The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Ababil of Minab: il gruppo Iran-MOIS che ha distrutto 58 server GPS con un solo script Python
#CyberSecurity
insicurezzadigitale.com/ababil…


Ababil of Minab: il gruppo Iran-MOIS che ha distrutto 58 server GPS con un solo script Python


Si parla di:
Toggle

Un singolo script Python. Cinquantotto server Microsoft SQL. Zero possibilità di recupero. È il bilancio dell’operazione condotta dal gruppo Ababil of Minab contro Vyncs, servizio americano di monitoraggio GPS, in quella che i ricercatori di Gambit Security definiscono una campagna sistematica di distruzione del “recovery layer” attribuita al Ministero dell’Intelligence e Sicurezza iraniano (MOIS).

Chi è Ababil of Minab


La persona operativa “Ababil of Minab” è emersa pubblicamente tra la fine di marzo e l’inizio di aprile 2026, rivendicando l’intrusione alla Los Angeles County Metropolitan Transportation Authority (LACMTA / LA Metro), la distruzione di sistemi e l’esfiltrazione di dati. Il gruppo si presenta come un collettivo hacktivista indipendente, ma l’analisi forense condotta da Gambit Security racconta una storia diversa.

Le prove tecniche collegano la campagna attuale all’infrastruttura e all’attività associata a Black Shadow, cluster Iran-linked già pubblicamente attribuito dall’Israel National Cyber Directorate (INCD) al MOIS. La stessa infrastruttura utilizzata in questa operazione era stata impiegata nel 2025 in una falsa piattaforma di supporto psicologico per militari israeliani — il dominio nefeshhope[.]com — attraverso cui venivano raccolti dati personali e distribuito malware.

La portata geografica: quattro paesi, una strategia unica


La campagna ha colpito organizzazioni in Stati Uniti, Israele, Arabia Saudita e Turchia. L’esfiltrazione di dati ha interessato tutte le vittime; le operazioni distruttive sono state riservate a un sottoinsieme di esse, principalmente negli USA. Tra le organizzazioni israeliane e turche colpite figurano istituzioni educative, media, compagnie assicurative e siti culturali — identità che Gambit ha identificato ma che il gruppo non ha scelto di rendere pubbliche.

Lo strumento personalizzato di esfiltrazione recuperato dai ricercatori è FileFiend, un programma scritto in C++ in grado di raccogliere file da dischi locali e di rete per trasmetterli al server di comando. I dati venivano esfiltrati anche attraverso i web server compromessi delle stesse vittime.

Il playbook distruttivo: colpire il layer di recovery


Ciò che distingue Ababil of Minab da un attore ransomware tradizionale è la scelta deliberata di colpire non solo i dati operativi, ma l’intera infrastruttura di ripristino. Ogni tecnica impiegata introduce una sfida di recovery separata, moltiplicando i tempi e la complessità della risposta agli incidenti.

LA Metro (LACMTA): Gli attaccanti hanno ottenuto accesso a VMware vCenter, eliminando le virtual machine insieme ai file disco. Ore dopo, la metropolitan authority segnalava interruzioni nel sistema mobile di pagamento dei trasporti. In seguito, tramite accesso RDP a una macchina Windows guest, hanno eliminato le partizioni dei dischi attraverso lo strumento nativo di gestione dei volumi.

South Florida Regional Transportation Authority: Accesso RDP con privilegi di amministratore locale su un server IIS, seguito dalla cancellazione di database tramite Microsoft SQL Server Management Studio e dall’utilizzo di WipeFile per eliminare il contenuto delle directory del web server e dei backup.

UNIMAC: Formattazione delle partizioni, eliminazione dei volumi e creazione di nuovi volumi rinominati “Minab” come firma. Distruzione della catena di backup attraverso Veeam Backup & Replication.

Lo script automatizzato e l’uso di ChatGPT


L’attacco a Vyncs, il servizio americano di monitoraggio GPS via OBD-II, rappresenta l’episodio più emblematico dell’intera campagna dal punto di vista dell’automazione offensiva. Gli attaccanti hanno sviluppato un file main.py che si connetteva automaticamente a 58 server Microsoft SQL Server e cancellava i database degli utenti. Parallelamente, operatori umani eliminavano manualmente i backup e le directory di sistema Windows. Una volta rimossi i dati, anche la connessione al server si è interrotta — conferma dell’avvenuta distruzione dell’infrastruttura.

Un dettaglio che segna una svolta nell’impiego dell’AI offensiva: nei video pubblicati dallo stesso gruppo, i ricercatori hanno osservato gli operatori utilizzare ChatGPT per raffinare lo script di cancellazione, in particolare per escludere i database di sistema di Microsoft SQL Server dall’elenco degli oggetti da eliminare, assicurandosi che lo script agisse esclusivamente sui dati degli utenti senza bloccarsi per errori di sistema.

“Modern intrusion operators are moving from initial access straight into the recovery layer, virtualization, backups, storage volumes, to maximize destruction and deny remediation. The skill required to do that at scale is collapsing in parallel. As AI capabilities become widely available, any actor, skilled or not, will be able to execute this kind of campaign.”
— Gambit Security Threat Intelligence Team


Implicazioni strategiche: la nuova frontiera del cyber warfare


La campagna di Ababil of Minab illustra un cambiamento fondamentale nella dottrina degli attacchi informatici statali. Non si tratta più solo di compromettere i sistemi o rubare dati: l’obiettivo diventa negare la capacità di recupero, trasformando ogni intrusione in un danno duraturo che richiede settimane o mesi per essere risolto.

La combinazione di tecniche — eliminazione di VM, cancellazione di database, distruzione dei backup Veeam, wiping dei volumi — è progettata per costringere i team di risposta agli incidenti a eseguire processi di remediation separati in parallelo, aumentando la probabilità che almeno uno fallisca o che l’organizzazione non possa tornare operativa nei tempi attesi.

Indicatori di compromissione (IoC)

# Infrastruttura nota
Dominio: nefeshhope[.]com
  Utilizzo: finta piattaforma di supporto psicologico per militari israeliani (2025)
  Collegamento: attributo a Iran MOIS / Black Shadow

# Strumenti identificati
FileFiend - Exfiltration tool C++
  Funzione: raccolta file da dischi locali e di rete, trasmissione a C2

main.py - Script di distruzione DB
  Funzione: connessione automatica a SQL Server, eliminazione database utenti
  Nota: raffinato con ChatGPT per escludere DB di sistema

WipeFile - Utility di cancellazione sicura
  Utilizzo: pulizia directory web server e backup

# Tecniche TTP (MITRE ATT&CK)
T1078 - Valid Accounts (RDP con credenziali admin)
T1485 - Data Destruction
T1490 - Inhibit System Recovery (Veeam destruction)
T1486 - Data Encrypted for Impact (analoga a ransomware senza riscatto)
T1041 - Exfiltration Over C2 Channel (FileFiend)

Due righe per i difensori


La campagna di Ababil of Minab rende evidente che la sicurezza perimetrale da sola non è più sufficiente. Le organizzazioni devono investire nella resilienza operativa, con particolare attenzione a tre aree critiche:

  • Backup immutabili e isolati: I backup devono essere fisicamente e logicamente separati dall’ambiente primario. La compromissione di Veeam o di altri sistemi di backup integrati nella stessa infrastruttura virtuale vanifica qualsiasi piano di recovery.
  • Protezione dell’accesso all’infrastruttura di virtualizzazione: VMware vCenter e sistemi equivalenti devono essere protetti con autenticazione multi-fattore obbligatoria, accesso privilegiato minimo e segmentazione di rete dedicata. Un account vCenter compromesso può eliminare l’intera infrastruttura in minuti.
  • Validazione continua del recovery: Non è sufficiente avere backup. Le organizzazioni devono testare regolarmente la capacità di ripristino in scenari avversariali — non solo in caso di guasto hardware. La domanda non è “abbiamo i backup?”, ma “riusciremo davvero a ripristinare in tempo?”.

Il report completo di Gambit Security è disponibile per il download sul loro sito ed include la documentazione forense completa, i dettagli sull’infrastruttura e l’analisi delle vittime non ancora pubblicamente identificate.


The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Glassworm smantellato: CrowdStrike abbatte la botnet che prendeva di mira gli sviluppatori attraverso npm, PyPI e GitHub
#CyberSecurity
insicurezzadigitale.com/glassw…


Glassworm smantellato: CrowdStrike abbatte la botnet che prendeva di mira gli sviluppatori attraverso npm, PyPI e GitHub


Si parla di:
Toggle

CrowdStrike Counter Adversary Operations, Google e Shadowserver Foundation abbattono simultaneamente tutti e quattro i canali di comando e controllo della botnet Glassworm. Infetta da oltre un anno attraverso l’ecosistema open-source, l’infrastruttura criminale — progettata per sopravvivere ai takedown tradizionali usando blockchain, peer-to-peer e servizi Google come dead-drop — perde il controllo di migliaia di macchine di sviluppatori in tutto il mondo.

Perché gli sviluppatori sono il bersaglio ideale


Glassworm rappresenta un cambio di paradigma nel threat landscape: gli attaccanti non prendono più di mira direttamente i prodotti software — prendono di mira le persone che li costruiscono. Un singolo workstation di sviluppatore compromessa può aprire agli attaccanti l’accesso a repository di codice sorgente, piattaforme cloud, pipeline CI/CD, credenziali di accesso e registry di pacchetti. Da lì, il malware può propagarsi a valle della supply chain, raggiungendo organizzazioni che non hanno mai avuto contatti diretti con gli operatori di Glassworm.

Dall’inizio del 2025, gli operatori di Glassworm hanno condotto una campagna sistematica contro gli sviluppatori su Windows, macOS e Linux, sfruttando tre vettori principali dell’ecosistema open-source:

1. Estensioni VSCode trojanizzate su OpenVSX


Le estensioni malevoli venivano pubblicate sul marketplace OpenVSX, camuffate da strumenti legittimi come time tracker e code formatter. L’impatto andava oltre VSCode: qualsiasi editor compatibile con l’ecosistema — Cursor, Positron, Windsurf, VSCodium — risultava vulnerabile allo stesso payload.

2. Pacchetti npm e Python con hook di installazione malevoli


Il codice malevolo veniva eseguito durante l’installazione ordinaria delle dipendenze, attraverso hook postinstall e script setup.py. Per lo sviluppatore, l’operazione appariva come un normale aggiornamento di libreria. Il payload veniva eseguito prima che qualsiasi analisi manuale potesse rilevarlo.

3. Repository GitHub avvelenati con credenziali rubate


Oltre 300 repository GitHub sono stati compromessi usando credenziali di sviluppatori ottenute in infezioni precedenti. Gli operatori eseguivano force push sui branch predefiniti, inserendo codice malevolo dove altri sviluppatori si aspettavano di trovare il progetto originale — un classico attacco alla fiducia implicita nell’ecosistema open-source.

GlasswormRAT: le capacità del malware


Il payload finale installato dalle infezioni Glassworm è GlasswormRAT, un remote access tool scritto in Node.js con funzionalità complete: furto di informazioni, harvesting di credenziali e controllo remoto completo del sistema compromesso. Nel corso di oltre un anno di operazioni, gli sviluppatori di Glassworm hanno evoluto continuamente il codice, passando da JavaScript a Rust e Zig, ampliando il supporto a più ecosistemi e costruendo infrastrutture ridondanti in previsione di eventuali takedown.

L’architettura C2 a quattro canali: progettata per sopravvivere


L’elemento più sofisticato di Glassworm è la sua infrastruttura di comando e controllo, progettata esplicitamente per resistere ai takedown tradizionali. I ricercatori hanno identificato quattro canali distinti che garantivano ridondanza operativa:

  • Blockchain Solana: Gli indirizzi dei server C2 venivano codificati nei campi memo delle transazioni blockchain. Una volta scritti, i dati sono immutabili e pubblicamente accessibili — non possono essere rimossi da una richiesta a un hosting provider.
  • BitTorrent DHT (Distributed Hash Table): GlasswormRAT interrogava la rete peer-to-peer BitTorrent cercando dati di configurazione attraverso chiavi pubbliche hardcoded. Una rete decentralizzata senza single point of failure, impossibile da abbattere con i metodi convenzionali.
  • Google Calendar: Il malware usava i titoli degli eventi di Google Calendar come dead-drop per path C2 codificati in Base64. Per i difensori, bloccare il dominio avrebbe significato interrompere anche l’uso legittimo del calendario aziendale.
  • Server VPS diretti: Infrastruttura C2 tradizionale su provider commerciali, usata per la delivery dei payload finali alle macchine infette.

La combinazione di questi quattro canali rendeva qualsiasi takedown parziale inefficace: abbattere uno solo avrebbe consentito agli operatori di ripristinare il controllo attraverso gli altri tre. Questo è il motivo per cui il takedown ha richiesto una coordinazione precisa tra CrowdStrike, Google e Shadowserver Foundation per colpire tutti e quattro i canali simultaneamente alle 14:00 UTC.

Attribuzione: gli indizi puntano verso la Russia


CrowdStrike attribuisce con moderata fiducia la campagna a operatori con sede in Russia, basandosi su un pattern coerente osservato per oltre un anno. Il malware effettua controlli runtime sulla locale, la lingua e il fuso orario della vittima, terminando silenziosamente se la macchina risulta in un paese CIS — una tecnica consolidata tra i cybercriminali dell’area ex-sovietica per evitare di colpire obiettivi vicini a casa. Nel codice sorgente compaiono commenti in russo.

CrowdStrike precisa che nessun indicatore singolo costituisce prova definitiva: i controlli di locale possono essere copiati, i commenti possono derivare da strumenti AI. Ma il pattern complessivo, consistente per oltre dodici mesi di osservazione, è considerato sufficientemente solido per l’attribuzione.

Come verificare un’infezione da Glassworm


Dopo il takedown, tutte le macchine infette da Glassworm tentano di contattare un IP gestito da CrowdStrike (sinkholed). Qualsiasi connessione a questo indirizzo nei log di rete indica un’infezione attiva che richiede remediation immediata.

# Indicatore di rete (sinkhole CrowdStrike post-takedown)
IP: 164.92.88[.]210
# Cosa verificare:
- Log di rete per connessioni a 164.92.88[.]210
- Telemetria endpoint su workstation sviluppatori
- Installazioni recenti di estensioni OpenVSX da fonti non verificate
- Pacchetti npm o Python installati da repository non ufficiali
- Repository GitHub con commit anomali o force push recenti
# YARA Rule 1: GlasswormRAT
rule CrowdStrike_GlasswormRat_01 : glassworm glasswormrat
{
    meta:
        description = "Characteristic strings in Glassworm RAT script"
        malware_family = "GlasswormRAT"
    strings:
        $download = "DownloadManager" ascii
        $socks = "start_socks" ascii
        $nodejs = "https://nodejs.org/download/release" ascii
        $dht = "bootstrap" ascii
    condition:
        all of them
}
# YARA Rule 2: Glassworm Python Downloader
rule CrowdStrike_GlasswormDownloader_01 : glassworm
{
    meta:
        description = "Obfuscated Python installer Glassworm variant"
        malware_family = "Glassworm"
    strings:
        $zlib = "__import__('zlib')" ascii
        $decomp = "decompress(" ascii
        $lambda = "lambda" ascii
        $exec = /exec\(compile\(.{5,20}, '', 'exec'\)\)/
    condition:
        all of them and filesize < 10KB
}

Il takedown come modello: cosa cambia nella difesa della supply chain


L'operazione Glassworm dimostra che la difesa attraverso la sola detection è strutturalmente insufficiente contro gli attacchi alla supply chain. I pacchetti malevoli vengono installati in secondi durante aggiornamenti di routine; la detection avviene dopo che il danno è già fatto. Con decine di ecosistemi — npm, PyPI, OpenVSX, GitHub — e milioni di pacchetti con controlli di sicurezza limitati, gli attaccanti possono pubblicare codice malevolo e raggiungere migliaia di vittime in minuti.

Il takedown coordinato imposta un precedente operativo: la disruption proattiva dell'infrastruttura avversariale è tecnicamente possibile anche contro architetture C2 deliberatamente progettate per la resilienza. La precisione richiesta — colpire simultaneamente blockchain, DHT, servizi Google e VPS tradizionali — ha richiesto la collaborazione tra intelligence privata (CrowdStrike), piattaforme tecnologiche (Google) e coordinamento internazionale (Shadowserver Foundation).

Per i team di sicurezza, le raccomandazioni immediate includono: audit delle estensioni installate negli ambienti di sviluppo, verifica dei pacchetti npm e Python con strumenti come npm audit e pip-audit, revisione dei log di accesso ai repository GitHub per force push anomali, e implementazione di controlli di integrità sulle dipendenze nei pipeline CI/CD.


The Pirate Post ha ricondiviso questo.

Der chinesische Online-Händler Temu schlampt im Umgang mit gefährlichen und illegalen Produkten, hat heute die EU-Kommission festgestellt. Nach X handelt es sich um den zweiten Online-Dienst, der gegen den Digital Services Act verstoßen hat. netzpolitik.org/2026/unsichere…

Message in a Bottle #10 – Declaration of Principals


The following was submitted by a Pirate supporter using the pseudonym “A. Pirate, MD.”; the Declaration of Independence, reborn as a Pirate Party battle cry against two-party rule. This article is apart of the project “Message in a Bottle”, allowing supporters of the US Pirate Party to submit editorial articles to the United States Pirate Party website.


“When in the course of human events, it becomes necessary for one people to dissolve the political bands which have connected them with another and to assume among the powers of the Earth, the separate and equal station to which the laws of nature and of nature’s God entitled them a decent respect to the opinions of mankind requires that they should declare the causes which impel them to the separation” – Thomas Jefferson, Declaration of Independence, 1776

When asked where they stand on politics, 250 years later, many Americans respond succinctly, “I think we should just burn it all down and start over”. The same frustration experienced by the American colonies lives on in the modern day.

Several truths that Jefferson, paraphrasing Voltaire, thought to be “Self-Evident” were that “all men are created equal” and that “they are endowed by their creator with certain unalienable rights. That among these are Life, Liberty, and the pursuit of happiness”

These principles of equality, life, liberty and happiness still excite us and draw us toward hope. For 250 years we have strived for them and fought against them so violently that we could hardly claim any ownership of these virtues. We may only hold them up as goals yet unattained and renew our commitment to move in their direction.

Jefferson, as part of the committee of five, goes on to state that, “To secure these rights, governments are instituted among men-deriving their just powers from the consent of the governed”.

The Constitution of the United States sought to institute a representative government and to create a structure for obtaining the consent of the governed. This government has been altered over time by constitutional amendments and by acts and laws meant to “perfect” the union.

However, every change has been accompanied by more power lost by the people and gained by industry and factions.

The Declaration stated plainly, “That whenever any form of government becomes destructive of these ends, it is the right of the people to alter or abolish it and to institute new government”. It said clearly that its principles and structures should be those which seem most likely to effect the people’s safety and happiness. Jefferson went on to declare that “it is their right. It is their duty to throw off such government and to provide new guards for their future security”

Before enumerating the transgressions of the king who had so offended the colonists, the Congress identified six principles (equality, life, liberty, happiness, safety and security) upon which government should be founded.

The problem inherent in these principles is that they conflict with one another. Life is often in jeopardy when safety is threatened. Liberty frequently conflicts directly with security. And, equality contradicts individual pursuits of happiness.

The Committee of Five (Jefferson, Franklin, Adams, Livingston and Sherman), suggested prudence in deciding to alter “governments long established” and applauded the “patient sufferance” of the colonies. These qualities are necessary to endure the balance of conflicting priorities inherent in government.

But, “when a long train of abuses and usurpations” by the king tyrannized the colonists, they decided to act. The modern-day tyrant is a system of government completely beholden to industry and special interests which subverts the needs of citizens in the name of party.

Each party isolates and demonizes the other while representing a scant quarter of the actual voting public. Neither values the rights of the rest and our principles are compromised in the name of consolidating power and treasure.

Out of a “decent respect to the opinions of mankind” the founders listed the grievances which precipitated their separation from England. So, in Colonial terms, “let facts be submitted to a candid world”.

  • Under two-party rule, the deficit has risen to more than $38 Trillion dollars and the people pay ever-more taxes to pay only the interest with no plan to repay the principle.
  • The Federal Reserve continues to profit from deficit spending by both parties which enriches banks and bankers at the expense of the people.
  • Each party gerrymanders the maps to consolidate power over the other party while failing to provide actual representation to the people. In this way, constituents are chosen by the parties and the people never get to choose their representatives.
  • Private equity firms and foreign powers fund campaigns for both parties in exchange for favors. This amounts to sedition in that it undermines the integrity of our elections, Congress and executive branch and leaves each participant open to blackmail and manipulation. The appearance of corruption is everywhere.
  • Their constant infighting deprives us of common-sense laws which protect and preserve our rights in favor of laws which further deny us our lives, liberty, and property to bolster and finance private industry.
  • Congress has failed to check or to balance the over-reach of the executive branch in direct violation of our constitution.
  • They have spent over $14 Trillion on the department of homeland security and the department of defense to fight wars which have not contributed greatly to our security while costing us lives and liberties for almost 25 years.
  • During the same 25 years, they have spent $150 billion to maintain the largest prison population the world has ever known.
  • The have violated the privacy of citizens en masse and without judicial oversight.
  • They have failed to facilitate and legislate legal immigration and weaponized the enforcement of immigration policy to violate human and constitutional rights.
  • They have weaponized our police forces against us in violation of our privacy, civil rights, and human rights.
  • They have used force, coercion, and murder to deprive us of trial by jury.
  • They have protected these officers by mock trials for the felonies and murders they have committed against us.
  • They have corrupted the courts by way of political appointment and created political conflict between the executive and judicial branches.
  • They have become rich by committing financial crimes through insider trading, taking bribes by way of campaign contributions, and accepting emoluments in exchange for selling out our security.
  • They have manipulated free markets to our detriment for personal and political gain.
  • They have protected criminal activity through pardons for convicted drug lords and wayward family members.
  • They have facilitated the importation and distribution of poisonous chemicals among us under the guise of progress, control, trade, or science.
  • They have imposed taxes on us without representation.
  • They have created trade agreements which make us dependent on other nations and denied us trade relations more favorable to our security.
  • They have refused to secure statehood and representation for Puerto Rico and Washington DC.
  • They have deregulated corporate polluters in exchange for financial and political favors.
  • They have failed to fully repair the damages suffered by our native populations during the genocide of the 18th, 19th and 20th centuries.

“In every stage of these oppressions, we have petitioned for redress in the most humble terms: our repeated petitions have been answered only by repeated injury”.

That line is directly from the Declaration. Their actions are the very definition of tyranny which is by the reckoning of the Second Continental Congress “unfit to rule a free people”.

We have told the Congress that we want honesty, transparency, equity, privacy, freedom, and liberty. We have begged them to legislate term limits, stop insider trading, reform campaign finance laws, and hold government accountable when our rights are violated.

We have asked for safety, security, and clear pathways to pursue happiness. We ask for low taxes and fair wages. Yet we are, again and again, met with frustration, aggression and suppression of our voices in favor of the two-parties.

We, therefore, as Pirates, declare ourselves independent of the two party system. We call for an Article V Convention of States to amend our Constitution and to reform our government to provide new guards for our security and to alter the system to one that may better effect our happiness.


uspirates.org/message-in-a-bot…

Elezioni e Politica 2026 reshared this.

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

BadHost (CVE-2026-48710): Critical Authentication Bypass Threatens Thousands of AI Agent Applications
#CyberSecurity
securebulletin.com/badhost-cve…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Tycoon 2FA Phishing Kit Bypasses MFA at Scale — 62% of Microsoft 365 Phishing Attempts Linked to Single Threat Actor
#CyberSecurity
securebulletin.com/tycoon-2fa-…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Seedworm (MuddyWater) APT Abuses Signed Security Binaries in Global Espionage Campaign Across 9 Countries
#CyberSecurity
securebulletin.com/seedworm-mu…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

NightSpire Ransomware Exploits RDP and Remote Admin Tools to Hit 64 Organizations in 33 Countries
#CyberSecurity
securebulletin.com/nightspire-…

What’s behind the EU’s digitalisation push? Surveillance, control and exclusion


The EU institutions have been engaged in a broad and wholesale digitalisation project but underneath the rhetoric of efficiency, modernisation, and citizen empowerment lies a more troubling reality. It is not a mere technical upgrade of public services, but a political choice, long in the making, to forego care and rights of individuals in favour of normalising surveillance, control and exclusion of the most marginalised. This blog explores the various facets of the EU’s digital welfare state push, and what it means for the relationship between people and the state.

The post What’s behind the EU’s digitalisation push? Surveillance, control and exclusion appeared first on European Digital Rights (EDRi).

Elezioni e Politica 2026 reshared this.

A push back to Czech football club‘s plan to install facial recognition CCTV system


There is a debate in the Czech Republic over the use of facial recognition cameras in stadiums. Both clubs and politicians are calling for biometric surveillance after hundreds of fans stormed the football pitch during a recent match. The debate has unfolded with pushbacks from the public opinion and digital rights groups, including IuRe, while government officials are still considering the implementation of biometric system regardless of their illegality.

The post A push back to Czech football club‘s plan to install facial recognition CCTV system appeared first on European Digital Rights (EDRi).

reshared this

Inside Italy’s low-cost spyware economy


Commercial spyware in Europe has recently made headlines with the now notorious names of Pegasus and Graphite, the expensive, exploitation-driven products at the top end of the market. Much less known is the wide underworld ecosystem of low-cost spyware vendors, often targeting citizens via their smartphones. EDRi member Osservatorio Nessuno has investigated and analysed two separate products, Spyrtacus and Morpheus.

The post Inside Italy’s low-cost spyware economy appeared first on European Digital Rights (EDRi).

Elezioni e Politica 2026 reshared this.

The Pirate Post ha ricondiviso questo.

Ein Journalist wurde mit dem Staatstrojaner Predator angegriffen. Gegen diesen Hacking-Versuch wehrt sich Trung Khoa Lê jetzt. Er stellt Strafanzeige. Die GFF @Freiheitsrechte unterstützt ihn, denn der Staat sei verpflichtet, ihn vor solchen Angriffen zu schützen netzpolitik.org/2026/strafanze…

Journalists slam proposed Paramount merger as threat to press freedom


FOR IMMEDIATE RELEASE:

A group of award-winning journalists and documentarians expressed strong opposition to the proposed merger between Paramount and Warner Bros. Discovery during a press conference today, citing the threat the deal poses to journalism and American democracy.

Journalists Kara Swisher, Jim Acosta, and Katie Phang along with Emmy-winning documentary filmmakers Laura Poitras and Geeta Gandbhir spoke at the event, hosted by Freedom of the Press Foundation (FPF), Democracy Defenders Fund, International Documentary Association, Future Film Coalition, and Free Press.

The 2026 News & Documentary Emmy Awards, which begin tonight, celebrate achievements that wouldn’t be possible without press freedom and editorial independence. But, as the speakers discussed, Paramount CEO David Ellison has a track record of throwing those fundamental American principles under the bus to curry favor with the Trump administration, harming the press, the public, and Paramount itself. Case in point, today news broke that Paramount-owned CBS News would not renew the contract of journalist Sharyn Alfonsi, who resisted censorship of her “60 Minutes” story on torture of Venezuelan migrants.

“I think what’s happening right now is pretty dangerous,” said Acosta. “To essentially announce the departure of Sharyn Alfonsi from 60 Minutes is a very in-your-face move by some people who don’t care very much about the First Amendment.” Acosta added, “Folks need to use a little bit of their imagination here to recognize what may be coming down the pike” with a “strange oligarchical empire … attempting to do state media.”

“There’s a feeling that the wall has come down between editorial independence and corporate interests,” said Swisher. “They’re not doing it for economics. The math doesn’t math. You think Elon Musk bought Twitter to make money? These people are rich beyond all possible wealth. You have to really be thinking about what’s the actual game here, and the actual game is influence, and to take corporate interests and align them with editorial.”

Phang added that in a world where the government dictates who owns the media, “editorial independence will be a thing of the past, and what you’ll have is no one capable of being able to hold power to account.”

“Consolidation of media is bad for the public, it’s bad for creators, it’s bad for the public’s right to know,” said Poitras, who also serves on FPF’s board of directors. “The government has always tried to silence and censor the press, and the job of the press and the journalist is to be adversarial to power … the interests of corporations are entirely different [from] what is good for the press,” which, she explained, leads to capitulation by conglomerates faced with government pressure.

Gandbhir highlighted an often-overlooked issue: The proposed merger’s impact on news archives. “Many of us documentary filmmakers depend on access to archives to make our films, and specifically, the CNN archive holds over 4 million assets, spanning 45-plus years of global news, wars, elections, and political events. And, the CBS archive adds to that years of network television programming. And folding these two massive archives, two of the four major U.S. news archives, under the control of one entity, who has shown themselves to be active in editorial suppression, is a grave threat to documentary filmmakers,” she explained.

FPF also released an open letter yesterday signed by over 200 current and former journalists, documentarians, journalism professors, and rights organizations. The letter elaborates on the dangers of allowing the administration to steer media companies to stooges and oligarchs who have shown a willingness to censor the news — and tank news companies — to further their own interests. Notable signers include Sam Donaldson, SE Cupp, and Mehdi Hasan, as well as Acosta, Phang, and Poitras, among many others. FPF plans to continue collecting signatures.

FPF Chief of Advocacy Seth Stern said: “The First Amendment assumes that the government will attempt to silence the press, but the First Amendment also assumes that the press won’t voluntarily agree, won’t go down without a fight.” He added that “news outlets have a constitutional right to report from whichever perspective they see fit, but presidents don’t have a right to abuse their offices to shape those decisions, and executives like Ellison who are willing to let them do so need to stay out of the news business and find some other widget to sell.”

Please contact us if you would like further comment or a copy of the transcript and/or video of the press conference.


freedom.press/issues/journalis…

Elezioni e Politica 2026 reshared this.

Unsealing of failed Don Lemon and Georgia Fort warrants exposes attack on press


FOR IMMEDIATE RELEASE:

New York, May 27, 2026 — A federal judge twice rejected search warrant applications for the YouTube accounts of journalists Don Lemon and Georgia Fort, according to court records unsealed yesterday. Federal prosecutors sought the search warrants in connection with the spurious criminal cases they’re pursuing against Lemon and Fort for covering a protest at a church in St. Paul, Minnesota. A third journalist, photographer Junn Bollmann, is also facing baseless charges.

Magistrate Judge John Docherty rejected the initial warrants — which sought information about Lemon and Fort’s use of their YouTube channels as well as information about the people who may have watched them — because they lacked probable cause, a basic legal requirement for all search warrants.

Docherty then refused to sign the resubmitted search warrants because they failed to comply with the requirements of the Privacy Protection Act of 1980, a federal law that prohibits most search warrants targeting journalists and others who disseminate information to the public. The government later withdrew the search warrants, and Docherty ordered them unsealed.

The following statement can be attributed to Freedom of the Press Foundation (FPF) Senior Advocacy Adviser Caitlin Vogus:

“These failed search warrants are what happens when incompetent prosecutors pursue political vendettas instead of justice. Having or watching a YouTube channel aren’t crimes, and neither is reporting on a protest. Before the Department of Justice embarrasses itself even more, it should immediately drop the prosecutions of Don Lemon, Georgia Fort, and Junn Bollmann.

Once again, the DOJ also conveniently left out of its applications any mention of the Privacy Protection Act of 1980 and later wrongly insisted that prosecutors don’t need to tell judges when the warrants the government seeks may violate federal law. At this point, every judge should assume the DOJ will try to sneak illegal search warrants past the court. Congress should pass the Privacy Protection Updates Act before this abuse gets even worse.

“Secrecy around search warrants can be dangerous. These applications only became public because the government failed so badly, and Judge John Docherty properly recognized the public’s right to see them. Given the DOJ’s repeated attacks on First Amendment rights and flagrant abuse of the legal system, journalists and all Americans should be asking what’s still buried in sealed search warrant applications around the country.”

Please contact us if you would like further comment.


freedom.press/issues/unsealing…

reshared this

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

SQL Server 2025 e Azure SQL: vettori, modelli AI nativi e agenti autonomi nel database
#tech
spcnet.it/sql-server-2025-e-az…
@informatica


SQL Server 2025 e Azure SQL: vettori, modelli AI nativi e agenti autonomi nel database


SQL Server 2025: un database nativamente AI


Con il rilascio di SQL Server 2025 (versione 17.x) e i progressivi aggiornamenti di Azure SQL Database, Microsoft ha compiuto un salto qualitativo radicale: non si tratta più di integrare l’intelligenza artificiale come funzionalità accessoria, ma di rendere il database stesso una piattaforma AI di prima classe. Vettori, modelli esterni, agenti autonomi e GitHub Copilot nel gestore dello studio: in questo articolo esploriamo tutto ciò che i professionisti IT devono conoscere.

Tipo di dato VECTOR e ricerca semantica con DiskANN


Il cambiamento più strutturale è l’introduzione del tipo di dato nativo VECTOR, supportato dall’indice DiskANN (Disk-based Approximate Nearest Neighbor), un algoritmo ottimizzato per la ricerca di similarità in grandi dataset ad alta dimensionalità.

Un vettore di embedding è una rappresentazione numerica densa di un contenuto (testo, immagine, documento) in uno spazio ad alta dimensionalità. SQL Server 2025 supporta vettori fino a 1536 dimensioni, compatibili con i modelli di embedding Azure OpenAI come text-embedding-3-large.

-- Creazione tabella con colonna vettoriale
CREATE TABLE Documenti (
    Id INT PRIMARY KEY,
    Testo NVARCHAR(MAX),
    Embedding VECTOR(1536)
);

-- Ricerca di similarità semantica tramite distanza coseno
SELECT TOP 5
    Id,
    Testo,
    VECTOR_DISTANCE('cosine', Embedding, @queryEmbedding) AS Distanza
FROM Documenti
ORDER BY Distanza ASC;

La funzione VECTOR_DISTANCE supporta le metriche cosine, euclidean e dot. In marzo 2026 Microsoft ha annunciato ulteriori ottimizzazioni tramite quantizzazione (riduzione della precisione vettoriale per risparmiare storage e accelerare il calcolo) e iterative filtering, disponibili sia su Azure SQL Hyperscale che su SQL Database in Microsoft Fabric.

CREATE EXTERNAL MODEL: modelli AI come oggetti database


Una delle novità più significative per gli sviluppatori è la possibilità di registrare modelli AI esterni come oggetti database di prima classe, con la stessa dignità di una tabella o di una view.

-- Registrazione di un modello Azure OpenAI come external model
CREATE EXTERNAL MODEL AzureOpenAI_Ada
WITH (
    LOCATION = 'https://mio-endpoint.openai.azure.com/',
    API_KEY = 'secret-key',
    API_TYPE = 'azure_openai',
    DEPLOYMENT = 'text-embedding-ada-002',
    TASK = 'EMBEDDINGS'
);

Una volta registrato, il modello è disponibile per tutte le query T-SQL dell’istanza, con gestione automatica del retry per i fallimenti transitori e supporto per il versioning (A/B testing tra deployment diversi).

La stored procedure sp_invoke_external_rest_endpoint consente invece di chiamare qualsiasi API REST direttamente da T-SQL, incluse OpenAI, Azure OpenAI, Anthropic e anche modelli locali come Ollama:

EXEC sp_invoke_external_rest_endpoint
    @url = 'https://api.openai.com/v1/embeddings',
    @method = 'POST',
    @headers = '{"Authorization": "Bearer sk-xxx", "Content-Type": "application/json"}',
    @payload = '{"input": "testo da vettorializzare", "model": "text-embedding-3-small"}',
    @response = @json OUTPUT;

RAG nativo: addio al database vettoriale separato


Il pattern Retrieval-Augmented Generation (RAG) — recuperare contesto rilevante da una base di conoscenza per arricchire il prompt di un LLM — si implementa ora interamente all’interno di SQL Server, senza bisogno di database vettoriali separati come Pinecone, Milvus o Weaviate.

Il flusso tipico è:

  1. Inserire i documenti nella tabella con colonna VECTOR
  2. Generare gli embedding tramite CREATE EXTERNAL MODEL o sp_invoke_external_rest_endpoint
  3. Archiviare i vettori nella stessa tabella dei dati operativi
  4. Al momento della query, vettorializzare il testo dell’utente e cercare i k documenti più simili con VECTOR_DISTANCE
  5. Passare i documenti recuperati come contesto all’LLM

Questo approccio elimina la complessità della sincronizzazione tra il database relazionale e quello vettoriale, riducendo la latenza e semplificando enormemente la gestione della sicurezza (un solo perimetro di autorizzazione).

Per scenari ibridi, è disponibile anche l’integrazione con Azure AI Search, che combina full-text search tradizionale con ricerca vettoriale semantica.

Agenti AI autonomi e GitHub Copilot in SSMS 22


SQL Server 2025 introduce il concetto di agente AI integrato nel database: un componente che riceve richieste in linguaggio naturale, le traduce in T-SQL, le esegue e ragiona sui risultati per determinare i passi successivi, rispettando il modello di sicurezza e i permessi SQL Server.

Azure SQL Database Hyperscale espone un SQL MCP Server (endpoint Model Context Protocol, ora in public preview), che consente ad agenti AI e Copilot di connettersi al database e ragionare sui dati SQL per applicazioni cloud-native.

GitHub Copilot in SSMS 22 è diventato generalmente disponibile l’11 novembre 2025. Le funzionalità principali:

  • Chat in linguaggio naturale per interrogare il database o costruire query T-SQL
  • Slash command: /doc per la documentazione, /fix per la correzione errori, /explain per la spiegazione di query complesse
  • Database instructions: contesto specifico del database e regole di business memorizzati come extended properties, che Copilot applica automaticamente
  • Autocompletamento contestuale nell’editor query (disponibile dalla versione SSMS 22.2.1, rilasciata il 21 gennaio 2026)


Machine Learning Services e integrazione con i framework AI


SQL Server Machine Learning Services — disponibile sin da SQL Server 2016 con R e poi Python — continua a essere supportata in SQL Server 2025. Permette di eseguire script Python e R in-database, senza spostare i dati fuori da SQL Server, mantenendo il perimetro di sicurezza e riducendo l’overhead di rete.

SQL Server 2025 aggiunge il supporto ai principali framework di orchestrazione AI:

  • LangChain: il pacchetto langchain-sqlserver abilita chatbot con pattern RAG sui dati SQL, con orchestrazione tramite LangChain e UI via Chainlit
  • Semantic Kernel: SDK open source Microsoft per .NET (e altri linguaggi), include un connettore nativo per il vector store di SQL Server, permettendo di costruire agenti e applicazioni RAG che chiamano modelli, strumenti e SQL Server in modo integrato
  • LSTM e architetture ibride: l’integrazione con Long Short-Term Memory offre un framework per agenti che devono mantenere stato contestuale su sequenze di interazioni


Copilot in Azure SQL Database


Microsoft Copilot in Azure SQL Database — in GA dall’11 aprile 2025 — offre esperienze AI-assisted per DBA e sviluppatori:

  • Risposta a domande sulle performance del database in linguaggio naturale
  • Troubleshooting tramite Dynamic Management Views e Query Store
  • Generazione T-SQL da descrizioni plain-text con spiegazione dettagliata delle query
  • Code completion nell’editor query di Fabric e quick actions per fix/explain

Il sistema analizza i metadati del database (nomi tabelle, colonne, struttura) per generare suggerimenti contestuali senza accedere ai dati effettivi.

Requisiti e disponibilità


Le funzionalità core — tipo VECTOR, CREATE EXTERNAL MODEL, sp_invoke_external_rest_endpoint — richiedono:

  • On-premises: SQL Server 2025 (17.x)
  • Azure SQL Database: tier Hyperscale
  • Azure SQL Managed Instance: policy di aggiornamento Always-up-to-date o SQL Server 2025
  • GitHub Copilot in SSMS: SSMS 22 o superiore, account GitHub con Copilot attivo
  • Azure OpenAI: risorsa con modelli di embedding distribuiti (text-embedding-3-large, text-embedding-3-small, text-embedding-ada-002)

In marzo 2026 Microsoft ha aggiunto: Database Hub in Microsoft Fabric (early access), SQL MCP Server per Azure SQL Hyperscale (public preview), e opzioni vCore più ampie (160 e 192) per Hyperscale. È stato anche annunciato un savings plan per database con risparmio fino al 35% rispetto al pay-as-you-go su impegno annuale.

Conclusione


SQL Server 2025 non è un semplice aggiornamento di versione: è il risultato di una strategia pluriennale per trasformare il database relazionale in un motore AI nativo. Per i professionisti IT che già operano nell’ecosistema Microsoft, le implicazioni sono concrete: è possibile implementare ricerca semantica, RAG, agenti autonomi e assistenza AI alle query senza aggiungere infrastrutture esterne, riutilizzando il perimetro di sicurezza e la governance già in essere su SQL Server.

La sfida è ora architetturale: capire dove ha senso spostare logica AI dentro il database e dove invece mantenerla nell’application layer. Ma avere questa scelta — e i tool per implementarla — è già un notevole passo avanti.


Fonte originale: AI features in Microsoft SQL Server 2025 and Azure SQL – 4sysops


The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Nimbus Manticore e il backdoor MiniFast: l’Iran usa l’IA per colpire aviazione e oil&gas durante la guerra
#CyberSecurity
insicurezzadigitale.com/nimbus…


Nimbus Manticore e il backdoor MiniFast: l’Iran usa l’IA per colpire aviazione e oil&gas durante la guerra


Mentre i cacciabombardieri statunitensi e israeliani colpivano obiettivi nucleari iraniani nel febbraio 2026, dall’altra parte del fronte cibernetico il gruppo Nimbus Manticore — affiliato ai Pasdaran (IRGC) — non rallentava. Accelerava. Tre ondate di attacchi in tre mesi, un nuovo backdoor sviluppato con l’ausilio dell’intelligenza artificiale, tecniche d’infezione mai viste prima: è quanto emerge dall’analisi congiunta pubblicata da Check Point Research e confermata da Palo Alto Networks Unit 42.

Il contesto: cyberoperazioni in tempo di guerra


Il 28 febbraio 2026 gli Stati Uniti e Israele hanno avviato Operation Epic Fury, la campagna militare che ha colpito le infrastrutture nucleari iraniane. Nelle stesse ore, Nimbus Manticore — già noto per campagne contro aviazione, difesa e telecomunicazioni con il malware MiniJunk — ha dimostrato una capacità di adattamento operativo senza precedenti: anzichè fermarsi, il gruppo ha sviluppato e distribuito nuovi strumenti offensivi nel mezzo del conflitto.

Il gruppo (tracciato anche come UNC1549 e Screening Serpens) è stato attivo in almeno cinque paesi — USA, Israele, Emirati Arabi Uniti, Arabia Saudita, Australia — colpendo aziende del settore aerospaziale, petrolifero, software e delle telecomunicazioni. Tra i bersagli identificati da Unit 42 figura anche un’azienda statunitense del settore oil & gas.

Tre ondate di attacchi: febbraio, marzo, aprile 2026


Prima ondata (febbraio 2026) — AppDomain Hijacking + MiniJunk. Prima ancora dello scoppio del conflitto, il gruppo prendeva di mira dipendenti di aziende software e aerospaziali in Arabia Saudita e Australia con false offerte di lavoro. Le vittime venivano indotte a scaricare un archivio ZIP ospitato su OnlyOffice contenente un eseguibile Microsoft legittimo (Setup.exe) e un file di configurazione .config modificato. Questa tecnica — chiamata AppDomain Hijacking — abusa del runtime .NET per far caricare una DLL malevola al posto di una legittima, in modo silenzioso. Il payload finale era una nuova variante di MiniJunk.

Seconda ondata (marzo 2026) — Trojanized Zoom + MiniFast. In piena guerra, Nimbus Manticore ha introdotto un installer Zoom manomesso, probabilmente distribuito tramite false convocazioni a meeting video. Il flusso di infezione è sofisticato: il loader di primo stadio monitora in loop la creazione dello scheduled task legittimo ZoomUpdateTaskUser-<SID> generato dall’installer originale, e quando viene creato lo hijacka, modificandolo per eseguire il secondo stadio. La persistenza si mimetizza perfettamente nel sistema operativo. Il payload finale è il nuovo backdoor MiniFast.

Terza ondata (aprile 2026) — SEO Poisoning + SQL Developer falso. Per la prima volta nel modus operandi del gruppo, nessun spear-phishing: il vettore è la ricerca su motore di ricerca. Nimbus Manticore ha registrato decine di domini satellite che puntano a getsqldeveloper[.]com, un sito clone della pagina di download di Oracle SQL Developer. Grazie a keyword stuffing e link-building artificiale, il dominio malevolo scalava le SERP di Bing e DuckDuckGo. Chiunque cercasse il software legittimo poteva ricevere un installer armato con MiniFast.

MiniFast: il backdoor scritto con l’IA


MiniFast è una DLL PE a 64 bit che espone una singola export (CheckForUpdates) come entry point. La backdoor è progettata per la persistenza a lungo termine e l’esecuzione remota di comandi. Comunica con il C2 via HTTP, impersonando Chrome con un hardcoded User-Agent (Mozilla/5.0 ... Chrome/146.0.0.0) per confondersi col traffico legittimo.

Check Point ha identificato segnali inequivocabili dell’uso di strumenti AI nella fase di sviluppo: gestione degli errori eccessiva anche su chiamate API triviali come GetUserName, naming delle funzioni verboso e descrittivo, messaggi di debug embedded, organizzazione modulare nonostante la semplicità del codice. Queste caratteristiche sono tipiche del codice assistito da LLM e indicano una pipeline che sfrutta l’IA per accelerare i cicli di rilascio malware.

L’architettura di comunicazione con il C2 segue un pattern API-style con scambio JSON. Gli endpoint includono POST /rg per l’handshake iniziale con identificativo vittima, POST /agent/init per la registrazione dell’host, GET /agent/poll?token= per il recupero dei task (con strutture binarie Base64-encoded), POST /agent/result per l’upload dei risultati, PUT /upload/ per l’esfiltrazione file e GET /files/ per il download dal C2.

Il set di comandi implementati copre un ampio spettro: listing directory, esecuzione shell tramite cmd.exe, enumerazione processi, upload/download file, kill process per PID, caricamento dinamico di DLL, creazione archivi ZIP, escalation privilegi con runas, e installazione di persistenza tramite scheduled task denominato WindowsSecurityUpdate. Il polling interval e il jitter sono regolabili da remoto, rendendo il beacon adattivo e difficile da rilevare con euristiche fisse.

Implicazioni geopolitiche


“Le loro ambizioni si estendevano ben oltre lo spionaggio in Medio Oriente,” ha dichiarato Sergey Shykevich di Check Point Research. “Hanno costruito e distribuito un backdoor completamente nuovo nel mezzo del conflitto, mentre le operazioni erano attivamente in corso. E hanno lanciato una terza ondata con un playbook completamente diverso — senza mai fermarsi tra febbraio e aprile.”

La velocità di adattamento di Nimbus Manticore suggerisce che il conflitto cinetico ha funzionato da acceleratore per le operazioni cyber. L’integrazione di AI nella catena di sviluppo malware riduce i tempi dal concept al deploy, rendendo le signature tradizionali basate su hash o pattern statici più rapidamente obsolete. I settori maggiormente a rischio rimangono aviazione, difesa, telecomunicazioni e oil & gas in USA, Europa e Medio Oriente.

Dal punto di vista difensivo, è raccomandabile monitorare il caricamento di DLL non firmate da %AppData% in processi .NET, verificare l’integrità degli scheduled task dopo installazioni software, e filtrare l’accesso a domini registrati di recente che mimano portali di download di software enterprise (SQL Developer, Zoom, Adobe, etc.).

Indicatori di Compromissione (IoC)

# SHA256 — MiniFast, loader e dropper associati
10fd541674adadfbba99b54280f7e59732746faf2b10ce68521866f737f1e46d
eee657ffdb2af8ed6412221e7d5fbf4f5742f2ac2c88f43f12db46af0697de71
781605ce9d4a9869e846f6c9657d71437cb6240ab27ffbc4cd550c0e06996690
2c214494fd0bad31473ca8adce78a4f50847876584571e66aadeae70827ec2dc
f08b17856616d66492a24dced27f788e235f35f42fa7cd10f315000d3a2f4c03
a57ffb819fe8d98ff925c5d7b239598fe302acf5a13193d7a535040a71298fdf
63d0d3c4a7f71bdbca720903d6a99b832089cc093c64d2938e7e001e56c17ab4
74882085db2088356ed7f72f01e0404a0a98cda88ef56fb15ce74c1f36b26d27
bc3b44154518c5794ce639108e7b9c5fecb0c189607a26de1aaed518d890c7ad
ecaf493c320d201d285ef5f61d75744216e47cf1115b4af528f9a78883cc446e
44f4f7aca7f1d9bfdaf7b3736934cbe19f851a707662f8f0b0c49b383e054250
0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864
# Domini C2 e siti di distribuzione
getsqldeveloper[.]com
business-startup[.]org
business-startup.azurewebsites[.]net
PremierHealthAdvisory[.]com
ramiltonsfinance[.]com
globalitconsultants.azurewebsites[.]net
global-it-consultants.azurewebsites[.]net
nanomatrix.azurewebsites[.]net
licencemanagers.azurewebsites[.]net
peerdistsvcmanagers.azurewebsites[.]net
buisness-centeral-transportation[.]com
# Certificati code-signing abusati
Gray Matter Software S.R.L.
Kirubel Kerie Negeya
# Scheduled task di persistenza creato da MiniFast
WindowsSecurityUpdate

The Pirate Post ha ricondiviso questo.

Künstliche Intelligenz ist inzwischen in der Massentierhaltung angekommen. Doch können Verhaltensscanner im Stall wirklich das Tierwohl verbessern? Und welches Rezept spuckt ein KI‑Chatbot aus, wenn man ihn nach Spaghetti Bolognese fragt? Mirjam Walser warnt im Interview: Die Folgen von KI für Tiere sind enorm. netzpolitik.org/2026/tiere-und…
in reply to netzpolitik.org

Vegan zu werden ist die einzige kongruente Option. Es ist gibt keine Alternative dazu die Versklavung von Tieren zu verhindern - Dieses kleine Unternehmen kauft Land in England um aus der industriellen Tierhaltung befreiten Tiere zu retten und ein neues Zu Hause zu schenken: veganlandmovement.com/ beneaththewoodsanctuary.co.uk/ Es gibt natürlich noch viele andere Möglichkeiten zu helfen, die billigste jedoch ist über eine vegane Lebensweise nachzudenken. #GoVegan #FriendNotFood
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

👀 Wie unterscheidet die KI eine einvernehmliche Umarmung zwischen zwei Menschen von einer Bedrohungssituation? Und wie akkurat funktioniert ein System, das mangels vorhandener Trainingsdatensätze auf nachgestellte Szenen zurückgreifen muss?

💡Das alles und noch viel mehr zum Thema „Verhaltensscanner“ hat sich Pia angeschaut. In diesem Reel erfährst du alles, was du wissen musst und wieso mehr Überwachung keine Adhoc-Lösung darstellt.

Credits: Pia Wagner, netzpolitik.org, 2026

in reply to netzpolitik.org

Nachtrag:
Wenn die KI RAF-Terroristen und Neonazis verwechselt:
digitalcourage.social/@sl007/1…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Runtime Async in .NET 11 Preview 1: addio alle state machine del compilatore
#tech
spcnet.it/runtime-async-in-net…
@informatica


Runtime Async in .NET 11 Preview 1: addio alle state machine del compilatore


Introduzione


Con il rilascio di .NET 11 Preview 1, Microsoft ha introdotto uno dei cambiamenti architetturali più significativi nella storia dell’async in .NET: il Runtime Async V2. Questo cambiamento sposta la responsabilità della gestione delle operazioni asincrone dal compilatore al runtime stesso, con impatti concreti su debug, profiling, leggibilità degli stack trace e potenzialmente sulle prestazioni.

In questo articolo analizziamo nel dettaglio come funziona il nuovo modello, come differisce dall’approccio attuale basato su state machine, come abilitarlo nei propri progetti e cosa aggiunge .NET 11 Preview 1 oltre al solo Runtime Async.

Il problema: le state machine del compilatore


Chiunque abbia lavorato seriamente con codice asincrono in C# conosce la frustrazione di leggere uno stack trace in produzione e trovarsi sommerso da frame generati dal compilatore. Ogni metodo async viene trasformato dal compilatore in una classe di stato (state machine) che implementa IAsyncStateMachine. Questa trasformazione è efficace, ma introduce livelli di indirezione che offuscano la reale catena di chiamate.

Un semplice stack di tre metodi async produce tipicamente oltre dieci frame nello stack trace live, la maggior parte appartenenti all’infrastruttura del compilatore (AsyncMethodBuilderCore.Start, ecc.). Il risultato è un debug più laborioso e strumenti di profiling che faticano a restituire una visione chiara dell’esecuzione.

Runtime Async V2: come funziona


Con Runtime Async, il compilatore non genera più la state machine. Emette invece un IL semplificato, annotato con [MethodImpl(MethodImplOptions.Async)], e delega al runtime la gestione della sospensione e ripresa dei metodi asincroni. In pratica, è il CLR stesso a tracciare l’esecuzione asincrona, non il codice generato dal compilatore.

Il risultato più visibile è nei live stack trace, ovvero ciò che profiler, debugger e new StackTrace() vedono durante l’esecuzione. Con Runtime Async, i metodi effettivi appaiono direttamente nello stack, senza wrapper di stato.

Confronto diretto degli stack trace


Consideriamo questo codice di esempio:

await OuterAsync();

static async Task OuterAsync()
{
    await Task.CompletedTask;
    await MiddleAsync();
}

static async Task MiddleAsync()
{
    await Task.CompletedTask;
    await InnerAsync();
}

static async Task InnerAsync()
{
    await Task.CompletedTask;
    Console.WriteLine(new StackTrace(fNeedFileInfo: true));
}

Senza Runtime Async — 13 frame, con tutta l’infrastruttura del compilatore visibile:
at Program.<<Main>$>g__InnerAsync|0_2() in Program.cs:line 24
at System.Runtime.CompilerServices.AsyncMethodBuilderCore.Start[TStateMachine](...)
at Program.<<Main>$>g__InnerAsync|0_2()
at Program.<<Main>$>g__MiddleAsync|0_1() in Program.cs:line 14
at System.Runtime.CompilerServices.AsyncMethodBuilderCore.Start[TStateMachine](...)
at Program.<<Main>$>g__MiddleAsync|0_1()
at Program.<<Main>$>g__OuterAsync|0_0() in Program.cs:line 8
...
(13 frame totali)

Con Runtime Async — 5 frame, la reale catena di chiamate:
at Program.<<Main>$>g__InnerAsync|0_2() in Program.cs:line 24
at Program.<<Main>$>g__MiddleAsync|0_1() in Program.cs:line 14
at Program.<<Main>$>g__OuterAsync|0_0() in Program.cs:line 8
at Program.<Main>$(String[] args) in Program.cs:line 3
at Program.<Main>(String[] args)

È importante notare che questo miglioramento riguarda i live stack trace. Gli exception stack trace (catch (Exception ex)) già apparivano in modo pulito grazie all’ExceptionDispatchInfo nelle versioni precedenti.

Miglioramenti al debugging


Con Runtime Async, il debugger può finalmente fare ciò che ci si aspetterebbe da sempre:

  • I breakpoint all’interno di metodi async si associano correttamente, senza essere deviati su codice generato
  • È possibile fare step-through attraverso i boundary degli await senza “saltare” nell’infrastruttura del compilatore
  • La finestra call stack del debugger mostra la catena reale, non i wrapper di stato

Questi miglioramenti avvantaggiano qualsiasi strumento che ispeziona lo stack live: profiler come dotTrace, logging diagnostico, e naturalmente il debugger integrato di Visual Studio e VS Code.

Come abilitare Runtime Async nel proprio progetto


Runtime Async è una feature in anteprima che richiede opt-in esplicito. Aggiungere le seguenti proprietà al file .csproj:

<PropertyGroup>
  <Features>runtime-async=on</Features>
  <EnablePreviewFeatures>true</EnablePreviewFeatures>
</PropertyGroup>

Ovviamente, essendo ancora in anteprima, non è consigliato per ambienti di produzione. È tuttavia un ottimo momento per sperimentarlo su branch di sviluppo e fornire feedback al team .NET.

Requisiti hardware aggiornati


.NET 11 alza il baseline hardware richiesto. Per x86/x64, il minimo passa da x86-64-v1 a x86-64-v2, richiedendo istruzioni aggiuntive come SSE3, SSSE3, SSE4.1, SSE4.2 e POPCNT. Questo rientra nei requisiti già imposti da Windows 11 e copre tutta l’hardware Intel/AMD attualmente supportato ufficialmente (i chip più vecchi sono usciti dal supporto intorno al 2013).

Per Arm64 su Windows, il baseline aggiunge ora il requisito dell’instruction set LSE, richiesto da Windows 11 e da tutti gli Arm64 supportati da Windows 10.

Altre novità di .NET 11 Preview 1

Supporto nativo a Zstandard


Le librerie guadagnano il supporto nativo alla compressione Zstandard tramite la nuova classe ZstandardStream. Zstandard offre rapporti di compressione migliori rispetto a gzip con velocità di decompressione molto elevate — un’aggiunta benvenuta per pipeline di dati e API ad alta frequenza.

BFloat16 per AI e ML


Arriva il tipo BFloat16 (Brain Float 16), un formato floating-point a 16 bit nato per carichi di lavoro di machine learning. È ampiamente usato da librerie AI come TensorFlow e PyTorch, e la sua presenza nativa in .NET facilita l’integrazione con modelli ML senza conversioni intermedie.

Miglioramenti JIT


  • Eliminazione dei bounds check: il JIT elimina ora i controlli ridondanti sul pattern i + cns < len, comune nei loop su array e Span
  • Rimozione di contesti checked ridondanti: quando un valore è già noto essere nel range, i controlli di overflow vengono rimossi
  • Devirtualizzazione in ReadyToRun: le immagini R2R possono ora devirtualizzare chiamate a virtual method generici non condivisi


Miglioramenti VM


Su piattaforme senza JIT (come iOS), l’interface dispatch ora usa un meccanismo di cache con miglioramenti di performance fino a 200x in codice ad alta intensità di interfacce. Guid.NewGuid() su Linux migliora del 12% circa usando la syscall getrandom() con batch caching.

C# 15: prime anticipazioni


.NET 11 Preview 1 include anche le prime feature di C# 15. Tra quelle già disponibili:

  • Collection expression arguments: possibilità di specificare capacità, comparatori o altri parametri del costruttore direttamente nella sintassi delle espressioni di collezione
  • Extended layout support: il compilatore emette TypeAttributes.ExtendedLayout per tipi annotati con ExtendedLayoutAttribute, principalmente per scenari di interop


Conclusione


Il Runtime Async V2 rappresenta un passo importante verso un’esperienza di sviluppo asincrono più trasparente e debuggabile in .NET. Non è ancora pronto per la produzione, ma la direzione è chiara: Microsoft vuole che gli sviluppatori smettano di combattere con stack trace incomprensibili e possano finalmente fare debug dell’async come del codice sincrono.

Con .NET 11 previsto per novembre 2026 come Standard Term Support (STS), c’è ancora tempo per sperimentare e contribuire al processo di feedback prima del rilascio finale.

Fonte: What’s new in the .NET 11 runtime — Microsoft Learn | InfoQ: .NET 11 Preview 1


The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

GPUStack: cluster GPU self-hosted per inferenza AI con API OpenAI-compatibile
#tech
spcnet.it/gpustack-cluster-gpu…
@informatica


GPUStack: cluster GPU self-hosted per inferenza AI con API OpenAI-compatibile


Avete le GPU. Magari un paio di NVIDIA A100 in un rack, alcune RTX 4090 sotto le scrivanie, o un cluster con hardware misto. Avete la potenza di calcolo. Bene. Adesso, però, viene il problema vero: come gestirla?

Capire quali modelli entrano in quale scheda, come bilanciare il carico tra più macchine, come gestire un nodo che cade alle 2 di notte, e come esporre tutto questo come una API pulita che il team di sviluppo possa effettivamente chiamare — questa è la parte che manda in crisi la maggior parte dei team. Il risultato tipico è una raccolta fragile di script Python e crontab entries che nessuno tocca da anni e che funzionano finché non smettono di funzionare.

GPUStack è stato costruito precisamente per risolvere questo problema.

Cos’è GPUStack?


GPUStack è uno strumento open source (licenza Apache 2.0) per la gestione di cluster GPU destinati all’inferenza AI. Pensatelo come Kubernetes per i vostri workload di inferenza, senza la necessità di passare tre giorni a debuggare un errore di indentazione in un Helm chart.

Al suo nucleo, GPUStack fa tre cose bene:

  • Aggrega le GPU: che l’hardware sia su bare-metal, pod Kubernetes o istanze cloud, GPUStack le vede tutte come un unico pool di compute. Una dashboard, visibilità completa.
  • Orchestrare gli inference engine: GPUStack si integra con vLLM, SGLang e TensorRT-LLM, sceglie il motore giusto per il job, lo configura e ne gestisce il ciclo di vita.
  • Espone i modelli via API OpenAI-compatibile: una volta deployato un modello, il team applicativo ottiene un endpoint REST familiare. Nessuna libreria client custom. Nessun protocollo nuovo da imparare. Solo cambiare il base URL.


Installazione in meno di 5 minuti

Step 1 — Avviare il server di controllo


Vi serve una macchina per il control plane. Non deve nemmeno avere una GPU — un box CPU-only è sufficiente per il ruolo di server:

sudo docker run -d --name gpustack   --restart unless-stopped   -p 80:80   --volume gpustack-data:/var/lib/gpustack   gpustack/gpustack

Aprite il browser, navigate a http://<ip-del-vostro-server> e vedrete la dashboard GPUStack. Al primo accesso impostate le credenziali admin.

Step 2 — Aggiungere i worker GPU


Su ogni nodo worker, assicuratevi di avere installato NVIDIA driver e NVIDIA Container Toolkit, poi eseguite:

sudo docker run -d --name gpustack-worker   --restart unless-stopped   --gpus all   -e GPUSTACK_SERVER_URL=http://<ip-server>   -e GPUSTACK_TOKEN=<vostro-token>   gpustack/gpustack

Il token lo trovate nella dashboard GPUStack. In pochi secondi il worker compare nella vista cluster con modello GPU, capacità VRAM e stato di salute. Tre macchine? Tre comandi. Trenta macchine? Un playbook Ansible.

Nota pratica: la parte più difficile non è eseguire il comando worker, ma installare correttamente driver e toolkit sull’host. Verificate sempre la compatibilità tra versione del driver NVIDIA, versione CUDA e container runtime prima di procedere.

Step 3 — Deploy di un modello


Dalla web UI andate al catalogo modelli. GPUStack supporta il pull da Hugging Face e dall’Ollama Library. Selezionate un modello e cliccate “Deploy”.

Qui il scheduler dimostra il suo valore: legge i metadati del modello, calcola i requisiti di VRAM e compute, e determina quali worker possono gestirlo. Se il modello è troppo grande per una singola GPU, può distribuirlo su più schede (model sharding). Non dovete calcolare manualmente se un modello a 70B parametri entra nel vostro hardware: ci pensa GPUStack.

Step 4 — Chiamare l’API


Una volta che il modello è running, ottenete un endpoint OpenAI-compatibile. Recuperate una API key dalla dashboard e testate:

curl http://<ip-server>/v1/chat/completions   -H "Authorization: Bearer <api-key>"   -H "Content-Type: application/json"   -d '{
    "model": "llama3",
    "messages": [
      {"role": "user", "content": "Spiega la gestione di cluster GPU in un paragrafo."}
    ]
  }'

Se usate già l’OpenAI Python SDK, la migrazione alla vostra infrastruttura è una modifica su una riga:
from openai import OpenAI

client = OpenAI(
    base_url="http://<ip-server>/v1",
    api_key="<api-key>"
)

response = client.chat.completions.create(
    model="llama3",
    messages=[{"role": "user", "content": "Hello from my own GPU cluster!"}]
)
print(response.choices[0].message.content)

Il codice applicativo rimane invariato. La vostra infrastruttura è ora completamente sotto il vostro controllo.

Funzionalità Avanzate

Flessibilità Multi-Backend


GPUStack supporta vLLM, SGLang e TensorRT-LLM out of the box. Nessun motore di inferenza è il migliore per ogni workload:

  • vLLM: eccellente per batch processing ad alto throughput
  • TensorRT-LLM: massimizza le performance sull’hardware NVIDIA
  • SGLang: ideale per la generazione strutturata

GPUStack vi permette di scegliere il motore giusto per ogni deployment, o di lasciare che il scheduler scelga per voi in base al workload.

Monitoraggio Integrato


GPUStack si integra nativamente con Grafana e Prometheus, offrendo dashboard in real-time per utilizzo GPU, consumo VRAM, token throughput e request rate dell’API. Non serve aggiungere uno stack di monitoraggio separato. Quando qualcosa si rompe alle 2 di notte, saprete esattamente quale GPU su quale macchina è il problema.

Recovery automatico dai guasti


Un nodo che cade a causa di un errore PCIe bus o un driver mismatch che si manifesta solo sotto carico pesante tipicamente porta la vostra API di inferenza a restituire 500 finché non intervenite manualmente. GPUStack rileva i nodi non raggiungibili e redistribuisce i workload automaticamente, eliminando la necessità di un intervento manuale d’emergenza.

Quando Usare GPUStack


GPUStack è la scelta giusta se:

  • Avete 2 o più macchine GPU e volete servire LLM o altri modelli AI tramite una API unificata
  • Volete eseguire inferenza sulla vostra hardware invece di pagare per token a un cloud provider — il risparmio sui costi a scala è reale
  • Il vostro team non vuole diventare ingegneri di infrastruttura a tempo pieno solo per tenere i modelli in funzione

Forse non è la scelta giusta se:

  • Avete una singola GPU e volete solo eseguire modelli localmente per uso personale: in quel caso Ollama è più semplice
  • Siete già profondamente integrati in una piattaforma ML custom su Kubernetes con KubeFlow o simili, dove l’overlap potrebbe non valere l’investimento


Il Quadro Generale: l’Inferenza Self-Hosted è di Nuovo Praticabile


Il panorama dell’infrastruttura AI sta cambiando rapidamente. Un anno fa la maggior parte dei team optava automaticamente per API provider per l’inferenza. Oggi, con modelli open-weight sempre più capaci e costi GPU in calo, l’inferenza self-hosted è diventata un’opzione reale — non solo per i grandi player, ma per startup e aziende di medie dimensioni.

Il collo di bottiglia non è più l’hardware. Sono le operations: il codice collante tra “abbiamo le GPU” e “la nostra applicazione può chiamare un modello in modo affidabile”. GPUStack è un tentativo serio di risolvere questo gap, ed è open source sotto licenza Apache 2.0 — ispezionabile, modificabile e deployabile senza vendor lock-in.

Se avete hardware che al momento scalda solo la stanza server, o se siete stanchi di bollette di inferenza cloud che sembrano mutui, vale la pena provare. Il progetto è disponibile su GitHub.

Fonte originale: Self-Hosted Inference Doesn’t Have to Be a Nightmare: How to Use GPUStack — DZone


Bouncers at the Digital Border: How Google’s reCAPTCHA Overhaul Fractures the Free Internet


“Prove that you are a human,” or “Click on all the images of cars”. Familiar phrases like these have been part of everyday internet life for a long time. Using these reCAPTCHA tools, Google has long acted as a digital gatekeeper, ensuring that the fingers on the device are those of a genuine human and keeping malicious bots at bay. Now, Google’s platform is undergoing a transition phase.

Google has made major changes to its widely used security tool, reCAPTCHA. What used to be a simple web widget is now fully part of the Google Cloud Platform (GCP) ecosystem.

While corporate narratives tout this step as necessary progress in cybersecurity, developers of privacy-focused Android systems, civil society organizations, and digital rights & privacy advocates such as the European Pirates and European Digital Rights (EDRi) see a far more alarming reality. This marks a shift in the fundamental architecture of web access, introducing systemic legal changes, economic gatekeeping, and technological exclusion.

At the center of this transformation lies a larger global shift driven by artificial intelligence. As AI systems become increasingly capable of mimicking human behavior online, corporations are restructuring how trust, access, and verification operate across the internet. Critics argue that the result is an internet where participation increasingly depends on compliance with opaque corporate ecosystems rather than open standards.

The New Architecture: What Has Changed?


The rules for how reCAPTCHA works have been completely changed, taking control away from regular website owners and users.

  • Mandatory Cloud Integration & Billing: Google has ended support for all old “Classic” reCAPTCHA accounts on Google Cloud Platform. To continue using reCAPTCHA, website owners must migrate to the Google Cloud Platform. Even though there is still a free option for smaller sites, one has to link a valid credit card or billing account to activate it.
  • The Legal Liability Loophole: Under the proposed changes, Google’s role shifts from a “data controller” to a “data processor,” with the entire onus of user tracking placed on individual website operators.
  • Device Attestation Locks: The security system is now closely tied to Google Play Services on Android. Devices that use alternative, uncertified, or privacy-focused operating systems (like custom ROMs) will not pass background checks and will be blocked from accessing protected websites.


The Corporate Rationale: The Defense of Infrastructure


To fully dissect the issue, one must understand the justification driving Google’s infrastructure overhaul.

  • Combating Advanced Botnets: Automated scripts and bots have become increasingly sophisticated. Many now use artificial intelligence to get past old text or image puzzles.
  • Enterprise Security Scaling: By making reCAPTCHA part of Google Cloud’s broader Fraud Defense tools, Google provides large companies with analytics that can help stop large, organized fraud attacks.
  • Data Ownership Framing: From Google’s perspective, handing over complete control of data to website operators grants businesses ultimate authority and governance over how their visitors’ security telemetry is compiled and managed.

Amidst a flurry of such proposals circulating every second day aimed at changing the face of internet operations, it is important to note that AI has changed the scale of online automations. The aforementioned change by Google marks a shift from simple spam filters to large-scale behavioral surveillance systems that continuously evaluate “trustworthiness” in the background.

The question is: will this change to the definition of “trusted user,” based on a behavioral algorithm, keep the internet accessible and safe for everyone?

The Counterarguments: The Case for Digital Rights


Civil society groups argue that Google’s explanation hides a bigger problem: the web is becoming more controlled by a few companies, and people are losing digital independence.

  1. The Subversion of GDPR Spirit

By calling itself just a “processor,” Google puts the financial and legal risks on small businesses, open-source projects, and independent blogs. Website owners cannot check or control the hidden algorithms Google adds to their sites. Google benefits from user tracking to improve fraud detection, but regular web creators face legal problems if anything goes wrong.

  1. Financial Identity Wall

Making people verify with a credit card to use basic web protection shuts some people out. Small creators, activist groups, and student developers have to give their financial information to a big tech company just to keep their sites safe from spam. This puts a barrier around the open web.

  1. Algorithmic Discrimination against Privacy Users

With more “invisible” tracking, users can only access sites if they agree to be tracked. If someone uses privacy tools such as a VPN, tracking blockers, or a privacy-focused phone system like GrapheneOS, Google’s checks may flag them as suspicious. Real people are treated like threats just because they want privacy. This is especially unfair to journalists, whistleblowers, and privacy advocates who need special tools to stay safe.

  1. Monopoly is the Motive

Many privacy-focused Android developers are concerned about the drastic economic impact that Google’s reCAPTCHA system update is set to bring about on millions of small websites. Brendon Eich, CEO of Brave Browser, expressed concern, stating that Google’s security concern is unfounded. The core idea is to maintain a monopoly through Google Mobile Services (GMS) licensing. The GrapheneOS team shares a similar view – the requirements set by Google and Apple services are more anti-competitive than security-focused.

Conclusion: Reclaiming Digital Freedom


Web security must not become a source of corporate tax. Individuals shouldn’t be made to compromise their financial identities or choose between web access and device autonomy. As Google hardens the borders of its proprietary cloud ecosystem, the need for decentralized, transparent, and privacy-respecting verification methods becomes a pressing structural necessity for a democratic internet.

Take Action: Speak at the Think Twice Conference (TT5)


Those seeking to challenge corporate gatekeeping and advocate for a transparent digital future will have an opportunity to join the discussion at the Think Twice Conference (TT5), hosted by the Pirate Parties International and the European Pirates.

This year’s conference theme focuses directly on AI & Governance: Opportunities and Risks for Digital Freedom, bringing together developers, activists, policymakers, and civil society groups to debate how automated systems can remain transparent, accountable, and aligned with human rights principles.

The official Call for Speakers is currently open for individual talks and panel roundtables.

The registration deadline for speaker applications is June 1, 2026.

As debates over AI, surveillance, and platform control intensify, events like TT5 are becoming increasingly important spaces for defending the future of a democratic and open internet.


europeanpirates.eu/bouncers-at…

Elezioni e Politica 2026 reshared this.

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🎙️ Stergios Konstantinou​ completed his legal #traineeship in 2019. In this video, he takes a look back at his time in Vienna.

#noyb #privacy #law #dataprotection #europe #opportunity #trainee #eu #throwback

The Pirate Post ha ricondiviso questo.

Corrente: Ethics & aesthetics in digital currents

Visarte Ticino launches "Corrente", an agile format of exhibitions and public conversations.

The first edition dives into the relationship between art & the digital, exploring its aesthetic, ethical, & cultural dimensions through a dialogue between two artists working in this field: Denis "Jaromil" Roio and Stefano "Dodo" Molo, from different generations, with deeply personal practices & operating around Lugano.

luganoregion.com/it/events/det…

1/2

reshared this

in reply to Dyne.org foundation

The event also marks the public debut of Generative Center, co-directed by Felix Bachmann and Kevin Merz, on the third floor of Via Besso 42A, a building already known for Jazz in Bess, artist studios, and Cerchio 91.

Opening hours:
🥂 Vernissage: 30 May 2026, 17:45–23:00
🟣 31 May 2026, 14:15–18:30
🟢 1–14 June 2026: daily by appointment

📍 Generative Center, Via Besso 42A, 6900 Lugano, Switzerland

J @ Dyne.org reshared this.

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

CVE-2026-5426: zero-day in KnowledgeDeliver LMS sfruttato per distribuire BLUEBEAM e Cobalt Strike BEACON
#CyberSecurity
insicurezzadigitale.com/cve-20…


CVE-2026-5426: zero-day in KnowledgeDeliver LMS sfruttato per distribuire BLUEBEAM e Cobalt Strike BEACON


Si parla di:
Toggle

Un attore di minacce non ancora attribuito ha sfruttato una vulnerabilità zero-day nel sistema LMS KnowledgeDeliver, sviluppato dalla giapponese Digital Knowledge, per ottenere Remote Code Execution non autenticato e distribuire la web shell in-memory BLUEBEAM. L’indagine di Mandiant rivela un attacco sofisticato a più strati: dalla deserialization di ViewState ASP.NET al social engineering degli utenti finali con un falso plugin di autenticazione che installa Cobalt Strike BEACON, personalizzato per organizzazione. Una vulnerabilità che colpisce sistemi universitari e aziendali in tutto il mondo a causa di una scelta progettuale fatale: chiavi crittografiche condivise tra tutte le installazioni.

La radice del problema: chiavi macchina hardcoded


KnowledgeDeliver è un Learning Management System (LMS) enterprise ampiamente utilizzato in Giappone e in numerosi contesti educativi e corporate internazionali. Come molte applicazioni ASP.NET, utilizza la funzionalità ViewState per preservare lo stato delle pagine web tra una richiesta e l’altra. ViewState è protetto tramite una machineKey: una coppia di chiavi crittografiche (validationKey + decryptionKey) che garantiscono l’autenticità e la riservatezza dei dati serializzati inviati tra client e server.

Il difetto critico di KnowledgeDeliver, ora tracciato come CVE-2026-5426, consiste nell’utilizzo di valori machineKey statici e identici in tutte le installazioni del prodotto. Digital Knowledge distribuiva il software con chiavi hardcoded nel file web.config, anziché generare valori unici per deployment. Il risultato è devastante: chiunque abbia accesso a una singola installazione — anche la propria — può ricavare le chiavi e usarle per forgiare payload ViewState malevoli validi su qualunque altro server che esegue KnowledgeDeliver nel mondo.

La catena di attacco: da ViewState a RCE


L’exploitation della vulnerabilità segue un pattern ben documentato, già osservato in attacchi a Sitecore e in campagne evidenziate da Microsoft riguardanti chiavi macchina esposte. L’attaccante costruisce un payload serializzato contenente istruzioni arbitrarie e lo inserisce nel parametro __VIEWSTATE di una normale richiesta HTTP. Il server ASP.NET, fidandosi della firma crittografica (valida perché l’attaccante conosce la chiave), deserializza il payload e lo esegue con i privilegi del processo IIS (tipicamente Network Service o Application Pool Identity).

L’intera operazione non richiede credenziali, autenticazione pregressa o interazione utente sul lato server. Un singolo POST HTTP con il ViewState artefatto è sufficiente a ottenere esecuzione di codice remoto. Mandiant ha datato la compromissione iniziale alla fine del 2025, suggerendo che l’attore fosse a conoscenza della vulnerabilità mesi prima della disclosure pubblica avvenuta il 24 febbraio 2026.

BLUEBEAM: la web shell fantasma


Una volta ottenuto il foothold iniziale, l’attaccante ha distribuito BLUEBEAM, una web shell .NET nota anche come Godzilla. Ciò che distingue BLUEBEAM dalle web shell tradizionali è la sua natura interamente in-memory: il malware non scrive file su disco ma viene caricato direttamente nel processo worker IIS (w3wp.exe), riducendo drasticamente la superficie di rilevamento per strumenti forensi e antivirus basati sulla scansione del filesystem.

BLUEBEAM comunica con il suo operatore tramite richieste HTTP POST cifrate, mascherandosi come normale traffico web. Attraverso questo canale, l’attaccante può eseguire comandi arbitrari, caricare ulteriori payload, modificare file e mantenere persistenza nell’ambiente compromes. Mandiant ha osservato l’uso del tool di sistema icacls per allargare i permessi sul filesystem, indebolendo ulteriormente i controlli di sicurezza dell’host compromesso.

Il vettore secondario: social engineering sugli utenti finali


L’attacco non si è fermato al server. Con l’accesso a w3wp.exe, l’attaccante ha manomesso i file JavaScript legittimi del portale LMS, iniettando codice malevolo nelle pagine visitate dagli studenti e dai dipendenti. Il codice iniettato mostrava un avviso di sicurezza convincente, informando l’utente della necessità di installare un “plugin di autenticazione” aggiuntivo per continuare ad accedere alla piattaforma. Parallelamente, caricava script da infrastruttura controllata dall’attaccante.

Gli utenti che installano il falso plugin vengono infettati con un Cobalt Strike BEACON, il framework di post-exploitation commerciale più abusato nel panorama delle minacce avanzate. L’elemento che rivela la natura mirata e pianificata dell’operazione è la personalizzazione del payload: il BEACON era cifrato con una chiave derivata dal nome dell’organizzazione vittima, dimostrando che l’attaccante aveva condotto ricognizione preventiva e aveva predisposto un payload ad hoc per ogni target.

Timeline degli eventi


  • Fine 2025: Compromissione iniziale rilevata da Mandiant durante un incident response
  • 24 febbraio 2026: Data limite per le installazioni vulnerabili (le versioni precedenti a questa data con machineKey di default sono esposte)
  • 25 maggio 2026: Pubblicazione dell’advisory Mandiant/Google Cloud e assegnazione CVE-2026-5426


Indicatori di compromissione (IoC)

# BLUEBEAM web shell
SHA-256: 7c1f99dca8e5a7897892f9d224a6495023a2cfd2671697d229d355978c415ed2
File:    LoadLibrary.dll (caricato in-memory da w3wp.exe)
# CVE
CVE-2026-5426 – KnowledgeDeliver ASP.NET machineKey RCE (CVSS: critico)
# Segnali di detection
Windows Application Log - Event ID 1316 (ViewState validation failure/anomalia)
Processo: w3wp.exe che genera child process cmd.exe, powershell.exe, cscript.exe
File JS del portale modificati con tag 
User-Agent anomali nelle richieste POST a pagine .aspx (concatenazione di UA multipli)
Uso di icacls.exe da processi IIS per modifica permessi
# Pattern ViewState malevolo
Parametro __VIEWSTATE con lunghezza anomala (>50KB)
Richieste POST a pagine .aspx che non prevedono ViewState volumioso

Remediation e due righe per i difensori


La mitigazione primaria e indispensabile è la rotazione immediata dei valori machineKey a valori unici e crittograficamente robusti per ogni singola installazione. Le chiavi devono essere generate con un generatore di numeri casuali sicuro (CSPRNG) e non devono mai essere condivise tra ambienti diversi. La configurazione va inserita nel file web.config sotto il tag <system.web><machineKey validationKey="..." decryptionKey="..." />. Oltre alla remediation tecnica, le organizzazioni dovrebbero limitare l'accesso al portale LMS a range IP fidati, condurre threat hunting retrospettivo alla ricerca di sign of compromise elencati sopra, verificare l'integrità dei file JavaScript del portale tramite confronto hash, e investigare eventuali installazioni del presunto "plugin di autenticazione" sulle macchine degli utenti finali. Questo incidente è un promemoria sistematico del rischio insito nelle configurazioni di default condivise: una singola chiave hardcoded può trasformare un'applicazione enterprise globale in una superficie di attacco che compromette simultaneamente organizzazioni altrimenti non correlate.


Resistance Lab: Making and distributing media under surveillance


Join Interrupting Criminalization's Abolition Journalism Fellow Lewis Raven Wallace, digital security firm Safety Sync Group, and fellow journalists and media makers for a resistance lab.

The post Resistance Lab: Making and distributing media under surveillance appeared first on European Digital Rights (EDRi).

Elezioni e Politica 2026 reshared this.

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Grafana GitHub Breach: TanStack npm Supply Chain Attack Leads to Source Code Theft and Ransom Demand
#CyberSecurity
securebulletin.com/grafana-git…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Fox Tempest: Microsoft DCU Dismantles Malware-Signing-as-a-Service That Forged Trusted Certificates for Ransomware Groups
#CyberSecurity
securebulletin.com/fox-tempest…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

TeamPCP Poisons Microsoft’s Official Python DurableTask SDK — Multi-Cloud Credential Worm Hits PyPI
#CyberSecurity
securebulletin.com/teampcp-poi…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Void Botnet Routes Commands Through Ethereum Smart Contracts to Evade Law Enforcement Takedowns
#CyberSecurity
securebulletin.com/void-botnet…
The Pirate Post ha ricondiviso questo.

Für eine dreistellige Millionensumme sollen SAP und Telekom eine „KI-Cloud“ für die öffentliche Verwaltung bauen. Digitalminister Karsten Wildberger nennt das souverän. Unabhängig wird Deutschlands Verwaltung damit nicht, warnen Opposition und Fachleute. netzpolitik.org/2026/fuer-250-…

Latest ruling in Herridge case highlights need for federal shield law


The latest decision in journalist Catherine Herridge’s legal fight over confidential sources highlights how fragile the reporter-source privilege remains in the absence of a federal shield law. Not only did the court refuse to reconsider the order forcing Herridge to identify her confidential sources, but it also asked the public to accept its decision without immediate access to the court records we need to fully understand it.

On May 22, the appeals court declined to revisit its prior ruling requiring Herridge to name her confidential sources for her 2017 reporting about an FBI investigation into scientist Yanping Chen. Chen, who had founded an online college that received government funding, sued the FBI and other government agencies, claiming that federal officials damaged her career by leaking to the press. She then subpoenaed Herridge, arguing it was necessary to identify the source of those leaks.

Because there’s no federal shield law, Herridge tried to rely on the First Amendment and common law protections that many courts have recognized for reporters. But both the trial court and the U.S. Court of Appeals for the District of Columbia Circuit rejected those arguments.

That outcome, and the court’s latest refusal to reconsider it, should concern every journalist who depends on confidential sources. The reporter’s privilege exists because source confidentiality serves the public interest. Whistleblowers and others often come forward only because they believe journalists can protect them.

In Herridge’s case, however, the courts treated the public interest as secondary or even irrelevant. They focused narrowly on whether Herridge’s testimony was essential to Chen’s claim and whether Chen had exhausted other avenues to obtain the information she sought.

That approach turns the reporter’s privilege into a weak procedural obstacle, rather than the meaningful safeguard for newsgathering it’s supposed to be. The D.C. Circuit has previously said that it should be the rare, exceptional case where a reporter is compelled to reveal her sources. But the decision in the Herridge case means that other journalists may be more likely to be forced to do so in the future.

The secrecy surrounding certain documents in Herridge’s legal fight makes matters even worse.

The right of access to court proceedings is supposed to be contemporaneous

Herridge argued that she shouldn’t be forced to reveal her sources because any harm Chen suffered wasn’t caused by the alleged leaks, but rather by a later, independent decision by the Department of Defense to terminate the participation of the college Chen founded in a government tuition reimbursement program “on national security grounds.” But key records related to the department’s decision were sealed in the trial court and remain sealed, even though they directly relate to the justification for forcing Herridge to reveal her sources.

As a result, the public can’t fully evaluate whether the courts properly weighed the factors before ordering Herridge to comply with the subpoena. Parts of the oral argument in Herridge’s appeal were even held behind closed doors because of the sealed materials. That’s hard to square with the principle that court proceedings should happen in public view.

And that’s especially true of court proceedings that reshape constitutional rights, like this one. Freedom of the Press Foundation (FPF) and Herridge separately asked the appeals court to unseal the documents and hearing transcript. But in its May 22 ruling, the court declined to do so, sending the issue back to the district court instead. It didn’t explain why it wouldn’t act itself, even though its own rules allow it to unseal district court records “when the interests of justice require.”

This delay matters. The right of access to court proceedings is supposed to be contemporaneous, so the public can understand and assess in real time whether judges are doing their job properly. Courts shouldn’t be making groundbreaking decisions on the reporter’s privilege by relying on partially sealed arguments and secret court records, even if they’re later unsealed.

Herridge may now seek Supreme Court review. But the Supreme Court only accepts a small fraction of the cases it’s asked to hear each term, and there’s no guarantee that it would improve the reporter’s privilege even if it takes her case.

It’s understandable if Herridge decides that petitioning the Supreme Court is necessary to protect her sources and her professional ethics. But the best solution in the longer term for other journalists would come from Congress. Lawmakers should pass a shield law like the PRESS Act to provide clear, strong protection against compelled disclosure of journalists’ sources. Without a federal shield law on the books, confidential newsgathering may continue to be eroded, one subpoena at a time.


freedom.press/issues/latest-ru…

Elezioni e Politica 2026 reshared this.

General Assembly June 20, 2026 Feedback Survey


The next PPI General Assembly is approaching, and there are several organizational points that still need to be finalized. The GA has already been published, but without a confirmed time. We now need to agree on the schedule and make sure all parties and delegates receive the necessary information.

As part of the preparation, we need to update Discourse (ga.pp-international.net/), publish the proposed statute amendments, and collect delegate information.

One proposal is to start sometime between 8:00 and 16:00 UTC. We also ask for your parties to update us on any motions or any other business that you would like to share for the GA.

We expect a relatively long debate, especially because several statute amendments will be discussed. For that reason, it may be useful to collect feedback from members in advance. However, there will be no elections at this GA.

A survey has been prepared to gather input on the preferred start time, proposals, and any other business for the June 2026 GA:

Complete the survey for the June 2026 GA


pp-international.net/2026/05/g…

Elezioni e Politica 2026 reshared this.