Hi Everyone,

Welcome to another dose of the interesting news I've been reading lately. Here's what caught my eye 👇

Cybersecurity News

  • Operation CameraSwarm hijacks 14,500 Dahua cameras across Ukraine and Russia: Hunt.io reconstructed a 35-day campaign where one operator took over 14,500+ Dahua cameras via credential attacks, auth-bypass flaws and a P2P trick, exposed by the operator's own leaked working directory. Find out more

  • UK police database breach exposes 100,000+ officers: A cyberattack on the UK's Police National Legal Database (PNLD) compromised the contact details of more than 100,000 police officers and other criminal-justice professionals, a particularly sensitive group to have exposed. Find out more

Vulnerabilities & Exploits & Hacks

  • VMware vCenter flaw under active attack: CVE-2026-59310 is being exploited in the wild, with suspected APT activity installing a reverse SSH framework for persistent access, tied to 361 IP addresses across 47 countries. Patch and hunt for anomalous SSH now. Find out more

  • Slovakia finds Russian SMS backdoors in EU-funded speed cameras: Slovakia's security authority found 279 new EU-funded speed cameras carry a hidden module giving remote shell access to twelve hardcoded Russian numbers, plus passwordless live feeds; the rebadged Russian units are now switched off. Find out more

Threat Hunting & Malware

  • Fake conference lure after DEF CON targets a researcher: Huntress detailed an actor posing as CoinDesk's marketing head who pitched a researcher a "security conference" via a booby-trapped Google Doc, delivering the AMOS infostealer on macOS and NetSupport RAT plus a Ledger implant on Windows. Find out more

  • Threat Hunting Labs launches a free "Hunting Leads" feature: A new free feature sharing small, real pieces of intrusion activity with full telemetry (Windows and Sysmon logs, EDR, Sigma detections, Zeek). Find out more

📰Reports

  • SK-CERT: Analysis of the Radar Camera NERO R-ONE. Report

  • OECD due diligence guidance for responsible AI. Report

Espionage & Counterintelligence

  • Poland grid attack formally pinned on FSB Centre 16: The UK and EU jointly attributed the December 2025 campaign against Poland's energy sector to Centre 16 of Russia's FSB, one of the more consequential state attributions of the year. Find out more

  • Germany convicts a Ukrainian in a Russian-linked parcel plot: A Stuttgart court jailed a Ukrainian for espionage over posting GPS-tracker parcels to map a courier's routes for Russian intelligence, part of a foiled sabotage plot. Find out more

  • Moscow jails a man for 23 years for spying for Poland: A Moscow court convicted Georgy Pirogov of treason for allegedly passing secrets on Russian weapons to Polish military intelligence. Find out more

  • Taiwan's archive opening backfires on reputations: Taiwan's declassification of martial-law-era intelligence files has damaged the reputations of officials named in them, with one legislator quitting a party election over it. Find out more

  • UK charges an alleged IRGC spy over RAF Akrotiri: In Britain's first overseas National Security Act case, a British-Azerbaijani man was arrested in Cyprus for allegedly surveilling the RAF Akrotiri airbase for Iran's IRGC. Find out more

SOCMINT

  • Signal tests paid, phone-number-free registration: Signal is trialling an optional way to sign up without a phone number, gated behind a one-time payment meant to curb spam and abuse and help fund the nonprofit. Find out more

  • Hidden Telegram proxy links can leak your IP in one click: A single click on what looks like a Telegram username or a harmless link can expose your real IP to an attacker, because of how Telegram handles proxy links. Worth flagging to anyone doing sensitive work on the app. Find out more

  • YouTube counts a view from the first frame: From 24 August, YouTube counts a public view from the very first frame with no minimum watch time, so counts climb faster and mean far less (the stricter number lives on as "Engaged views"). YouTube says earnings are unaffected, though its 2027 monetisation changes are drawing criticism. Find out more

Shadow Economy

  • Somali pirates seize an Iranian "shadow fleet" tanker: Armed pirates hijacked SIBU 1 (aka Seamull), an OFAC-sanctioned product tanker tied to Iran's covert oil fleet, about 130 miles off Yemen and steered it toward Bosaso, Somalia. It was the second hijacking in four days, with Somali piracy now at a 10-year high amid the regional turmoil around the US-Iran war. Find out more

Industry

  • Chainalysis and TRM Labs clash over a $94.6M ICE contract: Chainalysis is challenging in court ICE's sole-source award of a $94.6M blockchain-analytics contract to TRM Labs, calling it "arbitrary, capricious and unreasonable." A rare public look at the crypto-tracing industry's government business. Find out more

AI

  • Prompt injection is now treated as unsolved: OWASP's 2026 report keeps prompt injection at the top of the LLM Top 10 and calls it an unsolved problem, not a bug awaiting a patch. Attacks are up 340% year on year, and indirect injection (instructions hidden in an email, doc or web page) makes up more than 55% of incidents. Find out more

  • The men behind Danny Bones, an AI-generated far-right rapper: The Bureau of Investigative Journalism, with Novara Media, named the two men behind Danny Bones (a music producer and a 3D artist), whose anonymous outfit had been paid by Advance UK to make by-election videos. Find out more

OSINT Section

  • OSINT Ambition founder posts a candid mea culpa

Tools

  • fakemy.run: Generates a fake GPS run you can upload to Strava, a neat trick when you are building an account for OPSEC and do not want real routes or location patterns leaking.

  • what3words: Turns any 3x3m spot on Earth into three words, widely used in the UK (including by emergency services) to pin or share a precise location from three simple words.

  • GCVE database: A European, decentralised vulnerability-numbering system and lookup (run by CIRCL) that complements the classic CVE feed.

    • I have been using it while profiling software vendors: checking a product here helps me see the bigger picture, which versions clients are running, whether those are vulnerable, and whether the vendor is actually doing anything about it.

Darkweb

  • Tor vs VPNs, down the rabbit hole (Part 2): A HackerNoon explainer digging into the real privacy trade-offs between Tor and VPNs, good grounding for anyone working on or around the dark web. Find out more

Upcoming CyberSec / OSINT Events

Free

Virtual

  • GIJN Academy: investigating technology and AI in conflict: A workshop where British investigative journalist Iain Overton, executive director of Action on Armed Violence, introduces a practical framework for investigating the technological systems behind modern warfare. Sep 29. Register here

CTF

  • Maltego Community CTF, Sep 12 (online): 60 OSINT challenges from beginner to advanced, competing against investigators worldwide. Find out more

  • ENISA European Cybersecurity Challenge, Oct 12 to 16: Europe's flagship CTF for young cybersecurity talent. Find out more

  • Trace Labs 30 Days of OSINT, from Sep 1: One OSINT challenge a day for 30 days, each focused on practical skills. Entry is $7 CAD via the CTF platform, with prizes for the top three. Registration closes Sep 1 at 10 AM ET. Register here

Onsite

  • CyberSweden 2026, Stockholm: Sweden's cybersecurity research conference, with speakers from PQShield, the Swedish Ministry of Defence, NCSC-SE and RISE, plus a PhD poster session. Register by 30 August. Find out more

  • UN Digital Cooperation Day 2026, Sep 21 (New York City): A day of sessions across AI science, AI policy and AI capacity building, hosted by the UN Office for Digital and Emerging Technologies. Find out more

  • Hack.lu 2026, Oct 20 to 23 (Luxembourg): The 20th edition of the open convention on computer security, privacy and the cultural and technical implications of technology on society. Find out more

🙃 Bonus

Mnemonic is hiring an Open-Source Researcher (Palestine): Mnemonic is looking for a part-time OSINT researcher (TOR) for its Rapid Response Programme, focused on Palestine. Location: Berlin or remote (Europe and SWANA countries). Deadline: August 27, 2026. Find out more

Found this helpful? Forward it to someone who’d enjoy it.