Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The AI ‘Ghosts’ Contaminating Academic Publishing

    August 27, 2026

    The OSINT Newsletter – Issue #120

    August 27, 2026

    InfoSec News Nuggets – 08/27/2026 – AboutDFIR

    August 27, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»The OSINT Newsletter – Issue #120
    News

    The OSINT Newsletter – Issue #120

    adminBy adminAugust 27, 2026No Comments7 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    👋 Welcome to the 120th issue of The OSINT Newsletter. This issue contains OSINT news, community posts, tactics, techniques, and tools to help you become a better investigator. Here’s an overview of what’s in this issue:

    • What OPSEC actually protects

    • How small mistakes lead to big exposure

    • Why identity separation is non-negotiable

    • …and why even floppy disks won’t save you

    🪃 If you missed the last newsletter, here’s a link to catch up.

    ⚡ Creating a Facial Recognition Search Engine Without Storing Faces

    The OSINT Newsletter - Issue #119

    The OSINT Newsletter – Issue #119

    🎙️ If you prefer to listen, here’s a link to the podcast instead.

    Episode 22: Reply Guys and Robot Toolsmiths: Mining Forums for Long-Term History and Building an OSINT Tool That Improves Itself

    Episode 22: Reply Guys and Robot Toolsmiths: Mining Forums for Long-Term History and Building an OSINT Tool That Improves Itself

    Let’s get started. ⬇️

    You can have perfect tools, clean workflows, and solid methodology… and still blow your own cover in five minutes.

    What makes OpSec tricky is that bossing it doesn’t require you to learn something complex. OpSec is about not doing obvious things wrong. If you picture yourself getting exposed or even doxxed, sophisticated attacks or advanced tracking are probably part of the picture. Maybe even 007 spy tactics. The opposite is more likely. Most exposures come from small, repeatable habits going wrong on autopilot: logging into the wrong account, reusing a username, letting your browser autofill something it shouldn’t, or forgetting which profile you started working under – fourteen hours ago.

    In this issue, you’ll learn (or recap):

    • What OPSEC actually protects

    • How small mistakes lead to big exposure

    • Why identity separation is non-negotiable

    • …and why even floppy disks won’t save you

    Think you can skip this issue? Think again. OSINT teaches you how to connect dots. OpSec is just as important: making sure those dots don’t lead back to you.

    Operational Security (OpSec) is the all-important discipline of controlling what others can learn about you while you conduct investigations.

    In OSINT, we’re trained to extract meaning from fragments: a username here, a timestamp there, a reused image somewhere else. OpSec is the recognition that you generate those same fragments, and some other investigator might be searching for you.

    Hiding your government name and location is just one part. Aside from avoiding doxxing, good OpSec means limiting attribution. Namely, the ability for someone to confidently connect activity back to a real person (a.k.a you).

    Put your tinfoil hat away; OpSec doesn’t mean disappearing completely. No need to be paranoid. It just means reducing signals that make linking easier, like separating identities, and avoiding patterns. Your infrastructure (accounts, browser setup), your behaviour (how and when you act), and your ‘data exhaust’ (cookies, sessions, metadata) all play a role in how visible you are.

    In case you didn’t notice the connection, good OPSEC is all about your choices. It’s all about you.

    Before you change setups or download anything, you need to learn the fundamentals: what it is that exposes you, why, and how to prevent it. Chances are, you refer to these OpSec concepts in all your OSINT (albeit from the other side). Still, managing them underpins everything; get them wrong, and no amount of tooling will save you.

    Everything you do online leaves some form of trace. Sure, this includes obvious things like accounts and posts, but it also means browsing behaviour, session data, and login activity.

    Even something as simple as searching for the same usernames across platforms while logged into a personal account can be enough. If you can build a profile from someone else’s footprints, assume yours can be built too. Tread carefully.

    The foundation of good OpSec: your personal identity and your investigative identity should never overlap. Imagine that you’re two different people. The investigative you and the personal you should have separate accounts with separate usernames, separate email addresses, and separate browser environments. Ideally, separate workflows entirely.

    The biggest mistake some beginners make is only managing partial separation. For example, a different username but the same browser. A new email, but logged in alongside your personal Instagram – and the same recovery mail for both.

    Once two identities are linked, they stay linked. Forever.

    Modern browsers are exposure machines. Autofill. Cookies. Saved logins. Saved sessions. It can all bleed personal into investigative work without you noticing. That’s before getting pwned even comes into the equation.

    Maybe revise that profile picture you’ve used on two accounts (even if you look hotter than that one felon). Maybe don’t write down your life story. It’s possible to identify a writing style carried between them, or a repeated phrase you use in your real life or career. Keep an eye on even harmless details that show who you really are.

    Private or incognito modes have their uses. Even if they’re not actually 100% private, these modes stop your browser saving history, cookies, and session data after use. This helps reduce long-term tracking and accidental cross-account contamination. Don’t think these are truly anonymous environments, but consider them an automatic OpSec starting point.

    Just curious. When was the last time you created a dedicated account for investigative work? So long? How come? Making dedicated or ‘sock puppet’ accounts is OpSec 101. They shouldn’t be tied to your real name, primary email, or existing accounts either.

    Email, social media, marketplaces, anything you interact with. If it touches your real identity, don’t touch it.

    If you’re an OSINT-er, you already know IP addresses can act as a location signal. VPNs are your new best friend: they help mask your IP, by routing your traffic through different locations.

    This is non-negotiable. No personal logins, no shared accounts, no shortcuts. It only takes one overlap to screw everything up.

    Even “just for a second.” Or completely irrelevant to anything you’re investigating. Running personal and investigative activity in the same session creates risk, and risk is what OpSec was created to avoid.

    Stay compartmentalised. Logged out: no problemo. Logged in: big problemo.

    Be intentional about what you do and how you do it. Don’t click unnecessarily. Don’t interact unless you need to. Trust us, you really don’t need to comment or like. Look what happened to the Pope.

    Assume that anything you do could be logged. Because it will be.

    You’ve locked it down.

    Now you should know:

    • Why OpSec is all about you

    • How small mistakes lose you big

    • Which data to be wary of exposing

    If you’ve separated your identities, controlled your environment, and stayed consistent in how you operate, you’ve already avoided the most common mistakes. Great job! You’re already doing better than America’s most notorious serial killer. You can outsmart the Mindhunters, but even floppy disks have metadata.

    …Now get moving with the rest of the tips you just read.

    See you next week, investigators!

    🏁 New CTF Challenge Live – The Metro

    A new CTF challenge has been posted on our CTF website. This week’s challenge puts your OSINT and geolocation skills to the test. Participants are given a photograph posted by an alleged hacker associated with an APT group, apparently showing them on their way to work.

    Your mission? Identify the metro entrance visible in the background and determine its precise geocoordinates.

    Think you can pinpoint the location from the clues in the image?

    Start competing in our Capture the Flag (CTF) !

    🪃 If you missed the last CTF, here’s a link to catch up.

    Last week’s CTF challenge featured a challenge titled “The Email,” in which participants were tasked with gathering social media intelligence to investigate a threat actor’s profile and identify an email address that had been shared following the compromise of a website’s database to facilitate discussions about payments.

    Challenge solution WU:

    To solve this challenge, participants need to collect social media intelligence.

    By checking across several social media platforms, they can find an X account using that specific username.

    By identifying the X account behind that username and checking the replies, at the bottom of the page they can find the email address which was shared by the hacker after they managed to dump the database of an organization.

    ✅ That’s it for the free version of The OSINT Newsletter. Consider upgrading to a paid subscription to support this publication and independent research.

    By upgrading to paid, you’ll get access to the following:

    👀 All paid posts in the archive. Go back and see what you’ve missed!

    🚀 If you don’t have a paid subscription already, don’t worry. There’s a 7-day free trial. If you like what you’re reading, upgrade your subscription. If you can’t, I totally understand. Be on the lookout for promotions throughout the year.

    🚨 The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleInfoSec News Nuggets – 08/27/2026 – AboutDFIR
    Next Article The AI ‘Ghosts’ Contaminating Academic Publishing
    admin
    • Website

    Related Posts

    News

    The AI ‘Ghosts’ Contaminating Academic Publishing

    August 27, 2026
    News

    InfoSec News Nuggets – 08/27/2026 – AboutDFIR

    August 27, 2026
    News

    Disruptive cyber activity highlights risk from internet-exposed systems and edge devices

    August 27, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    The AI ‘Ghosts’ Contaminating Academic Publishing

    August 27, 2026

    The OSINT Newsletter – Issue #120

    August 27, 2026

    InfoSec News Nuggets – 08/27/2026 – AboutDFIR

    August 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.