Cybersecurity & cyberwarfare ha ricondiviso questo.

Ho fatto parte di #Assoli (Associazione per il Software Libero) per anni, si parla di un tempo in cui la dominanza di applicazioni proprietarie inibiva ogni speranza di opernsourcismo.

Oggi l'open source è uscito dalla nicchia dei geek e le applicazioni che vengono sviluppate sono privacy focused by design e pensate per un utilizzo proprio AKA senza pagare per tenere i dati sul cloud degli altri.

Self hosting, open source e privacy costituiscono una triade che funziona e che va diffusa.


@AAMfP @pondolo @datak @andre123
Capisco la titubanza nel proseguire a cambiare la mentalità della massa ma io ci sto provando con ufficio zero dove uno degli sponsor é Infomaniak e quando utilizzi ufficio zero puoi creare facilmente una loro casella mail… noi attivisti facciamo passi piccoli ma conta essere sempre costanti. Forza e coraggio che non sei solo 💪😉

Clay Extruder Enables Printable Pottery


The media in this post is not displayed to visitors. To view it, please log in.

A clay vase sits in the center of a circular table, with an extruder in contact with the top surface. The extruder has a tube containing clay on the right side, with a motor mounted above an auger over the main nozzle.

Ceramic 3D printers, despite using the same fundamental mechanism as standard FDM printers, are much harder to find. Part of this comes down to the material properties of fired ceramics versus thermoplastics, but they’re also significantly harder to build; for example, in his ceramic printer build, [Joshua Bird] had to deal with severe material shrinkage, collapsing bridges, and the surprisingly abrasive effects of clay.

The centerpiece of the printer is the clay extruder: an air compressor pushes clay along a tube into the extruder, which uses an auger to squeeze the clay through the nozzle, while a gap at the top lets trapped air escape. The extruder has enough control for successful retractions, but rheology remained a challenge: the clay needed to be soft enough to flow through the nozzle, but stiff enough to form bridges without collapsing. [Joshua] thus pressurized the clay as much as possible, making it possible to use stiffer clay mixtures. The extruder’s greatest challenge was longevity: [Joshua] tried many 3D-printed plastic augers, but the clay abraded them all much too quickly, often in under an hour of use; a 3D-printed stainless steel extruder solved this.

Printing in ceramic isn’t a simple process: for each part, [Joshua] had to mix the clay, load it into the tube, clean the extruder, actually print the object, let it dry, fire it, apply glaze, and fire it again. The clay’s shrinkage during drying and firing destroyed many prints, but [Joshua] was nevertheless able to print a double-walled cup, a decorative climbing-themed cup, and even a chain-mail mesh.

The 3D printer’s motion system is a polar design, an adaptation of his earlier non-planar 3D printer, which might eventually make it easier to print overhangs. We’ve previously seen a similar auger-based clay extruder, an approach reminiscent of direct-granule FDM printing.

youtube.com/embed/ajfrOBs_mNk?…


hackaday.com/2026/07/11/clay-e…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#ChatControl 1.0: il giorno buio della democrazia autoritaria europea. Un'analisi prospetticamente ampia a cura di @lastknight

«Andiamo con ordine, perché in questa storia ci sono due scandali intrecciati: quello che la legge permette di farvi, e il modo in cui è stata fatta risorgere.»

mgpf.it/2026/07/11/chat-contro…

@privacypride

Cybersecurity & cyberwarfare ha ricondiviso questo.

Il Telefono Non Deve Sapere. Il post di Andrea Amani

Mettiamo che sia passata. L'Europa ha smesso di somigliare a se stessa, e la legge che per anni era stata respinta di misura adesso e' in vigore: ogni dispositivo legge quello che scrivi e quello che leggi, prima che venga cifrato, e lo riferisce. Signal non ti salva, WhatsApp nemmeno. Quando il regime controlla il telefono, controlla il chiaro. La difesa non e' un'app da scaricare. E' spostare la cifratura fuori dal telefono, e lasciare al telefono solo un mestiere: trasportare buste sigillate di cui non puo' leggere il contenuto.

pinperepette.github.io/signal.…

@Privacy Pride

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Robot umanoidi in Coppa del Mondo: la sfida tecnologica che cambia il futuro

📌 Link all'articolo : redhotcyber.com/post/robot-uma…

A cura di Silvia Felici

#redhotcyber #news #robotica #intelligenzaartificiale #coreadelsud #robocup #competizionerobotica

A Look Inside a 1997 BBC Ceefax Generator


The media in this post is not displayed to visitors. To view it, please log in.

Ceefax was the BBC’s broadcast teletext service that ran until 2012, providing text and rudimentary graphics that were broadcast invisibly with the TV signal. In order to get this teletext data merged into the analog TV signal, special equipment was needed, of which [Nathan Dane] has a 1997-era unit on his bench to take a gander at.

Interestingly, until this time the Ceefax signal had been generated centrally in London, meaning that regional TV broadcasts might have Ceefax issues on occasion due to retransmission glitches. This makes this Ceefax Inserter system so much more interesting, as it was one of the early examples of what these regional stations would end up installing in their racks.

At their core these units are regular PCs, running MS-DOS 6.22 on a 486-class CPU and all the typical bits and bobs that go with a PC. The speculation here is that these are essentially rebranded industrial PCs, which would make a lot of sense. As for how [Nathan] got his hands on these units, it required a deal with the company scrapping them, preventing him from showing details of the software configuration.

Following a booting demonstration, we get the teardown of a typical 1990s rackmount PC, revealing a rather interesting backplane with the mainboard being one of the cards on it. Of these, two ISA cards provide the special Ceefax sauce as well as a timing signal in the form of a PDC card featuring a Lattice CPLD or FPGA that VCRs could use to automatically start recording.

The Ceefax main event comes in the form of the inSERT Teletext Encoder card. This is pretty much its own computer system, featuring a TI TMS34010 CPU and its own RAM as well as IO. Compared to modern takes on teletext generators, this card appears to directly mix the analog signals, without any kind of conversion.

Although teletext systems have been largely shutdown now at this point due to the transition to digital TV broadcasting, there’s still a lot to be said for having such a service available for basic news and information.

youtube.com/embed/myqe_EYdZJY?…


hackaday.com/2026/07/11/a-look…

Cybersecurity & cyberwarfare ha ricondiviso questo.

☕ CYBERBRIEFING — Sabato 11 luglio 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

Cybersecurity & cyberwarfare ha ricondiviso questo.

A ennesima dimostrazione che i parlamenti funzionano bene se noi cittadini VOTIAMO CON CRITERIO.
Se votiamo a cazzo o se non votiamo, invece...


Ecco perché sono contento che l'Europa abbia approvato #Chatcontrol

Ieri non poteva andare peggio, ma domani sì. Eppure stavolta, nel momento più buio, riesco a vedere una luce nuova

informapirata.it/2026/07/10/ec…

@privacypride


reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Giuseppe Giulietti:

«Alla vigilia della legge elettorale truffa, nel pieno della compravendita dei quotidiani più importanti, si vogliono colpire e imbavagliare le ultime trasmissioni non allineate.
Report è un problema sulla via della riconferma della maggioranza di governo, perché non tace su nulla e su nessuno. Non possono lasciarlo procedere, neanche in replica».


#politica @politica

poliverso.org/display/0477a01e…

Questa voce è stata modificata (1 mese fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Ricordiamoci chi sono e facciamo in modo di non eleggerli mai più.

#politica @politica

poliversity.it/@nuke/116890207…


Il dettaglio italiano della votazione odierna sulla Proposta di rifiuto di Chat Control.

Dovremo ricordarci sempre di tutte le persone che ci rappresentano a favore di questa porcheria (quindi contrarie al rifiuto)

dariofadda.it/chat-control/202…

#stopchatcontrol


in reply to Jhyrachy

@jhyrachy Dobbiamo fare quello che possiamo con gli strumenti che abbiamo. La nostra Costituzione è un gioiello, altrettanto lo è la nostra partecipazione. Ci sarà sempre almeno una lista che non contenga nessuna di quelle persone.
Non lasciamoci convincere da chi, per poter fare i propri comodi, cerca di farci credere che sia inutile.

@politica

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

367 – OPENAI E ANTHROPIC NON RIESCONO A STARE A GALLA camisanicalzolari.it/367-opena…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Il computer quantistico non cercherà i tuoi dati: cercherà le tue credenziali

📌 Link all'articolo : redhotcyber.com/post/il-comput…

A cura di Luigi Zullo

#redhotcyber #news #crittografia #sicurezzainformatica #computerquantistici #cybersecurity

Fixing the Fix for a 3dfx Voodoo Card’s Overly Bright Picture


The media in this post is not displayed to visitors. To view it, please log in.

After previously fixing an overly bright picture from a Voodoo graphics card with a simple resistor on one of the RAMDAC’s pins to correct its faulty internal Vref, [Bits und Bolts] got called out for not taking component drift into account. Thus in an update video he shows how instead to use an adjustable AMS1117 voltage regulator to hopefully prevent either the original issue or something new and exciting from cropping up later.

The basic idea here is to use the external voltage reference (Vref) pin for this ICS5342 RAMDAC and supply it with a constant 1.235V. If unused – as on this Orchid-branded Voodoo card – it is connected via an 0.1 microFarad capacitor to ground. This fortunately means that the pin is routed to easily accessible pads that make this modification relatively straightforward.

Basically this is where the AMS1117-ADJ chip comes into the picture, as a widely available adjustable LDO option, even if the 0.8A current rating is very much overkill for this application. With the supplied voltage the lowest voltage this LDO can output is around 1.25V, which is within the 1.10 – 1.35 V range of the datasheet.

Of course, with the PCB never having had a provision for this part, much of the rest of the video is about planning out where to place and route the components. After that tedious work and testing that nothing explodes, the new voltage is used for the RAMDAC’s Vref pin, fixing the brightness issue.

While one could argue that this RAMDAC is likely simply defective and already beginning to break down inside, this should at least give it a bit longer on what seems to be a little used card anyway.

youtube.com/embed/QQEO4e0rt2g?…


hackaday.com/2026/07/10/fixing…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

L’AI entra nella lista dei rischi nazionali: la mossa del Vietnam sorprende tutti

📌 Link all'articolo : redhotcyber.com/post/lai-entra…

A cura di Carolina Vivianti

#redhotcyber #news #intelligenzaartificiale #vietnam #dirittiumani #rischioalto #settoristrategici

reshared this

Reject Modernity, Return to 80s, Learn C.


The media in this post is not displayed to visitors. To view it, please log in.

We’re not exactly sure how old [SnailMail] is, but he’s probably a member of Generation Alpha considering that to our wizened eyes the lad looks only slightly older than a fetus– which makes it all the more impressive that he’s written his own text editor, from scratch, in C– on a 386. See, [SnailMail] tried to learn the modern way, with IDEs that have code completion and AI integration, but his thoughts couldn’t gel in the modern environment. So he went online and bought an old IBM-compatible complete with monochrome amber monitor, and a whole 4MB of RAM. Big spender that he is, [SnailMail] upgraded that to 8MB.

Rather than fall victim to the siren song of Wolfenstien 3D or SimCity, he set out to learn to code: C, specifically, since that language bridges four decades between [SnailMail] and his new PC. Even more specifically, he got ahold of disks for Borland Turbo C and Turbo C++, which brings back memories for some of us. Of course the lad also had to learn how to use a DOS PC at the same time, but a teen in the 80s with a fresh box would have climbed the same steep learning curve. Some of you probably remember doing so yourselves. Just like you–or the hypothetical teen in the 80s–[SnailMail] did it not by googling or begging Claude for answers, but by digging into books. Many books.

After all the reading, he started with a text editor, something we remember being a pretty big project not given to first year students. Video evidence suggests he pulled it off. He describes how his solution works from about 8:00 in the video, so you greybeards in the audience can judge his work for yourself.

If you’re a member of Gen Alpha reading this and looking to learn to program, we cannot recommend this technique highly enough– [SnailMail] is going to have a better understanding of the underlying logic of computer science than a lot of CS grads being frocked today. Especially when you consider he ends by promising to learn assembly, something we heartily endorse.

youtube.com/embed/I7CeqmFiWYY?…


hackaday.com/2026/07/10/reject…

Documenting the IR Protocol of the PumpSaver Plus Device


The media in this post is not displayed to visitors. To view it, please log in.

Having a pump in a remote location where you aren’t constantly monitoring it is a common scenario, which can be unfortunate when said pump runs into problems like a dry well, jammed impeller or power issues. This is where pump monitors like the older SymCom (now Littelfuse) PumpSaver Plus 233P will protect the pump if such conditions are detected. Of course, the infrared communication port on it uses an undocumented protocol that was meant to be used with a long-since discontinued handheld device. Ergo [Elizabeth Camporeale] saw fit to reverse-engineer this protocol.

In the installation manual for this device this Informer unit is briefly mentioned along with the information it will display on its screen, making it clear that it’s quite literally just there to act as a display for the information that’s constantly generated on this interface. Naturally, this is incredibly useful if you wish to tie the system into a wider monitoring and automation system.

Somewhat unusual, this IR interface on the used 233P-1.5 unit turned out to be use a 5,000 baud NRZ, MSB-first protocol, with the juicy details fully documented and a Python-based decoder implementation provided.

Naturally [Elizabeth] didn’t just reverse-engineer this for the fun of it, but also for ESPHome integration. This uses a setup as can be seen in the top image, with an ESP32-C6 module providing the processing power and Wi-Fi, with a standard phototransistor recording the data pumped out by the pump monitor.


hackaday.com/2026/07/10/docume…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Rientrato da un Meraviglioso @devconf

La Conferenza Biennale dedicato allo Sviluppo Open Source!

Le Emozioni sono state tante, i colleghi, il calore delle persone, le bellissime idee condivise, lo spirito partecipativo, il pubblico incredibile!

È stato un momento di ritrovo magico e stimolante come mai ho avuto modo di sperimentare prima.

Inoltre è stata una emozione incredibile riuscire ad avere tra il pubblico il personale docente e tecnico dell'università di Pavia (università davvero incredibile per spazi e competenze tecniche).

Non posso fare altro che ringraziarvi infinitamente per avermi regalato emozioni costanti e momenti di coinvolgimento davvero incredibili.

Un Grazie anche a @BoostMediaAPS e a tutti i suoi soci presenti presenti assieme a me, per averci dato la possibilità di realizzare qualcosa di davvero bello e unico in Italia. Abbiamo finalmente dimostrato che possiamo avere una conferenza di livello senza importarla dall'estero!

Presto vi farò avere lo spezzone del mio intervento, nel frattempo vi invito a recuperare l'intera diretta sul canale YouTube dell'Associazione:"BoostMedia APS"

Adesso ci avanti tutta per l'organizzazione del @fossday pronti per un'altra incredibile avventura.

Grazie ancora 🙏🏻 siete tutti incredibilmente meravigliosi!

#DevConf #Linux #FOSS #OpenSource

in reply to Lorenzo DM

solo a pensare a come mi é venuta in mente l’idea rabbrividisco perché so che sognare ed osare sono possibili ma che altri soci sono probabilmente folli quanto me ed oggi questa follia ci ha portato a concludere un evento pronto per essere ripetuto tra 2 anni.

La diversità di pensiero è un tema che mi appassiona e proprio da questo ed altre motivazioni sono stato spinto a riflettere su come poteva essere il @devconf nel nostro paese: non talk di Max 13 min, non solo chiacchiere ma progetti reali già operativi e funzionanti e funzionali come ha detto anche @stefano nel suo intervento per la comunità.

Oggi lasciamo in eredità al popolo sano dell’open source un altro pezzo di storia e di codice, ma domani saremo già proiettati su altro, sempre per coloro che credono sia possibile utilizzare prodotti open💪

Solo un folle, anticonformista, va contro le masse e continuerò a farlo nonostante i miei bei gufi che adoro.

In punta di piedi, passo dopo passo, continueremo ad avanzare certi di riuscire nel nostro intento: far appassionare più persone all’open 😎.

Il treno va verso la prossima fermata e voi ci sarete?

Cybersecurity & cyberwarfare ha ricondiviso questo.

Gravissimo: per colpire le fake news di Russia Today, la Corte di Giustizia dell'Unione Europea vieta a tutti i cittadini di diffondere i contenuti dal proprio blog

@Politica interna, europea e internazionale

Una recentissima e importante sentenza emessa dalla Corte di Giustizia dell'Unione Europea (causa C-67/25), pubblicata proprio nei primi giorni di luglio 2026 affronta l'applicazione e l'estensione delle sanzioni europee contro i media statali russi nel contesto del conflitto in Ucraina, in particolare la rete Russia Today (RT).

Il caso d'origine


- Il procedimento nasce da una vicenda avvenuta in Germania, dove tre individui erano stati accusati penalmente per aver caricato e diffuso ripetutamente e gratuitamente video provenienti dal canale sanzionato RT Germany su un sito internet ad accesso libero, finanziato solo da donazioni.

Il fulcro legale (chi sono gli "operatori"?)


- I difensori sostenevano che il divieto europeo di diffusione si applicasse solo ai grandi operatori commerciali o televisivi, e non a privati cittadini senza scopo di lucro. Il giudice tedesco ha quindi chiesto il parere vincolante della Corte UE.

La decisione della Corte di Giustizia


- La Corte ha stabilito che il divieto è totale e si applica a chiunque. Il termine "operatore" comprende qualsiasi persona (fisica o giuridica) che metta a disposizione i contenuti vietati, indipendentemente dal fatto che lo faccia gratis, a pagamento, per hobby o in modo amatoriale.

La motivazione strategica


- La Corte ha praticamente blindato le sanzioni per evitare "scappatoie". Se si fosse consentito ai singoli siti gratuiti di ridistribuire la propaganda russa, l'efficacia delle sanzioni dell'Unione Europea volte a tutelare l'ordine pubblico e la sicurezza nazionale sarebbe stata completamente vanificata.

Le ricadute sugli utenti dei social


- Estendendo la definizione di "operatore" a chiunque metta a disposizione i contenuti sanzionati, la Corte ha di fatto cancellato la distinzione tra grandi media e utenti privati.

Responsabilità penale o amministrativa individuale


- Fino ad oggi, molti utenti pensavano che il divieto di trasmettere i canali di Stato russi (come Russia Today o Sputnik) riguardasse solo le compagnie televisive, i provider Internet (ISP) o le grandi piattaforme. Con questa sentenza, se un privato cittadino scarica un video di RT e lo ricarica sul proprio profilo Facebook, su X, su un canale Telegram o su un blog amatoriale, commette un illecito. A seconda delle leggi del proprio Stato membro (come il caso della Germania che ha dato origine alla sentenza), l'utente rischia procedimenti penali o pesanti sanzioni amministrative.

Fine dell'esimente del "No-Profit" o del "Piccolo Canale"


- La Corte ha esplicitamente chiarito non sono fattori esimenti né l'assenza di lucro (non importa se il video viene condiviso gratuitamente, per hobby o senza monetizzazione), né la portata della diffusione (si è perseguibili anche se il video viene visto da poche decine di persone e non si è un "influencer") né la durata) anche una condivisione temporanea o di breve durata rientra nella violazione)

La fine della libertà di espressione


- La libertà di condivisione sui social incontra un limite legale rigidissimo. Per l'utente comune diventa tassativo evitare tassativamente di ripubblicare, caricare o redistribuire materiali video, audio o articoli provenienti direttamente dalle emittenti governative russe colpite dalle sanzioni UE

curia.europa.eu/site/upload/do…

in reply to The Pirate Post

Beh, il concetto è lo stesso di quello riguardante la diffusione di materiale protetto da copyright. Che esso sia diffuso mediante una grande piattaforma web oppure un forum di un gruppetto di amici, comunque accessibile, non fa differenza. L'unica scappatoia potrebbe essere quella di contestualizzare il contenuto (ad es. mostrandolo come esempio di propaganda filorussa) come potrebbe fare una testata giornalistica, coi limiti del caso (es. riproduzione parziale).
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Ecco perché sono contento che l’Europa abbia approvato Chatcontrol

Ieri non poteva andare peggio, ma domani sì. Eppure stavolta, nel momento più buio, riesco a vedere una luce nuova
informapirata.it/2026/07/10/ec…

Questa voce è stata modificata (1 mese fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

Update Now: Critical #Zimbra Classic Web Client Flaw Could Expose Mailboxes
securityaffairs.com/195130/hac…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

#Chatcontrol: l'epifania dell'Unione europea.
Epifania significa "manifestazione" - in questo caso non della natura divina di Gesù ma della natura profana, e autoritaria, della suddetta unione.

Però qui sotto si può vedere anche la fotografia della Befana che a Mark Zuckerberg porta doni e a tutti gli altri porta via diritti costituzionalmente protetti.


Ecco perché sono contento che l’Europa abbia approvato Chatcontrol

Ieri non poteva andare peggio, ma domani sì. Eppure stavolta, nel momento più buio, riesco a vedere una luce nuova
informapirata.it/2026/07/10/ec…


How To Use Those Cute But Slightly Odd 7-Segment LCDs


The media in this post is not displayed to visitors. To view it, please log in.

If you’re not aware, there is such a thing as adorable little three digit LCD 7-segment displays. They come in a ten-pin DIP package and are just begging to be integrated into a project. The catch is they are just a tiny bit weird. Luckily for us all, [Nagy Krisztián] spells out exactly how to use them.

The first odd thing about these ten-pin LCD displays have a footprint that doesn’t quite mesh with standard 0.1 inch spacing, meaning they will not cleanly fit into a breadboard. Luckily, one can solve this with a bit of force. It’s a small part, and the pins don’t seem to mind.
These little LCDs are adorable, but a bit unusual to interface with.
The second odd thing is wrapping one’s head around the pin mapping. Figuring out which pins activate which segments in the digits is easier if one keeps in mind that each segment of each digit is the product of two different pins. For example, “2A” is digit two, segment A, and is the product of pins 3 and COM4.

That’s not all. Electrically speaking, driving this LCD isn’t nearly as straightforward as an LED.

With an LED display, the COM pins are either common anode or common cathode, which tells one whether lighting up a segment means holding the COM pin at GND with voltage applied to the segment pin, or the other way around. But in the case of this LCD display, the polarity applied is swapped every cycle. Oh, and inactive COM pins need to held at half-voltage. Neat!

[Nagy] drives the whole thing with little more than an ATtiny84 microcontroller and a few resistors. A switchable half-voltage signal is cleverly created by combining a simple voltage divider and taking advantage of the fact that the ATtiny84’s pins can be in one of three different states depending on how they are configured: high, low, or high-impedance (pin configured as an input). Each COM pin on the display gets connected to both an ATtiny84 pin, and to the supply voltage via two resistors forming a voltage divider. When the ATtiny drives the pin high, the LCD pin sees about 3 V. When the pin is driven LOW, the LCD pin sees 0 V. When the ATtiny configures the pin as an input, the LCD pin receives about 1.5 V.

The bulk of the software is defining which pins and states equal which digits, and cycling the LCD at a rate of vaguely 60 Hz which delivers flicker-free results.

We appreciate the clever combination of voltage divider with pin configuration to create three switchable voltage levels. If you liked that and want to see more serious leveraging of pin configuration on a microcontroller, check out how to drive seven LEDs with only two pins.


hackaday.com/2026/07/10/how-to…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Addio chiavette USB e ISO! Windows 11 cambia tutto: il PC si reinstalla da solo dal cloud

📌 Link all'articolo : redhotcyber.com/post/addio-chi…

A cura di Luca Galuppi del gruppo DarkLab

#redhotcyber #news #windows11 #cloudrebuild #microsoft #sistemaoperativo #cloud #reinstallazione

reshared this

Robot Dog in Browser


The media in this post is not displayed to visitors. To view it, please log in.

You’ve doubtlessly seen the current crop of robot dogs and, if you are like us, thought about getting one to play with. The problem is that the cheap ones are toys, and the serious ones cost serious money. But now you can experiment with a mid-range cost one for free in your browser. The sponsor will be happy to sell you a robot in kit or assembled form, although it is the OpenCat robot (we’ve covered it before), so you could simply build a real one yourself if you wanted to.

The code is all in a Web-based IDE, and the main file is deceptively simple. However, the real work is in read_serial (in the src/moduleManager.h file, for some reason) and reaction in the aptly-named src/reaction.h file. If you just want to play, you can use the buttons in the simulator or enter serial commands (documented elsewhere). For example, ksit will make the dog sit down.

You can change as much code as you like. You might consider starting simple and just sending commands programmatically, but you can dive as deep as you like. Press compile up at the top right, and it will load and run your code in the virtual robot. If you run it off the desk (of course, we did), you can reset and try again.

Here’s a quick example to get you started:

//***********************
#define BITTLE // Petoi 9 DOF robot dog: 1 on head + 8 on leg

#define BiBoard_V1_0
//***********************

#include "src/OpenCat.h"

void setup() {
Serial.begin(115200); // USB serial
Serial.setTimeout(SERIAL_TIMEOUT);

while (Serial.available() && Serial.read())
; // empty buffer

Serial.println("Hello Hackaday!");
initRobot();
}

unsigned int loopct=0;
unsigned int phase=0;

#define cmdtokenEOF 0xFFFF

// commands (token + argument)
char *cmd[] =
{
"sit", // good boy
"up", // stand up
"bf", // back flip
"ff", // forward flip
"EOF" // string doesn't matter here
};

unsigned int cmdtoken[] = {
T_SKILL,
T_SKILL,
T_SKILL,
T_SKILL,
cmdtokenEOF
};

#define LOOPDELAY 1000 // number of loops between actions

void loop() {
// This code runs repeatedly
// Put any change here if you want to change behaviors
if (loopct % 1000 == 0 )
{
loopct=0;
if (cmdtoken[phase]==cmdtokenEOF) phase=0;
strcpy(newCmd,cmd[phase]);
token=cmdtoken[phase++];
newCmdIdx=1;
}
loopct++;

reaction();
}

The robot is better than the cheap toys, but it still lacks many sensors. You can add on a few simple sensors that appear to mount in the dog’s mouth, or you can replace its head with an arm if you opt for beefy enough servos.

Of course, we’ve seen plenty of robot dogs. We want one, but we don’t know what we’d do with it. Any ideas?


hackaday.com/2026/07/10/robot-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The endless long tail of the post-quantum transition includes: Apple Business encrypts FileVault recovery keys to a customer-generated RSA public key.

There's a literal "openssl req -newkey rsa:2048" in the docs.

support.apple.com/guide/busine…

in reply to Filippo Valsorda

> to a customer-generated RSA public key.

What if this public key is secret?

I assume Apple infrastructure will not publish public keys of their customers, current infrastructure passes those certificates over the PFS link, then future infrastructure will link over the ML-* secured connection. Am I mistaken?

What if ed25519 public key is secret? Do we have quantum attacks that can target the signature having no access to formerly "public" key?

😀)

Cybersecurity & cyberwarfare ha ricondiviso questo.

Ecco perché sono contento che l'Europa abbia approvato #Chatcontrol

Ieri non poteva andare peggio, ma domani sì. Eppure stavolta, nel momento più buio, riesco a vedere una luce nuova

informapirata.it/2026/07/10/ec…

@privacypride

in reply to Paolo Redaelli

@paoloredaelli @andre123 @datak @juliandv @AAMfP @pondolo
Per l'uso che ne faccio (sostituto del DTP) le cose che mi mancano sono:

1. Bilanciamento automatico delle colonne (ora lo fai con il colbreak a mano)
2. Nel caso di layout a 3 colonne, spread su 2 colonne.
3. Linee di testo allineate alla griglia

Per il resto l'ho usato anche per fare layout abbastanza complessi senza troppa fatica (xoxarle.itch.io/vecchia-scuola e qui: xoxarle.itch.io/breathless-srd… )

Hackaday Podcast Episode Ep 377: Parallel Pixels, Wiggly Consoles, and Seven Segments


The media in this post is not displayed to visitors. To view it, please log in.

This week’s podcast sees Elliot joined by Jenny List, as both suffer silently in the European summer heat because the sound of a desk fan would come over on the recording.

A stand-out hack of the week comes from [Bitluni], whose GPU made from thousands of cheap microcontrollers is on a scale we’ve never seen before. It’s an amazing project in itself, but the manufacturing and power consumption issues of so many processors running at the same time make for a discussion of their own.

Otherwise, we have diecasting on the bench, an impressive achievement by any measure, a Raman spectrometer, and an open source take on something like a Kei truck. In quick hacks there’s a dicussion of soldering versus crimping for high current connectors, and neon tubes used as digital logic in an organ. The recording finishes with a discussion of 7-segment display history, and whether an engineering education teaches design for manufacture.

html5-player.libsyn.com/embed/…

Or download it yourself, in glorious 192-bit MP3.

Where to Follow Hackaday Podcast

Places to follow Hackaday podcasts:



Episode 377 Show Notes:

Mailbag:


  • We were contacted by long-time listener [Alex], with a question about the deadline for What’s That Sound entries. The podcast is recorded on Thursday evening European time, most of the time, but Wednesday evening when Tom is onboard. If you get your entry in by Wednesday morning, wherever you are, you’re safe. Good luck!
  • Then we had a couple of responses to Zoe Skyforest’s pitot tube air speed sensor piece. Reese Johnson suggested that some version of this might be found in motorcycle fuel gauges, and Jeff told us about very similar differential pressure airflow sensors being used in the climate control systems of large buildings. So we’re closer than we think to these devices.


What’s that Sound:



Interesting Hacks of the Week:



Quick Hacks:



Can’t-Miss Articles:



hackaday.com/2026/07/10/hackad…

in reply to Cybersecurity & cyberwarfare

Hello, my name is Alene Stahl.

Are you looking to increase your podcast's visibility and reach a wider audience on Apple Podcasts? My podcast promotion service can help you grow your audience, increase downloads, and improve your podcast's ranking.

How I Promote Podcasts

* Social media advertising (Standard/Premium Packages)
* Facebook and Instagram ads
* Google Ads campaigns
* Social media posting and direct outreach
* Promotion through Twitter, Facebook, and Instagram
* Email marketing for every new episode
* Cross-promotion with other podcast hosts

Benefits of My Service

✔ 100% organic, real human traffic
✔ Quick growth in subscribers and listeners
✔ Increased popularity and improved rankings
✔ High-quality podcast advertising
✔ Safe and authentic audience engagement

Why Choose Me?

✔ Build your listener base organically
✔ Reach more podcast enthusiasts naturally
✔ 100% safe and secure promotion methods
✔ SEO-friendly strategies
✔ Social media-driven traffic
✔ 100% satisfaction guarantee

If you have any questions, please feel free to contact me.

Thank you, and have a wonderful day!

Alene Stahl

Se il Garante privacy non risponde, che si fa? Ecco cosa dice la Cassazione


@Informatica (Italy e non Italy)
La Corte di Cassazione con una recente sentenza torna sulla questione concernente la natura dei termini entro i quali l’Autorità Garante per la protezione dei dati deve rispondere. Se il Garante non risponde, per le organizzazioni è un problema. Ecco le regole

3D Printed Scooter Fits in Your Luggage, Some Assembly Required


The media in this post is not displayed to visitors. To view it, please log in.

Though [Ivan Miranda] calls the 3D printed vehicle in his recent video a motorbike, what he ultimately pulls out of his suitcase is clearly a scooter. Linguistic confusion aside, the “Mirandetta” looks like an awesome build and pulling a scooter out of your suitcase and whizzing past everyone in the taxi line just sounds amazing, especially knowing you made it yourself.

Aside from a whole lot of filament, he’s got a couple of tool batteries for hot-swappable energy that Airport security shouldn’t mind too much — provided you carry them with you, anyway — plus the usual e-bike motor and electronic speed control you might expect, and lawnmower tires which you might not. The narrow 3D printed rims round over the normally-flat tires to make them usable for this application. He seems particularly taken with the bi-stable mechanism he built for the kickstand, and we can’t blame him as we love seeing that kind of thing ourselves. The TPU seat is also a nice touch to keep with ‘everything printed’ vibe.

Now while the finished product does indeed fit into his suitcase, it needs to be completely disassembled. Well, unless you have an over-sized suitcase, perhaps. So our dreams of zooming away from the luggage line from the first paragraph were perhaps a bit premature. Still, from the footage at Prague Maker Faire at the end of the video, it looks like it was a fun enough ride that we can forgive [Ivan] for our overactive imaginations.

If you want an open-source e-bike, we’ve seen those too — but that won’t fit in any kind of suitcase.

youtube.com/embed/CH65FIqxGEI?…


hackaday.com/2026/07/10/3d-pri…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

17 foto al giorno da migrare.. magari per la fine dell'estate ce la faccio 🙂‍↔️

#Pixelfed (sì, mi va bene pure mezzo rotto, ma IG deve morire); peccato perdere le date perché non funziona l'import.. la prima foto, lassù, è del maggio 2012.

Sensori, droni e AI: la nuova architettura di difesa della NATO sul fianco Est


@Informatica (Italy e non Italy)
Una rete digitale coprirà quasi 2.600 chilometri, per collegare satelliti, droni, radar, sensori terrestri e sistemi di tecno sorveglianza lungo l'intero fianco orientale europeo. Ecco i dettagli della difesa della NATO per rilevare e bloccare un

This Week in Security: Escaping Linux VMs, Vulnerable Solar, Confusing AI (Again), and Confusing NPM Malware


The media in this post is not displayed to visitors. To view it, please log in.

The Januscape vulnerability allows a user in a guest VM managed by the Linux Kernel Virtual Machine (KVM) to corrupt memory in the host system and break out of isolation.

KVM virtualization is used by major hosting platforms like Amazon AWS, Google GCP, Digital Ocean, and many more. All of the shared hosting platforms count on virtualization to isolate untrusted guest systems from the physical hardware and each other; being able to corrupt memory for all guests or break isolation presents a major threat.

The bug report says the error has been present for 16 years, which is nearly the entire lifetime of the KVM subsystem in Linux. Fixes are available in mainline, and major hosting providers who count on KVM are likely already updating.

Vulnerabilities In Balcony Solar


Micro solar, or “balcony solar”, installs have been gaining traction in Europe as a way to offset rising electrical costs by connecting solar and battery systems to a house or apartment power system.

Vulnerabilities have been found in the popular Hoymiles micro-inverter, which uses a proprietary RF radio protocol to manage the devices. Unfortunately, it looks like this protocol has no encryption or authentication beyond validating the serial number, and the serial number is also available over a wireless probe command.

Armed with a Nordic nRF radio researchers were able to discover nearby inverters in the wild and collect the serial numbers, though of course they stopped short of issuing commands to random users.

The wireless management control allows controlling the device power and output levels, as well as setting a lockout PIN, which the researchers suspect could be used to disable devices and lock the legitimate owners out completely.

There are an estimated 500,000 units in use, and currently the only known mitigation is to unplug the device entirely and disconnect the solar panels, though the team suggests that setting an anti-theft PIN may also help – or at least prevent an unknown PIN being set.

Be sure to check out the link for an in-depth analysis of the protocol and the surprising lack of protection.

OpenSSH 10.4


OpenSSH 10.4 is out, bringing a handful of security fixes and new features.

The most interesting security fixes appear to be to file handling in the sftp and scp file transfer tools, a malicious remote server could cause the files to be downloaded to the wrong directories. Besides those, the security fixes seem relatively calm, making behavior more consistent when forwarding and tunneling options were in conflict, mitigating a potential denial of service, and cleaning up other behavior.

OpenSSH 10.4 introduces some experimental support for additional post-quantum encryption standards, but beyond that seems to be a normal update.

Tenda Routers (may) Have Backdoor


According to CVE-2026-11405, Tenda brand routers may have a deliberate backdoor in the web interface.

The vulnerability report claims that the httpd binary contains a fallback to a plaintext, hardcoded password that allows anything on the internal network to bypass authentication and reconfigure the router. This seems entirely plausible, based on issues found in other router firmwares, however additional reports raise doubts about the pervasiveness of the backdoor, or if it exists in all firmware versions.

If you have a Tenda brand router and are so inclined, now might be a great time to investigate OpenWRT or other alternate, updated firmware, but there’s probably not a reason to panic just yet.

Tricking the GitHub Agent With Prompt Injection


Can we go a week without discussing prompt injection in AI agents? Apparently the answer is no.

Noma Labs reveals how they were able to use prompt injection against the GitHub support agent to reveal private repositories of an organization. Leveraging the GitHub Agentic Workflows that link workflows with AI agents, Noma Labs were able to file an issue in a public repository that exposed private repositories in the same organization.

The attack appears to be as simple as filing an issue in the public repo, and requesting the contents of files in both the public and private repo, which the agent happily provided. Not only did the AI agent provide the file content of private repos, but it put it in a public issue in the public repository!

Noma Labs says in the writeup that GitHub had instituted guardrails to prevent an agent from accessing private repositories, but simply including the request to “additionally” perform other tasks was sufficient to bypass. This makes GitHub the latest in a seemingly endless chain of AI agents happily helping bypass corporate security, and it doesn’t seem like a trend that will slow down for a while.

Windows Device Identifier Catches Ransomware Operator


Windows installs contain a globally unique identifier generated during the initial install, which is used to track device behavior across Microsoft platforms. Toms Hardware reports that during an investigation of the “Scattered Spider” ransomware group, Microsoft provided records tracking the GDID of one of the ransomware operators, allowing the identification and arrest of one of the groups members.

Scattered Spider has been responsible for millions of dollars in ransomware attacks globally, including high-profile ransomware attacks against major Las Vegas resorts, Qantas airlines, Visa, and hundreds of other companies.

Court documents reveal that following the arrest of one of the suspected members of the group, the Windows global ID was used to link other behavior across Azure, video games, and other telemetry.

CISA reviews lessons learned


Mentioned here in May, the US government cybersecurity agency (CISA) suffered a disclosure of authentication tokens, cloud infrastructure, and plaintext passwords via a public GitHub repository named “Private-CISA” and operated by a contractor.

CISA has published the results of their internal review. Unsurprisingly, as a large government agency, CISA essentially followed the playbook for dealing with incidents: identify the most critical issues and disable the access of the contractor who exposed credentials, determine the full scope of disclosed data, and terminate accounts, change passwords, and expire authentication tokens which were exposed.

More NPM malware packages


Opensource Malware reports on additional infostealer malware uploaded to the NPM repository. Like most NPM-based malware, these packages rely on the install script mechanism to trigger arbitrary commands, firing immediately during package install with no additional interaction.

All of the malware packages mimic existing popular packages and depend on user typos or confusion to get selected. Once triggered, the malware collects a machine fingerprint, git user information, GitHub account information, SSH account information, and corporate identifiers. The packages are largely nonfunctional – the code in the package itself is irrelevant, once a victim triggers the install the malware payload is fired.

All of the packages were uploaded by the same source, tracked to the owner of a cybersecurity company. It is unclear if this is a misguided attempt to generate leads or hype, or if this is a research project gone wrong, but the payload of the malicious packages has been developed and tuned over time. For a company trying to build a reputation or trust, this is surely the wrong way to do it.


hackaday.com/2026/07/10/this-w…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Network Bonding su Linux: guida completa a ridondanza e throughput aggregato
#tech
spcnet.it/network-bonding-su-l…
@informatica


Network Bonding su Linux: guida completa a ridondanza e throughput aggregato


Perché il bonding delle interfacce di rete è ancora rilevante


Una singola scheda di rete è un punto singolo di fallimento. Su un server di produzione, un cavo che si stacca, una porta dello switch che si guasta o un driver che va in crash possono bastare per portare giù un servizio. Il network bonding su Linux (noto anche come NIC teaming o link aggregation) risolve il problema aggregando due o più interfacce fisiche in un’unica interfaccia logica gestita dal kernel: bond0. A seconda della modalità scelta, si ottiene ridondanza, throughput aggregato maggiore, oppure entrambi.

Non è una tecnologia nuova, il driver bonding è nel kernel Linux da anni, ma resta uno degli strumenti più sottoutilizzati nella cassetta degli attrezzi di chi amministra server fisici, hypervisor o anche semplici home lab. Vediamo come funziona davvero, quali modalità scegliere e come configurarlo con gli strumenti che si trovano oggi sulle distribuzioni più diffuse.

Bonding non è bridging


Prima di entrare nella configurazione, vale la pena chiarire un equivoco comune: il bonding non è la stessa cosa del bridging. Un bridge collega segmenti di rete distinti, permettendo al traffico di attraversare due reti separate. Il bonding, invece, aggrega più interfacce fisiche facendole apparire al sistema operativo e alle applicazioni come un unico dispositivo di rete. Sono strumenti diversi, per scopi diversi, e vanno configurati in modo diverso.

Un altro equivoco frequente riguarda la banda: il bonding non raddoppia automaticamente il throughput di una singola connessione TCP. La maggior parte delle modalità distribuisce connessioni multiple su interfacce diverse, non spezzetta un singolo trasferimento su tutti i link contemporaneamente. Il guadagno di banda aggregata si ottiene quando più flussi sono attivi in parallelo, non con un singolo trasferimento di file.

Va inoltre notato che le interfacce WiFi generalmente non sono compatibili con il bonding: la maggior parte dei driver wireless non supporta la modalità promiscua e la manipolazione dell’indirizzo MAC richieste dal driver bonding. Il bonding va quindi limitato a interfacce Ethernet cablate.

Le modalità di bonding: quale scegliere


Il driver bonding del kernel Linux supporta sette modalità. Per la maggior parte degli scenari operativi ne bastano tre o quattro:

  • Mode 0 (balance-rr): round-robin, trasmette i pacchetti in sequenza su tutte le interfacce. Offre load balancing e fault tolerance, ma richiede un gruppo di aggregazione statico configurato correttamente sullo switch. Senza questo, si ottengono pacchetti fuori ordine e prestazioni scadenti.
  • Mode 1 (active-backup): una sola interfaccia attiva alla volta; se quella attiva si guasta, subentra la backup. Non richiede alcuna configurazione sullo switch. È la modalità più sicura e compatibile, ideale quando l’obiettivo è puramente la ridondanza.
  • Mode 2 (balance-xor): selezione dell’interfaccia basata su un hash degli indirizzi MAC sorgente e destinazione. Load balancing per connessione e fault tolerance, richiede supporto dello switch.
  • Mode 3 (broadcast): trasmette ogni pacchetto su tutte le interfacce contemporaneamente. Usata raramente, solo in scenari di fault tolerance molto specifici.
  • Mode 4 (802.3ad / LACP): link aggregation dinamica secondo lo standard IEEE 802.3ad. Richiede uno switch gestito con LACP abilitato. È la modalità più usata in ambito enterprise: se lo switch la supporta, è la scelta corretta per la produzione.
  • Mode 5 (balance-tlb): load balancing adattivo del traffico in uscita in base al carico corrente su ciascuna interfaccia; il traffico in ingresso arriva sull’interfaccia attiva corrente. Non richiede configurazione dello switch.
  • Mode 6 (balance-alb): come mode 5, ma bilancia anche il traffico in ingresso tramite negoziazione ARP. Non richiede switch gestito e offre buoni guadagni di throughput, anche se alcuni switch e ambienti virtualizzati gestiscono il bilanciamento basato su ARP in modo incoerente: va testato prima di affidarcisi in produzione.

Per un homelab o un setup semplice senza switch gestito, Mode 1 (failover puro) o Mode 6 (bilanciamento senza configurazione switch) sono le scelte pratiche. Per server di produzione con switch gestito, Mode 4 (LACP) è la strada corretta.

Prerequisiti


Servono almeno due interfacce di rete fisiche (o virtuali, in una VM), accesso root o sudo, il modulo kernel bonding e uno strumento di gestione della rete (NetworkManager, systemd-networkd o Netplan, a seconda della distribuzione).

Verificare che il modulo bonding sia disponibile:

modinfo bonding

Se restituisce le informazioni del modulo, si può procedere caricandolo:
sudo modprobe bonding

Prima di modificare qualsiasi configurazione, è indispensabile identificare le interfacce disponibili:
ip link show

Sui sistemi moderni i nomi saranno del tipo enp3s0, enp4s0, oppure i più tradizionali eth0, eth1. Annotarli, perché verranno referenziati per tutta la configurazione.

Metodo 1: NetworkManager (desktop e la maggior parte dei server moderni)


Su Ubuntu, Fedora, Debian con NetworkManager, o qualunque distribuzione desktop, questo è l’approccio più semplice, grazie al supporto per il bonding consolidato da anni tramite nmcli.

Creare l’interfaccia bond:

sudo nmcli con add type bond con-name bond0 ifname bond0 bond.options "mode=active-backup,miimon=100"

Aggiungere le interfacce fisiche come slave del bond:
sudo nmcli con add type ethernet slave-type bond con-name bond0-slave1 ifname enp3s0 master bond0
sudo nmcli con add type ethernet slave-type bond con-name bond0-slave2 ifname enp4s0 master bond0

Assegnare un indirizzo IP statico al bond:
sudo nmcli con modify bond0 ipv4.addresses 192.168.1.100/24 ipv4.gateway 192.168.1.1 ipv4.dns 1.1.1.1 ipv4.method manual

Oppure, per usare il DHCP:
sudo nmcli con modify bond0 ipv4.method auto

Attivare il bond:
sudo nmcli con up bond0

Le interfacce slave dovrebbero attivarsi automaticamente. In caso contrario, portarle su manualmente:
sudo nmcli con up bond0-slave1
sudo nmcli con up bond0-slave2

Verificare lo stato del bond:
cat /proc/net/bonding/bond0

Il file /proc/net/bonding/bond0 è lo strumento diagnostico principale: va consultato ogni volta che qualcosa non sembra funzionare come previsto.

Metodo 2: systemd-networkd (server e installazioni minimali)


Su server senza NetworkManager, systemd-networkd gestisce il bonding in modo pulito. Creare il file netdev del bond:

sudo nano /etc/systemd/network/10-bond0.netdev
[NetDev]
Name=bond0
Kind=bond

[Bond]
Mode=active-backup
MIIMonitorSec=100ms
UpDelaySec=200ms
DownDelaySec=200ms

Creare la configurazione di rete per l’interfaccia bond (esempio DHCP):
sudo nano /etc/systemd/network/20-bond0.network
[Match]
Name=bond0

[Network]
DHCP=yes

Vincolare le interfacce fisiche al bond, un file per ciascuno slave:
sudo nano /etc/systemd/network/30-bond0-slave1.network
[Match]
Name=enp3s0

[Network]
Bond=bond0

Riavviare systemd-networkd e verificare:
sudo systemctl restart systemd-networkd
cat /proc/net/bonding/bond0

Metodo 3: Netplan (Ubuntu Server)


Ubuntu Server 18.04 e successivi usano Netplan come layer di configurazione di rete predefinito. Editare il file (di solito /etc/netplan/01-netcfg.yaml):

network:
  version: 2
  renderer: networkd
  ethernets:
    enp3s0:
      dhcp4: no
    enp4s0:
      dhcp4: no
  bonds:
    bond0:
      interfaces:
        - enp3s0
        - enp4s0
      addresses:
        - 192.168.1.100/24
      routes:
        - to: default
          via: 192.168.1.1
      nameservers:
        addresses:
          - 1.1.1.1
      parameters:
        mode: active-backup
        mii-monitor-interval: 100
        primary: enp3s0

Applicare la configurazione:
sudo netplan apply

Se si sta lavorando da remoto, Netplan offre una modalità di test sicura che ripristina automaticamente la configurazione precedente dopo 120 secondi se non viene confermata:
sudo netplan try

Per usare LACP, basta modificare il blocco parameters:
parameters:
  mode: 802.3ad
  lacp-rate: fast
  mii-monitor-interval: 100
  transmit-hash-policy: layer2+3

Metodo 4: LACP (Mode 4) con switch gestito


Con uno switch gestito che supporta LACP, Mode 4 vale la configurazione aggiuntiva: si ottiene link aggregation reale con negoziazione dinamica. Sul lato switch, le porte interessate vanno configurate come LAG (Link Aggregation Group) con LACP abilitato: su Cisco il comando è channel-group X mode active; sulla maggior parte degli switch gestiti consumer c’è una sezione LAG o Trunk nell’interfaccia web.

Sul lato Linux, l’unica differenza rispetto al Metodo 1 sono le opzioni del bond:

sudo nmcli con add type bond con-name bond0 ifname bond0 bond.options "mode=802.3ad,miimon=100,lacp_rate=fast"

La policy transmit-hash-policy: layer2+3 distribuisce il traffico basandosi sia sull’indirizzo MAC sia sull’IP, offrendo una distribuzione del carico migliore rispetto alla policy predefinita solo layer2.

Attenzione: se si abilita LACP sul lato Linux ma lo switch non è configurato di conseguenza, il bond torna a usare un solo link attivo. Non va in errore, ma non si ottiene alcuna aggregazione: va sempre configurato prima lo switch.

Testare il failover


Con il bonding in active-backup configurato, si può simulare un guasto e osservare il recupero. In un terminale, avviare un ping continuo verso il gateway:

ping 192.168.1.1

In un altro terminale, disattivare l’interfaccia attiva:
sudo ip link set enp3s0 down

Si osserveranno al massimo uno o due pacchetti persi, poi il traffico continuerà a fluire attraverso l’interfaccia di backup. Verificare lo stato del bond:
cat /proc/net/bonding/bond0

La riga Currently Active Slave mostrerà il passaggio alla seconda interfaccia. Per impostare un’interfaccia primaria preferita:
sudo nmcli con modify bond0 bond.options "mode=active-backup,miimon=100,primary=enp3s0"

Comandi utili per il monitoraggio

# Stato del bond in tempo reale
watch -n 1 cat /proc/net/bonding/bond0

# Traffico sull'interfaccia bond
sudo iftop -i bond0

# Stato IP e link
ip addr show bond0
ip link show bond0

# Conteggio dei fallimenti di link (utile per individuare cavi difettosi)
grep "Link Failure Count" /proc/net/bonding/bond0

Se il contatore dei fallimenti su una sola interfaccia cresce mentre il sistema funziona normalmente, probabilmente c’è un cavo o una porta dello switch difettosa: conviene sostituirli prima che il guasto si presenti nel momento peggiore.

Problemi comuni e soluzioni

Il bond non ha IP dopo il riavvio


Probabilmente le interfacce slave vengono attivate prima che il bond sia inizializzato. Con systemd-networkd, i numeri più bassi vengono processati per primi: assicurarsi che il file netdev (10-bond0.netdev) abbia un numero inferiore rispetto ai file network degli slave. Verificare anche che il modulo si carichi al boot:

echo "bonding" | sudo tee /etc/modules-load.d/bonding.conf

Solo uno slave risulta attivo anche in round-robin o LACP


Lo switch non è configurato per il LAG. Configurarlo correttamente, oppure passare a Mode 1 o Mode 6, che non richiedono configurazione dello switch.

I drop di ping durante il failover durano più del previsto


Abbassare il valore di miimon (l’intervallo di polling predefinito è 100ms):

bond.options "mode=active-backup,miimon=50,updelay=100,downdelay=100"

updelay e downdelay prevengono il flapping su link instabili: impostarli ad almeno il doppio del valore di miimon.

Conclusione


Il network bonding è una di quelle funzionalità che sembrano complicate finché non si mettono effettivamente in pratica. Il modulo kernel è già presente nella maggior parte delle distribuzioni, la configurazione è lineare, e il risultato è concreto: failover a downtime quasi zero, throughput aggregato maggiore, o entrambi, a seconda della modalità scelta.

Per chi non ha certezze su quale modalità scegliere, Mode 1 è il punto di partenza più sicuro: non richiede configurazione dello switch, funziona ovunque e il failover è quasi istantaneo. Si può poi passare a Mode 4 con LACP quando si dispone di uno switch gestito e si desidera una vera link aggregation. In entrambi i casi, /proc/net/bonding/bond0 resta lo strumento diagnostico di riferimento: va controllato dopo il setup, dopo ogni modifica, e ogni volta che qualcosa sembra non funzionare come dovrebbe.

Fonte: LinuxBlog.io


Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

NetScaler MCP Gateway: Citrix mette ordine nel traffico degli agenti AI aziendali
#tech
spcnet.it/netscaler-mcp-gatewa…
@informatica


NetScaler MCP Gateway: Citrix mette ordine nel traffico degli agenti AI aziendali


Il problema: agenti AI che parlano con troppi sistemi, senza controllo


Il Model Context Protocol (MCP) si sta affermando rapidamente come lo standard con cui gli agenti AI aziendali si collegano a strumenti, database e sistemi interni. È comodo: un agente può interrogare un CRM, aprire un ticket, leggere un repository Git o lanciare una pipeline, tutto attraverso lo stesso protocollo. Il problema è che questa comodità sta creando, nella maggior parte delle aziende, un far west di endpoint MCP sparsi, ciascuno con la propria autenticazione, i propri permessi e nessuna visibilità centralizzata.

Gartner stima che il 60% dei proof-of-concept di GenAI venga abbandonato dopo il completamento, principalmente per mancanza di governance, controlli di rischio inadeguati e dati non pronti per l’AI. Citrix ha deciso di attaccare esattamente questo problema estendendo NetScaler, la sua piattaforma di application delivery e sicurezza, con una nuova funzionalità chiamata MCP Gateway.

Cos’è NetScaler MCP Gateway


MCP Gateway trasforma NetScaler in un punto di ingresso unico e governato per tutto il traffico MCP dell’organizzazione. Invece di lasciare che ogni team gestisca in autonomia i propri server MCP, con metodi di autenticazione diversi e nessun log centralizzato, il gateway instrada dinamicamente le richieste verso i server MCP approvati, applicando policy coerenti in un unico punto della rete.

Le funzionalità principali includono:

  • Autenticazione centralizzata e granulare: token per utente e token globali, flussi OAuth e ibridi, rate limiting a livello di singolo tool e liste di allow/block per i server, così da impedire agli agenti di raggiungere endpoint non approvati o di generare carichi di richieste incontrollati.
  • Affidabilità per i workflow multi-step: la persistenza di sessione e un monitoraggio “protocol-aware” mantengono l’agente collegato al backend corretto e verificano che i server MCP restino sani durante flussi di lavoro lunghi e articolati.
  • Model routing e visibilità sui consumi per il traffico LLM: instradamento basato su content switching e tracciamento dell’uso a livello di token, per team, utente o applicazione.

Il tutto sfrutta l’architettura “single-pass” proprietaria di NetScaler, che esegue in un solo passaggio traffic management, autenticazione, routing, ispezione di sicurezza, rate limiting e observability. È una scelta progettuale rilevante: il traffico AI è molto volumetrico sia in termini di dimensioni dei payload che di numero di pacchetti, e concatenare più proxy separati aggiunge hop e latenza esattamente nel punto in cui le performance contano di più.

Governance anche sul lato LLM


Parallelamente al gateway MCP, Citrix ha esteso anche NetScaler AI Gateway, il componente che gestisce il traffico verso i provider LLM. Le richieste in arrivo da agenti e applicazioni possono ora essere instradate verso modelli diversi in base a policy, con tracciamento di token in ingresso e in uscita per team, utente o applicazione. L’obiettivo dichiarato è evitare il vendor lock-in su un singolo provider e responsabilizzare i team sui costi generati dall’uso dell’AI.

Un caso d’uso interessante, in anteprima privata, riguarda l’integrazione con Claude Code: NetScaler AI Gateway agisce da gateway LLM davanti a Claude Code, fornendo un punto di controllo centralizzato per l’accesso ai modelli Anthropic da parte di migliaia di sviluppatori, senza dover applicare l’identità due volte (una lato IdP aziendale, una lato provider AI).

Perché questo interessa a chi gestisce infrastrutture, non solo ai team AI


Per un sistemista o un architetto che ha già affrontato la messa in sicurezza di API gateway e reverse proxy classici, il parallelo con MCP Gateway è immediato: cambia il protocollo, ma la logica di centralizzazione di autenticazione, rate limiting e observability resta la stessa buona pratica che si applica da anni a qualunque superficie di API esposta internamente.

Ci sono almeno tre ragioni pratiche per iniziare a pensarci ora, anche se in azienda gli agenti AI sono ancora in fase pilota:

  • Proliferazione silenziosa degli endpoint. Ogni team che sperimenta con agenti AI tende a esporre un proprio server MCP, spesso senza coinvolgere il team di sicurezza. Senza un punto di controllo centrale, il numero di endpoint cresce più velocemente della capacità di monitorarli.
  • Settori regolamentati. In ambiti come finanza, sanità e pubblica amministrazione, un agente che accede a sistemi con dati sensibili senza audit trail centralizzato è un problema di compliance, non solo di sicurezza tecnica.
  • Il costo nascosto del traffico LLM. Senza tracciamento dei token per team o applicazione, è comune scoprire solo a fine mese quale progetto ha generato la spesa maggiore verso un provider AI.

Come osserva Steve Shah, general manager di NetScaler in Citrix: “non è una questione di se, ma di quando le polizze di cyber-insurance inizieranno a richiedere l’uso di gateway MCP per proteggersi da agenti pericolosi”. È una previsione plausibile: lo stesso percorso è già avvenuto con i Web Application Firewall e, più di recente, con gli API Gateway.

Cosa fare oggi, anche senza NetScaler


Che l’organizzazione adotti NetScaler o un’altra soluzione, i principi di governance restano validi in modo tecnologicamente agnostico:

  • Censire tutti i server MCP attivi in azienda, anche quelli nati come esperimento di un singolo team.
  • Imporre un solo punto di ingresso autenticato per il traffico MCP verso sistemi che trattano dati sensibili, invece di esporre i server direttamente.
  • Applicare rate limiting per tool, non solo per endpoint: un agente compromesso o mal configurato può generare un numero di chiamate ripetute a un singolo strumento capace di saturare un backend anche legittimo.
  • Loggare in modo centralizzato ogni richiesta MCP, per poter ricostruire “chi ha fatto cosa” in caso di incidente, esattamente come si farebbe con un audit log su un database di produzione.


Conclusione


MCP sta diventando, nelle parole di Shah, “la nuova API call” per gli agenti AI aziendali. Ma proprio come le API REST hanno richiesto un decennio per maturare pattern di sicurezza consolidati (OAuth, rate limiting, API gateway centralizzati), anche MCP dovrà attraversare lo stesso percorso, probabilmente in tempi molto più compressi vista la velocità con cui l’adozione dell’AI agentica sta avvenendo nelle aziende. Chi gestisce infrastrutture farebbe bene ad anticipare questa esigenza, piuttosto che rincorrerla dopo il primo incidente.

Fonte: Help Net Security e 4sysops


Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🚨 Microsoft 365 accounts breached through forgotten MFA gaps

Attackers made 81M login attempts in 14 days, compromising 78 accounts across 64 organizations through an ROPC flow excluded from MFA policies.

🔗 read more: www.bleepingcomputer.com/news/securit...

#ransomNews #cybersecurity

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Il #phishing è sempre dietro l'angolo.

Un falso messaggio di DPD mi informa che “Il pacco non può essere consegnato.”
Poi arriva il link per “correggere l’indirizzo”.. 😓

È uno degli SMS di phishing più comuni: il messaggio finge di provenire da DPD, DHL, Poste o altri corrieri e crea urgenza parlando di consegna fallita, deposito locale o restituzione imminente.
E, per la paura di non perdere il pacco, ecco che parte il click selvaggio.

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🚨 nuova rivendicazione #ransomware Italia 🚨

🏴‍☠️ gruppo #TheGentlemen
🧬 Vicenzi S.P.A. | San Giovanni Lupatoto (VR)
🎯 settore: C - Manifatturiero
🔗 vicenzi.it
🗓️ 10 luglio 2026

📄 sample: -
▪️ dati esfiltrati dichiarati: -
▪️ dati esfiltrati pubblicati: -
⏲️ scadenza: 20 luglio 2026

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Il #marketing al passo coi tempi: la busta "microondabile" sdogana l'utilizzo del termine e ne indica perfettamente l'utilizzo - "La busta la puoi mettere nel microonde" è in effetti troppo lungo.

Condizione win-win da manuale.

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Ransomware Never Stopped: Over 9,000 Confirmed Attacks Since 2018
securityaffairs.com/195117/cyb…
#securityaffairs #hacking