March 30, 2023
Between Two Nerds: The Real Problem with TikTok
The best podcast has released another episode.
-
Google finds more Android, iOS zero-days used to install spyware
-
New: for years instead of getting a warrant, the DEA paid rogue employees inside U.S. airline, bus, and parcel private companies for access to reams of customer data. Bypassed the courts and simply bought info instead. Senators now trying to stop it.
-
-
-
-
Just finished Bruce’s book on undersea cable telegraphy and I’m pleased to say it is a great read. Undersea cable telegraphy is such a fascinating topic and there’s so much more work to be done on this subject.
Aaron Bateman @aaronbateman22
-
-
So it turns out that police can touch fentanyl without having a seizure.
-
New WiFi vulns that downgrade power save buffered frames! As always @vanhoefm has usable code ready to go, this time without limitations to specific atheros cards. The readme is also super accessible if you aren’t the type to read the paper.
-
MacOS malware expert @patrickwardle has been covering the MacOS variant of the 3CX VOIP supply chain attack.
Additionally, we have managed to get our hands on the MacOS variant.
Download: share.vx-underground.org
Patrick Wardle @patrickwardle
-
-
Thrilled to see my new @IISS_org paper covered here alongside an excellent report from @MsftSecIntel on recent GRU activity.
-
-
-
"It is evident that the Russian special services managed to recruit a large agent network in Ukraine ... and that much of the support apparatus has remained viable after the invasion, providing a steady stream of human intelligence to Russian forces".
-
There is a fallacy in the "AI will cause unemployment" discussion that employment is related to the amount of work that needs to get done.
This is not actually the case.
Employment in large orgs is more driven by resource allocation politics than actual work.
-
“When the police hit you with teargas but you still need to smoke”
-
-
-
somewhere on Wall Street there is a computer like this running an excel spreadsheet where if someone shuts the lid the whole world economy comes to a halt https://t.co/M6zdiC75Qa
Jed Bridges @JedBridges
@Duderichy @thegrugq I know of a bank in my home country that had an outage and couldn't take on new clients because they reached the maximum number of lines in an Excel file (at the time at least)🙈
-
I hacked into a @bing CMS that allowed me to alter search results and take over millions of @Office365 accounts.
How did I do it? Well, it all started with a simple click in @Azure… 👀
This is the story of #BingBang 🧵⬇️
BingBang: The AAD misconfiguration that led to Bing.com results manipulation and account takeover explained
https://www.wiz.io/blog/azure-active-directory-bing-misconfiguration
-
A Q&A with the hacktivists rocking Latin America: Guacamaya
https://therecord.media/interview-with-guacamaya-hacktivist-group-latin-america
-
Really happy to announce that @helenawoodfield's and my new book 'The Language for Fake News' has finally been published by @CambUP_LangLing!
Please check it out! It's a quick read and can be downloaded in full for free (forever)!
doi.org/10.1017/978100…
A thread...
-