the grugq's newsletter

Subscribe
Archives
June 18, 2025

June 18, 2024

June 18, 2024

🚗🔌 We reverse engineered the Tesla Wall Connector and uncovered a previously undocumented attack surface via the charging cable. From protocol analysis to code execution, a Pwn2Own Automotive 2025 exploit write-up.https://t.co/kUsIFaTcQr

— Synacktiv (@Synacktiv) June 17, 2025


Exploiting the CVE-2025-21756 1-day vulnerability@v4bel and @_qwerty_po posted a kernelCTF report about exploiting a UAF in the vsock subsystem of the Linux kernel:https://t.co/iw1O0ZivdG pic.twitter.com/f8rC7YqAVC

— Linux Kernel Security (@linkersec) June 17, 2025


I mapped Iranian-linked cyber operations following Operation Rising Lion. Each event is attributed to a specific threat actor, there is a blend of hacktivist and state-sponsored activities. Their targeting goes beyond Israel, extending to critical sectors like defense contractors… pic.twitter.com/ufYJXDH8xK

— Arda Büyükkaya (@WhichbufferArda) June 17, 2025


Following Sepah Bank hit, Sparrows hit a large Iranian exchange and sucked up $47M. They're not exactly wrong about the mentioned affiliation though. Multiple cases and sources exist that highlights them being the favorite upstream money shop of "places of interest". https://t.co/hSMMqRkyTW

— Hamid Kashfi (@hkashfi) June 18, 2025

The sad part is, this will hurt civilians as much as it will affect the main targets of their attacks. There are only a handful of exchanges active in Iran, which means people have practically no choice, if they have crypto assets and need to work with it.

— Hamid Kashfi (@hkashfi) June 18, 2025

The smoke is growing bigger and bigger:

49M:https://t.co/G2TkW49jlj
24M: https://t.co/Ou5jqr82Pq
2M: https://t.co/dgtxffeeBr

so far about $75M in total.

— Hamid Kashfi (@hkashfi) June 18, 2025

It's also worth highlighting that unlike most global exchanges that customer assets are insured, or somehow backed up, that's not the case for Iranians. At least as far as I know. So there's no way for Nobitex to recover their loss, or pay back their customers. https://t.co/kFk4nYXRqk

— Hamid Kashfi (@hkashfi) June 18, 2025

Thoughts

The predatory sparrows just burned millions of crypto from one of Irans only crypto exchanges. That will, as Hamid says, mostly impact civilians. But it is a major signal about the motivation for these guys.


Possible cyber/kinetic integration for strategic effect:

According to sources familiar with the operation, Mossad initiated a targeted disinformation effort days before the strike. Using falsified communications through Iranian channels, they triggered what appeared to be an… https://t.co/aQ7qNNfGv1

— Dmitri Alperovitch (@DAlperovitch) June 17, 2025


ok my new blog is live, will update with older blog posts soon!
👉 https://t.co/DSXfWg4Ei7 pic.twitter.com/UGIchGy60u

— pwn() (@PwnFunction) June 17, 2025


The "Doomsday" radio station UVB-76 is transmitting messages again.

Before the announcement that the U.S. Navy had entered the Persian Gulf, the station broadcast mysterious codes:
NZHTI 9709 BOMZHOKREM 1192 2400 and NZHTI 31553 DUETOTIP 6855 6414.

Some Western media believe… pic.twitter.com/SHCQ0WGla3

— WarTranslated (@wartranslated) June 18, 2025


🚨 China is using AI not just to innovate — but to infiltrate. New NYT reporting, based on Recorded Future research, shows how AI is improving the speed, accuracy, and scale of military intelligence.https://t.co/2LHOEQLUFT

— Recorded Future (@RecordedFuture) June 17, 2025

China’s PLA Leverages Generative AI for Military Intelligence: Insikt Group Report

Explore how China’s PLA is adopting generative AI for military intelligence. This Insikt Group report reveals AI-driven intelligence tools, strategic adaptations, and implications for global security.


Don't miss what's next. Subscribe to the grugq's newsletter:
X