logo

Security alert: XZ Linux utility backdoor

ID: 6e97732a-bd77-5270-9602-7f7ff60e94e3

STIX ID: report--6e97732a-bd77-5270-9602-7f7ff60e94e3

Feed Name: Expel Blog

Threat Score
80/100

Date Published: 2024-03-29

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

Researchers discovered a supply-chain backdoor in the XZ compression utility (versions 5.6.0 and 5.6.1) introduced by a maintainer, which grants anyone possessing the embedded public key the ability to execute commands as root; affected systems should be identified and downgraded to XZ 5.4.6 or earlier and replaced binaries to remove the backdoor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.