#XZUtils
We don't even know if this is as fully automated as the spammer wants us to think. Very possible this is partly or entirely directed by the person who runs the bot.

Pretty "clever" way of automating an xzutils situation, anyway.
February 12, 2026 at 7:22 PM
Your parenthetical is what makes me twitch a little. Look at the '03 backdoor attempt, and the xzutils campaign last year, extrapolate... and Mythos is going to burn a LOT of folks' exclusive access tooling that relies on "it's so obscure they'll never find this".
April 10, 2026 at 1:16 AM
The latter is particularly concerning to me because we just don't know what potential adversarial training can do. If somebody cracks that, with just some commits to public GitHub repos, they could seed vulnerabilities/backdoors that make the XZUtils operation look quaint.
August 8, 2025 at 3:58 AM
yet another reason I love nerds.

xzutils backdoor discovered because of a microsecond delay in things.

sound-based device fingerprinting outed because some nerd got annoyed at their bt headphones not switching devices correctly.

keep digging down into the weird inconvenient stuff, fellow nerds.
August 24, 2026 at 12:46 PM
it seems fucking retarded on github's part to remove the xzutils repo

i figure the sentiment is "let's protect our users fom bad/compromised content by removing it"

and i think that's a symptom some sort of platform as feudal lord type mentality
March 30, 2024 at 12:29 PM
When a software update causes a PTSD trigger.

#xzutils #security #hacking #foss #floss #opensource
June 2, 2026 at 11:59 AM
Tapaus xz Utils on huikea tarina, josta voisi vääntää myös elokuvan.

Käytännössä koko internetin tietoturva oli juuri tuhoutumassa, mutta kaiken esti yksi nörtti, joka viime viikolla ihmetteli miksi sisäänkirjautuminen kestää yhtäkkiä puoli sekuntia kauemmin.

dawn.fi/uutiset/2024...

#xzUtils
xz Utils - Kun koko netin turvallisuus oli uhattuna, tuuri pelasti
Huikea tietoturvaan liittyvä tapahtumasarja purkautui vuoden 2024 pääsiäisenä, kun pienestä avoimen lähdekoodin xz Utils -kirjastosta paljastui takaportti. Takaportin avulla Linux-palvelimille olisi p...
dawn.fi
April 2, 2024 at 12:49 PM
Microsoft engineer Andres Freund inadvertently uncovered malicious code in versions of the XZ Utils compression tool, potentially averting thousands of infections. #XZUtils #MaliciousCode #SecurityDiscovery #AndresFreund
March 31, 2024 at 8:57 PM
#XZUtils 5.8.1 (stable) has been released ( #xz / #LZMAUtils / #LZMA / #LZMA2 / #DataCompression ) tukaani.org/xz/
XZ Utils
tukaani.org
April 8, 2025 at 11:39 PM
En plus de faire des lives recaps du #DevFestNantes, @ponceto91.bsky.social nous présente l'anatomie de la faille de l'enfer sur xzutils ! Terrifiant 🙀
October 18, 2024 at 1:14 PM
i may be overthinking it, but the Esperanto Guy mentioned in the article is making me see parallels between the way social justice language gets hijacked by bad actors and the way bullying was used by the xzutils attacker
April 3, 2024 at 10:18 PM
🚨 Stay safe out there folks

Very similar to XZUtils incident last year. Malicious code was checked in as an encoded string

semgrep.dev/blog/2025/po...
March 15, 2025 at 2:15 PM
“Même un code malveillant de courte durée peut rester longtemps inaperçu” : DockerHub recèlerait la porte dérobée XZ dans les paquets #xzutils !

blog.sosordi.net/2025/08/meme...

#securite #Internet #Linux #Docker
August 14, 2025 at 1:34 PM
El hackeo que casi INFECTA al MUNDO ENTERO | La puerta trasera de xzutils

Vía: Nate Gentile
El Hackeo que casi INFECTA al MUNDO ENTERO | La puerta trasera de xzutils
Juega ya Skull&Bones: https://ubi.li/PswQU ¡Prueba gratis disponible hasta el 06 de Junio y 50% de Descuento si lo compras! - si lo ves mas tarde, mira las o...
www.youtube.com
June 3, 2024 at 2:24 AM
On peut aussi parler de xzutils où on est passé à ça de la catastrophe... (en plus c'est tellement plus un scénario de roman d'espionnage qu'un pauvre déploiement qui a foiré)
July 19, 2024 at 11:33 AM
Excellente initiative, mais qui ne résout pas tout: dans le logiciel libre, les attaques par injection de code sont bien plus faciles (cf. l'effrayante attaque XZutils contre de nombreuses distributions Linux), et quasiment indétectables vu la complexité monstrueuse des logiciels actuels.
June 15, 2025 at 6:33 AM
Die CVE-2024-3094 ist ja echt wild. Gar nicht primär das technische (das auch!), sondern wie strategisch das anscheinend geplant wurde. PsyOp vom Feinsten. #xz #xzutils
April 2, 2024 at 8:37 AM
don't worry, i'll burn out in 20 minutes, get distracted by xzutils obsession, and end up embarking on a 24 hour journey to write coreutils from scratch.
April 30, 2024 at 6:44 AM
Les journalistes tech sont nuls en tech édition 90878757556, la faille XZUtils:
la presse: "gneugneugneu crise de l'open source, gneugneugneu c'est très grave on vit dans une saucisse numérique"
April 8, 2024 at 9:27 AM
Ben ouai, toujours être au taquet niveau version, pas pour moi❗
Comme dans tout, LE JUSTE MILIEUX est une bonne valeur😉
En retrait et observer, j'aime bien 😎
#XZUtils Linux #Mint 21.3 base Ubuntu 22.04.3, cool Raoul 🤙
March 30, 2024 at 10:20 PM
also ich muss zugeben, ich bin echt fan von der art und weise wie #liblzma / #xz / #xzutils gehackt wurde
den exploit nicht in das eigentliche programm sondern in die tests zu programmieren ist echt genial
April 6, 2024 at 2:36 PM
Internet estaba a semanas del desastre y nadie lo sabía

«Cómo un solo ataque informático infectó el sistema operativo más importante del mundo».

Vía: Veritasium en español

#Tecnología #Ciencia #Veritasium #DerekMuller #Internet #GNU #Linux #XZUtils #RSA #JiaTan #LasseCollin #AndresFreund
Internet Estaba A Semanas Del Desastre y Nadie Lo Sabía
YouTube video by Veritasium en español
www.youtube.com
April 1, 2026 at 1:51 AM
What we know about the xz Utils backdoor that almost infected the world | #netsec #security #xzutils #linux | arstechnica.com/security/202...
What we know about the xz Utils backdoor that almost infected the world
Malicious updates made to a ubiquitous tool were a few weeks away from going mainstream.
arstechnica.com
April 1, 2024 at 4:14 PM
What do you do when you learn about a new 0-day like the xzutils CVE? Come to 0.14 at 11am to see how Tetragon makes it easier to cope. There will be demos! #OSSsummit #eBPF
September 17, 2024 at 6:23 AM