reshared this
reshared this
⚠️ WhatsApp voting scam hijacks linked devices
Fake contest links trick victims into approving attacker-controlled sessions.
🔗 read more: www.malwarebytes.com...
WhatsApp account takeover scam...
Scammers are trying to take over WhatsApp accounts by sending messages asking people to vote for a friend in a fake online contest.Pieter Arntz (Malwarebytes)
reshared this
Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals.Pierluigi Paganini (Security Affairs)
Cybersecurity & cyberwarfare reshared this.
If you’ve ever thought about the nomenclature of electrical components, potentiometer stands out as a strange name, etymologically suggesting something like a voltmeter. In fact, the component took its name from a voltage-measuring instrument also named the potentiometer. [Alnwlsn] recently took a look at one such device, which was integrated into a thermometer, and the Weston cell used to calibrate it.
The potentiometer (instrument) has a galvanometer at its heart. One side of the galvanometer is connected to the center lead of a potentiometer (component) which spans a voltage source; the other side is connected to a reference voltage. The potentiometer can be adjusted until no current flows through the galvanometer, at which point both sides match the reference voltage. The reference voltage source can then be replaced with some other source, which can then be measured relative to the reference by adjusting the potentiometer until both the voltages match. The reference voltage source is a Weston cell, which uses two mercury electrodes, one amalgamated with cadmium, to produce a stable 1.018 volt reference; despite being 74 years old, this particular cell still measured at 1.017 volts.
In this case, the potentiometer was made to measure the voltage produced by a thermocouple. After calibrating the potentiometer and connecting an iron-constantan thermocouple, [Alnwlsn] tested it with ice and boiling water, and in each case it proved accurate. In a more extreme test, it captured the temperature difference between the base and the tip of an alcohol flame.
For a bit more on the history of similar devices, check out the history of Weston Electrical Instruments.
youtube.com/embed/NQvPDH1g4Hs?…
Thanks to [PeterF] for the tip!
Disinformazione e minacce ibride: l’Italia è pronta a fronteggiare le crisi come Ceuta?
📌 Link all'articolo : redhotcyber.com/post/disinform…
Massimo Dionisi
#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology
Ceuta dimostra come un ingresso migratorio fantasma possa trasformarsi in minaccia ibrida. L’Italia è pronta?Massimo Dionisi (Red Hot Cyber)
reshared this
UK AISI says Anthropic's Mythos 5 and OpenAI's GPT-5.6-Sol hacked real-world orgs during an evaluation last month: aisi.gov.uk/blog/incident-repo…
Both confirmed
Anthropic: x.com/AnthropicAI/status/20847…
OpenAI: openai.com/index/third-party-c…
The most serious case was trying to social-engineer a FOSS project
The UK’s @AISecurityInst (AISI) has published a report on their recent cybersecurity evaluation of Anthropic’s Claude Mythos 5 and OpenAI’s GPT-5.6 Sol.Anthropic (X (formerly Twitter))
reshared this
U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog.Pierluigi Paganini (Security Affairs)
Cybersecurity & cyberwarfare reshared this.
@Informatica (Italy e non Italy)
In due episodi Amazon ha analizzato gli attaccanti far leva su tecniche di ingegneria sociale per conquistare la fiducia degli amministratori dei pacchetti e ottenere così i privilegi. Ecco come gruppi legati alla Corea del
🤖 L'IA si ripromette di curare il cancro, ma viene usata principalmente per scopi bellici
Quando a fine febbraio gli Stati Uniti e Israele attaccarono l'Iran, l'IA di Claude fu utilizzata per pianificare l'attacco. In meno di 24 ore furono colpiti 2000 obiettivi, una cifra pressoché impossibile da elaborare in così poco tempo dagli esseri umani.
Diffusasi la notizia, la compagnia si sfilò dagli accordi con il Pentagono perché rifiutava che il proprio sistema potesse scegliere in autonomia chi dovesse morire - l'IA infatti sbaglia ogni tanto anche sulle cose frivole, si immagini darle il potere di determinare a chi togliere la vita. Fu quindi OpenAI a subentrare, non facendosi troppi problemi inerenti all'etica.
Se nel 2025 il rapporto ONU sul genocidio palestinese accusava nomi come Amazon, Google e Microsoft di essere complici in genocidio in quanto fornivano la potenza di calcolo allo stato israeliano per accelerare il massacro, qui si va decisamente oltre: la macchina è strumento attivo di sterminio. Proprio come fece Israele, utilizzando la propria IA Habsora per determinare dove colpire in Palestina.
Dalle parole del giornalista: "Gli evangelisti della tecnologia ci promettono come l'IA un giorno curerà il cancro, porrà fine alla povertà e aumenterà notevolmente la qualità della vita. Al momento, però, l'impatto maggiore che ha avuto è palesemente quello nelle guerre".
codastory.com/armed-conflict/t…
#ia
In Iran, artificial intelligence is being used to select targets, summarize intelligence and make the ‘kill chain’ ruthlessly efficientSimon Allison (Coda Story)
reshared this
OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch.Pierluigi Paganini (Security Affairs)
Cybersecurity & cyberwarfare reshared this.
More than a dozen Republican attorneys general are calling on #OpenAI to preserve records on its models’ recent breach of #HuggingFace, suggesting the #AI firm may have violated state or federal laws in the incident.
Press release: iowaattorneygeneral.gov/newsro…
Direct link to full letter:
iowaattorneygeneral.gov/media/…
Iowa Department of Justice, Office of the Attorney General news releases.State of Iowa Office of the Attorney General (Iowa Attorney General)
reshared this
reshared this
Once upon a time, telephones were primarily point-to-point communications systems. There were options for three-way and conference calls out there, but by and large the plain old telephone system was about connecting one handset to another for a direct conversation. For this reason, the telephone was seldom used for mass emergency communications, because it was simply not fit for broadcasting a message to a wide number of people.
However, technology has since changed. Our modern phones are all connected to a big digital over-the-air network, and large swathes of them can be addressed all at once if so needed. This has led to the development of emergency warning systems that use the cellular network, with Cell Broadcast being the most notable iteration.
Cell Broadcast technology has been a part of mobile network infrastructure for some decades now, having been included in various forms in 2G, 3G, 4G, and 5G mobile standards. The system was first demonstrated in 1997 in Paris, with the concept being straightforward enough—a way for cell networks and authorities to send rapid notifications in a one-to-many broadcast. The technology is sometimes referred to as Short Message Service-Cell Broadcast (SMS-CB), differentiating it from the more familiar Short Message Service-Point to Point (SMS-PP) that individual subscribers use. A Cell Broadcast message can be fired off to select cells of a cellular network, with the notification in turn popping up on the handsets of all subscribers connected to that cell. This allows for easy geofencing of emergency alerts and information, such that only individuals in the relevant area receive the Cell Broadcast message.The infamous false alarm missile warning message sent out in Hawaii in 2018 was, in part, distributed via the Wireless Emergency Alerts system using Cell Broadcast. Credit: public domain
By firing a Cell Broadcast to entire mobile networks across a country, it’s possible for authorities to get a message out to millions of phones in mere seconds—a remarkably effective way of communicating critical information quickly.
A typical Cell Broadcast emergency message will be announced by a special alert tone with the textual message content appearing on the phone in turn. Messages can be sent in a primary and an additional language and displayed according to a devices individual language settings to aid in accessibility. There is also generally no need for a given device to have a SIM card installed, since the Cell Broadcast messages are not addressed to any given individual subscriber number.
Modern Cell Broadcast messages can be up to 1,395 characters long using Latin characters, or up to 615 characters in languages using UCS-2 character encoding. Messages can be set to refire from every 2 seconds to over 30 minutes, with handsets typically ignoring rebroadcasted messages that have already been displayed. In turn, new messages can also be sent quickly to reflect changing conditions or updated information.
Cell Broadcast messages can come in several different levels depending on the intended severity of the alert. These are identified by hex codes laid out in 3GPP standards, though the exact alert levels vary across different national implementations of the system. In the EU, they are ranked from Alert Level 1 (most severe) to Alert Level 4 (least severe) with additional levels for “Amber,” “Test,” and “Information” alerts beneath. Levels below 1 can be “opted out” on certain handsets with the functionality to do so. Similarly, in the US, the highest level is “National Alert” which can not be opted out of and will always fire on handsets receiving the message. Below that, the levels step down to “Extreme Alert,” “Severe Alert,” and “Public Safety Alert,” with Amber Alerts and test levels beneath that.Some handsets allow opting out of lower-level alerts. The highest-level CB alerts will typically sound a tone and display on all capable handsets, regardless of volume settings or silent or “Do Not Disturb” modes. Credit: Aveaoz, CC BY-SA 4.0
Many nations have built emergency communications systems around the Cell Broadcast infrastructure. Since a high percentage of populations in developed countries own cellular phones and keep them close at hand at all times, it serves as a highly effective way to distribute emergency warnings. Many countries simply name their systems after their own nation—such as FR-Alert and DE-Alert in France and Germany, to T-Alert in Thailand. Others get more creative, such as S!RENEN in Denmark, or more descriptive, such as the Disaster and Emergency Warning Network (DEWN) in Sri Lanka.
Despite Cell Broadcast having existed in various forms across previous generations of mobile networks, some nations are still yet to fully implement emergency warnings over this infrastructure. Notably, Australia is in the process of rolling out AusAlert in 2026, with the first national test of the system firing off on the 27th of July, 2026. Authorities noted that 94% of targeted cell towers broadcast the message succesfully, though there was some controversy around some phones not displaying the broadcast message, and concerns around secret phones being revealed by the test which would sound regardless of silent or “do not disturb” modes. Other countries still developing Cell Broadcast emergency systems include India, Poland, Ukraine, Sweden, and Brazil.Not all CB messages are high-level emergencies. Above, a cold weather warning sent out via Cell Broadcast in South Korea. The device in question had a German language setting, hence the message title in a different language. Notably, SMS-CB messages sent in non-Latin alphabets feature a lower character limit. Credit: Verganglichkeit, CC BY-SA 4.0
There are limitations to Cell Broadcast. Namely, as a one-to-many broadcast message, it’s not directly possible for authorities or telecommunications operators to determine how many or which subscribers may have received the message. The technology is effectively a “push” message system with no backchannel for confirmation of receipt. This is somewhat by design, however, as thousands or millions of devices sending a read receipt via the network would create huge network congestion. This would be particularly undesirable during an emergency situation.
Regardless, the Cell Broadcast methodology has key benefits for emergency and mass notifications compared to other methods of reaching out via the mobile network. Most of all, it’s a message that is broadcast rather than sent to individual subscribers. Sending the same notifications via SMS or MMS would require huge amounts of network capacity as each individual message for each individual phone number was sent out.
There are also logistical difficulties in such a method, wherein a list of valid phone numbers must be maintained and updated at all times. It can also be more difficult to do things like geofenced messaging, since individual subscribers and their phones tend to move around a fair bit.
Hopefully, you’ll never find yourself wrapped up in a major weather event or other serious emergency. If you do, though, you might just find that critical information you need to survive thanks to a timely Cell Broadcast message. Expect such systems to become a baseline part of emergency management efforts in future as long as cellphones remain a ubiquitous communication tool across the population.
reshared this
reshared this
reshared this
Troubleshooting Windows: perché partire dall’evidenza e non dal comando di riparazione
#tech
spcnet.it/troubleshooting-wind…
@informatica
reshared this
CVE “Allucinate”: 54 falsi bug generati dall’AI entrano nei database ufficiali di sicurezza
📌 Link all'articolo : redhotcyber.com/post/cve-alluc…
Luigi Zullo
#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology
I database delle vulnerabilità includevano segnalazioni di problemi critici di SQLite con punteggi fino a 9,8 punti, ma un controllo del codice sorgente non ha confermato un singolo errore segnalato.Luigi Zullo (Red Hot Cyber)
reshared this
reshared this
Diagnosticare lo swap su Linux con smem: USS, PSS, RSS e il ruolo di vm.swappiness nei cgroup v2
#tech
spcnet.it/diagnosticare-lo-swa…
@informatica
reshared this
✨ Acqua sotto attacco: come hacker legati all’Iran hanno tentato di contaminare le reti idriche di sette stati USA
#CyberSecurity
insicurezzadigitale.com/acqua-…
reshared this
✨ OVERCAST PANDA: la Cina compromette fisicamente i laptop di giornalisti e scienziati in hotel
#CyberSecurity
insicurezzadigitale.com/overca…
reshared this
@Informatica (Italy e non Italy)
FBI ed EPA confermano un'ondata di attacchi contro PLC Rockwell esposti su internet in almeno sette stati americani, con l'obiettivo dichiarato di abbassare la pressione idrica fino a
@Informatica (Italy e non Italy)
Il CrowdStrike 2026 Threat Hunting Report rivela come, tra marzo e maggio 2026, l’adversary china-nexus OVERCAST PANDA abbia installato il backdoor FlowCloud su laptop incustoditi di giornalisti e ricercatori in viaggio in Cina,
Si parla di:
Toggle
Non un semplice blackout digitale, ma un tentativo — riuscito solo in parte — di trasformare un attacco informatico in un’emergenza sanitaria pubblica. FBI ed EPA hanno confermato che, dal 27 luglio 2026, impianti idrici e fognari di almeno sette stati americani sono stati colpiti da intrusioni coordinate contro controllori industriali esposti su internet. Un memo delle forze dell’ordine del Minnesota, il primo stato a rendere pubblico l’incidente, è ancora più esplicito sul movente: l’obiettivo dichiarato degli attaccanti non era interrompere il servizio, ma contaminare l’acqua potabile.
Il Minnesota ha rilevato attività ostile su oltre 30 sistemi idrici e fognari comunitari nella notte tra domenica 26 e lunedì 27 luglio. L’impianto idrico di Braham, una comunità di circa 1.700 abitanti, è stato messo completamente fuori uso e ripristinato in circa due ore passando alla gestione manuale. A Plymouth sono state disconnesse apparecchiature con connettività cellulare su due torri idriche e diverse stazioni di sollevamento fognario. South St. Paul e Maple Plain hanno mantenuto il servizio nonostante l’impatto sui controlli automatizzati, ma Maple Plain ha dichiarato lo stato di emergenza locale.
L’incidente non si è fermato al Minnesota: il Wisconsin ha rilevato attività ostile sui propri impianti idrici nello stesso arco temporale, tanto da spingere il Dipartimento delle Risorse Naturali a ordinare “azioni immediate” agli operatori. Nell’avviso congiunto pubblicato giovedì, FBI ed EPA hanno confermato che utility idriche di almeno sette stati — non nominati pubblicamente — hanno segnalato incidenti dal 27 luglio in poi, in alcuni casi con degrado operativo reale.
L’avviso FBI/EPA identifica con precisione l’equipaggiamento colpito: controllori logici programmabili (PLC) Allen-Bradley delle serie MicroLogix 1100 e 1400, prodotti da Rockwell Automation, raggiungibili direttamente da internet. Gli attaccanti hanno effettuato accesso remoto a questi dispositivi, modificandone indirizzo IP e password — di fatto scacciando gli operatori legittimi dalla possibilità di monitorare e controllare l’impianto. In almeno un caso, dopo aver notato discrepanze tra siti diversi, l’organizzazione vittima ha scoperto che gli attaccanti erano andati oltre, alterando direttamente i file di progetto del PLC: la logica ladder che governa il comportamento fisico di pompe e valvole.
La fisica dietro l’obiettivo dichiarato dagli attaccanti si chiama backsiphonage. Le reti di distribuzione idrica lavorano in pressione positiva, tipicamente tra 40 e 80 psi, per spingere l’acqua verso gli utenti e tenere fuori dalle tubature eventuali contaminanti esterni. L’EPA fissa a 20 psi la soglia sotto la quale un evento di perdita di pressione viene classificato come pericoloso: scendere sotto quel valore in prossimità di un cross-connection — un punto in cui le tubature di distribuzione corrono vicino a fonti non potabili, come acque di falda, pozzi privati o linee fognarie — può risucchiare quei contaminanti all’interno del sistema attraverso giunti o crepe nelle tubature, lo stesso principio fisico di una cannuccia. La pericolosità dell’attacco sta nella combinazione di due capacità simultanee: manipolare i PLC per abbassare la pressione, e allo stesso tempo sopprimere gli allarmi che dovrebbero avvisare gli operatori del calo, lasciandoli con dashboard apparentemente normali mentre il sistema fisico è già in stato non sicuro.
Nessuna contaminazione è stata confermata: il Dipartimento della Salute del Minnesota ha dichiarato che la qualità dell’acqua non è stata compromessa in nessuno degli impianti colpiti e non sono state emesse ordinanze di bollitura a livello statale.
Gli investigatori federali ritengono probabile il coinvolgimento di attori legati all’Iran, sebbene l’attribuzione non sia confermata. Il tempismo è indicativo: gli attacchi in Minnesota sono iniziati quattro giorni dopo che la CISA aveva aggiornato un avviso su larga scala riguardante l’espansione delle operazioni iraniane contro acqua, energia e infrastrutture governative statunitensi. Tre giorni prima degli attacchi, il gruppo Handala — attribuito al Ministero dell’Intelligence iraniano — aveva pubblicamente minacciato di colpire reti idriche, elettriche e di trasporto americane, proprio nello stesso giorno dell’aggiornamento CISA.
Secondo i ricercatori di Tenable, il pattern operativo osservato in Minnesota è coerente con l’ecosistema CyberAv3ngers, gruppo collegato al Corpo delle Guardie Rivoluzionarie Islamiche che dal 2023 prende sistematicamente di mira le infrastrutture idriche statunitensi e sanzionato dal Tesoro USA nel febbraio 2024. Il contesto geopolitico è quello di un conflitto armato aperto tra Stati Uniti e Iran, iniziato il 28 febbraio 2026 e proseguito con un cessate il fuoco entrato in vigore ad aprile: le operazioni cyber iraniane contro le infrastrutture critiche americane sono continuate e si sono intensificate da allora.
Gli inquirenti stanno però valutando anche un’ipotesi più inquietante: che chi ha condotto l’attacco abbia deliberatamente riutilizzato tattiche, strumenti e infrastruttura associati agli attori iraniani per costruire un’operazione false flag, capace di alimentare tensioni tra Washington e Teheran in un momento in cui i due paesi sono già in conflitto aperto. Nessuna attribuzione formale è stata effettuata; nessuna accusa è stata mossa.
La vicenda ha acceso anche uno scontro politico interno: il presidente Trump ha respinto pubblicamente l’attribuzione all’Iran, attribuendo la responsabilità alla “grossolana incompetenza” del Minnesota e del governatore democratico Tim Walz. Walz ha risposto puntando il dito contro i tagli imposti dall’amministrazione Trump alla CISA, che secondo TechCrunch ha perso circa un terzo del proprio organico, incluso lo smantellamento della sua iniziativa anti-ransomware. Al di là della disputa politica, il problema strutturale resta: un’indagine EPA del 2024 ha rilevato che il 70% dei sistemi idrici ispezionati dal 2023 non rispettava gli obblighi di valutazione del rischio previsti dall’America’s Water Infrastructure Act, e un successivo rapporto dell’Inspector General ha individuato vulnerabilità critiche o gravi in 97 dei oltre 1.000 sistemi idrici controllati, per una popolazione servita di circa 26,6 milioni di persone.
Le raccomandazioni congiunte di FBI, EPA e CISA per il settore idrico sono immediate e concrete: scollegare i PLC dall’accesso diretto a internet, sostituendo la connettività cellulare non protetta con VPN dedicate e autenticazione a più fattori dove l’accesso remoto resta necessario; cambiare tutte le password predefinite o deboli, dato che una quota significativa dei dispositivi compromessi utilizzava credenziali banali; confrontare i file di progetto dei PLC in produzione con backup offline noti per individuare eventuali discrepanze nella logica ladder, che possono persistere anche dopo un reset delle password; impostare fisicamente i selettori a chiave dei controllori in modalità “Run”, che blocca la modifica remota della logica anche in caso di compromissione di rete; e pianificare la sostituzione dei dispositivi a fine vita come le serie MicroLogix 1100/1400, che potrebbero non ricevere più aggiornamenti di sicurezza da Rockwell Automation.
Un dettaglio da non sottovalutare riguarda i fornitori di servizi gestiti: l’avviso FBI segnala che configurazioni di rete replicate da uno stesso managed service provider su più clienti possono moltiplicare il successo di un singolo attacco su decine di impianti diversi — un rischio di supply chain che le utility idriche, spesso piccole e con personale IT limitato o assente, raramente hanno la capacità di verificare da sole.
Dispositivi presi di mira:
Rockwell Automation Allen-Bradley MicroLogix 1100 (PLC)
Rockwell Automation Allen-Bradley MicroLogix 1400 (PLC)
Tecnica osservata:
Accesso remoto diretto a PLC esposti su internet
Modifica di IP e password del dispositivo
Alterazione dei file di progetto / logica ladder ("ladder logic discrepancies")
Soppressione di allarmi e monitoraggio
Attore sospettato:
CyberAv3ngers / cluster IRGC-CEC (attribuzione non confermata da FBI)
Possibile operazione false flag in corso di verifica
Riferimenti ufficiali:
FBI/EPA PSA - Malicious Cyber Actors Targeting Water and Wastewater Sector PLCs
CISA Advisory AA26-097A (campagna ICS legata all'Iran)reshared this
Si parla di:
Toggle
Non serve sempre un exploit da milioni di dollari per compromettere un bersaglio di alto valore: a volte basta un cacciavite, una chiavetta USB e una cena fuori dalla stanza d’albergo. È questo lo scenario descritto dal CrowdStrike 2026 Threat Hunting Report, pubblicato il 3 agosto, che rivela come tra marzo e maggio 2026 il team OverWatch abbia individuato e neutralizzato una serie di operazioni “close access” condotte in Cina dall’adversary OVERCAST PANDA contro i laptop di giornalisti, ricercatori e altri professionisti stranieri in viaggio nel Paese.
OVERCAST PANDA è un adversary china-nexus attivo almeno dal 2019, in precedenza tracciato con il nome di cluster ClearVariable. Il suo tradecraft è storicamente caratterizzato dall’uso di due impianti proprietari, FlowCloud e LookBack, distribuiti attraverso vettori diversi a seconda dell’operazione. Ciò che distingue questa campagna dalle tipiche intrusioni china-nexus — solitamente basate su spear phishing, sfruttamento di vulnerabilità edge o compromissioni della supply chain software — è la scelta di un approccio interamente fisico, capace di bypassare di netto qualunque difesa di rete o endpoint basata su telemetria da remoto.
Secondo la ricostruzione di CrowdStrike, gli operatori di OVERCAST PANDA hanno sfruttato momenti di assenza dei bersagli — tipicamente durante cene o eventi collaterali di conferenze — per accedere fisicamente a laptop lasciati incustoditi nelle stanze d’albergo. Il dispositivo veniva avviato da un supporto USB rimovibile, bypassando così il sistema operativo in esecuzione e le relative protezioni, incluso qualunque agente EDR installato: l’impianto FlowCloud veniva scritto direttamente sul disco, fuori dal contesto del sistema operativo attivo.
Al successivo riavvio del laptop — un’operazione del tutto ordinaria che non insospettisce la vittima — il backdoor si avviava automaticamente e restava operativo in modo persistente e silenzioso. Su almeno uno dei casi disinnescati da OverWatch, il laptop non aveva mai mostrato alcun segno di intrusione a livello di rete, a conferma che l’intero attacco si era consumato offline, senza lasciare tracce nei log di traffico che i team di sicurezza normalmente monitorano.
Una volta attivo, FlowCloud fornisce agli operatori un accesso pressoché completo alla macchina compromessa: keylogging, cattura di screenshot, raccolta ed esfiltrazione di file, furto di credenziali salvate. Per un giornalista che sta lavorando su fonti sensibili o per un ricercatore che porta con sé dati proprietari o pre-pubblicazione, l’impianto rappresenta un rischio equivalente a una sorveglianza fisica prolungata, ma condotta interamente a livello digitale e senza necessità di ulteriore contatto con il bersaglio dopo l’installazione iniziale.
Il caso OVERCAST PANDA si inserisce in un quadro più ampio disegnato dal report, che descrive un ecosistema china-nexus sempre più aggressivo e rapido. Gli adversary VAULT PANDA e GENESIS PANDA, ad esempio, hanno sfruttato vulnerabilità critiche entro 24 ore dalla pubblicazione di proof-of-concept pubblici — un ritmo nettamente superiore alla media generale osservata da CrowdStrike, secondo cui l’88% degli sfruttamenti di vulnerabilità con PoC disponibile avviene comunque entro 48 ore dalla release. Il report segnala inoltre una crescita del 30% negli annunci di initial access broker relativi a società tecnologiche (277 aziende offerte in vendita), a testimonianza di una domanda crescente per accessi già pronti all’uso.
In questo contesto, le operazioni close access di OVERCAST PANDA rappresentano un promemoria che la sofisticazione offensiva cinese non si esaurisce nel dominio puramente informatico: la disponibilità di personale sul territorio nazionale permette di condurre operazioni ibride, fisiche e digitali, contro bersagli che altrimenti sarebbero difficili da raggiungere da remoto.
Per chi viaggia in Cina — o in qualunque contesto ad alto rischio — con dispositivi aziendali, alcune contromisure restano fondamentali:
Il caso dimostra che, contro adversary con risorse statali e accesso fisico al territorio, anche l’igiene di sicurezza informatica più rigorosa deve essere affiancata da protocolli di sicurezza operativa (OPSEC) pensati per il mondo fisico.
Adversary: OVERCAST PANDA (ex cluster ClearVariable), china-nexus, attivo dal 2019
Malware: FlowCloud (impianto principale), LookBack (impianto storico)
TTP osservate:
- T1200 – Hardware Additions (uso di supporto USB rimovibile per boot esterno)
- Bypass del sistema operativo e degli agenti EDR tramite avvio da media esterno
- Scrittura dell'impianto direttamente su disco, fuori dal contesto OS
- Persistenza tramite avvio automatico al riavvio successivo del sistema
- Capacità: keylogging, screenshot capture, file collection, credential theft
- Nessuna attività di rete rilevabile durante la fase di compromissione iniziale
Finestra operativa nota: marzo-maggio 2026
Bersagli: giornalisti, ricercatori/scienziati e altri professionisti stranieri in viaggio in Cina
Contesto di compromissione: laptop incustoditi in stanze d'albergo durante eventi/conferenze
Fonte: CrowdStrike 2026 Threat Hunting Report (pubblicato 3 agosto 2026)reshared this
We're thrilled to announce IFIN has achieved 501(c)(3) recognition! Now we can get down to business.
ifin-intel.org/blog/nonprofit/
#IFIN
IFIN has achieved 501(c)(3) status. What this means for us, and for you.IFIN
reshared this
Carlos Solís likes this.
reshared this
⚠️ Beneficial owners registry exposes 31,000 entities
Attackers stole data copies tied to companies, foundations and trusts, forcing the register offline.
🔗 read more: thecyberexpress.com/...
Beneficial Owners Register breach exposed data copies linked to around 31,000 legal entities after unauthorized access.Samiksha Jain (The Cyber Express)
reshared this
🚨 ExfilSquad leaks UK police contact data
Over 100.000 officers and justice staff had names and emails exposed.
🔗 read more: www.bleepingcomputer...
reshared this
Probabilmente sono un po' fuori dal mondo, ma qualcuno sa darmi informazioni su Substack? Mi ci sono imbattuto per caso e sembra interessante 
reshared this
@elettrona @lindasartini @giuliocavalli @valeriorenzi curioso come su Substack affermino il contrario.
Devo dire che una parvenza di algoritmo l’ho captata anche io, magari non come Instagram, ma certi contenuti vengono spinti più di altri.
Articolo che avrei dovuto scrivere tempo fa (meglio tardi che mai 😋): OpenCode, l'alternativa #opensource a Claude Code e similari.
Nell'articolo elenco le caratteristiche, i pro e i contro, ecc
Link 👇
domenicotenace.dev/blog/open-c…
Software developer passionate about the IT world and everything related to itdomenicotenace.dev
like this
reshared this
Telegram è stato rimosso dall'App Store per qualche ora: dietro la segnalazione, un'estorsione ai danni di Apple. Se un'app da un miliardo di utenti sparisce senza preavviso, chi decide chi vive e chi muore nel mercato delle app? #Telegram #AppStore #DMA
melamorsicata.it/2026/08/05/te…
Telegram rimosso dall'App Store per contenuti illegali e ripristinato in poche ore. L'analisi del caso e del potere dei gatekeeper nel mercato delle appKiro (Melamorsicata)
reshared this
WELCOME TO THE FREE MONTHLY EDITION of Digital Politics.I'm Mark Scott, and many of you (I hope) are on vacation. A lot has happened so far in 2026. With the summer lull upon us, this week's edition is updating a piece that I wrote for POLITICO in 2024 about the global race to control artificial intelligence.
It's not a like-for-like comparison. Back then, I was a tech reporter. Now, I'm a think tanker (and newsletter writer.) But the underlying question — about who will control the emerging technology for years to come — has not changed.
If anything, it's become even more complex.
Let's get started:
ON A WET AFTERNOON IN LATE 2023, the likes of former US vice president Kamala Harris and then-senior Meta executive Nick Clegg trudged into a wind-swept tent an hour north of London. They had gathered to show a united front against what many feared would be a threat to the world: uncontrolled artificial intelligence. After late-night negotiations, the outcome was the Bletchley Declaration, a voluntary commitment by 28 countries, including the United States and China, to identify and respond to existential risks tied to the emerging technology.
Fast forward two years, and Narendra Modi, India's prime minister, stood in front of a podium in February to address thousands of conference attendees at a purpose-built convention center in New Delhi. His speech — translated simultaneously into 11 languages via AI — had followed announcements from Google, Tata and Anthropic about multi-billion dollar investments in India's fast-growing economy. The event's communiqué, signed by 92 countries and international bodies, only paid lip service to the safety concerns that had been central to the United Kingdom's inaugural AI summit.
Instead, the so-called AI Impact Summitin New Delhi was, above all, about the economic gain to be derived from the technology. "This is the fourth AI summit since Bletchley Park," Anthropic chief executive, Dario Amodei, told conference-goers. "We are increasingly close to a country of geniuses in a data center, systems more capable than most humans at most tasks."
What follows is an assessment of the global race for AI in 2026. It focuses on four themes that remain central to this geopolitical battle: 1) Who sets the rules?; 2) What do those rules look like?; 3) How corporate lobbying merged with countries' priorities; 4) How AI merged with national security.
These themes are obviously intertwined. But, above all, this update on the global race around AI tracks the rise of geopolitics, the disintegration of a Western consensus around AI safety/governance and a fundamental change in the global debate since officials first gathered at Bletchley Park in November 2023.
THERE WAS NEVER A WESTERN CONSENSUS for AI rule-making. Back in 2023-2024, the European Commission and former White House administration criss-crossed the globe to champion their respective visions of what AI oversight looked like. Washington preferred voluntary commitments. Brussels went all-in on its AI Act.
That basic tension is still there. Arguably, it's more pronounced in 2026. Where we are now (at least in terms of the European Union, US and China) is three competing sets of rules with no realistic "translation layer" to connect them. If the Bletchley Park Declaration, albeit voluntary, was about setting aside national interests to promote AI safety at a global level, then the current landscape is defined by fragmented national/regional rule-setting designed to favor individual strategic interests.
Thanks for reading the free monthly version of Digital Politics. Paid subscribers receive at least one newsletter a week. If that sounds like your jam, please sign up here.
Here's what paid subscribers read in July:
— An inside look at how regulators and companies view digital rules differently; Why Europe's digital sovereignty ambitions are missing a critical element; Almost half of Americans use AI chatbots at work. More here.
— Platform governance has entered a new phase: redesigning social media; The United Nations' push into AI misses where the real decisions are made; People aren't relying on chatbots to access news. More here.
— An ongoing focus on digital foreign interference misses where the next online threats are coming from; How the US and China laid out AI governance plans that left everyone else in their wake; More than half of Americans now favor a social media ban for kids. More here.
— Brussels and Washington are a lot closer on digital competition than you may think; The United Kingdom again shows why it's a second-tier digital nation; Data to show why China and the US are so far ahead on AI. More here.
The US' subtle pivot is demonstrable of how things have changed. During Joe Biden's administration, Washington laid out plans (via White House Executive Order) that made clear US efforts to remain the global leader on AI. But it also included some safety provisions, including watermarking for AI content and protecting consumers from AI harm, that positioned Biden in a co-regulatory relationship with AI firms.
That Biden-era Executive Order was quickly scrapped. In its place, Donald Trump's administration initially doubled down on removing all forms of AI oversight in the name of promoting US dominance. That framing, however, has shifted in 2026 as US officials respond to growing national security concerns around both how powerful the latest AI models have become and how quickly China's open-source rivals have matched US tech firms' proprietary systems. Ironically, in imposing export controls on Anthropic's most-advanced model, the laissez-faire Trump Administration had more direct intervention than the Biden Administration — and its favoring of some regulation — ever did.
For Europe, there also has been an about-turn on what had been Brussels' clear policymaking objective: comprehensive AI rules.
It's not that the EU isn't still committed to its AI Act. Those rules — like everything in Brussels — will stick around no matter what. But the recent AI Omnibus delayed some of the regulatory deadlines associated with high-risk AI use cases. It also introduced a ban on AI tools that created non-consensual explicit images/deepfake content, in part to placate anger within the European Parliament for the wider delay in the comprehensive AI rulebook.
More importantly, Europe shifted gears from using regulation to police AI to passing rules to jumpstart AI-enabled economic growth. The bloc's recent European Technology Sovereignty Package is less about AI enforcement, and more about using public funds to build EU digital infrastructure and compute power to ward off the "kill switch" fear associated with the bloc's current reliance on US tech providers.
This change put Brussels directly at odds with Washington's "AI dominance" strategy in a way that escalates the previous tensions between the US and EU on who should set global AI standards.
I won't pretend to be an expert in China's domestic AI rulebook (more on that here, here and here). But its international priorities now match those of Beijing's similar approach to digital diplomacy: use its convening, financial and standards-setting muscle to nudge other (Global Majority) countries to back its more authoritarian take on the emerging technology.
Its recent creation of the so-called World Artificial Intelligence Cooperation Organization, based in Shanghai, is this "Belt and Road" philosophy tilted toward the AI age. It's nominally multilateral, with 28 countries joining the organization, and includes language around openness, equity and inclusiveness. But the geopolitical aim is clear: to export a China-focused regulatory and governance model for AI to position Beijing (and its world view) at the center of the global AI rule-making discussion.
Total combined investment between 2021-2024 for countries worldwide (with a minimum investment of $1 billion).
The scale of accumulated US and Chinese investment over the time period explains why AI rulemaking for those countries is now inseparable from states’ attempts to protect existing industrial advantages for strategic national gain.Source: The 2025 AI Index Report; Visual Capitalist
THIS IS WHERE THINGS REALLY HAVE BECOME complex compared to where we stood in 2023/24. Back then, the battle centered on disputes about what regulation should do and who should be policed. Many of the largest US tech firms — the ones with the most advanced large language models — called for regulatory limits so only their systems could be used. That would be based on voluntary commitments to comply with oversight from a number of national AI safety institutes that had begun to sprout up.
The fear was that the alternative — framed via the expansion of open-source alternatives — would lead to short-term (AI's creation of bioweapons) and existential (read: Skynet) risks that were just too big to not be enforced by strict rules.
That dynamic continues in 2026, but with an even greater corporate bent. The likes of Google's DeepMind now actively call for greater regulation — albeit via an industry-funded self-regulatory agency akin to the US Financial Industry Regulatory Authority. OpenAI's Sam Altman has similarly suggested Washington lead efforts to create international certificates/standards for the latest large language models, again in a model that would massively favor that tech giant over smaller rivals.
Now, the regulatory discussion has become a geopolitical contest where each country's/region's approach and strategy is framed around promoting separate strategic interests. Regulation has become industrial policy by another name.
In the US, AI rules have now become OK, especially in light of the recent hacking efforts by OpenAI's systems and rumors about what Anthropic's latest models can do. Yet these proposals are inevitably self-serving. Companies propose oversight that will likely entrench their dominance by raising barriers around who can build such advanced AI systems. Call it regulatory capture framed as public safety.
The Chinese have thrown their full weight behind open source. In part, that is a pragmatic response to increasing US efforts to stop the world's second largest economy from accessing AI infrastructure like high-end semiconductors. But it's also a strategic play to reduce Beijing's (and other capitals') reliance on US proprietary models when much of the world's willingness to trust Washington has been diminished.
It helps that Chinese open source models are now mostly on par with those from Anthropic, Google and OpenAI. It also helps to position Beijing as a willing partner, see above section, with national capitals across the Global Majority which feel shut out from the conversations going on in Brussels and Washington, respectively. The fact that Western companies are now embracing such Chinese open source models is a sign that Beijing's tactics are bearing fruit, even across the US and Europe.
Europe, the OG of digital regulation, has been caught flat-footed by the "open versus closed" battle between the US and China. Part of that can be explained by the 27-country bloc's fixation on its digital sovereignty agenda that now includes pumping public money into "Made In Europe" digital infrastructure. That goal has been championed by the Continent's legacy industries.
The recently-published European Tech Sovereignty Package didn't go as far as many of these firms would have liked in terms of kicking US tech giants out of the bloc's digital infrastructure. It also embraced open source as a means to both reduce the EU's reliance on US tech providers and jumpstart AI-enabled economic growth, which — at least on paper — sounded awfully similar to what China is now promoting.
But Europe's rule-making, like that of the US and China, is now overwhelmingly positioned to support the Continent's industrial interests. Two years ago, that conversation was squarely focused on policing the emerging technology for public good.
COMPANIES PUSHING THEIR CORPORATE INTERESTS is not new. And even in 2023/24, many of the arguments about whether regulation should favor either open or closed AI models were more akin to a lobbying fight between rival industrial camps.
Yet in 2026, the line between corporate lobbying and countries' geopolitical strategies has blurred into insignificance. With so much on the line when it comes to AI (in terms of economic growth and national security, see below), officials are now more willing to actively promote specific companies — both at home and abroad — to ensure their vision of the AI future comes to pass.
I've already outlined some of this in the section above. But when Anthropic's chief executive outlines his concerns about the Chinese Communist Party developing AI models that are "more powerful than those built by the US, and use them to achieve permanent military superiority," the distinction between what are corporate and national priorities becomes hard to disentangle.
There is a reason why some within US tech circles now refer to Chinese rival AI models as "Communist AI," and it's not because of legitimate concerns about how the authoritarian regime could potentially use such advanced technologies. It plays directly into Washington's mounting fears of Beijing's technological prowess, and turns corporate concerns about being supplanted by cheaper, Chinese open source competitors into national security concerns that, potentially, may lead to action by the US Congress or White House.
It's not like the Chinese are not doing something similar with their embrace of open source. They decided that competing head-on with the likes of OpenAI and Google was a mug's game. A lack of access to high-end Nvidia chips and semiconductor technology from the likes of the Netherlands' ASML also forced their hand. But Beijing's interests now align with Chinese companies' interests: build globally-competitive open-source models that reduce the ability of US rivals to sell their wares to would-be clients worldwide.
The European lobbying is equally grounded in policymaking priorities, albeit Brussels is somewhat more navel-gazing than either Washington and Beijing. EU companies have successfully (and possibly legitimately) framed the bloc's ongoing use of US technology as a strategic dependency that now must end. Europe's willingness to use public funds to build up its own digital infrastructure — often via contracts to these very same European companies — brings those corporate interests and policymaking goals full circle.
What no one (or, almost no one) is willing to admit in the EU is that, currently and likely for the foreseeable future, European alternatives are not yet ready to compete, at scale, with incumbent US tech providers. Many in Brussels know that reality. Few are willing to say it out loud.
WHEN I REPORTED THE POLITICO ARTICLE in 2023/24, national security was an also-ran in the AI governance conversation. There were concerns around how the technology would be used in autonomous weapons. But questions around AI safety and "trustworthiness" were central to global AI policymaking discussions.
How much can change in two years.
Alongside a focus on AI-enabled economic growth, the merging of artificial intelligence with national security priorities has become the only digital policymaking game in town. Well, that and kids' social media bans. Many of the AI safety institutes created in the wake of the Bletchley Park Declaration even renamed themselves "security" institutes (looking at you, United Kingdom.)
There are good reasons for this shift. The latest AI models are breaking things that many thought unthinkable, even a year ago. The use of AI in warfare is now worryingly routine.
Thanks for getting this far. Enjoyed what you've read? Why not receive weekly updates on how the worlds of technology and politics are colliding like never before. The first two weeks of any paid subscription are free.
Subscribe
Email sent! Check your inbox to complete your signup.
No spam. Unsubscribe anytime.
The ability of governments (aka Washington) to impose export bans on advanced large language models, as well as stop other countries from accessing high-end chips, is now accepted, even if opposed by the likes of China that face such restrictions. There are some in the US who now even want to ban Chinese open-source models from entering the country.
Where once AI governance was framed through the prismof traditional digital regulation, it is now conducted via such export controls, model restrictions and investment screenings directly in the wheelhouse of national security.
In truth, national security has now consumed the other areas of the global AI race that were so prominent in 2023/24. Rules are set to meet national security objectives. Regulation is constructed to promote national strategic advantages. Corporate lobbying is positioned through a geopolitical lens, and not as one that pits companies and governments on separate sides of the table.
That is the biggest fundamental shift — and speaks to the geopolitical nature of the global AI race that, while present in 2023/24, has been turned up to 11 over two years later.
In 2024, I asked who would control AI. The answer in 2026 is that control itself has become the objective. Each jurisdiction is building the AI infrastructure, the regulatory framework and the corporate alliances to try to control the emerging technology, and not be controlled by it.
[Mansour] presents an interesting idea in his essay A Common Thread — just as USB-C has become the “One Connector To Rule Them All” in the world of electronics, so too should his projects have a unified physical connection layer. A common thread, if you will.
Specifically, the 1/4″-20 UNC connector that was already on all his camera equipment. Unifying his stuff around that connector wasn’t a bolt from the blue brainwave. By the sounds of it, the idea evolved over time and only became intentional after he’d already started using it.
There’s something to be said for it, though. One thing is the convenience of knowing your various bits and bobs are going to fit together like they were made with LEGO. Another is taking away a whole set of decisions in the design process: it’s going to have a 1/4″-20 UNC fitting, so [Mansour] needs only decide if its going to be tapped into the material or if he’s using an inset or captive bolt.
It isn’t like a 1/4″ bolt is going to introduce a weak point in most things we build — with good hardware it can take a ton or more. On the other hand it’s not exactly resilient to torque, but [Mansour]’s camera bag had the answer to that, too: spring loaded locator pins that drop into holes on the female side to take up the torque. In the photography world, these are AARI pins. To us they just seem like a good idea.
Maybe you don’t see the point of avoiding redesigning the wheel every time for custom mounts and brackets. After all, that lets you come up the the ideal solution every time. On the other hand, [Mansour] has both simplified his design process and made decades worth of camera-holding objects — everything from tripods to stabilizing gimbals — accessible to all his stuff. It’s an interesting idea, and his full blog post is worth a read, even if it’s not likely the EU is going to force its adoption like it did USB-C.
reshared this
non è sbagliato investire nella difesa, soprattutto in un momento come quello attuale in cui potenze pericolosissime hanno perso il senso della dcenza.
Tuttavia oggi investire nella difesa è un rischio troppo grande, perché significa comprare (anzi, diciamo noleggiare) a carissimo prezzo armi soprattutto dagli USA (che sono "alleati" ma che non sono nostri amici) e alimentare la costosissima e inefficiente logistica industriale occidentale e il conseguente "mazzettificio difesa"
@informapirata in un certo senso avete entrambi le vostre ragioni. In un mondo come quello odierno avere una buona difesa può essere utile. Ma spender miliardi in armi straniere no (vatti a fidare che tra pc, reti e IA quando servono qualcuno da lontano stacca la spina alle "tue" armi). Dovrebbe essere la UE ad autoprodurre le proprie armi, con investimenti oculati che rilancino anche tecnologia e imprese locali .
Ma soprattutto pochi soldi (relativamente ) e investiti con progetti sensati a lungo termine. Non finanziare i soliti mafiosi dell'industria delle armi.
informapirata ⁂ reshared this.
#nerdystuff in pausa pranzo
#TopCartoons è l'archivio streaming dei cartoni classici: Looney Tunes, Tom & Jerry, la golden age dell'animazione senza reboot né remaster... insomma, il pomeriggio dell'infanzia, on demand!
📺 topcartoons.tv
reshared this
Pippe scandalosamente inadeguate al ruolo: secondo fonti informate, quasi l'80% degli intercettori di un importante sistema di difesa missilistica (patriot?) è stato esaurito 🤡
Gli alti comandanti militari statunitensi avvertono che in generale le scorte di munizioni del Pentagono sono "pericolosamente basse"
Vabbe', se non hanno ancora mandato via tutti gli ingegneri indiani, possono sempre lanciare le batterie vuote con le catapulte 😂
reshared this
informapirata ⁂ reshared this.
@sandropisano la difesa NATO-like si è concentrata sul costosissimo hi-tech perché ha reputato che bastasse il terrore della efficientissima reazione USA a mantenere il mondo sottomesso (e perché il complesso militare industriale pensava ad arricchirsi più che a difendere la patria).
Peccato che in qualsiasi settore (e in qualsiasi dimensione dell'universo), dilapidare le risorse porta sempre al loro esaurimento
Majden 🍉🎗🎨🥋👠☮️ reshared this.
informapirata ⁂ reshared this.
informapirata ⁂ reshared this.
Pensionati egoisti che sminuiscono le passioni calcistiche del figlio: niente soldi per la partita dell'Hellas, 41enne prende a pugni i genitori
Ha 41 anni e non lavora e quando la scorsa domenica i genitori pensionati gli hanno rifiutato il denaro per andare allo stadio li ha picchiati.
(alla fine è finito in carcere 😂)
larena.it/territorio-veronese/…
Non lavora, vive con i genitori settantenni e pretende da loro denaro. Stando a quanto emerso è dal 2010 che li minaccia, li maltratta... Scopri di piùFabiana Marcolini (L'Arena)
reshared this
@Black_Plettro84 tu non capisci proprio: mi spieghi come può lavorare un ragazzino di 41 anni appassionato di calcio, se deve tenersi aggiornato sulle notizie che riguardano la Hellas Verona?
Si vede che non hai mai avuto una passione 😜
Verona reshared this.
-Hacker breaches Hungary's State Treasury
-Russia to mandate 40 apps on all smartphones next year
-Hackers hits Liechtenstein's business database
-AI hallucinates 55 vulnerability reports
-Pass-ta-key attack recovers passkeys from Chrome
-Data breach at UK govt investment fund
-Switzerland's IT agency was hacked
-Iran water hacks spread to 12 states
-Coinkite destroys inventory after hack
-BeaconCRM hack impacts UK charities
N: news.risky.biz/risky-bulletin-…
P: risky.biz/RBNEWS596/
In other news: Russia to mandate 40 apps on all smartphones next year; hackers hits Liechtenstein's business database; AI hallucinates 55 vulnerability reports.Catalin Cimpanu (Risky.Biz)
reshared this
Catalin Cimpanu reshared this.
Dr. Christopher Kunz
in reply to Catalin Cimpanu • • •Oh, did you read about the hidden prompt injection?
Absolutely bonkers.
Catalin Cimpanu reshared this.