`kernel.yama.ptrace_scope = 2` looks like a promising way to mitigate
0xdeadbeefnetwork/ssh-keysign-pwn
I can't assess it fully, but it does disable the particular PoC published here.
View on GitHub ↗
SaaS Metrics