cKure Red
2.55K subscribers
72 photos
51 videos
21 files
465 links
The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

β˜•οΈ or queries email us
πŸ“¨ i@ckure.org
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
Declassified: Shreya Pharmaceuticals purchased 1,100 XE9680 Dell servers with Nvidia's H100 GPUs at behest of Russia to train computer models for software to be used in automated drones.
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ’½ Phantomdrive is an open-source USB drive designed to conceal its actual capacity. Upon initial insertion, the device presents itself as an 8GB disk. To access the secondary partition, a file named "unlock.txt" must be created, followed by the entry of the password; the drive will subsequently unmount and remount, revealing the remaining data. All data is encrypted in place using an AES-256 key derived from the password. This mechanism is fundamentally different from how Veracrypt operates.
Please open Telegram to view this post
VIEW IN TELEGRAM
1πŸ”₯1😁1πŸ€”1πŸ™ˆ1
This media is not supported in your browser
VIEW IN TELEGRAM
IoT side channel (correlation) attack using WiFi.

Heuristic surveillance data is both widely under-reported and difficult to mitigate without tossing your devices and living in the stone age.
1πŸ”₯2
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ†’πŸ†’πŸ†’πŸ†’πŸ”’πŸ”’
FAST16 β€” Pre-Stuxnet Sabotage Malware (2005)

- Referenced in Shadow Brokers (2017) leak (β€œNOTHING TO SEE HERE”)
- Compiled ~2005 β†’ ~5 years before Stuxnet
- Type: Sabotage malware (not espionage)

Target

- High-precision engineering / simulation software
- Includes LS-DYNA, PKPM, MOHID
- Used for physics, impact, and advanced simulations (incl. nuclear-related domains)

Technique

- Kernel driver: "fast16.sys"
- In-memory patching of target processes
- Injects subtle calculation errors (floating-point manipulation)
- Goal: corrupt outputs while appearing normal

Propagation

- Worm-like spread via weak Windows network shares

Attribution

- Not confirmed
- Strong suspicion: US or allied origin (based on NSA-linked leak context)

Note

- LS-DYNA β‰  purely β€œexplosive software”
- Broader simulation usage; β€œexplosive calculations” is a subset use case
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯3πŸ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ…°οΈπŸ…°οΈπŸ…°οΈπŸ”’πŸ…°οΈπŸ…°οΈπŸ…°οΈ
Devcore team chained ⛓️‍πŸ’₯ 4 logic bugs to achieve sandbox escape in Microsoft Edge in PwnΒ²Own 2026, Berlin.
Please open Telegram to view this post
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
⚠️⚠️⚠️⚠️⚠️⚠️
CVE-2026-0073: Critical Android Zero-Click, Zero-Day exploit in wireless debugging (if enabled) can allow adjacent hacker (in same network) to execute code as shell user.
Please open Telegram to view this post
VIEW IN TELEGRAM
❀2
cKure Red pinned a video
This media is not supported in your browser
VIEW IN TELEGRAM
🀩 ❗️❗️❗️❗️❗️❗️

LLM used to make a Zero-Day by APT group on a popular software.

The zero day was a 2FA bypass via logic bug πŸͺ²

Security researchers at Alphabet’s Google said they believe a cybercrime group used artificial intelligence to create a hacking tool that can bypass defenses in a widely-used tool to administer computer systems. The scheme, which was foiled when Google alerted the tool developer, would mark the first time that Google’s Threat Intelligence Group caught a hacker using an AI-generated β€œzero-day” in such a way, according to a report published Monday.
Please open Telegram to view this post
VIEW IN TELEGRAM
2
This media is not supported in your browser
VIEW IN TELEGRAM
πŸš€40K Starlink terminals hacked to lure Russians into a cyber trap as per anti-Russia propaganda news.

40,000 Starlink terminals go dark. Russian soldiers scramble for answers and turn to Telegram. They don’t realise they’ve just walked into a trap. The journalists travelled across Ukraine from Lviv to the front line in Zaporizhzhia to uncover a pretty audacious cyber operation. Meet Goldfinger and the 256 Cyber Assault Brigade and Yaro, and the 128th Mechanised Brigade, holding the line in the south.
Please open Telegram to view this post
VIEW IN TELEGRAM
❀1
πŸ€– πŸ†’πŸ†’πŸ†’πŸ†’πŸ†’πŸ†’
Earlier today Cloudflare's CSO shared how they tested Anthropic Mythos using an unreleased 8-stage vulnerability-discovery agent.

Opus implemented the agent and it works via Claude SDK with a Pro or Max subscription, no API.

https://github.com/evilsocket/audit


𝕏 | Simone
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯1
cKure Red pinned Β«πŸ€– πŸ†’πŸ†’πŸ†’πŸ†’πŸ†’πŸ†’ Earlier today Cloudflare's CSO shared how they tested Anthropic Mythos using an unreleased 8-stage vulnerability-discovery agent. Opus implemented the agent and it works via Claude SDK with a Pro or Max subscription, no API. https://github.com…»
πŸ” πŸ” πŸ” πŸ” πŸ” πŸ” πŸ” βž–πŸ” πŸ” πŸ” 

https://www.theverge.com/tech/935202/flipper-devices-one-zero-wireless-multi-tool-linux-open-source-computer
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ“±Anthropic co-founder says there is a "real possibility that AI will displace human labor at a very large scale," and that supporting those people "will be a moral imperative of historic proportions."


And we do not have a mechanism while most of the control of AI is with few wealthy nations and individuals.
Please open Telegram to view this post
VIEW IN TELEGRAM
🀣3
cKure Red pinned Β«πŸ˜” Mini Plasma Zero-Day by Chaotic Eclipse (aka Nightmare Eclipse) with a total of 6 0-Days in 6 weeks. Official blog: https://deadeclipse666.blogspot.com https://blog.barracuda.com/2026/05/19/nightmare-eclipse-zero-days-grudgeΒ»
πŸ”—πŸ†’πŸ†’πŸ”€πŸ†’πŸ†’πŸ†’πŸ†’

Transfer data between devices using just QR codes!


QR-Beam β€” A browser-based data transfer tool where both sender and receiver run entirely client-side via JavaScript. No installation, simple mobile-friendly UI, and designed for real-world use.

The idea isn't new, but was focused on turning it into a practical, production-ready solution with several improvements over existing PoCs.

Beta: https://ckure.org/rx/QR-Beam
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯1😐11
πŸ“‘πŸ›° For 19 years, GPS satellites have secretly broadcast a β€œnumbers station” in their public signals. We decoded 12M messages: a 2011 flash where 31 of 32 satellites flipped in hours, β€œghost” substrings repeating years apart, and a β€œTEXT” prefix spreading now.

https://lsc-pagepro.mydigitalpublication.com/publication/?i=865273&p=62&view=issueViewer

https://github.com/sjmurdoch/gps-special-messages

https://x.com/i/status/2061829547289387209
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘©β€πŸ’» Performing RCE in Internet Explorer via clickjacking!

Credits: Igor Sak-Sakovsky's (𝕏 | Psych0tr1a)


https://swarm.ptsecurity.com/the-click-that-shouldnt-have-worked-rce-via-clickjacking-in-internet-explorer/
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ”₯1
cKure Red pinned Β«πŸ‘©β€πŸ’» Performing RCE in Internet Explorer via clickjacking! Credits: Igor Sak-Sakovsky's (𝕏 | Psych0tr1a) https://swarm.ptsecurity.com/the-click-that-shouldnt-have-worked-rce-via-clickjacking-in-internet-explorer/Β»