Salta al contenuto principale




This could pose a problem! Be vigilant guys and gals.

Free certificates for IP addresses: security problem or solution? malwarebytes.com/blog/news/202…

#cybersecurity #infosec

in reply to CybersecKyle

So “people would notice a link to mybank.com going to hahapwned.com but not to 89.72.4.2?”

People are more likely, not less, to smell something fishy if they see a random string of digits when they expect the name of a site they trust.

If this is the only argument against certificates for IP addresses, I think we’re good.

reshared this

in reply to Aral Balkan

Great point — and I agree that most users would be suspicious if they saw an IP address like 89.72.4.2 instead of a familiar domain like mybank.com. The concern raised in the article, though, was more about scenarios where users don’t see the link clearly — such as in emails, PDFs, or messaging apps where URLs may be masked behind anchor text or shortened links. For example, a phishing email might show a link that says “View Invoice” but actually points to https: //203.0.113.10/login.

Experienced users like you and I know to hover over links, check certificate info, or inspect the address bar. But many users don’t do that — or worse, they click links without verifying anything. According to the Verizon DBIR and other phishing studies, this is still one of the top attack vectors today.

Also, I don’t think the article was arguing against IP certs outright — just highlighting that, like with any new capability, there's potential for abuse that the broader public (and infosec community) should be aware of.

#CyberSecurity #Phishing #DigitalTrust #TLS

Questa voce è stata modificata (2 mesi fa)
in reply to Aral Balkan

@aral
also it's not like this is something new. I am pretty sure Cloudflare has a certificate for 1.1.1.1 even if it redirects to a domain.
And even without LE there are other CAs offering certificates for IP addresses.


lucinda apples, painted by william henry prestele, 1895


#Singapore owns 5% of Michigan’s Upper Peninsula. Its wealth fund bet on timber bridgemi.com/michigan-governme… #Michigan #Trees


Synthesizer 😍: Genesis - Abacab

Beim Konzert am Samstag gehörte Anekdote: Phil Collins und Sting hätten in den letzten Jahren mal gemeinsam musiziert, Phil Collins sei stimmlich angeschlagen gewesen und habe daher Sting gefragt, ob jener die nicht ganz unkomplizierten Basslinien einen Ton tiefer spielen könne. Sting habe daraufhin ohne viel Federlesens alles eben einen Ton tiefer gespielt und Phil Collins das mit den Worten „Toll, dass das klappt, bei Genesis hätten wir dafür jetzt zwei Wochen proben müssen" kommentiert.

fediserve.de/preview.php?v=suC…

#Musik #music #MusikZurNacht #Genesis



Municipales : l’Appel des 69 femmes pourrait-il débloquer l’union de la gauche ?
mediacites.fr/pouvoirs/politiq…
"Et si la solution pour parvenir à une union des gauches pour les municipales venait des femmes ? L'Appel des 69 a présenté une liste symbolique, dans l'espoir de peser sur l'union des gauches, dans le programme, et d'insuffler une nouvelle méthode pour faire de la


Männer im String-Tanga tanzen vor Kindern – schockierende Poledance-Show im Prenzlauer Berg apollo-news.net/maenner-im-str… Ein nur mit String-Tanga und High Heels bekleideter Mann räkelt sich vor den Augen mehrerer Kinder im Grundschulalter an einer ...
The post Männer im String-Tanga tanzen vor Kindern – schockierende Poledance-Show im Prenzlauer Berg appeared first on Apollo News. #news #press




Flood risks continue to batter #Texas as extreme weather rattles much of the U.S. nbcnews.com/weather/storms/flo… #ClimateChange


Meteo Valle d'Aosta del 07/07/2025 ore 19:30

Meteo Valle d'Aosta. Le ultime notizie della regione Valle d'Aosta aggiornate in tempo reale. - Edizione del 07/07/2025 - 19:30





California’s New Landscaping Rules: You May Soon Be Required to Fire-Proof Your Yard sacobserver.com/2025/07/califo… #California


"E la liberta' non viene
perche' non c'e' l'unione
crumiri col padrone
crumiri col padrone
E la liberta' non viene
perche' non c'e' l'unione
crumiri col padrone
son tutti da ammazzar."

youtube.com/watch?v=QN8pgK7yM3…

#LeMondine #LaLega #CantiPopolari #MastoRadio #MastoMusic

reshared this



Warum die Labortheorie prinzipiell nicht rechts ist, auch wenn es herbeigeschrien werden soll onkelmichael.blog/2025/07/07/w…


"La legislación estadounidense prohíbe que el Gobierno espíe a sus propios ciudadanos sin una orden judicial, pero nada le impide comprarla legalmente en el mercado ¿Cómo? Las empresas como #Google, #Amazon, #Meta y #OpenAI pueden espiar a cualquier estadounidense que acepte sus términos de uso y políticas de privacidad" elpais.com/eps/2025-07-... - bsky.app/profile/minipetite.bs… #Trump #USA #privacidad #vigilancia #surveillance #inmigracion #privacy #migrations


Based on some old photos, took in my parent's village as I remember. This time I tried to draw clouds in new way, using other brushes in #Krita.

#drawing #art #MastoArt #CreativeToots #ArtWithOpenSource #landscape #sunset #evening #sky



“When implementing an AI strategy, #companies have to look at all these aspects to find the best fit for their needs. This is harder than it sounds. A business’s decision on how to #deploy AI is very different to choosing a static #technology stack to be rolled out across an entire organisation in an identical way.

Businesses have yet to understand that a successful #AIStrategy is “no longer a #tech decision made in a tech department about #hardware”, says #MackenzieHowe, co-founder of #Atheni, an AI strategy #consultant. As a result, she says, nearly *three-quarters of #AI rollouts do not give any return on investment*.”

#WhiteCollar / #ZeroHourWork / #infrastructure / #AIDeployment <ft.com/content/8452bf94-9a41-4…> (paywall) / <archive.md/WlhLh>



"There is no “cloud,” just someone else's computer—and when the cops come knocking on their door, these hosts need to be willing to stand up for privacy, and know how to do so to the fullest extent under the law. These legal limits are also important for users to know, not only to mitigate risks in their security plan when choosing where to share data, but to understand whether these hosts are going to bat for them. Taking action together, service hosts and users can curb law enforcement getting more data than they’re allowed, protecting not just themselves but targeted populations, present and future.

This is distinct from law enforcement’s methods of collecting public data, such as the information now being collected on student visa applicants. Cops may use social media monitoring tools and sock puppet accounts to collect what you share publicly, or even within “private” communities. Police may also obtain the contents of communication in other ways that do not require court authorization, such as monitoring network traffic passively to catch metadata and possibly using advanced tools to partially reveal encrypted information. They can even outright buy information from online data brokers. Unfortunately there are few restrictions or oversight for these practices—something EFF is fighting to change.

Below however is a general breakdown of the legal processes used by US law enforcement for accessing private data, and what categories of private data these processes can disclose. Because this is a generalized summary, it is neither exhaustive nor should be considered legal advice. Please seek legal help if you have specific data privacy and security needs."

eff.org/deeplinks/2025/06/how-…

#USA #CyberSecurity #PoliceState #Surveillance #Privacy #Encryption #E2E #DataBrokers





The militarization of the USA, picture from ICE on the streets of LA.
Also note the complete overkill in gear and equipment, intimidation and fear is their goal.
#ICE #USA #trump #LA #geopolitics @geopolitics

reshared this

in reply to Erik Jonker

Patsies. Insurrectionists. Anti-freedom, anti-American menace.
in reply to Erik Jonker

those jokers are cosplaying. I wonder how they perform if her masters order them to attack unarmed civilians.


IR Point and Shoot Has a Raspberry Heart in a 35mm Body


Photography is great, but sometimes it can get boring just reusing the same wavelengths over and over again. There are other options, though and when [Malcolm Wilson] decided he wanted to explore them, he decided to build a (near) IR camera.
The IR images are almost ethereal.
Image : Malcom Wilson.
The housing is an old Yashica Electro 35 — apparently this model was prone to electrical issues, and there are a lot of broken camera bodies floating around– which hides a Pi NoIR Camera v3. That camera module, paired with an IR pass filter, makes for infrared photography like the old Yashica used to do with special film. The camera module is plugged into a Pi Zero 2 W, and it’s powered by a PiSugar battery. There’s a tiny (0.91″) OLED display, but it’s only for status messages. The viewfinder is 100% optical, as the designers of this camera intended. Point, shoot, shoot again.

There’s something pure in that experience; we sometimes find stopping to look at previews pulls one out of the creative zone of actually taking pictures. This camera won’t let you do that, though of course you do get to skip on developing photos. [Malcom] has the Pi set up to connect to his Wifi when he gets home, and he grabs the RAW (he is a photographer, after all) image files via SSH. Follow the link above to [Malcom]’s substack, and you’ll get some design details and his python code.

The Raspberry Pi Foundation’s NoIR camera shows up on these pages from time to time, though rarely so artistically. We’re more likely to see it spying on reptiles, or make magic wands work. So we are quite grateful to [Malcom] for the tip, via Petapixel. Yes, photographers and artists of all stripes are welcome to use the tips line to tell us about their work.
Follow the links in this article for more images like this.
Image: Malcom Wilson


hackaday.com/2025/07/07/ir-poi…





I'm on a Jack White kick... it would seem and a potpourri of other ear tickles.

shesoverthere.com/2025/07/escu…

#Music #Monday #blog



in reply to Violet Madder

@violetmadder I lived in Utah for many years, and the smell after a summer thunderstorm was so sweet and fresh. Sigh.


Cooperation Within BRICS Has Never Been and Will Never Be Aimed at Third Countries – Kremlin sputnikglobe.com/20250707/coop… Moscow has seen statements by US President Donald Trump about the possibility of introducing additional duties on BRICS countries, Kremlin spokesman Dmitry Peskov said on Monday. #news #press


Just uploaded 4 new photos to my Flickr page: flickr.com/photos/stillugly/54… taken around Washington state. #photography


#politics

Ted Cruz, giving me new reasons to hate him every day

thedailybeast.com/ted-cruz-was…



nuovo testo nel comparto “post-poetica” del sito ‘ahida’: “oil, gas & tapes_ (core sampling)”, di antonio syxty


ahidaonline.com/post/post-poet…

*

Il testo di Antonio Syxty, che tiene insieme (e prende spunto dal)la complessità e le vicende di quarant’anni di storia, si confronta con le radici del contemporaneo peggiore: petrolio, denaro, mezzi militari, distruzione e – in sostanza – morte altrui. E, questo, non senza mescolare il male con frammenti, più o meno apparentemente irrelati, di pseudovita e banalità (un discorso funebre, un museo delle auto, un diario personale, una sorta di canovaccio sospeso tra soggetto e sceneggiatura, con varie schegge di azioni). Le pagine funzionano così come un rapido costante cambio di canale – o affaccendarsi di interferenze – su una sequenza di ‘frame’ tratti da quel ben noto film horror che l’occidente è.

MG

ahidaonline.com/post/post-poet…

#ahida #AntonioSyxty #postPoetica #scritturaDiRicerca #scrittureDiRicerca

reshared this



nuovo testo nel comparto “post-poetica” del sito ‘ahida’: “oil, gas & tapes_ (core sampling)”, di antonio syxty

* Il testo di Antonio Syxty, che tiene insieme (e prende spunto dal)la complessità e le vicende di quarant'anni di storia, si confronta con le radici del contemporaneo peggiore: petrolio, denaro, mezzi militari, distruzione e - in sostanza - morte altrui. E, questo, non senza mescolare il male con frammenti, più o meno apparentemente irrelati, di pseudovita e…

slowforward.net/2025/07/07/nuo…


nuovo testo nel comparto “post-poetica” del sito ‘ahida’: “oil, gas & tapes_ (core sampling)”, di antonio syxty


ahidaonline.com/post/post-poet…

*

Il testo di Antonio Syxty, che tiene insieme (e prende spunto dal)la complessità e le vicende di quarant’anni di storia, si confronta con le radici del contemporaneo peggiore: petrolio, denaro, mezzi militari, distruzione e – in sostanza – morte altrui. E, questo, non senza mescolare il male con frammenti, più o meno apparentemente irrelati, di pseudovita e banalità (un discorso funebre, un museo delle auto, un diario personale, una sorta di canovaccio sospeso tra soggetto e sceneggiatura, con varie schegge di azioni). Le pagine funzionano così come un rapido costante cambio di canale – o affaccendarsi di interferenze – su una sequenza di ‘frame’ tratti da quel ben noto film horror che l’occidente è.

MG

ahidaonline.com/post/post-poet…

#ahida #AntonioSyxty #postPoetica #scritturaDiRicerca #scrittureDiRicerca





in reply to ray

This is frightning, google giving law enforcement a list of users who did a particular keyword search.

I am glad it helped solve the murder case but it also implies that my search history when using google services will always be stored and can be shared without my permission.
Given that its almost impossible to not use google unless you want to be frustrated while trying to do basic stuff like email, searches etc. This basically mean every bit of data generated my anyone is permanently stored and its just about time until it will be searched for any useful stuff in case there is a situation like this again which there always will be.

Questa voce è stata modificata (2 mesi fa)
in reply to tfowinder

I use duckduckgo for searches and proton for emails for 4+ years, and I have been less frustrated than with google services
in reply to ray

Consider the people who were killed here also.

The first fire truck arrived at 2:47 am. By then, the inferno had shattered the windows and plumed the air with smoke. The stench of burning wood filled the neighborhood. When firefighters subdued the blaze enough to get in the front door, they found the small body of a child. Djiby’s daughter Khadija had been two months shy of her second birthday. Farther in sprawled Djiby himself and his 23-year-old wife, Adja.

Next to Adja lay Djiby’s 25-year-old sister, Hassan. She’d only been living in the house for three months. Like Adja, she had dreamed of going back to school to study nursing. She died with her arms still wrapped around her 7-month-old daughter, Hawa Beye. Medical examiners would later conclude that all five died of smoke inhalation, airways coated in black soot, internal organs and muscles burnished “cherry-red” from the heat.





Bluesky users can customize their notifications, including activity alerts from their favorite accounts
https://techcrunch.com/2025/07/07/bluesky-users-can-customize-their-notifications-including-activity-alerts-from-their-favorite-accounts/?utm_source=flipboard&utm_medium=activitypub

Posted into All About Apps @all-about-apps-Techcrunch



🗳️ ■ La negativa a un gobierno de coalición con Vox se le atraganta al PP sólo horas después de su congreso ■ Tellado dice fuera de micrófonos, pero no delante, que no habrá gobierno de coalición, mientras Ester Muñoz pide esperar a los resultados de las generales. Los de Abascal creen que el […]
huffingtonpost.es/politica/la-…

#politica #partidopopular(pp) #albertonunezfeijoo #vox



Good news, everyone!

I just found out how to update the license on all my Flickr photos, and I used a CC license, so have at it:

www.flickr.com/photos/27946937@N06/

@cogdog -in case you've been wondering why I was hogging my pics for myself, it's because I wasn't aware I wasn't sharing them all nicely like you do!

#Photography #CreativeCommons #SharingIsCaring



Esports World Cup kicks off in Riyadh with $70M prize pool
semafor.com/article/07/07/2025…


La Terra è più sensibile ai gas serra: cosa significa per il nostro futuro climatico
@scienza
focustech.it/news/la-terra-e-p…

#News #Scienza #Gasserra #Sensibilit #Terra #scienza
Un recente studio internazionale ha rivelato che la Terra potrebbe essere molto più sensibile ai

Scienza e tecnologia reshared this.



TGR Valle d'Aosta del 07/07/2025 ore 19:30

TGR Valle d'Aosta. Le ultime notizie della regione Valle d'Aosta aggiornate in tempo reale. - Edizione del 07/07/2025 - 19:30



Trump’s team denies that halting weapon shipments to Ukraine was a presidential decision. White House Press Secretary Karoline Leavitt clarified it’s part of a routine Pentagon review of all U.S. military aid programs.

Doubt.

in reply to NOELREPORTS 🇪🇺 🇺🇦

if so important decision is not approved by POTUS, the USA are currently a real mess.



L’elevada temperatura de l’aigua del riu Aar obliga Axpo a tancar els dos reactors de la central nuclear de Beznau, al cantó d’Argòvia, Suïssa dialec.blogspot.com/2025/07/le…


What a sight! A colony of sea lions basking in the sun, next to a large group of Pigeon Guillemots (I think?). I loved the contrast of this scene and really enjoyed photographing it -- even if the wind made it almost impossible to get a stable shot 🤣
Oregon has no shortage of kick-ass opportunities to learn your new camera!

📸 Canon EOS Rebel T7 (75-300m lens)
📍 South of Heceta Head Lighthouse

#Nature #Oregon #Photography #Wildlife

in reply to Seasons of Jason 🎒

It's really something to be walking through woods on a mountain hearing sea lions down below.





“Il #Mediterraneo è il mare che si riscalda più velocemente al mondo”. Il #WWF lancia l'allarme e chiede alla #politica di impegnarsi per mitigare il fenomeno.

lanotiziagiornale.it/il-medite…

#Ambiente #Clima #SurriscaldamentoClimatico



How would you feel if you could no longer use The Fediverse?

#Fediverse

  • Very disappointed (77%, 7 votes)
  • Somewhat disappointed (11%, 1 vote)
  • Not disappointed (11%, 1 vote)
9 voters. Poll end: 2 mesi fa






Il fondo per l’acquisto dei libri di testo da parte delle famiglie meno abbienti, in base alla legge di bilancio del 2023, stanziava, per l’anno 2024, 133 milioni di euro, a cui vanno aggiunti ulteriori 4 milioni di euro che il #MIM ha destinato a ta…
#MIM


"Ted Cruz stayed in Greece and continued to sightsee as rescuers scoured the floodwaters in Central #Texas that killed at least 91 people, including 27 campers and counselors from a summer camp."

thedailybeast.com/ted-cruz-was…

in reply to Justin

@justin Partly I think it's important people know this because persuading folks that huge (esp. neatly-identified) swaths of their community are irredeemably malicious or stupid is part of the divide and conquer strategy. Kinda like how ~2/3 of US believe in reproductive rights, trans rights, and the need for climate action, but think they're in a 1/3 minority: it's meant to keep us disconnected, quieter and less troublesome than if we knew we were overwhelmingly on the same page.
@GottaLaff


La stampa anglosassone è notevole: si fa una domanda diretta, l'interrogato non risponde con un no secco, la titolazione diventa "Declines to rule out".
bloomberg.com/news/articles/20…


I absolutely *love* that after Home Secretary #YvetteCooper branded non-violent #PalestineAction as a terrorist group for OPPOSING genocide (meaning that any of us expressing support for them can be sentenced to 14 years in prison), direct action against Israeli weapons of genocide continues under a new name.

And the name this new direct action group goes by is... #YvetteCooper!

Well played, friends 😆

planetcritical.com/p/complianc…

reshared this



70 Domini italiani di PA, Banche e Assicurazioni affetti da CitrixBleed2! Patchare immediatamente


In data odierna il CERT-AGID ha avuto evidenza di scansioni pubbliche mirate a individuare host vulnerabili. Attualmente, su una lista di 18K host, risultano oltre 70 domini italiani potenzialmente vulnerabili tra cui alcuni di Pubbliche Amministrazioni, istituti bancari, agenzie assicurative e organizzazioni private. Le Pubbliche Amministrazioni coinvolte sono state puntualmente informate dal CERT-AGID affinché possano intraprendere con urgenza le azioni di mitigazione necessarie.

L’emergenza relativa alla vulnerabilità CVE-2025-5777, battezzata con nome “CitrixBleed 2” per la sua somiglianza con la nota CVE-2023-4966, già sfruttata in passato per attacchi di ampia portata, non rappresenta una novità improvvisa.

La vulnerabilità, riscontrata in Citrix NetScaler ADC e NetScaler Gateway, è stata resa nota e corretta da Citrix a inizio giugno 2025, ma ha recentemente attirato maggiore attenzione a seguito del rilascio di un Proof-of-Concept (PoC) pubblico e delle prime segnalazioni di sfruttamento attivo in-the-wild.

Il ritardo nell’applicazione delle patch da parte di molte organizzazioni, incluse numerose Pubbliche Amministrazioni, ha aumentato in modo significativo il rischio di attacchi, soprattutto ora che è disponibile un PoC funzionante e sono stati confermati tentativi di sfruttamento.

Modalità di sfruttamento


Il difetto nasce da una validazione insufficiente degli input, che permette a un attaccante remoto non autenticato di inviare richieste appositamente costruite che consentono di ottenere risposte contenenti parti di memoria non inizializzate o sensibili. Nello specifico, l’attacco può essere portato a termine con i seguenti step.

  • L’attaccante invia una richiesta HTTP POST manipolata all’endpoint di login del Gateway.
  • La richiesta include solo il parametro login senza valore né simbolo “=” (es. login al posto di login=username).
  • Un difetto di inizializzazione nel backend fa sì che il server risponda con una struttura XML contenente il tag , che può esporre dati di memoria non inizializzata.
  • L’utilizzo del formato %.*s per stampare la variabile in questione fa sì che il contenuto venga restituito fino al primo byte nullo. Tuttavia, richieste ripetute possono rivelare segmenti di memoria aggiuntivi.

Esempio di richiesta che sfrutta la vulnerabilità

POST /login HTTP/1.1
Host: [citrix-gateway-target]
Content-Type: application/x-www-form-urlencoded
Content-Length: 5
login

Impatti potenziali


Se sfruttata, la vulnerabilità consente ad attori non autenticati di:

  • accedere a token di autenticazione direttamente dalla memoria del dispositivo;
  • bypassare l’autenticazione a più fattori (MFA);
  • dirottare sessioni utente attive;
  • ottenere accesso non autorizzato a sistemi critici.

Le conseguenze possono includere violazioni di dati, attacchi ransomware o interruzioni operative.

Azioni di mitigazione


  • Applicare le patch per tutte le versioni supportate e/o aggiornare immediatamente le versioni EOL.
  • Dopo l’aggiornamento, terminare tutte le sessioni attive per prevenire accessi non autorizzati tramite sessioni compromesse.
  • Monitorare i log per attività sospette, in particolare accessi anomali o provenienti da IP non riconosciuti.

L'articolo 70 Domini italiani di PA, Banche e Assicurazioni affetti da CitrixBleed2! Patchare immediatamente proviene da il blog della sicurezza informatica.



✊MUTU MEDIAS LIBRES✊
Sur ce qui se passe en ce moment à la Commune du Maquis... / Avril 2025
iaata.info/Sur-ce-qui-se-passe…

"Petite fédération rurale autogouvernée et dont la valeur principale est la solidarité. Uni.e.s notamment dans le combat pour le rachat du Domaine de Bois-Bas (Minerve, Hérault), les Communard.e.s s'organisent afin d'offrir à toutes et à tous un projet de société contre le système capitaliste., La Commune



5⭐ Brook Walk Falls, Castle In The Clouds, NH
trailspotting.com/2025/05/broo…
1-2 miles | Easy | Lakes Region

#NewHampshire #Nature #Waterfalls #Hiking #Trail #NewEngland #Water #Landscape



Margaret Sullivan: Is the New York Times trying to wreck Zohran Mamdani’s mayoral bid? With their made-up scandal, combined with the pre-election editorial, the Times looks like it’s on a crusade against #Mamdani

#NewYorkTimes #media #nyc
theguardian.com/commentisfree/…

JonChevreau reshared this.



With few seats in Parliament, no coherent policy platform beyond his usual outrage machine, and no serious political capital in Europe, Farage is not being snubbed by Emmanuel Macron.

He’s being treated according to his actual political relevance.
frenchdispatch.eu/p/macron-snu…



UK defence review slammed as misrepresenting China's defense policy; Labour's 'military Keynesianism' faces scrutiny globaltimes.cn/page/202506/133…


Wimbledon legend Billie Jean King calls for empathy and inclusion for trans athletes

#News #GCN #GayCommunityNews #LGBTQIA #LGBTQ #LGBTIreland
gcn.ie/billie-jean-king-empath…
Tennis legend and LGBTQ+ rights advocate Billie Jean King has spoken out in defence of trans athletes. Speaking to The Telegraph ahead of this year’s Wimbledon, King described the increasingly hostile climate faced by trans athletes as “a nightmare” and called on sporting bodies to