the grugq's newsletter

Subscribe
Archives
September 30, 2024

September 30, 2024

September 30, 2024

strcpy bug in Tony Hawk's Pro to achieve RCEhttps://t.co/XY4wWgyOK5

Credits @Grimdoomer#cybersecurity pic.twitter.com/T2fusrhPhD

— 0xor0ne (@0xor0ne) September 29, 2024


This talk about reversing the iCloud Private Relay implementation is low-key awesome! I was taking a lazy easier approach of injecting into Safari to use it outside of browser, but Heiko goes further, demonstrating a custom client implementation.https://t.co/OtS7AQig99

— Hamid Kashfi (@hkashfi) September 29, 2024


In the future, we won't need programmers; just people who can describe to a computer precisely what they want it to do.

— Jason Gorman @jasongorman@mastodon.cloud (@jasongorman) September 29, 2024


This blog is about PE process injection as implemented in BugSleep backdoor loader. This is an old technique, but I go over why the implementation in the loader is buggy and easily blocked by EDRs.
https://t.co/5LvPBKQIc7

— Nikhil Hegde (@ka1do9) September 29, 2024


China outdoes itself again…

After setting a world record with over 8,000 drones in a light show…

Now they have a 10,000 drone light show.
pic.twitter.com/45lufd4qsh

— Mario Nawfal (@MarioNawfal) September 29, 2024


How do I express that I’m concerned about the people of western NC and I’m also concerned about the potential future global economic disaster because Spruce Pine is the sole producer of ultra pure Quartz for crucibles that all global semiconductor production relies on? pic.twitter.com/pcg4bonoJn

— Fossil Locator (@FossilLocator) September 29, 2024


and what if you set the UDP url to http://localhost:<tcp cups port>/... and injected additional HTTP headers by IPP injection to start the print job? OMFG, it's 0click!!!! my mistake was overestimating how much between the lines ppl can read

— Simone Margaritelli (@evilsocket) September 29, 2024


According to German media, North Korean-linked #Kimsuky hackers targeted Diehl Defense, a German arms company, to steal sensitive military data through fake job offers and a spoof website, tricking individuals into downloading malware.
Article: https://t.co/r93c0854zc

This… pic.twitter.com/IOFKGfpAZc

— Seongsu Park (@unpacker) September 30, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X