the grugq's newsletter

Subscribe
Archives
June 10, 2025

June 10

June 10

I've always said self-driving technology would save lives. Had there been humans driving those cars, the death toll would be devastating. https://t.co/pD6irG5NUA

— Sridhar Ramesh (@RadishHarmers) June 9, 2025

https://t.co/OmAPxhNJ5G pic.twitter.com/RU7ohXcEjO

— ms. gender (@twunkbucket) June 9, 2025


https://www.coverdrop.org/


I wrote a bit about X’s new encrypted DMs and the Juicebox protocol. https://t.co/Q1NwGb61ya

— Matthew Green is on BlueSky (@matthew_d_green) June 9, 2025

A bit more on Twitter/X’s new encrypted messaging – A Few Thoughts on Cryptographic Engineering

Update 6/10: Based on a short conversation with an engineering lead at X, some of the devices used at X are claimed to be using HSMs. See more further below. Matthew Garrett has a nice post about T…


A story of a terrifying immigration scam from @Documentedny, revealing how scammers created fake immigration courts, with actors pretending to be judges and ICE officers, to rip off migrants who were trying to do everything right. Instead, they were doubly victimized. pic.twitter.com/NpJW3ndyB8

— Aaron Reichlin-Melnick (@ReichlinMelnick) June 9, 2025


🛠️ Real-world RE with IDA

In this video, @bellis1001 uses patch diffing to investigate a CoreAudio vulnerability recently fixed in iOS 18.4.1—believed to have been exploited in the wild.

Follow along as they uncover key changes in the binary, trace the source of memory…

— Hex-Rays SA (@HexRaysSA) June 9, 2025


“We know more about what’s in our sausages than in our software.”🌭

NCSC CTO @ollieatnowhere discussed why secure tech goes unrewarded at #CYBERUK25. Read our latest blog to learn why incentives fail, 4 drivers to fix it, and why we must think big 💡https://t.co/fzt52csnM8

— NCSC UK (@NCSC) June 9, 2025


9 outta 10 APTs agree, Ivanti is great for remote access and management https://t.co/wa9uNRrYT7

— UwU Underground (@uwu_underground) June 10, 2025


Vibe coding has no place in Linux kernel maintenance. The vulnerability inserted into 5 LTS kernels at once apparently without any review is yet another instance of AUTOSEL fallout, here with the "new" LLM-powered version. Sources: https://t.co/5HAXO6QRzE https://t.co/3aGOt2poxM

— Brad Spengler (@spendergrsec) June 9, 2025

Thread by @spendergrsec on Thread Reader App – Thread Reader App

@spendergrsec: Vibe coding has no place in Linux kernel maintenance. The vulnerability inserted into 5 LTS kernels at once apparently without any review is yet another instance of AUTOSEL fallout, here with the "new...…


“are you talking to anyone?” yes his name is chatgpt and we are in a hallucinationship

— Shweta (@shweta_ai) June 9, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:
X