When AI finds everything, the trick is knowing which vulnerabilities matter. 🛡When AI finds everything, the trick is knowing which vulnerabilities matter. 🛡When AI finds everything, the trick is knowing which vulnerabilities matter. 🛡When AI finds everything, the trick is knowing which vulnerabilities matter. 🛡️
🚨 Critical Linux Kernel Vulnerability Alert
Qualys has disclosed ssh-keysign-pwn: a 6-year race condition in __ptrace_may_access() that lets unprivileged local users read root-owned files.
A privileged process (e.g. ssh-keysign or chage) opens sensitive FDs. During do_exit(), after exit_mm() (mm=NULL) but before exit_files(), pidfd_getfd() can steal those FDs.
Impact: • Theft of host SSH private keys → real impersonation & MitM risk until keys are rotated • Full read access to /etc/shadow → offline password cracking
Affected: All kernels before 31e62c2ebbfd (May 14, 2026) — Ubuntu, Debian, Arch, CentOS, Raspberry Pi OS and more.
Immediate action required: Apply the kernel patch NOW.
🔗 PoC: https://t.co/UZJyKb6Szj 🔗 Patch: https://t.co/rNU2YB4mVv…/31e62c2ebbfd 🔗 Full analysis: Phoronix & Qualys oss-security
#LinuxSecurity #KernelVulnerability #CyberSecurity #InfoSec #OpenSSH #PrivilegeEscalation #ThreatIntelligence #Linux #CyberThreat #PatchNow
I kinda feel bad for the tech bros in cyber security that spend 8-10 hours a day writing agents, prompts, solving hard problems, and handholding AI all day long all to say that AI did all the work completely on its own and fully unguided when they find a good bug.
Looking back at 2005 in Bucharest, we had a small team with a simple belief: people deserve to do less boring tasks and more rewarding work. Nobody thought RPA was possible then - just like nobody believed our 5-minute demo would work in 2013 when competitors needed two days.
Today we're launching our agentic automation platform. This is about solving real problems for companies drowning in 175+ applications, through a platform that combines what robots do best (repetitive execution), what agents do best (reasoning), and what humans do best (judgment) - all orchestrated through Maestro.
The technology actually works. That's what matters to me as an engineer.
https://t.co/cUCRnzTZLs
🤝 @UiPath este și în acest an partener al #RoCSC2024, precum și al #ECSC2024!
🛡️💻 Echipa UiPath va contribui la selecția și pregătirea tinerilor care vor reprezenta țara noastră la Finala Campionatului European în Octombrie 2024, la Torino.
#UiPath#cybersecurity#TeamRomania
Windows Exploit Mitigation Series thus far:
- Do Not Allow Child Processes:
https://t.co/oDItEY7uOC
- Stack Pivot Protection:
https://t.co/DP8WeP7WQT
- Isolated Heaps:
https://t.co/qnpMY5aIQC
- High level look at CFG and Heap Spraying:
https://t.co/mj9Va674FP
As a high-level IC at meta who isn’t in charge of a specific large-scale system, my job is basically to fix big, ill-defined problems.
The problem with these problems though is that they usually can’t be solved by one person, or else they already would have been solved. They’re also often orthogonal to stated goals: they’re emergent from the current set of incentives and systems.
To solve them usually requires first identifying the forces in the systems causing the emergent problem and then applying lots of nudges and adjustments all over the place — people, tech, goals, politics.
In the end, if they do get solved, the solution doesn’t turn out looking like something *I* did. Instead, I was the proximate cause.
It reminds me a bit of the joke about the person stranded in the ocean praying to god for help. As a variety of rescuers come by, the person waves them away saying god will save them. Eventually the person drowns and confronts god about not saving them. God responds, “what do you think I sent the two boats and helicopter for?!”
For me, I’m usually not the person that wrote the code or ran the project or set of projects that ended up resolving the issue, but they may not have been done the same way or at all without me.
To operate like this requires a high level of trust between me and my manager. And in fact, because the biggest problems often arise AS A RESULT OF current systems, they aren’t even *approachable* without a deep foundation of trust.
To jump on @HackingLZ ‘s statement. I also believe that every internal red team should have a development team. Yes, separate people who specialize in software development, to build tools to make the red team more effective. One good developer is multiplicative on a red team.
Are you ready for Starfield?
Starting now until 5pm PST on Sunday, September 3rd, we'll be hosting a giveaway in partnership with @AMD to give you the chance to win ONE of FIVE Starfield AMD Radeon RX 7900 XTX and Ryzen 7 7800X3D combos with a premium edition game code. Just sign-up at https://t.co/thtuxFmqoY to enter for a chance to win!