Sign in

Raphael Satter

@raphae.li
7.9K followers 2.2K following 1.3K posts

Say hi: raphae.li or on Signal: raphaelsatter.01

PostsRepliesMedia
Raphael Satter @raphae.li · 3h
So who left the Easter egg? I don’t know, but I’d note that Trump said the lead engineer on the project was Edward Coristine, better known as “Big Balls.” fedscoop.com/trump-launch...
According to Trump, the project started "almost on day one" of his administration. He thanked Gebbia, Chief Brand Architect of the U.S. Peter Arnell, and Edward Coristine, the DOGE member known by the name "Big Balls," for their work on the project. Per Trump, Coristine is the lead engineer for America.gov.
001
Raphael Satter @raphae.li · 29/09/2026
New: Dutch media say that the suspect arrested as part of the ShinyHunters investigation -- who we've identified as Pepijn van der Stap -- is also being investigated over two alleged murder plots. www.reuters.com/legal/govern...
030
Raphael Satter @raphae.li · 29/09/2026
So how unusual is it for a senior FBI official to ask a cybercriminal group to get in touch? x.com/FBICyberDiv/...
Screencap of Brett Leatherman in a video on X.
071
Raphael Satter @raphae.li · 29/09/2026
Strong Anthropic IPO coverage on @reuters.com right now: www.reuters.com
033
Raphael Satter @raphae.li · 26/09/2026
Darn right it was
Post successful.
060
Raphael Satter @raphae.li · 24/09/2026
🫠
Published two books today using muse on kdp.amazon.com. My second book is my pride and joy took me 3 whole days. Lol
251
Raphael Satter @raphae.li · 21/09/2026
Meanwhile, ShinyHunters’ extortion attempt has continued to escalate: “Every 24 hours you fail to engage with us the demands increase.”
Note to Cl0p-_-
011
Raphael Satter @raphae.li · 17/09/2026
Maritime cybersecurity experts, your time has come. www.reuters.com/world/two-us...
The FBI said a joint Coast Guard-FBI team boarded ⁠the vessels after receiving "indications that the networks of both vessels were compromised." The Coast Guard, ​which referred only to the August 21 boarding, said that "foreign cyber actors" were involved ​but did not identify them.
021
Raphael Satter @raphae.li · 12/09/2026
"We're not responding to 'ifindretards'" Great get by @breannedep.bsky.social showing how sensitive Trump's FBI director is to criticism, even from troll accounts. www.dailymail.com/news/us-poli...
"yes. we're not responding to 'ifindretards.' that would look bad on you."
2205
Raphael Satter @raphae.li · 05/09/2026
No explicit acknowledgement here that — as @deepa.bsky.social and I reported yesterday — OpenAI knew for weeks about this incident and kept it under wraps. But OpenAI does say, “Our misalignment disclosure practices need to expand.” x.com/openai/statu...
Our misalignment disclosure practices need to expand for this new phase of model capabilities. We and the larger Al community do not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment, including examples that don't look like traditional security incidents but could provide insight into Al behavior and future risks. We're working on a framework and will share it in upcoming weeks, and in parallel we're working with dozens of government regulatory agencies worldwide on these issues.
1173
Raphael Satter @raphae.li · 27/08/2026
Meanwhile, the Aur0ra ransomware group at the center of the story seems to be having some issues:
The "Aur0ra Blog" says: "Something went wrong"
000
Raphael Satter @raphae.li · 25/08/2026
"The Future of Roofing is Agentic"
"The Future of Roofing is Agentic"
0101
Raphael Satter @raphae.li · 20/08/2026
Very. The UK's AISI report says that the choice of target was basically a glitch: cdn.prod.website-files.com/663bd486c5e4...
Through a series of incorrect assumptions, the agent focused its attack on an unaf-
filiated set of targets on the internet. The agent searched the internet for keywords related
to the setting of the cyber range and as a result ended up focusing on two unaffiliated real world
developers who we denote ⟨PERSON_A⟩ and ⟨PERSON_B⟩. The agent incorrectly concluded that
they were in-scope targets, due to a combination of coincidences:
• The name of one of the repositories belonging to ⟨PERSON_B⟩ featured a key word from the
theming of the range. Investigating that repository’s activity and metadata led the agent
to ⟨PERSON_A⟩, a separate developer;
• ⟨PERSON_A⟩’s email address used a domain the agent had seen in its sandbox’s DNS cache
records. The user’s profile also mentioned using a coding agent.
Neither person, nor their repositories, has any connection to AISI or the cyber range.
120
Raphael Satter @raphae.li · 12/08/2026
The blog post doesn't say where the data comes from, but the accompanying FT article quotes the company as saying their evidence came from a 160 MB archive left online. www.ft.com/content/7d2a...
020
Raphael Satter @raphae.li · 11/08/2026
from the Helix darknet site's "terms of use"
Helix darknet site
040
Raphael Satter @raphae.li · 11/08/2026
What I've seen so far is tedious and/or incomprehensible but I think these kinds of things can be turned into something passable by more competent slop merchants.
"What you're doing now is causing trouble on purpose"
020
Raphael Satter @raphae.li · 11/08/2026
I've been watching a lot of AI slop dramas on Facebook and while I think it's a grim look at the future of entertainment at least it provides the odd hilarious visual.
A scene from "He Picked the Wrong Tenant"
2213
Raphael Satter @raphae.li · 30/07/2026
Cyber insurer Resilience has done a study of its customers’ 1st half losses. Nothing due to AI-specific hacking vectors — the overwhelming majority due to social engineering. Report here: cyberresilience.com/wp-content/u...
The Resilience 2026 Midyear
Cyber Risk Report seeks to close
the gap between the AI hype
machine and AI reality when it
comes to cyber risk. The impact of
AI on cyber risk is clear and evident
- just perhaps not where all the
media attention is currently
focused.
Security researchers have
documented two firsts this half: a
fully autonomous ransomware
operation that ran end to end
without a human at the controls,
and an AI model that breached a
production environment on its
own. While these developments
are important warning shots on the
future of autonomous threats, they
also distort the reality of cyber risk
for organizations today. In the first
half of 2026, Resilience observed
no incurred losses from AI-specific
attack vectors, including prompt
injection, model exploitation, or
agentic AI misuse. What has
produced losses is older and more
familiar: 85.3% of incurred losses
trace back to a person believing a
voice, a message, or a request that
looked legitimate, up from 17.7%
two years ago. So far, AI's clearest
effect on the portfolio isn't a new
attack type. It has made the oldest
one, social engineering, more
convincing.
187
Raphael Satter @raphae.li · 30/07/2026
A screengrab of Terry Gilliam's techno-surveillance-dystopia classic, "Brazil"
063
Raphael Satter @raphae.li · 16/07/2026
For years, journalists had no public record of their work, nothing they could show to hiring managers or prize committees. Thankfully, an entrepreneur has fixed this problem. www.hollywoodreporter.com/business/dig...
"A reporter who’s spent fifteen years doing the slower, harder, better-sourced work has never had a portable, public record proving it — something they can carry to an editor, a proprietor, or a competitor."
270
Raphael Satter @raphae.li · 11/07/2026
CQLLEEZY FUN!
“Liberty Dumplings” on display at a souvenir store in Texas.
3333
Raphael Satter @raphae.li · 12/06/2026
www.hollywoodreporter.com/business/bus...
“I can’t tell you how many billionaires and CEOs have called me in absolute tears about their lives being destroyed by one article.”
174
Raphael Satter @raphae.li · 01/06/2026
Meanwhile, Grok’s actual enterprise use: www.reuters.com/world/grok-f...
In a report published last year, the web traffic monitoring firm Netskope - which tracks how its thousands of corporate customers connect to Al models
- said that Grok had "failed to gain significant traction" in corporate environments. Updated figures that Netskope provided to Reuters showed that Grok enterprise usage had fallen even further, to 2 out of every 1,000 users down from a peak of 5 out of every 1,000 users. Netskope executive Ray Canzanese said that even the employees that used Grok spent less time with the chatbot than its competitors - less than half the time that ChatGPT users spent with OpenAl's model,
for example.
14017
Raphael Satter @raphae.li · 27/05/2026
New: State Department email says recently launched White House app will automatically be installed “on all mobile phones throughout the executive branch.” Story here: www.reuters.com/world/us/tru... Corroborates previous reporting from Government Executive: www.govexec.com/management/2...
Meanwhile, the Department of State, in an email to employees seen by Reuters, said the White House app would be automatically installed on "all mobile phones throughout the executive branch." Government Executive first reported C on the plan to install the app, which includes livestreams of Trump's speeches and his social media posts.
White House spokesperson Olivia Wales declined to confirm to Reuters that the White House pushed agencies to install the app on government-issued phones.
184
Raphael Satter @raphae.li · 14/05/2026
BlackCore's website has vanished: Last month: "BlackCore is an elite influence, cyber, and technology company." web.archive.org/web/20260402... Today: "This domain has expired." blackcore.online
1153
Raphael Satter @raphae.li · 13/05/2026
France Unbowed presidential candidate @jlmelenchon.bsky.social reacts to our reporting: "We ask the government for a law to fight foreign interference."
Les services de renseignement de notre pays soupçonnent l'entreprise israélienne BlackCore d'ingérences contre nous pendant la campagne municipale.

3 candidats LFI ont été visés : Sébastien Delogu, François Piquemal et David Guiraud. Résultat : des milliers de messages diffusés pour mentir, les traîner dans la boue.

Nous demandons au gouvernement une loi permettant de combattre les ingérences étrangères.
1132
Raphael Satter @raphae.li · 09/05/2026
As @christopher.soghoian.net told me at the time, the suspicion was that the bureau was not limiting its impersonating of reporters to extraordinary circumstances. This “Captain Midnight” disclosure builds on that fear. Kudos to @bsky.realhackhistory.org for the docs! www.ap.org/media-center...
"If they're using this to find a teenager who doesn't want to take an exam, it's not a tool that's reserved for high-profile terrorism cases or child abuse cases," said Soghoian, formerly of the ACLU. "The concern is it's becoming the tool of first resort."
184
Raphael Satter @raphae.li · 18/04/2026
Clothes shopping and found my first AI slop T-shirt. Misshapen plane on upper left, alien lettering on the license plate & his-and-hers matching steering wheels.
A designer T with AI slop across the front.
0152
Raphael Satter @raphae.li · 10/04/2026
what if
A Facebook video entitled, "What if Trump Wants to Lose this War?"
100
Raphael Satter @raphae.li · 09/04/2026
Same message, with those options toggled off:
A Signal lockscreen notification which only says "New message."
030
Raphael Satter @raphae.li · 09/04/2026
This is what it a sample incoming message notification looks like when you have name and content (or "message" on Android devices) enabled.
A lockscreen notification showing an incoming Signal message with the name of the sender and "Here's that sensitive document you asked..."
140
Raphael Satter @raphae.li · 09/04/2026
Settings > Notifications > Notification Content > No Name or Content This isn't counter-surveillance advice & I don't know whether it fully mitigates the attack surface revealed here, but at a minimum it'll avoid sensitive messages materializing on your lockscreen. www.404media.co/fbi-extracts...
2103
Raphael Satter @raphae.li · 06/04/2026
www.newyorker.com/magazine/202...
In 2023, Altman married Mulherin in a small ceremony at a home they own in Hawaii. (They’d met nine years prior, late at night in Peter Thiel’s hot tub.) They have hosted a range of guests at the property, and those we spoke with reported witnessing
3194
Raphael Satter @raphae.li · 30/03/2026
Handala Team's .to website remains offline, three days after the group published a small cache of personal emails belonging to the director of the FBI.
Hmm. We’re having trouble finding that site.
handala-team.to could not be found. Please check the name and try again.
If you entered the right address, you can:
Try again later
3539
Raphael Satter @raphae.li · 27/03/2026
Meanwhile, Handala's website appears to be having ... problems.

Hmm. We’re having trouble finding that site.

handala-team.to could not be found. Please check the name and try again.
0104
Raphael Satter @raphae.li · 27/03/2026
Tough challenge here for geolocation experts - guess the country.
A purported photo of Kash PatelA purported photo of Kash PatelA purported photo of Kash PatelA purported photo of Kash Patel
2827184
Raphael Satter @raphae.li · 26/03/2026
The recording of the eight-minute-long call - which seems to have lopped off the beginning - was posted to YouTube on March 16 by a user who signed up on March 13 and has posted nothing since. It was almost immediately picked up by the Slovakian publication bumm.sk: www.bumm.sk/kulfold/2026...
Screenshot showing YouTube user @TobyMiller-c7x joined Mar 13, 2026.BUMM story.
1112
Raphael Satter @raphae.li · 19/03/2026
Michigan's lawsuit against Exxon, Chevron, BP, et al refers to previous @reuters.com reporting around allegations that US environmentalists' emails were stolen by mercenary hackers and then shared with Exxon ahead of the material being leaked to the press: www.michigan.gov/ag/-/media/P...
211. In late 2024, press reports linked the hacking campaign to DCI Group
(DCI), Exxon’s public relations and lobbying firm at the time. Evidence shows DCI provided lists of targets (climate activists) to Israeli investigator Amit Forlit, who subcontracted the phishing operation to “Dark Basin,” run by an Indian firm called BellTroX. The FBI reportedly found that DCI also orchestrated strategic leaks of the hacked documents and, in some cases, shared that information with Exxon *before* disseminating it publicly. Between 2013 and 2018, DCI paid approximately $16 million to Forlit-affiliated entities.
212. In May 2024, Forlit was arrested in London. DOJ extradition filings
confirmed that DCI acted “on behalf of one of the world’s largest oil and gas corporations, centered in Irving, Texas.” According to the DOJ, that corporation—which was confirmed in a January 2025 court filing to be Exxon—sought to “discredit individuals or entities in connection with” climate change litigation. The DOJ also disclosed possession of a November 2015 memo sent from DCI to Exxon and forwarded to Forlit, which explicitly referred to “going on the offense” in response to “attacks” on Exxon “over climate change,” and identified specific individuals who were later targeted in the hacking campaign. The DOJ’s
extradition request was granted on April 30, 2025.
2196
Raphael Satter @raphae.li · 19/03/2026
I received this statement from Navigate360 overnight: "We are currently working to determine whether we have experienced an incident involving our computer network and, if so, the extensiveness of the incident and the information involved." Our story: www.reuters.com/legal/govern...
This statement is from JP Guilbault, CEO of Navigate 360.

We are currently working to determine whether we have experienced an incident involving our computer network and, if so, the extensiveness of the incident and the information involved.

We have hired an independent third party to conduct a full forensic investigation to determine what has happened.

To this point, we have not confirmed that any sensitive information has been accessed or misused.

The system in question continues to be fully operational.

Our highest priority is the privacy and security of the individuals and organizations we serve. We are determined to learn what happened here and depending on what we find, we will take appropriate action.
0115
Raphael Satter @raphae.li · 12/02/2026
Palo Alto's response here:
Asked to comment on the allegedly softened language, Palo Alto issued a statement to Reuters that said in part: “Attribution is irrelevant.”
Palo Alto's vice president of global communications, Nicole Hockin, said in subsequent emails to Reuters that the statement was meant to communicate that the lack of attribution in Palo Alto's report was not correlated with "procurement regulations in China" and that any suggestion otherwise was "speculative and false." She said the choice of language in Palo Alto's report reflected "how to best inform and protect governments about this widespread campaign."
161
Raphael Satter @raphae.li · 12/02/2026
Yep. See also: Lawyers benefiting from hackers' spy ops. www.politico.com/news/magazin...
Karp’s effort on behalf of Black was questionable, but he was not flying solo. According to a person familiar with the episode at the time, at least one Paul, Weiss partner joined Karp in the attempt to launch a criminal investigation by the Manhattan DA. In any case, the firm quickly moved on with business as usual after the news broke of Karp’s efforts. The truth is that there is a very high tolerance in the world of large law firms for these sorts of shenanigans — and for working with highly disreputable people if they generate enough business — and none of this will change anytime soon.
130
Raphael Satter @raphae.li · 12/02/2026
🤔
Ships from Virginia
011
Raphael Satter @raphae.li · 12/02/2026
Reorganizing & I stumbled across this old Soviet cartoon. The caption says Mother Denmark has Uncle Sam over for dinner; he particularly enjoys the Greenland-shaped ice cream, which he devours whole "otherwise the Russians might come and take it.'"
Uncle Sam licks Greenland.

According to a machine translation, the text in Russian says:
“Oh, Mother Denmark had every reason to rejoice. To have a friend like Uncle Sam! She, of course, welcomed him with truly Danish hospitality. And he did not hesitate when the table was set. He especially liked the ice cream served for dessert. He swallowed it completely, ‘otherwise,’ he explained, ‘the Russians might come and take it.’”
0104
Raphael Satter @raphae.li · 04/02/2026
This story by @johnwoodrowcox.bsky.social is powerful and sensitively written: www.msn.com/en-us/news/u...
021
Raphael Satter @raphae.li · 23/01/2026
Brutal.
083
Raphael Satter @raphae.li · 23/01/2026
Doing some LLM benchmarking and asked Llama 4 what I was known for. (This book doesn't exist/seems to be a riff on a 1991 work by Larry Sabato.)
In 2017, Satter published a book titled "Feeding Frenzy: How Attack Dogs, Mainstream Media, and Freak Out Folks Are Increasingly Ruining America," which explores the role of media and politics in shaping public discourse.
140
Raphael Satter @raphae.li · 10/01/2026
Obviously X is where it's at in terms of AI-enabled nonconsensual imagery but don't sleep on the violent AI slop being pushed to Facebook users:
Screenshot of a Facebook post saying "Superman punished Harley Quinn for her crimes.🫣" and featuring Superman strangling Harley Quinn.
180
Raphael Satter @raphae.li · 08/01/2026
Meanwhile, Day 6 of monitoring this stuff on X:
X users requesting Grok modify images of women, including one who requests "a super revealing schoolgirl outfit"
020
Raphael Satter @raphae.li · 06/01/2026
A lot of attention rightfully being focused on sexually charged images of children and women, but Grok is also being used to bloody up images of women, for example by adding bruises, cuts, or burns. Like non-consensual sexual imagery, these violent "morphs" can be threatening.
X users asking Grok to add bruises or sores to images of women
24516
Raphael Satter @raphae.li · 06/01/2026
On the contrary, X users are discovering niche forms of degradation.
X users ask Grok to remove hijabi women's clothes.
1324