RSS Amplifier

Project OSINT · Aug 11, 2026

Project Osint Tuesday 11 august

0
Sign in to vote or save

Project OSINT · Project OSINT

Is a complex, autonomous verification system: the research manager oversees the 10-stage LangGraph workflow (research, extraction, risk assessment, linking, verification, temporal analysis, reporting, graphing), which includes risk discussion, the detection of temporal contradictions and the identification of graphs in Neo4j for analysis and verification. It was created for technical assessment, but its core concepts – the coordination of the work between the manager and the executor, the trade-off between cost and quality across different models, explicit state and graph-based analysis – are applicable to any field requiring structured and verifiable research from open-source materials.

https://github.com/solankiharsh/ai-assessment

The Federal Bureau of Investigation (FBI) is concerned that artificial intelligence models of the Anthropic Mythos calibre could drastically lower the threshold for identifying and exploiting software vulnerabilities. FBI Deputy Director Todd Hemmen stated that Mythos has uncovered vulnerabilities in widely used open-source projects, which form the basis of operating systems, security tools, web infrastructure and encryption technologies. Such capabilities could pose difficulties for law enforcement, as they could be exploited by foreign intelligence services, cybercriminals and other malicious actors.

The FBI has not yet detected widespread use of advanced language models in real-world attacks, but believes it is only a matter of time. Access to Mythos 5 remains restricted and is granted only to approved organisations, but the developer emphasises that even less powerful public AI models are capable of performing comparable functions.

The FBI is currently expanding its internal use of artificial intelligence. The agency uses facial recognition, helps triage reports of suspected crimes, enhances the efficiency of court-authorised offensive operations, and applies artificial intelligence in general investigations. In total, the FBI’s inventory includes around 🤖50 use cases for artificial intelligence, and decisions affecting investigations are subject to mandatory review by a staff member.

Furthermore, according to investigative journalist Daniel Boguslaw (Reason), the FBI’s Centre for Threat Screening (TSC) is increasingly interested in predictive artificial intelligence technologies. It is anticipated that these tools will be used to analyse data and predict potentially dangerous actions by members of the public before they are committed.

The agency is seeking technical solutions that can help analyse connections between data across different systems, identify matches and predict, for example, which citizens might be linked to terrorist activities. During a congressional hearing in March 2026, FBI Director Kash Patel reported a significant increase in biometric capabilities and the volume of intelligence data. In an interview with Fox News, he also confirmed that experts from leading technology companies are working within the FBI to implement artificial intelligence algorithms for the instantaneous analysis of terabytes of information.

Essentially, US intelligence agencies are seeking to use predictive artificial intelligence algorithms and large language models to automatically identify ‘potential domestic threats’ even before citizens commit any offence. Terrorist surveillance records are being redirected from international extremist organisations towards US citizens who criticise government policy, capitalism or the official ideology.

Due to the enormous volume of data (the surveillance database has grown to include nearly 2 million people), FBI analysts are unable to manage it manually. To identify connections, patterns and predictive models, the agency relies on major technology companies. The databases contain numerous errors even without the application of predictive algorithms. Journalists, human rights defenders and politicians are already included on the surveillance lists, and it is legally virtually impossible to challenge one’s inclusion in the database or have one’s name removed.

This week’s OSINT mistake comes from a viral video that claimed to show the Iranian Revolutionary Guard Corps striking a tanker with a missile in the Strait of Hormuz after the vessel allegedly refused to comply with Iranian orders.

The claim was dramatic, geopolitically explosive, and visually compelling. It was also false.

On August 10, 2026, Misbar reported that the circulating footage was AI-generated and did not show a real Iranian missile strike in the Strait of Hormuz. According to Misbar’s investigation, the video was created using a real image published by Reuters and other outlets on November 28, 2025, showing the oil tankers Virat and Kairos on fire in the Black Sea off the Turkish coast after explosions near the Bosphorus Strait.

The OSINT mistake was simple but serious: analysts and social media users treated a synthetic video as evidence of a live military-maritime incident before verifying its provenance.

The key lesson is that a real geopolitical context does not authenticate the media attached to it. Tensions in the Gulf, concerns over the Strait of Hormuz, and Iranian military signaling may all be real. But that does not mean every viral clip showing a burning tanker is evidence of a new attack.

Misbar found that a frame from the AI-generated video matched several visual elements from the older Reuters image, including the shape of the flames, smoke plume, vessel structure, fire reflection on the water, and details visible at the bow and stern. The outlet also reported that Hive’s AI-generated content detection tool assessed the footage as containing digitally generated content with 99.7% confidence.

A major attack in the Strait of Hormuz would likely produce multiple independent confirmations, including maritime security alerts, shipping data anomalies, official statements, satellite imagery, or wire-service reporting. Instead, the claim relied heavily on a single viral visual artifact.

The video also emerged in a high-emotion information environment, where maritime security, Iran, the IRGC, energy markets, and U.S. regional posture are already sensitive topics. That makes verification even more important, not less.

A professional OSINT workflow should have started with keyframe extraction, reverse image search, and comparison against older maritime incident imagery. The correct analytical question was not: “Does this look like a tanker strike?” It was: “Can we prove this video was created at the claimed location, on the claimed date, by a verifiable source?”

The answer was no.

Assessment: the video should not be used as evidence of an Iranian strike on a tanker in the Strait of Hormuz.

Lesson of the week:
In OSINT, visual realism is not provenance. A convincing video is still just an unverified artifact until its origin, date, location, and source chain are established.

The State Standardisation Committee of the People’s Republic of China has officially approved the plan to develop the mandatory national standard ‘Fundamental Safety Requirements for the Use of AI Agents’ (plan number: 20263116-Q-252) . This is the world’s first mandatory national standard dedicated to the security of AI agents. It is stated that its inclusion in the plan fills an international gap in the field of mandatory security standards for AI agents in the public services sector and is a strategic measure to improve China’s comprehensive AI management system. The standard is overseen by the Office of the Central Commission for Cybersecurity and Informatisation. The main developers are China Mobile, the China Electronics Standardisation Research Institute (CESI) and the National Co-ordination Centre for Cyber Incident Response (CNCERT/CC).

Currently, the industrialisation of AI agents is accelerating rapidly, and the pace of technological advancement and sectoral penetration is exceeding expectations. At the same time, the fundamental logic underpinning the security of AI agents has undergone a radical transformation. Security risks have shifted from the traditional level of content generation to that of autonomous actions. Information leaks, loss of control over access rights, misuse of tools and deviation from intended purposes are increasingly becoming real threats. The world’s major economies are successively adopting regulations for the management of AI agents, and competition in the technology and standards sectors is constantly intensifying. Under these circumstances, the development of a single mandatory security standard is timely.

China Mobile draws on a long history of technological development in three areas: communication networks, computing infrastructure and AI. The company has built a security system covering the entire lifecycle of AI agents’ activities. The successful inclusion of the standard in the development plan means that China Mobile’s expertise in AI security management has reached a leading level in the country.

The standard is aimed at products and services based on AI agents that are accessible to the general public. It is structured around the task of preventing major security risks and ensuring compliance with a minimum level of protection. The standard creates a legislative basis for subsequent sector regulation, market access and technical assessment, whilst leaving reasonable scope for technological innovation and practical implementation.

The development plan for this mandatory national standard serves as a forward-looking instrument of state governance, combining development and security. It sets a benchmark for the prevention of systemic risks in the AI agent sector and for ensuring a minimum level of cybersecurity and data protection, and lays the foundations for the creation of a secure, reliable and manageable AI industrial ecosystem. At the same time, this is an important step towards China’s deeper involvement in global AI governance, the promotion of the Chinese approach, and the strengthening of the country’s position in the development of international rules for the AI agents sector.

From a cybersecurity perspective, the significance of this standard lies in the fact that, for the first time, in the form of a mandatory national technical standard, it defines security requirements targeting the autonomous actions of AI agents, and not merely the content they generate. The scope of the verifiable requirements includes identification, management of system privileges, invocation of tools, data collection and use, manual intervention in the event of risky operations, protection of input/output, logging and dynamic monitoring, as well as anomaly detection and emergency shutdown. China is positioning itself as a regulatory benchmark, and as Chinese agent platforms expand overseas, the national compliance model could become an industry standard for export.

SHADODORKS è un motore di ricerca per il “dorking” su Google. È un insieme completo di strumenti per la ricognizione, progettato per ricercatori di sicurezza e specialisti nel penetration testing.

https://shadohdorks.vercel.app/

The Click To Pray app, officially launched by Pope Francis in January 2019, contained a serious vulnerability that allowed access to the personal data of over 700,000 users. The service was developed by the agency La Machi Communication for Good Causes for the organisation ‘The Pope’s Worldwide Prayer Network’. In January 2026, independent cybersecurity researcher BobDaHacker discovered an issue in the app’s API. An unsecured interface provided information on any registered user without verifying access permissions.

The vulnerability fell into the IDOR (Insecure Direct Object Reference) category and was linked to a failure to verify whether the requesting user had the right to view a specific entry. User accounts were assigned sequential numerical identifiers. By incrementing the identifier sequentially, it was possible to cycle through entries in the range from 1 to 719,517.

In response, the API returned the email address, first name, surname, country, date of birth, user role, account deletion status and certain service fields. No request rate limits were detected, so automated data collection could be carried out using a simple script.

The cybersecurity researcher also identified a second issue. During registration, the API returned a `validation_hash` which was used in the email confirmation link. This allowed an account to be created using an arbitrary email address and confirmed without access to the corresponding email inbox.

On 3 January 2026, BobDaHacker sent details of the issue to nine recipients associated with Click To Pray and the ‘Pope’s Worldwide Prayer Network’, but received no reply. In July, the cybersecurity researcher passed the information on to a journalist at Dark Reading.

On 24 July 2026, Dark Reading and BobDaHacker published articles on the vulnerability. Following publication, the API’s behaviour changed, as confirmed by BobDaHacker in a subsequent check. When requesting another user’s profile, the server no longer revealed the email address, country or date of birth, displaying only the public first name and surname.

This is not the first publicly known case of a serious vulnerability in an application linked to the Vatican. In 2019, the British company Fidus Information Security discovered issues in the eRosary electronic rosary application. The API returned the account’s four-digit PIN in plain text. By knowing the user’s email address, an attacker could obtain the PIN from the API’s response and completely compromise the corresponding account.

The names, email addresses, countries and dates of birth disclosed via Click To Pray could be used for personalised phishing attacks in the name of the Vatican or the ‘Pope’s Worldwide Prayer Network’.

If this is useful, share it.

This is the weekly selection. But it’s not the only one.

If you’d like to read more: → full articles on the website

👉 https://projectosint.com

If you’d like to get the latest updates first: → Telegram

👉 https://t.me/osintprojectgroup

Location never lies.
It only waits to be decoded.

Read the original on projectosint.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.