@nuke86i
iAccount based inItaly
About this account
- Account based in
- Italy
- Connected via
- Italy App Store
Account-level information from X, not a live location or the device used for a specific post.
SOC analyst coder with ❤️ #opensource #freesoftware #infoSec for https://nitter.cf/t.co/OF0JznPSz1 Founder of https://nitter.cf/t.co/bIavxmQiLV Fediverse: https://nitter.cf/t.co/PyA9f7VZFC
Cagliari, Italia
Joined July 2007
- Tweets8.3K
- Following661
- Followers1.8K
- Likes12K
711 collettivi italiani già schedati nelle liste USA
#sovranità
openb.app/posts/01a0dcbd-179…
N_{Dario Fadda} retweeted
#IAmNotAVillain has today made strong statements directed at Italy and at alleged civil servants who are selling their access to the public administration! 🤦♂️
The threat actor #IAmNotAVillain published a new section on their claim site last night!
The section, entitled "The Italy Files", contains Italian documents (not just identity documents).
And he states: "We have shown samples that are embarrassingly unprofessional on Italy’s.."
Caso #Revolut - attenzione ai titoli -
allo stato attuale i dati che sono stati pubblicati sono alcuni sample di qualche foto di documenti personali di cittadini e documenti interni di uffici pubblici.
I dati (150 GB) non sono stati ancora pubblicati
✨ Provider Terraform malevoli e il malware Graphalgo: la nuova minaccia supply-chain per i team DevOps
Leggi il blog: spcnet.it/provider-terraform…
💬 Se ne può parlare sul forum: internet-forum.it
avete presente la condivisione file su #IRC? FediShare porta il #p2p a livello del #fediverso.
ogni computer diventa un nodo che usa un gateway per federare l'actor con un dominio, si sceglie una cartella da condividere e tutti i file diventano link scaricabili, stando in locale
hi fedi-friends, I’m developing FediShare.
it’s a #P2P-style server based on #ActivityPub.
you install the desktop client;
you choose a folder to share;
it federates all the content;
and every file becomes a downloadable link across the #Fediverse.
github.com/insicd/fedishare
ShinyHunters contro l’FBI: rivendicata la violazione dei sistemi HR del Bureau, dati su “quasi tutti gli agenti”
il blog: insicurezzadigitale.com/shin…
#cybersecurity #cybercrime #databreach #fbi #infosec #shinyhunters
💬 Il forum: internet-forum.it/t/stanza-s…
hi fedi-friends, I’m developing FediShare.
it’s a #P2P-style server based on #ActivityPub.
you install the desktop client;
you choose a folder to share;
it federates all the content;
and every file becomes a downloadable link across the #Fediverse.
github.com/insicd/fedishare
to see it in action, once you have installed the desktop client, you can choose a username, and FediShare creates an actor available on the Fediverse.
an example is currently online: search for "@alice@fedishare.console.itagora.it" on Mastodon or anywhere else.
#Revolut gruppo #IamNotAVillain pubblica i primi files italiani. Una collezione di databreach che emerge 150 GB
#Revolut e IAmNotAVillain:
In queste ore si sono susseguiti takedown continui sui siti (almeno 4) e i canali Telegram aperti dalla cyber gang.
Finirà che si farà girare un dominio onion sotto rete Tor e i file staranno li in bella mostra.
ZRON: l’azienda cinese che trasforma email diplomatiche rubate in report di intelligence con l’IA
il blog: insicurezzadigitale.com/zron…
#cybersecurity #apt #cina #cybercrime #cyberwar #darkweb #infosec #russia #spyware
💬 Il forum: internet-forum.it/t/stanza-s…
✨ Addio SMS e voce per l’MFA in Entra ID: la guida completa alla migrazione verso i passkey
Leggi il blog: spcnet.it/addio-sms-e-voce-p…
💬 Se ne può parlare sul forum: internet-forum.it
N_{Dario Fadda} retweeted
Se state cercando gli IoC di #IamNotAVillain del caso #Revolut, sul forum c'è la traccia.
Da quelli bloccati con takedown, ai nuovi emersi in queste ore. Compreso onion dls
internet-forum.it/d/5232-ave…
#Revolut e IAmNotAVillain:
In queste ore si sono susseguiti takedown continui sui siti (almeno 4) e i canali Telegram aperti dalla cyber gang.
Finirà che si farà girare un dominio onion sotto rete Tor e i file staranno li in bella mostra.
‼️ BREAKING: The Revolut hacker has shared with Duel's investigation team, for the first time, a complete video showing the scale of his information treasure trove. Multiple celebrities are included in the leaks.
The hacker plans to announce his ransom demands today.
Here's everything we know about the case so far:
- As we established in our previous posts, the hacker gained access to an Italian government email address through an infostealer.
- Over the course of several months, using fake European Investigation orders, the hacker would submit large numbers of cryptocurrency transaction IDs to Revolut asking for all personal information associated with the accounts to be sent over. Revolut complied, sending hundreds of files, all belonging to high value crypto holders or transferors.
- The hacker's goal was to obtain high value crypto targets. This has various potential use cases in the cyber criminal world, such as online social engineering, conducting IRL robberies, reselling the information to other criminal groups, or blackmailing Revolut directly.
- The hacker says that any individual can "buy themselves" out of the data leaks. He will be publishing the ransom note without 24 hours outlining his demands from Revolut. We do not currently know what amount he will be demanding.
- We asked the hacker if he feels bad about what he did and the effects this will have on victims and their privacy. His reply was: "If the ransom is not paid, then the data will be sold, and their blood will be on Revolut's hands, not mine."
- A member of the hacking group known as "Smilik" had a falling out with Villain. They splintered into two channels, each one claiming to be the hacker. Smilik was unable to provide our team with sufficient evidence proving he was the original hacker. Villain provided videos, original emails with attachments, and proof that he had originally sent a subset of files to Smilik. We are satisfied that Villain is the original hacker and that his narrative is consistent.
- The hacker will be contacting other journalists and investigation groups today to release the same information, allowing for the existence of the files and authenticity of the emails to be independently corroborated
- Our team is under the impression that this is an amateur group that got lucky due to Revolut's lack of checks and continued incompetence over several months. This does not seem to be a professionally organized hacking group.
- The partial files sent to us contained details of a famous Swedish singer and Idol finalist, a prominent Armenian academic, an Indian cricket star, and several founders and CEOs. To balance public disclosure with user privacy, our team redacted every piece of personal information from the original video before publication. We have also deleted the original information from our end.
- Our understanding is that the files sent to us were just one of dozens. Each file, which comes with full banking and transaction history, would allow hackers to establish the target's daily spending patterns, location data, people they send money to (likely family, employees, or other close contacts) and more, leading to highly damaging personal disclosures.
We are releasing this information in the interest of public transparency. The breach is real, and Revolut was not forthcoming enough about it in enough time. We hope Revolut takes all legal and necessary steps available to them to prevent this data from being either publicly released or sold to criminal groups, as it would be highly damaging and disastrous for victims involved.
This is most of what we have for now. We'll keep an eye for any further updates, including when the ransom demand comes out.
Stando al video diffuso, i documenti italiani, rivenienti dalla casella PEC abusata e non legati a Revolut, saranno molti più di quanti pensiamo: sempre che l’archivio sia realmente di 147 GB come rivendicato
Se state cercando gli IoC di #IamNotAVillain del caso #Revolut, sul forum c'è la traccia.
Da quelli bloccati con takedown, ai nuovi emersi in queste ore. Compreso onion dls
internet-forum.it/d/5232-ave…
Stavo facendo qualche riflessione tra me e me sul core di #Openbook: per ora il mood resta cercare di mantenere locale soltanto la porzione di Fediverse pertinente alla propria comunità.
Mentre sviluppo, se volete fare un giro mi trovate qui: openb.app/@nuke
N_{Dario Fadda} retweeted
⚡️ ATTACCHI #DDoS verso Italia 🇮🇹
Ultime 24 ore: diversi domini italiani tra i target della botnet DDoSia, nelle prossime ore possono diventare attacchi reali.
La piattaforma #DDoSia Monitor di #Ransomfeed è disponibile su ddosia.rfeed.it, sia monitoraggio che alert.
Google si infiltra in TeamPCP: la talpa di Mandiant che ha smontato dall’interno la gang del supply chain
il blog: insicurezzadigitale.com/goog…
#cybersecurity #cybercrime #google #infosec #mandiant #npm #pypi #supplychain #teampcp
💬 Il forum: internet-forum.it/t/stanza-s…
ShinyHunters buca il leak site di Clop e minaccia di estorcere gli estorsori
il blog: insicurezzadigitale.com/shin…
#cybersecurity #clop #cybercrime #darkweb #infosec #ransomware #shinyhunters #skids10p
💬 Il forum: internet-forum.it/t/stanza-s…
✨ Da 430.000 righe di TypeScript a Rust: GitHub ha usato agenti AI per riscrivere il runtime di Copilot
Leggi il blog: spcnet.it/da-430-000-righe-d…
💬 Se ne può parlare sul forum: internet-forum.it
✨ Windows 11, KB5124008 e la Machine Identity Isolation: quando l’update rompe il trust con Active Directory
Leggi il blog: spcnet.it/windows-11-kb51240…
💬 Se ne può parlare sul forum: internet-forum.it
✨ Identità di workload vs account utente: perché passare a gMSA e Managed Identity
Leggi il blog: spcnet.it/identita-di-worklo…
💬 Se ne può parlare sul forum: internet-forum.it