the grugq's newsletter

Subscribe
Archives
May 22, 2025

May 22, 2025

May 22, 2025

This is a wild story.

SCOOP: In Feb, federal agencies "lost" many #FOIA requests but you probably had no idea. It turns out that the FOIAs disappeared due to an "insider threat attack" by 2 employees at a software company who were previously convicted of hacking into the State Dept

🧵

🎁…

— Jason Leopold (@JasonLeopold) May 21, 2025

Thread by @JasonLeopold on Thread Reader App – Thread Reader App

@JasonLeopold: SCOOP: In Feb, federal agencies "lost" many #FOIA requests but you probably had no idea. It turns out that the FOIAs disappeared due to an "insider threat attack" by 2 employees at a software company...…


After some refinement and wrestling with Chrome's / Edge's quirky ABE COM setup for my decryption project, I knew I needed a better way! Hence why I built COMrade ABE. A tool to dynamically analyze Chromium ABE interfaces. It finds the CLSIDs, IIDs, method layouts & generates C++… pic.twitter.com/pHidwooz7e

— Alex (@xaitax) May 21, 2025


excited to finally share on arxiv what we've known for a while now:

All Embedding Models Learn The Same Thing

embeddings from different models are SO similar that we can map between them based on structure alone. without *any* paired data

feels like magic, but it's real:🧵 https://t.co/Cwj1LytGos

— jack morris (@jxmnop) May 21, 2025

and practically, this is bad for vector databases. this means that even if you fine-tune your own model, and keep the model secret, someone with access to embeddings alone can decode their text

embedding inversion without model access 😬 pic.twitter.com/JBWvheEyB3

— jack morris (@jxmnop) May 21, 2025

Thread

Thread by @jxmnop on Thread Reader App – Thread Reader App

@jxmnop: excited to finally share on arxiv what we've known for a while now: All Embedding Models Learn The Same Thing embeddings from different models are SO similar that we can map between them based on structure...…

I’m stoked to share our new paper: “Harnessing the Universal Geometry of Embeddings” with @jxmnop, Collin Zhang, and @shmatikov.

We present the first method to translate text embeddings across different spaces without any paired data or encoders.

Here's why we're excited: 🧵👇🏾 pic.twitter.com/FtQ7sYpWnV

— Rishi Jha (@rishi_d_jha) May 21, 2025

Thread

Thread by @rishi_d_jha on Thread Reader App – Thread Reader App

@rishi_d_jha: I’m stoked to share our new paper: “Harnessing the Universal Geometry of Embeddings” with @jxmnop, Collin Zhang, and @shmatikov. We present the first method to translate text embeddings across differen...…

Paper

[2505.12540] Harnessing the Universal Geometry of Embeddings

We introduce the first method for translating text embeddings from one vector space to another without any paired data, encoders, or predefined sets of matches. Our unsupervised approach translates any embedding to and from a universal latent representation (i.e., a universal semantic structure conjectured by the Platonic Representation Hypothesis). Our translations achieve high cosine similarity across model pairs with different architectures, parameter counts, and training datasets. The abil...


The Spy Factory

Russia’s intelligence services turned Brazil into an assembly line for deep-cover operatives. A team of federal agents from the South American country has been quietly dismantling it.

https://archive.is/fLPI7


Oh good apparently now the Coinbase breach happened on Dec 26, 2024.

LOL

So since Coinbase won't be straight with you, I will.

Threat actors had ongoing access via multiple insiders over a prolonged period of time.https://t.co/AQotFi07KX pic.twitter.com/a0EhiMqIKN

— Tay 💖 (@tayvano_) May 21, 2025


A 🇨🇳 intelligence ring, which was active for the past 5 years, has been shattered in Turkey. Its operatives eavesdropped on Uyghurs and Turkish officials using IMSI-catchers, which function as fake base stations to collect data, phone logs, conversations and other information… pic.twitter.com/8EgRkjTR0D

— Byron Wan (@Byron_Wan) May 21, 2025


Decibels are ridiculous

Decibels are ridiculous - lcamtuf’s thing

Celebrating a rare dumpster fire in the kingdom of science.


http://www.incompleteideas.net/IncIdeas/BitterLesson.html


Because I continue to see developers make this mistake:

Human nature being what it is, the most important rule of construction management is always to owe your contractor money & never to allow him to owe you work.

Everything else, as the rabbis say, is commentary.

— Moses Kagan (@moseskagan) May 20, 2025


🚨Today, we have issued an advisory exposing Russia’s military intelligence service for a campaign of malicious cyber activity against Western logistics and technology firms, including those involved in delivering support to Ukraine⬇️https://t.co/rNf9dwlRLo

— NCSC UK (@NCSC) May 21, 2025


Hmmm, @FBI got access to #LummaC2 panel and the private chat?! 👀🕊️ pic.twitter.com/QIaiPKNChO

— RussianPanda 🐼 🇺🇦 (@RussianPanda9xx) May 21, 2025

Don't miss what's next. Subscribe to the grugq's newsletter:
X