eb, to security
@eb@social.coop avatar

Unfolding now: https://news.ycombinator.com/item?id=39865810

An incredibly technically complex in xz (potentially also in libarchive and elsewhere) was just discovered. This backdoor has been quietly implemented over years, with the assistance of a wide array of subtly interconnected accounts:

The timeline on this is going to take so long to unravel

scy, to random
@scy@chaos.social avatar

Eek. Apparently liblzma (part of the xz package) has a backdoor in versions 5.6.0 and 5.6.1, causing SSH to be compromised.

https://www.openwall.com/lists/oss-security/2024/03/29/4

This might even have been done on purpose by the upstream devs.

Developing story, please take with a grain of salt.

The 5.6 versions are somewhat recent, depending on how bleeding edge your distro is you might not be affected.

#liblzma #xz #lzma #backdoor #ITsecurity #OpenSSH #SSH

gmate8, (edited ) to privacy
@gmate8@mastodon.online avatar

#Privacy is in global danger by the oppression of the World's Elite having a pact with ruling politicians. This is the BIGGEST global threat yet to our freedom and free speech. Don't let yourself down.

We don't need to be China to be safe. They know it, just don't admit it.

📎: https://www.eff.org/deeplinks/2023/09/today-uk-parliament-undermined-privacy-security-and-freedom-all-internet-users

#Freedom #Oppression #Injustice #SurveillanceCapitalism #UK #Politics #OnlineSafetyBill #Encryption #Backdoor #Cybersecurity #EFF

glynmoody, to opensource
@glynmoody@mastodon.social avatar

The Mystery of ‘Jia Tan,’ the XZ #Backdoor Mastermind - https://www.wired.com/story/jia-tan-xz-backdoor/ "The thwarted XZ Utils supply chain attack was years in the making. Now, clues suggest nation-state hackers were behind the persona that inserted the malicious code." another reason for governments to support #opensource properly

rysiek, to microsoft
@rysiek@mstdn.social avatar

Hey it's totally cool that #Microsoft #GitHub blocked access to one of the repositories in the very center of the #xz backdoor saga. :blobeyes:

It's not like a bunch of people are scrambling to try and make sense of all this right now, or that specific commits got linked to directly from media and blogposts and the like. :blobcatcoffee:

Cool, cool. :blobcatfingerguns:

#InfoSec #Backdoor

Viss, to random
@Viss@mastodon.social avatar

the only input i have on the discussion is that folks who had turned on auto updates were way more likely to have had the backdoor installed without them knowing about it, versus folks that manually do their upgrading.

not that those folks would have known either, but im estimating that the cadence of auto updates is more often than when folks do it by hand, and the attackers were relying on that to be the case so they could slip in on the shady shady.

moira, to infosec
@moira@mastodon.murkworks.net avatar

Holy shit did we dodge a bullet. When I upgraded our mastodon server last December I originally ordered a Gigabyte motherboard as part of the upgrade, ended up sending it back as defective.

Turns out it was much, much more defective than I knew.

#InfoSec #gigabyte #backdoor #HolyShit #NoMoreGigaByteForMeThanks

https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/

Viss, to random
@Viss@mastodon.social avatar

PROPOSAL:

the #xz #backdoor should be codenamed DOUBLEPULSSHAR :D

because its more or less exactly double pulsar (in.. features?) but for linux.

hamoid, to random
@hamoid@genart.social avatar

Does the #xz #backdoor issue affect users with the sshd service disabled? It's hard to know that by reading those super detailed posts. Basically, under what circumstances is it an issue?

jspath55, to random
@jspath55@chaos.social avatar

Great. I did a CygWin install the other day, and got this:

$ xz --version
xz (XZ Utils) 5.6.1
liblzma 5.6.1

#BackDoor

0x58, to Cybersecurity

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #35/2023 is out! It includes the following and much more:

➝ 🔓 🏌🏻‍♂️Golf gear giant #Callaway data breach exposes info of 1.1 million
➝ 🔓👕 Forever 21 data breach affects half a million people
➝ 🔓 🤦🏻‍♂️ #LogicMonitor customers hit by hackers, because of default passwords
➝ 🇺🇸 ⚖️ Lawsuit Accuses University of Minnesota of Not Doing Enough to Prevent #DataBreach
➝ 🎬 🔓 #Paramount discloses data breach following security incident
➝ 🏥 🔓 #Healthcare Organizations Hit by Cyberattacks Last Year Reported Big Impact, Costs
➝ 🇺🇸 🌎 #Microsoft joins a growing chorus of organizations criticizing a #UN cybercrime treaty
➝ 🇺🇸 🦠 U.S. Hacks #QakBot, Quietly Removes Botnet Infections
➝ 🇷🇺 🇺🇦 #Russia targets #Ukraine with new Android #backdoor, intel agencies say
➝ 🇷🇺 🕵🏻‍♂️ Unmasking #Trickbot, One of the World’s Top Cybercrime Gangs
➝ 🇨🇳 👀 ‘Earth Estries’ #Cyberespionage Group Targets Government, Tech Sectors
➝ 🇨🇳 Chinese Hacking Group Exploits Barracuda Zero-Day to Target Government, Military, and Telecom
➝ 💸 🇪🇺 Pay our ransom instead of a #GDPR fine, #cybercrime gang tells its targets
➝ 🇺🇸 🇨🇳 #Meta: Pro-Chinese influence operation was the largest in history
➝ 🇪🇸 📸 Spain warns of #LockBit Locker ransomware phishing attacks
➝ 🇵🇱 🚂 Two Men Arrested Following #Poland Railway Hacking
➝ 🇰🇵 🐍 #Lazarus hackers deploy fake #VMware PyPI packages in #VMConnect attacks
➝ 💸 #Classiscam fraud-as-a-service expands, now targets banks and 251 brands
➝ 💬 🎠 Trojanized #Signal and #Telegram apps on Google Play delivered spyware
➝ 🦠 📄 MalDoc in PDFs: Hiding malicious Word docs in PDF files
➝ 🇧🇷 👀 A Brazilian phone #spyware was hacked and victims’ devices ‘deleted’ from server
➝ 👨🏻‍💻 🔐 #GitHub Enterprise Server Gets New Security Capabilities
➝ 🚗 💰 Over $1 Million Offered at New #Pwn2Own #Automotive Hacking Contest
➝ 🩹 #Splunk Patches High-Severity Flaws in Enterprise, IT Service Intelligence
➝ ⛏️ 🔓 Recent #Juniper Flaws Chained in Attacks Following #PoC Exploit Publication

📚 This week's recommended reading is: "Spam Nation: The Inside Story of Organized Cybercrime―from Global Epidemic to Your Front Door" by @briankrebs

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-352023

heiseonline, to security German

Digitaler Behördenfunk: Massive Schwachstellen bei TETRA entdeckt

Der TETRA-Funkstandard wird vor allem von Behörden genutzt. Doch die international genutzte Verschlüsselung hat eine Hintertür.

https://www.heise.de/news/Digitaler-Behoerdenfunk-Massive-Schwachstellen-bei-TETRA-entdeckt-9226620.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

#Verschlüsselung #Geheimdienste #Backdoor #Militär #Netze #NSA #Polizei #Security #news

jschauma, to random
@jschauma@mstdn.social avatar

For anybody cynically going "haha, 'given enough eyeballs, all bugs are shallow" my ass", I'm willing to argue that the reverse engineering of the #xz #backdoor actually validates this claim.

We just didn't have enough eyeballs on this particular dependency, nor is it possible to have every commit in your dependency graph investigated. But once the issue was found, the community's focus moved like the 👁️ of Sauron; few teams could have done that work (as quickly, thoroughly, or at all).

eighthave, to fdroid

Three years ago, had a similar kind of attempt as the . A new contributor submitted a merge request to improve the search, which was oft requested but the maintainers hadn't found time to work on. There was also pressure from other random accounts to merge it. In the end, it became clear that it added a . In this case, we managed to catch it before it was merged. Since similar tactics were used, I think its relevant now

https://gitlab.com/fdroid/fdroidclient/-/merge_requests/889

Tutanota, to microsoft
@Tutanota@mastodon.social avatar

Here's a stark reminder that any #backdoor is a #vulnerability:

"China-based hackers used a stolen sign-in key" to hack into US government's #Microsoft email accounts.

That's why we at Tutanota fight for strong encryption - without any backdoor. 🔒

https://edition.cnn.com/2023/07/12/politics/china-based-hackers-us-government-email-intl-hnk/index.html

Uraael, to linux

Linux folks: If your response to the XZ backdoor is to joke or even contextualise along the lines of "Yes, but Windows/Mac are worse..." take a moment to think about how you'd respond to an individual taking responsibility by insulting others to make themselves look better.

Not a great look, is it?

qlp, to debian
@qlp@linh.social avatar

Debian users who are using testing, unstable or experimental may want to be wary of the compromised version of xz. This is tied to the same notification that went out for Fedora 41, some Fedora 40 and Rawhide users.

https://lists.debian.org/debian-security-announce/2024/msg00057.html

cccfr, to internet German
@cccfr@chaos.social avatar

xz or not xz , thats the question?
ugly, mode: alles anzünden

"Backdoor found in xz liblzma specifically targets the RSA implementation of OpenSSH. Story still developing."


https://www.youtube.com/watch?v=jqjtNDtbDNI
https://openwall.com/lists/oss-security/2024/03/29/4
https://archlinux.org/news/the-xz-package-has-been-backdoored/
https://sc.tarnkappe.info/d941c4

freezenet, (edited ) to business
@freezenet@noc.social avatar

Signal CEO Reaffirms Exit of UK if Ordered to Break Encryption Via Online Safety Bill

The CEO of encrypted chat service, Signal, has reaffirmed that they will leave the UK if they are asked to break their encryption.

Fallout from the UKs disastrous passage

https://www.freezenet.ca/signal-ceo-reaffirms-exit-of-uk-if-ordered-to-break-encryption-via-online-safety-bill/

#Business #Privacy #Security #backdoor #britain #encryption #EndtoendEncryption #OnlineSafetyBill #Signal #UK

MeineKehrseite, to Software German

Je mehr rollende #Hubs auf den Straßen unterwegs sind, um so mehr mache ich mir Sorgen über #Backdoors in den #Fahrzeugbetriebssystemen.
Ich finde tatsächlich die #Macht von #Software in einem Fahrzeug/Flugzeug/Schiff/Pottwal(😂) bedenklich. #SpaceFascho #China #Hacker #backdoor

evawolfangel, to Cybersecurity German
@evawolfangel@chaos.social avatar

Ich durfte im Kaspersky-Quellcode nach einer Backdoor suchen. Hab keine gefunden. (Bin aber auch nicht wirklich qualifiziert dafür…)
Das hat mich in die Frage des Vertrauen vertiefen lassen. Eines ist klar: Andere haben das Vertrauen schon oft gebrochen.

https://www.zeit.de/digital/datenschutz/2023-07/kaspersky-antivirensoftware-russland-sicherheitsfirma-datenschutz

irreticent, to technology
jschauma, to random
@jschauma@mstdn.social avatar

Here's a thorough analysis of all the commits by "Jia Tan" from 2023-08 through 2024-03, showing the many legitimate code changes done before the introduction of the :

https://tukaani.org/xz-backdoor/review.html

GayOldTime, to Vintage
@GayOldTime@masto.ai avatar

I don't even know why I have this image in my collection. It clearly doesn't contain innuendo or double entendres of any kind.
#vintage #gay #backdoor #comics

redhotcyber, to Symfony Italian
@redhotcyber@mastodon.bida.im avatar

Adobe Magneto: una pericolosa minaccia RCE per i siti di e-commerce

Gli specialisti di Sicurezza Informatica hanno avvertito che gli #hacker stanno già sfruttando una nuova #vulnerabilità in #Magento (CVE-2024-20720) e l'utilizzatore per implementare una #backdoor persistente sui siti di e-commerce.

#redhotcyber #online #it #web #ai #hacking #privacy #cybersecurity #cybercrime #intelligence #intelligenzaartificiale #informationsecurity #ethicalhacking #dataprotection #cybersecurityawareness #cybersecuritytraining #cybersecuritynews #infosecurity

https://www.redhotcyber.com/post/adobe-magneto-una-pericolosa-rce-minaccia-i-siti-di-e-commerce/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • JUstTest
  • All magazines