The XZ Utils Backdoor (CVE-2024-3094): How a Nation-State Nearly Compromised the World’s SSH
The XZ Utils backdoor (CVE-2024-3094) explained — the 2-year social engineering campaign, how the backdoor worked, which systems were affected, and lessons for open source security.