New XZ backdoor scanner detects implant in any Linux binary
ID: 4c9e73eb-9b70-5f9e-b519-9e27207c0f04
STIX ID: report--4c9e73eb-9b70-5f9e-b519-9e27207c0f04
Feed Name: Bleeping Computer
Threat Score
Binarly released a free online scanner and API (xz.fail) to detect a supply-chain backdoor (CVE-2024-3094) implanted in XZ Utils that leverages GCC IFUNC resolution to hook execution (observed in XZ 5.6.0/5.6.1); the article describes the backdoor's mechanism, limited exposure to bleeding-edge distributions, and Binarly's static-analysis approach to find IFUNC tampering across binaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
