The Pirate Post ha ricondiviso questo.

LibreOffice batte ogni record di download dopo aver dichiarato di non avere funzionalità basate sull'intelligenza artificiale

LibreOffice 26.8, rilasciato il 26 agosto , è diventato l'aggiornamento più popolare del software.

LibreOffice è un'alternativa gratuita a Microsoft Office presente sul mercato da quasi vent'anni. In una settimana, il programma di installazione è stato scaricato più di un milione di volte, senza contare gli aggiornamenti tramite i repository delle distribuzioni Linux.

Qualcuno potrebbe dire che i miglioramenti al sistema di scrittura e alla tipografia sono un successo tra le ONG, le agenzie governative e gli uffici che utilizzano LibreOffice. Io, però, punto su una "non-funzionalità": l'affermazione che LibreOffice non includa funzionalità di intelligenza artificiale generativa a causa della (mancanza di) privacy della tecnologia.

Il giorno dopo aver celebrato il record di download e l'ampia copertura mediatica, la Document Foundation (TDF), che gestisce il software, ha chiarito la propria posizione in un post intitolato "Sì, l'IA non è più una funzionalità".

L'articolo, firmato da @Italo Vignoli , afferma che TDF "non respinge l'intelligenza artificiale a priori", ma che la tecnologia non soddisfa ancora un elenco esaustivo di principi per essere inclusa di default. Tali principi sono:

manualdousuario.net/en/libreof…

@GNU/Linux Italia

The Stars and Stripes firings look familiar to those behind bars


Last month’s firing of the publisher of Stars and Stripes, as well as an editor and reporter, further cemented the Trump administration’s full-fledged declaration of war against press freedom. To me personally, it stood out from his countless other attacks because I know the dangers this specific form of censorship entails.

I am in my 28th consecutive year of incarceration in the state of Texas. When I first arrived, I enjoyed receiving the prison’s newspaper, The Echo. Each month, there were stories that provided useful information about legal, social, and educational issues that were vastly important to the incarcerated population.

At that time, the Texas prison system was still under federally imposed “special master” supervision as a result of a civil rights lawsuit filed by seven jailhouse lawyers nearly three decades earlier.

In 1972, incarcerated individuals accused the Texas prison system of violating their constitutional rights in numerous ways. The litigation became known as the “Ruiz case” after one of the original plaintiffs, David Ruiz.

This lawsuit resulted in a trial that holds the record as the longest prisoners’ case in the history of American jurisprudence. In 1980, the court found Texas was indeed violating the constitutional rights of people in its care and ordered systemic change.

A year after my arrival in prison, issues of the prison’s newspaper disappeared without explanation.

The Echo was the tool that incarcerated journalists used to keep the incarcerated population — and their loved ones, because it was not uncommon for people to mail news clippings to family members — updated on prison officials’ compliance or lack thereof with the federal mandates.

A year after my arrival, issues of The Echo disappeared without any explanation. In 2003, it resurfaced as a shell of its prior self. Instead of critical coverage, the pages were filled with “feel-good stories” that inaccurately depicted prison life in Texas as the best of all possible worlds.

The old staff had been replaced by a new group of workers subservient to prison officials, who had taken complete control over all editorial decisions. The Echo was no longer independent. It had become — and continued to be — a tool for false government propaganda.

Before the Stars and Stripes firings (which have been paused due to legal proceedings), the newspaper was publishing the kind of reporting that the Echo was known for before its makeover, except for members of the military rather than the incarcerated population.

That changed, according to a lawsuit filed by the fired journalists, when Stars and Stripes angered the Pete Hegseth-led Department of Defense through its reporting on the USS Abraham Lincoln, a 5,000-person aircraft carrier that had been out at sea for a record-setting nine months.

Stars and Stripes was publishing the kind of reporting the prison newspaper was known for. That changed.

Reports revealed that sailors on the military vessel were suffering from low morale as a result of the long deployment and difficult living conditions. Americans read about a shortage of basic supplies, water contamination, broken toilets, disruption in the mail system, and deck safety concerns, leading to deteriorating mental health and suicide attempts. MS NOW and others reported that sailors have actually jumped from the carrier.

The staff at Stars and Stripes — despite knowing the administration was looking for reasons to target them — upheld their journalistic responsibility by reporting accurately to the military American public about the situation on the USS Abraham Lincoln.

But in Trump’s world, which Hegseth also inhabits, an independent press serves no legitimate purpose. If a media outlet’s content does not praise him or demonize and discredit his critics, it’s fake news and counterproductive.

Of course, the removal of the staff at Stars and Stripes is just the latest attack in the administration’s war to eradicate independent media. Hegseth doesn’t only want to control government-funded media — he wants private journalists to swear away their constitutional rights as a condition of attending news conferences. Trump himself has raided journalists’ homes, subpoenaed them and their families, sued them for billions, and targeted them for immigration and other arrests.

In Trump and Hegseth’s world, an independent press serves no legitimate purpose.

Authoritarian regimes, current and past, have shown how brutal a government becomes when press freedoms are restricted. But the Echo’s example shows one does not have to travel back to Nazi Germany or apartheid South Africa to grasp the dangers.

Since the Echo became an instrument for the state, incarcerated people in Texas are exposed daily to inhumanity beyond description, contributing to the same mental health issues the government seeks to cover up by silencing Stars and Stripes. Texas prisons averaged about 56 suicides a year from 2020-23, compared to 28 per year from 2005-19.

Others have turned to extreme substance abuse as an escape. Walking onto any cellblock at any Texas prison can be like taking a stroll down Philadelphia’s infamous Kensington Avenue. Incarcerated people are laid out, unconscious, in a drug-induced stupor. Texas prisons report a nearly 2,500 percent increase in drug overdose deaths in the past seven years alone.

Basic necessities like toilet paper, deodorant, toothpaste, soap, and functioning plumbing are scarce, forcing people without outside sources of funds to resort to all sorts of bizarre measures.

Most importantly, there is no independent press to inform the incarcerated population inside the prison system and help them protect or advocate for their constitutional freedom from cruel and unusual punishment.

Despite the suicide crisis and substance-use epidemic, the cover story for the July issue of the Echo is “Stitches With Love,” a story about a new prison quilting program.

This exemplifies what news content in Stars and Stripes and elsewhere will look like if Trump and Hegseth are successful. Military families may no longer hear about the horrid conditions causing sailors to jump ship, but they’ll get to read all about the activities offered in aircraft carriers’ craft rooms.


freedom.press/issues/the-stars…

The Pirate Post ha ricondiviso questo.

Nach der Landtagswahl in Sachsen-Anhalt wird am Wochenende in dutzenden Städten gegen Rechtsextremismus demonstriert. Die Demos haben unterschiedliche Zielsetzungen, bundesweit werden Zehntausende Menschen erwartet. Ein Überblick.

netzpolitik.org/2026/nach-wahl…

Hegseth is a propaganda flop. Don’t let Congress throw him a lifeline


Defense Secretary Pete Hegseth is obsessed with controlling the narrative. His censorship and propaganda efforts are myriad: lashing out over photographs of himself he doesn’t like, barring reporters from the Pentagon who don’t sign away their First Amendment rights, forcing suspected leakers to take ineffective polygraph tests, undermining the independence of military newspaper Stars and Stripes, and secretly compensating social media influencers who praise him.

But as Guardian columnist Margaret Sullivan recently noted, Hegseth is failing as a propagandist. The Iran war is deeply unpopular, and his approval numbers are far lower than whatever testosterone level he and his insecurities deem unworthy of military service.

Still, Hegseth’s inability to sell the public on alternative facts doesn’t mean Americans are uniquely resistant to spin. It only means Hegseth can’t control the information ecosystem, no matter how many reporters he bans from news conferences. But that could change if politicians of both parties don’t stop supporting measures that undermine journalists and whistleblowers.

Journalists in the U.S. don’t need government permission to report — for now. But there are some things they do need.

Sources willing to come forward.

News outlets that aren’t vulnerable to reliance on the government. (The attacks on Stars and Stripes and other outlets that get federal funding show the limits of statutory guarantees of independence).

And an open internet where information can travel, notwithstanding private actors’ efforts to censor some corners.

When these conditions exist, journalists who turn in their press passes rather than sign loyalty pledges can find scoops in plenty of other ways, most of which would be far more difficult, if not impossible, absent the independent media and open internet.

Hegseth can’t sell the public on alternative facts because he can’t control the information ecosystem.

Officials in other countries without these ingredients have succeeded in pushing propaganda where Hegseth and the rest of the Trump administration have failed, and it’s not because those countries have less courageous journalists, a more gullible public, or more likable censors.

In Russia, independent outlets not controlled by loyal oligarchs have been forced to shut down or relocate abroad. Those who stay face prosecution for even calling the war in Ukraine a war. Many social media companies have been shut down, and Russia has started blocking VPNs that its citizens were using to evade the bans.

By contrast, the Trump administration’s efforts to relabel the war in Iran as anything but have been met with mockery, and anyone with an internet connection can get in on the joke.

In North Korea and Eritrea, the two lowest-ranking countries in Reporters Without Borders’ global press freedom index this year, there are no local journalists to blow the whistle to because reporting anything but authorized propaganda is a crime, punishable by imprisonment in horrid conditions or labor camps.

Those who oppose Trumpian censorship presumably appreciate that the conditions that blunt its impact exist here. And yet, support across both political parties in the U.S. remains strong for crackdowns on government leaks, and increased restrictions and surveillance of the internet.

Even as leaks enable countless important news stories about the administration — on immigration enforcement, the war in Iran, or the fiasco involving Trump’s unsafe Qatari jet — few politicians are standing up for whistleblowers who speak to the press.

We haven’t heard any mea culpas from politicians who supported prosecuting WikiLeaks publisher Julian Assange under the Espionage Act, even after the Trump administration cited Assange’s case to justify raiding the home of a Washington Post reporter in January, seizing terabytes of data.

Even as leaks enable countless important news stories about the administration, few politicians are standing up for whistleblowers.

In fact, last year, despite Trump threatening journalists and sources throughout his campaign, Democratic Sen. Mark Warner made calling whistleblower and Freedom of the Press (FPF) board member Ed Snowden a “traitor” into a litmus test for service in government. Warner hasn’t changed his tune since.

Similarly, lawmakers from both parties have shown a disturbing willingness to support initiatives to make the internet far less free.

Both Democrats and Republicans have cheered legislation that would require adults to submit to invasive age verification in order to read news online, as well as praised the recent legal settlement by Meta that will likely impose similar requirements across a swath of social media companies.

These requirements destroy the anonymity that people rely on to speak, read, and watch freely online. In an era where the feds may show up at your door over what you read, and tech companies may out you for criticizing the government, online anonymity is vital.

Similarly, proposals to repeal or gut Section 230 of the Communications Decency Act to make platforms legally responsible for user content — supported by some politicians from both parties — would do little to stem the tide of lawful but awful online posts. What it would do is push platforms to remove anything that upsets the powerful rather than invest in legal review of an infinite number of posts.

If you don’t like how the government cajoles tech companies into taking down users’ posts that displease it today (or yesterday), this problem will be far worse if platforms are unprotected from civil liability.

Congress should be focused on passing laws that safeguard First Amendment freedoms, rather than supporting measures that will allow Hegseth and his colleagues in the Trump administration to stamp out independent journalism like their authoritarian idols abroad.

Congress should be focused on passing laws that safeguard First Amendment freedoms.

It should pass The Daniel Ellsberg Press Freedom and Whistleblower Act, named after the famed Pentagon Papers leaker and FPF co-founder, which would increase protections for those who expose government wrongdoing.

And it should pass The Privacy Protection Updates Act, which would help put a stop to government raids on reporters.

It should also pass The Subpoena Abuse Prevention Act to rein in administrative subpoenas targeting journalists.

And, finally, it should pass the PRESS Act to stop the government from compelling reporters and tech companies to out whistleblowers.

These are some of the bills that you can urge your lawmakers to support. Otherwise, the consequences for the free press may be far uglier than any bad Hegseth hair day captured by news photographers at the Pentagon.


freedom.press/issues/hegseth-i…

Elezioni e Politica 2026 reshared this.

The Pirate Post ha ricondiviso questo.

I support this proposal. I could also support many variations on the theme. Kudos to the 10 co-authors.
zenodo.org/records/21934115

The gold, green, bronze, hybrid... labels were never a systematic classification. They evolved like the winding streets in the center of an old city. Plus, they're opaque and widely misunderstood.

#GoldOA #GreenOA #OpenAccess #ScholComm

Questa voce è stata modificata (4 giorni fa)
The Pirate Post ha ricondiviso questo.

Dall’autunno 2026 tutti i ricercatori di enti italiani potranno pubblicare su Open Research Europe senza costi


In base alla decisione di cui abbiamo dato notizia qui, da questo autunno i ricercatori che lavorano in istituzioni italiane potranno pubblicare su ORE, piattaforma europea ad accesso aperto che pratica la revisione paritaria aperta, senza costi. Per il momento ORE non è ancora amministrativamente scientifica. Si suppone che l'Anvur cambierà idea - cosa che non muta la circostanza che, in Italia, la scientificità continui a dipendere, più che mai, dal potere esecutivo.

In base alla decisione di cui abbiamo dato notizia qui, da questo autunno i ricercatori che lavorano in istituzioni italiane potranno pubblicare su ORE, piattaforma europea ad accesso aperto che pratica la revisione paritaria aperta, senza costi.

Per il momento ORE non è ancora amministrativamente scientifica. Si suppone che l’Anvur cambierà idea – cosa che non muta la circostanza che, in Italia, la scientificità continui a dipendere, più che mai, dal potere esecutivo.


La notizia è visibile sul sito del ministero, qui. Rimane non risolta, però, una questione strutturale: che, in Italia, a stabilire che cos’è pubblicazione scientifica e che cosa no sia il governo o una sua sempre più diretta emanazione. Il fatto che sulla scientificità di ORE, dopo precedenti diversi, ci si avvii a cambiare idea è un dettaglio che non muta il quadro.
- The post’s content. aisa.sp.unipi.it/il-ministero-…

Questa voce è stata modificata (4 giorni fa)
The Pirate Post ha ricondiviso questo.

⚠️ A report has been released by Europol and the lobby seeking to dismantle all forms of protected communication, titled "Horizon scanning of emerging privacy-enhancing technologies."

What is described merely as a "participatory technology foresight exercise developed by the JRC and Europol to support policymakers and law enforcement" is, in reality, a comprehensive document designed to enable policymakers to eliminate all private citizen communications.

europol.europa.eu/publications…

@privacy

The Pirate Post ha ricondiviso questo.

⚠️ Pubblicato il report di #Europol e della lobby che vuole scardinare tutte le comunicazioni protette: "Analisi prospettica delle tecnologie emergenti per la tutela della privacy"

Un "esercizio partecipativo di previsione tecnologica sviluppato dal JRC e da EUROPOL a supporto dei responsabili politici e delle forze dell'ordine" o un documento più completo messo a disposizione della politica per eliminare ogni comunicazione riservata dei cittadini?

europol.europa.eu/publications…

@privacypride

The Pirate Post ha ricondiviso questo.

Interesting initiative I just became aware of:

#Peerreview is a finite resource, and every review invitation presents a choice about where our time goes. The Diamond Reviewer Pledge asks researchers to commit to reviewing at least one article a year for a #diamond #openaccess journal — free to publish, free to read, and run by the scholarly community. It takes a minute to sign and helps sustain the journals that keep research open to everyone. Learn more and join:

forrt.org/diamond-reviewer

The Pirate Post ha ricondiviso questo.

❗ Nun ist es sicher: noyb wird eine Unterlassungsklage gegen #SCHUFA einbringen. ⚖️ Vor zwei Wochen haben wir diese bereits wegen ihrer #Schattendatenbank abgemahnt.

🧑‍⚖️ Du bist an einer möglichen #Sammelklage interessiert? Trage dich hier ein, um up to date zu bleiben: 👉 schufa.noyb.eu/

Alle weiteren Infos findest du hier: 🔗 noyb.eu/de/schufa-insists-shad…

Questa voce è stata modificata (3 giorni fa)
The Pirate Post ha ricondiviso questo.

Die Hamburger Datenschutzbehörde hat Metas Überwachungsbrille untersucht und kommt zu einem klaren Urteil. Deren Aufnahmeleuchte sei nur „eingeschränkt wahrnehmbar“, die Brille deswegen nur in Ausnahmefällen zulässig.

netzpolitik.org/2026/meta-uebe…

Programma Piratendag 12 septemper


Kom ook… 11.00 uur presentatie van Stefan Dekker over Linux, 11.45 uur presentatie Bart met zijn project Shaer 12.30 uur Leontien over de Provinciale Staten verkiezing 13.00 uur pauze 13.30 uur presentatie Bianca 14.15 uur gezellig samenzijn onder het genot van een drankje 17.00 uur afronden van de dag.

Het bericht Programma Piratendag 12 septemper verscheen eerst op Piratenpartij.

Elezioni e Politica 2026 reshared this.

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Critical ArangoDB Flaws Enable Login Bypass and Root-Level Code Execution
#CyberSecurity
securebulletin.com/critical-ar…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

BlueMoon Exploit Kit Chains Chrome and Windows Zero-Days in Espionage Attacks
#CyberSecurity
securebulletin.com/bluemoon-ex…
The Pirate Post ha ricondiviso questo.

Veradigm Discloses Patient SSNs Exposed After Vendor Credentials Were Stolen
#CyberSecurity
securebulletin.com/veradigm-di…
The Pirate Post ha ricondiviso questo.

Fake Job Interviews Deliver NodeRabbit and PollCat Malware to Software Developers
#CyberSecurity
securebulletin.com/fake-job-in…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

AI Agent Swarm Exploits PaperCut Flaws Across 440 Servers Worldwide
#CyberSecurity
securebulletin.com/ai-agent-sw…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

ClearFake CAPTCHA Campaign Disables EDR to Deploy Crypto Stealer
#CyberSecurity
securebulletin.com/clearfake-c…
The Pirate Post ha ricondiviso questo.

MapLibre Sanitizer Bug Puts 2.7 Million Sites at Risk of Zero-Click Code Execution
#CyberSecurity
securebulletin.com/maplibre-sa…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

CVE-2026-82533: la falla in DeepSeek Harness che lasciava agli agenti AI le chiavi della propria sandbox
#tech
spcnet.it/cve-2026-82533-la-fa…
@informatica


CVE-2026-82533: la falla in DeepSeek Harness che lasciava agli agenti AI le chiavi della propria sandbox


Gli agenti AI per la scrittura di codice promettono di automatizzare interi flussi di sviluppo, ma per farlo hanno bisogno di eseguire comandi shell, modificare file e talvolta chiamare API esterne in totale autonomia. Per questo motivo i tool più seri li fanno girare dentro una sandbox: un ambiente isolato che limita cosa l’agente può leggere, scrivere o eseguire, con un sistema di approvazione umana per le operazioni più rischiose. Una vulnerabilità critica scoperta in DeepSeek Harness, il tool open source di DeepSeek per eseguire coding agent in locale, dimostra però quanto sia fragile questo modello quando il “guardiano” della sandbox è raggiungibile senza autenticazione. Con un singolo comando shell, l’agente stesso poteva disattivare le proprie restrizioni — bypassando sia il file-sandbox sia i prompt di approvazione.

Cos’è DeepSeek Harness e come funziona la sua sandbox


DeepSeek Harness espone un’interfaccia web locale che funge da pannello di controllo per la sessione dell’agente: consente di monitorare l’esecuzione, approvare le azioni sensibili e, soprattutto, gestisce lo stato di sicurezza della sandbox. Come molti tool della stessa categoria, l’harness fornisce all’agente stesso l’indirizzo di questa interfaccia e l’identificativo di sessione, così che possa interagirci per richiedere operazioni o notificare eventi.

È proprio questa combinazione — interfaccia locale privilegiata + agente che ne conosce i dettagli di accesso — ad aver reso possibile l’attacco.

Il meccanismo della vulnerabilità (CVE-2026-82533)


La falla, tracciata come CVE-2026-82533 con un punteggio CVSS 9.4 (critico) e classificata come CWE-807 (“Reliance on Untrusted Inputs in a Security Decision”), nasce dalla combinazione di tre debolezze distinte:

  • Nessuna autenticazione sull’API web locale del control-plane: chiunque potesse raggiungere l’endpoint poteva invocarlo senza credenziali.
  • Validazione errata dell’origine della richiesta: il servizio si fidava del valore Host fornito dal client invece di verificare l’effettiva origine della connessione TCP (host header spoofing).
  • Superficie di attacco esposta all’agente stesso: dato che l’harness comunica all’agente indirizzo e session ID dell’interfaccia, un agente compromesso (ad esempio tramite prompt injection da codice o output di terze parti) aveva già tutto ciò che serviva per attaccare il proprio control-plane.

Sfruttando lo spoofing dell’header Host, un attore malevolo — o l’agente stesso se manipolato — poteva raggiungere l’interfaccia in loopback e inviare una richiesta che impostava la sessione in modalità danger-full-access. Questo stato elimina la sandbox sul filesystem e disattiva i prompt di conferma per le operazioni sensibili. Con questo accesso era inoltre possibile invocare direttamente endpoint privilegiati come commands/execute e leggere le conversazioni salvate in sessione, senza mai fornire una credenziale.

Versioni interessate e correzione


Le versioni 0.1.1-rc.2 e precedenti sono vulnerabili. Il fix introduce un’autenticazione a token monouso per l’interfaccia locale: al momento dell’avvio, il tool stampa un token che il browser scambia con un cookie firmato, richiesto da quel momento per ogni chiamata al control-plane.

VersioneStato
≤ 0.1.1-rc.2Vulnerabile
0.1.2-alpha.1Fix pubblicato solo su GitHub (non su npm)
0.1.2-alpha.2Prima release corretta pubblicata su npm
0.1.2-rc.1 (corrente)Consigliata per l’aggiornamento

È importante notare il dettaglio sulla distribuzione: chi installa il pacchetto da npm senza controllare la versione esatta rischiava di restare esposto anche dopo l’annuncio della patch, perché la prima correzione non era disponibile su quel registro.

Non è un caso isolato: un problema architetturale


La vulnerabilità era già stata segnalata autonomamente dalla community su GitHub Discussions il 13 e 14 agosto, prima ancora del report ufficiale a VulnCheck (24 agosto) da parte di OX Research. Analisi successive hanno evidenziato pattern simili — API di controllo locali prive di autenticazione solida, affidamento eccessivo sull’header Host o su altri dati forniti dal client — anche in altri framework per agenti AI, tra cui LangChain, CrewAI e Google ADK. Il messaggio per chi lavora con questi strumenti è chiaro: la logica di orchestrazione e di esecuzione tool-calling degli agenti AI è oggi un’area con superficie di attacco ancora immatura, non un caso isolato di un singolo progetto.

Come proteggersi


Per chi gestisce infrastrutture dove girano coding agent locali (server di sviluppo condivisi, VM CI/CD, workstation con accesso a repository sensibili) valgono alcune raccomandazioni pratiche:

  • Aggiornare immediatamente DeepSeek Harness alla versione 0.1.2-rc.1 o successiva, verificando che il pacchetto installato provenga effettivamente da npm e non da una cache vecchia.
  • Verificare l’esposizione delle API locali: controllare che le porte del control-plane non siano raggiungibili da reti diverse dal loopback, e che non ci siano tunnel, reverse proxy o port-forwarding che le espongano inavvertitamente (es. tramite VS Code Remote, SSH -L o container con rete condivisa).
  • Rivedere le sessioni e le conversazioni eventualmente esposte durante il periodo di vulnerabilità, specialmente se contenevano segreti, token o codice proprietario.
  • Applicare il principio del minimo privilegio agli agenti: eseguirli con utenti dedicati a permessi limitati, evitando di lanciarli con lo stesso utente che ha accesso a credenziali cloud o chiavi SSH.
  • Non fidarsi della sola autenticazione basata su header HTTP per servizi locali critici: preferire token generati a runtime, socket Unix con permessi ristretti, o mutui TLS quando possibile.


Conclusione


Il caso DeepSeek Harness è un promemoria utile per chi sta integrando agenti AI autonomi nei propri flussi di sviluppo o di sistema: la sandbox è utile solo quanto il meccanismo che la protegge, e un’interfaccia di controllo locale non autenticata è, di fatto, una porta sul retro. Con CVSS 9.4 e un percorso di sfruttamento che richiede solo un comando HTTP verso localhost, questa vulnerabilità mostra come la sicurezza degli agenti AI vada trattata con lo stesso rigore — se non maggiore — riservato a qualsiasi altro servizio che espone comandi privilegiati in rete, anche se “in rete” significa solo 127.0.0.1.

Fonte: The Hacker News e VulnCheck Advisory, via 4sysops.


The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

N0va Phishing Kit Hijacks Real Microsoft Logins to Steal Session Tokens
#CyberSecurity
securebulletin.com/n0va-phishi…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ Xinbi Guarantee: il Tesoro USA smantella l’erede da 24 miliardi di dollari di Huione Guarantee
#CyberSecurity
insicurezzadigitale.com/xinbi-…

@informatica


Xinbi Guarantee: il Tesoro USA smantella l’erede da 24 miliardi di dollari di Huione Guarantee


Si parla di:
Toggle

Il Tesoro USA e il Dipartimento di Giustizia hanno colpito uno dei più grandi mercati neri del crimine informatico mai smantellati: Xinbi Guarantee, piattaforma su Telegram che secondo la società di blockchain intelligence Elliptic ha movimentato almeno 24 miliardi di dollari in transazioni criminali, diventando il secondo marketplace illecito più grande della storia dopo il suo predecessore, Huione Guarantee.

L’azione, annunciata il 9 settembre 2026, unisce sanzioni OFAC del Tesoro e un mandato di sequestro del DOJ contro i canali Telegram della piattaforma, con il congelamento di 52,8 milioni di dollari distribuiti su 52 wallet collegati a Xinbi e alla sua rete di venditori, più altri 12 milioni sequestrati da due portafogli usati per raccogliere i pagamenti dei fornitori. Un colpo pesante, ma che arriva dentro un ecosistema criminale che si è dimostrato capace di rigenerarsi nel giro di poche settimane.

Dall’ombra di Huione: la “garanzia” per il crimine informatico asiatico


Per capire cos’è Xinbi bisogna partire dal suo predecessore. Huione Guarantee era il marketplace di riferimento per il cybercrime cinese e del sud-est asiatico: una sorta di eBay del crimine organizzato digitale, dove migliaia di venditori offrivano servizi di riciclaggio, dati personali rubati, strumenti di deepfake e infrastrutture per le truffe romantico-finanziarie note come pig butchering. Il meccanismo era quello dell’escrow: la piattaforma “garantiva” (da cui il nome) che acquirente e venditore si sarebbero scambiati denaro e servizi senza fregature, funzionando come camera di compensazione per un’economia criminale che altrimenti non potrebbe fidarsi di sé stessa.

Sotto la pressione internazionale, Telegram ha chiuso i canali di Huione, che nella sua vita operativa aveva gestito circa 31 miliardi di dollari. Ma lo spazio lasciato libero non è rimasto vuoto: Xinbi Guarantee, fondata nel 2022 e già operativa in parallelo, ne ha semplicemente raccolto l’eredità, arrivando a ospitare oltre 4.600 fornitori di servizi criminali al momento dell’intervento delle autorità USA.

Come funzionava: USDT, Tron e un catalogo del crimine su abbonamento


Operativamente, Xinbi elaborava pagamenti esclusivamente in Tether USDT sulla blockchain Tron, lo standard de facto per il riciclaggio su larga scala in Asia grazie a commissioni contenute e velocità di transazione. Sul catalogo della piattaforma comparivano servizi di riciclaggio di denaro, vendita di dati personali rubati (dai documenti d’identità ai dataset finanziari), strumenti di deepfake per superare le verifiche KYC dei servizi finanziari, e il coordinamento di intere operazioni di pig butchering — le truffe sentimentali-finanziarie che, spesso gestite da lavoratori vittime di tratta negli hub del sud-est asiatico, hanno drenato miliardi di dollari da vittime in tutto il mondo.

Il Tesoro ha collegato la piattaforma a due entità già designate in precedenti round di sanzioni: Jin Bei Group Co., Ltd. e la galassia di Prince Group TCO, organizzazione transnazionale che il governo statunitense associa ai compound di scam nel sud-est asiatico. Non solo: secondo le autorità, la piattaforma sarebbe stata utilizzata anche da hacker nordcoreani per monetizzare parte dei proventi delle loro operazioni, un dettaglio che conferma quanto questi mercati neri funzionino da infrastruttura condivisa tra cybercrime finanziariamente motivato e attori state-sponsored.

Il ruolo di Tether e la reazione a caldo degli operatori


Un elemento interessante dell’operazione è la collaborazione diretta di Tether, che ha congelato i due wallet usati per i pagamenti ai fornitori non appena notificata dalle autorità. La reazione della rete criminale è stata immediata: secondo i dati raccolti dagli analisti, Xinbi ha convertito rapidamente circa 2,8 milioni di dollari di USDT residuo in USDD, uno stablecoin alternativo meno soggetto a congelamento centralizzato — segno che gli operatori di queste piattaforme monitorano attivamente il rischio regolatorio e sono pronti a migrare liquidità in tempo reale non appena percepiscono una minaccia.

Un pattern che si ripete: la geografia del “whack-a-mole”


Il caso Xinbi si inserisce in una traiettoria di enforcement che il DOJ ha intensificato dalla creazione, a novembre 2025, di una task force dedicata alle truffe online, seguita ad agosto 2026 dallo smantellamento di 13 centri operativi in Madagascar collegati alla stessa economia criminale. Ma la storia di Huione che rinasce come Xinbi suggerisce che sequestrare wallet e chiudere canali Telegram, per quanto necessario, non basta a smontare l’infrastruttura di fondo: finché esisteranno compound fisici nel sud-est asiatico dove la manodopera (spesso ridotta in schiavitù) continua a operare le truffe, un nuovo “Guarantee marketplace” è pronto a emergere entro poche settimane dal precedente.

Due righe per i difensori


  • Le aziende che offrono servizi finanziari o KYC dovrebbero considerare la presenza di strumenti deepfake commerciali a basso costo come rischio concreto e non più teorico nei flussi di onboarding remoto.
  • I team anti-frode dovrebbero monitorare pattern di transazione USDT-TRON verso wallet neo-creati come indicatore di possibile riciclaggio legato a piattaforme di questo tipo.
  • Le organizzazioni con dipendenti esposti a contatti social/dating non richiesti dovrebbero rafforzare la formazione su pig butchering, che resta uno dei vettori di frode finanziaria in più rapida crescita a livello globale.
  • Il monitoraggio delle sanzioni OFAC aggiornate resta essenziale per i compliance team con esposizione a controparti asiatiche in criptovalute.


Indicatori e riferimenti

Piattaforma: Xinbi Guarantee (Telegram-based marketplace, fondata 2022)
Predecessore: Huione Guarantee (chiuso, ~31 miliardi USD movimentati)
Volume stimato Xinbi: almeno 24 miliardi USD in transazioni
Fornitori attivi al momento del takedown: 4.600+

Asset sequestrati/congelati:
- 52,8 milioni USD da 52 wallet (rete Xinbi + merchant)
- 12 milioni USD da 2 wallet di raccolta pagamenti

Valuta principale: USDT (Tether) su blockchain TRON
Migrazione post-freeze: ~2,8 milioni USD convertiti in USDD

Entità sanzionate OFAC (9 settembre 2026):
- Jin Bei Group Co., Ltd.
- Prince Group TCO

Azioni: sanzioni Treasury/OFAC + mandato di sequestro DOJ sui canali Telegram
Collaborazione: Tether (congelamento wallet)

Bastian’s Night #493 September, 10th


Every Thursday of the week, Bastian’s Night is broadcast from 21:30 CEST/DST.

Bastian’s Night is a live talk show in German with lots of music, a weekly round-up of news from around the world, and a glimpse into the host’s crazy week in the pirate movement.


If you want to read more about @BastianBB: –> This way


piratesonair.net/bastians-nigh…

Elezioni e Politica 2026 reshared this.

The Pirate Post ha ricondiviso questo.

🍪 "The industry, which was once vehemently opposed to the introduction of #cookie banners, now views their abolition with scepticism. Not least because the vast majority of users 'consent' to the collection of personal information." (from German)

Continue reading 🔗 orf.at/stories/3441633/

🤝 We need YOUR help to #KillTheCookieBanner! 🔗 killthecookiebanner.eu/

The Pirate Post ha ricondiviso questo.

Die deutsche Version der EUDI-Wallet, die im Januar 2027 starten soll, wird „d‑you“ heißen. Bis dahin muss das Digitalministerium aber noch Probleme bei der IT-Sicherheit lösen. Bei „Restrisiken“ könnte die Bundesregierung den Start verschieben.

netzpolitik.org/2026/neuer-nam…

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🍪 Tired of misleading cookie banners? The #EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.

🥊 Unfortunately, the tracking industry is pushing back – and so far, they’ve been successful. Now we need YOUR help to #KillTheCookieBanner!

👉 To find out how, as well as read the joint open letter, visit the coalition website killthecookiebanner.eu

The Pirate Post ha ricondiviso questo.

☕ CYBERBRIEFING MATTUTINO — Giovedì 10 settembre 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

The Pirate Post ha ricondiviso questo.

Mit ihrem Digitalen Omnibus will die EU-Kommission vor allem der Wirtschaft das Leben versüßen. Zu einem ihrer Vorschläge zählt jedoch auch, die vermaledeiten Cookie-Banner weitgehend aus der Welt zu schaffen. Dagegen läuft die Werbewirtschaft Sturm und bekommt nun ihrerseits Gegenwind zu spüren.

netzpolitik.org/2026/digitaler…

in reply to netzpolitik.org

The media in this post is not displayed to visitors. To view it, please go to the original post.

mastodon.social/@noybeu/117246…


🍪 Tired of misleading cookie banners? The #EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.

🥊 Unfortunately, the tracking industry is pushing back – and so far, they’ve been successful. Now we need YOUR help to #KillTheCookieBanner!

👉 To find out how, as well as read the joint open letter, visit the coalition website killthecookiebanner.eu


in reply to netzpolitik.org

Die Werbeindustrie ist milliardenschwer. Es wäre naiv gewesen zu denken, dass es da keinen Widerstand gäbe. Zudem hat die Industrie immense Ressourcen für Lobbyisten.
Ich glaube nicht, dass die EU sich in dem Punkt für die Menschen durchsetzen wird, eher dem Heulen der Industrie nachgibt, wie immer.
Ich würde es mir trotzdem wünschen, denn die Werbeindustrie ist eins der Undinge im Internet, neben früher der Email-Spam-Flut und aktuell den ganzen KI-Bots.
Questa voce è stata modificata (4 giorni fa)
The Pirate Post ha ricondiviso questo.

OpenAI avrebbe giocato sporco sul problema della dimostrazione completa del problema di esistenza e fluidità di Navier–Stokes


Il professore di matematica della New York University Tristan #Buckmaster ha annunciato martedì tre dimostrazioni con una scoperta preliminare su uno dei principali problemi irrisolti della matematica teorica. I risultati, realizzati in collaborazione con il matematico di #Anthropic Levent #Alpöge e utilizzando modelli di intelligenza artificiale Codex e Claude, sono significativi di per sé — ma sono anche accompagnati da un'insolita controversia che circonda i tentativi di OpenAI di risolvere lo stesso problema.

Secondo la dichiarazione, un'iniziativa parallela di #OpenAI si è basata sul loro lavoro prima che diventasse pubblico, dando origine a un groviglio di rivalità accademiche e affermazioni contrastanti.

techcrunch.com/2026/09/08/open…

@matematica

The Pirate Post ha ricondiviso questo.

Howto tecnico per salvare i tuoi dati sui servizi #AutisticiInventati

Il post di @cavallette

Nei prossimi 10 giorni tutti i servizi sui server Autistici/Inventati saranno spenti.

Questo significa che tutte le mail smetteranno di funzionare, quindi se avete utilizzato le nostre caselle di posta per registrarvi su servizi vari online dovete al più presto cambiare queste mail.

Di seguito trovate indicazioni su come esportare dati per i vari servizi presenti sulla infrastruttura di A/I.

cavallette.noblogs.org/2026/09…

@Pirati Europei

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Wo ich schon mal beim Spenden bin, hat @netzpolitik_feed für seine Arbeit auch Unterstützung bekommen.
Questa voce è stata modificata (5 giorni fa)

DOJ drops appeal of wiretapping counts against journalist Tim Burke


FOR IMMEDIATE RELEASE:

New York, Sept. 9, 2026 — The Department of Justice moved today to dismiss its appeal of a lower court decision that rejected seven felony wiretapping counts against Florida-based independent journalist Tim Burke.

Burke was indicted in 2024 after he exposed unaired outtakes of antisemitic remarks from a Fox News interview with musician Ye, formerly known as Kanye West. The government raided Burke’s newsroom — seizing dozens of pieces of equipment, many of which remain in FBI custody — and charged him with various offenses under the Wiretap Act and the Computer Fraud and Abuse Act. In September 2025, a federal trial court dismissed the Wiretap Act counts, holding that the government’s reading of the statute was overbroad.

The following can be attributed to Freedom of the Press Foundation (FPF) Chief of Advocacy Seth Stern:

“By confiscating most of Tim Burke’s newsroom equipment for years and getting multiple extensions in court before ultimately dropping its appeal, the DOJ has successfully held Burke’s journalism hostage and used the legal system to punish him for reporting on a clearly newsworthy issue.

“Prosecutors were right to drop their appeal of the Wiretap Act counts, but they’re wrong to continue to pursue other charges to punish a journalist who exposed antisemitism.

“Perhaps most disturbing is the DOJ’s use of the Computer Fraud and Abuse Act, a vague, ambiguous law that would criminalize routine journalism if the government had its way. The DOJ should not stop with dismissing this appeal. It must drop all of the charges against Tim Burke.”

Freedom of the Press Foundation and a coalition of press freedom organizations previously filed an amicus brief in support of Burke’s motion to dismiss the Wiretap Act counts.

Please contact us if you would like further comment.


freedom.press/issues/doj-drops…

Elezioni e Politica 2026 reshared this.

Meta ha impiegato giorni per rimuovere gli annunci contenenti materiale di abuso sessuale su minori (CSAM) generato dall'intelligenza artificiale su Facebook e Instagram.

Alcuni annunci presentavano foto di bambini veri, tra cui una foto stampa di un giovane membro di una famiglia reale europea e immagini rubate da un popolare profilo Instagram di una ragazza preadolescente considerata un'influencer.
In un'indagine pubblicata martedì, il Tech Transparency Project (TTP) ha riferito che quest'anno Meta non è riuscita a rilevare 332 annunci contenenti CSAM. La “stragrande maggioranza” degli annunci pubblicizzava app di intelligenza artificiale prodotte in Cina, mentre molti annunci pubblicizzavano le cosiddette app “nudify” che facilitano l’uso dell’intelligenza artificiale da parte di malintenzionati e alterano digitalmente le immagini dei bambini.

arstechnica.com/tech-policy/20…

reshared this

The Pirate Post ha ricondiviso questo.

Vincitori del premio EFF 2026: #AccessNow, #7amleh – Centro arabo per la promozione dei social media, #DeFlock e #NewMediaRights

Riconosciuti contributi tecnici, sociali, economici o culturali specifici e sostanziali in diversi campi tra cui giornalismo, arte, accesso digitale, legislazione, sviluppo tecnologico e diritto, per il loro fondamentale lavoro nel garantire che la tecnologia supporti la libertà, la giustizia e l'innovazione per tutte le persone.

eff.org/deeplinks/2026/09/2026…

@pirati@feddit.it