the grugq's newsletter

Subscribe
Archives
November 24, 2024

November 24, 2024

November 24, 2024

#SpyNews - week 47 (November 17-23):
A summary of 77 espionage-related stories from week 47 coming from ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ธ๐Ÿ‡ฌ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡ซ๐Ÿ‡ฎ๐Ÿ‡ซ๐Ÿ‡ท๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡ธ๐Ÿ‡พ๐Ÿ‡ฆ๐Ÿ‡ท๐Ÿ‡ณ๐Ÿ‡ฟ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡จ๐Ÿ‡ญ๐Ÿ‡ฑ๐Ÿ‡น๐Ÿ‡ธ๐Ÿ‡ช๐Ÿ‡ฎ๐Ÿ‡ท๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡ฐ๐Ÿ‡ต๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡ต๐Ÿ‡ธ๐Ÿ‡ช๐Ÿ‡ธ๐Ÿ‡ต๐Ÿ‡ญ๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡ต๐Ÿ‡ฑ๐Ÿ‡ฉ๐Ÿ‡ฐ๐Ÿ‡ณ๐Ÿ‡ฑ๐Ÿ‡ฎ๐Ÿ‡ถ๐Ÿ‡ฑ๐Ÿ‡ง๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡น๐Ÿ‡ฏ๐Ÿ‡ฐ๐Ÿ‡ฌ๐Ÿ‡น๐Ÿ‡ฒ๐Ÿ‡ฐ๐Ÿ‡ฟ๐Ÿ‡ณ๐Ÿ‡ด๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡ต๐Ÿ‡ฆ๐Ÿ‡ฉ๐Ÿ‡ฟ๐Ÿ‡ฆ๐Ÿ‡ซ๐Ÿ‡ง๐Ÿ‡พ๐Ÿ‡ฆ๐Ÿ‡ฒ๐Ÿ‡ฑ๐Ÿ‡พ๐Ÿ‡ธ๐Ÿ‡ธ https://t.co/EZtvj2Yuwo#OSINT #HUMINT #SIGINT #espionage #spy

โ€” Spy Collection (@SpyCollection1) November 24, 2024

SPY NEWS: 2024 โ€” Week 47. Summary of the espionage-related newsโ€ฆ | by The Spy Collection | Nov, 2024 | Medium

Summary of the espionage-related news stories for the Week 47 (November 17โ€“23) of 2024.


AV/EDR Lab environment setup references to help in Malware development https://t.co/lUeAefxgJW

โ€” Panos Gkatziroulis ๐Ÿฆ„ (@netbiosX) November 23, 2024

Cool to see that the same techniques still work after twenty years.https://t.co/UTjSvs1rQZ https://t.co/YQd5tmw2Pc

โ€” thaddeus e. grugq (@thegrugq) November 24, 2024

Spoofing Call Stacks To Confuse EDRs | WithSecureโ„ข Labs

Call stacks are an understated yet often important source of telemetry for EDR products.

Everything old is new again.

https://phrack.org/issues/62/5.html#article

perfect infosec aphorism

Old tricks with new dogs ๐Ÿ•

โ€” Christopher Burgess (@burgessct) November 24, 2024


Introduction to Windows kernel exploitation

Part 1: https://t.co/nNTKqtgmA4
Part 2: https://t.co/QwbNVNNyt2
Part 3: https://t.co/f1hRv93yrB
Part 4: https://t.co/vS1SUVUF0c
Part 5: https://t.co/2aDetUK8g1#infosec #windows pic.twitter.com/JBZzC5BOHn

โ€” 0xor0ne (@0xor0ne) November 24, 2024


"He is also expected to single-out Russia's Unit 29155, which the government says has carried out a number of attacks in the UK and Europe".https://t.co/y6pIC5MR6m

โ€” Dr. Dan Lomas (@Sandbagger_01) November 24, 2024

Alternate take:

UK minister warns that Russia may increase cyberattacks on the UK. The minister spreads fear about cyberattacks turning off electricity and highlights largely symbolic hacktivist activities with no impact, perhaps except propaganda. https://t.co/55K7SusyEJ

โ€” Lukasz Olejnik (@lukOlejnik) November 23, 2024


@shashj.bsky.social on Bluesky

Donโ€™t know which department pre-briefed this speech by Pat Macfadden but top lines are back to old days of cyber hysteria, crossing the line from encouraging preparedness to doing Russiaโ€™s job for it by painting UK power grid and CNI as defenceless. https://www.telegraph.co.uk/politics/2024/11/23/putin-ready-to-cripple-britain-in-cyber-war/

Iโ€™m officially spending a bit more time on Bluesky now, since there seems to be a community forming up.


@filippo.abyssdomain.expert on Bluesky

Optimist: The cup is half full Pessimist: The cup is half empty Cryptography Engineer: The cup matches the test vectors in the specification [contains quote post or other embedded content]

(This is mostly an experiment to see how Bluesky nested quotes are treated)


Seems like there's some focus on static binary instrumentation for kernel again recently. Therefore I decide to public my toy for fuzzing Windows kernel drivers with coverage. Wrote this last year and it works for MS released drivers on Windows 11.https://t.co/g9Onnz5e2P

โ€” chiefpie (@cplearns2h4ck) November 23, 2024

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X