circl, to infosec
@circl@social.circl.lu avatar

TR-82 - backdoor discovered in xz-utils - CVE-2024-3094

🔗 For more information including detection and information about vulnerable distribution https://www.circl.lu/pub/tr-82/

#xz #vulnerability #infosec #backdoor #vulnerabilities #cve20243094

Uraael, to linux

Linux folks: If your response to the XZ backdoor is to joke or even contextualise along the lines of "Yes, but Windows/Mac are worse..." take a moment to think about how you'd respond to an individual taking responsibility by insulting others to make themselves look better.

Not a great look, is it?

shamanix, to opensource
@shamanix@mastodon.gamedev.place avatar
isaac, to linux
@isaac@hachyderm.io avatar

openSUSE is advising many of its Tumbleweed users to install fresh.

https://news.opensuse.org/2024/03/29/xz-backdoor/

#xz #backdoor #linux

deltatux, to linux
@deltatux@infosec.town avatar

A Microsoft engineer discovered a backdoor in the latest Linux release of xz, a popular compression format. Both Debian and Red Hat has issued security advisories for these and a 10/10 CVE was generated for this.

As most stable Linux distributions tend to freeze library versions, most people are likely unaffected. However, this does affect development versions of distros, short release window distros like Fedora and rolling release distros like Arch.
www.bleepingcomputer.com/news/security/red-hat-warns-of-backdoor-in-xz-tools-used-by-most-linux-distros/

#linux #backdoor #xz #redhat #fedora #debian

Debby, to internet
@Debby@esperanto.masto.host avatar

A Backdoor in XZ Utils was found!
To know if you are affected rune:
xz -V in your terminal
if like me you have XZ 5.6.0 or XZ 5.6.1 downgrade XZ Utils to an earlier version, such as 5.4.6 (Stable) or disable ssh

Malicious backdoor found in ssh libraries https://www.youtube.com/watch?v=jqjtNDtbDNI

Are You Affected by the Backdoor in XZ Utils?
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils

https://openwall.com/lists/oss-security/2024/03/29/4

https://archlinux.org/news/the-xz-package-has-been-backdoored/

veronica, to python
@veronica@mastodon.online avatar
roguelazer, to random
@roguelazer@hachyderm.io avatar

This #xz #backdoor really sucks. You know it's serious because it doesn't even seem to be designed to mine shitcoins!

https://www.openwall.com/lists/oss-security/2024/03/29/4

Adorable_Sergal, to random
@Adorable_Sergal@hachyderm.io avatar
cccfr, to internet German
@cccfr@chaos.social avatar

xz or not xz , thats the question?
ugly, mode: alles anzünden

"Backdoor found in xz liblzma specifically targets the RSA implementation of OpenSSH. Story still developing."


https://www.youtube.com/watch?v=jqjtNDtbDNI
https://openwall.com/lists/oss-security/2024/03/29/4
https://archlinux.org/news/the-xz-package-has-been-backdoored/
https://sc.tarnkappe.info/d941c4

cccfr,
@cccfr@chaos.social avatar

"I think a LOT of people are missing the fact that we got LUCKY with this malicious backdoor.".

you could be affected if using Debian sid or kali.
In other cases you probably wont.

we expect more, and good detailed write ups / Videos on that the coming hours and days.

"I gave a talk about state actors attacking FOSS, ten years ago, on : https://www.youtube.com/watch?v=3jQoAYRKqhg "

here 2 threads
https://chaos.social/@tinker@infosec.exchange/112180669379673577
https://chaos.social/@tinker@infosec.exchange/112181161454177547

jspath55, to random
@jspath55@chaos.social avatar

Great. I did a CygWin install the other day, and got this:

$ xz --version
xz (XZ Utils) 5.6.1
liblzma 5.6.1

#BackDoor

RLetot, to debian French
@RLetot@mamot.fr avatar

oooook, donc #liblzma distribué dans le package #xz-utils 5.6 sous #debian sid/trixie, contient un #backdoor pour sshd...

https://www.openwall.com/lists/oss-security/2024/03/29/4

Si vous êtes sous debian sid/trixie et relativement à jour, c'est le moment d'être complètement à jour, le package ayant été corrigé.

Go go go:

apt update && apt upgrade

ianto_jones, to linux
@ianto_jones@mastodon.social avatar
dvzrv, to archlinux
@dvzrv@chaos.social avatar
eb, to security
@eb@social.coop avatar

Unfolding now: https://news.ycombinator.com/item?id=39865810

An incredibly technically complex in xz (potentially also in libarchive and elsewhere) was just discovered. This backdoor has been quietly implemented over years, with the assistance of a wide array of subtly interconnected accounts:

The timeline on this is going to take so long to unravel

qlp, to debian
@qlp@linh.social avatar

Debian users who are using testing, unstable or experimental may want to be wary of the compromised version of xz. This is tied to the same notification that went out for Fedora 41, some Fedora 40 and Rawhide users.

https://lists.debian.org/debian-security-announce/2024/msg00057.html

canard164, to Cybersecurity French

Red Hat warns of backdoor in XZ tools used by most Linux distros

https://www.bleepingcomputer.com/news/security/red-hat-warns-of-backdoor-in-xz-tools-used-by-most-linux-distros/

> Today, Red Hat warned users to immediately stop using systems running Fedora development versions because of a backdoor found in the latest XZ data compression tools and libraries.

#cybersecurity #linux #backdoor #xz

janvlug, to linux
@janvlug@mastodon.social avatar

☠️ ⚠️ The upstream xz repository and the xz tarballs have been backdoored. ⚠️ ☠️

https://www.openwall.com/lists/oss-security/2024/03/29/4

#linux #xz #backdoor #security #warning

w8emv, to random
@w8emv@hachyderm.io avatar

Red Hat assigned this issue CVE-2024-3094.

"Subject: backdoor in upstream xz/liblzma leading to ssh server compromise"

As posted to oss-security by Andres Freund andres@

https://www.openwall.com/lists/oss-security/2024/03/29/4

scy, to random
@scy@chaos.social avatar

Eek. Apparently liblzma (part of the xz package) has a backdoor in versions 5.6.0 and 5.6.1, causing SSH to be compromised.

https://www.openwall.com/lists/oss-security/2024/03/29/4

This might even have been done on purpose by the upstream devs.

Developing story, please take with a grain of salt.

The 5.6 versions are somewhat recent, depending on how bleeding edge your distro is you might not be affected.

#liblzma #xz #lzma #backdoor #ITsecurity #OpenSSH #SSH

informapirata, (edited ) to random Italian
@informapirata@mastodon.uno avatar

Su richiesta di alcuni follower abbiamo creato (molto controvoglia) una versione whatsapp del nostro canale Telegram Informapirata...

Ebbene? Dopo diversi giorni quanti utanti abbiamo totalizzato?

(per la cronaca, il nostro canale Telegram, dopo tre anni, ha raggiunto quasi 1000 utenti)

paoloredaelli,
@paoloredaelli@mastodon.uno avatar

@informapirata
Sicuro un corno, essendo può essere strapieno di assai difficili da stanare. La memoria vacilla ma mi sembra di ricordare che la polizia possa tranquillamente accedere a tutte le chat su Whatsapp
@Shivablue @xylya

simontsui, to macos

BitDefender identified a MacOS backdoor written in Rust that has possible link to ALPHV/BlackCat ransomware group. "Specifically, three out of the four command and control servers have been previously associated with ransomware campaigns targeting Windows clients. ALPHV/BlackCat is a ransomware family (also written in Rust), that first made its appearance in November 2021, and that has pioneered the public leaks business model." IOC provided.
🔗 https://www.bitdefender.com/blog/labs/new-macos-backdoor-written-in-rust-shows-possible-link-with-windows-ransomware-group/

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2024 is out! It includes the following and much more:

➝ 🔓 🎽 Halara probes breach after hacker leaks data for 950,000 people
➝ 🔓 💥 's X Account Was Hacked Using Brute-Force Attack
➝ 🔓 🇵🇾 warns of Black Hunt attacks after Tigo Business
➝ 🇺🇸 💸 US SEC’s X account hacked to announce fake ETF approval
➝ 🔓 🇨🇦 Toronto Zoo: Ransomware attack had no impact on animal
➝ 🔓 Mortgage firm loanDepot impacts IT systems, payment portal
➝ 🇫🇮 💸 warns of Akira ransomware wiping NAS and tape devices
➝ 🇩🇰 🇷🇺 probably wasn’t behind Danish critical infrastructure cyberattack, report says
➝ 🇺🇦 🇷🇺 Pro-Ukraine hackers breach Russian ISP in revenge for attack
➝ 🇫🇷 🇺🇸 French Computer Hacker Jailed in US
➝ 🇳🇬 ⚖️ Nigerian gets 10 years for laundering millions stolen from elderly
➝ 🇹🇷 Turkish Hackers Exploiting Poorly Secured Servers Across the Globe
➝ 🇹🇷 🇳🇱 Turkish Targeting Netherlands
➝ ☁️ 🇪🇺 Lets Cloud Users Keep Personal Data Within to Ease Fears
➝ 🇺🇸 🇨🇳 is helping US spies catch stealthy Chinese hacking ops, official says
➝ 🇱🇧 ✈️ Beirut Airport Screens Hacked with Anti-Hezbollah Message
➝ 🇸🇦 Saudi Ministry exposed sensitive data for 15 months
➝ 🇬🇷 to Establish New Authority to Counter Cyber-Attacks
➝ 🩹 , Release First Patch Tuesday Advisories of 2024
➝ 🐍 ☁️ New -based FBot Hacking Toolkit Aims at and Platforms
➝ 🦠 📺 Videos Promoting Cracked Software Distribute Lumma Stealer
➝ 🦠 🐧 devices are under attack by a never-before-seen worm
➝ 🦠 🇳🇱 Dutch Engineer Used Water Pump to Get Billion-Dollar Into Iranian Nuclear Facility
➝ 🐡 🔐 DSA removal from
➝ 🩹
➝ 🐛 🔓 Actively exploited 0-days in VPN are letting hackers networks
➝ 🔓 🔧 Hackers can infect network-connected wrenches to install ransomware
➝ 🇨🇳 🔓 cracked by , revealing phone number and email address of sender
➝ 🩹 Patches High-Severity Flaws in QTS, Video Station, QuMagie, Netatalk Products
➝ 🐛 🔓 KyberSlash attacks put projects at risk

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-022024

jwildeboer, to random German
@jwildeboer@social.wildeboer.net avatar

#NFC geeks/nerds: where can I buy NFC cards with a #ST25TA64K chip? It seems that is the chip with the biggest storage available? Or do you know of other standard type 4 tags with 8kB or more?

kkarhan,
@kkarhan@mstdn.social avatar

@mwfc @jwildeboer Good question!

Most barely allow one to use documented APIs and shove private keys on, generate new keypairs and export the public keys and wipe the keys on it.

Let's just say I don't trust them at all - espechally to not have some #Govware #backdoor to spit out private keys against the user/owner's consent!

https://www.youtube.com/watch?v=s7WDbnHlc1E

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • JUstTest
  • All magazines