Skip to content

XZ Vulnerability

You drink tap water every day, right? Do you know who invented the filtering mechanism that makes water pure and clean?… Well, do you actually care?

Do you know that this mechanism is exactly the same in all the taps of all the houses of any country? Do you know that this specialized piece is the work of an engineer who does it just because? Can you imagine what could happen if this person had a bad day?

Let’s talk about the XZ Utils library and why it is not a good idea to depend on a single supplier and make them angry. Let’s talk about the XZ Utils library and its latest developer, Jia Tan.

Yes, open source software can offer a series of benefits in terms of prices (because it is actually “free”), transparency, collaboration and adaptability, but it also entails risks regarding the security and excessive trust that we place as users.

What happened?

On March 29, Red Hat, Inc. disclosed the vulnerability CVE-2024-3094, with a score of 10 on the Common Vulnerability Scoring System scale, and, therefore, a critical vulnerability, which compromised the affected SSH servers.

This vulnerability affected the XZ Utils package, which is a set of software tools that provide file compression and decompression using the LZMA/LZMA2 algorithm, and is included in major Linux distributions. Had it not been discovered, it could have been very serious, since it was a malicious backdoor code, which would grant unauthorized remote access to the affected systems through SSH.

The vulnerability began in version 5.6.0 of XZ, and would also affect version 5.6.1.

During the liblzma building process it would retrieve an existing camouflaged test file in the source code, later used to modify specific functions in the liblzma code. The result is a modified liblzma library, which can be used by any software linked to it, intercepting and modifying data interaction with the library.

This process of implementing a backdoor in XZ is the final part of a campaign that was extended over 2 years of operations, mainly of the HUMNIT type (human intelligence) by the user Jia Tan.

User Jia Tan created his Github account in 2021, making their first commit to the XZ repository on February 6, 2022. More recently, on February 16, 2024, a malicious file would be added under the name of “build-to-host.m4” in .gitignore, later incorporated together with the launch of the package, to finally on March 9, 2024 incorporate the hidden backdoor in two test files:

  • tests/files/bad-3-corrupt_lzma2.xz
  • tests/files/good-large_compressed.lzma

How was it detected?

The main person in charge of locating this issue is Andres Freund.

It is one of the most important software engineers at Microsoft, who was performing micro-benchmarking tasks. During testing, they noticed that sshd processes were using an unusual amount of CPU even though the sessions were not established.

After profiling sshd, they saw a lot of CPU time in the liblzma library. This in turn reminded them of a recent bizarre complaint from Valgrind about automated testing in PostgreSQL. This behavior could have been overlooked and not discovered, leading to a large security breach on Debian/Ubuntu SSH servers.

As Andres Freund himself claims, a series of coincidences were required to be able to find this vulnerability, it was a matter of luck to have found it.

What set off Freund’s alarms was a small delay of only 0.5 sec in the ssh connections, which although it seems very little, was what led him to investigate further and find the problem and the potential chaos that it may have generated.

This underscores the importance of monitoring software engineering and security practices. The good news is that, the vulnerability has been found in very early releases of the software, so in the real world it has had virtually no effect, thanks to the quick detection of this malicious code. But it makes us think about what could have happened, if it had not been detected in time. It is not the first nor will be the last. The advantage of Open Source is that this has been made public and the impact can be evaluated, in other cases where there is no such transparency, the impact can be more difficult to evaluate and therefore, remediation.

Reflection

After what happened, we are in the right position to highlight both positive and negative points related to the use of open source.

As positive points we can find transparency and collaboration between developers from all over the world. Having a watchful community, in charge of detecting and reporting possible security threats, and have flexibility and adaptability, since the nature of open source allows adapting and modifying the software according to specific needs.

As for the disadvantages, we find the vulnerability to malicious attacks, as is the case with the action of developers with malicious intentions. Users trust that the software does not contain malicious code, which can lead to a false sense of security. In addition, due to the number of existing contributions and the complexity of the software itself, it can be said that it is very difficult to exhaustively verify the code.

If we add to all of that the existence of libraries maintained by one person or a very small group of people, the risk of single point of failure is greater. In this case, that need or benefit of having more people contributing is what caused the problem.

In conclusion, while open source software can offer us a number of benefits in terms of transparency, collaboration and adaptability, it can also present disadvantages or challenges in terms of the security and trust we place in it as users.ing.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

Cybersecurity firm ESET welcomes new member of the Board

BRATISLAVA — March 27, 2024 —  ESET, a global leader in digital security for more than 30 years, today announces that Jan Hrubý has joined the company’s Board of Shareholders, effective March 11, 2024, representing the joint ownership interests of himself and sister Elena Hrubá. Mr. Hrubý takes the seat after his father ESET co-founder Rudolf Hrubý who sadly passed away in December 2023. 

“We warmly welcome Jan to the ESET Board of Shareholders at an exciting time for the company,” said Peter Paško, Chair of the Board. “As consumers, businesses and governments alike are increasingly reliant on security solutions to enable them to focus on their own progress and innovation, ESET continues to expand its offering accordingly, with growth expected for years to come.”

ESET, a privately held company, is guided by the Board of Shareholders which is comprised of the company’s owners: Miroslav Trnka, Peter Paško, Maros Grund, Richard Marko, Anton Zajac and, now, Jan Hrubý and Elena Hrubá.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET has been recognized as a Top Player in Radicati Market Quadrant for the fifth consecutive year

BRATISLAVA, Slovakia — March 27, 2024 —  ESET, a global leader in digital security, has been named a Top Player in Radicati´s APT Protection Market Quadrant 2024, covering the advanced persistent threat (APT) protection segment of the security market. 

As stated in the Radicati report, which illustrates how individual vendors fit within specific technology markets at any given point in time, ESET is ranked among the “current market leaders with products that offer both breadth and depth of functionality, as well as possess a solid vision for the future. Top Players shape the market with their technology and strategic vision.”

Among the most appreciated of ESET´s key strengths is the unified single-click security management platform ESET PROTECT, which together with ESET Inspect delivers extended detection and response (XDR) with granular visibility, risk assessment, incident response, investigation, and remediation. The platform is available for deployment either in the cloud or on-premises, and it supports all major operating systems, such as Windows, macOS and Linux. The report further highlighted that ESET´s solutions offer multilanguage support and a large set of localized versions. Another key area that has contributed to ESET´s success is the partnership with Intel, which combines ESET Endpoint Security solutions with Intel® TDT as an additional source of threat telemetry to assist in the detection of threats that use advanced evasion techniques, such as zero-day variants, binary obfuscation, cloaking in a virtual machine, and fileless attacks.

“We are excited to be ranked as a Top Player by Radicati in the APT Protection Market Quadrant for the fifth consecutive time. With this milestone, ESET reaffirms its dedication to the development of cutting-edge security software and our commitment to innovation. We are proud to be recognized for our efforts in making technology safer for all technology users,” said Juraj Malcho, ESET’s Chief Technology Officer.

APT protection is defined as a “set of integrated solutions for the detection, prevention and possible remediation of zero-day threats and persistent malicious attacks.” Radicati, the renowned market research firm, positions vendors in the quadrant according to two criteria: functionality assessed based on the breadth and depth of features of each vendor’s solution and strategic vision, which refers to the vendor’s strategic direction.

To read more about the 2024 Radicati APT Protection Market Quadrant, please click here, and to find out more about ESET PROTECT Elite, visit our website.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

When Windows 10 support ends, here’s what you need to do

When Windows 10 support ends, here’s what you need to do

Microsoft recently announced the end of support for Windows 10, and users are encouraged to make the transition to Windows 11 sooner rather than later.

From the official statement on the Windows 10 product page, “Windows 10 will reach the end of support on October 14, 2025. The current version, 22H2, will be the final version of Windows 10, and all editions will remain in support with monthly security update releases through that date.”

After October 2025, however, computers running Windows 10 will become increasingly vulnerable to security threats and may encounter compatibility issues with new software and hardware releases.

Naturally, if you’re an IT admin or just a long-time Windows user, developing a plan of action prior to Windows 10’s official end of life is a priority. That plan could include upgrading your device(s), finding a virtualization solution that makes things relatively painless, or some combination of the above.

Read on to learn more — and if you’re ready to get started, get your free trial of Parallels® RAS or Parallels DaaS now.

Transitioning from Windows 10 to Windows 11 successfully

Windows 11 is the most secure version of Windows ever created, leveraging hardware security to complement software defenses against modern cybersecurity threats. It is also faster, enhancing productivity with an improved user interface, tighter integration of Microsoft Teams across apps, and snap layouts.

However, this push towards Windows 11 comes with challenges.

It could result in millions of perfectly functional PCs being discarded because Windows 11 mandates the presence of a Trusted Platform Module (TPM) chip, potentially rendering many devices obsolete.

This is a relatively new component in modern PCs and laptops, and as a result, there are millions of devices that will be left unused or thrown out as they do not have the TPM and, therefore, the Windows 11 OS cannot be installed.

Newer enterprise and consumer devices will meet the criteria. Starting in 2016, Microsoft mandated that OEMs integrate TPM 2.0 into devices for Windows 10 and Windows Server 2016 to obtain Microsoft’s endorsement.

Older devices lacking TPM 2.0 or equipped solely with TPM 1.2 (which cannot always be upgraded), will fall short of Windows 11’s minimum system requirements.

This could force users to replace their devices prior to Windows EoL, potentially resulting in a substantial increase in electronic waste and necessitating businesses to reinvest or repurchase hardware. And with Windows 10 at nearly 70% usage, that’s potentially a lot of devices!

Before taking on the significant expense of replacing your fleet of laptops and PCs, why not explore the option of virtualizing your IT systems?

Virtualization offers the opportunity to extend the lifespan of these devices while unlocking a range of benefits and ultimately increasing security —one of the main improvements on Windows 11.

Extending the life of your Windows 10 devices post-EOL with virtualization

Virtualization technology has proven invaluable for many enterprise companies that manage extensive fleets of workforce devices. It streamlines and automates device management at scale.

A virtual migration to Windows 11 can also be a cost-effective choice since costs for virtual PCs start at $110 USD per user annually and go up to $1,600 USD for high-end virtual PCs. On the contrary, new hardware that’s Windows 11-compatible is rarely less than $1,000 USD per user.

Instead of upgrading to new Windows 11 devices, organizations can maximize their existing hardware by virtualizing their IT environment. This allows users to run Windows 11 on a virtual machine on an older device.

How to upgrade your virtual machines from Windows 10 to Windows 11

You may already use virtual machines for Windows applications or desktops. If that’s the case, you can migrate those to Windows by following these steps.

Note that a virtual TPM chip is required for upgrading to Windows 11, and you need to ensure that your virtual machines meet the system requirements for Windows 11.

Once you are sure that your virtual machines meet the requirements, you can follow the instructions in this Knowledge Base article to upgrade.

The Parallels ecosystem of virtualization solutions

Here at Parallels, we have a host of application and desktop delivery solutions that can be tailored to your needs and requirements, whether you are upgrading to Windows 11, extending the life of legacy Windows 10 devices, or solving a different challenge.

Parallels® RAS

Parallels RAS is a flexible virtual application and desktop delivery solution that empowers organizations of all sizes to work securely from anywhere, on any device.

The platform offers an agile, cloud-ready foundation and end-to-end security, controlled by a centralized management console. Leverage on-premises, hybrid, or public cloud deployments and integrate with existing technologies like Azure Virtual Desktop and Amazon EC2.

With Parallels RAS, you gain the flexibility, scalability, and IT agility to quickly adapt to changing business needs. Best of all, Parallels RAS offers a single, full-featured licensing model that includes 24/7 support and access to free training.

Parallels DaaS

Parallels DaaS is a cloud-based app and desktop delivery solution that offers flexible and secure access to critical data and apps from any internet-connected device.

This Desktop-as-a-Service offering uses a unique, cloud-native architecture that isolates the management infrastructure (which is managed by Parallels) and leaves critical business data where it belongs, in the business environment. This dramatically improves security and offers incredible scalability.

For IT admins, Parallels DaaS simplifies the onboarding and management process with intuitive administration controls and real-time dashboards, allowing all types of businesses to deliver and use enterprise-grade IT solutions.

Desktop as a Service (DaaS) exemplifies the cloud option, where infrastructure is handled by the cloud provider, allowing IT managers to focus on aspects like VM provisioning, applications, and data management.

While on-premises virtualization emphasizes control and security, cloud solutions prioritize scalability, cost-effectiveness, and convenience through redundant infrastructure and flexible pricing models.

It is time to virtualize Windows 11?

Upgrading to Windows 11 via a virtualization solution means that organizations do not need to buy new PCs and laptops before the Windows 10 end-of-life.

Rather, businesses can recycle or extend their existing fleet of devices.

For example, if a company has decided to move to Windows 11 and refresh its fleet of endpoint devices, that company could face compatibility issues or other growing pains as its IT department adjusts existing apps and needs to adapt to the new OS. Virtualization can also help with this!

By decoupling the applications from the device — or virtualizing them — users can migrate to the latest OS (Windows 11, in this case) and enjoy their new devices without worrying about whether their essential applications will still work.

End users can access their applications via the Parallels Client while on their new device. This can accelerate the adoption of Windows 11 or other new operating systems among the workforce, as IT managers can upgrade their teams’ devices at their own pace, without being hindered by application compatibility concerns.

With virtualization, users can enjoy the same great security and user experience expected with a Windows 11 device, but instead of the operating system being installed “on-device,” it is virtualized and does not require the latest TPM chip.

Ready to get started with a virtualization solution? Get your full-featured trial of Parallels RAS and/or Parallels DaaS.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

Announcement on Atlas VPN

Atlas VPN, a valued member of the Nord Security family, has made the decision to conclude its services on April 24. 

Atlas VPN was established with the goal of offering secure, accessible, and user-friendly VPN services. Despite its unwavering dedication and the remarkable support from AtlasVPN’s community, the challenges posed by advancing technologies, a competitive market, and the rising costs of maintaining high-quality services have led to this difficult but necessary decision.

The conclusion of Atlas VPN’s journey marks a significant moment for both Atlas VPN and Nord Security. We extend our gratitude to the Atlas VPN team for their dedication to online privacy and security. Their efforts have made a lasting impact on their users and the cybersecurity community.

Recognizing the importance of continuous and secure online protection for Atlas VPN users, we are facilitating their smooth transition to NordVPN. NordVPN’s mission aligns closely with that of Atlas VPN, and we are excited to welcome Atlas users into the NordVPN family. We believe that through NordVPN, Atlas VPN users will experience enhanced online security, privacy, and freedom.

To the Atlas VPN community, we thank you for your trust, support, and for being part of an important mission to make the internet a safer place. As we transition to this next chapter with NordVPN, we are committed to providing you with exceptional service, ensuring the utmost security and privacy online.

Warmest regards,

The Nord Security Team

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.