the grugq's newsletter

Archives
Subscribe
January 8, 2026

January 7-8, 2026

January 7-8, 2026

In 2021 Ukraine's IAC discovered this in a residential building. A covert listening device using COTS tradecraft. A cell phone with auto-answer in silent mode, and a simple mic, modified into a covert listening device. The ability of using COTS for espionage is a crucial skill. pic.twitter.com/rwCCMEHozy

— Spy Collection (@SpyCollection1) January 7, 2026


Ransomware attacks kept climbing in 2025

https://www.theregister.com/2026/01/08/ransomware_2025_emsisoft/


Didn’t know HR even had a policy against borrowing the engineering team’s spectrum analyzer and touching people with the antenna to see if any of them have ausistm

— annie (@soychotic) January 6, 2026


Imagine being a GRU analyst and having to try to understand U.S. military charts/slides, label them, and describe their meaning and practical importance to others.
I think I might rather be a Novichok canister transporter courier.
🤣🤣 https://t.co/16W0X2dkQ3

— Brian in Pittsburgh (@arekfurt) January 6, 2026


I am the Chief Information Officer of a global enterprise.

Last quarter, I eliminated MFA.

Multi-factor authentication. The thing where you need two things to log in instead of one.

It created friction.

Employees complained. "Why do I need a code from my phone?" "This slows… pic.twitter.com/vZFa6r63ug

— Peter Girnus 🦅 (@gothburz) January 6, 2026


Whoever's behind this phishing attack deserves an award pic.twitter.com/uHJcJAZiGs

— Eoghan McCabe (@eoghan) January 6, 2026


NEW BLOG: The Great VM Escape 💕

We caught threat actors deploying a VMware ESXi exploit toolkit in the wild - potentially was a zero-day developed over a year before VMware's disclosure 👀

If anyone has thoughts on it let me know, but I needed almost a full case of beer to…

— RussianPanda 🐼 🇺🇦 (@RussianPanda9xx) January 7, 2026


I do wonder how many CTI vendors are actually cooked when more analysts realise they can do this stuff themselves for a few quid and an LLMhttps://t.co/b3NTTRE7gx

— Will (@BushidoToken) January 7, 2026


GRAB THIS WHILE YOU CAN! lmfao Claude's FULL system prompt: https://t.co/lXDPDwSd7B

— uɐpʇou@ ✸ (@notdan) January 8, 2026


iOS Predator Implant Analysishttps://t.co/PSxVxfi24J

— Tony Gorez (@tonygo_) January 6, 2026


If I were a threat actor exfiltrating a ton of company data I’d set my user agent to “ChatGPT”

— Zack Korman (@ZackKorman) January 7, 2026


Just wanted to repost this since retro gaming devices are becoming more popular. These things are (usually) riddled with trivial vulns, but at the same time these make for a great target for new folks trying to learn more about embedded ||Android security 🖤 https://t.co/4f5Zmjj2xz

— b1ack0wl (@b1ack0wl) January 8, 2026


stay truthy. pic.twitter.com/yGFnfb33qQ

— SinSinology (@SinSinology) January 8, 2026


AI-powered automatic cyberattacks/red teaming is already possible and will only improve. It can also be embedded on robots to gain work in the physical domain or for close-access operations for offence & defence. https://t.co/8FHYCxKqBR pic.twitter.com/Wvs6dhPt2j

— Lukasz Olejnik (@lukOlejnik) January 8, 2026


Group-IB researchers have observed the growing proliferation of NFC-enabled Android tap-to-pay malware developed and sold within Chinese cybercrime communities on Telegram. https://t.co/BBZEW5QB5d @GroupIB

— 780th Military Intelligence Brigade (Cyber) (@780thC) January 7, 2026


Attack surface reduction is one of the key underlying principles of cybersecurity (heck, all security) that you must understand and apply religiously.
Doing so starting with most exposed and most critical assets/locations and extending across more and more layers of depth. https://t.co/Fp6CCeg0VO

— Brian in Pittsburgh (@arekfurt) January 7, 2026


New Stanford paper shows production LLMs can leak near exact book text, with Claude 3.7 Sonnet hitting 95.8%.

The big deal is that many companies and courts assume production LLMs are safe because they have filters, refusals, and safety layers that stop copying.

This paper… pic.twitter.com/6RrarvVYag

— Rohan Paul (@rohanpaul_ai) January 8, 2026


I use “uwu underground has to write a song about it” as the ultimate failure https://t.co/ldmXzfHeWG

— Zack Korman (@ZackKorman) January 6, 2026


Don't miss what's next. Subscribe to the grugq's newsletter:

Add a comment:

Share this email:
Share on Twitter Share on Hacker News Share via email Share on Mastodon Share on Bluesky
Twitter