#podcast da Caffe20.it
Un recente studio suggerisce che le turbolenze del mercato del lavoro a cui abbiamo assistito siano cominciate prima della diffusione di ChatGPT e della GenAI. Non è ancora referato: potrebbe contenere errori o avere limiti di validità, ma lo cito perché il volume di affermazioni apodittiche sull’effetto dell’intelligenza artificiale sul mercato del lavoro raggiunge ogni giorno livelli sempre più insopportabili. I dati che emergono, da confermare, tendono a smorzare o a confutare le affermazioni più allarmistiche o apocalittiche (come quelle sull’impatto sui giovani di cui discutevo qualche giorno fa)
Il post di @Alfonso Fuggetta
abassavoce.it/p/ai-e-mercato-d…
Un articolo LSE sul calo di assunzioni junior mostra che il riflesso “è l’AI” copre quasi sempre cause più prosaiche. Troppe volte viviamo di questi riflessi che rischiano di portarci fuori strada.Alfonso Fuggetta (A bassa voce)
reshared this
As of 2026, the world population is approximately 8.3 billionThe global dog population is estimated to be 700–900 million
That's a bullshit ratio.
reshared this
reshared this
-Russia greatly expands SORM surveillance requirements
-NIST is looking for new PQC algorithms
-ENSOC launches in Europe
-New PAN firewall bug exploited in the wild
-Gravity Bridge hacked for $5.4m
-DxSale hacked for $7.3m
-PostHog security breach
-Prison calling service leaks sensitive data
-California sues 23andMe over breach
-Composer will scan for malicious PHP packages
-Zig bans AI-generated code
-More AI layoffs
Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS571/
In other news: NIST is looking for new PQC algorithms; ENSOC launches in Europe; new PAN firewall bug exploited in the wild.Catalin Cimpanu (Risky.Biz)
reshared this
Catalin Cimpanu reshared this.
reshared this
There are strategies to improve healthcare, but US isn't trying them.Beth Mole (Ars Technica)
reshared this
Japanese lawmakers have passed a law to establish a national intelligence agency.
While several intelligence bureaus exist under several ministries, Japan has operated without a central intelligence agency since 1952
reshared this
The Composer PHP package manager will scan all new libraries for malware to avoid future supply chain attacks: blog.packagist.com/composer-2-…
Packagist also intends to enable MFA by default for all Composer packages in the near future: blog.packagist.com/an-update-o…
The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems.Nils Adermann (Private Packagist)
reshared this
Canon has released firmware updates for more than 200 enterprise printer models to fix a bug that let you dump configs with plaintext domain/network passwords
praetorian.com/blog/canon-prin…
One printer, default creds, full domain compromise. Canon's config export enforces encryption client-side. CVE-2026-1789 hits 200+ models.Michelle Rhodes (Praetorian)
reshared this
Russia's FSTEC military technical agency has published a guide to help local companies mitigate DDoS attacks
fstec.ru/dokumenty/vse-dokumen…
Федеральная служба по техническому и экспортному контролюФСТЭК России
reshared this
Tech Force set out to hire 1,000 technologists last year — it’s onboarded 10 so far
😂
nextgov.com/people/2026/05/tec…
The effort is meant to infuse the government with young engineers, cyber and data workers. It follows the loss of almost 20,000 technology workers through the Trump administration’s efforts to downsize the workforce last year.Natalie Alms (Nextgov.com)
reshared this
The Zig programming language has updated its code of conduct to ban LLM-generated code, vulnerability research, text-generation, and about anything AI at all
businessinsider.com/zig-progra…
Zig, an open-source programming language bans contributors from using AI. Its president said that the these submissions have "no value whatsoever."Henry Chandonnet (Business Insider)
gmc likes this.
reshared this
This got me curious, so I looked at GCC and clang. GCC is still working on it:
gcc.gnu.org/wiki/working-group…
LLVM allows slop, which disappointed me, even if they include language which suggests that the contributor should be accountable for the code:
llvm.org/docs/AIToolPolicy.htm…
I wonder how the complete lack of clarity around slop contributions is acceptable to the projects.
France's privacy watchdog issued and collected €487 million from 83 fines last year
Most came from just two fines, against Google (€325m) and Shein (€150m), which accounted for 97% of the collected funds
cnil.fr/fr/rapport-annuel-2025
Chaque année, la CNIL publie son rapport d'activité pour faire le point sur ses actions autour de ses quatre grandes missions : informer et protéger le grand public, accompagner et conseiller les professionnels et les pouvoirs publics, anticiper et i…www.cnil.fr
reshared this
PostHog says it's currently experiencing a security incident. The analytics company said it's "rotating keys after a security research team was able to confirm an exploit in one of our AWS environments," referring to Amazon Web Services.
Incident page: posthogstatus.com/incidents/01…
reshared this
Some infosec conference talks
SANS AI Cybersecurity Summit 2026 videos: youtube.com/playlist?list=PLtg…
SISAP 2026 videos: youtube.com/playlist?list=PLfj…
RWC 2026 videos: youtube.com/playlist?list=PLee…
RWC 2026 took place in Taipei, Taiwan on March 9-11, 2026. See https://rwc.iacr.org/2026 for more information about the conference, including links to slides.IACR (YouTube)
reshared this
There's open-source traffic distribution systems now? Ha?!?
silentpush.com/blog/drivesurge…
Silent Push observed several drive-by attack clusters using ClickFix and FakeUpdates campaigns. We named the primary driver DriveSurge.Peggy Kelly (Silent Push)
reshared this
The Chinese government will assign unique digital IDs to humanoid-shaped robots.
The IDs will be assigned through a new website named the Humanoid Full Lifecycle Management Service Platform.
The IDs will be used to track robots from production to sale and recycling
scmp.com/tech/policy/article/3…
The national initiative will give every bipedal humanoid a unique code, like a national ID but for robots.Ben Jiang (South China Morning Post)
reshared this
There's another branded Linux LPE bug, this one named CIFSwitch
This was also found with AI, but it's not universal as it only affects a handful of distros and under certain conditions.
Unlike all the other Linux LPEs, this one received a patch ahead of release
Harnessing LLMs into composing complex, multihop vulnerability chainsAsim Viladi Oglu Manizada (Hey, it's Asim)
reshared this
NIST is looking for a new round of PQC algorithms in case the first 3 selected ones get cracked and to provide better performance alternatives
csrc.nist.gov/Projects/pqc-dig…
Official comments on the Third Round Candidates should be submitted using the 'Submit Comment' link for the appropriate algorithm. Comments from the pqc-forum Google group subscribers will also be forwarded to the pqc-forum Google group list.csrc.nist.gov
reshared this
reshared this
CommsRisk shuts down 😑
reshared this
The Linux Foundation launched DNS-AID, a new open-source project to enable AI agents to use the DNS infrastructure to discover and talk to each other
reshared this
Oracle's first monthly security updates are out
Company recently switched from a quarterly to a monthly update scheme
reshared this
Cybersecurity agencies from eight EU countries have launched a shared Security Operations Center (named ENSOC)
linkedin.com/feed/update/urn:l…
🌐 The official ENSOC website is now live 🔗 To see all future longform materials, ongoing progress, and news about our project, make sure to visit the official ENSOC website through the following link: ensoc.ENSOC (LinkedIn)
reshared this
The amount of fuckery going on when you put something online is absolutely mindboggling to me.
Internet, truly, is a rather hostile place.
reshared this
So... they're gonna tank their whole economy?
Ha?
reshared this
Well, aren't they already doing a pretty good job of flushing the economy down a gold-plated toilet?
One reason that Microsoft might be issuing such harshly worded language here to describe the researcher may be that, according to Nightmare Eclipse, they until recently worked as a security researcher at Microsoft.
Scroll back far enough through their Xitter account (to June 2020) and you will see they claimed CVE-2019-1385 was theirs.
On July 1, 2021, Nightmare Eclipse complained that Microsoft failed to fix one of the weaknesses they reported in CVE-2021-24084. Microsoft credits both of these flaws to the same researcher, whose LinkedIn account says they are in Germany and worked full time at Microsoft from Sept. 2022 to June 2025.
For the record, I think @GossiTheDog called it that this person was a former MS employee.
reshared this
Going after the hacker who found the security hole sounds like oh such a wonderful way to secure their own code.
:/
This person has been a prolific bug finder for quite some time. Here's their public HackerOne profile: hackerone.com/halove23/hacktiv…
Reading their Xitter timeline over the years is pretty interesting. They went from working w/ a lot of these bug bounty programs and giving MS time to fix stuff beyond the usual 90-day window to increasing frustration in dealing w/ vendors. I wish that were less of a common experience than it still is today, but some dynamics in this industry never seem to change.
Also just noticed something interesting. Back in 2019, MS was including hyperlinks to researchers in their advisories. In this advisory, they actually link to the researcher's shitposting Facebook profile, which has posts up until this month.
reshared this
reshared this
This Week in Package Management: 30 May 2026
nesbitt.io/2026/05/30/this-wee…
Releases, advisories, and articles from across the package management worldAndrew Nesbitt
reshared this
reshared this
SentinelOne's stock closes down 8% after the company announced plans to lay off 8% of its workforce and forecasted Q2 and FY revenue guidance below estimates (Samantha Subin/CNBC)
cnbc.com/2026/05/29/sentinelon…
techmeme.com/260529/p31#a26052…
SentinelOne reported earnings after the bell Thursday and issued lackluster guidance for the current quarter and full-year.Samantha Subin (CNBC)
reshared this
Plus, a concern about the Anthropic and OpenAI IPOs expected later this yearScott Barlow (The Globe and Mail)
reshared this
Wikipedia went from "do not cite" to "the last trustworthy source on the internet" in the past 25 years and now it looks like they want to throw it all away because they want to break a union.
The largest community driven project in the world, relying directly on volunteers, and they still do not see the value of their own people.
I hate capitalism
Big Tech’s Anti-Labor Playbook Has Come for Wikipedia | by Jake Orlowitz | May, 2026 | Medium
medium.com/@jakeorlowitz/wikip…
reshared this
This is similar to what is happening to Mozilla.
What we should learn from it, is that lawyers, finance and corporate people should always be kept in consulting roles only, but never be left near the helm.
-Dutch police take down giant botnet of 17 million devices
-US military staff tracked with adtech location data
-Google engineer arrested for Polymarket bets
-Unpatched bugs in Gogs, Casdoor IAM
-SuperFortune hacked for $15m
-VentraIP hit by DDoS attack
-UK Visa Portal leak
-Amadeus gets massive GDPR fine
-EU fines Temu
-IBM announces Project Lightwell
-C# improves memory safety
-Sextortionist gets 33 years
Podcast: risky.biz/RBNEWS570/
Newsletter: news.risky.biz/risky-bulletin-…
In other news: US military staff tracked with adtech location data; Google engineer arrested for Polymarket bets; unpatched bugs in Gogs and Casdoor IAM.Catalin Cimpanu (Risky.Biz)
reshared this
📰 Risky Bulletin: Dutch police take down giant botnet of 17 million devices
risky.biz/risky-bulletin-dutch…
Dutch authorities have conducted one of the largest-ever malware disruptions and took down a botnet that infected more than 17 million dev [Read More]risky.biz
reshared this
reshared this

reshared this
An app on SuperBOX streaming devices turns them into residential proxy nodes
reshared this
Lorenzo
in reply to Valentino Spataro • •