the grugq's newsletter
RSS
Archive
Subscribe
July 22, 2023
July 22, 2023 If chameleons were better at their jobs we wouldn't even know there were chameleons.— Dead Pan Nick (@Contwixt) July 29, 2016 <br /> Retired...
The Revolution in Military Media Affairs
May 6, 2024
The Revolution in Military Media Affairs Shifting Dynamics of the Information Environment during Conflicts While watching this interview I had some thoughts....
May 6, 2024
May 6, 2024
May 6, 2024 People adapt to systems, because changing systems is hard North Yorkshire Council to phase out apostrophe use on street signs - BBC NewsA North...
May 5th, 2024
May 5, 2024
May 5th, 2024 The Attritional Art of War: Lessons from the Russian War on Ukraine | Royal United Services InstituteIf the West is serious about the...
May the 4th, 2024
May 4, 2024
May the 4th, 2024 Be with you. CZ taking action against APT28: "In the context of the upcoming European elections, national elections in a number of European...
May 3, 2024
May 3, 2024
May 3, 2024 The McAfee central America Travel Guide - Who Is McAfee?As all of my close friends know, I have not always been a teetotalling, drug fighting...
May 2, 2024
May 2, 2024
May 2, 2024 A Phantom’s Tale: The Coyote Influencer on TikTok - bellingcatHe had tens of thousands of followers and posted regularly about his alleged people...
May 1, 2024
May 1, 2024
May 1, 2024 Happy May Day! LABScon23 Replay | From Vulkan to Ryazan – Investigative Reporting from the Frontlines of Infosec, by @hatr...
April 30, 2024
April 30, 2024
April 30, 2024 Wow wow wow wow First there were "The Americans", now there are "The Czechs": Husband and wife outed as GRU spies aiding bombings and...
April 29, 2024
April 29, 2024
April 29, 2024 Interesting reading on antivirus evasion techniques for beginners Credits @gatarieehttps://t.co/D2CApg1fXT#infosec #evasion...
April 28, 2024
April 28, 2024
April 28, 2024 Excellent LPE write-up by @gabe_k , where he details how suspected compiler changes lead to the introduction of double fetch vulnerabilities....
April 27, 2024
April 27, 2024
April 27, 2024 Exploiting the NT Kernel in 24H2: New Bugs in Old Code & Side Channels Against KASLR by @gabe_k https://t.co/E7PhfD8TbR— lander (@landaire)...
April 26, 2024
April 26, 2024
April 26, 2024 Absolutely wild story. A Baltimore County principal was seemingly caught on recorded audio making blatantly racist and anti-Semitic comments....
April 24, 2024
April 24, 2024
April 24, 2024 I just published C isn’t a Hangover; Rust isn’t a Hangover Cure https://t.co/CyDpCwGMJy— John Viega (@viega) April 23, 2024 from @violazhouyi...
April 23, 2024
April 23, 2024
April 23, 2024 ChatGPT and its ilk are making people worse at writing, in a more insidious way than social media or text messaging ever did. Woah Daniel, how...
April 22, 2024
April 22, 2024
April 22, 2024 I had a great time at T2 con, Helsinki was a load of fun. First time I’ve seen snow in at least a decade. Introduction to "EDR-Preloading"...
April 21, 2024
April 22, 2024
April 21, 2024 GPT-4 can exploit vulnerabilities by reading CVEs : https://t.co/Kw65h1q7Nm (pdf)— Binni Shah (@binitamshah) April 21, 2024 IMO as co-founder...
April 18, 2024
April 19, 2024
April 18, 2024 The second order side effects of using memory safe code languages in edge devices is that all discovered vulnerabilities thereafter will...
April 17, 2024
April 18, 2024
April 17, 2024 My @BlackHatEvents #BHEU presentation has now been posted 📽️https://t.co/NUJQhW1ha6— Brett Hawkins (@h4wkst3r) March 28, 2024 Finished reading...
April 16, 2024
April 17, 2024
April 16, 2024 I am in Helsinki, Finland, for the T2.fi conference this Thursday and Friday. The newsletter will be on semi-hiatus while I am away. If you’re...
April 14, 2024
April 14, 2024
April 14, 2024 Note: I will be traveling to Helsinki for T2.fi con this week. The newsletter will be sporadic while I’m away. If you’re in Helsinki, feel...
April 13, 2024
April 13, 2024
April 13, 2024 Those who don't read https://t.co/DWIfxzByU0 (which turned 11 last month) are doomed to whatever people shocked about /sys/kernel/notes are...
April 12, 2024
April 12, 2024
April 12, 2024 Instagram is rolling out nude detection in private DMs; will automatically blur images it believes are nudes, including in end-to-end...
April 11, 2024
April 11, 2024
April 11, 2024 Looks like someone dropped a Linux kernel 0day https://t.co/UYPK9rItOc pic.twitter.com/wGFK4Vw7Fb— matteyeux (@matteyeux) April 10, 2024...
April 10, 2024
April 10, 2024
April 10, 2024 Come see how I used my jerry-rigged “EMBite” probe to capture an EM side-channels using a HackRF. I used this to figure out the precise timing...
April 9, 2024
April 9, 2024
April 9, 2024 In a shot across Microsoft's bow, @RonWyden is introducing legislation that would set a four-year deadline for the government to stop using...
April 8, 2024
April 8, 2024
April 8, 2024 Ever want to test systems & see if your password is ever stored/sent in plaintext? Make it: X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-...
April 7, 2024
April 7, 2024
April 7, 2024 Interesting video from the cockpit of an A350 flying from Copenhagen to Bangkok. "The challenge on this route is like the jamming and the...
April 6, 2023
April 6, 2024
April 6, 2023 Series by @pberba about persistence in Linux environments Map: https://t.co/8KaO3celxe Auditd: https://t.co/YFlzhgrWjX Accounts:...
April 5, 2024
April 5, 2024
April 5, 2024 We have been reverse engineering the XZ Utils backdoor and are sharing some initial findings: we've identified multiple hooking options to...
April 4, 2024
April 4, 2024
April 4, 2024 xz bd engineer 1: bro, we need a way to probe the address space to make sure we never SEGV sshd xz bd engineer 2: we'll just do a pselect...
April 3, 2024
April 3, 2024
April 3, 2024 "At Kirovskoe Airfield on occupied Crimea [and at at least 12 other air bases] there are decoy Russian fighter aircraft painted on the concrete...
April 2, 2024
April 2, 2024
April 2, 2024 I am currently helping my wife look for the Lindt chocolate bunny I ate on Thursday.— Douglas Cheape (@CheapeDouglas) March 31, 2024 A day...
April 1, 2024
April 1, 2024
April 1, 2024 Kinda feel like the xz backdoor story should’ve waited for Monday. NEW: Facebook snooped on Snapchat users' encrypted network traffic to study...
March 31, 2024
March 31, 2024
March 31, 2024 Backdoor in upstream xz/liblzma leading to ssh server compromise https://t.co/29Vfiz0n1T— Open Source Security mailing list (@oss_security)...
March 30, 2024
March 30, 2024
March 30, 2024 Absolutely the biggest story in a while. The backdoor developer appears to be Jia Tan who spent years working on the xz project to gain a...
March 29, 2024
March 29, 2024
March 29, 2024 The rev.ng decompiler goes open source + start of the UI closed beta The rev.ng decompiler goes open source + start of the UI closed beta -...
March 28, 2024
March 28, 2024
March 28, 2024 Fascinating Google report with details of zero days - the breakdown of who is using zero days gives pause for thought https://t.co/3nxxVRIIUe...
March 27, 2024
March 27, 2024
March 27, 2024 Feds Now Adding Dragnet Searches Of YouTube Users’ Video Watching To Their Investigative Arsenal | TechdirtAll you need is Google. That’s how...
March 26, 2024
March 26, 2024
March 26, 2024 I wrote this Format dialog back on a rainy Thursday morning at Microsoft in late 1994, I think it was. We were porting the bajillion lines of...
March 25, 2024
March 25, 2024
March 25, 2024 I mentioned the idea of using Tailscale as a reverse shell in my @rejektsio talk and promised a blog with some more details. Here's the blog...
March 24, 2024
March 24, 2024
March 24, 2024 EU bans anonymous crypto payments to hosted walletsIn a recent regulatory development, the European Union (EU) has voted to ban cryptocurrency...
March 23, 2024
March 23, 2024
March 23, 2024 GitHub - getgrit/gritql: GritQL is a query language for searching, linting, and modifying code.GritQL is a query language for searching,...
March 23, 2024
March 22, 2024
March 23, 2024 GitHub - getgrit/gritql: GritQL is a query language for searching, linting, and modifying code.GritQL is a query language for searching,...
March 22, 2024
March 21, 2024
March 22, 2024 White House and EPA tell US governors that water facilities need to improve their defenses against cyber threats https://t.co/YI6rusC0WT...
March 20, 2024
March 20, 2024
March 20, 2024 Wallet Drainers Starts Using Create2 Bypass Wallet Security Alert Wallet Drainers Starts Using Create2 Bypass Wallet Security Alert - Scam...
March 19, 2024
March 19, 2024
March 19, 2024 In this post I'll use CVE-2023-6241, a vulnerability in the Arm Mali GPU that I reported last November to gain arbitrary kernel code execution...
March 18, 2023
March 18, 2024
March 18, 2023 IT helpdeskers increasingly targeted by cybercriminals GitHub - albertan017/LLM4Decompile: Reverse Engineering: Decompiling Binary Code with...
March 17, 2024
March 17, 2024
March 17, 2024 Passkeys – Under The Hood Fuzzing Ladybird with tools from Google Project Zero Irish Broadcasting History & Hall of Fame: The Economics of...
March 16, 2024
March 16, 2024
March 16, 2024 Update: last update. I got it finished, turned in on time, and Ive got a place that is interested in publishing it. Thanks for your patience...
Older archives
Twitter