cKure Red
2.5K subscribers
71 photos
46 videos
21 files
458 links
The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

☕️ or queries email us
📨 i@ckure.org
Download Telegram
Automated pentesting / BugBounty.

https://yogeshojha.github.io/rengine/
Zero-Day in a Vmware product leads to unauthenticated remote code execution via Web interface.

Vmware is aware about the bug and is patching.

There is no patch to the Zero-Day. However, workarounds include use of WAF and disabling features.
☆ FORCEDENTRY: Sandbox Escape. A blog by Google's elite Project zero.

The article documents samples share by CitizenLab of the malware the Israel 🇮🇱 based state-sponsored Cyber-Crime syndicate 'NSO-Group' is infecting devices of people. Which often results in their death or harm to them or their relatives.

https://googleprojectzero.blogspot.com/2022/03/forcedentry-sandbox-escape.html
Pwning a Cisco RV340 with a 4 bug chain exploit as demonstrated in pwn2own competition.

https://blog.relyze.com/2022/04/pwning-cisco-rv340-with-4-bug-chain.html
🔧 Tool: A modern, simple TCP tunnel in Rust that exposes local ports to a remote server, bypassing standard NAT connection firewalls. That's all it does: no more, and no less.

https://github.com/ekzhang/bore
Kernel RCE in FreeBSD via WiFi frames.

https://www.freebsd.org/security/advisories/FreeBSD-SA-22:07.wifi_meshid.asc

Also affects pfSense / OPNsense / etc.
Zero-Day in Java: A researcher has released proof-of-concept (PoC) code for a digital signature bypass vulnerability in Java.

CVE-2022-21449 Proof of Concept demonstrating its usage with a client running on a vulnerable Java version and a malicious TLS server.

https://github.com/khalednassar/CVE-2022-21449-TLS-PoC
Israeli 🇮🇱 Pegasus Spyware — Untold — Chinese Engineering — Samples 1 & 2.

The Israel, unable to create a smart spyware copied code for the app from China 🇨🇳 based APT and purchased Zero-Day from a security researcher from rhe money 💰 of primarily United States' 🇺🇸 taxpayers.

https://jonathandata1.medium.com/pegasus-spyware-untold-chinese-engineering-samples-1-2-e5aba2a0b20b
● Telegram Messenger (as per my analysis) becomes the largest public collection of DarkWeb content, resources, breached data and similar.