the grugq's newsletter

Subscribe
Archives
February 29, 2024

February 29, 2024

February 29, 2024

Administrivia: lots of words due to the editor on Friday. Reduced newsletter until then. Thank you for your understanding.

I recently found two very interesting Linux binaries uploaded to Virustotal.

I call this malware 'GTPDOOR'.

GTPDOOR is a 'magic/wakeup' packet backdoor that uses a novel C2 transport protocol: GTP (GPRS Tunnelling Protocol), silently listening on the GRX network (1/n) đź§µ pic.twitter.com/IwuEcL14lx

— HaxRob (@haxrob) February 28, 2024

https://doubleagent.net/telecommunications/backdoor/gtp/2024/02/27/GTPDOOR-COVERT-TELCO-BACKDOOR.html

Thread by @haxrob on Thread Reader App – Thread Reader App

@haxrob: I recently found two very interesting Linux binaries uploaded to Virustotal. I call this malware 'GTPDOOR'. GTPDOOR is a 'magic/wakeup' packet backdoor that uses a novel C2 transport protocol: GTP (GPRS Tunn...…


On a long enough time-line, technique will "solve" almost any game into a boring non-event.

Remember being a kid and realizing that tic tac toe wasn't really a game? This problem of optimizing the fun out of things scales in terrifying ways. pic.twitter.com/jBsi6rNWUI

— Zarathustra (@zarathustra5150) February 27, 2024


This is my biggest achievement all day so far: https://t.co/MHZseD6uk0

— Julien Vanegue (jvanegue@mathstodon.xyz) (@jvanegue) February 28, 2024


AIBOMs are coming! Like an SBOM, they list everything needed to build, train, validate, and configure an AI model. But, how do you capture tricky inputs like data ordering, labeling process, and data transformation procedures?https://t.co/l0xDTtA2ty

— Dan Guido (@dguido) February 28, 2024

We responded to an RFI by the US Army’s PEO IEW&S on methods for implementing and automating AIBOM tools. Check out a summary of our response: https://t.co/47oBUgZIjh pic.twitter.com/xSNNrE2DPO

— Trail of Bits (@trailofbits) February 28, 2024


Based on the amount of pottery fragments alone, the Roman Empire may be the clumsiest empire history has ever known.

— Ryan 🥣 (@ryanposting) February 28, 2024


DOOM on a Toothbrush? Sure! pic.twitter.com/Z1qOV7g6zk

— atc1441 (@atc1441) February 28, 2024


The Linux CNA – Red Flags Since 2022 – Rants of a deranged squirrel.

[2/28/2024 Update: A bit more info added at end regarding “almost any bug might exploitable”.] MITRE announced that The Linux Kernel Organization (Kernel.org, hereafter referred to as &…


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X