regreSSHion: biggest security vulnerability since log4shell

B2B Cyber ​​Security ShortNews

Share post

Security researchers report regreSSHion, one of the most significant security vulnerability discoveries in recent years in terms of scale and potential impact.

Discovered by the Qualys Threat Research Unit (TRU), regreSSHion (CVE-2024-6387) is an unauthenticated remote code execution (RCE) vulnerability in OpenSSH's server in glibc-based Linux systems that went undetected for four years. If exploited, this vulnerability could allow an attacker to execute arbitrary code with the highest privileges, which could lead to a complete system takeover, installation of malware, creation of backdoors, and more.

With over 14 million instances worldwide, the RegreSSHion is severe and critical, especially for organizations that rely heavily on OpenSSH to manage remote servers. OpenSSH is known to be a very secure software, and this vulnerability found is a glaring hole in an otherwise nearly flawless implementation.

More at Qualys.com

 


About Qualys:

Qualys is a pioneer and leader in disruptive cloud-based IT, security and compliance solutions. The company has more than 15.700 active customers in over 130 countries, including the majority of the Forbes Global 100 and Fortune 100 companies. Qualys helps companies optimize and consolidate their security and compliance solutions into a single platform, fundamentally secure digital transformation initiatives, and thereby achieve greater agility, better business results and significant cost reductions.


 

Matching articles on the topic

TUM: New seminar trains cybersecurity specialists

The Technical University of Munich (TUM) was selected as the only German university among 23 international universities to offer students a new cybersecurity ➡ Read more

Commentary on the Digital Operational Resilience Act (DORA)

Unlike other economic sectors that also have to comply with the NIS2, the financial sector is no stranger to strict regulations such as DORA. ➡ Read more

Zero-Day: Highly dangerous security vulnerability in Microsoft Windows

A new, highly dangerous security vulnerability in Microsoft Windows allows the execution of malicious code via a zero-day exploit. The vulnerability, discovered by ESET researchers, ➡ Read more

AI features transform support into automated workflows

A cloud communications and IT solutions provider announced powerful new AI capabilities for support. These innovative features are designed to simplify IT management ➡ Read more

Germany: Over 37 million phishing attempts in 2024

Last year, phishing attacks in Germany increased by around 16 percent, there were 2,6 million malicious email attachments and almost ➡ Read more

How cybercrime threatens national security

The new Cybercrime Report from the Google Threat Intelligence Group highlights the threat to national security posed by cybercrime. China, Russia and ➡ Read more

Fake updates spread malware

Security experts have identified a new threat that redirects users to compromised websites and prompts them to install fake updates that lead to ➡ Read more

Russian hackers target Ukrainian Signal users

The Google Threat Intelligence Group (GTIG) publishes its research on how the group APT44 (also known as Sandworm) and other ➡ Read more