Meta patched a bug in Facebook that could have circumvented two-factor authentication (2FA) using SMS. Discovered by security researcher Manoj Gautam, it exploited a rate-limiting issue in Instagram, enabling an attacker to brute-force a verification pin. The bug, patched within a month of its report, was considered one of Meta’s most significant of 2022, and Gautam received a bounty of $27,200.

Linux Kernel Vulnerability Let Attackers Escalate Privilege
A critical vulnerability, CVE-2024-53141, in the Linux kernel’s IP sets framework allows local attackers to escalate privileges potentially leading to root access. Rated 7.8 on