the grugq's newsletter

Archives
Subscribe
July 23, 2025

July 23, 2025

July 23, 2025

https://www.theregister.com/2025/07/21/replit_saastr_vibe_coding_incident/?td=rt-3a


MSTIC blog on Sharepoint exploitation

At least 3 actors exploiting CVE-2025-49706 & CVE-2025-49704 as early as July 7:
Linen Typhoon
Violet Typhoon
Storm-2603 (CN-based actor deployed Warlock & Lockbit ransomware in past - current motivation unknown)https://t.co/IgEp6yxx3B

— Christopher Glyer (@cglyer) July 22, 2025


"Branchless Programming" is a term used to describe a programming style that improves performance by avoiding branches (e.g. if statements and similar). One of the most common branchless tricks is to use multiplication in place of an if statement: pic.twitter.com/nVi3acoZXN

— Nic Barker (@nicbarkeragain) July 22, 2025


US Army learning how to drop grenades from drones https://t.co/XY2cQ5mFgM pic.twitter.com/x8LE9Qd4Uw

— OSINT Gorilla (@GorillaOSINT) July 21, 2025


Hackers reportedly breached the National Nuclear Security Administration and other parts of the Department of Energy through the Microsoft SharePoint vulnerability. https://t.co/ocYSWgg4MW pic.twitter.com/jdsuDZb8Md

— Eric Geller (@ericgeller) July 23, 2025


Update: the Mattress salesman is great at finding bugs. https://t.co/xT9a8iMjTM pic.twitter.com/tzYRj5EXqT

— AIfredo 0rtega (@ortegaalfredo) July 22, 2025


From a very detailed exploration of securing protection relays in a modern digital substation: https://t.co/Mb41x7eGsO pic.twitter.com/V8VLC8wNgc

— Ravi Nayyar (@ravirockks) July 23, 2025


WhoFi

https://www.theregister.com/2025/07/22/whofi_wifi_identifier/?td=rt-3a

Paper

[2507.12869v1] WhoFi: Deep Person Re-Identification via Wi-Fi Channel Signal Encoding

Person Re-Identification is a key and challenging task in video surveillance. While traditional methods rely on visual data, issues like poor lighting, occlusion, and suboptimal angles often hinder performance. To address these challenges, we introduce WhoFi, a novel pipeline that utilizes Wi-Fi signals for person re-identification. Biometric features are extracted from Channel State Information (CSI) and processed through a modular Deep Neural Network (DNN) featuring a Transformer-based encoder...


For years, Sacramento has been running an illegal scheme using power meters for mass surveillance. Last week, we asked for a court order to stop this practice for good. https://t.co/ls2RwHvG6G

— EFF (@EFF) July 22, 2025


Per French authorities — the suspected administrator of XSS has been arrested in Ukraine https://t.co/ZAqIyvWeWX

— vx-underground (@vxunderground) July 23, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:

Add a comment:

Share this email:
Share on Twitter Share on Hacker News Share via email Share on Mastodon Share on Bluesky
Twitter