On March 29, a software engineer at Microsoft discovered and disclosed a supply chain attack against the popular Linux decompression utility XZ Utils. After analysis, researchers confirmed a rogue developer had inserted malicious code into the 5.6.0 and 5.6.1 releases of XZ Utils. This malicious code could allow an adversary with a carefully crafted SSH public key to execute arbitrary code with SYSTEM permissions on affected Linux-based systems.
Affected
No WatchGuard products use the affected versions of XZ Utils