Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

krebsonsecurity.com/2026/05/ci…

Lorenzo ha ricondiviso questo.

Interpol arrests 201 suspects across MENA for their involvement in cyber scams, phishing, and malware ops

interpol.int/News-and-Events/N…

reshared this

in reply to Catalin Cimpanu

I think you are slightly misinterpreting what he said.

I read it as "the duplication of reports submitted by multiple people using the same tools makes the security list unusable with them being repeatedly triaged aka pointless churn, wasting everybody's time."

Which is not saying that he doesn't like the bugs that are being found, or the fact that they are being found by AI tools, just that the processes around how the bugs are surfacing is undesirable/unmanageable.

Lorenzo ha ricondiviso questo.

So... they imposed that stupid checkmark on my profile and then limit my account?

On top of the fact that any tweet seems to be silently limited to max 2k impression anyway... hence why I stopped posting there in the first place

It's literally a pay-to-be-seen platform


X quietly limits users who didn't pay for verification to "50 original posts and 200 replies per day", down from 2,400 posts per day (Jackson Chen/Engadget)

engadget.com/2175771/x-free-ac…
techmeme.com/260518/p36#a26051…


reshared this

Lorenzo ha ricondiviso questo.

📺 NCSC’s Ollie Whitehouse on surviving the "bugpocalypse"

risky.biz/video/ncscs-ollie-wh…

reshared this

Lorenzo ha ricondiviso questo.

Playing the Hive and Grove factions in this game is pure torture... never again!!!


I would like to report that I'm consistently beating the AI on "easy mode"... probably because it was bugged for a few days and the AI was in God mode regardless of settings 🤣

I'd honestly thought I'd like the "tournament" format in multiplayer, but I kinda hate the forced mandatory battles

@campuscodi@mastodon.social:

90% of the people streaming the new Heroes: Olden Era game are Russians
Anyone know why is it so popular over there?



reshared this

Lorenzo ha ricondiviso questo.

Bitcoin Depot, the US' largest crypto ATM operator, is shutting down citing anti-fraud measures it had to roll out

...and now you know why these things existed in the first place

globenewswire.com/news-release…

reshared this

Fadocx il visualizzatore documenti open per Android

@GNU/Linux Italia

linuxeasy.org/fadocx-visualizz…

Fadocx è il visualizzatore documenti open source per Android che punta tutto su privacy, supporto offline e OCR locale senza tracker.
L'articolo Fadocx il visualizzatore documenti open per Android proviene da Linux Easy.
E' vietato riprodurre questo articolo

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Indonesia emerges as a new hub for cyber scams
-Grafana hacked and held for ransom
-Fast16 malware targeted nuclear explosion simulation software
-Exchange zero-day is under attack
-Hackers breach US tank gauges
-THORChain hacked for $11m after months-long hack
-Microsoft adds driver rollback feature
-Microsoft removes Edge passwords from RAM
-KDE gets EU funding
-Google tests new Gmail quota
-BlueSky considering Edit button

Podcast: risky.biz/RBNEWS565/
Newsletter: news.risky.biz/risky-bulletin-…

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-arXiv will ban authors of AI-generated papers
-Starlink tracking is now a thing
-Trump & Xi discussed cyberattacks
-Tech giants threaten to leave Canada over lawful access bill
-Poland tells officials to move from Signal to in-house messenger
-FBI advises against paying ShinyHunters
-CRXfiltrate campaign is back
-A new data extortion group emerges, and then shuts down
-Americans lost $388m to crypto ATMs
-FlowerStorm PhaaS adds VM-based obfuscation
-APT37 poses as the police

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Twill Typhoon's FDMTP backdoor
-New TencShell attacks
-Sandworm and Leek Likho activity still going
-UK sanctions Russian disinfo firms
-Malware reports on Gremlin Stealer, Vidar, XWorm
-openDCIM and NGINX Rift come under attack
-Bug bounty hunters break Apple's MIE
-2020 Windows patch gets rolled back
-New Eris LPE
-AI-assisted vulnerability discovery is here
-GitHub bug bounty program to allow AI-found bugs
-New tools—PatchWatch & pocsmith
-Pwn2Own 2026 Berlin
Lorenzo ha ricondiviso questo.

Russia may ban the “6-7” meme because of.... national security 🤣

absatz.media/news/163478-v-ros…

reshared this

in reply to Catalin Cimpanu

the given train of thought described in the article is along the lines of: This and similar "brain rot" trends are significantly disrupting the education system which has potential for significant long-term consequences

While that seems like a reasonable concern, I suspect this being a western trend, and kids not being unquestioningly obedient are the real concerns driving this 🤷‍♂️

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The Polish government has advised officials to replace Signal with its national secure messenger platform mSzyfr: gov.pl/web/baza-wiedzy/rekomen…

mSzyfr release presser: gov.pl/web/baza-wiedzy/komunik…

This comes after Russian hackers have launched major Signal phishing operations this year.

reshared this

Lorenzo ha ricondiviso questo.

GitHub says it has no problems with security researchers using AI to find bugs in its service, but it has a problem with researchers filing bad reports that haven't been validated, are extra-verbose and long, and don't contain steps to reproduce and a proof-of-concept.

Basically, KISS!

github.blog/security/raising-t…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

After a joint PAN and RH-ISAC report, the BlackFile group has shut down its dark web leak site

Per Google, the group has the same tactics as ShinyHunters, but is a separate operation

rhisac.org/threat-intelligence…

cloud.google.com/blog/topics/t…

reshared this

Lorenzo ha ricondiviso questo.

Some new exploitation waves:

-NGINX Rift bug: linkedin.com/feed/update/urn:l…

-openDCIM, data center software: linkedin.com/posts/ccondon_cyb…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

VulnCheck has noted a common trend this year, with new CVEs exploding for some vendors, a clear sign of more vulnerabilities being discovered with the help of AI tools

vulncheck.com/blog/ai-assisted…

reshared this

in reply to Catalin Cimpanu

Not that it’s the *most* reliable indicator, but a similar trend is evident in what I see on vuln garden. This year we have 83 “named vulns” and we’re not even half way through the year. This pace could see 200+ while no year prior has ever gone over 130. It also seems like a majority of findings coming out recently are from AI shops (V12, those copyfail buggers, xbox, etc…)
in reply to Paolo Redaelli

@Paolo Redaelli le alternative sono generalmente sprovviste di tutte le caratteristiche enterprise: prova tu a spostare una VM sul cloud di Azure o di AWS con "le alternative" oppure prova a spostare una macchina virtuale accesa da un server a un altro senza avere VMWare e poi fammi sapere che succede

E poi se vuoi gestire un sistema aziendale con un tecnico certificato, puoi andare solo su VMWare. C'è anchee Virtualbox ma malgrado è di Oracle sta ancora a qualche parsec di distanza dall'usabilità business

in reply to Lorenzo

noto solo ora che in quella lista manca #ProxMox @proxmox che mi pare sia il concorrente libero, **con supporto commerciale** più adatto al mondo aziendale (qui un confronto stackscale.com/blog/vmware-vs-… )
Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

The THORChain DeFi platform suspended crypto trading after hackers stole $10.7m worth of assets on Friday

The hack involved a complex exploit that leaked private key material over time

The attackers reconstructed the private key and drained one of THORChain's wallets

x.com/THORChain/status/2055376…

reshared this

Rilasciato Shelly 2.3 migliora il package manager alternativo per Arch Linux

@GNU/Linux Italia

linuxeasy.org/rilasciato-shell…

Shelly 2.3 migliora il package manager per Arch Linux con prestazioni superiori, supporto traduzioni e gestione avanzata di AUR e Flatpak.
L'articolo Rilasciato Shelly 2.3 migliora il package manager alternativo per Arch Linux proviene da Linux Easy.
E'

Lorenzo ha ricondiviso questo.

Grafana has disclosed a hack of its GitHub repos and extortion attempt.

They mention an FBI alert about not paying the hackers. The FBI sent one last week about ShinyHunters, so I presume it's them

bsky.app/profile/grafana.bsky.…

Questa voce è stata modificata (6 giorni fa)

reshared this

Wine 11.9 migliora il supporto Wayland per i giochi Windows su Linux

@GNU/Linux Italia

linuxeasy.org/wine-11-9-suppor…

Wine 11.9 migliora il gaming Linux su Wayland con nuovo supporto cursori, fix per giochi Windows e maggiore compatibilità software.
L'articolo Wine 11.9 migliora il supporto Wayland per i giochi Windows su Linux proviene da Linux Easy.

BleachBit aggiunge una TUI interattiva ideale per server Linux

@GNU/Linux Italia

linuxeasy.org/bleachbit-tui-in…

BleachBit introduce una nuova interfaccia TUI interattiva per Linux, ideale per server headless e sistemi leggeri senza ambiente grafico.
L'articolo BleachBit aggiunge una TUI interattiva ideale per server Linux proviene da Linux Easy.
E' vietato riprodurre

Debian 13.5 Trixie Rilasciato con oltre 100 fix di sicurezza

@GNU/Linux Italia

linuxeasy.org/debian-13-5-trix…

Debian 13.5 aggiorna Trixie con 103 fix di sicurezza e 144 correzioni di stabilità per server, desktop e infrastrutture Linux.
L'articolo Debian 13.5 Trixie Rilasciato con oltre 100 fix di sicurezza proviene da Linux

bomby reshared this.

Lorenzo ha ricondiviso questo.

Exclusive: Fast16 malware has raised questions about what it was designed to do. Researchers at Symantec finally confirm it was subverting software used to simulate nuclear weapons explosions. Nuclear experts also tell me Iran was the likely target and explain how it impacted nuclear weapons tests. Fast16 wasn't aimed at sabotaging nuclear weapons themselves, but was only designed to alter data being fed to engineers from software used to simulate nuclear explosions tests. The goal was to trick engineers into believing their tests were failing to create confusion and slow down weapons program. Fast16 and Stuxnet were similar in that they both fed false data to engineers. But Stuxnet also physically altered centrifuges while tricking engineers into believing the devices were fine. New analysis from me also shows the two codes were contemporaneous, not separated by years.

Here's my story, which contains a link to a timeline showing how they were being developed around the same time, likely as part of a multi-pronged operation to slow down Iran's nuclear program.

zetter-zeroday.com/experts-con…

BudsLink porta i controlli avanzati di AirPods e Galaxy Buds su Linux

@GNU/Linux Italia

linuxeasy.org/budslink-control…

BudsLink porta su Linux controlli avanzati per AirPods, Galaxy Buds, Sony e Nothing con gestione ANC, batteria e gesture.
L'articolo BudsLink porta i controlli avanzati di AirPods e Galaxy Buds su Linux proviene da Linux

Double Xeon reshared this.

KDE Plasma 6.7 porta Bigscreen nel salotto

@GNU/Linux Italia

linuxeasy.org/kde-plasma-6-7-p…

KDE Plasma 6.7 porta Bigscreen su Linux con un’interfaccia ottimizzata per TV, controller e mini PC da salotto.
L'articolo KDE Plasma 6.7 porta Bigscreen nel salotto proviene da Linux Easy.
E' vietato riprodurre questo articolo senza autorizzazione.
Questo feed RSS è

Tdarr Server automatizza la gestione delle librerie video

@GNU/Linux Italia

linuxeasy.org/tdarr-server-aut…

Tdarr Server automatizza transcodifica, controllo e gestione delle librerie video con nodi distribuiti, GPU, FFmpeg e HandBrake.
L'articolo Tdarr Server automatizza la gestione delle librerie video proviene da Linux Easy.
E' vietato riprodurre

Lorenzo ha ricondiviso questo.

Presentata la nuova piattaforma digitale dedicata ai “Portatori di Interesse”


La nuova piattaforma nasce con l’obiettivo di rendere totalmente trasparente la Difesa. In prospettiva, infatti, il Ministero potrà diventare una delle principali stazioni appaltanti del Paese e, proprio per questo, è fondamentale garantire regole chiare, correttezza e pari opportunità per tutti. Abbiamo la necessità che ogni rappresentante delle Forze Armate possa interagire con qualsiasi azienda, offrendo a tutti le stesse possibilità di proporre idee, progetti e soprattutto innovazioni tecnologiche. Allo stesso tempo, vogliamo assicurarci che ogni rapporto avvenga nel segno della trasparenza, dell’onestà e della legalità. Per questo abbiamo scelto di registrare e tracciare ogni contatto con la Difesa: uno strumento che da un lato consente di filtrare eventuali soggetti non affidabili, dall’altro tutela il nostro personale, permettendo a chi lavora nelle nostre strutture di operare con serenità. La piattaforma vuole inoltre incoraggiare tutte quelle aziende che non hanno mai collaborato con la Difesa, ma che possiedono idee innovative e competenze strategiche, a farsi avanti e a proporre il proprio contributo.

difesa.it/primopiano/presentaz…

@politica

reshared this

Telefono Protetto punta sulla prevenzione delle truffe digitali su Android

@GNU/Linux Italia

linuxeasy.org/telefono-protett…

Telefono Protetto aiuta a individuare SMS sospetti e truffe digitali con analisi intelligente di notifiche e messaggi Android
L'articolo Telefono Protetto punta sulla prevenzione delle truffe digitali su Android

Double Xeon reshared this.