the grugq's newsletter

Subscribe
Archives
April 28, 2024

April 28, 2024

April 28, 2024

Excellent LPE write-up by @gabe_k , where he details how suspected compiler changes lead to the introduction of double fetch vulnerabilities. Also discusses a KASLR side channel bypass. PoCs included. Definitely check it out https://t.co/RAjMDsnTgm

โ€” chompie (@chompie1337) April 28, 2024


Germany grapples with wave of spying threats from Russia and Chinahttps://t.co/RuMfY9IGae

โ€” Dr. Dan Lomas (@Sandbagger_01) April 28, 2024


#SpyNews - week 17 (April 21-27):
A summary of 89 espionage-related stories from week 17 coming from ๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฆ๐Ÿ‡ซ๐Ÿ‡ซ๐Ÿ‡ท๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ญ๐Ÿ‡ฐ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡ฑ๐Ÿ‡ง๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡จ๐Ÿ‡ฟ๐Ÿ‡ฎ๐Ÿ‡ถ๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡ฑ๐Ÿ‡พ๐Ÿ‡ท๐Ÿ‡ด๐Ÿ‡จ๐Ÿ‡พ๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ช๐Ÿ‡ธ๐Ÿ‡ฉ๐Ÿ‡ฟ๐Ÿ‡ฐ๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡ธ๐Ÿ‡ฉ๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ช๐Ÿ‡น๐Ÿ‡ณ๐Ÿ‡น๐Ÿ‡ฏ๐Ÿ‡น๐Ÿ‡ฉ๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡ฌ๐Ÿ‡ท๐Ÿ‡ณ๐Ÿ‡ฑ๐Ÿ‡ณ๐Ÿ‡ฟ๐Ÿ‡น๐Ÿ‡ผ๐Ÿ‡ฎ๐Ÿ‡ท๐Ÿ‡ต๐Ÿ‡น๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡ต๐Ÿ‡ฑ๐Ÿ‡ง๐Ÿ‡ท๐Ÿ‡ฆ๐Ÿ‡ฟ https://t.co/wccMd7Two6#OSINT #SIGINT #HUMINT #Espionage #Spy

โ€” Spy Collection (@SpyCollection1) April 28, 2024


A ~/.bashrc 1-liner to sniff ๐Ÿถsudo/ssh/git passwords (pty MitM). No root required. ๐Ÿ‘€

๐Ÿ‘‰ https://t.co/zVCLwmbXv2 pic.twitter.com/Ep54gcWAqj

โ€” The Hacker's Choice (@thc@infosec.exchange) (@hackerschoice) April 28, 2024


Here's also our postmortem of 3 years of Rust gamedev, and why we're leaving Rusthttps://t.co/oA8u7ehLuf#rustgamedev #rustlang

โ€” LogLog Games (@LogLogGames) April 26, 2024


I worked on MS-DOS, but not this one! Microsoft has open-sourced MS-DOS 4.00 on Github, but it might not be what you think it is.

MS-DOS 4.00 was an attempt at a multitasking MS-DOS, but OEMs weren't really interested, and it was only ever in limited release. So it's almostโ€ฆ pic.twitter.com/vVeDgf57mO

โ€” Dave W Plummer (@davepl1968) April 27, 2024


As someone who worked in retail for almost 20 years, yes.

All of these are correct. pic.twitter.com/fFPmb9dTSt

โ€” Kelli โ™ซ The Opera Geek โ™ซ (@TheOperaGeek) April 27, 2024


From a one byte out-of-bounds write to a complete ROP chain
Writeup by @pepsipuhttps://t.co/q24vIRvdOR #cybersecurity #exploit pic.twitter.com/rM5sQU6cVH

โ€” 0xor0ne (@0xor0ne) April 27, 2024


We are proud to finally share some great research by Arnau Ortega on a 1-click #Azure tenant takeover attack. You can read all about it in our latest blog post. It explains how we could take over any Azure tenant; just by clicking one legitimate linkย ๐Ÿ˜จhttps://t.co/WHMNJpPC7B pic.twitter.com/z4Q6eEPObb

โ€” FalconForce Official (@falconforceteam) April 26, 2024


I didn't want to write this, but I felt like I had to. Put this in your .bash_profile and get notifications whenever someone impersonates you, hijacks your credentials, or nefariously attaches to your forwarded ssh-agent to gain access to machines they cannot without your user pic.twitter.com/Ars98v4ztt

โ€” FreeBSD Frau (@freebsdfrau) April 26, 2024




Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X