-

Binarly Releases Free Detection Tool for XZ Backdoor

LOS ANGELES--(BUSINESS WIRE)--Binarly, provider of an industry leading AI-powered firmware and software supply chain security platform, has created and released a free scanning tool to help defenders spot signs of the dangerous XZ backdoor (CVE-2024-3094).

The XZ.fail detection tool was released less than 24 hours after the discovery of a backdoor in the open-source XZ Utils, which provides lossless data compression on virtually all Unix-like operating systems, including Linux. (See CISA advisory).

According to Binarly chief executive Alex Matrosov, the tool includes generic IFUNC implantation detection with close to zero false-positives, showcasing the company’s binary code intelligence engine in action.

“This detection is based on behavioral analysis and can detect any invariants automatically if a similar backdoor is implanted somewhere else,” Matrosov added.

“Such a complex and professionally designed implantation framework is not developed for a one-shot operation. It could already be deployed elsewhere or partially reused in other operations. That’s exactly why we started focusing on more generic detection for this complex backdoor,” Matrosov added.

For those seeking more comprehensive detection and remediation strategies, the Binarly Transparency Platform offers an in-depth solution. With XZ detection capabilities deployed, the platform facilitates easy identification of malicious activities at scale, enabling users to take prompt and effective action to safeguard their software supply chains.

The XZ backdoor came to light on March 29, 2024, when a thread was published on Openwall's oss-security mailing list by Andres Freund, revealing a potential compromise in the open-source code.

For more information read our research article and access the free XZ backdoor scanner at XZ.fail.

About Binarly:

Binarly is a global firmware and software supply chain security company founded in 2021. The company’s flagship Binarly Transparency Platform is an enterprise-class, AI-powered solution used by device manufacturers, OEMs, IBVs and product security teams to identify known and unknown vulnerabilities, misconfigurations and signs of malicious code implantation. Binarly’s validated remediation playbooks have significantly reduced the cost and time to respond to security exposures. Based in Los Angeles, California, Binarly brings decades of research and program analysis expertise to build solutions to protect businesses, critical infrastructure, and consumers around the world.

Contacts

media@binarly.io
818.351.9637

More News From Binarly

Binarly Transparency Platform 3.5 Introduces Java Ecosystem Support, Enterprise-Scale YARA Integration, Smarter Automation

SANTA MONICA, Calif.--(BUSINESS WIRE)--Binarly, a leading provider of software supply chain security solutions, today released the Binarly Transparency Platform 3.5 with Java ecosystem support, full enterprise-grade YARA integration, and operational upgrades designed to meet the speed and scale of modern product security workflows. With this update, Binarly’s cryptographic algorithm identification engine now supports Java archives (JARs) and JVM bytecode, scanning both standalone and embedded f...

Binarly Names Rick Congdon Independent Board Member and Strategic Advisor; Appoints AppSec Leader Chris Eng as Strategic Advisor

SANTA MONICA, Calif.--(BUSINESS WIRE)--Binarly, the industry leader in software and firmware supply‑chain security, today announced Rick Congdon has joined the company as an Independent Board Member and Strategic Advisor. Congdon will provide expert guidance to steer Binarly’s global go-to-market and enterprise sales strategy. The company also appointed software security veteran Chris Eng as a Strategic Advisor focused on product vision and long-range roadmap. Congdon, a proven growth leader wh...

Binarly Partners with QuSecure to Accelerate Enterprise Post‑Quantum Readiness

SANTA MONICA, Calif.--(BUSINESS WIRE)--Binarly, the industry leader in software and firmware supply‑chain security, is announcing a strategic technology alliance with QuSecure, a provider of post‑quantum cryptography (PQC) and crypto‑agility solutions, to deliver the most comprehensive solution available for enterprises facing quantum-safe compliance deadlines. The integration combines Binarly’s deep‑binary cryptographic analysis with QuSecure’s QuProtect platform, giving defenders a single pan...
Back to Newsroom