"Shim Bootloader Vulnerability Threatens Linux Distros"

TL;DR Summary
Linux has a shim problem due to Secure Boot and GPLv3, resulting in a broken shim with serious vulnerabilities. LastPass was banned from the App Store due to a suspiciously similar app. Reports of three million compromised smart toothbrushes used in a DDoS attack were found to be based on a hypothetical scenario, not actual events. Security researchers are facing challenges due to the abundance of honeypots, while undocumented SSH access with a known root password was discovered in some heat pumps. A vulnerability in Mastodon's federated account handling was published, prompting an update to address the issue.
- This Week In Security: Broken Shims, LassPass, And Toothbrushes? Hackaday
- Critical vulnerability affecting most Linux distros allows for bootkits Ars Technica
- Shim vulnerability exposes most Linux systems to attack ZDNet
- Linux Distros Hit by RCE Vulnerability in Shim Bootloader DARKReading
- Shim Shady and Algorithm Lovers – PSW #816 | SC Media SC Media
Reading Insights
Total Reads
0
Unique Readers
1
Time Saved
6 min
vs 7 min read
Condensed
92%
1,216 → 98 words
Want the full story? Read the original article
Read on Hackaday