the grugq's newsletter

Subscribe
Archives
February 13, 2024

February 13, 2024

February 13, 2024

FuckStalkerware pt. 4 - the truth come out: does TheTruthSpy is secure

#FuckStalkerware pt. 4 - the truth come out: does TheTruthSpy is secure

they had like two years to fix this shit, jesus christ


β€” Bluesky


Matt Franz: "Good thing they lock up the APT at Walmart" - Infosec Exchange

Attached: 1 image Good thing they lock up the APT at Walmart


🚨NEW PAPER🚨

Which societal conditions breed online hostility?

We surveyed experiences of victims in 30 countries across the world (N=15,202) to show that political & economic inequality drive global differences in abuse on online platforms: https://t.co/RPoZ2eMqRt

🧡 1/12 pic.twitter.com/1COJmEXPOH

β€” Michael Bang Petersen (@M_B_Petersen) February 8, 2024

Consistent with this, we find that the primary perpetrators of online hostility across the world are status-seekers who are also hostility in offline interactions. 5/12 pic.twitter.com/9NTtjG88si

β€” Michael Bang Petersen (@M_B_Petersen) February 8, 2024


New WinDbg tutorial video: More powerful conditional breakpoints in WinDbg! Breakpoints that check values, callers, and run scripts as a condition before breaking into the debugger.https://t.co/tBgyQxGMfb

β€” Tim Misiak (@timmisiak) February 12, 2024


Excellent writeup discussing SIM card-related security aspects
Credits @senseposthttps://t.co/zBTBraoYNv#sim #infosec #cybersecurity pic.twitter.com/hiIIjpzRg3

β€” 0xor0ne (@0xor0ne) February 13, 2024


When is it generally safe to CreateRemoteThread? A short blog post with interesting observations regarding remote thread creation.https://t.co/BrkI0ebPS8

β€” Michael Maltsev (@m417z) February 12, 2024


"Tianfu Cup 2023" Chrome use-after-free vulnerability in WebAudio bug entry (CVE-2023-5996 [1497859]) is now open with a PoC:https://t.co/sJg5PyPnzk https://t.co/3lnoXumiZg

β€” Hossein Lotfi (@hosselot) February 12, 2024

"Tianfu Cup 2023" Chrome use-after-free vulnerability in WebAudio (CVE-2023-5996 [1497859]) is fixed by ignoring channel count update after the context is closed:https://t.co/9wZdcSA3FB

β€” Hossein Lotfi (@hosselot) November 13, 2023


New: the Taliban took control of the domain "https://t.co/LaL3WSEJex" (af being the TLD of Afghanistan). With the Taliban now controlling the country, it is taking back domains. This had the effect of killing the https://t.co/LaL3WSEJex Mastodon instance https://t.co/AScafokHtc pic.twitter.com/igzbydLeu8

β€” Joseph Cox (@josephfcox) February 12, 2024


The U.S. Department of State is offering a reward of up to $10,000,000 for information leading to the identification or location of any individual(s) who hold a leadership position in the Hive ransomware variant transnational organized crime group.Β  In addition, a reward offer of…

β€” Azim Khodjibaev (@AShukuhi) February 12, 2024


⚑️ this report by @e11i0t_ is worth your time!

Compromising Google Accounts: Malware Exploiting Undocumented OAuth2 Functionality for Session Hijackinghttps://t.co/heSo5KqZAY

β€” π•―π–’π–Žπ–™π–—π–ž π•Ύπ–’π–Žπ–‘π–žπ–†π–“π–Šπ–™π–˜ (@ddd1ms) February 12, 2024


a whole generation's political confusions captured in one tweet pic.twitter.com/L1J0tMUM3R

β€” Oliver Traldi (@olivertraldi) February 12, 2024

I just wanna ask the person who registered the domain what they were thinking

β€” Chris Allen ☦︎ εΈŒθ…Šε€©δΈ»ζ•™ β˜¦οΈπŸ‡»πŸ‡¦ (@bitemyapp) February 12, 2024

hi! that's me. i registered it in full knowledge that one day, we would get talibanned. that was part of the point of it

β€” edef (@edefic) February 12, 2024

my biggest fear was that we wouldn't manage to keep the project alive until that point, that there wouldn't be anything interesting to ban. some of us were leftists at the time or are today, but certainly none of us had illusions about the taliban wanting our heads cut off

β€” edef (@edefic) February 12, 2024

but for this particular project, getting them to shut us down was the intention, the apotheosis of it as a piece of performance art living on borrowed time from day 0

β€” edef (@edefic) February 12, 2024

Thread by @edefic on Thread Reader App – Thread Reader App

@edefic: @olivertraldi @bitemyapp @default_friend i can't say with certainty that nobody on the instance followed those tendencies personally i left the fediverse because it showcases some of the most depressing poli...…


https://github.com/singularseclab/Slides/blob/main/2023/find_and_exploit_race_condition_bugs_in_modern_JS_engines-zer0con2023.pdf


zdi decided not to buy it so here it is , https://t.co/gPzQGP0T70

β€” offline till OSEE certified. Hf&gl! (@f00fc7c800) February 12, 2024


https://t.co/t42uol62uN pic.twitter.com/bWxomAF77S

β€” Dr Emma Salisbury (@salisbot) February 12, 2024

We've waited 38 years for this view! With the scaffolding fully removed from the Cathedral's East End, we can now admire the original beauty of the entire exterior as it would have looked in the 14th century after the Spire was added.

πŸ“Έ: Martin Cook pic.twitter.com/S11fv2CRCg

β€” Salisbury Cathedral (@SalisburyCath) February 12, 2024


https://gur.gov.ua/en/content/u-rashystiv-masshtabnyi-zbii-prohramy-keruvannia-dronamy-detali-kiberataky-hur.html

A truly amazing cyber operation. Attacking a critical piece of military infrastructure. This is where cyber really shines.

Of course, I think there are other things that could be done from this position. Supply chain attacks seem like the best option to explore. But this is probably one of the more interesting cyber attacks of the entire war.


Being an Austro-Hungarian soldier in WWI was wild. If you were captured by the Russians you could end up in Central Asia, then Siberia, then the country falls apart, then you’re in a civil war, then have to somehow make your way home via Japan & the whole of Eurasia by sea.

β€” Luka Ivan Jukic (@lijukic) February 12, 2024

One of the bizarre results of all this was that somehow the patriotic Croatian song β€˜U boj, u boj’ was spread to Japan where they thought it was a Czech folk song or something and Japanese choirs still sing it to this day https://t.co/hE36h5WWL9

β€” Luka Ivan Jukic (@lijukic) February 12, 2024


https://lore.kernel.org/lkml/20240206182559.32264-1-ryncsn@gmail.com/
Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X