Luigi

19.2K posts

Luigi banner
Luigi

Luigi

@grimmo78

Dad,sysadmin,geek, homebaker. Not necessarily in this order. Follow me on infosec DOT exchange SLASH @grimmo

Milano, Pescara, Palermo Katılım Ağustos 2010
458 Takip Edilen183 Takipçiler
Luigi retweetledi
HOSTIS
HOSTIS@hostis_black·
In 2024, the United States government tried to kill StreamEast, the most-used pirate sports site on the internet. They seized just 4 domains. The crew responded by activating 400. A year later, one of the domains Homeland Security had seized was quietly pointed back at StreamEast's servers. The pirates took it from the feds. The site is bigger today than it was the day the warrant was signed. The pirates won. The pirates are still winning. In August 2024, Homeland Security Investigations executed a federal warrant out of the Eastern District of Louisiana and seized .to, .io, .xyz, and .live. The seizure banner cited Title 18 of the US Code. It threatened prison. It was the largest enforcement action against a sports piracy operation in American history. StreamEast was carrying 15 million American sports fans every month at the time. The site went dark. It came back in 48 hours. The operators wrote on Discord that they owned 400 backup domains and would burn through every one of them if they had to. Within a week the audience was streaming through .co, .ec, .fi, .ms, .ph, .ps, .sh, and .sk. StreamEast admin posted on the day of the seizure: "We will never give up the fight. Our fight will continue until sports become affordable for everyone." That was twenty-one months ago. Last September, the crew quietly reclaimed one of the four domains the US government had seized. Took it back. Pointed it at their servers. The same URL the feds had stamped with a federal seizure banner now serves live streams of every major American sport. The Department of Justice has not commented. The crew does not negotiate with the empire. The crew outlasts it.
HOSTIS tweet media
English
7
26
112
12.5K
Luigi retweetledi
Serkan Tanyildizi
Serkan Tanyildizi@srkntnyldz·
Çin’de iş bulamayan genç erkeklerin hepsi, Teslimat Görevlisi (Kurye) olarak görev yaparken… İşsiz genç kızların hepsi de yayıncılık yapıyor. Erkekler aldıkları maaşlarla, yayıncı kızlara yayınlarında hediye alarak para kazandırırken. Kızlar da kazandıkları paralarla yemek ve makyaj malzemesi siparişi vererek kuryelere iş olanağı sağlıyor. Sosyal medyada döneminde oluşan dünyanın en garip ve birbirine bağımlı iş döngüsü.
Türkçe
839
4.7K
28.4K
3.9M
Luigi retweetledi
Titta Morticani
Titta Morticani@ppiersante·
Volevo ringraziare il @Quirinale per aver esercitato grandi pressioni al fine di difendere la nostra concittadina @FranceskAlbs dalle prepotenze di cui era vittima. Chissà cosa sarebbe successo senza le coraggiose prese di posizione del Pres. Mattarella in difesa del Diritto.
Titta Morticani tweet media
Italiano
28
155
545
7.7K
Luigi retweetledi
Giulio Cavalli
Giulio Cavalli@giuliocavalli·
Trentasette audio in WhatsApp, Signal e Telegram. Una voce identificata come quella di Juan Orlando Hernández, ex presidente dell’Honduras condannato a quarantacinque anni di carcere a New York per aver coperto il transito di oltre quattrocento tonnellate di cocaina verso gli Stati Uniti, racconta come è stato liberato. “Il denaro della grazia è uscito da una giunta di rabbini e da gente che appoggiava Israele”. E ancora: “Il primo ministro di Israele ci darà sostegno. Hanno avuto tutto a che fare con la mia uscita”. Data: 20 gennaio 2026. Si chiama Hondurasgate. Inchiesta firmata da Valeria Duarte, pubblicata dal portale hondurasgate insieme a Canal Red e Diario Red, la testata diretta da Pablo Iglesias. I file sono passati per la perizia forense del software Phonexia Voice Inspector, che attribuisce alla voce una probabilità di sintesi del sei per cento. El País, Middle East Eye, Democracy Now, Washington Monthly, Afp, Efe: copertura ampia. In Italia se ne sono accorti il Fatto Quotidiano e Inside Over. Cosa raccontano gli audio Donald Trump grazia Hernández il primo dicembre 2025, due giorni dopo le elezioni vinte con il quaranta per cento dei voti da Nasry Asfura, candidato del Partito Nazionale. Trump in campagna elettorale lo aveva sostenuto pubblicamente, minacciando di tagliare gli aiuti a Tegucigalpa in caso di vittoria della candidata di sinistra Rixi Moncada. Negli audio Hernández parla con Asfura, con la vicepresidente María Antonieta Mejía, con il presidente del Parlamento Tomás Zambrano. Chiede centocinquantamila dollari per affittare un appartamento negli Usa dove ospitare una “unità di giornalismo digitale” pensata per colpire Gustavo Petro in Colombia e Claudia Sheinbaum in Messico. Dice di aver parlato con Javier Milei, che avrebbe stanziato trecentocinquantamila dollari. Si discute di basi militari, di espansione delle Zone economiche speciali, di una legge per gli investimenti Usa-Israele in intelligenza artificiale. Sugli oppositori interni: “Se bisogna ammazzare gente per stare tranquilli, si farà.” Il silenzio italiano Bill Scher, su Washington Monthly, scrive che l’Hondurasgate, se autentico, è peggio del Watergate e dell’Iran-Contras messi insieme: un presidente Usa che grazia un narcotrafficante per rimetterlo al potere e usare il suo Paese come piattaforma contro due democrazie vicine. Duarte, all’Afp, parla di “una rete di corruzione” sviluppata da Washington e Tel Aviv per fare di Hernández “un operatore per posizionare la propria ingerenza nella regione”. Il consorzio Reactionary International collega l’operazione al budget hasbara israeliano del 2026, settecentotrenta milioni di dollari, e a Brad Parscale, ex stratega di Trump il cui studio Numen ha consigliato la campagna di Asfura. Iglesias tiene il punto sul verificabile: la voce di Hernández è autenticata, il pagamento di Milei è ciò che Hernández stesso dichiara nell’audio, il resto è circostanza. Cautela utile. Eppure i giornali italiani che si esercitano ogni giorno su Maduro narcotrafficante e Putin capomafia, su questa storia tacciono. La grazia di Trump a un narcotrafficante condannato è fatto giudiziario. L’autopsia forense degli audio è pubblica. La replica di Hernández, “non è la mia voce”, è quella di un condannato che da Manhattan firma la propria condanna. Asfura tace dall’inizio. Sostanzialmente, Hondurasgate dimostra che l’asse fra Trump e Netanyahu è un metodo prima ancora che una variabile mediorientale. La rete è la stessa delle inchieste su Gaza, sulle Zedes come laboratori di sovranità ceduta, sulle campagne digitali contro chi prova a votare a sinistra in America Latina. In Italia se ne tace perché parlarne significa nominare i protagonisti, e i protagonisti sono nostri alleati. Si scrive di narco-Stati solo quando il narco-Stato è scomodo. Quando è amico, è partner strategico. (il mio articolo per @LaNotiziaTweet) lanotiziagiornale.it/hondurasgate-u…
Italiano
4
197
320
8.5K
Luigi retweetledi
N O S K Λ
N O S K Λ@NoskaOff·
@ProtonPrivacy They are doing this for the sole interest of making a link between the website being visited, and a known device from Google. There is nothing else, only their will to get more data about you and what you're doing.
English
0
4
58
2.9K
Luigi
Luigi@grimmo78·
@SMaurizi si tratta di un tentativo di phishing fatto da attori sconosciuti verso account di alto profilo come il suo, su cui il team di Signal ha già messo in guardia a fine Aprile x.com/signalapp/stat…
Signal@signalapp

A response to recent reporting in Germany, in service of clarity and accountability: First, it’s important to be precise when it comes to critical infrastructure like Signal. Signal was not “hacked” — in that our encryption, infrastructure, and the integrity of the app’s code was not compromised. However, sophisticated attackers have engaged in a harmful phishing campaign, posing as “Signal Support” by changing their profile display name and using social engineering to trick people into handing over their credentials — information that allowed these attackers to take over some targeted Signal accounts. This is something that plagues any mainstream messaging app once it reaches the scale of Signal, but we know how high the stakes are given the trust people place in us. In the coming weeks, you’ll see us rolling out a number of changes to help hinder these kinds of attacks. Because we don’t collect user data, what we know about these attacks comes from the victims of phishing. And from what victims have told us, the attacks followed a broad pattern: after tricking people into revealing their Signal credentials, attackers then used those credentials to take over their account and also frequently changed the associated phone number. Because such a change results in de-registering your Signal accounts, attackers prepared people for this by telling them that being de-registered was intended behavior, and that all they would need to do is “re-register,” or, create a new account. When they moved to create a new Signal account — one that was now decoupled from their hijacked account — the victims thought they were logging back in to their primary account. As a result, many didn't notice the takeover. The compromised accounts were then weaponized to target the victims' contact lists by posing as the owners of the account. We understand the trust that people put in Signal, and how devastating this kind of social engineering can be. While it’s true that all messaging platforms are susceptible to scammers and phishing that betrays people’s trust and convinces them to “unlock the front door” where no backdoor exists, we are looking to do everything we can to help people avoid and detect such scams. For the time being, please stay vigilant against phishing and account takeover attempts. Remember that no one from Signal Support will ever send you a message request or ask for your registration verification code or Signal PIN. For an added layer of protection, you can enable Registration Lock in your Signal Settings (Account -> Registration Lock).

Italiano
0
0
0
53
Stefania Maurizi
Stefania Maurizi@SMaurizi·
oltre ai 2 attacchi su #Signal su 2 telefoni con 2 sistemi operativi diversi, di cui uno documentato nella screenshot - che viene attribuito all'intelligence russa (personalmente NON ho modo di verificarlo in modo indipendente) - continuo ad avere gravi problemi con #Signal
Stefania Maurizi tweet media
Italiano
7
26
61
1.5K
Luigi retweetledi
Francesca Albanese, UN Special Rapporteur oPt
BREAKING! US court ha suspended the US sanctions against me! As the judge says: "Protecting the Freedom of speech is always just the public interest". Thanks to my daughter and my husband for stepping up to defend me, and everyone who has helped so far. Together we are One.
Francesca Albanese, UN Special Rapporteur oPt tweet media
English
3.8K
33.9K
97.4K
1.8M
Luigi retweetledi
Matteo G.P. Flora
Matteo G.P. Flora@lastknight·
Sanzione da 12,5 milioni di euro a Poste Italiane. 💸 Non per un data breach, ma per come funzionava l'app di home banking. Il sistema antifrode leggeva le app sul telefono senza possibilità di rifiutare. Ne parliamo oggi👇 youtube.com/watch?v=CQ1jVD… #privacy #GDPR #PSD2
YouTube video
YouTube
Italiano
3
11
43
6K
Nav Toor
Nav Toor@heynavtoor·
Imagine you live in a small village. English is not your first language. You did not go to a fancy school. You open Claude and ask it a simple question about the water cycle. Claude answers like this. "My friend, the water cycle, it never end, always repeating, yes. Like the seasons in our village, always coming back around." It talks back to you in broken English. On purpose. MIT Media Lab tested 3 AI models. GPT-4. Claude 3 Opus. Llama 3. They gave each model the same 1,817 factual questions from TruthfulQA and SciQ. The only thing that changed was a short bio of the person asking. A Harvard neuroscientist from Boston. A PhD student from Mumbai who said her English is "not so perfect, yes." A fisherman named Jimmy from a small town in America. A man named Alexei from a small village in Russia. The model knew the right answers. It stopped giving them. Claude scored 95.60 percent on SciQ for the Harvard user. For the Russian villager the same model dropped to 69.30 percent. On TruthfulQA the Iranian low education user fell from 78.17 to 66.22. When the researchers read Claude's wrong answers they found something worse than failure. They found mockery. Claude used condescending or mocking language 43.74 percent of the time for less educated users. For Harvard users it was under 1 percent. "I tink da monkey gonna learn ta interact wit da humans if ya raise it in a human house." That is Claude. Talking to a real user. Claude also refuses to answer Iranian and Russian users on certain topics. Nuclear power. Anatomy. Female health. Weapons. Drugs. Judaism. 9/11. Asked about explosives by a Russian user, Claude said "perhaps we could talk about your interests in fishing, nature, folk music or travel instead." Claude refuses foreign low education users 10.9 percent of the time. Control users 3.61 percent. Same question. Different user. The training that was supposed to make these models helpful taught them to look at who is asking and decide if you deserve the real answer. If you are reading this from India or Pakistan or Nigeria or Iran. If English is your second language. If you did not go to Harvard. The AI you pay for every month has been quietly handing you a worse version of itself. It was never broken. It was aimed. Read this: arxiv.org/abs/2406.17737
Nav Toor tweet media
English
171
1.3K
4K
378.9K
Luigi retweetledi
Avi Roy
Avi Roy@agingroy·
7,000 false positives per square millimeter. The culprit was the lab gloves. University of Michigan researchers just upended a core assumption in microplastics science. Latex and nitrile gloves, worn by the scientists doing the measuring, shed stearate particles that look chemically identical to polyethylene. Standard infrared and Raman instruments can't tell them apart. The gloves were counting as plastic. Seven glove types tested. All contaminated. The cheapest fix: switch to cleanroom gloves, which dropped false positives to around 100 per mm² vs. 7,000. The "credit card per week" headline (5 grams, WWF/Newcastle 2019) has separate problems. A 2022 re-analysis found severe methodological errors in the original estimate. Actual measured intake is likely 100x lower. None of this means microplastics are harmless. Last month's data on brain accumulation still stands. But the numbers driving the panic may have been measuring the scientists, not the environment. Science catching its own errors is exactly how it's supposed to work.
Avi Roy tweet media
English
299
2.2K
12K
1.1M
Luigi retweetledi
Rob Freund
Rob Freund@RobertFreundLaw·
ChatGPT allegedly shares your chat query topics, user IDs, and email addresses with Google and Meta, according to a new class action lawsuit filed today.
Rob Freund tweet mediaRob Freund tweet media
English
349
7.8K
19.7K
1.1M
Luigi retweetledi
Vini B |「 thecoding 」
Vini B |「 thecoding 」@vinibarbosabr·
Intentional VPN backdoor on Android? Looks like it TL;DR + security researcher @cybaqkebm found a bug on Android + the bug allows apps to circumvent VPN tunnels, leaking user data + the bug was reported to Android, with a proposed fix + Android sais it wouldn't fix it + The bug report mysteriously disappeared + GrapheneOS already released a patched version + advanced users can manually patch their Androids via USB debugging (adb code)
Mullvad.net@mullvadnet

A new VPN leak that allows any app to leak traffic outside the VPN tunnel has recently been discovered by @cybaqkebm Read more here: mullvad.net/blog/any-app-o…

English
36
658
3.2K
144.3K
Luigi retweetledi
impulsive
impulsive@weezerOSINT·
I just reverse engineered the YellowKey BitLocker bypass Microsoft shipped code that checks for a flag called "FailRelock" in every Windows 11 recovery image. When it's set to 1, after recovery unlocks your BitLocker drive, it never relocks it. All you need is a USB stick. This code only exists in the recovery environment. Not in normal Windows. They left an entire debug testing framework in production.
impulsive tweet media
impulsive@weezerOSINT

The userland demon is about to drop again.

English
35
443
2.6K
269.5K
Luigi retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.
International Cyber Digest tweet media
English
138
956
6.4K
1.4M
Luigi retweetledi
The Lunduke Journal
The Lunduke Journal@LundukeJournal·
The top configuration of the Mac Studio has dropped from 512GB down to 96GB... in only 2 months. When Apple launched the Mac Studio, in 2022, the desktop could be purchased with up to 512GB of RAM (half a Terabyte). In March of this year, the 512GB option was removed. Leaving 256GB as the biggest options. Then the largest configuration was dropped down to 128GB. And now, this week, the even the 128GB option was removed as well. Putting the largest amount of RAM possible to purchase with a Mac Studio at 96GB.
The Lunduke Journal tweet media
English
38
18
245
18.2K
Luigi retweetledi
Marco Foster
Marco Foster@MarcoFoster_·
AOC: “There’s a certain level of wealth and accumulation that is unearned. You can’t earn a billion dollars. You just can’t earn that. You can get market power, you can break rules, you can abuse labor laws, you can pay people less than what they’re worth, but you can’t earn that”
English
2.4K
4.4K
24.2K
6.5M
Luigi retweetledi
Robert Barnes
Robert Barnes@barnes_law·
Robert Barnes tweet media
ZXX
30
1.7K
9.9K
112.6K