italy Approves Military Code Overhaul and Intelligence Reorganisation: Italy's government approved a draft bill introducing broad changes to the Military Code and reorganising military intelligence. Find out more

  • Kim Jong Un Orders a Boost to North Korean Intelligence: Kim Jong Un directed North Korea's main intelligence agency to significantly strengthen its military reconnaissance and foreign-intelligence capabilities. Find out more

  • Japan Sets Up a National Intelligence Office: Japan's government has established a National Intelligence Office, according to Chinese state media. Find out more

  • Sweden to Create Its Own MI6: Sweden is setting up its own foreign-intelligence service, modelled on the UK's MI6. Find out more

  • Former Turkish Spy Gains a UK Foothold via a London Firm: A former Turkish intelligence officer established a foothold in the UK through a private intelligence company registered in London. Find out more

SOCMINT

  • Australia's eSafety Sues Telegram Over Terror Content: Australia's online regulator filed civil-penalty proceedings in the Federal Court, alleging Telegram failed to remove pro-terror material, including footage tied to the Christchurch and Buffalo attacks, after user reports, with some content live for weeks. Telegram denies it and will fight; penalties could reach A$54.6M (about US$38M). Find out more

  • WhatsApp Tests Date-of-Birth Prompt in India: WhatsApp began testing an optional date-of-birth field for users in India, its largest market at 600M+ users, as it prepares for age-verification rules under the country's DPDP framework. Find out more

Press freedom

  • Worth reading: Veteran national-security reporter Jeff Stein (SpyTalk) was hit with a $1M defamation suit after reporting that an incoming Pentagon health official had been "effectively fired" from the CIA. Backed by Substack's Defender program and two pro-bono lawyers, he fought it, and last week the case was dismissed with prejudice in federal court. A good reminder of what a single nuisance suit can do to an independent journalist's time, sleep and finances. Read the interview

AI

  • Grokipedia Quietly Stopped Reviewing Edits in April, and Didn't Say So: Lawfare details how xAI's Grokipedia halted its edit-review process months ago without disclosure, raising real questions about integrity and manipulation of the AI-generated reference. Find out more

  • SAFE: A Standard for Sharing AI Security Incidents: The newly-formed Open Secure AI Alliance (Nvidia, Cisco, CrowdStrike, Hugging Face, Red Hat; now 120+ members) published a first proposal, Shared AI Findings Exchange (SAFE), giving organisations a confidential channel to report AI-agent incidents and near-misses as shared threat intel. Find out more

OSINT Section

  • Getting to Know Overpass (Turbo): At the last DIVER CTF one task really called for Overpass, and I'd never had a reason to use it, so I dug in, for me and for you. Overpass Turbo is a web tool that queries OpenStreetMap data directly: you can pull every object with a given tag (petrol stations, water towers, benches, specific brands) inside an area and see it on a map. It's a quiet superpower for geolocation, narrowing "where was this photo taken?" from a whole city to a handful of candidate spots. Try Overpass Turbo | OSM wiki

Tools

  • osint.industries, New Face Search (Beta): osint[.]industries rolled out a new face-search app ("Midsummer"). Has anyone put it through its paces yet? Find out more

  • Beeper, All Your Chats in One App: A free multi-platform chat aggregator that pulls messages from across your messaging apps into a single interface, on desktop and mobile. Find out more

  • SearXNG, Private Metasearch: A free, self-hostable metasearch engine that pulls from 279 sources in one place with zero tracking or profiling, and you can even run it over Tor for full ghost mode. Find out more

Google Updates

  • Google Pulls Earth AI Feature: Google disabled a new generative AI tool in Google Earth that allowed users to modify satellite imagery, following quick backlash over photorealistic deepfakes of disaster zones. Find out more

  • Google's Crawlers Use More Than GET and POST: Google's Gary Illyes confirmed the crawlers also send HEAD, OPTIONS, PUT, PATCH and DELETE requests, under 1.5% of total volume, mostly for JavaScript. A useful footnote for anyone reading server logs during an investigation. Find out more

Upcoming CyberSec / OSINT Events

Free

  • SPAR: AI Safety Research Mentorship: SPAR pairs people interested in AI safety with experts in the field. Research Scientist Jack Kengott (SaferAI) is mentoring a project on "Transcript Analysis for Cybersecurity Evals." Apply by August 18. Find out more

CTF

  • SCAN 2026 (Chainalysis × DAsset): A blockchain-forensics competition and official KBW2026 side event: on-chain analysis, transaction tracing and wallet-behaviour attribution. 24-hour online qualifier Aug 2 (teams up to 4); top 20 compete in the Seoul finals Sep 28. Prize pool: 2 BTC. Find out more

Onsite

  • Open Source Conference Luxembourg, Oct 7: A new track on "Decentralized Technologies for Digital Sovereignty" (federated tech, self-hosting, the fediverse, interoperability). CFP open, submit by August 23; conference in Belval, Luxembourg. Find out more

  • OSINT Switzerland, OSINT Night, Lugano (Sep 28): The first OSINT Night in Italian-speaking Switzerland, in collaboration with OSINTITALIA. Mirko Lapi (President, OSINTITALIA) speaks on how AI is reshaping OSINT and why human judgement still matters. Held in Italian; everyone welcome. Register here

  • DNSC Romania, BCC2026 Call for Volunteers: The Bucharest Cybersecurity Conference (DNSC and Bitdefender, 20 to 22 Oct) is recruiting volunteers aged 18 to 26 for the organising team, with a DNSC certificate and recommendation letter. Find out more

🙃 Bonus

Jobs: Alliance4Europe Is Hiring: A4E is growing its Red Team to 12 and has eight remote roles open for Europe-based candidates, including OSINT researchers, network coordinators and analysts working to counter foreign information manipulation. Apply by 18 August.

Found this helpful? Forward it to someone who’d enjoy it.