Linux malware distribution, major GPU vulnerability, Proton vulnerabilities, new passkey support, data breaches, companies, research, politics, FOSS, and Misfits. Allegations against Elon Musk, net neutrality plans, advancements in quantum resistance, updates from various companies, next generation desktop app, releases for Cryptomater and Linux Mint Debian Edition, Google's vulnerability correction, WordPress blogs in the Fediverse, and the controversy surrounding a TikTok account exploiting facial recognition technology.
Linux users were redirected to a malicious domain hosting malware through a free download manager.org page
Caesar's Entertainment loyalty program suffered a cyber attack resulting in the theft of customer data including driver's license numbers and social security numbers
A new spyware tool exploits ads to plant zero-click malware, raising concerns about privacy and security
Deep dives
Linux malware distribution scheme through free download manager
The official download page of free download manager.org would sometimes redirect Linux users to a malicious domain hosting a malicious Debian package.
Caesar's Entertainment data breach
Customer data, including driver's license numbers and social security numbers, was stolen in a cyber attack on Caesar's Entertainment loyalty program database.
Microsoft AI researchers accidentally exposed terabytes of internal sensitive data
An exposed GitHub repo contained 38 terabytes of sensitive information, including personal backups, secret keys, and internal messages from Microsoft employees.
Proton Pass Extension Vulnerability
The recent audit revealed a vulnerability in the Proton Pass extension, where saved items were not immediately cleared from memory when the extension was locked. This means that an attacker with physical access to the victim's computer can retrieve the saved items even when the extension is locked. The issue was previously fixed, but it seems to have been reintroduced with new features.
Wi-Fi Attack for Stealing Numerical Passwords
A new attack called WikiEve can steal numerical passwords over Wi-Fi with an accuracy rate of up to 90%. It exploits the beamforming feedback information in Wi-Fi 5, allowing attackers to intercept and decipher numeric keystrokes and passwords. While this attack only works on numerical passwords, a study revealed that 16 out of 20 top passwords use digits. It requires the attacker to be on the same network and identify the target with an identity indicator.
Spyware Tool Exploiting Advertising Stack
A new spyware tool has been developed, which can exploit ads to plant zero-click malware. This tool, created by cyber firms like NSO, takes advantage of the ad serving process to plant malicious ads that infect devices with malware without the need for user interaction. The tool reportedly bypasses existing safeguards, and there is concern about how it can compromise privacy and security, especially with law enforcement potentially utilizing it as well.
A clever Linux malware distribution scheme, a new vulnerability in all major GPUs, a couple of Proton vulnerabilities, lots of new passkey support, and more!