Adform compromised to serve crypto stealer via supply chain attack
Large web advertising firm serving crypto wallet stealer and C2 beacon traffic.Kevin Beaumont (Medium)
reshared this
Large web advertising firm serving crypto wallet stealer and C2 beacon traffic.Kevin Beaumont (Medium)
reshared this
Dolphin si arricchisce con un menu contestuale per convertire PDF, immagini, audio e video
linuxeasy.org/dolphin-si-arric…
Un nuovo menu contestuale per Dolphin su KDE Plasma 6 aggiunge conversione di PDF, immagini, audio, video, ebook e documenti
📺 Srsly Risky Biz: Chipping away at Chinese AI risks
risky.biz/video/srsly-risky-bi…
Tom Uren and James Wilson talk about open-weight AI models and distillation. These topics have been subject to a lot of US government atte [Read More]risky.biz
reshared this
SpeakoFlow potente assistente vocale open source che porta l’IA direttamente su Linux
linuxeasy.org/speakoflow-poten…
SpeakoFlow è un assistente vocale open source che trasforma la voce in testo su Linux con trascrizione locale, IA personalizzabile e funzioni
GNOME 50.3 migliora desktop remoto, prestazioni e accessibilità su Linux
linuxeasy.org/gnome-50-3-migli…
GNOME 50.3 migliora stabilità, accessibilità e prestazioni con accelerazione hardware per il desktop remoto su GPU AMD e numerose correzioni
GOG Galaxy arriva ufficialmente su Linux: lo sviluppo è iniziato
linuxeasy.org/gog-galaxy-arriv…
GOG conferma lo sviluppo ufficiale di Galaxy per Linux: il celebre launcher offrirà funzioni avanzate come salvataggi cloud, aggiornamenti automatici e obiettivi
Tommi reshared this.
COSMIC Desktop 1.5 migliora scaling di Chromium, sfondi e stabilità del sistema
linuxeasy.org/cosmic-desktop-1…
COSMIC Desktop 1.5 migliora il supporto allo scaling per Chromium, amplia la gestione degli sfondi e introduce numerose correzioni per stabilità e prestazioni.
Shelly 3.0 rinnova il gestore pacchetti per Arch Linux con una nuova base in Zig
linuxeasy.org/shelly-3-0-rinno…
Shelly 3.0 rinnova il gestore pacchetti per Arch Linux con codice Zig, nuova GUI GTK4, miglioramenti AUR e supporto Flatpak
Grayslate il blocco note intelligente per sviluppatori e analisti di dati
linuxeasy.org/grayslate-il-blo…
Grayslate, l'app open source per trasformare testo, JSON e CSV con oltre 80 strumenti integrati, disponibile anche per Linux
Zuno il client desktop open per YouTube Music disponibile anche su Linux
linuxeasy.org/zuno-il-client-d…
Zuno, il client desktop open source per YouTube Music per Linux, Windows e macOS con download offline, testi sincronizzati e tante funzioni avanzate
We just released Mastodon 4.6.4, 4.5.14 and 4.4.21.
Those updates include multiple security fixes, including fixes for two major issues.
We encourage server administrators to update as soon as possible, as one of the issues can expose PII of local users. We are investigating potential uses of this exploit and will soon share more information.
Full release notes and update instructions are available on the GitHub release page.
github.com/mastodon/mastodon/r…
Upgrade overview This release contains upgrade notes that deviate from the norm: ℹ️ Requires assets recompilation For more information, view the complete release notes and scroll down to the upgrad...GitHub
reshared this
like this
reshared this
Carlos Solís likes this.
reshared this
reshared this
Open Archiver la piattaforma open per archiviare e ricercare email in modo sicuro
linuxeasy.org/open-archiver-la…
Open Archiver, la piattaforma open source per archiviare email in locale con ricerca avanzata, crittografia e installazione semplice tramite Docker
HuggingFace incident report:
huggingface.co/blog/agent-intr…
The report itself reeks of LLM slop with gems like the "kill chain", consisting of phases like recon, exfil, c2...and k8s 😀 Nuances are overemphasized (like how code execution was used to execute code) while important steps are blurry (e.g. they had some kind of "allowlist" in the dataset processor, that allowed everything which didn't look like a URL?).
I feel sorry for blue teams not because they'll have to respond to more incidents but because they'll have to wade through reports like this...
We’re on a journey to advance and democratize artificial intelligence through open source and open science.Hugo Larcher (Hugging Face)
reshared this
🎙️ Risky Business #846 -- OpenAI built a fireplace out of wood
On this week’s show special guest co-host Pete Ranks, the former director of the CIA's Centre for Cyber Intelligence, joins Patrick Gray a [Read More]risky.biz
reshared this
Warning: A few hours after this post, the user NetscapeNavigator was suspended from the Vivaldi instance
I've been vilely attacked in the past, with reports and private messages, simply for writing this
We don't deserve to be bombarded by thousands of tragic requests for help that we can't directly verify and that prey on our pity, or worse, our guilt.
Sending private messages is harassment. Sending private messages asking for money is even more odious, because we know that sooner or later, someone vulnerable will donate.
A mastostar, a guy with 47,000 followers who passes for a prominent figure in the Fediverse, told me I'm "just a hugely privileged twat throwing his toys out of the pram because he is being forced to see things he’d rather ignore" and that perhaps I lack a moral compass.
I imagine if I've been subjected to harassment for saying something trivial, poor @NetscapeNavigator@vivaldi.net will be subjected to harassment, stalking, doxxing, and multiple reports to force him to close his account.
But what did Netscape write?
Here's his message before it was deleted:
My annoyance with the Fediverse is all the scammers.
I do not suspect they're scammers — I know they're scammers, because they're using the same photos as the next person. I also have the unique perspective from my job where I deal with this sort of thing professionally (I work for Meta/Facebook).
Some of them are not just staged or stock photos, but even A.I. photos too. Honestly, I always get a small laugh when I see the old photo re-shared with 6 fingers. The stupid scammers are so low-effort here that I doubt they noticed, and I doubt they care. Like all scammers, they want your money quick and easy. Which is why they often re-share the same photos and videos among themselves.
They use both a repeated heart-bleeding story to tug at people's sympathy, but the reason why they repeat themselves is volume. They're not so much trying to convince people as they are hoping to flood timelines so someone who is more gullible and who wears their heart on their sleeve will act and give them money.
It is the same marketing tactic corporations use. You see an ad repeated for a soda, and become thirsty, and if you happen to buy their soda, all the better. Just as the scammers repeat their heartfelt story over and over, and you feel sorry, and if you happen to pay them, all the better.
If there is substance, it always circles back to the scam.
A normal person may post a photo of their home and ask for tips on decorating or point out how cool the new couch looks in their living room. The scammer will point out the couch and claim it's too bad they have to sell it or no longer have it, but it would be better if you gave them money.
A normal person may post a photo of their spouse and children, talking about how proud they are of them or how lucky they feel to have them in their life. The scammer will claim they love their spouse and kids, but it would be better if they had your money.
Everything circles back to needing your money. Everything reinforces the scam.You're unlikely to see content that does not circle back to wanting and needing your money.
Objectively, @NetscapeNavigator@vivaldi.net's accusation is not supported by evidence. I'd love to see a dossier from Netscape or a post from @iftas, or even better, a journalistic investigation, but nothing of the sort currently exists.
But what is the verification method for "GazaVerified"? Here it is:
What does the verification process look like?
It’s very simple: we have a quick video chat to verify that you are a Palestinian from Gaza and the same person you say you are on your Mastodon account, after which we add you to Gaza Verified.
A damn video call? Is this the verification method for a fundraising system that moves hundreds of thousands of euros? In an environment heavily influenced by a terrorist organization like Hamas? And so with the risk that donors could be accused of financing a terrorist organization? And with another terrorist organization (the Israeli government) eager to infiltrate the donation request system?
It seems to me like the perfect recipe for creating a gigantic explosive backpack to blow yourself up inside four reinforced concrete walls...
infosec.exchange/@NetscapeNavi…
We’ve personally had video conversations on Signal with the people from Gaza whose Mastodon accounts on the fediverse are listed here and we verify that their accounts are genuine. – Joy & Aral Balkangaza-verified.org
like this
reshared this
reshared this
TUI Calculator la calcolatrice scientifica avanzata che porta la matematica visiva nel terminale
linuxeasy.org/tui-calculator-l…
Calcolatrice scientifica avanzata per il terminale ispirata a Casio. Scritta in Rust con Ratatui, supporta
russia’s FSB reported bringing charges against Telegram founder Pavel Durov for facilitating terrorist activity and placing him on the international wanted list.
According to the security service, the administration of the messaging app fails to delete channels and bots that, according to the russian side, are used to coordinate terrorist attacks and acts of sabotage in russia.
en.interfax.com.ua/news/genera…
Russia’s FSB reported bringing charges against Telegram founder Pavel Durov for facilitating terrorist activity and placing him on the international wanted list.Interfax-Ukraine
reshared this
Publii il CMS statico open source che punta su sicurezza, velocità e privacy
linuxeasy.org/publii-il-cms-st…
Publii è un CMS statico open source che permette di creare siti web veloci, sicuri e orientati alla privacy senza database o server complessi
AuraScan porta un controllo avanzato della sicurezza per AUR
linuxeasy.org/aurascan-porta-u…
AuraScan aiuta gli utenti Arch Linux a individuare pacchetti sospetti, analizzare aggiornamenti e prevenire problemi prima dell'installazione.
Joe Vinegar 🏳️🌈 reshared this.
Docking il dock open per Linux con supporto Wayland e oltre 60 applet
linuxeasy.org/docking-il-dock-…
Docking è un dock open source per Linux ricco di funzionalità, compatibile con X11 e Wayland e dotato di oltre 60 applet integrate
Visor il boot manager UEFI open source che punta su velocità e semplicità
linuxeasy.org/visor-il-boot-ma…
Visor è un nuovo boot manager UEFI open source leggero, veloce e moderno con supporto a Secure Boot, snapshot Btrfs e rilevamento automatico.
KDE Plasma 6.8: sicurezza RDP automatica e nuovi strumenti per il display
linuxeasy.org/kde-plasma-6-8-s…
KDE Plasma 6.8 è in arrivo e porta con sé un bagaglio di novità pensate sia per chi lavora in remoto sia per gli utenti desktop più esigenti.
Rox il player musicale in Rust che raccoglie l’eredità di Foobar2000
linuxeasy.org/rox-il-player-mu…
Rox è un nuovo lettore musicale open source in Rust ispirato a Foobar2000, progettato per gestire grandi librerie locali con prestazioni elevate.
FireDragon 13 rivoluziona il browser con una nuova architettura
linuxeasy.org/firedragon-13-ri…
FireDragon 13 rinnova completamente il browser con una nuova base di codice, più privacy, migliori prestazioni e nuove opzioni di configurazione.
I will remind you that OpenAI is worth nearly $1,000,000,000,000.
The going rate for an engineer that knows how to secure a website is $166,000/year.
reshared this

reshared this
FreeCAD 1.1.3 risolve vulnerabilità critiche e migliora stabilità e prestazioni
linuxeasy.org/freecad-1-1-3-ri…
FreeCAD 1.1.3 corregge importanti vulnerabilità di sicurezza e numerosi bug. Aggiornamento consigliato per tutti gli utenti.Stai leggendo FreeCAD 1.1.3 risolve
Writeup of the openai attack on HuggingFace via @campuscodi
Key points
- access to source: OSS code, trivially decompiled JAR files,... allows for the LLMs to perform offline searches for vulnerabilities at scale. Then, when the goal "solve this problem" could only be met by attacking an external company, it did.
Interesting hypothesis that part of the attack may have involved supplying malicious artifacts to other systems to get them to run your exploit. This is why package managers must require signed artifacts & build tools must check them
hacktron.ai/blog/here-is-how-o…
OpenAI and Hugging Face probably won’t tell us exactly how the whole incident unfolded. But using publicly available data, we can reconstruct what likely happened.s1r1us (Hacktron AI)
reshared this
reshared this
Faugus Launcher 2.0 migliora il gaming su Linux con GTK4, AppImage e supporto GOG Galaxy
linuxeasy.org/faugus-launcher-…
Faugus Launcher 2.0 porta GTK4, AppImage, supporto GOG Galaxy e tante novità per avviare giochi Windows e Linux con ProtonStai leggendo
YTSage il downloader YouTube con interfaccia grafica intuitiva
linuxeasy.org/ytsage-il-downlo…
YTSage, il downloader moderno per YouTube su Linux con supporto a video, audio, sottotitoli, playlist e guida completa all'installazione.
Stai leggendo YTSage il downloader YouTube con interfaccia grafica
K3L3V®∆ reshared this.
Lumalarm la sveglia intelligente che riattiva automaticamente il PC
linuxeasy.org/lumalarm-la-sveg…
Lumalarm è una sveglia per Linux che riattiva automaticamente il PC dalla sospensione e offre funzioni avanzate per evitare di riaddormentarsi.Stai leggendo Lumalarm la sveglia intelligente che
MusicGrabber: il servizio self-hosted che automatizza il download e l’organizzazione della musica
linuxeasy.org/musicgrabber-il-…
MusicGrabber è una piattaforma self-hosted per scaricare musica da più fonti, organizzare la libreria e
On Air porta radio, podcast e streaming avanzato su KDE
linuxeasy.org/on-air-porta-rad…
On Air è un widget per KDE Plasma 6 che porta radio online, podcast, registrazioni e streaming avanzato in un'unica interfaccia modernaStai leggendo On Air porta radio, podcast e streaming avanzato su KDE, un articolo del blog Linux
Debian apre il dibattito sull’intelligenza artificiale: vietare o regolamentare i contributi?
linuxeasy.org/debian-apre-il-d…
Debian discute una proposta per vietare o regolamentare i contributi realizzati con strumenti di intelligenza artificiale
ArDali WebMedia riunisce browser Chromium, audio professionale e strumenti multimediali
linuxeasy.org/ardali-webmedia-…
ArDali WebMedia unisce browser Chromium, strumenti multimediali avanzati, gestione password e audio professionale in un'unica
Fedora 45 prepara importanti novità per crittografia, bootloader e strumenti di sviluppo
linuxeasy.org/fedora-45-prepar…
Fedora 45 prepara importanti novità per sicurezza e avvio del sistema con modifiche alla crittografia del kernel, un nuovo GRUB
Ubuntu Touch 24.04-2.0 migliora il browser e stampa
linuxeasy.org/ubuntu-touch-24-…
Ubuntu Touch 24.04-2.0 aggiorna Morph Browser a Chromium 134, aggiunge la stampa, migliora Lomiri e amplia il supporto ai dispositivi.Stai leggendo Ubuntu Touch 24.04-2.0 migliora il browser e stampa, un articolo del blog Linux Easy. Non
Kevin Beaumont
in reply to Kevin Beaumont • • •(function(){var A=window.Adform=window.Adform||{};var aa=Object.prototype.toStri - Pastebin.com
PastebinKevin Beaumont
in reply to Kevin Beaumont • • •I didn't cover it in the blog but it does an amusing thing where aside from hijacking the clipboard, it also rewrites browser forms already filled in to change wallet addreses, lol. So if you browse an autofill form it replaces that too.
One of the big crypto firm execs sits on Adform's executive, I think they may have been hit in the incident by this.
Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Attempt to get Adform to admit it, LinkedIn tag edition
Ian Campbell 🏴
in reply to Kevin Beaumont • • •i know this will shock you but Russia looks involved.
vk-proxy[.]com active on that IP
also a Lithuanian VPS service transiting through the Netherlands, cherryservers[.]net
Ian Campbell 🏴
in reply to Ian Campbell 🏴 • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Admore have finally admitted they were hacked:
site.adform.com/resources/news…
Security Incident - Adform
site.adform.comKevin Beaumont
in reply to Kevin Beaumont • • •To clarify a few things:
"Based on our investigation to date, we have found no evidence that the malicious code transmitted users’ IP addresses or information about the websites they visited to an external party. Technical analysis indicates that such transmission may have been possible, and this aspect remains under investigation." <- It did. The code for it is in my blog.
Cav
in reply to Kevin Beaumont • • •Duncan Bayne
in reply to Kevin Beaumont • • •fuzzyfuzzyfungus
in reply to Kevin Beaumont • • •We can only hope that this might, for someone somewhere, move the needle on "adblocking is untrusted code restriction, which is security".
That's one area where, stubbornly, running untrusted and untrustworthy code is treated as some sort of respectable obligation, even by outfits that are otherwise at least somewhat buttoned down about execution.
ninkosan
in reply to Kevin Beaumont • • •Max Maass
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Max Maass • • •Rasmus Kaj 🎼🦀
in reply to Kevin Beaumont • • •If they are serving malicious code and haven't told people they've been hacked, we should assume they are knowingly serving the malicious code.
It's not that different from their core business.
Graham Sutherland / Polynomial
in reply to Kevin Beaumont • • •Kevin Beaumont
Unknown parent • • •I’m Adform Famous on LinkedIn
Kevin Beaumont
in reply to Kevin Beaumont • • •Interesting catch by @zackwhittaker - although we don't know the number of people impacted by the Adform breach has they haven't commented, Adform say they serve 1.5 billion adverts a day, and the breach lasted at least 5 days.
Pretty compelling reason to use an adblocker.
reshared this
Poujol 𝖱u𝗌𝗍 ✅ reshared this.
Kevin Beaumont
Unknown parent • • •Veikkaus, a Finnish government-owned betting agency which holds a monopoly in the country, has informed customers their cryptocurrency may have been stolen as they use Adform.
voice.fi/ilmiot/veikkauksen-ve…
Veikkauksen verkkosivuilla ollut haittakoodia – "lottokansan" tulee tehdä nyt näin
JT Tuomela (Voice.fi)Kevin Beaumont
in reply to Kevin Beaumont • • •Adform customers publishing advisories to their customers.. will be interesting to see which companies don’t bother to tell anybody.
Rairii
in reply to Kevin Beaumont • • •Jukka Niiranen
in reply to Kevin Beaumont • • •When opening the app for 2nd biggest retail group in Finland, Kesko, I saw a notification about Adform warning any users dealing with crypto. Just like Veikkaus, these are pretty huge audiences to get exposed to not just the malicious script but also awareness of a trusted consumer brand fucking things up on their computer because of ads.
#Kesko #KRuoka #Veikkaus #Adform #Finland