Open Source Signal logo
Open Source SignalСигнал відкритих джерел
Issue #059 20 July 2026 Daily Signal EN + UKR

Open Source Signal

Сигнал відкритих джерел

Bilingual OSINT radar for Ukrainian accountability work, verification, war-crimes documentation, losses, captivity and missing-persons research, maps, platforms, surveillance and researcher safety.

Daily issue #059: coordinated republication after a Ukrainian court blocked a corruption investigation; the OSCE human-rights monitoring method as a separation of interviews, remote observation and open-source corroboration; software provenance linking a European password manager to a Russian-certified counterpart without evidence of compromise; payment, company and domain records used to investigate an abusive-content platform while protecting victims; manipulated event flyers in a state-linked influence operation; and the evidentiary gap between promised pollution monitoring and data that communities can actually inspect.

Editorial frame

What this is: A bilingual editorial filter for public-interest OSINT. Each item explains what happened, why it matters, how a reader can use the insight, and where the method or evidence has limits.

What this is not: Doxxing, live targeting, stolen-data workflows, private-person deanonymization, credential hunting, revenge calls, unsafe operational guidance or unverified accusations against private people.

Rubric map

🇺🇦 Ukraine Lens
⚖️ War Crimes Verification
🛡️ Investigator OPSEC
🗂️ Casefile
📱 Platform Watch
🛰️ Infrastructure Signals
🇺🇦Ukraine LensУкраїнська оптика
#01

Coordinated republication needs a legal and evidence ledger, not only a solidarity statement

Source: OCCRP · 17 July 2026

What happened

Eight Ukrainian media outlets jointly republished an investigation by Slidstvo.Info and the Anti-Corruption Action Center after Kyiv’s Pecherskyi District Court prohibited disclosure before publication. The investigation concerned the acquisition of 143 properties in Kharkiv by the brother of State Bureau of Investigation director Oleksandr Sukhachov. The publishers created Initiative 143, while the original reporting team appealed the order.

Why it matters

Distributed publication can protect a public-interest investigation from becoming a single point of failure. It also creates a demanding record-management problem: every outlet should be able to show which version it received, what it independently checked, what legal notice applied and what was withheld to protect unrelated people.

How to use it

For coordinated republication, preserve the source package hash, transfer time, editor, verification checklist, court order and appeal status, legal advice, redactions, right-of-reply record, publication time, corrections and mirror locations. Make clear which facts were independently checked by each publisher.

Limits

Republication does not automatically validate every allegation or cancel a court order. Do not reproduce exact residential addresses, documents containing unrelated personal data or claims that the participating outlet did not review. The underlying property findings remain allegations unless established through the relevant legal process.

Спільне перевидання потребує правового й доказового журналу, а не лише заяви солідарності

Джерело: OCCRP · 17 липня 2026

Що сталося

Вісім українських медіа спільно опублікували розслідування Slidstvo.Info та Центру протидії корупції після того, як Печерський районний суд Києва заборонив його поширення ще до виходу. Матеріал стосувався придбання 143 об’єктів нерухомості у Харкові братом директора Державного бюро розслідувань Олексія Сухачова. Видавці створили «Ініціативу 143», а автори первинного матеріалу оскаржили судове рішення.

Чому це важливо

Розподілена публікація може не дозволити одному судовому або технічному рішенню повністю зупинити суспільно важливе розслідування. Водночас вона створює складне завдання для керування записами: кожна редакція має знати, яку версію отримала, що перевірила самостійно, яке правове повідомлення діяло та які подробиці вилучила для захисту непричетних людей.

Як це застосувати

Для спільного перевидання зберігайте контрольну суму пакета матеріалів, час передавання, відповідального редактора, перелік перевірок, судове рішення та стан оскарження, правову консультацію, вилучені подробиці, запити на коментар, час виходу, виправлення й місця розміщення копій. Чітко позначайте, які факти кожна редакція перевірила самостійно.

Обмеження

Перевидання не підтверджує автоматично кожне твердження й не скасовує судового рішення. Не поширюйте точні адреси житла, документи з даними непричетних людей або твердження, яких редакція не перевіряла. Висновки щодо нерухомості лишаються твердженнями, доки їх не встановлено у відповідній правовій процедурі.

ukrainepress-freedomcorruption-investigationevidence-custodylegal-risk
⚖️War Crimes VerificationВерифікація воєнних злочинів
#02

Interviews, remote monitoring and open sources should remain separate corroboration layers

Source: OSCE Office for Democratic Institutions and Human Rights · 15 July 2026

What happened

The OSCE Office for Democratic Institutions and Human Rights released the ninth interim report of its Ukraine Monitoring Initiative, covering alleged international humanitarian and human-rights law violations from December 2025 through May 2026. Its method combines trauma-informed interviews with survivors and witnesses, institutional and civil-society material, desk research, remote monitoring and open-source techniques, with findings cross-checked across credible independent sources.

Why it matters

A mixed-method report is strongest when readers can see which layer supports each finding. A witness account can establish experience, a public record can establish an institutional act, remote observation can establish visible conditions, and cross-source corroboration can strengthen timing or recurrence. They are complementary, not interchangeable.

How to use it

For each finding, record allegation type, date and location range, direct interview count, consent and protection status, institutional document, remote-observation artefact, open-source item, independent corroboration, contradiction, legal provision, confidence level and whether the conclusion applies to one case or a recurring practice.

Limits

The initiative documents and reports; it does not conduct criminal investigations or issue judicial findings. Do not expose interviewees, exact shelter or detention locations, covert communication methods or identifiable family details. A verified reporting period is not a complete account of every violation.

Інтерв’ю, дистанційне спостереження й відкриті джерела мають лишатися окремими шарами підтвердження

Джерело: OSCE Office for Democratic Institutions and Human Rights · 15 липня 2026

Що сталося

Бюро демократичних інститутів і прав людини ОБСЄ оприлюднило дев’яту проміжну доповідь Ініціативи спостереження за Україною. Вона охоплює ймовірні порушення міжнародного гуманітарного права та прав людини від грудня 2025-го до травня 2026 року. Методика поєднує чутливі до травми інтерв’ю з постраждалими й свідками, матеріали установ і громадських організацій, кабінетне дослідження, дистанційне спостереження та роботу з відкритими джерелами; висновки звіряють за кількома незалежними джерелами.

Чому це важливо

Змішана методика найсильніша тоді, коли видно, який шар підтримує кожен висновок. Свідчення встановлює пережитий досвід, відкритий документ — дію установи, дистанційне спостереження — видимі умови, а звіряння кількох джерел посилює часову прив’язку або повторюваність. Ці шари доповнюють, але не замінюють один одного.

Як це застосувати

Для кожного висновку фіксуйте тип ймовірного порушення, часові й географічні межі, кількість безпосередніх інтерв’ю, стан згоди й захисту, відомчий документ, матеріал дистанційного спостереження, запис із відкритого джерела, незалежне підтвердження, суперечність, правову норму, рівень упевненості та масштаб висновку: окремий випадок чи повторювана практика.

Обмеження

Ініціатива документує й повідомляє, але не проводить кримінальних розслідувань і не ухвалює судових рішень. Не викривайте опитаних, точні місця укриття чи утримання, приховані способи зв’язку або подробиці родин, що дають змогу встановити особу. Перевірений звітний період не є повним переліком усіх порушень.

ukrainewar-crimes-verificationhuman-rights-monitoringwitness-interviewscorroboration
🛡️Investigator OPSECБезпека дослідника
#03

Software provenance is a chain-of-custody question, not a country-of-origin label

Source: OCCRP · 17 July 2026

What happened

OCCRP reported that Spain-based password manager Passwork shares a common codebase origin, closely synchronized updates and near-identical documentation with a Russian counterpart certified by Russian security regulators. Updates for the Spanish product were described as arriving through an opaque company in the United Arab Emirates managed by a Russian co-founder. Passwork denied an ongoing relationship and said the products share no clients, servers, data or administrative access.

Why it matters

For a password manager, the relevant risk object is the update and build chain: who writes, reviews, signs, transfers and distributes code. Corporate domicile alone cannot prove independence, while shared origins alone cannot prove malicious behaviour or compromise.

How to use it

Create a software-provenance record with legal entities, founders, codebase origin, repositories and build systems, update source, signing certificates, package hashes, release timestamps, dependency changes, independent audit, data-flow claims, vendor response and confirmed incident status. Test updates in an isolated environment before organisational deployment.

Limits

OCCRP reported no evidence that the European product contains malicious code, that customer data was compromised or that the arrangement was illegal. Do not turn architectural similarity, nationality or regulatory certification into an allegation of espionage. Security conclusions require technical testing and evidence from the deployed environment.

Походження програмного забезпечення є питанням ланцюга зберігання, а не ярликом країни

Джерело: OCCRP · 17 липня 2026

Що сталося

OCCRP повідомив, що іспанський засіб керування паролями Passwork має спільне походження програмного коду, майже одночасні оновлення та дуже подібну документацію з російським відповідником, сертифікованим російськими органами безпеки. Оновлення іспанського продукту, за даними розслідування, надходили через непрозору компанію в Об’єднаних Арабських Еміратах, якою керує російський співзасновник. Passwork заперечив чинний зв’язок і заявив, що продукти не мають спільних клієнтів, серверів, даних чи службового доступу.

Чому це важливо

Для засобу керування паролями головним об’єктом ризику є ланцюг створення й оновлення: хто пише, перевіряє, підписує, передає та поширює код. Місце реєстрації компанії саме по собі не доводить незалежності, а спільне походження коду не доводить шкідливої поведінки чи зламу.

Як це застосувати

Створіть запис про походження програмного забезпечення: юридичні особи, засновники, початковий код, сховища й системи складання, джерело оновлень, сертифікати підпису, контрольні суми пакунків, час випуску, зміни залежностей, незалежна перевірка, заявлені потоки даних, відповідь постачальника та стан підтвердженого інциденту. Перед установленням в організації перевіряйте оновлення в ізольованому середовищі.

Обмеження

OCCRP не повідомляв про докази шкідливого коду в європейському продукті, витоку даних клієнтів або незаконності описаної схеми. Не перетворюйте подібність будови, громадянство чи державну сертифікацію на звинувачення у шпигунстві. Висновки щодо безпеки потребують технічної перевірки та доказів із конкретного середовища використання.

investigator-opsecsoftware-provenancepassword-managerssupply-chainvendor-risk
🗂️CasefileРозбір кейсу
#04

Payment and domain records can investigate a platform operator without re-exposing victims

Source: Bellingcat · 16 July 2026

What happened

Bellingcat investigated the person behind a forum used to trade non-consensual intimate images and other abusive material. Rather than reproducing victim content, the investigation linked payment streams, company records, archived pages, domain and certificate history, public profiles and connected code-hosting accounts. The subject denied operating the forum and disputed the reporting.

Why it matters

Infrastructure and financial records can shift an investigation away from harmful content and toward the operator’s service chain. The method is strongest when each link has a timestamp and independent source, and when identity inference remains distinct from proof of criminal responsibility.

How to use it

Build an entity-link table with platform, domain, historical registration, certificate, hosting provider, payment processor, merchant account, company, officer, archived profile, code account, timestamp, source URL, confidence, contradiction, right of reply and victim-safety redaction. Capture only the minimum abusive-content evidence required to establish the platform function.

Limits

The article contains descriptions of sexual abuse material and requires a content warning. Do not download, redistribute or embed victim imagery, identify victims or pursue unrelated family and social contacts. A linked infrastructure pattern is an investigative finding, not a court judgment.

Платіжні й доменні записи дають змогу дослідити оператора платформи без повторного викриття постраждалих

Джерело: Bellingcat · 16 липня 2026

Що сталося

Bellingcat дослідив імовірного оператора форуму, на якому поширювали інтимні зображення без згоди та інші шкідливі матеріали. Замість повторного показу матеріалів постраждалих розслідування поєднало платіжні потоки, корпоративні записи, архівні сторінки, історію доменів і сертифікатів, відкриті профілі та пов’язані облікові записи у сховищах коду. Згадана людина заперечила керування форумом і висновки матеріалу.

Чому це важливо

Інфраструктурні та фінансові записи дають змогу відвести дослідження від шкідливих матеріалів і зосередитися на ланцюгу обслуговування платформи. Метод найсильніший, коли кожен зв’язок має час і незалежне джерело, а припущення про особу не підміняє доказ кримінальної відповідальності.

Як це застосувати

Побудуйте таблицю зв’язків: платформа, домен, історичний запис реєстрації, сертифікат, постачальник розміщення, платіжний посередник, торговий рахунок, компанія, посадова особа, архівний профіль, обліковий запис у сховищі коду, час, адреса джерела, рівень упевненості, суперечність, запит на коментар і вилучення даних для захисту постраждалих. Зберігайте лише мінімум шкідливого матеріалу, потрібний для встановлення функції платформи.

Обмеження

Матеріал містить описи сексуального насильства й потребує попередження про чутливий зміст. Не завантажуйте, не поширюйте й не вбудовуйте зображення постраждалих, не встановлюйте їхні особи та не досліджуйте непричетні родинні чи соціальні контакти. Пов’язана інфраструктура є журналістським висновком, а не судовим рішенням.

casefiledomain-historypayment-recordsentity-resolutionvictim-protection
📱Platform WatchПлатформний радар
#05

A manipulated event flyer needs an artifact lineage and an event-ground-truth check

Source: Graphika · 13 July 2026

What happened

Graphika reported that the Chinese state-linked Spamouflage network used inauthentic accounts on Facebook and X to circulate manipulated event flyers and false information about human-rights events and protests in the United States and Europe. The activity occurred in June and July 2026 and was the first time Graphika said it had observed this specific tactic from the network.

Why it matters

A false flyer can alter attendance, create safety concerns and manufacture a record of an event that never existed. Verification therefore needs both image lineage and ground truth from organisers, venues and official schedules, not only account-level attribution.

How to use it

Preserve the earliest known original and manipulated flyer, file hashes, visual differences, publication time, account history, cross-platform copies, organiser and venue confirmation, event status, propagation graph, platform response and attribution confidence. Publish a clear corrected artifact without amplifying the false logistics.

Limits

One manipulated image or suspicious account does not establish state direction. Graphika’s attribution concerns a network assessed as state-linked and should retain its confidence language. Do not repost false dates, addresses or security instructions in a way that extends the operation’s reach.

Підроблена афіша потребує ланцюга походження та перевірки реальної події

Джерело: Graphika · 13 липня 2026

Що сталося

Graphika повідомила, що пов’язана з китайською державою мережа Spamouflage використовувала неавтентичні облікові записи у Facebook та X для поширення змінених афіш і неправдивих відомостей про правозахисні події та протести у Сполучених Штатах і Європі. Активність тривала в червні та липні 2026 року; Graphika вперше зафіксувала саме такий прийом у цієї мережі.

Чому це важливо

Підроблена афіша може вплинути на відвідуваність, створити загрозу безпеці та вигадати слід події, якої не було. Тому перевірка потребує і походження зображення, і підтвердження від організаторів, майданчика та офіційного розкладу, а не лише висновку щодо облікових записів.

Як це застосувати

Зберігайте найранішу відому справжню й підроблену афішу, контрольні суми файлів, видимі відмінності, час публікації, історію облікового запису, копії на інших платформах, підтвердження організатора й майданчика, стан події, схему поширення, відповідь платформи та рівень упевненості щодо походження. Публікуйте чітке виправлення, не посилюючи неправдиві організаційні подробиці.

Обмеження

Одне змінене зображення або підозрілий обліковий запис не доводять державного керування. Graphika описує мережу як пов’язану з державою, тому формулювання про рівень упевненості слід зберігати. Не повторюйте неправдиві дати, адреси чи вказівки з безпеки так, щоб розширювати охоплення операції.

platform-watchinfluence-operationsimage-verificationevent-verificationtransnational-repression
🛰️Infrastructure SignalsІнфраструктурні сигнали
#06

A monitoring promise is not a dataset until sensors, dates and public access are live

Source: Human Rights Watch · 16 July 2026

What happened

Human Rights Watch reported that the United States delayed and weakened implementation of a rule requiring continuous fenceline monitoring for six hazardous pollutants at industrial facilities. Plants had been due to begin collecting data on 15 July 2026, with public reporting planned for July 2027, but extensions and regulatory changes postponed monitoring at additional facilities.

Why it matters

Policy text, installed sensor, operating sensor, calibrated measurement and public record are different evidence states. A delayed monitoring duty creates a documented absence of data; it does not prove clean air, exact emissions or compliance.

How to use it

Track facility, operator, pollutant, sensor method, required start date, actual start date, exemption or extension, calibration record, data completeness, publication deadline, public endpoint, exceedance rule, corrective action and community complaint. Keep calculated emissions separate from direct measurements.

Limits

Monitoring data require calibration, siting and missingness review before comparison. A fence-line reading does not by itself prove a specific source, health outcome or legal violation, while the absence of a sensor reading is not evidence that pollution was absent.

Обіцянка контролю не є набором даних, доки не працюють прилади, строки й публічний доступ

Джерело: Human Rights Watch · 16 липня 2026

Що сталося

Human Rights Watch повідомила, що Сполучені Штати відклали й послабили впровадження правила про безперервне вимірювання шести небезпечних забруднювачів на межі промислових підприємств. Підприємства мали почати збирати дані 15 липня 2026 року, а оприлюднення планувалося на липень 2027-го, однак продовження строків і зміни правил відтермінували контроль на додаткових об’єктах.

Чому це важливо

Норма в документі, встановлений прилад, справний прилад, відкаліброване вимірювання та відкритий запис є різними станами доказу. Відкладений обов’язок контролю створює задокументовану відсутність даних, але не доводить чистого повітря, точного обсягу викидів чи дотримання правил.

Як це застосувати

Відстежуйте підприємство, оператора, забруднювач, спосіб вимірювання, обов’язкову й фактичну дату початку, виняток або продовження строку, запис калібрування, повноту даних, строк оприлюднення, відкриту адресу доступу, правило перевищення, виправний захід і скарги громади. Розрахункові викиди зберігайте окремо від безпосередніх вимірювань.

Обмеження

Перед порівнянням даних потрібно перевірити калібрування, місце приладу та пропуски. Показник на межі підприємства сам по собі не доводить конкретного джерела, наслідку для здоров’я чи правопорушення, а відсутність вимірювання не є доказом відсутності забруднення.

infrastructure-signalsenvironmental-monitoringpublic-datasensor-recordsimplementation-gap