the grugq's newsletter

Archives
November 10, 2024

November 10, 2024

November 10, 2024

Sorry about November 9th’s newsletter. I’ve raised the issue with Buttondown support and hopefully they’ll fix it.


I got out of my Waymo to ask someone to take this pic, and the fking waymo drove off with everything I own in the car.

Bros… it might be so over pic.twitter.com/4THmvOJmrE

— noah 🐔 (@noahgsolomon) November 8, 2024

MacBook Air M2, Remarkable 2 Pro, Theragun, Herschel backpack, Hydroflask with Fire whop stickers, Cold brew coffee

ALL STOLEN BY A ROBOT

— noah 🐔 (@noahgsolomon) November 8, 2024


TIL: The rationale for why Google Sheets didn’t clone more of Microsoft Excel (and appeal to more hardcore finance users). pic.twitter.com/RTnS0wMmrv

— Trung Phan (@TrungTPhan) November 8, 2024


Did you know you can lock out ALL domain users (including Domain Admins!) by exceeding the Kerberos MaxTokenSize limit?

There are a few ways to do that.

I'll add links to the blogpost and #github repo in the comments .@penterasec #redteam #activedirectory pic.twitter.com/1tUAEiQkXK

— Nir Chako (@C_h4ck_0) November 9, 2024

https://pentera.io/blog/dos-attack-active-directory-sid-exploitation/


https://t.co/mPEHWRagcs
TL;DR I Implemented a super reliable macOS kernel binary rewriting to instrument any KEXT or XNU at BB or edge level.

— Meysam (@R00tkitSMM) November 8, 2024


Japan just launched a wooden (yes made of wood) satellite called LignoSat.

It is the world's first wooden satellite and I t'll stay in orbit for six months in an attempt to prove wood is a space-grade material.pic.twitter.com/9Lu5buCrvZ

— Brian Roemmele (@BrianRoemmele) November 8, 2024


> be new to cybersecurity
> google cybersecurity discords
> @bishopfox listed
> click to join their discord
> discord requires verification (image 1)
> verification site has tons of pop ups (image 2)
> massive pop up saying need to install thing
> annoying page appears
> lady… pic.twitter.com/IvCcVrOn6v

— vx-underground (@vxunderground) November 9, 2024


My Flare-On 11 writeups are now public, check them out! These are all very rough drafts, I will be polishing them more as I have more time to work on them, along with the videos of the solves pic.twitter.com/1rDOUCwjPU

— cts🌸🏳️‍⚧️ (@gf_256) November 10, 2024
Don't miss what's next. Subscribe to the grugq's newsletter:

Add a comment:

Share this email:
Share on Twitter Share on Hacker News Share via email Share on Mastodon Share on Bluesky
Twitter