October 17, 2023
October 17, 2023
The Strange Story of Dagobert, the “DuckTales” Bandit | The New Yorker
In the nineties, a frustrated artist in Berlin went on a crime spree—building bombs, extorting high-end stores, and styling his persona after Scrooge McDuck. He soon became a German folk hero.
Alert! 🚨🚨🚨
— Exploit Code Not People 🏴 (@cooperq) October 16, 2023
A 0day has been discovered in the popular software that you all use! 😵😵 I can't tell you which software it is 🤫 but it was sent to me by a source to be trusted! 🧙♂️🧙♂️ So update your software right away! 🕑🕑 and share this with 10 friends or you will get hax0red
Here’s the thing.
— thaddeus e. grugq thegrugq@infosec.exchange (@thegrugq) October 17, 2023
1) 0day is an exploit for a vulnerability that is not patched
2) exploit developers are lazy
3) result: 0day tends to work best against the current patch level because that’s what it’s developed against
If there is 0day, being patched makes you vulnerable. 😁 https://t.co/zP8OOLZpHp
Does this mean “don’t patch”? No, absolutely not. 0day is rare and exceptional. Exploits for known vulnerabilities are cheap and plentiful. Patching is to ensure that only 0days are a threat, because they’re a rare vector. If the adversary needs an 0day, you’re doing great!
— thaddeus e. grugq thegrugq@infosec.exchange (@thegrugq) October 17, 2023
I’m trying something new. Seeing if there is a way to embed BlueSky posts before ButtondownEmail adds support. This works in the draft preview, so let’s see if it works for real.
I agree with Dr Matt.
I’m going to say this again. If you briefly turned off Signal “link previews” for a day or two in response to a possible vulnerability, you made the correct risk assessment and paid a minor cost for (maybe) being wrong. https://t.co/UjgZ2TJfJy
— Matthew Green (@matthew_d_green) October 17, 2023
Really disappointed with the amount of otherwise smart infosec people who shared the signal 0day copypasta this weekend without investigating at all or confirming it. We are not immune to disinformation attacks and this weekend was a stunning example of that.
— Exploit Code Not People 🏴 (@cooperq) October 16, 2023
This video of analysis of various bugs in Pokemon Red/Blue is very satisfying: https://t.co/hAfjdlTsGG
— Matt Suiche (@msuiche) October 17, 2023