Cybersecurity & cyberwarfare ha ricondiviso questo.

L'Open Source Made in EU è già morto

In tredici giorni sono successe tantissime cose per quanto riguarda l'open source in Europa, e potrebbe pure sembrare l'alba di un risorgimento del software libero. Spoiler: non è così.

newsletter.zornade.com/p/lopen…

@eticadigitale

Grazie a Marco per la segnalazione

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Tata #Electronics Confirms Data Breach After 630GB Leak Claim Targets Apple and Tesla
securityaffairs.com/194237/dat…
#securityaffairs #hacking

Cheap 80s Keyboard Gets Modern Brain Upgrade


The media in this post is not displayed to visitors. To view it, please log in.

The 1981 Casio VL-1 was a fine cheap keyboard. It had a robust build, though an admittedly limited sound palette. [Max Vega] had one of these charming instruments, and decided to use modern tech to rebrain it for the modern world.

The original electronics of the VL-1 were largely surplus to requirements for this build. The original interface and speaker were kept in service, while the rest of the monophonic sound synthesis hardware was removed. [Max Vega] enlisted an ESP32-C3 to run the show, turning the VL-1 into a ROMpler instead. If you’re unfamiliar with the term, it refers to a keyboard or other instrument that relies on hardcoded sample playback instead of raw synthesis. The ESP32 loads its samples from a microSD card, which provides an enormous amount of storage for different sound packs. Selecting different instruments is handled with a simple interface built around the original buttons and a OLED screen. Playing the instrument is still the same using the simple keyboard, though [Max] also implemented some extra fun modes that play chords at a single touch.

If you want a fun, versatile keyboard instrument that fits perfectly in a backpack, it’s hard to go wrong with a build like this. We’ve seen similar Casio keyboard hacks before, too. Video after the break.

youtube.com/embed/JbmBMPSxh24?…


hackaday.com/2026/06/25/cheap-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: Prediction market giant Polymarket said hackers stole funds from an unspecified number of users, whom the company said are gonna get refunded.

Blockchain monitoring researchers said hackers stole around $3 million from Polymarket users.

techcrunch.com/2026/06/25/poly…

Questa voce è stata modificata (1 mese fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

#Curl Fixes a 25-Year-Old Bug in Its Largest CVE Release Yet
securityaffairs.com/194220/sec…
#securityaffairs #hacking #malware

CSS On The ESP32


The media in this post is not displayed to visitors. To view it, please log in.

There are lots of graphics libraries available for the ESP32, and lots of ways to program one to boot. Even still, most of us wouldn’t immediately think to CSS when it comes to embedded products — yet that’s now a thing on the Espressif platform, apparently.

The Gea stack allows one to compose CSS and TypeScript code that is then turned into generated C++ code that compiles to native firmware. The team behind Gea have demoed this ability by running a 3D cube animation on an ESP32 at up to 60 FPS. This isn’t some ugly, low-res wireframe demo, either. It’s a full-color animation running on a 410×502 AMOLED screen. It’s very fluid, and can even handle transparency on the cube faces (albeit with a performance penalty).

It’s worth noting that this isn’t a full browser engine. As you might expect, some concessions had to be made to get it running on the ESP32. Namely, it doesn’t handle “:hover” states because it’s designed for touchscreen use, fonts are rasterized, and the UI tree is limited to just 512 nodes. Regardless, it shows that using CSS and TypeScript to develop for the ESP32 is entirely possible without some crazy loss of performance. If you want to build easy interfaces on an ESP32 while leaning on web dev experience, this could be very useful indeed.

There are lots of fun ways to write code for the ESP32; you can even try MicroPython if you like.

youtube.com/embed/pC3kNSWaL18?…


hackaday.com/2026/06/25/css-on…

Cybersecurity & cyberwarfare ha ricondiviso questo.

SCOOP: Klue, which got hacked earlier this month, is telling customers that cybercriminals are deleting their stolen data — but now there’s a second group of hackers demanding a ransom from the affected customers.

Klue said it’s communicating with the original hackers, known as Icarus, and the company told customers Icarus suggests not paying this second group.

This new gang claimed Klue paid the ransom to the original hackers. But as of now, Klue has neither confirmed nor denied a payment.

techcrunch.com/2026/06/25/hack…

Questa voce è stata modificata (1 mese fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

LastPass e BeyondTrust vittime di un attacco in supply chain della piattaforma Klue

📌 Link all'articolo : redhotcyber.com/post/lastpass-…

A cura di Chiara Nardini

#redhotcyber #news #cybersecurity #hacking #malware #ransomware #furtoDati #salessforce

Increasing Local GPS Accuracy for a Small Robot


The media in this post is not displayed to visitors. To view it, please log in.

Even though GPS makes it possible for us to easily navigate around the planet in almost any vehicle we’d like, whether that’s a passenger vehicle, airplane, or cargo ship, it’s not really suitable for applications that require sub-meter accuracy. For that, some specialized hardware is needed, and [GreatScott!] shows us how to do it using a small robot as a platform.

The key to extremely accurate GPS signals in this case is using a receiver that supports real-time kinematic positioning (RTK). This type of system relies on a base station with a known position communicating with local mobile receivers to increase the precision of those mobile receivers by comparing the phase angle of the received signals. Of course these modules are much more expensive than the average standard GPS receiver, but for this kind of accuracy there is always a cost.

After getting a baseline accuracy of around two meters with a standard GPS receiver, [GreatScott!] installs the RTK GPS mobile receiver on a tracked robotic platform and a base station on a fence post. With the RTK system running, the limiting factor in accuracy became the robot’s steering system, as its turning radius and steering algorithms weren’t up to the task of hitting centimeter-sized targets out of the box.

But, as a proof-of-concept, it goes to show how accurate GPS can be as long as the right hardware is used, and for practical applications is good enough to mow a lawn with a robot or even do some amateur land surveying.

youtube.com/embed/y0UkxnTC1p4?…


hackaday.com/2026/06/25/increa…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ Kit AiTM contro AWS: Datadog svela una campagna di phishing che bypassa l’MFA in tempo reale
#CyberSecurity
insicurezzadigitale.com/kit-ai…

@informatica


Kit AiTM contro AWS: Datadog svela una campagna di phishing che bypassa l’MFA in tempo reale


Si parla di:
Toggle

Tra il 16 e il 19 giugno 2026, i ricercatori di Datadog Security Research hanno osservato una campagna di phishing altamente sofisticata contro la console AWS. Non si tratta del classico furto di credenziali: il kit implementa tecniche adversary-in-the-middle (AiTM) che permettono di catturare i codici MFA in tempo reale, bypassando email, SMS e app di autenticazione TOTP. Un’analisi tecnica dettagliata pubblicata il 24 giugno svela l’architettura del kit, gli IoC e le tecniche di delivery utilizzate.

La campagna: tre domini in 48 ore


La campagna si è concretizzata con la registrazione di tre domini in una finestra di soli due giorni, tutti attraverso il registrar NICENIC INTERNATIONAL GROUP CO., LIMITED e ospitati su infrastruttura Cloudflare. I domini impersonavano con fedeltà la pagina di login della console AWS:

  • us-west-login[.]com (registrato il 18 giugno 2026) — con sottodomini aws.us-west-login[.]com e aws-central.us-west-login[.]com
  • us-east-prod[.]com (registrato il 17 giugno 2026) — con sottodominio aws.us-east-prod[.]com
  • loginportal-aws[.]com (registrato il 16 giugno 2026)

In parallelo, sono stati identificati altri tre domini che impersonavano SendGrid, registrati nello stesso arco temporale attraverso lo stesso registrar. La doppia infrastruttura — AWS e SendGrid — suggerisce che gli attaccanti abbiano progettato un sistema integrato: SendGrid per la consegna delle email di phishing, i cloni AWS per la raccolta delle credenziali.

Come funziona il kit: AiTM in tempo reale


La caratteristica più pericolosa di questo kit non è la clonazione della pagina login, ma la capacità di intercettare e ritrasmettere il secondo fattore di autenticazione in tempo reale. Il flusso si articola in più fasi:

1. Validazione del target prima del rendering: quando la vittima accede alla pagina di phishing, il kit legge il parametro URL input_24 contenente un blob base64 cifrato. Il server decodifica l’indirizzo email della vittima e lo imposta come cookie. Solo se l’email è valida e registrata come target, la pagina viene effettivamente renderizzata — una misura anti-sandbox che rende inutile l’analisi automatica senza una email vittima valida.

// Logica di validazione dell'indirizzo vittima
let e = new URLSearchParams(window.location.search).get(`input_24`);
(e ? fetch(`/api/check`, {
  method: `POST`,
  body: JSON.stringify({ encrypted: e }),
  credentials: `include`
}) : Promise.resolve({ ok: !1 }))
.then(e => e.ok ? e.json() : null)
.then(() => fetch(`/api/me`, { credentials: `include` }))
.then(e => e.json())
.then(e => t(e.email || null))

2. Furto delle credenziali primarie: la pagina clonata raccoglie username e password tramite i form di login AWS (sia account root che IAM) e li invia a /api/login. Il server, agendo come proxy verso la vera console AWS, ottiene in risposta quale tipo di MFA è configurato sull’account.

3. Intercettazione dell’MFA in real-time: il kit presenta alla vittima la challenge MFA corrispondente al secondo fattore configurato — /email, /sms, o /gauth per le app TOTP. Il codice inserito viene intercettato e ritrasmesso immediatamente al server AWS legittimo, completando l’autenticazione prima che il codice scada.

Delivery: phishing mirato via SendGrid e Nimbu


Il 19 giugno 2026 è apparso su VirusTotal un batch file che funge da artefatto di validazione dell’infrastruttura. Il file contiene la struttura di un’email di phishing che impersona il supporto AWS, citando un ticket di supporto fasullo su presunto throttling della banda. La consegna avviene tramite piattaforme email legittime come SendGrid e Nimbu, scelta tattica che permette di passare i controlli SPF/DKIM/DMARC e bypassare i filtri antispam aziendali.

L’uso del parametro input_24 per la validazione dell’email suggerisce inoltre che si tratti di una campagna di spear phishing mirato piuttosto che mass phishing: ogni link contiene l’email cifrata della specifica vittima, rendendo impossibile l’accesso alla pagina di phishing senza il link personalizzato.

TTPs e mapping MITRE ATT&CK


  • T1566.002 — Spearphishing Link: link personalizzati con email cifrata per targeting preciso
  • T1111 — MFA Interception: cattura in real-time di email OTP, SMS e codici TOTP
  • T1056.001 — Keylogging: raccolta di username, password e codici di verifica prima del forwarding
  • T1583.001 — Acquire Infrastructure: Domains: tre domini registrati nello stesso arco di 48 ore
  • T1133 — External Remote Services: targeting dell’accesso alla console AWS


Indicatori di compromissione (IoC)

# Domini AWS phishing
us-west-login[.]com
aws.us-west-login[.]com
aws-central.us-west-login[.]com
us-east-prod[.]com
aws.us-east-prod[.]com
loginportal-aws[.]com

# Registrar comune
NICENIC INTERNATIONAL GROUP CO., LIMITED

# Infrastruttura di hosting
Cloudflare (tutti i domini)

# Endpoint API del kit
/api/check   - validazione email vittima
/api/me      - recupero email da cookie
/api/login   - furto credenziali e identificazione MFA
/email       - challenge MFA via email
/sms         - challenge MFA via SMS
/gauth       - challenge MFA via TOTP

# Parametro URL di targeting
input_24 (blob base64 cifrato contenente email vittima)

Come rilevare l’attacco


Datadog consiglia le seguenti azioni di hunting per chi sospetti di essere stato targetizzato:

  • DNS hunting: verificare la presenza nei log DNS di query verso i domini elencati negli IoC, inclusi i sottodomini
  • CloudTrail monitoring: controllare eventi ConsoleLogin da IP inusuali o da località geografiche anomale, soprattutto a ridosso delle date di campagna (16-19 giugno 2026)
  • Email gateway review: cercare email provenienti da SendGrid o Nimbu che contengano link con il parametro input_24 nell’URL
  • Credential review: se si sospetta compromissione, revocare immediatamente le sessioni AWS attive, ruotare le credenziali e abilitare notifiche di accesso non familiare

La sofisticazione di questo kit — targeting selettivo, bypass MFA in real-time, uso di infrastrutture email legittime — lo colloca in una categoria diversa rispetto al phishing di massa. Le organizzazioni che utilizzano AWS in ambienti enterprise dovrebbero trattare questa campagna come un rischio attivo, non come una minaccia teorica.


Cybersecurity & cyberwarfare ha ricondiviso questo.

La Russia ha hackerato il telefono di un oppositore politico di Putin tramite Cellebrite, tre mesi dopo che l'azienda aveva annunciato di aver interrotto i rapporti con il governo russo.

Sul suo sito web ufficiale, #Cellebrite afferma che a partire da marzo 2021 ha interrotto i rapporti con il governo russo e "può impedire al dispositivo di funzionare o di ricevere aggiornamenti software".

Ma in questo caso ciò non l'ha fatto!

techcrunch.com/2026/06/25/cell…

@informatica

Una lettera e un coltellino tradirono una grande spia (prima parte)

@Informatica (Italy e non Italy)

Una curiosa e poco conosciuta storia di spionaggio: come si tradì una grande spia.
All’inizio del XX secolo i Russi misero le mani sul tesoro di Alì Babà (inteso in senso metaforico) grazie al Colonnello e maggior esperto di intelligence dell’esercito austro-ungarico: Alfred

Cybersecurity & cyberwarfare ha ricondiviso questo.

Inside #Mistic, the New Stealth #Backdoor in #Ransomware Intrusions
securityaffairs.com/194207/cyb…
#securityaffairs #hacking #malware

Flying Cell Towers Are A Thing


The media in this post is not displayed to visitors. To view it, please log in.

Typically, when you’re sitting on a plane on the tarmac, you switch your phone to flight mode while you’re sitting through yet another “quirky” (boring) safety video. You’ll watch some inflight entertainment, read the airline magazine if you get really desperate, and wonder if anyone ever buys those random watches for sale in the “duty free” section. Then, finally, upon landing, you’ll be connected back to the Internet and you’ll finally feel like you can breathe again.

Only, this time, you forgot to set your plane on flight mode. You’re sitting at 30,000 feet, and… your phone has signal? You’re online, and you’re getting notifications and emails just like you’re on the ground. You’ve accidentally discovered that your flight has an on-board cell tower.

Connection


When you’re cruising on a passenger airliner, you would typically expect to see little to no cellular signal by sheer virtue of altitude and speed. For one thing, you’re blasting past at immense speed and not staying in any one coverage zone for very long at all. Meanwhile, while you’re probably within 10 kilometers or so, vertically speaking, cell towers generally have their antennas aimed at the ground, not the sky. There simply isn’t much signal available, and you’re zooming around a bit too fast to hang on to any cell tower before it’s disappeared out of range.
The connectivity back to the Internet is effectively the same as any inflight WiFi system. The difference is that passengers are served with cellular connectivity instead of WiFi. Credit: AeroMobile
Some airlines have gotten around this problem by providing on-board Internet connectivity over WiFi. The aircraft features an uplink to one of various satellite networks that provide Internet access, and that is provisioned to customers in the cabin over a WiFi router with a captive portal. Typically, for some painful charge in double digit US dollars, you can purchase a few hours of access to your emails and the Web, often with quite shaky connectivity.

However, there is sometimes a way to dodge the painful fees for onboard WiFI, while still getting online. A handful of airlines have equipped some of their fleets with cellular connectivity via a system called AeroMobile. They still rely on a satellite uplink for Internet access, and these planes generally still have onboard WiFi as well. However, if you happen to switch your phone out of flight mode, you might notice it connecting to a cell tower onboard—the AeroMobile picocell, in fact. Your phone connects to this tiny cell tower over cellular data links—originally 3G, later 4G or 5G depending on the hardware onboard—instead of WiFi. You escape the airline’s captive portal and data charges, instead paying your home carrier for data and whatever fee you normally get billed for international roaming. The ability to do this depends on your home mobile carrier, too, and whether they have an agreement with AeroMobile.

youtube.com/embed/Jd3yspIHBYo?…

AeroMobile’s service depends on customers actually switching out of “Flight Mode” in order to allow the phone to use its cellular radios to connect to the picocell onboard the aircraft. Credit: AeroMobile

AeroMobile has been around for a long time now, first demonstrating its hardware with GSM and GPRS data links on aircraft as far back as 2005. The company’s voice and data offerings have stepped up over the years as mobile technology has moved on, albeit often some years behind the state-of-the-art in the cellular world. The first planes with 3G didn’t fly until 2015, well over a decade after the technology was becoming established on the ground. As a subsidiary of Panasonic Avionics, AeroMobile-equipped aircraft communicate with a range of satellites that Panasonic has access to over Ku-band and L-band links. In recent years, the company has been developing the capacity for its aircraft to seamlessly switch between links to geostationary and low-earth orbit satellites, with the former offering the best coverage, and the latter Eutelsat OneWeb satellites offering much reduced latency and higher link speeds. Ultimately, user experience depends on flight route, local conditions, and other factors; speeds and reliability can vary from good to spotty on any given day. There’s also the fact that, on any given flight, tens or hundreds of other users may be trying to get online over the same link, which can quickly dry up what little bandwidth may be available in some black spots on the world map with poor satellite coverage.

If you’re flying soon, it’s still unwise to rely on in-flight internet connectivity. Whether you’re hooking up over WiFi or cellular, there are still often issues with coverage, or with systems being inoperative on certain flights and at lower altitudes, even on airlines with the best-equipped fleets. You’re also unlikely to regularly get high enough speeds for comfortable streaming, so you’re better off downloading The Thick Of It prior to take-off rather than trying to watch it live off a server while you’re scooting over downtown Astana. However, now and then, when you’re lonely and high above this marbled sphere, you might be just able to hang out on Discord and flirt with a few friends back home thanks to Panasonic and a steady link to the satellites above. Have fun up there.


hackaday.com/2026/06/25/flying…

The media in this post is not displayed to visitors. To view it, please log in.

Kit AiTM contro AWS: Datadog svela una campagna di phishing che bypassa l’MFA in tempo reale


@Informatica (Italy e non Italy)
Tra il 16 e il 19 giugno 2026, una campagna di phishing mirato ha preso di mira le credenziali della console AWS usando tecniche adversary-in-the-middle per intercettare MFA via email, SMS e TOTP in tempo reale. Datadog Security


Kit AiTM contro AWS: Datadog svela una campagna di phishing che bypassa l’MFA in tempo reale


Si parla di:
Toggle

Tra il 16 e il 19 giugno 2026, i ricercatori di Datadog Security Research hanno osservato una campagna di phishing altamente sofisticata contro la console AWS. Non si tratta del classico furto di credenziali: il kit implementa tecniche adversary-in-the-middle (AiTM) che permettono di catturare i codici MFA in tempo reale, bypassando email, SMS e app di autenticazione TOTP. Un’analisi tecnica dettagliata pubblicata il 24 giugno svela l’architettura del kit, gli IoC e le tecniche di delivery utilizzate.

La campagna: tre domini in 48 ore


La campagna si è concretizzata con la registrazione di tre domini in una finestra di soli due giorni, tutti attraverso il registrar NICENIC INTERNATIONAL GROUP CO., LIMITED e ospitati su infrastruttura Cloudflare. I domini impersonavano con fedeltà la pagina di login della console AWS:

  • us-west-login[.]com (registrato il 18 giugno 2026) — con sottodomini aws.us-west-login[.]com e aws-central.us-west-login[.]com
  • us-east-prod[.]com (registrato il 17 giugno 2026) — con sottodominio aws.us-east-prod[.]com
  • loginportal-aws[.]com (registrato il 16 giugno 2026)

In parallelo, sono stati identificati altri tre domini che impersonavano SendGrid, registrati nello stesso arco temporale attraverso lo stesso registrar. La doppia infrastruttura — AWS e SendGrid — suggerisce che gli attaccanti abbiano progettato un sistema integrato: SendGrid per la consegna delle email di phishing, i cloni AWS per la raccolta delle credenziali.

Come funziona il kit: AiTM in tempo reale


La caratteristica più pericolosa di questo kit non è la clonazione della pagina login, ma la capacità di intercettare e ritrasmettere il secondo fattore di autenticazione in tempo reale. Il flusso si articola in più fasi:

1. Validazione del target prima del rendering: quando la vittima accede alla pagina di phishing, il kit legge il parametro URL input_24 contenente un blob base64 cifrato. Il server decodifica l’indirizzo email della vittima e lo imposta come cookie. Solo se l’email è valida e registrata come target, la pagina viene effettivamente renderizzata — una misura anti-sandbox che rende inutile l’analisi automatica senza una email vittima valida.

// Logica di validazione dell'indirizzo vittima
let e = new URLSearchParams(window.location.search).get(`input_24`);
(e ? fetch(`/api/check`, {
  method: `POST`,
  body: JSON.stringify({ encrypted: e }),
  credentials: `include`
}) : Promise.resolve({ ok: !1 }))
.then(e => e.ok ? e.json() : null)
.then(() => fetch(`/api/me`, { credentials: `include` }))
.then(e => e.json())
.then(e => t(e.email || null))

2. Furto delle credenziali primarie: la pagina clonata raccoglie username e password tramite i form di login AWS (sia account root che IAM) e li invia a /api/login. Il server, agendo come proxy verso la vera console AWS, ottiene in risposta quale tipo di MFA è configurato sull’account.

3. Intercettazione dell’MFA in real-time: il kit presenta alla vittima la challenge MFA corrispondente al secondo fattore configurato — /email, /sms, o /gauth per le app TOTP. Il codice inserito viene intercettato e ritrasmesso immediatamente al server AWS legittimo, completando l’autenticazione prima che il codice scada.

Delivery: phishing mirato via SendGrid e Nimbu


Il 19 giugno 2026 è apparso su VirusTotal un batch file che funge da artefatto di validazione dell’infrastruttura. Il file contiene la struttura di un’email di phishing che impersona il supporto AWS, citando un ticket di supporto fasullo su presunto throttling della banda. La consegna avviene tramite piattaforme email legittime come SendGrid e Nimbu, scelta tattica che permette di passare i controlli SPF/DKIM/DMARC e bypassare i filtri antispam aziendali.

L’uso del parametro input_24 per la validazione dell’email suggerisce inoltre che si tratti di una campagna di spear phishing mirato piuttosto che mass phishing: ogni link contiene l’email cifrata della specifica vittima, rendendo impossibile l’accesso alla pagina di phishing senza il link personalizzato.

TTPs e mapping MITRE ATT&CK


  • T1566.002 — Spearphishing Link: link personalizzati con email cifrata per targeting preciso
  • T1111 — MFA Interception: cattura in real-time di email OTP, SMS e codici TOTP
  • T1056.001 — Keylogging: raccolta di username, password e codici di verifica prima del forwarding
  • T1583.001 — Acquire Infrastructure: Domains: tre domini registrati nello stesso arco di 48 ore
  • T1133 — External Remote Services: targeting dell’accesso alla console AWS


Indicatori di compromissione (IoC)

# Domini AWS phishing
us-west-login[.]com
aws.us-west-login[.]com
aws-central.us-west-login[.]com
us-east-prod[.]com
aws.us-east-prod[.]com
loginportal-aws[.]com

# Registrar comune
NICENIC INTERNATIONAL GROUP CO., LIMITED

# Infrastruttura di hosting
Cloudflare (tutti i domini)

# Endpoint API del kit
/api/check   - validazione email vittima
/api/me      - recupero email da cookie
/api/login   - furto credenziali e identificazione MFA
/email       - challenge MFA via email
/sms         - challenge MFA via SMS
/gauth       - challenge MFA via TOTP

# Parametro URL di targeting
input_24 (blob base64 cifrato contenente email vittima)

Come rilevare l’attacco


Datadog consiglia le seguenti azioni di hunting per chi sospetti di essere stato targetizzato:

  • DNS hunting: verificare la presenza nei log DNS di query verso i domini elencati negli IoC, inclusi i sottodomini
  • CloudTrail monitoring: controllare eventi ConsoleLogin da IP inusuali o da località geografiche anomale, soprattutto a ridosso delle date di campagna (16-19 giugno 2026)
  • Email gateway review: cercare email provenienti da SendGrid o Nimbu che contengano link con il parametro input_24 nell’URL
  • Credential review: se si sospetta compromissione, revocare immediatamente le sessioni AWS attive, ruotare le credenziali e abilitare notifiche di accesso non familiare

La sofisticazione di questo kit — targeting selettivo, bypass MFA in real-time, uso di infrastrutture email legittime — lo colloca in una categoria diversa rispetto al phishing di massa. Le organizzazioni che utilizzano AWS in ambienti enterprise dovrebbero trattare questa campagna come un rischio attivo, non come una minaccia teorica.


Cybersecurity & cyberwarfare ha ricondiviso questo.

🚨CHATCONTROL DOPPIA MINACCIA:

🏛️La Pres. del PE tradisce la democrazia per imporre #ChatControl 1.0.
👁️E lunedì il trilogo minaccia scansioni di massa & verifiche dell'età!

🛡️Salvate le chat private! 💬🔒Scrivete ORA a governi & deputati UE:

fightchatcontrol.eu/it/#contac…

@privacypride

Cybersecurity & cyberwarfare ha ricondiviso questo.

Kit AiTM contro AWS: Datadog svela una campagna di phishing che bypassa l’MFA in tempo reale


Tra il 16 e il 19 giugno 2026, una campagna di phishing mirato ha preso di mira le credenziali della console AWS usando tecniche adversary-in-the-middle per intercettare MFA via email, SMS e TOTP in tempo reale. Datadog Security Research ha analizzato il kit, pubblicando IoC, codice sorgente e guida al rilevamento.
The media in this post is not displayed to visitors. To view it, please go to the original post.

Si parla di:
Toggle

Tra il 16 e il 19 giugno 2026, i ricercatori di Datadog Security Research hanno osservato una campagna di phishing altamente sofisticata contro la console AWS. Non si tratta del classico furto di credenziali: il kit implementa tecniche adversary-in-the-middle (AiTM) che permettono di catturare i codici MFA in tempo reale, bypassando email, SMS e app di autenticazione TOTP. Un’analisi tecnica dettagliata pubblicata il 24 giugno svela l’architettura del kit, gli IoC e le tecniche di delivery utilizzate.

La campagna: tre domini in 48 ore


La campagna si è concretizzata con la registrazione di tre domini in una finestra di soli due giorni, tutti attraverso il registrar NICENIC INTERNATIONAL GROUP CO., LIMITED e ospitati su infrastruttura Cloudflare. I domini impersonavano con fedeltà la pagina di login della console AWS:

  • us-west-login[.]com (registrato il 18 giugno 2026) — con sottodomini aws.us-west-login[.]com e aws-central.us-west-login[.]com
  • us-east-prod[.]com (registrato il 17 giugno 2026) — con sottodominio aws.us-east-prod[.]com
  • loginportal-aws[.]com (registrato il 16 giugno 2026)

In parallelo, sono stati identificati altri tre domini che impersonavano SendGrid, registrati nello stesso arco temporale attraverso lo stesso registrar. La doppia infrastruttura — AWS e SendGrid — suggerisce che gli attaccanti abbiano progettato un sistema integrato: SendGrid per la consegna delle email di phishing, i cloni AWS per la raccolta delle credenziali.

Come funziona il kit: AiTM in tempo reale


La caratteristica più pericolosa di questo kit non è la clonazione della pagina login, ma la capacità di intercettare e ritrasmettere il secondo fattore di autenticazione in tempo reale. Il flusso si articola in più fasi:

1. Validazione del target prima del rendering: quando la vittima accede alla pagina di phishing, il kit legge il parametro URL input_24 contenente un blob base64 cifrato. Il server decodifica l’indirizzo email della vittima e lo imposta come cookie. Solo se l’email è valida e registrata come target, la pagina viene effettivamente renderizzata — una misura anti-sandbox che rende inutile l’analisi automatica senza una email vittima valida.

// Logica di validazione dell'indirizzo vittima
let e = new URLSearchParams(window.location.search).get(`input_24`);
(e ? fetch(`/api/check`, {
  method: `POST`,
  body: JSON.stringify({ encrypted: e }),
  credentials: `include`
}) : Promise.resolve({ ok: !1 }))
.then(e => e.ok ? e.json() : null)
.then(() => fetch(`/api/me`, { credentials: `include` }))
.then(e => e.json())
.then(e => t(e.email || null))

2. Furto delle credenziali primarie: la pagina clonata raccoglie username e password tramite i form di login AWS (sia account root che IAM) e li invia a /api/login. Il server, agendo come proxy verso la vera console AWS, ottiene in risposta quale tipo di MFA è configurato sull’account.

3. Intercettazione dell’MFA in real-time: il kit presenta alla vittima la challenge MFA corrispondente al secondo fattore configurato — /email, /sms, o /gauth per le app TOTP. Il codice inserito viene intercettato e ritrasmesso immediatamente al server AWS legittimo, completando l’autenticazione prima che il codice scada.

Delivery: phishing mirato via SendGrid e Nimbu


Il 19 giugno 2026 è apparso su VirusTotal un batch file che funge da artefatto di validazione dell’infrastruttura. Il file contiene la struttura di un’email di phishing che impersona il supporto AWS, citando un ticket di supporto fasullo su presunto throttling della banda. La consegna avviene tramite piattaforme email legittime come SendGrid e Nimbu, scelta tattica che permette di passare i controlli SPF/DKIM/DMARC e bypassare i filtri antispam aziendali.

L’uso del parametro input_24 per la validazione dell’email suggerisce inoltre che si tratti di una campagna di spear phishing mirato piuttosto che mass phishing: ogni link contiene l’email cifrata della specifica vittima, rendendo impossibile l’accesso alla pagina di phishing senza il link personalizzato.

TTPs e mapping MITRE ATT&CK


  • T1566.002 — Spearphishing Link: link personalizzati con email cifrata per targeting preciso
  • T1111 — MFA Interception: cattura in real-time di email OTP, SMS e codici TOTP
  • T1056.001 — Keylogging: raccolta di username, password e codici di verifica prima del forwarding
  • T1583.001 — Acquire Infrastructure: Domains: tre domini registrati nello stesso arco di 48 ore
  • T1133 — External Remote Services: targeting dell’accesso alla console AWS


Indicatori di compromissione (IoC)

# Domini AWS phishing
us-west-login[.]com
aws.us-west-login[.]com
aws-central.us-west-login[.]com
us-east-prod[.]com
aws.us-east-prod[.]com
loginportal-aws[.]com

# Registrar comune
NICENIC INTERNATIONAL GROUP CO., LIMITED

# Infrastruttura di hosting
Cloudflare (tutti i domini)

# Endpoint API del kit
/api/check   - validazione email vittima
/api/me      - recupero email da cookie
/api/login   - furto credenziali e identificazione MFA
/email       - challenge MFA via email
/sms         - challenge MFA via SMS
/gauth       - challenge MFA via TOTP

# Parametro URL di targeting
input_24 (blob base64 cifrato contenente email vittima)

Come rilevare l’attacco


Datadog consiglia le seguenti azioni di hunting per chi sospetti di essere stato targetizzato:

  • DNS hunting: verificare la presenza nei log DNS di query verso i domini elencati negli IoC, inclusi i sottodomini
  • CloudTrail monitoring: controllare eventi ConsoleLogin da IP inusuali o da località geografiche anomale, soprattutto a ridosso delle date di campagna (16-19 giugno 2026)
  • Email gateway review: cercare email provenienti da SendGrid o Nimbu che contengano link con il parametro input_24 nell’URL
  • Credential review: se si sospetta compromissione, revocare immediatamente le sessioni AWS attive, ruotare le credenziali e abilitare notifiche di accesso non familiare

La sofisticazione di questo kit — targeting selettivo, bypass MFA in real-time, uso di infrastrutture email legittime — lo colloca in una categoria diversa rispetto al phishing di massa. Le organizzazioni che utilizzano AWS in ambienti enterprise dovrebbero trattare questa campagna come un rischio attivo, non come una minaccia teorica.

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: Russia hacked into the phone of a Putin political opponent with Cellebrite — three months after the company said it cut ties with the Russian government.

On its official website, Cellebrite claims that as of March 2021, when it cut ties with the Russian government, the company “can stop the device from functioning or receiving software updates.”

It's unclear why that did not make a difference here.

techcrunch.com/2026/06/25/cell…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Ieri la Commissione europea ha annunciato una nuova proposta di riforma per Europol , l'agenzia di polizia dell'UE, che amplia i poteri operativi di Europol e indebolisce le principali garanzie in materia di protezione dei dati per un valore di 3 miliardi di euro

Si tratta della terza riforma di Europol in sei anni, che modifica il mandato dell'agenzia per aumentarne i poteri e il budget.

protectnotsurveil.eu/resources…

@privacypride@feddit.it

eupolicy.social/@edri/11680982…


🚨 Yesterday, the European Commission announced a new reform proposal for #Europol – the EU’s policing agency – which expands Europol’s operational powers and weakens key data protection safeguards to the tune of €3 billion.

This is the third Europol reform in six years changing the agency’s mandate to increase its powers and budget.

Read more from #ProtectNotSurveil ➡️ protectnotsurveil.eu/resources…


Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Legge sui mercati digitali, l’UE mette nel mirino i servizi cloud di Amazon e Microsoft

Da verifiche preliminari per l'esecutivo comunitario hanno quote di utenze tali da giustificare l'applicazione del DMA

eunews.it/2026/06/25/legge-sui…

@privacypride


🚨 Yesterday, the European Commission announced a new reform proposal for #Europol – the EU’s policing agency – which expands Europol’s operational powers and weakens key data protection safeguards to the tune of €3 billion.

This is the third Europol reform in six years changing the agency’s mandate to increase its powers and budget.

Read more from #ProtectNotSurveil ➡️ protectnotsurveil.eu/resources…


Questa voce è stata modificata (1 mese fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

Legge sui mercati digitali, l’UE mette nel mirino i servizi cloud di Amazon e Microsoft
@news
eunews.it/2026/06/25/legge-sui…
Da verifiche preliminari per l'esecutivo comunitario hanno quote di utenze tali da giustificare l'applicazione del DMA
Cybersecurity & cyberwarfare ha ricondiviso questo.

DevConf 2026 - La conferenza italiana dedicata agli sviluppatori e creatori di codice open source. Due giorni di talk, networking e condivisione di conoscenze.

La conferenza si terrà a Pavia, presso il Learning Space Cravino (Via Agostino Bassi 2) il 7 e l'8 Luglio 2026 con sessioni mattutine e pomeridiane.

Talk tecnici, possibilità di sviluppare in tempo reale e presentare il proprio progetto, networking, opportunità di collaborazione dinanzi ad un pubblico in cui sono presenti anche Risorse Umane di aziende interessate al recruiting di talenti in ambito Open Source.

Prenota il tuo ingresso


I posti a sedere sono limitati per cui è necessaria la prenotazione. L'ingresso è gratuito!

NB: il convegno risulta essere anche un corso formativo per il Personale Tecnico Amministrativo e Cel


devconf.it/2026/programma.html

@GNU/Linux Italia

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Venti Agentici: Oracle riduce forza lavoro di 21.000 dipendenti nel 2026

📌 Link all'articolo : redhotcyber.com/post/venti-age…

A cura di Carolina Vivianti

#redhotcyber #news #oracle #intelligenzaartificiale #riorganizzazioneaziendale #tecnologia

New Record Resurrects Long-Dead CD Graphics Format


The media in this post is not displayed to visitors. To view it, please log in.

Audio CDs were the ubiquitous audio format of the 1990s. Lesser known were the extensions to the format that packaged all kinds of interesting additional data into a musical release. Now, a new record from [Aizysse Baga] has brought back some of the most quirky and obscure CD features that time and industry long forgot.

[Aizysse Baga] worked with [Adelaide] on the Divacore record, which was to be released on a mini-CD. The original plan was to include additional CD+G data, featuring artwork to go with the music. CD+G, or CD+Graphics, was often used to display synchronized lyrics for karaoke releases, and stored data in formerly-unused subcodes next to the track start, track number, and running time data. This format allowed storing a slideshow of images with a resolution of 288 x 192 with a 16 color palette.
Note the quality difference between the 16-color CD+G and the 256-color CD+EG images.
The duo got handy with art and some smart dithering to get great 16-bit artwork packed in to the audio CD release, with the aid of a custom Python encoder. CD-TEXT metadata was thrown in for good measure. Then, the existence of the more advanced CD+EG became apparent. This was a 256-color extension to the CD+G format that was backwards compatible to boot. It was a format that was barely ever implemented on any commercial releases, and very little hardware could even display it. Naturally, Divacore had to have it. Much work was done to understand the Red Book documentation on the standard and figure out how to implement even higher quality artwork for the record.

After so much work to understand and implement the CD+G and CD+EG data, the question was whether it would survive the CD reproduction process for the final release. Thankfully, the final discs came out perfectly, and the full 256-color CD+EG artwork can be seen in all its glory if you happen to play Divacore on a Sega Saturn or a super-obscure Victor VS-G2 or VS-G3. Throw it in a less-sophisticated karaoke machine or something like an Amiga CD32, and you’ll still get to see the 16-color versions for your trouble.

We love to see ancient formats brought back to life, particularly those that never got their time in the sun. If you’re working hard to resurrect something the mainstream media world has forgotten, let us know on the tipsline.


hackaday.com/2026/06/25/new-re…

Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools


The media in this post is not displayed to visitors. To view it, please log in.

Small and medium-sized businesses (SMBs) remain attractive targets for cybercriminals – in both mass cyberattacks and sophisticated campaigns targeting larger enterprises through trusted relationship attacks. At the same time, smaller businesses may lack the robust cybersecurity policies and necessary resources to protect themselves against an evolving threat landscape.

Kaspersky believes that raising awareness can help small and medium-sized enterprises develop an effective protection strategy. Ahead of International SMB Day on June 27, Kaspersky presents the findings of its 2026 threat analysis for SMBs, which includes real-world examples of attacks.

Key findings


  • In the first four months of 2026, Kaspersky solutions detected over 33,300 cyberattacks on SMBs masquerading as popular artificial intelligence (AI) tools – almost five times more than in 2025 and 39% more than the number of attacks disguised as the office and collaboration tools that Kaspersky’s research focuses on.
  • Popular messengers and communication services remained the attacker’s most widespread lure, with almost 415,000 attacks involving fake messenger apps and video conferencing software.
  • The attackers follow trends: the AI tools Claude and OpenClaw (ex-ClawdBot/MoltBot), which have gained popularity in 2026, were among the common AI lures.
  • Fraudsters use fake AI tools to scam businesses out of money, while corporate accounts on social media also remain targets.
  • The majority of initial accesses to corporate infrastructures sold on the dark web are allegedly accesses to SMBs. This could be because SMBs tend not to be as well protected as large enterprises and, at the same time, may be trusted contractors for those well-protected enterprises.


Malware and potentially unwanted applications (PUAs) disguised as popular services


Kaspersky researchers used data from Kaspersky Security Network (KSN) to explore how frequently malicious and unwanted files are disguised as legitimate applications that may be used by SMBs. KSN is a system for processing anonymized cyberthreat-related data shared voluntarily by Kaspersky users. For this part of the report, only anonymized data received from users of Kaspersky solutions for SMBs were analyzed.

According to a survey by the Small Business & Entrepreneurship Council (SBE Council), small business owners continue to embrace artificial intelligence and digital transformation as they maintain a generally positive outlook on the economy. Threat actors are also aware of the hype surrounding AI and exploit it for their own benefit. In particular, they actively distribute cyberthreats under the guise of popular AI services.

From January to April 2026, Kaspersky solutions detected 33,352 attacks on SMB users in which malware or potentially unwanted applications for PCs were disguised as five popular AI services. This figure represents an increase of almost five times compared to the previous year. This highlights an evolving trend in which threat actors are weaponizing trust in widely used AI platforms and services, especially popular ones like Claude. Kaspersky experts note that it’s important to download apps from official sources and to verify which apps are available for which platforms.

Share of attacks targeting SMBs in which malware or PUAs mimic the five popular, legitimate AI apps that Kaspersky’s research focuses on, first four months of 2025 and 2026 (download)
In the first four months of 2026, Kaspersky researchers also identified more than 1,100 unique samples of malware and PUAs detected in the SMB sector that masqueraded as five popular AI applications, representing a 21% increase compared to the same period of 2025. The samples were mainly different types of Trojware (Trojans and Trojan-like malware), including those capable of downloading and running other malware on compromised devices. Trojware disguises itself as harmless files to trick users into installing them. Their functionality may vary depending on the particular type of Trojware. This may include stealing, deleting, blocking, modifying or copying users’ data, as well as other malicious actions. Trojware therefore represents a highly dangerous cyberthreat to entrepreneurs and businesses.

Kaspersky experts also note that the threat landscape is constantly evolving with new lures appearing all the time. For example, in the first four months of 2026, Kaspersky solutions blocked hundreds of attacks in which malware or PUAs for PCs were disguised as OpenClaw (previously known as Clawdbot or Moltbot).

Other lures for SMBs: Fake communication apps and office software


Kaspersky analysts also explored how attackers leverage other legitimate applications as lures to target SMBs. For example, from January to April 2026, Kaspersky solutions blocked 414,736 attacks on SMB users in which malicious software or PUAs for PCs were disguised as the popular communication apps that Kaspersky’s report focuses on. The number of attacks changed marginally compared to the previous year’s figure, indicating that the lure of fake communication apps remains a serious cyberthreat.

Share of attacks targeting SMBs in which malware or PUAs mimic the four legitimate communication apps covered by Kaspersky’s research, first four months of 2025 and 2026 (download)
Various fake office applications and collaborative platforms also remain among the lures that attackers may exploit to target SMBs. According to Kaspersky telemetry, more than 24,000 attacks were detected from January to April 2026 in which malware or PUAs for PCs were disguised as specific office applications.

Share of attacks targeting SMBs in which malware or PUAs mimic the six popular office applications and collaboration tools covered by Kaspersky’s research, first four months of 2025 and 2026 (download)
In 2026, AI-related baits have become more widespread among cybercriminals than traditional fake office and collaboration tools. Kaspersky experts note that the more publicity and hype there is around certain tools, the more likely a user is to come across a fake package online.

Scammers and phishers tricking victims into providing credentials and funds


In 2026, Kaspersky researchers observed a wide range of phishing campaigns and scams targeting businesses and entrepreneurs. Fraudsters mimic financial and AI services as well as other platforms in order to steal credentials, personal information and funds.

In the following example, fraudsters disguise themselves as a bank that allegedly offers services for businesses (in other similar schemes they may offer business loans). Entrepreneurs are prompted to visit a scam website and enter their data to open a business account. The requested information varies depending on the scam, but may include name, email address, phone number, social security number, date of birth and address. Scammers may then use this data in their schemes or sell it on the dark web.

Kaspersky experts advise: if you encounter such a website, you should not rush to enter any data. First, examine it. Does the purported financial organization actually exist? How old is the website? Check the WHOIS records and read user reviews before entering any information on the page.

Example of a scam page targeting entrepreneurs
Example of a scam page targeting entrepreneurs

As with many other cyberthreats, AI services are also leveraged as a lure in scams. For example, Kaspersky experts identified a scam website for an AI service “built for contractors”. According to the text on the fraudulent page, the tool can help with “estimates, invoices and schedule”. However, in reality, in such schemes victims usually receive nothing after paying for a subscription, while the scammers get all the money.

Example of a scam page promoting an AI tool
Example of a scam page promoting an AI tool

Kaspersky experts note that business accounts on social networks and messengers remain attractive targets for cybercriminals in 2026. In one scheme, phishers distributed notifications with fake alerts related to companies’ business pages. The notifications claimed that Facebook’s review system had detected behavior that seriously violated its Community Standards and Advertising Policies. To avoid permanent restriction of their business page on the social network, owners were prompted to fill out an appeal form and provide personal and business email addresses, phone numbers, as well as the name of their business page and the password for their social network account. The attackers’ goal was to obtain credentials. To reduce user vigilance and appear legitimate, fraudsters also sent victims a fake appeal code.

Example of a fake notification
Example of a fake notification

Email threats: Fake online documents and exploitation of legitimate platforms


Email remains one of the most widely used channels for cyberattacks targeting enterprises, including small and medium-sized businesses. In 2026, attackers have frequently combined email distribution with the exploitation of legitimate third-party platforms. This is how phishers and scammers usually attempt to bypass traditional email filters and exploit user trust in reputable services. Kaspersky researchers have also observed a large number of schemes targeting corporate users in which phishers and scammers use fake online documents or nonexistent meetings as bait.

In one recent scheme detected by Kaspersky, the attackers sent a fake notification disguised as a letter from OneDrive. The victim was prompted to access the document by clicking a button, but in reality, it led to a phishing website where users risked losing their confidential data. To make the email appear legitimate, the attackers added a phrase designed to lower the victim’s vigilance: “This item is encrypted and hosted within your secure cloud perimeter.” They also parsed the recipient’s email address and used the extracted data in the fake notification text so that the email looked like a standard notification from this type of service: “[email address domain as company name] has successfully uploaded a new file for [the user’s name as stated in their email address].”

Example of a phishing scheme with fake online documents
Example of a phishing scheme with fake online documents

Attackers also use other pretexts to trick victims into sharing confidential information, for example fake compliance issues. In the example below, the attackers posed as Apple representatives. The fake notification stated: “Apple has identified a compliance issue related to Google Ads campaigns directing traffic to Apple product detail pages associated with the victim’s seller account.” However, the button in the email led to a phishing website where users are tricked into sharing confidential data.

Example of a fake compliance issue notification
Example of a fake compliance issue notification

Kaspersky experts observed another notable two-stage scheme aimed at stealing credentials from corporate emails, which involved distributing an invitation to a nonexistent meeting. The scheme is deployed in two stages. In stage one, a corporate user receives an email about a fictitious meeting. After clicking the “Accept Meeting Invitation” button, the user is redirected to a legitimate Zoom Docs (previous Zoom canvas brand) page. In stage two, the victim is prompted to click a hyperlink that reads “Click Here to Accept Meeting”. However, the URL of a phishing page is hidden behind this hyperlink.

Example of an email with a fake meeting
Example of an email with a fake meeting

Zoom Docs page containing the phishing link
Zoom Docs page containing the phishing link

Malware is also actively distributed via email. In 2025, individuals and corporate users encountered over 144 million malicious and potentially unwanted email attachments, representing a 15% increase from the previous year.

Kaspersky experts note that the lures used in subject lines and texts of malicious emails can appear relatively harmless and rather unsophisticated. In the example below, the attackers target businesses with a fake request for “the best quote for the items attached.” However, the attached file actually contains a Trojan.

Example of a malicious email
Example of a malicious email

Corporate infrastructure access for sale: Posts on the dark web


To assess threat actor activity, Kaspersky Digital Footprint Intelligence experts analyzed hundreds of posts offering initial access to corporate infrastructures published on dark web forums from January to April of both 2025 and 2026. Kaspersky experts note that a single post may contain several offers for access to different allegedly compromised companies.

Example of a post on a darknet forum
Example of a post on a darknet forum

Initial access brokers (IABs) sell initial access to compromised businesses, for example, via RDP or web shells. In their posts, IABs may provide information about the region where the allegedly compromised companies are located, their industry and revenue, as well as the type of access. IABs sell access that the buyers can then use for different purposes, including ransomware attacks, stealing corporate confidential information or other fraudulent activity. The price of initial access on dark web forums may depend on the revenue, industry or location of the allegedly compromised companies, or on the access privileges. For example, accounts with admin rights are usually more expensive because they can provide attackers with a wide range of possibilities.

According to the research, there were more posts offering initial access to companies of different sizes located in the Middle East (up 53% from last year), Africa (up 40%) and Latin America (up 17%). Meanwhile the number of posts related to companies located in Europe decreased by 34%. According to Kaspersky experts, this decline can be partially explained by the closure of a dark web forum containing such posts around the time of the study. The number of publications related to companies located in the APAC region also decreased slightly (down 4%), but remained at a consistently significant level for the second year in a row.
At the same time, the number of posts where the region was not specified decreased by 56% in 2026 compared to the previous year. Kaspersky analysts assume that this may indicate that initial access posts from IABs are becoming more targeted and unique.

Share of posts with initial access offers by business size


For this research, Kaspersky experts defined a small business as having an annual revenue of up to US$50 million, and a medium-sized business as having an annual revenue of between US$50 million and US$1 billion.

According to Kaspersky’s research, at the beginning of 2026 the share of posts on dark web forums with offers of initial access to allegedly compromised small businesses was larger than the shares of posts offering access to medium, large or nonprofit organizations. However, this share decreased in the first four months of 2026 compared to the same period in 2025. The share of posts concerning mediumsized organizations also remained significant for two consecutive years. Taken together, posts concerning small and mediumsized organizations account for more than half of all the analyzed posts with initial access offers on dark web forums.

At the same time for a certain number of posts initial access brokers didn’t indicate companies’ revenue, therefore, making it impossible to determine the size of the company.

Share of posts with initial access offers by business size, January–April 2025 (download)

Share of posts with initial access offers by business size, January–April 2026 (download)
Kaspersky experts note that despite the prevalence of posts concerning small businesses, threat actors may target medium‑sized businesses because they generate higher revenues than small businesses and may have weaker security defenses than large businesses.

SMBs can also become targets as a part of trusted relationship attacks, which enable the attackers to reach larger organizations. According to the Global Report by Kaspersky Security Services, the share of trusted relationship attacks among the initial vectors increased from 12.7% in 2024 to 15.5% in 2025. Therefore, the common belief that small and medium‑sized enterprises are of no interest to attackers is a misconception. Companies of all sizes need to understand the cyberthreat landscape, adhere to cybersecurity rules, implement appropriate cybersecurity solutions, and continuously improve employee awareness.

Cybersecurity action plan for SMBs


SMBs can reduce risks and ensure business continuity by investing in comprehensive cybersecurity solutions and increasing employee awareness. To protect themselves from the ever-evolving threat landscape, companies are advised to follow these rules:

  1. Define access rules for corporate resources such as internet services, email accounts, shared folders, and online documents. Keep access lists up to date and revoke access promptly when employees leave the company.
  2. Regularly back up important data to ensure the preservation of corporate information in case of emergencies.
  3. Establish clear guidelines for using external services and resources. Create well-defined procedures for coordinating specific tasks, such as implementing new software, with the IT department and other responsible managers. Develop short, easy-to-understand cybersecurity guidelines for employees, with a special focus on account and password management, email protection, and safe web browsing. A well-rounded training program will equip employees with the necessary knowledge and ability to apply it in practice.
  4. Raise employees’ security awareness. Conduct dedicated training to teach staff how to detect and address potential threats, and track their educational progress. Organizations can achieve this with the Kaspersky Automated Security Awareness Platform through interactive online modules and simulated phishing campaigns that build sustainable cyber hygiene habits across all teams.
  5. Implement specialized cybersecurity solutions that fit your budget, size, and industry requirements, with an emphasis on scalability and ease of integration.
    1. Kaspersky Small Office Security Premium is an easy-to-use solution that protects against advanced threats and also provides access to security awareness training for employees, making it ideal for micro-businesses.
    2. Small and medium-sized enterprises with more mature IT expertise should consider Kaspersky Next Optimum, which is designed specifically for growing organizations and offers real-time protection, threat visibility, as well as EDR and XDR investigation and response capabilities.


  6. Protect your business against email-borne threats. Kaspersky Security for Mail Server, a comprehensive email security platform that offers robust, multi-layered protection at mailbox and gateway levels, can help with this. Powered by machine learning and leading global threat intelligence, it effectively addresses all mail security challenges.
  7. Adopt specialized solutions such as Kaspersky Digital Footprint Intelligence to monitor the surface, deep, and dark webs for information about a company’s credentials, leaked data, and lookalike websites. Small and medium-sized companies with limited IT security budgets can partner with a managed security service provider (MSSP) to access this comprehensive digital risk protection service at an affordable, subscription-based price point.

securelist.com/smb-threat-repo…

A Look at a Gaggle of Transputer Boards


The media in this post is not displayed to visitors. To view it, please log in.

A long time before Beowulf clusters wired up with commodity Ethernet hardware became a hobbyist thing and a running joke, the transputer took a swing at a very similar architecture. This used stand-alone computers that were networked together with other transputer systems, to achieve task-level parallelism. For some people like [Lance Harvie] this is the kind of hardware that he used during his university years for a project, with him not only still having that hardware, but also recently adding to this collection with a recent eBay purchase.

The transputer story is a fascinating one, forming a major part of the UK’s semiconductor industry during the 1980s, creating a strong legacy as the computer industry awkwardly tried to figure out what types of parallelism to target. Whereas the industry largely moved to instruction-level (superscalar) parallelism alongside tightly coupled task-level parallelism along with multiple CPU cores on a single die, one could consider today’s supercomputer clusters to be one example of the transputer legacy.

Close-up of the T424-based 4-processor board. (Credit: Lance Harvie, YouTube)

[Lance]’s university-era board features the T400, which he shows off while recalling programming it in the Occam language. He’s currently looking for an ISA-to-USB adapter to be able to use it again with a modern PC. While searching around, he came across an EBay listing for a four-processor board, containing four T425s. These are significantly more powerful and also can use external memory, unlike the T400.

This four-CPU board omits the external serial links, as it’s meant to be used in e.g. a scientific instrument as a stand-alone 4-unit transputer system, with all of the available four serial links per processor connected on the PCB. Even more interesting is that the processors on this board were manufactured in 1999 by ST, which was many years after transputers stopped being developed.

As [Lance] explains, this was due to the UK government pulling the plug on the transputer project, with the IP subsequently ending up at ST who kept producing the chips until 1999 at its Philippines plant.

In time, [Lance] hopes to power up all these boards and use them again in combination with a modern-day Linux-based computer. We’re definitely looking forward to seeing that happen.

Although you can definitely use any random MCU these days as your very own transputer module or link chip, with e.g. SPI making for an attractive alternative for the high-speed serial links, there’s always something to be said for using real, original hardware.

youtube.com/embed/lhG2r78Vi5Y?…


hackaday.com/2026/06/25/a-look…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

La faccenda di #Emma di #Egomnia, la spocchiosità di Achilli e il motore a gatto imburrato.

Era una giornata partita male, ma mi sto divertendo un sacco =)

Orsù, imbrileggiate tutti!

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Venduti accessi a POS italiani sul dark web: 250 dollari per controllare un punto vendita

📌 Link all'articolo : redhotcyber.com/post/venduti-a…

A cura di Luca Stivali del gruppo DarkLab

#redhotcyber #news #cybersecurity #hacking #malware #ransomware #cracking #accessoRemoto

Cybersecurity & cyberwarfare ha ricondiviso questo.

#WSocial, metriche fittizie del patetico social closed source europeo (e la bellezza dei dati aperti). Il post di @_elena

Emerge un'abnorme discrepanza tra le metriche visualizzate sulla landing page di W Social, che mostra i post della sua rete come schede fluttuanti, e il numero reale di interazioni che si riscontra controllando i messaggi originali su ATproto.

blog.elenarossini.com/w-social…

@fediverso

mastodon.social/@_elena/116809…


SCOOP: on #WSocial's website, comment counts for posts by prominent users are incorrectly displayed, showing artificially elevated numbers.

An ATproto user came up with an interesting theory for it.

My article: "W Social, Fictional Metrics and the Beauty of Open Data"

🔗 : blog.elenarossini.com/w-social…

#blog #BigTech #EUBigTech #TEP #TrustedEuropeanPlatforms #TrustYourFeed


Cybersecurity & cyberwarfare ha ricondiviso questo.

È venuta a trovarmi Serena Mazzini, esperta di media digitali. Siamo partiti da come gli strumenti digitali stanno agendo come surrogati dei rapporti sociali, modificando l'esperienza delle persone che li usano dai bambini agli anziani.

Qui: youtu.be/OnC7H2hMt5I

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

il vero #condizionatore naturale

#alberi
#meravigliedellanatura
#PassoDelChiodo
#MontePenna
@genova

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Cisco #Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited Months Before Disclosure
securityaffairs.com/194200/hac…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

Risotto o non risotto? Ma è meglio il cosciotto o l'orata?

È giovedì, e non si parla di delikatessen, ma di quella subdola abitudine di fotografare il cibo prima di mangiare..

Ne parlo nel nuovo #SocialDebug, confessando anche di aver spesso fatto foto al cibo e di essere arrivata al punto in cui il mio Armadillo interiore m'ha detto: "e mo' basta! Che ogni volta che devi fotografa' tutto quello che sta sul tavolo more un Dodo. E già, a senti' l'ai de' #Egomnia stanno messi male, nun te ce mette pure te! Dai, su!"

signorina37.substack.com/p/soc…

L’irrilevanza delle formule di stile: l’autorizzazione dell’interessato non solleva dall’accountability


@Informatica (Italy e non Italy)
Il Garante Privacy chiarisce che una formula di autorizzazione al trattamento non esime il titolare dall’applicare i principi del GDPR e, nel procedimento di accesso civico generalizzato, la pubblica

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

State-Sponsored Hackers Exploit Cisco Catalyst SD-WAN Manager Zero-Day to Gain Root Access
#CyberSecurity
securebulletin.com/state-spons…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Operation Endgame Strikes Again: Europol Seizes StealC, Amadey and SocGholish Infrastructure — 326 Servers Down, $47M Frozen
#CyberSecurity
securebulletin.com/operation-e…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

CISA Flags Actively Exploited Ubiquiti UniFi OS Vulnerabilities — Patch Deadline June 26
#CyberSecurity
securebulletin.com/cisa-flags-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

World Leaks Ransomware Dumps 630 GB of Tata Electronics Data — Confidential Apple and Tesla Files Exposed
#CyberSecurity
securebulletin.com/world-leaks…
Cybersecurity & cyberwarfare ha ricondiviso questo.

Nathan Austad Pleads Guilty in #DraftKings Hacking Scheme, Gets 18 Months
securityaffairs.com/194184/cyb…
#securityaffairs #hacking
in reply to securityaffairs

So this is how they're going to cover up what essentially is an admission that they aren't actually able to cover all of the bases on a platform that basically operates in a way that invites fraud.
In 2022 my debit card was used on Draft Kings. This shouldn't be possible a) They have no license in my state, b) As an advantage wagerer I'm not allowed to wager on shore anywhere, or am severely limited. Of course there's no official list but in Nevada I can go to a book and watch games, order drinks, but wager? Hah.
But since I don't wager on shore I don't keep fiat so hilariously enough they weren't able to wager much anyway. Since there's no "advantage player central" type chat I don't know anyone else's strategy, but I win 30% of my bets and make, depending on sport, anywhere between 8-10% profit. Except for the Crystal Palace giant killing spree where I managed a 108% ROI and DeepDribble 1.2 for 3 month had a 12% edge on the opening line. Thanks to the senator from Idaho nobody who does this for a living is able to wager this year because of a one line 10% per-wager tax added to the OBBBA that thanks to the shutdown and apathy is left in the law. 400k Americans lost their jobs. Thanks Mike Crapo. Nominative Determinism, anyone?
In any case, since they can't be taking any wagers on shore from Nevada, real or fake, the incident was reported to the NV Gaming Commission. Obviously nothing came of it, because just to stop Boyd from getting free money for no reason took 4 individuals writing in separately. What a joke.
And onshore books that don't know what they're really doing are asking to get wiped. Look, we know who you hire to make lines. We know how much of an edge we have on them. You don't offer enough markets to make it worthwhile and ban or bankrupt is not a viable long term strategy. Lobby all you want, but to do this for a living a unit is at least 4, and frequently 5 digits. We expect to lose on individual bets, but in the aggregate even through COVID 9 years of profit isn't an accident, the sample size is too big.
But credential stuffing is so 2018. Come on. This is barely worth the time of an AUSA. I'm not allowed to sign up on these books, it's not creds (I use a pass manager + HW key anyway if possible), it's a backend leak of CC info that went over rails that were hilariously insecure. You just can't figure out where. I'd like to know who doesn't get credential stuffed, frankly. Thta would be news.

Sincerely, former CJA Attorney who knows your tactics, and also, knows wagering is a financial derivative.