the grugq's newsletter

Subscribe
Archives
April 4, 2022

April 4th

Russian espionage continues apace.

Twitter avatar for @FideliusSchmid
Fidelius Schmid @FideliusSchmid
Exclusive: Berlin is to extradite a man accused of espionage for Russia to the United Kingdom ⁦@derspiegel⁩
spiegel.deBerlin liefert mutmaßlichen Russen-Spion David S. an Großbritannien ausDavid S. soll seinen Job an der britischen Botschaft in Berlin genutzt haben, um brisante Informationen an Moskau zu liefern. Er sitzt in Deutschland in Haft – vor Gericht kommt er aber im Vereinigten Königreich.
8:20 AM ∙ Apr 4, 2022
202Likes39Retweets

0d in an AV solution used to drop web shells. Not infrequently the security of security products is poor. Not the first, and definitely not the last.

Twitter avatar for @GossiTheDog
Kevin Beaumont @GossiTheDog
Interesting one for Trend Micro customers - CVE-2022-26871 Exploited in the wild, Trend Micro Apex Central (on-premise and SaaS), being used for webshell deployment. They don't mention but I've heard it was a zero day used for weeks to access customers.
success.trendmicro.comDCX
8:47 AM ∙ Apr 4, 2022
16Likes3Retweets

An interesting project. The entirety of eBPF is endlessly fascinating for security. It can be used for root kits, back doors, novel intrusion detection (and prevention) systems, plus whatever it is supposed to actually be used for.

A research project to demonstrate remote code injection over TCP with a malicious eBPF probe.

https://github.com/kris-nova/boopkit

Octal with an insightful point.

Twitter avatar for @octal
Ryan Lackey @octal
Cryptocurrency has done more for computer security than I'd ever expected (basically, instant bug bounty for lots of tech, and an actual market demand for real security vs. compliance-focused games.)
12:43 PM ∙ Apr 3, 2022
594Likes63Retweets

Potentially interesting: a collection of all things Enigma.

Twitter avatar for @FWeierud
Frode Weierud 🇳🇴🇺🇦 @FWeierud
I have released publicly a NSA report entitled "Catalog of Enigma Cipher Machine Wirings" that I obtained through a FOIA request in 2007. The full report or in chapters is available here:
cryptocellar.orgFrode Weierud’s CryptoCellar | The Enigma CollectionThe Enigma Collection contains historical information about the cipher machine Enigma as well as infomation on how to break and analyse the machine’s cipher algorithm.
1:46 PM ∙ Apr 4, 2022
10Likes4Retweets

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X