Seenthis
•
 
Identifiants personnels
  • [mot de passe oublié ?]

 
  • #s
  • #se
  • #sec
  • #sécu
RSS: #security

#security

  • #security'
  • #security_
  • #security-
  • #securitythreat
  • #securityaffairs
  • #securitycouncil
  • #securityculture
  • #security.asymmetric
0 | 25 | 50 | 75 | 100 | 125 | 150 | 175 | 200 | ... | 475
  • @oanth_rss
    oAnth_RSS @oanth_rss via RSS CC BY 15/06/2026

    #OMG, Russian #propaganda is telling the #truth, and we’re all bein...
    ▻https://diaspora.psyco.fr/p/12535322

    #OMG, Russian #propaganda is telling the #truth, and we’re all being monitored by the #NSA.

    source: united24media.com/investigatio…

    The report, aired on the Russian state-owned Rossiya-1 television channel, alleges that companies including #Microsoft, #Apple, and #Google are operating in partnership with the US National #Security Agency (NSA) and the #FBI to compromise the #mobile devices of high-ranking government figures, ...

    Poor #Snowden is now stuck in #Russia for telling the #world the truth about the U.S. #surveillance program.

    #fsb #news #policestate #bigtech #propaganda #fnord #newspeack #whistleblower #cybersecurity #tracking #bigdata #bigbrother #orwell #spy #secretservice #intelligence #usa #worldorder #prtivacy #society #ethics #smartphone

    oAnth_RSS @oanth_rss via RSS CC BY
    Écrire un commentaire
  • @omgubuntu
    OMG ! Ubuntu ! @omgubuntu via RSS CC BY 13/05/2026

    Downloaded Cemu for Linux recently? You may have #malware
    ▻https://www.omgubuntu.co.uk/2026/05/cemu-linux-malware

    If you recently downloaded the Cemu emulator for Linux from the project’s GitHub, be aware: it may have added malware to your system. The team behind the Wii U emulator discovered that both Linux builds of Cemu 2.6 on Github, the #AppImage and a standalone Ubuntu 22.04 ZIP, were “compromised”. Cemu’s Flatpak was not affected, nor were the GitHub installers for Windows and macOS. If you downloaded the Cemu 2.6 AppImage or Ubuntu 22.04 ZIP from the project’s GitHub, or used a third-party launcher that pulls from there, between 6 May and 12 May, 2026, you may have a compromised build. If […] You’re reading Downloaded Cemu for Linux recently? You may have malware, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.

    #News #Gaming #security

    OMG ! Ubuntu ! @omgubuntu via RSS CC BY
    Écrire un commentaire
  • @oanth_rss
    oAnth_RSS @oanth_rss CC BY 10/05/2026

    Will Italy be left without American protection?

    via ▻https://diaspora.psyco.fr/p/12458112

    ▻https://eu.eot.su/2026/05/09/will-italy-be-left-without-american-protection

    (lien mal vu par les médias occidentaux)

    oAnth_RSS @oanth_rss CC BY
    • @02myseenthis01
      oAnth @02myseenthis01 CC BY 10/05/2026

      cf. aussi:

      Italy Suspends Defense Cooperation with Israel Amid Rising Political Tensions

      military.com - 2026-05-02

      ici: ►https://seenthis.net/messages/1171636

      oAnth @02myseenthis01 CC BY
    • @02myseenthis01
      oAnth @02myseenthis01 CC BY 10/05/2026

      eu.eot.su - 2026-05-09

      #Trump and Meloni ’s quarrel could become the beginning of a revision of #security guarantees in #Europe.

      The geopolitical landscape of Europe is on the verge of major changes. The era of unconditional American security guarantees, which the Old World has grown accustomed to over the decades following the end of the Cold War, may come to an end. #Washington ’s harsh “America first” rhetoric is threatening the established architecture of #NATO. According to the Italian news agency ANSA, following the high-profile decision to withdraw thousands of American troops from Germany, Italy and Spain have also come under the close scrutiny of US President Donald Trump.

      For Rome, the implementation of such a scenario means not just a technical redeployment of allied troops, but a major challenge to national security and a deep crisis in relations with its main overseas partner. And while previously the main US complaints were about financial issues, today the catalyst for a possible rupture has become an open conflict between Trump and Italian Prime Minister Giorgia Meloni over the war in the #Middle_East.

      To fully assess the scale of the possible consequences, it is necessary to evaluate how deeply US military presence is integrated into Italy’s defense structure. Today, between 12,000 and 13,000 American soldiers, officers, and technical personnel are permanently stationed on the Apennine Peninsula and Sicily. In terms of the size of the American contingent, Italy is one of the key strongholds of the #Pentagon in Europe, second only to Germany. The American presence strengthens the overall air and missile defense system of NATO on the southern flank. Independently replacing this entire complex of capabilities would require Rome and its European allies many years and large investments.

      The United States operates a number of critically important facilities here. First, there is #Aviano Air Base in the north of the country, which hosts F-16 fighter jets and, according to military experts, stores tactical nuclear weapons. Second, there is #Vicenza Base (Caserma Ederle), serving as the headquarters of the US Army garrison in Southern Europe. The strategic hub of Camp Darby near Livorno is one of the largest logistics centers and weapons depots of the US Army abroad. Finally, the naval air station at Sigonella in Sicily is de facto the “eyes and ears” of NATO in the #Mediterranean, playing a vital role in operations in the Middle East and North Africa. The command of the US Sixth Fleet is also based in Naples. The withdrawal or even partial reduction of these forces would create a gaping hole in the southern flank of the North Atlantic Alliance.

      Until the spring of 2026, Giorgia Meloni was considered one of the main allies of American conservatives in Europe. However, in April, relations sharply deteriorated. The trigger was the US-Israeli military campaign against Iran, which Italy categorically refused to support.

      The crisis unfolded on several fronts at once and was accompanied by unprecedentedly harsh rhetoric, which is completely unacceptable to Trump with his ego:

      – Italy’s denial of access to bases. According to Corriere della Sera, Rome refused American bombers permission to transit through the Sigonella base before their deployment to the Middle East. The Italian side argued that landing aircraft carrying weapons required parliamentary approval, for which the US left no time.

      - Defense of the Vatican. Trump publicly attacked Pope Leo XIV, calling him “weak” for his calls for a peaceful resolution of the Middle East conflict. In response, Meloni harshly condemned the US president’s words, calling them unacceptable and expressing full solidarity with the pontiff.

      – Suspension of pacts with #Israel. Rome froze the defense agreement with Israel, demonstratively distancing itself from military escalation.

      – Washington’s response was not long in coming. In an interview with the Italian press, Trump became personal, insulting Meloni: “I’m shocked by her. I thought she had courage, but I was wrong. Iran would blow up Italy in two minutes if it had the chance.“

      Later, on his Truth Social network, Donald Trump delivered a final verdict on allied commitments: “Italy did not come to our aid, and we will not come to its aid.“

      Rome’s Middle Eastern démarche fell on the fertile ground of Trump’s long-standing dissatisfaction with fiscal discipline in NATO. Washington’s basic requirement — to spend at least 2% of GDP on defense — was chronically unmet by Italy, which hovered around 1.4–1.5%. Only recently, largely by revising accounting methods, did Rome reach the threshold of 2%, remaining among the allies that barely meet the former NATO minimum.

      In the transactional logic of the White House, the picture is clear: Italy not only tries to save on its own security at the expense of American taxpayers, but also, at a critical moment, refuses to show loyalty by blocking the use of bases. For the Trump administration, this is sufficient political reason to threaten to reduce the contingent, punishing a recalcitrant ally.

      For the Italian prime minister, the situation has turned into a diplomatic trap. On the one hand, a rupture with the US threatens the country’s basic security. On the other hand, Meloni is constrained by strict domestic political limits.

      In Italy, anti-war sentiment has traditionally been strong. Directly dragging the country into a war with Iran would be political suicide for the government against the backdrop of an already difficult economic situation. Furthermore, Italian industry is critically dependent on energy supplies from the Middle East region. As Trump bluntly stated, Rome does not want to risk oil, believing the US will do all the work on its own. Defending the Pope was also the only correct move for Meloni in a Catholic country where the pontiff’s authority carries enormous weight.

      If Donald Trump’s threats move into the practical realm, the consequences will extend far beyond the Apennines. The current situation shows how much the European security model depends on the political will of Washington. For Rome, the US bases were part of a system of logistics, intelligence, air support, and allied planning that cannot be quickly replaced by its own forces.

      Therefore, a possible withdrawal of American troops could be a signal to the entire European Union: the former automaticity of American guarantees no longer works unconditionally. European countries will have to accelerate the creation of their own defense infrastructure, expand military budgets, and take on those functions that the US provided for decades. Whether a decision to withdraw troops will be reached will be shown in the coming weeks.

      #OTAN #États-Unis #Italie #sécurité

      oAnth @02myseenthis01 CC BY
    • @02myseenthis01
      oAnth @02myseenthis01 CC BY 11/05/2026

      cf. les billets d’ici:

      ►https://seenthis.net/messages/1171352

      oAnth @02myseenthis01 CC BY
    Écrire un commentaire
  • @omgubuntu
    OMG ! Ubuntu ! @omgubuntu via RSS CC BY 8/05/2026

    Ubuntu Snap Prompting Improvements
    ▻https://www.omgubuntu.co.uk/2026/05/ubuntu-snap-prompting-client-improved

    If you haven’t tried Ubuntu’s ‘Permission Prompting’ feature for a while, there’s more reason to do so in the latest release. Canonical’s Oliver Calder has shared an update on recent improvements to the #security feature, which sets out to “empower users” by letting them decide what software can access on the rest of the system at runtime rather than retrospectively. Android or iOS show similar prompts, with screen modals asking if you want to “allow Acme App to access the camera” and similar. Ubuntu’s app prompting effort is still an ‘experimental’ feature in 26.04 LTS, but is now said to […] You’re reading Ubuntu Snap Prompting Improvements, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.

    #News #Prompting_Client #Snap_Apps #Ubuntu_26.04_LTS

    OMG ! Ubuntu ! @omgubuntu via RSS CC BY
    Écrire un commentaire
  • @jluc1
    JLuc’s trucs @jluc1 16/04/2026
    2
    @jluc1
    @biggrizzly
    2

    La sécurité du web serait désormais entre les mains de l’AI / des LLMs ?

    Une étude récente montre qu’en y consacrant assez de temps et de tokens, et donc d’argent, les LLMs trouvent des failles qui permettent de cracker-pirater les logiciels et que plus on y consacre de token, plus les LLMs trouvent des failles. Normal, mais ce qu’il apparaît, c’est qu’avec le budget il n’y a pas de limite à cela.

    ▻https://arxiv.org/abs/2603.11214

    « None of the models given a 100M budget showed signs of diminishing returns. “Models continue making progress with increased token budgets across the token budgets tested,” »

    La « solution » pour les défenseurs, c’est donc de mettre des LLMs suffisamment de temps sur ces mêmes logiciels pour trouver ces bugs avant les attaquants, et les corriger. Suffisamment longtemps, en y consacrant suffisamment de tokens et d’argent, plus que les attaquants.

    C’est donc devenu une course à qui consacrera le plus de token.

    Le titre fait référence au proof of work : une stratégie qui demande aux utilisateurs (légitimes oui pas) de faire un calcul complexe afin de « prouver » leur bonne foi... ou leur motivation en tout cas.

    https://www.dbreunig.com/img/the_last_ones_chart.png

    ▻https://www.dbreunig.com/2026/04/14/cybersecurity-is-proof-of-work-now.html

    #security #llm #ia #course-a-l-echalotte #securité

    JLuc’s trucs @jluc1
    • @jluc1
      JLuc’s trucs @jluc1 17/04/2026

      ▻https://blog.discourse.org/2026/04/discourse-is-not-going-closed-source

      *Discourse is Not Going Closed Source*

      Cal.com just closed their source code, arguing AI has made open source too dangerous. After 13 years of building Discourse in public, we’re staying open. Here’s why.

      JLuc’s trucs @jluc1
    • @jluc1
      JLuc’s trucs @jluc1 15/05/2026

      ▻https://www.metabase.com/blog/strip-mining-era-of-open-source-security

      TL;DR: High volume, LLM-powered scanning for security vulnerabilities is going to uncover lots of security issues in anything with public source code.
      This all started a few months ago

      JLuc’s trucs @jluc1
    Écrire un commentaire
  • @omgubuntu
    OMG ! Ubuntu ! @omgubuntu via RSS CC BY 2/04/2026

    Ubuntu 26.04’s #sudo-rs gets a password feedback toggle
    ▻https://www.omgubuntu.co.uk/2026/04/sudo-rs-password-feedback-toggle

    Ubuntu 26.04’s sudo-rs now includes a keypress toggle for password feedback. Switch between visible asterisks and silent input without editing a config file. You’re reading Ubuntu 26.04’s sudo-rs gets a password feedback toggle, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.

    #News #security #Ubuntu_26.04_LTS
    ▻https://www.omgubuntu.co.uk/wp-content/uploads/2026/04/sudo-rs-feedback-tab-toggle.mp4

    OMG ! Ubuntu ! @omgubuntu via RSS CC BY
    Écrire un commentaire
  • @omgubuntu
    OMG ! Ubuntu ! @omgubuntu via RSS CC BY 28/03/2026

    #Ubuntu_26.10 could drop btrfs, ZFS and LUKS support from #GRUB
    ▻https://www.omgubuntu.co.uk/2026/03/ubuntu-grub-secure-boot-luks-changes

    Ubuntu engineers are debating ways to reduce the number of features present in the signed version of GRUB, the boot loader used on systems with #Secure_Boot enabled. Canonical engineer Julian Klode proposes dropping support for /boot on btrfs, HFS+, XFS and ZFS filesystems, alongside GRUB’s JPEG and PNG image parsers, ahead of Ubuntu 26.10. Apple partition table support, LVM volume handling, all software RAID except RAID 1 and, more controversially, LUKS-encrypted /boot partitions are also on the chopping block. Many of these features are said to be ‘inherited by Debian, but never tested in Ubuntu’. “The timing here is crucial”, Klode […] You’re reading Ubuntu 26.10 could drop btrfs, ZFS and LUKS support from GRUB, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.

    #News #encryption #security

    OMG ! Ubuntu ! @omgubuntu via RSS CC BY
    Écrire un commentaire
  • @biggrizzly
    BigGrizzly @biggrizzly CC BY-NC-SA 25/03/2026

    The #US #government just #banned #consumer #routers made outside the US
    ▻https://www.theverge.com/news/899172/fcc-foreign-router-ban

    The US claims #foreign-made routers pose #national #security risks.

    In December, the #Federal_Communications_Commission banned all future #drones made in #foreign #countries from being #imported into the #United_States, unless or until their #maker gets an #exemption. Now, the FCC has done the exact same for consumer #networking gear, citing “an unacceptable risk to the national security of the United States and to the safety and security of U.S. persons.”

    (...)

    But since the vast majority — if not all — consumer routers are manufactured outside the United States, the vast majority of future consumer routers are now banned. By adding all foreign-made consumer routers to its Covered List, the #FCC is saying it will no longer authorize their radios, which de facto bans new #devices from import into the country.

    (...)

    BigGrizzly @biggrizzly CC BY-NC-SA
    Écrire un commentaire
  • @oanth_rss
    oAnth_RSS @oanth_rss CC BY 21/03/2026
    1
    @02myseenthis01
    1

    #IEA: released today a rpt with demand side measures." -J Blas

    via ▻https://diaspora.psyco.fr/p/12350054

    ♲ Kim Perales - 2026-03-20 13:01:47 GMT

    “Seaborne Buffer🚨Runs Down Fast as #IranWar Drags On‼️The amount of oil stored at sea -a vital buffer for markets🚨 -is running down fast, as supply from the PG remains constrained for a 3rd week & buyers are forced to find quick alternatives.

    It’s a hoard that could shrink even more swiftly if the US advances a proposal to remove sanctions on sea.” Reuters

    ABOUT🚨1/3 OF WHAT’S LEFT IS IRANIAN.

    #IEA: released today a rpt with demand side measures." J Blas

    ►https://www.iea.org/reports/sheltering-from-oil-shocks
    (Pdf)

    #Oil #USPol

    oAnth_RSS @oanth_rss CC BY
    • @02myseenthis01
      oAnth @02myseenthis01 CC BY 21/03/2026

      Sheltering From Oil Shocks

      Measures to reduce impacts on households and businesses

      About this reportThe conflict in the #Middle_East has created the largest supply disruption in the history of the global oil market, due to the near halt in shipping traffic through the Strait of #Hormuz. The loss of supply is having significant impacts in global markets, pushing up prices for crude oil above $100/barrel, and leading to much higher prices for some refined products – notably #diesel, #jet_fuel and liquefied petroleum gas ( #LPG ). Concerns are growing about the impacts of higher prices on households, businesses and the broader economy.

      In this report, the #IEA details 10 demand-side options open to households, businesses and governments to shelter themselves from today’s oil shock and relieve the strains on affordability. These are based on the IEA’s longstanding expertise on #energy #security and on specific country examples.

      […]

      oAnth @02myseenthis01 CC BY
    Écrire un commentaire
  • @biggrizzly
    BigGrizzly @biggrizzly CC BY-NC-SA 19/03/2026

    Aura confirms data breach exposing 900,000 marketing contacts
    ▻https://www.bleepingcomputer.com/news/security/aura-confirms-data-breach-exposing-900-000-marketing-contacts

    #Identity_protection company Aura has confirmed that an unauthorized party gained access to nearly 900,000 #customer #records containing names and email addresses.

    The company states that the #incident was caused by a #voice #phishing #attack targeting an #employee, which exposed the #sensitive_data of 20,000 current and 15,000 former customers.

    In a communication this week, Aura states that the data originated from a #marketing tool used by a company acquired by Aura in 2021, which exposed limited information.

    Aura is a consumer #digital_safety firm that sells #identity_theft_protection, #credit and #fraud #monitoring, and #online #security tools for #phishing_protection, positioning itself as an all-in-one service for #online_protection.

    ON VOUS PROTÈGE !!!

    BigGrizzly @biggrizzly CC BY-NC-SA
    Écrire un commentaire
  • @biggrizzly
    BigGrizzly @biggrizzly CC BY-NC-SA 19/03/2026

    Despite Doubts, #Federal #Cyber #Experts Approved #Microsoft #Cloud Service — ProPublica
    ▻https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government

    Reporting Highlights

    – “Cloud First”: To move federal #agencies to the cloud, the #government created a program known as #FedRAMP, whose job was to ensure the #security of new #technology.
    – Security #Breakdown: ProPublica found that FedRAMP authorized a Microsoft product called #GCC High to handle #sensitive government #data, despite years of concerns about its security.
    – Potential #Conflict_of_Interest: The government relies, in part, on #third-party firms to vet cloud technology, but those firms are hired and paid by the company being assessed.

    These highlights were written by the reporters and editors who worked on this story.

    BigGrizzly @biggrizzly CC BY-NC-SA
    Écrire un commentaire
  • @biggrizzly
    BigGrizzly @biggrizzly CC BY-NC-SA 11/02/2026

    #Palantir's Swiss Exit Highlights Global Data Sovereignty Challenge | NewsCase
    ▻https://www.newscase.com/palantirs-swiss-exit-highlights-global-data-sovereignty-challenge

    #Switzerland’s #military has terminated its contract with Palantir Technologies Inc. following a #security audit. The review concluded that U.S. #intelligence agencies could potentially access sensitive Swiss #defense data, a deal-breaker for the neutrality-focused Alpine nation. This move represents a significant reputational warning for the data analytics firm, with potential ripple effects across other international partnerships.

    BigGrizzly @biggrizzly CC BY-NC-SA
    Écrire un commentaire
  • @biggrizzly
    BigGrizzly @biggrizzly CC BY-NC-SA 4/02/2026
    1
    @02myseenthis01
    1

    #DIY #AI bot farm #OpenClaw is a #security ’dumpster fire’
    ▻https://www.theregister.com/2026/02/03/openclaw_security_problems

    OpenClaw, the AI-powered personal assistant users interact with via messaging apps and sometimes entrust with their credentials to various online services, has prompted a wave of malware and is delivering some shocking bills.

    Just last week, OpenClaw was known as #Clawdbot, a name that its developers changed to #Moltbot before settling on the new moniker.

    The project, based on the Pi coding agent, launched in November. It recently attracted the attention of developers with large social media followings like Simon Willison and Andrej Karpathy, leading to an explosion in popularity that quickly saw researchers and users find nasty flaws.

    In the past three days, the project has issued three high-impact security advisories: a one-click remote code execution #vulnerability, and two command #injection #vulnerabilities.

    In addition, Koi Security identified 341 #malicious skills (OpenClaw extensions) submitted to #ClawHub, a repository for OpenClaw skills that’s been around for about a month. This was after security researcher Jamieson O’Reilly detailed how it would be trivial to backdoor a skill posted to ClawHub. Community-run threat database OpenSourceMalware also spotted a skill that stole cryptocurrency.

    BigGrizzly @biggrizzly CC BY-NC-SA
    Écrire un commentaire
  • @aurelieng
    aurelieng @aurelieng via RSS CC BY 29/01/2026

    The relationship between #shyness and #depression: the multiple mediating roles of sense of #security and #adaptability
    ▻https://www.frontiersin.org/journals/psychology/articles/10.3389/fpsyg.2026.1690111/full

    — Permalink

    #personality

    aurelieng @aurelieng via RSS CC BY
    Écrire un commentaire
  • @biggrizzly
    BigGrizzly @biggrizzly CC BY-NC-SA 29/01/2026
    4
    @ericw
    @sombre
    @kassem
    @rastapopoulos
    4

    Signal president warns AI agents are making encryption irrelevant
    ▻https://cyberinsider.com/signal-president-warns-ai-agents-are-making-encryption-irrelevant

    #Signal Foundation president Meredith Whittaker said #artificial_intelligence #agents embedded within operating systems are eroding the practical #security guarantees of #end-to-end #encryption (#E2EE).

    #IA #AI

    BigGrizzly @biggrizzly CC BY-NC-SA
    Écrire un commentaire
  • @biggrizzly
    BigGrizzly @biggrizzly CC BY-NC-SA 19/01/2026
    2
    @kent1
    @ericw
    2

    nixCraft 🐧"curl, which is one of the most…" - Mastodon
    ▻https://mastodon.social/@nixCraft/115910328009783851

    #curl, which is one of the most popular CLI/API tools for network requests and data transfer on Linux/Unix, is to discontinue its #HackerOne #bug_bounty program due to “too strong incentives to find and make up ’problems’ in bad faith that cause overload and abuse”.

    The authors simply cannot keep up with #LLM-generated #fake #security reports created to collect money using bots. So, it now shuts down at the end of January 2026. This is why we can’t have good things

    ▻https://github.com/curl/curl/pull/20312

    Plusieurs trolls pour commenter sur Github et dont l’intervention a été masquée parce que qualifiée d’abus, dont, un aperçu, laissé par @badger lui même :

    bagder commented 4 days ago

    - So luddites laugh at how bad vibecoding is, but when AI finds more bugs than code in a human project, they take down the bounty instead of fixing them.

    Feel free to point out all the bugs you say we have not fixed.

    BigGrizzly @biggrizzly CC BY-NC-SA
    Écrire un commentaire
  • @omgubuntu
    OMG ! Ubuntu ! @omgubuntu via RSS CC BY 19/11/2025

    #xubuntu Reveals How its Website Was Hijacked
    ▻https://www.omgubuntu.co.uk/2025/11/xubuntu-website-breach-report

    The Xubuntu team has shared an incident report on its October website breach. Attackers brute-forced the site to inject #malware - but was anything else affected? You’re reading Xubuntu Reveals How its Website Was Hijacked, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.

    #News #Canonical #security

    OMG ! Ubuntu ! @omgubuntu via RSS CC BY
    Écrire un commentaire
  • @omgubuntu
    OMG ! Ubuntu ! @omgubuntu via RSS CC BY 13/11/2025

    #Kaspersky Brings Its #antivirus Software to Linux Desktops
    ▻https://www.omgubuntu.co.uk/2025/11/kaspersky-linux-antivirus-released

    Kaspersky launches Linux antivirus for Ubuntu and other distros. Features, system requirements and why the banned #security firm has come to open-source desktops. You’re reading Kaspersky Brings Its Antivirus Software to Linux Desktops, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.

    #News

    OMG ! Ubuntu ! @omgubuntu via RSS CC BY
    Écrire un commentaire
  • @omgubuntu
    OMG ! Ubuntu ! @omgubuntu via RSS CC BY 8/11/2025

    Linux PPA Ransomware Scare is Light on Evidence
    ▻https://www.omgubuntu.co.uk/2025/11/linux-ppa-ransomware-investigated-no-malware

    Hysteria is contagious online. One person’s worry becomes another’s conviction, and that belief hardens — the thrill of righteous outrage is addictive! This week saw claims a PPA is being used to distribute Linux ransomware go wild online — but is it true? The story is a bit long, and a bit dry but it goes like this: A user said they tried to install #WinBoat (a tool for running Windows apps on Linux) but it wouldn’t connect to FreeRDP. So they tried FreeRDP from different sources, to no avail. Then, they saw a comment on GitHub about a custom […] You’re reading Linux PPA Ransomware Scare is Light on Evidence, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without (...)

    #News #malware #PPAs #security

    OMG ! Ubuntu ! @omgubuntu via RSS CC BY
    Écrire un commentaire
  • @biggrizzly
    BigGrizzly @biggrizzly CC BY-NC-SA 27/10/2025

    “It’s not about #security, it’s about #control” – How #EU governments want to #encrypt their own comms, but break our #private chats | TechRadar
    ▻https://www.techradar.com/vpn/vpn-privacy-security/its-not-about-security-its-about-control-how-eu-governments-want-to-encry

    #Data #sovereignty. Communication security. Strong #encryption. These are the words I heard the most in my day at the #Matrix Conference in Strasbourg last week.

    An event organized by the creators of Matrix, an #open-source #protocol that developers can use to build #decentralized and secure #messaging applications, showcased multiple iterations of how organizations have used this #federated system.

    BigGrizzly @biggrizzly CC BY-NC-SA
    Écrire un commentaire
  • @b_b
    b_b @b_b PUBLIC DOMAIN 6/10/2025

    Payloads All The Things
    ▻https://swisskyrepo.github.io/PayloadsAllTheThings

    https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/master/.github/banner.png

    A list of useful #payloads and bypasses for #Web Application #Security

    #xss

    b_b @b_b PUBLIC DOMAIN
    Écrire un commentaire
  • @omgubuntu
    OMG ! Ubuntu ! @omgubuntu via RSS CC BY 30/07/2025

    #Ubuntu_25.10 Offers Improved Disk #encryption Using #TPM
    ▻https://www.omgubuntu.co.uk/2025/07/ubuntu-25-10-tpm-disk-encryption

    Ubuntu 25.10 improves experimental TPM-backed full-disk encryption, which ties #security to hardware integrity. New options and checks will be in place. You’re reading Ubuntu 25.10 Offers Improved Disk Encryption Using TPM, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.

    #News

    OMG ! Ubuntu ! @omgubuntu via RSS CC BY
    Écrire un commentaire
  • @omgubuntu
    OMG ! Ubuntu ! @omgubuntu via RSS CC BY 19/07/2025

    4 Critical Security Flaws Patched in #vmware Workstation Pro
    ▻https://www.omgubuntu.co.uk/2025/07/vmware-workstation-pro-update-security-patches

    Virtualisation choices on Linux are, as I’m sure you’re know, varied – even more so since VMware made its Workstation Pro software entirely free to download and use on Windows and Linux, even for commercial purposes, no license key needed. This week, VMware Workstation Pro on Windows and Linux, and its macOS counterpart VMware Fusion, received an update with critical #Security_Fixes and a remedy to an issue affecting the (useful) Snapshots feature. VMware Workstation Pro 17.6.4 patches four critical security vulnerabilities (CVE-2025-41236, CVE-2025-41237, CVE-2025-41238, and CVE-2025-41239) and include a fix a fifth flaw filed under ‘moderate’ severity. The critical issues […] You’re reading 4 Critical Security Flaws Patched in VMware Workstation Pro, a blog post from OMG! Ubuntu. Do not (...)

    #News #App_Updates #Virtual_Machines

    OMG ! Ubuntu ! @omgubuntu via RSS CC BY
    Écrire un commentaire
  • @omgubuntu
    OMG ! Ubuntu ! @omgubuntu via RSS CC BY 6/07/2025

    Ubuntu #security Flaw Lets Attackers Bypass Full Disk Encryption
    ▻https://www.omgubuntu.co.uk/2025/07/ubuntu-security-initramfs-bypass-encryption

    Cybersecurity researchers have discovered a “critical” security vulnerability on Linux that can give attackers full system access — even on devices using full disk encryption. A report published by ERNW demonstrates the exploit on Ubuntu 25.04 and Fedora 42, though not all Linux distributions are affected, such as OpenSUSE Tumbleweed. So how does it work? Attackers with physical access to a Linux system can access a debug shell simply by entering the wrong decryption password several times in a row. On Ubuntu, they hit esc at the password prompt, punch in a few key combos, and bam: debug shell appears. […] You’re reading Ubuntu Security Flaw Lets Attackers Bypass Full Disk Encryption, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without (...)

    #News #dracut #secureboot #zfs

    OMG ! Ubuntu ! @omgubuntu via RSS CC BY
    Écrire un commentaire
  • @oanth_rss
    oAnth_RSS @oanth_rss CC BY 1/07/2025
    2
    @gao_tumbuktu
    @02myseenthis01
    2

    Cloudflare declares war on AI crawlers - and the stakes couldn’t be higher

    via ▻https://diasp.eu/p/17724248

    ▻https://www.zdnet.com/article/cloudflare-declares-war-on-ai-crawlers-and-the-stakes-couldnt-be-higher

    #computers #security #technology #news #education #updates #tech #analysis #research

    oAnth_RSS @oanth_rss CC BY
    • @02myseenthis01
      oAnth @02myseenthis01 CC BY 2/07/2025

      Get out of my website! Cloudflare, one of the world’s largest Internet infrastructure providers, has begun blocking AI web crawlers by default.

      Written by Steven Vaughan-Nichols, Senior Contributing Editor

      July 1, 2025 at 1:11 p.m. PT

      The major Internet Content Delivery Network (CDN), Cloudflare, has declared war on AI companies. Starting July 1, Cloudflare now blocks by default AI web crawlers accessing content from your websites without permission or compensation.

      The change addresses a real problem. My own small site, where I track all my stories, Practical Technology, has been slowed dramatically at times by AI crawlers. It’s not just me. Numerous website owners have reported that AI crawlers, such as OpenAI’s GPTBot and Anthropic’s ClaudeBot, generate massive volumes of automated requests that clog up websites so they’re as slow as sludge. GoogleBot alone reports that the cloud-hosting service Vercel bombards the sites it hosts with over 4.5 billion requests a month.

      These AI bots often crawl sites far more aggressively than traditional search engine crawlers. They sometimes revisit the same pages every few hours or even hit sites with hundreds of requests per second. While the AI companies deny that their bots are to blame, the evidence tells a different story.

      Thus, on behalf of its two million-plus customers, 20% of the web, Cloudflare now blocks #AI_crawlers. For any new website signing up for its services, AI crawlers will be automatically blocked from accessing its content unless the site owner grants explicit permission. Additionally, Cloudflare promises to detect “shadow” #scrapers — bots that attempt to evade detection — by using behavioral analysis and machine learning. What’s good for the AI goose is good for the gander.

      This move reverses the previous status quo, where website owners had to opt out of AI crawling. Now, blocking is the default, and AI vendors must request access and clarify their intentions, whether for model training, search, or other uses, before they’re allowed in.

      This change arises not only because of frustrated website owners. Numerous publishing companies, such as The Associated Press, Condé Nast, and ZDNET’s own parent company, Ziff Davis, are frustrated that #AI companies have been “strip mining” the web for content. All too often, this has been done without compensation or consent, and sometimes, ignoring standard protocols like robots.txt that are meant to block #crawlers.

      (Disclosure: Ziff Davis, ZDNET’s parent company, filed an April 2025 lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.)

      Moreover, recent court cases have ruled in favor of Meta and Anthropic, finding that their use of copyrighted works was legal under the doctrine of fair use. Needless to say, writers, artists, and publishers don’t like this one bit. Publishers are still worried that the federal government will give AI free rein to do as it wants with their content. AI powerhouses such as #OpenAI and Google are continuing to lobby the government to classify AI training on copyrighted data as fair use.

      It’s also worth noting that after the Copyright Office released a pre-publication version of its 108-page #copyright and #AI report, which struck a middle ground by supporting both of these world-class industries that contribute so much to our economic and cultural advancement. However, it added that while some generative AI probably constitutes a “transformative” use, the mass scraping of all data did not qualify as fair use. The next day, the Trump administration fired the head of the Copyright Office and replaced her with an attorney with no prior experience in #copyright_law.

      Given all this, it’s no wonder that publishers sought an ally in technology.

      As Cloudflare CEO Matthew Prince said in a statement, its new policy is meant to “give publishers the control they deserve and build a new economic model that works for everyone—creators, consumers, tomorrow’s AI founders, and the future of the web itself.”

      To complement the move to block AI crawlers, Cloudflare has also launched its “Pay Per Crawl” program. This enables publishers to set their own rates for AI companies that want to scrape their content.

      This system is currently in private beta and aims to create a framework where AI firms can pay for access, or be denied if they refuse. Technically, this will be done by dusting off an old, mostly unused web server response, HTTP 402, which responds with a “Payment Required” error message. This means it should be simple to implement and compatible with existing websites and their infrastructure.

      Overall, this is a big deal. Thanks to Cloudflare powering such a large portion of the internet, a significant amount of web content could become inaccessible to AI companies unless they negotiate access or pay licensing fees. As Nicholas Thompson, CEO of The Atlantic, noted, “Until now, AI companies have not needed to pay for content licenses because they could simply take it without repercussions. Now they will need to negotiate.”

      To this point, most AI companies have been actively against paying for content. As Sir Nick Clegg, former deputy UK Prime Minister and Meta executive, said recently, merely asking artists’ permission before they scrape copyrighted content will “basically kill the AI industry.”

      Cloudflare’s new policy is a direct response to this approach and the increasing volume and intrusiveness of AI crawlers that have come with it. It’s also an attempt to stop the siphoning of traffic that would otherwise go to publishers.

      Since the rise of AI, traffic to news sites has plunged. For example, Business Insider’s traffic dropped by over half, 55% from April 2022 to April 2025. Left unchecked, Thompson recently predicted that, thanks to AI, the Atlantic staff should expect traffic from Google to drop to zero.

      [...]

      oAnth @02myseenthis01 CC BY
    • @02myseenthis01
      oAnth @02myseenthis01 CC BY 2/07/2025

      #AI : aspects évidents du droit d’ #auteur, de la protection contre la #copie ainsi que des intentions et fréquences d’ #accès et de la #monétisation

      oAnth @02myseenthis01 CC BY
    Écrire un commentaire
0 | 25 | 50 | 75 | 100 | 125 | 150 | 175 | 200 | ... | 475

Thèmes liés

  • #cybersecurity
  • #news
  • #blockchain
  • #security
  • #cryptocurrency
  • #technology
  • #ethereum
  • #security-token
  • #news
  • #tech
  • #dns
  • #internet
  • #afnic
  • #privacy
  • #surveillance
  • #sécurité
  • #invector-labs
  • #malware
  • #encryption
  • #ai
  • #updates
  • #education
  • #computers
  • #sécurité
  • #snap_apps
  • #drones
  • #phishing
  • #canonical
  • #web
  • #app_updates
  • #linux
  • #bleeping_computer
  • #bleepingcomputer
  • #domains
  • #europe
  • #hacking
  • #dotfr
  • #cctlds
  • #tips_and_tricks
  • technology: cryptography