the grugq's newsletter

Subscribe
Archives
September 22, 2023

September 22, 2023

September 22, 2023

Want to see a crazy trade?

Yesterday, someone OPENED $SPLK 127 calls, for $22,000, expiring tomorrow.

Then today Cisco Systems $CSCO announced acquiring Splunk for $28B, $SPLK up 20%.

The contracts were $0.04 yesterday, now $18.30.

They exited today for a 45,650% return... pic.twitter.com/uP6BnNzscp

— unusual_whales (@unusual_whales) September 21, 2023

The MGM Grand is looking to hire a Red Hat Linux System Admin willing to work 10 hours per day 7 days a week to completely rebuild its IT environment from the ground up and get the slot machines working again. (h/t @zero04013437) pic.twitter.com/m7IqukzQP7

— Las Vegas Locally 🌴 (@LasVegasLocally) September 21, 2023

"The WebP 0day" -- a full technical analysis the recently patched vulnerability in the WebP image library that was exploited in the wild (CVE-2023-4863). https://t.co/6yUcE9sOZa

— Ben Hawkes (@benhawkes) September 21, 2023

At @labscon_io, @juanandres_gs and I reviewed the use of Lua in #APT activities, from as early as 2005 to just a few weeks ago.

Meet the new #Sandman APT and its novel Lua-based backdoor: LuaDream.

A thread🧵https://t.co/3e4JpMTpKd

— Aleksandar Milenkoski (@milenkowski) September 21, 2023

Part of the reason people worry about misinformation: They think other people are gullible and easily misled (unlike them). Meanwhile, the other people think the same thing. https://t.co/o8rNXGAU0m pic.twitter.com/8F7hoasChj

— Steve Stewart-Williams (@SteveStuWill) September 20, 2023

I saw a tweet asking why sometimes when you unsubscribe from an email list it says it can ‘take a few days’. Buckle up, as I have a RIDICULOUS story about this happening in The Enterprise™️...

— Joe Pettersson (@Joe8Bit) July 30, 2019

Shinzo Abe Assassination Cosplay 😭 pic.twitter.com/QfZanohIu2

— KMCHNH (@KHAMCHANH) September 6, 2023

I really appreciate the way this report clearly translates offensive tradecraft into defensive ideas https://t.co/jaL1IPAiK8 pic.twitter.com/dFdJJRyr0J

— Jamie Williams (@jamieantisocial) September 20, 2023

Beware of LUCR-3! 🚨 Threat actor that overlaps with Scattered Spider, Oktapus, UNC3944, & STORM-0875, they exploit IDPs for initial access & aim to steal IP for extortion. They use victims' tools and evade detection with expertise. @permisosecurity https://t.co/WEbwLJkBWY

— 1aN0rmus (@TekDefense) September 20, 2023

—

pic.twitter.com/wk8UF8yruX

— internet hall of fame (@InternetH0F) September 21, 2023

pic.twitter.com/95wSJ1e8N7

— internet hall of fame (@InternetH0F) September 21, 2023

David Brooks is getting cooked on Facebook by an airport bar and grill, social media's best days are still ahead pic.twitter.com/SVSpMdtwch

— Tom Gara (@tomgara) September 22, 2023

‘Be careful what you wish for’ DoD official warns separate cyber force could pose new challenges: https://t.co/CYSpssu7GW

— Electrospaces (@electrospaces) September 21, 2023

Significant words from US NSA Jake Sullivan today on Trudeau’s allegations against India: “There’s not some special exemption you get for actions like this.” He was essentially saying India shouldn’t get a free pass-something you rarely hear from US officials speaking publicly.

— Michael Kugelman (@MichaelKugelman) September 21, 2023

ChatGPT becoming more human by the day pic.twitter.com/j6iKwpkRkM

— Dara (@daraladje) September 21, 2023

Understanding the internals of #Rust and learn how Rust code maps to assembly
Collection of blog posts by @eventhelix)https://t.co/MaACB6DTwH#rustlang #reverseengineering pic.twitter.com/UEehtAq19w

— 0xor0ne (@0xor0ne) September 21, 2023

The problem of bogus CVEs

The bogus CVE problem [LWN.net]

The "Common Vulnerabilities and Exposures" (CVE) system was launched late in the previous century (September 1999) to track vulnerabilities in software. Over the years since, it has had a somewhat checkered reputation, along with some some attempts to replace it, but CVE numbers are still the only effective way to track vulnerabilities. While that can certainly be useful, the CVE-assignment (and severity scoring) process is not without its problems. The prominence of CVE numbers, and the cons...


My dystopian vision of an AI-powered future is that LLMs drives down the cost of generating long text even further, and the only way for readers to keep up is to use LLMs to summarize. https://t.co/Ri6qdshniE

— Erik Bernhardsson (@bernhardsson) September 22, 2023

Raising the retirement age reduces grandparent childcare supply https://t.co/T10FMgmwZH

— James Medlock (@jdcmedlock) September 22, 2023

cool to see the UK continuing their tradition of inexplicable hostility to cryptographers and encryption technologists. hey at least the monarchy issued a token apology for turing 60 years later

— suzuha⚡️🌙 (@dystopiabreaker) September 20, 2023

A U.S. government contractor was arrested on Aug. 24 based on espionage charges in a complaint unsealed today. Abraham Teklu Lemma, 50, a naturalized U.S. citizen of Ethiopian descent, of Silver Spring, Maryland, is charged with delivering national defense information to aid a foreign government,…

…, between on or about Dec. 19, 2022, and Aug. 7, 2023, Lemma copied classified information from intelligence reports and deleted the classification markings from them. Lemma then removed the information, which was classified as SECRET and TOP SECRET, from secure facilities at the Department of State. This material related to a specific country and/or geographic region...

…, Lemma used an encrypted application to transmit classified national defense information to a … foreign country’s intelligence service. In these communications, Lemma expressed an interest and willingness to assist the foreign government official by providing information. In one communication, the foreign official stated, “[i]t’s time to continue ur support.” Lemma responded, “Roger that!” In other chats, the foreign official tasked Lemma to focus on information related to particular subjects, and Lemma responded “[a]bsolutely, I have been focusing on that all this week . . . .”

…, the classified national defense information Lemma transferred to the foreign official included satellite imagery and other information regarding military activities in the foreign country and region.

U.S. Government Contractor Arrested on Espionage Charges @FBIWFO https://t.co/vrus0pZS01

— FBI (@FBI) September 21, 2023

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X