the grugq's newsletter

Subscribe
Archives
August 25, 2025

August 25, 2025

August 25, 2025

David Gerard: "latest hilarity: Perplexity, the AI search engin…" - GSV Sleeper Service

latest hilarity: Perplexity, the AI search engine, have a new AI-Agent web browser, Comet! It can do things for you! like get prompt-injected by any web page comment I am annoyed this was found by Brave, who can fuck off, but due credit: https://web.archive.org/web/20250820140623/https://brave.com/blog/comet-prompt-injection/


👉 CVE-2025-42069 is a glippity glop flaw in the zibble-zabble firewall matrix.
💥 It affects versions full-rizzle and wizzle-wazzle with blop authentication enabled.
💻 Remote jibber-jabber can execute glop-glop with high blargh — full system zabble possible! 😱

👉…

— 安坂星海 Azaka || VTuber (@AzakaSekai_) August 24, 2025


If you’ve never read a cyber insurance policy, I recommend it. They’re crazy. The only reason they ever pay out anything is to keep you on the hook for continuing the policy. They can deny pretty much anything as it is! https://t.co/I47gzD7tXz

— Dr. Wesley McGrew (@McGrewSecurity) August 24, 2025


https://www.suspectfile.com/qilin-and-their-alleged-legal-department-criminal-propaganda-disguised-as-legitimacy/


Following their defeat: The Wagner Group withdraws from Mali https://t.co/YAqmUHeFLh

— switched (@switch_d) August 25, 2025


Unexpectedly, one of the subjects of our investigations, Tim Stigal - core former member of GRU Unit 29155's hacking team - speaks to the press and admits nearly everything we disclosed here: https://t.co/9gD4ytaKav pic.twitter.com/H11wCNeiZT

— ChristoGrozev@bsky.social (@christogrozev) August 25, 2025


Made a pwn challenge for this year’s HITCON CTF, which required participants to bypass PAC, BTI, and deal with relative vtables. Here’s the write-up:https://t.co/5IrEynUF3T
Check it out if you're interested🙂

— Bruce Chen (@bruce30262) August 25, 2025

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X