the grugq's newsletter

Subscribe
Archives
December 23, 2023

December 23, 2023

December 23, 2023

Holiday gift for you. Ghidra 11.0 released! New BSim feature can find structurally similar functions in (potentially large) collections of binaries or object files. Initial support for Rust compiled binaries. Golang improved. +morehttps://t.co/08mFeYtGW3

— Rob Joyce (@NSA_CSDirector) December 22, 2023

Latest Ghidra has function similarity search built in, using feature vectors calculated by the decompiler. https://t.co/mrmvH8CJU1 pic.twitter.com/ywSesC7BCp

— Antti Tikkanen (@anttitikkanen) December 22, 2023


Dear folks running bounty programs, I have a holiday request: If I send you a full read XXE, consider it as RCE. That has been true for me, always, since 2012. I don't want to mess with your prod environment to change the CVSS from 9.6 to 9.8 or 10 but if, you ask, I will. Thanks

— Reginaldo Silva (@reginaldojsf) December 22, 2023


Predatory sparrows are still all up in the Iranian gas stations. Seems like they are banging the “signal” drum pretty hard on this one

با وجود اینکه چند روز از #هک سیستم #سوخت_رسانی گذشته اما هنوز #پمپ_بنزین ها کار نمیکنند، در اصل چون ما تصمیم نگرفتیم که کار کنند...
پس چه زمانی کار میکنند؟ هر وقت تصمیم بگیریم :) https://t.co/fqyOua0L1k

— Gonjeshke Darande (@darandegonjeshk) December 22, 2023

شرمنده #جمهوری_اسلامی منطقه را نا امن کرد
ما هم گفتیم یه واکنش مختصری بهشون بدیم
خلاصه خوشحال شدیم هنوز کار نمیکنه 😉

The #Islamic_republic destabilized the region with their #terror_proxies and we had to give them a small response. Happy out response is still "working" 😉 https://t.co/DlDvV6GSjN

— Gonjeshke Darande (@darandegonjeshk) December 22, 2023


I bet I could do some bad things in this hotel room🐸 pic.twitter.com/zFMEseM4wv

— Takwan (@CriticalTakwan) December 22, 2023


If I put this together, can I list server architect on my resume? pic.twitter.com/shIJGiW9hX

— InfoSec Artist (@infosecart) December 22, 2023


pic.twitter.com/0AKUd42RLk

— EvilMog (@Evil_Mog) December 22, 2023


omg take away his keys https://t.co/YvuqREhT65

— Faux Pelini (@FauxPelini) December 22, 2023

One person has been arrested every hour since the start of December for drink or drug driving, according to gardaí https://t.co/UTVqeZwisF

— RTÉ News (@rtenews) December 21, 2023


Lot of noise to signal in here, but an interesting exploit. By combining a number of small low severity vulnerabilities spammers are able to achieve good results.

Google Search Overwhelmed By Massive Spam Attack

Google is apparently struggling to contain a spam attack that's been ongoing for days


pic.twitter.com/8txTsk7uKU

— ettingermentum (@ettingermentum) December 22, 2023


when people recognize me irl they yell my tweets at me like “tom i always say GORSH when i nut now” or “my dick looks like a bald werewolf too” and i have to be like “thanks man... grandma this is FootFreak69 he’s my friend from the computer”

— old tom (@YuckyTom) August 12, 2018


BREAKING: President Joe Biden has announced he's issuing a federal pardon to every American who has used marijuana in the past, including those who were never arrested or prosecuted.

— unusual_whales (@unusual_whales) December 22, 2023


One cyber crime actor – Lace Tempest (and pretty much a single persona within that team) – has obtained and exploited 5 0days and 1 n-day without a public POC to deploy ransomware [CL0P]

1️⃣ Accellion FTA CVE-2021-27101 (+CVE-2021-27102/CVE-2021-27103/CVE-2021-27104)
2️⃣… https://t.co/ZomsUKOu5T

— Nick Carr (@ItsReallyNick) December 21, 2023

🔴 Lace Tempest (aka FIN11/TA505/DEV-0950) has used at least 1 n-day and 4 zero-day attacks as initial access (T1190) to deploy CL0P ransomware/extortion:

▪ Accellion FTA CVE-2021-27101 (+CVE-2021-27102/CVE-2021-27103/CVE-2021-27104)
▪ SolarWinds Serv-U CVE-2021-35211
▪… https://t.co/hDnYXljHBS pic.twitter.com/stQaMEi5aq

— Germán Fernández (@1ZRR4H) June 6, 2023


This week on the blog: How do we know how many people lived in ancient Greece or Rome? What methods do we use to make those estimates? Are they good enough to do big 'macro-history' with?

Spoilers: the best we can do is not very reliable at all!https://t.co/YGkK1jax3u

— Bret Devereaux (@BretDevereaux) December 23, 2023


Cyber-espionage group Cloud Atlas targets Russian companies with war-related phishing attackshttps://t.co/aIc8c4YdlE

— Dr. Dan Lomas (@Sandbagger_01) December 22, 2023


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X