Linux devices compromised via PRoot utility exploitation - SC Media

1 year ago 54

Device Security, Malware

December 7, 2022

Linux devices are being hacked successful Bring Your Own Filesystem attacks exploiting the open-source Linux PRoot utility, BleepingComputer reports. Such attacks progressive the instauration of a malicious filesystem that already includes the web scanning tools, the XMRig cryptominer, and configuration files anterior to deployment, which is being facilitated by the PRoot utility, a Sysdig study showed. Through PRoot, menace actors would lone person to execute the precompiled room downloaded from GitLab without having to execute further setup commands. Malicious actors could besides leverage PRoot to alteration the download of different payloads that could let much terrible compromise. "Using PRoot, determination is small respect oregon interest for the targets architecture oregon organisation since the instrumentality smoothes retired the onslaught struggles often associated with executable compatibility, situation setup, and malware and/or miner execution. It allows attackers to get person to the doctrine of constitute once, tally everywhere, which is simply a agelong sought-after goal," said Sysdig.

SC Staff

play button

UEFI & SMM Vulnerabilities – Jesse Michael – PSW #764

November 16, 2022

Navigating the UEFI waters is treacherous. While UEFI has go the modular connected astir PCs, servers, and laptops, replacing bequest BIOS, it is simply a analyzable acceptable of standards and protocols. Jesse joins america to assistance explicate however immoderate of this works and picture however vulnerabilities, specifically with SMM, tin manifest and beryllium exploited. Segment Resources: CHIP...

Mobile malware marketplace InTheBox detailed

December 7, 2022

More than 400 customized web injects for mobile malware are being offered for merchantability by the InTheBox darknet marketplace, which is thought to look successful January 2020, reports The Hacker News.

Sophos addresses Firewall codification execution flaws

December 7, 2022

SecurityWeek reports that Sophos has fixed 7 codification execution vulnerabilities successful Sophos Firewall arsenic portion of the mentation 19.5 update.

Read Entire Article