the grugq's newsletter

Subscribe
Archives
July 26, 2022

July 26, 2022

Notes from Dave Aitel correcting a poor analysis on Ukraine cyber conflict.


Goodbye Cyberwar - Google Docs


The Info Op is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

-

Twitter avatar for @christogrozev
Christo Grozev @christogrozev
Today FSB announced that they have “foiled a plot by Ukraine’s intelligence services” to lure Russian military pilots to surrender to Ukraine – with their planes – in return for millions of USD in payments (thread).
11:51 AM ∙ Jul 25, 2022
11,743Likes2,623Retweets

-

Twitter avatar for @Aimtech9
Vasken @Aimtech9
When the employer asks for 10+ years of experience and you're 20 😁
Image
7:02 AM ∙ Jul 25, 2022
124Likes39Retweets

-

Twitter avatar for @ARozenshtein
Alan Rozenshtein @ARozenshtein
Terrific analysis of the special cybersecurity issues around open-source software, from @ChinmayiSharma in @lawfareblog.
lawfareblog.comOpen-Source Security: How Digital Infrastructure Is Built on a House of CardsLog4Shell remains a national concern because the open-source community cannot continue to shoulder the responsibility of securing this critical asset and vendors are not exercising due care in incorporating open-source components into their products. A comprehensive institutional response to the inc…
2:01 PM ∙ Jul 25, 2022
12Likes9Retweets

-

Twitter avatar for @archeohistories
Archaeo - Histories @archeohistories
The three headed Lernaean Hydra wall painting from an Etruscan tomb at the necropolis of Pianacce, dated to the 4th century BC.
Image
4:05 PM ∙ Feb 21, 2021
29Likes14Retweets

-

What a story!

Twitter avatar for @michaeldweiss
Michael Weiss 🌻🇺🇸🇮🇪 @michaeldweiss
NEW: Remember Jan Marsalek, the fugitive Wirecard COO and suspected GRU agent, who fled to Russia from Munich? The exclusive story of how he did it -- with the help of one of Austria's top former intelligence officers.
dossier.centerFrom Munich to MoscowThe inside story of how fugitive Wirecard COO Jan Marsalek fled from a 2 billion euro corruption saga in Germany and wound up living under state protection in Russia
1:55 PM ∙ Jul 25, 2022
400Likes159Retweets

-

Twitter avatar for @swagitda_
Kelly Shortridge @swagitda_
At @SummerC0n 2022, @rpetrich and I presented “Lamboozling Attackers” on how you can leverage deception environments to exploit attacker brains (i.e. their learning & decision-making). Slides are now online here and they are An Experience: swagitda.com/speaking/Lambo…
A screenshot of our slide deck. The title is Lamboozling Attackers and our names and Summercon 2022 are at the bottom of the slide. The background is a turquoise lagoon at the base of a waterfall, waterfall foamy and enticing and glittering in sunlight. There is a spectacular rainbow arcing across the top third of the slide, hitting the tropical water at the slide's edges. The transcendent scenery inspires hope, enchantment, and a bit of whimsy.
A screenshot of our slide deck. The text says: Systems terraforming: reify an entire constellation of hosts upon connection. The background image is of the Milky Way as seen from Earth. There are an astonishing number of purple hues within it -- the purple of bruises, of lilacs and pansies and orchids, of glittering amethysts, just as the stars look so scintillant and shimmering in the photo. The space dust of the Milky way looks nacreous, opalescent while glowing peach in the bottom right of the image. It is impossible not to behold beauty in this image, to not feel like perhaps anything is indeed possible.
A screenshot from our slide deck. It features a Sun Tzu quote, which says "Hold out baits to entice the enemy. Feign disorder and crush him." The background is of a beach where a lavish, foamy wave is mid-crash upon the sandy shores, which look lavender in the light of dusk.
A screenshot of a slide from our presentation. The text says: Imagine if software engineers could exploit attackers as much as attackers exploit defenders now! The background image is of a sunny, cloud-painted sky -- as if you can feel the delicate rays warming your face through the screen. But, notably, there is a rainbow lens flare in it the shape of a waxing moon. Such moons represent birth, enchantment, opportunity -- the start of something bigger to come. And rainbows reflect possibility as well, do they not? That something magical and wonderful might be vibrating the very air we breathe right at this moment. Lamboozling is that magic, that opportunity, that inspiration. The overall impression imparted is one of affirmation and encouragement.
3:18 PM ∙ Jul 20, 2022
26Likes9Retweets

Paper here:

https://cacm.acm.org/magazines/2022/6/261170-lamboozling-attackers/fulltext

-

Why are McDonald’s Self Service Kiosks so hackable?


Why are McDonald’s Self Service Kiosks so hackable?

McDonalds in Australia do a decent cup of coffee. It’s not great but it’s consistently decent so I often start my day with a cup. Due to my travels around Australia in a decked out van I have seen how many McDonalds operate and just how many of

-

Twitter avatar for @pancak3stack
pancak3 @pancak3stack
Aleksandr Vadimovich Zhukov (06.04.1984), one of the malware developers working for the Conti RaaS organization. pancak3.substack.com/p/van

Cc @Kozielectric

pancak3.substack.comvanOne of the malware developers working for the Conti RaaS organization.
3:31 PM ∙ Jul 25, 2022
91Likes15Retweets

-

Twitter avatar for @d_olex
Dmytro Oleksiuk @d_olex
Enjoyed new malware report? Want similar UEFI firmware implant for your operations? Check out my Boot Backdoor: it is more reliable than #CosmicStrand, it is harder to detect, it has more deployment options and its sources available on github: github.com/Cr4sh/s6_pcie_…
Twitter avatar for @GustavoCols
Gustavo Cols @GustavoCols
Our new blog post is about a UEFI firmware bootkit that we called #CosmicStrand and attributed to an unknown Chinese-speaking threat actor. #APT #Securelist #Kaspersky
https://t.co/jbb7GLCnKB
3:48 PM ∙ Jul 25, 2022
57Likes21Retweets

For attackers who have started using cr4sh’s tools in the wild, see here:

https://www.theregister.com/2022/07/21/us_cyber_command_malware_ukraine/

-

Twitter avatar for @mrkoot
Matthijs R. Koot @mrkoot
Russian Intelligence: A Case-based Study of Russian Services and Missions Past and Present (14MB .pdf, Spring 2022, 370 pages) ni-u.edu/wp/wp-content/…

Author: Kevin P. Riehle (@riehle_kevin) Editor/Publisher: National Intelligence (NI) Press

/c @krypt3ia #intelligence #russia

Image
Image
Image
Image
5:26 PM ∙ May 17, 2022
40Likes13Retweets

-

The diary of Arthur Bremer, which was made into the book “and assassin’s diary” which partially inspired the movie “Taxi Driver.”

It is amazingly articulate and well written.


Bremer Arthur Diary Book of : Harold Weisberg : Free Download, Borrow, and Streaming : Internet Archive

Weisberg, an Office of Strategic Services officer during World War II, U.S. Senate staff member and investigative reporter, devoted 40 years of his life to...

-

Twitter avatar for @avalaina
Oleksandra Matviichuk @avalaina
It’s a really a case when one graffiti from St. Petersburg (Russia) is worth a thousand words. One of the best examples of oppositional street art. #RussianWarCrimes
Image
9:31 AM ∙ Jul 25, 2022
10,442Likes2,524Retweets

-

-

Twitter avatar for @ButWithRaptors
But With Raptors @ButWithRaptors
Singin' in the Rain (1952) but with a Velociraptor
4:01 PM ∙ Jul 25, 2022
66,552Likes11,926Retweets

-

Twitter avatar for @jerryaldrichiii
Jerry Aldrich @jerryaldrichiii
LMAO, anyone else remember the thread on the left? Well, here's how it turned out.
Screenshot showing a Twitter thread from 2021 of a T-Mobile rep saying that they can't be hacked because their security is "amazingly good"
Screenshot of an Arstechnica article on 2022 saying that T-Mobile had to pay $500M for one of the largest data breaches on US history.
3:40 AM ∙ Jul 26, 2022
501Likes163Retweets

The Info Op is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X