Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: After the UK government sent a secret legal request to access users’ encrypted iCloud data, Apple has reportedly filed a new legal challenge against it.

This is the latest in a legal fight that started early last year. Critics see these demands as a threat to Apple users worldwide.

techcrunch.com/2026/08/03/appl…

Child-Friendly Music Player Uses RFID


The media in this post is not displayed to visitors. To view it, please log in.

[David] has a young child who is clever enough to use a computer to play music, but he doesn’t quite want to hand over the mouse just yet. Thus, he set about building an electronic music player that could be operated in an altogether simpler fashion.

The build is based around an Arduino Nano — its job is to read RFID tags via an RC522 reader, with the tags themselves embedded in a series of small dolls belonging to [David]’s daughter. Upon reading the tag, the Arduino Nano chats over serial with a DFPlayer Mini module, which reads a playlist of MP3 files off of an SD card and plays them over a small 4 ohm speaker that [David] had laying around. It’s a simple build, with the components all neatly wrapped up in a handsome wooden case with a volume control and a skip button for if any one song becomes too annoying for a repeat listen.

We’ve featured other builds in this vein before, too. There’s something satisfying about a music player with such a simple interface—no delicate media to fiddle with, just pop the toy on top and get the playlist you were looking for. If you’re creating your own little musical builds at home, we’d love to see them on the tipsline.


hackaday.com/2026/08/03/child-…

Congratulations to the Frikkin Laser Winners!


The media in this post is not displayed to visitors. To view it, please log in.

Apparently you all love lasers just as much as we do. We put out a challenge to use, build, or otherwise abuse our favorite coherent light sources, and you responded. Some of the projects had been in the works for quite a while and were ridiculously polished, some were whipped together on the fly just for the contest, and we truly enjoyed both.

We only have three $150 DigiKey gift certificates to give out, though, so without further ado, we present to you…

The Winners


Our judges’ favorite project was [Jacob]’s CubeRaman, and it’s not hard to see why. A Raman spectrometer shines laser light at an object and catches the reflection, filtering all of the original laser wavelength out. What remains are photons that have interacted with electrons in the atoms that make up the target itself, and come back at a shifted wavelength. Comparing the spectrum of this Raman reflection with a database of known spectra tells you what it is made of.

This is by no means an easy project, but [Jacob]’s documentation, careful selection of parts to buy used and parts to build, coupled with a clever 3D-printed mounting system make it plausible for the home gamer. We love seeing out-of-reach science gear brought into reach, and we know we’ll be keeping an eye on this project in the future.

Next up, we had [Kyle Mayer]’s Measuring Microns with Lasers, which is a DIY laser rangefinder, but for measuring very small distances — under a centimeter — with precision. Like many laser optical rangefinders, this bounces a laser off the target and collects the light on a line sensor, using the angle at which the light returns to figure out how far the target is.

[Kyle]’s implementation uses three of these measurement heads and produces a reading that is precise down to 0.25 μm nearly 5,000 times per second. This puts it in league with devices that you have to request a quote for, so you probably don’t want to have to afford them.

And finally, an art project! [AJRussell]’s Glow Engine is a beautiful take on a familiar laser trick: shining a blue laser at glow-in-the-dark materials to leave persistent traces. Scan the laser over the phosphorescent screen, and you have something like a CRT, only in [AJ]’s case, a very very slow CRT.

The beauty here lies in the details. [AJ] chose high quality strontium aluminate for the glowing, and used high resolution encoders and the open-source SimpleFOC motor driver firmware to get the spots in the right place. Snippets of old hard drive platters make fantastic mirrors. All in all, a super implementation that we’re pretty sure looks even better in the real world.

Honorable Mentions


We always come up with a few honorable mention categories to give you all some inspiration. And it also gives us a nice excuse to feature some more sweet projects.

Lightshow


We wanted to see pretty displays of laser light. [Daniel Ross]’s Laser Oscilloscope 360 not only draws out pretty waveforms, but it does so in prime steampunk style. Both [Owen Trueblood]’s Laser Cyanotypes and [GRNCH]’s Scored: Laser Woodblock Prints flip the script, making beautiful images from lasers, but not the way we intended. Kudos.

DIY


We wanted to see what laser-involved projects you were building yourselves, from scratch. While we were shocked that we had no TEA laser entries, [Armin Bindzus]’s Versatile Laser Processing Machine more than made up for it. It’s a pulsed-laser do-everything machine that we’re absolutely jealous to see made real. And if you don’t think there’s some real laser DIY going on here, you’ve never maintained a q-switched diode pumped Nd:YAG laser.

With Remaining Eye


This was our catch-all category for doing basically anything else with lasers. It turns out that what you all mostly wanted to do was science. [Matt Venn] used a fast-rise-time laser driver to Measure the Speed of Light at Home, and got damn good results considering the 2 m baseline. [Tim] put together a 3D Printed Optical Cavity interferometer on a budget.

But it wasn’t all labcoats and pocket protectors. [WeldingRod1]’s Laser Bandsaw is basically as bad an idea as it sounds like it is. Please, please wear eye protection!

Thanks again to DigiKey for sponsoring the contest. We’re sure that our winners will find whatever they need for their next laser project.

2026 Hackaday Freaking Lasers Contest


hackaday.com/2026/08/03/congra…

Cybersecurity & cyberwarfare ha ricondiviso questo.

"𝗛𝗼𝘄 𝗺𝘂𝗰𝗵 𝗼𝗳 𝗥𝗲𝗱𝗔𝗖𝗧 𝗶𝘀 𝗮𝘂𝘁𝗼𝗺𝗮𝘁𝗲𝗱?"
101% human. And that's not a typo.

Marco Adolfo De Felice (founder, author of #SuspectFile) sat down with us to talk about the #RedACT H1 2026 report, on how ransomNews started, how we build the dataset.

@sonoclaudio.ransomnews.online@bsky.brid.gy

Ransomware in Italy: RedACT re...

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Da ascoltare la musica e pagare un concerto ce ne passa.. soprattutto se si tratta dei tuoi soldi! (..vedi che poi il Signor Baci ha ragione a voler disdire?)

Fake #Spotify payment, ne parlo sul mio #PacketHunters per Baited: blog.baited.io/2026/%f0%9f%8e%…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Treno con 450 persone a bordo investe due mucche ed esce dai binari: è successo in prossimità della stazione di Piana Bella, nel comune di Montelibretti (RM). È successo all'alba di oggi: i viaggiatori sono stati trasferiti su un secondo treno. Nessun ferito.

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

#AI Runs the Hack: Chinese Actor Automates Cyberattacks With #DeepSeek
securityaffairs.com/196544/ai/…
#securityaffairs #hacking

New File Manager is C64’s Answer to Norton Commander


The media in this post is not displayed to visitors. To view it, please log in.

Norton was always a PC company — Norton Commander, the file manager that launched a thousand clones, was only ever available for DOS, like the rest of the company’s offerings in those days. If they’d decided to port it to the C64, though, it would likely look a lot like [retro3872809] aka [Chicken 64]’s Multi Floppy Commander with Turbo, available on GitLab.

As you might be able to see on the screen shot above or in the demo video below, the application provides an 80-column interface with a split view to show a pair of floppies side-by-side. Not that you’re limited to two floppies, however. The software is happy to swap between all the drives on the bus, to the C64’s maximum of four. All four drives will be usable since the file manager lives on a cartridge.

All drive models are supported, though not all have turbo. As a file manager, it looks like it has the normal functionality you’d expect: renaming, copying, moving and deleting files and directories. You can also launch programs or print disk listings, assuming you have a printer attached to your Commodore.

Said Commodore perhaps needn’t be vintage, as they’re selling new ones again, but if you want a disk drive you may have to fix it yourself.

youtube.com/embed/c9GbLmYIrHg?…


hackaday.com/2026/08/03/new-fi…

Cybersecurity & cyberwarfare ha ricondiviso questo.

New, by me: Samsung has banned smart TV apps that enlist owners' internet connections into residential proxy networks, which are increasingly linked to cybercrime. Samsung told me it's also removing apps containing resproxy code.

This comes as new research by Mnemonic found Samsung promoted barebone apps as "editor's choice," which allowed outsieders to rent access to a Samsung smart TV's internet connection.

Read more: techcrunch.com/2026/08/03/sams…

Bypass for ad-blockers: web.archive.org/web/2026080312…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Modifiche alla viabilità: Strada Rocca Bruna e via di Ponte Lucano


Per consentire il proseguimento di due importanti interventi infrastrutturali nell’area di Ponte Lucano, sono state adottate alcune modifiche temporanee alla viabilità, finalizzate a garantire la sicurezza del cantiere e una gestione più ordinata della circolazione. La prima modifica riguarda via di Ponte Lucano, dove Acea Ato 2 sta eseguendo lavori sulla rete idrica. Le lavorazioni interesseranno direttamente la corsia di marcia in direzione via Nazionale Tiburtina e, poiché si svolgono sulla

Per consentire il proseguimento di due importanti interventi infrastrutturali nell’area di Ponte Lucano, sono state adottate alcune modifiche temporanee alla viabilità, finalizzate a garantire la sicurezza del cantiere e una gestione più ordinata della circolazione.

La prima modifica riguarda via di Ponte Lucano, dove Acea Ato 2 sta eseguendo lavori sulla rete idrica. Le lavorazioni interesseranno direttamente la corsia di marcia in direzione via Nazionale Tiburtina e, poiché si svolgono sulla sede stradale in un tratto caratterizzato da una carreggiata di dimensioni ridotte, è necessario riservare parte della strada al cantiere. Per questo motivo, dal civico 70 fino all’intersezione con via Nazionale Tiburtina, dalle ore 7.00 del 3 agosto alle ore 23.59 del 13 agosto 2026, e comunque fino al termine dei lavori, è istituito il divieto di sosta con rimozione forzata per tutti i veicoli, ad eccezione dei mezzi d’opera, ed è previsto il divieto di transito per tutti i veicoli con obbligo di svolta a sinistra in direzione via dei Canneti. La corsia di marcia da via Nazionale Tiburtina in direzione via di Ponte Lucano resterà invece regolarmente percorribile.

La seconda modifica interessa strada Rocca Bruna ed è una conseguenza dei lavori in corso su via Maremmana Inferiore, dove è in fase di realizzazione un nuovo impianto di raccolta delle acque pluviali, progettato per migliorare il deflusso delle acque meteoriche ed evitare il ricorrente allagamento dell’area di Ponte Lucano. La chiusura parziale della viabilità necessaria per questo intervento ha comportato una redistribuzione del traffico sull’intero quartiere di Villa Adriana. Il monitoraggio effettuato dopo l’entrata in vigore delle precedenti ordinanze ha evidenziato che su strada Rocca Bruna si è registrato un forte aumento del flusso veicolare, con ripetuti episodi di blocco della circolazione. Considerata inoltre la particolare conformazione della strada, che tra il civico 12 e il civico 42 non consente il doppio senso di marcia con gli attuali volumi di traffico, è stata disposta, dalle ore 8.00 del 3 agosto alle ore 23.59 del 10 settembre 2026, e comunque fino al termine dei lavori, l’istituzione di senso unico di marcia con provenienza da Largo Margherita Yourcenar e direzione via Maremmana Inferiore. Una misura temporanea che permetterà di mantenere più fluida e sicura la circolazione durante l’esecuzione dell’opera.

comunicacity.net/tivoli/2026/0…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#River #Bank obtained assurances from the attackers that the stolen data in the June attack was deleted
securityaffairs.com/196537/cyb…
#securityaffairs #hacking

Hacker Iran contro 30 aziende idriche Usa: la lezione del Minnesota per le infrastrutture critiche


@Informatica (Italy e non Italy)
CyberAv3ngers, il collettivo di hacker iraniani, avrebbe colpito 30 aziende idriche del Minnesota, mettendo offline queste infrastrutture critiche. Ecco perché il sospetto è caduto su exploit a cui si riferiscono

Cybersecurity & cyberwarfare ha ricondiviso questo.

Settimana prossima uscirà un video interessante per chi crea contenuti sul software #FOSS . È un video in collaborazione che ho promesso ormai più di un anno fa (non dimentico mai un video promesso).

Tra due settimane invece esce uno dei video più importanti del mio anno di divulgazione, il climax del lavoro che ho svolto nell'ultimo anno intero con sorprese finali. Di quest'ultimo sono particolarmente orgoglioso, perché tratta, condensato in una spiegazione, tutto il mio amore per #Linux , il #Software #OpenSource , e la mia passione per il #Developing e il #ProjectManagement .

Chiudiamo poi tra 3 settimane con una bella pausa estiva (piccolina) per poi riprendere a Settembre più carichi che mai! 💪🏻

#StayTuned

@gnulinuxitalia

The 16K Display that Ate Las Vegas


The media in this post is not displayed to visitors. To view it, please log in.

You may have a 4K television. Perhaps you have even bought an 8K screen, despite the shortage of things worth watching in 8K. A 16K display is, today, a rarity. But even when those eventually become commonplace, yours probably will not cover 14,900 square meters, rise 73 meters into the air, or wrap over your head and behind your peripheral vision.

That is approximately what happens inside Sphere in Las Vegas. The venue’s interior display is quoted as having a resolution of 16K by 16K and an area of 160,000 square feet, or about 3.7 acres. Unlike most enormous movie screens, it is not illuminated by a projector. The entire surface is a direct-view LED display: an immense, curved video wall assembled from tens of thousands of smaller pieces.

After seeing The Wizard of Oz at Sphere, however, the most interesting part was not simply the screen’s size. It was how thoroughly the screen could disguise itself.

Where Did The Theater Go?


Radio City or the Sphere? (It is the Sphere; photo courtesy [DP])Before the presentation began, the auditorium appeared to have a conventional architectural ceiling. Great orange ribs curved over the seating, while ventilation grilles, suspended loudspeakers, lighting fixtures, curtains, and video monitors completed the illusion. It looked like the Radio City Music Hall’s proscenium. Then the show started — and the apparent theater completely disappeared. The speakers, the TVs, even the stage.

The obvious first conclusion was that the LED surface must be optically transparent, allowing the audience to see the real roof behind it until the pixels illuminated. That explanation was attractive because Sphere’s audio system really is installed behind the display, and the surface must allow sound through it.

It was also, apparently, wrong. The only explanation that makes sense is that the ceiling, ribs, grilles, speakers, and monitors were already being displayed by the screen. It was like a holodeck impersonating a physical theater interior. When the Oz material began, the system simply replaced one complete visual environment with another.

That’s what happens when a display fills nearly all of your useful visual field. A normal screen announces itself with a bezel, a wall, or at least a clearly visible edge. Sphere’s display extends upward and around the audience, removing many of those references. Give the image credible perspective, texture, shadows, and familiar architectural details, and the brain accepts the pixels as a room.

The same effect makes the Oz landscapes seem less like scenes displayed in front of the audience and more like places into which the auditorium has been inserted. Of course, there are more special effects. For The Wizard of Oz, there is wind and smoke, along with paper leaves, flower petals, and foam-rubber apples that fall from the sky. All of this makes it even more immersive.

youtube.com/embed/hLSEgGwswbw?…

Not Your Standard 16K Monitor


Calling it “16K” is not exactly untruthful, but potentially misleading. Consumer display resolutions normally describe a rectangular raster. A 4K UHD television has 3840 by 2160 pixels, or about 8.3 million pixels. An 8K set has four times as many, at roughly 33 million.

A literal 16,384-by-16,384 image contains about 268 million picture locations, but that’s not how Sphere is built. Sphere describes its interior display plane as 16K by 16K, but that does not mean it is equivalent to a square desktop monitor with a neat, uniformly spaced Cartesian grid. It is a custom media surface with complex curvature and geometry, driven as one enormous canvas.

Sphere says the screen reaches 240 feet high and wraps up, over, and around the audience. SACO, the company responsible for the LED technology, describes the interior as the world’s highest-resolution LED screen and says it has more than 120 times the resolution of an HDTV.

youtube.com/embed/nQB_M2GumNo?…

Published numbers vary slightly depending on the source. One source describes approximately 64,000 SACO LED tiles, while structural contractor Seele refers to approximately 65,000 LED screens or frames. The difference may be terminology, rounding, or the boundary between the LED tile and its mechanical carrier. Either way, this is clearly not a single panel that arrived in the world’s largest shipping crate, but rather was built on-site.

The surface is assembled onto a precisely engineered secondary structure. Seele says it created 839 facet units containing approximately 45,500 custom structural components. Those facets establish the overall geometry and give the LED hardware suitable mounting points while maintaining alignment across the enormous screen wall.

In other words, the apparent smooth curve is made from many accurately positioned pieces. At the intended viewing distance, the facets and individual emitters merge into a continuous image.

Feeding The Beast

Foam apples rain down on the audience during one scene.
Building the display is only half the problem. The other half is getting a quarter-billion-pixel-class image onto it up to sixty times per second without tearing, losing synchronization, or pausing while somebody clears a buffering dialog.

The public description of the playback chain resembles a broadcast plant crossed with a high-end video wall. Pre-rendered content is kept on network-attached storage and streamed to dozens of 7thSense media servers. Each server produces 4K video at 60 frames per second, with the streams distributed using the SMPTE ST 2110 professional-media-over-IP standards. Pixel processors drive the appropriate regions of the display.

Hitachi Vantara says the storage system can deliver data at up to 400 GB/s with less than five milliseconds of latency. (At least it did for Postcard from Earth; it could be capable of more, for all we know.) The material is handled using 12-bit color and uncompressed 4:4:4 chroma sampling. That does not necessarily mean every show continuously consumes the maximum quoted bandwidth, but it provides some sense of the infrastructure needed to treat the whole venue as a dependable display rather than an interesting laboratory experiment.

Content also has to be geometrically transformed for the screen. An image that looks correct on a flat monitor would be badly distorted if copied directly onto the curved surface. The production pipeline therefore needs a detailed model of the display and the audience’s relationship to it.

youtube.com/embed/VSuSN_qfB0I?…

Stretching Oz Beyond The Frame


The Wizard of Oz presents an additional problem: the 1939 film was photographed for a nearly square 1.37:1 frame. Sphere’s interior is absolutely not 1.37:1 or even close.

Simply magnifying the original would waste most of the display. Cropping it to fill the screen would remove the actors and much of the composition. Instead, Sphere Studios expanded the film’s world beyond the photographed frame, using Google AI tools along with conventional restoration, compositing, animation, and visual-effects work.

The original photography remains central to the presentation, but scenery, skies, crowds, buildings, and environmental details extend far outside the old frame. Sphere says the project used AI to enhance characters and expand scenes while attempting to preserve the performances and familiar imagery.

youtube.com/embed/1ZTEajxD6EU?…

This is more complicated than expanding a still photograph. The additions must remain temporally consistent as the camera and characters move. A tree cannot change shape from frame to frame, and a newly invented Munchkin cannot grow an extra arm whenever the model becomes distracted. The generated material also has to survive at extraordinary scale, where a small artifact can become several meters wide.

Whatever one thinks about altering a classic film, it is difficult to imagine adapting this particular source material to this particular display without reconstructing substantial portions of the unseen world.

Of course, not everyone is thrilled. If you hated colorizing black-and-white movies, this will probably set you off. Even the original Star Trek got new digital effects.

What Happens When A Pixel Dies?


With roughly 64,000 or 65,000 LED assemblies, failures are inevitable. We couldn’t find much public information about Sphere’s exact maintenance procedure, but we can infer some probable scenarios from other large LED systems. Big systems generally report power, temperature, communications, and controller faults automatically. We would imagine that Sphere can do this, too. Then, technicians can also probably display red, green, blue, white, black, and low-gray test patterns while cameras or human observers look for dead, stuck, or miscalibrated pixels.

A single failed subpixel may be invisible from most seats during moving content. A stuck-bright pixel in a dark sky would be much more conspicuous, as would an entire failed tile or data branch.

Seele says the screen structure includes 229 accessible panels, suggesting that maintenance access was designed into the system rather than left to exceptionally adventurous climbers. A failed field-replaceable assembly could be swapped, repaired on a bench, and returned to the spare inventory.

The replacement would then need calibration. LEDs from different production batches — and LEDs of different ages — do not produce precisely identical brightness or color. A technically functional replacement could appear as a visible rectangle unless the controller corrected its red, green, and blue response, gamma, and low-level output to match its neighbors.

Curiously, this may be one of the hardest features to appreciate during a show: tens of thousands of modules are working together, yet the audience perceives no modules at all.

The Screen That Pretends Not To Exist


Sphere’s specifications are impressive, but resolution alone does not explain the experience. Spread 16K pixels across a screen tens of meters high and the pixel density is far below that of a phone. The system works because the pixel pitch, viewing distance, brightness, content, architecture, and human visual system were engineered together using a lot of science.

While the Wizard of Oz was an impressive feat, we hope they’ll bring us something like 2001: A Space Odyssey. Or maybe a triple feature with shorts from Star Trek, Star Wars, and Avatar. Sure, the rights to pull that off would take a team of lawyers, but we can dream, can’t we? What movie would you like to see on a giant screen like Sphere? Or would you only see an original production? Any of you out there work behind the LED curtain?


hackaday.com/2026/08/03/the-16…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Alle volte, la vita di un tecnico è veramente frustante! 😆😆

#redhotcyber #cybersecurity #hacking #hacker #infosec #infosecurity #quotes #meme #comica #vignette #citazioni #cybersec #sicurezzainformatica #malware #cybercrime #awareness #meme #memetime

reshared this

An analysis of incidents at Brazilian educational institutions


The media in this post is not displayed to visitors. To view it, please log in.


Introduction


Because of the amount of data that can be obtained and the high impact that successful attacks may have, educational institutions are frequent targets of cybercriminals. Both public and private schools and universities rely on software for managing personally identifiable information (PII) that is often insecure or insufficiently tested against known vulnerabilities. In addition, machines used by multiple people without accountability can be vulnerable to insider threats.

The complexity of academic environments amplifies this risk. Unlike corporate networks, educational institutions have to provide a network that supports students, professors, researchers, administrative staff, third-party contractors, and visitors. Each of these groups has different security requirements and access control levels, making it difficult to enforce consistent security policies. A security breach can have severe consequences since it may expose vast amounts of sensitive information, such as social security numbers (CPF in Brazil), addresses, phone numbers, and even parents’ names. Armed with this information, attackers can attempt phishing attacks and impersonate the victims in SIM swapping attacks, a common practice in Brazil.

In this article, we provide details about attacks on educational institutions in Brazil observed by our Global Emergency Response Team (GERT) since 2025. We share general statistics, common threats, initial access vectors, and the impact of such violations. Additionally, we present some interesting cases encountered by our team and the identified TTPs. Finally, we offer recommendations to help institutions protect themselves against future attacks.

Key findings and statistics


Our dataset encompasses incident response cases from January 2025 to June 2026. As the chart below shows, the majority of attacks targeted institutions in São Paulo state, Brazil’s most populous state and a significant center of economic and financial activity. We also had cases in Rio de Janeiro and Pernambuco.

Geographical distribution of incident response requests at educational institutions (download)

Of the customers who requested incident response, 60% were private institutions and 40% were public institutions.

Private and public institutions (download)

The most frequent reasons for requesting IR services were related to suspicious endpoint activities, encrypted files, and the presence of suspicious files.

Incident response request reasons (download)

High-severity incidents accounted for 40% of the total cases, while the remaining 60% were medium severity.

Distribution of incidents by severity (download)

The high-severity incidents were mainly related to ransomware attacks. Interestingly, private institutions were the most targeted by ransomware, while incidents in public institutions were mostly related to suspicious endpoint activity and privilege escalation attempts. The most common ransomware families found in our dataset were DragonForce and LockBit 3, whose builder was leaked back in 2022. By using the leaked LockBit builder with a valid privileged account, attackers can build variants capable of disabling defenses and erasing logs.

The most common initial access vectors included the use of valid accounts, exploitation of public-facing applications, and insiders.

Initial access vectors (download)

For privilege escalation, the attackers often relied on Potato variants (GodPotato, SweetPotato, and BadPotato).

We also observed attackers using tools like AnyDesk for remote access, PsExec for lateral movement within compromised infrastructures, and AV-killer malware to terminate the system’s defenses. The latter was mainly used in ransomware-related incidents.

These data reveal an interesting pattern in the threat landscape affecting educational institutions in the region. Many incidents were not caused by highly sophisticated techniques but rather by the abuse of common weaknesses such as valid accounts, exposed applications, and inadequate patch management, as well as the use of publicly available tools that are well-known to the adversaries. The prevalence of ransomware in private institutions suggests a stronger financial motivation, likely because attackers assume these organizations are more capable of paying for data recovery than public schools and universities.

Most attacks were discovered promptly and lasted from a few minutes to a couple of hours. However, technical incident response activities averaged 9.6 hours. This indicates that the impact caused by an incident often extends beyond the timeframe of the active attack, requiring extensive triage and analysis by the forensic investigators to fully restore operations.

One interesting fact is that we are still observing the use of Windows 10 in the infrastructures of educational institutions, even after Microsoft’s official end-of-support date of October 2025. In addition, we found that some customer organizations were using Windows Server 2016 without security patches and fixes. Using outdated and unsupported operating systems increases the attack surface of an infrastructure because attackers can exploit publicly available vulnerabilities to access vulnerable systems and expand their presence in the network. In addition, legacy operating systems may be incompatible with modern evidence collection tools, necessitating extra time and alternative procedures for forensic acquisition.

Obsolete systems in organizations (download)

Interesting cases

Case 01 – Leaked LockBit builder


In one case, we identified the use of a custom version of LockBit that was generated using the leaked builder. The ransomware was delivered to the organization’s infrastructure via a valid account that had been leaked. It encrypted the organization’s internal systems, including file servers and databases that stored student profiles and other data. There was no evidence of data exfiltration from the affected machines.

During our analysis of the LockBit sample, we were able to extract its configuration. Interestingly, it was configured without the impersonation and spreading options. This meant the attacker had to perform manual lateral movement to deploy the malware across the network.
"config": {
"settings": {
"impersonation": false,
"local_disks": true,
"network_shares": true,
"kill_processes": true,
"kill_services": true,
"set_wallpaper": true,
"self_destruct": true,
"kill_defender": true,
"wipe_freespace": true,
"psexec_netspread": false,
"gpo_netspread": false,

Further analysis revealed that the attacker used PsExec for lateral movement. By analyzing the Update Sequence Number (USN) Journal, we were able to identify .KEY files associated with PsExec that showed us the previously compromised machines used by the attacker.

After gaining access to the target machines, the adversaries deployed a batch script to disable the system’s defenses. Our analysis of this artifact showed that they had the administrative credentials to disable the EDR in place. In addition, the script enabled RDP, which gave the attackers remote access to the target. The listing below shows an excerpt of the script:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
netsh advfirewall firewall add rule name="allow RemoteDesktop" dir=in protocol=TCP localport=3389 action=allow
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableBehaviorMonitoring /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableOnRealTimeProtection /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableIOAVProtection /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableScriptScanning /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpyNetReporting /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SecurityHealth" /t REG_SZ /d "" /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{UUID}" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v ServiceKeepAlive /t REG_DWORD /d 0 /f
sc stop WinDefend
sc config WinDefend start= disabled
Finally, by cross-checking the Prefetch files, we were able to identify the precise dates of PsExecSvc.exe and LBB.exe (LockBit) execution. This revealed that the attacker established the initial connection to the analyzed machine around 5:30am UTC and ran LBB.exe for the last time at 10am UTC on the same day, resulting in an activity window of approximately four hours and thirty minutes. We were able to identify the extent of the compromise and the additional machines that required network isolation for further forensic analysis, containment, and remediation.

Case 02 – DragonForce deployed via AnyDesk


In another incident, we identified a compromised user account that the adversaries used to install the AnyDesk software to enable remote access. Although the attacker erased the system logs after encrypting the victim’s files, we were able to identify the ransomware execution event via the Prefetch and Amcache.hve files, which provided us with the SHA-1 hash of the sample.

Once we obtained the SHA-1 of the malicious artifact (named by the attacker as 1.EXE), we were able to confirm that it was a DragonForce variant. Even though the lack of evidence made the analysis more difficult, this case shows that forensic investigators must be prepared to identify information that the attackers missed or left untouched.

Case 03 – Python keylogger used by an insider


The third incident illustrates how a series of bad practices enabled an insider to collect passwords from other users inside the infrastructure. First, the customer contacted us stating that a machine was exhibiting strange behavior: files containing passwords were being created. We started with triage collection on one of the affected machines.

Evidence from the Program Compatibility Assistant (PCA) showed the execution of two suspicious files, Windows Host Widgets.exe and Windows Host Widgets_.exe, both located in the C:\Users\<user>\.vscode\dlo directory, where <user> represents a user account shared by everyone who uses the machine. The same artifacts were identified within the Amcache.hve file, and multiple executions were also confirmed by analyzing the Prefetch files. Another interesting source of evidence, UserAssist, confirmed that the threat actor also executed both EXE files by double-clicking on them.

MFT analysis showed that multiple log files named cacheX.txt were created in the previously mentioned directory, where X was a number that increased with each malware execution. We then analyzed the EXE files to confirm their behavior. Luckily, both proved to be the same Python script, which we could easily decompile.

As shown in the listing below, the script contains methods and strings with Portuguese names. It is capable of hiding the log files from view in Explorer. The developer also set a procedure to identify when the Caps Lock key was pressed, in order to record the correct passwords.
def get_base_path():
...

def encontrar_proximo_nome(base='cache'):
...

def set_file_hidden(filepath):
...
ctypes.windll.kernel32.SetFileAttributesW(str(filepath), FILE_ATTRIBUTE_HIDDEN)
...

with open(log_file, 'a', encoding='utf-8') as f:
f.write(f'\n\n--- Registro iniciado em {datetime.datetime.now()} ---\n')
set_file_hidden(log_file)
...

def is_capslock_on():
return bool(ctypes.windll.user32.GetKeyState(20) & 1)

...

def on_press(key):
...

def on_release(key):
...

def main():
with keyboard.Listener(on_press=on_press, on_release=on_release) as listener:
listener.join()

if __name__ == '__main__':
main()
This simple script did not implement any persistence or automated data exfiltration mechanisms. Therefore, the insider likely had to manually retrieve the generated log files containing the text typed by the victims. By revisiting the previously collected evidence, we identified USB connections around the same time as the script’s executions. This suggests that removable media was probably used to collect the generated keylogging logs from the environment. As a result of the investigation, the customer changed the passwords of all affected accounts. However, without additional evidence or footage, it was not possible to conclusively attribute the activities to a specific individual and take the appropriate disciplinary and legal measures.

Conclusions and recommendations


The incidents highlighted in this article demonstrate that Brazilian educational institutions face a diverse set of threats, ranging from ransomware operations to insider activity. In many cases, the attackers relied on valid credentials, exposed services, remote access tools, poor patch management, and insufficient endpoint hardening rather than advanced malware or new techniques. Based on these findings, educational institutions should prioritize controls that reduce the likelihood of account compromise and the impact of ransomware deployment. They should also improve forensic visibility after an incident.

Institutions should enforce the use of multi-factor authentication (MFA) for all publicly accessible services, especially VPNs, remote access portals, and email accounts. Since valid accounts were one of the most common initial access vectors observed in our dataset, MFA can significantly reduce the likelihood that stolen or reused credentials alone will compromise the entire environment. We also recommend periodically reviewing privileged accounts, removing unnecessary administrative permissions, and avoiding shared accounts, especially on machines accessed by multiple users, since this makes accountability extremely difficult.

Each user should have their own account, following the principle of least privilege to prevent unauthorized software execution. Additionally, it is advisable to restrict and monitor the use of remote access tools such as AnyDesk or TeamViewer. Unexpected installations or executions of these tools should be treated as high-priority alerts.

To minimize the impact of ransomware, educational institutions should improve their backup and recovery strategy. Backups should be isolated from the primary environment (preferably in more than one location) and tested regularly. Centralized logging, extended EDR telemetry retention, and proper time synchronization across hosts can also improve the ability to reconstruct an attack timeline and implement the necessary response measures.

The use of outdated systems increases the attack surface, so we recommend that organizations adopt an effective update and patch management policy. It is also important to raise security awareness, since users must understand the risks associated with credential sharing, unknown executables, and unauthorized software.

From a digital forensics and incident response (DFIR) perspective, the reviewed incidents demonstrate that effective incident response activities require correlating multiple forensic artifacts in order to reconstruct the attacker’s actions. Investigators should be aware of how to find information even when logs are missing. Many other artifacts are preserved and can be used for this purpose, such as Amcache, PCA, Prefetch, UserAssist, MFT, and USN Journal. The attackers may fail to erase all traces of their activity, so taking a broad forensic approach is of the utmost importance for determining the scope of the compromise and supporting containment and remediation actions.

Observed TTPs


The table below shows the observed TTPs in our dataset, including cases not detailed in this post.

TacticTechniqueID
Resource DevelopmentCompromise AccountsT1586
CollectionInput Capture: KeyloggingT1056.001
ExecutionSystem Services: Service ExecutionT1569.002
ExecutionHijack Execution Flow: DLLT1574.001
Privilege EscalationExploitation for Privilege EscalationT1068
Lateral MovementRemote Services: Remote Desktop ProtocolT1021.001
Command and ControlRemote Access ToolsT1219
ExfiltrationExfiltration over Physical Medium: Exfiltration over USBT1052.001
ImpactData Encrypted for ImpactT1486

securelist.com/incidents-at-br…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Gli USA si arroccano di nuovo: stop ai robot stranieri! La sicurezza nazionale prima di tutto

📌 Link all'articolo : redhotcyber.com/post/gli-usa-s…

Carolina Vivianti

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati


@Informatica (Italy e non Italy)
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per installare OWAReaper, una backdoor che sopravvive a reset password e reimaging. Colpiti enti

Gazzetta del Cadavere reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

#PNLD Confirms Data Breach Affecting #UK #Police and Justice Staff
securityaffairs.com/196525/dat…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

L'etichetta "generato dall'intelligenza artificiale" diventa obbligatoria nell'UE per le aziende

Le aziende che creano o utilizzano contenuti generati dall’intelligenza artificiale devono etichettarli chiaramente affinché gli utenti possano saperlo, come parte di una linea guida dell’UE implementata domenica.

euronews.com/my-europe/2026/08…

@aitech

reshared this

Arch Linux AUR colpito da un'altra ondata di malware

Dopo aver avuto a che fare in precedenza con una grande ondata di malware nell'Arch Linux AUR (Arch User Repository), un'altra ondata si è verificata mentre ero fuori a toccare l'erba (breve vacanza).

Lo sviluppatore Robin Candau ha osservato il 30 luglio:

"A causa dell'attuale afflusso di adozioni di pacchetti dannosi e di impegni di follow-up effettuati tramite l'AUR, l'adozione di pacchetti è attualmente disabilitata mentre gestiamo la situazione
Invieremo un follow-up non appena sarà possibile. Nel frattempo, sentitevi liberi di segnalare eventi o impegni di adozione sospetti che non sono stati ancora affrontati, e rimanete vigili!".

E in un post successivo nello stesso thread del 1° agosto:

"Per il momento abbiamo disattivato del tutto anche le spinte, mentre gestiamo la situazione. Ci scusiamo per l'inconveniente."

C'è anche un thread di persone che pubblicano vari pacchetti che sono stati colpiti.

gamingonlinux.com/2026/08/arch…

@GNU/Linux Italia

m3ss3dupbytes reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

@signalapp @AboutSignalNL

I just discovered that when you want to share your location using the Signal's 'share your location' feature, it sends a link of..... Google Maps 🥴

I could not find a way to change this to an (open standard) geolocation link.

- did I overlook a setting?
If not:
- why is Signal revealing it's user location to Google?
- why would Signal promote Google Maps?

#privacy #locationsharing

reshared this

in reply to Eelco Mulder 🇪🇺

there's an open feature request to remove gmaps in favor of OSM from _2019_

community.signalusers.org/t/us…

please add your votes to it!

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Californians' data deletion requests, DROP, become enforceable Aug. 1
L: nbcsandiego.com/nbc-7-responds…
C: news.ycombinator.com/item?id=4…
posted on 2026.08.02 at 18:16:34 (c=0, p=3)

reshared this

The global battle for AI, revisited


The media in this post is not displayed to visitors. To view it, please log in.

The global battle for AI, revisited
IT'S MONDAY, AND THIS IS DIGITAL POLITICS. I'm Mark Scott, and many of you (I hope) are on vacation. A lot has happened so far in 2026. With the summer lull upon us, this week's edition is updating a piece that I wrote for POLITICO in 2024 about the global race to control artificial intelligence.

It's not a like-for-like comparison. Back then, I was a tech reporter. Now, I'm a think tanker (and newsletter writer.) But the underlying question — about who will control the emerging technology for years to come — has not changed.

If anything, it's become even more complex.

Let's get started:



digitalpolitics.co/global-ai-g…

Andre123 reshared this.

Get a Remote Terminal With One Binary, One URL, and Zero Config


The media in this post is not displayed to visitors. To view it, please log in.

Launch a single static binary executable, send someone a QR code or URL (or failing that, text a numerical code or shout it across a room), and they’ll get an encrypted terminal in their browser. No VPN, no port forwarding, no firewall modifications, and no account setup required. It’s BitBang by [Rich LeGrand], and there is a lot to go through in this one.

The best part? It’s not actually limited to just firing off a terminal. It’s a whole open framework for establishing an encrypted peer-to-peer connection between two systems over WebRTC without needing either a trusted central authority, or any special network configuration.
The signaling server brokers the handshake, then has no further involvement. By design, it couldn’t see application data even if it wanted to. Click to enlarge.
Opening a remote terminal, transferring files, or accessing web apps on a remote machine’s network is done with bitbang-cli, an implementation of BitBang focused on providing simple, zero-config remote access.

Before we go on, we want to mention that BitBang does require a lightweight, trustless signaling server only to broker the initial connection, but more on that in a moment.

On the machine to be shared, one first downloads the binary. Easiest way to do that is to go to bitba.ng and download manually, or copy and paste the one-line installer to auto-detect one’s system, download the correct release, and verify the checksum.

After the binary is downloaded, simply run it in a terminal and receive a QR code to scan, a URL to copy & paste, or a numerical code if those are inconvenient. One the remote side, one accesses the signaling server and the connection is made — one gets a terminal on the target machine open in the browser tab, with added options for file sharing and accessing web applications on the target network.

The signaling server isn’t involved in authentication or encryption, and couldn’t see private data between the two ends even if it wanted to. Prefer not to use someone else’s regardless? Run your own local instance with bitbang-server.

Originally developed as an easy way to securely make telepresence robots reachable over the Internet with nothing more than a QR code, today it’s a whole framework.

It includes not just the remote-access tool mentioned above, but also a BitBang Octoprint plugin for cloud-free remote access to 3D printers, and bitbang-python is a library for turning local Python web applications into a URL that can be opened from anywhere.

We’re sure some of you are getting more than a few ideas from this. If it lets you bring a project over the finish line, let us know on our tips line.


hackaday.com/2026/08/03/get-a-…

Tyorgg reshared this.

E-mail aziendali: la sanzione privacy a Piaggio fissa nuovi limiti alla raccolta dei dati


@Informatica (Italy e non Italy)
L’Autorità Garante per la protezione dei dati, nella nota del 29 luglio 2026, ha reso noto di aver irrogato una sanzione di 460 mila euro alla Piaggio per raccolta sistematica delle e-mail dei dipendenti. Vediamo meglio, in ottica

Gazzetta del Cadavere reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

L'economia dell'intelligenza artificiale - L'intervista di SkyTG24 ad Alessandro Longo e Francesco Caio

Due spunti interessanti:
1. l'osservazione di Alessandro Longo sul fatto che tutto questo "miracolo tecnologico" non stia lasciando la minima traccia su un reale miglioramento della produttività delle aziende che lo utilizzano
2. la brama di Caio di mettere le mani sui dati dei cittadini italiani conservati nei database della pubblica amministrazione

youtu.be/vCqR8LVA04c

@aitech

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

L’AI cambia gli esami: la scuola deve ripensare la valutazione


L’intelligenza artificiale generativa mette in discussione il modello tradizionale di verifica scolastica. Il nodo non è solo impedire l’uso dell’AI negli esami, ma capire quali competenze valutare in una società in cui studenti e professionisti collaborano stabilmente con sistemi intelligenti

agendadigitale.eu/scuola-digit…

@aitech

@scuola

Questa voce è stata modificata (6 giorni fa)
in reply to Mic Pin

@grep_harder sono completamente d'accordo e ho notato che nella percezione dei genitori o almeno della maggior parte di loro, la scuola viene percepita come una realtà dal basso valore aggiunto, praticamente poco più che un kindergarten dove parcheggiare i bambini.

Basta vedere che ogni volta che c'è una riduzione di orario i genitori non sono incazzati perché i figli avranno un'ora di istruzioni in meno, ma solo perché gli tornano a casa un'ora prima

@aitech @scuola

Scuola - Gruppo Forum reshared this.

in reply to Mic Pin

in reply to Mic Pin

@grep_harder Io penso che nessuno meriti disprezzo, ne un insegnante, ne uno studente ne qualunque altra brava persona; però penso anche che un docente dovrebbe avere "autorevolezza", non "autorità". La differenza è che la prima parola indica essere un punto di riferimento riconosciuto e svolgere il ruolo di guida della classe, mente la seconda indica avere qualche forma di potere di comando sugli studenti, che a giorno d'oggi mi sembra alquanto anacronistico.

E riguardo al fatto che gli insegnanti sarebbero stati rimpiazzati da modelli offerti dai mass media, devo dire che mi sembra un po' ridicolo; parliamoci chiaro, chi è che idolatrerebbe il proprio professore? I giovani idealizzano modelli alternativi agli stereotipi della società ed è sempre stato così, non è una cosa degli anni 2020.

reshared this

in reply to Mic Pin

@grep_harder la scuola è una delusione. E la politica non aiuta: da un lato abbiamo i politici (di destra) che dicono "genitori troppo permissivi, genitori che insegnano ai prof come si insegna". Dall'altro gli stessi politici "educazione sessuale solo se i genitori danno il consenso".
Siamo passati dal prof che te le dava e i genitori che te le davano il doppio, all'estremo opposto.

reshared this

E-mail aziendali: la sanzione privacy a Piaggio fissa nuovi limiti alla raccolta dei dati


@Informatica (Italy e non Italy)
L’Autorità Garante per la protezione dei dati, nella nota del 29 luglio 2026, ha reso noto di aver irrogato una sanzione di 460 mila euro alla Piaggio per raccolta sistematica delle e-mail dei dipendenti. Vediamo meglio, in ottica

Cybersecurity & cyberwarfare ha ricondiviso questo.

#nerdystuff in pausa pranzo

#TraduttoreDaUfficio raccoglie 30 traduzioni dal "quello che vorresti scrivere" al "quello che scrivi davvero" in un'email di lavoro.
La guida di sopravvivenza per ogni casella di posta aziendale 📧

📧 thelanguagenerds.com/2022/30-translations-from-blunt-insults-and-angry-emails-into-professional-language-shared-by-this-tiktoker

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

La domanda di chip Nvidia supera l’offerta di 12 volte mentre i ricavi sono aumentati dell’85%

📌 Link all'articolo : redhotcyber.com/post/la-domand…

Silvia Felici

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Alleged #Żabka Breach Exposes Jira Data, Source Code, and API Keys
securityaffairs.com/196510/dat…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

Com’è fatta una piattaforma di sorveglianza digitale cinese

L'ha trovata un ricercatore qualche tempo fa: probabilmente è una demo ma contiene comunque una quantità enorme di dati

Leggi tutto: ilpost.link/ImMZeKUxpv

@informapirata

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

I Black Hacker usano le AI per attaccare le infrastrutture governative

📌 Link all'articolo : redhotcyber.com/post/i-black-h…

Luigi Zullo

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Spotting Emacs in the Wild


The media in this post is not displayed to visitors. To view it, please log in.

Emacs is one of the big classic text editors, right up there next to vi. It’s famous for its interface and its ubiquity across the *nix world. It’s such a core piece of software in the coding world that it has showed up a fair few times in popular culture—and [Ian Y.E. Pan] has collated some of those appearances.

Emacs played a role in The Social Network, the retelling of the origin story of Facebook (the social network everybody used to use). Notably, Mark Zuckerberg used the tool to slap together a script for scraping a website. It also appears in Tron: Legacy, Arctic Blast, and the tech TV comedy Silicon Valley—more than once, in fact.

Other appearances include comics, Japanese anime series Key The Metal Idol, and a few miniseries and documentaries to boot.

[Ian]’s list is unlikely to be exhaustive. Both because he hasn’t seen every movie or TV show ever made, and because you can make new content featuring Emacs references tomorrow if you so desire. Still, it’s fun to see some of the famous properties that have featured good ol’ Emacs.

Don’t hesitate to let us know if you happen to put together a similar list about vi. The tipsline is waiting.


hackaday.com/2026/08/03/spotti…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Russia is behind the recent hotel WiFi hacks
-Anthropic models also did the hacky-hacky
-npm adds publish-time malware scanning
-Coldcard hacked for $70m
-CyberCom to open Silicon Valley office
-Iran water hacks impacted seven states
-Wemix hacked again
-DNC falls for BEC scam
-Google pauses Google Earth genAI feature over disinformation fears
-Telco data breach reporting rules under assault again
-SMS blaster arrested in Malaysia

P: risky.biz/RBNEWS595/
N: news.risky.biz/risky-bulletin-…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

☕ CYBERBRIEFING — Lunedì 3 agosto 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

Cybersecurity & cyberwarfare ha ricondiviso questo.

Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing
securityaffairs.com/196486/sec…
#securityaffairs #hacking