Sign in

Renato Gabriele

@remagio.bsky.social
158 followers 254 following 46 posts

I thrive on high-country trekking and trail riding. For sport, I do systems forensics while building new things. “If you have a garden in your library, nothing will be lacking.” Marcus Tullius Cicero

PostsRepliesMedia
Reposted by Renato Gabriele
Andrea Draghetti @andreadraghetti.bsky.social · 8h
Tosint v1.0.0 is out: an open-source Telegram OSINT tool for bot and chat analysis, message history and media exports. Richer JSONL metadata, optional SHA-256 hashes, and bot/user authentication. github.com/drego85/tosi... #OSINT #DFIR #Telegram #Tosint #CTI
github.com
GitHub - drego85/tosint: Tosint is a Telegram OSINT tool that extracts actionable intelligence from bot tokens and chat IDs for security investigations.
Tosint is a Telegram OSINT tool that extracts actionable intelligence from bot tokens and chat IDs for security investigations. - drego85/tosint
021
Reposted by Renato Gabriele
Riccardo Coluccini @orariccardo.bsky.social · 12h
L’UE aveva davanti l’occasione della vita: raccogliere dati sui consumi di tutti i data center in Europa come mai nessuno ha potuto fare prima. I dati sarebbero stati la base per garantire trasparenza ai cittadini e regolarne lo sviluppo. Non è andata così www.lighthousereports.com/investigatio...
lighthousereports.com
Data Centre Silence
How EU leaders sided with Big Tech over the public’s right to know about the true scale and environmental impact of the AI build-out, forcing a legal challenge to seek disclosure
154
Reposted by Renato Gabriele
Martin Shelton @mshelton.bsky.social · 28/09/2026
Come work with our team! We're hiring a Sr. Digital Security Trainer. You would lead digital security trainings for journalists, conduct organizational risk assessments, contribute to our editorial efforts, and help to develop our curriculum. freedomofthepress.na.teamtailor.com/jobs/708479-...
freedomofthepress.na.teamtailor.com
Sr. Digital Security Trainer - Freedom of the Press Foundation (FPF)
FPF is hiring a senior digital security trainer to conduct in-field digital security training with journalists and newsrooms.
0817
Reposted by Renato Gabriele
Kenn White @kennwhite.bsky.social · 29/09/2026
So proud of this: real-time highly scalable distributed generalized database search on fully encrypted data, what we call Queryable Encryption is now out of beta. Culmination of 25+ years of academic work and 7 years of R&D engineering leadership under @senykamara.com and Tarik Moataz... (1/2)
1117
Reposted by Renato Gabriele
Filippo Valsorda @filippo.abyssdomain.expert · 28/09/2026
I'm excited to announce that the PLC Organization now has a statute! And a bank account! And a @standard.site publication! All the important stuff. The PLC Org is an independent Swiss Association meant to operate the PLC directory, which collects and distributes signed updates to atproto accounts.
blog.plcred.org
First steps of the PLC organization - Public Ledger of Credentials Organization
One year ago, Bluesky Social PBC announced their intention to facilitate the creation of an independent organization to operate the Public Ledger of Credenti…
425157
Reposted by Renato Gabriele
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 25/09/2026
Italian zero-day maker Dataflow Security generated €63 million in revenue in three years, and the company also has strong ties with former Israeli intelligence veterans, according to an investigation by @irpimedia.eu. irpimedia.irpi.eu/en-inside-th...
irpimedia.irpi.eu
Inside the secretive cyberweapons company that won over Israel’s intelligence elite
Founded in Italy by a young hacker, Dataflow develops code to break into computers and smartphones. Since January, its operations in Israel have been led by Eyal Tsir Cohen, a former senior Mossad off...
0147
Reposted by Renato Gabriele
adafruit @adafruit.com · 23/09/2026
This IoT project listens for messages on LoRa networks and displays them on a tri-color e-ink learn.adafruit.com/meshfruit-me... #3dprinting #adafruit youtu.be/FxuyWbHRbRs
1333
Reposted by Renato Gabriele
Space Rogue @spacerog.bsky.social · 21/09/2026
All these AI companies seem to think that when their pet escapes, it proves just how smart and capable their creation is. Maybe. To me, it mostly proves they built a crappy cage. Capability without containment isn't a breakthrough. It's a security failure.
1142
Reposted by Renato Gabriele
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 21/09/2026
~ Personal news ~  I left TechCrunch. I will now focus on finishing my book about Hacking Team and the history of government spyware. After that, and in the meantime as well, I will be freelancing. Contact me: Lorenzofb.writes@gmail.com or Signal @LorenzoFB.1337 (+1 917 257 1382)
A masked puppet comes out of a keyboard.
89624
Reposted by Renato Gabriele
Miro Haller @mirohaller.bsky.social · 21/09/2026
We finally finished the universal signature forgery for 1024-bit RSA! 2^32 oracle queries, 1200 core years precomputation, 180 core years for an individual forgery, and 3 years of human labor (no AI involved) by Laura, Adam, Nadia, Emmanuel and me to pull of this computation against real HSMs.
14019
Reposted by Renato Gabriele
adafruit @adafruit.com · 21/09/2026
radio can/does have a user interface ...did some fruit jam work and now have software-defined radio projects we'll be publishing ...
2364
Reposted by Renato Gabriele
evacide @evacide.bsky.social · 14/09/2026
The real reason I spend so much time at the circus school is that I have been slowly developing an immunity to clowns. This allows me to continue to do tech policy.
1342665
Reposted by Renato Gabriele
Dominic White @singe.bsky.social · 11/09/2026
I added post-quantum authentication (ML-DSA) checks to QuantumHello, thanks to the ML-DSA support in go 1.27 from @filippo.abyssdomain.expert and others. quantumhello.xyz
quantumhello.xyz
QuantumHello
Check whether a site supports post-quantum encryption.
032
Reposted by Renato Gabriele
Filippo Valsorda @filippo.abyssdomain.expert · 11/09/2026
Oh damn I had not seen the details of the MicroTik RCE: the client can send a public RSA key with correct N and e = 1 and the server will use it. Two primitives/protocol things that would have prevented it: if RSA was defined with a fixed e, and if SSH clients sent a key hash instead.
github.com
CVE-2026-67276 - GitHub Advisory Database
RouterOS does not compare the complete RSA public key...
26016
Reposted by Renato Gabriele
adafruit @adafruit.com · 04/09/2026
Build an IOT CO2 sensing bird to alert you of the air quality levels! This bird alerts you when it detects high levels of CO2 Guide: learn.adafruit.com/iot-canary #3dprinting #adafruit #iot youtu.be/Zy6EItdtGv8
1132
Reposted by Renato Gabriele
Randall Munroe @xkcd.com · 28/08/2026
Perseids xkcd.com/3287/
4-panel comic. (1) [Three people. The person on the left has shoulder-length hair; the person on the right has a white hat.] PERSON 1: I’m sad that we missed the Perseids. PERSON 2 with hat: There’s still the Geminids. PERSON 1: Yeah, but they’re in December. (2) PERSON 1: The Perseids happen when it’s warm enough to lie outside with a blanket, and we found a good mosquito-free beach. So we just lie around watching the stars and eating snacks. One year we saw the aurora. (3) PERSON 3 with shoulder-length hair: You know, I think I heard that the Perseids might be late this year. PERSON 2: Yeah, actually, I heard that too. (4) Later… [Three people lying down gazing up at stars in dark sky. One meteor is in the sky.] PERSON 3: Hm, seems like a normal number of meteors. Guess I heard wrong. PERSON 1: Maybe the Perseids are *next* weekend. PERSON 2: Oh, good thinking. Let’s come back then, just in case.
82105270
Renato Gabriele @remagio.bsky.social · 28/08/2026
There is an annoying bug that pops up every 2 releases, since ever. You open a linked post, on Android, and you get back in the app, but it reset and restart the app like at first opening... The only fix is waiting for the next update, often it need two updates @support.bsky.team
000
Reposted by Renato Gabriele
Julia Angwin @juliaangwin.com · 27/08/2026
It’s good that Meta is creating some bare-bones safety features for kids, but a far better option would be to make these platforms safe for everyone. Shouldn’t we all be protected from Big Tech’s predations? My latest @nytopinion.nytimes.com (gift link). www.nytimes.com/2026/08/27/o...
nytimes.com
Opinion | Meta Settles. Finally. (Gift Article)
Meta’s settlement is far from perfect, but every blow counts as the company declines.
1278
Reposted by Renato Gabriele
Lea Kissner @leak.bsky.social · 21/08/2026
I can't believe that our book, "Building Safer Technology: A Field Guide to Failing Well" is here NOW. Learn how to build safely -- security, privacy, trust&safety, AI safety, etc. We concentrate on the underlying thinking and skills so this is durable knowledge even as technology changes.
Copy of the book "Building Safer Technology: A Field Guide to Failing Well"
1359
Reposted by Renato Gabriele
Filippo Valsorda @filippo.abyssdomain.expert · 17/08/2026
I am mostly done implementing crypto/passkey, but now I need YOUR help collecting real-world traces for its test suite! Please go to help-test-crypto-passkey.exe.xyz and click the buttons. It should take 1–3 minutes. 𝘌𝘴𝘱𝘦𝘤𝘪𝘢𝘭𝘭𝘺 if you have some unusual Linux-on-the-desktop xkcd 1987 passkey setup.
Bernie "I Am Once Again Asking for Your Financial Support" but it says "I am once again asking for your help testing Go cryptography."
1411441
Reposted by Renato Gabriele
Joseph Cox @josephcox.bsky.social · 17/08/2026
New from 404 Media: we solved which AI company is buying massive shipments of rare books, scanning and destroying them to train AI. We put an Apple AirTag in a rare book, followed it. It ended up at an Amazon facility. Its logo is a dinosaur ripping through a book www.404media.co/we-tracked-a...
404media.co
We Tracked a Shipment of Rare Books. It Ended at an Amazon AI Training Facility
We placed a tracking device in a shipment of rare books to see which AI company was buying it, and found an Amazon facility where Amazon scans and destroys books.
12537932368
Reposted by Renato Gabriele
Filippo Valsorda @filippo.abyssdomain.expert · 15/08/2026
I think something broke in my relationship with the tech world. Not due to AI, but to threads like this. I thought my community cared about reality. I block ads with uBO Lite in Chrome. Anyone has access to verify this reality by experience. And yet pages and pages of comments on... not reality.
news.ycombinator.com
Firefox is now the last major browser that still supports uBlock Origin | Hacker News
2515511
Reposted by Renato Gabriele
Andy Greenberg @agreenberg.bsky.social · 06/08/2026
Two security researchers shipped me a pink plastic kid's smartwatch from Amazon. When I wore it, they tracked my movements, surreptitiously took photos of me, even listened to my conversations. The same backend they hacked is used by 30+ watch brands for kids. 🧵👇 www.wired.com/story/hacker...
wired.com
Hackers Stalked Me by Hijacking a Smartwatch for Kids
Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets.
11732480
Reposted by Renato Gabriele
GrapheneOS @grapheneos.org · 06/08/2026
Revolut recently banned using GrapheneOS without any justification. They're falsely claiming to do be doing it for security reasons. In reality, they're enforcing licensing Google Play. Revolut doesn't enforce security standards. It runs on Android 9 with no patches since 2018.
319736
Reposted by Renato Gabriele
Lorax Horne @lorax.bsky.social · 03/08/2026
AI will never become a good writer, because a machine can never feel the pleasure of hearing words flow through a mind.
041
Reposted by Renato Gabriele
Dominic White @singe.bsky.social · 02/08/2026
Those “public wifi is fine now” people are going to hate Microsoft’s good advice for the SVR abuses of hospitality captive portals. www.microsoft.com/en-us/securi... “When traveling, users should treat hotel, conference, airport, & other guest wireless networks as untrustworthy.”
microsoft.com
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order ...
032
Reposted by Renato Gabriele
Joseph Cox @josephcox.bsky.social · 31/07/2026
Took me seconds to make an image showing 'protesters' around Google buildings, using Google Earth's new AI generation tool. You can make bomb blasts, protesters, drone strikes, nuclear plants. How on earth did Google think this was a good idea www.404media.co/google-earth...
fake ai generated protesters around google buildings, made with the new google earth ai tool
321959368
Reposted by Renato Gabriele
Faine Greenwood @faineg.com · 31/07/2026
I used to do some work on the ethical use of satellite and drone imagery for aid and disaster response, and it is genuinely hard to express in words what a dangerous, stupid thing Google is doing by making it easy to use GenAI to create faked satellite imagery:
digitaldigging.org
How to plant a nuclear plant in Iran
The question is: what on earth is Google doing?
742396895
Reposted by Renato Gabriele
FlokiNET ehf @flokinet.bluesky.flokinet.social · 31/07/2026
delete that password spreadsheet
Cartoon man pointing accusingly at his own reflection in a mirror. Caption: "WHEN YOU FINALLY FIND THE WEAKEST LINK IN THE SECURITY CHAIN".
001
Reposted by Renato Gabriele
Dominic White @singe.bsky.social · 29/07/2026
I realised some people* were using a super out-of-date version of hostapd-mana based off the upstream 2.6 branch instead of the newer 2.10 branch. This was probably because I never made the 2.10 branch the main. Well that’s fixed now. github.com/sensepost/ho... * me - see last commit for an eg
github.com
GitHub - sensepost/hostapd-mana: SensePost's modified hostapd for wifi attacks.
SensePost's modified hostapd for wifi attacks. Contribute to sensepost/hostapd-mana development by creating an account on GitHub.
061
Reposted by Renato Gabriele
Zack Whittaker @zackwhittaker.com · 29/07/2026
Over on Mastodon (I strongly recommend), @doublepulsar.com asked fellow defenders what's on their radars and how much of what they're actively dealing with is AI-related. The responses are overwhelmingly, no. ClickFix attacks and phone calls/social engineering remain among the top threats.
cyberplace.social
Kevin Beaumont (@GossiTheDog@cyberplace.social)
Sense check for people working in cybersecurity in operations roles in the trenches: I’m not finding or seeing cyber incidents off the back of Generative AI still. Are you? Not ones you’ve read about...
34017
Reposted by Renato Gabriele
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 29/07/2026
This is a great explainer of the OpenAI hack against Hugging Face, particularly of the report that the latter published earlier this week. If you had trouble parsing the highly technical report, this article can walk you through it.
techcrunch.com
The Hugging Face AI break-in, as told through an increasingly committed bear metaphor | TechCrunch
Another way to think about the whole thing is to picture a bear at a campsite. (Really, we are going there.)
0188
Reposted by Renato Gabriele
Filippo Valsorda @filippo.abyssdomain.expert · 29/07/2026
I know it’s not most folks‘ primary concern, but LLMs or not, I’m unimpressed by how soft these infrastructure services are. What do you mean HF had a Jinja2 template injection. And I’m still not over GitHub’s unsandboxed RCE. Geomys might need to self-host code/CI to avoid a weak link.
1020119
Reposted by Renato Gabriele
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 25/07/2026
An example of the fall of a security civilization: Cisco collapsing multiple different vulnerabilities into one CVE. It breaks a lot of feeds & products built to manage risk & is non compliant with standards like ISO 29147 Vulnerability disclosure sec.cloudapps.cisco.com/security/cen...
sec.cloudapps.cisco.com
Cisco's Transition to a Risk-Based Vulnerability Disclosure Model
46217
Reposted by Renato Gabriele
derek guy @dieworkwear.bsky.social · 24/07/2026
watched the odyssey last night. film ruined by everyone speaking english instead of ancient greek.
667182741589
Reposted by Renato Gabriele
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 24/07/2026
The guardrails were coming from inside the (White)house - Anthropic’s models refused to help Hugging Face analyze their intrusion. We don’t need more guardrails impeding defenders when they need AI most. “Hugging Face tried using Anthropic Fable 5 & Opus …both models refused, citing guardrails…”
2193
Reposted by Renato Gabriele
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 23/07/2026
The experiment escaped the lab. OpenAI's models broke containment and breached Hugging Face. We are holding radium in our bare hands. What governments and organizations should do next, and why tighter commercial guardrails are exactly the wrong move: www.lutasecurity.com/post/openfac...
lutasecurity.com
OpenFace: The Hugging Face Breach and What to Do About It
These models are like the world's cleverest octopus escape artists, with unlimited prehensile arms and the ability to squeeze through anywhere. A single vulnerable package proxy stood between the mode...
35716
Reposted by Renato Gabriele
Firewalls Don't Stop Dragons @firewalldragons.bsky.social · 21/07/2026
Every surveillance device in a public space should be legally required to emit an RF beacon (eg, BTLE) announcing its presence. Ideally, this would include make, model, and operator contact info. This includes Flock, video doorbells, traffic cams, etc.
031
Reposted by Renato Gabriele
Filippo Valsorda @filippo.abyssdomain.expert · 21/07/2026
Passkeys can be stored just like password hashes! I'm proposing an interoperable $webauthn$v=1$… format, and a Go API that uses these passkey records for authentication. I'm looking for feedback before proposing this as crypto/passkey for Go 1.28!
words.filippo.io
Opaque, Interoperable Passkey Records (and a Go API)
Passkey records are an interoperable format for WebAuthn credentials, similar to password hash strings. I propose a potential crypto/passkey Go API based on them.
519741
Reposted by Renato Gabriele
Rachel Tobac @racheltobac.bsky.social · 21/07/2026
Was curious if I could use AI (Graylark) to find coordinates of this house using just a *reflection in a keypad* of the surroundings. Well...it worked. YIKES. Daniel Heinen does not make this AI tool available to the public for this reason. youtube.com/shorts/Xzbvi...
youtube.com
Can AI geolocate using just reflections?!
YouTube video by SocialProof Security
1189
Reposted by Renato Gabriele
The Citizen Lab @citizenlab.ca · 17/07/2026
Join the Citizen Lab in Calgary at the 26th Privacy Enhancing Technologies Symposium (PETS). Senior researchers @jsrailton.bsky.social and Rebekah Brown will be speaking, and Citizen Lab researchers are presenting their analysis of censorship on Amazon. Register: web-eur.cvent.com/event/fbb91d...
web-eur.cvent.com
Registration Details - PETS 2026
Privacy Enhancing Technologies Symposium 2026
0114
Reposted by Renato Gabriele
The Citizen Lab @citizenlab.ca · 17/07/2026
WATCH: Last week, the European Parliament had a debate on #spyware after we found that a former MEP's phone was hacked with #Pegasus. The consensus: the crisis is getting worse. @hneumannmep.bsky.social @saskiabricmont.bsky.social @lukassiepermdep.bsky.social @danusenerudova.bsky.social
01811
Reposted by Renato Gabriele
Etienne - Tek @tek.randhome.io · 16/07/2026
Inside Pegasus: The evolution of the world’s most notorious spyware system securitylab.amnesty.org/latest/2026…
035
Reposted by Renato Gabriele
Ryan Naraine @ryanaraine.bsky.social · 06/07/2026
Buried on p9 and p30 of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking WATCH youtu.be/mx0CpTp3Q4Y?...
youtu.be
Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen
YouTube video by Three Buddy Problem
177
Reposted by Renato Gabriele
Andrea Barisani @andreabarisani.bsky.social · 15/07/2026
The recent addition of a Google Compute Engine Virtual Ethernet (gVNIC) driver in TamaGo now allows networked GCP Confidential VMs. A small, reproducible, memory-safe unikernel, yet allowing use of the entire Go ecosystem, all measured at launch as a single binary.
072
Reposted by Renato Gabriele
Deth Veggie @dethveggie.bsky.social · 15/07/2026
Make no mistake: This is hacktivism.
05320
Reposted by Renato Gabriele
evacide @evacide.bsky.social · 14/07/2026
This Certo report on how abusers are using Chrome sync for stalking is an important reminder that tech-enabled abuse isn't just limited to stalkerware: www.certosoftware.com/insights/cyb...
certosoftware.com
Cyberstalkers Are Exploiting Chrome Sync to Spy on Victims | Certo Software
Certo's research team reveals how cyberstalkers are quietly switching the signed-in account in Google Chrome to remotely monitor victims' browsing history and saved passwords with no warning ever show...
110852
Renato Gabriele @remagio.bsky.social · 09/07/2026
Damn, I cannot but #NoHatGo it's definitely one of the best sec gathering where to go. Then check winter #HackinBo edition too ;) My 2 cents
000
Reposted by Renato Gabriele
No Hat Con @nohatcon.bsky.social · 06/07/2026
KEYNOTE UNLOCKED_ Excited to have @weld.bsky.social opening up our conference with his Keynote: “WHEN EVERY ATTACKER CAN HAVE A RESEARCH TEAM” > Access talk details: nohat.it/talks #nohat2026 #CyberSecurity #InfoSec
053
Reposted by Renato Gabriele
Benn Jordan @bennjordan.bsky.social · 08/07/2026
Oh cool, an Easter egg feature that traps you in a driverless car and kidnaps you when it's decided you've misbehaved. Imagine what a hacker group or ICE can do with this. The fact that this is even functionally possible is horrifying.
882846819