Sponsor of the Day:
Jerkmate
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
Everything I Know About the XZ Backdoor
Please note: This is being updated in real-time. The intent is to make sense of lots of simultaneous discoveries
xz backdooreverythingknow
https://rya.nc/xz-valid-n.html
Putting an xz Backdoor Payload in a Valid RSA Key | rya.nc
Last week, a backdoor was discovered in xz-utils. The backdoor processes commands sent using RSA public keys as a covert channel. In order to prevent…
xz backdoorrsa keyrya ncputtingpayload
https://xygeni.io/blog/xz-backdoor-that-was-a-close-one/
XZ Backdoor: “That was a close one” | Xygeni
xz backdoorclosexygeni
https://www.wired.com/story/xz-backdoor-everything-you-need-to-know/
The XZ Backdoor: Everything You Need to Know | WIRED
Apr 2, 2024 - Details are starting to emerge about a stunning supply chain attack that sent the open source software community reeling.
xz backdoorknow wiredeverythingneed
https://optimizedbyotto.com/post/xz-backdoor-debian-git-detection/
Could the XZ backdoor have been detected with better Git and Debian packaging practices?
Oct 19, 2025 - The discovery of a backdoor in XZ Utils in the spring of 2024 shocked the open source community, raising critical questions about software supply chain...
xz backdoorbetter gitdebian packagingcoulddetected
https://luj.fr/blog/how-nixos-could-have-detected-xz.html
How NixOS and reproducible builds could have detected the xz backdoor for the benefit of all —...
Introduction In March 2024, a backdoor was discovered in xz, a (de)-compression software that is regularly used at the core of Linux distributions to unpack...
reproducible buildsxz backdoornixoscoulddetected
https://www.kusari.dev/blog/xz-backdoor-software-security-lessons
XZ Backdoor: Lessons for Software Supply Chain Security | Kusari®
Uncover crucial software supply chain security lessons from the XZ backdoor incident. Learn how Kusari helps prevent similar threats in your development...
software supply chainxz backdoorlessonssecurity
https://www.openwall.com/lists/oss-security/2024/03/29/15
oss-security - Re: backdoor in upstream xz/liblzma leading to ssh server compromise
upstream xz liblzmassh server compromiseoss securitybackdoorleading
https://www.openwall.com/lists/oss-security/2024/03/30/5
oss-security - Re: backdoor in upstream xz/liblzma leading to ssh server compromise
upstream xz liblzmassh server compromiseoss securitybackdoorleading
https://www.schneier.com/blog/archives/2024/04/xz-utils-backdoor.html
XZ Utils Backdoor - Schneier on Security
Apr 10, 2024 - The cybersecurity world got really lucky last week. An intentionally placed backdoor in XZ Utils, an open-source compression utility, was pretty much...
xz utils backdoorschneiersecurity
https://www.openwall.com/lists/oss-security/2024/03/30/21
oss-security - Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise
upstream xz liblzmassh server compromiseoss securitybackdoorleading
https://blog.rubygems.org/2024/03/31/rubygems-and-xz.html
RubyGems is not vulnerable to the xz/liblzma backdoor - RubyGems Blog
Mar 31, 2024 - The past few days have seen the security world focused on the revelation of the xz/liblzma backdoor. For more background, see this early writeup of the issue,...
xz liblzmarubygemsvulnerablebackdoorblog
https://www.openwall.com/lists/oss-security/2024/03/29/4
oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise
upstream xz liblzmassh server compromiseoss securitybackdoorleading
https://guardsix.com/blog/emerging-threats/xz-utils-backdoor
XZ Utils Backdoor: Supply Chain Vulnerability (CVE-2024-3094) - guardsix
xz utils backdoorcve 2024 3094supply chainvulnerabilityguardsix
https://www.openmandriva.org/en/news/article/discovered-a-backdoor-in-xz-security-update-for-openmandriva-users?q=%2Fen%2Fnews%2Fen%2Fnews%2Farticle%2Fdiscovered-a-backdoor-in-xz-security-update-for-openmandriva-users
Discovered a backdoor in xz. Security update for (…) - OpenMandriva
As it might affect cooker and rolling users, please upgrade as soon as possible. A backdoor in liblzma, part of the xz compressor has been
security updatediscoveredbackdoorxzopenmandriva
https://tukaani.org/xz-backdoor/
XZ Utils backdoor
xz utils backdoor
https://arstechnica.com/security/2024/04/what-we-know-about-the-xz-utils-backdoor-that-almost-infected-the-world/
What we know about the xz Utils backdoor that almost infected the world - Ars Technica
Apr 1, 2024 - Malicious updates made to a ubiquitous tool were a few weeks away from going mainstream.
xz utils backdoorworld ars technicaknowalmostinfected