Ubuntu 'command-not-found' tool can be abused to spread malware
ID: a8cb027a-73fa-5356-95b6-621435683beb
STIX ID: report--a8cb027a-73fa-5356-95b6-621435683beb
Feed Name: Bleeping Computer
Threat Score
Aqua Nautilus researchers discovered a logic flaw in Ubuntu's 'command-not-found' utility that can suggest malicious Snap packages to users (via typo-squatting, unclaimed snap names, or registering snaps that impersonate APT packages), creating a significant supply-chain and impersonation risk affecting Ubuntu, its forks, and WSL users; about 26% of APT commands are potentially exploitable and at least two malicious Snap incidents have been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
