the grugq's newsletter

Subscribe
Archives
May 16, 2024

May 16, 2024

May 16, 2024

Linux maintainers were infected for 2 years by SSH-dwelling backdoor with huge reach | Ars Technica

Ebury backdoors SSH servers in hosting providers, giving the malware extraordinary reach.


https://www.villagevoice.com/littlejohn-the-mob-saga-of-a-heist/


The slides and demo of my talk "Decrypting Crypto PoS" https://t.co/V22MKSBiec

— Guanxing (@hhj4ck) May 16, 2024


‼️ THIS!

The methods used by Russian propaganda described by a Russian journalist:

“I studied at the Faculty of Journalism of Moscow State University. We had a military department. In an atmosphere of secrecy, we were taught special combat propaganda - the art of sowing discord… pic.twitter.com/OOwxunE2dC

— Natalka (@NatalkaKyiv) May 15, 2024

Instead of proving something, you submit what you want to convince the audience of as something obvious, taken for granted, and therefore unconditionally supported by the overwhelming majority of the population.

Despite its seeming simplicity, this method is incredibly…

— Natalka (@NatalkaKyiv) May 15, 2024


#ESETresearch has discovered the Lunar toolset, two previously unknown backdoors (which we named #LunarWeb and #LunarMail) possibly linked to Turla, compromising a European MFA and its diplomatic missions abroad. https://t.co/VnCsGTidwr 1/6

— ESET Research (@ESETresearch) May 15, 2024


1980: We will de-industrialize our society and export our manufacturing industry to China in exchange for cheap products and vast shareholder profits

40 Years Later: Ah fuck,

— Rob (@robrousseau) May 15, 2024


💡Twint💡An advanced Twitter scraping & #OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations.👇#DarkWeb #Cybersecurity #Security #Cyberattack #Cybercrime #Privacy… pic.twitter.com/kJXMbh3rpt

— Dark Web Informer (@DarkWebInformer) May 15, 2024


C’mon Apple, iOS kernel vulnerability is not eligible for bounty? What would then be?
It could have been ended up in @DonnchaC or @jsrailton blogs. 🤦‍♂️ https://t.co/yJG7dw3pEe pic.twitter.com/TtDDq2OaxB

— Meysam (@R00tkitSMM) May 14, 2024

I reported CVE-2024-27804, an iOS/macOS kernel vulnerability that leads to the execution of arbitrary code with kernel privileges.
Will publish the POC soon.https://t.co/12r1PxZfpT

— Meysam (@R00tkitSMM) May 13, 2024


Someone is having a bad week losing months of work lol

Meanwhile, I'm getting Chrome updates as frequent as Windows asking I'm sure not want to read weather & news on my desktop.

And yes, there's a zero-day patched in Chrome today so you must patch asap.https://t.co/1lu7TUX8zM

— Haifei Li (@HaifeiLi) May 15, 2024

Press those update buttons folks. pic.twitter.com/qDnw2Uos86

— Matt Johansen (@mattjay) May 15, 2024


Cool #decompilation wiki: https://t.co/Xsm7KBIVaW #reversing

— ringzerø.training && @ringzer0@infosec.exchange (@_ringzer0) May 16, 2024


Today has been a whirling wind of chaos.

tl;dr we don't know anything. We need solid proof.

First, earlier this morning the current owner of Doxbin, Operator, was allegedly beaten and kidnapped. Footage released by the would-be kidnappers shows, presumably Operator, tied to a…

— vx-underground (@vxunderground) May 15, 2024


If you use Apple devices and iCloud, today would be a great day to turn on Advanced Data Protection and enable end-to-end encryption for all your backups. https://t.co/fl8xjaBZwm

— Matthew Green (@matthew_d_green) May 15, 2024


NEW: #Poland is making an about-face on spyware.

From gaslighting victims and researchers about abuses ...to push for accountability.

I spoke with @timstarks w/@davidakaye @natynettle and @KrzysztofBrejza on this surprising and welcome development.https://t.co/640kwEB8yq pic.twitter.com/AuZniZ1vnc

— John Scott-Railton (@jsrailton) May 15, 2024


2020: Microsoft sets goal to be carbon negative by end of the decade.

2023: Microsoft's emissions are 30% higher than in 2020.

Main cause? The relentless push to meet AI demand, which requires carbon-intensive steel, cement, chips.

Story with @dinabass: https://t.co/TP8e9BPvNL pic.twitter.com/w6kglcwFkJ

— Akshat Rathi (@AkshatRathi) May 15, 2024


Martin Kleppmann: "Our university deployed a mail filter that rewrit…" - Nondeterministic Computer

Our university deployed a mail filter that rewrites URLs in emails to redirect them via a service that checks for bad websites. Somebody clever worked out that PGP-signed emails are exempt from the rewrite rule, so now people are starting their emails with "BEGIN PGP MESSAGE" even though they haven't used PGP at all, just to fool the filter 😂 Anybody sending malware links has probably also worked out that trick by now, thereby rendering the entire filter pointless

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X