About
OSINTITALIA - HAckinBO Spring Edition 2025 - Writeup! /01
Writeup of the CTF challenge called 'Silent Signal' published for OSINTITALIA - HAckinBO Spring Edition 2025 event.
OSINTITALIA - HAckinBO Spring Edition 2025 - Writeup! /02
Writeup of the CTF challenge called 'Silent Signal' published for OSINTITALIA - HAckinBO Spring Edition 2025 event.
Direttiva CER: la resilienza diventa una funzione strategica dell’impresa
La direttiva CER introduce un nuovo modello europeo di resilienza che coinvolge board, security, risk management e compliance. Per i soggetti critici non si tratta solo di nuovi adempimenti, ma di ripensare la governance aziendale per gestire rischi sempre più interconnessi
Get your app to Mars!
This is a blog post about firmware updates, and I was inspired to write it by the news that NASA’s Curiosity rover on Mars has got an OTA update. The firmware image was about 21MB and took 11 days to send it over-the-air (or in this case, over-the-vacuum: Mars is currently 242 million kilometres from Earth).
Inferring the sender of a CAN frame
The latest update of the open source can2 protocol decoder is able to automatically infer the sender of a CAN frame. It uses the method of deterministic distortion of CAN signals that result in frames from a given node on the bus having consistently shortened or lengthened recessive pulses. The differences can be quite small - just 10 or 15 nanoseconds - but they can be picked up by a suitably accurate logic analyzer.
APTs Top the List of Most Active Threat Actors in H1 2026
Cyble breaks down the most active threat actors in H1 2026 as APTs dominate the global threat landscape, followed by ransomware and hacktivist groups.
Angelina Jolie, Robert De Niro Among Hollywood Stars Hit by Tribeca Data Leak
Tribeca Film Festival data breach reportedly exposed contact details linked to Angelina Jolie, Robert De Niro, Martin Scorsese and other.
Hackers used autonomous AI agent to spy on Thailand's finance ministry
Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution
A GitLab vulnerability in the Oj parser lets attackers exploit Jupyter Notebook files for remote code execution on affected GitLab versions.
84 Streams Later: Exploring the Evolution of Apple Biome in iOS
DFIR research
No Room For Compromise: How Business Email Protection Predicts BEC Before It Starts
Most business email compromise (BEC) attacks start with stolen credentials, not a malicious email. Group-IB uses threat intelligence to detect compromised accounts before attackers log in — predicting BEC before it starts.
TrickBot ora usa il DNS tunneling per nascondersi: come mitigare il rischio
Una variante dello storico malware TrickBot adotta nuove tecniche di evasione e il DNS tunneling come metodo di comunicazione con il server di comando e controllo, per consentire agli attaccanti di nascondere lo scambio di dati all’interno del normale traffico DNS. Ecco tutti i dettagli e i consigli per mitigare il rischio
Antivirus VPN: l’offerta Kaspersky con sconti fino al 65% e VPN illimitata
Antivirus con VPN: l'offerta di Kaspersky garantisce tantissimi servizi a un prezzo davvero molto conveniente, ecco come attivarla.
Sconto Avast: fino al 60% sull’antivirus e sui servizi di sicurezza digitale
Lo sconto Avast è interessante perché consente di risparmiare fino al 60% per l'antivirus: come attivare la promozione e i servizi inclusi.
Il chatbot elettorale sposta voti: ma alle urne il vero rischio è la manipolazione
L'indagine ha messo alla prova ChatGPT e Gemini, rilevando una distorsione sistematica nella visibilità dei partiti, mentre conversare con un chatbot elettorale sposta le preferenze di voto. Ecco tutti rischi di un chatbot elettorale, fra indicazioni di voto inaccurate e tentativi di manipolare le risposte generate automaticamente
AI Act: una normativa per tutti, ma con impatti rilevanti solo per pochi
A patto di regolamentare adeguatamente gli usi dell’AI in azienda, l’AI Act potrebbe essere molto meno impegnativo di quanto ci si aspetti, ma coinvolge tutte le organizzazioni. Ecco la reale portata e impegno richiesto da una normativa che riguarda tutti
Four Men Admit to $2.2M Medicaid Fraud Scheme Using ChatGPT
Minnesota Medicaid fraud case sees four men plead guilty after allegedly stealing $2.2 million and using artificial intelligence to fabricate records.
How the Gentlemen Ransomware Group Built a Multi-Region Attack Machine in H1 2026
The Gentlemen ransomware group expanded globally in H1 2026, targeting critical sectors across regions with aggressive double-extortion campaigns.
[Fix] download ssgdio64.sys - (enginefall, Battlefield, EA Anti-Cheat)
EA Anti-Cheat warns about "downloading" ssgdio64.sys while in reality you must disable/remove it. go in C:\Windows\SysWOW64\drivers and ...
GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.
Reverse engineering what HyperGuard monitors in ntoskrnl
A hands-on investigation of Secure Kernel Patch Guard, revealing which ntoskrnl pages, SSDTs, dispatch entries and control pointers Windows monitors from VTL1.
Se i chatbot fanno consulenza sull’aborto
Per fornire informazioni, i modelli linguistici attingono da un ecosistema di fonti dove autorevolezza e visibilità non sempre coincidono. E che le realtà pro-choice faticano a presidiare.
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers.
The hacker who humiliated spyware makers and was never caught
An awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher?
I Asked Claude for a Housing Map. It Gave Me a Gambling Site
Malicious sites use JavaScript to build malware in browser memory
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory.
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.
OpenAI confirms ChatGPT is down worldwide
ChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide.
Project ORBITAL
Introduction The modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Adv...