Business Wire

Binarly Releases Free Detection Tool for XZ Backdoor

Share

Binarly, provider of an industry leading AI-powered firmware and software supply chain security platform, has created and released a free scanning tool to help defenders spot signs of the dangerous XZ backdoor (CVE-2024-3094).

The XZ.fail detection tool was released less than 24 hours after the discovery of a backdoor in the open-source XZ Utils, which provides lossless data compression on virtually all Unix-like operating systems, including Linux. (See CISA advisory).

According to Binarly chief executive Alex Matrosov, the tool includes generic IFUNC implantation detection with close to zero false-positives, showcasing the company’s binary code intelligence engine in action.

“This detection is based on behavioral analysis and can detect any invariants automatically if a similar backdoor is implanted somewhere else,” Matrosov added.

“Such a complex and professionally designed implantation framework is not developed for a one-shot operation. It could already be deployed elsewhere or partially reused in other operations. That’s exactly why we started focusing on more generic detection for this complex backdoor,” Matrosov added.

For those seeking more comprehensive detection and remediation strategies, the Binarly Transparency Platform offers an in-depth solution. With XZ detection capabilities deployed, the platform facilitates easy identification of malicious activities at scale, enabling users to take prompt and effective action to safeguard their software supply chains.

The XZ backdoor came to light on March 29, 2024, when a thread was published on Openwall's oss-security mailing list by Andres Freund, revealing a potential compromise in the open-source code.

For more information read our research article and access the free XZ backdoor scanner at XZ.fail.

About Binarly:

Binarly is a global firmware and software supply chain security company founded in 2021. The company’s flagship Binarly Transparency Platform is an enterprise-class, AI-powered solution used by device manufacturers, OEMs, IBVs and product security teams to identify known and unknown vulnerabilities, misconfigurations and signs of malicious code implantation. Binarly’s validated remediation playbooks have significantly reduced the cost and time to respond to security exposures. Based in Los Angeles, California, Binarly brings decades of research and program analysis expertise to build solutions to protect businesses, critical infrastructure, and consumers around the world.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

media@binarly.io
818.351.9637

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Binarly Launches Next-Generation Transparency Platform to Elevate Software Supply Chain Security23.4.2024 19:00:00 EEST | Press release

Binarly, provider of an industry leading AI-powered firmware and software supply chain security platform, announces the release of the Binarly Transparency Platform v2.0 with features for continuous post-build compliance, visibility into the security posture of IoT and XIoT devices, and the ability to identify malicious behavior and hidden backdoors within binaries based on their behavior. Learn more here. Based on the company’s proprietary Binary Risk Intelligence technology, the new innovations underscore Binarly's commitment to pioneering solutions that enhance transparency and security across firmware and software ecosystems. Founded in 2021 with a vision to increase transparency in the software supply chain through advanced program analysis, Binarly’s flagship platform has automated the discovery of hundreds of new vulnerabilities, preemptively addressing our customers' security risks before they could escalate. Binarly’s patented approach, powered by modern AI, has proactively ne

Making History: ASPIRE to Launch Inaugural ‘Abu Dhabi Autonomous Racing League’ Redefining Future of Extreme Sport on April 2723.4.2024 18:54:00 EEST | Press release

On Saturday, April 27th, Abu Dhabi will host a groundbreaking event, welcoming 10,000 spectators to witness the inaugural ASPIRE Abu Dhabi Autonomous Racing League (A2RL) at the iconic Yas Marina Circuit. This brand-new autonomous racing competition marks a significant milestone in motorsport history, billed as the largest league of its kind globally. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240423980323/en/ Making History: ASPIRE to Launch Inaugural ‘Abu Dhabi Autonomous Racing League’ Redefining Future of Extreme Sport on April 27 (Photo: AETOSWire) Eight teams will compete: Code19 Racing (one of the first independent autonomous racing entity from the USA), Constructor University (based in Germany and Switzerland), Fly Eagle (representing Beijing Institute of Technology from China and Khalifa University from the UAE), HUMDA Lab (a member of the Széchenyi István University Group from Hungary), KINETIZ (a collaboration

DataXstream Expands into Nordic Region with Successful Go Live for Martin & Servera23.4.2024 16:07:00 EEST | Press release

DataXstream LLC, an SAP solution provider focused on order management and point of sale for sales and distribution, today announced it is expanding into the Nordic region after a successful implementation of its OMS+ platform across two key business units for the Martin & Servera group, Sweden’s leading restaurant and catering distributor that specializes in the needs of the restaurant industry. Learn more about DataXstream OMS+ here. Martin & Servera is a group of companies based in Stockholm who was faced with the challenge of managing multiple ERP systems that were facing end of life, so they decided to consolidate onto a single instance of SAP S/4 HANA for all their business units. As part of this migration, Martin & Servera turned to DataXstream’s OMS+ cross-channel order management platform to help them enable faster order entry and streamline their sales and order processes between all companies within their organization. Working with DataXstream’s LATAM delivery team, Kötthalle

Autel Energy’s Global ESG Launch Is A Success: Around 5,000 Trees Planted In EVergreen's Inaugural Tree Planting Initiative23.4.2024 16:00:00 EEST | Press release

Autel Energy, a leading provider of electric vehicle (EV) charging solutions and services, proudly announces the successful conclusion of its first EVergreen Global Tree Planting Initiative, which saw hundreds of participants around the globe plant an estimated 5,000 trees in the initial phase. This activity offsets an estimated 2,190,000 kilograms of carbon emissions (CO2), and emphasizes Autel Energy's and partners' commitment to their ESG goals towards a sustainable tomorrow. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240423142946/en/ Autel Energy’s Global ESG Launch A Success (Graphic: Business Wire) Partner Experience and NGO Feedback Reflecting on the Initiative, one partner remarked, “We show the world we are not only talking about a better world and clean energy, but we are really taking steps by putting shovels in the ground.” The non-governmental organizations (NGO) involved expressed sincere gratitude for the

EIG’s MidOcean Energy Completes Acquisition of 20 Percent Stake in Peru LNG23.4.2024 15:00:00 EEST | Press release

MidOcean Energy (“MidOcean” or the “Company”), a liquefied natural gas (LNG) company formed and managed by EIG, a leading institutional investor in the global energy and infrastructure sectors, today announced the completion of its previously announced agreement to acquire SK earthon’s (“SK”) 20 percent interest in Peru LNG (“PLNG”), owner and operator of the first LNG export facility in South America. PLNG’s assets comprise a natural gas liquefaction plant with 4.45 mmtpa processing capacity, a fully-owned 408km-long pipeline with 1,290 mmcf/d capacity, two 130,000 m3 storage tanks, a fully-owned 1.4 km-long marine terminal and a truck loading facility with capacity of up to 19.2 mmcf/d. PLNG, operated by Hunt Oil Company, is one of only two LNG production facilities in Latin America, located in Pampa Melchorita, 170km south of Lima. De la Rey Venter, MidOcean Energy’s CEO, said, “The completion of this investment is an important milestone in our efforts to create a global, diversifie

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
HiddenA line styled icon from Orion Icon Library.Eye