the grugq's newsletter

Subscribe
Archives
January 18, 2024

January 18, 2024

January 18, 2024

https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html


1/ A technical writeup on @Meta’s @WhatsApp privacy issue:
WA leaks victim devices’ end-to-end encryption (E2EE) identity information (mobile device + up to 4 linked devices) to any user, by design, even if blocked and not in contacts.https://t.co/ONmcdC3ZqC

— Tal Be'ery (@TalBeerySec) January 17, 2024

2/ for example it can be applied on Hamas leaders (which obviously I did not have previous communication with)https://t.co/9pFMHE9KJ9

— Tal Be'ery (@TalBeerySec) January 17, 2024

Did you know Ghazi Hamad, a senior Hamas leader, has WhatsApp installed on a mobile device, but also on 3 other linked devices (WhatsApp web & desktop)?
Mahmoud Zahar has WhatsApp installed only on his mobile device.#WhatsAppDeviceLeak pic.twitter.com/fdzphetAQk

— Tal Be'ery (@TalBeerySec) January 17, 2024

Thread by @TalBeerySec on Thread Reader App – Thread Reader App

@TalBeerySec: 1/ A technical writeup on @Meta’s @WhatsApp privacy issue: WA leaks victim devices’ end-to-end encryption (E2EE) identity information (mobile device + up to 4 linked devices) to any user, by design, ev...…


Hacking into a Toyota/Eicher Motors insurance company by exploiting their premium calculator website

A vulnerable API on Toyota Tsusho Insurance Broker India’s premium calculator website exposed Microsoft corporate cloud credentials.


Nice series here >> "The toddler’s introduction to Heap exploitation (Part 1)" https://t.co/xivRCYFxu3

— reverseame (@reverseame) January 17, 2024


🔥 NEW podcast alert: Costin Raiu digs into why he left the GReAT team after 13 years at the helm, ethical questions on exposing certain APT operations, changes in the nation-state malware attribution game, the most technically impressive attacks, the 'dark spots' where…

— Ryan Naraine (@ryanaraine) January 15, 2024


New video in our archived content/footage playlist. It's from the detainment of a Ukrainian serviceman by the #SBU in Apr. 2023. He was recruited as an agent of Russian intel, using the cryptonym Кримчанин (Crimean).https://t.co/d7TS9mBDKM#Espionage #Russia #Ukraine #CI

— Spy Collection (@SpyCollection1) January 18, 2024


ME: I would like to buy a bond

STOCKBROKER: ok! which bond are you interested in?

ME: one with my dad

— Rads (@_radsy) March 27, 2018



Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X