the grugq's newsletter

Archives
Subscribe
January 6, 2026

January 6, 2026

January 6, 2026

Sharing my Burp Extension that earned me $200k in 2025 while API testing heavy JS-rich targets.https://t.co/eMXZ2G4cAk

The tool helps find endpoints, files, internal emails, and some secrets from minified JS.

Its goal is to achieve maximum efficiency with reduced noise in… pic.twitter.com/KfyKl5t6PZ

— Jenish Sojitra (@_jensec) January 5, 2026


Most effective disinformation techniques do not leave fingerprints. Oh and by the way, contrary to popular belief, message personalization (and microtargeting) gives only a small, though repeatable, gain in perceived persuasiveness (an influence effect). However, AI and LLMs… https://t.co/jNhVcra6qx pic.twitter.com/j3iRqrGTCj

— Lukasz Olejnik (@lukOlejnik) January 5, 2026


My new site for learning macOS malware reverse engineering:https://t.co/kzeSDjFqWp

I got my start in RE by using @patrickwardle's awesome blog. I would download samples and follow along. So I created this to complement that with dives into specific code from recent samples.

— L0Psec (@L0Psec) January 5, 2026


By far the most comprehensive guide for virtual machines, literallyy.
-great for understanding low level concepts
-it's kind of very detailed guide
the whole thing is soo structured and anyone can understand vm. pic.twitter.com/YgiatL87ey

— Abhishek🌱 (@Abhishekcur) January 4, 2026


Build a Fake Phone, Find Real Bugs: Qualcomm GPU Emulation and Fuzzing with LibAFL QEMU https://t.co/bNDaNLG8Ut #39c3

— Hardened-GNU/Linux (@hardenedlinux) January 5, 2026


The BYTE Vol. 14, Iss. 1 "Cyber as Maneuver"https://t.co/0gnbjKJXZD
The theme and articles inside this edition of The BYTE are directly in line with the Army priority to “train as we fight” and the Army focus areas: warfighting; delivering ready combat formations; strengthening… pic.twitter.com/BBCNlLY1hc

— 780th Military Intelligence Brigade (Cyber) (@780thC) January 5, 2026


Right before the holidays, I broke the news that DHS had effectively forced out the staffer running CISA's ransomware warning program: https://t.co/R6Zea89dvl

People who worked w/ him are really worried. And we may be starting to see the impact... https://t.co/nVVaiuDkQ4 pic.twitter.com/UNKFaDncZ5

— Eric Geller (@ericgeller) January 5, 2026


Wait that post is not satire https://t.co/j5kJIEvEEQ pic.twitter.com/Lo8577uOv1

— Deva Hazarika (@devahaz) January 5, 2026


Most “cyberattacks” are not “attacks” in the legal sense, though “cyberwarfare below the threshold of war” is fine as a publicist label. pic.twitter.com/lRls1BQz7u

— Lukasz Olejnik (@lukOlejnik) January 5, 2026


You can now give infinite memory to Claude Code.

Claude-Mem just released a free open source memory plugin by thedotmack.

It saves context so Claude resumes work without reexplaining everything.

𝗣𝗲𝗿𝘀𝗶𝘀𝘁𝗲𝗻𝘁 𝗺𝗲𝗺𝗼𝗿𝘆 𝗳𝗼𝗿 𝗖𝗹𝗮𝘂𝗱𝗲 𝗖𝗼𝗱𝗲
Claude-Mem records… pic.twitter.com/SQ5CX3fSec

— Lior Alexander (@LiorOnAI) January 5, 2026


🚨NEW: Microsoft is renaming all their products

GitHub —> CopilotHub
LinkedIn —> Copilot Unemployed
Xbox —> XCopilot
Teams —> CopilotSkype
Azure —> CopilotCloud
OneDrive —> CopilotDeleteurfiles
Edge —> CopilotExplorer
VSCode —> CopilotCursor
Bing —> Copilot4cucks
Defender…

— solst/ICE of Astarte (@IceSolst) January 5, 2026


Apropos of nothing in particular pic.twitter.com/ZvJCuBhtc4

— Joe Słowik 🌻 (@jfslowik) January 4, 2026


Holiday Project 👨🏻‍💻🎄
Interested in macOS malware? Have a read! https://t.co/jOlE98Vs57

— Patrick Wardle (@patrickwardle) January 5, 2026


An investigative journalist infiltrated a white supremacist dating site & made them fall in love with an AI.

She created a website with over 8k profiles and placed them on a map, exposing users from very different regions of the world.

You can click your city to see them 🧵 pic.twitter.com/eQf4HsNts9

— Mukhtar (@I_amMukhtar) January 5, 2026

https://okstupid.lol/


Knownsec Data Breach: A Trove of Espionage Tradecraft with an Insider Narrative | The Knownsec leak is a pivotal incident of 2025 because it exposed the inner workings of a major state-linked Chinese cybersecurity firm@RESecurity https://t.co/FLOPgyl3ZD

— 780th Military Intelligence Brigade (Cyber) (@780thC) January 5, 2026


This might be one of my favorite articles I've ever read in one of these magazines: rube gets hired by an MKULTRA affiliated front by accident, becomes a hippie, annoys the fuck out of the CIA with sensitivity training programs until they give him $15,000 to fuck off https://t.co/hvr3KAv0rY pic.twitter.com/CKknQsXZxz

— Robert Skvarla (@RobertSkvarla) January 6, 2026


Wanted to silence some Bluetooth speakers?
I did - and had spare Raspberry Pi Picos in my inventory, so…
> https://t.co/bFmHMouxX8 pic.twitter.com/L9MbKUposD

— 🥝🏳️‍🌈 Benjamin Delpy (@gentilkiwi) January 5, 2026


We've reinstated the gay bar report.

The site now tracks Freddie's Beach Bar (1.4 mi from Pentagon) and The Little Gay Pub (1.1 mi from The White House).

This signal works inverse from the pizza signal. If these bars have unusually low activity, especially on weekend nights,… pic.twitter.com/5UMC8DXKZz

— Pentagon Pizza Watch (@pizzintwatch) January 5, 2026
Don't miss what's next. Subscribe to the grugq's newsletter:

Add a comment:

Share this email:
Share on Twitter Share on Hacker News Share via email Share on Mastodon Share on Bluesky
Twitter