XZ Utils Backdoor (CVE-2024-3094): A Supply Chain Post-Mortem
A near-miss that would have put a backdoor in sshd across major Linux distributions, undone by a curious engineer noticing sshd was 500ms slower.
A near-miss that would have put a backdoor in sshd across major Linux distributions, undone by a curious engineer noticing sshd was 500ms slower.
How a pre-authentication SQL injection in a managed file transfer product became one of the largest data theft campaigns of 2023.
How Java Bean data binding turned into remote code execution on Spring MVC applications deployed as WAR files on Tomcat.
A week after disclosure, what we knew about the Log4j JNDI flaw, why the blast radius was so large, and how to find affected systems.
Notes on the four-vulnerability chain that let an unauthenticated attacker take over on-premises Exchange servers in early 2021.