Skip to content

Podcasts/Best episodes

Best podcast episodes on the XZ Utils backdoor

On March 29, 2024, Andres Freund disclosed on the oss-security mailing list that XZ Utils versions 5.6.0 and 5.6.1 contained a backdoor that could lead to SSH server compromise. The malicious code sat in the release tarballs rather than the project's git source, and CISA advised users to downgrade to an uncompromised version (CVE-2024-3094).

Sources: openwall.com, cisa.gov

8 episodes from 6 shows. Dates and lengths are from each show's own feed.

  1. 01

    Crying Out Cloud

    CROC News - XZ Utils backdoor explained

    · 13 min · Beginner

    Thirteen minutes, recorded within days: the fastest way to understand what was found.

  2. 02

    Microsoft Threat Intelligence Podcast

    Behind the Scenes of the XZ vuln with Andres Freund and Thomas Roccia

    · 33 min · Beginner

    Andres Freund himself on how an SSH performance oddity led him to the backdoor.

  3. 03

    Open Source Security

    XZ Bonus Spectacular Episode

    · 61 min · Practitioner

    An emergency episode from open source security veterans, explaining the basics while facts were still moving.

  4. 04

    Three Buddy Problem

    Costin Raiu joins the XZ Utils backdoor investigation

    · 52 min · Expert

    Costin Raiu digs into the timeline and the long-con tradecraft behind the attack.

  5. 05

    Paul's Security Weekly

    XZ - Backdoors and The Fragile Supply Chain - PSW #823

    · 172 min · Expert

    The full Security Weekly crew breaks down the technical details at length; long, but thorough.

  6. 06

    Application Security Weekly

    Lessons That The XZ Utils Backdoor Spells Out - Farshad Abasi - ASW #280

    · 60 min · Practitioner

    The appsec lessons: abuse of maintainer trust, obscured changes, and suppressed warnings.

  7. 07

    Application Security Weekly

    Open Source Software Supply Chain Security The Real Crisis Behind XZ Utils - Idan Plotnik, Luis Villa, Erez Hasson - ASW #287

    · 72 min · Practitioner

    Why undersupported maintainers are the real problem XZ exposed, and what consumers owe them.

  8. 08

    Open Source Security

    Detecting XZ in Debian with Otto Kekäläinen

    · 32 min · Expert

    A Debian maintainer on why an attack like XZ is nearly impossible to catch at packaging time.