the grugq's newsletter

Subscribe
Archives
November 16, 2024

November 16, 2024

November 16, 2024

@martu.bsky.social on Bluesky

Death threats, phishing emails, leaks and mobile malware—Iranian intelligence has heavily targeted Israeli athletes during this summer's Olympics in Paris. French intelligence has attributed this activity to the well-known Iranian contractor Emmenet Pasargad, according to @mediapart.fr https://www.mediapart.fr/journal/france/141124/selon-la-dgsi-l-iran-cible-les-athletes-israeliens-durant-les-jeux-olympiques?at_medium=rs-cm&at_campaign=bluesky


CVEs patch diffing to track down vulnerabilities in firmwareshttps://t.co/mOMWazUL3Q

Credits @suidpit and @Th3Zer0#embedded #cybersecurity pic.twitter.com/BOa7xMK0hK

— 0xor0ne (@0xor0ne) November 14, 2024


Thinkst Q3 security research summary

Thinkst

Keeping up with security research is near impossible. ThinkstScapes helps with this. We scour through thousands of blog posts, tweets and conference proceedings to give you an overview of the work we think significantly moves the needle.


Excited to share our latest post on memory safety! We're tackling spatial safety in our massive C++ codebase by hardening libc++ *by default*. It adds bounds checks to things like std::vector, preventing a fair bit of out-of-bounds vulnerabilities: https://t.co/Dek3jJaTxn

— Alex Rebert (@ayper) November 15, 2024


New:
Hours after Trump won, ICE asked companies to submit plans for how they’d expand ICE’s system of GPS trackers + databases surveilling “noncitizens” awaiting trial or deportation.

Gov contractors said ICE’s timing was probably not a coincidence:https://t.co/rDKvLxN0eA

— Caroline Haskins (@car0linehaskins) November 13, 2024


Our first vmware escape! Very luck to found a bug and finished the exploitation within 3 months. pic.twitter.com/1mzFUsI94M

— kangel (@J_kangel) November 15, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X