Marco Bellaccini

Infrastructure, security and automation at RAI - Italian national public broadcasting company.
EBU MediaCybersecurity workgroup member.
Opinions are my own.

Marco Bellaccini boosted:
2025-02-02

tl;dr WhatsApp fixed the vuln on the back end, so you don't need to do anything to your phone, up to and including enabling Lockdown mode. Paragon Solutions sucks and you should be mad at them for enabling spying on civil society.

theguardian.com/technology/202

2025-02-01

#Spyware is harming journalists and freedom of speech.
#Paragon, NSO Group and similar companies (including Italian spyware vendors, of course) must be stopped and banned from operating.
www-ilpost-it.translate.goog/2

2025-01-15

I wanted to know if a certain AO tennis match has already been played or not, without reading the final score in the former case, and I thought "let's give this #grok AI a try".
As I often experienced with other AIs, the reply looked really good but was absolutely false.
#aifailures

2024-12-26
2024-12-14

RAI and other media companies are launching a new nonprofit company hosted at #EBU.
#Security4Media aims at building a secure and trustworthy media landscape.
security4media.org/
Looking for a new #infosec #job?
#Security4Media is #hiring! πŸ‘¨β€πŸ’»πŸ”
ebu.ch/careers/vacancy?utm_sou
Feel free to write me for any information.
#HiringAlert #HiringOpportunity

2024-12-07

Automated, #LLM #AI powered, replies to #googlemaps business #reviews are going mainstream.
I don't like them and here's my #turingtest .
#pizza #extinct #animals

I reviewed pizzas with pieces of extinct animals and for the "business owner" it's absolutely normal.
Marco Bellaccini boosted:
2024-11-17
A 16:9 image that is half Magenta and half grey, designed to cause signal processing issues with SDI video gear
Marco Bellaccini boosted:
2024-10-19

It's true: Google Scholar profile of the renowned former physicist and polymath, Sir Isaac Newton bears a "verified" email note. According to Google Scholar, Isaac Newton is a "Professor of Physics, MIT" with a "Verified email at mit.edu."

bleepingcomputer.com/news/secu

Marco Bellaccini boosted:
Lukasz OlejnikLukaszOlejnik
2024-09-25

GREAT change is approaching. NIST will standardise prohibition of requirement of composing passwords from various character styles, and requirement for periodic password changes. These are harmful and obsolete rules. Now they will be treated as a cybersecurity weakness pages.nist.gov/800-63-4/sp800-

Marco Bellaccini boosted:
2024-09-24

New from 404 Media: Google is serving AI images of mushrooms when users search for some species. Very risky, potentially fatal error for foragers who are trying to find what mushrooms are safe to eat. Could have "devastating consequences" one expert said 404media.co/google-serves-ai-g

2024-09-20

@ecn great analysis! I received this yesterday and I also received two other, similar emails, a couple of days before:

Marco Bellaccini boosted:
quite possibly an ianecn
2024-09-20

GitHub Notification Emails Hijacked to Send Malware

ianspence.com/blog/2024-09/git

2024-09-14

Nasty things for nasty programmers.
#github #spam

A service selling GitHub stars
2024-09-04

I partly agree with this article...
Still, I'd never ever drop #Debian because it doesn't have #SELinux
unix.foo/posts/insecurity-of-d

Marco Bellaccini boosted:
2024-08-09

Signal is blocked in several countries but you can set up a proxy server to help people access Signal no matter where they live. Here’s how:

signal.org/blog/proxy-please

Thank you for helping keep Signal available for everyone who needs it.

To share your proxies use #SignalProxy

Marco Bellaccini boosted:
2024-08-09

We're aware of reports that access to Signal has been blocked in some countries. As a reminder, Signal's built-in censorship circumvention feature might be able to help if your connection is affected:

Signal Settings > Privacy > Advanced > Censorship circumvention (on)

2024-08-07

Getting bored of "limited, targeted exploitation"
#cve_2024_36971 #android #exploitation

Android security advisory about CVE-2024-36971 being under "limited, targeted exploitation"
Marco Bellaccini boosted:
Kenn Whitekennwhite
2024-08-07

Great piece by @lhn and @mattburgess on the infostealer marketplace. The bad guys have gone full service retail.

wired.com/story/infostealer-ma

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst