the grugq's newsletter

Subscribe
Archives
March 4, 2024

March 4, 2024

March 4, 2024

Update: another section submitted to the editor. Three down, five to go. Bad news though, my editor has a family emergency.


"The head of the German air force used a telephone line that was not encrypted to discuss highly sensitive military secrets".https://t.co/QrKPPSxQrO

— Dr. Dan Lomas (@Sandbagger_01) March 3, 2024


You connect a device (Bluetooth) on a Mac and it pings an http server at Apple… pic.twitter.com/3EYG64bc60

— mRr3b00t (@UK_Daniel_Card) March 3, 2024


Every #dog owner knows this expression. This very good boy is waiting for your approval, as he's brought you a hare (!). 🐇#Roman bronze lamp of a greyhound with a bunny in his mouth (face down, its head forms the nozzle where the wick would have gone). #BritishMuseum
📸 me pic.twitter.com/NSQsXgpgxq

— Chapps (@chapps) March 3, 2024


Ideas for NsA inspired stickers.

"you cant clear our browser history"

— Connected (@LucyIsOpal) March 3, 2024

D) your shell history is boring

— Guy Cole (@guycole) March 3, 2024

I’d have gone for “All your internet history belongs to us”.

— Vanessa Wishart (@VanessaWishart1) March 3, 2024


It's a beautiful Sunday, so let's chat about hacking AWS environments! In this thread, I want to talk about an interesting quirk with Amazon Cognito, demo why least privilege is the most important thing in the cloud, and emphasize that mitigations aren't always enough. A 🧵

— Nick Frichette (@Frichette_n) March 3, 2024

Thread by @Frichette_n on Thread Reader App – Thread Reader App

@Frichette_n: It's a beautiful Sunday, so let's chat about hacking AWS environments! In this thread, I want to talk about an interesting quirk with Amazon Cognito, demo why least privilege is the most important thin...…

As the creator of Cognito, I thought I had seen it all. You sir have created a config more feral than the setup of the aristocrats 🤣. I'm honored that my defenses protected you from yourself for at least a few hours.

— David Behroozi (@rooToTheZ) March 4, 2024


Ouch. ‘…“We know Germany is pretty penetrated by Russian intelligence so it just demonstrates they are neither secure nor reliable,” Ben Wallace, the former defence secretary, said….’ https://t.co/dzhZcXARV4

— Shashank Joshi (@shashj) March 3, 2024

not even sure if Germany has a functioning Counter Intelligence program these days. I doubt it.

— Marius (wishi) (@windsheep_) March 3, 2024

Bellingcat and Der Spiegel. But that’s it.

— thaddeus e. grugq thegrugq@infosec.exchange (@thegrugq) March 4, 2024


One if our primary recommendations to younger people is to immediately, without hesitation, involve yourself in the cybersecurity-ecosystem. It does not matter if it is Twitter, Mastodon, whatever, but it needs to be done.

The reason why is not social networking (although this…

— vx-underground (@vxunderground) March 4, 2024


pic.twitter.com/njbLBdmVxi

— vx-underground (@vxunderground) March 3, 2024


I was at the International Spy Museum in DC earlier today, and they had this CIA bug on display. I was surprised to see something not mentioned in the caption: the chips are Soviet manufactured. I can’t identify the logo on the large chip (К145ИК11П), but I found the datasheet… pic.twitter.com/mufrbvYklq

— Ian Farquhar (@ianbfarquhar) March 3, 2024


cool fucking website elon now u can doxx urself by default. anyway settings>privacy and safety>direct messages>disable calls if u dont want the world to see ur ip https://t.co/vTmlaeUrVZ

— yaoi lesbian (@gatolletaz) March 1, 2024


Do you use a virtual machine to browse dangerous links safely? If you use the Chrome browser inside that virtual machine, is it secure enough?
As you might have guessed, the answer is not so much.

We chained six unique CVEs from 2023 listed below.

• Chrome Renderer RCE :… pic.twitter.com/GuOp18oZd6

— Theori (@theori_io) March 4, 2024

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X