the grugq's newsletter

Archives
April 7, 2026

April 7, 2026

April 7, 2026

fml-inc/panopticon (2 stars, TypeScript)


Awkward scenes aboard Artemis II as Trump stops ranting and none of the astronauts have anything left to say to him, leading to extended dead air

— Aaron Rupar (@atrupar.com) April 07, 2026


Orban is the first politician in history to get election interference help from both CIA and SVR.

Mindblowing.

— Cthulhu President (@Cthulhu4Prez) April 7, 2026


Bloomberg just dropped the Orbán tapes and it reads like a bad fanfic.

Hungary’s prime minister spent a phone call with Putin calling him a “lion,” casting himself as the helpful little “mouse,” offering Budapest as a venue to end the war on Russia’s terms, and closing with “I… pic.twitter.com/fZ8J1xWIwX

— Saint Javelin (@saintjavelin) April 7, 2026


If you’re cold, they’re cold. Bring your FSB tails inside. https://t.co/PwhcRHOcPe

— thaddeus e. grugq (@thegrugq) April 7, 2026


Much the same (Me, FSB, 2020s, Moscow) https://t.co/v5Agduq7FK pic.twitter.com/1Y6v6wOcSG

— John Foreman CBE (@John_ForemanCBE) April 7, 2026


This article reminded me of a GOATed FPGA bistream RE task from GoogleCTF - GPURTL by Robin - where the key to solving it for me was observing the pattern of changing bits in FPGA's registers.
LiveOverflow made a video about it - link in the reply in case you want to check it out https://t.co/W7edRiKrFc

— Gynvael Coldwind (@gynvael) April 7, 2026


This isn’t a real “vulnerability”. It’s marketing slop.

Step 1 is “user downloads a malicious repo and runs Claude on it” and if you do that there’s already a million ways an attacker could pwn you.

The whole thing was found and written by AI. https://t.co/KiW1yALF7k

— Zack Korman (@ZackKorman) April 6, 2026


I had no idea Plex was a real company with so many employees. I thought it was just a guy who was really passionate about movie piracy. https://t.co/yDy1rHkzV4

— Jacob Shamsian ⚖️ (@JayShams) April 6, 2026


pic.twitter.com/5YuPMNOa54

— allisx86 (@allisx86) April 6, 2026


Ukraine has developed drones that operate without GPS, using an optical odometry system from NASA’s Martian helicopters and Qualcomm chips, according to Russian military bloggers.

At the final stage of the attack, the drone turns off communication and becomes fully autonomous.… pic.twitter.com/uroAaAgfcM

— Slava 🇺🇦 (@Heroiam_Slava) April 6, 2026


a stasi operative photographs a CIA operative who is photographing him back (1960s) pic.twitter.com/j6JcsdrXfk

— blackstar (@blackstarops) April 6, 2026


CERT-UA has documented a significant tactical pivot by hacking groups. Adversaries are increasingly moving away from rapid, one-off data exfiltration in favour of securing long-term, unauthorised access to targeted systems.
"Cyber Threats: Ukraine" report https://t.co/Lj0v01tYmh

— SSSCIP Ukraine (@SSSCIP) April 6, 2026

https://cip.gov.ua/en/statics/analitichni-materiali-derzhspeczv-yazku


Mastermind Behind REvil and GandCrab Revealed: Daniil Shchukin (“UNKN”)https://t.co/FlwoJpIaMP

— club1337 (@club31337) April 6, 2026

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab – Krebs on Security

An elusive hacker who went by the handle "UNKN" and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and…


They can glean that I never open LinkedIn. https://t.co/e8hUfrmAzj

— thaddeus e. grugq (@thegrugq) April 6, 2026


OSS-Fuzz found this 18 yr old remote integer underflow in nginx. I found it too, but 2 weeks slower.

Google's CodeMender AI submitted the exact same fix as me.

Just look how similar our reports are.

Security research might just be cooked.https://t.co/Uu9mZp3nmj pic.twitter.com/GQfvQg5bte

— dinosaurlover38 (@_dinolover38) April 6, 2026

https://issues.oss-fuzz.com/issues/486561029


Don't miss what's next. Subscribe to the grugq's newsletter:

Add a comment:

Share this email:
Share on Twitter Share on Hacker News Share via email Share on Mastodon Share on Bluesky
Twitter