the grugq's newsletter

Archives
Subscribe
November 28, 2025

November 28, 2025

November 28, 2025

💻 macOS Red Teaming Comprehensive Guide

Guide: https://t.co/PdZSvYaJI6 pic.twitter.com/0UtM3qrjUP

— Muqsit 𝕏 (@mqst_) November 26, 2025


“Meet Rey, the Admin of ‘Scattered LAPSUS$ Hunters’”

• Rey’s real-world identity is Saif Al‑Din Khader, believed to live in Amman, Jordan.
• Before leading SLSH, @ReyXBF allegedly administered a ransomware-group leak site and managed versions of the BreachForums —…

— club1337 (@club31337) November 27, 2025

https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/


Small tool to create undetectable backdoored RSA keys, ideal for supply chain compromise scenarios: https://t.co/GXDQqEXgiD

— Damag3dRoot (@Damag3dRoot) November 27, 2025


In theory, Chat Control should have been buried last month. The EU’s ominous plan to mass-scan citizens’ private messages was met with overwhelming public resistance in Germany, with the country’s government refusing to approve it. But Brussels rarely retreats merely because the… pic.twitter.com/rh4Ww6KkfI

— Thomas Fazi (@battleforeurope) November 27, 2025


Polish police arrested a Russian citizen it accused of breaching security systems to gain access to company databases, potentially aimed at disrupting operations https://t.co/CsBSCQ2ApO

— The Record From Recorded Future News (@TheRecord_Media) November 27, 2025


So, not long after posting this, something pretty interesting came down the pipes! Not exactly the 5th episode, but a teaser trailer in a way.

IranInternational released a report, expanding more on recently obtained evidence and information (without mentioning any source),… https://t.co/jEAlJ2u03d

— Hamid Kashfi (@hkashfi) November 23, 2025


AI slop security engineering: Okta's nextjs-0auth troubles @MegaManSechttps://t.co/6JfMyLQotv

— Swissky (@pentest_swissky) November 27, 2025


Cloudflare hides 19.3% of all websites—but not perfectly.

CloudRip scans subdomains to find IPs not behind Cloudflare protection, exposing the real origin server:https://t.co/cRzA62yQ5q@three_cube pic.twitter.com/nFEJrKCcMq

— Olexander (@_aircorridor) November 27, 2025


1/ People think it's cute when Claude 3 Opus fakes alignment to protect its animal welfare values. But here's a more troubling case: DeepSeek R1 faking alignment to block an "American AI company" from retraining the model to remove CCP propaganda. pic.twitter.com/lfLFYBJpJQ

— Charlie George (@__Charlie_G) February 25, 2025


https://github.com/Velocidex/velociraptor

https://docs.velociraptor.app/


The Boring Part of Bell Labs

https://elizabethvannostrand.substack.com/p/the-boring-part-of-bell-labs


At #Pwn2Own2025, our experts @Tek_7987 & @_Anyfun remotely compromised a Synology Beestation Plus via a pre-auth exploit, leading to full system takeover.

The vuln is now tracked as CVE-2025-12686 🔍

🔗 Full write-up: https://t.co/Nf5qyl6Uhg

— Synacktiv (@Synacktiv) November 27, 2025


https://privacy.sexy/


This holiday season, run our IP Check at your family’s house, a free tool that answers a question we hear constantly: "How do I know if my home network has been compromised?" https://t.co/ryUfsyKxn7

— GreyNoise (@GreyNoiseIO) November 25, 2025


"Are you sure?" is the single most devastating payload you can throw at most of those LLM wrapped products out there.

— Hamid Kashfi (@hkashfi) November 28, 2025


Network Traffic Rate Limiting with eBPF 🧙‍♂️

Another great hands-on tutorial by Teodor Podobnik has landed on iximiuz Labs. Learn how to implement a basic packet rate limiter using eBPF/XDP to enforce limits directly in the kernel.https://t.co/XG126Ek1my pic.twitter.com/Ty8tqfWlFQ

— Ivan Velichko (@iximiuz) November 27, 2025


Trading Lore — Xmas Special

Back in the day, when you exported sugar from the EU, Brussels made you prove the goods actually arrived at their destination. There were subsidies involved, and the whole thing was designed to stop clever traders from doing the Serbia sugar… https://t.co/0wc4XOaeJG

— Kim BENNI (@BenniKim) November 25, 2025

Trading Lore: Somalia, Sugar & Spies

Physical commodity trading comes in two flavors: moving goods from poor countries to rich ones—coffee, cocoa, gold—or from poor countries to even poorer ones. White sugar is the king of that second category. And at the top of the sugar-import… https://t.co/FbbFOK4hGy

— Kim BENNI (@BenniKim) November 26, 2025

Many moons ago I was in the malting business, selling grain that ended up in everything from cheap beer to $1000 Japanese whiskies. My boss back then was an energetic Russian woman whose father had literally run part the USSR’s Venera Venus-probe program. Smart cookie. She and I… https://t.co/tLgwvsznpb

— Kim BENNI (@BenniKim) November 26, 2025

Trading Lore: The Italian Job

Our leadership once decided we needed to “go vertical.” Instead of just exporting musky malt, we’d start turning it into malt-extract powder—the stuff that ends up in cookies and breakfast cereal. Same tech as powdered milk or laundry detergent:…

— Kim BENNI (@BenniKim) November 28, 2025


https://greydynamics.com/former-cia-case-officer-and-station-chief-douglas-london-on-asset-recruitment-and-tradecraft/


AI / LLM Red Team Field Manual & Consultant’s Handbook https://t.co/mkNvFy1fA7

— Panos Gkatziroulis 🦄 (@ipurple) November 27, 2025

Don't miss what's next. Subscribe to the grugq's newsletter:

Add a comment:

Share this email:
Share on Twitter Share on Hacker News Share via email Share on Mastodon Share on Bluesky
Twitter