Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Linux Vulnerabilities Uncovered By Netflix
News & Analysis

Linux Vulnerabilities Uncovered By Netflix

ISBuzz TeamBy ISBuzz TeamJune 19, 2019Updated:July 4, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Linux worm targeting Routers, Set-top boxes and Security Cameras with PHP vulnerability
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Yesterday, Netflix issued an advisory identifying several TCP networking vulnerabilities in FreeBSD and Linux kernels. While patches are already available for the identified vulnerabilities, Linux is the most popular system on the Internet. This means that the issue will remain widespread and dangerous until every single company has applied patches.

https://twitter.com/zackwhittaker/status/1140725252781236226

Linux SACK Panic and Other TCP Denial of Service Issues
CVE-2019-11477, CVE-2019-11478, CVE-2019-11479https://t.co/qAde0bGB34https://t.co/xf1Epdg0SI

workaround:
$ sudo sysctl -w net.ipv4.tcp_sack=0
$ sudo iptables -A INPUT -p tcp -m tcpmss –mss 1:500 -j DROP

— Levente Polyak | @[email protected] (@anthraxx42) June 17, 2019

Expert Comments: 

David Atkinson, CEO at Senseon:

“While it is Netflix that identified these flaws, the issue is much, much bigger than one company or service. Linux is used by 40 percent of the world’s websites. It is embedded in thousands of devices, from Internet routers to IoT products, and it is a key component to most corporate infrastructure. In short, Linux is everywhere.

“This means it is also difficult to know where it is enabled. While there is a patch, it could take weeks or months for companies to find every potential vulnerability and patch it. Embedded systems may not even get upgraded due to the perceived inconvenience of patching, something particularly true for IoT devices.

“In the worst case scenario, a single hacker could exploit this known vulnerability to bring down any corporate service that uses Linux. Until they are patched, millions of companies and products are vulnerable. This also increases the risk of a coordinated nation-state attack.

“While a malicious attack has not yet been reported, it is only a matter of time. There are at least eight million public-facing services using Linux. Companies should urgently issuing emergency patches on these systems to prevent disruption and be using threat detection to spot any attack or malicious activity on their system quickly.”

Boris Cipot, Senior Security Engineer at Synopsys:

“The good thing is that the vulnerability was found and the patches are available. It is now crucial that patches are applied as cyber criminals will for sure start writing malware that searches and exploits the non-patched, vulnerable machines. We have seen many times that the most critical thing is the time between the public notification of a vulnerability and the applying of a fix. Most of the time the cyber criminals are always a step ahead in the game, as patching is not always done in a timely manner. Let’s hope that this will not be the case here. Patching is needed to keep your systems running securely and avoiding breaches or fall outs. Even if patching takes time and requires money, think of what a downtime to your systems is worth in reverse.”

Jake Moore, Cyber Security Expert at ESET:

“Cyber criminals tend to create phishing emails purporting to be sent from large companies to have the largest effect. As Netflix have millions of users, there are more users to target in the hope that more unsuspecting victims will click on the links. Years ago, the blanket emails would have been from a Nigerian Prince but now they tend to create emails looking like they are from Apple, PayPay and Netflix to name a few. Telltale signs still lie in the fact they say “Dear customer” to start the email rather than your name and they attempt to instill fear threatening restricted access to the account. Social engineering techniques use the principles of persuasion such as fear to entice people to do what they are told which has a far greater click rate. Netflix, and other companies used by hackers, will not kill your account without going through far more personal details with you and won’t ever use threatening communication. It is always worth ringing a number found on the genuine website to speak with customer service if you are ever doubtful of any correspondence.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}