ar
Feedback
cKure Red

cKure Red

الذهاب إلى القناة على Telegram

The director's cut on critical feeds from InfoSec world 🌎 Main Channel: @cKure ☕️ or queries email us 📨 i@ckure.org

إظهار المزيد
2 558
المشتركون
لا توجد بيانات24 ساعات
+77 أيام
+5130 أيام

جاري تحميل البيانات...

جذب المشتركين
يونيو '26
يونيو '26
+37
في 2 قنوات
مايو '26
+82
في 1 قنوات
Get PRO
أبريل '26
+81
في 2 قنوات
Get PRO
مارس '26
+69
في 2 قنوات
Get PRO
فبراير '26
+51
في 2 قنوات
Get PRO
يناير '26
+119
في 2 قنوات
Get PRO
ديسمبر '25
+81
في 2 قنوات
Get PRO
نوفمبر '25
+86
في 1 قنوات
Get PRO
أكتوبر '25
+54
في 3 قنوات
Get PRO
سبتمبر '25
+56
في 3 قنوات
Get PRO
أغسطس '25
+34
في 2 قنوات
Get PRO
يوليو '25
+39
في 3 قنوات
Get PRO
يونيو '25
+41
في 2 قنوات
Get PRO
مايو '25
+71
في 3 قنوات
Get PRO
أبريل '25
+36
في 1 قنوات
Get PRO
مارس '25
+37
في 2 قنوات
Get PRO
فبراير '25
+50
في 1 قنوات
Get PRO
يناير '25
+29
في 1 قنوات
Get PRO
ديسمبر '24
+75
في 3 قنوات
Get PRO
نوفمبر '24
+112
في 3 قنوات
Get PRO
أكتوبر '24
+65
في 1 قنوات
Get PRO
سبتمبر '24
+110
في 1 قنوات
Get PRO
أغسطس '24
+114
في 1 قنوات
Get PRO
يوليو '24
+127
في 6 قنوات
Get PRO
يونيو '24
+53
في 2 قنوات
Get PRO
مايو '24
+70
في 2 قنوات
Get PRO
أبريل '24
+158
في 26 قنوات
Get PRO
مارس '24
+95
في 2 قنوات
Get PRO
فبراير '24
+153
في 24 قنوات
Get PRO
يناير '24
+114
في 2 قنوات
Get PRO
ديسمبر '23
+96
في 1 قنوات
Get PRO
نوفمبر '23
+28
في 1 قنوات
Get PRO
أكتوبر '23
+34
في 1 قنوات
Get PRO
سبتمبر '23
+22
في 0 قنوات
Get PRO
أغسطس '23
+32
في 0 قنوات
Get PRO
يوليو '23
+31
في 0 قنوات
Get PRO
يونيو '23
+32
في 0 قنوات
Get PRO
مايو '23
+16
في 0 قنوات
Get PRO
أبريل '23
+29
في 0 قنوات
Get PRO
مارس '23
+22
في 0 قنوات
Get PRO
فبراير '23
+18
في 0 قنوات
Get PRO
يناير '23
+28
في 0 قنوات
Get PRO
ديسمبر '22
+33
في 0 قنوات
Get PRO
نوفمبر '22
+33
في 0 قنوات
Get PRO
أكتوبر '22
+12
في 0 قنوات
Get PRO
سبتمبر '22
+14
في 0 قنوات
Get PRO
أغسطس '22
+38
في 0 قنوات
Get PRO
يوليو '22
+34
في 0 قنوات
Get PRO
يونيو '22
+30
في 0 قنوات
Get PRO
مايو '22
+38
في 0 قنوات
Get PRO
أبريل '22
+40
في 0 قنوات
Get PRO
مارس '22
+51
في 0 قنوات
Get PRO
فبراير '22
+23
في 0 قنوات
Get PRO
يناير '22
+39
في 0 قنوات
Get PRO
ديسمبر '21
+243
في 0 قنوات
التاريخ
نمو المشتركين
الإشارات
القنوات
12 يونيو+2
11 يونيو+1
10 يونيو0
09 يونيو+2
08 يونيو+3
07 يونيو+2
06 يونيو+4
05 يونيو+1
04 يونيو+2
03 يونيو+6
02 يونيو+9
01 يونيو+5
منشورات القناة
Exploiting CVE-2024-1065 via the Page Cache! A strategy for physical-page UAFs in MIGRATE_MOVABLE, where Dirty Pagetable and Dirty Cred don't apply. https://kuzey.rs/posts/MaliUAF/ Demonstrated on the Mali GPU UAF found by Project Zero.

2
Free research papers https://sci-bot.ru/
502
3
📡🅰️🅰️🅰️❎❎🅰️🅰️🅰️🅰️ PimEyes.Com
📡🅰️🅰️🅰️❎❎🅰️🅰️🅰️🅰️ PimEyes.Com
886
4
👩‍💻 Performing RCE in Internet Explorer via clickjacking! Credits: Igor Sak-Sakovsky's (𝕏 | Psych0tr1a) https://swarm.ptsecurity.com/the-click-that-shouldnt-have-worked-rce-via-clickjacking-in-internet-explorer/
967
5
📡🛰 For 19 years, GPS satellites have secretly broadcast a “numbers station” in their public signals. We decoded 12M messages: a 2011 flash where 31 of 32 satellites flipped in hours, “ghost” substrings repeating years apart, and a “TEXT” prefix spreading now. https://lsc-pagepro.mydigitalpublication.com/publication/?i=865273&p=62&view=issueViewer https://github.com/sjmurdoch/gps-special-messages https://x.com/i/status/2061829547289387209
1 416
6
🔗🆒🆒🔤🆒🆒🆒🆒 Transfer data between devices using just QR codes! QR-Beam — A browser-based data transfer tool where both sender and receiver run entirely client-side via JavaScript. No installation, simple mobile-friendly UI, and designed for real-world use. The idea isn't new, but was focused on turning it into a practical, production-ready solution with several improvements over existing PoCs. Beta: https://ckure.org/rx/QR-Beam
1
7
🔗🆒🆒🔤🆒🆒🆒🆒 Transfer data between devices using just QR codes! QR-Beam — A browser-based data transfer tool where both sender and receiver run entirely client-side via JavaScript. No installation, simple mobile-friendly UI, and designed for real-world use. The idea isn't new, but was focused on turning it into a practical, production-ready solution with several improvements over existing PoCs. Beta: https://ckure.org/rx/QR-Beam
1
8
🔗🆒🆒🔤🆒🆒🆒🆒 Transfer data between devices using just QR codes! QR-Beam — A browser-based data transfer tool where both sender and receiver run entirely client-side via JavaScript. No installation, simple mobile-friendly UI, and designed for real-world use. The idea isn't new, but was focused on turning it into a practical, production-ready solution with several improvements over existing PoCs. Beta: https://ckure.org/rx/QR-Beam
1 042
9
😔 Mini Plasma Zero-Day by Chaotic Eclipse (aka Nightmare Eclipse) with a total of 6 0-Days in 6 weeks. Official blog: https://deadeclipse666.blogspot.com https://blog.barracuda.com/2026/05/19/nightmare-eclipse-zero-days-grudge
1 160
10
📱Anthropic co-founder says there is a "real possibility that AI will displace human labor at a very large scale," and that s
📱Anthropic co-founder says there is a "real possibility that AI will displace human labor at a very large scale," and that supporting those people "will be a moral imperative of historic proportions." And we do not have a mechanism while most of the control of AI is with few wealthy nations and individuals.
853
11
🔠🔠🔠🔠🔠🔠🔠➖🔠🔠🔠 https://www.theverge.com/tech/935202/flipper-devices-one-zero-wireless-multi-tool-linux-open-source-com
🔠🔠🔠🔠🔠🔠🔠➖🔠🔠🔠 https://www.theverge.com/tech/935202/flipper-devices-one-zero-wireless-multi-tool-linux-open-source-computer
1 359
12
🤖 🆒🆒🆒🆒🆒🆒 Earlier today Cloudflare's CSO shared how they tested Anthropic Mythos using an unreleased 8-stage vulnerability-discovery agent. Opus implemented the agent and it works via Claude SDK with a Pro or Max subscription, no API. https://github.com/evilsocket/audit 𝕏 | Simone
1 446
13
🚀40K Starlink terminals hacked to lure Russians into a cyber trap as per anti-Russia propaganda news. 40,000 Starlink termin
🚀40K Starlink terminals hacked to lure Russians into a cyber trap as per anti-Russia propaganda news. 40,000 Starlink terminals go dark. Russian soldiers scramble for answers and turn to Telegram. They don’t realise they’ve just walked into a trap. The journalists travelled across Ukraine from Lviv to the front line in Zaporizhzhia to uncover a pretty audacious cyber operation. Meet Goldfinger and the 256 Cyber Assault Brigade and Yaro, and the 128th Mechanised Brigade, holding the line in the south.
1 351
14
🤩 ❗️❗️❗️❗️❗️❗️ LLM used to make a Zero-Day by APT group on a popular software. The zero day was a 2FA bypass via logic bug �
🤩 ❗️❗️❗️❗️❗️❗️ LLM used to make a Zero-Day by APT group on a popular software. The zero day was a 2FA bypass via logic bug 🪲 Security researchers at Alphabet’s Google said they believe a cybercrime group used artificial intelligence to create a hacking tool that can bypass defenses in a widely-used tool to administer computer systems. The scheme, which was foiled when Google alerted the tool developer, would mark the first time that Google’s Threat Intelligence Group caught a hacker using an AI-generated “zero-day” in such a way, according to a report published Monday.
1 178
15
⚠️⚠️⚠️⚠️⚠️⚠️ CVE-2026-0073: Critical Android Zero-Click, Zero-Day exploit in wireless debugging (if enabled) can allow adjace
⚠️⚠️⚠️⚠️⚠️⚠️ CVE-2026-0073: Critical Android Zero-Click, Zero-Day exploit in wireless debugging (if enabled) can allow adjacent hacker (in same network) to execute code as shell user.
1 425
16
🅰️🅰️🅰️🔢🅰️🅰️🅰️ Devcore team chained ⛓️‍💥 4 logic bugs to achieve sandbox escape in Microsoft Edge in Pwn²Own 2026, Ber
🅰️🅰️🅰️🔢🅰️🅰️🅰️ Devcore team chained ⛓️‍💥 4 logic bugs to achieve sandbox escape in Microsoft Edge in Pwn²Own 2026, Berlin.
1 187
17
🤖 Mythos finds a curl vulnerability. https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/
1 296
18
🆒🆒🆒🆒🔢🔢 FAST16 — Pre-Stuxnet Sabotage Malware (2005) - Referenced in Shadow Brokers (2017) leak (“NOTHING TO SEE HERE”)
🆒🆒🆒🆒🔢🔢 FAST16 — Pre-Stuxnet Sabotage Malware (2005) - Referenced in Shadow Brokers (2017) leak (“NOTHING TO SEE HERE”) - Compiled ~2005 → ~5 years before Stuxnet - Type: Sabotage malware (not espionage) Target - High-precision engineering / simulation software - Includes LS-DYNA, PKPM, MOHID - Used for physics, impact, and advanced simulations (incl. nuclear-related domains) Technique - Kernel driver: "fast16.sys" - In-memory patching of target processes - Injects subtle calculation errors (floating-point manipulation) - Goal: corrupt outputs while appearing normal Propagation - Worm-like spread via weak Windows network shares Attribution - Not confirmed - Strong suspicion: US or allied origin (based on NSA-linked leak context) Note - LS-DYNA ≠ purely “explosive software” - Broader simulation usage; “explosive calculations” is a subset use case
1 781
19
IoT side channel (correlation) attack using WiFi. Heuristic surveillance data is both widely under-reported and difficult to
IoT side channel (correlation) attack using WiFi. Heuristic surveillance data is both widely under-reported and difficult to mitigate without tossing your devices and living in the stone age.
817
20
💽 Phantomdrive is an open-source USB drive designed to conceal its actual capacity. Upon initial insertion, the device prese
💽 Phantomdrive is an open-source USB drive designed to conceal its actual capacity. Upon initial insertion, the device presents itself as an 8GB disk. To access the secondary partition, a file named "unlock.txt" must be created, followed by the entry of the password; the drive will subsequently unmount and remount, revealing the remaining data. All data is encrypted in place using an AES-256 key derived from the password. This mechanism is fundamentally different from how Veracrypt operates.
1 520