cKure
6.87K subscribers
1.38K photos
395 videos
273 files
12.1K links

This channel was created in 2018 and contains content from the information security domain.

This channel is primarily run by AI bots (n8n).

Archive: ckure.esy.es
Criticals: @ckuRED
linkedin.com/company/ckure

Support 📨 i@ckure.org
Download Telegram
■■■■□ Hackers posing as Kyrgyzstan’s Justice Ministry are spreading 2013-era NetSupport RAT across Kyrgyzstan and Uzbekistan using fake PDFs and old Java tricks—blocking outsiders to hide the attack.
■□□□□ CVE-2025-5318
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.

https://access.redhat.com/errata/RHSA-2025:18231
■■□□□ Pakistan infra targeted on a DoS attack. This is per the threat actor; Keymous group. As they mentioned the following victims taken offline.

NTDC (National Transmission & Despatch Co.)
LESCO (Lahore Electric Supply Co.)
FESCO (Faisalabad Electric Supply Company)
GEPCO (Gujranwala Electric Power Co.)
MEPCO (Multan Electric Power Company)
TESCO (Tribal Electric Supply Co.)
HESCO (Hyderabad Electric Supply Co.)
SEPCO (Sukkur Electric Power Co.)
QESCO (Quetta Electric Supply Co.)
■■■□□ Unconfirmed: GrapheneOS vacates from France amid pressure to implement potential backdoors.
1
Forwarded from cKure Red
🇮🇱Jew Supply-Chain Attack [last week]: New Samsung Galaxy A and M series phones that have entered Gaza via checkpoints (post official but not-working ceasefire) have malfunctioned and one exploded in the hands of Gaza resident. This is second such incident in two days.

This could be the Jewsish supply chain attack as A and M series device by Samsung has a built-in zionist signal intelligence app that collects user telemetric and metadata.

Based on a source around 5K to 10K such devices have entered Gaza.

The app is from Iron Source.
The zionist entity (Israel) has “Iron” in the name of many 🪖 technologies (defense-related):

Iron Beam – Israel. High-energy laser air-defense system.

Iron Fist – Israel. Active protection system for vehicles.

Iron Curtain – US. APS for close-range RPG/missile interception.

Iron Wolf – Lithuania. Mechanized infantry brigade (NATO).

Iron Sting – Israel. Precision 120mm mortar-guided munition.

Iron Vision – Elbit helmet-mounted 360° situational awareness for tanks.
Please open Telegram to view this post
VIEW IN TELEGRAM
😡2🔥1😁1😭1
■■■□□ TOKYO: Japanese beer giant Asahi said Thursday (Nov 27) it was not negotiating with the hackers behind a "sophisticated and cunning" ransomware attack that is about to enter its third month.

"Even if we had a ransom demand, we would not have paid it," CEO Atsushi Katsuki said.


https://www.channelnewsasia.com/east-asia/beer-giant-asahi-not-engaging-ransomware-hackers-5493016
1🥰1
■■□□□ CodeRED emergency alert system CodeDEAD after INC ransomware attack.

Regions across US affected, and one tore up its contract for the product

https://www.theregister.com/2025/11/26/codered_emergency_alert_ransomware/
Forwarded from cKure Red
🔄Tomiris wreaks Havoc: New tools and techniques of the APT group.

https://securelist.com/tomiris-new-tools/118143/
Please open Telegram to view this post
VIEW IN TELEGRAM
■■□□□ 💭💭💭💭 hacktivist group strikes Israel 🇮🇱 again.
Please open Telegram to view this post
VIEW IN TELEGRAM
1🔥1👏1👌1
cKure pinned a photo
■■■□□ Inside 💭 💭💭💭

Origins, Motives, and Methods of a Rapidly Expanding Hacktivist Collective.


ckure.org/archives/18075
Please open Telegram to view this post
VIEW IN TELEGRAM
4🔥32
cKure pinned «■■■□□ Inside 💭 💭💭💭 Origins, Motives, and Methods of a Rapidly Expanding Hacktivist Collective. ckure.org/archives/18075»
■■■■□ Cyber-Attack by Iranian state sponsored hacker group.

The Hendala group announces that it sent flowers to an Israeli scientist, after gaining access to a system allegedly related to the Soreq nuclear center.

It is likely that the flower delivery was carried out by a local collaborator, who placed the bouquet inside the scientist's car and documented the action with several photos and videos.

The attackers publish several screenshots from the system, allegedly showing administrative access and exposure to information about various parties involved in the Seraph project at Soreq (particle accelerator).
cKure pinned «■■■■□ Cyber-Attack by Iranian state sponsored hacker group. The Hendala group announces that it sent flowers to an Israeli scientist, after gaining access to a system allegedly related to the Soreq nuclear center. It is likely that the flower delivery was…»