Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

I’m not surprised that SBOM adoption is so low, almost all the efforts around SBOMs have been compliance theatre, not actually tackling the hard work of working out which software is being packaged.

There’s also zero incentives for open source to generate or use sboms, it’s just companies trying to sell products based on EU directives.

For developers package managers and lockfiles do almost everything they need.


SBOM getting no love from companies

Adoption still very low

enisa.europa.eu/publications/s…


reshared this

Lorenzo ha ricondiviso questo.

I Could've Rickrolled the FIFA World Cup. All I Needed Was My ID
L: bobdahacker.com/blog/fifa-hack
C: news.ycombinator.com/item?id=4…
posted on 2026.06.16 at 01:23:42 (c=1, p=3)

reshared this

Lorenzo ha ricondiviso questo.

Zitron just reported that OpenAI lost $38.5 billion dollars in 2025:

wheresyoured.at/exclusive-open…

Questa voce è stata modificata (6 giorni fa)

VirtualBox 7.2.10 introduce il supporto iniziale per Linux Kernel 7.1

@GNU/Linux Italia

linuxeasy.org/virtualbox-7-2-1…

VirtualBox 7.2.10 migliora la compatibilità Linux con supporto iniziale al kernel 7.1, correzioni per CentOS 10 e novità per Wayland
L'articolo VirtualBox 7.2.10 introduce il supporto iniziale per Linux Kernel 7.1 proviene da Linux Easy.
E' vietato riprodurre

Mozilla Thunderbird 152 rafforza la sicurezza di Gmail e migliora l’esperienza d’uso

@GNU/Linux Italia

linuxeasy.org/mozilla-thunderb…

Thunderbird 152 migliora sicurezza, compatibilità Gmail, gestione email e calendario con numerose correzioni e ottimizzazioni
L'articolo Mozilla Thunderbird 152 rafforza la sicurezza di Gmail e migliora l’esperienza d’uso proviene da

dnstrace analisi pratica del tracciamento DNS su Linux

@GNU/Linux Italia

linuxeasy.org/dnstrace-analisi…

Guida a dnstrace: cos’è, come funziona e perché è utile per analizzare la risoluzione DNS in modo preciso e leggibile.
L'articolo dnstrace analisi pratica del tracciamento DNS su Linux proviene da Linux Easy.
E' vietato riprodurre questo articolo

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-China arrests members of Silver Fox cybercrime group
-EU to help Ukraine in major cyberattacks
-MS-ISAC loses 70% of members
-SBOM still not widely adopted
-Infosec execs call for lifting Anthropic ban
-Cyberattack hits Iranian banks
-Fire department sues security firm over breach
-Crypto-heists at Raydium and Aztec Connect
-Hacker abuses Australian journalists
-Membership of Thiel's Dialog secret group leaks online

Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS578/

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Multiple US states launch OpenAI probe
-New Athena project to secure FOSS with AI
-Roblox launches age-based accounts
-Violent and hateful speech explodes on Facebook
-Australia plans Essential Eight update
-DGSI ends Palantir contract
-France to stop certifying non PQC products
-Estonia to quarantine emails from Russian email domains
-India temp-bans Telegram over exam cheating
-UK bans social media for kids under 16
-Russia arrests suspects who registered accounts on behalf of Ukrainians

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Server of Ababil of Minab hacker group leaks its content
-Malicious JetBrains IDE plugins found in the wild
-FTC reports $3.5b loses to imposter scams
-New i-SOON malware
-New malware: Rokarolla, GlassWASM, Backdoor.Turn, Scales, Potemkin loader
-New UNC6508 group targets REDCap servers
-New Cisco SD-WAN zero-day
-New LiteSpeed zero-day
-CVE program on pace for record year
-New SearchLeak vulnerability
-Hacker hijacks half of Monero's P2Pool
Questa voce è stata modificata (5 giorni fa)
Lorenzo ha ricondiviso questo.

An attacker hijacked the mining pools for more than half of the Monero P2Pool mining network last week

old.reddit.com/r/Monero/commen…

github.com/SChernykh/p2pool/se…

reshared this

KDE Plasma 6.7 Rilasciato, tutte le novità del desktop Linux che punta su usabilità, controllo e rifinitura

@GNU/Linux Italia

linuxeasy.org/kde-plasma-6-7-r…

KDE Plasma 6.7 porta più controllo, nuove funzioni per Wayland, notifiche aggiornate e miglioramenti pratici per l’uso quotidiano
L'articolo KDE Plasma 6.7 Rilasciato, tutte le novità del desktop Linux che punta su usabilità, controllo e

Ubuntu Touch 24.04-2 Beta punta su compatibilità web e funzioni più moderne

@GNU/Linux Italia

linuxeasy.org/ubuntu-touch-24-…

Ubuntu Touch 24.04-2 Beta migliora Morph Browser, aggiunge funzioni pratiche e amplia la compatibilità su dispositivi selezionati.
L'articolo Ubuntu Touch 24.04-2 Beta punta su compatibilità web e funzioni più moderne proviene da Linux

Ubuntu Touch 24.04-2 Beta punta su compatibilità web e funzioni più moderne

@GNU/Linux Italia

linuxeasy.org/ubuntu-touch-24-…

Ubuntu Touch 24.04-2 Beta migliora Morph Browser, aggiunge funzioni pratiche e amplia la compatibilità su dispositivi selezionati.
L'articolo Ubuntu Touch 24.04-2 Beta punta su compatibilità web e funzioni più moderne proviene da Linux

Scade il certificato Secure Boot Microsoft per Linux: cosa cambia davvero

@GNU/Linux Italia

linuxeasy.org/scade-certificat…

Il certificato Secure Boot Microsoft del 2011 per Linux scade a giugno 2026, ma i sistemi moderni continueranno ad avviarsi senza problemi.
L'articolo Scade il certificato Secure Boot Microsoft per Linux: cosa cambia davvero proviene

Lorenzo ha ricondiviso questo.

There's been 46% more vulnerabilities reported this year than initially expected, and the FIRST team has now updated its 2026 CVE total projection to 66,000

first.org/newsroom/releases/20…

Questa voce è stata modificata (5 giorni fa)

reshared this

GNU Linux-Libre 7.1 disponibile: il kernel pensato per la massima libertà software

@GNU/Linux Italia

linuxeasy.org/gnu-linux-libre-…

GNU Linux-Libre 7.1 arriva basato sul kernel Linux 7.1 con aggiornamenti ai driver, supporto Rust migliorato e rimozione del codice proprietario
L'articolo GNU Linux-Libre 7.1 disponibile: il kernel pensato per la massima libertà software

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

SBOM getting no love from companies

Adoption still very low

enisa.europa.eu/publications/s…

reshared this

in reply to Catalin Cimpanu

I think that's because getting an SBOM is like the dog catching the car. Great, well done, but now what? You can plug it into a CVE feed, but when it reports there's a vuln in a dep, you can't tell if you're actually vulnerable, and you can't fix it, all you can do is hassle the vendor, probably just clogging their support channels alongside a hundred other customers all asking the same question.
Lorenzo ha ricondiviso questo.

🇬🇧 British police say they stopped the far-right activist Tommy Robinson and seized his phones as he returned from a trip to #Russia

theguardian.com/uk-news/2026/j…

reshared this

Lorenzo ha ricondiviso questo.

How Brexit has made Britain poorer – in charts

As the 10th anniversary of the Brexit vote approaches, the verdict on Britain’s economic performance is clear: voting to leave has resulted in severe costs for households and businesses.

theguardian.com/politics/2026/…

reshared this

Lorenzo ha ricondiviso questo.

5.3M-year-old deep-sea whale necropolis in the Diamantina Zone
L: nature.com/articles/s41586-026…
C: news.ycombinator.com/item?id=4…
posted on 2026.06.13 at 22:01:00 (c=0, p=4)

reshared this

Lorenzo ha ricondiviso questo.

Since June 1 2026, less than two weeks ago, Cloudflare has protected at least 100,000 newly observed or newly active domains that have earned a 100 risk score from us, meaning they are blocklisted by a third party.

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Arch Linux supply chain attack hits 1,900+ AUR packages
-FISA S702 expires for the first time since 2008
-US puts exports controls on Anthropic
-FBI takes down Chinese PhaaS
-Major supply chain attack hits WP ecosystem
-Dilian flaunts Predatorgate evidence
-UK police ask Apple for help with stolen phones
-FBI has a secret town
-US urges NATO allies to replace Huawei gear
-Vietnam arrests scam group
-Conti member pleads guilty

Podcast: risky.biz/podcasts/
Newsletter: news.risky.biz/risky-bulletin-…

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-US disrupt deepfake porn service
-Cluster of 150 malicious Chrome extensions
-MeowProject forced to relocate after getting hacked
-New OnyxC2 and TonRAT malware
-ProxyCB botnet is still alive
-All the Shai-Hulud variants
-BlackCore disinfo firm was active in more countries
-Ghostwriter starts targeting personal Gmails
-Velvet Ant hides in a company's network for a decade
-Famous Chollima's Google Docs campaign
-Maine disables data breach portal
-New batch of ShinyHunters victims

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Novo Nordisk discloses breach
-Ransomware group claims Nintendo hack
-Humanity Protocol hacked for $36m
-GSG K12 group gets hacked
-ICO to investigate smart TV makers
-GlobalSign revokes certs for Russian companies
-Bug deletes all Ziggo password vaults
-Edge moves to two-week release cycle
-Splunk forgets about authentication
-AMD finally fixes update hijack bug
-New ITScape and BUMSRAKETE vulnerabilities
-GreatXML Bitlocker bypass
-.vuln TLD proposal
in reply to Catalin Cimpanu

"GlobalSign told Russian partners it is complying with new CA/B Forum rules passed in May."
This seems odd. As far as I can tell, section 3.2.2.12.2 in the EV Requirements has been unchanged since around 2022, so what is actually new? RBC mentions a document on the CAB site that came into effect in May, but I might be too confused to find it.
Questa voce è stata modificata (6 giorni fa)
in reply to Dr. Christopher Kunz

This piece has a link to CAB:

altusintel.com/public-yyr53j/?…

But I don't know if that's the exact one

Questa voce è stata modificata (6 giorni fa)
in reply to Catalin Cimpanu

Yeah, these are the EV Requirements, and there's a version from May 5. However, it just removes three commas in section 3.2.2.12.2. cku.gt/9A1TL
Contrary to altusintel's opinion, the section (albeit with different numbering) has been in the requirements since their inception in 2007.
That's why I'm wondering how RBC would frame this as a recent development and why GlobalSign specifically is using this as a reason to start revoking _now_.
Questa voce è stata modificata (6 giorni fa)
in reply to Catalin Cimpanu

I think @izby might be alluding to this recent change in LE's subscriber agreement: letsencrypt.org/documents/LE-S…
This pertains only to new certificates, though. As far as I know, there is no revocation going on for LE certificates in Russia.
Weird coincidence though - it would seem like someone reminded the certificate issuers in the CA/B that they are bound by US and internaional law.
Lorenzo ha ricondiviso questo.

KPMG pulls report on AI usage due to apparent hallucinations
L: techcrunch.com/2026/06/13/kpmg…
C: news.ycombinator.com/item?id=4…
posted on 2026.06.14 at 10:01:35 (c=2, p=6)

reshared this

Lorenzo ha ricondiviso questo.

a Métis woman noticed crows circling and dive bombing around a particular house. one of them had gotten stuck in an eavestrough, and no one had a ladder long enough to save it. she spied a fire engine nearby and got firefighters to rescue the crow, then she took it to the wildlife veterinarian. it held onto her finger en route, and hasn't forgotten who saved its life. she's gotten at least half a dozen thank-you gifts from other crows 😭🖤🐦‍⬛ ctvnews.ca/vancouver/sawatsky-…

reshared this

ChromaLeon: colori dinamici in GNOME per un desktop più coerente

@GNU/Linux Italia

linuxeasy.org/chromaleon-color…

ChromaLeon sincronizza colori e icone di GNOME con lo sfondo, migliorando coerenza visiva, app e temi in modo automatico.
L'articolo ChromaLeon: colori dinamici in GNOME per un desktop più coerente proviene

Paolo Redaelli reshared this.