An exploit developed by GitHub user YassDEV221608 targets a significant vulnerability in the OpenSSH protocol, posing a significant threat to users relying on it for secure communication. The flaw is a race condition within OpenSSH’s server daemon, specifically if a client does not authenticate within the required LoginGraceTime, and has been confirmed not to affect OpenBSD systems. It allows attackers to gain unauthorized root access by executing code.

Smokeloader Users Identified and Arrested in Operation Endgame
Authorities in North America and Europe are arresting users of the Smokeloader botnet, marking a shift in cybercrime enforcement. Following Operation Endgame in May 2024