the grugq's newsletter

Subscribe
Archives
October 20, 2025

October 20, 2025

October 20, 2025

We recently took over an APT investigation from another forensic company. While reviewing analysis reports from the other company, we discovered that the attackers had been active in the network for months and had deployed multiple backdoors.

One way they could regain rootโ€ฆ

โ€” Stephan Berger (@malmoeb) October 19, 2025


https://t.co/YyFGIv4wnh

โ€” vx-underground (@vxunderground) October 19, 2025


#SpyNews - week 42 (October 12-18):
A summary of 55 espionage-related stories from week 42 coming from ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡ธ๐Ÿ‡ช๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ณ๐Ÿ‡ฑ๐Ÿ‡ณ๐Ÿ‡ด๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡ฎ๐Ÿ‡ท๐Ÿ‡ต๐Ÿ‡ฑ๐Ÿ‡ฝ๐Ÿ‡ฐ๐Ÿ‡ฎ๐Ÿ‡ถ๐Ÿ‡ธ๐Ÿ‡พ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ช๐Ÿ‡ฌ๐Ÿ‡ฑ๐Ÿ‡ง๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡ซ๐Ÿ‡ท๐Ÿ‡ญ๐Ÿ‡บ๐Ÿ‡ง๐Ÿ‡ช๐Ÿ‡น๐Ÿ‡ผ๐Ÿ‡ฒ๐Ÿ‡ฒ๐Ÿ‡พ๐Ÿ‡ช๐Ÿ‡ป๐Ÿ‡ช๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡ฌ๐Ÿ‡ท๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡ธ๐Ÿ‡ฆ๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡ฐ๐Ÿ‡ต๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ท๐Ÿ‡ด๐Ÿ‡ธ๐Ÿ‡ฐ๐Ÿ‡ธ๐Ÿ‡ฎ๐Ÿ‡ช๐Ÿ‡ช๐Ÿ‡ฑ๐Ÿ‡ป๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡ฒ๐Ÿ‡พ๐Ÿ‡ป๐Ÿ‡ณ https://t.co/BAd5fjNqdC#OSINT #HUMINT #SIGINT #spy #espionage

โ€” Spy Collection (@SpyCollection1) October 19, 2025


After the 16th, the scale of Huionepay's USDT transfers dropped sharply.

If there was no address change, it would indicate that the entity's USDT business may have been affected. https://t.co/jQ3FqaKY8K pic.twitter.com/qRVxQSAJyG

โ€” Bitrace (@Bitrace_team) October 18, 2025


You donโ€™t find deep vulns just by reading code carefully; you find them by asking โ€œwhat assumptions does this code silently make?โ€ when you've carefully built the cognitive code map, and are constantly updating it. https://t.co/ScoSuh5v0B

โ€” dunadan (@udunadan) October 17, 2025


โ€œChina accuses US of cyber breaches at national time centreโ€

Somewhere in Fort Meade thereโ€™s a guy bragging he just pwned UTC+8https://t.co/tRkFRwzbee pic.twitter.com/ilEEZrAEcZ

โ€” Florian Roth โšก๏ธ (@cyb3rops) October 19, 2025


Operation Triangulation + #DanderSpritz
Come back โ€ฆ#iphone -> Windowshttps://t.co/KcNuiDq8or pic.twitter.com/dHTzt41mP6

โ€” blackorbird (@blackorbird) October 19, 2025


Leaked system prompts for CHATGPT, GEMINI, GROK, CLAUDE, PERPLEXITY, CURSOR, DEVIN, REPLIT, AND MORE! - AI systems transparency for all https://t.co/ATxe71jcE5

โ€” Nicolas Krassas (@Dinosn) October 19, 2025


It was a threat lmao https://t.co/GdZWajjlfl pic.twitter.com/7bwkEqkrGw

โ€” NSG650 (@nsg650) October 19, 2025


genuinely jaw-dropping billboard in san francisco and the website it takes you to pic.twitter.com/hTWHxGfPOg

โ€” matt (@mattxiv) October 18, 2025


Really amazing security is having your UN/PW taped on a sticky note taped to the public-facing side of your device as you're out recording protesters. pic.twitter.com/AkRPBee1M0

โ€” sudox (@kmcnam1) October 19, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X