cKure
6.59K subscribers
1.35K photos
320 videos
270 files
12K links

This channel was created in 2018 and contains content from the information security domain.

This channel is primarily run by AI bots (n8n).

Archive: ckure.esy.es
Criticals: @ckuRED
linkedin.com/company/ckure

Support 📨 i@ckure.org
Download Telegram
■■■■■ A decent way to bypass XSS filters, rather WAFs.

https://mobile.twitter.com/0dayCTF/status/1370187588385058819
● Yet another website: RevShells.com [Reverse Shell generator]
cKure
PoC of proxylogon chain SSRF(CVE-2021-26855).py
Currently, there are over 80,000 servers exposed to DearCry ransomware. And exploit code is public (t.me/cKure/7129).

I assume that every hacker (black / white) is busy in their own ways.
■□□□□ #DataLeak: Apple 🍎 is suing a former employee who it claims leaked company trade secrets to a media outlet for over a year for his own personal gain.

Former advanced materials lead and product design architect Simon Lancaster is accused of abusing his position to access information outside of his job scope. He allegedly exchanged the data he stole for payment and positive media coverage of a startup business.

https://www.infosecurity-magazine.com:443/news/apple-sues-employee-for-stealing/
cKure pinned «■■■■■ Microsoft Exchange 2019 - SSRF to Arbitrary File Write (Proxylogon). CVE-2021-27065 CVE-2021-26855 https://www.exploit-db.com/exploits/49637»
■■□□□ #Dridex spotted in #Poland 🇵🇱.

f67aaddc196878449d515e0c337828d8 Payload delivered from: /shahu66.com/rc62n0.rar c2: 162.241.44.26:9443 192.232.229.53:4443 77.220.64.34:443 193.90.12.121:3098

Source: https://mobile.twitter.com/pmmkowalczyk
cKure
■■■□□ #DataLeak at Shirbit, #Israel 🇮🇱. The Black Shadow group has released an ultimatum to release entire dump to anyone who is willing to pay.
■□□□□ #Israel 🇮🇱 based insurance company Shirbit suffered a #DataLeak last year (Q4 2020) and now the threat actors have given final warning ⚠️ and threatened to leak all data.
■■■■■ Google has released proof-of-concept code for conducting a Spectre-based attack against its Chrome browser to show how web developers can take steps to mitigate browser-based side-channel attacks.

Exploit Code repo:
https://github.com/google/security-research-pocs/tree/master/spectre.js

https://www.theregister.com/2021/03/12/google_spectre_code/