Critical Zero-Day in OpenSSH Exposes Millions of Linux Servers to RCE
Security researchers disclosed a critical unauthenticated remote code execution flaw in OpenSSH affecting versions 8.5p1 through 9.7p1. Patch immediately — active exploitation confirmed in the wild.
Because The Hacker News has flagged this as a breaking, actively-developing story, details may change as more information becomes available. Treat the specifics below as a first read rather than a final account.
For security teams, the practical question is always the same: what changes because of this? Unpatched systems are the most common route into an organisation. Prioritise patching internet-facing assets and confirm your asset inventory reflects every affected version.
Follow the source link below for the full report and any indicators of compromise the original authors have published.