the grugq's newsletter

Subscribe
Archives
November 14, 2023

November 14, 2023

November 14, 2023

where does a man even go to buy an outfit like this? does canada have a store for hotel concierges who do closeup magic? did someone start designing a joker outfit and died 60% of the way through? is he a prison guard at a prison that's just for clowns? fascinating pic.twitter.com/uJMkOPXkX5

— america's lounge singer (@KrangTNelson) November 13, 2023

Google/Chrome is deprecating and removing third-party cookies. So it has begun. End of the line for 3rd-party cookies is near. You will not be missed. #GDPR #DigitalServicesAct #privacy #dataprotection https://t.co/0VXSwRCZ6j https://t.co/0VXSwRCZ6j https://t.co/VXgepZatku pic.twitter.com/JsrrdysuzE

— Lukasz Olejnik, Ph.D, LL.M (@lukOlejnik) November 13, 2023

User tracking on the web will be increasingly phased out. It will also be made more unwelcome, and illegal, than it is today. The political process to arrive there is in motion. Some technology companies feel this evolution and are preparing for this. https://t.co/AlLqsf7rTs

— Lukasz Olejnik, Ph.D, LL.M (@lukOlejnik) November 8, 2023



Hacking Google Bard - From Prompt Injection to Data Exfiltration · Embrace The Red

Google Bard allowed an adversary to inject instructions via documents and exfiltrate the chat history by injecting a markdown image tag.


🇦🇫 #Afghanistan: Footage has emerged showing what appears to be Taliban security forces patrolling the streets of Kabul on rollerblades. pic.twitter.com/QYnlkVHKjK

— POPULAR FRONT (@PopularFront_) November 14, 2023

PhreakByte: "Thank you everyone who attended my session “Bypas…" - Infosec Exchange

Attached: 1 image Thank you everyone who attended my session “Bypassing Windows Defender for Endpoints Device Isolation” at BSides København . Many good questions, and hopefully they all got answered

Slides here:

https://sec1.dk/blog/BypassingDefenderforEndpointdeviceisolation.pdf


Our team members have spotted another fake account imposing as our team member.
This is the fake account:https://t.co/djZSgc7SeE

This one belongs to our team member.https://t.co/6UeyOfZuCe

— starlabs (@starlabs_sg) November 14, 2023


Thanks to @bindinghook for letting me share some additional thoughts about Sandworm's latest attack method and what it means for our broader policy conversation related to cyber conflict.https://t.co/CA8Mn4deec

— Dan Black (@DanWBlack) November 14, 2023


Introducing RFCGPT: the virtual assistant that has read the entire RFC series. Ask it anything about internet protocols and standardization!https://t.co/ayBAJzRCzB

This tool is built on OpenAI’s new “My GPT” feature and is available to all ChatGPT Plus customers. Note that…

— Nick Sullivan (@grittygrease) November 13, 2023

This is sweet as. Playing with it has made me smile

Nicely done https://t.co/noJxJaxriE pic.twitter.com/7THAZmQ9Dy

— Daniel Cuthbert (@dcuthbert) November 14, 2023


i once worked at a company with bad glassdoor reviews so the CEO made us all go on glassdoor & write good reviews

— Rona Wang (@ronawang) November 13, 2023

I heard of a guy who was fired from a company and had a grudge

So he wrote fake Glassdoor reviews that were unrealistically POSITIVE

Overly high salaries, absurd benefits, fancy perks

They had trouble hiring for YEARS because candidates thought they were being lowballed! https://t.co/9jBxqRfVJt

— Daniel Feldman (@d_feldman) November 14, 2023


#Ubuntu Privilege Escalation bash one-liner using CVE-2023-32629 & CVE-2023-2640https://t.co/q2kisqzeWb

Nifty #PoC!https://t.co/to1G6PGc94

— raptor@infosec.exchange (@0xdea) November 14, 2023

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X