{
  "type": "bundle",
  "id": "bundle--5c109c01-1b48-5b1c-81d7-c33553da2e92",
  "objects": [
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--5346c5c2-1f5b-57c3-8e6f-32d05ed1ecac",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:596903c9-f7ea-5cbe-b0dd-bd8430e10f78",
      "name": "xz Utils backdoor discovery"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--5b07ea8c-cb21-5150-86c5-da71f1675349",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:b4e83ee2-7181-583d-b115-b086117ca15b",
      "name": "xz Utils backdoor discovery"
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--5f29d1ca-6b22-508e-8214-cef7721161a3",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:c61532ab-11d7-55b6-b8c1-08666149dd0e",
      "confidence": 83,
      "external_references": [
        {
          "source_name": "oss-security",
          "url": "https://www.openwall.com/lists/oss-security/2024/03/29/4",
          "external_id": "cit:9544eb99-dbc0-53d8-8aa1-342658ba3692",
          "description": "- Products - Openwall GNU/*/Linux server OS - Linux Kernel Runtime Guard - John the Ripper password cracker - Free & Open Source for any platform - in the cloud - Pro for Linux - Pro for macOS - Wordlists for password cracking - passwdqc policy enforcement - Free & Open Source for Unix - Pro for Windows (Active Directory) - yescrypt KDF & password hashing - yespower Proof-of-Work (PoW) - crypt_blowfish password hashing - phpass ditto in PHP - tcb better password shadowing - Pluggable Authentication Modules - scanlogd port scan detector - popa3d tiny POP3 daemon - blists web interface to mailing lists - msulogin single user mode login - php_mt_seed mt_rand() cracker - Services - Publications - Articles - Presentations - Resources - Mailing lists - Community wiki - Source code repositories (GitHub) - File archive & mirrors - How to verify digital signatures - OVE IDs - What's new",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:1a117fd0cac898fcad8e62698e3849c8644cb281cd4a2a1850b4daabb4e13bfb"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Caught before widescale exploitation by a single engineer noticing a performance anomaly."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--6025ce78-d03c-529a-837f-ff582a508f82",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:3430bfb9-b7c8-5790-b318-c84b7e2b2d95",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "oss-security",
          "url": "https://www.openwall.com/lists/oss-security/2024/03/29/4",
          "external_id": "cit:d05f1257-ca10-5f35-898c-b077688c037a",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:1a117fd0cac898fcad8e62698e3849c8644cb281cd4a2a1850b4daabb4e13bfb"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the xz utils backdoor discovery involving xz Utils backdoor."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--8ebfd804-c3f7-54f2-8821-bce3132bb7f6",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:c21df046-2ebf-5694-8f08-50b5c63cbd79",
      "confidence": 83,
      "external_references": [
        {
          "source_name": "oss-security",
          "url": "https://www.openwall.com/lists/oss-security/2024/03/29/4",
          "external_id": "cit:5cfb8b21-49b2-5d15-b66c-94c9fd4fb0bf",
          "description": "Message-ID: <20240329155126.kjjfduxw2yrlxgzm@awork3.anarazel.de> Date: Fri, 29 Mar 2024 08:51:26 -0700 From: Andres Freund <andres@...razel.de> To: oss-security@...ts.openwall.com Subject: backdoor in upstream xz/liblzma leading to ssh server compromise",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:1a117fd0cac898fcad8e62698e3849c8644cb281cd4a2a1850b4daabb4e13bfb"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Multi-year social engineering of a maintainer to insert an SSH backdoor into a core Linux compression library."
      }
    }
  ]
}
