SC StaffDecember 7, 2022
Linux devices are being hacked successful Bring Your Own Filesystem attacks exploiting the open-source Linux PRoot utility, BleepingComputer reports. Such attacks progressive the instauration of a malicious filesystem that already includes the web scanning tools, the XMRig cryptominer, and configuration files anterior to deployment, which is being facilitated by the PRoot utility, a Sysdig study showed. Through PRoot, menace actors would lone person to execute the precompiled room downloaded from GitLab without having to execute further setup commands. Malicious actors could besides leverage PRoot to alteration the download of different payloads that could let much terrible compromise. "Using PRoot, determination is small respect oregon interest for the targets architecture oregon organisation since the instrumentality smoothes retired the onslaught struggles often associated with executable compatibility, situation setup, and malware and/or miner execution. It allows attackers to get person to the doctrine of constitute once, tally everywhere, which is simply a agelong sought-after goal," said Sysdig.
UEFI & SMM Vulnerabilities – Jesse Michael – PSW #764
November 16, 2022
Navigating the UEFI waters is treacherous. While UEFI has go the modular connected astir PCs, servers, and laptops, replacing bequest BIOS, it is simply a analyzable acceptable of standards and protocols. Jesse joins america to assistance explicate however immoderate of this works and picture however vulnerabilities, specifically with SMM, tin manifest and beryllium exploited. Segment Resources: CHIP...
Mobile malware marketplace InTheBox detailed
SC StaffDecember 7, 2022
More than 400 customized web injects for mobile malware are being offered for merchantability by the InTheBox darknet marketplace, which is thought to look successful January 2020, reports The Hacker News.
Sophos addresses Firewall codification execution flaws
SC StaffDecember 7, 2022
SecurityWeek reports that Sophos has fixed 7 codification execution vulnerabilities successful Sophos Firewall arsenic portion of the mentation 19.5 update.