News Score: Score the News, Sort the News, Rewrite the Headlines

Timeline of the xz open source attack

Timeline of the xz open source attack Posted on Monday, April 1, 2024. Over a period of over two years, an attacker using the name “Jia Tan” worked as a diligent, effective contributor to the xz compression library, eventually being granted commit access and maintainership. Using that access, they installed a very subtle, carefully hidden backdoor into liblzma, a part of xz that also happens to be a dependency of OpenSSH sshd on Debian, Ubuntu, Fedora, and other systemd-based Linux systems. That...

Read more at research.swtch.com

© News Score  score the news, sort the news, rewrite the headlines