the grugq's newsletter

Subscribe
Archives
October 22, 2023

October 22, 2023

October 22, 2023

Theoretically interesting targeting. The company that helps the Canadian military (and others) move was hit by Lockbit.

Company that arranges military moves has been hacked, defence department confirms | CBC News

The private company that assists members of the Canadian military and foreign service when they move across the country or around the world has been hacked, says a Department of National Defence note issued internally late Friday.


My talk at @hack_lu about cyberwarfare, mixing technology, cyber threat intelligence, international law (including international humanitarian law), policy. Video: https://t.co/jZ5uNgMpMA Slides: https://t.co/WsVRW8MySt pic.twitter.com/6iEHDg4fQ7

— Lukasz Olejnik (@LukaszOlejnik@Mastodon.Social) (@lukOlejnik) October 21, 2023

Frank Lucas, the black drug lord who ruled Harlem in the 1970s, was so discreet that the police didn't know who he was in 1971 when he decided to wear a $100,000 full-length chinchilla coat — to a Muhammad Ali boxing match.

He later wrote that this was a “massive mistake.… pic.twitter.com/7gC9pu6s04

— Fascinating (@fasc1nate) October 20, 2023

https://en.wikipedia.org/wiki/List_of_security_hacking_incidents

Well, that backfired!

Sounds like @okta laid off their *entire* Red Team. As in they no longer have the function. Wherever they land will be lucky to have them. If your org relies on okta you may want to start asking questions. pic.twitter.com/Ih32qQBk6V

— Misha Davidov 🏳️‍⚧️ (@sirus) March 20, 2023

@_xpn_ pls push button when you wake up :)https://t.co/k0ZfPQV3xy

— SkelSec (@SkelSec) October 21, 2023

Uhaul was breached. 13GBs of data was exfiltrated from their SharePoint. Initial access was granted by social engineering an employee through text messages.

tl;dr another day in Shangri-La

— vx-underground (@vxunderground) October 21, 2023

Again, we’re seeing a huge increase in attacks starting with a phone call or text message. In the new Uhaul breach the attacker is claiming social engineering via text message as initial point of entry. If you’re not communicating the likelihood of text message and phone call… https://t.co/AbFNWVXJWp

— Rachel Tobac (@RachelTobac) October 21, 2023

Lol. Lmao. pic.twitter.com/pGMObSMghN

— William "Balloon Guy" Kim (@TheKimulation) October 21, 2023

1/ Our digital security experts released our latest anti-doxing guide to help BIPOC activists stay protected against harassment and targeted digital attacks. We encourage anyone organizing or attending actions in the coming weeks to utilize this resource. https://t.co/VnTlP22mt3 pic.twitter.com/mftDq0A8j1

— Equality Labs (@EqualityLabs) October 20, 2023

A production line of Type 69-II's in China. The left side was destined for the Iraqi's, the right line was for Iran https://t.co/00b315gdIu pic.twitter.com/BK19sIblNA

— AWACS Anthrax🇦🇺 (@Anthrax_In_UK) October 21, 2023

Sun Tzu is alive and living in Somerset pic.twitter.com/i2GEg8N1ab

— Nick (@Dozibugger) October 21, 2023

Berlusconi's 'worthless' art proving a headache to heirs - BBC News

The ex-Italian prime minister bought many of his 25,000 paintings from late-night telesales programmes.

Woodworms have already destroyed part of the collection. In some cases, the cost of exterminating the pests exceeds the value of the paintings.


Skyview

Good Fortune Burger in Toronto renamed their menu items office supplies so customers could expense them. HEROES.


Armadillos collect leaf litter to build nests in their burrows by bunching leaves against their abdomens and hopping backward towards their nest due to their unique body shapepic.twitter.com/FJrELwGKuf

— Science girl (@gunsnrosesgirl3) October 21, 2023

War crimes tribunal says September cyberattack was act of espionage

The September attack came at a time of “broader and heightened security concerns for the Court,” including threats against several of its elected officials.


Exploiting a use-after-free vulnerability in the Netfilter subsystem in Linux kernel (CVE-2022–32250)
Excellent blog post by @theori_iohttps://t.co/6QkBzGViW5#Linux #exploit #infosec pic.twitter.com/Lf6DgYfBJ3

— 0xor0ne (@0xor0ne) October 21, 2023

This was a nice research by @_CPResearch_ about a vulnerability in Xiaomi's TEE and payment system that allows forging of payments directly from an unprivileged Android application https://t.co/cqSa81oB7P pic.twitter.com/3AxTI5V0s2

— 0xor0ne (@0xor0ne) October 21, 2023

People who are against Russia being split into smaller countries just don't get the beauty of the Siberian Independent Republic. pic.twitter.com/T1gQNO2tLU

— Denis Zakharov (@betelgeuse1922) October 21, 2023

An amazing 5,000 year-old complete Neolithic axe from Scotland!

This rare example of a stone axehead still set in the original wooden haft was found in a peat bog at Shulishader on the Isle of Lewis.

National Museums Scotland. Read more: https://t.co/0aer3y3B8v#Archaeology pic.twitter.com/ZCmP8Tsqel

— Alison Fisk (@AlisonFisk) October 22, 2023

[realhackhistory@home]#: "One of the earliest TV news segments still findab…" - chaos.social

One of the earliest TV news segments still findable online that deals with #hackers and #hacking, a 1983 segment from CBS Nightwatch on the movie WarGames, the 414s #hacker group busts and the safety of the US nuclear arsenal. https://www.youtube.com/watch?v=ui8BejEVpz4

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X