Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
near-miss cyberattack put US officials and the tech industry on edge
#1
UPDATE 1-Why a near-miss cyberattack put US officials and the tech industry on edge
Raphael Satter
Fri, Apr 5, 2024, 11:10 AM EDT5 min read


By Raphael Satter

WASHINGTON, April 5 (Reuters) - German software developer Andres Freund was running some detailed performance tests last month when he noticed odd behavior in a little known program. What he found when he investigated has sent shudders across the software world and drawn attention from tech executives and government officials.

Freund, who works for Microsoft out of San Francisco, discovered that the latest version of the open source software program XZ Utils had been deliberately sabotaged by one of its developers, a move that could have carved out a secret door to millions of servers across the internet.

Security experts say it’s only because Freund spotted the change before the latest version of XZ had been widely deployed that the world was spared a digital security crisis.   continues-safety of open source software
Reply
#2
This backdoor almost infected Linux everywhere: The XZ Utils close call | ZDNET


(04-06-2024 , 03:30 PM)scolli23 Wrote: UPDATE 1-Why a near-miss cyberattack put US officials and the tech industry on edge
Raphael Satter
Fri, Apr 5, 2024, 11:10 AM EDT5 min read


By Raphael Satter

WASHINGTON, April 5 (Reuters) - German software developer Andres Freund was running some detailed performance tests last month when he noticed odd behavior in a little known program. What he found when he investigated has sent shudders across the software world and drawn attention from tech executives and government officials.

Freund, who works for Microsoft out of San Francisco, discovered that the latest version of the open source software program XZ Utils had been deliberately sabotaged by one of its developers, a move that could have carved out a secret door to millions of servers across the internet.

Security experts say it’s only because Freund spotted the change before the latest version of XZ had been widely deployed that the world was spared a digital security crisis.   continues-safety of open source software
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)