http://lpoaj76nfopd5lpinbskyqtroppamrzhhay3g4vvjm75st6ger34lbyd.onion/posts/2024/03/news.html
XZ backdoor Apparently, someone spent years gaining the trust of the maintainer of the XZ compression tool, in order to insert a backdoor into versions 5.6.0 and 5.6.1. It seems that this backdoor would only be inserted into dpkg and RPM builds on x86_64 Linux, and that it somehow alters the execution of sshd when it is linked to liblzma (which again depends on XZ), however, it is as of now unclear if the backdoor also applies to other things linked to liblzma, and what exactly it would...