@nixintel

Steven Harris | OSINT & Cyber Security Specialist | Investigator | Teach OSINT @SANSInstitute | @OSINTCurious | https://nitter.cf/t.co/EGO8CWyA6H

UK
Joined February 2019
🚨 The #OSINTSummit 2027 Call for Presentations is OPEN! Have an OSINT case study, tool, technique, research project, or lesson learned worth sharing with the community? ⏰ Submit by Oct. 19 📩 go.sans.org/dPm8qI #OSINT #OpenSourceIntelligence
1
2
4
827
Frustrating but predictable. It's hard for Russian info ops content to reach a wide audience, but they probably find that they can rely on western journalists to amplify it for them.
My one wish anytime I read an article about Matryoshka/Overload is to put in perspective that these posts are incredibly hard to see if you’re not actively looking for them. Their view and engagements (200k+ as NYT says) are almost entirely inflated thanks to automated bots.
1
2
839
Nixintel retweeted
Legislative Trojan horses 🇪🇺 Chat Control 1.0 and 2.0 🇪🇺 Social media ban for children 🇪🇺 Addictive design ban for adults 🇪🇺 Combat fraud and serious crime 🇦🇺 Social media ban for children 🇺🇸 Social media ban for children 🇺🇸 Addictive design restrictions for children 🇳🇿 Social media ban for children 🇮🇪 Social media ban for children 🇫🇷 Social media ban for children 🇨🇦 Social media ban for children 🇬🇧 Social media ban for children 🇬🇧 Addictive design restrictions for children 🇬🇧 Child exploitation & grooming protection 🇬🇧 Force platforms to prioritise "trusted" news 🇦🇪 Social media ban for children 🇪🇸 Social media ban for children 🇬🇷 Social media ban for children 🇩🇰 Social media ban for children 🇳🇴 Social media ban for children 🇦🇹 Social media ban for children 🇵🇱 Social media ban for children 🇸🇮 Social media ban for children 🇹🇷 Social media ban for children 🇮🇩 Social media ban for children 🇲🇾 Social media ban for children 🇧🇷 Social media restrictions for children 🇵🇹 Social media restrictions for children 🇮🇳 Social media ban for children 🇸🇪 Social media ban for children 🇩🇪 Social media restrictions for children 🇮🇹 Social media restrictions for children 🇨🇳 Social media restrictions for children I’m sharing this because more journalists have started following my work, and I want to show what I’m exposing through technical analysis anyone can understand. I’m working on one of my most consequential investigations into legislation and technology built for digital surveillance. It’s called Chat Control. What follows looks like coordination between governments and a handful of tech companies. Tech companies get more data to monetise. Governments gain the ability to monitor who says what, to whom, why, where they go and how they spend money. Technical Trojan horses 🇪🇺 Compulsory identity verification 🇪🇺 Scan private communications 🇪🇺 Weaken end to end encryption 🇪🇺 Expand lawful access 🇬🇧 Compulsory identity verification 🇬🇧 Compulsory on-device scanning for every app 🇬🇧 Algorithms to prioritize trusted news sources 🇦🇺 Compulsory identity verification 🇳🇿 Compulsory identity verification 🇮🇪 Compulsory identity verification 🇫🇷 Compulsory identity verification 🇪🇸 Compulsory identity verification 🇬🇷 Compulsory identity verification 🇩🇰 Compulsory identity verification 🇳🇴 Compulsory identity verification 🇦🇹 Compulsory identity verification 🇵🇱 Compulsory identity verification 🇸🇮 Compulsory identity verification 🇹🇷 Compulsory identity verification 🇦🇪 Compulsory identity verification 🇮🇩 Compulsory identity verification 🇲🇾 Compulsory identity verification 🇧🇷 Compulsory identity verification 🇵🇹 Compulsory identity verification 🇨🇦 Compulsory identity verification 🇺🇸 Compulsory identity verification Spot the pattern. 🔞 Australia set the stage. Other countries are now following with "robust" age assurance language in their TV appearances, including the US, UK and Ireland. The US AGs have added it to the proposed legislation following the Meta lawsuit. 💡 Australia’s own standard says age checks must be "technically accurate, robust, and reliable". "Robust" means fault proof. It brings meaning like "best" endeavours. Age estimation can’t meet that standard. As Australia defines it, age verification determines age "to a high level of accuracy", while age estimation only provides an approximate age. Fault proof age checking requires identity verification. Now look at the tech companies and what they built recently. Apple, Google, Meta and Microsoft built identity verification capabilities before governments started saying existing age assurance wasn’t "robust" enough. They knew what was coming. 🪪 Apple has age assurance APIs that can return verified age ranges, including confirmation using government ID, and its Wallet API lets apps verify age or identity from government issued digital ID. 🪪 Google recently built an Age Signals API so apps can receive age ranges and verification status. Android already lets parents block apps by age across the entire device, so this isn’t technically necessary for child safety. Google has also added facial verification to Google Account and Gmail recovery through selfie video matching, presented as account security. 🪪 Meta launched selfie based Facebook verification that checks a video selfie against profile photos and plans to expand it globally. 🪪 Microsoft has rolled out age assurance across Microsoft Accounts using facial age estimation, identity documents and government systems. Refuse to verify and some content and features are blocked. 💭 A handful of tech companies control the operating systems, app stores and identity layers across almost every mobile device. Governments barely need to negotiate outside G7 rooms. If Apple, Google, Meta and Microsoft enforce the same rules, billions of people are instantly impacted. The same technical capability keeps appearing: identify verification. Identity the person first, then decide what they’re allowed to do, who they're allowed to speak to, and when they're allowed to move money. p.s. Anthropic and OpenAI have identity verification services and the US government holds a kill switch that decides who has permission to use AI. --- Let me know if I got anything wrong. I have 60 minutes to make an edit. Or just leave a comment so others can see your correction.
This needs to be in front of every legislator in the world. Basic common sense, tech informed, genuine care for the wellbeing of children. Journalists who might be thinking of asking me in to talk about teen social media bans: please ask Paul as well. He's an expert.
17
338
28
907
27,967
Today at noon EDT I'm launching a book I've been working on for 20 months: Dynamic Incident Response, an iterative IR framework designed for how security teams actually work. Free in all formats. Join me for the launch today: sans.org/engage/dynamic-inci…
🤖 Made with AI
1
24
4
63
8,082
Last week I set out every Russian attack on European soil proven in court or formally attributed by a government. Nine cases. Here's the surprising reason why that list may stop growing. NATO has reportedly foiled a Russian operation in the Arctic rehearsing a weapon designed to disable undersea cables without leaving any trace of who did it. Britain, Norway and the United States tracked the vessels and confronted them. Read that again. Designed to leave no fingerprints. Every case on my previous list turned on evidence. Arsonists caught on camera. Parcels traced to a post office in Vilnius. Six people convicted at the Old Bailey on hard evidence. In each case evidence is what made attribution possible. However, a weapon engineered for deniability breaks that chain deliberately. The campaign doesn't stop. It just becomes unprovable. The UK is unusually exposed. Sixty-four cables connect Britain to the world, carrying some £220 billion of financial transactions every day. But it is worse than the number suggests: just two of those cables carry three quarters of our transatlantic capacity. In January last year the Russian survey ship Yantar was found loitering over British cables. Parliament's national security committee has reported on this. It said it was not confident Britain could prevent an attack on these cables, or recover within an acceptable period. That was the warning. So whilst we have spent five years getting better at exposing what Russia is doing. Moscow has spent that time building approaches they believe we won't be able to prove at all.
Yesterday, Germany named Russia as responsible for the drone attack on Leipzig-Halle Airport. Berlin summoned the Russian ambassador, ordered the consulate in Bonn to close, shut the Russian House in Berlin, and raised its national threat level. So I went back through the record. Not the suspicions. Not the speculation. The cases that have been settled in court or formally attributed by a government. The scales below mark cases proven in court. The columns mark cases attributed by a government. ⚖️ March 2024, London. Warehouse holding Starlink terminals for Ukraine burned down. Five convicted, up to 17 years. Ordered by Wagner via Telegram. ⚖️ May 2024, Vilnius. IKEA store set alight. A Ukrainian, 17 at the time, jailed. He acted for Russian military and security structures. 🏛️ May 2024, Warsaw. Marywilska 44 shopping centre destroyed, 1,400 units lost. Poland's Prime Minister confirmed it was arson ordered by Russian services. ⚖️ January 2025, Estonia. A supermarket and a Ukrainian restaurant torched. Two convicted. The court found the principal was tasked by the GRU. ⚖️ March 2025, Cologne. GPS-tracked parcels used to map delivery routes. A Ukrainian convicted of acting as a sabotage agent; the court found a Russian state entity initiated it. ⚖️ May 2025, London. Six Bulgarians jailed for a combined 50 years for surveillance run from a Great Yarmouth guesthouse. Targets: journalists, dissidents, Ukrainian troops. ⚖️ October 2025, Poland. Three Ukrainians convicted over a sabotage network spanning Poland, Lithuania, Latvia, Ukraine and Russia. 🏛️ November 2025, Poland. Explosion on the Warsaw-Lublin railway, a route carrying aid to Ukraine. Two men working with Russian intelligence identified. Classed as terrorism. 🏛️ August 2026, Leipzig. Explosive drone found beside a Ukrainian cargo aircraft. Attributed to Russia yesterday. Nine established cases. Six proven in court, three formally attributed by governments. Five countries. Britain in two of them. There is also a case currently before the British courts, which I have deliberately excluded from the tally above. In July 2024 an incendiary device posted from Vilnius ignited at a DHL warehouse in Birmingham, one of four parcels sent across Europe. Fifteen people have been charged. Those proceedings are ongoing and the allegations have yet to be determined by the court. And these nine are only the cases that have been established. There are many more besides: the plots disrupted before they landed, the cases still under investigation, the incidents no government has yet felt able to name. This is not a series of unfortunate events. It is a campaign. Russia is at war with the West today. Not tomorrow, not in some future scenario we can plan for at leisure. Today. We need to respond as though we understand that, and defend ourselves and our democracies accordingly.
26
84
9
243
57,989
Seriously not good
Your TV might be one of 216,000,000 LG smart TVs sold worldwide. Researchers rooted one and pulled plain text transcripts of what people said in the room. It kept recording while the screen looked off. If your TV can do that, it’s time to look at everything else on your desk👇🏻
13
30
2
300
69,619
Nixintel retweeted
We've somehow managed to make it a quarter of a century with this silly hobby project. Thanks to everyone who has helped make this happen - crazy hackers the world over, the wardriving community, and everyone who loves to see the RF spectrum come alive.
6
21
51
1,983
This was always going to happen to age verification systems. It wasn’t even so much of a prediction as it was an inevitability. The second half of this is tying actual web usage to real-world ID, and breaches will give us that too, soon.
Holy hell. "Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year." Masnick has huge updates on the massive identity verification data breach. And these were for IN PERSON uses. Lawmakers want them for endless online services too.
24
382
8
1,282
125,501
I've created a site called Dossier Overasselt that will update every 12 hours breaking down this case: dossier-overasselt.pplx.app/ #osint #overasselt
The Netherlands #overasselt case is getting more serious by the minute. @Crimesite obtained some new footage with some serious threats. What happened ? : Around , police received a report of a suspicious situation at a home on Ewijkseweg, where a large group of masked people had reportedly been seen. When the first officers arrived, they were immediately fired upon. A critically injured 51-year-old man from Wijchen was found and later died. Two officers were shot and taken to hospital. Police launched a major operation, including specialist arrest teams. Searches and arrests took place in Overasselt and surrounding areas, including near the A73, A76 and Nijmegen. Warning shots were fired during some actions. By the end of the day, police had arrested 34 suspects. The two injured officers are out of immediate danger. The investigation is ongoing; police have not confirmed a motive or individual roles, so claims of a specific criminal connection remain unverified. Source: Dutch Police politie.nl/nieuws/2026/septe… Contextl: the same Ewijkseweg address was reportedly targeted in a separate shooting in June 2025, but authorities have not publicly confirmed a connection to this week’s incident.
2
8
36
18,002
Nixintel retweeted
Investigate malicious IPs and report them back to the community. The AbuseIPDB integration for Cortex & TheHive provides confidence scores, report history, and abuse categories. Teams can also report malicious IPs to AbuseIPDB. strangebee.com/integration/a… #AbuseIPDB #TheHive
2
7
266
Some people in the community seem to be fully locked into the idea that there is no risk, no uplift, just hype from AI. I find this totally perplexing, it’s obvious how impactful the technology is. As capability progress continues rapidly we, more than other groups, should be advocating on behalf of people that don’t have the same foundational understanding.
2
3
41
4,305
The media is making the same mistake it always does about foreign info ops: framing them as though the goal is to advance a specific political agenda. In reality, the goal is specifically to amplify existing cultural fissures in American society.
14
29
2
285
8,974
One message to @VodafoneUK's #CEO was all it took. Within hours of the disclosure to Mr Taylor's team, the HMD Fuse/#Harmblock+ device appears to have been pulled from Vodafone & Three. It's disappeared from Mozillion too, for reasons unknown. This is what #responsibleDisclosure looks like when a company's commitment to #ChildSafety is genuine rather than a marketing line. Vodafone deserve enormous credit for how they handled this. Swift, decisive, no legal obstruction. One of the most straightforward disclosures I've been involved in; the new yardstick to which all others will be compared. The #HMDFuse should not return to market. Nobody involved in building it appears to have asked the most basic questions about whether it actually safe, not even the then Secretary of State for #DSIT, @peterkyle or @jessphillips - who claimed it was "proven technology" whilst testing the vulnerable device. #HMD's own website still has it advertised at a £50 discount, yet the platform has been offline since July 8th. Thanks to everyone who raised awareness with retweets/quotes.
PSA: Multiple Critical HMD Fuse / #HarmBlock+ Vulnerabilities Over the past seven months, I've responsibly disclosed multiple critical security vulnerabilities affecting the HMD Fuse and HarmBlock+ platform to HMD and Xplora. Those reports have now resulted in the platform being taken offline. During my research, I was able to: • Silently pair with any HMD Fuse device, anywhere in the world, assume the role of the parent/guardian, access the child's live GPS location, remotely manage installed apps, and disable all HarmBlock+ protections. • Emulate any HMD Fuse device, allowing arbitrary device data to be uploaded and presented to the parent/guardian application. • Remove all HarmBlock+ protections entirely by factory resetting the device using Google's Find My Device or a standard ADB command, despite the platform being marketed as "deeply embedded into the OS" and "cannot be bypassed or uninstalled." HMD has notified the UK Information Commissioner's Office (@ICOnews). However, affected users have not been informed of the nature or impact of the incident. Instead, the app simply states the service is unavailable due to "maintenance and security upgrades." Based on my findings, these vulnerabilities were present from the product's launch and affected the platform's core security model. In my opinion, they created a significant risk to children's privacy and safety and render the product unfit for its intended purpose. Whilst I commend HMD for taking the platform offline, I believe parents deserve a clear explanation of what happened, what information may have been affected, and what steps they should take. A detailed analysis is coming soon. Clarification: The HMD Fuse embeds HarmBlock AI, developed by @SafeToNet. Despite the similar names, HarmBlock AI and HarmBlock+ are different products. The vulnerabilities I've disclosed relate to HMD's HarmBlock+ implementation and surrounding platform, not SafeToNet's HarmBlock AI technology. These findings do not indicate any weakness in HarmBlock AI itself.
4
11
1
32
6,682
Sound ON! 🔊 #OnThisDay in 2005 🗓️ One of the great balls 🙌
52
223
42
2,728
284,006
Nixintel retweeted
Shodan Membership sale is live until 2026-08-09 00:00 UTC (~48 hours from now): account.shodan.io/billing/me…
76
491
109
1,444
499,353
Nixintel retweeted
Incidentally I am conceding this bet. Strictly speaking it hasn’t resolved (I think we’ve yet to see an Annals-quality number theory paper) but it’s clear I was wrong about what capabilities were necessary to produce one, and it’s just a matter of time.
I bet @littmath that in 5 years AI will be able to produce Annals-quality Number Theory papers at an inference budget at or below $100k/paper, at 3:1 odds in my favor.
60
191
32
3,196
420,838
Completely gripped by this cricket scandal 😁 The fact that playing statistics are now heavily recorded even at village cricket level means it's become possible to spot anomalous behaviour caused by cheating in a way that was not possible before.
Amazing village cricket drama. Don't think I've ever seen anything so brazen. I went through the matches he kept wicket this year on Play-Cricket, and he averaged an astonishing 4 catches per game, including 8 in an innings! (World record in test cricket is 7 in an innings btw)
1
2
981