the grugq's newsletter

Subscribe
Archives
April 26, 2024

April 26, 2024

April 26, 2024

Absolutely wild story. A Baltimore County principal was seemingly caught on recorded audio making blatantly racist and anti-Semitic comments.

After investigation... the audio was fake. AI-generated, in a plot by the school's former athletic director. https://t.co/s2fX9njF7y

— Alex Griswold (@HashtagGriswold) April 25, 2024

Baltimore County Public Schools is investigating the principal at Pikesville High for alleged derogatory remarks about students and staff

A voice believed to be the principal can be heard ranting about Black students and Jewish families https://t.co/Nuxkgxwrte pic.twitter.com/Iv2yJvps6v

— philip lewis (@Phil_Lewis_) January 17, 2024


Writeup is now done!https://t.co/bUrhAp0MVo

— hex nomad (@hexnomad) June 8, 2023


This dude found a kernel RCE on PS5 via the network (!!!). “Heartbleed”-like attack using an ancient bug from 2006. Disclosed via @Hacker0x01 to @Sony. This bug allows 3rd parties to clone games (!), cheat, or APTs to persist by compromising PS5/PS4.

What did he get? $12.5k 🤦‍♂️ https://t.co/do3MF4f5dq

— Zuk (@ihackbanme) April 26, 2024

Pretty cool bug!
1. Insane to see a known CVE from 2006 providing Remote kernel RW.
2. Only $12.5k ?? Not cool @Sony… https://t.co/XvSX5Q6FLG

— Zuk (@ihackbanme) April 25, 2024

The PS4 (up to FW 11.00) and PS5 (up to FW 8.20) were vulnerable to CVE-2006-4304: https://t.co/e3JBDFFnqW. I'll share details about successful exploitation at TyphoonCon. https://t.co/rkycouWyVC

— Andy Nguyen (@theflow0) April 25, 2024

 🌪️ PlayStation 4 Kernel RCE will be presented by @theflow0 at #TyphoonCon24!

Early bird tickets are now on sale: https://t.co/GpiHQlQx6w pic.twitter.com/nodTuBJ3JL

— TyphoonCon🌪️ (@typhooncon) February 3, 2024


New post on the blog… Exploiting CVE-2024-21111 : Local Privilege Escalation in Oracle VirtualBox by @filip_dragovic https://t.co/AYQ7PCopl1 pic.twitter.com/4UQbGinJ44

— MDSec (@MDSecLabs) April 25, 2024


@jack_halon's Chrome (V8) series is good.https://t.co/Qmg0tK3pH6

Bit old but this is good to for Firefox (Spidermonkey)https://t.co/9Zabdp1ZkZ

— j j (@mistymntncop) April 25, 2024


!Warning! Russian and Chinese state threat actors are using the same tactics ransomware gangs have been using for years. !Warning!

Of course, some people might note that threat actors have been exploiting edge devices for decades, and those people are traitors to Google!

Chinese and Russian hackers have turned their focus to edge devices — like VPN appliances, firewalls, routers and Internet of Things (IoT) tools — amid a startling increase in espionage attacks, according to Google security firm Mandiant. https://t.co/BVv5KlphDt @TheRecord_Media

— 780th Military Intelligence Brigade (Cyber) (@780thC) April 24, 2024


Two more privacy developers arrested in the US today.

This time for building a bitcoin privacy service.

Where does it stop?

"The Samourai wallet developers should have known you can't host a centrally operated mixer."

Ok, well the tornado cash developers deployed privacy as…

— RYAN SΞAN ADAMS - rsa.eth 🦄 (@RyanSAdams) April 24, 2024

🚨 BREAKING: 🚨

The developers of Samourai Wallet have been ARRESTED, INDICTED by the Department of Justice, and their web servers & domain have been SEIZED.

DOJ is also ordering Google to remove the Samourai Wallet app from the Play Store. pic.twitter.com/O3zSAm0MkL

— Chris Blec (@ChrisBlec) April 24, 2024

Southern District of New York | Founders And CEO Of Cryptocurrency Mixing Service Arrested And Charged With Money Laundering And Unlicensed Money Transmitting Offenses | United States Department of Justice

Damian Williams, the United States Attorney for the Southern District of New York; Thomas Fattorusso, the Special Agent in Charge of the New York Field Office of the Internal Revenue Service, Criminal Investigation (“IRS-CI”); and James Smith, the Assistant Director in Charge of the New York Field Office of the Federal Bureau of Investigation (“FBI”), announced today the unsealing of an Indictment charging KEONNE RODRIGUEZ, the Chief Executive Officer and a co-founder of Samourai Wallet (“Samour...


Microsoft shares more details on ICSpector, an open-source framework that enables investigators to scan their network for PLCs, extract project configuration and code from controllers, and detect any anomalous components within ICS environments: https://t.co/7HFKNahXhH

— Microsoft Threat Intelligence (@MsftSecIntel) April 25, 2024


"how I hacked Google": dependency confusionhttps://t.co/iRa5ngGQji pic.twitter.com/9DjSDrR8qg

— Juliano Rizzo (@julianor) April 25, 2024


Home router (SOHO) hacking

"Your not so Home Office - SOHO Hacking at Pwn2Own" (HITB2023)

HITB2023 presentation by @NCCGroupInfosec
https://t.co/WgT1UlzRtP#iot #cybersecurity pic.twitter.com/HeJnSHqVU7

— 0xor0ne (@0xor0ne) April 26, 2024


Encryption is one or two badly-constructed laws from being broken the world over.

— Matthew Green (@matthew_d_green) April 26, 2024

In India the government is close to passing laws that make end to end encryption unworkable, with the consequence that WhatsApp may leave the country. In Europe it’s worse: the EU may mandate mass scanning of conversations.

— Matthew Green (@matthew_d_green) April 26, 2024


Napoleon won wars because he built an administrative machine that could systemically mobilize resources from the territories under his control on a scale no other European state could before. No 18th century ruler could have lost his army in 1812 and have a new one by 1813. https://t.co/8rULdzJpAt

— Stilicho (@StilichoReads) April 25, 2024

Bullshit bureaucratic jobs are a waste of time and money. Napoleon didn’t win wars because of pencil pushers, he won them because of hard-working military men. https://t.co/Dw7UnSaxlQ

— Siomy Coxese (@mujaya_) April 22, 2024

A lot of right wing accounts forget that “the West” ran well because of cogs in the machine like this guy

For every Napoleon or Washington there was a man in a factory or doing boring bureaucratic work.

It didn’t just come from aesthetic memes and militaristic vibes https://t.co/MJN2jfRTYb

— Cody (@AltHistCody) April 22, 2024

One of the most disturbing videos I've ever watched pic.twitter.com/FIGxnj9nAZ

— Keith Woods (@KeithWoodsYT) April 22, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X