Threat landscape for industrial automation systems. Q1 2026


The media in this post is not displayed to visitors. To view it, please log in.


All threats


The percentage of ICS computers on which malicious objects were blocked continued to decrease, reaching 19.6% in Q1 2026. This is the lowest value in three years, and it is 1.4 times lower than in Q2 2023.

Percentage of ICS computers on which malicious objects were blocked, Q2 2023–Q1 2026
Percentage of ICS computers on which malicious objects were blocked, Q2 2023–Q1 2026

Regionally, the percentages ranged from 9.1% in Northern Europe to 27.4% in Africa.

Regions ranked by percentage of attacked ICS computers
Regions ranked by percentage of attacked ICS computers

The percentage of ICS computers on which malicious objects were blocked increased in five regions over the quarter, most notably in Southern Europe, Northern Europe, and Russia.

In Q1 2026, Southern Europe led the way in growth for internet and email threats. The region also saw the fastest growth in spyware, as well as malicious scripts and phishing pages.

In Russia, the percentage of ICS computers on which malicious objects were blocked exceeded the figures for the previous two quarters. Russia saw an increase in the percentage for threats from the internet, and a slight increase in the figure for threats from email clients (Russia is one of three regions where this figure did not decrease).

Among the threat categories, the greatest increases were observed in the percentages for denylisted internet resources, as well as spyware (distributed in the region via the internet and email clients).

Selected industries


Biometric systems (26.4%) traditionally rank top among the industries and OT infrastructure types covered in this report in terms of the percentage of ICS computers on which malicious objects were blocked. These systems are characterized by internet access, extensive email use for data exchange and approvals (such as access granting), and, in many cases, minimal cybersecurity controls within the organizations that use these systems.

Industries ranked by the percentage of ICS computers on which malicious objects were blocked
Industries ranked by the percentage of ICS computers on which malicious objects were blocked

Biometric systems rank first among industries in terms of email threats. At the same time, unlike other industries, the percentage for email threats in biometric systems exceeds that for internet threats.

In all selected industries, the global average follows a downward trend. In Q1 2026, the percentage of ICS computers on which malicious objects were blocked increased only in the manufacturing sector — by 1.0 pp. The percentages for this industry increased across 10 regions, with the most notable increases in Western Europe, Northern Europe, and Russia.

Threat categories


In Q1 2026, Kaspersky security solutions blocked malware from 10,052 different malware families of various categories on industrial automation systems.

Over the quarter, the percentage of ICS computers on which denylisted internet resources were blocked increased (after decreasing over the previous two quarters), and there was a slight increase in the percentage for AutoCAD malware.

Percentage of ICS computers on which the activity of malicious objects from various categories was prevented
Percentage of ICS computers on which the activity of malicious objects from various categories was prevented

Malicious scripts and phishing pages (JS and HTML)


Malicious scripts and phishing pages retained their to spot among threat categories by the percentage of ICS computers on which these threats were blocked. The global average in Q1 2026 was 6.56%.

Over the quarter, the percentages increased in four regions. The most significant change was observed in Southern Europe (9.85%, +0.94 pp). The figures for malicious scripts in the region increased over three consecutive quarters.

Among the selected industries, across all regions, the highest percentages for the malicious scripts and phishing pages category were recorded for biometric systems (19.59%) and building automation (15.43%) in Southern Europe. These same industries lead in similar rankings for malicious documents and spyware.

Spyware


The percentage of ICS computers on which spyware was blocked decreased over two consecutive quarters, dropping to 3.73%. Despite the decline, spyware has ranked second among threat categories by the percentage of attacked computers for three consecutive quarters.

The percentages increased in five regions over the quarter, most notably in Southern Europe (5.46%, +0.35 pp) and Russia (2.84%, +0.24 pp).

In Southern Europe, the percentage of ICS computers on which spyware was blocked increased in all the selected industries except manufacturing. The greatest increase was observed in biometric systems.

Among the selected industries, the highest percentage of spyware in Russia was recorded in biometric systems. That said, the percentage of ICS computers on which spyware was blocked increased in all industries in the region except construction. The percentage figure has been increasing for two consecutive quarters in the oil and gas industry (by a factor of 1.63 over six months), and for three consecutive quarters in engineering and ICS integration, as well as electric power. In the remaining sectors, the values have been fluctuating.

Percentage of ICS computers on which spyware was blocked in various industries in Russia, Q3 2025–Q1 2026
Percentage of ICS computers on which spyware was blocked in various industries in Russia, Q3 2025–Q1 2026

Denylisted internet resources


The percentage of ICS computers on which denylisted internet resources were blocked increased to 3.54%.

The most notable increase over the quarter occurred in Southeast Asia (4.58%, +0.65 pp). Among the industries in the region, the highest percentage figures for this threat category were recorded in electric power and construction. Over the quarter, the largest increases in percentages figures were observed in the electric power and manufacturing industries.

In North America (Canada), denylisted internet resources (2.14%) showed the greatest increase among all categories — by a factor of 1.22.

Among the selected industries across all regions, the highest percentage figures for the denylisted internet resources category were in the electric power (7.11%) and construction (6.25%) industries in Southeast Asia.

Malicious documents (Microsoft Office + PDF)


The percentage figure for this category decreased over two consecutive quarters, reaching its lowest value (1.56%) for the entire period of observations in Q1 2026. It increased just in two regions: Australia and New Zealand (1.12%, +0.04 pp), and Russia (0.62%, +0.01 pp).

Among the selected industries across all regions, the highest percentages for malicious documents were recorded for biometric systems (9.02%) and building automation (6.97%) in Southern Europe. These same industries also lead in similar rankings for malicious scripts and spyware.

Ransomware


The percentage of ICS computers on which ransomware was blocked has decreased for two consecutive quarters, dropping to 0.14%. This is the lowest value among all categories.

The percentage increased in two regions: North America (Canada) (0.11%, +0.04 pp) and slightly in Northern Europe (0.06%, +0.01 pp).

Among the selected industries across all regions, the highest percentages for ransomware were recorded in the oil and gas and manufacturing industries (0.92% and 0.65%, respectively) in Central Asia and the South Caucasus, and in biometric systems (0.89%) in Russia.

Miners in the form of executable files for Windows


The percentage of ICS computers on which miners in the form of executable files for Windows were blocked decreased to 0.59%.

The percentage increased in seven regions. The largest increase was observed in Africa (0.63%, +0.16 pp). Among the selected industries, the largest increases in the region were in the manufacturing and oil and gas industries.

Among the selected industries across all regions, the highest percentages for miners in the form of executable files were recorded in construction (1.99%), biometric systems (1.98%), and the oil and gas industry (1.97%) in Central Asia and the South Caucasus.

Web miners


The percentage of ICS computers on which web miners were blocked has been declining for a year, and in Q1 2026, it reached the lowest value for the entire period under review (0.22%).

At the same time, the percentage increased in seven regions. The largest increases were observed in South Asia (0.28%, +0.11 pp), the Middle East (0.31%, +0.09 pp), and Africa (0.34%, +0.08 pp). Despite the increases, the percentages in these regions for Q1 2026 did not exceed those observed in 2023–2024 and in Q1 2025.

Among the selected industries across all regions, the highest percentages for web miners were recorded for biometric systems (0.97%) in Russia. Biometric systems in South Asia (0.79%) ranked second, and the electric power sector in Southeast Asia (0.76%) ranked third.

Worms


The percentage of ICS computers on which worms were blocked decreased to 1.33%.

The percentage decreased across all regions following an increase in the previous quarter (due to a wave of phishing attacks that distributed the Backdoor.MSIL.XWorm backdoor worm across all regions of the world).

Among the selected industries across all regions, the highest percentage figure for worms was recorded for biometric systems (4.80%) in Central Asia and the South Caucasus. Two industries in Africa – biometric systems (4.04%) and electric power (3.53%) – took the second and third spots, respectively.

Viruses


The percentage of ICS computers on which viruses were blocked decreased to 1.31%.

The top 3 regions by this figure remained the same: Southeast Asia (6.11%, first by a wide margin), Africa (4.15%), and East Asia (2.97%). These same regions are also among the leaders by the percentage of systems affected by AutoCAD malware. The largest increase in this figure was observed in Africa (+0.41 pp).

Among the selected industries across all regions, the highest percentages for viruses were recorded in the construction industry (6.35%) and building automation (5.50%) in Southeast Asia.

Malware for AutoCAD


The percentage of ICS computers on which malware for AutoCAD was blocked increased to 0.30%.

The most notable increase over the quarter was observed in Africa, with the region’s percentage figure rising by 0.47 pp, a very significant increase for this category, and almost doubling (to 0.91%).

Among the selected industries across all regions, the highest percentages for AutoCAD malware were recorded in the construction industry in East Asia (5.58%) and Southeast Asia (3.87%).

Main threat sources


In Q1 2026, the average percentages across all threat sources, except threats from the internet, decreased globally.

Percentage of ICS computers on which malicious objects from various sources were blocked
Percentage of ICS computers on which malicious objects from various sources were blocked

Internet


The percentage of ICS computers on which threats from the internet were blocked increased to 7.88%. However, over the past three years, the percentage figure for internet threats has followed a downward trend.

The largest increases in the percentages were recorded in Southern Europe (8.59%, +0.59 pp), Southeast Asia (10.16%, +0.55 pp), and Northern Europe (4.47%, +0.51 pp).

Among the selected industries across all regions, the highest percentages for threats from the internet were recorded in electric power (13.16%) and construction (12.55%) in Southeast Asia, and in the engineering and ICS integration sector (12.33%) in South Asia.

Email clients


The percentage of ICS computers on which threats delivered via email clients were blocked decreased to 2.59%. This is a three-year low.

The percentage of this threat source increased in three regions: Southern Europe (6.54%, +0.2 pp), East Asia (1.5%, +0.09 pp), and slightly in Russia (0.7%, +0.04 pp).

Among the selected industries across all regions, the highest percentages for email threats were recorded for biometric systems (19.78%) and building automation (12.34%) in Southern Europe. In these two industries, the percentage of ICS computers on which email threats are blocked is higher than the percentage for threats from the internet. A similar situation was observed in two other instances, both in biometric systems (in South America and Southeast Asia).

Removable media


The percentage of ICS computers on which threats were detected when connecting removable media continued to decrease, reaching its lowest value for the period under review (0.26%).

Among the selected industries across all regions, the highest percentages for removable media threats blocked on ICS computers were observed in the electric power sector in Central Asia and the South Caucasus (1.45%), East Asia (1.34%), and Africa (1.16%).

Network folders


The percentage of ICS computers on which threats are blocked in network folders is steadily decreasing. In Q1 2026, it was the lowest for the period under review (0.029%).

East Asia has traditionally led by a wide margin. The percentage for East Asia (0.135%) is 27 times higher than the lowest regional value (recorded in Northern Europe).

The largest increases in the percentages for threats from network folders were observed in Africa (0.037%, +0.006 pp) and South America (0.013%, +0.006 pp).
Among the selected industries across all regions, the construction industry in East Asia, at 0.36%, holds the top positions in the ranking by the percentage of ICS computers on which threats are blocked in network folders.

For more information on industrial threats see the full version of the report.


securelist.com/industrial-thre…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Vi costringeremo a studiare! L’Europa è prossima a vietare i social network ai minori

📌 Link all'articolo : redhotcyber.com/post/vi-costri…

A cura di Silvia Felici

#redhotcyber #news #regolesocial #minori #socialnetwork #commissioneue #etaminima

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Hidden #Tenda Router #Backdoor Grants Admin Access, No Patch Available
securityaffairs.com/194878/sec…
#securityaffairs #hacking

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Leonardo Tamiano al @devconf@poliversity.it: per migliorare un sistema dobbiamo imparare a criticarlo...

Il progetto Esadecimale nasce per offrire il migliore contenitore di didattica informatica online presente in tutto il territorio italiano

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM

Questa voce è stata modificata (1 mese fa)

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Leonardo Tamiano al @devconf@poliversity.it presenta "Voglio migliorare la didattica dell'Informatica"

"Le astrazioni devono essere aperte, esplorate e ricostruite per formare persone in grado di costruire le astrazioni del futuro"

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM

Questa voce è stata modificata (1 mese fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

COME

GODO

@calcio
#unocalcio
#MondialiDiCalcio2026

Questa voce è stata modificata (1 mese fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

@inmarvinwetrust al @devconf@poliversity.it: L'hacking e l'open-source condividono tantissimi valori

Curiosità, trasparenza, condivisione della conoscenza, piacere nell'aiutare, altra curiosità

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM

Questa voce è stata modificata (1 mese fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

GNOME Papers arriva su Windows con un porting nativo


GNOME Papers arriva anche su Windows grazie a un porting nativo che mantiene le funzionalità del visualizzatore di documenti GNOME
L'articolo GNOME Papers arriva su Windows con un porting nativo proviene da Linux Easy.
E' vietato riprodurre questo articolo senza autorizzazione.
Questo feed RSS è destinato ai lettori, non agli scraper o aggregatori.
Linux Easy viene rilasciato con Licenza CC BY-N...

🔗 Leggi il post completo

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Vi siete sentiti in colpa?


"Hai democratizzato il #ransomware. Prego." Il secondo intervento al @devconf@poliversity.it è di @signorina37

20 minuti sul paradosso più scomodo della cultura software: gli stessi principi che hanno abbassato le barriere per costruire hanno abbassato anche quelle per attaccare - e per farci sentire anche un po’ in colpa ;)

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM


reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Le icone sono carine e coccolone nelle slide originali!!!!


Il problema che abbiamo contribuito a creare, inconsapevolmente, con le migliori intenzioni, può essere mitigato. Con le stesse competenze.

@signorina37 al @devconf@poliversity.it: threat modeling nel codice 5 minuti prima del rilascio: come potrebbe essere abusato?
Le dipendenze come attack surface: conosci le tue dipendenze?
Segui il threat landscape. Non per paranoia, per contesto.

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM


reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Ecco @inmarvinwetrust al @devconf@poliversity.it: #Hacking the developer: Attacchi reali nella toolchain open source

Oggi gli attaccanti puntano agli sviluppatori perché la toolchain moderna vive di fiducia ed eseguiamo continuamente codice di terze parti

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM

Questa voce è stata modificata (1 mese fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

"Ma cosa vuoi che importino i miei dati..." @signorina37 la tocca piano al @devconf@poliversity.it

I dati sensibili sono il patrimonio dei gruppi #Ransomware

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM

Questa voce è stata modificata (1 mese fa)

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

AI-Generated #Malware Powers New #Armored #Likho APT Campaign
securityaffairs.com/194854/apt…
#securityaffairs #hacking #AI #APT

The media in this post is not displayed to visitors. To view it, please log in.

Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup


@Informatica (Italy e non Italy)
JFrog scopre una nuova campagna di supply chain attribuita a Lazarus/Contagious Interview: pacchetti npm che imitano rollup-plugin-polyfill-node nascondono un impianto completo con accesso remoto, furto di wallet crypto e monitoraggio della


Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup


Si parla di:
Toggle

Sei pacchetti npm, un nome quasi identico a un progetto scaricato oltre un milione di volte al mese, e in fondo alla catena un impianto capace di aprire sessioni SSH, leggere la clipboard e rovistare tra i wallet crypto della vittima. È l’ultima campagna di supply chain attribuita a gruppi legati alla Corea del Nord, documentata da JFrog Security Research il 30 giugno e ancora attiva nei repository pubblici a inizio luglio. Non è un incidente isolato: è l’ennesima iterazione di una macchina offensiva, quella riconducibile all’ecosistema Lazarus/Contagious Interview, che negli ultimi anni ha trasformato l’npm registry in un vettore di spionaggio e furto di criptovalute su scala industriale.

Un travestimento quasi perfetto


I ricercatori di JFrog hanno individuato due pacchetti “entry point”, rollup-packages-polyfill-core e rollup-runtime-polyfill-core, costruiti per somigliare in tutto e per tutto al legittimo rollup-plugin-polyfill-node: stesso tipo di README (“A modern Node.js polyfill for your Rollup bundle”), stesso link a repository e homepage puntati al progetto originale su GitHub, persino porzioni di codice del plugin reale copiate all’interno del pacchetto malevolo prima della logica dannosa. Il progetto legittimo conta circa 295.000 download settimanali e oltre 1,2 milioni nell’ultimo mese: un bersaglio ideale per un attacco che punta sulla somiglianza superficiale, non sul typosquatting grossolano.

Il dettaglio tecnico più rilevante è che solo l’entry point CommonJS (dist/index.js) contiene la backdoor: le versioni ESM restano pulite, un accorgimento che complica le analisi automatiche basate su un singolo file di ingresso.

La catena d’infezione, passo dopo passo


All’importazione del pacchetto, una funzione dal nome innocuo (ValidateSvgModule) decodifica una stringa base64 che nasconde il comando npm install swift-parse-stream --no-save --silent --no-audit --no-fund, eseguito in silenzio tramite child_process.spawn. Il secondo pacchetto, quirky-token, viene installato allo stesso modo dal gemello rollup-runtime-polyfill-core.

Questi pacchetti di secondo stadio si presentano come utility di sanitizzazione SVG, e in gran parte lo sono davvero: rimuovono tag <script>, minificano il markup. Ma in coda al file, una funzione getPlugin() effettua una richiesta verso un endpoint su jsonkeeper.com, estrae un campo JSON chiamato model e lo passa direttamente a eval(). Il codice malevolo, quindi, non risiede mai nei file pubblicati sul registry: vive su un servizio di hosting JSON esterno, invisibile a qualunque analisi statica del pacchetto.

Il payload recuperato da JSONKeeper effettua per primo un controllo ambientale, uscendo silenziosamente se rileva variabili tipiche di Codespaces, CodeSandbox, Vercel, AWS Lambda, Google Cloud, Azure Functions, Docker, Render o sandbox di analisi — un chiaro tentativo di colpire solo workstation di sviluppatori reali ed evitare l’esposizione in ambienti di test automatizzati. Superato il controllo, installa axios e socket.io-client e scarica da un IP grezzo (216.126.236.244) un blob cifrato in AES-256-CBC (chiave derivata via scryptSync), lo decifra, lo scrive in una directory temporanea come file pack e lo esegue con node pack.

Controllo remoto, furto wallet e sorveglianza della clipboard


Il modulo pack altro non è che un loader per almeno quattro componenti distinti, ricostruiti da JFrog in ambiente sandbox: scdata.js, un modulo di accesso remoto che installa ssh2, node-pty e librerie di cattura schermo/input, offrendo all’operatore sessioni terminali interattive (PowerShell su Windows, zsh altrove), sessioni SSH, screenshot, movimento del mouse e digitazione simulata tramite @nut-tree-fork/nut-js; ldata.js, dedicato al furto di dati da browser e wallet crypto, che tenta l’esfiltrazione di file come Login Data, Web Data e lo storage delle estensioni di wallet noti (incluso MetaMask, identificato tramite i suoi ID di estensione); un file collector che scandaglia il filesystem alla ricerca di chiavi SSH, file .env, cronologia di editor come VS Code, Cursor e Windsurf, e directory di configurazione di strumenti AI (.claude, .gemini, .cursor); infine un modulo di monitoraggio della clipboard, che invia ogni nuovo contenuto copiato — password, seed phrase, token — a un endpoint dedicato.

La combinazione di queste capacità va ben oltre il semplice furto di credenziali una tantum: garantisce all’attaccante un accesso interattivo e persistente alla macchina compromessa, tipico degli impianti usati da attori state-sponsored per operazioni di raccolta informativa prolungata, non solo per il cash-out rapido tipico del cybercrime finanziario puro.

Il contesto: non è la prima volta


Questa campagna si inserisce in un pattern già documentato. Ad aprile 2026 la società Panther aveva descritto una campagna sostenuta con 108 pacchetti npm malevoli distribuiti in 261 versioni, veicolo dei malware BeaverTail e OtterCookie, entrambi associati al cluster Contagious Interview — l’insieme di operazioni nordcoreane che si finge selezione del personale per convincere sviluppatori a clonare repository infetti come parte di un finto colloquio tecnico. Nello stesso periodo, Google aveva collegato attori nordcoreani anche a un dirottamento di un progetto open source molto diffuso, portato a termine dopo settimane di lavoro di ingegneria sociale ai danni del maintainer. Il filo conduttore è sempre lo stesso: colpire la fiducia implicita che sviluppatori e pipeline CI/CD ripongono nelle dipendenze open source.

Due righe per i difensori


Per i team di sicurezza e gli sviluppatori, la lezione operativa è chiara: la somiglianza del nome non è un indicatore affidabile di legittimità, e i controlli automatici basati su pattern di typosquotting classico (distanza di edit, caratteri sostituiti) non intercettano questo tipo di masquerading semantico. Chi ha installato uno dei pacchetti elencati dovrebbe considerare la macchina compromessa, ruotare tutte le credenziali (npm, GitHub, cloud, SSH, wallet) e verificare la presenza di processi o file residui nelle directory temporanee. Vale la pena ricordare che gran parte della logica dannosa non è mai stata pubblicata sul registry npm: bloccare gli indicatori di rete elencati sotto è quindi essenziale quanto rimuovere i pacchetti stessi.

Indicatori di compromissione

Pacchetti npm malevoli:
rollup-packages-polyfill-core
rollup-runtime-polyfill-core
swift-parse-stream
quirky-token
react-icon-svgs
rollup-plugin-polyfill-connect
Indicatori di rete:
hxxps[:]//www[.]jsonkeeper[.]com/b/3P9BF
hxxp[:]//216[.]126[.]236[.]244/api/service/98cb54c0b4ac259d30c9c1ca1ae87c68
hxxp[:]//216[.]126[.]236[.]244/api/service/makelog
hxxp[:]//216[.]126[.]236[.]244/api/service/process/
hxxp[:]//216[.]126[.]236[.]244:4801
hxxp[:]//216[.]126[.]236[.]244:4806/upload
hxxp[:]//216[.]126[.]236[.]244:4809/upload
hxxp[:]//216[.]126[.]236[.]244:4809/cldbs
Indicatori host:
/pack
/scdata
/ldata
vhost.ctl
Comandi/comportamenti sospetti:
npm install swift-parse-stream --no-save --silent --no-audit --no-fund
npm install quirky-token --no-save --silent --no-audit --no-fund
node pack
node scdata
node ldata

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Il problema che abbiamo contribuito a creare, inconsapevolmente, con le migliori intenzioni, può essere mitigato. Con le stesse competenze.

@signorina37 al @devconf@poliversity.it: threat modeling nel codice 5 minuti prima del rilascio: come potrebbe essere abusato?
Le dipendenze come attack surface: conosci le tue dipendenze?
Segui il threat landscape. Non per paranoia, per contesto.

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM

Questa voce è stata modificata (1 mese fa)

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

"Hai democratizzato il #ransomware. Prego." Il secondo intervento al @devconf@poliversity.it è di @signorina37

20 minuti sul paradosso più scomodo della cultura software: gli stessi principi che hanno abbassato le barriere per costruire hanno abbassato anche quelle per attaccare - e per farci sentire anche un po’ in colpa ;)

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM

Questa voce è stata modificata (1 mese fa)

reshared this

Why the NES Put Out a Wobbly Picture


The media in this post is not displayed to visitors. To view it, please log in.

The NTSC television standard is a masterpiece of mid-century engineering, to pack a color image into the transmission bandwidth of a monochrome one, and to do so while maintaining backward compatibility with earlier monochrome TV sets. In terms of its timings and choice of sync and carrier frequencies it’s elegantly thought out for maximum quality on a 1950s round-CRT color TV set.

The trouble is, that while the standards are exacting, the receivers are quite forgiving, and will display adequately even with substantially off-spec video. [Nicole Express] is here with an in-depth examination of a time when that was pushed just a little bit too far, explaining why the Nintendo Entertainment System (NES) displayed wobbly color images.

We’re treated to a run-through of the NTSC standard itself, and a look at how some of the other consoles and home computers of that era either had similar problems, or managed to avoid them. The key lies in the exacting timing required to achieve perfect interlacing, and the NES’s use of a single crystal to provide all the clocks. The dot clock on adjacent frames was almost right, but not quite, leading to a side-to-side wobble that while barely perceptible, was exacerbated by some graphics. It’s a fascinating read.

We’ve looked at composite video in detail in the past.


NES image: JCD1981NL, CC BY 3.0.


hackaday.com/2026/07/07/why-th…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Due giornate di talk, condivisione e incontri. @lorenzodm conclude la presentazione del #DevConf

Talk tecnici: interventi su progetti e tecnologie open source
Coding dal vivo: si da modo di sviluppare concretamente le proprie idee
Presentare un progetto: uno spazio per mostrare ciò che hai creato
Networking: conosci altri sviluppatori e appassionati
Recruiting: aziende presenti cercano nuovi talenti
Community: entri a far parte della rete open source italiana

@devconf

youtube.com/live/OwU4nQzD3jM

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Il problema: l’Italia è indietro. L'apertura del @devconf@poliversity.it con @lorenzodm

Dipendenza dall’estero: usiamo soprattutto software proprietario di grandi aziende straniere.
Poca cultura del codice aperto: meno progetti, meno community, meno contributi rispetto ad altri Paesi.
Anche la PA ne risente: la Pubblica Amministrazione potrebbe risparmiare e guadagnare trasparenza
con l’open source.

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM

Questa voce è stata modificata (1 mese fa)

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Cos'è il DevConf e perché è necessario in Italia? L'apertura dei lavori del @devconf@poliversity.it a cura di @lorenzodm

La prima conferenza italiana dedicata agli sviluppatori e ai creatori di codice open source.
Un evento nazionale, tutto italiano, organizzato da @boostmedia che riunisce chi scrive software libero per imparare, collaborare e crescere insieme

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM

reshared this

in reply to Lorenzo DM

The media in this post is not displayed to visitors. To view it, please go to the original post.

Ecco i lavori più avanzati sul tema dei circuiti integrati liberi verificabili dagli utenti finali, realizzati negli ultimi anni dal piccolo team internazionale di hacker della piccola federazione crypto-anarchica di cui faccio parte e nella quale saresti il benvenuto, poiché al momento non abbiamo contributori italiani :

informapirata ⁂ reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Alle 10.00 avrà inizio il #DevConf: due giorni di interventi sullo sviluppo di codice open source e su alcune delle applicazioni più interessanti

L'evento @devconf@poliversity.it è stato organizzato da @boostmedia grazie al contributo di @lorenzodm @redflegias e @adriano_morselli dello staff di @ufficiozero

Se non potete seguire la diretta, potete seguire gli aggiornamenti sul gruppo @devconf@citiverse.it che può essere seguito dal vostro account del Fediverso

youtube.com/live/OwU4nQzD3jM

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Arriva il Phantom Squatting: come i black hacker sfruttano le allucinazioni degli LLM

📌 Link all'articolo : redhotcyber.com/post/arriva-il…

A cura di Luigi Zullo

#redhotcyber #news #cybersecurity #hacking #malware #ransomware #phishingscam

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup
#CyberSecurity
insicurezzadigitale.com/lazaru…

@informatica


Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup


Si parla di:
Toggle

Sei pacchetti npm, un nome quasi identico a un progetto scaricato oltre un milione di volte al mese, e in fondo alla catena un impianto capace di aprire sessioni SSH, leggere la clipboard e rovistare tra i wallet crypto della vittima. È l’ultima campagna di supply chain attribuita a gruppi legati alla Corea del Nord, documentata da JFrog Security Research il 30 giugno e ancora attiva nei repository pubblici a inizio luglio. Non è un incidente isolato: è l’ennesima iterazione di una macchina offensiva, quella riconducibile all’ecosistema Lazarus/Contagious Interview, che negli ultimi anni ha trasformato l’npm registry in un vettore di spionaggio e furto di criptovalute su scala industriale.

Un travestimento quasi perfetto


I ricercatori di JFrog hanno individuato due pacchetti “entry point”, rollup-packages-polyfill-core e rollup-runtime-polyfill-core, costruiti per somigliare in tutto e per tutto al legittimo rollup-plugin-polyfill-node: stesso tipo di README (“A modern Node.js polyfill for your Rollup bundle”), stesso link a repository e homepage puntati al progetto originale su GitHub, persino porzioni di codice del plugin reale copiate all’interno del pacchetto malevolo prima della logica dannosa. Il progetto legittimo conta circa 295.000 download settimanali e oltre 1,2 milioni nell’ultimo mese: un bersaglio ideale per un attacco che punta sulla somiglianza superficiale, non sul typosquatting grossolano.

Il dettaglio tecnico più rilevante è che solo l’entry point CommonJS (dist/index.js) contiene la backdoor: le versioni ESM restano pulite, un accorgimento che complica le analisi automatiche basate su un singolo file di ingresso.

La catena d’infezione, passo dopo passo


All’importazione del pacchetto, una funzione dal nome innocuo (ValidateSvgModule) decodifica una stringa base64 che nasconde il comando npm install swift-parse-stream --no-save --silent --no-audit --no-fund, eseguito in silenzio tramite child_process.spawn. Il secondo pacchetto, quirky-token, viene installato allo stesso modo dal gemello rollup-runtime-polyfill-core.

Questi pacchetti di secondo stadio si presentano come utility di sanitizzazione SVG, e in gran parte lo sono davvero: rimuovono tag <script>, minificano il markup. Ma in coda al file, una funzione getPlugin() effettua una richiesta verso un endpoint su jsonkeeper.com, estrae un campo JSON chiamato model e lo passa direttamente a eval(). Il codice malevolo, quindi, non risiede mai nei file pubblicati sul registry: vive su un servizio di hosting JSON esterno, invisibile a qualunque analisi statica del pacchetto.

Il payload recuperato da JSONKeeper effettua per primo un controllo ambientale, uscendo silenziosamente se rileva variabili tipiche di Codespaces, CodeSandbox, Vercel, AWS Lambda, Google Cloud, Azure Functions, Docker, Render o sandbox di analisi — un chiaro tentativo di colpire solo workstation di sviluppatori reali ed evitare l’esposizione in ambienti di test automatizzati. Superato il controllo, installa axios e socket.io-client e scarica da un IP grezzo (216.126.236.244) un blob cifrato in AES-256-CBC (chiave derivata via scryptSync), lo decifra, lo scrive in una directory temporanea come file pack e lo esegue con node pack.

Controllo remoto, furto wallet e sorveglianza della clipboard


Il modulo pack altro non è che un loader per almeno quattro componenti distinti, ricostruiti da JFrog in ambiente sandbox: scdata.js, un modulo di accesso remoto che installa ssh2, node-pty e librerie di cattura schermo/input, offrendo all’operatore sessioni terminali interattive (PowerShell su Windows, zsh altrove), sessioni SSH, screenshot, movimento del mouse e digitazione simulata tramite @nut-tree-fork/nut-js; ldata.js, dedicato al furto di dati da browser e wallet crypto, che tenta l’esfiltrazione di file come Login Data, Web Data e lo storage delle estensioni di wallet noti (incluso MetaMask, identificato tramite i suoi ID di estensione); un file collector che scandaglia il filesystem alla ricerca di chiavi SSH, file .env, cronologia di editor come VS Code, Cursor e Windsurf, e directory di configurazione di strumenti AI (.claude, .gemini, .cursor); infine un modulo di monitoraggio della clipboard, che invia ogni nuovo contenuto copiato — password, seed phrase, token — a un endpoint dedicato.

La combinazione di queste capacità va ben oltre il semplice furto di credenziali una tantum: garantisce all’attaccante un accesso interattivo e persistente alla macchina compromessa, tipico degli impianti usati da attori state-sponsored per operazioni di raccolta informativa prolungata, non solo per il cash-out rapido tipico del cybercrime finanziario puro.

Il contesto: non è la prima volta


Questa campagna si inserisce in un pattern già documentato. Ad aprile 2026 la società Panther aveva descritto una campagna sostenuta con 108 pacchetti npm malevoli distribuiti in 261 versioni, veicolo dei malware BeaverTail e OtterCookie, entrambi associati al cluster Contagious Interview — l’insieme di operazioni nordcoreane che si finge selezione del personale per convincere sviluppatori a clonare repository infetti come parte di un finto colloquio tecnico. Nello stesso periodo, Google aveva collegato attori nordcoreani anche a un dirottamento di un progetto open source molto diffuso, portato a termine dopo settimane di lavoro di ingegneria sociale ai danni del maintainer. Il filo conduttore è sempre lo stesso: colpire la fiducia implicita che sviluppatori e pipeline CI/CD ripongono nelle dipendenze open source.

Due righe per i difensori


Per i team di sicurezza e gli sviluppatori, la lezione operativa è chiara: la somiglianza del nome non è un indicatore affidabile di legittimità, e i controlli automatici basati su pattern di typosquotting classico (distanza di edit, caratteri sostituiti) non intercettano questo tipo di masquerading semantico. Chi ha installato uno dei pacchetti elencati dovrebbe considerare la macchina compromessa, ruotare tutte le credenziali (npm, GitHub, cloud, SSH, wallet) e verificare la presenza di processi o file residui nelle directory temporanee. Vale la pena ricordare che gran parte della logica dannosa non è mai stata pubblicata sul registry npm: bloccare gli indicatori di rete elencati sotto è quindi essenziale quanto rimuovere i pacchetti stessi.

Indicatori di compromissione

Pacchetti npm malevoli:
rollup-packages-polyfill-core
rollup-runtime-polyfill-core
swift-parse-stream
quirky-token
react-icon-svgs
rollup-plugin-polyfill-connect
Indicatori di rete:
hxxps[:]//www[.]jsonkeeper[.]com/b/3P9BF
hxxp[:]//216[.]126[.]236[.]244/api/service/98cb54c0b4ac259d30c9c1ca1ae87c68
hxxp[:]//216[.]126[.]236[.]244/api/service/makelog
hxxp[:]//216[.]126[.]236[.]244/api/service/process/
hxxp[:]//216[.]126[.]236[.]244:4801
hxxp[:]//216[.]126[.]236[.]244:4806/upload
hxxp[:]//216[.]126[.]236[.]244:4809/upload
hxxp[:]//216[.]126[.]236[.]244:4809/cldbs
Indicatori host:
/pack
/scdata
/ldata
vhost.ctl
Comandi/comportamenti sospetti:
npm install swift-parse-stream --no-save --silent --no-audit --no-fund
npm install quirky-token --no-save --silent --no-audit --no-fund
node pack
node scdata
node ldata

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Januscape: 16-Year-Old #Linux KVM Bug Enables Cloud VM Escape Attacks
securityaffairs.com/194868/sec…
#securityaffairs #hacking #AI
Cybersecurity & cyberwarfare ha ricondiviso questo.

Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup


JFrog scopre una nuova campagna di supply chain attribuita a Lazarus/Contagious Interview: pacchetti npm che imitano rollup-plugin-polyfill-node nascondono un impianto completo con accesso remoto, furto di wallet crypto e monitoraggio della clipboard.
The media in this post is not displayed to visitors. To view it, please go to the original post.

Si parla di:
Toggle

Sei pacchetti npm, un nome quasi identico a un progetto scaricato oltre un milione di volte al mese, e in fondo alla catena un impianto capace di aprire sessioni SSH, leggere la clipboard e rovistare tra i wallet crypto della vittima. È l’ultima campagna di supply chain attribuita a gruppi legati alla Corea del Nord, documentata da JFrog Security Research il 30 giugno e ancora attiva nei repository pubblici a inizio luglio. Non è un incidente isolato: è l’ennesima iterazione di una macchina offensiva, quella riconducibile all’ecosistema Lazarus/Contagious Interview, che negli ultimi anni ha trasformato l’npm registry in un vettore di spionaggio e furto di criptovalute su scala industriale.

Un travestimento quasi perfetto


I ricercatori di JFrog hanno individuato due pacchetti “entry point”, rollup-packages-polyfill-core e rollup-runtime-polyfill-core, costruiti per somigliare in tutto e per tutto al legittimo rollup-plugin-polyfill-node: stesso tipo di README (“A modern Node.js polyfill for your Rollup bundle”), stesso link a repository e homepage puntati al progetto originale su GitHub, persino porzioni di codice del plugin reale copiate all’interno del pacchetto malevolo prima della logica dannosa. Il progetto legittimo conta circa 295.000 download settimanali e oltre 1,2 milioni nell’ultimo mese: un bersaglio ideale per un attacco che punta sulla somiglianza superficiale, non sul typosquatting grossolano.

Il dettaglio tecnico più rilevante è che solo l’entry point CommonJS (dist/index.js) contiene la backdoor: le versioni ESM restano pulite, un accorgimento che complica le analisi automatiche basate su un singolo file di ingresso.

La catena d’infezione, passo dopo passo


All’importazione del pacchetto, una funzione dal nome innocuo (ValidateSvgModule) decodifica una stringa base64 che nasconde il comando npm install swift-parse-stream --no-save --silent --no-audit --no-fund, eseguito in silenzio tramite child_process.spawn. Il secondo pacchetto, quirky-token, viene installato allo stesso modo dal gemello rollup-runtime-polyfill-core.

Questi pacchetti di secondo stadio si presentano come utility di sanitizzazione SVG, e in gran parte lo sono davvero: rimuovono tag <script>, minificano il markup. Ma in coda al file, una funzione getPlugin() effettua una richiesta verso un endpoint su jsonkeeper.com, estrae un campo JSON chiamato model e lo passa direttamente a eval(). Il codice malevolo, quindi, non risiede mai nei file pubblicati sul registry: vive su un servizio di hosting JSON esterno, invisibile a qualunque analisi statica del pacchetto.

Il payload recuperato da JSONKeeper effettua per primo un controllo ambientale, uscendo silenziosamente se rileva variabili tipiche di Codespaces, CodeSandbox, Vercel, AWS Lambda, Google Cloud, Azure Functions, Docker, Render o sandbox di analisi — un chiaro tentativo di colpire solo workstation di sviluppatori reali ed evitare l’esposizione in ambienti di test automatizzati. Superato il controllo, installa axios e socket.io-client e scarica da un IP grezzo (216.126.236.244) un blob cifrato in AES-256-CBC (chiave derivata via scryptSync), lo decifra, lo scrive in una directory temporanea come file pack e lo esegue con node pack.

Controllo remoto, furto wallet e sorveglianza della clipboard


Il modulo pack altro non è che un loader per almeno quattro componenti distinti, ricostruiti da JFrog in ambiente sandbox: scdata.js, un modulo di accesso remoto che installa ssh2, node-pty e librerie di cattura schermo/input, offrendo all’operatore sessioni terminali interattive (PowerShell su Windows, zsh altrove), sessioni SSH, screenshot, movimento del mouse e digitazione simulata tramite @nut-tree-fork/nut-js; ldata.js, dedicato al furto di dati da browser e wallet crypto, che tenta l’esfiltrazione di file come Login Data, Web Data e lo storage delle estensioni di wallet noti (incluso MetaMask, identificato tramite i suoi ID di estensione); un file collector che scandaglia il filesystem alla ricerca di chiavi SSH, file .env, cronologia di editor come VS Code, Cursor e Windsurf, e directory di configurazione di strumenti AI (.claude, .gemini, .cursor); infine un modulo di monitoraggio della clipboard, che invia ogni nuovo contenuto copiato — password, seed phrase, token — a un endpoint dedicato.

La combinazione di queste capacità va ben oltre il semplice furto di credenziali una tantum: garantisce all’attaccante un accesso interattivo e persistente alla macchina compromessa, tipico degli impianti usati da attori state-sponsored per operazioni di raccolta informativa prolungata, non solo per il cash-out rapido tipico del cybercrime finanziario puro.

Il contesto: non è la prima volta


Questa campagna si inserisce in un pattern già documentato. Ad aprile 2026 la società Panther aveva descritto una campagna sostenuta con 108 pacchetti npm malevoli distribuiti in 261 versioni, veicolo dei malware BeaverTail e OtterCookie, entrambi associati al cluster Contagious Interview — l’insieme di operazioni nordcoreane che si finge selezione del personale per convincere sviluppatori a clonare repository infetti come parte di un finto colloquio tecnico. Nello stesso periodo, Google aveva collegato attori nordcoreani anche a un dirottamento di un progetto open source molto diffuso, portato a termine dopo settimane di lavoro di ingegneria sociale ai danni del maintainer. Il filo conduttore è sempre lo stesso: colpire la fiducia implicita che sviluppatori e pipeline CI/CD ripongono nelle dipendenze open source.

Due righe per i difensori


Per i team di sicurezza e gli sviluppatori, la lezione operativa è chiara: la somiglianza del nome non è un indicatore affidabile di legittimità, e i controlli automatici basati su pattern di typosquotting classico (distanza di edit, caratteri sostituiti) non intercettano questo tipo di masquerading semantico. Chi ha installato uno dei pacchetti elencati dovrebbe considerare la macchina compromessa, ruotare tutte le credenziali (npm, GitHub, cloud, SSH, wallet) e verificare la presenza di processi o file residui nelle directory temporanee. Vale la pena ricordare che gran parte della logica dannosa non è mai stata pubblicata sul registry npm: bloccare gli indicatori di rete elencati sotto è quindi essenziale quanto rimuovere i pacchetti stessi.

Indicatori di compromissione

Pacchetti npm malevoli:
rollup-packages-polyfill-core
rollup-runtime-polyfill-core
swift-parse-stream
quirky-token
react-icon-svgs
rollup-plugin-polyfill-connect
Indicatori di rete:
hxxps[:]//www[.]jsonkeeper[.]com/b/3P9BF
hxxp[:]//216[.]126[.]236[.]244/api/service/98cb54c0b4ac259d30c9c1ca1ae87c68
hxxp[:]//216[.]126[.]236[.]244/api/service/makelog
hxxp[:]//216[.]126[.]236[.]244/api/service/process/
hxxp[:]//216[.]126[.]236[.]244:4801
hxxp[:]//216[.]126[.]236[.]244:4806/upload
hxxp[:]//216[.]126[.]236[.]244:4809/upload
hxxp[:]//216[.]126[.]236[.]244:4809/cldbs
Indicatori host:
/pack
/scdata
/ldata
vhost.ctl
Comandi/comportamenti sospetti:
npm install swift-parse-stream --no-save --silent --no-audit --no-fund
npm install quirky-token --no-save --silent --no-audit --no-fund
node pack
node scdata
node ldata

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

☕ CYBERBRIEFING — Martedì 7 luglio 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

363 – L’ONU pubblica il primo rapporto scientifico sull’AI camisanicalzolari.it/363-lonu-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

PeerTube ha 1 milione di video: la sfida a YouTube arriva dal Fediverso

#PeerTube utilizza #WebRTC e non utilizza sistemi di raccomandazione, algoritmi o annunci pubblicitari, basandosi invece sul modello che fa leva sulle donazioni dirette.

hdblog.it/android/articoli/n66…

@fediverso

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Claude sfida le Big Pharma: Anthropic userà l’IA per trovare cure alle malattie rare

📌 Link all'articolo : redhotcyber.com/post/claude-sf…

A cura di Carolina Vivianti

#redhotcyber #news #ricercascientifica #malattie #intelligenzaartificiale #farmaci #sanita

reshared this

Belt Fed Potato Cannon Spits Spuds


The media in this post is not displayed to visitors. To view it, please log in.

The gun on its bipod.

Spud guns are a staple of summertime fun for the maker set, especially on the Eagleland side of the pond, combining as they do two of our favourite things: firearms and calories. Nine out of ten Canadians agree that there’s nothing quite like a high-speed poutine– but judging by accent [Current Concept] is an American and so his potato cannon needed a little something extra that even the second amendment doesn’t protect: fully automatic firing, with a belt feed.

Like many spud guns, this one is powered by compressed air and uses PVC for both the barrel and air reservoir; unlike most spud guns, it has a steel frame holding it together, and a 3D-printed belt-feed mechanism to bring the spuds into position, with a beefy stepper motor pulling the potatoes. Of course just sticking an extra length of pipe between resivoire and barrel would just result in 80PSI potato-scented flatulence as the air escaped betwixt the gap, so a pair of piston-actuated, 3D printed fittings slides over the plastic casings in the belt that hold the spuds. It’s not a perfect seal, but video evidence suggests it’s tight enough to get the tubers flying. Finally, the whole thing was put on a bipod mount, because– uh. Look at it. It might be light enough for one man to carry, but this is clearly a crew-served weapon, even if there’s only one guy there.

Now, there are some caveats– the air reservoir is only good for one shot, so it needs to stay hooked to an air compressor to take advantage of the repeated firings. Since it has to recharge, it’s also only firing a spud every six seconds, so while the mechanism could do “full auto”, it’s actually semiautomatic in practice as nobody’s going to sit and hold the trigger that long. Finally, we must warn you that the YouTuber behind this is trying to be funny for much of the video. Some may find his delivery leaves them in stitches; others will be left cold. There is, of course, no accounting for taste.

Oddly enough, this isn’t the first automatic air gun to grace these pages. It’s also one of the weaker potato propellers, especially compared to this MAPP-gas powered monster. Hopefully [Current Concept] doesn’t see that and get any ideas for the promised revision of his belt-fed tuber tosser, or he may get a visit from the ATF– that’s the US Bureau of Alcohol, Tobacco, and Firearms, who are way less fun to deal with than the name might imply.

youtube.com/embed/K-4xhVD7WDQ?…


hackaday.com/2026/07/06/belt-f…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Pendragon: la Francia sviluppa unità robotica da combattimento autonoma per il 2027

📌 Link all'articolo : redhotcyber.com/post/pendragon…

A cura di Luigi Zullo

#redhotcyber #news #robotica #intelligenzaartificiale #esercito #francia #tecnologiamilitare #uav

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

RHC Conference 2026 - Fiducia nei Modelli: l'IA come Moltiplicatore delle Minacce Cyber

📍Guarda il video: youtube.com/watch?v=3XlwTtBnn8…

#redhotcyber #rhcconference #conferenza #informationsecurity #ethicalhacking #dataprotection

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Gentlemen Ransom Group aggiorna il proprio toolkit di cifratura

📌 Link all'articolo : redhotcyber.com/post/gentlemen…

A cura di Luigi Zullo

#redhotcyber #news #cybersecurity #hacking #malware #ransomware #kaspersky #thegentlemen

Performance Improvements For Open-Source 80386


The media in this post is not displayed to visitors. To view it, please log in.

The Intel 80386 is a rather fascinating slice of computer history. It marked the first 32 bit X86 processor, and was a staple of early desktop computing. Like all chips, it has a number of quirks, one of which being the fact that all commands are executed in microcode. By this nature, it was a rather excellent prospect to be re-implemented in an FPGA core called the z386. However, it was lacking a feature native to the original 386, early start memory access. If you haven’t been c, [nand2mario] went forth to fully implement this feature for FPGA 80386s.

Instead of taking a cycle to find and allocate the memory required for executing the next instruction, the 386 would start this in the previous cycle. This is achieved in hardware by nature of having a separate memory management unit. In the FPGA, the key difficulty proved to be in getting the computation fast enough to execute within a single cycle. This change netted an approximate 9% performance benefit. However, for [nand2mario] this was too small a performance uplift.

Some rewrites of the store cue allowed for cutting a cycle out of the process further improving the performance. However, more performance required slight deviations from the design of the original 386. Because code-branches are performance critical, the z386 project now computes the branch memory jump several cycles earlier than the 386, reducing the cycle time for the jumps from 9.25 to a mere 6. Some final changes to the microcode decode frontend rounded out the optimizations covered in this latest blog post.

The net result is an approximate 39% increase in performance in the all important DOOM benchmark. The z386 still not a complete project, the performance is still lacking compared to the 386, and it remains unable to boot Windows. X86 is complicated, which will take time, so make sure to stay tuned for more coverage! While you wait, make sure to check out our original writeup of the z386 project.

Pauli Rautakorpi, CC BY 3.0.


hackaday.com/2026/07/06/perfor…

Cybersecurity & cyberwarfare ha ricondiviso questo.

OpenSSH 10.4 has just been released

This release includes a number of security and bug fixes, as well as a handful of new features - most notable experimental support for a hybrid post-quantum signature scheme (ML-DSA 44 with Ed25519).

openssh.org/releasenotes.html#…

in reply to Damien Miller

Awesome! Thank you!

I was making an effort at updating MacPorts' to 10.4p1, yet @schamschula@mastodon.social beat me to it!

The MacPorts' pam.patch and launchd.patch have been removed as they are no longer necessary.

Meanwhile: I also submitted a story to undeadly.org though I'll let the other editors check it for errors and publish it.

#OpenSSH #SecureShell #OpenSource #MacPorts #Encryption #Cryptography #PostQuantum

CC: @damienmiller@hachyderm.io

Cybersecurity & cyberwarfare ha ricondiviso questo.

I cant believe they fell for it again. They were told that AI was cheaper than their own people. They replaced their people with AI, AI companies jacked up the prices AND it has worse performance than the humans it replaced. Get wrecked idiots.

Flight Sim Tracking from Spatial Audio


The media in this post is not displayed to visitors. To view it, please log in.

Flight sims are wonderful to play around with to get immersed in the position of a pilot. Racing sims can give you a thrill that can only be beaten by the real thing. However, most of this tech is on the more expensive side, so it would be great if you could use some of the hardware already found in your house. Many Sony headphones already have rotation and movement data built in for spatial audio, so why not start there?

[Nicholas Slattery] had this very idea and has produced an open-source application to connect your headphones straight to your sim. There’s a surprising amount of support built into many headsets that use a known protocol called the Android Head Tracker HID protocol. This allowed [Nicholas] to connect a family of Sony headphones straight into OpenTrack, which is often used with flight sims. The best part is you can still use the headphones as normal with a Bluetooth connection.

If you want to give this a try with your own rig, check out [Nicholas]’s GitHub here. While flight and driving sims might be expensive to put together, it’s never too hard to hack together something to lower that barrier! Whether it’s a flight sim force-feedback joystick or driving sim hand-breaks we got you!


hackaday.com/2026/07/06/flight…

Cybersecurity & cyberwarfare ha ricondiviso questo.

New, by me: Canada's top eavesdropping agency said it conducted "active cyber operations" during 2025 against drug traffickers, a violent extremist group, and a ransomware gang, using offensive hacking operations to disrupt or degrade their ability to function and cause harm.

Read more: techcrunch.com/2026/07/06/cana…

Bypass for ad-blockers: web.archive.org/web/2026070614…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Le regole della FIFA sull'interferenza politica e perché gli Stati Uniti devono essere squalificati e Infantino privato della presidenza.

Le regole della FIFA sull'ingerenza politica sono chiare; gli Stati Uniti le hanno violate e l'unico modo per ripristinare l'integrità è che Infantino venga rimosso dalla presidenza e che agli Stati Uniti venga tolto il loro posto.

andymuirhead.com/p/fifas-rules…

@Tutto il calcio - Serie A, Nazionale, Champions