The Privacy Post ha ricondiviso questo.

:fsfe: Our July Newsletter is here! 📩

While YH4F 2026 wrapped up, we submitted our position on the EC's Android interoperability consultation, and put (thanks to @nicolef !) the Teufel Mynd speaker to test

Find out this stories and more: fsfe.org/news/nl/nl-202607.htm…

#FreeSoftware #SoftwareFreedom

reshared this

The Privacy Post ha ricondiviso questo.

Narrow majority to allow the urgent motion to reinstate #ChatControl 1.0 mass scans.
331 in favor.
304 against.
11 abstentions.
A dark day for privacy and democracy. On Thursday, there will be a vote on the substance of the law. Only an absolute majority can stop it. 🚨
fightchatcontrol.eu
The Privacy Post ha ricondiviso questo.

#Chatkontrolle 1.0
Gleich wird im Europäischen Parlament über den Antrag auf ein Eilverfahren abgestimmt. Eigentlich ab 12:00 Uhr aber es gibt ein paar Verspätungen im Ablauf. Nach der aktuellen Aussprache zum vorherigen Tagesordnungspunkt sollte es los gehen.
Wer es live mitverfolgen möchte, hier gibt es einen Stream (und Simultanübersetzung).
europarl.europa.eu/plenary/en/…
in reply to Konstantin Macher

Die EVP versucht Kinder gegen die Grundrechte aller Menschen in der EU auszuspielen. Sachlich längst wiederlegt halten die "Konservativen" an ihrem Narrativ fest.
Als nächstes spricht eine Rechtspopulistin. Leider hat sie heute das Rederecht zu dem Antrag bekommen und nicht eine der sachlich versierten Abgeordneten, die sich tatsächlich gegen das Gesetz engagieren (und nicht erst, wenn es viel Aufmerksamkeit gibt).
Jetzt wird abgestimmt.
in reply to Konstantin Macher

Es gibt eine knappe Mehrheit dafür den Eilantrag zur Neueinsetzung der #Chatkontrolle 1.0 zuzulassen.

331 dafür.
304 dagegen.
11 Enthaltungen.

Das ist nicht gut. Jetzt wird am Donnerstag abgestimmt, ob das Gesetz auch inhaltlich durch kommt. Nur mit einer absoluten Mehrheit können die Abgeordneten das dort noch aufhalten. 🚨
#ChatkontrolleStoppen

reshared this

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Leonardo Tamiano al @devconf@poliversity.it presenta "Voglio migliorare la didattica dell'Informatica"

"Le astrazioni devono essere aperte, esplorate e ricostruite per formare persone in grado di costruire le astrazioni del futuro"

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM

Questa voce è stata modificata (3 settimane fa)
The Privacy Post ha ricondiviso questo.

GNOME Papers arriva su Windows con un porting nativo


GNOME Papers arriva anche su Windows grazie a un porting nativo che mantiene le funzionalità del visualizzatore di documenti GNOME
L'articolo GNOME Papers arriva su Windows con un porting nativo proviene da Linux Easy.
E' vietato riprodurre questo articolo senza autorizzazione.
Questo feed RSS è destinato ai lettori, non agli scraper o aggregatori.
Linux Easy viene rilasciato con Licenza CC BY-N...

🔗 Leggi il post completo

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Ecco @inmarvinwetrust al @devconf@poliversity.it: #Hacking the developer: Attacchi reali nella toolchain open source

Oggi gli attaccanti puntano agli sviluppatori perché la toolchain moderna vive di fiducia ed eseguiamo continuamente codice di terze parti

@devconf@citiverse.it

youtube.com/live/OwU4nQzD3jM

Questa voce è stata modificata (3 settimane fa)
The Privacy Post ha ricondiviso questo.

Wer nicht versteht, dass Unterdrückungsinfrastruktur erst an den Schwächsten erprobt wird, bevor es die Nächststärkeren zu spüren bekommen, versteht wirklich nicht viel.


Kein Online-Shopping, kein Flohmarkt-Besuch: Das Leben mit Bezahlkarte ist teuer und fremdbestimmt, berichtet Alexandra Keiner. Die Soziologin am Weizenbaum-Institut erforscht, wie Migrant*innen durch Finanzinfrastruktur kontrolliert werden. Sie sagt, die Bezahlkarte könne bald auch anderen Gruppen drohen. netzpolitik.org/2026/bezahlkar…

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup
#CyberSecurity
insicurezzadigitale.com/lazaru…

@informatica


Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup


Si parla di:
Toggle

Sei pacchetti npm, un nome quasi identico a un progetto scaricato oltre un milione di volte al mese, e in fondo alla catena un impianto capace di aprire sessioni SSH, leggere la clipboard e rovistare tra i wallet crypto della vittima. È l’ultima campagna di supply chain attribuita a gruppi legati alla Corea del Nord, documentata da JFrog Security Research il 30 giugno e ancora attiva nei repository pubblici a inizio luglio. Non è un incidente isolato: è l’ennesima iterazione di una macchina offensiva, quella riconducibile all’ecosistema Lazarus/Contagious Interview, che negli ultimi anni ha trasformato l’npm registry in un vettore di spionaggio e furto di criptovalute su scala industriale.

Un travestimento quasi perfetto


I ricercatori di JFrog hanno individuato due pacchetti “entry point”, rollup-packages-polyfill-core e rollup-runtime-polyfill-core, costruiti per somigliare in tutto e per tutto al legittimo rollup-plugin-polyfill-node: stesso tipo di README (“A modern Node.js polyfill for your Rollup bundle”), stesso link a repository e homepage puntati al progetto originale su GitHub, persino porzioni di codice del plugin reale copiate all’interno del pacchetto malevolo prima della logica dannosa. Il progetto legittimo conta circa 295.000 download settimanali e oltre 1,2 milioni nell’ultimo mese: un bersaglio ideale per un attacco che punta sulla somiglianza superficiale, non sul typosquatting grossolano.

Il dettaglio tecnico più rilevante è che solo l’entry point CommonJS (dist/index.js) contiene la backdoor: le versioni ESM restano pulite, un accorgimento che complica le analisi automatiche basate su un singolo file di ingresso.

La catena d’infezione, passo dopo passo


All’importazione del pacchetto, una funzione dal nome innocuo (ValidateSvgModule) decodifica una stringa base64 che nasconde il comando npm install swift-parse-stream --no-save --silent --no-audit --no-fund, eseguito in silenzio tramite child_process.spawn. Il secondo pacchetto, quirky-token, viene installato allo stesso modo dal gemello rollup-runtime-polyfill-core.

Questi pacchetti di secondo stadio si presentano come utility di sanitizzazione SVG, e in gran parte lo sono davvero: rimuovono tag <script>, minificano il markup. Ma in coda al file, una funzione getPlugin() effettua una richiesta verso un endpoint su jsonkeeper.com, estrae un campo JSON chiamato model e lo passa direttamente a eval(). Il codice malevolo, quindi, non risiede mai nei file pubblicati sul registry: vive su un servizio di hosting JSON esterno, invisibile a qualunque analisi statica del pacchetto.

Il payload recuperato da JSONKeeper effettua per primo un controllo ambientale, uscendo silenziosamente se rileva variabili tipiche di Codespaces, CodeSandbox, Vercel, AWS Lambda, Google Cloud, Azure Functions, Docker, Render o sandbox di analisi — un chiaro tentativo di colpire solo workstation di sviluppatori reali ed evitare l’esposizione in ambienti di test automatizzati. Superato il controllo, installa axios e socket.io-client e scarica da un IP grezzo (216.126.236.244) un blob cifrato in AES-256-CBC (chiave derivata via scryptSync), lo decifra, lo scrive in una directory temporanea come file pack e lo esegue con node pack.

Controllo remoto, furto wallet e sorveglianza della clipboard


Il modulo pack altro non è che un loader per almeno quattro componenti distinti, ricostruiti da JFrog in ambiente sandbox: scdata.js, un modulo di accesso remoto che installa ssh2, node-pty e librerie di cattura schermo/input, offrendo all’operatore sessioni terminali interattive (PowerShell su Windows, zsh altrove), sessioni SSH, screenshot, movimento del mouse e digitazione simulata tramite @nut-tree-fork/nut-js; ldata.js, dedicato al furto di dati da browser e wallet crypto, che tenta l’esfiltrazione di file come Login Data, Web Data e lo storage delle estensioni di wallet noti (incluso MetaMask, identificato tramite i suoi ID di estensione); un file collector che scandaglia il filesystem alla ricerca di chiavi SSH, file .env, cronologia di editor come VS Code, Cursor e Windsurf, e directory di configurazione di strumenti AI (.claude, .gemini, .cursor); infine un modulo di monitoraggio della clipboard, che invia ogni nuovo contenuto copiato — password, seed phrase, token — a un endpoint dedicato.

La combinazione di queste capacità va ben oltre il semplice furto di credenziali una tantum: garantisce all’attaccante un accesso interattivo e persistente alla macchina compromessa, tipico degli impianti usati da attori state-sponsored per operazioni di raccolta informativa prolungata, non solo per il cash-out rapido tipico del cybercrime finanziario puro.

Il contesto: non è la prima volta


Questa campagna si inserisce in un pattern già documentato. Ad aprile 2026 la società Panther aveva descritto una campagna sostenuta con 108 pacchetti npm malevoli distribuiti in 261 versioni, veicolo dei malware BeaverTail e OtterCookie, entrambi associati al cluster Contagious Interview — l’insieme di operazioni nordcoreane che si finge selezione del personale per convincere sviluppatori a clonare repository infetti come parte di un finto colloquio tecnico. Nello stesso periodo, Google aveva collegato attori nordcoreani anche a un dirottamento di un progetto open source molto diffuso, portato a termine dopo settimane di lavoro di ingegneria sociale ai danni del maintainer. Il filo conduttore è sempre lo stesso: colpire la fiducia implicita che sviluppatori e pipeline CI/CD ripongono nelle dipendenze open source.

Due righe per i difensori


Per i team di sicurezza e gli sviluppatori, la lezione operativa è chiara: la somiglianza del nome non è un indicatore affidabile di legittimità, e i controlli automatici basati su pattern di typosquotting classico (distanza di edit, caratteri sostituiti) non intercettano questo tipo di masquerading semantico. Chi ha installato uno dei pacchetti elencati dovrebbe considerare la macchina compromessa, ruotare tutte le credenziali (npm, GitHub, cloud, SSH, wallet) e verificare la presenza di processi o file residui nelle directory temporanee. Vale la pena ricordare che gran parte della logica dannosa non è mai stata pubblicata sul registry npm: bloccare gli indicatori di rete elencati sotto è quindi essenziale quanto rimuovere i pacchetti stessi.

Indicatori di compromissione

Pacchetti npm malevoli:
rollup-packages-polyfill-core
rollup-runtime-polyfill-core
swift-parse-stream
quirky-token
react-icon-svgs
rollup-plugin-polyfill-connect
Indicatori di rete:
hxxps[:]//www[.]jsonkeeper[.]com/b/3P9BF
hxxp[:]//216[.]126[.]236[.]244/api/service/98cb54c0b4ac259d30c9c1ca1ae87c68
hxxp[:]//216[.]126[.]236[.]244/api/service/makelog
hxxp[:]//216[.]126[.]236[.]244/api/service/process/
hxxp[:]//216[.]126[.]236[.]244:4801
hxxp[:]//216[.]126[.]236[.]244:4806/upload
hxxp[:]//216[.]126[.]236[.]244:4809/upload
hxxp[:]//216[.]126[.]236[.]244:4809/cldbs
Indicatori host:
/pack
/scdata
/ldata
vhost.ctl
Comandi/comportamenti sospetti:
npm install swift-parse-stream --no-save --silent --no-audit --no-fund
npm install quirky-token --no-save --silent --no-audit --no-fund
node pack
node scdata
node ldata

The Privacy Post ha ricondiviso questo.

☕ CYBERBRIEFING — Martedì 7 luglio 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

The Privacy Post ha ricondiviso questo.

🇩🇪Missbrauchsopfer an EU-Parlament: #Chatkontrolle lässt Opfer verstummen und erschwert Strafverfolgung. Kein Eilverfahren! thatprivacyguy.com/blog/csa-su…
📞 Ruft Abgeordnete an, die als „UNTERSTÜTZT“ markiert sind — fordert ein NEIN zur Dringlichkeit: fightchatcontrol.eu/de/#delega…
in reply to Patrick Breyer

🇮🇹 Un sopravvissuto ad abusi al Parlamento europeo: la #ChatControl fa tacere le vittime e ostacola l'azione penale. No alla procedura d'urgenza! thatprivacyguy.com/blog/csa-su…

📞 Chiama i deputati « sostiene » – di' NO alla procedura d'urgenza: fightchatcontrol.eu/it/#delega…

Questa voce è stata modificata (3 settimane fa)

Gazzetta del Cadavere reshared this.

in reply to Patrick Breyer

🇪🇸Un superviviente de abusos al Parlamento Europeo: el #ChatControl silencia a las víctimas y dificulta la acción penal. ¡No al procedimiento de urgencia! thatprivacyguy.com/blog/csa-su…

📞 Llama a diputados « a favor » – exige un NO a la urgencia: fightchatcontrol.eu/es/#delega…

Questa voce è stata modificata (3 settimane fa)
The Privacy Post ha ricondiviso questo.

Interview zum menschenrechtlichen Schutz und zur Beschwerde von Reporter ohne Grenzen beim EGMR gegen den Einsatz der #Staatstrojaner durch den BND: „Es wird immer behauptet, die Geheimdienste würden in Deutschland besonders ‚engmaschig‘ kontrolliert. Das genaue Gegenteil ist der Fall.“ netzpolitik.org/2026/staatstro…
The Privacy Post ha ricondiviso questo.

#ChatControl 1.0 e 2.0 spiegati: Non esiste una sola proposta di legge sul "Controllo delle chat", bensì due, che stanno procedendo in parallelo attraverso le istituzioni dell'UE. Questa pagina chiarisce le due questioni.

Non esiste un'unica proposta di legge sul "controllo delle chat", bensì due , che stanno procedendo in parallelo attraverso le istituzioni europee . Per questo motivo le notizie possono sembrare contraddittorie: una proposta di legge sul controllo delle chat è stata "bloccata" nel marzo 2026, un'altra è ancora in fase di negoziazione e la prima è ora in fase di riesumazione

fightchatcontrol.eu/chat-contr…

@Privacy Pride

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

#ChatControl 1.0 and 2.0 Explained: There is not one proposed “Chat Control” law — there are two, and they are moving through the EU institutions in parallel. This page untangles the two.
fightchatcontrol.eu/chat-contr…
Questa voce è stata modificata (3 settimane fa)
The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

DevConf 2026 - Domani e dopodomani siete tutti invitati a Pavia per la conferenza italiana dedicata agli sviluppatori e creatori di codice open source


La conferenza @devconf si terrà a Pavia, presso il Learning Space Cravino (Via Agostino Bassi 2) il 7 e l'8 Luglio 2026 con sessioni mattutine e pomeridiane.

Organizzata da @BoostMediaAPS presenta talk tecnici, possibilità di sviluppare in tempo reale e presentare il proprio progetto, networking, opportunità di collaborazione dinanzi ad un pubblico in cui sono presenti anche Risorse Umane di aziende interessate al recruiting di talenti in ambito Open Source.

Grazie a @redflegias e @adriano_morselli di @ufficiozero e a @lorenzodm per l'organizzazione

I posti a sedere sono limitati per cui è necessaria la prenotazione. L'ingresso è gratuito!
Per prenotare l'ingresso: pretix.eu/BoostMediaAPS/devcon…

NB: il convegno è anche un corso formativo per il Personale Tecnico Amministrativo e Cel (formazione.unipv.it/catalogo-c…)

Di seguito il programma delle due giornate:

Martedì 7 Luglio 2026


10:00 - 10:15: Lorenzo De Marco, Cos'è il DevConf e perché è necessario in Italia?
10:20 - 10:50: Claudia Galingani Mongini, "Hai democratizzato il ransomware. Prego."
10:55 - 11:25: Marvin Pascale, Hacking the developer: Attacchi reali nella toolchain open source
11:30 - 12:15: Leonardo Tamiano, "Voglio migliorare la didattica dell'Informatica"
12:20 - 12:50: Claudia Galingani Mongini, git clone malware – come i ransomware group sfruttano l'open source aka il LOLBins dei poveri

12:50 - 14:15: Pausa pranzo

14:15 - 14:45: Valentina Nardecchia, Fediverso: la novità che riporta alle origini
14:50 - 15:20: Andrea Guani, Poliverso, Poliversity, Feddit e Citiverse
15:25 - 15:55: Fabrizio Balliano, Maho: la fenice delle piattaforme ecommerce, grazie all'open source
16:00 - 16:20: Lorenzo De Marco, Project Management e sviluppo del software
16:25 - 16:55: Stefano Marinelli, FediMeteo, i BSD e il Fediverso: sotto il sole, senza nuvole, liberi e connessi
17:00 - 17:30: Chiara Masci, Software-as-a-Medical device open source: utopia o potenziale realtà?

Mercoledì 8 Luglio 2026


10:00 - 10:15: Lorenzo De Marco, Cos'è il DevConf e perché è necessario in Italia?
10:20 - 10:50: Valentina Nardecchia, Sovranità digitale: perché è una scelta politica necessaria per il futuro
10:55 - 11:25: Giuseppe Aceto, Il futuro si decide insieme. Dal CERN a Relatronica: tecnologia, partecipazione e democrazia
11:30 - 12:15: Fabio Manganiello, Un blog federato basato su file di testo: git log per social media con Madblog + ActivityPub + Indieweb
11:35 - 11:55: Gianluca Aurelio, You've Been Owned. Not Own. Dal floppy disk al cloud: come abbiamo ceduto la nostra sovranità digitale… e come ce la stiamo riprendendo
12:20 - 12:50: Dario Dieci, Linux alla riscossa: dagli ostacoli storici alla sua diffusione al recente exploit

12:50 - 14:15: Pausa pranzo

14:15 - 14:45: Valentino Spataro, Indipendenza informatica in azienda con l'open source e l'AI, partendo da Windows
14:50 - 15:20: Italo Vignoli, Dopo il software, liberate i documenti.
15:25 - 15:55: DNDG srl, La progettazione UX/UI diventa open con Penpot
16:00 - 16:20: Francesco Macchia & Diego Beraldin, Il Fediverso e i gruppi tematici: le opportunità per la comunità, il peccato originale di Mastodon e le soluzioni applicative
16:25 - 16:55: Gianluca Aurelio, L'open source come strumento per i diritti umani
17:00 - 17:30: Fabio "Kenobit" Bortolotti, Assalto alle piattaforme. Riprendiamoci internet.

Segui gli aggiornamenti sul gruppo Activitypub @devconf@citiverse.it dedicato all'evento

The Privacy Post ha ricondiviso questo.

Nach den verheerenden Erdbeben in Venezuela versorgen NGOs die Menschen mit Satelliteninternet und Strom, um Kommunikation zu ermöglichen. Die Regierung lockert ihre Online-Zensur nur teilweise: X ist nach zwei Jahren Blockade wieder erreichbar, dutzende Nachrichtenseiten bleiben gesperrt. netzpolitik.org/2026/internet-…
The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

1/4 🚨 Third European Parliament vote on #MassSurveillance in 4 months? Why is the Council pushing MEPs to approve mass scanning of users’ private messages? 🚨

😮 This week, due to an unprecedented move by European Parliament President Roberta Metsola, being described as her backstabbing her own institution, MEPs will be forced to vote once again on the interim ePrivacy derogation – sometimes known as “#ChatControl 1.0”.

Questa voce è stata modificata (3 settimane fa)
in reply to EDRi

2/4 🔎 This law would allow #BigTech companies like Microsoft and Meta to mass scan their users’ private messages to search for child abuse material. Despite the important aim to protect children, EDRi and many legal experts have argued that scanning everyone’s messages – rather than just those reasonably suspected of serious criminal acts – is a violation of everyone’s communications confidentiality and fundamental rights.

Why is the upcoming THIRD vote this week concerning?... 🧵

Em reshared this.

in reply to EDRi

3/4 ⚠️ If the interim derogation is voted through, voluntary mass scanning by Big Tech platforms becomes legal - with no need for a warrant, little to no oversight, and with no legal basis, on millions of conversations.

⚠️ The outcome of the vote on "#ChatControl 1.0" will either strengthen or undermine the Parliament's position on the #CSARegulation - which has so-far protected encryption and rejected mandatory mass surveillance of private.

in reply to EDRi

4/4 ⚠️ Roberta Metsola and EPP MEPs should not be allowed to make a joke out of EU's democratic processes. The Parliament's stance on a law is final, and not a suggestion to keep revisiting.

We are urging MEPs to hold strong this week, remember the stakes at play, and to make it clear once and for all: mass surveillance of private communications is incompatible with a safe and secure democratic society 🫶🏽

Catch up on the saga of "Chat Control 1.0" with our blogpost ➡️ edri.org/our-work/did-the-eu-p…

reshared this

in reply to EDRi

Third European Parliament vote on #MassSurveillance in 4 months? Why is the Council pushing MEPs to approve mass scanning of users’ private messages? 🚨

European Parliament President Roberta Metsola, Check out her husband, there are reports he is involved in a surveillance business

Metsola pushed a new ethics code that demanded EU Parliament’s senior members declare conflicts of interest

Under those new rules, one person was left out: the president herself

politico.eu/article/roberta-me…

The Privacy Post ha ricondiviso questo.

Citizen Lab found that former Member of the European Parliament Stelios Kouloglou was hacked with #Pegasus #spyware while serving on the PEGA committee, which investigated Pegasus and other spyware abuses in Europe. Citizen Lab found that the attackers could have had access to confidential documents and committee deliberations.

Saskia Bricmont, coordinator of the PEGA committee and co-chair of the Parliamentary Interest Group against the Illegal Use of Spyware, believes it is “ high time that the @EUCommission puts forward concrete proposals based on the recommendations issued by our committee of inquiry, starting with the introduction of very strict conditions for the use of spyware, and the creation of a European technology laboratory, modelled on Citizen Lab, to provide assistance to victims.”

citizenlab.ca/research/member-…

Questa voce è stata modificata (3 settimane fa)
in reply to Jan Walraven ⁂

Last year we unveiled that money from the European Investment Fund was used to finance #Paragon, another Israeli spyware company.

Several months after @apache_be revealed this investment, the European Investment Fund decided it will no longer provide funding to spyware companies based outside the EU.

But @edri EDRi believes that “no spyware company — regardless of whether it is Israeli, European, or from anywhere else – should receive public money from European taxpayers”.

apache.be/2026/05/08/european-…

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇩🇪 Ansage der Renew-Fraktion zur #Chatkontrolle: Dauerhafte Lösung jetzt statt endloser Überwachungs-Schleife und Verfahrens-Tricks! eureporter.co/de/politics/2026…

📞 JETZT EU-Abgeordnete mit Markierung „UNTERSTÜTZT“ anrufen & Trickserei stoppen: fightchatcontrol.eu/de/#delega…

in reply to Patrick Breyer

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇪🇸 Renew sobre #ChatControl: ¡Solución permanente ya en vez de vigilancia infinita y trucos de procedimiento! eureporter.co/es/politics/2026…

📞 Llama AHORA a diputados « a favor » y para el truco: fightchatcontrol.eu/es/#delega…
gpt-5.2-chat-latest

The Privacy Post ha ricondiviso questo.

Die schwarz-rote Koalition behauptet, geplante Einschnitte bei der Transparenz würden der Sicherheit dienen und die Nutzung des IFG erleichtern. Die Informationsfreiheitsbeauftragten von Bund und Ländern widersprechen vehement und warnen: Die Pläne würden Deutschland zurück in die Zeit des „verschlossenen Obrigkeitswissens“ katapultieren.

netzpolitik.org/2026/heftige-k…

The Privacy Post ha ricondiviso questo.

Ich habe mich bereits zum zweiten Mal mit Alexandra Keiner unterhalten und muss sagen: Es ist jedes Mal sehr interessant. Sie kennt sich mit der diskriminierenden Bezahlkarte einfach sehr gut aus. Dieses Interview ist aus dem Gespräch entstanden: netzpolitik.org/2026/bezahlkar…
The Privacy Post ha ricondiviso questo.

Kein Online-Shopping, kein Flohmarkt-Besuch: Das Leben mit Bezahlkarte ist teuer und fremdbestimmt, berichtet Alexandra Keiner. Die Soziologin am Weizenbaum-Institut erforscht, wie Migrant*innen durch Finanzinfrastruktur kontrolliert werden. Sie sagt, die Bezahlkarte könne bald auch anderen Gruppen drohen. netzpolitik.org/2026/bezahlkar…
The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇩🇪🚨 LETZTE CHANCE: EU‑Regierungen wollen #Chatkontrolle MORGEN durchdrücken. Forscher warnen.
⏳ Noch 21 Stunden.
📞 Rufe Abgeordnete an, die als „UNTERSTÜTZT“ markiert sind — fordere ein NEIN zur Dringlichkeit: fightchatcontrol.eu/de/#delega…
📰 Details: patrick-breyer.de/verfahrenstr…
in reply to Patrick Breyer

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇪🇺🚨 LAST CHANCE: EU leaders try to sneak #ChatControl back TOMORROW via a procedural trick. Cybersecurity researchers warn.
⏳ We have 21 hours.
📞 Call MEPs marked “SUPPORTS” — demand a NO on urgency procedure: fightchatcontrol.eu/#delegates
📰 Details: patrick-breyer.de/en/procedura…
Questa voce è stata modificata (3 settimane fa)
in reply to Patrick Breyer

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇫🇷 🚨DERNIÈRE CHANCE : L’UE tente d’imposer la #ChatControl DEMAIN par ruse. Les experts alertent.
⏳ Plus que 21h.
📞 Appelez les députés « favorable » – exigez un NON à l’urgence : fightchatcontrol.eu/fr/#delega…
📰 Détails : patrick-breyer.de/fr/procedura…
Questa voce è stata modificata (3 settimane fa)
in reply to Patrick Breyer

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇮🇹 🚨ULTIMA CHANCE: Domani l'UE prova a far passare #ChatControl con un trucco. Esperti allertano.
⏳ Mancano 21h.
📞 Chiama i deputati « sostiene » – di' NO alla procedura d'urgenza: fightchatcontrol.eu/it/#delega…
📰 Dettagli: patrick-breyer.de/it/procedura…
Questa voce è stata modificata (3 settimane fa)

reshared this

in reply to Patrick Breyer

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇪🇸🚨 ÚLTIMA OPORTUNIDAD: La UE intenta colar #ChatControl MAÑANA con trucos. Expertos advierten.
⏳ Quedan 21h.
📞 Llama a diputados « a favor » – exige un NO a la urgencia: fightchatcontrol.eu/es/#delega…
📰 Detalles: patrick-breyer.de/es/procedura…
Questa voce è stata modificata (3 settimane fa)
The Privacy Post ha ricondiviso questo.

Dalla Bestia a X: la nuova macchina di Salvini parla muskiano
#PoliticalNotes

ilglobale.it/2026/07/dalla-bes…
@politica

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

1/2 🚨 On Friday, a new investigation by @citizenlab revealed that a member of the European Parliament's PEGA committee was targeted with the Pegasus #spyware WHILE he was investigating spyware abuse in Europe ➡️ citizenlab.ca/research/member-…

✊🏾 Today, EDRi, along with 38 civil society organisations and experts, is calling on EU lawmakers to act now to ensure that spyware abuse in Europe is met with accountability, not impunity. Read the full statement ➡️ cdt.org/wp-content/uploads/202…

in reply to EDRi

2/2 🙅🏽‍♀️These revelations might be new but our concerns are long-standing: spyware is incompatible with a safe and secure democratic society that respects fundamental rights.

Join us, and thousands of people, in urging EU lawmakers to keep it safe and secure by banning spyware ➡️ edri.org/take-action/our-campa…

The Privacy Post ha ricondiviso questo.

GitHub e le big tech si oppongono alla legge sulla trasparenza dell’IA? Secondo SFC è pura ipocrisia verso l’open-surce


GitHub e altri colossi tech si oppongono alla legge californiana sulla trasparenza dell'IA (SB 1000) sostenendo - ipocritamente, secondo la Software Freedom Conservancy - che danneggerebbe le licenze FOSS.
E il discorso ritorna a quanto sono liberi i modelli che usiamo quotidianamente e quanto, volutamente, vogliamo ignorare questo aspetto a favore della comodità.

🔗 Leggi il post completo

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The latest Pegasus revelations show that the EU's spyware crisis is far from over.

Today, CDT Europe, alongside 39 civil society organisations and individual signatories, is calling on the EU to act: investigate the hacking of former MEP Stelios Kouloglou, implement the PEGA Committee's recommendations, ensure effective remedies for victims, strengthen enforcement of the Dual-Use Regulation, and stop EU funds supporting spyware companies.

Read our joint statement: cdt.org/insights/joint-stateme…

The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

PamStealer: New macOS Infostealer Disguises Itself as the Maccy Clipboard Manager
#CyberSecurity
securebulletin.com/pamstealer-…
The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Seven New CVEs in FatFs Filesystem Driver Put Millions of Embedded and IoT Devices at Risk
#CyberSecurity
securebulletin.com/fatfs-cves-…
The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

New “Bad Epoll” Linux Zero-Day Lets Local Users Root Servers and Android Devices
#CyberSecurity
securebulletin.com/bad-epoll-l…
The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Cybersecurity Week in Review: AI Model Redeployment, a Linux Root Zero-Day, and Hundreds of Chrome Patches
#CyberSecurity
securebulletin.com/cybersecuri…
The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Apache ActiveMQ Patches Three Vulnerabilities Enabling DoS, Data Leakage, and Privilege Escalation
#CyberSecurity
securebulletin.com/apache-acti…
The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

New T3MP3ST Framework Turns AI Coding Agents Into Autonomous 0-Day Hunters
#CyberSecurity
securebulletin.com/new-t3mp3st…
The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Flipper Zero Maker Overhauls Firmware Contribution Rules After Community Backlash
#CyberSecurity
securebulletin.com/flipper-zer…
The Privacy Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Microsoft Ships KB5095189 Cumulative Update to Patch the Windows 11 Setup Experience
#CyberSecurity
securebulletin.com/microsoft-s…
The Privacy Post ha ricondiviso questo.

Die aktuelle Welle von Polizeigesetzverschärfungen muss man mit der drohenden Rückkehr des Faschismus zusammendenken. Dann wird erst so richtig klar, wie bedrohlich die kommende automatisierte Überwachung ist. Viele der Menschen, die versuchten, den AfD-Parteitag in Erfurt zu blockieren, haben das verstanden. netzpolitik.org/2026/afd-parte…
The Privacy Post ha ricondiviso questo.

Bei den Protesten gegen den AfD-Parteitag in Erfurt ging es auch um drohende KI-Überwachung. Viele Protestierende fürchten sich davor, dass Videoanalysen und Megadatenbanken Nazis in die Hände fallen. Bereits jetzt ist das Tech-Arsenal beeindruckend, mit dem die Polizei die Rechten absichert. netzpolitik.org/2026/afd-parte…
in reply to netzpolitik.org

Auch interessant, dass die Polizei eine rechte Veranstaltung der Afd problemlos gegen 50.000 schützen kann. Da gibt es offensichtlich weder personelle, technische oder finanzielle Grenzen, alles ist möglich!

Die Veranstaltung der Grünen 2024 in Biberach dagegen konnte die Polizei komischerweise nicht einmal gegen ein paar hundert Landwirte, Reichsbürger und rechte Schwurbler schützen.

Braucht sich die #Polizei nicht wundern, wenn man ihr eine politische Neigung unterstellt.

The Privacy Post ha ricondiviso questo.

Dopo una bestia, arriva la nuova Bestia di Salvini #stroppa

editorialedomani.it/politica/i…

The Privacy Post ha ricondiviso questo.

Wehren wir uns! Sonst ist 1984 näher als wir denken. Na dann gute Nacht Internet!

Ein guter Text auf @netzpolitik_feed: netzpolitik.org/2026/widerstan….

Questa voce è stata modificata (3 settimane fa)
The Privacy Post ha ricondiviso questo.

☕ CYBERBRIEFING — Lunedì 6 luglio 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica