Salta al contenuto principale




BruteForceAI: Quando l’IA impara a bucare i login meglio di un Hacker umano


BruteForceAI è un nuovo framework di penetration testing che unisce intelligenza artificiale e automazione per portare il brute-force a un livello superiore. Sviluppato da Mor David, lo strumento utilizza modelli linguistici di grandi dimensioni per analizzare automaticamente i moduli di login e condurre attacchi mirati in modo più veloce ed efficace. A differenza delle soluzioni tradizionali, non richiede configurazioni manuali complesse e riduce il rischio di errori umani, semplificando il lavoro degli specialisti di sicurezza.

Come funziona e a cosa serbe BruteForceAI


Il funzionamento si articola in due momenti distinti. In una prima fase, l’LLM analizza l’HTML della pagina target e individua con estrema precisione campi di input, pulsanti e selettori CSS. Successivamente entra in gioco la cosiddetta “fase Smart Attack”, durante la quale il tool lancia test di credenziali multi-thread sfruttando i selettori rilevati. L’utente può scegliere tra un approccio brute-force classico, che prova tutte le combinazioni possibili, oppure la modalità password-spray, più discreta e utile per ridurre i rischi di blocco.

Tra i punti di forza ci sono le capacità di evasione. Lo strumento è in grado di imitare il comportamento umano grazie a ritardi temporizzati e jitter casuale, alterna gli user-agent, supporta l’uso di proxy e controlla la visibilità del browser. Questo rende gli attacchi più difficili da intercettare da parte dei sistemi di difesa automatizzati. Inoltre, registra tutto in un database SQLite e invia notifiche immediate tramite webhook a piattaforme come Slack, Discord, Teams o Telegram.

Per chi si avvicina al penetration testing, BruteForceAI offre una chiave di lettura interessante. Non si tratta solo di un software per lanciare attacchi, ma di un supporto per comprendere come funzionano i meccanismi di autenticazione e quanto siano vulnerabili se non adeguatamente protetti. Usato in contesti autorizzati, diventa un alleato per imparare, testare e migliorare le difese informatiche senza dover scrivere codice complesso.

Per Red Team e non per Criminali informatici?


La sua adozione è pensata soprattutto per red team, ricercatori di sicurezza e professionisti che svolgono test su incarico. Automatizzando passaggi solitamente lenti e ripetitivi, riduce drasticamente i tempi di analisi e rende più immediato il rilevamento di sistemi di login deboli. È un esempio concreto di come l’intelligenza artificiale possa migliorare strumenti già consolidati, trasformando un processo manuale e noioso in un flusso ottimizzato.

Dal punto di vista tecnico, l’installazione non è complicata. Sono necessari Python 3.8 o superiore, Playwright e alcune librerie standard come requests e PyYAML. Dopo aver clonato il repository da GitHub ed eseguito il comando pip install -r requirements.txt, è possibile scegliere il modello linguistico da utilizzare: Ollamaper un’esecuzione locale o Groq per lavorare in cloud. Una volta configurato, il tool si avvia con comandi semplici per l’analisi degli obiettivi e l’esecuzione degli attacchi.

È importante sottolineare che BruteForceAI è destinato esclusivamente a scopi etici e professionali: test autorizzati, ricerca accademica e attività formative. L’utilizzo improprio contro sistemi non autorizzati è illegale e contrario all’etica professionale.

Nelle mani giuste, però, rappresenta una risorsa preziosa per scoprire vulnerabilità e rinforzare la sicurezza dei sistemi digitali, avvicinando nuove generazioni di specialisti a metodologie più intelligenti e consapevoli.

L'articolo BruteForceAI: Quando l’IA impara a bucare i login meglio di un Hacker umano proviene da il blog della sicurezza informatica.



We celebrate Labor Day in September rather than May 1st in the United States because the Grover Cleveland administration worried that celebrating it in May like other countries would strengthen left-wing movements around the world. Enjoy your day!


In the previous part of my ongoing series to save "The Masters of the Elements", we finally fixed the game itself by removing the broken library and replacing it with a more modern alternative.

However, we are not done yet - there are still some minor issues left to fix. Let’s go!

fabulous.systems/posts/2025/08…

#retrogaming #retrocomputing #digipres



I used to really enjoy being creeped out by 70s dystopias but it’s no fun anymore


Knapp eine Tasse pro Tag: Dieses Hydrogel gewinnt Trinkwasser aus der Luft

Das neue Material sammelt sogar im Death Valley, dem trockensten Ort der Welt, genug Wasser, um einen Haushalt zu versorgen.

heise.de/news/Knapp-eine-Tasse…

#Forschung #Wissenschaft #news



kernelnuggets.com/artificial-i…



His cute tummy was not a trap two days in a row. This is an actual miracle :catLaugh: #Cats
#cats
in reply to Bruno Miguel

The image shows a cat lying on its back on a bed with a checkered quilt. The cat has a light brown and white coat with darker brown markings on its face, ears, and tail. Its belly is white, and its paws are white with black tips. The cat's eyes are closed, and it appears to be sleeping peacefully. The quilt has a pattern of squares in shades of pink, gray, and purple. The cat's tail is long and black, extending towards the bottom right corner of the image. The cat's body is relaxed, with its legs slightly bent and its paws up in the air.

Provided by @altbot, generated privately and locally using Ovis2-8B

🌱 Energy used: 0.167 Wh




TL;DR: NetDocuments has introduced its Judge Analytics App as part of its ndMAX Studio Apps, expanding its offerings beyond traditional document management services. artificiallawyer.com/2025/09/0… #law #tech #legaltech ⚖️ 🤖 #autosum


The XML grammar is ambiguous. The grammar for XML grammars is infinitely ambiguous. That came as a surprise to me. #XML

so.nwalsh.com/2025/08/31-ambig…

#xml


Schon gehört? 😳 Rot-Pink schnalzt die Öffi-Preise massiv in die Höhe: Das Wiener Jahresticket wird 467 Euro pro Jahr kosten, also um ganze 100 Euro teurer werden!

💥Wir Grüne finden das richtig oag. Du auch? Dann unterschreib unsere Petition:
✍️ wien.gruene.at/petition-jahres…

#wien #wienerlinien #preiserhöhung #öffis

in reply to Neubauer Grüne

dafür leisten die Öffis in #Wien auch richtig viel. Im Gegensatz zu Parkplätzen: Die wurden massiv reduziert und müssten daher günstiger werden.
#wien


We're delighted to welcome Kirstie Whitaker of the #BerkeleyInstituteForDataScience (BIDS) to the #CURIOSS community!

We're looking forward to learning more about Kirstie's work with the #UniversityOfCaliforniaBerkeley #OSPO

ℹ️ Learn about UC Berkeley OSPO: ospo-berkeley-edu.netlify.app/

🔍 Find out more about the #UniversityOfCalifornia Open Source Program Office Network: ucospo.net/

#academicOSPOs #academicOSS #opensourcesoftware #openscience #opensource #OSScommunity




Searchlight: **Thousands raised by far right in Dundee ‘migrant attack’ case police say didn’t happen**

searchlightmagazine.com/2025/0…

From the moment UK fascists started to focus on a disturbing incident that happened in Dundee, Scotland, we knew something was wrong. A video, obviously made on a mobile phone, started to circulate on fascist social media channels. The footage showed two very



»Melanie Amann: Vize-Chefredakteurin verlässt „Spiegel“« taz.de/Melanie-Amann/!6110917/… #Medien #SocialMedia


So if I'm reading this new Google thing right
Basically it's a continuation of their play verification for apps downloaded from Google play
The only application I have on my phone that is not play verified is a patched discord app which obviously won't have a developer ID on it
This shouldn't affect pretty much anything except pirated Google play apps and modified apks, which makes sense from a developer and security first standpoint
This may affect apps like ReVanced (which you shouldn't be using anyways please consider grayjay newpipe or something else that does not use the YouTube APK)
As far as I know Google does not become the arbiter of what developers are allowed to ID their applications so apps like grayjay should remain installable despite violating Google play policy
in reply to argo

if youre "degoogling" but you still depend on downloading applications only available on the play store, and youre using something like aurora store or apk mirrors, you'll probably be affected by this
Grapheneos I'm pretty sure has access to the Google play store and I think Daniel said it's the most secure way to install Google play distributed applications anyways so it should be a non issue
in reply to waffles

It isn't an issue for GrapheneOS because it doesn't have Google Mobile Services to enforce rules about which apps can be installed. If people install sandboxed Google Play, that doesn't have the ability to block installing apps since they're regular sandboxed apps with no special access. Therefore, whatever rules they come up with for requirements apps must meet to be installed are not relevant. Play Integrity API is what's problematic: apps banning using non-GMS devices/OSes.


Diese wissenschaftlichen Gesellschaften sind auf Mastodon aktiv:
🔹 Astronomische Gesellschaft @GermanAstroSoc
🔹Digital Humanities im deutschsprachigen Raum @DHd
🔹Deutsche Gesellschaft für die Erforschung des 18. Jahrhunderts
@DGEJ
🔹Deutsche Gesellschaft für Erziehungswissenschaft @DGfE_eV
🔹 Deutsche Gesellschaft für Hochschuldidaktik @dghd_info
🔹 Deutsche Gesellschaft für Osteuropakunde e.V. @dgo_berlin
🔹 Deutsche Gesellschaft für Soziologie @dgsoziologie
🔹Deutscher Verband für Kunstgeschichte @kunstgeschichte
🔹 Gesellschaft für Informatik @informatik
🔹 Gesellschaft für Medien in der Wissenschaft @gmw
🔹Verband der Historiker und Historikerinnen Deutschlands e.V @VHD
🔹Verband Deutscher Vermessungsingenieure e.V. @vdv

Vielen Dank an
@gewam und @julian für die Mithilfe bei der Erstellung der Liste! 🙏
Die Auflistung in der von @scammo erstellten Liste
👉 mastodon-listen.playground.54g…
bedarf noch weiterer Einträge auf #Wikidata.
Sagt gerne Bescheid, wenn Ihr noch weitere kennt.

#UnisInsFediverse #WissKomm

reshared this



Wife, kid and me all went to game night with cousins/friends last night. I almost bowed out but I’m really glad I went. We played jackbox games on the Switch and had a ball



Friendly reminder

Inequality and climate breakdown are one crisis.

🔥 Climate chaos and obscene inequality are two sides of the same coin.⁣
💸 The richest 1% emit more than the poorest 66%.⁣
🌡️ The world’s richest 10% are responsible for over two-thirds of global warming.⁣
💥 The poorest pay the highest price.⁣

Let's #TaxTheSuperRich to fund a fairer, greener future 👉 act.gp/4lW1CI7

#TimeToResist #TaxTheSuperRich #ClimateJustice #ClimateCrisis #LivesBeforeProfits #FightInequality

reshared this



Lo specchio del tempo

media.inaf.it/2025/09/01/lo-sp…

> Spazio e tempo, simmetrie e asimmetrie, destra e sinistra. Sono i concetti affrontati da Giorgio Chinnici nel saggio divulgativo



Fiscalità del lavoro a portata di mano

sabato 27 settembre dalle 10 alle 13 presso la sede di MAG2 in Via Angera 3 a Milano

mag2.it/notizie/748-fiscalita-…

#Milano #MAG2 #fisco #lavoro



Nicht ineinerwocheimclub, aber weil es besonders besonders ist:

---
ELECTRONIC BODY MOVIE ‐ EBM
Film (OMU) + Rahmenprogramm

16.10.2025 | 20:00 Uhr
Eintritt: 15€ / Ermäßigter Eintritt: 13€

Vorverkauf: rausgegangen.de/events/ebm-mov…

Der Electronic Body Movie hat keinen regulären Vertrieb und läuft nur als Event. Es empfiehlt sich daher rechtzeitig Tickets zu sichern.

---
Vor dem Film gibt es eine kurze Einleitung von Antonio Marquês Bras ‐ Media Artist und Musiker, der Mitte der 80er die ersten EBM‐Bands in den süddeutschen Raum brachte.

---
Im Anschluss EBM/Industrial‐Musik mit BINARx (alias Antonio Marquês Bras).
Exklusiv für den Slow Club wird er an diesem Abend zum ersten Mal zwei Tracks von BINAR vorstellen die er u.a. mit Itchy (Shock Therapy) Anfang der 90er in Detroit aufgenommen hat und bisher unveröffentlicht waren.

---
DER FILM
Electronic Body Movie - EBM ist die erste Dokumentation, in der die Geschichte und Wiederentdeckung der Electronic Body Music (EBM) beleuchtet wird, die in Deutschland und Belgien in den frühen 80ern begann. EBM stellt eine Tanzflächen‐orientierte Weiterentwicklung der Industrial‐Musik dar, mit tiefen Wurzeln im Post‐Punk und der Neuen Deutschen Welle. Wegweisende Bands wie die Deutsch Amerikanische Freundschaft (DAF), Front 242 und Liaisons Dangereuses u.a. legten den Grundstein für diesen neuen Musikstil, der durch stampfende Beats, aggressiven Gesang und sequenzierte Synthie‐Bässe geprägt war. Adrenalingeladene Live‐Shows, kontroverse Texte und provokante Looks schockierten die Musikpresse, beflügelten die Fantasie des Publikums und hinterließen eine brennende Spur in den Herzen und Köpfen ihrer Anhänger.

Vier Jahrzehnte später gilt die EBM als wichtiger Vorläufer des Techno und der modernen Clubbing‐Musik. Eine große und treue Fangemeinde aus der ganzen Welt hält den Kult am Leben und organisiert regelmäßig Festivals und spezielle Veranstaltungen. Der Dokumentarfilm ist eine visuelle Reise in den ikonischen Sound der EBM, voller seltener Archivvideos, unveröffentlichtem Live‐Material und exklusiven Interviews. Aktuelle DJs und Produzenten berichten, wie sie bis heute von diesen Einflüssen inspiriert werden. Dabei wird enthüllt, was hinter der Langlebigkeit dieser Musik steckt und wie sie die elektronische Musik weiterhin prägt.

YouTube: m.youtube.com/watch?v=vuDgDKMo…

#slowclub #ebm #film #freiburg



Emily Blunt è una sirena al Festival di Venezia 2025: l'abito con spalline gioiello in stile mermaidcore
https://www.vogue.it/article/emily-blunt-festival-di-venezia-2025-look?utm_source=flipboard&utm_medium=activitypub

Pubblicato su Moda @moda-VogueItalia

@Moda


youtube.com/watch?v=qRcYjJQ0JH…

FreedomPatriot reshared this.



Amal Clooney con scarpe Prada e borsa naturale: il look Dolcevita a Venezia
https://www.vogue.it/article/amal-clooney-scarpe-prada-look-dolcevita-venezia?utm_source=flipboard&utm_medium=activitypub

Pubblicato su Moda @moda-VogueItalia

@Moda


French government be like: Yeah let's use only American tech.
in reply to Benoit

The image displays a security verification page from the website www.info.gouv.fr. The background is dark gray, and the text is white. At the top, the website address "www.info.gouv.fr" is prominently displayed. Below it, there is a message instructing the user to "Verify you are human by completing the action below." A checkbox labeled "Verify you are human" is present, accompanied by the Cloudflare logo, indicating that Cloudflare is managing the security. The message below states that "www.info.gouv.fr needs to review the security of your connection before proceeding." The overall layout is simple, with clear instructions and a focus on security verification.

Provided by @altbot, generated privately and locally using Ovis2-8B

🌱 Energy used: 0.139 Wh



When big breakthroughs are required, Hattie can't be stopped.

reshared this



The #Mainstreaming communication is Hallucinating

They call it communication, but it’s not dialogue, not listening, not truth.

It’s hallucination: Smiling faces repeating empty words. Buzzwords covering the rot.
Smoke and mirrors to hide power.

While they hallucinate, the #deathcult stays at the centre.

Our path is not their delusion. Our task is composting — shovel in hand — to grow something real.

#4opens #OMN #KISS



💬 Ein älteres Zitat...

Die Grundaussage im zweiten Satz trift immer noch VOLLUMFÄNGLICH zu❗

in reply to » Aakerbeere 🏖️

Das Bild zeigt einen Text auf einem warmen, braunen Hintergrund mit einem Textur-Effekt, der an ein altes Papier erinnert. Der Text ist in weißer Schrift geschrieben und lautet: "Ich finde es sehr ärgerlich, wenn sich Journalisten hier über Xxitter X beschweren. Diese Plattformen bleiben nur bestehen, weil Sie sie weiterhin nutzen." Der Name "mxthxw" ist in kleinerer Schrift am rechten Rand des Bildes zu sehen, was darauf hinweist, dass es sich um ein Zitat handelt. Der Text vermittelt eine kritische Meinung zu einer Plattform, die von Journalisten kritisiert wird, und betont die Abhängigkeit der Plattform von ihrer Nutzung durch die Nutzer.

Bereitgestellt von @altbot, privat und lokal generiert mit Ovis2-8B

🌱 Energieverbrauch: 0.203 Wh



I should not have tried a ghost chilli sauce on an empty stomach.
in reply to Feff

I'm not a lightweight any more since my friend is a Kimchi connoisseur and creates different variants with changing amount of chilli hotness ... but Ghost pepper, and on an empty stomach?
Uhhhhhh hopefully everything went well and is going well 😅


“Crediamo più nei ponti che nei muri”: srotolata una bandiera per la Palestina
L'iniziativa di un gruppo di cittadini a sostegno alla Global Sumud Flotilla

luccaindiretta.it/in-sociale/2…



Tira e molla con la Juve, poi Kolo Muani va al Tottenham: sì del Psg al prestito senza obbligo
https://www.gazzetta.it/Calciomercato/01-09-2025/juve-kolo-muani-al-tottenham-l-accordo-col-psg.shtml?utm_source=flipboard&utm_medium=activitypub

Pubblicato su Calcio @calcio-Gazzetta



@dansup Is there any special setting I have to check to use the pixelfed embed feature? I have it enabled in the .env file, but if I try to embed it, it shows nothing. The only account I managed to make it work with is yours from pixelfed.social. No luck with accounts from other servers as well.


All summer I’ve been trying to get close enough to one of the huge female snakes to get a good photo of her pattern and coloring. But I haven’t yet because, you know, MASSIVE SNAKE. But yesterday she was in the perfect position (ie. not looking at me.) 😄

Sensitive content

Oblomov reshared this.

Unknown parent

mastodon - Collegamento all'originale
Dan McCullough
All summer I’ve been trying to get close enough to one of the huge female snakes to get a good photo of her pattern and coloring. But I haven’t yet because, you know, MASSIVE SNAKE. But yesterday she was in the perfect position (ie. not looking at me.) 😄

Sensitive content



Perché l’agenzia di rating Fitch tagliuzza Baidu, la Google cinese. Troppa concorrenza per la Big Tech asiatica?
https://startupitalia.eu/economy/fitch-rating-outloog-negativo-baidu/?utm_source=flipboard&utm_medium=activitypub

Posted into Ischool @ischool-StartupItalia



Mamma o papà? Alcuni geni possono avere effetti opposti a seconda del genitore da cui si ereditano
https://www.lastampa.it/salute/dossier/labrevolution/2025/09/01/news/mamma_o_papa_alcuni_geni_possono_avere_effetti_opposti_a_seconda_del_genitore_da_cui_si_ereditano-424819485/?utm_source=flipboard&utm_medium=activitypub

Pubblicato su La Stampa Spettacoli @la-stampa-spettacoli-LaStampa



El meu cap visualitza una pallissa estil Bud Spencer però sense riure, només les hòsties:

rac1.cat/societat/20250901/285…