the grugq's newsletter

Subscribe
Archives
April 19, 2024

April 18, 2024

April 18, 2024

The second order side effects of using memory safe code languages in edge devices is that all discovered vulnerabilities thereafter will approach 100% reliability for exploitation.

High volume of 100% reliability vulns VS a high volume of 80% reliability vulns. Which is worse?

— remy🐀 (@_mattata) April 18, 2024


TechScape: How cheap, outsourced labour in Africa is shaping AI English | Technology | The Guardian

Workers in Africa have been exploited first by being paid a pittance to help make chatbots, then by having their own words become AI-ese. Plus, new AI gadgets are coming for your smartphones


Hunting and analysing (Windows) vulnerable kernel drivers by Takahiro Haruyama (@VMware)https://t.co/PnIAH0b5wN#Windows pic.twitter.com/VePQbbkowv

— 0xor0ne (@0xor0ne) April 17, 2024


"Prosecutors allege that Carsten L. made photos and screenshots of nine BND files, which he transferred to Arthur E., who then transported them to Moscow".https://t.co/jfx45HqHtO

— Dr. Dan Lomas (@Sandbagger_01) April 17, 2024


Congratulations to all the researchers recognized in this quarter’s MSRC 2024 Q1 Security Researcher Leaderboard! 🎉 Thank you to everyone for your hard work and continued partnership to secure customers.

Learn more in our blog post: https://t.co/YtfvE6Urgo

We also want to… pic.twitter.com/zjwijVOHcj

— Security Response (@msftsecresponse) April 17, 2024


For those on Mastodon, there's a thread where people smarter than I are working out if the PA CVE was a real 'Palo Alto' bug or a problem in upstream. Current thinking is that PA were misusing the Gorilla library in a way that was unsafe. https://t.co/9Wy6oSKWy1

— Aliz (@AlizTheHax0r) April 18, 2024


Congrats to mandiant in making their own renaming of a threat actor into a story. Quite a coup!

The Russian GRU-linked hacker team Sandworm has become so aggressive and impactful that @Mandiant is formally upgrading it to an Advanced Persistent Threat: APT44. https://t.co/HPvEDdtCOP

It presents "a significant proliferation risk for new cyber attack concepts and methods." pic.twitter.com/T3OWhDP96H

— Eric Geller (@ericgeller) April 17, 2024

Over a decade in the making: Sandworm is now APT44.

Below is a thread with some major takeaways and insights from our new report:https://t.co/viVfvF4Bvb

— Dan Black (@DanWBlack) April 17, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X