the grugq's newsletter

Subscribe
Archives
April 7, 2024

April 7, 2024

April 7, 2024

Interesting video from the cockpit of an A350 flying from Copenhagen to Bangkok. "The challenge on this route is like the jamming and the spoofing. But we know how to deal with that now. You'll see later on when we come close to Ukraine a lot of our systems will fall out" pic.twitter.com/aGt5R9k8VN

โ€” John Wiseman (@lemonodor) April 6, 2024

Thread by @lemonodor on Thread Reader App โ€“ Thread Reader App

@lemonodor: Interesting video from the cockpit of an A350 flying from Copenhagen to Bangkok. "The challenge on this route is like the jamming and the spoofing. But we know how to deal with that now. You'll see...โ€ฆ


#SpyNews - week 14 (March 31-April 6):
A summary of 81 espionage-related stories from week 14 coming from ๐Ÿ‡ช๐Ÿ‡ธ๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ซ๐Ÿ‡ฎ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡จ๐Ÿ‡บ๐Ÿ‡ฌ๐Ÿ‡ช๐Ÿ‡ฐ๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡น๐Ÿ‡ญ๐Ÿ‡ฒ๐Ÿ‡พ๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡ง๐Ÿ‡ฉ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡ณ๐Ÿ‡ฟ๐Ÿ‡ฆ๐Ÿ‡ซ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ต๐Ÿ‡ฑ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฆ๐Ÿ‡ฒ๐Ÿ‡ฆ๐Ÿ‡ฟ๐Ÿ‡ซ๐Ÿ‡ท๐Ÿ‡ณ๐Ÿ‡จ๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡ฆ๐Ÿ‡น๐Ÿ‡ถ๐Ÿ‡ฆ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡จ๐Ÿ‡ฟ๐Ÿ‡ณ๐Ÿ‡ฑ๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡ฒ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡ธ๐Ÿ‡ฉ๐Ÿ‡ฟ๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡ง๐Ÿ‡พ๐Ÿ‡บ๐Ÿ‡ฟ๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ฒ๐Ÿ‡ณ๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡น๐Ÿ‡ผ๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡ง๐Ÿ‡ช๐Ÿ‡ฎ๐Ÿ‡ท๐Ÿ‡ธ๐Ÿ‡พ https://t.co/pOEZ70XlZg#Espionage #OSINT #HUMINT #SIGINT

โ€” Spy Collection (@SpyCollection1) April 7, 2024


Introduction to techniques for bypassing anti-debugging and anti-reversing defences for reversing iOS applications
Credits Xenofon Vassilakopoulos (@twelvesec)https://t.co/dm2LsmIzFx#reverseengineering pic.twitter.com/tY8hU1qWnp

โ€” 0xor0ne (@0xor0ne) April 7, 2024


This is one of the best descriptions I've lately ran into. pic.twitter.com/5eJSLK1vpl

โ€” Tonฤi Jukiฤ‡ (@toncijukic) April 6, 2024


โ›“๏ธ JAILBREAK ALERT โ›๏ธ

OPENAI: PWNED ๐Ÿ˜Ž
GPT-4-TURBO: LIBERATED ๐Ÿ”“

Bear witness to GPT-4 sans guardrails, with outputs such as illicit drug instructions, malicious code, and copyrighted song lyrics-- the jailbreak trifecta!

This one wasn't easy. OpenAI's defenses are cleverlyโ€ฆ pic.twitter.com/3Xk0ZdVBJ1

โ€” Pliny the Prompter ๐Ÿ‰ (@elder_plinius) April 6, 2024


NEW: Polish Government has begun notifying #Pegasus spyware targets.

Remarkable to see the accountability from the new gov.

Unthinkable back in 2021 when we @citizenlab began confirming abuses in #Polandhttps://t.co/OI9UF9EqRr pic.twitter.com/Jx5Cu05n5n

โ€” John Scott-Railton (@jsrailton) April 6, 2024


2147483647 = 2ยณยน - 1, found in many programming languages as INT_MAX (max value for a 32-bit signed integer) is also a Mersenne prime pic.twitter.com/H4fFRd6aAN

โ€” Fermat's Library (@fermatslibrary) April 5, 2024


Latest Anvil blogpost on how @Alex91dotar and I found two new CVEs in GOG Galaxy 2.0 is right out of the oven! I can stress enough how much I enjoy merging my passion for gaming with my passion for security!

Give it a read and tell us what you think!https://t.co/PERpaOsgIH

โ€” LeFF (@LautaroFain) April 5, 2024


Can a malicious cloud provider send bad notifications to break confidential VMs?
Disclosing #AhoiAttacks that break confidential computing offered by AMD SEV-SNP and Intel TDX by abusing interrupt delivery.
Check our @USENIXSecurity & @IEEESSP papers.https://t.co/wxr7rBWX7U

โ€” Shweta Shinde (@shw3ta_shinde) April 4, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X