the grugq's newsletter

Subscribe
Archives
September 15, 2024

September 15, 2024

September 15, 2024

Security Phd: run fuzzers for days and get an unexploitable bug ๐Ÿคก

Game console players: look at the fbsd kernel for 15 minutes and find a race-condition based UAF ๐Ÿ˜Žhttps://t.co/RXr5dhoxbL

โ€” itewqq (@lyq_sqsp) September 14, 2024


read another paper: An Empirical Assessment of Endpoint Security Systems Against Advanced Persistent Threats Attack Vectors

Took some time, since I'm not that familiar with Windows internals,

Four different attack vectors were used: (CPL) a DLL (.cpl) file which can be executedโ€ฆ pic.twitter.com/U4oQovdQmH

โ€” ajdin (@ajdinre) September 14, 2024


Bytecode Reuse Attack (Part 4) : https://t.co/5p9cvo3NI1

Bytecode Injection (Part 3) : https://t.co/KGASPPibhr

Fundamentals for Bytecode Exploitation (Part 2) : https://t.co/5gTSkE7QGD

Introduction to Android Bytecode Exploitation (Part 1) : https://t.co/D82tu0Vd2Z pic.twitter.com/QsiotxMsKv

โ€” Binni Shah (@binitamshah) September 14, 2024


No need for sci-fi cyberpunk dystopias anymore, these are all real photos from the last few years pic.twitter.com/KiCyiDm0jP

โ€” Sebastiaan de With (@sdw) September 14, 2024


By popular request here is the link to my @BlueTeamCon slide deck on Adventures in Cloud Hacking. Refresh tokens have been revoked to protect the innocent.

There is no recorded video but be on the lookout for one in the future. https://t.co/0RhH59k07Y

โ€” rootsecdev (@rootsecdev) September 14, 2024


New #TradecraftSunday episode! This time we look into how nation-states take advantage of browser extensions/plugins for SIGINT operations.https://t.co/JaWDhq8RN3#SIGINT #cyberespionage #CNE

โ€” Spy Collection (@SpyCollection1) September 15, 2024


OPEN SOURCE INTELLIGENCE (OSINT) NEWS: Realistic Spy Thrillers: Movies Praised by the CIA for Accuracy

A blog about the 17 spy agencies comprising the US Intelligence Community

Looking for some real-deal spy thrillers? Hereโ€™s a list of movies praised by the CIA for their accuracy! ๐Ÿ•ต๏ธโ€โ™‚๏ธ Get ready for suspense that hits close to home. #SpyThrillers #CIA #RealisticEspionage #MustWatch #USA #spymovieshttps://t.co/ESJyoQIqTp pic.twitter.com/H47JSPxXhj

โ€” Robert Morton (@Robert4787) September 14, 2024


OPEN SOURCE INTELLIGENCE (OSINT) NEWS: CIA Numbers Stations- do they still exist?

A blog about the 17 spy agencies comprising the US Intelligence Community


The Way to Android Root: Exploiting Your GPU on Smartphone by Xiling Gong, Xuan Xing, Eugene Rodionov. Slides available at:https://t.co/wyrpO3myhz pic.twitter.com/MiW1sw13Wb

โ€” 8kSec (@8kSec) September 13, 2024


https://diffusionillusions.com


Well, this was a stupid insomnia project, but... ๐Ÿ˜‚

Playground code is here: https://t.co/GQsVFrYsvy https://t.co/KhdbhTJKxN pic.twitter.com/CQxvTUMuZP

โ€” John Hammond (@_JohnHammond) September 13, 2024


#SpyNews - week 37 (September 8-14):
A summary of 62 espionage-related stories from week 37 coming from ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡ฑ๐Ÿ‡พ๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡น๐Ÿ‡ผ๐Ÿ‡พ๐Ÿ‡ช๐Ÿ‡ซ๐Ÿ‡ท๐Ÿ‡ณ๐Ÿ‡ฑ๐Ÿ‡ฎ๐Ÿ‡ท๐Ÿ‡ธ๐Ÿ‡ฆ๐Ÿ‡ฑ๐Ÿ‡ง๐Ÿ‡ณ๐Ÿ‡ด๐Ÿ‡ฐ๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡ต๐Ÿ‡ฑ๐Ÿ‡ง๐Ÿ‡พ๐Ÿ‡ธ๐Ÿ‡ช๐Ÿ‡ง๐Ÿ‡ฉ๐Ÿ‡ฆ๐Ÿ‡ฑ๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡ฌ๐Ÿ‡ช๐Ÿ‡จ๐Ÿ‡ฟ๐Ÿ‡ณ๐Ÿ‡ฌ๐Ÿ‡ฐ๐Ÿ‡ฟ๐Ÿ‡ฐ๐Ÿ‡ฌ๐Ÿ‡น๐Ÿ‡ฏ๐Ÿ‡บ๐Ÿ‡ฟ https://t.co/DdwSCrkLXp#espionage #OSINT #SIGINT #HUMINT #spy

โ€” Spy Collection (@SpyCollection1) September 15, 2024


This is certainly one way to frame thingsโ€ฆ

>Microsoft paves the way for Linux gaming success with plan that would kill kernel-level anti-cheat

>Microsoft has officially announced its intent to move security measures out of the kernel, following the Crowdstrike disaster a few short months ago.
The removal of kernelโ€ฆ pic.twitter.com/RW0NAbHvg9

โ€” Pirat_Nation ๐Ÿ”ด (@Pirat_Nation) September 14, 2024


Oof, AWS had a bug that allowed Transit Gateway peering requests to be accepted by the requestor, so an attacker could accept their own requests and peer to any gateway. The prevention logic for this was only in the web console UI, not the API. ๐Ÿ˜ž https://t.co/DZLcWSaROh

โ€” Scott Piper (@0xdabbad00) September 15, 2024


https://t.co/TjJhsc5bfyhttps://t.co/h6PBuJbwcM

Great job @0x10n https://t.co/lAf5EjmZ72 pic.twitter.com/xIOpSLSHeQ

โ€” xvonfers (@xvonfers) September 14, 2024


PS5's umtx exploit for Lua?https://t.co/Xtt73vtDZW

โ€” Aleksei Kulaev (@flat_z) September 14, 2024

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X