the grugq's newsletter

Subscribe
Archives
July 26, 2023

July 25, 2023

July 25, 2023

https://lock.cmpxchg8b.com/zenbleed.html

Well, I put our new research on arxiv while it's under review, thinking it wouldn't get much attention, but I guess the cat's out of the bag.

We took a look at ransomware against OT assets, which currently isn't a thing, and came up with our new technique: Dead Man's PLC. 1/2

— Ric (@RicDerby) July 24, 2023

I won't be speaking about it much until the full publication and any talks are confirmed, which maybe a while off yet, but here's the link:https://t.co/D7DHUY5t0o

2/2

— Ric (@RicDerby) July 24, 2023

One GREAT Cold War story that didn't make the cut into The Santiago Boys involves the great Argentinian writer Rodolfo Walsh. He stumbled upon mysterious gibberish telex messages while working for Prensa Latina (Fidel's answer to Reuters and AP) in Havana around 1960 ... 1/4 pic.twitter.com/2nVV26PZU4

— Evgeny Morozov (evgenymorozov.bsky.social) (@evgenymorozov) July 25, 2023

https://twitter.com/clhubes/status/1683545401238999041

I know it hurt when he had to put this listing up pic.twitter.com/sbgseIKWFe

— Bill Ari (@ImBillRay) July 24, 2023

This logo is giving extreme "Have a panic attack when you're screensharing on Zoom" energy. pic.twitter.com/rKWbC3w5ax

— follow @bencollins on bluesky (@oneunderscore__) July 24, 2023

https://twitter.com/un_a_valeable/status/1683607586170638338

https://twitter.com/dalperovitch/status/1683484585378586629

Another critical remote unauthenticated API access 0day vulnerability, known to be exploited in-the-wild and all we get is a "patch now", as if that will solve everything

0day + in-the-wild exploitation requires publication of IOCs / detections#MobileIron… pic.twitter.com/ukJ0Dia9zY

— Florian Roth ⚡️ (@cyb3rops) July 25, 2023

Norwegian National Security Authority shared details about the supply chain attack disclosed this morning: a zero day in Ivanti Endpoint Manager, used by the Government Security and Service Organization (DSS). https://t.co/TYLWVCGUOn

— Runa Sandvik (@runasand) July 25, 2023


New release of EMBA version 1.3.0 is now available. AI-Assisted firmware analysis is now integrated into the fully automated Open-Source firmware security analyzer EMBA. Check it out https://t.co/UCdKxBClWQ pic.twitter.com/9uB2oi8juF

— EMBA Firmware Analyzer (@securefirmware) July 25, 2023

you’re living in it, baby https://t.co/ARQ4eV4RS0

— your wife’s tennis coach (@youwouldntpost) July 25, 2023

I went into grad school full of grand theories of society and politics, and I'm exiting it with a belief in historical contingency above all else, which is really just a pretentious way of saying "yeah shit just kinda happens"

— William B. Fuckley (@opinonhaver) July 25, 2023

Great new #IO blog from @Mandiant exposing a pro- #China #HaiEnergy campaign leveraging a wire service to feed dozens of legit #US news outlets' sub domains with fake content. HaiEnergy also paid for protests in DC and much more... https://t.co/rKTBmNZGh7 pic.twitter.com/f2zCfjHExk

— Nathan Brubaker (@NathanBrubaker) July 24, 2023

TRM Finds Mounting Evidence of Crypto Use by ISIS and its Supporters in Asia | TRM Insights https://t.co/UvxsAJYWbB

— switched (@switch_d) July 25, 2023

Ah yes, I love my job working at the National Radio Astrology Observatory (that’s not photoshop- we got pranked by our summer students… I wonder how they got up there…) pic.twitter.com/QTQ0ykEe5G

— Rebecca Charbonneau (@rebecca_charbon) July 24, 2023

https://twitter.com/jckieferrentino/status/1683505311905116160

https://twitter.com/browtweaten/status/1683581180636012544
Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X