cKure Red
رفتن به کانال در Telegram
The director's cut on critical feeds from InfoSec world 🌎 Main Channel: @cKure ☕️ or queries email us 📨 i@ckure.org
نمایش بیشتر2 669
مشترکین
-124 ساعت
+57 روز
+6030 روز
در حال بارگیری داده...
کانالهای مشابه
ابر برچسبها
اشارات ورودی و خروجی
---
---
---
---
---
---
جذب مشترکین
ژوئیه '26
ژوئیه '26
+84
در 3 کانالها
ژوئن '26
+106
در 2 کانالها
Get PRO
مه '26
+82
در 1 کانالها
Get PRO
آوریل '26
+81
در 2 کانالها
Get PRO
مارس '26
+69
در 2 کانالها
Get PRO
فوریه '26
+51
در 2 کانالها
Get PRO
ژانویه '26
+119
در 2 کانالها
Get PRO
دسامبر '25
+81
در 2 کانالها
Get PRO
نوامبر '25
+86
در 1 کانالها
Get PRO
اکتبر '25
+54
در 3 کانالها
Get PRO
سپتامبر '25
+56
در 3 کانالها
Get PRO
اوت '25
+34
در 2 کانالها
Get PRO
ژوئیه '25
+39
در 3 کانالها
Get PRO
ژوئن '25
+41
در 2 کانالها
Get PRO
مه '25
+71
در 3 کانالها
Get PRO
آوریل '25
+36
در 1 کانالها
Get PRO
مارس '25
+37
در 2 کانالها
Get PRO
فوریه '25
+50
در 1 کانالها
Get PRO
ژانویه '25
+29
در 1 کانالها
Get PRO
دسامبر '24
+75
در 3 کانالها
Get PRO
نوامبر '24
+112
در 3 کانالها
Get PRO
اکتبر '24
+65
در 1 کانالها
Get PRO
سپتامبر '24
+110
در 1 کانالها
Get PRO
اوت '24
+114
در 1 کانالها
Get PRO
ژوئیه '24
+127
در 6 کانالها
Get PRO
ژوئن '24
+53
در 2 کانالها
Get PRO
مه '24
+70
در 2 کانالها
Get PRO
آوریل '24
+158
در 26 کانالها
Get PRO
مارس '24
+95
در 2 کانالها
Get PRO
فوریه '24
+153
در 24 کانالها
Get PRO
ژانویه '24
+114
در 2 کانالها
Get PRO
دسامبر '23
+96
در 1 کانالها
Get PRO
نوامبر '23
+28
در 1 کانالها
Get PRO
اکتبر '23
+34
در 1 کانالها
Get PRO
سپتامبر '23
+22
در 0 کانالها
Get PRO
اوت '23
+32
در 0 کانالها
Get PRO
ژوئیه '23
+31
در 0 کانالها
Get PRO
ژوئن '23
+32
در 0 کانالها
Get PRO
مه '23
+16
در 0 کانالها
Get PRO
آوریل '23
+29
در 0 کانالها
Get PRO
مارس '23
+22
در 0 کانالها
Get PRO
فوریه '23
+18
در 0 کانالها
Get PRO
ژانویه '23
+28
در 0 کانالها
Get PRO
دسامبر '22
+33
در 0 کانالها
Get PRO
نوامبر '22
+33
در 0 کانالها
Get PRO
اکتبر '22
+12
در 0 کانالها
Get PRO
سپتامبر '22
+14
در 0 کانالها
Get PRO
اوت '22
+38
در 0 کانالها
Get PRO
ژوئیه '22
+34
در 0 کانالها
Get PRO
ژوئن '22
+30
در 0 کانالها
Get PRO
مه '22
+38
در 0 کانالها
Get PRO
آوریل '22
+40
در 0 کانالها
Get PRO
مارس '22
+51
در 0 کانالها
Get PRO
فوریه '22
+23
در 0 کانالها
Get PRO
ژانویه '22
+39
در 0 کانالها
Get PRO
دسامبر '21
+243
در 0 کانالها
| تاریخ | رشد مشترکین | اشارات | کانالها | |
| 29 ژوئیه | +2 | |||
| 28 ژوئیه | 0 | |||
| 27 ژوئیه | 0 | |||
| 26 ژوئیه | +2 | |||
| 25 ژوئیه | +4 | |||
| 24 ژوئیه | +2 | |||
| 23 ژوئیه | +3 | |||
| 22 ژوئیه | 0 | |||
| 21 ژوئیه | +4 | |||
| 20 ژوئیه | +5 | |||
| 19 ژوئیه | +3 | |||
| 18 ژوئیه | +4 | |||
| 17 ژوئیه | +3 | |||
| 16 ژوئیه | +1 | |||
| 15 ژوئیه | +2 | |||
| 14 ژوئیه | +2 | |||
| 13 ژوئیه | +2 | |||
| 12 ژوئیه | +5 | |||
| 11 ژوئیه | +2 | |||
| 10 ژوئیه | +3 | |||
| 09 ژوئیه | +3 | |||
| 08 ژوئیه | +3 | |||
| 07 ژوئیه | +5 | |||
| 06 ژوئیه | +5 | |||
| 05 ژوئیه | +3 | |||
| 04 ژوئیه | +3 | |||
| 03 ژوئیه | +3 | |||
| 02 ژوئیه | +5 | |||
| 01 ژوئیه | +5 |
پستهای کانال
| 2 | Fish Audio just launched S2.1 Pro, a new voice AI model positioned as a serious competitor to ElevenLabs. Its biggest advantage is cost. Depending on the ElevenLabs model used for comparison, Fish Audio can be nearly 5 times cheaper while also being built on an open-weight foundation. In this demo, the system handles multiple speakers, interruptions, changing requests, name spelling, and a longer conversation without losing track of the order. It shows how quickly voice AI is becoming more capable, accessible, and affordable for developers. The real test will be whether Fish Audio can match ElevenLabs in voice quality, reliability, latency, and production performance. | 60 |
| 3 | 👩💻 Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities.
Technical Summary:
https://depthfirst.com/research/going-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities
PoC:
https://github.com/wupco/gitlab-rce-demo/tree/main
Overview:
https://depthfirst.com/gitlab-rce-oj-spill
Thread: 🧵
https://x.com/i/status/2080763568044290535 | 721 |
| 4 | ✅CVE-2026-63030: Unauthenticated SQL injection in WordPress core chaining to RCE. No credentials, no configuration. One endpoint: POST /wp-json/batch/v1.
The REST batch endpoint builds two parallel arrays ($matches and $validation) that fall out of step when a sub-request path fails wp_parse_url(). A sub-request gets dispatched under a different handler's context. The PoC nests this route confusion twice: first to bypass the method allow-list, then to reach a blind SQL injection via author_exclude in WP_Query, which interpolates the value into SQL as a string.
The chain:
boolean/time-based blind SQLi → extract admin password hash → crack → plugin upload → command execution. Interactive shell included.
Affects WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. Fixed in 6.9.5 and 7.0.2. Python 3.8+, zero dependencies.
Mitigation:
block /wp-json/batch/v1 and rest_route=/batch/v1 at the edge, or require auth via rest_pre_dispatch filter.
https://github.com/Icex0/wp2shell-poc | 1 026 |
| 5 | Detecting jammers via over the shelf hardware like directional antenna 📡 | 1 044 |
| 6 | 💻😯Windows includes a file-system virtualization feature that can redirect one local path to another without modifying the original file or leaving a persistent filesystem artifact. It is implemented by bindflt.sys, the Bind Filter minifilter driver, and used legitimately by Store apps, Windows Sandbox, and Windows containers.
https://www.bitdefender.com/en-us/blog/businessinsights/bind-link-abuses-windows-feature-edr-evasion-technique
https://x.com/i/status/2078016406856282445 | 936 |
| 7 | Techno-Fascism, The Palantair; an evil-corp in true sense. | 1 202 |
| 8 | 🐧GhostLock (CVE-2026-43499): a 15-year-old Linux kernel vulnerability that affects every distribution. Desktop, server, Android, IoT, embedded. $92,337 Google kernelCTF bounty.
A stack-UAF in the rtmutex subsystem. remove_waiter() uses current instead of waiter::task during proxy-lock rollback in futex_requeue(), leaving a dangling pointer to freed kernel stack memory. No special kernel modules needed, only CONFIG_FUTEX_PI which is enabled on every distro.
Nebula Security (NebuSec) turned it into a 97% stable privilege escalation and container escape. The exploit chains a dangling pointer into an arbitrary address write, hijacks a function table for control flow, and achieves root in about 5 seconds. Found by VEGA, their AI vulnerability scanner.
Part of IonStack, the first browser-to-kernel full-chain RCE on Android 17: CVE-2026-10702 (Firefox IonMonkey JIT 0-day, near 100% success rate) chained with GhostLock for kernel LPE.
Present since Linux 2.6.39 (2011). Fixed in Linux 7.1. Full exploit code published on GitHub.
Exploit:
https://github.com/NebuSec/CyberMeowfia/tree/main/IonStack/CVE-2026-43499 | 1 242 |
| 9 | 🎚 The Mosad Playbook: How One Alias Built a Cross-Platform Leak Network.
https://stealthmole-intelligence-hub.blogspot.com/2026/07/the-mosad-playbook-how-one-alias-built.html | 555 |
| 10 | Peter Stokes was pulled off a flight in Helsinki, and Scattered Spider’s run of arrests keeps growing as they triste Microsoft Windows for their operational security.
This is when a cyber crime group trusted Microsoft.
The GDID gives Microsoft access to everyone of your internet history of all applications.
And can also initiate remote monitoring through security updates.
And if you think that there is some hard drive you used encryption that uses TPM.
TPM let's are actually stored with Microsoft for every installation.
Never use Microsoft products and any organisation known for complicity and backdoor installations. | 1 134 |
| 11 | 👍Sim Swap Attack
https://covertaccessteam.substack.com/p/podcast-with-dmitry-kurbatov | 1 678 |
| 12 | 🇮🇱 CARS ARE EXPLODING ACROSS ISRAEL
Iranian cyber units and agents have penetrated the heart of Israel, and multiple assassinations are taking place.
-Ethan Levins (not verbatim)
Source: https://x.com/i/status/2071203804326805937 | 1 502 |
| 13 | 📱 President of Signal (messenger) on shift in policy. | 1 705 |
| 14 | 💀 The Eternal Jew rises with same tricks up the sleeve: ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
https://x.com/i/status/2067993607597092865 | 1 429 |
| 15 | Exploiting CVE-2024-1065 via the Page Cache!
A strategy for physical-page UAFs in MIGRATE_MOVABLE, where Dirty Pagetable and Dirty Cred don't apply.
https://kuzey.rs/posts/MaliUAF/
Demonstrated on the Mali GPU UAF found by Project Zero. | 1 044 |
| 16 | Free research papers
https://sci-bot.ru/ | 1 488 |
| 17 | 📡🅰️🅰️🅰️❎❎🅰️🅰️🅰️🅰️
PimEyes.Com | 1 551 |
| 18 | 👩💻 Performing RCE in Internet Explorer via clickjacking!
Credits: Igor Sak-Sakovsky's (𝕏 | Psych0tr1a)
https://swarm.ptsecurity.com/the-click-that-shouldnt-have-worked-rce-via-clickjacking-in-internet-explorer/ | 1 505 |
| 19 | 📡🛰 For 19 years, GPS satellites have secretly broadcast a “numbers station” in their public signals. We decoded 12M messages: a 2011 flash where 31 of 32 satellites flipped in hours, “ghost” substrings repeating years apart, and a “TEXT” prefix spreading now.
https://lsc-pagepro.mydigitalpublication.com/publication/?i=865273&p=62&view=issueViewer
https://github.com/sjmurdoch/gps-special-messages
https://x.com/i/status/2061829547289387209 | 1 898 |
| 20 | 🔗🆒🆒🔤🆒🆒🆒🆒
Transfer data between devices using just QR codes!
QR-Beam — A browser-based data transfer tool where both sender and receiver run entirely client-side via JavaScript. No installation, simple mobile-friendly UI, and designed for real-world use.
The idea isn't new, but was focused on turning it into a practical, production-ready solution with several improvements over existing PoCs.
Beta: https://ckure.org/rx/QR-Beam | 1 |
