>

The XZ Utils Backdoor: Inside the Almost-Catastrophe

The most patient supply-chain attack ever caught — a two-year maintainer infiltration that planted an SSH backdoor into xz-utils release tarballs, discovered in March 2024 only because one engineer noticed 500 milliseconds of latency. This account traces the Jia Tan persona from helpful contributor to release engineer, the test-file obfuscation and build-stage injection, the systemd/sshd target chain, the near-miss that kept stable distros clean, and the trust-model reforms that rippled through open source.

Continue ReadingThe XZ Utils Backdoor: Inside the Almost-Catastrophe

Ray AI Framework’s ‘Won’t Fix’ CVEs: A Control-Plane Debate

When Protect AI disclosed five Ray vulnerabilities in March 2024 — including critical RCE via the unauthenticated control plane — Anyscale's 'won't fix, trusted-networks design' stance ignited the year's sharpest debate over AI infrastructure responsibility. This piece unpacks the job-submission RCE, the exposed-cluster census, the bounty economics, what Anyscale later shipped anyway, and the hardening playbook that became standard for every exposed ML control plane.

Continue ReadingRay AI Framework’s ‘Won’t Fix’ CVEs: A Control-Plane Debate

JetBrains TeamCity Auth Bypass: Build Servers as Front Door

March 2024's CVE-2024-27198 let unauthenticated attackers mint admin accounts on self-hosted TeamCity CI servers, converting every connected build agent into attacker-controlled execution holding source, secrets and signing keys. This piece covers the alternate-path authentication bypass, the companion path traversal, the ransomware crews that queued within days, and the year's hard-learned rule that build infrastructure deserves domain-controller-grade security.

Continue ReadingJetBrains TeamCity Auth Bypass: Build Servers as Front Door
>