the grugq's newsletter

Subscribe
Archives
September 26, 2024

September 26, 2024

September 26, 2024

A watering hole campaign against 25 Kurdish websites, which we named #SilentSelfie 📸:
> 4⃣distinct variants identified;
>📱Ranging from geolocation theft to malicious APKs;
> 🔍Operating undetected for over a year.
...and still not attributed.https://t.co/1riP3NtZ3M

— Félix Aimé (@felixaime) September 25, 2024


The BBC sound effects library is now completely free to access.
This is news. https://t.co/jsaSsrIVxB

— Iain McD (@pop_rambler) September 24, 2024

BBC Rewind - Sound Effects

BBC Sound Effects


Most of life's wisdom can be found in chainsaw manuals pic.twitter.com/hQdyY6jGVr

— lcamtuf (@lcamtuf) September 25, 2024


It’s starting https://t.co/1JddvnUYq5 pic.twitter.com/T2DE39UTcB

— Daniel (@growing_daniel) September 26, 2024


This is a good point by @chompie1337 - exdev is usually presented as a single timeline but often it's an iterative process - requiring you to go back to square 1 if for example your primitives aren't quite good enough pic.twitter.com/Ge8Gx8LcB5

— mdowd (@mdowd) September 25, 2024


Scrantic: "@haroonmeer @ThinkstCanary@mastodon.sdf.org Tha…" - Infosec Exchange

Attached: 1 image @haroonmeer @ThinkstCanary@mastodon.sdf.org Thank you so much Haroon & Thinks for your Canary Tokens. I created this token a couple of months ago for our Entra Login without an expectation of if or when it might trigger or how it would look if it did trigger. Well it triggered this morning an email to our service desk, the result of this alert was within 30 minutes we'd completed our investigation revoked all the sessions MFA tokens etc disabled the account identified the...


Google’s cybersecurity unit, Mandiant, has found dozens of US companies have accidentally hired North Korean spies using fake identities as remote workers.

Many of them hold multiple jobs and decline Zoom meetings at work to avoid detection.

This is nutshttps://t.co/Hr8eWCqsuq

— Dare Obasanjo🐀 (@Carnage4Life) September 25, 2024


Phd student Yanyu Chen interviewed Cambodian money launderers who help move money for pig butchering scams

"Like another similar enterprise I had previously visited, their premises was in a dozen hotel rooms above a casino in Sihanoukville that were rented monthly. The managers…

— Zeke Faux (@ZekeFaux) September 25, 2024

https://globalchinapulse.net/moving-bricks-money-laundering-practices-in-the-online-scam-industry/


Eliminating Memory Safety Vulnerabilities at the Source


Google Online Security Blog: Eliminating Memory Safety Vulnerabilities at the Source

Posted by Jeff Vander Stoep - Android team, and Alex Rebert - Security Foundations Memory safety vulnerabilities remain a pervasive threa...

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X