the grugq's newsletter

Subscribe
Archives
March 21, 2025

March 21, 2025

March 21, 2025

https://x.com/ethicalchaos/status/1902481711109214484


People seem to fear vulnerability discovering and exploiting AI, but I worry more about a swarm of autonomous AI agents with tool use that automatically discover and exploit trust relationships on internal infra in parallel at machine speeds.

โ€” Dino A. Dai Zovi (@dinodaizovi) March 20, 2025

Thoughts:

You donโ€™t actually need an AI for that. The morris worm did that back in the 80s, and NotPetya did the same. You can brute force your way through the shadow internet by just connecting to neighbours and systems that are configured as peers on the compromised host.


3 years earlier (ab)used by @x86matthew ๐Ÿคhttps://t.co/qK3oB34dDS

L"%512S/c [...] https://t.co/MKKo2VgTd4

โ€” mgeeky | Mariusz Banach (@mariuszbit) March 19, 2025

ZDI 0day discovery

1/7 Trend Zero Day Initiativeโ„ข (ZDI) discovered ZDI-CAN-25373, a critical vulnerability in Windows shortcut files.

State-sponsored #APT groups are actively exploiting this #ZeroDay in targeted attacks, posing a serious risk to affected systems.

Read: https://t.co/3NbQ4gltJ9 pic.twitter.com/CnWPsyvg1m

โ€” Trend Micro Research (@TrendMicroRSRCH) March 18, 2025

Original discovery in 2022

https://web.archive.org/web/20240122163849/https://www.x86matthew.com/view_post?id=embed_exe_lnk

Abusing .LNK

>.LNK shortcut ๐‚๐ซ๐ข๐ญ๐ข๐œ๐š๐ฅ ๐•๐ฎ๐ฅ๐ง๐ž๐ซ๐š๐›๐ข๐ฅ๐ข๐ญ๐ฒ
>abused as ๐—ญ๐—ฒ๐—ฟ๐—ผ-๐——๐—ฎ๐˜†
>look inside
>it's just lots of spaces and \r\n to hide command line string

๐Ÿ™„ https://t.co/qimOArVa1M

โ€” sixtyvividtails (@sixtyvividtails) March 19, 2025

Trend Micro on LNK exploitation in 2017

Releasing a blogpost about uncovering #ZDI-CAN-25373 - the malicious abuse of MAX_PATH for lnk files "Zero-Day in Widespread APT Campaigns". Here is the trendmicro blog post from ... *checks notes* ... 2017?
---https://t.co/KFeY0H8Sdf pic.twitter.com/DOhYVg75mn

โ€” tmechen (@tmechen_) March 19, 2025


Vultisig swaps have collected $200k in revenue so far!
Look at them pile in here from the TC affiliate collector module.

We are finalising the staking contract - should be live for launch! Stake your $VULT - earn your share of the $200k.

No tricks - remember $VULT is a 100%โ€ฆ pic.twitter.com/GcGdDiPqR5

โ€” JP (@jpthor) March 20, 2025

JP I hope you realize a good chunk of that revenue is being generated from the Bybit hack.

DPRK has been doing BTC -> BNB or AVAX TC swaps via Vultisig for the past few days in size. pic.twitter.com/yy9S4JRdIm

โ€” ZachXBT (@zachxbt) March 20, 2025


"... Soviet illegal agents all over the world, when they want a meet with their principal, are under instruction to send a proper communication to 'K.S. Smirnov, Central Post Office, Vladimir, USSR'..." #KGB โฌ‡๏ธ pic.twitter.com/Y9Hbq17ceR

โ€” Filip Kovacevic (@ChekistMonitor) March 20, 2025


https://www.galois.com/articles/introducing-grease


NEW: North Korea is reportedly launching a new cybersecurity research unit called Research Center 227, which will be housed within the intelligence agency Reconnaissance General Bureau (RGB), and will focus on AI-based hacking and stealing digital assets.https://t.co/AMnKwPohBC

โ€” Lorenzo Franceschi-Bicchierai (@lorenzofb) March 20, 2025


CVE-2025-0927 details here!https://t.co/z9amcuNjKP

โ€” Attila Szasz (@4ttil4sz1a) March 18, 2025


nice Linux kernel pwn challenge write up by @terawhiz for LACTF 2025. exploiting a 3 byte OOB write primitive https://t.co/keuUUdwOCl

โ€” h0mbre (@h0mbre_) March 20, 2025


๐Ÿ“ฃ๐Ÿšจ BAT SIGNAL: A law in France that would mandate a backdoor in end to end encrypted communications is set for a vote within the next day, after some start-stop skirmishes.ย 

The French Narcotraffic law would require encrypted communications providersโ€”like Signalโ€”create aโ€ฆ

โ€” Meredith Whittaker (@mer__edith) March 19, 2025


CIA Covert Ops: Kennedy Assassination Records Lift Veil of Secrecyhttps://t.co/Q67MRB0wNM

โ€” Dr. Dan Lomas (@Sandbagger_01) March 19, 2025


No idea if its real but it sure is funny. Are we cooked? pic.twitter.com/izEd5SJM7s

โ€” Matt Johansen (@mattjay) March 20, 2025


New AI Red Team tool released! My team at Verizon just released a set of Burp Extensions to test and leverage GenAI during penetration tests: https://t.co/Q5gjhEtotI

Check it out!

โ€” Jorge Orchilles (@jorgeorchilles) March 19, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:
X