Salta al contenuto principale



Gli Usa accelerano sulla riforma dell’export militare per intercettare il riarmo europeo. I dettagli

@Notizie dall'Italia e dal mondo

Gli Stati Uniti stanno spingendo sull’acceleratore per esportare i loro sistemi d’arma all’estero. Al Congresso è infatti in corso il tentativo più ambizioso degli ultimi decenni di aggiornare le regole sull’export



Grecia. Sciopero generale contro la giornata lavorativa di 13 ore


@Notizie dall'Italia e dal mondo
Sciopero generale oggi in Grecia contro la proposta del governo di permettere ai dipendenti di lavorare fino a 13 ore al giorno per aumentare il proprio salario
L'articolo Grecia. Scioperohttps://pagineesteri.it/2025/10/01/mediterraneo/grecia-sciopero-generale-giornata-lavorativa-13-ore/



e meno male esageravamo e putin non era nostro nemico... sembra come quando prima dell'invasione ucraina noi europei eravamo "isterici"... a detta di putin. sarà il caso di armarsi e cominciare a controbattere. almeno in modo difensivo..


Il governo del Regno Unito tenta di nuovo di accedere ai dati crittografati dei clienti Apple

Se ti interessa questo tipo di aggiornamenti puoi seguire il gruppo Activitypub @Informatica (Italy e non Italy 😁)

Secondo quanto riferito, il governo del Regno Unito sta nuovamente chiedendo ad Apple di creare una backdoor per consentire ai funzionari governativi di accedere ai backup iCloud crittografati end-to-end nel Paese.

L'ultima volta che è successo, Apple ha disattivato la protezione avanzata dei dati di iCloud, la funzionalità opzionale che consente agli utenti di crittografare i backup nel cloud.

techcrunch.com/2025/10/01/uk-g…


NEW: The U.K. government is reportedly once again requesting Apple build a backdoor so government officials can access end-to-end encrypted iCloud backups in the country.

Last time this happened, Apple disabled iCloud's Advanced Data Protection, the opt-in feature that lets users encypt cloud backups.

techcrunch.com/2025/10/01/uk-g…


informapirata ⁂ reshared this.

in reply to Cybersecurity & cyberwarfare

@lorenzofb ma hanno completamente ragione,ho solo pensiero per cui vorrei una risposta da lor signori,che sia legalmente rispettosa e in base al principio che stabilisce uguaglianza di diritti e senza retorica perché "essi"dovrebbero/devono esserne esclusi?per le cariche che svolgono!?forse tra di "essi"non possono esserci pedofili,corrotti,ladri!?"sono eletti dal popolo che MERITA rispetto per la fiducia affidatagli,non ABUSARE del potere ottenuto a fini personali.🤐


Messico. Due difensori dell’acqua incriminati: la giustizia colpisce i movimenti popolari


@Notizie dall'Italia e dal mondo
Tra le crescenti concessioni idriche alle multinazionali private e le proteste delle popolazioni locali, due attivisti per la difesa dell'acqua e del territorio sono stati incriminati dopo un'udienza caratterizzata da numerose



La Svezia addestra le truppe Nato ad operare nel Grande Nord

@Notizie dall'Italia e dal mondo

La narrativa comune sull’Artico come teatro di guerra evoca immagini di ghiaccio, neve e temperature proibitive. Ma per gli addetti ai lavori ed i comandanti militari la stagione più insidiosa non è l’inverno, ma il “quinto tempo”, l’autunno e la primavera, quando il disgelo trasforma il terreno in un pantano impraticabile



Gaza. Quasi 7 vittime su 10 sono donne, bambine e ragazze


@Notizie dall'Italia e dal mondo
Il pericolo non arriva solo dalle bombe, cresce la violenza di genere e i diritti essenziali vengono calpestati. 700mila donne e ragazze in età fertile non hanno assorbenti, acqua pulita, sapone e privacy.
L'articolo Gaza. Quasi 7 vittime su 10 sono donne, bambine e ragazze proviene da



Sicurezza mobile: l’impatto dell’hacking etico e il ruolo del vulnerability management


@Informatica (Italy e non Italy 😁)
Scoperta e risolta una vulnerabilità critica di escalation dei privilegi nell’app PosteID da parte dei ricercatori SERICS, poi risolta dal team dell’Identity Provider Poste Italiane, a testimonianza dei benefici nella

la_r_go* reshared this.




Tilly Norwood fa tremare Hollywood: sindacato degli attori contro l’attrice creata con IA

[quote]LOS ANGELES – Si definisce “aspirante attrice”, di base a Londra. I suoi profili social la ritraggono nei caffè o in scene di vita quotidiana da film. Il 30 luglio…
L'articolo Tilly Norwood fa tremare Hollywood: sindacato degli attori contro l’attrice creata



Sto pensando se partecipare alla marcia Perugia-Assisi.

Va bene tutto ma ho un problema con il "no" al riarmo.

Non discutiamo sul fatto che la pace sia meglio della guerra, che sentirsi fratelli sia meglio che sentirsi nemici, che spendere soldi per fare ospedali e scuole sia meglio che spenderli per fare bombe, ecc. ecc. perché siamo tutti d'accordo e perderemmo solo tempo.

Credo che la marcia e tante altre iniziative simili siano importanti per spingere le persone a riflettere sul fatto che un altro mondo è possibile e che a noi tutti spetta il compito di essere il motore per questo cambiamento verso un mondo migliore.

Ma quando si dice "no al riarmo" si fa un salto qualitativo, si passa dall'indicare dei principi generali ampiamente condivisibili a prendere una posizione politica da agire immediatamente, nella realtà presente, nel qui e ora.

E la domanda che mi pongo io è se sia giusto non armarsi, se sia giusto prendere oggi la decisione di rinunciare ad avere una difesa armata.

Cosa succederebbe se una metà dei governi mondiali smettesse di spendere soldi per armarsi e li spendesse in ospedali e scuole, e l'altra metà invece no? Vivremmo in un mondo con più pace o con più guerre?

La lunghissima pace che c'è stata in Europa negli ultimi 70 anni la dobbiamo ad una svolta pacifista che c'è stata dopo al fine della seconda guerra mondiale o la dobbiamo al fatto che gli arsenali sono stati riempiti di armi al punto tale che nessuno ha avuto il coraggio di sparare per primo?

Se i palestinesi avessero avuto un esercito forte come quello di Israele, Gaza oggi sarebbe distrutta?

Se gli ucraini avessero avuto un esercito forte come quello russo, si sarebbero trovati oggi con i carri armati russi in casa? Avrebbero le loro città costantemente sotto il tiro di missili e droni?

Quello che voglio dire è che da un lato capisco che il disarmo sia LA soluzione ma che dall'altro sono altrettanto convinto che un disarmo unilaterale non possa che essere foriero di tragedie.



Sinner trionfa a Pechino e ringrazia il team: “Fortunato a lavorare con persone oneste”

[quote]PECHINO – Jannik Sinner torna a vincere un torneo dopo la finale persa agli Us Open. Il numero 2 del mondo si aggiudica l’Atp 500 di Pechino grazie al successo…
L'articolo Sinner trionfa a Pechino e ringrazia il team: “Fortunato a lavorare con persone oneste” su



How companies working for landlords are scraping data inside corporate environments; lawyers explain why they used AI (after getting caught); and all the Ruby drama.#Podcast


Podcast: Landlords Demand Your Workplace Logins to Scrape Paystubs


We start this week with Joseph’s article about landlords and income verification companies demanding login details from potential renters so the companies can log in and scrape their paystubs. That has some potential legal issues for everyone involved! After the break, 18 lawyers tell us why they used AI. In the subscribers-only section, Emanuel breaks down the massive drama around Ruby.
playlist.megaphone.fm?e=TBIEA4…
Listen to the weekly podcast on Apple Podcasts,Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.
youtube.com/embed/KtvSBb6rtHE?…




La presidenza Trump non è follia, è la conseguenza della politica dello spettacolo
possibile.com/trump-postman/?u…
Il futuro non è scritto, diceva Postman. Ed è vero anche oggi: dipende da come useremo i mezzi di comunicazione, se come strumenti di intrattenimento o come occasioni di pensiero. La differenza non è secondaria. Da essa dipende la qualità della nostra democrazia.
L'articolo La presidenza Trump non è follia, è la


Flotilla verso la Striscia. Scotto (Pd): “Nottata in allerta. Abbordaggio sarebbe illegale”

[quote]ROMA – Nella notte tra martedì 30 settembre e mercoledì 1 ottobre diverse barche della Global Sumud Flotilla sono state avvicinate da alcune imbarcazioni non identificate. A bordo c’era anche…
L'articolo Flotilla verso la Striscia. Scotto (Pd): “Nottata in



Da tempo sto provando a ridurre le spese e cerco qualcuno con cui condividere uno spazio che ho affittatto come studio musicale.

Rispondo alla richiesta di questa band che cerca una sala prove.

Mi contatta Enrico, dicendomi che sono in 5, che hanno una cover band di sigle di anime e musiche dei videogiochi.
Mi rassicura sul fatto che sono tutti molto tranquilli e riservati e che fuori dalle prove non li vedrò mai in saletta.
Mi dice che assolutamente non faranno feste in studio e casini vari.

Molto bene dico e mi accordo per fargli vedere il posto e lasciargli le chiavi.

Nel pomeriggio viene a prenderle un ragazzo che sembrava un po' la fotocopia dell'altro: pallidissimo, con i capelli di un nero corvino e gli occhiali da vista spessi. Uguale a st'altro.
Fatalità anche lui si chiama Enrico.

Enrico mi dice che siccome con l'altro Enrico non si sono capiti verrà in studio un'ora dopo. Mi chiede se per favore gli posso lasciare le chiavi da qualche parte.



An FPGA-Based Mechanical Keyboard


You can buy all kinds of keyboards these days, from basic big-brand stuff to obscure mechanical delicacies from small-time builders. Or, you can go the maker route, and build your own. That’s precisely what [Lambert Sartory] did with their Clavier build.

This build goes a bit of a different route to many other DIY keyboards out there, in that [Lambert] was keen to build it around an FPGA instead of an off-the-shelf microcontroller. To that end, the entire USB HID stack was implemented in VHDL on a Lattice ECP5 chip. It was a heavy-duty way to go, but it makes the keyboard quite unique compared to those that just rely on existing HID libraries to do the job. This onboard hardware also allowed [Lambert] to include JTAG, SPI, I2C, and UART interfaces right on the keyboard, as well as a USB hub for good measure.

As for the mechanical design, it’s a full-size 105-key ISO keyboard with one bonus key for good measure. That’s the coffee key, which either locks the attached computer when you’re going for a break, or resets the FPGA with a long press just in case it’s necessary. It’s built with Cherry MX compatible switches, has N-key rollover capability, and a mighty 1000 Hz polling rate. If you can exceed that by hand, you’re some sort of superhuman.

The great thing about building your own keyboard is you can put in whatever features you desire. If you’re whipping up your own neat interface devices, don’t hesitate to let us know!


hackaday.com/2025/10/01/an-fpg…



Forensic journey: hunting evil within AmCache



Introduction


When it comes to digital forensics, AmCache plays a vital role in identifying malicious activities in Windows systems. This artifact allows the identification of the execution of both benign and malicious software on a machine. It is managed by the operating system, and at the time of writing this article, there is no known way to modify or remove AmCache data. Thus, in an incident response scenario, it could be the key to identifying lost artifacts (e.g., ransomware that auto-deletes itself), allowing analysts to search for patterns left by the attacker, such as file names and paths. Furthermore, AmCache stores the SHA-1 hashes of executed files, which allows DFIR professionals to search public threat intelligence feeds — such as OpenTIP and VirusTotal — and generate rules for blocking this same file on other systems across the network.

This article presents a comprehensive analysis of the AmCache artifact, allowing readers to better understand its inner workings. In addition, we present a new tool named “AmCache-EvilHunter“, which can be used by any professional to easily parse the Amcache.hve file and extract IOCs. The tool is also able to query the aforementioned intelligence feeds to check for malicious file detections, this level of built-in automation reduces manual effort and speeds up threat detection, which is of significant value for analysts and responders.

The importance of evidence of execution


Evidence of execution is fundamentally important in digital forensics and incident response, since it helps investigators reconstruct how the system was used during an intrusion. Artifacts such as Prefetch, ShimCache, and UserAssist offer clues about what was executed. AmCache is also a robust artifact for evidencing execution, preserving metadata that indicates a file’s presence and execution, even if the file has been deleted or modified. An advantage of AmCache over other Windows artifacts is that unlike them, it stores the file hash, which is immensely useful for analysts, as it can be used to hunt malicious files across the network, increasing the likelihood of fully identifying, containing, and eradicating the threat.

Introduction to AmCache


Application Activity Cache (AmCache) was first introduced in Windows 7 and fully leveraged in Windows 8 and beyond. Its purpose is to replace the older RecentFileCache.bcf in newer systems. Unlike its predecessor, AmCache includes valuable forensic information about program execution, executed binaries and loaded drivers.

This artifact is stored as a registry hive file named Amcache.hve in the directory C:\Windows\AppCompat\Programs. The metadata stored in this file includes file paths, publisher data, compilation timestamps, file sizes, and SHA-1 hashes.

It is important to highlight that the AmCache format does not depend on the operating system version, but rather on the version of the libraries (DLLs) responsible for filling the cache. In this way, even Windows systems with different patch levels could have small differences in the structure of the AmCache files. The known libraries used for filling this cache are stored under %WinDir%\System32 with the following names:

  • aecache.dll
  • aeevts.dll
  • aeinv.dll
  • aelupsvc.dll
  • aepdu.dll
  • aepic.dll

It is worth noting that this artifact has its peculiarities and limitations. The AmCache computes the SHA-1 hash over only the first 31,457,280 bytes (≈31 MB) of each executable, so comparing its stored hash online can fail for files exceeding this size. Furthermore, Amcache.hve is not a true execution log: it records files in directories scanned by the Microsoft Compatibility Appraiser, executables and drivers copied during program execution, and GUI applications that required compatibility shimming. Only the last category reliably indicates actual execution. Items in the first two groups simply confirm file presence on the system, with no data on whether or when they ran.

In the same directory, we can find additional LOG files used to ensure Amcache.hve consistency and recovery operations:

  • C:\Windows\AppCompat\Programs\Amcache.hve.*LOG1
  • C:\Windows\AppCompat\Programs\Amcache.hve.*LOG2

The Amcache.hve file can be collected from a system for forensic analysis using tools like Aralez, Velociraptor, or Kape.

Amcache.hve structure


The Amcache.hve file is a Windows Registry hive in REGF format; it contains multiple subkeys that store distinct classes of data. A simple Python parser can be implemented to iterate through Amcache.hve and present its keys:
#!/usr/bin/env python3

import sys
from Registry.Registry import Registry

hive = Registry(str(sys.argv[1]))
root = hive.open("Root")

for rec in root.subkeys():
print(rec.name())
The result of this parser when executed is:

AmCache keys
AmCache keys

From a DFIR perspective, the keys that are of the most interest to us are InventoryApplicationFile, InventoryApplication, InventoryDriverBinary, and InventoryApplicationShortcut, which are described in detail in the following subsections.

InventoryApplicationFile


The InventoryApplicationFile key is essential for tracking every executable discovered on the system. Under this key, each executable is represented by its own uniquely named subkey, which stores the following main metadata:

  • ProgramId: a unique hash generated from the binary name, version, publisher, and language, with some zeroes appended to the beginning of the hash
  • FileID: the SHA-1 hash of the file, with four zeroes appended to the beginning of the hash
  • LowerCaseLongPath: the full lowercase path to the executable
  • Name: the file base name without the path information
  • OriginalFileName: the original filename as specified in the PE header’s version resource, indicating the name assigned by the developer at build time
  • Publisher: often used to verify if the source of the binary is legitimate. For malware, this subkey is usually empty
  • Version: the specific build or release version of the executable
  • BinaryType: indicates whether the executable is a 32-bit or 64-bit binary
  • ProductName: the ProductName field from the version resource, describing the broader software product or suite to which the executable belongs
  • LinkDate: the compilation timestamp extracted from the PE header
  • Size: the file size in bytes
  • IsOsComponent: a boolean flag that specifies whether the executable is a built-in OS component or a third-party application/library

With some tweaks to our original Python parser, we can read the information stored within this key:
#!/usr/bin/env python3

import sys
from Registry.Registry import Registry

hive = Registry(sys.argv[1])
root = hive.open("Root")

subs = {k.name(): k for k in root.subkeys()}
parent = subs.get("InventoryApplicationFile")

for rec in parent.subkeys():
vals = {v.name(): v.value() for v in rec.values()}
print("{}\n{}\n\n-----------\n".format(rec, vals))

InventoryApplicationFile subkeys
InventoryApplicationFile subkeys

We can also use tools like Registry Explorer to see the same data in a graphical way:

InventoryApplicationFile inspected through Registry Explorer
InventoryApplicationFile inspected through Registry Explorer

As mentioned before, AmCache computes the SHA-1 hash over only the first 31,457,280 bytes (≈31 MB). To prove this, we did a small experiment, during which we got a binary smaller than 31 MB (Aralez) and one larger than this value (a custom version of Velociraptor). For the first case, the SHA-1 hash of the entire binary was stored in AmCache.

First AmCache SHA-1 storage scenario
First AmCache SHA-1 storage scenario

For the second scenario, we used the dd utility to extract the first 31 MB of the Velociraptor binary:

Stripped binary
Stripped binary

When checking the Velociraptor entry on AmCache, we found that it indeed stored the SHA-1 hash calculated only for the first 31,457,280 bytes of the binary. Interestingly enough, the Size value represented the actual size of the original file. Thus, relying only on the file hash stored on AmCache for querying threat intelligence portals may be not enough when dealing with large files. So, we need to check if the file size in the record is bigger than 31,457,280 bytes before searching threat intelligence portals.

Second AmCache SHA-1 storage scenario
Second AmCache SHA-1 storage scenario

Additionally, attackers may take advantage of this characteristic to purposely generate large malicious binaries. In this way, even if investigators find that a malware was executed/present on a Windows system, the actual SHA-1 hash of the binary will still be unknown, making it difficult to track it across the network and gathering it from public databases like VirusTotal.

InventoryApplicationFile – use case example: finding a deleted tool that was used


Let’s suppose you are searching for a possible insider threat. The user denies having run any suspicious programs, and any suspicious software was securely erased from disk. But in the InventoryApplicationFile, you find a record of winscp.exe being present in the user’s Downloads folder. Even though the file is gone, this tells you the tool was on the machine and it was likely used to transfer files before being deleted. In our incident response practice, we have seen similar cases, where this key proved useful.

InventoryApplication


The InventoryApplication key records details about applications that were previously installed on the system. Unlike InventoryApplicationFile, which logs every executable encountered, InventoryApplication focuses on those with installation records. Each entry is named by its unique ProgramId, allowing straightforward linkage back to the corresponding InventoryApplicationFile key. Additionally, InventoryApplication has the following subkeys of interest:

  • InstallDate: a date‑time string indicating when the OS first recorded or recognized the application
  • MsiInstallDate: present only if installed via Windows Installer (MSI); shows the exact time the MSI package was applied, sourced directly from the MSI metadata
  • UninstallString: the exact command line used to remove the application
  • Language: numeric locale identifier set by the developer (LCID)
  • Publisher: the name of the software publisher or vendor
  • ManifestPath: the file path to the installation manifest used by UWP or AppX/MSIX apps

With a simple change to our parser, we can check the data contained in this key:
<...>
parent = subs.get("InventoryApplication")
<...>

InventoryApplication subkeys
InventoryApplication subkeys

When a ProgramId appears both here and under InventoryApplicationFile, it confirms that the executable is not merely present or executed, but was formally installed. This distinction helps us separate ad-hoc copies or transient executions from installed software. The following figure shows the ProgramId of the WinRAR software under InventoryApplicationFile.

When searching for the ProgramId, we find an exact match under InventoryApplication. This confirms that WinRAR was indeed installed on the system.

Another interesting detail about InventoryApplication is that it contains a subkey named LastScanTime, which is stored separately from ProgramIds and holds a value representing the last time the Microsoft Compatibility Appraiser ran. This is a scheduled task that launches the compattelrunner.exe binary, and the information in this key should only be updated when that task executes. As a result, software installed since the last run of the Appraiser may not appear here. The LastScanTime value is stored in Windows FileTime format.

InventoryApplication LastScanTime information
InventoryApplication LastScanTime information

InventoryApplication – use case example: spotting remote access software


Suppose that during an incident response engagement, you find an entry for AnyDesk in the InventoryApplication key (although the application is not installed anymore). This means that the attacker likely used it for remote access and then removed it to cover their tracks. Even if wiped from disk, this key proves it was present. We have seen this scenario in real-world cases more than once.

InventoryDriverBinary


The InventoryDriverBinary key records every kernel-mode driver that the system has loaded, providing the essential metadata needed to spot suspicious or malicious drivers. Under this key, each driver is captured in its own uniquely named subkey and includes:

  • FileID: the SHA-1 hash of the driver binary, with four zeroes appended to the beginning of the hash
  • LowerCaseLongPath: the full lowercase file path to the driver on disk
  • DigitalSignature: the code-signing certificate details. A valid, trusted signature helps confirm the driver’s authenticity
  • LastModified: the file’s last modification timestamp from the filesystem metadata, revealing when the driver binary was most recently altered on disk

Because Windows drivers run at the highest privilege level, they are frequently exploited by malware. For example, a previous study conducted by Kaspersky shows that attackers are exploiting vulnerable drivers for killing EDR processes. When dealing with a cybersecurity incident, investigators correlate each driver’s cryptographic hash, file path, signature status, and modification timestamp. That can help in verifying if the binary matches a known, signed version, detecting any tampering by spotting unexpected modification dates, and flagging unsigned or anomalously named drivers for deeper analysis. Projects like LOLDrivers help identify vulnerable drivers in use by attackers in the wild.

InventoryDriverBinary inspection
InventoryDriverBinary inspection

In addition to the InventoryDriverBinary, AmCache also provides the InventoryApplicationDriver key, which keeps track of all drivers that have been installed by specific applications. It includes two entries:

  • DriverServiceName, which identifies the name of the service linked to the installed driver; and
  • ProgramIds, which lists the program identifiers (corresponding to the key names under InventoryApplication) that were responsible for installing the driver.

As shown in the figure below, the ProgramIds key can be used to track the associated program that uses this driver:

Checking program information by ProgramIds
Checking program information by ProgramIds

InventoryDriverBinary – use case example: catching a bad driver


If the system was compromised through the abuse of a known vulnerable or malicious driver, you can use the InventoryDriverBinary registry key to confirm its presence. Even if the driver has been removed or hidden, remnants in this key can reveal that it was once loaded, which helps identify kernel-level compromises and supporting timeline reconstruction during the investigation. This is exactly how the AV Killer malware was discovered.

InventoryApplicationShortcut


This key contains entries for .lnk (shortcut) files that were present in folders like each user’s Start Menu or Desktop. Within each shortcut key, the ShortcutPath provides the absolute path to the LNK file at the moment of discovery. The ShortcutTargetPath shows where the shortcut pointed. We can also search for the ProgramId entry within the InventoryApplication key using the ShortcutProgramId (similar to what we did for drivers).

InventoryApplicationShortcut key
InventoryApplicationShortcut key

InventoryApplicationShortcut – use case example: confirming use of a removed app


You find that a suspicious program was deleted from the computer, but the user claims they never ran it. The InventoryApplicationShortcut key shows a shortcut to that program was on their desktop and was accessed recently. With supplementary evidence, such as that from Prefetch analysis, you can confirm the execution of the software.

AmCache key comparison


The table below summarizes the information presented in the previous subsections, highlighting the main information about each AmCache key.

KeyContainsIndicates execution?
InventoryApplicationFileMetadata for all executables seen on the system.Possibly (presence = likely executed)
InventoryApplicationMetadata about formally installed software.No (indicates installation, not necessarily execution)
InventoryDriverBinaryMetadata about loaded kernel-mode drivers.Yes (driver was loaded into memory)
InventoryApplicationShortcutInformation about .lnk files.Possibly (combine with other data for confirmation)

AmCache-EvilHunter


Undoubtedly Amcache.hve is a very important forensic artifact. However, we could not find any tool that effectively parses its contents while providing threat intelligence for the analyst. With this in mind, we developed AmCache-EvilHunter a command-line tool to parse and analyze Windows Amcache.hve registry hives, identify evidence of execution, suspicious executables, and integrate Kaspersky OpenTIP and VirusTotal lookups for enhanced threat intelligence.

AmCache-EvilHunter is capable of processing the Amcache.hve file and filter records by date range (with the options --start and --end). It is also possible to search records using keywords (--search), which is useful for searching for known naming conventions adopted by attackers. The results can be saved in CSV (--csv) or JSON (--json) formats.

The image below shows an example of execution of AmCache-EvilHunter with these basic options, by using the following command:
amcache-evilhunter -i Amcache.hve --start 2025-06-19 --end 2025-06-19 --csv output.csv
The output contains all applications that were present on the machine on June 19, 2025. The last column contains information whether the file is an operating system component, or not.

Basic usage of AmCache-EvilHunter
Basic usage of AmCache-EvilHunter

CSV result
CSV result

Analysts are often faced with a large volume of executables and artifacts. To narrow down the scope and reduce noise, the tool is able to search for known suspicious binaries with the --find-suspicious option. The patterns used by the tool include common malware names, Windows processes containing small typos (e.g., scvhost.exe), legitimate executables usually found in use during incidents, one-letter/one-digit file names (such as 1.exe, a.exe), or random hex strings. The figure below shows the results obtained by using this option; as highlighted, one svchost.exe file is part of the operating system and the other is not, making it a good candidate for collection and analysis if not deleted.

Suspicious files identification
Suspicious files identification

Malicious files usually do not include any publisher information and are definitely not part of the default operating system. For this reason, AmCache-EvilHunter also ships with the --missing-publisher and --exclude-os options. These parameters allow for easy filtering of suspicious binaries and also allow fast threat intelligence gathering, which is crucial during an incident.

Another important feature that distinguishes our tool from other proposed approaches is that AmCache-EvilHunter can query Kaspersky OpenTIP (--opentip ) and VirusTotal (--vt) for hashes it identifies. In this way, analysts can rapidly gain insights into samples to decide whether they are going to proceed with a full analysis of the artifact or not.

Threat intel lookup
Threat intel lookup

Binaries of the tool are available on our GitHub page for both Linux and Windows systems.

Conclusion


Amcache.hve is a cornerstone of Windows forensics, capturing rich metadata, such as full paths, SHA-1 hashes, compilation timestamps, publisher and version details, for every executable that appears on a system. While it does not serve as a definitive execution log, its strength lies in documenting file presence and paths, making it invaluable for spotting anomalous binaries, verifying trustworthiness via hash lookups against threat‐intelligence feeds, and correlating LinkDate values with known attack campaigns.

To extract its full investigative potential, analysts should merge AmCache data with other artifacts (e.g., Prefetch, ShimCache, and Windows event logs) to confirm actual execution and build accurate timelines. Comparing InventoryApplicationFile entries against InventoryApplication reveals whether a file was merely dropped or formally installed, and identifying unexpected driver records can expose stealthy rootkits and persistence mechanisms. Leveraging parsers like AmCache-EvilHunter and cross-referencing against VirusTotal or proprietary threat databases allows IOC generation and robust incident response, making AmCache analysis a fundamental DFIR skill.


securelist.com/amcache-forensi…



Oggi 1° ottobre, memoria liturgica di Santa Teresa di Lisieux, il vescovo di Macerata Nazzareno Marconi ha presieduto il rito di benedizione per l’apertura del cantiere di restauro della chiesa di Santa Maria delle Grazie a Tolentino.


Porting a Fortran Flight Simulator to Unity3D


There’s an old saying (paraphrasing a quote attributed to Hoare): “I don’t know what language scientists will use in the future, but I know it will be called Fortran.” The truth is, there is a ton of very sophisticated code in Fortran, and if you want to do something more modern, it is often easier to borrow it than to reinvent the wheel. When [Valgriz] picked up a textbook on aircraft simulation, he noted that it had an F-16 simulation in it. In Fortran. The challenge? Port it to Unity3D.

If you have a gamepad, you can try the result. However, the real payoff is the blog posts describing what he did. They go back to 2021, although the most recent was a few months ago, and they cover the entire process in great detail. You can also find the code on GitHub. If you are interested in flight simulation, flying, Fortran, or Unity3D, you’ll want to settle in and read all four posts. That will take some time.

One limitation. The book’s simulator was all about modeling the aerodynamics using data from wind tunnel tests. However, the F-16 is notorious for being a negative stability aircraft — meaning it’s virtually impossible to fly by hand. It is very maneuverable, but only if you let the computer drive using the flight control system. When you direct the aircraft, the control system makes your desire happen, while accounting for all the strange extra motions the plane will create as it flies.

The problem: the book doesn’t include code for the flight controller. [Valgriz], of course, wrote his own. He uses some PID controllers along with limiters for G-force and angle of attack. Interestingly, to do this, the simulator actually runs its own stripped-down simulator to determine the effects of different control inputs.

This is one of those projects we aren’t sure we would attempt, but we’re glad someone did, and we can watch. Just be careful. An interest in flight simulation can lead to reduced space in your garage. We know of at least one F-16, by the way, that has an Arduino in it. However, it is probably the only one.

youtube.com/embed/2HZQnnxdISM?…

youtube.com/embed/7vAHo2B1zLc?…


hackaday.com/2025/10/01/portin…



“Siamo scioccate dal misbruik e colpite dal coraggio delle vittime che hanno deciso di raccontare la loro storia. Condanniamo ogni forma di abuso e offriamo alle vittime le nostre scuse e il nostro cordoglio”.


A ‘stray bullet’ 25,000 people offline near Dallas.#News


A Bullet Crashed the Internet in Texas


The internet can be more physically vulnerable than you think. Last week, thousands of people in North and Central Texas were suddenly knocked offline. The cause? A bullet. The outage hit cities all across the state, including Dallas, Irving, Plano, Arlington, Austin, and San Antonio. The outage affected Spectrum customers and took down their phone lines and TV services as well as the internet.

“Right in the middle of my meetings 😒,” one users said on the r/Spectrum subreddit. Around 25,000 customers were without services for several hours as the company rushed to repair the lines. As the service came back,, WFAA reported that the cause of the outage came from the barrel of a gun. A stray bullet had hit a line of fiber optic cable and knocked tens of thousands of people offline.
playlist.megaphone.fm?p=TBIEA2…
“The outage stemmed from a fiber optic cable that was damaged by a stray bullet,” Spectrum told 404 Media. “Our teams worked quickly to make the necessary repairs and get customers back online. We apologize for the inconvenience.”

Spectrum told 404 Media that it didn’t have any further details to share about the incident so we have no idea how the company learned a bullet hit its equipment, where the bullet was found, and if the police are involved. Texas is a massive state with overlapping police jurisdictions and a lot of guns. Finding a specific shooting incident related to telecom equipment in the vast suburban sprawl around Dallas is probably impossible.

Fiber optic cable lines are often buried underground, protected from the vagaries of southern gunfire. But that’s not always the case, fiber can be strung along telephone poles in the sky and sent to a vast and complicated network junction boxes and service stations that overlap different municipalities and cities, each with their own laws about how the cable can be installed. That can leave pieces of the physical infrastructure of the internet exposed to gunfire and other mischief.

This is not the first time gunfire has taken down the internet. In 2022, Xfinity fiber cable in Oakland, California went offline after people allegedly fired 17 rounds into the air near one of the company’s fiber lines. Around 30,000 people were offline during that outage and it happened moments before the start of an NFL game that saw the Los Angeles Rams square off against the San Francisco 49ers.

“We could not be more apologetic and sincerely upset that this is happening on a day like today,” Comcast spokesperson Joan Hammel told Dater Center Dynamics at the time. Hammel added that the company has seen gunshot wounds on its equipment before. “While this isn’t completely uncommon, it is pretty rare, but we know it when we see it.”


#News

Breaking News Channel reshared this.



Quale sarà il futuro di Daniel Ek dopo Spotify?

L'articolo proviene da #StartMag e viene ricondiviso sulla comunità Lemmy @Informatica (Italy e non Italy 😁)
Nel 2026 Daniel Ek lascerà la carica di amministratore delegato di Spotify, azienda che in quasi vent'anni ha rivoluzionato l'industria della musica (e non solo). Il co-fondatore ha spiegato di volersi concentrare sullo sviluppo di nuove startup innovative



Student journalists fight Trump’s anti-speech deportations


It’s not every day a student newspaper takes on the federal government. But that’s exactly what The Stanford Daily is doing.

Backed by the Foundation for Individual Rights and Expression, the Daily sued Secretary of State Marco Rubio and Secretary of Homeland Security Kristi Noem in August over the Trump administration’s push to deport foreign students for exercising free speech, like writing op-eds and attending protests. The suit argues the administration’s actions violate the First Amendment by retaliating against foreign students for protected speech and chill press freedom by discouraging them from speaking to and writing for the Daily.

We spoke at the start of Stanford University’s fall term with Greta Reich, editor-in-chief of the Daily and president of Stanford Daily Publishing Corp., which operates the paper, about why the Daily is fighting back, even as many corporate media outlets stay silent or capitulate.

Why did The Stanford Daily decide to take this issue to court?

We decided to take this issue to court because we believe legal action would be best for the Daily. Our mission as an independent student paper is to represent the voices of the Stanford community. We cannot fulfill this mission to the fullest extent when a significant portion of students on our campus and in our newsroom are afraid to speak up. The decision ultimately came down to whether or not we felt we could handle the potential negative ramifications of a public suit against the government in order to stay true to our mission. We decided that we could, and we’re hoping for the best outcome.

What happens to your reporting when international students are afraid to talk to your reporters, or when staff quit or avoid covering certain stories because they’re worried about government retaliation?

As we said in our letter from the editors on the lawsuit, fear of government retaliation directly impacts the quality of the Daily’s work.

With every resignation, declined assignment, and refusal to speak on the record, we actively miss out on covering an entire group of students’ voices — as well as the many events and stories on campus that benefit from an international student’s perspective. We are simply not able to conduct our business when speech is chilled like this.

Journalism, and especially student journalism, depends on members of a community not only being able to speak on the record but actively wanting to, at least at times. When an entire subsection of the student population doesn’t feel comfortable speaking with or writing for the Daily, we can’t know what stories are being lost.

When an entire subsection of the student population doesn’t feel comfortable speaking with or writing for the Daily, we can’t know what stories are being lost.


Greta Reich, editor-in-chief of The Stanford Daily

How have people on campus responded to the lawsuit so far?

We only returned to campus this week, so I don’t think I’ve seen every reaction yet, but so far the biggest response has been curiosity. Many of my peers, both in and outside of the Daily, have questions about how the lawsuit is going.

In speaking more in depth with some students throughout the summer and hearing feedback on various social platforms, I know there is a somewhat mixed reaction, though I think it skews positive. Some students, understandably, are concerned about the attention the suit will draw to Stanford as a university. Others have expressed excitement about action being taken to protect First Amendment rights.

I hope that as the suit progresses, students, alumni, faculty, and community members will feel comfortable sharing any opinion with us — we want to hear what people have to say!

How does it feel to stand up for the First Amendment as student journalists when some in corporate media are utterly failing to do so?

It feels great! As student journalists, we definitely face a different set of obstacles and constraints than those in corporate media do. I think that, in a way, these different constraints give us the freedom to take actions like these (though it would be exciting to see more publications taking action too). I am incredibly grateful for all of the support I’ve received from professional journalists and mentors in corporate media, who have reached out with kind words for the Daily. It is not taken for granted one bit.

What outcome are you hoping for, both in terms of the law, but also inspiring student journalists or impacting the national conversation about press freedom?

In terms of the law, we are obviously hoping for the lawsuit to create a real change in how noncitizens are treated with respect to the First Amendment. Whether working for or speaking to our newspaper, no one should fear deportation for what they have to say. In any scenario, I hope those who hear about this lawsuit consider what it means to have a free press and why fear tactics like those the government is currently using have such an impact on it. A central tenet of my education at Stanford has been to form and express my thoughts and opinions with agility. The ability to state these thoughts and opinions publicly is not only being threatened but actively taken away.

And to other student journalists: I am constantly inspired by you and your work, and I hope you are getting through this year with support and engagement from your staff and readers.


freedom.press/issues/student-j…




Al via dal 4 ottobre il XXII Congresso dell’Associazione Luca Coscioni


Appuntamento sabato 4 ottobre alle 9.30 al Palazzo del Capitano del Popolo, in piazza del Popolo 1 ad Orvieto. Il Congresso si svolgerà anche nella giornata di domenica 5 ottobre

Il titolo si ispira a una frase di Laura Santi: “Non rassegnatevi mai”


Oltre 170mila persone hanno sostenuto le nostre richieste alla politica per rimuovere le discriminazioni su fine vita, PMA, aborto e psichedelici. Sono 39 le azioni legali intraprese, 241 le richieste di accesso agli atti. Il Congresso sarà anche l’occasione per fare il punto sui nuovi obiettivi e le azioni politiche del 2026. Filomena Gallo e Marco Cappato commentano: “Non stiamo ad aspettare che vengano tempi migliori per i diritti civili, altrimenti si rischia di tornare indietro come negli USA“.


Nonostante l’ostilità o l’inerzia dei vertici della politica ufficiale e dei partiti, il 2025 è stato un anno di conquiste e azioni concrete per la libertà di scelta, l’autodeterminazione e il diritto alla salute. Dall’approvazione di due leggi regionali per tempi certi di erogazione delle prestazioni sul “suicidio assistito” in Toscana e Sardegna, con proposte analoghe depositate in tutte le Regioni fino alla proposta di legge nazionale in Parlamento per legalizzare l’eutanasia.

E poi, quattro sentenze della Corte costituzionale ottenute tramite procedimenti giudiziari accanto alle persone: due sul fine vita (sentenze 66/2025 e 132/2025) che interpretano come deve essere considerato il requisito del trattamento di sostegno vitale, una sull’accesso alla procreazione medicalmente assistita per donne singole che evidenzia che la cancellazione del divieto non incontra ostacoli costituzionali; una sentenza che ammette con sentenza di incostituzionalità, la firma certificata per le persone che non possono firmare manualmente le liste elettorali, attuando piena partecipazione politica alla vita del paese senza discriminazioni.

La richiesta di garantire l’aborto farmacologico senza obbligo di ricovero e la possibilità alle persone con disabilità di viaggiare in aereo con la propria carrozzina; la pressione sulle ASL per il diritto alla salute in carcere; liste di attesa azioni per garanzie nell’ accesso alle prestazioni. L’Associazione Luca Coscioni ha trasformato nell’ultimo anno le battaglie civili in conquiste di libertà.

Il XXII Congresso, in programma il 4 e 5 ottobre 2025 a Orvieto porrà le basi per le azioni future nella nella Regione dove sono nati Luca Coscioni, pioniere della libertà di ricerca scientifica, e Laura Santi, leader e volto della campagna sul fine vita, che dopo un calvario giudiziario di tre anni ha ottenuto il diritto ad accedere al “suicidio assistito” nel suo Paese, sostenuta dall’Associazione. “Non rassegnatevi mai”, le sue ultime parole, insieme alla memoria di Luca, saranno il filo conduttore del Congresso e delle strategie future dell’Associazione.

Filomena Gallo e Marco Cappato, rispettivamente Segretaria nazionale dell’Associazione e Tesoriere dell’Associazione, hanno dichiarato: “La nostra missione è quella di dare voce e volto alle persone rese invisibili dalla ottusità e dalla violenza delle istituzioni ancora di più che dalla malattia o dalla disabilità e di consentire loro di battersi in prima persona. Non aspettiamo che ‘vengano tempi migliori’ per le libertà civili, perché rischierebbero di non arrivare mai. Infatti, in assenza di lotte sociali nonviolente, in grado di imporsi nell’agenda della politica ufficiale, si rischia anche nel nostro Paese, come sta avvenendo negli USA e in altri Paesi formalmente democratici, un arretramento sul piano dei diritti civili“.

➡ Oltre 170mila firme raccolte


Nell’ultimo anno l’Associazione Luca Coscioni ha raccolto le firme di oltre 170 mila persone in tutta Italia sui temi principali delle sue ventennali battaglie: eutanasia e fine vita, procreazione medicalmente assistita, gravidanza per altri, Aborto senza ricovero, per garantire la possibilità di deospedalizzare l’aborto farmacologico, disabilità, terapie assistite da psichedelici, cannabis legale e firma digitale.

A queste si aggiungono le firme 65.000, raccolte in questi anni su Liberi Subito, la proposta di legge regionale che garantisce il percorso di richiesta di suicidio medicalmente assistito e i controlli necessari in tempi certi e adeguati.

➡ Sono state intraprese 39 azioni legali


Fine vita: 24 procedimenti di cui 18 civili e 6 penali, riguardo l’accesso al “suicidio assistito” in Italia e le disobbedienze civili per l’accompagnamento in Svizzera. Di questi 10 sono attualmente in tribunale e gli altri in fase stragiudiziale. Mentre per i procedimenti penali: un procedimento con tre persone sulle quali pende una imputazione coatta (Felicetta Maltese, Chiara Lalli e Marco Cappato) e altre nove indagate nei cinque procedimenti in cui sono in corso le indagini.

PMA: 15 casi sul tema della fecondazione assistita nei tribunali, di cui oltre 10 sul tema della gravidanza per altri (GPA). Di questi 10, almeno 7 anche sul fronte penale. Sono oltre 50 i casi su cui sono stati forniti pareri in fase stragiudiziale. Sul tema della PMA, è stata ottenuta una sentenza della Corte costituzionale in merito all’accesso alla PMA per donne singole a partire del caso di Evita, 40enne torinese, cui è stata negato l’accesso in Italia alla PMA.

➡ Sono stati condotti 241 accessi agli atti


Salute in carcere: a seguito delle diffide per verificare le condizioni igienico-sanitarie negli istituti penitenziari, sono state effettuate 102 richieste di accesso agli atti a tutte le ASL italiane per ottenere le relazioni delle visite in carcere in modo da monitorare le condizioni degli istituti.

Fine vita (“suicidio assistito”): sono state effettuate 93 richieste di accesso agli atti tra Regioni e ASL per conoscere il numero di richieste di accesso al “suicidio assistito” effettuate in Italia dalla sentenza della Corte costituzionale 242 del 2019 sul caso Cappato-Dj Fabo che ha di fatto legalizzato l’accesso alla morte volontaria assisita in Italia a determinate condizioni.

Sempre in tema di fine vita, oltre 16.000 cittadini hanno ricevuto informazioni tramite il Numero Bianco su diritti legati a fine vita. Le iniziative popolari hanno portato all’approvazione di 2 leggi regionali sul suicidio assistito, al deposito in tutte le Regioni (discussa in 6), mentre sono state ottenute 2 udienze in Corte costituzionale sul fine vita. A livello nazionale, è stata depositata una proposta di legge di iniziativa popolare per legalizzare l’eutanasia. Sono 16.000, inoltre, i testamenti biologici scaricati dal sito dell’Associazione.

Barriere architettoniche: L’Associazione sta conducendo anche una attività di ricognizione dei Piani di Eliminazione delle barriere architettoniche nei comuni capoluoghi italiani. A fronte delle informazioni reperite sui siti di 60 capoluoghi, sono state promosse 46 richieste di accessi agli atti nelle restanti città. All’accesso, per il momento, hanno risposto 17 capoluoghi.

➡ Partecipazione e mobilitazione


Oltre 585 eventi pubblici in tutta Italia hanno portato nelle piazze e nelle città temi sociali e scientifici spesso ignorati dalla politica, coinvolgendo 45.000 persone in campagne, petizioni e azioni politiche. Sono state inoltre depositate 2 proposte di legge in Parlamento, una sul fine vita e una sulla legalizzazione della gravidanza per altri.

L'articolo Al via dal 4 ottobre il XXII Congresso dell’Associazione Luca Coscioni proviene da Associazione Luca Coscioni.





A proposito di treni bloccati…

@Politica interna, europea e internazionale

In Germania, un’italiana di Bolzano prende in mano le rotaie delle ferrovie pubbliche. Evelyn Palla, manager cresciuta all’estero ma di chiare origini italiane, è stata nominata alla guida della Deutsche Bahn. Sarà la prima donna a dirigere il colosso tedesco, con un compito ben chiaro: rimettere sui binari un sistema ferroviario che da orgoglio



2025, una lunga estate (troppo) calda


@Notizie dall'Italia e dal mondo
Nel corso del 2025, l’Europa ha di nuovo vissuto un’estate segnata da incendi devastanti e temperature record, con effetti che si intrecciano a disuguaglianze sociali e fragilità economiche. Dalle ondate di calore alla cooling poverty, il cambiamento climatico ha mostrato ancora una volta il suo
L'articolo 2025, una lunga estate (troppo) calda

Mauro in montagna reshared this.



Accidenti, il genocidio è già finito

@Politica interna, europea e internazionale

E ora, come la mettiamo con l’ipotesi genocidaria? Ora che Benjamin Netanyahu ha accettato un piano di pace che non prevede la deportazione dei palestinesi da Gaza, ma, al contrario, la nascita di un governo guidato da “palestinesi”, come potranno i teorici dell’orrida similitudine tra lo Stato di Israele e il Terzo Reich andare



Missili Houthi su nave cargo europea. Perché l’attacco riguarda tutti noi

@Notizie dall'Italia e dal mondo

Il Golfo di Aden, già da tempo teatro di tensioni, è tornato al centro delle cronache a seguito dell’attacco al cargo olandese Minervagracht. Colpita da missili Houthi e ridotta in fiamme, la nave è stata evacuata grazie all’intervento delle fregate europee della missione



MAROCCO. La Generazione Z scende in piazza


@Notizie dall'Italia e dal mondo
I giovani marocchini crescono in un mondo digitale ricco di immagini da ogni parte del mondo che mostrano diritti garantiti e standard di qualità. E li vogliono anche in Marocco
L'articolo MAROCCO. La Generazione Z scende in piazza proviene dahttps://pagineesteri.it/2025/10/01/africa/marocco-la-generazione-z-scende-in-piazza/






Il rock della prigione
freezonemagazine.com/rubriche/…
“La guardia organizzò una festa nella prigione della contea, la band era lì e cominciò a darci dentro, la band stava saltando e tutti i carcerati cominciarono ad agitarsi, avreste dovuto sentire come cantavano quei perdenti uccellini in gabbia. Scateniamoci tutti quanti, scateniamoci tutti quanti nell’intero settore delle celle. Ballavano il Rock della Prigione“. In […]
L'articolo Il rock della pr
“La


Qualcuno/a di voi avrà letto che dopo le sanzioni americane contro Francesca Albanese lei aveva provato ad aprire un conto presso Banca Etica e che la banca non aveva potuto aprirglielo.

La spiegazione, in breve:

le banche che offrono servizi a individui o entità presenti nelle liste Ofac sono passibili di sanzioni civili (multe di milioni di dollari, confisca di fondi e asset delle persone sanzionate, etc.) e penali, restrizioni operative su tutta l’operatività in dollari di tutti i clienti, controlli più rigidi e audit da parte delle autorità, implementazione di programmi di compliance più severi che ne possono bloccare interamente l’operatività anche per lunghi periodi di tempo.


Per chi volesse approfondire invece:
altreconomia.it/perche-banca-e…

reshared this



rainews.it/articoli/2025/09/uc…

“Salvatore - dice ancora il prete - è una persona fragile, tranquilla. Un lavoratore, anche se in passato aveva sofferto di una depressione da cui era guarito”.

Poverino... mi fa una pena...

E invece della moglie e del figlio minorenne, uccisi a sassate, e della figlia in prognosi riservata con una frattura cranica, sempre per i colpi con un sasso, non abbiamo nulla da dire?

Loro non erano "grandi lavoratori"? Non erano persone tranquille? La loro salute com'era?

Loro non salutavano sempre?

E questa è la Rai, gente che dovrebbe avere un'infarinatura di come è opportuno raccontare i femminicidi, e invece... una professionalità da giornalino studentesco.



:: ACUFENI :: FASTIDI AURICOLARI CONTEMPORANEI #32


Nuove recensioni su :: acufeni ::
Questa settimana ci siamo persi (e ritrovati) tra post punk, elettronica, black metal e patchwork sonori fuori da ogni schema.

- Coded Marking – debutto impeccabile, forse fin troppo. Un album che avrebbe potuto gridare, ma sceglie di sussurrare.
- Giant Claw – libertà totale e ironia sonora: un patchwork che funziona come poche volte capita.
- Sea Mosquito – spiritualità oscura e critica alla modernità: psichedelia e black metal intrecciati in un lavoro imponente, anche se non perfetto.
- Siavash Amini – Caligo: la polvere dei bombardamenti a Teheran trasformata in un suono che fa male.
- Xeeland – Master Builder: drone e krautrock per costruire cattedrali di cemento sonoro, fredde e opprimenti.

#iyezine #inyoureyesezine #iyezine.com
iyezine.com/acufeni-fastidi-au…
@Musica Agorà



I sondaggi anonimi su Mastodon sono davvero anonimi? Beh, parliamone...

Riportiamo una sintesi di un post pubblicato un anno fa da @Terence Eden sulla questione dell'anonimato nei sondaggi di Mastodon, ma il post richiama l'attenzione sul fatto che tutto ciò che rende aperto il Fediverso rende necessaria una maggiore consapevolezza da parte degli utenti.

Quando voti in un sondaggio, il tuo server invia un messaggio al server dell'utente che ha creato quel sondaggio dicendo: "Sono l'utente @XXXX@YYY.ZZ e desidero votare per l'opzione X. Ecco una firma HTTP che conferma il mio messaggio."

Le specifiche Activitystreams relative ai sondaggi non sono definite benissimo e anche la documentazione di Mastodon è un po' vaga. Nessuno dei due affronta con chiarezza la questione della privacy.

C'è un eccellente post sul blog di @Humberto Rocha (Aprovecho la oportunidad... Hola Humberto, ¿podrías arreglar el enlace a tu cuenta de Mastodon en tu blog?) che analizza il sondaggio Mastodon in ActivityPub. Mostra chiaramente che un voto è solo un normale messaggio che viene trasmesso al server ricevente.

Servizi come Mastodon sono appositamente sviluppati per non permettere all'autore del sondaggio di vedere chi ha votato e per quale opzione.

Ma questa è solo una convenzione. Non c'è nulla di tecnico che impedisca di recuperare quel dato. Se quel dato esiste, allora c'è un modo per intercettarlo. Un server mastodon inaffiddabile o appositamente configurato per raccogliere dati può collegare le tue preferenze al tuo account

Pertanto, quando vedi un sondaggio su Mastodon, poniti sempre queste domande:

1) dichiarare una preferenza in quel sondaggio può danneggiarmi?
2) il server cui appartiene l'utente che lancia il sondaggio rispetta il GDPR oppure è un server extracomunitario? O, peggio, è un server comunitario senza privacy policy o con una privacy policy ricopiata da un altro server?

All'esposizione di un qualsiasi dato personale, infatti, corrisponde sempre una riduzione delle proprie difese.

Da chi potrebbe essere sfruttata questa caratteristica?

1) un attore che lo fa attraverso un server malevolo, appositamente configurato per raccogliere quetsi dati
2) un attore che lo fa attraverso un server che ha compromesso

Perché qualcuno dovrebbe sfruttare questa caratteristica?

1) per profilare il tuo account anonimo/pseudonimo e renderne più facile l'identificazione
2) per profilare te e il tuo account già correlato alla tua vera identità e colpirti dal punto di vista reputazionale (al tuo datore di lavoro piace avere dipendenti sotto l'attacco di una shitstorm?) o legale (pensa solo a come il governo degli USA sta rendendo illegali opinioni e comportamenti)

Se sei interessato a questi contenuti sul #Fediverso puoi seguire l'utente @Che succede nel Fediverso?; si tratta di un "gruppo activitypub" che simula i gruppi Facebook: quando lo segui, l'account ti ricondivide tutti i messaggi di chi lo menziona! Se vuoi scrivere un post sul Fediverso, ricordati di menzionare quell'utente alla fine del tuo nuovo messaggio

shkspr.mobi/blog/2024/09/no-ac…

reshared this

in reply to Poliverso - notizie dal Fediverso ⁂

La prima volta che ho fatto un sondaggio mi sono chiesto perché alla fine non mi dicesse chi aveva votato cosa, l'ho sempre trovato strano, mi è sempre stato evidente che "il sistema" avesse l'informazione e mi è sempre sembrato un difetto che questa informazione non fosse accessibile.

Concordo, se si vogliono sondaggi anonimi, l'anonimato va gestito a livello di protocollo. Non chiamerei neppure "malevolo" un server che mostri le informazioni che ha…
@humrochagf @Edent @fediverso

in reply to Pare 🚲 🌞

Comunque il programma che uso per il fediverso, quando scrivo messaggi diretti (privati? personali?) apre un riquadro per ricordarmi che non c'è alcuna vera garanzia di protezione.
Forse sarebbe bene mettere un messaggio del genere anche ogni volta che viene proposto di rispondere a un sondaggio?

Sui media della "concorrenza" non viene ricordato ad ogni piè sospinto che "il sistema registra molte più cose di quanto pensiate", ma qui val la pena farlo, no?
@humrochagf @Edent @fediverso

Questa voce è stata modificata (8 ore fa)
in reply to Pare 🚲 🌞

@Pare 🚲 🌞 @Humberto Rocha @Terence Eden

Forse sarebbe bene mettere un messaggio del genere anche ogni volta che viene proposto di rispondere a un sondaggio?

Sono d'accordo

Fediverso reshared this.

in reply to Pare 🚲 🌞

@Pare 🚲 🌞 il sondaggio deve restare "segreto", soprattutto per evitare effetti distorsivi sui partecipanti ed è giusto che resti "anonimo" perché fa parte del gioco. Ma il punto è che si tratta di un gioco, non di una votazione ufficiale 😅

@Humberto Rocha @Terence Eden

Fediverso reshared this.




Documents show that ICE has gone back on its decision to not use location data remotely harvested from peoples' phones. The database is updated every day with billions of pieces of location data.

Documents show that ICE has gone back on its decision to not use location data remotely harvested from peoplesx27; phones. The database is updated every day with billions of pieces of location data.#News


ICE to Buy Tool that Tracks Locations of Hundreds of Millions of Phones Every Day


Immigration and Customs Enforcement (ICE) has bought access to a surveillance tool that is updated every day with billions of pieces of location data from hundreds of millions of mobile phones, according to ICE documents reviewed by 404 Media.

The documents explicitly show that ICE is choosing this product over others offered by the contractor’s competitors because it gives ICE essentially an “all-in-one” tool for searching both masses of location data and information taken from social media. The documents also show that ICE is planning to once again use location data remotely harvested from peoples’ smartphones after previously saying it had stopped the practice.

Surveillance contractors around the world create massive datasets of phones’, and by extension people’s movements, and then sell access to the data to government agencies. In turn, U.S. agencies have used these tools without a warrant or court order.

“The Biden Administration shut down DHS’s location data purchases after an inspector general found that DHS had broken the law. Every American should be concerned that Trump's hand-picked security force is once again buying and using location data without a warrant,” Senator Ron Wyden told 404 Media in a statement.

💡
Do you know anything else about this contract or others? Do you work at Penlink or ICE? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

The ICE document is redacted but says a product made by a contractor called Penlink “leverages a proprietary data platform to compile, process, and validate billions of daily location signals from hundreds of millions of mobile devices, providing both forensic and predictive analytics.” The products the document is discussing are Tangles and Webloc.

Forbes previously reported that ICE spent more than $5 million on these products, including $2 million for Tangles specifically. Tangles and Webloc used to be run by an Israeli company called Cobwebs. Cobwebs joined Penlink in July 2023.

The new documents provide much more detail about the sort of location data ICE will now have access to, and why ICE chose to buy access to this vast dataset from Penlink specifically.

“Without an all-in-one tool that provides comprehensive web investigations capabilities and automated analysis of location-based data within specified geographic areas, intelligence teams face significant operational challenges,” the document reads. The agency said that the issue with other companies was that they required analysts to “manually collect and correlate data from fragmented sources,” which increased the chance of missing “connections between online behaviors and physical movements.”
A screenshot from the document.
ICE’s Homeland Security Investigations (HSI) conducted market research in May and June, according to the document. The document lists two other companies, Babel Street and Venntel, which also sell location data but which the agency decided not to partner with.

404 Media and a group of other media outlets previously obtained detailed demonstration videos of Babel Street in action. They showed it was possible for users to track phones visiting and leaving abortion clinics, places of worship, and other sensitive locations. Venntel, meanwhile, was for some years a popular choice among U.S. government agencies looking to monitor the location of mobile phones. Its clients have included ICE, CBP, and the FBI. Its contracts with U.S. law enforcement have dried up in more recent years, with ICE closing out its work with the company in August, according to procurement records reviewed by 404 Media.

Companies that obtain mobile phone location data generally do it in two different ways. The first is through software development kits (SDKs) embedded in ordinary smartphone apps, like games or weather forecasters. These SDKs continuously gather a user’s granular location, transfer that to the data broker, and then sell that data onward or repackage it and sell access to government agencies.

The second is through real-time bidding (RTB). When an advert is about to be served to a mobile phone user, there is a near instantaneous, and invisible, bidding process in which different companies vie to have their advert placed in front of certain demographics. A side-effect is that this demographic data, including mobile phones’ location, can be harvested by surveillance firms. Sometimes spy companies buy ad tech companies out right to insert themselves into this data supply chain. We previously found at least thousands of apps were hijacked to provide location data in this way.

Penlink did not respond to a request for comment on how it gathers or sources its location data.
playlist.megaphone.fm?p=TBIEA2…
Regardless, the documents say that “HSI INTEL requires Penlink's Tangles and Weblocas [sic] an integral part of their investigations mission.” Although HSI has historically been focused on criminal investigations, 90 percent of HSI have been diverted to carry out immigration enforcement, according to data published by the Cato Institute. Meaning it is unclear whether use of the data will be limited to criminal investigations or not.

After this article was published, DHS Assistant Secretary Tricia McLaughlin told 404 Media in a statement “DHS is not going to confirm or deny law enforcement capabilities or methods. The fact of the matter is the media is more concerned with peddling narratives to demonize ICE agents who are keeping Americans safe than they are with reporting on the criminals who have victimized our communities.” This is a boilerplate statement that DHS has repeatedly provided 404 Media when asked about public documents detailing the agency’s surveillance capabilities, and which inaccurately attacks the media.

In 2020, The Wall Street Journal first revealed that ICE and CBP were using commercially smartphone location data to investigate various crimes and for border enforcement. I then found CBP had a $400,000 contract with a location data broker and that the data it bought access to was “global.” I also found a Muslim prayer app was selling location data to a data broker whose clients included U.S. military contractors.

In October 2023, the Department of Homeland Security (DHS) Inspector General published a report that found ICE, CBP, and the Secret Service all broke the law when using location data harvested from phones. The oversight body found that those DHS components did not have sufficient policies and procedures in place to ensure that the location data was used appropriately. In one case, a CBP official used the technology to track the location of coworkers, the report said.

The report recommended that CBP stop its use of such data; CBP said at the time it did not intend to renew its contracts anyway. The Inspector General also recommended that ICE stop using such data until it obtained the necessary approvals. But ICE’s response in the report said it would continue to use the data. “CTD is an important mission contributor to the ICE investigative process as, in combination with other information and investigative methods, it can fill knowledge gaps and produce investigative leads that might otherwise remain hidden. Accordingly, continued use of CTD enables ICE HSI to successfully accomplish its law enforcement mission,” the response at the time said.

In January 2024, ICE said it had stopped the purchase of such “commercial telemetry data,” or CTD, which is how DHS refers to location data.

Update: this piece has been updated with a statement from DHS.


#News #x27


La UE sta per svuotare di significato il consenso sui cookies. L'analisichiarissima di @Matteo G.P. Flora

@Etica Digitale (Feddit)

Addio ai fastidiosi popup? Sì, ma il rischio è perdere davvero il controllo sui tuoi dati: il consenso diventa un click nascosto nelle impostazioni, e il tracciamento dei big del web vola. Secondo la Commissione Europea, questa mossa dovrebbe alleggerire del 25% il peso normativo, ma il consenso informato rischia di diventare solo una formalità.

Se passa, potresti non dover più cliccare niente… ma tutto quello che viene tracciato su di te finirà direttamente nei data center delle Big Tech, pronto per essere venduto e sfruttato senza il tuo reale permesso.

Vale davvero la pena scambiare meno fastidi per meno libertà digitale? Sei pro semplificazione o pro trasparenza?

youtu.be/tDRlipjE2W0

in reply to The Privacy Post

ricordo che i banner sono fastidiosi e scomodi perché sono stati progettati (da Big Tech, non dalla CE) per essere fastidiosi e scomodi.

Ciccio dell’Oca reshared this.



Riceviamo e pubblichiamo: Ministero della Salute Palestinese – Gaza
Rapporto statistico quotidiano sulle vittime e i feriti dell’aggressione israeliana alla Striscia di Gaza
Aggiornato al 30 settembre 2025
Ultime 24 ore:
• Sono arrivati agli ospedali della Striscia di Gaza 42 martiri e 190 feriti.
• Numerose vittime rimangono ancora sotto le macerie o per le strade, impossibili da raggiungere a causa dell’intensità dei bombardamenti e del collasso dei servizi di soccorso e protezione civile.

Bilancio complessivo dell’aggressione (dal 7 ottobre 2023):
• Totale martiri: 66.097
• Totale feriti: 168.536
Bilancio dal 18 marzo 2025 ad oggi:
• Martiri: 13.229
• Feriti: 56.495

Vittime tra coloro che cercavano aiuti umanitari (“martiri del pane”):
• Nelle ultime 24 ore, sono arrivati agli ospedali 5 martiri e 56 feriti mentre tentavano di accedere agli aiuti alimentari.
• Il bilancio totale sale a:
➤ 2.576 martiri
➤ Oltre 18.873 feriti

Morti per fame e malnutrizione:
Secondo i dati ufficiali del Ministero della Salute a Gaza:
• Il numero totale delle vittime causate dalla carestia e dalla malnutrizione ha raggiunto 453 martiri, tra cui 150 bambini.
• Dalla dichiarazione ufficiale di carestia da parte dell’IPC (Integrated Food Security Phase Classification), sono stati registrati:
➤ 175 decessi, tra cui 35 bambini, fino alla data odierna.

Appello urgente:
Il Ministero della Salute e le autorità palestinesi rinnovano l’appello alla comunità internazionale, alle organizzazioni umanitarie e ai media affinché:
• Si imponga un cessate il fuoco immediato e duraturo
• Si garantisca l’ingresso sicuro e incondizionato degli aiuti umanitari
• Si denunci pubblicamente l’uso della fame come arma di guerra, in flagrante violazione del diritto internazionale umanitario

Questo rapporto è pubblicato a fini di documentazione, trasparenza e per sollecitare un’azione urgente da parte della comunità internazionale.
Ministero della Salute Palestinese – Gaza
30 settembre 2025

Gazzetta del Cadavere reshared this.



The Secretary of War lectured America’s generals on fitness standards, beards, and warriors for an hour.#News #military


In Unhinged Speech, Pete Hegseth Says He's Tired of ‘Fat Troops,’ Says Military Needs to Go Full AI


Last week, Secretary of War Pete Hegseth called America’s Generals to Quantico to meet for an unknown reason. America’s top civilian military leader calling the generals home all at once is strange and unprecedented. It’s the kind of move that often presages something like a major war. But that’s not what he wanted. During a bizarre, unhinged speech before America’s military leadership, Hegseth focused almost entirely on the culture wars and called for the restoration of what he called a “warrior ethos.” He said some of America’s generals are fat, demanded the Pentagon go all in on AI, whined about beards and accountability, told the troops they “kill people and break things for a living,” and plugged his book.

“The speech today is about the nature of ourselves,” Hegseth said. For the next hour, before setting up President Trump for remarks, Hegseth spoke about a new American military that will shave its beards, reduce the number of women in combat, and focus on killing. “To our enemies: FAFO. If necessary, our troops can translate that for you. Peace through strength, brought to you by the warrior ethos.”(FAFO means fuck around and find out.)
playlist.megaphone.fm?p=TBIEA2…
An earlier theme of the speech was more and faster. “This urgent moment, of course, requires more troops, more munitions, more drones, more [Patriot missiles], more submarines, more B-21 bombers,” Hegseth said. “It requires more innovation, more AI in everything and ahead of the curve, more cyber effects, more counter [unmanned aerial systems], more space, more speed. America is the strongest, but we need to get stronger and quickly.”

The alarming speech took most of the attention of social media Tuesday morning and comes at a time where Donald Trump has deployed troops in American cities, has threatened to invade Portland, and told the military they should use American cities as a “training ground.” Hegseth himself has been said to be more or less having a meltdown, according to reporting by The Daily Mail.

The Pentagon has been all in on AI and drones for years now, but it hasn’t gone well. Last week, The Wall Street Journal reported that the Pentagon is struggling to deploy AI weapons and is worried about catching up to China. A Biden era initiative called Replicator was meant to help bridge the gap between dreams and reality, but hasn’t worked fast enough for its critics. So the Pentagon is turning the project over to Special Operations Command—the part of the Pentagon in charge of its operators—under a new division called Defense Autonomous Warfare Group (DAWG). This means that the military leaders who run SEAL Team Six will soon be in charge of getting AI controlled drone swarms to the troops.

Much of Hegseth’s speech was about aesthetics and fitness. For him, a return to the “warrior ethos” meant never seeing a fat general or admiral ever again. “Every member of the joint force at any rank is required to take a PT test twice a year as well as meet height and weight requirements twice a year, every year of service,” he said. “Also today, at my direction, every warrior across our joint force is required to do PT every duty day. Should be common sense…but we’re codifying it. And we’re not talking hot yoga and stretching. Real hard PT, either as a unit or an individual. At every level, from the Joint Chiefs to everyone in this room to the lowest private.”

“It all starts with physical fitness and appearance,” Hegseth said. “If the Secretary of War can do regular, hard PT, so can every member of our joint force. Frankly, it's tiring to look out at combat formations, or really any formation, and see fat troops. Likewise, it's completely unacceptable to see fat generals and admirals in the halls of the Pentagon and leading commands around the country in the world, it's a bad look. It is bad and it's not who we are.”

Hegseth’s aesthetic concerns extended to facial hair. “This also means grooming standards. No more beards. Long hair. Superficial individual expression. We’re going to cut our hair, shave our beards, and adhere to standards. It’s like the broken windows theory of policing. When you let the small stuff go, the big stuff eventually goes. So you have to address the small stuff,” he said.

There was, of course, a carve out for America’s operators. “ If you want a beard you can join Special Forces. If not, then shave. We don’t have a military full of Nordic Pagans. At my direction, the era of unprofessional appearance is over. No more beardos. The era of rampant and ridiculous shaving profiles is done.”

Beards may seem like small stuff in the grand scheme of things, but it’s a hot topic among military recruits. Over the past few years, military recruits have fought and won exemptions for grooming standards based on their religion, often in court. A federal court told the Marine Corps it couldn't force Sikh recruits to shave in 2022. There’s also medical issues. Men with pseudofolliculitis barbae, a condition that causes painful ingrown hairs and razor burn after shaving, have gotten long gotten waivers to exempt them from shaving in the military. Around 60 percent of black men have pseudofolliculitis barbae.

💡
Do you know anything else about this story? I would love to hear from you. Using a non-work device, you can message me securely on Signal at +1 347 762-9212 or send me an email at matthew@404media.co.

Hegseth made it clear that these new conditions mean there will be fewer women on the frontlines and in physically demanding roles. “I don’t want my son serving alongside troops who are out of shape or in combat units with females who can’t meet the same combat arm physical standards as men,” he said. “When it comes to any job that requires physical power to perform in combat, those physical standards must be high and gender neutral. If women can make it excellent,” he said. “If not, it is what it is. If that means no women qualify for some combat jobs. So be it, that is not the intent, but it could be the result.”

The Secretary also said he would end the tyranny of accountability in the military. “We are overhauling an Inspector General process, the IG that has been weaponized, putting complainers, ideologues and poor performers in the driver's seat,” he said. “We're doing the same with the Equal Opportunity and Military Equal Opportunity policies. The EO and MEO at our department. No more frivolous complaints, no more anonymous complaints, no more repeat complaints. No more smearing reputations. No more endless waiting. No more legal limbo. No more side-tracking careers, no more walking on eggshells.”

Pentagon acting Inspector General Steven Stebbins is currently investigating Hegseth over his use of an unsecured Signal clone to plan military operations.

A modern military is a technological and logistics machine. A warrior takes many shapes and, if Hegseth wants to go all in on cyber, drones, and AI, then harsh grooming standards and increased physical fitness requirements will cut off many of the brightest minds who could help him fulfill that goal.

That doesn’t seem to matter to Hegseth and Trump as much as aesthetics does. Towards the end of his speech, the Secretary said the Pentagon lost its way. Then he plugged his 2024 book The War on Warriors. “We became the woke department, but not anymore. No more identity months, DEI offices, dudes in dresses. No more climate change worship. No more division, distraction, or gender delusions. No more debris. As I’ve said before and will say again: we are done with that shit,” he said.

“You might say we’re ending the war on warriors. I hear someone wrote a book about that.”