the grugq's newsletter

Subscribe
Archives
September 7, 2022

September 7, 2022

Twitter avatar for @DanWBlack
Dan Black @DanWBlack
A remarkable statement and response from Albania on the cyber attacks impacting the country from mid-July. According to Prime Minister Edi Rama, Albania has severed diplomatic relations with Iran over the incident, with 24 hours notice.
youtube.comKryeministri Edi Rama - 🔮 NjĂ« VENDIM I DETYRUAR I QEVERISË🔮 NjĂ« VENDIM I DETYRUAR I QEVERISË si kundĂ«rpĂ«rgjigje ndaj njĂ« akti tĂ« paprovokuar dhe tĂ« pajustifikuar
10:18 AM ∙ Sep 7, 2022
12Likes7Retweets

-

Twitter avatar for @LandguardNot
Chris Ryde @LandguardNot
The oldest working seagoing paddle steamer Waverley passes by the newest, not working, warship, HMS Prince of Wales, off the Isle of Wight yesterday. Thanks to Chris Glover for this fantastic photo.
Image
3:33 PM ∙ Sep 5, 2022
2,132Likes345Retweets

-

Twitter avatar for @Reaperfeed1
Callsign Batya @Reaperfeed1
Mongolian soldier in Iraq, second time in history since the Siege of Baghdad in 1258. We are working on the article about the Mongolian contingent in Iraq, will be published soon.
Image
5:56 PM ∙ Sep 5, 2022
3,517Likes397Retweets

-

Twitter avatar for @zoyashef
Zoya Sheftalovich @zoyashef
Big story on POLITICO this morning on Putin's microchip shopping list. I was able to see a list of the spare parts Russia is hunting to replenish its arsenal, expended in its war on Ukraine. The list shows Western firms control this chokepoint tech.
politico.euThe chips are down: Putin scrambles for high-tech parts as his arsenal goes up in smokeList seen by POLITICO shows US and allies control chokepoint technologies sought by Moscow.
3:04 AM ∙ Sep 6, 2022
3,997Likes1,475Retweets

-

The attack takes advantage of the fact that the very rich user interface allows displaying formulae in invisible color or in font size zero. This allows to render some code portions invisible when opened using the tool [Mathematica]

Twitter avatar for @TheRealSpaf
Gene Spafford @TheRealSpaf
A fun paper with an example of how UI design choices can introduce weaknesses that a clever attacker may exploit:
eprint.iacr.orgInvisible Formula Attacks
2:23 PM ∙ Sep 6, 2022
15Likes10Retweets

-

[Ed: I seem to have forgotten to include the new Perun video on Sunday. A thousand apologies!]

-

Twitter avatar for @justinschuh
Justin Schuh @justinschuh
This post by @lukOlejnik is far and away the best summary I've seen on the major upcoming changes to privacy on the Web. It does such a good job of distilling the key points that it's a worth a read for anyone who relies on the Web.
blog.lukaszolejnik.comPrivacy architectural changes in the web are comingIn 2019 I argued and explained that we are in the midst of a perfect storm that the privacy debate has caused. I predicted the impact on the web architecture, and the web platform. The thing that billions of people use every day, that is. These very basic building fabrics
5:21 PM ∙ Sep 6, 2022
39Likes16Retweets

-

Twitter avatar for @ThinkstCanary
Thinkst Canary @ThinkstCanary
Some commands are overwhelmingly run by attackers on compromised hosts (and seldom ever by regular users in regular usage). Our @subtee has just released a new (free) Canarytoken to make monitoring these commands trivial. Read more about it - blog.thinkst.com/2022/09/sensit

Image
5:58 PM ∙ Sep 6, 2022
349Likes111Retweets

-

Twitter avatar for @PadraigBelton
PĂĄdraig Belton @PadraigBelton
British woman Liz Trussell, who tweets as @Liztruss, has been spending the morning replying to world leaders and it's possibly the best thing in the history of the internet.
Image
Image
Image
Image
12:01 PM ∙ Sep 6, 2022
56,211Likes7,513Retweets

-

Twitter avatar for @yarden_shafir
Yarden Shafir @yarden_shafir
If you’re interested in Windows IPC mechanisms, this is an excellent series by @0xcsandker:
csandker.ioOffensive Windows IPC Internals 1: Named Pipes · csandker.io
4:56 PM ∙ Sep 6, 2022
278Likes78Retweets

-

Twitter avatar for @lyonwj
William Lyon @lyonwj
So happy my book "Full Stack GraphQL Applications" is now available in print from @ManningBooks that I spent the holiday weekend re-reading it in the hammock! Get your FREE full ebook copy (thanks to @neo4j) here: dev.neo4j.com/graphql-book
Image
4:44 PM ∙ Sep 6, 2022
49Likes18Retweets

-

Twitter avatar for @TheRecord_Media
The Record by Recorded Future @TheRecord_Media
Ten years ago @vx_herm1t had his website shut down by Ukrainian security officials and was charged with distributing computer viruses. Now he's helping his country fend off Russian hackers (via @ddd1ms)
therecord.mediaAn interview with Ukrainian hacker ‘Herm1t’ on countering pro-Kremlin attacksAndrey Baranovich, who is known online as “Herm1t,” spent much of the ’90s and ’00s chronicling the history of malware development on a site known in the hacking community as VX Heaven.
5:01 PM ∙ Sep 6, 2022
60Likes27Retweets

-

Some more info about the Fat Leonard escape. Worth noting that he is now Skinny Leonard after gastric bypass and cancer.

https://news.usni.org/2022/09/06/new-details-revealed-in-fat-leonard-escape-detention-as-manhunt-continues

-

Twitter avatar for @TeenageStepdad
Teenage Stepdad @TeenageStepdad
Image
6:18 PM ∙ Jul 29, 2022
2,175Likes403Retweets

-

Twitter avatar for @flipper_zero
Flipper Zero @flipper_zero
PayPal has blocked our business account and is holding $1.3M for more than 2 months without explaining what exactly they are not happy with. Even @PayPal support doesn't know what's going on. ⚠This endangers the production of Flipper Zero in general. More details in thread 1/5
Image
4:54 PM ∙ Sep 6, 2022
4,807Likes1,628Retweets

-

Twitter avatar for @JoeBeOne
Dr. Joseph Lorenzo Hall @JoeBeOne
On October 18 — three days before Global Encryption Day (@encryption_day) on 21-Oct, the @USPS will release a new stamp honoring women cryptologists of World War II about.usps.com/newsroom/natio

An image of the stamp (description included in accompanying alt-text)
Women Cryptologists of World War II
This stamp honors all the women cryptologists of World War II. One of the conflict’s best-kept secrets, their service played an inestimable role in the Allied victory. The stamp art features an image from a World War II-era recruitment poster for the U.S. Navy’s Women Accepted for Volunteer Emergency Service, whose members were known as WAVES. The image has an overlay of characters from the “Purple” encrypted code, which was used by Japan. In the pane selvage, seemingly random letters can be deciphered to reveal some key words. The reverse side of the pane discloses the cipher needed to read the words. Antonio Alcalá was the art director and designer for the stamp and pane.
1:24 AM ∙ Sep 7, 2022
57Likes28Retweets

-

Twitter avatar for @uncledrunky
Uncle Drunky đŸ„ƒ @uncledrunky
Bad decisions make great stories
12:46 AM ∙ Sep 7, 2022
34Likes13Retweets

-

Twitter avatar for @coleleiter
Cole Leiter @coleleiter
Say what you will about this website.
Image
1:30 AM ∙ Sep 7, 2022
39,244Likes3,055Retweets

-

Twitter avatar for @VickiTurk
Vicki Turk @VickiTurk
I mean this is only like a side note in the piece but like... wow
Image
1:18 PM ∙ Sep 6, 2022
3,103Likes671Retweets

Complete article here on NFTs, gaming, and 
cryptocolonialism?

https://restofworld.org/2022/minecraft-nft-ban-critterz/

-

Twitter avatar for @FbBagholder
Supreme Bagholder @FbBagholder
$META "Defence Budget" is ~$5B/year with >10,000 engineers working on Facebook's defence systems.
This would make it the 43rd highest budget when compared with countries' military expenditure.
4:06 AM ∙ Aug 27, 2022
72Likes16Retweets

-

Twitter avatar for @karissabe
Karissa Bell @karissabe
Almost 3 hours into Musk/Twitter hearing and I actually laughed out loud this exchange: Musk lawyer (re: whistleblower complaint): one might wonder why we didn't discover this in due diligence .. they hid it, that's why Judge: we'll never know.. there was no due diligence
7:59 PM ∙ Sep 6, 2022
5,254Likes493Retweets

-

Continuing saga of kiwi farm

Twitter avatar for @GossiTheDog
Kevin Beaumont @GossiTheDog
Anyhoo, Kiwi Farms new anti-DDoS provider, who also operated as a DDoS attack service, sounds like he could make the ideal new CEO of Cloudflare. bloomberg.com/news/features/

Image
11:21 AM ∙ Sep 6, 2022
249Likes32Retweets
Twitter avatar for @GossiTheDog
Kevin Beaumont @GossiTheDog
Btw, this quote basically sums up my mentions over the past week.
Image
12:54 PM ∙ Sep 6, 2022
425Likes66Retweets

-

The media is seriously lagging behind the info sec curve here.

Twitter avatar for @happygeek
Davey Winder @happygeek
So many people appear to want to believe TikTok was hacked. That's the only conclusion I can draw, seeing as it's now obvious it wasn't. Public data was scraped, and poster banned from Breach Forums for misinformation. #infosec #TikTok #TikTokersleaked
forbes.comTikTok Denies Breach After Hacker Claims ‘2 Billion Data Records’ StolenAfter messages, and sample data, claiming TikTok has been hacked were posted online, TikTok says there’s no evidence of a security breach.
8:36 AM ∙ Sep 7, 2022
17Likes15Retweets

The Info Op is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Don't miss what's next. Subscribe to the grugq's newsletter:
X