December 24, 2022 at 11:19PM

● Exclusive – Zero-Day: A critical security vulnerability has been identified in appviewx. It can be used to spoof certificates. This is not the official def. Will wait for researcher to share details. https://t.me/cKure/12029

December 24, 2022 at 11:17PM

Impact of the Zero-Day (mentioned here: https://t.me/ckuRED/231). Enrollment: An adversary can issue a certificate from the CA and later use that for hosting fake websites that all the clients of that firm under attack will automatically trust. Revocation: An adversary can bring down any website /application by just getting the public certificate of that application.…

December 24, 2022 at 09:42PM

● Exclusive – Zero-Day: A critical security vulnerability has been identified in ACME. It can be used to spoof certificates. This is not the official def. Will wait for researcher to share details. https://t.me/cKure/12026

December 20, 2022 at 10:51AM

Critical Windows code-execution vulnerability went undetected until now. https://arstechnica.com/information-technology/2022/12/critical-windows-code-execution-vulnerability-went-undetected-until-now/ https://t.me/cKure/12021

December 19, 2022 at 12:55PM

■■■■■ Get root on macOS 13.0.1 with CVE-2022-46689 (macOS equivalent of the Dirty Cow bug), using the testcase extracted from Apple’s XNU source. https://github.com/zhuowei/MacDirtyCowDemo https://t.me/cKure/12018