Debian issued DSA 5649-1 for xz-utils, publishing a security update for the compression package in supported distributions. The advisory identified a vulnerability in xz-utils and directed users to install updated packages through Debian security channels to remediate the issue.
Later disclosures about a backdoor in certain XZ releases prompted broader scrutiny across Unix-like systems, but FreeBSD said it was not affected by the malicious code found in those upstream releases. Together, the notices show parallel security activity around xz-utils: Debian distributing patched packages for its own tracked flaw, and FreeBSD confirming its exposure did not include the subsequently disclosed upstream backdoored versions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The upstream XZ Utils project published review notes related to the xz backdoor incident. The publication represents a later official technical update from the project following the March disclosure.
FreeBSD published a security notice about the disclosed backdoor in xz releases and said FreeBSD was not affected. This reflects the public disclosure and vendor response captured in the reference.
Debian published security advisory DSA 5649-1 for xz-utils, announcing a security update for the package. This is the earliest concrete event referenced in the provided materials.
A Debian bug report for xz-utils was filed noting that a new upstream version was available. This reflects a distinct Debian package maintenance event shortly before the public xz backdoor disclosure wave.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
binarly.io
Open sourcetukaani.org
Open sourceopenwall.com
Open sourcelists.freebsd.org
Open sourcebugs.debian.org
Open sourceweb.archive.org
Open sourcelists.debian.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.