FreeBSD DHCP Client Flaw CVE-2026-42511 Allows Root Code Execution via Rogue DHCP Server
#CyberSecurity
securebulletin.com/freebsd-dhc…
reshared this
reshared this
reshared this
Costruire un’app di conferenza AI con lo stack composable di .NET
#tech
spcnet.it/costruire-unapp-di-c…
@informatica
reshared this
reshared this
Governare le chiamate MCP in .NET con l’Agent Governance Toolkit
#tech
spcnet.it/governare-le-chiamat…
@informatica
reshared this
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Linux Kernel to its Known Exploited Vulnerabilities catalogPierluigi Paganini (Security Affairs)
Cybersecurity & cyberwarfare reshared this.
Differenze Nord - Sud (Italy)
Nell'estate del 2018 crolló il ponte Morandi. Nei mesi successivi furono controllati tutti i ponti italiani nel timore di crolli come a Genova.
A Capua fu chiuso il ponte "nuovo" sul Volturno (porta Roma) costruito dagli alleati alla fine della II Guerra Mondiale. Il traffico auto fu deviato sull'antico ponte romano ristrutturato.
Sono passati 8 anni, il ponte Morandi é stato ricostruito e quello di Capua é ancora chiuso.
@caffeitalia @feddit @notizie #news
like this
reshared this
313 Team: il gruppo filo-Iraniano che ha paralizzato Canonical con un DDoS estorsivo durante il lancio di Ubuntu 26
#CyberSecurity
insicurezzadigitale.com/313-te…
reshared this
The primary goal for attackers in a phishing campaign is to bypass email security and trick the potential victim into revealing their data. To achieve this, scammers employ a wide range of tactics, from redirect links to QR codes. Additionally, they heavily rely on legitimate sources for malicious email campaigns. Specifically, we’ve recently observed an uptick in phishing attacks leveraging Amazon SES.
Amazon Simple Email Service (Amazon SES) is a cloud-based email platform designed for highly reliable transactional and marketing message delivery. It integrates seamlessly with other products in Amazon’s cloud ecosystem, AWS.
At first glance, it might seem like just another delivery channel for email phishing, but that isn’t the case. The insidious nature of Amazon SES attacks lies in the fact that attackers aren’t using suspicious or dangerous domains; instead, they are leveraging infrastructure that both users and security systems have grown to trust. These emails utilize SPF, DKIM, and DMARC authentication protocols, passing all standard provider checks, and almost always contain .amazonses.com in the Message-ID headers. Consequently, from a technical standpoint, every email sent via Amazon SES – even a phishing one – looks completely legitimate.
Phishing URLs can be masked with redirects: a user sees a link like amazonaws.com in the email and clicks it with confidence, only to be sent to a phishing site rather than a legitimate one. Amazon SES also allows for custom HTML templates, which attackers use to craft more convincing emails. Because this is legitimate infrastructure, the sender’s IP address won’t end up on reputation-based blocklists. Blocking it would restrict all incoming mail sent through Amazon SES. For major services, that kind of measure is ineffective, as it would significantly disrupt user workflows due to a massive number of false positives.
In most cases, attackers gain access to Amazon SES through leaked IAM (AWS Identity and Access Management) access keys. Developers frequently leave these keys exposed in public GitHub repositories, ENV files, Docker images, configuration backups, or even in publicly accessible S3 buckets. To hunt for these IAM keys, phishers use various tools, such as automated bots based on the open-source utility TruffleHog, which is designed for detecting leaked secrets. After verifying the key’s permissions and email sending limits, attackers are equipped to spread a massive volume of phishing messages.
In early 2026, one of the most common themes in phishing emails sent with Amazon SES was fake notifications from electronic signature services.
Phishing email imitating a Docusign notification
The email’s technical headers confirm that it was sent with Amazon SES. At first glance, it all looks legitimate enough.
In these emails, the victim is typically asked to click a link to review and sign a specific document.
Phishing email with a “document”
Upon clicking the link, the user is directed to a sign-in form hosted on amazonaws.com. This can easily mislead the victim, convincing them that what they’re doing is safe.
The resulting form is, of course, a phishing page, and any data entered into it goes directly to the attackers.
However, Amazon SES is used for more than just standard phishing; it’s also a vehicle for a very sophisticated type of BEC campaigns. In one case we investigated, a fraudulent email appeared to contain a series of messages exchanged between an employee of the target organization and a service provider about an outstanding invoice. The email was sent as if from that employee to the company’s finance department, requesting urgent payment.
BEC email featuring a fake conversation between an employee and a vendor
The PDF attachments didn’t contain any malicious phishing URLs or QR codes, only payment details and supporting documentation.
Naturally, the email didn’t originate with the employee, but with an attacker impersonating them. The entire thread quoted within the email was actually fabricated, with the messages formatted to appear as a legitimate forwarded thread to a cursory glance. This type of attack aims to lower the user’s guard and trick them into transferring funds to the scammers’ account.
Phishing via Amazon SES is shifting from isolated incidents into a steady trend. By weaponizing this service, attackers avoid the effort of building dubious domains and mail infrastructure from scratch. Instead, they hijack existing access keys to gain the ability to blast out thousands of phishing emails. These messages pass email authentication, originate from IP addresses that are unlikely to be blocklisted, and contain links to phishing forms that look entirely legitimate.
Since these Amazon SES phishing attacks stem from compromised or leaked AWS credentials, prioritizing the security of these accounts is critical. To mitigate these risks, we recommend following these guidelines:
We recommend that users remain vigilant when handling email. Do not determine whether an email is safe based solely on the From field. If you receive unexpected documents via email, a prudent precaution is to verify the request with the sender through a different communication channel. Always carefully inspect where links in the body of an email actually lead. Additionally, robust email security solutions can provide an essential layer of protection for both corporate and personal correspondence.
ChatGPT finisce in tribunale: le chat diventano prove nei casi di omicidio
📌 Link all'articolo : redhotcyber.com/post/chatgpt-f…
A cura di Silvia Felici
#redhotcyber #news #chatgpt #intelligenzaartificiale #investigazioni #crimini #statiuniti #giustizia
Le conversazioni con ChatGPT stanno diventando una nuova tipologia di traccia digitale utilizzata dagli investigatori. Scopri di più su come l'intelligenza artificiale sta cambiando il volto della giustiziaSilvia Felici (Red Hot Cyber)
Cybersecurity & cyberwarfare reshared this.
@Informatica (Italy e non Italy)
Il gruppo "Islamic Cyber Resistance in Iraq 313 Team" ha lanciato un attacco DDoS prolungato contro Canonical coincidendo con il rilascio di Ubuntu 26, mandando offline Snap Store,
reshared this
The UK NCSC warns AI is speeding up vulnerability discovery, likely causing a “patch wave” of urgent software updates to fix exposed flaws.Pierluigi Paganini (Security Affairs)
Cybersecurity & cyberwarfare reshared this.
Pensare come un attaccante e dubitare come un filosofo! La nuova frontiera della Cyber
📌 Link all'articolo : redhotcyber.com/post/pensare-c…
A cura di Daniela Farina
#redhotcyber #news #sicurezzainformatica #cybersecurity #securitybydesign
La sicurezza informatica basata sulla filosofia di René Descartes e il suo metodo di dubbio per costruire sistemi sicuri e ridurre la superficie di attaccoDaniela Farina (Red Hot Cyber)
Cybersecurity & cyberwarfare reshared this.
A time domain reflectometer (TDR) is a useful tool to have for finding faults in a wiring harness. However, they don’t come cheap, putting them out of reach for many shadetree mechanics that like to work on their own cars. However, [László SZŐKE] has been exploring a neat way to build a similar device on the cheap.
Typically, time domain reflectometry involves shooting a short electric pulse down a wire, and listening for how long it takes to bounce back. The time depends on the length of the wire, so it can be used to determine the location of a break in conductivity. Unfortunately, these pulses move so fast that very fast, very expensive hardware is needed to make these measurements.
[László’s] technique relies on lower-tech hardware. Instead of sending a very short pulse down a wire, his rig uses a cheap C-Media USB audio device to send a 4 kHz or 8 kHz sine wave instead. Then, by listening to the reflection and measuring the phase shift, it’s possible to detect the distance to the end of the wire (or a break along its length). Some supporting hardware is required for protection’s sake, and to tune the setup for measuring shorter or longer cabling. However, with some smart software processing, [László] states that it’s possible to measure down to 1 cm resolution.
The idea is that this setup could prove particularly useful for automotive troubleshooting. If you measure a wire and the device reports a length of 30 cm, when you know the wire stretches several meters into the engine bay… you know there’s a break around 30 cm from your measurement point.
There’s still plenty of work to be done – for now, [László] is working on a new prototype that should have better performance when testing shorter cables. Still, we love to see this sort of out-of-the-box thinking put towards a common troubleshooting task. If you’re doing fun signal analysis work of your own, don’t hesitate to light up the tipsline.
Domani divento chef da milioni di visualizzazioni anche se non so cucinare E così domani divento chef da milioni di visualizzazioni anche se non so cucinare. Basta chiedere all'AI di scrivermi dieci ricette al giorno.Marco Camisani Calzolari
Cybersecurity & cyberwarfare reshared this.
Quando le AI trovano i bug: il futuro del bug hunting nell’era dell’intelligenza artificiale
📌 Link all'articolo : redhotcyber.com/post/quando-le…
A cura di Massimiliano Brolli
#redhotcyber #news #cybersecurity #hunting #intelligenzaartificiale #sicurezzainformatica
Scopri come le AI stanno rivoluzionando il bug hunting e qual è il nuovo ruolo del bug hunter nel futuro della sicurezza informatica. Leggi ora!Massimiliano Brolli (Red Hot Cyber)
Cybersecurity & cyberwarfare reshared this.
Bluekit is a new phishing kit with AI features, automated domain setup, and tools like spoofing, voice cloning, and 40+ attack templates.Pierluigi Paganini (Security Affairs)
Cybersecurity & cyberwarfare reshared this.
🚀 Gli speaker della RHC Conference 2026
📍𝗤𝘂𝗮𝗻𝗱𝗼: Martedì 19 Maggio con ingresso dalle ore 8:45
📍𝗗𝗼𝘃𝗲: Teatro Italia, Via Bari 18, Roma (Metro Piazza Bologna)
📍𝗣𝗿𝗼𝗴𝗿𝗮𝗺𝗺𝗮: redhotcyber.com/linksSk2L/prog…
📍𝗜𝘀𝗰𝗿𝗶𝘇𝗶𝗼𝗻𝗲 conferenza di Martedì 19 Maggio: rhc-conference-2026.eventbrite…
#redhotcyber #rhcconference #conferenza #informationsecurity #ethicalhacking #dataprotection
Registrazione per l'evento Red Hot Cyber Conference 2026 del 19 Maggio 2026 presso il Teatro Italia di Roma, in Via Bari 18.Eventbrite
Cybersecurity & cyberwarfare reshared this.
Meta e Amazon insieme per l’intelligenza artificiale: decine di milioni di core Graviton
📌 Link all'articolo : redhotcyber.com/post/meta-e-am…
A cura di Carolina Vivianti
#redhotcyber #news #intelligenzaartificiale #amazon #meta #aws #graviton #cloudcomputing #ai
Scopri di più sull'accordo tra Meta e Amazon per implementare decine di milioni di core Graviton per l'intelligenza artificiale. Leggi oraCarolina Vivianti (Red Hot Cyber)
Cybersecurity & cyberwarfare reshared this.
PlayStation cambia tutto: senza verifica età niente chat e messaggi
📌 Link all'articolo : redhotcyber.com/post/playstati…
A cura di Bajram Zeqiri
#redhotcyber #news #playstation #sony #verificaeta #messaggistica #chatvocale #sicurezzainternet
Sony introduce la verifica dell'età su PlayStation per garantire un ambiente digitale più sicuro. Scopri come funziona e cosa cambiaBajram Zeqiri (Red Hot Cyber)
Cybersecurity & cyberwarfare reshared this.
Although modern cameras can, with skill and good conditions, produce photographs nearly indistinguishable from the original scene, this fidelity relies on the limitations of human vision. According to the trichromatic theory, humans perceive light as a mixture of three colors, which can be recorded and represented by cameras, displays, and color printing; a spectrometer, however, can detect a clear distance between the three colors present in a photograph and the wide range of spectra in the original scene. By contrast, one of the earliest color photography methods, Lippmann plates, captured not just true color, but true spectra.
A Lippmann plate, as [Jon Hilty] details, starts with a layer of photographic gel containing extremely fine silver halide crystals over the back of a glass plate. This layer is placed on top of a mirror, traditionally a mercury bath, and put in the camera. When light passes through the emulsion and reflects off the mirror, it interferes with incoming light to create a standing wave. The portions of the emulsion at the wave’s antinodes absorb the most energy, converting local silver halide crystals into reflective silver. The spacing of the silver particles depends on the incoming light’s wavelength, and is fixed in place during the development process.
This creates a matrix of vertically-stacked diffraction gratings, each diffracting back the original wavelength when illuminated with white light. Unlike normal diffraction gratings, the wavelength of diffracted light doesn’t depend strongly on the viewing angle; since the interference structure here is vertically-arranged, it refracts a narrow range of wavelengths across all possible viewing angles. The viewing angles, however, are limited; unlike with dye-based photographs, you can only view the colors nearly straight-on. This, along with the necessity for long exposures, the chance of producing washed-out colors, and the impossibility of creating reprints, kept Lippmann plates from ever really catching on. The basic concept lives on in holograms, which encode spatial information in a similar kind of photographically-formed diffraction pattern.
For a more conventional method of color photography, we’ve also seen a recreation of the autochrome method. Alternatively, check out this homemade silver halide photography emulsion.
youtube.com/embed/-DyrBDsKA5s?…
Thanks to [Stephen Walters] for the tip!
Although the ReactOS project is in no rush to dethrone Windows as the desktop operating system of choice, this doesn’t mean that some real changes aren’t happening. Most recently two big changes got merged, the first pertaining to the separate boot- and live CD images that are now merged into a single image, and the second being a new PnP-aware ATA storage stack for ATA and AHCI devices, with NT6+ compatibility.
Although there is still a separate live CD for now, this first change means that testing and installing ReactOS becomes easier, and that the old-school text-based installer may soon be on its way out as well.
Having the new ATA storage stack in place will translate into much better compatibility with real hardware, including the ability to use more hardware to install on and boot from compared to the old UniATA driver.
Combined, these two changes should bring the ReactOS installation and usage experience a lot closer to that of Windows, as well as many Linux distros. If you had issues with the OS on real hardware, this might be just the right time to give it another shake and provide detailed feedback to the developers if any remaining issues are encountered.
Thanks to [jeditobe] for the tip.
Software that collects public data from the Internet and uses it to provide half-assed answers to your questions might seem like a modern craze, but today we bid farewell to a website that helped pioneer pretend conversations all the way back in 1997 — as of May 1st, Ask Jeeves is no more.
Well, technically they dropped the “Jeeves” part back in 2006. Since then it’s just been Ask.com, but as the name implies the idea was more or less the same. Rather than the relatively rigid parameters and keywords required by traditional search engines, you could ask Jeeves questions about the world using natural language. Early advertisements showed the virtual valet answering arbitrary questions like “How many calories in a banana?,” which of course today seems commonplace and utterly unimpressive, but was a pretty wild for the 1990s.
It might seem surprising that a site designed from day one to offer a human-like Q&A experience should fold right as such technology is becoming commonplace. But of course, that commonality is the problem. When Google can answer your questions just as well (or poorly…) as Jeeves or anyone else, what’s the benefit for the average Internet user to seek out another service? But it’s still somewhat ironic, which is probably why the farewell message on Ask.com ends with the line “Jeeves’ spirit endures.”
Gone but never forgotten.
While on the subject of technology that’s potentially ahead of its time, MacRumors is reporting that Apple is giving up on their Vision Pro augmented reality googles. They haven’t been formally discontinued as of yet, but sources indicate that the internal development team for the entire product line has been disbanded and reassigned to other projects within the company. This comes after a October 2025 refresh of the hardware still failed to connect with consumers. Insiders have said that not only were sales sluggish on the ~$3,500 headsets, but that they were getting returned at a far higher rate than any of Apple’s other hardware products.
Now, we’re hardly Apple apologists here at Hackaday. It sort of goes without saying that the whole “Walled Garden” thing doesn’t really fit our ethos. But we can’t deny that the Vision Pro is an impressive piece of technology. After years of sticking our phones in crappy plastic headsets, or trying to force hardware designed for VR gaming to do literally anything else, the Vision Pro offered a practical way to put augmented reality to work. But even for a company known for producing expensive hardware, the price tag was just too much for most consumers.
We’ll go out on a limb here and predict that the Vision Pro will one day be looked back on like the Newton — a product that was too expensive and niche to be a commercial success when it came out, but still a technical milestone that gave us a glimpse into the shape of things to come.
Speaking of a technology that will inevitably become more common, the European Patent Office (EPO) released a report this week showing a seven-fold increase in the number of inventions intended for battery reuse and recycling over the last decade. Given our insatiable demand for rechargeable batteries, it should come as no surprise that there’s a huge push for new methods of squeezing more use out of cells. As noted several times by the EPO, it’s not purely about saving money either. Even if Europe produces the batteries domestically, they need to import the raw materials. Relying on foreign countries to provide critical infrastructure can be precarious in the best of times, and is likely to only become more politically onerous in the future.
Finally, we’ll leave you with a fun way to waste some time on a Sunday evening: Visible Zorker. Created by Andrew Plotkin, this website allows you to not only play through all three installments of Zork, but presents a debugger-style view of the source code as the game is running. Even if you’re not terribly interested in seeing how your responses are parsed, the map that shows your progress through the world is certainly handy. The project was actually started back in 2025, but Andrew just completed the trilogy by adding support for Zork III a couple days ago so now is the perfect time to check it out.
See something interesting that you think would be a good fit for our weekly Links column? Drop us a line, we’d love to hear about it.
@Informatica (Italy e non Italy)
Una vulnerabilità critica CVSS 9.8 nel pannello di controllo hosting più diffuso al mondo — sfruttata in silenzio per mesi prima della patch — ha permesso a un gruppo criminale di compromettere oltre 44.000 server e distribuire il
reshared this
40 anni fa l’#Italia entrava in #Internet: dalla storica connessione di #Pisa nasce la rete nazionale, oggi pilastro del #digitale di massa e del futuro connesso. Digitale diffuso come leva di crescita: infrastrutture e #competenze riducono il #digital #divide, rilanciando territori e innovazione. Verifica dell’età: su #Linux emergono dubbi su #privacy e controllo. Contenuti umani certificati: nuove etichette sfidano l’#IA garantendo autenticità.
Il tuo aggiornamento digitale: gratuito, indipendente, senza pubblicità. La tecnologia spiegata senza filtri, solo per te.Open Genova APS (Da zero a digital)
like this
reshared this
@Informatica (Italy e non Italy)
Trend Micro ha smascherato SHADOW-EARTH-053, un gruppo APT allineato alla Cina attivo dal dicembre 2024 che ha colpito governi e contractor difesa in Pakistan, India, Malaysia, Taiwan e Polonia. In parallelo,
reshared this
@Informatica (Italy e non Italy)
Il team Unit 42 di Palo Alto Networks ha identificato 18 estensioni Chrome mascherate da tool di produttività AI che nascondono trojan ad accesso remoto (RAT), attacchi meddler-in-the-middle,
reshared this
@Informatica (Italy e non Italy)
Il Garante privacy ha ribadito alle associazioni di categoria del settore hospitality il divieto di conservare le copie dei documenti di identità degli ospiti oltre il tempo necessario alla comunicazione dei dati alle autorità di
reshared this
@Informatica (Italy e non Italy)
Il gruppo TeamPCP ha compromesso i pacchetti npm ufficiali di SAP in un attacco supply chain denominato 'Mini Shai-Hulud': versioni malevole pubblicate il 29 aprile 2026 rubano credenziali AWS, Azure,
reshared this
@Informatica (Italy e non Italy)
La Cassazione si pronuncia sul sequestro probatorio di uno smartphone contenente informazioni e dati personali. Ecco la conclusione della Corte
L'articolo Cassazione: sequestro probatorio dello smartphone solo per acquisire dati mirati proviene da
reshared this
@Informatica (Italy e non Italy)
Morpheus è uno spyware che si presenta come un’applicazione innocua ma, una volta installato, consente un controllo completo del dispositivo. Nuovo elemento di quella zona grigia, alimentata da interessi economici miliardari e da un ecosistema globale poco regolato, in cui si
reshared this
@Informatica (Italy e non Italy)
Il Citizen Lab svela GLITTER CARP e SEQUIN CARP, due gruppi hacker allineati con la Cina che colpiscono giornalisti ICIJ e attivisti uiguri, tibetani e hongkonghesi con campagne di phishing sofisticate e abuse di OAuth
reshared this
@Informatica (Italy e non Italy)
Il report di TrendAI accende i riflettori sulle nuove tecniche adottate dagli hacker di stato. I gruppi APT guidano il cambiamento sfruttando sempre più spesso le vulnerabilità di dispositivi edge e l’adozione dell’AI rischia di peggiorare la situazione
L'articolo Gli attacchi cyber si stanno spostando sull’edge
reshared this
@Informatica (Italy e non Italy)
Il gruppo nordcoreano BlueNoroff ha perfezionato un attacco multi-stadio che combina deepfake generati con ChatGPT, finte videochiamate Zoom e tecniche ClickFix per
reshared this
April 2026 breach at Sistemi Informativi (IBM Italy) raises concerns over Chinese-linked cyber ops in Europe, including Salt Typhoon.Pierluigi Paganini (Security Affairs)
Cybersecurity & cyberwarfare reshared this.
Triple monitor workstations are pretty common these days, particularly for those wishing to maximise screen space for greater productivity. [Will It Work?] has put together a sillier take on this concept, however, hooking the diminutive iPod Nano up to three monitors instead.
The 6th-generation iPod nano brought forth a new form factor – it’s the postage stamp-sized one that you could clip to your workout gear. It’s not typically what you’d call a productivity device, but there is a way to get more out of it. The trick is to grab a 30-pin Keyboard Dock, which allows access to the composite video signal from the iPod. It was originally designed for the iPad, but it works with the iPad nano too with a 30-pin spacer adapter – just don’t expect the keys to do anything. This setup also allows access to the 3.5mm four-pole jack, which handles audio input and output. With a bunch of additional cables and adapters, the iPod was able to be hooked up to three screens, a set of Apple Pro speakers, and three Sharp LCD monitors.
What can you do with this setup? Fundamentally, not a whole lot. You can’t use the keyboard with the iPod Nano, so you’re limited to interacting with the tiny touchscreen. There also aren’t exactly a lot of apps to run on the platform, either. You can basically listen to music, watch a slide show, or record voice memos, while looking at the iPod’s display spread identically across three TVs. Still, it’s a fun joke build, because at a glance it genuinely looks like you’ve set up a triple-monitor workstation running off a tiny iPod from over a decade ago.
If you want to blow the mind of your next podcast guest, consider recording your next episode on this rig. Alternatively, explore some of the other hacks we’ve seen for the platform. Video after the break.
youtube.com/embed/PRGp8LWK9-k?…
@Informatica (Italy e non Italy)
La mappatura dei fondali oceanici sta diventando un elemento sempre più importante della competizione tra le due superpotenze, per motivi militari, economici e scientifici.
L'articolo Cina, Stati Uniti e la sfida degli abissi proviene da Guerre di Rete.
reshared this
@Informatica (Italy e non Italy)
ShinyHunters ha violato Anodot, una piattaforma SaaS di analytics cloud, sottraendo token di accesso che hanno aperto le porte ai data
reshared this
@Informatica (Italy e non Italy)
Xu Zewei, 34 anni, contractor del Ministero della Sicurezza dello Stato cinese, è stato estradato dall'Italia agli USA per la sua partecipazione alla campagna HAFNIUM/Silk
reshared this
Tomtits
in reply to reporter • • •informapirata ⁂
in reply to reporter • • •🤦♂️
@caffeitalia @feddit @notizie
Caffè Italia reshared this.