The Crying out Cloud team revisits 2024's top stories—the XZ Utils backdoor (CVE-2024-3094), the SeleniumGreed misconfiguration campaign, and the SAPwned flaws in SAP AI Core—and their lessons.
A backdoor in XZ Utils 5.6.0 and 5.6.1 (CVE-2024-3094) surfaced when Andres Freund noticed sshd slowdowns; the code hid in compressed test files after a long-grooming supply chain effort.
A beginner walkthrough for reproducing the xz-utils/liblzma backdoor (CVE-2024-3094): set up a Kali VM, install backdoored liblzma 5.6.1 from Debian snapshots, and verify the compromise.
Summarizes the xz/liblzma CVE-2024-3094 supply chain backdoor: Microsoft's Andres Freund noticed odd SSH CPU usage and 500ms delays, uncovering a backdoor planted by long-term contributor Jia Tan.
Wiz explains CVE-2024-3094, the XZ Utils backdoor in versions 5.6.0 and 5.6.1 that could enable SSH authentication bypass and RCE on certain distros; about 2% of cloud environments were affected.
Kali explains CVE-2024-3094: xz-utils 5.6.0-5.6.1 contained a backdoor that could compromise sshd authentication and grant remote system access, with commands to check and patch affected installs.