@0xPira@reefbr KKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK O CARA MANDOU O LINK DA PHRACK PRO MANOELT, IMPOSSIVEL. olha o pique @sidhw1ks
‼️🚨 This is really bad. According to our research, at least one of Brazil's government IT workers was infected with an infostealer. We found:
- He was doing goverment infrastructure work on his home RGB gaming PC
- He was running Windows 7 (EoL Jan 2020)
- No antivirus
- NO MFA for some critical infra
- His browser held gov VPN creds for himself and two colleagues (they were using each others creds?)
- Search history includes "ativar windows 10," "download office 2019 + ativador," "comprar office 365," and "download mobaxterm cracked"
- Malware dropped via malicious game installer
- The keys to his password managers were in the stolen browser: a LastPass account and a keypass[.]mdr[.]gov[.]br vault
- Exposed: VPN, GitLab, Jenkins, webmail, SSO, M365, and dev/staging environments across mec[.]gov[.]br and mdr[.]gov[.]br
Publiquei minha pesquisa sobre uma vulnerabilidade de RCE em visualizadores PDF Linux como Atril, Evince e Xreader, resultando na CVE-2026-46529.
Abrindo o PDF, e clicando qualquer parte da pagina um comando arbitrário é executado no sistema
O artigo:
https://t.co/NgkUNYmhHJ
Apple and Google are gradually expanding their use of hardware-based attestation. They're convincing a growing number of services to adopt it. Google's Play Integrity API and Apple's App Attest API are very similar. Apple brought it to the web via Privacy Pass, which Google intends on doing too.
Google's Play Integrity API requires hardware attestation for the strong integrity level and is gradually phasing in requiring it for the more commonly used device integrity level. Apple already has it as a requirement. Over the long term, this will increasingly lock out hardware and OS competition.
The purpose of these systems is disallowing people from using hardware and software not approved by Apple or Google. This is wrongly presented as being a security feature. Banks and government services are the main ones adopting it but Apple and Google are encouraging every service to use it.
Apple's Privacy Pass brought hardware attestation to the web to help with passing captchas on their own hardware. Many people saw that as harmless since few sites would be willing to lock out non-Apple-hardware users. Apple and Google are both likely to bring broader hardware attestation to the web.
Google's reCAPTCHA is planning an approach where they use Privacy Pass on Apple hardware, their own approach on Google Mobile Services Android devices and a QR code scanning system to require an iOS or Google certified Android device for Windows and other systems:
https://t.co/7rQnioRa8A
Banking and government services increasingly require using a mobile app where they can use attestation to force using an Apple or Google approved device and OS. Apple's privacy pass, Google's 'cancelled' Web Environment Integrity and now reCAPTCHA Mobile Verification are bringing this to the web.
Current media coverage for reCAPTCHA Mobile Verification misunderstands it and the impact of it. They're bringing a hardware attestation requirement to Windows, desktop Linux, OpenBSD, etc. by requiring a QR scan from a certified smartphone to pass reCAPTCHA in some cases. They could expand it more.
Control over reCAPTCHA puts Google in a position where they can require having either iOS or a certified Android device to use an enormous amount of the web. Google defines certification requirements for Android which includes forcing bundling Google Chrome, etc. It's enormously anti-competitive.
Google's Play Integrity API bans using GrapheneOS despite it being far more secure than anything they permit. It also bans using any other alternative. This isn't somehow specific to an AOSP-based OS. You can't avoid this by using a mobile OS based on FreeBSD instead. You'll just be more locked out.
Google's Play Integrity API permits devices with no security patches for 10 years. The device integrity level can be bypassed via spoofing but they can detect it quite well and block it once it starts being done at scale. The strong integrity level requires leaked keys from TEEs/SEs to bypass it.
It doesn't provide a useful security feature, but it does lock out competition very well. Services requiring Apple App Attest or Google Play Integrity are primarily helping to lock in Apple and Google having a duopoly for mobile devices. Play Integrity is more relevant due to AOSP being open source.
Governments are increasingly mandating using Apple's App Attest and Google's Play Integrity for not only their own services but also commercial services. The EU is leading the charge of making these requirements for digital payments, ID, age verification, etc. Many EU government apps require them.
Instead of governments stopping Apple and Google from engaging in egregiously anti-competitive behavior, they're directly participating in locking out competition via their own services. Requiring people to have an Apple device or Google-certified Android device is anti-competition, not security.
reCAPTCHA Mobile Verification will currently work with sandboxed Google Play on GrapheneOS but it clearly exists to provide a way for them to start using hardware attestation on systems without it. People without an iOS or Android device will be locked out when this is required even without that.
This isn't about security or any missing functionality. GrapheneOS can be verified via hardware attestation. Google bans using GrapheneOS for Play Integrity because we don't license Google Mobile Services and conform to anti-competitive rules already found to be illegal in South Korea and elsewhere.
Services shouldn't ban people from using arbitrary hardware and operating systems in the first place. Google's security excuse is clearly bogus when they permit devices with no patches for 10 years but not a much more secure OS. It's for enforcing their monopolies via GMS licensing, that's all.
🚨 Bitwarden CLI 2026.4.0 was compromised as part of the ongoing Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
We’ll continue updating our coverage as more details are confirmed.
https://t.co/G0aakn8swq
Brazil's authoritarian age verification law became active this month. It won't be implemented by GrapheneOS. Complying would require integrating a mandatory process for each user where a third party service checks government identification and confirms a match using the camera.
1. Not true. Minor exception.
This is a long-standing conspiracy dating back to the very inception of malware, in essence the idea governments and anti-malware vendors are cooperating with each other for espionage. The reality is this is simply improbable. Not every anti-malware vendor resides in the United States and not every anti-malware vendor has to cooperate with the United States government. Additionally, some anti-malware services may feel hostile toward the United States government and actively disregard any form of communication.
However, there have been some instances where the United States government has partnered with anti-malware vendors and/or security companies to target high-profile targets (sex traffickers, terrorist organizations) and requested assistance. It would not be outside the realm of possibility to intentionally insert an exception in highly targeted operations.
This has been semi-documented in the past whereas Google identified a malware campaign in the Middle East and it was discovered to be a United States military operation targeting individuals believed to be part of ISIS.
Finally, Magic Lantern is old. It is old as dirt. It was discussed in the early-2000's. Malware has changed a lot since then. The anti-malware industry has changed a lot. This sort of operation (wide spread espionage via malware) just isn't really possible without global cooperation, including China and Russia.
2. Not true. Long standing schizo theory. Google it. Even real privacy schizos know it's not true. The concern arose when security researchers identified a debug switch in INTEL ME. Additionally, if this were true, network traffic monitoring software would identify this.
There is also open source solutions, you don't need INTEL ME or anything else.
The exception to this is when the United States government intercepts hardware and places malware on it or intentionally modifies it. This is true.
3. Partially true. There is some speculation, but basically the NSA recommended Dual_EC_DRBG to vendors as a standard despite criticism of it and known vulnerabilities in which could allow exploitation. Basically, the NSA was recommending a known bad thing.
4. No idea. I don't do anything with frequencies and radios.
5. This is true.
6. This is true. However, this is not exclusive to the NSA.
7. Partially true. The United States government owns a bunch of Tor nodes and monitors it, the monitoring however is for entry and exit of Tor. However, this cannot easily identify you. If this were the case then there would be much less child pornography and fentanyl sales on Tor. Additionally, they would use this to heavily crackdown on ransomware groups.
Most of the time people are caught on Tor from information leaking from Tor (long story, basically cookies)
8. Partially true. It has been documented several times large tech organizations are aware of critical exploits and (based on existing contracts with them) may notify them before anyone else due to the risk to critical infrastructure of the United States. Microsoft has big contracts with the United States. This isn't a surprise. Furthermore, it was been speculated heavily that Microsoft has delayed patches to aid the United States military in offensive cyber operations (APT NightEagle)
9. This is true. However, to the extent they can "take it over" is ambiguous because your cars electronics and GPS are not connected to your steering wheel.
10. IoT is a huge piece of shit and is compromised all the time. Seriously, don't use IoT devices.
11. No idea.
Meanwhile in Brazil: Arch Linux has to suspend access from Brazil because kids could use Arch Linux, or something, and something about pedophiles.
I actually have no idea what the politicians are even saying anymore. It's all bullshit and it's fucking over FOSS.
When we look at the Brazilian economy and wonder why growth has been so low for so long, an uncomfortable part of the answer lies in the private sect itself. Brazil is a notorious breeding ground for zombie companies. These are firms that cannot generate enough profit even to pay the interest on their own debt, but remain in existence because the financial system allows for the constant rollover of this liability. They do not innovate, they do not grow, they do not increase productivity.
According to an article by Granzotto et al. (2025) in the Brazilian Review of Finance, which compares companies in various emerging markets, on average 7.6% of firms are "static zombies" (firms with EBITDA/Financial Expenses < 1) and 5.5% are "dynamic zombies" (EBITDA/Financial Expenses >/= 1) in these markets.
In the Brazilian case, 16.75% of companies are classified as static zombies and 13.94% as dynamic zombies! In other words, more than double the average for emerging markets. The authors themselves bluntly state that Brazil is the "heart of the zombie economy" among emerging markets, about 2.3 times above the international standard.
To clarify what this means: we are talking about companies that cannot generate enough profit to cover their financial costs, meaning that investors will have to wait longer to recover their principal, and that workers will be employed in firms without the capacity to invest in new technologies and processes that could improve their human capital and productivity.
The article shows that this mass of zombie companies distorts capital allocation, reduces aggregate productivity, and weakens investment dynamics. Credit, labor, and resources are trapped in financially fragile firms, while more productive companies face a hostile financing environment. And this, of course, has a cost in terms of potential economic growth.
As long as the Brazilian government does not address the problem of reforming the business environment and its capital markets, these types of inefficiencies will continue to persist and condemn workers and investors to remain trapped in firms that should be defunct.
SOURCE: https://t.co/a8MPL6y7xz
#Economía #econtwitter #Economics #Finance #Brazil
The EU Council appear ready to approve Chat Control. This must be stopped. To highlight the corruption behind the proposal, Mullvad VPN now present "And Then?"
The backstory: https://t.co/rwbbh0DoKH