cKure Red
2.4K subscribers
70 photos
34 videos
21 files
451 links
The director's cut on critical feeds from InfoSec world ๐ŸŒŽ

Main Channel: @cKure

โ˜•๏ธ or queries email us
๐Ÿ“จ i@ckure.org
Download Telegram
cKure Red pinned ยซโš ๏ธ โ€˜Despicableโ€™ iPhone Hacks In Armenia Find NSO Spyware โ€˜In Active Warzoneโ€™. For the first time, the Israeli companyโ€™s spyware has been used in a conflict zone, according to researchers. In mid-2021, Apple sent a warning to Anna Naghdalyan, then a spokespersonโ€ฆยป
Money message ransomware group hacks MSI and steals BIOS / Intel keys which will enable bad actors to code sign the firmware and send as an update to MSI systems.

MSI Signing Keys for Intel Boot Guard we're released by the group.

Now anyone can sign device firmware with MSI private keys. This represents a long-term persistent risk to be considered by all users.

The data is leaked after MSI ignored to pay the group.

https://vt.tiktok.com/ZSLNqWmTx/

https://www.bleepingcomputer.com/news/security/money-message-ransomware-gang-claims-msi-breach-demands-4-million/

https://www.kaspersky.com/blog/msi-firmware-keys-leak/48300/

https://socradar.io/money-message-ransomware-leaks-msi-signing-keys-for-intel-boot-guard/
cKure Red pinned ยซMoney message ransomware group hacks MSI and steals BIOS / Intel keys which will enable bad actors to code sign the firmware and send as an update to MSI systems. MSI Signing Keys for Intel Boot Guard we're released by the group. Now anyone can sign deviceโ€ฆยป
cKure Red pinned ยซDNS Analyzer - Finding DNS vulnerabilities with Burp Suite. https://sec-consult.com/blog/detail/dns-analyzer-finding-dns-vulnerabilities-with-burp-suiteยป
CVSS 4.0 released
Google Dork - Valuable Extensions.

site:"target[.]com" ext:log | ext:txt | ext:conf | ext:cnf | ext:ini | ext:env | ext:sh | ext:bak | ext:backup | ext:swp | ext:old | ext:~ | ext:git | ext:svn | ext:htpasswd | ext:htaccess
STUXNET - TACTICS & TECHNIQUES.pdf
3.1 MB
A brief peak onto one of the world's most high profile cases involving nation state actors, millions of dollars and thousands of hours of work involving 5 countries across 3 continents over at least half a decade.
Sites scramble to block ChatGPT web crawler after instructions emerge.

User agent token: GPTBot
Full user-agent string: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.0; +https://openai.com/gptbot)


https://arstechnica.com/information-technology/2023/08/openai-details-how-to-keep-chatgpt-from-gobbling-up-website-data/