TGViewer
Channel Public Channel
cKure Red

cKure Red

@ckured

The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

☕️ or queries email us
📨 i@ckure.org
Subscribers
2.77K
Photos
73
Videos
69
Links
480

Showing posts older than #732 · Back to latest

Older Posts 20 shown
Post #731 1.94K
🤖 🆒🆒🆒🆒🆒🆒
Earlier today Cloudflare's CSO shared how they tested Anthropic Mythos using an unreleased 8-stage vulnerability-discovery agent.

Opus implemented the agent and it works via Claude SDK with a Pro or Max subscription, no API.

https://github.com/evilsocket/audit


𝕏 | Simone
GitHub GitHub - evilsocket/audit: An 8-stage vulnerability-discovery agent. An 8-stage vulnerability-discovery agent. Contribute to evilsocket/audit development by creating an account on GitHub.
  • 🔥 2
Post #730 1.7K
🚀40K Starlink terminals hacked to lure Russians into a cyber trap as per anti-Russia propaganda news.

40,000 Starlink terminals go dark. Russian soldiers scramble for answers and turn to Telegram. They don’t realise they’ve just walked into a trap. The journalists travelled across Ukraine from Lviv to the front line in Zaporizhzhia to uncover a pretty audacious cyber operation. Meet Goldfinger and the 256 Cyber Assault Brigade and Yaro, and the 128th Mechanised Brigade, holding the line in the south.
  • ❤ 1
Post #729 1.49K
🤩 ❗️❗️❗️❗️❗️❗️

LLM used to make a Zero-Day by APT group on a popular software.

The zero day was a 2FA bypass via logic bug 🪲

Security researchers at Alphabet’s Google said they believe a cybercrime group used artificial intelligence to create a hacking tool that can bypass defenses in a widely-used tool to administer computer systems. The scheme, which was foiled when Google alerted the tool developer, would mark the first time that Google’s Threat Intelligence Group caught a hacker using an AI-generated “zero-day” in such a way, according to a report published Monday.
Post #727 1.78K
⚠️⚠️⚠️⚠️⚠️⚠️
CVE-2026-0073: Critical Android Zero-Click, Zero-Day exploit in wireless debugging (if enabled) can allow adjacent hacker (in same network) to execute code as shell user.
  • ❤ 2
Post #726 1.46K
🅰️🅰️🅰️🔢🅰️🅰️🅰️
Devcore team chained ⛓️‍💥 4 logic bugs to achieve sandbox escape in Microsoft Edge in Pwn²Own 2026, Berlin.
Post #724 2.12K
🆒🆒🆒🆒🔢🔢
FAST16 — Pre-Stuxnet Sabotage Malware (2005)

- Referenced in Shadow Brokers (2017) leak (“NOTHING TO SEE HERE”)
- Compiled ~2005 → ~5 years before Stuxnet
- Type: Sabotage malware (not espionage)

Target

- High-precision engineering / simulation software
- Includes LS-DYNA, PKPM, MOHID
- Used for physics, impact, and advanced simulations (incl. nuclear-related domains)

Technique

- Kernel driver: "fast16.sys"
- In-memory patching of target processes
- Injects subtle calculation errors (floating-point manipulation)
- Goal: corrupt outputs while appearing normal

Propagation

- Worm-like spread via weak Windows network shares

Attribution

- Not confirmed
- Strong suspicion: US or allied origin (based on NSA-linked leak context)

Note

- LS-DYNA ≠ purely “explosive software”
- Broader simulation usage; “explosive calculations” is a subset use case
  • 🔥 3
  • 👍 1
Post #723 1.04K
IoT side channel (correlation) attack using WiFi.

Heuristic surveillance data is both widely under-reported and difficult to mitigate without tossing your devices and living in the stone age.
  • 🔥 2
Post #722 1.86K
💽 Phantomdrive is an open-source USB drive designed to conceal its actual capacity. Upon initial insertion, the device presents itself as an 8GB disk. To access the secondary partition, a file named "unlock.txt" must be created, followed by the entry of the password; the drive will subsequently unmount and remount, revealing the remaining data. All data is encrypted in place using an AES-256 key derived from the password. This mechanism is fundamentally different from how Veracrypt operates.
  • 🔥 1
  • 😁 1
  • 🤔 1
  • 🙈 1
Post #720 1.9K
Declassified: Shreya Pharmaceuticals purchased 1,100 XE9680 Dell servers with Nvidia's H100 GPUs at behest of Russia to train computer models for software to be used in automated drones.
Post #719 1.99K
⚡️0️⃣➖🔠🅰️🔠 drop by researcher.

🤩A security researcher, who was not satisfied with Microsoft's response to his report, decided to publicly release a Zero-Day vulnerability.

The vulnerability, named BlueHammer, allows an attacker to perform Privilege escalation and currently has no proper patch.

The researcher claims that the PoC code he published still contains bugs, and various security researchers have confirmed that they have not been able to reproduce the vulnerability (so far).

https://deadeclipse666.blogspot.com/2026/04/public-disclosure.html
Post #718 2.21K
cKure Red 📱AI-H (AI Hacking): Excerpts from a video showing an employee at ANTHROPIC just showed CLAUDE finding ZERO-DAY vulnerabilities in a live conference demo. Claude has found zero day in Ghost, 50,000 stars on github, never had a critical security vulnerability…
📱Claude Code's Entire Source Code Was Leaked via npm Source Maps — Here's What's inside.

https://dev.to/gabrielanhaia/claude-codes-entire-source-code-was-just-leaked-via-npm-source-maps-heres-whats-inside-cjo
DEV Community Claude Code's Entire Source Code Was Just Leaked via npm Source Maps — Here's What's Inside A security researcher found Anthropic's full CLI source code exposed through a source map file. 1,900 files. 512,000+ lines. Everything.
  • 👍 1
Post #716 2.48K
📱AI-H (AI Hacking): Excerpts from a video showing an employee at ANTHROPIC just showed CLAUDE finding ZERO-DAY vulnerabilities in a live conference demo.

Claude has found zero day in Ghost, 50,000 stars on github, never had a critical security vulnerability in its entire, history...


It further found the blind SQL injection in 90 minutes, stole the admin api key, then did the exact, same thing to the linux Kernel, Smart Contract hacking and more.
  • 🔥 4
  • 🤯 2
Post #715 2.06K
⚠️ Privacy breach by US elites as Google 🔍 creates privacy compromising rule.

In August 2025, Google announced ↗ that as of September 2026, it will no longer be possible to develop apps for the Android platform without first registering centrally with Google. This registration will involve:

‼️Paying a fee to Google
‼️Agreeing to Google’s Terms and Conditions
‼️Providing government identification
‼️Uploading evidence of the developer’s private signing key
‼️Listing all current and future application identifiers


https://keepandroidopen.org
Post #714 1.8K
⚠️ Dark Sword 🗡️ hacker group has been actively exploiting Apple iOS Zero-Day exploit to takeover device with a link click.

The exploit chain used 6 Zero-Day vulnerabilities.


Software patch has been released.

https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain
Google Cloud Blog The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors | Google Cloud Blog DarkSword is a new iOS exploit chain that leverages multiple zero-day vulnerabilities to fully compromise iOS devices.
Post #713 1.75K
🔻🅰️🅰️🅰️🅰️🅰️🅰️🅰️🅰️🅰️🅰️
🅰️🅰️🅰️🅰️🅰️🅰️

Electronic-Warfare: Three sources from different government agencies tell 60 Minutes that undercover agents purchased a miniaturized microwave weapon from a complex Russian criminal network. It’s classified. We didn’t see it. But it has been described to us. The weapon is designed to be concealed and small enough to be carried by a person. The vital components were made in Russia, sources say. U.S. officials and their families who have experienced Havana Syndrome say they experienced dizziness, fatigue, memory problems, and impaired vision. In some cases, it led to health conditions like traumatic brain injury, vision, hearing, and memory loss. Our confidential sources tell us the classified weapon has been tested in a U.S. military lab for more than a year. Tests on rats and sheep show injuries consistent with those seen in humans.
Post #712 1.62K
🇮🇷 Summary of the hack

Iran hacks U.S. medical giant - Stryker. The Handala hacker group, that is run by Iran Military Intelligence Services, wiped out 200,000 devices across 79 countries and brought the company’s operations to a complete standstill. This is the story of how they did it and what you can do to protect your organization.
  • 🔥 1
  • 😎 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →