the grugq's newsletter

Subscribe
Archives
September 17, 2023

September 17, 2023

September 17, 2023

So, amongst other things, apparently France wants [platforms] to log and block people who use VPNs to access the platforms and use that information to block user activity.

(continues) https://t.co/DJKMenC3Qe

โ€” Alec Muffett (@AlecMuffett) September 16, 2023

New screencast! I filmed myself debugging the SerenityOS Piano app having zero experience with the codebase or OS. ๐Ÿž

In this, I show my approach to working with and debugging unknown systems. A super useful skill to have!

cc @awesomekling ๐Ÿซกhttps://t.co/5GTXmVYxG6

โ€” Mark Mossberg (@offlinemark) September 16, 2023

Gave a guest lecture "Windows Internals Crash Course" at the Ruhr-Universitรคt Bochum today. No novel research, but might be interesting for people getting into started. https://t.co/ggvhtidF5T Thanks to @mr_phrazer for the invite!

โ€” Duncan Ogilvie (@mrexodia) June 29, 2023

Ransomware flingers hit Manchester cops in the supply chain

https://www.theregister.com/2023/09/15/greater_manchester_police_breach_demonstrates/

#SpyNews - week 37 (10-16 September):
A summary of 66 espionage-related stories from week 37 coming from ๐Ÿ‡ณ๐Ÿ‡ด๐Ÿ‡ฒ๐Ÿ‡พ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡ฎ๐Ÿ‡ท๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡ญ๐Ÿ‡ฐ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡ช๐Ÿ‡ท๐Ÿ‡ช๐Ÿ‡น๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ธ๐Ÿ‡พ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ฑ๐Ÿ‡พ๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ง๐Ÿ‡ช๐Ÿ‡ณ๐Ÿ‡ฑ๐Ÿ‡จ๐Ÿ‡ญ๐Ÿ‡ง๐Ÿ‡ท๐Ÿ‡ธ๐Ÿ‡พ๐Ÿ‡ฎ๐Ÿ‡ถ๐Ÿ‡จ๐Ÿ‡ด๐Ÿ‡ท๐Ÿ‡ด๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡ฐ๐Ÿ‡ช๐Ÿ‡ฐ๐Ÿ‡ต๐Ÿ‡ป๐Ÿ‡ณ๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡ฆ๐Ÿ‡น๐Ÿ‡ฏ๐Ÿ‡ด๐Ÿ‡ธ๐Ÿ‡ด๐Ÿ‡ธ๐Ÿ‡จ๐Ÿ‡ง๐Ÿ‡พ๐Ÿ‡ฎ๐Ÿ‡ช๐Ÿ‡จ๐Ÿ‡ฟ๐Ÿ‡ซ๐Ÿ‡ทhttps://t.co/tNjZJmDxT1#Espionage #OSINT #HUMINT #SIGINT

โ€” Spy Collection (@SpyCollection1) September 17, 2023

I just think we should be able to disagree with her politics while also admitting that vaping and giving a handjob at a beetlejuice musical is awesome

โ€” eve6 (@Eve6) September 16, 2023

If you believe a basic machine learning (ML) model based on statistical learning can learn & survive on its own, run & maintain it's own servers & be able persuade military powers to handover nuclear launch codes then yes, you don't have a firm understanding of the basics of ML. https://t.co/2QKnZxhhpF

โ€” Chomba Bupe (@ChombaBupe) September 16, 2023

Do none of these people understand the basics of machine learning?https://t.co/bvs62uK0oh pic.twitter.com/n3BW6aWHRB

โ€” Neel Nanda (@NeelNanda5) September 16, 2023


๐Ÿšจ In light of the recent #UNC3944 adversary activities, the Splunk Threat Research Team has curated specialized security content to help you stay ahead:

๐Ÿ›ก๏ธ Suspicious Okta Activity: https://t.co/JCNTviPtho
๐Ÿšซ Okta MFA Exhaustion: https://t.co/bw7wGf4l70
๐Ÿ› ๏ธ Attacker Tools Onโ€ฆ pic.twitter.com/TgJ9yLnJqy

โ€” The Haagโ„ข (@M_haggis) September 15, 2023

So, the security of your employees' private Google accounts now determines the effectiveness of your MFA. I guess it's a good idea to routinely check their Google accounts on https://t.co/GXEvWgxBe5 - hahahttps://t.co/94y9rWZAVc pic.twitter.com/jQQnWYy7cO

โ€” Florian Roth (@cyb3rops) September 16, 2023

HALT + CATCH FIRE
(Found pencilled into notes on the undefined instructions of the 6800. Notes from 1977) pic.twitter.com/d7s46u9wTU

โ€” Ben Z ๐Ÿ’ช๐Ÿคช๐Ÿคณ๐Ÿผ (@bzotto) September 16, 2023

Alarm over alleged spyโ€™s meeting with Cabinet Office minister https://t.co/zcvAlfSwHx

โ€” Dr. Dan Lomas (@Sandbagger_01) September 16, 2023

Based on Lockbits new rule to only accept ransom payments of 1.5% to 3%, I spoke with a few professional negotiator colleagues this morning. All had similar sentiments but this was general response/feeling to lockbits new rule. This may backfire for #Lockbit. @AL3xL7โ€ฆ pic.twitter.com/2mrDM5G2Ye

โ€” Jon DiMaggio (@Jon__DiMaggio) September 16, 2023

I just published Periscope, a complete adversarial operations toolkit (C2, stagers, agents, automated ephemeral redirectors and task runners, a complete phishing engine, and more).

Read the thread ๐Ÿ‘‡ or jump straight to the repo:https://t.co/Kuv3AdF5Ai

โ€” Tim MalcomVetterโ„ข๏ธ (@malcomvetter) September 16, 2023

BlackCat ransomware hits Azure Storage with Sphynx encryptor - @sergheihttps://t.co/7lZTHqz9Zi

โ€” BleepingComputer (@BleepinComputer) September 16, 2023

There remains a whole unexplored chapter in history on how the post-Cold War reforms to resize U.S. influence/public diplomacy in the 90s created the political economy of the Internet. Internet was the influence machine for democracies by design pic.twitter.com/tdxP0X4nFl

โ€” Pukhraj Singh (@RungRage) September 17, 2023

We applaud Google and Apple for taking privacy from cell-site simulators seriously. There's still more they can do to protect people, but in the meantime, here are some settings to consider changing. https://t.co/PMcQBDyv6P

โ€” EFF (@EFF) September 16, 2023

This is literally a coming of age movie ๐Ÿ˜ญ pic.twitter.com/kRKBGmg9Lu

โ€” Ex Beyonce Fan (@kingbealestreet) September 15, 2023

AI created image from the phrase, โ€œJesus flipping over the tables in the temple.โ€ pic.twitter.com/DgXNodYbES

โ€” Rick Lee James (@RickLeeJames) September 16, 2023

Debugging the undebuggable and finding a CVE in Microsoft Defender for Endpointhttps://t.co/rdNI4Zo8bp

โ€” kmkz (@kmkz_security) September 17, 2023


My @defcon talk on loginjections and malicious ANSI Escape sequences are now available at : https://t.co/0GjJHsd44D pic.twitter.com/qIym1zslhF

โ€” STร–K โœŒ๏ธ (@stokfredrik) September 16, 2023

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X