ZeroHour
Product

Linux

0 mentions in 7 days · 1 in 30 days · 2 total · first seen · last

Timeline

CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products

CISA added six actively exploited vulnerabilities in Microsoft, Linux, Red Hat and Citrix products to its KEV catalog on August 26.

CISA added six new vulnerabilities to its Known Exploited Vulnerabilities catalog on August 26, citing signs of active exploitation in the wild. The affected products span Microsoft, Linux, Red Hat, and Citrix. Specific CVE identifiers and affected versions were not listed in the source text, but KEV listing requires confirmed exploitation.

Infosecurity Magazine · 19d agoExploit / PoC in the wild

Backdoor Xz Utils Linux Open Source

Infosecurity Magazine covers the XZ Utils open-source backdoor, a malicious implant in liblzma that targeted OpenSSH on major Linux distributions.

The article covers the XZ Utils backdoor, a malicious implant introduced into the widely used open-source compression library. The compromised liblzma code manipulated functions used by OpenSSH, nearly reaching stable releases of major Linux distributions before discovery. The incident is a prominent example of software supply chain compromise targeting critical open-source infrastructure.

Infosecurity Magazine · Aug 17, 2026VulnerabilityCVE-2024-3094

Related CVEs

  • Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
    Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
    · tukaani xz

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.