April 1, 2024, 12:51 p.m. | iturunen@sonatype.com (Ilkka Turunen)

Sonatype Blog blog.sonatype.com




As sure as long weekends arrive in the western world, so too does news of new supply chain attacks. The easter bank holidays were no exception, with the discovery of a targeted attack against the popular XZ compression utility seen in many linux distributions such as fedora, debian to name a few.

attack attacks backdoor bank compression cve cve-2024 cve-2024-3094 debian discovery distributions easter everything open source featured fedora holidays linux linux distributions malicious injection news and views popular software supply chain supply supply chain supply chain attack supply chain attacks targeted attack utility western world

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC