the grugq's newsletter

Subscribe
Archives
November 28, 2023

November 28, 2023

November 28, 2023

This light spot in the middle of the South Pacific is no Google Earth anomaly. This appears exactly at the coordinates where the U.S. aircraft carrier Saratoga sank in 1946. The top of her intact superstructure is a mere 18 meters below the surface. Amazing relics lurk below. 1/8 pic.twitter.com/kHxT1BMqt5

— GEOAvia (@bclemens) November 27, 2023


Local reporter misses gigantic scoop 85 years ago and perhaps saves Britain pic.twitter.com/rEGyrmGmwD

— Patrick Hosking (@HoskingTheTimes) November 26, 2023


Be prepared to lose your kernel pointers! Windows will soon start restricting KASLR leaks to non-admins: https://t.co/n2WoFqU9og

(mentioned this here before but figured it's worth a blog post) pic.twitter.com/QEI5adEh9S

— Yarden Shafir (@yarden_shafir) November 27, 2023


The 16y/o just explained Rust borrowing to me. People, I cannot warn you enough: keep a close eye on what your kids are doing on the Internet.

— Matthew Green (@matthew_d_green) November 28, 2023


“Everything becomes a lot slower,” a nurse at one of the affected New Jersey hospitals told CNN, referring to the reliance on paper, rather than computers, to track things like lab work for patients. “We drill on that a few times a year, but it still sucks.”

— Sean Lyngaas (@snlyngaas) November 27, 2023


If you use https://t.co/rRSMl0rqfp in AWS EKS, be aware of a privesc vector that leads to full cluster compromise. We recommend revoking pod creation permission and switching to domain verification using DNS.

See the update at the end of this blog post: https://t.co/IouTvb4A1Z https://t.co/y4strHRq8m

— Calif (@calif_io) November 27, 2023

Today @futurism reported that Sports Illustrated was publishing articles credited to fake, AI-generated writers. I did a little digging and found connections to AdVon Commerce — the company that was behind the botched Gannett AI reviews in Oct.https://t.co/CGY6YJM9H9

— mia sato 佐藤みあ (@MiaRSato) November 27, 2023

A whimsical journey awaits and you just sitting there fucking tweeting https://t.co/JT6x7wokV4

— Healthy chronicles Vol. 4 (@bighealthyfr) November 26, 2023

Man why Why the fuck is there a train infront of my house pic.twitter.com/1wCvGE0xlQ

— Michal (bonus track) (@cutarded) November 25, 2023


Shrig 🐌: "New Outlook is good, both for yourself and 766 th…" - this godforsaken website

Attached: 1 image New Outlook is good, both for yourself and 766 third parties.


it’s time to create a butter world by eliminating shellfish corporations pic.twitter.com/nMKbfNKFp1

— Uncle Duke (@UncleDuke1969) November 27, 2023


Several Chamilo RCE detailed analysis from our team member, @Creastery
Patches available since September 2023.https://t.co/LQOOByHwUohttps://t.co/EDYbywRxT7https://t.co/AhOzVsQ5VPhttps://t.co/kKKlBGH78Qhttps://t.co/9k6lvCbtuZhttps://t.co/tvoyhKqVkF

— starlabs (@starlabs_sg) November 28, 2023

Oh we missed out 3 more advisories from our member @Creastery https://t.co/8q6GtN7RRVhttps://t.co/gJddaHOQnGhttps://t.co/lCe1VNzqp8 https://t.co/TyavrbwzeZ

— starlabs (@starlabs_sg) November 28, 2023


Skyview

Venture capital killed a 151-year-old magazine that I and so many other people were proud to work for, until, of course, we were all laid off a few weeks ago.


Skyview

Shall I compare thee to a fucking jerk


Skyview

I will never recover from this student email.


“never sell security to folks who don’t care - let the bad guys do it for you”

— cje (@caseyjohnellis) November 28, 2023


BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses https://t.co/Ig50JlUPa5

— Daniele Antonioli (@francozappa) November 27, 2023


Skyview

screw Amazon, this is the true Everything Store


Ch12 received leaked emails fom 8200! Even more details on the intelligence failure. Keep in mind this is but one piece of a big, seemingly dysfunctional, machine.https://t.co/h4IcUlGnWQ

— Steven B. Wagner (@StevenWagner85) November 28, 2023

Thread by @StevenWagner85 on Thread Reader App – Thread Reader App

@StevenWagner85: Ch12 received leaked emails fom 8200! Even more details on the intelligence failure. Keep in mind this is but one piece of a big, seemingly dysfunctional, machine. mobile.mako.co.il/news-military/… ...…


And fair warning to ppl…

If you paste a link to a PDF in iMessage it downloads the document, renders it, creates a preview and then sends:
- the preview
- the PDF
- the link

What the actual fuck? It’s like attack surface maximalism

— thaddeus e. grugq thegrugq@infosec.exchange (@thegrugq) November 27, 2023
Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X