The Kali Linux distribution is going to switch to a new security model by defaulting to a non-root user starting with the upcoming 2020.1 release. Learn more: . This change will come with the release of the 2020.1 version scheduled for late January 2020, but users can already test it via the daily builds . They will also be able to test it by downloading and running theweekly images released until Kali 2020.1 will be officially available. The link for this article located at Bleeping Computer is no longer available. . In the 2020.1 release, Kali Linux adopts a safety-first approach by defaulting to non-administrative user accounts, significantly improving user security.. Kali Linux Release, User Privilege Changes, Default Non-Root User, Linux Security Model. . LinuxSecurity.com Team
Before his coffee was cold he had found a local privilege escalation vulnerability in Mac OS X Tiger, which could allow people to elevate from normal user to full super user, and had written code that could exploit the hole.. "I just think that I got lucky, but that's what I always think when I find a bug that quickly," he said in an interview on Wednesday. Dai Zovi has been exploiting Macs for a long time, publishing his first Mac OS X shellcode (code used as the payload in an exploitation of a vulnerability) for the PowerPC in July 2001. He said he has reported more than 10 vulnerabilities to Apple over the years and does so out of love for the platform. The link for this article located at CNET is no longer available. . Investigate a regional privilege escalation flaw within Mac OS X and understand how analysts take advantage of weaknesses to enhance security.. Local Escalation, Exploit Research, Security Flaws, Mac OS Techniques. . LinuxSecurity.com Team
Zope Weekly News has reported a problem with its security model that appears to be potentially pervasive and not necessarily Zope-specific. This is the first installation in a three-part series on Zope's efforts to rein in the trojan, which will . . .. Zope Weekly News has reported a problem with its security model that appears to be potentially pervasive and not necessarily Zope-specific. This is the first installation in a three-part series on Zope's efforts to rein in the trojan, which will be further explored in LinuxNews.com later this week. According to Zope, the problem isn't necessarily an easy one to spot. "The issue involves a way that less privileged site users with the ability to edit DTML [content] could trick more privileged users into executing their content, taking actions on behalf of the higher privileged user that he did not intend (and may not even be aware of)." The link for this article located at LinuxMall [LinuxToday] is no longer available. . Zope Weekly Update highlights a pervasive flaw in the security framework, jeopardizing user permissions and potentially leading to DTML content manipulation.. Zope Security Issue,Trojan Exploit,User Privilege Escalation,DTML Content Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.