Ubuntu 'command-not-found' Tool Could Trick Users into Installing Rogue Packages
ID: ca7017ee-0748-5b65-9396-1ec14b6a2313
STIX ID: report--ca7017ee-0748-5b65-9396-1ec14b6a2313
Feed Name: The Hacker News
Aqua Security researchers disclosed that Ubuntu's default command-not-found utility can be manipulated via the snap ecosystem: attackers who claim snap names (including names matching APT packages) or register aliases/typosquatted snaps can have their malicious snaps suggested above legitimate APT packages, potentially leading users to install counterfeit software. The issue stems from command-not-found delegating snap suggestions to the advicesnap mechanism, and Aqua warns developers and users to register associated snap names and verify package sources to prevent impersonation and supply-chain abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
