the grugq's newsletter

Subscribe
Archives
October 30, 2024

October 30, 2024

October 30, 2024

An air "battle" between a Ukrainian FPV and an enemy reconnaissance drone equipped with a rear camera with an AI module for evasion. pic.twitter.com/e61jN0tLJR

β€” WarTranslated (Dmitri) (@wartranslated) October 29, 2024


From observation in the wild (September 13):

Interesting vector, ever seen this before @_JohnHammond? pic.twitter.com/oAkaXgnRBI

β€” Mohamed Aruham #boleh (@aruhamm) September 12, 2024

To replication in the lab (implemented in 18 hours):

Well, this was a stupid insomnia project, but... πŸ˜‚

Playground code is here: https://t.co/GQsVFrYsvy https://t.co/KhdbhTJKxN pic.twitter.com/CQxvTUMuZP

β€” John Hammond (@_JohnHammond) September 13, 2024

To operationalization in the wild (announced October 25):

This technique is now being used by APT28/FANCYBEAR (The Russian GRU) to phish local governments in Ukrainehttps://t.co/Kshy32V4kU https://t.co/BTK2E7ldIS pic.twitter.com/GY4vnk92jR

β€” Will (@BushidoToken) October 28, 2024


oh hell yeah https://t.co/su0D1lENbW pic.twitter.com/6gfmaqOvju

β€” Adam Johnson (@adamjohnsonCHI) October 29, 2024


When you are an OpSec king you will use your home ip-address 25 times to access your malware license server and then same ip-address - 701 times to communicate with your personal iCloud account. #RedLine pic.twitter.com/kjk8j0Lxtq

β€” B r a t v a (@BratvaCorp) October 29, 2024


My maldev works and practices [Oct 2024]:

+ Remote Process Injection using NTAPI: https://t.co/X3s8eYIXUr

+ Code injection using (NtCreateSection,NtMapViewOfSection) : https://t.co/CbpxC7NkvK

+ Payload Shuffling Technique: https://t.co/mA32QeAcDD

+ Local Mapping Injection:… pic.twitter.com/g2ymKRKrsu

β€” Smukx.E (@5mukx) October 29, 2024


New: A leaked training presentation from a NY's largest hospital system shows how doctors are being encouraged to use AI for everything from writing emails to summarizing clinical evaluations to "diagnosing pancreatic cancer" and "parse" health recordshttps://t.co/kMF3PjuMs5

β€” Jason Koebler (@jason_koebler) October 29, 2024


The Independent's Persian-language newspaper, citing anonymous sources, reports that Iran's radar systems were hacked and frozen minutes before the first wave of Israeli strikes on Saturday, preventing the Iranian army from detecting or intercepting Israeli planes.

The same…

β€” Aleph א (@no_itsmyturn) October 28, 2024


Privilege escalation through TPM Sniffing when BitLocker PIN is enabled – SCRT Team Blog

https://blog.scrt.ch/2024/10/28/privilege-escalation-through-tpm-sniffing-when-bitlocker-pin-is-enabled/


Anatomy of an LLM RCE

Anatomy of an LLM RCE

As large language models (LLMs) become more advanced and are granted additional capabilities by developers, security risks increase dramatically. Manipulated LLMs are no longer just a risk of...


Insane story out of Italy:https://t.co/1SyjvoKD1X

A PI firm hired hackers to break into a Italian government database. They then sold the data to private clients who allegedly used the information to secretly blackmail and intimate government officials. pic.twitter.com/wHbO7zYglc

β€” Chris Bing (@Bing_Chris) October 29, 2024


Let's debunk the popular claim that misinformation is everywhere and is always harmful with impacts. Misinformation is overstated. But has huge impact on public opinions and changed laws. Example: people consuming a great deal of false, untrustworthy or otherwise harmful content… https://t.co/Nh2sHORmYf pic.twitter.com/gD67KJbrgB

β€” Lukasz Olejnik (@lukOlejnik) October 30, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X