Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Comunicazione di servizio: nelle prossime 24 ore potrebbero esserci dei disservizi sul portale Fedinews

#Fedinews, la pagina con le notizie pubblicate nel #fediverso italiano potrebbe risultare irraggiungibile nelle prossime 24 ore. Ci scusiamo per il disagio

fedinews.it/

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug
securityaffairs.com/195454/sec…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

si parla spesso di IA e tutti a prenderla come un oracolo. Fate una semplice prova e poi decidete quanto fidarvi. Ad esempio (questo è stato una mia prova ma voi potete ovviamente inventarvi qualcos'altro)fatevi fare una guida su come creare un nas con un pc con 3 dischi di cui uno per il sistema e gli altri per dati. una volta che ha finito chiedete di controllare la guida per risolvere eventuali errori (e l ia la corregge) poi richiedete se è sicura che non ci siano ulteriori errori ( e lei corregge) poi passate il risultato ad un altra ia e chiedete di generare un altra guida partendo dall
ultimo risultato e fate correggere e fatevi generare una guida corretta. poi prendete una terza ia e fate confrontare le guide e generare la guida corretta definitiva. quando siete stufi di gironzolare tra le varie ia guardate quanto tempo avete buttato via e notate che ogni volta la guida scritta era presentata come corretta ed ogni volta usciva qualche errore. è possibile che con modelli a pagamento i risultati siano decisamente migliori ma1) non li ho mai provati 2) come si suol dire se il buongiorno si vede dal mattino .....
in reply to ugone

Scenario: unmarell che ha iniziato nel 1975 alla Breda a inserire nel VT-100 ("mica quelle cose tutte colorate!") il peso dei camion in entrata e uscita, sostituito con sistema automatico che "legge" la targa e riporta il peso dalla bilancia alla rete aziendale.

Può il nuovo sistema essere definito "intelligente"?

Certo, perché non rompe i coglioni dicendo "voi capelloni ciavete voglia di fare un casso, noi invece lavoravamo duro!".

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

372 – ARRIVA IL ROBOT CHE PROMETTE DI AMARCI PER SEMPRE camisanicalzolari.it/372-arriv…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Nasce RHC4Edu: Cybersecurity e intelligenza artificiale! Per tutte le scuole, da Settembre

📌 Link all'articolo : redhotcyber.com/post/parte-rhc…

A cura di Silvia Felici

#redhotcyber #news #trasformazionedigitale #cybersecurity #intelligenzaartificiale #mondodigitale

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

10.000 server SharePoint vulnerabili esposti su internet. Il CISA avverte da Internet

📌 Link all'articolo : redhotcyber.com/post/10-000-se…

A cura di Luigi Zullo

#redhotcyber #news #cybersecurity #hacking #malware #ransomware #sharepoint #cisa #vulnerabilità

Chromatography as Art


The media in this post is not displayed to visitors. To view it, please log in.

You may or may not remember in some ancient chemistry class studying or even performing chromatography. The short definition is using media like paper or powder to separate a mixture. It is an old technique, but [Suchir2004] is using it as an art form.

Chromatography works because the parts of the liquid mixture travel through the media at different speeds. While experimenting, [Suchir2004] noted that black ink and water perfused into constituent pigments. A butterfly ensued.

Is it art? Yes! Is it science? Well, sort of. Especially since the post does talk about how the effect works and even does some simple tests to start. This would be an excellent project for a class where some students are more motivated by art and others by science. Even with an individual kid, it might show you where their interests lie.

There’s nothing particularly difficult. A sketch pen, some paper, a coffee filter, a glue stick, and a few other household items are all you really need to get started.

Want something more practical? How about measuring caffeine content?


hackaday.com/2026/07/15/chroma…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

GigaWiper: Nuova backdoor Windows che cancella i tuoi dati in modo permanente

📌 Link all'articolo : redhotcyber.com/post/gigawiper…

A cura di Luigi Zullo

#redhotcyber #news #microsoft #gigawiper #backdoorwindows #malware #spionaggioinformatico

reshared this

Pinch Puts an Arduino On a USB-C Connector


The media in this post is not displayed to visitors. To view it, please log in.

Compared to the Arduino Uno of old, modern microcontrollers are absolutely tiny — especially for the amount of processing power and I/O you get. But if you need something really small, like fits-on-the-tip-of-your-finger small, most of the turn-key development boards on the market are still a bit too big.

Enter the pinch from moddo, which they advertise as “The World’s Smallest 32-Bit Arduino-
Compatible Board.” We can’t vouch for its world-record status, but we certainly can’t think of a smaller one. At least not a complete solution like this, which offers native USB and 15 GPIO pins in addition to the usual suspects like SPI, I2C, PWM, and UART. In fact, it’s so small that it even includes a breakout board to make prototyping a bit easier.

Coming from something like an ESP32, the biggest adjustment will probably be working around the relatively limited specs of the SAMD11. The ARM Cortex-M0+ under the hood tops out at 48 MHz, and there’s only 4 KB SRAM and 16 KB flash (of which the bootloader eats up 4 KB). Still, not bad for something that occupies roughly the same surface area as a female USB-C connector.

We’re told the team is in the final stages of testing and production of the pinch, and you can currently pre-order the $16 board ahead of its planned September ship date. A circuit schematic and STEP 3D model are already available, and it looks like board design files aren’t far behind.


hackaday.com/2026/07/15/pinch-…

DOOM runs (slowly) in a IBM PC-Compatible CSS Sheet


The media in this post is not displayed to visitors. To view it, please log in.

Just when you thought we’d run out of things to port DOOM to, here comes [Ahmed Amer] with his CSS-DOS, a massive 300 MB CSS style sheet, that runs not just DOS, but Windows 1.0 and, of course, DOOM. The CSS sheet isn’t holding a DOOM port this time, though — it’s holding a full IBM PC compatible, with a simulated 8086, 640 kB of RAM, floppy and VGA controllers. Yes, in one style sheet. We did mention it was 300 MB, right?

CSS is not a very good programming language. It’s got functions and if statements nowadays, but it doesn’t really do programs in the usual sense. That is, lists of instructions that feed one into another. You can’t change a variable without jumping through hoops. The sort of static behavior you get from a CSS sheet actually matches hardware architecture better than software, which was the key insight [Ahmed] had to make the project possible. It’s still not easy, or elegant, or perhaps even sane, as you can find out from the excellent write-up he has describing how he pulled this off. We particularly like the interactive guide to the full mountain of madness that is the .css file.

Now, we admit that “runs DOOM” may be an exaggeration — even if the maddeningly massive CSS sheet ran an IBM-AT full speed, that hardware can’t handle the game at any playable speed. It doesn’t emulate at anything close to full speed, though. Because this is such a gratuitously weird hack, it only runs at two instructions per second. No, not FPS, instructions, as in at the CPU level. Well, it could be worse, at least it’s not clock ticks. Still, if you’re time-dilated enough you can wait the 3 weeks to boot DOS, and the 3 months to load a level, you can play DOOM at 0.0001 FPS.

Look, we didn’t make the rules — they say everything has to try and run DOOM. They don’t say everything has to run it well.


hackaday.com/2026/07/15/doom-r…

Cut And Fold Your 3D Printer’s Next Cover


The media in this post is not displayed to visitors. To view it, please log in.

[cmh]’s ultra-simple top cover for the Snapmaker U1 3D printer has a 3D model, but don’t let that fool you. There’s no 3D printing at all involved in this project. Rather, the model is a reference shape for making an effective top cover out of cardboard or corrugated plastic sheet (also known as Coroplast) which is what [cmh] used.
The pattern can be cut from a single sheet, or from multiple pieces taped together.
Corrugated plastic is a versatile option for things like printer enclosures. It’s cheap, a good insulator, easy to cut, and available from just about any plastics supplier. We’ve made the case that they’re a good alternative to acrylic sheets for printer enclosures, but [cmh] goes even further with a design that requires no additional hardware whatsoever. Assembly doesn’t even require more than tape, really.

He provides a cutout diagram for pieces that, when assembled, make a sort of hat that is just right to cover the top of the Snapmaker U1 without obstructing the extruders. One can even lift the front panel to access the inside without removing the cover, which is a nice touch. Should one wish to add a viewing window anywhere, just cut out a square and tape a sheet of clear plastic over the hole.

For a 3D printer, an enclosure and top cover helps retain heat, block drafts, and keep dust (or curious fingers) away from the printer’s build area. The cover doesn’t need to be completely sealed to deliver those benefits, but if you do prefer your covers completely enclosed, a carefully-chosen IKEA storage box makes a conveniently great cover for the U1.


hackaday.com/2026/07/15/cut-an…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

RoguePlanet (CVE-2026-50656): la race condition in Microsoft Defender che regala privilegi SYSTEM
#tech
spcnet.it/rogueplanet-cve-2026…
@informatica


RoguePlanet (CVE-2026-50656): la race condition in Microsoft Defender che regala privilegi SYSTEM


Il 9 luglio 2026 Microsoft ha rilasciato la correzione per RoguePlanet, una vulnerabilità zero-day nel Malware Protection Engine di Microsoft Defender che permetteva a un attaccante con accesso locale di ottenere privilegi SYSTEM su qualsiasi macchina Windows 10 o Windows 11 completamente aggiornata. Il dettaglio che rende questo bug particolarmente istruttivo per chi amministra flotte Windows non è tanto la gravità – con un CVSS 4.0 di 7.8 non è la falla più critica dell’anno – quanto il fatto che a essere vulnerabile sia proprio il componente che dovrebbe proteggere il sistema, e che il proof-of-concept pubblico funzioni indipendentemente dallo stato della protezione in tempo reale.

Cos’è RoguePlanet (CVE-2026-50656)


RoguePlanet è tracciata come CVE-2026-50656 ed è una vulnerabilità di elevazione dei privilegi locale nel Microsoft Malware Protection Engine, il motore di scansione condiviso da Defender e da altri prodotti Microsoft di sicurezza. La causa tecnica è una improper link resolution before file access, in pratica una race condition simile alle classiche TOCTOU (time-of-check to time-of-use): il motore di scansione risolve un percorso o un link simbolico/junction in un momento diverso da quello in cui accede effettivamente al file, e questa finestra temporale può essere sfruttata per far operare il processo, che gira con privilegi SYSTEM, su un file diverso da quello previsto.

Il ricercatore che ha scoperto e divulgato pubblicamente il bug, noto con lo pseudonimo Chaotic Eclipse (in alcune fonti riportato come Nightmare-Eclipse), ha pubblicato dettagli tecnici e codice exploit già a giugno 2026, prima che Microsoft rilasciasse una patch, nel contesto di una disputa pubblica con l’azienda sulle tempistiche di risposta alle segnalazioni di vulnerabilità. Questo ha reso RoguePlanet una vulnerabilità “N-day pubblica” per diverse settimane, con Microsoft che ha classificato lo sfruttamento come “Exploitation More Likely” sul proprio Exploitability Index.

Perché disattivare Defender non è una mitigazione valida


Un dettaglio operativo importante per chi ha dovuto gestire l’incidente: il proof-of-concept pubblicato funziona indipendentemente dal fatto che la protezione in tempo reale sia attiva o meno. Questo significa che la contromisura “tampone” spesso adottata in scenari di zero-day – disattivare temporaneamente il modulo vulnerabile finché non arriva la patch – non era efficace in questo caso, perché il motore di scansione resta comunque presente e invocabile sul sistema anche a protezione realtime disattivata.

Come funziona l’attacco in pratica


RoguePlanet è un exploit post-compromise: non è una falla che consente l’accesso iniziale a un sistema, ma serve ad ampliare i privilegi una volta che l’attaccante ha già ottenuto un punto d’appoggio, ad esempio tramite credenziali rubate, malware, phishing o un’altra vulnerabilità. Lo schema tipico è:

  • L’attaccante ottiene accesso come utente standard (senza privilegi amministrativi) su un endpoint Windows.
  • Sfrutta la race condition nel Malware Protection Engine per far scrivere, sostituire o manipolare un file in un percorso controllato dall’attaccante mentre il motore opera con privilegi SYSTEM.
  • Ottiene l’esecuzione di codice arbitrario con privilegi SYSTEM, uscendo di fatto dal sandbox dei permessi utente.
  • Da lì può disabilitare protezioni, esfiltrare dati, installare impianti persistenti o muoversi lateralmente nella rete.

È lo schema classico che trasforma una compromissione limitata (un singolo account utente) in una compromissione totale della macchina, ed è per questo che le vulnerabilità di questo tipo vengono trattate con priorità alta anche quando il CVSS non è altissimo: il vettore di attacco (locale, bassa complessità, nessuna interazione utente richiesta) le rende un tassello estremamente efficiente nelle catene di attacco moderne, specie quelle assistite da AI dove le fasi di privilege escalation e lateral movement vengono automatizzate.

Cosa fare subito


La buona notizia è che la correzione è già disponibile e, trattandosi di un aggiornamento del motore antimalware, viene distribuita automaticamente tramite gli aggiornamenti regolari delle definizioni, senza richiedere un intervento manuale sugli endpoint. La versione corretta del Malware Protection Engine è la 1.1.26060.3008 o successiva. Ecco però una checklist di verifica utile in ambienti gestiti:

# Verifica la versione del Malware Protection Engine su un endpoint Windows
Get-MpComputerStatus | Select-Object AMEngineVersion, AMProductVersion, AntivirusSignatureLastUpdated

# Forza un aggiornamento immediato delle definizioni e del motore
Update-MpSignature -UpdateSource MicrosoftUpdateServer

# In ambienti con Configuration Manager / WSUS, verifica la data
# dell'ultimo aggiornamento delle definizioni su tutta la flotta
Get-MpComputerStatus | Select-Object ComputerID, AMEngineVersion |
    Export-Csv -Path C:\Reports\defender-engine-status.csv -NoTypeInformation

Se gestisci endpoint tramite Microsoft Defender for Endpoint, puoi verificare la copertura a livello di flotta dal portale Security, sezione Reports > Microsoft Defender Antivirus, filtrando per versione del motore. In ambienti air-gapped o con aggiornamenti WSUS ritardati, questo è il momento di controllare che la cadenza di distribuzione delle definizioni non stia introducendo un ritardo superiore a qualche giorno rispetto al rilascio Microsoft.

Indicatori di compromissione da monitorare


Per chi sospetta un possibile sfruttamento avvenuto prima della patch, Microsoft e i ricercatori indipendenti suggeriscono di dare priorità ai seguenti segnali in fase di threat hunting:

  • Processi SYSTEM anomali generati da MsMpEng.exe o da altri componenti del Malware Protection Engine, specialmente se seguiti dall’avvio di una shell (cmd.exe, powershell.exe).
  • Modifiche non pianificate alle impostazioni o ai servizi di Microsoft Defender, incluse disattivazioni temporanee della protezione in tempo reale non riconducibili a policy note.
  • Creazione di attività pianificate (scheduled task) sospette nella stessa finestra temporale di scansioni antimalware.
  • Nuovi meccanismi di persistenza (servizi, chiavi di avvio, WMI event subscription) creati con privilegi SYSTEM da processi non abituali.

Al di là del singolo CVE, RoguePlanet è un buon promemoria di un principio generale di hardening: restringere i privilegi standard degli utenti, limitare l’esecuzione di codice non autorizzato tramite AppLocker o Windows Defender Application Control, e mantenere una cadenza di patching aggressiva restano le difese più efficaci contro l’intera classe di vulnerabilità di elevazione dei privilegi, indipendentemente dal componente specifico coinvolto.

Conclusione


RoguePlanet dimostra ancora una volta che anche i componenti di sicurezza non sono immuni da vulnerabilità e possono, paradossalmente, diventare essi stessi superficie d’attacco. Per i sistemisti la buona notizia è che la correzione è già in distribuzione automatica: il compito principale è verificare che la propria flotta stia effettivamente ricevendo gli aggiornamenti del motore in tempi ragionevoli e, per gli ambienti a rischio più elevato, effettuare una verifica retrospettiva degli indicatori di compromissione descritti sopra.

Fonte: Petri IT Knowledgebase – Microsoft Patches Zero-Day RoguePlanet Defender Flaw


Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Passkey come default in Microsoft Entra ID: guida alla migrazione da SMS e voce entro il 2027
#tech
spcnet.it/passkey-come-default…
@informatica


Passkey come default in Microsoft Entra ID: guida alla migrazione da SMS e voce entro il 2027


Il 13 luglio 2026 Microsoft ha annunciato un cambiamento che riguarda praticamente ogni amministratore Entra ID: a partire da settembre, le passkey diventeranno il metodo di autenticazione predefinito per i nuovi accessi, mentre SMS e voce – i metodi di verifica più diffusi negli ultimi quindici anni – verranno progressivamente dismessi come servizio nativo, con ritiro definitivo fissato per il 1 febbraio 2027. Non è un annuncio isolato: è la formalizzazione di una traiettoria che Microsoft persegue da tempo, ma con date precise che ogni tenant dovrà rispettare, volenti o nolenti.

Perché Microsoft accelera proprio ora


La motivazione dichiarata da Microsoft nel post ufficiale sul Security Blog non è generica. Il Microsoft Threat Intelligence ha osservato campagne di phishing assistite da AI con tassi di click-through fino al 54%, contro il circa 12% delle campagne tradizionali. A questo si aggiunge la crescente accessibilità di tecniche come il SIM swapping e il bypass dell’autenticazione multifattore, che rendono SMS e voce – entrambi basati su segreti condivisi trasmessi su canali intercettabili – sempre meno affidabili come secondo fattore. Le passkey, basate su crittografia a chiave pubblica anziché su segreti condivisi, sono phishing-resistant per costruzione: non esiste un codice da rubare o da far digitare su un sito civetta, perché la chiave privata non lascia mai il dispositivo dell’utente.

Cosa cambia concretamente: la timeline


Per pianificare la migrazione senza sorprese, questi sono i passaggi principali comunicati da Microsoft:

  • 1 settembre 2026 – Tutti gli utenti già abilitati per SMS o voce vengono automaticamente iscritti e sollecitati a registrare una passkey al successivo accesso con autenticazione multifattore.
  • 18 settembre 2026 – Microsoft pubblica i dettagli su provider di telecomunicazioni supportati, prezzi e condizioni commerciali per chi deve continuare a usare SMS/voce tramite terze parti.
  • 30 ottobre 2026 – Gli amministratori possono selezionare e configurare un provider telecom di terze parti tramite il Microsoft Security Store.
  • 1 febbraio 2027 – Microsoft ritira il servizio nativo di autenticazione SMS e voce in Entra ID. Da questa data, chi non ha configurato un provider terzo o una passkey dovrà necessariamente registrarne una prima di poter accedere: non è previsto alcun opt-out.

Il punto da evidenziare per chi pianifica: l’auto-enrollment parte a settembre, ma la scadenza reale – quella che rompe l’accesso per chi non si è mosso – è a febbraio 2027. Sono circa sette mesi di finestra, che possono sembrare tanti ma si riducono rapidamente se il tenant ha migliaia di utenti, dispositivi eterogenei o processi di change management lenti.

Quali tipi di passkey supporta Entra ID


Entra ID distingue due famiglie di passkey, ed è una distinzione operativa rilevante per la policy da adottare:

  • Passkey sincronizzate (synced): memorizzate in un gestore di credenziali a livello di piattaforma e sincronizzate tra i dispositivi dell’utente, ad esempio tramite iCloud Keychain o Google Password Manager. Comode per utenti finali, ma con un livello di attestazione hardware inferiore.
  • Passkey vincolate al dispositivo (device-bound): legate a un singolo dispositivo o chiave fisica, ad esempio le passkey di Microsoft Authenticator, le Entra passkey su Windows (basate su Windows Hello for Business) e le chiavi di sicurezza FIDO2 hardware. Offrono garanzie di attestazione più solide, adatte a account amministrativi o a scenari con requisiti di compliance stringenti.

Le passkey FIDO2 sono disponibili in tutte le edizioni di Entra ID, inclusa quella Free, senza licenze aggiuntive: un dettaglio non scontato che elimina l’alibi del costo per rimandare l’adozione.

Come prepararsi: guida pratica per amministratori

1. Mappa chi usa ancora SMS o voce


Il primo passo è puramente ricognitivo: individuare quali utenti o gruppi sono ancora configurati su SMS o voce come metodo di autenticazione. Con Microsoft Graph PowerShell:

# Connessione a Microsoft Graph con i permessi necessari
Connect-MgGraph -Scopes "UserAuthenticationMethod.Read.All","Policy.Read.All"

# Elenca gli utenti con metodo di autenticazione telefonico configurato
$users = Get-MgUser -All -Property Id, DisplayName, UserPrincipalName
foreach ($u in $users) {
    $methods = Get-MgUserAuthenticationPhoneMethod -UserId $u.Id -ErrorAction SilentlyContinue
    if ($methods) {
        [PSCustomObject]@{
            User  = $u.UserPrincipalName
            Phone = ($methods.PhoneNumber -join ", ")
        }
    }
}

2. Configura i passkey profile


Da qualche mese Entra ID supporta i passkey profile, che permettono configurazioni granulari per gruppo anziché un’unica impostazione a livello di tenant: puoi definire requisiti di attestazione, tipo di passkey ammesso (device-bound vs synced) e restrizioni per AAGUID (l’identificativo del modello di authenticator) differenziando, ad esempio, gli amministratori – per cui puoi imporre solo chiavi FIDO2 hardware con attestazione verificata – dal resto del personale, per cui le passkey sincronizzate sono sufficienti. La configurazione si effettua da Entra admin center > Protection > Authentication methods > Passkey (FIDO2), oppure via Graph API sull’endpoint /policies/authenticationMethodsPolicy/authenticationMethodConfigurations/Fido2.

3. Attiva una registration campaign


Per portare gli utenti alla registrazione senza dover organizzare sessioni di onboarding manuali, Entra ID offre le registration campaign: durante un normale accesso MFA, l’utente viene invitato a registrare una passkey in modo contestuale. Si abilitano da Authentication methods > Registration campaign, specificando quale metodo promuovere (in questo caso, passkey) e per quali gruppi.

4. Valuta l’enforcement con Conditional Access


Per i ruoli più sensibili, non basta rendere le passkey disponibili: conviene richiederle esplicitamente. Le authentication strength policy di Conditional Access permettono di imporre l’uso di metodi phishing-resistant (passkey, FIDO2, Windows Hello for Business) per l’accesso a risorse critiche, indipendentemente dal fatto che l’utente abbia ancora SMS configurato come fallback.

5. Se devi mantenere SMS o voce per obblighi regolatori


Non tutti i contesti possono abbandonare SMS/voce immediatamente per vincoli normativi o tecnici (ad esempio utenti privi di smartphone aziendale). In questo caso, il percorso è: documentare i segmenti di utenti interessati, attendere l’apertura del catalogo provider il 18 settembre, configurare un provider supportato tramite il Microsoft Security Store dal 30 ottobre, e testare la configurazione su un gruppo pilota prima del rollout esteso.

Conclusione


La transizione a passkey-by-default non è una feature opzionale da valutare con calma: ha una data di rottura precisa, il 1 febbraio 2027, dopo la quale gli utenti ancora legati a SMS o voce senza un provider terzo configurato saranno bloccati in accesso finché non registrano una passkey. Per i team IT il consiglio pratico è iniziare subito con la ricognizione degli utenti a rischio e l’attivazione di una registration campaign pilota, così da arrivare a settembre con un processo già collaudato invece di gestire l’auto-enrollment massivo come un’emergenza.

Fonte: Microsoft Security Blog – Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID


Cybersecurity & cyberwarfare ha ricondiviso questo.

US and allied Governments' Recommendations: Securing Network Devices Against Russian #APT Groups
securityaffairs.com/195448/apt…
#securityaffairs #hacking #Russia
Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: A security vulnerability in the remastered version of the classic 25-year-old war strategy game Age of Empires II allowed hackers to take over victims' computers with just a malicious game invite.

techcrunch.com/2026/07/15/micr…

reshared this

FLOSS Weekly Episode 875: JavaScript as a Systems Language


The media in this post is not displayed to visitors. To view it, please log in.

This week Jonathan chats with Nariman Jelveh about Puter! It’s the project that takes the idea of the Browser-as-the-OS seriously. Why did a simulated desktop on the web take off, what the story of making it Open Source, and what’s coming next? Watch to find out!


youtube.com/embed/9vrzEvWiALw?…

Did you know you can watch the live recording of the show right on our YouTube Channel? Have someone you’d like us to interview? Let us know, or have the guest contact us! Take a look at the schedule here.

play.libsyn.com/embed/episode/…

Direct Download in DRM-free MP3.

If you’d rather read along, here’s the transcript for this week’s episode.

Places to follow the FLOSS Weekly Podcast:


Theme music: “Newer Wave” Kevin MacLeod (incompetech.com)

Licensed under Creative Commons: By Attribution 4.0 License


hackaday.com/2026/07/15/floss-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Aggirare l'ultima app europea di verifica dell'età (2026.07-1) con un'estensione Chrome... di nuovo.

Nonostante 3 mesi di rafforzamento della sicurezza e miglioramenti genuini in tutti i fronti, il problema fondamentale non può essere risolto.

La verifica dell'età anonima non funziona.

x.com/i/status/207702935558733…

@privacypride

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Chaotic #Eclipse Unveils LegacyHive Exploit Affecting Fully Patched #Windows Systems
securityaffairs.com/195418/hac…
#securityaffairs #hacking

Hayabusa2’s Next Target is a Tiny 11 Meter Asteroid


The media in this post is not displayed to visitors. To view it, please log in.

Launched in 2014, Japan’s Hayabusa2 spacecraft completed its primary asteroid sample return mission all the way back in 2020. But with the main spacecraft still healthy, the intrepid little probe was assigned new missions — such as its future investigation of asteroid 1998 KY26, a rather unassuming 11 meter diameter rock.
Artist impression of Hayabusa2 firing its ion thrusters. (Credit: DLR, Wikimedia)Artist impression of Hayabusa2 firing its ion thrusters. (Credit: DLR, Wikimedia)
Earlier this month Hayabusa2 flew by the 450 meter 98943 Torifune at a distance of 800 meters, close enough to get an up-close look of its surface of mostly silicate minerals. With the spacecraft flying past at around 5 km/s, this posed some challenges with tracking, especially since its systems and instruments were not designed for high-speed tracking.

With that mission now complete, 1998 KY26 – first discovered in 1998 – is next on the menu, though this will have to wait a while. Currently it’s estimated that the two will not meet until July 2031.

Once they do meet up, after Hayabusa2 zips twice more past Earth, it’ll be another major challenge for the by now rather degraded spacecraft. Its sensors have suffer radiation and other types of damage, while its ion engines are quite depleted. The goal at this target asteroid is to enter orbit, deploy its last target marker and projectile, before attempting a landing, probably at one of its poles.

As likely the final mission for this spacecraft it’ll be very educational in many ways, not the least of which is that of planetary defense, but also that of deepening our understanding of these asteroids and the many varieties that we share space with.


hackaday.com/2026/07/15/hayabu…

Putting Some Zig in a Linux-Based 3D Printer


The media in this post is not displayed to visitors. To view it, please log in.

Having Linux on so many devices is both a blessing and a curse. Sure, it is great that you can hack on things and modify them or even totally repurpose them. But it also means you have a fleet of Linux devices you have to manage and keep track of.

My current “main” 3D printer is a Flashforge AD5X: a nice, cheap machine that does four colors with the purge/exchange method. It sort of runs Klipper. I say sort of because Flashforge has Klipper running on a Linux host in the box, but it is massively crippled and modified. I’m sure it works for most folks. I’m also sure that if you know nothing about Linux, Klipper, or 3D printing, the experience is probably better thanks to all the cloud point-and-click interfaces. But, of course, I check none of those boxes.

I’ve had the printer for probably a year or more. Almost immediately, I put a “mod” on the printer to give it a more true Klipper interface and gave me things like shell access. There are several that I think will do this, but I used Zmod, which doesn’t totally replace the printer’s firmware; it just sort of patches it and extends it. You can easily bypass or even remove it and go back to the stock printer, although I would not want to.

In my case, the issue was a printer, but the same idea might apply to any embedded Linux system, from a router to a thermostat. Sure, it runs Linux, but is it Linux you can change?

The Problem

The AD5X runs Linux… sort of.
The Flashforge firmware and Zmod both will run on the AD5X’s little sister, the AD5M. However, the AD5M has a significantly less capable processor board than the AD5X. That means that Linux on the boxes is very stripped down. From Flashforge’s point of view, no one should be in the Linux OS anyway, and the author of Zmod probably figures every byte used is a byte taken away from the user or other advanced Zmod features.

It may seem like a first-world problem, but there were two things that irked me about the printer’s Linux. There was no less or more command for poking around files. There was also only vi as an editor. I did a few hacks to make myself happy. I wrote a pager in shell script, for example. I would try to remember to use my desktop emacs and tramp to edit files on the box. But it was a shame that there were some very basic tools lacking. Besides that, even the tools that were there like ls lacked help commands in case you want some strange option you can’t remember.

No Install


To save space, the printer doesn’t really have programs like ls, cat, and grep. Instead, it has a single busybox executable. This is common on small systems. You get one copy of the libraries and a single executable that will do all the work you need. You can invoke, for example, grep by running “busybox grep” or, if you make a symlink to busybox named grep, the user may never realize that you don’t really have grep installed.

However, busybox has to be built. You can’t easily install packages to it. So I could just run some package manager and install less or anything else. My plan was to produce a new busybox package myself to supply at least the missing commands and maybe some of the more basic ones, too. How hard could it be?

How Hard, Indeed


The first issue was figuring out exactly what the printer was running. The OS was a buildroot compile as shown by /etc/os-release:
NAME=Buildroot
VERSION=2020.02.1-g0b1f992-dirty
ID=buildroot
VERSION_ID=2020.02.1
PRETTY_NAME="Buildroot 2020.02.1"
In theory, you could probably try to rebuild everything from that information, but it seemed like a bad idea. Who knows what changes they’ve made or what strange dependencies were out there?

The next piece of the puzzle was the architecture. It turned out to be MIPS, which has many variations, a problem that would come back to haunt me later. To figure it all out, I grabbed busybox from the machine and copied it to my regular computer. This let me read the elf file:

# readelf -h busybox
ELF Header:
Magic: 7f 45 4c 46 01 01 01 00 03 00 00 00 00 00 00 00
Class: ELF32
Data: 2's complement, little endian
Version: 1 (current)
OS/ABI: UNIX - System V
ABI Version: 3
Type: EXEC (Executable file)
Machine: MIPS R3000
Version: 0x1
Entry point address: 0x403fa0
Start of program headers: 52 (bytes into file)
Start of section headers: 775880 (bytes into file)
Flags: 0x70001405, noreorder, cpic, nan2008, o32, mips32r2
Size of this header: 52 (bytes)
Size of program headers: 32 (bytes)
Number of program headers: 10
Size of section headers: 40 (bytes)
Number of section headers: 30
Section header string table index: 29


Forensics


Just knowing that the CPU was MIPS was hardly enough. Note that the processor could have been big endian, but this one was little endian. What’s more, the flags show a few things, and the important ones would turn out to be mips32r2, which defines a particular set of instructions, and nan2008, which means everything is using a more modern floating point stack compared to some older MIPS setups.

The next step is to find a toolchain that can run on my Linux box and produce executables for such a machine. There were two main candidates that I thought about: zig and crosstool-ng.

Zig


You may remember that Zig is a completely different language from C. So it might not make sense that I want to compile busybox, a C program with Zig. However, Zig has an interesting feature. It can pretend to be gcc, and maybe compilers for some other languages too. The idea is that if you have a lot of C code, you could start changing over to Zig without having to convert everything today or even ever. Using CLang and LLVM, Zig purports to be able to just drop in a project as the system C compiler.

So why does that matter for this project? Zig also supports a lot of targets, including MIPS, and provides run time libraries for them. So if I just tell the build system to use Zig, everything will be fine, right?

Right…


Naturally, this didn’t work as well as I expected. It could be that I don’t understand Zig well enough, but passing --target mipsel-linux-musleabihf -mcpu=mips32r2 to zig cc couldn’t produce a working ‘hello world’ program. The reason? Zig appears not to supply a nan2008 library for MIPS. Or maybe I just didn’t know how to enable it. As far as I can tell, Zig might have done the right thing for mips32r6, but that, unsurprisingly, led to illegal instruction problems. Besides, I wanted to stick as close to the existing setup as possible.

I could have made Zig rebuild its libraries, but then I might as well build a full toolchain. However, I wondered if floating point would matter much for what I was doing, so I decided to cheat. I let Zig build an executable, and then I simply patched the output header to say it used nan2008. It worked for a simple program.

Busybox

The configuration menu for busybox lets you customize it to your liking or, at least, requirements.
Configuring busybox is a matter of using a menuconfig system similar to building a kernel. I mainly asked it to make a static copy in options and then just picked a bunch of things I wanted, especially less and more.

Many programs, including less, have options to help you minimize the size. For example, you could disable regular expressions or make it not read $LESS for options. I left nearly everything on for most of the programs.

Once it was ready to go, I needed to run make with the Zig compilers and then do the patch to fool the printer into running it.

The command line that worked the best turned out to be: make V=1 CC="zig cc -target mipsel-linux-musleabihf -mcpu=mips32r2 -static -Os" STRIP='llvm-strip' -j6

Of course, you could adjust the -j6 to suit how many CPUs you have. I like to use about 1/2 of mine when compiling. Then the patch is as simple as:

printf '\024' | dd of=busybox bs=1 seek=37 count=1 conv=notrunc

Did it Work?


Once I transferred the file, renamed to busybox-ad5x, over to the printer, I was able to successfully run things like busybox less or even busybox ls. Everything seemed to work. You can ask busybox to install a bunch of symlinks for everything it knows how to do, but I wanted to start small, so I only made symlinks for things that didn’t already exist in the native busybox.

Once I didn’t find problems, I eventually replaced even the old busybox utilities with the new ones. I even made busybox-ad5x a symlink and renamed this version as busybox-zig because I wanted to try one more experiment: using crosstool-ng to make a proper toolchain.

Next Time


But that’s a whole other topic for another day. For now, Zig — with a little patching — got the job done. There are many ways to get things done under Linux. Turns out it is very hard for a vendor to totally lock down a system, and if there is a way in, then there is almost always some way to tune things to your liking. Busybox is a great tool for stripped-down systems. Even floppy-based boots.


hackaday.com/2026/07/15/puttin…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Quando qualcuno ride per un poveraccio che ha perso tutti i dati perché li ha affidati solo a una megacorporation statunitense, ricordatevi sempre di questo fatto incontrovertibile:

mastodon.uno/@informapirata/11…


@anfibolo il tuo ospedale si fida di Microsoft, la tua scuola si fida di Microsoft e probabilmente anche il tuo comune e la tua azienda si fidano di Microsoft. Mi spieghi per quale motivo dovrebbe essere colpa di un cittadino se si fida di microsoft?

Non bisogna colpevolizzare mai le vittime se queste vivono in un mondo condizionato dal pregiudizio per cui le Big Tech sono sempre affidabilissime


reshared this

in reply to FrankDmt90

@FrankDmt90 saggia decisione. Io un paio di anni fa mi sono comprato un NAS per avere un backup ridondante gestito solo da me. L'operazione di migrazione è stata abbastanza tortuosa. Non avevo in casa un disco abbastanza grande per scaricarci tutta la mia collezione. Alla fine ho usato uno script che mi ha permesso di fare scaricare tutto direttamente sul NAS senza ponti. Solo quando ti cimenti in questa operazione capisci quanto cacchio siamo dipendenti da Google!

informapirata ⁂ reshared this.

in reply to Neff

@Neffscape
Non uso un NAS ma ho un semplice disco esterno da 500GB e un account su Koofr da un bel po' di anni.
Prima avevo un paio di file batch che copiavano dal disco del PC al disco esterno e a Koofr.
Ora gli stessi due file batch chiamano rclone per copiare/sincronizzare, quindi sia sul disco esterno sia su Koofr i dati sono cifrati in partenza e, anche se Koofr ha il suo Vault "zero knowledge" mi fido di più così.
@FrankDmt90 @informapirata
in reply to FrankDmt90

@FrankDmt90
Io ho un account Google gratuito dove metto una selezione ristretta di foto/video importanti, così come alcuni documenti su Drive.
Poi tutte le altre cose (comprese migliaia di foto e video) vanno su un account Infomaniak myKSuite, su un NAS che ho a casa e, periodicamente, su due vecchi dischi USB tenuti in un cassetto.

Paranoico? Sì, ma non voglio perdere i ricordi di una vita, i viaggi e le foto dei miei figli perché mi sono affidato a un single point of failure
@informapirata

Cybersecurity & cyberwarfare ha ricondiviso questo.

Microsoft chiude un account hackerato, 25 anni di dati personali persi per sempre


Microsoft ha appena perso una causa in Brasile per il modo in cui ha gestito un account hackerato, e a quanto pare ci risiamo con più o meno le stesse modalità. A denunciare l’accaduto è stato lo streamer Joshua Khane, che sostiene di aver perso definitivamente il proprio account Microsoft e tutti i dati associati dopo un attacco informatico, con conseguenze che definisce devastanti. Khane racconta su Twitter che gli hacker hanno modificato le informazioni di sicurezza, impedendogli di riprenderne il controllo.

Microsoft è intervenuta, chiudendo definitivamente l'account (in modo "irreversibile", conferma la nota della società) ed escludendo in modo categorico qualsiasi tentativo di recupero. Khane dice che l’account conservava circa 25 anni di dati personali, tra cui documenti, contenuti digitali e fotografie di famiglia considerate insostituibili - incluse quelle dell’infanzia del figlio, archiviate su OneDrive e ora non più accessibili. Oltre ai contenuti personali, lo streamer sostiene di aver investito migliaia di euro in videogiochi e acquisti digitali collegati allo stesso profilo Microsoft, che risultano anch’essi irrecuperabili.

hdblog.it/microsoft/articoli/n…

@informatica

Cybersecurity & cyberwarfare ha ricondiviso questo.

#AsyncAPI #npm Supply Chain Attack: #Malware Injected Into Packages With 2 Million Weekly Downloads
securityaffairs.com/195395/sec…
#securityaffairs #hacking

Making a Locked Down Wearable Work Without a Subscription


The media in this post is not displayed to visitors. To view it, please log in.

WHOOP does not have the presence in the wearable space as other brands, but in certain circles, it’s a household name. Their business model requires you to have a yearly app subscription to use their fitness tracker, but here at Hackaday, we are big fans of actually owning the devices you buy — which is why we were happy to hear about an open source and subscription free WHOOP compatible app!

The goal of the so-called OpenStrap project is not to re-create the WHOOP app. Rather, the algorithms and processing methods are developed from scratch, based on public research. It’s all calculated locally on a 1 Hz interval, based on the data the WHOOP 4.0 device feeds the app. As such, the health data collected from the watch, never leaves the phone. While not the main goal of the project, the privacy improvement of the app’s serverless nature cannot be overstated. However, to display metrics, you first need to get data off the WHOOP to begin with.

The crux of the issue with making the WHOOP 4.0 work without the official app is the reliance on proprietary Bluetooth protocols. Fortunately, the protocol itself ended up being relatively simple. The WHOOP 4.0 amounts to little more than a series of sensors that sit on the user’s wrist. As such, the app can subscribe to the Bluetooth feed and decode the data, right? Well, the devil is always in the details with such things, and the protocol came with its fair share of quirks. The hardware clock needs to be synchronized, or it simply defaults to zero Unix time. Moreover, the analog sensors like, ambient temperature are given in relative ADC values, and are not terribly useful without calibration. Regardless, the result of the reverse engineering effort speaks for itself with the OpenStrap app able to recreate much of the functionality in WHOOP’s official app.

Quite often, devices reliant on proprietary apps are little more than manufactured e-waste. While we don’t expect many of you to actually own a WHOOP 4.0, we do hope to see the OpenStrap project keep at least a few out of the landfill in the future.


hackaday.com/2026/07/15/making…

Patch Tuesday, il record che nessuno voleva: 622 CVE e un nuovo modo di fare sicurezza


@Informatica (Italy e non Italy)
Il Patch Tuesday di luglio 2026 stabilisce il record assoluto nella storia di Microsoft: 622 CVE corrette, incluse due zero-day già sfruttate in attacchi reali su SharePoint e Active Directory. Eppure, nessuna delle due supera il CVSS 6.

Cybersecurity & cyberwarfare ha ricondiviso questo.

Croazia, giorno 2: Isola di Ciovo: mare come in Sardegna, ma...un'amara scoperta.


The media in this post is not displayed to visitors. To view it, please go to the original post.

Nel secondo giorno del recente viaggio in Croazia, nella splendida regione della Dalmazia, ho scelto un itinerario di circa 200 km per visitare prima Almissa (Omiš), e poi l'isola di Bua (Čiovo), per passare dei momenti fantastici tra panorami, scogliere, spiagge meravigliose che mi hanno riportato all'adolescenza, quando frequentavo posti incantevoli simili qui da noi.

C'è qualcosa, però, che ha rovinato l'incanto dei posti, per ben 2 volte nella giornata...

Non mancheranno i consigli e il mio punto di vista su alcune cose.

📌 Non dimenticare di iscriverti al canale e attivare la campanellina per non perdere i prossimi giorni del viaggio!

=== COMMUNITY per viaggiatori....iscriviti oppure citala in quello che scrivi per postare nella community! ===
- @viaggi@feddit.it

=== Il mio blog ===
simoneviaggiatore.com

=== CONSIGLI ===
- Punto di osservazione spettacolare per vedere Almissa dall'alto:
maps.app.goo.gl/k5P6xbA6sgF91u…

=== CAPITOLI ===

00:00 Introduzione e itinerario del giorno 00:19 Omis: la città sul fiordo 01:12 Lavanda e prodotti tipici croati 01:35 Incontri ravvicinati: gli scarabei 02:02 La grande spiaggia di Omis, VELIKA: bandiera blu d'Europa 02:56 Panorama sull'isola di Brac 03:34 Riflessioni sul viaggio e il caldo umido 04:56 Il problema dei rifiuti in Croazia 05:43 Arrivo sull'isola di Ciovo 06:39 Un mare da favola: confronto con la Sardegna 07:11 Vista su Spalato dall'isola 08:11 Curiosità sul borgo medievale 09:06 Verso Okrug e le spiagge di sassolini bianchi 11:00 Consigli utili: luce e occhiali da sole 11:21 Un'amara scoperta: discariche abusive

Questa voce è stata modificata (1 giorno fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

U.S. #CISA adds #SonicWall and #Microsoft flaws to its Known Exploited Vulnerabilities catalog
securityaffairs.com/195383/sec…
#securityaffairs #hacking

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

#nerdystuff in pausa pranzo

#HubbleBirthday ti mostra cosa fotografava il telescopio Hubble il giorno in cui sei nato: nebulose, ammassi, galassie che esistevano già mentre tu strillavi in sala parto.
Meglio di qualsiasi oroscopo, e pure vero =)

🔭 science.nasa.gov/mission/hubble/multimedia/what-did-hubble-see-on-your-birthday

reshared this

OkoBot: new sophisticated malware framework targets cryptocurrency users


The media in this post is not displayed to visitors. To view it, please log in.


Introduction


In January 2026, we identified multiple attacks involving unknown malware that captures the contents of cryptocurrency wallet windows. During the investigation, we reconstructed the complete infection chain, which consisted of four tightly linked stages initiated by the execution of the previously described malicious PowerShell script TookPS. However, this campaign differs from previous activity in that it uses a new framework to deliver all malicious modules and orchestrate them via an SSH tunnel. In total, the framework includes more than 20 malicious payloads and implants, covering a wide variety of functions. At the time of writing, the threat remains active.

Kaspersky’s products detect this threat as Trojan-Downloader.Win32.TookPS.*, Trojan.Win64.BypassUAC.*, Trojan-Banker.Script.Agent.gen, Trojan.Win32.Dllhijack.*, Backdoor.Win32.TeviRat.*, Trojan-PSW.Win64.Stealer.*, Trojan-Spy.Win64.Keylogger.*, Trojan-Spy.Win64.Agent.*, Trojan.Win64.Agent.*.

Background


TookPS is a downloader used for retrieving malicious commands and scripts from attacker-controlled servers to further propagate attacks. The first campaign using TookPS was discovered in March 2025. At that time, malicious scripts delivered a Python‑based infostealer along with a script that installed and configured an SSH tunnel on the victim’s machine. The next wave appeared in April 2025: the payload was changed, and TookPS was used to deliver the TeviRAT malware with the same SSH installer.

Then at the end of April 2025, TookPS underwent minor changes, yet its attack chain was completely redesigned. Unlike previous incidents, in this case, TookPS was used solely for the initial infection, with an automated SSH bot responsible for payload delivery. This new malicious campaign has multiple stages that cover the full attack lifecycle, from initial infection to persistence and data exfiltration. Among various malware strains, at one of the stages, the TeviRAT backdoor is delivered to the compromised host, ultimately fetching another version of a TookPS script.

We dubbed this updated TookPS campaign “OkoBot”.

Original OkoBot infection chain
Original OkoBot infection chain

We will break down this chain in greater detail later in the article. However, this is not the only version of OkoBot we were able to find. Already in March 2026, we discovered a new phase in the development of the framework, with Volume2 now being installed directly using TookPS. The HDUtil launcher → extl injector → Rilide chain was found to be abandoned in this newer version since it was replaced in full by the identical ext_daemon Volume2 plugin. TeviRAT was also removed, most likely because its functions were covered by the new plugins dispatcher.

New OkoBot infection chain
New OkoBot infection chain

Initial infection


The initial infection is primarily delivered through two vectors: a ClickFix attack, and malware distributed through GitHub that masquerades as legitimate software. One such example is the fake SQL Server Management Studio (SSMS) package distributed through GitHub. In fact, it is actually the legitimate Audacity — a popular audio editor — compiled with a malicious implant embedded in one of its libraries. Because the repository was indexed by most search engines and appeared at the top of the results for the query SSMS, the malware looked legitimate and quickly earned users’ trust.

Malicious application distribution report
Malicious application distribution report

This repository was created at the end of March 2025 and existed until June of that year. It consisted of a single file, README.md, which provided a fake SSMS installation guide written in an official style and likely derived from excerpts of Microsoft’s documentation. However, the download link for the program, located at the beginning of the guide, pointed to the latest release in the same repository.

Both infection vectors trigger the execution of the malicious script TookPS, which installs SSH on the victim’s system, establishes a connection to the attacker-controlled SSH server and subsequently forwards the SSH daemon port. Following a delay, an automated SSH bot connects to the forwarded port.

Back connection


The automated SSH bot collects system information such as usernames, antivirus software installed, the IP address, and OS version. It harvests cryptocurrency wallet files, browser cookies, profiles, and other credentials through an SSH tunnel. For subsequent delivery of malicious modules, it disables Windows Defender notifications via a registry modification. Moreover, it gains access to the graphical session on the victim’s system using the following sequence:

  1. Open firewall ports for inbound RDP traffic
  2. Create a user in the “Remote Desktop Users” group
  3. Replace the legitimate termsrv.dll with a patched one to permit multiple concurrent RDP sessions
  4. Create a scheduled task named Apple Sync to maintain a reverse SSH tunnel that forwards the local RDP port every hour

After that, the SSH bot begins retrieving malicious modules over SFTP.

Launcher with advanced options


One of the deployed modules is HDUtil, an auxiliary utility protected with VMProtect and heavily obfuscated. This launcher is used by the SSH bot during an attack to deploy various malicious modules via the target command. Additionally, it implements three auxiliary commands that were not observed during the attacks we analyzed. Nevertheless, their presence and potential capabilities further demonstrate the high degree of integration among all components of the framework.

Active sessions


At startup, the launcher verifies its execution environment by checking the HWID in the contents of %PROGRAMDATA%\hwid.dat, a technique consistently employed throughout the framework. If the file is missing or contains invalid data, such as a non‑MD5 hash, the launcher terminates without performing any further actions. Otherwise, the specified commands are executed. For example, enumsessions provides a list of sessions along with detailed information, including the session type (Console, Services, RDP, and others), username, connection host, and domain. In turn, enumadapters returns the names of all graphics adapters present on the system.

Example output of HDUtil enumeration commands
Example output of HDUtil enumeration commands

UAC bypass


The most important command of the launcher is target, which enables payload execution on the system. An optional nouac argument enables automatic UAC bypassing via Windows RPC and an auto-elevated msconfig.exe program, allowing the payload to run with elevated privileges stealthily. This technique has been known for a long time, discovered and described in 2019 by the Project Zero team, who provided a full report with a detailed technical description.

Below is the list of all HDUtil commands.

CommandDescription
target [nouac [user=<user>]] [noattach] <file>Starts file and prints its output.
If optional argument noattach passed, command to be executed in background.
If optional argument nouac passed, automatic UAC bypass to be performed.
If optional argument user passed, new process to be executed under , otherwise default local administrator to be chosen.
pcopy <file> <dir_src> <dir_dst>Copies file <file> located in <dir_src> to <dir_dst>. Not used by SSH bot.
enumadaptersPrints names of graphical adapters on current system. Not used by SSH bot.
enumsessionsPrints all sessions on current system. Not used by SSH bot.

Browser extensions loader


The first malicious module delivered to the infected system via SFTP is executed using the previously described launcher with the command .\HDUtil.exe target extl.exe. It is a heavily obfuscated DLL injector protected with VMProtect. At startup, the module enters an infinite loop and uses the EnumWindows and IsWindowVisible API methods to enumerate the PIDs of active windows and retrieve the corresponding executable filenames. For processes associated with widely used Chromium‑based browsers, the module invokes a routine that injects a specialized implant.

The injector opens a process, allocates a memory region, and writes the payload directly into this region as unencrypted raw bytes. Then it resolves two exported implant functions, LdrInitMain and LdrCallMain, based on a pre-specified hash derived from a modified version of DJB2 hash function. The first function performs the final PE unpacking, including rebase operations and the initialization of the import and exception tables. The second function directly initiates malware execution.

Setting up protections on the regions and launching the implant
Setting up protections on the regions and launching the implant

This loader installs malicious browser extensions and hides them from the user. It uses an internal engine that resolves the addresses of stripped functions by analyzing the byte patterns of their calls using YARA-style syntax. This approach enables the malicious code to access critical Chromium engine functions required for extension installation and management. This functionality is also implemented for other browsers with appropriate modifications. For example, in the case of Microsoft Edge, the corresponding DLL msedge.dll is hooked using the specific patterns.

List of the functions hooked by the malware
List of the functions hooked by the malware

Using the obtained address of the BrowserProcess object, the loader traverses the inheritance hierarchy and subsequently resolves a pointer to the function responsible for registering observers of browser‑window creation, specifically ProfileManager::BrowserListObserver::OnBrowserAdded. With a specialized built‑in engine, they are hooked using the attacker’s own implementations while preserving the original function’s address.

The loader replaces the functions it finds with its own
The loader replaces the functions it finds with its own

When a new Chromium window is opened, a hooked function is invoked that silently installs extensions. This routine scans the user’s %APPDATA% directory, loads all .crx files (Chromium-based browsers extension format), and records them in the ext_table. The extensions are then installed in the browser.

During installation, the extension is unpacked into a non‑default extensions directory, Local Extension Settings, and its manifest is dynamically modified. An object named custom_args is added, containing the fields hwid (the identifier of the infected system) and browser (the name of the browser in which the extension is installed). Then, using previously resolved internal functions of chrome.dll, the extension is installed and all requested permissions are granted.

Extensions are unpacked into a non-default directory
Extensions are unpacked into a non-default directory

All extensions loaded in this manner are added to a special array to be subsequently identified among regular extensions and to remain hidden from the user.

The remaining patched functions are used to hide the installed malicious extensions from the user. When invoked with registered extensions as parameters, they perform no operation and return a constant value. This enables the threat actor to suppress notifications related to the malicious nature of the extensions and to exclude them from the displayed list of installed extensions. As a result, the behavior of other extensions remains unaffected.

Stub for hiding malicious extensions
Stub for hiding malicious extensions

During the attack, the Rilide extension was installed on the victim’s system using the previously described loader. Rilide is a stealer targeting Chromium-based browsers that has been frequently used by Russian-speaking threat actors since April 2023. The malware is designed to steal sensitive user data, including login credentials, cookies, and financial information, with a specific emphasis on cryptocurrency theft.

Plugins dispatcher


The final module delivered via SFTP is an open-source utility called Volume2, which is executed with elevated privileges using the command .\HDUtil.exe target nouac noattach Volume2.exe. The executable was linked with the malicious protobuf.dll library. Although the library seems identical to the legitimate DLL, it has been modified to include a malicious exported function, ProtobufGetVer2. This function decrypts and initiates a malicious implant. The payload is encrypted using AES GCM, initialized with a static 256‑bit key and a 96‑bit nonce. The GCM authentication tag is omitted, resulting in the absence of integrity verification. Starting in March 2026, the name of protobuf.dll was changed to version.dll, although its contents remained a modified ProtoBuf library.

Decrypting implant using AES GCM and subsequent mapping
Decrypting implant using AES GCM and subsequent mapping

The loaded implant functions as a malicious plugin dispatcher. Upon initialization, it reads and verifies the HWID before establishing communication with the C2 server via the HTTP protocol. Each request follows a predefined binary format: a 2-byte numeric bot identifier encoded in little-endian format, followed by an AES CBC-encrypted JSON object. By default, the BotID is set to 0, and the key and IV consist of 32 and 16 bytes of 0xff, respectively. The implant polls the server every 20 seconds to retrieve new commands. The request contains client data encoded in Base64, and the server may respond with a command containing three mandatory fields: TaskIndex (the command number from the dispatcher), TaskID (a unique task identifier), and HWID (the client identifier). The dispatcher supports four built-in commands:

Task indexAction
1Reconfigure client: update session keys, assign ID, switch to another C2
2Load DLL implant into memory and run its entry point
3Load plugin into process and register tasks with RegisterPlugin function
4Restart dispatcher as new process
xIf the task number is none of the above, search for it among the registered plugins

Each plugin is required to export two functions: RegisterPlugin and PluginDispatch. These functions are used to manage and configure plugins. The RegisterPlugin function registers the plugin’s tasks with the dispatcher, whereas the PluginDispatch function is invoked when the plugin is called. Both these functions, as well as other external API functions, are located within the base libraries using one algorithm. This algorithm iterates through the export table and uses a specialized callback that calculates the MurmurHash3 hash and compares it against the target value to identify the appropriate function.

Resolving a plugin initialization function
Resolving a plugin initialization function

During the analysis, we were able to discover five plugins that implement functions under their unique task identifiers.

  • CMD wrapper (10xx): allows running scripts and individual commands in cmd.
  • PowerShell wrapper (11xx): allows running scripts and individual commands in PowerShell.
  • Environment enumerator (12xx): gathers system information, active sessions, and processes.
  • Dropper (14xx): downloads an additional payload directly onto the system both from embedded Base64-encoded binary blob and via URL.
  • Process injector (16xx): launches additional malicious implants on the target system by injecting them into legitimate processes.

We identified four malicious implants that are delivered to the system via the process injector plugin.

ext daemon


The malware is functionally identical to the browser extensions loader (extl.exe) described above, but less obfuscated and not protected with VMProtect.

SeedHunter


Similarly to extl.exe, this malware monitors the list of active processes in the system and injects an implant into Trezor Suite, Ledger Wallet, and Ledger Live processes. The implant is malware that collects seed phrases of Ledger and Trezor cryptocurrency wallets. Initially, it verifies the HWID, and if it fails, it terminates immediately. Then, based on the value of BaseDllName, the malware determines the process context and uses the corresponding implementation for either Trezor or Ledger. It then utilizes the previously described technique to hook the internal Electron framework functions.

List of functions hooked by the malware
List of functions hooked by the malware

Then the malware communicates with the C2 (moonsand[.]store) over HTTPS, sending a Base64-encoded JSON request containing the fields Pid, HWID, and Build. In response, it receives a JSON payload containing the Wait flag. If this flag is set to true, the malware initiates periodic USB device scans filtered by VID and PID (Vendor and Product ID). Upon detecting a connected Trezor or Ledger hardware wallet, it invokes the hooked functions to display a hard‑coded phishing page designed for seed phrase recovery, with a distinct layout used for each identified wallet. If the Wait flag is set to false, the phishing page is displayed immediately.

When the seed phrase is entered and validated, the JavaScript code of the page outputs the phrase to the console prefixed with @:app:print. This prefix helps identify the malware messages in the hooked function mal_LogConsoleMessage.

Phishing pages for seed phrase recovery
Phishing pages for seed phrase recovery

The obtained seed phrase is subsequently sent to the C2 server within a JSON payload containing fields such as App (ledger or trezor), Build, DeviceName, DeviceHardwareId, and SeedData. Furthermore, an identical JSON, encrypted with the RC4 algorithm using the HWID as the key, is saved in a temporary directory under the filename sh_<ts>.json, where <ts> is the file creation timestamp.

MC Keylogger


This module is a keylogger that, in addition to recording user input, performs three malicious activities:

  1. Clipboard logging: periodically checks various clipboard formats, including CF_HDROP for files dragged between windows, CF_DIB for copied bitmap images, and CF_UNICODETEXT for Unicode text. Each format is handled appropriately, and all copy events are logged under the Clipboard section. Text data is written directly to the log, while copied files are recorded by their file paths. Images are saved as JPG files following the naming pattern bf_YYYY-MM-DD hh_mm_ss.jpg, and the path to the saved image is added to the log.
  2. Logging connected devices: logs information about USB devices connected to the system, including hardware characteristics like VID, PID, manufacturer, and other details.
  3. Screenshot creation: creates a screenshot every five minutes with a name in the format sc_YYYY-MM-DD hh_mm_ss.jpg. A corresponding message is recorded in the log under the Screenshot section, including the path to the screenshot.

Thus, the keylogger creates three types of different file artifacts, which are placed in a temporary directory. Below is an example of a log file generated by the keylogger.

Example of the keylogger log file
Example of the keylogger log file

OkoSpyware


This module, which we dubbed OkoSpyware, captures both keystrokes and the video stream of the target application’s window. It first compiles a list of over 100 executable names, including cryptocurrency wallet applications (such as Exodus or Litecoin QT), password managers (such as KeePassXC or 1Password), and other widely used applications, to identify which processes should be monitored among all active system processes. For each identified process, the module uses a bundled FFmpeg instance to capture an MP4 video of the window while concurrently logging keystrokes within that window. The resulting video file is saved in %TEMP% as media_<ts> (where <ts> is the recording’s start timestamp). In the same folder, a JSON file named oko_<ts>.json is created, containing metadata about the captured stream, such as the process name, intercepted input, the stream’s MD5 hash, and additional details.

Example of an OkoSpyware metadata file
Example of an OkoSpyware metadata file

The malware also monitors the state of browsers, and when the window title matches a specified regular expression — for instance, a MetaMask or Tonkeeper wallet extension page — it performs video recording and input logging, adding the window title value to the corresponding field in the JSON metadata file.

Artifacts exfiltration


The TookPS script launched via a scheduled task receives a PowerShell exfiltration script as its payload from the C2. All files created by the MC Keylogger and OkoSpyware are sent to the C2 server to the endpoint ir-post.php. After that, the files are deleted from the victim’s system and a command history file, ConsoleHost_history.txt, is cleared.

Sequential exfiltration of artifacts from the temporary directory
Sequential exfiltration of artifacts from the temporary directory

Victims


At the time of writing, we have detected hundreds of victims of the OkoBot campaign in more than 25 countries, with the largest proportion of attacked end users found in Brazil, Vietnam, Canada, Mexico, and Türkiye.

Distribution of users attacked by OkoBot by country, April 2025–June 2026 (download)

Attribution


At the time of writing, we can’t attribute this malicious campaign to any known crimeware actor. However, during the analysis, we observed that the servers hosting the PowerShell scripts used in the initial infection stage implement server-side geoblocking. When attempting to retrieve the malicious script using an IP from Russia or CIS countries, the server returns an empty response. This technique is very popular among Russian-speaking threat actors.

It was previously mentioned that the campaign uses the malicious Rilide extension, an infostealer that is actively spreading on Russian-speaking, invitation-only cybercrime forums. Additionally, the source code of the SeedHunter phishing pages includes comments in Russian.

Conclusion


The framework described here has numerous modules — mostly written in C and C++ — that are obfuscated and use a variety of packing techniques. Across all stages, specific patterns and techniques can be identified that are borrowed and used in other modules, which allows us to conclude that there is a close interconnectedness among all stages, forming a full‑fledged high‑level framework. Overall, these modules enable a wide range of functions, such as collecting local files, executing remote commands, downloading arbitrary browser extensions, and stealing crypto wallets.

The OkoBot campaign has been ongoing for over a year, and it remains active at the time of publication. Moreover, it is adapting, which indicates that this framework is being maintained and distribution campaigns continue.

Indicators of compromise


Additional information about this threat, with a comprehensive IoC list and decryption scripts, is available to customers of the Kaspersky Threat Intelligence Reporting service. Contact: intelreports@kaspersky.com.

Dispatcher


B07D451EE65A1580F20A784C8F0E7A46 # protobuf.dll
187A1F68AE786E53D3831166DC84E6D2 # protobuf.dll
D84E8DC509308523E0209D3CD3544619 # protobuf.dll
83E6B8FCB92A0B13E109301F8FF649CF # version.dll

Plugins


7306885BB4C98F2A9F056104CF092BC9 # PowerShell wrapper
B4C2E16CDB513BE4DC798F88E2527334 # CMD wrapper
2157D2429124AD28DB7A26F2477CB985 # Environment enumerator
77CECF5E2A622AE07D8AE9913457AB57 # Dropper
E0C3BC27A65750E740C4F1719E531C7D # Process injector

Injector payloads


3D2B43F91F65BFBF36A9C71B6B418876 # ext_daemon.exe
70FEF9FD6E351F4D53CFEEE8DCDFCD99 # seedhunter_x64.exe
ACD31C9941B6C1CABD4E45E6877B9038 # keylog_x64.dll
DD52F5108A176C62AD807C327734AD12 # oko.dll

SSH bot utilities


AC93A821617AEA1F56D4BC0BEF4AF327 # HDUtil.exe
11DBC8A2BEA04B15F8F68F3F01E8FAF9 # extl.exe

File paths


%USERPROFILE%\.ssh\go.bat
%PROGRAMDATA%\HDVideo\HDUtil.exe
%PROGRAMDATA%\hwid.dat
%PROGRAMDATA%\oko_ver
%TEMP%\extl.exe
%APPDATA%\hwid.dat

Domains and IPs


2baserec2[.]guru # TookPS
recavb22[.]online # TookPS
kbeautyreviews[.]com # TookPS
coffeesaloon[.]online # TookPS
104.243.43[.]16 # SSH bot
104.243.32[.]213 # SSH bot
62.210.188[.]209 # SSH bot
livewallpapers[.]online # Volume2 C2
thatwascringe[.]com # Volume2 C2
moonsand[.]store # SeedHunter C2


securelist.com/okobot-framewor…

Cybersecurity & cyberwarfare ha ricondiviso questo.

La Francia dice addio a Windows: la sovranità digitale passa da Linux 🇫🇷🐧


The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

La Francia ha deciso di accelerare la migrazione della pubblica amministrazione da Windows a Linux: entro l'autunno tutti i ministeri dovranno presentare un piano di transizione, coinvolgendo fino a 2,5 milioni di postazioni di lavoro. L'obiettivo è chiaro: ridurre la dipendenza dalle Big Tech statunitensi, riprendere il controllo dei propri dati e costruire una vera sovranità digitale europea.

Questa non è solo una scelta tecnologica. È una scelta politica.

Ogni euro investito nel software libero resta sul territorio, rafforza competenze locali, aumenta trasparenza, sicurezza e indipendenza. Mentre molti continuano a parlare di autonomia digitale, la Francia inizia a metterla in pratica.

L'Europa ha bisogno di più Linux, più software libero e meno dipendenza dai monopoli digitali.

La sovranità digitale non si compra: si costruisce. Seguici e partecipa al nostro Digital Indipendence day✊🐧


A novembre arriva in Italia il primo Digital Independence Day!


Per la prima volta il Digital Independence Day arriva in Italia. L’appuntamento è fissato per il 13 e 14 novembre a Bolzano all’interno di SFSCON, probabilmente la più importante conferenza italiana dedicata al Software Libero che ogni anno riunisce un migliaio fra sviluppatori, aziende, attivisti, pubbliche amministrazioni, associazioni e comunità open source provenienti da tutta Europa.

L’iniziativa è organizzata da Fedimedia, l’associazione italiana che riunisce amministratori del Fediverso, attivisti del software libero, sviluppatori e operatori che ogni giorno realizzano servizi concreti per ridurre la dipendenza dalle Big Tech.

Un movimento europeo per l’indipendenza digitale


Il Digital Independence Day non è un semplice evento, ma fa parte di un movimento europeo nato per promuovere una cultura della libertà digitale.

L’obiettivo è semplice quanto ambizioso: dimostrare che esistono già oggi alternative concrete ai grandi servizi centralizzati. Social network federati, cloud personali, sistemi operativi liberi, strumenti di collaborazione, servizi di traduzione, videoconferenze, posta elettronica, mappe, repository di codice e decine di altre tecnologie permettono di utilizzare Internet senza affidare ogni aspetto della propria vita digitale a poche multinazionali.

Ogni mese la rete europea del Digital Independence Day promuove oltre 300 eventi tra incontri pubblici, workshop, install party, conferenze, laboratori e momenti di formazione, coinvolgendo cittadini, scuole, associazioni e amministrazioni pubbliche.

L’edizione italiana rappresenta quindi l’ingresso del nostro Paese in una rete internazionale che considera la sovranità digitale non come uno slogan, ma come un percorso concreto fatto di tecnologia, formazione e comunità.

Perché parlare di indipendenza digitale


Negli ultimi anni milioni di persone hanno affidato comunicazioni, documenti, fotografie, relazioni sociali e perfino il proprio lavoro a un numero sempre più ristretto di piattaforme.

Questa concentrazione porta con sé diversi problemi:

  • raccolta massiva dei dati personali;
  • profilazione commerciale;
  • dipendenza da servizi proprietari;
  • difficoltà nel cambiare piattaforma;
  • perdita di controllo sui propri contenuti;
  • crescente utilizzo di algoritmi opachi e sistemi di intelligenza artificiale centralizzati.

L’indipendenza digitale non significa rifiutare la tecnologia, ma riappropriarsi della possibilità di scegliere strumenti aperti, interoperabili e rispettosi della libertà degli utenti.

SFSCON: il punto di riferimento del Software Libero in Italia


A ospitare il primo Digital Independence Day italiano sarà SFSCON, la storica conferenza internazionale di Bolzano dedicata al Software Libero che da anni rappresenta uno degli appuntamenti più importanti in Europa con più di 1000 partecipanti ad edizione.

L’evento riunisce sviluppatori, ricercatori, aziende, pubbliche amministrazioni, studenti e comunità open source provenienti da tutta Europa, affrontando temi come:

  • software libero;
  • open data;
  • sicurezza informatica;
  • pubblica amministrazione digitale;
  • infrastrutture aperte;
  • sovranità tecnologica.

Portare il Digital Independence Day all’interno di SFSCON significa creare un ponte tra il mondo dello sviluppo del software libero e quello degli utenti, delle associazioni e delle comunità che ogni giorno utilizzano queste tecnologie.

Fedimedia: costruire alternative, non solo raccontarle


A promuovere l’iniziativa è Fedimedia, associazione nata per mettere in rete le realtà italiane che lavorano ogni giorno per costruire un ecosistema digitale indipendente.

Fedimedia riunisce amministratori di server del Fediverso, associazioni, sviluppatori, divulgatori e attivisti che gestiscono servizi basati esclusivamente su software libero.

Tra questi figurano piattaforme Mastodon, PeerTube, Matrix, Pixelfed, lemmy, Forgejo, Nextcloud, LibreTranslate e numerosi altri servizi che permettono a cittadini, associazioni e organizzazioni di utilizzare strumenti aperti senza dipendere dalle Big Tech.

L’obiettivo dell’associazione è favorire la collaborazione tra gli operatori del settore, condividere competenze tecniche e diffondere una cultura dell’autonomia digitale attraverso eventi, formazione e supporto reciproco.

Di cosa parleremo nel Digital Indipendence day a Bolzano il 13-14 novembre?


La sovranità digitale e l’indipendenza tecnologica dalle Big Tech: storie, esperienze e soluzioni per costruire un’Europa più libera, aperta e consapevole. Un percorso tra progetti, comunità e strumenti che stanno già rendendo possibile un ecosistema digitale più autonomo, trasparente e rispettoso dei diritti delle persone: di.day

Un invito a tutta la comunità


Il Digital Independence Day italiano non vuole essere solo un punto di incontro per chi sviluppa software libero, per chi amministra infrastrutture, ma è dedicato alla grande comunità di persone e che semplicemente desidera capire come ridurre la propria dipendenza dalle grandi piattaforme digitali.

Non sarà una conferenza tecnica, ma un luogo dove ritrovarsi dal vivo, confrontarsi su come costruire un ecosistema digitale più aperto, decentralizzato e sostenibile. E sopratutto riuscire a ritrovarsi anche dal vivo almeno una volta e conoscere chi amministra le grandi piattaforme delfediverso italiano, discutere e migliorarsi insieme.

Perché la vera innovazione non consiste nel creare nuovi strumenti proprietari online, ma nel restituire alle persone il controllo della propria tecnologia con software realmente libero ed europeo.

Il 13 e 14 novembre, a SFSCON, l’Italia entrerà ufficialmente nella rete europea del Digital Independence Day. Un primo passo per dimostrare che un’informatica più libera non appartiene al futuro: esiste già oggi, grazie al lavoro di comunità, sviluppatori e volontari che ogni giorno costruiscono alternative concrete alle Big Tech.

Un’iniziativa libera, indipendente e costruita dalla comunità


C’è un aspetto che rende il Digital Independence Day diverso da molte altre manifestazioni dedicate alla tecnologia.

L’iniziativa è totalmente indipendente: non è sponsorizzata da aziende, non ha investitori alle spalle, non è uno strumento di marketing e non nasce per promuovere un prodotto o generare profitti.

È un movimento dal basso, nato in Germania e diffusosi rapidamente in tutta Europa grazie al lavoro di associazioni, volontari, comunità locali, sviluppatori e attivisti che condividono un obiettivo comune: restituire alle persone il controllo della propria vita digitale.

Fedimedia aderisce a questo movimento europeo portandone per la prima volta l’esperienza in Italia, mantenendone lo stesso spirito: collaborazione, condivisione della conoscenza, software libero e indipendenza dalle grandi piattaforme.

Crediamo che la sovranità digitale non possa essere venduta come un prodotto. Deve essere costruita insieme, attraverso comunità aperte, tecnologie libere e persone disposte a condividere competenze ed esperienze.

Unisciti al movimento


Se credi anche tu che sia arrivato il momento di costruire un’alternativa concreta alle Big Tech, e creare una reale sovranità digitale europea puoi partecipare fin da oggi:

💬 Entra nei nostri gruppi:

Telegram
t.me/+y61epDtOmy80NWE0

Matrix
matrix.to/#/%23fedimedia:mozil…

🤝 Oppure entra a far parte di Fedimedia inviando la tua richiesta di iscrizione:
cloud.mastodon.uno/apps/forms/…

Vuoi seguire un intervento?


Il programma del Digital Independence Day è ormai quasi completo e nelle prossime settimane pubblicheremo l’elenco dei relatori.

Se però vuoi avere un’anteprima di quello che verrà presentato a Bolzano il 13 e 14 novembre, c’è il canale peertube del DIgital Indipendence Day..

📧 Contattaci all’indirizzo email info@fedimedia.it oppure su mastodon o telegram per ogni informazione sul Digital Indipendence Day.

L’indipendenza digitale non si costruisce insieme, condividendo conoscenze, creando servizi liberi, aiutando le persone ad abbandonare le piattaforme proprietarie e dimostrando che un’altra Internet non solo è possibile, ma esiste già.


Questa voce è stata modificata (1 mese fa)

Hacking Around the Financial Pain of New 3DS XL Top Screens


The media in this post is not displayed to visitors. To view it, please log in.

With Nintendo’s 3DS experiencing a bit of a renaissance lately, prices for functioning systems have shot through the roof. Getting a busted one with a broken screen is a lot cheaper, but then you run into the eye-watering price difference between a replacement top screen for the regular version and the larger XL variant. The latter costs about the same as a whole new used 3DS, while the former goes for peanuts. Here the solution is obvious, with [Skawo] demonstrating how they hacked the cheaper, smaller top screen into a New 3DS XL.

The price difference on AliExpress as shown in the video is on the order of $120, with the smaller screen going for less than $10. Since they both use the same connector pin-out and display technology, you can plug either display into the New 3DS XL mainboard.

Where you’ll run into issues, other than the replacement display being obviously not XL, is the physically shorter flat flex cable for the controls that forces the display to be installed in an offset manner. You need jailbroken firmware like Luma3DS here to adjust for the screen offset. Filling in the missing screen real-estate is the other issue you have to patch over somehow, which was done here in barbaric fashion with some cardboard.

Beyond that it does work, and as a fix to at least get a broken New 3DS XL back into the game it’s worth considering. Do note that there’s a difference between regular 3DS and New 3DS (second generation) screens with neither being compatible, so be careful before you try such a fix.

youtube.com/embed/UjJDxgVC6-c?…


hackaday.com/2026/07/15/hackin…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#SonicWall warns of active exploitation of two SMA 1000 zero-days
securityaffairs.com/195364/hac…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

☕ CYBERBRIEFING — Mercoledì 15 luglio 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

371 – CI STANNO OBBLIGANDO AD ADDESTRARE CHI CI LICENZIERÀ camisanicalzolari.it/371-ci-st…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

#ESETresearch discovered and reported to @certcc 11 old Microsoft-signed UEFI shim bootloaders that allow bypassing UEFI Secure Boot on most UEFI systems. Read about it at welivesecurity.com/en/eset-res…
Tracked by #CVE-2026-8863 and #CVE-2026-10797, all these vulnerable shims were revoked in Microsoft’s June Patch Tuesday updates.

cve.org/CVERecord?id=CVE-2026-…

cve.org/CVERecord?id=CVE-2026-…
Exploiting these vulnerable shims allows execution of untrusted code at system boot by using the Bring Your Own Vulnerable Driver (#BYOVD) technique, enabling deployment of malicious UEFI bootkits on systems that trust the Microsoft Corporation UEFI CA 2011 certificate.
What makes these old shims dangerous is not a novel vulnerability, it’s that no new vulnerability is needed to bypass Secure Boot. Just an old, still-trusted, unrevoked shim and basic knowledge of how UEFI works is enough to bypass UEFI Secure Boot and deploy a UEFI bootkit.
For more details and instructions on how to verify that the dbx patches were properly applied on your system, read our blogpost:
welivesecurity.com/en/eset-res…

reshared this

in reply to .mau.

Mi sa che sono stato troppo oscuro, mi spiego meglio: se invece che la regola "3n+1" avessimo "3n-1", o "4n+1" o qualcosa di simile, il comportamento della successione non sarebbe così interessante. È un po' come con Life: un'altra scelta dei parametri di nascita/sostentamento/morte non porta a nulla di interessante, e mi pare di avere letto che Conway ci abbia studiato un po' prima di trovare la giusta via.
Cybersecurity & cyberwarfare ha ricondiviso questo.

«Il Dipartimento di Stato degli Stati Uniti sta ora offrendo sovvenzioni fino a 3 milioni di dollari a gruppi allineati al movimento MAGA in Europa, scrive il Financial Times.
Quindi fammi capire...
Putin conduce una guerra in Europa. Questo costringe l'Europa a comprare armi dagli Stati Uniti. Trump aggiunge un margine del 10% su quelle armi per riempire le sue casse. Poi spende soldi in Europa per far avanzare gruppi che siano pro-Putin. In breve: gli Stati Uniti stanno combattendo attivamente contro il mondo democratico spingendo il progetto di Putin nei paesi che combattono il progetto di Putin».

mastodon.social/@randahl/11692…


The US state department is now offering grants of up to $3 million to MAGA-alligned groups in Europe, writes FT.

So let me get this straight…

Putin wages a war in Europe. That forces Europe to buy weapons from the US. Trump ads a 10 percent markup on those weapons to fill his coffers. He then spends money on advancing groups in Europe that are pro Putin. In short: The US is actively fighting against the democratic world by pushing the Putin agenda in countries fighting the Putin agenda.


Questa voce è stata modificata (1 mese fa)

AIM-ing For a More Open Platform Than Discord


The media in this post is not displayed to visitors. To view it, please log in.

The OpenOscar Server in terminal, with Pidgin connected

Do you remember AIM? It may suprize you to hear that AOL’s instant messanger was actually supported all the way up to 2017– two years after Discord launched. Unlike Discord, AIM is a protocol, not a platform. Everything on your favourite Discord server is at the mercy of the corporate masters of said server; you can’t just spool up your own. Not so for AIM, as [Veronica] explains, both on her blog and in a YouTube video that we’ve embedded below.

The key is the fact that the AIM protocol isn’t locked into AOL’s now-defunct servers; it was reverse engineered in its prime for open-source messengers like Pidgin. You can host your own server, too, using the OpenOscarServer by [mk6i]. Even better, it’s not just AIM, but ICQ! In the sort of irony you only get in real life, the OpenOscar community does all its support on a Discord server. But then, they couldn’t hardly do it over AIM or ICQ these days.

For those of you who were too old or too young to get sucked into the 90s instant messenger craze, these protocols don’t just create chat rooms, that would be the even older Internet Relay Chat protocol, but usually worked more like SMS text messages. You have a contact list, and you send messages to your contacts via a server that acts as a hub. Once upon a time, that server was AOL’s, but now thanks to the OpenOscar project, it can be anybody’s computer. Of course, like texting, you can rope all of your contacts into one big group chat, and the protocol does support images and VOIP. (Which is starting to sound a lot like Discord.)

If you’re tired of your friend-group being at the mercy of American tech companies, [Veronica]’s blog post serves as a good guide to get you started running OpenOscarServer on a Linux system; she used a virtual private server but figures a Raspberry Pi ought to have enough grunt if you don’t have a huge number of people signed up.

For completeness, we should mention that while AOL pulled the plug on AIM nearly a decade back, ICQ, the other protocol supported by OpenOscarServer, lasted straight through until 2024.

Thanks to Keith Olson for the tip! Our tipsline is based on decentralized “electronic mail” technology that anyone can access.

youtube.com/embed/VDQTuJWST4M?…


hackaday.com/2026/07/14/aim-in…