#openwall

2024-04-14

Kaspersky analysis of the backdoor in XZ | Securelist
securelist.com/xz-backdoor-sto

"(...) On March 29, 2024, a single message on the #Openwall OSS-security mailing list marked an important discovery for the information security, open source and #Linux communities: the discovery of a malicious #backdoor in #XZ. (...)

Unlike other supply chain attacks (...) in Node.js, PyPI (...), this incident was a multi-stage operation that almost succeeded in compromising #SSH servers on a global scale. (...)"

Benjamin Carr, Ph.D. 👨🏻‍💻🧬BenjaminHCCarr@hachyderm.io
2023-10-13

#Squid games: In February 2021, #security researcher Joshua Rogers performed a security audit of Squid #proxy and said he uncovered 55 flaws in the project's C++ source code.
Fast forward to today, and Rogers asserts only 20 of those flaws have been fixed.
"After two and a half years of waiting, I have decided to release the issues publicly," Rogers wrote in a post to the #Openwall security mailing list.
We'd like to say don't panic … but maybe?
theregister.com/2023/10/13/squ

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst