Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Quando il cyberattacco si trasforma in responsabilità penale e amministrativa per i vertici aziendali

📌 Link all'articolo : redhotcyber.com/post/quando-il…

Paolo Galdieri

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

De-Aging Human Tissue Using Special Enzyme to Remove AGEs


The media in this post is not displayed to visitors. To view it, please log in.

With human bodies being bags of mostly salty water and countless messy biochemical processes, it’s little wonder that over time some residues tend to collect in these systems. Although evolution has seen fit to also evolve a range of mechanisms to clean up many of those messes, some of these waste products are left to gather, such as advanced glycation end-products (AGEs). Implicated in everything from diabetes to chronic kidney disease and general aging-related conditions, recently researchers have developed a way to break down one type of these AGEs.

Called N(6)-Carboxymethyllysine (CML), there is evidence to suggest that the presence of AGEs like it in the extracellular matrix (ECM) has damaging effects on the ECM’s functioning, as observed in e.g. the inhibiting of collagen crosslinking and the resulting ‘aging’ of skin among other tissues. Essentially these waste product jam up the normal biochemical machinery, while also triggering pro-inflammatory factors.

Beyond aging-related conditions, this can result in a whole range of other diseases that may be resolved if these waste products could be cleaned out. To this end [Narisa Trabosh] et al. of the San Francisco-based Revel Pharmaceuticals laboratory created CMLase, an enzyme that breaks down CML.
Arterial tissue treated with the CMLase enzyme shows a clear difference. (Credit: Trabosh et al., Nature communications, 2026)Arterial tissue treated with the CMLase enzyme shows a clear difference. (Credit: Trabosh et al., Nature communications, 2026)
The challenge here was to design this enzyme, which used a genetic selection approach in modified E. coli to narrow down suitable enzymes, optimized for dealing with free CML. Once they were fairly confident that they had a working enzyme, they had to test it and observe the results.

This testing was performed in model proteins in vitro, as well as in tissue samples from elderly donors. These latter included lens, skin and arterial tissue, all of which are long-lived tissues that have plenty of time to collect CML. After treatment with CMLase the presence of CML in these tissues was reduced by 55% for skin and 75% for arterial tissue.

Of course, as also noted in the article these are ex vivo experiments that do not yet directly translate to living patients. An initial human trial would need to show safety above all, even if the amount of waste produced by the clean-up of CML won’t be that significant.

Subsequent trials would need to demonstrate that such removal of CML leads to healthier tissues, which if confirmed would open the path for other pathogenic AGEs to get their own matching enzyme.


hackaday.com/2026/07/27/de-agi…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Exploit pubblico per vBulletin: codice PHP eseguibile da remoto senza autenticazione

📌 Link all'articolo : redhotcyber.com/post/exploit-p…

Luigi Zullo

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

A Labour Of Love Brings A Kids Book To The Spectrum


The media in this post is not displayed to visitors. To view it, please log in.

Back in the early 1980s when 8-bit home computers became affordable educational toys for children, the traditional paper publishing industry did its best to keep up. For a few brief years, there were children’s books dedicated to the innards of a computer in meticulous detail, and courtesy of [Jason Jacques] we have a chance to look at one of the lesser-known ones.

The British publisher Ladybird made a series of four computer books, and while the first three had content for both the Sinclair Spectrum and the BBC Micro, the last in the series only featured the BBC. [Jason] took that book and re-imagined the missing Sinclair Spectrum version.

The surprise is how deep it dives into the architecture of an 8-bit computer, and it’s refreshing to see something that’s not unduly dumbed-down for kids. We’re guessing that this would have appealed to the 5% of kids who ran with their computers rather than just playing Jet Set Willy back then, and we’re sure a few grown-up 50-somethings may remember it or books like it.

If you think you may have seen Ladybird books here before, it may be because we reviewed another influential tech book of theirs for kids. Meanwhile you can take a look at the contemporary computer books from their arch-rival Usborne.


hackaday.com/2026/07/27/a-labo…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Citiverse aggiornato alla versione v4.14.2

Da ieri sera Citiverse è aggiornato alla versione 4.14.2.

Siamo passati dalla 4.14.0 alla 4.14.2 quindi per il changelog bisogna guardare anche quello della 4.14.1. Ve li lascio entrambi:

v4.14.1
v4.14.2

Ne approfitto anche per segnalare che dovremmo finalmente aver risolto un problema che ci portavamo dietro da qualche settimana e che non permetteva la federazione corretta con Feddit e con altri server del Fediverso! 🔥

Questa voce è stata modificata (12 ore fa)

Re-Testing an Apollo Guidance Computer Module that Failed Certification Testing


The media in this post is not displayed to visitors. To view it, please log in.

After getting his hands on a rope driver module from the Apollo project era that had a big ‘Scrapped Module’ stamped on it, [Mike Stewart] was naturally left curious as to what exactly had failed in this module. Originally destined for the Apollo Guidance Computer, these Raytheon-manufactured modules were the pinnacle of space-grade high-tech of the 1960s, with requisite acceptance testing so as to not endanger a very expensive space mission.

The cool part here is that the acceptance documents for the module in question (B16-B17) have been scanned in and can be found on the Internet Archive. With the part itself being potted and very much inaccessible, this document helpfully lays out the expected measurements on the module’s pins, as well as schematics and mechanical drawings. Unfortunately the reasons for the rejection were not recorded, so replicating the failing test results is required to understand the reason.
NASA Rope Driver Module with suspicious exploration marks. (Credit: Mike Stewart, YouTube)NASA Rope Driver Module with suspicious exploration marks. (Credit: Mike Stewart, YouTube)
A slight complication here is that the testing procedure doesn’t just involve hooking up a multimeter for some voltage and capacitance measurements. There are also temperature and voltage extremes, and vibration tolerance involved, which would be somewhat complex to test, but most of all risk damaging a historical artefact. Thus a somewhat conservative testing procedure was chosen, even if this may not reveal the actual fault.

As noted in the video, sometimes modules were also rejected because someone simply dropped it on the floor along the way. However, generally if a module was found to be faulty they would open it to diagnose said fault, with a closer look at this module indeed revealing suspicious marks in the potting compound where it was apparently opened and conceivably repaired. This also might explain why they also put the ‘For engineering use only’ on it.

With multiple of such locations visible in the potting compound, these locations were mapped to the schematics for the module, to get some idea of what may have been accessed. After this, basic testing was performed on the module, as per the acceptance testing document.

Along the way an error was detected in said document, in the form of the wrong pin number. In table 4-2 the input pin 269 was mistakenly listed as having output pin number 169 when it should have been pin 168. Pin 169 is chassis ground, so this was presumably fixed in a later version of the document.

After all the testing with just stationary, room-temperature conditions, everything appeared to check out. This means that likely this was indeed a repaired module that got subsequently used for engineering purposes rather than installed in flight-ready hardware. The only issue found was that channels were out of calibration, but whether this was an original flaw or due to the module being half a century old is hard to tell in the absence of repair logs.

Overall it’s an exciting opportunity to document another part of history, since so many of the details pertaining to these original modules and related technologies got lost or muddled over the decades.

youtube.com/embed/-VzQMX-DoDI?…


hackaday.com/2026/07/27/re-tes…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Reuters: #OpenAI Agent Hacked #Hugging #Face for Days Before Being Detected
securityaffairs.com/196120/ai/…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: After Redditors and journalists found an untold number of Claude chats publicly available on Google, Anthropic blamed the users.

The company told us that share links only appear in search results when they’ve been posted somewhere search engines can see, like a forum or on social media.

techcrunch.com/2026/07/27/psa-…

Reviving a Retro Mouse with BlueTooth low Energy support


The media in this post is not displayed to visitors. To view it, please log in.

Several mice and their internal electronics

One of the disadvantages to collecting retro peripherals is that they’re not necessarily easy to use anymore. [eSPee77] changes that by retrofitting a Genius GM-6000 mouse with modern hardware, all while preserving the feel.

To make this mouse without compromising on the feel of the original, means replacing the PCB with a new one while retaining the same buttons and encoders. So [eSPee77] did exactly that. At the heart of the conversion lies an nRF52840 on a custom PCB. It uses new optical sensors to read the existing quadrature encoders, and uses the same type of switch for the mouse buttons as the original.

But from there, it diverges because–powered by the BLE capabilities of the nRF–this is actually a wireless mouse! And the modern features don’t end there, either. To support scrolling on a mouse which did not originally have it, you can press the middle mouse button while moving it forward/backward. Finally, as the cherry on the cake, it features an “air mouse” mode using an inertial measurement unit, handy for use in presentations.


hackaday.com/2026/07/27/revivi…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The Cloud Security Alliance has released a post-mortem of the OpenAI hack of Hugging Face

HF apparently reviewed and cleared the report

cloudsecurityalliance.org/arti…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: I delved into the mystery of Phineas Fisher, probably the most prolific and public hacker never to have gotten caught.

This is what we know about the infamous hacktivist and their spectacular hacks against spyware makers FinFisher and Hacking Team.

There will be even more in my upcoming book.

techcrunch.com/2026/07/25/the-…

Regain Some Trust in Unknown USB Drives


The media in this post is not displayed to visitors. To view it, please log in.

For how useful USB thumb drives are for quickly toting around and copying files from one computer to another, they can be a bit of a security headache. Programs can be loaded on them with all kinds of malware; they can be obscured in some ways that are difficult to detect, and they can be set up to execute certain programs when they’re plugged in. The general wisdom is to simply avoid untrusted USB devices completely, but that sort of abstinence-only policy rarely works in the real world. If, for some reason, an untrusted USB device absolutely needs to be used, many of these security issues can be mitigated with this tool.

Built by [Novamostra], the device is simple on the surface: it’s a Raspberry Pi Pico mated to a 2-in-1 USB splitter cable. But with the USB Neutralizer software they have written loaded onto the Pico, it automatically destroys the ability of any connected USB thumb drive to load files. The program works by deleting the first and last 34 Logical Block Addressing (LBA) sectors on the drive immediately when it’s plugged in, without doing anything else. This effectively corrupts the drive bad enough to prevent malicious software in the partitions from doing anything, allowing the user to (relatively) safely put the USB drive into their computer and format it for re-use. The code for this tool is also open-source and reviewable on the project’s GitHub page.

Of course, this isn’t a perfect security solution for all USB attacks. It doesn’t erase or replace the firmware on the drive itself, and although firmware-level attacks are rare they’re not out of the question for all users, all the time. It also won’t prevent a malicious physical attack like this high-voltage one, and it may also not stop hidden or obscured partitions or devices programmed for storage and some other nefarious purpose simultaneously, like a USB HID. But still, this solves a great many of the problems associated with getting new drives from semi-untrustworthy sources, like retailers or friends whose computer skills we don’t fully trust.


hackaday.com/2026/07/27/regain…

The media in this post is not displayed to visitors. To view it, please log in.

JadeProx: il cluster cinese che si è tradito da solo mentre colpiva ospedali, ministeri e università in Asia


@Informatica (Italy e non Italy)
Un server Alibaba Cloud lasciato esposto ha rivelato JadeProx, cluster China-nexus dietro intrusioni contro un ospedale vietnamita, il Ministero degli Esteri malese e l'ateneo di Hong Kong. Al


JadeProx: il cluster cinese che si è tradito da solo mentre colpiva ospedali, ministeri e università in Asia


Un server Alibaba Cloud lasciato aperto per errore ha smascherato un intero cluster di cyberspionaggio China-nexus: intrusioni attive contro un ospedale vietnamita, il Ministero degli Esteri malese, decine di istituti universitari di Hong Kong e persino un pacchetto di spear-phishing indirizzato al Congresso dell’Honduras. Group-IB lo chiama JadeProx, e la sua tradecraft ruota attorno a un loader Windows mai documentato prima, il TriBack Loader, distribuito anche tramite un finto installer di Claude.

Un errore operativo che vale un intero dossier


A metà aprile 2026 i ricercatori di Group-IB hanno individuato, nella regione Singapore di Alibaba Cloud, un server di staging esposto senza alcuna autenticazione. Al momento della pubblicazione del report, il 23 luglio 2026, il server era già stato smantellato, ma la sua cronologia bash, i pacchetti di phishing, gli strumenti post-exploitation e i path dei webshell hanno permesso di ricostruire in dettaglio un’operazione attiva su tre continenti diversi.

Gli obiettivi identificati sono eterogenei ma coerenti con un mandato di raccolta informativa ad ampio spettro tipico degli operatori legati alla Cina: il sistema di imaging medicale (PACS, Picture Archiving and Communications System) di un ospedale pubblico vietnamita, da cui transitano radiografie, TAC e risonanze dei pazienti; il Ministero degli Esteri della Malesia, violato con webshell e strumenti di tunneling; l’infrastruttura universitaria di Hong Kong, colpita con una scansione massiva; e un pacchetto di spear-phishing con decoy finanziario indirizzato al Congresso Nazionale dell’Honduras. Gli operatori sono arrivati al server dell’ospedale vietnamita attraverso webshell piazzate su un’interfaccia di gestione Java esposta su Internet.

TriBack Loader: un unico loader, quattro varianti


Al centro della tradecraft c’è un loader Windows che Group-IB battezza TriBack Loader, mai documentato in precedenza. Compare in quattro catene di infezione, tutte costruite attorno al DLL sideloading: un eseguibile legittimo firmato viene abbinato a una DLL malevola e a un payload cifrato in formato .dat o .log.

La DLL inverte i byte del payload, li decifra con XOR a chiave rotante, ed esegue lo shellcode tramite chiamate Win32 che gli EDR monitorano meno rispetto alla classica CreateThread. Le quattro varianti si differenziano proprio nella chiamata finale usata per l’esecuzione: due si affidano a InitOnceExecuteOnce e a un callback TimerQueue, una terza sfrutta EtwpCreateEtwThread, una routine non documentata di ntdll per la creazione di thread. Anche il binario firmato ospite cambia da variante a variante. Per i ricercatori, la ripetizione sistematica della stessa sequenza di API suggerisce l’esistenza di un builder automatizzato per la generazione del loader.

Due varianti distribuiscono AdaptixC2, framework open source di post-exploitation già osservato in altre campagne ransomware. Una terza variante, particolarmente insidiosa, si maschera da software Claude: usa DonutLoader per eseguire Beagle, una backdoor documentata per la prima volta da Sophos. La quarta variante resta un mistero: il file cifrato che ne conteneva il payload non è mai stato recuperato.

L’esca perfetta: un finto Claude con MSI malevolo


Uno degli aspetti più rilevanti per un pubblico di professionisti è la campagna di impersonificazione del software Anthropic. Il dominio claude-pro[.]com, registrato il 28 marzo 2026, ha distribuito un installer MSI malevolo che, superato un prompt UAC, posizionava la catena di sideloading nella cartella di avvio di Windows per garantirsi la persistenza. La backdoor Beagle consegnata da questa variante comunicava con license[.]claude-pro[.]com come infrastruttura di comando e controllo.

Sophos, lavorando a partire dal sito fasullo, dalla sua infrastruttura di hosting e dai campioni di malware raccolti, ha rilevato la stessa chiave XOR riutilizzata in build risalenti a febbraio 2026, ma ha specificato che una chiave condivisa non basta da sola a confermare un singolo attore dietro tutte le campagne: nell’ecosistema China-nexus gli strumenti circolano liberamente tra gruppi diversi. Lo stesso approccio prudente vale per Group-IB, che raggruppa le intrusioni asiatiche sotto l’etichetta JadeProx senza attribuirle in modo definitivo a un gruppo APT già catalogato.

Se la valutazione di Sophos è corretta e il sito fasullo faceva parte di una campagna di malvertising attiva, l’esposizione va ben oltre ministeri e ospedali: raggiunge chiunque, nel mondo, stesse semplicemente cercando di scaricare Claude.

Vulnerabilità vecchie di anni per colpire infrastrutture nuove


Sul fronte dello scanning contro l’istruzione di Hong Kong, gli operatori hanno lanciato Nuclei con template a severità critica contro una lista di 14.653 URL legati al settore educativo, individuando 13 vulnerabilità uniche. Il report non specifica quanti tentativi di sfruttamento successivi abbiano avuto successo, ma indica quattro CVE specifiche tentate contro singoli host, tutte con punteggio CVSS 9.8: CVE-2018-11511 (ASUSTOR ADM), CVE-2021-24139 (plugin WordPress 10Web Photo Gallery), CVE-2021-31755 (router Tenda AC11) e CVE-2021-32305 (WebSVN).

Il dettaglio interessante per i difensori è che la falla su Tenda AC11 è nel catalogo KEV (Known Exploited Vulnerabilities) di CISA dal 3 novembre 2021, con una scadenza di remediation federale spirata appena due settimane dopo. In altre parole: la parte “artigianale” e sofisticata di questa operazione — loader custom, sideloading, ETW abuse — si appoggia a un ingresso iniziale banale, fatto di CVE pubbliche e non patchate da anni. L’ingegneria del loader conta poco se la porta d’ingresso resta aperta dal 2021.

Cosa monitorare


Group-IB e i ricercatori coinvolti raccomandano di concentrare il rilevamento sulla catena di sideloading piuttosto che sui singoli indicatori di rete, dato che nomi file e host firmati cambiano a ogni build:

  • Segnalare binari vendor firmati eseguiti da directory scrivibili dall’utente, temporanee o dalla cartella Startup, specialmente in presenza di file .dat o .log cifrati nella stessa cartella.
  • Cercare copie sospette di hostfxr.dll, avk.dll o MpClient.dll, insieme a cartelle annidate del tipo _CL_###### e allo script ~del.vbs.bat.
  • Bloccare o investigare i domini del cluster: claude-pro[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, e tre domini civetta che imitano vendor di sicurezza condividendo lo stesso IP — update-trellix[.]com, update-crowdstrike[.]com, update-sentinelone[.]com.
  • Dare priorità alle applicazioni Java esposte su Internet, quindi a qualsiasi sistema pubblico con una falla non patchata di severità 9.8, incluse le quattro citate.


Indicatori di compromissione

Domini:
claude-pro[.]com (registrato 28/03/2026)
license[.]claude-pro[.]com
sylverixstrategy[.]com
gouvvbo[.]top
vertextrust-advisors[.]com
update-trellix[.]com
update-crowdstrike[.]com
update-sentinelone[.]com

Infrastruttura di staging:
43.106.71[.]28:8000

CVE sfruttate (CVSS 9.8):
CVE-2018-11511 - ASUSTOR ADM
CVE-2021-24139 - 10Web Photo Gallery (WordPress)
CVE-2021-31755 - Tenda AC11 (KEV CISA dal 03/11/2021)
CVE-2021-32305 - WebSVN

Artefatti su disco:
hostfxr.dll / avk.dll / MpClient.dll (copie sospette)
_CL_###### (cartelle annidate)
~del.vbs.bat

Malware associato:
TriBack Loader (loader custom, DLL sideloading)
AdaptixC2 (post-exploitation open source)
DonutLoader -> Beagle backdoor

Fonti: report Group-IB, The Hacker News, Sophos.

Rassilon reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

#MedusaHVNC #Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data
securityaffairs.com/196111/mal…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The media in this post is not displayed to visitors. To view it, please go to the original post.

✨ JadeProx: il cluster cinese che si è tradito da solo mentre colpiva ospedali, ministeri e università in Asia
#CyberSecurity
insicurezzadigitale.com/jadepr…

@informatica


JadeProx: il cluster cinese che si è tradito da solo mentre colpiva ospedali, ministeri e università in Asia


Un server Alibaba Cloud lasciato aperto per errore ha smascherato un intero cluster di cyberspionaggio China-nexus: intrusioni attive contro un ospedale vietnamita, il Ministero degli Esteri malese, decine di istituti universitari di Hong Kong e persino un pacchetto di spear-phishing indirizzato al Congresso dell’Honduras. Group-IB lo chiama JadeProx, e la sua tradecraft ruota attorno a un loader Windows mai documentato prima, il TriBack Loader, distribuito anche tramite un finto installer di Claude.

Un errore operativo che vale un intero dossier


A metà aprile 2026 i ricercatori di Group-IB hanno individuato, nella regione Singapore di Alibaba Cloud, un server di staging esposto senza alcuna autenticazione. Al momento della pubblicazione del report, il 23 luglio 2026, il server era già stato smantellato, ma la sua cronologia bash, i pacchetti di phishing, gli strumenti post-exploitation e i path dei webshell hanno permesso di ricostruire in dettaglio un’operazione attiva su tre continenti diversi.

Gli obiettivi identificati sono eterogenei ma coerenti con un mandato di raccolta informativa ad ampio spettro tipico degli operatori legati alla Cina: il sistema di imaging medicale (PACS, Picture Archiving and Communications System) di un ospedale pubblico vietnamita, da cui transitano radiografie, TAC e risonanze dei pazienti; il Ministero degli Esteri della Malesia, violato con webshell e strumenti di tunneling; l’infrastruttura universitaria di Hong Kong, colpita con una scansione massiva; e un pacchetto di spear-phishing con decoy finanziario indirizzato al Congresso Nazionale dell’Honduras. Gli operatori sono arrivati al server dell’ospedale vietnamita attraverso webshell piazzate su un’interfaccia di gestione Java esposta su Internet.

TriBack Loader: un unico loader, quattro varianti


Al centro della tradecraft c’è un loader Windows che Group-IB battezza TriBack Loader, mai documentato in precedenza. Compare in quattro catene di infezione, tutte costruite attorno al DLL sideloading: un eseguibile legittimo firmato viene abbinato a una DLL malevola e a un payload cifrato in formato .dat o .log.

La DLL inverte i byte del payload, li decifra con XOR a chiave rotante, ed esegue lo shellcode tramite chiamate Win32 che gli EDR monitorano meno rispetto alla classica CreateThread. Le quattro varianti si differenziano proprio nella chiamata finale usata per l’esecuzione: due si affidano a InitOnceExecuteOnce e a un callback TimerQueue, una terza sfrutta EtwpCreateEtwThread, una routine non documentata di ntdll per la creazione di thread. Anche il binario firmato ospite cambia da variante a variante. Per i ricercatori, la ripetizione sistematica della stessa sequenza di API suggerisce l’esistenza di un builder automatizzato per la generazione del loader.

Due varianti distribuiscono AdaptixC2, framework open source di post-exploitation già osservato in altre campagne ransomware. Una terza variante, particolarmente insidiosa, si maschera da software Claude: usa DonutLoader per eseguire Beagle, una backdoor documentata per la prima volta da Sophos. La quarta variante resta un mistero: il file cifrato che ne conteneva il payload non è mai stato recuperato.

L’esca perfetta: un finto Claude con MSI malevolo


Uno degli aspetti più rilevanti per un pubblico di professionisti è la campagna di impersonificazione del software Anthropic. Il dominio claude-pro[.]com, registrato il 28 marzo 2026, ha distribuito un installer MSI malevolo che, superato un prompt UAC, posizionava la catena di sideloading nella cartella di avvio di Windows per garantirsi la persistenza. La backdoor Beagle consegnata da questa variante comunicava con license[.]claude-pro[.]com come infrastruttura di comando e controllo.

Sophos, lavorando a partire dal sito fasullo, dalla sua infrastruttura di hosting e dai campioni di malware raccolti, ha rilevato la stessa chiave XOR riutilizzata in build risalenti a febbraio 2026, ma ha specificato che una chiave condivisa non basta da sola a confermare un singolo attore dietro tutte le campagne: nell’ecosistema China-nexus gli strumenti circolano liberamente tra gruppi diversi. Lo stesso approccio prudente vale per Group-IB, che raggruppa le intrusioni asiatiche sotto l’etichetta JadeProx senza attribuirle in modo definitivo a un gruppo APT già catalogato.

Se la valutazione di Sophos è corretta e il sito fasullo faceva parte di una campagna di malvertising attiva, l’esposizione va ben oltre ministeri e ospedali: raggiunge chiunque, nel mondo, stesse semplicemente cercando di scaricare Claude.

Vulnerabilità vecchie di anni per colpire infrastrutture nuove


Sul fronte dello scanning contro l’istruzione di Hong Kong, gli operatori hanno lanciato Nuclei con template a severità critica contro una lista di 14.653 URL legati al settore educativo, individuando 13 vulnerabilità uniche. Il report non specifica quanti tentativi di sfruttamento successivi abbiano avuto successo, ma indica quattro CVE specifiche tentate contro singoli host, tutte con punteggio CVSS 9.8: CVE-2018-11511 (ASUSTOR ADM), CVE-2021-24139 (plugin WordPress 10Web Photo Gallery), CVE-2021-31755 (router Tenda AC11) e CVE-2021-32305 (WebSVN).

Il dettaglio interessante per i difensori è che la falla su Tenda AC11 è nel catalogo KEV (Known Exploited Vulnerabilities) di CISA dal 3 novembre 2021, con una scadenza di remediation federale spirata appena due settimane dopo. In altre parole: la parte “artigianale” e sofisticata di questa operazione — loader custom, sideloading, ETW abuse — si appoggia a un ingresso iniziale banale, fatto di CVE pubbliche e non patchate da anni. L’ingegneria del loader conta poco se la porta d’ingresso resta aperta dal 2021.

Cosa monitorare


Group-IB e i ricercatori coinvolti raccomandano di concentrare il rilevamento sulla catena di sideloading piuttosto che sui singoli indicatori di rete, dato che nomi file e host firmati cambiano a ogni build:

  • Segnalare binari vendor firmati eseguiti da directory scrivibili dall’utente, temporanee o dalla cartella Startup, specialmente in presenza di file .dat o .log cifrati nella stessa cartella.
  • Cercare copie sospette di hostfxr.dll, avk.dll o MpClient.dll, insieme a cartelle annidate del tipo _CL_###### e allo script ~del.vbs.bat.
  • Bloccare o investigare i domini del cluster: claude-pro[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, e tre domini civetta che imitano vendor di sicurezza condividendo lo stesso IP — update-trellix[.]com, update-crowdstrike[.]com, update-sentinelone[.]com.
  • Dare priorità alle applicazioni Java esposte su Internet, quindi a qualsiasi sistema pubblico con una falla non patchata di severità 9.8, incluse le quattro citate.


Indicatori di compromissione

Domini:
claude-pro[.]com (registrato 28/03/2026)
license[.]claude-pro[.]com
sylverixstrategy[.]com
gouvvbo[.]top
vertextrust-advisors[.]com
update-trellix[.]com
update-crowdstrike[.]com
update-sentinelone[.]com

Infrastruttura di staging:
43.106.71[.]28:8000

CVE sfruttate (CVSS 9.8):
CVE-2018-11511 - ASUSTOR ADM
CVE-2021-24139 - 10Web Photo Gallery (WordPress)
CVE-2021-31755 - Tenda AC11 (KEV CISA dal 03/11/2021)
CVE-2021-32305 - WebSVN

Artefatti su disco:
hostfxr.dll / avk.dll / MpClient.dll (copie sospette)
_CL_###### (cartelle annidate)
~del.vbs.bat

Malware associato:
TriBack Loader (loader custom, DLL sideloading)
AdaptixC2 (post-exploitation open source)
DonutLoader -> Beagle backdoor

Fonti: report Group-IB, The Hacker News, Sophos.

Flexible PCBs: Not Only For The Few


The media in this post is not displayed to visitors. To view it, please log in.

Flexible printed circuit boards are a fascinating technique for making electronics venture beyond the two-dimensional, but surprisingly they’re not something many of us have worked with. [Jessica Stanley] gave a talk at the recent Electromagnetic Field event in the UK, exploring the different ways to make your electronics bend.

She starts with an overview of flexible electronics, detailing the techniques used with conventional polyimide substrates and etched copper. We’re particularly enamoured of a stretchable PCB made by coiling a flexible circuit round a piece of elastic. Since she’s looking for techniques accessible to everyone that don’t either cost a fortune or require dangerous chemicals we look at conductive paint and electrolysis, before arriving at using a vinyl cutter to create adhesive traces.

We’ve no doubt all noticed that flexible PCBs can be ordered from the usual fabrication houses at a price, but the value in this talk lies in reminding the viewer that this is not the only path. She demonstrates well that simple flexible PCBs can be within the reach of almost anyone, which is perhaps the encouragement needed for people to try this medium. The full talk is below the break.

media.ccc.de/v/emf2026-235-1-f…


hackaday.com/2026/07/27/flexib…

Cybersecurity & cyberwarfare ha ricondiviso questo.

JadeProx: il cluster cinese che si è tradito da solo mentre colpiva ospedali, ministeri e università in Asia


Un server Alibaba Cloud lasciato esposto ha rivelato JadeProx, cluster China-nexus dietro intrusioni contro un ospedale vietnamita, il Ministero degli Esteri malese e l'ateneo di Hong Kong. Al centro, il nuovo TriBack Loader e un finto installer di Claude usato come esca.
The media in this post is not displayed to visitors. To view it, please go to the original post.

Un server Alibaba Cloud lasciato aperto per errore ha smascherato un intero cluster di cyberspionaggio China-nexus: intrusioni attive contro un ospedale vietnamita, il Ministero degli Esteri malese, decine di istituti universitari di Hong Kong e persino un pacchetto di spear-phishing indirizzato al Congresso dell’Honduras. Group-IB lo chiama JadeProx, e la sua tradecraft ruota attorno a un loader Windows mai documentato prima, il TriBack Loader, distribuito anche tramite un finto installer di Claude.

Un errore operativo che vale un intero dossier


A metà aprile 2026 i ricercatori di Group-IB hanno individuato, nella regione Singapore di Alibaba Cloud, un server di staging esposto senza alcuna autenticazione. Al momento della pubblicazione del report, il 23 luglio 2026, il server era già stato smantellato, ma la sua cronologia bash, i pacchetti di phishing, gli strumenti post-exploitation e i path dei webshell hanno permesso di ricostruire in dettaglio un’operazione attiva su tre continenti diversi.

Gli obiettivi identificati sono eterogenei ma coerenti con un mandato di raccolta informativa ad ampio spettro tipico degli operatori legati alla Cina: il sistema di imaging medicale (PACS, Picture Archiving and Communications System) di un ospedale pubblico vietnamita, da cui transitano radiografie, TAC e risonanze dei pazienti; il Ministero degli Esteri della Malesia, violato con webshell e strumenti di tunneling; l’infrastruttura universitaria di Hong Kong, colpita con una scansione massiva; e un pacchetto di spear-phishing con decoy finanziario indirizzato al Congresso Nazionale dell’Honduras. Gli operatori sono arrivati al server dell’ospedale vietnamita attraverso webshell piazzate su un’interfaccia di gestione Java esposta su Internet.

TriBack Loader: un unico loader, quattro varianti


Al centro della tradecraft c’è un loader Windows che Group-IB battezza TriBack Loader, mai documentato in precedenza. Compare in quattro catene di infezione, tutte costruite attorno al DLL sideloading: un eseguibile legittimo firmato viene abbinato a una DLL malevola e a un payload cifrato in formato .dat o .log.

La DLL inverte i byte del payload, li decifra con XOR a chiave rotante, ed esegue lo shellcode tramite chiamate Win32 che gli EDR monitorano meno rispetto alla classica CreateThread. Le quattro varianti si differenziano proprio nella chiamata finale usata per l’esecuzione: due si affidano a InitOnceExecuteOnce e a un callback TimerQueue, una terza sfrutta EtwpCreateEtwThread, una routine non documentata di ntdll per la creazione di thread. Anche il binario firmato ospite cambia da variante a variante. Per i ricercatori, la ripetizione sistematica della stessa sequenza di API suggerisce l’esistenza di un builder automatizzato per la generazione del loader.

Due varianti distribuiscono AdaptixC2, framework open source di post-exploitation già osservato in altre campagne ransomware. Una terza variante, particolarmente insidiosa, si maschera da software Claude: usa DonutLoader per eseguire Beagle, una backdoor documentata per la prima volta da Sophos. La quarta variante resta un mistero: il file cifrato che ne conteneva il payload non è mai stato recuperato.

L’esca perfetta: un finto Claude con MSI malevolo


Uno degli aspetti più rilevanti per un pubblico di professionisti è la campagna di impersonificazione del software Anthropic. Il dominio claude-pro[.]com, registrato il 28 marzo 2026, ha distribuito un installer MSI malevolo che, superato un prompt UAC, posizionava la catena di sideloading nella cartella di avvio di Windows per garantirsi la persistenza. La backdoor Beagle consegnata da questa variante comunicava con license[.]claude-pro[.]com come infrastruttura di comando e controllo.

Sophos, lavorando a partire dal sito fasullo, dalla sua infrastruttura di hosting e dai campioni di malware raccolti, ha rilevato la stessa chiave XOR riutilizzata in build risalenti a febbraio 2026, ma ha specificato che una chiave condivisa non basta da sola a confermare un singolo attore dietro tutte le campagne: nell’ecosistema China-nexus gli strumenti circolano liberamente tra gruppi diversi. Lo stesso approccio prudente vale per Group-IB, che raggruppa le intrusioni asiatiche sotto l’etichetta JadeProx senza attribuirle in modo definitivo a un gruppo APT già catalogato.

Se la valutazione di Sophos è corretta e il sito fasullo faceva parte di una campagna di malvertising attiva, l’esposizione va ben oltre ministeri e ospedali: raggiunge chiunque, nel mondo, stesse semplicemente cercando di scaricare Claude.

Vulnerabilità vecchie di anni per colpire infrastrutture nuove


Sul fronte dello scanning contro l’istruzione di Hong Kong, gli operatori hanno lanciato Nuclei con template a severità critica contro una lista di 14.653 URL legati al settore educativo, individuando 13 vulnerabilità uniche. Il report non specifica quanti tentativi di sfruttamento successivi abbiano avuto successo, ma indica quattro CVE specifiche tentate contro singoli host, tutte con punteggio CVSS 9.8: CVE-2018-11511 (ASUSTOR ADM), CVE-2021-24139 (plugin WordPress 10Web Photo Gallery), CVE-2021-31755 (router Tenda AC11) e CVE-2021-32305 (WebSVN).

Il dettaglio interessante per i difensori è che la falla su Tenda AC11 è nel catalogo KEV (Known Exploited Vulnerabilities) di CISA dal 3 novembre 2021, con una scadenza di remediation federale spirata appena due settimane dopo. In altre parole: la parte “artigianale” e sofisticata di questa operazione — loader custom, sideloading, ETW abuse — si appoggia a un ingresso iniziale banale, fatto di CVE pubbliche e non patchate da anni. L’ingegneria del loader conta poco se la porta d’ingresso resta aperta dal 2021.

Cosa monitorare


Group-IB e i ricercatori coinvolti raccomandano di concentrare il rilevamento sulla catena di sideloading piuttosto che sui singoli indicatori di rete, dato che nomi file e host firmati cambiano a ogni build:

  • Segnalare binari vendor firmati eseguiti da directory scrivibili dall’utente, temporanee o dalla cartella Startup, specialmente in presenza di file .dat o .log cifrati nella stessa cartella.
  • Cercare copie sospette di hostfxr.dll, avk.dll o MpClient.dll, insieme a cartelle annidate del tipo _CL_###### e allo script ~del.vbs.bat.
  • Bloccare o investigare i domini del cluster: claude-pro[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, e tre domini civetta che imitano vendor di sicurezza condividendo lo stesso IP — update-trellix[.]com, update-crowdstrike[.]com, update-sentinelone[.]com.
  • Dare priorità alle applicazioni Java esposte su Internet, quindi a qualsiasi sistema pubblico con una falla non patchata di severità 9.8, incluse le quattro citate.


Indicatori di compromissione

Domini:
claude-pro[.]com (registrato 28/03/2026)
license[.]claude-pro[.]com
sylverixstrategy[.]com
gouvvbo[.]top
vertextrust-advisors[.]com
update-trellix[.]com
update-crowdstrike[.]com
update-sentinelone[.]com

Infrastruttura di staging:
43.106.71[.]28:8000

CVE sfruttate (CVSS 9.8):
CVE-2018-11511 - ASUSTOR ADM
CVE-2021-24139 - 10Web Photo Gallery (WordPress)
CVE-2021-31755 - Tenda AC11 (KEV CISA dal 03/11/2021)
CVE-2021-32305 - WebSVN

Artefatti su disco:
hostfxr.dll / avk.dll / MpClient.dll (copie sospette)
_CL_###### (cartelle annidate)
~del.vbs.bat

Malware associato:
TriBack Loader (loader custom, DLL sideloading)
AdaptixC2 (post-exploitation open source)
DonutLoader -> Beagle backdoor

Fonti: report Group-IB, The Hacker News, Sophos.
Cybersecurity & cyberwarfare ha ricondiviso questo.

Nella vita credo che conoscere persone interessanti sia un ottimo modo per crescere, non solo professionalmente, ma come essere umano.

Questa è stata una di quelle volte.

Con grande piacere, vi porto la mia intervista ad @elettrona che tra #accessibilità , #social , #tecnologia , #fediverso , #linux e #OpenSource ha arricchito di sicuro il mio bagaglio culturale.

Ringraziandola infinitamente per il suo tempo e l'opportunità, vi lascio il link al video 😉

youtu.be/Cf682e50O4U?is=fdV3Bk…

@linux

in reply to Lorenzo DM

ciao! L'amministratore di poliversity è @informapirata che è pure un moderatore di mastodon.uno, e fa parte della stessa associazione @fedimedia quindi non è certo con lui che ci sono ruggini.
Sinceramente non intervengo ormai da anni con chi vuole fare le guerre fra poveri, a Novembre saremo presenti al SFSCON il più grande evento italiano sul mondo "libero": L'invito è aperto a tutti, il confronto diretto di persona è sempre più utile delle polemiche da social.
in reply to filippodb ⁂

@filippodb @informapirata @fedimedia perdonami di quali ruggini parli? Non ho mai detto nulla riguardo ruggini, attriti, ecc. Così come non ho mai accennato a convegni o associazioni in tutta l'intervista 😅 con Informa Pirata siamo amici e non abbiamo alcun tipo di attrito, anzi i rapporti sono super cordiali.

Se con pazienza ascolterai tutta l'intervista invece (quasi 2h capisco siano tante) scoprirai che affrontiamo i problemi di Linux sull'accessibilità oltre che tantissimi altri temi molto interessanti (tra cui il fediverso), per cui non capisco dove si fosse fuori tema.

Per altre questioni (a me oscure) non saprei come aiutarti invece, mi spiace 😅

in reply to Elena Brescacin

speriamo bene, hanno detto che a Bolzano hanno avuto un boom di proposte, solo noi abbiamo una ventina di talk e spero/credo li accettino tutti visto che sarà presente anche il gran capo del digital indipendence day europeo. Ma sicuramente ci sarà una grande selezione. Io lotterò perché tutti partecipino e credo non ci siano problemi visto che sono molto contenti dell’iniziativa.
in reply to filippodb ⁂

@filippodb @informapirata @fedimedia se poi mi stai invitando a qualche convegno come relatore (davvero non so come interpretare il messaggio sul convegno di novembre) posso vedere le mie disponibilità lavorative in base agli slot che il mio lavoro principale può permettermi nelle giornate preposte di novembre. Nel caso, possiamo sentirci in privato, tanto sai che sono sempre disposto a partecipare come relatore ovunque 😉

Neanche io sono per le guerre (a quali ti riferisci nello specifico poi non so, visto che io sono in buoni rapporti con tutti) meglio fare unione nel mondo Open e lavorare in un'unica direzione comune che faccia fronte e permetta all'Open Source di emergere in Italia, in Europa e nel Mondo, così come potrebbe tranquillamente fare. Senza veti, obblighi e immobilismo. Liberamente, come è nella sua filosofia e nel suo spirito che tanto mi ha appassionato negli anni 😉

Un saluto!

informapirata ⁂ reshared this.

in reply to Lorenzo DM

@filippodb

Intervista molto interessante!
A volte nascono dei "contrasti" anche all'interno del Fediverso, ma non sembra questo il caso.

Mi è capitato di sentire persone che accusano questa o quella istanza di attuare tattiche di "accentramento", a scapito della filosofia del fediverso stesso.

Io non ho avuto questo sentore finora, e ricordiamoci che siamo in un mondo basato sulle donazioni.
Sarebbe diverso se qualcuno cercasse di acchiappiare utenti a fini commerciali.

in reply to DajeLinux

io sono qui da anni e ne ho visti di guerrieri da tastiera venire e sparire 😀 poi contro Mastodon.social e pixelfed.social c’era anche la campagna per defederarli perché accentravano troppo e per altre motivazioni di lana caprina. Il risultato è che ora sono ancora più concentrate e grandi. 😀
Sono un pericolo per il fediverso? No. Centralizzano? Sì verso loro stessi e non è un pericolo è solo che istanze così grandi sono dispersive
Questa voce è stata modificata (9 ore fa)
in reply to DajeLinux

@dajelinux ti ringrazio! Si, non ci sono attriti con nessuno per quanto mi riguarda, e sai che ci tengo a dare spazio a tutte le persone che ritengo interessanti come Elena.

Credo che la forza dell'Open sia nella sua libertà e nel non voler combattersi a vicenda. Chi lo fa, semplicemente sbaglia e non penso possa neanche definirsi davvero Open 😉

Lasciamo libertà di pensiero e di idee, solo così vedremo tante bellissime cose nascere!

Grazie di cuore Luca per il tuo apprezzamento, come sempre è un piacere sentirti

Cybersecurity & cyberwarfare ha ricondiviso questo.

In Croazia c'è un borgo fortificato (dicono) tra i meglio conservati d'Europa. "La piccola Venezia", lo chiamano. Ma sarà vero?


The media in this post is not displayed to visitors. To view it, please go to the original post.


La Verità su Trogir: è davvero la piccola Venezia della Croazia? (+ borghi circostanti)


In questo nuovo capitolo del mio viaggio in Croazia, vi porto a Trogir (Traù). Viene definita "la piccola Venezia della Croazia" e anche "il borgo medievale fortificato meglio conservato d'Europa"... ma sarà davvero così?

Come sapete, su questo canale cerco l'autenticità e in questo video vi dico in tutta onestà cosa ne penso. Trogir è bellissima, un gioiello architettonico, ma la sensazione è quella di un "parco giochi a cielo aperto" creato a tavolino per il turismo di massa. Mi ha ricordato un po' Grazzano Visconti (che, nel suo "non avere pretese, invece, è bella): opere d'arte reali, ma un'anima che sembra essersi persa tra negozi di souvenir e menu turistici.

Per fortuna, a pochi chilometri da Spalato, ho scoperto la zona dei Castelli. Qui il ritmo cambia: borghi fortificati che profumano di storia vera, mura che raccontano di incursioni di pirati e un mare cristallino che non ha nulla da invidiare alla mia amata Sardegna.

Unisciti alla mia Community dei Viaggiatori su Feddit! Se anche tu ami viaggiare fuori dai sentieri battuti questo è il posto giusto per condividere esperienze genuine, fotografie e consigli senza filtri. Cita

@viaggi@feddit.it

se vuoi postare qualcosa nel gruppo.

E voi cosa ne pensate? Siete stati a Trogir? Avete avuto la mia stessa impressione o vi ha incantato? Parliamone nei commenti!

Capitoli del video:

00:00 Arrivo a Trogir: un'isola molto particolare
00:46 La "Piccola Venezia": prime impressioni e costi
01:42 La Fortezza di Camarlengo (vista da fuori)
03:10 Riflessioni: un posto senz'anima?
05:07 Il fascino veneziano e i miei dubbi sulla "fama"
07:15 Piazza del Comune: ho cambiato idea?
08:32 Il lato commerciale di Trogir
10:18 Alla scoperta della zona dei Castelli
11:15 Castel San Giorgio e la storia dei pirati
12:44 Castel Gomilica: un borgo che vive ancora
14:40 Castel Vitturi: scenografia sull'acqua
16:36 Spalato e il traffico "napoletano"
18:27 Relax sul lungomare: un mare da Sardegna
19:41 Prossima tappa: l'impatto con la Bosnia

#Croazia #Trogir #ViaggiAutentici #IlSimoneViaggiatore #Fediverso #CastelliCroazia #TravelVlog


reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

I will remind you that OpenAI is worth nearly $1,000,000,000,000.
The going rate for an engineer that knows how to secure a website is $166,000/year.

cyberplace.social/@GossiTheDog…


Google search:

site:claude.ai/public

Coming soon to
claude.ai/robots.txt

/share was full of chats but they added it to robots.txt


reshared this

M.A.S.K.-Inspired Cyberdeck for all your Portable Computing needs


The media in this post is not displayed to visitors. To view it, please log in.

There are infinite varieties of cyberdeck you could make, each with their own inspirations. Today, [RadioactiveArtist] shows us a M.A.S.K. lunchbox cyberdeck faithful to the 80s show.

To know why putting a cyberdeck in a lunchbox is exactly the kind of thing you would see in the show, [RadioactiveArtist] briefly explains what both are (but we’ll skip the former): M.A.S.K. is a cartoon running from ’85 to ’86 where ordinary objects transform to reveal a hidden purpose–and this cyberdeck does just that by hiding in M.A.S.K. merchandise: the lunch box.

Like any cyberdeck build, it starts as a pile of components on a desk. It’s made from a Raspberry Pi 5, a cute little 75% keyboard, stereo speakers, a card reader with some USB 3 ports and of course a battery made with four 18650 cells. After testing the electronics on the bench, [RadioactiveArtist] test-fits them in the lunch box before revealing the plan: keyboard and speakers on the bottom, thinner half, the rest on top, and the screen on a second hinge so it can flip up when opened.

The construction itself doesn’t harm the lunch box, because it shouldn’t be obvious that this isn’t just lunch. (Bonus points because the box itself is vintage.) Everything that was screwed into, was sacrificial material like plastic, which was then placed into the lunch box. The keyboard and speakers are fully enclosed on the bottom, which looks very sleek, but the top is exposed–both because it’s easier to access and fix, and because it looks cool.

[RadioactiveArtist] goes over all this and more, in the video below:
youtube.com/embed/1Y7mCeVBv5U?…


hackaday.com/2026/07/27/m-a-s-…

L’INTELLIGENCE DEGLI ITTITI (PRIMA PARTE)

@Informatica (Italy e non Italy)

La tarda Età del Bronzo (secoli dal XV al XIII a.C.) ha rappresentato per l’antico vicino Oriente un’epoca di grande interazione politica, economica e culturale.
L'articolo L’INTELLIGENCE DEGLI ITTITI (PRIMA PARTE) proviene da GIANO NEWS.
#DIFESA

Gazzetta del Cadavere reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

Il #Garanteprivacy sanziona #Lusha per 2 milioni di euro. Monitorati e in vendita i dati di un elevato numero di persone

Il data broker Usa, che fornisce a pagamento informazioni “arricchite” su persone fisiche, ha trattato illecitamente i dati personali di un elevato numero di individui presenti sul territorio italiano

gpdp.it/home/docweb/-/docweb-d…

@privacypride@feddit.it

NIS2 e supply chain: le nuove FAQ ACN cambiano la gestione del rischio fornitori


@Informatica (Italy e non Italy)
ACN aggiorna le FAQ sulla supply chain dei soggetti NIS: le quattro fasi della gestione del rischio fornitori, i criteri minimi di valutazione e la proporzionalità dei requisiti nei contratti misti. Una guida operativa per il percorso di conformità

reshared this

in reply to Cybersecurity & cyberwarfare

> @cybersecurity@poliverso.org ha detto in NIS2 e supply chain: le nuove FAQ ACN cambiano la gestione del rischio fornitori:
>
> i soggetti NIS

"I soggetti NIS" sembrano delle persone con un disturbo patologico...


NIS2 e supply chain: le nuove FAQ ACN cambiano la gestione del rischio fornitori


@Informatica (Italy e non Italy)
ACN aggiorna le FAQ sulla supply chain dei soggetti NIS: le quattro fasi della gestione del rischio fornitori, i criteri minimi di valutazione e la proporzionalità dei requisiti nei contratti misti. Una guida operativa per il percorso di conformità


Hackaday Europe 2026: High Performance SDR On The Cheap


The media in this post is not displayed to visitors. To view it, please log in.

Radios were once big complicated appliances, full of warm valves and paper-wrapped capacitors, all humming and glowing to capture signals from the aether and spit them out of a speaker. Every component was chosen to build the radio to suit a particular purpose.

These days, we have altogether fancier technology that lets us build radios that can be reconfigured on the fly; software-defined radios, if you will. [Anders Nielsen] has been exploring how to build a high-performance SDR recently, and came to Hackaday Europe 2026 to tell us all about it.

SDR Killed The Radio Star


youtube.com/embed/uKCpQ13NyUo?…

[Anders] is a bit of hacker type. He’s a firmware developer for satellites in his day job, and he’s always a fan of tinkering with old integrated circuits and trying to build new and interesting things with them. Recently, though, his personal project has been developing a software-defined radio on a budget of under $50.

Now, [Anders] could have simply bought a cheap SDR off the shelf; he himself calls out the Zync/AD9363 platform as one particular example. However, he notes that many available options hide a lot of the signal chain and come at a certain price. He wanted to build something cheap and transparent for experimentation’s sake.
Early testing just relied on using a soundcard as an ADC to verify things were working.
The ultimate goal was to build an affordable SDR with a bandwidth up to 20 MHz. To reach this in his build, [Anders] picked a TLV3253 to serve in the quadrature sampling role, for its quick switching speed and low on resistance. It’s paired with a Silicon Labs 5351 which serves as the local oscillator. It’s possible to phase offset two clocks from the same phased-locked loop, allowing the generation of multiple clocks of the same frequency but offset by 90 degrees. An ADA4891 op-amp is used as a buffer between the capacitors of the quadrature sampling detector and the analog-to-digital converter itself. Testing began with a very simple ADC—a soundcard, capable of up to 44.1 KHz of bandwidth. Later, [Anders] stepped up to using an STM32 with a dual ADC for 200 KHz bandwidth. Eventually, though, the build was upgraded to the HT9201 dual 20 MHz 10-bit ADC. Getting the signal into the computer is handled with an FX2LP clone, which can stream data over USB 2.0 at high speed. With a nominal 480 megabits on offer, the choice is to run with 20 MHz of bandwidth at 8-bit samples, or 10 MHz of bandwidth with 10-bit samples.
[Anders] laced together the build, piece by piece. It’s less integrated than some off the shelf solutions out there, but it’s cheaper, too.The live demo showed the SDR pulling in the whole FM broadcast spectrum at once—a neat way to put the rig through its paces.
There were some challenges that cropped up along the way. Getting a flat analog frequency response proved difficult, with [Anders] noting this requires good attention to PCB layout, as well as things like amplification and filtering. There were also difficulties with clock jitter and synchronization, and bandwidth limitations in the front end. However, none of this stopped [Anders] from giving a live demo of the SDR in action during the talk. He showed off his rig pulling in the whole FM broadcast band, all at once. The crunchy sound of a commercial station coming in live was an excellent way to show that the SDR indeed was functioning as intended. [Anders] also used this as an opportunity to show some tricks to identifying and dealing with mirror signals when they pop up. There’s plenty that [Anders] wants to do with this project going forward, too. He notes that a wideband front-end mixer is on the cards, as well as a low-noise amplifier and an improved filtering strategy, all of which should improve flexibility and performance.

It’s not the greatest SDR out there, but it is one that taught [Anders] a great deal, and could do the same for others eager to tinker in this field. Sometimes the best way to learn about something is to go and build one for yourself, and this project proves that as so many have done before. It’s exactly what we love to see at a Hackaday conference!


hackaday.com/2026/07/27/hackad…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

UE punta il dito su TikTok! Gravi le accuse sull’algoritmo che tiene incollati i ragazzi alla piattaforma

📌 Link all'articolo : redhotcyber.com/post/ue-punta-…

Carolina Vivianti

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

#DentaQuest disclosed a data breach that impacted +23 million individuals
securityaffairs.com/196100/dat…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

Writeup of the openai attack on HuggingFace via @campuscodi
Key points
- access to source: OSS code, trivially decompiled JAR files,... allows for the LLMs to perform offline searches for vulnerabilities at scale. Then, when the goal "solve this problem" could only be met by attacking an external company, it did.

Interesting hypothesis that part of the attack may have involved supplying malicious artifacts to other systems to get them to run your exploit. This is why package managers must require signed artifacts & build tools must check them

#cybersecurity

hacktron.ai/blog/here-is-how-o…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

GrapheneOS protections against data extraction from locked devices
L: discuss.grapheneos.org/d/40700…
C: news.ycombinator.com/item?id=4…
posted on 2026.07.26 at 01:57:22 (c=0, p=3)

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Five-Year-Old Bugs in a JSON Parser Open a Code Execution Hole in Self-Managed GitLab
#CyberSecurity
securebulletin.com/five-year-o…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Foxit’s Own Update Service Can Be Turned Into a SYSTEM-Level Backdoor on Windows
#CyberSecurity
securebulletin.com/foxits-own-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

OpenAI Patches ‘AgentForger’ Flaw That Let One Link Hijack ChatGPT Workspace Agents
#CyberSecurity
securebulletin.com/openai-patc…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

JetBrains Patches a Wave of Critical Flaws Across IntelliJ IDEA and TeamCity
#CyberSecurity
securebulletin.com/jetbrains-p…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Claude AI’s Shared Chat Links Briefly Turned Up in Google Search, Exposing Private Conversations
#CyberSecurity
securebulletin.com/claude-ais-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Inside the Pro-Iran Hacktivist Coalition Racing to Mobilize During the US-Iran Conflict
#CyberSecurity
securebulletin.com/inside-the-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

AI-Powered Pentest Uncovers Eight Security Holes in Popular NodeBB Forum Software
#CyberSecurity
securebulletin.com/ai-powered-…

Questo account è gestito da @informapirata ⁂ e propone e ricondivide articoli di cybersecurity e cyberwarfare, in italiano e in inglese

I post possono essere di diversi tipi:

1) post pubblicati manualmente
2) post pubblicati da feed di alcune testate selezionate
3) ricondivisioni manuali di altri account
4) ricondivisioni automatiche di altri account gestiti da esperti di cybersecurity

NB: purtroppo i post pubblicati da feed di alcune testate includono i cosiddetti "redazionali"; i redazionali sono di fatto delle pubblicità che gli inserzionisti pubblicano per elogiare i propri servizi: di solito li eliminiamo manualmente, ma a volte può capitare che non ce ne accorgiamo (e no: non siamo sempre on line!) e quindi possono rimanere on line alcuni giorni. Fermo restando che le testate che ricondividiamo sono gratuite e che i redazionali sono uno dei metodi più etici per sostenersi economicamente, deve essere chiaro che questo account non riceve alcun contributo da queste pubblicazioni.

reshared this