#CVE-2024-3094
CVE-2024-3094: The computer is not a collection of binaries; rather, it is a social relation among people, mediated by binaries
March 29, 2024 at 9:20 PM
This is the first time I see a CVE trending on Twitter
March 30, 2024 at 8:43 PM
Happy xz CVE-2024-3094 day to all who celebrate.

news.ycombinator.com/item?id=3986...
Backdoor in upstream xz/liblzma leading to SSH server compromise | Hacker News
news.ycombinator.com
March 31, 2024 at 2:59 PM
xzの脆弱性によるリモート攻撃を受け入れるhoneypot実装。おーいいねぇ。
GitHub - amlweems/xzbot: notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094) - amlweems/xzbot
github.com
April 6, 2024 at 12:26 PM
Secret backdoor found in XZ Utils compression library (CVE-2024-3094) used by major #Linux distros, like #Fedora, #Kali Linux, and #openSUSE. Attackers could breach SSH and take control of systems. 🙄
March 30, 2024 at 12:27 PM
This issue was also found in a recent Kali Linux update from March 26th-29th. So if you updated then, you need to do the newest update to fix it. @canadianry.bsky.social @youranonriots.bsky.social @anonymous.expectus.fyi might want to get the word out.
www.helpnetsecurity.com/2024/03/29/c...
Beware! Backdoor found in XZ utilities used by many Linux distros (CVE-2024-3094) - Help Net Security
A vulnerability (CVE-2024-3094) in XZ Utils may enable a malicious actor to gain unauthorized access to Linux systems remotely.
www.helpnetsecurity.com
March 29, 2024 at 8:24 PM
🕸️XZ-utils backdoor (CVE-2024-3094)

🔖#infosec #cybersecurity #hacking #pentesting #security

👤beacons.ai/cyberkid1987
👤t.me/VasileiadisAnastasis
👥t.me/infosec101
April 1, 2024 at 4:55 PM
Talos Linux is not vulnerable to CVE-2024-3094 for the following reasons

❌ no ssh
❌ no systemd
❌ no glibc
❌ no rpm/deb packages

I hope you all enjoyed not-patching this weekend

You can read more about it here
www.siderolabs.com/blog/xz-util...
XZ Utils and Talos Linux (CVE-2024-3094) - Sidero Labs
Talos Linux doesn't have SSH so it's not vulnerable to CVE-2024-3094, but that's not the only benefit to a minimal Kubernetes operating system.
www.siderolabs.com
April 2, 2024 at 5:03 PM
Xzbot: exploit demo for the xz backdoor (CVE-2024-3094)
Xzbot: exploit demo for the xz backdoor (CVE-2024-3094)
github.com
April 1, 2024 at 5:09 PM
XZ Utils CVE-2024-3094: A Tale of Broken Trust, Curious Persistence, and a Call to Action

https://www.hackerone.com/vulnerability-management/cve-2024-3094

#cybersecurity #infosec #security #hacker
December 14, 2024 at 11:45 AM
xzの脆弱性(バックドア埋め込み: Critical: CVE-2024-3094) - SIOS SECURITY BLOG
https://security.sios.jp/vulnerability/xz-security-vulnerability-20240330/
xzの脆弱性(バックドア埋め込み: Critical: CVE-2024-3094) - SIOS SECURITY BLOG
03/29/2024にxzの脆弱性(バックドア埋め込み: Critical: CVE-2024-3094)が公
security.sios.jp
March 31, 2024 at 6:32 AM
Link roundup related to xz/liblzma compromise (CVE-2024-3094) shellsharks.com/xz-compromis...
xz/liblzma Compromise Link Roundup
Links to analysis, discussion and more related to the xz/liblzma compromise (CVE-2024-3094)
shellsharks.com
March 31, 2024 at 4:51 PM
Only recently the tech industry realised how close the entire infrastructure of the internet came to having a backdoor installed by someone who worked for *several years* on a project:

gist.github.com/thesamesam/2...
xz-utils backdoor situation (CVE-2024-3094)
xz-utils backdoor situation (CVE-2024-3094). GitHub Gist: instantly share code, notes, and snippets.
gist.github.com
August 21, 2024 at 7:49 PM
Xzbot: Notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094) (@github.com)

Main Link | Discussion
April 1, 2024 at 4:44 PM
The XZ Utils backdoor (CVE-2024-3094) required extraordinary planning, patience, and discipline to execute. Is the person or organization capable of executing this hack more likely to tend a single potted plant, or a field of crops?
April 2, 2024 at 8:21 PM
From The Debian Project:
Although no Debian stable versions are known to be affected by CVE-2024-3094 the next point release for 12.6 has been postponed while we investigate the effects of this CVE on the Archive. lists.debian.org/debian-secur...
dlvr.it/T4rt3l #debian
Although no Debian stable versions are known to be affected by CVE-2024-3094 the next point release for 12.6 has been postponed while we investigate the effects of this CVE on the Archive. https://lis...
Although no Debian stable versions are known to be affected by CVE-2024-3094 the next point release for 12.6 has been postponed while we investigate the effects of this CVE on the Archive. https://lis...
dlvr.it
March 30, 2024 at 11:38 PM
The XZ backdoor was a critical vulnerability (CVE-2024-3094) discovered in XZ Utils on March 29, 2024. It affected versions 5.6.0 and 5.6.1 of XZ Utils, which were released in February 2024. The backdoor allowed unauthorized individuals to remotely access with admin-level privileges.
The XZ Backdoor: Everything You Need to Know
Details are starting to emerge about a stunning supply chain attack that sent the open source software community reeling.
www.wired.com
January 18, 2025 at 10:13 AM
xz Backdoor CVE-2024-3094 – Open Source Security Foundation
https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/
xz Backdoor CVE-2024-3094 – Open Source Security Foundation
openssf.org
March 30, 2024 at 10:03 PM