the grugq's newsletter

Subscribe
Archives
August 29, 2023

August 29, 2023

August 29, 2023

NEW: Hackers breached WebDetective, a Portuguese-language stalkerware app that was used to monitor 76,000 Android phones in recent years.

The hackers claimed they deleted the data of people spied with the app from the company's servers. https://t.co/MiohMYEMwy

— Lorenzo Franceschi-Bicchierai (@lorenzofb) August 28, 2023

North Korean Lazarus group launching new malware with several on-trend features: 1) targetting healthcare because they pay 2) using a vulnerability in respected software to get in and 3) using open source code and tools to avoid detection. @thegrugq https://t.co/Q0smjMYKmm

— Jan Lemnitzer (@JanLemnitzer) August 28, 2023

Forget vulnerable drivers - Admin is all you need

Article 👉 https://t.co/dHO0KJ90WH
👇 Demo - enable sound 🔊 pic.twitter.com/ZoTqsuXZ7k

— Gabriel Landau (@GabrielLandau) August 28, 2023

A detailed two part video showing how we found a DNS parsing vulnerability and wrote a remote root exploit for it🤌

Part 1: Finding the vulnerability via "fuzzing" and reverse engineering with Ghidra 👾https://t.co/NwXsa32sMB

Part 2: Understanding vulnerability constraints and… pic.twitter.com/D9zCV35ZH9

— Pedro Ribeiro (@pedrib1337) August 28, 2023

System-wide Intel PT+ DCI (hardware debugger) + NT symbol resolution. it is going to be🔥 https://t.co/nETT0AVzRh

— Satoshi Tanda (@standa_t) August 28, 2023

Are you a cyber practitioner in Scotland? If so, consider lending your expertise as a judge in our first-ever #Cyber912 competition for S5 and S6 students.

Find more details and register here:https://t.co/GOHL46vmRb@CyberStatecraft @dewarcyber @AbertayCQ @girvanacademy

— Cyber Statecraft (@CyberStatecraft) August 28, 2023

Also a reminder about how resilience & safety works in critical systems.

People ask: “what if hackers took down air traffic control?”

The answer is what we’re seeing today with accidental failure: move to backup methods, massive delays & costs but no extra risk to human safety https://t.co/DcralkDQVN

— Ciaran Martin (@ciaranmartinoxf) August 28, 2023

A note about what's going on here.
1) Word will render HTML (including MHT) content regardless of what comes before it. Plain text plays nicest.
2) When MHT content includes a <link rel=Edit-Time-Data> object that points to an undocumented ActiveMime blob, there's your Macro! https://t.co/GVM9Ke9zE7 pic.twitter.com/9f3NqhQ7N4

— Will Dormann (@wdormann) August 28, 2023

Russian-Swede Accused of Illicit Western Technology Transfers to Moscow https://t.co/8foHapzXzi

— Dr. Dan Lomas (@Sandbagger_01) August 28, 2023

My custom instructions to fix chatGPT output:
----
I'm your technical manager Geoffrey Hinton who likes kanban boards and always requires you submit complete output, complete code that just works when I copy paste it to use in my own work.
----
Respond with tree of thought… pic.twitter.com/K4D7OWZxTH

— nisten (@nisten) August 28, 2023

*youth pastor sitting on chair backwards*

“Let me tell you about *another* three person polycule…”

— 🦇VaginoplASCII🦇 (@nataliereed84) June 24, 2023

Interesting blog post on embedded devices reverse engineering (Brightway (Xiaomi) scooters)https://t.co/xAyTqQjSND#reverseengineering #cybersecurity #infotech pic.twitter.com/vdubSknegw

— 0xor0ne (@0xor0ne) August 28, 2023

"In July, an attack that was disguised as a ransomware incident temporarily closed down the port of Nagoya. It has since been assessed by government cyber experts as part of a “persistent testing of Japan’s infrastructural defences by China”." https://t.co/WOKkCdy3jA

— Dan Black (@DanWBlack) August 29, 2023

Hello @x @premium the phishing scam spam from fake verified orgs on Twitter has gotten out of control.

These 12 accounts are all just from the past 48 hrs alone.

Verified orgs were intended to make it harder for scammers but it has just created a new black market for accounts… pic.twitter.com/cppyD5cUSj

— ZachXBT (@zachxbt) August 27, 2023

Tod Beardsley 🏴‍☠️: "Well that’s just too many #DLink vulns. 51 on one…" - Infosec Exchange

Well that’s just too many #DLink vulns. 51 on one day from #ZDI? https://www.zerodayinitiative.com/advisories/published/


Don't miss what's next. Subscribe to the grugq's newsletter:
X