@danielleaminov

1 Followers
1 Following
2 Posts
Threat researcher at @wiz
CVE-2024-3094: Critical RCE Vulnerability Found in XZ Utils | Wiz Blog

CVE-2024-3094 is a malicious code vulnerability in versions 5.6.0 and 5.6.1 of XZ Utils, enabling an SSH authentication bypass in certain Linux distributions

wiz.io
I've been looking into how the xz backdoor works and drew this sketch to make it easier to understand.
I'll update it as new information comes to light ✨