the grugq's newsletter

Subscribe
Archives
February 9, 2025

February 9, 2025

February 9, 2025

Interesting report from ReversingLabs researchers, who named a new attack nullifAI, a novel malware distribution technique targeting ML models on Hugging Face.

๐Ÿ˜ˆAttackers exploited Pickle serialization to deliver payloads undetected.https://t.co/wwGP91Bpcg

โ€” Thomas Roccia ๐Ÿค˜ (@fr0gger_) February 8, 2025


still can't believe .zip domains exist pic.twitter.com/InbzccNIsy

โ€” Aiden Bai (@aidenybai) February 8, 2025


that one time China had a single factory for producing Type-69-II tanks with one row being for Iraq and the other for Iran pic.twitter.com/VnjQuqLmJJ

โ€” TMG โ–ณ (@PunishedTMG_) February 7, 2025


#SpyNews - week 6 (February 2-8):
A summary of 75 espionage-related stories from week 6 coming from ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡ต๐Ÿ‡ญ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡ซ๐Ÿ‡ท๐Ÿ‡ฎ๐Ÿ‡ท๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡ณ๐Ÿ‡ฑ๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ธ๐Ÿ‡ธ๐Ÿ‡ง๐Ÿ‡ช๐Ÿ‡ธ๐Ÿ‡ด๐Ÿ‡ธ๐Ÿ‡ช๐Ÿ‡ต๐Ÿ‡ธ๐Ÿ‡ฐ๐Ÿ‡ฟ๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡ฑ๐Ÿ‡ง๐Ÿ‡ฑ๐Ÿ‡ป๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡ฐ๐Ÿ‡ต๐Ÿ‡ฆ๐Ÿ‡ฟ๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ฌ๐Ÿ‡ท๐Ÿ‡ฑ๐Ÿ‡น๐Ÿ‡ฆ๐Ÿ‡น๐Ÿ‡จ๐Ÿ‡พ๐Ÿ‡จ๐Ÿ‡ฟ๐Ÿ‡ฉ๐Ÿ‡ฐ๐Ÿ‡ต๐Ÿ‡น๐Ÿ‡ช๐Ÿ‡ธ๐Ÿ‡ฒ๐Ÿ‡ฆ๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡ธ๐Ÿ‡พ๐Ÿ‡ฎ๐Ÿ‡ถ๐Ÿ‡ป๐Ÿ‡ฆ๐Ÿ‡ญ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡ธ๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡ฆ๐Ÿ‡ซ๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡ง๐Ÿ‡ฆ๐Ÿ‡ซ๐Ÿ‡ฎ https://t.co/rGUFeULzbb#OSINT #spy #espionage #SIGINT #HUMINT

โ€” Spy Collection (@SpyCollection1) February 9, 2025


A group of 200 former national security officials urged congressional leaders to investigate the motive behind the Central Intelligence Agencyโ€™s buyout offers to staff https://t.co/tcQjz7Kwtw via @bpolitics

โ€” Dr. Dan Lomas (@Sandbagger_01) February 8, 2025


1/ QUICK THREAD - an account of the Ukrainian UGV-UAV combined assault on Russian positions in December 2024: "The mission itself involved complex logistics and communications requirements. No drone swarm technology was used..." https://t.co/50xeJkK0yI

โ€” Samuel Bendett (@sambendett) February 8, 2025


How many advisories did we publish in 2024? What was the top CWE? How many were 0-day? How much money did Pwn2Own award? You can find this - and more - in our 2024 retrospective. https://t.co/jJY8ojNBxL

โ€” Trend Zero Day Initiative (@thezdi) February 7, 2025


New release: #IDA_IFL (Interactive Functions List) plugin v1.5 - works for IDA 9. Shout-out to my new contributor,@mahmoudimus who added the support! https://t.co/vLrF2wwKdJ pic.twitter.com/dNpx0ATsHj

โ€” hasherezade (@hasherezade) February 8, 2025


lol a literal multi-billion dollar money laundering operation paid @CertiK to stamp of approval their new money laundering contract ๐Ÿซ https://t.co/jNYFLOKCn2

โ€” Tay ๐Ÿ’– (@tayvano_) February 7, 2025

hidden 60% thru the raw pdf is this lil note.

yet they still took their money and stamped them.

lmfaoooooooooooooo pic.twitter.com/8vfKzYozrI

โ€” Tay ๐Ÿ’– (@tayvano_) February 7, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:
X