Binarly Releases Free Detection Tool for XZ Backdoor
Binarly, provider of an industry leading AI-powered firmware and software supply chain security platform, has created and released a free scanning tool to help defenders spot signs of the dangerous XZ backdoor (CVE-2024-3094).
The XZ.fail detection tool was released less than 24 hours after the discovery of a backdoor in the open-source XZ Utils, which provides lossless data compression on virtually all Unix-like operating systems, including Linux. (See CISA advisory).
According to Binarly chief executive Alex Matrosov, the tool includes generic IFUNC implantation detection with close to zero false-positives, showcasing the company’s binary code intelligence engine in action.
“This detection is based on behavioral analysis and can detect any invariants automatically if a similar backdoor is implanted somewhere else,” Matrosov added.
“Such a complex and professionally designed implantation framework is not developed for a one-shot operation. It could already be deployed elsewhere or partially reused in other operations. That’s exactly why we started focusing on more generic detection for this complex backdoor,” Matrosov added.
For those seeking more comprehensive detection and remediation strategies, the Binarly Transparency Platform offers an in-depth solution. With XZ detection capabilities deployed, the platform facilitates easy identification of malicious activities at scale, enabling users to take prompt and effective action to safeguard their software supply chains.
The XZ backdoor came to light on March 29, 2024, when a thread was published on Openwall's oss-security mailing list by Andres Freund, revealing a potential compromise in the open-source code.
For more information read our research article and access the free XZ backdoor scanner at XZ.fail.
About Binarly:
Binarly is a global firmware and software supply chain security company founded in 2021. The company’s flagship Binarly Transparency Platform is an enterprise-class, AI-powered solution used by device manufacturers, OEMs, IBVs and product security teams to identify known and unknown vulnerabilities, misconfigurations and signs of malicious code implantation. Binarly’s validated remediation playbooks have significantly reduced the cost and time to respond to security exposures. Based in Los Angeles, California, Binarly brings decades of research and program analysis expertise to build solutions to protect businesses, critical infrastructure, and consumers around the world.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240401230046/en/
Contact information
media@binarly.io
818.351.9637
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
the International Film Criticism Conference Is Launched in Riyadh8.11.2024 19:06:00 EET | Press release
The Saudi Film Commission announced the commencement of the second edition of the International Film Criticism Conference in Riyadh, running from November 6 to 10, 2024. The conference is distinguished by a vast presence of international filmmakers, critics, and cinephiles. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20241108289069/en/ The International Film Criticism Conference is launched in Riyadh (Photo: AETOSWire) The second edition of the Film Criticism Conference is held under the theme "Sound in Cinema", to explore the various impacts of sound on the film experience and its influence on the film industry. The discussions will cover different elements such as film scores, sound effects, and nature sounds. The conference will also include workshops, film screenings, and interactive exhibits. The opening ceremony started with an introductory video about the conference, its objectives, and past achievements, followed by
Panini S.p.A. Launches Expanded BioCred Solution Suite in Europe at Future Identity Festival8.11.2024 17:00:00 EET | Press release
Panini S.p.A., a global leader in payments technology and identity solutions, announces the European launch of its BioCred solution suite at Future Identity Festival, in London, UK. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20241108392625/en/ Securing the Future, One Identity at a Time. (Photo: Business Wire) BioCred is now available on cloud infrastructure, giving rise to the new BioCred CloudServ, which represents the first step toward a hardware-agnostic solution. As of today, BioCred CloudServ is accessible via the mobile device BioCred SecureTab, the latest addition to the Panini BioCred family of devices, creating a seamlessly integrated flow and delivering a comprehensive, secure identity solution. This turnkey solution, which was presented for the first time at Identity Week America in September, offers a wide range of authentication and verification functions, including the patented Panini BioCred method into a s
ITEN to Launch the Industrial-Scale Production of Its All-Solid-State Battery Powency Product Family8.11.2024 10:00:00 EET | Press release
Electronica 2024 Trade Fair--ITEN, a pioneer in the development and production of solid-state batteries for electronics markets, today announced the production launch of its new Powency family of rechargeable Li-ion batteries. The new family consists of high-power density batteries, including for now the PWY0150S battery, available in pre-production, and the PWY0250S battery, available as engineering samples. Those first Powency batteries respectively have a capacity of 150µAh and 250µAh. The Powency product family, which is manufactured at the ITEN facility in France, is a testament to the demonstration of ITEN's technological and industrial leadership in the field of solid-state batteries. ITEN will participate in the Electronica trade show in Munich from November 12 to 15, 2024 (Hall B4 - Stand E05) to showcase both PWY0150S and PWY0250S. Powency PWY0150S and PWY0250S, solid-state energy storage in an unmatched form factor The Powency PWS0150S and PWS0250S batteries are designed to
FPT Named Disruptor In HFS Horizons: IoT Service Providers, 20248.11.2024 07:53:00 EET | Press release
Global IT firm FPT, through its subsidiary FPT Software, has been recognized as a Disruptor in HFS Research Horizons report: IoT Service Providers, 2024. This marks the inaugural inclusion of FPT in this prestigious industry assessment, demonstrating its Internet of Things (IoT) capabilities. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20241107263712/en/ (Graphic: Business Wire) The report examines the IoT service capabilities of 23 service providers in the evolving IoT landscape in the age of the Generative Enterprise. It focuses on the supply side, detailing the service providers’ strengths and growth opportunities. FPT’s IoT capabilities encompass a comprehensive range of services designed to address diverse industry needs, from smart homes and healthcare to logistics and manufacturing. With over 3,000 IoT engineers and a portfolio of more than 500 projects, FPT delivers end-to-end IoT solutions, including hardware desig
Analyze Contracts Like a Lawyer - Wordsmith’s First Pass Unlocks Legal Insight for Everyone8.11.2024 00:54:00 EET | Press release
“Contracts often hold up business because legal teams are stretched too thin,” said Ross McNairn, CEO of Wordsmith. “First Pass allows anyone from the legal, commercial or other teams to quickly identify risks and key terms, helping move things forward.” This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20241108164624/en/ Wordsmith's First Pass lets you review contracts in minutes, not hours. (Graphic: Business Wire) This is a glimpse at the future of legal AI agents. Taking a very specific task end-to-end and making it trivial for anyone to trigger. Try It for Free Users can access First Pass for free by creating an account at wordsmith.ai and then uploading the relevant agreement to the web, or simply email standard agreements—like NDAs—to nda@wordsmith.ai. Over the coming weeks, Wordsmith will be expanding this to many other agreement types. End-to-End AI Analysis—More Than Just Contracting What makes First Pass revolutionary
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom