● Exclusive – Zero-Day: A critical security vulnerability has been identified in appviewx. It can be used to spoof certificates. This is not the official def. Will wait for researcher to share details. https://t.me/cKure/12029
All posts tagged cyber
December 24, 2022 at 11:17PM
Impact of the Zero-Day (mentioned here: https://t.me/ckuRED/231). Enrollment: An adversary can issue a certificate from the CA and later use that for hosting fake websites that all the clients of that firm under attack will automatically trust. Revocation: An adversary can bring down any website /application by just getting the public certificate of that application.…
December 24, 2022 at 09:42PM
● Exclusive – Zero-Day: A critical security vulnerability has been identified in ACME. It can be used to spoof certificates. This is not the official def. Will wait for researcher to share details. https://t.me/cKure/12026
December 22, 2022 at 11:08AM
■■□□□ Data-Leak: Hackers Breach Okta’s GitHub Repositories, Steal Source Code. https://thehackernews.com/2022/12/hackers-breach-oktas-github.html https://t.me/cKure/12025
December 22, 2022 at 11:07AM
■■□□□ Microsoft research uncovers new Zerobot capabilities. https://www.microsoft.com/en-us/security/blog/2022/12/21/microsoft-research-uncovers-new-zerobot-capabilities/ https://t.me/cKure/12024
December 22, 2022 at 11:02AM
■■■□□ Fuzzing Golang msgpack for fun and panic. https://redcanary.com/blog/fuzzing/ https://t.me/cKure/12023
December 20, 2022 at 11:16AM
■■■□□ PS5 Kernel Exploit: ELF Loader added to BD-JB version. https://wololo.net/2022/12/18/ps5-kernel-exploit-elf-loader-added-to-bd-jb-version/ https://t.me/cKure/12022
December 20, 2022 at 10:51AM
Critical Windows code-execution vulnerability went undetected until now. https://arstechnica.com/information-technology/2022/12/critical-windows-code-execution-vulnerability-went-undetected-until-now/ https://t.me/cKure/12021
December 19, 2022 at 09:21PM
■■■■□ A POC for the new injection technique, abusing windows fork API to evade EDRs. https://github.com/deepinstinct/Dirty-Vanity https://t.me/cKure/12020
December 19, 2022 at 12:55PM
■■■■■ Get root on macOS 13.0.1 with CVE-2022-46689 (macOS equivalent of the Dirty Cow bug), using the testcase extracted from Apple’s XNU source. https://github.com/zhuowei/MacDirtyCowDemo https://t.me/cKure/12018
