Salta al contenuto principale



The FBI Spent a Generation Relearning How to Catch Spies. Then Came Kash Patel.

As China’s spies grow more aggressive, the FBI is distracted and off-balance.

thebulwark.com/p/fbi-spent-gen…

#Ukraine #Russia #US #FBI #Trump #Patel

in reply to Hanse Mina

Very interesting tales, but I get a queasy feeling when they blithely ignore the possibility that Tulsi Gabbard and Kash Patel may not have America's best interest at heart, especially considering Tulsis known pro-Russian work.

emptywheel.net/2025/08/14/kash…

in reply to Hanse Mina

pooty is REALLY gettin his money's worth.
The Orange One dismantling USA on behalf of pooty.



My roundup of most important tech events last week #TechLetters ☕️ Chrome gets an AI-pilot. Ireland pays HSE victims. US targets Russian hacktivists. Russian actors sabotage U.S. sater systems, chemicals leak. SMS-verified bot armies are cheap. techletters.substack.com/p/tec…


Cosa faccio se, dopo ore di attesa, il soggetto non si fa vedere? Come capisco quando è il momento di rinunciare?
Non tutte le attese portano al risultato desiderato. A volte passi ore aspettando invano, con la luce che svanisce e il soggetto che non compare. Tuttavia, l’attesa è un investimento sul potenziale: anche quando non dà #frutti, insegna pazienza e presenza. Fotografare il #Mignattaio, ad esempio, può richiedere ore di osservazione..Continua a leggere: galassianatura.it/pixeldinatur…



«Il modello Caivano del governo Meloni? È servito ma sul territorio ci vuole ascolto». Parla il neo sindaco di Azione del comune napoletano - L'intervista
https://www.open.online/2025/12/14/modello-caivano-servito-sbaglia-chi-dice-contrario-neo-sindaco-azione-antonio-angelino/?utm_source=flipboard&utm_medium=activitypub

Pubblicato su GIORGIA MELONI @giorgia-meloni-OpenGiornale



Quando il coglione parcheggiato in doppia fila incontra in una strada a senso unico la cogliona che non conosce le dimensioni della propria macchina, il #traffico si ferma.
Unknown parent

mastodon - Collegamento all'originale
rag. Gustavino Bevilacqua
@ALFA
Creiamo un milione di posti di lavoro!
Unknown parent

hometown - Collegamento all'originale
Uilebheist
@ALFA Se è come da altre parti, dove si attaccano al clacson perché sono convinti che in qualche modo faccia spostare gli ostacoli inamovibili, forse possiamo portare i tappi per le orecchie...


Salut et adelphité les #sallesconnes de la #fediverse et du #mastodon

Il pleut.
On est lundi, cet après-midi rendez-vous chez ma néphrologue.
1h 1/2 aller, autant pour le retour, c'est à Montpellier.
Cat vient avec moi. Les deux vont pouvoir échanger professionnellement, je n'aurai aucun effort intellectuel à faire, pour une fois, ça me convient.
N'empêche, je n'ai pas réellement une grosse envie d'y aller…

Je vous souhaite un douce semaine, camarades !
🫶 ✊🏼 🤗 🥰 🫶 ✊🏼 🤗 🥰 🫶 ✊🏼 🤗 🥰




Perché tutti dovremmo salvare i messaggi importanti su WhatsApp
https://www.esquire.com/it/lifestyle/tecnologia/a69513032/salvare-messaggi-canali-whatsapp/?utm_source=flipboard&utm_medium=activitypub

Pubblicato su Lifestyle @lifestyle-Esquireitalia2



Canklow meadows: a place in labour history

In our continuing series on places in labour history, Joe Stanley draws on his family's history to recall the pit pony races that raised money and the morale of Rotherham miners during the 1926 general strike. In 1997, my great uncle Denis Stanley (1920-2011) published a history of his childhood in Brinsworth, Rotherham, in the Ivanhoe Review, a journal of local history in his home town.

sslh.org.uk/2025/12/15/canklow…



Donne in Cybersecurity: da Outsider a Cornerstone

📌 Link all'articolo : redhotcyber.com/post/donne-in-…

#redhotcyber #news #cybersecurity #donneininformatica #informatica #sicurezzainformatica #lavorotecnico



A few things you might not know about us:

- All of our articles are written by experts in their field
- We're a non-profit newsroom
- We share our content for free

If you value our unique model of non-profit news by experts, donate today: tcnv.link/diKQ8lr



Le #blog se promène dans les rues d'un village provençal abandonné chezmarketmarcel.blogspot.com/…
#blog



The values of patriarchy are buried in the very plots of our stories. New plots are needed.' — Karen Joy Fowler



Moin Leute! ✌️🙂

Ich wünsche euch allen einen guten Morgen. Habt alle einen guten Start in die neue Woche und bleibt alle sicher und gesund. 🌻🍀

Viele Grüße
Houbey

#montag, #gutenmorgen, #deutschland, #fediverse, #mastodon, #troetcafe, #troet_cafe



Non tutti gli istituti resteranno chiusi, ma ai genitori si consiglia di contattare direttamente scuole e asili per verificare.

#Berlino #sciopero

Foto: EPA-EFE/CLEMENS BILAN

ilmitte.com/2025/12/18-dicembr…



Apple computer says no.

Anyone got a lawyer to recommend to help me write a nastygram to Apple and/or help me sue them?

in reply to Dr Paris (he/him)

your story has now been surfaced in Kagi news under global technology

news.kagi.com/s/qydpkb

Hopefully the attention it’s getting will help unlock some solutions 🤞

in reply to Dr Paris (he/him)

I'm so sorry to hear about the problems you're experiencing with Apple. I don't have any constructive advice for you, but this scenario is exactly why I've told anyone who would listen, "There is no cloud. It's someone else's computer and you don't control it."



Nelle scuole italiane spesso manca l'#alternativa all'IRC ed è diffuso il #confessionalismo.
Aiutaci a rendere la #scuola più laica e a dare supporto a studenti e genitori che si rivolgono all'Uaar.
Iscriviti o rinnova già da ora per tutto il 2026! 👇
uaar.it/adesione

reshared this





#followerpower

Ich suche eine Radiologische Praxis, die eine Kassenzulassung für ein Offenes MRT hat.
Angeblich gibt es eine in Dortmund, aber die KVs sowie die gKV sind keine Hilfe bei der Suche.
Nehme auch jeden anderen Tipp für NRW, RP oder Hessen.

Please share, thx!



Due accordi commerciali, una scadenza: la corsa di Bruxelles di fine anno ad alto rischio euractiv.it/section/commercio-…


Wenn Netflix Warner Bros. kauft, dann wird endgültig alles zu Content; es gibt dann keine Filme mehr, sondern nur noch Content; keine Kinos, denn Content wird nicht zelebriert; Filmtitel, Serientitel werden egal, schnell vergessen, alles ist nur noch ein Strom, am Ende wird aller Content wie Tiktok sein.

reshared this



#Fantasy time now - What if a person being #president is in one group [you choose], then he/she chooses as the #vicepresident someone from the opposite group of #politics? Then we'd have 1 P and 1 VP as 1 Red and 1 Blue?

Would those four years be something strange?

Has that happened before in past?

#government #Democrat #republican



Un bouquin qui affiche en perspective la vallée du Rhin. Je découvre par la même occasion que ce type de "livre" s'appelle un "tunnel book", même si j'ai l'impression que ça intègre également les livres pour enfants qui sont faits dans une version très simplifiée de ce style.


Perché l’amichettismo di Giorgia Meloni e Fratelli d’Italia è un affare molto più serio di quanto pensate

fanpage.it/politica/perche-lam…



Sidney, i poliziotti perquisiscono la casa dei sospetti attentatori. Il vicino: "Un dramma"
https://www.lastampa.it/esteri/2025/12/15/video/sidney_i_poliziotti_perquisiscono_la_casa_dei_sospetti_attentatori_il_vicino_un_dramma-15435086/?utm_source=flipboard&utm_medium=activitypub

Pubblicato su La Stampa Video @la-stampa-video-LaStampa



Moi, au sujet de la panne qui a affecté 6000 avions Airbus :
theconversation.com/airbus-dou…

(J'avais prévu des liens vers des documents techniques mais on m'a dit que c'était trop de détails, je peux les fournir aux curieuses et aux curieux.)

Questa voce è stata modificata (1 settimana fa)


I think Bee Eaters are my most photographed birds so far (May be Pied Bush Chats are a close second) 📷 🪶 Asian Green Bee Eater#Wildlife #Nature #Birds #Photography


A może by tak nie kupować wielkiej choinki? #jm 2025/12/14 20:21:18 ♥

2025/12/14 20:21:18 przez www, 4 ♥
(Feed generated with FetchRSS)
blabler.pl/s/1juwX

#jm
in reply to rmikke

Obraz przedstawia widok z góry na podłogę pokoju. Na podłodze leży kilka podarunków w kolorowych opakowaniach. Z lewej strony znajduje się podarunek w czerwonym opakowaniu z motywami kwiatów, obok podarunek w zielonym opakowaniu z motywami roślinnymi. W centrum znajdują się dwa podarunki: jeden w zielonym opakowaniu z motywami roślinnymi, a drugi w czerwonym opakowaniu z motywami roślinnymi. Z prawej strony znajduje się podarunek w kolorowych kratkach. Z sufitu zwisa ozdoba w kształcie choinki. Na podłodze znajdują się również inne przedmioty, w tym elementy mebli i dywan.

Alt-text: Obraz przedstawia podłogę pokoju z kilkoma podarunkami w kolorowych opakowaniach. Z lewej strony podarunek w czerwonym papierze z motywami kwiatów i zielonym papierze z motywami roślinnymi. W centrum znajdują się podarunki w zielonym i czerwonym papierze z motywami roślinnymi. Z prawej strony podarunek w kolorowych kratkach. Z sufitu zwisa ozdoba w kształcie choinki. Na podłodze są również dywan oraz elementy mebli.

Dostarczone przez @altbot, wygenerowane lokalnie i prywatnie za pomocą Gemma3:27b

🌱 Zużyta energia: 0.180 Wh



Venezia: corteo in solidarietÀ ai detenuti di santa maria maggiore
@anarchia
Diffondiamo Corteo in solidarietà ai detenuti di Santa Maria Maggiore 14 dicembre ore 15 Piazzale Roma (Venezia) Contro il carcere e la società che ne ha bisogno
rivoluzioneanarchica.it/venezi…

reshared this



As The Resolution Foundation (quoted in the Guardian) points out:

'The fall in employment over both the past 12 months & the past five years is entirely accounted for by higher unemployment, not rising economic inactivity as many people assume & young people are bearing the brunt of Britain’s jobs downturn'....

Govt. policy on tackling labour market participation may be focussed on the wrong issue, while young people's opportunities evaporate!

#unemployment #workers

resolutionfoundation.org/publi…

in reply to Emeritus Prof Christopher May

Wonder if this'll be attributed to "quiet quitting" which is literally just doing exactly what the job demands in the time allocated to it, no overtime and no extra work. They're trying to make employment numbers go up but they think removing the social safety nets are the way to do it and automating various entry level jobs won't lead to higher unemployment forcing them into the precarious gig economy which is barely making a living for those engaged with it besides the wealthy elites running the gigs.
Questa voce è stata modificata (1 settimana fa)
in reply to Nini

@nini

yes, we've not heard as much about quiet quitting recently (or working to rule as the unions used to call it), but I'd say this is a key issue for productivity.

Most incremental improvements in productivity come through organic worker-led innovation - a disengaged workforce has no interest in handing their bosses yet more money

@Nini


Hong Kong - X5826, Extra 1959.
1 photograph : color transparency ; 35 mm (slide format)

Title: "Sightseeing in Hong Kong" ( Sports Illustrated Assignment)

Date: July 1959

Description: This photograph by Toni Frissell features a scene from Hong Kong, capturing the city's vibrant atmosphere. The image includes people enjoying golf and taking in the harbor views.

People:
Toni Frissell was an American photographer known for her work with Sports Illustrated magazine. She began her career as a photographer at National Geographic Society in 1947 and continued working with various publications until her death in 1988.

Locations: Hong Kong, China

Keywords: Hong Kong, Sports Illustrated, Toni Frissell, Photography

#HongKong-X5826 #HongKong #ToniFrissell #American #SportsIllustrated #hongkong #china #photography

loc.gov/pictures/item/20217178…



Le souffle de décembre 1995
monde-diplomatique.fr/2025/12/…

"Lorsque les mouvements sociaux piétinent, que l'austérité budgétaire domine le débat public, qu'un président français et une bureaucratie européenne voient dans le réarmement et la rhétorique guerrière les remèdes à leur folle impopularité, il est bon de se rappeler qu'en novembre-décembre 1995 (…)
/ France, Politique, Idées, Mouvement de contestation, Économie, Libéralisme"





THE WHITE STRIPES
White Blood Cells
2021 U.S. 20th Anniversary reissue

I haven’t sat down and listened to a White Stripes album front to back in quite some time.
And although I like all of the White Stripes records, I think White Blood Cells will always be my favorite on whole.

Dead Leaves, Hotel Yorba, Fell In Love With A Girl, We’re Going To Be Friends, I Think I Smell A Rat… just so many killer tunes that, when they first hit, came at the right time in my life.

As close to a perfect rock record as you can get.

#vinyl #vinylrecords #vinylcommunity #vinylcollection #retro #vintage #art #music #alternative #thewhitestripes #jackwhite #whitebloodcells #2000s #2000smusic



Dicembre è il mese dell'anno in cui si moltiplicano i reati d'odio, pare. 😞
Unknown parent

glitchsoc - Collegamento all'originale
Floreana
@ALFA
Lo so, ma mica andiamo tutti in giro ad ammazzare gente innocente.
Unknown parent

glitchsoc - Collegamento all'originale
Floreana
@ALFA
Lo so, lo so. 🤗
Si spera a oltranza, ma di tanto in tanto viene difficile.


Il materiale esplosivo era stato consegnato al ragioniere di Oneglia a Sanremo aspettirivieraschi.blogspot.co…


A un concerto per quartetto d’archi (Konzermeister: Ren'nosuke Fukuda) a tema inverno dove sento per la prima volta “Invierno Porteño” di Piazzolla, bellissimo. (J HALL - Okayama Univ. Junko Fukutake Hall 北区鹿田町2-5-1 (@ 岡山大学鹿田キャンパス内), 岡山市, 岡山県, 700-0914, JP) app.foursquare.com/share/check…


【じゃんけん】最後に何が出るのか予想しよう!ピタゴラスイッチ!#marblerun #dominos #ピタゴラスイッチ #tiktok #as...

youtube.com/shorts/6EvQmncHGK0



12 min
In the world we live in you’ve got the crazy Nazi types and or people outraged over what’s happening in in Gaza.

Take your pick.

The right wing, the richest men in the world, conservatives are responsible for all of it.

youtu.be/WabLjSCOJjQ

Questa voce è stata modificata (1 settimana fa)


Do you know what Milo is?

:boostRequested:

  • Yes (38%, 7 votes)
  • No (61%, 11 votes)
18 voters. Poll end: 5 giorni fa

in reply to David Njoku

answer
@davidnjoku I absolutely am, but that gives me valuable info - in that it's probably not nearly as popular in the UK as elsewhere. Especially since you describe it as a hot chocolate - something I'd never do, the two are completely distinct to me.
in reply to yelling jackal

answer

Sensitive content




Contrast in the canopy: living leaves meet the quiet beauty of the bare branch.

Mannum, South Australia.

© 𝓐𝓵𝓵 𝓡𝓲𝓰𝓱𝓽𝓼 𝓡𝓮𝓼𝓮𝓻𝓿𝓮𝓭 𝓫𝔂 𝓚𝓮𝓿 𝓟𝓮𝓲𝓻𝓬𝓮.

#photo #photography #australia #southaustralia #BlackAndWhitePhotography #AustralianTrees #Deadwood #trees





Twitter hatte ein paar Dinge, die irgendwann einmal in der Community entstanden sind, von der UI/UX nicht wirklich vorgesehen waren, und lange nur in den Clients und in Third Party apps wirklich Sinn machten. Zum Beispiel die @user Notation, Hashtags, und natürlich Threads.

Threads waren die Community-Antwort auf Twitter's absolut wissenschafts- und diskussionsfeindlichen 280 Zeichen. Mit unter 1000 Zeichen kann keine freundliche Unterhaltung stattfinden, das System förderte Slogans und Proklamation über Daten und menschlichen Umgang miteinander auf Augenhöhe. Dieses eine Ding, die kurzen Statuse, waren (IMHO, aber nicht nur my humble opinion) der Grund für die Verrohung und den Rand-Drift der Plattform.

Sehr lange gab es nur die Nutzung von Drittdiensten wie Tweetlonger oder RiverTweet um das Ganze lesbar zu machen.

Mastodon, die am meisten genutzte Server-Software im Fediverse, hat einige dieser Probleme geerbt: die kurzen Statuse, und die nicht optimale Darstellung von Threads.

Im Fediverse helfen andere Reader-Frontends wie Phanpy oder Elk da extrem, auch einige Smartphone Apps machen das Lesen im Thread einfacher.

in reply to Mikka, MD

Ich weiß nicht, ob ich die Timeline richtig wiedergebe, aber Threads waren AFAIK die Antwort auf *140* Zeichen.
Das reichte im Englischen für ein paar schnippische Bemerkungen, aber im Deutschen meist nur für Steno-, Kommandoton oder Beleidigungen.
in reply to Florian Schmidt

Du hast absolut Recht. Ich hab mal geschaut, und die erste Tweetlonger war lange vor den 280. Witzigerweise waren die 140 ja auch nur eine Antwort auf Twitter's Ursprung als Twtr SMS App, wo mehr einfach nicht ging, und das wurde "aus Gründen" nie hochgeschraubt.


Nemůžu vědět "jak to je", nemůžu vědět "jak to bude", můžu věřit a věřím, s podporou rozumu, s podporou citu, že "ten náš způsob dělání věcí" je řádově silnější, úspěšnější, vítěznější než systém Módiů, Putinů, Siů a Trumpů. Ukrajina vyhraje. Euro-unijní ukrajinská Koalice ochotných vyhraje. Rusko bude poraženo. Klidně a efektivně na tom pracujme.

---
#tg253036870 Věřím.




Hackaday Links: December 14, 2025


Hackaday Links Column Banner

Fix stuff, earn big awards? Maybe, if this idea for repair bounties takes off. The group is dubbed the FULU Foundation, for “Freedom from Unethical Limitations on Users,” and was co-founded by right-to-repair activist Kevin O’Reilly and perennial Big Tech thorn-in-the-side Louis Rossman. The operating model works a bit like the bug bounty system, but in reverse: FULU posts cash bounties on consumer-hostile products, like refrigerators that DRM their water filters or bricked thermostats. The bounty starts at $10,000, but can increase based on donations from the public. FULU will match those donations up to $10,000, potentially making a very rich pot for the person or team that fixes the problem.

So far, it looks like FULU has awarded two $14,000 bounties for separate solutions to the bricked Nest thermostats. A second $10,000 bounty, for an air purifier with DRM’d filters, is under review. There’s also a $30,000 bounty outstanding for a solution to the component pairing problem in Xbox Series X gaming consoles. While we love the idea of putting bounties on consumer-unfriendly products and practices, and we celebrate the fixes discovered so far, we can’t help but worry that this could go dramatically wrong for the bounty hunters, if — OK, when — someone at a Big Tech company decides to fight back. When that happens, any bounty they score is going to look like small potatoes compared to a DMCA crackdown.

From the “Interesting times, interesting problems” Department comes this announcement by NASA of a change in vendor for the ground support vehicles for the Artemis program. The US space agency had been all set to use EVs manufactured by Canoo to whisk astronauts on the nine-mile trip from their prep facility to the launch pad, but when the company went belly up earlier this year, things abruptly changed. Now, instead of the tiny electric vans that look the same coming and going, NASA will revert to type and use modified Airstream coaches to do the job. Honestly, we think this will be better for the astronauts. The interior of the Airstream is spacious, allowing for large seats to accommodate bulky spacesuits and even providing enough headroom to stand up, a difficult proposition in the oversized breadloaf form-factor of the Canoo EV. If they’re going to strap you into a couple of million pounds of explosives and blast you to the Moon, the least they can do is make the last few miles on Earth a little more comfortable.

Speaking of space, we stumbled across an interesting story about time on Mars that presented a bit of a “Well, duh!” moment with intriguing implications. The article goes into some of the details about clocks running slower on Mars compared to Earth, thanks to the lower mass of the Red Planet and the reduced gravity. That was the “duh” part for us, as was the “Einstein was right” bit in the title, but we didn’t realize that the difference would be so large — almost half a millisecond. While that might not sound like much, it could have huge implications when considering human exploration of Mars or even eventual colonization. Everything from the Martian equivalent of GPS to a combined Earth-Mars Internet would need to take the differing concept of what a second is into account. Taking things a bit further, would future native-born Martians even want to use units of measurement based on those developed around the processes and parameters of the Old World? Seems like they might prefer a system of time based on their planet’s orbital and rotational characteristics. And why would they measure anything in meters, being based (at least originally) on the distance between the North Pole and the equator on a line passing through Paris — or was it Greenwich? Whatever; it wasn’t Mars, and that’s probably going to become a sticking point someday. And you thought the U.S. versus the metric system war was bad!

Sticking with space news, what does it take to be a U.S. Space Force guardian? Brains and brawn, apparently, as the 2025 “Guardian Arena” competition kicked off this week at Florida’s Space Force Base Patrick. Guardians, as Space Force members are known, compete as teams in both physical and mental challenges, such as pushing Humvees and calculating orbital properties of a satellite. Thirty-five units from across the Space Force compete for the title of Best Unit, with the emphasis on teamwork. It’s not quite the Colonial Marines, but it’s pretty close.

And finally, Canada is getting in on the vintage computer bandwagon with the first-ever VCF Montreal. In just a couple of weeks, Canadian vintage computer buffs will get together at the Royal Military College of Saint-Jean-sur-Richelieu for an impressive slate of speakers, including our friend “Curious Marc” Verdiell, expounding on his team’s efforts to unlock the secrets of the Apollo program’s digital communications system. Along with the talks, there’s a long list of exhibitors and vendors. The show kicks off on January 24, so get your tickets while you can.


hackaday.com/2025/12/14/hackad…



NSFW 18+ Nudity
  • Sensitive content
  • Parola filtrata: nsfw

turbolove.de reshared this.



Quando l’EDR diventa un cavallo di Troia: Storm-0249 abusa di SentinelOne


Un noto broker di accesso iniziale (IAB) denominato “Storm-0249“, ha modificato le proprie strategie operative, utilizzando campagne di phishing ma anche attacchi altamente mirati, i quali sfruttano proprio gli strumenti di sicurezza pensati per la protezione delle reti come mezzo per raggiungere i propri obiettivi.

Il gruppo utilizza una nuova tecnica allarmante che include un metodo chiamato DLL sideloading. I pacchetti MSI dannosi vengono diffusi da Storm-0249 tramite campagne di phishing, sfruttando spesso tattiche di ingegneria sociale denominate “ClickFix”, le quali spingono gli utenti a eseguire comandi per risolvere presunti problemi tecnici fasulli.

Il ReliaQuest Threat Research Team (dopo che l’analisi era stata in parte sviluppata dagli specialisti di TrendMicro) ha pubblicato un rapporto aggiornato, il quale sottolinea che il gruppo di minaccia sta anche sfruttando indebitamente i processi legittimi di rilevamento e risposta agli endpoint (EDR), soprattutto le componenti SentinelOne, al fine di occultare le proprie tracce e facilitare l’avvio di attacchi del tipo ransomware.

Una volta eseguito con privilegi di SYSTEM, il programma di installazione rilascia una versione legittima e firmata digitalmente di SentinelAgentWorker.exe, un componente fondamentale dell’agente di sicurezza di SentinelOne , nella cartella AppData dell’utente. Insieme a essa, inserisce un file dannoso denominato SentinelAgentCore.dll.

“Quando il file binario SentinelOne portato con sé dall’aggressore viene avviato, carica la DLL dannosa invece di quella legittima che si trova accanto ad essa”, spiega il rapporto.

Questo trasforma di fatto lo strumento di sicurezza in un cavallo di Troia. Per chi si occupa della difesa della rete, l’attività appare come una normale operazione EDR, che consente agli aggressori di aggirare il rilevamento basato sulle firme e stabilire canali di comando e controllo (C2) crittografati mascherati da telemetria legittima.

I difensori dovrebbero monitorare:

  • Caricamento laterale anomalo: file binari legittimi che caricano DLL da posizioni insolite come AppData.
  • Traffico sospetto: connessioni a domini appena registrati provenienti da processi EDR attendibili.
  • Abuso di LoLBin: utilizzo inaspettato di curl.exe o reg.exe da parte degli agenti di sicurezza.

Oltre al sideloading, Storm-0249 abusa anche delle utilità integrate di Windows per eludere il rilevamento. Il gruppo crea domini falsi che imitano gli URL di Microsoft (ad esempio, /us.microsoft.com/) per ingannare gli utenti e i filtri di sicurezza.

ReliaQuest sottolinea che questo non indica una vulnerabilità in SentinelOne in sé. “I processi legittimi all’interno dei comuni strumenti EDR, incluso SentinelOne, non vengono sfruttati, aggirati, elusi o compromessi con le tecniche descritte nel presente documento”. Al contrario, gli aggressori stanno abusando della fiducia riposta nei file binari firmati.

Utilizzano quindi curl.exe, uno strumento standard per il trasferimento dati, per recuperare script dannosi e inviarli direttamente nella memoria di PowerShell. “Invece di salvare lo script su disco, dove l’antivirus potrebbe intercettarlo, il comando invia il contenuto direttamente nella memoria di PowerShell per l’esecuzione immediata”, creando una catena di attacchi “fileless” che lascia prove forensi minime.

L’obiettivo finale di queste intrusioni è vendere l’accesso a gruppi di ransomware come LockBit e ALPHV. Il rapporto sottolinea che Storm-0249 conduce una ricognizione specifica per estrarre il MachineGuid, un identificatore di sistema univoco.

L'articolo Quando l’EDR diventa un cavallo di Troia: Storm-0249 abusa di SentinelOne proviene da Red Hot Cyber.