What we know about the xz Utils backdoor that almost infected the world | Ars Technica
On Friday, a lone Microsoft developer rocked the world when he revealed a backdoor had been intentionally planted in xz Utils, an open source data compression utility available on almost all installations of Linux and other Unix-like operating systems. The person or people behind this project likely spent years on it. They were likely very close to seeing the backdoor update merged into Debian and Red Hat, the two biggest distributions of Linux, when an eagle-eyed software developer spotted something fishy. Researchers have spent the weekend gathering clues. Here's what we know so far. What is xz Utils? xz Utils is nearly ubiquitous in Linux. It provides lossless data compression on virtually all Unix-like operating systems, including Linux. xz Utils provides critical functions for compressing and decompressing data during all kinds of operations. xz Utils also supports the legacy .lzma format, making this component even more crucial. What happened? Andres Freund, a developer and engin
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav On Friday, a lone Microsoft developer rocked the world when he revealed a backdoor had been intentionally planted in xz Utils, an open source data compression utility available on almost all installations of Linux and other Unix-like operating systems. The person or people behind this project likely spent years on it. They were likely very close to seeing the backdoor update merged into Debian and Red Hat, the two biggest distributions of Linux, when an e
Explore this link on the map →saved by
related reading
- research!rsc: Timeline of the xz open source attackresearch.swtch.com
- XZ Utils backdoor - Wikipediaen.wikipedia.org
- Everything I Know About the XZ Backdoorboehs.org
- Backdoor (computing) - Wikipediaen.wikipedia.org
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Zenbleedlock.cmpxchg8b.com
- When Intrusions Don’t Align: A New Water Watering Hole and Oldsmar | Dragosdragos.com
- The Dirty Pipe Vulnerability — The Dirty Pipe Vulnerability documentationdirtypipe.cm4all.com
- Security incident disclosure — July 2026huggingface.co
- Devlog ⚡ Zig Programming Languageziglang.org
- Florida water plant compromise came hours after worker visited malicious site - Ars Technicaarstechnica.com
- zlib - Wikipediaen.wikipedia.org