the grugq's newsletter

Subscribe
Archives
October 31, 2023

October 31, 2023

October 31, 2023

Shorter Halloween issue, because it’s Halloween and things are scary enough.

“volume of security issues being identified over the last month have [sic] outstripped the capacity of Engineering teams to resolve.”

Most orgs are like this.

Didn’t expect to see CISO liability before software liability, but here we are. #solarwinds https://t.co/q3ex6Be4LJ

— Katie🌻Moussouris (she/her) (@k8em0) October 31, 2023

‘THEY FOLLOW’, the sequel to ‘IT FOLLOWS’ from director David Robert Mitchell.

Coming soon in theaters. pic.twitter.com/T8FwPof78k

— Film Updates (@FilmUpdates) October 30, 2023

Oh shit….it’s nonbinary now https://t.co/xiv9aiaYUN

— roro, PhD (@fuglibetty) October 30, 2023

under-remarked in this Apple announcement is the fact that for the first time in a decade or more, there is now an aspect in which Signal is behind the state of the art in secure messaging.

huge congrats to the team, it’s a massive leap forward!https://t.co/HjDjefHQs1 pic.twitter.com/JcjyqVfiTY

— henry 🌘 (@hdevalence) October 31, 2023

Paxlovid does not prevent Long COVID, finds study.

Negative results are as important as positive results in medical research, because we also need to know what doesn’t work.

It is impressive that it got published. https://t.co/1CH3QgvitU pic.twitter.com/6Ol46067R8

— Rajeev Jayadevan (@RajeevJayadevan) October 31, 2023

My @HITBSecConf talk on library recognition using strings:https://t.co/xTVOsOV7K7

— babush (@pmontesel) October 30, 2023

The White House calls for all LLMs to have "but do it safely" appended to the system prompt

— lcamtuf (@lcamtuf@infosec.exchange) (@lcamtuf) October 30, 2023

New Executive Order is out. Already one notable item:

Any AI model that required more than 1e26 floating point operations or 1e23 integer operations to build must report to the government. pic.twitter.com/pDwJ4CJ8O8

— David Vorick (@DavidVorick) October 30, 2023

One reason (among many) that VC firms of different shapes & sizes have refocused on seed/early A in this tough capital market -- the multiples on narratives & promises is infinite while the multiples on evidence & traction is painfully finite.

— Semil (@semil) October 29, 2023

I've thought about this Russ Hanneman quote / scene so many times pic.twitter.com/zANGQdHIDA

— Sheel Mohnot (@pitdesi) October 29, 2023

the courtroom sketch artist was definitely paid off by SBF pic.twitter.com/OTzfOy05f8

— litquidity (@litcapital) October 30, 2023

Important new paper by : "Why Aren't We Using Passkeys? Obstacles Companies Face Deploying FIDO2 Passwordless Authentication" by @Leochrima et al.

Absolutely insane that regulations prevent adoption of the best security improvement anyone could make https://t.co/Yexkwwc8WF pic.twitter.com/pqiyAtQzS0

— Devdatta Akhawe (@frgx) October 30, 2023

the video reactions thing that @apple added to Sonoma as a default is so bad that now telehealth sites are begging people to understand that it's not their fault. pic.twitter.com/3K8t77cWUZ

— April King 🌀 (@CubicleApril) October 30, 2023

Confluence bug is popping off. VAST majority of it is blasting thru Tor, similar to the first wave of Log4J exploitation two years ago. If you haven't patched, it's probably popped. https://t.co/4JC0uiTaqc pic.twitter.com/wLDgQpq7r0

— Andrew Morris (@Andrew___Morris) October 30, 2023

SEC is charging SolarWinds CISO for their breach due to hiding and inaccurately painting their security posture picture.

I probably know a few “people-leader CISO’s” that probably fall into this. Be warned. Know what you’re doing or let someone else lead.https://t.co/g4dAWNlkBJ

— Frank McGovern (@FrankMcG) October 30, 2023

Actual complaint here:https://t.co/DoN1jLj2f4 https://t.co/xvBD5VLt06

— Richard Johnson (@richinseattle) October 30, 2023

That's not a buffer overflow, that's just the American Automobile Association Always Advocates Astonishingly Abundant Adventures, Achieving Ample Amusement, And Appreciating Amazingly Astounding Automobiles, Anytime, Anywhere, Allowing Awe-struck Amazement; All Aboard An Aweso

— remy🐀 (@_mattata) October 30, 2023

Skyview

Fuck this hustle-culture bullshit. When I’m a skeleton I’m not doing a goddamn thing


CISO & Security Exec friends:

Shit is changing. You can be held accountable for risk decisions.

Cover yourself with your contract, document everything, build into your yearly cost a legal stipend, build into your contract fixed/immutable severance package.

Just my 2c ✌️

— Jason Haddix (@Jhaddix) October 30, 2023

Given that @pdnuclei has posted a full PoC for CVE-2023-46747, we're sharing the full F5 RCE blog post now. Link is https://t.co/6CWJ01Chk4. Shout outs to @iamnoooob @rootxharsh for getting the PoC in < 72 hours and to @OrangeTsai for the inspiration! #f5 #cve202346747 #nuclei

— Michael Weber (@BouncyHat) October 30, 2023

Skyview

Tonight’s brutal attack: Brutal Kid’s twin: “Dad, what’s your dream car?” The Brutal Kid, casually, as he is walking away, over his shoulder: “A Honda Civic.”

Skyview

And today’s posterization? Me, to wife: “So … I launched my blog today.” Wife, to me: “Oh! What’d you name it?” The Brutal Kid, without missing a beat: “ ‘I’m Voicing My Opinions for No Apparent Reason’?”


Scoop: Mossad chief visits Qatar for talks on hostages held by Hamas in Gaza
https://t.co/d7lrEpW8gb

— Dr. Dan Lomas (@Sandbagger_01) October 30, 2023

I published an article about the DOM-based race condition, which was the solution for the challenge that I posted 3 weeks ago.https://t.co/kYoIh9Spew

— RyotaK (@ryotkak) October 29, 2023

When you have a great personality pic.twitter.com/t9LNmk1Yo3

— faulty *ptrrr (@0x_shaq) October 30, 2023

Less spoken about U.S. Biden's Executive Order on AI is that it has a lot to unpack about privacy. That's a privacy win, even without something like #GDPR. Thread. It even uses the highly technical term "differential-privacy" (and privacy-enhancing technologies)! pic.twitter.com/bTN0EfE4Xt

— Lukasz Olejnik (@LukaszOlejnik@Mastodon.Social) (@lukOlejnik) October 31, 2023

this is so funny pic.twitter.com/Qwu1jcoaf9

— tyson brody (@tysonbrody) October 30, 2023


For once someone predicted the Simpsons in stead of the Simpsons predicting everything.
Yes, this is real, ladies & gentlemen: Ancient Egyptian Marge.

Apparently this is the coffin of Tadi Ist, daughter of the High Priest of Djehouti in Ashmunein:https://t.co/hIg6iXFRcf pic.twitter.com/6IltB8TfQF

— Fake History Hunter (@fakehistoryhunt) October 29, 2023

i love ancient history https://t.co/e9nPvKTYUH pic.twitter.com/IpQCgXlmOH

— RIP Spike R. Monster 🪦 (@spikermonster) October 29, 2023

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X