the grugq's newsletter

Subscribe
Archives
March 30, 2025

March 30, 2025

March 30, 2025

A good read:

The Security Conversation – Adversary Fan Fiction Writers Guild

Is Offensive Security just security testing? No. Offensive security is a way of thinking about the current security context, predicting what’s next, exploring those hypotheses, and adding to the se…


Linux kernel Rust module for detecting rootkitshttps://t.co/uUgjzALnxW#infosec #Linux pic.twitter.com/Z6IjI9An9o

— 0xor0ne (@0xor0ne) March 29, 2025

Linux kernel Rust module for detecting rootkitshttps://t.co/uUgjzALnxW#infosec #Linux pic.twitter.com/Z6IjI9An9o

— 0xor0ne (@0xor0ne) March 29, 2025


Everyone knows all the apps on your phone - by peabee

Until a few years ago, any app you installed on an Android device could see all other apps on your phone without your permission.


#SpyNews - week 13 (March 23-29):
A summary of 76 espionage-related stories from week 13 coming from 🇨🇳🇫🇷🇮🇱🇷🇴🇷🇺🇺🇦🇨🇦🇮🇳🇺🇸🇦🇹🇳🇿🇸🇦🇬🇭🇱🇷🇸🇱🇹🇷🇪🇬🇬🇧🇮🇷🇦🇿🇦🇪🇩🇿🇲🇽🇭🇳🇧🇩🇧🇬🇩🇪🇰🇷🇰🇵🇪🇪🇱🇹🇧🇪🇷🇸🇹🇼🇵🇭🇳🇦🇫🇮🇻🇳🇨🇭🇰🇪🇿🇦🇾🇪🇱🇧🇸🇾🇨🇿🇨🇱🇳🇱🇧🇾🇵🇸🇸🇴🇸🇸🇸🇬 https://t.co/jUUiKXbK4n#OSINT #HUMINT #SIGINT #Espionage #spy

— Spy Collection (@SpyCollection1) March 30, 2025


1/ Leaked interrogation transcripts have revealed that the Kremlin has secretly taken over dozens of popular Russian Telegram channels, deanonymising their administrators on Putin's direct orders and 'persuading' them to hand control to the Russian presidential administration. ⬇️ pic.twitter.com/WCyNSmZSlN

— ChrisO_wiki (@ChrisO_wiki) March 29, 2025

Thread:

Thread by @ChrisO_wiki on Thread Reader App – Thread Reader App

@ChrisO_wiki: 1/ Leaked interrogation transcripts have revealed that the Kremlin has secretly taken over dozens of popular Russian Telegram channels, deanonymising their administrators on Putin's direct orders and '...…


source code for CyberVolk ransomware, found on virus total

1c64a0eb0846e5c4c402130185362ed85952603ef2ee24c2466953f67b819e22https://t.co/o5dvH5hSbP

— Aziz Farghly (@FarghlyMal) March 29, 2025


This repository contains collection of regular expressions to detect sensitive information, API keys, tokens, and credentials in code or text files.

Credit URL : https://t.co/X8dscrB26y

— 7h3h4ckv157 (@7h3h4ckv157) March 29, 2025

GitHub

GitHub - Lu3ky13/Search-for-all-leaked-keys-secrets-using-one-regex-: Search for all leaked keys/secrets using one regex! bugbounty

Search for all leaked keys/secrets using one regex! bugbounty - Lu3ky13/Search-for-all-leaked-keys-secrets-using-one-regex-


A Ukrainian EW device may broadcast instructions to Russian drones with ELRS frequency-hopping to stop their motors during flight so that they fall out of the sky.
It exploits that some Russian drone suppliers apparently use the same binding key for all their ELRS controllers.
1/ pic.twitter.com/wCIglb3H86

— Roy🇨🇦 (@GrandpaRoy2) March 21, 2025

Usually this key is unique for each controller that binds with its drone and sets the frequency hopping pattern.
For “convenience” Russian COs may not want that.
This allows the EW device to search for known ELRS packet signatures tied to the reused binding key signatures.
2/ pic.twitter.com/JHnyMd1wOs

— Roy🇨🇦 (@GrandpaRoy2) March 21, 2025

A spoofed signal can then be sent mimicking a legitimate control packet, using the same key and frequency hopping sequence.
This signal could include a command to set the throttle to zero while in flight!
The device may also scan for other repeated signatures to attack.
3/

— Roy🇨🇦 (@GrandpaRoy2) March 21, 2025

Sources https://t.co/ykLAOytmKj https://t.co/XGjoOMTrTu

— Roy🇨🇦 (@GrandpaRoy2) March 21, 2025


Checkmate communist plot to sap and impurify our precious bodily fluids!

Utah becomes first US state to ban fluoride in its water

The move has been criticised by experts, who say the mineral helps reduce oral cavities, especially in children.


Some IDA MCP servers can be tricked into executing arbitrary code directly from the malware sample pic.twitter.com/4kGjlKowfA

— jro (@junr0n) March 29, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:
X