Risk of socially engineered backdoors in critical software seems like an indictment of open-source projects, but it could happen anywhere, EFF’s Molly told @theintercept - in fact, this one was found only due to the project’s open nature.
https://theintercept.com/2024/04/03/linux-hack-xz-utils-backdoor/
The Other Players Who Helped (Almost) Make the World’s Biggest Backdoor Hack

A hacker spent years ingratiating themself to a developer — then, perhaps with the help of others, injected a backdoor into their Linux code.

The Intercept
@eff @theintercept Exactly - see Solarwinds, or even the Microsoft o365 hack.
@pyperkub @eff @theintercept see also the North Koreans getting hired at cryptocurrency startups.
@womble @eff @theintercept Hmm. Hadn't heard of that - got a link?