the grugq's newsletter

Subscribe
Archives
August 4, 2024

August 4, 2024

August 4, 2024

LayeredSyscall – Abusing VEH to Bypass EDRs : https://t.co/PWlPoiLZm9

Bypassing AV/EDR Hooks via Vectored Syscall - POC
Vectored Syscall : https://t.co/TPqn6oCtuI pic.twitter.com/DuuHZrrh6X

— Binni Shah (@binitamshah) August 2, 2024


Instead of playing cat and mouse with attackers trying to disable EDR, build your environment so that hosts can't authenticate to access network and resources without backend systems verifying that EDR is active on that host via querying host's status on EDR backend. https://t.co/TiZu4wCQos

— Dino A. Dai Zovi (@dinodaizovi) August 3, 2024


Interested in messaging app research on iOS? Follow along with @__comedian in our blog series "You Can't Spell WebRTC without RCE!" Part 1 dives into Signal’s WebRTC calling library and injects bugs to facilitate deeper research: https://t.co/Z239n7HjGu

— Margin Research (@Margin_Research) July 22, 2024

You Can't Spell WebRTC without RCE - Part 2 blog post, which turns the vulnerabilities we injected in Part 1 into remote code execution on iOS 16.4! Follow along with @__comedian to learn more about the iOS shared cache, Corellium, and ROP in ARM64! https://t.co/vxSlNpnFtc

— Margin Research (@Margin_Research) August 2, 2024


This is an interesting OSINT source

Based on the Wikipedia edit history rule, it looks like Harris's VP pick might be Shapiro (more than 50 edits in the last 24 hours, compared to zero/single digits for Kelly and Walz) pic.twitter.com/ELzdrqB3E1

— graham starr (@GrahamStarr) August 3, 2024


The model of the sunken and deteriorated Soviet K-129 submarine was created by the CIA during the AZORIAN mission, and has never been displayed before. (cia museum/ cia) pic.twitter.com/KPYJmGLK6O

— J.J. (@kadonkey) August 3, 2024


The model of the sunken and deteriorated Soviet K-129 submarine was created by the CIA during the AZORIAN mission, and has never been displayed before. (cia museum/ cia) pic.twitter.com/KPYJmGLK6O

— J.J. (@kadonkey) August 3, 2024


The video from the 30 Years of Decompilation celebration at @QUT
is now live at https://t.co/i4dDuO6eSU. The celebration features discussions with Emeritus Professor John Gough, myself, Mike Van Emmerik, Anne Fitzgerald, and Trent Waddington. Thanks to Paul Roe for organising!

— Cristina Cifuentes (@criscifuentes) August 4, 2024


One of Jeff Dean's super powers is to be able to come up with reasonable approximations for very complex problems quickly. He also has the "latency numbers every engineer should know" that helped him reason about map reduce, search indexes, etc for this reason as well. Incredibly… https://t.co/TFZDXXSduD pic.twitter.com/LiOUdT2Z3V

— xjdr (@_xjdr) August 3, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X