#MaliciousCode

Ars Technica Newsarstechnica@c.im
2025-08-22

Developer gets 4 years for activating network “kill switch” to avenge his firing arstechni.ca/k4hK #maliciouscode #cybercrime #killswitch #developer #Policy

2025-07-25

Un hacker ha inserito codice malevolo nella estensione Amazon Q per Visual Studio Code, progettata per assistere programmatori con AI generativa. Il codice, seppur difettoso e non dannoso, mirava a cancellare dati di sistema. Amazon ha rimosso la versione compromessa e invitato gli utenti ad aggiornare all’ultima release sicura.

bleepingcomputer.com/news/secu

#amazonavscode #hackerattack #maliciouscode #cybersecurity #softwareupdate

2025-07-06

Ubuntu Security Flaw Lets Attackers Bypass Full Disk Encryption
#OMGUbuntu article: omgubuntu.co.uk/2025/07/ubuntu

“Not all #Linux distributions are affected, such as #OpenSUSE_Tumbleweed.”

#Attackers with physical access to a Linux system can access a debug shell simply by entering the wrong #decryption #password several times in a row. On Ubuntu, they hit esc at the password prompt, punch in a few key combos and debug shell appears.
They can mount a USB drive with tools that let them modify the #initramfs (Initial RAM Filesystem – a temporary system run during boot to prep the main OS) to inject #maliciouscode, and then repack it – without tripping any #security flags.
Then, the next time the owner boots up their #laptop and enters their correct password, the code runs with elevated privileges to do whatever the #attacker wants.”

“Impactful though this exploit could be in the wild, there is no reason for most #Ubuntu users to be concerned about it.
This #vulnerability is what the security industry refer to as an '#evilmaidattack': it requires physical access to a #device to pull off.”

“Finally, protecting against this #vulnerability is easy. Users can simply tweak their system #kernel so that the #computer #reboots on failed password attempts, instead of providing a #debug shell.”

PUPUWEB Blogpupuweb
2024-11-16

🚨 Malicious commits target GitHub projects! A Texas researcher claims someone is impersonating him to sabotage his reputation. 🛑👨‍💻

Inautiloinautilo
2024-06-06
〇 ṃѧяȗṿєяṡє 〇maruverse@infosec.exchange
2024-04-03

Article about XZ: As for which nation, Raiu names the usual suspects: China, Russia, North Korea. He says it’s still too early to know the true culprit.

Why is it never: United States of America. Because I can assure you, they are quite the player when it comes to building backdoors and other infiltration tech. Somehow they're always kept from the list.

Maybe they were less in need of it though, since they already have their ways by official means

#XZ #hack #maliciouscode #cybersecurity

2020-07-29

OkCupid Security Flaw Threatens Intimate Dater Details - Attackers could exploit various flaws in OkCupid's mobile app and webpage to steal victims' sensit... more: threatpost.com/okcupid-securit #crossoriginresourcesharing #vulnerabilities #okcupidsecurity #maliciouscode #mobileappflaw #vulnerability #securityflaw #websecurity #datingapp #okcupid #hack

2019-07-27

No matter how many times I share to Mastodon from YouTube, it won't put it at the top of the share-to list. It actually keeps shuffling it around, making it more of a pain to locate.
#MaliciousCode
#Algorithms

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst