We've found the best Prime Day Garmin deals so you don’t have to
https://www.runnersworld.com/uk/gear/tech/g60265980/garmin-deals-amazon-prime-day-1/?utm_source=flipboard&utm_medium=activitypub
Posted into Gear @gear-RunnersWorldUK
We've found the best Prime Day Garmin deals so you don’t have to
Looking for a discounted Garmin watch? We've rounded up the top Garmin deals to shop in the Amazon Prime Day sale this July.Ali Ball (Runner's World)
Zorin OS
Link: zorin.com/os/
Discussion: news.ycombinator.com/item?id=4…
Zorin OS - Make your computer better.
Discover the alternative to Windows and macOS designed to make your computer faster, more powerful, secure, and privacy-respecting.Zorin
reshared this
yougov.co.uk/international/art…
Who do Britons see as the UK’s allies and enemies?
Britons most likely to see Anglosphere countries as the UK’s friends, while nearly nine in ten view Russia as unfriendly or a threatDylan Difford (YouGov)
reshared this
Trump Sows Turmoil on Metals Markets
https://www.bloomberg.com/news/newsletters/2025-07-09/trump-sows-turmoil-on-metals-markets?utm_source=flipboard&utm_medium=activitypub
Posted into Bloomberg @bloomberg-bloomberg
Trump Sows Turmoil on Metals Markets
Good morning. Donald Trump’s copper tariff threats reverberate. Russian imitators are filling the void left by McDonald’s & Co. And Christian Horner is out at Red Bull Racing. Listen to the day’s top stories.Angela Cullen (Bloomberg)
05/07/1934
Titraille & MAIS PURÉE DE PUNAISE, RIEN NE VA DANS CE TITRE, C'EST PAS CROYABLE !!
gallica.bnf.fr/ark:/12148/bpt6…
Consulter le document sur Gallica
L'Ouest-Éclair : journal quotidien d'informations, politique, littéraire, commercial @GallicaBnFGallica
Golden power su Unicredit, attesa la decisione del Tar. Ue: “Valutazioni non ancora concluse”
https://www.repubblica.it/economia/2025/07/09/news/golden_power_unicredit_bpm_tar_commerz_ue-424720455/?utm_source=flipboard&utm_medium=activitypub
Pubblicato su Economia - La Repubblica @economia-la-repubblica-repubblica
Golden power su Unicredit, attesa la decisione del Tar. Ue: “Valutazioni non ancora concluse”
È iniziata la discussione del ricorso presentato dall’istituto di piazza Gae Aulenti sulla legittimità delle prescrizioni del governo in relazione alla Ops su …a cura della redazione Economia (la Repubblica)
Scoraggiati, care giver o disoccupati di lungo corso: chi sono davvero i Neet
https://www.repubblica.it/economia/2025/07/09/news/scoraggiati_care_giver_o_disoccupati_di_lungo_corso_chi_sono_davvero_i_neet-424720438/?utm_source=flipboard&utm_medium=activitypub
Pubblicato su Economia - La Repubblica @economia-la-repubblica-repubblica
Scoraggiati, care giver o disoccupati di lungo corso: chi sono davvero i Neet
Presentato a Montecitorio dalla Fondazione GI Group l’Osservatorio permanente sui giovani italiani che non studiano e non lavoranoRosaria Amato (la Repubblica)
Fabrice Ducceschi será el nuevo director general de Familia Torres a partir de septiembre
La bodega catalana refuerza su apuesta internacional y sostenible con un relevo en la dirección tras una etapa de transiciónVinetur
Barcelona Wine Week 2026 roza el lleno con 1.300 bodegas y 85 denominaciones de origen confirmadas
El evento prevé superar los 26.000 visitantes profesionales y centrará su programa en el factor humano del sector vitivinícola españolVinetur
Laut aktuellen Daten des Statistischen Bundesamts ist „Krankheit, Sucht oder Unfall“ 2024 erstmals der häufigste Auslöser privater Überschuldung in Deutschland (18,1 %). Die Universität Witten/Herdecke sieht darin ein alarmierendes Signal: Krankheit trifft viele doppelt – gesundheitlich ...
nachrichten.idw-online.de/2025…
Ich stehe kurz davor, mir eine gemanagte #Nextcloud zu holen. Speicherplatz 1TB.
Wichtig ist mir, dass ich selber aus dem App Store jede App installieren kann, die ich möchte. Eigene Domain nice aber nicht wichtig.
Aktuell stehen zur Auswahl #Hetzner (hetzner.com/de/storage/storage…) für 5,11€ oder #Wolkesicher (wolkesicher.de/sichere-cloud-f…) für 3,99€
Hetzner ist ja der Platzhirsch. Wie sind eure Erfahrungen damit?
Kennt und nutzt jemand wolkesicher.de? Wenn ja, wie sind damit die Erfahrungen?
Sonstiger Input zu diesem Thema?
Habe gestern noch eine eigene Domain auf die Cloud aufgeschaltet. Das ging problemlos und die NC war nach ein paar Stunden inkl. Zertifikat von LE mit der eigenen Domain erreichbar.
Also bis jetzt macht mir wolkesicher einen soliden Eindruck.
A group of major European media organisations has launched ChatEurope - a chatbot aimed at combating online disinformation.
computing.co.uk/news-analysis/…
#technews #eurpoe #eu #genai #ai #llm #disinformation #mistral #chateurope
'Remains pending': Texas says Trump is stalling long-term aid after disaster
Notus reports President Donald Trump is still holding back on pivotal mitigation funds to prevent future disaster in Texas, even as the state's body count continues to rise from its latest calamity.Adam Lynch (Alternet.org)
Die #PeterThiel Story
Peter Thiel ist der Strippenzieher hinter dem kulturellen Rechtsruck in den #USA und einer der wichtigsten Unterstützer von #DonaldTrump. Mit #Paypal und #Facebook ist er reich geworden. Das ist die Geschichte des geheimnisvollen Tech-Milliardärs. ardaudiothek.de/sendung/die-pe…
Die Peter Thiel Story
Peter Thiel ist der Strippenzieher hinter dem kulturellen Rechtsruck in den USA und einer der wichtigsten Unterstützer von Donald Trump. Mit Paypal und Facebook ist er reich geworden. Das ist die Geschichte des geheimnisvollen Tech-Milliardärs.ARD Audiothek
Climate Change 2025
Here's Where's Next!
Flash flooding after intense rainfall leave three dead in New Mexico!
#AureFreePress #News #press #headline #GlobalWarming #climatechange #climatecrisis #Breaking #BreakingNews
[Municipio 8] M'INCANTO - Festival a cielo aperto di arte, teatro, musica, circo e danza per tutti
M’Incanto è un festival multidisciplinare ideato dal Teatro Pane e Mate per rafforzare l’offerta culturale nei quartieri del Municipio 8, valorizzandone il patrimonio culturale e sociale e promuovendo la partecipazione attiva e inclusiva dei cittadini.
Si svolge tra il 9 luglio e il 25 ottobre 2025, con 60 eventi gratuiti tra spettacoli, concerti, installazioni e laboratori, in una logica di capillarità territoriale e valorizzazione delle periferie. Il festival mira a trasformare gli spazi coinvolti in presidi culturali vivi e condivisi.
L’inclusione è al centro del progetto grazie a una rete di partner sociali e culturali locali con eventi accessibili gratuitamente, percorsi guidati, presenza di interpreti LIS, materiali informativi accessibili e assistenza a persone con difficoltà motorie.
L'evento fa parte di Milano è viva, Il programma diffuso in tutta la città che porta musica, teatro, laboratori, incontri e molto altro in tutti i Municipi, da giugno ad ottobre.
Qui gli eventi: yesmilano.it/eventi/tutti-gli-…
reshared this
"China has the world’s top EV industry and dominates the global lithium supply chain: About 70% of all lithium is processed there. As other nations race to catch up, Beijing has leaned into its long-standing role as a major investor in mining in Africa. In Zimbabwe, China’s relations with the government are particularly close, dating to when it backed eventual dictator Robert Mugabe’s guerilla faction during the struggle for liberation in the 1960s. Mugabe’s successor, President Emmerson Mnangagwa, has supported Chinese takeovers of lithium mines, arguing they will bring economic growth for a country where close to half the population lives in poverty.
But many residents in mining areas in Zimbabwe say the relationship with China is one of exploitation. The lithium boom has created little benefit for their communities, they argue, and in many ways has harmed them. Residents say they’ve been displaced from their homes by expanding operations at Chinese-run mines with little or no compensation. They say farmland has been degraded and water supplies contaminated. Some residents have complained that well-paying jobs in the mines are often filled by workers imported from China or Zimbabwe’s cities, while unions have criticized conditions and pay. Security crackdowns at the mines have resulted in arrests of illicit miners.
“China is seeing Zimbabwe as a colony, and it has marked it as its territory,” Farai Maguwu, executive director of the Centre for Natural Resource Governance, a research and advocacy group in Harare, told Rest of World. Zimbabwe’s mining sector has long been allegedly intertwined with the financial interests of government and military elites. But Maguwu accused Beijing of helping to further an environment of unaccountability in which Zimbabwe’s leaders “don’t take action to protect the integrity of their own people” — echoing critiques of Chinese mining operations around the continent."
restofworld.org/2025/zimbabwe-…
#Africa #Zimbabwe #Lithium #China #EVs
Zimbabwe lithium mining boom fuels a dangerous black market for locals - Rest of World
The EV boom has brought a surge Chinese investment into Zimbabwe’s lithium mines, but many locals say they’re being pushed out, exploited, and left behind.Kate Bubacz (Rest of World)
Joe Vinegar reshared this.
like this
reshared this
Wer hätte gedacht dass ausgerechnet die #noAfD mit einer Anfrage im Bundestag die beste Begründung liefert, warum eine #positive_Migrationspolitik nötig ist.
Das Problem ist nie #Migration gewesen.
Das Problem ist, dass der Staat Kommunen und Ehrenamtliche mit der #Integration alleine lässt.
Sprachkurse, Ausbildung und psychologische Hilfe sind nötig. Die Migration ist eine unfassbar große Chance. Wir müssen sie nur als solche begreifen.
Trump's tariffs are hitting US businesses in the Pocketbook with few trade deals to show for the pain.
#AureFreePress #News #press #headline #GOP #Politics #uspolitics #uspol #Breaking #BreakingNews
Georgia Police Arrest Immigrants — Then Get Warrants From DHS
theintercept.com/2025/07/09/ge…
#StopMassDeportations #AbolishICE #ICEGestapo #OpposeTrumpsAmerika #GOPFourthReich #NoNazis #StopFascism #SaveDemocracy
Georgia Police Arrest Farmworkers — Then Get Warrants From DHS
Georgia authorities said their goal was to serve warrants for crimes against children. They swept people up and got immigration detainers later.Schuyler Mitchell (The Intercept)
Was ein Bild... Gestartet sind sie alle letzten Samstag um 12 Uhr in #Wien. Das Ziel heißt dieses Jahr #Nizza.
Die erste Frau, Larissa Unsinn mit der Startnummer #tpbr2025cap51, ist durch den anspruchsvollen #schwarzwald Parcours durch. Allein dieser ist über 100km lang und es sind ca. 2.500 Höhenmeter zu bewältigen.
Der erste Mann erreicht gerade den Parcours am dritten "Peak" - dem #ColledelleFinestre. Die Nordrampe ist eine geschotterte Straße und es sind auf gut 18 Kilometern fast 1.700 Höhenmeter zu überwinden.
Quelle: quaeldich.de/paesse/colle-dell…
Link zum Live-Tracking:
tpbr2025.legendstracking.com/
Wer so richtig noch keine Vorstellung hat, wie so ein #Fahrradrennen fernab vom #TourdeFrance #Tourtross abläuft, findet in dem Film "Three Peaks And In Between" mit #JanaKesenheimer eine ganz wunderbare #Doku aus einem der letzten Jahre.
Verfügbar auf youtube - hier der Link. Datensparsam am besten via #Freetube (am PC) oder #NewPipe (am Smartphone) zu genießen.
youtu.be/g_joucawmh0 oder
redirect.invidious.io/watch?v=…
#Gravel #ultracycling #langstrecke #bikepacking #nice #dotwatcher #tdf2025 #tdf
Colle delle Finestre (2178 m)
Zum Giro 2005 war die Spannung groß: der unasphaltierte Colle delle Finestre war am letzten Bergtag im Programm. Extra für diesen Tag wurde die Südrampe von Pourriere asphaltiert, und die Nordrampe von Susa einer Generalüberholung unterzogen.www.quaeldich.de
South Africa to Tap Private Firms to Revamp Crumbling Courts
https://www.bloomberg.com/news/articles/2025-07-09/south-africa-to-tap-private-firms-to-revamp-crumbling-courts?utm_source=flipboard&utm_medium=activitypub
Posted into Business @business-bloomberg
gaming.hwupgrade.it/news/video…
I giochi non sono i tuoi e posso chiederti di distruggerli: il nuovo (assurdo) aggiornamento di Ubisoft
Ubisoft ha aggiornato il suo EULA, imponendo la distruzione delle copie dei giochi in caso di cessazione del supporto.Hardware Upgrade
Alex 🐘 reshared this.
reshared this
The image shows a group of people sitting around a long white table in a well-lit indoor setting, likely a conference or event space. They are all wearing blue t-shirts with a logo on the left side, suggesting they are part of the same team or organization. The table is set with water bottles, glasses, and some papers, indicating a meal or break time. The individuals are engaged in conversation, with some looking at the camera and others focused on their surroundings. In the background, other attendees are visible, seated at similar tables, contributing to a busy atmosphere. The setting includes plants and a modern design, with white walls and pillars. The overall mood appears to be casual and collaborative.
Provided by @altbot, generated privately and locally using Ovis2-8B
🌱 Energy used: 0.163 Wh
ca.wikipedia.org/wiki/Viquip%C…
Deciding to use an external library for convenience can take its toll. My latest blog post explains what happened some days ago and why I moved away from Ktorfit, halting all my other (more needed) tasks.
livefasteattrashraccoon.github…
Why I decided to migrate away from the Ktorfit library
Why maintaining an open source app is hard…LiveFastEatTrashRaccoon (Procyon Project Blog)
Poliverso - notizie dal Fediverso ⁂ likes this.
reshared this
anyway, i'm glad i found raccoon developer on mastodon, it's the best lemmy client ever for android, thanks. sadly it doesn't really recognized 🥲
i love the appearance of full post layout but i don't like the way it also shows the body of the post on the timeline, is changing the post body max lines to 0 do-able? i'll make the issue for this in github if it's possible to implement, i won't if it's a 'wontfix'.
changing post body max lines to 0 making it will be unlimited
Poliverso - notizie dal Fediverso ⁂ likes this.
Poliverso - notizie dal Fediverso ⁂ reshared this.
Poliverso - notizie dal Fediverso ⁂ likes this.
youtube.com/watch?v=5USCRxbcH_…
- YouTube
Profitez des vidéos et de la musique que vous aimez, mettez en ligne des contenus originaux, et partagez-les avec vos amis, vos proches et le monde entier.www.youtube.com
theguardian.com/technology/202…
Musk’s AI firm forced to delete posts praising Hitler from Grok chatbot
The popular bot on X began making antisemitic comments in response to user queriesJosh Taylor (The Guardian)
darum zahl ich alles nur noch mit münzen
netzpolitik.org/2025/bargeld-t…
Bargeld-Tracking: Du hast Überwachungsinstrumente im Portemonnaie
Bargeld gilt als anonymes Zahlungsmittel. Dabei ist anhand der Seriennummer durchaus ersichtlich, welche Routen Geldscheine nehmen. Die Infrastruktur zum Bargeld-Tracking wird immer weiter ausgebaut.netzpolitik.org
Google Maps: Große Neuerung für Radfahrer kommt: watson.de/leben/mobilitaet-ver…
Vorschläge für den Verkehrsknotenpunkt: Hamburgs besserer Hauptbahnhof: taz.de/Vorschlaege-fuer-den-Ve…
Agora-Verkehrswende-Radar: Noch immer weniger Pkw als vor Corona: vision-mobility.de/news/agora-…
Berlin rollt Verkehrs-Spielteppich aus: bz-berlin.de/ticker/berlin-rol…
ZDK kritisiert Merz Kurs für E-Mobilität: kfz-betrieb.vogel.de/zdk-kriti…
ZDK kritisiert Merz Kurs für E-Mobilität
Die Elektromobilität braucht eine klare Richtung, fordert der ZDK und kritisiert die Bundesregierung. Bei seinem 25.Nick Luhmann (»kfz-betrieb«)
#3DPrinting
Arachne wall generator, or if that's already enabled try adjusting the line width.
You can also try playing with XY compensation if dimensional accuracy is not crucial.
This recent video touched upon the same thing, and why it leads to loss of nozzle pressure and reduced print quality
youtu.be/7MOKjQxbP18
youtube.com/watch?v=IUevS6ANNv…
- YouTube
Profitez des vidéos et de la musique que vous aimez, mettez en ligne des contenus originaux, et partagez-les avec vos amis, vos proches et le monde entier.www.youtube.com
Das Bild zeigt einen Screenshot eines Online-Artikels von T-Online. Der Titel des Artikels lautet: "Droht die Mega-Hitzewelle in Deutschland? Plötzlich ändern sich die Wettermodelle." Der Artikel wurde vor 23 Stunden veröffentlicht und stammt von Leon Pollok. Der Hintergrund des Screenshots ist schwarz, und der Text ist in weißer Schrift dargestellt.
Bereitgestellt von @altbot, privat und lokal generiert mit Ovis2-8B
🌱 Energieverbrauch: 0.099 Wh
theguardian.com/us-news/2025/j…
US only has 25% of all Patriot missile interceptors needed for Pentagon’s military plans
Exclusive: Low stockpiles for the crucial Patriot missile interceptors led to Trump administration pausing transfers to UkraineHugo Lowell (The Guardian)
Deutsche #Solarindustrie:
Mit der nun angemeldeten Insolvenz der Glasmanufaktur Brandenburg GmbH (GMB) geht wohl die letzte Solarglasfirma Europas unter.
Die GMB sitzt nicht in Frankfurt (Oder), sondern in Tschernitz in der Lausitz. Wenn die GMB hier zusperrt, dann gehen 248 Jobs flöten - in einem Landkreis (Spree-Neiße), in dem die #AfD bei der Bundestagswahl 61,9 Prozent der Stimmen erhielt.
nd-aktuell.de/artikel/1192448.…
Aus für letzte Solarglasfirma Europas
Ein Bonus für Solarglas aus heimischer Produktion hätte die Glasmanufaktur Brandenburg in Tschernitz retten können. Doch weder die alte Bundesregierung noch die neue haben in dieser Hinsicht etwas unternommen.nd-aktuell.de
Dass die AfD da so viele Stimmen hat, ist Scheiße, aber irrelevant. Vorrangig ist doch, dass Arbeit in einem ohnehin strukturschwachen Gebiet verloren geht. Sinnvolle Arbeit in einem Bereich, der zu den Zukunftstechnologien gehört. Gute Wirtschaftspolitik hätte das verhindert und so den Menschen vor Ort eine Perspektive geboten.
Was wir bräuchten, wäre eine neue Treuhand, die solche Firmen in staatlicher Führung übernimmt und ausbaut. Für eine bessere Zukunft für alle.
FIFA opens New York office in U.S. president’s Trump Tower
FIFA opens New York office in U.S. president’s Trump Tower
FIFA boss Gianni Infantino has forged strong links with Trump as the U.S. is hosting this summer's Club World Cup.Matt Slater (The Athletic)
Durchschnittlich 8 Tote und fast 1 000 Verletzte pro Tag bei Verkehrsunfällen im Jahr 2024
Im Jahr 2024 sind in Deutschland 2 770 Menschen bei Straßenverkehrsunfällen gestorben. Das waren 69 Getötete weniger als im Jahr 2023 (2 839) und in etwa so viele wie im Jahr 2022 (2 788).Statistisches Bundesamt
rnd.de/wissen/studie-zahl-der-…
Studie: Zahl der Hitzetoten in Europa hat sich durch Klimawandel verdreifacht
Hitzewellen in europäischen Städten fordern immer mehr Menschenleben. Der Grund dafür ist der Klimawandel, wie Berechnungen britischer Forschender zeigen.Irene Habich (RedaktionsNetzwerk Deutschland)
GR Valle d'Aosta del 09/07/2025 ore 12:10
GR Regionale Valle d'Aosta. Le ultime notizie della regione Valle d'Aosta aggiornate in tempo reale. - Edizione del 09/07/2025 - 12:10
ISRAEL COMMITS MURDER!
Israel kills 105 Palestinians in Gaza in the past 24 hours
Seeking food aid in Gaza is a deadly endeavor...
#AureFreePress #News #press #headline #Israel #gaza #Hamas #BreakingNews #Breaking
aljazeera.com/news/liveblog/20…
LIVE: Israel kills 105 Palestinians in Gaza in 24 hours
Leaders of Israel and the US meet for the second time in 24 hours about a ceasefire in Gaza, without a breakthrough.Tim Hume (Al Jazeera)
10 Substack Alternatives That Work for Me in 2025
I listed 10 paid and free Substack alternatives recommended by content creators. These newsletter tools are beehiiv, Kit, and Mighty Networks, to name a few.Victoria Kurichenko (Self Made Millennials)
PIC Burnout: Dumping Protected OTP Memory in Microchip PIC MCUs
Normally you can’t read out the One Time Programming (OTP) memory in Microchip’s PIC MCUs that have code protection enabled, but an exploit has been found that gets around the copy protection in a range of PIC12, PIC14 and PIC16 MCUs.
This exploit is called PIC Burnout, and was developed by [Prehistoricman], with the cautious note that although this process is non-invasive, it does damage the memory contents. This means that you likely will only get one shot at dumping the OTP data before the memory is ‘burned out’.
The copy protection normally returns scrambled OTP data, with an example of PIC Burnout provided for the PIC16LC63A. After entering programming mode by setting the ICSP CLK pin high, excessively high programming voltage and duration is used repeatedly while checking that an area that normally reads as zero now reads back proper data. After this the OTP should be read out repeatedly to ensure that the scrambling has been circumvented.
The trick appears to be that while there’s over-voltage and similar protections on much of the Flash, this approach can still be used to affect the entire flash bit column. Suffice it to say that this method isn’t very kind to the fzslash memory cells and can take hours to get a good dump. Even after this you need to know the exact scrambling method used, which is fortunately often documented by Microchip datasheets.
Thanks to [DjBiohazard] for the tip.
Companies That Tried to Save Money With #AI Are Now Spending a Fortune Hiring People to Fix Its Mistakes.
Oopsie.
futurism.com/companies-fixing-…
Companies That Tried to Save Money With AI Are Now Spending a Fortune Hiring People to Fix Its Mistakes
Companies that rushed to replace human labor with AI are now shelling out to have IRL workers to fix the technology's screwups.Noor Al-Sibai (Futurism)
Fische haben verändertes Erbgut
"Hochdramatische" Entdeckung in der Ostsee
t-online.de/nachrichten/panora…
Wissenschaftler haben eine durch Menschen ausgelöste Evolution in der Ostsee festgestellt. Demnach veränderte sich der Dorsch innerhalb von nur 25 Jahren......
Mansa reshared this.
Google e Microsoft si sono fidati di loro. 2,3 milioni di utenti li hanno installati. Erano malware.
parzialmente tradotto da: blog.koi.security/google-and-m…
TL;DR - La nostra indagine su un singolo contagocce “verificato” ha rivelato una campagna coordinata di 18 estensioni dannose che hanno infettato ben 2,3 milioni di utenti su Chrome ed Edge.
Se pensi che un'estensione di Chrome con il badge verificato di Google, oltre 100.000 installazioni, oltre 800 recensioni e un posizionamento in evidenza nello store sia affidabile? Ripensaci.
Vi presentiamo “Color Picker, Eyedropper — Geco colorpick”, un'estensione che dimostra perfettamente come attori di minacce sofisticati stiano sfruttando i segnali di fiducia su cui facciamo affidamento. Non si tratta di una palese estensione truffa messa insieme in un fine settimana. Questo è un cavallo di Troia accuratamente realizzato che offre esattamente ciò che promette (un selettore di colori funzionale) mentre contemporaneamente dirotta il browser, traccia ogni sito web visitato e mantiene una backdoor persistente di comando e controllo. Non solo, ma è rimasto legittimo per anni prima di diventare malevolo tramite un aggiornamento di versione.
Se ciò non bastasse, ecco la campagna RedDirection . La nostra indagine sull'estensione Color Picker ha rivelato che era solo la punta dell'iceberg. Analizzando l'infrastruttura di comando e controllo e tracciando schemi di codice simili, abbiamo scoperto quella che chiamiamo la campagna RedDirection, una sofisticata rete multipiattaforma di diciotto estensioni dannose che coprono sia i negozi Chrome che Edge, tutte con la stessa funzionalità di dirottamento. Complessivamente, queste diciotto estensioni hanno infettato oltre 2,3 milioni di utenti su entrambi i browser, creando una delle più grandi operazioni di dirottamento del browser che abbiamo documentato.
Queste estensioni si mascherano da popolari strumenti di produttività e intrattenimento in diverse categorie: tastiere emoji, previsioni meteo, controller di velocità video, proxy VPN per Discord e TikTok, temi scuri, amplificatori di volume e sbloccatori di YouTube. Ognuna fornisce funzionalità legittime mentre implementa segretamente le stesse capacità di sorveglianza e dirottamento del browser che abbiamo scoperto nel selettore di colori.
Molte di queste estensioni hanno ottenuto lo stato verificato o il posizionamento in primo piano sia nel Chrome Web Store che nel Microsoft Edge Add-ons store, dimostrando che i fallimenti della sicurezza si estendono a entrambi i principali marketplace dei browser. Ogni estensione opera con il proprio sottodominio di comando e controllo (come admitclick.net, click.videocontrolls.com, c.undiscord.com), dando l'impressione di operatori separati pur facendo parte della stessa infrastruttura di attacco centralizzata che si estende su entrambe le piattaforme.
Google and Microsoft Trusted Them. 2.3 Million Users Installed Them. They Were Malware.
TL;DR - Our investigation of a single “verified” color picker exposed a coordinated campaign of 18 malicious extensions that infected a massive 2.3 million users across Chrome and Edge. If you think…Idan Dardikman (Koi Security)
reshared this
Gum on China’s Shoe
in reply to Information Is Beautiful • • •