The xz backdoor is, well, setting a fire under the entire Linux ecosystem... but I'm also so impressed with how it was set up: 2-yr maintainership, oss-fuzz, etc.
...and who knows how long it would've stayed undetected if the injected sshd code ran faster (<600ms)
Highlights: