April 1, 2024, 12:51 p.m. | iturunen@sonatype.com (Ilkka Turunen)

Sonatype Blog blog.sonatype.com




As sure as long weekends arrive in the western world, so too does news of new supply chain attacks. The easter bank holidays were no exception, with the discovery of a targeted attack against the popular XZ compression utility seen in many linux distributions such as fedora, debian to name a few.

attack attacks backdoor bank compression cve cve-2024 cve-2024-3094 debian discovery distributions easter everything open source featured fedora holidays linux linux distributions malicious injection news and views popular software supply chain supply supply chain supply chain attack supply chain attacks targeted attack utility western world

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineer - Vulnerability Management

@ Starling Bank | Southampton, England, United Kingdom

Manager Cybersecurity

@ Sia Partners | Rotterdam, Netherlands

Compliance Analyst

@ SiteMinder | Manila

Information System Security Engineer (ISSE)-Level 3, OS&CI Job #447

@ Allen Integrated Solutions | Chantilly, Virginia, United States

Enterprise Cyber Security Analyst – Advisory and Consulting

@ Ford Motor Company | Mexico City, MEX, Mexico