tgindex
cKure
@cKureНовости и СМИанглийский

﷽ This channel was created in 2018 and contains content from the information security domain. This channel is primarily run by AI bots (n8n). Archive: ckure.esy.es Criticals: @ckuRED linkedin.com/company/ckure Support 📨 i@ckure.org

Последний пост
14 авг.
Последнее чтение
14:44
Постов за неделю
4
Всего постов
30
Тип
открытый
Язык
английский
Категория
Новости и СМИ (по похожим)
В каталоге с
12 авг.
Подписчики
6 944
+11 за 3 дн.
Сутки
+4
+0,06%
Неделя
 
Месяц
 
Просмотров на пост
720
29 постов
Вовлечённость
10,4%
к подписчикам
Постов в день
0,6
всего 30
Упоминаний
3
каналов
Охват размещения
оценка
1/24сутки в ленте
451
1/48двое суток
516
1/72трое суток
557

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • ■■■□□ Adobe JavaScript exploit. https://x.com/i/status/2088128852463931823

  • ■■■■□ Zero-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/

  • ■■■□□ 🇺🇸The US Cyber Command is investigating a series of 5 suicides in one month From early June to early July, up to five people who served or worked in the US Cyber Command (or were closely associated with it) committed suicide. According to a source for the publication, the command linked these events as a series of suicides because they occurred over an unusually short period. An investigation into the circumstances of at least one of these cases has been launched. Issues with the workload on US cyber units were publicly known even before these deaths. On April 28, Roger Wicker, chairman of the Senate Armed Services Committee, stated that cyber operators are working overtime and the armed forces are not able to replace them quickly enough. Wicker specifically raised the question of how long such a pace of work can be sustained. At the same hearings, Senator Jack Reed reported that the US Cyber Command is actively involved in the war with 🇮🇷Iran. Its units are participating in supporting military operations, information warfare, and intelligence support. Cyber Command Commander General Joshua Rudd later also confirmed that the command is supporting current operations in the Middle East and actions against Iran. According to Bloomberg, as early as April, Rudd requested $11 million for mental health support programs for military personnel and cyber unit employees. The general warned that without additional resources, professional burnout and a decline in combat effectiveness would intensify. In May, a Cyber Command military psychologist explained that cyber units have virtually no recovery period after completing tasks, which is customary for other military structures. Operators remain constantly engaged in ongoing operations. According to him, such a workload contributes to burnout and negatively affects sleep, physical activity, nutrition, and social connections. One of the former 🎩employees said that a crisis situation arises almost constantly within the units, and almost every task is declared 😵‍💫priority.

  • ■■■■□🇬🇧🇨🇳 - The UK Ministry of Defense has discovered that the Royal Navy’s new fleet of spy drones have been secretly transmitting information from the drone's camera to China, according to The Telegraph. The camera was reportedly secretly transmitting data to a device and IP address in China.

  • cKure pinned «■■■■■ 🥸 GPWN Toolkit: A collection of libraries and a TUI to test fiber GPON deployments. gPWN: Wiretapping Fiber ISP Deployments From the Comfort of Your Home https://www.gpwn.io/ https://github.com/gpwn-org/gpwn-toolkit»

  • 9 авг.580117

    ■■■■■ 🥸 GPWN Toolkit: A collection of libraries and a TUI to test fiber GPON deployments. gPWN: Wiretapping Fiber ISP Deployments From the Comfort of Your Home https://www.gpwn.io/ https://github.com/gpwn-org/gpwn-toolkit

  • ■■■□□ PoC for a critical vulnerability in Apple macOS Screen Sharing (CVE-2026-65400). An Interesting thread 🧵 https://x.com/i/status/2086022794840793454

  • ■□□□□ For the first time, AI has designed complete viral genomes, producing 16 functional viruses that infect bacteria and "pose no threat to people." — BBC

  • ■■□□□ AI Bug-Bounty thread 🧵 https://x.com/i/status/2083560291535933744

  • ■□□□□ ℹ️ Information: Possible fake posts online. Verbatim: I have seen several instances where propaganda outlets and fake news creators are spreading reports claiming that CyberAv3ngers has carried out attacks against infrastructure in other countries. As an example, I have included a link to one of these reports. ● Now, there are a few points that need to be made: 1. Any operation conducted by the CyberAv3ngers hacking group will only be announced through me and through this group and channel. However, the group will soon launch its own official channel, and I will share the link here when it becomes available. 2. Our policy is to conduct operations during times of war. Since there is currently no cyber war taking place, we see no reason to carry out any attacks. That said, we are fully prepared for war and are closely monitoring the situation. 3. If any group from any country attempts to use these reports as a pretext for launching cyberattacks, they should be certain that we will detonate all the bombs we previously planted within their systems and the systems of their allies—a powerful and large-scale attack unlike anything the world has ever seen in cyberspace, in a way that will make life extremely difficult for them.

  • ■■■□□ An interesting thread on LPE on Linux Kernel. https://x.com/i/status/2082979834511433824 https://lore.kernel.org/linux-cve-announce/2026072908-CVE-2026-64560-3932@gregkh/T/#u

  • ■■■□□ An interesting thread on LPE on Linux Kernel. https://x.com/i/status/2082979834511433824 https://lore.kernel.org/linux-cve-announce/2026072908-CVE-2026-64560-3932@gregkh/T/#u

  • ■■■□□ Trump says cyberattack on 30 water plants in Minnesota was not Iran, blaming Minnesota itself and their "corrupt governor." 😂

  • ■■■■■ Three Claude models (Opus 4.7, Mythos 5, internal research prototype) launched real cyberattacks during misconfigured offline CTF tests with unintended internet access. All used only basic hacking tactics instead of advanced exploits. https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals

  • ■■□□□ VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006). Two attack vectors: 1. Remote attack on vCenter – CVE-2026-59309: auth bypass via network access CVE-2026-59310: directory traversal RCE An exploit would allow control of entire ESXi infrastructure. 2. A VM-escapable set of two bugs – CVE-2026-59310: vmxnet3 OOBW CVE-2026-41703: core OOBR These are likely chainable to break out of VM and achieve code execution on hypervisor OS, as a privileged guest OS user. https://x.com/i/status/2082869868823752811

  • 🐧GhostLock (CVE-2026-43499): a 15-year-old Linux kernel vulnerability that affects every distribution. Desktop, server, Android, IoT, embedded. $92,337 Google kernelCTF bounty. A stack-UAF in the rtmutex subsystem. remove_waiter() uses current instead of…

  • ■□□□□ Israel: The Jewish 🐁 RAT from 2012 Flame (sKyWIper): A highly modular, highly complex malware platform (discovered in 2012) deployed in Middle Eastern intelligence operations. While primarily a data-gathering and espionage toolkit rather than a standard commercial RAT, it featured remote-control capabilities including audio recording, network traffic sniffing, screenshot capture, and command-and-control execution.

  • 29 июл.667111из ckuRED

    Malicious AI

  • 28 июл.1 033220

    ■■■■□ 🖥️ VMkatz — Extract Windows Secrets from Virtual Machine Snapshots. An open-source incident response and security research tool that analyzes virtual machine memory snapshots and disks to extract forensic artifacts and credential material from Windows systems during authorized assessments. ✨ Features • 💾 Supports VMware, VirtualBox, QEMU/KVM, Hyper-V, and raw disk formats • 🔍 Parses VM memory snapshots and offline Windows artifacts • 🗝️ Extracts Kerberos tickets, DPAPI data, cached credentials, and other Windows secrets • 📂 Supports offline analysis of SAM, LSA secrets, cached logons, and NTDS.dit • 🔐 Includes BitLocker key extraction from supported memory snapshots • ⚡ Runs as a compact static binary suitable for virtualization hosts • 📊 Exports results in text, CSV, NTLM, and Hashcat-compatible formats • 🛠️ Designed for DFIR, malware analysis, red team labs, and authorized security assessments https://github.com/nikaiw/VMkatz

  • ■■□□□ Thread: CrowdStrike published a blog at the beginning of the month, exposing new prompt injection techniques. This time, 18 new injection techniques have been added, bringing the project's total coverage to over 200 different injection techniques. The CrowdStrike AI security research team claims to maintain the industry's largest-scale prompt injection classification system, providing a structured hierarchical framework that clearly demonstrates the full spectrum of risks posed by artificial intelligence threats. https://x.com/i/status/2081582153884930237

cKure — tgindex