Sign in

Gillo

@alicudi.bsky.social
115 followers 452 following 40 posts

Activism and infosec. "If you’re not living on the edge, you’re taking up too much space." Cross Mastodon posting on: @gillo@infosec.exchange

PostsRepliesMedia
Gillo @alicudi.bsky.social · 18/09/2026
New Global Witness report: 124 land and environmental defenders were killed globally in 2025, with 85% of deaths in Latin America. Read "Collective power" to learn more about the urgent fight to protect these communities. globalwitness.org/en/campaigns... #activism #environment #globalwitness
globalwitness.org
002
Gillo @alicudi.bsky.social · 09/09/2026
nteresting take by @proton.me on the importance of RSS for security and privacy matters. (I just wish they published it on their blog and not Substack…) protonprivacy.substack.com/p/rss-read-t... #RSS #Privacy #Security #infosec
protonprivacy.substack.com
RSS: Read The Internet Without It Reading You
Sometimes, the old ways are better...
001
Gillo @alicudi.bsky.social · 30/08/2026
Great article by @micahflee about the history of Autistici/Inventati and the potential consequences of the US designating it a terrorist organization. micahflee.com/the-server-c... #AutisticiInventati #activism
micahflee.com
The Server Called Paranoia: Defend Autistici/Inventati
For twenty-five years, an Italian hacker collective has built communications infrastructure designed to survive censorship, surveillance and police raids. On August 26, the United States designated it...
003
Reposted by Gillo
CrimethInc. Ex-Workers' Collective @crimethinc.com · 26/08/2026
The US government has designated the Italian collective Autistici/Inventati, which produces the infrastructure of NoBlogs.org, a "Specially Designated Global Terrorist," freezing their assets and prohibiting all transactions with them——citing their "far-left" politics for justification.
cryptobriefing.com
United States sanctions Autistici/Inventati for supporting far-left terrorism
The US designated Italy-based tech collective Autistici/Inventati as a global terrorist entity, freezing assets and banning transactions over
13472277
Gillo @alicudi.bsky.social · 22/08/2026
Indie Web is definitely punk! indiewebispunk.net #indieweb
indiewebispunk.net
The IndieWeb Is Punk Manifesto
Three chords and a domain name. A manifesto for the DIY web.
000
Reposted by Gillo
DuckDuckGo @duckduckgo.com · 30/07/2026
No camera. No AI. Just Normal Sunglasses. From DuckDuckGo x @Knockaround. (Yes, these are actually real. Get a pair here: knockaround.com/products/duc...)
23473195
Gillo @alicudi.bsky.social · 18/07/2026
Passwork, a Spain-based password manager used by European government agencies and universities, shares technological ties with a Russian counterpart #infosec www.occrp.org/en/investiga...
occrp.org
European Password Manager Shares Origins and Updates with State-Certified Russian Firm
Passwork, a Spain-based password manager used by European government agencies and universities, shares technological ties with a Russian counterpart — an arrangement that experts say poses a state-lev...
000
Gillo @alicudi.bsky.social · 28/05/2026
Javier Bardem explaining how corporate bullies abuse SLAPPs to shut up journalists, whistleblowers and activists? Yeah, he understood the assignment 😏 #javierbardem #YasminFinney #slappsuit #activism #greenpeace youtu.be/ai5COjEQ9og?...
youtu.be
SLAPP Suit (ft. Javier Bardem & Yasmin Finney)
YouTube video by Greenpeace International
031
Gillo @alicudi.bsky.social · 21/03/2026
ODF FTW!! itsfoss.com/news/germany... #odf #germany #opensource
itsfoss.com
Big Win for Open Source as Germany Backs Open Document Format
The Deutschland-Stack names ODF and PDF/UA as the only permitted document formats for German public administrations.
020
Gillo @alicudi.bsky.social · 25/02/2026
breach.txt is a password wordlist built from real-world passwords found in breaches, forum dumps, leaked logs, and other underground sources. Interesting to check if you’re into password forensics. weakpass.com/wordlists/br... #infosec #passwords #breaches
weakpass.com
000
Gillo @alicudi.bsky.social · 29/01/2026
Nobody is immune from phishing attacks. Not even Signal users. Signal has published a good article warning about phishing risks on their platform. Remember to always setup a Signal username instead of sharing your phone number. support.signal.org/hc/en-us/art...
support.signal.org
Staying Safe from Phishing, Scams, and Impersonation
We provide a privacy-first, end-to-end encrypted (E2EE) messaging and calling platform designed so only you and your intended recipients can communicate securely. Even with strong encryption, attac...
021
Gillo @alicudi.bsky.social · 28/01/2026
Using AI to process sensitive files?it happens also to the best (clowns). #US #infosec #AI www.politico.com/news/2026/01...
politico.com
Trump’s acting cyber chief uploaded sensitive files into a public version of ChatGPT - POLITICO
The interim director of the Cybersecurity and Infrastructure Security Agency triggered an internal cybersecurity warning with the uploads — and a DHS-level damage assessment.
010
Gillo @alicudi.bsky.social · 19/12/2025
As the year wraps up, here’s a roundup of the year’s worst, weirdest, and most impactful data breaches. Enjoy the break and keep your infosec antennas up during the holidays. www.eff.org/deeplinks/20...
eff.org
The Breachies 2025: The Worst, Weirdest, Most Impactful Data Breaches of the Year
Another year has come and gone, and with it, thousands of data breaches that affect millions of people. The question these days is less, Is my information in a data breach this year? and more How many...
010
Gillo @alicudi.bsky.social · 11/12/2025
Welcome to the US. But first, hand over your social media life. www.theguardian.com/us-news/2025... #usa #trump #tourism
theguardian.com
Tourists to US would have to reveal five years of social media activity under new Trump plan
Plan would apply to countries not currently required to get visas to the US, including Britain and France
020
Gillo @alicudi.bsky.social · 19/11/2025
Yesterday’s event with Trump and Mohammed  bin  Salman was already a horror show, and it got even worse when it was followed by a dinner with the tech bros, Cristiano Ronaldo, and a whole crew of suck‑ups. www.nytimes.com/2025/11/18/u...
nytimes.com
Who Attended Trump’s Dinner for the Saudi Crown Prince?
020
Gillo @alicudi.bsky.social · 10/11/2025
In the new multi-channel social engineering landscape, LinkedIn is one of the main breeding grounds for phishing attacks. This article, even if biased given its sponsor, gives a good overview of the risks. www.bleepingcomputer.com/news/securit... #socialengineering #phishing #infosec #linkedin
bleepingcomputer.com
5 reasons why attackers are phishing over LinkedIn
Attackers are increasingly phishing over LinkedIn to reach executives and bypass email security tools. Push Security explains how real-time browser protection detects and blocks phishing across apps a...
020
Gillo @alicudi.bsky.social · 17/10/2025
Very good article by the excellent Cory Doctorow about how digital activism and climate activism actually have a ton in common - really interesting connections between the two movements and how they’re tackling similar challenges. #climate #environment #activism doctorow.medium.com/https-plural...
doctorow.medium.com
The curious, intertwined history of climate and digital rights activism
It’s going much [better|worse] than expected.
012
Gillo @alicudi.bsky.social · 09/10/2025
Germany has committed to oppose the EU’s controversial “Chat Control” regulations which means most likely that this law will not be accepted by the EU council next week. Germany’s position was influenced by huge pressure from multiple activists.  www.theregister.com/2025/10/08/g... #infosec
theregister.com
Germany slams brakes on EU's Chat Control snoopfest
: Berlin's opposition likely kills off Brussels' bid to scan everyone's messages
041
Gillo @alicudi.bsky.social · 09/10/2025
Sora and AI generated videos are a game changers in terms of mis/disinformation: they are making it impossible to trust what we see in videos—deepfakes are now mainstream and everyone needs to be skeptical. #ai #deepfakes #sora #openai #disinformation www.nytimes.com/2025/10/09/t...
nytimes.com
What the Arrival of A.I.-Fabricated Video Means for Us
043
Gillo @alicudi.bsky.social · 05/10/2025
Geeez…. The US administration is really running out of funds. They don’t even have enough money to buy privacy screens. www.theguardian.com/us-news/2025... #infosec #shouldersurfing
theguardian.com
White House official inadvertently reveals plans to send elite army unit to Portland | US military | The Guardian
Anthony Salisbury displayed chat about deployment of 82nd airborne division on cell phone while in Minnesota
010
Gillo @alicudi.bsky.social · 26/09/2025
The EU “Chat Control” law would scan everyone’s messages, breaking encryption and risking digital rights for all—kids included. Experts & civil groups say it’s dangerous. Sign to stop mass surveillance: crm.edri.org/stop-scannin...
crm.edri.org
Children deserve a secure and safe internet | EDRi CiviCRM
010
Gillo @alicudi.bsky.social · 24/09/2025
Original post: mastodon.archive.org/@internetarc...
000
Gillo @alicudi.bsky.social · 23/09/2025
Attackers move beyond email-based phishing, personal accounts (messengers, social media, etc.) are being targeted more often than work ones and regular phishing campaign trainings might create a false sense of security. #phishing #socialengineering #infosec www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Why attackers are moving beyond email-based phishing attacks
Phishing isn't just email anymore. Attackers now use social media, chat apps & malicious ads to steal credentials. Push Security explains the latest tactics and shows how to stop multi-channel phishin...
010
Gillo @alicudi.bsky.social · 22/09/2025
Amazing news in the activism and human rights world edition.cnn.com/2025/09/22/m...
edition.cnn.com
Alaa Abd El-Fattah pardoned: Egyptian president orders release of prominent activist, state media reports | CNN
Egypt’s President Abdel Fattah el-Sisi has ordered the release of prominent activist Alaa Abd El-Fattah, the Egyptian state-run outlet Al Ahram reported on Monday.
000
Gillo @alicudi.bsky.social · 01/09/2025
GPS jamming at work… www.politico.eu/article/ursu...
politico.eu
Von der Leyen’s plane hit by suspected Russian GPS jamming
Commission president was on a tour of frontline states when her plane was the target of interference.
000
Gillo @alicudi.bsky.social · 19/08/2025
And now… Bad bad UK!! Cracking down on VPNs is a horrible idea. gizmodo.com/uk-official-...
gizmodo.com
UK Official Calls for Age Verification on VPNs to Prevent Porn Loophole
The call comes as governments go to war with the anonymous web.
000
Gillo @alicudi.bsky.social · 19/08/2025
Well done UK (although it took US pressure…) www.theverge.com/news/761240/...
theverge.com
UK drops demand for backdoor into Apple encryption
Here’s hoping that ADP returns to the UK.
000
Reposted by Gillo
Freedom of the Press Foundation @freedom.press · 07/08/2025
📣 Are you aware of journalists being harassed at immigration courts? Officers photographing them or their press badges? Being asked to sign in when others aren't? @freedom.press and our partner organizations want to know about it. Reach out on Signal to ssugars.01 or via DM.
08253
Gillo @alicudi.bsky.social · 10/08/2025
Imagine if AI chatbots’ popularity had started just before COVID… futurism.com/man-poisons-...
futurism.com
Man Follows ChatGPT's Advice and Poisons Himself
An older man learned the hard way that ChatGPT isn't to be trusted with health advice after the toxic chatbot landed him in the hospital.
010
Gillo @alicudi.bsky.social · 07/08/2025
techcrunch.com/2025/08/06/c...
techcrunch.com
Citizen Lab director warns cyber industry about US authoritarian descent | TechCrunch
Ron Deibert, the head of the prominent digital human rights groups Citizen Lab, sounds the alarm at the Black Hat security conference about the "dramatic descent into authoritarianism," but one that t...
000
Gillo @alicudi.bsky.social · 08/07/2025
Nobody is immune to deepfakes, and definitely not the current US administration www.theguardian.com/us-news/2025... #ai #infosec #deepfakes #marcorubio #socialengineering
theguardian.com
AI scammer posing as Marco Rubio targets officials in growing threat | US news | The Guardian
Fake voice and text messages on Signal tricked senior leaders, as AI impersonation rises in global politics
010
Gillo @alicudi.bsky.social · 20/06/2025
Very good article by @micahflee.com about using Signal groups for activism. Some new tips there like creating announcement-only groups for rapid response and using QR codes during physical meetings. micahflee.com/using-signal... #infosec #signal #activism #security #privacy
micahflee.com
Using Signal groups for activism
Things are heating up. Millions of people are taking to the streets against Trump's rising authoritarianism. Communities around the US are organizing to defend against ICE raids, to protest Israeli ge...
087
Gillo @alicudi.bsky.social · 18/06/2025
Researchers found out that recently a million SMS two-factor authentication codes and login information were intercepted!  As expected, authenticator apps or security keys are the best solution. www.lighthousereports.com/investigatio... #infosec #2FA #leaks #sms
lighthousereports.com
Two Factor Insecurity
How Google, Amazon, Meta and thousands of other companies leave customers vulnerable over one-time codes to save time and money
010
Gillo @alicudi.bsky.social · 13/06/2025
More on how to secure your phone before a protest. www.theverge.com/21276979/pho... #protest #activism #surveillance #USA #privacy #infosec
theverge.com
How to secure your phone before attending a protest | The Verge
Here are some privacy measures you can take
010
Gillo @alicudi.bsky.social · 13/06/2025
Interesting WIRED article about how law enforcement uses facial recognition and phone tracking at protests. www.wired.com/story/how-to... #protest #surveillance #infosec #USA
wired.com
How to Protest Safely in the Age of Surveillance | WIRED
Law enforcement has more tools than ever to track your movements and access your communications. Here’s how to protect your privacy if you plan to protest.
021
Gillo @alicudi.bsky.social · 12/06/2025
New forensic research proves two Italian journalists were hacked using government spyware made by Israeli surveillance tech provider Paragon. techcrunch.com/2025/06/12/r... #spyware #paragon #journalists #italy #infosec
techcrunch.com
Researchers confirm two journalists were hacked with Paragon spyware | TechCrunch
The confirmation of two hacked victims further deepens an ongoing spyware scandal that, for now, appears largely focused on the Italian government.
000
Gillo @alicudi.bsky.social · 30/05/2025
Frontline Defenders have updated their Guide to Protect Information while Traveling. Although the guide’s target audience is usually at-risk human rights defenders, it’s still a great article for general security guidelines. securityinabox.org/en/assess-pl... #infosec #opsec
securityinabox.org
Protect your information and devices while traveling
Protect your information and devices while traveling
000
Gillo @alicudi.bsky.social · 18/05/2025
Besos investing in Saudi Arabia, the country guilty of killing one of his journalists, is as disgusting as it sounds. #amazon #bezos #saudiarabia #mbs #ai #humanrights #kashoggi www.theverge.com/amazon/66791...
theverge.com
Jeff Bezos makes his most ghoulish deal yet | The Verge
Freedom of the press ain’t free.
001
Gillo @alicudi.bsky.social · 30/04/2025
Apple sent notifications this week to several people who the company believes were targeted with government spyware. techcrunch.com/2025/04/30/a... #infosec #apple #spyware
techcrunch.com
Apple notifies new victims of spyware attacks across the world | TechCrunch
Two alleged victims came forward claiming they received a spyware notification from Apple.
000
Gillo @alicudi.bsky.social · 23/04/2025
AI has been a gift from Heaven for social engineers... www.securitymagazine.com/articles/101... #deepfakes #socialengineering #infosec
securitymagazine.com
Deepfake-enabled fraud caused more than $200 million in losses
In Q1 2025, deepfake-driven fraud led to $200 million in financial losses.
010
Reposted by Gillo
ваят @denbib.bsky.social · 21/04/2025
U.S. governmental visits turning deadly
011
Gillo @alicudi.bsky.social · 17/04/2025
A new US company, Massive Blue, is helping law enforcement agencies deploy AI-powered social media bots to interact with suspected criminals. Unfortunately this can also be used against activists… www.wired.com/story/massiv... #activism #ai #deepfakes #socialengineering
wired.com
This ‘College Protester’ Isn’t Real. It’s an AI-Powered Undercover Bot for Cops | WIRED
Massive Blue is helping cops deploy AI-powered social media bots to talk to people they suspect are anything from violent sex criminals all the way to vaguely defined “protesters.”
002
Gillo @alicudi.bsky.social · 09/04/2025
Just lovely… Spyware maker NSO, still on the US Commerce Department’s “blacklist,” has hired a new lobbying firm with direct ties to the Trump administration. www.wired.com/story/nso-gr... #spyware #nso #trump #infosec
wired.com
Spyware Maker NSO Group Is Paving a Path Back Into Trump’s America | WIRED
The Israeli spyware maker, still on the US Commerce Department’s “blacklist,” has hired a new lobbying firm with direct ties to the Trump administration, a WIRED investigation has found.
000
Reposted by Gillo
ваят @denbib.bsky.social · 26/02/2025
For almost two years,Chinese hackers stole sensitive data and captured 10% of the incoming and outgoing emails of the Belgian intelligence service (VSSE). According to sources, it’s the most serious security incident ever experienced by the VSSE. www.lesoir.be/657866/artic...
lesoir.be
Des hackers chinois ont volé des données sensibles à la Sûreté de l’Etat
Durant près de deux ans, des hackers à la solde de l’espionnage chinois ont exploité la brèche d’une cybersociété américaine pour siphonner 10 % des courriels entrants et sortants du service de rensei...
001
Gillo @alicudi.bsky.social · 23/01/2025
I decided to "bridge" my Mastodon account to Bsky, so my posts will appear here: @gillo.infosec.exchange.ap.brid.gy If you want your Bluesky account to be discoverable on Mastodon, just follow @ap.brid.gy here on Bluesky
000