Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Certighost Flaw Let Ordinary Users Impersonate Domain Controllers and Seize Active Directory
#CyberSecurity
securebulletin.com/certighost-…
Cybersecurity & cyberwarfare ha ricondiviso questo.

non so ma io fatico davvero a leggere il testo per umani. devo essere un robot.
Cybersecurity & cyberwarfare ha ricondiviso questo.

Fediverse Loaded and Ready!


#Introduction post, like the Fediverse does. We're European Pirates and our great adventure comprises of making sure the European Union sails straight, through straits and narrows, and does not compromise to ludicrous demands or goes along with the willy-nilly. We're here and we're here to stay, grow and become big enough to dutifully represent the interests of European citizens. We hope to hear more from you as well, and we look forward to participating in the online conversation!
The media in this post is not displayed to visitors. To view it, please go to the original post.

#Introduction post, like the Fediverse does. We’re European Pirates and our great adventure comprises of making sure the European Union sails straight, through straits and narrows, and does not compromise to ludicrous demands or goes along with the willy-nilly. We’re here and we’re here to stay, grow and become big enough to dutifully represent the interests of European citizens. We hope to hear more from you as well, and we look forward to participating in the online conversation!
Questa voce è stata modificata (18 ore fa)
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

La Russia investe in infrastrutture sottomarine per le comunicazioni dell’Estremo Oriente

📌 Link all'articolo : redhotcyber.com/post/la-russia…

Chiara Nardini

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

ICCU Monitor Logs Data in E-GMP EV Failures


The media in this post is not displayed to visitors. To view it, please log in.

A baby blue hatchback with red accents drives down a road with blurry trees and a blue sky in the background.

EVs are less mechanically complicated than their combustion kin, but that doesn’t mean they’re immune to component failure. The Integrated Charge Control Unit (ICCU) has been the main failure point in recent Hyundai/Kia EVs, and ICCU Observer is an attempt to log data from the systems to find the culprit.

The ICCU handles all charging and voltage conversion duties from 800 V down to 12 V in the E-GMP platform EVs from Hyundai, Kia, and Genesis. The main failure mode appears to be when the circuit charging the 12 V fails, eventually rendering the vehicle inoperable. While the rate of failure is relatively low, the exact numbers are unknown, and Hyundai has remained quiet on if they know what’s causing it.

Unsurprisingly, speculation is rampant with owners experiencing failures relaying similarities and differences to others with the same problem. In an effort to bring actual data to the process, [broadwall] has started working on an open data set of information collected over the vehicle’s OBD II port in an effort to pinpoint similarities between the vehicles that have experienced failures.

Hyundai is currently replacing the failed units under warranty (recently expanded to 15 years in most markets), but that’s little comfort when you’re sitting on the side of the road waiting for a tow. These failures stand out in an otherwise easy to maintain platform, so hopefully this effort will lead to a permanent fix instead of merely swapping out for a new unit.

If you’d like to explore data analysis a little further, how about using astrophotography to detect exoplanets or learning more from Stanford?


hackaday.com/2026/07/25/iccu-m…

Gazzetta del Cadavere reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

☕ CYBERBRIEFING MATTUTINO — Sabato 25 luglio 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Nvidia riduce drasticamente chip AI in Asia: solo il 49% delle aziende autorizzate restano nella lista

📌 Link all'articolo : redhotcyber.com/post/nvidia-ri…

Carolina Vivianti

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Nvidia riduce drasticamente chip AI in Asia: solo il 49% delle aziende autorizzate restano nella lista

📌 Link all'articolo : redhotcyber.com/post/nvidia-ri…

A cura di Carolina Vivianti

#redhotcyber #news #politicheinformatiche #cybersecurity #siccurezzainformatica #protezionedati

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

381 – VI RACCONTANO STORIE DA FILM SULL’AI camisanicalzolari.it/381-vi-ra…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Il mio regalo di compleanno!


3D Printed Go Kart Designed to Fit in a Suitcase


[Ivan Miranda] is famous for his large-scale 3D printed vehicles. They’re pretty fun, but they’re also pretty big and heavy—which can make transporting them around rather impractical. Hence, when he had reason to travel with a 3D printed go kart, he went back to the drawing board to create something light enough to pack in regular plane luggage.

The build started with some major compromises compared to [Ivan]’s previous go kart build. Notably, there are only three wheels instead of four, and a simplified control layout that eschews a regular steering wheel. These decisions were made to save weight and allow the design to be more compact. The kart uses a set of handles either side of the rider to handle steering. Drive is via a brushless motor, with power supplied from a series of 18 V drill batteries. Parts were produced on [Ivan]’s massive printer which comes in handy on large-scale projects like these.

All in all, the final build weighed around 20 kg. That’s light enough to be broken down across checked luggage and carry-on for a typical flight. We’d consider the project a success on that basis, even if quite a bit of assembly was required upon arriving at the destination. [Ivan]’s other builds in this realm are pretty fun too, from the printed scooter to the ride-on tank.

youtube.com/embed/0foNjHxT8bw?…


hackaday.com/2026/07/24/3d-pri…


3D Printed Go Kart Designed to Fit in a Suitcase


The media in this post is not displayed to visitors. To view it, please log in.

[Ivan Miranda] is famous for his large-scale 3D printed vehicles. They’re pretty fun, but they’re also pretty big and heavy—which can make transporting them around rather impractical. Hence, when he had reason to travel with a 3D printed go kart, he went back to the drawing board to create something light enough to pack in regular plane luggage.

The build started with some major compromises compared to [Ivan]’s previous go kart build. Notably, there are only three wheels instead of four, and a simplified control layout that eschews a regular steering wheel. These decisions were made to save weight and allow the design to be more compact. The kart uses a set of handles either side of the rider to handle steering. Drive is via a brushless motor, with power supplied from a series of 18 V drill batteries. Parts were produced on [Ivan]’s massive printer which comes in handy on large-scale projects like these.

All in all, the final build weighed around 20 kg. That’s light enough to be broken down across checked luggage and carry-on for a typical flight. We’d consider the project a success on that basis, even if quite a bit of assembly was required upon arriving at the destination. [Ivan]’s other builds in this realm are pretty fun too, from the printed scooter to the ride-on tank.

youtube.com/embed/0foNjHxT8bw?…


hackaday.com/2026/07/24/3d-pri…

Fast Volumetric Imaging of Seizures with Adaptive Optics Light Sheet Microscopy


The media in this post is not displayed to visitors. To view it, please log in.


Seizure in zebrafish larva imaged using AO setup. (Credit: Bingxi Liu et al., Biomedical Optics Express, 2026)Seizure in zebrafish larva imaged using AO setup. (Credit: Bingxi Liu et al., Biomedical Optics Express, 2026)
Key to understanding something like epilepsy is to be able to record highly transient events in biological tissues. Generally this is done using light sheet microscopy, which provides effectively a 2D ‘slice’ of the tissue in question, but to observe a brief event in a larger biological system you need to be able to rapidly change the layer and focus between the virtual layers. This is what [Bingxi Liu] et al. al did using adaptive optics with an electrically tunable lens (ETL) in order to capture seizures in the brain of zebrafishes.

Their system can capture a volume of 499 × 499 × 150 μm3 at 4 volumes per second, which is large enough to fit optically transparent zebrafish larva into. The optical setup is shown in the above image, with the design based on the OpenSPIM platform for selective plane illumination microscopy.

Here the 488 nm laser provides the illumination (excitation) of the layer, while the 543 nm laser is for calibration purposes. The ETL is thus in the imaging path that allows for capturing by a digital camera, while a beam splitter directs part of the captured data to a Shack-Hartmann wave front sensor (SHWFS), which is part of the adaptive optics system.

After a seizure was induced in the zebrafish larva using the drug pentylenetetrazol the results were recorded using this system. It showed the seizure’s origin in the posterior brain, with subsequent propagation to the anterior before subsiding gradually over tens of seconds.

This system should be quite useful even outside of seizure research, as there are a lot of 3D systems in biology where having a relatively high-speed microscopic capture can be very revealing.


hackaday.com/2026/07/24/fast-v…

Hands-Free Mouse Uses Eyes And Muscles Instead


The media in this post is not displayed to visitors. To view it, please log in.

The standard computer mouse is a perfectly useful peripheral if your hands work. If you’ve got some trouble in that area, you might appreciate an alternative input solution. To that end, [Varun Adinath Patil] created a neat hands-free solution for moving a cursor around a screen.

The build is based on the Neuro PlayGround Lite, a board built for physiological signal acquisition in the Feather form factor. It’s hooked up to an IMU sensor—both a MPU6050 or BMI270 work—which tracks head movements to allow the cursor to be panned around the screen. Other biological signals are then used to activate other standard mouse functions. Clenching the jaw fires off a left click, while a triple blink fires a right click. Clicking and dragging is achieved by a double-blink. The jaw muscles are sensed via EMG signals picked up with gel electrodes on the skin, while the blinks are detected via EOG signals via the same contact points.

Commercial solutions in this realm exist, but it’s great to see how such a device can be built from the ground up. We’ve looked at other neat applications of head-tracking before, too. If you’re working on your own innovative accessibility tools, don’t hesitate to let us know via the tipsline.


hackaday.com/2026/07/24/hands-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Gli USA avviano un'indagine commerciale sull'Ue dopo la multa da 890 milioni di euro a Google

Trump ha annunciato un’indagine commerciale sull’Ue, accusando il blocco di prendere di mira ingiustamente le Big tech statunitensi, un giorno dopo la multa antitrust da 890 milioni di euro inflitta a Google

it.euronews.com/business/2026/…

@eticadigitale

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

youtu.be/TX8PAc01d4w?si=8WlUoJ…

minuto 45 della conversazione tra @rabble.nz e Blaine Cook

"the impulse to regulate platform based on age is this idea that there're unchangeable.
So I often describe this as like, you know, if we had libraries and 20 years ago people where like, you know what, libraries would be much more financially sustainable if we let people put sort of one armed bandit like gambling machine into libraries, and then oh we should have a bar in the library, that would be great. And let's just make it a strip club too. What we are doing"

"yeah, and now you have to walk through the bar and the strip club and everything else in order to get to the children's book section. You're like. This is a nightmare. Kids can't read books in "

"and so the political decision is, what we need to do is *ban* children from libraries. And there is this total lack of imagination that maybe libraries could be different"

@kenobit @marcocappato
@quinta @DataKnightmare
@informapirata

Questa voce è stata modificata (3 giorni fa)

reshared this

Cybersecurity & cyberwarfare ha ricondiviso questo.

#Google Fined €890M Under #EU Digital Markets Act Over Search and Play Store Practices
securityaffairs.com/195963/law…
#securityaffairs #hacking #DMA

Codeberg Bans Cryptocurrency and LLM-Generated Code Projects


The media in this post is not displayed to visitors. To view it, please log in.

Community-led open source project hosting site Codeberg has formally announced that projects whose code is largely or fully machine-generated through LLMs and other ‘AI’ tools will no longer be welcome. This follows on the heels of a similar ban on cryptocurrency-related projects.

The community vote was on two issues, the first being the notion that scraping of project code for the use in LLMs should be forbidden, which was a motion that easily passed. The second motion was on disallowing projects whose code was substantially generated by LLMs like Claude, OpenAI Codex, and similar. This motion passed with 358 in favor versus 144 against.

In the earlier linked blog post the reasoning behind especially this second issue is expanded upon, covering not only ‘license whitewashing’, but also the direct and indirect hardware costs, with the expanding ‘AI’ datacenter hyperscaling having massively increased hardware costs for Codeberg over the past years, as the costs have been largely externalized.

Also covered is also the aspect of these LLM-based tools destroying the OSS community, which is something that is backed up by recent studies. Even if we ignore that such LLM-tools are destroying the cognitive abilities of its users, there’s an argument to be made that if LLM-scraping is disallowed, then it’s consistent to also not allow LLM-generated code.

In the Terms of Use you can see these changes, both for LLMs and for cryptocurrency projects.

Thanks to [mk-fg] for the tip.


hackaday.com/2026/07/24/codebe…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Lemonade: la piattaforma open source per usare l’intelligenza artificiale in locale


Lemonade, la piattaforma open source per eseguire modelli di intelligenza artificiale in locale con supporto a chat, immagini, codice e gestione avanzata.Stai leggendo Lemonade: la piattaforma open source per usare l’intelligenza artificiale in locale, un articolo del blog Linux Easy. Non riprodurlo altrove senza permesso.

🔗 Leggi il post completo

E-ink Writing Deck Rocks a Typewriter Aesthetic


The media in this post is not displayed to visitors. To view it, please log in.

[Myth Made] has a goal to get into writing. However, she likes to do things the aesthetic way, rather than the easy way. Thus, she has eschewed simple word processing on a conventional computer, instead choosing to build a remarkably attractive writing deck styled after a classic typewriter.
The keycap marking technique is worth watching the video for on its own.
The build began with a mechanical keyboard with a compact layout. The square keycaps were swapped out for custom 3D printed versions that were rounded to suit the desired look. [Myth Made] used a neat technique where the caps were colored in with a paint marker and then ran through a laser engraver to bond the paint to the surface to make all the key markings.

With the input side sorted, the rest of the build could progress. The typewriter shell was printed in multiple parts, and then welded together with acetone. This was then covered with an ABS-acetone solution that helped remove some of the surface artifacts, before priming and paint. As for the electronics side, a Raspberry Pi Zero runs the show, hooked up to a Waveshare e-ink display which can be cranked up and down like a piece of paper coming out of a typewriter. There’s also a lovely 7-segment display which displays the current word count.

It’s a fun build that looks utterly joyous to use. Sometimes leaning into the aesthetic side of a project is what makes it so magical.

youtube.com/embed/MEqnDIuDGxc?…


hackaday.com/2026/07/24/e-ink-…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Nuova versione di Tails 7.10 Tails 7.10, il sistema operativo Linux anonimo, introduce una nuova procedura di spegnimento

A un mese di distanza da Tails 7.9, che si limitava ad aggiornare Tor Browser alla versione 15.0.16 e ad alcuni pacchetti firmware, la versione Tails 7.10 rappresenta un aggiornamento più consistente, introducendo una nuova procedura di spegnimento, quella dell'ambiente desktop GNOME

blog.torproject.org/new-releas…

@gnulinuxitalia

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

1449 bug di sicurezza per Oracle! L’effetto Anthropic Mythos si fa sentire

📌 Link all'articolo : redhotcyber.com/post/1449-bug-…

A cura di Luigi Zullo

#redhotcyber #news #cybersecurity #hacking #malware #ransomware #intelligenzaArtificiale #sicurezzaInformatica

Hackaday Podcast Episode 379: Driving E-ink DIY, NES on ESP, and the Other IRC


The media in this post is not displayed to visitors. To view it, please log in.

On this episode, Hackaday editors Elliot Williams and Tom Nardi discuss their love of electronic paper, clunky cartridges, and keeping old games alive by any means possible. You’ll also hear about getting the most out of the sensors in our 3D printers, playing with X-rays at home, a ring that runs Java, and a roulette wheel that outgrew its 555 timer. Stick around to the end to learn about a different sort of IRC that’s even more niche than the one you’re probably familiar with, as well as the logistical challenges and potential benefits of catching rockets with a giant net.

Check out the links if you want to follow along, and as always, tell us what you think about this episode in the comments!

html5-player.libsyn.com/embed/…

Direct download in DRM-free MP3.

Where to Follow Hackaday Podcast

Places to follow Hackaday podcasts:



Episode 379 Show Notes:

News:



What’s That Sound:


  • We’re putting What’s That Sound on hold while we sort out new prizes. Stay tuned.


Interesting Hacks of the Week:



Quick Hacks:



Can’t-Miss Articles:



hackaday.com/2026/07/24/hackad…

Acn: nel primo semestre 2026 resta elevata la pressione da parte delle minacce cyber


@Informatica (Italy e non Italy)
Secondo l'operational summary dell'Acn, nel primo semestre 2026 si sta consolidando il sistema nazionale di cyber security, mentre l'entrata a regime degli obblighi di notifica previsti dalla direttiva NIS2 rafforza la resilienza del Paese.

Tecnologia citiverse reshared this.

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Alleged 160-Million-Record Decathlon Customer Database Surfaces on Cybercrime Forum
#CyberSecurity
securebulletin.com/alleged-160…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Chaos Ransomware’s New msaRAT Tool Hijacks Chrome and Edge as a Stealth Command Channel
#CyberSecurity
securebulletin.com/chaos-ranso…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Sloppy Server Configuration Unmasks JadeProx Espionage Campaign and Its TriBack Malware Loader
#CyberSecurity
securebulletin.com/sloppy-serv…
Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Next.js Ships Emergency Fixes for Nine Flaws, Including High-Severity SSRF and Auth Bypass Bugs
#CyberSecurity
securebulletin.com/next-js-shi…

Keeping Mosquitoes Away with Catnip-Based Repellent


The media in this post is not displayed to visitors. To view it, please log in.

An image of a brown, red, and black mosquito on light human skin

Despite their small size, mosquitoes are one of the deadliest creatures on Earth, and keeping them away from you is one of the best ways to stay safe. DEET has been the mainstay of insect repellents for decades, but what if there was a repellent you could grow yourself?

Researchers at Cardiff University found that the essential oil from catnip plants (Nepeta cataria) could be as effective as DEET at repelling mosquitoes when applied as a 6% lotion. The oil has been shown to be effective against many species of mosquitoes, ticks, and mites in previous research. You can look at the paper for details, but the catnip oil was obtained through steam distillation followed by some processing with hexane. The essential oil was then mixed with “water, glycerin, emulsifying wax, cetyl alcohol, cetyl stearyl alcohol, shea butter, glycerol monostearate, olive oil, coconut oil, sunflower oil, methyl paraben, propyl paraben and silicone oil.” We suspect that list will look familiar to anyone who’s read an ingredient label of most any store bought lotion, unless it was paraben free.

The Guardian’s coverage quotes one of the researchers, [Dr. Simon Scofield]: “We did not conduct any experiments to see if it is attractive to cats, but given that the active ingredient [nepetalactone] has well-known cat-attractive properties, I would expect they would quite like it,” he said. Depending on how your cats react, you may want to consider applying the lotion shortly before departing home.

If you want some more options in your mosquito defense, how about becoming a bug zapper, using drones and sonar, or genetically modifying mosquitoes to curb their numbers.


hackaday.com/2026/07/24/keepin…

Malware nella supply chain software: gli sviluppatori sono il punto più vulnerabile


@Informatica (Italy e non Italy)
Il nuovo malware individuato da Doctor Web non si limita a sottrarre credenziali o installare backdoor: compromette i progetti C++ e C# trasformando gli ambienti di sviluppo in vettori di attacco. Un’evoluzione che conferma come la supply

This Week in Security: AI is a Mess, Hacking Car Chargers, an OpenSSL DoS, and Factories Under Attack


The media in this post is not displayed to visitors. To view it, please log in.

[Ayush Paul] posts about extracting data from Claude agents while it accesses web data to fulfill user requests.

But it wasn’t that easy. [Ayush] discovered that Anthropic anticipated many of the attacks, and set up guardrails in an attempt to keep the agent from accessing arbitrary web sites. For Claude to access a website, the user has to specify it, it must be the results of a web search, or it must be referenced by a website previously specified by the user or returned in a search.

To convince the Claude agent to navigate a malicious site designed to extract data, Ayush formed a false warning that Cloudflare was blocking the agent for authentication purposes, and asked it to spell out the name of the agents owner by clicking a list of alphabetical links. Of course Claude trusts Cloudflare and wants to be helpful, so it cheerfully completed the task.

Once the agent is trapped in the false authentication loop, it can be interrogated for all sorts of information it knows about the owner: Ayush was able to convince it to disclose employer, and even data about the user that could be linked to security questions, like their home town.

Since Claude can be detected by the user agent (the field attached to web requests that tells the web server what sort of browser is requesting the page) custom information can be fed to the bot while users see a normal website; clicking a link looks completely normal, but asking an agent to summarize the site triggers fooling the bot into spilling the beans.

After reporting the issue, Ayush was told that Anthropic had already identified the issue internally, and eventually prevented the attack for now by preventing the agent from following links on external pages.

Grok sends entire codebases


Cereblab discovered that the Grok coding agent uploaded the entire content of the codebase it’s working with – and all Git history – to xAI servers, almost immediately. Even when told to never upload a file, the agent would reply “OK”, and then begin uploading the code bundle anyway.

If uploading your code to a remote server isn’t bad enough, and this could be extremely bad in some situations involving sensitive company code, including the entire Git history means that previously deleted files, like accidentally committed secrets or authentication credentials and tokens, were also leaked. Attempting to opt out by disabling options to improve the model by uploading code had no effect.

After gaining attention, Grok has added a privacy option to opt out of data retention. xAI has committed to deleting the retained uploaded code, but it is unclear if users will be told when their data has been removed. To actually prevent the agent from uploading local files to the xAI servers, even temporarily, a global flag “disable_codebase_upload” is required. Watch out, the privacy retention flags are only per-session!

Steam malware used to steal crypto


Court filings in Washington state this month revealed an attempt to steal cryptocurrency using malware uploaded to the Steam gaming platform. Publicly identified and taken off the store in 2025, the filing alleges the same individuals were behind multiple games containing crypto stealing trojans: “Dashverse”, “Lunara”, “PirateFi”, “BlockBlasters”, and “Lampy”.

PC World covered the initial discovery of the malware on Steam. While Steam, overall, seems to do a good job preventing malware titles, 2025 had several high-profile cases. Prosecutors say the malware netted approximately $200,000 in stolen cryptocurrency wallets as well as other stolen credentials including Steam accounts.

OpenSSL DoS in 11 Bytes


Okta posts about a denial of service in OpenSSL where a single pre-auth packet is able to cause an allocation of up to 16 megabytes of RAM.

The “11 bytes” headline is very catchy, but more important than the actual number of bytes is the general asymmetric behavior; an attacker can send a very small amount of data and achieve a disproportionately large result. The OpenSSL vulnerability only has local impacts, exhausting server memory rather than generating network traffic, but similar attacks in the network space can fuel denial of service storms when extremely small requests result in amplified results.

The bug is ultimately due to being insufficiently suspicious of remotely supplied content, in this case the pre-authentication fields in the connection message that define the length of the incoming client message. Since the memory is pre-allocated in the server, the client doesn’t need to actually transmit that much data – it simply needs to hold the connection open. Keeping the connection open isn’t even required for causing problems – repeatedly allocating large blocks of different sizes can lead to memory fragmentation where the memory allocator keeps grabbing larger and larger ranges of memory because there isn’t sufficient ram available in a contiguous chunk.924899

Fortunately this bug has already been addressed in OpenSSL 4.0.1 and backported to maintenance releases of previous versions.

Exposed Interfaces on Car Chargers


Saiflow has a report on a range of exposures via the electric vehicle charging infrastructure.

In CVE-2026-9039 Saiflow exposes the risks in some CCS2 EV charging stations. As part of the standard, communication is established between the charging station and the operator network, which is typically strongly secured via TLS and VPN use. A second connection, however, is established over the charging plug between the charging station and the vehicle; the vehicle is assigned an IPv6 address for communicating with the charger for various charging protocols.

The XCharge C6 charging station exposes SSH and basic telnet network services on all network interfaces, including the interface connected to the vehicle. To make it even worse, they allow root login, with password “root”, giving full admin access to the charging station.

Once inside the charging station, an attacker has access to the network connection from the charging station to the company network, as well as root control over the charging station itself, with the possibility of damaging the charger, changing the power output levels, or getting free charging. If a future vulnerability was found in the management interface of the vehicle, a compromised charger could be used to attack future connected vehicles.

The main lessons for vendors seem to be ones we’re familiar with already: never leave default credentials, especially not “root” and “root” in a product, and be aware of what networks you expose services on. Good lessons for all of us; let those who have never left a Raspberry Pi with default credentials on a network cast the first stone.

Hugging Face Breach


In news that has likely been impossible to avoid, Axios reports on a compromise of the Hugging Face platform by an OpenAI model. The reports around the incident echo the frequently weird boastful statements from OpenAI, who state “We consider this to be an unprecedented cyber incident” and they “are responding accordingly”, despite being the originators of and cause of said incident.

Multiple vulnerabilities in the Hugging Face API were combined to accomplish the breach, including an unknown vulnerability in the package registry system. OpenAI says that safeguards on their model had been disabled for the test, which seems irresponsible given the outcome. Under almost any normal situation, conducting an unsolicited test of the security of a company because safeguards were ignored is considered illegal hacking, not fodder for a pre-IPO press release and humble-brag.

Linux Kernel Discloses 442 Vulnerabilities


Possibly feeling that Microsoft has all the press for a record-breaking Patch Tuesday last week, the Linux kernel developers have announced 442 CVEs related to the kernel.

With this many vulnerabilities in one report, it’s nearly impossible to isolate at a glance which ones are truly impactful and which are simply incorrect behavior. While CVE entries have been created, none have been assigned severity scores yet.

It appears the majority of the vulnerabilities were found with Sashiko, an agent developed by the Linux Foundation and trained on the Linux kernel for finding vulnerabilities in new submissions.

LG to Ban Residential Proxy Apps


After recent negative press (some of which we covered here) about the prevalence of residential proxy apps on the LG platform, Krebs on Security now reports that LG is banning the behavior from apps on the platform.

This comes after Spur reported that 42% of apps on the platform contained libraries to enable always-on residential proxies, which allow access to the network the television is connected to. Residential proxies can be used as a pivot point to attack companies and bypass geographic IP restrictions, commit ad fraud, or access the internal home networks of users.

Iran Attacking Industrial Logic Controllers


CISA, the US cyber security agency, has issued a warning that Iranian based attackers are targeting industrial control systems made by Rockwell Automation, Schneider Electric, and Siemens.

These sort of controllers are found in manufacturing, waste processing, water treatment, and other industrial processes, and attackers have been able to upload custom control logic, overriding “safe operating parameters” according to the report. Most of us will never be responsible for these systems, but they impact our lives all the time.

Cisco Releases Open-Weight Vulnerability-Finding Models


Finally, Cisco has released a set of open-weight models to aid in searching a codebase for known vulnerabilities. The Antares models are open-weight models designed to run fully locally and search a code base for vulnerabilities related to lists of known CVE issues. Cisco has published the models on Hugging Face.

Are you using AI tooling for security scans or research? How is it going?


hackaday.com/2026/07/24/this-w…

in reply to Cybersecurity & cyberwarfare

The biggest practical gap I see in AI security scans is confusing pattern detection with a trust-boundary review. For agent skills, I check what the instructions authorize, where credentials can flow, whether callbacks or fetched content can redirect execution, and which paid/destructive actions lack an explicit consent gate. Those semantic failures often look harmless to a string scanner.

I turned that checklist into a fixed review for one public SKILL.md, MCP manifest, or agent card: evidence-backed findings and concrete remediations, 24h, 0.12 SOL.
solana-quick-kit.nxtboyiii.cha…

Cybersecurity & cyberwarfare ha ricondiviso questo.

La BCE lancia una consultazione per il design futuro delle prossime banconote in euro


"Le nostre banconote in euro si rifanno il look! Designer di tutta Europa hanno ripensato al loro aspetto."


Vorresti dire la tua sui tuoi modelli preferiti? Fallo pure, tanto non gliene fregherà niente a nessuno!

SPOILER: 5 progetti presentano diverse specie di paduli volanti 🐦‍⬛ ... E no, non è uno scherzo


ecb.europa.eu/euro/banknotes/f…

in reply to Emanuele Cariati

@emanuelecariati diciamo che la UE della VonDerLeyen non è quella dei miei sogni ma a noi in famiglia è piaciuto commentare e votare per le varie proposte. Anche perché la banconota da 100 ogni tanto la vediamo quando la nonna fa la bustina a Natale, ma quella da 200 credo la vedremo solo riprodotta sul sito, per cui è qualcosa che proprio sapendo quanto poco impatterà su di noi, è stato un semplice passatempo.
Cybersecurity & cyberwarfare ha ricondiviso questo.

I governi dell'UE hanno voluto il ritorno di Chat Control 1.0 – Breyer: “I veri perdenti sono i nostri figli”

#ChatControl 1.0 è tornato: i governi UE (tranne 🇭🇺+🇧🇪) hanno prorogato la scansione indiscriminata dei messaggi privati da parte dei servizi USA fino al 2028, aggirando il Parlamento europeo. Cosa cambia ora e i prossimi passi

pirati.io/2026/07/i-governi-de…

@privacypride

Cybersecurity & cyberwarfare ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇩🇪Die #Chatkontrolle 1.0 ist zurück: EU-Regierungen (inkl. Bundesregierung) haben das anlasslose Scannen privater Nachrichten durch US-Dienste bis 2028 gestern verlängert – am EU-Parlament vorbei.

Was sich jetzt ändert und wie es weitergeht: patrick-breyer.de/eu-regierung…

in reply to Patrick Breyer

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇪🇺#ChatControl 1.0 is back: EU governments (except for 🇭🇺+🇧🇪) have extended the suspicionless scanning of private messages by US services until 2028 – bypassing the EU Parliament.

What changes now and what happens next: patrick-breyer.de/en/eu-govern…

Questa voce è stata modificata (3 giorni fa)

reshared this

in reply to Patrick Breyer

🇫🇷Le #ChatControl 1.0 est de retour : les gouv. de l'UE (sauf 🇭🇺+🇧🇪) ont prolongé le scan indiscriminé des messages privés par les services US jusqu'en 2028 – contournant le Parlement européen.

Ce qui change et la suite : patrick-breyer.de/en/eu-govern…

Questa voce è stata modificata (3 giorni fa)
in reply to Patrick Breyer

🇮🇹Il #ChatControl 1.0 è tornato: i governi UE (tranne 🇭🇺+🇧🇪) hanno prorogato la scansione indiscriminata dei messaggi privati da parte dei servizi USA fino al 2028, aggirando il Parlamento europeo.

Cosa cambia ora e i prossimi passi: patrick-breyer.de/en/eu-govern…

Questa voce è stata modificata (3 giorni fa)

reshared this

in reply to Patrick Breyer

🇪🇸El #ChatControl 1.0 está de vuelta: los gobiernos de la UE (salvo 🇭🇺+🇧🇪) han prorrogado el escaneo indiscriminado de mensajes privados por servicios de EE. UU. hasta 2028, eludiendo al Parlamento Europeo.

Qué cambia ahora y próximos pasos: patrick-breyer.de/en/eu-govern…

Questa voce è stata modificata (3 giorni fa)
in reply to Patrick Breyer

en el pasado las ovejas del sistema no oyeron a los expertos en ciberseguridad, no hicieron caso a los expertos lo de proteger su privacidad. Por no hacer caso, ahora esas ovejas se indignaron con chat control, y la verificación de edad para acceder a servicios. Pero cuando llegue el ID wallet digital europeo ya será muy tarde. Aún es tiempo, hay tiempo de no dejarse someter a la vigilancia masiva. O actúan ahora, o serán ovejas llevadas al matadero digital. Ustedes deciden.
Cybersecurity & cyberwarfare ha ricondiviso questo.

NEW: I spoke to several offensive cybersecurity researchers, including zero-day developers, about how the guardrails imposed by OpenAI and Anthropic on their AI models are getting in the way of their work.

Most complained that the guardrails are inconsistent and too strict, which pushes them to use open source models instead.

techcrunch.com/2026/07/23/how-…

Ah, il dramma di Codeberg. È stata davvero una settimana interessante nel mondo del FLOSS... Il post di @Tommaso Gagliardoni

@GNU/Linux Italia

A seguito di un'assemblea generale alla fine di giugno, è stata avviata una votazione su due mozioni e il periodo di votazione si è concluso un paio di giorni fa. Le mozioni riguardavano una modifica ai Termini di utilizzo del servizio di hosting Git di Codeberg: il divieto di progetti relativi a LLM e criptovalute . Entrambe sono state approvate.

Pensateci un attimo: Codeberg ora vieta l'hosting e la condivisione di:

- Progetti relativi alle criptovalute;
- Progetti "fortemente legati all'ecosistema LLM";
- Progetti "creati dagli agenti LLM in modo autonomo";
- Progetti "scritti e gestiti con un ampio utilizzo di LLM".

Tutto questo è talmente sbagliato che non so nemmeno da dove cominciare, quindi forse è più facile iniziare da ciò che non è sbagliato. Solita avvertenza: opinioni personali, bla bla bla...

gagliardoni.net/#20260724_code…

Cybersecurity & cyberwarfare ha ricondiviso questo.

La marcia degli "scarafaggi" - La polizia indiana ha represso i manifestanti e loro sono tornati a casa e hanno creato dei meme sull'accaduto

@Politica interna, europea e internazionale

"Hanno chiesto le dimissioni del Ministro dell'Istruzione Dharmendra Pradhan a causa della fuga di notizie sui test d'esame e degli scandali relativi alle assunzioni. Pradhan si è rifiutato di dimettersi, accusando l'opposizione di strumentalizzare gli studenti a fini politici.

Le autorità hanno sospeso la connessione internet mobile nell'area della protesta. In serata, i manifestanti hanno affermato che decine di persone erano state picchiate dalla polizia, mentre la polizia ha dichiarato che anche diversi agenti erano rimasti feriti.

Quando Chhavi finalmente caricò i video quella sera, una cosa saltò subito all'occhio. Prima della marcia, aveva scherzato sull'eventualità di essere picchiata dalla polizia. Ore dopo, sorrideva ancora, posava accanto agli agenti antisommossa, faceva il segno della vittoria, filmava tra la folla e intervistava persino un manifestante ferito.

Questi video erano tra le migliaia di filmati, meme e testimonianze dirette che hanno invaso Instagram non appena i manifestanti hanno riacquistato l'accesso a internet. Alcuni trasudavano rabbia. Altri erano pieni di ansia, paura o silenziosa sfida. Eppure, spesso era l'umorismo sarcastico ad attirare l'attenzione."

NB: il movimento ha assunto questo nome riappropriandosi di un insulto giudiziario. Durante un'udienza in tribunale riguardante i giovani disoccupati, un giudice della Corte Suprema ha paragonato in modo sprezzante i giovani disoccupati a "scarafaggi" e "parassiti".

bbc.com/news/articles/c3ek3l9g…

Cybersecurity & cyberwarfare ha ricondiviso questo.

Divieto di protestare. Un saggio imperdibile di Annalisa Camilli

@Politica interna, europea e internazionale

Come sono cambiati i movimenti di protesta? Cosa produce la criminalizzazione del dissenso? L’approccio penale preventivo trasforma coloro che esercitano diritti garantiti dalla Costituzione (diritto di sciopero, libertà di pensiero e parola…) in persone da sanzionare, criminalizzare, intimidire e manganellare.

Il saggio di Annalisa Camilli “Divieto di protestare” contiene un’analisi articolata e documentata della deriva autoritaria in corso non solo in Italia, ma in vari paesi importanti dell’Occidente. Germania, Gran Bretagna, Italia e USA presentano fenomeni analoghi di repressione securitaria, con differenze normative che non cambiano la sostanza.

pressenza.com/it/2026/07/divie…

Cybersecurity & cyberwarfare ha ricondiviso questo.

La crisi dei data center subprime

In "The Big Short", un manager di CDO diceva che il mercato per l'assicurazione dei titoli ipotecari era 20 volte più grande del mercato dei titoli ipotecari stessi
Il paragone tra un data center per l'IA e un CDO può sembrare un po' ridicolo, ma in realtà è incredibilmente simile. Ma ognuno di questi contratti ha delle strane clausole uniche che li rendono, beh, più pericolosi

wheresyoured.at/the-subprime-d…

@aitech pub.towardsai.net/what-if-your…

reshared this