the grugq's newsletter

Subscribe
Archives
February 11, 2024

February 11, 2024

February 11, 2024

"This included £10 million from Huawei, the tech firm banned in 2020 from Britain’s 5G networks. Overall, about a third of all Chinese funding to UK universities had links to the country’s military, according to the report".https://t.co/3t9vVuMTgS

— Dr. Dan Lomas (@Sandbagger_01) February 10, 2024


After a late night drinking with @_dirkjan I decided to add his ROADTools package (at least in part) to octopwn.
Had to do some rewrite and not all functionalities supported at the moment.
Regardless, if you're interested the code is here:https://t.co/Ugc390whL6

— SkelSec (@SkelSec) February 10, 2024

GitHub - skelsec/aroadtools: fully async implementation of Dirkjan's ROADTools

fully async implementation of Dirkjan's ROADTools - GitHub - skelsec/aroadtools: fully async implementation of Dirkjan's ROADTools


“we need more complex female characters” y’all could barely handle her https://t.co/woVoHMlTAi pic.twitter.com/J1je6e7Lor

— i can be your long lost pal (@PallaviGunalan) February 10, 2024


This is an excellent blog post on (x86-64 ELF) Thread Local Storage (TLS) for
anyone interested in learning more about ELF, Linux kernel and processes and
dynamic linkerhttps://t.co/HRGmrKFkmO#elf #Linux pic.twitter.com/9MJclINefG

— 0xor0ne (@0xor0ne) February 10, 2024

The new director of the #NSA, Timothy D. Haugh, in his new office (with phones and computers likely behind his back): https://t.co/HebKlRBiWV

— Electrospaces (@electrospaces) February 10, 2024

Gen Timothy D. Haugh, who assumed leadership of @US_CYBERCOM and NSA/CSS at a ceremony last week, dives into his new role during his first week on the job. pic.twitter.com/45oVdLzijg

— NSA/CSS (@NSAGov) February 9, 2024


Chainalysis' report indicates ransomware *payments exceeded $1,100,000,000 in 2023.

*Payments which are confirmed to be attributed to ransomware attacks, more attacks may not have been identified

More information: https://t.co/NPkAqMcf8B pic.twitter.com/xecwxtKxpQ

— vx-underground (@vxunderground) February 10, 2024


One of the more amusing things I saw in the Hamas tunnel leading to its data center under the UNRWA HQ in Gaza City was this poster with opsec instructions for the terror group's IT staff.

You can read more here: https://t.co/K8N11PnrGf pic.twitter.com/US1NvZZlZj

— Emanuel (Mannie) Fabian (@manniefabian) February 10, 2024


Dear François-Philippe,

We'd appreciate it if you could provide any evidence of Flipper Zero being involved in any criminal activities of this kind. We're not aware of any events like this and frankly speaking not sure what was the reason for this discussion to begin with.

— Flipper Zero (@flipper_zero) February 9, 2024


A Pole meets a genie, and gets granted three wishes:

"I wish that the Mongols ransack Poland."

⁠"Weird take, but your wish is granted. Your second wish?"

"That the Mongols plunder Poland... again."

“Oof. Can't argue with your wish, though... your third wish?"

"The Mongols… pic.twitter.com/0QizE42yEe

— NonCredibleDefense Unofficial (@NonCRDDefence) February 10, 2024


Regarding the latest Ivanti Pulse Secure vulnerability disclosure - they claimed they found CVE-2024-22024 internally and it's not under active exploitation. Both are false.@watchtowrcyber reported it, and it's under active exploitation. https://t.co/nLVHeozzat pic.twitter.com/Z97lqaiag2

— Kevin Beaumont (@GossiTheDog) February 9, 2024


George Lucas was coldblooded for this one pic.twitter.com/0TFxLn54Xo

— Justin🦩Boldaji (@justinboldaji) February 11, 2024


I laughed out loud. Thanks James Dempsey. https://t.co/tsEQaiibxT

"CWE-74 ..., responsible for two of the top twelve most routinely exploited vulnerabilities in 2022, would be a definitive no-no, but I’ve heard the argument that current coding practices are unable to prevent it.…

— Joshua J. Drake (@jduck) February 11, 2024

https://s3.documentcloud.org/documents/24371794/krp-editsdempsey_sbd-paper_final_jan23.pdf


Full chain analysis for CVE-2022-4262 to commemorate my time spent on this non-trivial type confusion! Shoutout to @mistymntncop for his crafted artful exploit and discussion with me! And shoutout to @_clem1, @5aelo, @alisaesage for their prior work :). https://t.co/7SlcfN9aL9

— Jack Ren (@bjrjk) February 11, 2024


Writeup on Call of Duty: Black Ops 3 runtime code integrity protection Reverse engineering by @momo5502https://t.co/SASbsSjxX5#reverseengineering #infosec pic.twitter.com/weFpBolPb5

— 0xor0ne (@0xor0ne) February 11, 2024


Playing snake on @Ubiquiti Etherlighting switch.

Most expensive gaming console I own. Game selection is pretty limited due to the poor resolution. They went overkill on ethernet connectivity but forgot about other ports, I can't even plug in my gamepad. But it has RGB. 9/10 pic.twitter.com/P8ctnolkVY

— Adam Ježek 🦔 má konečně semafor 🚦🚦🚦 (@adamjezek98) February 10, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X