the grugq's newsletter

Subscribe
Archives
September 9, 2025

September 9, 2025

September 9, 2025

Great technical writeup on how NodeZero solves Game of Active Directory (GOAD):

TL;DR – How NodeZero Solved GOAD in 14 Minutes:

NodeZero treated the Game of Active Directory (GOAD) like any real environment: no prior knowledge, no humans nudging, just autonomous exploration and…

— Snehal Antani (@snehalantani) August 20, 2025

Here’s a short talk I did on the architecture: https://t.co/hwUtdc1kqD

— Snehal Antani (@snehalantani) September 8, 2025

tl;dr on npm breach, yes the packages had a lot of weekly downloads but the community acted quickly, so the malware-d packages had 0 downloads (according to npm), it was removed in <1hr, and the malware just targeted crypto wallets, so it's not as bad as ppl say

— Katie Paxton-Fear (@InsiderPhD) September 8, 2025

> do largest supply chain attack in history
> potentially infect millions of apps
> doesnt do the thing good
> makes $0 from compromise

I don't wanna support the villain here, but my guy, you gotta lock in. You could have infected hundreds of millions of apps and you FUMBLE IT pic.twitter.com/MUQ0foTC8j

— vx-underground (@vxunderground) September 8, 2025

Live coverage at the attack here, updated as details emerge: https://t.co/opipkzZfP6

— Aikido Security (@AikidoSecurity) September 8, 2025

In 2016, somebody decided to write a worm that compromises Ubiquiti devices, change their hostnames to match how the system was compromised and close off the service. Years later the worm is still active with hundreds of compromised systems: https://t.co/oSjTHEMwck pic.twitter.com/oAZBaFC7dt

— Shodan (@shodanhq) September 8, 2025

My new article on Substack!

Part 3 of "11 Lithuanian #KGB Counterintelligence Operations Against the West in 1955." #spies #coldwar

Based on my ongoing archival research @HooverInst.

The link: https://t.co/qqsyfwyZt3 pic.twitter.com/d0b3V4SyF2

— Filip Kovacevic (@ChekistMonitor) September 8, 2025

🇷🇴 #Romania - 🇲🇩 #Moldova: A former deputy head of Moldova's Intelligence and Security Service has been detained by Romania's anti-terror prosecutors for treason, accused of selling Romanian state secrets to Belarus's "KGB".

He allegedly leaked classified information to… pic.twitter.com/cKBNLVX3zh

— POPULAR FRONT (@PopularFront_) September 8, 2025

🚨 must-read 🚨

A new months-long investigation based on a leak of more than 100,000 internal documents from 🇨🇳 Geedge Networks (积至), co-founded by 🇨🇳 Fang Binxing (方滨兴) — an academician of 🇨🇳 Chinese Academy of Engineering and “the Father of China’s Great Firewall”, has… pic.twitter.com/4VpJPTMGST

— Byron Wan (@Byron_Wan) September 9, 2025


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X