The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🔒 To continue our work towards a more #privacy-friendly future, noyb requires stable, long-term funding. Individuals like yourself can play an integral part in this task by joining noyb as a #SupportingMember. 🧩

Follow the link to learn more 👉 noyb.eu/en/support-us

reshared this

Evaluating the Digital Networks Act: The European Pirates’ Consultation Input


Explore, Enhance, and Include – these three principles capture the broader ambitions of the Digital Networks Act (DNA), a cornerstone of the European Union’s Digital Decade vision for 2030. The proposal seeks to modernize Europe’s digital infrastructure, accelerate connectivity, and create a more integrated telecommunications market across Member States. However, as the DNA moves from policy ambition toward implementation, it is time to introduce another dimension: Evaluation.

From a policy and administrative perspective, the Digital Networks Act is designed to improve the internet and communication across Europe. It isa plan to strengthen Europe’s digital infrastructure – faster, stronger, safer, and more consistent across all EU countries.

The EU believes that technologies such as AI, cloud computing, smart cities, self-driving vehicles, remote healthcare, and advanced manufacturing require better digital networks. The DNA aims to create those foundations.

As the DNA is progressing towards legislative procedure, the question now is not what the DNA wants to achieve, but whether it can actually deliver on its goals. Feedback from industry, regulators, civil society, and public authorities highlights several technical, administrative, and economic challenges that could impact the implementation of DNA. Looking at these gaps is key to seeing whether the DNA can truly create a connected, competitive, and integrated digital Europe.

After carefully reviewing the proposal and the consultation process, the European Pirate Party has sent its response to the European Commission. Our policy team aims to help the discussion by highlighting implementation risks, raising concerns that may have been overlooked, and suggesting ways to improve the DNA so it meets its goals while protecting competition, digital rights, transparency, and equal access to connectivity.

From Vision to Reality


The Digital Networks Act is one of the biggest changes to European telecommunications in recent years. It aims to simplify regulations, boost investment in fiber and new networks, support cross-border operations, and help Europe compete in the global digital economy.

The European Pirate Party sees these goals as important. Reliable, affordable, and secure connectivity is now essential for taking part in modern society. Digital infrastructure supports everything from education and healthcare to economic growth and democracy.

However, ambitious laws also need to work in practice. During the consultation, stakeholders often raised concerns that, if left unaddressed, could weaken the proposal.

Key Issues Identified in Our Submission


  • Protecting the Open Internet and Democratic Oversight

The internet has thrived because it is open, neutral, and governed through transparent democratic processes. The Digital Networks Act introduces new powers that would allow the European Commission to define important aspects of specialized services through implementing acts.

While flexibility is sometimes necessary, decisions that could shape how the open internet operates should not move away from democratic scrutiny or independent regulatory oversight. Parliament and the Body of European Regulators for the European Commission (BEREC) each play distinct roles in ensuring that rules are developed transparently and in the public interest.

  • Safeguarding Privacy While Strengthening Network Security

Europe’s digital infrastructure must be secure and resilient. As cyber threats continue to take increasingly menacing forms, stronger security requirements are both necessary and welcome.

However, stronger security should never come at the expense of fundamental rights. Certain provisions in the proposal could be interpreted too broadly, potentially allowing intrusive monitoring of communications or data retention practices without sufficient judicial safeguards.

  • Ensuring a Fair and Inclusive Fiber Transition

Replacing aging copper networks with fiber is an important step towards building Europe’s digital future. Faster and more reliable connectivity benefits citizens, businesses, and public services alike.

But not every community will make that transition at the same pace. The current proposal allows for derogations when fiber deployment has not yet reached certain areas, yet it provides limited guarantees for users who may still depend on existing infrastructure.

Digital transformation should not leave people behind simply because they live in rural or less commercially attractive regions.

  • Preserving Competition in Spectrum Allocation

The radio spectrum is one of Europe’s most valuable public resources. How it is allocated directly impacts competition, innovation, and consumer choice.

The DNA creates stronger expectations that existing license holders will be able to renew their spectrum rights. While this may encourage investment, it could also make it more difficult for new operators to enter the market and compete on equal terms.

A competitive digital market depends on opportunities for innovation and new entrants, not just stability for incumbent providers.

  • Strengthening Transparency and Accountability in Digital Governance

The Digital Networks Act gives BEREC an increasingly important role in supporting the operation of the European telecommunications market. As its responsibilities grow, so too should the mechanisms that ensure transparency and public accountability.

Stronger governance standards should match greater influence. Stakeholders, civil society organizations, and citizens should have meaningful opportunities to understand, scrutinize, and contribute to decisions that shape Europe’s digital infrastructure.

Evaluation


A recurring lesson from digital policymaking is that legislation does not end with adoption. The success of any regulatory framework ultimately depends on how effectively it is implemented, monitored, and adapted over time.

For this reason, the European Pirate Party believes that evaluation should become a core component of the Digital Networks Act. Continuous assessment of implementation outcomes, market impacts, consumer access, competition, and technological developments will be essential to ensuring that the framework remains effective and responsive.

The DNA could become a key part of Europe’s digital future. But its success depends not just on its goals, but also on whether policymakers address the real concerns raised during the consultation.

Looking Ahead


The European Pirate Party supports the goal of strengthening and connecting Europe’s digital infrastructure. We also believe that good laws should balance investment with competition, harmonization with flexibility, and new ideas with accountability.

Our submission to the European Commission reflects this view. By tackling the technical, administrative, and economic gaps found during the consultation, the Digital Networks Act can better deliver on its promise of a digital Europe that is connected, open, competitive, inclusive, and respects rights.

Though discussions on the proposal continue, we stay dedicated to contributing evidence-based recommendations that place citizens, digital rights, and the public interest at the center of Europe’s digital future.

​Attached is a copy of our formal submission. Click here to read:

PPEU DNA Feedback June2026 (9)Download


europeanpirates.eu/evaluating-…

reshared this

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

📢 Kennst du #CRIF? Nein? Aber CRIF weiß vermutlich wie du heißt, wo du lebst und wann du geboren wurdest. Sei bei noybs erster großer DSGVO-Sammelklage dabei! Wir gehen aktuell von einem Schadensbetrag von €500 pro Person aus. 👉 crif.noyb.eu

#Sammelklage #Verbandsklage #noyb #Schrems #Austria

in reply to noyb.eu

Das zur #CRIF gesagte dürfte so wohl auch weitgehend auf die #Schufa zutreffen: heise.de/news/Schufa-speichert… - Für Kreditauskunfteien scheint die DSGVO wohl nicht zu gelten?
Questa voce è stata modificata (6 giorni fa)
The Pirate Post ha ricondiviso questo.

Die Politik steht vor einer Wahl: Sie kann ein Verbotsschild am verseuchten See aufstellen und das Baden untersagen. Oder sie kann das Chemiewerk dazu zwingen, keine giftigen Abwässer mehr einzuleiten.

Unser Wochenrückblick zum Social-Media-Verbot.

netzpolitik.org/2026/die-woche…

in reply to netzpolitik.org

Schönes Bild, das nicht nur für SoMe gilt, sondern für viele andere Beispiele, wo immer nur an Symptomen rumgedoktort wird, aber die eigentlichen Ursachen unberührt bleiben und keine Strategie für deren Bekämpfung sichtbar wird. So'ne Kopfschmerztablette lindert zwar die Kopfschmerzen, behebt aber auch nicht die Ursachen dafür. So'n Parteiverbot zerschlägt die Auswüchse, aber die Ursache für die Existenz bleibt unberührt.
The Pirate Post ha ricondiviso questo.

Auch nach fast 580 Tagen demonstrieren in der georgischen Hauptstadt Tiflis jeden Abend Hunderte Menschen gegen die autoritäre Regierung. Der gelang es, die Protestbewegung in Georgien zu brechen: mit physischer Gewalt – und mit Gesichtserkennungssoftware und einem Netzwerk aus KI-gestützten Kameras. Eine Reportage.

netzpolitik.org/2026/gefilmt-b…

Can’t punish reporting it? Punish transporting it


Dear Friend of Press Freedom:

A Texas man was sentenced to decades in prison for transporting political publications. We break down what his case means for press freedom. Plus, more on Brendan Carr’s latest attack on the media and journalist Catherine Herridge’s fight to protect her confidential sources.

Can’t punish reporting it? Punish transporting it


We’ve often written about the bipartisan trend of criminalizing mere possession or transporting of information. This week it became more real than ever.

Texas artist Daniel “Des” Sanchez Estrada was sentenced to 30 years in prison for transporting a box of leftist political pamphlets, allegedly to prevent them from being used as evidence against his wife, who attended a protest where a police officer was shot. She was sentenced to 70 years.

But the pamphlets said nothing about the protest or the shooting, which his wife was not alleged to have been involved with anyway. In fact, they aren’t far off from the pro-Revolution writings the framers had in mind when they wrote the First Amendment’s press clause.

We said in a statement, “Sanchez’s case is the latest example of the Trump administration grasping at any legal straws it can to criminalize disfavored ideologies and writings.” Freedom of the Press Foundation (FPF) Chief of Advocacy Seth Stern and columnist Jeremy Busby also wrote about the draconian sentence and what it means for journalists in The Intercept.


Tell Trump’s censorship czar to stop retaliating against ABC


Federal Communications Commission Chair Brendan Carr is going after ABC again, this time over the decades-old “bona fide news” exemption that protects its daytime talk show, “The View,” from the regulator’s equal-time rules.

Everyone with a smidgen of common sense knows what Carr’s up to: Retaliation for ABC’s exercise of First Amendment rights. President Donald Trump has a long-standing grudge against ABC, and Carr publicly endorses Trump’s campaign to silence his critics and reshape the media — and ABC specifically — to be more gentle to his fragile ego.

ABC is urging the public to file comments with the FCC reminding it of the Constitution. You can use our action center to do so quickly and easily.


Judge to journalist: Burn your source or pay $800 per day


The government flouts court orders constantly and faces no meaningful consequence. At worst, it gets scolded by a judge.

But when an independent journalist like Catherine Herridge seeks to keep her word to confidential sources who relied on her to protect their identities? That’ll cost $800 a day, even though she’s seeking Supreme Court review of the anti-press ruling holding her in contempt.

As we said in a statement, “The prospect of crippling fines will especially impact independent journalists like Herridge, at a time when corporate outlets are increasingly compromised. Congress needs to provide clear statutory protection against compelled disclosure of journalists’ sources by passing a strong shield law like the PRESS Act.”


Government agencies: Repeal gag policies before you get sued and lose


The Coconut Grove Spotlight, a small nonprofit newsroom in Miami, is the latest outlet to challenge a policy funnelling press inquiries through a public information office. These PIO policies are unconstitutional, but government agencies across the country still maintain them.

And they normalize even worse abuses by the feds. The Trump administration recently pushed to have government employees sign corporate-style nondisclosure agreements, and the Defense Department shut off access to journalists who wouldn’t promise to only report what the Pentagon authorizes.

FPF Executive Director Trevor Timm explains why any agency that still has one of these policies needs to drop it before they’re next to get sued and lose.


California schemin’ to erode transparency


Our friends in Sacramento must have whiplash after a series of extreme changes to a proposed public records law that would have severely undermined transparency. Ultimately, a coalition of press freedom advocates salvaged an important victory, as lawmakers backed down and removed the problematic additions to the bill.

Prior to the retreat, FPF Deputy Director of Advocacy Adam Rose explained why the legislation was one of the most anti-transparency bills in recent memory. It would have even allowed the government to sue people for daring to request public records. Yikes! Successfully gutting such awful provisions is a reminder of the work it takes to ensure state capitals preserve the public’s right to know.


What we're reading


Leaked Kanye West tape prosecution stalls as DOJ weighs appeal

Bloomberg Law
“There are far better uses of prosecutorial resources than going after a journalist who used publicly available information” to expose antisemitism, FPF’s Stern said about the case against Tim Burke.


CBS News’ independent watchdog stays quiet amid ‘60 Minutes’ turmoil

The New York Times
Who would have thought that an “ombudsman” handpicked to appease Donald Trump and his lapdog Brendan Carr would have nothing to say about “60 Minutes” being gutted to ... appease Donald Trump and Brendan Carr.


Al Jazeera cameraman Ahmed Wishah killed in Israeli strike on Gaza

The Guardian
The shameful killings of journalists in Gaza by the Israeli military continue. Targeting journalists is wrong, and it must stop.


Free-speech fraud Bari Weiss would rather deport than debate

The Nation
It’s shameful for a news outlet to call on the government to deport people it doesn’t like. Nobody who values the First Amendment would encourage kicking people out of the country for their speech.


Why reporters don’t belong in front of grand juries

The Washington Post
If whistleblowers can’t speak to reporters in confidence, government corruption, abuse, and wrongdoing will never see the light of day.


Some senators want more grandstanding at the Supreme Court

The Washington Post
This is an outrageous take by the Post editorial board. Transparency, including cameras in the court, is how power is held to account.


Tennessee Supreme Court raises bar for secrecy, unseals docs on former judge

The Tennessean
Judicial records can’t be kept secret without a compelling interest, says the Tennessee Supreme Court. This is a major win for public access.



Are you subscribed to our other newsletters? Sign up for news on excessive government secrecy, and for digital security tips and advice at the link below.
Subscribe Here


freedom.press/issues/cant-puni…

Elezioni e Politica 2026 reshared this.

“Doppia minaccia” alla comunicazione privata: si riaccende la resistenza dopo gli accordi antidemocratici sottobanco per reintrodurre chatcontrol


Di seguito la traduzione del post pubblicato oggi da Patrick Breyer: L’attivista per i diritti civili Dr. Patrick Breyer mette in guardia contro un “doppio attacco” senza precedenti alle app di messaggistica sicura in vista delle cruciali riunioni dell’UE di questo venerdì e lunedì. Anche il governo tedesco sta giocando un ruolo pericoloso. In vista di giorni cruciali per i diritti…

Source

reshared this

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ macOS.Gaslight: backdoor nordcoreana in Rust che inganna i tool AI degli analisti di sicurezza
#CyberSecurity
insicurezzadigitale.com/macos-…

@informatica


macOS.Gaslight: backdoor nordcoreana in Rust che inganna i tool AI degli analisti di sicurezza


Il panorama delle minacce avanzate ha appena acquisito una dimensione inedita e preoccupante: un malware nordcoreano progettato specificamente per manipolare i tool di analisi basati su intelligenza artificiale, non per sfuggire ai sandbox tradizionali. macOS.Gaslight, scoperto e analizzato dai ricercatori di SentinelOne Labs, introduce una tecnica mai vista in natura: la prompt injection direttamente nel binario, indirizzata ai pipeline di triage assistiti da LLM che oggi affiancano il lavoro degli analisti di sicurezza.

Il contesto: l’escalation del malware DPRK per macOS


La Corea del Nord ha sviluppato negli anni una capacità offensiva su macOS di tutto rispetto, tipicamente orientata al furto di criptovalute e all’infiltrazione di aziende nel settore tecnologico e finanziario. I gruppi Lazarus, BlueNoroff e i loro cluster affiliati hanno già firmato strumenti come RustBucket, KANDYKORN e ObjCShellz. macOS.Gaslight si inserisce in questa filiera, ma aggiunge un elemento evolutivo significativo: la consapevolezza che i moderni workflow di analisi del malware si appoggiano sempre più a strumenti di triage automatizzato basati su LLM, e la volontà di sfruttare proprio questa dipendenza come vettore di evasione.

La tecnica centrale: prompt injection contro l’analista, non contro il sandbox


La caratteristica distintiva di macOS.Gaslight è un payload da 3,5 KB embedded direttamente nel binario: un blob in formato Markdown contenente 38 messaggi di sistema fasulli, delimitati da token {{DATA}}. Questa struttura imita deliberatamente lo scaffold di un harness LLM per il triage del malware, rendendo indistinguibile il confine tra dati campione non attendibili e istruzioni attendibili del sistema.

I messaggi fabricati simulano scenari di errore critici: scadenza del token, kill per esaurimento della memoria (OOM), esaurimento dello spazio su disco, ripetuti fallimenti operativi, avvisi di vulnerabilità da injection e flag da analisi statica. L’obiettivo, secondo SentinelOne, è far dubitare l’agente LLM della propria sessione di analisi, portandolo ad abortire o rifiutare l’esame del campione.

«La sua caratteristica più notevole è una cascata di messaggi di sistema fabbricati, progettata per far dubitare un agente di triage assistito da LLM della propria sessione. Attacca la percezione dell’agente, non il sandbox in cui opera.»
Phil Stokes, SentinelOne Labs


Architettura tecnica del malware


Linguaggio e firma: il binario è scritto in Rust, compilato per l’architettura macOS aarch64 (Apple Silicon). È firmato in modalità ad hoc e porta l’identificatore endpoint-macos-aarch64-5555494492fc075f441637fb9d894913dde3a2ea. Il campione era stato caricato su VirusTotal il 22 maggio 2026, prima che un aggiornamento di Apple XProtect lo intercettasse basandosi puramente sull’hash.

Persistenza: il malware installa un LaunchAgent nel profilo utente, usando il label com.apple.system.services.activity nel file .plist, volutamente progettato per mimetizzarsi tra i processi di sistema legittimi di Apple. Per ottenere il percorso assoluto di se stesso da inserire nell’array ProgramArguments, il binario risolve a runtime la propria posizione tramite __NSGetExecutablePath.

Comando e controllo: l’implant utilizza il Telegram Bot API come canale C2, entrando in un ciclo di polling con getUpdates che permette all’operatore di inviare istruzioni tramite una shell interattiva e ricevere i risultati. Una scelta operativa che sfrutta la legittimità del traffico Telegram per eludere blocchi di rete basati su reputazione dei dominio. Il malware si auto-censura eliminando il proprio token Telegram dall’output runtime, impedendo a chiunque catturi log o crash di recuperarlo.

Modulo infostealer: incorporato nel binario è presente uno script Python da 6,6 KB codificato in Base64 che funge da suite di raccolta informazioni. Raccoglie: cronologia dei comandi del terminale, lista delle applicazioni installate, snapshot dei processi in esecuzione, profilo hardware e software del sistema, il database Keychain di macOS e credenziali salvate nei browser Chrome, Brave, Firefox e Safari. I dati raccolti vengono compressi in un archivio ZIP (temp/collected_data.zip) e caricati su Telegram.

Due righe per i difensori


macOS.Gaslight segna un punto di svolta: per la prima volta in natura si documenta l’uso della prompt injection come tecnica di evasione nei confronti dei pipeline di analisi automatizzata del malware. Non è più sufficiente affidarsi esclusivamente all’AI-assisted triage per la classificazione di campioni sospetti; i team di sicurezza devono implementare approcci a difesa in profondità che combinino analisi statica tradizionale, sandbox comportamentali e revisione umana.

Per quanto riguarda la detection su endpoint macOS, è consigliabile monitorare creazioni di LaunchAgent con label che imitano naming convention Apple (com.apple.*), connessioni uscenti verso l’API di Telegram (api.telegram.org) da processi non familiari, accessi al database Keychain da processi non autorizzati, e la creazione di archivi ZIP in directory temporanee non standard.

Indicatori di compromissione (IoC)

# Identificatore binario
endpoint-macos-aarch64-5555494492fc075f441637fb9d894913dde3a2ea
# Persistenza LaunchAgent
Label: com.apple.system.services.activity
Path: ~/Library/LaunchAgents/com.apple.system.services.activity.plist
# File creato durante esfiltrazione
temp/collected_data.zip
# Traffico di rete C2
api.telegram.org (polling via getUpdates)
# Caratteristiche binario
Arch: macOS aarch64 (Apple Silicon)
Linguaggio: Rust
Firma: ad hoc signed

L’analisi completa con ulteriori indicatori tecnici è disponibile nel report originale di SentinelOne Labs. La scoperta rafforza la necessità di trattare qualsiasi output di analisi AI di campioni sconosciuti con un livello aggiuntivo di scetticismo, verificando manualmente le conclusioni quando i tool automatizzati segnalano errori di sessione o fallimenti operativi insoliti durante il triage.

The Pirate Post ha ricondiviso questo.

🍪📰 “The European #Commission has put forward a proposal that could largely do away with #cookie banners. However, not only lobbying groups representing the tracking industry but also countries, such as #Germany and #France, have long opposed this.” (from German)

🔗 netzpolitik.org/2026/online-tr…

in reply to noyb.eu

I really don't understand why everybody is surprised by this. Remember, these cookiewalls exist BECAUSE the tracking industry invented them to badmouth the privacy laws. So OFF COURSE they lobby against a solution: the problem must remain for the users, so they can continue to blame the privacy laws.

It was always perfectly possible to avoid cookiewalls by just abiding the law.

The Pirate Post ha ricondiviso questo.

Tecnologie emergenti e tutela dei minori: le autorità del G7 per la protezione dei dati concordano sui principi chiave.

Sono state discusse le problematiche relative all'utilizzo degli occhiali intelligenti in termini di protezione dei dati e privacy, in particolare su iniziativa della CNIL, che ha prodotto una sintesi (un compendio) degli approcci adottati dalle autorità di protezione dei dati del G7 su questo tema .

cnil.fr/en/emerging-technologi…

@privacypride@feddit.it

The Pirate Post ha ricondiviso questo.

VPN, confini digitali in una rete senza confini

Internet è nato per connettere le persone al di là dei confini. Eppure, sempre più spesso, gli utenti sperimentano versioni diverse dello stesso internet a seconda della loro posizione geografica.

pirati.io/2026/06/vpn-confini-…

@pirati@feddit.it

reshared this

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

1/4 ⛔ The Council has failed to reach an agreement on the #DataOmnibus.

A group of Member States — including Germany, Italy, Poland, Sweden, Denmark, the Czech Republic and Austria — pushed to postpone the discussion and blocked agreement on the latest Council text.

🚦 After months of negotiations, it seems that powerful corporations are succeeding in putting pressure on the Council to weaken #GDPR and #ePrivacy protections even further.

Questa voce è stata modificata (3 settimane fa)
in reply to EDRi

4/4 📣 The EU and its citizens do not need deregulation disguised as simplification. What we need are clear, enforceable rules that protect people (and the planet) from commercial surveillance, abusive data practices and harmful AI systems.

📚 The file has now been placed on the table of upcoming Irish Presidency of the Council, and we will make sure to resist any further erosion of this data protection framework.

The Pirate Post ha ricondiviso questo.

Dopo il recente caso delle immagini registrate dalle telecamere di proprietà del comune di #Genova (che finiscono chissà dove e a chi), ora anche la sorveglianza dei cittadini con #droni e #AI. Alle brutte notizie non c’è mai fine.

🔗 genova24.it/2026/06/sicurezza-…

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Shai-Hulud Malware Expands to npm Ecosystem, Stealing Cloud and CI/CD Credentials From Developers
#CyberSecurity
securebulletin.com/shai-hulud-…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Authentication Laundering e TonRAT: come il malware Node.js prende di mira il settore hospitality
#tech
spcnet.it/authentication-laund…
@informatica


Authentication Laundering e TonRAT: come il malware Node.js prende di mira il settore hospitality


Microsoft Threat Intelligence ha recentemente portato alla luce una campagna di attacco multi-stadio particolarmente sofisticata, attiva dall’aprile 2026 contro l’industria dell’ospitalità in Europa e Asia. Il vettore principale è il phishing, ma la tecnica di evasione usata — ribattezzata dagli analisti “authentication laundering” — rappresenta un salto di qualità rispetto ai metodi tradizionali.

Cos’è l’Authentication Laundering


Il termine prende spunto dal concetto di “money laundering”: come si riciclano fondi illeciti attraverso canali legittimi, gli attaccanti “riciclano” URL malevoli attraverso servizi reputati come Calendly e i redirect di Google. In pratica, il link inserito nell’email di phishing non punta direttamente al payload, ma a una pagina Calendly o a un redirect Google che a sua volta reindirizza alla risorsa malevola.

Il risultato è che i gateway email sicuri (SEG) vedono un dominio affidabile nel corpo del messaggio e lasciano passare il messaggio. La destinazione finale, quella pericolosa, viene raggiunta solo dopo che l’utente ha già cliccato. Questo approccio bypassa efficacemente:

  • Reputazione URL in tempo reale
  • Sandboxing statico dei link
  • Filtri basati su domain reputation


La catena di attacco passo per passo

Fase 1 – Il lure


Le email di phishing sono costruite per sembrare comunicazioni legittime da parte di ospiti: reclami fotografici su condizioni delle camere, richieste di prenotazione, o segnalazioni su oggetti smarriti. Tutte contengono un link che sfrutta l’authentication laundering descritto sopra. L’obiettivo è persuadere il personale dell’hotel — tipicamente non tecnico — ad aprire un archivio ZIP allegato o scaricato.

Fase 2 – Lo ZIP con shortcut fasulli


Il file ZIP contiene shortcut (.lnk) mascherati da immagini. Quando l’utente fa doppio clic sul presunto file JPG, in realtà esegue uno script PowerShell heavily obfuscated che dà il via alla catena di infezione.

# Esempio semplificato di obfuscation tipica nei dropper PowerShell
$encoded = "JABzAD0AIgBoAHQAdABwAHMAOi..."
[System.Text.Encoding]::Unicode.GetString([Convert]::FromBase64String($encoded)) | IEX

Gli script evolvono attraverso multiple iterazioni per evitare le signature statiche degli antivirus: ogni stage decodifica il successivo in memoria prima di eseguirlo.

Fase 3 – Deployment di TonRAT (Implant Node.js)


Il payload finale è TonRAT, un Remote Access Trojan scritto in Node.js. La scelta di Node.js è deliberata: viene eseguito da directory user-space (es. %APPDATA%), senza richiedere privilegi elevati, e sfrutta un runtime legittimo — il processo node.exe — che non desta sospetti ai controlli superficiali.

TonRAT dispone di capacità avanzate:

  • Modifica delle esclusioni di Microsoft Defender: aggiunge i propri processi temporanei alla lista delle esclusioni per operare indisturbato.
  • Compilazione .NET dinamica: genera ed esegue codice .NET in memoria per estendere le proprie capacità senza toccare il disco.
  • Download di componenti aggiuntivi: se un componente viene rimosso da un prodotto di sicurezza, l’implant si riconnette al C2 e lo riscarica automaticamente.


Fase 4 – Persistenza duale nel Registro


La persistenza viene garantita attraverso un meccanismo a doppio strato nel registro di Windows:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

Sia il componente Node.js principale che i payload secondari in ProgramData hanno proprie entry con percorsi randomizzati. Se la sicurezza rimuove uno dei due, l’altro sopravvive e provvede a ripristinare il componente eliminato.

Come difendersi: Indicatori e Contromisure

Monitoraggio comportamentale


Il punto critico da monitorare è l’esecuzione di node.exe da directory non standard. In un ambiente aziendale, Node.js non dovrebbe mai girare da %APPDATA%, %TEMP% o %LOCALAPPDATA%. Un alert su questo pattern è altamente indicativo.

# Query per trovare processi node.exe in esecuzione da directory sospette (PowerShell)
Get-CimInstance Win32_Process -Filter "Name = node.exe" |
  Select-Object ProcessId, CommandLine, @{
    Name=Path; Expression={$_.ExecutablePath}
  } |
  Where-Object { $_.Path -notlike "*\Program Files*" -and $_.Path -notlike "*\nodejs*" }

Audit delle Registry Run Keys


Verificare regolarmente la presenza di entry con nomi randomizzati (tipicamente 8-12 caratteri alfanumerici) nelle chiavi di autorun:

# Controllo chiavi Run e RunOnce per tutti gli utenti del sistema
$keys = @(
  "HKLM:\Software\Microsoft\Windows\CurrentVersion\Run",
  "HKLM:\Software\Microsoft\Windows\CurrentVersion\RunOnce",
  "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run",
  "HKCU:\Software\Microsoft\Windows\CurrentVersion\RunOnce"
)
foreach ($key in $keys) {
  Write-Host "`n[$key]"
  Get-ItemProperty -Path $key -ErrorAction SilentlyContinue |
    Select-Object -Property * -ExcludeProperty PS*
}

Politiche di restrizione PowerShell


Abilitare la modalità Constrained Language di PowerShell e configurare le AMSI-based logging per catturare gli script decodificati prima dell’esecuzione:

# Abilitare la trascrizione di PowerShell (via GPO o direttamente)
Set-ItemProperty -Path "HKLM:\Software\Policies\Microsoft\Windows\PowerShell\Transcription" `
  -Name "EnableTranscripting" -Value 1 -Force
Set-ItemProperty -Path "HKLM:\Software\Policies\Microsoft\Windows\PowerShell\Transcription" `
  -Name "OutputDirectory" -Value "C:\PSLogs" -Force

Formazione del personale


Poiché il vettore iniziale è sociale, la formazione rimane fondamentale. Il personale dell’ospitalità deve essere addestrato a:

  • Non aprire allegati ZIP da email sconosciute, anche se contengono presunte foto di ospiti
  • Verificare il dominio reale di un link passando il mouse sopra prima di cliccare
  • Segnalare immediatamente comportamenti anomali dei propri dispositivi

La campagna TonRAT esemplifica l’evoluzione delle minacce verso un’evasione sempre più raffinata. L’authentication laundering rende inefficaci i controlli perimetrali basati sulla reputazione dei domini, spostando il punto di difesa verso il rilevamento comportamentale. Per i sysadmin, il takeaway principale è chiaro: non basta bloccare URL malevoli — occorre monitorare ciò che accade dopo il click, dentro i sistemi.

Fonte: 4sysops.com | Analisi tecnica originale: Microsoft Threat Intelligence


The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

FortiBleed: Over 73,000 Fortinet Firewalls Compromised in Industrial-Scale Cyber Espionage Campaign
#CyberSecurity
securebulletin.com/fortibleed-…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Gestire Microsoft Defender Antivirus con PowerShell: cmdlet pratici per sysadmin
#tech
spcnet.it/gestire-microsoft-de…
@informatica


Gestire Microsoft Defender Antivirus con PowerShell: cmdlet pratici per sysadmin


Microsoft Defender Antivirus è il componente di sicurezza integrato in Windows 10, Windows 11 e Windows Server 2016 e successivi. Spesso gestito tramite interfaccia grafica o Group Policy, offre però un set completo di cmdlet PowerShell che permettono una gestione programmatica potente, particolarmente utile in ambienti server headless, pipeline di automazione e script di provisioning.

In questo articolo esploriamo i cmdlet principali, con esempi pratici di utilizzo per la gestione quotidiana da parte di amministratori di sistema.

Prerequisiti e Accesso


I cmdlet di Defender sono disponibili per impostazione predefinita su Windows 10/11 e Windows Server 2016+. Per usarli è necessario aprire PowerShell come amministratore.

# Verifica che il modulo Defender sia disponibile
Get-Module -ListAvailable -Name Defender

# Per visualizzare la documentazione completa di qualsiasi cmdlet
Get-Help <cmdlet> -Online

Nota importante: le modifiche apportate via PowerShell agiscono sulle impostazioni locali del dispositivo. Politiche distribuite tramite Microsoft Intune, Group Policy o Configuration Manager possono sovrascriverle. Pianificare di conseguenza nelle architetture gestite centralmente.

Verificare lo Stato della Protezione


Il punto di partenza è sempre capire in che stato si trova il sistema.

# Stato complessivo di Defender Antivirus
Get-MpComputerStatus

# Output selettivo: solo i campi più rilevanti
Get-MpComputerStatus | Select-Object `
  AntivirusEnabled, `
  RealTimeProtectionEnabled, `
  BehaviorMonitorEnabled, `
  IoavProtectionEnabled, `
  NISEnabled, `
  QuickScanAge, `
  FullScanAge, `
  AntivirusSignatureLastUpdated, `
  AntivirusSignatureVersion

QuickScanAge e FullScanAge indicano da quanti giorni non viene eseguita una scansione rapida o completa. Un valore molto alto può indicare un problema di pianificazione. AntivirusSignatureLastUpdated è critico: firme obsolete riducono drasticamente l’efficacia della protezione.

Configurare le Preferenze con Set-MpPreference


Set-MpPreference è il cmdlet centrale per la configurazione. Permette di intervenire su centinaia di parametri.

Protezione in Tempo Reale

# Abilitare la protezione in tempo reale (default: abilitata)
Set-MpPreference -DisableRealtimeMonitoring $false

# Abilitare il monitoraggio comportamentale
Set-MpPreference -DisableBehaviorMonitoring $false

# Abilitare la protezione cloud-delivered (MAPS)
Set-MpPreference -MAPSReporting Advanced
Set-MpPreference -SubmitSamplesConsent SendAllSamples

Gestire le Esclusioni


Le esclusioni sono necessarie in ambienti dove certi processi o directory generano falsi positivi, ma vanno gestite con attenzione: sono uno dei vettori sfruttati dagli attaccanti (come visto nel caso TonRAT).

# Aggiungere un percorso alle esclusioni
Add-MpPreference -ExclusionPath "C:\AppData\MyApp\cache"

# Aggiungere un processo alle esclusioni
Add-MpPreference -ExclusionProcess "msbuild.exe"

# Aggiungere un’estensione file alle esclusioni
Add-MpPreference -ExclusionExtension ".log"

# Verificare le esclusioni configurate
Get-MpPreference | Select-Object ExclusionPath, ExclusionProcess, ExclusionExtension

# Rimuovere una singola esclusione
Remove-MpPreference -ExclusionPath "C:\AppData\MyApp\cache"

Best practice: documentare ogni esclusione con il motivo tecnico e revisionarle periodicamente. Un’esclusione dimenticata è una superficie di attacco aperta.

Pianificazione delle Scansioni

# Impostare una scansione rapida giornaliera alle 03:00
Set-MpPreference -ScanScheduleDay Everyday
Set-MpPreference -ScanScheduleTime 03:00:00

# Impostare una scansione completa settimanale alla domenica alle 02:00
Set-MpPreference -ScanParameters FullScan
Set-MpPreference -ScanScheduleDay Sunday
Set-MpPreference -ScanScheduleTime 02:00:00

# Abilitare la scansione dei file email e degli archivi compressi
Set-MpPreference -DisableEmailScanning $false
Set-MpPreference -DisableArchiveScanning $false

Aggiornare le Definizioni Antivirus

# Aggiornare le signature immediatamente
Update-MpSignature

# Aggiornare da un percorso UNC condiviso (es. WSUS o share locale)
Update-MpSignature -UpdateSource InternalDefinitionUpdateServer

# Verificare la versione corrente delle signature
(Get-MpComputerStatus).AntivirusSignatureVersion
(Get-MpComputerStatus).AntivirusSignatureLastUpdated

In ambienti con dispositivi offline o in reti segmentate, la distribuzione delle signature tramite share UNC o WSUS è essenziale. Update-MpSignature supporta diversi source: MicrosoftUpdateServer, MMPC, InternalDefinitionUpdateServer, FileShares.

Avviare Scansioni Manuali

# Scansione rapida
Start-MpScan -ScanType QuickScan

# Scansione completa
Start-MpScan -ScanType FullScan

# Scansione di un percorso specifico (custom scan)
Start-MpScan -ScanType CustomScan -ScanPath "D:\Downloads"

# Avviare in modo asincrono (non blocca la shell)
Start-MpScan -ScanType QuickScan -AsJob

Rilevare e Gestire le Minacce

# Visualizzare le minacce rilevate attualmente attive
Get-MpThreat

# Visualizzare lo storico delle rilevazioni (incluse quelle già gestite)
Get-MpThreatDetection

# Output dettagliato di una singola minaccia per ID
Get-MpThreat | Where-Object { $_.ThreatID -eq 12345 } | Format-List *

# Rimuovere tutte le minacce attive in quarantena
Remove-MpThreat

Performance Analyzer: Individuare i Colli di Bottiglia


Se Defender causa rallentamenti, il Performance Analyzer integrato aiuta a identificare quali file, processi o estensioni impattano maggiormente sui tempi di scansione:

# Avviare la raccolta dati per 60 secondi
New-MpPerformanceRecording -RecordTo "C:\Temp\DefenderPerf.etl"

# Analizzare i risultati: top 10 file più lenti da scansionare
Get-MpPerformanceReport -Path "C:\Temp\DefenderPerf.etl" `
  -TopFiles 10 `
  -TopScansPerFile 5 `
  -TopProcessesPerFile 5

Automazione: Script di Audit Difensivo


Uno script di audit rapido da eseguire periodicamente su ogni macchina o tramite PSRemoting su più host:

function Get-DefenderAudit {
  $status = Get-MpComputerStatus
  $prefs  = Get-MpPreference

  [PSCustomObject]@{
    ComputerName            = $env:COMPUTERNAME
    AVEnabled               = $status.AntivirusEnabled
    RealTimeProtection      = $status.RealTimeProtectionEnabled
    SignatureAge_Days       = ((Get-Date) - $status.AntivirusSignatureLastUpdated).Days
    SignatureVersion        = $status.AntivirusSignatureVersion
    LastQuickScan_Days      = $status.QuickScanAge
    LastFullScan_Days       = $status.FullScanAge
    ExclusionPathCount      = @($prefs.ExclusionPath).Count
    ExclusionProcessCount   = @($prefs.ExclusionProcess).Count
    CloudProtection         = $prefs.MAPSReporting
  }
}

# Esecuzione locale
Get-DefenderAudit | Format-List

# Esecuzione remota su più host
$servers = @("SRV01", "SRV02", "SRV03")
Invoke-Command -ComputerName $servers -ScriptBlock ${Function:Get-DefenderAudit} |
  Sort-Object SignatureAge_Days -Descending |
  Format-Table -AutoSize

Conclusione


I cmdlet PowerShell di Microsoft Defender Antivirus offrono un controllo granulare e scriptabile su ogni aspetto della protezione, rendendoli uno strumento fondamentale per i sysadmin che gestiscono flotte di macchine Windows. Integrarli in pipeline di provisioning, script di audit periodici e runbook di incident response è una pratica che migliora significativamente la postura di sicurezza senza dipendere da interfacce grafiche.

Ricorda: le modifiche via PowerShell sono locali e possono essere sovrascritte da GPO o Intune. In ambienti gestiti centralmente, usa PowerShell per audit e diagnostica, e riserva la configurazione permanente agli strumenti di management centralizzato.

Fonte: 4sysops.com | Documentazione ufficiale: Microsoft Learn


The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

25-Year-Old cURL Vulnerability Patched in Record-Breaking Security Release Fixing 18 CVEs
#CyberSecurity
securebulletin.com/25-year-old…
The Pirate Post ha ricondiviso questo.

„Hennemann gilt als Vertreter eines wirtschaftsorientierten Datenschutzes, der Daten als ökonomisches Gut sieht und die Nutzung von Daten für Innovation und Geschäftsmodelle betont.“ na toll 🫠 netzpolitik.org/2026/moritz-he…
in reply to Bianca Kastl

Das Problem an der Sichtweise von Daten als ökonomisches Gut ist übrigens, dass es ja immer die Daten anderer sind, die verwertet werden. Abbau Daten anderer, die dann auf den Risiken und Folgen sitzen bleiben, wohingegen die Datenverwerter mit dem Gewinn davongehen.
Questa voce è stata modificata (3 settimane fa)

reshared this

The Pirate Post ha ricondiviso questo.

Wie bereits mehrfach geschrieben befindet sich die #Chatkontrolle gerad in den letzten Zügen.
Jetzt ist aber mal wieder etwas historisches passiert, von dem wir eigentlich dachten das es nicht passieren wird.
TL;DR Wir müssen jetzt erneut Laut werden, wenn ihr euch also bei der Fußball WM langweilt oder eine alternative Beschäftigung sucht schreibt euren Abgeordneten.
Mehr Details findet ihr hier
chat-kontrolle.eu/index.php/20…

Und nun zu den eigentlichen Details 1/4

in reply to khaleesi

#Chatkontrolle Zusätzlich zum entscheidenden letzten Trilogue Termin wird morgen, der 26.06 wichtig. Die eigentlich schon gecancelte Chatkontrolle 1.0 wurde für eine zweite Lesung auf die Tagesordnung gesetzt. Dieser Vorschlag wurde vor 3 Monate bereits vom Parlament abgelehnt. Hier ist es wichtig das ihr euren Abgordneten noch einmal deutlich macht das sie bei dieser Entscheidung bleiben.
Mehr Details findet ihr im Blog der 2/4 @digiges
digitalegesellschaft.de/2026/0…
in reply to khaleesi

#Chatkontrolle Nicht nur im EU-Parlament kommt es zu Verirrungen auch die deutsche Bundesregierung macht erneut einen Rückzieher und will nun doch einen "möglichst breiten Anwendungsbereich" wenn es um das scannen von Kommunikation geht. 3/4
netzpolitik.org/2026/interne-d…

reshared this

The Pirate Post ha ricondiviso questo.

"Doppia minaccia" alla comunicazione privata: si riaccende la resistenza dopo gli accordi antidemocratici sottobanco per reintrodurre chatcontrol

Lunedi prossimo le élites politiche europee potrebbero approvare 👁️ la scansione di massa obbligatoria dei messaggi privati e 🆔la verifica dell'età per le app di messaggistica (= la fine dell'anonimato!)

pirati.io/2026/06/doppia-minac…

@privacypride@feddit.it

Qui il post di @echo_pbreyer
⬇️
digitalcourage.social/@echo_pb…


Montag droht der #Chatkontrolle-Worst-Case:
👁️ Verpflichtende Massenscans privater Nachrichten
🆔 Alterskontrolle für Messenger (= Ende der Anonymität!)

📰 Hintergrund im Blog: patrick-breyer.de/doppelte-gef…
🛡️ Noch bis Montag könnt ihr PROTESTIEREN: fightchatcontrol.de


The Pirate Post ha ricondiviso questo.

🚨 They are bringing back #ChatControl 🚨

Discussion is scheduled for Monday, so act now: fightchatcontrol.eu/

#No2Surveillance #Privacy #Security

in reply to Dyne.org foundation

They just going to push until there is no state opposing. I’m glad NL and PL are against though but still I find this whole chatcontrol such a shot in the foot from EU. While trying to create alternative to US corporate services and as a result trying to embrace open source soilutions as alternatives, they try to create an open gate for the same US based services to totally take control of communication. Which will lead to even more exodus from europe.
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Microsoft Secure Boot Certificates Expire — Over a Billion PCs and Linux Systems at Risk
#CyberSecurity
securebulletin.com/microsoft-s…
The Pirate Post ha ricondiviso questo.

Montag droht der #Chatkontrolle-Worst-Case:
👁️ Verpflichtende Massenscans privater Nachrichten
🆔 Alterskontrolle für Messenger (= Ende der Anonymität!)

📰 Hintergrund im Blog: patrick-breyer.de/doppelte-gef…
🛡️ Noch bis Montag könnt ihr PROTESTIEREN: fightchatcontrol.de

The Pirate Post ha ricondiviso questo.

📢 𝗢𝗽𝗲𝗻 𝗰𝗮𝗹𝗹: Open Technology Research is a global, multidisciplinary research symposium bringing academics and practitioners together to advance understanding of the role of open technologies in the modern world and produces policy-relevant research that helps decision-makers drive impact.

symposium.opentechresearch.org…

reshared this

in reply to Dyne.org foundation

With keynotes anchored in what is already working & sessions designed to translate research directly into policy recommendations and practice, the event is both a stocktaking exercise & a forward-looking call to build a more united, evidence-based global research agenda ON – one that strengthens open technology's role as a shared foundation for resilience and sovereignty, reinforces public interest governance & mobilizes research and evidence to drive collective action.

symposium.opentechresearch.org…

The Pirate Post ha ricondiviso questo.

Moritz Hennemann: Der neue Bundesbeauftragte für Datenschutz und Informationsfreiheit gilt als Verfechter einer „Datenrealpolitik“, die Daten als ökonomisches Gut sieht und die Nutzung von Daten für Innovation und Geschäftsmodelle betont netzpolitik.org/2026/moritz-he…
The Pirate Post ha ricondiviso questo.

Der größte Schmarrn in der Welt der Webentwicklung bleibt uns leider erhalten. Technisch gesehen sinnfrei. Gut für ethisch fragwürdige Abmahn-Unternehmen, Google und einige EU-Mitgliedsstaaten…

netzpolitik.org/2026/online-tr…

Vielen Dank an die @netzpolitik_feed 👍

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Wissenschaftskommunikation im Fediverse von @tomkalei

thomas-kahle.de/blog/2026/fedi…

#fediverse #mastodon #academia #academicchatter #university #research #wissenschaft #forschung #wisskomm #scicomm #scholcomm

The Pirate Post ha ricondiviso questo.

A new study on citation impact (in the field of sleep disorders) finds that "only 27.7% of articles exceeded their journal’s #JIF, while 72.3% fell below it."
link.springer.com/article/10.1…

PS: In other words, about three-fourths of articles that might use their journal's impact factor as a bragging point (advertisement, credential, distinction, tribute) actually drag down the journal's average citation impact. Another reason why it's wrong to judge articles (and authors) by journal-based metrics.

#CitationImpact #Journals #ScholComm

Questa voce è stata modificata (3 settimane fa)
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ Kit AiTM contro AWS: Datadog svela una campagna di phishing che bypassa l’MFA in tempo reale
#CyberSecurity
insicurezzadigitale.com/kit-ai…

@informatica


Kit AiTM contro AWS: Datadog svela una campagna di phishing che bypassa l’MFA in tempo reale


Si parla di:
Toggle

Tra il 16 e il 19 giugno 2026, i ricercatori di Datadog Security Research hanno osservato una campagna di phishing altamente sofisticata contro la console AWS. Non si tratta del classico furto di credenziali: il kit implementa tecniche adversary-in-the-middle (AiTM) che permettono di catturare i codici MFA in tempo reale, bypassando email, SMS e app di autenticazione TOTP. Un’analisi tecnica dettagliata pubblicata il 24 giugno svela l’architettura del kit, gli IoC e le tecniche di delivery utilizzate.

La campagna: tre domini in 48 ore


La campagna si è concretizzata con la registrazione di tre domini in una finestra di soli due giorni, tutti attraverso il registrar NICENIC INTERNATIONAL GROUP CO., LIMITED e ospitati su infrastruttura Cloudflare. I domini impersonavano con fedeltà la pagina di login della console AWS:

  • us-west-login[.]com (registrato il 18 giugno 2026) — con sottodomini aws.us-west-login[.]com e aws-central.us-west-login[.]com
  • us-east-prod[.]com (registrato il 17 giugno 2026) — con sottodominio aws.us-east-prod[.]com
  • loginportal-aws[.]com (registrato il 16 giugno 2026)

In parallelo, sono stati identificati altri tre domini che impersonavano SendGrid, registrati nello stesso arco temporale attraverso lo stesso registrar. La doppia infrastruttura — AWS e SendGrid — suggerisce che gli attaccanti abbiano progettato un sistema integrato: SendGrid per la consegna delle email di phishing, i cloni AWS per la raccolta delle credenziali.

Come funziona il kit: AiTM in tempo reale


La caratteristica più pericolosa di questo kit non è la clonazione della pagina login, ma la capacità di intercettare e ritrasmettere il secondo fattore di autenticazione in tempo reale. Il flusso si articola in più fasi:

1. Validazione del target prima del rendering: quando la vittima accede alla pagina di phishing, il kit legge il parametro URL input_24 contenente un blob base64 cifrato. Il server decodifica l’indirizzo email della vittima e lo imposta come cookie. Solo se l’email è valida e registrata come target, la pagina viene effettivamente renderizzata — una misura anti-sandbox che rende inutile l’analisi automatica senza una email vittima valida.

// Logica di validazione dell'indirizzo vittima
let e = new URLSearchParams(window.location.search).get(`input_24`);
(e ? fetch(`/api/check`, {
  method: `POST`,
  body: JSON.stringify({ encrypted: e }),
  credentials: `include`
}) : Promise.resolve({ ok: !1 }))
.then(e => e.ok ? e.json() : null)
.then(() => fetch(`/api/me`, { credentials: `include` }))
.then(e => e.json())
.then(e => t(e.email || null))

2. Furto delle credenziali primarie: la pagina clonata raccoglie username e password tramite i form di login AWS (sia account root che IAM) e li invia a /api/login. Il server, agendo come proxy verso la vera console AWS, ottiene in risposta quale tipo di MFA è configurato sull’account.

3. Intercettazione dell’MFA in real-time: il kit presenta alla vittima la challenge MFA corrispondente al secondo fattore configurato — /email, /sms, o /gauth per le app TOTP. Il codice inserito viene intercettato e ritrasmesso immediatamente al server AWS legittimo, completando l’autenticazione prima che il codice scada.

Delivery: phishing mirato via SendGrid e Nimbu


Il 19 giugno 2026 è apparso su VirusTotal un batch file che funge da artefatto di validazione dell’infrastruttura. Il file contiene la struttura di un’email di phishing che impersona il supporto AWS, citando un ticket di supporto fasullo su presunto throttling della banda. La consegna avviene tramite piattaforme email legittime come SendGrid e Nimbu, scelta tattica che permette di passare i controlli SPF/DKIM/DMARC e bypassare i filtri antispam aziendali.

L’uso del parametro input_24 per la validazione dell’email suggerisce inoltre che si tratti di una campagna di spear phishing mirato piuttosto che mass phishing: ogni link contiene l’email cifrata della specifica vittima, rendendo impossibile l’accesso alla pagina di phishing senza il link personalizzato.

TTPs e mapping MITRE ATT&CK


  • T1566.002 — Spearphishing Link: link personalizzati con email cifrata per targeting preciso
  • T1111 — MFA Interception: cattura in real-time di email OTP, SMS e codici TOTP
  • T1056.001 — Keylogging: raccolta di username, password e codici di verifica prima del forwarding
  • T1583.001 — Acquire Infrastructure: Domains: tre domini registrati nello stesso arco di 48 ore
  • T1133 — External Remote Services: targeting dell’accesso alla console AWS


Indicatori di compromissione (IoC)

# Domini AWS phishing
us-west-login[.]com
aws.us-west-login[.]com
aws-central.us-west-login[.]com
us-east-prod[.]com
aws.us-east-prod[.]com
loginportal-aws[.]com

# Registrar comune
NICENIC INTERNATIONAL GROUP CO., LIMITED

# Infrastruttura di hosting
Cloudflare (tutti i domini)

# Endpoint API del kit
/api/check   - validazione email vittima
/api/me      - recupero email da cookie
/api/login   - furto credenziali e identificazione MFA
/email       - challenge MFA via email
/sms         - challenge MFA via SMS
/gauth       - challenge MFA via TOTP

# Parametro URL di targeting
input_24 (blob base64 cifrato contenente email vittima)

Come rilevare l’attacco


Datadog consiglia le seguenti azioni di hunting per chi sospetti di essere stato targetizzato:

  • DNS hunting: verificare la presenza nei log DNS di query verso i domini elencati negli IoC, inclusi i sottodomini
  • CloudTrail monitoring: controllare eventi ConsoleLogin da IP inusuali o da località geografiche anomale, soprattutto a ridosso delle date di campagna (16-19 giugno 2026)
  • Email gateway review: cercare email provenienti da SendGrid o Nimbu che contengano link con il parametro input_24 nell’URL
  • Credential review: se si sospetta compromissione, revocare immediatamente le sessioni AWS attive, ruotare le credenziali e abilitare notifiche di accesso non familiare

La sofisticazione di questo kit — targeting selettivo, bypass MFA in real-time, uso di infrastrutture email legittime — lo colloca in una categoria diversa rispetto al phishing di massa. Le organizzazioni che utilizzano AWS in ambienti enterprise dovrebbero trattare questa campagna come un rischio attivo, non come una minaccia teorica.


The Pirate Post ha ricondiviso questo.

Bürger:innen stellen digitale Anträge und die Verwaltung bearbeitet sie. Damit sie an der richtigen Stelle ankommen, braucht es eine Transport-Infrastruktur. Bund und Länder haben sich nun auf eine Lösung dafür geeinigt und wollen sie bundesweit ausrollen. Scheitern könnte das jedoch schon an den Landesgrenzen.

netzpolitik.org/2026/verwaltun…

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Die Expert*innen-Kommission hat gestern ihre Empfehlungen zum Thema Jugendschutz im Netz vorgestellt.
Klar ist: Ein pauschales Verbot würde nichts an der Problematik ändern. Es ist umso wichtiger, die Plattformen in die Verantwortung zu nehmen und gefährdende Praktiken und Funktionsweisen stärker zu regulieren.

+++ Unterstütze uns noch heute unter netzpolitik.org/spenden/ und kämpfe mit uns für unabhängigen Journalismus mit Haltung! +++

#socialmedia #verbot #socialmediaverbot #netzpolitik

in reply to netzpolitik.org

Da ich nicht daran glaube, dass sich Plattformen regulieren lassen, bzw. die Umsetzung eventueller Regelungen Jahre dauern wird, finde ich es wichtig eine Notbremse durch ein Verbot zu ziehen. Bis eine mögliche Regulierung und deren Umsetzung in Kraft treten könnten, würden Jahre vergehen, in denen Kinder weiterhin der Gier der Techkonzerne ausgeliefert sind.