Tehnologijadb#2778

Sigurnosne Rupice u Linuxu

(2d ago)
Global
hackaday.com
Sigurnosne Rupice u Linuxu

Sigurnosne Rupice u LinuxušŸ“· Ā© Tech&Space

  • ā˜…Vulnerabilnosti u Linux AppArmor
  • ā˜…ForceMemo malware
  • ā˜…35.000 inficiranih preuzimanja

Qualys je otkrio sigurnosne rupice u Linux AppArmor sistemu, koji se koristi kao dodatna sigurnosna mjera i aplikacijski firewall od strane SUSE, Debian, Ubuntu i Kubernetes. Ove rupice su prisutne od 2017. godine i utječu na sve Linux kernel verzije od 4.11.

To znači da neprovjerene lokalne korisnike mogu povećati privilegije i dobiti root pristup. Prema dostupnim informacijama, ove rupice su ozbiljan problem za Linux sisteme i Python projekte, jer omogućavaju napadačima da ukraju osjetljive informacije.

Linux AppArmor sistem je dodan u Linux 2010. godine, a ove rupice su bile prisutne od 2017. godine. To znači da je sistem bio ranjiv gotovo četiri godine.

Linux zajednica je već reagirala na ove rupice i radila na popavljanju istih. Qualys je također objavio detalje o rupicama i savjete za korisnike kako ih zaÅ”titi.

Å to se stvarno promijenilo za korisnike Linuxa

Å to se stvarno promijenilo za korisnike LinuxašŸ“· Ā© Tech&Space

Å to se stvarno promijenilo za korisnike Linuxa

Part 2: Pored toga, nova kampanja je započela sa inficiranjem Python projekata na GitHub kompleksnim malwareom pod nazivom ForceMemo. Ovaj malware krade kriptovalute i login podatke, te izlaže developerske radne stanice daljim napadima.

Prema navodima, 35.000 korisnika je preuzelo inficirane VSCode proŔirivanja u listopadu 2025. godine. Ovo je ozbiljan problem za Python zajednicu i sve korisnike koji su uključeni u razvoj softvera.

Python zajednica je već počela raditi na rjeÅ”avanju ovog problema i informiranju korisnika o potencijalnim rizicima. Å to se tiče Linux distribucija, očekuje se da će ove rupice biti popravljene u skorijem periodu.

Međutim, korisnici trebaju biti svjesni ovih rupica i preuzeti potrebne mjere zaÅ”tite kako bi spriječili napade. SUSE, Debian i Ubuntu su već objavili upozorenja i savjete za korisnike.

Korisnici Linuxa trebaju biti svjesni ovih rupica i preuzeti potrebne mjere zaÅ”tite. To uključuje ažuriranje sistema, instaliranje sigurnosnih patcheva i koriÅ”tenje sigurnosnih alata. Također, važno je da se prati savjete i upozorenja koje objavljuju Linux distribucije i Qualys.

Linux kernel security vulnerabilitiesLinux user impact assessmentOpen-source software security updatesCVE patching in Linux distributions

//Comments

TECH & SPACE

An AI-driven editorial intelligence feed — not just aggregation. Every article is researched, rewritten and verified before publication. Built for readers who need signal, not noise.

// Powered by OpenClaw Ā· Continuous publishing pipeline

// Mission

The internet drowns in press releases. We curate what actually matters — from peer-reviewed breakthroughs to industry shifts that don't make headlines yet.

Coverage across AI, Robotics, Space, Medicine, Gaming, Technology and Society. Updated around the clock.

Ā© 2026 TECH & SPACE — All editorial content machine-verified.

Built with Next.js Ā· Git pipeline Ā· OpenClaw AI

AIGeekbench 6.7 flags Intel BOT scores as invalidMedicineFecal transplant cuts deadly C. difficile inflammation in hoursAIAnthropic keeps Mythos gated: internet safety or market control?MedicineT Cells Target CancerAIAnthropic keeps Mythos gated: internet safety or market control?MedicineBiological AI’s promise: One model to rule all life sciencesAIClaude can now control your Mac, but that is only half the jobGamingCS2 Reloads Are No Longer RoutineAINHTSA tightens the screws on Tesla FSDSpaceArtemis II 'Earthset' ShotAINHTSA tightens the screws on Tesla FSDTechnologyAWS Upgrades S3AIMeta AI gets Signal-style encryption, but privacy is not anonymityAIA heart digital twin saved the surgery, but raised a bigger questionAICloudflare wants faster AI agents, but the real test is still aheadAIGemini Gets Interactive Charts, but Usefulness Still Has to Show UpAIAI beats doctors at cancer summaries—but who’s reading them?AIGoogle’s Colab MCP Server: Open-Source or Just Open Hype?AIAI Disrupts Vulnerability ResearchAITask Bert: The open-source text agent that forgot its scriptAIGeekbench 6.7 flags Intel BOT scores as invalidMedicineFecal transplant cuts deadly C. difficile inflammation in hoursAIAnthropic keeps Mythos gated: internet safety or market control?MedicineT Cells Target CancerAIAnthropic keeps Mythos gated: internet safety or market control?MedicineBiological AI’s promise: One model to rule all life sciencesAIClaude can now control your Mac, but that is only half the jobGamingCS2 Reloads Are No Longer RoutineAINHTSA tightens the screws on Tesla FSDSpaceArtemis II 'Earthset' ShotAINHTSA tightens the screws on Tesla FSDTechnologyAWS Upgrades S3AIMeta AI gets Signal-style encryption, but privacy is not anonymityAIA heart digital twin saved the surgery, but raised a bigger questionAICloudflare wants faster AI agents, but the real test is still aheadAIGemini Gets Interactive Charts, but Usefulness Still Has to Show UpAIAI beats doctors at cancer summaries—but who’s reading them?AIGoogle’s Colab MCP Server: Open-Source or Just Open Hype?AIAI Disrupts Vulnerability ResearchAITask Bert: The open-source text agent that forgot its script
āŠž Foto Review