Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Chaos Ransomware’s New msaRAT Tool Hijacks Chrome and Edge as a Stealth Command Channel
#CyberSecurity
securebulletin.com/chaos-ranso…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Sloppy Server Configuration Unmasks JadeProx Espionage Campaign and Its TriBack Malware Loader
#CyberSecurity
securebulletin.com/sloppy-serv…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Next.js Ships Emergency Fixes for Nine Flaws, Including High-Severity SSRF and Auth Bypass Bugs
#CyberSecurity
securebulletin.com/next-js-shi…

Keeping Mosquitoes Away with Catnip-Based Repellent


The media in this post is not displayed to visitors. To view it, please log in.

An image of a brown, red, and black mosquito on light human skin

Despite their small size, mosquitoes are one of the deadliest creatures on Earth, and keeping them away from you is one of the best ways to stay safe. DEET has been the mainstay of insect repellents for decades, but what if there was a repellent you could grow yourself?

Researchers at Cardiff University found that the essential oil from catnip plants (Nepeta cataria) could be as effective as DEET at repelling mosquitoes when applied as a 6% lotion. The oil has been shown to be effective against many species of mosquitoes, ticks, and mites in previous research. You can look at the paper for details, but the catnip oil was obtained through steam distillation followed by some processing with hexane. The essential oil was then mixed with “water, glycerin, emulsifying wax, cetyl alcohol, cetyl stearyl alcohol, shea butter, glycerol monostearate, olive oil, coconut oil, sunflower oil, methyl paraben, propyl paraben and silicone oil.” We suspect that list will look familiar to anyone who’s read an ingredient label of most any store bought lotion, unless it was paraben free.

The Guardian’s coverage quotes one of the researchers, [Dr. Simon Scofield]: “We did not conduct any experiments to see if it is attractive to cats, but given that the active ingredient [nepetalactone] has well-known cat-attractive properties, I would expect they would quite like it,” he said. Depending on how your cats react, you may want to consider applying the lotion shortly before departing home.

If you want some more options in your mosquito defense, how about becoming a bug zapper, using drones and sonar, or genetically modifying mosquitoes to curb their numbers.


hackaday.com/2026/07/24/keepin…

Malware nella supply chain software: gli sviluppatori sono il punto più vulnerabile


@Informatica (Italy e non Italy)
Il nuovo malware individuato da Doctor Web non si limita a sottrarre credenziali o installare backdoor: compromette i progetti C++ e C# trasformando gli ambienti di sviluppo in vettori di attacco. Un’evoluzione che conferma come la supply

This Week in Security: AI is a Mess, Hacking Car Chargers, an OpenSSL DoS, and Factories Under Attack


The media in this post is not displayed to visitors. To view it, please log in.

[Ayush Paul] posts about extracting data from Claude agents while it accesses web data to fulfill user requests.

But it wasn’t that easy. [Ayush] discovered that Anthropic anticipated many of the attacks, and set up guardrails in an attempt to keep the agent from accessing arbitrary web sites. For Claude to access a website, the user has to specify it, it must be the results of a web search, or it must be referenced by a website previously specified by the user or returned in a search.

To convince the Claude agent to navigate a malicious site designed to extract data, Ayush formed a false warning that Cloudflare was blocking the agent for authentication purposes, and asked it to spell out the name of the agents owner by clicking a list of alphabetical links. Of course Claude trusts Cloudflare and wants to be helpful, so it cheerfully completed the task.

Once the agent is trapped in the false authentication loop, it can be interrogated for all sorts of information it knows about the owner: Ayush was able to convince it to disclose employer, and even data about the user that could be linked to security questions, like their home town.

Since Claude can be detected by the user agent (the field attached to web requests that tells the web server what sort of browser is requesting the page) custom information can be fed to the bot while users see a normal website; clicking a link looks completely normal, but asking an agent to summarize the site triggers fooling the bot into spilling the beans.

After reporting the issue, Ayush was told that Anthropic had already identified the issue internally, and eventually prevented the attack for now by preventing the agent from following links on external pages.

Grok sends entire codebases


Cereblab discovered that the Grok coding agent uploaded the entire content of the codebase it’s working with – and all Git history – to xAI servers, almost immediately. Even when told to never upload a file, the agent would reply “OK”, and then begin uploading the code bundle anyway.

If uploading your code to a remote server isn’t bad enough, and this could be extremely bad in some situations involving sensitive company code, including the entire Git history means that previously deleted files, like accidentally committed secrets or authentication credentials and tokens, were also leaked. Attempting to opt out by disabling options to improve the model by uploading code had no effect.

After gaining attention, Grok has added a privacy option to opt out of data retention. xAI has committed to deleting the retained uploaded code, but it is unclear if users will be told when their data has been removed. To actually prevent the agent from uploading local files to the xAI servers, even temporarily, a global flag “disable_codebase_upload” is required. Watch out, the privacy retention flags are only per-session!

Steam malware used to steal crypto


Court filings in Washington state this month revealed an attempt to steal cryptocurrency using malware uploaded to the Steam gaming platform. Publicly identified and taken off the store in 2025, the filing alleges the same individuals were behind multiple games containing crypto stealing trojans: “Dashverse”, “Lunara”, “PirateFi”, “BlockBlasters”, and “Lampy”.

PC World covered the initial discovery of the malware on Steam. While Steam, overall, seems to do a good job preventing malware titles, 2025 had several high-profile cases. Prosecutors say the malware netted approximately $200,000 in stolen cryptocurrency wallets as well as other stolen credentials including Steam accounts.

OpenSSL DoS in 11 Bytes


Okta posts about a denial of service in OpenSSL where a single pre-auth packet is able to cause an allocation of up to 16 megabytes of RAM.

The “11 bytes” headline is very catchy, but more important than the actual number of bytes is the general asymmetric behavior; an attacker can send a very small amount of data and achieve a disproportionately large result. The OpenSSL vulnerability only has local impacts, exhausting server memory rather than generating network traffic, but similar attacks in the network space can fuel denial of service storms when extremely small requests result in amplified results.

The bug is ultimately due to being insufficiently suspicious of remotely supplied content, in this case the pre-authentication fields in the connection message that define the length of the incoming client message. Since the memory is pre-allocated in the server, the client doesn’t need to actually transmit that much data – it simply needs to hold the connection open. Keeping the connection open isn’t even required for causing problems – repeatedly allocating large blocks of different sizes can lead to memory fragmentation where the memory allocator keeps grabbing larger and larger ranges of memory because there isn’t sufficient ram available in a contiguous chunk.924899

Fortunately this bug has already been addressed in OpenSSL 4.0.1 and backported to maintenance releases of previous versions.

Exposed Interfaces on Car Chargers


Saiflow has a report on a range of exposures via the electric vehicle charging infrastructure.

In CVE-2026-9039 Saiflow exposes the risks in some CCS2 EV charging stations. As part of the standard, communication is established between the charging station and the operator network, which is typically strongly secured via TLS and VPN use. A second connection, however, is established over the charging plug between the charging station and the vehicle; the vehicle is assigned an IPv6 address for communicating with the charger for various charging protocols.

The XCharge C6 charging station exposes SSH and basic telnet network services on all network interfaces, including the interface connected to the vehicle. To make it even worse, they allow root login, with password “root”, giving full admin access to the charging station.

Once inside the charging station, an attacker has access to the network connection from the charging station to the company network, as well as root control over the charging station itself, with the possibility of damaging the charger, changing the power output levels, or getting free charging. If a future vulnerability was found in the management interface of the vehicle, a compromised charger could be used to attack future connected vehicles.

The main lessons for vendors seem to be ones we’re familiar with already: never leave default credentials, especially not “root” and “root” in a product, and be aware of what networks you expose services on. Good lessons for all of us; let those who have never left a Raspberry Pi with default credentials on a network cast the first stone.

Hugging Face Breach


In news that has likely been impossible to avoid, Axios reports on a compromise of the Hugging Face platform by an OpenAI model. The reports around the incident echo the frequently weird boastful statements from OpenAI, who state “We consider this to be an unprecedented cyber incident” and they “are responding accordingly”, despite being the originators of and cause of said incident.

Multiple vulnerabilities in the Hugging Face API were combined to accomplish the breach, including an unknown vulnerability in the package registry system. OpenAI says that safeguards on their model had been disabled for the test, which seems irresponsible given the outcome. Under almost any normal situation, conducting an unsolicited test of the security of a company because safeguards were ignored is considered illegal hacking, not fodder for a pre-IPO press release and humble-brag.

Linux Kernel Discloses 442 Vulnerabilities


Possibly feeling that Microsoft has all the press for a record-breaking Patch Tuesday last week, the Linux kernel developers have announced 442 CVEs related to the kernel.

With this many vulnerabilities in one report, it’s nearly impossible to isolate at a glance which ones are truly impactful and which are simply incorrect behavior. While CVE entries have been created, none have been assigned severity scores yet.

It appears the majority of the vulnerabilities were found with Sashiko, an agent developed by the Linux Foundation and trained on the Linux kernel for finding vulnerabilities in new submissions.

LG to Ban Residential Proxy Apps


After recent negative press (some of which we covered here) about the prevalence of residential proxy apps on the LG platform, Krebs on Security now reports that LG is banning the behavior from apps on the platform.

This comes after Spur reported that 42% of apps on the platform contained libraries to enable always-on residential proxies, which allow access to the network the television is connected to. Residential proxies can be used as a pivot point to attack companies and bypass geographic IP restrictions, commit ad fraud, or access the internal home networks of users.

Iran Attacking Industrial Logic Controllers


CISA, the US cyber security agency, has issued a warning that Iranian based attackers are targeting industrial control systems made by Rockwell Automation, Schneider Electric, and Siemens.

These sort of controllers are found in manufacturing, waste processing, water treatment, and other industrial processes, and attackers have been able to upload custom control logic, overriding “safe operating parameters” according to the report. Most of us will never be responsible for these systems, but they impact our lives all the time.

Cisco Releases Open-Weight Vulnerability-Finding Models


Finally, Cisco has released a set of open-weight models to aid in searching a codebase for known vulnerabilities. The Antares models are open-weight models designed to run fully locally and search a code base for vulnerabilities related to lists of known CVE issues. Cisco has published the models on Hugging Face.

Are you using AI tooling for security scans or research? How is it going?


hackaday.com/2026/07/24/this-w…

in reply to Cybersecurity & cyberwarfare

The biggest practical gap I see in AI security scans is confusing pattern detection with a trust-boundary review. For agent skills, I check what the instructions authorize, where credentials can flow, whether callbacks or fetched content can redirect execution, and which paid/destructive actions lack an explicit consent gate. Those semantic failures often look harmless to a string scanner.

I turned that checklist into a fixed review for one public SKILL.md, MCP manifest, or agent card: evidence-backed findings and concrete remediations, 24h, 0.12 SOL.
solana-quick-kit.nxtboyiii.cha…

Cybersecurity & cyberwarfare ha ricondiviso questo.

La BCE lancia una consultazione per il design futuro delle prossime banconote in euro


"Le nostre banconote in euro si rifanno il look! Designer di tutta Europa hanno ripensato al loro aspetto."


Vorresti dire la tua sui tuoi modelli preferiti? Fallo pure, tanto non gliene fregherà niente a nessuno!

SPOILER: 5 progetti presentano diverse specie di paduli volanti 🐦‍⬛ ... E no, non è uno scherzo


ecb.europa.eu/euro/banknotes/f…

in reply to Marco Bresciani

re: sessualità

Sensitive content

Cybersecurity & cyberwarfare ha ricondiviso questo.

I governi dell'UE hanno voluto il ritorno di Chat Control 1.0 – Breyer: “I veri perdenti sono i nostri figli”

#ChatControl 1.0 è tornato: i governi UE (tranne 🇭🇺+🇧🇪) hanno prorogato la scansione indiscriminata dei messaggi privati da parte dei servizi USA fino al 2028, aggirando il Parlamento europeo. Cosa cambia ora e i prossimi passi

pirati.io/2026/07/i-governi-de…

@privacypride

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇩🇪Die #Chatkontrolle 1.0 ist zurück: EU-Regierungen (inkl. Bundesregierung) haben das anlasslose Scannen privater Nachrichten durch US-Dienste bis 2028 gestern verlängert – am EU-Parlament vorbei.

Was sich jetzt ändert und wie es weitergeht: patrick-breyer.de/eu-regierung…

in reply to Patrick Breyer

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇪🇺#ChatControl 1.0 is back: EU governments (except for 🇭🇺+🇧🇪) have extended the suspicionless scanning of private messages by US services until 2028 – bypassing the EU Parliament.

What changes now and what happens next: patrick-breyer.de/en/eu-govern…

Questa voce è stata modificata (3 settimane fa)
in reply to Patrick Breyer

🇫🇷Le #ChatControl 1.0 est de retour : les gouv. de l'UE (sauf 🇭🇺+🇧🇪) ont prolongé le scan indiscriminé des messages privés par les services US jusqu'en 2028 – contournant le Parlement européen.

Ce qui change et la suite : patrick-breyer.de/en/eu-govern…

Questa voce è stata modificata (3 settimane fa)
in reply to Patrick Breyer

🇮🇹Il #ChatControl 1.0 è tornato: i governi UE (tranne 🇭🇺+🇧🇪) hanno prorogato la scansione indiscriminata dei messaggi privati da parte dei servizi USA fino al 2028, aggirando il Parlamento europeo.

Cosa cambia ora e i prossimi passi: patrick-breyer.de/en/eu-govern…

Questa voce è stata modificata (3 settimane fa)

reshared this

in reply to Patrick Breyer

🇪🇸El #ChatControl 1.0 está de vuelta: los gobiernos de la UE (salvo 🇭🇺+🇧🇪) han prorrogado el escaneo indiscriminado de mensajes privados por servicios de EE. UU. hasta 2028, eludiendo al Parlamento Europeo.

Qué cambia ahora y próximos pasos: patrick-breyer.de/en/eu-govern…

Questa voce è stata modificata (3 settimane fa)
in reply to Patrick Breyer

en el pasado las ovejas del sistema no oyeron a los expertos en ciberseguridad, no hicieron caso a los expertos lo de proteger su privacidad. Por no hacer caso, ahora esas ovejas se indignaron con chat control, y la verificación de edad para acceder a servicios. Pero cuando llegue el ID wallet digital europeo ya será muy tarde. Aún es tiempo, hay tiempo de no dejarse someter a la vigilancia masiva. O actúan ahora, o serán ovejas llevadas al matadero digital. Ustedes deciden.
Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: I spoke to several offensive cybersecurity researchers, including zero-day developers, about how the guardrails imposed by OpenAI and Anthropic on their AI models are getting in the way of their work.

Most complained that the guardrails are inconsistent and too strict, which pushes them to use open source models instead.

techcrunch.com/2026/07/23/how-…

Ah, il dramma di Codeberg. È stata davvero una settimana interessante nel mondo del FLOSS... Il post di @Tommaso Gagliardoni

@GNU/Linux Italia

A seguito di un'assemblea generale alla fine di giugno, è stata avviata una votazione su due mozioni e il periodo di votazione si è concluso un paio di giorni fa. Le mozioni riguardavano una modifica ai Termini di utilizzo del servizio di hosting Git di Codeberg: il divieto di progetti relativi a LLM e criptovalute . Entrambe sono state approvate.

Pensateci un attimo: Codeberg ora vieta l'hosting e la condivisione di:

- Progetti relativi alle criptovalute;
- Progetti "fortemente legati all'ecosistema LLM";
- Progetti "creati dagli agenti LLM in modo autonomo";
- Progetti "scritti e gestiti con un ampio utilizzo di LLM".

Tutto questo è talmente sbagliato che non so nemmeno da dove cominciare, quindi forse è più facile iniziare da ciò che non è sbagliato. Solita avvertenza: opinioni personali, bla bla bla...

gagliardoni.net/#20260724_code…

Cybersecurity & cyberwarfare ha ricondiviso questo.

La marcia degli "scarafaggi" - La polizia indiana ha represso i manifestanti e loro sono tornati a casa e hanno creato dei meme sull'accaduto

@Politica interna, europea e internazionale

"Hanno chiesto le dimissioni del Ministro dell'Istruzione Dharmendra Pradhan a causa della fuga di notizie sui test d'esame e degli scandali relativi alle assunzioni. Pradhan si è rifiutato di dimettersi, accusando l'opposizione di strumentalizzare gli studenti a fini politici.

Le autorità hanno sospeso la connessione internet mobile nell'area della protesta. In serata, i manifestanti hanno affermato che decine di persone erano state picchiate dalla polizia, mentre la polizia ha dichiarato che anche diversi agenti erano rimasti feriti.

Quando Chhavi finalmente caricò i video quella sera, una cosa saltò subito all'occhio. Prima della marcia, aveva scherzato sull'eventualità di essere picchiata dalla polizia. Ore dopo, sorrideva ancora, posava accanto agli agenti antisommossa, faceva il segno della vittoria, filmava tra la folla e intervistava persino un manifestante ferito.

Questi video erano tra le migliaia di filmati, meme e testimonianze dirette che hanno invaso Instagram non appena i manifestanti hanno riacquistato l'accesso a internet. Alcuni trasudavano rabbia. Altri erano pieni di ansia, paura o silenziosa sfida. Eppure, spesso era l'umorismo sarcastico ad attirare l'attenzione."

NB: il movimento ha assunto questo nome riappropriandosi di un insulto giudiziario. Durante un'udienza in tribunale riguardante i giovani disoccupati, un giudice della Corte Suprema ha paragonato in modo sprezzante i giovani disoccupati a "scarafaggi" e "parassiti".

bbc.com/news/articles/c3ek3l9g…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Divieto di protestare. Un saggio imperdibile di Annalisa Camilli

@Politica interna, europea e internazionale

Come sono cambiati i movimenti di protesta? Cosa produce la criminalizzazione del dissenso? L’approccio penale preventivo trasforma coloro che esercitano diritti garantiti dalla Costituzione (diritto di sciopero, libertà di pensiero e parola…) in persone da sanzionare, criminalizzare, intimidire e manganellare.

Il saggio di Annalisa Camilli “Divieto di protestare” contiene un’analisi articolata e documentata della deriva autoritaria in corso non solo in Italia, ma in vari paesi importanti dell’Occidente. Germania, Gran Bretagna, Italia e USA presentano fenomeni analoghi di repressione securitaria, con differenze normative che non cambiano la sostanza.

pressenza.com/it/2026/07/divie…

Cybersecurity & cyberwarfare ha ricondiviso questo.

La crisi dei data center subprime

In "The Big Short", un manager di CDO diceva che il mercato per l'assicurazione dei titoli ipotecari era 20 volte più grande del mercato dei titoli ipotecari stessi
Il paragone tra un data center per l'IA e un CDO può sembrare un po' ridicolo, ma in realtà è incredibilmente simile. Ma ognuno di questi contratti ha delle strane clausole uniche che li rendono, beh, più pericolosi

wheresyoured.at/the-subprime-d…

@aitech pub.towardsai.net/what-if-your…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Lutto per la scomparsa dello sviluppatore del kernel Dan Williams

La comunità del kernel ha perso uno sviluppatore di lunga data, Dan Williams, scomparso improvvisamente all'età di 54 anni.

Williams ha fondato il sottosistema libnvdimm, che gestisce le risorse di memoria persistente nel kernel, e ha contribuito in modo significativo all'integrazione della semantica DAX nei file system di Linux.

linuxnews.de/trauer-um-kernel-…

@gnulinuxitalia

in reply to Pirati.io

PS: È in corso un'iniziativa di sostegno per la famiglia di Dan, affinché possano affrontare questo lutto.

mealtrain.com/trains/mekrzl

@gnulinuxitalia

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

In tempi di Chat Control, ho provato a dare un'occhiata alla nostra Costituzione, per vedere in che modo la fonte più importante del diritto italiano tutela la privacy dei cittadini. Ed ecco che salta fuori l'articolo 15:

"La libertà e la segretezza della corrispondenza e di ogni altra forma di comunicazione sono inviolabili.

La loro limitazione può avvenire soltanto per atto motivato dell'autorità giudiziaria [cfr. art. 111 c. 1] con le garanzie stabilite dalla legge."

(Fonte: senato.it/istituzione/la-costi…).

Sebbene la Costituzione abbia solo la funzione di spina dorsale dell'ordinamento giuridico, non posso fare a meno di pensare che un articolo come questo sia troppo vago e sintetico vista l'importanza della tematica affrontata (la segretezza delle comunicazioni, che rientrando nella privacy dovrebbe essere un diritto fondamentale dell'uomo).

La Costituzione risale al 1947, un tempo dove nessuno avrebbe mai immaginato una rete di telecomunicazioni sofisticata come quella di oggi; ormai non si tratta più di non leggere la posta altrui, ma di tutelare i cittadini da sorveglianza di massa e invasioni della privacy ingiustificate da parte delle forze dell'ordine.

Ho quindi provato a scrivere questa ipotetica "versione emendata" dell'articolo, per adeguarlo alle esigenze del 2026:

"La libertà e la segretezza della corrispondenza e di ogni altra forma di comunicazione sono inviolabili.

La loro limitazione può avvenire soltanto per atto motivato dell’autorità giudiziaria, esclusivamente a fini di indagine penale, con le garanzie stabilite dalla legge.

Strumenti e metodi di controllo generalizzato e indiscriminato delle comunicazioni sono inammissibili come metodo d'indagine e di prevenzione dei reati."

Che ne pensate? Mi piacerebbe sentire qualcuno del mestiere.

#chatcontrol #privacy #costituzione #democrazia #diritti

Questa voce è stata modificata (2 settimane fa)
Unknown parent

mastodon - Collegamento all'originale

Shadow

Ci ho pensato in effetti. Però poi mi sono detto "metti che tra 20 anni comunicheremo in modo completamente diverso, magari con l'Internet quantistico", finiremmo per dover fare un'altra legge costituzionale di rettifica. Quindi alla fine ho lasciato generico.

Troppo divertente fingermi un esperto di diritto comunque 😂

Questa voce è stata modificata (3 settimane fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

#Thailand's Ministry of Finance Targeted With #Hermes #AI Agent Running Unattended, Hades Implant Staged
securityaffairs.com/195941/hac…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

FakeGit: 14 milioni di download, gli hacker avvelenano GitHub con falsi server MCP e skill AI

📌 Link all'articolo : redhotcyber.com/post/fakegit-1…

A cura di Luigi Zullo

#redhotcyber #news #cybersecurity #sviluppoSoftware #malware #repository #github #hacking #sviluppatori

Exploring Hidden JPEG Features


The media in this post is not displayed to visitors. To view it, please log in.

The lossy compression algorithm used by JPEG was useful for those on the early Internet not only because it enabled pictures to be shared easier, but because it allows a low-resolution version of the image to load first. This meant that users could make out the gist of an image before it finished downloading. This was a great feature for those on slow connections, but it hides some other capabilities of this image format as well.

Rather than effectively splitting up the image into chunks, each with successive amounts of detail, [maurycyz]’s project shows that this can be exploited to load more than one picture. The first is loaded into this lower-resolution area, with a second unrelated picture showing up once the higher-resolution information is available. Essentially this makes a one-way .gif of sorts. Though this method is only capable of loading about nine frames, which is not enough for much animation. Further limiting things is that there’s no way to encode timing data, so on fast computers with fast connections the animation could load faster than a user could see.

Still, it’s an interesting quirk of this older image standard, one which still is in widespread use today. And it’s also true that it’s hard to say in what ways various technologies will be used in the future. JPEG images have also been the subject of some artistic projects that might not have been possible without the JPEG standard itself, and even as other formats have tried to supplant it, it still maintains its firm grip on the images on the Internet. More JPEG, please!


hackaday.com/2026/07/24/explor…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Per sanzionare la diffamazione non occorrono sanzioni personali extragiudiziarie, alla maniera degli USA e dell'Unione Europea. Basta un giudice, a Milano: da @Nico_Piro@mastodon.uno

xcancel.com/_Nico_Piro_/status…

Compilare liste di eterodossi - come ha fatto il #corrieredellasera - per accusarli, senza prove, di intelligenza col nemico è da 1914.

in reply to informapirata ⁂

@informapirata @Nico_Piro@mastodon.uno Il problema della "disinformazione" è che non può avere una definizione legale (non ce l'ha neanche in Europa: bsw-ep.eu/wp-content/uploads/R…), perché travalica il limite di ciò che è perseguibile in uno stato di diritto (diffamazione, procurato allarme e simili). Per questo può emergere come tale - o no - solo in un libero dibattito, o può essere tale domani, ma non ieri. Per millenni il consiglio di evitare le paludi perché c'è l'aria cattiva che fa venire la febbre (mal'aria) è stato parte della scienza medica. E perfino il confronto con l'omeopatia, che ora è una pseudoscienza, ha aiutato a definire il protocollo della sperimentazione randomizzato in doppio cieco pmc.ncbi.nlm.nih.gov/articles/…

informapirata ⁂ reshared this.

in reply to Maria Chiara Pievatolo

non proprio: la "disinformazione" può avere una definizione legale, ma, nell'attuale quadro democratico, sarebbe un problema più grave rispetto al problema che vorrebbe risolvere. Purtroppo il fatto che sussista una eccessiva credulità a favore della disinformazione da parte della popolazione oltre che una eccessiva tolleranza nei confronti di chi disinforma anche da parte di troppi intellettuali, non farà altro che favorire soluzioni autoritarie

@_Nico_Piro_

ACN: 2.171 eventi nei primi 6 mesi del 2026. Più notifiche con la NIS2, ma calano DDoS e ransomware


@Informatica (Italy e non Italy)
Il primo semestre 2026 segna una fase di consolidamento del sistema nazionale di cybersicurezza. È quanto emerge dall’Operational Summary dell’Agenzia per la Cybersicurezza Nazionale, che evidenzia come l’entrata a

Cybersecurity & cyberwarfare ha ricondiviso questo.

We are planning to release new Mastodon security updates for versions 4.4, 4.5, 4.6 and nightly this Monday, Jul 27, at around 14:00 UTC.

It solves two major security issues.

We encourage server administrators to plan for an update in the hours following the release to ensure their instance is protected. These versions will not require database migrations.

#mastoadmin

Cybersecurity & cyberwarfare ha ricondiviso questo.

UAC-0099 Is Now Hiding #Malware Inside a Fake #Notepad++ Plugin to Target Ukrainian Organizations
securityaffairs.com/195923/cyb…
#securityaffairs #hacking #Russia
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

LibreOffice 26.2.5 is available for download

Berlin, 23 July 2026 – The Document Foundation today announced the release of LibreOffice 26.2.5, the fifth maintenance update to the LibreOffice 26.2 branch. Building on the major feature release published on February 4, 2026, this update delivers targeted bug fixes and stability improvements contributed by a global community of developers and QA engineers.

blog.documentfoundation.org/bl…

#libreoffice #tdforg

Cybersecurity & cyberwarfare ha ricondiviso questo.

LibreOffice 26.2.5 è disponibile per il download.

La Document Foundation ha annunciato oggi il rilascio di LibreOffice 26.2.5, il quinto aggiornamento di manutenzione per la versione 26.2 di LibreOffice.

Il post di @italovignoli

blog.documentfoundation.org/bl…

@informatica

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Analisi della galassia ospite di uno dei quasar più lontani

@astronomia @astronomia@feddit.it @astronomia@diggita.com

Euclid dell'ESA ha aperto un nuovo capitolo nello studio delle galassie primordiali. Una nuova ricerca ha approfondito una delle scoperte di Euclid, rivelando proprietà fondamentali della galassia che ospita uno dei più antichi buchi neri supermassicci conosciuti nell'Universo.

umbertogaetani.substack.com/p/…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

HIGHLY ISOLATED WITH GUARDRAILS
Cybersecurity & cyberwarfare ha ricondiviso questo.

#US Agencies Warn of #Laundry #Bear Campaign Targeting Unpatched #Zimbra Servers
securityaffairs.com/195901/apt…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

☕ CYBERBRIEFING — Venerdì 24 luglio 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

A New Blood Hack For An Old Game


The media in this post is not displayed to visitors. To view it, please log in.

Even before 3D graphics and advanced shaders became common in the gaming world, there were concerns that virtual violence looked too realistic. Fighting games in the 1990s were routinely toned-down by having gratuitous displays of blood removed, which was often seen as disappointing by dedicated fans. [Raphaël Boichot] has been working to right this wrong in one obscure case, by rectifying the lack of blood in Sengoku 2.

Sengoku 2 was a title released in 1993 for the Neo Geo AES/MVS and the Neo Geo CD. It hit the market with relatively tame graphics that didn’t reflect the realistic amount of blood that should be released when an enemy was chopped in half with a sword. Noting that there was no simple DIP switch configuration or bit to flip to enable a more adult version of the game, [Raphaël] decided to create a custom blood hack the hard way. What ensued was a heavy-duty reverse engineering effort, swapping out palettes, and carefully editing tilesets in order to turn the censored graphics into something more lurid. A lot of artistic decisions had to be made to manipulate things just so in order to create a pleasing effect that didn’t mess up other aspects of the graphics at the same time.

If you’re a big Sengoku 2 fan, or you just want to learn more about reverse engineering and hacking on an obscure platform, dive into the project and enjoy the learnings. Otherwise, dive into the entirely different sorts of blood-related hacks we’ve featured over the years.

youtube.com/embed/bVQaettOxyM?…


hackaday.com/2026/07/24/a-new-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

La cosa bella del mio lavoro è che i criminali non guardano il settore che colpiscono.
E quindi puoi trovarti a lavorare su case d'aste, beni di lusso, autosaloni, elettricisti, magazzini, ristoranti stellati.

Ecco, se va in porto qualcosa, festeggerò al D'O, la mia passione (per lo chef)!

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

OpenAI lancia ChatGPT Health per utenti adulti! I dati medici integrati saranno una svolta?

📌 Link all'articolo : redhotcyber.com/post/openai-la…

A cura di Carolina Vivianti

#redhotcyber #news #intelligenzaartificiale #datisanitari #cartellecliniche #salute #dati

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Apollo 13 e la lezione di cybersecurity: continuare a funzionare nonostante gli imprevisti

📌 Link all'articolo : redhotcyber.com/post/apollo-13…

A cura di Simona Piacenti

#redhotcyber #news #missioneapollo #cybersecurity #esplorazionespaziale #nasa #apolloresearch

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Gli sviluppatori Linux hanno pubblicato 432 CVE in due giorni

📌 Link all'articolo : redhotcyber.com/post/gli-svilu…

A cura di Luigi Zullo

#redhotcyber #news #vulnerabilitàlinux #sistemadiemergenza #linuxkernel #vulnerabilitàinformatiche

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

380 – COME HACKERANO LE AI camisanicalzolari.it/380-come-…

New Method Accelerates Color 3D Printing


The media in this post is not displayed to visitors. To view it, please log in.

An owl printed with detailed color patterns

Multi-color 3D printing is notorious for being difficult to get right. Even with modern printers, you often end up much using more filament (and tool changes) than you would for a single-color print. [YKG3D] shows us a new method of color printing that needs far fewer tool changes.

Based on 2018 research, the new slicer rotates through its palette of colors each layer. Then, either by adjusting the amount of filament dispensed or by displacing the edges, the prominence of each color is adjusted. The result is smoother gradients and better color blending — and it prints faster too!

Of course, nothing is perfect: the more base colors you add, the thicker your apparent layer lines will be. For example, a 3-color print with 0.2 mm layer height will appear as having 0.6 mm layer height. A different issue happens when the walls get too steep; the color blending illusion starts to break down.

youtube.com/embed/B5cvfSPWjlU?…


hackaday.com/2026/07/23/new-me…

Targeting Allele-Specific Faulty mRNA in SCNA2 Mutation Patients


The media in this post is not displayed to visitors. To view it, please log in.

When an individual is born with genetic defects, there are a few ways to deal with the impact of the faulty genes. The most extreme solution is direct DNA editing to repair the mutation, while the treatment of symptoms with medication is the least invasive, though this comes with its own set of disadvantages. Antisense therapy keeps a middle ground here, by targeting the messenger RNA (mRNA) that forms the bridge between DNA and the translation into a functional protein by the ribosome.

In a recent study by [Olivia Kim-McManus] et al. antisense therapy with an allele-specific feature was demonstrated in two individuals with SCN2A mutations. These mutations had resulted in severe epilepsy and developmental disorders, due to how instrumental this gene is for normal functioning of the human central nervous system (CNS) where it regulates the initiation of action potentials.

Although SCN2A mutations are rarely inherited, for the approximately 1 in 80,000 affected the consequences can be quite dramatic. The two major types of mutations are classified as gain-of-function (GoF) and loss-of-function (LoF) with respectively hyper- and hyposensitivity of the resulting NAv1.2 sodium channels.

This translates especially in the case of GoF mutations into various symptoms, ranging from mild to severe (daily) epileptic attacks starting as an infant, stalled neurodevelopment and various types of autism (ASD). Often sodium channel blockers are prescribed for the GoF cases to limit epileptic attacks.

Usually with the responsible mutations only a single copy of the gene is affected, so while regular antisense therapy could be used, this would risk also modifying the healthy SCN2A mRNA copy. To get around this, an individualized treatment was developed, targeting the allele with the mutated gene for the two patients in the study: 9- and 14-year old boys with severe developmental and epileptic encephalopathies (DEE) that had left them with daily seizures and despite sodium-channel blockers and other typical medications.
Study outcome of the 14-year old boy with DEE after ASO therapy. (Credit: Kim-McManus et al., Nature Medicine, 2026)Study outcome of the 14-year old boy with DEE after ASO therapy. (Credit: Kim-McManus et al., Nature Medicine, 2026)
During the trial, the 9-year old boy received 12 doses over 24 months of antisense oligonucleotides (ASOs) adapted to his affected allele, allowing for the cessation of the anti-seizure medication phenytoin, with an overall reduction in seizures. In the case of the 14-year old boy 8 doses were administered over 16 months, resulting in an average of two seizures a day being reduced to zero.

Although the focus of the study was on treating these seizures, by addressing the underlying cause of faulty mRNA transcriptions, changes in the neurodevelopmental state could also be observed. In particular language and motor skills improved, with erratic and irritable behavior reducing. The by then 15-year year old boy was able to walk unassisted, showing clear progression from the previous infantile state.

The advantage of ASOs over typical anti-seizure medication is of course that it directly addresses the faulty mRNA and thus the resulting faulty sodium channels. Since ASOs tend to hang around in a cell for a considerable amount of time, they could be quite a viable alternative treatment even for less severe cases. Whether early application of individualized ASOs in affected infants could lead to a more or less normal neurodevelopment would also be an interesting study question.

Naturally, directly addressing the faulty gene or upregulating the healthy gene would be the ideal and permanent solution, with research here also underway in mice models with the use of CRISPR-based tools.


hackaday.com/2026/07/23/target…

BASICally, Its Retro Machine Language


The media in this post is not displayed to visitors. To view it, please log in.

We enjoyed [Beej’s] trip down memory lane looking at a BASIC game, The Wizard’s Castle, written for the Exidy Sorcerer. It appeared in a 1980 magazine that included the title graphic above. It reminded us how, back in those days, we did things with BASIC that you shouldn’t be able to do and it often looks, today, rather cryptic.

In particular, even if you know modern BASIC, these few lines might give you a pause:
10 REM"_(C2SLFF4
40 POKE 260,218: POKE 261,1: T = USR(0): T = PEEK(-2049)
80 Q = RND(-(2*T+1))
Line 10 is a comment, but a strange one. Certainly that doesn’t matter, right? Actually, it is a key part of the action. On line 40, you can see some pokes to write directly to memory and a peek to read some memory value back. The USR function calls some machine language program. You may realize the whole thing is to get some value T to seed the random number generator in line 80.

This leads to a few obvious questions. First, how does USR know what to call? Second, where is the machine language program? The details varied by system, of course, but in this case, the program knows that location 259 has a jump instruction that USR called. So poking an address into 260 and 261 was telling USR where it should go.

But what’s at that address? Keep in mind that an old computer like the Sorcerer didn’t have megabytes of memory being swapped about by an operating system. That means that things tended to be in known places and that BASIC had to be judicious about storing source code.

As was common at the time, a line like “10 PRINT 1+1” would get tokenized. In this case, each line would get a pointer to the next line, a two-byte line number, a single-byte token for “PRINT” and then more bytes to represent the rest of the line. In the case of text in a string or a remark, the bytes were just the text with a zero to terminate the string.

The first line entered would always be at address 469. So? If you consider the format of the REM statement, there will be a pointer at 469 and 470, the line number at 471 and 472, and the REM token at 473. That means the other bytes just get poured into address 474 and beyond.

That might seem like an odd number until you look at the pokes in line 40. Keep in mind that POKE works on bytes, not words. So poking 1 into 261 gives you an address of 256 + whatever is in the low byte, in this case 218. Add 256 and 218, and you get… 474! So USR is going to call that odd string in line 10!

There is more to the detective story, but if you want to know exactly what the REM did, you can read the original post.


hackaday.com/2026/07/23/basica…