Backdoor in XZ Utils poses security risk in Linux

nextgov.com

CISA warns of a backdoor in XZ Utils, a Linux file compression tool, potentially allowing system access. Red Hat confirms the vulnerability affects certain beta Linux versions. Microsoft engineer discovers the flaw. Malicious code introduced by a long-time XZ contributor. CISA advises downgrading to secure versions. GitHub investigates exploit repository closure. Suspicions of nation-state involvement prompt FBI and NSA investigation. Open-source tool security debates reignite.


With a significance score of 3.9, this news ranks in the top 5.1% of today's 27646 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers: