AI Panel On August 7th moderated by Fusion Cyber AI
Army Navy Country Club, 1700 Army Navy Drive, Arlington, VA
Read More
A secret backdoor has been discovered in the XZ Utils compression library, used by several major Linux distributions including Fedora, Kali Linux, and openSUSE. This has been reported by The Hacker News.
Key Details:
sshd
daemon and systemd
. The attacker can inject code into the OpenSSH server, allowing execution of arbitrary payloads before authentication.How the Backdoor Works:
The malicious code is heavily obfuscated. It involves a prebuilt object file disguised within a test file in the source code. During the liblzma
build process, this object file is extracted and used to modify functions in the library, allowing interception and modification of data interactions.
Responses:
Note: At the time of this report, there are no reports of active exploitation in the wild.
Gain the Skills, Certifications, and Support You Need to Secure Your Future. Enroll Now and Step into a High-Demand Career !
Army Navy Country Club, 1700 Army Navy Drive, Arlington, VA
Read MoreHi! How may I help you?