Vista elenco

Controler validité adresse mail saisie dans formulaire

Je viens de créer un formulaire pour faire une pétition. Votre outil est excellent, c’est du très bon travail. Bravo à toute l’équipe.

Comme vous avez bloquer la modification de la structure des emails comment faire maintenant pour vérifier si une adresse email saisie sur le formulaire est valide ?

Merci de votre réponse…

Bonne fin de journée

1 message - 1 participant(e)

Lire le sujet en entier

Commentaires sur Khrys’presso du lundi 10 août 2026 par Jérôme

Mes chers amis de Framasoft,

Cela fait des années ( 15 ? ) que je donne à Framasoft tous les mois. Je dois avouer que plus le temps passe plus le militantisme politique et sociale ( et sexuel ! ? ) de Framasoft me gène. N’y a t’il pas eu un tournant ces dernières années sur ces thèmes ?

Ce à quoi tu résiste persiste, ce que tu juges tu deviendras et ce que tu condamnes te condamnera.
Parfois il faut prendre de la hauteur et je ne prends plus vraiment de plaisir à lire ce qui provient de vous mes chers amis, notamment ce Khryspresso, auquel je préfère les cerises de hiatus, https://lescerisesdehiatus.bearblog.dev/ . Je pense prendre mes distances et me conforter avec l’APRIL, que je trouve plus posé, plus centré, moins dans le jugement et plus dans l’apport de solutions.

Soyez heureux, soyez libres.

Framateam - Discussions indépendantes

Bonjour, dans mon association, j’essaie de convaincre de passer de MS 365/Teams à des outils Framasoft. Mais je fais face a une résistance assez farouche.

Pour ce qui concerne Framateam, outre l’absence d’integration avec framaspace pour le partage de document, ce qui bloque, c’est le manque de possibilité d’avoir des discussions séparées dans un canal. Avec Teams, il y a 2 mode :

  • discussion continue, comme Framateam, ou tous les échanges sont mélés
  • discussions séparées ou chaque discussion reste indépendante

Cette fonctionnalité existe-t-elle ?

Merci

5 messages - 2 participant(e)s

Lire le sujet en entier

Risolte vulnerabilità in ClamAV

10 Agosto 2026 ore 11:31
Aggiornamenti di sicurezza Cisco sanano 7 vulnerabilità con gravità "alta" presenti in ClamAV, software open source per l'analisi antivirus. Tra queste si evidenziano le CVE-2026-20337 e CVE-2026-20338 per le quali il vendor conferma la presenza di Proof of Concept (PoC) disponibili in rete.

More Than Half the Homes in East Omaha Have Unsafe Lead Levels. That Doesn’t Mean the EPA Will Clean Them Up.

10 Agosto 2026 ore 11:00
A woman with long auburn hair wearing a white shirt, checkered pants and a necklace with a cross holds a toddler turned away from the camera wearing a blue dress, beaded bracelet and hairclip.
Omaha resident Natalie Thorpe’s 3-year-old tested high for lead as a baby. Thorpe’s yard has enough lead to be risky but not enough to qualify for government cleanup. Rebecca S. Gratz for ProPublica

Despite hundreds of millions of dollars spent on environmental cleanup, more than half the yards in a section of Omaha, Nebraska, that used to surround a lead smelter still have enough contamination to cause high blood-lead levels in kids, according to tests by the Flatwater Free Press and ProPublica.

The findings were consistent across the city’s older urban core — in the historically Black neighborhoods north of downtown, the predominantly Hispanic areas to the south and the more white and affluent areas in midtown. However, homes closest to where a lead smelter and other downtown factories operated tended to have slightly higher concentrations than those farther out.

As part of the Environmental Protection Agency’s Superfund program, the federal government and the city of Omaha have been attempting to remove lead from Omaha’s yards since the late 1990s. 

The EPA’s cleanup standard for Omaha was set in 2009 and is based on health recommendations from 1994. Since then, research has shown that lower exposures can cause IQ loss in kids and heart attacks in adults. Twice in the last 15 years, the Centers for Disease Control and Prevention lowered what it considers a high blood-lead level. An EPA risk model found that to protect most kids according to those new health guidelines, soil levels would have to be below 100 parts per million — about 10 grains of rice in a 10-pound bucket of dirt.

The Flatwater Free Press and ProPublica tested 388 homes in the Omaha Superfund site and found that 208 had levels over 100 parts per million.

But the EPA has never required that level of cleanup in Omaha or as a national remediation standard. Current EPA policy for the Omaha cleanup site directs contractors to dig up and replace yards if tests show they contain more than 400 parts per million of lead — about a marble’s worth of the metal dispersed across a 10-gallon bucket of dirt. Last week, the Flatwater Free Press and ProPublica reported that 1 in 10 of the homes we tested that were remediated still has a lead concentration over that threshold

The risk worries Natalie Thorpe, whose 3-year-old daughter tested high for lead as a baby. When the history and English teacher bought a house in Omaha, she knew about the Superfund site, but friends assured her the EPA had taken care of any problems with the dirt. Instead, her yard has enough lead to be risky but not enough to qualify for government cleanup.

“It feels a little bit like being a sitting duck,” Thorpe said.

A toddler wearing a blue dress and a beaded bracelet holds a yellow tomato. She is surrounded by leaves and flowers that are out of focus.
Thorpe’s 3-year-old picks a tomato from their garden. Rebecca S. Gratz for ProPublica

EPA spokesperson Kellen Ashford said removing lead in soil is only one factor in protecting communities. Because no level of lead in the body is safe and it would be impossible to remove all lead from a site, the agency works with local health officials to protect the community from lead risks in other ways, he said. 

Those include establishing the Omaha Lead Registry, a website where people can search for the highest lead level and remediation status of any property in the site. The EPA also funds the Douglas County Health Department’s lead poisoning prevention program, which performs home visits when a child tests high for exposure to the toxic metal. 

Cleanup, combined with these other layers of protection, has led to a dramatic decline in elevated blood-lead levels in Omaha, Ashford said. (While the percentage of kids testing high for lead has dropped significantly, as it has nationally, kids in the Omaha site still test high for lead at rates above the national average.)

Work on lead has historically been focused on protecting people from extreme poisonings, often caused by paint, said Tom Neltner, who heads the lead poisoning prevention nonprofit Unleaded Kids. As more public health experts have acknowledged the risks of smaller exposures, they’ve had to examine soil more closely. Confronting that will require new research and renewed advocacy, he said.

But even with updated science, politics have complicated potential cleanups. The first step in any cleanup is to identify which properties deserve attention. So the EPA typically tests soil to screen for potential problem areas. If results hit a certain level of lead concentration, it kicks off a more in-depth process of monitoring that site and discussing cleanup options. In 2024, President Joe Biden’s EPA lowered that recommended screening level to as little as 100 parts per million. 

Cleaning up to 100 parts per million would have carried enormous costs. About 40% of U.S. homes exceed those levels, according to a 2024 study by some of the country’s top researchers of lead-contaminated soil, and it could cost $500 billion to $1.4 trillion to clean up all of them. The authors argued the government could take a more cost-effective approach by covering lead-laced soil with clean soil or mulch rather than digging it out. 

Last year, the Trump administration rolled back Biden’s standards in what it said was an effort to speed up cleanups of the highest-risk areas, raising the lowest screening level from 100 parts per million to 200 parts per million.

A woman in checkered pants and a toddler wearing a blue dress stand outside with their backs to the camera. The woman is standing over a tank filled with plants, and the toddler stands in the tank. The backyard has a green lawn, brown wooden fence and potted plants. Trees, other houses and power lines can be seen beyond the fence.
Thorpe and her daughter pick vegetables from their raised garden bed. Zinnias, basil, golden beets, squash and other plants grow in store-bought soil. Rebecca S. Gratz for ProPublica

However, some local and state governments, as well as other countries, have committed to standards of 100 parts per million or lower.

Norway recommends risk assessments for any dirt that children have regular access to that has more than 100 parts per million of lead in it. In 2006, the country required all playgrounds and daycares be remediated to that level.

Even in the United States, some areas have lower limits. Minnesota requires replacing any soil that has more than 100 parts per million of lead around the home of a child with a high blood level, said Minnesota Department of Health spokesperson Scott Smith. In April, New Orleans announced plans to clean up its parks after an investigation by Verite News and KFF Health News found more than half of the 80 sites the organizations tested had levels above 100 parts per million.

California has cleaned up properties to 80 parts per million of lead, its screening level for potentially risky soil, though residents of properties exceeding that threshold more often receive safety education rather than a new lawn, said Seth John, a University of Southern California earth sciences professor.

Do You Live in Council Bluffs or Carter Lake, Iowa? Sign Up for Free Lead Testing of Your Soil.

An Omaha lead smelter spread dust that seeped into the soil and bodies of many residents. The EPA spent decades cleaning up the surrounding area — but not Council Bluffs, Carter Lake or Bellevue.

This summer the EPA is testing soil around Omaha as part of an investigation that may help the agency determine if it should expand the site’s boundaries or lower the amount of lead that would qualify for cleanup. The agency expects to share its findings by October 2027, Ashford said.

Earlier research suggests there may be more homes with lead-soil concentrations over 100 parts per million than the Flatwater Free Press and ProPublica identified: EPA testing found 84% of the Superfund site in Omaha — more than 36,000 properties — had areas with lead concentrations above 100 parts per million, according to a March 2024 email sent by an EPA manager to a Nebraska Department of Environment and Energy official. 

But trying to determine what the agency might do in Omaha is difficult because the EPA has applied its new guidance in different ways, setting higher lead levels for cleanup at some Superfund sites and lower levels at others.

Without cleanup, there are several things Omaha residents can do to lower their risk, said Neltner of Unleaded Kids. Maintaining ground cover like grass reduces the amount of lead dust that can spread from the dirt to kids’ hands and bodies, he said. The EPA also recommends washing hands and taking shoes off inside. 

Those are easy things that lower risk, Neltner said, but he noted that they’re not a long-term solution. 

“We have to keep doing what we can,” he said. “We need our leadership at local, state and federal levels to support people in finding solutions.”

A toddler’s bare feet rest in soil. The photo is framed by flowers and leaves that are out of focus.
Thorpe’s 3-year-old daughter stands barefoot in her family’s garden. Rebecca S. Gratz for ProPublica

The post More Than Half the Homes in East Omaha Have Unsafe Lead Levels. That Doesn’t Mean the EPA Will Clean Them Up. appeared first on ProPublica.

Attacco alla supply chain di WordPress tramite un'API malevola

10 Agosto 2026 ore 10:39
Attacco alla supply chain di WordPress tramite un'API malevola

L'attacco alla supply chain di WordPres tramite un'API avvelenata rappresenta una nuova e insidiosa frontiera negli attacchi alla sicurezza. Immagina questo scenario: hai installato plugin popolari e affidabili e mantieni tutto aggiornato, ma il tuo sito viene compromesso ugualmente. Come è possibile? Ora non stiamo più parlando di un classico plugin con una falla nel codice. La vulnerabilità, in questo caso, è molto più subdola e colpisce la cosiddetta "supply chain", ovvero la catena di fiducia su cui si basa l'intero ecosistema di WordPress. Infatti in recente incidente ha dimostrato come gli hacker possano sfruttare non il plugin in sé, ma le risorse esterne a cui si collega.

Analizziamo nel dettaglio come funziona questo attacco e, soprattutto, come puoi proteggere il tuo sito.

Come funziona l'attacco alla supply chain di WordPress?

L'attacco ha preso di mira diversi plugin molto noti sviluppati da BdThemes, tra cui Element Pack, Prime Slider e Ultimate Post Kit. Questi strumenti utilizzano un componente interno per mostrare banner promozionali nella bacheca di WordPress. Per farlo, si collegano a un server esterno e recuperano i dati da un semplice file JSON. Ed è proprio qui che si nasconde il problema.

Gli aggressori non hanno violato il repository di WordPress.org né hanno modificato il codice sorgente dei plugin. Hanno invece trovato il modo di compromettere il file JSON ospitato sul server esterno. In pratica, hanno "avvelenato" la fonte dei dati. Il componente del plugin, fidandosi ciecamente di questa fonte, recuperava le informazioni malevole.

A causa di una vulnerabilità di tipo cross-site scripting (XSS), il codice dannoso veniva eseguito direttamente nel browser dell'amministratore del sito non appena accedeva a una qualsiasi pagina del back-end. Un'operazione silenziosa, che si completa in pochi millisecondi e apre le porte del sito agli aggressori.

Per approfondire questo tema, leggi anche il nostro articolo "Attacchi alla supply chain: una minaccia in crescita".

Quali sono le conseguenze per i siti WordPress?

Una volta che il codice malevolo è in esecuzione, le conseguenze possono essere devastanti. L'attacco è progettato per ottenere il controllo completo e persistente del sito compromesso, agendo su più livelli.

Creazione di amministratori fantasma e backdoor

Il primo passo dello script è creare un nuovo account amministratore-truffa. Spesso questi account usano nomi utente prevedibili, come "bd_" seguito da una stringa di caratteri, garantendo agli aggressori un accesso privilegiato e diretto al sito. Successivamente, il malware installa un finto plugin con un nome innocuo, come "wp-smart-thumbnails". Al suo interno, però, si nasconde una webshell: un file, spesso chiamato emer-run.php, che permette agli hacker di eseguire comandi sul server da remoto, come se fossero seduti di fronte al tuo computer.

Meccanismi di persistenza e occultamento

Gli aggressori non si sono fermati al primo accesso, ma hanno puntato alla persistenza. Per assicurarsi di poter rientrare anche se l'account admin venisse scoperto, installavano dei Must-Use plugin. Si tratta di plugin speciali che sono sempre attivi e non possono essere disattivati dalla bacheca.

Infine, per rendere tutto più difficile da scoprire, il malware manipolava il database per nascondere l'account amministratore-truffa dalla normale lista degli utenti. Alterava persino il contatore totale per non destare sospetti: un'operazione studiata per eludere i controlli.

Come rilevare e mitigare l'attacco alla supply chain di WordPress

Anche se la fonte dell'attacco è stata bonificata, il tuo sito potrebbe essere già compromesso. Ecco una checklist pratica per verificare la sicurezza del tuo sito WordPress:

  • Controlla gli account amministratore: vai nella sezione Utenti e cerca profili sospetti che non hai creato tu. Presta particolare attenzione a username che iniziano con "bd_" o che utilizzano email strane.
  • Ispeziona i plugin installati: verifica la lista dei tuoi plugin e, se ne trovi uno che non ricordi di aver installato, indaga. Controlla anche la cartella mu-plugins tramite FTP o il File Manager del tuo hosting.
  • Cerca file malevoli: esegui una scansione dei file del tuo sito alla ricerca di nomi sospetti come emer-run.php o file che iniziano con class-wp-query-.
  • Verifica il database: se hai competenze tecniche, cerca nel database opzioni sospette, come fz_emer_login_tokens, che è legata a questo specifico attacco.

L'uso di un plugin di sicurezza affidabile può aiutarti ad automatizzare molte di queste verifiche e a ricevere notifiche in tempo reale.

Una lezione per il futuro: la fiducia non basta

Questo attacco alla supply chain di WordPress è un potente campanello d'allarme per tutta la community. Ci insegna che la sicurezza non riguarda solo il codice che installiamo sul nostro server, ma anche la catena di fiducia che si estende a servizi e API esterne. Infatti un plugin può essere scritto in modo impeccabile, ma se si affida a una risorsa esterna non sicura, diventa un cavallo di Troia. Inoltre questi attacchi non hanno colpito solo WordPress, ma in passato hanno coinvolto anche GitHub.

Per gli sviluppatori la lezione è chiara: ogni dato proveniente dall'esterno deve essere validato e sanificato prima di essere utilizzato. Per gli utenti, invece, la consapevolezza di questi nuovi vettori di attacco è il primo passo per una difesa più efficace.

Ricordati sempre che la sicurezza non è un'azione una tantum, ma un processo continuo di vigilanza e manutenzione.

L'articolo Attacco alla supply chain di WordPress tramite un'API malevola proviene da sicurezza.net.

Khrys’presso du lundi 10 août 2026

Comme chaque lundi, un coup d’œil dans le rétroviseur pour découvrir les informations que vous avez peut-être ratées la semaine dernière.


Tous les liens listés ci-dessous sont a priori accessibles librement. Si ce n’est pas le cas, pensez à activer votre bloqueur de javascript favori ou à passer en “mode lecture” (Firefox) ;-)

Brave New World

Spécial IA

Spécial Israël

Spécial femmes dans le monde

Spécial France

Spécial femmes en France

Spécial médias et pouvoir

Spécial emmerdeurs irresponsables gérant comme des pieds (et à la néolibérale)

Spécial recul des droits et libertés, violences policières, montée de l’extrême-droite…

Spécial résistances

Spécial outils de résistance

Spécial MAGAM et cie

Les autres lectures de la semaine

Les BDs/graphiques/photos de la semaine

Les vidéos/podcasts de la semaine

Les trucs chouettes de la semaine

Retrouvez les revues de web précédentes dans la catégorie Libre Veille du Framablog.

Les articles, commentaires et autres images qui composent ces « Khrys’presso » n’engagent que moi (Khrys).

❌