Direttiva CER: la resilienza diventa una funzione strategica dell’impresa
La direttiva CER introduce un nuovo modello europeo di resilienza che coinvolge board, security, risk management e compliance. Per i soggetti critici non si tratta solo di nuovi adempimenti, ma di ripensare la governance aziendale per gestire rischi sempre più interconnessi
This is a blog post about firmware updates, and I was inspired to write it by the news that NASA’s Curiosity rover on Mars has got an OTA update. The firmware image was about 21MB and took 11 days to send it over-the-air (or in this case, over-the-vacuum: Mars is currently 242 million kilometres from Earth).
The latest update of the open source can2 protocol decoder is able to automatically infer the sender of a CAN frame. It uses the method of deterministic distortion of CAN signals that result in frames from a given node on the bus having consistently shortened or lengthened recessive pulses. The differences can be quite small - just 10 or 15 nanoseconds - but they can be picked up by a suitably accurate logic analyzer.
No Room For Compromise: How Business Email Protection Predicts BEC Before It Starts
Most business email compromise (BEC) attacks start with stolen credentials, not a malicious email. Group-IB uses threat intelligence to detect compromised accounts before attackers log in — predicting BEC before it starts.
TrickBot ora usa il DNS tunneling per nascondersi: come mitigare il rischio
Una variante dello storico malware TrickBot adotta nuove tecniche di evasione e il DNS tunneling come metodo di comunicazione con il server di comando e controllo, per consentire agli attaccanti di nascondere lo scambio di dati all’interno del normale traffico DNS. Ecco tutti i dettagli e i consigli per mitigare il rischio
Il chatbot elettorale sposta voti: ma alle urne il vero rischio è la manipolazione
L'indagine ha messo alla prova ChatGPT e Gemini, rilevando una distorsione sistematica nella visibilità dei partiti, mentre conversare con un chatbot elettorale sposta le preferenze di voto. Ecco tutti rischi di un chatbot elettorale, fra indicazioni di voto inaccurate e tentativi di manipolare le risposte generate automaticamente
AI Act: una normativa per tutti, ma con impatti rilevanti solo per pochi
A patto di regolamentare adeguatamente gli usi dell’AI in azienda, l’AI Act potrebbe essere molto meno impegnativo di quanto ci si aspetti, ma coinvolge tutte le organizzazioni. Ecco la reale portata e impegno richiesto da una normativa che riguarda tutti
GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.
Reverse engineering what HyperGuard monitors in ntoskrnl
A hands-on investigation of Secure Kernel Patch Guard, revealing which ntoskrnl pages, SSDTs, dispatch entries and control pointers Windows monitors from VTL1.
Per fornire informazioni, i modelli linguistici attingono da un ecosistema di fonti dove autorevolezza e visibilità non sempre coincidono. E che le realtà pro-choice faticano a presidiare.
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers.
The hacker who humiliated spyware makers and was never caught
An awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher?
Malicious sites use JavaScript to build malware in browser memory
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory.
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.
ChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide.
OnTrac notifies customers of data breach after network hack
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers.
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance.