the grugq's newsletter

Subscribe
Archives
June 26, 2024

June 26, 2024

June 26, 2024

AI associated platforms are one of my 1st targets on internal pentests and red team tests atm.

Training web UIs, model GUIs, AI associated web frontends.

🔑 Auth is bad or non-existent
⏲️ They all have old web bugs (LFI, SQLi, IDOR, etc)
👀 They house ALL of the sensitive… https://t.co/8AmtuRUh22

— Jason Haddix (@Jhaddix) June 25, 2024


So, six Russian hackers were added to the EU’s sanctions list on Monday.

What I find really interesting in this story are the discrepancies between the European Council’s sanctions and those from the United States and United Kingdom...

Quick đź§µhttps://t.co/rbrihobKaK

— Alex Martin (@AlexMartin) June 24, 2024


Reverse engineering and emulating an automotive electronic control unit (ECU) (Renesas RH850)
Great work by Philippe Azalbert and Damien Cauquil (@quarkslab)https://t.co/EUlmn4m8z2#automotive pic.twitter.com/PGzBlsrSfi

— 0xor0ne (@0xor0ne) June 24, 2024


Detecting stealth rootkits on Linux can be done from the command line. The secret is to ask the same question multiple ways to make sure all answers agree.

Let's find a directory from the Reptile stealth rootkit on Linux with link checks.

h/t @hal_pomeranz for this method. pic.twitter.com/nAzbxRNiyf

— Craig Rowland - Agentless Linux Security (@CraigHRowland) June 25, 2024


i see you kids buying pre-rolled joints and now i understand the pain my grandpa felt when i told him i paid somebody to change my car’s oil

— skáld (@boogerdiner) June 25, 2024


What a time to be alivehttps://t.co/oh8NzsTqCJ pic.twitter.com/5cnDve9SBK

— dmnk@infosec.exchange (@domenuk) June 25, 2024


✍️ Shot Through the Heart: An Introduction to Fault Injection by @joegrand

An overview, demonstration, and personal stories of injecting faults into embedded systems in order to reveal their secrets. https://t.co/6bEd1cuJuX pic.twitter.com/wpD5geGAXw

— Alex Plaskett (@alexjplaskett) June 25, 2024


Transporter delivering $420,000 Rolls-Royce receives text to change destination address to a random parking lot. Thief texts dealer showing they already removed the GPS tracker.https://t.co/wha1zigE6N

— SwiftOnSecurity (@SwiftOnSecurity) June 25, 2024


Some fear that the Korea-Russia Strategic Partnership Treaty, combined with the existing Korea-China Treaty, could lead to China being dragged into war if North Korea feels obliged to support Russia in wars , e.g. Ukraine. It considers also cooperation in information and… pic.twitter.com/IV7JJkzWoR

— Lukasz Olejnik (@lukOlejnik) June 26, 2024

My quick technology and security assessment of Russia-Korea treaty. It is very significant. The treaty art. 4 is equivalent to NATO art. 5 collective defence clause. Art 4 gives grounds for cybersecurity and information security cooperation. Art. 18 and 19 is about cybersecurity… pic.twitter.com/hTQYMHGD1O

— Lukasz Olejnik (@lukOlejnik) June 26, 2024


Turns out the great Westminster honey trap was just a guy harassing and cyber bullying politicians.

Man arrested over Westminster honeytrap case

Earlier this year, a string of men, mostly in politics, revealed they had received unsolicited WhatsApps.


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X