Are you affected by the 2024 backdoor in xz-utils?
Yesterday (2024-03-29) a backdoor was discovered in xz-utils 💔. It made the rounds on all social media opsec channels.
You can read the full disclosure here and. here.
As the only affected versions are 5.6.0
and 5.6.1
,
you can check if you are affected by running the gist below.
on a fleet of servers.
https://gist.github.com/gorillamoe/5922aa7b410ea6f03a57d25490492c02
If you are affected, you should upgrade to a newer version of xz-utils, or disable SSH on the affected servers.
Stay safe out there 🙃!