the grugq's newsletter

Subscribe
Archives
June 20, 2025

June 20, 2025

June 20, 2025

Package Hallucinations: How LLMs Can Invent Vulnerabilities | USENIX



I’ve started joining every Google Meet 30 seconds early.

When you join early, everyone’s virtual note takers join early too.

I spend the first few seconds screaming about how I’m on the Titanic, we’ve just hit an iceberg, the end is near, and I need immediate assistance.

I…

— Chris Bakke (@ChrisJBakke) June 19, 2025


Russian husband and wife ‘masterminding Argentina spy network’https://t.co/91ABxnEi4x

— Dr. Dan Lomas (@Sandbagger_01) June 19, 2025


OK guys this is absolutely not the lesson.

These people getting hit are not getting hit *by Zoom*. They talk to some impersonator who gives them a Zoom phishing link, like https://t.co/JvYFKBK4wu, and they don't have the Zoom app installed natively (otherwise it'd be weird that… https://t.co/rMKqLZGxKr

— Haseeb >|< (@hosseeb) June 20, 2025


I found that you can overwrite the pointer in ntdll.__guard_xfg_dispatch_icall_fptr ( & others ) in .00cfg section without triggering copy_on_write / loss of SharedOriginal. Result is you can effectively disable CFG within a CFG-enabled proc, don't need to add addrs to bitmap

— Octoberfest7 (@Octoberfest73) June 18, 2025
Don't miss what's next. Subscribe to the grugq's newsletter:
X