// Field Knowledge & Guides

Digital Security Guides & Tutorials

Practical guides for journalists and frontline activists on hardening phones, securing accounts, and countering hacking and inspection attempts.

Security Alerts ⏱️ 3 min read

Critical Vulnerabilities in Ubuntu’s needrestart Utility Expose Servers to Root Access

The needrestart utility, a critical component of Ubuntu Server systems, has been found to contain multiple severe Local Privilege Escalation (LPE) vulnerabilities. Identified by the Qualys Threat Research Unit (TRU), these vulnerabilities (CVE-2024-48990, CVE-2024-48991, CVE-2024-48992, CVE-2024-10224, and CVE-2024-11003) allow unprivileged users to gain full root access without user interaction. Notably, these vulnerabilities have been present […]

ثغرات جديدة في أداة needrestart على أنظمة لينكس

أداة needrestart هي أداة أساسية في أنظمة Ubuntu Server، وقد تم اكتشاف وجود عدة ثغرات خطيرة فيها تتعلق بتصعيد الامتيازات المحلية (LPE). تم التعرف على هذه الثغرات من قبل وحدة أبحاث التهديدات في Qualys (TRU)، وهي تمكّن المستخدمين غير المميزين من الحصول على صلاحيات الجذر (root) دون الحاجة لتفاعل مدير السيرفر. ونظرًا لاستخدام أداة needrestart […]

Security Alerts ⏱️ 2 min read

Apple Fixes Two Zero-Day Vulnerabilities Actively Exploited on Intel-Based Macs

Apple has rolled out emergency security updates to address two zero-day vulnerabilities actively exploited in attacks targeting Intel-based Mac systems. These vulnerabilities, found in macOS Sequoia components, posed critical risks, enabling attackers to remotely execute code and carry out cross-site scripting (XSS) attacks. Apple confirmed these vulnerabilities were exploited in real-world attacks but has not […]

آبل تعالج ثغرتين خطيرتين في أجهزة Mac بمعالجات Intel

أعلنت شركة آبل عن إطلاق تحديثات أمنية طارئة لمعالجة ثغرتين أمنيتين خطيرتين من نوع Zero-Day، تم استغلالهما في هجمات استهدفت أجهزة Mac التي تعمل بمعالجات Intel. الثغرتان، المكتشفتان في مكونات نظام macOS Sequoia، تُشكلان تهديدًا كبيرًا، حيث تمكن المهاجمين من تنفيذ تعليمات برمجية عن بُعد وتنفيذ هجمات XSS (Cross-Site Scripting).  وأكدت آبل أن هذه الثغرات […]

Security Alerts ⏱️ 2 min read

Critical Security Flaw in WordPress Plugin: Millions of Websites at Risk

A major security vulnerability has been recently uncovered in the Really Simple Security plugin (previously known as Really Simple SSL), which is widely used across millions of WordPress websites. The plugin offers several features, including SSL setup, login protection, two-factor authentication (2FA), and instant security scans. The vulnerability, identified as CVE-2024-10924, allows attackers to bypass […]

ثغرة أمنية خطيرة في إضافة WordPress تهدد ملايين المواقع

كُشف مؤخرًا عن ثغرة أمنية شديدة الخطورة في إضافة Really Simple Security (المعروفة سابقًا باسم Really Simple SSL) المختصة بحماية مواقع WordPress، والتي تُستخدم على نطاق واسع في ملايين المواقع. تُقدم الإضافة ميزات عديدة، مثل إعداد SSL، حماية تسجيل الدخول، التحقق بخطوتين (2FA)، وفحص الأمان الفوري. الثغرة، التي تحمل الرمز CVE-2024-10924، تتيح للمهاجمين تجاوز أنظمة […]

Security Alerts ⏱️ 2 min read

Microsoft Fixes Four Zero-Day Vulnerabilities in November 2024 Patch

Microsoft released its monthly security update, Patch Tuesday, addressing 89 vulnerabilities, including four critical zero-day flaws. What is a Zero-Day Flaw? A zero-day flaw is a newly discovered security hole that hackers can exploit before a fix is available. This makes it particularly dangerous. Out of the four zero-day vulnerabilities fixed this month, two were […]

مايكروسوفت تُعالج ثغرات خطيرة في تحديثات نوفمبر 2024

أصدرت شركة مايكروسوفت التحديث الأمني الشهري المعروف باسم “Patch Tuesday” لشهر نوفمبر 2024، حيث عالجت 89 ثغرة أمنية، من بينها أربع ثغرات خطيرة من نوع Zero-Day. ما هي ثغرات Zero-Day؟ ثغرات Zero-Day هي ثغرات أمنية مكتشفة حديثًا لم تصدر لها تحديثات أو حلول بعد، مما يجعلها شديدة الخطورة. في تحديث هذا الشهر، تضمنت الثغرات أربعًا […]

News ⏱️ 2 min read

Signal Makes Group Calls Easier with ‘Call Links’

Signal has rolled out several updates to make group calls simpler and more user-friendly. These improvements focus on accessibility, convenience, and keeping conversations private. Call Links: Simplified Connections: Now you can create a link for a call and share it with others, no need to set up a group chat. Links can be reused for […]

أخبار ⏱️ 2 min read

سيجنال يطرح ميزات جديدة في المكالمات الجماعية

في خطوة تعكس التزامه بتقديم تجربة استخدام مميزة، أعلن تطبيق “سيجنال” عن مجموعة جديدة من الميزات المصممة لتسهيل المكالمات الجماعية وجعلها أكثر سلاسة وخصوصية. التحديثات الأخيرة تركز على تعزيز الوصول، وتحسين تجربة المستخدم، وضمان حماية البيانات الشخصية. روابط المكالمات: سهولة في التنظيم والمشاركة بفضل الميزة الجديدة، أصبح بإمكان المستخدمين إنشاء روابط مباشرة للمكالمات الجماعية ومشاركتها […]