the grugq's newsletter

Subscribe
Archives
September 14, 2025

September 13-14,

September 13-14,

There's a sick linenoise article by @iximeow in @phrack 71 called "Learning An ISA By Force Of Will", where ixi goes from unknown binary blob, to manual instruction decoding, to figuring out control flow, and gives a critique of the RE'd ISA.https://t.co/LK4R6e6lUI https://t.co/AsPvKJKmag

— Battle Programmer Yuu (@netspooky) September 13, 2025


Since Kerberoast/Kerberoasting is in the news, here's the article on how to setup a Kerberoast honeypot to detect Kerberoasting activity: https://t.co/nssQu12jwk

And this article describes some best practices for setting up an Active Directory honeypot account:…

— Sean Metcalf (@PyroTek3) September 12, 2025


The Great Firewall of China (GFW) today experienced the largest internal document leak in its history. More than 500GB of source code, work logs, and internal communications have been exposed, revealing details about the development and operation of the GFW.

The leak originated… pic.twitter.com/DADdDtKZ7w

— gfw.report (@gfw_report) September 13, 2025


Brilliant bit of research into the ugly world of parameter pollution and the utter shit show that is the WAF industry: https://t.co/TNUqoCPkqD

kudos to the @ethiack team here.

— Daniel Cuthbert (@dcuthbert) September 12, 2025


I totally forgot to upload my Defcon33 Workshop content...

If you want to learn and play with Instrumentation Callback on Windows, weaponize the Nirvana Debugging feature for syscall hijacking, process injection or sleep obfuscation, everything is here:https://t.co/hdGwIv2KgB

— OtterHacker (@OtterHacker) September 11, 2025


Deep dive into building an EDR kernel driver: from callbacks to user-mode orchestration#WindowsInternals #KernelDriver #EDRhttps://t.co/7apGIY9mIC pic.twitter.com/EkKiC3nmTo

— Raashid Bhat (@raashidbhatt) September 11, 2025


It’s true that NATO would struggle to intercept mass drone/missile salvos in a sustainable & economical way. But that doesn’t mean it’s helpless. In a state of war, it would also go after the launchers at source. Don’t conflate peacetime dilemmas with wartime constraints. https://t.co/dsY7B1fR1V

— Shashank Joshi (@shashj) September 12, 2025


Great writeup from @Intel471Inc!
https://t.co/0oXThWlGUm

— Phrack Zine (@phrack) September 12, 2025


Bugs disclosed in the Shopify program are a goldmine for learning about access control bugs.

Dive into the reports, study the techniques, and level up your skills:https://t.co/n3PSBSHAnx

— Behi (@Behi_Sec) September 12, 2025


Honestly the impact of this incident is really bloody bad https://t.co/I2q8QaFwJV

— mRr3b00t (@UK_Daniel_Card) September 12, 2025


A resource containing all the tools each ransomware gangs useshttps://t.co/6lSLaGOqCD

— Panos Gkatziroulis 🦄 (@netbiosX) September 12, 2025


Multimap

An online tool for comparing online maps side by side. It includes dozens of different maps, including the most up-to-date and well-known ones (Bing, OpenStreetMap), as well as local and historical maps for different countries.https://t.co/JOqunyYQ9n#geoint pic.twitter.com/XOVpWSkyKF

— Cyber Detective💙💛 (@cyb_detective) September 12, 2025


KIM KITSURAGI - "What is it, detective? Can you make it out?"

BULLET - "if you read this you are gay lmao"

1. "It, um, doesn't say anything."

2. "Transgender ideology. My old foe."

3. [Espirit de Corps - Medium 10] "I think you should read it for yourself, Kim."

— yoshimi red (@nise_yoshimi) September 12, 2025


This feels like a threat pic.twitter.com/NtY2GVclB2

— Cranky Federalist (@CrankyFed) September 13, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X