the grugq's newsletter

Subscribe
Archives
March 15, 2024

March 15, 2024

March 15, 2024

Update: done!

“Drivers of cars manufactured by General Motors, Ford, Honda and other popular brands say that their insurance rates went up after the companies sent data about their driving behavior to issuers without their knowledge.

Dahl said that his insurance agent told him the price… pic.twitter.com/aikf0GlQ1J

— Chief Nerd (@TheChiefNerd) March 13, 2024


The Cisco Product Security Incident Response Team (PSIRT) became aware of additional attempted exploitation of this vulnerability in the wild... for Cisco Adaptive Security Appliance Software - CVE-2020-3259https://t.co/5mwgjcCFS8 pic.twitter.com/3Onqu26rfi

— Alexandre Dulaunoy @adulau@infosec.exchange (@adulau) March 14, 2024


In a rather amusing development, a convicted spy in Sweden, currently serving a life sentence in prison, has to pay additional taxes for the income he received from the Russians. https://t.co/6vFyYy7y2b

— Tony Ingesson (@tonyingesson) March 14, 2024

You have not yet realised the power of the Swedish inkomstbeskattning. Älskar när det gråbyråkratiska systemet kommer in och skipar lite rättvisa.
"Peyman Kia krävs på skatt för spionpengarna från Ryssland"https://t.co/YCxL7h7XQy

— David Bergman (@David_M_Bergman) March 14, 2024


VirtualBox internals, vulnerabilities analysis and exploitation (CVE-2023-21987 and CVE-2023-21991) by @qriousechttps://t.co/E3vPy2raRR#cybersecurity #virtualbox pic.twitter.com/7ZEfMe62W3

— 0xor0ne (@0xor0ne) March 14, 2024


In Monero traceability news, here's some "how it started" vs. "how it's going" pic.twitter.com/irlbl763mQ

— Ric “el pony esponjoso” (@fluffypony) March 14, 2024


A case of missing bytes: #bruteforcing your way through #Jenkins' CVE-2024-23897

(In which US crypto export restrictions prove to be still harmful after 25 years)https://t.co/e0BiGpVNaMhttps://t.co/XzHzuZmwb5

— raptor@infosec.exchange (@0xdea) March 14, 2024


Oh, yes! The "Progress" way to keep researchers out of your stuff... https://t.co/3YX64N4t3G pic.twitter.com/BG4uBZ9o4r

— MCKSys Argentina (@MCKSysAr) March 14, 2024

Today we are disclosing several vulnerabilities effecting the #Fortinet #FortiWLM (Wireless LAN Manager). The vulnerabilities span from command injection, SQL injection, to file reads.

While most were patched late last year, 2 remain unpatched after 307 days from our initial…

— Horizon3 Attack Team (@Horizon3Attack) March 14, 2024


I've audited the Android kernel in late 2023, and reported 10+ kernel bugs to Google, along with 2 exploits. Today, I'm releasing the first exploit, targeting the Mali GPU on Pixel devices, accessible from an untrusted_app context.https://t.co/r7wXj7TvwH

— simo (@_simo36) March 13, 2024


(CVE-2024-0223)[1505009][$15000][ANGLE][SwiftShader]WebGL Vulkan Spirv bytecode builder length truncate lead to heap overflow is now open with a PoChttps://t.co/c0xNiKlYvb

./chrome -use-gl=angle -use-angle=swiftshader http://localhost:8000/poc2.htmlhttps://t.co/Y4y8UrpxoE https://t.co/hM6IIExwZT

— xvonfers (@xvonfers) March 14, 2024


An Iranian linked hacktivist group is claiming to have breached @Viber messenger. As proof they released images of access to their management panel. Screenshots look legitimate and seem to give full access to all user data.
Additionally they claim to have extracted source code. pic.twitter.com/U8q3KHGkd7

— Gi7w0rm (@Gi7w0rm) March 14, 2024


pic.twitter.com/QJcl9fzsQA

— ᴉpᴉǝH 🐐💕 (@summer__heidi) March 14, 2024

Don't miss what's next. Subscribe to the grugq's newsletter:
X