Richardcyoung.com

  • Home
  • Debbie Young
  • Jimmy Buffett
  • Key West
  • Your Survival Guy
  • How We Are Different
  • Paris
  • About Us
    • Foundation Principles
    • Contributors
  • Investing
    • You’ve Read The Last Issue of Intelligence Report, Now What?
  • The Swiss Way
  • My Rifles
  • Dividends and Compounding
  • Your Security
  • Dick Young
  • Dick’s R&B Top 100
  • Liberty & Freedom Map
  • Bank Credit & Money
  • Your Survival Guy’s Super States
  • NNT & Cholesterol
  • Your Health
  • Ron Paul
  • US Treasury Yield Curve: My Favorite Investor Tool
  • Anti-Gun Control
  • Anti-Digital Currency
  • Joel Salatin & Alfie Oakes
  • World Gold Mine Production
  • Fidelity & Wellington Since 1971
  • Hillsdale College
  • Babson College
  • Contact Us

World Narrowly Escaped MASSIVE Cyber Attack

April 8, 2024 By The Editors

By solarseven @ Shutterstock.com

A cyberattack on servers across the world was narrowly averted by a German software developer working for Microsoft. Raphael Satter reports for Reuters:

German software developer Andres Freund was running some detailed performance tests last month when he noticed odd behavior in a little known program. What he found when he investigated has sent shudders across the software world and drawn attention from tech executives and government officials.

Freund, who works for Microsoft (MSFT.O), opens new tab out of San Francisco, discovered that the latest version of the open source software program XZ Utils had been deliberately sabotaged by one of its developers, a move that could have carved out a secret door to millions of servers across the internet.

Security experts say it’s only because Freund spotted the change before the latest version of XZ had been widely deployed that the world was spared a digital security crisis.

“We really dodged a bullet,” said Satnam Narang, a security researcher with Tenable who has been tracking the fallout from the find. “It is one of those moments where we have to wipe our brow and say, ‘We were really lucky with this one.’”

The near-miss has refocused attention on the safety of open source software – free, often volunteer-maintained programs whose transparency and flexibility mean they serve as the foundation for the internet economy.

Many such projects depend on a tiny circle of unpaid volunteers fighting to get out from under a pile of demands for fixes and upgrades.

XZ, a suite of file compression tools packaged into distributions of the Linux operating system, was long maintained by a single author, Lasse Collin.

In recent years, he appeared to be under strain.

In a message posted to a public mailing list, opens new tab in June 2022, Collin said he was dealing with “longterm mental health issues” and hinted that he working privately with a new developer named Jia Tan and that “perhaps he will have a bigger role in the future.”

Update logs available through the open source software site Github show that Tan’s role quickly expanded. By 2023 the logs show Tan was merging his code into XZ, a sign that he had won a trusted role in the project.

But cybersecurity experts who’ve scoured the logs say that Tan was masquerading as a helpful volunteer. Over the next few months, they say, Tan introduced a nearly invisible backdoor into XZ.

Collin didn’t return messages seeking comment and said on his website that he would not respond to reporters until he understood the situation well enough to do so.

Tan did not return messages sent to his Gmail account. Reuters has been unable to ascertain who Tan is, where he is, or who he was working for, but many of those who’ve examined his updates believe Tan is a pseudonym for an expert hacker or group of hackers — likely one working on behalf of a powerful intelligence service.

“This is not kindergarten stuff,” said Omkhar Arasaratnam, the general manager of the Open Source Security Foundation, which works to defend projects like XZ. “This is incredibly sophisticated.”

‘WE LUCKED OUT’

Tan could easily have gotten away with it had it not been for Freund, the Microsoft developer, whose curiosity was piqued when he noticed the latest version of XZ intermittently using an unexpected amount of processing power on the system he was testing.

Read more here.

If you’re willing to fight for Main Street America, click here to sign up for the Richardcyoung.com free weekly email.

Related Posts

  • Cyber Attack on America’s Critical Infrastructure?
  • DHS Monitoring New Cyber Attack that Rivals WannaCry Ransomware in Scope
  • MAP: Victims of Chinese Cyber-espionage
  • Are American Utilities Already Compromised by Cyber Attack?
  • Author
  • Recent Posts
The Editors
The Editors
The Editors
Latest posts by The Editors (see all)
  • Is There a Case for Defending Taiwan? - May 19, 2025
  • Donald Trump ROASTS Bruce Springsteen - May 19, 2025
  • Russian Black Sea Fleet Decimated - May 6, 2025

Dick Young’s Must Reads

  • Investing Habits of the Fairly Wealthy: #8 “Safety”
  • Are You Prepared to Run Out of Water?
  • What’s the Best Survival Currency?
  • Sen. Hawley Makes the Case Against U.S.-China Relationship
  • The Masters of the Universe Align Themselves with CHINA Using YOUR Money?
  • How about Hiring Erik Prince to Crush the Drug Cartels?
  • Democracy: The Most Dangerous and Insidious Effect of Majority Rule.
  • Rich Grandchild, Poor Grandchild
  • DIGITAL DOLLAR DOOMSDAY: The Wall Street Journal Is NOT Going to Tell You This
  • Conflict Between Democratic Sovereignty and Transnational Progressivism (Globalism)

Compensation was paid to utilize rankings. Click here to read full disclosure.

RSS Youngresearch.com

  • Congratulations, You’re Retired: Now What? Part 6
  • U.S. Billionaires Target Congo’s Cobalt in Bid to Secure Energy Future
  • China Dominates Battery Supply Chain: From Mine to Market
  • Shale Plateau Looms as Global LNG Market Set to Double
  • Congratulations, You Graduated into Retirement. Now What? #5
  • World’s Leading EV Motor Factory to Supply Ferrari and Lamborghini
  • Hackers Target Coinbase: DOJ Opens Investigation into Data Breach
  • Stargate Project Breaks Ground in Texas
  • Retirement #4: How Do You Feel? How Will You Feel?
  • Nippon’s Push for U.S. Steel Approval Faces Uncertainty

RSS Yoursurvivalguy.com

  • Your Retirement Life: Top of the Rock
  • Congratulations, You’re Retired: Now What? Part 6
  • Investing Habits of the Fairly Wealthy: #10 Powerball
  • Is America Poised for Next Gen Nuclear Power?
  • Congratulations, You Graduated into Retirement. Now What? #5
  • Big Blue Blob Cities Drive Residents (and Money) Away
  • Don’t Forget the Laffer Curve
  • Retirement #4: How Do You Feel? How Will You Feel?
  • Don’t Over SALT the Big Beautiful Bill
  • Two Americas: The Assassination Attempt on Trump

US Treasury Yield Curve: My Favorite Investor Tool

My Key West Garden Office

Your Retirement Life: Traveling the Efficient Frontier

Live a Long Life

Your Survival Guy’s Mt. Rushmore of Investing Legends

“Then One Day the Grandfather was Gone”

Copyright © 2025 | Terms & Conditions | About Us | Dick Young | Archives