# Judy Ahmad ## Posts - [CVE-2026-23111: How One Character Gave Away Linux Root](https://judyahmad.com/cve-2026-23111-linux-kernel-root/): Every now and then, a kernel bug comes along that is humbling precisely because it is so small. CVE-2026-23111 is one of those. It is a use-after-free in the Linux kernel’s nf_tables subsystem, and it lets an unprivileged local user climb all the way to root — and break out of a container while doing it. The root cause is a single inverted check. One character. That is the whole story, and that is exactly why I think it is worth writing about. As of this week there is a fully documented, working exploit in public, so this has moved out […] - [Building a Simple Encrypted Password Manager in Python](https://judyahmad.com/building-encrypted-password-manager-python/): For a long time I’ve been bouncing between Python tutorials — following along, copying code, feeling like I understood it, then realizing days later that I couldn’t write any of it from scratch. The cure was obvious: stop reading and start building. So I built a small password manager. Nothing fancy: a CLI tool that generates strong passwords, scores their strength, encrypts them with Fernet, and stores them locally. So I built an encrypted password manager in Python — a small CLI tool that generates strong passwords, scores their strength, encrypts them with Fernet, and stores them locally. This post walks […] - [1 Million Exposed AI Services: How Bad Is LLM Security?](https://judyahmad.com/1-million-exposed-ai-services-how-bad-is-llm-security/): What’s exposed Researchers from Intruder scanned over 2 million hosts and found 1 million exposed AI services online. The findings are bad — most LLM deployments ship with insecure defaults, and many sit on the public internet with no authentication at all. This isn’t a hypothetical risk. Real user data, internal company workflows, and production AI agents are accessible to anyone who knows where to look. What the scan found The investigation surfaced three categories of exposed services: Why this happens The pattern across these projects is “insecure by design”: The AI ecosystem is moving faster than its security model. Defaults […] - [MetInfo CMS Vulnerability CVE-2026-29014 Exploited in Wild](https://judyahmad.com/metinfo-cms-vulnerability-cve-2026-29014-exploited-in-wild/): What happened CVE-2026-29014, a code injection vulnerability with a CVSS score of 9.8, has been discovered in MetInfo CMS versions 7.9, 8.0, and 8.1. This flaw allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Technical details The vulnerability is rooted in the “/app/system/weixin/include/class/weixinreply.class.php” script and stems from a lack of adequate sanitization of user-supplied input when issuing Weixin (aka WeChat) API requests. To exploit this vulnerability, attackers need to inject and execute arbitrary PHP code. On non-Windows servers, the “/cache/weixin/” directory must exist beforehand, which is created when installing and configuring the official WeChat […] - [Claude Mythos: The AI Model That's Rewriting the Rules of Cybersecurity](https://judyahmad.com/claude-mythos-ai-cybersecurity-project-glasswing/): If you work in cybersecurity — or you’re studying to get into the field — you need to pay attention to what just happened. Claude Mythos is here, and it’s about to change everything we know about vulnerability research. On April 7, 2026, Anthropic announced Claude Mythos Preview, a new AI model that sits above their entire existing lineup (Haiku, Sonnet, Opus) in a brand-new tier called Capybara. And it’s not just “a little better.” This thing is a completely different animal when it comes to security. In just a few weeks of testing, Mythos found thousands of zero-day vulnerabilities — […] - [Metasploit Tutorial – Learn How to Use Metasploit](https://judyahmad.com/metasploit-tutorial/): Metasploit is a powerful and widely-used framework in the field of penetration testing and cybersecurity. It is used to discover vulnerabilities, develop exploits, and manage exploitation sessions—all within a safe and legal testing environment. This Metasploit tutorial will guide you through the basics of using Metasploit, one of the most powerful frameworks for penetration testing and cybersecurity. 📌 This article is also available in Arabic: here What is Metasploit? A Brief History Metasploit was created by H.D. Moore in 2003 as a portable tool. It initially started as a Perl project and was completely rewritten in Ruby by 2007. In October 2009, the project […] - [What is Penetration Testing (Pen Test)?](https://judyahmad.com/what-is-penetration-testing-pen-test/): Penetration Testing (Pen Test), also known as Ethical Hacking, is the process of simulating a real-world cyberattack against computer systems, networks, or web applications.The main goal is to identify security vulnerabilities before malicious hackers exploit them, and then fix those weaknesses to improve overall security. 📌 This article is also available in Arabic: here Why is Penetration Testing Important? Types of Penetration Testing Areas of Penetration Testing The Penetration Testing Process Penetration testing usually involves several key phases: Popular Penetration Testing Tools Metasploit – Framework for developing and executing exploits.Burp Suite – Essential tool for web application security testing.Nmap – Network […] - [SMB Enumeration Using Nmap – NetBIOS Scanning & Lab Setup](https://judyahmad.com/smb-netbios-enumeration-using-nmap-a-full-lab-setup/): In this article, we’ll walk through SMB enumeration using Nmap, a core skill in the enumeration phase of penetration testing. You’ll learn how NetBIOS and SMB services work, how to scan and analyze them, and how to set up a hands-on lab to practice. Understanding NetBIOS and SMB NetBIOS (Network Basic Input/Output System) NetBIOS (Network Basic Input/Output System) is a network protocol used primarily in Windows systems to allow applications on separate computers to communicate over a local area network (LAN). It plays a key role in file and printer sharing, service discovery, and remote resource access in older and legacy […] - [Understanding TCP SYN Flood Attacks: How to Perform and Detect Them With Wireshark](https://judyahmad.com/understanding-tcp-syn-flood-attacks-detect-with-wireshark/): In this article, we’ll delve into TCP SYN Flood attacks, how they work, and how to perform and detect them using Wireshark. A SYN flood attack is a type of Denial-of-Service (DoS) attack that exploits the TCP three-way handshake. By sending an overwhelming number of SYN packets to a server, attackers exhaust the server’s resources, leading to network congestion or making the server unavailable to legitimate users. How Do SYN Flood Attacks Work? To understand a SYN flood attack, let’s first review the normal behavior of the TCP three-way handshake, which establishes a reliable connection between a client and a server. […] - [Wireshark Tutorial: How to Install and Use Wireshark](https://judyahmad.com/introduction-to-wireshark-understanding-and-installing-the-essential-network-analysis-tool/): Wireshark is a powerful network protocol analyzer used to monitor network traffic, troubleshoot issues, analyze communications, and secure networks. It captures and displays data from network packets in real-time, allowing you to see every detail of transactions across your network. This makes Wireshark an essential tool for IT professionals, cybersecurity analysts, and network administrators, helping them identify potential security threats, inefficiencies, and network problems. What is Wireshark? Wireshark allows users to inspect the details of network traffic at various levels, including application, transport, and network layers. It’s especially useful for identifying anomalies, potential intrusions, and troubleshooting network issues like delays, packet […] - [Understanding ARP Poisoning and detection using wireshark](https://judyahmad.com/understanding-arp-poisoning-and-detection-using-wireshark/): In this article, we will explore ARP Poisoning, one of the common Man-in-the-middle(MITM) attack techniques used in network security breaches. The goal of this article is to provide a hands-on guide for setting up a lab environment to perform an ARP poisoning attack and then detect it using Wireshark. By the end of this article, you will: What is ARP Poisoning? ARP (Address Resolution Protocol) is a protocol used to map IP addresses to MAC addresses in a local network. ARP Poisoning (or ARP Spoofing) is a network attack that allows an attacker to intercept communication between devices on the same […] ## Pages - [Articles (English)](https://judyahmad.com/articles-english/): Articles (English) Understanding TCP SYN Flood Attacks: How to Perform and Detect Them With Wireshark November 28, 2024 In this article, we’ll delve into TCP SYN Flood attacks, how they work, and how to perform and detect them using Wireshark. A SYN… Read More >> دليل Wireshark: كيفية التثبيت والاستخدام[:ar]دليل Wireshark: كيفية التثبيت والاستخدام November 9, 2024 Wireshark هو أداة قوية لتحليل بروتوكولات الشبكة، تُستخدم لمراقبة حركة المرور عبر الشبكة، حل المشكلات، تحليل الاتصالات، وتأمين… Read More >> Wireshark Tutorial: How to Install and Use Wireshark November 8, 2024 Wireshark is a powerful network protocol analyzer used to monitor network traffic, […] - [Home](https://judyahmad.com/): Hi, I’m Judy Ahmad Welcome to my Cybersecurity Journey, Exploring the World of Cybersecurity and Technology. - [About](https://judyahmad.com/judy-ahmad/): About Judy Ahmad | جودي أحمد | Judy Ahmad Eager to learn Judy Ahmad جودي أحمد >  Hey! I’m Judy Ahmad — a Kurdish-Syrian self-taught cybersecurity student. I have a deep curiosity for how systems work and how they can be broken. Every day I’m learning something new about penetration testing, network security, and incident response — and I document everything along the way on this blog, in English, Arabic, and Kurdish. I believe the best way to truly learn something is to teach it to others. My Work ↓ Get in Touch Areas of Interest 🔓 Penetration Testing Learning ethical […] - [Portfolio](https://judyahmad.com/portofolio/): Portfolio Selected projects I’ve built and documented — code, cybersecurity tools, and writing. Password Tool A simple encrypted password generator and manager built in Python. Uses Fernet symmetric encryption (AES-128 + HMAC-SHA256) to securely store passwords locally, with a customizable generator, strength scoring, and an interactive CLI menu. Built as a hands-on learning project to apply Python fundamentals and practical cryptography. Python • Cryptography (Fernet) • CLI View on GitHub ## Optional - [Agent (MCP protocol)](websites-agents.hostinger.com/judyahmad.com/mcp) [comment]: # (Generated by Hostinger Tools Plugin)