Status Display Keeps Eye on Your Prusa Fleet


The media in this post is not displayed to visitors. To view it, please log in.

Whether you’ve been dragging an old MK2 or MK3 kicking and screaming into the present through the available upgrade paths, or recently picked up a CORE One, pretty much any of the 3D printers still being actively supported by Prusa are able to connect to the network for the purposes of remote monitoring and control. Although their printers can work entirely offline, Prusa offers a smartphone application as well as web interface that makes it easy to keep tabs on all the hot plastic action.

If you’ve got a few Prusa printers on the net and would like a dedicated interface for controlling them, check out this custom firmware for the BigTreeTech K-Touch and Panda Touch devices. These touch screen gadgets were originally intended for controlling printers running Klipper, but thanks to [Nomads Galaxy], they can now talk to Prusa printers either directly over the local network or through the Prusa Connect cloud API with a user interface that mimics the aesthetics of the official offerings.

As an added bonus, the new firmware still retains the ability to talk to Klipper printers and cloud-connected units from Bambu Labs. Though for the latter it looks like the setup is a bit more convoluted, and there’s always a chance that these unofficial projects could break if Bambu decides to really start playing dirty.

The project is entirely open source, and ready to flash binary images are available to install via several methods. Incidentally the two supported displays are apparently using the ESP32 under hood, so they could be useful toys for all sorts of applications outside the 3D printing realm.

We took a look at one of the aftermarket 3D printer controllers from BigTreeTech back in 2022, but it would appear fair to say that the state of the art has advanced considerably since then.


hackaday.com/2026/06/23/status…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Scoperta botnet AryStinger: vecchi bug per router obsoleti soprattutto in Asia

📌 Link all'articolo : redhotcyber.com/post/scoperta-…

A cura di Luigi Zullo

#redhotcyber #news #cybersecurity #hacking #malware #botnet #proxy #attivitailegali

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Xsolis Data Breach Impacts 1.4 Million People
securityaffairs.com/194067/cyb…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Squidbleed: 29-Year-Old Squid Proxy Vulnerability Leaks Passwords and API Keys from Other Users
#CyberSecurity
securebulletin.com/squidbleed-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

AryStinger Botnet Hijacks 4,300+ Routers to Build Global Covert Attack Proxy Network
#CyberSecurity
securebulletin.com/arystinger-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

🐊💧Niente lacrime per il sionista Starmer
(di Alberto Negri)

"Ha cacciato Corbin da partito laburista accusandolo di essere anti-semita ma era solo filo-palestinese, ha continuato ad appoggiare i raid inglesi a Gaza per individuare i bersagli da colpire, ha bannato come terroristico il gruppo Palestine Action, è sempre stato dalla parte di Israele e cresciuto i suoi figli nella religione ebraica. Questo bell'esemplare di sionista ieri piagnucolava pure: lacrime di coccodrillo."

#Starmer #Zionism #AlbertoNegri

in reply to guerrilla stickers 地下通信

Starmer è un viscido servo degli interessi USA ed è sempre stato questa roba qui
⬇️⬇️ ⬇️ ⬇️ ⬇️
poliverso.org/display/0477a01e…


Keir Starmer si è dimesso. Siccome per lui proviamo solo ribrezzo, non ci mancherà

@Politica interna, europea e internazionale

Il ruolo di Keir Starmer come viscido servo degli Stati Uniti durante la persecuzione giudiziaria di Julian #Assange si è esplicitato bene durante il suo mandato come Direttore delle Pubbliche Accuse (DPP) in Inghilterra (2008-2013).

In quel periodo, il Crown Prosecution Service (CPS) gestì il primo tentativo di estradizione di Assange in Svezia, rappresentando le autorità svedesi nei procedimenti legali britannici.

Le controversie principali sul suo operato sono state raccontate benissimo dalla giornalista d'inchiesta @stefania maurizi ma possiamo riassumerle riguardo a tre episodi:

  • suggerimento ai pubblici ministeri svedesi di strategie che penalizzassero il diritto dell'imputato: i documenti ottenuti negli anni tramite le richieste di accesso agli atti hanno rivelato che gli avvocati del CPS (l'agenzia guidata da Starmer) sconsigliarono formalmente alle autorità svedesi di recarsi a Londra per interrogare Assange. Secondo i critici e i legali di Assange, se fosse stato interrogato nel Regno Unito, si sarebbe potuto evitare il lungo stallo presso l'ambasciata ecuadoriana.
  • frequenti visite a Washington: durante il periodo in cui il caso Assange era attivo, Starmer ha effettuato diversi viaggi a Washington, D.C., per incontrare funzionari del Dipartimento di Giustizia degli Stati Uniti.
  • ciliegina sulla torta: la vera e propria distruzione di prove: Il CPS ha ammesso di aver distrutto gran parte delle e-mail e della documentazione interna relative a quegli anni e al caso Assange, inclusi i registri delle trasferte di Starmer negli Stati Uniti. Questo ovviamente ha confermato i sospetti di giornalisti e attivisti riguardo a possibili pressioni politiche o irregolarità istituzionali.

E adesso brindiamo alle umilianti dimissioni che, come purtroppo sappiamo fin troppo bene, saranno una riga in più sul curriculum vitae per chi lo assumerà in un qualche ruolo strapagato a caso in una qualche Organizzazione Internazionale a caso (NATO, Corte di Giustizia di qualcosa, Organizzazione Mondiale di qualcos'altro, Federazione Internazionale di un qualche sport o Inviato Speciale delle Nazioni Unite per i paesi del Golfo Persico – oh no! Quell'incarico risulta già occupato! 😒)

ilpost.it/2026/06/22/dimission…


reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Prinz Eugen Ransomware Uses RemotePC RMM and PowerShell Stagers to Evade Detection
#CyberSecurity
securebulletin.com/prinz-eugen…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Klue Supply Chain Hack Exposes Salesforce Data at Nine Cybersecurity Companies
#CyberSecurity
securebulletin.com/klue-supply…
Cybersecurity & cyberwarfare ha ricondiviso questo.

#ShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates
securityaffairs.com/194059/hac…
#securityaffairs #hacking

Long-Theorized GPS Weakness Exploited on Large Scale


The media in this post is not displayed to visitors. To view it, please log in.

GPS has become fairly common in our everyday lives, not only able to pinpoint our locations on Earth but also as an incredibly accurate timekeeping method. But since these satellites are around 20,000 km above Earth, the received signals on the surface of the planet can be incredibly weak. This makes them prone to jamming and spoofing, a weakness of the technology that has long been known. Although attempts to mitigate these problems have been ongoing, there has recently been a large-scale attempt to interfere with these signals that put all mitigation efforts to the test.

One proposed way to improve resilience is to supplement existing GNSS systems with low-Earth-orbit navigation satellites. In this example, a company called Xona is using a satellite called Pulsar-0 that operates in low-Earth orbit (LEO) and provides positioning and timing signals that are around 100 times stronger than standard signals from GPS/GNSS satellites. It is able to receive GPS signals as well, ensuring the two systems agree on one another. And, because Pulsar’s navigation signals originate from LEO and are much stronger than conventional GNSS signals, Xona expects them to be significantly more resistant to jamming.

Beyond geopolitics, spoofing GPS has some applications in finding legendaries in Pokemon Go as well as making it fairly trivial to steal GPS-guided drones.


hackaday.com/2026/06/23/long-t…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

La guerra digitale: come l’Italia si sta preparando a fronteggiare le minacce nel cyberspace

📌 Link all'articolo : redhotcyber.com/post/la-guerra…

A cura di Paolo Galdieri

#redhotcyber #news #cyberspazio #guerrainformatica #difesacibernetica #ministerodelladifesa

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Squidbleed: 29-Year-Old #Squid Bug Leaks User Credentials
securityaffairs.com/194041/hac…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

Fatta la direttiva, trovato l’inganno

@politica - Come evitare di far verificare davvero la trasparenza retributiva

wp.me/phh2yV-9Lq

in reply to informapirata ⁂

@informapirata io non mi stupisco... però dovrei leggere cosa è stato detto alle audizioni. Al webinar cui ho partecipato è stato detto che avevano segnalato la cosa, ma il ddl non è stato modificato.

@politica

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

349 – La Cina ha cancellato 12.000 lauree camisanicalzolari.it/349-la-ci…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Finalmente è arrivato dopo tanta attesa! 🌟📖 Il manuale definitivo che ogni CISO e IT Manager stavano aspettando! 🌟

#redhotcyber cloudsovrano #mythos #anthropic #meme #comics #nis2 #cybersecurity

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

RHC Conference 2026 - Il Futuro è Presente: l'Impatto degli AI Agents sull'Architettura dei SOC Moderni

📍Guarda il video: youtube.com/watch?v=gdUykrLgUQ…
📍Guarda la galleria: redhotcyber.com/red-hot-cyber-…

All'interno della RHC Conference 2026 è intervenuto con lo speech "Il Futuro è Presente: l'Impatto degli AI Agents sull'Architettura dei SOC Moderni" Alessandro Ghezzi (Senior Sales Engineer – CrowdStrike) durante la giornata dedicata alla cybersecurity, all’innovazione e alle nuove sfide del mondo digitale.

#redhotcyber #rhcconference #conferenza #informationsecurity #ethicalhacking #dataprotection #hacking #cybersecurity #cybercrime #cybersecurityawareness #cybersecuritytraining #cybersecuritynews #privacy #infosecurity

Rickrolling the World Cup


The media in this post is not displayed to visitors. To view it, please log in.

A VLC media window with a live feed of a soccer field. Players are just starting to come off the sideline to play.

Sometimes, hacking requires a certain amount of restraint, especially when you find a system woefully unsecured. It would be so easy to play some pranks, but [bobdahacker] chose not to rickroll the entire FIFA World Cup.

The fun starts after [bobdahacker] signed up for a free FIFA agent profile. After a simple ID verification process, he had a login for the FIFA Agent platform, but they used the same account system across the whole organization in Microsoft Entra. When he tried to access the FIFA Football Data Platform system, it returned an error saying he had no assigned role to allow access. This was on the client side though, so he was able to bypass the error as the server didn’t block accounts without assigned roles.

Once inside, he found he was able to access not just the data, but had full control of the RTMP ingest URLs of all the FIFA matches. For those of us less conversant in streaming media protocols, “Those RTMP ingest URLs are the literal pipe from the stadium cameras to FIFA’s broadcast distribution chain. Camera -> RTMP ingest -> MediaKind -> broadcast partners -> your TV.” He could’ve shut off the feeds or injected whatever alternate stream he wanted, but instead chose to try contacting FIFA, their streaming contractor, and various law enforcement agencies since the World Cup was already underway when he made the discovery.

“Competitions, Matches, Teams, Tools, Exchange Platform, Analysis Dashboard, Commentator Information System, FIFA AI Pro, Admin” were also in the open. Live match scores could be changed, player bios, and any number of other stats could be modified. We’ll let you imagine the possibilities of what mischief could occur.

While rickrolling the world would be funny, a rickroll throwie will be a bit more circumspect. If you’re more interested in soccer/football than security hacks, we hope you enjoy this LEGO soccer tank or these robot soccer players and avoid any soccer ball-sized meteorites or legal troubles for your soccer-related invention.


hackaday.com/2026/06/22/rickro…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Venti Agentici: la Cina elimina 12.000 programmi di laurea e rinnova la scuola

📌 Link all'articolo : redhotcyber.com/post/venti-age…

A cura di Massimiliano Brolli

#redhotcyber #news #riformauniversitaria #istruzione #cina #nuoviprogrammidiLaurea #economia

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

9,8 su 10! Gli Hacker criminali stanno sfruttando un bug critico su Splunk Enterprise

📌 Link all'articolo : redhotcyber.com/post/98-su-10-…

A cura di Luigi Zullo

#redhotcyber #news #cybersecurity #hacking #vulnerabilita #splunk #cve202620253

Dynamic RAM from First Principles


The media in this post is not displayed to visitors. To view it, please log in.

Before the past year, many of us took computer memory for granted. It was one of the lower-cost parts of a PC build and was usually available in whatever quantity one desired. As its cost has skyrocketed, a lot of PC builders and other users of computers in general are taking a deeper look at memory, how much is really needed, and what its functions truly are. [Igor] is working on a drum sequencer project which needs a small amount of memory, and has built this dynamic RAM from discrete components.

The first video goes into the construction of the memory array and how its addressed. It’s only eight bytes total, and using fairly large electrolytic capacitors to store data means that a gigabyte of this memory would take up well over a thousand acres, but it’s still enough memory for [Igor]’s needs. In addition to the capacitor, each bit uses a pair of diodes to determine if a read or write is occuring, and a set of transistors on the read and write busses to perform those actions. Worth noting here is that dynamic RAM like this needs to be refreshed because the capacitors lose charge over time, but these large capacitors can hold charge sometimes overnight, as [Igor] has confirmed experimentally.

There’s a followup video to the construction of these modules as well, where [Igor] demonstrates a number of ways this module can be used, from controlling LED arrays, 7-segment displays, and then installs it into his drum machine. With 64 bits available it’s capable of creating up to eight beats with eight samples available per beat. Although there are complete machines available for all of this, we appreciate his goal of not buying any pre-manufactured hardware and instead constructing it all from the ground up. There are analog drum machine options available in this same style as well.

youtube.com/embed/lYUuGf6b0IQ?…

youtube.com/embed/O6Coh5Ey3AU?…


hackaday.com/2026/06/22/dynami…

LightComposer – Reach Out and Touch Your Lighting


The media in this post is not displayed to visitors. To view it, please log in.

Lightcomposer

While there is a time and place for wirelessly controlled devices, sometimes you want something you can just reach out and touch to interact with, no apps to install or devices to configure. In this case [John] wanted a lamp that was just that. Drawing inspiration from the rotary phone, he created the LightComposer.

This small lamp, just a bit smaller than a hockey puck, uses a 3D printed enclosure and a straightforward PCB. It’s a very accessible project to recreate. The 3D prints are well thought out including a TPU ring on the bottom to keep the lamp from sliding around. The light source comes from 32 SK6812 LEDs, which are very similar to NeoPixels. An ATmega328P microcontroller powers the project and can easily be programmed using the Arduino IDE. A rotary encoder in the center, coupled to the top diffuser, lets you control LED brightness and color by turning it. The firmware also includes some fun hidden light-effect modes.

Head over to [John]’s site for all the files needed to make your own LightComposer, or links to buy a premade one. What devices have you made that use a straightforward physical user interface in lieu of an app? Be sure to check some of the other lamp builds we’ve featured before.


hackaday.com/2026/06/22/lightc…

Cybersecurity & cyberwarfare ha ricondiviso questo.

There we go. US Government tightens post-quantum cryptography transition deadlines for high-value systems to 2030 for key exchange and 2031 for signatures.

Also, speeding up the CMVP (FIPS 140 validation) processes. That’s how you know the rush is real.

The quantum computers are (potentially) coming.

whitehouse.gov/presidential-ac…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

#WhatsApp #Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools
securityaffairs.com/194031/mal…
#securityaffairs #hacking

Investigating Annealing as Fix for Poor CF Adhesion in 3D Prints


The media in this post is not displayed to visitors. To view it, please log in.

After recently publishing a few videos covering research into the poor adhesion between chopped carbon fiber (CCF) and the thermoplastic filaments as used with FDM 3D printing, some of the feedback received by [I built a thing] included the idea that the missing step to make CCF additives work was post-print annealing. Naturally this claim had to be investigated, both through the resulting physical characteristics as well as on a microscopic level in the same scanning electron microscope (SEM) as before.
Post-annealing SEM scan, showing clear voids. (Credit: I built a thing, Youtube)Post-annealing SEM scan, showing clear voids. (Credit: I built a thing, Youtube)
Theories as to why annealing the parts would help here seem to focus on increased bonding and filling of voids in the printed CCF-infused material, while there are the typical worries with annealing such as parts warping and shrinking to also take into account as potential downsides of this treatment.

For the sample materials PETG and PETG-CF, as well as PLA and PLA-CF filaments are used, with each filament type featuring an annealed and not annealed version. These were then tested for tensile strength, stiffness and failure type, as well as dimensional accuracy and warping, before being examined under the SEM. A total of 160 samples were used, with 20 samples per material and annealing state.

Perhaps the biggest surprise here was how much PETG benefits from annealing, making it much more resilient to breaking, whereas neither PLA nor PLA-CF seemed to see much benefit. Shocking was how much worse PETG-CF performs than PETG, with the former being worse than both PLA and PLA-CF here.

In terms of dimensional accuracy, annealing caused a Z direction expansion while shrinking the samples in the other directions. The CCF addition here actually prevented much of the shrinking and expansion, showing the first clear benefit of this additive. Yet despite annealing at right above the glass transition temperature as is proper, this would seem to be the limit of this approach in terms of practical benefits.

Compared to the previous research that focused on PLA-CF, PETG-CF would seem to make the case even more strongly that there’s no real purpose to CCF additives, especially since you can already account for parts shrinkage during annealing before printing. That there’s no improvement to the CCF and thermoplastic interface adhesion is also no mystery, considering the science behind how e.g. thermoset materials create bonds with CF.

youtube.com/embed/hT-YXG1b8qA?…


hackaday.com/2026/06/22/invest…

Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: A spyware and hacking tools maker has released details of an unpatchable flaw in Apple chips that could potentially allow hackers to make a jailbreak for older devices.

The flaw, dubbed usbliter8, can help someone with physical access to devices up to the iPhone 11 to unlock and break into them.

The bug affects Apple-made chips A12 and A13, released in 2018 and 2019.

techcrunch.com/2026/06/22/a-ne…

reshared this

Breaking Into a Prison Tablet


The media in this post is not displayed to visitors. To view it, please log in.

Usually the term ‘jailbreaking’ isn’t meant to be taken quite that literally, but in the case of the US prison tablet that [Hugh Jeffreys] got sent, it’s really quite apt. Unlike the typical transparent prison electronics, this tablet is hermetically sealed inside an opaque plastic case, with the Windows 10 install firmly locked-down and not allowing anything more to be done with it than access some prison-provided services via the browser in kiosk mode.

The first challenge was to see whether it could be booted at all, with just four metal pads visible on the side of the case. These turn out to correspond to USB pins, but the tablet only briefly tries to turn on with a charger connected. This means that a teardown is required, which ended up involving a hacksaw due to the sealed case.

Inside the case is the Windows tablet with the back cover removed, presumably for easy access to extend its USB port. All of this is embedded in foam and more gunk that makes disassembly rather messy. With the case opened it becomes clear that the likely reason why this tablet was junked was due to a bad third-party charger board, as using the tablet’s own USB port it charges happily and even turns on.

From there it’s a bit of a fight with the locked-down Windows installation, but as it’s just a Windows 10 Home installation, there’s no drive encryption or such to get in the way. This allows for the device to be fully jailbroken, revealing its specifications as an Iview Optimus-C-8001, powered by an Intel Atom Z8350 at 1.44 GHz with a blistering 2 GB of RAM. The Windows installation was from 2018, with apparently no updates since.

Despite the very high school arts-and-crafts appearance of the case itself, the tablet itself isn’t too shabby considering the limited hardware specifications. Although getting the case off is a bit of a pain, it’s not a bad catch if you can find one of these puppies in the e-waste bin.

youtube.com/embed/at8KPvN4UV8?…


hackaday.com/2026/06/22/breaki…

The media in this post is not displayed to visitors. To view it, please log in.

AryStinger: la botnet che trasforma router D-Link in armi silenziose per attacchi globali


@Informatica (Italy e non Italy)
AryStinger è una nuova botnet scoperta da XLab che ha compromesso oltre 4.000 router D-Link obsoleti trasformandoli in proxy per attacchi di ricognizione e intrusione globali. Sfrutta vulnerabilità vecchie di anni e comunica via


AryStinger: la botnet che trasforma router D-Link in armi silenziose per attacchi globali


I ricercatori di XLab (Qianxin) hanno scoperto AryStinger, una botnet precedentemente sconosciuta che ha compromesso oltre 4.000 router obsoleti in tutto il mondo, trasformandoli in proxy silenziosi al servizio di attori malevoli. A differenza delle classiche botnet DDoS, AryStinger è progettata per il ricognizione e il supporto alle intrusioni — un’infrastruttura invisibile concepita per penetrare reti aziendali e governative.

Scoperta e timeline dell’operazione


Il 12 marzo 2026, il sistema di threat awareness di XLab ha rilevato l’indirizzo IP 107.150.106.14 che diffondeva un campione ELF con zero detection su VirusTotal, sfruttando due vulnerabilità datate: CVE-2013-3307 e CVE-2016-5681. Il campione, implementato in C, prendeva di mira router D-Link DIR-850L e DIR-818LW — dispositivi giunti a fine vita, privi di patch e ancora ampiamente diffusi in ambito SOHO.

Il 26 aprile è comparso un secondo campione correlato, questa volta scritto in Go e rivolto a dispositivi NAS, sfruttando CVE-2025-11837. Il percorso nel codice sorgente del campione Go rivela il nome del progetto interno: Ary-Attack — un dettaglio che ha consentito ai ricercatori di attribuire le due famiglie alla stessa operazione.

Architettura e capacità operative


AryStinger converte i dispositivi infetti in “executor” telecomandati, capaci di eseguire un insieme ricco di operazioni su richiesta del C2:

  • Scansione di rete: port scanning, identificazione dei servizi, enumerazione di sottodomini — attività tipiche della fase di ricognizione pre-intrusione.
  • Proxying e tunneling: il device infetto instrada traffico malevolo verso destinazioni terze, mascherando l’origine reale dell’attaccante.
  • Esecuzione di comandi arbitrari sul sistema.
  • Modifiche DNS: la botnet può alterare le configurazioni DNS del router per intercettare il traffico web degli utenti connessi.
  • Payload multi-linguaggio: supporta l’iniezione di payload scritti in Go, Java e Python, garantendo flessibilità operativa.
  • Canali di accesso persistente via dropbear (SSH) o gs-netcat.

Le comunicazioni con il server di comando e controllo avvengono via HTTP/HTTPS, con traffico serializzato tramite Protobuf e cifrato con XOR — una scelta che garantisce compattezza e una certa difficoltà nell’ispezione del traffico.

Distribuzione geografica e target


La telemetria di Qianxin mostra che la distribuzione delle infezioni è geograficamente concentrata: Corea del Sud (48,5%), Cina (31,8%), Svezia (6,4%), Malesia (3,5%) e Singapore (2,5%). La forte prevalenza asiatica suggerisce che il deployment iniziale sia stato mirato su mercati dove i router D-Link di fascia bassa hanno avuto larga diffusione e dove la sostituzione dei dispositivi a fine vita avviene con ritardi.

Il targeting di NAS oltre ai router nella seconda fase dell’operazione indica un’evoluzione verso dispositivi con maggiore capacità di elaborazione e connettività persistente — ideali per operazioni di lunga durata che richiedono stabilità dell’infrastruttura proxy.

Perché AryStinger è diversa dalle botnet tradizionali


La distinzione fondamentale di AryStinger rispetto a botnet come Mirai o AISURU è l’obiettivo operativo: non DDoS né mining di criptovalute, bensì la costruzione di un’infrastruttura di intrusione distribuita. I dispositivi compromessi diventano nodi di una rete di proxy residenziali che conferiscono agli attaccanti un’anonimizzazione difficile da penetrare: il traffico malevolo emerge da indirizzi IP domestici o di piccola impresa, superando spesso i blocchi basati su reputazione IP.

Questo modello operativo è tipico di gruppi APT che necessitano di infrastrutture di staging durante la fase di ricognizione e di pivoting nelle reti bersaglio. La capacità di modificare le configurazioni DNS aggiunge una dimensione ulteriore: chi usa un router infetto espone tutte le proprie comunicazioni a potenziale intercettazione.

Indicatori di compromissione (IoC)

# IP di spreading iniziale
107.150.106.14
# Dominio C2 autenticazione
eixfi.ajb8.com  (/auth endpoint)
# CVE sfruttate
CVE-2013-3307   (D-Link DIR-850L - autenticazione bypassata)
CVE-2016-5681   (D-Link DIR-818LW - esecuzione remota di codice)
CVE-2025-11837  (dispositivi NAS - variante Go)
# Processi sospetti da verificare sul dispositivo
syswapd0h
syswapd0w
# Percorso da verificare
/tmp/bin/  (presenza di campioni malware)
# Nome progetto interno (da path nel codice Go)
Ary-Attack

Due righe per i difensori


Per chi gestisce reti con dispositivi edge, le azioni prioritarie sono: sostituire immediatamente i router D-Link DIR-850L e DIR-818LW con modelli supportati e aggiornati; applicare gli aggiornamenti firmware più recenti su tutti i dispositivi di rete perimetrali; modificare le credenziali amministrative di default; disabilitare le interfacce di gestione remota se non strettamente necessarie. A livello di monitoraggio, è opportuno inserire il dominio eixfi.ajb8.com e l’IP 107.150.106.14 nelle blocklist e verificare nei log di rete la presenza di connessioni Protobuf verso host sconosciuti su porte non standard.

La scoperta di AryStinger conferma una tendenza consolidata: i dispositivi IoT e i router SOHO a fine vita restano un vettore di attacco privilegiato per costruire infrastrutture di intrusione persistenti e difficili da attribuire. La prossima botnet potrebbe già essere nascosta nel router del vostro operatore ISP locale.


Cybersecurity & cyberwarfare ha ricondiviso questo.

Texas Parks & Wildlife (#TPWD) Data Breach impacts 3 Million People
securityaffairs.com/194023/dat…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ AryStinger: la botnet che trasforma router D-Link in armi silenziose per attacchi globali
#CyberSecurity
insicurezzadigitale.com/arysti…

@informatica


AryStinger: la botnet che trasforma router D-Link in armi silenziose per attacchi globali


I ricercatori di XLab (Qianxin) hanno scoperto AryStinger, una botnet precedentemente sconosciuta che ha compromesso oltre 4.000 router obsoleti in tutto il mondo, trasformandoli in proxy silenziosi al servizio di attori malevoli. A differenza delle classiche botnet DDoS, AryStinger è progettata per il ricognizione e il supporto alle intrusioni — un’infrastruttura invisibile concepita per penetrare reti aziendali e governative.

Scoperta e timeline dell’operazione


Il 12 marzo 2026, il sistema di threat awareness di XLab ha rilevato l’indirizzo IP 107.150.106.14 che diffondeva un campione ELF con zero detection su VirusTotal, sfruttando due vulnerabilità datate: CVE-2013-3307 e CVE-2016-5681. Il campione, implementato in C, prendeva di mira router D-Link DIR-850L e DIR-818LW — dispositivi giunti a fine vita, privi di patch e ancora ampiamente diffusi in ambito SOHO.

Il 26 aprile è comparso un secondo campione correlato, questa volta scritto in Go e rivolto a dispositivi NAS, sfruttando CVE-2025-11837. Il percorso nel codice sorgente del campione Go rivela il nome del progetto interno: Ary-Attack — un dettaglio che ha consentito ai ricercatori di attribuire le due famiglie alla stessa operazione.

Architettura e capacità operative


AryStinger converte i dispositivi infetti in “executor” telecomandati, capaci di eseguire un insieme ricco di operazioni su richiesta del C2:

  • Scansione di rete: port scanning, identificazione dei servizi, enumerazione di sottodomini — attività tipiche della fase di ricognizione pre-intrusione.
  • Proxying e tunneling: il device infetto instrada traffico malevolo verso destinazioni terze, mascherando l’origine reale dell’attaccante.
  • Esecuzione di comandi arbitrari sul sistema.
  • Modifiche DNS: la botnet può alterare le configurazioni DNS del router per intercettare il traffico web degli utenti connessi.
  • Payload multi-linguaggio: supporta l’iniezione di payload scritti in Go, Java e Python, garantendo flessibilità operativa.
  • Canali di accesso persistente via dropbear (SSH) o gs-netcat.

Le comunicazioni con il server di comando e controllo avvengono via HTTP/HTTPS, con traffico serializzato tramite Protobuf e cifrato con XOR — una scelta che garantisce compattezza e una certa difficoltà nell’ispezione del traffico.

Distribuzione geografica e target


La telemetria di Qianxin mostra che la distribuzione delle infezioni è geograficamente concentrata: Corea del Sud (48,5%), Cina (31,8%), Svezia (6,4%), Malesia (3,5%) e Singapore (2,5%). La forte prevalenza asiatica suggerisce che il deployment iniziale sia stato mirato su mercati dove i router D-Link di fascia bassa hanno avuto larga diffusione e dove la sostituzione dei dispositivi a fine vita avviene con ritardi.

Il targeting di NAS oltre ai router nella seconda fase dell’operazione indica un’evoluzione verso dispositivi con maggiore capacità di elaborazione e connettività persistente — ideali per operazioni di lunga durata che richiedono stabilità dell’infrastruttura proxy.

Perché AryStinger è diversa dalle botnet tradizionali


La distinzione fondamentale di AryStinger rispetto a botnet come Mirai o AISURU è l’obiettivo operativo: non DDoS né mining di criptovalute, bensì la costruzione di un’infrastruttura di intrusione distribuita. I dispositivi compromessi diventano nodi di una rete di proxy residenziali che conferiscono agli attaccanti un’anonimizzazione difficile da penetrare: il traffico malevolo emerge da indirizzi IP domestici o di piccola impresa, superando spesso i blocchi basati su reputazione IP.

Questo modello operativo è tipico di gruppi APT che necessitano di infrastrutture di staging durante la fase di ricognizione e di pivoting nelle reti bersaglio. La capacità di modificare le configurazioni DNS aggiunge una dimensione ulteriore: chi usa un router infetto espone tutte le proprie comunicazioni a potenziale intercettazione.

Indicatori di compromissione (IoC)

# IP di spreading iniziale
107.150.106.14
# Dominio C2 autenticazione
eixfi.ajb8.com  (/auth endpoint)
# CVE sfruttate
CVE-2013-3307   (D-Link DIR-850L - autenticazione bypassata)
CVE-2016-5681   (D-Link DIR-818LW - esecuzione remota di codice)
CVE-2025-11837  (dispositivi NAS - variante Go)
# Processi sospetti da verificare sul dispositivo
syswapd0h
syswapd0w
# Percorso da verificare
/tmp/bin/  (presenza di campioni malware)
# Nome progetto interno (da path nel codice Go)
Ary-Attack

Due righe per i difensori


Per chi gestisce reti con dispositivi edge, le azioni prioritarie sono: sostituire immediatamente i router D-Link DIR-850L e DIR-818LW con modelli supportati e aggiornati; applicare gli aggiornamenti firmware più recenti su tutti i dispositivi di rete perimetrali; modificare le credenziali amministrative di default; disabilitare le interfacce di gestione remota se non strettamente necessarie. A livello di monitoraggio, è opportuno inserire il dominio eixfi.ajb8.com e l’IP 107.150.106.14 nelle blocklist e verificare nei log di rete la presenza di connessioni Protobuf verso host sconosciuti su porte non standard.

La scoperta di AryStinger conferma una tendenza consolidata: i dispositivi IoT e i router SOHO a fine vita restano un vettore di attacco privilegiato per costruire infrastrutture di intrusione persistenti e difficili da attribuire. La prossima botnet potrebbe già essere nascosta nel router del vostro operatore ISP locale.


Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Cina espande la lista dei ban contro 10 aziende USA: Lockheed Martin è tra queste

📌 Link all'articolo : redhotcyber.com/post/cina-espa…

A cura di Carolina Vivianti

#redhotcyber #news #relazionibilaterali #cinaeusa #tensioneeconomica #commerciointazionale

Cybersecurity & cyberwarfare ha ricondiviso questo.

Troubleshooting su Linux: il metodo sistematico in 4 passi che risolve il 99% degli errori
#tech
spcnet.it/troubleshooting-su-l…
@informatica


Troubleshooting su Linux: il metodo sistematico in 4 passi che risolve il 99% degli errori


Chi lavora con Linux da anni conosce bene quella sensazione: un errore inaspettato blocca il server, un servizio smette di rispondere, un sistema che ieri funzionava perfettamente oggi presenta comportamenti anomali. La differenza tra un amministratore di sistema esperto e uno alle prime armi non sta tanto nella conoscenza enciclopedica dei comandi, quanto nell’adozione di un metodo sistematico di analisi.

In questo articolo descriviamo un approccio in quattro passi che consente di affrontare con metodo qualsiasi errore su Linux, riducendo drasticamente i tempi di risoluzione e gli errori per tentativi.

Il principio fondamentale: metodo prima di tutto


Il troubleshooting efficace non è una questione di fortuna o di esperienza accumulata a caso. È una disciplina che richiede di rallentare, osservare e procedere un passo alla volta. La tentazione più comune è quella di applicare subito la prima soluzione trovata online, modificando più variabili contemporaneamente. Questo approccio porta quasi sempre a peggiorare la situazione o, nella migliore delle ipotesi, a non capire quale modifica ha effettivamente risolto il problema.

Passo 1: raccogliere indizi e definire il problema con precisione


Il punto di partenza è una definizione precisa del problema. “Il server non funziona” è inutile ai fini diagnostici. “Il web server restituisce un 503 su /api/users dopo il deploy delle 14:30″ è un punto di partenza solido.

Le domande da porsi immediatamente sono:

  • Quando si è manifestato il problema per la prima volta?
  • Cosa è cambiato recentemente? (aggiornamento pacchetti, modifica configurazione, riavvio)
  • Il problema è riproducibile? In quali condizioni?
  • Qual è esattamente il messaggio di errore?

Un consiglio pratico spesso sottovalutato: se un’applicazione non si avvia correttamente, chiudete l’interfaccia grafica e lanciatela da terminale. La maggior parte delle applicazioni stampa i messaggi di errore sullo standard output o standard error, fornendo clue preziosi che l’interfaccia nasconde.

Catturate sempre l’output esatto dell’errore. Un kernel panic al boot, un prompt GRUB rescue, o un messaggio “device not found” contengono già le informazioni necessarie per risolvere il problema.

Passo 2: analizzare lo stato del sistema e i log


Con il problema definito, è il momento di esaminare lo stato corrente del sistema. Questa fase si divide in due parti: lo stato delle risorse e l’analisi dei log.

Stato delle risorse


Verificate se CPU, memoria, disco e rete sono in condizioni normali:

# CPU e memoria
top
htop

# Spazio disco
df -h
du -sh /var/log/* | sort -rh | head -20

# Rete
ip a
ip route
ping -c 4 8.8.8.8


Analisi dei log


Linux mette a disposizione strumenti potenti per l’analisi dei log. Con systemd, il comando principale è journalctl:

# Log del boot corrente con dettagli errori
journalctl -xb

# Log di un servizio specifico (es. nginx)
journalctl -u nginx --since "1 hour ago"

# Seguire i log in tempo reale
journalctl -f

# Filtrare solo gli errori
journalctl -p err -b


Per i sistemi che usano ancora i log tradizionali:
# Syslog generale
grep -i error /var/log/syslog | tail -50

# Log kernel
dmesg | grep -i "error\|fail\|warn" | tail -30

# Ricerca per intervallo temporale
journalctl --since "2026-06-22 14:00" --until "2026-06-22 15:00"


Non è necessario comprendere ogni singola riga dei log. L’obiettivo è identificare parole chiave come error, failed, segfault, permission denied, o il nome del servizio problematico nelle righe temporalmente vicine all’evento.

Passo 3: formulare ipotesi e testare una variabile alla volta


Con i dati raccolti nei passi precedenti, è il momento dell’analisi. Basandosi sui sintomi, sui cambiamenti recenti e sui log, si formula un’ipotesi sulla causa del problema.

Alcune regole pratiche:

  • Un segmentation fault → sospettare corruzione della memoria o libreria incompatibile
  • “Permission denied” → verificare permessi file, SELinux/AppArmor, ACL
  • “Device not found” al boot → UUID del disco modificato dopo aggiornamento o sostituzione
  • Servizio che crasha dopo un aggiornamento → provare il rollback del pacchetto

La regola d’oro è modificare una variabile alla volta. Se sospettate che un aggiornamento del pacchetto abbia causato il problema, fate il downgrade su un sistema di test prima di applicarlo in produzione. Questo permette di isolare la causa con certezza.

# Rollback di un pacchetto su Debian/Ubuntu
apt-cache showpkg nginx
apt-get install nginx=1.24.0-2

# Su RHEL/Rocky Linux
dnf downgrade nginx

# Verificare i file di configurazione con sintassi check
nginx -t
systemd-analyze verify /etc/systemd/system/myservice.service


La ricerca online è un validissimo alleato: incollare il messaggio di errore esatto in un motore di ricerca, nella documentazione ufficiale della distro, o in un AI assistant porta quasi sempre a soluzioni già documentate.

Passo 4: applicare la correzione e documentare


Una volta identificata la causa, applicare la correzione in modo controllato. Per le modifiche più invasive (sostituzione hardware, rebuild dell’initramfs, cambio configurazione kernel), è fondamentale:

  • Eseguire uno snapshot del sistema prima di procedere
  • Procedere un passo alla volta
  • Verificare dopo ogni modifica che il problema sia risolto e che nulla si sia rotto

Il passo finale, spesso trascurato, è la documentazione. Annotare cosa è andato storto, quali log hanno fornito i clue decisivi, e come è stato risolto il problema. Un ticket nel sistema di ticketing, un post nel blog interno, o anche una semplice nota in un file di testo possono fare la differenza quando lo stesso problema si ripresenterà tra sei mesi.

Strumenti essenziali da padroneggiare


Per mettere in pratica questo metodo in modo efficace, vale la pena avere familiarità con questi strumenti:

# Monitoraggio risorse
htop, btop, atop, glances

# Analisi disco e I/O
iotop, iostat, lsblk, blkid, smartctl -a /dev/sda

# Rete
ss -tlnp, netstat -tlnp, tcpdump, traceroute, mtr

# File di sistema
strace -p , lsof -i, inotifywait

# Analisi log avanzata
grep, awk, sed, logwatch, fail2ban-client status

Conclusione


Il troubleshooting su Linux non è magia: è l’applicazione di un metodo. Raccogliere i dati, analizzare i log, formulare ipotesi e testarle una alla volta, applicare la correzione e documentare. Quattro passi che, se seguiti con disciplina, permettono di affrontare con sicurezza qualsiasi problema, dai più banali ai più complessi.

La vera competenza si costruisce nel tempo, attraverso l’accumulo di esperienze documentate. Ogni errore risolto correttamente è una voce nel vostro archivio personale di soluzioni.


Fonte originale: Linux Troubleshooting: These 4 Steps Will Fix 99% of Errors – LinuxBlog.io


Cybersecurity & cyberwarfare ha ricondiviso questo.

Soldi Tuoi - Il gioco da tavolo di sole carte che ti fa scoprire, giocando, come funzionano risparmio, investimenti e indipendenza finanziaria.

Nessuna lezione, nessun manuale: solo strategia, fortuna e qualche risata.

@giochidatavolo

giocosoldituoi.com/

#GiochiDaTavolo #SoldiTuoi #NicolaBorzi

Cybersecurity & cyberwarfare ha ricondiviso questo.

AryStinger: la botnet che trasforma router D-Link in armi silenziose per attacchi globali


AryStinger è una nuova botnet scoperta da XLab che ha compromesso oltre 4.000 router D-Link obsoleti trasformandoli in proxy per attacchi di ricognizione e intrusione globali. Sfrutta vulnerabilità vecchie di anni e comunica via Protobuf cifrato con XOR — un'infrastruttura invisibile per APT e cybercriminali.
The media in this post is not displayed to visitors. To view it, please go to the original post.

I ricercatori di XLab (Qianxin) hanno scoperto AryStinger, una botnet precedentemente sconosciuta che ha compromesso oltre 4.000 router obsoleti in tutto il mondo, trasformandoli in proxy silenziosi al servizio di attori malevoli. A differenza delle classiche botnet DDoS, AryStinger è progettata per il ricognizione e il supporto alle intrusioni — un’infrastruttura invisibile concepita per penetrare reti aziendali e governative.

Scoperta e timeline dell’operazione


Il 12 marzo 2026, il sistema di threat awareness di XLab ha rilevato l’indirizzo IP 107.150.106.14 che diffondeva un campione ELF con zero detection su VirusTotal, sfruttando due vulnerabilità datate: CVE-2013-3307 e CVE-2016-5681. Il campione, implementato in C, prendeva di mira router D-Link DIR-850L e DIR-818LW — dispositivi giunti a fine vita, privi di patch e ancora ampiamente diffusi in ambito SOHO.

Il 26 aprile è comparso un secondo campione correlato, questa volta scritto in Go e rivolto a dispositivi NAS, sfruttando CVE-2025-11837. Il percorso nel codice sorgente del campione Go rivela il nome del progetto interno: Ary-Attack — un dettaglio che ha consentito ai ricercatori di attribuire le due famiglie alla stessa operazione.

Architettura e capacità operative


AryStinger converte i dispositivi infetti in “executor” telecomandati, capaci di eseguire un insieme ricco di operazioni su richiesta del C2:

  • Scansione di rete: port scanning, identificazione dei servizi, enumerazione di sottodomini — attività tipiche della fase di ricognizione pre-intrusione.
  • Proxying e tunneling: il device infetto instrada traffico malevolo verso destinazioni terze, mascherando l’origine reale dell’attaccante.
  • Esecuzione di comandi arbitrari sul sistema.
  • Modifiche DNS: la botnet può alterare le configurazioni DNS del router per intercettare il traffico web degli utenti connessi.
  • Payload multi-linguaggio: supporta l’iniezione di payload scritti in Go, Java e Python, garantendo flessibilità operativa.
  • Canali di accesso persistente via dropbear (SSH) o gs-netcat.

Le comunicazioni con il server di comando e controllo avvengono via HTTP/HTTPS, con traffico serializzato tramite Protobuf e cifrato con XOR — una scelta che garantisce compattezza e una certa difficoltà nell’ispezione del traffico.

Distribuzione geografica e target


La telemetria di Qianxin mostra che la distribuzione delle infezioni è geograficamente concentrata: Corea del Sud (48,5%), Cina (31,8%), Svezia (6,4%), Malesia (3,5%) e Singapore (2,5%). La forte prevalenza asiatica suggerisce che il deployment iniziale sia stato mirato su mercati dove i router D-Link di fascia bassa hanno avuto larga diffusione e dove la sostituzione dei dispositivi a fine vita avviene con ritardi.

Il targeting di NAS oltre ai router nella seconda fase dell’operazione indica un’evoluzione verso dispositivi con maggiore capacità di elaborazione e connettività persistente — ideali per operazioni di lunga durata che richiedono stabilità dell’infrastruttura proxy.

Perché AryStinger è diversa dalle botnet tradizionali


La distinzione fondamentale di AryStinger rispetto a botnet come Mirai o AISURU è l’obiettivo operativo: non DDoS né mining di criptovalute, bensì la costruzione di un’infrastruttura di intrusione distribuita. I dispositivi compromessi diventano nodi di una rete di proxy residenziali che conferiscono agli attaccanti un’anonimizzazione difficile da penetrare: il traffico malevolo emerge da indirizzi IP domestici o di piccola impresa, superando spesso i blocchi basati su reputazione IP.

Questo modello operativo è tipico di gruppi APT che necessitano di infrastrutture di staging durante la fase di ricognizione e di pivoting nelle reti bersaglio. La capacità di modificare le configurazioni DNS aggiunge una dimensione ulteriore: chi usa un router infetto espone tutte le proprie comunicazioni a potenziale intercettazione.

Indicatori di compromissione (IoC)

# IP di spreading iniziale
107.150.106.14
# Dominio C2 autenticazione
eixfi.ajb8.com  (/auth endpoint)
# CVE sfruttate
CVE-2013-3307   (D-Link DIR-850L - autenticazione bypassata)
CVE-2016-5681   (D-Link DIR-818LW - esecuzione remota di codice)
CVE-2025-11837  (dispositivi NAS - variante Go)
# Processi sospetti da verificare sul dispositivo
syswapd0h
syswapd0w
# Percorso da verificare
/tmp/bin/  (presenza di campioni malware)
# Nome progetto interno (da path nel codice Go)
Ary-Attack

Due righe per i difensori


Per chi gestisce reti con dispositivi edge, le azioni prioritarie sono: sostituire immediatamente i router D-Link DIR-850L e DIR-818LW con modelli supportati e aggiornati; applicare gli aggiornamenti firmware più recenti su tutti i dispositivi di rete perimetrali; modificare le credenziali amministrative di default; disabilitare le interfacce di gestione remota se non strettamente necessarie. A livello di monitoraggio, è opportuno inserire il dominio eixfi.ajb8.com e l’IP 107.150.106.14 nelle blocklist e verificare nei log di rete la presenza di connessioni Protobuf verso host sconosciuti su porte non standard.

La scoperta di AryStinger conferma una tendenza consolidata: i dispositivi IoT e i router SOHO a fine vita restano un vettore di attacco privilegiato per costruire infrastrutture di intrusione persistenti e difficili da attribuire. La prossima botnet potrebbe già essere nascosta nel router del vostro operatore ISP locale.

reshared this

WhatsApp e crimeware: la convergenza tra malware, social engineering e strumenti leciti


@Informatica (Italy e non Italy)
File VBScript malevoli distribuiti via messaggi diretti, tramite account WhatsApp violati, abusano di software RMM legittimi per ottenere persistenza e controllo dei sistemi compromessi. Ecco come mitigare i rischi legati al social

Cybersecurity & cyberwarfare ha ricondiviso questo.

Ecco perché i marchi di tablet da disegno non collaboreranno sui driver FLOSS per Linux

"Devo scusarmi perché oggi ho parlato di nuovo con il nostro team tecnico e abbiamo deciso di non procedere con il progetto del driver Linux in questo momento"

davidrevoy.com/article1154/why…

@informatica

Graphics Upgrade for Nintendo Entertainment System


The media in this post is not displayed to visitors. To view it, please log in.

Modern video game consoles rarely have expansion ports, but in the 80s and 90s it was practically guaranteed. With the speed that hardware was advancing it made sense to build in some way to expand a system’s capabilities throughout its lifespan, like the memory port in the Nintendo 64 or the Sega CD and 32X attachments for the Sega Genesis. Some were ultimately unused as well, like the port under the Super Nintendo or, arguably, the interesting way that [decrazyo] figured out how to add graphics capabilities to the original Nintendo Entertainment System.

The basis of this upgrade is the fact that the Picture Processing Unit (PPU) on the NES has four pins that are grounded. These four pins tell the NES to display the background color if the pixel is transparent. Since they’re normally grounded, this means the NES can only display a limited background image, but there’s no reason these pins must be grounded. By using a second PPU configured to output graphics information and wiring it to these four pins on the first PPU, the NES can be given all kinds of new abilities, such as adding parallax effects to backgrounds, rendering more sprites, and showing more colors in the backgrounds.

Of course, the hardware requirements for this will require a donor NES to get the second PPU as well as the necessary memory chip for it, and we don’t recommend tearing apart perfectly good retro consoles for experimentation if it can be avoided. Presumably, you could use this open-source NES hardware alternative instead. But for those with the parts and the gumption, creating a demo or adding graphics features to homebrew games using this second graphics chip is within reach.

youtube.com/embed/V2kaV_m4iNU?…


hackaday.com/2026/06/22/graphi…

FortiBleed e una lezione dura da imparare


@Informatica (Italy e non Italy)
Il leak di oltre 73.000 credenziali relative ad apparati Fortinet esposti o malconfigurati, di cui oltre 1200 italiane, accende nuovamente i riflettori sullo stato del panorama cyber italiano.
Source

L'articolo proviene dal blog zerozone.it/cybersecurity/fort…

Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: I took a look at the history of using export controls to limit the proliferation of cyber capabilities.

From the Crypto Wars of the 1990s to limit the spread of PGP, to the Wassenaar Arrangement to stop spyware flowing out of Europe, and now powerful AI models, I argue that this approach mostly does not work.

techcrunch.com/2026/06/19/encr…

reshared this

MSYS2 and the No-Fuss Way to Get More GNU Into Your Windows


The media in this post is not displayed to visitors. To view it, please log in.

As great and streamlined as the Windows desktop experience is, one area where it’s at best disappointing and at worst rage-inducing is when it comes to its command line interface (CLI) offerings. In Windows 9x/ME this could be excused by the fact that it was essentially just a dressed-up MS-DOS CLI experience, but on Windows NT-based OSes no such excuse exists.

Yet even after Microsoft finally acknowledged the shortcomings of the cmd.exe shell by 2006, they then proceeded to go their own way with PowerShell, industry standards be damned. Especially for those of us who have no beef with the UNIX/BSD/Linux CLI experience and the joys of shell scripting, this insistence was disappointing. Simultaneously, everyone from OS X/MacOS to Haiku were happily offering a familiar CLI environment alongside POSIX compatibility.

Although Windows NT OSes were POSIX compliant, they never offered a suitable shell along with it, nor any of the other things you’d expect in a modern-day BSD, Haiku or Linux CLI environment. In a recent article by my esteemed colleague Al Williams, these sore points were somewhat addressed as far as basic CLI tools go, but the issue goes obviously much deeper than just the basic userland tools. Which is where MSYS2 comes into the picture.

Defining The Problem


When one says that they’d like a ‘Linux shell on Windows’, it can be hard to pin down exactly what this means. As Al noted in his article on CoreUtils last week, there are solutions like Cygwin that add a translation layer between Windows and Linux-ish code and offer a basic shell experience, but what if you really want to have a full Linux-like shell experience including support for common POSIX tools and libraries, as well as typical tooling like make and gcc?

Microsoft’s CoreUtils package gets you a GNU userland-like experience, but that’s arguably a small part of the whole issue. The reason why over the years I drifted away from Linux tools ported to Windows – as well as bailed on WSL, WSL2, Cygwin and full-fat VMs – is due the amount of friction these added when all that I wanted was to use a Bash-like shell for day-to-day tasks and general software development. For all intents and purposes I wanted to pretend that I was just on a modern Linux distro like Arch without having to fire up some special application with significant overhead or waddle over to one of my systems that have Linux installed.

This means a GNU-style userland, basic POSIX compatibility, being able to run shell scripts, having access to a package manager like on BSDs/Linuxes/Haiku/etc., ideally all in a way where it blends quite seamlessly into the overall Windows GUI experience. Essentially the laziest and most off-the-shelf experience possible, if you want.

This is where a full-fat VM is obviously too heavy and restricted, while WSL(2) also carries too many of the VM-related flaws with it, as it’s too much trying to be Linux instead of integrating with the Windows experience. The ideal solution here would probably feel more like the standard terminal on Haiku.

The MSYS2 Solution


With MSYS2 you can use the same pacman package manager you’d use on Arch/Manjaro to fetch packages. You’re also using a regular Bash shell and the only major hurdles you’re likely to run into concern limitations with low-level tools like Valgrind and some Windows-related quirks that the MSYS2 developers can’t do too much about because Microsoft. Internally it’s still based on Cygwin, so you can count on a similar level of compatibility, but without fuss.

For day-to-day use it’s a very familiar Linux-like experience for especially software-development purposes and common shell-based shenanigans like automation tasks and running a range of tools such as ffmpeg and yt-dlp, both of which are of course readily available from the package repository. In this sense MSYS2 adds a terminal and CLI environment that blurs the lines between BSD/Haiku/Linux and Windows, just the way us cross-platform developers like things, as this way you can use the same scripts and same know-how and muscle-memory across terminals and TTYs.

Perhaps the only negative here is again due to MSYS2 being not fully integrated into Windows, resulting in e.g. binaries compiled within an MSYS2 environment relying on shared libraries that are not on the Windows system path. This can be worked around by copying all the DLLs into the binary folder, or doing system path things, but it’s one of the reasons why I do distribute binary builds for Windows of my OSS projects that are compiled using NMake and MSVC.

The MSYS2 Environments


When you first install MSYS2, the most important thing to learn are the distinctions between the various MSYS2 environments. This is the first thing you see after happily installing MSYS2, finding yourself staring at a list of various terminal options, as summarized below. Over the years a number of these environments have been retired, in particular the 32-bit environments, but also the MinGW64 environment that used to be the primary one until Windows 10 added the Universal C Runtime (UCRT).

The MSYS2 environments page provides a lot more detail, but the brief summary is that you should just use the UCRT terminal. It builds upon the MSYS environment just like the other options, essentially setting up a number of defaults, with some of these listed in the above table. Although you can use the Clang environments, these aren’t nearly as mature or full-featured, so your mileage may vary there.

Development Features


My basic software development workflow involves Notepad++ to write code and a Makefile, and the use of an MSYS2 UCRT terminal to run make, along with gdb, grep and utilities such as ldd for happy-fun debugging purposes. When I do embedded development that targets e.g. STM32, I can fetch the entire GCC-based toolchain for ARM Cortex-M via pacman and use that in exactly the same way as I would in a Linux-based terminal or TTY.

I have always found doing such development things the ‘Windows way’ to be rather tedious and cumbersome, having spent considerable time in the past using environments like Visual Studio and other IDEs such as Code::Blocks. While any approach can be made to work, just being able to use the same shell scripts, same gdb configurations, and the same Makefiles. across FreeBSD, Linux, Haiku, and Windows saves a lot of time and effort as you never have to duplicate effort.

MSYS2 Limitations


As alluded to earlier, MSYS2 doesn’t integrate perfectly in Windows as it is still just a third-party application. It also only covers userland, so kernel-level drivers and tools like Valgrind will require a full-blown Linux system. However, unless I’m doing some crazy involved profiling or debugging I’ll generally just use Dr. Memory on Windows, which works the same as Valgrind and also has packages for Linux and MacOS.

Whether it’s a limitation or not I’m not entirely sure, but stdout in MSYS2 Bash also sometimes does seem to have trouble outputting where Bash or similar on BSD/Haiku/Linux does not, which is an issue that I still need to diagnose in more depth one day to file a ticket for. That said, having created issue tickets for the MSYS2 (packages) project in the past has at least made it clear that its developers are quite responsive and fairly tame.

These minor niggles aside, I’m quite grateful to the MSYS2 project for allowing me to have both the solid Windows GUI experience and also have my heavily Arch-inspired CLI cake with pacman icing.


hackaday.com/2026/06/22/msys2-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

A new edition of my weekly cyber newsletter, ~ this week in security ~, is out. Leading this week: Anthropic's AI ban wasn't ever really about a jailbreak, Ozempic maker gets hacked (twice), Apple kneecaps a privacy feature, a secret society's members were exposed, and find out how the UK's social media law, which pissed everyone off, was announced, denounced, and already potentially trounced.

Read online: this.weekinsecurity.com/this-w…

Sign up for the weekly newsletter: this.weekinsecurity.com


this week in security — june 21 2026 edition


~ ~

THIS WEEK, TL;DR


U.S. government's Anthropic ban wasn't really about an AI jailbreak
Axios ($), TechCrunch ($): Well that blew up… More than a week after the Trump administration used its export control powers to effectively ban Anthropic from offering its cybersecurity focused Mythos and Fable models, they're still largely offline. What initially erupted over cybersecurity fears after the White House took umbrage with an alleged Amazon-discovered jailbreak in Anthropic's latest AI models quickly turned out to be largely "personality clashes" between Trump and Anthropic, per Axios ($). The White House also seems to want a resolution to the jailbreak issue, which experts say isn't possible to fully remediate. Dozens of security researchers and experts have since called on the government to pull its export restrictions to allow Anthropic to offer its models again. So far, no dice. Anthropic has since dispatched a team to Washington, D.C. to negotiate with Trump officials, but we're not likely to see any change in positions here for the time being amid the impasse, and it's not known for how long this might drag on. Tech Policy Press said the quiet part out loud, that the "climate is one of a cloud of suspicion that senior officials are picking favorites based on personal and political factors." Infosec legend Bruce Schneier also has thoughts.
More: Luta Security | TechCrunch ($) | Axios ($) | The New York Times ($) | Wired ($) | The New Stack

'FortiBleed' bug affects thousands of Fortinet firewalls, hackers reportedly cracked admin passwords
DoublePulsar: Security researcher Kevin Beaumont is filling in the knowledge gaps because Fortinet's response to its customers getting hacked has been (predictably) crap. Meet FortiBleed, a new mass-hacking campaign targeting Fortinet firewalls belonging to big corporations around the world. There are at least 1,000 known compromised organizations so far out of a suspected 75,000 total internet-facing firewalls. A hacking crew appears to have scanned the internet for these firewalls, somehow logged in (it's unclear exactly how), exported the firewall configs, and then later unscrambled the hashed admin passwords offline. This allows the hackers to breach the firewalls and break into the victim's networks. CloudSEK also has a really good report on this campaign as well. Beaumont has IOCs, and the excellent folks at GAYINT have a list of affected Fortinet devices, so check if your organization is a victim. CISA also has a hardening guide for Fortinet customers. Expect more from this ongoing (albeit rumbled) campaign.
More: The Register | Ars Technica | @IFIN | @GossiTheDog | @ransomwaresommelier | @shadowserver
a sample of data shown in a screenshot containing sensitive domain, Fortinet firewall and password information relating to customers around the world. Fortinet firewalls only produce this kind of sensitive data when they're in extreme distress.
Ozempic maker Novo Nordisk hit twice by separate hacking campaigns
DataBreaches.net: Journalist Dissent Doe reports not one, but two hacking campaigns have hit Danish pharmaceutical giant and Ozempic maker Novo Nordisk of late. One gang stole a ton of pseudonymized health data of clinical trial patients, but it's not clear if the data will ever stay fully private if the key used to scramble the data is ever leaked. An entirely separate group, about two weeks later, stole gigabytes of AI-related data, source code, credentials, and more. The groups demanded respectively $50M and $25M, but neither got paid. Novo's negotiator allegedly strung the hackers along to give the firm time to prepare for a public disclosure. (I bet the negotiator got paid pretty well, though.) Dissent Doe has a great run through in both stories about the state of Novo's security, in some cases as told by the hackers themselves, who were critical of the company's posture. Meanwhile: Cardiac equipment firm iRhythm said this week that it was hacked, with patient data stolen. The company didn't say how many people are affected.
More: DataBreaches.net | Reuters ($) | HelpNetSecurity | MedTech Dive | The Register

U.K. social media law announced, denounced, and potentially trounced amid possible change in U.K. government
The Guardian: Governments generally only roll out disastrous policies when they're in extreme distress or when their politicians are on a hideous losing streak. The U.K. is there, and is attempting to roll out a social media ban for kids under 16, following Australia's semi-unsuccessful effort to roll out its own law late last year. Even the kids are like, "this makes no sense." (But of course they'd say that; many of them are evidently smarter than our politicians these days.) This may also include bans on VPNs, per the U.K. tech minister. It's a staggeringly bad idea, but the BBC News ($) tries to make sense of it all. As you can imagine, much of it will rely on scanning your driver's license or passport for access. And yet none of this might matter if newly minted MP Andy Burnham becomes U.K. prime minister after an anticipated upcoming leadership battle among the ruling Labour Party. This is because the U.K. is a parliamentary system that allows leaders to change with relative ease (unlike other places 😑), which is why the U.K. is about to have its fifth prime minister in four years. Make that make sense, kids. More thoughts by @tjheffernan and Signal's Meredith Whittaker via Bloomberg ($).
More: GOV.UK | Wired ($) | EFF | Politico EU | NPR | @hypervisible

~ ~

PLEASE SUPPORT THIS NEWSLETTER!

~this week in security~ is my weekly cybersecurity newsletter supported by readers like you. Please consider signing up for a paying subscription starting at $10/month for access to exclusive articles, analysis, and more.

Or, you can submit a one-time tip to show your support!

Subscribe to support this newsletter

~ ~

THE STUFF YOU MIGHT'VE MISSED


Spy agencies using bulk data to snoop on targets
Financial Times ($): Advertising intelligence, aka "Adint," is now one of the major sources of government surveillance, according to a survey of European spy agencies. Buying access to huge datasets containing people's browsing and location data is sometimes far easier for the spy agencies than tapping undersea cables and sifting through ungodly amounts of intercept traffic. Using ad-blockers is a good way to combat public data collection.

Some health providers are recording your mental health care visits
The Markup: A horror story from The Markup investigating how medical providers, like Kaiser, are recording patient interactions — including mental health sessions — using "ambient listening," which is code for "listen to everything and feed it into an AI model for processing." You can (and should be able to) opt-out of this recording but as noted, it's increasingly making patients feel uncomfortable and wanting to change doctors.

An elite secret society is exposed after a data leak spilled its members
Straight Arrow News: A Peter Thiel-founded secret society of elite members that allegedly exists for fostering off-the-record discussions *pinches bridge of nose and sighs relentlessly* can't even seem to keep its members' information secret, because its website exposed dozens of their email addresses and phone numbers. The list includes celebrities, politicians, journos, and more, per @crimew.gay. More via Wired ($).
maia arson crimew post on Bluesky: "Both datasets were obtained due to insufficiently secured systems that were openly leaking data, no security mechanisms were bypassed and no "advanced hacking" took place. I verify all source data sent to me and it's provenance before using it in research or passing it along to other journalists."
Apple is about to kneecap its Hide My Email privacy service
Arseniy Shestakov: For no good (or obvious) reason, Apple is about to make its email hiding feature, Hide My Email, less effective by moving users' masked email addresses from @icloud.com domains (which all customers use) to @private.icloud.com, making it far easier for websites and apps to block anonymous users from signing up. I asked Apple why it changed this but didn't get back to me. (*makes chicken clucking noises*)

How residential proxy networks power hacker and crime groups
Wall Street Journal ($): Want to know more about how hackers hide in your router (and also apps and cracked video games) and hijack that access as a funnel for cybercrims' bad activity? Here's your primer on residential proxy networks, the backdoor software that powers them, and why they're a risk to confidential information. Plus! Brian Krebs digs into one major residential proxy provider and the botnet it allegedly (heavy wink) runs, thanks to millions of hijacked Android TV boxes.

~ ~

OTHER NEWSY NUGGETS


Knicks data nicked: The ShinyHunters' hackers leaked some 45GB of data stolen relating to the Knicks and Madison Square Garden, where the team just played, including "risk" score data about high-profile attendees, per 404 Media ($). Meanwhile, Have I Been Pwned reports retail giant JCPenney and fashion outlet Ralph Lauren also didn't pay the hackers after they had data stolen by the same group, nor did Kodak nor Council of Europe pay. (via HigherEd Dive, GovTech)

Not so sweet sugar cyberattack: Queensland-based Mackay Sugar, Australia's second largest sugar producer, was hacked, forcing the shutdown of at least two mills. The hack prompted the company to ask farmers to keep crops in the ground for longer. It's unclear if that'll affect the collective harvest. A hacking group called The Gentlemen (narrator voice: they are not) took credit. (via ABC.net.au, The Register)

Joomla bug sparks alarm: A maximum severity 10/10 bug in Joomla's content management system, used by an estimated 1% of the web, has patched a bug actively under attack by hackers, per the software maker. The bug allows unauthenticated access and execution of PHP code, so that's… not great. Update today. (via Widget Factory, CISA, @IntCyberDigest)

Trump's Pulte takes spy agency reins: Another political mess is bubbling over in the U.S. capital as President Trump decided to dig in on Bill Pulte as his administration's part-U.S. spy chief, part-federal housing boss, and part-Trump's personal attack dog (but actually though). As such, Pulte took office as the acting U.S. director of national intelligence, much to the chagrin of both parties. Meanwhile, Trump said he won't pass the FISA renewal bill (even though it's nowhere near close to being resolved) because lawmakers won't pass his absolutely insane voter ID bill under the guise of Trump trying to steal another election. It's all very messy, but our neighborhood natsec cyberscribe @dustinvolz explains the s...hituation atThe New York Times ($). (via @atrupar.com)

Time is a flat circle, spyware edition: Human Rights Watch found Bulgaria-based surveillance vendor Circles sold its spyware to countries with atrocious records of human rights, like Bahrain and the UAE. Circles sells Pixcell (for tracking calls, messages, and data) and Landmark (tracks location). The EU just can't seem to stop its countries exporting spyware to the world. If only it actually tried to begin with! (via Bloomberg ($), The Record)

Canada gets legal anti-botnet kibosh order: Canadian spy agency CSIS was granted approval by a court to take down botnets… two years ago, following a request by the agency to "remove the compromised devices from Canada." The ruling was made public this week in a barebones filing, but as Risky.biz notes, it's probably China-related. The FBI used similar court orders in the past to take down botnets, too, but also remove the malware code from routers and servers. (via The Canadian Press, CityNews)

Klue app compromised: Klue, a market intelligence company that makes the Battlecards integration for Salesforce customers, was compromised (Klue noindex'd its blog post, hiding it from search engines). This breach allowed hackers to hijack those integrations and steal customer data. A new extortion gang called Icarus took credit for the hack.A bunch of customers are affected, including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. (via Dark Reading, Bleeping Computer, DataBreachToday)

~ ~

THE HAPPY CORNER


It's a corner, it's got happy stuff, it's the happy corner. And it's got all that we need to relax after a busy week of news.

To the kids facing a social media ban today, well… at least you didn't have to rely on using an Excel spreadsheet on a Nokia 9210 to send text messages to your boo. (I fear nobody under the age of 30 will get this reference and if that's the case, I'm gonna go find a nice quiet corner to just crumble into dust.)
Dr Chris Burden post on X: "Under 16s messaging each other on Excel post the social media ban," followed by a screenshot from a Nelly-Kelly Rowland music video from the 2000s featuring a still of a typed-out text message saying "WHERE YOU AT?" on an Excel spreadsheet on a Nokia 9210 phone.
I will admit, I got a little hooked on this secrets-finding game. Find the exposed tokens, credentials, and other exposed sensitive data in this data leak simulator.

Be careful out there, folks. Things are getting desperate among AI-fueled CEOs. Please, please use our sh*tty AI products, they beg. Will someone think of the executives?
James Hawkins post on Bluesky: "seriously be careful out there everyone i had 2 Microsoft Copilot licenses in my car, and someone broke in and left 4 more," followed by a photo of a smashed car window.
And lastly this week. Thank you so much to everyone who contributed to last week's shout-out to a special cause, Project Sunshine, a nonprofit that my partner Jordan and I are involved with that helps to raise funds so that kids with medical challenges can enjoy much-needed playtime. We were just blown away by the support and love from you. We raised our goal and then some! If you're reading this on the weekend, there's still a few more hours before the Play-A-Thon closes for this season, but if you can spare a few bucks to donate, it will make all the difference to the kids that you help to support. Thank you again, really; it means so much.

Got good news to share? Get in touch! this@weekinsecurity.com.

~ ~

CYBER CATS & FRIENDS


This week's cyber cat is Meech, who can be seen h… Zzzz…. Z..z zz… zzz… Zz… *shhh* sleeping softly with his head on a… keyboard?! …Zzz…. Z.. Zz…zz.. must be exhausted after a busy day hacking. Z.. zz…. z….. back to snoozing for you… *psssts quietly* Thanks so much to Mike B. for sending in…!
Meech is an orange kitty who can be seen asleep, with his head resting on the side of a computer keyboard.
🐈 Keep sending in your cyber cats! 🐈‍⬛ Got a cat or a non-feline friend? Send me an email with their photo and name and they will be featured in a later newsletter! I always appreciate an update if you've sent in before!

~ ~

SUGGESTION BOX


And that's all there is for this week. Thank you so much for reading, subscribing, and supporting this newsletter (and blog!). That was... a bit of a busy one. I hope this edition gave you everything you needed to catch up.

If you like this newsletter, please do share it on your socials and whatnot! I really appreciate getting new readers in and word-of-mouth is one of the best ways to do that.

And, if you have anything you want to share for the newsletter, including suggestions and feedback, please drop me a note any time.

As a short programming note from me, there will be no newsletter next week! I'll be away in New England for a few days with Jordan; she's always wanted to go up to Maine, so we're going to drive north and disconnect from the world. I'm back the week after for July 5, with the latest edition of ~this week in security~ to mark a special milestone.

Logging off for now... take care, and catch you soon.

Back in a fortnight,
@zackwhittaker

Reading this online? Get ~this week in security~ by email


a weekly cybersecurity newsletter by Zack Whittaker, plus analysis and blogs. All the news you need to know. No slop.

Subscribe
Email sent! Check your inbox to complete your signup.

No spam. Unsubscribe anytime. This newsletter does not use email open or link trackers.


reshared this