logo

Backdoor Discovered in XZ Utils: Patch Your Systems Now (CVE-2024-3094)

ID: 36193522-51df-5049-98dd-8216db0f1eb5

STIX ID: report--36193522-51df-5049-98dd-8216db0f1eb5

Feed Name: HackRead

Threat Score
70/100

Date Published: 2024-04-01

Date Updated: 2026-04-22

Author: Waqas

...
...

A malicious backdoor was found in the liblzma component of XZ Utils (CVE-2024-3094), present in versions 5.6.0 and 5.6.1, which could allow attackers to gain SSH access without valid credentials; the issue was discovered in late March 2024 before widespread distribution and users are advised to patch, downgrade, or update their systems immediately to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.