Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

China’s vast tools secretly extract from SMS, GPS data and confiscated mobile phones.

UNG0002 group hits Hong Kong China in Pakistan using LNK files and rats in twin campaign

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » New OpenSSH flaws allow mid and DOS attacks – patch now
Identity

New OpenSSH flaws allow mid and DOS attacks – patch now

userBy userFebruary 18, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

February 18, 2025Ravi LakshmananVulnerability/Network Security

openssh

Two security vulnerabilities have been discovered in the Openssh Secure Networking utility suite. conditions.

The vulnerabilities detailed by the Qualys Threat Research Unit (TRU) are listed below –

CVE-2025-26465-OpenSSH client contains versions 6.8p1-9.9p1 (comprehensive) logic errors that are vulnerable to active MITM attacks when the VerifyHostKeyDNS option is enabled. Client tries to connect to IT (introduced December 2014) CVE-2025-26466- OpenSSH client and server are pre-accepted between versions 9.5p1 and 9.9p1 (comprehensive) causing memory and CPU consumption Vulnerable to DOS attacks (Introduced (Introduced) August 2023)

“If an attacker can perform a midterm attack via CVE-2025-26465, the client can accept the attacker’s key rather than the legal server key,” said Qualys Tru’s product manager One Saeed Abbasi said.

Cybersecurity

“This destroys the integrity of the SSH connection, allowing for potential interception and tampering with the session before the user can achieve that.”

In other words, successful exploitation allows malicious actors to compromise and hijack SSH sessions, allowing unauthorized access to sensitive data. It is worth noting that the VerifyHostKeyDNS option is disabled by default.

Meanwhile, repeated use of CVE-2025-26466 brings the issue of availability, preventing administrators from managing servers, locking legal users, and effectively crippling daily operations. can.

Both vulnerabilities are addressed in version OpenSSH 9.9p2 released today by OpenSSH maintainer.

This disclosure could result in uncertified remote code execution with root privileges for GLIBC-based Linux systems after Qualys shed light on another Openssh flaw called Regresshion (CVE-2024-6387). there is.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCambridge impulses lead the charging of battery technology
Next Article Trump administration gives schools a deadline to end the DEI program
user
  • Website

Related Posts

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

July 18, 2025

China’s vast tools secretly extract from SMS, GPS data and confiscated mobile phones.

July 18, 2025

UNG0002 group hits Hong Kong China in Pakistan using LNK files and rats in twin campaign

July 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

China’s vast tools secretly extract from SMS, GPS data and confiscated mobile phones.

UNG0002 group hits Hong Kong China in Pakistan using LNK files and rats in twin campaign

Ivanti Zero-Days was exploited to drop MdifyLoader and launch a cobalt strike attack in memory

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

BREAKING: TwinH Set to Revolutionize Legal Processes – Presented Today at ICEX Forum 2025

Building AGI: Zuckerberg Commits Billions to Meta’s Superintelligence Data Center Expansion

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.