DFRLab tracked four fake Baltic stories back to the same recycled amplifier accounts
In August, Storm-1516, the Kremlin-linked disinfo operation with roots in Prigozhin's old troll farm, ran four fake stories targeting the Baltics: NATO troops supposedly killed at a military exercise, cloned outlet logos tying the Estonian and Lithuanian presidents to Epstein, and a Grok-generated video claiming Latvian conscripts were dodging medical exams. DFRLab's write-up is really about the method they used to prove it was one operation.
They pulled 275 mentions across six platforms, then coded every post by account, campaign, platform, and engagement so they could find accounts repeating across campaigns. Out of 1,651 amplifying accounts, only 105 touched more than one story, but eleven of those reposted the same account across three separate fakes. That's the tell: individual fakes are easy to dismiss, but a recycled amplifier list across unrelated narratives is what proves coordination.
Useful template if you're trying to show scattered junk content is one operation: map who's repeating it, not just what it says.
A Prague bus depot arson just turned into a Kremlin murder-for-hire indictment
A newly unsealed US indictment names five people running what prosecutors call the "RIS Network" on behalf of Russian intelligence. The charges connect a 2024 arson attempt at a Prague bus depot to a wider campaign: surveillance for targeted killings, commissioned attacks on infrastructure in countries backing Ukraine, and at least two attempted assassination recruitments, one in the US and one in Lithuania.
The alleged ringleader is a retired Russian intelligence colonel working with his own son, an active FSB officer, and a Cuban logistics fixer based in Russia who arranged crypto payments and hotels for the Prague attacker. When a Lithuanian recruit turned down a $25,000 offer to kill a Russian critic, the colonel reportedly suggested "simpler jobs" like firebombing NATO electrical substations. All five remain at large.
It's a rare case where the public record catches up to real-time attribution: Czech PM Petr Fiala pinned the arson on Moscow back in 2024, and the indictment now backs that up.
Hackers tore apart a Flock camera and found the encryption key hiding in plain sight
A hacker group calling itself stegan0gram pulled a Flock Safety camera down off a pole, cracked it open, and copied its Android filesystem. Working with 404 Media and WIRED, they found two unencrypted partitions sitting right next to all the locked-down stuff, one labeled "vendor" and one labeled "media." The media partition held the encryption key for most of the camera's stored footage. That's the kind of oversight that's worth remembering any time you're assessing how "secure" a piece of surveillance hardware actually is on-device versus in marketing copy.
The recovered logs are the more useful part for practitioners: one camera photographed about 50,200 vehicles and generated 1.6 million images over 21 days, and the object-detection code explicitly logs people in frame with a confidence score, not just plates. It also mixed up bumper stickers and a flag patch for actual plates. If you ever have to evaluate what an ALPR system captures versus what a vendor claims, this teardown is a genuinely useful reference point, and the hackers say they're publishing how they did it so it's replicable.
China's still getting banned NVIDIA chips, and C4ADS just mapped how
Export controls on advanced NVIDIA chips have been in place since 2022, and China has spent that whole time finding ways around them. C4ADS just published the receipts: they used Chinese government records, Southeast Asian trade data, and corporate filings to trace three live pathways. Chinese universities with defense-industry ties bought at least 56 restricted chips bundled into vague multimillion-dollar contracts routed through shell-like companies. Fifty separate shipments got diverted through Vietnam, India and Malaysia before landing in Hong Kong and China. And the biggest piece is a Singapore-based importer, Megaspeed, that's moved $4.6 billion in NVIDIA hardware since 2022 through an ownership structure that traces back toward the PRC.
What I like about this one is it's not a "gotcha" story, it's a map. C4ADS is upfront that this only covers six months of records and probably understates the real scale by a lot. If you ever need a template for how to structure a sanctions-evasion investigation around trade data and corporate ownership, this is worth studying for the method as much as the finding.
Join Signal & Shadow OSINT Hub Community
A working space for open-source investigators: verification, tools, and field intelligence, shared as it happens.




















