Hunting the XZ Backdoor (CVE-2024-3094) | Threat SnapShot

Описание к видео Hunting the XZ Backdoor (CVE-2024-3094) | Threat SnapShot

Welcome back to another episode of SnapAttack's Threat SnapShot! I’m AJ King, the Director of Threat Research here at SnapAttack. In today’s episode, I dive into detecting the XZ Backdoor, CVE-2024-3094, a sophisticated supply chain attack that could have had a massive impact on many Linux distributions.

This episode is crucial for anyone responsible for protecting Linux systems, providing you with the knowledge to hunt your in your environment for reverse shell activity. Whether you’re a seasoned professional or new to cybersecurity, this story of near-missed danger and breakdown of threat detection will keep you engaged and informed.

✅ Subscribe to SnapAttack for more in-depth analyses and real-world applications of cybersecurity defenses.

📢 Have questions or topics you’d like us to cover? Drop a comment below!

👋 Follow us:
  / snapattack  
  / snapattackhq  
  / ajkingio  
  / ajkingio  

References:
- https://github.com/tukaani-project/xz...
- https://www.cisa.gov/news-events/aler...
- https://access.redhat.com/security/cv...
- https://www.openwall.com/lists/oss-se...
- https://tukaani.org/xz-backdoor/
- https://tukaani.org/xz-backdoor/revie...
- https://gist.github.com/thesamesam/22...
- https://jfrog.com/blog/xz-backdoor-at...
- https://pentest-tools.com/blog/xz-uti...
- https://github.com/amlweems/xzbot

SnapAttack Resources:
- https://app.snapattack.com/collection... - Collection: CVE-2024-3094
- https://app.snapattack.com/threat/283... - Threat: XZ SSH Backdoor (CVE-2024-3094)
- https://app.snapattack.com/detection/... - Detection: Suspicious SSH Child Process
- https://app.snapattack.com/detection/... - Detection: Suspicious SSH Connection
- https://app.snapattack.com/detection/... - Detection: Netcat Outbound Connection
- https://app.snapattack.com/detection/... - Detection: Possible Netcat Reverse Shell
- https://app.snapattack.com/detection/... - Detection: Potential Exploitation of CVE-2024-3094 - Suspicious SSH Child Process
- https://app.snapattack.com/detection/... - Detection: Potential Netcat Reverse Shell Execution

Комментарии

Информация по комментариям в разработке