the grugq's newsletter

Subscribe
Archives
August 23, 2025

August 23, 2025

August 23, 2025

Brief info and POC for this week's Apple 0click iOS 18.6.1 RCE bug CVE-2025-43300 https://t.co/EL3qg56N8X pic.twitter.com/j8yuv1CXU7

— binaryboy (@b1n4r1b01) August 22, 2025


attribution often finds you, yet sometimes... https://t.co/B9Ev2Tf1hM pic.twitter.com/ITWEU2hmTw

— J⩜⃝mie Williams (@jamieantisocial) August 22, 2025


Right now, the media is hyping up a story that a SECRET HACKER FIRMWARE FOR FLIPPER ZERO HAS APPEARED ON THE DARKNET THAT CAN HACK ANY CAR!!!11 WE’RE ALL IN DANGER.

Let’s break it down and see if that’s actually true (spoiler: it’s not): https://t.co/JZPz5KZKcP pic.twitter.com/bDTCi9aHFt

— Flipper Zero (@flipper_zero) August 22, 2025


Weekly summary is out..https://t.co/gBUcyelB96

— Ollie Whitehouse (@ollieatnowhere) August 23, 2025


In case you haven't been following, incredible things are being unpacked in this thread about all these little stupid software (OneStart, AppSuite, Wave Browser, etc.) you've been getting alerts for in the last few months/year.

So much collaborative effort too 💪 https://t.co/kf5QZhiXV9

— Aura (@SecurityAura) August 22, 2025


I Just documented a cool way to authenticate proxied tooling to LDAP in an AD environment using C2 payload auth context, without stealing any tickets or hashes!

Keep tooling execution off-host and away from EDR on your Red Team assessments! https://t.co/VLE2Kh4idY

— Logan Goins (@_logangoins) August 22, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X