The Pirate Post ha ricondiviso questo.

Die Anti-Überwachungs-Demo von @Sicherheit_ohne_Ueberwachung am Samstag in Berlin hat mir sehr gut getan. Sie war groß, laut und schön bunt. Zu sehen, dass so viele Menschen gegen die ausufernden Polizei-Befugnisse auf die Straße gehen, gibt mir Hoffnung für diesen Abwehrkampf. Hier haben Kollege Denis und ich aufgeschrieben, was wir vor Ort gesehen haben: netzpolitik.org/2026/proteste-…
The Pirate Post ha ricondiviso questo.

Deutsche Polizeien sollen uns mit KI überwachen. Lange blieb der Aufschrei aus, jetzt gab und gibt es in gleich vier Städten Demonstrationen dagegen. netzpolitik.org/2026/proteste-…
The Pirate Post ha ricondiviso questo.

The UK social media ban for under-16s does nothing to sort out the harms caused by platforms.

Harmful content is a product of a business model that uses data to drive engagement and target users with ads.

Digital ID checks feed more data into this system, while leaving the engine for harms unchecked.

Read our response ⬇️

openrightsgroup.org/press-rele…

#socialmediaban #socialmedia #stopkillinginternet #ukpolitics #ukpol #onlinesafety #ageverification #StopKillingInternet #StopKillingTheInternet

The Pirate Post ha ricondiviso questo.

Scienza libera o valutazione di stato?


Scriveva Kant:

Un ministro francese convocò alcuni dei commercianti più stimati, per chiedere loro suggerimenti sul modo in cui poter sollevare le sorti del commercio, come se intendesse scegliere l’avviso migliore. Dopo che uno ebbe suggerito questo e l’altro quel rimedio, un vecchio commerciante, che fino ad allora era rimasto in silenzio, prese a dire: costruite buone strade, battete buona moneta, accordate uno diritto snello in materia di cambio e così via; quanto al resto, ‘lasciateci fare!’ Questa sarebbe la risposta che dovrebbe dare la facoltà di filosofia, se il governo le chiedesse quali dottrine deve imporre agli studiosi: solo di non impedire il progresso delle idee e delle scienze.


Lo stato deve occuparsi delle infrastrutture normative e fisiche, mentre la ricerca, specie quella di base, va lasciata libera - diceva Kant, contro l'#università cameralistica, burocratica e controllata dallo stato, con cui aveva a che fare.

Oggi avviene l'opposto di quanto chiedeva Kant: la valutazione di stato si intromette nella ricerca e le infrastrutture sono abbandonate a privati quali Microsoft o Elsevier.

Il risultato del capovolgimento è ben spiegato da Davide Borrelli, qui.

Questa voce è stata modificata (1 mese fa)
The Pirate Post ha ricondiviso questo.

Kudos to the #MIT Graduate Student Council for adopting "a resolution expressing support for campus libraries to exit big deal journal packages and calling for changes to promotion and tenure processes to move away from journal-based metrics."
heliosopen.org/campus-rpt-refo…

Here's the resolution itself.
drive.google.com/file/d/1KLbj4…

#Assessment #BigDeals #Cancellations #ECR #JIF #Libraries #Metrics #Students

The Pirate Post ha ricondiviso questo.

📊 "#CRIF sammelt Daten über Personen und stellt Unternehmen Informationen zur Einschätzung von Zahlungsausfällen zur Verfügung. #noyb hält Teile dieser Praxis für rechtswidrig. Das soll nun gerichtlich geklärt werden." 🧑‍⚖️

🗞️ Weiterlesen: help.orf.at/stories/3235956/
⚖️ Zur Sammelklage: crif.noyb.eu

#noyb
Questa voce è stata modificata (1 mese fa)
The Pirate Post ha ricondiviso questo.

'Für den Landrat vom Landkreis hat Martina Müller dann einen Ordner vorbereitet. “Ich bin super aufgeregt zu unserem Landrat gegangen. Der wollte den Ordner überhaupt nicht sehen.” Er habe nur gefragt, ob es funktioniere, ob die Schulen zufrieden seien und ob es günstiger sei als das, was wir bisher machen. “Und als ich bei allen drei Punkten genickt habe, hatte ich sein Okay.”' netzpolitik.org/2026/vorreiter… /via @netzpolitik_feed #pos #eos #san #linux
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ Shadow fleet digitale: Russia e Iran usano 36 siti contraffatti per sfuggire alle sanzioni marittime
#CyberSecurity
insicurezzadigitale.com/shadow…

@informatica


Shadow fleet digitale: Russia e Iran usano 36 siti contraffatti per sfuggire alle sanzioni marittime


Un rapporto pubblicato oggi da Recorded Future’s Insikt Group smantella pezzo per pezzo una vasta rete di siti web contraffatti utilizzati dalle flotte ombra iraniane e russe per aggirare le sanzioni internazionali. Oltre 36 siti impersonano registri navali, amministrazioni marittime nazionali e società di classificazione inesistenti, formando un ecosistema digitale al servizio dell’evasione sanzionatoria.

Il contesto: flotte ombra e sanzioni internazionali


Da quando le sanzioni occidentali hanno colpito le esportazioni energetiche di Russia e Iran, entrambi i Paesi hanno sviluppato reti di navi “ombra” — imbarcazioni che operano cambiando frequentemente bandiera, proprietario apparente e documentazione per continuare a trasportare petrolio sul mercato globale. Il problema centrale è la verifica: port state control, compagnie assicurative e broker richiedono documenti ufficiali — certificati di classe, certificati per i marittimi, lettere P&I — e questi documenti ora vengono prodotti digitalmente da entità fittizie che mimano quelle reali.

Tre cluster, un ecosistema interconnesso


Insikt Group ha identificato tre cluster di infrastruttura online, designati Alpha, Bravo e Charlie, accomunati da sovrapposizioni tecniche, pattern di registrazione domini e ricorrenti errori OPSEC. L’analisi mostra connessioni esplicite a 17 navi, la maggioranza delle quali già sanzionate dall’OFAC (Office of Foreign Assets Control) del Dipartimento del Tesoro statunitense.

Cluster Alpha è quello più sofisticato dal punto di vista tecnico: include un generatore automatizzato di PDF che produce certificati fraudolenti per marittimi con QR code funzionali, apparentemente riconducibile all’azienda indiana di sviluppo web Oceaniek Technologies. I certificati vengono emessi “per conto” delle amministrazioni marittime di Benin, Comore e Nicaragua — paesi con scarsa capacità di supervisione e spesso sfruttati come bandiere di comodo.

Cluster Bravo è collegato a due cittadini siriani, uno dei quali ha precedenti di coinvolgimento in attività illecite, e comprende organizzazioni fittizie come la Med Lloyd Classification Society, Hellas Naval Bureau of Shipping e vari siti di formazione per marittimi. Cluster Charlie condivide caratteristiche tecniche e di design con Bravo ma rimane non attribuito, e utilizza uno schema di “validazione a strati” in cui le amministrazioni marittime false avallano altre entità false per costruire credibilità reciproca.

Tecniche di falsificazione: il generatore di certificati


Il meccanismo più significativo identificato nel Cluster Alpha è un’applicazione web che consente la generazione self-service di documenti marittimi fraudolenti. Il sistema accetta i dati del marittimo in input, genera un certificato PDF formalmente identico a quello ufficiale, associa al documento un QR code che punta a una pagina di verifica controllata dagli stessi attori — restituendo risultati “positivi” durante le ispezioni portuali — e mantiene un database queryabile di certificati fittizi per simulare consultazioni da parte delle autorità. Questa capacità trasforma il sistema di verifica documentale in uno strumento di validazione per i documenti fraudolenti stessi.

Pattern tecnici e indicatori di infrastruttura

# Domini identificati nei tre cluster
## Cluster Alpha
beninmaritime[.]org / beninmaritime[.]co / beninmaritime[.]net
epnicaragua[.]org
atlasregister[.]net
## Cluster Bravo
medlloyd[.]online
hellasnaval[.]net
nauticacentro[.]mx
isithin[.]com
## Cluster Charlie
pioneersmaritime[.]com
alliance-scs[.]org
sasmaa[.]club
zambmaritime[.]org
# IP di hosting condivisi
159[.]198[.]36[.]123
217[.]76[.]51[.]133
151[.]80[.]4[.]227

Collegamento a report precedenti e navi sanzionate


Il rapporto integra indagini precedenti: Bellingcat aveva documentato nel febbraio 2026 l’attività di Oceaniek Technologies, e Lloyd’s List aveva scoperto un cluster di registri navali falsi centrati attorno al dominio marinegov[.]net. Le 17 navi per cui Insikt Group ha trovato connessioni esplicite includono petroliere già sanzionate da OFAC, Unione Europea e altri Paesi. Questo elemento rafforza la tesi che le reti di siti fraudolenti non siano operative isolate ma componenti di un’infrastruttura di servizio — un sanctions-evasion-as-a-service — che vende documentazione falsa a più reti operative simultaneamente.

Due righe per compliance e difensori


Per le organizzazioni del settore marittimo, portuale e finanziario coinvolte in operazioni di due diligence, il rapporto segnala un cambio di paradigma: la verifica documentale tradizionale non è più sufficiente. Le raccomandazioni operative includono la verifica indipendente contattando direttamente le autorità nazionali (non tramite link nei documenti), l’integrazione di feed CTI nelle piattaforme di compliance per rilevare domini fraudolenti, l’analisi WHOIS dei domini presenti nei certificati e la segnalazione coordinata alle autorità dei Paesi la cui identità viene impersonata.

Fonte primaria: Insikt Group / Recorded Future, 11 giugno 2026.


The Pirate Post ha ricondiviso questo.

Ähnlich wie in Propagandafilmen wird heute daran geforscht, wie sich Werbebotschaften gut in KI-Suchen integrieren lassen. Mit Blick auf Google stellt sich die Frage, ob es da nicht einen harten Schnitt braucht, schreibt @bkastl in ihrer Kolumne.

netzpolitik.org/2026/degitalis…

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

⚖️🇦🇹 #CRIF hat von fast allen in Österreich Name, Geburtsdatum und Adresse gesammelt, um „Bonitätsscores“ zu berechnen. Dabei gibt es in 90% der Fälle keine Finanzdaten. Wir starten deshalb u. a. eine #Sammelklage auf Schadenersatz.

👉 Mach mit: crif.noyb.eu

Questa voce è stata modificata (1 mese fa)

A Letter from Pirate Hunter Rand


June 13

Pirates, thank you.

Something I want to echo from my media statement is what an honor it has been to participate in our American democracy, especially during the 250th anniversary of our nation’s founding. I also want to acknowledge what a privilege it has been to participate in that process as a Pirate.

My wife and I were talking about how close this race was, and she said something that has stuck with me: “If you had changed your party, you probably could have won, but that wouldn’t have been you.”

Regardless of the outcome, I am proud that I am still me. Authentically me. Authentically a Pirate.

This campaign changed me. Over the last year I experienced things I never expected to experience. I received death threats. I was followed. People harassed my coworkers at my office. In February, someone drove past my home and discharged a firearm 10 times. I was sent threatening letters, and received vague, threatening emails from someone presenting themselves as an impartial journalist while acknowledging ties to an opponent’s campaign. I was ridiculed for being a Pirate and ridiculed for criticizing ALPRs and other surveillance technology. I was threatened and intimidated because I wanted to do something that is apparently revolutionary: put people first.

Experiences like those help explain why some people become cynical, apathetic, or withdrawn from public life. They do not excuse it, but they help explain it.

Despite all of that, I am still me. And, I am still a Pirate.

Am I more confident? Yes.

Am I less tolerant of corruption, dishonesty, and cruelty? Absolutely.

Have I grown and changed? Of course.

But I am still the same man who entered this race last June.

That said, I want to acknowledge something many people have already asked me about. I will not be running for office again.

I have no interest in becoming a perennial candidate. This campaign demanded an extraordinary amount of time, energy, and sacrifice, and I would like to move on into the next chapter of my life.

But the work does not end here.

One of the things I am most excited about is continuing the development of Cutlass Maps and the other campaign tools we have built. For far too long, access to common and important campaign infrastructure and tools has been concentrated in the hands of the two major parties. We built tools that gave us parity with organizations that have existed for generations, and I have no intention of gatekeeping those resources the way they have often been gatekept from us.

Instead, I want to help other third-party and independent candidates succeed, especially our Pirate candidates.

That means improving Cutlass Maps. It means creating candidate training materials. It means sharing lessons learned. It means helping future Pirate candidates run professional, competitive campaigns from day one.

And that brings me to what I am most proud of.

This race was fought against a well established incumbent with over $45,000 available at the last reporting period, dozens of serious endorsements, and another candidate who enjoyed the support and infrastructure of a major political party. We had neither advantage.

What we had was a small team, a lot of determination, and a belief that ordinary people deserve a voice.

We were outspent. We were underestimated. We were told what was possible and what wasn’t.

Yet this race remained close enough that it took days before a concession was appropriate.

We did that with roughly $13,000. We did it as Pirates. We did it as members of what Washoe County calls an, “other,” party.

We earned the attention of our community. We earned the attention of both major political parties. More importantly, we proved that people are willing to listen when someone offers them an alternative to, “the lesser of two evils.”

To the best of my knowledge, I am the first Pirate candidate to run for office in Nevada.

If this is what one Pirate candidate can accomplish on a first attempt, imagine what becomes possible when the next candidate starts with better tools, better training, and a stronger foundation than we had.

This campaign may have ended in defeat, but it also demonstrated something that had never been done before in Nevada. It demonstrated that Pirates can run serious campaigns, compete seriously, and be taken seriously.

That matters.

So while today is a loss for this campaign and me personally, I believe it is a victory for our community, a victory for our party, and a victory for everyone who wants to challenge the idea that only the major parties deserve a seat at the table.

None of this would have been possible without the Pirate Party, without my family, without my team, and without every volunteer, donor, supporter, friend, and neighbor who believed in what we were trying to accomplish.

From the bottom of my heart, thank you.

Don’t give up the ship,

Hunter Rand


Read the letter from Hunter Rand to the Pirate Party here for the official release.


uspirates.org/a-letter-from-pi…

Elezioni e Politica 2026 reshared this.

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please log in.

Quando l'Open Social Web si ibrida: Raccoon for Friendica è una nuova app... Mastodon. E contiene anche un po' di Lemmy! Ecco perché la coppia Free Software + Fediverso è una risorsa preziosa

> Se vuoi avere altri aggiornamenti sul Fediverso, segui il gruppio @Che succede nel Fediverso? dal tuo account e se vuoi aprire nuove conversazioni, crea un nuovo post e menziona il gruppo alla fine del tuo messaggio


Nei giorni scorsi è stata finalmente pubblicata la release 1.0 di #Raccoon per Android, un client piuttosto innovativo nato per #Friendica, ma diventato oggi una delle app più innovative per l'esperienza utente su #Mastodon. L'app è disponibile per Android (la release 1.0 è già sul PlayStore e su Izzidroid e a breve sarà anche su F-Droid), ma ora è stato rilasciato anche un pacchetto #Debian, mentre per una versione iOS bisognerà capire quale sarà il successo tra il pubblico.

L'app introduce alcune novità molto importanti nel panorama delle app federate. Vediamole insieme:

----

1. Il Fediverso anche senza un account

Raccoon è l'unica app che consente di navigare il Fediverso anche senza avere un account. Infatti, quando la si installa è possibile selezionare una qualsiasi istanza Friendica o Mastodon e "appoggiarsi" sulla sua timeline locale pubblica e su quella federata. In questo modo gli utenti potranno esplorare diverse istanze prima di scegliere su quale aprire un account. Naturalmente, anche dopo aver aggiunto un account (l'app gestisce più account), sarà possibile esplorare le timeline dei server diversi da quello cui ci si è iscritti

Seleziona l’istanza pivot in modalità lurker

----

2. La navigazione "swipe"

A differenza di tutte le altre app social (sia di quelle per i social del Fediverso, sia di quelle dei social commerciali), #RaccoonForFriendica consente di aprire uno dei post della timeline e di proseguire la navigazione dei post precedenti e successivi, solo sfogliandolo a destra e a sinistra.
Si tratta di una novità ergonomica davvero interessante

Un esempio di navigazione swipe

----

3. La barra di formattazione

Siccome l'app nasce per Friendica, dispone di una barra di formattazione integrata che ricorda i client Lemmy (infatti lo svilupatore si è cimentato per la prima volta con lo sviluppo di app con un'app Lemmy). La barra di formattazione può essere utilizzata anche per le istanze Mastodon che eseguono il fork Glitch-soc, come la mia istanza poliversity.it che è stata quella con cui lo sviluppatore @𝔻𝕚𝕖𝕘𝕠 🦝🧑🏻‍💻🍕 ha fatto diversi esperimenti.
Oltre che essere più immediata, la scrittura di post formattati è agevolata anche da una funzione di "anteprima" che aiuta a evitare errori nella codifica del Markdown o del BBCode.

Barra di formattazione e anteprima

----

4. Finalmente anche gli utenti Mastodon potranno godersi i gruppi del Fediverso

Come forse saprete, Mastodon non aiuta la visualizzazione dei post dei gruppi. Anche selezionando un gruppo, continueremo a vedere una timeline unica in cui i post principali si alterneranno con le risposte. Cercare un thread su Mastodon è quindi molto complicato, ma lo svilupatore di Raccoon ha trovato un modo per consentire una visualizzazione per "topic" su tutti gli account che risultano essere "gruppi activitypub", siano essi gruppi #Lemmy, #NodeBB, Piefed, Mbin, Peertube, #Wordpress, Mobilizon, #Flipboard, etc.
Anche questa trovata è nata grazie al fatto che lo sviluppatore si è cimentato in passato con lo svluppo di un'app per Lemmy e ha potuto misurarsi con le barre di formattazione e la visualizzazione delle "comunità" Lemmy, che altro non sono che "gruppi #Activitypub"

Visualizzazione dei gruppi in modalità topic

----

5. Altre funzionalità interessanti

Tra le altre cose, c'è la possibilità di
- visualizzare il codice HTML dei messaggi;
- inviare post schedulati;
- configurare completamente l'interfaccia;
- supportare la scrittura in HTML, utile sia per Mastodon Glitch-soc, sia per scrivere post Wordpress integrando il plugin Activitypub for Wordpress di @Matthias Pfefferle e il plugin "Enable Mastodon App" di @Alex Kirk
- integrare librerie di traduzione

----

6. Cosa manca ancora?

L'app presenta tutte le funzionalità presenti nella maggior parte delle altre app Mastodon, tranne una: la corretta gestione dei post Mastodon che citano altri post. Questi, infatti, vengono visualizzati ancora in maniera abbastanza primitiva. Lo sviluppatore sta cercando di capire se adeguarsi alle specifiche Mastodon oppure reinterpretare la funzionalità in maniera più personalizzata.
C'è da dire infatti che, purtroppo, l'implementazione dei messaggi con citazione (già presente da secoli in Friendica) è stata implementata da Mastodon molto tardivamente solo negli ultimi mesi e in un modo molto "personale" che non è piaciuto a molti degli sviluppatori di altri software.


----

7. Un'app che farà bene agli utenti che già usano Mastodon ma anche a chi non ha mai "provato" il Fediverso

Lo sviluppo di questa app procede da quasi due anni e la versione beta ha poco più di un anno di vita, ma con la versione 1.0 sono stati risolti tutti i problemi incontrati precedentemente.
In base a quello che sarà il riscontro da parte degli utilizzatori, lo sviluppatore valuterà se creare una versione iOS e addirittura una versione Windows.
Chi vuole consentire l'invio di segnalazioni in caso di errore dell'applicazione potrà abilitare i report anonimi sui crash.


----

8. Collegamenti e risorse


Questo è il profilo dello sviluppatore:
androiddev.social/users/janTek…
poliverso.org /profile/dieguitux8623

Questo è il repository del'app: github.com/LiveFastEatTrashRac…

Questo il link del PlayStore:
play.google.com/store/apps/det…

Questo è il link su IzzyDroid (su F-Droid l'app uscirà a breve, ma ora è in fase di controllo):
apt.izzysoft.de/fdroid/index/a…

Qui è invece accessibile il blog dello sviluppatore:
livefasteattrashraccoon.github…

Da qui infine è possibile scaricare il pacchetto .apk o il pacchetto .deb senza utilizzare gli store on line:
github.com/LiveFastEatTrashRac…

---

Un ultimo consiglio


Il riscontro del pubblico sarà fondamentale per consentire l'ulteriore sviluppo di questa app.
Se desiderate testarla su Mastodon, provate a farlo con istanze che eseguono il fork glitch-soc. Tra le istanze italiane potete trovare la mia istanza poliversity.it e l'istanza senigallia.one gestita da @Michele Pinto
Per quanto riguarda Friendica, l'unica istanza italiana aperta al pubblico è poliverso.org. L'istanza ha avuto un forte incremento di iscrizioni, quindi ricordatvi di offrire un contributo attraverso LiberaPay 😅.
Se comunicate in italiano, sarò lieto di ospitarvi sulla mia istanza poliverso.org .

Un saluto a tutti e fatemi sapere se avete bisogno di ulteriori informazioni, se avete provato l'app e cosa ne pensate.
Francesco.
Potete interagire con me anche tramite gli account @informapirata ⁂ e @macfranc

The Pirate Post ha ricondiviso questo.

Bei @netzpolitik_feed durfte ich über eines meiner Lieblingsthemen derzeit schreiben: Open Source an Schulen und wovon es abhängt, ob das funktioniert.

netzpolitik.org/2026/vorreiter…

#opensource #Schule #FediLZ _dut #diday #did #dut #souveränität

The Pirate Post ha ricondiviso questo.

Künftig muss man sich wohl zweimal überlegen, ob man auf eine Demo geht. Wir sind daher heute bei einer Anti-Überwachungsdemo in Berlin dabei.

Unser Wochenrückblick:
netzpolitik.org/2026/kw-24-die…

The Pirate Post ha ricondiviso questo.

Schulbildung macht mündig, Open-Source-Software ebenfalls. Ob aber an den mehr als 30.000 deutschen Schulen Open Source eingesetzt wird, hängt oftmals von drei Faktoren ab. Das zeigen erfolgreiche Beispiele in Lübeck und im Harz.

netzpolitik.org/2026/vorreiter…

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

📢 Falls du es verpasst hast: noyb hat am Dienstag eine Unterlassungsklage gegen die Kreditauskunftei CRIF eingebracht und startet nun seine erste große DSGVO-Sammelklage! Hier kannst du mitmachen: crif.noyb.eu

Mehr Infos zum Fall: noyb.eu/de/secret-scoring-join…

Questa voce è stata modificata (1 mese fa)
The Pirate Post ha ricondiviso questo.

Palantir perde la causa legale intentata per costringere una rivista svizzera a pubblicare le repliche


La società tecnologica statunitense Palantir ha perso una causa legale intentata contro una rivista svizzera indipendente per obbligarla a pubblicare le proprie risposte agli articoli riguardanti il ​​rifiuto da parte del governo svizzero dei servizi offerti dall'azienda.

La società di analisi dei dati ha perso 22 dei 23 capi d'accusa. In una sentenza emessa venerdì, il tribunale commerciale di Zurigo ha respinto la maggior parte delle richieste di controdeduzione presentate dall'azienda e dalla sua filiale svizzera, ritenendo che solo un singolo passaggio di un articolo giustificasse una risposta pubblicata da parte della società.

theguardian.com/technology/202…

@giornalismo

China’s escalating crackdown on VPN use


For many years access to foreign media, social media platforms, and independent sources of information in China has been limited through extensive filtering and platform blocking. However, most Chinese could get around these restrictions by using VPNs without any serious consequences. Recent reporting suggests that law enforcement may now be clamping down on users who use a VPN. This worries us very much at Pirate Parties International, and so we decided it was a good time to share more information with our community in the hopes of applying global pressure to stop this.

The recent crackdown on VPNs marks a dangerous escalation in digital authoritarianism. The Chinese state is no longer merely censoring content, it is punishing regular people. A Pirate party to the best of our knowledge does not exist in China, as there is no venue to operate outside the communist party. The current situation shows the need for Pirate organizations that can help people seek information, communicate securely, and participate in the global public sphere. Here at Pirate Parties International, we hope that we will find Pirates in China who will join our global community and can help create venues for Chinese people to access online information without fear of getting caught. We hope inevitably that we can pressure the Chinese government to cease internet restrictions, and thus give their people the freedom to use the global internet with all of its good and bad content. China does not need to be a pariah nation.

A very large proportion of the world lives in China. They deserve the same uncensored information, secure communications, and privacy-enhancing technologies that most of us are able to access around the world. Punishing the mere use of VPNs is incompatible with basic human rights and deepens a broader system of surveillance and intimidation. VPNs are not crimes. They are essential safeguards for privacy, like a door in a bathroom. And we must respect everyone’s right to have this level of privacy.

There are not yet famous Pirate organizations in China, but we suspect that Pirates will soon begin organizing themselves better in China as a result of this crack down on VPN users. We call on Chinese Pirates to join us and support democratic reforms to your government, aim to find solutions that will assist the public to have free use of the internet. Protect at-risk activists, journalists, and researchers who depend on secure cross-border communications. Support the development and distribution of resilient anti-censorship technologies. Publicly condemn sanctions against VPN users and providers of lawful privacy and circumvention tools.

We stand with all people in China and elsewhere who defend the free internet. We hope that this situation improves, and we will continue to monitor it closely. If you or someone you know would like to share more information about this recent problem, please contact us and share more about things that the global Pirate movement can do to support the Chinese people.

Pirate parties have repeatedly opposed censorship, attacks on encryption, and Chinese-style models of internet control. Below we share some of the statements from Pirate parties that reflect our commitment to a free, uncensored, and privacy-respecting internet.


pp-international.net/2026/06/c…

Elezioni e Politica 2026 reshared this.

PPE protects your right to know


The media in this post is not displayed to visitors. To view it, please log in.

Dear Friend of Press Freedom:

“If I hadn’t had it, I’d be dead right now.” That’s how one journalist described the protective gear that kept her alive while covering a protest. So why are authorities trying to take it away? Plus: Our latest fights against the government secrecy and media mergers that are harming the public’s right to know.

PPE protects the public’s right to know


Reporters covering protests in the United States have been shot with crowd-control munitions, sprayed with tear gas, hit with cars, and physically attacked by both law enforcement and demonstrators.

So it makes sense that many journalists wear personal protective equipment like helmets, goggles, and gas masks at demonstrations, and that organizations like Reporters Without Borders offer grants for reporters to buy PPE. One journalist told Freedom of the Press Foundation (FPF) Senior Advocacy Adviser Caitlin Vogus that PPE is “the only reason I am alive.”

Yet across the country, jurisdictions are banning safety gear at public protests, Vogus explains. By stripping journalists of basic protections, these bans endanger both reporters and the public’s right to know.


Join us today to learn about attacks on the press at Delaney Hall


Journalists covering protests at the Delaney Hall immigration detention facility in Newark, New Jersey, over the past few weeks have been met with crowd-control munitions, pepper spray, and batons by law enforcement. The onslaught is part of a wave of violence journalists have faced documenting protests against Immigration and Customs Enforcement during President Donald Trump’s second administration.

Join us for a webinar at 2 p.m. ET today, where you’ll hear from FPF staff who have been documenting assaults of journalists on the ground, and from journalists who’ve observed and experienced officers’ violent tactics firsthand.


Trump’s disappearing DMs


The Trump Presidential Library recently told The Washington Post that it possessed “no records” of Donald Trump’s first-term Twitter direct messages.

But the same day, the library sent FPF a contradictory response confirming that it does hold those records. (The Trump library is the official National Archives and Records Administration website for processing FOIA requests, not to be confused with the shrine Trump is building in Miami.)

The DM disappearing act is a component of the administration’s broader assault on public access to its records, and raises uncomfortable questions about NARA’s ability to remain impartial, much less effective, at releasing Trump’s records under its new leadership.


Tell Congress to investigate crooked Paramount mergers


Paramount CEO David Ellison’s acquisition of CBS was enabled by a $16 million bribe to Donald Trump, laundered as a settlement of the president’s frivolous lawsuit, and a commitment to alter news content to Trump’s liking.

Now, Ellison wants to repeat the same playbook at CNN and HBO. We need lawmakers to use all of their available powers — both now and in the next Congress — to investigate these bribes and quid pro quo arrangements. Use our action center to tell your representatives to step up.


FPF sues to uncover search warrant abuses


FPF filed a federal Freedom of Information Act lawsuit against the Department of Justice to uncover whether the agency is systematically misrepresenting the law and hiding statutory press protections from federal judges so that it can secure search warrants against journalists.

The lawsuit, filed with assistance from Free Information Group, follows the DOJ’s failure to disclose records regarding the unprecedented January FBI raid on Washington Post reporter Hannah Natanson’s home. These include whether the agency has adopted an internal practice of hiding from magistrate judges the existence of the Privacy Protection Act of 1980 — which outlaws raids on newsrooms and journalists’ homes — to evade judicial scrutiny during leak investigations.


NDAs don’t belong in government


The Trump administration wants federal agencies to require employees to sign standardized nondisclosure agreements like the ones Trump used in the business world. If adopted, the rule would give the federal government a powerful weapon to silence public employees and trample on the free speech rights guaranteed to them by the U.S. Constitution.

Permitting federal agencies to force their employees to sign nondisclosure agreements is one more effort by this administration to silence dissent and punish whistleblowers.

We joined a coalition of press freedom and other rights organizations in opposing the rule.


What we're reading


Outrage mounts at assaults of journalists and hunger strikers at Delaney Hall

Truthout
“Protesters were literally pleading for press to remain. Police had other ideas,” said Adam Rose, FPF’s deputy director of advocacy.


Beyond Pulte, Congress cannot renew spy law without reforms

The Hill
Congress needs to make real changes to Section 702 of FISA to protect Americans’ privacy, even if Bill Pulte won’t be the permanent director of national intelligence.


More than 40 Democrats voted to let Trump spy on Americans. They might do it again

MS NOW
Speaking of Section 702, Democrats who support its reauthorization have a lot of explaining to do. Who exactly in the Trump administration do they trust with unchecked spying power? We joined a letter with over 100 organizations calling them out.


A merger could put two of America’s most important news archives under one owner

Poynter
Yet another reason that journalists should be concerned about the possible Paramount-Warner merger: Consolidation of the CNN and CBS News archives under a single owner who can allow or deny access at will.


Trump DOJ tried to surveil Minnesota journalists. A judge said no

Minnesota Spokesman-Recorder
“These failed search warrants are what happens when incompetent prosecutors pursue political vendettas instead of justice,” said FPF’s Vogus.


‘First Amendment nightmare’: Trump’s DOJ targets journalists AND their viewers

FPF
And the Minnesota search warrants didn’t just target Don Lemon and Georgia Fort — they targeted people who merely watched their YouTube channels too, FPF Executive Director Trevor Timm explains in a video.


My arrest as a student journalist

The News Record
It’s a disgrace that journalist Lucas Griffith was prosecuted for doing his job. We need more journalists with his backbone.


Transaction denied

Firewalls Don’t Stop Dragons
Rainey Reitman, FPF’s board president, explains on a podcast how our access to banks, credit cards, and payment processors can be weaponized to stifle speech.

Flyer for webinar on June 12 at 2 ET about attacks on the press at Delaney Hall in Newark, New Jersey
Flyer for FPF event with our board president Rainey Reitman on June 12 at POWERHOUSE Arena in Brooklyn


freedom.press/issues/ppe-prote…

Elezioni e Politica 2026 reshared this.

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ ShinyHunters colpisce le università americane con uno zero-day Oracle PeopleSoft: l’operazione UNC6240 analizzata da Mandiant
#CyberSecurity
insicurezzadigitale.com/shinyh…

@informatica


ShinyHunters colpisce le università americane con uno zero-day Oracle PeopleSoft: l’operazione UNC6240 analizzata da Mandiant


Si parla di:
Toggle

Mandiant e Google Threat Intelligence Group (GTIG) hanno pubblicato oggi un rapporto dettagliato su una campagna attiva di compromissione ed estorsione attribuita a UNC6240, meglio noto come ShinyHunters. L’obiettivo: le istituzioni universitarie americane, colpite attraverso uno zero-day critico in Oracle PeopleSoft che ha consentito l’accesso non autenticato a centinaia di sistemi prima ancora che Oracle rilasciasse la patch.

Il vettore d’attacco: CVE-2026-35273, un RCE con CVSS 9.8


Al centro della campagna si trova CVE-2026-35273, una vulnerabilità di remote code execution (RCE) con punteggio CVSS di 9.8 nel componente Environment Management di Oracle PeopleSoft. Il punto di ingresso sfruttato è l’Environment Management Hub (PSEMHUB), un servizio amministrativo spesso esposto direttamente su Internet nelle configurazioni multi-server. L’attività — documentata tra il 27 maggio e il 9 giugno 2026 — ha preceduto l’advisory Oracle del 10 giugno 2026, classificando di fatto l’exploit come zero-day operativo per oltre due settimane.

GTIG ha identificato gli endpoint vulnerabili e avviato notifiche a oltre 100 organizzazioni globali, con una concentrazione geografica negli Stati Uniti. Particolarmente colpito il settore dell’istruzione superiore: il 68% delle organizzazioni notificate sono atenei e college.

Chi sono gli ShinyHunters: da BreachForums a campagne zero-day


ShinyHunters (tracciato da Mandiant come UNC6240) è un gruppo cybercriminale che si è fatto conoscere tra il 2020 e il 2022 per una serie di breach di alto profilo — AT&T, Ticketmaster, Santander, Advance Auto Parts — venduti poi su BreachForums. Il gruppo ha assunto il controllo di BreachForums dopo l’arresto degli amministratori precedenti, consolidando la propria posizione nell’ecosistema del cybercrime anglofono. La campagna attuale segna un’evoluzione tattica: da semplici acquirenti di accesso iniziale a gruppo capace di sviluppare o acquisire exploit zero-day per piattaforme enterprise.

Infrastruttura C2: MeshCentral travestito da Microsoft Azure


L’analisi delle directory aperte sui cinque host di staging (IP sequenziali 142.11.200.186–190) ha rivelato un’infrastruttura C2 basata su MeshCentral, un software open-source di remote management. Gli agenti Windows precompilati erano rinominati per mimare endpoint legittimi di Microsoft Azure:

  • meshagent64-azure-ops.exe
  • meshagent32-azure-ops.exe
  • meshagent64-v2.exe

Tutti gli agenti erano hardcoded per connettersi al server C2 wss://azurenetfiles.net:443/agent.ashx. Il dominio azurenetfiles.net è stato scelto per imitare Microsoft Azure NetApp Files, una tecnica di masquerading volta a confondere i team di sicurezza durante l’analisi dei log di rete. I server di staging eseguivano Python SimpleHTTP sulla porta 8888, inavvertitamente esposti al pubblico — errore OPSEC che ha permesso a Mandiant e ai ricercatori indipendenti di recuperare l’intero corredo di artefatti.

Timeline operativa e reconnaissance


Il file .bash_history — identico su tutti e cinque i server di staging — ha fornito una timeline dettagliata delle operazioni. Il 27 maggio 2026 alle 22:14 UTC gli attaccanti hanno installato MeshCentral (v1.1.59); pochi minuti dopo, alle 22:25 UTC, hanno configurato il client acme-client per l’automazione dei certificati Let’s Encrypt per il dominio di masquerading. La reconnaissance sulle reti interne delle vittime includeva:

  • Lettura del file psappsrv.cfg per estrarre hostname e indirizzi IP interni
  • Analisi dei mount NFS attivi (mount | grep psoft)
  • Lettura del file /etc/hosts per mappare la topologia interna
  • Ispezione delle configurazioni WebLogic (config.xml)


Propagazione laterale e script fanout


Una volta ottenuto l’accesso al primo nodo, gli attaccanti hanno utilizzato MeshCentral per distribuire uno script Bash denominato [victim_abbreviation]_fanout.sh, scritto direttamente in /tmp tramite heredoc. Lo script automatizza il credential spraying SSH verso gli host interni, parsing la lista da /etc/hosts, e — una volta ottenuto l’accesso — copia un file di estorsione nelle directory WebLogic e Process Scheduler:

README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT

L’esfiltrazione dei dati è avvenuta tramite compressione con zstd seguita da una connessione SSH in uscita verso 176.120.22.24, IP che ospita il mirror pubblico del ShinyHunters Data Leak Site (DLS). Il 9 giugno 2026, alcune organizzazioni vittime sono apparse sul DLS confermando la compromissione avvenuta con successo.

Indicatori di compromissione (IoC)

# IP di staging C2
142.11.200.186
142.11.200.187
142.11.200.188
142.11.200.189
142.11.200.190

# DLS mirror
176.120.22.24

# Dominio C2
azurenetfiles.net

# Hash SHA-256 artefatti
.bash_history:              2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35
meshagent64-azure-ops.exe:  f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc
meshagent64-v2.exe:         d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f
meshagent32-azure-ops.exe:  c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f
meshagent (Linux):          68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309

# Porte
Python SimpleHTTP: porta 8888
WebSocket C2: wss://azurenetfiles.net:443/agent.ashx

Azioni di remediation prioritarie


Per i team di sicurezza che gestiscono ambienti Oracle PeopleSoft, Mandiant raccomanda azioni immediate:

  • Disabilitare EMHub: in configurazioni multi-server, disabilitare il servizio Environment Management Hub; in configurazioni single-server, rimuovere completamente l’applicazione PSEMHUB.
  • Blocco perimetrale: bloccare l’accesso esterno agli endpoint /PSEMHUB/* e /PSIGW/HttpListeningConnector a livello firewall — non affidarsi esclusivamente a regole WAF.
  • Analisi log: verificare nei log WebLogic richieste POST anomale verso /PSEMHUB/hub da IP esterni.
  • Audit filesystem: cercare file .jsp non previsti in PSEMHUB.war/ e directory inattese logs/, persistantstorage/, scratchpad/.
  • Monitoraggio NetFlow: rilevare traffico SMB in uscita (porta 445) da host PeopleSoft verso destinazioni internet esterne (indicatore potenziale di cattura hash NetNTLM).

Fonte primaria: Mandiant / Google Cloud Blog, 11 giugno 2026.


The Pirate Post ha ricondiviso questo.

@andre_meister droppt bei @netzpolitik_feed neue 🔥 Leaks 🔥 zur #Chatkontrolle!

+++ „Deutschland spricht sich für eine weitgehende Chatkontrolle aus, entgegen anderslautender Äußerungen der Bundesregierung.“ +++ Juristischer Dienst im Rat warnt weiter „vor genereller Suche in interpersoneller Kommunikation“ +++ Mitgliedsstaaten sind sich bei Details uneins.

Jetzt aktiv werden #ChatkontrolleStoppen!
Bundesregierung und Regierungsparteien an ihre Versprechen erinnern:
chat-kontrolle.eu/index.php/20…


Die EU-Institutionen verhandeln zentrale Aspekte der Chatkontrolle. Rat und Parlament streiten, ob Internet-Dienste alle Nutzer freiwillig scannen dürfen oder verdächtige Nutzer verpflichtend scannen müssen. Wir veröffentlichen eingestufte Verhandlungsdokumente. netzpolitik.org/2026/interne-d…

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

CISA BOD 26-04: Federal Agencies Must Patch Critical Vulnerabilities Within 3 Days Under New Risk-Based Mandate
#CyberSecurity
securebulletin.com/cisa-bod-26…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

GoFlateLoader: New Go-Based Malware Loader Infects 33,000+ Users by Outsizing Security Scanners
#CyberSecurity
securebulletin.com/goflateload…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

CVE-2026-44963: RCE critico su Veeam Backup & Replication — aggiornare subito a 12.3.2.4854
#tech
spcnet.it/cve-2026-44963-rce-c…
@informatica


CVE-2026-44963: RCE critico su Veeam Backup & Replication — aggiornare subito a 12.3.2.4854


Il 9 giugno 2026 Veeam ha rilasciato una patch di emergenza per CVE-2026-44963, una vulnerabilità di esecuzione di codice remoto con CVSS v4 di 9.4 (Critical) che colpisce Veeam Backup & Replication 12.x. La falla consente a un qualsiasi utente autenticato nel dominio Active Directory di eseguire codice arbitrario sul backup server — anche senza privilegi specifici sull’applicazione Veeam stessa. In un ambiente enterprise, questo equivale alla potenziale compromissione dell’intera infrastruttura di disaster recovery.

Cosa permette di fare CVE-2026-44963


Si tratta di una falla di deserializzazione non sicura nel servizio Veeam Backup & Replication. Un utente di dominio può inviare richieste costruite ad hoc all’API interna del backup server e ottenere esecuzione di codice con i permessi del processo Veeam — tipicamente SYSTEM o un account di servizio ad alto privilegio.

Il vettore è di rete, la complessità bassa, non è richiesta interazione utente. L’unica limitazione: il backup server deve essere membro di un dominio Active Directory. I server Veeam in workgroup non sono affetti da questa CVE specifica.

Versioni affette e versione sicura

VersioneStato
12.3.2.4465 e precedenti (tutta la linea 12.x)⚠️ Vulnerabile
12.3.2.4854✅ Patchata
13.x✅ Non affetta (architettura diversa)

Perché i backup server sono target critici


Un backup server ha accesso privilegiato a tutti i sistemi che protegge: credenziali, snapshot, dati di configurazione. Un attaccante che lo compromette può:

  • Esfiltrare dati sensibili dai backup di sistemi critici
  • Cifrare o cancellare i backup, rendendo inutile la strategia di disaster recovery
  • Usare le credenziali salvate per muoversi lateralmente nell’infrastruttura
  • Distribuire ransomware sapendo che il ripristino sarà impossibile

Sina Kheirkhah di WatchTowr, che ha scoperto e segnalato la falla, sottolinea come compromettere il backup server sia l’equivalente di togliere la rete di sicurezza prima che qualcuno cada.

Verificare la versione installata


Da PowerShell sul backup server:

Get-ItemProperty -Path "HKLM:\SOFTWARE\Veeam\Veeam Backup and Replication" |
    Select-Object -ExpandProperty PackageVersion

Oppure via registry:
reg query "HKLM\SOFTWARE\Veeam\Veeam Backup and Replication" /v PackageVersion

In alternativa, dalla Veeam Backup Console: Help → About.

Procedura di aggiornamento a 12.3.2.4854


L’update è disponibile sul portale download Veeam. Prima di procedere:

  1. Verificare lo spazio disco: l’installer richiede almeno 3 GB liberi sul volume di sistema.
  2. Eseguire un backup manuale dei sistemi più critici come precauzione.
  3. Mettere in pausa i job schedulati per evitare conflitti durante l’aggiornamento.
  4. Aggiornare i componenti remoti dopo l’update del server principale (proxy, repository, agent). Non ignorare questo passaggio.


# Verificare componenti da aggiornare dopo l'update del server
Add-PSSnapin VeeamPSSnapIn
$currentVer = (Get-VBRVersion).ProductVersion
Get-VBRServer | Where-Object { $_.ComponentsVersion -ne $currentVer }

Mitigazioni se non è possibile aggiornare subito


Se non è possibile applicare la patch immediatamente, queste misure riducono la superficie di attacco:

  • Isolare il backup server dalla rete generale: limitare l’accesso alle porte di gestione Veeam (default TCP 9392, 9401) ai soli host autorizzati tramite firewall o ACL.
  • Ridurre gli account di dominio con accesso al server Veeam: applicare il principio del minimo privilegio.
  • Monitorare i log di autenticazione: cercare autenticazioni anomale verso il Veeam Backup Service in orari inusuali.
  • MFA per gli account di gestione Veeam: se il provider di identità lo supporta, abilitare l’autenticazione a più fattori.


Il pattern storico delle vulnerabilità Veeam


Non è la prima volta che Veeam finisce sotto i riflettori per falle critiche. CVE-2023-27532 (CVSS 7.5), CVE-2024-40711 (CVSS 9.8) e ora CVE-2026-44963 mostrano che i backup server sono bersagli sempre più ricercati, specialmente dagli operatori ransomware. Il suggerimento è di trattare i server Veeam come sistemi Tier-0, al pari dei Domain Controller: monitoraggio dedicato, accesso privilegiato minimale, patch urgente e segmentazione di rete.

Conclusione


CVE-2026-44963 non ammette ritardi: qualsiasi utente di dominio può compromettere il backup server e da lì raggiungere tutto il resto. Verificare la versione installata, pianificare l’aggiornamento a 12.3.2.4854 nel più breve tempo possibile e applicare nel frattempo le mitigazioni di rete.

Fonte: The Hacker News — Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code | BleepingComputer — New Veeam vulnerability exposes backup servers to RCE attacks


The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

OceanLotus APT (APT32) Compromises FireAnt MetaKit in Targeted Supply-Chain Attack on Vietnamese Stock Investors
#CyberSecurity
securebulletin.com/oceanlotus-…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

IAKerb e LocalKDC su Windows: meno dipendenza da NTLM, più Kerberos
#tech
spcnet.it/iakerb-e-localkdc-su…
@informatica


IAKerb e LocalKDC su Windows: meno dipendenza da NTLM, più Kerberos


Perché NTLM è ancora vivo (e quanto è difficile eliminarlo)


In ambienti Active Directory, Kerberos è il protocollo di autenticazione preferito da Microsoft da oltre vent’anni. Eppure, NTLM continua a essere presente in quasi ogni infrastruttura Windows perché esistono tre scenari in cui Kerberos non funziona e il sistema ricade inevitabilmente su NTLM:

  • Il client non ha visibilità di rete diretta su un Domain Controller (DC)
  • L’autenticazione coinvolge un account locale invece di un account di dominio
  • L’ambiente è un workgroup o una macchina standalone, senza infrastruttura di dominio

Sono esattamente questi tre gap che Microsoft sta affrontando con IAKerb e LocalKDC, due funzionalità oggi in public preview su Windows Insider (Canary Channel) e previste in disponibilità generale su Windows 11 24H2 e Windows Server 2025 nella seconda metà del 2026.

IAKerb: Kerberos anche senza visibilità sul Domain Controller


IAKerb (Initial and Pass-Through Authentication using Kerberos) è un meccanismo definito nella bozza IETF draft-ietf-kitten-iakerb-03. Si implementa come sotto-meccanismo GSS-API, inserendosi nel protocollo SPNEGO che Windows già utilizza per la negoziazione dell’autenticazione.

Nel flusso Kerberos standard, il client deve contattare direttamente il KDC (Key Distribution Center, il servizio che gira su ogni DC) sulla porta TCP/UDP 88 per ottenere un ticket prima di potersi autenticare su un servizio. Se nessun DC è raggiungibile, Kerberos fallisce e Windows scade su NTLM.

IAKerb risolve questo problema rendendo il server di destinazione un proxy trasparente per i messaggi Kerberos. Il client tunnel i messaggi Kerberos all’interno della connessione esistente verso il server applicativo (ad esempio, sulla porta TCP 445 per SMB), e il server li inoltra al DC per conto del client. Il server non vede mai la password o l’hash: si limita a fare da relay ai messaggi di protocollo.

Il risultato pratico è che l’autenticazione rimane su percorso Kerberos anche quando:

  • Il client si trova in una subnet segmentata senza accesso diretto ai DC
  • L’accesso avviene via VPN o accesso remoto con routing limitato
  • L’architettura cloud restringe la connettività diretta ai controller di dominio


LocalKDC: Kerberos anche per gli account locali


LocalKDC affronta il secondo grande limite: gli account locali. Kerberos richiede un KDC per emettere i ticket, e gli account locali (quelli nel SAM della macchina) non hanno nessun KDC a cui rivolgersi. Di conseguenza, qualunque autenticazione remota che coinvolgesse un account locale era storicamente vincolata a NTLM.

LocalKDC è un KDC leggero integrato direttamente in Windows, che opera esclusivamente sugli account del SAM locale. Emette ticket Kerberos basati su AES per le identità locali, abilitando l’autenticazione Kerberos anche in ambienti workgroup, macchine standalone e qualsiasi scenario con credenziali locali.

Stato attuale e configurazione via registro


Le due funzionalità hanno default diversi nel preview corrente:

  • IAKerb: abilitato per default
  • LocalKDC: disabilitato per default

La configurazione avviene tramite valori di registro di tipo REG_DWORD:

  • DisableIAKerb: impostare a 0 per abilitare, 1 per disabilitare
  • DisableLocalKDC: impostare a 0 per abilitare, 1 per disabilitare

Group Policy e gestione tramite MDM (Intune incluso) saranno aggiunti quando le funzionalità usciranno dalla fase di preview.

Prima di testare: auditing NTLM


Prima di attivare IAKerb e LocalKDC in produzione, è fondamentale capire dove NTLM viene ancora usato nell’ambiente. Windows 11 24H2 e Windows Server 2025 includono log operativi NTLM migliorati, accessibili in Event Viewer sotto:

Applications and Services Logs > Microsoft > Windows > NTLM > Operational

Gli Event ID rilevanti sono:

  • 4020, 4021: eventi client (includono nome processo, IP di destinazione, codice motivo per cui Kerberos non è stato usato)
  • 4022, 4023: eventi server (nome processo e IP client)
  • 4030–4033: eventi sui domain controller (dettagli client e server)

I log client sono i più informativi perché riportano il motivo del fallback a NTLM, permettendo di identificare i workload che richiedono intervento prima di pensare a disabilitare NTLM.

L’abilitazione del logging si gestisce via Group Policy:

  • Per client e server: Administrative Templates > System > NTLM > NTLM Enhanced Logging
  • Per i domain controller: Administrative Templates > System > Netlogon > Log Enhanced Domain-wide NTLM Logs


Limiti attuali e roadmap Microsoft


IAKerb e LocalKDC non eliminano ogni dipendenza da NTLM. Rimangono scenari che continuano a richiedere NTLM:

  • Applicazioni con NTLM hardcoded nel codice
  • Infrastrutture che assumono NTLM come default nella loro logica di autenticazione
  • Alcune interazioni tra account di dominio e account locali sulla stessa macchina

La roadmap Microsoft per la disabilitazione di NTLM si articola in tre fasi:

  • Fase 1 (già in produzione): miglioramenti all’auditing NTLM
  • Fase 2 (H2 2026): disponibilità generale di IAKerb e LocalKDC
  • Fase 3 (~2027–2028): NTLM disabilitato per default nella prossima versione major di Windows Server


Cosa fare adesso


Per un amministratore di sistema che vuole prepararsi al cambiamento in anticipo, il percorso consigliato è: abilitare i log NTLM migliorati oggi (già disponibili su 24H2/Server 2025), analizzare gli event ID nei prossimi mesi per mappare i workload con dipendenza NTLM, e pianificare i test con IAKerb e LocalKDC su ambienti non produttivi non appena la disponibilità generale sarà confermata. Affrontare questa transizione gradualmente è molto più gestibile che trovarsi a fare remediation d’emergenza quando NTLM verrà disabilitato per default.

Fonte originale: Reducing NTLM fallback with IAKerb and LocalKDC in Windows – 4sysops.com


The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

CVE-2026-5027: Critical Langflow Path Traversal Flaw Actively Exploited for Remote Code Execution
#CyberSecurity
securebulletin.com/cve-2026-50…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Patch Tuesday Giugno 2026: record di 208 CVE, 6 zero-day e una falla kernel wormable con CVSS 9.8
#tech
spcnet.it/patch-tuesday-giugno…
@informatica


Patch Tuesday Giugno 2026: record di 208 CVE, 6 zero-day e una falla kernel wormable con CVSS 9.8


Il Patch Tuesday di giugno 2026 ha stabilito un nuovo record assoluto: Microsoft ha rilasciato aggiornamenti di sicurezza per ben 208 CVE, superando il precedente record e portando con sé 6 zero-day, di cui uno attivamente sfruttato in attacchi reali. Per i sistemisti, questo ciclo di patch è tra i più critici dell’anno: ci sono falle wormable nel kernel, bypass multipli di BitLocker, RCE su Hyper-V, AKS e DHCP, e una vulnerabilità Exchange già sfruttata in produzione.

Il quadro generale


Delle 208 vulnerabilità corrette, 33 sono classificate Critical. La distribuzione per tipologia:

  • 65 Elevation of Privilege
  • 55 Remote Code Execution
  • 30 Information Disclosure
  • 27 Spoofing
  • 19 Security Feature Bypass
  • 7 Denial of Service

Il conteggio esclude le 360 CVE ereditate da Chromium/Edge e le falle in servizi cloud come Exchange Online e Microsoft Graph, già patchate in precedenza nel mese.

I sei zero-day

CVE-2026-42897 — Exchange Server Spoofing (attivamente sfruttata)


L’unica zero-day già in uso attivo. Un attaccante invia una email costruita ad hoc: se la vittima la apre in Outlook Web Access, viene eseguito JavaScript arbitrario nel browser. Microsoft ha distribuito mitigazioni tramite il servizio Exchange Emergency Mitigation (EEMS). Verificare che EEMS sia abilitato di default; la patch completa è in lavorazione. Azione immediata richiesta.

CVE-2026-45586 — Windows CTFMON GreenPlasma (EoP)


Divulgata da Nightmare Eclipse, permette di ottenere un shell SYSTEM sfruttando una link following errata nel Windows Collaborative Translation Framework. Prima di una serie di zero-day rilasciate dallo stesso ricercatore in protesta contro il bug bounty Microsoft.

CVE-2026-45585 — BitLocker YellowKey (Security Feature Bypass)


Con accesso fisico al dispositivo, un attaccante inserisce file costruiti su USB o partizione EFI e, avviando in WinRE tenendo CTRL, ottiene accesso illimitato al disco cifrato. Colpisce sistemi con BitLocker in modalità TPM-only. Mitigazione: abilitare TPM+PIN.

CVE-2026-50507 — BitLocker bitskrieg (Security Feature Bypass)


Secondo bypass BitLocker, divulgato da Jonas Lykkegaard. La patch potrebbe causare l’errore “A required file couldn’t be accessed because your BitLocker key wasn’t loaded correctly”. Il fix:

reagentc /disable
reagentc /enable

CVE-2020-17103 — Cloud Files Mini Filter Driver Mini-Plasma (EoP)


CVE originariamente del 2020, segnalata da James Forshaw (Google Project Zero). Sembrava già corretta nel dicembre 2020, ma Nightmare Eclipse ha dimostrato che la vulnerabilità era ancora sfruttabile. L’update di giugno 2026 la chiude definitivamente.

CVE-2026-49160 — HTTP/2 Bomb DoS su HTTP.sys


Abusa della compressione degli header HTTP/2 per forzare il server ad allocare quantità sproporzionate di memoria con pochissimi dati in ingresso. Microsoft ha introdotto la chiave di registro MaxHeadersCount per limitare il numero di header accettati (KB5102602):

; HKLM\SYSTEM\CurrentControlSet\Services\HTTP\Parameters
; DWORD: MaxHeadersCount = 100

Le CVE Critical più rilevanti per l’infrastruttura

CVE-2026-45657 — Windows Kernel RCE (CVSS 9.8, wormable)


È la vulnerabilità che preoccupa di più. Una use-after-free nel kernel legata all’elaborazione del traffico TCP/IP permette a un attaccante non autenticato di eseguire codice da remoto, senza interazione utente. Il vettore CVSS (AV:N/AC:L/PR:N/UI:N) e la classificazione wormable significa che un exploit funzionante potrebbe autopropag arsi tra macchine sulla stessa rete. Sistemi colpiti: Windows 11 (23H2, 24H2, 25H2, 26H1) e Windows Server 2022/2025 incluso Server Core. I ricercatori stimano la finestra per un exploit pubblico in giorni, non settimane. Priorità assoluta.

CVE-2026-32193 — Azure Kubernetes Service Container Escape (Critical)


Path traversal in AKS che permette a un container configurato con hostNetwork: true di evadere il container e ottenere il controllo del worker node. Chi gestisce cluster AKS deve verificare aggiornamenti disponibili:

az aks upgrade --resource-group myRG --name myCluster --kubernetes-version latest

CVE-2026-44815 — DHCP Client Service RCE (Critical)


RCE nel client DHCP di Windows, sfruttabile da un attaccante che controlla un server DHCP malevolo in rete. Rischio elevato in ambienti con BYOD o reti ospiti non segregate.

CVE-2026-45641 / CVE-2026-47652 — Hyper-V RCE (Critical)


Due falle di esecuzione di codice in Hyper-V. Su hypervisor il patching è prioritario: una compromissione può portare all’escape delle VM e alla compromissione dell’host.

CVE-2026-45648 — Active Directory Domain Services RCE (Critical)


RCE nei Domain Controller. Qualunque falla RCE su DC va trattata con la massima urgenza: una compromissione equivale a quella dell’intero dominio.

CVE-2026-47291 — HTTP.sys RCE (Critical)


RCE nel driver HTTP.sys, separata dalla HTTP/2 Bomb. Colpisce tutti i sistemi che espongono servizi HTTP inclusi IIS e applicazioni che usano direttamente HTTP.sys.

Strategia di deployment


Con 208 CVE e sei zero-day, non c’è spazio per ritardi. Alcune linee guida pratiche:

  1. Controllare ADV990001: verificare che il Servicing Stack Update (SSU) sia installato. È il prerequisito per l’installazione corretta di tutti gli altri aggiornamenti.
  2. Exchange prima: CVE-2026-42897 è attivamente sfruttata. Applicare le mitigazioni EEMS immediatamente.
  3. Domain Controller: CVE-2026-45648 su AD DS è Critical. Test in ambiente non-prod, poi deployment rapido su DC.
  4. BitLocker — leggere le release notes: CVE-2026-50507 può richiedere il fix manuale con reagentc. Testare prima del rollout su larga scala.
  5. Hotpatch su Azure VM: Microsoft ha reso generalmente disponibile l’hotpatching per Azure VM (Linux e Windows Server), che applica le patch kernel senza riavvio. Nei workload Azure, è la modalità preferita per ridurre i downtime.


Conclusione


Il Patch Tuesday di giugno 2026 non è un mese da rimandare. La CVE-2026-45657 (kernel wormable CVSS 9.8), la zero-day Exchange in produzione, i doppi bypass BitLocker e la falla AKS compongono un quadro che richiede azione rapida e pianificata. Scaricare gli update, verificare l’SSU, prioritizzare Exchange e DC, e monitorare per eventuali regressioni post-patch, specialmente per il caso BitLocker/reagentc.

Fonte: BleepingComputer — Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws | Zero Day Initiative — June 2026 Security Update Review


The Pirate Post ha ricondiviso questo.

Schon wieder geht die Polizei auf einer Demonstration wegen einer angeblichen Beleidigung des Bundeskanzlers gegen eine minderjährige Person vor. Solche Maßnahmen beschränken die Versammlungs- und Meinungsfreiheit. Eine Analyse.

netzpolitik.org/2026/krise-der…

in reply to netzpolitik.org

Die Amtsermittlung in §194 StGB setzt §188 voraus, und dieser hat als eine von mehreren Bedingungen "und ist die Tat geeignet, sein öffentliches Wirken erheblich zu erschweren" - mir scheint es offenkundig, dass der Bundeskanzler durch möglicherweise die Grenze zur Beleidigung überschreitenden kritischen Zuschreibungen nicht, schon gar nicht erheblich, in seiner Amts-, nicht einmal in seiner sonstigen Lebensführung behindert ist!
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇦🇹👤 #CRIF is one of the largest credit reference agencies in #Austria. It has built up a largely unknown ‘shadow registry’ and use this data to assign credit scores. However, for 90% of those affected, the score is based primarily only on address, gender and age.

❌ We are convinced that this unwarranted data collection and the scoring of those 90% violates the #GDPR. We are therefore bringing an injunction and a class action for damages.

To sign up, go to crif.noyb.eu! 🤝

Questa voce è stata modificata (1 mese fa)
The Pirate Post ha ricondiviso questo.

When the Open Social Web Hybridizes: Raccoon for Friendica is a new app... Mastodon. And it even has a little Lemmy in it! That's why the Free Software + Fediverse duo is such a valuable resource.


@fediverse

Raccoon 1.0 was finally released for Android in recent days, a rather innovative client originally created for #Friendica, but which has now become one of the most innovative apps for the user experience on #Mastodon. The app is available for Android (already on the Play Store and Izzidroid, and will soon be available on F-Droid), but a #Debian package has also been released. An iOS version remains to be seen for its success.

The app introduces some very important innovations to the federated app landscape.

1. Navigate the Fediverse from an app, even without creating an account


Raccoon is the only app that lets you browse the Fediverse even without an account. When you install it, you can select any Friendica or Mastodon instance and "leverage" its local public and federated timelines. This way, users can explore multiple instances before choosing which one to open an account on. Of course, even after adding an account (the app manages multiple accounts), you can browse the timelines of servers other than the one you signed up to.

2. "Browse through" messages: "swipe" navigation


Unlike all other social apps (both those for the Fediverse and those for commercial social networks), #RaccoonForFriendica lets you open a post in your timeline and continue browsing through previous and next posts by simply swiping left and right.
This is a truly interesting ergonomic innovation.

3. Finally a formatting bar in social apps


Since the app was created for Friendica, it features a built-in formatting toolbar reminiscent of Lemmy clients (in fact, the developer @janTeko first experimented with app development with a Lemmy app). The formatting toolbar can also be used for Mastodon instances running the Glitch-soc fork, such as infosec.exchange, tech.lgbt, and my poliversity.it instance, which was the one the developer experimented with.

In addition to being more immediate, writing formatted posts is also made easier by a "preview" function that helps avoid errors in Markdown or BBCode coding.

4. Finally, Mastodon users will be able to enjoy Fediverse groups too.


As you may know, Mastodon doesn't support the display of group posts. Even if you select a group, you'll still see a single timeline where top posts alternate with replies. Searching for a thread on Mastodon is therefore very complicated, but the #Raccoon developer has found a way to enable "topic" viewing across all accounts that are "activitypub groups," be they #Lemmy, #NodeBB, Piefed, Mbin, Peertube, Wordpress, Mobilizon, Flipboard, etc.
This idea also came about thanks to the fact that the developer had previously tried his hand at developing an app for Lemmy and was able to experiment with the formatting bars and display of Lemmy "communities," which are nothing other than "#activitypub groups."

5. Other interesting features


Among other features, you can


6. What's still missing?


The app features all the features found in most other Mastodon apps, except one: the correct handling of Mastodon posts that quote other posts. These are still displayed in a fairly primitive way. The developer is trying to decide whether to adapt to Mastodon specifications or reinterpret the feature in a more personalized way.
It must be said that, unfortunately, the implementation of quoted messages (already present in Friendica for ages) was implemented by Mastodon very late, only in recent months, and in a very "personal" way that many other software developers did not appreciate.

7. Raccoon is an app that will benefit users who already use Mastodon but also those who have never "tried" the Fediverse


This app has been under development for almost two years, and the beta version is just over a year old. However, version 1.0 has resolved all previously encountered issues.
Based on user feedback, the developer will evaluate whether to create an iOS version and even a Windows version.
Anyone who wishes to allow reporting of application errors can enable anonymous crash reports.

8. Links and Resources


This is the developer's profile:
androiddev.social/users/janTek…

This is the app repository: github.com/LiveFastEatTrashRac…

This is the Play Store link:
play.google.com/store/apps/det…

This is the link on IzzyDroid (the app will be released on F-Droid soon, but is currently under review):
apt.izzysoft.de/fdroid/index/a…

Here is the developer's blog:
livefasteattrashraccoon.github…

Finally, from here you can download the .apk or .deb package without using the online stores. line:
github.com/LiveFastEatTrashRac…

One last recommendation


The public's response will be important to enable the further development of this app.
If you want to test it on Mastodon, I recommend using instances running the glitch-soc fork. Among these, I'd recommend the infosec.exchange instance, which is well managed by @jerry. And of course, but only if you communicate in Italian or Esperanto, I'd be happy to host you on my poliversity.it instance.
Regarding Friendica, I recommend two instances: friendica.world, managed by @ruud and featuring a rather lively timeline, and, of course, social.trom.tf, excellently managed by @tio.
If you communicate in Italian, I'd be happy to host you on my poliverso.org instance.

Greetings to all and let me know if you need further information, if you have tried the app and how you found it.
Francesco
You can also interact with me through the Mastodon account @informapirata and the Friendica account @notizie
in reply to macfranc

Mastodon isn’t the entirely of ActivityPub apps. There's also PeerTube, Pixelfed, Loops, Micro.blog, Flipboard (145M users), Misskey, and many many others.

Is there any ActivityPub app that Lemmy is compatible with, or is it broken for all of them? Why pretend that it's part of a big Fediverse, when a vast majority of these instances are broken to us? (I'm not picking on discuss.tchncs.de, but you can plug in any Lemmy server you want and see the same kind of problems.)

The fact that Lemmy adopts solutions that are different from other software, but still more in line with Activitypub, shouldn’t be considered a problem.


You can have this stance, and be a purist about the RFCs and how the protocol is supposed to work. And you can push for these standards on your own platform for Lemmy.

But, at the end of the day, you still have to deal with the warts of other protocols and write the custom code it takes to bridge one app with another app. And then be thankful that you are not trying to bridge together an entirely different standard and are just trying to smooth over some structural differences in implementation.

in reply to P03 Locke

oh, a clarification: I'm still @macfranc@poliversity.it

I'm a fan of Lemmy, though I recognize that some limitations could be considered flaws (piefed.social/comment/11707767).

However, your perspective must take into account some design (and history) issues with the software you mentioned:

Lemmy barely works with PeerTube [discuss.tchncs.de]


It's important to understand a few concepts here:
- Lemmy is based on Activitypub groups
- A group works by "resharing" an initial post and all replies to that post
- With some programs (Mastodon's "socialverse," Misskey, Pleroma, Friendica, or Pixelfed), you can "post inside a group" only by mentioning the "group user"; with others (Lemmy/Piefed/Mbin/NodeBB's forumverse, but also Peertube, Mobilizon, or Flipboard), you simply assign a discussion to a group (you can do this easily from the interface). This second mode doesn't yet have a syntax shared by all the software in the Fediverse.
- Finally, a very important feature of Lemmy is that a post can only be published to one channel at a time. This might seem like a limitation (we'll discuss it later, when talking about Flipboard), but it's actually designed by the developers to prevent synchronous crossposting, which can dramatically increase spam.

Lemmy handles the display of Peertube content very well and correctly assigns it to the correct Peertube channel. What doesn't work well is the update system, which is why Lemmy can't act as a Peertube feed reader. This isn't Lemmy's fault, nor is it Peertube's, as each handles Activitypub groups differently.

Lemmy doesn't work with Pixelfed [discuss.tchncs.de]


That's not true. Lemmy handles Pixelfed very well. Pixelfed users can open threads on Lemmy or reply to Lemmy discussions. However, Pixelfed only shows users retweets made by Pixelfed, not those from other software. Therefore, Pixelfed users cannot access the groups.
Regarding your user, I'd like to point out that feddit.it can see it: feddit.it/u/NotAHopeInHades@pi…

Lemmy doesn't work with Loops [discuss.tchncs.de]


Loops is still a very immature software, with very limited interoperability. I wouldn't consider it a valid test for certifying Lemmy's functionality.
Regarding your user, I'd like to point out that feddit.it can see it: feddit.it/u/spaceotter@loops.v…

Lemmy doesn't work with Micro.blog [discuss.tchncs.de]


I'm not familiar with Microblog, but (regarding your user) I'd like to point out that feddit.it can see it: feddit.it/u/akshay@social.lear…

Lemmy doesn't seem to work with Flipboard


Flipboard uses groups to manage the "magazines" of the "main accounts." Magazines are the thematic sections of the main account. Basically, the main account (for example, @NationalGeographic@flipboard.com) publishes a news item, and depending on the topic, it can be published in the "Science" Activitypub group (@science-NationalGeographic@flipboard.com) or the "Environment" Activitypub group (@environment-NationalGeographic@flipboard.com), OR both.
This design, intended to maximize visibility on the Mastodon audience, is incompatible with Lemmy's logic.
Lemmy, in fact, as I mentioned before, doesn't allow synchronous crossposting of the same content across multiple groups.

The same goes for Misskey.


Lemmy handles Misskey very well. And Misskey handles Lemmy very well. I don't understand the problem.


From what I can see, that is not a back-end restructuring but as far as a new architectural design it will purely affect the front-end UI. Which will begin to look somewhat more similar to PieFed, yet without coming anywhere close to what PieFed offers today, as opposed to what PieFed offered like a year ago. e.g. there will be no ability to hold polls (or to share those custom-built feeds?).

More relevant is that Lemmy 1.0 may take a year or so to become fully deployed across the Threadiverse, if past experience is any judge. The devs say to explicitly expect major breaking bugs and perhaps to avoid deployment in prod as a result. And ofc apps are going to need to catch up as well. This one being a breaking change may lead most older apps unable to connect to an instance that uses the newer software (unless I am misreading that part about the older backwards compatible API).

Lemmy.world in particular, which holds ~50% of Threadiverse users and >90% of the most highly-active communities (unfortunately for the aim of decentralization) is well-known for delaying deployment until the Lemmy code fixes such issues.

So a year from now Lemmy will begin to catch up to some of what PieFed had almost a year ago in the past already, and meanwhile I expect PieFed will not itself be standing still all that time... I am glad to see that Lemmy is still being actively worked on, truly I am, but also I find it hard to actually be excited about that pace, by comparison. Then again, any movement forward still counts, and improves the Fediverse as a whole, so by however much, it is still a good thing! 😀


reshared this

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Unsere Arbeit kostet viel Geld. Gleichzeitig braucht unsere Zivilgesellschaft kritischen und unabhängigen Journalismus mit Haltung mehr denn je.

Wir bleiben an den drängenden Themen dran und das mit euch gemeinsam! Wir kämpfen für die Grundrechte aller Menschen und setzen uns für eine starke Zivilgesellschaft ein. Jeder Euro zählt und hilft, unseren Kampf für mehr Gerechtigkeit weiterzuführen.

+++ Unterstütze uns unter: netzpolitik.org/spenden/ +++

Questa voce è stata modificata (1 mese fa)
The Pirate Post ha ricondiviso questo.

Mein Text „Die Rückkehr zur Registrierung“ (netzpolitik.org/2026/datenaust…) zur Geschichte und Gegenwart des Datenaustauschs über Menschen mit psychischen Erkrankungen wurde von der Vorjury für den Alternativen Medienpreis 2026 in der Kategorie „Geschichte“ nominiert (alternativer-medienpreis.de/no…). Ich freue mich, dass es die Recherche in die engere Auswahl geschafft hat! ✨
The Pirate Post ha ricondiviso questo.

Die EU-Institutionen verhandeln zentrale Aspekte der Chatkontrolle. Rat und Parlament streiten, ob Internet-Dienste alle Nutzer freiwillig scannen dürfen oder verdächtige Nutzer verpflichtend scannen müssen. Wir veröffentlichen eingestufte Verhandlungsdokumente. netzpolitik.org/2026/interne-d…
The Pirate Post ha ricondiviso questo.

Die EU-Institutionen verhandeln zentrale Aspekte der Chatkontrolle. Rat und Parlament streiten, ob Internet-Dienste alle Nutzer freiwillig scannen dürfen oder verdächtige Nutzer verpflichtend scannen müssen. Wir veröffentlichen eingestufte Verhandlungsdokumente. netzpolitik.org/2026/interne-d…