the grugq's newsletter

Subscribe
Archives
October 6, 2024

October 6, 2024

October 6, 2024

CATASTROPHIC: Chinese hackers massively wiretapped 🇺🇸USA by compromising the interception portals mandated under US law.

Remember this the next time a government demands encryption backdoors.

By: @bysarahkrouse @dnvolz @aviswanatha @bobmcmillan h/t @RonDeibert

READ:… pic.twitter.com/vamrQ2xA61

— John Scott-Railton (@jsrailton) October 5, 2024

Thread by @jsrailton on Thread Reader App – Thread Reader App

@jsrailton: CATASTROPHIC: Chinese hackers massively wiretapped 🇺🇸USA by compromising the interception portals mandated under US law. Remember this the next time a government demands encryption backdoors. By: @bysara...…

A very common tactic. Used by everyone.


This talk by Paul Gerste from @Sonar_Research is really cool 🤩

It applies the principles of "HTTP Desync" attacks to non-HTTP protocols, here database wire protocols 🧠https://t.co/RZ1pRjxHlO

— Nicolas Grégoire (@Agarri_FR) October 5, 2024


NEW

The Washington Post is out with new reporting on how the Mossad got those pagers into the hands of Hezbollah.

Hezbollah operatives were enticed by the bulky, rugged pagers that were pitched to them because they felt they could survive battlefield conditions.

They were… pic.twitter.com/umDVSLzWBo

— Yashar Ali 🐘 (@yashar) October 5, 2024

https://archive.is/nnUoK


Portable Hacking Lab: Control The Smallest Kali Linux With a Smartphone

Portable Hacking Lab: Control The Smallest Kali Linux With a Smartphone

This guide shows you how to set up a headless Pi-Tail, controlled entirely from your smartphone via SSH or VNC. This compact and cost-effective setup is perfect for on-the-go Wi-Fi pentesting, network scanning, and vulnerability assessments.


Man sits by me on train.
MAN: Loads of psychopaths around here
ME: Really?
MAN: Loads mate
ME: How'd you know?
MAN: There's signs aren't there?
ME: I guess?
MAN: I love them
(47 minutes of awkward silence.)
Man leaves train, he has a bike. I realise he was saying 'cycle paths'.

— Paul Watson (@paul_c_watson) October 4, 2024


Johnathan Norman: "The 24H2 Update will include Windows Protected Pr…" - Infosec Exchange

The 24H2 Update will include Windows Protected Print (WPP). If you have a compatible printer or no printer at all, I really encourage those who care about security to enable the feature. Enabling WPP switches users to the new print stack which kills a LOT of attack surface in Windows. It is one of the largest reductions of overall attack surface in Windows that I can recall. Moreover, it disables all 3rd party drivers. In the next month or two, the Restricted Worker update will also be applied w...


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X