Backdoor Discovered in XZ Utils: Patch Your Systems Now (CVE-2024-3094)
ID: 36193522-51df-5049-98dd-8216db0f1eb5
STIX ID: report--36193522-51df-5049-98dd-8216db0f1eb5
Feed Name: HackRead
Threat Score
A malicious backdoor was found in the liblzma component of XZ Utils (CVE-2024-3094), present in versions 5.6.0 and 5.6.1, which could allow attackers to gain SSH access without valid credentials; the issue was discovered in late March 2024 before widespread distribution and users are advised to patch, downgrade, or update their systems immediately to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
