the grugq's newsletter

Subscribe
Archives
October 28, 2025

October 28, 2025

October 28, 2025

📣THREAD: It’s surprising to me that so many people were surprised to learn that Signal runs partly on AWS (something we can do because we use encryption to make sure no one but you–not AWS, not Signal, not anyone–can access your comms).

It’s also concerning. 1/

— Meredith Whittaker (@mer__edith) October 27, 2025

https://threadreaderapp.com/thread/1982762813329457244.html


When the CFO walks in and you need to justify the budget for “research”

Hacking simulators
1. https://t.co/AusjdgH9tH
2. https://t.co/VBBF2CHrkg
3. https://t.co/RhayacAQVP
4. https://t.co/WyJm3NlMcx
5. https://t.co/WFJNcdCmyo

Pew Pew Maps
A. https://t.co/xBpU2Hc2m3
B.… pic.twitter.com/CLDHq2W9bq

— Florian Roth ⚡️ (@cyb3rops) October 27, 2025


GRU's Spy Airbnb: check out our latest video investigation into Unit 29155, and the "Czech" spy couple they used to help them plant explosives in weapons depots. https://t.co/k5qr3JQSX4

— ChristoGrozev@bsky.social (@christogrozev) October 27, 2025


Short post about LPE and TCC Bypass on macOS through third-party apps bundled with Sparkle framework - a reminder of why XPC services should validate their clients.https://t.co/uymrg3U72K

— Karol Mazurek (@karmaz95) October 27, 2025


thanks to everyone who attended my #TheSAS2025 talk "Typographic hit job: when fonts pull the trigger". 🙏

I've written an accompanying blogpost that goes over all the details: https://t.co/I91zIQ3kho

— blasty (@bl4sty) October 27, 2025


So… based on the episode 4 of the kittens leaks, are we now assuming Chaeming Kittens & Moses-staff are actually parts of the same group? Needs extra verification though, so don’t just blindly assume based on the leak. But if confirmed, this is an important piece of the leak and… pic.twitter.com/byiBBzBqHa

— Hamid Kashfi (@hkashfi) October 28, 2025


https://www.wbaltv.com/article/student-handcuffed-ai-system-mistook-bag-chips-weapon/69114601


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X