The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Replacing Selenium Rectifiers
poliverso.org/display/0477a01e…
Replacing Selenium RectifiersOld radios often had selenium rectifiers to convert AC to DC. The problem is that the old units, dating back to 1933, are prone to failure and to release dangerous chemicals like hydrogen selenide. [M Caldeira] has a new board made to fit a particular rectifier youtube.com/watch?v=TMfBJIsDgk… and also allows a varying voltage drop. The circuit consists of a few diodes,


Replacing Selenium Rectifiers


Old radios often had selenium rectifiers to convert AC to DC. The problem is that the old units, dating back to 1933, are prone to failure and to release dangerous chemicals like hydrogen selenide. [M Caldeira] has a new board made to fit a particular rectifier and also allows a varying voltage drop. The circuit consists of a few diodes, a MOSFET, and a pot for adjusting the voltage drop. An IRF840 MOSFET provides the adjustment.

Did it work? It did. The good news is that if it fails — which shouldn’t happen very often — it won’t release stinky and noxious fumes

We wondered if he should 3D print a fake case to make it look more the part. If you haven’t seen a real selenium rectifier, they were made of stacks of metal plates coated with bismuth or nickel. Then, a film of doped selenium was annealed to the surface to form cadmium selenide. Each plate could handle about 20 V and the more plates you used, the more reverse voltage the device could withstand.

Selenium was also found in old photocells. If you fancy replacing other parts of an old radio, you might consider a faux magic eye or even one of the main tubes.

youtube.com/embed/TMfBJIsDgkY?…


hackaday.com/2024/09/24/replac…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Digital Audio Workstation In A Box
poliverso.org/display/0477a01e…
Digital Audio Workstation In A BoxAlthough it’s still possible to grab a couple of friends, guitars, and a set of drums and start making analog music like it’s 1992 and there are vacant garages everywhere yearning for the sounds of power chords, the music scene almost demands the use of a computer now. There are a lot of benefits, largely that it dramatically lowers the barrier to entry since it


Digital Audio Workstation In A Box


Although it’s still possible to grab a couple of friends, guitars, and a set of drums and start making analog music like it’s 1992 and there are vacant garages everywhere yearning for the sounds of power chords, the music scene almost demands the use of a computer now. There are a lot of benefits, largely that it dramatically lowers the barrier to entry since it greatly reduces the need for expensive analog instruments. It’s possible to get by with an impressively small computer and only a handful of other components too, as [BAussems] demonstrates with this tiny digital audio workstation (DAW).

The DAW is housed inside a small wooden box and is centered around a Behringer JT-4000 which does most of the heavy lifting in this project. It’s a synthesizer designed to be as small as possible, but [BAussems] has a few other things to add to this build to round out its musical capabilities. A digital reverb effects pedal was disassembled to reduce size and added to the DAW beneath the synthesizer. At its most basic level this DAW can be used with nothing but these components and a pair of headphones, but it’s also possible to add a smartphone to act as a sequencer and a stereo as well.

For a portable on-the-go rig, this digital audio workstation checks a lot of the boxes needed including MIDI and integration with a computer. It’s excellent inspiration for anyone else who needs a setup like this but doesn’t have access, space, or funds for a more traditional laptop- or desktop-centered version. For some other small on-the-go musical instruments we recently saw a MIDI-enabled keyboard not much larger than a credit card.


hackaday.com/2024/09/23/digita…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Attacco Ransomware: La Minaccia che Può Bloccare la Tua PMI
poliverso.org/display/0477a01e…
Attacco Ransomware: La Minaccia che Può Bloccare la Tua PMIHai mai pensato che un semplice clic potrebbe mettere in ginocchio la tua azienda? La mattina arrivi in azienda già pensando che devi pagare gli F24 che ti ha mandato il commercialista. Accendi il tuo PC (sei il primo ad arrivare) e scopri che tutti i tuoi dati sono inaccessibili perché criptati. Sullo schermo un


Attacco Ransomware: La Minaccia che Può Bloccare la Tua PMI


Hai mai pensato che un semplice clic potrebbe mettere in ginocchio la tua azienda? La mattina arrivi in azienda già pensando che devi pagare gli F24 che ti ha mandato il commercialista. Accendi il tuo PC (sei il primo ad arrivare) e scopri che tutti i tuoi dati sono inaccessibili perché criptati. Sullo schermo un avviso che ti illustra cosa è successo: li ha resi indisponibili e ti sta chiedendo un riscatto. Dramma. La giornata è compromessa. Forse anche tutta le settimana. Questo è un attacco Ransomware! Ma non finisce qui.

Ci sono i dati dei tuoi clienti in mano a dei criminali che potrebbero venderli (e lo faranno) sul Dark Web. Coincidenza ti chiama il tuo avvocato perchè dovevi mandargli dei dati per quella cosa…

“Ma te li hanno rubati?” ti chiede lui. Rispondi che credi di si.

“Allora probabilmente devi fare la notifica al Garante e potrebbe esserci una sanzione, preparati”.

Le PMI vengono viste come bersagli facili: con meno risorse per la sicurezza informatica ma con dati preziosi che possono essere sfruttati.

Non ci credi? Un piccolo report qui.

I criminali spesso lasciano aperto un canale di trattativa ma…spoiler: pagare la non è la soluzione.

Le buone notizie: il gruppo HackerHood di Red Hot Cyber, ha questo programma di aiuto per le attività colpite, il No Pay Ransomware. Per i dettagli clicca QUI.

Come Funziona un Attacco Ransomware


Un attacco ransomware può iniziare in diversi modi. Spesso, tutto parte da un’email ingannevole che sembra provenire da un fornitore o da un collega. L’email contiene un allegato o un link che, una volta cliccato, scarica il malware. Oppure da un software scaricato da internet che si pensava fosse legittimo. Altri attacchi sfruttano vulnerabilità nei software aziendali o nei sistemi operativi non aggiornati.

Il malware si installa silenziosamente e una volta attivato, sfruttando le funzioni crittografiche del sistema operativo, cripta tutti i file del tuo PC.

Poi manda la chiave di decodifica creata ai criminali via internet. Finto qui? Non solo cripta i file nel tuo PC, ma anche nelle altre sezioni delle rate a cui quel PC ha accesso (NAS per esempio).

Se vuoi conoscere meglio questo mondo, qui un articolo molto approfondito di Massimiliano Brolli (clicca QUI per leggerlo).

Perché le PMI Sono un Obiettivo Facile per i Cybercriminali


“Perché dovrebbero colpire proprio la mia azienda e non una grande multinazionale?” Ecco la dura verità: le PMI sono bersagli più facili e accessibili. Spesso, non hanno le risorse per un’adeguata sicurezza informatica e i loro dipendenti non sono sufficientemente formati sui rischi del cybercrimine.

Gli attacchi ransomware possono sembrare eventi rari e isolati, ma la realtà è molto diversa. Secondo uno studio del primo trimestre del 2024 condotto da Ransomfeed (il report lo trovi QUI ) , solo nei primi 3 mesi dell’anno ci sono stati 39 casi nel nostro paese con un trend di crescita mondiale del 34% rispetto al 2022.

Le Conseguenze di un Attacco Ransomware per le PMI


I danni di un attacco ransomware possono essere devastanti:

  1. perdita di produttività
  2. perdita di fiducia dei clienti
  3. possibili sanzioni

In soldoni? Fatti due conti.

Come Proteggere la Tua PMI dal Ransomware


Scommetto che vuoi sapere quali azioni concrete puoi intraprendere per proteggere la tua azienda da un attacco ransomware. Vediamole nel dettaglio:

  1. Backup Regolari sconnessi dalla rete o comunque immutabili: Il primo passo è assicurarsi di avere backup regolari dei dati aziendali. Questi backup devono essere conservati offline o su cloud resi sicuri con la tecnica della versione immutabile. Devono essere testati periodicamente per verificare che possano essere ripristinati rapidamente.
  1. Aggiornamenti Software: Spesso, gli attacchi ransomware sfruttano falle nei software non aggiornati. Assicurati di mantenere tutti i programmi e i sistemi operativi aggiornati con le ultime patch di sicurezza.
  2. Formazione del Personale: Il 90% degli attacchi ransomware inizia con un errore umano. Formare i tuoi dipendenti sui rischi legati alle email sospette, agli allegati e ai link può fare la differenza.
  3. Firewall e Antivirus: Utilizzare firewall, software antivirus e soluzioni di sicurezza avanzate è essenziale per bloccare eventuali tentativi di attacco prima che possano causare danni. Un Antivirus può bloccare un file dannoso mentre il Firewall può bloccare la comunicazione del ransomware con l’esterno.


Perchè pagare non è una opzione


Semplicemente perchè non ti puoi fidare. Ecco cosa potrebbe succedere dopo un attacco ransomware:

  1. paghi il riscatto
  2. ti inviano un file che dicono contenere il codice per riavere i dati
  3. ti dicono che perchè funzioni, devi disabilitare l’antivirus
  4. lo scarichi, lo apri e…
  5. non succede niente

Pare che non sia successo niente: non solo non hai sbloccato i dati, ma adesso nel tuo PC c’è un software di accesso remoto. Possono accedere quando vogliono e magari rubarti non solo altri dati, ma anche le password dei servizi che usi.

Pensaci.

L'articolo Attacco Ransomware: La Minaccia che Può Bloccare la Tua PMI proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Spanish premier seeks international leadership role against ‘fake news’
poliverso.org/display/0477a01e…
Spanish premier seeks international leadership role against ‘fake news’Spanish Prime Minister Pedro Sánchez wants to make the fight against disinformation a priority with a plan for "democratic renewal", though the country's conservative opposition has blasted it as an attempt to censor critical media.euractiv.com/section/disinform…


Spanish premier seeks international leadership role against ‘fake news’


Spanish Prime Minister Pedro Sánchez wants to make the fight against disinformation a priority with a plan for "democratic renewal", though the country's conservative opposition has blasted it as an attempt to censor critical media.


euractiv.com/section/disinform…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Scoperto Splinter! Quando uno strumento di Sicurezza viene usato dai malintenzionati
poliverso.org/display/0477a01e…
Scoperto Splinter! Quando uno strumento di Sicurezza viene usato dai malintenzionatiPalo Alto Networks ha scoperto unit42.paloaltonetworks.com/an… un nuovo strumento post-sfruttamento chiamato Splinter che è stato trovato sui sistemi dei clienti utilizzando gli strumenti di scansione della memoria di Advanced WildFire. Strumenti come Splinter


Scoperto Splinter! Quando uno strumento di Sicurezza viene usato dai malintenzionati


Palo Alto Networks ha scoperto un nuovo strumento post-sfruttamento chiamato Splinter che è stato trovato sui sistemi dei clienti utilizzando gli strumenti di scansione della memoria di Advanced WildFire. Strumenti come Splinter vengono spesso utilizzati per testare la sicurezza della rete di un’azienda, ma possono rappresentare una seria minaccia se nelle mani di aggressori. Ciò evidenzia l’importanza del monitoraggio e del rilevamento continui di tali minacce.

Splinter è uno strumento sviluppato utilizzando il linguaggio di programmazione Rust. Sebbene Rust sia comunemente utilizzato per creare programmi sicuri per la memoria, la sua elevata densità di codice ne rende difficile l’analisi. I campioni di Splinter trovati hanno raggiunto i 7 MB a causa dell’utilizzo di un gran numero di librerie esterne. Splinter utilizza file di configurazione in formato JSON contenenti dati sul sistema di destinazione e sul server di comando e controllo a cui lo strumento si connette per eseguire varie attività come l’esecuzione di comandi remoti, il trasferimento di file e la raccolta di dati.

Lo strumento è stato rilevato su diversi sistemi client, ma finora non vi è alcuna prova del suo utilizzo da parte di aggressori. Splinter offre un set standard di funzionalità per strumenti simili, come l’esecuzione di comandi e l’inserimento di processi. Sebbene non sia avanzato quanto strumenti più noti come Cobalt Strike, le sue capacità rappresentano una minaccia per le organizzazioni se utilizzate in modo errato.

Palo Alto Networks ha migliorato la protezione dei propri clienti contro questa minaccia con gli aggiornamenti Advanced WildFire, Cortex XDR e XSIAM che aiutano a rilevare e bloccare modelli noti e monitorare l’attività post-sfruttamento.

La scoperta evidenzia il numero crescente di strumenti di attacco che rendono più difficile la protezione delle reti aziendali. Le organizzazioni sono incoraggiate a mantenere aggiornati i propri sistemi di sicurezza e ad aggiornare regolarmente i propri metodi di rilevamento delle minacce.

L'articolo Scoperto Splinter! Quando uno strumento di Sicurezza viene usato dai malintenzionati proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Quantum needs more investment, better innovation recipe for growth [Advocacy Lab Content]
poliverso.org/display/0477a01e…
Quantum needs more investment, better innovation recipe for growth [Advocacy Lab Content]Leonardo Quattrucci believes quantum needs to be at the forefront of Europe’s thinking about new technologies in the next decade. It’s a question of leadership, ambition and investment in growth, but a new approach to innovation is needed


Quantum needs more investment, better innovation recipe for growth [Advocacy Lab Content]


Leonardo Quattrucci believes quantum needs to be at the forefront of Europe’s thinking about new technologies in the next decade. It’s a question of leadership, ambition and investment in growth, but a new approach to innovation is needed too.


euractiv.com/section/digital-s…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The Possibility of Reverting Time on the Ageing of Materials
poliverso.org/display/0477a01e…
The Possibility of Reverting Time on the Ageing of MaterialsEveryone knows that time’s arrow only goes in one direction, regardless of the system or material involved. In the case of material time, i.e. the ageing of materials such as amorphous materials resulting from glass transition, this material time is determined after the initial solidification by the relaxation


The Possibility of Reverting Time on the Ageing of Materials


Everyone knows that time’s arrow only goes in one direction, regardless of the system or material involved. In the case of material time, i.e. the ageing of materials such as amorphous materials resulting from glass transition, this material time is determined after the initial solidification by the relaxation of localized stresses and medium-scale reordering. These changes are induced by the out-of-equilibrium state of the amorphous material, and result in changes to the material’s properties, such as a change from ductile to a brittle state in metallic glasses. It is this material time which the authors of a recent paper (preprint) in Nature Physics postulates to be reversible.

Whether or not this is possible is said to be dependent on the stationarity of the stochastic processes involved in the physical ageing. Determining this stationarity through the investigation of the material time in a number of metallic glass materials (1-phenyl-1-propanol, laponite and polymerizing epoxy) was the goal of this investigation by [Till Böhmer] and colleagues, and found that at least in these three materials to be the case, suggesting that this process is in fact reversible.

Naturally, the primary use of this research is to validate theories regarding the ageing of materials, other aspects of which have been investigated over the years, such as the atomic dynamics by [V.M Giordano] and colleagues in a 2016 paper in Nature Communications, and a 2022 study by [Birte Riechers] and colleagues in Science Advances on predicting the nonlinear physical ageing process of glasses.

While none of these studies will give us time-travel powers, it does give us a better understanding of how materials age over time, including biological systems like our bodies. This would definitely seem to be a cause worthy of our time.

Header image: Rosino on Flickr, CC BY-SA 2.0.


hackaday.com/2024/09/23/the-po…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Cybersecurity: Italia prima della classe
poliverso.org/display/0477a01e…
Cybersecurity: Italia prima della classeLa notizia è di pochi giorni fa ed è di quelle tanto inaspettate quanto belle: l’Italia è tra i primi della classe per quanto riguarda la sicurezza informatica. E non stiamo parlando di una classifica europea, ma mondiale. Qualche giorno fa ha visto la luce la quinta edizione del Global Cybersecurity Index, pubblicato dall’International

reshared this

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Find My Power Tool Battery
poliverso.org/display/0477a01e…
Find My Power Tool BatteryApple’s Find My network has seen its fair of hacks to devices, but perhaps the most unusual we’ve seen is before us today. [biemster] has added a Lidl Parkside smart connected power tool battery to the network hackaday.io/project/197894-the…, not by concealing an AirTag within it, but by hacking its on-board firmware.Opening up the device reveals a Tuya BT17L Bluetooth mo


Find My Power Tool Battery


Apple’s Find My network has seen its fair of hacks to devices, but perhaps the most unusual we’ve seen is before us today. [biemster] has added a Lidl Parkside smart connected power tool battery to the network, not by concealing an AirTag within it, but by hacking its on-board firmware.

Opening up the device reveals a Tuya BT17L Bluetooth module, the hackable nature of which due to other projects prompted a port of a previous Find My project which provided open source access to the network. The result is as he describes, the world’s chunkiest key finder, and also we’re guessing the one with one of the longest battery lives too.

The European budget supermarkets are well known for their budget bargain aisles, and Lidl’s Parkside range has some surprisingly robust tools among it. They might not quite be up to replacing IKEA in the hacker source stakes, but those of us who live in countries served by them know to keep an eye out in the hope of fresh gems alongside those awesome AlpenFest apple crumble cakes. This one certainly isn’t the first Parkside hack we’ve seen.


hackaday.com/2024/09/23/find-m…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Digital Crime: Art. 609-undecies c.p.: Sanzioni e Normative sull’Adescamento di MinorenniDigital Crime:
poliverso.org/display/0477a01e…
Digital Crime: Art. 609-undecies c.p.: Sanzioni e Normative sull’Adescamento di MinorenniDigital Crime:Art.609-undecies c.p.: Chiunque, allo scopo di commettere i reati di cui agli articoli 600, 600 bis, 600 ter e 600 quater, anche se relativi al materiale pornografico di cui all'articolo 600 quater 1,600 quinquies,609 bis,609


Digital Crime: Art. 609-undecies c.p.: Sanzioni e Normative sull’Adescamento di MinorenniDigital Crime:


Art.609-undecies c.p.: Chiunque, allo scopo di commettere i reati di cui agli articoli 600, 600 bis, 600 ter e 600 quater, anche se relativi al materiale pornografico di cui all'articolo 600 quater 1,600 quinquies,609 bis,609 quater,609 quinquies e 609 octies, adesca un minore di anni sedici, è punito, se il fatto non costituisce più grave reato, con la reclusione da uno a tre anni.

Per adescamento si intende qualsiasi atto volto a carpire la fiducia del minore attraverso artifici, lusinghe o minacce posti in essere anche mediante l'utilizzo della rete internet o di altre reti o mezzi di comunicazione.

La pena è aumentata:

1) se il reato è commesso da più persone riunite;
2) se il reato è commesso da persona che fa parte di un'associazione per delinquere e al fine di agevolarne l'attività;
3) se dal fatto, a causa della reiterazione delle condotte, deriva al minore un pregiudizio grave;
4) se dal fatto deriva pericolo di vita per il minore.

Il contenuto della norma


L’articolo 609-undecies sanziona l’adescamento dei minorenni. Si tratta di un delitto residuale poiché la punibilità dell’azione di adescamento è subordinata all’impossibilità di ricondurlo a un reato più grave. Tale illecito punisce l’atto noto come “grooming” (dall’inglese “to groom”, ovvero “curare”, “preparare” o “accarezzare”), specialmente il “child grooming”, che consiste nell’esecuzione di azioni mirate a indebolire gradualmente la volontà del giovane al fine di ottenere il controllo su di esso. Solitamente, quest’attività si svolge attraverso i canali di comunicazione preferiti dai giovani, come i social network e i telefoni cellulari, stabilendo con la vittima , dopo aver valutato la mancanza di controllo genitoriale o supervisione nell’uso del computer, una relazione amichevole e garantendosi così la fiducia, anche mediante la condivisione di confidenze personali, sfruttando la curiosità e l’ingenuità tipica dei giovani immaturi. Questa azione persuasiva ha l’obiettivo principale di convincere il giovane, anche attraverso l’invio e lo scambio di materiale pedopornografico, della normalità delle relazioni sessuali tra adulti e bambini. Trattandosi di reato di mera condotta a forma vincolata, verranno in rilievo solo le condotte che rientrano nella definizione di artifici, lusinghe o minacce. Per artificio si intende qualsiasi simulazione, dissimulazione, espediente subdolo o menzogna capace di ingannare la vittima e attirarla nella trama criminale ideata dal colpevole. Il concetto di lusinghe fa riferimento all’attività di adulare, gratificare falsamente, rivolgere finte ed eccessive attenzioni al fine di guadagnarsi la simpatia e la benevolenza di qualcuno per spingerlo a un determinato comportamento. La minaccia consiste nel prospettare un male futuro e ingiusto la cui realizzazione dipende dalla volontà dell’agente. Considerando che si tratta di una norma con diverse fattispecie, agire con modalità differenti, ad esempio sia con lusinghe che con minacce, comporta comunque la commissione di un singolo reato. Queste azioni devono essere compiute con l’intento di commettere specifici reati, tra cui il 600-ter e il 600-quater, anche se relativi al materiale di cui all’articolo 600-quater 1. Il soggetto attivo può essere chiunque, persino un giovane. Il soggetto passivo deve essere un individuo di età inferiore ai sedici anni e non diciotto, come per gli altri reati di pedofilia. Eventuali errori sull’età della persona offesa non escludono il dolo, tranne che nell’ipotesi di errore inevitabile, inteso come l’ignoranza non riprovevole almeno a titolo di colpa. Il dolo è specifico, poiché è necessario che l’agente sia mosso dall’intenzione di commettere uno dei reati previsti dall’articolo 609-undecies c.p.

Cosa dice la giurisprudenza


Integra il reato di adescamento di minori la condotta di colui che intrattiene con una minore di anni dieci conversazioni a sfondo sessuale nella chat di un sito di giochi online, chiedendole di scaricare un’applicazione per l’invio di fotografie, in modo da poter ricevere foto della minore a sfondo pornografico. Infatti, nel caso in cui vi sia l’intervento di un genitore che scopra la chat e denunci immediatamente il fatto, si consuma proprio ed esclusivamente il reato di adescamento di minori, dato che non sono configurabili i reati sessuali più gravi indicati come reati scopo nell’art. 609-undecies c.p.(Cass., Sez. III, sent. n. 11305/22).

Sussiste il delitto di cui all’art. 609-undecies c.p. allorquando un insegnante di un complesso scolastico attraverso una chat di un social, con espressioni lusinghiere volte a capirne la fiducia, rivolge ad uno studente domande volte a comprenderne l’orientamento sessuale. La condizione di affidamento per ragioni di istruzione, di vigilanza o di custodia prevista per il reato di atti sessuali con minorenne può avere carattere temporaneo o occasionale, potendo configurarsi anche quando il soggetto attivo non sia l’insegnante diretto del minore, ma appartenga comunque alla stessa struttura scolastica. Inoltre, il rapporto di affidamento esistente tra insegnante ed alunno non può essere ritenuto escluso per il fatto che gli atti illeciti oggetto dell’imputazione si svolgano fuori dall’ambiente e dall’orario scolastico (Cass., Sez. III, sent.n. 9735/22; In senso conforme: Cass. ,Sez. III, sent. n. 17373/19; Cass., Sez. III , sent. n. 32170/18).

L’oggetto del dolo specifico deve riguardare anche gli atti sessuali che l’agente intende compiere carpendo la fiducia del minore attraverso artifici, lusinghe o minacce e, cioè, per mezzo dell’attività di adescamento descritta dalla fattispecie (Cass.,Sez. III, sent.n. 17373/19).

Il reato si consuma nel tempo e nel luogo in cui l’agente realizza le condotte descritte nella fattispecie incriminatrice; tuttavia, qualora l’illecito sia posto in essere tramite Internet o con mezzi di comunicazione a distanza, la sua consumazione si verifica nel luogo in cui si trova il minore adescato, perché il delitto presuppone una comunicazione tra due soggetti e in tale luogo si perfeziona la dimensione offensiva del fatto (Cass.,Sez.III, sent. n.36492/19).

Non integra gli estremi del reato la condotta di adescamento di minore commessa al fine di avere rapporti sessuali con un minore di età compresa tra i quattordici ed i sedici anni di età, essendo tale finalità estranea alle ipotesi di cui all’art. 609-quater, comma primo, n. 2) c. p .(Cass.,Sez.III,sent.n.23173/18).

L'articolo Digital Crime: Art. 609-undecies c.p.: Sanzioni e Normative sull’Adescamento di MinorenniDigital Crime: proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

A Beautiful Lamp-Inspired PC Case
poliverso.org/display/0477a01e…
A Beautiful Lamp-Inspired PC CaseSometimes you see something super cool and think of how it would be really neat if applied in a totally different context. [MXC Builds] saw an awesome lamp from [karacreates], but decided it would be better as a PC case youtube.com/watch?v=hv1y0OlhD_….We love seeing how different techniques can be used in conjunction to make something that no one method could


A Beautiful Lamp-Inspired PC Case


A series of wooden rectangles are arranged vertically around the edges of a dark wooden base, reminiscent of a very tall radial fan. Light glows from the base up the slots between the vanes. a cord runs from behind the dark base to a small puck of the same color. The setup sits on a light grey table in front of a light grey wall.

Sometimes you see something super cool and think of how it would be really neat if applied in a totally different context. [MXC Builds] saw an awesome lamp from [karacreates], but decided it would be better as a PC case.

We love seeing how different techniques can be used in conjunction to make something that no one method could produce on its own, and for this build, we see [MXC Builds] use 3D printing, laser cutting, CNC, sewing, soldering, and traditional woodworking techniques.

A large part of the video is spent on the CNC process for the walnut base and power button enclosure for the build. As with any project, there are a few places requiring some creative use of the tools on hand, like the walnut piece for the base being too tall for the machine’s usual z-calibration puck or any of [MXC Builds]’s bits to do in one pass, and it’s always interesting to see how other makers solve these issues.

If you’re looking for other beautiful casemods, how about a transparent PS2 or this Art Deco number? Before you go, may we bend your ear about how PC Cases are Still Stuck in the Dark Ages?

youtube.com/embed/hv1y0OlhD_k?…


hackaday.com/2024/09/23/a-beau…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Custom Mini-Neon Signs in 10 Minutes
poliverso.org/display/0477a01e…
Custom Mini-Neon Signs in 10 MinutesSometimes, you see a project that isn’t a technical powerhouse but just looks so good you can’t help but think about duplicating it. That’s how we felt with the mini-neon signs youtube.com/watch?v=i0Oduk7Lc6… made by [makerverse]. From an electronics point of view, it is just some filament LEDs and a 3D-printed casing. But, as you’ll see in the video below,


Custom Mini-Neon Signs in 10 Minutes


Sometimes, you see a project that isn’t a technical powerhouse but just looks so good you can’t help but think about duplicating it. That’s how we felt with the mini-neon signs made by [makerverse]. From an electronics point of view, it is just some filament LEDs and a 3D-printed casing. But, as you’ll see in the video below, these look like little miniature neon signs, and they look great.

Although we might use a different set of tools to get there, the idea is to create your text in DXF, extrude it in CAD, and then print a dark shell with a light or translucent center using a filament change. Glow-in-the-dark filament is also an option. Obviously, if you are handy in any CAD tool, you could easily pull this off.

After printing, you simply put your LED lighting in the center, and there you go. Sure, there’s no high voltage or neon involved, but it is a cute, fun 3D-printing project.

We’ve seen this trick before, but the contrasting 3D printing really sells it. You can also take a peek at how a pro shop in Korea does it.

youtube.com/embed/i0Oduk7Lc60?…


hackaday.com/2024/09/23/custom…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

AI has a ‘special place’ in French government, says new AI and digital minister
poliverso.org/display/0477a01e…
AI has a ‘special place’ in French government, says new AI and digital minister"AI will take on a very special place in my work" as a member of the new French government, said newly-appointed Secretary of State for artificial intelligence (AI) and digital technologies Clara Chappaz.euractiv.com/section/artificia…


AI has a ‘special place’ in French government, says new AI and digital minister


"AI will take on a very special place in my work" as a member of the new French government, said newly-appointed Secretary of State for artificial intelligence (AI) and digital technologies Clara Chappaz.


euractiv.com/section/artificia…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Revisiting 1990’s Mac Games That Never Were
poliverso.org/display/0477a01e…
Revisiting 1990’s Mac Games That Never Were[John Calhoun] was digging around their old MAC hard drives, revisiting some abandoned shareware games engineersneedart.com/blog/move… they wrote over three decades ago, and has uploaded the recovered disk images to GitHub github.com/EngineersNeedArt/So… for everyone to take apart and play with. This repository has a few of the games complete


Revisiting 1990’s Mac Games That Never Were


[John Calhoun] was digging around their old MAC hard drives, revisiting some abandoned shareware games they wrote over three decades ago, and has uploaded the recovered disk images to GitHub for everyone to take apart and play with. This repository has a few of the games complete with their development files and the compiler environment, a mixture of Think Pascal and C.

Back then, [John] had a solid mantra when creating projects, specifically prototyping fast and abandoning things quickly if they were not working out. The blog shows a list of twenty-eight projects, of which only five ever made it to release, with all the rest left to rot. This is reminiscent of the attitude around Silicon Valley of moving fast and breaking things. Anyway, reasons for ditching a project ranged from ‘too much sprite work’ for a D’n’D style game to simply ‘not fun’ for some with clunky control mechanisms. [John] even abandoned a neat-looking steampunk flight simulator due to the sheer amount of work needed. Of course, it’s not all lost effort. Much of the code written was reused across multiple projects; after all, there’s no point in re-writing a cosine lookup table if you’ve already got one kicking around in another project.

Still, it’s a fun trip down memory lane, looking deep into projects that never were and the development journey to becoming a successful programmer.

While it isn’t hard to find old Macintosh hardware, some are not in great shape. Here’s a fun Hackintosh project that uses retro parts. [John] was featured a while back, with his homage to his first mac, a sleek Rpi-powered eInk desk ornament. Finally, we can’t talk about recovering retro software without looking in detail at the floppy disk themselves.


hackaday.com/2024/09/23/revisi…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Cucù: La Backdoor non c’è più! La Cina pronta a sostituire Windows con HarmonyOS
poliverso.org/display/0477a01e…
Cucù: La Backdoor non c’è più! La Cina pronta a sostituire Windows con HarmonyOSAbbiamo seguito da vicino l’evoluzione delle sanzioni statunitensi e assistito alla nascita di sistemi come HarmonyOS redhotcyber.com/?s=harmony+ose Astra Linux redhotcyber.com/?s=astra+linux, sviluppati in risposta alle sanzioni Statunitensi. Forse lo Zio Sam non aveva


Cucù: La Backdoor non c’è più! La Cina pronta a sostituire Windows con HarmonyOS


Abbiamo seguito da vicino l’evoluzione delle sanzioni statunitensi e assistito alla nascita di sistemi come HarmonyOS e Astra Linux, sviluppati in risposta alle sanzioni Statunitensi. Forse lo Zio Sam non aveva previsto che, in pochi anni, nazioni come Cina e Russia sarebbero riuscite a colmare il vuoto tecnologico creato dal divieto di acquistare tecnologia occidentale. Questo scenario ha portato alla costruzione di nuovi ‘muri’, non fatti di mattoni, ma di barriere digitali, eretti in nome della sicurezza nazionale e dell’autonomia tecnologica.

E come sappiamo i muri una volta eretti, ci vuole tempo prima che questi vengano abbattuti. Ma vi rimandiamo alla lettura “Il mondo ha bisogno di nuovi muri“, di Massimiliano Brolli, per comprendere a pieno di cosa stiamo parlando.

Nello specifico, Huawei si sta preparando ad abbandonare Windows nei suoi futuri computer in favore del proprio sistema operativo HarmonyOS. Lo ha affermato il capo del settore consumer dell’azienda, Yu Chengdong, durante un’intervista il 20 settembre. Secondo lui, la prossima generazione di laptop Huawei verrà fornita con HarmonyOS preinstallato al posto di Windows.

Il motivo di questa decisione sono state le sanzioni statunitensi imposte a Huawei nel 2019, a causa delle quali l’azienda ha perso l’accesso a tecnologie avanzate, strumenti di produzione di chip e software migliorati. Ora l’azienda sta cercando la completa indipendenza dai componenti estranei e l’installazione di HarmonyOS sui laptop è uno dei passi in questa direzione.

Yu Chengdong ha anche osservato che la dipendenza dalle tecnologie straniere nei prodotti Huawei è in calo da molto tempo e che i dispositivi futuri saranno più efficienti introducendo le proprie soluzioni. Secondo lui l’azienda ha già ridotto significativamente l’utilizzo di componenti americani e in futuro intende sostituirli completamente.

HarmonyOS è già utilizzato in altri dispositivi Huawei, come tablet e smartwatch, ma l’azienda ha installato Windows sui laptop fino ad oggi. Tuttavia, le sanzioni hanno costretto Huawei a sviluppare piani di indipendenza per il proprio hardware, che potrebbero portare a una maggiore adozione di HarmonyOS nel mercato globale.

Non è ancora chiaro se HarmonyOS sarà disponibile solo in Cina o apparirà sul mercato internazionale. Si prevede che ulteriori informazioni verranno visualizzate quando verranno lanciati ufficialmente i computer con il nuovo sistema operativo.

L'articolo Cucù: La Backdoor non c’è più! La Cina pronta a sostituire Windows con HarmonyOS proviene da il blog della sicurezza informatica.


The Privacy Post ha ricondiviso questo.

Mandiant vs Judische: Una Partita a Scacchi nel Dark Web
poliverso.org/display/0477a01e…
Mandiant vs Judische: Una Partita a Scacchi nel Dark WebSecondo lo stesso aggressore, Judische ha guadagnato circa 2 milioni di dollari estorcendo dati. All’inizio dell’anno, Judische ha lanciato una serie di attacchi, hackerando i database cloud di Snowflake e rubando dati sensibili. Secondo alcuni rapporti, sono state colpite fino a 165 aziende, tra cui Ticketmaster,


Mandiant vs Judische: Una Partita a Scacchi nel Dark Web


Secondo lo stesso aggressore, Judische ha guadagnato circa 2 milioni di dollari estorcendo dati. All’inizio dell’anno, Judische ha lanciato una serie di attacchi, hackerando i database cloud di Snowflake e rubando dati sensibili. Secondo alcuni rapporti, sono state colpite fino a 165 aziende, tra cui Ticketmaster, Santander Bank e Neiman Marcus. Gli hack hanno causato gravi conseguenze per vari settori.

Uno degli attacchi più importanti di Judische è stata la violazione dei dati di AT&T, in cui lui e il suo complice John Binns hanno rubato informazioni su milioni di utenti. I dati ottenuti potrebbero tracciare la cronologia delle chiamate e dei messaggi degli abbonati, fornendo ai criminali un quadro ricco della vita personale delle vittime. Judische e Binns hanno iniziato effettua do frodi di SIM Swapping. I criminali catturavano i numeri di telefono delle vittime per hackerare i loro account online.

Binns è stato arrestato in Turchia dopo l’attacco hacker ad AT&T, ma Judische ha continuato le sue attività, aumentando il numero degli attacchi. Judische ha utilizzato gli alias “zfa”, “catgwuirrel”, “scarlet” e altri. I messaggi dell’hacker su Telegram sono caotici e minacciosi per i ricercatori di sicurezza informatica. Una strategia è quella conosciuta come “detrace“: incolpa gli altri per i suoi attacchi per confondere gli investigatori.

Oltre al ricatto, Judische ha interagito attivamente con gli intermediari che lo hanno aiutato a strutturare i dati per ulteriori estorsioni. Uno di questi intermediari era Vinny Troia, che ha offerto a Judische i suoi servizi per la vendita di dati rubati. Troia ha mantenuto una corrispondenza attiva con i soci dell’hacker, offrendo opzioni per monetizzare le informazioni rubate.

Le attività di Judische hanno iniziato ad attirare l’attenzione degli esperti di sicurezza informatica. Uno degli esperti, l’analista senior delle minacce di Mandiant Austin Larsen, ha concentrato i suoi sforzi sulla ricerca di tracce che l’hacker potrebbe aver lasciato dietro di sé. Alla conferenza sulla sicurezza informatica LABScon, Larsen presenterà le sue scoperte sull’identità e sulla posizione dell’hacker.

Durante l’indagine, Larsen ha esaminato i messaggi pubblici e privati ​​di Judische su Telegram, dove era attivo. A poco a poco, il ricercatore iniziò a farsi un’idea di chi fosse Judische e dove potesse trovarsi.

Judische ha commesso un errore fondamentale che ha permesso agli investigatori di rintracciarlo. Durante la registrazione di uno dei video in cui Judische avrebbe cancellato i dati rubati della vittima, nell’inquadratura era presente il nome host del computer, che ha aiutato Larsen a tracciare la posizione del server dell’hacker. Utilizzando il motore di ricerca Censys, Larsen è stato in grado di identificare l’infrastruttura che supporta le attività di Judische. Il server è stato trovato in Ucraina e l’accesso è stato presto bloccato.

Il blocco dell’infrastruttura ha rallentato l’hacker, poiché ora non aveva più accesso ad una parte dei dati rubati, ritardando ulteriori tentativi di ricatto verso le aziende. Judische ha risposto con una tempesta di messaggi arrabbiati su Telegram, dove si è lamentato dell’interferenza delle autorità ucraine e ha affermato che il server sarebbe stato restituito a causa di un malinteso. Tuttavia, subito dopo, Mandiant è riuscita a bloccare molti altri server Judische.

La ricerca di Larsen e del team Mandiant ha identificato diverse centinaia di indicatori di compromesso relativi alle attività di Judische. Questi includevano indirizzi IP, nomi host e altri tag tecnici che aiutavano a tenere traccia delle azioni dell’hacker su varie piattaforme.

Sulla base dei dati raccolti, Mandiant è riuscita a farsi un quadro più completo dell’identità dell’aggressore. Judische è un giovane sulla ventina, che si ritiene venga dal Canada, appassionato di videogiochi e “cat woman” (un cliché popolare negli anime), e può stare sveglio per giorni interi mentre hackera Telegram. Al momento, gli investigatori, sia di Mandiant che delle forze dell’ordine negli Stati Uniti e in altri paesi, stanno continuando attivamente le indagini, coordinando i loro sforzi per identificare finalmente l’hacker e reprimere le sue attività.

L'articolo Mandiant vs Judische: Una Partita a Scacchi nel Dark Web proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Fukushima Daiichi: Cleaning Up After a Nuclear Accident
poliverso.org/display/0477a01e…
Fukushima Daiichi: Cleaning Up After a Nuclear AccidentOn 11 March, 2011, a massive magnitude 9.1 earthquake shook the west coast of Japan, with the epicenter located at a shallow depth of 32 km, a mere 72 km off the coast of Oshika Peninsula, of the Touhoku region. Following this earthquake, an equally massive tsunami made its way towards Japan’s eastern shores, flooding


Fukushima Daiichi: Cleaning Up After a Nuclear Accident


On 11 March, 2011, a massive magnitude 9.1 earthquake shook the west coast of Japan, with the epicenter located at a shallow depth of 32 km, a mere 72 km off the coast of Oshika Peninsula, of the Touhoku region. Following this earthquake, an equally massive tsunami made its way towards Japan’s eastern shores, flooding many kilometers inland. Over 20,000 people were killed by the tsunami and earthquake, thousands of whom were dragged into the ocean when the tsunami retreated. This Touhoku earthquake was the most devastating in Japan’s history, both in human and economic cost, but also in the effect it had on one of Japan’s nuclear power plants: the six-unit Fukushima Daiichi plant.

In the subsequent Investigation Commission report by the Japanese Diet, a lack of safety culture at the plant’s owner (TEPCO) was noted, along with significant corruption and poor emergency preparation, all of which resulted in the preventable meltdown of three of the plant’s reactors and a botched evacuation. Although afterwards TEPCO was nationalized, and a new nuclear regulatory body established, this still left Japan with the daunting task of cleaning up the damaged Fukushima Daiichi nuclear plant.

Removal of the damaged fuel rods is the biggest priority, as this will take care of the main radiation hazard. This year TEPCO has begun work on removing the damaged fuel inside the cores, the outcome of which will set the pace for the rest of the clean-up.

Safety Cheese Holes

Overview of a GE BWR as at Fukushima Daiichi. (Credit: WNA)Overview of a GE reactor as at Fukushima Daiichi. (Credit: WNA)
The Fukushima Daiichi nuclear power plant was built between 1967 and 1979, with the first unit coming online in 1970 and the third unit by 1975. It features three generations of General Electric-designed boiling water reactors of a 1960s (Generation II) design. It features what is known as a Mark I containment structure. At the time of the earthquake only units 1, 2 and 3 were active, with the quake triggering safeties which shut down these reactors as designed. The quake itself did not cause significant damage to the reactors, but three TEPCO employees at the Fukushima Daiichi and Daini plants died as a result of the earthquake.

A mere 41 minutes later the first tsunami hit, followed by a second tsunami 8 minutes later, leading to the events of the Fukushima Daiichi accident. The too low seawall did not contain the tsunami, allowing water to submerge the land behind it. This damaged the seawater pumps for the main and auxiliary condenser circuits, while also flooding the turbine hall basements containing the emergency diesel generators and electrical switching gear. The backup batteries for units 1 and 2 also got taken out in the flooding, disabling instrumentation, control and lighting.

One hour after the emergency shutdown of units 1 through 3, they were still producing about 1.5% of their nominal thermal power. With no way to shed the heat externally, the hot steam, and eventually hydrogen from hot steam interacting with the zirconium-alloy fuel rod cladding, was diverted into the dry primary containment and then the wetwell, with the Emergency Core Cooling System (ECCS) injecting replacement water. This kept the cores mostly intact over the course of three days, with seawater eventually injected externally, though the fuel rods would eventually melt due to dropping core water levels, before solidifying inside the reactor pressure vessel (RPV) as well as on the concrete below it.

It was attempted to vent the steam pressure in unit 1, but this resulted in the hydrogen-rich air to flow into the service floor, where it found an ignition source and blew off the roof. To prevent this with unit 2, a blow-out panel was opened, but unit 3 suffered a similar hydrogen explosion on the service floor, with part of the hydrogen also making it into the defueled unit 4 via ducts and similarly blowing off its roof.

The hydrogen issue was later resolved by injecting nitrogen into the RPVs of units 1 through 3, along with external cooling and power being supplied to the reactors. This stabilized the three crippled reactors to the point where clean-up could be considered after the decay of the short-lived isotopes present in the released air. These isotopes consisted of mostly iodine-131, with a half-life of 8 days, but also cesium-137, with a half-life of 30 years, and a number of other isotopes.

Nuclear Pick-up Sticks


Before the hydrogen explosions ripped out the service floors and the building roofs, the clean-up would probably have been significantly easier. Now it seemed that the first tasks would consist out of service floor clean-up of tangled metal and creating temporary roofs to keep the elements out and any radioactive particles inside. These roof covers are fitted with cameras as well as radiation and hydrogen sensors. They also provide the means for a crane to remove fuel rods from the spent fuel pools at the top of the reactors, as most of the original cranes were destroyed in the hydrogen explosions.
Phot of the damaged unit 1 of Fukushima Daiichi and a schematic overview of the status. (Credit: TEPCO)Phot of the damaged unit 1 of Fukushima Daiichi and a schematic overview of the status. (Credit: TEPCO)
This meant that the next task is to remove all spent fuel from these spent fuel pools, with the status being tracked on the TEPCO status page. As units 5 and 6 were undamaged, they are not part of these clean-up efforts and will be retained after clean-up and decommissioning of units 1-4 for training purposes.

Meanwhile, spent fuel rods were removed already from units 3 and 4. For unit 1, a cover still has to be constructed as has has been done for unit 3, while for the more intact unit 2 a fuel handling facility is being constructed on the side of the building. Currently a lot of the hang-up with unit 1 is the removal of debris on the service floor, without risking disturbing the debris too much, like a gigantic game of pick-up sticks. Within a few years, these last spent fuel rods can then be safely transported off-site for storage, reprocessing and the manufacturing of fresh reactor fuel. That’s projected to be 2026 for Unit 2 and 2028 for Unit 1.

This spent fuel removal stage will be followed by removing the remnants of the fuel rods from inside the RPVs, which is the trickiest part as the normal way to defuel these three boiling-water reactors was rendered impossible due to the hydrogen explosions and the melting of fuel rods into puddles of corium mostly outside of the RPVs. The mostly intact unit number 2 is the first target of this stage of the clean-up.
Estimated corium distribution in Fukushima Daiichi unit 1 through 3. (Credit: TEPCO)Estimated corium distribution in Fukushima Daiichi unit 1 through 3. (Credit: TEPCO)
To develop an appropriate approach, TEPCO relies heavily on exploration using robotic systems. These can explore the insides of the units, even in areas which are deemed unsafe for humans and can be made to fit into narrow tubes and vents to explore even the insides of the RPVs. This is how we have some idea of where the corium ended up, allowing for a plan to be formed for the extracting of this corium for disposal.

Detailed updates on the progress of the clean-up can be found as monthly reports, which also provide updates on any changes noted inside the damaged units. Currently the cores are completely stable, but there is the ongoing issue of ground- and rainwater making it into the buildings, which causes radioactive particles to be carried along into the soil. This is why groundwater at the site has been for years now been pumped up and treated with the ALPS radioactive isotope removal system. This leaves just water with some tritium, which after mixing with seawater is released into the ocean. The effective tritium release this way is lower than when the Fukushima Daiichi plant was operating.
TEPCO employees connect pipes that push the 'Telesco' robot into the containment of Unit 2 for core sample retrieval. (Credit: TEPCO)TEPCO employees connect pipes that push the ‘Telesco’ robot into the containment of Unit 2 for core sample retrieval. (Credit: TEPCO)
In these reports we also get updates on the robotic exploration, but the most recent update here involves a telescoping robot nicknamed ‘Telesco’ (because it can extend by 22 meters) which is tasked with retrieving a corium sample of a few grams from the unit 2 reactor, in the area underneath the RPV where significant amounts of corium have collected. This can then be analyzed and any findings factored into the next steps, which would involve removing the tons of corium. This debris consists of the ceramic uranium fuel, the zirconium-alloy cladding, the RPV steel and the transuranics and minor actinides like plutonium, Cs-137 and Sr-90, making it radiologically quite ‘hot’.

Looking Ahead


Although the clean-up of Fukushima Daiichi may seem slow, with a projected completion date decades from now, the fact of the matter is that time is in our favor, as the issue of radiological contamination lessens with every passing day. Although the groundwater contamination is probably the issue that gets the most attention, courtesy of the highly visible storage tanks, this is now fully contained including with sea walls, and there is even an argument to be made that dilution of radioisotopes into the ocean would make it a non-issue.

Regardless of the current debate about radiological overreacting and safe background levels, most of the exclusion zone around the Fukushima Daiichi plant has already been reopened, with only some zones still marked as ‘problematic’, despite having background radiation levels that are no higher than the natural levels in other inhabited regions of the world. This is also the finding of the UNSCEAR in their 2020 status report (PDF), which finds levels of Cs-137 in marine foods having dropped already sharply by 2015, no radiation-related events in those evacuated or workers in the exclusion zone, and no observed effects on the local fauna and flora.

Along with the rather extreme top soil remediation measures that continue in the exclusion zone, it seems likely that within a few years this exclusion zone will be mostly lifted, and the stricken plant itself devoid of spent fuel rods, even as the gradual removal of the corium will have begun. First starting with small samples, then larger pieces, until all that will left inside units 1-3 will be some radioactive dust, clearing the way to demolish the buildings. But it’s a long road.


hackaday.com/2024/09/23/fukush…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

New note by cybersecurity
poliverso.org/display/0477a01e…
L’agroalimentare americano tra AI e minacce cyber key4biz.it/lagroalimentare-ame…@Informatica (Italy e non Italy 😁)Crescono le cyber minacce per l’agri-food USA Il settore dell’agri-food statunitense ha visto in questi anni un impiego massiccio di nuove tecnologie. Robotica, intelligenza artificiale (AI), cloud, internet delle cose, gps e droni hanno fatto progressivamente la loro comparsa nell’ag


L’agroalimentare americano tra AI e minacce cyber


@Informatica (Italy e non Italy 😁)
Crescono le cyber minacce per l’agri-food USA Il settore dell’agri-food statunitense ha visto in questi anni un impiego massiccio di nuove tecnologie. Robotica, intelligenza artificiale (AI), cloud, internet delle cose, gps e droni hanno fatto progressivamente la loro comparsa nell’agroalimentare americano, ma con


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

New Release of Vision Basic: Hot New Features!
poliverso.org/display/0477a01e…
New Release of Vision Basic: Hot New Features!As the Commodore 64 ages, it seems to be taking on a second life. Case in point: Vision BASIC is a customized, special version of the BASIC programming language with a ton of features to enable Commodore 64 programs to be written more easily and with all sorts of optimizations. We’ve tested out both the original 1.0 version of Vision


New Release of Vision Basic: Hot New Features!


As the Commodore 64 ages, it seems to be taking on a second life. Case in point: Vision BASIC is a customized, special version of the BASIC programming language with a ton of features to enable Commodore 64 programs to be written more easily and with all sorts of optimizations. We’ve tested out both the original 1.0 version of Vision BASIC, and now with version 1.1 being released there are a whole host of tweaks and updates to make the experience even better!

One of the only limitation of Vision BASIC is the requirement for expanded RAM. It will not run on an unexpanded C64 — but the compiled programs will, so you can easily distribute software made using Vision on any C64. A feature introduced in version 1.1 is support for GeoRAM, a different RAM expansion cartridge, and modern versions of GeoRAM like the NeoRAM which has battery-backed RAM. This allows almost instantaneous booting into the Vision BASIC development environment.

Some of the standout features include a doubling of compilation speed, which is huge for large programs that take up many REU segments in source form. There are new commands, including ALLMOBS for setting up all sprites with a single command; POLL to set up which joystick port is in use; CATCH to wait for a particular scanline; and plenty more! Many existing commands have been improved as well. As in the original version of Vision BASIC, you can freely mix 6510 assembly and BASIC wherever you want. You can use the built-in commands for bitmaps, including panning, collision detection, etc., or you can handle it in assembly if you want! And of course, it comes with a full manual — yes, a real, printed book!

One of the nice features of Vision BASIC is the customization of the development environment. On the first run, after agreeing to the software terms, you enter your name and it gets saved to the Vision BASIC disk. Then, every time you start the software up, it greets you by name! You can also set up a custom colour scheme, which also gets saved. It’s a very pleasant environment to work in. Depending on how much additional RAM you have, you can hold multiple program segments in different RAM banks. For example, you could have all your source code in one bank, all your bitmaps and sprites in another, and your SID tunes in yet another. The compiler handles all this for you when you go to compile the program to disk, so it’s easy to keep large programs organized and easy to follow.

If you’ve always wanted to write a game or application for the C64 but just didn’t know how to get started, or you felt daunted at having to learn assembly to do sprites and music, Vision BASIC is a great option. You will be blown away at the number of commands available, and as you become more experienced you can start to sprinkle in assembly to optimize certain parts of your code if desired.


hackaday.com/2024/09/23/new-re…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Draghi is right: To rebuild competitiveness, Europe must reimagine its approach to innovation
poliverso.org/display/0477a01e…
Draghi is right: To rebuild competitiveness, Europe must reimagine its approach to innovationTo reap the benefits of artificial intelligence (AI), the EU needs to change its regulatory approach, invest in research and development (R&D) and infrastructure, and skills, writes Google's Matt Brittin.euractiv.com/section/artificia…

The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

La Guerra Silenziosa dei Dati! Gli infostealer contro Chrome: chi vincerà la battaglia?
poliverso.org/display/0477a01e…
La Guerra Silenziosa dei Dati! Gli infostealer contro Chrome: chi vincerà la battaglia?Gli sviluppatori dei popolari infostealer hanno informato x.com/g0njxa/status/1837093565… i clienti di aver imparato a bypassare la funzionalità di crittografia security.googleblog.com/2024/0… di Chrome e a raccogliere cookie di autenticazione


La Guerra Silenziosa dei Dati! Gli infostealer contro Chrome: chi vincerà la battaglia?


Gli sviluppatori dei popolari infostealer hanno informato i clienti di aver imparato a bypassare la funzionalità di crittografia di Chrome e a raccogliere cookie di autenticazione precedentemente crittografati.

security.googleblog.com/2024/0…

Una nuova funzionalità di sicurezza è stata aggiunta a Chrome 127 a luglio ed è progettata per crittografare i dati associati al processo del browser. Tali dati possono essere decrittografati solo utilizzando un account amministratore.

Negli ultimi due mesi gli sviluppatori di malware hanno cercato attivamente modi per aggirare la barriera. Alcuni hanno inserito codice dannoso direttamente nel processo Chrome o hanno utilizzato vulnerabilità di escalation dei privilegi per ottenere l’accesso ai diritti di amministratore. Ora gli infostealer come Lumar, Lumma, Meduza, Vidar e WhiteSnake hanno nuove capacità per effettuare questo bypass.

Google aveva capito che la funzionalità di crittografia associata all’app non era una panacea e che gli aggressori alla fine avrebbero trovato il modo di aggirarla. Tuttavia, l’azienda ha deciso di implementarlo perché sapeva che i tentativi di aggirarlo avrebbero reso le azioni dei ladri di informazioni più visibili ai software antivirus. Come spiega Google, “Poiché App-Bound funziona con privilegi di sistema, gli hacker devono fare molto di più che semplicemente indurre un utente a eseguire un’app dannosa. Il malware deve ora ottenere i diritti di sistema o iniettare codice in Chrome, rendendo le sue azioni più sospette per il software antivirus e con maggiori probabilità di essere rilevato.”

Nell’ultimo mese, gli infostealer sono stati sempre più utilizzati per hackerare e distribuire ransomware, costringendo il team di sicurezza di Google a prestare maggiore attenzione alla protezione dei dati nel browser. Sebbene la crittografia associata all’app attualmente funzioni solo per i cookie, la società prevede di espanderla a password, informazioni di pagamento e altri token di autenticazione archiviati in Chrome.

Si prevede che la nuova funzionalità di sicurezza sarà supportata su circa la metà di tutti i dispositivi Chrome desktop e sarà pienamente coerente con l’eliminazione graduale dei cookie di terze parti in Chrome.

L'articolo La Guerra Silenziosa dei Dati! Gli infostealer contro Chrome: chi vincerà la battaglia? proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

How the Necro Trojan infiltrated Google Play, again
poliverso.org/display/0477a01e…
How the Necro Trojan infiltrated Google Play, againIntroductionWe sometimes come across modified applications when analyzing suspicious files. These are created in response to user requests for more customization options within the app or for new features that the official versions don’t have. Unfortunately, it’s not uncommon for popular mods to contain malware. This often


How the Necro Trojan infiltrated Google Play, again



Introduction


We sometimes come across modified applications when analyzing suspicious files. These are created in response to user requests for more customization options within the app or for new features that the official versions don’t have. Unfortunately, it’s not uncommon for popular mods to contain malware. This often happens because they’re distributed on unofficial websites that don’t have any moderation. For example, last year we found popular WhatsApp mods infected with CanesSpy and distributed this way. Before that, we found ads for WhatsApp mods infected with the Triada Trojan dropper in the popular Snaptube application. However, even official app stores can be infiltrated by infected apps. In 2019, we discovered the Necro dropper hidden within CamScanner, a widely used document scanning and processing app available on Google Play. At the time of the malware discovery, this app had been downloaded to more than 100 million devices worldwide. Sadly, history has repeated itself, and this time the Trojan authors exploited both distribution vectors: the new version of the multi-stage Necro loader infected both apps in Google Play and modified versions of Spotify, Minecraft, and other popular applications in unofficial sources.

Our conclusions in a nutshell:

  • The new version of the Necro Trojan has infected various popular applications, including game mods, with some of them being available on Google Play at the time of writing this report. The combined audience of the latter exceeds 11 million Android devices.
  • The new version of the Necro loader, like most payloads it loads, has begun to use obfuscation to evade detection.
  • The loader, embedded in some applications, used steganography techniques to hide payloads.
  • The downloaded payloads, among other things, could display ads in invisible windows and interact with them, download and execute arbitrary DEX files, install applications it downloaded, open arbitrary links in invisible WebView windows and execute any JavaScript code in those, run a tunnel through the victim’s device, and potentially subscribe to paid services.


How Necro spreads

Necro loader inside a Spotify mod


In late August 2024, our attention was drawn to a Spotify mod called Spotify Plus, version 18.9.40.5. At the time of writing this, the mod could be downloaded from spotiplus[.]xyz and several related sites that linked to it. The original website claimed that the mod was certified, safe, and contained numerous additional features not found in the official app. We decided to verify the claims about the application’s safety by downloading the latest version from this website (acb7a06803e6de85986ac49e9c9f69f1) and analyzing it.

Site containing the Spotify mod
Site containing the Spotify mod

The mod implements a custom Application subclass that initializes an SDK named adsrun in its
onCreate method. This SDK is intended for integrating several advertising modules into the application: among other things, it initializes a module named Coral SDK. Upon activation, Coral SDK transmits a POST request to a designated command-and-control server. This request contains encrypted JSON data, specifically detailing the compromised device and the application hosting the module. The encryption method employed is a substitution cipher, where the substitution values are generated using a standard Java pseudo-random number generator seeded with a predefined constant. See an example of data sent by the module below.{
"appId": "REDACTED",
"channelId": "com.spoti.plus",
"androidId": "REDACTED",
"isAdb": false,
"isProxy": false,
"isSimulator": false,
"isDebug": false,
"localShellVer": 0,
"sdkVer": 116,
"appVersion": "1020000005",
"appVersionName": "18.9.40.5"
}
The C2 server returns a JSON response with an error code, encrypted with the same method. A value of 0 indicates successful execution. In this case, the response from the C2 will also contain an array of one object with a link to download the image in PNG format and associated metadata: name, MD5, version, and so on. Intriguingly, the downloaded file is termed “shellP”, suggesting it might be a condensed form of “shellPlugin”.
{
"code": 0,
"result": [{
"md5": "F338384C5B4BC7D55681A3532273B4EB",
"name": "shellP",
"sdkver": 100,
"url": "hxxps://adoss.spinsok[.]com/plugin/shellP_100.png.png"
}
]
}
Next, the module verifies the integrity of the downloaded image by calculating its MD5 hash and comparing it to the value received from the server. A payload is hidden in this image using steganography, which the module must extract and execute in the next step.

Coral SDK uses a very simple steganographic algorithm. If the MD5 check is successful, it extracts the contents of the PNG file — the pixel values in the ARGB channels — using standard Android tools. Then the
getPixel method returns a value whose least significant byte contains the blue channel of the image, and processing begins in the code.
Steganographic algorithm for payload extraction
Steganographic algorithm for payload extraction

If we consider the blue channel of the image as a byte array of dimension 1, then the first four bytes of the image are the size of the encoded payload in Little Endian format (from the least significant byte to the most significant). Next, the payload of the specified size is recorded: this is a JAR file encoded with Base64, which is loaded after decoding via DexClassLoader. Coral SDK loads the
sdk.fkgh.mvp.SdkEntry class in a JAR file using the native library libcoral.so. This library has been obfuscated using the OLLVM tool. The starting point, or entry point, for execution within the loaded class is the run method.
Starting the payload
Starting the payload

Therefore, the security claims made about the application on the mod website can be considered false.

Popular applications in Google Play are infected with Necro


Having searched for the loader in our telemetry, we found other apps infected with Necro, including those available in Google Play at the time of writing this report. Their combined audience numbered more than 11 million Android devices.

Wuta Camera app in Google Play
Wuta Camera app in Google Play

Our first find is the Wuta Camera app. Judging by its page in Google Play, it was downloaded at least 10 million times. According to our data, the Necro loader has been embedded in it starting from version 6.3.2.148. The latest version of the app at the time of collecting information, 6.3.6.148 (1cab7668817f6401eb094a6c8488a90c), which was available on Google Play, also had the Necro loader. We reported the presence of malicious code to Google Play, after which the loader was removed from the app in version 6.3.7.138.

Malicious loader in Wuta Camera
Malicious loader in Wuta Camera

The second infected app we found was Max Browser.

Max Browser app in Google Play
Max Browser app in Google Play

This browser, according to Google Play, has been installed more than a million times and, starting with version 1.2.0, also contained the Necro loader. After we reported it, Google took down the infected app from their store.

Necro Trojan within Max Browser
Necro Trojan within Max Browser

WhatsApp mods with the Necro loader


We also found WhatsApp mods containing the Necro loader (0898d1a6232699c7ee03dd5e58727ede) in unofficial sources. The infected application is distributed under the package name
com.leapzip.animatedstickers.maker.android. Interestingly, there’s a legitimate app on Google Play with the exact same package name that isn’t a WhatsApp mod, but instead offers a collection of stickers for the messaging app.
The loader contained within the ad module in these applications functions somewhat differently from the sample described above. For instance, the code isn’t obfuscated at all but is protected by the SecAPK code protector. Additionally, the application uses Google’s Firebase Remote Config cloud service as a C2, storing information about files that need to be downloaded and executed.

Running the payload
Running the payload

While examining this loader, we discovered an interesting quirk: the malicious code within it has an 84% or 90% chance of execution. Initially, a random number between 0 and 99 is generated. Subsequently, based on the application package name, a threshold for malware execution is selected: the generated number must exceed either 9 or 15 for the loader to launch. If the number meets this criterion, a corresponding flag inhibiting loader operation is set to
false, and the malicious functionality is executed.
The malicious functionality will be executed with a predetermined probability
The malicious functionality will be executed with a predetermined probability

Intermediate payloads downloaded by this loader are not pre-encoded. The Trojan receives both the entry point information for the downloaded file and the download link from its C2 server. According to our data, one of the payloads (37404ff6ac229486a1de4b526dd9d9b6) bore resemblance to a loader found in a modified version of Spotify, albeit with minor variations.

  • The next-stage payload (shellPlugin) is loaded without the aid of native code.
    Loading shellPlugin
    Loading shellPlugin
  • A different path is used for the POST request to the command-and-control server to retrieve shellPlugin information.
  • Instead of using the steganographic algorithm, shellPlugin is decoded with Base64.


Other infected applications


This is not an exhaustive list of our findings. In addition to Spotify and WhatsApp mods, as well as apps in Google Play, we found infected game mods, including the following:

  • Minecraft;
  • Stumble Guys;
  • Car Parking Multiplayer;
  • Melon Sandbox.

Given that various apps from multiple sources, including official ones, were found to be infected, we believe that the developers used an untrusted solution for ad integration. This led to a malicious loader appearing in the apps. Our security solutions detect it with the following verdicts:

  • HEUR:Trojan-Downloader.AndroidOS.Necro.f;
  • HEUR:Trojan-Downloader.AndroidOS.Necro.h.


The Necro lifecycle in the wild: how the payload works


During our research, we managed to obtain several samples of payloads that the loader subsequently executes. This particular payload (fa217ca023cda4f063399107f20bd123) exhibits several interesting characteristics that allow us to classify it as belonging to the Necro family:

  • The loader obtains download information from the C2 domain bearsplay[.]com. According to our telemetry data, the domain has been contacted by Necro-family malware.
  • According to our data, the C2 domains that this file interacts with are also being used by the Necro and xHelper Trojans.
  • The functionality of this new payload is very similar to the previous version of Necro (402b91c6621b8093d44464fc006e706a). The code of the Trojans is also similar, but in this new payload, the attackers have used an obfuscator to make it harder for security solutions to detect and analyze.
    Code snippet from the payload
    Code snippet from the payload

    Similar code snippet from an old version of Necro
    Similar code snippet from an old version of Necro

  • The payload configuration structure is identical to that of older versions of Necro, including the one we previously discovered in the CamScanner app. The field names in the configuration match the corresponding fields in other Necro versions.

Based on this, we assert that both the examined payload and the original loader belong to the Necro family, which is familiar to us.

Payload structure


Now let’s move on to analyzing the payload. The second stage of the launch process reads a JSON-formatted configuration embedded within the code. An example of the configuration is provided below.
{
"hs":{
"server":"https://oad1.azhituo.com:9190",
"default":"https://oad1.azhituo.com:9190",
"dataevent":"https://oad1.azhituo.com:9190",
"PluginServer":"https://oad1.azhituo.com:9190"
},
"ps":{
"web":"canna",
"dsp":"hatch"
},
"mp":{
"PMask":"159"
},
"rp":{}
}
The
rp switch might contain malicious services to be launched, but it was empty in the samples we analyzed.
Code for launching the malicious service from the "rp" parameter
Code for launching the malicious service from the “rp” parameter

The
mp configuration switch holds parameters for the second-stage loader. It’s likely an abbreviation for “module parameters”.
The malicious functionality of Necro is implemented in additional modules that are downloaded from the C2 server. The malware authors frequently refer to these as “plugins” in the code. The
ps configuration field (likely an abbreviation for “plugin stop list”, meaning a list of prohibited plugins) is necessary to block these modules. The switches in this object are the names of plugins that are forbidden to load, and the values are alternative plugins that can be executed instead of the blocked ones if they were loaded. The download ban will be applied if the mp field has the PluginControl flag set to true. However, in the samples we were able to obtain, the restrictions did not apply. Additionally, the mp field may contain the PluginUpdateFeature flag, which controls plugin updates. If this flag is not present, plugins will be updated by default.
The
hs switch in the configuration stores a list of C2 addresses which the Trojan will talk to. Note that the malware logic does not require all addresses to match, although in the sample we examined, they were identical. The Trojan needs each address to perform the following tasks:

  • server is used to update the PluginServer server address. To do this, the Trojan first sends a POST request containing the ID of the malicious implant and the name of the application package it’s embedded into. After that, the server can send a new PluginServer address. If the address cannot be updated, the value from the configuration set in the code is used.
    Updating PluginServer
    Updating PluginServer
  • dataevent is used to store various events related to SDK activity.
  • default is not used at this stage.
  • PluginServer instructs the Trojan which plugins to download. Initially, a large amount of data is sent to this server. This includes information about the infected device (screen size, RAM, IMEI, IMSI, operating system version), information about the device’s environment (whether USB debugging mode and developer mode are enabled, if emulator artifacts are detected, etc.), details about the infected app, and so on.
    Sending collected data to PluginServer
    Sending collected data to PluginServer

In response, the server sends a list of plugins to download. These are downloaded asynchronously. To do this, the malware registers a broadcast receiver, and a separate thread, which is started for the download, sends a broadcast message when a plugin is ready to be downloaded. The plugins are differentiated by their name, which is also provided by the server.

Plugin encryption and loading


The plugin loading code supports, among other things, the ability to decrypt plugins using various methods. Additionally, payloads can be extracted beforehand using the steganographic algorithm described above if a file with a .png extension was downloaded. The decryption method is specified in the file URL. The following options are available:

  • new/enc: decryption with a substitution cipher similar to that used for C2 communication
  • ssd: plugin decryption using the DES algorithm
  • ori: unencrypted plugin
    Selecting a decryption procedure
    Selecting a decryption procedure

If no encryption method is specified, the plugin will be decrypted using a substitution cipher. The initial seed for this cipher will be the
PMask parameter (short for plugin mask), which is defined in the mp object within the loader configuration. Once decoded, plugins can be loaded in various ways.
Selecting a method to load the plugin
Selecting a method to load the plugin


  • dex: this method loads the plugin using DexClassLoader. The loader provides it with the application and plugin context, and additional plugin information.
    Loading the plugin in dex mode
    Loading the plugin in dex mode

    Launching the plugin entry point
    Launching the plugin entry point

  • res: this method allows loading plugins with new resources. These resources can be used to download more plugins in the future.
    Loading new resources
    Loading new resources
  • apk: a method that allows sending information about a downloaded file to a service via the IPC Binder mechanism. The name of the service is specified in the bird_vm_msg_service property. While it’s not definitively known which services Necro used, we can speculate that this function is used to install arbitrary APK files on the victim’s device.


Types of plugins


To better understand the attackers’ goals, we decided to thoroughly examine the payloads downloaded by the Trojan and, after analyzing telemetry data, found several Necro modules.

ed6c6924201bc779d45f35ccf2e463bb – Trojan.AndroidOS.Necro.g

This is a Necro module named “NProxy”. Its purpose is to create a tunnel through the victim’s device. When launched, the module connects to a server defined in the code.

Connecting to the server
Connecting to the server

This server acts as a C2 server that the Trojan talks to via an unidentified protocol implemented over TCP sockets. The C2 sends commands, which the Trojan processes. After processing, the Trojan forwards traffic from one endpoint to another through the victim’s device.

b3ba3749237793d2c06eaaf5263533f2 – Trojan.AndroidOS.Necro.i

We named this plugin “island”. When launched, the plugin generates a pseudo-random number, which it uses as an interval (in milliseconds) between displays of intrusive ads.

Trojan showing ads
Trojan showing ads

ccde06a19ef586e0124b120db9bf802e – Trojan.AndroidOS.Necro.d

This plugin is named “web”, and it is one of the most popular Necro plugins, judging by our telemetry data. Its code contains a configuration similar in structure to the shellPlugin payload configuration in the previous stage. It’s interesting that the code for this plugin contains artifacts of older versions of Necro.

nicro is one such artifact from older Necro versions found within the plugin's configuration
nicro is one such artifact from older Necro versions found within the plugin’s configuration

Depending on the value of the
CheckAbnormal flag, the plugin checks for the presence of a debugger in the execution environment and if a phone is connected via USB using ADB. If either condition is met, the Trojan clears the Logcat log to hide traces of its activity. Additionally, the plugin verifies if it has the permission to display windows on top of other applications. After all these checks, it launches a malicious task that runs once every two hours. When the malware starts, it sends a POST request containing details about the infected device to the server server. This is done to get the address of another server, named main URL, which the Trojan will communicate with frequently. If there’s an error when getting this address, the malware will fall back to using a server named default.
Data about the infected device sent to the C2
Data about the infected device sent to the C2

The received
main URL serves as the C2 server: it sends a list of pages to the Trojan, which the malware later opens in the background before processing the interactive elements contained on them. This functionality has a couple of interesting features. First, the Trojan code contains some artifacts that indicate it might be running with elevated privileges. However, Android processes with elevated privileges do not allow WebView by default. Privilege checks occur directly when creating an instance of the WebView factory: in privileged processes, it won’t be created. To circumvent this restriction, the Trojan creates an instance of the factory directly using reflection, thus bypassing all checks of the current process.
Instantiating a WebView factory directly
Instantiating a WebView factory directly

Secondly, the Trojan can download and run other executables, which are then used to replace links loaded with WebView. Combined with the functionality described above, this theoretically allows to do things like adding any additional information to the URL parameters of a replaced link, such as confirmation codes for paid subscriptions, as well as executing other arbitrary code when loading specific links.

36ab434c54cce25d301f2a6f55241205 – Trojan-Downloader.AndroidOS.Necro.b

This module is named “Happy SDK”. Its code partially combines the NProxy and web modules logic, as well as the functionality of the previous stage of the loader with a few minor differences:

  • The code lacks the Trojan configuration, and backup C2 servers are located by default in the corresponding methods.
    Server address for updating the module is specified in the method code by default
    Server address for updating the module is specified in the method code by default
  • The code corresponding to the “web” plugin lacks the functionality to execute arbitrary code.
    Note that we have occasionally encountered this SDK under the name “Jar SDK”. Analysis has shown that Jar SDK is a new version of Happy SDK.
    Happy SDK artifacts in Jar SDK
    Happy SDK artifacts in Jar SDK

We believe this is a different variant of Necro where the developers have opted for a non-modular architecture in the malicious SDK. This suggests that Necro is highly adaptable and can download different iterations of itself, perhaps to introduce new features.

874418d3d1a761875ebc0f60f9573746 – Trojan.AndroidOS.Necro.j

We dubbed this plugin “Cube SDK”. It’s pretty simple and acts as a helper: its only job is to load other plugins to handle ads in the background.

522d2e2adedc3eb11eb9c4b864ca0c7f – Trojan.AndroidOS.Necro.l

This plugin, in addition to NProxy’s functionality, has an entry point for another plugin we’ve named “Tap”. Judging by its code, the latter is still under development: it contains a lot of unused functionality for interacting with ad pages. Tap downloads arbitrary JavaScript code and a WebView interface from the C2 server, which are responsible for viewing ads in the background. Among other things, the plugin includes
com.leapzip.animatedstickers.maker.android as the package name of the infected app. This confirms that the WhatsApp mod loader described earlier, which uses Firebase Remote Config as a C2, also belongs to the Necro family.
These are all the payloads we were able to find during our research. For simplicity, we’ve combined all the processes described above into a single diagram illustrating all stages of the Necro Trojan.

Necro Trojan infection diagram
Necro Trojan infection diagram

It’s worth noting that the creators of Necro may regularly release new plugins and distribute them among infected devices, selectively or otherwise, for example, depending on the information about the infected application.

Victims


According to Google Play data, the infected applications could have been downloaded over 11 million times. However, the actual number of infected devices might be much higher, considering that the Trojan also infiltrated modified versions of popular apps distributed through unofficial sources.

KSN data shows that our security solutions blocked over ten thousand Necro attacks worldwide between August 26th and September 15th. Russia, Brazil, and Vietnam experienced the highest number of attacks. The chart below illustrates the distribution of Necro attacks across countries and territories where users most frequently encountered the Trojan.

Necro attacks by country and territory, August 26 through September 15, 2024 (download)

Conclusion


The Necro Trojan has once again managed to attack tens of thousands of devices worldwide. This new version is a multi-stage loader that used steganography to hide the second-stage payload, a very rare technique for mobile malware, as well as obfuscation to evade detection. The modular architecture gives the Trojan’s creators a wide range of options for both mass and targeted delivery of loader updates or new malicious modules depending on the infected application. To avoid being infected with this malware:

  • If you have any of the aforementioned Google Play apps installed and the versions are infected, update the app to a version where the malicious code has been removed, or delete it.
  • Download applications from official sources only. Applications installed from unofficial platforms may contain malicious functionality.
  • Use a reliable security solution to protect your device from attempts to install malware.


Indicators of compromise


Applications infected with the loader

ApplicationVersionMD5
Wuta Camera6.3.6.1481cab7668817f6401eb094a6c8488a90c
6.3.5.14830d69aae0bdda56d426759125a59ec23
6.3.4.1484c2bdfcc0791080d51ca82630213444d
6.3.2.1484e9bf3e8173a6f3301ae97a3b728f6f1
Max Browser1.2.428b8d997d268588125a1be32c91e2b92
1.2.352a2841c95cfc26887c5c06a29304c84
1.2.2247a0c5ca630b960d51e4524efb16051
1.2.0b69a83a7857e57ba521b1499a0132336
Spotify Plus (spotiplus[.]xyz)18.9.40.5acb7a06803e6de85986ac49e9c9f69f1
GBWhatsApp2.22.63.160898d1a6232699c7ee03dd5e58727ede
FMWhatsApp20.65.081590d5d62a4d97f0b12b5899b9147aea

Loader C2 server
oad1.bearsplay[.]com
shellPlugin versions

URLMD5 of the extracted file
hxxps://adoss.spinsok[.]com/plugin/shellP_100.png.pngfa217ca023cda4f063399107f20bd123
hxxps://adoss.spinsok[.]com/plugin/shellE_30.png59b44645181f4f0d008c3d6520a9f6f3

Second-stage payload
37404ff6ac229486a1de4b526dd9d9b6

Second-stage payload C2 server
oad1.azhituo[.]com

Plugins (third stage)

Plugin nameMD5Verdict
NProxyed6c6924201bc779d45f35ccf2e463bbTrojan.AndroidOS.Necro.g
Cube874418d3d1a761875ebc0f60f9573746
cfa29649ae630a3564a20bf6fb47b928
Trojan.AndroidOS.Necro.j
Islandb3ba3749237793d2c06eaaf5263533f2Trojan.AndroidOS.Necro.i
Web/Lotus SDKccde06a19ef586e0124b120db9bf802eTrojan.AndroidOS.Necro.d
Happy SDK36ab434c54cce25d301f2a6f55241205Trojan-Downloader.AndroidOS.Necro.b
Jar SDK1eaf43be379927e050126e5a7287eb98Trojan-Downloader.AndroidOS.Necro.b
Tap522d2e2adedc3eb11eb9c4b864ca0c7fTrojan.AndroidOS.Necro.l

Plugin C2 servers
47.88.246[.]111
174.129.61[.]221
47.88.245[.]162
47.88.190[.]200
47.88.3[.]73
hsa.govsred[.]buzz
justbigso[.]com
bear-ad.oss-us-west-1.aliyuncs[.]com


securelist.com/necro-trojan-is…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

StratoSoar Glider Flies Itself from High Altitude
poliverso.org/display/0477a01e…
StratoSoar Glider Flies Itself from High AltitudeAs the technology available to the average hacker and maker gets better and cheaper each year, projects which at one time might have only been within the reach of government agencies are inching closer to our grasp. Take for example the impressive work [Charlie Nicholson] has put into his StratoSoar github.com/crnicholson/StratoS…


StratoSoar Glider Flies Itself from High Altitude


As the technology available to the average hacker and maker gets better and cheaper each year, projects which at one time might have only been within the reach of government agencies are inching closer to our grasp. Take for example the impressive work [Charlie Nicholson] has put into his StratoSoar series of autonomous gliders.

Dropped from several thousand feet by a high-altitude balloon, the glider’s avionics are designed to either guide it along a series of waypoints or head directly towards a specific target. Once at the given coordinates it can initiate different landing programs, such as spiraling down to the ground or releasing an onboard parachute. It’s an ambitious combination of custom hardware and software, made all the more impressive by the fact that it’s been put together by somebody who’s not yet old enough to have a driver’s license.

[Charlie] originally experimented with developing his own airframe using 3D printed components, but at least for now, found that a commercial off-the-shelf foam glider was a more practical option. All that’s required is to hollow out some areas to mount the servos, battery, and the avionics. This takes the form of a custom PCB that contains a ATSAMD21G18 microcontroller, an ICM-20948 inertial measurement unit (IMU), connections for GPS and LoRa modules, as well as several onboard sensors and some flash storage to hold collected data.

The goal of this open source project is to make these sort of unmanned aerial vehicles (UAVs) cheaper and more accessible for hobbyists and researchers. Eventually [Charlie] hopes to offer kits which will allow individuals to build and operate their own StratoSoar, making it even easier to get started. He’s currently working on the next iteration of the project that he’s calling StratoSoar MK3, but it hasn’t had a flight test yet.

We’ve seen various attempts to launch autonomous gliders from balloons in the past, but none from anyone as young as [Charlie]. We’re eager to see the StratoSoar project develop, and wish him luck in future test flights.

youtube.com/embed/TiqkcGWG4g8?…


hackaday.com/2024/09/23/strato…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Tempeste di Rumere su Internet! La stringa “LOVE” confonde le connessioni dei grandi provider di rete
poliverso.org/display/0477a01e…
Tempeste di Rumere su Internet! La stringa “LOVE” confonde le connessioni dei grandi provider di reteGli specialisti di GreyNoise hanno riferito greynoise.io/blog/greynoise-re… che da gennaio 2020 stanno osservando grandi ondate di “tempeste di rumore” che contengono traffico Internet distorto. Nonostante un’attenta analisi e


Tempeste di Rumere su Internet! La stringa “LOVE” confonde le connessioni dei grandi provider di rete


Gli specialisti di GreyNoise hanno riferito che da gennaio 2020 stanno osservando grandi ondate di “tempeste di rumore” che contengono traffico Internet distorto. Nonostante un’attenta analisi e anni di osservazione, i ricercatori non sono stati in grado di stabilire l’origine e lo scopo di questi “rumori”.

Gli analisti ritengono che i “rumori” possano essere associati ad alcune comunicazioni segrete, segnali per il coordinamento di attacchi DDoS, canali nascosti per il controllo di malware o in generale possano essere il risultato di impostazioni errate.

Un aspetto interessante di quanto sta accadendo è la presenza della stringa ASCII “LOVE” nei pacchetti ICMP osservati, che confonde ulteriormente la situazione.

GreyNoise ha pubblicato le sue ipotesi sulle “tempeste di rumore” nella speranza che la comunità globale di specialisti della sicurezza informatica aiuti a risolvere questo mistero e a scoprire la causa delle anomalie del traffico.

I ricercatori hanno affermato di aver riscontrato ondate di traffico Internet falso proveniente da milioni di indirizzi IP falsificati da una varietà di fonti, inclusi i CDN delle piattaforme cinesi QQ, WeChat e WePay.

Queste tempeste generano grandi ondate di traffico che prendono di mira fornitori specifici (come Cogent, Lumen e Hurricane Electric) evitandone altri, come Amazon Web Services (AWS).

La maggior parte di questo traffico è focalizzata su connessioni TCP (specialmente sulla porta 443), ma recentemente abbiamo visto anche molti pacchetti ICMP contenenti la stringa ASCII incorporata “LOVE”, come mostrato nello screenshot qui sotto.

Si noti inoltre che parametri come la dimensione della finestra vengono modificati nel traffico TCP per emulare diversi sistemi operativi, il che rende questa attività più invisibile e difficile da rilevare.

I valori Time to Live (TTL), che determinano per quanto tempo un pacchetto rimane sulla rete prima di essere scartato, sono impostati su un intervallo compreso tra 120 e 200 per simulare i salti di rete reali.

I ricercatori affermano che, nel complesso, il formato e le caratteristiche di queste “tempeste di rumore” sembrano più il lavoro deliberato di una persona competente, piuttosto che effetti collaterali su larga scala derivanti da configurazioni errate. Cioè, il traffico strano imita i normali flussi di dati e il suo vero scopo rimane ancora un mistero.

Gli analisti di GreyNoise hanno già pubblicato i dati PCAP di due recenti “tempeste di rumore” su GitHub , invitando altri ricercatori sulla sicurezza informatica a unirsi all’indagine e condividere le loro opinioni su ciò che sta accadendo.

Gli esperti di GreyNoise hanno anche pubblicato un resoconto dettagliato delle loro scoperte sulle “tempeste di rumore” su YouTube.

L'articolo Tempeste di Rumere su Internet! La stringa “LOVE” confonde le connessioni dei grandi provider di rete proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

RHC Intervista Lynx Ransomware. La cyber-gang che offre servizi di Pentest assicurando la Privacy
poliverso.org/display/0477a01e…
RHC Intervista Lynx Ransomware. La cyber-gang che offre servizi di Pentest assicurando la PrivacyLynx redhotcyber.com/post/il-ransom… ha fatto irruzione nel mondo del crimine digitale nel Luglio 2024 e fin da subito ha dimostrato una aggressività e successo negli attacchi superiore alla media con un totale di 22 vittime presenti sul


RHC Intervista Lynx Ransomware. La cyber-gang che offre servizi di Pentest assicurando la Privacy


Lynx Ransomware ha fatto irruzione nel mondo del crimine digitale nel Luglio 2024 e fin da subito ha dimostrato una aggressività e successo negli attacchi superiore alla media con un totale di 22 vittime presenti sul loro Data Leak Site (disponibile anche nel clearnet).

Le categorie vittime di Lynx sono principalmente Costruzioni (ex:/ Miller Boskus Lack Architects e True Blue Environmental), Finanza (ex:/ Pyle Group) ed Alberghiero (ex:/ Warwick Hotels and Resorts e
Riverside Resort Hotel and Casino). Lynx esegue tecniche di doppia estorsione ed una alta frequenza di attacchi in USA ma anche UK, Canada ed Australia.

Il gruppo descrive le proprie attività come esclusivamente “financial motivated” e una policy che non permette attacchi contro strutture critiche, governative ed ospedaliere. Interessante come presentano al pubblico il loro modello operazionale “basato sulla collaborazione e dialogo disincentivando caos e distruzione”.

Nel Ransomware Report H1 2024 di DarkLab abbiamo evidenziato come i “rookies” si stiano inserendo nell’ecosistema ransomware nonostante la capitalizzazione della top 5. Lynx si prospetta essere una new entry preparata e designata a restare sul medio/lungo termine. La densità di attacchi pertuata fin dai primi giorni dalla nascita di Lynx promettono grandi evoluzioni per il futuro del gruppo.

Lo sguardo del gatto delle foreste


Il gruppo di DarkLab è riuscito a comunicare con Lynx che ha accettato di rispondere alle domande poste dalla redazione. Ringraziamo lo staff del RaaS per aver sacrificato il loro tempo per offrire ai nostri lettori informazioni dirette riguardo a Lynx e le loro prospettive presenti e future.

RHC: Grazie Lynx per averci concesso la possibilità di questa intervista. Se potete presentarvi al nostro pubblico spiegando cosa svolgete e perché avete deciso di lavorare in questo settore.

Lynx: Il nostro team è composto da appassionati di cybersecurity. Come abbiamo osservato, molte aziende, sia grandi che piccole, non danno la priorità ai loro sforzi di cybersecurity in modo adeguato. Inoltre, quelle che lo fanno spesso cadono preda di promesse ingannevoli da parte di società di recupero e di cybersicurezza, con un impatto sulla loro posizione di sicurezza complessiva. Sebbene la nostra motivazione includa un aspetto finanziario, siamo ugualmente spinti dal desiderio di aumentare la consapevolezza della fragilità della sicurezza informatica su scala globale. È essenziale che il grande pubblico comprenda e riconosca queste vulnerabilità e prenda provvedimenti significativi.
Vogliamo sottolineare che siamo impegnati a evitare qualsiasi impatto negativo sulle infrastrutture critiche. Il nostro obiettivo è solo quello di far luce sulle sfide pervasive della sicurezza informatica e di incoraggiare misure proattive in tutti i settori.

RHC: Il gruppo Lynx è una nuova stella nascente nell’ambiente RaaS. Nonostante sia una new entry, il vostro gruppo si rivolge ad aziende di diversi settori. Perché avete fondato il gruppo e quale è il segreto per essere così bravi fin dall’inizio?

Lynx: Il nostro team dimostra costantemente un alto livello di competenza e dedizione, che aumenta significativamente l’impatto dei nostri gruppi.

RHC: Attualmente, quali sono le maggiori sfide per lo sviluppo di codice ransomware?

Lynx: L’evasione degli Antivirus

RHC: Il vostro codice di condotta è chiaro: “evitare danni indebiti alle organizzazioni” ed evitare infrastrutture critiche/servizi sanitari. Come attenuate i potenziali operatori disonesti che utilizzano il vostro prodotto su vittime proibite? Avete un processo di selezione?

Lynx: Il nostro approccio prevede un attento processo di selezione, che assicura che vengano ingaggiati solo i target approvati. Questo metodo ci permette di mantenere uno standard elevato nelle nostre operazioni e di raggiungere i nostri obiettivi in modo efficace.

RHC: Il vostro modello operativo “incoraggia il dialogo e la risoluzione piuttosto che il caos e la distruzione”, qual è il vostro approccio alla negoziazione con le vittime?

Lynx: Il nostro obiettivo è lavorare per raggiungere un consenso reciprocamente vantaggioso che non solo ci porti un guadagno economico, ma che rafforzi anche la sicurezza informatica dell’azienda. Ci impegniamo a promuovere un dialogo positivo e costruttivo per un vantaggio reciproco.

RHC: Il vostro lavoro comporta un rischio elevato e una posta in gioco alta: come fa Lynx a seguire le attività ransomware e a rimanere al sicuro? Vale la pena rischiare?

Lynx: Il nostro settore comporta sempre dei rischi intrinseci. Ne siamo tutti consapevoli quando scegliamo di far parte di questo settore. Anche se non possiamo eliminare del tutto i rischi, è essenziale adottare misure proattive per ridurli il più possibile.

RHC: Siete un gruppo uscito allo scoperto solo di recente, cosa pensate vi distingua dagli altri gruppi e vi permetta di affermarvi come i migliori?

Lynx: Non siamo gay.

RHC: Voi sostenete che i vostri obiettivi non sono le infrastrutture critiche, ma invece territorialmente ci sono paesi che non attaccherete o non avete confini?

Lynx: Non abbiamo confini o affiliazioni politiche, solo che alcuni Paesi hanno più soldi e sono più digitalizzati di altri.

RHC:A proposito di collaboratori, come siete organizzati? Avete molte persone che lavorano con voi? Com’è il processo di selezione di un candidato che vuole entrare in Lynx?

Lynx: Sono informazioni che non divulgheremo.

RHC: La rivalità all’interno della vostra comunità di hacker riguarda solo la superiorità tecnica o c’è qualcosa di più profondo, come ambizioni geopolitiche o economiche? In che modo la competizione tra gruppi influenza le vostre azioni e la scelta dei vostri obiettivi? Questa rivalità interna potrebbe avere il potenziale per spostare gli equilibri globali o creare nuove alleanze strategiche?

Lynx: Non abbiamo alcuna rivalità con altre organizzazioni; il nostro obiettivo principale è il guadagno monetario e la sensibilizzazione del pubblico su questioni cruciali di cybersicurezza.

RHC: Cosa direste per convincere nuovi potenziali collaboratori a unirsi al suo gruppo?

Lynx: Non stiamo cercando nuovi collaboratori.

RHC: Probabilmente sapete cosa è successo tra LockBit e l’Operazione Cronos, siete preoccupati che le forze dell’ordine si impegnino sempre di più per eliminare gruppi come il vostro? Avete visto qualche cambiamento/reazione dopo l’Operazione Cronos?

Lynx: Come sappiamo, ogni impresa nel nostro settore comporta alcuni rischi intrinseci. Tuttavia, ci impegniamo a fare tutto il possibile per ridurre questi rischi.

RHC: Qual è il vostro approccio all’accesso iniziale alla rete di vittime? Vi affidate a Creadential Broker (e simili) o preferite farlo da soli?

Lynx: Crediamo nell’utilizzo di entrambi gli approcci, poiché è utile avere a disposizione diverse strade. Questa diversità ci permette di migliorare la nostra efficacia e il nostro raggio d’azione.

RHC: Qual è la sua opinione su altri RaaS senza codice etico che attaccano infrastrutture critiche o strutture sanitarie?

Lynx: Esistono due tipi di gruppi. Sembra che alcuni gruppi abbiano provocato un notevole rumore e disturbo, perché ritengono che ciò aumenti le possibilità di pagamento. Mentre per altri gruppi tali azioni possono derivare da opzioni limitate nei loro obiettivi. In genere gli ospedali, le ONG e le agenzie governative hanno una sicurezza informatica più scarsa.

RHC: In base alla vostra esperienza, come viene implementata la sicurezza nelle reti aziendali? Su cosa dovrebbero concentrarsi i professionisti per migliorare lo stato dell’arte?

Lynx: I problemi derivano principalmente dall’errore umano quando si parla di sicurezza informatica. Questi problemi spesso derivano da semplici abitudini, come l’utilizzo di password facili da indovinare, la mancata implementazione dell’autenticazione a due fattori (2FA) e la gestione di più account con la stessa password (password reuse). Sebbene queste possano sembrare comode scorciatoie, possono compromettere in modo significativo la nostra sicurezza.

RHC: Hai mai fallito uno dei tuoi attacchi? Qual è stato il punto di fallimento?

Lynx: Ogni fase di un attacco contiene potenziali punti di fallimento. Come sappiamo entrambi, qualsiasi comportamento insolito in una rete può essere rilevato in qualsiasi fase, il che rende essenziale agire con rapidità e discrezione. Affrontando le situazioni con rapidità e furtività, possiamo ridurre al minimo le possibilità di rilevamento e, in ultima analisi, migliorare il nostro successo complessivo.

RHC: Lynx, grazie mille per il tuo tempo! C’è qualcosa che vorresti dire e che non ti abbiamo chiesto?

Lynx: Stiamo progettando di offrire un servizio in abbonamento che permetta ai clienti di richiedere test di penetrazione per le loro reti, il tutto assicurando privacy e garanzie di sicurezza. Abbiamo stabilito connessioni con i gruppi leader in questa linea di lavoro e siamo fiduciosi nella nostra capacità di fornire loro un alto livello di garanzia che nessuno di loro comprometterà la sicurezza della loro organizzazione. A differenza di molte società di recupero e di cybersecurity che applicano tariffe significative ma spesso forniscono servizi inadeguati, il nostro approccio è sia economico che diretto, consentendo alle aziende di mitigare in modo proattivo i rischi potenziali.

L'articolo RHC Intervista Lynx Ransomware. La cyber-gang che offre servizi di Pentest assicurando la Privacy proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Vulneravilità 0-Click RCE nei Chipset Wi-Fi MediaTek. Aggiornare subito!
poliverso.org/display/0477a01e…
Vulneravilità 0-Click RCE nei Chipset Wi-Fi MediaTek. Aggiornare subito!Di recente è stata scoperta una vulnerabilità redhotcyber.com/post/vulnerabi… critica nei chipset Wi-Fi MediaTek, comunemente utilizzati nelle piattaforme embedded che supportano Wi-Fi 6 (802.11ax). La vulnerabilità redhotcyber.com/post/vulnerabi… consente agli aggressori di lanciare


Vulneravilità 0-Click RCE nei Chipset Wi-Fi MediaTek. Aggiornare subito!


Di recente è stata scoperta una vulnerabilità critica nei chipset Wi-Fi MediaTek, comunemente utilizzati nelle piattaforme embedded che supportano Wi-Fi 6 (802.11ax). La vulnerabilità consente agli aggressori di lanciare attacchi di esecuzione di codice remoto (RCE) senza alcuna interazione da parte dell’utente.

Questa vulnerabilità 0-Click CVE-2024-20017 classificata con un punteggio CVSS di 9,8, consente l’esecuzione di codice remoto (RCE) su una vasta gamma di telefoni e punti di accesso Wi-Fi di vari OEM. La vulnerabilità CVE-2024-20017 risiede nel demone di rete wappd, un componente critico del bundle di driver MediaTek MT7622/MT7915 SDK e RTxxxx SoftAP. I chipset Wi-Fi e i bundle di driver MediaTek sono utilizzati nei router e negli smartphone di vari produttori, tra cui Ubiquiti, Xiaomi e Netgear.

La vulnerabilità interessa una gamma di chipset MediaTek, tra cui MT6890, MT7915, MT7916, MT7981, MT7986 e MT7622. Il problema riguarda le versioni 7.4.0.1 e precedenti di MediaTek SDK, nonché OpenWrt 19.07 e 21.02.

Secondo i ricercatori di SonicWall Capture Labs, che hanno scoperato la falla (CVE-2024-20017, CVSS 9.8), lo sfruttamento della vulnerabilità aprirebbe la strada consentendo potenzialmente agli aggressori di eseguire codice remoto (RCE) senza nessuna interazione dell’utente, rendendo il bug un canale per una facile acquisizione del dispositivo.

Aggrava ulteriormente la situzione, la recente disponibilità di un exploit proof-of-concept pubblico (PoC) disponibile su GitHub.

La scoperta di questa vulnerabilità CVE-2024-20017 ci ricorda quanto sia importante la protezione dei propri sistemi e quanto sia fondamentale l’identificazione e risoluzione di potenziali falle si sicurezza.

MediaTek ha corretto questa falla a Marzo, quindi il primo passo da compiere per prevenire potenziali compromissioni, è assicurarsi che tutti i dispositivi interessati siano stati aggiornati all’ultima versione Firmware.

L'articolo Vulneravilità 0-Click RCE nei Chipset Wi-Fi MediaTek. Aggiornare subito! proviene da il blog della sicurezza informatica.


The Privacy Post ha ricondiviso questo.

Partecipa alla Conferenza Nazionale GDPR Day 2024: l’evento di riferimento sulla Data Protection, il 23 e 24 Ottobre a Bologna
poliverso.org/display/0477a01e…
Partecipa alla Conferenza Nazionale GDPR Day 2024: l’evento di riferimento sulla Data Protection, il 23 e 24 Ottobre a BolognaLa Conferenza nazionale GDPR Day 2024, evento leader in Italia sulla protezione dei dati, si terrà il 24 ottobre al Grand Tour Italia, ex-FICO Eataly World di Bologna. La


Partecipa alla Conferenza Nazionale GDPR Day 2024: l’evento di riferimento sulla Data Protection, il 23 e 24 Ottobre a Bologna


La Conferenza nazionale GDPR Day 2024, evento leader in Italia sulla protezione dei dati, si terrà il 24 ottobre al Grand Tour Italia, ex-FICO Eataly World di Bologna. La conferenza sarà preceduta da una cena di networking il 23 ottobre, occasione unica per connettersi con i principali esperti del settore.

Programma 2024: tematiche di avanguardia e networking strategico


Come ogni anno, anche l’edizione 2024 offrirà un’Agenda ricca di interventi e panel di alto livello, intervallati da tanti momenti di networking, pause strategiche utili per conoscere gli Speaker e gli altri partecipanti. Saranno affrontate le tematiche più rilevanti e innovative nel campo della protezione dei dati, quindi anche la Privacy e la Cyber Security, oltre che tanti altri temi correlati. Ecco di seguito alcuni degli interventi di maggior rilievo:

  • Intervento del Garante Privacy, Guido Scorza
  • DGA, DSA, DMA: verso la costituzione digitale europea e la UE come Stato digitale di diritto, Prof. Francesco Pizzetti
  • Il Futuro della data protection: come AI, blockchain e web 3.0 cambieranno il trattamento dei dati personali, Avv. Marco Tullio Giordano
  • GDPR e intelligenza artificiale: il rapporto tra dati personali e intelligenza artificiale, Prof.ssa Giusella Dolores Finocchiaro
  • Intervento della Guardia di Finanza, Lgt. CS. Pierluca Toselli
  • NIS2 e il potenziale punto di svolta: normativa e tecnologia o tecnologia e normativa? Sebastian Zdrojewski, Cybersecurity Advisor.
  • Laboratorio Privacy: esecuzione di una DPIA, Prof. Avv. Monica Gobbato, Avv. Adriana Augenti, Avv. Marco Cuniberti
  • Valorizzazione dei dati nel business: norme e tecnologie che cambiano la visione del mondo, Avv. Luca Bolognini
  • Fare Impresa tra GDPR ed AI Act, Andrea Chiozzi, Founder di PrivacyLab
  • Privacy e sicurezza delle email personali, transazionali e di marketing, Luca Marras, Co-founder e CTO di Emailchef
  • AI: tutti ne parlano, pochi la conoscono, quasi nessuno la contrattualizza, Prof. Avv. Federica De Stefani
  • Oblio: quando la privacy incontra la reputazione, Avv. Piera Di Stefano
  • Data breach: come gestire un attacco ransomware, Avv. Vittoria Piretti e Avv. Benedetta Pinna


Accreditamenti e Formazione


Partecipare al GDPR Day 2024 significa accedere a un’importante opportunità di formazione con crediti riconosciuti:

  • TÜV Examination Institute: 8 crediti formativi per Privacy Officer e Consulenti della Privacy (CDP) e 8 ore formative per DPO e altri profili privacy (PRV).
  • Consiglio dell’Ordine degli Avvocati di Bologna: 6 crediti formativi per gli avvocati presenti, anche di altri ordini


L’area espositiva


Visita l’area espositiva per incontrare i team delle aziende Sponsor e scoprire soluzioni innovative e compliant con il GDPR. Tra i Top Sponsor Emaichef, piattaforma di e-mail marketing GDPR compliant, e PrivacyLab, leader nel supporto alla gestione dei dati personali. Privacy Evo, Platinum Sponsor, presenterà la sua piattaforma versatile per la gestione del GDPR.

Nella stessa area espositiva saranno presenti: Fred for Security, Exhibitor Sponsor, nonché i corner di associazioni come Privacy Academy e Adiconsum. La Guardia di Finanza parteciperà sia con un intervento che con un corner espositivo, che darà la preziosa opportunità al pubblico di conoscere da vicino la sua attività.

Endorsement e Patrocini


L’edizione 2024 ha ottenuto il patrocinio di rinomate associazioni e Istituzioni, tra cui la Regione Emilia-Romagna, Ordine degli Avvocati di Bologna, Privacy Academy, Assocompliance, Cyber Security Italy Foundation, Adiconsum, Istituto Italiano per la Privacy e la Valorizzazione dei Dati (IIP), CSIG Bologna (Centro Studi Informatica Giuridica), ONIF (Osservatorio Nazionale Informatica Forense), ANIPA, ClubTI Milano, Stati Generali dell’Innovazione e altre ancora. IusLaw Web Radio è Main Media Partner, mentre sono Media Partner testate specializzate come Red Hot Cyber, Risk & Compliance, Report Difesa, Zeroventiquattro e AreaNetworking.it.

L’impegno green


Gli organizzatori rinnovano il loro impegno verso la sostenibilità ambientale. Come per ogni edizione, il Programma sarà disponibile solo in digitale ed è incentivato il riuso degli allestimenti e del materiale pubblicitario. Da quest’anno, la Conferenza aderisce anche all’iniziativa #Plastic-freER ed Emilia-Romagna 2030, per cui non saranno utilizzati prodotti in plastica monouso durante i momenti di catering.

Inoltre, sarà presente una Tesla disponibile per un giro per titolari dei biglietti Premium, grazie ad Enerev, E-Mobility partner dell’evento.

Come partecipare


Non perdere l’opportunità di partecipare a un evento cruciale per il futuro della privacy e della protezione dei dati in Italia! Riserva il tuo posto e aggiungiti ai già tanti iscritti. Incontrerai tanti DPO, Privacy Officer, Avvocati, Responsabili Ufficio Legale, Marketing Manager, IT Consultant, Digital Solutions Architect, Security Manager, Titolari di aziende, Privacy Specialist, IT Manager, CTO, Responsabili Servizio Privacy, ICT Manager, Consulenti informatici, Consulenti Privacy.

Sono disponibili tre tipologie di biglietto, Standard, Business e Premium, per poter scegliere il tipo di partecipazione più adatto alle proprie esigenze. Attualmente tutti i biglietti sono scontati del 30%, sconto che progressivamente diminuirà.

Per acquistare il biglietto: www.gdprday.it/registrazione

L'articolo Partecipa alla Conferenza Nazionale GDPR Day 2024: l’evento di riferimento sulla Data Protection, il 23 e 24 Ottobre a Bologna proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Hands-on With New iPhone’s Electrically-Released Adhesive
poliverso.org/display/0477a01e…
Hands-on With New iPhone’s Electrically-Released AdhesiveThere’s a wild new feature making repair jobs easier (not to mention less messy) and iFixit covers it in their roundup of the iPhone 16’s repairability: electrically-released adhesive ifixit.com/News/100352/we-hot-….Here’s how it works. The adhesive looks like a curved strip with what appears to be a thin film of


Hands-on With New iPhone’s Electrically-Released Adhesive


There’s a wild new feature making repair jobs easier (not to mention less messy) and iFixit covers it in their roundup of the iPhone 16’s repairability: electrically-released adhesive.

Here’s how it works. The adhesive looks like a curved strip with what appears to be a thin film of aluminum embedded into it. It’s applied much like any other adhesive strip: peel away the film, and press it between whatever two things it needs to stick. But to release it, that’s where the magic happens. One applies a voltage (a 9 V battery will do the job) between the aluminum frame of the phone and a special tab on the battery. In about a minute the battery will come away with no force, and residue-free.

There is one catch: make sure the polarity is correct! The adhesive releases because applying voltage oxidizes aluminum a small amount, causing Al3+ to migrate into the adhesive and debond it. One wants the adhesive debonded from the phone’s frame (negative) and left on the battery. Flipping the polarity will debond the adhesive the wrong way around, leaving the adhesive on the phone instead.

Some months ago we shared that Apple was likely going to go in this direction but it’s great to see some hands-on and see it in action. This adhesive does seem to match electrical debonding offered by a company called Tesa, and there’s a research paper describing it.

A video embedded below goes through the iPhone 16’s repairability innovations, but if you’d like to skip straight to the nifty new battery adhesive, that starts at the 2:36 mark.

youtube.com/embed/M6jBXI6CR9s?…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The Tiny Toolkit Manifesto
poliverso.org/display/0477a01e…
The Tiny Toolkit ManifestoMost of us have some form of an on-the-go toolkit, but how much thought have we put into its contents? there’s a community of people who put a lot of thought into this, and EMF Camp have put up one of their talks from earlier in the summer in which [Drew Batchelor] sets out their manifesto media.ccc.de/v/emf2024-265-the… and introduces tinytoolk.it/, a fascinating resour


The Tiny Toolkit Manifesto


Most of us have some form of an on-the-go toolkit, but how much thought have we put into its contents? \there’s a community of people who put a lot of thought into this, and EMF Camp have put up one of their talks from earlier in the summer in which [Drew Batchelor] sets out their manifesto and introduces tinytoolk.it, a fascinating resource.

The talk is well worth a watch, as rather than setting the tools you should be carrying, it instead examines the motivations for your kit in the firs place, and how to cull those which don’t make the grade. If an items seems to see little use, put a piece of tape with the date on it every time it comes out, to put a number on it. As an example he ended up culling a multi-tool from his kit, not because it’s not an extremely useful tool, but because he found everything it did was better done by other items in the kit.

It’s probable we’ll all look at our carry-around kit with new eyes after watching this, it’s certain that ours could use a few tweaks. What’s in your kit, and how could you improve it? Let us know in the comments.

media.ccc.de/v/emf2024-265-the…


hackaday.com/2024/09/22/the-ti…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

3D Printing a Wire-Wrap Tool: Emergency Fix or Permanent Solution?
poliverso.org/display/0477a01e…
3D Printing a Wire-Wrap Tool: Emergency Fix or Permanent Solution?Although less popular these days, wire-wrap is still a very relevant, easily reversible solder-free way to assemble (prototype) systems using wire-wrap wire and a wire-wrap tool. This latter tool can be either a hand or powered tool, but all it has to do is retain the stripped wire, fit around the


3D Printing a Wire-Wrap Tool: Emergency Fix or Permanent Solution?


Completed wire-wrap connection with WSU-30M tool. (Credit: Sparkfun)

Although less popular these days, wire-wrap is still a very relevant, easily reversible solder-free way to assemble (prototype) systems using wire-wrap wire and a wire-wrap tool. This latter tool can be either a hand or powered tool, but all it has to do is retain the stripped wire, fit around the wire-wrapping post and create a snug, oxidation-proof metal-metal contact fit. For the very common 30 AWG (0.25 mm) wire-wrap wire, the Jonard Tools (OK Industries) WSU-30M wire-strip-unwrap tool is pretty much the popular standard. It allows you to strip off insulation, wrap and unwrap connections all with one tool, but the question is whether you can just 3D print a wrap-unwrap tool that’s about as good?

First a note about cost, as although the genuine WSU-30M has risen in cost over the years, it can still be obtained for around $50 from retails like Mouser, while clones of varying quality can be obtained for around $15 from your favorite e-tailer website. From experience, these clones have quite sloppy tolerance, and provide a baseline of where a wrapping tool becomes unusable, as they require some modding to be reliable.

Wire-wrap tool model by [KidSwidden] on Thingiverse.Taking a quick look at the wire-wrap tools available on Thingiverrse, we can see basically two categories: one which goes for minimally viable, with just a cylinder that has a hole poked on the side for the stripped wire to fit through, as these versions by [JLSA_Portfolio], [paulgeneres], [orionids] and [cmellano]. The WSU-30M and similar tools have a channel on the side that the stripped wire is fed into, to prevent it from getting tangled up and snagging. On the clone units this channel often has to be taped off to prevent the wire from escaping and demonstrating why retaining the wire prior to wrapping is a good idea.

This leads us to three examples of a 3D printed wire-wrap tool with such a wire channel: by [KidSwidden] (based on a Radio Shack unit, apparently), another by [DieKatzchen] and an interesting variation by [4sStylZ]. Naturally, the problem with such fine features is that tolerance matter a lot, with an 0.2 mm nozzle (for FDM printers) recommended, and the use of an SLA printer probably a good idea. It’s also hard to say what kind of wire-wrap connection you are going to get, as there are actually two variants: regular and modified.

The starting guide to wire-wrapping by Sparkfun uses the WSU-30M, which as the name suggests uses modified wire-wrap, which means that part of the wire insulation is wrapped around the bottom of the post, for extra mechanical stability, effectively like strain-relief. A lot of such essential details are covered in this [Nuts and Volts] article which provides an invaluable starting guide to wire-wrapping, including detecting bad wraps.

Naturally, the 3D printed tools will not include a stripper for the wire insulation, so you will have to provide this yourself (PSA: using your teeth is not recommended), and none of these 3D models include an unwrap tool, which may or may not be an issue for you, as careful unwrapping allows you to reuse the wire, which can be useful while debugging or reworking a board.

Top image: completed wire-wrap on a post. (Credit: Sparkfun)


hackaday.com/2024/09/22/3d-pri…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Hackaday Links: September 22, 2024
poliverso.org/display/0477a01e…
Hackaday Links: September 22, 2024Thanks a lot, Elon. Or maybe not, depending on how this report tomshardware.com/tech-industry… that China used Starlink signals to detect low-observable targets pans out. There aren’t a lot of details, and we couldn’t find anything approximating a primary source, but it seems like the idea is based on forward scatter, which is when waves striking an object are


Hackaday Links: September 22, 2024


Hackaday Links Column Banner

Thanks a lot, Elon. Or maybe not, depending on how this report that China used Starlink signals to detect low-observable targets pans out. There aren’t a lot of details, and we couldn’t find anything approximating a primary source, but it seems like the idea is based on forward scatter, which is when waves striking an object are deflected only a little bit. The test setup for this experiment was a ground-based receiver listening to the downlink signal from a Starlink satellite while a DJI Phantom 4 Pro drone was flown into the signal path. The drone was chosen because nobody had a spare F-22 or F-35 lying around, and its radar cross-section is about that of one of these stealth fighters. They claim that this passive detection method was able to make out details about the drone, but as with most reporting these days, this needs to be taken with an ample pinch of salt. Still, it’s an interesting development that may change things up in the stealth superiority field.

Another week, another example of how the fine print on the EULA is never your friend. This time around it’s the popular Wyze security cameras, where there’s an unconfirmed report that a recent firmware update nerfed the “Recording Cooldown” setting menu, making the option to have no cooldown period between recording a paid feature. As we understand it, Wyze cameras previously had a cooldown feature, intended to keep the camera from overheating or killing the battery if the motion sensor detects a lot of continual movement. But it looks like earlier firmware revs allowed users to bypass the default five-minute period between recordings, a reasonable choice for anyone using these as security cameras. Now, bypassing the cooldown seems to require a paid subscription. We have to stress that we don’t know anything beyond this one unconfirmed report, but this enshittification is certainly something we’ve seen before, so it at least rings true, and it seems like another solid example of the fact that with cheap IoT appliances, you never truly own your stuff.

We hate to be the bearers of bad news — well, that might be a stretch given the two articles above — but this is really the kind of news we hate to hear. The Eugene Makerspace in Eugene, Oregon, suffered a major fire in their community shop on September 15. Judging by the pictures, the place was pretty thoroughly destroyed, and the fact that it was an early morning fire probably contributed to the lack of injuries. Their GoFundMe campaign is doing pretty well, but they could certainly use some help getting back on their feet. If you’re in a position to contribute, we’re sure they’d appreciate it.

When it comes to OpenAI’s newest AI model, you’d better watch what you think — or rather, you’d better not think too much about how the model thinks. Trying to get inside the model’s “head” is apparently against the terms of service, with users getting nastygrams from OpenAI warning them to step off. The “Strawberry” AI model has a feature that lets users have a glimpse into the “chain of thought” used to answer a question or complete a task, which on the face of it seems to be exactly what they don’t want users to do. But the chain of thought is only a hand-waving summary of the raw thought process, filtered through a separate AI model. This is what OpenAI doesn’t want people probing, and any attempts at engineering tricky prompts to reveal the raw chain of thought will potentially get you banned.

And finally, although motorsports aren’t really our thing, we have to admit a certain sense of awe at this video that exposes some of the extreme engineering that goes into top fuel drag racing. Specifically, this video concentrates on drag racing, where nitromethane-fueled engines-on-wheels scream down a quarter-mile track in less than four seconds. Everything about this sport is extreme, especially the engines, which run themselves almost to death for the few seconds they are under full power. The video is packed full of tidbits that boggle the mind, such as these engines burning out their sparkplugs about halfway through the course, with the engine continuing to run in diesel mode thanks to the high compression and temperatures. Drivers experience a brain-squishing 8 g of acceleration during a run, which consumes over 30 gallons of fuel and exerts so much force on the engine that the connecting rods get compressed. The supercharger alone takes 800 horsepower to run, and yet the engine still produces enough power that the car is going 60 miles per hour before it covers its own length. Oh, and that ridiculous exhaust plume? That’s raw fuel that is purposely left unburned until it escapes the exhaust tips, which are angled to provide additional down-force to make sure as much torque as possible gets from the tires to the track. Enjoy!

youtube.com/embed/GHZGPppf8Uw?…


hackaday.com/2024/09/22/hackad…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Nuovo Data Breach Uber Eats in Meno di un Anno: Esposti 283.000 Ordini su BreachForums
poliverso.org/display/0477a01e…
Nuovo Data Breach Uber Eats in Meno di un Anno: Esposti 283.000 Ordini su BreachForumsRecentemente, Uber Eats, una delle principali piattaforme di food delivery a livello globale, è stata vittima di un nuovo presunto data breach. Un membro di BreachForums, con l’alias “888”, ha pubblicato una nuova violazione dei dati che ha esposto circa


Nuovo Data Breach Uber Eats in Meno di un Anno: Esposti 283.000 Ordini su BreachForums


Recentemente, Uber Eats, una delle principali piattaforme di food delivery a livello globale, è stata vittima di un nuovo presunto data breach. Un membro di BreachForums, con l’alias “888”, ha pubblicato una nuova violazione dei dati che ha esposto circa 283.000 ordini. Le informazioni trapelate includono dettagli come numeri di riferimento, nomi dei negozi, ID degli ordini, costi di consegna e tasse. Questo data breach rappresenta un nuovo colpo per la piattaforma, che già nel novembre 2023 aveva subito un’altra violazione, in cui 1,4 milioni di record erano stati compromessi.

Al momento, non possiamo confermare la veridicità della notizia, poiché l’organizzazione non ha ancora rilasciato alcun comunicato stampa ufficiale sul proprio sito web riguardo l’incidente. Pertanto, questo articolo deve essere considerato come ‘fonte di intelligence’.

Post rinvenuto nel Dark Web

Secondo quanto pubblicato nel forum, i dati trafugati comprendono informazioni dettagliate sugli ordini effettuati su Uber Eats. Tra le informazioni divulgate figurano i nomi dei ristoranti, gli ID degli ordini, i provider di consegna, e i costi associati, come le spese di spedizione e le tasse pagate dai clienti. Un esempio di ordine trapelato riguarda il ristorante “Guy Fieri’s Flavortown Kitchen”, con dettagli come l’orario di consegna e l’importo totale dell’ordine. Anche se al momento non sono emerse informazioni personali come nomi o indirizzi degli utenti, l’entità e la natura dei dati trafugati destano preoccupazioni in termini di privacy e sicurezza.

Conclusioni


Al momento, Uber Eats non ha rilasciato dichiarazioni ufficiali riguardo al presunto attacco, rendendo difficile verificare la veridicità del breach. Tuttavia, la mancanza di conferme non riduce la gravità della situazione. Se confermata, questa violazione rappresenterebbe un rischio per i clienti, che potrebbero essere esposti a frodi o tentativi di phishing basati sui dati divulgati. Questo incidente, che segue il breach del 2023, evidenzia ancora una volta la necessità di misure di sicurezza più rigorose.

Come nostra consuetudine, lasciamo sempre spazio ad una dichiarazione da parte dell’azienda qualora voglia darci degli aggiornamenti sulla vicenda. Saremo lieti di pubblicare tali informazioni con uno specifico articolo dando risalto alla questione.

RHC monitorerà l’evoluzione della vicenda in modo da pubblicare ulteriori news sul blog, qualora ci fossero novità sostanziali. Qualora ci siano persone informate sui fatti che volessero fornire informazioni in modo anonimo possono utilizzare la mail crittografata del whistleblower.

L'articolo Nuovo Data Breach Uber Eats in Meno di un Anno: Esposti 283.000 Ordini su BreachForums proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Brass Propeller Gets Impressive Hand Trimming
poliverso.org/display/0477a01e…
Brass Propeller Gets Impressive Hand TrimmingWhether you’re a landlubber or an old salt, you’ve got to appreciate the effort that [The Aussie boat guy] puts into cutting an old brass propeller down youtube.com/watch?v=wCCUClvZhE… into a far smaller and sleeker specimen. Especially since he does the entire thing with hand tools, a couple different calipers, and that most valuable of


Brass Propeller Gets Impressive Hand Trimming


Whether you’re a landlubber or an old salt, you’ve got to appreciate the effort that [The Aussie boat guy] puts into cutting an old brass propeller down into a far smaller and sleeker specimen. Especially since he does the entire thing with hand tools, a couple different calipers, and that most valuable of natural resources: experience.

The whole process was made somewhat easier by the fact that [The Aussie boat guy] had a model to work from — his friend had a small propeller that was already known to perform well, it was just a matter of cutting the larger prop down to match its dimensions. Using what appears to be pieces of leather (presumably for its flexibility), a template was made to accurately map out the front face of the blade.
As Bob Ross would say — “Here comes your bravery test”
By measuring out from the hub of the prop with his calipers, [The Aussie boat guy] was able to make sure the template was properly positioned before scribing its shape into the larger prop. An angle grinder was used to cut the shape out of each blade, followed by a smoothing off with a flap wheel.

But there was still a problem — the blades were the right shape, but they were far too thick. So he took the angle grinder to the back of each one to start removing material, using another set of calipers to occasionally spot-check them to make sure they were thinning out at roughly the same rate.

This thinning out process continued until the prop was brought into balance. How do you check that, you might be wondering? Well, if you’re a madman like [The Aussie boat guy], you chuck the thing into a power drill and spin er’ up to see how badly it shakes. But this only gives you a rough idea, so he has to move over to a somewhat more scientific apparatus that uses a set of parallel bars to help determine which blade is heavier than its peers.

Along the way, [The Aussie boat guy] also installs a bushing in the hub of the prop to adapt it to his engine, but he doesn’t spend much time talking about that given the far more audacious surgery he’s performing. He takes the end result out for a test run and achieves a notable speed boost when compared to the prop he was running previously — the final product doesn’t just look incredible, it brings the results as well.

This would appear to be the first time we’ve come across [The Aussie boat guy], which looking at some of his past videos, is a bit surprising. His channel is full of engine and boat modifications made in the pursuit of speed; check it out if you’ve ever dreamed of screaming across the surface of the water in a boat not much larger than a bathtub.

youtube.com/embed/wCCUClvZhEA?…

Thanks to [Bill] for the tip.


hackaday.com/2024/09/22/brass-…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Robotic Touch Using a DIY Squishy Magnetic Pad
poliverso.org/display/0477a01e…
Robotic Touch Using a DIY Squishy Magnetic PadThere are a number of ways to give a robotic actuator a sense of touch, but the AnySkin any-skin.github.io/ project aims to make it an overall more reliable and practical process. The idea is twofold: create modular grippy “skins” that can be slipped onto actuators, and separate the sensing electronics from the skins themselves. The whole


Robotic Touch Using a DIY Squishy Magnetic Pad


There are a number of ways to give a robotic actuator a sense of touch, but the AnySkin project aims to make it an overall more reliable and practical process. The idea is twofold: create modular grippy “skins” that can be slipped onto actuators, and separate the sensing electronics from the skins themselves. The whole system ends up being quite small, as shown here.
Cast skins can be installed onto bases as easily as slipping a phone case onto a phone.
The skins are cast in whatever shape is called for by using silicone (using an off-the-shelf formulation from Smooth-on) mixed with iron particles. This skin is then slipped onto a base that contains the electronics, but first it is magnetized with a pulse magnetizer. It’s the magnetic field that is at the heart of how the system works.

The base contains five MLX90393 triple-axis magnetometers, each capable of sensing tiny changes in magnetic fields. When the magnetized skin over the base is deformed — no matter how slightly — its magnetic field changes in distinct ways that paint an impressively detailed picture of exactly what is happening at the sensor. As a bonus, slippage of the skin against the sensor (a kind of shearing) can also be distinctly detected with a high degree of accuracy.

The result is a durable and swappable robotic skin that can be cast in whatever shape is needed, itself contains no electronics, and can even be changed without needing to re-calibrate everything. Cameras can also sense touch with a high degree of accuracy, but camera-based sensors put constraints on the size and shape of the end result.

AnySkin builds on another project called ReSkin and in fact uses the same sensor PCB (design files and bill of materials available here) but provides a streamlined process to create swappable skins, and has pre-made models for a variety of different robot arms.


hackaday.com/2024/09/22/__tras…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

New note by cybersecurity
poliverso.org/display/0477a01e…
Guerre di Rete - Cercapersone esplosi: una ricostruzione guerredirete.substack.com/p/gu…@Informatica (Italy e non Italy 😁)Una prima provvisoria cronaca/analisi di quanto avvenuto in Libano.#GuerreDiRete è la newsletter curata da @Carola Fredianiguerredirete.substack.com/p/gu…

The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

“Basta incolpare gli utenti degli attacchi informatici!”. Lo riporta il capo del CISA Jen Easterly
poliverso.org/display/0477a01e…
“Basta incolpare gli utenti degli attacchi informatici!”. Lo riporta il capo del CISA Jen EasterlyGli sviluppatori di software che rilasciano prodotti con vulnerabilità redhotcyber.com/post/vulnerabi… sono i veri colpevoli di tutti gli attacchi informatici. Almeno questo è quello che ha detto Jen Easterly,


“Basta incolpare gli utenti degli attacchi informatici!”. Lo riporta il capo del CISA Jen Easterly


Gli sviluppatori di software che rilasciano prodotti con vulnerabilità sono i veri colpevoli di tutti gli attacchi informatici. Almeno questo è quello che ha detto Jen Easterly, capo della Cybersecurity and Infrastructure Security Agency ( CISA ) degli Stati Uniti, alla recente conferenza mWise.

Easterly ha invitato le aziende tecnologiche a smettere di rilasciare codici con difetti che aprono le porte ai criminali informatici. Ha sottolineato che sono i fornitori di tecnologia a creare i problemi che gli aggressori sfruttano con successo per attaccare le loro vittime.

Ha inoltre osservato che le falle nella sicurezza del software non dovrebbero essere chiamate “vulnerabilità”, ma “difetti del prodotto”, che riflette più accuratamente la responsabilità degli sviluppatori. A suo avviso, l’industria dovrebbe smettere di attribuire la colpa agli utenti che non hanno il tempo di installare gli aggiornamenti in modo tempestivo e iniziare a richiedere agli sviluppatori prodotti migliori che non richiedano costanti “patch mission-critical”.

Easterly ha osservato che, nonostante i miliardi investiti nella sicurezza informatica, il problema principale risiede nella scarsa qualità del software. Ha paragonato la situazione alle automobili e agli aerei, che nessuno comprerebbe se venissero utilizzati “a proprio rischio”, come spesso accade con i software.

Intervenendo in precedenza alla conferenza RSA, Easterly ha affermato che un codice forte è l’unico modo per rendere rari gli attacchi informatici. Alla conferenza mWise, ha ribadito che il settore della sicurezza informatica dovrebbe concentrarsi sulla creazione di prodotti sicuri piuttosto che sull’aumento del numero di controlli di sicurezza.

Attualmente , circa 200 importanti attori del mercato, tra cui Amazon, Microsoft e Google, hanno aderito all’iniziativa CISA “Secure by Design”, che prevede l’impegno delle aziende a migliorare la sicurezza dei prodotti. Tuttavia, Easterly ha sottolineato che per ora si tratta solo di un impegno volontario e ha esortato i clienti a utilizzare il proprio potere d’acquisto per esigere che i fornitori rispettino questi standard.

Infine, il capo della CISA ha invitato le organizzazioni ad assumere un ruolo più proattivo ponendo le giuste domande ai fornitori e richiedendo maggiore attenzione alla sicurezza in tutte le fasi dello sviluppo del software.

L'articolo “Basta incolpare gli utenti degli attacchi informatici!”. Lo riporta il capo del CISA Jen Easterly proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Operazione FBI: Svelata la Botnet Cinese Flax Typhoon che Controllava il Mondo IoT
poliverso.org/display/0477a01e…
Operazione FBI: Svelata la Botnet Cinese Flax Typhoon che Controllava il Mondo IoTGli Stati Uniti hanno scoperto e smantellato una campagna redhotcyber.com/post/come-funz… orchestrata da redhotcyber.com/post/i-padri-f… cinesi, progettata per infiltrarsi nelle infrastrutture statunitensi e in vari dispositivi connessi a Internet.Il direttore


Operazione FBI: Svelata la Botnet Cinese Flax Typhoon che Controllava il Mondo IoT


Gli Stati Uniti hanno scoperto e smantellato una campagna botnet orchestrata da hacker cinesi, progettata per infiltrarsi nelle infrastrutture statunitensi e in vari dispositivi connessi a Internet.

Il direttore dell’FBI, Christopher Wray, ha annunciato l’operazione, chiamata “Flax Typhoon”, durante il Cyber Summit di Washington il 18 settembre. Ha affermato che questa campagna fa parte di un’iniziativa più ampia guidata da Pechino.

La minaccia del Flax Typhoon


“Flax Typhoon ha preso il controllo di dispositivi IoT come telecamere, videoregistratori e dispositivi di archiviazione comunemente utilizzati in grandi e piccole organizzazioni”, ha dichiarato Wray. “Circa la metà di questi dispositivi compromessi si trovano negli Stati Uniti.”

Gli hacker, fingendosi parte della società di sicurezza informatica Integrity Technology Group, hanno raccolto dati da aziende, media, università e agenzie governative. Hanno sfruttato centinaia di migliaia di dispositivi connessi a Internet per creare una botnet, utilizzata per compromettere sistemi e sottrarre dati sensibili.

La scorsa settimana, in collaborazione con gli alleati, l’FBI ha preso il controllo della botnet su ordine del tribunale, interrompendo le attività di Flax Typhoon. Gli hacker hanno tentato di migrare ai sistemi di backup, ma di fronte alla reazione delle forze dell’ordine, hanno distrutto la nuova infrastruttura e abbandonato la botnet.

“Pensiamo che gli autori si stiano rendendo conto che l’FBI e i nostri partner non lasceranno loro scampo”, ha affermato Wray.

Legami con il gruppo Volt Typhoon


Flax Typhoon sembra avere legami con un altro gruppo di hacker cinesi, Volt Typhoon, scoperto da Microsoft nel maggio dello scorso anno. Questo gruppo ha utilizzato apparecchiature di rete per penetrare e compromettere infrastrutture, incluso il sistema di comunicazioni di Guam, un’importante base militare statunitense.

L’ambasciata cinese a Washington ha negato le accuse statunitensi. “Senza prove valide, gli Stati Uniti hanno tratto conclusioni frettolose e avanzato accuse infondate”, ha dichiarato Liu Pengyu, portavoce dell’ambasciata, in un’email inviata a VOA. “Gli Stati Uniti stessi sono la fonte principale di attacchi informatici globali.”

A seguito dell’annuncio dell’FBI, la National Security Agency (NSA) ha emesso un avviso esortando le organizzazioni a applicare patch sui dispositivi compromessi. Secondo la NSA, la botnet utilizzava oltre 260.000 dispositivi in Nord America, Europa, Africa e Sud-Est asiatico fino a giugno di quest’anno.

L'articolo Operazione FBI: Svelata la Botnet Cinese Flax Typhoon che Controllava il Mondo IoT proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Hackfest, A New Event For Your European Calendar
poliverso.org/display/0477a01e…
Hackfest, A New Event For Your European CalendarOur community’s events are something special, bringing as they do an opportunity to meet and mingle with other hackers whether their field be hardware, software, or security, to share ideas, and to see some very cool projects. Here at Hackaday aside from our own Supercon and Hackaday Europe events we try to take in as many as we can


Hackfest, A New Event For Your European Calendar


Our community’s events are something special, bringing as they do an opportunity to meet and mingle with other hackers whether their field be hardware, software, or security, to share ideas, and to see some very cool projects. Here at Hackaday aside from our own Supercon and Hackaday Europe events we try to take in as many as we can over the year, and thus it’s always interesting to sot a new one. If you’re in north-west Europe next weekend, consider dropping by Hackfest, in the Dutch city of Enschede, right on the German border.

Looking at the program and the projects and workshops listed on the website we can see robotics, lockpicking, demoscene, retrocomputing, and plenty of open source. There are quite a few names which have featured at times here on these pages, something which certainly piqued our interest. Finding that it’s only 15 Euros for a weekend’s admission sealed the deal, and thus it’s time for Hackaday to break out the trusty Interrail pass once more and make the trek. Sadly many of Hackaday’s community will be too far away to join us, but if you’re close enough to make it then it’s one to consider.

This is a part of the world it’s fair to say isn’t often featured on Hackaday, but some of you might remember the city as being at the centre of a Wi-Fi tracking scandal.


hackaday.com/2024/09/22/hackfe…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Where Did the Japanese Computers Go?
poliverso.org/display/0477a01e…
Where Did the Japanese Computers Go?If you are a retrocomputer person, at least in North America and Europe, you probably only have a hazy idea of what computers were in the Japanese market at the time we were all buying MSDOS-based computers. You may have heard of PC-98, but there were many Japanese-only computers out there, and a recent post by [Misty De Meo] asks the question: What happened


Where Did the Japanese Computers Go?


If you are a retrocomputer person, at least in North America and Europe, you probably only have a hazy idea of what computers were in the Japanese market at the time we were all buying MSDOS-based computers. You may have heard of PC-98, but there were many Japanese-only computers out there, and a recent post by [Misty De Meo] asks the question: What happened to the Japanese computers?

To answer that question, you need a history lesson on PC-98 (NEC), FM Towns (Fujitsu), and the X68000 (Sharp). The PC-98 was originally a text-only MSDOS-based computer. But eventually, Microsoft and NEC ported Windows to the machine.

The FM Towns had its own GUI operating system. However, it too had a Windows port and the machine became just another Windows platform. The X68000, as you may well have guessed, used a 68000 CPU. Arguably, this was a great choice at the time. However, history shows that it didn’t work out, and when Sharp began making x86-based Windows machines — and, of course, they did — there was no migration path.

[Misty] makes an interesting point. While we often think of software like Microsoft Office as driving Windows adoption, that wasn’t the case in Japan. It turns out that multitasking was the key feature since Office, at the time, wasn’t very friendly to the native language.

So where did the Japanese computers go? The answer for two of them is: nowhere. They just morphed into commodity Windows computers. The 68000 was the exception — it just withered away.

Japanese pocket computers were common at one time and have an interesting backstory. Japanese can be a challenge for input but, of course, hackers are up to the challenge.


hackaday.com/2024/09/22/where-…


The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Disney abbandona Slack dopo la violazione di 1 TB di dati riservati
poliverso.org/display/0477a01e…
Disney abbandona Slack dopo la violazione di 1 TB di dati riservatiLa Walt Disney sarebbe in procinto di abbandonare Slack cnbc.com/2024/09/19/disney-to-… a seguito dell’importante attacco informatico che ha portato alla presunta violazione dei dati di luglio, che avrebbe reso pubblici oltre 1 TB di messaggi e file riservati che erano stati pubblicati sui canali


Disney abbandona Slack dopo la violazione di 1 TB di dati riservati


La Walt Disney sarebbe in procinto di abbandonare Slack a seguito dell’importante attacco informatico che ha portato alla presunta violazione dei dati di luglio, che avrebbe reso pubblici oltre 1 TB di messaggi e file riservati che erano stati pubblicati sui canali di comunicazioni interni dell’azienda. Qui il link che riporta la presunta violazione.

Secondo CNBC, Disney avrebbe già pianificato di abbandonare l’uso di Slack come sistema di collaborazione aziendale per migrare verso nuovi strumenti. Avrebbe inoltre già inviato una mail ai dipendenti questa settimana informandoli del completamento della migrazione entro la fine del prossimo trimestre fiscale dell’azienda.

Cos’è Slack


Slack è uno strumento di comunicazione e collaborazione in tempo reale. Slack offre uno spazio condiviso in cui lavorare e dialogare, per rimuovere le barriere comunicative all’interno di organizzazioni di ogni tipo.

Compatibile con diversi dispositivi e piattaforme, Slack consente di chattare, caricare e condividere file in gruppo o individualmente. Inoltre il grande numero di integrazioni possibili con altri strumenti (ad esempio di word automation, monitoring, versioning…) permette di accorpare tutti gli elementi necessari per la gestione del progetto. In questo modo gli sviluppatori hanno a disposizione un unico ambiente per collaborare tra di loro e comunicare con tutti gli altri membri del team.

La decisione di Disney di abbandonare Slack, sembrerebbe arrivare proprio in seguito alla presunta violazione di luglio, quando il Threat Actor chiamato “NullBulge” pubblicò un post dettagliato nel quale descrisse la natura e la portata del furto di dati. Secondo il post, furono resi pubblici non solo dati sensibili ma anche elementi di grande valore strategico per Disney, come progetti ancora in fase di sviluppo e codice sorgente utilizzato per applicazioni e piattaforme interne.

Ricordiamo che Disney subì presumibilmente anche un’altra violazione dei dati un mese prima, quando 2,5 GB di dati aziendali e di Club Penguin sono trapelati dal Server Confluence dell’azienda e pubblicati in un post anonimo sul popolare forum 4Chan.

Conclusioni


Non è chiaro come i dipendenti dell’azienda comunicheranno dopo aver dismesso Slack e se Disney passerà a un’altra piattaforma aziendale, come Microsoft Teams, o al proprio software interno. Le piattaforme di comunicazione, come Slack, possono essere un bersaglio allettante per gli autori delle minacce informatiche che vogliono rubare file riservati e dati personali. Come sempre è importante sottolineare che le aziende devono mantenere un livello elevato di vigilanza e adottare misure preventive efficaci per proteggere i propri dati e le proprie operazioni da simili minacce. Tuttavia, fino a conferma ufficiale, queste informazioni dovrebbero essere trattate con cautela come una possibile indicazione di rischio.

RHC monitorerà l’evoluzione della vicenda in modo da pubblicare ulteriori news sul blog, nel caso in cui ci fossero novità sostanziali. Qualora ci siano persone informate sui fatti che volessero fornire informazioni in modo anonimo possono utilizzareredhotcyber.com/whistleblowerla mail crittografata del whistleblower.

L'articolo Disney abbandona Slack dopo la violazione di 1 TB di dati riservati proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.