the grugq's newsletter

Subscribe
Archives
September 6, 2024

September 6, 2024

September 6, 2024

This is a cool project, shows you what percentage of ads you’re blocking. Tried it on wifi with @The_Pi_Hole doing its thing then on 5G, check the results: https://t.co/huSs5idEvZ pic.twitter.com/Js4v2GIc1N

— Troy Hunt (@troyhunt) September 4, 2024

Test Ad Block - Toolz

Looking for an easy way to check the efficiency of your ad blocker?Toolz offers a simple and beautiful design test that allows you to quickly and easily test the performance of current ad/content blocker solution. Intuitive interface makes it easy to navigate and use, and the beautiful design ensures that the experience is visually appealing. With just a click, you can see how well the ad blocker is working and make any necessary adjustments.


The crux of this vulnerability is an endpoint returning JSON data with a "text/html" Content-Type.

This kind of behavior is trivial to identify with the following bambda: https://t.co/omBfKWiEp2 https://t.co/hAEfSJyeQi

— Mastering Burp Suite Pro (@MasteringBurp) September 3, 2024


CVE-2020-27786 Linux kernel exploit
covering msg_msg + timerfd_ctx + tty_struct and finishing with ROP.https://t.co/rweAvGhQnN

— ii4gsp (@ii4gsp) September 3, 2024


If you take it away, they will find a way. https://t.co/6y6eyXeF4s

— AndrewMohawk ᴺᵒ ˡᵒᵍˢ, ⁿᵒ ᶜʳᶦᵐᵉ (@AndrewMohawk) September 4, 2024


4 exploits, 1 bug: exploiting CVE-2024-20017 4 different ways | hyprblog

a post going over 4 exploits for CVE-2024-20017, a remotely exploitable buffer overflow in a component of the MediaTek MT7622 SDK.


DoJ announcing now: Cyber threat group Cadet Blizzard is Unit 29155. https://t.co/eVMkRKncyB 📷

— Michael Weiss (@michaeldweiss) September 5, 2024


The AUTOK automatic bug hunter is now available as a VSCode extension!

Compatible with most C-like languages (JavaScript, C/C++, even Solidity). Functions offline as well.

Consider enabling it on that junior developer's computer: pic.twitter.com/i5vyWNxnC2

— AIfredo Ortega (@ortegaalfredo) September 5, 2024

Download and documentation available here:https://t.co/jfBMpBKVMz

— AIfredo Ortega (@ortegaalfredo) September 5, 2024


.@m_u00d8 et al.:
No Peer, no Cry. Network Application Fuzzing via Fault Injectionhttps://t.co/njYSjxZadF [PDF] pic.twitter.com/1yDwPAj6xb

— Enno Rey (@Enno_Insinuator) September 1, 2024


https://t.co/1CY27w85eo
Just finished,, exploring cache timing leakages in ZK protocols,, I wonder how it might look in the future with power or more sophisticated side-channel attacks.
any feedback would be cool ;)

— Shibam Mukherjee (@ShibamMukherjii) September 4, 2024


Too lazy to archive my presentation slides, but I finally did it, including the slide on CLFS from the Off-By-One 2024 conference, and the awesome 010 Editor Template to parse CLFS Log file (.blf) by @Mas0nShi https://t.co/cqJdjYAwGy

— Quan Jin (@jq0904) September 5, 2024


Can't help myself.. Taking a look into some of these 32 domains sheds light on a few unmentioned Doppelganger domains still active and personas posting on Twitter. Quick 🧵 https://t.co/3hA8qY1Pho

— Tom Hegel (@TomHegel) September 5, 2024

Thread by @TomHegel on Thread Reader App – Thread Reader App

@TomHegel: Can't help myself.. Taking a look into some of these 32 domains sheds light on a few unmentioned Doppelganger domains still active and personas posting on Twitter. Quick 🧵 lebelligerant[.]io Twitter Accou...…


Anarchist collective teach people how to make pirated versions of expensive pharma drugs using precursor ingredients. "A course of Solvadi, the drug by Gilead that cures Hepatitis C, costs $83,000. We made it for $70." https://t.co/IQyBlCVNkx

— Nate Bear (@NateB_Panic) September 5, 2024


Today, DOJ unsealed an indictment charging Russian GRU military intelligence officers—part of a group known as Unit 29155—with conducting offensive hacking operations before and after the invasion of Ukraine. Read about the indictment and Unit 29155 here: https://t.co/JpxLxfT5NK

— FBI (@FBI) September 5, 2024


Glamorous mistress recorded trysts with Italian minister on ‘spy glasses’https://t.co/yQbbiD12GQ

— Dr. Dan Lomas (@Sandbagger_01) September 6, 2024


I said this so many times: It's not x64 vs ARM.

It's Intel's fab vs TSMC. In this graph we see TSMC 3nm on both latest Intel and latest Apple. This is Intel's first CPU using TSMC.

Also Intel has in-package memory for the first time for x64 SoC. Apple has in-package RAM too. https://t.co/sycNmG1h11

— Sebastian Aaltonen (@SebAaltonen) September 6, 2024


and now @RandomlyWalking remembering how Chris has been a kind mentor, and then diving into how LLMs can be good for code and where they still fail.

With a big kudos to the authors of the Counterfeit Conundrum @theo_olausson pic.twitter.com/0j4H44M2pY

— antonio vergari - hiring PhD students (@tetraduzione) September 5, 2024


Found a 0-day in the Linux Kernel TCP a while back and finally sharing the details! https://t.co/VUgB1cFsEq

— V4bel (@v4bel) September 6, 2024


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X