[Security] Security Experts Warn of Ubuntu Exploit to Push Malicious Snaps

1 message · started by Devi Garcia on Feb 14, 2024

[Security] Security Experts Warn of Ubuntu Exploit to Push Malicious Snaps

From Devi Garcia · Feb 14, 2024

Researchers at Aqua Nautilus say they’ve identified a security flaw in the way Ubuntu’s “command not found” feature works, which attackers could exploit to trick users into installing malicious snaps.

In a blog post detailing their findings the security outfit concludes that “the risk of attackers exploiting the ‘command-not-found’ utility to recommend their own malicious snap packages is a pressing concern”.

“The true peril lies in the potential scope of this issue, with attackers capable of mimicking thousands of commands from widely-used packages,” adding “past instances of malicious packages appearing in the Snap Store highlight this issue.”

Read Article:

View original on FreeLists


Previous thread · Next thread

Back to February 2024