the grugq's newsletter

Subscribe
Archives
April 10, 2022

April 9

“The sky was the color of a TV tuned to a QR code of a rick roll video…”

Dallas got RickRolled by QR code in the sky formed by drones.


Dallas Got Rick Rolled With a Giant QR Code on April Fools Day | Dallas Observer

Internet fads come and go faster than a hiccup, but one that's somehow lasted almost as long as the Internet itself is the "Rick roll."


Yandex and the new Russian certificate authority.

Twitter avatar for @koenrh
Koen Rouwhorst @koenrh
I wrote about Russia's new national certificate authority for sanctioned organizations and how it is supported in Yandex Browser.
koen.engineerRussia’s certificate authority for sanctioned organizationsAfter Russia’s invasion of Ukraine, it has created a new certificate authority to support sanctioned organizations.
2:01 PM ∙ Apr 8, 2022
90Likes56Retweets

Microsoft’s “anatomy of a breach” website hacked to redirect to an mp3 downloaded. Much lol

Twitter avatar for @GossiTheDog
Kevin Beaumont @GossiTheDog
Microsoft's "Anatomy Of A Breach" site has also been breached to go to Free Mp3 Downloader …oud-platform-assets.azurewebsites.net/anatomy-of-a-b…
Image
9:43 PM ∙ Apr 8, 2022
148Likes39Retweets

Linux vulnerability analysis write up.

Twitter avatar for @0xdea
raptor @0xdea
How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables << impressive writeup by @pqlqpql

blog.dbouman.nlHow The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tablesAnalysis and exploitation of Linux kernel vulnerabilities CVE-2022-1015 and CVE-2022-1016. I talk about how I found these vulnerabilities, explain the internals of nf_tables and come up with an local privilege escalation exploitation strategy.
9:38 PM ∙ Apr 8, 2022
22Likes15Retweets

Some nuance on how the last not so big bug was reported vs. how it actually works. Spring4Shell has a bug in one library, but the exploitation path was more flexible.

Twitter avatar for @AmitaiCo
Amitai Cohen @AmitaiCo
I think many early publications about #Spring4Shell / CVE-2022-22965 slightly glossed over the relationship between the underlying bug in Spring Beans and the exploitation path of this vulnerability through WebMVC / WebFlux (1/5) 🧵
4:38 AM ∙ Apr 8, 2022
54Likes21Retweets

An article on Russian radios and problems they have.


K-pop jamming compounds Russian HF woes in Ukraine | Shephard


%

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X