cKure Red – Telegram
cKure Red
2.29K subscribers
69 photos
31 videos
21 files
444 links
The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

☕️ or queries email us
📨 i@ckure.org
Download Telegram
📱 Critical zero-click vulnerability (CVE-2025-55177) within WhatsApp has been leveraged in targeted spyware operations, in conjunction with an Apple Imagel0 flaw (CVE-2025-43300).

This combination enabled malicious actors to disseminate exploits via WhatsApp, resulting in potential data exfiltration from the user's Apple device.
The attack sequence involved:
🚫Attacker-controlled delivery
🚫Malicious DNG/remote image (Imagel0) parsing vulnerability (OOB write)
Remote code execution
All occurring without user engagement.

https://techcrunch.com/2025/08/29/whatsapp-fixes-zero-click-bug-used-to-hack-apple-users-with-spyware/

https://blog.quarkslab.com/patch-analysis-of-Apple-iOS-CVE-2025-43300.html
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥2211
DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains.

EtherHiding, a novel technique where the attackers embed malicious payloads (like JADESNOW and INVISIBLEFERRET malware) within smart contracts on public blockchains (like BNB Smart Chain and Ethereum).

https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding/
🔥511
This media is not supported in your browser
VIEW IN TELEGRAM
■■■■□ Illegal cell tower location tracking en-masse as FARA disclosure of yet another Jew act emerges.

Credits: Ian Caroll
🤔1😱1😐1
This media is not supported in your browser
VIEW IN TELEGRAM
🔴Cybercrime-as-a-Service Takedown

Major coordinated operation leads to the arrest of 7 suspects behind a large-scale SMS spoofing and SIM-boxing network.

Operation highlights:

🔍 26 searches conducted

👥 5 main operators apprehended

📦 1,200 SIM-boxes running 40,000 SIM cards seized

💳 Hundreds of thousands of additional SIM cards confiscated

🌐 5 servers hosting the illegal service dismantled

💻 2 domains — gogetsms.com & apisim.com — seized and replaced with law enforcement splash pages

💶 €431,000 frozen in bank accounts

💰 $333,000 in crypto seized

🚗 4 luxury cars confiscated


💡 Credits: @smspoolnet (𝕏)
🔗 More: https://x.com/DarkWebInformer/status/1978603403354792430

#CyberSecurity #Takedown #OSINT #CyberCrime #LEA
Please open Telegram to view this post
VIEW IN TELEGRAM
👍21🔥1🤣1
Media is too big
VIEW IN TELEGRAM
🎞 Surveillance company expo gets video taped by journalists.
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥2😱1
WhatsApp 📱 and Signal 📱 suffer from metadata leakage.

📱https://youtu.be/B9Syj555RQc
Please open Telegram to view this post
VIEW IN TELEGRAM
👏4🤔1
cKure Red
📱 Samsung shares surveillance software under the control of the Israeli firm [IronSource]. 📌 A class of Samsung devices are vulnerable. 📌Legally, Samsung can not install the third-partyware. 📌App cloud ☁️ can not be removed unless the device is rooted.
🇮🇱Jew Supply-Chain Attack [last week]: New Samsung Galaxy A and M series phones that have entered Gaza via checkpoints (post official but not-working ceasefire) have malfunctioned and one exploded in the hands of Gaza resident. This is second such incident in two days.

This could be the Israeli supply chain attack as A and M series device by Samsung has a built-in zionist signal intelligence app that collects user telemetric and metadata.

Based on a source around 5K to 10K such devices have entered Gaza.

The app is from Iron Source.
The zionist entity (Israel) has “Iron” in the name of many 🪖 technologies (defense-related):

Iron Beam – Israel. High-energy laser air-defense system.

Iron Fist – Israel. Active protection system for vehicles.

Iron Curtain – US. APS for close-range RPG/missile interception.

Iron Wolf – Lithuania. Mechanized infantry brigade (NATO).

Iron Dome – Missile Defense system of Israel.

Iron Sting – Israel. Precision 120mm mortar-guided munition.

Iron Vision – Elbit helmet-mounted 360° situational awareness for tanks.
Please open Telegram to view this post
VIEW IN TELEGRAM
🤯3🤮2🤔1
🔄Tomiris wreaks Havoc: New tools and techniques of the APT group.

https://securelist.com/tomiris-new-tools/118143/
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥1
📱 React2Shell Ultimate - CVE-2025-66478 Scanner.

https://github.com/hackersatyamrastogi/react2shell-ultimate
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥3👌11
cKure Red pinned a photo