the grugq's newsletter

Subscribe
Archives
June 7, 2024

June 7, 2024

June 7, 2024

🚨NEW: Last Christmas Eve, @newsbreakApp, a free app with roots in China that is the most downloaded news app in the U.S. published an alarming piece about a small town shooting headlined "Christmas Day Tragedy Strikes Bridgeton, New Jersey Amid Rising Gun Violence in Small…

— James Pearson (@pearswick) June 5, 2024


TPM GPIO fail: How bad OEM firmware ruins TPM security


How Online Privacy Is Like Fishing


Since this cat is bagless - you don’t need admin rights to steal the Recall database. https://t.co/v3J4w3ZxKA pic.twitter.com/NXaPX1gLNz

— Kevin Beaumont (@GossiTheDog) June 6, 2024


Whoa, this is kinda cool! One spaceship sees another.

Yesterday, @eumetsat's #Meteosat weather satellite saw the @BoeingSpace #Starliner during launch.

That bright spot above the Earth is the @ulalaunch booster propelling the crew into orbit! 🚀 pic.twitter.com/qdgqxXCbVo

— Simon Proud (@simon_sat) June 6, 2024


New from me for @just_security "Open Source AI: The Overlooked National Security Imperative". In it, I argue that the future AI-driven world will be dependent on OS models and discuss why it is essential to support the OS AI ecosystem.https://t.co/4w2uR3pV6J@oiioxford @CNASdc

— Keegan McBride (@KeeganMcB) June 6, 2024


Writeup on exploiting a Use-after-free (UAF) vulnerability in Linux kernel nf_tables (CVE-2022-2586)https://t.co/hHnuzFbFDO#cve pic.twitter.com/8XgJ36d06c

— 0xor0ne (@0xor0ne) June 6, 2024


https://www.theregister.com/2024/06/05/tiktok_confirms_cnn_accounts_hijacked/


A Bayesian Treatment of the German Tank Problem | The Mathematical Intelligencer

The Mathematical Intelligencer -



Do artifacts have politics? Langdon Winner

https://matthewjbrown.net/teaching-files/philtech/winner-artifacts.pdf


Apple declined to issue a bug bounty to the Russian cybersecurity company Kaspersky Lab after Kaspersky disclosed four zero-day vulnerabilities in iPhone software that were allegedly used to spy on its employees as well as Russian diplomats. https://t.co/wiDQK7jFRH

— Alex Martin (@AlexMartin) June 5, 2024


The recording of my @offensive_con talk “UEFI and the Task of the Translator: Using cross-architecture UEFI quines as a framework for UEFI exploit development” is now on YouTube ✨https://t.co/cx14tzibgi

— ic3qu33n (@nikaroxanne) June 7, 2024


Hey, for anyone who wanted to see this slide deck, it was a keynote about the 0day market, but it commented on public research vs saleable products. I have put it here: https://t.co/XZ89wFwLVJ // cc @chompie1337 @bsdaemon https://t.co/xjOUmnTPMC

— mdowd (@mdowd) June 7, 2024


GenAI, you sweet stupid child. pic.twitter.com/j9JxnXS70f

— Seamus Blackley (@SeamusBlackley) June 6, 2024


Today we proposed reporting requirements aimed to improve internet routing security and help protect America's networks against cyberattacks. https://t.co/oeObJoiGpz

— The FCC (@FCC) June 6, 2024


LLM bullshit knife, to cut through bs

RAG -> Provide relevant context
Agentic -> Function calls that work
CoT -> Prompt model to think/plan
FewShot -> Add examples
PromptEng -> Someone w/good written comm skills.
Prompt Optimizer -> For…

— Hamel Husain (@HamelHusain) June 6, 2024


Thinking about something I heard at BSides Cheltenham last weekend: “The company was hit by ransomware 5 times in an 11 month period, and paid the ransom each time and invoiced it to outsourced IT contractors…” 💀

— Will (@BushidoToken) June 6, 2024

They should just buy a monthly subscription by now pic.twitter.com/G13xLLZAjt

— MartinZugec (@MartinZugec) June 6, 2024


Linux kernel LPE with a Use-After-Free due to a Race Condtiton in n_gsm modulehttps://t.co/dY4vzTARmK#Linux pic.twitter.com/6ShtY0fKNO

— 0xor0ne (@0xor0ne) June 7, 2024


Losing it at the community notes https://t.co/e07EQg0B2m pic.twitter.com/jqDEWgLv61

— ˗ˏˋuıʍʇʎdəəɹɔˎˊ˗👑King of the Reply Guys☁️ (@creeptwin) June 7, 2024

pic.twitter.com/Vc5dbsghNW

— ˗ˏˋuıʍʇʎdəəɹɔˎˊ˗👑King of the Reply Guys☁️ (@creeptwin) June 7, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X