the grugq's newsletter

Subscribe
Archives
December 7, 2024

December 7, 2024

December 7, 2024

A Russian state-sponsored hacker group, known as Gamaredon, has been targeting Ukrainian-speaking victims in an ongoing cyber-espionage campaign, researchers have found. https://t.co/8Tz3bog44I @TheRecord_Media

— 780th Military Intelligence Brigade (Cyber) (@780thC) December 6, 2024


Don't forget: the government spent decades warning us against against encryption.

Short-sighted gaslighting that made America less safe. pic.twitter.com/DczCyG3Tkm

— John Scott-Railton (@jsrailton) December 6, 2024

The systems used to intercept those calls were designed, built and installed specifically for the FBI to intercept calls. These systems were working exactly as intended, except being operated by “the bad guys.” A scenario always raised as a reason for strong encryption. https://t.co/HoTKO8KxW7

— thaddeus e. grugq (@thegrugq) December 6, 2024

A good question to ask is the societal damage greater from LE losing access to all wiretap at the risk of an APT having access ( to some currently unknown degree)?

— Mither (@reidgarrett48) December 7, 2024

This is exactly the conversation to have, except instead we’ve had the FBI et al. stating that there is no risk except the risk of losing access. They have shut down the discussion by insisting it is good guys vs bad guys, rather than tradeoffs between different bad outcomes.

— thaddeus e. grugq (@thegrugq) December 7, 2024


this actually is the cyberpunk i expected pic.twitter.com/q3gKd97ZG1

— phones with six ones (@phones111111) December 6, 2024


When your LLM troll bot has a 2023 knowledge cutoff date pic.twitter.com/arFoXZENeJ

— lcamtuf (@lcamtuf) December 6, 2024


I figured out a new way to **completely** disable certain EDR products only with Admin privileges in less than 30 lines of code with native applications.

It works by deleting critical application files before they can do anything 🙃

A link to the GitHub repo with a PoC follows. pic.twitter.com/wU0XJAQv6u

— Rad (@rad9800) December 5, 2024

https://t.co/hiOKYckvQq

— Rad (@rad9800) December 5, 2024


Even worse, half of today’s students score below the median, some of them well below. pic.twitter.com/W5xT3WTYTt

— Benjamin Ryan (@benryanwriter) December 6, 2024


look: when you solve a simple problem (finding all the UUIDs) in an effective way (making a big list), people notice.

investors, I'm happy to talk about leasing UUID space on my site to you https://t.co/E5UbEjUmTU pic.twitter.com/Fd9iL1EmEj

— nolen (@itseieio) December 6, 2024

the site is over here: https://t.co/ZecM1gErEx and i wrote a blog about what i learned from making it over at https://t.co/vEq57jwXsb. but i can capture a few fun things here:

— nolen (@itseieio) December 6, 2024


Let us be grateful that most supply chain attacks are crypto weenie attacks and nothing more serioushttps://t.co/Zoiluf1MOX

silver lining and all that

— Daniel Cuthbert (@dcuthbert) December 7, 2024


https://t.co/ayWWt8UJJy pic.twitter.com/XoYEDgbq60

— Encyclopaedia Britannica (@Britannica) December 6, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
X