Il Blog di Michele Pinassi
305 subscribers
389 photos
17 videos
122 files
8.64K links
Parliamo di tecnologia, politica e cybersecurity.

Post automatici e rassegna personale.
Download Telegram
"An AI agent tried to join the DN42 hobbyist network to perform a network scan, and bankrupted its operator with a $6531.30 AWS bill, to the extent that they are begging for donations from the DN42 community."

https://lantian.pub/en/article/fun/ai-agent-bankrupted-their-operator-scan-dn42lantian.lantian/
Uso di LLM e automazione nelle operazioni ransomware del gruppo “The Gentlemen”
L'evoluzione di "The Gentlemen" dimostra come l'intelligenza artificiale e l'agilità strategica consentano alle gang criminali di superare i vecchi limiti logistici e di sicurezza. Quando un data leak ha esposto le loro chat interne nel maggio 2026, il gruppo ha reagito all'istante, migrando l'intera infrastruttura di comunicazione verso piattaforme decentralizzate. [...]

by CERT-AgID - https://r.zerozone.it/post/XvnGqMvyYVqcdXJ4N
We predict that the impact of superhuman AI over the next decade will be enormous, exceeding that of the Industrial Revolution.

We wrote a scenario that represents our best guess about what that might look like.1 It’s informed by trend extrapolations, wargames, expert feedback, experience at OpenAI, and previous forecasting successes.

https://ai-2027.com/
Phishing e spam via PEC: oltre 650 gli eventi gestiti nel 2026
Nell'ambito della consueta attività di monitoraggio sulle minacce veicolate tramite Posta Elettronica Certificata, il CERT-AGID rileva con continuità la circolazione di messaggi indesiderati e potenzialmente malevoli trasmessi attraverso caselle PEC legittime riconducibili ad account compromessi o a caselle registrate per finalità illecite. A seguito delle segnalazioni in merito al [...]

by CERT-AgID - https://r.zerozone.it/post/Ygp6E2xEpEzfRtSzW
Buratti
Ransomware group called thegentlemen claims attack for Buratti. The target comes from Italy. We identify this attack with following hash code: d60594a463269df1217f7e4db362d71b77263755615e65d9e8946ed40fcbafa7 (ID: 33065)Target victim website: buratti.it

by RansomFeed - https://r.zerozone.it/post/ZsrZNWaUHB4B1rqj4
1
Tecfi SpA
Ransomware group called dragonforce claims attack for Tecfi SpA. The target comes from Italy. We identify this attack with following hash code: 27f85d02eea26f46b21348a5fd4b38583d47ec9f6197060e680d94edf4abe403 (ID: 33120)Target victim website: tecfi.it

by RansomFeed - https://r.zerozone.it/post/du9rTMuFYwaqmSTuq
seinordovest.it
Ransomware group called safepay claims attack for seinordovest.it. The target comes from Italy. We identify this attack with following hash code: c22c36956d65cb517271030b75033db9119a4ece47a1bc4e5e59dd04c6d23867 (ID: 33146)Target victim website: seinordovest.it

by RansomFeed - https://r.zerozone.it/post/AFuxd8pVD70HXK6TR
brscappuccio.it
Ransomware group called safepay claims attack for brscappuccio.it. The target comes from Italy. We identify this attack with following hash code: 14520d3ecc50bc4ca8697c32c8776abf4238b055095815f31bc365c77a55750d (ID: 33143)Target victim website: brscappuccio.it

by RansomFeed - https://r.zerozone.it/post/wqWpGde2Mde0RABMF
Check whether your organization's data has been exposed in misconfigured storage or FortiBleed VPN firewall breaches.

https://socradar.io/free-tools/fortibleed
FortiBleed: credenziali Fortinet esposte, interessata anche la PA italiana
È recentemente emerso un dataset di credenziali compromesse di dispositivi Fortinet, denominato FortiBleed. Il dataset è stato originariamente scoperto dal ricercatore Bob Diachenko su un server accessibile pubblicamente, contenente un archivio strutturato di credenziali riferite a interfacce SSL VPN e pannelli di amministrazione di apparati FortiGate distribuiti a livello globale.

by CERT-AgID - https://r.zerozone.it/post/2ZNEqX887cUSTAvV2
Analisi diffusione della criticità FortiBleed da parte di Dario Fadda.

https://ransomfeed.it/?page=fortibleed&country=IT
Campagne di phishing a tema criptovalute abusano del nome dell’Agenzia delle Entrate
Il CERT-AGID ha rilevato diverse campagne attive che sfruttano in modo fraudolento il nome, il logo e la grafica dell'Agenzia delle Entrate, con l'obiettivo di sottrarre informazioni finanziarie e patrimoniali agli utenti. Il tema comune è la presunta obbligatorietà di una dichiarazione di cripto-asset digitali, talvolta accompagnata da richiami a scadenze imminenti per [...]

by CERT-AgID - https://r.zerozone.it/post/aSzRy5Efn7uChkzWP