cKure Red
2.39K subscribers
70 photos
34 videos
21 files
449 links
The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

☕️ or queries email us
📨 i@ckure.org
Download Telegram
💥 VPN Zero-Day

DYK most VPN services can actually make you less secure? Today x.com/PET_Symposium, Benjamin Mixon-Baca will present research done in collaboration with the Citizen Lab about how VPNs can enable an attacker to act as an in-path router between you and the VPN server. The study identifies a new vulnerability called a “port shadow”.
https://petsymposium.org/popets/2024/popets-2024-0070.pdf
Please open Telegram to view this post
VIEW IN TELEGRAM
💥💥💥👉 Breached Forum backend data is publicly searchable.

Includes credentials, registrant IP, and last login IP, among other details.


https://bf.based.re/
Please open Telegram to view this post
VIEW IN TELEGRAM
cKure Red pinned «💥💥💥👉 Breached Forum backend data is publicly searchable. Includes credentials, registrant IP, and last login IP, among other details. https://bf.based.re/»
🎧Basic offensive security tactics for various domains.
Please open Telegram to view this post
VIEW IN TELEGRAM
💥💥💥
‼️‼️‼️

Cyber-Warfare
📍Apparently the Jew ✡️ (Israel) used sonic booms 💥 of fighter jets (apparently F-35s) in Beirut, Lebanon 🇱🇧 and nearby areas during the telecast of Hizbollah chief Hassan Nasrallah's speech to get his location in a corelation attack (had it been live).

https://x.com/Lonewolf8ier/status/1820825946212978816
Please open Telegram to view this post
VIEW IN TELEGRAM
☣️ Project Zero: ‘It Will Take All of Us to End The Era of Zero Days’.

It’s becoming increasingly apparent that security research is not enough to end the era of zero days.
Natalie Silvanovich

https://duo.com/decipher/project-zero-it-will-take-all-of-us-to-end-the-era-of-zero-days
Please open Telegram to view this post
VIEW IN TELEGRAM
cKure Red pinned «☣️ Project Zero: ‘It Will Take All of Us to End The Era of Zero Days’. It’s becoming increasingly apparent that security research is not enough to end the era of zero days. Natalie Silvanovich https://duo.com/decipher/project-zero-it-will-take-all-of-us…»
cKure Red pinned «🍊Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server. https://blog.orange.tw/posts/2024-08-confusion-attacks-en/»
Please open Telegram to view this post
VIEW IN TELEGRAM
💎 Stealth Shell: A Fully Virtualized Attack Toolchain.

https://phrack.org/issues/71/14.html
Please open Telegram to view this post
VIEW IN TELEGRAM
1
🕯 WhenFS turns your Google Calendar into a FUSE filesystem. It whimsically supports the following features:

➡️Create a filesystem out of existing Google Calendars, or create a new one from scratch
➡️Read and write files and directories.
➡️Mount your friends' WhenFS calendar file systems to share files in the silliest way possible

https://github.com/lvkv/whenfs
Please open Telegram to view this post
VIEW IN TELEGRAM
💬 GAZEploit: Remote Keystroke Inference Attack by Gaze Estimation from Avatar Views in VR/MR Devices.

https://sites.google.com/view/Gazeploit/

PDF: https://arxiv.org/pdf/2409.08122
Please open Telegram to view this post
VIEW IN TELEGRAM