the grugq's newsletter

Subscribe
Archives
December 8, 2023

December 8, 2023

December 8, 2023

Huge if true. If…

‼️BREAKTHROUGH? First quantum computer with a programmable processor based on encoded 48 logical qubits operating with up to 280 physical qubits, with error correction. Are we nearing the era of useful quantum computation? If this is real, maybe soon? https://t.co/DuODD6ZeUi pic.twitter.com/vNjvh17SG0

— Lukasz Olejnik, Ph.D, LL.M (@lukOlejnik) December 7, 2023

-

Quality reporting this. Expose Russian ops AND point out their failure. Without the latter, we contribute to their success.

Nice one ⁦@gordoncorera⁩

“Russia hacking: 'FSB in years-long cyber attacks on UK', says government” https://t.co/CBsnc7OyPb

— Rory Cormac (@RoryCormac) December 7, 2023

Microsoft Threat Intelligence is sharing additional intelligence on Star Blizzard (overlaps Calisto / ColdRiver), who is active in espionage and IO. UK NCSC has just attributed them to FSB Center 18. The blog details ongoing campaigns and evasionhttps://t.co/bZAiEFPmRz https://t.co/ZJI3qK81Fh

— Justin (@sixdub) December 7, 2023

Microsoft continues to track and disrupt activity attributed to a Russian state-sponsored actor we track as Star Blizzard (SEABORGIUM), who has improved their evasion capabilities since 2022 while remaining focused on email credential theft. Get TTPs: https://t.co/MbvBsF0tlQ

— Microsoft Threat Intelligence (@MsftSecIntel) December 7, 2023


More on the train hack from December 6th

They HACKED A TRAIN. For real. Train operators asked for this to see why their trains didn't run after servicing. Turns out that vendor/producer implemented a geofence lock for trains serviced somewhere else. Amazing story, one of the best hacks in 2023. https://t.co/1ZFpIVfLZr pic.twitter.com/wl81uPiP43

— Lukasz Olejnik, Ph.D, LL.M (@lukOlejnik) December 6, 2023


Another great writeup by @mmolgtm on Chrome RCE through type confusion (CVE-2023-4069)https://t.co/YH8IQzdQs1#chrome #infosec pic.twitter.com/7qwQT1CuaY

— 0xor0ne (@0xor0ne) December 6, 2023


As a Director at Amazon, I repeatedly saw that big tech career incentives basically guarantee cycles of too much growth, and then layoffs. I just had someone email me, and say that they're worried about their career as a development manager.

🧵

— Dave Anderson (@scarletinked) December 6, 2023

How Companies Incentivize Layoffs—A Study of Corporate Career Incentives

Managers at growing companies are incentivized to do one thing more than anything else. Grow their teams. Is it mysterious that most tech companies seem to have over hired?

Thread by @scarletinked on Thread Reader App – Thread Reader App

@scarletinked: As a Director at Amazon, I repeatedly saw that big tech career incentives basically guarantee cycles of too much growth, and then layoffs. I just had someone email me, and say that they're worried abo...…


New blog out by @jshermcyber on Positive Hack Days. Russias largest cyber security conference.https://t.co/9toBOxEQPm

— Ian Roos (@ian_roos) December 5, 2023


Standard Harvard admissions interview pic.twitter.com/i6zb7UpVHG

— Alex Cohen (@anothercohen) December 6, 2023


You see the child safety advocates presenting slanted statistics like this, and they never answer the base rate question: how do their statistics compared to what "everybody does?"

Everybody uses encrypted. Messengers. Therefore, bad people use encrypted messengers. pic.twitter.com/NhiGUwGuJz

— Alec Muffett (@AlecMuffett) December 7, 2023


Here goes fresh Russian propaganda, casually & proudly displaying the USSR flag.
This is the Tupolev Tu-144. A soviet version of the Franco-British supersonic #Concorde. In the 60's, the GRU actually spied on the French manufacturer Sud Aviation to obtain detailed plans of the… pic.twitter.com/4uKWv6jnlf

— x0rz (@x0rz) December 7, 2023


Fun fact: that viral-ish Gemini demo video is basically entirely fake pic.twitter.com/Kaia0UG30y

— Andrew Jones (@ajones55555) December 7, 2023


Just released a full secure-boot exploit chain for the Chromecast with Google TV 1080P with Jan Altensen and Ray Volpe!

Go check it out on DirectDefense's blog! https://t.co/hXXjDPEWVZ

Or on my personal security blog: https://t.co/ZC3G5MmtiE#security #vulnerability #vrp #cve

— Nolen Johnson (@nolenjohnson) December 6, 2023


One day my kid will find out that McDonald’s does not sell a 5 piece McNugget.

— Jessie (@mommajessiec) December 6, 2023


Red Cross: A blood donation is the best gift you can give to someone.

[Christmas morning]

Kids: [all screaming while opening presents]

— Rodney Lacroix (@RodLacroix) December 6, 2023


Absolutely not the bottleneck for phishing emails. There is probably room for AI to improve cyber criminal operations, but writing emails is not gonna be that 10x improvement

EXCLUSIVE: ChatGPT builder helps create cyber crime tool. BBC News built a bespoke GPT trained to craft convincing emails, texts and social posts for well known hacks and scams that the public ChatGPT is moderated to block. It took minutes and zero coding. https://t.co/vTVWdHGVDO

— Joe Tidy (@joetidy) December 7, 2023


https://www.reuters.com/technology/cybersecurity/governments-spying-apple-google-users-through-push-notifications-us-senator-2023-12-06/


Great to see that some of the bugs that we reported to ICS vendors had been fixed.
Thanks to @Peterpan980927 & @CurseRed for CVE-2023-6358https://t.co/UXcdapQgrR
And @testanull for CVE-2023-39474https://t.co/WHEQ4gjQjL
More to come soon.

— starlabs (@starlabs_sg) December 8, 2023


How We Investigated France’s Mass Profiling Machine - Lighthouse Reports

France uses an algorithm to rank millions of people by their alleged risk of welfare fraud — here’s how we took it apart.


you can't fool me, these are all slang words from Futurama or possibly Cyberpunk 2077 https://t.co/YnQHSP2jyY

— Rob DenBleyker (@RobDenBleyker) December 8, 2023

feel like im having a stroke pic.twitter.com/UNG8pRqkgU

— snowboiiii (@snowboiiii) December 8, 2023


Japan-headquartered cybersecurity software provider Trend Micro is relocating its China R&D operations to Canada and has already laid off around 70 employees in its Nanjing R&D center.https://t.co/MFhOflTi5fhttps://t.co/spvXa5XDbq pic.twitter.com/PHx1msuwIS

— Byron Wan (@Byron_Wan) December 8, 2023


Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X