the grugq's newsletter

Subscribe
Archives
August 26, 2023

August 26, 2023

August 26, 2023

Introducing:
"Prompt Injection Primer for Engineers" 🚀

One of my big take-aways from the AI Village at @defcon was the confusion around Prompt Injection.

How serious is it?
What can attackers do with it?
How can it be prevented?

This has the answers: https://t.co/URvJxCX03E pic.twitter.com/ucmBFKEvBe

— 𝚛𝚎𝚣𝟶 (@rez0__) August 25, 2023

🔥 The People v Moyer appellate decision just dropped

Tom Moyer is Apple's Chief Compliance Officer & was indicted for bribing Santa Clara's Sheriff's Office

The charges mysteriously got dropped, but DA appealed

The charge of criminal bribery against Moyer was just reinstated pic.twitter.com/EMI8xdiR2j

— Ashley M. Gjøvik (@ashleygjovik) August 25, 2023

Repo for my @reconmtl talk slides+demo code is up. It’s a WIP so ⭐️ it for all the updates (diabolical polymorphism++): https://t.co/ZR3N9tk0Aa
Bootkit can be run on an emulator or real hardware. Merci x1000 à @reconmtl for having me as a speaker this year. À la prochaine✨[1/n]

— ic3qu33n (@nikaroxanne) August 25, 2023

A privately owned Israeli spyware firm helped the DHS monitor the online presences of Americans. That company is now set to join forces with competitors, creating a private social media surveillance apparatus unlike anything previously known.https://t.co/OqyHi4rLU4

— JΞSŦΞR ✪ ΔCŦUΔL (@th3j35t3r) August 23, 2023

"Never write down your passwords" they said...https://t.co/4Pm0bF6jwO

— mtanji (@mtanji) August 25, 2023

My turn

“Cybersecurity trends to watch for in 2024” https://t.co/vfg9KDOlTt

— C:\hristina (@divinetechygirl) August 25, 2023

I’ll pass https://t.co/5FNVuHtmwR

— switched (@switch_d) August 25, 2023

The declassified intelligence analysis said the F.S.B. had helped fund Creative Diplomacy and that it was a “grooming campaign” that Russian intelligence operatives used to build up a network of “future Western influencers”https://t.co/Y0ApWgJLyD

— Preston Stewart (@prestonstew_) August 26, 2023

CVE-2020-19909 is everything that is wrong with CVEs

Another 9.8 CRITICAL curl problem. All made up.https://t.co/iiWAnJHCYh pic.twitter.com/1GZOeb158C

— daniel:// stenberg:// (@bagder) August 25, 2023

Pleased to share that my client Roman Storm is already out on bail, although I remain very disappointed that the prosecutors charged him because he helped develop software - their novel legal theory has dangerous implications for all software developers.https://t.co/elmU8VqpYq

— Brian Klein (@brianeklein) August 24, 2023

Here are the slides for my talk “It was harder to sniff Bluetooth through my mask during the pandemic…” from yesterday at @HITBSecConf . (Oh hey, and new website!)https://t.co/RJ15fWxGF0

— Xeno Kovah (@XenoKovah) August 25, 2023

NEW: The number of victims of the massive MOVEit data breach has reached 1,000.

If those were the only victims it would already be one of the largest hacks of the year, but it's likely there are a lot more companies who were hit and we don't know yet. https://t.co/d6ukjUyT7w

— Lorenzo Franceschi-Bicchierai (@lorenzofb) August 25, 2023

Me, @caseyjohnellis, and @joegrand settling in front row, giddy af to see @thegrugq close out @HITBSecConf... 😂 great exhibition all round @l33tdawg #HITB2023HKT pic.twitter.com/m7VVHg7TTa

— Sick.Codes (@sickcodes) August 25, 2023

The keynote has arrived.

“Systems Alchemy: The Transmutation of Hacking by @thegrugq” @HITBSecConf #HITB2023HKT pic.twitter.com/1XyLLrwTVN

— Sick.Codes (@sickcodes) August 25, 2023

Apple denied rehearing on Apple v. Corellium case. https://t.co/BxH7tdgPhB

— Chris (@cmwdotme) August 24, 2023

Rapid7 asking me to remove an educational content from YouTube over the fact that used them as an example for publicly accessible swagger file. pic.twitter.com/qkOcixlLny

— Ben Sadeghipour (@NahamSec) August 23, 2023

Excellent free book on compilers, linkers, JITs and assemblers for software security hardening

Low-Level Software Security for Compiler Developers:https://t.co/7tIZD6zFwP#cybersecurity #compilers pic.twitter.com/m2ehUcCJev

— 0xor0ne (@0xor0ne) August 25, 2023

Interesting bug chain 🪲🔗

CVE-2023-36844 And Friends: #RCE In #Juniper Deviceshttps://t.co/Iii2X4Dkse pic.twitter.com/2YWN5SKKf4

— raptor@infosec.exchange (@0xdea) August 26, 2023

Still time to apply for our online PG Cert course (PT or FT) this September. The course starts with a module on Covert Action. https://t.co/WsmHhpr53y pic.twitter.com/4F1vEcvjxV

— BUCSIS (@BUCSIS2) August 26, 2023

The shittiest street in all of England! pic.twitter.com/qrnz0N8lU2

— Cody Moser (@LTF_01) August 26, 2023

“And if it isn’t it is a solid number 2”

— Bert Hubert 🇺🇦 (@bert_hu_bert) August 26, 2023

Oakland Tribune, California, August 20, 1939 pic.twitter.com/avU591NPa9

— Yesterday's Print (@yesterdaysprint) August 25, 2023

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X