Red Hat Warns of Malware Embedded in Popular Linux Tool, Opening Doors for Unauthoriz
#1
Exclamation 
Quote:Red Hat has issued an urgent security alert regarding a highly sophisticated supply chain attack targeting the popular xz compression utility.

Cybersecurity researchers discovered malicious code embedded within recent versions of the xz libraries, which could potentially grant threat actors unauthorised remote access to affected Linux systems.

Technical Analysis of the Exploit
  • The vulnerability is tracked as CVE-2024-3094.
  • Compromised tools include the general-purpose data compression formats xz and xz-libs.
  • Malicious code is actively present in versions 5.6.0 and 5.6.1.
  • Security teams recommend reverting to the safe 5.4.x releases.
  • Affected distributions currently include Fedora Rawhide, Fedora 40 Beta, Debian unstable (Sid), and openSUSE.
  • The primary threat involves unauthorized remote system access via an SSH bypass.
The xz utility is a fundamental data compression format utilized across nearly every community and commercial Linux distribution to manage large file transfers.

The malicious injection specifically targets versions 5.6.0 and 5.6.1 of the libraries. Threat actors heavily obfuscated the payload, ensuring the complete exploit is only assembled within the official download package.

Continue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Kaspersky\VPN\KSOS 21.26 (MR26) & KES 1...
harlan4096 — 07:05
Audacity 3.7.8
Audacity 3.7.8 ...harlan4096 — 07:02
Google Chrome 149.0.7827.114/.115
Google Chrome 149....harlan4096 — 07:00
Microsoft Windows 11 Low Latency Profile...
Windows 11 June up...harlan4096 — 06:52
Microsoft: Windows 11 KB5094126, KB50939...
Windows June 2026 ...harlan4096 — 06:29

[-]
Birthdays
Today's Birthdays
avatar (32)horancos
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>