the grugq's newsletter

Subscribe
Archives
September 15, 2025

September 15, 2025

September 15, 2025

Say hello to Eternal Tux🐧, a 0-click RCE exploit against the Linux kernel from KSMBD N-Days (CVE-2023-52440 & CVE-2023-4130)https://t.co/Cbk9MBo91v

Cheers to @u1f383 for finding these CVEs + the OffensiveCon talk from gteissier & @laomaiweng for inspiration! pic.twitter.com/CsE7gv4HgN

β€” Crusaders of Rust (@cor_ctf) September 14, 2025


All #OrangeCon2025 talks are now online!
Watch them on our YouTube channel: https://t.co/nchTeqVwkP

β€” OrangeCon (@OrangeCon_nl) September 13, 2025


Bootchain exploit for MediaTek devices

PoC exploit for a vulnerability in the Nothing Phone (2a) / CMF Phone 1 secure boot chain (and possibly other MediaTek devices).https://t.co/XM7Ausg6gs pic.twitter.com/xF1k4RjNHI

β€” blackorbird (@blackorbird) September 14, 2025


🀯 Instagram is testing new iOS push notifications that include a profile photo. Each time the notification is shown on your screen, it triggers a GET request to fetch that image, letting Meta track every on-screen impression.

The app still misuses push notifications to send… pic.twitter.com/IUSdpYhdVV

β€” Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ (@mysk_co) September 14, 2025


Lockbit ransomware group, Dragonforce ransomware group, and Qilin ransomware group, have established a truce and are all best friends now

"The enemy of my enemy is my friend" β€” Ransomware groups regarding law enforcement agencies, probably pic.twitter.com/CH8oeCcAYL

β€” vx-underground (@vxunderground) September 15, 2025


Hackers the movie was released 30 years ago today! September 15th 1995.

Hack the planet! pic.twitter.com/2NK0D0PtG4

β€” Justin Elze (@HackingLZ) September 15, 2025


Someone at a16z claimed a few weeks ago that 80% of Bay Area startups are building on Chinese open source models. The graphic below shows Chinese model downloads exceeding US models on HuggingFace. pic.twitter.com/wRoGY1dr9V

β€” Omer Cheema (@OmerCheeema) September 14, 2025


If you're keeping an eye on the Big Sleep issue tracker (https://t.co/1hAhesgXRd) you might have noticed that the detailed reports for some bugs (e.g. https://t.co/xNRb1bxr20) are now public. Note however that all reports are lovingly crafted by a human and not AI-generated.

β€” Ivan Fratric πŸ’™πŸ’› (@ifsecure) September 15, 2025
Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X