-

Binarly Releases Free Detection Tool for XZ Backdoor

LOS ANGELES--(BUSINESS WIRE)--Binarly, provider of an industry leading AI-powered firmware and software supply chain security platform, has created and released a free scanning tool to help defenders spot signs of the dangerous XZ backdoor (CVE-2024-3094).

The XZ.fail detection tool was released less than 24 hours after the discovery of a backdoor in the open-source XZ Utils, which provides lossless data compression on virtually all Unix-like operating systems, including Linux. (See CISA advisory).

According to Binarly chief executive Alex Matrosov, the tool includes generic IFUNC implantation detection with close to zero false-positives, showcasing the company’s binary code intelligence engine in action.

“This detection is based on behavioral analysis and can detect any invariants automatically if a similar backdoor is implanted somewhere else,” Matrosov added.

“Such a complex and professionally designed implantation framework is not developed for a one-shot operation. It could already be deployed elsewhere or partially reused in other operations. That’s exactly why we started focusing on more generic detection for this complex backdoor,” Matrosov added.

For those seeking more comprehensive detection and remediation strategies, the Binarly Transparency Platform offers an in-depth solution. With XZ detection capabilities deployed, the platform facilitates easy identification of malicious activities at scale, enabling users to take prompt and effective action to safeguard their software supply chains.

The XZ backdoor came to light on March 29, 2024, when a thread was published on Openwall's oss-security mailing list by Andres Freund, revealing a potential compromise in the open-source code.

For more information read our research article and access the free XZ backdoor scanner at XZ.fail.

About Binarly:

Binarly is a global firmware and software supply chain security company founded in 2021. The company’s flagship Binarly Transparency Platform is an enterprise-class, AI-powered solution used by device manufacturers, OEMs, IBVs and product security teams to identify known and unknown vulnerabilities, misconfigurations and signs of malicious code implantation. Binarly’s validated remediation playbooks have significantly reduced the cost and time to respond to security exposures. Based in Los Angeles, California, Binarly brings decades of research and program analysis expertise to build solutions to protect businesses, critical infrastructure, and consumers around the world.

Contacts

media@binarly.io
818.351.9637

More News From Binarly

Binarly Secures Patent for Machine Learning Technique to Optimize Large-Scale Binary Analysis

SANTA MONICA, Calif.--(BUSINESS WIRE)--Binarly, a leading innovator in software supply chain security, today announced that it has been granted U.S. Patent No. US 12,236,262 B1 for its groundbreaking "Machine Learning Technique for Efficiently Scheduling Tasks for Large-Scale Analysis of Binary Executables." The patent, issued on February 25, 2025, covers a novel method for analyzing binary software efficiently by leveraging machine learning to predict peak memory usage and dynamically allocate...

Binarly Expands Platform to Enable Post-Quantum Compliance Readiness

SANTA MONICA, Calif.--(BUSINESS WIRE)--Binarly, a leader in firmware and software supply chain security, today announced the release of its flagship Binarly Transparency Platform v2.7, a major update that immediately enables corporate defenders to prepare for a mandatory transition to Post-Quantum Cryptography (PQC) standards. As quantum computing advances, the National Institute of Standards and Technology (NIST) has issued fresh guidance on Post-Quantum Cryptography (PQC), underscoring the ur...

Binarly Secures Patent for Cutting-Edge CBOM Generation From Binaries

SANTA MONICA, Calif.--(BUSINESS WIRE)--Binarly, a leader in firmware and software supply chain security, today announced it has been awarded U.S. Patent No. 12153686, recognizing its invention of an innovative process for generating Cryptography Bills of Materials (CBOM) from binary executables. The invention underscores Binarly’s commitment to deep technical innovation in addressing supply chain security risks across modern computing. By combining program analysis and machine learning techniqu...
Back to Newsroom