Vista elenco

Aggiornamenti di sicurezza Apple

7 Agosto 2026 ore 16:26
Aggiornamenti di sicurezza Apple sanano una vulnerabilità con gravità "alta", presente in macOS Sonoma, macOS Sequoia e macOS Tahoe. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un utente malintenzionato non autenticato di eludere i meccanismi di autenticazione sui sistemi target.

Hulp gezocht bij update PT8.2 - Help wanted to update to 8.2

Ik gebruik PT voor mijn video’s en livestreams etc. Maar omdat ik niet super bedreven ben in het onderhouden van de server zoek ik hulp bij het updaten naar PT 8.2

Stuur mij een berichtjes (voorkeur voor iemand in NL)

I am using PT for my video’s and livestreams etc. But I am not fluent in server maintenance so: I am looking for somebody that can help me with upgrade and maintenance.

Just send me a message (I am in The Netherlands).

Cheers Stefan

4 messages - 3 participant(e)s

Lire le sujet en entier

WarrenGuard, tunnel QUIC en Rust sous AGPL

Bonjour à tous !

Bon, je ne sais pas si c’est le bon endroit pour parler de ça, n’hésitez pas à me reprendre si ce n’est pas le cas, aucun souci.

Ça fait environ 10 ans que j’héberge le chaton p2p.legal, mon service le plus connu est peut-être notre instance PeerTube tube.p2p.legal. Pour ceux qui me connaissent, je suis aussi l’un des développeurs principaux du projet Duniter, pour la monnaie libre Ğ1.

Aujourd’hui j’ai le plaisir de vous annoncer qu’on ouvre la bêta gratuite de notre VPN Warren: https://warren.ro

La raison pour laquelle j’en parle ici, c’est qu’on essaie de se différencier du reste du secteur en mettant au cœur le logiciel libre et l’esprit de partage communautaire, et qu’on ne sort pas ça de nulle part juste pour surfer sur une vague. On a recréé un moteur de VPN from scratch en Rust, qu’on a appelé WarrenGuard, basé sur QUIC, conçu pour que ton trafic ressemble à de la navigation web ordinaire plutôt qu’à un tunnel VPN identifiable. On ne bloque pas ce qu’on ne voit pas. C’est le cœur de notre démarche, et il est publié en AGPL-3.0: GitHub - WarrenBrowse/warrenguard: Generic VPN-over-QUIC engine (AGPL-3.0), the data-plane behind Warren VPN · GitHub

Je n’en dis pas plus, le site et notre livre blanc donneront plus d’infos aux curieux que ça intéresse.

C’est une bêta, donc il peut y avoir des bugs, des choses pas claires, et vos avis nous sont précieux: ici, sur notre forum, ou en issue GitHub. Et si quelque chose dans notre discours vous fait tiquer, dites-le franchement, c’est aussi pour ça que je viens en parler ici plutôt qu’ailleurs.

On y a mis tout notre cœur, j’espère que ça se verra. Je suis vraiment curieux d’avoir des retours de libristes venus d’ici :slight_smile:

Au plaisir !
poka

2 messages - 2 participant(e)s

Lire le sujet en entier

House Democrats Demand Answers From Trump’s VA on Vets Struggling to Access Mental Healthcare

7 Agosto 2026 ore 12:00
A man wearing glasses and a red and blue tie.
Department of Veterans Affairs Secretary Doug Collins received a letter signed by more than 60 lawmakers citing a recent ProPublica investigation that detailed how the agency has failed to provide veterans with adequate mental healthcare. Samuel Corum/Getty Images

What Happened: More than 60 House Democrats are pressing Department of Veterans Affairs Secretary Doug Collins for answers about how the agency’s mental healthcare has been increasingly strained under President Donald Trump’s second administration. The lawmakers sent the secretary a letter last week asking questions about the state of VA care, citing a ProPublica investigation from this spring that revealed the agency’s mental health workforce has been plummeting and veterans have been left in the lurch.

What They Said: The letter was spearheaded by Rep. Judy Chu, who is a psychologist and represents a district in Southern California. “Caring for our nation’s Veterans is a fundamental responsibility,” the letter says. “That includes ensuring access to high-quality mental health care.”

The lawmakers demanded that the VA disclose details about its shortage of mental health providers and the impact on veterans. It also pushed the agency to lay out how long veterans have to wait for care.

As ProPublica has detailed, while the VA has long had a shortfall of mental health providers, the situation has gotten far worse under the current Trump administration. Hundreds of mental health staffers have left the VA and not been replaced.

Background: ProPublica’s investigation recounted the troubling experiences of both mental health providers and of veterans seeking care.

With so many staffers leaving and not being replaced, the remaining providers have often been stretched remarkably thin.

A psychologist who worked for a VA in Arizona recounted how some of her one-on-one sessions were replaced with online group sessions that included as many as 35 veterans. The therapist said their remaining individual sessions were sometimes limited to as little as 16 minutes.

“It was always bad,” said the psychologist. “And now it’s at a breaking point.”

In VA exit surveys that ProPublica obtained, mental health staffers who quit often wrote that they were no longer able to provide high-quality care.

“Mental Health is understaffed, burned out,” wrote one New York-based staffer who was leaving. “There is not enough mental health care for the Veterans who need the services.”

Veterans, meanwhile, have started to fall through the cracks.

Jason Beaman, a Navy and Army vet, was shuffled among therapists who later left until he finally had enough. “I just quit. I don’t want to mess with the therapist anymore,” Beaman told us this spring.

Why It Matters: After Trump returned to office last year, his administration promised to deliver veterans “the highest quality care.”

The VA is the country’s largest healthcare system, serving 9 million veterans. Those men and women face many mental health issues at a higher rate than the general population. They die by suicide at roughly twice the rate.

VA mental health staff have developed deep expertise in addressing the particular needs of vets. Indeed, studies have shown that vets get better care at the VA than through private providers.

“VA psychologists are best in class,” said Russell Lemle, former chief psychologist for the San Francisco VA Health Care System and now a senior policy analyst at the Veterans Healthcare Policy Institute. “When you lose them, the veterans are the ones who pay the price.”

ProPublica reported that in January, the department had around 500 fewer psychologists and psychiatrists than it had at the same time last year. Recent VA data shows those head counts continue to decline.

Response: In response to questions from ProPublica, VA spokesperson Quinn Slaven defended the agency. “The Trump Administration is solely focused on measuring VA’s success by how well it serves Veterans,” Slaven wrote in an email. “This commonsense approach has led to dramatic improvements for Veterans, families, caregivers, and survivors across the country.”

Slaven said that the VA completed a record number of mental healthcare appointments in the past fiscal year while also lowering veterans’ wait times.

The VA previously declined our request for an interview. Instead, spokesperson Peter Kasperowicz accused ProPublica of attempting to mislead the public by “cherry picking issues that are limited to a handful of sites and in many cases were worse under the Biden Administration.”

After ProPublica shared the findings of its investigation and the names of veterans who would appear in it, the agency reached out to several to inquire about their care and offer help.

The congressional letter gives the VA until Aug. 14 to respond.

The post House Democrats Demand Answers From Trump’s VA on Vets Struggling to Access Mental Healthcare appeared first on ProPublica.

Risolta vulnerabilità in prodotti Sophos

7 Agosto 2026 ore 11:47
Rilasciato aggiornamento di sicurezza che risolve una vulnerabilità con gravità “critica” presente nei prodotti “Sophos Endpoint for macOS” e “Sophos Home for macOS”. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un utente malintenzionato di elevare i propri privilegi, e/o eseguire codice arbitrario sui sistemi interessati.

Aggiornamenti per prodotti Autodesk

7 Agosto 2026 ore 11:06
Aggiornamenti di sicurezza Autodesk risolvono 5 vulnerabilità, di cui 4 con gravità “alta”, che interessano i prodotti AutoCAD, Civil 3D, Advance Steel e Revit. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un utente malintenzionato di accedere ad informazioni sensibili, compromettere la disponibilità del servizio ed eseguire codice arbitrario sui sistemi interessati.

What Is the Trump Administration Doing With Foreign Aid Money?

7 Agosto 2026 ore 11:00
President Donald Trump sits in a gold patterned arm chair holding up a printed article to a crowd, next to South Africa President Cyril Ramaphosa, who is looking at him. Both men are in suits.
In a 2025 meeting, U.S. President Donald Trump held up a printed article from American Thinker while accusing South Africa President Cyril Ramaphosa of state-sanctioned violence against white farmers in South Africa. Chip Somodevilla/Getty Images

Since he returned to office, President Donald Trump’s administration has upended foreign aid. It’s labeled well-established, long-running programs as “not aligned with American interests” and slashed their budgets. 

Still, the billions of taxpayer dollars Congress has allocated for foreign aid programs must be spent; lawmakers have insisted the government continue to fund humanitarian aid, global health and pro-democracy causes around the world. With most of the old programs now gone, however, we wanted to know: What is the Trump administration doing with that money now?

Recently, we published our investigation that found one answer to that question in a little-known bureau of the State Department that has dramatically transformed under Trump. For decades, the Bureau of Democracy, Human Rights and Labor, known as DRL, has supported  human rights in some of the most oppressive countries in the world. Now, our reporting found,  it’s planning to direct funds to controversial groups supporting right-wing causes in Europe and elsewhere. 

Our full story lays out some of the groups the government has considered funding, which include a British free-speech organization that has fought against bans on “gay conversion therapy” and a British American think tank created this year to focus on “existential threats to Britain, to America, and to our shared Judeo-Christian civilisation.” (Administration officials dropped that grant after significant pushback from Congress.) 

One proposed grant particularly caught our attention: Trump administration officials suggested funding research on crime against minority populations in South Africa. 

It’s clear from sources we spoke with that the key targeted minority population in question is the white ethnic group known as Afrikaners. Afrikaners were responsible for creating the nation’s infamous and brutal racially segregated apartheid system. Previously, DRL staff had been told to begin the process of awarding funds to a group called Lex Libertas, which was founded by a controversial figure who has called for Afrikaner self-governance. The group is currently fundraising to place 3,000 white crosses on the National Mall in remembrance of attacks on South African farmers.

The proposed grant was later opened up to allow a broader set of invited groups to apply for $1 million of funding, though it is still intended for the same purpose, according to people with knowledge of the process. The State Department declined to say whether Lex Libertas will be among those invited to compete, citing ongoing deliberations, but said the Trump administration has serious concerns about the human rights situation in South Africa that need to be addressed. Lex Libertas did not respond to questions about the organization or the proposed grant.

Former diplomats who have worked extensively on human rights told us they were shocked that the victimization of white South Africans would be prioritized over the serious issues elsewhere in the region. 

“It’s laughable to suggest that on the African continent, the prime issue of human rights concern is whites in South Africa,” one former agency official said when we asked him about the grant. South Africa is plagued by violence, but extensive research has found that white South African farmers are not victims of crime at higher rates than other groups.

Experts also described the proposed grant to fund research into violence against Afrikaners as keeping with the Trump administration’s overall stance toward South Africa.

For decades, the U.S. relationship with the country has been symbolized by our massive support for HIV care, Mattie Webb, a professor at the Virginia Military Institute who studies South Africa and U.S. foreign policy, told us. 

Since Trump returned to office, there’s been a stark shift as the administration has strengthened ties with borderline white nationalist groups that are considered fringe in South Africa. 

“The U.S. is very clearly shifting its priorities away from aid that would benefit far more people in South Africa to this narrow focus on the white minority,” Webb said.

In the last 18 months, Trump has argued there is a genocide of white South Africans and used claims that white people are subjected to disproportionate violence to justify cutting off U.S. funding for HIV treatment and research. And even as he’s barred nearly all new refugees from the United States, he’s welcomed white South Africans, fast-tracking their entry.  

There have long been tensions between South Africa and the U.S., former diplomats told us, but the aid the U.S. provided saved lives and helped sustain a working relationship that is vital to U.S. national security and economic interests. Now, by seeking to fund a movement antagonistic to the South African government, the U.S. risks driving a wedge between the two nations.

Other grants also raised red flags for experts and lawmakers. Political appointees at the State Department are considering funding a British free-speech organization that has fought bans on discredited therapy practices that attempt to convert gay people to heterosexuality. That proposed $5 million grant would provide support for people facing “deplatforming” and advocate against “restrictive online safety and hate speech laws,” according to a document we reviewed. (The organization’s founder said it had “neither applied for nor been awarded a grant from the US State Department or any other branch of the US Government” but did not respond to our other questions.) And a call for proposals recently released by the bureau would fund research, conferences and cultural engagements in wealthy democracies to develop “civilizational self-confidence in Europe.” 

Not all the proposed funding is directed to controversial groups, our reporting found. But even some of the grants slated to fund more traditional human rights projects skirt federal requirements for competitive bidding that are meant to deter waste, fraud and abuse. Instead, officials are trying to direct millions to handpicked organizations, according to sources and documents. 

In response to questions about our reporting, the State Department stressed that the process of awarding grants is ongoing and that multiple offices provide input, writing that “programs are still in active deliberation and receipt of a grant is not guaranteed to any organization that does not meet all requirement and standards for federal grants.” 

We are continuing to report on foreign aid and the Trump administration’s policies in South Africa. If you have tips or information we should know about either of these issues, please feel free to get in touch with us! Reach out via phone or Signal to Anna Maria Barry-Jester at 408-504-8131 or Sharon Lerner at 718-877-5236.

The post What Is the Trump Administration Doing With Foreign Aid Money? appeared first on ProPublica.

I 5 migliori servizi DNS protettivi (PDNS) del 2026

7 Agosto 2026 ore 09:54
I 5 migliori servizi DNS protettivi (PDNS) del 2026

Trovare i migliori servizi DNS protettivi (PDNS) è diventato un passo fondamentale per la sicurezza informatica di aziende e professionisti. Infatti un servizio PDNS agisce come un guardiano per le tue connessioni, analizzando ogni richiesta DNS e bloccando l'accesso a domini malevoli in modo automatico.

Oggi, strumenti che un tempo erano considerati una "best practice" sono diventati una necessità. Persino agenzie come la NSA e la CISA ne raccomandano l'adozione. Si tratta di una delle misure di sicurezza più efficaci e meno invasive che puoi implementare, perfettamente integrata nei moderni framework di sicurezza a "zero trust".

In questa guida, analizzeremo le 5 soluzioni più performanti sul mercato, con un verdetto rapido per chi ha fretta. Sei pronto a scoprire quale servizio si adatta meglio alle tue esigenze? Continua a leggere.

Cosa sono i servizi DNS protettivi (PDNS)?

Immagina il DNS (Domain Name System) come la rubrica di Internet. Quando digiti un sito web, il DNS traduce quel nome in un indirizzo IP numerico che i computer possono capire, migliorando la tua navigazione web.

Un servizio DNS protettivo fa un passo in più: prima di fornirti l'indirizzo, controlla se quel dominio è presente in una lista di minacce note. Se il dominio è associato a phishing, malware, ransomware o comandi C2 (Command and Control), il PDNS semplicemente rifiuta la connessione. In questo modo, la minaccia viene neutralizzata sul nascere, prima che possa causare danni. È un livello di protezione proattivo, essenziale per difendere ogni dispositivo connesso alla rete.

La nostra classifica dei migliori servizi DNS protettivi

Abbiamo valutato i principali servizi basandoci sui criteri raccomandati da NSA e CISA:

  • Qualità e velocità di aggiornamento dei feed di minacce,
  • Capacità di rilevamento avanzato (come DGA e tunneling),
  • Opzioni di copertura per dispositivi fissi e mobili
  • Integrazione con i sistemi di sicurezza esistenti (SOC).

1. Cisco Umbrella

Ideale per grandi aziende che cercano lo standard di riferimento del settore, collaudato e con integrazioni mature. Cisco Umbrella è considerato l'evoluzione di OpenDNS ed è da anni il punto di riferimento nel mercato PDNS. La sua forza risiede nell'intelligence fornita da Talos, uno dei team di ricerca sulle minacce più grandi al mondo. Offre funzionalità avanzate come il rilevamento di algoritmi di generazione di domini (DGA) e tunneling DNS, garantendo una protezione completa.

Caratteristiche principali:

  • Intelligence sulle minacce fornita da Talos.
  • Rilevamento di DGA e tunneling DNS.
  • Integrazione con Active Directory per l'attribuzione interna degli IP.
  • Client per la protezione dei dispositivi in mobilità.

Pro: Profondità dell'intelligence, scalabilità comprovata, vasto ecosistema di integrazioni.

Contro: Il costo può essere elevato e le funzioni più recenti tendono a integrarsi strettamente con l'ecosistema Cisco Secure Access.

2. DNSFilter

Ideale per piccole e medie imprese (PMI) e Managed Service Provider (MSP) che necessitano di una protezione efficace, veloce da implementare e con prezzi chiari. DNSFilter brilla per la sua trasparenza e semplicità. Utilizza il machine learning per categorizzare i domini in tempo reale e offre un modello di prezzo per utente chiaro e prevedibile. La sua console di gestione multi-tenant è un vero punto di forza per gli MSP che devono gestire la sicurezza di più clienti contemporaneamente.

Caratteristiche principali:

  • Categorizzazione dei domini basata su ML in tempo reale.
  • Prezzi pubblici e scalabili per utente.
  • Piattaforma nativa per la gestione multi-tenant (MSP).
  • Client inclusi per la copertura dei dispositivi mobili.

Pro: Prezzi trasparenti, onboarding rapidissimo (meno di un'ora), strumenti eccellenti per MSP.

Contro: Meno profondità nelle integrazioni enterprise rispetto a Cisco Umbrella.

3. Cloudflare Gateway

Ideale per chiunque voglia iniziare a proteggersi immediatamente, con un piano gratuito solido e un percorso di crescita verso funzionalità avanzate. Cloudflare Gateway sfrutta una delle reti di resolver DNS più veloci e resilienti al mondo. Offre un generoso piano gratuito che permette a chiunque di iniziare a filtrare le minacce in pochi minuti. Man mano che le esigenze crescono, è possibile passare a piani a pagamento che includono SWG, ZTNA e CASB, tutto dalla stessa dashboard. Non a caso, è la tecnologia scelta dal governo britannico per il suo PDNS nazionale.

Caratteristiche principali:

  • Rete di resolver anycast enorme e veloce.
  • Piano gratuito e piani Zero Trust a prezzi pubblici.
  • Supporto nativo per DNS-over-HTTPS (DoH) e DNS-over-TLS (DoT).
  • Client WARP per la protezione dei dispositivi in mobilità.

Pro: Si passa da zero a protetti in un pomeriggio, infrastruttura su scala globale, un percorso di crescita flessibile.

Contro: L'attribuzione avanzata tramite Active Directory richiede più configurazione rispetto a Umbrella.

4. Akamai

Ideale per governi, operatori di telecomunicazioni e grandi aziende che necessitano di una risoluzione protettiva su larghissima scala. Akamai Secure Internet Access opera su una delle piattaforme più grandi di Internet. È progettato per assorbire attacchi DDoS massicci e proteggere intere basi di abbonati per gli ISP. La sua forza sta nella vastità della sua infrastruttura e nella visibilità globale che ne deriva per la ricerca sulle minacce.

Pro: Scala e affidabilità massicce, ricerca sulle minacce di alto livello.

Contro: Pacchetti pensati per il mondo carrier/enterprise; il valore massimo si ottiene se si è già clienti Akamai.

5. Infoblox

Ideale per aziende con un'infrastruttura DNS interna complessa che vogliono fondere il PDNS con il contesto DDI (DNS, DHCP, IPAM). Infoblox adotta un approccio unico, applicando l'intelligence sulle minacce direttamente ai resolver DNS che già gestisci. Sfruttando il contesto IPAM, può dirti esattamente quale dispositivo ha effettuato una richiesta malevola e attivare risposte automatiche per metterlo in quarantena.

Pro: Attribuzione nativa delle minacce, applicazione delle policy a livello di infrastruttura.

Contro: Il modello di costo presume l'adozione della piattaforma DDI di Infoblox.

Come scegliere tra i migliori servizi DNS protettivi

La scelta dipende dalle tue esigenze specifiche.

Prima di decidere, poniti alcune domande chiave:

  • Qualità delle minacce: Con quale velocità vengono bloccati i nuovi domini malevoli? Richiedi dati concreti.
  • Copertura dei dispositivi: Hai bisogno di proteggere solo la rete dell'ufficio o anche i laptop dei dipendenti da remoto? Verifica la disponibilità di agenti per i dispositivi mobili.
  • Gestione del DNS criptato: Il servizio offre i propri endpoint DoH/DoT per garantire che il traffico non bypassi la protezione?
  • Logging e integrazione: Puoi esportare i log per analizzarli nel tuo SIEM?
  • Prezzo: Il modello di costo è trasparente e adatto al tuo numero di utenti?

Confronta due o tre finalisti in base ai precedenti punti. La trasparenza dei prezzi di servizi come DNSFilter rende questo confronto molto più semplice.

Domande frequenti (FAQ) sui PDNS

L'argomento può essere complesso e la scelta può non essere ancora chiara, per questo abbiamo selezionate le domande più frequenti sul tema:

Cos'è esattamente un PDNS? È un servizio di risoluzione DNS che controlla ogni richiesta confrontandola con database di minacce. Se una richiesta è diretta a un dominio malevolo (phishing, malware), viene bloccata prima che la connessione venga stabilita.

Perché NSA e CISA lo raccomandano? Perché è una difesa ad alto impatto e a basso attrito. La maggior parte degli attacchi informatici utilizza il DNS in qualche fase. Bloccarli a questo livello è estremamente efficace e l'implementazione richiede solo di cambiare gli indirizzi dei resolver DNS.

Un PDNS può proteggere dispositivi senza agenti (IoT, stampanti)? Sì, questo è uno dei suoi maggiori vantaggi. Impostando il PDNS a livello di rete (es. nel router), ogni dispositivo che si connette, inclusi ospiti e dispositivi IoT, viene protetto automaticamente senza agenti.

Quanto costa un servizio DNS protettivo? I costi variano molto: si parte dai piani gratuiti di Cloudflare, si passa ai prezzi pubblici per utente di DNSFilter e si arriva alle quotazioni personalizzate per piattaforme enterprise come Cisco Umbrella o Akamai.

Qual è il verdetto finale?

In sintesi, possiamo dire che i migliori servizi DNS protettivi sono:

  • Cisco Umbrella, che si conferma lo standard per le grandi aziende.
  • DNSFilter, è la scelta di valore predefinita per PMI e MSP.
  • Cloudflare Gateway, che offre un percorso incredibilmente versatile, perfetto per chiunque.
  • Akamai, perfetto per la scala carrier.
  • Infoblox, pensato per l'integrazione DDI.

Ogni servizio ha i suoi punti di forza e di debolezza, ma l'aspetto più importante è sempre quello di agire. Infatti implementare un PDNS è un passo che non puoi più rimandare per proteggere al meglio la tua attività.

L'articolo I 5 migliori servizi DNS protettivi (PDNS) del 2026 proviene da sicurezza.net.

❌