the grugq's newsletter

Subscribe
Archives
April 22, 2024

April 21, 2024

April 21, 2024

GPT-4 can exploit vulnerabilities by reading CVEs : https://t.co/Kw65h1q7Nm (pdf)

— Binni Shah (@binitamshah) April 21, 2024

IMO as co-founder of CVE back in 1999, this paper appears to have significant flaws that other knowledgeable CVE consumers or producers can point out if they wish. I doubt that its findings can be scaled.

/cc @attritionorg ur welcome for the nerd snipe, I don't have the energy

— Steve Christey Coley, BS 🐀 (@SushiDude) April 21, 2024

np Binni :) (big fan btw). There are some interesting aspects of the findings, but I'm immediately concerned about the hype and misunderstanding that could come from this paper, e.g., success of 87% of 15 CVEs from a highly biased sample is interesting-ish but not generalizable.

— Steve Christey Coley, BS 🐀 (@SushiDude) April 21, 2024


The 2024 Pwnie Award Nominations are now live! Submit your best and brightest bugs, wins, and failures at the link below:https://t.co/s9UnLrQ1z8

— Pwnie Awards (@PwnieAwards) April 21, 2024


My slide deck from Black Hat Asia 2024. I explain how Volt Typhoon indicates that the CCP's wartime constructs like the Information Operations Group (信息 作战群) have been activated, which is unprecedented https://t.co/OHHpuUTXzV CC: @daveaitel

— Pukhraj Singh (@RungRage) April 19, 2024


Mirroring US capabilities: $1 trillion
Mirroring US bureaucracy: Priceless https://t.co/ctpKRMpohh

— GeorgeWilliamHerbert (@GeorgeWHerbert) April 20, 2024

China's Ministry of Defense has created the Aerospace Force, announced via a news release today.

When asked about what tasks will the Aerospace Force undertake and if it implies any changes to China’s space policy spokesperson Wu Qian answered:

"Space is a shared asset of… pic.twitter.com/C0bzJ9heDh

— Phazzee 🏳️‍⚧️🏳️‍🌈 | 中国航天爱好者 🇨🇳 | 🇵🇸 (@PhazzeeYeehaw) April 19, 2024


Among the most promising military applications of AI is staff work. Tons of routine products—intel summaries, orders, etc.—can be generated much faster by machine. Does this mean staffs will reverse the historic trend and begin to shrink?

No: they’re about to explode in size.🧵 pic.twitter.com/9qtiDZnSZm

— The Bazaar of War (@bazaarofwar) April 20, 2024

Thread by @bazaarofwar on Thread Reader App – Thread Reader App

@bazaarofwar: Among the most promising military applications of AI is staff work. Tons of routine products—intel summaries, orders, etc.—can be generated much faster by machine. Does this mean staffs will reverse th...…


I’ve been writing a lot of stories about state-sponsored cyberespionage by China. The case we’re revealing today is a prime example of this, telling the story of a five-year campaign against one of the key players in 🇩🇪 the Volkswagen grouphttps://t.co/78aAE3STef (€)

— hakan (@hatr) April 20, 2024


🤯 you can upload any file as an attachment in a draft comment on any public GitHub repo, delete the comment but the file download URL remains active, and the repo owner can’t do anything about it https://t.co/dbffKpNmRC

— randy@infosec.exchange - Stand with 🇺🇦 (@rpargman) April 20, 2024

Weeks later... GitHub bug still dropping malware 👌 pic.twitter.com/s165zOAsoI

— herrcore (@herrcore) March 27, 2024


I didn't remember this but lolz pic.twitter.com/DRf3Db08v0

— Justin Elze (@HackingLZ) April 21, 2024


https://t.co/3cPJdgkLne pic.twitter.com/lYoff9nqkZ

— Ian Coldwater 📦💥 (@IanColdwater) April 20, 2024
Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X