XZ has been backdoored, whoah. Good thing people noticed it very quickly and we already have a patch. Since there is no official version with the fix, just downgrade.
https://archlinux.org/news/the-xz-package-has-been-backdoored/
https://www.phoronix.com/news/XZ-CVE-2024-3094
https://archlinux.org/news/the-xz-package-has-been-backdoored/
https://www.phoronix.com/news/XZ-CVE-2024-3094
Phoronix
XZ Struck By Malicious Code That Could Allow Unauthorized Remote System Access
Red Hat today issued an 'urgent security alert' for Fedora 41 and Fedora Rawhide users over XZ
List of interesting repos, libraries, tools, blog posts, writeups and papers related to cybersecurity.
https://github.com/0xor0ne/awesome-list
https://github.com/0xor0ne/awesome-list
GitHub
GitHub - 0xor0ne/awesome-list: Cybersecurity oriented awesome list
Cybersecurity oriented awesome list. Contribute to 0xor0ne/awesome-list development by creating an account on GitHub.
Forwarded from vx-underground
Today Avast unveiled 'GuptiMiner'.
tl;dr eScan AV, out of India, used HTTP for AV updates, not HTTPS, North Korea man-in-the-middle'd updates to large networks to deliver malware
We give this APT campaign an A+ because it's absurdly well executed
https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/
tl;dr eScan AV, out of India, used HTTP for AV updates, not HTTPS, North Korea man-in-the-middle'd updates to large networks to deliver malware
We give this APT campaign an A+ because it's absurdly well executed
https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/
Gendigital
GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining
Malware Campaign Exploiting Antivirus Updates
This media is not supported in your browser
VIEW IN TELEGRAM
Me whenever I hear "Dude, AI is going to steal your job"
I didn't have much time to write code recently. Projects are accumulating, but I'll deal with them later.
β€4