GM #nostr ☕️🌞
the xz utils attack should be a wake-up call for all open source projects. an attack was planned here over a long period of time.
GM #nostr ☕️🌞
the xz utils attack should be a wake-up call for all open source projects. an attack was planned here over a long period of time.
GM ☕☀️🎨
Everyone called it a back door, while it was a supply chain attack.
exactly, you get to the point
What happened 👀?
in my opinion a supply chain attack on open ssh over xz.
https://nvd.nist.gov/vuln/detail/CVE-2024-3094
This time it was discovered (by accident), but how often has it worked or will it work?
Never underestimate a bad actors patience.