TGViewer
Channel Public Channel
cKure Red

cKure Red

@ckured

The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

☕️ or queries email us
📨 i@ckure.org
Subscribers
2.78K
Photos
73
Videos
69
Links
480

Showing posts older than #606 · Back to latest

Older Posts 20 shown
Post #605 1.44K
🔴 Hackers Decrypt Telco Customer Data.

👤Most sensitive data be encrypted by organizations that handle it? Yes, absolutely. Is it always encrypted?

🔥Unfortunately, not like in the recent SK Telecom HSS breach, USIM keys were reportedly stored in plain format without proper protection.

💻 Now, what happens when the stolen data is encrypted?
Time plays in the hacker’s favour. If the data has long-term value, they may invest effort in decrypting it, and that's exactly what seems to have happened here:

📂 A dataset of over 70 million AT&T customer records (some say 86 million) began circulating on cybercrime forums in mid-May 2025:

🔻Full names, birthdates, phone numbers, emails, and addresses.
🔻Around 44 million Social Security Numbers, now fully decrypted!

It’s believed the dataset originates from earlier breaches (possibly 2021), where the SSNs were encrypted. But now it’s been fully decrypted, repackaged, and released as a clean structured identity database.

🧨 Which is bad… This data has lifelong fraud potential!
Hackers can use it to bypass most legacy validation and KYC processes, from SIM swap attacks to full-scale identity theft, fraudulent loans, etc.

⚠️ A not so quiet side effect: a reminder that static data was never meant to prove identity. SSNs and similar identifiers were never meant to be authentication factors, but they’ve been treated as such for decades.

Please keep in mind:
🔻SSN + DOB + Address + Else ≠ Identity proof
🔻Any system relying on static identity data is open to impersonation and abuse.


Credits: Linkedin | Dimitry Kurbatov
Post #604 1.58K
💧🌊 Hydroph0bia (CVE-2025-4275) - a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O.

Secure Boot bypass for laptops, embedded and medical devices, and car ECUs: technical details and exploit. Security researcher Nikolaj Schlej shared yesterday a new and quite effective (even trivial) way to bypass Secure Boot in Insyde H20 UEFI BIOS. The vulnerability, CVE-2025-4275, was named Hydroph0bia by the author. Most ARM-based laptops from Acer, HP, Lenovo, Huawei, Samsung, and Dell use this BIOS and are therefore affected. This product is also ported to multiple systems for IoT, SCADA, and critical infrastructure. Insyde H20 continuously presents its solutions for communication devices, robotics, and manufacturing equipment. Car components, as well as other areas in digital mobility (aviation, maritime, and railroad), also use Insyde H20 Secure Boot as part of ARM-based and other UEFI-compatible systems. So, check your SBOMs and make sure your product is not affected.


https://coderush.me/hydroph0bia-part1/

https://coderush.me/hydroph0bia-part2/
Post #601 1.7K
👩‍💻 Zero-Day used by Stealth Falcon (UAE 🇦🇪based APT group) in a spear-phishing campaign:

⛓ .URL file exploitation (assigned CVE-2025-33053)

💻 Custom Mythic implants, LOLBins, and custom payloads

🌍 High-profile targets across the Middle East and Africa.

https://research.checkpoint.com/2025/stealth-falcon-zero-day/
Check Point Research Stealth Falcon's Exploit of Microsoft Zero Day Vulnerability - Check Point Research Check Point Research uncovers Stealth Falcon's cyber espionage campaign exploiting a Microsoft Zero Day Vulnerability
  • 🔥 1
  • 🥴 1
Post #599 1.96K
🟥 Facebook app and other Meta apps are malware that bypass security audits to leak user data to meta servers.

The covert method Meta uses to track mobile browsing without consent — even in incognito mode or with a VPN on all androis devices.

Patch immediately: Reset the phone and make sure not to install any app by Meta.


https://english.elpais.com/technology/2025-06-03/the-covert-method-meta-uses-to-track-mobile-browsing-without-consent-even-in-incognito-mode-or-with-a-vpn.html
EL PAÍS English The covert method Meta uses to track mobile browsing without consent — even in incognito mode or with a VPN A group of researchers has uncovered a system that Instagram and Facebook have been using since September 2024 to collect users’ web browsing history on Android devices
  • 🤯 4
  • ❤ 1
  • 🤡 1
Post #598 1.83K
🤩Google Chrome’s unique handling of referrer-policy creates a major loophole for silent data siphoning.

CVE-2025-4664 proves that even trusted browsers are not immune to catastrophic zero-day vulnerabilities.

Cross-origin data is up for grabs if you haven't updated Chrome or Chromium.


https://wazuh.com/blog/detecting-chrome-cve-2025-4664-vulnerability-with-wazuh/

https://www.techradar.com/pro/security/billions-of-chrome-users-at-risk-from-new-data-stealing-browser-vulnerability-how-to-stay-safe
Wazuh Detecting Chrome CVE-2025-4664 vulnerability with Wazuh | Wazuh Detect the Chrome CVE-2025-4664 vulnerability on Windows and Linux using Wazuh. Learn how to scan and secure your endpoints now.
Post #596 1.97K
A comprehensive review of over 50 research papers on fault injection and side-channel attacks, published between 2009 and 2021, has been compiled by a team of academic researchers. This survey analyzes existing knowledge, significant discoveries, and potential avenues for future research in this field. The accompanying bibliography includes 175 relevant sources.

📁"Physical Fault injection and Side-Channel Attacks on
Mobile Devices: A Comprehensive Analysis"

https://pure.royalholloway.ac.uk/ws/portalfiles/portal/43165354/Physical_Fault_Injection_and_Side_Channel_Attacks_on_Mobile_Devices.pdf
  • 🔥 2
  • 👍 1
  • 😱 1
Post #595 2.6K
🌐Breaking TETRA: a backdoor in cryptography and other security issues in radios used by police, army, and OT worldwide.

Security researchers Jos Wetzels, Carlo Meijer, and Wouter Bokslag shared their research on TETRA technology by reverse engineering Motorola MBTS and MTM5400 radios and extracting the secrets from them.

TETRA is a radio technology patented in 1995 and based on proprietary cryptography. Equipment using this protocol was developed for law enforcement and military clients, as well as for 0T and SCADA systems used in machine-to-machine communication. So, the impact is huge.

The authors also identified traces of the first attacks on TETRA dating back to 2009. It looks like an NDA is not enough to protect against hackers.

References:
All Cops Are Broadcasting: Breaking TETRA After Decades In The Shadows.
https://youtube.com/watch

📝PDF:
https://orangecon.nl/legacy/2024/assets/slides/2024/OrangeCon2024%20-%20All%20Cops%20Are%20Broadcasting.pdf

White Paper 📃
https://www.usenix.org/system/files/usenixsecurity23-meijer.pdf
  • ❤ 1
  • 🤔 1
  • 🥱 1
  • 🆒 1
Post #594 4.58K
3626205.3659144.pdf1.4 MB
✈️ Silently taking over a plane using the ARINC 429 protocol: message injection, modification, and deletion on avionics data buses. Security researchers Daniel Dorigat, Martin Strohmeier, and Stephan Neuhaus shared their academic article, "Air-Bus Hijacking: Silently Taking Over Avionics Systems," on the security analysis of avionics systems in Boeing planes. The main goal was to highlight security weaknesses in avionics data protocols. The authors analyzed the protocols, carried out successful data manipulation attacks, and demonstrated how these attacks could disrupt internal plane systems and feed false information to the pilots. The attacks require physical access to the bus, and there is currently no way to carry them out from outside the plane… yet.
  • 🔥 4
Post #593 2.35K
📱 Samsung shares surveillance software under the control of the Israeli firm [IronSource].

📌 A class of Samsung devices are vulnerable.

📌Legally, Samsung can not install the third-partyware.

📌App cloud ☁️ can not be removed unless the device is rooted.
  • 👏 3
  • 🤮 2
  • 🤯 1
  • 😨 1
Post #592 2.04K
😎😎😎 Zuckerberg's contribution to genocide. The jew ✡️ who hired Zionists from Mossad / Unit 8200 and likes; as employees at high positions to access WhatsApp data of users and, in one instance murdering all members of a group for the fact that one of the members was once affiliated with Hamas militant group.
  • 🤮 5
  • 👍 2
  • 😨 2
  • ❤‍🔥 1
  • 🔥 1
  • 👏 1
  • 🆒 1
Post #589
cKure Red pinned «🍎CVE-2025-31200: Apple iPhone RCE by opening a video file. 🎞https://youtu.be/nTO3TRBW00E»
Post #587 1.77K
🔒Bypassing CrowdStrike Falcon using PowerShel.

Simulated scenario where a PowerShell script is used to silently bypass a CrowdStrike Falcon endpoint and establish a reverse shell all while the sensor is running
Objective: Demonstrate how threat actors may abuse trusted scripting environments and highlight the importance of layered defence and behavioural detection.

Source: Linkedin Bibek Sapkota
  • 👻 5
  • 👍 3
Post #586 1.6K
Post #585 1.88K
🍏 CVE-2024-44236: Remote Code Execution vulnerability in Apple macOS.

An out-of-bounds write vulnerability has been reported in macOS. The vulnerability is due to the lack of proper validation of “lutAToBType” and “lutBToAType” tag types.

A remote attacker could exploit this vulnerability by enticing a victim to open a crafted file. A successful attack may result in code execution on the victim's machine in the context of the running process.


https://www.zerodayinitiative.com/blog/2025/5/7/cve-2024-44236-remote-code-execution-vulnerability-in-apple-macos
Zero Day Initiative Zero Day Initiative — CVE-2024-44236: Remote Code Execution vulnerability in Apple macOS In this excerpt of a Trend Vulnerability Research Service vulnerability report, Nikolai Skliarenko and Yazhi Wang of the Trend™ Research Team detail a recently patched code execution vulnerability in the Apple macOS operating system. This bug was originally…
  • 👍 1
Post #584 1.85K
❤️ Running code on Tesla security ECU from tire: dlDetails on new CVE-2025-2082 vulnerability.

Security researchers Thomas Imbert, Vincent Dehors, and David Bérard found and responsibly disclosed recently a remote code execution (RCE) vulnerability in Tesla's VCSEC ECU.

Technical overview: By manipulating the response sent from the Tire Pressure Monitoring System (TPMS), an attacker can trigger an integer overflow and execute code in the context of the VCSEC module. This gives the attacker the ability to send arbitrary messages to the vehicle's CAN bus.

More details: "0-click RCE on Tesla Model 3 through TPMS Sensors" [PDF]:
https://www.synacktiv.com/sites/default/files/2024-10/hexacon_0_click_rce_on_tesla_model_3_through_tpms_sensors_light.pdf

Advisory: https://www.zerodayinitiative.com/advisories/ZDI-25-265/

Under Pressure: Exploring a Zero-Click RCE Vulnerability in Tesla's TPMS:
https://vicone.com/blog/under-pressure-exploring-a-zero-click-rce-vulnerability-in-teslas-tpms
  • 👍 3
  • 🆒 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →