Salta al contenuto principale

Lorenzo ha ricondiviso questo.


The Pope involves himself in Italy's spy scandal and asks intel officials to respect people's privacy and not leak data and smear people with hacked data

reuters.com/world/pope-tells-i…

Questa voce è stata modificata (3 ore fa)

reshared this


Lorenzo ha ricondiviso questo.


The GNOME project has banned developers from including AI-generated code in its shell extensions

blogs.gnome.org/jrahmatzadeh/2…

in reply to Catalin Cimpanu

Your news headline, which is written like a tabloid, is not accurate. Read the article.
in reply to Catalin Cimpanu

I think I'll never get along with GNOME's general design principles, but darned if my general opinion of them didn't just go up like ten points all at once.

Lorenzo ha ricondiviso questo.


Meta finds that the state government of the autonomous region of Gagauzia, in Moldova, has directly sponsored Kremlin propaganda in the country

transparency.meta.com/metasecu…

reshared this


Lorenzo ha ricondiviso questo.


Google is now tracking at least five Chinese cyber-espionage groups that are exploiting the React2Shell vulnerability for initial access.

The groups are UNC6600, UNC6586, UNC6588, UNC6595, and UNC6603. This is up from two at the beginning.

cloud.google.com/blog/topics/t…

Questa voce è stata modificata (19 ore fa)

reshared this


Lorenzo ha ricondiviso questo.


A report on Weyhro C2, a new offensive toolkit advertised on underground forums.

The toolkit appears to be the work of the individual behind the (now-failed) Weyhro ransomware from March this year.

lumma-labs.com/weyhro-c2-becau…

reshared this


Lorenzo ha ricondiviso questo.


SABATO 20 DICEMBRE 2025 ORE 20:45 IL CORO LA PIEVE PRESENΤΑ NELLA PIEVE ROMANICA DI SAN FLORIANO IL CONCERTO di NATALE

AL TERMINE MOMENTO CONVIVIALE CON SCAMBIO DI AUGURI

E c'è anche @matz @matteo che dirige

agcverona.it/eventi/concerto-d…

@verona

in reply to Esserci. O no?

comunque volvo ringraziarti per avere utilizzato il gruppo Activitypub di Verona che al momento era rimasto un po' deserto 😅

@matz @matteo @verona

reshared this

in reply to Esserci. O no?

non è solo la categoria Verona che non viene utilizzata ma ce ne sono diverse che vengono utilizzate poco. Il problema è che il server è nato da pochi mesi, E soprattutto non l'abbiamo mai pubblicizzato abbastanza. Al momento sono pochi gli gli iscritti al server e la maggior parte dei contenuti proviene dal Fediverso.

A causa di questo, alcune categorie legate ad alcune città sono abbastanza vuote di contenuti... 😅

@matz @matteo @verona

in reply to macfranc

ah, non sapevo ci fosse!

reshared this

in reply to matz

abbiamo inserito tutte le province del Veneto (compresa la mia @treviso 😅) e ci siamo spinti pure con qualche comune come @este ma al momento mancano soprattutto gli utenti 🙄

PS: Tra l'altro, la struttura di NodeBB ci consente non solo di rendere le categorie/città come gruppi #Activitypub, non solo di aprire le nostre categorie a nuovi moderatori, ma in futuro ci consentirà anche di più: per esempio, se domani nascesse un'istanza NodeBB dedicata a Vicenza, io potrei chiudere la mia categoria @vicenza e linkare la categoria "Vicenza" di quell'istanza NodeBB o di tutte le sue sottocategorie. Mi basterebbe solo venirlo a sapere. Sono convinto che #NodeBB può cambiare il volto del Fediverso come lo conosciamo, forse ancora più di quanto lo farà #WordPress


@esserci @verona

reshared this

in reply to matz

@macfranc
Già che chi siamo posso ringraziare anche per aver usato Mobilizon ? 😉

reshared this


Lorenzo ha ricondiviso questo.


An activist was charged with destruction of evidence after resetting his phone to factory settings

techspot.com/news/110560-man-a…

reshared this

in reply to Catalin Cimpanu

Hey, look, if Hillary can erase entire email servers without reprisal, surely one cellphone being reset by a musician isn't that big of a deal...

/s

Questa voce è stata modificata (20 ore fa)

Lorenzo ha ricondiviso questo.


RE: techhub.social/@Techmeme/11571…

This is another unneeded action from the Trump administration and is just another way for defence contractors to siphon money from the US govt at inflated prices


Sources: The Trump administration is drafting a new cyber strategy that would enlist private companies to mount offensive cyberattacks on foreign adversaries (Jamie Tarabay/Bloomberg)

bloomberg.com/news/articles/20…
techmeme.com/251213/p9#a251213…


reshared this

in reply to Catalin Cimpanu

The other fun thing is that a lot of the staff working on these contracts will end up indicted for crimes, just like we do to hackers in China and Russia. Assurances that the US Government won't prosecute them don't carry over to other jurisdictions, and these contractors won't be protected as lawful combatants like uniformed personnel.

Lorenzo ha ricondiviso questo.


The Dutch NCSC on the Notepad++ update hijack attacks:

"Currently, as far as is known, only organizations with interests in East Asia are victims of targeted attacks"

cc: @GossiTheDog

ncsc.nl/actueel/nieuws/2025/12…

reshared this


Lorenzo ha ricondiviso questo.


Arena Breakout is giving out 10-year bans for cheating

reshared this


Lorenzo ha ricondiviso questo.


Can you please correct the naming of your Fedidevs.com starter packs?

@filippodb @amministratore dear Mastodon.uno administrators,
I've noticed that some starter packs you've uploaded to the site have incorrect descriptions: they almost seem designed to promote ONLY USERS of your instance, while ignoring all other instances in the #fediverse. In fact, they were all created by service accounts on the mastodon.uno instance.

This seems understandable, but I think it's urgent to rename the descriptions of those starter packs to specify that they are exclusively for users of your instance, otherwise they could mislead other users.

The starter packs in question are as follows:

  • Satira vignette e meme (created by the @satira account, a mastodon.uno service account)
  • Retrogames (created by the @kickoffworld account, a mastodon.uno service account)
  • Profili Free Open Source su Mastodon on Mastodon (created by the @opensource account, a mastodon.uno service account)
  • Ambiente Mobilità sostenibile e giustizia climatica (created by the @ambiente account, a mastodon.uno service account)
  • Fedilug Account Linux Italiani Account Italian Linux Accounts (created by the @linux account, a mastodon.uno service account)
  • Sicurezza digitale (created by the @sicurezza account, a Mastodon.uno service account)
  • Fediverso e Social network (created by the @socialnetwork account, a Mastodon.uno service account)

I repeat: it's right to advertise to your users, but it's important to explain that it's self-promotional advertising. For example, the Mastodon UNO & Official Devol Accounts starter pack clearly specifies that it refers to the users of your instance.

This is out of respect for all Italian users of the Fediverse and for the developers who created and made the fantastic Fedidevs resource available for free.

Thank you for your attention and have a good evening

@anze3db @fedidevs

reshared this

in reply to Al Kath

I'd like to @Fedidevs and @Anže that I tried using Fedidevs with Friendica and it worked great with both Friendica and Mastodon contacts (it gave me an error, but then the follow was confirmed)!
Thanks to @Al Kath for the suggestion: #fedidevs is a very powerful tool.

Al Kath reshared this.

in reply to Al Kath

aggiunto allo starter pack un bel po di satira internazionale, che incredibilmente avevo lasciato fuoi, come XKCD, devo capire se viene aprezzata o meno. Mancano le statistiche su questo servizio.
Questa voce è stata modificata (2 giorni fa)

Lorenzo ha ricondiviso questo.


"Germany has accused Russia of a cyber-attack on air traffic control and attempted electoral interference, and summoned the Russian ambassador. "

bbc.com/news/articles/cvgrrnyl…

reshared this


Lorenzo ha ricondiviso questo.


-EU has a problem attracting and retaining cyber talent
-Coupang CEO resigns following breach
-NoName057 and CARR member charged in the US
-Chrome and Gogs zero-days
-UK sanctions Chinese hacking firms
-Coupang hacker was a cyber employee
-Petco takes down leaky Vetco site
-UK fines LastPass over breach
-Ransomware at HSE Ireland, again
-Russia denies military registry hack
-New PowerShell security feature

Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS507/

reshared this

in reply to Catalin Cimpanu

-New Android Emergency Live Video feature
-CA/B Forum to sunset 11 domain validation methods
-Let's Encrypt to reach 1 billion certs in 2026
-Belarus blocks six crypto exchanges
-Russia preparing full Google ban
-US readies "thought police" for foreign travelers
-Ukrainian bot farm operator arrested
-Crypto money launderer pleads guilty
-Dutch man attacked emergency 112 service
-US charges Accenture manager over false cloud security claims
-Cybercrime trainer gets jail sentence

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

-Crypto-exchange pleads guilty to laundering hacked funds
-More VS Code malicious extensions
-New PeerBlight and NANOREMOTE backdoors, InboxPrime AI PhaaS, PyStoreRAT, 01flip and VolkLocker RaaS
-New DroidLock Android ransomware
-Charming Kitten payroll data leaks online
-New Russian disinfo op backs Musk's EU attacks
-Salt Typhoon operators trained with Cisco back in 2010s
-Traefik misconfiguration disables TLS verification
-SOAPwn vulnerabilities
-Notepad++ fixes update hijack flaw
in reply to Catalin Cimpanu

-New ConsentFix attack
-Microsoft bug bounty expands to.... EVERYTHING [Gary Oldman voice]
-10k Docker Hub images leak secrets
-1k MCP servers exposed online
-SPAs leak 42k secrets
-We have an OWASP Agentic Top 10
-The 2025 CWE Top 25 is out
in reply to Catalin Cimpanu

I don't see why bad actors having trained with Cisco is news. I don't have a particular brief for Cisco, but they can't be supposed to be responsible for what alumni do, nor reasonably vet people who sign up. Bad actors have probably trained on many school programmes - I don't expect all of them were self-taught in their bedrooms.

Lorenzo ha ricondiviso questo.


MITRE has published the list of Top 25 most common software vulnerabilities of 2025, also known as the CWE Top 25

cwe.mitre.org/top25/archive/20…

reshared this

in reply to Catalin Cimpanu

I once had to wait after work to catch a programmer who was using a buffer pointer after he'd freed it. QA caught it, and thought it was my code. Nope, but I figured out whose it was.

That one has been around for a long, long time.


Lorenzo ha ricondiviso questo.


Looks like Notepad++ has fixed its update system: community.notepad-plus-plus.or…

This is after reports that users received malicious Notepad++ updates containing malware: doublepulsar.com/small-numbers…

reshared this


Lorenzo ha ricondiviso questo.


Some phishers have taken inspiration from Russian cyber-espionage group UTA0355 and are using a technique that tricks users into sharing their OAuth material in a web page (UAT0355 did it via email replies)

pushsecurity.com/blog/consentf…

reshared this


Lorenzo ha ricondiviso questo.


Google is rolling out a new feature for Android users that will let them share live video with emergency services.

The new feature is being rolled out in the US and some regions in Mexico and Germany.

It will be available for Android 8 (2017) devices or higher

blog.google/products/android/e…

reshared this


Lorenzo ha ricondiviso questo.


RE: mastodon.social/@campuscodi/11…

More research of this type

Intruder found 43k secrets across 5 million single-page apps: businesswire.com/news/home/202…

Bitsight has found more than 1,000 MCP servers exposed on the internet with no authorization in place and exposing sensitive data: bitsight.com/blog/exposed-mcp-…


Security firm Flare has scanned the Docker Hub portal and found secrets and tokens, including for production systems, in more than 10,000 images

flare.io/learn/resources/docke…


reshared this


Lorenzo ha ricondiviso questo.


CA/B Forum to sunset 11 domain validation methods used to issue TLS certificates

security.googleblog.com/2025/1…

reshared this


Lorenzo ha ricondiviso questo.


UK ICO fines LastPass £1.2m for 2022 data breach

ico.org.uk/about-the-ico/media…

reshared this


Lorenzo ha ricondiviso questo.


Looks like Twitter finally took down the NoName057 account after yesterday's indictment

x.com/Safety/status/1998528342…

reshared this


Lorenzo ha ricondiviso questo.


SOAPwn -- new bugs that can lead to RCE in .NET apps

Vulnerable applications include the Umbraco CMS, Barracuda's Service Center, the Ivanti Endpoint Manager, and more

Microsoft did not fix them

labs.watchtowr.com/soapwn-pwni…

reshared this


Lorenzo ha ricondiviso questo.


Dutch prosecutors are seeking an eight-month prison sentence for a man who launched DDoS attacks against the country's 112 emergency line.

The suspect allegedly tried to frame some business partners for the attack

om.nl/actueel/nieuws/2025/12/1…

reshared this


Lorenzo ha ricondiviso questo.


There's this image on social media about how most of the Red Bull team that helped Verstappen win his titles are now gone... but few people posting this remember this drama started from the Verstappens.

This is the definition of shooting yourself in the nuts. You should have 0 sympathy for him

reshared this


Lorenzo ha ricondiviso questo.


The Paxful cryptocurrency exchange has pleaded guilty to laundering crypto-assets linked to scams, fraud, and extortions

Will pay a $4mil fine only

justice.gov/opa/pr/virtual-ass…

reshared this


Lorenzo ha ricondiviso questo.


This constant stream of malicious VSCode extensions won't end anytime soon....

This batch hid its payload, a Rust-based trojan, as PNG files inside the dependencies folder

reversinglabs.com/blog/malicio…

reshared this


Lorenzo ha ricondiviso questo.


A popular reverse proxy and ingress controller shipped misconfigured versions for the past five months.

The Traefik setting that enabled TLS verification was actually disabling it across the board.

aisle.com/blog/cve-2025-66491-…

reshared this


Lorenzo ha ricondiviso questo.


Pffff... the Coupang insider, who allegedly stole the company's data, was apparently a cybersecurity employee

koreajoongangdaily.joins.com/n…

reshared this

in reply to Catalin Cimpanu

The Coupang CEO also resigned following the hack and police raids: koreatimes.co.kr/business/comp…

That's the third South Korean CEO to resign after a breach after the KT and SK Telecom ones


Lorenzo ha ricondiviso questo.


Security firm Flare has scanned the Docker Hub portal and found secrets and tokens, including for production systems, in more than 10,000 images

flare.io/learn/resources/docke…

reshared this


Lorenzo ha ricondiviso questo.


The Justice Department charged a former product manager at Accenture Federal Services with falsely misleading government customers about the security posture of a cloud product offered by the company.

nextgov.com/cybersecurity/2025…

reshared this

in reply to Catalin Cimpanu

presumably they falsely claimed something or mislead customers. It would be unlikely although awesome if they were expected to mislead and did so falsely. Which would kinda make it the truth

Lorenzo ha ricondiviso questo.


RE: flipboard.com/@retrowarehouse/…

If any font needs to be banned, it should be Trebuchet MS...

Inter all the things!!!!

reshared this


Lorenzo ha ricondiviso questo.


The ENISA yearly survey is out: enisa.europa.eu/publications/n…

Yo, EU! Patch your stuff!

reshared this


Lorenzo ha ricondiviso questo.


A new US startup named Operation Bluebird has asked the US Patent and Trademark Office to vacate old Twitter trademarks, claiming that Elon Musk has abandoned them

reuters.com/technology/us-star…

reshared this


Lorenzo ha ricondiviso questo.


A crypto CEO "web2 security is not strong" while his industry lost billions in hacks over the past years must be the definition of tone deaf

reshared this



Arnad: 50 Valdostani infuriati acchiappano un ladro d'appartamento e lo picchiano con diversi oggetti tra cui un piccone e gli fratturano il bacino. L'altro ladro s'è dato

È un tranquillo venerdì sera ad Arnad, in Valle d’Aosta. Ma la serata viene funestata da due ladri che si introducono in una abitazione nella frazione Sisane, tentando di forzare una cassaforte.

I due, però, vengono colti in flagrante dal vicinato che li ha sentiti e ha chiamato le forze dell’ordine. Nel frattempo, però, parte anche il passaparola tramite cellulare che ha portato in breve tempo molti residenti in strada e, al tentativo di fuga dei malviventi, almeno 50 persone si sono lanciate al loro inseguimento.

Se uno dei ladri è riuscito a dileguarsi, per l’altro – un 40enne – invece le cose sono andate diversamente: i cittadini lo hanno bloccato mentre tentava la fuga verso il bosco, lo hanno accerchiato e picchiato con un piccone fino a procurargli la frattura del bacino. L’uomo è stato poi trasportato in ospedale; la lesione è stata giudicata guaribile in 30 giorni.

quotidianopiemontese.it/2025/1…

@Valle d'Aosta

reshared this


Lorenzo ha ricondiviso questo.


-Linux adds PCIe encryption to secure cloud servers
-Europol cracks down on Violence-as-a-Service providers
-ICC designates cyberspace as a genocide enabler
-Cambodia busts SMS blaster warehouse
-Police raid Coupang offices
-New Khashoggi lawsuit filed in France
-Aeroflot hack originated from contractor network
-FTC denies SpyFone CEO petition
-Meta agrees to use less personal data for ads in EU

Podcast: risky.biz/RBNEWS506/
Newsletter: news.risky.biz/risky-bulletin-…

reshared this

in reply to Catalin Cimpanu

-New Chrome and Firefox versions
-Patch Tuesday security updates are out
-NDAA 2026 comes with cyber provisions
-New Zealand notifies Lumma victims
-Poland arrests three Ukrainian hackers
-Russia arrests NFCGate hackers
-Spain arrests 19yo hacker
-React2Shell exploitation hits IoT space
-Telegram cracked down on crime channels since Oct '24
-New malware: GhostFrame PhaaS, Spiderman PhaaS, ChimeraWire, DeadLock ransomware, Broadside botnet, GhostPenguin Linux backdoor
-ZeroBoot exploit

Catalin Cimpanu reshared this.


Lorenzo ha ricondiviso questo.


The point of entry for the Aeroflot hack (from July) appears to have been Bakka Soft, an IT company that developed the airline's mobile and web apps

thebell.io/istoriya-bolshogo-v…

reshared this


Lorenzo ha ricondiviso questo.


New Zealand's cybersecurity agency is notifying more than 26,000 users who have been infected with the Lumma Stealer

ncsc.govt.nz/news/nz-cyber-age…

reshared this


Lorenzo ha ricondiviso questo.


Germany's cybersecurity agency has conducted a security audit of ten password managers and found that three of them can access a user's stored passwords—Google Chrome, mSecure, and PassSecurium

bsi.bund.de/DE/Service-Navi/Pr…

reshared this

in reply to Catalin Cimpanu

Wouldn't it be more worrying if the password managers *couldn't* access the passwords that the user has stored in them?
in reply to Catalin Cimpanu

interesting selection of software. Are some of those particularly popular in Germany? There are (at least) a couple of fairly big ones missing

Lorenzo ha ricondiviso questo.


Cydome has spotted Broadside, a new variant of the Mirai IoT malware.

The botnet is targeting TBK DVRs, commonly used by the maritime sector, including on some vessels.

cydome.io/cydome-identifies-br…

reshared this