the grugq's newsletter

Subscribe
Archives
January 12, 2025

January 12, 2025

January 12, 2025

Ships Must Practice Celestial Navigation

An interesting point here, actually.

The Navy conducts live-fire weapons drills, damage control drills with real smoke and fire, and exercises hunting real submarines, but it does not regularly practice for emergency, long-term, open-ocean navigation without GPS. With many vulnerabilities, GPS will likely be the first system an adversary attempts to disrupt during a war.

https://www.usni.org/magazines/proceedings/2025/january/ships-must-practice-celestial-navigation


99% of YouTube videos lately are clickbait and stretch out ~1 paragraph of Wikipedia into 30+ minutes of content. Many videos are just questions with simple answers.

So I built https://t.co/q2SexFNiRi: put in the URL and save your time! pic.twitter.com/qYadYi0DiE

— cts🌸🏳️‍⚧️ (@gf_256) January 11, 2025

tldw.tube


Pentesting realities https://t.co/SsUGjhwhXu

— mRr3b00t (@UK_Daniel_Card) January 11, 2025


Secret Phone Surveillance Tech Was Likely Deployed at 2024 DNC | WIRED

Data WIRED collected during the 2024 Democratic National Convention strongly suggests the use of a cell-site simulator, a controversial spy device that intercepts sensitive data from every phone in its range.


Bad Apple but it's 6,500 regular expressions that I search for in Vim one at a time with a macro

i built most of a general purpose video-in-vim-using-regex-search tool for this lol

(details below!) pic.twitter.com/6ew4NsrrPq

— nolen (@itseieio) January 10, 2025


I continue to think this is one of the most important cartoons of recent years. @marketoonist pic.twitter.com/HSILx7tcr0

— nxthompson (@nxthompson) January 10, 2025


Made a simple dashboard to help track/search CVEs and security vulnerabilities in near real-time. No fancy stuff - just a clean interface to see what's burning in the security world right now. (it's Ivanti🙈) https://t.co/uQ88UEWo0L) https://t.co/6e32nsFY68

Feedback welcome! pic.twitter.com/PvVxFG4Wpd

— Patrik Fehrenbach (@ITSecurityguard) January 10, 2025


🇹🇼 prosecutors have indicted seven retired military officers — members of the Fukang Alliance Party (or Rehabilitation Alliance Party; 復康聯盟黨) including founder / chairman Chu Hung-yi (屈宏義) — for allegedly obtaining funds from 🇨🇳 PLA and forming paramilitary groups and… pic.twitter.com/UpxIjf6WJe

— Byron Wan (@Byron_Wan) January 9, 2025


“C is NOT a low-level language”

A short read on how C’s simplified model of memory & execution hides modern hardware details (caches, pipelines etc) leading to performance pitfalls + vulnerabilities like Spectre & Meltdown.

A refreshing take on what “low-level” actually means. pic.twitter.com/Z66oj2pLFb

— katzz (@0xkatzz) January 11, 2025


Bug Bounty became such a scam recently. Reported a critical issue to Wells Fargo, H1 triaged it as 9.3. Found an actuator (env only), Akamai blocked heapdump, bypassed it by fuzzing finding the correct origin ip... PM makred as "informative".

— Damian Strobel (@damian_89_) January 10, 2025

GitHub - pdelteil/scammy-bbp: Self-hosted bug bounty programs that are "scammy" or unethical

Self-hosted bug bounty programs that are "scammy" or unethical - pdelteil/scammy-bbp


Don't miss what's next. Subscribe to the grugq's newsletter:
X