Lorenzo ha ricondiviso questo.

Redditors have caught Google secretly updating its Chrome terms of service to remove a line that guaranteed that local AI models won't send data to Google servers.

That's now gone, meaning your local AI sends data to Google, so it's not that local.

old.reddit.com/r/chrome/commen…

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Can Someone Please Explain Whether Cloudflare Blackmailed Canonical? flyingpenguin.com/can-someone-…

reshared this

Lorenzo ha ricondiviso questo.

I don't think it's blackmail per se; the proper term for an Organization allowing crime to happen in their area to anyone who doesn't pay the Organization for 'protection' against said crime is a "racket" - as in, 'racketeering'.

reshared this

in reply to Fi 🏳️‍⚧️

Now, whether or not cloudflare can be actually punished -for- racketeering, given they "just" "host" the service instead of running it directly? prrrobably not under this administration.

But y'know.

en.wikipedia.org/wiki/Racketee…

It's pretty obvious that this is a racket.

Lorenzo ha ricondiviso questo.

Cloudflare: "You've got some lovely infrastructure here. Shame if something... Happened to it."

flyingpenguin.com/can-someone-…

reshared this

Lorenzo ha ricondiviso questo.

In this 3,000+ word deep-dive for my blog and newsletter ~ this week in security ~ I explore the most pressing threats to face the internet this year. This includes surveillance and choking online access to governments going rogue, and more, and why they pose a risk.

this.weekinsecurity.com/the-mo…

reshared this

Lorenzo ha ricondiviso questo.

It's a day ending in "y".... so there's a supply chain attack happening on npm

socket.dev/blog/tanstack-npm-p…

reshared this

in reply to Catalin Cimpanu

It has now spread from npm to PyPI, and has hit OpenSearch, Mistral AI, Squawk, Guardrails AI, and others, a total of 416 malicious artifacts. TeamPCP is taking credit, latest update in our post:

socket.dev/blog/tanstack-npm-p…

JDownloader hackerato: malware RAT nei download Linux e Windows

@GNU/Linux Italia

linuxeasy.org/jdownloader-hack…

Sito JDownloader violato: installer Linux con malware RAT per root access. Una supply chain attack da non sottovalutare per utenti Linux.
L'articolo JDownloader hackerato: malware RAT nei download Linux e Windows proviene da Linux Easy.
E' vietato

SparkyLinux 8.3 Rilasciato, arriva il supporto per Linux 7.0

@GNU/Linux Italia

linuxeasy.org/sparkylinux-8-3-…

SparkyLinux 8.3 aggiorna kernel, desktop e software principali con base Debian 13 Trixie e nuove ISO disponibili.
L'articolo SparkyLinux 8.3 Rilasciato, arriva il supporto per Linux 7.0 proviene da Linux Easy.
E'

Debian blocca i pacchetti non riproducibili nella repository Testing

@GNU/Linux Italia

linuxeasy.org/debian-blocca-i-…

Debian blocca i pacchetti non riproducibili in Testing e rafforza il controllo sulla sicurezza della supply chain.
L'articolo Debian blocca i pacchetti non riproducibili nella repository

Linux valuta un killswitch per limitare le vulnerabilità più pericolose

@GNU/Linux Italia

linuxeasy.org/linux-valuta-un-…

Il kernel Linux valuta un killswitch per disattivare funzioni vulnerabili e ridurre il rischio tra disclosure e patch.
L'articolo Linux valuta un killswitch per limitare le

PDFCraft: toolkit PDF open source completo e orientato alla privacy

@GNU/Linux Italia

linuxeasy.org/pdfcraft-toolkit…

PDFCraft è un toolkit PDF open source che funziona nel browser, con oltre 90 strumenti per modificare, convertire e proteggere documenti.
L'articolo PDFCraft: toolkit PDF open source completo e orientato alla

PhotoFlare nasconde oltre 500 filtri avanzati grazie a G’MIC-Qt

@GNU/Linux Italia

linuxeasy.org/photoflare-nasco…

PhotoFlare integra G’MIC-Qt con oltre 500 filtri gratuiti per fotoritocco, restauro immagini ed effetti artistici avanzati.
L'articolo PhotoFlare nasconde oltre 500 filtri avanzati grazie a G’MIC-Qt proviene da Linux Easy.
E' vietato

Lorenzo ha ricondiviso questo.

A data center drained 30M gallons of water unnoticed — until residents complained about low water pressure

Residents in Fayetteville, Georgia, noticed low water pressure last year. The utility discovered two unaccounted-for water connections at one of the nation’s largest data center campuses.

“We get this notification from Fayette County water system saying you need to stop watering your lawns to help conserve water."

politico.com/news/2026/05/08/g…

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Vodafone were being held to ransom by some organised crime clowns. Vodafone refused to pay, good on 'em, break the cycle of crime clowns.

It's not "full infrastructure" as claimed (it's only a 5gb file), nor is it VMware ESXi as originally claimed.

reshared this

Lorenzo ha ricondiviso questo.

pretty wild that American farmers are suffering from a fertilizer shortage despite record levels of bullshit from the White House

Omarchy 3.8 Rilasciato migliora i promemoria integrati e meteo live

@GNU/Linux Italia

linuxeasy.org/omarchy-3-8-rila…

Omarchy 3.8 aggiorna l’esperienza Arch Linux con promemoria integrati, meteo live e gestione rapida delle app predefinite.
L'articolo Omarchy 3.8 Rilasciato migliora i promemoria integrati e meteo

Parrot OS 7.2 aggiorna sicurezza e strumenti con Linux Kernel 6.19

@GNU/Linux Italia

linuxeasy.org/parrot-os-7-2-ag…

Parrot OS 7.2 aggiorna kernel Linux 6.19, corregge la vulnerabilità Copy Fail e rinnova strumenti di sicurezza e desktop KDE Plasma.
L'articolo Parrot OS 7.2 aggiorna sicurezza e strumenti con Linux Kernel 6.19

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-FCC relaxes foreign router ban to allow for security updates
-ShinyHunters disrupts schools across US
-21-year-old RCE found in FreeBSD
-Another Linux zero-day LPE
-Mexican water utility hacked with AI
-SailPoint breach
-Recordings leak US-Israel-Argentina plan to destabilize LATAM govts with fake news
-France opens investigation of Musk and Twitter (X)
-FCC wants KYC for telcos
-CyberCorps scholarship rebrands to AI

Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS562/

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-EU calls VPNs a "loophole" for age checks
-JDownloader supply chain attack
-Checkmarx hack update
-RansomHouse claims Trellix hack
-The Dutch fine Yango €100m
-GM gets a tiny fine for selling driver data
-TrustedVolumes hacked for $6.7m
-Google sabotages de-Googled smartphones with new reCAPTCHA
-Trenchant exec on the hook for an extra $10m
-Infosec exec arrested in CSAM investigation
-Twin pleads guilty to destroying govt DBs
-Kingdom Market admin sentenced to prison
-Crimenetwork 2 takedown

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-WhatsApp bans scam accounts in India
-Malware found on HuggingFace and npm
-Malware reports on Lorem Ipsum backdoor, Needle MaaS, Doko PhaaS, PamDOORa Linux backdoor, Jenkins DDoS botnet
-NZ sanctions Russian cyber actors
-Argentina detains La Compañía disinfo network boss
-Russian disinfo networks go wild on TikTok
-New LiteLLM exploitation in the wild
-New ClaudeBleed vulnerability
-Vulnerabilities in Yarbo lawn mowers
-Cloudflare layoffs
-DistrictCon and SREcon 2026 videos

Gazzetta del Cadavere reshared this.

in reply to Catalin Cimpanu

#alttext

Who may be at risk: Only people who downloaded and installed from jdownloader.org during 6th-7th May 2026 (UTC) using one or more website download links for "Download Alternative Installer" and/or the affected Linux shell installer link - see the timeline below.
Who is not affected: Everything that is not among the at-risk cases above - all other downloads and install paths on this site, existing installations, in-app updates, and installations from any other source.

DP Code la nuova interfaccia minimal per programmare con agenti AI

@GNU/Linux Italia

linuxeasy.org/dp-code-interfac…

DP Code semplifica lo sviluppo con agenti AI come Codex e Claude, offrendo workflow rapidi, PR automatiche e gestione multi-progetto.
L'articolo DP Code la nuova interfaccia minimal per programmare con agenti AI proviene da Linux

Lorenzo ha ricondiviso questo.

Checkmarx hack update:

"We are aware that a modified version of the Checkmarx Jenkins AST plugin was published to the Jenkins Marketplace"

checkmarx.com/blog/ongoing-sec…

reshared this

Lorenzo ha ricondiviso questo.

France arrested a cybersecurity executive for allegedly buying child sexual abuse material from the dark web

Filigran (OpenCTI) founder Samuel Hassine is allegedly one of the 232 suspects identified by police as buyers on the "Alice with Violence CP" portal

lelibrepenseur.org/samuel-hass…

reshared this

Lorenzo ha ricondiviso questo.

Argentina arrested and deported a Russian national linked to a Kremlin disinformation network.

Dmitry Novikov, 26, was one of the managers of a group known as "La Compañía" that used fake news and disinformation to attack LATAM governments that support Ukraine.

instagram.com/reel/DYC_AaLxWtR…

reshared this

Lorenzo ha ricondiviso questo.

Here's the website with the recordings. It's been under heavy DDoS for a week now

hondurasgate.ch/

reshared this

Lorenzo ha ricondiviso questo.

The Linux kernel team is working on Killswitch, a new security feature that will temporarily disable some kernel functions until a patch is available

This is in response to the recent CopyFail and DirtyFrag disclosure debacles

lore.kernel.org/all/2026050707…

reshared this

in reply to Catalin Cimpanu

it’s like turning the whole kernel into a bunch of modules. The two vulnerabilities were mitigated by keeping the modules from loading (if in module form).
While it’s nice to have this, I’d like to see more hardening of systems by minimizing unused features.
I understand one argument for this feature is people can do without a feature for a while though still want the feature. Despite that, many can do without these features altogether.
Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The FreeBSD team has patched a remote code execution in its operating system that impacts all versions released since 2005

Tracked as CVE-2026-42511, the vulnerability resides in the FreeBSD DHCP client and is extremely easy to exploit

aisle.com/blog/aisle-discovers…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

TikTok has published its monthly report on covert influence operations the company has spotted on its platform in March this year.

Most of these networks have a connection with Russia, promoted Russian interests, pro-Kremlin parties, or were run from Russia.

tiktok.com/safety/en/transpare…

Questa voce è stata modificata (1 giorno fa)

reshared this

Lorenzo ha ricondiviso questo.

Security researchers extracted an API key from the Needle malware and then enumerated its backend to retrieve a list of 1900+ victims

The malware is an infostealer with a focus on crypto

beelzebub.ai/blog/needle-c2-cr…

reshared this

Riepilogo settimanale Linux Easy – Settimana 19 (4–10 maggio 2026)

@GNU/Linux Italia

linuxeasy.org/riepilogo-settim…

Settimana 19 su Linux Easy: nuove distribuzioni, aggiornamenti software, strumenti avanzati e novità per il gaming su Linux.
L'articolo Riepilogo settimanale Linux Easy – Settimana 19 (4–10 maggio 2026) proviene da Linux Easy.
E'

AloxBook porta la contabilità personale offline su desktop con doppia scrittura e dati cifrati

@GNU/Linux Italia

linuxeasy.org/aloxbook-contabi…

AloxBook è un software desktop per contabilità personale con doppia scrittura, archiviazione cifrata locale e importazione CSV
L'articolo AloxBook porta la contabilità personale offline su desktop con doppia

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

A cluster of 38 malicious npm libraries targeted the internal networks of large tech companies like Apple, Alibaba, and Google.

The campaign attempted to compromise dev machines by leveraging a technique known as dependency confusion.

The packages deployed malware that attempted to steal npm publish tokens, suggesting the goal was malicious and not bug bounty research.

Security firm Panther linked the campaign to "a single Indonesian-speaking threat actor."

panther.com/blog/frankly-malic…

reshared this

Lorenzo ha ricondiviso questo.

A cluster of three npm accounts used 51 libraries over the past four years to abuse npm as a config storage system for their mobile apps.

The apps belonged to Chinese sports gambling and pirate streaming platforms.

panther.com/blog/4-years-51-pa…

reshared this

Lorenzo ha ricondiviso questo.

A malicious credentials harvester was found in a popular HuggingFace repository named Open-OSS/privacy-filter

At the time of the discovery, the repository was listed as #1 in HuggingFace's trending section with more than 240,000 downloads

hiddenlayer.com/research/malwa…

#1

reshared this

Lorenzo ha ricondiviso questo.

"openai.com" was once the personal homepage of a guy named glenn
L: bsky.app/profile/annierau.bsky…
C: news.ycombinator.com/item?id=4…
posted on 2026.05.10 at 06:21:40 (c=0, p=4)

reshared this

Lorenzo ha ricondiviso questo.

Website of download manager JDownloader was hacked in another supply chain incident

-spread malware for two days
-malware was included with Windows and Linux versions
-no malicious updates so infections occurred via new downloads only
-infection timeline May 6-7

jdownloader.org/incident_8.5.2…

reshared this

ONLYOFFICE Workspace 12.8.0: compatibilità avanzata e nuove funzionalità

@GNU/Linux Italia

linuxeasy.org/onlyoffice-works…

ONLYOFFICE Workspace 12.8.0 migliora la compatibilità con file Apple, Visio e Hancom, introducendo nuove funzioni e aggiornamenti.
L'articolo ONLYOFFICE Workspace 12.8.0: compatibilità avanzata e nuove funzionalità proviene

Parchment l’editor di testo minimale per GNOME Linux

@GNU/Linux Italia

linuxeasy.org/parchment-editor…

Parchment è un editor di testo minimale per Linux, pensato per scrivere codice e contenuti senza distrazioni inutili.
L'articolo Parchment l’editor di testo minimale per GNOME Linux proviene da Linux Easy.
E' vietato riprodurre questo articolo senza

Lorenzo ha ricondiviso questo.

Anthropic’s Claude used in attempted compromise of Mexican water utility

cybersecuritydive.com/news/ant…

dragos.com/blog/ai-assisted-ic…

reshared this