Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Hugging Face Breach Reveals a New Front: AI Agents Attacking, AI Agents Defending
#CyberSecurity
securebulletin.com/hugging-fac…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

AnyDesk: l’accesso remoto è stato bloccato a causa di uno zero-day

📌 Link all'articolo : redhotcyber.com/post/anydesk-l…

A cura di Luigi Zullo

#redhotcyber #news #vulnerabilitazero #accessoremoto #sicurezzainformatica #minacciedigitali #hacking

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Inside NadMesh: The Shodan-Powered Botnet Hunting Exposed AI Servers
#CyberSecurity
securebulletin.com/inside-nadm…
Cybersecurity & cyberwarfare ha ricondiviso questo.

Scattered Spider smascherata: 5 anni e mezzo di carcere per l’attacco da 29 milioni di sterline a Transport for London


Owen Flowers e Thalha Jubair, membri di Scattered Spider, condannati dalla Woolwich Crown Court per l'intrusione 2024 in Transport for London: 148 sistemi bloccati, 27.000 dipendenti senza credenziali e un rischio economico stimato in 56 miliardi di sterline scampato solo per lo shutdown preventivo della rete.
The media in this post is not displayed to visitors. To view it, please go to the original post.

Cinque anni e mezzo di carcere ciascuno. È questa la cifra con cui la giustizia britannica ha chiuso, almeno sul fronte penale, uno degli attacchi informatici più dirompenti mai subiti da un’infrastruttura critica del Regno Unito: l’intrusione del 2024 in Transport for London, l’authority che gestisce la mobilità dell’intera Londra. Owen Flowers, 18 anni, e Thalha Jubair, 20, sono stati condannati il 16 luglio 2026 dalla Woolwich Crown Court. Sono, secondo l’accusa, i primi ad essere condannati per la Section 3ZA del Computer Misuse Act — la fattispecie più grave della legge britannica sui crimini informatici — e la National Crime Agency (NCA) definisce il loro caso il più grande procedimento per cybercrime mai affrontato dai tribunali del Paese.

Chi sono Flowers e Jubair, e cosa hanno fatto


I due sono descritti dalla NCA come membri di primo piano di Scattered Spider, il collettivo criminale tracciato anche come Octo Tempest, UNC3944 e 0ktapus, responsabile secondo gli inquirenti di centinaia di attacchi tra il 2022 e il 2025. La Crown Prosecution Service (CPS) è più cauta nell’attribuzione diretta, notando che gli imputati hanno rivendicato in vari momenti l’appartenenza al gruppo senza che questo costituisse, di per sé, la base dell’accusa.

L’intrusione in TfL è avvenuta tra il 31 agosto e il 3 settembre 2024. L’attacco ha reso inutilizzabili 148 sistemi dell’authority, costringendo tutti i 27.000 dipendenti a recarsi fisicamente in un ufficio per il reset delle credenziali — non essendo più possibile farlo da remoto in sicurezza. Sono stati compromessi anche il sistema di rimborsi Oyster (inclusi, per circa 5.000 persone, numeri di conto bancario e codici sort code), il servizio Dial-a-Ride per i cittadini con disabilità, il canale dei pagamenti digitali e le domande per le Oyster photocard agevolate per bambini e giovani. NCA e CPS stimano il danno complessivo, tra perdite e costi di ripristino, in 29 milioni di sterline.

Un rischio sistemico da 56 miliardi di sterline


Il dato più inquietante emerso dal processo riguarda ciò che sarebbe potuto succedere e non è successo. Secondo la ricostruzione dell’accusa, le conversazioni tra i due imputati suggerivano l’intenzione di cancellare l’accesso al termine dell’operazione, ma nessuno può dire con certezza cosa avessero realmente pianificato. La NCA stima che uno shutdown riuscito della rete di TfL — che gestisce in media 9 milioni di spostamenti al giorno — avrebbe potuto costare all’economia britannica fino a 56 miliardi di sterline. Uno scenario rimasto ipotetico solo perché TfL, rendendosi conto della compromissione, ha scelto di disattivare preventivamente la propria rete per contenere gli attaccanti.

I due si sono dichiarati colpevoli il 22 giugno 2026, il primo giorno del processo, evitando così il dibattimento. Hanno ammesso il reato sulla base di aver agito in modo “reckless” — sconsiderato — rispetto al rischio di causare o creare un pericolo significativo per il benessere umano, elemento costitutivo della Section 3ZA.

Come sono stati identificati


Flowers è stato arrestato per la prima volta il 6 settembre 2024, tre giorni dopo la fine dell’intrusione in TfL, nella sua abitazione a Walsall. Al momento dell’arresto, gli agenti NCA lo hanno sorpreso mentre era ancora attivo su due ulteriori obiettivi: le reti delle organizzazioni sanitarie statunitensi SSM Health Care Corporation e Sutter Health. Tra i dispositivi sequestrati — laptop, computer desktop, hard disk e chiavette USB — un portatile Acer conteneva uno screenshot della connettività di rete verso l’infrastruttura TfL e diversi video, registrati dallo stesso Flowers, che mostravano Jubair muoversi all’interno dei sistemi dell’authority londinese durante l’attacco. I due comunicavano in tempo reale su Telegram e condividevano uno spazio di lavoro online.

L’accusa ha dimostrato che Flowers era collegato al server remoto usato per lanciare tutte e tre le intrusioni, con prove ricavate dai suoi stessi dispositivi. Le informazioni che collegano Jubair all’attacco TfL sono state invece ottenute all’estero, con la collaborazione di autorità giudiziarie di altri Paesi — un dettaglio che la CPS non ha specificato ulteriormente. Jubair, arrestato il 16 settembre 2025, ha un secondo procedimento ancora aperto negli Stati Uniti: un atto d’accusa depositato nel New Jersey lo collega a circa 120 intrusioni di rete e almeno 47 vittime statunitensi tra maggio 2022 e settembre 2025, per oltre 115 milioni di dollari in riscatti pagati, incluse violazioni ai danni di un’infrastruttura critica USA e dei tribunali federali. Su questo fronte rischia fino a 95 anni di carcere; nessuna delle comunicazioni ufficiali diffuse finora affronta il tema dell’estradizione.

Scattered Spider è davvero finita?


La NCA sostiene che l’azione contro i due abbia “sostanzialmente fermato” il gruppo, citando una valutazione di Microsoft secondo cui gli arresti ne avrebbero degradato in modo significativo la capacità operativa. Ma la stessa agenzia ammette che altri criminali potrebbero continuare a usare il marchio “Scattered Spider” per rivendicare nuovi attacchi. Non è un’ipotesi remota: a gennaio 2026 Mandiant ha documentato l’espansione di un’operazione di estorsione a marchio ShinyHunters che replica lo stesso modello — vishing verso i dipendenti, pagine di phishing per rubare credenziali SSO e codici MFA, enrollment di un dispositivo dell’attaccante per bypassare l’autenticazione multifattore.

È proprio questo il punto debole che accomuna la maggior parte dei casi riconducibili a Scattered Spider: non un exploit tecnico sofisticato, ma la manipolazione dei processi di help desk — reset password, gestione dei dispositivi MFA — con tecniche di social engineering telefonico mirate e ben documentate.

Due righe per i difensori


Il caso TfL resta un caso di scuola su come un’infrastruttura critica possa essere messa in ginocchio non da uno zero-day, ma da processi organizzativi vulnerabili al fattore umano. Alcune indicazioni pratiche per ridurre l’esposizione a gruppi con TTP simili a Scattered Spider:

  • Verificare sempre l’identità con procedure fuori banda (callback su numero verificato, verifica video) prima di eseguire reset password, modifiche MFA o enrollment di nuovi dispositivi richiesti telefonicamente all’help desk.
  • Limitare la possibilità per il personale di help desk di eseguire reset critici senza approvazione di un secondo operatore (four-eyes principle).
  • Monitorare enrollment MFA anomali, specialmente se avvengono subito dopo un reset password.
  • Coinvolgere le forze dell’ordine tempestivamente in caso di incidente: secondo la NCA, la collaborazione precoce di TfL è stata determinante per l’esito del procedimento.
  • Segmentare le reti operative critiche (biglietteria, pagamenti, servizi per l’utenza vulnerabile) da quelle amministrative, per limitare l’impatto di una compromissione laterale.

Fonti: The Hacker News, National Crime Agency.

Cybersecurity & cyberwarfare ha ricondiviso questo.

Coca-Cola ferma la produzione di Fairlife dopo un attacco ransomware: quando il cybercrime arriva in tavola


Un attacco ransomware ai sistemi produttivi di Fairlife, controllata di Coca-Cola, ha bloccato la produzione statunitense di latte ultrafiltrato. Il caso si inserisce in un pattern crescente di attacchi alla filiera alimentare globale, da JBS ai recenti incidenti in Giappone.
The media in this post is not displayed to visitors. To view it, please go to the original post.

Non serve colpire una centrale elettrica per mettere in ginocchio una filiera critica: basta un ransomware ben piazzato nei sistemi produttivi di un’azienda che imbottiglia latte. Il 16 luglio 2026 Coca-Cola ha comunicato alla SEC che la sua controllata Fairlife ha sospeso la produzione negli Stati Uniti dopo un attacco ransomware che ha colpito i sistemi legati alla produzione stessa. Un episodio che, al netto delle dimensioni del marchio coinvolto, racconta molto sullo stato di sicurezza dell’OT nel settore alimentare.

Cosa è successo


Fairlife, con sede a Chicago, è il marchio di latte ultrafiltrato di proprietà di Coca-Cola, noto anche per le linee Core Power Protein Shakes e Nutrition Plan. Nel filing 8-K depositato presso la Securities and Exchange Commission, Coca-Cola ha dichiarato che soggetti non autorizzati hanno avuto accesso a una parte dei sistemi di Fairlife, inclusi quelli legati alla produzione, in un attacco che l’azienda descrive esplicitamente come ransomware. Le operazioni negli stabilimenti statunitensi sono state temporaneamente sospese; la produzione in Canada, gestita separatamente, non risulta invece impattata.

Coca-Cola ha attivato i protocolli di incident response e business continuity, coinvolto consulenti esterni e notificato le forze dell’ordine, precisando che qualità e sicurezza del prodotto non sono state compromesse. Al momento della scrittura, la società non ha reso noto quale gruppo ransomware sia responsabile, se siano stati sottratti dati né se sia stata ricevuta una richiesta di riscatto. Nessuna gang ransomware nota ha ancora rivendicato l’attacco, un silenzio che nel settore viene letto come tipico delle prime fasi di un negoziato, prima che gli estorsori tornino a farsi vivi minacciando la pubblicazione di eventuali dati sottratti.

Non è un caso isolato: la filiera alimentare nel mirino


L’attacco a Fairlife arriva in un contesto in cui il comparto food & beverage è bersaglio ricorrente del ransomware, spesso proprio perché la convergenza IT/OT nelle linee di produzione rende gli impianti fragili: basta bloccare i sistemi SCADA o MES che orchestrano il confezionamento per fermare intere linee, anche senza toccare la sicurezza alimentare in senso stretto. Il precedente più noto resta l’attacco del 2021 a JBS, il colosso mondiale della carne, costretto a fermare impianti in Nord America e Australia e a pagare 11 milioni di dollari di riscatto al gruppo REvil. Nella sola finestra delle ultime 48 ore, la stessa dinamica si è ripetuta altrove: in Giappone, un attacco informatico a un operatore logistico ha svuotato le cucine di migliaia di ristoranti per un blocco nelle consegne di prodotti alimentari, mentre il colosso giapponese dei surgelati Nichirei ha segnalato la disruzione delle proprie operazioni per un incidente informatico separato.

Il filo comune è la dipendenza di filiere alimentari globalizzate da sistemi IT centralizzati per pianificazione della produzione, gestione ordini e logistica: quando quei sistemi vengono cifrati o resi inaccessibili, l’impatto si propaga rapidamente dagli scaffali dei supermercati alle cucine dei ristoranti, ben oltre il perimetro aziendale colpito.

Perché conta anche per chi non produce latte


Il caso Fairlife è interessante per i difensori non tanto per i dettagli tecnici, che Coca-Cola non ha ancora reso pubblici, quanto per la dinamica di disclosure e per l’esposizione di un brand multimiliardario a un rischio operativo concreto tramite una controllata. Il filing SEC evidenzia un punto spesso sottovalutato nei risk assessment: la segmentazione tra rete IT aziendale e rete OT di produzione, quando esiste, va verificata regolarmente, perché un attacco che compromette “solo” i sistemi IT può comunque paralizzare la produzione se i due domini condividono directory service, credenziali o piattaforme di orchestrazione.

Per le aziende manifatturiere, specialmente nel food & beverage dove i margini di tolleranza su tempi di fermo sono minimi per ragioni di deperibilità delle materie prime, le priorità restano quelle già emerse dai casi JBS e Nichirei: backup offline testati e realmente isolati (non solo replicati su un secondo datacenter raggiungibile dalla stessa rete), piani di failover manuale per le linee di produzione critiche, segmentazione rigorosa tra reti corporate e reti OT/ICS, e accordi di incident response pre-negoziati con forze dell’ordine e consulenti forensi, in modo da non partire da zero quando il tempo conta più di ogni altra cosa.

  • Verificare che i backup dei sistemi MES/SCADA siano realmente air-gapped e non solo “logicamente separati”
  • Testare periodicamente scenari di failover manuale per le linee di produzione più critiche
  • Mappare le dipendenze condivise (Active Directory, VPN, orchestrazione cloud) tra rete IT e rete OT
  • Predisporre in anticipo contatti con FBI/law enforcement locale e retainer di incident response per ridurre i tempi di reazione


Cosa manca ancora al quadro


Al momento della pubblicazione, mancano ancora elementi chiave per una piena attribuzione: nome della gang ransomware, vettore di accesso iniziale, eventuale esfiltrazione di dati e ammontare della richiesta di riscatto. Continueremo a seguire l’evoluzione del caso Fairlife, aggiornando l’articolo qualora emergano rivendicazioni o dettagli tecnici da fonti di threat intelligence.

Stato indicatori al 18/07/2026:
- Gruppo ransomware responsabile: non identificato pubblicamente
- Vettore di accesso iniziale: non divulgato
- Esfiltrazione dati: non confermata
- Richiesta di riscatto: non divulgata
- Sistemi impattati: infrastrutture di produzione Fairlife (solo USA)
- Sistemi non impattati: produzione Fairlife Canada, qualita/sicurezza prodotto

Riferimento normativo: SEC Form 8-K depositato da The Coca-Cola Company il 16/07/2026

Open-Source Mid-Drive e-Bike Motor Has Lots of Promise, and Hyphens


The media in this post is not displayed to visitors. To view it, please log in.

[Pedro Neves] has a mid-drive e-bike, but he doesn’t own it — not truly, since he can’t repair the motor unit. For a hacker to be in that position, there are only two options: crack the old one and make it your own, or build your own from scratch. [Pedro] built his own and is open-sourcing it on his website for everyone to play with. Right now, that’s .step files and a BOM, so you’ll need to watch the design/build video on YouTube below to get the full picture.

His choice of a motor from an old battery-powered angle grinder is both thrifty and environmentally friendly, so we approve. His goal of 25 km/h seems like a reasonable speed limit, but may still be too fast for some countries’ regulations— so do check the local rules if you’re going to build this. Making the most of 3D-printed components is also a choice that makes the project more accessible, but don’t worry — the bearing surfaces are all metal. That includes the clutch bearing that will let you pedal home if the battery dies or the motor craps out. Well, unless the printed plastic axle gives up the ghost, but that got replaced with a CNC version, so it’s all good. Unless you’ve got legs like Hercules, it ought to hold.

If that’s not DIY enough, you could always build the motor yourself. This mid-drive is also part of a larger project [Pedro] is working on for a whole cargo bike, as he details in his video, which is a worthy project we’ve seen other examples of before.

youtube.com/embed/0jco-RKzRSo?…


hackaday.com/2026/07/18/open-s…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Attackers Can Take Over #WordPress Sites Using Newly Released wp2shell Exploits
securityaffairs.com/195597/hac…
#securityaffairs #hacking

reshared this

Write 2D and 3D Games in Modern MoonBASIC


The media in this post is not displayed to visitors. To view it, please log in.

One of the major strengths of the BASIC programming languages has always been their no-fuss setup and rich set of commands for operations that would take considerably more work in a bare-bones language like C. MoonBASIC continues this legacy with a BASIC variant optimized for both 2D and 3D game development.

Included in the package are Raylib, Box2D, and Jolt, whose functionality is exposed via over 4,200 commands in their respective namespaces. You can also download a whole IDE package based around VS Code, use it on the command line, or add it to an existing VS Code installation.

A quick glance at the ‘getting started‘ guide gives a pretty good idea of what to expect of MoonBASIC, including a range of custom language additions and support for PBR materials, dynamic lighting, and other modern game engine features.

Whether writing a game in BASIC was on your bingo card for this year or not, it might be worth taking a look to see whether it’s your jam. After all, if BASIC was good enough for both AI and game development in the 1980s, surely it can be used for complex games in 2026.


hackaday.com/2026/07/18/write-…

Your AI Ham Radio Buddy


The media in this post is not displayed to visitors. To view it, please log in.

AI chatbots are everywhere these days, and they seem to “know” about everything. But while that is a strength, it can sometimes be a weakness because it isn’t laser-focused on one topic. Not so with this Ham-radio-centric chatbot called HamGPT. The service is clearly built on another GPT engine but understands how to retrieve data from common ham radio sources, such as the FCC database, propagation reports, and the like. It didn’t, however, seem to have access to ham radio-related books, magazine articles, or other “static” data that we could tell.

You do have to sign up for an account, which includes providing your callsign and location. There is a free tier that allows a limited number of queries per day, so you can try it to see if it is useful for you without subscribing.

Here’s a typical session:

What band will have the best propagation to Japan from my QTH right now?

The best band for Japan from your QTH right now is 30 meters, which shows good propagation reliability. 20 meters is also active and providing a viable path.

Real-time data confirms activity on both bands, primarily using FT8. While the path is open, the signals are relatively weak (typical for this long-haul path), making digital modes like FT8 or CW your best bet for a successful contact.

Would you like me to check if your current antenna setup is suitable for these bands, or perhaps help you calculate dimensions for a 30m or 20m antenna?


In addition, bubbles at the bottom of the screen showed me the busiest band in my area and how many repeaters were nearby.

In all fairness, we asked ChatGPT the same question, but did say “ham radio band” just to give it some idea of scope. It gave a much more detailed answer with sources, even provided headings, and made a suggestion about another location I sometimes operate from because it remembers things from previous unrelated chats.

We understand reactions will be mixed. If you’ve been a ham for a long time, you probably could have guessed that a path from the US to Japan in the morning was likely to be on 20 or 30 meters. You probably also know how to look things up yourself.

We didn’t try any more sophisticated queries that might make it more worthwhile. For example, what if you could send it an ADIF log file and ask it what awards you qualified for? Or to process contest logs for duplicates and fill out a scoring worksheet? What would you like a ham radio-aware AI to do for you?

Ham radio — at least parts of it — has become inextricably linked with computers.


hackaday.com/2026/07/18/your-a…

Calculator UI Is More Complex Than You Might Think


The media in this post is not displayed to visitors. To view it, please log in.

Calculators are so ubiquitous and so familiar that they are easy to take for granted in many different ways. [lcamtuf] points out one that has probably never occurred to many of us: the user interface for a calculator is an unexpectedly complex thing.
The internal logic to support sequential inputs and multiple operators in a way that feels intuitive is a complex thing.
Resolving something like 1 + 2 = is pretty straightforward but complexity compounds rapidly after that, with numerous special cases. Let’s imagine one decides to program a simple calculator UI as a weekend project. The development process might look a little like this:

  1. User types in 1 + 2 = and the calculator displays 3. What happens if the user immediately presses -?
  2. No problem, just consider the result of the previous operation as an already-there input. So we’ll have 3 - for this next operation, and wait for more.
  3. Unless we should have treated that - as a negative sign for whatever number is coming next, making it a negative number? No, ignore that. Just treat whatever results from pressing equals as a pre-typed input.
  4. Unless the user hits a number. Because if they hit 2 (for example) then we’ll have a 32 and not a 2 which they probably, definitely don’t expect. So that’s a special case and we should insert a clear if that happens.
  5. Oh, better clear if the user enters a decimal, too.
  6. I’m going to need a coffee…

And that’s just the tip of the iceberg. Imagine trying to figure all this out for the very first time, without the benefits of habit and history to fall back on.

The fact is that supporting the apparently trivial behavior of a simple calculator requires an underlying complex state machine that deals with all kinds of special cases in order to make the UI feel intuitive. And that’s just for a basic four-function calculator; we haven’t even touched on how special keys like % should behave.

We know [lcamtuf] speaks from experience, not just because of their deep knowledge of calculator history but because they rolled their own calculator that uses voltmeters as digit displays and there’s nothing like actually implementing something to make one appreciate it.


hackaday.com/2026/07/18/calcul…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Kimi K3 è fuori! La Cina sta vincendo la sfida sull’IA? ecco il modello Open Weight più grande al mondo

📌 Link all'articolo : redhotcyber.com/post/kimi-k3-e…

A cura di Carolina Vivianti

#redhotcyber #hacking #cti #ai #online #it #cybercrime #cybersecurity

Cybersecurity & cyberwarfare ha ricondiviso questo.

#OpenSSL Fixes #HollowByte Memory Exhaustion Bug
securityaffairs.com/195588/hac…
#securityaffairs #hacking

ESP32-driven Roulette Wheel Could Have Used a 555, but That Didn’t have WiFi


The media in this post is not displayed to visitors. To view it, please log in.

Sometimes you see a project and immediately, before going into the details, your mind throws up the old refrain: “coulda used a 555” — well, [Hulk] actually agrees when it comes to his ESP32-based, 3D printed roulette wheel. The first version did use a 555, but then feature creep kicked in and the final project ended up with an ESP32 instead. We’ve all been there.

The roulette wheel circuit is retained from the 555 version, with the ESP32 providing clock pulses instead of the venerable oscillator chip — it uses a pair of decade counters to create the chase effect of the LED around the wheel. With a handsome printed enclosure, [Hulk] could have stopped there, but then he’d have to keep track of scoring and the like manually like some kind of dark age peasant. It’s the 21st century, we have computers to to that for us!

Now, even though the ESP32 is still driving the LED chase via the decade counters, it can keep track of where the “ball” of light lands, and reports that via WiFi or serial. While it would have been an option to run the whole game on the ESP32. [Hulk] just has those values put into an SQL database on a server, which also runs the game front-end via PHP. The resulting web page lets two players make their bets and track their wins and losses over time. You can see that in action in the video embedded below.

Overkill? Sure, but we suspect [Hulk] already had the equipment and experience to make this the fastest way to get a playable game. There are easy ways to serve web content from an ESP32, but the easiest tool to use is always the one in your back pocket, right?

youtube.com/embed/5jVFR7KSNmg?…


hackaday.com/2026/07/18/esp32-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Cloudflare blocca il bug wp2shell di WordPress tramite WAF, anche sulle offerte gratuite

📌 Link all'articolo : redhotcyber.com/post/cloudflar…

A cura di Luigi Zullo

#redhotcyber #hacking #cti #ai #online #it #cybercrime #cybersecurity #technology #news #cyberthreatintelligence

reshared this

Simple Games from a Simpler Time


The media in this post is not displayed to visitors. To view it, please log in.

Modern video games are nothing short of amazing. My son and I were playing through the one of the latest Zeldas, which involve a mix of combat and puzzle-solving that’s pretty much the hallmark of the franchise. But the most recent open-world Zelda is simply massive. Made by around 1,000 people at a development expense of $150,000,000, it takes probably 60-80 hours to play through if you’re not rushing, and more if you’re taking it easy. It has layers of game mechanics, and worlds in the sky, on land, and underground. It’s big in every way.

Contrast the games of my youth, which were a lot smaller. Written by a pair of people or maybe a handful, with playtimes in the single-digit hours, and of course fitting in the limited computing resources of the time. But the low-stakes nature of the early phases of the industry meant that software developers could take risks, and many of the games were consequently kinda idiosyncratic in this more innocent time.

I think there’s something to be said for small games. They don’t require a lifestyle commitment just to get through. They can still be fun, without taking all of your time. And honestly, when you’re done with a game quickly, you have more time for other stuff. Granted, some of this spirit lives on in the small indie games of today, but even so, game developers have the big studios’ products in the backs of their minds when they are working on their smaller oeuvres.

We were talking about preserving old games for posterity around Hackaday and on the podcast, and our conversations reminded me of a couple of educational games that, despite their rudimentary graphics, are still pretty good today. Both were electronics related, and both are still playable today thanks to efforts on emulation and software preservation. To get a feel for the 1980’s, give Rocky’s Boots a try. (I like the TRS-80 Color Computer version the best, but that may just be nostalgia.) Most of you grownups out there will get through it in an hour or so.

And if you want a challenge, try Rocky’s harder sequel: Robot Odyssey. If you already have a background in digital circuits, you’ll find it doable. Younger me hit a wall about two-thirds of the way through.

Both of these games stick with me because they taught me something, but also because they were simply quirky in a way that a game can only be when it’s written by a small team of folks who are just having fun programming it. If you pitched “a puzzle game about a raccoon who builds logic circuits to activate robot boots”, the boardroom would look at you like you’re out of your mind. But it’s just exactly the quirkiness and individuality of some of these early games that I cherish the most.

If you find yourself knee-deep in an endless modern game, take a side-quest off into a more naive time, and you’ll appreciate why people are putting efforts into archiving them.

This article is part of the Hackaday.com newsletter, delivered every seven days for each of the last 200+ weeks. It also includes our favorite articles from the last seven days that you can see on the web version of the newsletter. Want this type of article to hit your inbox every Friday morning? You should sign up!


hackaday.com/2026/07/18/simple…

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Daxin: 13-Year-Old China-Linked #Malware Found Still Active on Manufacturer's Network
securityaffairs.com/195577/mal…
#securityaffairs #hacking
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

EY Notifies Clients After Breach of IT Support Platform Exposes Tax Documents
#CyberSecurity
securebulletin.com/ey-notifies…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

CISA Confirms Active Exploitation of Critical SharePoint Deserialization Flaw
#CyberSecurity
securebulletin.com/cisa-confir…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Coca-Cola’s Fairlife Brand Halts US Production After Ransomware Hits Manufacturing Systems
#CyberSecurity
securebulletin.com/coca-colas-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Unpatched LegacyHive Bug Lets Standard Windows Users Hijack Admin Accounts
#CyberSecurity
securebulletin.com/unpatched-l…

Spidery Drone Goes Near-invisible By Spinning Really, Really Fast


The media in this post is not displayed to visitors. To view it, please log in.

Researchers demonstrate that something interesting happens when a small drone with a spindly airframe spins at a high speed: it very nearly turns invisible. The spidery device is shown mounted in its launcher in the image above. The dark blur at the rightmost side is an outlet on the wall behind the drone, not motion blur from a moving part.
There’s not much to do about the noise, but a high-speed spin becomes nearly invisible.
It’s called the Phantom Twist, and while we’ve seen single-motor drones that spin around a central axis before, they have always incorporated a wing-like structure or cleverly leverage the magnus effect to generate lift.

There’s not a lot of detail about the Phantom Twist’s hardware design but it appears to use a downward-angled motor for lift, relying on a high-speed control system to maneuver and maintain altitude.

This does away with the need for a wing, at the cost of only being stable while rotating at a high speed. We imagine it is also a touchy design that depends greatly on being balanced just so.

A hand launcher spins the device up before releasing it for flight. The visual effect once it is up and running is pretty striking; see for yourself in the short video, embedded just below.

youtube.com/embed/1mUgyV3A1O0?…


hackaday.com/2026/07/18/spider…

Cybersecurity & cyberwarfare ha ricondiviso questo.

What?!

nysfocus.com/2026/07/14/new-yo…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

📺 Srsly Risky Biz: Ransomware uses AI to amp up negotiations

risky.biz/video/srsly-risky-bi…

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

#Odissea di #Nolan e l'inutilità delle critiche al trailer

Il regista dei flashback reinterpreta totalmente il primo flashback della letteratura occidentale, usando l'intertestualità con Virgilio e Dante in un film maestoso e intimo insieme, con gli attori giusti (sì, anche Zendaya e Batman sono perfetti per interpretare l'Athena e l'Agamennone del film), effetti così speciali che non si notano quasi mai, un Polifemo meraviglioso e una Circe sorprendente.

@cinema_serietv

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

Insetti nella pasta. Il Salvagente non ha diffamato il Pastificio Garofalo
@giornalismo
ossigeno.info/insetti-nella-pa…
18 lug 2026 - L'azienda campana voleva 250mila euro di risarcimento. Invece dovrà pagare le spese processuale del giornale dei consumatori
L'articolo Insetti nella pasta. Il Salvagente non ha diffamato il Pastificio Garofalo proviene da Ossigeno per l'informazione.
#Ossigeno
Cybersecurity & cyberwarfare ha ricondiviso questo.

☕ CYBERBRIEFING MATTUTINO — Sabato 18 luglio 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

Cross-Sectioning Crickets with a Femtosecond Laser


The media in this post is not displayed to visitors. To view it, please log in.

A scanning-electron micrograph is shown of a cricket's body, focusing on the head, which has been sliced off just above the eyes.

Unlike most cutting lasers, femtosecond lasers don’t vaporize materials; rather, they produce such short, intense bursts of light that the affected region is ablated without having the chance to heat its surroundings. This makes them good at cutting away material without damaging the surroundings, something [Ben Krasnow] exploited to cut cross-sections of samples while still in a scanning-electron microscope.

In this case, the samples were crickets, and before imaging they had to be prepared. First, the bodies were soaked in glutaraldehyde to cross-link the proteins and stabilize the structure. Next, a series of solvent exchanges replaced the water in the bodies with a low-surface-tension solvent; this meant that during the next step, drying, surface tension wouldn’t distort the crickets’ internal structure. Finally, the insect bodies were charred under argon, which made the bodies conductive and more absorptive to laser light.

The laser itself and the scanning galvo are mounted outside the microscope, and shine in through a transparent window. To protect the detector and electron optics from a spray of ablated carbon, a servo motor swings an aluminium shutter between these and the sample while the laser is active. This caused some mysterious problems during testing: after the first ablation run, the electron microscope’s image would contain so much noise as to be unusable, but it would improve over time. As it turned out, the shutter was painted, and the other side of the paint was getting coated with charged carbon particles. This created a small capacitor which disrupted the electron optics as it discharged. Eventually, after solving this and a few other strange problems, [Ben] was able to take several time-lapse videos of the laser gradually ablating a cricket, 30 microns at a time, revealing its inner structure.

Although scanning-electron microscopes are unfortunately shard to come by, it’s still possible to restore a secondhand microscope or, as [Ben] did, build your own. Femtosecond lasers are yet more inaccessible, though they can be used to replicate themselves.

youtube.com/embed/NwhVJ7cv9B4?…


hackaday.com/2026/07/18/cross-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

374 – L’AI HA BISOGNO DI OPERAI. TANTI. E NON LI TROVA camisanicalzolari.it/374-lai-h…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Massimo allarme per WordPress: RCE critica nel core, 500 milioni di siti potenzialmente vulnerabili

📌 Link all'articolo : redhotcyber.com/post/massimo-a…

A cura di Luigi Zullo

#redhotcyber #hacking #cti #ai #online #it #cybercrime #cybersecurity #technology #news

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Umani contro robot: il primo sciopero contro la robotizzazione degli stabilimenti in Hyundai

📌 Link all'articolo : redhotcyber.com/post/umani-con…

A cura di Carolina Vivianti

#redhotcyber #hacking #cti #ai #online #it #cybercrime #cybersecurity #technology #news

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Gli impianti di Fairlife, di proprietà della Coca-Cola bloccati da un attacco hacker

📌 Link all'articolo : redhotcyber.com/post/gli-impia…

A cura di Chiara Nardini

#redhotcyber #hacking #cti #ai #online #it #cybercrime #cybersecurity #technology #news

reshared this

Flex Filament Stuck To Your Build Platform? Reach For The Isopropanol


The media in this post is not displayed to visitors. To view it, please log in.

3D printing has been around long enough that everyone’s heard at least one weird trick regarding 3D prints. [Angus] of [Maker’s Muse] puts a few to the test, and came away with one solid tip for releasing TPU from a build platform to which it has unfortunately welded itself.

Flexible filaments tend to stick too well to build plates, which is why an interface layer like a thin layer of glue stick is called for. But what if one forgets to apply it before starting a print job? That can result in a print that is well and truly stuck. Peeling flex filament off a textured PEI bed is a bad time, because the print can tear and tends to leave little bits behind.

[Angus] heard that applying isopropyl alcohol helps release things in that case, so he gives it a try. Lo and behold, it seems to work! See for yourself at 18:10 in the video and keep it in mind if you end up in a similar situation. The print doesn’t exactly fall off on its own, but it does remain in one piece which is more than one can expect otherwise.

Watching isopropyl alcohol help release a stuck print is reminiscent of the way it also removes hot glue from just about any surface. The trick is getting the alcohol to wick in underneath for best results, and the same seems to be true with releasing TPU from a build plate.

One thing to keep in mind when evaluating tips and tricks from over the years is that the landscape changes. Something that maybe seemed to have potential years ago might not make much sense today. A good example is sugar as a bed adhesive, which [Angus] tries out. What started as an experiment in getting PLA to play better with glass build plates years ago doesn’t really carry over to now, with PEI-coated magnetic build platforms pretty much a solved problem. The more likely result nowadays is just a mess.

youtube.com/embed/JZ5rcWgxeFo?…


hackaday.com/2026/07/17/flex-f…

Using Solar Air Heating to Dry Clothes


The media in this post is not displayed to visitors. To view it, please log in.

About a month ago, [Greenhill Forge] built a few solar panels to collect energy from the sun. Unlike solar photovoltaics, which turn sunlight directly into electricity, these were designed to gather solar thermal energy with air. These types of panels can gather a tremendous amount of energy for a very low cost, and although the first video only went into the theory of their operation, his latest video actually shows us how to use that energy in a practical way.

The video starts by building a new solar panel, using upgraded materials and building methods compared to the previous versions which should improve the efficiency. There’s some data analysis of the performance, but at the end of the video [Greenhill Forge] actually hooks one of these up to a clothes dryer to explore its real-world efficacy. This process involves disconnecting the electric heater, removing one of the blower fans, and building a new flange to accept the heated air from the solar panel. A microcontroller keeps an eye on the incoming air temperature and controls a fan to try to hit the target temperature.

After an hour of drying, the test clothing was completely dry, with the only electricity used to turn the drum in the dryer. This is more than an order of magnitude of reduction in the power needed to dry clothes, which is fairly impressive. [Greenhill Forge] also notes that systems like these could augment off-grid systems not only for clothes drying but for home heating, greenhouse heating, or drying out various crops and that they could reduce strain on an electrical system that otherwise relies on resistive heating methods. There are many ways of building these panels, so be sure to check out his first video for ideas.

youtube.com/embed/6fCx8LTxLP4?…


hackaday.com/2026/07/17/using-…

How Octopuses Hacked their Ribosome to Become Smart


The media in this post is not displayed to visitors. To view it, please log in.

A fascinating aspect in evolutionary biology is that of convergent evolution — whereby similar structures and functions evolve independently from each other. The highly advanced nervous system of octopuses is a good example here, displaying levels of intelligence and capabilities far beyond those of other cephalopods and matching that of primates, despite no evolutionary link here. Exactly how octopuses developed this rather unique capability remained a mystery, though recent research by [Rishav Mitra] points at the rather unique ribosomes in these animals.

Ribosomes are the molecular machinery at the core of each cell that enable the synthesis of proteins. Due to their highly crucial role, they tend to remain evolutionary unchanged, which makes the big change observed in the octopus (i.e. order Octopoda) in the form of this H88 rRNA break quite remarkable.
Common octopus (<i&gt;Octopus vulgaris&lt;/i&gt;). (Credit: Albert Kok, Wikimedia)Common octopus (Octopus vulgaris). (Credit: Albert Kok, Wikimedia)
This H88 break increases the accuracy of translated proteins, something that is essential for complex nervous systems as it reduces cases of misfolded proteins (proteinopathy). Because of how well-preserved ribosomes are across species, the researchers were able to run a number of experiments including a similar rRNA break in E. coli that confirmed many of the assumptions about how these octopus ribosomes performed.

Since proteinopathy results in misfolded proteins that are either useless or harmful to the organism – as seen in various human diseases – this can especially harm long-lived cells like neurons. Unsurprisingly, we can see a similar change to ribosomes in other animal groups, including that of us primates. Although the reasons for octopuses to develop more complex nervous systems wasn’t due to social pressures but rather to cope with highly complex and dynamic environments, it would seem that both types of environmental pressures led to the same convergent path, with a little ribosomal help.


hackaday.com/2026/07/17/how-oc…

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

La VPN che hai pagato finanzia davvero i valori in cui credi? Il caso Mullvad e la crisi dell’etica digitale
#tech
spcnet.it/la-vpn-che-hai-pagat…
@informatica


La VPN che hai pagato finanzia davvero i valori in cui credi? Il caso Mullvad e la crisi dell’etica digitale


Per molti anni il mondo della privacy digitale ha goduto di una sorta di immunità morale. Mentre i grandi colossi della tecnologia venivano criticati per il capitalismo della sorveglianza, per la raccolta indiscriminata di dati personali e per modelli di business fondati sulla profilazione degli utenti, una parte dell’ecosistema open source è riuscita a costruirsi un’immagine quasi opposta. Scegliere una VPN indipendente, utilizzare software libero o affidarsi a servizi come Proton e Mullvad è diventato, per molti utenti, molto più di una decisione tecnica: è stata una scelta culturale e, in alcuni casi, persino politica.

Non è difficile comprenderne le ragioni. La comunità che ruota attorno al software libero ha spesso condiviso valori come la trasparenza, il diritto alla riservatezza, la decentralizzazione del potere tecnologico e la difesa delle libertà civili. Sebbene nessuno abbia mai sostenuto ufficialmente che queste realtà appartenessero a una precisa area politica, nell’immaginario collettivo si è consolidata l’idea che rappresentassero un’alternativa etica alle grandi multinazionali del digitale. In altre parole, pagando un abbonamento a questi servizi si aveva la sensazione non soltanto di acquistare un prodotto migliore, ma anche di sostenere un diverso modo di concepire Internet.

È proprio questa percezione che negli ultimi giorni è stata improvvisamente messa in discussione.

Secondo quanto riportato dal quotidiano svedese Flamman, Daniel Berntsson, fondatore e comproprietario di Mullvad VPN, ha effettuato una donazione di cinque milioni di corone svedesi a Örebropartiet, un partito locale che negli ultimi mesi ha attirato l’attenzione della stampa per posizioni considerate vicine al concetto di “remigrazione”, tema frequentemente associato alla nuova destra identitaria europea. Berntsson ha confermato la donazione, precisando che si tratta di una scelta esclusivamente personale e non riconducibile all’azienda.

Dal punto di vista giuridico la questione potrebbe anche chiudersi qui. In una democrazia liberale ogni cittadino ha il diritto di sostenere economicamente il partito che ritiene più vicino alle proprie convinzioni, e sarebbe profondamente sbagliato mettere in discussione questo principio.

La questione, tuttavia, cambia radicalmente se la si osserva da una prospettiva etica.

Mullvad non vende soltanto una VPN. Da anni vende fiducia. Vende l’idea di essere un soggetto indipendente, rispettoso della privacy, lontano dalle logiche speculative delle grandi corporation e profondamente radicato in una cultura della trasparenza che ha contribuito a renderla uno dei nomi più rispettati dell’intero settore. Quando un’azienda costruisce il proprio patrimonio economico su un capitale reputazionale così forte, è inevitabile che anche i comportamenti pubblici dei suoi proprietari assumano un significato diverso rispetto a quelli di un qualsiasi cittadino.

Sostenere che la donazione sia “personale” è corretto dal punto di vista formale, ma rischia di essere insufficiente dal punto di vista sostanziale. I dividendi distribuiti da una società entrano nel patrimonio personale dei soci e, una volta disponibili, possono essere destinati a qualsiasi finalità, comprese iniziative politiche. Chi sceglie di acquistare un servizio proprio perché ritiene di sostenere un certo sistema di valori potrebbe quindi legittimamente chiedersi se quella fiducia non stia indirettamente contribuendo anche ad alimentare progetti politici che non condivide.

Naturalmente nessuno può pretendere di controllare le convinzioni personali di un imprenditore. Sarebbe una deriva tanto pericolosa quanto incompatibile con i principi di una società libera. Esiste però una differenza sostanziale tra il diritto di avere idee politiche e la pretesa che tali idee rimangano irrilevanti rispetto all’immagine pubblica dell’azienda di cui si è fondatori.

Un imprenditore non smette di rappresentare la propria impresa quando esce dall’ufficio. Questo principio vale quotidianamente per amministratori delegati, dirigenti e figure pubbliche di qualsiasi settore. Una dichiarazione controversa, una presa di posizione politica o un comportamento ritenuto incompatibile con i valori dell’azienda producono inevitabilmente conseguenze reputazionali che ricadono sull’intera organizzazione e, spesso, anche sugli altri soci che condividono quel progetto imprenditoriale.

Per questo motivo appare difficile sostenere che la vicenda riguardi esclusivamente la sfera privata di Berntsson. Non perché Mullvad abbia finanziato direttamente un partito politico — affermazione che non troverebbe riscontro nei fatti — ma perché la reputazione dell’azienda è ormai inscindibile da quella delle persone che l’hanno costruita. Quando il prodotto venduto è la fiducia, anche la credibilità personale dei fondatori diventa parte integrante di quel prodotto.

Una riflessione analoga è emersa anche all’interno della comunità di Proton. Negli ultimi giorni numerosi utenti hanno chiesto chiarimenti riguardo ad alcune scelte comunicative dell’azienda e ai rapporti con figure considerate politicamente divisive. Anche in questo caso il dibattito non nasce da dubbi sulla qualità tecnica dei servizi offerti, che continua a essere ampiamente riconosciuta, bensì dalla crescente consapevolezza che chi acquista strumenti per la tutela della privacy non sta semplicemente scegliendo un software, ma spesso decide di sostenere economicamente una determinata organizzazione.

Questo aspetto merita una riflessione più ampia, soprattutto all’interno della comunità open source. Per anni si è diffusa l’idea, spesso implicita, che il software libero fosse quasi naturalmente associato a una cultura progressista, libertaria o comunque orientata alla difesa dei diritti civili. È stata una semplificazione che oggi mostra tutti i suoi limiti. Gli sviluppatori, gli imprenditori e gli investitori che operano in questo settore appartengono alle più diverse sensibilità politiche, esattamente come accade in qualsiasi altro ambito economico. L’apertura del codice non implica automaticamente una determinata visione della società.

Eppure proprio questa consapevolezza rende ancora più importante il tema della trasparenza. Se un’azienda decide di costruire la propria identità commerciale attorno a concetti come etica, fiducia, indipendenza e libertà, deve accettare che il pubblico valuti anche la coerenza tra quei principi e i comportamenti delle persone che la guidano. Non si tratta di pretendere un’impossibile neutralità politica, ma di riconoscere che, nel momento in cui un’impresa vende valori oltre che servizi, i suoi fondatori non possono realisticamente rivendicare una netta separazione tra la dimensione privata e quella pubblica.

Forse la vera lezione di questa vicenda non riguarda soltanto Mullvad. Riguarda tutti noi. Per anni abbiamo creduto che bastasse scegliere un servizio open source o una VPN rispettosa della privacy per sentirci automaticamente partecipi di un ecosistema eticamente migliore rispetto a quello delle Big Tech. Oggi scopriamo che la realtà è molto più complessa. Le aziende possono sviluppare ottimi prodotti, sottoporli ad audit indipendenti e difendere concretamente la privacy degli utenti, senza che questo dica nulla sulle convinzioni personali di chi ne possiede le quote.

La domanda è se, nell’economia digitale contemporanea, sia ancora possibile separare completamente il valore tecnico di un servizio dal destino economico e politico delle persone che, grazie a quel servizio, costruiscono il proprio patrimonio. È una domanda scomoda, destinata probabilmente a dividere la comunità della privacy. Ma proprio per questo merita di essere posta.


Cybersecurity & cyberwarfare ha ricondiviso questo.

Ernst & Young (#EY) Investigates Data Breach Involving Third-Party Support Tickets
securityaffairs.com/195550/dat…
#securityaffairs #hacking