the grugq's newsletter

Subscribe
Archives
January 6, 2025

January 6, 2025

January 6, 2025

https://archive.ph/2025.01.05-232824/https://www.wsj.com/tech/cybersecurity/typhoon-china-hackers-military-weapons-97d4ef95?st=4zK2ke


Ollie Whitehouse: "Weekly summary is out .. https://ctoatncsc.subst…" - Infosec Exchange

Weekly summary is out .. https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-january-df5?r=q9u24&utm_campaign=post&utm_medium=web&triedRedirect=true


Kevin Beaumont: "lol, OpenAI’s $200 a month personal subscription …" - Cyberplace

lol, OpenAI’s $200 a month personal subscription is still not making a profit. Sam Altman says he pulled the price out of his ass one day and now they’re losing money on that, too. https://techcrunch.com/2025/01/05/openai-is-losing-money-on-its-pricey-chatgpt-pro-plan-ceo-sam-altman-says/


Deterrence by whitepapers about zero trust best practices https://t.co/0KS52R7fek

— Alexei Bulazel (@0xAlexei) January 6, 2025

Made more bitterly ironic by the fact that said white papers advocating primacy of defensive best practice were largely recycled from vendor lobbyist talking points, who were themselves unable to defend against ongoing intrusion sets pivoting across their infrastructure to .gov &…

— JD Work (@HostileSpectrum) January 6, 2025

The national policy alternative to deterrence by denial through vulnerability reduction (placing DCO and DFIR as primary if not in practice only response COA), is a mix of counter-cyber operations to erode adversary capabilities through persistent engagement (with other…

— JD Work (@HostileSpectrum) January 6, 2025


My close personal friend Marc Rogers had a serious accident and could use help now.

One of the finest hackers & humans to ever hack the planet needs our help. @marcwrogers is lucky to be alive & we are luckier to be able to help him.

Donate if you can and please *share* to spread the word.https://t.co/VWx0ZrLy2I pic.twitter.com/qN2f6LJLAA

— Katie🌻Moussouris (she/her/she-ra/she-hulk) 🪷 (@k8em0) January 6, 2025


Deterrence by denial simply does not work.

Ukraine had 8 years of “cold cyber war” and 3 years of “hot cyber war” and the most common CVEs exploited by threat actors in 2023 were from ~2018.

Not even existential threat can make cyber security best practices work. https://t.co/vBospP6M44

— thaddeus e. grugq (@thegrugq) January 6, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:
X