Open Source Signal logo
Open Source Signal Сигнал відкритих джерел
Issue W36 31 August–6 September 2026 Weekly Magazine EN + UKR

Open Source Signal Weekly

Тижневий сигнал відкритих джерел

Sunday editorial synthesis for Ukrainian accountability OSINT.

Week 36 was a lesson in preserving boundaries. Leipzig moved from pending attribution to a formal German accusation without becoming a judicial finding. A violent clash between Ukrainian security bodies produced competing accounts, notices of suspicion and an investigation, not a settled narrative. T4P's live war-crimes statistics demonstrated why documented cases are a lower bound rather than a denominator for all crimes. A new parliamentary platform for returning Ukrainian children showed why verified data, advocacy, locating a child, negotiating a return and an actual return are distinct case states. Reuters' visual-verification workflow reinforced corroboration over detector verdicts. Saturday's tools extended the same principle into provenance and archive infrastructure. Maritime traffic data supplied the final warning: what a sensor can see is not the whole physical universe.

Editorial frame

What this is: A Sunday weekly magazine that develops the strongest signals from the week's Daily Signal issues and Saturday Tool Radar into seven editorial sections with practical evidence models, publication limits and a reading list.

What this is not: A mechanical merge of daily cards, a breaking-news feed, a live-targeting board, a tool-generated verdict, a replacement for forensic or judicial findings, or permission to access sensitive systems or personal data.

Rubric map

📡 Signal of the Week / Головний сигнал тижня
🇺🇦 Ukraine Lens / Українська оптика
⚖️ War Crimes Verification / Верифікація воєнних злочинів
🕯️ Losses, Captivity & Missing / Втрати, полон, зниклі
🧰 Tradecraft / Методика
🛠️ Tools / Datasets / Інструменти й набори даних
⚠️ Risk Watch / Межі й ризики

Editorial note

The durable pattern this week is an evidence ladder. Observation should not silently become attribution; attribution should not silently become individual guilt; a database count should not become prevalence; an advocacy mechanism should not become an outcome; metadata should not become authenticity; a forensic flag should not become proof; and a sensor-visible count should not become a census. The practical response is versioned, append-only analysis: preserve each source, timestamp, claim, denominator, method and upgrade event separately. That makes later correction possible without rewriting history.

📡 Signal of the Week Головний сигнал тижня
#01

Leipzig shows what a real evidence-state transition looks like: pending attribution became formal attribution, not judicial proof

Reuters · 30 August 2026; Associated Press · 1 September 2026

What happened

At the start of the week, Germany was finalising its investigation into the explosives-laden drone found near a Ukrainian Antonov aircraft at Leipzig/Halle airport and had not publicly named a perpetrator. Germany then formally blamed Russia for the attempted August 4 attack and announced countermeasures, including closure of the Russian consulate in Bonn and the Russian House in Berlin. Moscow denied involvement.

Why it matters

This is exactly why an evidence record should be versioned rather than overwritten. The later government attribution is a material upgrade, but it does not retroactively make the earlier pending state formal and does not itself establish individual criminal responsibility in court.

How to use it

Keep separate dated fields for incident, physical evidence, investigative status, media attribution, official attribution, stated basis, denial, diplomatic response and any later judicial findings. Never collapse the ladder into a single 'confirmed' flag.

Limits

The German government's attribution is an authoritative state assessment, not a public judicial finding. The public record does not expose all underlying intelligence or forensic material.

Лейпциг показав справжній перехід доказового стану: очікувана атрибуція стала формальною, але не судовим доведенням

Reuters · 30 серпня 2026; Associated Press · 1 вересня 2026

Що сталося

На початку тижня Німеччина завершувала розслідування щодо дрона з вибухівкою, знайденого поблизу українського літака Antonov в аеропорту Лейпциг/Галле, і публічно не називала виконавця. Згодом Німеччина формально поклала на Росію відповідальність за спробу атаки 4 серпня й оголосила заходи у відповідь, зокрема закриття російського консульства в Бонні та Російського дому в Берліні. Москва заперечила причетність.

Чому це важливо

Саме тому доказовий запис треба версіонувати, а не переписувати. Подальша державна атрибуція є суттєвим підвищенням статусу, але вона не робить попередній невизначений стан формальним заднім числом і сама по собі не встановлює індивідуальної кримінальної відповідальності в суді.

Як це застосувати

Окремо й із датами зберігайте інцидент, фізичні докази, стан розслідування, атрибуцію в медіа, офіційну атрибуцію, заявлену основу, заперечення, дипломатичну відповідь і можливі подальші судові висновки. Не стискайте всю драбину до одного прапорця «підтверджено».

Обмеження

Атрибуція німецького уряду є авторитетною державною оцінкою, але не публічним судовим висновком. У відкритому доступі немає всього розвідувального чи криміналістичного матеріалу, на якому вона ґрунтується.

weeklyattributionstate-transitionleipzighybrid-threat
🇺🇦 Ukraine Lens Українська оптика
#02

The SBU-HUR clash is a claim-ledger problem: competing accounts, procedural actions and responsibility must stay separate

Reuters · 3 September 2026

What happened

President Volodymyr Zelenskyy said an investigation was underway after a dispute between the SBU Security Service and HUR military intelligence escalated into a shootout in Kyiv that injured three HUR members. The episode was connected to the disappearance of a Russian nationalist activist fighting for Ukraine. The activist and the SBU gave competing accounts of his detention and the alleged security threat. Two servicemen received notices of suspicion.

Why it matters

Accountability reporting becomes unreliable when a participant's allegation, an agency account, a notice of suspicion, an internal investigation, prosecution and a court finding are treated as one state. This case makes the separation unusually visible.

How to use it

Build a claim ledger with one row per speaker, allegation and procedural step. Preserve retractions and contradictions. Add responsibility only when the competent process establishes it rather than inferring it from institutional confidence or suspicion notices.

Limits

The public record is still developing. Reuters did not establish the truth of the activist's allegations or the SBU's account of the alleged plot.

Конфлікт СБУ та ГУР — це задача для реєстру тверджень: взаємовиключні версії, процесуальні дії та відповідальність треба розділяти

Reuters · 3 вересня 2026

Що сталося

Президент Володимир Зеленський повідомив про розслідування після того, як конфлікт між СБУ та ГУР переріс у стрілянину в Києві, внаслідок якої були поранені троє співробітників ГУР. Епізод був пов'язаний зі зникненням російського націоналістичного активіста, який воює на боці України. Активіст і СБУ дали взаємовиключні версії його затримання та ймовірної загрози безпеці. Двом військовослужбовцям повідомили про підозру.

Чому це важливо

Матеріали про відповідальність стають ненадійними, коли твердження учасника, версію відомства, повідомлення про підозру, внутрішнє розслідування, обвинувачення та судовий висновок подають як один стан. У цій справі потреба в розділенні особливо очевидна.

Як це застосувати

Ведіть реєстр тверджень: окремий рядок для кожного джерела, версії та процесуального кроку. Зберігайте відмови від заяв і суперечності. Відповідальність додавайте лише тоді, коли її встановлює компетентна процедура, а не коли відомство впевнене у своїй версії чи комусь повідомлено про підозру.

Обмеження

Публічний запис ще формується. Reuters не встановило істинність ані тверджень активіста, ані версії СБУ щодо ймовірного плану.

weeklyukraineaccountabilityclaim-ledgerinvestigation-status
⚖️ War Crimes Verification Верифікація воєнних злочинів
#03

T4P's live database makes its own denominator warning explicit: documented probable war crimes are a lower bound, not the full universe

Tribunal for Putin · live statistics checked 6 September 2026

What happened

T4P's live statistics describe one of Ukraine's largest public collections of probable war-crime incidents. On September 6 the site continued to publish regional and category counts while explicitly stating that the database is neither complete nor final and that the true total for some crimes is almost certainly higher than the documented count.

Why it matters

Documented incidents, unique events, victim counts, legal classifications and estimated prevalence have different denominators. A database can be exceptionally valuable without being a census.

How to use it

Attach snapshot date, geography, category definition, incident/victim unit and the database's completeness caveat to every exported statistic. Treat changes between snapshots as changes in the documented corpus unless independent evidence supports a claim about real-world incidence.

Limits

Coverage depends on access, reporting, documentation capacity, deduplication and legal coding. Categories can overlap, and live totals change as the corpus is updated.

Поточна база T4P сама формулює застереження про знаменник: задокументовані ймовірні воєнні злочини — нижня межа, а не повна сукупність

Tribunal for Putin · поточну статистику перевірено 6 вересня 2026

Що сталося

Поточна статистика T4P описує один із найбільших публічних масивів даних про події ймовірних воєнних злочинів в Україні. 6 вересня сайт продовжував публікувати регіональні та категорійні підрахунки й прямо зазначав, що база не є повною чи остаточною, а реальна кількість деяких злочинів майже напевно перевищує задокументовану.

Чому це важливо

Задокументовані записи, унікальні події, кількість потерпілих, правові кваліфікації та оцінка поширеності мають різні знаменники. База може мати надзвичайну цінність, не будучи повним переписом.

Як це застосувати

До кожної експортованої цифри додавайте дату зрізу, географію, визначення категорії, одиницю підрахунку — події чи потерпілі — та застереження бази щодо неповноти. Зміну між зрізами вважайте передусім зміною задокументованого масиву, якщо незалежні докази не дозволяють говорити про зміну реальної поширеності.

Обмеження

Охоплення залежить від доступу, повідомлень, спроможності документувати, усунення дублів і правової класифікації. Категорії можуть перетинатися, а поточні цифри змінюються разом з оновленням масиву.

weeklywar-crimesdocumentationdenominatorpublic-data
🕯️ Losses, Captivity & Missing Втрати, полон, зниклі
#04

Bring Kids Back UA highlights a case-state ladder: verified information and advocacy are not the same as locating or returning a child

Verkhovna Rada of Ukraine · 3 September 2026

What happened

The Verkhovna Rada and the presidential Bring Kids Back UA initiative launched expert briefings for MPs on deportation, forced transfer and other crimes against Ukrainian children. The stated goal is a permanent platform providing verified data, legal assessments, current analysis and tailored material for parliamentary work with international partners.

Why it matters

A verified case record, advocacy action, international contact, located child, agreed return channel and completed return are distinct states. Mixing them can inflate outcome claims and can also expose sensitive child-level information.

How to use it

Maintain child-level case states separately from aggregate advocacy products. Publish only the minimum information required for public interest, and keep location, family and negotiation details restricted unless safe and necessary.

Limits

The parliamentary announcement describes an information and advocacy platform. It does not provide a new verified total of deported, located or returned children and should not be used to infer one.

Bring Kids Back UA показує драбину станів справи: перевірені дані й адвокація не тотожні встановленню місцеперебування чи поверненню дитини

Верховна Рада України · 3 вересня 2026

Що сталося

Верховна Рада та президентська ініціатива Bring Kids Back UA розпочали експертні зустрічі для депутатів щодо депортації, примусового переміщення та інших злочинів проти українських дітей. Заявлена мета — постійна платформа з перевіреними даними, юридичними оцінками, актуальною аналітикою та підготовленими матеріалами для роботи парламенту з міжнародними партнерами.

Чому це важливо

Перевірений запис справи, адвокаційна дія, міжнародний контакт, встановлення місцеперебування дитини, погоджений канал повернення та завершене повернення — різні стани. Їх змішування може завищувати показники результату й водночас розкривати чутливі дані на рівні конкретної дитини.

Як це застосувати

Ведіть стани конкретних справ окремо від агрегованих адвокаційних матеріалів. Публікуйте лише мінімум інформації, потрібний у суспільних інтересах, а місцеперебування, дані родини та деталі переговорів обмежуйте, якщо їх розкриття не є безпечним і необхідним.

Обмеження

Парламентське повідомлення описує інформаційно-адвокаційну платформу. Воно не містить нової перевіреної загальної кількості депортованих, знайдених або повернутих дітей, і таку цифру з нього не слід виводити.

weeklychildrenreturncase-statusdata-minimisation
🧰 Tradecraft Методика
#05

Reuters' visual-verification workflow is strongest as a sequence of corroboration, not a detector stack

Reuters · 28 August 2026

What happened

Reuters described how its visual-verification team checks user-generated imagery by contacting or assessing creators, inspecting metadata, geolocating scenes, comparing weather and satellite data and using AI-detection tools among other signals. The workflow is designed to corroborate authenticity and context rather than outsource judgment to one automated score.

Why it matters

Each method answers a different question. Creator contact speaks to source history; metadata to embedded claims; geolocation to place; satellite and weather to external consistency; detectors to possible anomalies. Agreement among independent layers is more informative than confidence from one layer.

How to use it

Write the verification record as a matrix: claim, method, source, result, contradiction and residual uncertainty. Preserve negative results too. A failed reverse search or missing metadata is not evidence of fakery.

Limits

Verification quality depends on the available source material and independent reference data. AI detectors are imperfect, metadata can be stripped or altered, and source contact can itself be deceptive.

Методика візуальної верифікації Reuters найсильніша як послідовність взаємного підтвердження, а не набір детекторів

Reuters · 28 серпня 2026

Що сталося

Reuters описало роботу своєї команди з верифікації користувацьких зображень: перевірка автора, аналіз метаданих, геолокація сцени, порівняння погодних і супутникових даних та використання засобів виявлення ШІ серед інших ознак. Робочий процес побудований на взаємному підтвердженні автентичності й контексту, а не на передачі рішення одному автоматичному показнику.

Чому це важливо

Кожен метод відповідає на інше питання. Перевірка автора стосується історії джерела; метадані — вбудованих тверджень; геолокація — місця; супутникові й погодні дані — зовнішньої узгодженості; детектори — можливих аномалій. Збіг незалежних шарів інформативніший за впевненість одного шару.

Як це застосувати

Оформлюйте перевірку як матрицю: твердження, метод, джерело, результат, суперечність і залишкова невизначеність. Зберігайте й негативні результати. Невдалий зворотний пошук або відсутність метаданих не є доказом підробки.

Обмеження

Якість перевірки залежить від доступного вихідного матеріалу та незалежних довідкових даних. Детектори ШІ помиляються, метадані можна видалити чи змінити, а контакт із джерелом сам може бути оманливим.

weeklytradecraftvisual-verificationcorroborationprovenance
🛠️ Tools / Datasets Інструменти й набори даних
#06

ChronoVerify and Metawarc point to the same architecture: keep source objects, integrity facts and analytical layers separate

ChronoVerify; ruarxive / Metawarc · official documentation checked 5–6 September 2026

What happened

ChronoVerify separates reproducible file-integrity and provenance information from probabilistic metadata and pixel-forensics signals, explicitly treating anomaly verdicts as triage. Metawarc 2.0 indexes immutable WARC collections into a versioned DuckDB catalogue with bounded querying, metadata extraction, hashes and controlled exports instead of rewriting the source archives.

Why it matters

Together they model a defensible evidence stack: immutable source → hash/provenance layer → derived catalogue or forensic signals → human interpretation → publication derivative. Errors in one layer do not need to contaminate the others.

How to use it

Preserve evidentiary masters read-only, hash them before analysis, record tool and method versions, keep derived databases rebuildable, and store analyst conclusions separately from machine outputs. For sensitive material, assess processing and confidentiality before sending files to any external service.

Limits

A valid hash proves file identity, not truth. C2PA proves what a valid signer asserted, not that a depicted event occurred. A WARC catalogue improves analysis but inherits the provenance limits of the original capture.

ChronoVerify і Metawarc підводять до однієї архітектури: відокремлюйте вихідні об'єкти, факти цілісності та аналітичні шари

ChronoVerify; ruarxive / Metawarc · офіційну документацію перевірено 5–6 вересня 2026

Що сталося

ChronoVerify розділяє відтворювані дані про цілісність і походження файла та ймовірнісні сигнали з метаданих і піксельного аналізу, прямо визначаючи аномальні результати як первинну перевірку. Metawarc 2.0 індексує незмінні WARC-колекції у версійований каталог DuckDB із контрольованими запитами, вилученням метаданих, контрольними сумами та керованим експортом замість переписування вихідних архівів.

Чому це важливо

Разом вони утворюють захищувану доказову модель: незмінне джерело → шар контрольних сум і походження → похідний каталог або криміналістичні сигнали → людська інтерпретація → публікаційна версія. Помилка одного шару не повинна заражати інші.

Як це застосувати

Зберігайте доказові оригінали лише для читання, хешуйте їх до аналізу, фіксуйте версії інструментів і методик, робіть похідні бази відтворюваними, а висновки аналітика зберігайте окремо від машинних результатів. Для чутливих матеріалів оцінюйте спосіб обробки й конфіденційність до передавання файлів будь-якому зовнішньому сервісу.

Обмеження

Коректна контрольна сума доводить тотожність файла, а не істинність його змісту. C2PA підтверджує те, що заявив валідний підписант, а не факт зображеної події. Каталог WARC покращує аналіз, але успадковує обмеження походження початкового збереження.

weeklytoolsprovenancewarcevidence-architecture
⚠️ Risk Watch Межі й ризики
#07

The observable universe is not the physical universe: AIS traffic makes the coverage problem impossible to ignore

Reuters / Kpler · 4 September 2026

What happened

Reuters reported Kpler data showing four commodity vessels transited the Strait of Hormuz on Thursday compared with a 10-day average of 15. Reuters explicitly noted that the count excluded ships operating with Automatic Identification System transponders switched off.

Why it matters

The lesson generalises far beyond maritime OSINT. Platform search results, satellite revisit windows, mobile-phone traces, sanctions databases and casualty datasets all observe subsets shaped by coverage, behaviour and collection rules.

How to use it

For every quantitative OSINT claim, write down the observation mechanism, inclusion rules, blind spots, comparison baseline and denominator. Phrase conclusions as claims about the observed system unless you have a defensible model for the unseen portion.

Limits

The Kpler count itself is provider-dependent and excludes AIS-dark vessels. It is a measurement-boundary example, not a complete account of all physical movement through Hormuz.

Спостережувана сукупність не дорівнює фізичній: дані AIS роблять проблему покриття неможливою для ігнорування

Reuters / Kpler · 4 вересня 2026

Що сталося

Reuters повідомило, що за даними Kpler у четвер Ормузькою протокою пройшли чотири товарні судна проти середнього показника 15 за попередні десять днів. Reuters прямо зазначило, що до підрахунку не входили судна з вимкненими транспондерами Автоматичної ідентифікаційної системи.

Чому це важливо

Цей урок значно ширший за морську розвідку з відкритих джерел. Пошук на платформах, періодичність супутникового знімання, сліди мобільних телефонів, санкційні бази та дані про втрати завжди бачать лише підмножини, сформовані покриттям, поведінкою та правилами збору.

Як це застосувати

Для кожного кількісного висновку з відкритих джерел записуйте механізм спостереження, правила включення, сліпі зони, базу порівняння та знаменник. Формулюйте висновок про спостережувану систему, якщо у вас немає обґрунтованої моделі невидимої частини.

Обмеження

Сам підрахунок Kpler залежить від покриття постачальника й не охоплює судна з вимкненим AIS. Це приклад меж вимірювання, а не повний опис усіх фізичних переходів через Ормузьку протоку.

weeklyrisk-watchcoverageaisdenominator
📌Evidence model

Version states; do not overwrite them

  • Observation → attribution → legal responsibility are separate upgrades.
  • Preserve the timestamp and source that justified each transition.
  • A later confirmation does not erase the uncertainty of the earlier record.
🧪Weekly workflow

Record the denominator before the number

  • Define what is counted: incidents, victims, vessels, records or unique entities.
  • Store coverage and exclusion rules beside every quantitative claim.
  • Treat live-database growth as corpus growth unless real-world incidence is independently established.
🛡️Safety line

Keep the evidentiary master separate

  • Use read-only originals and hashed masters before analysis or redaction.
  • Publish derivatives with only the minimum personal or operational detail required.
  • External tool privacy claims do not remove the need for a confidentiality assessment.

Reading List