Log in

goodpods headphones icon

To access all our features

Open the Goodpods app
Close icon
Crying Out Cloud - CROC News - XZ Utils backdoor explained

CROC News - XZ Utils backdoor explained

03/31/24 โ€ข 12 min

Crying Out Cloud

The backdoor in XZ Utils is shaking the industry ๐Ÿ”” How could we not talk about it?

Tune in to the special unscheduled episode of Crying Out Cloud with Eden Naftali and Amitai Cohen as they delve into the stealthy supply chain attack!

In this episode: ๐Ÿ” The Alert from CISA regarding CVE-2024-3094, a vulnerability in XZ Utils Data Compression Library versions 5.6.0 and 5.6.1 ๐Ÿ›‘ The potential risks posed by the embedded malicious code and the unauthorized access it may grant to affected systems ๐Ÿ›ก๏ธ Security Team Action Plans

Tune in now!

plus icon
bookmark

The backdoor in XZ Utils is shaking the industry ๐Ÿ”” How could we not talk about it?

Tune in to the special unscheduled episode of Crying Out Cloud with Eden Naftali and Amitai Cohen as they delve into the stealthy supply chain attack!

In this episode: ๐Ÿ” The Alert from CISA regarding CVE-2024-3094, a vulnerability in XZ Utils Data Compression Library versions 5.6.0 and 5.6.1 ๐Ÿ›‘ The potential risks posed by the embedded malicious code and the unauthorized access it may grant to affected systems ๐Ÿ›ก๏ธ Security Team Action Plans

Tune in now!

Previous Episode

undefined - CROC News: Malicious Repos, Bandwidth Theft, & NVD or NoVD?

CROC News: Malicious Repos, Bandwidth Theft, & NVD or NoVD?

๐ŸŽ™๏ธ What is a better way to stay updated on cloud security than a NEW Crying Out Cloud episode! Join Eden Naftali and Amitai Cohen as they explore what is new and ๐Ÿ”ฅ: ๐Ÿ‘พ Open-source repos flooded by malicious code. ๐Ÿ’ป What is to become of the National Vulnerability Database? โ›“๏ธ Proof of bandwidth cryptojacking ๐Ÿ› ๏ธ Critical vulnerabilities discovered in popular CI/CD tool

Links:

Next Episode

undefined - CROC Talks: Helping Secure Hugging Face Hub - Special Guest: Shir Tamari

CROC Talks: Helping Secure Hugging Face Hub - Special Guest: Shir Tamari

๐Ÿšจ BREAKING: Wiz Research identifies critical risks in #AI-as-a-service ๐Ÿšจ Dive into Crying Out Cloud's latest episode, featuring a very special guest, Shir Tamari, head of the research team at Wiz. This episode sheds light on the security challenges that come with the rapid integration of AI technologies. Highlights include: ๐Ÿš€ Exploring the rapid integration of AI and its associated security risks, identified by Wiz Research in collaboration with Hugging Face. ๐Ÿ›ก๏ธ Exposing two significant security flaws within Hugging Face's systems: shared inference and CI/CD systems, which could potentially offer unauthorized access to sensitive data. ๐Ÿ“ข Highlighting the critical need for robust security frameworks in AI services. โœ… Demonstrating Hugging Face's dedication to security through the adoption of Wiz CSPM, continuous vulnerability assessments, and annual penetration tests, thereby establishing a high standard in AI safety.

Episode Comments

Generate a badge

Get a badge for your website that links back to this episode

Select type & size
Open dropdown icon
share badge image

<a href="https://goodpods.com/podcasts/crying-out-cloud-387088/croc-news-xz-utils-backdoor-explained-55009277"> <img src="https://storage.googleapis.com/goodpods-images-bucket/badges/generic-badge-1.svg" alt="listen to croc news - xz utils backdoor explained on goodpods" style="width: 225px" /> </a>

Copy