the grugq's newsletter

Subscribe
Archives
June 24, 2024

June 24, 2024

June 24, 2024

Thoughts on Strategy, War and AI - by Dr. Heather M. Roff

Self-Reflection, Deception, and Degradation of "The People" (or political and strategic theory for a Sunday)


https://www.journals.uchicago.edu/doi/10.1086/731029


Arm64EC for Windows 11 apps on Arm | Microsoft Learn

Learn how Arm64EC empowers you to build and incrementally update apps that benefit from native performance on Arm devices, without interrupting your current x64 functionality.


This weekend, I played with Blue Water in GoogleCTF. Here are my challenge writeups. Give them a read, I had a lot of fun writing them!

TL;DR: Rust reversing, inverting a crappy cipher, finite fields :D
πŸ‘‡https://t.co/3CeEy134DU pic.twitter.com/3WSzcdysTb

β€” cts 🌸 (@gf_256) June 24, 2024


Get Started With GraphRAG: Neo4j's Ecosystem Tools

The Neo4j GraphRAG Ecosystem Tools make it easy to develop GenAI applications grounded with knowledge graphs.


Wrote a blogpost summarizing all of the features we've added to Lucid in the last few months: Snapshots, Code Coverage Feedback, and more. In the blogpost we actually get all the way to fuzzing a Linux kernel syscall which includes a setup description. https://t.co/XvVQN8HJ8m

β€” h0mbre (@h0mbre_) June 23, 2024


Maybe a wax Lincoln sculpture wasn’t the best idea during DC’s first week of summer heat pic.twitter.com/qfp0lIGFWo

β€” Kirk A. Bado (@kirk_bado) June 23, 2024


MSFT released a patch for CVE-2024-30078 (Wi-Fi Driver RCE) on June cumulative update, however details on the advisory have been very limited.
I'm leaving some quick notes from a quick reverse engineering of the patch that hopefully will shed a little more light on the issue. 🧡

β€” farmpoet (@f4rmpoet) June 23, 2024

Thread by @farmpoet_eth on Thread Reader App – Thread Reader App

@f4rmpoet: MSFT released a patch for CVE-2024-30078 (Wi-Fi Driver RCE) on June cumulative update, however details on the advisory have been very limited. I'm leaving some quick notes from a quick reverse engineering...…


pic.twitter.com/HGFKQ2eO8g

β€” Rothmus 🏴 (@Rothmus) June 23, 2024


Execute arbitrary code as any app on a device (CVE-2024-31317) (Zygote injection)https://t.co/gFFCgvdiMR

Technical blog post by Tom Hebb#android pic.twitter.com/9Aapc317uW

β€” 0xor0ne (@0xor0ne) June 23, 2024


In biology, there's this phenomenon of carcinization, where non-crab crustaceans eventually develop features that make them crab-like.

I posit that there exists an equivalent of this in IT: any non-adtech business eventually evolves all the features of an advertising company.

β€” lcamtuf (@lcamtuf) June 23, 2024


My iOS Web Hacking Setup - Surge, Termius, and Caido:https://t.co/h0bbMWK9iH

β€” Evan Connelly (@Evan_Connelly) June 23, 2024


Hello everyone! Finally I have published the post about how I designed the first version of MjolnIR, the IR of Kunai, an Android analysis tool I did for my PhD, you can find it here: https://t.co/SWpGt9XqOn
I have to specially thanks @yates82 for his technical and english review.

β€” Farenain (@Farenain) June 23, 2024


The original electoral deepfake from 1924!πŸ‘‡

Lessons:

- despite all the hysteria over AI imagery, this sort of thing really isn’t new;

- very few of these deepfake efforts cut through to the election (the Zinoviev letter, as @redhistorian says, is one of the exceptions) https://t.co/BFWZWwo61w

β€” Ciaran Martin (@ciaranmartinoxf) June 24, 2024


I found a 1-click exploit in South Korea's biggest mobile chat app. This would have allowed to steal all user's chat messages. Full write-up available here: https://t.co/vPgjd9NtjS

β€” D. Schmidt (@dschmidt0815) June 23, 2024

https://css.ethz.ch/en/center/CSS-news/2024/06/from-vegas-to-chengdu-hacking-contests-bug-bounties-and-chinas-offensive-cyber-ecosystem.html


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X