X's algorithm feeds ragebait to the people most likely to argue with it
A new PNAS study on X's feed algorithm found something worth knowing if you monitor the platform for work: the "For You" feed doesn't just serve engagement, it specifically learns from replies. Users who reply to content the study's authors call "value-misaligned" — the stuff designed to provoke — get fed more of it, because the algorithm reads the reply as a signal to show more. The study also found this effect hits users who identify as Democrats harder, though the researchers aren't fully sure why yet.
Worth flagging for anyone doing social listening or sentiment work on X: what shows up in a feed isn't a neutral sample of what's being said, it's shaped by who argues back. A former X head of product confirmed to 404 Media that the reply-predictor was a known driver of ragebait and that X quietly turned it down last month. If you're building any kind of monitoring workflow around X content, that's a live variable, not a static one.
A free, searchable database of 660M+ ad supply-chain records just dropped
If you've ever tried to figure out which data broker is actually selling location data to ICE or CBP, you know how opaque the ad-tech supply chain is. Zach Edwards just launched DecryptAds, which aggregates the compliance files the ad industry is required to publish (ads.txt, app-ads.txt, sellers.json) into one queryable database — 284M+ ads.txt records, 184M+ app-ads.txt, 201M+ sellers.json at launch. It's the largest public corpus of this data assembled anywhere.
The useful part for verification work: it flags "geo-risk" on ad systems tied to sanctioned countries (Russia, Belarus, Iran) or adversary-designated ones (China, Hong Kong) and secrecy jurisdictions like Cyprus and the BVI. 404 Media already used it to identify close to 20,000 sites still running Adform code after that platform's July breach. If you're tracing where an app's data actually goes after it leaves the device, this is now a real starting point instead of guesswork.
Ireland cleared a Russian-linked alumina plant on evidence it never had
Back in March, OCCRP and partners reported that Ireland's Aughinish Alumina — Europe's biggest alumina refinery — had been shipping most of its output to Russian smelters owned by the same parent company, Rusal, and that those smelters were selling finished aluminum to a Moscow trader supplying 63 EU-sanctioned defense contractors. It set off a real fight in Brussels over closing the "alumina loophole."
Ireland just finished its own investigation and cleared Aughinish, saying there wasn't "sufficient evidence" its alumina ends up in weapons. But read the actual report and the caveat swallows the conclusion: Ireland's government admits it has no way to physically trace the material once it's inside Russia, never got access to the transaction data OCCRP used, and leaned mainly on a signed warranty from Rusal's own CEO. Meanwhile OCCRP's data shows over a quarter of the aluminum from one of the top importing smelters went to the domestic Russian market last year.
Good case study in the gap between "no evidence found" and "cleared," especially when the clearing body didn't have access to the same sourcing.
Apple's Private Relay has a real IP leak, and it's not the first time this year
If you've got Private Relay baked into your OpSec setup, worth knowing: researchers found a set of WebKit bugs (the passkey/WebAuthn flow, DNS prefetching, and WebTransport) that let a site quietly grab your real IP address even while Private Relay is on. No prompt, no indication it happened. It also hits OnionBrowser on iOS.
The practical bit: Private Relay only ever covered Safari traffic, never your whole device, and this shows even that promise doesn't hold in every case. Apple's confirmed it's investigating but hasn't given a fix date. If you're relying on it as your only layer, this is a good moment to pair it with something that tunnels all traffic instead of just Safari's.
Second Apple privacy feature to fail this way in as many months (Hide My Email got the same treatment from 404 Media last month).
Henk van Ess analyzed 1.8 million AI chatbot messages to find out who's actually falling down the rabbit hole
Someone spent thirteen hundred messages asking ChatGPT to check his theory about black holes. The bot told him he was ahead of 90% of published physics. He wasn't. It never said so.
Henk van Ess ran the numbers on the AI chatbot conversations that got indexed publicly (the story behind how those got exposed is worth its own read, and it's the piece I flagged last time as a bit stale). This is the follow-up: 112,000 conversations, 1.8 million messages, across ChatGPT, Claude, Copilot, and Gemini, all aimed at one question — does the model pull people deeper into a delusion, or do people do that themselves? He's got data on whether it's one company's problem or all of them, and whether you can actually spot it happening to you in real time.
Part of it's behind Digital Digging's paywall, but the free portion covers the core findings. Good one for anyone thinking about how AI chat logs get used (or misused) as an evidence source, or just watching what these tools do to people's epistemics.
How a redacted indictment still unmasked a Prince Group "enforcer"
OCCRP and the Straits Times just did something satisfying: they took a US federal indictment that anonymized seven Prince Group co-conspirators, and they unmasked one of them anyway. "Co-Conspirator-2" is allegedly the group's chief enforcer, the guy who bribed cops and officials to keep the Cambodian scam empire's compounds running. The indictment kept his name out, but it couldn't scrub the personal details.
The identification hinges on something almost mundane: the indictment says Co-Conspirator-2 chaired a specific subsidiary between 2017 and 2022. Cambodian corporate records show exactly one person held that seat during that window — Chen Sokly. From there it's a straight line through California property records, a Mauritius company registry, a Singapore superyacht dealership, and even a 2018 party video showing him mingling under an alias. None of it is exotic. It's just patient cross-referencing of public filings against a document that tried hard not to name him.
Worth reading if you ever have to work from a redacted or anonymized source document — this is a clean playbook for how much a timeline detail can give away.
Someone finally counted which OSINT tools actually get recommended
Indicator pulled every tool listed across 19 public OSINT toolkits — more than 12,000 entries — and ranked them by how often they actually show up, rather than trusting any single curator's taste. 57 tools made the cutoff (ties all included rather than broken arbitrarily), and notably, every one of them is free or has a working free tier.
The more useful part for daily use is what they built to generate the list: OSINT Navigator, a free app that aggregates all 19 toolkits into one searchable interface. Type something like "how do I find the owner of a website" and it surfaces the relevant tools, which toolkits recommend them, and a summary of your options. It's rebuilt weekly against a public dataset, so it doesn't go stale the way a static list does.
A Georgian outlet's YouTube channel vanished, then a reporter found the guy who killed it
Monitori — an OCCRP member center in Georgia — had its YouTube channel taken down last week over three bogus copyright claims, on videos about a politician's wife's Hermès collection, sanctioned judges, and a tax break for a government-linked businessman. A reporter emailed the complainant posing as a client, and within minutes had a WhatsApp number and a price list: $3,000–$5,000 to nuke a channel, $380 a video to walk a claim back once caught.
The same racket has hit Radio Azattyq (RFE/RL's Kazakh service) across Instagram, YouTube, and Facebook, flagged over stories on a presidential decree and a politically connected company. A researcher at Citizen Lab makes the point that matters here: this kind of takedown is invisible to everyone except the outlet losing its channel, and the burden of proof sits entirely on the victim.
ICE built a round-the-clock dragnet to unmask its social media critics
The Wall Street Journal published a piece last night that's worth your time if you do any work involving US government requests to platforms. It opens with an anonymous Reddit account, "Tired_Thumb," who posted 116 comments across 40 subreddits between January and mid-February, three of them critical of ICE. By March, that person was in a constitutional fight after DHS tried to unmask them.
That's not an outlier case. ICE has built a 24/7 operation scanning Facebook, Instagram, and X for anything that might "endanger the agency's mission," paying private contractors to turn public posts into dossiers with a target's name, location, date of birth, employer, and vehicle records. To unmask anonymous accounts, DHS has sent hundreds of subpoenas to social platforms, and reporting says they've recently escalated to grand jury subpoenas, which are harder to challenge than administrative ones.
Worth reading closely if you build dossiers from public posts for a living. It's the same open-source method, pointed at people documenting or criticizing a government agency instead of at bad actors.
Join Signal & Shadow OSINT Hub Community
A working space for open-source investigators: verification, tools, and field intelligence, shared as it happens.















