The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Ti ricordi del format per i ragazzi incentrato sul libro Ada&Zangemann? È giunta l’ora di contattare le Scuole! 😀 ✏️

Trovi tutto il necessario (scheda per i volontari, istruzioni per attività ricreativa, template per le scuole) a questo link: share.fsfe.org/s/eSDatbWSitrZ6…

Like questo post se hai già mandato la tua richiesta!
E #staytuned il progetto sarà arricchito da alcune chicche che sveleremo a brevissimo 😉

in reply to Free Software Foundation Europe

Sensitive content

Questa voce è stata modificata (1 anno fa)
The Privacy Post ha ricondiviso questo.

Updated FPF Infographic Explores Data in Connected Vehicles
fpf.org/blog/updated-fpf-infog…
@privacy
Today, The Future of Privacy Forum is launching the Data and the Connected Vehicle Infographic 2.0, including new updates to account for the types of data associated with connected vehicles, features in and outside of the vehicle, and data handlers who receive and process data. Lawmakers, manufacturers, privacy professionals, and

The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Hack Your Eyesight with High Tech Bifocals
poliverso.org/display/0477a01e…
Hack Your Eyesight with High Tech BifocalsAs we get older, our eyes get worse. That’s just a fact of life. It is a rite of passage the first time you leave the eye doctor with a script for “progressive” lenses which are just fancy bifocals. However, a new high-tech version of bifocals promises you better vision gizmodo.com/these-hi-tech-bifo…, but with a slight drawback, as [Sherri L.


Hack Your Eyesight with High Tech Bifocals


As we get older, our eyes get worse. That’s just a fact of life. It is a rite of passage the first time you leave the eye doctor with a script for “progressive” lenses which are just fancy bifocals. However, a new high-tech version of bifocals promises you better vision, but with a slight drawback, as [Sherri L. Smith] found.

Remember how users of Google Glass earned the nickname “glassholes?” Well, these new bifocals make Google Glass look like a fashion statement. If you are too young to need them, bifocals account for the fact that your eyes need different kinds of help when you look close up (like soldering) or far away (like at an antenna up on a roof). A true bifocal has two lenses and you quickly learn to look down at anything close up and up to see things far away. Progressives work the same, but they transition between the two settings instead of having a discrete mini lens at the bottom.

The new glasses, the ViXion01 change based on what you are looking for. They measure range and adjust accordingly. For $555, or a monthly rental, you can wear what looks like a prototype for a Star Trek visor and let it deduce what you are looking at and change its lenses accordingly.

Of course, this takes batteries that last about ten hours. It also requires medical approval to be real glasses and it doesn’t have that, yet. Honestly, if they worked well and didn’t look so dorky, the real use case might be allowing your eye doctor to immediately download a new setting as your vision changes. How about you? How much odd headgear are you willing to wear in public and why?

Glasses have a long strange history. While a university prototype we saw earlier was not likely to win fashion awards, they did look better than these. Maybe.


hackaday.com/2024/09/16/hack-y…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Infographic Explores Driver Data Collection and Use in Connected Cars
fpf.org/blog/infographic-explo…
@privacy
FPF’s “Data and the Connected Vehicle” Demystifies Connected Car Ecosystem as Policymakers Look to Regulate SEPT. 16, 2024 — Vehicle technologies are evolving rapidly, in every facet of the system, from safety features to entertainment, and occupant convenience. Many of these new features are enabled by the

The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Attacco Informatico alla Kawasaki Motors! RansomHub pubblica 487 GB di dati rubati
poliverso.org/display/0477a01e…
Attacco Informatico alla Kawasaki Motors! RansomHub pubblica 487 GB di dati rubatiKawasaki Motors Europe si sta riprendendo da un attacco informatico kawasaki.eu/en/News_and_events… effettuato dal gruppo redhotcyber.com/post/il-ransom… RansomHub. L’incidente ha causato interruzioni del servizio, tuttavia, come affermano i rappresentanti


Attacco Informatico alla Kawasaki Motors! RansomHub pubblica 487 GB di dati rubati


Kawasaki Motors Europe si sta riprendendo da un attacco informatico effettuato dal gruppo ransomware RansomHub. L’incidente ha causato interruzioni del servizio, tuttavia, come affermano i rappresentanti dell’azienda, il ripristino attivo è attualmente in corso e si prevede che il 90% dei server ritornerà in servizio la prossima settimana.

L’attacco ha preso di mira la sede europea della Kawasaki all’inizio di settembre. Nell’ambito delle misure di sicurezza adottate, tutti i server aziendali sono stati temporaneamente disabilitati per verificare la presenza di malware.

Il personale IT, insieme ad esperti esterni di sicurezza informatica, hanno esaminato manualmente ciascun server prima di riconnetterlo alla rete aziendale.
Post all’interno del Data Leak Site (DLS) di RansomHub
Kawasaki Motors Europe, una filiale di Kawasaki Heavy Industries, produttore globale di motociclette e altre attrezzature motorizzate, ha affermato che l’incidente non ha influenzato le operazioni aziendali chiave come concessionari, fornitori e logistica.

Nel frattempo, il gruppo RansomHub ha rivendicato l’attacco informatico affermando di aver rubato 487 GB di dati dalla rete dell’azienda. Gli hacker hanno pubblicato i dati rubati in quanto l’azienda si è rifiutata di pagare il riscatto.

Non è chiaro se i dati rubati contengano informazioni sui clienti dell’azienda, ma questo scenario non è stato escluso. I rappresentanti della Kawasaki non hanno risposto alle richieste di commento dei giornalisti.
Alcune directory dei dati pubblicati da RansomHub
Il gruppo RansomHub è diventato attivo dopo la fine dell’operazione BlackCat/ALPHV, nella quale erano coinvolti molti attuali membri di RansomHub. Dall’inizio del 2024 ha effettuato più di 200 attacchi riusciti, anche contro grandi aziende come Rite Aid e Planned Parenthood.

Un allarme congiunto emesso il mese scorso da FBI, CISA e Dipartimento della Salute degli Stati Uniti ha evidenziato la minaccia del gruppo ai principali settori infrastrutturali statunitensi.

L'articolo Attacco Informatico alla Kawasaki Motors! RansomHub pubblica 487 GB di dati rubati proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

1/4 📢Today, 64 orgs & experts urge the @EU_Commission to halt proposals for using #AgeVerification tools when implementing #DigitalServicesAct & #eIDAS.

Evidence & lived experiences show these tools are dangerous, discriminatory & unsafe.

READ MORE: edri.org/our-work/open-letter-…

in reply to EDRi

4/4 #AgeVerification tools aren't a silver bullet for addressing children's needs online.

Strict verification can block access to valuable resources, hinder digital skills & put users at risk.

edri.org/our-work/open-letter-…

in reply to EDRi

Signatories: @comunal
@article19org
@ansol
@danesjenovdan
@wikimediaDE
@vrijschrift
@superrr
@digiges
@des.network
@BoellStiftung
@apti
@accessnow
@dfri
@d3

For more see the open letter: edri.org/our-work/open-letter-…

The Privacy Post ha ricondiviso questo.

French Commissioner Thierry Breton resigns over row with Von der Leyen
poliverso.org/display/0477a01e…
French Commissioner Thierry Breton resigns over row with Von der LeyenThierry Breton, Internal Market Commissioner also in charge of tech and defence announced his resignation from the European Commission, in a last move to question von der Leyen’s right to reign.euractiv.com/section/defence-a…


French Commissioner Thierry Breton resigns over row with Von der Leyen


Thierry Breton, Internal Market Commissioner also in charge of tech and defence announced his resignation from the European Commission, in a last move to question von der Leyen’s right to reign.


euractiv.com/section/defence-a…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Usagi Electric’s Paper Tape Reader is Ready to Hop With the Tube Computer
poliverso.org/display/0477a01e…
Usagi Electric’s Paper Tape Reader is Ready to Hop With the Tube ComputerAfter previously working out a suitable approach to create a period-correct paper tape reader for his tube-based, MC14500B processor-inspired computer, [David Lovett] over at the Usagi Electric farm is back with a video on how he made a working tape reader


Usagi Electric’s Paper Tape Reader is Ready to Hop With the Tube Computer


After previously working out a suitable approach to create a period-correct paper tape reader for his tube-based, MC14500B processor-inspired computer, [David Lovett] over at the Usagi Electric farm is back with a video on how he made a working tape reader.
The assembled paper tape reader as seen from the front with tape inserted. (Credit: David Lovett, Usage Electric, YouTube)The assembled paper tape reader as seen from the front with tape inserted. (Credit: David Lovett, Usage Electric, YouTube)
The tape reader’s purpose is to feed data into the tube-based computer, which for this computer system with its lack of storage memory means that the instructions are fed into the system directly, with the tape also providing the clock signal with a constant row of holes in the tape.

Starting the tape reader build, [David] opted to mill the structural part out of aluminum, which is where a lot of machining relearning takes place. Ultimately he got the parts machined to the paper design specs, with v-grooves for the photodiodes to fit into and a piece to clamp them down. On top of this is placed a part with holes that line up with the photodiodes.

Another alignment piece is added to hold the tape down on the reader while letting light through onto the tape via a slot. After a test assembly [David] was dismayed that due to tolerance issues he cracked two photodiodes within the v-groove clamp, which was a hard lesson with these expensive (and rare) photodiodes.

Although tolerances were somewhat off, [David] is confident that this aluminum machined reader will work once he has it mounted up. Feeding the tape is a problem that is still to be solved. [David] is looking for ideas and suggestions for a good approach within the limitations that he’s working with. At the video’s end, he mentions learning FreeCAD and 3D printing parts in the future. That would probably not be period-correct in this situation, but might be something he could get away with for some applications within the retrocomputing space.

We covered the first video and the thought process behind picking small (1.8 mm diameter) photodiodes as a period-correct tape hole sensor for a 1950s-era computing system, like the 1950s Bendix G-15 that [David] is currently restoring.

youtube.com/embed/xdyZEZTv-xg?…


hackaday.com/2024/09/16/usagi-…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Nella mente del criminale informatico: Cosa Spinge un Hacker a Compiere Attacchi?
poliverso.org/display/0477a01e…
Nella mente del criminale informatico: Cosa Spinge un Hacker a Compiere Attacchi?Cosa spinge un redhotcyber.com/post/i-padri-f… criminale oppure un’organizzazione a compiere un attacco informatico? La sicurezza informatica redhotcyber.com/rubriche/alla-… inizia dalla comprensione dell’animo umano. Scopriamo insieme perchè.La profilazione psicologica


Nella mente del criminale informatico: Cosa Spinge un Hacker a Compiere Attacchi?


Cosa spinge un hacker criminale oppure un’organizzazione a compiere un attacco informatico? La sicurezza informatica inizia dalla comprensione dell’animo umano. Scopriamo insieme perchè.

La profilazione psicologica cerca di costruire un profilo psicologico di un individuo, in questo caso di un criminale informatico, analizzando le sue azioni, il suo modus operandi e le tracce digitali che lascia.

I fattori che influenzano le emozioni sono diversi ma i più importanti sono:

  • Successo o fallimento: Un attacco riuscito può portare a una sensazione di trionfo e potere, mentre un fallimento può causare frustrazione e rabbia.
  • Riconoscimento: Molti attaccanti cercano il riconoscimento dei loro pari nella comunità hacker. Il fatto di essere considerati un esperto può aumentare l’autostima e la motivazione.
  • Conseguenze delle azioni: Alcuni potrebbero provare rimorso o senso di colpa dopo aver causato danni significativi. Tuttavia, altri potrebbero giustificare le loro azioni sostenendo di aver agito per il bene comune o per difendersi da un torto subito o per grandi guadagni.


La motivazione


  • Economica: Chi agisce per guadagno potrebbe provare eccitazione all’idea di un colpo riuscito e frustrazione se fallisce.
  • Ideologica: Un hacker motivato da ideologie politiche o sociali potrebbe provare soddisfazione nel danneggiare un sistema o nel diffondere informazioni.
  • Vendetta: Un attacco potrebbe essere motivato da rancore personale, e l’attaccante potrebbe provare sollievo o vendetta nel causare danni.

Altri aspetti da considerare

  • Il ruolo dei media: I media spesso presentano gli hacker come figure romantiche o antieroi, contribuendo a creare un’aura di fascino intorno a questa figura.
  • La dipendenza: Alcuni hacker possono sviluppare una vera e propria dipendenza dall’adrenalina e dalla soddisfazione che provano nel compiere attacchi informatici.
  • L’impatto sociale: Gli attacchi informatici possono avere conseguenze devastanti sulla società, causando perdite economiche, interruzioni dei servizi e danni alla reputazione.

I cyber criminali raramente agiscono da soli ed a tal proposito cerchiamo di scoprire le differenze.

Hacker Solitario vs. Gruppo Organizzato


La profilazione di un hacker, sia esso solitario o parte di un gruppo, è un compito complesso che richiede una profonda conoscenza del mondo del cybercrime. Tuttavia, esistono delle differenze significative nel modus operandi e nei profili psicologici tra queste due tipologie di attaccanti.

Attaccante Solitario:

  • Motivazioni: Spesso guidati da curiosità, vendetta, sfida personale o ideologie.
  • Competenze: Le competenze tecniche possono variare notevolmente, da un principiante a un esperto.
  • Modus operandi: Tende ad essere meno sofisticato e più imprevedibile.
  • Traccia digitale: La traccia digitale è spesso più facile da seguire, poiché il solitario lascia meno false piste.
  • Profilo psicologico: Può essere introverso, solitario, con un forte bisogno di riconoscimento.

Gruppo Organizzato:

  • Motivazioni: Principalmente economiche, ma anche politiche o legate al crimine organizzato.
  • Competenze: Elevato livello di specializzazione, con membri che hanno competenze complementari.
  • Modus operandi: Più sofisticato, pianificato e coordinato.
  • Traccia digitale: La traccia digitale è spesso più difficile da seguire, grazie all’utilizzo di tecniche di offuscamento e alla distribuzione delle responsabilità.
  • Profilo psicologico: I membri possono avere profili psicologici diversi, ma spesso condividono una forte coesione e un senso di appartenenza al gruppo.


Differenze chiave nella profilazione dell’Hacker Solitario e del Gruppo Organizzato


  • Complessità dell’analisi: La profilazione di un gruppo è più complessa, in quanto richiede l’analisi di dinamiche di gruppo, gerarchie e ruoli.
  • Varietà di competenze: Un gruppo organizzato può includere esperti in diverse aree, come hacking, ingegneria sociale.
  • Motivazioni più varie: I gruppi organizzati possono avere motivazioni più complesse e difficili da individuare.
  • Traccia digitale più difficile da seguire: I gruppi organizzati utilizzano spesso infrastrutture complesse e tecniche di offuscamento per nascondere le loro attività.

La psicologia può svolgere un ruolo cruciale nell’identificazione delle emozioni che motivano i criminali informatici, offrendo un contributo significativo alla società in diversi modi:

1. Comprensione delle motivazioni profonde:


  • Profiling psicologico: Attraverso l’analisi del modus operandi, delle comunicazioni online e del contesto sociale, gli psicologi possono costruire profili psicologici degli hacker, cercando di individuare le motivazioni profonde che li spingono ad agire.
  • Teorie della personalità: Applicando teorie della personalità come quella dei Big Five o di Maslow, si possono identificare tratti comuni tra gli hacker, come il bisogno di potere, la ricerca di eccitazione o la volontà di vendicarsi.


2. Identificazione di segnali premonitori:


  • Analisi del linguaggio: Analizzando il linguaggio utilizzato negli ambienti online, gli psicologi possono individuare segnali di allarme, come espressioni di rabbia, frustrazione o desiderio di vendetta, che potrebbero indicare una potenziale minaccia.
  • Monitoraggio dei comportamenti online: Attraverso l’analisi dei comportamenti online, si possono identificare individui che manifestano un interesse eccessivo per argomenti legati alla sicurezza informatica o che mostrano segni di radicalizzazione.


3. Sviluppo di strategie di prevenzione:


  • Interventi educativi: La psicologia può contribuire a sviluppare programmi educativi per sensibilizzare i giovani ai rischi del cybercrime e promuovere comportamenti online responsabili.
  • Interventi riabilitativi: Per gli hacker che desiderano cambiare vita, la psicologia può offrire strumenti e tecniche per affrontare le motivazioni profonde che li hanno spinti a compiere reati informatici.


4. Collaborazione con le forze dell’ordine:


  • Supporto investigativo: Gli psicologi possono fornire alle forze dell’ordine un supporto fondamentale nell’interpretazione delle evidenze digitali e nella costruzione di profili psicologici degli indagati.
  • Negoziazione: In alcuni casi, gli psicologi possono essere coinvolti in negoziazioni con gli hacker per cercare di farli desistere dalle loro azioni o per recuperare i dati rubati.


Conclusione


In conclusione, la psicologia offre un contributo fondamentale alla comprensione delle motivazioni che spingono gli individui a compiere reati informatici.

Attraverso l’analisi dei comportamenti, delle comunicazioni e del contesto sociale, gli psicologi possono aiutare a identificare i segnali premonitori, sviluppare strategie di prevenzione e collaborare con le forze dell’ordine per contrastare il cybercrime.

La psicologia ci insegna a leggere tra le righe, mentre la sicurezza informatica ci insegna a proteggere ciò che conta di più.

Insieme, creano una sinergia potente.

L'articolo Nella mente del criminale informatico: Cosa Spinge un Hacker a Compiere Attacchi? proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Nuovo schema fraudolento: Falsi test CAPTCHA installano malware su Windows
poliverso.org/display/0477a01e…
Nuovo schema fraudolento: Falsi test CAPTCHA installano malware su WindowsGli specialisti della sicurezza informatica redhotcyber.com/rubriche/alla-… mettono in guardia da un nuovo schema fraudolento: gli aggressori hanno iniziato a utilizzare falsi test CAPTCHA per installare redhotcyber.com/post/la-storia… sui computer Windows. Questo è un segnale per


Nuovo schema fraudolento: Falsi test CAPTCHA installano malware su Windows


Gli specialisti della sicurezza informatica mettono in guardia da un nuovo schema fraudolento: gli aggressori hanno iniziato a utilizzare falsi test CAPTCHA per installare malware sui computer Windows. Questo è un segnale per gli utenti di prestare maggiore attenzione alla protezione dei propri dati e di fare attenzione quando interagiscono con CAPTCHA.

Come sai, i test CAPTCHA standard richiedono all’utente di eseguire determinate attività, ad esempio selezionare gli oggetti desiderati in un’immagine o inserire caratteri di testo. Gli aggressori hanno però approfittato di questo scenario familiare e hanno creato una versione falsa del test che, invece di verificare, chiede all’utente di eseguire una serie di azioni sulla tastiera che portano all’installazione di un virus.

Invece dei suggerimenti tradizionali, il falso CAPTCHA chiede all’utente di premere la combinazione di tasti “Windows + R”, che fa apparire una finestra sul computer per eseguire i comandi. Successivamente, il test ti chiede di premere “CTRL + V” e quindi il tasto Invio. Se l’utente non pensa a ciò che sta accadendo, potrebbe non notare che nella finestra che avvia il download di uno script PowerShell dannoso viene eseguito un comando.

Processo di attivazione dello script tramite CAPTCHA

Secondo l’Unità 42 di Palo Alto Networks, lo script dannoso installa sul dispositivo Lumma Stealer, progettato per rubare password, cookie e dati del portafoglio di criptovaluta dal dispositivo infetto.

Gli esperti di Hudson Rock hanno inoltre confermato che quando si visitano siti pericolosi che ospitano un falso test CAPTCHA, uno script dannoso viene automaticamente copiato nel browser. Quando l’utente esegue le azioni suggerite, viene attivato lo script, che porta all’infezione del dispositivo.

Continuano a verificarsi attacchi che utilizzano CAPTCHA falsi. Lo specialista in sicurezza informatica John Hammond di Huntress ha notato che la società ha registrato un’altra apparizione di questa minaccia la scorsa settimana.

I test CAPTCHA falsi possono essere distribuiti tramite e-mail e messaggi di phishing, rendendoli particolarmente pericolosi. Gli utenti devono essere vigili e non eseguire attività sospette durante il controllo del CAPTCHA.

L'articolo Nuovo schema fraudolento: Falsi test CAPTCHA installano malware su Windows proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Un Mondo di Spioni! L’Active Listening sembrerebbe non essere fantascenza
poliverso.org/display/0477a01e…
Un Mondo di Spioni! L’Active Listening sembrerebbe non essere fantascenza404 Media 404media.co/heres-the-pitch-de… ha ricevuto un documento di presentazione da documentcloud.org/documents/25… Cox Media Group (CMG). Afferma che l’azienda può indirizzare gli annunci in base a ciò che i potenziali clienti dicono ad alta voce vicino ai microfoni dei loro


Un Mondo di Spioni! L’Active Listening sembrerebbe non essere fantascenza


404 Media ha ricevuto un documento di presentazione da Cox Media Group (CMG). Afferma che l’azienda può indirizzare gli annunci in base a ciò che i potenziali clienti dicono ad alta voce vicino ai microfoni dei loro dispositivi.

Inoltre, Google, Amazon, Bing e altre società sono menzionate nel documento come partner CMG.

Nel dicembre dello scorso anno la pubblicazione parlava già della funzionalità pubblicizzata da CMG denominata Active Listening. A quel tempo, i giornalisti utilizzavano materiali dal sito web di CMG, ma dopo la pubblicazione dell’articolo la società ha cancellato queste informazioni.

Prima sul sito CMG era scritto: “Che impatto avrebbe sulla tua attività se potessi rivolgerti a potenziali clienti che discutono attivamente della necessità dei tuoi servizi nelle conversazioni quotidiane? No, questo non è un episodio di Black Mirror: si tratta di dati vocali e CMG ha le capacità per utilizzarli a vantaggio del tuo business.”

Ora la redazione ha a disposizione una presentazione pubblicitaria dedicata all’Ascolto Attivo. Si noti che questa presentazione è stata inviata almeno ad una società alla quale i rappresentanti di CMG prevedevano di vendere i propri servizi.

“I dispositivi intelligenti raccolgono dati sulle intenzioni in tempo reale ascoltando le nostre conversazioni. Gli inserzionisti possono abbinare questi dati vocali a parametri comportamentali per rivolgersi ai consumatori sul mercato. Utilizziamo l’intelligenza artificiale per raccogliere questi dati da oltre 470 fonti per migliorare l’implementazione, il targeting e le prestazioni delle campagne”, si legge nella prima diapositiva della presentazione di CMG.

Il documento non dice da dove esattamente CMG riceverebbe questi dati vocali (cioè non elenca, ad esempio, marchi specifici di smart TV, altoparlanti o specifiche applicazioni per smartphone). Ma è stato riferito che CMG utilizza i dati vocali per identificare il pubblico “pronto ad acquistare”, quindi compila un elenco di tali utenti e lo trasferisce alle piattaforme pubblicitarie per il successivo targeting degli annunci.

Il documento afferma che per 100 dollari al giorno, CMG può rivolgersi a persone entro un raggio di 10 miglia (16 chilometri), o per 200 dollari al giorno, un raggio di 20 miglia (32 chilometri).

Come accennato in precedenza, CMG afferma di avere partnership con Google, Amazon e Facebook. Molto probabilmente, in questo contesto stiamo parlando di pubblicità in generale e non specificamente del prodotto Active Listening. Ma la presentazione dice che CMG è:

  • partner principale ( Premier Partner ) di Google, cioè incluso nel 3% delle società pubblicitarie di maggior successo in un determinato Paese;
  • Il primo media partner di Amazon Advertising;
  • una delle prime società di media a diventare partner di marketing di Facebook.

Dopo che 404 giornalisti di Media hanno pubblicato la loro storia e contattato le aziende per un commento, Google ha rimosso CMG dal suo programma di affiliazione.

“Tutti gli inserzionisti sono tenuti a rispettare tutte le leggi e i regolamenti applicabili, nonché le norme di Google Ads, e quando identifichiamo annunci o inserzionisti che violano queste norme, adottiamo le misure appropriate”, ha affermato Google alla pubblicazione.

Amazon ha affermato che “Amazon Ads non ha mai collaborato con CMG su questo programma e non ha intenzione di farlo”. La società ha aggiunto che se si venisse a sapere che uno dei partner viola le regole di marketing, Amazon potrà intraprendere le azioni appropriate.

Meta ha affermato di non poter commentare informazioni su specifici account di inserzionisti, ma ha osservato che gli inserzionisti dovrebbero avere i diritti necessari per utilizzare qualsiasi dato come parte delle loro campagne. E dopo che Google ha rimosso CMG dal suo programma di affiliazione, Meta ha aggiunto che stava attualmente esaminando se CMG avesse violato i Termini e condizioni dell’azienda e ha affermato che avrebbe potuto agire se necessario.

L'articolo Un Mondo di Spioni! L’Active Listening sembrerebbe non essere fantascenza proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Exploring TapTo NFC Inegration On The MiSTer
poliverso.org/display/0477a01e…
Exploring TapTo NFC Inegration On The MiSTer[Ken] from the YouTube channel What’s Ken Making is back with another MiSTer video youtube.com/watch?v=73Kx3jwyk0… detailing the TapTo project tapto.wiki/Main_Page and its integration into MiSTer. MiSTer, misterfpga.org/feed/ as some may recall, is a set of FPGA images and a supporting ecosystem for the Terasic DE10-Nano FPGA board


Exploring TapTo NFC Inegration On The MiSTer


[Ken] from the YouTube channel What’s Ken Making is back with another MiSTer video detailing the TapTo project and its integration into MiSTer. MiSTer, as some may recall, is a set of FPGA images and a supporting ecosystem for the Terasic DE10-Nano FPGA board, which hosts the very capable Altera Cyclone V FPGA.
The TeensyROM C64 cart supports TapTo
The concept behind TapTo is to use NFC cards, stickers, and other such objects to launch games and particular key sequences. This allows an NFC card to be programmed with the required FPGA core and game image. The TapTo service runs on the MiSTer, waiting for NFC events and launching the appropriate actions when it reads a card. [Ken] demonstrates many such usage scenarios, from launching games quickly and easily with a physical ‘game card’ to adding arcade credits and even activating cheat codes.

As [Ken] points out, this opens some exciting possibilities concerning physical interactivity and would be a real bonus for people less able-bodied to access these gaming systems. It was fun to see how the Nintendo Amiibo figures and some neat integration projects like the dummy floppy disk drive could be used.

TapTo is a software project primarily for the MiSTer system, but ports are underway for Windows, the MiSTex, and there’s a working Commodore 64 game loader using the TeensyROM, which supports TapTo. For more information, check out the TapTo project GitHub page.

We’ve covered the MiSTer a few times before, but boy, do we have a lot of NFC hacks. Here’s an NFC ring and a DIY NFC tag, just for starters.

youtube.com/embed/73Kx3jwyk0U?…

Thanks to [Stephen Walters] for the tip!


hackaday.com/2024/09/15/explor…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Microwave Forge Casts the Sinking-est Benchy Ever
poliverso.org/display/0477a01e…
Microwave Forge Casts the Sinking-est Benchy EverAs a test artifact, 3DBenchy does a pretty good job of making sure your 3D printer is up to scratch. As an exemplar of naval architecture, though — well, let’s just say that if it weren’t for the trapped air in the infilled areas, most Benchy prints wouldn’t float at all. About the only way to make Benchy less seaworthy would be to


Microwave Forge Casts the Sinking-est Benchy Ever


As a test artifact, 3DBenchy does a pretty good job of making sure your 3D printer is up to scratch. As an exemplar of naval architecture, though — well, let’s just say that if it weren’t for the trapped air in the infilled areas, most Benchy prints wouldn’t float at all. About the only way to make Benchy less seaworthy would be to make it out of cast iron. Challenge accepted.

We’ve grown accustomed to seeing [Denny] over at “Shake the Future” on YouTube using his microwave-powered kilns to cast all sorts of metal, but this time he puts his skill and experience to melting iron. For those not in the know, he uses standard consumer-grade microwave ovens to heat kilns made from ceramic fiber and lots of Kapton tape, which hold silicon carbide crucibles that get really, really hot under the RF onslaught. It works surprisingly well, especially considering he does it all on an apartment balcony.

For this casting job, he printed a Benchy model from PLA and made a casting mold from finely ground silicon carbide blasting medium mixed with a little sodium silicate, or water glass. His raw material was a busted-up barbell weight, which melted remarkably well in the kiln. The first pour appeared to go well, but the metal didn’t quite make it all the way to the tip of Benchy’s funnel. Round two was a little more exciting, with a cracked crucible and spilled molten metal. The third time was a charm, though, with a nice pour and complete mold filling thanks to the vibrations of a reciprocating saw.

After a little fettling and a saltwater bath to achieve the appropriate patina, [Denny] built a neat little Benchy tableau using microwave-melted blue glass as a stand-in for water. It highlights the versatility of his method, which really seems like a game-changer for anyone who wants to get into home forging without the overhead of a proper propane or oil-fired furnace.

youtube.com/embed/-WFin_4Ltfs?…


hackaday.com/2024/09/15/microw…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Hackaday Links: September 15, 2024
poliverso.org/display/0477a01e…
Hackaday Links: September 15, 2024A quick look around at any coffee shop, city sidewalk, or sadly, even at a traffic light will tell you that people are on their phones a lot. But exactly how much is that? For Americans in 2023, it was a mind-boggling 100 trillion megabytes reuters.com/technology/america…, according to the wireless industry lobbying association CTIA. The group doesn’t discuss


Hackaday Links: September 15, 2024


Hackaday Links Column Banner

A quick look around at any coffee shop, city sidewalk, or sadly, even at a traffic light will tell you that people are on their phones a lot. But exactly how much is that? For Americans in 2023, it was a mind-boggling 100 trillion megabytes, according to the wireless industry lobbying association CTIA. The group doesn’t discuss their methodology in the press release, so it’s a little hard to make judgments on that number’s veracity, or the other numbers they bandy about, such as the 80% increase in data usage since 2021, or the fact that 40% of data is now going over 5G connections. Some of the numbers are more than a little questionable, too, such as the claim that 330 million Americans (out of a current estimate of 345.8 million people) are covered by one or more 5G networks. Even if you figure that most 5G installations are in densely populated urban areas, 95% coverage seems implausible given that in 2020, 57.5 million people lived in rural areas of the USA. Regardless of the details, it remains that our networks are positively humming with data, and keeping things running is no mean feat.

If you’ve ever wondered what one does with a degree in wildlife biology, look no further than a study that looks into “avian-caused ignitions” of wildfires. The study was led by Taylor Barnes, a wildlife biologist and GIS specialist who works for a civil engineering firm, and concludes that some utility poles are 5 to 8 times more likely to spark a wildfire than the average pole due to “thermal events” following electrocution of a bird, squirrel, bear, or idiot. Unfortunately, the paper is paywalled, so there’s no information on methodology, but we’re guessing a grad student or intern spent a summer collecting animal carcasses from beneath power poles. It’s actually very valuable work since it informs decisions on where to direct wildlife mitigation efforts that potentially reduce the number of service outages and wildfires, but it’s still kinda funny.

From the “How to get rid of a lot of money in a hurry” files comes a story of a bad GPU made into an incredibly unattractive purse. About the only thing good about the offering, which consists of a GeForce GT 730 video card stuffed into a clear plastic box with a gold(ish) chain attached, is the price of $1,024. The completely un-dodgy GPUStore Shopify site also lists a purse fashioned from an NVIDIA H100 Tensor Core GPU for a cool $65,536. At least somebody knows about base two.

And finally, if you’ve struggled with the question of what humanoid robots bring to the table, chances are pretty good that adding the ability to fly with four jet engines isn’t going to make things much clearer. But for some reason, a group from the Italian Institute of Technology is working on the problem of “aerial humanoid robotics” with a cherub-faced bot dubbed iRonCub. The diminutive robot is only about 70 kilograms, which includes the four jet engines generating a total of 1,000 newtons of thrust. Applications for the flying baby robot are mostly left to the imagination, although there is a vague reference to “search and rescue” applications; we’re not sure about you, but if we’re lost in the woods and half-crazed from hunger and exposure, a baby descending from the sky on a 600° plume of exhaust might not be the most comforting sight.


hackaday.com/2024/09/15/hackad…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Archiving Data On Paper Using 2D Images
poliverso.org/display/0477a01e…
Archiving Data On Paper Using 2D ImagesIt seems like only yesterday we covered a project using QR codes to archive data on paper (OK, it was last Thursday), so here’s another way to do it ronja.twibright.com/optar/, this time with a dedicated codec using the full page. Optar or OPTical ARchiver is a project capable of squeezing a whopping 200 Kb of data onto a single A4 sheet of paper, with


Archiving Data On Paper Using 2D Images


It seems like only yesterday we covered a project using QR codes to archive data on paper (OK, it was last Thursday), so here’s another way to do it, this time with a dedicated codec using the full page. Optar or OPTical ARchiver is a project capable of squeezing a whopping 200 Kb of data onto a single A4 sheet of paper, with writing and reading achieved with a standard laser printer and a scanner. It’s a bit harder than you might think to get that much data on the page, given that even a 600 DPI printer can’t reliably place every dot each time. Additionally, paper is rarely uniform at the microscopic scale, so Optar utilizes a forward error-correcting coding scheme to cater for a little irregularity in both printing and scanning.

The error-correcting scheme selected was an Extended Golay code (24, 12, 8), which, interestingly, was also used for image transmission by the NASA Voyager 1 and 2 missions. In information theory terms, this scheme has a minimum Hamming Distance of 8, giving detection of up to seven bit errors. This Golay code implementation is capable of correcting three-bit errors in each 24-bit block, with 12 bits available for payload. That’s what the numbers in those brackets mean.

More after the break…

Another interesting problem is paper stretch during printing. A laser printer works by feeding the paper around rollers, some of which are heated. As a printer wears or gets dirty, the friction coefficient along the rollers can vary, leading to twisting and stretching of the paper during the printing process. Water absorbed by the paper can also lead to distortion. To compensate for these effects, Optar regularly inserts calibration targets throughout the bit image, which are used to locally resynchronize the decoding process as the image is processed. This is roughly similar to how the alignment patterns work within larger QR codes. Finally, similar to the position detection targets (those square bits) in QR codes, Optar uses a two-pixel-wide border around the bit image. The border is used to align to the corners well enough to locate the rows of bits to be decoded.

In the distant past of last week, we covered a similar project that uses QR codes. This got us thinking about how QR codes work, and even if encoding capacity can be increased using more colors than just black and white?

Thanks to [Petr] for the tip!


hackaday.com/2024/09/15/archiv…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

New note by cybersecurity
poliverso.org/display/0477a01e…
L’utilità della tecnologia edoardolimone.com/2024/09/15/l…@Informatica (Italy e non Italy 😁)Da qualche mese si cominciano a leggere articoli che sembrano riproporzionare l’importanza di talune tecnologie di cui finora si è parlato molto. Tra queste, ovviamente, c’è anche l’intelligenza artificiale… Cosa […]L'articolo L’utilità della tecnologia proviene da Edoardo Limone.L'articolo proviene dal blo


L’utilità della tecnologia


@Informatica (Italy e non Italy 😁)
Da qualche mese si cominciano a leggere articoli che sembrano riproporzionare l’importanza di talune tecnologie di cui finora si è parlato molto. Tra queste, ovviamente, c’è anche l’intelligenza artificiale… Cosa […]
L'articolo L’utilità della tecnologia proviene da Edoardo Limone.

L'articolo proviene dal blog dell'esperto di #Cybersecurity


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Mastercard acquista per 2,65 Miliardi di dollari Recorded Future
poliverso.org/display/0477a01e…
Mastercard acquista per 2,65 Miliardi di dollari Recorded FutureMastercard ha deciso di potenziare la propria infrastruttura di sicurezza informatica redhotcyber.com/rubriche/alla-… acquistando la società di intelligence delle minacce globali Recorded Future dalla societàdi private equity Insight Partners per 2,65 miliardi di dollari.L’emittente di carte di credito


Mastercard acquista per 2,65 Miliardi di dollari Recorded Future


Mastercard ha deciso di potenziare la propria infrastruttura di sicurezza informatica acquistando la società di intelligence delle minacce globali Recorded Future dalla società
di private equity Insight Partners per 2,65 miliardi di dollari.

L’emittente di carte di credito ha affermato giovedì che l’acquisizione “rafforza le intuizioni e l’intelligence utilizzate per proteggere l’economia digitale odierna, nell’ecosistema dei pagamenti e oltre“. La società ha affermato che la necessità di una difesa informatica olistica e globale “non è mai stata così grande”.

Si prevede che la transazione si concluda nel primo trimestre del prossimo anno.

L’intelligenza artificiale utilizzata per analizzare le potenziali minacce


Mastercard ha affermato che Recorded Future utilizza l’intelligenza artificiale (IA) per analizzare miliardi di dati per identificare potenziali minacce. Ha aggiunto che questa combinazione “consentirà lo sviluppo di pratiche ancora più solide e guiderà maggiori sinergie nella sicurezza informatica e nell’intelligence, rafforzando il marchio Mastercard come marchio di fiducia”.

Giovedì pomeriggio le azioni Mastercard hanno registrato un leggero rialzo, raggiungendo il massimo storico di oltre 490 dollari.

Nel 2007, i co-fondatori di Recorded Future, Christopher Ahlberg e Staffan Truvé, hanno depositato un brevetto per un sistema di analisi dei dati che utilizza l’apprendimento automatico per raccogliere e analizzare informazioni dal web. L’azienda è stata ufficialmente costituita nel 2009, ricevendo finanziamenti iniziali da Google e In-Q-Tel.

Breve storia di Recorded Future


Nel 2012, Recorded Future ha iniziato a concentrarsi sull’intelligence delle minacce informatiche, e nel 2014 ha lanciato Recorded Future Dark Web, espandendo le sue capacità di analisi sul dark web. Nel 2017, ha introdotto l’Insikt Group, il suo braccio di ricerca per l’intelligence delle minacce.

Nel 2019, Recorded Future è stata acquisita dalla società di private equity Insight Partners per 780 milioni di dollari. Nel 2020, ha lanciato un’agenzia di stampa sulla sicurezza informatica chiamata “The Record”. Nel 2023, l’azienda ha introdotto Recorded Future AI, un modello basato su OpenAI GPT per arricchire le analisi di sicurezza. Infine, nel 2024, MasterCard ha acquisito Recorded Future per 2,65 miliardi di dollari.

L'articolo Mastercard acquista per 2,65 Miliardi di dollari Recorded Future proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

An 80386 Upgrade Deal and Intel 486 Competitor: the Cyrix Cx486DLC
poliverso.org/display/0477a01e…
An 80386 Upgrade Deal and Intel 486 Competitor: the Cyrix Cx486DLCThe x86 CPU landscape of the 1980s and 1990s was competitive in a way that probably seems rather alien to anyone used to the duopoly that exists today between AMD and Intel. At one point in time, Cyrix was a major player, who mostly sought to provide a good deal that would undercut Intel. One such


An 80386 Upgrade Deal and Intel 486 Competitor: the Cyrix Cx486DLC


The x86 CPU landscape of the 1980s and 1990s was competitive in a way that probably seems rather alien to anyone used to the duopoly that exists today between AMD and Intel. At one point in time, Cyrix was a major player, who mostly sought to provide a good deal that would undercut Intel. One such attempt was the Cx486DLC and the related Tx486DLC by Texas Instruments. These are interesting because they fit in a standard 386DX mainboard, are faster than a 386 CPU, and add i486 instructions. Check your mainboard though, as these parts require a mainboard that supports them.

This is something that [Bits und Bolts] over at YouTube discovered as well when poking at a TX486DLC (TI486DLC) CPU. The Ti version of the Cyrix Cx486DLC CPU increases the 1 kB L1 cache to 8 kB but is otherwise essentially the same. He found the CPU and the mainboard in the trash and decided to adopt it. After removing the very dead battery from the Jamicon KMC-40A Baby AT mainboard, the mainboard was found to be in good working order. The system fired right up with the Ti CPU, some RAM, and a video card installed.

That’s when the excitement began, as although the mainboard is ‘Cyrix-aware’, its BIOS support is somewhat buggy. Although it technically will beat the living tar out of a 386, the Speedsys benchmark utility was crashing because the internal L1 cache wasn’t being enabled properly. Fixing the problem required an external Cyrix utility application. These issues were why so few people were interested in bolt-on solutions. The sentiment extended to Intel with their ill-fated Pentium OverDrive products.

For enthusiasts looking for a good deal, they were an exciting option, but Intel took offense to Cyrix barging into the x86 CPU market without a negotiated license. Cyriz instead utilized reverse engineering to make their own x86-compatible designs. This included their later 5×86 and 6×86 CPUs. After a series of lawsuits Cyrix was merged into National Semiconductor and later sold to AMD, who sold Cyrix’s latest designs under the Geode name before discontinuing it in 2019.

youtube.com/embed/XxzDE6aDAA8?…


hackaday.com/2024/09/15/an-803…


The Privacy Post ha ricondiviso questo.

Frodi Sentimentali: Oltre 2,7 Milioni Riciclati da una Donna della Florida
poliverso.org/display/0477a01e…
Frodi Sentimentali: Oltre 2,7 Milioni Riciclati da una Donna della FloridaUna donna della Florida si è dichiarata colpevole di aver partecipato a una cospirazione internazionale per riciclare milioni di dollari ottenuti da truffe romantiche, inviando i fondi a un complice all’estero.Secondo i documenti del tribunale, justice.gov/opa/pr/florida-wom…


Frodi Sentimentali: Oltre 2,7 Milioni Riciclati da una Donna della Florida


Una donna della Florida si è dichiarata colpevole di aver partecipato a una cospirazione internazionale per riciclare milioni di dollari ottenuti da truffe romantiche, inviando i fondi a un complice all’estero.

Secondo i documenti del tribunale, Christine Petitfrere, 30 anni, residente a Miramar, ha gestito conti bancari utilizzati per ricevere denaro proveniente da truffe sentimentali. Dopo aver ricevuto i fondi dalle vittime, Petitfrere tratteneva una parte come commissione personale, mentre il resto veniva trasferito a un suo complice al di fuori degli Stati Uniti. In totale, Petitfrere ha riciclato oltre 2,7 milioni di dollari, guadagnando centinaia di migliaia di dollari per il suo ruolo nella frode.

Le truffe sentimentali coinvolgono la creazione di falsi profili online, spesso su piattaforme di incontri, per guadagnare la fiducia e l’affetto delle vittime, per poi sfruttarle finanziariamente. Questo tipo di frode non solo provoca ingenti perdite economiche, ma infligge anche gravi danni emotivi, specialmente a persone vulnerabili, come gli anziani. La Federal Trade Commission (FTC) ha stimato che nel 2023, gli americani hanno perso circa 1,14 miliardi di dollari a causa di queste truffe.

“Le truffe romantiche causano non solo perdite finanziarie significative, ma infliggono anche profonde sofferenze emotive a innumerevoli individui”, ha dichiarato Brian Boynton, vice procuratore generale della divisione civile del Dipartimento di Giustizia. “Questa condanna evidenzia l’impegno del dipartimento nel distruggere le reti criminali che sfruttano le vulnerabilità delle persone con schemi sofisticati.”

Petitfrere sarà condannata l’11 dicembre presso il tribunale federale del Distretto Meridionale della Florida e rischia una pena massima di 10 anni di carcere. La condanna definitiva sarà decisa da un giudice federale, che prenderà in considerazione le linee guida delle US Sentencing Guidelines e altri fattori legali.

L’FBI di Miami ha condotto le indagini, mentre Matthew Robinson e Lauren M. Elfner, avvocati della Sezione per la Protezione dei Consumatori del Dipartimento di Giustizia, sono a capo del processo.

Per le vittime di frodi finanziarie, specialmente se di età superiore ai 60 anni, è disponibile una linea di assistenza del Dipartimento di Giustizia, la National Elder Fraud Hotline (1-833-FRAUD-11), che offre supporto e risorse per affrontare questo tipo di crimini. I case manager sono disponibili dal lunedì al venerdì dalle 10:00 alle 18:00 ET, offrendo supporto in inglese, spagnolo e altre lingue. Segnalare tempestivamente può contribuire a recuperare parte delle perdite finanziarie e a fermare i truffatori.

L'articolo Frodi Sentimentali: Oltre 2,7 Milioni Riciclati da una Donna della Florida proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

G4 Mac Mini is a Wolf in Apple IIc Clothing
poliverso.org/display/0477a01e…
G4 Mac Mini is a Wolf in Apple IIc ClothingRestomods let us relive some of the glory days of industrial design with internals that would blow the socks off the original device. [Mental Hygiene] decided to update an Apple IIc with a G4 brain flickr.com/photos/charles_mang….Starting with a broken IIc, they pulled the internals, including the venerable 6502, and transplanted the parts from


G4 Mac Mini is a Wolf in Apple IIc Clothing


A beige computer monitor with a green glow sits atop a flat, beige Apple IIc with a mouse next to it on a dark wooden table. A vase full of bright pink flowers is in the background.

Restomods let us relive some of the glory days of industrial design with internals that would blow the socks off the original device. [Mental Hygiene] decided to update an Apple IIc with a G4 brain.

Starting with a broken IIc, they pulled the internals, including the venerable 6502, and transplanted the parts from a G4 Mac mini into the case. There was plenty of room for the small desktop and its power supply. We love how they were able to repurpose the 5 1/4″ floppy access on the side of the IIc as a DVD drive.

A Mac OSX install DVD peeks out from the disc slot on a beige Apple IIc. You'd never guess this was originally a floppy drive.The original keyboard was adapted with an Arduino Teensy into a USB unit for the mini, but the internals of the mouse were replaced with a modern USB laser mouse running the signals over the original connector. What really sells this particular restomod is the “VGA adapter that outputs monochrome NTSC via RCA” allowing a vintage Apple CRT to make this look like a device that somehow upgraded all the way to OSX.

This mod looks to be from 2012, so we’re wondering if it’s time someone did this with an Apple Silicon mini? We’ve previously covered a few different minis inside G4 iMacs. We’ve even seen someone tackle the Compact Macintosh with an iPad mini.


hackaday.com/2024/09/15/g4-mac…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

An Espresso Machine for the DIY Crowd
poliverso.org/display/0477a01e…
An Espresso Machine for the DIY CrowdWant to build your own espresso machine, complete with open-source software to drive it? The diypresso.com/ might be right up your alley. hackaday.com/wp-content/upload…diyPresso parts, laid out and ready for assembly.It might not be the cheapest road to obtaining an espresso machine, but it’s probably the most economical way to turn high-quality


An Espresso Machine for the DIY Crowd


Want to build your own espresso machine, complete with open-source software to drive it? The diyPresso might be right up your alley.
diyPresso parts, laid out and ready for assembly.
It might not be the cheapest road to obtaining an espresso machine, but it’s probably the most economical way to turn high-quality components (including a custom-designed boiler) and sensors into a machine of a proven design.

Coffee and the machines that turn it into a delicious beverage are fertile ground for the type of folk who like to measure, modify, and optimize. We’ve seen DIY roasters, grinders, and even a manual lever espresso machine. There are also many efforts at modifying existing machines with improved software-driven controls but this is the first time we’ve seen such a focused effort at bringing the DIY angle to a ground-up espresso machine specifically offered as a kit.

Curious to know more? Browse the assembly manual or take a peek at the software’s GitHub repository. You might feel some ideas start to flow for your next coffee hack.


hackaday.com/2024/09/15/an-esp…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Non-planar Ironing Makes Smooth Prints
poliverso.org/display/0477a01e…
Non-planar Ironing Makes Smooth PrintsIf you want to smooth out the top surface of your FDM 3D prints, you can try ironing. Many slicers allow you to set this option, which drags the hot printhead through the top surface with a tiny bit of plastic to smooth out the extrusion lines. However, a recent paper explains how non-planar ironing can provide a better result


Non-planar Ironing Makes Smooth Prints


If you want to smooth out the top surface of your FDM 3D prints, you can try ironing. Many slicers allow you to set this option, which drags the hot printhead through the top surface with a tiny bit of plastic to smooth out the extrusion lines. However, a recent paper explains how non-planar ironing can provide a better result.

Usually, non-planar printing requires rotating the print bed in addition to the normal linear motion. However, you can also manipulate the layer height in real time to create bulges in the 3D print. This is the approach taken by Curvislicer, which shares authors with this paper. Another approach is to build a part conventionally but add non-planar printing to the last few layers.

The non-planar ironing is a variation of the latter technique. After slicing, the top layer of g-code passes through a Python script. The results on a test object look very impressive. We’d be interested to see how some more complex shapes look, though.

Of course, it looks like all you need is an ordinary printer, a modified copy of Slic3r, and the script, so if you try it yourself, let us know what you think. It would be great to smooth prints without extra chemicals and post-processing. While you can get good results, it is a lot of work.


hackaday.com/2024/09/15/non-pl…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Watch NASA’s Solar Sail Reflect Brightly in the Night Sky
poliverso.org/display/0477a01e…
Watch NASA’s Solar Sail Reflect Brightly in the Night SkyNASA’s ACS3 (Advanced Composite Solar Sail System) is currently fully deployed in low Earth orbit, and stargazers can spot it if they know what to look for smithsonianmag.com/smart-news/…. It’s actually one of the brightest things in the night sky. When the conditions are right, anyway.


Watch NASA’s Solar Sail Reflect Brightly in the Night Sky


NASA’s ACS3 (Advanced Composite Solar Sail System) is currently fully deployed in low Earth orbit, and stargazers can spot it if they know what to look for. It’s actually one of the brightest things in the night sky. When the conditions are right, anyway.
ACS3’s sail is as thin as it is big.
What conditions are those? Orientation, mostly. ACS3 is currently tumbling across the sky while NASA takes measurements about how it acts and moves. Once that’s done, the spacecraft will be stabilized. For now, it means that visibility depends on the ACS’s orientation relative to someone on the ground. At it’s brightest, it appears as bright as Sirius, the brightest star in the night sky.

ACS3 is part of NASA’s analysis and testing of solar sail technology for use in future missions. Solar sails represent a way of using reflected photons (from sunlight, but also possibly from a giant laser) for propulsion.

This perhaps doesn’t have much in the way of raw energy compared to traditional thrusters, but offers low cost and high efficiency (not to mention considerably lower complexity and weight) compared to propellant-based solutions. That makes it very worth investigating. Solar sail technology aims to send a probe to Alpha Centauri within the next twenty years.

Want to try to spot ACS3 with your own eyes? There’s a NASA app that can alert you to sighting opportunities in your local time and region, and even guide you toward the right region of the sky to look. Check it out!


hackaday.com/2024/09/15/watch-…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Il Primo Robot Cafe in Africa Orientale: Camerieri Robot al Servizio
poliverso.org/display/0477a01e…
Il Primo Robot Cafe in Africa Orientale: Camerieri Robot al ServizioIn uno dei ristoranti della capitale del Kenya, Nairobi, i visitatori possono assistere a uno spettacolo insolito: i camerieri robot consegnano i piatti ai tavoli dei clienti. In questo ristorante, chiamato Robot Cafe, tre robot, di nome Claire, R24 e Nadia, si muovono tra i camerieri umani,


Il Primo Robot Cafe in Africa Orientale: Camerieri Robot al Servizio


In uno dei ristoranti della capitale del Kenya, Nairobi, i visitatori possono assistere a uno spettacolo insolito: i camerieri robot consegnano i piatti ai tavoli dei clienti. In questo ristorante, chiamato Robot Cafe, tre robot, di nome Claire, R24 e Nadia, si muovono tra i camerieri umani, impressionando gli ospiti con il loro servizio. Questa struttura è considerata la prima nel suo genere non solo a Nairobi, ma in tutta l’Africa orientale.

Nairobi si è affermata da tempo come hub tecnologico della regione, guadagnandosi il soprannome di “Silicon Savannah” grazie alle sue numerose startup e innovazioni. L’introduzione dei robot nel settore della ristorazione conferma lo status di leader tecnologico della città.

I robot del Robot Cafe sono stati acquistati per intrattenere i clienti e, sebbene importarli non fosse economico, il proprietario del ristorante Mohammed Abbas afferma che ne è valsa la pena. Lo stabilimento è popolare e attira molti clienti curiosi che vogliono sperimentare il servizio robot.

Tuttavia, nonostante l’attrattiva della tecnologia, i robot non possono ancora sostituire completamente il lavoro umano. Eseguono solo compiti semplici: informano i clienti che il loro ordine è pronto e richiedono loro di premere un pulsante per completare il servizio. I robot sono controllati tramite un’app per tablet, mentre i camerieri umani svolgono ancora un ruolo importante nel servire gli ospiti, prendere gli ordini e consegnare le bevande.

Gli esperti ritengono che tali tecnologie potrebbero cambiare il mercato del lavoro in futuro, soprattutto in Africa, dove l’età media della popolazione è di soli 19 anni. Tuttavia, i robot non sono ancora in grado di sostituire completamente l’uomo nel settore della ristorazione.

Ad esempio, al Robot Cafe, i camerieri robotici si limitano a integrare il servizio umano, offrendo ai clienti un’esperienza unica, ma non sostituiscono il calore umano e l’attenzione che sono importanti per molti clienti.

Pertanto, l’introduzione dei robot nel settore dei servizi apre nuove opportunità per combinare automazione e servizi tradizionali, soddisfacendo così una varietà di preferenze dei clienti.

L'articolo Il Primo Robot Cafe in Africa Orientale: Camerieri Robot al Servizio proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

San Pietroburgo vieta l’uso di WhatsApp e Telegram per comunicazioni ufficiali. Si passa all’App Nazionale eXpress
poliverso.org/display/0477a01e…
San Pietroburgo vieta l’uso di WhatsApp e Telegram per comunicazioni ufficiali. Si passa all’App Nazionale eXpressI capi di tutti gli organi esecutivi di San Pietroburgo hanno ricevuto istruzioni di vietare l’uso di servizi di messaggistica istantanea stranieri per lo scambio di informazioni ufficiali. L’ordinanza ha


San Pietroburgo vieta l’uso di WhatsApp e Telegram per comunicazioni ufficiali. Si passa all’App Nazionale eXpress


I capi di tutti gli organi esecutivi di San Pietroburgo hanno ricevuto istruzioni di vietare l’uso di servizi di messaggistica istantanea stranieri per lo scambio di informazioni ufficiali. L’ordinanza ha interessato anche applicazioni popolari come WhatsApp e Telegram.

Secondo le informazioni ricevute dalla pubblicazione Fontanka, il 4 settembre il Comitato per l’informazione e la comunicazione ha inviato una lettera in tal senso. Successivamente, le istituzioni subordinate hanno ricevuto notifiche simili dai comitati che le controllavano, ma sotto forma di divieto categorico.

Fonte “Fontanka”

Nella lettera, firmata dal capo del comitato, si afferma che il divieto viene introdotto per prevenire casi di “compromissione, distruzione o modifica di informazioni ad accesso limitato”, nonché per eliminare l’emergere di precondizioni per tali incidenti.

In alternativa ai messenger stranieri si propone di utilizzare la piattaforma di comunicazione aziendale nazionale eXpress. Gli sviluppatori posizionano il loro prodotto come “l’unica Super App aziendale certificata dall’FSTEC della Federazione Russa”, implementata in grandi aziende con una copertura di decine e centinaia di migliaia di utenti.

Il messenger eXpress è stato sviluppato dalla società moscovita Unlimited Production, di proprietà di Andrey Vratsky. Nel 2023 l’azienda ha realizzato un fatturato superiore al miliardo di rubli (Circa 10 milioni di euro). Ha più volte stipulato contratti per la fornitura di licenze per il suo software a organizzazioni e istituzioni governative.

L'articolo San Pietroburgo vieta l’uso di WhatsApp e Telegram per comunicazioni ufficiali. Si passa all’App Nazionale eXpress proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

AGI ma in Sicurezza! Il fondatore di OpenAi crea Safe Superintelligence: 1 miliardo di dollari di finanziamento
poliverso.org/display/0477a01e…
AGI ma in Sicurezza! Il fondatore di OpenAi crea Safe Superintelligence: 1 miliardo di dollari di finanziamentoQualche mese fa ci eravamo lasciati con la decisione del fondatore di OpenAi, Ilya Sutskever di lasciare l’azienda redhotcyber.com/post/ilya-suts… e per imbattersi in una nuova per importante avventura.Ancora


AGI ma in Sicurezza! Il fondatore di OpenAi crea Safe Superintelligence: 1 miliardo di dollari di finanziamento


Qualche mese fa ci eravamo lasciati con la decisione del fondatore di OpenAi, Ilya Sutskever di lasciare l’azienda e per imbattersi in una nuova per importante avventura.

Ancora non sapevamo nulla di quali fossero le reali intenzioni del genio dell’intelligenza artificiale. Recentemente ha ottenuto un finanziamento straordinario di 1 miliardo di dollari per la sua startup, dedicata a sviluppare un’intelligenza artificiale superintelligente con un focus sulla sicurezza. Questo annuncio segna un’importante evoluzione nel campo dell’IA, evidenziando l’urgenza di affrontare le sfide legate alla sicurezza e al controllo di tecnologie avanzate.

Il co-fondatore di OpenAI, Ila, ha recentemente ottenuto un finanziamento straordinario di 1 miliardo di dollari per la sua startup, dedicata a sviluppare un’intelligenza artificiale superintelligente con un focus sulla sicurezza. Questo annuncio segna un’importante evoluzione nel campo dell’IA, evidenziando l’urgenza di affrontare le sfide legate alla sicurezza e al controllo di tecnologie avanzate.

Un Obiettivo Ambizioso


La startup di Sutskever si propone di creare una superintelligenza artificiale che non solo eccelle nelle sue capacità intellettive, ma che è progettata con rigorosi meccanismi di sicurezza per prevenire eventuali rischi. Questo progetto è particolarmente significativo in un momento in cui le preoccupazioni relative all’IA stanno crescendo e la necessità di soluzioni sicure diventa sempre più pressante.

Il Finanziamento e i Suoi Impatti


Il miliardo di dollari raccolto rappresenta uno degli investimenti più sostanziali nel campo dell’IA e conferma l’interesse e la fiducia nella visione di Sutskever. Questo capitale consentirà alla startup di accelerare il suo sviluppo e di garantire che le risorse adeguate siano destinate alla gestione dei potenziali rischi e alla realizzazione di una tecnologia affidabile e sicura.

L’Importanza della Sicurezza nell’IA


L’iniziativa di Sutskever risponde a una crescente consapevolezza della necessità di controllare e limitare i rischi associati all’IA superintelligente. Con l’avanzamento rapido delle tecnologie, è essenziale che le nuove forme di intelligenza artificiale siano progettate con misure di sicurezza integrate per evitare conseguenze indesiderate e garantire che il loro impatto sia positivo e controllabile.

Reazioni e Opinioni del Settore


Il progetto ha attirato l’attenzione e l’interesse di esperti del settore, che si sono espressi favorevolmente sulla missione di Sutskever, apprezzando l’approccio proattivo verso la sicurezza. Tuttavia, alcuni esperti rimangono scettici sulla fattibilità di mantenere un controllo totale su una forma di intelligenza così avanzata e sollevano interrogativi su come saranno gestiti i potenziali problemi etici e pratici.

Prospettive Future


L’iniziativa di Sutskever segna un passo significativo verso il futuro dell’IA e potrebbe avere un impatto duraturo sul modo in cui sviluppiamo e utilizziamo queste tecnologie. Con un obiettivo chiaro e un sostegno finanziario notevole, questa startup potrebbe non solo avanzare la ricerca sull’IA, ma anche stabilire nuovi standard per la sicurezza e l’etica nel settore.

L'articolo AGI ma in Sicurezza! Il fondatore di OpenAi crea Safe Superintelligence: 1 miliardo di dollari di finanziamento proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Cast21 Brings Healing Into 2024
poliverso.org/display/0477a01e…
Cast21 Brings Healing Into 2024It takes but an ill-fated second to break a bone, and several long weeks for it to heal in a cast. And even if you have one of those newfangled fiberglass casts, you still can’t get the thing wet, and it’s gonna be itchy under there because your skin can’t breathe. Isn’t it high time for something better?Enter cast21.com/, co-founded by Chief Technical Officer [Jason


Cast21 Brings Healing Into 2024


Five colors of Cast21 on five different wrists.

It takes but an ill-fated second to break a bone, and several long weeks for it to heal in a cast. And even if you have one of those newfangled fiberglass casts, you still can’t get the thing wet, and it’s gonna be itchy under there because your skin can’t breathe. Isn’t it high time for something better?

Enter Cast21, co-founded by Chief Technical Officer [Jason Troutner], who has been in casts more than 50 times due to sports injuries and surgeries. He teamed up with a biomedical design engineer and an electrical engineer to break the norms associated with traditional casts and design a new solution that addresses their drawbacks.

A medical professional fills a Cast21 with purple resin.So, how does it work already? The latticework cast is made from a network of silicone tubes that harden once injected with resin and a catalyst mixture. It takes ten seconds to fill the latticework with resin and three minutes for it to cure, and the whole process is much faster than plaster or fiberglass.

This new cast can be used along with electrical stimulation therapy, which can reduce healing time and prevent muscle atrophy.

Cast21 is not only breathable, it’s also waterproof, meaning no more trash bags on your arm to take a shower. The doctor doesn’t even need a saw to remove it, just cut in two places along the seam. It can even be used as a splint afterward.

It’s great to see advancements in simple medical technologies like the cast. And it looks almost as cool as this 3D-printed exoskeleton cast we saw ten years ago.

Thanks to [Keith Olson] for the tip!


hackaday.com/2024/09/14/cast21…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Taking Back The Internet With The Tildeverse
poliverso.org/display/0477a01e…
Taking Back The Internet With The TildeverseFor many of us of a particular vintage, the internet blossomed in the ’90s with the invention of the Web and just a few years of development. Back then, we had the convenience of expression on the WWW and the backup of mature services such as IRC for all that other stuff we used to get up to. Some of us still hang out there. Then something


Taking Back The Internet With The Tildeverse


For many of us of a particular vintage, the internet blossomed in the ’90s with the invention of the Web and just a few years of development. Back then, we had the convenience of expression on the WWW and the backup of mature services such as IRC for all that other stuff we used to get up to. Some of us still hang out there. Then something happened. Something terrible. Big-commerce took over, and it ballooned into this enormously complex mess with people tracking you every few seconds and constantly trying to bombard you with marketing messages. Enough now. Many people have had enough and have come together to create the Tildeverse, a minimalist community-driven internet experience.
A collaborative Minecraft server hosted on a Tilde site
Tilde, literally ‘ ~ ‘, is your home on the internet. You can work on your ideas on a shared server or run your own. Tilde emphasises the retro aesthetic by being minimal and text-orientated. Those unfamiliar with a command line may start getting uncomfortable, but don’t worry—help is at hand. The number of activities is too many to list, but there are a few projects, such as a collaborative Sci-Fi story, a radio station, and even a private VoIP server. Gamers are catered for as long as you like Minecraft, but we think that’s how it should go.

The Tildeverse also supports Gopher and the new Gemini protocol, giving some people a few more options with which to tinker. The usual method to gain access is to first sign up on a server, then SSH into it; you’re then taken to your little piece of the internet, ready to start your minimalist journey into the Tildeverse.

A couple of videos after the break go into much more detail about the whys and hows of the Tildeverse and are worth a chunk of your time.

We’ve talked about the ‘small web’ before. Here’s our guide to Gemini.

youtube.com/embed/qK1mInnbfrU?…

youtube.com/embed/I2Q35uFCq8Q?…

Thanks to [Andrew] for the tip!


hackaday.com/2024/09/14/taking…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

An Earth-Bound Homage to a Martian Biochemistry Experiment
poliverso.org/display/0477a01e…
An Earth-Bound Homage to a Martian Biochemistry ExperimentWith all the recent attention on Mars and the search for evidence of ancient life there, it’s easy to forget that not only has the Red Planet been under the figurative microscope since the early days of the Space Race, but we went to tremendous effort to send a pair of miniaturized biochemical laboratories there


An Earth-Bound Homage to a Martian Biochemistry Experiment


With all the recent attention on Mars and the search for evidence of ancient life there, it’s easy to forget that not only has the Red Planet been under the figurative microscope since the early days of the Space Race, but we went to tremendous effort to send a pair of miniaturized biochemical laboratories there back in 1976. While the results were equivocal, it was still an amazing piece of engineering and spacefaring, one that [Marb] has recreated with this Earth-based version of the famed Viking “Labeled Release” experiment.

The Labeled Release experimental design was based on the fact that many metabolic processes result in the evolution of carbon dioxide gas, which should be detectable by inoculating a soil sample with a nutrient broth laced with radioactive carbon-14. For this homage to the LR experiment, [Marb] eschewed the radioactive tracer, instead looking for a relative increase in the much lower CO2 concentration here on Earth. The test chamber is an electrical enclosure with a gasketed lid that holds a petri dish and a simple CO2 sensor module. Glands in the lid allow an analog for Martian regolith — red terrarium sand — and a nutrient broth to be added to the petri dish. Once the chamber was sterilized, or at least sanitized, [Marb] established a baseline CO2 level with a homebrew data logger and added his sample. Adding the nutrient broth — a solution of trypsinized milk protein, yeast extract, sugar, and salt — gives the bacteria in the “regolith” all the food they need, which increases the CO2 level in the chamber.

More after the break…

[Marb]’s results are not surprising by any means, but that’s hardly the point. This is just a demonstration of the concept of the LR experiment, one that underscores the difficulties of doing biochemistry on another planet and the engineering it took to make it happen. Compared to some of the instruments rolling around Mars today, the Viking experiments seem downright primitive, and the fact that they delivered even the questionable data they did is pretty impressive.

youtube.com/embed/8T492TxZCrI?…


hackaday.com/2024/09/14/an-ear…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Create Custom Gridfinity Boxes Using Images Of Tools
poliverso.org/display/0477a01e…
Create Custom Gridfinity Boxes Using Images Of ToolsExhibit A: A standard-issue banana.We love it when a community grabs hold of an idea and runs wild with it despite obvious practicality issues. Gridfinity by YouTuber [Zach Freedman] is one of those concepts. For the unaware, this is a simple storage system standard, defining boxes to hold your things. These boxes can be


Create Custom Gridfinity Boxes Using Images Of Tools



Exhibit A: A standard-issue banana.
We love it when a community grabs hold of an idea and runs wild with it despite obvious practicality issues. Gridfinity by YouTuber [Zach Freedman] is one of those concepts. For the unaware, this is a simple storage system standard, defining boxes to hold your things. These boxes can be stacked and held in place in anything from a desk drawer to hanging off the side of a 3D printer. [Georgs Lazdāns] is one such Gridfinity user who wanted to create tool-specific holders without leaving the sofa. To do so, they made a web application using node.js and OpenCV to extract outlines for tools (or anything else) when photographed on a blank sheet of paper.

The OpenCV stack assumes that the object to be profiled will be placed on a uniformly colored paper with all parts of its outline visible. The first part of the stack uses a bilateral filter to denoise the image whilst keeping edge details.
Make a base, then add a banana. Easy!
Next, the image is converted to greyscale, blurred, and run through an adaptive threshold. This converts the image to monochrome, again preserving edge details. Finally, the Canny algorithm pulls out the paper contour. The object outline can be given an accurate scale with the paper contour and paper size specified. The second part of the process works similarly to extract the object outline. The second contour should follow the object pretty accurately. If it doesn’t, it can be manually tweaked in the editor. Once a contour is captured, it can be used to modify a blank Gridfinity base in the model editor.

With a few tweaks to the OpenCV parameters, we were able to create a usable profile from an image of a banana (obviously, Gridfinity is the perfect snack storage system). From there, inside the model editor, we adjusted the box outline to encompass it. Then, we cut out the traced profile to create our banana holder. The web app allows you to download an STL file, which can be fed into your slicer of choice. We would have printed the thing but accidentally ate the banana. Ah well.

More information can be found on the project’s GitHub page.

We’ve touched on Gridfinity before; here’s our first article. Of course, we can’t talk about making outlines of tools for storage without mentioning shadow boards. Finally, on the subject of the awesome OpenCV, it has many, many uses, including catching a dirty stinkin’ thief.

Thanks to [JohnU] for the tip!


hackaday.com/2024/09/14/create…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Ivanti sotto Attacco! Il CISA conferma lo Sfruttamento Attivo del Bug
poliverso.org/display/0477a01e…
Ivanti sotto Attacco! Il CISA conferma lo Sfruttamento Attivo del BugUna versione ormai fuori produzione del software di gestione dei servizi IT cloud di Ivanti presenta una vulnerabilità redhotcyber.com/post/vulnerabi… recentemente rilasciata che, secondo la Cybersecurity and Infrastructure Security Agency (CISA) degli Stati Uniti D’America, è in fase di


Ivanti sotto Attacco! Il CISA conferma lo Sfruttamento Attivo del Bug


Una versione ormai fuori produzione del software di gestione dei servizi IT cloud di Ivanti presenta una vulnerabilità recentemente rilasciata che, secondo la Cybersecurity and Infrastructure Security Agency (CISA) degli Stati Uniti D’America, è in fase di sfruttamento.

CISA ha avvertito che le organizzazioni dotate di Cloud Service Appliance di Ivanti versione 4.6 e precedenti sono state prese di mira dagli hacker criminali e il bug è stato aggiunto all’elenco delle vulnerabilità note sfruttate (KEV). Venerdì, l’azienda con sede nello Utah ha affermato che un “numero limitato di clienti” ha confermato lo sfruttamento, ma non ha fornito ulteriori dettagli.

Inoltre, il bug è l’ultimo della versione end-of-life, ha detto Ivanti, quindi le organizzazioni dovrebbero aggiornare a CSA 5.0 per ulteriori aggiornamenti di sicurezza. Il bug, una vulnerabilità di iniezione di comandi del sistema operativo, consente a un hacker criminale con diritti di amministratore nel software di ottenere l’esecuzione di codice remoto del dispositivo.

“CSA 5.0 è l’unica versione supportata e non contiene questa vulnerabilità”, ha osservato Ivanti. Inoltre, Ivanti ha affermato che “le configurazioni CSA dovrebbero essere dual-homed con eth0 come rete interna”.

La vulnerabilità, CVE-2024-8190 , è stata resa pubblica per la prima volta il 10 settembre e all’epoca non erano noti exploit pubblici. Per trovare prove di compromissione, Ivanti suggerisce di esaminare il Cloud Service Appliance per rilevarei nuovi utenti amministratori.

Le agenzie civili federali sono tenute ad attenuare quanto riportato dal CISA entro 60 giorni dall’aggiunta all’elenco KEV.

L'articolo Ivanti sotto Attacco! Il CISA conferma lo Sfruttamento Attivo del Bug proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Pong in a Petri Dish: Teasing Out How Brains Work
poliverso.org/display/0477a01e…
Pong in a Petri Dish: Teasing Out How Brains Work hackaday.com/wp-content/upload…Experimental setup for the EAP hydrogel free energy principle test. (Credit: Vincent Strong et al., Cell, 2024)Of the many big, unanswered questions in this Universe, the ones pertaining to the functioning of biological neural networks are probably among the most intriguing. From the lowliest neurally


Pong in a Petri Dish: Teasing Out How Brains Work



Experimental setup for the EAP hydrogel free energy principle test. (Credit: Vincent Strong et al., Cell, 2024)Experimental setup for the EAP hydrogel free energy principle test. (Credit: Vincent Strong et al., Cell, 2024)
Of the many big, unanswered questions in this Universe, the ones pertaining to the functioning of biological neural networks are probably among the most intriguing. From the lowliest neurally gifted creatures to us brainy mammals, neural networks allow us to learn, to predict and adapt to our environments, and sometimes even stand still and wonder puzzlingly how all of this even works. Such puzzling has led to a number of theories, with a team of researchers recently investigating one such theory, as published in Cell. The focus here was that of Bayesian approaches to brain function, specifically the free energy principle, which postulates that neural networks as inference engines seek to minimize the difference between inputs (i.e. the model of the world as perceived) and its internal model.

This is where Electro Active Polymer (EAP) hydrogel comes into play, as it features free ions that can migrate through the hydrogel in response to inputs. In the experiment, these inputs are related to the ball position in the game of Pong. Much like experiments involving biological neurons, the hydrogel is stimulated via electrodes (in a 2 x 3 grid, matching the 2 by 3 grid of the game world), with other electrodes serving as outputs. The idea is that over time the hydrogel will ‘learn’ to optimize the outputs through ion migration, so that it ‘plays’ the game better, which should be reflected in the scores (i.e. the rally length).

Based on the results some improvement in rally length can be observed, which the researchers present as statistically significant. This would imply that the hydrogel displays active inference and memory. Additional tests with incorrect inputs resulted in a marked decrease in performance. This raises many questions about whether this truly displays emergent memory, and whether this validates the free energy principle as a Bayesian approach to understanding biological neural networks.

To the average Star Trek enthusiast the concept of hydrogels, plasmas, etc. displaying the inklings of intelligent life would probably seem familiar, and for good reason. At this point, we do not have a complete understanding of the operation of the many billions of neurons in our own brains. Doing a bit of prodding and poking at some hydrogel and similar substances in a dish might be just the kind of thing we need to get some fundamental answers.


hackaday.com/2024/09/14/pong-i…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

6 Gruppi APT controllati dall’RGB della Corea Del Nord conducono in Silenzio una Guerra Informatica Globale
poliverso.org/display/0477a01e…
6 Gruppi APT controllati dall’RGB della Corea Del Nord conducono in Silenzio una Guerra Informatica GlobalePalo Alto Networks in un nuovo rapporto ha descritto le attività dei gruppi di redhotcyber.com/post/i-padri-f… associati all’intelligence nordcoreana. I gruppi, spesso indicati come Lazarus nei resoconti pubblici,


6 Gruppi APT controllati dall’RGB della Corea Del Nord conducono in Silenzio una Guerra Informatica Globale


Palo Alto Networks in un nuovo rapporto ha descritto le attività dei gruppi di hacker associati all’intelligence nordcoreana. I gruppi, spesso indicati come Lazarus nei resoconti pubblici, lavorano per conto del governo nordcoreano, impegnandosi in spionaggio informatico, crimini finanziari e attacchi dirompenti alle industrie di tutto il mondo.

RGB è una struttura composta da più divisioni, ognuna delle quali ha i propri obiettivi e la propria specializzazione. Ad oggi sono stati identificati sei gruppi chiave:

  1. Alluring Pisces (noto anche come Bluenoroff) – è specializzato in attacchi a istituti finanziari, società di criptovaluta e bancomat. È questo gruppo responsabile delle principali rapine informatiche.
  2. Gleaming Pisces (Citrine Sleet) – attacca le società di criptovaluta ed è associato alla campagna AppleJeus, che distribuiva false applicazioni di criptovaluta.
  3. Jumpy Pisces (Andariel) – Si concentra sullo spionaggio informatico, ma è anche noto per condurre attacchi ransomware.
  4. Selective Pisces (TEMP.Hermit) – prende di mira le aziende dei media, della difesa e dell’IT, impegnandosi sia nello spionaggio che negli attacchi alle reti con l’obiettivo di distruggerle o comprometterle.
  5. Slow Pisces (TraderTraitor) – noto per gli attacchi alle società blockchain e alle catene di fornitura, distribuisce applicazioni dannose come TraderTraitor.
  6. Sparkling Pisces (Kimsuky) – L’attività principale di questo gruppo è la raccolta di informazioni e le loro operazioni sono finanziate attraverso la criminalità informatica.


Organigramma dei gruppi nordcoreani all’interno dell’RGB
Il rapporto include anche un’analisi di 10 famiglie di malware sviluppate da gruppi nordcoreani scoperte di recente. Questi programmi, che prendono di mira Windows, macOS e Linux, vengono utilizzati per vari tipi di attacchi, come la raccolta di informazioni, l’hacking di reti aziendali e la diffusione di ransomware.

Il rapporto descrive anche malware come RustBucket, KANDYKORN, SmoothOperator, ObjCShellz e Fullhouse. Il malware copre una vasta gamma di funzioni, dall’infiltrazione nei sistemi al furto di dati e al controllo dei dispositivi infetti.

Uno dei programmi più importanti è RustBucket, un malware macOS in più fasi scoperto nel 2023. I passaggi prevedono il download e l’esecuzione di più componenti, rendendo difficile il rilevamento e la rimozione. KANDYKORN è un altro esempio di un attacco complesso in più fasi che inizia con l’ingegneria sociale, in cui la vittima viene indotta con l’inganno a eseguire uno script dannoso mascherato da un normale file.

È stato identificato anche il programma SmoothOperator che, secondo i ricercatori, veniva utilizzato per attaccare i client della popolare applicazione 3CX. Il malware era incorporato nei file di installazione e raccoglieva dati dai dispositivi infetti.

I ricercatori sottolineano che i gruppi sotto il controllo di RGB sono diventati noti grazie a incidenti di alto profilo come l’attacco a Sony Pictures nel 2014, l’epidemia globale WannaCry nel 2017 e numerosi attacchi agli scambi di criptovaluta. Le attività degli hacker nordcoreani sono in corso dal 2007 e abbracciano molti settori e regioni in tutto il mondo.

A causa della portata e della complessità delle attività dei gruppi nordcoreani, questi sono stati inclusi nella valutazione annuale sulla sicurezza di MITRE ATT&CK nel 2024 , che ne analizza i metodi, le tattiche e i software utilizzati. Palo Alto Networks, a sua volta, continua a sviluppare e migliorare soluzioni volte a proteggere le aziende dalle minacce poste da questi gruppi di hacker.

Il rapporto evidenzia la necessità di un approccio globale alla protezione delle organizzazioni per ridurre al minimo i rischi associati alle attività degli hacker statali, come i gruppi nordcoreani gestiti da RGB.

L'articolo 6 Gruppi APT controllati dall’RGB della Corea Del Nord conducono in Silenzio una Guerra Informatica Globale proviene da il blog della sicurezza informatica.


The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Always Something New Under the Sun
poliverso.org/display/0477a01e…
Always Something New Under the SunSome of the entries we got into the Tiny Games Contest have been really mind-blowing. Just as you think you’ve seen it all, for instance, alnwlsn comes along and mills the DIP-package ATtiny84 and embeds a complete Simon game in the space normally wasted by all that plastic overmolding hackaday.com/2024/09/12/2024-t…. It’s the tiniest, and most gonzo,


Always Something New Under the Sun


Some of the entries we got into the Tiny Games Contest have been really mind-blowing. Just as you think you’ve seen it all, for instance, alnwlsn comes along and mills the DIP-package ATtiny84 and embeds a complete Simon game in the space normally wasted by all that plastic overmolding. It’s the tiniest, and most gonzo, circuit-sculpture Simon we’ve ever seen.

Soldering fine wires to the leadframe of an ATtiny84 in a DIP-14 package.Now, our judges are hard at work ranking all 80 of the entries, and we have a fantastic range of entries all around, so I’m not calling any winners yet. But have you ever seen a project milled into a chip before? Nope, me neither.

What’s amazing is that this happens every time we run a contest. The second you put limitations on a project, there’s always someone out there who says “Hold my beer” and blows the limits out of the water. Indeed, the frequency with which we see someone pull off the impossible on Hackaday makes me wish I were buying more lottery tickets. You all really are stupendous.

We hope that feats like this are as inspirational to you as they are to us. No idea is too bonkers to not at least give it a try. Who knows, it might work! And when it does, please write it up and let us know. Keep the cycle of inspiration going!

This article is part of the Hackaday.com newsletter, delivered every seven days for each of the last 200+ weeks. It also includes our favorite articles from the last seven days that you can see on the web version of the newsletter. Want this type of article to hit your inbox every Friday morning? You should sign up!


hackaday.com/2024/09/14/always…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Phishing della “truffa da 1 centesimo”. Arrestato 19enne sospetto nei Paesi Bassi
poliverso.org/display/0477a01e…
Phishing della “truffa da 1 centesimo”. Arrestato 19enne sospetto nei Paesi BassiMartedì 10 settembre un uomo di 19 anni è stato arrestato politie.nl/nieuws/2024/septemb… nella città di Amersfoort perché sospettato di aver partecipato ad una truffa di redhotcyber.com/post/il-phishi…. In precedenza era stato processato tre volte per crimini simili.La


Phishing della “truffa da 1 centesimo”. Arrestato 19enne sospetto nei Paesi Bassi


Martedì 10 settembre un uomo di 19 anni è stato arrestato nella città di Amersfoort perché sospettato di aver partecipato ad una truffa di phishing. In precedenza era stato processato tre volte per crimini simili.

La polizia ha avviato un’indagine dopo aver ricevuto una denuncia da una delle banche, che riportava una serie di attacchi di phishing ai danni dei propri clienti. I truffatori hanno utilizzato una tecnica nota come “truffa da 1 centesimo”, che prevede che un utente malintenzionato si fingesse acquirente su una piattaforma di beni usati per chiedere ai venditori di fare clic su un collegamento per confermare una transazione da 1 centesimo.

In realtà, il collegamento portava a un sito di phishing in cui ignari commercianti inserirono i propri dati bancari, consentendo al truffatore di accedere ai loro conti.

Utilizzando questo schema l’aggressore ha tentato di rubare quasi 100.000 euro da diversi conti. Fortunatamente, la maggior parte delle transazioni sospette sono state bloccate dalla banca prima che fossero completate.

Nel corso delle indagini la polizia è riuscita a risalire al sospettato analizzando le tracce digitali. Durante l’arresto è stata effettuata una perquisizione nel suo domicilio, dove sono stati sequestrati diversi supporti di memorizzazione.

Le indagini sono in corso e la polizia continua a raccogliere ulteriori prove.

L'articolo Phishing della “truffa da 1 centesimo”. Arrestato 19enne sospetto nei Paesi Bassi proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Soldering, Up Close and Personal
poliverso.org/display/0477a01e…
Soldering, Up Close and PersonalA word of warning before watching this very cool video on soldering youtube.com/watch?v=m3Ny3j5nH0…: it may make you greatly desire what appears to be a very, very expensive microscope. You’ve been warned.Granted, most people don’t really need to get this up close and personal with their soldering, but as [Robert Feranec] points out, a close look at what’s going on


Soldering, Up Close and Personal


A word of warning before watching this very cool video on soldering: it may make you greatly desire what appears to be a very, very expensive microscope. You’ve been warned.

Granted, most people don’t really need to get this up close and personal with their soldering, but as [Robert Feranec] points out, a close look at what’s going on when the solder melts and the flux flows can be a real eye-opener. The video starts with what might be the most esoteric soldering situation — a ball-grid array (BGA) chip. It also happens to be one of the hardest techniques to assess visually, both during reflow and afterward to check the quality of your work. While the microscope [Robert] uses, a Keyence VHX-7000 series digital scope, allows the objective to swivel around and over the subject in multiple axes and keep track of where it is while doing it, it falls short of being the X-ray vision you’d need to see much beyond the outermost rows of balls. But, being able to look in at an angle is a huge benefit, one that allows us a glimpse of the reflow process.

More after the break

[Robert] also takes a look at other SMD packages, such as a TSSOP chip and a QFN package, as well as some through-hole terminals. He also forces a few errors, like misaligning leads or using way too much solder, just to show how fault-tolerant SMD soldering can be. The real eye-opener here was the excess tinning on the central pad of the QFN, which clearly caused problems by preventing capillary action from pulling the outer contacts down onto the pads. We’ve had that same problem ourselves, and seeing this makes us want to give that repair another go.

Kudos to [Roboert] for sharing these delicious views of what’s really going on when the solder starts to flow.

youtube.com/embed/m3Ny3j5nH0U?…


hackaday.com/2024/09/14/solder…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Gli Hacker di Lazarus si spacciano per reclutatori e ingannano gli sviluppatori Python
poliverso.org/display/0477a01e…
Gli Hacker di Lazarus si spacciano per reclutatori e ingannano gli sviluppatori PythonGli analisti di ReversingLabs avvertono reversinglabs.com/blog/fake-re… che i membri del gruppo di redhotcyber.com/post/i-padri-f… nordcoreano Lazarus si spacciano per reclutatori e offrono agli sviluppatori Python il compito di svolgere compiti di test


Gli Hacker di Lazarus si spacciano per reclutatori e ingannano gli sviluppatori Python


Gli analisti di ReversingLabs avvertono che i membri del gruppo di hacker nordcoreano Lazarus si spacciano per reclutatori e offrono agli sviluppatori Python il compito di svolgere compiti di test presumibilmente legati allo sviluppo di un falso gestore di password. In effetti, non esiste un gestore di password e tali attività contengono solo del malware.

Secondo i ricercatori, gli attacchi fanno parte della campagna VMConnect, scoperta nell’agosto 2023. Successivamente gli aggressori prendono di mira gli sviluppatori, utilizzando pacchetti Python dannosi caricati nel repository PyPI.

Secondo il rapporto che monitora questa campagna da più di un anno, i partecipanti a Lazarus stanno ora pubblicando i loro progetti dannosi su GitHub, dove le vittime possono anche trovare file README con le istruzioni su come completare l'”attività di test”. Inoltre, le istruzioni sono scritte in modo tale che tutto appaia professionale, legittimo e crei anche l’impressione di urgenza.

In questo caso gli aggressori si fingono grandi banche americane, tra cui Capital One e Rookery Capital Limited, per attirare l’attenzione dei candidati e probabilmente offrono loro condizioni e pacchetti di servizi interessanti. Le vittime hanno detto ai ricercatori che i membri di Lazarus in genere si connettono con i loro obiettivi tramite LinkedIn.

Come test, gli aggressori hanno chiesto alle loro vittime di trovare un errore in un falso gestore di password, inviare la loro soluzione e fornire screenshot come prova.

Il file README per questa “attività di test” richiedeva alle vittime di eseguire prima un’applicazione di gestione delle password dannosa (PasswordManager.py) sul proprio sistema, quindi di iniziare a cercare i bug e risolverli.

Se l’utente non si accorgesse del problema ed eseguisse il file, ciò causerebbe l’esecuzione di un modulo base64 offuscato nascosto nei file _init_.py delle librerie pyperclip e pyrebase. La stringa offuscata è il loader del malware, che contattava il proprio server di comando e controllo e attende ulteriori comandi.

Per garantire che gli utenti non controllino i file di progetto alla ricerca di malware o codice offuscato, le istruzioni nel file README indicano di completare rapidamente l’attività: 5 minuti per creare il progetto, 15 minuti per implementare la patch e altri 10 minuti per inviare il file risultato finale al “reclutatore”.

Apparentemente, tutto ciò avrebbe dovuto confermare l’esperienza della vittima nel lavorare con progetti Python e GitHub, ma in realtà gli hacker criminali hanno semplicemente costretto gli utenti a rifiutare qualsiasi controllo di sicurezza in grado di rilevare codice dannoso.

I ricercatori notano che questa campagna era attiva dal 31 luglio 2024 e rimane attiva oggi.

L'articolo Gli Hacker di Lazarus si spacciano per reclutatori e ingannano gli sviluppatori Python proviene da il blog della sicurezza informatica.


The Privacy Post ha ricondiviso questo.

Arrestato l’hacker 17enne per aver effettuato l’attacco informatico alla metropolitana di Londra
poliverso.org/display/0477a01e…
Arrestato l’hacker 17enne per aver effettuato l’attacco informatico alla metropolitana di LondraLa National Crime Agency del Regno Unito ha annunciato nationalcrimeagency.gov.uk/new… l’arresto di un adolescente di 17 anni sospettato di coinvolgimento in un attacco al Transport for London, il servizio municipale che coordina il lavoro


Arrestato l’hacker 17enne per aver effettuato l’attacco informatico alla metropolitana di Londra


La National Crime Agency del Regno Unito ha annunciato l’arresto di un adolescente di 17 anni sospettato di coinvolgimento in un attacco al Transport for London, il servizio municipale che coordina il lavoro di metropolitana, metropolitana leggera, metropolitana, tram e si occupa anche di la concessione di licenze per i taxi urbani e il trasporto pubblico acquatico.

Le autorità affermano che l’adolescente, il cui nome non è stato rilasciato, è stato arrestato con l’accusa di reati ai sensi del Computer Misuse Act in relazione all’attacco, avvenuto a Transport for London il 1 settembre 2024.

Si sa che il sospettato è stato ora interrogato e rilasciato su cauzione.

Il 1° settembre di quest’anno, i rappresentanti di Transport for London hanno riferito che il servizio aveva subito un attacco informatico, che li ha costretti a chiudere o limitare l’accesso a diversi sistemi IT per impedire la diffusione della minaccia.

Sebbene l’attacco non abbia avuto alcun impatto sulle operazioni di trasporto pubblico di Londra, ha interessato i sistemi interni di Transport for London utilizzati dal personale, nonché vari servizi di assistenza clienti online. L’incidente ha portato anche a interruzioni del servizio Dial-a-Ride, che fornisce il trasporto alle persone con disabilità.

I trasporti per i sistemi di Londra non si sono ancora completamente ripresi. Pertanto, i dipendenti continuano a dover affrontare interruzioni nel funzionamento di vari sistemi, ad esempio non possono rispondere alle richieste dei clienti inviate tramite moduli online, emettere rimborsi per viaggi pagati tramite metodi contactless e così via.

Sebbene inizialmente fosse stato riferito che durante l’attacco non erano stati rubati dati dei clienti, questa settimana Transport for London ha dichiarato che si era verificata una violazione. In seguito all’hacking sono stati rubati nomi, informazioni di contatto, indirizzi e-mail e indirizzi di casa dei clienti. È emerso inoltre che gli aggressori sono riusciti ad accedere ai dati di rimborso della carta Oyster e alle informazioni sui conti bancari di circa 5.000 clienti.

L'articolo Arrestato l’hacker 17enne per aver effettuato l’attacco informatico alla metropolitana di Londra proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

A 1930s Ham Station
poliverso.org/display/0477a01e…
A 1930s Ham Station[Mikrowave1] wanted to build an authentic 1930s-style ham radio station that was portable. He’s already done a regenerative receiver, but now he’s starting on a tube transmitter youtube.com/watch?v=_FC-VLkK7D… that runs on batteries. He’s settled on a popular design for the time, a Jones push-pull transmitter. Despite the tubes, it will only put out a few watts, which is probabl


A 1930s Ham Station


[Mikrowave1] wanted to build an authentic 1930s-style ham radio station that was portable. He’s already done a regenerative receiver, but now he’s starting on a tube transmitter that runs on batteries. He’s settled on a popular design for the time, a Jones push-pull transmitter. Despite the tubes, it will only put out a few watts, which is probably good for the batteries which, at the time, wouldn’t have been like modern batteries. You can see the kickoff video below.

According to the video, these kinds of radios were popular with expeditions to exotic parts of the world. He takes a nostalgic look back at some of the radios and antennas used in some of those expeditions.

The Jones oscillator originates with [Frank Jones, W6AJF] and was quite popular in the day, as he was well-known in ham radio circles then. Normally, these took a dual triode and a crystal along with some passive components. In this case, though, the transmitter will use two type 30 tubes. If you missed the series on the receiver, that’ll give you something to watch while you wait for the next installment on the transmitter.

We are excited to see — and maybe hear — this station on the air. Of course, you can build simple gear today, too. You can only wonder what [Frank Jones] would think of modern software-defined radios.

youtube.com/embed/_FC-VLkK7DU?…


hackaday.com/2024/09/14/a-1930…


The Privacy Post reshared this.

The Privacy Post ha ricondiviso questo.

Autenticazione a più fattori nel mirino dei criminali. Colpite le identità degli utenti nella metà degli attacchi
poliverso.org/display/0477a01e…
Autenticazione a più fattori nel mirino dei criminali. Colpite le identità degli utenti nella metà degli attacchiMilano, 10 settembre 2024 – A rischio l’autenticazione a più fattori. Secondo i dati riportati dal report del primo trimestre del 2024 primapaginacomunicazionesrl.mu… di Cisco Talos Incident Response (Talos


Autenticazione a più fattori nel mirino dei criminali. Colpite le identità degli utenti nella metà degli attacchi


Milano, 10 settembre 2024 – A rischio l’autenticazione a più fattori. Secondo i dati riportati dal report del primo trimestre del 2024 di Cisco Talos Incident Response (Talos IR) – la più grande organizzazione privata di intelligence al mondo dedicata alla cybersecurity – quasi la metà di tutti gli incidenti di sicurezza hanno riguardato questa problematica (MFA, Multi Factor Authentication).

Nel 25% dei casi, la causa è stata l’accettazione da parte degli utenti di notifiche push MFA fraudolente, mentre nel 21% è stata rilevata l’assenza di un’implementazione corretta dell’MFA. Nonostante negli ultimi anni ci siano stati molti progressi per quanto riguarda l’implementazione dell’autenticazione a più fattori all’interno delle aziende, i criminali informatici continuano a prendere di mira gli account protetti dall’MFA per poter accedere ai sistemi informativi aziendali.

Gli attacchi MFA


La tipologia più comune di attacchi che Cisco Talos ha dovuto gestire ha utilizzato le notifiche push MFA non autorizzate da parte degli utenti. Questa situazione si verifica quando l’aggressore tenta di autenticarsi ripetutamente a un account utente con credenziali valide al fine di sommergere le vittime di notifiche push MFA fino a quando, per esasperazione, la vittima accetta permettendo l’accesso. Cisco Duo, l’azienda di Cisco che si occupa di servizi di autenticazione multi-factor (MFA) e di accesso sicuro, ha rilevato, da giugno 2023 a maggio 2024, circa 15.000 attacchi basati su notifiche push. Cisco Duo ha inoltre constatato che il momento in cui avvengono questi attacchi è principalmente l’inizio della giornata lavorativa, quando gli utenti si autenticano per accedere ai sistemi aziendali.

Ecco i principali metodi, oltre alle notifiche push, utilizzati per eludere le difese MFA:

  1. Token di autenticazione rubati. I criminali utilizzano i token di sessione rubati ottenendo così un’identità legittima che gli permette di accedere ai sistemi aziendali.
  2. Ingegneria sociale del reparto IT. In genere, un aggressore si spaccia per qualcuno che la vittima conosce e cerca di trasmettere un senso di urgenza e importanza alle sue comunicazioni per incoraggiarlo a cliccare sul suo messaggio. Una volta ottenute le credenziali, il criminale le utilizza per entrare nei sistemi informativi e per aggiungere nuovi dispositivi abilitati all’autenticazione a più fattori.
  3. Compromissione di un fornitore dell’azienda presa di mira. Gli aggressori prendono di mira un fornitore per accedere all’MFA utilizzando il dispositivo compromesso.
  4. Compromissione di un singolo endpoint. Il fine è quello di aumentare i privilegi a livello di amministratore e quindi disattivare la protezione MFA.
  5. Attacchi As a Service. I criminali utilizzano applicazioni software erogate attraverso il dark web e, una volta ottenuto l’accesso ai sistemi informatici, utilizzano script per disabilitare gli strumenti di sicurezza.


Come difendersi


Ecco alcune raccomandazioni di Cisco Talos per implementare correttamente l’MFA:

  • Abilitare il number matching nelle applicazioni MFA per fornire un ulteriore livello di sicurezza e impedire agli utenti di accettare notifiche push MFA dannose.
  • Implementare l’autenticazione a più fattori su tutti i servizi critici, inclusi tutti i servizi di accesso remoto e di gestione dell’accesso all’identità (IAM).
  • Configurare un alert per l’autenticazione al fine di identificare rapidamente anomalie e modifiche nei criteri di autenticazione a più fattori.
  • Investire nella formazione degli utenti per aggiornarli sul panorama delle minacce informatiche e aiutarli a essere vigili, segnalando tempestivamente situazioni sospette.

L'articolo Autenticazione a più fattori nel mirino dei criminali. Colpite le identità degli utenti nella metà degli attacchi proviene da il blog della sicurezza informatica.


The Privacy Post reshared this.