Security Researchers Find XZ Utils Backdoored Debian Images on Docker Hub

12 6581 2 8/16/2025, 3:25:12 PM news.itsfoss.com ↗

Comments (2)

notherhack · 7h ago
"The Debian development team put it like this: So, given the wafer thin vectors of attack here, the extreme age of the images in question, and the fact that even at the time that they were fresh, they were images that shouldn't be used in production anyhow (Debian's "development" repositories), we've opted to leave them in place.

Binarly kind of agrees ... "

daymanstep · 5h ago
Good to know that the Debian team's attitude towards security has not materially changed since the OpenSSL fiasco.