the grugq's newsletter

Subscribe
Archives
October 12, 2025

October 12, 2025

October 12, 2025

Christopher Berry, one of the suspects in the China spy case, allegedly had secure communication apps used only by Beijing agents installed on ‘burner phones’.

The suspicious apps, which are not available to the Chinese public, were allegedly found on Berry’s mobiles after he… https://t.co/bUbdxfseS5 pic.twitter.com/hZRNqR5vQE

— Byron Wan (@Byron_Wan) October 12, 2025

The White House has warned Sir Keir Starmer that the failure to prosecute two alleged Chinese spies — Chris Cash and Christopher Berry — risks undermining the special relationship and could threaten intelligence sharing between Britain and the US.

Trump is understood to be… https://t.co/p4meFz3le0 pic.twitter.com/s5kW60HpLU

— Byron Wan (@Byron_Wan) October 12, 2025


Defending LLM applications against Unicode character smuggling | AWS Security Blog

When interacting with AI applications, even seemingly innocent elements—such as Unicode characters—can have significant implications for security and data integrity. At Amazon Web Services (AWS), we continuously evaluate and address emerging threats across aspects of AI systems. In this blog post, we explore Unicode tag blocks, a specific range of characters spanning from U+E0000 to […]


Most security practitioners will tell you that the traditional network perimeter between internal trusted systems and the external untrusted internet disappeared with the emergence of client side exploits. It was replaced by coarse grained network isolation roughly between what… https://t.co/zSwosxHNxQ

— chrisrohlf (@chrisrohlf) October 11, 2025

securing ai agents.pptx - Google Slides

How to securely deploy agents that make sensitive decisions autonomously Joshua Saxe AI security engineering @ Meta 1


https://obsolescence.dev/enigma-touch.html


Today, we publish our analysis of CVE-2025-3600 that we discovered in Telerik UI, a prolific library used in hundreds of thousands of applications.

Tagged as a Denial of Service vulnerability, today we go deeper and demonstrate RCE scenarios..https://t.co/RzHmW1Mrgu

— watchTowr (@watchtowrcyber) October 10, 2025


Huge escalation by China!

MOFCOM announces new exports controls taking effect after Dec 1 of rare earths to anyone anywhere in the world producing chips or equipment to make chips below 14nm or 256 layer memory due to “military applications”

1/2 https://t.co/bKHpjX6RHE

— Dmitri Alperovitch (@DAlperovitch) October 9, 2025


[Research] Starting Chrome Exploitation with Type Confusion 101 ^-^☆ Part 4.https://t.co/YcbFf8QkUa

Hi — OUYA77 here. Celebrating Chuseok(Korean Thanksgiving Day), I happily continued my Chrome research post. In the last post I covered the journey all the way to RCE (which I… pic.twitter.com/Etl9eqFfWc

— hackyboiz (@hackyboiz) October 10, 2025


🤓 I created a new community project dedicated to Adversarial Prompts called PromptIntel.

PromptIntel is a public and free database that helps you:
・ Explore and classify adversarial prompts taxonomy
・ Contribute new prompts from your research
・ Access a live feed with… pic.twitter.com/MeHvnJvOHF

— Thomas Roccia 🤘 (@fr0gger_) October 12, 2025


Something you may not know about Sonnet 4.5: it’s a special model for cybersecurity.

For the past few months, the Frontier Red Team has been researching how to make models more useful for defenders.

We now think we’re at an inflection point. New post on Red: pic.twitter.com/ECOkVfeDKV

— Logan Graham (@logangraham) September 29, 2025

Thread by @logangraham on Thread Reader App – Thread Reader App

@logangraham: Something you may not know about Sonnet 4.5: it’s a special model for cybersecurity. For the past few months, the Frontier Red Team has been researching how to make models more useful for defenders. We...…

https://red.anthropic.com/2025/ai-for-cyber-defenders/


A report reveals that the OceanLotus group, also known as APT32 or APT-Q-31, has been conducting long-term cyber operations against China and neighboring Southeast Asian countries. #CyberSecurity #APT32 https://t.co/6HwWloovqp

— Cyber_OSINT (@Cyber_O51NT) October 11, 2025


#SpyNews - week 41 (October 5-11):
A summary of 75 espionage-related stories from week 41 coming from 🇬🇧🇨🇳🇮🇳🇵🇰🇷🇴🇺🇸🇮🇷🇫🇷🇩🇪🇮🇱🇹🇷🇷🇸🇭🇺🇧🇪🇮🇹🇨🇦🇺🇦🇷🇺🇵🇱🇵🇸🇸🇴🇬🇪🇹🇼🇻🇦🇪🇪🇾🇪🇨🇿🇦🇹🇩🇰🇻🇪🇰🇵🇧🇫🇳🇱🇲🇱🇸🇬🇯🇵🇰🇷🇭🇰🇲🇦🇨🇾🇨🇺🇽🇰🇱🇧🇧🇬🇲🇾🇪🇸🇧🇩🇦🇺 https://t.co/frInNRrojr#OSINT #HUMINT #SIGINT #spy #espionage

— Spy Collection (@SpyCollection1) October 12, 2025

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X