the grugq's newsletter

Subscribe
Archives
July 7, 2025

July 7, 2025

July 7, 2025

my weekend project to learn about bluetooth mesh networks, relays and store and forward models, message encryption models, and a few other things.

bitchat: bluetooth mesh chat...IRC vibes.

TestFlight: https://t.co/P5zRRX0TB3
GitHub: https://t.co/Yphb3Izm0P pic.twitter.com/yxZxiMfMH2

— jack (@jack) July 6, 2025


I’ve been unfair to Stuxnet in the past. It turns out even bombs can’t compete with the effectiveness of cyber*

* in the right domain, caveats apply, etc etc. https://t.co/UicrXKplCe

— thaddeus e. grugq (@thegrugq) July 7, 2025


Open source being more secure has always been a myth. Very few devs want to spend time auditing code. If the original author didn't find the bug at time of writing it, it almost never gets seen because nobody is taking the time to go back and look (except red team). https://t.co/2xDcFASIYA

— Craig Rowland - Agentless Linux Security (@CraigHRowland) July 6, 2025


Might be fun to drop this as an @_MG_
Cable payload. pic.twitter.com/20yNRdR2ev

— Lozaning (@lozaning) July 6, 2025

https://t.co/NkxXWyITqA

— Lozaning (@lozaning) July 6, 2025


AI + cybersecurity articles have an extreme lack of imagination. Where are the tabletop exercises for nation state APTs silently tampering with SentencePiece tokenizer implementations introducing backdoors into normalization logic or injecting semantic collisions into tokenizer…

— chrisrohlf (@chrisrohlf) July 6, 2025


When I see discussion about AI in security (especially AI agents) - it’s often about how it will replace Tier 1 SOC analysts. It might…but I think the biggest area of opportunity in cyber security is for AI to analyze all the un-triaged alerts from an org’s security products

— Christopher Glyer (@cglyer) July 6, 2025

Thread by @cglyer on Thread Reader App – Thread Reader App

@cglyer: When I see discussion about AI in security (especially AI agents) - it’s often about how it will replace Tier 1 SOC analysts. It might…but I think the biggest area of opportunity in cyber security is...…


https://dhmo.org/


People are putting prompt injections in their research papers https://t.co/ApF6x2c3As

— Joseph Thacker (@rez0__) July 6, 2025


I wrote a short rant about what irks me when people anthropomorphize LLMs:https://t.co/AkMbdmpdqL

— Halvar Flake (@halvarflake) July 7, 2025

ADD / XOR / ROL: A non-anthropomorphized view of LLMs

In many discussions where questions of "alignment" or "AI safety" crop up, I am baffled by seriously intelligent people imbuing almost magic...


Don't miss what's next. Subscribe to the grugq's newsletter:
X