the grugq's newsletter

Subscribe
Archives
July 23, 2022

July 23, 2022

Twitter avatar for @arekfurt
Brian in Pittsburgh @arekfurt
I'm not sure people understand the reason having a functional, capable, independent, dedicated cybersecurity incident investigation body could be of great benefit. To put it one way... The neverending stream of cybersecurity breaches is, in a sense, caused by lies.
10:46 PM ∙ Jul 22, 2022
86Likes22Retweets

-

The Info Op is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

https://www.cyberscoop.com/ukraine-cyber-officials-prepare-for-attacks/

-

Twitter avatar for @3sunzzz
🎭ᑌᖇᔕᑌᒪᗩ🎭 @3sunzzz
My husband pissed me off so when he wasn't looking I poured water on the floor in front of the dishwasher. He's been fixing it for the past 2 hours.
1:09 PM ∙ Oct 12, 2019
24,433Likes3,924Retweets

-

Twitter avatar for @runasand
Runa Sandvik @runasand
The #PanamaPapers whistleblower said they reached out to @nytimes and @WSJ, but the journalists there “were uninterested.”
occrp.orgPanama Papers Whistleblower Speaks Out: “Shell Companies are Putin’s Best Friend” - The Panama PapersThe anonymous whistleblower behind the bombshell leak known as the Panama Papers has emerged anew to warn how offshore companies are enabling Russia’s war machine.
11:08 PM ∙ Jul 22, 2022
87Likes45Retweets

-

Twitter avatar for @TeneyiaRenee
T€n€yia R€n€€ @TeneyiaRenee
😂😂
Image
9:27 PM ∙ Jul 21, 2022
5,114Likes770Retweets

-

Twitter avatar for @MrTuxracer
Julien Ahrens 🇪🇺 @MrTuxracer
As promised: Here's my story about 8 CVEs resulting in a plugin removal and more than $30,000 in bounties! I've chained 3 of them to go from unauthenticated to admin, aka how to exploit a blind SQL Injection via XSS. rcesecurity.com/2022/07/WordPr… #BugBounty #security
rcesecurity.comWordPress Transposh: Exploiting a Blind SQL Injection via XSSIntroductionYou probably have read about my recent swamp of CVEs affecting a WordPress plugin called Transposh Translation Filter, which resulted in more than $30,000 in bounties and WordPress’s removal of the plugin from its directory:
2:33 PM ∙ Jul 22, 2022
570Likes185Retweets

-

Twitter avatar for @lkrg_org
LKRG @lkrg_org
Linux Kernel Runtime Guard (LKRG) 0.9.4 by @Adam_pi3 et al. is out, featuring more consistent log messages suitable for both automated analysis and human consumption, as well as adding support for more longterm Linux kernels and for the OpenRC init system.
openwall.comannounce - [openwall-announce] LKRG 0.9.4
7:39 PM ∙ Jul 22, 2022
34Likes11Retweets

-

Twitter avatar for @3arrowscap
Three Arrows Capital @3arrowscap
Image
7:49 AM ∙ Jul 22, 2022
17,638Likes1,737Retweets

-

Twitter avatar for @billmarczak
Bill Marczak @billmarczak
Spyware vendor Candiru is back! @Avast detected a Candiru client hacking targets' computers in Lebanon, Turkey, Yemen, and Palestine via a Chrome 0day on compromised websites
decoded.avast.ioThe Return of Candiru: Zero-days in the Middle East - Avast Threat LabsWe recently discovered a zero-day vulnerability in Google Chrome (CVE-2022-2294) when it was exploited in the wild in an attempt to attack Avast users in the Middle East. The vulnerability was a memory corruption in WebRTC that was abused to achieve shellcode execution in Chrome’s renderer process.…
2:45 PM ∙ Jul 21, 2022
48Likes32Retweets

-

Twitter avatar for @DFRLab
DFRLab @DFRLab
Russia is spinning new and recycled narratives to claim that Ukraine is re-selling French weapon systems on the black market and they are ending up in Russian hands. @DFRLab retraces steps from the Kremlin playbook on how to amplify a false claim🔍medium.com/dfrlab/how-rus…
medium.comHow Russia promoted the claim that Ukraine re-sold French howitzers for profitKremlin media amplified narrative until mainstream coverage on the risk of weapons smuggling allegedly gave it credence
7:56 PM ∙ Jul 21, 2022
213Likes105Retweets

-

Twitter avatar for @FatherWithTwins
Robert Knop @FatherWithTwins
8yo: The internet is down. I’m going to go play at my friend’s house Me: Ok, have fun! 8yo: *Leaves* Me: *Turns router back on*
11:36 PM ∙ Jul 24, 2018
3,301Likes575Retweets

-

Twitter avatar for @Marlebean
Marl @Marlebean
Me: "One time I farted so long, I was surprised that my butt didn't have to stop and catch its breath." Interviewer: " ... and a weakness?"
2:42 PM ∙ Apr 30, 2018
2,487Likes1,060Retweets

-

Twitter avatar for @TerribleMaps
Terrible Maps @TerribleMaps
Image
10:21 PM ∙ Jul 22, 2022
17,609Likes1,708Retweets

-

-

Twitter avatar for @icing
Stefan 🏒 Eissing @icing
The talk by @bert_hu_bert from yesterday evening:
media.ccc.deHacking the genome: how does it work, and should we?Building on the very well attended DNA presentations (“DNA: The Code Of Life”) at SHA2017, this talk will cover: * A brief recap what D...
7:59 AM ∙ Jul 23, 2022
13Likes5Retweets

-

Twitter avatar for @TheWillOShow
WILL 🅾️ @TheWillOShow
"so you must agree, that the only crime committed here was that of love", I say to the jury, "Because my client absolutely loves to steal car stereos"
5:39 PM ∙ Jul 12, 2020
63Likes30Retweets

-

Twitter avatar for @LockWilford
Lock Wilford @LockWilford
*planting a gallon of milk* I am a cow farmer.
3:15 AM ∙ Jul 13, 2020
92Likes36Retweets

The Info Op is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X