the grugq's newsletter

Subscribe
Archives
April 10, 2023

April 10, 2023

-

FTX stored private keys to its crypto wallets in AWS đź«  pic.twitter.com/IFoLwBhmzZ

— Molly White (@molly0xFFF) April 9, 2023

-

*youth pastor voice* you know who else got wasted on Friday and dint get up until Sunday?

https://twitter.com/browtweaten/status/1645146448311250945

-

Channel 5 has put the wrong subtitles on Ben Hur! It is hilarious!! pic.twitter.com/GTyIyqrqV7

— Professor Graham Williams (@ProfGAWilliams) April 8, 2023

-

Rule Writing for CodeQL and Semgrep

Rule Writing for CodeQL and Semgrep | Spaceraccoon's Blog

One common perception is that it is easier to write rules for Semgrep than CodeQL. Having worked extensively with both of these static code analysis tools for about a year, I have some thoughts.

Some AppSeccy thoughts on the rule writing experience for CodeQL vs Semgrep https://t.co/uxrFixM3RX

— spaceraccoon | Eugene Lim (@spaceraccoonsec) April 8, 2023

-

Reading Mein Kampf and shaking my head the whole time so the people on the bus know I disagree with it

Reading Mein Kampf and shaking my head the whole time so the people on the bus know I disagree with it

— Kafka, esq. 🔻 (@metalgearobama) December 30, 2020

-

With ICMP magic, you can snoop on vulnerable HiSilicon, Qualcomm-powered Wi-Fi

https://www.theregister.com/2023/04/07/wifi_access_icmp/

-

Microsoft is preparing to kill many known KASLR bypasses in the next release.
Unless the calling process has debug privilege enabled, kernel addresses will be stripped from the output data for all leaking NtQuery APIs pic.twitter.com/USteeVJ0EW

— Yarden Shafir (@yarden_shafir) April 8, 2023

-

8086 emulator for the web

8086 Emulator

8086 Online Emulator | Platform Independent | Code Anywhere

-

I really enjoyed this piece. Not because it’s an Ocean’s 11 style casino heist (it’s not), but because it’s a lovely telling of a single moment of intrigue that mattered to real people for decades. https://www.bloomberg.com/features/2023-how-to-beat-roulette-gambler-figures-it-out/

https://mastodon.social/@MattHodges/110172024039548153

-

Zero Day
Leaked Pentagon Document Claims Russian Hacktivists Breached Canadian Gas Pipeline Company
A pro-Russia hacktivist group claims to have breached the network of a Canadian gas pipeline company in February and caused damage that resulted in loss of profits, according to a document found among a tranche of US classified intelligence assessments leaked online recently…
Read more
9 days ago · 12 likes · 2 comments · Kim Zetter

Per recently leaked US intel document, the Russian hacking group Zarya claims it hacked a Canadian gas pipeline firm in Feb and caused unspecified damage. Zarya says it had ability to increase valve pressure, disable alarms, and initiate emergency shutdownhttps://t.co/mFjGnC6Wdp

— Kim Zetter (@KimZetter) April 9, 2023

-

The Broad, Vague RESTRICT Act Is a Dangerous Substitute for Comprehensive Data Privacy Legislation

The Broad, Vague RESTRICT Act Is a Dangerous Substitute for Comprehensive Data Privacy Legislation | Electronic Frontier Foundation

This bill is being called a “TikTok ban,” but it’s more complicated than that. The bill would give more power to the executive branch and remove many of the commonsense restrictions that exist under the Foreign Intelligence Services Act and the Berman Amendments.

The RESTRICT Act is more than a “TikTok ban.” Tell your representatives to oppose it. https://t.co/UKZs1DoXXe

— EFF (@EFF) April 9, 2023

-

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X