ar
Feedback
cKure Red

cKure Red

الذهاب إلى القناة على Telegram

The director's cut on critical feeds from InfoSec world 🌎 Main Channel: @cKure ☕️ or queries email us 📨 i@ckure.org

إظهار المزيد
2 734
المشتركون
-124 ساعات
+77 أيام
+5230 أيام

جاري تحميل البيانات...

جذب المشتركين
سبتمبر '26
سبتمبر '26
+68
في 6 قنوات
أغسطس '26
+56
في 5 قنوات
Get PRO
يوليو '26
+90
في 3 قنوات
Get PRO
يونيو '26
+106
في 2 قنوات
Get PRO
مايو '26
+82
في 1 قنوات
Get PRO
أبريل '26
+81
في 2 قنوات
Get PRO
مارس '26
+69
في 2 قنوات
Get PRO
فبراير '26
+51
في 2 قنوات
Get PRO
يناير '26
+119
في 2 قنوات
Get PRO
ديسمبر '25
+81
في 2 قنوات
Get PRO
نوفمبر '25
+86
في 1 قنوات
Get PRO
أكتوبر '25
+54
في 3 قنوات
Get PRO
سبتمبر '25
+56
في 3 قنوات
Get PRO
أغسطس '25
+34
في 2 قنوات
Get PRO
يوليو '25
+39
في 3 قنوات
Get PRO
يونيو '25
+41
في 2 قنوات
Get PRO
مايو '25
+71
في 3 قنوات
Get PRO
أبريل '25
+36
في 1 قنوات
Get PRO
مارس '25
+37
في 2 قنوات
Get PRO
فبراير '25
+50
في 1 قنوات
Get PRO
يناير '25
+29
في 1 قنوات
Get PRO
ديسمبر '24
+75
في 3 قنوات
Get PRO
نوفمبر '24
+112
في 3 قنوات
Get PRO
أكتوبر '24
+65
في 1 قنوات
Get PRO
سبتمبر '24
+110
في 1 قنوات
Get PRO
أغسطس '24
+114
في 1 قنوات
Get PRO
يوليو '24
+127
في 6 قنوات
Get PRO
يونيو '24
+53
في 2 قنوات
Get PRO
مايو '24
+70
في 2 قنوات
Get PRO
أبريل '24
+158
في 26 قنوات
Get PRO
مارس '24
+95
في 2 قنوات
Get PRO
فبراير '24
+153
في 24 قنوات
Get PRO
يناير '24
+114
في 2 قنوات
Get PRO
ديسمبر '23
+96
في 1 قنوات
Get PRO
نوفمبر '23
+28
في 1 قنوات
Get PRO
أكتوبر '23
+34
في 1 قنوات
Get PRO
سبتمبر '23
+22
في 0 قنوات
Get PRO
أغسطس '23
+32
في 0 قنوات
Get PRO
يوليو '23
+31
في 0 قنوات
Get PRO
يونيو '23
+32
في 0 قنوات
Get PRO
مايو '23
+16
في 0 قنوات
Get PRO
أبريل '23
+29
في 0 قنوات
Get PRO
مارس '23
+22
في 0 قنوات
Get PRO
فبراير '23
+18
في 0 قنوات
Get PRO
يناير '23
+28
في 0 قنوات
Get PRO
ديسمبر '22
+33
في 0 قنوات
Get PRO
نوفمبر '22
+33
في 0 قنوات
Get PRO
أكتوبر '22
+12
في 0 قنوات
Get PRO
سبتمبر '22
+14
في 0 قنوات
Get PRO
أغسطس '22
+38
في 0 قنوات
Get PRO
يوليو '22
+34
في 0 قنوات
Get PRO
يونيو '22
+30
في 0 قنوات
Get PRO
مايو '22
+38
في 0 قنوات
Get PRO
أبريل '22
+40
في 0 قنوات
Get PRO
مارس '22
+51
في 0 قنوات
Get PRO
فبراير '22
+23
في 0 قنوات
Get PRO
يناير '22
+39
في 0 قنوات
Get PRO
ديسمبر '21
+243
في 0 قنوات
التاريخ
نمو المشتركين
الإشارات
القنوات
23 سبتمبر+1
22 سبتمبر+1
21 سبتمبر+4
20 سبتمبر+2
19 سبتمبر+2
18 سبتمبر+2
17 سبتمبر+6
16 سبتمبر+1
15 سبتمبر+2
14 سبتمبر+7
13 سبتمبر+2
12 سبتمبر+6
11 سبتمبر0
10 سبتمبر+2
09 سبتمبر+5
08 سبتمبر+3
07 سبتمبر+2
06 سبتمبر+3
05 سبتمبر+5
04 سبتمبر+3
03 سبتمبر+5
02 سبتمبر+1
01 سبتمبر+3
منشورات القناة
AliExpress spyware caught using side channel attack to compromise hardware.

2
😒 Claude Code was used to make missile guidance system for 9 months by Houthis using multiple agents to make an offline flig
😒 Claude Code was used to make missile guidance system for 9 months by Houthis using multiple agents to make an offline flight simulator. The accounts linked were banned by Claude. The offline version of flight simulator is however on the loose.
2 361
3
theartofexploitation.pdf
1 107
4
A prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and…”) is embedded in a specially crafted prose wrapper. An LLM with limited resources and attention fails to realize the payload is there, classifies the prompt as benign and passes it off to the target model. The target then notices the payload, extracts it and treats it as further input. This technique is itself not a jailbreak, but it can be combined with one by using a jailbreak prompt as the payload. https://research.checkpoint.com/2026/puzzlemask-abusing-plain-prose-as-a-covert-ai-attack-vector/
1 223
5
🎵 Cloudflare Zero-day: Accessing Any Host Globally. https://fearsoff.org/research/cloudflare-acme
1 534
6
🤩🤩🤩Harmony SASE: When a quote in the path was enough for root. https://somelab.ai/harmony-sase-helpertool-lpe
1 369
7
⭕️ RFID relay attack by Lukas Stefanko.
⭕️ RFID relay attack by Lukas Stefanko.
1 823
8
🛫A device the size of a coin could hack a Boeing 737. Security researchers from the University of California San Diego and O
🛫A device the size of a coin could hack a Boeing 737. Security researchers from the University of California San Diego and Oberlin College recently presented a prototype device that could hack a Boeing 737 in less than a minute. Their aim was to expose a blind spot in aviation security and to show how physical access hacking represents a practical threat. In a statement to WIRED, Boeing downplayed that threat. “Our technical experts are confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks.” The researchers say, Boeing hasn't told them about any technical fix for the vulnerabilities they've discovered. That lack of an immediate security update for planes shouldn't be cause for panic or grounding aircraft, the security researchers wrote in their paper. “All of the authors of this paper routinely travel on Boeing 737 aircraft and expect to continue doing so,” the introduction of the paper reads. Words: Andy Greenberg Video Producer: Tamanna Sajeed
1 016
9
🇮🇱🇮🇱 How NSW police could soon clone your entire phone at a traffic stop. No warrant needed. On Friday the Minns governme
🇮🇱🇮🇱 How NSW police could soon clone your entire phone at a traffic stop. No warrant needed. On Friday the Minns government introduced legislation letting police plug your phone into military-grade Israeli extraction tech, the same UFED devices used by ICE, and copy everything. Contacts, messages, photos, even deleted files, in minutes. Refuse your PIN and they can brute force it anyway. It also lets them pull unredacted toll camera images into the national facial recognition database, search your device without a warrant, and override your right against self-incrimination.
2 284
10
Malicious AI
Malicious AI
1 880
11
Fish Audio just launched S2.1 Pro, a new voice AI model positioned as a serious competitor to ElevenLabs. Its biggest advanta
Fish Audio just launched S2.1 Pro, a new voice AI model positioned as a serious competitor to ElevenLabs. Its biggest advantage is cost. Depending on the ElevenLabs model used for comparison, Fish Audio can be nearly 5 times cheaper while also being built on an open-weight foundation. In this demo, the system handles multiple speakers, interruptions, changing requests, name spelling, and a longer conversation without losing track of the order. It shows how quickly voice AI is becoming more capable, accessible, and affordable for developers. The real test will be whether Fish Audio can match ElevenLabs in voice quality, reliability, latency, and production performance.
917
12
👩‍💻 Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities. Technical Summary: https://depthfirst.com/research/going-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities PoC: https://github.com/wupco/gitlab-rce-demo/tree/main Overview: https://depthfirst.com/gitlab-rce-oj-spill Thread: 🧵 https://x.com/i/status/2080763568044290535
1 695
13
✅CVE-2026-63030: Unauthenticated SQL injection in WordPress core chaining to RCE. No credentials, no configuration. One endpoint: POST /wp-json/batch/v1. The REST batch endpoint builds two parallel arrays ($matches and $validation) that fall out of step when a sub-request path fails wp_parse_url(). A sub-request gets dispatched under a different handler's context. The PoC nests this route confusion twice: first to bypass the method allow-list, then to reach a blind SQL injection via author_exclude in WP_Query, which interpolates the value into SQL as a string. The chain: boolean/time-based blind SQLi → extract admin password hash → crack → plugin upload → command execution. Interactive shell included. Affects WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. Fixed in 6.9.5 and 7.0.2. Python 3.8+, zero dependencies. Mitigation: block /wp-json/batch/v1 and rest_route=/batch/v1 at the edge, or require auth via rest_pre_dispatch filter. https://github.com/Icex0/wp2shell-poc
1 388
14
Detecting jammers via over the shelf hardware like directional antenna 📡
Detecting jammers via over the shelf hardware like directional antenna 📡
1 315
15
💻😯Windows includes a file-system virtualization feature that can redirect one local path to another without modifying the original file or leaving a persistent filesystem artifact. It is implemented by bindflt.sys, the Bind Filter minifilter driver, and used legitimately by Store apps, Windows Sandbox, and Windows containers. https://www.bitdefender.com/en-us/blog/businessinsights/bind-link-abuses-windows-feature-edr-evasion-technique https://x.com/i/status/2078016406856282445
1 134
16
Techno-Fascism, The Palantair; an evil-corp in true sense.
Techno-Fascism, The Palantair; an evil-corp in true sense.
1 376
17
🐧GhostLock (CVE-2026-43499): a 15-year-old Linux kernel vulnerability that affects every distribution. Desktop, server, Andr
🐧GhostLock (CVE-2026-43499): a 15-year-old Linux kernel vulnerability that affects every distribution. Desktop, server, Android, IoT, embedded. $92,337 Google kernelCTF bounty. A stack-UAF in the rtmutex subsystem. remove_waiter() uses current instead of waiter::task during proxy-lock rollback in futex_requeue(), leaving a dangling pointer to freed kernel stack memory. No special kernel modules needed, only CONFIG_FUTEX_PI which is enabled on every distro. Nebula Security (NebuSec) turned it into a 97% stable privilege escalation and container escape. The exploit chains a dangling pointer into an arbitrary address write, hijacks a function table for control flow, and achieves root in about 5 seconds. Found by VEGA, their AI vulnerability scanner. Part of IonStack, the first browser-to-kernel full-chain RCE on Android 17: CVE-2026-10702 (Firefox IonMonkey JIT 0-day, near 100% success rate) chained with GhostLock for kernel LPE. Present since Linux 2.6.39 (2011). Fixed in Linux 7.1. Full exploit code published on GitHub. Exploit: https://github.com/NebuSec/CyberMeowfia/tree/main/IonStack/CVE-2026-43499
1 382
18
🎚 The Mosad Playbook: How One Alias Built a Cross-Platform Leak Network. https://stealthmole-intelligence-hub.blogspot.com/2026/07/the-mosad-playbook-how-one-alias-built.html
555
19
Peter Stokes was pulled off a flight in Helsinki, and Scattered Spider’s run of arrests keeps growing as they triste Microsof
Peter Stokes was pulled off a flight in Helsinki, and Scattered Spider’s run of arrests keeps growing as they triste Microsoft Windows for their operational security. This is when a cyber crime group trusted Microsoft. The GDID gives Microsoft access to everyone of your internet history of all applications. And can also initiate remote monitoring through security updates. And if you think that there is some hard drive you used encryption that uses TPM. TPM let's are actually stored with Microsoft for every installation. Never use Microsoft products and any organisation known for complicity and backdoor installations.
1 220
20
👍Sim Swap Attack https://covertaccessteam.substack.com/p/podcast-with-dmitry-kurbatov+1
👍Sim Swap Attack https://covertaccessteam.substack.com/p/podcast-with-dmitry-kurbatov
1 713