EPISODE · Apr 1, 2024 · 7 MIN
ISC StormCast for Monday, April 1st, 2024
from SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) · host Johannes Ullrich
xz-utils Backdoor CVE-2024-3094https://www.openwall.com/lists/oss-security/2024/03/29/4https://tukaani.org/xz-backdoor/https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 Backdoor reverse analysishttps://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b YARA Rulehttps://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar Social Engineering Attempts to Include Backdoor in Distroshttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708https://news.ycombinator.com/item?id=39866275 Github Repo (now disabled)https://github.com/tukaani-project/xz Statements from Distributionshttps://www.kali.org/blog/about-the-xz-backdoor/https://archlinux.org/news/the-xz-package-has-been-backdoored/https://access.redhat.com/security/cve/CVE-2024-3094https://bugs.gentoo.org/928134https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024
What this episode covers
xz-utils Backdoor CVE-2024-3094https://www.openwall.com/lists/oss-security/2024/03/29/4https://tukaani.org/xz-backdoor/https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 Backdoor reverse analysishttps://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b YARA Rulehttps://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar Social Engineering Attempts to Include Backdoor in Distroshttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708https://news.ycombinator.com/item?id=39866275 Github Repo (now disabled)https://github.com/tukaani-project/xz Statements from Distributionshttps://www.kali.org/blog/about-the-xz-backdoor/https://archlinux.org/news/the-xz-package-has-been-backdoored/https://access.redhat.com/security/cve/CVE-2024-3094https://bugs.gentoo.org/928134https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024
NOW PLAYING
ISC StormCast for Monday, April 1st, 2024
No transcript for this episode yet
Similar Episodes
Mar 26, 2026 ·1m
Jan 2, 2026 ·47m
Dec 21, 2025 ·46m