the grugq's newsletter

Subscribe
Archives
October 30, 2023

October 30, 2023

October 30, 2023

Gary's hacking stuff: Exploiting DNS response parsing on the Wii U

It's annual Wii U exploit time! ๐Ÿ˜„ Image of the Wii U connection test screen on the GamePad. After reverse engineering parts of the Wii Us' ...


#SpyNews - week 43 (22-28 October):
A summary of 92 espionage-related stories from week 43 coming from ๐Ÿ‡ฉ๐Ÿ‡ฐ๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ธ๐Ÿ‡พ๐Ÿ‡ฎ๐Ÿ‡ถ๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡ซ๐Ÿ‡ท๐Ÿ‡ฎ๐Ÿ‡ท๐Ÿ‡ญ๐Ÿ‡ฐ๐Ÿ‡ณ๐Ÿ‡ต๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ณ๐Ÿ‡ฟ๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡ช๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ช๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡ฑ๐Ÿ‡ฐ๐Ÿ‡ฐ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ช๐Ÿ‡ฒ๐Ÿ‡ณ๐Ÿ‡ฐ๐Ÿ‡ฟ๐Ÿ‡ฆ๐Ÿ‡ฟ๐Ÿ‡ถ๐Ÿ‡ฆ๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡ฐ๐Ÿ‡ญ๐Ÿ‡ธ๐Ÿ‡ช๐Ÿ‡น๐Ÿ‡ผ๐Ÿ‡ฑ๐Ÿ‡ป๐Ÿ‡ธ๐Ÿ‡ฎ๐Ÿ‡ฒ๐Ÿ‡ฆ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡ซ๐Ÿ‡ฎ๐Ÿ‡ช๐Ÿ‡ช๐Ÿ‡ฑ๐Ÿ‡ง https://t.co/2KEttf9FTE#Espionage #OSINT #HUMINT #SIGINT #Spy

โ€” Spy Collection (@SpyCollection1) October 29, 2023

I have just published #Diaphora 3.1.1. It contains two new ("oBvIoUs") heuristics, some enhancements for the support to try to find potentially fixed vulnerabilities and noticeable performance bug fixes.https://t.co/XtPVuWnXtZ pic.twitter.com/4w7F15KmrJ

โ€” Joxean Koret (@joxean@mastodon.social) (@matalaz) October 29, 2023

Skyview

Apple will let users verify if the person they speak to over iMessages is really the person, or maybe the account is hijacked. Implementation of CONIKS and Vaudenay's protocol. Serious crypto engineering. security.apple.com/blog/imessag... www.usenix.org/system/files... www.iacr.org/archive/cryp...


https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/

pic.twitter.com/5MhwA0pZxf

โ€” Havoc Six (@Havoc_Six) October 30, 2023


Spy satellites reveal hundreds of undiscovered Roman forts - 396 previously undiscovered Roman forts in what is now Syria and Iraq https://t.co/9dH1KHZmyO

โ€” switched (@switch_d) October 30, 2023

FACT SHEET: President Biden Issues Executive Order on Safe, Secure, and Trustworthy Artificial Intelligence | The White House

Today, President Biden issued a landmark Executive Order to ensure that America leads the way in seizing the promise and managing the risks of artificial intelligence (AI). The Executive Order establishes new standards for AI safety and security, protects Americansโ€™ privacy, advances equity and civil rights, stands up for consumers and workers, promotes innovation andโ€ฆ


Police tried to check on the Maine gunman over concerns he could โ€˜snap and commit a mass shootingโ€™ | CNN

The Maine National Guard asked local police to check on the reservist who killed 18 people last Wednesday after a soldier became concerned he would โ€œsnap and commit a mass shooting,โ€ according to information shared with CNN.

โ€œWhen [his friend] told him to knock it off because he was going to get into trouble talking about shooting up places and people, [he] punched him,โ€ the statement said. โ€œAccording to [the friend], [he] said he has guns and is going to shoot up the drill center at Saco and other places โ€ฆ [the friend] is concerned that [he] is going to snap and commit a mass shooting.โ€

The threat to the National Guard facility in Saco led to some extra patrols, Saco Police Chief Jack Clements told WMTW Maine, but the troubled guardsman never showed up.

Sagadahoc County Sheriff Merry told The New York Times he sent an alert to all law enforcement agencies in Maine sometime in September after learning of the threat to the Saco base.

CNN had not been able to independently verify that.

Can you imagine hearing โ€œthis guy is hearing voices and talking about shooting up the Saco base and doing mass shootings and stuff. Please do something before he snaps and kills people!โ€ and thinking โ€œbetter send a couple extra patrols around Sacoโ€ is the correct response??

Itโ€™s like hearing about an exploit for an edge router and rather than patching, instead decide to increase the logging verbosity on the firewall for a couple days. You know, so you can spot and stop the exploit.

The police incompetence is unfathomable. I donโ€™t know how you can even create people who think like this.

Don't miss what's next. Subscribe to the grugq's newsletter:
X