the grugq's newsletter

Subscribe
Archives
December 9, 2023

December 9, 2023

December 9, 2023

Spain expels two US diplomats on charges they tried to buy secrets off Spanish agents everyone has kept this pretty quiet https://t.co/y1UCtjldzO

— Mitchell Prothero (@mitchprothero) December 8, 2023

UK gov has some thoughts on Facebook deploying a safer Messenger.

Apparently because Facebook Messenger is now encrypted, every single month 1200 children will be victims of CSAM and 800 perpetrators will evade the police. That means Facebook is putting about 10,000 pedophiles on the streets every single year.

NCA response to Meta's rollout of end-to-end-encryption - National Crime Agency

James Babbage, Director General for Threats at the National Crime Agency, said:


5G bugs

https://asset-group.github.io/disclosures/5ghoul/


For those interested in developing standalone binaries that exploit vulnerable drivers (BYOVD), I just released a tool called IoctlHunter. This tool ease the process of identifying weaponisable IOCTL codes in win drivers 👌

📚 Blog post, code & full demo: https://t.co/oinfd0KJUz pic.twitter.com/cSza2EAAlt

— Zak (@_ZakSec) December 8, 2023


quite the jump! pic.twitter.com/0C8yI1x4sB

— sean (@DilettanteryPod) December 8, 2023

https://t.co/dUniaR4QD8 pic.twitter.com/Znz5bHquX4

— sean (@DilettanteryPod) December 8, 2023


Verizon fell for fake “search warrant,” gave victim’s phone data to stalker | Ars Technica

Verizon tricked by fake cop, fake search warrant despite obvious warning signs.


decades-long manhunt ends, finally bringing closure to grandson of trampling victim pic.twitter.com/YKGsRTq5mT

— Uncle Duke (@UncleDuke1969) December 8, 2023


Skyview

I said that “tankies” are people who want to fuck thomas the tank engine


Cartographer from @NCCGroupInfosec Austin Peavy - Nice code coverage visualizer for Ghidra similar to @gaasedelen Lighthouse plugin for IDA/Binja. It came up in discussion while I was teaching my Advanced Fuzzing and Crash Analysis training this week.https://t.co/IuUbcVZ5HL

— Richard Johnson (@richinseattle) December 9, 2023


Thanks to everyone that helped connect the dots 🫶🏻

to Dan & Glenn for writing such a great tune to share with us 25 years later 👽https://t.co/EkmdBAZ2eG https://t.co/TQBzJ4cbCm

— auntie cistamine (@laurenancona) December 8, 2023

The stunning conclusion to this thread:

just had the weirdest experience

was watching an X-files episode & there’s this country song playing in the background of the bar they’re in

& it’s so good it jars me out of my idle multitasking to Shazam it

except

— auntie cistamine (@laurenancona) December 5, 2023


Today I used Father Christmas to teach implausible deniability in covert action.

My son knows. He knows I know he knows. But we tacitly agree that acknowledgment would be consequential

— Rory Cormac (@RoryCormac) December 8, 2023


Love this detail on Russian attempts to hack St Andrews: pic.twitter.com/5spKC66UnV

— James Shield (@jshield) December 7, 2023


This is clever. I like it

Notable tactic from the UNC4057/COLDRIVER indictment yesterday that's a favorite for them:

"Some of the [phishing] emails directed the victims to a document that was not attached, designed to engage in an email response for the missing document and to later include the document"

— Dan Black (@DanWBlack) December 8, 2023


They made the agreement! Where there is Will and Hope, there is a way. The sleep-deprivating 20-hour marathon on Wednesday/Thursday, and the fact of Friday may have helped. The AI Artificial Intelligence Act has been agreed and it is moving forward! https://t.co/lobK7UOTdo pic.twitter.com/RwP7FLzLJL

— Lukasz Olejnik, Ph.D, LL.M (@lukOlejnik) December 9, 2023


I promise I only started singing when the police needed people to evacuate the train. https://t.co/i73m5ifQSq

— James Blunt (@JamesBlunt) December 8, 2023

Rachel Riley and James Blunt among Elizabeth Line passengers stuck for hours after electrical cables damaged https://t.co/ELctPu2Evr

— LBC (@LBC) December 8, 2023

you're dutiful, it's true

— Domino's Pizza UK (@Dominos_UK) December 8, 2023


Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X