Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

FBI and Allied Governments Warn Companies Are Unknowingly Hiring North Korean Operatives
#CyberSecurity
securebulletin.com/fbi-and-all…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

SolarWinds Patches Critical Authentication Bypass That Could Unlock Help Desk Portals Without a Login
#CyberSecurity
securebulletin.com/solarwinds-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The Gentlemen Ransomware Uses a Malicious Kernel Driver to Blind Security Tools Before Striking
#CyberSecurity
securebulletin.com/the-gentlem…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

How One Poisoned Tracking Script Turned a Major Ad Platform Into a Crypto-Theft Pipeline
#CyberSecurity
securebulletin.com/how-one-poi…

Road Trains Roam The Backroads of Australia


The media in this post is not displayed to visitors. To view it, please log in.

Trains and the railways they run on are a great way to move lots of stuff, or lots of people, a long way. Steel wheels on steel rail can shift great loads at good speeds and railways remain a backbone of logistics for this very reason. The only problem is that they require a great deal of initial investment to build and plenty of maintenance to keep them functional over time.

These concerns can make a railway a difficult proposition when it comes to getting large amounts of goods in and out of remote areas. It’s a problem that Australia faces, with settlements far off the beaten track that are nevertheless in need of high-throughput freight connections. And if you can’t go rail, you go road… in a big way.

Heavy Haulers


The simple fact of Australia’s geography is that there are towns and cities separated from each other by thousands upon thousands of kilometers. It’s often desirable to move goods to and from these places, along with remote mines and farms buried in the country’s vast, dry interior. However, it has never been practical to link all these disparate locales by permanent railways. The distances have always been too vast, and the freight volumes not quite high enough to justify the expense. At the same time, relying on trucks alone was seldom economically convenient.
An MGM Kenworth C509 pulling a 60-meter A-quad configuration in Western Australia. Credit: SquiddyFish, CC BY 4.0
The solution was straightforward, and surprisingly simple—bigger trucks hauling more trailers. In the local parlance, a road train consists of a prime mover (or tractor) that hauls two or more trailers.

The official definition from the Heavy Vehicle National Law excludes the standard B-Double configuration that is regularly seen across the country. Instead, a road train could be a longer A-Double configuration, or even one of a variety of combinations involving three or four trailers being hauled by a single prime mover, like a B-Triple or a BAB Quad. The A and B designations refer to the type of coupling used. A-type refers to drawbar-based couplings, while B-types are fifth-wheel or turntable-type couplings. A truck or road train setup is thus referred to by the couplings that make up the consist.
A four-trailer BAB-Quad road train in Marla, South Australia. Credit: Caroline Jones, CC0 We count 12 shipping containers.
The longest road train configurations of three or four trailers typically range up to 53.5 meters in length and over 135 tons in weight, per the rules laid down by the National Heavy Vehicle Regulator, though even longer configurations are used in some specially-permitted or off-highway roles in mining or agricultural industries.

These long consists are typically pulled by large prime movers with anywhere from 500 to 700 horsepower and 1500 to 2000 pound-feet of torque. Ultimately, it doesn’t actually take a grand amount of power to get even a very heavy load moving; it’s the torque that helps the most, anyway. The bigger challenge is actually stopping, and that takes great care and makes road trains unsuitable for crowded roads. As far as applications go, road trains are used for hauling all sorts of goods and material across Australia. Common loads include livestock, ores, and general freight, as well as long chains of tankers for hauling bulk amounts of fuel.
Various road train configurations, as laid out by the Heavy Vehicle National Law. Consists are referred to by the manner in which trailers are coupled together. Credit: NHVR.gov.au
Road trains also wear large signs front and back to indicate their status. Typically, this consists of large black text on a yellow background reading “ROAD TRAIN” or “LONG VEHICLE” depending on the jurisdiction. Classified nationally as heavy vehicles, road trains are limited to speeds of 100 km/h, except in NSW and Queensland where they are limited to just 90 km/h (except for B-Triples in the latter state). These regulations in part help to ensure that motorists know what they’re dealing with when coming across a large road train on the open roads in the Australian outback. It can take quite a long time to pass a road train at legal highway speeds, so motorists need to be aware when attempting such a manuever.

Largely by virtue of their length alone, road trains are restricted in where they may or may not travel. For example, in South Australia, B-triples that measure up to 35 meters long are only allowed to travel via specific routes to industrial and import/export hubs, to avoid them causing chaos in built-up metropolitan areas. Similar rules exist in other states and territories, too, where triple and quad configurations are allowed to operate at all. Notably, Darwin, capital of the Northern Territory, is unique in allowing triple and quad roadtrain consists to operate within a kilometer of the central business district. The city’s limited size and density, with a population of just 140,000, means that this isn’t the same practical disaster that it would be in other major metropolitan centres around the nation.
A four-trailer road train hauling fuel near Broome, Western Australia. Credit: W. Bulach, CC BY-SA 4.0
The “road train” terminology does have some purchase in other parts of the world. However, it generally refers to B-Doubles or other smaller consists compared to the Australian norm, where it only refers to the very largest configurations.

For example, countries like Spain, Sweden and Germany allow truck-trailer combinations up to 25 meters long, while trucks in the United States are largely limited to two trailer configurations up to 19 meters maximum. In these other jurisdictions, there is seldom the same economic incentive to haul excessively long trailer loads to maximise the efficiency of freighting to and from far-flung destinations. Greater traffic and other road network considerations also limit the practicality of extra-long consists in more densely populated regions.

However, in the outback of Australia, where the roads are so empty and the distances so great, the three- or four-trailer road train starts to make a whole lot more sense. Road trains aren’t going anywhere as long as Australia maintains its low population density and needs to haul goods to and from distant rural and regional areas. If you go far enough beyond the cities, or to the right freight terminals, you might just see some of these rolling behemoths ploughing their way across the landscape!


hackaday.com/2026/08/04/road-t…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

865,000 ‘No-Logs’ VPN Users Exposed After SplitVPN Breach Reveals Hidden Connection Records
#CyberSecurity
securebulletin.com/865000-no-l…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

ShinyHunters Strikes Again: Brinks Home Confirms Breach Tied to Salesforce Systems
#CyberSecurity
securebulletin.com/shinyhunter…
Cybersecurity & cyberwarfare ha ricondiviso questo.

#INC #Ransomware is Calling Victims - Pressure Tactics Post #SonicWall Zero-Day Exploit
securityaffairs.com/196607/mal…
#securityaffairs #hacking #malware
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

CVSS 10.0: la vulnerabilità critica di Ruflo espone le chiavi OpenAI e Anthropic

📌 Link all'articolo : redhotcyber.com/post/cvss-10-0…

Luigi Zullo

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

4/8/2026 - Installazione/Aggiornamento Openbook

L'ultima release appena pubblicata implementa il sistema di installazione/aggiornamento di una istanza estremamente semplificato.
Per iniziare una nuova istanza è ora possibile andare su about.openb.app e scaricare lo script di bootstrap. E' sufficiente farne upload sul proprio shared hosting con PHP+MYSQL e via browser partirà un wizard che recupera tutta l'ultima release di Openbook, con le impostazioni di base.

Nello screenshot vedete il pannello admin della propria istanza che controlla se ci sono aggiornamenti da applicare. Se ci sono, si potranno applicare direttamente da questa schermata.

Added


  • Bootstrap setup-openbook.php: wizard pre-Laravel che scarica la release
    ufficiale da about.openb.app (zip + SHA-256), prepara .env / .htaccess
    e avvia /install.
  • Pannello admin Aggiornamenti: confronta la versione locale con
    releases/latest.json, applica l'archivio preservando .env e storage/,
    esegue le migration e registra l'azione in audit.
  • Script bin/build-release.sh e template in distribution/ per pubblicare
    pacchetti shared hosting (con vendor/) e il manifesto JSON.
Cybersecurity & cyberwarfare ha ricondiviso questo.

Riflessioni di Luciano Della Volpe sui domiciliari allo youtuber che durante una diretta ha ucciso un bambino con il suo SUV


Differenza tra notizia data bene e notizia data male solo per attirare click e commenti indignati.
Purtroppo lo fanno molti giornali che hanno capito le dinamiche dei social e le sfruttano per fare disinformazione.
Il caso è quello dello schianto a tutta velocità mentre facevano un video YouTube (probabilmente ve lo ricordate).

Notizia corretta:
Lo youtuber Matteo Di Pietro, condannato a 4 anni e 4 mesi, finirà di scontare gli ultimi 15 mesi ai servizi sociali (dopo aver già fatto3 anni ai domiciliari)

Notizia acchiappa-clic:
Uccise con un Suv un bambino di 5 anni. Lo youtuber ai servizi sociali per 15 mesi.

Inutile dirvi che nei commenti il putiferio: "Omicidio stradale 15 mesi ai servizi sociali! Complimenti".
Quando è che l'ordine inizia a segnalare la disinformazione dei giornali?

(Certo, anche la pena totale di 4 anni è spicci è discutibile , ma la seconda versione fa credere che gli abbiano dato solo 15 mesi di servizi sociali.)


x.com/i/status/208455697074108…

@giornalismo

Cybersecurity & cyberwarfare ha ricondiviso questo.

New npm worm ChainDrop appears to be having a great time in the ecosystem right now

stepsecurity.io/blog/chaindrop…

socket.dev/blog/popular-npm-pa…

safedep.io/keyv-npm-supply-cha…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

CVE-2026-58048: #cPanel Bug Enables Full Database Administrator Access
securityaffairs.com/196595/sec…
#securityaffairs #hacking

How legitimate cloud platforms enable phishers to bypass MFA


The media in this post is not displayed to visitors. To view it, please log in.

Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, we have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This post analyzes the mechanics of a real-life adversary-in-the-middle (AitM) attack in a cloud environment and presents detailed statistics on the platforms and domains phishers abuse most frequently.

The cloud as a safe haven for phishers


Threat actors select platform-as-a-service (PaaS) offerings and distributed cloud environments to host phishing sites for much the same reasons legitimate software developers do:

  • Inherent trust and reputation. Phishing pages hosted on reputable platforms appear trustworthy, reducing suspicion among potential victims.
  • Most platforms offer generous free-tier developer plans. The onboarding process takes minutes and rarely requires Know Your Customer (KYC) identity verification. This enables a single operator to create hundreds of malicious accounts.
  • Evasion and anonymity. Attackers leverage native security features to obscure their true origin server IP address behind a CDN, which complicates detection for security vendors.

Additionally, these platforms allocate shared subdomains hosting millions of legitimate projects and websites. Security teams cannot simply block the parent domain or its subdomains without inflicting collateral damage on bona fide users – a limitation that malicious actors take advantage of. To counter this tactic, security vendors must advance content-based analysis methodologies.

Multi-stage AitM attack


Consider a modern AitM phishing campaign that leverages Cloudflare Workers, a widely adopted cloud platform. The attackers execute the operation through multiple HTML pages distributed across a compromised website and the cloud platform. Each page serves a specific function: harvesting target email addresses, initializing the reverse-proxy infrastructure, or spoofing the login form to capture multi-factor authentication (MFA) sessions.

Stage 1. Contact harvesting and network monitoring evasion


The attack typically begins with a phishing email that uses a plausible pretext – such as a request from a coworker to review documents – to entice the target into clicking a malicious link.

Upon clicking the link, the user is redirected to a fake CAPTCHA landing page hosted on a compromised legitimate website. This specific campaign used the https://t[REDACTED]e.com website, but any other variations are possible. In this scenario, the compromised page served as a disposable relay — vendor detection mechanisms typically block phishing links delivered directly via email much faster — to prevent the early discovery of the core phishing content hosted on Cloudflare.

If the user entered their email address and clicked Continue, the pseudo-CAPTCHA marked them as a human user and initiated a redirect. The primary objective of this stage is to harvest target email addresses, filter out bots, and route legitimate users to a subdomain of workers.dev. Such subdomains are generated automatically and free of charge by Cloudflare Workers. The victim’s email address was embedded in the URL hash (the part of the URL following the # character), allowing the page at [REDACTED].workers.dev to extract the email without issuing a request to the attacker’s server, thereby avoiding detection.


Stage 2. Initializing a transparent proxy


The user’s browser then loaded a [REDACTED].workers.dev page with #user@business.com at the end of the URL. At this point, the page presented the victim with a genuine CAPTCHA challenge. This step ensured that an actual user was interacting with the page rather than a security sandbox.

Another CAPTCHA, this time a legitimate one
Another CAPTCHA, this time a legitimate one

Once the user successfully completed the challenge, a service worker was registered in their browser. This is a special JavaScript file capable of running in the background and intercepting all network requests generated by the current tab. As this type of script was designed as a core component of progressive web apps (PWAs) to optimize load times and support offline functionality, browsers treat service workers as standard site feature and execute them without prompting for user consent as long as the website uses an HTTPS connection.

The attackers leveraged the service worker to deploy Ultraviolet, a legitimate open-source web proxy library, to dynamically rewrite all links and forms on the page. This forced every outgoing request – including those for Microsoft login credentials – to route through the attackers’ server rather than directly to the legitimate services.

Immediately upon loading, the page extracted the victim’s email address from the URL hash and stored it in the browser’s sessionStorage property so it would not be overwritten when the CAPTCHA loaded. This step also allowed the script to pre-fill the username field in the form automatically. A pre-populated login field enhanced the page’s credibility and bolstered user trust. Once the CAPTCHA was passed, the malicious script constructed a redirect URL for the third stage, appending the email retrieved from sessionStorage back to the hash. By passing the email via the URL hash across three consecutive stages, the attackers successfully kept it hidden from network attack detection systems.

Registering a service worker to intercept traffic
Registering a service worker to intercept traffic

Establishing a transparent proxy via an external library
Establishing a transparent proxy via an external library

Stage 3. Session hijacking and browser window spoofing


The final stage unfolded on a third page, combining adversary-in-the-middle (AitM) traffic interception with a browser-in-the-browser (BitB) UI spoofing technique. BitB attacks operate by rendering a block inside a legitimate webpage that visually mimics a native browser pop-up window.

In this case, the script hosted on the attacker’s page generated a pop-up visually identical to a native browser window, complete with window controls and a spoofed address bar showing a trusted Microsoft URL. Within this simulated window, an iframe loaded the authentic login interface, routed dynamically through the service worker reverse proxy created in Stage 2. When the victim entered their credentials and MFA code into the BitB window, the proxy script intercepted both the credentials and the session tokens. Combining BitB with AitM significantly increases the threat: BitB provides a convincing, trusted visual wrapper (displaying a legitimate URL and branding), while the hidden AitM proxy quietly handles traffic interception and session hijacking behind the scenes.

Upon successful login, the proxy instructs the interface to close the pop-up and redirect the victim to a generic system error page, such as SessionExpired. This minimizes suspicion: the victim assumes a technical glitch occurred and attempts to log in again, unaware that the attacker already has full access to the session.

Cloud platform phishing attack statistics


We analyzed phishing URLs hosted across popular cloud platforms – including Cloudflare, Netlify, and GitHub Pages – over a 12-month period spanning August 2025 to July 2026. The data below outlines trends in unique third-level domains exploited to deliver phishing content. In total, our security solutions blocked 224,984 unique third-level domains on cloud and decentralized services used in phishing attacks within that timeframe.

Number of unique third-level domains
(download)

Based on this telemetry, we compiled a list of the TOP 10 cloud domains most frequently abused in phishing campaigns over the specified period.


Number of phishing links

Unsurprisingly, Cloudflare and Vercel emerged as the undisputed leaders: both offer free tiers, automated SSL certificate issuance, and global CDNs. GitHub Pages ranked third. The widespread legitimate use of the github.io domain complicates bulk blocking efforts, as security teams risk limiting access to non-malicious projects.

Decentralized networks also warrant close attention – we posted on this subject in 2023. The ipfs.io and dweb.link domains function as IPFS gateways. The principal risk associated with these platforms is content persistence: even if a specific gateway gets blocked, the phishing page remains accessible via alternative nodes across the network.

The visual website builders Wix and Webflow also ranked among the TOP 10 (eighth and ninth, respectively). These platforms allow low-skilled individuals to build phishing pages rapidly without advanced coding expertise, which significantly lowers the barrier to entry for less capable malicious actors.

DomainNumber of phishing linksPlatform
1pages.dev24.9%Cloudflare Pages
2vercel.app13.8%Vercel
3github.io13.7%GitHub Pages
4netlify.app10.0%Netlify
5dweb.link7.8%IPFS gateway
6ipfs.io5.3%IPFS (InterPlanetary File System)
7workers.dev2.5%Cloudflare Workers
8wixstudio.com1.9%Wix Studio
9webflow.io1.0%Webflow
10azurewebsites.net1.0%Microsoft Azure
Other17.9%

In total, we identified and neutralized over 390,000 phishing pages hosted across legitimate cloud platforms and decentralized networks (IPFS) over the past 12 months. This data confirms that threat actors actively exploit the implicit trust associated with legitimate PaaS providers (such as Cloudflare Workers, Vercel, Netlify, and GitHub Pages) and IPFS gateways. High domain reputation, generous free tiers, and built-in evasion capabilities enable phishers to deploy multi-stage AitM attacks designed to hijack MFA sessions.

Recommendations


Traditional security controls, such as relying on HTTPS lock icons or reputation-based domain denylists, are inadequate against these attacks. The cloud provider’s apex domain maintains a positive reputation score, while attackers generate malicious subdomains programmatically and at scale.

Effective defense against these threats calls for a layered security posture:

  • Exercise caution with unexpected requests, even if they are served from reputable domains or secured with valid SSL/TLS certificates.
  • Treat any CAPTCHA interface requiring personal data input as a possible scam. Legitimate CAPTCHA challenges rarely request personally identifiable information, such as email addresses.
  • Inspect the URL in the address bar at the very top of the browser window. In BitB attacks, threat actors can render a fake browser pop-up displaying any target URL, even a legitimate one. However, the true address bar – located at the top of the main browser window alongside native navigation controls (Back, Forward, Refresh) – will continue to display the actual attacker-controlled domain.
  • Avoid entering credentials in pop-ups you did not expect to see. If a login or MFA form appears without your explicit action, close the tab immediately. Navigate to the intended service manually by entering its address directly into the browser.
  • Additional protection can be provided by Kaspersky Secure Mail Gateway for enterprise environments and Kaspersky Premium for personal correspondence. These robust email security solutions neutralize phishing links at the delivery stage before they reach the inbox.

securelist.com/cloud-platforms…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Le immagini palesemente generate dall’intelligenza artificiale in genere vi piacciono o vi danno un certo fastidio? A me quelle troppo “artificiali” non piacciono per nulla. Viceversa quelle in stile “fumetto” in genere mi le trovo gradevoli. Sono curioso di sapere cosa ne pensate.

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Should you have to prove your age before you can read or speak online? KOSA would pressure online services to build age verification systems that put everyone's privacy at risk. eff.org/deeplinks/2026/08/sena…

Testing Hundreds of Used LFP Cells Requires Some Automation


The media in this post is not displayed to visitors. To view it, please log in.

Although Li-ion cells have become a lot cheaper over the years, if you wish to buy hundreds of high-quality ones for that performance go-kart project, you may feel financially pressured into going for the option of stripping down years-old commercial battery packs instead.

While this is a financially sound option, you do have to figure out what the condition is of each cell before you happily stuff them into a new battery pack for said go-kart, as [Within Tolerance] recently did.

This is something that can be done manually, but for the 768 lithium iron phosphate (LFP) cells that were obtained for this project that’d be quite the tedious task. Hence it was decided to instead spend that time designing a system to automate this process, capable of charging, discharging, measuring and quantifying individual cells.

You can find the resulting Cell Goblin battery tester project on GitHub, which entails a custom PCB featuring an ESP32-S2 as the brains and associated software to monitor the process on a connected PC. Fortunately the issues on the PCB that are described in the video are claimed to be fixed in the repository version.

Using five of these dual-cell cell testers it was possible to run through the hundreds of cells with ten cells at a time. An internal resistance meter was also wired into the PC-based software via its UART. As of publication of the video the testing was still in progress, which gives some idea of how long it takes to work through those cells.

youtube.com/embed/NCjXZjViC6E?…


hackaday.com/2026/08/04/testin…

Cybersecurity & cyberwarfare ha ricondiviso questo.

U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog
securityaffairs.com/196585/sec…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Buongiorno a tuttззззззззззззззз 🤣


Non ho nulla contro lo schwa e ho tanti amici schwa, ma quando scrivete

Buongiorno a tuttз


e vedo quel 3 rovesciato, penso sempre a questo:

japanesewithanime.com/2020/02/…

@azzate

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🚨 nuova rivendicazione #ransomware Italia 🚨

🏴‍☠️ gruppo #Safepay
🧬 New Point S.P.A. | Signa (FI)
🎯 settore: G - Commercio
🔗 new-point.it
🗓️ 03 agosto 2026

📄 sample: -
▪️ dati esfiltrati dichiarati: -
▪️ dati esfiltrati pubblicati: -
⏲️ scadenza: 06 agosto 2026

#ransomNews #cyberthreats #cybersecurity

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

#nerdystuff in pausa pranzo

#NothingToWatch è un modo assurdamente elegante di scegliere un film: un diagramma di Voronoi interattivo con decine di migliaia di titoli che si respingono e si attraggono come particelle =)

🎬 nothing-to-watch.port80.ch

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Un mare di bug per Chrome! Corrette 1442 vulnerabilità nelle ultime tre versioni di Chrome

📌 Link all'articolo : redhotcyber.com/post/un-mare-d…

Luigi Zullo

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

☕ CYBERBRIEFING — Martedì 4 agosto 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

Yellow YAG Produces Powerful Pulses in Les’ Leftover Laser


The media in this post is not displayed to visitors. To view it, please log in.

[Les] likes lasing lasers, and who doesn’t? [Les] likes larger lasers than lots of folks, with his current project being an Nd:YAG (that’s Neodymium:Yttrium Aluminum Garnet) flash pumped laser intended for tattoo removal. Like most of its ilk, the YAG crystal at the heart of that device is a rosy purple color, so when [Les] spotted a Yellow YAG with different doping promising powerful pulses, he purchased it promptly.

Specifically, the retailer was claiming a 30-50% efficiency increase for this yellow rod, thanks to cerium doping. It’s still considered an Nd:YAG, though you can label it as an Nd:Ce:YAG for clarity. The efficiency gain comes from the cerium atom taking unused energy from the flashbulb pulse — which is much broader-wavelength than the thin absorption line of the Nd ions in the rod — and giving that energy to the Nd atoms that do the lasing via fluorescence. He doesn’t try it, but reports on a paper showing these crystals can actually lase with reasonable efficiency from sunlight alone, which we’d love to see. Send us a tip if you try.

His original Nd:YAG rod produced 72.8 mJ pulses, while in the same setup with the yellow laser is peaking at 153 mJ, more than double the original output. That’s even better than the 30-50% [Les] expected, but he reckons it is because the old YAG is, well, old. The coatings break down over time, and UV light from the flashbulbs degrades the crystals too. That’s another benefit of tossing cerium in there, as apparently it acts as sunscreen for your laser rod. It lasts longer and works better, making it a no-brainer of an upgrade.

We’ve seen [Les]’s laser-based hacking before, like this diode-laser PSU and we’re always glad to take a look with our remaining eye. We also featured his tattoo removal laser back when he started working on it, along with less-lasery projects like his crystal-growing rig.

youtube.com/embed/fp-jHYiTUVY?…


hackaday.com/2026/08/04/yellow…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🚨 Si chiama DATABREACH, non "piccolo inconveniente tecnico"! 🚨

#redhotcyber #meme4cyber #meme #comico #cyber #hacking #hacker #infosec #infosecurity #quotes #meme #comica

Cybersecurity & cyberwarfare ha ricondiviso questo.

31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register
securityaffairs.com/196558/cyb…
#securityaffairs #hacking

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Dalla filiale italiana alla capogruppo UE: tra GDPR, Golden Power e segreti militari

📌 Link all'articolo : redhotcyber.com/post/dalla-fil…

Paolo Galdieri

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

391 – COME NON FARSI SOSTITUIRE DALL’INTELLIGENZA ARTIFICIALE camisanicalzolari.it/391-come-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Il costo dell’inganno: perché la cybersecurity è diventata una responsabilità del CEO

📌 Link all'articolo : redhotcyber.com/post/il-costo-…

Redazione RHC

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

A Versatile PDP-11/70 Emulator


The media in this post is not displayed to visitors. To view it, please log in.

The PDP-11 was a 16-bit minicomputer that was very influential in its time. That’s what inspired [vanheusden] to start working on an emulator for the machine in 2018, which has since been developed to run on a wide variety of platforms.

The emulator, named “Kek,” is quite capable, able to run Unix 5 up to an d including Unix 7 in multi-user mode, along with BSD 2.11 Unix depending on what it’s running on. It also supports classic hardware like RK05, RL02, RP06, and RP07 disks, the KW11-L line time clock, and the DC-11 serial line interface. The emulator can also run on a wide variety of platforms. It’s possible to run it on a standard Linux machine if so desired, or you can run it on BSD, MacOS, or Windows if so desired. Beyond that, you can even get it going on a Teensy 4.1 or an ESP32 if that’s more your jam. Modern microcontrollers are just that powerful that emulating a PDP-11/70 just isn’t a challenge anymore.

We love seeing old machines emulated and brought back to life. It’s funny to see how often it’s done on microcontrollers instead of full-scale PCs these days, too. Video after the break.

youtube.com/embed/6bbowY5vlmQ?…


hackaday.com/2026/08/03/a-vers…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

TOR Browser sotto tiro! Una pagina dannosa potrebbe compromettere la privacy

📌 Link all'articolo : redhotcyber.com/post/tor-brows…

Luigi Zullo

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Sketching Temporary Circuits with a Light-Triggered Floquet Topological Insulator


The media in this post is not displayed to visitors. To view it, please log in.

In semiconductor technology, a base material like silicon is permanently modified to induce certain electrical behavior. In comparison a topological insulator material could be used to create temporary circuits using something like light exposure. An example of this is the Floquet topological state, which has long been theorized, but is now claimed to have been demonstrated in SnTe semiconductor material, per a paper by [F. Chassot] et al. in Nature Physics.

The concept of topological insulators was first proposed in 1985, but proving their existence was hard. Recently photonic Floquet topological insulators (PFTIs) have gained interest, with experiments by [Qian Ma] et al. in 2025 as well as other teams confirming aspects of the theory.

This recent publication by [Chassot] et al. would thus confirm that optical control of topological insulators is thus possible. At the core of this effect is the band inversion that results from the light pulses, with the change in conduction being very brief, essentially for as long as the femtosecond pulses were maintained.

Although still very much in the fundamental research phase, the research on these electronic topological insulators offers an interesting look at potential new technologies, much like the field of photonic topological insulators does for photonics.


hackaday.com/2026/08/03/sketch…

Cybersecurity & cyberwarfare ha ricondiviso questo.

🥾 Abbiamo appena aggiornato Wanderer!

Abbiamo installato l'ultima versione di Wanderer, la piattaforma open source perr organizzare, pianificare e condividere percorsi GPS, senza pubblicità, abbonamenti o paywall.

Con questo aggiornamento abbiamo risolto alcuni problemi segnalati e ora tutto dovrebbe funzionare correttamente. 🤞
Se non avete un account, potete registrarvi qui:

👉 wanderer.devol.it

fateci sapere se è tutto a posto!

Buone escursioni!🥾🗺

siamo su: @internet

Questa voce è stata modificata (6 giorni fa)

Energizing a Vacuum Tube Flip-Flop Module of the IBM 604


The media in this post is not displayed to visitors. To view it, please log in.


Reverse-engineered schematic of the IBM 604's TR-3 module. (Credit: Ken Shirriff)Reverse-engineered schematic of the IBM 604’s TR-3 module. (Credit: Ken Shirriff)
Taking a break from ogling microscopic features in Intel’s semiconductor processors, [Ken Shirriff] is back to instead poking at decidedly macroscopic pluggable modules from the 1948 IBM 604 Electronic Calculator. This time around it’s one of the so-called trigger modules in the form of the TR-3, which uses a flip-flop circuit to implement the timing signals and pulses that made the 604 work.

This differs from the thyratron module that we covered previously. A thyratron is a high current switch and rectifier, which is useful more for the periphery of the computer system. These TR-3s on the other hand were used to implement the basic logic circuits, even if a flip-flop by itself seems rather boring, being just a circuit that toggles between two states.

In this TR-3 module we find a 2033 dual triode design which thus increases density by having the two inverters of the flip-flop in the same tube. The rest of the module is taken up by the requisite capacitors and resistors that complete the circuit. After wiring up this original module, [Ken] was able to make it trigger somewhat reliably, requiring a stable input trigger.

Notable is that in the IBM 650 from 1954 this flip-flop circuit was abandoned in favor of one based on diode logic, presumably to use more reliable Boolean logic instead of the much fussier analog interactions. Naturally, in the first transistorized computers the use of diode-transistor logic (DTL) was exceedingly common, so this makes a lot of sense.

youtube.com/embed/KaAv1yJ30PU?…


hackaday.com/2026/08/03/energi…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Live streams from the BSides Las Vegas 2026 security conference, which is taking place this week, are available on YouTube

youtube.com/@BsideslvOrg/strea…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

#PacketHunters – Una falsa email di "pagamento non riuscito", 48 ore e un addebito di 500 sterline da Ticketmaster che non hai autorizzato

Come fa la truffa dell'email di pagamento falsa di Spotify a rubare i dati della carta di credito?

Un abbonato a #Spotify riceve un'email.
Pagamento non riuscito, aggiorna la tua carta entro 48 ore o perderai l'abbonamento Premium.
È distratto, la sua vera carta sta davvero per scadere, quindi la storia gli sembra plausibile ancora prima di finire di leggere. Clicca.
Pochi minuti dopo: un SMS di verifica della carta, seguito da un tentativo di acquisto su Ticketmaster per un valore di circa 630 dollari. Non è un'ipotesi, è quello che il Guardian ha riportato essere accaduto a una vittima reale nel luglio 2026, e si tratta dello stesso tipo di truffa che sta colpendo le caselle di posta elettronica proprio ora.

blog.baited.io/2026/%f0%9f%8e%…

@informatica

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Diversi utenti hanno segnalato ore fa un'interruzione del servizio WhatsApp in tutto il mondo. Tuttavia non ho visto notizie sulle principali fonti di informazione.

Secondo i report di Downdetector, i problemi principali, che adesso sembrerebbero rientrati riguardavano l'invio di messaggi, la connessione al servizio e l'accesso.

@informatica

reshared this

Circuit Bending, But Make It MIDI


The media in this post is not displayed to visitors. To view it, please log in.

Circuit bending is a chaotic art. At its simplest, it can just involve making connections between random points on a circuit board to create weird sounds in musical hardware. Or, you can complicate things, get really specific with your hookups, and twist them with various sorts of modulation. [Simon the Magpie] has been working on something closer to the latter category, with his neat project to add MIDI to the circuit bending world.

The concept is straightforward enough. [Simon] has created a device that you place in line with your circuit bent connections, particularly those that create pitch bends with pots thanks to their variable resistance. You can then play your MIDI keyboard, and the device will vary the resistance in the circuit and bend the pitch at your command. [Simon] simply calls the device MIDI TO RESISTANCE, because that’s… precisely what it does, with the aid of a digital potentiometer. He then demonstrates it doing its thing on pitchbent toys, and it sounds pretty radical in use.

If you’re trying to make your circuit bent toys and instruments more musical, this build should serve as a great inspiration. We’ve featured other oddball musical hacks in a similarly creative vein before, too—such as using mixers as a synthesizer in their own right. Have fun out there.

youtube.com/embed/iuE5xW97DIw?…


hackaday.com/2026/08/03/circui…

Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: We spoke to hacking law experts to learn if OpenAI and Anthropic could be prosecuted for their AI agents’ hacks against Hugging Face, and three unnamed victims.

The answers are complicated, as we are in “uncharted territory,” as one lawyer put it.

But another lawyer said there is a potential avenue to hold the two AI giants liable for negligence. And for him, it would be a "no brainer" to sue the two companies.

techcrunch.com/2026/08/03/whos…

in reply to Lorenzo Franceschi-Bicchierai

I'm gonna have to agree with the "no brainer". Disabled brakes on a car plus nobody monitoring the road is the most simple duty-of-care failure. Call it common-law negligence plus trespass.

This isn't even Rylands v. Fletcher (liability is on those who bring a hazardous thing onto their land and let it escape, regardless of care taken). This is more like Jurassic Park. This is turning off the guardrails and provisioning egress, which is the behavior of risk creation, not even a risk containment failure. You cannot design a study around whether the Velociraptor can open doors, leave the doors open, and then argue the escape was novel, let alone unforeseeable.

In all my interviews with the press last week I said Grover Shoe Factory 1905 is the real world precedent. It's what I've been teaching my CS students about AI/ML/BigData ethics for a decade already.

Massachusetts passed boiler inspection law in 1907, ASME convened its code committee in 1911, the Boiler and Pressure Vessel Code arrived in 1914-15, and states adopted it as the condition of operation. Self-certified pressure vessels ended as a legal category, because of the Grover Shoe Factory disaster. Nobody after that asked the boiler manufacturer whether its boiler was safe; an independent inspector signed or the thing did not run.

This isn't actually hard. It's corporate malfeasance prevention. No agentic deployment runs without independent certification of its containment and monitoring, per system, renewable, with the certificate as the condition of operation. We know how to do it. We know why to do it. We just need someone with the authority.

Questa voce è stata modificata (5 giorni fa)