the grugq's newsletter

Subscribe
Archives
October 7, 2022

October 7, 2022

Twitter avatar for @mrkoot
Matthijs R. Koot @mrkoot
Trace Oddity: Methodologies for Data-Driven Traffic Analysis on Tor (Rimmer et al., July 2022, in Proc. of PETS, #3) petsymposium.org/popets/2022/po… HT @PET_Symposium Re: novel end-to-end traffic correlation attack on Tor. Direct link to paper (1.9MB .pdf, 22pp) petsymposium.org/popets/2022/po…
Image
1:31 PM ∙ Oct 6, 2022
5Likes5Retweets

-

The Info Op is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Twitter avatar for @DrWhax
🏴 Jurre van Bergen @DrWhax
The hacktivist group Guacamaya compromised the chiefs of staff of Chile and published several gigabytes of their e-mail spools online. In this data, there's some references to known spyware and resellers of these tools. 🧵👇
Image
10:06 AM ∙ Oct 6, 2022
42Likes32Retweets

-

Twitter avatar for @electrospaces
Electrospaces @electrospaces
Interesting piece about the #Snowden files: "journalists find themselves in the ironic position of responsibly protecting some of NSA’s most sensitive secrets."
spytalk.coThe Curious Fate of Citizen Snowden’s ArchiveA ‘vast’ trove of NSA files remains, with some stuff so sensitive even journalists with access don’t want to report it, a SpyTalk investigation finds
9:31 PM ∙ Oct 6, 2022
5Likes8Retweets

-

Twitter avatar for @swagitda_
Kelly Shortridge @swagitda_
Cybersecurity Awareness Month Tip #5: If a big attacker is close by: Stay in a group; carry junior developers; make noise. Do not run and do not bend down to pick up code. Act dominant and stand your ground — stare in the attacker’s eyes and show your teeth while making noise.
11:46 PM ∙ Oct 5, 2022
691Likes173Retweets

-

Twitter avatar for @web3isgreat
web3 is going just great @web3isgreat
Binance Smart Chain halts after $100+ million bridge exploit October 6, 2022 web3isgoinggreat.com/?id=binance-sm…
Binance Smart Chain halts after $100+ million bridge exploit Binance Smart Chain, the relatively popular blockchain that Binance is trying to rebrand as "BNB Chain", was halted when an attacker moved at least $100 million of crypto off the chain. Some have estimated the theft at more like $600 million. Binance CEO Changpeng Zhao ("CZ") tweeted that "An exploit on a cross-chain bridge, BSC Token Hub, resulted in extra BNB. We have asked all validators to temporarily suspend BSC." A BSC developer later confirmed that "we coordinated with validators to temporarily suspend BSC after having determined an exploit on a cross-chain bridge, BSC Token Hub- which resulted in extra BNB". The value of the $BNB token dropped from $293.10 to $280.40 after the news.
12:51 AM ∙ Oct 7, 2022
221Likes34Retweets

-

Twitter avatar for @bascule
Tony "Abolish ICE" Arcieri 🦀🌹 @bascule
Interesting paper from @Nature showing that SARS-CoV-2 reduces antiviral response by disrupting gene transcription. It does this mimicking histone proteins which are ordinarily responsible for packaging DNA in a cell’s nucleus
nature.comSARS-CoV-2 disrupts host epigenetic regulation via histone mimicry - NatureThe SARS-CoV-2 protein ORF8 functions as a mimic of histone H3 to disrupt host cell epigenetic regulation.
2:40 AM ∙ Oct 7, 2022
3Likes1Retweet

-

Twitter avatar for @runasand
Runa Sandvik @runasand
Earlier this year, financial journalist @nasoskook and @citizenlab found that his phone had been infected with the Predator spyware from Cytrox. He’s now suing the parent company, Intellexa, “alleging a criminal breach of privacy and communication laws.”
gizmodo.comJournalist Sues Spyware Company for Allegedly Helping Gov. Surveil HimA Greek financial journalist is one of several who believe they have been targeted for surveillance by the nation’s government with the help of Intellexa.
2:17 AM ∙ Oct 7, 2022
59Likes34Retweets

-

Twitter avatar for @HITBSecConf
HITBSecConf @HITBSecConf
#HITB2022SIN KEYNOTE 2: Adventures In Security Research - Runa Sandvik -
youtube.com#HITB2022SIN KEYNOTE 2: Adventures In Security Research - Runa SandvikA personal talk about my 12-year relationship with defensive security work and other random stories. Come for the tales about journalism security, mission an...
1:40 AM ∙ Oct 7, 2022
7Likes11Retweets

-

Twitter avatar for @ShannonEliza
Shannon Hardwick @ShannonEliza
Okay
Image
2:39 AM ∙ Oct 6, 2022
37,256Likes9,441Retweets

-

Twitter avatar for @turtlekiosk
😈 @turtlekiosk
telling github copilot to write my next function "in the style of john carmack"
5:15 PM ∙ Oct 6, 2022
1,482Likes132Retweets
Twitter avatar for @moyix
Brendan Dolan-Gavitt @moyix
@turtlekiosk @adhsec Yes this works
Image
12:56 AM ∙ Oct 7, 2022
156Likes27Retweets

-

Twitter avatar for @GossiTheDog
Kevin Beaumont @GossiTheDog
Another update to #ProxyNotShell blog - There's an unannounced bypass to the mitigation again today. - Windows Server 2016 and above automatically excludes IIS processes from Defender scanning, which has implications for detection and MS telemetry.
doublepulsar.comProxyNotShell— the story of the claimed zero day in Microsoft ExchangeYesterday, cybersecurity vendor GTSC Cyber Security dropped a blog saying they had detected exploitation of a new Microsoft Exchange zero…
9:33 AM ∙ Oct 7, 2022
15Likes4Retweets

-

Twitter avatar for @ciaranmartinoxf
Ciaran Martin @ciaranmartinoxf
“You can’t wreck undersea cables with a laptop: you have to attack them physically” - enjoyed talking to ⁦@MishalHusain⁩ ⁦@BBCr4today⁩ about keeping a calm, measured & nuanced view of Russia’s cyber threat to the west It’s at about 1hr51 👇 bbc.co.uk/sounds/play/m0…
bbc.co.ukToday - 07/10/2022 - BBC SoundsNews and current affairs, including Sports Desk, Weather and Thought for the Day.
9:23 AM ∙ Oct 7, 2022
42Likes10Retweets

-

Twitter avatar for @RoryCormac
Rory Cormac @RoryCormac
First seminar of the term done and I, at least, really enjoyed it. We used this article to deconstruct prisms which shape understandings of secrecy - & why they matter It's got Bond, it's got Diana, it's got guns, legends, "mad" ops, license to kill!
thesun.co.ukInside the Increment - the unit so secret Government won’t admit they existFOR years Britain’s spies have distanced themselves from the image of James Bond – sipping cocktails one minute, leaping out of planes the next, garrotting the Queen’s enemies in gin-soaked brothel…
9:05 AM ∙ Oct 7, 2022
32Likes5Retweets

-

Twitter avatar for @kristenstockdal
Kristen @kristenstockdal
An interesting development in the Kim <> Kanye saga
Image
5:50 AM ∙ Oct 5, 2022
458,530Likes41,434Retweets

-

Twitter avatar for @campuscodi
Catalin Cimpanu @campuscodi
Actively exploited Zimbra zero-day Exploited for a month ☑ Public PoC ☑ Patch ❌
attackerkb.comCVE-2022-41352 | AttackerKBOn September 25, 2022, CVE-2022-41352 was filed for Zimbra Collaboration Suite. The vulnerability is a remote code execution flaw that arises from unsafe usage…
2:51 AM ∙ Oct 7, 2022
81Likes48Retweets

-

Twitter avatar for @poolio
Ben Poole @poolio
We have been calling this issue where the learned 3D model has multiple faces the Janus problem (en.wikipedia.org/wiki/Janus) h/t @jon_barron View-dependent prompting helps, but doesn't solve it in all cases as seen with the DreamFusion model of the squirrel below.
Image
Twitter avatar for @_akhaliq
AK @_akhaliq
Failure cases: "A DSLR photo of a squirrel" https://t.co/ibDXCwkTpL
3:31 PM ∙ Oct 6, 2022
98Likes18Retweets

-

The Info Op is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X