the grugq's newsletter

Subscribe
Archives
April 27, 2023

April 27, 2023

April 27, 2023

So, I think I figured out how these edited casualty counts came about.

The first public mention of them was through the pro-Russia Donbass Devushka Telegram channel. How did the channel get her?

A pro-Ukraine troll group on Telegram made them as a joke, and sent on to her. https://t.co/TxoYmGnsXE

— Aric Toler (@AricToler) April 26, 2023

My new blog “Smash PostScript Interpreters Using a Syntax-Aware Fuzzer”https://t.co/KQ1bOp237S, the findings include 3 vulnerabilities in Acrobat Distiller and 1 vulnerability in Apple’s PSNormalizer. It’s inspired from ⁦@steventseeley 's
⁩ previous Postscript research.

— KevinLu (@K3vinLuSec) April 26, 2023

The movies “War Games” and “Hackers” were on target. https://t.co/Z7yN9cQm1V

— Chris Wysopal (@WeldPond) April 26, 2023

I want to give some props to @C_M_Dougherty for writing such a tremendous paper on contested logistics. I’ve been a bit busy but I wanted to take a few minutes to highlight the good work he did for @CNASdc https://t.co/TkUwrON2ui

— Tony Stark (@Iron_Man_Actual) April 26, 2023

The US bringing some awfully damning claims about Jack Teixeira in its arguments to keep him detained pretrial. Which would seem to also be some strong arguments against him having that clearance in the first place.https://t.co/2v4zaRhCHv pic.twitter.com/8lirJX2sI4

— Kevin Collier (@kevincollier) April 27, 2023

I wrote a Discord C2 that operates entirely over voice chat as an exercise to learn golang better. Check out the tool and let me know what ya think! https://t.co/5fO0dMUJWe

— sm00v! (@5m00v) April 26, 2023

This week's Seriously Risky Business:

- North Korea's vibe-based targeting
- Iran Cries Havoc and Lets Slip the Dogs of Cyber
- Team Cymru Not the Cyber Villain

plus more...
Available on the site that cannot be named! pic.twitter.com/meCJKUdkuw

— Tom Uren (@tomatospy) April 27, 2023

Today Lockbit ransomware group ransomed a day care center. When Lockbit ransomware group administration discovered the victim they issued an apology and claim to have fired the affiliate.

"I am ashamed" - Lockbit administration pic.twitter.com/n836hnDKwZ

— vx-underground (@vxunderground) April 27, 2023

Best I can do is offer some facts about ancient Egypt pic.twitter.com/H6sGWJcT5O

— Inflow | The ADHD App (@get_inflow) April 26, 2023

https://t.co/0qQpZEp5j8

— Dr. Dan Lomas (@Sandbagger_01) April 27, 2023

Delve into the 1963–1966 Konfrontasi conflict between Indonesia & Malaysia with our latest declassified release. See previously classified records of Australia’s involvement, meetings, intel that was shared, infiltration reports and more 👉 https://t.co/rsrbwESu0O pic.twitter.com/Y4NZ4HuAkQ

— Australian Signals Directorate (@ASDGovAu) April 27, 2023

"The U.S. Space Force wants to create a space-based 'outernet' that would allow military satellites and networks to communicate more efficiently." https://t.co/ZzdsNdC6Hx

— Stefan Soesanto (@iiyonite) April 27, 2023

An interesting twist on this wide spread bug is that #Linux kernel itself mis-parses own /proc/pid/stat output:https://t.co/PFjIhRTLpAhttps://t.co/hP3jobjuJA https://t.co/3USI7GQD7m

— Dmitry Vyukov (@dvyukov) April 27, 2023

Bringing Memory Safety to sudo and su - Prossimo

Our Prossimo project has historically focused on creating safer software on network boundaries. Today however, we're announcing work on another critical boundary - permissions. We're pleased to announce that we're reimplementing the ubiquitous sudo and su utilities in Rust. Sudo was first developed in the 1980s. Over the decades, it has become an essential tool for performing changes while minimizing risk to an operating system. But because it's written in C, sudo has experienced many vulnerabil...


"We are really building a different type of agency - which is not a government bureaucracy, but really something that is much more like a private-public collaborative." - @CISAJen @CISAgov

For more from this panel, check out the full video here! https://t.co/2OZ9BJJ6hn pic.twitter.com/IRnY2SziOb

— Cyber Statecraft (@CyberStatecraft) April 26, 2023

https://twitter.com/lameypilled/status/1650874048006721537

If you speak the 43rd language then they won’t know what you’re saying! Security through obscurity!!! https://t.co/xBTm4ZrjOn

— thaddeus e. grugq thegrugq@infosec.exchange (@thegrugq) April 27, 2023
Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X