Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Ethereum Hashrate Breaks All-Time High, Will Price Follow? bitcoin news
  • Blackrock, Citadel, Gemini Deny Involvement in Terra Collapse – Featured Bitcoin News bitcoin news
  • Elon Musk, Mark Cuban Discuss Using Dogecoin to Solve Twitter Spam Problem – Altcoins Bitcoin News bitcoin news
  • Bitcoin Collapses By Most In Nearly A Month bitcoin news
  • Shanghai High Court Declares Bitcoin Virtual Asset With Economic Value Protected by Chinese Law – Regulation Bitcoin News bitcoin news
  • Russian Crypto Mining Giant Bitriver Considers Challenging US Sanctions – Mining Bitcoin News bitcoin news
  • WAVES Drops 17% as NEAR, SOL, and AVAX Also Take Double-Digit Hits on Friday – Market Updates Bitcoin News bitcoin news
  • SEC Fines Nvidia $5.5 Million for Failing to Disclose Crypto Mining Significantly Boosted Its Revenue – Regulation Bitcoin News bitcoin news

Microsoft Discovers New Privilege Escalation Flaws in Linux Operating System

Posted on May 2, 2022 By root


Privilege Escalation Flaws in Linux

Microsoft on Tuesday disclosed a set of two privilege escalation vulnerabilities in the Linux operating system that could potentially allow threat actors to carry out an array of nefarious activities.

Collectively called “Nimbuspwn,” the flaws “can be chained together to gain root privileges on Linux systems, allowing attackers to deploy payloads, like a root backdoor, and perform other malicious actions via arbitrary root code execution,” Jonathan Bar Or of the Microsoft 365 Defender Research Team said in a report.

On top of that, the defects — tracked as CVE-2022-29799 and CVE-2022-29800 — could also be weaponized as a vector for root access to deploy more sophisticated threats such as ransomware.

The vulnerabilities are rooted in a systemd component called networkd-dispatcher, a daemon program for the network manager system service that’s designed to dispatch network status changes.

Privilege Escalation Flaws in Linux

Specifically, they relate to a combination of directory traversal (CVE-2022-29799), symbolic link (aka symlink) race, and time-of-check to time-of-use (CVE-2022-29800) flaws, leading to a scenario where an adversary in control of a rogue D-Bus service can plant and execute malicious backdoors on the compromised endpoints.

CyberSecurity

Users of networkd-dispatcher are highly recommended to update their instances to the latest version to mitigate potential arising out of exploiting the flaws.

“The growing number of vulnerabilities on Linux environments emphasize the need for strong monitoring of the platform’s operating system and its components,” Bar Or said.

“This constant bombardment of attacks spanning a wide range of platforms, devices, and other domains emphasizes the need for a comprehensive and proactive vulnerability management approach that can further identify and mitigate even previously unknown exploits and issues.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: NPM Bug Allowed Attackers to Distribute Malware as Legitimate Packages
Next Post: Emotet Testing New Delivery Ideas After Microsoft Disables VBA Macros by Default

Related Posts

  • Iranian Hackers Leveraging BitLocker and DiskCryptor in Ransomware Attacks cyber security news
  • High-Severity Bug Reported in Google’s OAuth Client Library for Java cyber security news
  • NPM Bug Allowed Attackers to Distribute Malware as Legitimate Packages cyber security news
  • Microsoft Warns of “CryWare” Info-Stealing Malware Targeting Crypto Wallets cyber security news
  • U.S. Proposes $1 Million Fine on Colonial Pipeline for Safety Violations After Cyberattack cyber security news
  • Ukrainian Hacker Jailed for 4-Years in U.S. for Selling Access to Hacked Servers cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Hackers Trick Users with Fake Windows 11 Downloads to Distribute Vidar Malware
  • Cyprus Drafts Crypto Rules, May Introduce Them Before EU Regulations – Regulation Bitcoin News
  • MetaOasis AVAX Hackathon News Report – Press release Bitcoin News
  • Pakistan Can Generate $90 Million Annually if It Introduces a 15% Tax on Crypto Transactions – Emerging Markets Bitcoin News
  • QNAP Urges Users to Update NAS Devices to Prevent Deadbolt Ransomware Attacks

Recent Comments

No comments to show.
  • Bitcoin Price Takes Deepest Dive Since 2020, Will BTC Bounce? bitcoin news
  • Strong US Dollar Posts 5-Week High, Markets Price in a 75 bps Fed Rate Hike for June – Economics Bitcoin News bitcoin news
  • Bitcoin Price Crashes Below $30K As Markets Show Signs Of Paranoia bitcoin news
  • BTC Falls Below $30,000, Is 55% Below Its Record High – Market Updates Bitcoin News bitcoin news
  • Ukrainian Soccer Club Shakhtar to Raise Humanitarian Funds Through NFT Sale – Bitcoin News bitcoin news
  • Nigerian CBDC Wallet Update to Enable Utility Payments, USSD Functionality to Be Added – Featured Bitcoin News bitcoin news
  • Pakistan Can Generate $90 Million Annually if It Introduces a 15% Tax on Crypto Transactions – Emerging Markets Bitcoin News bitcoin news
  • Dragon War is Bringing the Most Exclusive NFT Collections to Magic Eden bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme