the grugq's newsletter

Subscribe
Archives
February 26, 2023

February 26, 2023

-

Twitter avatar for @mountainherder
Dark Centrist Panera Mom (@scarnecchia@social.lol) @mountainherder
It's going to be grimly ironic when older Taliban in government start getting concerned about the corrosive effects of 4chan on Afghan society. Then our cultural victory will truly be complete.
Twitter avatar for @svenllama
Svenllama Parker Bowles @svenllama
"In Herat, I paid a visit to a young doctor—a well-educated non-Pashtun from a local elite family, fluent in five languages, who was well-acquainted with American culture through years spent on 4chan." https://t.co/pfVeQJnZUf
2:37 PM ∙ Feb 25, 2023
106Likes21Retweets

-

Planting Undetectable Backdoors in Machine Learning Models

https://ieeexplore.ieee.org/abstract/document/9996741

Paper here:

https://arxiv.org/abs/2204.06974

-

Twitter avatar for @adschina
Adam Segal (@adschina@mastodon.social) @adschina
A NATO Minnow Reels From Cyberattacks Linked to Iran
nyti.msA NATO Minnow Reels From Cyberattacks Linked to IranAlbania has been the target of repeated digital assaults believed to be linked to its sheltering of an Iranian dissident group on its soil.
10:00 PM ∙ Feb 25, 2023
2Likes1Retweet

-

Twitter avatar for @David3141593
David Buchanan @David3141593
python memfd_create() oneliner:
python3 -c "import os;os.fork()or(os.setsid(),print(f\"/proc/{os.getpid()}/fd/{os.memfd_create(str())}\"),os.kill(os.getpid(),19))" This prints the path of a memfd, which you can use to do whatever you want (like fileless ELF execution!)
Terminal screenshot, showing `/usr/bin/date` being cat'ed into the memfd. Then, the memfd is executed (printing the current date).

[david@david-asahi ~]$ python3 -c "import os;os.fork()or(os.setsid(),print(f\"/proc/{os.getpid()}/fd/{os.memfd_create(str())}\"),os.kill(os.getpid(),19))"
/proc/1162878/fd/3
[david@david-asahi ~]$ cat /usr/bin/date > /proc/1162878/fd/3
[david@david-asahi ~]$ /proc/1162878/fd/3
Sun 26 Feb 03:52:53 GMT 2023
[david@david-asahi ~]$
3:56 AM ∙ Feb 26, 2023
104Likes25Retweets

-

Twitter avatar for @0xdea
raptor@infosec.exchange @0xdea
This looks like an awesome addition to any #vulnerability #research toolkit 👏 Security Notes - A #VSCode extension to aid code reviews from a #security perspective // by @refactorsec github.com/RefactorSecuri…
github.comGitHub - RefactorSecurity/vscode-security-notes: Create notes during a security code review in VSCode 📝 Import your favorite SAST tool fin…Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝 - GitHub - RefactorSecurity/vscode-security-notes: Create notes durin...
8:29 AM ∙ Feb 25, 2023
65Likes17Retweets

-

Twitter avatar for @Sandbagger_01
Dr. Dan Lomas @Sandbagger_01
"001 Sadly, real spies don’t look like Sean Connery". Yeah, no shit ...
standard.co.uk007 Things I learnt from a (sort of) spyA new book by Ava Glass — not her actual name, obvs — is based on real life experiences working with MI5 and MI6. Joanna Taylor meets her
5:15 PM ∙ Feb 24, 2023
31Likes4Retweets

-

Twitter avatar for @br4s1d4s
Brasidas @br4s1d4s
This is what happens when your incentive is to write more malware so you don't get sent to the front...
arstechnica.comUkraine suffered more data-wiping malware than anywhere, everRussia has greatly accelerated cyberattacks on its neighbor in the wake of its invasion.
3:21 PM ∙ Feb 24, 2023
34Likes6Retweets

-

Twitter avatar for @HostileSpectrum
JD Work @HostileSpectrum
@GlitchyMichael @br4s1d4s Offensive remains dominant. This just means one has to re-assess who is the apex predator.
8:50 PM ∙ Feb 24, 2023
4Likes1Retweet

-

Twitter avatar for @PopularFront_
POPULAR FRONT @PopularFront_
#Myanmar: Anti-junta guerrillas in Myanmar building JStark’s FGC-9 3D-printed gun. The FGC-9 has been seen in the hands of rebels in Myanmar a number of times now, and have been used in combat against government troops.
Image
Image
3:25 AM ∙ Feb 26, 2023
265Likes51Retweets

-

Twitter avatar for @vxunderground
vx-underground @vxunderground
Minneapolis public schools says it is facing technical issues following an encryption event (meme #2)
Image
3:54 AM ∙ Feb 26, 2023
822Likes126Retweets
Twitter avatar for @BrettCallow
Brett Callow @BrettCallow
What is an “encryption event”? Via @bzosiad #ransomware sahanjournal.com/education/tech…
Image
Image
3:32 AM ∙ Feb 25, 2023
506Likes121Retweets

-

Twitter avatar for @0xor0ne
0xor0ne @0xor0ne
(1/4) Great series on Linux rootkits by @TheXcellerator Part 1: Introduction and Workflow: xcellerator.github.io/posts/linux_ro… Part 2: Ftrace and Function Hooking: xcellerator.github.io/posts/linux_ro… Part 3: A Backdoor to Root: xcellerator.github.io/posts/linux_ro… #Linux #kernel #malware #infosec #cybersecurity
Image
Image
Image
Image
7:30 PM ∙ Feb 25, 2023
430Likes153Retweets

-

Twitter avatar for @0xabad1dea
badidea 🪐 @0xabad1dea
Dutch people will seriously put up a sign advertising “hotdog fromage” as if the unforgivable international crime court isn’t just down the street
12:47 PM ∙ Feb 25, 2023
171Likes18Retweets

-

Twitter avatar for @TheChiefNerd
Chief Nerd @TheChiefNerd
If you noticed your iPhone is charging a little slower recently it may be due to a new setting Apple added in iOS 16.1 — Clean Energy Charging With it turned on, iOS will only recharge the iPhone's battery when the electrical grid uses cleaner energy sources like solar or wind… https://t.co/r35GkgivQl
Image
2:22 AM ∙ Feb 26, 2023
8,289Likes3,646Retweets

-

Australia uncovers Russian espionage ring, expels spies: Report

https://www.aljazeera.com/news/2023/2/24/australia-uncovers-russian-espionage-ring-expels-spies-report

-

Twitter avatar for @Sandbagger_01
Dr. Dan Lomas @Sandbagger_01
Chinese spy who visited key Delhi ‘installations’ held during Nepal return | Bareilly News - Times of India
m.timesofindia.comChinese spy who visited key Delhi ‘installations’ held during Nepal return | Bareilly News - Times of IndiaA court in Uttar Pradesh has extended the police custody remand (PCR) of 26-year-old Chinese national Wang Goujun, accused of spying against India, by
6:55 PM ∙ Feb 25, 2023
7Likes7Retweets

-

Twitter avatar for @0xdea
raptor@infosec.exchange @0xdea
This article by @a13xp0p0v is a great introduction to Fuchsia OS #vulnerability #research and #exploitation
A #Kernel #Hacker Meets #Fuchsia OS
a13xp0p0v.github.ioA Kernel Hacker Meets Fuchsia OSFuchsia is a general-purpose open-source operating system created by Google. It is based on the Zircon microkernel written in C++ and is currently under active development. The developers say that Fuchsia is designed with a focus on security, updatability, and performance. As a Linux kernel hacker,…
8:10 AM ∙ Feb 26, 2023
15Likes6Retweets
Don't miss what's next. Subscribe to the grugq's newsletter:
X