PLAY PODCASTS
Network Security News Summary for Monday April 01th, 2024

Network Security News Summary for Monday April 01th, 2024

SANS Internet Storm Center's Daily Network Security News Podcast · Johannes B. Ullrich

March 31, 20247m 38s

Audio is streamed directly from the publisher (traffic.libsyn.com) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.

Show Notes

xz-utils Backdoor (CVE-2024-3094) xz-utils Backdoor CVE-2024-3094 https://www.openwall.com/lists/oss-security/2024/03/29/4 https://tukaani.org/xz-backdoor/ https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 Backdoor reverse analysis https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b YARA Rule https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar Social Engineering Attempts to Include Backdoor in Distros https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708 https://news.ycombinator.com/item?id=39866275 Github Repo (now disabled) https://github.com/tukaani-project/xz Statements from Distributions https://www.kali.org/blog/about-the-xz-backdoor/ https://archlinux.org/news/the-xz-package-has-been-backdoored/ https://access.redhat.com/security/cve/CVE-2024-3094 https://bugs.gentoo.org/928134 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 keywords: xz-utils; backdoor; xz