![]() |
|
#1
|
||||
|
||||
|
State-sponsored hackers inject malware into "XZ" library
A Microsoft employee unintentionally discovered that SSH is a little slow! This triggered him to make a performance test then he realized that a guy is injected a malware into the liblzma lossless compression library.
OpenSSH doesn't need xz-utils as a dependency; but distros which -unfortunately- uses systemd have to patch OpenSSH to support systemd. There is a long debate started and going on social media for the last 24 hours. But I want to clear one point: when hackers are from China/North Korea/Russia/Iran, infosec community immediately reveal this information. They "emphatically" say where they are from. On the other hand if the hackers are not from those countries they the hackers are only `state-sponsored`! State sponsored but which state? Nobody is talking this issue ![]() Read the full mailing on Openwall: Code:
https://www.openwall.com/lists/oss-security/2024/03/29/4 Code:
https://lcamtuf.substack.com/p/technologist-vs-spy-the-xz-backdoor Code:
https://twitter.com/_ruby/status/1774073953440747664 Code:
https://infosec.exchange/@bluedevil/112185519485326084 |
| The Following User Gave Reputation+1 to blue_devil For This Useful Post: | ||
Fyyre (04-11-2024) | ||
| Tags |
| liblzma, state sponsored hackers, trojan, xz lossless compression |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| How come new registrants given "guest" rank and not even a "friend" rank? | OldieHans | General Discussion | 4 | 09-25-2023 12:19 |
| When use "vendor defined encryption routines", how to set daemon related part? | bridgeic | General Discussion | 6 | 01-22-2015 11:35 |
| Wlscgen: Are "Vendor Id" and "Developer Id" different ? | Numega Softice | General Discussion | 6 | 02-12-2007 18:12 |