Lorenzo ha ricondiviso questo.

Today's featured color from Storied Colors: storiedcolors.com/color/iznik-…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Remote exploitation drops cryptominers on macOS devices
-White House lets private companies carry out offensive cyber ops
-AI hacking campaign breached Taiwan's government
-Kenya orders internet cafes to store logs
-Colombia's Ministry of Justice hit by ransomware
-Ransomware hits Guatemala Supreme Court
-Romania restores land registry after cyberattack
-ICO reprimands ACRO over breaches
-Uber Freight and RingCentral had breaches

N: news.risky.biz/risky-bulletin-…
P: news.risky.biz/risky-bulletin-…

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Russia to test AI models for "traditional values"
-Montenegro arrests 50 for high-tech crime
-Ukraine disrupts 94 call centers
-Spain arrests AI face-swapping scammer
-Apple sends new mercenary spyware alerts
-78k TeamPCP stolen creds leak online
-737 malicious Chrome extensions spotted
-Vuln-scan campaign poses as AI crawlers
-Deadbugz campaign tries to poison AI tools
-More AI tools found on hacking forums
-Deno runtime sees increased abuse
-Crypter ecosystem has 24 sellers
-Evooo1Bot botnet
in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-New Armored Likho activity in Russia
-APT36 has new malware
-Jewelbug co-hosts e-crime and APT infrastructure
-Academics hack a Boeing
-New VMware bug exploited in the wild
-New Plug and Pwn attack
-New ShieldBreak Windows zero-day
-New Zapscape and CopyEscape vulnerability
-New WindRelay and Octagon Android malware, JWR phishing kit, Lucid Stealer
-Akira abuses Safe Mode
-Rapid7 lays off 300
-DEFCON 2026 videos
Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

II'm getting so lazy at posting on social media... but Clop listed 40+ companies on its leak site, likely from the Windchill exploitation

Some large corps listed like Shell, Philips, and GE

reshared this

Lorenzo ha ricondiviso questo.

New White House memo instructs the NCC to establish a program through which private companies can apply for approval to carry out offensive cyber ops against cybercrime groups

Memo: whitehouse.gov/presidential-ac…

Fact sheet: whitehouse.gov/fact-sheets/202…

reshared this

Dove scaricare ebook e libri digitali gratis legalmente

@GNU/Linux Italia

linuxeasy.org/dove-scaricare-e…

Scopri dove trovare ebook e libri digitali gratuiti da scaricare legalmente, tra pubblico dominio, licenze libere e strumenti open come Calibre

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Perché l'istanza snowfan.it ha deciso di chiudere totalmente i ponti con la nuova istanza fedisky.it?

Chiedo ai tre moderatori dell'istanza @snow @PaoloParti e @assofante quali sono i motivi che hanno determinato la scelta non solo di limitare (ossia impedire la visibilità dei contenuti di fedisky.it nella timeline locale di snowfan.it) ma addirittura di sospendere qualsiasi possibilità di collegarsi a fedisky.it

Infatti se posso capire che possa esserci una resistenza ideologica nei confronti dell'universo Bluesky, è anche vero che fedisky.it non trasporta i contenuti di Bluesky dentro al fediverso!

Tranne questa motivazione, che però è appunto fallace, tagliare i ponti con fedisky.it sarebbe esattamente come costringere la propria famiglia a tagliare i ponti con tutte le famiglie abbonate a Prime Video per esprimere la propria contrarietà ad Amazon.

Poi è sicuramente vero che Fedisky.it al momento è un'istanza sperimentale e non ha un regolamento né una privacy policy, ma proprio per questo ha consentito le iscrizioni soltanto a utenti già presenti nel fediverso da anni (alcuni dei quali sono anche amministratori e moderatori) e quindi, a parte un po' di rumore fisiologico nei post sperimentali (tipo "Saluti in markdown da Wafrn" o "Vediamo come si vede questo post lunghiiiissiiimoooo su Bluesky"), non c'è alcun motivo di bloccare l'istanza.

Ripeto: nessun contenuto proveniente da Bluesky può attraversare fedisky.it per passare al fediverso.


Fedisky.it non è un mirror che replica contenuti blusky, non è un bridge opt-out e non è neanche un bridge opt-in. Fedisky.it per tutti gli utenti del fediverso è solo un'istanza come tante altre che pubblica nella posta in uscita soltanto contenuti activitypub prodotti dall'istanza stessa oppure ricondivide contenuti Activitypub da altre istanze Activitypub.

@fediverso

in reply to Andre123

@andre123 @prealpinux se dico che una mia scelta prescinde da qualcosa, questo non trasforma tale scelta in una scelta giustificata. Io voglio capire qual è il motivo per cui la mia istanza è stata defederata dalla vostra e non mi sembra che mi sia stato spiegato il motivo. Dal momento che fedisky.it non ha a che fare con Bluesky, non più rispetto a quasi tutte le altre istanze del Fediverso, la motivazione per cui non volete avere a che fare con Bluesky non è una spiegazione
Lorenzo ha ricondiviso questo.

🎙️ Risky Business #848 -- OpenAI comes clean

risky.biz/RB848/

#848

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Russian hackers jump on the fake job interview train
-Portuguese to face trial for developing WormGPT
-AI assistant hacks gym website
-OpenAI releases cyber models for blue teams
-Flight turns off WiFi after hack, blames it on DEFCON hacker
-CEVA breach impacts shipping across Europe
-UAE thwarts cyber campaigns
-Hackers breach Poland's MyDr healthcare platform
-LexisNexis hit by Metabase hack
-Mozilla leaks PGP key

N: news.risky.biz/risky-bulletin-…
P: risky.biz/RBNEWS599/

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Federal agency hires DPRK remote worker
-FTC wants to be AI thought police
-NIST seeks AI adoption feedback for CVE
-US Water Cyber Shield Act
-UK removes Chinese cams from Navy drones
-Thailand to "consider" better security after hack
-Romance scammers arrested in Hong Kong
-FBI advises against storing nudes online
-Banned Chrome extensions return
-Serbian state-hacker arrested in Croatia
-The Com member gets years in prison
-UzCERT warns of mass RDP attacks

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Explosion of large DDoS attacks this year
-ShinyHunters claims Metabase hacks
-Kimwolf returns
-Reports on Gunra and DeadLock ransomware, Abyssos RAT, CAV3RN, Aeternum, Camview toolkit
-Insolent Hyena moves from hacktivism to espionage
-Russian info-op aims to redivide Germany
-Lazarus deploys new Windows zero-day
-New Cisco zero-day
-Patch Tuesday is out
-GhostJacking attack
-New Zoomsday vulnerability
-X33fcon 2026 videos
in reply to Catalin Cimpanu

AI assistant hacks gym website: An AI assistant hacked a gym's website after its owner asked it to book an appointment. The agent exploited the website's unsecured API to kick customers from the waiting list and move its owner at the top of the queue. The misbehaving agent was identified as a local OpenClaw instance. [ABC
#infosec #ai
Lorenzo ha ricondiviso questo.

Cisco has patched a zero-day in its ASA, FMC, and FTD firewalls that was exploited in the wild to crash its security appliances: sec.cloudapps.cisco.com/securi…

Microsoft patched a Windows zero-day abused by Lazarus: research.checkpoint.com/2026/s…

reshared this

Lorenzo ha ricondiviso questo.

Zoom has patched a bug that could have allowed an attacker participating in a meeting to run malicious code across all participants

The Zoomsday bug required no interaction from meeting participants and worked across all Zoom OS clients

a.security/blog/asecurity-zoom…

reshared this

Lorenzo ha ricondiviso questo.

The Kimwolf, aka Aisuru, botnet is back online with a new version, surviving a December takedown by the FBI

unit42.paloaltonetworks.com/ki…

reshared this

Lorenzo ha ricondiviso questo.

Mozilla rotates GPG signing subkey for official Firefox and Thunderbird releases after the previous one leaked (it was inadvertently committed to a private GitHub repository)

blog.mozilla.org/security/2026…

reshared this

Lorenzo ha ricondiviso questo.

Russia's Sandworm follows North Korea and Iran and adopts the fake IT job interview as a malware delivery vector

cert.gov.ua/article/6318863

reshared this

Lorenzo ha ricondiviso questo.

Grokipedia Stopped Reviewing Edits in April. It Didn’t Tell Anyone.

But don't worry.... DuckDuckGo will still rank its pages right below Wikipedia anyway

lawfaremedia.org/article/groki…

reshared this

in reply to Catalin Cimpanu

oh dang this is like when DBpedia quit updating

the inadvertent misinformation, it was very bad

@platypus and I wrote about it in scholarsphere.psu.edu/resource… (that bit was Ruth's not mine)

Lorenzo ha ricondiviso questo.

Microsoft to end MV2 extension support in Edge by the end of the year

"To put some numbers around the progress the ecosystem has made, there are only 58 MV2-based extensions in the Edge Add-on Store with any meaningful usage."

blogs.windows.com/msedgedev/20…

reshared this