Poesie aus den Abgründen der Cyberkriminalität: Von der #BlackWidow 🕷️ über das Dumpster Diving bis hin zur #EvilMaidAttack: Die neun schönsten Wortkreationen rund um die Digitalbetrüger und ihr hackerhaftes Tun: 💻🔨
https://blog.clickomania.ch/2025/11/21/die-schoensten-bezeichnungen-aus-der-it-sicherheit/ #clickomaniach
Die poetische Seite der Cyberkriminalität

Hier ist sie, die Top 9 der poe­tischs­ten Be­grif­fe aus dem Le­xi­kon der Cy­ber­sicher­heit: schöne und kreative Wort­krea­tio­nen, die über­aus gar­stige Dinge be­zeichnen.

Clickomania

Ubuntu Security Flaw Lets Attackers Bypass Full Disk Encryption
#OMGUbuntu article: https://www.omgubuntu.co.uk/2025/07/ubuntu-security-initramfs-bypass-encryption

“Not all #Linux distributions are affected, such as #OpenSUSE_Tumbleweed.”

#Attackers with physical access to a Linux system can access a debug shell simply by entering the wrong #decryption #password several times in a row. On Ubuntu, they hit esc at the password prompt, punch in a few key combos and debug shell appears.
They can mount a USB drive with tools that let them modify the #initramfs (Initial RAM Filesystem – a temporary system run during boot to prep the main OS) to inject #maliciouscode, and then repack it – without tripping any #security flags.
Then, the next time the owner boots up their #laptop and enters their correct password, the code runs with elevated privileges to do whatever the #attacker wants.”

“Impactful though this exploit could be in the wild, there is no reason for most #Ubuntu users to be concerned about it.
This #vulnerability is what the security industry refer to as an '#evilmaidattack': it requires physical access to a #device to pull off.”

“Finally, protecting against this #vulnerability is easy. Users can simply tweak their system #kernel so that the #computer #reboots on failed password attempts, instead of providing a #debug shell.”

New Linux Security Flaw Uses Initramfs to Inject Malware

A newly found security flaw in Ubuntu could allow attackers with physical access to bypass full disk encryption. Learn how the attack works.

OMG! Ubuntu

@lzg I think everyone knows better than to leave you alone with a laptop #evilmaidattack

https://en.wikipedia.org/wiki/Evil_Maid_attack

Evil maid attack - Wikipedia

#infosec
The #SANS_ISC has a new diary entry about simple steps to prepare against an #EvilMaidAttack:
https://isc.sans.edu/diary/rss/29256

I always liked the idea with the glitter nail polish, but never implemented it. I bet it will lead to interesting discussions if someone notices the colored spots on the underside of your laptop. 😄
And I should definitely play around with #QubesOS.

RT @KitPloit: EvilAbigail - Automated Linux Evil Maid Attack https://t.co/YENRJiBBi6 #Debian #Detection #EvilMaidAttack https://t.co/3VFWp9hU7j