the grugq's newsletter

Subscribe
Archives
October 21, 2023

October 21, 2023

October 21, 2023

New: an incredible court record pulls back the curtain on a $30 million dollar underground Bitcoin exchange running for years in the heart of New York. Massive bags of cash, drive-by pickups. This is what real criminals use, not services like Coinbase https://t.co/XZVoHUtEpY pic.twitter.com/bmV3hsMG9X

— Joseph Cox (@josephfcox) October 20, 2023

BleepingComputer: "Law enforcement agencies arrested a malware devel…" - Infosec Exchange

Law enforcement agencies arrested a malware developer linked with the Ragnar Locker ransomware gang and seized the group's dark web sites in a joint international operation. https://www.bleepingcomputer.com/news/security/police-arrests-ragnar-locker-ransomware-developer-in-france/


The funniest thing about the fascist pro-Putin grifters on Twitter is that they are so obviously corrupt and are siphoning off donations that would otherwise bolster the Russian war effort. They are actively undermining their own cause through greed. https://t.co/zIgOflzEpF

— Oz Katerji (@OzKaterji) October 20, 2023

...Z-merchandise and collecting donations for made-up causes and charities. Even her former colleague, @squatsons, seemed confused about the whole charity situation, and eventually admitted that he didn't know where the money went - probably to Bils' own pockets.

5/16 pic.twitter.com/xZOS7lF2NX

— Pekka Kallioniemi (@P_Kallioniemi) October 20, 2023

A lot of people said sniffing a TPM requires advanced knowledge and equipment - so let’s change that!

Soon a couple of pogo-pins and a @Raspberry_Pi Pico will be enough 😀 pic.twitter.com/hoWRdePohV

— stacksmashing (@ghidraninja) October 19, 2023

Well, shit.
Encrypted traffic interception on Hetzner and Linode targeting https://t.co/wrWg1FCVNp, the largest Russian XMPP (Jabber) messaging service.
The instant messaging have been wiretapped for 3 months, on both hosting providers in Germany.https://t.co/MIof2vET4B

— ValdikSS (@ValdikSS) October 20, 2023

https://notes.valdikss.org.ru/jabber.ru-mitm/

Hackers stole access tokens from Okta's support unit. "Okta says the incident affected a 'very small number' of customers, however it appears the hackers...had access to Okta’s support platform for at least two weeks" https://t.co/TJtN7L9DqN

— Kim Zetter (@KimZetter) October 20, 2023

Worth highlighting that Okta discovered this only because Beyond Trust reported to them that someone was trying to hack BT using a session cookie stolen from Okta - Okta didn't believe BT, and it took them two weeks to confirm that, yes ,they had been breached https://t.co/AD3gz8KQyH

— Kim Zetter (@KimZetter) October 20, 2023

Asked DALL-E 3 for the ingredients to make a cake.. the more you look the better this gets pic.twitter.com/4eJXuZfn9A

— Daniel Feldman (@d_feldman) October 20, 2023

“[31m"?! ANSI Terminal security in 2023 and finding 10 CVEs

https://dgl.cx/2023/09/ansi-terminal-security

A really bad day for Okta

How Cloudflare Mitigated Yet Another Okta Compromise

"On Oct 18, we discovered attacks on our system that we were able to trace back to Okta – threat actors were able to leverage an authentication token compromised at Okta..."https://t.co/mpRxY2ic1m

— Kim Zetter (@KimZetter) October 20, 2023

—

😂 “I don’t have time to listen to your complaints” “I’m not your therapist” pic.twitter.com/20VnQIK1ir

— Ian Arawjo (@ianarawjo@hci.social) (@IanArawjo) October 20, 2023

Weekly summary is out (attribution by others):
-🇷🇺 ops in 🇺🇦++
-🇰🇵 ops using watering holes
-🇰🇵 ops on industrials in 🇪🇺
-🇮🇷 & Hamas infra overlaps
-🦹 malvertising++

then:
-mass router compromises
-visual studio for access

& off/defensive tradecraft.https://t.co/1UFzlEAvcW

— Ollie Whitehouse (@ollieatnowhere) October 21, 2023

#RaidRating 8/10 - Cheesy law enforcement swagger and they posted hashes👍. Great office pictures. In the future, consider more camera angles besides butt. https://t.co/vAdWeLd9zV pic.twitter.com/wv8Fp8T6xP

— Silas // p1nk (@silascutler) October 21, 2023

Just bought a new monitor.

Still can’t fit my Java Class names in it. pic.twitter.com/C7IwALKFhc

— Lewis Menelaws (@LewisMenelaws) October 20, 2023

I was dating this guy who took me home to his parents' house for the weekend and his mom was learning taxidermy and I slept in a room with all her practice chickens

— mean things I say to myself (@meantomyself) November 22, 2021

"This is a global phenomenon. Our information indicates that senior Russian government officials, including in the Kremlin, see value in this type of influence operation and perceive it to be effective".https://t.co/rQevpsx41w

— Dr. Dan Lomas (@Sandbagger_01) October 20, 2023

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X