the grugq's newsletter

Subscribe
Archives
May 11, 2025

May 11, 2025

May 11, 2025

‘High levels of trust [in our secret agencies] based on low levels of knowledge’. That’s a fascinating conclusion which will, rightly, command wide attention. Well done.
Will spy chiefs want to keep it that way, & put intel academics out of a job? https://t.co/ZJjwrKRfBo

— Anthony Glees @anthonyglees @anthonyglees.bsky.soc (@AnthonyGlees) May 10, 2025

⁉️ What does the UK public think about GCHQ, MI5, MI6/SIS? Do they trust them?

🆕️ In this new @IntelNatSecJnl article, we study 🇬🇧 public trust and knowledge in detail.

📊 The results make interesting reading. If you're interested, link here ⏬️

🔗 https://t.co/7MGIgf5qwK pic.twitter.com/z2e2sdvDVe

— Dr. Dan Lomas (@Sandbagger_01) May 9, 2025


The Secret History of America’s Involvement in the Ukraine War - The New York Times

This is the untold story of America’s hidden role in Ukrainian military operations against Russia’s invading armies.


Thrilled to announce my new Project Zero blog post is LIVE! 🎉 I detail my knowledge-driven fuzzing process to find sandbox escape vulnerabilities in CoreAudio on MacOS.

I'll talk about this and the exploitation process next week @offensive_con!https://t.co/9Oj2AaxbRk

— Dillon Franke (@dillon_franke) May 9, 2025

I've also open-sourced my fuzzing harness, custom instrumentation, and a PoC for CVE-2024-54529:https://t.co/wPiKHFKG1j

— Dillon Franke (@dillon_franke) May 9, 2025


🔥🔥🔥
CVE-2025-0995)[391907159][$55000][wasm]WasmCode "resurrection" using the WasmImportWrapperCache - > JIT allocation UAF is now open with PoC & exploithttps://t.co/jvQLnZJoBr

Reported by Popax21(Matthias Pleschinger) https://t.co/mpVUljSR58 pic.twitter.com/OjbQJDZ890

— xvonfers (@xvonfers) May 10, 2025


Elizabeth Holmes is advising her husband’s AI medical testing startup, which can “conduct diagnostic tests using a small sample of blood” from prison.

We’re so back. pic.twitter.com/xOV31NKQjs

— Chris Bakke (@ChrisJBakke) May 10, 2025


https://www.baesystems.com/en/digital/feature/responsible-cyber-behaviour


🐊 PentestEverything: A gold-mine repo to find resources, tools, checklists, etc related to different areas in Cyber Security.

Github: https://t.co/sB3zlAQBDC#infosec pic.twitter.com/GgFakO9Agp

— Muqsit 𝕏 (@mqst_) May 9, 2025


it's really fucking hard to find competent engineers.

i've interviewed about 20 cs majors who claim to be experts at python and only 3 of them have been able to explain what the purpose of torch.special.lambertw is (not trolling).

— vik (@vikhyatk) May 10, 2025

How any normal engineer should first encounter Lambert W.

- Be first year math major.

- Stare at this infinite power tower until you find a trick that lets you solve it.

- Apply that same trick to the same equation when the right side is set to 4.

- Realize you accidentally… pic.twitter.com/VmIMnCAf3w

— Jason Wilkes (@dynamic_linker) May 10, 2025


Last year Tijme Gommers walked us through bypassing UAC using the CMSTPLUA COM interface. Dive back into Orangecon and watch the full talk for free on our Youtube. https://t.co/tQC0BbBux8

— OrangeCon (@OrangeCon_nl) May 9, 2025


"Interviews for the post took place last week and the final three candidates were all women — two of them MI6 officers ... Dame Barbara Woodward, who is Britain’s ambassador to the United Nations, is the most senior woman in the Foreign Office".https://t.co/cE3IlRBsjV

— Dr. Dan Lomas (@Sandbagger_01) May 11, 2025


📍 How to: automate session rotation in BurpSuite with mitmproxy

Blog: https://t.co/LfcNeLTd9A

author: @adeadfed pic.twitter.com/A6ObWfQmT9

— Muqsit 𝕏 (@mqst_) May 10, 2025


#SpyNews - week 19 (May 4-10):
A summary of 65 espionage-related stories from week 19 coming from 🇬🇧🇧🇦🇮🇳🇵🇰🇺🇦🇷🇺🇺🇸🇨🇳🇩🇪🇧🇷🇵🇾🇫🇷🇹🇷🇪🇸🇮🇱🇻🇪🇸🇻🇲🇦🇱🇻🇰🇷🇸🇬🇧🇾🇵🇱🇽🇰🇩🇰🇬🇱🇨🇺🇮🇷🇻🇦🇬🇷🇬🇪🇱🇹🇦🇿🇧🇬🇦🇹🇲🇪🇲🇾🇱🇧🇭🇰🇸🇾🇦🇱🇷🇸🇲🇰🇭🇺🇧🇩🇹🇭🇹🇼🇾🇪🇨🇾 https://t.co/nMzHaKVeWR#OSINT #SIGINT #HUMINT #espionage #spy

— Spy Collection (@SpyCollection1) May 11, 2025



Don't miss what's next. Subscribe to the grugq's newsletter:
X