⤷ Title: Everything You Need to Know About OpenSSH
════════════════════════
𐀪 Author: Kuldeepkumawat
════════════════════════
ⴵ Time: Sun, 11 May 2025 13:51:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #networking #devops #openssh #linux
════════════════════════
𐀪 Author: Kuldeepkumawat
════════════════════════
ⴵ Time: Sun, 11 May 2025 13:51:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #networking #devops #openssh #linux
Medium
How OpenSSH Keeps the Internet Secure (And How to Use It Like a Pro)
Security is not a product, but a process. — Bruce Schneier
⤷ Title: Hardening Linux : OpenSSH
════════════════════════
𐀪 Author: Fahmi Saddam
════════════════════════
ⴵ Time: Thu, 05 Jun 2025 12:09:48 GMT
════════════════════════
⌗ Tags: #hardening #openssh #cybersecurity #idnbootcampcyber
════════════════════════
𐀪 Author: Fahmi Saddam
════════════════════════
ⴵ Time: Thu, 05 Jun 2025 12:09:48 GMT
════════════════════════
⌗ Tags: #hardening #openssh #cybersecurity #idnbootcampcyber
Medium
Hardening Linux : OpenSSH
SSH adalah jalur utama Anda untuk mengelola server dari jauh. Jika ini bobol, habislah sudah. Jadi, amankan baik-baik! File yang akan kita…
⤷ Title: OpenSSH Flaw (CVE-2025-61984) Allows Remote Code Execution via Usernames
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 02:34:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_61984 #git #OpenSSH #ProxyCommand #rce #Remote Code Execution #ssh
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 02:34:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_61984 #git #OpenSSH #ProxyCommand #rce #Remote Code Execution #ssh
Daily CyberSecurity
OpenSSH Flaw (CVE-2025-61984) Allows Remote Code Execution via Usernames
OpenSSH (before 10.1) has a flaw (CVE-2025-61984) that allows RCE when ProxyCommand is used. Attackers exploit control characters in usernames to inject commands.
⤷ Title: OpenSSH 10.1 Released: Security Fixes and Post-Quantum Warnings
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 08:50:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #cryptography #cybersecurity #OpenSSH #post_quantum #security #ssh #Update
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 08:50:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #cryptography #cybersecurity #OpenSSH #post_quantum #security #ssh #Update
Penetration Testing Tools
OpenSSH 10.1 Released: Security Fixes and Post-Quantum Warnings
OpenSSH 10.1 is released with a critical fix for shell injection, a new warning for weak crypto, and socket relocation for enhanced security and performance.
⤷ Title: OpenSSH ProxyCommand Flaw CVE-2025-61984 Bypasses Filters, Allowing RCE via Crafted Usernames
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 02:32:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #CVE_2025_61984 #Git Submodule #OpenSSH #ProxyCommand #RCE #Shell Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 02:32:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #CVE_2025_61984 #Git Submodule #OpenSSH #ProxyCommand #RCE #Shell Security
Penetration Testing Tools
OpenSSH ProxyCommand Flaw CVE-2025-61984 Bypasses Filters, Allowing RCE via Crafted Usernames
OpenSSH (before 10.1) has a flaw (CVE-2025-61984) allowing RCE via the ProxyCommand and specially crafted usernames. The exploit uses shell syntax errors in Bash to inject malicious commands.
⤷ Title: Sandworm APT Attacks Belarus Military With LNK Exploit and OpenSSH Over Tor obfs4 Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 01 Nov 2025 11:35:46 +0000
════════════════════════
⌗ Tags: #Cyber Security #Belarus Military #DLL Sideloading #LNK Exploit #obfs4 #OpenSSH #Russia APT #SANDWORM #Tor network
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 01 Nov 2025 11:35:46 +0000
════════════════════════
⌗ Tags: #Cyber Security #Belarus Military #DLL Sideloading #LNK Exploit #obfs4 #OpenSSH #Russia APT #SANDWORM #Tor network
Daily CyberSecurity
Sandworm APT Attacks Belarus Military With LNK Exploit and OpenSSH Over Tor obfs4 Backdoor
Cyble exposed a Sandworm-linked espionage campaign targeting Belarusian military UAV personnel. It uses a malicious LNK file to deploy OpenSSH over Tor obfs4 for stealthy, persistent remote access.
⤷ Title: Operation SkyCloak Targets Russian/Belarusian Military With LNK Exploit and OpenSSH Over Tor Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:41:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Belarus Military #DLL Sideloading #LNK Exploit #obfs4 #OpenSSH #Russian Espionage #SkyCloak #Tor network
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:41:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Belarus Military #DLL Sideloading #LNK Exploit #obfs4 #OpenSSH #Russian Espionage #SkyCloak #Tor network
Daily CyberSecurity
Operation SkyCloak Targets Russian/Belarusian Military With LNK Exploit and OpenSSH Over Tor Backdoor
SEQRITE exposed SkyCloak, an espionage campaign targeting Russian/Belarusian military personnel. It uses malicious LNK files to deploy OpenSSH over Tor obfs4 bridges for stealthy, persistent remote access.
⤷ Title: OpenSSH & Tor: ‘Operation SkyCloak’ Targets Defense Agencies with Stealthy Multi-Stage Backdoor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 03:53:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Backdoor #Belarus #cybersecurity #Espionage #obfs4 #OpenSSH #Operation SkyCloak #phishing #Russia #Tor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 03:53:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Backdoor #Belarus #cybersecurity #Espionage #obfs4 #OpenSSH #Operation SkyCloak #phishing #Russia #Tor
Penetration Testing Tools
OpenSSH & Tor: 'Operation SkyCloak' Targets Defense Agencies with Stealthy Multi-Stage Backdoor
Operation SkyCloak targets Russian/Belarus defense with a multi-stage backdoor using OpenSSH and Tor/obfs4 for stealthy C2. The malware checks for sandboxes before execution.
⤷ Title: Critical Alert: Moxa Switches Exposed to OpenSSH Remote Code Execution (CVSS 9.8)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 00:07:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2023_38408 #ICS security #Industrial Ethernet Switches #Moxa #Network Infrastructure #OpenSSH #Remote Code Execution #SCADA Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 00:07:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2023_38408 #ICS security #Industrial Ethernet Switches #Moxa #Network Infrastructure #OpenSSH #Remote Code Execution #SCADA Security
Daily CyberSecurity
Critical Alert: Moxa Switches Exposed to OpenSSH Remote Code Execution (CVSS 9.8)
A critical security vulnerability has been identified in Moxa’s industrial ethernet switches, threatening the integrity of operational technology (OT) networks. The vulnerability, tracked as…
⤷ Title: A Single Line of Code: Pre-Auth OpenSSH Flaw Exposes Ubuntu and Debian Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Mar 2026 00:07:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_3497 #cybersecurity #Debian #GSSAPI Key Exchange #heap corruption #infosec #Linux Security #OpenSSH #Ubuntu #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Mar 2026 00:07:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_3497 #cybersecurity #Debian #GSSAPI Key Exchange #heap corruption #infosec #Linux Security #OpenSSH #Ubuntu #Vulnerability
Daily CyberSecurity
A Single Line of Code: Pre-Auth OpenSSH Flaw Exposes Ubuntu and Debian Servers
A pre-auth flaw in OpenSSH's GSSAPI Key Exchange (CVE-2026-3497) exposes Ubuntu and Debian servers to heap corruption and data leaks. Patch now.
⤷ Title: OpenSSH 10.3 Patches Command Execution and “scp” Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 08:00:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_35385 #CVE_2026_35386 #infosec #Linux Security #OpenSSH #OpenSSH 10.3 #Patch Alert #privilege escalation #Remote Access #SCP #SSH security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 08:00:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_35385 #CVE_2026_35386 #infosec #Linux Security #OpenSSH #OpenSSH 10.3 #Patch Alert #privilege escalation #Remote Access #SCP #SSH security
Daily CyberSecurity
OpenSSH 10.3 Patches Command Execution and “scp” Privilege Escalation
In the critical infrastructure of the internet, OpenSSH stands as one of the most vital gatekeepers for secure remote access. However, even the most trusted tools require constant refinement. A se…
⤷ Title: Legacy Shadows: OpenSSH 10.3 Eradicates Decades-Old “Berkeley rcp” Security Flaws
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 09:55:48 +0000
════════════════════════
⌗ Tags: #Vulnerability #Berkeley rcp #CVE_2026 #Cybersecurity 2026 #Infosec #Linux Security #Network Protocol #OpenSSH 10.3 #privilege escalation #SCP #Shell Injection #SSHD
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 09:55:48 +0000
════════════════════════
⌗ Tags: #Vulnerability #Berkeley rcp #CVE_2026 #Cybersecurity 2026 #Infosec #Linux Security #Network Protocol #OpenSSH 10.3 #privilege escalation #SCP #Shell Injection #SSHD
Penetration Testing Tools
Legacy Shadows: OpenSSH 10.3 Eradicates Decades-Old "Berkeley rcp" Security Flaws
The OpenSSH architects have promulgated version 10.3—an iteration that proves significantly more profound than a mere routine synchronization.
⤷ Title: Velvet Ant Hid in Air-Gapped Network for 10 Years
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:49:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #air_gapped network #China APT #cybersecurity #OpenSSH Compromise #Operation Highland #PAM Backdoor #Velvet Ant
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:49:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #air_gapped network #China APT #cybersecurity #OpenSSH Compromise #Operation Highland #PAM Backdoor #Velvet Ant
Information Security News
Velvet Ant Hid in Air-Gapped Network for 10 Years
Sygnia exposes Operation Highland: China-linked Velvet Ant persisted for nearly 10 years in an air-gapped network by backdooring PAM and OpenSSH.
⤷ Title: Velvet Ant’s Operation Highland: A Decade Inside Critical Infrastructure
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:08:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus threat actor #Critical Infrastructure #CVE_2024_20399 #OpenSSH backdoor #Operation Highland #PAM Backdoor #Sygnia #Velvet Ant
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:08:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus threat actor #Critical Infrastructure #CVE_2024_20399 #OpenSSH backdoor #Operation Highland #PAM Backdoor #Sygnia #Velvet Ant
Daily CyberSecurity
Velvet Ant’s Operation Highland: A Decade Inside Critical Infrastructure
A China-nexus threat group known as Velvet Ant hid inside one organization’s network for nearly a decade. Sygnia’s incident response team uncovered the campaign and named it Operation …
⤷ Title: OpenSSH 10.4 Ships Eight Security Fixes for SSH Clients and Servers
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 15:16:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_59999 #CVE_2026_60001 #CVE_2026_60002 #OpenSSH #OpenSSH 10.4 #SFTP #SSH security #use after free
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 15:16:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_59999 #CVE_2026_60001 #CVE_2026_60002 #OpenSSH #OpenSSH 10.4 #SFTP #SSH security #use after free
Daily CyberSecurity
OpenSSH 10.4 Ships Eight Security Fixes for SSH Clients and Servers
TL;DR OpenSSH 10.4 landed on July 6 with eight security fixes. The most serious is a client-side use-after-free, CVE-2026-60002, scored 7.7. Most other issues involve file transfers and server har…