the grugq's newsletter

Subscribe
Archives
August 29, 2025

August 29, 2025

August 29, 2025

I'm once again looking at the epic 20-part essay which Ian Lance Taylor wrote about linkers https://t.co/DKtvyCiP6r - did anyone ever write anything remotely comparable about the MSVC linker? Like, very remotely even?

— Mari0n (@pinkflawd) August 28, 2025

https://lwn.net/Articles/276782/


typos remain the undefeated forensic artifact. https://t.co/MnUFGiOAMQ pic.twitter.com/npvS7RNkzK

— J⩜⃝mie Williams (@jamieantisocial) August 28, 2025


📣AI propaganda factories🏭 are now operational. My study shows how small, open-weight models can run as fully automatic generators in influence campaigns. mechanising personas, engagement, cadence. Possible for State, non-state, and micro-actors, including and bedroom ones. pic.twitter.com/V1GTy7zJwJ

— Lukasz Olejnik (@lukOlejnik) August 29, 2025


Bump pic.twitter.com/ix3jOCL1Zp

— Justin Elze (@HackingLZ) August 28, 2025


Here's an interesting and detailed piece of how the #NSA moved its data from many different databases and repositories to a single secure cloud environment:https://t.co/F8HTe0ifji

— Electrospaces (@electrospaces) August 28, 2025


Iran link to Australian synagogue attack uncovered via funding trail, spy agency says  https://t.co/igIWaFTNp7

— Dr. Dan Lomas (@Sandbagger_01) August 29, 2025


"An attacker is doing 2️⃣ + 2️⃣ to get 4️⃣, and that’s a problem so you block it.

...then they do 5️⃣ – 1️⃣" https://t.co/AF9v7FGdal pic.twitter.com/M1AA1gFt8k

— J⩜⃝mie Williams (@jamieantisocial) August 28, 2025


This technique is clever... the stochastic nature of LLMs mean that the commands emitted by the LLM will be somewhat diverse, but still achieve the same objective. https://t.co/ODxC4RwpGC

— Dino A. Dai Zovi (@dinodaizovi) August 28, 2025


In summary, make a big ass button at the top of a webpage. Safari can't think good and the big ass button overlaps the URL display. The URL will then incorrectly display iCloud instead of the actual URL (malicious).

It doesn't impact Chromium-based browsers or Firefox https://t.co/bhWYXOK1GK

— vx-underground (@vxunderground) August 28, 2025


I'm working on a universal bucket list for corporations:

1) Declare that you're a different kind of a company

2) Design and announce your own typeface

3) One year of free credit monitoring

— lcamtuf (@lcamtuf) August 28, 2025
Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X