Fun quiz — I got 4/5 human (I recognized the Sagan quote though) www.nytimes.com/interactive/...
Fun quiz — I got 4/5 human (I recognized the Sagan quote though) www.nytimes.com/interactive/...
We are aware of recent reports regarding targeted phishing attacks that have resulted in account takeovers of some Signal users, including government officials and journalists. We take this very seriously. 1/7
“Both the sender and receiver hold matching one-time pads, identical sheets of random numbers used to encode and decode each message. Once used, the sheet is destroyed. The encryption is considered unbreakable.”
ICYMI: Yesterday, @bellingcat.com analyzed a video showing the attack on the Minab IRGC base that killed at least 168 people (mostly children) at the Shajareh Teyyebeh girl's elementary school.
We concluded the attack on the base involved a US Tomahawk missile.
www.bellingcat.com/news/2026/03...
U.S. Tomahawk hit naval base beside Iranian school, video shows
From @malachy.bsky.social and @johnismay.bsky.social
Free gift link: www.nytimes.com/2026/03/08/w...
Here's what Bellingcat has been up to this week:
Bellingcat analysed imagery and reporting from the first days of the conflict with Iran to identify US, Israeli and Iranian munitions now being deployed.
www.bellingcat.com/news/2026/03...
And X helpfully provides a built-in deanonymization LLM called Grok
Trying to make sense of an aircraft’s movements during a conflict? Context is everything. That’s why we built Turnstone, an open source tool that searches historical flight data to allow researchers to explore flight patterns over time and in specific locations. www.bellingcat.com/resources/20...
U.S. and EU police say they've taken down LeakBase, “one of the world’s largest online forums for cybercriminals” for sharing stolen passwords and hacking tools.
The site now displays a seizure notice.
New from 404 Media: the FBI is using AI to hack targets. FBI official was talking about "remote access operations," FBI's term for hacking. FBI said it's a "game changer". The comments were unusually candid about FBI's very secretive hacking operations. www.404media.co/the-fbi-is-u...
Yeah, so basically Mandiant and iVerify released a paper today about this spoopy thingy called "Coruna".
Coruna is very, very silly. Mandiant and iVerify discovered SOMEONE (they don't say who) developed some hardcore iOS zero day exploits. It exploited how iOS devices handled visiting
A full iOS exploitation toolkit, "Coruna," has been found in the wild, hacking iPhones that visited infected websites, used by Russian spies targeting Ukrainians and thieves targeting Chinese crypto holders. And it may have been originally created for the US government. www.wired.com/story/coruna...
Threat actors are abusing the redirection-to-URL feature of legitimate OAuth services to redirect the targets of phishing campaigns to malicious downloads.
Attacks are ongoing and have targeted government and public-sector organizations.
www.microsoft.com/en-us/securi...
New from 404 Media: CBP tapped into the online advertising ecosystem to track peoples' movements, according to an internal DHS document. Shows for the first time DHS tracked phones via process for putting ads in ordinary apps—video games, fitness apps, many more www.404media.co/cbp-tapped-i...
I built a free tool that shows how night-time lights have changed anywhere on Earth.
Here's how it works and why it's useful for monitoring conflict, disasters, development and growth. 👇
🚨NEW🚨 One of Iran's most notorious hacker crews, linked by Israelis to Tehran's intelligence apparatus, is using Elon Musk's Starlink to stay online.
It also has a blue tick account on Elon Musk's X, where it's been advertising its unverified retaliatory hacks.
www.forbes.com/sites/thomas...
Smoke rising over the Bandars Abbas Naval Harbour in Iran on March 2.
Fires at the Jebel Ali Port on March 1.
Planet has just released new high-res images from the Middle East conflict.
Left: Smoke rising over the Bandars Abbas Naval Harbour in Iran on March 2.
Right: Fires at the Jebel Ali Port in Dubai, UAE on March 1.
(Credit: Planet Labs PBC)
DHS's Office of Industry Partnership was hacked by a group called "Department of Peace" and info about ICE contracts with over 6,000 companies is now published on @ddosecrets.org!
Enjoy 🧊🔨 ddosecrets.org/article/ice-...
New: the government just made it harder to see what spy tech it buys. This includes ICE, the FBI, essentially any agency. Why? Because they decided to retire the perfectly good system for searching contracts and replaced it with one that fucking sucks
www.404media.co/the-governme...
Last May, Tennessee Highway Patrol joined ICE on the streets of Nashville.
We @lighthousereports.com + partners mapped the traffic stops and used 1M+ ICE records, dashcam video, and court files to show how supposed routine encounters became deportations.
New: the FBI got Grok to hand over the prompts a suspect used to generate nonconsensual porn. Connected to a harassment case. Pretty rare to see a Grok search warrant like this
www.404media.co/fbi-subpoena...
Want to investigate something using open sources but not sure where to start? 🧵
We’ve gathered some of our go-to resources for learning, practicing, and collaborating on open source research - whether you’re brand new or sharpening your skills...
New —> OpenAI uses the ChatGPT logs of a Chinese law enforcement official to trace a sprawling covert influence operation aimed at intimidating Chinese dissidents worldwide & denigrating the Japanese prime minister: www.cnn.com/2026/02/25/p...
New: this app warns you if someone is wearing smart glasses nearby.
Meta plans to add facial recognition to its Ray-Ban smart glasses. A 404 Media reader made this app after we showed men filming people w/o their consent, and DHS officials were wearing the glasses www.404media.co/this-app-war...
Tracing a ship's flag is often the first step toward uncovering bigger stories of corruption, smuggling, or sanctions evasion.
www.occrp.org/en/feature/p...
Today in Have LLMs finally mastered geolocation (cc @foeke.bsky.social)
From my colleagues: A covert Chinese nuclear test is part of a push by Beijing to develop the world’s most advanced nuclear arsenal, US spy agencies believe www.cnn.com/2026/02/21/p...
“weak credentials with single-factor authentication” — credential stuffing but AI
Bellingcat's latest documentary, Killing Anna, a tale of catfishing Syrian war criminals and exposing their roles in a massacre, will be shown at CPH:DOX in March. The ultimate Doxxing at DOX.
cphdox.dk/film/killing...
For those who don't understand the "banality of evil" reference, it's from Hannah Arendt's book about Adolf Eichmann's trial in Israel. She used it to describe how ordinary Germans/Poles/Ukrainians became accomplices to the Nazis by mindlessly buying into the demonization of their Jewish neighbors