April 2, 2024, 7:10 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

The malicious code found embedded in versions 5.6.0 and 5.6.1 of XZ Utils last week appears to be the product of a carefully crafted supply chain attack that took several years to set up, security researchers said.


The malicious code (CVE-2024-3094) drew attention because it could allow remote, malicious actors to break sshd authentication and gain unauthorized access to impacted systems. The malicious versions of XZ were released in February, and Microsoft software engineer Andres Freund accidentally discovered and posted …

attack attention backdoor campaign code cve cve-2024 cve-2024-3094 embedded found led malicious malicious actors product researchers security security researchers supply supply chain supply chain attack week xz utils

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

DevSecOps Engineer

@ LinQuest | Beavercreek, Ohio, United States

Senior Developer, Vulnerability Collections (Contractor)

@ SecurityScorecard | Remote (Turkey or Latin America)

Cyber Security Intern 03416 NWSOL

@ North Wind Group | RICHLAND, WA

Senior Cybersecurity Process Engineer

@ Peraton | Fort Meade, MD, United States

Sr. Manager, Cybersecurity and Info Security

@ AESC | Smyrna, TN 37167, Smyrna, TN, US | Santa Clara, CA 95054, Santa Clara, CA, US | Florence, SC 29501, Florence, SC, US | Bowling Green, KY 42101, Bowling Green, KY, US