cKure Red
2.39K subscribers
70 photos
34 videos
21 files
449 links
The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

☕️ or queries email us
📨 i@ckure.org
Download Telegram
🟥 Microsoft launches CoPilot AI on telegram as a bot.

@CopilotOfficialBot
Please open Telegram to view this post
VIEW IN TELEGRAM
🗞 State-sponsored terrorism by Israel 🇮🇱 caught by OpenAI.

OpenAI bans accounts of the mercenaries. Facebook (Meta) follows suit.

Disrupting deceptive uses of AI by covert influence operations.

We have terminated accounts linked to covert influence operations; no significant audience increase due to our services.
-OpenAI

Official statement:
https://openai.com/index/disrupting-deceptive-uses-of-AI-by-covert-influence-operations/

Supporting article by journalists in Israel: https://www.timesofisrael.com/openai-says-it-disrupted-covert-influence-operation-by-israeli-firm-stoic/

Stoic also acted to meddle with elections in India 🇮🇳

https://www.business-standard.com/elections/lok-sabha-election/openai-report-on-lok-sabha-polls-zero-zeno-what-is-israeli-firm-stoic-and-how-it-tried-to-disrupt-lok-sabha-polls-2024-124060100518_1.html
Please open Telegram to view this post
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
Israel 🇮🇱 Palestine 🇵🇸 conflict
Title: Disinformation campaign

Company name: Stoic (Tel Aviv).
Subtitle: The lying Jew ✡️

The company's goal is to spread lies and form a narrative that supports the criminal state; starting at home in Israel.

The company created bots that mimicked African American students and Jewish students as if they were concerned. These accounts commented on Facebook and Instagram in favor of genocide in the Muslim lands (Gaza, Palestine 🇵🇸).
cKure Red pinned «✔️ BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution. https://google.github.io/security-research/pocs/linux/bleedingtooth/writeup.html»
This media is not supported in your browser
VIEW IN TELEGRAM
✔️ Zero-Day: Breaking BitLocker via MitM between CPU and TPM chip.
Please open Telegram to view this post
VIEW IN TELEGRAM
cKure Red pinned a video
🤍Rockyou-2024 has been released on July 4, 2024, in a 45 GB zip file.

Previous Rockyou-2021 had 8.4 billion passwords, and the new version has 1.5 billion (added by hacker 'ObamaCare'), making it a 10 billion word-list.
Please open Telegram to view this post
VIEW IN TELEGRAM
p25.pdf
593.2 KB
🖥 Header Enrichment: A technique used by Telco operators to acquire MSISDN (phone number) through a website (HTTP-GET is enough).

It can be used to trace users and target them for ads by the ISP or their associated vendors. And if the API key 🔑 is leaked through a vendor or ISP itself.

Scenarios:
1. The token can be used by anyone in a get request to fetch the end-user's phone number. This request can be posted via QR-codes of restaurant menus where there will be HTTP-302 (redirection) to the actual menu or by injecting 💉.js in a vulnerable website (viz. XSS); which is famous (like some blog or forum).

2. A user sharing hotspot from their phone, the hotspot client can acquire the phone number. In addition to this, if the HE enables authentication. This would lead to 0-click account takeover.


● I had tested systems for this implementation for a telco. The telco without informing users (IMHO) was sharing data to third parties.
-Admin cKure


Source: https://conferences.sigcomm.org/sigcomm/2015/pdf/papers/hotmiddlebox/p25.pdf
Please open Telegram to view this post
VIEW IN TELEGRAM