the grugq's newsletter

Subscribe
Archives
September 17, 2025

September 17, 2025

September 17, 2025

Quite a good Between Two Nerds discussion.

Between Two Nerds: The limits of cyber power - Risky Business Media


OpenAI literally just leaked what people use ChatGPT for pic.twitter.com/gZj5Me9Fxo

— Yu Lin (@basicprompts) September 15, 2025


Big drama today in the Tor community.

Conrad Rockenhaus, a Tor operator based out of Michigan, United States, was arrested in 2020 after refusing to cooperate with the United States Federal Bureau of Investigation

Rockenhaus, a disabled United States military veteran, ran the…

— vx-underground (@vxunderground) September 16, 2025


Do yourself a favor and set this in your pnpm config https://t.co/RnS5hFvVT3 pic.twitter.com/FD014hld3b

— Sawyer Hood (@sawyerhood) September 15, 2025


I've updated my #VulnerabilityResearch and #ReverseEngineering tools to use the latest version of @binarly_io #idalib #Rust bindings, which support @HexRaysSA IDA Pro 9.2 and their freshly open-sourced SDK.https://t.co/MbMFvjHrtThttps://t.co/c4hLimHqWuhttps://t.co/wPsWzyUax3

— raptor@infosec.exchange (@0xdea) September 16, 2025


Yesterday, my colleague Andreas Grasser published a tech blog article titled "Windows local privilege escalation through the bitpixie vulnerability".

I can highly recommend this article to learn more about this boot vulnerability and its mitigations.https://t.co/uFCybrfW2r

— Matthias Deeg (@matthiasdeeg) September 16, 2025


This is an interesting interaction of multiple pieces of web infrastructure. An emergent property of the system.

  • YouTube pays creators based on view counts
  • EasyPrivacy list added YouTube’s telemetry url to the block list
  • Ublock Origin incorporated the new EasyPrivacy list
  • YouTube creator view counts drop significantly
  • Google AdSense payments decrease
  • YouTube doesn’t promote the videos as much (maybe?)

tl;dr adblockers started blocking YouTube telemetry and now people make less money from YouTube videos

TL;DR: The YouTube view drops are because of the EasyPrivacy list adding the URL "youtube[.]com/api/stats/atr" on August 11th. Causing Adblockers to block view counting telemetry.

The blocked merged into UbO Lite on August 12th, pushed to chrome webstore by next day.

It… https://t.co/S1zNzr7EEq

— ThioJoe (@thiojoe) September 16, 2025


In a pickle with ML security?
We added a new pickle file scanner to Fickling that enhances supply-chain security 🧵 pic.twitter.com/DDaUU9T0tC

— Trail of Bits (@trailofbits) September 16, 2025

Fickling’s new AI/ML pickle file scanner -The Trail of Bits Blog

We’ve added a pickle file scanner to Fickling that uses an allowlist approach to protect AI/ML environments from malicious pickle files that could compromise models or infrastructure.

GitHub - trailofbits/fickling: A Python pickling decompiler and static analyzer

A Python pickling decompiler and static analyzer. Contribute to trailofbits/fickling development by creating an account on GitHub.


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X