the grugq's newsletter

Subscribe
Archives
August 22, 2022

August 22, 2022

The Offensive Cyber Working Group has released a new journal issue. I have opinions on some of these papers.

Twitter avatar for @Offensive_Cyber
Offensive Cyber Working Group @Offensive_Cyber
🚨 Summer 2022 Special Issue in the Cyber Defense Review We are pleased to announce a special issue on 'An Offensive Future?' published by @cyberdefreview in their Summer 2022 edition, curated by the Offensive Cyber Working Group. A 🧵of the papers 🔽 offensivecyber.org/2022/08/22/an-…
offensivecyber.orgAn Offensive Future?Cyber Defense Review Summer 2022 Special Issue published with curated papers from the Offensive Cyber Working Group.
8:55 AM ∙ Aug 22, 2022
13Likes2Retweets

The in-depth analysis of the Zerodium brochures is on par with other papers in this space. The findings always suggest their methodology involves a lot of monkeys and dartboards: 🙈 🎯

The Info Op is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Credit for predictive tweeting

Twitter avatar for @udunadan
dunadan @udunadan
Does somebody have a copy of "Advanced Threat Modeling: Zerodium Charts Querying And Beyond"? Asking for a friend.
5:54 PM ∙ Mar 17, 2022

-

Kenneth Geers has published a paper via DEFCON on the Russian Ukraine cyberwar. It looks promising.

https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Kenneth%20Geers%20-%20Computer%20Hacks%20in%20the%20Russia-Ukraine%20War%20-%20paper.pdf

-

Twitter avatar for @riskybusiness
Patrick Gray @riskybusiness
New podcast up, featuring @tomatospy and @thegrugq
risky.biz/BTN2
Image
3:30 AM ∙ Aug 22, 2022
20Likes3Retweets

-

Twitter avatar for @razhael
Raphael Satter @razhael
Israeli spyware company NSO Group CEO steps down
reuters.comIsraeli spyware company NSO Group CEO steps downIsraeli spyware firm NSO Group said on Sunday its Chief Executive Shalev Hulio is stepping down with immediate effect, with Chief Operating Officer Yaron Shohat appointed to oversee a reorganisation of the company before a successor is named.
2:08 PM ∙ Aug 21, 2022
63Likes37Retweets

-

Twitter avatar for @Th4ntis
Th4ntis:~$ @Th4ntis
Updated my Gitbook for aWardriving guide with @KismetWireless. Check it out. th4ntis.gitbook.io/th4ntis-cybers… #wardriving #kismetwireless #cybersec #cybersecurity
th4ntis.gitbook.ioWardriving - Th4ntis-CyberSec-Notes
5:27 AM ∙ Aug 20, 2022
17Likes4Retweets

-

-

I am surprised to learn there are drones manufactured to drop bombs. Taiwan has a drone, the Revolver, that can carry and drop 8 mortar rounds in sequence.

-

Twitter avatar for @gf_256
cts @gf_256
Image
4:17 AM ∙ Aug 21, 2022
1,182Likes195Retweets

-

Twitter avatar for @GossiTheDog
Kevin Beaumont @GossiTheDog
Clop have now posted the data dump of South Staffordshire Water. It includes a significant amount of PII of staff - e.g. passports etc - and lots of corporate data. Passwords are stored in Excel. Alarmingly, it appears they did indeed get on the SCADA/ICS network for water.
10:08 AM ∙ Aug 22, 2022
42Likes15Retweets

-

Twitter avatar for @AlecMuffett
Alec Muffett @AlecMuffett
1/3 The POINT of end-to-end #encryption is to open up new frontiers in secure communication: to be able to safely & privately share intimacy, be that for telemedicine, for family stuff, or for simply partners. This *obsession* with stopping one bad thing, is disproportionate.
Twitter avatar for @kashhill
Kashmir Hill @kashhill
A dad in San Francisco took photos of his toddler’s groin for the doctor. When his Android backed the photos up to the cloud, Google flagged them as child sexual abuse material. He lost his Google account and was investigated by the police. https://t.co/OO4ipXJPsO
12:39 PM ∙ Aug 21, 2022
65Likes37Retweets

-

Twitter avatar for @MalwareTechBlog
Marcus Hutchins @MalwareTechBlog
This is a hilarious scam. The person pretends to be a clueless crypto users asking for help withdrawing money and sends you their private key. Wallet has over $1k in it, but no gas. If someone deposits the gas fee needed to steal the money, it just gets forwarded to the scammer.
Image
Image
Image
5:49 PM ∙ Aug 21, 2022
1,263Likes227Retweets

-

Twitter avatar for @jaimeblascob
Jaime Blasco @jaimeblascob
@attrc @GitHubCopilot @moyix All PHP code is a CTF
4:19 AM ∙ Aug 20, 2022
37Likes7Retweets

-

Twitter avatar for @bert_hu_bert
Bert Hubert 🇺🇦 @bert_hu_bert
I made a very very simple tool that makes some noise every time your computer sends data to Google. Here a demo on the official Dutch government jobs site. The noise starts while typing the domain name already. Code, currently Linux only: github.com/berthubert/goo…
9:32 PM ∙ Aug 21, 2022
8,976Likes2,216Retweets

-

Twitter avatar for @JoshRovner1
Josh Rovner @JoshRovner1
Essays on espionage from Hew Strachan, Elizabeth Braw, Richard Aldrich, Chrostopher Moran, @RoryCormac, and me:
engelsbergideas.comInnovation and Espionage ArchivesIt’s Innovation and Espionage week at Engelsberg Ideas. Our writers will be discussing the link between technology and intelligence gathering throughout history and what the future of this relationship might hold.
11:30 AM ∙ Aug 21, 2022
47Likes13Retweets
Twitter avatar for @WarintheFuture
Mick Ryan, AM @WarintheFuture
"Above all, war is more than battles and operations. Regardless of the technology, it is, as Thucydides reminds us, the human aspects that matter most." I love this piece from @RJohnsonCCW1 at @EngelsbergIdeas
engelsbergideas.comHuman behaviour will still determine who wins warsDigitalised defence systems and new technology are important, but they do not eliminate the age old realities of warfare.
3:49 AM ∙ Aug 22, 2022
202Likes34Retweets

-

Twitter avatar for @k8em0
Katie🌻Moussouris @k8em0
Can't believe my @BlackHatEvents talk was a week ago! In case you can't wait for the recording, here are the highlights & announcements I made including: - Metrics to improve VDPs & bug bounties - Hybrid labor models bounty-to-contract - Referral bounties! lutasecurity.com/post/bug-bount…
10:15 PM ∙ Aug 18, 2022
68Likes17Retweets

-

Twitter avatar for @NASAExoplanets
NASA Exoplanets @NASAExoplanets
The misconception that there is no sound in space originates because most space is a ~vacuum, providing no way for sound waves to travel. A galaxy cluster has so much gas that we've picked up actual sound. Here it's amplified, and mixed with other data, to hear a black hole!
7:58 PM ∙ Aug 21, 2022
161,152Likes34,332Retweets

-

Twitter avatar for @matteyeux
matteyeux @matteyeux
[Slides] The hitchhacker’s guide to iPhone Lightning & JTAG hacking
5:26 AM ∙ Aug 22, 2022
121Likes39Retweets

-

https://nelsonfigueroa.dev/using-python-to-flood-scammers-with-fake-passwords/

-

Twitter avatar for @DefenceU
Defense of Ukraine @DefenceU
Maybe we are being too hard on russian tourists… Sometimes they can be really helpful. Like this man taking pictures at russian air defense positions near Yevpatoria, in occupied Crimea. Thank you and keep up the good work!
Image
9:48 AM ∙ Aug 22, 2022
16,776Likes1,578Retweets

The Info Op is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Don't miss what's next. Subscribe to the grugq's newsletter:
X