Ubuntu Security Flaw Lets Attackers Bypass Full Disk Encryption
#OMGUbuntu article: https://www.omgubuntu.co.uk/2025/07/ubuntu-security-initramfs-bypass-encryption

“Not all #Linux distributions are affected, such as #OpenSUSE_Tumbleweed.”

#Attackers with physical access to a Linux system can access a debug shell simply by entering the wrong #decryption #password several times in a row. On Ubuntu, they hit esc at the password prompt, punch in a few key combos and debug shell appears.
They can mount a USB drive with tools that let them modify the #initramfs (Initial RAM Filesystem – a temporary system run during boot to prep the main OS) to inject #maliciouscode, and then repack it – without tripping any #security flags.
Then, the next time the owner boots up their #laptop and enters their correct password, the code runs with elevated privileges to do whatever the #attacker wants.”

“Impactful though this exploit could be in the wild, there is no reason for most #Ubuntu users to be concerned about it.
This #vulnerability is what the security industry refer to as an '#evilmaidattack': it requires physical access to a #device to pull off.”

“Finally, protecting against this #vulnerability is easy. Users can simply tweak their system #kernel so that the #computer #reboots on failed password attempts, instead of providing a #debug shell.”

Ubuntu Security Flaw Lets Attackers Bypass Full Disk Encryption - OMG! Ubuntu

Cybersecurity researchers claim to have found a "critical" security vulnerability affecting Linux able to give attackers full system access — even if on

OMG! Ubuntu

I hate my #bank...

"As a #security measure" when you #login, instead of typing it the whole #password, you have to type in 8 #random characters from it, like 1st, 4th, 10th etc.

What does this #secure against? Your user being able to log in? Every time I have to open a #notepad and type out my password, count the characters, and type them in one by one, instead of JUST USING A PASSWORD #MANAGER.

If an #attacker knows your password... WHAT DIFFERENCE DOES THIS MAKE?!

External Affairs Minister S Jaishankar questioned the consistency of global standards on sovereignty, political interference, and territorial integrity. At the Raisina Dialogue, he discussed historical injustices, particularly citing the Kashmir issue as an example, and called for a review of global governance frameworks to acknowledge evolving power dynamics.
#Attacker #Jaishankar #UN #Kashmir #MastIndia #MastodonIndians #India @mastodonindians
https://timesofindia.indiatimes.com/india/attacker-and-victim-were-put-on-par-jaishankar-takes-a-jibe-at-un-cites-kashmir-calls-for-fair-global-order/articleshow/119144922.cms
'Attacker and victim were put on par': Jaishankar takes a jibe at UN, cites Kashmir, calls for fair global order | India News - The Times of India

India News: External Affairs Minister S Jaishankar questioned the consistency of global standards on sovereignty, political interference, and territorial integrit

The Times of India

Saif Ali Khan Attack : Attacker Custody Extended Till Jan 29

A MUMBAI court on Friday extended till January 29 the police custody of the Bangladeshi man arrested for allegedly stabbing Bollywood actor Saif Ali Khan at his home during a robbery attempt last week.....This was originally posted on India Weekly. Read the detailed report here:

https://www.indiaweekly.biz/saif-ali-khan-attacker-custody-extended/

#Saifalikhanattack #Saifalikhannews #Attacker #Policecustody #CustodyExtended #India #mumbai #Uk #USA

Saif Ali Khan Attack : Attacker Custody Extended Till Jan 29

A MUMBAI court on Friday extended till January 29 the police custody of the Bangladeshi man arrested for allegedly stabbing Bollywood actor Saif Ali Khan at....

The manhunt to arrest the intruder who attacked actor Saif Ali Khan in his Bandra residence on Thursday is still ongoing, with the Mumbai Police recording statements of over 30 people. One person has been detained for questioning.
#Saif #Attacker #Run #BandraStation #MastIndia #MastodonIndians #India @mastodonindians
https://www.ndtv.com/india-news/saif-ali-khan-attack-2-days-on-saif-ali-khans-attacker-still-on-the-run-20-teams-formed-to-arrest-him-kareena-kapoor-statement-recorded-7500324
54 Hours On, Saif Ali Khan's Attacker Still On Run, Was Last Seen At Bandra Station

The manhunt to arrest the intruder who attacked actor Saif Ali Khan in his Bandra residence on Thursday is still ongoing, with the Mumbai Police recording statements of over 30 people. One person has been detained for questioning.

NDTV
Actor Saif Ali Khan, who underwent surgeries on Thursday after an attacker stabbed him at his Mumbai home, is out of danger and recovering well, doctors at the Lilavati Hospital said. The police have formed 20 teams to arrest the accused.
#SaifAliKhan #Danger #Attacker #Crore #MastIndia #MastodonIndians #India @mastodonindians
https://www.ndtv.com/india-news/saif-ali-khan-out-of-danger-attacker-demanded-rs-1-crore-10-points-saif-ali-khan-attack-updates-kareena-kapoor-khan-jeh-taimur-lilavati-hospital-7492310
Saif Ali Khan 'Out Of Danger', Attacker Demanded Rs 1 Crore: 10 Points

Actor Saif Ali Khan, who underwent surgeries on Thursday after an attacker stabbed him at his Mumbai home, is out of danger and recovering well, doctors at the Lilavati Hospital said. The police have formed 20 teams to arrest the accused.

NDTV

#crime #criminal #violence #attack #elderly #attacker #robbery #theft
My heart bleeds for this brave man, but very well done, and it’s a shame he didn’t manage to give the attacker a full on punch and knock him over. I really hope they catch him.

Mugger 'fought off with jeans' by 84-year-old

https://news.sky.com/video/share-13289220

CCTV: Mugger 'fought off with a pair of jeans' by 84-year-old in Maltby launderette

Masked miscreant is repelled successfully by pensioner with no time for intimidation as he washes his clothes.

Sky News
“Social engineering is using #manipulation, #influence and #deception to get a person, a trusted insider within an #organization, to #comply with a request, and the request is usually to release #information or to perform some sort of #action item that benefits that #attacker.” — #KevinMitnick
Toxic masculinity links the New Orleans attacker and the Las Vegas bomber

Salon.com
Elon #Musk should finally be held #accountable after this horrific #attack in #Magdeburg. The #attacker has apparently #announced #crimes on #X. #Platform operators are legally obliged to report this to the #authorities. Why has this not happened? @bluewavesurfer.bsky.social ... 1/...

RE: https://bsky.app/profile/did:plc:o6kqa3h73juszsovlvqvwwqu/post/3ldteu5njw22a
Bluesky

Bluesky Social