the grugq's newsletter

Subscribe
Archives
August 1, 2025

August 1, 2025

August 1, 2025

boB Rudis ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿ‡ฌ๐Ÿ‡ฑ ๐Ÿ‡จ๐Ÿ‡ฆ: "๐Ÿ†• GreyNoise Research: Early Warning Signals Beforโ€ฆ" - Mastodon

Attached: 2 images ๐Ÿ†• GreyNoise Research: Early Warning Signals Before CVEs Drop Full report: https://www.greynoise.io/resources/early-warning-signals-attacker-behavior-precedes-new-vulnerabilities In our latest research, we examined dozens of incidents where attacker activity โ€” often in the form of exploit attempts โ€” spiked weeks before a new CVE was disclosed. This chart shows what we found (much more in the report). Each โšช is a confirmed spike in attacker activity targeting a specific ...

Early Warning Signals: When Attacker Behavior Precedes New Vulnerabilities

GreyNoiseโ€™s new research reveals a recurring pattern: spikes in malicious activity often precede the disclosure of new CVEs โ€” especially in enterprise edge technologies like VPNs and firewalls.

https://info.greynoise.io/hubfs/resources/GreyNoise-Early-Warning-Signals-Attacker-Behavior-Precedes-New-Vulnerabilities-Report.pdf

(Hopefully the link to download the paper directly will work.)


Facts Will Not Save You https://t.co/TEeA9xpFc6 pic.twitter.com/sjBBkUEqPa

โ€” Seva (@SevaUT) July 31, 2025


The Hacker Pager | exploitee.rs

Wireless messenger and LoRa radio multitool. Retro-stylish, open-source, and packed with features.

Hands On: The Hacker Pager | Hackaday

It should come as no surprise that the hacker community has embraced the Meshtastic project. Itโ€™s got a little bit of everything we hold dear: high quality open source software, fantastic docโ€ฆ


How spy agencies are experimenting with the newest AI models https://t.co/RtSE8gZ5O3

โ€” Dr. Dan Lomas (@Sandbagger_01) July 31, 2025

https://archive.is/ufDTf


Apparently there is spying going on at embassies.

https://www.theregister.com/2025/07/31/kremlin_goons_caught_abusing_isps/

Microsoft Threat Intelligence has uncovered a cyberespionage campaign by the Russian state actor we track as Secret Blizzard targeting embassies in Moscow using an adversary-in-the-middle (AiTM) position to deploy their custom ApolloShadow malware. https://t.co/VbI9M73D9m

โ€” Microsoft Threat Intelligence (@MsftSecIntel) July 31, 2025

even an

--apex-predator APT

--using home field advantage

--to deliver malware from the ISP/Telco level

still relies on multiple social engineering tricks to execute critical steps in their kill-chain https://t.co/gSAkoFzjF3 pic.twitter.com/P2BLL6PHiw

โ€” Jโฉœโƒmie Williams (@jamieantisocial) July 31, 2025


Kali Linux can now run in Apple containers on macOS systems - @LawrenceAbramshttps://t.co/FmfkPwqMYOhttps://t.co/FmfkPwqMYO

โ€” BleepingComputer (@BleepinComputer) July 31, 2025


Announcing #Pwn2Own Ireland for 2025! We return to the Emerald Isle with our new partner @Meta and a $1,000,000 WhatsApp bounty. Yes - one million dollars. Plus new USB attack vectors on phones and more. Check out the details at https://t.co/dgHvL8QC2R

โ€” Trend Zero Day Initiative (@thezdi) July 31, 2025


Google has a new monospaced coding font.

Google Sans Code - Google Fonts

Personally, Iโ€™m still using M Plus Code Latin. It has some personality, at least.

M PLUS Code Latin - Google Fonts

M+ FONTS is a little nifty font family for everyday usage. Mplus Code Latin is a Sans Serif font with seven weights from Thin to Bold, supporting GF Latin Plus.


https://www.bleepingcomputer.com/news/security/cisa-open-sources-thorium-platform-for-malware-forensic-analysis/


https://news.ycombinator.com/item?id=44747204


These add-ons use delay tactics, encryption, swapping versions, and legit telemetry services to hide their activity.
Users: avoid newly published crypto extensions.
My analysis: https://t.co/YzDJtOH7oH

โ€” Lukasz Olejnik (@lukOlejnik) August 1, 2025


Iranian ๐Ÿ‡ฎ๐Ÿ‡ท anti censorship tools

If you want to learn about how to evade censorship look no further than here:https://t.co/Vuez3iJiIXhttps://t.co/zS60e2j3HF#Online #Safety #Privacy #UK #Internet #freedom

โ€” mRr3b00t (@UK_Daniel_Card) August 1, 2025

GitHub - bepass-org/oblivion-desktop: Oblivion Desktop - Unofficial Warp Client for Windows/Mac/Linux

Oblivion Desktop - Unofficial Warp Client for Windows/Mac/Linux - bepass-org/oblivion-desktop


What could happen when you ban or put barriers in front of things on the internet?

Surely nothing bad could happen, because you are restricting of banning the bad thing right! *inserts Anakin/Padme meme*#OnlineSafetyAct #UK pic.twitter.com/2usY1fZFAd

โ€” mRr3b00t (@UK_Daniel_Card) August 1, 2025

Thread:

Thread by @UK_Daniel_Card on Thread Reader App โ€“ Thread Reader App

@UK_Daniel_Card: What could happen when you ban or put barriers in front of things on the internet? Surely nothing bad could happen, because you are restricting of banning the bad thing right! *inserts Anakin/Padme ...โ€ฆ


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X