Xz is a tool tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.
Xz is a tool tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed March 27, 2026; most recent activity August 5, 2026.
Debian has released updates addressing critical vulnerabilities in p7zip and 7zip, which could allow remote code execution. The vulnerabilities include CVE-2026-14266, a heap-based buffer overflow in XZ decompression,…
Red Hat has issued a critical security alert regarding a sophisticated supply chain attack affecting the xz compression utility. Researchers found malicious code embedded in recent versions of the xz libraries, tracked…
Xz is a tool tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.
The most recent intelligence report mentioning Xz on ThreatCluster is dated August 5, 2026. Activity was first observed March 27, 2026, giving a tracked span from then to August 5, 2026.
Across ThreatCluster reporting, Xz most frequently co-occurs with Malware, Remote Code Execution, Supply Chain Attack, Debian, CVE-2024-3094, among 12 tracked related entities.
The most significant recent cluster is “Debian LTS p7zip and 7zip Vulnerabilities Lead to Remote Code Execution Risks” (2 articles · Updated August 5, 2026). Xz appears across 2 threat clusters in total, listed above with sources.
Xz appears in 3 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.