Salta al contenuto principale



Mostra del Cinema di Venezia 2025, arriva il film italiano di Maresco

VENEZIA – Nel penultimo giorno dell’82esima edizione della Mostra Internazionale del Cinema di Venezia arriva il 5 settembre “Un film fatto per bene” di Franco Maresco, l’ultimo dei cinque film…
L'articolo Mostra del Cinema di Venezia 2025, arriva il film italiano di Maresco su Lumsanews.


Yoox annuncia 211 licenziamenti in Italia. I sindacati proclamano sciopero da sedici ore

[quote]I lavoratori di Yoox Net a Porter scendono in campo contro l'annuncio di licenziamento collettivo da parte del colosso dello shopping online nelle sedi di Bologna e Milano
L'articolo Yoox annuncia 211 licenziamenti in Italia. I sindacati proclamano sciopero da



Mosca avverte l’Ue: “Truppe in Ucraina bersaglio legittimo”. Zelensky: “Garanzie subito”

[quote]MOSCA – Le “truppe occidentali in Ucraina sono un bersaglio legittimo”. Le dure parole del presidente russo Vladimir Putin riassumono la presa di posizione del Cremlino nei confronti dell’Europa. A…
L'articolo Mosca avverte l’Ue: “Truppe in Ucraina bersaglio

Associazione Peacelink reshared this.



IT threat evolution in Q2 2025. Mobile statistics
IT threat evolution in Q2 2025. Non-mobile statistics

The mobile section of our quarterly cyberthreat report includes statistics on malware, adware, and potentially unwanted software for Android, as well as descriptions of the most notable threats for Android and iOS discovered during the reporting period. The statistics in this report are based on detection alerts from Kaspersky products, collected from users who consented to provide anonymized data to Kaspersky Security Network.

Quarterly figures


According to Kaspersky Security Network, in Q2 2025:

  • Our solutions blocked 10.71 million malware, adware, and unwanted mobile software attacks.
  • Trojans, the most common mobile threat, accounted for 31.69% of total detected threats.
  • Just under 143,000 malicious installation packages were detected, of which:
    • 42,220 were mobile banking Trojans;
    • 695 packages were mobile ransomware Trojans.



Quarterly highlights


Mobile attacks involving malware, adware, and unwanted software dropped to 10.71 million.

Attacks on users of Kaspersky mobile solutions, Q4 2023 — Q2 2025 (download)

The trend is mainly due to a decrease in the activity of RiskTool.AndroidOS.SpyLoan. These are applications typically associated with microlenders and containing a potentially dangerous framework for monitoring borrowers and collecting their data, such as contacts lists. Curiously, such applications have been found pre-installed on some devices.

In Q2, we found a new malicious app for Android and iOS that was stealing images from the gallery. We were able to determine that this campaign was linked to the previously discovered SparkCat, so we dubbed it SparkKitty.

Fake app store page distributing SparkKitty
Fake app store page distributing SparkKitty

Like its “big brother”, the new malware most likely targets recovery codes for crypto wallets saved as screenshots.

Trojan-DDoS.AndroidOS.Agent.a was this past quarter’s unusual discovery. Malicious actors embedded an SDK for conducting dynamically configurable DDoS attacks into apps designed for viewing adult content. The Trojan allows for sending specific data to addresses designated by the attacker at a set frequency. Building a DDoS botnet from mobile devices with adult apps installed may seem like a questionable venture in terms of attack efficiency and power – but apparently, some cybercriminals have found a use for this approach.

In Q2, we also encountered Trojan-Spy.AndroidOS.OtpSteal.a, a fake VPN client that hijacks user accounts. Instead of the advertised features, it uses the Notification Listener service to intercept OTP codes from various messaging apps and social networks, and sends them to the attackers’ Telegram chat via a bot.

Mobile threat statistics


The number of Android malware and potentially unwanted app samples decreased from Q1, reaching a total of 142,762 installation packages.

Detected malware and potentially unwanted app installation packages, Q2 2024 — Q2 2025 (download)

The distribution of detected installation packages by type in Q2 was as follows:

Detected mobile malware by type, Q1 — Q2 2025 (download)

* Data for the previous quarter may differ slightly from previously published data due to some verdicts being retrospectively revised.

Banking Trojans remained in first place, with their share increasing relative to Q1. The Mamont family continues to dominate this category. In contrast, spy Trojans dropped to fifth place as the surge in the number of APK files for the SMS-stealing Trojan-Spy.AndroidOS.Agent.akg subsided. The number of Agent.amw spyware files, which masquerade as casino apps, also decreased.

RiskTool-type unwanted apps and adware ranked second and third, respectively, while Trojans – with most files belonging to the Triada family – occupied the fourth place.

Share* of users attacked by the given type of malicious or potentially unwanted apps out of all targeted users of Kaspersky mobile products, Q1 — Q2 2025 (download)

* The total may exceed 100% if the same users experienced multiple attack types.

The distribution of attacked users remained close to that of the previous quarter. The increase in the share of backdoors is linked to the discovery of Backdoor.Triada.z, which came pre-installed on devices. As for adware, the proportion of users affected by the HiddenAd family has grown.

TOP 20 most frequently detected types of mobile malware


Note that the malware rankings below exclude riskware or potentially unwanted software, such as RiskTool or adware.

Verdict%* Q1 2025%* Q2 2025Difference (p.p.)Change in rank
Trojan.AndroidOS.Fakemoney.v26.4114.57-11.840
Trojan-Banker.AndroidOS.Mamont.da11.2112.42+1.20+2
Backdoor.AndroidOS.Triada.z4.7110.29+5.58+3
Trojan.AndroidOS.Triada.fe3.487.16+3.69+4
Trojan-Banker.AndroidOS.Mamont.ev0.006.97+6.97
Trojan.AndroidOS.Triada.gn2.686.54+3.86+3
Trojan-Banker.AndroidOS.Mamont.db16.005.50-10.50-4
Trojan-Banker.AndroidOS.Mamont.ek1.835.09+3.26+7
DangerousObject.Multi.Generic.19.304.21-15.09-7
Trojan-Banker.AndroidOS.Mamont.eb1.592.58+0.99+7
Trojan.AndroidOS.Triada.hf3.812.41-1.40-4
Trojan-Downloader.AndroidOS.Dwphon.a2.192.24+0.050
Trojan-Banker.AndroidOS.Mamont.ef2.442.20-0.24-2
Trojan-Banker.AndroidOS.Mamont.es0.052.13+2.08
Trojan-Banker.AndroidOS.Mamont.dn1.462.13+0.67+5
Trojan-Downloader.AndroidOS.Agent.mm1.451.56+0.11+6
Trojan-Banker.AndroidOS.Agent.rj1.861.45-0.42-3
Trojan-Banker.AndroidOS.Mamont.ey0.001.42+1.42
Trojan-Banker.AndroidOS.Mamont.bc7.611.39-6.23-14
Trojan.AndroidOS.Boogr.gsh1.411.36-0.06+3

* Unique users who encountered this malware as a percentage of all attacked users of Kaspersky mobile solutions.

The activity of Fakemoney scam apps noticeably decreased in Q2, but they still held the top position. Almost all the other entries on the list are variants of the popular banking Trojan Mamont, pre-installed Trojans like Triada and Dwphon, and modified messaging apps with the Triada Trojan built in (Triada.fe, Triada.gn, Triada.ga, and Triada.gs).

Region-specific malware


This section describes malware types that mostly affected specific countries.

VerdictCountry*%**
Trojan-Banker.AndroidOS.Coper.cTürkiye98.65
Trojan-Banker.AndroidOS.Coper.aTürkiye97.78
Trojan-Dropper.AndroidOS.Rewardsteal.hIndia95.62
Trojan-Banker.AndroidOS.Rewardsteal.lvIndia95.48
Trojan-Dropper.AndroidOS.Agent.smTürkiye94.52
Trojan.AndroidOS.Fakeapp.hyUzbekistan86.51
Trojan.AndroidOS.Piom.bkzjUzbekistan85.83
Trojan-Dropper.AndroidOS.Pylcasa.cBrazil83.06

* The country where the malware was most active.
** Unique users who encountered this Trojan variant in the indicated country as a percentage of all Kaspersky mobile security solution users attacked by the same variant.

In addition to the typical banking Trojans for this category – Coper, which targets users in Türkiye, and Rewatrdsteal, active in India – the list also includes the fake job search apps Fakeapp.hy and Piom.bkzj, which specifically target Uzbekistan. Both families collect the user’s personal data. Meanwhile, new droppers named “Pylcasa” operated in Brazil. They infiltrate Google Play by masquerading as simple apps, such as calculators, but once launched, they open a URL provided by malicious actors – similar to Trojans of the Fakemoney family. These URLs may lead to illegal casino websites or phishing pages.

Mobile banking Trojans


The number of banking Trojans detected in Q2 2025 was slightly lower than in Q1 but still significantly exceeded the figures for 2024. Kaspersky solutions detected a total of 42,220 installation packages of this type.

Number of installation packages for mobile banking Trojans detected by Kaspersky, Q2 2024 — Q2 2025 (download)

The bulk of mobile banking Trojan installation packages still consists of various modifications of Mamont, which account for 57.7%. In terms of the share of affected users, Mamont also outpaced all its competitors, occupying nearly all the top spots on the list of the most widespread banking Trojans.

TOP 10 mobile bankers
Verdict%* Q1 2025%* Q2 2025Difference (p.p.)Change in rank
Trojan-Banker.AndroidOS.Mamont.da26.6830.28+3.59+1
Trojan-Banker.AndroidOS.Mamont.ev0.0017.00+17.00
Trojan-Banker.AndroidOS.Mamont.db38.0713.41-24.66-2
Trojan-Banker.AndroidOS.Mamont.ek4.3712.42+8.05+2
Trojan-Banker.AndroidOS.Mamont.eb3.806.29+2.50+2
Trojan-Banker.AndroidOS.Mamont.ef5.805.36-0.45-2
Trojan-Banker.AndroidOS.Mamont.es0.125.20+5.07+23
Trojan-Banker.AndroidOS.Mamont.dn3.485.20+1.72+1
Trojan-Banker.AndroidOS.Agent.rj4.433.53-0.90-4
Trojan-Banker.AndroidOS.Mamont.ey0.003.47+3.479

Conclusion


In Q2 2025, the number of attacks involving malware, adware, and unwanted software decreased compared to Q1. At the same time, Trojans and banking Trojans remained the most common threats, particularly the highly active Mamont family. Additionally, the quarter was marked by the discovery of the second spyware Trojan of 2025 to infiltrate the App Store, along with a fake VPN client stealing OTP codes and a DDoS bot concealed within porn-viewing apps.


securelist.com/malware-report-…



Gli aggressori utilizzano Velociraptor per gli attacchi informatici. Rapid7 è al corrente


Gli specialisti della sicurezza di Sophos hanno attirato l’attenzione su un attacco informatico in cui aggressori sconosciuti hanno utilizzato lo strumento forense open source Velociraptor per monitorare gli endpoint .

“In questo incidente, gli aggressori hanno utilizzato uno strumento per scaricare ed eseguire Visual Studio Code con il probabile intento di creare un tunnel verso un server di comando e controllo”, hanno affermato gli esperti della Sophos Counter Threat Unit.

Il rapporto sottolinea che gli aggressori spesso impiegano tattiche di tipo “living-off-the-land” (LotL) e utilizzano legittimi strumenti di monitoraggio e controllo remoto negli attacchi, ma l’uso di Velociraptor segnala un’evoluzione di tali tattiche, in cui il software di risposta agli incidenti viene utilizzato per scopi dannosi.

L’analisi dell’incidente ha mostrato che gli aggressori hanno utilizzato l’utility msiexec di Windows per scaricare un programma di installazione MSI dal dominio Cloudflare Workers, che funge anche da area di staging per altre soluzioni utilizzate dagli hacker, tra cui lo strumento di tunneling Cloudflare e l’utility di amministrazione remota Radmin.

Il file MSI è stato progettato per distribuire Velociraptor, che avrebbe poi comunicato con un altro dominio Cloudflare Workers. L’accesso è stato quindi utilizzato per scaricare Visual Studio Code dallo stesso server di staging utilizzando un comando PowerShell codificato ed eseguirlo con l’opzione di tunneling abilitata per consentire sia l’accesso remoto che l’esecuzione di codice remoto.

Inoltre, è stato osservato che gli aggressori riutilizzavano l’utilità msiexec di Windows per scaricare payload aggiuntivi. “Le organizzazioni dovrebbero monitorare e indagare sull’uso non autorizzato di Velociraptor e considerare l’impiego di tali tattiche come un precursore della distribuzione di ransomware”, avverte Sophos.

In seguito alla pubblicazione di questo rapporto da parte di Sophos, la società di sicurezza Rapid7, che sviluppa Velociraptor, ha pubblicato un white paper che spiega nel dettaglio come le organizzazioni possono rilevare l’abuso di Velociraptor nei loro ambienti.

“Rapid7 è a conoscenza di segnalazioni di abusi dello strumento open source di risposta agli incidenti Velociraptor. Velociraptor è ampiamente utilizzato dai difensori per scopi legittimi di analisi forense digitale e risposta agli incidenti. Ma come molti altri strumenti di sicurezza e amministrazione, può essere utilizzato per scopi dannosi se finisce nelle mani sbagliate”, commentano gli sviluppatori.

L'articolo Gli aggressori utilizzano Velociraptor per gli attacchi informatici. Rapid7 è al corrente proviene da il blog della sicurezza informatica.



IT threat evolution in Q2 2025. Non-mobile statistics
IT threat evolution in Q2 2025. Mobile statistics

The statistics in this report are based on detection verdicts returned by Kaspersky products unless otherwise stated. The information was provided by Kaspersky users who consented to sharing statistical data.

The quarter in numbers


In Q2 2025:

  • Kaspersky solutions blocked more than 471 million attacks originating from various online resources.
  • Web Anti-Virus detected 77 million unique links.
  • File Anti-Virus blocked nearly 23 million malicious and potentially unwanted objects.
  • There were 1,702 new ransomware modifications discovered.
  • Just under 86,000 users were targeted by ransomware attacks.
  • Of all ransomware victims whose data was published on threat actors’ data leak sites (DLS), 12% were victims of Qilin.
  • Almost 280,000 users were targeted by miners.


Ransomware

Quarterly trends and highlights

Law enforcement success


The alleged malicious actor behind the Black Kingdom ransomware attacks was indicted in the U.S. The Yemeni national is accused of infecting about 1,500 computers in the U.S. and other countries through vulnerabilities in Microsoft Exchange. He also stands accused of demanding a ransom of $10,000 in bitcoin, which is the amount victims saw in the ransom note. He is also alleged to be the developer of the Black Kingdom ransomware.

A Ukrainian national was extradited to the U.S. in the Nefilim case. He was arrested in Spain in June 2024 on charges of distributing ransomware and extorting victims. According to the investigation, he had been part of the Nefilim Ransomware-as-a-Service (RaaS) operation since 2021, targeting high-revenue organizations. Nefilim uses the classic double extortion scheme: cybercriminals steal the victim’s data, encrypt it, then threaten to publish it online.

Also arrested was a member of the Ryuk gang, charged with organizing initial access to victims’ networks. The accused was apprehended in Kyiv in April 2025 at the request of the FBI and extradited to the U.S. in June.

A man suspected of being involved in attacks by the DoppelPaymer gang was arrested. In a joint operation by law enforcement in the Netherlands and Moldova, the 45-year-old was arrested in May. He is accused of carrying out attacks against Dutch organizations in 2021. Authorities seized around €84,800 and several devices.

A 39-year-old Iranian national pleaded guilty to participating in RobbinHood ransomware attacks. Among the targets of the attacks, which took place from 2019 to 2024, were U.S. local government agencies, healthcare providers, and non-profit organizations.

Vulnerabilities and attacks
Mass exploitation of a vulnerability in SAP NetWeaver


In May, it was revealed that several ransomware gangs, including BianLian and RansomExx, had been exploiting CVE-2025-31324 in SAP NetWeaver software. Successful exploitation of this vulnerability allows attackers to upload malicious files without authentication, which can lead to a complete system compromise.

Attacks via the SimpleHelp remote administration tool


The DragonForce group compromised an MSP provider, attacking its clients with the help of the SimpleHelp remote administration tool. According to researchers, the attackers exploited a set of vulnerabilities (CVE-2024-57727, CVE-2024-57728, CVE-2024-57726) in the software to launch the DragonForce ransomware on victims’ hosts.

Qilin exploits vulnerabilities in Fortinet


In June, news broke that the Qilin gang (also known as Agenda) was actively exploiting critical vulnerabilities in Fortinet devices to infiltrate corporate networks. The attackers allegedly exploited the vulnerabilities CVE-2024-21762 and CVE-2024-55591 in FortiGate software, which allowed them to bypass authentication and execute malicious code remotely. After gaining access, the cybercriminals encrypted data on systems within the corporate network and demanded a ransom.

Exploitation of a Windows CLFS vulnerability


April saw the detection of attacks that leveraged CVE-2025-29824, a zero-day vulnerability in the Windows Common Log File System (CLFS) driver, a core component of the Windows OS. This vulnerability allows an attacker to elevate privileges on a compromised system. Researchers have linked these incidents to the RansomExx and Play gangs. The attackers targeted companies in North and South America, Europe, and the Middle East.

The most prolific groups


This section highlights the most prolific ransomware gangs by number of victims added to each group’s DLS during the reporting period. In the second quarter, Qilin (12.07%) proved to be the most prolific group. RansomHub, the leader of 2024 and the first quarter of 2025, seems to have gone dormant since April. Clop (10.83%) and Akira (8.53%) swapped places compared to the previous reporting period.

Number of each group’s victims according to its DLS as a percentage of all groups’ victims published on all the DLSs under review during the reporting period (download)

Number of new variants


In the second quarter, Kaspersky solutions detected three new families and 1,702 new ransomware variants. This is significantly fewer than in the previous reporting period. The decrease is linked to the renewed decline in the count of the Trojan-Ransom.Win32.Gen verdicts, following a spike last quarter.

Number of new ransomware modifications, Q2 2024 — Q2 2025 (download)

Number of users attacked by ransomware Trojans


Our solutions protected a total of 85,702 unique users from ransomware during the second quarter.

Number of unique users attacked by ransomware Trojans, Q2 2025 (download)

Geography of attacked users

TOP 10 countries and territories attacked by ransomware Trojans
Country/territory*%**
1Libya0.66
2China0.58
3Rwanda0.57
4South Korea0.51
5Tajikistan0.49
6Bangladesh0.45
7Iraq0.45
8Pakistan0.38
9Brazil0.38
10Tanzania0.35

* Excluded are countries and territories with relatively few (under 50,000) Kaspersky users.
** Unique users whose computers were attacked by ransomware Trojans as a percentage of all unique users of Kaspersky products in the country/territory.

TOP 10 most common families of ransomware Trojans
NameVerdict%*
1(generic verdict)Trojan-Ransom.Win32.Gen23.33
2WannaCryTrojan-Ransom.Win32.Wanna7.80
3(generic verdict)Trojan-Ransom.Win32.Encoder6.25
4(generic verdict)Trojan-Ransom.Win32.Crypren6.24
5(generic verdict)Trojan-Ransom.Win32.Agent3.75
6Cryakl/CryLockTrojan-Ransom.Win32.Cryakl3.34
7PolyRansom/VirLockVirus.Win32.PolyRansom / Trojan-Ransom.Win32.PolyRansom3.03
8(generic verdict)Trojan-Ransom.Win32.Crypmod2.81
9(generic verdict)Trojan-Ransom.Win32.Phny2.78
10(generic verdict)Trojan-Ransom.MSIL.Agent2.41

* Unique Kaspersky users attacked by the specific ransomware Trojan family as a percentage of all unique users attacked by this type of threat.

Miners

Number of new variants


In the second quarter of 2025, Kaspersky solutions detected 2,245 new modifications of miners.

Number of new miner modifications, Q2 2025 (download)

Number of users attacked by miners


During the second quarter, we detected attacks using miner programs on the computers of 279,630 unique Kaspersky users worldwide.

Number of unique users attacked by miners, Q2 2025 (download)

Geography of attacked users

TOP 10 countries and territories attacked by miners
Country/territory*%**
1Senegal3.49
2Panama1.31
3Kazakhstan1.11
4Ethiopia1.02
5Belarus1.01
6Mali0.96
7Tajikistan0.88
8Tanzania0.80
9Moldova0.80
10Dominican Republic0.80

* Excluded are countries and territories with relatively few (under 50,000) Kaspersky users.
** Unique users whose computers were attacked by miners as a percentage of all unique users of Kaspersky products in the country/territory.

Attacks on macOS


Among the threats to macOS, one of the biggest discoveries of the second quarter was the PasivRobber family. This spyware consists of a huge number of modules designed to steal data from QQ, WeChat, and other messaging apps and applications that are popular mainly among Chinese users. Its distinctive feature is that the spyware modules get embedded into the target process when the device goes into sleep mode.

Closer to the middle of the quarter, several reports (1, 2, 3) emerged about attackers stepping up their activity, posing as victims’ trusted contacts on Telegram and convincing them to join a Zoom call. During or before the call, the user was persuaded to run a seemingly Zoom-related utility, but which was actually malware. The infection chain led to the download of a backdoor written in the Nim language and bash scripts that stole data from browsers.

TOP 20 threats to macOS

* Unique users who encountered this malware as a percentage of all attacked users of Kaspersky security solutions for macOS (download)

* Data for the previous quarter may differ slightly from previously published data due to some verdicts being retrospectively revised.

A new piece of spyware named PasivRobber, discovered in the second quarter, immediately became the most widespread threat, attacking more users than the fake cleaners and adware typically seen on macOS. Also among the most common threats were the password- and crypto wallet-stealing Trojan Amos and the general detection Trojan.OSX.Agent.gen, which we described in our previous report.

Geography of threats to macOS

TOP 10 countries and territories by share of attacked users
Country/territory%* Q1 2025%* Q2 2025
Mainland China0.73%2.50%
France1.52%1.08%
Hong Kong1.21%0.84%
India0.84%0.76%
Mexico0.85%0.76%
Brazil0.66%0.70%
Germany0.96%0.69%
Singapore0.32%0.63%
Russian Federation0.50%0.41%
South Korea0.10%0.32%

* Unique users who encountered threats to macOS as a percentage of all unique Kaspersky users in the country/territory.

IoT threat statistics


This section presents statistics on attacks targeting Kaspersky IoT honeypots. The geographic data on attack sources is based on the IP addresses of attacking devices.

In the second quarter of 2025, there was another increase in both the share of attacks using the Telnet protocol and the share of devices connecting to Kaspersky honeypots via this protocol.

Distribution of attacked services by number of unique IP addresses of attacking devices (download)

Distribution of attackers’ sessions in Kaspersky honeypots (download)

TOP 10 threats delivered to IoT devices

Share of each threat delivered to an infected device as a result of a successful attack, out of the total number of threats delivered (download)

In the second quarter, the share of the NyaDrop botnet among threats delivered to our honeypots grew significantly to 30.27%. Conversely, the number of Mirai variants on the list of most common malware decreased, as did the share of most of them. Additionally, after a spike in the first quarter, the share of BitCoinMiner miners dropped to 1.57%.

During the reporting period, the list of most common IoT threats expanded with new families. The activity of the Agent.nx backdoor (4.48%), controlled via P2P through the BitTorrent DHT distributed hash table, grew markedly. Another newcomer to the list, Prometei, is a Linux version of a Windows botnet that was first discovered in December 2020.

Attacks on IoT honeypots


Geographically speaking, the percentage of SSH attacks originating from Germany and the U.S. increased sharply.

Country/territoryQ1 2025Q2 2025
Germany1.60%24.58%
United States5.52%10.81%
Russian Federation9.16%8.45%
Australia2.75%8.01%
Seychelles1.32%6.54%
Bulgaria1.25%3.66%
The Netherlands0.63%3.53%
Vietnam2.27%3.00%
Romania1.34%2.92%
India19.16%2.89%

The share of Telnet attacks originating from China and India remained high, with more than half of all attacks on Kaspersky honeypots coming from these two countries combined.

Country/territoryQ1 2025Q2 2025
China39.82%47.02%
India30.07%28.08%
Indonesia2.25%5.54%
Russian Federation5.14%4.85%
Pakistan3.99%3.58%
Brazil12.03%2.35%
Nigeria3.01%1.66%
Germany0.09%1.47%
United States0.68%0.75%
Argentina0.01%0.70%

Attacks via web resources


The statistics in this section are based on detection verdicts by Web Anti-Virus, which protects users when suspicious objects are downloaded from malicious or infected web pages. Cybercriminals create malicious pages with a goal in mind. Websites that host user-generated content, such as message boards, as well as compromised legitimate sites, can become infected.

Countries that served as sources of web-based attacks: TOP 10


This section gives the geographical distribution of sources of online attacks blocked by Kaspersky products: web pages that redirect to exploits; sites that host exploits and other malware; botnet C2 centers, and the like. Any unique host could be the source of one or more web-based attacks.

To determine the geographic source of web attacks, we matched the domain name with the real IP address where the domain is hosted, then identified the geographic location of that IP address (GeoIP).

In the second quarter of 2025, Kaspersky solutions blocked 471,066,028 attacks from internet resources worldwide. Web Anti-Virus responded to 77,371,384 unique URLs.

Web-based attacks by country, Q2 2025 (download)

Countries and territories where users faced the greatest risk of online infection


To assess the risk of malware infection via the internet for users’ computers in different countries and territories, we calculated the share of Kaspersky users in each location who experienced a Web Anti-Virus alert during the reporting period. The resulting data provides an indication of the aggressiveness of the environment in which computers operate in different countries and territories.

This ranked list includes only attacks by malicious objects classified as Malware. Our calculations leave out Web Anti-Virus detections of potentially dangerous or unwanted programs, such as RiskTool or adware.

Country/territory*%**
1Bangladesh10.85
2Tajikistan10.70
3Belarus8.96
4Nepal8.45
5Algeria8.21
6Moldova8.16
7Turkey8.08
8Qatar8.07
9Albania8.03
10Hungary7.96
11Tunisia7.95
12Portugal7.93
13Greece7.90
14Serbia7.84
15Bulgaria7.79
16Sri Lanka7.72
17Morocco7.70
18Georgia7.68
19Peru7.63
20North Macedonia7.58

* Excluded are countries and territories with relatively few (under 10,000) Kaspersky users.
** Unique users targeted by Malware attacks as a percentage of all unique users of Kaspersky products in the country.

On average during the quarter, 6.36% of internet users’ computers worldwide were subjected to at least one Malware web-based attack.

Local threats


Statistics on local infections of user computers are an important indicator. They include objects that penetrated the target computer by infecting files or removable media, or initially made their way onto the computer in non-open form. Examples of the latter are programs in complex installers and encrypted files.

Data in this section is based on analyzing statistics produced by anti-virus scans of files on the hard drive at the moment they were created or accessed, and the results of scanning removable storage media. The statistics are based on detection verdicts from the On-Access Scan (OAS) and On-Demand Scan (ODS) modules of File Anti-Virus. This includes malware found directly on user computers or on connected removable media: flash drives, camera memory cards, phones, and external hard drives.

In the second quarter of 2025, our File Anti-Virus recorded 23,260,596 malicious and potentially unwanted objects.

Countries and territories where users faced the highest risk of local infection


For each country and territory, we calculated the percentage of Kaspersky users whose devices experienced a File Anti-Virus triggering at least once during the reporting period. This statistic reflects the level of personal computer infection in different countries and territories around the world.

Note that this ranked list includes only attacks by malicious objects classified as Malware. Our calculations leave out File Anti-Virus detections of potentially dangerous or unwanted programs, such as RiskTool or adware.

Country/territory*%**
1Turkmenistan45.26
2Afghanistan34.95
3Tajikistan34.43
4Yemen31.95
5Cuba30.85
6Uzbekistan28.53
7Syria26.63
8Vietnam24.75
9South Sudan24.56
10Algeria24.21
11Bangladesh23.79
12Belarus23.67
13Gabon23.37
14Niger23.35
15Cameroon23.10
16Tanzania22.77
17China22.74
18Iraq22.47
19Burundi22.30
20Congo21.84

* Excluded are countries and territories with relatively few (under 10,000) Kaspersky users.
** Unique users on whose computers Malware local threats were blocked, as a percentage of all unique users of Kaspersky products in the country/territory.

Overall, 12.94% of user computers globally faced at least one Malware local threat during the second quarter.
The figure for Russia was 14.27%.


securelist.com/malware-report-…



Heart Rate Monitoring via WiFi


Before you decide to click away, thinking we’re talking about some heart rate monitor that connects to a display using WiFi, wait! Pulse-Fi is a system that monitors heart rate using the WiFi signal itself as a measuring device. No sensor, no wires, and it works on people up to ten feet away.

Researchers at UC Santa Cruz, including a visiting high school student researcher, put together a proof of concept. Apparently, your heart rate can modify WiFi channel state information. By measuring actual heart rate and the variations in the WiFi signal, the team was able to fit data to allow for accurate heart rate prediction.

The primary device used was an ESP32, although the more expensive Raspberry Pi performed the same trick using data generated in Brazil. The Pi appeared to work better, but it is also more expensive. However, that implies that different WiFi chipsets probably need unique training, which, we suppose, makes sense.

Like you, we’ve got a lot of questions about this one — including how repeatable this is in a real-world environment. But it does make you wonder what we could use WiFi permutations to detect. Or other ubiquitous RF signals like Bluetooth.

No need for a clunky wristband. If you could sense enough things like this, maybe you could come up with a wireless polygraph.


hackaday.com/2025/09/05/heart-…



GhostRedirector: la campagna di redirect black SEO che manipola i motori di ricerca


Un gruppo di criminali informatici, che i ricercatori di ESET hanno soprannominato GhostRedirector e collegato all’ecosistema cinese, ha silenziosamente implementato uno schema di manipolazione dei motori di ricerca globali basato su host Windows hackerati. Secondo la telemetria e le scansioni Internet di giugno, almeno 65 server in diversi paesi sono stati compromessi. Le prime infezioni confermate sono state registrate da dicembre, ma una serie di campioni correlati indica attività almeno da agosto 2024, quindi non si tratta di un’epidemia, ma di una campagna a lungo termine con ruoli e infrastrutture consolidati.

Al centro ci sono due componenti appositamente scritti. Rungan è una backdoor passiva scritta in C++ che, una volta attivata, accetta comandi su una macchina compromessa e funge da meccanismo di amministrazione remota silenzioso. Gamshen è un trojan per Internet Information Services che modifica le risposte del server web in modo che Googlebot non veda le pagine originali, ma versioni modificate utili per i domini di gioco d’azzardo di terze parti.

A livello di motore di ricerca, sembra che i siti legittimi linkino massicciamente a risorse promosse e gli algoritmi di ranking interpretano questi link artificiali come raccomandazioni. Di conseguenza, le posizioni dei siti di gioco d’azzardo aumentano e i proprietari di host hackerati non sospettano nemmeno che i loro siti stiano alimentando lo schema SEO di qualcun altro .

La geografia dell’attacco mostra una chiara prevalenza nei paesi del Sud America e dell’Asia meridionale. Il maggior numero di computer infetti è stato rilevato in Brasile, Perù, Thailandia, Vietnam e Stati Uniti, e gli aggressori non si sono limitati a un singolo settore. Sono stati colpiti istituti scolastici, organizzazioni mediche, compagnie assicurative, aziende di trasporti, aziende tecnologiche e del commercio al dettaglio. Tale distribuzione suggerisce che la selezione delle vittime non sia stata determinata dal profilo dell’azienda, ma da segnali tecnici di vulnerabilità e dalla facilità di successiva operatività.

Secondo gli analisti, il punto di ingresso iniziale è associato a specifiche vulnerabilità di SQL injection. Dopo aver compromesso l’applicazione web, gli aggressori hanno proceduto alla fase di espansione dell’accesso e hanno distribuito una catena di loader e strumenti sul server. Gli script di controllo in PowerShell hanno estratto tutti i componenti necessari dallo stesso nodo 868id[.]com, semplificando la logistica dell’attacco e consentendo una rapida sostituzione delle versioni del payload.

Per uscire dal contesto del processo web e raggiungere il livello di amministratore, sono state utilizzate utility basate su exploit pubblici della famiglia Potato, in particolare sulle idee di EfsPotato e BadPotato, ampiamente utilizzate nel segmento criminale di lingua cinese. Alcuni dei campioni presentavano una firma digitale corretta: il certificato è stato rilasciato dal centro TrustAsia RSA Code Signing CA G3 alla società Shenzhen Diyuan Technology. La presenza di una firma valida aumenta l’affidabilità dei meccanismi di protezione nei file eseguibili e ne facilita l’avvio. Dopo aver completato con successo l’escalation dei privilegi , il lavoro è stato completato creando o modificando un account locale con inclusione nel gruppo degli amministratori, il che ha garantito la stabilità del controllo e la possibilità di eseguire operazioni sensibili senza ripetuti attacchi informatici.

Oltre alle backdoor finali, i ricercatori descrivono due moduli ausiliari che forniscono ricognizione e controllo. La libreria Comdai assume una serie di funzioni a livello di backdoor: stabilisce l’interazione di rete con la parte di controllo, crea account con diritti amministrativi, esegue file, ottiene elenchi di directory, interferisce con il funzionamento dei servizi e modifica le chiavi del registro di Windows. Un componente separato, Zunput, è responsabile dell’inventario dei siti web in grado di eseguire contenuti dinamici. Controlla l’attività delle raccolte siti, ne raccoglie i parametri (il percorso fisico alla radice web, il nome del sito, l’indirizzo IP, il nome host) e quindi lascia una web shell sul server per ulteriori operazioni.

La fase finale della catena è l’implementazione di una coppia di Rungan e Gamshen. Il primo esegue una serie di comandi su un nodo hackerato e supporta l’attività operativa remota senza rumore nei log, il secondo trasforma una risorsa legittima in una guarnizione invisibile per la manipolazione delle ricerche. Il trucco chiave di Gamshen è la sostituzione selettiva della risposta solo per Googlebot, e gli inserimenti vengono formati dinamicamente in base ai dati provenienti dal server di controllo C2. In questo modo vengono creati backlink artificiali da domini attendibili alle pagine desiderate, che li spostano nelle prime righe per le query di destinazione. A giudicare dalla descrizione della meccanica, un progetto di terze parti ne trae vantaggio, il che è molto probabile che paghi per il servizio di cheating, e GhostRedirector agisce come un appaltatore tecnico con il proprio arsenale e un proprio set di accessi.

Il quadro emerso da questa operazione mostra quanto strettamente si intersechino oggi le pratiche SEO criminali e l’hacking tradizionale dei server. Da un lato, lo sfruttamento mirato di vulnerabilità, l’escalation dei privilegi, l’entrenchment e i moduli di controllo; dall’altro, un attento lavoro su contenuti e traffico, basato sui segnali comportamentali dei motori di ricerca. Nel complesso, ciò consente in un breve lasso di tempo di creare una rete di link di supporto provenienti da risorse altrui e di aumentare la visibilità dei siti promossi, senza lasciare praticamente tracce visibili per i proprietari dei siti compromessi.

L'articolo GhostRedirector: la campagna di redirect black SEO che manipola i motori di ricerca proviene da il blog della sicurezza informatica.



Armani, lo stilista che inventò la “rivoluzione sottovoce” della moda

MILANO – “Io non sono né un couturier né un sarto, sono uno che crea uno stile”. È stato proprio Giorgio Armani, scomparso a 91 anni il 4 settembre 2025,…
L'articolo Armani, lo stilista che inventò la “rivoluzione sottovoce” della moda su Lumsanews.


Nazionale, Gattuso al debutto con l’obiettivo mondiale: stasera in campo contro l’Estonia.

[quote]BERGAMO – Adesso si fa sul serio. Si può riassumere così quello che sarà il ritorno in campo della Nazionale italiana nella sfida di stasera contro l’Estonia, per continuare il…
L'articolo Nazionale, Gattuso al debutto con l’obiettivo mondiale: stasera in



Il fragile equilibrio del Tigray tra accordi disattesi e rischio di nuova guerra


@Notizie dall'Italia e dal mondo
La regione etiope, uscita stremata dal conflitto 2020-2022, vive nuove fratture interne e il mancato rispetto degli accordi di pace
L'articolo Il fragile equilibrio del Tigray tra accordi disattesi e rischio di nuova guerra proviene da Pagine Esteri.



Ecco il tributo a Jason Molina
freezonemagazine.com/news/ecco…
MJ Lenderman, Sun June, Hand Habits, Advance Base, Friendship, Horse Jumper of Love, Runnner e altri artisti partecipano a un nuovo album dedicato al compianto cantautore Jason Molina (Songs: Ohia e Magnolia Electric Co.) L’album, intitolato I Will Swim to You: A Tribute to Jason Molina, uscito oggi 5 settembre per Run for Cover e […]
L'articolo Ecco il tributo a Jason Molina proviene da FREE ZON



Inizia l’era delle armi laser. Come si muovono Stati Uniti ed Europa

@Notizie dall'Italia e dal mondo

Negli ultimi anni le armi a energia diretta, e in particolare i laser ad alta potenza, stanno emergendo come una vera rivoluzione nella difesa aerea e navale. Grazie alla capacità di colpire bersagli con velocità praticamente istantanea, riducendo i costi e semplificando la logistica,



Pordenone Linux User Group aps – PNLUG - Corso Self-Hosting


pnlug.it/2025/09/05/corso-self…
Segnalato da Linux Italia e pubblicato sulla comunità Lemmy @GNU/Linux Italia
Desideri riappropriarti della tua sovranità digitale, gestendo in autonomia i tuoi servizi online, proprio come un vero sysadmin? Allora, abbiamo […]

versodiverso reshared this.



Germania, le autorità della protezione dati criticano il governo sull’AI Act

L'articolo proviene da #Euractiv Italia ed è stato ricondiviso sulla comunità Lemmy @Intelligenza Artificiale
Le autorità tedesche per la protezione dei dati hanno espresso forti critiche nei confronti del progetto di legge del governo federale per l’attuazione della legge dell’UE



Cuffie conduzione ossea F806 - Questo è un post automatico da FediMercatino.it

Prezzo: 20 €

Cuffie a conduzione ossea F806.
Usate poco, in buone condizioni.
Prezzo trattabile.

Luogo: Torino

🔗 Link su FediMercatino.it per rispondere all'annuncio

@Il Mercatino del Fediverso 💵♻️


Cuffie conduzione ossea F806

Cuffie a conduzione ossea F806. Usate poco, in buone condizioni. Prezzo trattabile.

Luogo: Torino

Price: 20 € :: Questo è un articolo disponibile su FediMercatino.it

Si prega di rispondere con un messaggio diretto/privato al promotore dell'annuncio.

Per informazioni su: Fedimercatino: Chi siamo

Seguici su @fedimercatino@mastodon.uno e sul gruppo @mercatino@feddit.it


informapirata ⁂ reshared this.



Il fragile equilibrio del Tigray tra accordi disattesi e rischio di nuova guerra


@Notizie dall'Italia e dal mondo
La regione etiope, uscita stremata dal conflitto 2020-2022, vive nuove fratture interne e il mancato rispetto degli accordi di pace
L'articolo Il fragile equilibrio del Tigray tra accordi disattesi e rischio di nuova guerra proviene da Pagine Esteri.



Ecco il tributo a Jason Molina
freezonemagazine.com/news/ecco…
MJ Lenderman, Sun June, Hand Habits, Advance Base, Friendship, Horse Jumper of Love, Runnner e altri artisti partecipano a un nuovo album dedicato al compianto cantautore Jason Molina (Songs: Ohia e Magnolia Electric Co.) L’album, intitolato I Will Swim to You: A Tribute to Jason Molina, uscito oggi 5 settembre per Run for Cover e […]
L'articolo Ecco il tributo a Jason Molina proviene da FREE ZON


Luca Sapio – Black Waves
freezonemagazine.com/articoli/…
Nel 1989 la Motown fece una operazione che per qualcuno è stata di nostalgia, per altri di curiosità, per altri di collezionismo. Pubblicò il disco dal titolo, Nero Italiano- Quando in Italia Si Cantava Il Rhythm&Blues. Il disco era composto da artisti di punta della storica etichetta di Detroit, che negli anni sessanta volle ampliare […]
L'articolo Luca Sapio – Black Waves proviene da FREE ZONE M
Nel



Dash cam con alimentazione USB-C


Vorrei installare una dash cam nella mia auto e vorrei farlo approfittando del fatto che lo specchietto retrovisore ha una porta USB-C pensata proprio per alimentare una dash cam.

I modelli che ho trovato io vengono tutti venduti con il cavo per collegarle alla batteria (scatola dei fusibili, ecc.), cosa che richiede un lavoro che non ho voglia di fare.

A me interessa filmare solo quando l'auto è accesa quindi non mi serve neanche arrivare fino alla batteria.

Conoscete qualche modello di dash cam venduta con presa USB-C?

#dashcam



La Cina tra diplomazia e deterrenza. Così Sco e parate ridefiniscono l’ordine globale

@Notizie dall'Italia e dal mondo

Il vertice di Tianjin ha rappresentato molto più di un incontro regionale. Con la partecipazione di 25 paesi che rappresentano oltre il 40% della popolazione mondiale e il 24,7% del Pil globale, l’evento ha assunto i contorni di una vera e propria controffensiva







Lorenzo Bertocchini – Happy Island
freezonemagazine.com/articoli/…
Uscito da qualche mese, questo Happy Island di Lorenzo Bertocchini, merita però di essere segnalato per le ragioni che potrete leggere di seguito. Un disco corposo contenente ben tredici brani nuovi originali ai quali si aggiungono tre cover, più una sorta di ghost track finale. Questo è il settimo album che esce di Lorenzo, senza […]
L'articolo Lorenzo Bertocchini – Happy Island


Tsitsi Dangarembga – Nevrosi
freezonemagazine.com/articoli/…
Nevrosi è il primo di una trilogia di scritti della autrice dello Zimbabwe e l’unico tradotto in italiano finora. La Dangarembga, che è anche regista e autrice teatrale, è entrata con This mournable body, ultimo della suddetta serie, nella long list del Booker Prize nel 2020. In questo primo romanzo entriamo in una grande famiglia […]
L'articolo Tsitsi Dangarembga – Nevrosi proviene da FREE ZONE M


in Italia i magistrati hanno uno scudo penale, e grazie a questo governo pure la polizia, carabinieri e adesso i medici. a quando altre categorie? giusto per risolvere i problemi di malasanità...


al di la dell'essere di destra o di sinistra, in quale universo pare accettabile che il presidente di una nazione mandi l'esercito a presidiare solo le città con amministrazione locale controllata dall'opposizione?


In sentencing memos and exhibits, Pratt's attorney paints of picture that points at Pratt's abusive father, his ADHD, his co-conspirators, the entire pornography industry, and the victims themselves.

In sentencing memos and exhibits, Prattx27;s attorney paints of picture that points at Prattx27;s abusive father, his ADHD, his co-conspirators, the entire pornography industry, and the victims themselves.#girlsdoporn


Ahead of Sentencing, GirlsDoPorn Ringleader Michael Pratt Attempts to Seem Reformed


Days away from finding out his sentence for sex trafficking as the ringleader of Girls Do Porn, Michael James Pratt and his attorney are attempting to paint a picture of a man reformed behind bars, through personal letters and certificates from classes he has passed inside prison.

GirlsDoPorn was a sex trafficking operation posing as a porn studio that Pratt ran from 2009 to 2020. By lying to the women they recruited, telling them that they were being hired for “modeling” gigs and adult video shoots that would never be distributed outside offline private collections, GirlsDoPorn’s operators coerced young, inexperienced women into shooting rough, hours-long sex scenes in San Diego hotel rooms. The videos were distributed on massive porn sites including Pornhub, where GirlsDoPorn was a content partner for years. Women who have come forward for the civil and federal trials against GirlsDoPorn have said their lives were upended by Pratt’s criminal enterprise.

💡
Were you a victim of GirlsDoPorn, or do you have knowledge of how it operated? I would love to hear from you. Using a non-work device, you can message me securely on Signal at sam.404. Otherwise, send me an email at sam@404media.co.

Pratt has been in custody since he was arrested in Spain on December 21, 2022 and extradited to the US. Prior to that, he’d been in hiding since fleeing the US in the middle of a massive civil trial in 2019, where 22 victims sued him and his co-conspirators for $22 million (a case they won). Right after his disappearance, Pratt was charged with federal counts of sex trafficking by force, fraud and coercion, and was on the FBI’s Most Wanted List for years. He initially pleaded not guilty to these charges in 2024, but changed his plea to guilty in June.

Exhibits filed by Pratt’s lawyer Brian White on Sept. 1 include letters, mostly anonymous, from people who knew him when he was younger asking the judge for leniency, including his sister and mother. “Mike's father, Steve Pratt, was not a good role model. He was a drinker and had a controlling personality. I caught Steve smacking Michael uncontrollably on a couple of occasions. I stopped it immediately,” his mother wrote.

“Three years of prison has given me enough time to think about this entire situation,” Pratt wrote in a letter to the court submitted on Monday. “Trying to understand things from other points of view has given me insight into how some victims were really affected by these videos. I put myself in the shoes of the women who participated, trying to see what they have gone through. I myself have been a victim of bullying and know how rough that is on the psyche. I cannot imagine the trauma experienced by a video being published where friends and family could come across it.”

We know, in fact, from years of testimonies and interviews—many while it was still unsafe for them to come forward, when the consequences of speaking up about this abuse risked compounding trauma and continued, violent harassment—how Pratt’s victims were impacted by his actions.

Several of the women who’ve testified in the civil and federal trials, and came forward to speak on the record to journalists, reported violent assault to the point of bleeding or injury, being trapped inside the hotel rooms with no clothing, and being lied to by Pratt and his co-conspirators about who would be able to see the videos. As one of the women targeted by GirlsDoPorn told me in 2021: “There were a few points where I was just like please, I need to stop, I need to stop, because it was just so much pain. I said, I can’t go on anymore… At that point I could have said nothing. I could have been mute. My voice was just not heard at all.” Another woman said while testifying during the civil trial: “They put furniture in front of the door, so what was I going to do—jump over the balcony?” GirlsDoPorn’s attorney at the time, Aaron Sadock, asked that woman on the stand if she had fun. “No, I did not have fun!” she said, crying.

Kristy Althaus, who sued Pornhub in 2023 for disseminating the videos, claimed that Pratt’s conspirators held her captive in a hotel room and filmed her being raped for nine to 10 hours, barricading the doors, ignoring her bleeding and cries, forcing her to consume alcohol, marijuana, and Xanax, and spiking her drink with oxycodone. According to that complaint, when she refused to return for another “shoot,” Pratt threatened her and her family, texting, “You have it coming for u,” “I will cut and kill you bitch,” and “You better be here by noon shoot 2tomorrow or your graveyard,” according to screenshots of texts from Althaus’s complaint.

For many of these women, the trauma and harassment didn’t stop once they left the hotel rooms. In some cases, they were disowned by their families and friends, harassed endlessly, struggled to find jobs in previously-prestigious careers and found it difficult to date or trust anyone intimately again.

In the defendant’s sentencing memorandum, White blames Pratt’s alcoholic, abusive father and his own ADHD; throws his co-conspirators under the bus; accuses the entire pornography industry of being “exploitative and dehumanizing;” and asserts again that the women lied in their testimonies.

The memo paints a picture of Pratt as a precocious child with a difficult upbringing in Christchurch, New Zealand, where he taught himself how to use computers and eventually learned about websites and affiliate marketing. “Mr. Pratt began looking for better ways to generate income, and through the associations he made in the affiliate marketing business, he learned that making videos to direct internet traffic to pornography sites could be financially successful,” the memo says. But when he tried to make a pornography business himself, he wasn’t very good at it, blaming the banning of Craigslist’s erotic ads in 2009 for his difficulties in finding models. He claims he posted ads seeking “models” as a way around the ban.

Pratt's lawyer asserts in the memorandum that his employee, Andre Reuben “Dre” Garcia, the main “actor” in most of the GirlsDoPorn videos, stopped when the women told him to stop. “She said, ‘stop, it’s not going to work.’ Garcia stopped,” the memo says. “The model offered to try a second time and again told Garcia to stop because it wasn’t going to work. Again, Garcia stopped. That was the end of it. Forcing a model to do something against her will was not Mr. Pratt’s intention.” He also claims that when Pratt heard complaints about Garcia from models, Pratt “instituted certain safety measures” like locking the hotel room refrigerators and putting more cameras in the room. Those “safety measures” didn’t include firing Garcia, however.

When he’s arguing that he should have a lower sentence than Garcia’s 20 years, Pratt acknowledges that Garcia sexually assaulted many of these women. “Garcia physically raped a number of the models before and after the video shoots, and multiple women were forced to continue having sex with him on video despite their pleas to stop due to pain or because the sex went beyond the scope of what they had agreed to do,” the memorandum states.

The exhibits filed as part of the memo also attempt to show how productive and busy Pratt has been in prison. His attorney submitted nearly 100 “certificates of completion” issued by the learning platform Edovo, which offers classes for incarcerated people. The classes Pratt passed include “Embracing Unexpected Change,” “Doing Time With Jesus,” several anger management courses, “Media Relations Foundations,” marketing classes for LinkedIn and Facebook, “Augmented Reality Marketing,” “Human Trafficking in the United States: The Truth and What You Can Do About It,” “Introduction to Artificial Intelligence,” and multiple cooking classes, including “Soups” and “Sauces.”

Federal prosecutors seek a 22-year prison sentence, while Pratt’s defense countered with around 17 years; Judge Janis L. Sammartino will hand Pratt his sentence on Monday in San Diego.
playlist.megaphone.fm?p=TBIEA2…




Giorgio Armani: la grandezza e l’umiltà


@Giornalismo e disordine informativo
articolo21.org/2025/09/giorgio…
Con la scomparsa di Giorgio Armani ci dice addio una certa idea di moda, una certa idea di Milano e anche una certa idea d’Italia. Armani, infatti, era un uomo colto, partito dal basso e rimasto umile per tutta la vita. Piacentino, classe 1934, si è affermato



questo è il governo meloni.

Mauro reshared this.


in reply to simona

poi dice che uno bestemmia pure se non è credente!
in reply to simona

in cina con putin e il fascista della corea del nord sono li a prenderlo per il culo... lui e noi. e come dare loro torto...


A hacker has compromised Nexar, which turns peoples' cars into "virtual CCTV cameras" that organizations can then buy images from. The images include sensitive U.S. military and intelligence facilities.

A hacker has compromised Nexar, which turns peoplesx27; cars into "virtual CCTV cameras" that organizations can then buy images from. The images include sensitive U.S. military and intelligence facilities.#News


This Company Turns Dashcams into ‘Virtual CCTV Cameras.’ Then Hackers Got In


A hacker has broken into Nexar, a popular dashcam company that pitches its users’ dashcams as “virtual CCTV cameras” around the world that other people can buy images from, and accessed a database of terabytes of video recordings taken from cameras in drivers’ cars. The videos obtained by the hacker and shared with 404 Media capture people clearly unaware that a third party may be watching or listening in. A parent in a car soothing a baby. A man whistling along to the radio. Another person on a Facetime call. One appears to show a driver heading towards the entrance of the CIA’s headquarters. Other images, which are publicly available in a map that Nexar publishes online, show drivers around sensitive Department of Defense locations.

The hacker also found a list of companies and agencies that may have interacted with Nexar’s data business, which sells access to blurred images captured by the cameras and other related data. This can include monitoring the same location captured by Nexar’s cameras over time, and lets clients “explore the physical world and gain insights like never before,” and use its virtual CCTV cameras “to monitor specific points of interest,” according to Nexar’s website.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


#News #x27

Breaking News Channel reshared this.



rilanciamo la mobilitazione con una nuova due giorni di raccolta firme


Questo primo fine settimana di settembre rilanciamo la mobilitazione con una nuova due giorni di raccolta firme.
Sabato 6 e domenica 7 torniamo nelle piazze per cancellare i poteri speciali grazie ai quali Gualtieri gioca la partita con un mazzo di carte truccato. Contro l'abuso di potere legalizzato puoi metterci la firma. Nella locandina trovi dove e quando firmare. Massima diffusione 💪🏼


404 Media first revealed ICE’s new app, called Mobile Fortify, in June. Now members of a congressional committee are pressing DHS for more information, including ICE's legal basis for using the app inside the U.S.

404 Media first revealed ICE’s new app, called Mobile Fortify, in June. Now members of a congressional committee are pressing DHS for more information, including ICEx27;s legal basis for using the app inside the U.S.#Impact


Congress Pushes DHS for Details on ICE’s New Facial Recognition App


Members of a congressional committee have demanded Department of Homeland Security (DHS) Secretary Kristi Noem for more information about Mobile Fortify, Immigration and Customs Enforcement’s (ICE) new facial recognition app, which taps into an unprecedented array of government databases and uses a system ordinarily reserved for when people enter or exit the U.S. 404 Media first revealed the app in June.

The Democratic lawmakers, Bennie G. Thompson, J. Luis Correa, and Shri Thanedar, are asking Noem a host of questions about the app, including what databases Mobile Fortify searches, the tool’s accuracy, and ICE’s legal basis for using the app to identify people outside of ports of entry, including U.S. citizens.

“Congress has long had concerns with the Federal government’s use of facial recognition technology and has regularly conducted oversight of how DHS utilizes this technology. The Mobile Fortify application has been deployed to the field while still in beta testing, which raises concerns about its accuracy,” the letter from the Committee on Homeland Security and addressed to Noem reads.

💡
Do you know anything else about this app? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

404 Media first revealed Mobile Fortify’s existence through leaked emails. Those emails showed that ICE officers could use the app to identify someone based on their fingerprints or face by just pointing a smartphone camera at them. The underlying Customs and Border Protection (CBP) system for the facial recognition part of the app is ordinarily used when people enter or leave the U.S. With Mobile Fortify, ICE then turned that capability inwards to identify people away from ports of entry.

In the footnotes of the letter, the lawmakers indicate they have a copy of a similar email, and the letter specifically cites 404 Media’s reporting.

In July 404 Media published a second report based on a Mobile Fortify user manual which explained the app’s capabilities and data sources in more detail. It said that Mobile Fortify uses a bank of 200 million images, and can pull up a subject’s name, nationality, date of birth, “alien” number, and whether a judge has marked them for deportation. It also showed that Mobile Fortify links databases from the State Department, CBP, the FBI, and states into a single tool. A “super query” feature lets ICE officers query multiple databases at once regarding “individuals, vehicles, airplanes, vessels, addresses, phone numbers and firearms.”

“Face recognition technology is notoriously unreliable, frequently generating false matches and resulting in a number of known wrongful arrests across the country. Immigration agents relying on this technology to try to identify people on the street is a recipe for disaster. Congress has never authorized DHS to use face recognition technology in this way, and the agency should shut this dangerous experiment down,” Nathan Freed Wessler, deputy director of the American Civil Liberties Union’s Speech, Privacy, and Technology Project, previously told 404 Media.

In their letter the lawmakers ask Noem questions about the app’s legality, including ICE’s legal basis to use the app to conduct biometric searches on people outside ports of entry; the databases Mobile Fortify has access to; any agreements between CBP and ICE about the app; information about the usage of the app, such as the frequency of ICE searches using the tool and what procedures ICE officials follow with the app; the app’s accuracy; and any policies or training to ICE agents on how to use the app.

“To ensure ICE is equipped with technology that is accurate and in compliance with constitutional and legal requirements, the Committee on Homeland Security is conducting oversight of ICE’s deployment of the Mobile Fortify application,” the letter says.

CBP acknowledged a request for comment but did not provide a response in time for publication. ICE did not respond to a request for comment.

You can find a copy of the letter here.




Evento precongressuale a La Spezia: “Psichedelici e salute: nuove frontiere della terapia”


In occasione del XXII Congresso dell’Associazione Luca Coscioni per la libertà di ricerca scientifica, l’Associazione Luca Coscioni, in collaborazione con la Cellula Coscioni La Spezia e SIMEPSI, presenta l’evento

Psichedelici e salute: nuove frontiere della terapia

L’appuntamento è per sabato 27 settembre alle ore 10.00 presso l’Auditorium Beghi, in via del Canaletto 100, a La Spezia. L’evento, ad accesso libero, sarà registrato e poi reso disponibile sul canale YouTube dell’Associazione Luca Coscioni all’interno della playlist “Eventi precongressuali 2025”.
L’evento è in fase di accreditamento ECM per professioni sanitarie.


PROGRAMMA

ore 10 – 13 Prima sessione
moderano: Diego Silvestri e Guido Frosina


Ore 10 – 10.30 Introduzione, saluti vari – Marco Perducaore 10.30-11.50Modulo 1 – Fondamenti teorici “Dalla ricerca alla pratica: protocolli, evidenze e applicazioni cliniche”Dott. Dario Zaccheroni “Stati non ordinari di coscienza e psicoterapia assistita da psichedelici”

Dott.ssa Susanna Lucini Paioni “Medicina Psichedelica e nuovi paradigmi in salute mentale”

Dott. Lorenzo Goppa
“Funghi medicinali, psilocibina e prospettive di ricerca “

Ore 12.00 – 13.00Modulo 2: Applicazioni cliniche “Il cervello psichedelico: meccanismi d’azione e potenzialità”

Proff. Marco Scarselli “Uso terapeutico degli psichedelici: dal meccanismo d’azione alla efficacia clinica” Prof. Ciro Conversano “Uso terapeutico degli psichedelici: dal meccanismo d’azione alla efficacia clinica”

13-14.00 pausa pranzo

dalle ore 14.00 alle ore18.00
seconda sessione


14 – 15.20
Modulo 3 – Cultura, Società e riduzione del danno

Sara Ballotti
Dall’underground alla condivisione dell’esperienza psichedelica: i cerchi di integrazione
di illuminismo Psichedelico

Simone Toneatti e ITARDDservizi di riduzione del danno, rete ITARDD

Dott. Gabriele Marino “Tutte le teste ti porti via: origine e caratteri della psichedelia musicale”

Prof.ssa Teresa Prudente “Sostanze psicoattive, allucinazione e testo letterario: casi studio, forme, implicazioni

15.30 – 16.30
Modulo 4 – Psichedelici nelle cure palliative Dott. Luca Magnani “Accompagnamento al fine vita: dignità, significato e riduzione della sofferenza”

Ilaria Di LisoPotenzialità degli psichedelici nella malattia cronica e terminale e nel morire.” assistente spirituale

Diego Silvestri Numero Bianco

16.30
pausa caffè

16.45
Modulo 5 – confronto sui temi politici ed istituzionali locali
16.45
Voci dal territorio: Spazio riservato alle ASL e agli ordini professionali di psicologi e psichiatri, consiglieri regionali Liguria e domitato di bioetica regionale + Consiglieri regionali Liguria+ comitato di bioetica regionale

17.15
Quadro normativo e prospettive future Claudia Moretti, M. Perduca

17.45
“Innovazione e tradizione in medicina: quali prospettive per la Liguria?”
discussione aperta con i relatori, ripresa del focus sulle esigenze sanitarie specifiche del territoriomodera Marco Perduca

L'articolo Evento precongressuale a La Spezia: “Psichedelici e salute: nuove frontiere della terapia” proviene da Associazione Luca Coscioni.