the grugq's newsletter

Archives
April 3, 2026

April 3, 2026

April 3, 2026

ludocode/onramp (206 stars, C) A portable self-bootstrapping C compiler


a C compiler in portable shell

c89cc.sh - standalone C89/ELF64 compiler in pure portable shell · GitHub

c89cc.sh - standalone C89/ELF64 compiler in pure portable shell - c89cc.sh


GitHub - raytheonbbn/maude-hcs · GitHub

Contribute to raytheonbbn/maude-hcs development by creating an account on GitHub.

Paper

https://arxiv.org/pdf/2603.03369

https://www.theregister.com/2026/04/02/maude_hcs_rtx_raytheon_hcn/


“The U.S. military has given the president a plan to seize nearly 1,000 pounds of highly enriched uranium in Iran that would involve flying in excavation equipment and building a runway for cargo planes to take the radioactive material out” https://t.co/CYwpbXs35E

— Kim Zetter (@KimZetter) April 1, 2026


New post: Breaking Enigma with Index of Coincidence on a Commodore 64https://t.co/zwVaEjo67i

— mrdoornbos (@mrdoornbos) March 31, 2026

Breaking Enigma with Index of Coincidence on a Commodore 64 | Imapenguin

Breaking Enigma without known plaintext using statistical analysis on the Commodore 64.


I let a Commodore 64 run for three and a half days straight. 87 billion instructions, 303 billion clock cycles, 5.9 million candidate settings tested. It cracked an Enigma message in German without knowing a single character of the plaintext.
🧵1/2 pic.twitter.com/rHOnk2FFmZ

— mrdoornbos (@mrdoornbos) March 31, 2026


This war really makes a lot of sense when you rememeber it was planned by claude, way too confident, big initial changes, unexpected (but extremely predictable) problems arise, try to fix them, break other stuff, no backup plan, rewrite tests to get them to pass

— Joseph Redmon (@pjreddie) April 2, 2026


In 2001, we didn't give interns email addresses, and one intern had just graduated, so he only had his personal account.
I had him call a member's office to get a CRS report, and then listened as he sounded out, to the press sec, "P I, M P B, O, T, 2000 at hotmail dot com." https://t.co/9cXXkGFuit

— Tim Carney (@TPCarney) April 1, 2026


Artemis II crew is thousands of miles away from Earth

And they’re asking ground crew for help because they have two versions of Microsoft Outlook open and neither is working

This scene is now canon 😭 https://t.co/oP0uLCnIWa pic.twitter.com/AiXNnIVTA7

— Shishir (@ShishirShelke1) April 2, 2026


Inspiring https://t.co/hgiZ8my2Bq pic.twitter.com/XVTyDpjXOk

— Space Koala (@SpaceKoala) April 3, 2026


at google this was known as "buying the gnome". there's like a billion tweets about this already but basically the story goes back in like 2005 or something they were building out their shopping search system, and it was working pretty well. except for the fact that if you… https://t.co/7iv5Bs192U

— Tenobrus (@tenobrus) April 2, 2026


Icymi it: Former CIA ops officer Kevin Chalker says he practiced a defect-or-die pitch to Iranian nuclear clear scientists. The CIA was banned from carrying out assassinations itself but passed along names of those who refused him to Israel for elimination.… pic.twitter.com/XMStZelykB

— Jeff Stein (@SpyTalker) April 2, 2026

https://open.substack.com/pub/spytalk/p/an-astounding-tale-of-cia-ops-against?utm_campaign=post-expanded-share&utm_medium=web


For months, we’ve been digging into China’s nuclear weapons program, identifying where weapon components are built and how those sites are changing.
Every production site we found has expanded significantly in the last five years. 🧵:https://t.co/7fbO4acm1k

— Thomas Bordeaux (@ThomasBordeaux7) April 2, 2026

As arms agreements fray, China secretly expands its nuclear weapons infrastructure | CNN

When three villagers from China’s Sichuan province wrote to local officials in 2022 asking why the government was confiscating their land and evicting them from their homes, they received a terse reply: It was a “state secret.”


Vibe lawyering: type your facts or your darkest secrets into AI, get something that reads like legal analysis, and move forward as if you consulted counsel. People are doing this for employment disputes, equity negotiations, regulatory questions, and investor deals. Stop.…

— Mike Katz (@mikekatz29) April 1, 2026

Stop Vibe Lawyering - by MK - annotations

Claude is not your lawyer (but your lawyers should be using AI)


Everyone's mad at the Flipper Zero.

Nobody's mad at the company still selling 125 kHz cards in 2025.

Nobody's mad at the building manager who hasn't upgraded since 2003.

Nobody's mad at the industry body that certified "secure" systems with no encryption.

The Flipper is a… pic.twitter.com/FpA8LI65GF

— Iceman (@herrmann1001) April 2, 2026

Iceman Channel - YouTube

I'm Iceman, RFID hacking is my passion, and I'm thrilled to engage with anyone interested in elevating their skills with the Proxmark3 device and other RFID hacking tools. I also do talks on security conferences and train people. On this YouTube channel, you'll discover: - Guides, tips, and insights to take your RFID hacking skills to the next level - Latest news, trends, and breakthroughs in the RFID hacking world - Exclusive content on how to get the most value out of your RFID de...


We're open-sourcing more of our stack: iron-proxy, a default-deny egress proxy for untrusted workloads.

It's been a bad month for supply chain security. Trivy, KICS, LiteLLM, and Axios all followed the same playbook: compromise a package, harvest env vars, exfiltrate secrets to…

— Matthew Slipper (@mslipper) April 1, 2026

GitHub - ironsh/iron-proxy: An egress firewall for untrusted workloads. · GitHub

An egress firewall for untrusted workloads. Contribute to ironsh/iron-proxy development by creating an account on GitHub.


ironsh/iron-proxy (193 stars, Go) An egress firewall for untrusted workloads.

source: Matthew Slipper (@mslipper)


The FLARE team now freely distributes its quality reverse engineering and malware analysis educational content at https://t.co/bGCIjBfD3C. Launched with:
- Malware Analysis Crash Course
- Go Reversing Reference
- Intro to TTD

— Moritz (@m_r_tz) April 1, 2026

GitHub - mandiant/flare-learning-hub: Free educational content on reverse engineering and malware analysis from the FLARE team · GitHub

Free educational content on reverse engineering and malware analysis from the FLARE team - mandiant/flare-learning-hub


mandiant/flare-learning-hub (574 stars, JavaScript) Free educational content on reverse engineering and malware analysis from the FLARE team

source: Moritz (@m_r_tz)


Inside the trial shaking Vienna’s long tolerance for spies
https://t.co/yv50f8R4By

— Dr. Dan Lomas (@Sandbagger_01) April 1, 2026

Inside the trial shaking Vienna’s long tolerance for spies - The World from PRX

The largest spy trial in decades is currently underway in Austria. The case has drawn international attention to the country’s lax espionage laws and intensified calls for tougher legislation.


elastic/supply-chain-monitor (292 stars, Python)

source: Joe Desimone (@dez_)


🇫🇷 #France: A failed contract killing in July 2020 exposed an alleged mafia network operating within the Athanor Masonic Lodge in the Paris suburb of Puteaux.

So far, 22 people have gone on trial on charges including murder and other serious crimes linked to the lodge. Of these,… pic.twitter.com/27OknWXFJZ

— POPULAR FRONT (@PopularFront_) March 31, 2026


Thread summary on what happened by the Axios maintainer who was compromised, Jason Saayman.https://t.co/cZobzLchej pic.twitter.com/YCfZm0w0Vi

— Gadi Evron (@gadievron) April 2, 2026

axios@1.14.1 and axios@0.30.4 are compromised · Issue #10604 · axios/axios · GitHub

more details: https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan Most likely, a maintainer's GitHub and npm accounts are compromised as these iss...


This under-estimates and misunderstands the value found across Five Eyes, especially in SIGINT and IMINT, as well as analysis and assessment. And I say that as someone who has suggested being temporarily more cautious in intelligence exchanges with the US. https://t.co/L99TRqNXJf

— Matthew Savill (@MTSavill) April 1, 2026


Janosh “J” Neumann (pseudonym) grew up in the final years of the Soviet Union as the son of a prosecutor and a KGB officer.

At age 17, following a months-long student exchange trip to the United States, he entered training to become an FSB officer himself. J was one of the… pic.twitter.com/pUA6gSisQR

— Spycraft101 (@spycraft101) April 1, 2026


The Arabian plate is converging with the Eurasian so the Hormuz strait will close by itself in a few millions years effectively rendering this entire issue irrelevant.

— Micke Andersson (@TetsuoIronman) April 2, 2026


https://t.co/7cSB0XjQdT — GCU Tense Correction (@tensecorrection) April 2, 2026


Don't miss what's next. Subscribe to the grugq's newsletter:

Add a comment:

Share this email:
Share on Twitter Share on Hacker News Share via email Share on Mastodon Share on Bluesky
Twitter