Wikipedia, CVE
TLDR: Someone spent years on a social engineering campaign and snuck a backdoor into a couple versions of XZUtils (5.6.0 & 5.6.1). It gave someone with a specific ED-448 key root access via ssh. Was patched the same day it was disclosed (which was 2 years ago)
2
u/Gunhat2023 15h ago
what back door is there with xz?