cKure Red
2.51K subscribers
71 photos
46 videos
21 files
458 links
The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

☕️ or queries email us
📨 i@ckure.org
Download Telegram
🔧 Tool: A modern, simple TCP tunnel in Rust that exposes local ports to a remote server, bypassing standard NAT connection firewalls. That's all it does: no more, and no less.

https://github.com/ekzhang/bore
Kernel RCE in FreeBSD via WiFi frames.

https://www.freebsd.org/security/advisories/FreeBSD-SA-22:07.wifi_meshid.asc

Also affects pfSense / OPNsense / etc.
Zero-Day in Java: A researcher has released proof-of-concept (PoC) code for a digital signature bypass vulnerability in Java.

CVE-2022-21449 Proof of Concept demonstrating its usage with a client running on a vulnerable Java version and a malicious TLS server.

https://github.com/khalednassar/CVE-2022-21449-TLS-PoC
Israeli 🇮🇱 Pegasus Spyware — Untold — Chinese Engineering — Samples 1 & 2.

The Israel, unable to create a smart spyware copied code for the app from China 🇨🇳 based APT and purchased Zero-Day from a security researcher from rhe money 💰 of primarily United States' 🇺🇸 taxpayers.

https://jonathandata1.medium.com/pegasus-spyware-untold-chinese-engineering-samples-1-2-e5aba2a0b20b
● Telegram Messenger (as per my analysis) becomes the largest public collection of DarkWeb content, resources, breached data and similar.
An advanced threat actor has leaked data of multiple institutions, organizations, nation-states and civilians in varying forms (PII, documents, credentials and similar).

The data collage is huge and we (t.me/ckure) have received the copy.

Some leaks were previously public. However, some are either new or were previously unreported.
Multiple bugs chained to takeover Facebook Accounts which uses Gmail. ($42K)

https://ysamm.com/?p=763
Proof-of-concept exploit release: nginx mp4 module DoS & Infoleak Vulnerability (2018) by @alisaesage.

Proof-of-concept exploit that demonstrates an out of bounds read in nginx v1.15.5 heap. This can be worked up to an information disclosure exploit with a bit of extra work. The bug itself, and potentially the exploit, affects earlier nginx versions to some extent.

https://zerodayengineering.com/exploits/nginx-mp4-infoleak.html
"Masato Kinugawa vs Microsoft Teams" live from Pwn2Own Vancouver 2022.

https://t.co/EeQLS2Sbwfhttps://youtu.be/3fWo0E6Pa34
Zero-Day: When Windows Active Directory is newly installed and settings are not changed, any user can create 10 computer accounts.

using this command
"djoin /PROVISION /DOMAIN <fqdn> /MACHINE cKPC /SAVEFILE C:\temp\cKPC.txt /DEFPWD /PRINTBLOB /NETBIOS cKPC"

This will create the computer account named cKPC with the password cKPC.

Credits: Qusai Alhaddad
Zero-Day: iOS 15.1 jailbreak demonstration (dev - @xina520). iOS151.

https://youtu.be/f_zFmmgj860