cKure Red
2.36K subscribers
70 photos
32 videos
21 files
447 links
The director's cut on critical feeds from InfoSec world ๐ŸŒŽ

Main Channel: @cKure

โ˜•๏ธ or queries email us
๐Ÿ“จ i@ckure.org
Download Telegram
๐Ÿ›ธ Recently recovered Russian Shahed-136 UAVs feature GNSS modules with RTK (Real-Time Kinematic) capability, leveraging 4G/LTE modems for internet-based local correction data, enabling centimeter-level precision. Russia is enhancing its anti-jamming technology with CRPA (Controlled Reception Pattern Antenna) systems to augment the โ€œCometaโ€ GLONASS-based navigation in UMPK glide bombs and Shahed drones.

The current 8-antenna Cometa system offers limited spoofing resistance. A 16-antenna CRPA operating in the L1 band is under development, employing advanced algorithms to enhance spoof resistance. CRPA systems exploit angular discrimination between satellite signals and ground-based jamming by measuring direction and time of arrival.

RTK GNSS integrates satellite and base station data. The base station, connected to a local reference, transmits corrections via mobile networks for precise positioning. Ukrainian networks offering RTK services could potentially be exploited for selective disruptions. Additionally, private RTK systems, such as those used in precision agriculture, may present exploitable vulnerabilities.
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
โšก1
๐Ÿ’ฉ Reverse Engineering a trojan Telegram Clone.

https://dozheiny.net/2024/11/15/Reverse-Engineering-Trojan-Telegram-clone.html
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿงฌ ๐Ÿ”ค๐Ÿ”ค๐Ÿ”ค๐Ÿ”ค (unconfirmed)

Iran's Handala hacking group has hacked Israel's highly secure SSV blockchain network, used by Mossad to manage payments to foreign operatives.

Despite blockchain's reputation for being unhackable, Mossad's $1 million bug bounty challenge was bypassed.

8 TB of sensitive data being stolen, including personal details of their operatives.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿšฎ The SCADA Hack: From Exploits to Forensics: Deciphering the Unitronics Incident.

A hack of a nation state by another nation state amid ongoing genocide by Jews of native indigenous population of Palestine ๐Ÿ‡ต๐Ÿ‡ธ


https://claroty.com/team82/research/from-exploits-to-forensics-unraveling-the-unitronics-attack
Please open Telegram to view this post
VIEW IN TELEGRAM
This media is not supported in the widget
VIEW IN TELEGRAM
๐Ÿ’ฉ8๐Ÿ‘4๐Ÿ‘Ž1๐Ÿคก1
๐Ÿ‡ต๐Ÿ‡ธ Prolific cyber security professional, Dr. Reza Avazeh, architect at Hizbollah and many hacktivist groups was executed by Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ in a drone strike.

In a message by the hacker group, 'Handala': following statement of threat was made:


๐Ÿ˜ˆ Reza Avazeh Operation is coming!

Next Week
Destructive Week


Dr. Reza Avazeh, the former cyber commander of Hezbollah, the commander whose smile in Handala's actions will never be forgotten!

Martyr Reza Avazeh, one of the elites and senior managers of Hezbollah's cyber security, had a Ph.D in computer networks from the University of Tehran, and was martyred on October 20, 2024, along with his wife, engineer Masoume Karbasi, in a drone attack by the Zionist criminal regime in the city of Jounieh!

This cyber security elite was a prominent foundation in the field of Linux and had performed many valuable services in cyber resistance groups! We will never forget your smile! Your revenge is coming!

๐Ÿ’ป Handala-Hack.to
Please open Telegram to view this post
VIEW IN TELEGRAM
โ— Yer another website:
theyseeyourphotos.com

[Google's AI based photo interpreter]
๐Ÿ‘1
โ˜„๏ธ Swagger-UI DOM XSS via DOMPurify library.

example.tld/swagger/ index.html?configUrl=https://xss.smarpo.com/test.json

https://blog.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ2
๐Ÿฆ  LockBit Ransomware Developer Arrested in Israel.

Dual ๐Ÿ‡ท๐Ÿ‡บ Russian-Israeli ๐Ÿ‡ฎ๐Ÿ‡ฑ national Rostislav Panev was arrested last August and is facing extradition to the US for playing a critical role in LockBit's RaaS activities, dating back to the ransomware gang's origins.

https://www.darkreading.com/cyberattacks-data-breaches/lockbit-ransomware-developer-arrested-israel.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ•Š3๐Ÿ”ฅ1
cKure Red pinned Deleted message
๐Ÿ“ฑTool to parse iOS sms.db for SMS messages. Supports message editing and 'unsend'.

https://github.com/h4x0r/parse_sms.db/tree/main
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ†• EXIF Stripper: A web based image-metadata remover utility.

https://ckure.esy.es/rx/tools/exif/

*Images are uploaded on a shared hosting server. This may be concerning even though there is a script that removes the pictures from server after regular intervals.
Other Web Utilities: ckure.esy.es/rx
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿคฃ1
cKure Red pinned ยซ๐Ÿ†• JWT Breaker: A web based client-side JSON Web Token brute-forcing utility. https://ckure.esy.es/rx/tools/jwt/ To generate tokens, use: https://ckure.esy.es/rx/tools/jwt/gen.phpยป