Security News

Sudo Bug Lets Non-Privileged Linux and macOS Users Run Commands as Root
2020-02-03 07:35

Joe Vennix of Apple security has found another significant vulnerability in sudo utility that under a specific configuration could allow low privileged users or malicious programs to execute arbitrary commands with administrative privileges on Linux or macOS systems. Sudo has been designed to let users run apps or commands with the privileges of a different user without switching environments.

Here we go again: Software nasties slip into Google Play, exploit make-me-root Android flaw for maximum pwnage
2020-01-07 06:53

At least three malicious apps with device-hijacking exploits have made it onto the Google Play Store in recent weeks. The malicious apps were Camero, FileCrypt, and callCam, so check if you still have them installed.

VMware warning, OpenBSD gimme-root hole again, telco hit with GDPR fine, Ring camera hijackings, and more
2019-12-16 09:11

Your quick summary of infosec news beyond everything else we've reported Roundup Here's your Register security roundup of infosec news about stuff that's unfit for production but fit for print.…

Google Announces Open Source Silicon Root-of-Trust Project
2019-11-06 15:00

Google this week announced OpenTitan, an open source silicon root of trust (RoT) project that can help ensure that both hardware infrastructure and the software running on it remain in a...

Sudo Bug Opens Root Access on Linux Systems
2019-10-15 15:55

The bug allows users to bypass privilege restrictions to execute commands as root.

Sudo? More like Su-doh: There's a fun bug that gives restricted sudoers root access (if your config is non-standard)
2019-10-14 21:14

All it takes is -u#-1 ... Wh%& t#e fsck*? It's only Monday, and we already have a contender for the bug of the week.…

Sudo Flaw Lets Linux Users Run Commands As Root Even When They're Restricted
2019-10-14 18:34

Attention Linux Users! A vulnerability has been discovered in Sudo—one of the most important, powerful, and commonly used utilities that comes as a core command installed on almost every UNIX and...

I Have a New Book: We Have Root
2019-10-11 19:34

I just published my third collection of essays: We Have Root. This book covers essays from 2013 to 2017. (The first two are Schneier on Security and Carry On.) There is nothing in this book is...

Four words from Cisco to strike fear into the most hardened techies: Guest account as root
2019-09-26 12:44

Now is a very good time to patch your estate Cisco has doled out yet more security updates for its IOS and IOS XE network operating systems, which, we are obliged to remind you, is its scheduled...

Exim Vulnerability Allows Remote Code Execution as Root
2019-09-06 14:16

Exim mail servers are vulnerable to attacks due to a security hole that allows a local or remote attacker to execute arbitrary code with root privileges. read more