the grugq's newsletter

Subscribe
Archives
June 12, 2025

June 12, 2025

June 12, 2025

"We have been able to do that through the use of AI tools far more quickly than what was done previously—which was to have humans go through".

I felt a great disturbance in the Force, as if millions of redactors cried out ...https://t.co/5vDtFAWsOG via @thedailybeast

— Dr. Dan Lomas (@Sandbagger_01) June 11, 2025


This weekend, I gave a talk on web browser security research at a student-organized conference. I tried to make the talk reasonably beginner-friendly, so the slides (linked here) could hopefully be useful to someone as a learning resource. https://t.co/23xCj2AvTN

— Ivan Fratric 💙💛 (@ifsecure) June 11, 2025


The SDR outlines sensible steps to improve defence in the cyber domain. But it leaves details to be developed, particularly about how the UK should operate in cyberspace, writes @josephdevanny in the latest #RUSICommentary. https://t.co/OCltGWyQrR

— RUSI (@RUSI_org) June 11, 2025


Published, go check it out, it is a fun ride indeed: https://t.co/nkk0WkIzFt

Part 3 will be done when I see how Insyde fixed the vulnerability and if we could do something about that fix. https://t.co/5z6gOjac6y

— Nikolaj Schlej (@NikolajSchlej) June 11, 2025


pic.twitter.com/bKN0ZnApVS

— Arthur Conmy (@ArthurConmy) June 11, 2025


What does it take to hack a @Sonos Era 300 for Pwn2Own?

Take a look at our process of adapting existing research, establishing a foothold, and exploiting media parsers for unauthenticated RCE over the network🔥👇https://t.co/FxSbV3uEBp pic.twitter.com/53WI5eQEoN

— RET2 Systems (@ret2systems) June 11, 2025


Webkit: Cross-site CSS rule and redirect URL disclosure https://t.co/zbebKSXHXG

— Project Zero Bugs (@ProjectZeroBugs) June 12, 2025


#exploit#Kernel_Security
1. CVE-2025-21204:
Abusing the Windows Update Stack to Gain SYSTEM Accesshttps://t.co/8ylvL8ufqu

2. Bypassing MTE with CVE-2025-0072
(Arm Mali GPU kernel code execution)https://t.co/u4Kkub9Wv3
]-> PoC: https://t.co/LAOp98tvWr

— Mr. OS (@ksg93rd) June 10, 2025


oh, boy ... CVE-2025-33073 SMB Client Elevation of Privs is wildhttps://t.co/piQIg0lDV7 https://t.co/CAOnKQe3SJ

— Florian Roth ⚡️ (@cyb3rops) June 11, 2025

Don't miss what's next. Subscribe to the grugq's newsletter:
X