the grugq's newsletter

Archives
March 1, 2026

March 1, 2026

March 1, 2026

https://t.co/DDrdRSaLzn — Thomas Roccia 🤘 (@fr0gger_) March 1, 2026


Tip for using AI to find vulnerabilities in a repo: Remove the markdown files.

You want the AI to reason about security based on the code, not the claims the author makes in the readme.

— Zack Korman (@ZackKorman) February 28, 2026


TL/DR - yes, a lot:)
I will try to keep it simple

Interception geometry matters for endo-atmospheric TBM defence. A MaRV headed straight at the launcher is a different engagement from one aimed a few kilometres aside, particularly once overflight and rear-sector cases arise
1/16 https://t.co/oT1wB6cOeY

— Matej Rafael Risko (@MatejRisko) March 1, 2026


WHITE SMOKE. Iran has a new Ayatollah. pic.twitter.com/qT3n8k9HqX

— Rabbi Linda Goldstein (🇵🇸🍉I/P Commentary) (@realrabbilinda) February 28, 2026


The first two known exploits against live ZK circuits just happened, and they weren't subtle underconstrained bugs.

They were Groth16 verifiers deployed without completing the trusted setup ceremony. One was white-hat rescued for ~$1.5M, the other drained for 5 ETH.

🧵

— zkSecurity (@zksecurityXYZ) February 27, 2026


February 28th 1982: Via Crypto AG, Costa Mendez sends a classified message to Argentine Ambassadors in London and the UN, asking "What would the British do if we invaded?"

The message is covertly intercepted and declassified by the NSA and passed on to London.

1/2 pic.twitter.com/8VFUwDoMUR

— Ricky D Phillips - Military Historian (@RDPHistory) February 28, 2026


Just caught another illegal...but before we tell you that new crazy story, make sure you watch the full-length video of how we (@Dobrokhotov @FideliusSchmid @romanlehberger, @florianabulfon) caught "Maria Adela", the fake Peruvian jewelry maker. https://t.co/0olGMoH3tS

— Christo Grozev (@christogrozev) February 28, 2026


How I caught an Illegal Russian Spy — The Christo Files

source: Christo Grozev (@christogrozev)


Really important to me that Genghis Khan and his Mongol horde were going around saying 'what up dog' to each other pic.twitter.com/cGhDZyKYz4

— weird medieval guys (@WeirdMedieval) February 28, 2026


Emacs IS an age verification scheme. Nobody under 40 uses it. https://t.co/ma5Fs2Nb2g

— Olof Johansson (@olofj) February 28, 2026


well well well https://t.co/O8iOF4SQCp

— onionweigher 🧅⚖️ (@onionweigher) February 28, 2026


You’re laughing? A Dutch newspaper is going to have the front page headline: “Khamenei Dood. Wat Nou?” and you’re laughing?

— Daniel Sugarman (@Daniel_Sugarman) February 28, 2026


Well, well, well…… https://t.co/dsdzAnFYox

— ☀️AliquisNovus☀️ (@PalmyrPar) February 28, 2026


Link to the repo: https://t.co/m9QAaKXr6B

— Hash Milhan (@hashir) February 28, 2026

GitHub - koala73/worldmonitor: Real-time global intelligence dashboard — AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface

Real-time global intelligence dashboard — AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface - koala73/worldmonitor


koala73/worldmonitor (18,964 stars, TypeScript) Real-time global intelligence dashboard — AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface

source: Hash Milhan (@hashir)


With everything happening between the US and Iran, World Monitor by @eliehabib is worth knowing about. It's an open source intelligence dashboard with a 3D globe, 36+ data layers, and 150+ news feeds that you can run locally. Think of it as a free, self-hosted alternative to… https://t.co/d1W58RNaZC pic.twitter.com/RY7p3ZCozD

— Ryan (@ohryansbelt) February 28, 2026


JUST IN: 🇮🇷 🇺🇸 Six suspected insiders made $1.2M betting on a US strike on Iran

Most of these wallets:

• were funded in the last 24h
• specifically bet for February 28
• bought "yes" hours before the strike pic.twitter.com/n3G6OIEOXt

— Bubblemaps (@bubblemaps) February 28, 2026


One reason Twitter, despite being absolutely broken in many ways, never get threatened by Bluesky or Threads or whatever is because you have obviously state-sponsored shitposting in the middle of a war. https://t.co/4RBmEQuVxi

— Lain on the Blockchain (@CryptoCyberia) February 28, 2026


China's anti-stealth radar detects the presence of stealth aircraft by exploding, thus alerting defenders that a stealth aircraft is definitely in the area. pic.twitter.com/BBxKUjI6Ft

— Space Koala (@SpaceKoala) March 1, 2026


The Iranian Foreign Minister told me that Israel keeps killing his generals so I asked how many generals he has and he said he goes to the HQ and gets a new general afterwards so I said it sounds like he’s just feeding generals to the Mossad and then his daughter started crying https://t.co/Hn1lugAMmM

— HIGH PLANES Drifter (@the_engi_nerd) February 28, 2026


1. It lets me execute highly visible cyber attacks that can be easily reported on.
* CNN verifying I took out an MOIS network in Iran: hella difficult.
* Verifying I took out a media network or mobile app: stupid easy.

2. It doesn't put my core toolset and TTPs at risk. They… pic.twitter.com/9NDOMYrgQ6

— Jake Williams (@MalwareJake) February 28, 2026


If I were an Iran target cell leader in TAO (or whatever they're calling it these days), knowing that Trump was likely to order cyber attacks, I'd have prepositioned myself in Iranian commercial networks with limited/no intel value using ONLY throwaway tools.

This checks two… pic.twitter.com/7T74Wq2VAk

— Jake Williams (@MalwareJake) February 28, 2026


Don't miss what's next. Subscribe to the grugq's newsletter:

Add a comment:

Share this email:
Share on Twitter Share on Hacker News Share via email Share on Mastodon Share on Bluesky
Twitter