the grugq's newsletter

Subscribe
Archives
August 27, 2025

August27, 2025

August27, 2025

2025 State of the Internet Report: Summary and Conclusionshttps://t.co/rmgBK1198Q

(Screenshot: PolarEdge infections as of 5 August 2025) pic.twitter.com/CGq2Uryc68

— Silas Cutler // p1nk (@silascutler) August 26, 2025


Every bug hunter's eyes on Google Big Sleep recent v8 finding, I find it very challenging to prompt AI to create the testcase to trigger the crash given a bug description. https://t.co/YsgyWv30Rk

— Suto (@__suto) August 27, 2025


August 14th we posted this and mocked, sayiny it was probably North Korea. Some people (for reasons I don't understand) said it was probably safe (it's not)

Thankfully, @infrawatch_app went way out there way to investigate the company mentioned in the Reddit post (DSLRoot) and… pic.twitter.com/AR58gng51E

— vx-underground (@vxunderground) August 26, 2025


Suppose you're going to hype some malware using an LLM, at least hype what it's doing to make it more evasive, stealthy, etc. Simply pulling down the enumeration code from an LLM isn't it.

— Justin Elze (@HackingLZ) August 26, 2025


For our friends, active measures. For our enemies, red carpet summits. https://t.co/jHoraiZYLm pic.twitter.com/SdVx4EasUF

— Michael Weiss (@michaeldweiss) August 27, 2025


Lots of frustration in the malware analysis and reverse engineering community.

It's been discovered a DEFCON talk, presentation, and the code which coincided with it, was AI slop. The talk itself had hallucinated terminology which (apparently) no one at DEFCON noticed.

Bad. pic.twitter.com/TuoCB1cCE1

— vx-underground (@vxunderground) August 27, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X