TGViewer
Channel Public Channel
cKure Red

cKure Red

@ckured

The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

☕️ or queries email us
📨 i@ckure.org
Subscribers
2.78K
Photos
73
Videos
69
Links
480

Showing posts older than #691 · Back to latest

Older Posts 19 shown
Post #690 2.28K
Martha Root highlighted that the targets—WhiteDate, WhiteChild, and WhiteDeal—were essentially "security nightmares" built on a fragile WordPress foundation.

The "Secret" Endpoint: The most glaring flaw was an unauthenticated JSON/REST API endpoint. By simply adding a specific path (reportedly similar to /wp-json/v2/users or a custom /download-all-users/ script left by the devs), Root could bypass the login screen and trigger a full database dump.

Lack of Rate Limiting: The servers did not throttle requests. This allowed Root to run her AI chatbots (using Meta’s Llama) at scale, engaging with hundreds of users simultaneously to scrape personal "intent" data without being blocked.

Backup Mismanagement: Root discovered that the site’s backups were stored on the same server or within the same network environment. By gaining Remote Code Execution (RCE) through a vulnerable plugin (likely an outdated "Form" or "File Manager" plugin), she attained the privileges necessary to delete both the live environment and the archived backups.

The Operator's Response
The administrator of the sites, identified by journalists as a 57-year-old woman in Germany, was reportedly blindsided.
The Initial Denial: Early on, the operator claimed the site was simply "under maintenance."

The Admission: Following the 39C3 presentation, she confirmed on social media (X/Twitter) that the sites were offline. She labeled the hack "cyber-terrorism" and expressed fury over the data leak, particularly the exposure of GPS coordinates that revealed her own location and those of the site's users.

Current Status: As of January 2026, the primary domains remain offline, and the data remains active on the whistleblower site DDoSecrets.

📡 FINAL REPORT: The "Pink Ranger" Ops Summary 📡

The "Martha Root" saga is a masterclass in combining High-Tech AI with Low-Level Security exploits. Here is the final mission brief:
👤 THE HACKER: Martha Root (Pseudonym)
🎭 THE THEATRICS: 39C3 Stage, Pink Power Ranger suit, Live Terminal execution.
🎯 THE TARGETS: WhiteDate, WhiteChild, WhiteDeal.

🛠 TECHNICAL EXECUTION:
AI Infiltration: Used Llama-based LLMs to "catfish" extremists. The AI was trained to speak their language, successfully tricking users into revealing real names and private photos.

Infrastructure Audit: Exploited a "naked" WordPress API. No password was required to pull the user table—just the right URL.
GPS Extraction: Scraped EXIF data from 100GB of uploaded images. This turned "anonymous" profiles into a physical map of far-right activists globally.

The Kill-Switch: Ran lol.py live on stage. The script wiped the production SQL databases and reached into the directory to delete the site's only backups.

⚠️ THE FALLOUT:
8,000+ identities exposed.
100GB of data leaked via DDoSecrets.
okstupid.lol remains the searchable "Hall of Shame" for the victims.

QUOTE: "They thought they were the 'Master Race,' but they couldn't even secure a WordPress plugin." — Martha Root, 39C3.

#Infosec #OpNazi #MarthaRoot #CyberWar #39C3 #WordPressLeak
  • 🤡 11
  • ❤ 5
  • 🔥 2
Post #688 2.97K
🦠Kaspersky researchers discovered preinstalled malware on certain models of tablets running Android – calling it Keenadu.

It's a backdoor in 𝘭𝘪𝘣𝘢𝘯𝘥𝘳𝘰𝘪𝘥_𝘳𝘶𝘯𝘵𝘪𝘮𝘦.𝘴𝘰
Post #687
cKure Red pinned «Zero-Day: Zero-Click RCE on🍏Apple iOS viz. decoding logic vulnerability in Apple's image parser. 📹 https://youtu.be/jJ2QwvMDf7k»
Post #686 2.61K
Post #685 3.24K
🐲 GhidraGPT: A powerful Ghidra plugin that integrates Large Language Models (LLMs) directly into Ghidra to enhance reverse engineering workflows with code analysis and enhancement capabilities.

https://github.com/weirdmachine64/GhidraGPT
GitHub GitHub - weirdmachine64/GhidraGPT: Integrate LLM models directly into Ghidra for AI-enhanced reverse engineering. Integrate LLM models directly into Ghidra for AI-enhanced reverse engineering. - weirdmachine64/GhidraGPT
  • 👏 1
Post #680 2.53K
OSINT via Google 🔍
  • 🤔 1
Post #678 2.51K
🤩🤩 Jewish ✡️ state's another cyber crime unmasked.

Hacked in Pakistan: Israeli Spyware Firm Intellexa, Owned by Ex-intel Officer, Still Active Amid 🤩🤩 United States' Sanctions.

Spyware targets in Pakistan 🤩🤩 and Iraq 🇮🇶 and a new infection method. The sanctions aren't deterring Intellexa 💻

https://www.haaretz.com/israel-news/security-aviation/2025-12-04/ty-article-magazine/.premium/israeli-spyware-firm-intellexa-owned-by-ex-intel-officer-still-active-amid-us-sanctions/0000019a-e3e8-db35-afbf-ebfcb8bb0000
  • ❤ 1
Post #672 2.17K
cKure Red 📱 Samsung shares surveillance software under the control of the Israeli firm [IronSource]. 📌 A class of Samsung devices are vulnerable. 📌Legally, Samsung can not install the third-partyware. 📌App cloud ☁️ can not be removed unless the device is rooted.
🇮🇱Jew Supply-Chain Attack [last week]: New Samsung Galaxy A and M series phones that have entered Gaza via checkpoints (post official but not-working ceasefire) have malfunctioned and one exploded in the hands of Gaza resident. This is second such incident in two days.

➿This could be the Israeli supply chain attack as A and M series device by Samsung has a built-in zionist signal intelligence app that collects user telemetric and metadata.

➿Based on a source around 5K to 10K such devices have entered Gaza.

➿The app is from Iron Source.
The zionist entity (Israel) has “Iron” in the name of many 🪖 technologies (defense-related):

Iron Beam – Israel. High-energy laser air-defense system.

Iron Fist – Israel. Active protection system for vehicles.

Iron Curtain – US. APS for close-range RPG/missile interception.

Iron Wolf – Lithuania. Mechanized infantry brigade (NATO).

Iron Dome – Missile Defense system of Israel.

Iron Sting – Israel. Precision 120mm mortar-guided munition.

Iron Vision – Elbit helmet-mounted 360° situational awareness for tanks.
  • 🤯 3
  • 🤮 2
  • 🤔 1
Post #669 1.87K
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →