Follow

Ubuntu ‘Command Not Found’ Open to Exploit, Warn Experts

Researchers at Aqua Nautilus say they’ve identified a security issue with the way Ubuntu’s “command not found” feature works that attackers could exploit to trick users into installing malicious snaps. In a lengthy blog post detailing their investigation, the security outfit conclude that “the risk of attackers exploiting the ‘command-not-found’ utility to recommend their own malicious snap packages is a pressing concern”. “The true peril lies in the potential scope of this issue, with attackers capable of mimicking thousands of commands from widely-used packages,” adding “past instances of malicious packages appearing in the Snap Store highlight this issue.” What’s the :sys_more_orange:

:sys_omgubuntu: omgubuntu.co.uk/2024/02/securi

Sign in to participate in the conversation
小森林

每个人都有属于自己的一片森林,也许我们从来不曾走过,但它一直在那里,总会在那里。迷失的人迷失了,相逢的人会再相逢。愿这里,成为属于你的小森林。