- The Grugq's Newsletter
- Posts
- March 30, 2023
March 30, 2023
Between Two Nerds: The Real Problem with TikTok
The best podcast has released another episode.
-
Google finds more Android, iOS zero-days used to install spyware
-
New: for years instead of getting a warrant, the DEA paid rogue employees inside U.S. airline, bus, and parcel private companies for access to reams of customer data. Bypassed the courts and simply bought info instead. Senators now trying to stop it.
— Joseph Cox (@josephfcox)
3:07 PM • Mar 29, 2023
-
-
Adding to the reading pile 👀
— Dr. Dan Lomas (@Sandbagger_01)
3:35 PM • Mar 29, 2023
-
love those PLA side hustles
— yoshimi battles the xiaofenhong (@nise_yoshimi)
12:43 PM • Mar 29, 2023
-
Just finished Bruce’s book on undersea cable telegraphy and I’m pleased to say it is a great read. Undersea cable telegraphy is such a fascinating topic and there’s so much more work to be done on this subject.
— Aaron Bateman (@aaronbateman22)
3:30 PM • Mar 29, 2023
-
China's Nuclear Energy Sector Targeted in Cyberespionage Campaign - SecurityWeek securityweek.com/chinas-nuclear…
— Adam Segal (@[email protected]) (@adschina)
7:44 PM • Mar 29, 2023
-
So it turns out that police can touch fentanyl without having a seizure.
Here is our story
— Jonah Owen Lamb (@jonahowenlamb)
1:50 AM • Mar 30, 2023
-
New WiFi vulns that downgrade power save buffered frames! As always @vanhoefm has usable code ready to go, this time without limitations to specific atheros cards. The readme is also super accessible if you aren’t the type to read the paper.
— Dominic White 👾 (@singe)
5:51 AM • Mar 29, 2023
-
MacOS malware expert @patrickwardle has been covering the MacOS variant of the 3CX VOIP supply chain attack.
Additionally, we have managed to get our hands on the MacOS variant.
Download: share.vx-underground.org
— vx-underground (@vxunderground)
6:21 AM • Mar 30, 2023
-
Backend dev doing CSS
— Basharath (@wahVinci)
3:43 PM • Mar 2, 2023
-
Thrilled to see my new @IISS_org paper covered here alongside an excellent report from @MsftSecIntel on recent GRU activity.
— Dan Black (@DanWBlack)
8:06 AM • Mar 30, 2023
-
nzherald.co.nz/nz/proceedings…
— Dr. Dan Lomas (@Sandbagger_01)
7:56 AM • Mar 30, 2023
-
-
"It is evident that the Russian special services managed to recruit a large agent network in Ukraine ... and that much of the support apparatus has remained viable after the invasion, providing a steady stream of human intelligence to Russian forces".
— Dr. Dan Lomas (@Sandbagger_01)
4:25 PM • Mar 29, 2023
-
There is a fallacy in the "AI will cause unemployment" discussion that employment is related to the amount of work that needs to get done.
This is not actually the case.
Employment in large orgs is more driven by resource allocation politics than actual work.
— Halvar Flake (@halvarflake)
4:34 PM • Mar 29, 2023
-
“When the police hit you with teargas but you still need to smoke”
📸 Le calme pendant la tempête.
Rennes, 23 mars.— Vincent Dain (@v_dain)
10:14 AM • Mar 27, 2023
-
Head of cyber for the treasury of Britain.
£57k— Jon (@Jontafkasi)
9:41 PM • Mar 29, 2023
-
I emotionally manipulated GPT-4 into revealing its prompt
— Mehran Jalali (@mehran__jalali)
7:59 PM • Mar 29, 2023
-
somewhere on Wall Street there is a computer like this running an excel spreadsheet where if someone shuts the lid the whole world economy comes to a halt
— Rich (me/acc) 🍀 (@Duderichy)
3:47 AM • Mar 28, 2023
@thegrugq I know of a bank in my home country that had an outage and couldn't take on new clients because they reached the maximum number of lines in an Excel file (at the time at least)🙈
— Jonathan 🇿🇦🇺🇦 (@JonoCoetzee)
8:52 AM • Mar 30, 2023
-
I hacked into a @bing CMS that allowed me to alter search results and take over millions of @Office365 accounts.
How did I do it? Well, it all started with a simple click in @Azure… 👀
This is the story of #BingBang 🧵⬇️— Hillai Ben-Sasson (@hillai)
6:33 PM • Mar 29, 2023
BingBang: The AAD misconfiguration that led to Bing.com results manipulation and account takeover explained
-
A Q&A with the hacktivists rocking Latin America: Guacamaya
-
Really happy to announce that @helenawoodfield's and my new book 'The Language for Fake News' has finally been published by @CambUP_LangLing!
Please check it out! It's a quick read and can be downloaded in full for free (forever)!
doi.org/10.1017/978100…
A thread...
— Jack Grieve (@JWGrieve)
12:38 PM • Mar 29, 2023
-
Reply