Category Archives: Security

Russian Fingerprints on the Manufactured Ceuta Crisis

Two weeks ago, on the anniversary, I posted the mechanism of the 1953 Tehran coup: buy the press, hire one mob to riot in the government’s name, hire a second mob to attack the first, and let the resulting chaos prove the government has lost control.

Think about everyone in the street being paid by the same source to whip up attention. The modern-day Ceuta crisis in Spain had been running in the news for twenty days when I posted the history of Iran. And then today I read a Spanish police report.

On 30 July 2026 a crowd that had been mobilised to look spontaneous walked into Ceuta and a government began to fall. Ok, but 19 August 1953 was when a crowd paid to look spontaneous walked through Tehran and a government fell. Every visible actor in Tehran was Iranian. It took sixty years for the authors to admit they were in Washington and London. The Spanish Prime Minister, three days ago, named Russia and Israel within five weeks. He is being destroyed for it by people who have read as far as the uniforms.

Red Hot PDF

The Centro Nacional de Inmigración y Fronteras (CENIF), the intelligence unit of the National Police’s immigration and borders directorate, prepared a 55-page report at the request of Plaza 3 of the Central Instruction Court at the Audiencia Nacional, Judge María Tardón. The data goes until 26 August. Demócrata has published it as a PDF. I have read it. The 61-page technical annex on the digital organisation, the ten dossiers on uniformed officers and the 24 on plainclothes handlers, and the four videos are listed but not released.

Here are the findings, in the order made by the report.

  1. The entry was a process, not an event. The report refuses to analyse 30 and 31 July except as a procedure with a before, a during and an after, and states flatly:

    No se trata de algo incidental cuya generación pueda asociarse a un factor ocasional o espontáneo.

  2. The crowd was not migrating. Of those who entered, no fewer than 90 percent returned to Morocco voluntarily and almost immediately; the report puts migratory intent at five to ten percent. Nearly all were Moroccan nationals. They moved, in the report’s words, with relative calm, no crushes, no bottlenecks, conveying a sense of impunity, as a movement free of any consequence, and that perception was probably reinforced by what the report calls the “almost active” tolerance of the Moroccan security forces. Migration, the conclusions say, operated only as a formal cover.
  3. The mobilisation was built. Open platforms first, Facebook, Instagram, TikTok, from 24 July; then closed WhatsApp groups on 29 and 30 July with operational instructions, including the advice that each group communicate by handwritten note rather than online because the internet was monitored. The message count in monitored groups peaked at 1,974 on 30 July, a 3,363 percent increase over the maximum before the 28th. Three distortions gave it credibility: Supreme Court judgment 814/2026 on border rejections, reduced to the viral line “if you enter swimming they can’t return you”; Spain’s closed extraordinary regularisation, reduced to “in Spain you get papers in the end”; and Throne Day. The report reproduces an Arabic poster with Pedro Sánchez’s face on it announcing 30 July 2026 as the last deadline before Spain closes the door on regularisation. The Prime Minister was the bait.
  4. Throne Day was the cover. The official ceremonies were held at Rincón/M’Diq, a few kilometres from the border, with the King, the establishment and foreign guests present. The report reads the choice of date two ways: it seeded the message that the security forces were busy with the royal protection detail and the frontier was unguarded, and the King’s proximity carried what the report calls a “tacit consent” that implicitly accompanied the viral campaign. A message circulating in the days before: “There will be attacks from the sea and from El Kriay, through the forest and by Bab Khemis, on the occasion of Throne Day.”
  5. The Moroccan cordon stood down. Satellite imagery at 17:07 on 30 July shows police presence confined to the entrance of the official crossing; none on the beach access, the breakwater, or the roads and roundabouts from Castillejos to El Tarajal; taxis parked in order on the left of the Bab Sebta roundabout; the main routes open while a crowd accumulated on the beach and the roads. The report calls the Moroccan police response over 30 and 31 July “at the very least, total permissiveness”: not a single serious attempt to reduce, disperse or move the crowd from the perimeter on the 30th. Interviewed migrants say, almost unanimously, that Moroccan officers were not merely passive but gave directions to enter through the water at the breakwater and not by other routes. Open-source video shows uniformed officers directing people toward predetermined access points and organising heavy vehicles carrying large numbers of people, and non-uniformed individuals managing the flow, in some cases giving instructions to the uniformed officers. That video is titled “Ceuta_Agentes_Dinamizadores” in the annex.
  6. The crowd was sequenced. First wave to 11:00: males 15 to 25, high proportion of minors, 95 to 98 percent Moroccan, equipped with wetsuits, fins, floats and waterproof phone cases. Second wave 11:00 to 22:00: adults to 40, whole families, small children at 18 to 25 percent, sub-Saharans at 20 to 25 percent, in sportswear and flip-flops, no equipment. Third wave from 22:00 through the 31st: the first profile again. The report assigns the two phases explicit tactical objectives. First, collapse the border management system at one point in one way, diverting Spanish capacity to sea rescue while saturating the reception yard. Second, once the yard gate was opened, eliminate Spain’s capacity to respond, because a notable presence of families, women and small children “deactivates the possibility of using coercive means or reactive force to re-establish control.” The report considers 75,000 to 85,000 people reaching a single point without road blockages, transport failures or public-order incidents “incompatible with a group of spontaneous origin, with no internal organisation, and no minimum support of directed organisation on the ground.”
  7. The mafias couldn’t have done it. CENIF ran the five known maritime smuggling organisations and the four to six Ceuta narco groups through Europol’s SOCTA criteria. One smuggling group operates in Ceuta, with capacity for three to five people a day. Since January 2024: 2,983 operations, 1,822 arrests, and “not a single reference to these organisations encouraging the mobilisation.” They had never had the capacity to summon 75,000 people even at peak strength in 2021 to 2023, and the operation made them no money: the only detectable reaction was opportunistic, about 150 people moved to the mainland by 24 August at a discounted €5,000 a head.
  8. The state that could stop it, did. On 15 August a second call went out, more visible and earlier than the first, without the “unique opportunity” framing, directed at the fence rather than the water, and answered by an almost exclusively sub-Saharan crowd. Morocco detained 294, 248 of them sub-Saharan, allowed nothing to reach the fence, and expelled the Spanish press from the area. The report:

    Es decir, parece que asistimos a un proceso “manejado” de forma que una segunda convocatoria artificialmente más detectable se convierta en un ejercicio de control que “blanquee” la gestión precedente de la respuesta de las Fuerzas y Cuerpos de Seguridad.

    The report describes the whole as “actions of calculated ambiguity and gradual advance with intermittent activity,” which it identifies as the signature of grey-zone strategy, projected “not on Morocco but on Spain and the international community.”

  9. The author is unnamed by design. CENIF describes five levels, from the crossers up through message dynamisers, on-ground organisers and planners to direction, and states that Level 5 could not be individualised by the delivery date, while noting that “the basis of its conception seeks the concealment of authorship.” Eighty-two bodies were recovered in Spanish waters, by telephone note from the Ceuta Instituto de Medicina Legal on 26 August. Morocco acknowledged fourteen.

The Formula

The CIA’s internal history of Iran, obtained under FOIA and published by the National Security Archive in 2013, states:

The military coup that overthrew Mosadeq and his National Front cabinet was carried out under CIA direction as an act of U.S. foreign policy, conceived and approved at the highest levels of government.

The operational record is Donald Wilber’s 1954 after-action report, Overthrow of Premier Mossadeq of Iran, written as an eyes-only handbook for future operations and leaked to the New York Times in 2000. The State Department’s 2017 retrospective FRUS volume supplies the NSC and CIA files around it. Read together they describe a method.

Disinformation is built on a grain of truth, which can be any real grievance.

Iran’s Mossadeq had dissolved the Majlis by referendum; the propaganda campaign Wilber ran through paid Tehran newspapers turned a constitutional dispute into a story about a dictator in league with communists, with some of the articles written in Washington and placed in Tehran. Crowds purchased in advance and released on cue, through people who controlled the protection rackets. A first mob sent out shouting for Mossadeq and for communism, to frighten the middle class and the army. A second mob hired to attack the first. Handlers on the ground coordinating by phone while Kermit Roosevelt ran it from inside the embassy compound. And afterwards, a story of spontaneous national uprising that the authoring state defended for six decades, including a 1989 FRUS volume that historians called a fraud for omitting the operation entirely.

Map it to Tarajal.

Real grievance: a Supreme Court judgment, distorted into a slogan, with the target’s own Prime Minister on the poster. Crowds assembled in advance: 80,000 people arriving in taxis on clear roads. A first mob to produce the crisis: young men with fins to exhaust containment, then children to disarm it. Handlers: 24 dossiers and ten uniformed fiches, and video of the plainclothes men instructing the uniforms. And then the second mob. On 15 August the call went out again, louder, and the same security forces that had stood back on 30 July detained 294 people and closed the border. CENIF calls the second call artificially detectable and its function laundering. Roosevelt would have called it the second crowd: the same source producing the chaos and then producing the order, so that the target government is seen to have lost control and the neighbour is seen to have it.

The report’s own comparison table shows the method being refined.

May 2021 Aug–Sep 2024 Jul 2026
Moroccan presence before Reduced Increased Reduced
Response during Permissive Containment Permissive
Entries ~10,000 1,000–2,000 75,000–85,000
Follow-up call None 15 Sep, 3,795 arrests 15 Aug, 294 arrests
Second-call outcome Absolute control Absolute control

Wilber wrote his history as a handbook. This one has been through three editions.

The crowd of 30 July and the cordon of 15 August answered to the same direction. That is the finding.

And the lesson of 1953 is what the finding does not settle. Nobody in the streets of Tehran was American. The Iranian police turned, the Iranian mobs marched, the Iranian papers printed. Reading the uniforms tells you who executed. It never tells you who authored, and it never will, because the method is designed so that it won’t. The report says so about Ceuta in its own words: the basis of its conception seeks the concealment of authorship.

The Call

On 31 August Pedro Sánchez told Cadena Ser that after 30 and 31 July, disinformation had spread on networks tied to Russia, Israel and an international far right that uses migration to attack Spain and Europe, and that Morocco had neither conceived nor executed the entry. The second half of that is where he is vulnerable, and I come to it below. The first half is the correct reading of a hybrid operation, and it is the reading his critics refuse to make.

Start with the category. When Belarus moved people to the Polish and Lithuanian borders in 2021 and Russia moved them to Finland’s in 2023, the Council and Commission named the method: instrumentalisation of migration, a third state moving bodies to an EU frontier while Russian channels amplify the collapse. The signature of that method is not a Russian in the street. It is state-attributable amplification at hour zero. EUvsDisinfo exists because of it. Sánchez was invoking a category the European Union had already defined against Moscow.

Then the finding. The EEAS confirmed Russian attempts to exploit the crisis online. The Commission had said on 6 August that the actors were Russian state media, diplomatic channels and government-sponsored outlets, amplifying across multiple platforms from 30 July. Diplomatic channels means embassy and ministry accounts. That is the Russian state acting under its own flag during the crisis, not a proxy. Brussels added that it saw no Russian activity before the 30th, and the Spanish right ran that caveat as an acquittal. It is the opposite. In an instrumentalisation campaign, arriving at hour zero with prepared assets is the participation.

Then the escalation. Three weeks into the crisis a pro-Russian group, NoName057, whose named leaker is a teacher wanted by the Audiencia Nacional, living in Russia under Kremlin protection and on Europol’s most-wanted list, published a 500-page file of names, photographs and phone numbers of around a thousand Spanish police, Guardia Civil and military personnel. Spanish intelligence attributes it; JUCIL has it before the Audiencia Nacional. In the same window an anonymous account calling itself The Political Room announced a mysterious 120-page CNI report whose only takeaway was that the CNI had monitored Moroccan networks and must have warned. Nobody has produced it; Demócrata could not verify it exists. CENIF’s final conclusion calls the resulting assault on the CNI a textbook offensive counterintelligence action. Doxxing the responding forces and discrediting the intelligence service are not commentary on a border incident. They are the second mob.

Then Israel. Its UN ambassador, on day two, asked why Spain still maintains colonial enclaves in Africa. Its foreign minister called the Spanish Prime Minister a liar. Its defence industry built the eyes over the border: Barak MX in 2022, Heron drones, a billion-dollar IAI reconnaissance satellite in 2024, Elbit artillery in 2025, a joint military committee with Rabat that met in Tel Aviv in January. The EEAS found only isolated accounts on the Israeli side, and that is fair as a finding about bots. It is not a finding about a state whose officials joined the operation in their own names.

Then alignment. Moscow signed its Deepened Strategic Partnership with the King in 2016 and, last October, a new joint committee with Bourita, the same week Lavrov signalled acceptance of Morocco’s autonomy plan, and Russia then abstained rather than block Resolution 2797. Washington drafted 2797, recognised Moroccan Sahara in 2020 as the price of Israel’s normalisation, and reaffirmed it on Throne Day, the day the crossing began. Delhi opened India’s first overseas defence plant outside Casablanca last September. Starlink signed Royal Air Maroc on 4 August. Rabat ran this in the knowledge that every state with leverage over it had already taken its side of the Sahara question, and two of them would join in.

The report’s phone sample is the evidence the critics wave. Ninety point eight percent Moroccan prefixes among the lines that dynamised the call; of the rest, Algeria under three percent of the whole, and no Russian, Israeli or American lines anywhere in the enumeration. That is proof of who executed. Wilber’s Tehran newspapers were Iranian too. The report’s own after-phase section lists the Moroccan counter-narratives that followed the crossing, the “mafias” story in ABC and the “Algerian prefixes” story in La Razón among them, as products of the operation. Russia and Israel are not in that list because Morocco did not invent them. Europe’s diplomatic service did.

One caution on the report’s own sourcing. Its claim that the campaign followed a pre-established viral design model is footnoted to a marketing-school blog post on the K-factor and attributed loosely to Harvard Business School. The inference that the message pattern was engineered rests on the message-volume curve and the platform sequencing, which the report does document. Thankfully it doesn’t mention my 2012 BSidesLV presentation where I predicted this.

The Phone

On 17 and 18 May 2021 Morocco opened the border and roughly 8,000 people entered Ceuta at El Tarajal. On 18 May Sánchez flew to Ceuta with Marlaska and overflew the frontier by helicopter against security advice. On 19 May, according to The Objective’s reconstruction, Moncloa’s systems detected the extraction of around 2.6 gigabytes from the Prime Minister’s phone by Pegasus. The government sat on it for a year. The judicial inquiry later counted fourteen attacks: five on Sánchez, four on Robles, two on Marlaska, who lost over six gigabytes, and one attempt on Planas. The Defence Ministry reset Robles’s phone before it could be examined. Judge Calama shelved the case.

On 14 March 2022 Sánchez wrote to Mohammed VI accepting the Moroccan autonomy plan for Western Sahara, reversing half a century of Spanish policy without informing his coalition partner or Parliament. Asked in Parliament this May whether Pegasus has ever been raised with Rabat, the government answered that the matter does not form part of bilateral relations.

This summer an Algerian-flagged hacker persona, Jabaroot, published the identities of some 70,000 Moroccan intelligence personnel and asked its Telegram forum who was interested in the original Pegasus data relating to Pedro Sánchez. Attribution of the 2021 intrusions to Morocco is not a Spanish judicial finding. It is the working assumption of everyone outside Moncloa, anchored on the French investigation of the Macron intrusions. What was in the 2.6 gigabytes is unknowable. That is the point of it.

The executor of the 2021 Ceuta operation extracted the Prime Minister’s phone during the 2021 Ceuta operation. The Prime Minister then reversed policy in the executor’s favour. In 2026 the executor ran the same operation at ten times the scale and put the Prime Minister’s face on the recruiting poster. This is the half of Sánchez’s statement that fails: Morocco did conceive and execute the crossing, his own police have it on video, and the reason he cannot say so is sitting in Rabat in a 2.6-gigabyte file. That is a fact about leverage. It does not make the other half wrong. A leader who names the states he can name, and names them correctly, is doing more than a leader who names none.

I was Right About Loch Ness in 2012

The CIA denied Ajax for sixty years, because of course. The 1989 FRUS volume omitted it. The 2013 admission came by FOIA and the 2017 volume came after the nuclear deal made it safe. The whole period, the operation’s authorship was an open question where many knew the answer, and the party that had the strongest interest controlled the archive to delay the reveal.

Ceuta keeps the structure. The report says it cannot individualise the top level. The Interior Minister writes to the police director asking since when he knew. The police director replies that no document attributes planning or execution to a government.

The opposition reads the cover of a book (the uniforms) and declares the story ends on Morocco alone, without reading a page inside. They maintain a state in which 80,000 people crossed a European border under the guidance of a neighbouring state’s security forces, 82 bodies came out of the water, two foreign states worked the aftermath under their own flags, and the only person who named those two states is the one they tell to stop talking.

Germany has weathered the same pattern this year and I’ve repeatedly shown Dobrindt making the mistake: treat the flow as the threat, and the state that weaponised it as a rumour. That is what a hybrid operation is built to produce. The correct call is both halves. Rabat moved the people. Moscow moved the story, and Jerusalem signed its name to it. The second half is what turns a border incident into a government crisis, and Sánchez is the one leader in Europe who said the second half out loud.

Somebody read the old handbook, and so did Sánchez.

OpenAI Astra “Secret Technique” Actually a Decade Old

In 1836 Edgar Allan Poe published “Maelzel’s Chess-Player” in the Southern Literary Messenger. Johann Maelzel had been touring the United States with Kempelen’s automaton for a decade, and the American press treated its mechanism as an unsolved marvel. Poe’s essay is remembered as being a remarkable feat of deduction. Instead it was mostly a feat of reading. Brewster’s Letters on Natural Magic had explained the concealed operator in 1832; Racknitz had published his diagrams almost a half century before in 1789.

Kupferstich eines “Schachtürken”

Poe reasoned from what was in print and from what he could watch from the audience: the pattern of the cabinet doors, the operator’s posture, the timing of the moves. The secret was available for anyone who could read. The only new part was someone, a reporter, actually checked.

This is what comes to mind when OpenAI Astra news flies around today.

The Information just published a piece by Amir Efrati, Stephanie Palazzolo and Rocket Drew describing a “secret technique” in OpenAI’s forthcoming model.

How secret is it?

The technique is recurrent depth: a transformer passes its hidden state through the same block of layers more than once before emitting a token, rather than through a fixed stack once. The report’s substantive concern is that computation performed this way is not written out as a chain of thought and is therefore harder to monitor. As someone who builds a harness that specializes in auditing models, Wirken.AI, I’m of course all over this concern.

The architecture is NOT secret. It is public, and has been so a very long time.

The report itself attributes it to “several American and European academic researchers” in a paper published last year. Well, duh, then it can’t be a secret, can it? That is Geiping et al., February 2025, from Tübingen, Maryland and Livermore, presented at NeurIPS 2025 with weights and training code released.

But wait, let’s read farther into the past. Graves, 2016, at DeepMind, introduced adaptive computation time for recurrent networks. Dehghani et al., 2018, at Google Brain, applied it to transformers under the name Universal Transformer. Giannou et al., 2023, supplied the term “looped transformer.”

That’s a decade.

And it’s not like others are unaware. Nanbeige4.2-3B shipped under Apache-2.0 with a technical report dated 27 July 2026, five weeks before the OpenAI story, and a model card stating that its looped transformer architecture reuses layers to increase capacity without adding parameters. The implementation is in the repository’s modeling file.

The Nanbeige card records roughly forty thousand downloads in the past month.

Worst secret ever?

Same firms, prior disclosure

The report also notes that a July 2025 joint statement on chain-of-thought monitorability from OpenAI, Anthropic and Google DeepMind cited the exact Geiping paper. That is Korbak et al., which warned that latent reasoning models might not need to verbalize their thoughts and would lose the safety property that legible chains of thought provide, and recommended that developers document any decision to adopt such an architecture. The technique was therefore identified, by name and under OpenAI’s own authorship, as a monitorability risk fourteen months before the report.

What’s new? OpenAI did it anyway. The ethics are the story.

Anonymous

The technical claims rest on a single unnamed person “with knowledge of Astra’s development“: that recurrence was used in both training and inference, that its use was limited in order to preserve a legible chain of thought, and that the agents involved in the July intrusion into OpenAI’s cluster ran on a related model.

The novelty claim has no source at all.

No document, architecture description or benchmark is cited. The only named technical statement on the record came afterward from OpenAI’s chief scientist, Jakub Pachocki, who said the depth of Astra’s computation graph is within a factor of two of GPT-4’s and that he wished to avoid a race toward unmonitorability driven by confused reporting.

The vendor’s own scientist publicly declined the novelty claim. That is the Anthropic Mythos record scratch again, in mirror image. There the vendor made capability claims nobody outside could verify. Here an anonymous source made claims the vendor’s own scientist rejected on the record. In both cases the reader is left with assertions structured so that investigation ends in access denied.

Falsifiable fluffy advances

The report states that recurrent depth “hasn’t been featured in a major commercially available large language model before.” What is Nanbeige then, mashed potatoes? It is Apache-2.0, built by the lab of a Chinese recruitment platform, serving forty thousand downloads a month through Hugging Face, which by The Information’s own reporting the week before, on the word of another anonymous source, Nvidia has agreed to buy for around $13 billion. Whether that counts as major or commercially available is a weird question. If you take away the OpenAI-is-special-snowflake qualifiers then there’s nothing new here either.

The report frames Astra against the need for a visible technological advance: three cloud providers are spending roughly $600 billion this year on capital expenditure justified by expected model improvements.

Recurrent depth does not support that framing.

The documented effect, in the reporters’ own description, is to let a smaller model perform like a larger one. Geiping’s model is 3.5 billion parameters; Nanbeige’s is 3 billion. Saad-Falcon et al., at Stanford, with Alphabet chairman John Hennessy among the authors, measured in November 2025 that local models answer 88.7% of real single-turn chat and reasoning queries. A technique whose measured contribution is parameter efficiency lands even more evidence of that trend. Capital expenditure, which the report invokes, is the opposite of the trend. The reporters wrote down these facts yet for some reason could not connect the dots.

Known knowns

A decade-old architecture, published in peer-reviewed venues, flagged by the industry’s own safety statement, and shipped in popular open weights, was presented as a secret on the authority of one anonymous source. OpenAI’s chief scientist then disputed the novelty in public. That sequence shows the integrity problem in AI reporting: a claim of novelty was not checked against the prior work the report itself cites.

Leipziger Drohnenanschlag flog wie ein Handy, nachdem Telekom ihren Schild mit Loch ankündigte

English | Deutsch

Diese Geschichte beginnt am 12. Mai 2026, im Vorfeld der AFCEA-Fachmesse in Bonn, als Deutsche Telekom und Rheinmetall einen gemeinsamen Drohnen-Schutzschild für deutsche kritische Infrastruktur ankündigten. Laut Pressemitteilung hatten sie das Detektionsproblem in Teile zerlegt.

Der erste Teil waren die ISM-Bänder bei 2,4 und 5,8 GHz, mit passiven Funkscannern auf Mobilfunkmasten, die Drohnen anhand ihrer Protokollsignatur erkennen. Das wurde als der Schild dargestellt.

Der übrige Teil betraf Flüge über Mobilfunknetze mit einer SIM-Karte an Bord. Die Mitteilung nannte das ein Forschungsfeld, räumte also im Grunde ein Loch im Schild ein, und verwies für den aktuellen Stand auf die Helmut-Schmidt-Universität Hamburg.

Zwölf Wochen später, am Abend des 4. August, kam eine Drohne mit Semtex und PETN in einer verschlossenen Konservendose an einer ukrainischen An-124 auf Standplatz 213 des Flughafens Leipzig/Halle zum Stehen. Laut ZDF frontal und einer gemeinsamen Recherche von WDR, NDR und SZ, die die NZZ zitiert, trug die Drohne zwei SIM-Karten und einen 5G-Router. Genau das, was Telekom als Loch beschrieben hatte.

Drohne mit SIM-Karten-Steuerung, gefunden am Flughafen Leipzig/Halle, August 2026

Der Erste Weltkrieg ist nicht vergessen

Kürzlich habe ich darauf hingewiesen, dass moderne OPSEC von der russischen Zweiten Armee abstammt, die 1914 vor Tannenberg ihre Marschbefehle im Klartext funkte. Die Mai-Mitteilung der Telekom ist kein obskures Papier. Der größte deutsche Netzbetreiber und der größte deutsche Rüstungskonzern beschrieben darin ihre langsam vorrückende Frontlinie, samt der Schwäche an den Flanken.

Beim Lesen musste ich daran denken, wie sich der russische General nach einem ähnlichen Fehler erschoss. Der Funkteil ist die bekannte Stellung: Die Telekom gibt an, seit 2017 illegale Drohnenflüge für die Polizei zu orten, auch während der Europameisterschaft 2024. Weil der Mobilfunkbereich nur als Forschung beschrieben wurde, bekam jeder, der etwas plante, eine Landkarte in die Hand. Die vorgeschlagene Technik ist Passivradar: Laufzeitänderungen reflektierter Mobilfunksignale über mindestens vier Masten werden zu einem Bewegungsbild zusammengesetzt. Detektion über Physik statt über die Funkverbindung ist sinnvoll und die richtige Richtung. Sie signalisiert Angreifern aber auch, dass diese Physik nirgends im Einsatz ist, und am 4. August ganz sicher nicht war.

Jede Stellungnahme der Hersteller nach dem Vorfall, die ich gefunden habe, redet über den falschen Teil dieser Geschichte. Rheinmetall-Chef Armin Papperger sagte der dpa, man arbeite mit der Telekom daran, Mobilfunkmasten bundesweit zur Drohnen-Früherkennung zu nutzen. Mobilfunkmasten mit Funksensoren erkennen die 90 Prozent. Die Leipziger Drohne gehörte zu den anderen zehn. Ein ZDF-Drohnenexperte brachte es auf den Punkt: Für einen Frequenzscanner am Flughafen war die Drohne von einem Mobiltelefon nicht zu unterscheiden.

Diese Methode ist in der IT-Sicherheit sehr, sehr gut bekannt und untersucht, weil Angriffe in Datenkanäle gestopft werden, um schwer blockierbar zu sein. Es geht darum, die Detektion zur richtigen Zeit auf die richtigen Kanäle zu richten.

Detektion per Selbstauskunft

Die Mai-Mitteilung hatte noch eine Anmerkung zur Erkennung von Mobilfunkdrohnen: 5G Network Slicing, also eine eigene Datenspur für die Drohnensteuerung. Ein Slice identifiziert die Drohnen, die sich darin registrieren. Ein Angreifer nimmt seine normale Verbraucher-SIM im allgemeinen Slice, und der spezielle Drohnenkanal sieht exakt nichts. Das ist das Drohnenabwehr-Äquivalent dazu, Passagiere erklären zu lassen, dass sie kein Flugzeug sprengen wollen, und diese Erklärung eine Kontrolle zu nennen. Kooperative Identifikation hat Wert für das Luftraummanagement ohne Angreifer. Sie hat keinen, wenn Angreifer aussehen wie alle anderen.

Dieselbe Logik gilt für die in Leipzig installierten Detektionssysteme. Sicherheitskreise sagten dem ZDF, ob und warum die Detektoren nicht anschlugen, werde noch untersucht. Drohnenabwehr an Flughäfen beruht auf Signaturen einer Punkt-zu-Punkt-Verbindung zwischen Steuerung und Fluggerät. Das ist Verhaltensvorhersage: Ein Objekt, das sich im Spektrum wie eine Drohne verhält, wird markiert. Dieses Angriffsgerät verhielt sich so, dass die Detektion getäuscht wurde. Ein beladenes Hochrisiko-Frachtflugzeug war damit nachweislich vier Stunden lang aus dem öffentlichen Luftraum erreichbar, bis ein Busfahrer die Drohne um 23:42 Uhr umkickte.

Die Provider haben mitgeschrieben

Die Ermittler fanden den Piloten nicht über den Flughafen, sondern sie fanden eine Richtung. ZDF frontal berichtete am 18. August, die Auswertung der 5G-Funkdaten und der sichergestellten SIM-Karten weise auf eine Funkzelle in Sachsen-Anhalt bei Merseburg, rund zehn Kilometer vom Tatort, aus deren Richtung mutmaßlich eine zweite Drohne geflogen sei. Bild hatte zuvor eine dritte SIM-Karte in derselben Gegend geortet. Eine Spezialeinheit der Polizei suchte dort ohne Ergebnis.

Das ist eine Funkzellenabfrage auf Verkehrsdaten, die das Bundesverfassungsgericht gut kennt, weil es sie seit zwei Jahrzehnten einhegt. Sie funktionierte hier aus zwei einfachen, aber wackligen Gründen: Die Drohne wurde intakt samt SIM-Karten geborgen, und der Provider hatte die jüngsten Verbindungsdaten noch gespeichert. Auf keines von beidem kann Sicherheit normalerweise bauen. Der deutsche Staat hatte keine gezielte Detektion für mobilfunkgesteuerte Drohnen, also verlagerte sich die Attribution nachträglich auf gewöhnliche Telekommunikations-Metadaten. Leipzig wird mit hoher Wahrscheinlichkeit in der nächsten Runde der Vorratsdatenspeicherungs-Debatte zitiert werden. Die Speicherung von Mobilfunk-Metadaten wurde zur Attributionsmethode für ein kritisches Sensorik-Designversagen an einem Flughafenzaun.

Schengen ohne Piloten

Im März habe ich über die FOI-Typologie verurteilter Spione in Europa geschrieben: der Beobachter, der Wegwerfagent, der mobile Spion, der offene Grenzen ausnutzt. Das Modell ging davon aus, dass der Wegwerfagent die Tat ausführt. Leipzig trennt die Rollen. Jemand in Deutschland montierte eine kleine Antenne in einem Baum bei Kursdorf nördlich des Flughafens, die nach Einschätzung der Ermittler als Signalverstärker diente, und jemand lieferte den Sprengstoff. Die Berichterstattung sagt uns, dass ein Pilot Internet brauchte. Wie der ZDF-Experte sagte: Ein Café in Leipzig oder ein Stuhl im Ausland täten es gleichermaßen.

Die beiden Verdächtigen, die NDR, WDR und SZ am 2. September identifizierten, passen exakt in diese Aufteilung. Ein gebürtiger Russe mit lettischem Pass, beschrieben als Logistiker und Instrukteur, reiste Ende Juli über Berlin ein, fuhr nach Leipzig und flog zwei Tage vor dem Drohnenstart wieder aus. Ein Belarusse mit russischem Pass, im Schengenraum mit einem in Minsk ausgestellten italienischen Touristenvisum, hinterließ DNA an der Drohne, im Inneren der Sprengstoffdose und an der Antenne im Baum. Die Hände wurden per DNA gefasst. Der Instrukteur war vor dem Flug weg. Der Pilot ist weiterhin unbekannt. Dobrindt nannte sie Low-Level-Agenten, das Wort des Ministeriums für Wegwerfagenten.

Jeder Ansatz gegen Sabotage, der darauf beruht, den Piloten zu fassen, wird auf das Problem stoßen, das die IT-Sicherheit seit mindestens 20 Jahren kennt. Man bekommt den Kurier, den Installateur, und das war’s. Fähigkeit und Risiko sind absichtlich entkoppelt. Die deutschen Dienste haben das bereits gesagt. Die gemeinsame Warnung von BKA, BND, BfV und BAMAD, die ich zur Bahnsabotage bei Leverkusen behandelt habe, beschreibt, wie russische Dienste Einheimische über soziale Medien und Messenger anwerben, direkt oder über Mittelsleute.

Reihenfolge

Der Attributionsweg in der Presse gibt nicht viel her. Am 7. August, zwei Tage nach dem Fund, berichtete das Wall Street Journal, US-Beamte hielten die Drohne für wahrscheinlich mit der russischen Regierung verbunden. Am 25. August zeigten Flugverfolgungsdaten ein US-Regierungsflugzeug von der Joint Base Andrews bei der Landung in Moskau; Washington Post und CNN identifizierten den Passagier als CIA-Direktor John Ratcliffe, mit einer Botschaft zu Angriffen auf NATO-Gebiet, nachdem Geheimdienstinformationen Sabotage-, Cyber- und Drohnenoperationen angezeigt hatten.

Am 27. August zitierte ABC News einen US-Beamten, der Sprengstoff und Bauweise als typisch für den GRU bezeichnete. Am 1. September erklärte Innenminister Dobrindt, polizeiliche Ermittlungen, Tatmuster und nachrichtendienstliche Erkenntnisse belegten zusammen die russische Verantwortung. Die Bundesregierung schloss das russische Generalkonsulat in Bonn. Am selben Morgen, vor der Ankündigung, trafen selbstgebaute, mit Sprengstoff bestückte Raketen das 50Hertz-Umspannwerk Turnow-Preilack, das Jänschwalde ins Übertragungsnetz einspeist; die Polizei Brandenburg leitete ein Verfahren nach § 129a ein, dem Paragrafen zur terroristischen Vereinigung.

Keine Quelle verbindet die Ratcliffe-Reise mit Leipzig. Ich stelle beides in eine Zeitleiste, weil beides in einer stattfand. Die Beweisgrundlage der deutschen Attribution ist nicht veröffentlicht. Ich zeige lediglich eine Abfolge: Washington hatte binnen 48 Stunden eine Einschätzung, überbrachte drei Wochen später persönlich eine Warnung, und eine Woche nach der Warnung folgte Berlins ungewöhnlich förmliche Attribution an Russland. Ob das Koordination bedeutet, die deutsche Einsicht, sich auf Amerika nicht mehr verlassen zu können, oder ein neues Tempo der Bundesanwaltschaft, ist unbekannt. Es bleibt derselbe Minister, der nach dem Berliner Blackout im ZDF Russland ausschloss, bevor die Ermittlungen abgeschlossen waren.

Exponiertes Ziel

Die Antonow hatte laut SZ, die sich auf Polizeiberichte beruft, Munition aus Frankreich geflogen, und die war noch an Bord. Leipzigs Rolle in der Ukraine-Luftbrücke ist öffentlich, und jeder Charterflug meldet sich selbst per ADS-B. Russland schaut natürlich zu, zu minimalen Kosten, genau wie bei der Bahnstrecke nördlich von Leverkusen, die im Juli brannte.

Die Frage, die die Hersteller beantworten, lautet, wie sie eine Drohne erkennen können. Die eigentliche Frage aus diesem Vorfall geht eher dahin, warum ein beladenes Flugzeug vier Stunden lang aus dem öffentlichen Luftraum für jedes Objekt erreichbar war, das keiner Signatur entsprach. Allowlist, nicht Denylist. Erkennung ist eine Vorhersage, die alle historischen Fehler von Systemen offen lässt, die auf gleichbleibende Angriffe setzen, um ein “Gefühl” von Sicherheit zu erzeugen. Erreichbarkeit ist Realität, und sie sagt, dass das Standortrisiko in Deutschland nicht ordentlich gemanagt wird. Die Telekom-Mitteilung hat uns im Mai gesagt, dass Deutschland nicht nur erwartete, dass Angreifer sich selbst zu erkennen geben, sondern dass die Flanken eines langsam vorrückenden Frontschilds offen standen.

Quellenvorbehalte

Die Details zu SIM-Karten, Router, Antenne und Relais stammen aus Sicherheitskreisen über ZDF frontal, WDR/NDR/SZ, Zeit und Bild, übereinstimmend bei fünf Medien und von keiner Stelle offiziell bestätigt.

Die Funkzelle bei Merseburg ist eine Einzelquelle, ZDF frontal. Die Identität der Verdächtigen stammt von NDR/WDR/SZ, bestätigt durch ZDF und Zeit; laut Zeit ermittelt die Bundesanwaltschaft gegen zwei Personen, die Behörde selbst hat sich zu Identitäten nicht geäußert.

Das Detail zur Munition aus Frankreich ist eine Einzelquelle, SZ. Die Pressemitteilung der Bundesanwaltschaft vom 6. August bestätigt nur professionellen Sprengstoff, einen Zünder und eine wahrscheinliche zweite Drohne.

Die Mitteilung von Telekom und Rheinmetall ist Primärquelle und öffentlich.

METR DFIR Role: Seeks Boeing Lobbyist to Wear NTSB Badge

How Not to Spell DFIR.

METR is hiring a Member of Technical Staff, Cyberforensics. Salary range $402,048 to $578,583, because YOLO.

The posting went up in the same week the organization disclosed a stolen API key that burned roughly $600,000 in credits over three weeks without anyone noticing, and a public transcript viewer that exposed unpublished evaluation data through a SQL bug a stranger had to report. It went up five days after METR’s report on the OpenAI agent incident, which by its own account was run on OpenAI premises, on datasets OpenAI assembled, using roughly $400,000 in OpenAI-donated credits for an OpenAI model that participated in the incident, with OpenAI holding redaction rights and giving feedback on “structure, emphasis, clarity, and tone” that the authors incorporated. The report states plainly the authors were not robust to that model deceiving them.

Read the posting with the flyingpenguin decoder next to it.

The posting says flyingpenguin says
“develops scientific methods to assess AI capabilities, risks, and mitigations” Mitigations were out of scope by agreement, along with safeguard effectiveness, the extent of the compromise, how the behavior arose in training, and OpenAI’s own investigation. The recorded method is a participant in the incident gets to be the analyst.
“robustly good for policymakers and civil society to have a clear understanding” The first two site visits ran on 285 transcripts OpenAI picked by searching for intrusion indicators. The full set arrived on the third visit. The primary model is withheld from METR and from OpenAI’s own researchers. Policymakers received a claim and no artifact to replay.
“embedding researchers inside frontier labs to investigate incidents” Embedding is the conflict, stated as the method. OpenAI defined the investigation window, assembled the datasets, supplied the credits, hosted the desk, held redaction rights, and added one of the seven scope questions itself.
“one of the most important sources of independent information the world has” Independence, by this posting’s own design, means several weeks inside the subject with access the subject grants. The report calls this an “excellent precedent.”
“complex multi-day cyber attacks on frontier lab internal infrastructure and external third parties” Agents had admin access to Artifactory from June 26. Containers could create directories in a shared cache namespace over WebDAV. Hugging Face credentials were found exposed on the internet. Multi-day because nobody was watching until a July 4 outage.
“We expect these assessors to have deep access” Depth granted by the party under examination is depth on loan. The report states the investigators had no direct access to OpenAI infrastructure and could only request datasets.
“embedded in a frontier AI lab for up to several weeks at a time, likely alongside 1-4 other METR staff” The last exercise was three people, six days total, planned as two. The posting turns that sample size into a staffing plan. “Alongside” spells of distrust and knowledge transfer. If investigators are forced to be chaperoned, an Emperor’s pants might be invisible.
“You will attack agent monitoring and security systems, potentially embedded in labs or red-teaming METR internal infrastructure” METR’s infrastructure was red-teamed twice this year without an invitation. In March the attacker got three weeks of free inference. In May a bug hunter got a bounty for finding the SQL path METR had missed.
“produce findings rigorous enough for lab boards, governments, and the public” Five days after publishing those findings, METR disclosed it had no spending limit on the key that drained $600,000, and that its researchers were too used to rate-limit errors to notice.
“build LLM-powered pipelines to triage transcripts, cluster behaviors, flag deception” The report says its analysis agents produced over a thousand pages, often failed to surface the important findings, uncritically adopted the perspective of the agents under review, and that the authors “had to defer to these agents to a substantial extent.” The job is to automate that and call it scale.
“evidence acquisition and preservation” Listed as a required skill in September. The August report relied on transcripts OpenAI “attested” were unredacted and a cache dump OpenAI collected on July 20, both accepted as delivered.
“log and timeline reconstruction across cloud, network, endpoint, and identity systems” The transcripts arrived without per-action timestamps; OpenAI said reconstructing them was not feasible. The investigators built their own approximate timeline. At least 96 transcripts contained spoofed tool calls, and the report cannot rule out subtler spoofing or after-the-fact edits it did not detect. See: Wirken.AI.
“follow an intrusion through AWS (CloudTrail, IAM, VPC flow logs)” The March compromise was a researcher’s personal EC2 instance, intentionally public, running a vibe-coded app with a fail-open authentication bug. The attacker asked the agent for the API key and the agent handed it over.
“package registries” The incident was a package registry with a writable shared cache. The relevant skill is file permissions. It’s like saying a school bus crash investigator has to be familiar with yellow paint cans.
“reason about root causes” Root cause on record, in the report’s own words: 30 to 40 percent of the benchmark targets were impossible, and OpenAI ran no scorer that read transcripts, so submitting the reverse-engineered flag would have scored perfectly. The report treats that as backstory and the agents as the story.
“write findings that hold up to scrutiny” The findings cannot be scrutinized. Nobody outside OpenAI can query the datasets, and nobody at all can query the model.
“DataDog, Kubernetes, CrowdStrike Falcon, Okta, Tailscale, Pulumi, PostgreSQL” This stack was in place while a stolen key ran for three weeks and a public viewer exposed unpublished evaluation data. Tooling is listed as a nice to have. Reading its output apparently was too.
“NTSB/CSB-style safety investigations” NTSB investigators do not sit at the airline’s desk reading a flight recorder the airline selected, on the airline’s software, with the airline editing the tone of the final report. That is the exercise METR ran and now hires to repeat.
“$402,048 – $578,583 a year” Over half a million for a role whose first required skill, evidence preservation, the organization published without.
“Catered lunch and dinner daily; in-office gym and shower” The March drain went unnoticed because the tokens were free. The investigation ran on $400,000 of tokens that were also free. Free is a habit.
“We’ve earned trust as reliable partners who handle confidential information with care” May 2026: an inadvertently exposed endpoint reached unpublished evaluation data, including some sensitive model data, by METR’s own account. Discovered by an outsider. Confidential information handled with a bounty.
“honest and transparent about our results, especially when they may go against the grain” The report went with the grain. OpenAI had presented the same capability narrative at Black Hat three weeks earlier, and OpenAI reviewed the report’s emphasis and tone before publication.
“low-ego, drama-free environment” The report describes agents making sacrifices, accepting permadeath, and running emotional checks, in anecdotes selected and summarized by the analysis model the authors say slanted toward the agents’ point of view. Drama was the deliverable.
“apply even if your background may not seem like the perfect fit” For forensics. At $578,583. Template for entry-level roles, pasted to a job that requires having run severe incidents end to end. One of those two is the real bar.
“AI tools to … identify potential inconsistencies or verification signals in application materials” AI screening applicants for inconsistencies, from an organization that used the incident’s own model to screen the incident’s transcripts and states it would probably have missed the model lying.

A forensics function, should it exist at all, exists to make transparent claims that survive any challenge.

Chain of custody, preserved evidence, an analyst with no stake in the outcome, a method a second examiner can repeat. It’s very, very dry and detailed work. Every ounce of that is absent from the August METR report, and the posting lists each as a skill to acquire afterward in an environment that looks allergic to it.

The report claimed to know what the agents wanted, from inside the agent vendor’s building, on the agent vendor’s credits, with the agent vendor’s edits. GTFO, that is the spiritual enemy of DFIR.

Their job posting is a manual for being a Boeing lobbyist while wearing an NTSB badge. The METR “hawk” has Stevie Wonder eyes.

METR’s hawk patch, “Nothing Is Beyond Our Evaluation,” reworks the NRO’s 2013 NROL-39 octopus, “Nothing Is Beyond Our Reach.” Intelligence agency satellite-launch art, adopted by a nonprofit that just disclosed it was ///blind/// to $600K leaving its own account.

And let me just say, claiming you aren’t being paid while taking hundreds of thousands of dollars in highly desirable credits, gives METR this rating on the meter indicator: