Raspberry Pi has changed the default privilege model in Raspberry Pi OS 6.2, disabling passwordless sudo for new installations of the Debian Trixie-based release. Users must now enter their current account password when running administrative actions in the terminal or through certain desktop workflows, a move the company said is intended to reduce the risk that someone with physical or local access to a device could gain administrative control without authentication. After a successful prompt, sudo access remains cached for five minutes.
The update does not retroactively change existing systems: devices already running Raspberry Pi OS will continue to have passwordless sudo enabled unless users modify the setting themselves. Raspberry Pi said the behavior can still be reverted on new installs through the Control Centre by turning off the Admin Password option, preserving an easier workflow for users who prefer the previous default.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Coverage of the update noted that the passwordless sudo change does not modify existing Raspberry Pi OS installations, where passwordless sudo remains enabled unless users manually change it. This clarified the scope and impact of the security update following Raspberry Pi's announcement.
Raspberry Pi said Raspberry Pi OS 6.2, based on Debian Trixie, disables passwordless sudo by default on new installations to reduce the risk of unauthorized administrative actions by anyone with device access. Under the new behavior, users must enter their account password for sudo, with authentication cached for five minutes, and the setting can be reverted through Control Centre.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.