Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Venti Agentici: la Cina elimina 12.000 programmi di laurea e rinnova la scuola

📌 Link all'articolo : redhotcyber.com/post/venti-age…

A cura di Massimiliano Brolli

#redhotcyber #news #riformauniversitaria #istruzione #cina #nuoviprogrammidiLaurea #economia

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

9,8 su 10! Gli Hacker criminali stanno sfruttando un bug critico su Splunk Enterprise

📌 Link all'articolo : redhotcyber.com/post/98-su-10-…

A cura di Luigi Zullo

#redhotcyber #news #cybersecurity #hacking #vulnerabilita #splunk #cve202620253

Dynamic RAM from First Principles


The media in this post is not displayed to visitors. To view it, please log in.

Before the past year, many of us took computer memory for granted. It was one of the lower-cost parts of a PC build and was usually available in whatever quantity one desired. As its cost has skyrocketed, a lot of PC builders and other users of computers in general are taking a deeper look at memory, how much is really needed, and what its functions truly are. [Igor] is working on a drum sequencer project which needs a small amount of memory, and has built this dynamic RAM from discrete components.

The first video goes into the construction of the memory array and how its addressed. It’s only eight bytes total, and using fairly large electrolytic capacitors to store data means that a gigabyte of this memory would take up well over a thousand acres, but it’s still enough memory for [Igor]’s needs. In addition to the capacitor, each bit uses a pair of diodes to determine if a read or write is occuring, and a set of transistors on the read and write busses to perform those actions. Worth noting here is that dynamic RAM like this needs to be refreshed because the capacitors lose charge over time, but these large capacitors can hold charge sometimes overnight, as [Igor] has confirmed experimentally.

There’s a followup video to the construction of these modules as well, where [Igor] demonstrates a number of ways this module can be used, from controlling LED arrays, 7-segment displays, and then installs it into his drum machine. With 64 bits available it’s capable of creating up to eight beats with eight samples available per beat. Although there are complete machines available for all of this, we appreciate his goal of not buying any pre-manufactured hardware and instead constructing it all from the ground up. There are analog drum machine options available in this same style as well.

youtube.com/embed/lYUuGf6b0IQ?…

youtube.com/embed/O6Coh5Ey3AU?…


hackaday.com/2026/06/22/dynami…

LightComposer – Reach Out and Touch Your Lighting


The media in this post is not displayed to visitors. To view it, please log in.

Lightcomposer

While there is a time and place for wirelessly controlled devices, sometimes you want something you can just reach out and touch to interact with, no apps to install or devices to configure. In this case [John] wanted a lamp that was just that. Drawing inspiration from the rotary phone, he created the LightComposer.

This small lamp, just a bit smaller than a hockey puck, uses a 3D printed enclosure and a straightforward PCB. It’s a very accessible project to recreate. The 3D prints are well thought out including a TPU ring on the bottom to keep the lamp from sliding around. The light source comes from 32 SK6812 LEDs, which are very similar to NeoPixels. An ATmega328P microcontroller powers the project and can easily be programmed using the Arduino IDE. A rotary encoder in the center, coupled to the top diffuser, lets you control LED brightness and color by turning it. The firmware also includes some fun hidden light-effect modes.

Head over to [John]’s site for all the files needed to make your own LightComposer, or links to buy a premade one. What devices have you made that use a straightforward physical user interface in lieu of an app? Be sure to check some of the other lamp builds we’ve featured before.


hackaday.com/2026/06/22/lightc…

Cybersecurity & cyberwarfare ha ricondiviso questo.

There we go. US Government tightens post-quantum cryptography transition deadlines for high-value systems to 2030 for key exchange and 2031 for signatures.

Also, speeding up the CMVP (FIPS 140 validation) processes. That’s how you know the rush is real.

The quantum computers are (potentially) coming.

whitehouse.gov/presidential-ac…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

#WhatsApp #Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools
securityaffairs.com/194031/mal…
#securityaffairs #hacking

Investigating Annealing as Fix for Poor CF Adhesion in 3D Prints


The media in this post is not displayed to visitors. To view it, please log in.

After recently publishing a few videos covering research into the poor adhesion between chopped carbon fiber (CCF) and the thermoplastic filaments as used with FDM 3D printing, some of the feedback received by [I built a thing] included the idea that the missing step to make CCF additives work was post-print annealing. Naturally this claim had to be investigated, both through the resulting physical characteristics as well as on a microscopic level in the same scanning electron microscope (SEM) as before.
Post-annealing SEM scan, showing clear voids. (Credit: I built a thing, Youtube)Post-annealing SEM scan, showing clear voids. (Credit: I built a thing, Youtube)
Theories as to why annealing the parts would help here seem to focus on increased bonding and filling of voids in the printed CCF-infused material, while there are the typical worries with annealing such as parts warping and shrinking to also take into account as potential downsides of this treatment.

For the sample materials PETG and PETG-CF, as well as PLA and PLA-CF filaments are used, with each filament type featuring an annealed and not annealed version. These were then tested for tensile strength, stiffness and failure type, as well as dimensional accuracy and warping, before being examined under the SEM. A total of 160 samples were used, with 20 samples per material and annealing state.

Perhaps the biggest surprise here was how much PETG benefits from annealing, making it much more resilient to breaking, whereas neither PLA nor PLA-CF seemed to see much benefit. Shocking was how much worse PETG-CF performs than PETG, with the former being worse than both PLA and PLA-CF here.

In terms of dimensional accuracy, annealing caused a Z direction expansion while shrinking the samples in the other directions. The CCF addition here actually prevented much of the shrinking and expansion, showing the first clear benefit of this additive. Yet despite annealing at right above the glass transition temperature as is proper, this would seem to be the limit of this approach in terms of practical benefits.

Compared to the previous research that focused on PLA-CF, PETG-CF would seem to make the case even more strongly that there’s no real purpose to CCF additives, especially since you can already account for parts shrinkage during annealing before printing. That there’s no improvement to the CCF and thermoplastic interface adhesion is also no mystery, considering the science behind how e.g. thermoset materials create bonds with CF.

youtube.com/embed/hT-YXG1b8qA?…


hackaday.com/2026/06/22/invest…

Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: A spyware and hacking tools maker has released details of an unpatchable flaw in Apple chips that could potentially allow hackers to make a jailbreak for older devices.

The flaw, dubbed usbliter8, can help someone with physical access to devices up to the iPhone 11 to unlock and break into them.

The bug affects Apple-made chips A12 and A13, released in 2018 and 2019.

techcrunch.com/2026/06/22/a-ne…

reshared this

Breaking Into a Prison Tablet


The media in this post is not displayed to visitors. To view it, please log in.

Usually the term ‘jailbreaking’ isn’t meant to be taken quite that literally, but in the case of the US prison tablet that [Hugh Jeffreys] got sent, it’s really quite apt. Unlike the typical transparent prison electronics, this tablet is hermetically sealed inside an opaque plastic case, with the Windows 10 install firmly locked-down and not allowing anything more to be done with it than access some prison-provided services via the browser in kiosk mode.

The first challenge was to see whether it could be booted at all, with just four metal pads visible on the side of the case. These turn out to correspond to USB pins, but the tablet only briefly tries to turn on with a charger connected. This means that a teardown is required, which ended up involving a hacksaw due to the sealed case.

Inside the case is the Windows tablet with the back cover removed, presumably for easy access to extend its USB port. All of this is embedded in foam and more gunk that makes disassembly rather messy. With the case opened it becomes clear that the likely reason why this tablet was junked was due to a bad third-party charger board, as using the tablet’s own USB port it charges happily and even turns on.

From there it’s a bit of a fight with the locked-down Windows installation, but as it’s just a Windows 10 Home installation, there’s no drive encryption or such to get in the way. This allows for the device to be fully jailbroken, revealing its specifications as an Iview Optimus-C-8001, powered by an Intel Atom Z8350 at 1.44 GHz with a blistering 2 GB of RAM. The Windows installation was from 2018, with apparently no updates since.

Despite the very high school arts-and-crafts appearance of the case itself, the tablet itself isn’t too shabby considering the limited hardware specifications. Although getting the case off is a bit of a pain, it’s not a bad catch if you can find one of these puppies in the e-waste bin.

youtube.com/embed/at8KPvN4UV8?…


hackaday.com/2026/06/22/breaki…

The media in this post is not displayed to visitors. To view it, please log in.

AryStinger: la botnet che trasforma router D-Link in armi silenziose per attacchi globali


@Informatica (Italy e non Italy)
AryStinger è una nuova botnet scoperta da XLab che ha compromesso oltre 4.000 router D-Link obsoleti trasformandoli in proxy per attacchi di ricognizione e intrusione globali. Sfrutta vulnerabilità vecchie di anni e comunica via


AryStinger: la botnet che trasforma router D-Link in armi silenziose per attacchi globali


I ricercatori di XLab (Qianxin) hanno scoperto AryStinger, una botnet precedentemente sconosciuta che ha compromesso oltre 4.000 router obsoleti in tutto il mondo, trasformandoli in proxy silenziosi al servizio di attori malevoli. A differenza delle classiche botnet DDoS, AryStinger è progettata per il ricognizione e il supporto alle intrusioni — un’infrastruttura invisibile concepita per penetrare reti aziendali e governative.

Scoperta e timeline dell’operazione


Il 12 marzo 2026, il sistema di threat awareness di XLab ha rilevato l’indirizzo IP 107.150.106.14 che diffondeva un campione ELF con zero detection su VirusTotal, sfruttando due vulnerabilità datate: CVE-2013-3307 e CVE-2016-5681. Il campione, implementato in C, prendeva di mira router D-Link DIR-850L e DIR-818LW — dispositivi giunti a fine vita, privi di patch e ancora ampiamente diffusi in ambito SOHO.

Il 26 aprile è comparso un secondo campione correlato, questa volta scritto in Go e rivolto a dispositivi NAS, sfruttando CVE-2025-11837. Il percorso nel codice sorgente del campione Go rivela il nome del progetto interno: Ary-Attack — un dettaglio che ha consentito ai ricercatori di attribuire le due famiglie alla stessa operazione.

Architettura e capacità operative


AryStinger converte i dispositivi infetti in “executor” telecomandati, capaci di eseguire un insieme ricco di operazioni su richiesta del C2:

  • Scansione di rete: port scanning, identificazione dei servizi, enumerazione di sottodomini — attività tipiche della fase di ricognizione pre-intrusione.
  • Proxying e tunneling: il device infetto instrada traffico malevolo verso destinazioni terze, mascherando l’origine reale dell’attaccante.
  • Esecuzione di comandi arbitrari sul sistema.
  • Modifiche DNS: la botnet può alterare le configurazioni DNS del router per intercettare il traffico web degli utenti connessi.
  • Payload multi-linguaggio: supporta l’iniezione di payload scritti in Go, Java e Python, garantendo flessibilità operativa.
  • Canali di accesso persistente via dropbear (SSH) o gs-netcat.

Le comunicazioni con il server di comando e controllo avvengono via HTTP/HTTPS, con traffico serializzato tramite Protobuf e cifrato con XOR — una scelta che garantisce compattezza e una certa difficoltà nell’ispezione del traffico.

Distribuzione geografica e target


La telemetria di Qianxin mostra che la distribuzione delle infezioni è geograficamente concentrata: Corea del Sud (48,5%), Cina (31,8%), Svezia (6,4%), Malesia (3,5%) e Singapore (2,5%). La forte prevalenza asiatica suggerisce che il deployment iniziale sia stato mirato su mercati dove i router D-Link di fascia bassa hanno avuto larga diffusione e dove la sostituzione dei dispositivi a fine vita avviene con ritardi.

Il targeting di NAS oltre ai router nella seconda fase dell’operazione indica un’evoluzione verso dispositivi con maggiore capacità di elaborazione e connettività persistente — ideali per operazioni di lunga durata che richiedono stabilità dell’infrastruttura proxy.

Perché AryStinger è diversa dalle botnet tradizionali


La distinzione fondamentale di AryStinger rispetto a botnet come Mirai o AISURU è l’obiettivo operativo: non DDoS né mining di criptovalute, bensì la costruzione di un’infrastruttura di intrusione distribuita. I dispositivi compromessi diventano nodi di una rete di proxy residenziali che conferiscono agli attaccanti un’anonimizzazione difficile da penetrare: il traffico malevolo emerge da indirizzi IP domestici o di piccola impresa, superando spesso i blocchi basati su reputazione IP.

Questo modello operativo è tipico di gruppi APT che necessitano di infrastrutture di staging durante la fase di ricognizione e di pivoting nelle reti bersaglio. La capacità di modificare le configurazioni DNS aggiunge una dimensione ulteriore: chi usa un router infetto espone tutte le proprie comunicazioni a potenziale intercettazione.

Indicatori di compromissione (IoC)

# IP di spreading iniziale
107.150.106.14
# Dominio C2 autenticazione
eixfi.ajb8.com  (/auth endpoint)
# CVE sfruttate
CVE-2013-3307   (D-Link DIR-850L - autenticazione bypassata)
CVE-2016-5681   (D-Link DIR-818LW - esecuzione remota di codice)
CVE-2025-11837  (dispositivi NAS - variante Go)
# Processi sospetti da verificare sul dispositivo
syswapd0h
syswapd0w
# Percorso da verificare
/tmp/bin/  (presenza di campioni malware)
# Nome progetto interno (da path nel codice Go)
Ary-Attack

Due righe per i difensori


Per chi gestisce reti con dispositivi edge, le azioni prioritarie sono: sostituire immediatamente i router D-Link DIR-850L e DIR-818LW con modelli supportati e aggiornati; applicare gli aggiornamenti firmware più recenti su tutti i dispositivi di rete perimetrali; modificare le credenziali amministrative di default; disabilitare le interfacce di gestione remota se non strettamente necessarie. A livello di monitoraggio, è opportuno inserire il dominio eixfi.ajb8.com e l’IP 107.150.106.14 nelle blocklist e verificare nei log di rete la presenza di connessioni Protobuf verso host sconosciuti su porte non standard.

La scoperta di AryStinger conferma una tendenza consolidata: i dispositivi IoT e i router SOHO a fine vita restano un vettore di attacco privilegiato per costruire infrastrutture di intrusione persistenti e difficili da attribuire. La prossima botnet potrebbe già essere nascosta nel router del vostro operatore ISP locale.


Cybersecurity & cyberwarfare ha ricondiviso questo.

Texas Parks & Wildlife (#TPWD) Data Breach impacts 3 Million People
securityaffairs.com/194023/dat…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ AryStinger: la botnet che trasforma router D-Link in armi silenziose per attacchi globali
#CyberSecurity
insicurezzadigitale.com/arysti…

@informatica


AryStinger: la botnet che trasforma router D-Link in armi silenziose per attacchi globali


I ricercatori di XLab (Qianxin) hanno scoperto AryStinger, una botnet precedentemente sconosciuta che ha compromesso oltre 4.000 router obsoleti in tutto il mondo, trasformandoli in proxy silenziosi al servizio di attori malevoli. A differenza delle classiche botnet DDoS, AryStinger è progettata per il ricognizione e il supporto alle intrusioni — un’infrastruttura invisibile concepita per penetrare reti aziendali e governative.

Scoperta e timeline dell’operazione


Il 12 marzo 2026, il sistema di threat awareness di XLab ha rilevato l’indirizzo IP 107.150.106.14 che diffondeva un campione ELF con zero detection su VirusTotal, sfruttando due vulnerabilità datate: CVE-2013-3307 e CVE-2016-5681. Il campione, implementato in C, prendeva di mira router D-Link DIR-850L e DIR-818LW — dispositivi giunti a fine vita, privi di patch e ancora ampiamente diffusi in ambito SOHO.

Il 26 aprile è comparso un secondo campione correlato, questa volta scritto in Go e rivolto a dispositivi NAS, sfruttando CVE-2025-11837. Il percorso nel codice sorgente del campione Go rivela il nome del progetto interno: Ary-Attack — un dettaglio che ha consentito ai ricercatori di attribuire le due famiglie alla stessa operazione.

Architettura e capacità operative


AryStinger converte i dispositivi infetti in “executor” telecomandati, capaci di eseguire un insieme ricco di operazioni su richiesta del C2:

  • Scansione di rete: port scanning, identificazione dei servizi, enumerazione di sottodomini — attività tipiche della fase di ricognizione pre-intrusione.
  • Proxying e tunneling: il device infetto instrada traffico malevolo verso destinazioni terze, mascherando l’origine reale dell’attaccante.
  • Esecuzione di comandi arbitrari sul sistema.
  • Modifiche DNS: la botnet può alterare le configurazioni DNS del router per intercettare il traffico web degli utenti connessi.
  • Payload multi-linguaggio: supporta l’iniezione di payload scritti in Go, Java e Python, garantendo flessibilità operativa.
  • Canali di accesso persistente via dropbear (SSH) o gs-netcat.

Le comunicazioni con il server di comando e controllo avvengono via HTTP/HTTPS, con traffico serializzato tramite Protobuf e cifrato con XOR — una scelta che garantisce compattezza e una certa difficoltà nell’ispezione del traffico.

Distribuzione geografica e target


La telemetria di Qianxin mostra che la distribuzione delle infezioni è geograficamente concentrata: Corea del Sud (48,5%), Cina (31,8%), Svezia (6,4%), Malesia (3,5%) e Singapore (2,5%). La forte prevalenza asiatica suggerisce che il deployment iniziale sia stato mirato su mercati dove i router D-Link di fascia bassa hanno avuto larga diffusione e dove la sostituzione dei dispositivi a fine vita avviene con ritardi.

Il targeting di NAS oltre ai router nella seconda fase dell’operazione indica un’evoluzione verso dispositivi con maggiore capacità di elaborazione e connettività persistente — ideali per operazioni di lunga durata che richiedono stabilità dell’infrastruttura proxy.

Perché AryStinger è diversa dalle botnet tradizionali


La distinzione fondamentale di AryStinger rispetto a botnet come Mirai o AISURU è l’obiettivo operativo: non DDoS né mining di criptovalute, bensì la costruzione di un’infrastruttura di intrusione distribuita. I dispositivi compromessi diventano nodi di una rete di proxy residenziali che conferiscono agli attaccanti un’anonimizzazione difficile da penetrare: il traffico malevolo emerge da indirizzi IP domestici o di piccola impresa, superando spesso i blocchi basati su reputazione IP.

Questo modello operativo è tipico di gruppi APT che necessitano di infrastrutture di staging durante la fase di ricognizione e di pivoting nelle reti bersaglio. La capacità di modificare le configurazioni DNS aggiunge una dimensione ulteriore: chi usa un router infetto espone tutte le proprie comunicazioni a potenziale intercettazione.

Indicatori di compromissione (IoC)

# IP di spreading iniziale
107.150.106.14
# Dominio C2 autenticazione
eixfi.ajb8.com  (/auth endpoint)
# CVE sfruttate
CVE-2013-3307   (D-Link DIR-850L - autenticazione bypassata)
CVE-2016-5681   (D-Link DIR-818LW - esecuzione remota di codice)
CVE-2025-11837  (dispositivi NAS - variante Go)
# Processi sospetti da verificare sul dispositivo
syswapd0h
syswapd0w
# Percorso da verificare
/tmp/bin/  (presenza di campioni malware)
# Nome progetto interno (da path nel codice Go)
Ary-Attack

Due righe per i difensori


Per chi gestisce reti con dispositivi edge, le azioni prioritarie sono: sostituire immediatamente i router D-Link DIR-850L e DIR-818LW con modelli supportati e aggiornati; applicare gli aggiornamenti firmware più recenti su tutti i dispositivi di rete perimetrali; modificare le credenziali amministrative di default; disabilitare le interfacce di gestione remota se non strettamente necessarie. A livello di monitoraggio, è opportuno inserire il dominio eixfi.ajb8.com e l’IP 107.150.106.14 nelle blocklist e verificare nei log di rete la presenza di connessioni Protobuf verso host sconosciuti su porte non standard.

La scoperta di AryStinger conferma una tendenza consolidata: i dispositivi IoT e i router SOHO a fine vita restano un vettore di attacco privilegiato per costruire infrastrutture di intrusione persistenti e difficili da attribuire. La prossima botnet potrebbe già essere nascosta nel router del vostro operatore ISP locale.


Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Cina espande la lista dei ban contro 10 aziende USA: Lockheed Martin è tra queste

📌 Link all'articolo : redhotcyber.com/post/cina-espa…

A cura di Carolina Vivianti

#redhotcyber #news #relazionibilaterali #cinaeusa #tensioneeconomica #commerciointazionale

Cybersecurity & cyberwarfare ha ricondiviso questo.

Troubleshooting su Linux: il metodo sistematico in 4 passi che risolve il 99% degli errori
#tech
spcnet.it/troubleshooting-su-l…
@informatica


Troubleshooting su Linux: il metodo sistematico in 4 passi che risolve il 99% degli errori


Chi lavora con Linux da anni conosce bene quella sensazione: un errore inaspettato blocca il server, un servizio smette di rispondere, un sistema che ieri funzionava perfettamente oggi presenta comportamenti anomali. La differenza tra un amministratore di sistema esperto e uno alle prime armi non sta tanto nella conoscenza enciclopedica dei comandi, quanto nell’adozione di un metodo sistematico di analisi.

In questo articolo descriviamo un approccio in quattro passi che consente di affrontare con metodo qualsiasi errore su Linux, riducendo drasticamente i tempi di risoluzione e gli errori per tentativi.

Il principio fondamentale: metodo prima di tutto


Il troubleshooting efficace non è una questione di fortuna o di esperienza accumulata a caso. È una disciplina che richiede di rallentare, osservare e procedere un passo alla volta. La tentazione più comune è quella di applicare subito la prima soluzione trovata online, modificando più variabili contemporaneamente. Questo approccio porta quasi sempre a peggiorare la situazione o, nella migliore delle ipotesi, a non capire quale modifica ha effettivamente risolto il problema.

Passo 1: raccogliere indizi e definire il problema con precisione


Il punto di partenza è una definizione precisa del problema. “Il server non funziona” è inutile ai fini diagnostici. “Il web server restituisce un 503 su /api/users dopo il deploy delle 14:30″ è un punto di partenza solido.

Le domande da porsi immediatamente sono:

  • Quando si è manifestato il problema per la prima volta?
  • Cosa è cambiato recentemente? (aggiornamento pacchetti, modifica configurazione, riavvio)
  • Il problema è riproducibile? In quali condizioni?
  • Qual è esattamente il messaggio di errore?

Un consiglio pratico spesso sottovalutato: se un’applicazione non si avvia correttamente, chiudete l’interfaccia grafica e lanciatela da terminale. La maggior parte delle applicazioni stampa i messaggi di errore sullo standard output o standard error, fornendo clue preziosi che l’interfaccia nasconde.

Catturate sempre l’output esatto dell’errore. Un kernel panic al boot, un prompt GRUB rescue, o un messaggio “device not found” contengono già le informazioni necessarie per risolvere il problema.

Passo 2: analizzare lo stato del sistema e i log


Con il problema definito, è il momento di esaminare lo stato corrente del sistema. Questa fase si divide in due parti: lo stato delle risorse e l’analisi dei log.

Stato delle risorse


Verificate se CPU, memoria, disco e rete sono in condizioni normali:

# CPU e memoria
top
htop

# Spazio disco
df -h
du -sh /var/log/* | sort -rh | head -20

# Rete
ip a
ip route
ping -c 4 8.8.8.8


Analisi dei log


Linux mette a disposizione strumenti potenti per l’analisi dei log. Con systemd, il comando principale è journalctl:

# Log del boot corrente con dettagli errori
journalctl -xb

# Log di un servizio specifico (es. nginx)
journalctl -u nginx --since "1 hour ago"

# Seguire i log in tempo reale
journalctl -f

# Filtrare solo gli errori
journalctl -p err -b


Per i sistemi che usano ancora i log tradizionali:
# Syslog generale
grep -i error /var/log/syslog | tail -50

# Log kernel
dmesg | grep -i "error\|fail\|warn" | tail -30

# Ricerca per intervallo temporale
journalctl --since "2026-06-22 14:00" --until "2026-06-22 15:00"


Non è necessario comprendere ogni singola riga dei log. L’obiettivo è identificare parole chiave come error, failed, segfault, permission denied, o il nome del servizio problematico nelle righe temporalmente vicine all’evento.

Passo 3: formulare ipotesi e testare una variabile alla volta


Con i dati raccolti nei passi precedenti, è il momento dell’analisi. Basandosi sui sintomi, sui cambiamenti recenti e sui log, si formula un’ipotesi sulla causa del problema.

Alcune regole pratiche:

  • Un segmentation fault → sospettare corruzione della memoria o libreria incompatibile
  • “Permission denied” → verificare permessi file, SELinux/AppArmor, ACL
  • “Device not found” al boot → UUID del disco modificato dopo aggiornamento o sostituzione
  • Servizio che crasha dopo un aggiornamento → provare il rollback del pacchetto

La regola d’oro è modificare una variabile alla volta. Se sospettate che un aggiornamento del pacchetto abbia causato il problema, fate il downgrade su un sistema di test prima di applicarlo in produzione. Questo permette di isolare la causa con certezza.

# Rollback di un pacchetto su Debian/Ubuntu
apt-cache showpkg nginx
apt-get install nginx=1.24.0-2

# Su RHEL/Rocky Linux
dnf downgrade nginx

# Verificare i file di configurazione con sintassi check
nginx -t
systemd-analyze verify /etc/systemd/system/myservice.service


La ricerca online è un validissimo alleato: incollare il messaggio di errore esatto in un motore di ricerca, nella documentazione ufficiale della distro, o in un AI assistant porta quasi sempre a soluzioni già documentate.

Passo 4: applicare la correzione e documentare


Una volta identificata la causa, applicare la correzione in modo controllato. Per le modifiche più invasive (sostituzione hardware, rebuild dell’initramfs, cambio configurazione kernel), è fondamentale:

  • Eseguire uno snapshot del sistema prima di procedere
  • Procedere un passo alla volta
  • Verificare dopo ogni modifica che il problema sia risolto e che nulla si sia rotto

Il passo finale, spesso trascurato, è la documentazione. Annotare cosa è andato storto, quali log hanno fornito i clue decisivi, e come è stato risolto il problema. Un ticket nel sistema di ticketing, un post nel blog interno, o anche una semplice nota in un file di testo possono fare la differenza quando lo stesso problema si ripresenterà tra sei mesi.

Strumenti essenziali da padroneggiare


Per mettere in pratica questo metodo in modo efficace, vale la pena avere familiarità con questi strumenti:

# Monitoraggio risorse
htop, btop, atop, glances

# Analisi disco e I/O
iotop, iostat, lsblk, blkid, smartctl -a /dev/sda

# Rete
ss -tlnp, netstat -tlnp, tcpdump, traceroute, mtr

# File di sistema
strace -p , lsof -i, inotifywait

# Analisi log avanzata
grep, awk, sed, logwatch, fail2ban-client status

Conclusione


Il troubleshooting su Linux non è magia: è l’applicazione di un metodo. Raccogliere i dati, analizzare i log, formulare ipotesi e testarle una alla volta, applicare la correzione e documentare. Quattro passi che, se seguiti con disciplina, permettono di affrontare con sicurezza qualsiasi problema, dai più banali ai più complessi.

La vera competenza si costruisce nel tempo, attraverso l’accumulo di esperienze documentate. Ogni errore risolto correttamente è una voce nel vostro archivio personale di soluzioni.


Fonte originale: Linux Troubleshooting: These 4 Steps Will Fix 99% of Errors – LinuxBlog.io


Cybersecurity & cyberwarfare ha ricondiviso questo.

Soldi Tuoi - Il gioco da tavolo di sole carte che ti fa scoprire, giocando, come funzionano risparmio, investimenti e indipendenza finanziaria.

Nessuna lezione, nessun manuale: solo strategia, fortuna e qualche risata.

@giochidatavolo

giocosoldituoi.com/

#GiochiDaTavolo #SoldiTuoi #NicolaBorzi

Cybersecurity & cyberwarfare ha ricondiviso questo.

AryStinger: la botnet che trasforma router D-Link in armi silenziose per attacchi globali


AryStinger è una nuova botnet scoperta da XLab che ha compromesso oltre 4.000 router D-Link obsoleti trasformandoli in proxy per attacchi di ricognizione e intrusione globali. Sfrutta vulnerabilità vecchie di anni e comunica via Protobuf cifrato con XOR — un'infrastruttura invisibile per APT e cybercriminali.
The media in this post is not displayed to visitors. To view it, please go to the original post.

I ricercatori di XLab (Qianxin) hanno scoperto AryStinger, una botnet precedentemente sconosciuta che ha compromesso oltre 4.000 router obsoleti in tutto il mondo, trasformandoli in proxy silenziosi al servizio di attori malevoli. A differenza delle classiche botnet DDoS, AryStinger è progettata per il ricognizione e il supporto alle intrusioni — un’infrastruttura invisibile concepita per penetrare reti aziendali e governative.

Scoperta e timeline dell’operazione


Il 12 marzo 2026, il sistema di threat awareness di XLab ha rilevato l’indirizzo IP 107.150.106.14 che diffondeva un campione ELF con zero detection su VirusTotal, sfruttando due vulnerabilità datate: CVE-2013-3307 e CVE-2016-5681. Il campione, implementato in C, prendeva di mira router D-Link DIR-850L e DIR-818LW — dispositivi giunti a fine vita, privi di patch e ancora ampiamente diffusi in ambito SOHO.

Il 26 aprile è comparso un secondo campione correlato, questa volta scritto in Go e rivolto a dispositivi NAS, sfruttando CVE-2025-11837. Il percorso nel codice sorgente del campione Go rivela il nome del progetto interno: Ary-Attack — un dettaglio che ha consentito ai ricercatori di attribuire le due famiglie alla stessa operazione.

Architettura e capacità operative


AryStinger converte i dispositivi infetti in “executor” telecomandati, capaci di eseguire un insieme ricco di operazioni su richiesta del C2:

  • Scansione di rete: port scanning, identificazione dei servizi, enumerazione di sottodomini — attività tipiche della fase di ricognizione pre-intrusione.
  • Proxying e tunneling: il device infetto instrada traffico malevolo verso destinazioni terze, mascherando l’origine reale dell’attaccante.
  • Esecuzione di comandi arbitrari sul sistema.
  • Modifiche DNS: la botnet può alterare le configurazioni DNS del router per intercettare il traffico web degli utenti connessi.
  • Payload multi-linguaggio: supporta l’iniezione di payload scritti in Go, Java e Python, garantendo flessibilità operativa.
  • Canali di accesso persistente via dropbear (SSH) o gs-netcat.

Le comunicazioni con il server di comando e controllo avvengono via HTTP/HTTPS, con traffico serializzato tramite Protobuf e cifrato con XOR — una scelta che garantisce compattezza e una certa difficoltà nell’ispezione del traffico.

Distribuzione geografica e target


La telemetria di Qianxin mostra che la distribuzione delle infezioni è geograficamente concentrata: Corea del Sud (48,5%), Cina (31,8%), Svezia (6,4%), Malesia (3,5%) e Singapore (2,5%). La forte prevalenza asiatica suggerisce che il deployment iniziale sia stato mirato su mercati dove i router D-Link di fascia bassa hanno avuto larga diffusione e dove la sostituzione dei dispositivi a fine vita avviene con ritardi.

Il targeting di NAS oltre ai router nella seconda fase dell’operazione indica un’evoluzione verso dispositivi con maggiore capacità di elaborazione e connettività persistente — ideali per operazioni di lunga durata che richiedono stabilità dell’infrastruttura proxy.

Perché AryStinger è diversa dalle botnet tradizionali


La distinzione fondamentale di AryStinger rispetto a botnet come Mirai o AISURU è l’obiettivo operativo: non DDoS né mining di criptovalute, bensì la costruzione di un’infrastruttura di intrusione distribuita. I dispositivi compromessi diventano nodi di una rete di proxy residenziali che conferiscono agli attaccanti un’anonimizzazione difficile da penetrare: il traffico malevolo emerge da indirizzi IP domestici o di piccola impresa, superando spesso i blocchi basati su reputazione IP.

Questo modello operativo è tipico di gruppi APT che necessitano di infrastrutture di staging durante la fase di ricognizione e di pivoting nelle reti bersaglio. La capacità di modificare le configurazioni DNS aggiunge una dimensione ulteriore: chi usa un router infetto espone tutte le proprie comunicazioni a potenziale intercettazione.

Indicatori di compromissione (IoC)

# IP di spreading iniziale
107.150.106.14
# Dominio C2 autenticazione
eixfi.ajb8.com  (/auth endpoint)
# CVE sfruttate
CVE-2013-3307   (D-Link DIR-850L - autenticazione bypassata)
CVE-2016-5681   (D-Link DIR-818LW - esecuzione remota di codice)
CVE-2025-11837  (dispositivi NAS - variante Go)
# Processi sospetti da verificare sul dispositivo
syswapd0h
syswapd0w
# Percorso da verificare
/tmp/bin/  (presenza di campioni malware)
# Nome progetto interno (da path nel codice Go)
Ary-Attack

Due righe per i difensori


Per chi gestisce reti con dispositivi edge, le azioni prioritarie sono: sostituire immediatamente i router D-Link DIR-850L e DIR-818LW con modelli supportati e aggiornati; applicare gli aggiornamenti firmware più recenti su tutti i dispositivi di rete perimetrali; modificare le credenziali amministrative di default; disabilitare le interfacce di gestione remota se non strettamente necessarie. A livello di monitoraggio, è opportuno inserire il dominio eixfi.ajb8.com e l’IP 107.150.106.14 nelle blocklist e verificare nei log di rete la presenza di connessioni Protobuf verso host sconosciuti su porte non standard.

La scoperta di AryStinger conferma una tendenza consolidata: i dispositivi IoT e i router SOHO a fine vita restano un vettore di attacco privilegiato per costruire infrastrutture di intrusione persistenti e difficili da attribuire. La prossima botnet potrebbe già essere nascosta nel router del vostro operatore ISP locale.

reshared this

WhatsApp e crimeware: la convergenza tra malware, social engineering e strumenti leciti


@Informatica (Italy e non Italy)
File VBScript malevoli distribuiti via messaggi diretti, tramite account WhatsApp violati, abusano di software RMM legittimi per ottenere persistenza e controllo dei sistemi compromessi. Ecco come mitigare i rischi legati al social

Cybersecurity & cyberwarfare ha ricondiviso questo.

Ecco perché i marchi di tablet da disegno non collaboreranno sui driver FLOSS per Linux

"Devo scusarmi perché oggi ho parlato di nuovo con il nostro team tecnico e abbiamo deciso di non procedere con il progetto del driver Linux in questo momento"

davidrevoy.com/article1154/why…

@informatica

Graphics Upgrade for Nintendo Entertainment System


The media in this post is not displayed to visitors. To view it, please log in.

Modern video game consoles rarely have expansion ports, but in the 80s and 90s it was practically guaranteed. With the speed that hardware was advancing it made sense to build in some way to expand a system’s capabilities throughout its lifespan, like the memory port in the Nintendo 64 or the Sega CD and 32X attachments for the Sega Genesis. Some were ultimately unused as well, like the port under the Super Nintendo or, arguably, the interesting way that [decrazyo] figured out how to add graphics capabilities to the original Nintendo Entertainment System.

The basis of this upgrade is the fact that the Picture Processing Unit (PPU) on the NES has four pins that are grounded. These four pins tell the NES to display the background color if the pixel is transparent. Since they’re normally grounded, this means the NES can only display a limited background image, but there’s no reason these pins must be grounded. By using a second PPU configured to output graphics information and wiring it to these four pins on the first PPU, the NES can be given all kinds of new abilities, such as adding parallax effects to backgrounds, rendering more sprites, and showing more colors in the backgrounds.

Of course, the hardware requirements for this will require a donor NES to get the second PPU as well as the necessary memory chip for it, and we don’t recommend tearing apart perfectly good retro consoles for experimentation if it can be avoided. Presumably, you could use this open-source NES hardware alternative instead. But for those with the parts and the gumption, creating a demo or adding graphics features to homebrew games using this second graphics chip is within reach.

youtube.com/embed/V2kaV_m4iNU?…


hackaday.com/2026/06/22/graphi…

FortiBleed e una lezione dura da imparare


@Informatica (Italy e non Italy)
Il leak di oltre 73.000 credenziali relative ad apparati Fortinet esposti o malconfigurati, di cui oltre 1200 italiane, accende nuovamente i riflettori sullo stato del panorama cyber italiano.
Source

L'articolo proviene dal blog zerozone.it/cybersecurity/fort…

Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: I took a look at the history of using export controls to limit the proliferation of cyber capabilities.

From the Crypto Wars of the 1990s to limit the spread of PGP, to the Wassenaar Arrangement to stop spyware flowing out of Europe, and now powerful AI models, I argue that this approach mostly does not work.

techcrunch.com/2026/06/19/encr…

reshared this

MSYS2 and the No-Fuss Way to Get More GNU Into Your Windows


The media in this post is not displayed to visitors. To view it, please log in.

As great and streamlined as the Windows desktop experience is, one area where it’s at best disappointing and at worst rage-inducing is when it comes to its command line interface (CLI) offerings. In Windows 9x/ME this could be excused by the fact that it was essentially just a dressed-up MS-DOS CLI experience, but on Windows NT-based OSes no such excuse exists.

Yet even after Microsoft finally acknowledged the shortcomings of the cmd.exe shell by 2006, they then proceeded to go their own way with PowerShell, industry standards be damned. Especially for those of us who have no beef with the UNIX/BSD/Linux CLI experience and the joys of shell scripting, this insistence was disappointing. Simultaneously, everyone from OS X/MacOS to Haiku were happily offering a familiar CLI environment alongside POSIX compatibility.

Although Windows NT OSes were POSIX compliant, they never offered a suitable shell along with it, nor any of the other things you’d expect in a modern-day BSD, Haiku or Linux CLI environment. In a recent article by my esteemed colleague Al Williams, these sore points were somewhat addressed as far as basic CLI tools go, but the issue goes obviously much deeper than just the basic userland tools. Which is where MSYS2 comes into the picture.

Defining The Problem


When one says that they’d like a ‘Linux shell on Windows’, it can be hard to pin down exactly what this means. As Al noted in his article on CoreUtils last week, there are solutions like Cygwin that add a translation layer between Windows and Linux-ish code and offer a basic shell experience, but what if you really want to have a full Linux-like shell experience including support for common POSIX tools and libraries, as well as typical tooling like make and gcc?

Microsoft’s CoreUtils package gets you a GNU userland-like experience, but that’s arguably a small part of the whole issue. The reason why over the years I drifted away from Linux tools ported to Windows – as well as bailed on WSL, WSL2, Cygwin and full-fat VMs – is due the amount of friction these added when all that I wanted was to use a Bash-like shell for day-to-day tasks and general software development. For all intents and purposes I wanted to pretend that I was just on a modern Linux distro like Arch without having to fire up some special application with significant overhead or waddle over to one of my systems that have Linux installed.

This means a GNU-style userland, basic POSIX compatibility, being able to run shell scripts, having access to a package manager like on BSDs/Linuxes/Haiku/etc., ideally all in a way where it blends quite seamlessly into the overall Windows GUI experience. Essentially the laziest and most off-the-shelf experience possible, if you want.

This is where a full-fat VM is obviously too heavy and restricted, while WSL(2) also carries too many of the VM-related flaws with it, as it’s too much trying to be Linux instead of integrating with the Windows experience. The ideal solution here would probably feel more like the standard terminal on Haiku.

The MSYS2 Solution


With MSYS2 you can use the same pacman package manager you’d use on Arch/Manjaro to fetch packages. You’re also using a regular Bash shell and the only major hurdles you’re likely to run into concern limitations with low-level tools like Valgrind and some Windows-related quirks that the MSYS2 developers can’t do too much about because Microsoft. Internally it’s still based on Cygwin, so you can count on a similar level of compatibility, but without fuss.

For day-to-day use it’s a very familiar Linux-like experience for especially software-development purposes and common shell-based shenanigans like automation tasks and running a range of tools such as ffmpeg and yt-dlp, both of which are of course readily available from the package repository. In this sense MSYS2 adds a terminal and CLI environment that blurs the lines between BSD/Haiku/Linux and Windows, just the way us cross-platform developers like things, as this way you can use the same scripts and same know-how and muscle-memory across terminals and TTYs.

Perhaps the only negative here is again due to MSYS2 being not fully integrated into Windows, resulting in e.g. binaries compiled within an MSYS2 environment relying on shared libraries that are not on the Windows system path. This can be worked around by copying all the DLLs into the binary folder, or doing system path things, but it’s one of the reasons why I do distribute binary builds for Windows of my OSS projects that are compiled using NMake and MSVC.

The MSYS2 Environments


When you first install MSYS2, the most important thing to learn are the distinctions between the various MSYS2 environments. This is the first thing you see after happily installing MSYS2, finding yourself staring at a list of various terminal options, as summarized below. Over the years a number of these environments have been retired, in particular the 32-bit environments, but also the MinGW64 environment that used to be the primary one until Windows 10 added the Universal C Runtime (UCRT).

The MSYS2 environments page provides a lot more detail, but the brief summary is that you should just use the UCRT terminal. It builds upon the MSYS environment just like the other options, essentially setting up a number of defaults, with some of these listed in the above table. Although you can use the Clang environments, these aren’t nearly as mature or full-featured, so your mileage may vary there.

Development Features


My basic software development workflow involves Notepad++ to write code and a Makefile, and the use of an MSYS2 UCRT terminal to run make, along with gdb, grep and utilities such as ldd for happy-fun debugging purposes. When I do embedded development that targets e.g. STM32, I can fetch the entire GCC-based toolchain for ARM Cortex-M via pacman and use that in exactly the same way as I would in a Linux-based terminal or TTY.

I have always found doing such development things the ‘Windows way’ to be rather tedious and cumbersome, having spent considerable time in the past using environments like Visual Studio and other IDEs such as Code::Blocks. While any approach can be made to work, just being able to use the same shell scripts, same gdb configurations, and the same Makefiles. across FreeBSD, Linux, Haiku, and Windows saves a lot of time and effort as you never have to duplicate effort.

MSYS2 Limitations


As alluded to earlier, MSYS2 doesn’t integrate perfectly in Windows as it is still just a third-party application. It also only covers userland, so kernel-level drivers and tools like Valgrind will require a full-blown Linux system. However, unless I’m doing some crazy involved profiling or debugging I’ll generally just use Dr. Memory on Windows, which works the same as Valgrind and also has packages for Linux and MacOS.

Whether it’s a limitation or not I’m not entirely sure, but stdout in MSYS2 Bash also sometimes does seem to have trouble outputting where Bash or similar on BSD/Haiku/Linux does not, which is an issue that I still need to diagnose in more depth one day to file a ticket for. That said, having created issue tickets for the MSYS2 (packages) project in the past has at least made it clear that its developers are quite responsive and fairly tame.

These minor niggles aside, I’m quite grateful to the MSYS2 project for allowing me to have both the solid Windows GUI experience and also have my heavily Arch-inspired CLI cake with pacman icing.


hackaday.com/2026/06/22/msys2-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

A new edition of my weekly cyber newsletter, ~ this week in security ~, is out. Leading this week: Anthropic's AI ban wasn't ever really about a jailbreak, Ozempic maker gets hacked (twice), Apple kneecaps a privacy feature, a secret society's members were exposed, and find out how the UK's social media law, which pissed everyone off, was announced, denounced, and already potentially trounced.

Read online: this.weekinsecurity.com/this-w…

Sign up for the weekly newsletter: this.weekinsecurity.com


this week in security — june 21 2026 edition


~ ~

THIS WEEK, TL;DR


U.S. government's Anthropic ban wasn't really about an AI jailbreak
Axios ($), TechCrunch ($): Well that blew up… More than a week after the Trump administration used its export control powers to effectively ban Anthropic from offering its cybersecurity focused Mythos and Fable models, they're still largely offline. What initially erupted over cybersecurity fears after the White House took umbrage with an alleged Amazon-discovered jailbreak in Anthropic's latest AI models quickly turned out to be largely "personality clashes" between Trump and Anthropic, per Axios ($). The White House also seems to want a resolution to the jailbreak issue, which experts say isn't possible to fully remediate. Dozens of security researchers and experts have since called on the government to pull its export restrictions to allow Anthropic to offer its models again. So far, no dice. Anthropic has since dispatched a team to Washington, D.C. to negotiate with Trump officials, but we're not likely to see any change in positions here for the time being amid the impasse, and it's not known for how long this might drag on. Tech Policy Press said the quiet part out loud, that the "climate is one of a cloud of suspicion that senior officials are picking favorites based on personal and political factors." Infosec legend Bruce Schneier also has thoughts.
More: Luta Security | TechCrunch ($) | Axios ($) | The New York Times ($) | Wired ($) | The New Stack

'FortiBleed' bug affects thousands of Fortinet firewalls, hackers reportedly cracked admin passwords
DoublePulsar: Security researcher Kevin Beaumont is filling in the knowledge gaps because Fortinet's response to its customers getting hacked has been (predictably) crap. Meet FortiBleed, a new mass-hacking campaign targeting Fortinet firewalls belonging to big corporations around the world. There are at least 1,000 known compromised organizations so far out of a suspected 75,000 total internet-facing firewalls. A hacking crew appears to have scanned the internet for these firewalls, somehow logged in (it's unclear exactly how), exported the firewall configs, and then later unscrambled the hashed admin passwords offline. This allows the hackers to breach the firewalls and break into the victim's networks. CloudSEK also has a really good report on this campaign as well. Beaumont has IOCs, and the excellent folks at GAYINT have a list of affected Fortinet devices, so check if your organization is a victim. CISA also has a hardening guide for Fortinet customers. Expect more from this ongoing (albeit rumbled) campaign.
More: The Register | Ars Technica | @IFIN | @GossiTheDog | @ransomwaresommelier | @shadowserver
a sample of data shown in a screenshot containing sensitive domain, Fortinet firewall and password information relating to customers around the world. Fortinet firewalls only produce this kind of sensitive data when they're in extreme distress.
Ozempic maker Novo Nordisk hit twice by separate hacking campaigns
DataBreaches.net: Journalist Dissent Doe reports not one, but two hacking campaigns have hit Danish pharmaceutical giant and Ozempic maker Novo Nordisk of late. One gang stole a ton of pseudonymized health data of clinical trial patients, but it's not clear if the data will ever stay fully private if the key used to scramble the data is ever leaked. An entirely separate group, about two weeks later, stole gigabytes of AI-related data, source code, credentials, and more. The groups demanded respectively $50M and $25M, but neither got paid. Novo's negotiator allegedly strung the hackers along to give the firm time to prepare for a public disclosure. (I bet the negotiator got paid pretty well, though.) Dissent Doe has a great run through in both stories about the state of Novo's security, in some cases as told by the hackers themselves, who were critical of the company's posture. Meanwhile: Cardiac equipment firm iRhythm said this week that it was hacked, with patient data stolen. The company didn't say how many people are affected.
More: DataBreaches.net | Reuters ($) | HelpNetSecurity | MedTech Dive | The Register

U.K. social media law announced, denounced, and potentially trounced amid possible change in U.K. government
The Guardian: Governments generally only roll out disastrous policies when they're in extreme distress or when their politicians are on a hideous losing streak. The U.K. is there, and is attempting to roll out a social media ban for kids under 16, following Australia's semi-unsuccessful effort to roll out its own law late last year. Even the kids are like, "this makes no sense." (But of course they'd say that; many of them are evidently smarter than our politicians these days.) This may also include bans on VPNs, per the U.K. tech minister. It's a staggeringly bad idea, but the BBC News ($) tries to make sense of it all. As you can imagine, much of it will rely on scanning your driver's license or passport for access. And yet none of this might matter if newly minted MP Andy Burnham becomes U.K. prime minister after an anticipated upcoming leadership battle among the ruling Labour Party. This is because the U.K. is a parliamentary system that allows leaders to change with relative ease (unlike other places 😑), which is why the U.K. is about to have its fifth prime minister in four years. Make that make sense, kids. More thoughts by @tjheffernan and Signal's Meredith Whittaker via Bloomberg ($).
More: GOV.UK | Wired ($) | EFF | Politico EU | NPR | @hypervisible

~ ~

PLEASE SUPPORT THIS NEWSLETTER!

~this week in security~ is my weekly cybersecurity newsletter supported by readers like you. Please consider signing up for a paying subscription starting at $10/month for access to exclusive articles, analysis, and more.

Or, you can submit a one-time tip to show your support!

Subscribe to support this newsletter

~ ~

THE STUFF YOU MIGHT'VE MISSED


Spy agencies using bulk data to snoop on targets
Financial Times ($): Advertising intelligence, aka "Adint," is now one of the major sources of government surveillance, according to a survey of European spy agencies. Buying access to huge datasets containing people's browsing and location data is sometimes far easier for the spy agencies than tapping undersea cables and sifting through ungodly amounts of intercept traffic. Using ad-blockers is a good way to combat public data collection.

Some health providers are recording your mental health care visits
The Markup: A horror story from The Markup investigating how medical providers, like Kaiser, are recording patient interactions — including mental health sessions — using "ambient listening," which is code for "listen to everything and feed it into an AI model for processing." You can (and should be able to) opt-out of this recording but as noted, it's increasingly making patients feel uncomfortable and wanting to change doctors.

An elite secret society is exposed after a data leak spilled its members
Straight Arrow News: A Peter Thiel-founded secret society of elite members that allegedly exists for fostering off-the-record discussions *pinches bridge of nose and sighs relentlessly* can't even seem to keep its members' information secret, because its website exposed dozens of their email addresses and phone numbers. The list includes celebrities, politicians, journos, and more, per @crimew.gay. More via Wired ($).
maia arson crimew post on Bluesky: "Both datasets were obtained due to insufficiently secured systems that were openly leaking data, no security mechanisms were bypassed and no "advanced hacking" took place. I verify all source data sent to me and it's provenance before using it in research or passing it along to other journalists."
Apple is about to kneecap its Hide My Email privacy service
Arseniy Shestakov: For no good (or obvious) reason, Apple is about to make its email hiding feature, Hide My Email, less effective by moving users' masked email addresses from @icloud.com domains (which all customers use) to @private.icloud.com, making it far easier for websites and apps to block anonymous users from signing up. I asked Apple why it changed this but didn't get back to me. (*makes chicken clucking noises*)

How residential proxy networks power hacker and crime groups
Wall Street Journal ($): Want to know more about how hackers hide in your router (and also apps and cracked video games) and hijack that access as a funnel for cybercrims' bad activity? Here's your primer on residential proxy networks, the backdoor software that powers them, and why they're a risk to confidential information. Plus! Brian Krebs digs into one major residential proxy provider and the botnet it allegedly (heavy wink) runs, thanks to millions of hijacked Android TV boxes.

~ ~

OTHER NEWSY NUGGETS


Knicks data nicked: The ShinyHunters' hackers leaked some 45GB of data stolen relating to the Knicks and Madison Square Garden, where the team just played, including "risk" score data about high-profile attendees, per 404 Media ($). Meanwhile, Have I Been Pwned reports retail giant JCPenney and fashion outlet Ralph Lauren also didn't pay the hackers after they had data stolen by the same group, nor did Kodak nor Council of Europe pay. (via HigherEd Dive, GovTech)

Not so sweet sugar cyberattack: Queensland-based Mackay Sugar, Australia's second largest sugar producer, was hacked, forcing the shutdown of at least two mills. The hack prompted the company to ask farmers to keep crops in the ground for longer. It's unclear if that'll affect the collective harvest. A hacking group called The Gentlemen (narrator voice: they are not) took credit. (via ABC.net.au, The Register)

Joomla bug sparks alarm: A maximum severity 10/10 bug in Joomla's content management system, used by an estimated 1% of the web, has patched a bug actively under attack by hackers, per the software maker. The bug allows unauthenticated access and execution of PHP code, so that's… not great. Update today. (via Widget Factory, CISA, @IntCyberDigest)

Trump's Pulte takes spy agency reins: Another political mess is bubbling over in the U.S. capital as President Trump decided to dig in on Bill Pulte as his administration's part-U.S. spy chief, part-federal housing boss, and part-Trump's personal attack dog (but actually though). As such, Pulte took office as the acting U.S. director of national intelligence, much to the chagrin of both parties. Meanwhile, Trump said he won't pass the FISA renewal bill (even though it's nowhere near close to being resolved) because lawmakers won't pass his absolutely insane voter ID bill under the guise of Trump trying to steal another election. It's all very messy, but our neighborhood natsec cyberscribe @dustinvolz explains the s...hituation atThe New York Times ($). (via @atrupar.com)

Time is a flat circle, spyware edition: Human Rights Watch found Bulgaria-based surveillance vendor Circles sold its spyware to countries with atrocious records of human rights, like Bahrain and the UAE. Circles sells Pixcell (for tracking calls, messages, and data) and Landmark (tracks location). The EU just can't seem to stop its countries exporting spyware to the world. If only it actually tried to begin with! (via Bloomberg ($), The Record)

Canada gets legal anti-botnet kibosh order: Canadian spy agency CSIS was granted approval by a court to take down botnets… two years ago, following a request by the agency to "remove the compromised devices from Canada." The ruling was made public this week in a barebones filing, but as Risky.biz notes, it's probably China-related. The FBI used similar court orders in the past to take down botnets, too, but also remove the malware code from routers and servers. (via The Canadian Press, CityNews)

Klue app compromised: Klue, a market intelligence company that makes the Battlecards integration for Salesforce customers, was compromised (Klue noindex'd its blog post, hiding it from search engines). This breach allowed hackers to hijack those integrations and steal customer data. A new extortion gang called Icarus took credit for the hack.A bunch of customers are affected, including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. (via Dark Reading, Bleeping Computer, DataBreachToday)

~ ~

THE HAPPY CORNER


It's a corner, it's got happy stuff, it's the happy corner. And it's got all that we need to relax after a busy week of news.

To the kids facing a social media ban today, well… at least you didn't have to rely on using an Excel spreadsheet on a Nokia 9210 to send text messages to your boo. (I fear nobody under the age of 30 will get this reference and if that's the case, I'm gonna go find a nice quiet corner to just crumble into dust.)
Dr Chris Burden post on X: "Under 16s messaging each other on Excel post the social media ban," followed by a screenshot from a Nelly-Kelly Rowland music video from the 2000s featuring a still of a typed-out text message saying "WHERE YOU AT?" on an Excel spreadsheet on a Nokia 9210 phone.
I will admit, I got a little hooked on this secrets-finding game. Find the exposed tokens, credentials, and other exposed sensitive data in this data leak simulator.

Be careful out there, folks. Things are getting desperate among AI-fueled CEOs. Please, please use our sh*tty AI products, they beg. Will someone think of the executives?
James Hawkins post on Bluesky: "seriously be careful out there everyone i had 2 Microsoft Copilot licenses in my car, and someone broke in and left 4 more," followed by a photo of a smashed car window.
And lastly this week. Thank you so much to everyone who contributed to last week's shout-out to a special cause, Project Sunshine, a nonprofit that my partner Jordan and I are involved with that helps to raise funds so that kids with medical challenges can enjoy much-needed playtime. We were just blown away by the support and love from you. We raised our goal and then some! If you're reading this on the weekend, there's still a few more hours before the Play-A-Thon closes for this season, but if you can spare a few bucks to donate, it will make all the difference to the kids that you help to support. Thank you again, really; it means so much.

Got good news to share? Get in touch! this@weekinsecurity.com.

~ ~

CYBER CATS & FRIENDS


This week's cyber cat is Meech, who can be seen h… Zzzz…. Z..z zz… zzz… Zz… *shhh* sleeping softly with his head on a… keyboard?! …Zzz…. Z.. Zz…zz.. must be exhausted after a busy day hacking. Z.. zz…. z….. back to snoozing for you… *psssts quietly* Thanks so much to Mike B. for sending in…!
Meech is an orange kitty who can be seen asleep, with his head resting on the side of a computer keyboard.
🐈 Keep sending in your cyber cats! 🐈‍⬛ Got a cat or a non-feline friend? Send me an email with their photo and name and they will be featured in a later newsletter! I always appreciate an update if you've sent in before!

~ ~

SUGGESTION BOX


And that's all there is for this week. Thank you so much for reading, subscribing, and supporting this newsletter (and blog!). That was... a bit of a busy one. I hope this edition gave you everything you needed to catch up.

If you like this newsletter, please do share it on your socials and whatnot! I really appreciate getting new readers in and word-of-mouth is one of the best ways to do that.

And, if you have anything you want to share for the newsletter, including suggestions and feedback, please drop me a note any time.

As a short programming note from me, there will be no newsletter next week! I'll be away in New England for a few days with Jordan; she's always wanted to go up to Maine, so we're going to drive north and disconnect from the world. I'm back the week after for July 5, with the latest edition of ~this week in security~ to mark a special milestone.

Logging off for now... take care, and catch you soon.

Back in a fortnight,
@zackwhittaker

Reading this online? Get ~this week in security~ by email


a weekly cybersecurity newsletter by Zack Whittaker, plus analysis and blogs. All the news you need to know. No slop.

Subscribe
Email sent! Check your inbox to complete your signup.

No spam. Unsubscribe anytime. This newsletter does not use email open or link trackers.


reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Heads up, Gizmodo has been compromised by some #ErrTraffic affiliate to. Inject is in main response.
ErrTraffic C2 cdnpro-987[.]xyz (Resoved via #EtherHiding)
PS Payload domain cdnportal-us[.]xyz (dynamic PowerShell command URI path)
PowerShell downloads a 16MB encrypted 7z file, checks if 7z is installed and otherwise downloads it to unpack the file and run the contained EXE. The EXE will do some profiling (including refresh rate) and if passes, will drop #NetSupportRAT and run it.
NetSupport C2 178[.]16[.]55[.]191.

TA also has a Mac payload configured, but it seems broken at the moment and ask for a password of some zip file when executed 🤷

Note: ErrTraffic is a ClickFIx-as-a-Service, so other compromised sites can lead to other malware from other affiliates.


Don't look now, but it seems Gizmodo's homepage is now serving up a Clickfix attack.

Basics of the Click-Fix exploit, which causes a pasted URL to fetch malware via Windows Powershell.

krebsonsecurity.com/2025/03/cl…

#clickfix #gizmodo


reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Whoa. @pypi monthly download counts increase 19.8% since March 2026 - **163.8 billion** total downloads in May 2026

Thanks to #ClickHouse for producing this newsletter: clickpy.clickhouse.com/report/…

reshared this

Rokarolla, il banking trojan Android che punta al controllo totale dello smartphone


@Informatica (Italy e non Italy)
Si chiama Rokarolla la nuova famiglia di malware Android che si distingue per le sue avanzate capacità di compromissione e controllo remoto dei dispositivi mobili: progettato per massimizzare la persistenza sul dispositivo compromesso,

Cybersecurity & cyberwarfare ha ricondiviso questo.

Un accenno di resoconto, molto personale, dell'evento a tema "Luna" che si è svolto sabato 20 giugno in osservatorio.

stardust.blog/2026/06/una-nott…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Anthropic's Mythos AI broke into almost all #NSA classified systems in hours
securityaffairs.com/194016/ai/…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

L’Agenzia delle Entrate al centro di una truffa “Adattiva”. Scopriamo cosa sta circolando in Italia

📌 Link all'articolo : redhotcyber.com/post/lagenzia-…

A cura di Chiara Nardini

#redhotcyber #news #cybersecurity #hacking #phishing #agenziadelleentrate #certagid

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

SiderAI and MaxAI Chrome Extensions Expose 10 Million Users to Full Browser Compromise
#CyberSecurity
securebulletin.com/siderai-and…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

HazyBeacon APT Campaign Weaponizes AWS Lambda to Hide Command-and-Control Traffic
#CyberSecurity
securebulletin.com/hazybeacon-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

GentleKiller: Inside the Ransomware Framework Disabling 400+ EDR Security Products
#CyberSecurity
securebulletin.com/gentlekille…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

AutoJack: A Single Malicious Web Page Can Hijack Your AI Agent and Execute Arbitrary Code
#CyberSecurity
securebulletin.com/autojack-a-…

A VBScript campaign distributed through WhatsApp deploying RMM software


The media in this post is not displayed to visitors. To view it, please log in.

In June 2026, we observed a malware campaign distributing malicious VBScript files through direct messages in WhatsApp. The campaign affected users across multiple countries and territories, including Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia and Vietnam, with the highest number of victims observed in Malaysia. At the time of writing this article, the campaign is still active.

Analysis shows that the campaign primarily targets users of WhatsApp Desktop and WhatsApp Web. The threat actor uses deceptive file names masquerading as business and financial documents to persuade recipients to download and execute the attachment. Once executed, the VBScript initiates a multi-stage infection chain that ultimately results in the installation of legitimate Remote Monitoring and Management (RMM) software, enabling remote access to the victim’s system.

Overview of the WhatsApp-based VBScript infection chain
Overview of the WhatsApp-based VBScript infection chain

We came across a number of social media posts reporting that the malware was being distributed by the users’ contacts. The messages contained only the malicious attachment and did not include any accompanying text. One account sent the same attachment to multiple contacts from their list.

WhatsApp messages containing the malicious VBScript file observed across multiple accounts. Source: alleged victims' posts on social media
WhatsApp messages containing the malicious VBScript file observed across multiple accounts. Source: alleged victims’ posts on social media

Based on evidence collected from multiple victims through social media reports and submitted samples, we can conclude that the threat actor had gained access to several WhatsApp accounts and used them to distribute the malicious VBScript files to contacts on the compromised users’ contact lists. At the time of writing, the exact method used to compromise these WhatsApp accounts remains unknown.

Social engineering through financial-themed file names


Analysis of the samples revealed that the threat actor relied heavily on social engineering through the use of deceptive file names designed to appear as legitimate business and financial documents. The file names frequently referenced invoices, account statements, debt notices, payment records, and bank statements.
Examples of file names include:

  • Financial Reports.vbs
  • Debt confirmation.vbs
  • Statement of Debt(30K).vbs
  • Outstanding Payment List.vbs
  • Account Statement.vbs
  • Debt Statement.vbs
  • Billing Statement (2).vbs
  • Promissory_Note(b).vbs

Several file names were also localized into different languages, including Portuguese, French, German, and Malay. Examples include:

  • Extrato de Conciliação.vbs
  • Aviso de dívida.vbs
  • Le formulaire de demande le plus récent.vbs
  • Bitte füllen Sie das Formular für Umsatzsteuer-Nullsatz-Verkäufe aus.vbs
  • Penyata bank.vbs
  • Sila semak bil anda.vbs

The use of multiple languages further suggests that the campaign may be targeting victims across different geographic regions.

In addition, the VBScript samples contain extensive comments and metadata intended to mimic legitimate Microsoft Windows Update components. Many of these comments are written in Chinese and include references to Windows Update modules, certificate validation, system integrity checks, and deployment-related functionality. The screenshot below shows an example of the Windows Update–themed comments and Chinese-language annotations embedded within one of the analyzed scripts.

Windows Update–themed and Chinese-language comments observed across multiple Stage 1 VBScript variants
Windows Update–themed and Chinese-language comments observed across multiple Stage 1 VBScript variants

Delivery of the initial VBScript file


Analysis of telemetry collected from the systems where the malware was executed, conducted together with the dynamic analysis of the sample, showed that the VBScript is launched through Windows Script Host (WScript.exe), which subsequently retrieves and executes additional VBScript components required for the later stages of the attack.

Two user interactions are needed to initiate the infection chain. When the user first clicks the attachment in either WhatsApp Desktop or WhatsApp web, it is downloaded to their machine. To launch the app, they need to open it.

In WhatsApp Desktop, the malware is executed directly within the application by clicking once more the file icon or by choosing the option “Open” in the chat. The process tree analysis shows that WScript.exe is spawned by WhatsApp.Root.exe. The executed script was observed within WhatsApp Desktop’s attachment storage directory, with the following command line:
"C:\Windows\System32\WScript.exe" "C:\Users\<username>\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\Sessions\<session_identifier>\Transfers\<YYYY-MM>\financial reports(s).vbs"
This process relationship confirms that the malicious VBScript was executed directly from the WhatsApp Desktop client.

In contrast, when the attachment is accessed through WhatsApp Web, to launch the malware, the user should open the downloaded file from the Downloads folder or through the browser’s download history. In the first case, the malware’s parent process will be explorer.exe, while in the second, it will be executed by the browser where the web app was opened.

Technical analysis

Stage 1: Initial VBScript execution


The first stage of the infection chain is a VBS or VBE file delivered through WhatsApp. Although multiple variants of the scripts were observed, their core functionality remains consistent: the script creates a working directory under C:\Users\Public\Documents\, downloads two additional VBScript payloads from a remote infrastructure, and executes them using Windows Script Host.

Across the observed variants, the working directory is created using randomized names such as Temp_<random> or MSUpdate_<random>. Some variants also configure the directory and downloaded files with hidden and system attributes, likely to reduce visibility to the user during execution.

Example of the code generating a random working directory and configuring it with hidden and system attributes
Example of the code generating a random working directory and configuring it with hidden and system attributes

The scripts employ several obfuscation techniques, including string concatenation, encoded VBScript, randomized variable names, and large amounts of junk content. One notable variant employs even heavier obfuscation than the other samples. The script reconstructs object names, file paths, utilities, and URLs through character-by-character string concatenation.

Example of an obfuscated Stage 1 VBScript variant.
Example of an obfuscated Stage 1 VBScript variant.

Several variants copy curl.exe and bitsadmin.exe into the working directory and rename them using DLL-like filenames before downloading additional VBS files.

Example of the Stage 1 downloader logic using renamed Windows utilities and multiple download mechanisms to retrieve additional VBS files
Example of the Stage 1 downloader logic using renamed Windows utilities and multiple download mechanisms to retrieve additional VBS files

The downloaded files are commonly staged using misleading file extensions before execution. For example, some variants download files using PDF or TXT extensions and then change them to VBS before launching them with wscript.exe. Other variants download the secondary VBScript payloads directly.

Despite differences in infrastructure, file names, and obfuscation methods, all observed variants ultimately perform the same function: downloading and executing two secondary VBScript payloads that continue the infection chain.

Stage 2: Execution of secondary VBScript payloads


Following execution, the Stage 1 VBScript downloads and launches two additional VBScript files from attacker-controlled infrastructure. One script attempts to modify Windows User Account Control (UAC) settings, while the other downloads and executes a ZIP archive containing the installation package for a RMM software.

VBS script 1: UAC configuration modification


First Stage 2 scripts were observed attempting to modify Windows UAC behavior.

Stage 2 VBScript repeatedly attempting to modify the ConsentPromptBehaviorAdmin registry value
Stage 2 VBScript repeatedly attempting to modify the ConsentPromptBehaviorAdmin registry value

As shown in the figure above, the script repeatedly executes an elevated registry modification command targeting the following registry key:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
The command is launched using the ShellExecute method with the runas verb, causing Windows to request administrative privileges before the registry change can be applied. Its goal is to set the ConsentPromptBehaviorAdmin registry key value to 0, thus enabling administrative actions without displaying a consent prompt to the user. The script attempts to apply this registry change in a loop with short delays between executions, likely to increase the chances that the setting will be successfully modified if administrative privileges are granted by the victim.

VBS script 2: ZIP download and script execution


The second VBS script downloads a ZIP file, extracts it and executes a script to start the RMM installation.

Similar to the Stage 1 downloader, the Stage 2 downloader creates its own working directory under C:\Users\Public\Documents\, commonly using randomized folder names such as Sys<random>, Data<random>, or a random numeric value. In most cases, the hidden attribute is assigned to this folder. The script then downloads a ZIP archive from attacker-controlled infrastructure, extracts its contents, and executes an embedded setup1.vbs script.

Stage 2 downloader creating a hidden working directory under C:\Users\Public\Documents
Stage 2 downloader creating a hidden working directory under C:\Users\Public\Documents\

Similar to the Stage 1 downloader, the variants leverage multiple download mechanisms, including curl, bitsadmin, certutil, PowerShell, and direct HTTP requests.

Stage 2 downloader using multiple download mechanisms to retrieve the ZIP archive
Stage 2 downloader using multiple download mechanisms to retrieve the ZIP archive

Following a successful download, the archive is extracted using the Shell.Application COM interface. Most variants invoke the CopyHere method with flags intended to suppress user prompts and allow extraction to proceed without user interaction. The extracted setup1.vbs script is then launched through wscript.exe to proceed with the next stage of the infection chain.

Also, one variant additionally attempts to remove Zone.Identifier alternate data streams from extracted files prior to execution, likely to reduce security warnings associated with files downloaded from the Internet.

Example of the code responsible for ZIP extraction, Zone.Identifier removal, and execution of the next-stage VBScript
Example of the code responsible for ZIP extraction, Zone.Identifier removal, and execution of the next-stage VBScript

Stage 3: Installation of remote monitoring and management software


Besides the setup1.vbs script, the ZIP archive downloaded during Stage 2 contains a preconfigured ManageEngine Endpoint Central deployment package. Inside the archive are the files required to install and register the Endpoint Central agent, including the MSI installer, configuration files, certificates, and installation scripts.

Extracted Stage 3 Endpoint Central installation ZIP package
Extracted Stage 3 Endpoint Central installation ZIP package

The table below summarizes the purpose of each file contained within the deployment package:

FileDescription
DCAgentServerInfo.jsonEndpoint Central server configuration containing management server IP addresses and ports
DMRootCA.crtTrusted root certificate
DMRootCA-Server.crtServer authentication certificate
README.htmlEndpoint Central agent setup instructions
setup.batLegitimate Endpoint Central installer wrapper included in the package, not used by the malware chain
setup1.vbsMalicious launcher used by the threat actor to silently install the Endpoint Central agent
UEMSAgent.msiEndpoint Central agent installer package
UEMSAgent.mstCustom installation configuration settings for the MSI package

ManageEngine Endpoint Central is a legitimate enterprise management platform commonly used for software deployment, system administration, and remote support. Its remote administration capabilities make it attractive for abuse by threat actors seeking persistent access to compromised systems.

One interesting variant attempted to disguise the package as an income tax–related document. Instead of containing a legitimate tax document, the archive contained a VBScript file named “Income Tax Return Form.vbs” and accompanied by an instruction file designed to persuade the victim to open it. Analysis showed that the VBScript contained functionality similar to setup1.vbs, ultimately performing the same Endpoint Central installation process.

Tax document-themed VBScript lure and installation script
Tax document-themed VBScript lure and installation script

As discussed in Stage 2, the downloader ultimately executes a VBScript file named setup1.vbs. The script first verifies that the required installation files are present in the extracted folder and then attempts to relaunch itself with administrative privileges using the Windows runas mechanism before proceeding with the installation.

The setup1.vbs script verifying installation files and requesting administrative privileges
The setup1.vbs script verifying installation files and requesting administrative privileges

Once elevated, setup1.vbs silently installs the bundled ManageEngine Endpoint Central agent using msiexec.exe, applying the supplied configuration and certificate files. The installation is performed silently, preventing the user from seeing the Endpoint Central installation interface.

Endpoint Central agent installation via msiexec.exe
Endpoint Central agent installation via msiexec.exe

Analysis of the embedded DCAgentServerInfo.json configuration file revealed the following Endpoint Central management servers:

  • 202.61.160[.]208
  • 202.61.160[.]202
  • 202.61.160[.]201
  • 202.61.160[.]160
  • 202.61.160[.]137
  • 38.55.151[.]63

Notably, 202.61.160[.]201 had previously been observed as command-and-control infrastructure associated with ValleyRAT and Gh0st RAT activity. Although the overlap raises the possibility of the VBS campaign being linked to the operator of these known malware families, the available evidence is insufficient to confidently attribute the campaign to a known threat actor.

Victimology and attribution


Based on our telemetry, infections were observed across several countries and territories, including Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia, and Vietnam, with 80% of the victims located in Malaysia. The campaign primarily relied on malicious VBScript attachments distributed through WhatsApp and appeared to target individual users rather than specific organizations or industries. At the time of the analysis, no evidence suggested a focused targeting strategy, instead indicating a broad, opportunistic campaign aimed at consumers.

We were unable to confidently attribute this activity to a known threat actor or intrusion set. However, several artifacts observed throughout the campaign point to a possible Chinese-speaking threat actor.

Multiple VBScript samples contained comments, module descriptions, and execution notes written in simplified Chinese characters. These comments appeared consistently across different variants, suggesting that the scripts were likely developed or maintained by a Chinese-speaking operator.

We also identified infrastructure overlaps with IP addresses previously associated with ValleyRAT and Gh0st RAT activity. While these overlaps may indicate infrastructure reuse or shared hosting resources, they are not sufficient to establish a direct connection to any known threat actor.

Based on the available evidence, we assess with low confidence that the campaign was conducted by a Chinese-speaking operator. Additional investigation, infrastructure overlaps, or operational indicators would be required to support a stronger attribution assessment.

Conclusion


This campaign uses compromised WhatsApp accounts to distribute malicious VBScript attachments that ultimately install a preconfigured ManageEngine Endpoint Central agent on victim systems. Observed victims were located across multiple countries and territories, including Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia, and Vietnam, suggesting a broad and opportunistic campaign. Users should be cautious when receiving unexpected attachments through WhatsApp, even when they appear to originate from known contacts. Script and executable file types such as VBS, VBE, EXE, BAT, CMD, JS, and PS1 should not be opened unless their legitimacy has been independently verified.

IOCs

VBScript


c7f38cbb99c8b74fa0465293feeba700 Financial Reports.vbs
b7cd06c71465038b658a6dc1f273a507 Debt confirmation.vbs
9f13c7b8ba391b2f597874e54d310648 Electronic statement(A).vbs
993f4c0cadbc769a4b0ed62a918db58d Financial Reports(s).vbs
7f81c1bc8cfd588e8998968e2621456e Outstanding Payment List.vbs
7403cbcc5a9c32384d431856dc48fcc9 Statement of debt (4).vbs
68c16c46f8afb9e00bbaba0207fb0a46 Debt Note (2).vbs
66442f2457eca8f47385b1fb2c6fcab8 Statement of Debt(30K).vbs
6359e6236471cbe434d0ef4c42b7f879 Applicationform1.vbs
5b6bbcc06cf08cc99e1afeda486d42fb Extrato de Conciliação.vbs
5002eca748205d544618e3bd2dedc223 Statement of Debt(29K).vbs
4f0593e8e0e8fac49429e9b45ebf7fa1 Outstanding Payment List.vbs
4044e4b6471c9de7b0a4ba37d9d9df9a billing statement (2).vbs
20209b3a32769afc6a75694b8d8839dd Statement of Debt(A).vbs
0ba93109757776a44de9d8c88baa4963 Financial Reports(C1).vbs
02bb20455cc592a69c080abac770ce90 Le formulaire de demande le plus récent .vbs
6c39900d77dcba158e1d27c7619cb06d Outstanding Balance Sheet(A).vbs
dad708e050632a4280cabf98ac1376b7 Outstanding Balance Sheet.vbs
05d188f071d097f5b6bd8138749b4b14 Penyata bank.vbs
2c6f05f1f309d89b2236e6c8b59c88f9 Account Statement(13K) (2).vbs
3b1aba44dd3d9b6339b6f56e2f42034b Statement of Account.txt
d43fdaa1f0ee09d7e5f0f94ee9df7b6c Bitte füllen Sie das Formular für Umsatzsteuer-Nullsatz-Verkäufe aus.vbs
df4fa0369eaca5cec348be293890d4af Account Statement.vbs
63ac85195b73753333316a889cf5880f Statement of Account(O).vbs
74fd9f91fc93b6288b4fc253ea5b3e20 Sila semak bil anda.vbs
d06333c360b51456f427e616c3c5f8bd Sila semak bil anda.vbs
993f4c0cadbc769a4b0ed62a918db58d FinancialReportsS.vbs
1d94fbe9cab21278cc3f104bea334d08 Promissory_Note(b).vbs
9d9ac85765e4a818a3ccabe2cf4fef82 Debt Statement.vbs
6fb6a55424adfb61e31f06aef33273e5 dfjieya.vbs
f90ed4b2d0b67114aa89ddfed658e5c0 dfjieya.vbs
8c3322009b8982663c0cbecd9492e7eb 0lf.vbs
66705384a7ad81d14c34fc6c054a0ecf iowepv.vbs
8c6d9fc389ad3f20ccbc71d77eb39bfa btksfmsi.vbs
1a3cc75466ffb1971482f7abf7aabc3f home3.vbs
1c47c63e5ed25060d95359c57c77b107 zipats.vbs
31037a42ca048e06e69a78f55bc2eff5 1122.vbs
7f16449cd0c4862d1eadf8a5742bf09a payload_1.vbs
79ecd61b09b0f2d54b34586c916c4ec9 sac8.vbs
7849061c536a3efb05a56d504694e7e7 6oy.vbs
ddaffe9849f7f3c79f8804adb9a6b3d5 kof.vbs
d01cad98dd0d01b75e04e784953c5e2b sleestak_payload_1.vbs

Domains


temu.baskwms[.]top
invoice.msopsa[.]top
baoxis[.]cc
sdcwww.oss-ap-southeast-1.aliyuncs[.]com
baoyuw2s.s3.ap-southeast-1.amazonaws[.]com
sjdkjj23.s3.ap-southeast-1.amazonaws[.]com
xijkwm2.s3.ap-southeast-1.amazonaws[.]com
yifubafu.s3.ap-southeast-1.amazonaws[.]com

Attacker-controlled UEMS server IP Address


202.61.160[.]202
202.61.160[.]201
202.61.160[.]137
202.61.160[.]160
202.61.160[.]208
38.55.151[.]63


securelist.com/whatsapp-vbs-rm…

How social media bans can work


The media in this post is not displayed to visitors. To view it, please log in.

How social media bans can work
IT'S MONDAY, AND THIS IS DIGITAL POLITICS. I'm Mark Scott, and will be speaking on this panel about trust in digital services at the IAPP/Harvard Navigate conference in Portsmouth, New Hampshire this week. If anyone is around in Boston on June 25, drop me a line here to grab coffee.

— The United Kingdom became the latest country to propose a social media ban for children. If others follow suit, this is how such bans should actually work.

— One of Europe's top courts just blew a hole in liability protections for online platforms. It's the second time judges have upended this decades-old precedent in recent months.

— Digital industries added $18 trillion in market value over the last three years.

Let's get started:



digitalpolitics.co/social-medi…

SDS-Remote Brings Power-User Features to Siglent Scope


The media in this post is not displayed to visitors. To view it, please log in.

SDS-Remote

Many oscilloscopes have provisions to be connected to a computer and used remotely, but most of those interfaces are fairly rudimentary. To address this, [Winfried] has developed the SDS-Remote, a remote interface for the Siglent SDS 1000X-E series oscilloscopes.

The 1000X-E series oscilloscopes have both USB and network interfaces, and the SDS-Remote can use either (though the USB interface is still somewhat experimental). SDS-Remote allows for remote controlling the oscilloscope, capturing waveforms super handy as it lets you export a CSV file of the waveforms for further analysis. You can also capture screenshots of the scope through the web interface, making it much easier to compare waveforms as you’re working on a project. The built-in data logging lets you run long experiments and save out their results. The macro recorder lets you automate complex tests using SCPI commands and brings basic scripting to the interface without needing to run separate code. There’s also a mechanism to integrate an AI LLM to help translate common language into the correct scope configuration.

Thanks [Winfried] for sharing this awesome web interface for the oscilloscope no doubt it’ll be a welcome upgrade for those already remote controlling their Siglent scope. Head over to his GitHub page and check it out for yourself! Have you written any improved user interfaces for your equipment? Be sure to let us know what you’ve done so we can share with others who may find use in an interface that offers more than came with the product.

youtube.com/embed/sbQIYpyg1p4?…


hackaday.com/2026/06/22/sds-re…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation
securityaffairs.com/194004/hac…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

Homebrew is a masterpiece of software engineering. It nicely isolates packages in user-space, entirely skips the `sudo` bs of other package managers, and keeps the core OS clean. Dev tooling really doesn't get much better than this.

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Energy Security, Not Climate Goals, Is Now Driving the Clean Power Boom
L: oilprice.com/Alternative-Energ…
C: news.ycombinator.com/item?id=4…
posted on 2026.06.21 at 17:19:21 (c=0, p=3)

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Da grande voglio fare il #ninja!
Così mamma (mi manchi tanto) sarà felice che prendo un pezzo di carta =)

youtu.be/3R7c5OXNVho?si=yvKepG…