New XZ backdoor scanner detects implant in any Linux binary
A free web scanner has been made available by firmware security company Binarly to identify Linux executables affected by the XZ Utils supply chain exploit, which is known as CVE-2024-3094.
A supply chain vulnerability in the data compression tools and libraries XZ Utils, which are utilised in numerous popular Linux distributions, is known as CVE-2024-3094.
Andres Freud, a Microsoft worker, found the backdoor in the most recent version of the XZ Utils package late last month while looking at strangely delayed SSH logins on Debian Sid, a rolling release of the Linux operating system.
A pseudonymous developer to XZ version 5.6.0 introduced the backdoor, which persisted in 5.6.1. The majority of Linux distributions and versions that used an earlier, safe library version were unaffec...

