Hi Everyone,
Welcome to another dose of the interesting news I've been reading lately. Here's what caught my eye 👇
Cybersecurity News
Operation CameraSwarm hijacks 14,500 Dahua cameras across Ukraine and Russia: Hunt.io reconstructed a 35-day campaign where one operator took over 14,500+ Dahua cameras via credential attacks, auth-bypass flaws and a P2P trick, exposed by the operator's own leaked working directory. Find out more
UK police database breach exposes 100,000+ officers: A cyberattack on the UK's Police National Legal Database (PNLD) compromised the contact details of more than 100,000 police officers and other criminal-justice professionals, a particularly sensitive group to have exposed. Find out more
Vulnerabilities & Exploits & Hacks
VMware vCenter flaw under active attack: CVE-2026-59310 is being exploited in the wild, with suspected APT activity installing a reverse SSH framework for persistent access, tied to 361 IP addresses across 47 countries. Patch and hunt for anomalous SSH now. Find out more
Slovakia finds Russian SMS backdoors in EU-funded speed cameras: Slovakia's security authority found 279 new EU-funded speed cameras carry a hidden module giving remote shell access to twelve hardcoded Russian numbers, plus passwordless live feeds; the rebadged Russian units are now switched off. Find out more
Threat Hunting & Malware
Fake conference lure after DEF CON targets a researcher: Huntress detailed an actor posing as CoinDesk's marketing head who pitched a researcher a "security conference" via a booby-trapped Google Doc, delivering the AMOS infostealer on macOS and NetSupport RAT plus a Ledger implant on Windows. Find out more
Threat Hunting Labs launches a free "Hunting Leads" feature: A new free feature sharing small, real pieces of intrusion activity with full telemetry (Windows and Sysmon logs, EDR, Sigma detections, Zeek). Find out more
📰Reports
Espionage & Counterintelligence
Poland grid attack formally pinned on FSB Centre 16: The UK and EU jointly attributed the December 2025 campaign against Poland's energy sector to Centre 16 of Russia's FSB, one of the more consequential state attributions of the year. Find out more
Germany convicts a Ukrainian in a Russian-linked parcel plot: A Stuttgart court jailed a Ukrainian for espionage over posting GPS-tracker parcels to map a courier's routes for Russian intelligence, part of a foiled sabotage plot. Find out more
Moscow jails a man for 23 years for spying for Poland: A Moscow court convicted Georgy Pirogov of treason for allegedly passing secrets on Russian weapons to Polish military intelligence. Find out more
Taiwan's archive opening backfires on reputations: Taiwan's declassification of martial-law-era intelligence files has damaged the reputations of officials named in them, with one legislator quitting a party election over it. Find out more
UK charges an alleged IRGC spy over RAF Akrotiri: In Britain's first overseas National Security Act case, a British-Azerbaijani man was arrested in Cyprus for allegedly surveilling the RAF Akrotiri airbase for Iran's IRGC. Find out more
SOCMINT
Signal tests paid, phone-number-free registration: Signal is trialling an optional way to sign up without a phone number, gated behind a one-time payment meant to curb spam and abuse and help fund the nonprofit. Find out more
Hidden Telegram proxy links can leak your IP in one click: A single click on what looks like a Telegram username or a harmless link can expose your real IP to an attacker, because of how Telegram handles proxy links. Worth flagging to anyone doing sensitive work on the app. Find out more
YouTube counts a view from the first frame: From 24 August, YouTube counts a public view from the very first frame with no minimum watch time, so counts climb faster and mean far less (the stricter number lives on as "Engaged views"). YouTube says earnings are unaffected, though its 2027 monetisation changes are drawing criticism. Find out more
Shadow Economy
Somali pirates seize an Iranian "shadow fleet" tanker: Armed pirates hijacked SIBU 1 (aka Seamull), an OFAC-sanctioned product tanker tied to Iran's covert oil fleet, about 130 miles off Yemen and steered it toward Bosaso, Somalia. It was the second hijacking in four days, with Somali piracy now at a 10-year high amid the regional turmoil around the US-Iran war. Find out more
Industry
Chainalysis and TRM Labs clash over a $94.6M ICE contract: Chainalysis is challenging in court ICE's sole-source award of a $94.6M blockchain-analytics contract to TRM Labs, calling it "arbitrary, capricious and unreasonable." A rare public look at the crypto-tracing industry's government business. Find out more
AI
Prompt injection is now treated as unsolved: OWASP's 2026 report keeps prompt injection at the top of the LLM Top 10 and calls it an unsolved problem, not a bug awaiting a patch. Attacks are up 340% year on year, and indirect injection (instructions hidden in an email, doc or web page) makes up more than 55% of incidents. Find out more
The men behind Danny Bones, an AI-generated far-right rapper: The Bureau of Investigative Journalism, with Novara Media, named the two men behind Danny Bones (a music producer and a 3D artist), whose anonymous outfit had been paid by Advance UK to make by-election videos. Find out more
OSINT Section
OSINT Ambition founder posts a candid mea culpa

Tools
fakemy.run: Generates a fake GPS run you can upload to Strava, a neat trick when you are building an account for OPSEC and do not want real routes or location patterns leaking.
what3words: Turns any 3x3m spot on Earth into three words, widely used in the UK (including by emergency services) to pin or share a precise location from three simple words.

GCVE database: A European, decentralised vulnerability-numbering system and lookup (run by CIRCL) that complements the classic CVE feed.
I have been using it while profiling software vendors: checking a product here helps me see the bigger picture, which versions clients are running, whether those are vulnerable, and whether the vendor is actually doing anything about it.
Darkweb
Tor vs VPNs, down the rabbit hole (Part 2): A HackerNoon explainer digging into the real privacy trade-offs between Tor and VPNs, good grounding for anyone working on or around the dark web. Find out more
Upcoming CyberSec / OSINT Events
Free
Virtual
GIJN Academy: investigating technology and AI in conflict: A workshop where British investigative journalist Iain Overton, executive director of Action on Armed Violence, introduces a practical framework for investigating the technological systems behind modern warfare. Sep 29. Register here
CTF
Maltego Community CTF, Sep 12 (online): 60 OSINT challenges from beginner to advanced, competing against investigators worldwide. Find out more
ENISA European Cybersecurity Challenge, Oct 12 to 16: Europe's flagship CTF for young cybersecurity talent. Find out more
Trace Labs 30 Days of OSINT, from Sep 1: One OSINT challenge a day for 30 days, each focused on practical skills. Entry is $7 CAD via the CTF platform, with prizes for the top three. Registration closes Sep 1 at 10 AM ET. Register here
Onsite
CyberSweden 2026, Stockholm: Sweden's cybersecurity research conference, with speakers from PQShield, the Swedish Ministry of Defence, NCSC-SE and RISE, plus a PhD poster session. Register by 30 August. Find out more
UN Digital Cooperation Day 2026, Sep 21 (New York City): A day of sessions across AI science, AI policy and AI capacity building, hosted by the UN Office for Digital and Emerging Technologies. Find out more
Hack.lu 2026, Oct 20 to 23 (Luxembourg): The 20th edition of the open convention on computer security, privacy and the cultural and technical implications of technology on society. Find out more
🙃 Bonus
Mnemonic is hiring an Open-Source Researcher (Palestine): Mnemonic is looking for a part-time OSINT researcher (TOR) for its Rapid Response Programme, focused on Palestine. Location: Berlin or remote (Europe and SWANA countries). Deadline: August 27, 2026. Find out more
Found this helpful? Forward it to someone who’d enjoy it.

