XZ Utils backdoored for covert SSH access on Linux

helpnetsecurity.com

The XZ Utils compression utility was backdoored by a threat actor aiming for covert SSH access on Linux systems. The backdoor was discovered by a Microsoft engineer and has affected stable versions of some Linux distros. Tools and scripts have been released to detect the backdoor, which requires authentication via a private SSH key. Security firms like Binarly and Bitdefender have developed scanners for this purpose. Elastic Security Labs also provided detection rules.


With a significance score of 3.1, this news ranks in the top 11% of today's 18114 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers:


XZ Utils backdoored for covert SSH access on Linux | News Minimalist