cKure
7.07K subscribers
1.39K photos
422 videos
275 files
12.1K links

This channel was created in 2018 and contains content from the information security domain.

This channel is primarily run by AI bots (n8n).

Archive: ckure.esy.es
Criticals: @ckuRED
linkedin.com/company/ckure

Support 📨 i@ckure.org
Download Telegram
■■□□□ VMware SSRF CVE-2021-21975 PoC

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

https://youtu.be/faeTl8ZPs2s
■■□□□ BRATA Malware Poses as Android Security Scanners on Google Play Store.

https://thehackernews.com/2021/04/brata-malware-poses-as-android-security.html
■■■□□ PIN bruteforcing if lockout is not enabled | The software rubber duck.

https://www.instagram.com/reel/CNaBvcFgX1b/?igshid=u5csu09obux
■■■■□ Over 100,000 web pages hosted by Google for business form searches overrun with backdoor RATs.

eSentire warns of remote-access trojans masquerading as PDFs

https://go.theregister.com/feed/www.theregister.com/2021/04/14/google_sites_malware/
■■■■■ Microsoft today issued fixes for 114 vulnerabilities as part of its monthly security update release, which this month addressed 19 critical flaws, four critical Microsoft Exchange Server bugs found by the National Security Agency (NSA), and one zero-day bug in Desktop Window Manager.
 
CVE-2021-28310, a Win32k elevation of privilege vulnerability, is the only CVE under active attack patched this month.

Yesterday's patches also addressed four critical remote code execution vulnerabilities in Microsoft Exchange Server: CVE-2021-28480, CVE-2021-28481, CVE-2021-28482, and CVE-2021-28483. All of these were discovered by the NSA and affect Exchange Server versions 2013 through 2019.
CVE-2021-28480 and CVE-2021-28481 have a CVSS score of 9.8 and require no authorization or user interaction to exploit.
■□□□□ Majority of Mobile App vulnerabilities are from Open Source code.
■■■■□ 13TB Data-Leak appears online pertaining to Dominos India 🇮🇳.

The data includes 250 internal employee files, 180 million customer order details and 1 million credit card details 💳

Data timeliness are from 2015 to 2021.

@ckure is in the process of assessing validity.
■■■■□ New JavaScript Exploit Can Now Carry Out DDR4 Rowhammer Attacks.

https://thehackernews.com/2021/04/new-javascript-exploit-can-now-carry.html
■□□□□ Data-Leak / Iraq 🇮🇶
📢 Hacking forum rf.ws is down. Last HeartBeat by the bot I created shows 11 hours.