the grugq's newsletter

Subscribe
Archives
March 21, 2024

March 22, 2024

March 22, 2024

White House and EPA tell US governors that water facilities need to improve their defenses against cyber threats https://t.co/YI6rusC0WT pic.twitter.com/vJq2Rlbn7z

— Sean Lyngaas (@snlyngaas) March 19, 2024


Me: So now you will deep dive into my lore?

Interviewer: Well, we call it a background check, but sure.

— Jason, ex Inferis (@benedictsred) March 20, 2024


NEW: Users of the popular site Glassdoor, which lets anyone anonymously sign up to review companies they have worked for, say Glassdoor collected and added their names and other data to their user profiles without their consent.https://t.co/AAFFiq5h1H

— Lorenzo Franceschi-Bicchierai (@lorenzofb) March 20, 2024

Shocking. Trusting someone else to protect your secrets is a losing strategy


YIKES

'... the Bureau could not be sure the tasking of the capability was always in accordance with Government intelligence requirements, New Zealand law and the provisions of the MOU'.

cc: @Sandbagger_01 https://t.co/fXA6E9S8Ux pic.twitter.com/5rjfIYl4dt

— Ravi Nayyar (@ravirockks) March 21, 2024


Hahahaha

there's a guy on Base launching the most low-effort shitters, adding .8e of liq, then rugging for ~1e around 10min later

over, and over, and over again.

At first I was pissed but then I realized he's stealing money from launch bots, and it's quite funny pic.twitter.com/hBoPiKjsea

— GK 🗿 (@Grypto_GK) March 21, 2024


Our first BOOTSTRAP24 talk video comes from the wonderful @pinkflawd - Compiler Backdooring for Beginners: https://t.co/3BKzt7w9o6

— ringzerø.training && @ringzer0@infosec.exchange (@_ringzer0) March 19, 2024


🚨Critical security alert - Ivanti Standalone Sentry users must patch immediately. Remote code execution flaw (CVE-2023-41724) could allow attackers full control of affected systems.

Details: https://t.co/atOI1jmFNw

Get the patch ASAP!

— The Hacker News (@TheHackersNews) March 21, 2024


Wondering what would happen if you applied JPEG-style lossy compression to text?

Well, here's the tool you've been waiting for - The Text Lossifizer: https://t.co/ZWWdRaXmNs

— lcamtuf (@lcamtuf@infosec.exchange) (@lcamtuf) March 17, 2024


That brings a close to the first day of #Pwn2Own Vancouver 2024. We awarded $732,500 for 19 unique 0-days. @Synacktiv currently leads in the hunt for Master of Pwn, but @_manfp is right behind them. Here are the full standings: pic.twitter.com/GbtDzbCFgO

— Zero Day Initiative (@thezdi) March 21, 2024


also, why are the actors dressed up like it's old times? it was made in 2023!! and furthermore: who is holding the camera? who's recording the movie? checkmate, filmmakers https://t.co/DQn11VkKPZ

— Rob DenBleyker (@RobDenBleyker) March 21, 2024

Losing my mind at this Zone of Interest review from CNN. Good fucking lord, this guy is apparently a professor pic.twitter.com/GM3CX52ZOL

— Lady Emily (@GreatCheshire) March 20, 2024

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X