eupolicy.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
This Mastodon server is a friendly and respectful discussion space for people working in areas related to EU policy. When you request to create an account, please tell us something about you.

Server stats:

204
active users

#forensic

5 posts4 participants0 posts today

#CISA Open-Sources #Thorium Platform For #Malware , #Forensic Analysis - Slashdot

… a powerful #OpenSource platform developed with#Sandia National Labs that automates malware & forensic analysis at massive scale. …the platform can "schedule over 1,700 jobs per second & ingest over 10 million files per hour per permission group." From the report:

#Security teams can use Thorium for automating & speeding up various file analysis workflows, including but not limited to…

it.slashdot.org/story/25/07/31

it.slashdot.orgCISA Open-Sources Thorium Platform For Malware, Forensic Analysis - SlashdotCISA has publicly released Thorium, a powerful open-source platform developed with Sandia National Labs that automates malware and forensic analysis at massive scale. According to BleepingComputer, the platform can "schedule over 1,700 jobs per second and ingest over 10 million files per hour per pe...

Eyal Weizman - Intention génocidaire 1/2

#Architecte israélo-britannique et professeur à l’Université Goldsmiths, Eyal Weizman est le fondateur et le directeur du collectif de recherche et d’enquêtes #Forensic #Architecture. Cet article présente notre entretien avec Eyal Weizman et dévoile un extrait du chapitre 5/12: "Croisements: réalité matérielle et esprits coupables".

✒️ Par Diagrammes | En accès libre › blogs.mediapart.fr/diagrammes/

MediapartEyal Weizman - Intention génocidaire 1/2By Diagrammes

In search of riches, #hackers plant 4G-enabled #RaspberryPi in bank network

The researchers with security firm Group-IB said the “unprecedented tactic allowed the attackers to bypass perimeter defenses entirely.” The hackers combined the physical #intrusion with remote access #malware that used another novel technique to conceal itself, even from sophisticated #forensic tools.
#4g #security #privacy #GroupIB

arstechnica.com/security/2025/

Ars Technica · In search of riches, hackers plant 4G-enabled Raspberry Pi in bank networkBy Dan Goodin

“…sciences in the #UK are in a precarious state. Last month, a multiyear all-parliamentary inquiry concluded that the field was in a “graveyard spiral” that had led to #miscarriages of #justice and compounded failures in the UK’s justice system.

These issues have been especially pronounced since 2012, when the government-owned #ForensicScienceService, with a staff of 1,600 people, was shut down, leading to a rise in commercial #forensic agencies. #AcademicResearch in forensics is in an equally dire situation, as universities experience funding cuts.

The future of #DundeeUniversity’s #Leverhulme Research Centre for Forensic Science was called into question earlier this year. Lay-offs are expected and staff staged walkouts at the centre, which has helped investigate war crimes in Kosovo and the inquiry into the deadly Grenfell Tower fire in London.

The result of this decline is that the highly #SpecialisedKnowledge needed for forensic science in the UK is at risk of quietly disappearing.”

#ForensicScience / #botany / #knowledge <archive.md/Yv6lL> / <ft.com/content/b8211cfe-218f-4> (paywall)

Researchers confirm two #journalists were #hacked with #Paragon #spyware | TechCrunch

published a new report detailing the results of a new #forensic investigation into the #iPhones of Italian #journalist #CiroPellegrino and an unnamed “prominent” European journalist. The researchers said both journalists were hacked by the same Paragon customer, based on evidence found on the two journalists’ devices.
#privacy #surveillance #security

techcrunch.com/2025/06/12/rese

TechCrunch · Researchers confirm two journalists were hacked with Paragon spyware | TechCrunchThe confirmation of two hacked victims further deepens an ongoing spyware scandal that, for now, appears largely focused on the Italian government.

“Graphite Caught
First Forensic Confirmation of Paragon’s iOS Mercenary Spyware Finds Journalists Targeted”
⬇️
“On April 29, 2025, a select group of iOS users were notified by Apple that they were targeted with advanced spyware. Among the group were two journalists that consented for the technical analysis of their cases. The key findings from our forensic analysis of their devices are summarized below:
Our analysis finds forensic evidence confirming with high confidence that both a prominent European journalist (who requests anonymity), and Italian journalist Ciro Pellegrino, were targeted with Paragon’s Graphite mercenary spyware.
We identify an indicator linking both cases to the same Paragon operator.
Apple confirms to us that the zero-click attack deployed in these cases was mitigated as of iOS 18.3.1 and has assigned the vulnerability CVE-2025-43200.”
👇

citizenlab.ca/2025/06/first-fo

The Citizen Lab · Graphite Caught: First Forensic Confirmation of Paragon’s iOS Mercenary Spyware Finds Journalists Targeted - The Citizen LabOn April 29, 2025, a select group of iOS users were notified by Apple that they were targeted with advanced spyware. Among the group were two journalists who consented to the technical analysis of their cases. In this report, we discuss key findings from our forensic analyses of their devices.

Forschungsfrage:
Wenn ich alles mit KI ändern, generieren, anpassen, entfernen kann?
A) Wie sieht das mit
#Beweismitteln bei z.B. #Behörden aus?

Ja, wir leben schon in Zeiten v. Photoshop, KI kann hier aber deutlich mehr. Die Tools müssen dann auch für Privatpersonen ohne IT-Skills verwendbar/validierbar sein und wenn ich eine Anzeige erstatten müsste, will ich nich erst n' #DAW lernen müssen, um z.B. 'ne Tonspur validieren zu können. Ebenfalls wird "mach ein Screenshot mit der Website v. d. Atomuhr" nich´ mehr lange halten/bestand haben.
B) Wie kann "ich"/man ein "Selfmade-DIY" Foto noch als "echt" klassifizieren?
Klar könnte ich mit meinen #Openpgp key eine "Echtheit" beglaubigen, dass wäre aber allein von der Struktur falsch. Die PGP-Keys verifizieren nur, dass ich das Dokument signiert habe, nicht was ich signiert habe.
-
#It #security #cybersec #forensic #polizei #research

At least 206 Ukrainian soldiers died in Russian captivity amid brutal treatment

There have been multiple reports of #Ukrainian #POWs being tortured or #killed while in #Russian #captivity

As of May criminal investigations were underway regarding #execution of 268 Ukrainian POWs

AP reported, citing previous reports of #forensic expert who conducted the #autopsies of the POWs.

kyivindependent.com/over-200-u

The Kyiv Independent · At least 206 Ukrainian soldiers died in Russian captivity, AP reportsBy Kateryna Hodunova
Continued thread

Those #forensic #digital #records are important for record-keeping requirements & allow for troubleshooting, but they also allow experts to investigate potential breaches, sometimes even tracing the attacker's path back to the vulnerability that let them inside a network. The records can also help experts see what #data might have been removed. Basic logs would likely not be enough to demonstrate the extent of a bad actor's activities, but it would be a start.

#law#Trump#Musk

A 220-year-old mystery surrounding the remains of infamous German outlaw Johannes Bückler, known as #Schinderhannes, has at last been solved. An international research team used cutting-edge #forensic techniques to confirm that a skeleton long thought to be that of another criminal, “Schwarzer Jonas” (Black Jonas), is in fact Schinderhannes. The true destiny of Schwarzer Jonas’ remains remains a secret.

archaeologymag.com/2025/03/inf #science #history #FamilyHistory #Hunsrück #genome

Archaeology News Online Magazine · Infamous robber Schinderhannes identified after 220-year-old skeleton mix-upBy Dario Radley

Super happy to see the open source sysdiagnose joining the hackathon.lu held in Luxembourg on April 8th and 9th, 2025.

sysdiagnose is an open-source framework developed to facilitate the analysis of the Apple sysdiagnose files and especially the one generated on mobile devices (iOS / iPadOS). In the light of targeted attacks against journalists, activist, representatives from the civil society and politicians, it empowered incident response team to review device behaviour and ensure their integrity. This tool is initially the result of a joint effort between EC DIGIT CSOC (European Commission DG DIGIT) and CERT-EU (cert.europa.eu/).

hackathon.lu/projects/#sysdiag

Don't hesitate to register and add your project!

#opensource #dfir #forensic #hackathon #luxembourg

Thanks to @ddu and the team to join us.

cert.europa.euCERT-EUCERT-EU