Archive confirmed
xz-utils Backdoor (CVE-2024-3094) (Archive)
A build-time backdoor in liblzma, planted through a multi-year social engineering campaign against a single maintainer, and caught by a performance regression.
Archive category
Vulnerability disclosure, exploitation of widely deployed software, and systemic compromise.
Technical facts are taken from the vendor advisory and the CVE record; impact figures are not estimated here.
Archive confirmed
A build-time backdoor in liblzma, planted through a multi-year social engineering campaign against a single maintainer, and caught by a performance regression.
Archive confirmed
A remotely exploitable JNDI lookup in Apache Log4j 2, the disclosure-to-exploitation window, and the supply chain behind it.
Archive confirmed
The 7 May 2021 ransomware attack on the operator of the largest US fuel pipeline, the ransom payment, and the recovery of most of it.
Archive confirmed
A malicious update distributed through SolarWinds Orion, attributed publicly to a named threat actor, and the disclosure that followed.
Archive confirmed
The Windows SMB vulnerability that became the most consequential exploited vulnerability of the 2010s, and the two campaigns built on it.
Archive confirmed
A missing bounds check in OpenSSL that let a remote client read process memory, and the two years of unmonitored exploitation it enabled.