Red Hat Warns of Malware Embedded in Popular Linux Tool, Opening Doors for Unauthoriz
#1
Exclamation 
Quote:Red Hat has issued an urgent security alert regarding a highly sophisticated supply chain attack targeting the popular xz compression utility.

Cybersecurity researchers discovered malicious code embedded within recent versions of the xz libraries, which could potentially grant threat actors unauthorised remote access to affected Linux systems.

Technical Analysis of the Exploit
  • The vulnerability is tracked as CVE-2024-3094.
  • Compromised tools include the general-purpose data compression formats xz and xz-libs.
  • Malicious code is actively present in versions 5.6.0 and 5.6.1.
  • Security teams recommend reverting to the safe 5.4.x releases.
  • Affected distributions currently include Fedora Rawhide, Fedora 40 Beta, Debian unstable (Sid), and openSUSE.
  • The primary threat involves unauthorized remote system access via an SSH bypass.
The xz utility is a fundamental data compression format utilized across nearly every community and commercial Linux distribution to manage large file transfers.

The malicious injection specifically targets versions 5.6.0 and 5.6.1 of the libraries. Threat actors heavily obfuscated the payload, ensuring the complete exploit is only assembled within the official download package.

Continue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Microsoft confirms Windows 11 version 2...
Microsoft Confirms W...harlan4096 — 08:41
AxCrypt 3.1.5.0
AxCrypt 3.1.5.0: ...harlan4096 — 11:50
AMD will reinstate memory encryption on ...
The feature was qu...harlan4096 — 11:48
Microsoft confirms Windows 11 version 26...
Who would have gue...harlan4096 — 11:46
Windows 11 June 2026 Update Breaks Recyc...
Microsoft has conf...harlan4096 — 11:45

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>