Critical XZ Utils vulnerability allows unauthorized system access

Help Net Security March 31, 2024, 09:00 AM UTC

Summary: A critical vulnerability (CVE-2024-3094) in XZ Utils may allow unauthorized system access on Linux distros. A German warning states 17,000+ Microsoft Exchange servers are vulnerable. NHS Scotland confirms a ransomware attack leaked patient data. Google reports a surge in zero-day exploits in 2023. Gartner predicts AI will reduce cybersecurity incidents. Scams are increasing in complexity and cost. McAfee notes 25% of Americans lost money to online tax scams.

Full article

Article metrics

The article metrics are deprecated.

I'm replacing the original 8-factor scoring system with a new and improved one. It doesn't use the original factors and gives much better significance scores.

Timeline:

  1. [5.6]
    Volunteer engineer finds cybersecurity threat in XZ Utils (The Japan Times)
    151d 16h

  2. [5.5]
    XZ Utils backdoored for covert SSH access on Linux (Help Net Security)
    152d 12h

  3. [5.6]
    Malicious code found in XZ Utils on Good Friday (The Guardian)
    154d 10h

  4. [6.6]
    Andres Freund prevented cybersecurity breach in XZ Utils software (The Hindu)
    154d 20h

  5. [5.6]
    Andres Freund uncovers sabotage in XZ Utils, preventing crisis (The Japan Times)
    155d 0h

  6. [6.1]
    Backdoor discovered in XZ Utils by Microsoft developer (The Intercept)
    157d 2h

  7. [5.9]
    Free online scanner detects XZ Utils backdoor in Linux (TechRadar)
    157d 9h

  8. [6.2]
    Linux narrowly avoided cyber attack from XZ Utils backdoor (The Verge)
    158d 1h

  9. [5.7]
    Supply chain attack targets XZ Utils in Linux distributions (Cybersecurity Dive)
    158d 3h

  10. [7.2]
    Backdoor in XZ Utils allows unauthorized root access (WIRED)
    158d 16h

  11. [5.9]
    Backdoor in XZ Utils poses security risk in Linux (Nextgov/FCW)
    159d 9h

  12. [5.8]
    Critical Linux vulnerability; update XZ Utils before 5.6.0 (IT World Canada)
    159d 13h

  13. [5.9]
    Backdoor found in xz Utils for Linux systems (Ars Technica)
    159d 18h

  14. [6.3]
    Critical xz package vulnerability discovered on Debian, CVE-2024-3094 (TechRadar)
    160d 4h

  15. [5.9]
    XZ Utils compromised by maintainer "Jia Tan." (Help Net Security)
    160d 6h

  16. [5.9]
    Critical security flaw in xz-utils threatens Linux and macOS (Security Boulevard)
    160d 20h

  17. [5.5]
    Malicious code in xz libraries poses security threat (The New Stack)
    161d 6h

  18. [4.3]
    Backdoor in xz compression utility version 5.6.0 discovered (SC Media)
    162d 1h
    Source
  19. [4.1]
    Backdoor found in xz Utils 5.6.0/5.6.1, affecting Linux distributions (Ars Technica)
    162d 5h
    Source
  20. [6.1]
    Critical XZ Utils vulnerability (CVE-2024-3094) compromises Linux systems (Help Net Security)
    162d 7h