the grugq's newsletter

Subscribe
Archives
January 25, 2024

January 25, 2024

January 25, 2024

President Bongbong Marcos of the Philippines has been criticized for using the presidential helicopter to attend a Coldplay concert. Marcos says he has "studied music for many years" and that Coldplay was "unmissable" pic.twitter.com/l6I9M2Fpt3

— Populism Updates (@PopulismUpdates) January 23, 2024


Adventures in application compatibility: The case of the jump into the middle of an instruction from nowhere - The Old New Thing


In 2016, researchers at the University of Adelaide tested Kurt Vonnegut's theory that, "There’s no reason why the simple shapes of stories can’t be fed into computers."

They took the emotional arcs of 1300+ novels from Project Gutenberg, turned that into data, used modern tech… pic.twitter.com/TC96RGuzdn

— Nathan Baugh (@nathanbaugh27) January 24, 2024


New: read the notorious NSA Furby documents here, in which the spy agency was freaking out about the cuddly robot toys.

"Apparently, these stuffed critters learn from nearby speech patterns. That would definitely be a security concern."https://t.co/tlN22HthD9

— Joseph Cox (@josephfcox) January 23, 2024


L0pht was the first hacker space in the U.S. This is what a visitor saw 30 years ago. pic.twitter.com/QlTds6uJsC

— Chris Wysopal (@WeldPond) January 24, 2024


One of my favorite pieces of journalism and I mean ever, is when Portland city officials said it was okay to steal people’s garbage and do whatever you want with. Two journalists for Willamette Week said “Cool!” and went through the trash of the mayor, the DA, and the chief of… pic.twitter.com/7W4DSeWQCQ

— Hispanic Shaun King (@okimstillhungry) January 24, 2024

You can read the whole thing here. It rules.https://t.co/GO2goxMSCF

— Hispanic Shaun King (@okimstillhungry) January 24, 2024


https://t.co/MpvlVzx6nV pic.twitter.com/AAQpMg7yXa

— InstaCyber @instacyber@infosec.exchange (@instacyber) January 24, 2024

Announcement: Today the Bitwise Bitcoin ETF (BITB) becomes the first U.S. bitcoin ETF to publish the bitcoin addresses of its holdings.

Now anyone can verify BITB's holdings and flows directly on the blockchain.

Onchain transparency is core to Bitcoin's ethos. We're proud to… pic.twitter.com/1JTUh3zvDE

— Bitwise (@BitwiseInvest) January 24, 2024


Thanks @defcon for being you. pic.twitter.com/lrQNW4JyKW

— Minister of Ungentlemanly Warfare (@chrisrockhacker) January 23, 2024


RE the oss-sec thread on hidepid, this is why: https://t.co/8Z127FHeIt The problem is systemd and related tools alone, and that they see no problem at all with leaking commandlines of privileged users to unprivileged ones.

— Brad Spengler (@spendergrsec) January 24, 2024


So yes, we really did exploit an car IVI to run a playable doom, complete with touchscreen interaction! https://t.co/NN3pVNdcgI

— Alex Plaskett (@alexjplaskett) January 25, 2024

Confirmed! NCC Group EDG (@nccgroupinfosec, @_mccaulay, and @alexjplaskett) successfully used a 2-bug chain against the Alpine Halo9 iLX-F509. Style points for playing DOOM on the device! #Pwn2Own pic.twitter.com/WIVnJ4EVl5

— Zero Day Initiative (@thezdi) January 25, 2024


LockBit has made several statements regarding the recent attack on the https://t.co/BvmuPGEHyb, which was carried out using a leaked builder. He accused the person known as Signature of attacking the Russian company and claimed to be the owner of the Cl0p affiliate program.… pic.twitter.com/lxds26VkDo

— 3xp0rt (@3xp0rtblog) January 25, 2024


I'm increasingly of the view "once your market cap includes 3 commas, you're not allowed to acquire companies anymore."

— Corey Quinn (@QuinnyPig) January 24, 2024

But ... Think about how disruptive all that innovation would be to world stability.

— Halvar Flake (@halvarflake) January 25, 2024


"Nailed it!", says Intel officer who assessed Middle East violence as "possible". https://t.co/YQBtOQV0kO

— Duffel Blog (@DuffelBlog) January 24, 2024


People who clap when the plane lands, I owe you an apology... https://t.co/wO1al44NQR

— Tristan (@AyoTristan) January 24, 2024

Alaska Airlines says "many" of its Boeing 737 Max 9 planes were found to have loose bolts - NBC

— BNO News (@BNONews) January 23, 2024


OMG this is brilliant. This woman put her tech skills to use to troll VA Gov. Glenn Youngkin over a tipline he put up to report CRT. Her talk will give you life. pic.twitter.com/OBmIusKP9t

— Victoria Brownworth (@VABVOX) January 24, 2024


Exploit for CVE-2022-4262. Fukin finally! Shoutout to @_clem1 for finding the ITW exploit. And shoutout to @5aelo, @bjrjk, @alisaesage for their RCA's and prior analysis of the vuln :). https://t.co/JTRYBSgWw4

— j j (@mistymntncop) January 24, 2024

Advisoryhttps://t.co/egzCuyhMSz

— j j (@mistymntncop) January 24, 2024


Is it bogus if it allows you to bypass Secure Boot ? 🤭 pic.twitter.com/0Xug57Mc5D

— Raelize (@raelizecom) January 23, 2024


I am releasing my kernel fuzzer "SimpleNTSyscallFuzzer" for public use. With the help of this generic fuzzer, i managed to have more than 15 CVEs. Enjoy!https://t.co/EMRdWv1tk9

— Walied Assar (@waleedassar) January 25, 2024


2) Interesting talk from Cansecwest 2024 https://t.co/LIggcSgLfC

— Kevin2600 (@Kevin2600) January 24, 2024

1) Interesting talk from Cansecwest 2024 https://t.co/DSLsgIVEx1

— Kevin2600 (@Kevin2600) January 24, 2024


found a critical bug that exists in every Linux boot loader signed in the past decade 🥰 https://t.co/kjATsR4uvJ https://t.co/JrECpgGmWD pic.twitter.com/oKEl7PTUSp

— Bill Demirkapi (@BillDemirkapi) January 24, 2024

Found my first UEFI vulnerability (signed bootloader OOB-W) 😊 pic.twitter.com/Vd2DFo71wQ

— Bill Demirkapi (@BillDemirkapi) May 6, 2023


In this post I'll use CVE-2023-3420, an incorrect side effect modelling bug in the JIT compiler that I reported to Chrome, to gain a sandboxed remote code execution in the renderer: https://t.co/mFdIXuM7xY

— Man Yue Mo (@mmolgtm) September 26, 2023


Our friend @pancak3lullz has created a Twitter bot which monitors the SEC's RSS feed for 8-K and 6-K filings with cybersecurity incident materials (item 1.05).

tl;dr reported breaches

It's really cool.

Follow it here: @SECurityTr8Ker

— vx-underground (@vxunderground) January 25, 2024


Constantly updated collection of guides/resources/tutorials about (linux server) securityhttps://t.co/Ni8FXQXgDN#Linux #cybersecurity pic.twitter.com/KrQznj1lDh

— 0xor0ne (@0xor0ne) January 24, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X