the grugq's newsletter

Subscribe
Archives
May 25, 2023

May 25, 2023

May 25, 2023

Between Two Nerds

Cyber pinch points 37b


SFPD Obtained Live Access to Business Camera Network in Anticipation of Tyre Nichols Protest | Electronic Frontier Foundation

New documents EFF received through public records requests have revealed that the San Francisco Police Department (SFPD) received live access to the hundreds of surveillance cameras that comprise the Union Square Business Improvement District’s (USBID) camera network in anticipation of potential...


WTF is wrong with the EU? They’ve been on a roll of dumb ideas recently.

European Commission Calls for Pirate Site Blocking Around the Globe * TorrentFreak

The European Commission has published its biannual list of foreign countries with problematic copyright policies.


"Spy whale" #Hvaldimir is backhttps://t.co/KEiqQQQDfq

— Nordic News (@Nordic_News) May 24, 2023

Ok, let’s get this cleared up. It’s a case officer whale, not a spy. They recruit spy whales! Ugh, 🙄

The Strange Story of the Teens Behind the Mirai Botnet - IEEE Spectrum

PRC cyber threats to critical infrastructure are real and use sophisticated tradecraft that doesn't always rely on malware. This advisory describes tradecraft for hunting their intrusions and detecting this activity. We want to hear about discoveries. https://t.co/zjBtg7vbds pic.twitter.com/5TyIVMwX3s

— Rob Joyce (@NSA_CSDirector) May 24, 2023

John Scott-Railton, a researcher at Citizen Lab, says it was “inevitable” Pegasus would turn up in an international armed conflict. “Every country that has had negotiators and diplomatic staff involved in talks and negotiations on this issue would be wise to check themselves,” he adds.

This is absolutely despicable. Spying on negotiators and diplomats during negotiations?!? This is the sort of vile behaviour I’d expect from Australia or the US, but not Azerbaijan!

Imagine if anyone could just spy on their counterparts and find out what they’re doing? It would be chaos! Gentlemen do not read their counterparty’s private emails.

The very idea of spying during a war. I’m disgusted, absolutely disgusted. Things are bad enough with the conflict and now there’s spying too?? Is nothing sacred??

Joint investigation by @accessnow, @AmnestyTech, @citizenlab and others uncovers hacking of civil society victims in Armenia with NSO’s sophisticated Pegasus spyware. https://t.co/jLdFTN7Q5M

— Runa Sandvik (@runasand) May 25, 2023

NEW - For the first time, NSO's Pegasus iPhone spyware has been seen in a warzone, researchers say.

One victim was hacked "at least 27 times between October 2020 and July 2021, with infections happening almost every single month."

Wild.https://t.co/i784iQH1ig

— Thomas Brewster (@iblametom) May 25, 2023

https://twitter.com/dalperovitch/status/1661684741618188288

Of course that’s your contention. You’re a first-year threat intel analyst.

You’ve just read up on the MITRE ATT&CK framework and are convinced every problem is solve-able with a T-code https://t.co/vcdpo6mGh3

— Greg Lesnewich (@greglesnewich) May 24, 2023

There are certain phrases that will never cease to be alarming, and "kit-built DIY supersonic aircraft" ticks most of the requisite boxes. pic.twitter.com/D6374FYo3Y

— Dreadnought Holiday (@TheDreadShips) September 8, 2019

Like I'm going to trust AI with the future of humanity when it keeps putting my important emails in spam

— Karl Sharro (@KarlreMarks) May 25, 2023

I've said this privately a few times, but think it bears repeating in public:

There are folks with a vested interest in making you think that ML is literal magic that it takes six PhDs and a 580 IQ to understand. This is bullshit, especially when it comes to ML security.

— Rich Harang (@rharang) May 24, 2023

This is Huge. A UCLA student may have just found the first feasible Indistinguishability Obfuscation (iO) scheme, based on well-understood cryptographic theories.

In other words, imagine an obfuscator/packer that is nearly as difficult to crack as AES.

The research validates… pic.twitter.com/K7HvI56uOJ

— LaurieWired (@lauriewired) May 25, 2023

https://escholarship.org/content/qt7vq3z6v1/qt7vq3z6v1_noSplash_11cf93c4e513781acd1abae3cbe4e90d.pdf


Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X