the grugq's newsletter

Subscribe
Archives
August 7, 2025

August 7, 2025

August 7, 2025

This might be the first time the Swiss weren't able to reach a financial deal with nazis [contains quote post or other embedded content]

— Sam (ABeardedPanda) (@abeardedpanda.bsky.social) 2025-08-06T16:51:51.411Z


The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die: https://t.co/3vZ2bMx9DA

— James Kettle (@albinowax) August 6, 2025


We engineered an attack against @GitHubCopilot to add a hidden backdoor via a malicious GitHub issue. See if you would’ve fallen for it: https://t.co/sbhErMUkic

— Trail of Bits (@trailofbits) August 6, 2025


Our “Dark Corners: How a Failed Patch Left VMware ESXi VM Escapes Open for Two Years” slides are now available!

This research was a collaborative effort with @0x140ce, @ezrak1e and myself.

In this talk, we introduce the ESXi virtual machine escape and sandbox escape…

— Danis Jiang (@danis_jiang) August 7, 2025


A person familiar with the matter confirms that CISA will be publishing an emergency directive to agencies tomorrow that requires them to patch this vulnerability. https://t.co/KZfKmWjCPt

— Eric Geller (@ericgeller) August 7, 2025


Russians trying to fool our AI interceptor drones by putting bird stickers onto their reconnaissance drones.

Insane warfare. pic.twitter.com/qneUapEDzM

— Dimko Zhluktenko 🇺🇦⚔️ (@dim0kq) August 7, 2025


After a long hiatus into the world of ITWs, I present my research on Mangyongdae and its importance to the #DPRK Cyber-Warfare machine. Included are new ITW indicators, alongside analysis of recent developments within the district. We also found Unit 91.https://t.co/8zmdel3KYJ

— 🍌rchism (@eastside_nci) August 6, 2025


Full article: Learning from mistakes: the impact of the October 7 surprise attack on the youngest generation of IDF intelligence analysts https://t.co/1DFiNGxEqP

— Covert Intel and Operations (@covert_intel) August 6, 2025


A spectre is haunting Europe - the spectre of the Dutch Holiday Octopus https://t.co/obzCHmWtfr

— Mike Bird (@Birdyword) August 6, 2025


🚨New Black Hat research released: Over $200k in bounties earned in just two weeks. Join the movement to kill HTTP/1.1 today ⬇️

🔍PortSwigger’s James Kettle (@albinowax) introduces two new classes of HTTP desync attacks capable of compromising credentials on tens of millions of… pic.twitter.com/iIQatd8US8

— PortSwigger (@PortSwigger) August 6, 2025


Not sure why but we have lots of new followers!

FFmpeg makes extensive use of hand-written assembly code for huge (10-50x) speed increases so we are providing assembly lessons to teach a new generation of assembly language programmers. Learn more here:https://t.co/u6MKBb3Xbk

— FFmpeg (@FFmpeg) August 6, 2025


''GitHub - DosX-dev/obfus.h: Macro-header for compile-time C obfuscation (tcc, win x86/x64)''#infosec #pentest #redteam #blueteamhttps://t.co/f8i4SGXust

— Florian Hansemann (@CyberWarship) August 6, 2025
Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X