the grugq's newsletter

Subscribe
Archives
April 16, 2025

April 16, 2025

April 16, 2025

Russian cyber and information warfare and its impact on the EU and UK


Russian cyber and information warfare and its impact on the EU and UK | Feature from King's College London

Dr Lukasz Olejnik explores how Russian cyber and information warfare poses a growing threat to the EU and UK, highlighting its tactics, long-term goals and the need for stronger defences.


CVE canceled

MITRE supports a ton of federal cybersecurity work, with the CVE program probably being the most famous example. It's a globally used repository for vital information about vulnerabilities. https://t.co/2FuGusS3xU

I've asked DHS what's going on with the MITRE contract. https://t.co/WRwmpa8C7S

— Eric Geller (@ericgeller) April 15, 2025

https://www.theregister.com/2025/04/16/homeland_security_funding_for_cve/

CVE uncanceled

pic.twitter.com/gF66LFX1N7

— vx-underground (@vxunderground) April 16, 2025

You all are misreading the MITRE CVE situation. MITRE ran out of numbers and was not prepared to move to CVEv6.

— Jim Kennedy (@TonikJDK) April 15, 2025


We're at the "pivot to a social network" stage in the development of AGI pic.twitter.com/f4PwJYy5aX

— lcamtuf (@lcamtuf) April 15, 2025


4chan compromised by SoyJak Party people over some conflicts with raiding LGBT image boards — databases dumped, emails leaked, source code leaked

BreachForums domain seized

It's Tuesday pic.twitter.com/9YvuPGhTsC

— vx-underground (@vxunderground) April 15, 2025

tl;dr nerds from /qa/ raided /lgbt/, mods got irritated, shut down /qa/. Nerds migrated to SoyJak Party instead.

SoyJak Party nerds discovered 4chan was using a dangerously outdated version of PHP and compromised the site. They were able to get access to virtually everything on…

— vx-underground (@vxunderground) April 15, 2025

I’m seeing various reasons for the takedown, lead mod hacked, outdated PHP, outdated Ghostscript. What was it??

— MEGAMEGA (@itsMEGAMEGA) April 15, 2025


new FEATRUE in bincrypter. LOCK & ENCRYPT a binary to a target host. Will execute differently when uploaded to https://t.co/zlT4FOLPm6 or any other but the target host.

Please don't set BC_LOCK="rm -rf ~/" 🙈https://t.co/YplLBHQjL3 pic.twitter.com/Qu66tBvzZ9

— The Hacker's Choice (@thc@infosec.exchange) (@hackerschoice) April 15, 2025


This is an IMPRESSIVELY good pdf password dictionary brute forcer, got a password in literally milliseconds, if you're doing recon this is 👌 https://t.co/kuNzCdP1bU

— Katie Paxton-Fear (@InsiderPhD) April 15, 2025


An apparently sensitive section in the UKUSA Agreement from 1946 reveals that NSA and GCHQ have always been interested in commercial communications when they contain information of interest:https://t.co/mcxIaC6DTo pic.twitter.com/2hINMgJafq

— Electrospaces (@electrospaces) April 15, 2025


msldap new release on github an pip.
Improved bloodhound data gathering -still not in the quality I like, PR welcome-
ADExplorer conversion to Bloodhound zip feature added, the parser part is inspired by @c3c 's https://t.co/xRGjKI2zFv https://t.co/A02N7nyyH0

— SkelSec (@SkelSec) December 9, 2023


this continues to be the most simple yet diabolical defense evasion. https://t.co/Y3OW2KePGE pic.twitter.com/hrOzN5Ps5l

— J⩜⃝mie Williams (@jamieantisocial) April 15, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:
X