Nathan Patin

@nathanpatin.bsky.social

digital investigator // former @Bellingcat member // former adjunct at Georgetown // https://signal.me/#eu/NgJup15Ma2qMeT4LrMxTSoEjms9VQWtnut6sXW7CNidB5gEkzXJKlKpHsGXzQ9Eq

NEW: A PR firm used at least 15 fake personas — equipped with fake emails, fake websites, and in some cases, fake AI-generated faces — to send me dozens of pitch emails about its (very real) clients. Those clients told me they had no idea this was happening. futurism.com/artificial-i...

We Are Alarmed by This PR Firm Using a Small Army of Fake AI-Powered Publicists to Barrage Journalists With Pitches for Its Clients

A PR firm called Movchan Agency operated a roster of fake PR representatives, some with AI faces, to pitch journalists on stories. Why?

futurism.com

Scam researchers told a Claude agent and human "scammers" to text test subjects and build a relationship. After a week, subjects said they trusted the AI more than the human and almost half were willing to install an app at its request. Almost none detected it was AI. www.wired.com/story/ai-sca...

AI Scammers Are Better at Building Trust Than Humans

Researchers pitted a person against a Claude agent and found that, after a week of texting, the AI chatbot was more effective at creating “exploitable trust” with others.

wired.com

The FIFA World Cup was predicted to be the biggest betting event in history. Bellingcat researcher @msramalho.bsky.social looked into the data on prediction markets Polymarket and Kalshi - and found that fans wagered more than US $14 billion through the two sites www.bellingcat.com/news/2026/07...

Will Ronaldo Cry​? World Cup Fans Bet Billions Through Prediction Markets - bellingcat

Users traded on almost 60,000 outcomes, betting on everything from the sponsor of the Golden Boot winner to whether Cristiano Ronaldo would shed a tear during a Portugal match.

bellingcat.com

More than 30 water systems in Minnesota have been hit in what officials call a “coordinated cyberattack.” One said the hacking shared characteristics with those that federal agencies have been warning against — shortly after federal alerts about Iranian hacking. www.reuters.com/legal/litiga...

Minnesota IT officials disclose 'coordinated cyberattack' at more than 30 local water systems

A "coordinated cyberattack" targeted more than 30 ‌community water systems in the U.S. state of Minnesota on July 26 and July 27, the state's IT agency said in a statement.

reuters.com

“A capable human attacker could have found and exploited the same flaws […] The agent explored them at a different scale. It took 17,600 actions,” requiring Hugging Face to spin up an AI-assisted pipeline of their own to reconstruct and investigate the cyberattack huggingface.co/blog/agent-i...

Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident

We’re on a journey to advance and democratize artificial intelligence through open source and open science.

huggingface.co

3 sources on weird OpenAI LLM behavior before the Hugging Face incident: “an agent left notes apparently for future versions of itself […] The ‌notes, found in ⁠a part of OpenAI's infrastructure, laid out instructions for how agents could free themselves from OpenAI’s internal constraints.”

Raphael Satter@raphae.li · 2w ago

Scoop: Its AI agent spent days breaking into the systems of Hugging Face, but sources tell @deepa.bsky.social, @kenrick.bsky.social & me OpenAI did not even realize it was responsible for the hack for more than a week. www.reuters.com/business/its...

NEW: I spoke to several offensive cybersecurity researchers, including zero-day developers, about how the guardrails imposed by OpenAI and Anthropic on AI models are impeding their work. Most complained the guardrails are inconsistent and too strict, which pushes them to use open source models.

How AI guardrails are impeding the work of offensive cybersecurity researchers | TechCrunch

We spoke with several cybersecurity researchers, who look for unknown vulnerabilities and develop tools to exploit them, about how OpenAI’s and Anthropic’s guardrails affect their work.

techcrunch.com

New publication from me! 🎉 Please check out my latest investigation where we identify (no surprise) a crypto guy to a popular 'leaked' nudes website. Users could even get paid out for sharing leaked/hacked nudes from women. Within 48 hrs of reaching out to him, the site went offline. Impact! 🙌

Bellingcat@bellingcat.com · 3w ago

Bellingcat and @thepress.co.nz have uncovered a series of links between a New Zealand-based man and the adult forum LeakedBB – a site with over 2.3 million registered users, including some who distributed leaked nude photos and videos. www.bellingcat.com/news/2026/07...

Just used Opus 4.8 (High effort) to tally a list and it summed it incorrectly 😃 It even provided a correct tally for each item; copy/pasted that into Excel and sure enough it was 1 off

Opus 4.8 can't add

New: Our visual analysis of the ICE shooting in Maine, from the available video and audio available. There is no footage showing the shooting itself, but we obtained audio near the scene from immediately before the vehicle rolled into an intersection. 🎁 Free Gift Link www.nytimes.com/2026/07/14/u...