Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Heads up, Gizmodo has been compromised by some #ErrTraffic affiliate to. Inject is in main response.
ErrTraffic C2 cdnpro-987[.]xyz (Resoved via #EtherHiding)
PS Payload domain cdnportal-us[.]xyz (dynamic PowerShell command URI path)
PowerShell downloads a 16MB encrypted 7z file, checks if 7z is installed and otherwise downloads it to unpack the file and run the contained EXE. The EXE will do some profiling (including refresh rate) and if passes, will drop #NetSupportRAT and run it.
NetSupport C2 178[.]16[.]55[.]191.

TA also has a Mac payload configured, but it seems broken at the moment and ask for a password of some zip file when executed 🤷

Note: ErrTraffic is a ClickFIx-as-a-Service, so other compromised sites can lead to other malware from other affiliates.


Don't look now, but it seems Gizmodo's homepage is now serving up a Clickfix attack.

Basics of the Click-Fix exploit, which causes a pasted URL to fetch malware via Windows Powershell.

krebsonsecurity.com/2025/03/cl…

#clickfix #gizmodo


reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Whoa. @pypi monthly download counts increase 19.8% since March 2026 - **163.8 billion** total downloads in May 2026

Thanks to #ClickHouse for producing this newsletter: clickpy.clickhouse.com/report/…

reshared this

Rokarolla, il banking trojan Android che punta al controllo totale dello smartphone


@Informatica (Italy e non Italy)
Si chiama Rokarolla la nuova famiglia di malware Android che si distingue per le sue avanzate capacità di compromissione e controllo remoto dei dispositivi mobili: progettato per massimizzare la persistenza sul dispositivo compromesso,

Cybersecurity & cyberwarfare ha ricondiviso questo.

Un accenno di resoconto, molto personale, dell'evento a tema "Luna" che si è svolto sabato 20 giugno in osservatorio.

stardust.blog/2026/06/una-nott…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Anthropic's Mythos AI broke into almost all #NSA classified systems in hours
securityaffairs.com/194016/ai/…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

L’Agenzia delle Entrate al centro di una truffa “Adattiva”. Scopriamo cosa sta circolando in Italia

📌 Link all'articolo : redhotcyber.com/post/lagenzia-…

A cura di Chiara Nardini

#redhotcyber #news #cybersecurity #hacking #phishing #agenziadelleentrate #certagid

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

SiderAI and MaxAI Chrome Extensions Expose 10 Million Users to Full Browser Compromise
#CyberSecurity
securebulletin.com/siderai-and…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

HazyBeacon APT Campaign Weaponizes AWS Lambda to Hide Command-and-Control Traffic
#CyberSecurity
securebulletin.com/hazybeacon-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

GentleKiller: Inside the Ransomware Framework Disabling 400+ EDR Security Products
#CyberSecurity
securebulletin.com/gentlekille…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

AutoJack: A Single Malicious Web Page Can Hijack Your AI Agent and Execute Arbitrary Code
#CyberSecurity
securebulletin.com/autojack-a-…

A VBScript campaign distributed through WhatsApp deploying RMM software


The media in this post is not displayed to visitors. To view it, please log in.

In June 2026, we observed a malware campaign distributing malicious VBScript files through direct messages in WhatsApp. The campaign affected users across multiple countries and territories, including Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia and Vietnam, with the highest number of victims observed in Malaysia. At the time of writing this article, the campaign is still active.

Analysis shows that the campaign primarily targets users of WhatsApp Desktop and WhatsApp Web. The threat actor uses deceptive file names masquerading as business and financial documents to persuade recipients to download and execute the attachment. Once executed, the VBScript initiates a multi-stage infection chain that ultimately results in the installation of legitimate Remote Monitoring and Management (RMM) software, enabling remote access to the victim’s system.

Overview of the WhatsApp-based VBScript infection chain
Overview of the WhatsApp-based VBScript infection chain

We came across a number of social media posts reporting that the malware was being distributed by the users’ contacts. The messages contained only the malicious attachment and did not include any accompanying text. One account sent the same attachment to multiple contacts from their list.

WhatsApp messages containing the malicious VBScript file observed across multiple accounts. Source: alleged victims' posts on social media
WhatsApp messages containing the malicious VBScript file observed across multiple accounts. Source: alleged victims’ posts on social media

Based on evidence collected from multiple victims through social media reports and submitted samples, we can conclude that the threat actor had gained access to several WhatsApp accounts and used them to distribute the malicious VBScript files to contacts on the compromised users’ contact lists. At the time of writing, the exact method used to compromise these WhatsApp accounts remains unknown.

Social engineering through financial-themed file names


Analysis of the samples revealed that the threat actor relied heavily on social engineering through the use of deceptive file names designed to appear as legitimate business and financial documents. The file names frequently referenced invoices, account statements, debt notices, payment records, and bank statements.
Examples of file names include:

  • Financial Reports.vbs
  • Debt confirmation.vbs
  • Statement of Debt(30K).vbs
  • Outstanding Payment List.vbs
  • Account Statement.vbs
  • Debt Statement.vbs
  • Billing Statement (2).vbs
  • Promissory_Note(b).vbs

Several file names were also localized into different languages, including Portuguese, French, German, and Malay. Examples include:

  • Extrato de Conciliação.vbs
  • Aviso de dívida.vbs
  • Le formulaire de demande le plus récent.vbs
  • Bitte füllen Sie das Formular für Umsatzsteuer-Nullsatz-Verkäufe aus.vbs
  • Penyata bank.vbs
  • Sila semak bil anda.vbs

The use of multiple languages further suggests that the campaign may be targeting victims across different geographic regions.

In addition, the VBScript samples contain extensive comments and metadata intended to mimic legitimate Microsoft Windows Update components. Many of these comments are written in Chinese and include references to Windows Update modules, certificate validation, system integrity checks, and deployment-related functionality. The screenshot below shows an example of the Windows Update–themed comments and Chinese-language annotations embedded within one of the analyzed scripts.

Windows Update–themed and Chinese-language comments observed across multiple Stage 1 VBScript variants
Windows Update–themed and Chinese-language comments observed across multiple Stage 1 VBScript variants

Delivery of the initial VBScript file


Analysis of telemetry collected from the systems where the malware was executed, conducted together with the dynamic analysis of the sample, showed that the VBScript is launched through Windows Script Host (WScript.exe), which subsequently retrieves and executes additional VBScript components required for the later stages of the attack.

Two user interactions are needed to initiate the infection chain. When the user first clicks the attachment in either WhatsApp Desktop or WhatsApp web, it is downloaded to their machine. To launch the app, they need to open it.

In WhatsApp Desktop, the malware is executed directly within the application by clicking once more the file icon or by choosing the option “Open” in the chat. The process tree analysis shows that WScript.exe is spawned by WhatsApp.Root.exe. The executed script was observed within WhatsApp Desktop’s attachment storage directory, with the following command line:
"C:\Windows\System32\WScript.exe" "C:\Users\<username>\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\Sessions\<session_identifier>\Transfers\<YYYY-MM>\financial reports(s).vbs"
This process relationship confirms that the malicious VBScript was executed directly from the WhatsApp Desktop client.

In contrast, when the attachment is accessed through WhatsApp Web, to launch the malware, the user should open the downloaded file from the Downloads folder or through the browser’s download history. In the first case, the malware’s parent process will be explorer.exe, while in the second, it will be executed by the browser where the web app was opened.

Technical analysis

Stage 1: Initial VBScript execution


The first stage of the infection chain is a VBS or VBE file delivered through WhatsApp. Although multiple variants of the scripts were observed, their core functionality remains consistent: the script creates a working directory under C:\Users\Public\Documents\, downloads two additional VBScript payloads from a remote infrastructure, and executes them using Windows Script Host.

Across the observed variants, the working directory is created using randomized names such as Temp_<random> or MSUpdate_<random>. Some variants also configure the directory and downloaded files with hidden and system attributes, likely to reduce visibility to the user during execution.

Example of the code generating a random working directory and configuring it with hidden and system attributes
Example of the code generating a random working directory and configuring it with hidden and system attributes

The scripts employ several obfuscation techniques, including string concatenation, encoded VBScript, randomized variable names, and large amounts of junk content. One notable variant employs even heavier obfuscation than the other samples. The script reconstructs object names, file paths, utilities, and URLs through character-by-character string concatenation.

Example of an obfuscated Stage 1 VBScript variant.
Example of an obfuscated Stage 1 VBScript variant.

Several variants copy curl.exe and bitsadmin.exe into the working directory and rename them using DLL-like filenames before downloading additional VBS files.

Example of the Stage 1 downloader logic using renamed Windows utilities and multiple download mechanisms to retrieve additional VBS files
Example of the Stage 1 downloader logic using renamed Windows utilities and multiple download mechanisms to retrieve additional VBS files

The downloaded files are commonly staged using misleading file extensions before execution. For example, some variants download files using PDF or TXT extensions and then change them to VBS before launching them with wscript.exe. Other variants download the secondary VBScript payloads directly.

Despite differences in infrastructure, file names, and obfuscation methods, all observed variants ultimately perform the same function: downloading and executing two secondary VBScript payloads that continue the infection chain.

Stage 2: Execution of secondary VBScript payloads


Following execution, the Stage 1 VBScript downloads and launches two additional VBScript files from attacker-controlled infrastructure. One script attempts to modify Windows User Account Control (UAC) settings, while the other downloads and executes a ZIP archive containing the installation package for a RMM software.

VBS script 1: UAC configuration modification


First Stage 2 scripts were observed attempting to modify Windows UAC behavior.

Stage 2 VBScript repeatedly attempting to modify the ConsentPromptBehaviorAdmin registry value
Stage 2 VBScript repeatedly attempting to modify the ConsentPromptBehaviorAdmin registry value

As shown in the figure above, the script repeatedly executes an elevated registry modification command targeting the following registry key:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
The command is launched using the ShellExecute method with the runas verb, causing Windows to request administrative privileges before the registry change can be applied. Its goal is to set the ConsentPromptBehaviorAdmin registry key value to 0, thus enabling administrative actions without displaying a consent prompt to the user. The script attempts to apply this registry change in a loop with short delays between executions, likely to increase the chances that the setting will be successfully modified if administrative privileges are granted by the victim.

VBS script 2: ZIP download and script execution


The second VBS script downloads a ZIP file, extracts it and executes a script to start the RMM installation.

Similar to the Stage 1 downloader, the Stage 2 downloader creates its own working directory under C:\Users\Public\Documents\, commonly using randomized folder names such as Sys<random>, Data<random>, or a random numeric value. In most cases, the hidden attribute is assigned to this folder. The script then downloads a ZIP archive from attacker-controlled infrastructure, extracts its contents, and executes an embedded setup1.vbs script.

Stage 2 downloader creating a hidden working directory under C:\Users\Public\Documents
Stage 2 downloader creating a hidden working directory under C:\Users\Public\Documents\

Similar to the Stage 1 downloader, the variants leverage multiple download mechanisms, including curl, bitsadmin, certutil, PowerShell, and direct HTTP requests.

Stage 2 downloader using multiple download mechanisms to retrieve the ZIP archive
Stage 2 downloader using multiple download mechanisms to retrieve the ZIP archive

Following a successful download, the archive is extracted using the Shell.Application COM interface. Most variants invoke the CopyHere method with flags intended to suppress user prompts and allow extraction to proceed without user interaction. The extracted setup1.vbs script is then launched through wscript.exe to proceed with the next stage of the infection chain.

Also, one variant additionally attempts to remove Zone.Identifier alternate data streams from extracted files prior to execution, likely to reduce security warnings associated with files downloaded from the Internet.

Example of the code responsible for ZIP extraction, Zone.Identifier removal, and execution of the next-stage VBScript
Example of the code responsible for ZIP extraction, Zone.Identifier removal, and execution of the next-stage VBScript

Stage 3: Installation of remote monitoring and management software


Besides the setup1.vbs script, the ZIP archive downloaded during Stage 2 contains a preconfigured ManageEngine Endpoint Central deployment package. Inside the archive are the files required to install and register the Endpoint Central agent, including the MSI installer, configuration files, certificates, and installation scripts.

Extracted Stage 3 Endpoint Central installation ZIP package
Extracted Stage 3 Endpoint Central installation ZIP package

The table below summarizes the purpose of each file contained within the deployment package:

FileDescription
DCAgentServerInfo.jsonEndpoint Central server configuration containing management server IP addresses and ports
DMRootCA.crtTrusted root certificate
DMRootCA-Server.crtServer authentication certificate
README.htmlEndpoint Central agent setup instructions
setup.batLegitimate Endpoint Central installer wrapper included in the package, not used by the malware chain
setup1.vbsMalicious launcher used by the threat actor to silently install the Endpoint Central agent
UEMSAgent.msiEndpoint Central agent installer package
UEMSAgent.mstCustom installation configuration settings for the MSI package

ManageEngine Endpoint Central is a legitimate enterprise management platform commonly used for software deployment, system administration, and remote support. Its remote administration capabilities make it attractive for abuse by threat actors seeking persistent access to compromised systems.

One interesting variant attempted to disguise the package as an income tax–related document. Instead of containing a legitimate tax document, the archive contained a VBScript file named “Income Tax Return Form.vbs” and accompanied by an instruction file designed to persuade the victim to open it. Analysis showed that the VBScript contained functionality similar to setup1.vbs, ultimately performing the same Endpoint Central installation process.

Tax document-themed VBScript lure and installation script
Tax document-themed VBScript lure and installation script

As discussed in Stage 2, the downloader ultimately executes a VBScript file named setup1.vbs. The script first verifies that the required installation files are present in the extracted folder and then attempts to relaunch itself with administrative privileges using the Windows runas mechanism before proceeding with the installation.

The setup1.vbs script verifying installation files and requesting administrative privileges
The setup1.vbs script verifying installation files and requesting administrative privileges

Once elevated, setup1.vbs silently installs the bundled ManageEngine Endpoint Central agent using msiexec.exe, applying the supplied configuration and certificate files. The installation is performed silently, preventing the user from seeing the Endpoint Central installation interface.

Endpoint Central agent installation via msiexec.exe
Endpoint Central agent installation via msiexec.exe

Analysis of the embedded DCAgentServerInfo.json configuration file revealed the following Endpoint Central management servers:

  • 202.61.160[.]208
  • 202.61.160[.]202
  • 202.61.160[.]201
  • 202.61.160[.]160
  • 202.61.160[.]137
  • 38.55.151[.]63

Notably, 202.61.160[.]201 had previously been observed as command-and-control infrastructure associated with ValleyRAT and Gh0st RAT activity. Although the overlap raises the possibility of the VBS campaign being linked to the operator of these known malware families, the available evidence is insufficient to confidently attribute the campaign to a known threat actor.

Victimology and attribution


Based on our telemetry, infections were observed across several countries and territories, including Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia, and Vietnam, with 80% of the victims located in Malaysia. The campaign primarily relied on malicious VBScript attachments distributed through WhatsApp and appeared to target individual users rather than specific organizations or industries. At the time of the analysis, no evidence suggested a focused targeting strategy, instead indicating a broad, opportunistic campaign aimed at consumers.

We were unable to confidently attribute this activity to a known threat actor or intrusion set. However, several artifacts observed throughout the campaign point to a possible Chinese-speaking threat actor.

Multiple VBScript samples contained comments, module descriptions, and execution notes written in simplified Chinese characters. These comments appeared consistently across different variants, suggesting that the scripts were likely developed or maintained by a Chinese-speaking operator.

We also identified infrastructure overlaps with IP addresses previously associated with ValleyRAT and Gh0st RAT activity. While these overlaps may indicate infrastructure reuse or shared hosting resources, they are not sufficient to establish a direct connection to any known threat actor.

Based on the available evidence, we assess with low confidence that the campaign was conducted by a Chinese-speaking operator. Additional investigation, infrastructure overlaps, or operational indicators would be required to support a stronger attribution assessment.

Conclusion


This campaign uses compromised WhatsApp accounts to distribute malicious VBScript attachments that ultimately install a preconfigured ManageEngine Endpoint Central agent on victim systems. Observed victims were located across multiple countries and territories, including Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia, and Vietnam, suggesting a broad and opportunistic campaign. Users should be cautious when receiving unexpected attachments through WhatsApp, even when they appear to originate from known contacts. Script and executable file types such as VBS, VBE, EXE, BAT, CMD, JS, and PS1 should not be opened unless their legitimacy has been independently verified.

IOCs

VBScript


c7f38cbb99c8b74fa0465293feeba700 Financial Reports.vbs
b7cd06c71465038b658a6dc1f273a507 Debt confirmation.vbs
9f13c7b8ba391b2f597874e54d310648 Electronic statement(A).vbs
993f4c0cadbc769a4b0ed62a918db58d Financial Reports(s).vbs
7f81c1bc8cfd588e8998968e2621456e Outstanding Payment List.vbs
7403cbcc5a9c32384d431856dc48fcc9 Statement of debt (4).vbs
68c16c46f8afb9e00bbaba0207fb0a46 Debt Note (2).vbs
66442f2457eca8f47385b1fb2c6fcab8 Statement of Debt(30K).vbs
6359e6236471cbe434d0ef4c42b7f879 Applicationform1.vbs
5b6bbcc06cf08cc99e1afeda486d42fb Extrato de Conciliação.vbs
5002eca748205d544618e3bd2dedc223 Statement of Debt(29K).vbs
4f0593e8e0e8fac49429e9b45ebf7fa1 Outstanding Payment List.vbs
4044e4b6471c9de7b0a4ba37d9d9df9a billing statement (2).vbs
20209b3a32769afc6a75694b8d8839dd Statement of Debt(A).vbs
0ba93109757776a44de9d8c88baa4963 Financial Reports(C1).vbs
02bb20455cc592a69c080abac770ce90 Le formulaire de demande le plus récent .vbs
6c39900d77dcba158e1d27c7619cb06d Outstanding Balance Sheet(A).vbs
dad708e050632a4280cabf98ac1376b7 Outstanding Balance Sheet.vbs
05d188f071d097f5b6bd8138749b4b14 Penyata bank.vbs
2c6f05f1f309d89b2236e6c8b59c88f9 Account Statement(13K) (2).vbs
3b1aba44dd3d9b6339b6f56e2f42034b Statement of Account.txt
d43fdaa1f0ee09d7e5f0f94ee9df7b6c Bitte füllen Sie das Formular für Umsatzsteuer-Nullsatz-Verkäufe aus.vbs
df4fa0369eaca5cec348be293890d4af Account Statement.vbs
63ac85195b73753333316a889cf5880f Statement of Account(O).vbs
74fd9f91fc93b6288b4fc253ea5b3e20 Sila semak bil anda.vbs
d06333c360b51456f427e616c3c5f8bd Sila semak bil anda.vbs
993f4c0cadbc769a4b0ed62a918db58d FinancialReportsS.vbs
1d94fbe9cab21278cc3f104bea334d08 Promissory_Note(b).vbs
9d9ac85765e4a818a3ccabe2cf4fef82 Debt Statement.vbs
6fb6a55424adfb61e31f06aef33273e5 dfjieya.vbs
f90ed4b2d0b67114aa89ddfed658e5c0 dfjieya.vbs
8c3322009b8982663c0cbecd9492e7eb 0lf.vbs
66705384a7ad81d14c34fc6c054a0ecf iowepv.vbs
8c6d9fc389ad3f20ccbc71d77eb39bfa btksfmsi.vbs
1a3cc75466ffb1971482f7abf7aabc3f home3.vbs
1c47c63e5ed25060d95359c57c77b107 zipats.vbs
31037a42ca048e06e69a78f55bc2eff5 1122.vbs
7f16449cd0c4862d1eadf8a5742bf09a payload_1.vbs
79ecd61b09b0f2d54b34586c916c4ec9 sac8.vbs
7849061c536a3efb05a56d504694e7e7 6oy.vbs
ddaffe9849f7f3c79f8804adb9a6b3d5 kof.vbs
d01cad98dd0d01b75e04e784953c5e2b sleestak_payload_1.vbs

Domains


temu.baskwms[.]top
invoice.msopsa[.]top
baoxis[.]cc
sdcwww.oss-ap-southeast-1.aliyuncs[.]com
baoyuw2s.s3.ap-southeast-1.amazonaws[.]com
sjdkjj23.s3.ap-southeast-1.amazonaws[.]com
xijkwm2.s3.ap-southeast-1.amazonaws[.]com
yifubafu.s3.ap-southeast-1.amazonaws[.]com

Attacker-controlled UEMS server IP Address


202.61.160[.]202
202.61.160[.]201
202.61.160[.]137
202.61.160[.]160
202.61.160[.]208
38.55.151[.]63


securelist.com/whatsapp-vbs-rm…

How social media bans can work


The media in this post is not displayed to visitors. To view it, please log in.

How social media bans can work
IT'S MONDAY, AND THIS IS DIGITAL POLITICS. I'm Mark Scott, and will be speaking on this panel about trust in digital services at the IAPP/Harvard Navigate conference in Portsmouth, New Hampshire this week. If anyone is around in Boston on June 25, drop me a line here to grab coffee.

— The United Kingdom became the latest country to propose a social media ban for children. If others follow suit, this is how such bans should actually work.

— One of Europe's top courts just blew a hole in liability protections for online platforms. It's the second time judges have upended this decades-old precedent in recent months.

— Digital industries added $18 trillion in market value over the last three years.

Let's get started:



digitalpolitics.co/social-medi…

SDS-Remote Brings Power-User Features to Siglent Scope


The media in this post is not displayed to visitors. To view it, please log in.

SDS-Remote

Many oscilloscopes have provisions to be connected to a computer and used remotely, but most of those interfaces are fairly rudimentary. To address this, [Winfried] has developed the SDS-Remote, a remote interface for the Siglent SDS 1000X-E series oscilloscopes.

The 1000X-E series oscilloscopes have both USB and network interfaces, and the SDS-Remote can use either (though the USB interface is still somewhat experimental). SDS-Remote allows for remote controlling the oscilloscope, capturing waveforms super handy as it lets you export a CSV file of the waveforms for further analysis. You can also capture screenshots of the scope through the web interface, making it much easier to compare waveforms as you’re working on a project. The built-in data logging lets you run long experiments and save out their results. The macro recorder lets you automate complex tests using SCPI commands and brings basic scripting to the interface without needing to run separate code. There’s also a mechanism to integrate an AI LLM to help translate common language into the correct scope configuration.

Thanks [Winfried] for sharing this awesome web interface for the oscilloscope no doubt it’ll be a welcome upgrade for those already remote controlling their Siglent scope. Head over to his GitHub page and check it out for yourself! Have you written any improved user interfaces for your equipment? Be sure to let us know what you’ve done so we can share with others who may find use in an interface that offers more than came with the product.

youtube.com/embed/sbQIYpyg1p4?…


hackaday.com/2026/06/22/sds-re…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation
securityaffairs.com/194004/hac…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

Homebrew is a masterpiece of software engineering. It nicely isolates packages in user-space, entirely skips the `sudo` bs of other package managers, and keeps the core OS clean. Dev tooling really doesn't get much better than this.

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Energy Security, Not Climate Goals, Is Now Driving the Clean Power Boom
L: oilprice.com/Alternative-Energ…
C: news.ycombinator.com/item?id=4…
posted on 2026.06.21 at 17:19:21 (c=0, p=3)

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Da grande voglio fare il #ninja!
Così mamma (mi manchi tanto) sarà felice che prendo un pezzo di carta =)

youtu.be/3R7c5OXNVho?si=yvKepG…

Cybersecurity & cyberwarfare ha ricondiviso questo.

4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware
securityaffairs.com/193987/sec…
#securityaffairs #hacking

“Telescope Rancher” is The Coolest Job You Didn’t Know Existed


The media in this post is not displayed to visitors. To view it, please log in.

Bortle-1 Skies in the heart of darkest Texas.

McCulloch County, Texas, is smack dab in the middle of a very large state. We wouldn’t exactly call it the middle of nowhere, but given there’s so little light pollution it scores a 1 on the Bortle Scale, it’s not exactly the Big Apple, either. [Bray Falls] lives there, and has a job description we have become immediately jealous of: [Bray] is a telescope rancher.

Like the song goes, the stars really are big and bright at night deep in the heart of Texas. Not only is his ranch free of the light pollution that plagues more urban locations, central Texas is pretty dry, with only a few days of rain in any given month. That’s not great for agriculture, but it’s great for astronomy since it means the skies are most often cloud-free. Combine that with access to high-speed internet, and you have the makings of a telescope ranch.
Telescopes being let out of the barns for the night.
Image: Starfront Observatory
It’s brilliant in its simplicity: along with his own ‘scopes, [Bray]’s Starscope Observatory hosts hundreds of other people’s CCD equipped goto telescopes, all set up to be remote controlled over the information superhighway. On clear nights– which again, is most of them–the roofs roll off the telescope barns and observations can begin. Pad rental comes with tech support, too, so you don’t have to fly out to heart of darkest Texas if your mount gets jammed or you lose signal for any reason. That said, you should be sure to read the fine print before signing up, because said tech support probably doesn’t apply if you 3D printed your own ‘scope, or built your own mount.

That said, having gone to the effort of doing all that, would you really send your baby away to a farm upstate? Best reserve that for the old Celestron collecting dust in the corner. If you think we should be leaving these observations to the pros, be aware [Bray] has apparently discovered a very oddly-placed supernova remnant, 40 degrees off the galactic plane in Virgo. So this isn’t just a rewarding hobby; it’s still science, too.


hackaday.com/2026/06/22/telesc…

Cybersecurity & cyberwarfare ha ricondiviso questo.

usbliter8 Brings Unpatchable BootROM Exploit to #Apple A12 and A13 Devices
securityaffairs.com/193965/hac…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

348 – Google ora risponde di quello che dice la sua AI camisanicalzolari.it/348-googl…

Won’t Somebody Please Think Of Banning The British Children!


The media in this post is not displayed to visitors. To view it, please log in.

The British government is in a headlong rush to ban under-16s from social media, and restrict the access of under-18s. And in typical form, the EFF is here with a warning about the dangers and futility of such legislation.
A satirical mock-up of what UK Prime Minister Keir Starmer's driving licence might look like, courtesy of https://use-their-id.com/Kids aren’t stupid. They’ll use a fake ID like this one from the satirical use-their-id.com/ . Or they’ll become VPN experts.
The proposed new law will involve an age restriction policed through online ID verification, something which will not be limited to the young, as every British adult will also have to show ID to access large parts of the Internet.

There is little in the way of information about how this unprecedented invasion of privacy will be implemented, however we expect that it will be left to the lax security measures of a range of lowest-bidder third party identity verification services. The resulting database will become a very rich target indeed.

The EFF pull no punches in warning of the harms these measures will bring upon those it seeks to protect. Far from “Giving under-16s their childhood back” as it is being promoted, they warn that it will deprive them of access to community, friends, and distant family, as well as educational content that could be vital for them.

If it works at all. Certainly he more technically minded youth will put their efforts into the world of computer networking. A VPN ban is reportedly in the works, so a whole generation of future software developers and IT specialists will get their start running software to get round this on their Raspberry Pi.

We’ve reported on the EFF’s concerns over UK ID laws before.


Header image: Diliff, CC BY-SA 2.5.


hackaday.com/2026/06/21/wont-s…

Gazzetta del Cadavere reshared this.

Brewing Espresso with Ultrasonic Assistance


The media in this post is not displayed to visitors. To view it, please log in.

An AI-generated diagram of the coffee-making process is shown. A filter holds a basket of coffee grounds, which are contained in a paper filter. An ultrasonic transducer vibrates the basket.

There are as almost as many kinds of coffee as there are of coffee drinkers, with each method for preparing the beverage appealing to a different kind of palate: moka pots, filter coffee, pour-over coffee, French presses, cold brews, espresso, and more produce their own unique flavours by extracting different compounds from the grounds to different degrees. Now, a new method has joined the throng: ultrasonic-assisted extraction, which can produce even an espresso at room temperature.

Espresso is normally made by forcing hot water through tightly-packed, finely-ground coffee beans, quickly producing a concentrated extraction. Its one of the hardest kinds of coffee to consistently make well, since the outcome is influenced by everything from grind size and packing density to temperature, pressure, and more. Ultrasonic agitation helps here by creating cavitation bubbles, which form shock waves as they collapse, breaking open the bean structure and producing small, strong jets of water. The experimental apparatus was built into a modified espresso machine. An ultrasonic transducer delivers vibrations to the basket containing the room-temperature slurry of coffee grounds for two or three minutes.

To quantify the results, the researchers analysed total dissolved solids, extraction yield, pH, colour, volatile components, and caffeine and chlorogenic acid contents. By varying ultrasonic power and grind size, the extraction yield and dissolved solids could be adjusted to closely match traditional espresso or cold-brew coffee. The other metrics had no significant differences, and a survey of 100 coffee drinkers found no preference between this and traditional espresso. When the drinkers tried the cold-brew coffees, they preferred the version made with ultrasonic assistance. The experiment succeeded in its goal of reducing energy consumption: the ultrasonic-assisted coffee took about a quarter as much power to make.

If you still prefer a more traditional approach, we’ve covered some beautiful espresso machines before, including one made out of motorcycle engine parts.


hackaday.com/2026/06/21/brewin…

Hackaday Links: June 21, 2026


The media in this post is not displayed to visitors. To view it, please log in.

Hackaday Links Column Banner

Today marks the summer solstice, the longest day of the year and the start of astronomical summer in the Northern Hemisphere. This doesn’t really have much to do with hacking hardware or building gadgets other than the fact that from this point on you’ll have progressively less daylight hours to do it in each day. Of course, if you do your best work in the middle of the night this won’t impact things much.

If you’re as likely to find a controller in your hand as a soldering iron in the evenings, you might be interested in a recent filing against Sony. Lawyers representing a group of four gamers allege that the entertainment giant is violating a California law that says digital storefronts need to make it clear that buyers don’t technically own the games in question but are merely licensing them — a license which, as we’ve seen in the past, can be revoked or modified at any time with no restitution made to the purchaser.

Now while we agree conceptually that selling gamers a license rather than an actual copy of the game is clearly a one-sided deal, we’re still not sure this case has a lot of merit. As far as we can tell, Sony does make it clear in the fine print that you’re not really going to own anything once they take your money. Or, at the very least, they make it equally as clear as any other company that’s selling digital downloads these days. Should the court actually find that said fine print is a little too fine, it could conceivably have ramifications throughout the entertainment industry. This is certainly a case to keep an eye on.

If you want to be sure none of your games can be removed from your digital grasp without warning, perhaps your best bet is to stick to the classics. Fans of 1989’s F-15 Strike Eagle II on PC will be excited to hear that there’s an ongoing effort by Neuvieme Porte to reverse engineer the flight sim and re-implement the whole thing in portable C.

This would open up all sorts of possibilities, such as ports to other platforms and the addition of new features and content. But before the project can get to that point however, Neuvieme is looking to recruit some virtual test pilots. Just keep in mind that the goal, at least for now, is to recreate the game exactly. That means bugs present in the original release are to be preserved. As such, it would help to have logged enough hours back in the DOS days to recognize what’s an OG bug and what’s been newly introduced.

From working on virtual jet fighters to the real deal, IEEE Spectrum recently ran an article about a startup called Phoenix Semiconductor that’s looking to produce bespoke pin-compatible replacements of critical chips for the military. They reason that the Air Force won’t mind paying $1,000 for a chip that cost them a buck back in 1975 when the alternative is grounding a $70+ million F-18 that needs the thing to take off. The goal isn’t really to recreate the old parts as they were, but instead to build drop-in replacements that are tailored for specific applications. In other words, Uncle Sam doesn’t care of the IC actually looks like the original, so long as it fits and it gets the jet up in the air again.

Finally, on the subject of aerospace technology, NASA’s Jet Propulsion Laboratory published a blog post earlier this week detailing their work on the Exploration Rover for Navigating Extreme Sloped Terrain (ERNEST). While NASA’s Curiosity and Perseverance rovers have done some incredible work on Mars, they’re slow and have to be operated with the utmost caution to make sure they don’t get stuck. In comparison, ERNEST is several times faster and is designed with an active suspension system that lets it lift each wheel up off the ground independently if needed.

youtube.com/embed/d684P5a3xMc?…

The prototype rover also features improved autonomy that may allow future rovers make more decisions on their own. That may not be a huge time saver on the Moon, but given the communication delays with the Red Planet, a Mars rover that doesn’t have to stop and ask Earth for directions so often will be able to get more useful work done at the end of the day.


See something interesting that you think would be a good fit for our weekly Links column? Drop us a line, we’d love to hear about it.


hackaday.com/2026/06/21/hackad…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Per una visione realistica dell’intelligenza artificiale

Dal blog Link&Think di @enriconardelli
link-and-think.blogspot.com/20…
@informatica
di Enrico Nardelli

(english version here)

Si è svolta martedì 16 giugno, presso la sala stampa della Camera dei Deputati, la conferenza stampa di presentazione della lettera aperta alla società intitolata “Per una visione realistica dell’intelligenza

Cybersecurity & cyberwarfare ha ricondiviso questo.

For a Realistic Vision of Artificial Intelligence

Dal blog Link&Think di @enriconardelli
link-and-think.blogspot.com/20…
@informatica
by Enrico Nardelli

(versione italiana qua)

On Tuesday, June 16th, in the press room of the Chamber of Deputies, a press conference was held to present an open letter to society titled "For a Realistic Vision of Artificial Intelligence", signed so far by more than 350

Cybersecurity & cyberwarfare ha ricondiviso questo.

Tg1: Ritrovate le due sorelline scomparse da due settimane da una casa famiglia a Civitella Alfedena (L'Aquila). Sarah e Alisya sono state ritrovate dai carabinieri in buone condizioni di salute a casa di una zia a Formia (Latina)
Cybersecurity & cyberwarfare ha ricondiviso questo.

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 102
securityaffairs.com/193960/sec…
#securityaffairs #hacking

SmallRun.net Enters the Marketplace Market


The media in this post is not displayed to visitors. To view it, please log in.

So you have a project that you love, and everyone else loves too. People start saying “you should sell this” but where? Well, there’s a new marketplace you might want to consider called called SmallRun, aiming at makers and their, well, small production runs.

SmallRun will absolutely host your custom PCBs, on-demand 3D prints, and other traditional maker products — but they’ll also happily sell your merch, too. Along with electronics and hardware, they aim to allow you to sell products in categories like tabletop gaming, sciences, and yes, accessories/apparel.

For sellers, they offer automatic payouts and promise to take care of the taxes by integrating with Stripe. That said, they’re still working on getting the whole VAT thing set up for products imported to the EU. EU to EU sales are apparently OK. They’ll host build logs, which may drive engagement with your product. There’s even a handy tool to import your existing listings from eBay, Tindie, Lectronz, Etsy, Shopify, or Crowd Supply if you’re already in the biz. They make their money by taking a cut of your sales: eight percent, plus forty cents per listing.

Depending on your perspective, you might wonder if we need another marketplace, To that we can only say: “Let a thousand flowers bloom!” Competition should drive these marketplaces to continuously improve and we all win.

If you’re selling online, even packaging can become a project. If you’re not, but are interested in starting, our “From Project to Kit” series from ten years back remains surprisingly relevant.

Thanks to [Aron] for the tip!


hackaday.com/2026/06/21/smallr…

Fred de CLX reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Siviglia, Plaza de España

Video della giornata: video.simoneviaggiatore.com/w/…

#photography #fotografia #plazadeespana #sevilla #siviglia #spagna #espana #viaggio #viaggiare #europa #maravilla #simoneviaggiatore #diariosiviglia

Iscriviti al gruppo --> @viaggi@feddit.it


Siviglia, cosa vedere in questa perla dell'Andalusia: qui la Spagna è al suo massimo! | Travel vlog parte 1


Viaggiatori, eccovi la prima parte del mio vlog di viaggio a Siviglia (Febbraio 2026).

Mi auguro che queste immagini vi lascino estasiati come la Siviglia ha lasciato me: dopo un po' la bellezza era tanta da sopraffarti.

Condividete il video e come sempre ditemi cosa ne pensate.

Qui trovate la community dei Viaggiatori su Feddit: @viaggi@feddit.it.

Non siate timidi, raccontate i vostri viaggi, le vostre foto, o chiedete consigli!

A presto con la parte 2-3 di Sivigla.


Cybersecurity & cyberwarfare ha ricondiviso questo.

Security Affairs #newsletter Round 582 by Pierluigi Paganini – INTERNATIONAL EDITION
securityaffairs.com/193953/unc…
#securityaffairs #hacking

When a Favicon Becomes the Entire Website


The media in this post is not displayed to visitors. To view it, please log in.

Putting hidden data in places where few expect it can be a fun hobby or even a professional career. In the case of [Tim Wehrle] it’s just the former. His most recent project in this area uses a favicon image for storing a HTML-based website and rendering its contents within the browser after the favicon has been downloaded.

To pull this off, a very basic HTML page was turned into a series of UTF-8 encoded bytes that were then declared to be a standard PNG image. The original 208 byte payload plus 4-byte PNG header only used part of a 9×9 pixel favicon. With a larger favicon image as typically used you could thus easily store more data, whether as visual noise like here or a bit more hidden.

Of course there’s a catch, and in this case it’s the Typescript code to unpack the bytes from the “image” and render them; you have to load that separately. But still, in these days of all-singing, all-dancing websites that take forever to render, it’s refreshing to see what you can do with so few bytes that they fit in a favicon.

As for the purpose of such an approach, that’s left as an exercise for the reader, but you’re more than welcome to take a poke at the GitHub project and the demonstration site..


hackaday.com/2026/06/21/when-a…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Check whether a site supports post quantum crypto* quantumhello.xyz

* Well hybrid PQ key exchange in the form of TLS 1.3 with X25519MLKEM768

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

I dati provenienti da "mezzo milione di ore di filmati di droni sul conflitto in Ucraina" sono ora disponibili per addestrare l'intelligenza artificiale.

I dati video a pieno movimento stanno diventando sempre più rilevanti, poiché i droni stanno trasformando la guerra moderna e il telerilevamento commerciale, ha affermato l'amministratore delegato di Enabled Intelligence.

defensescoop.com/2026/06/16/da…

@aitech

Cybersecurity & cyberwarfare ha ricondiviso questo.

Yann LeCun afferma che xAI è "una sorta di fallimento" e che l'intero settore dell'IA potrebbe essere destinato a un "riavvio"

Secondo lui, Musk si trova ad affrontare difficoltà nell'attrarre ingegneri mentre l'azienda brucia liquidità

techspot.com/news/112836-yann-…

@aitech

Cybersecurity & cyberwarfare ha ricondiviso questo.

La Casa Bianca ritarda la pubblicazione dello studio sulle macchine per il voto negli Stati Uniti in vista delle elezioni di medio termine.

Secondo due fonti, l'ODNI ha tenuto informata la Casa Bianca per sei mesi senza autorizzazione alla pubblicazione del rapporto.
Secondo quanto riportato da tre fonti, molti stati utilizzano sistemi obsoleti.
Tutte le fonti hanno affermato di non essere a conoscenza di alcuna prova di manipolazione dei voti nelle elezioni statunitensi.

reuters.com/world/white-house-…

@Politica interna, europea e internazionale

Cybersecurity & cyberwarfare ha ricondiviso questo.

Il CEO di Nvidia, Jensen Huang, afferma che nel nuovo mondo del lavoro ci sarà bisogno di centinaia di migliaia di elettricisti e idraulici.

Alla Generazione Z viene continuamente ripetuto che le sue possibilità di trovare un lavoro sono scarse, poiché l'intelligenza artificiale minaccia i posti di lavoro di livello base. Ma in realtà, afferma Jensen Huang, CEO di Nvidia , ci sono migliaia di posti di lavoro per i giovani, grazie al boom accelerato dei data center. Devono solo essere disposti a frequentare una scuola professionale .

fortune.com/article/nvidia-bil…

@Lavoratori Tech

Cybersecurity & cyberwarfare ha ricondiviso questo.

Meta vuole che una legge sulla sicurezza dei bambini venga riscritta per proteggerla da cause legali relative a danni arrecati ai minori.

Meta e Google hanno già perso la loro prima causa sulla sicurezza dei minori quest'anno, con un risarcimento danni di 6 milioni di dollari.

techspot.com/news/112824-meta-…

@Informatica (Italy e non Italy)