reshared this
reshared this
🩷 We can only provide all these high-quality summaries because of our brilliant ✨volunteer Country Reporters✨ working in the background. To highlight this work and all our contributors, we are going to present one of them periodically.
Today: Lígia Lage Vieira
reshared this
Adobe patched a critical zero-day in Acrobat Reader (CVE-2026-34621) that was exploited for at least four months via a sophisticated prototype pollution technique.dark6 (Secure Bulletin)
reshared this
ShinyHunters has breached Rockstar Games by exploiting authentication tokens from third-party analytics vendor Anodot to access Snowflake data warehouses.dark6 (Secure Bulletin)
reshared this
Google has patched a high-severity use-after-free zero-day in Chrome's WebGPU implementation (CVE-2026-5281) that is actively exploited in the wild.dark6 (Secure Bulletin)
reshared this
Microsoft's April 2026 Patch Tuesday addresses 163 CVEs, including an actively exploited SharePoint spoofing zero-day (CVE-2026-32201) and a publicly leaked Defender EoP exploit dubbeddark6 (Secure Bulletin)
reshared this
Drift Protocol: il più grande furto DeFi del 2026 perpetrato da hacker nord-coreani con una campagna di social engineering durata 6 mesi
#CyberSecurity
insicurezzadigitale.com/drift-…
reshared this
🚨 The #AI Omnibus is deeply flawed. The EU Commission's proposal goes far beyond 'technical changes' and the process doesn't follow basic democratic procedures.
This would leave people in the EU without necessary protection from high-risk AI systems, such as biometric identification or AI use in schools.
41 organisations & experts are calling on EU lawmakers to REJECT the AI Omnibus, and protect the democratic process and our #FundamentalRights.
Read the open letter ➡️ edri.org/our-work/open-letter-…
Organisations and experts are calling on the European Commission, the European Parliament, and the Council to reject the AI Omnibus.EDRi (European Digital Rights (EDRi))
reshared this
Una verifica independente condotta sui siti web più popolari in California mostra che il 55% mantiene i #cookie nonostante il consenso negato e che il 78% dei cookie banner non sono effettivi
Perché in California? Perché è uno degli Stati #USA (pochi) che applica una propria legge sull'#eprivacy
Il totale delle sanzioni potrebbe superare i 5,8 miliardi USD
Le info si trovano qui: globalprivacyaudit.org/2026/ca…
#privacy #surveillance #sorveglianza
@sicurezza
Empirical analysis of Global Privacy Control compliance across popular websites accessed from California. Independent research by webXray.globalprivacyaudit.org
Giacomo Tesio likes this.
reshared this
dài dài dài! (cit.)
Azure MCP Server 2.0: 276 strumenti per integrare Azure negli agenti AI
#tech
spcnet.it/azure-mcp-server-2-0…
@informatica
reshared this
Phishing SPID contro le Pubbliche Amministrazioni: CERT-AGID smonta la campagna che usa siti WordPress legittimi per rubare credenziali istituzionali
#CyberSecurity
insicurezzadigitale.com/phishi…
reshared this
If it’s funded with public money, it should be public code.
That means guaranteeing the 4 freedoms:
🔓 Use the code
🔍 Study how it works
✏️ Modify it
🔁 Share it
Do you agree?
✍️ Sign the open letter
📢 Share it with your network
🏛️ Call on decision-makers to invest in public code
reshared this
Die AfD posiert als Retterin vor der freiwilligen #Chatkontrolle 1.0 — während ihre Fraktion (ESN) bei den laufenden Verhandlungen zu #Chatkontrolle 2.0 WIEDER als einzige komplett FEHLT! 🥱🛋️💤
europarl.europa.eu/committees/…
Wie schon vorher: digitalcourage.social/@echo_pb…
Liste der Verfahren, die derzeit im LIBE-Ausschuss behandelt werden. Einzelheiten zu Art und Stadium des Verfahrens, Links zu Dokumenten.www.europarl.europa.eu
clacke: exhausted pixie dream boy 🇸🇪🇭🇰💙💛 likes this.
reshared this
APT35 e la Cyber Guerra Parallela: come l’Iran aveva già compromesso ogni paese colpito nell’Operazione Epic Fury
#CyberSecurity
insicurezzadigitale.com/apt35-…
reshared this
CERT-EU has documented a cloud breach at the European Commission stemming from a supply-chain compromise in the Trivy container scanner. Approximately 91.dark6 (Secure Bulletin)
reshared this
A critical pre-authentication RCE vulnerability (CVE-2026-39987, CVSS 9.3) in the popular Marimo Python notebook platform was weaponised within 10 hours of public disclosure.dark6 (Secure Bulletin)
reshared this
The ShinyHunters extortion group claims to have stolen 9.4 million records from Amtrak's Salesforce environment, posting data samples as proof. The alleged breach highlights escalating ransomware threats targeting cloud infrastructure in the U.S.dark6 (Secure Bulletin)
reshared this
Il Pattern Saga in .NET con Wolverine: gestire workflow distribuiti a lungo termine
#tech
spcnet.it/il-pattern-saga-in-n…
@informatica
reshared this
A ransomware attack on ChipSoft, a major Dutch healthcare software provider, has exposed 13 million support tickets, 15,000 employee records, and sensitive corporate documents.dark6 (Secure Bulletin)
reshared this
Eine wirklich gute Reportage!
reshared this
La catena di fornitura software colpita: come CPUID è stata compromessa per distribuire il RAT stealer STX
#CyberSecurity
insicurezzadigitale.com/la-cat…
reshared this
reshared this
.NET Aspire 13.2: la modalità isolata risolve i conflitti di porta nello sviluppo parallelo
#tech
spcnet.it/net-aspire-13-2-la-m…
@informatica
reshared this
Can software developers write their own software license for their project?
a) Yes, it is best for software developers to write their own software license for their project
b) Yes, but it is best for software developers to choose an established #FreeSoftware
license with predictable legal effects for their project
c) No, software developers are prohibited by law to write their own software licenses
d) No, software licenses can only be written by legal professionals
#SoftwareFreedom
The Privacy Post reshared this.
A disgruntled researcher has published a working exploit for BlueHammer, an unpatched Windows local privilege escalation zero-day that abuses Windows Defender's update mechanism.dark6 (Secure Bulletin)
reshared this
A critical zero-day vulnerability (CVE-2026-35616, CVSS 9.1) in Fortinet FortiClient EMS was exploited in the wild before Fortinet published its advisory.dark6 (Secure Bulletin)
reshared this
Attackers compromised Nextend's update infrastructure to distribute a weaponized version of Smart Slider 3 Pro (v3.5.1.35) for approximately six hours on April 7, 2026.dark6 (Secure Bulletin)
reshared this
Visual Studio Code 1.116: tutte le novità di aprile 2026
#tech
spcnet.it/visual-studio-code-1…
@informatica
reshared this
Attacco SCADA nel mirino: le APT iraniane prendono di mira i controllori Unitronics negli Stati Uniti
#CyberSecurity
insicurezzadigitale.com/attacc…
reshared this
@Privacy Pride
Il post completo di Christian Bernieri è sul suo blog: garantepiracy.it/blog/weward/
Articolo scritto a quattro mani da Christian e Claudia NOTA PRELIMINARE: prima di leggere questo deep-dive è necessario rivedere il celeberrimo esperimento del Dr Peter Venkman... Che cosa è WeWard? Un'app per iOS/Android da scaricare sul proprio
Adobe has issued an emergency patch for CVE-2026-34621 (CVSS 8.6), a prototype pollution zero-day in Acrobat Reader actively exploited since December 2025.dark6 (Secure Bulletin)
reshared this
Die Pläne, im Internet mit Biometrie nach jedweder Person zu suchen, verstoßen laut AlgorithmWatch gegen Europarecht und die Verfassung. Sie seien so unverhältnismäßig, dass man sie nicht verbessern, sondern nur zurückziehen könne.
netzpolitik.org/2026/europarec…
Algorithm Watch stellt den Gesetzesentwürfen der Regierungskoalition ein fatales Zeugnis aus: Die Pläne, im Internet mit Biometrie nach jedweder Person zu suchen, verstoßen gegen Europarecht und gegen die Verfassung.Markus Reuter (netzpolitik.org)
reshared this
Da könnte so viel Geld gespart werden, wenn sie es sein lassen.
... von den Daten sowieso
ShinyHunters colpisce Rockstar Games attraverso Anodot: la campagna Salesforce-Snowflake mette a rischio 400 aziende
#CyberSecurity
insicurezzadigitale.com/shinyh…
reshared this
UNC1069 trasforma Axios in un vettore di spionaggio: WAVESHAPER.V2 colpisce la supply chain npm
#CyberSecurity
insicurezzadigitale.com/unc106…
reshared this
CISA has issued an urgent advisory (AA26-097A) warning that Iranian-affiliated APT actors have been actively targeting internet-exposed Programmable Logic Controllers across U.S. critical infrastructure since at least March 2026.dark6 (Secure Bulletin)
reshared this
Pro-Iranian hacktivist group APT Iran claims to have stolen 375 terabytes of data from Lockheed Martin, including alleged F-35 blueprints and internal source code. The group is demanding over $400 million in ransom and has listed the data for $598.dark6 (Secure Bulletin)
reshared this
Google has confirmed that CVE-2026-5281, a high-severity use-after-free vulnerability in Chrome's Dawn WebGPU implementation, is being actively exploited in the wild.dark6 (Secure Bulletin)
reshared this
Russia-linked APT28 (Fancy Bear) has launched a new spear-phishing espionage campaign deploying PRISMEX, a previously undocumented malware suite combining steganography, COM hijacking, and cloud-based C2 infrastructure.dark6 (Secure Bulletin)
reshared this
Stell dir vor, dass deine Standortdaten frei zugänglich im Netz für Leute zu kaufen sind. Klingt absurd? Ist aber Realität.
Sogenannte Databroker verkaufen von verschiedenen Apps gesammelte Standortdaten. Betroffen sind nicht nur Privatpersonen, sondern auch Politiker*innen oder hochrangige Beamte.
Wir haben jahrelang über das Thema geschrieben. Jetzt gibt es eine ARD-Doku zu unseren Recherchen:
"Gefährliche Apps - Im Netz der Datenhändler"
ardmediathek.de/video/story/ge…
Was viele Smartphone-Nutzer wissen: Die Apps auf ihren Handys sammeln detaillierte Standortdaten. Was den meisten jedoch nicht bewusst ist: Die Informationen landen oft in einem undurchsichtigen, weltweiten Netzwerk aus Datenhändlern und Werbefirmen.www.ardmediathek.de
Thomas likes this.
reshared this
KI-Unternehmen kreieren Mythen um sich und ihre Produkte. So entziehen sie sich der Verantwortung für Probleme, die sie selbst geschaffen haben. Und wir lassen es ihnen durchgehen. Mark Twain wäre das wohl nicht passiert, schreibt unsere Kolumnistin @bkastl.
netzpolitik.org/2026/degitalis…
KI-Unternehmen kreieren Mythen um sich und ihre Produkte. So entziehen sie sich der Verantwortung für Probleme, die sie selbst geschaffen haben. Und wir lassen es ihnen durchgehen. Mark Twain wäre das wohl nicht passiert.Bianca Kastl (netzpolitik.org)
reshared this
Reimund
in reply to netzpolitik.org • • •"Ein Internet ohne schädliche Anreize ist möglich"
"Ein Leben ohne Mops ist möglich, aber sinnlos" (Loriot)