Get the latest tech news

Backdoor found in widely used Linux utility breaks encrypted SSH connections


Malicious code planted in xz Utils has been circulating for more than a month.

Researchers have found a malicious backdoor in a compression tool that made its way into widely used Linux distributions, including those from Red Hat and Debian. An update the following day included a malicious install script that injected itself into functions used by sshd, the binary file that makes SSH work. “This could break build scripts and test pipelines that expect specific output from Valgrind in order to pass,” the person warned, from an account that was created the same day.

Get the Android app

Or read this on r/technology

Read more on:

Photo of Linux

Linux

Photo of SSH

SSH

Photo of backdoor

backdoor

Related news:

News photo

Red Hat warns of backdoor in XZ tools used by most Linux distros

News photo

Decade-old Linux ‘wall’ bug helps make fake SUDO prompts, steal passwords

News photo

Microsoft will let you manage Linux distros on Windows 11 through GUI