AI e mercato del lavoro: ci vuole tanta prudenza. Non bisogna affidarsi a emozioni o impressioni. Il rischio è di prendere decisioni sbagliate. E di correre dietro a mosche cocchiere.

Un recente studio suggerisce che le turbolenze del mercato del lavoro a cui abbiamo assistito siano cominciate prima della diffusione di ChatGPT e della GenAI. Non è ancora referato: potrebbe contenere errori o avere limiti di validità, ma lo cito perché il volume di affermazioni apodittiche sull’effetto dell’intelligenza artificiale sul mercato del lavoro raggiunge ogni giorno livelli sempre più insopportabili. I dati che emergono, da confermare, tendono a smorzare o a confutare le affermazioni più allarmistiche o apocalittiche (come quelle sull’impatto sui giovani di cui discutevo qualche giorno fa)

Il post di @Alfonso Fuggetta
abassavoce.it/p/ai-e-mercato-d…

@Intelligenza Artificiale

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Russia greatly expands SORM surveillance requirements
-NIST is looking for new PQC algorithms
-ENSOC launches in Europe
-New PAN firewall bug exploited in the wild
-Gravity Bridge hacked for $5.4m
-DxSale hacked for $7.3m
-PostHog security breach
-Prison calling service leaks sensitive data
-California sues 23andMe over breach
-Composer will scan for malicious PHP packages
-Zig bans AI-generated code
-More AI layoffs

Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS571/

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Social media moderation is failing
-CNIL had a productive year
-PQC comes to Chrome 150
-Last[.]fm is now an independent company again
-Wikipedia is union-busting
-EU squeezes out US space tech
-China to issue IDs to humanoid robots
-More US Cyber Force movement
-US Tech Force fails to hire staff
-Japan to establish a national intelligence agency
-Member of 764 group charged

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-New DriveSurge group
-Infrastructure Destruction Squad fakes hacktivism to sell malware
-New ChatGPT abuse technique
-New MicrosoftSystem64 RAT
-New WordPress malware
-Mullvad patches fingerprinting vector
-Oracle releases first monthly updates
-More Nightmare Eclipse bugs coming
-Canon fixes printer export bug
-New CIFSwitch LPE
Lorenzo ha ricondiviso questo.

Having a particularly hard time today with the simultaneous death of the climate, software development and the rule of law. And especially cheesed off with the people riding these waves for profit.

reshared this

Lorenzo ha ricondiviso questo.

US healthcare still stupidly expensive, with pathetic outcomes, study finds
L: arstechnica.com/health/2026/05…
C: news.ycombinator.com/item?id=4…
posted on 2026.05.31 at 16:41:10 (c=3, p=7)

reshared this

Lorenzo ha ricondiviso questo.

The Composer PHP package manager will scan all new libraries for malware to avoid future supply chain attacks: blog.packagist.com/composer-2-…

Packagist also intends to enable MFA by default for all Composer packages in the near future: blog.packagist.com/an-update-o…

reshared this

Lorenzo ha ricondiviso questo.

Canon has released firmware updates for more than 200 enterprise printer models to fix a bug that let you dump configs with plaintext domain/network passwords

praetorian.com/blog/canon-prin…

reshared this

Lorenzo ha ricondiviso questo.

reshared this

Lorenzo ha ricondiviso questo.

Tech Force set out to hire 1,000 technologists last year — it’s onboarded 10 so far

😂

nextgov.com/people/2026/05/tec…

reshared this

Lorenzo ha ricondiviso questo.

The Zig programming language has updated its code of conduct to ban LLM-generated code, vulnerability research, text-generation, and about anything AI at all

businessinsider.com/zig-progra…

ziglang.org/code-of-conduct/

in reply to Catalin Cimpanu

This got me curious, so I looked at GCC and clang. GCC is still working on it:

gcc.gnu.org/wiki/working-group…

LLVM allows slop, which disappointed me, even if they include language which suggests that the contributor should be accountable for the code:

llvm.org/docs/AIToolPolicy.htm…

I wonder how the complete lack of clarity around slop contributions is acceptable to the projects.

Lorenzo ha ricondiviso questo.

France's privacy watchdog issued and collected €487 million from 83 fines last year

Most came from just two fines, against Google (€325m) and Shein (€150m), which accounted for 97% of the collected funds

cnil.fr/fr/rapport-annuel-2025

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

PostHog says it's currently experiencing a security incident. The analytics company said it's "rotating keys after a security research team was able to confirm an exploit in one of our AWS environments," referring to Amazon Web Services.

Incident page: posthogstatus.com/incidents/01…

reshared this

Lorenzo ha ricondiviso questo.

Some infosec conference talks

SANS AI Cybersecurity Summit 2026 videos: youtube.com/playlist?list=PLtg…

SISAP 2026 videos: youtube.com/playlist?list=PLfj…

RWC 2026 videos: youtube.com/playlist?list=PLee…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

There's open-source traffic distribution systems now? Ha?!?

silentpush.com/blog/drivesurge…

reshared this

Lorenzo ha ricondiviso questo.

The Chinese government will assign unique digital IDs to humanoid-shaped robots.

The IDs will be assigned through a new website named the Humanoid Full Lifecycle Management Service Platform.

The IDs will be used to track robots from production to sale and recycling

scmp.com/tech/policy/article/3…

reshared this

Lorenzo ha ricondiviso questo.

There's another branded Linux LPE bug, this one named CIFSwitch

This was also found with AI, but it's not universal as it only affects a handful of distros and under certain conditions.

Unlike all the other Linux LPEs, this one received a patch ahead of release

heyitsas.im/posts/cifswitch/

reshared this

Lorenzo ha ricondiviso questo.

NIST is looking for a new round of PQC algorithms in case the first 3 selected ones get cracked and to provide better performance alternatives

csrc.nist.gov/Projects/pqc-dig…

reshared this

Lorenzo ha ricondiviso questo.

The Linux Foundation launched DNS-AID, a new open-source project to enable AI agents to use the DNS infrastructure to discover and talk to each other

linuxfoundation.org/press/linu…

dns-aid.org/

reshared this

Lorenzo ha ricondiviso questo.

Cybersecurity agencies from eight EU countries have launched a shared Security Operations Center (named ENSOC)

linkedin.com/feed/update/urn:l…

ensoc.eu/index.html#about

reshared this

Lorenzo ha ricondiviso questo.

One reason that Microsoft might be issuing such harshly worded language here to describe the researcher may be that, according to Nightmare Eclipse, they until recently worked as a security researcher at Microsoft.

Scroll back far enough through their Xitter account (to June 2020) and you will see they claimed CVE-2019-1385 was theirs.

On July 1, 2021, Nightmare Eclipse complained that Microsoft failed to fix one of the weaknesses they reported in CVE-2021-24084. Microsoft credits both of these flaws to the same researcher, whose LinkedIn account says they are in Germany and worked full time at Microsoft from Sept. 2022 to June 2025.

For the record, I think @GossiTheDog called it that this person was a former MS employee.

x.com/ChaoticEclipse0/with_rep…


After a security researcher published a series of unpatched bugs in Microsoft products, along with code to exploit them,
the company is now threatening to take legal action and call the cops on them.

Microsoft’s threat reignites a long-running argument over what responsibility, if any, security researchers have to disclose vulnerabilities affecting large and wealthy tech giants.

On Wednesday, Microsoft published a blog post criticizing the researcher, who goes by the handle
“Nightmare Eclipse,”
for publicly disclosing a series of bugs, including BlueHammer, RedSun, UnDefend, and YellowKey.

The flaws affected products such as the Windows built-in antivirus engine Defender and the disk-encryption tool BitLocker.

Katie Moussouris warned that the consequences of security researchers losing trust with Microsoft could result in a chilling effect of fewer people coming forward to report bugs,
“making it less safe for all of us.”

Security researcher and former Microsoft employee Kevin Beaumont also called out Microsoft in a blog post,
describing the company’s position a “dumpster fire of its own making.”

“Proof of concept exploit creation and distribution for zero days is ‘criminal activity’ now?”
wrote Beaumont.

“Responsible disclosure quite often is framed to protect the product owner, not the customer
— using it to try to criminally prosecute people is a new low.”
techcrunch.com/2026/05/29/micr…


reshared this

in reply to BrianKrebs

This person has been a prolific bug finder for quite some time. Here's their public HackerOne profile: hackerone.com/halove23/hacktiv…

Reading their Xitter timeline over the years is pretty interesting. They went from working w/ a lot of these bug bounty programs and giving MS time to fix stuff beyond the usual 90-day window to increasing frustration in dealing w/ vendors. I wish that were less of a common experience than it still is today, but some dynamics in this industry never seem to change.

Also just noticed something interesting. Back in 2019, MS was including hyperlinks to researchers in their advisories. In this advisory, they actually link to the researcher's shitposting Facebook profile, which has posts up until this month.

facebook.com/com.android.vendi…

msrc.microsoft.com/update-guid…

Questa voce è stata modificata (1 giorno fa)
Lorenzo ha ricondiviso questo.

SentinelOne's stock closes down 8% after the company announced plans to lay off 8% of its workforce and forecasted Q2 and FY revenue guidance below estimates (Samantha Subin/CNBC)

cnbc.com/2026/05/29/sentinelon…
techmeme.com/260529/p31#a26052…

Lorenzo ha ricondiviso questo.

Power bills more than 250 per cent higher near data centres
L: theglobeandmail.com/investing/…
C: news.ycombinator.com/item?id=4…
posted on 2026.05.26 at 23:26:25 (c=0, p=5)

reshared this

Lorenzo ha ricondiviso questo.

Wikipedia went from "do not cite" to "the last trustworthy source on the internet" in the past 25 years and now it looks like they want to throw it all away because they want to break a union.
The largest community driven project in the world, relying directly on volunteers, and they still do not see the value of their own people.

I hate capitalism

Big Tech’s Anti-Labor Playbook Has Come for Wikipedia | by Jake Orlowitz | May, 2026 | Medium
medium.com/@jakeorlowitz/wikip…

Questa voce è stata modificata (5 giorni fa)
Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Dutch police take down giant botnet of 17 million devices
-US military staff tracked with adtech location data
-Google engineer arrested for Polymarket bets
-Unpatched bugs in Gogs, Casdoor IAM
-SuperFortune hacked for $15m
-VentraIP hit by DDoS attack
-UK Visa Portal leak
-Amadeus gets massive GDPR fine
-EU fines Temu
-IBM announces Project Lightwell
-C# improves memory safety
-Sextortionist gets 33 years

Podcast: risky.biz/RBNEWS570/
Newsletter: news.risky.biz/risky-bulletin-…

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-CISA tells agencies to fix supply chain attack vectors
-Apple and Google demand Bill C-22 changes
-Fraudster gets 10 years
-Romanian IAB sentenced
-VenomRAT author extradited to France
-UK citizens lose £102 million to scams
-npm abused for adware campaigns
-Global smishing operation hits 19 countries
-BlackToad and JINX-0164 profiles
-New RatPressto phishing kit
-New SuperProxy botnet
Lorenzo ha ricondiviso questo.

📰 Risky Bulletin: Dutch police take down giant botnet of 17 million devices

risky.biz/risky-bulletin-dutch…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

#Meme #Humour
Lorenzo ha ricondiviso questo.

reshared this