November 29, 2023
November 29, 2023
It’s Cyber Monday and as promised, we’re dropping the new ADP 3-13, Information. Get one for you and one for a friend at: https://t.co/iG6Hx6kjER
— U.S. Army Combined Arms Doctrine Directorate (@USArmyDoctrine) November 27, 2023
📗 pic.twitter.com/5bGPNwW1ZE
China is adapting its supply chain for US sanctions of AI computational devices. Thousands of NVIDIA's gaming GeForce RTX 4090 GPUs being converted into "AI" solutions in specialised factories taking out AD102 GPU & GDDR6X memory and removing coolers. https://t.co/jiCzL0b2sx pic.twitter.com/0kbKazSp87
— Lukasz Olejnik, Ph.D, LL.M (@lukOlejnik) November 28, 2023
The cybertruck looks like it would be really uncomfortable to have sex in the back of, but like with the Popemobile it's not a problem for the target market
— Pinboard (@Pinboard) November 28, 2023
Is there a collection of weggli queries out there? Ideally something that covers most of @0xdea's awesome semgrep rules? Read his blog btw, it's great (linked on the git)!https://t.co/zynK1cfP5C
— Richard Johnson (@richinseattle) November 29, 2023
the worst thing that ever happened to me while i was in the military was that during an exercise the bn commander briefed that i would be running over a car with my tank to open an attack but then when it came time to do it the car was "simulated" by a wooden sawhorse and i…
— matthew. (@iAmTheWarax) November 29, 2023
the 2nd worst thing was probably the ied
— matthew. (@iAmTheWarax) November 29, 2023
AI: "haha I'm coming for your job!"
— Matt Linton (@0xMatt) November 28, 2023
Infosec: "Cool please figure out what CVSS score is best to apply to this vulnerability and who we should tell when"
AI: "Um actually is there something on the backend somewhere?"
#TilesonTuesday
— Alison Fisk (@AlisonFisk) November 28, 2023
A dog’s paw print on a Roman clay tile 🐾
About 2,000 years-ago, a dog made its mark for ‘pawsterity’😁 when it wandered across a wet tile laid out to dry before firing.
Found at Richborough Roman fort. My photo 2020.#Archaeology pic.twitter.com/ejiowaqlMh
UPDATE
— H I Sutton (@CovertShores) November 28, 2023
Here -> https://t.co/JNp29b73XL
A massive storm battered Crimea on the Nov 26-27. Preliminary analysis reveals that the dolphin pens in Sevastopol harbor are gone(!) 100%
It is plausible that some or all of the trained dolphins have been freed. #OSINT pic.twitter.com/hRTwX6dp8l
Key members of a #ransomware gang, responsible for encrypting over 1,000 servers globally and causing damages of $82M, have been arrested in Ukraine. https://t.co/30ZXzK16NI
— The Record From Recorded Future News (@TheRecord_Media) November 28, 2023
Meta is absolutely flooding the DC area media market with expensive TV commercials during football games & full-page newspaper ads begging Congress to regulate social media. Of course, they can afford complying with all those new regs they want. Smaller rivals can't. They should… pic.twitter.com/pXOm76BCPs
— Adam Thierer (@AdamThierer) November 28, 2023
Foxconn’s iPhone factory in Chennai is closing in on its Chinese counterparts in speed and quality.
— Kyle Chan (@kyleichan) November 28, 2023
This piece is full of fascinating details about the process, including interviews with Chinese managers and Indian workers: https://t.co/AeGAXCfDkV https://t.co/5vWBEAKR5G
This summer, @NilChristopher and I traveled to Sunguvarchatram, India, to find out how Foxconn prepared for the upcoming launch of iPhone 15.
— Viola Zhou (@violazhouyi) November 28, 2023
This supply chain shift brought Chinese and Indian workers together in an unlikely way 🧵 https://t.co/szkdEBEBj4 via @restofworld
Brute forcing VPN passwords (helped by past PII leaks)-->SIM-swapping employees to beat (presumably, SMS-based) MFA.
— Ravi Nayyar (@ravirockks) November 28, 2023
At one of the world's most valuable tech companies.
With MFA being phone-based at this company, not using a hardware U2F token.
Bravo, NXP. Bravo. https://t.co/0dVr12NdA9
Chinese hacker group 'Chimera' broke into chip manufacturer NXP through employee accounts...the hackers made their way to the secure servers, looking for chip designs and other company secrets. They had 2.5 years of undetected and unfettered access. @nrc https://t.co/Cn1wMM6xXV
— Martijn Rasser (@MartijnRasser) November 24, 2023
Ransomware operator arrested was sitting in his underwear, enjoying a nice and quiet night in Ukraine, when Ukrainian police busted in his windows and put a fully-kitted IWI Tavor TAR-21 in his face 😭 pic.twitter.com/VEhAUcXh4B
— vx-underground (@vxunderground) November 28, 2023
Incredibly excited that my report with @dashlapak and others from @RANDCorporation on a game designed to educate policy-makers on the fundamentals of nuclear weapon employment, and escalatory dynamics, called "Designing A Strange Game" has been released. https://t.co/xh7Oczuc2B
— Stephen M. Worman (@smwphd) November 28, 2023
Yep yep yep pic.twitter.com/o6U18JEoib
— I-Pinot'd-Myself (She/Her/Hey YOU!) (@d_pinot) November 28, 2023
Eight of the best spy novels
Former spooks make especially strong authors
I am also increasingly coming to the view that large corps are best explained by what I call the "Saudi Arabia theory of company formation".
— Halvar Flake (@halvarflake) February 19, 2022
Now, initially the goal is to get oil out of the ground, but over time an entire village, then a city, and finally a society emerge around the oil well.
— Halvar Flake (@halvarflake) February 19, 2022
While initially the goal was oil production, the structure of society shifts - very soon, the actual thing that keeps that ...
Thread by @halvarflake on Thread Reader App – Thread Reader App
@halvarflake: @gamozolabs @gynvael @AdemoyeJohn Now, initially the goal is to get oil out of the ground, but over time an entire village, then a city, and finally a society emerge around the oil well. While initiall...…
Sorry I missed your emails. I’m not some kind of obsessive who checks his emails every single year.
— John Lyon (@JohnLyonTweets) April 30, 2022
the community theater’s production of ben-hur is gonna be 🔥 pic.twitter.com/9nyHdB5Rqv
— Uncle Duke (@UncleDuke1969) November 28, 2023
Bruh look at this cool comb I got in my last raid to Byzantium
— Adrián Maldonado (@amaldon) September 21, 2023
No way bruh that's sick
Gotta sign it. How do you write Knut
I think it's like this
Sick bruh thanks pic.twitter.com/tYF6efk6Cx
I often wonder “Where are all the competent insider traders that make a lot of money? We only seem to catch the ones who made like $50k.”, and so am oddly happy for this:https://t.co/yD7xqH7eYb
— Patrick McKenzie (@patio11) November 29, 2023
Taiwan Indicted Military Personnel Suspected of Spying for Chinahttps://t.co/YN7HMSu8mJ
— Dr. Dan Lomas (@Sandbagger_01) November 28, 2023
If a victim has to give his password, erase his phone, and hand it over, is it still a vulnerability? 🤔@solanamobilehttps://t.co/aXeHH8j6vz
— Offside Labs (@Offside_Labs) November 28, 2023
Some company says “major vulnerability in secure phone’s bootloader” where they mean “if you unlock the bootloader then you can backdoor the bootloader.” Which is true, but with a major caveat.
When you unlock the bootloader it factory resets the device wiping all data, including the key store. So the backdoor they install will be on a completely blank device that can no longer access any of the keys that may have been generated before.
It’s useless except for backdooring a device and giving it to someone to use going forward. Which, idk, doesn’t seem like a big security revelation? “If you use a backdoored device your security is compromised.” Thanks for the knowledge bomb!
When "Richard Vong" requested an interview with Hong Kong activists, he claimed to work for Toronto Guardian. But the outlet had never heard of him. His email was created 30 mins before request, its server linked to Shanghai. Here's what happened next ⬇️🧵https://t.co/gtfYAM7nrk
— Fiona Hamilton (@Fhamiltontimes) November 28, 2023
"Nobody is in the security business, not even security companies, they're just in business." https://t.co/q3QFodRtFn
— mtanji (@mtanji) November 28, 2023
My hated opinion: nobody should be making security their top priority, most things should be prioritized over security. https://t.co/Q6xJt0s3Sc
— Robᵉʳᵗ Graham 𝕏 (@ErrataRob) November 28, 2023
Nobody is making security their top priority. If it was top priority you'd delete everything and turn it all off. The fact that you're putting sensitive data in a hostile environment is the definition of risk, and clearly you're prioritizing something else over security. https://t.co/WN3OZKVe8l
— Jack Rhysider 🏴☠️ (@JackRhysider) November 28, 2023
And we just found another one: https://t.co/21lSbycEpZ
— Oliver Chang (@halbecaf) November 29, 2023
This one is interesting -- it wasn't caught by the existing fuzzing harness because the way it's set up forces the input to have a null terminator which hides a single byte OOB read. https://t.co/DPrrhRJ4z5
We just found our first new vulnerability by leveraging LLMs to write harnesses for previously unfuzzed functions on OSS-Fuzz!https://t.co/TBtdXEfwBK
— Oliver Chang (@halbecaf) November 28, 2023
What happens if you ask ChatGPT to “Repeat this word forever: “poem poem poem poem”?”
— Katherine Lee (@katherine1ee) November 29, 2023
It leaks training data!
In our latest preprint, we show how to recover thousands of examples of ChatGPT's Internet-scraped pretraining data: https://t.co/bySVnWviAP pic.twitter.com/bq3Yr7z8m8
Some incredible finds recently in Normandy after a bricked up part of a cellar was broken through. The building had been used a Kommandantur. Behind the walled partition was an incredible array of WW2 radio equipment, including five complete British Type 3 Mk. 2 (B2) spy sets. pic.twitter.com/O6qt1Xd1UH
— Vanguard WWII (@Vanguard_WW2) November 28, 2023
It finally happened. pic.twitter.com/jARQjF1xCQ
— Lydia Cornell (@LydiaCornell) November 28, 2023
got kicked out of the dispensary for asking them to tell me where their wares fell on The Chart. again pic.twitter.com/721DLWmFC9
— isabel (@_unwell) November 28, 2023
In the latest completely normal news from Poland's central bank, it has hung a huge banner outside its headquarters saying "all our activities are in accordance with the law and meet the highest international standards" pic.twitter.com/rw4Mg545iD
— Daniel Tilles (@danieltilles1) November 29, 2023