9.5 CVE-2024-3094
XZ Utils Backdoor — CVE-2024-3094 Deep Dive
How a supply chain attacker spent two years building trust before planting a backdoor in a critical compression library.
Live CVE feed from NVD and CISA KEV, plus curated incident write-ups.
CVEs published in the last 48 hours, refreshed hourly.
Curated incident analyses and vulnerability deep dives.
How a supply chain attacker spent two years building trust before planting a backdoor in a critical compression library.
Two zero-day vulnerabilities in Ivanti Connect Secure allowed unauthenticated remote code execution before patches were available.