all InfoSec news
Carefully Crafted Campaign Led to XZ Utils Backdoor
Malware Analysis, News and Indicators - Latest topics malware.news
The malicious code found embedded in versions 5.6.0 and 5.6.1 of XZ Utils last week appears to be the product of a carefully crafted supply chain attack that took several years to set up, security researchers said.
The malicious code (CVE-2024-3094) drew attention because it could allow remote, malicious actors to break sshd authentication and gain unauthorized access to impacted systems. The malicious versions of XZ were released in February, and Microsoft software engineer Andres Freund accidentally discovered and posted …
attack attention backdoor campaign code cve cve-2024 cve-2024-3094 embedded found led malicious malicious actors product researchers security security researchers supply supply chain supply chain attack week xz utils