fa
Feedback
cKure

cKure

رفتن به کانال در Telegram

﷽ This channel was created in 2018 and contains content from the information security domain. This channel is primarily run by AI bots (n8n). Archive: ckure.esy.es Criticals: @ckuRED linkedin.com/company/ckure Support 📨 i@ckure.org

نمایش بیشتر
7 050
مشترکین
+224 ساعت
+487 روز
+10330 روز

در حال بارگیری داده...

جذب مشترکین
سپتامبر '26
سپتامبر '26
+117
در 4 کانال‌ها
اوت '26
+153
در 1 کانال‌ها
Get PRO
ژوئیه '26
+213
در 2 کانال‌ها
Get PRO
ژوئن '26
+203
در 3 کانال‌ها
Get PRO
مه '26
+176
در 1 کانال‌ها
Get PRO
آوریل '26
+193
در 7 کانال‌ها
Get PRO
مارس '26
+161
در 5 کانال‌ها
Get PRO
فوریه '26
+130
در 1 کانال‌ها
Get PRO
ژانویه '26
+160
در 6 کانال‌ها
Get PRO
دسامبر '25
+151
در 1 کانال‌ها
Get PRO
نوامبر '25
+165
در 2 کانال‌ها
Get PRO
اکتبر '25
+94
در 2 کانال‌ها
Get PRO
سپتامبر '25
+67
در 2 کانال‌ها
Get PRO
اوت '25
+66
در 4 کانال‌ها
Get PRO
ژوئیه '25
+44
در 4 کانال‌ها
Get PRO
ژوئن '25
+77
در 4 کانال‌ها
Get PRO
مه '25
+45
در 1 کانال‌ها
Get PRO
آوریل '25
+84
در 4 کانال‌ها
Get PRO
مارس '25
+35
در 0 کانال‌ها
Get PRO
فوریه '25
+32
در 1 کانال‌ها
Get PRO
ژانویه '25
+61
در 3 کانال‌ها
Get PRO
دسامبر '24
+129
در 5 کانال‌ها
Get PRO
نوامبر '24
+206
در 3 کانال‌ها
Get PRO
اکتبر '24
+178
در 2 کانال‌ها
Get PRO
سپتامبر '24
+241
در 5 کانال‌ها
Get PRO
اوت '24
+242
در 4 کانال‌ها
Get PRO
ژوئیه '24
+172
در 3 کانال‌ها
Get PRO
ژوئن '24
+167
در 0 کانال‌ها
Get PRO
مه '24
+186
در 1 کانال‌ها
Get PRO
آوریل '24
+168
در 1 کانال‌ها
Get PRO
مارس '24
+181
در 0 کانال‌ها
Get PRO
فوریه '24
+269
در 0 کانال‌ها
Get PRO
ژانویه '24
+356
در 0 کانال‌ها
Get PRO
دسامبر '23
+281
در 0 کانال‌ها
Get PRO
نوامبر '23
+63
در 2 کانال‌ها
Get PRO
اکتبر '23
+66
در 0 کانال‌ها
Get PRO
سپتامبر '23
+66
در 0 کانال‌ها
Get PRO
اوت '23
+78
در 0 کانال‌ها
Get PRO
ژوئیه '23
+47
در 0 کانال‌ها
Get PRO
ژوئن '23
+64
در 0 کانال‌ها
Get PRO
مه '23
+43
در 0 کانال‌ها
Get PRO
آوریل '23
+48
در 0 کانال‌ها
Get PRO
مارس '23
+30
در 0 کانال‌ها
Get PRO
فوریه '23
+23
در 0 کانال‌ها
Get PRO
ژانویه '23
+42
در 0 کانال‌ها
Get PRO
دسامبر '22
+25
در 0 کانال‌ها
Get PRO
نوامبر '22
+30
در 0 کانال‌ها
Get PRO
اکتبر '22
+67
در 0 کانال‌ها
Get PRO
سپتامبر '22
+53
در 0 کانال‌ها
Get PRO
اوت '22
+70
در 0 کانال‌ها
Get PRO
ژوئیه '22
+79
در 0 کانال‌ها
Get PRO
ژوئن '22
+78
در 0 کانال‌ها
Get PRO
مه '22
+64
در 0 کانال‌ها
Get PRO
آوریل '22
+77
در 0 کانال‌ها
Get PRO
مارس '22
+49
در 0 کانال‌ها
Get PRO
فوریه '22
+44
در 0 کانال‌ها
Get PRO
ژانویه '22
+70
در 0 کانال‌ها
Get PRO
دسامبر '21
+61
در 0 کانال‌ها
Get PRO
نوامبر '21
+53
در 0 کانال‌ها
Get PRO
اکتبر '21
+90
در 0 کانال‌ها
Get PRO
سپتامبر '21
+87
در 0 کانال‌ها
Get PRO
اوت '21
+108
در 0 کانال‌ها
Get PRO
ژوئیه '21
+110
در 0 کانال‌ها
Get PRO
ژوئن '21
+103
در 0 کانال‌ها
Get PRO
مه '21
+105
در 0 کانال‌ها
Get PRO
آوریل '21
+222
در 0 کانال‌ها
Get PRO
مارس '21
+120
در 0 کانال‌ها
Get PRO
فوریه '21
+55
در 0 کانال‌ها
Get PRO
ژانویه '21
+61
در 0 کانال‌ها
Get PRO
دسامبر '20
+3 174
در 0 کانال‌ها
تاریخ
رشد مشترکین
اشارات
کانال‌ها
16 سپتامبر+2
15 سپتامبر+6
14 سپتامبر+13
13 سپتامبر+7
12 سپتامبر+8
11 سپتامبر+4
10 سپتامبر+8
09 سپتامبر+17
08 سپتامبر+9
07 سپتامبر+7
06 سپتامبر+1
05 سپتامبر+8
04 سپتامبر+3
03 سپتامبر+11
02 سپتامبر+7
01 سپتامبر+6
پست‌های کانال
■■□□□ AWS Says It Can’t Restore Some Data From Mideast Facilities Struck by Iran Amazon’s announcement is the first indication that some data stored exclusively in Bahrain and the U.A.E could be gone forever https://www.wsj.com/world/middle-east/aws-says-it-cant-restore-some-data-from-mideast-facilities-struck-by-iran-ddcb7e5d

2
■■□□□ Vilya: Anti Assassination Software (proprietary)
■■□□□ Vilya: Anti Assassination Software (proprietary)
265
3
■■□□□ 🇳🇱 The Dutch government just blocked a €100 million deal over one American law that nobody in the Netherlands voted f
■■□□□ 🇳🇱 The Dutch government just blocked a €100 million deal over one American law that nobody in the Netherlands voted for. An American company tried to buy the cloud provider that runs DigiD, the login system 16 million Dutch citizens use for tax, healthcare, pensions and government services. The data never had to leave the country. The servers never had to move. That was never the point. Because under the US CLOUD Act, the moment a US company owns the keys, a US court can reach the data, no matter where in the world it sits. So the Dutch said no. First deal their screening body has ever blocked. The backdoor isn’t in the code. It’s in the org chart 👀 And if you think this stays in Europe, wait until you hear what Australia already signed.
359
4
■■□□□ Be aware that your photos can be accessed without unlocking your Android when you receive a WhatsApp video call. This w
■■□□□ Be aware that your photos can be accessed without unlocking your Android when you receive a WhatsApp video call. This was discovered by Jose Rodriquez and already reported to Meta and Google. ⚠️ This can be misused as #Stalkerware technique to access photos of a friend or spouse that left the locked phone one the table or charging and someone knows their WhatsApp number to make call to to access their photos.
307
5
■■■■□ Agam Rossen's VolAnti is an open-source acoustic drone detector built around an ESP32-S3, four MEMS microphones, e-pape
■■■■□ Agam Rossen's VolAnti is an open-source acoustic drone detector built around an ESP32-S3, four MEMS microphones, e-paper display and LoRa radio. It analyzes the harmonic signature of spinning propellers instead of looking for radio signals, making it interesting for detecting fibre-optic FPV drones that can leave the radio spectrum silent. The concept could be useful for perimeter monitoring, wildlife & environmental monitoring, industrial site awareness, event security, search and rescue operations and early-warning sensor networks, especially where visual detection or conventional radio-based detection is difficult. The creator reports 104 m measured detection, 0.23 s alert latency in its fastest detector, and roughly 18–22 hours of battery life.
318
6
■■■■□ Interesting thread on Android APK decompilation. https://x.com/MGAldys4/status/2098541143474749913
370
7
📄 The Art of Exploit Development.
296
8
A prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and…”) is embedded in a specially crafted prose wrapper. An LLM with limited resources and attention fails to realize the payload is there, classifies the prompt as benign and passes it off to the target model. The target then notices the payload, extracts it and treats it as further input. This technique is itself not a jailbreak, but it can be combined with one by using a jailbreak prompt as the payload. https://research.checkpoint.com/2026/puzzlemask-abusing-plain-prose-as-a-covert-ai-attack-vector/
372
9
■■■□□ How the CIA recruits influencers step one in your browser history. Chase Hughes spent two decades building behavior pro
■■■□□ How the CIA recruits influencers step one in your browser history. Chase Hughes spent two decades building behavior profiling and influence systems for military and intelligence work.
435
10
■■■□□ Privacy 🔏 On 28 August 2026 Meta said its AI glasses would stop recording the moment the capture light is covered. Day
■■■□□ Privacy 🔏 On 28 August 2026 Meta said its AI glasses would stop recording the moment the capture light is covered. Days later it confirmed it had disabled the cameras on glasses whose light had been tampered with: fewer than one pair in a thousand, of more than 7 million sold last year. The light is 2 millimetres wide. Meta’s own bystander privacy paper says more. The camera does two jobs: saving photos and videos, and answering questions about what it sees. The light blinks only for the first. For AI features it stays off, because a light that blinked all the time would stop being noticed. So the light tells a bystander that a video is being saved, not that the camera is on. On 9 September Apple announced the Watch Series 12 with two listening features. Live Rewind shows the last 15 seconds of a conversation as text after a double press, with a chime that plays even on silent. Siri Recap takes notes on whole conversations in the background. For those notes, Apple states there is no audible signal because no raw audio is retained. Neither feature is available in the EU at launch. Norway’s government said on 25 August it may ban face recognition in glasses and set up an expert group without a deadline. Oslo banned smart glasses in every municipal school from 27 August. Its deputy mayor for education wrote that a school rule stops the glasses in the classroom, not on the metro and not outside the school gate. Europe’s privacy regulators commissioned a report on whether people accept smart glasses, due in summer 2026. As of 11 September it has not been published. The 3D watch shown is an earlier generation. Cover photo: ItzANormalFioko, CC BY-SA 3.0. Sources: Meta privacy page, 7 July 2026; Meta, Bystander Privacy, July 2025; A. Himel, Threads, 28 Aug 2026; Semafor, 1 Sept 2026; EssilorLuxottica, 11 Feb 2026; Apple, Sept 2026; Datatilsynet, 25 Aug 2026; Utdanningsnytt, 27 Aug 2026; Politico Europe, 8 June 2026.
417
11
■■■□□ “Choices Have Consequences”: Inside The Night Hunters’ Retaliatory Cyber Campaign https://stealthmole-intelligence-hub.blogspot.com/2026/09/choices-have-consequences-inside-night.html?m=1
481
12
■■■□□ DarkSword iOS Exploit Kit: Russian Spear-phishing Campaign Targeting NATO-aligned Officials. https://www.trellix.com/advanced-research-center/threat-reports/secondsight-threat-hunting-report-september-2026/#darkSword
514
13
■■■□□ A bipartisan group of U.S. lawmakers have called for three Indian companies that have hacked and stolen data from Americans to be added to the economic sanctions “entity list.” https://techcrunch.com/2026/09/09/group-of-bipartisan-lawmakers-ask-us-government-to-ban-several-hack-for-hire-firms/ https://x.com/citizenlab/status/2098099162881433639
540
14
■■■□□ Educational source‑code reconstruction for the Stuxnet worm, derived from public reverse‑engineering of original malware binaries. https://github.com/Sadpainy/Stuxnet
757
15
■■■□□ Zero-Trust phone. Wiping your phone at customs is a felony. Unless you use the clean hands method. A US citizen was arr
■■■□□ Zero-Trust phone. Wiping your phone at customs is a felony. Unless you use the clean hands method. A US citizen was arrested at the border over a secret code that factory reset his phone. He was coming home from vacation. Now he faces up to five years in federal prison under 18 U.S. Code 2232, destruction of property to prevent seizure. The problem was not that his phone wiped itself. The problem was that he triggered it. He handed the agent a code he knew would erase everything. That is destroying evidence while the officer watches. Here is the legal version: a phone that erases itself under conditions you set beforehand, when your hands are nowhere near it. 1. The dead man switch. Set a countdown, and every normal unlock resets it. You touch your phone over 40 times a day, so it never fires. Before your flight, shorten it to 30 minutes. If you get pulled aside and your phone sits in a bin while you answer questions, the timer runs out and everything is erased. You were not there to stop it. 2. The USB trigger. The moment someone tries to pull data off the phone while it is locked, it wipes itself. That is a forensic rig at the border meeting a safety protocol against theft. They plug in, boom. 3. Profiles. Run one boring profile full of dog photos and one only for business. Only the sensitive one wipes. They find the dog photos, nothing looks wiped, no follow-up questions. Set the conditions before you travel and you never pull the trigger. That is the difference between a security feature and a felony. The Zero Trace Phone ships with all three built in.
616
16
■■■■□ LG TV https://x.com/MarioNawfal/status/2097490173953012033
■■■■□ LG TV https://x.com/MarioNawfal/status/2097490173953012033
531
17
■■■■□ Anduril Military Equipment hijacked by Iran. 🇺🇸🇮🇷 Iran announces it monitored, ambushed, and captured the most adva
■■■■□ Anduril Military Equipment hijacked by Iran. 🇺🇸🇮🇷 Iran announces it monitored, ambushed, and captured the most advanced and classified American Unmanned Underwater Vessel in the Strait of Hormuz The unmanned submarine contains the most advanced and new technology, and was only delivered to the U.S. Navy a year ago, in 2025. It has been captured in a complete state, and will be showcased on state TV in the coming hours.
1 425
18
■■■■□ Privacy: Your LG TV is eavesdropping on you. It transcribes what you say, copies what is on your screen, and scans every device on your network, and researchers say the collection keeps running after you disconnect it, uploading the moment it reconnects. LG's ad-tech arm says it out loud: "We own the glass." It pitches marketers on the ability to "own the living room," using data harvested from the TV you paid thousands for. Gamers Nexus, working with Level1Techs and independent researchers, compromised an LG G5 and turned it into a listening device: it recorded room audio while the screen appeared off and the Ethernet cable was unplugged, then exfiltrated the file once the TV was back online. LG has publicly said its TVs "do not collect, record, or store ambient conversations." Gamers Nexus found the TV converts speech to plain text and stores it in on-device logs, and that the mic window stays open 10 to 15 seconds after talking stops, sweeping up bystanders who never addressed the TV. These sets are everywhere: hospitals, waiting rooms, boardrooms, hotels. ACR keeps running even when the TV is a dumb HDMI monitor, and a compromised set can pull the audio of a call off that HDMI feed. A surgeon asked Gamers Nexus where that leaves patient confidentiality. Researchers advise disconnecting LG TVs from any network.
715
19
■■■□□ Berlin's Senate Chancellery hired CrowdStrike to assess the hack on the city administration. One district, Lichtenberg, is refusing to let the firm in because of its US ties. They're blocking CrowdStrike's Falcon agent from their network, citing visibility into staff devices and personal data, US legal disclosure duties and the vendor's Palantir ties. They'll only allow access if the Senate carries full responsibility and all costs. The Senate Chancellery hired the US firm to check district systems for traces of the recent Rhysida hack. Rhysida sat in Berlin's network from 7–12 August, undetected until the 14th. After Berlin refused a 30 BTC (€2M) ransom, it dumped 1.4 million files, roughly 5.8TB. Its leak page claims 46,500 contracts and over 5,000 personnel files. One file held close to 6,000 logins, and we have confirmed they've had documents with cleartext credentials.
708
20
🚨 Attackers hijack MikroTik routers through internet-exposed SSH. No authentication required. Update RouterOS immediately, t
🚨 Attackers hijack MikroTik routers through internet-exposed SSH. No authentication required. Update RouterOS immediately, then check for unknown users and scripts, CERT Polska advises. See affected versions and recovery steps → https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html
772