the grugq's newsletter

Subscribe
Archives
July 7, 2024

July 6-7, 2024

July 6-7, 2024

Delay due to being too damn sick to do anything.

So now that Nvidia has far outstripped the market cap of AMD and Intel, I thought this would be a fun story to tell. I spent 6+yrs @ AMD engg in mid to late 2000s helping design the CPU/APU/GPUs that we see today. Back then it was unimaginable for AMD to beat Intel in market-cap… pic.twitter.com/bYCS5vY0QO

— Hemant Mohapatra (@MohapatraHemant) July 5, 2024

Thread by @MohapatraHemant on Thread Reader App – Thread Reader App

@MohapatraHemant: So now that Nvidia has far outstripped the market cap of AMD and Intel, I thought this would be a fun story to tell. I spent 6+yrs @ AMD engg in mid to late 2000s...


Reminder that July is a dangerous time to shoot fireworks, probably best to wait until August just to be safe pic.twitter.com/6YJSgEwUAl

— James Medlock (@jdcmedlock) July 5, 2024


Again, critical infrastructure is already being compromised by cyber threat actors *without the use of AI*. The only thing that keeps your lights on is 1) the restraint those actors show and 2) thankless work by CISA and others to remove them. The defenses to each of these… https://t.co/HPpgx6lCBt

— chrisrohlf (@chrisrohlf) July 5, 2024


The asymmetry of nudges - lcamtuf’s thing

Answering the age-old question: why do bad decisions happen to good companies?


“Morality and ethics should play no part”: Leaks reveal how Russia's foreign intelligence agency runs disinformation campaigns in the West

The Insider has obtained hacked correspondence from officers of Russia's foreign intelligence agency (SVR) responsible for “information warfare” with the West. The leaked documents, intended for various government agencies, reveal the Kremlin's strategy: spreading disinformation on sensitive Western topics, posting falsehoods while posing as radical Ukrainian and European political forces (both real and specially created), appealing to emotions — primarily fear — over rationality, and utilizing ...

https://theins.ru/politika/272852


On the one hand Signal had some bad bugs that are now fixed. On the other hand when a bad guy is running code on your computer, your messenger apps are not going to be able to protect your comms. https://t.co/TOcz7bADtj

— Charlie Miller (@0xcharlie) July 6, 2024


https://www.theregister.com/2024/07/05/qilin_impacts_patient/


https://x.com/erasandepochs/status/1809530101320581554


ebpfkit is a rootkit that leverages multiple eBPF features to implement offensive security techniques

GitHub repo: https://t.co/NiWZ2gHpNA
BH presentation: https://t.co/1L7TkuJYlm
DefCon: https://t.co/xQESUkrpFr#rootkit #cybsersecurity pic.twitter.com/BL7BQpWVRl

— 0xor0ne (@0xor0ne) July 5, 2024


From the archive: Read Stephen Weissman’s 2014 essay on the history of U.S. covert action in Congo—and the lasting consequences of the CIA’s interventions.https://t.co/KJ2TqKTWUL

— Foreign Affairs (@ForeignAffairs) July 6, 2024

https://archive.is/EhUO8


The wonderful house clearer dropped some old papers off (for us to use when packaging up our Etsy parcels) Many wartime ones! This one @DailyMirror September 1939 pic.twitter.com/dkIOkmTpIY

— Garden Brocante (@GardenBrocante) March 14, 2021


Three-hundred-thirty-six (yes, 336) malicious npm packages were discovered last week:https://t.co/auIDTNmDpG

— Catalin Cimpanu (@campuscodi) July 6, 2024


A thread of threads. 20 misconceptions about the Revolutionary War (or American War of Independence). Americans (proud to be one) are often quite ill-informed about the military struggle which led to our independence from Great Britain.

This isn't your father's rev war. 1/25 pic.twitter.com/UY3y092R5o

— Dr. Alexander S. Burns (@KKriegeBlog) July 6, 2024

Thread by @KKriegeBlog on Thread Reader App – Thread Reader App

@KKriegeBlog: A thread of threads. 20 misconceptions about the Revolutionary War (or American War of Independence). Americans (proud to be one) are often quite ill-informed about the military struggle which led to o...…


https://yosefk.com/blog/advantages-of-incompetent-management.html


I hope the transition of power in the US is as peaceful and uneventful as Iran's, an actual thing I'm saying in 2024 https://t.co/dWNn5LSKDb

— Seva (@SevaUT) July 6, 2024


pic.twitter.com/BjvJcWY38F

— ᴉpᴉǝH 🐐💕 (@summer__heidi) July 6, 2024


pic.twitter.com/9mScawcv3g

— knv (@knveth) July 6, 2024


What every programmer should know about concurrency

https://assets.bitbashing.io/papers/concurrency-primer.pdf[concurrency-primer.pdf


Across the dialects of Ancient Greek, one difference is that a long ā vowel shifted to ē in Ionic and Attic Greek, but didn't shift in Doric.

This vowel split is reflected in two English words with a common Greek origin: 'mechanic' (from Ionic-Attic) and 'machine' (from Doric)!

— Danny Bate (@DannyBate4) July 1, 2024

Aside from some technical terms containing thálassa/thálatta 'sea', the only other example of this dialectal difference that I know of in English is 'glossary' (from Ionic) and 'glottal' (from Attic).https://t.co/62AO7H7HTw

— Danny Bate (@DannyBate4) July 1, 2024


If you're on an internal pentest engagement, always go after printers. There's a good chance if you're in a decent sized environment they have scan to email set up. Go into the network settings and change the SMTP server to one under your control. Then do a connection test and…

— ghostblade (@65thsquare) July 7, 2024


collection of kCTF exploits. not just exploit source, but documentation about the bug and documentation about how the exploit works. very cool stuff, and some really creative people out there https://t.co/g13hLmF2Rk

— h0mbre (@h0mbre_) July 5, 2024

security-research/pocs/linux/kernelctf at master · google/security-research · GitHub

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code. - google/security-research


https://cyberisfull.com/


Suddenly, half of the subway ads are for impenetrable B2B software. They’re all like: When Product tells HR they need a go-to-market huddle by yesterday — and there are no blockers? That’s Squindo.

— willy 🌜💧 (@willystaley) July 5, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X