The most important events of 2025 related to open projects

A final selection of the most significant and notable events of 2025 related to open projects and information security:

  • Conflicts:
    • Conflict over the domain putty.org;
    • Conflict between NixOS moderators and the board of directors;
    • Intention to exclude Bcachefs from the Linux kernel;
    • Python's refusal of a grant;
    • Automattic's withdrawal from WordPress development;
    • Protests from the Japanese Mozilla Support community;
    • The maintainer of libxml2 refused special treatment for vulnerability fixes;
    • Threat of a lawsuit from OBS Studio against Fedora;
    • Removal of maintainers from RubyGems.org and the creation of Gem Cooperative;
    • Departure of the leader of Asahi Linux;
    • Departure of the maintainer of Nouveau;
    • Departure of the maintainer of Dash to Panel.
  • Sanctions and bans:
    • F-Droid under threat of closure;
    • GitHub archived Organic Maps;
    • Google limited the Nextcloud Android application;
    • Microsoft C/C++ Extension blocked in VS Code forks;
    • Blocking Rockchip MPP for copying code from FFmpeg;
    • Blocking all users from the UK on the Haiku forum;
    • Blocking supporters of the WordPress fork;
    • Disabling uBlock Origin in the Chrome Web Store;
    • Mistaken removal of VSCode extensions;
    • Sanctions compliance in open source software.
  • Forks:
    • CoMaps — fork of Organic Maps;
    • libAdapta — fork of libAdwaita;
    • AMD’s composite server ACS, a fork of Weston;
    • X11Libre — fork of X.Org Server;
    • Zedless — fork of the Zed editor;
    • OpenVox — fork of Puppet.
  • Acquisitions, mergers, and joint projects:
    • The GitHub repository RubyGems has moved to the Ruby Core Team;
    • IBM acquires Confluent;
    • Microsoft takes over GitHub;
    • Qualcomm acquires Arduino;
    • Anthropic acquires Bun;
    • The game engine Nau Engine has been handed over to the community;
    • Acquisition of HashiCorp by IBM;
    • Support for projects on the Chromium engine.
  • Legal disputes:
    • Antitrust court on the fate of Chrome and Android;
    • Vizio's GPL violation;
    • AVM's LGPL violation;
    • Lawsuit concerning the legality of ad blockers.
  • Patents and copyrights:
    • Initiative to cancel JavaScript trademark;
    • Use of books for training AI models deemed fair use;
    • Rebranding of the Apache Foundation;
    • Renaming of the Varnish-Cache project due to trademark issues;
    • The essence of DRM usage by video services;
    • Removal of Mozilla's commitment to not sell user data.
  • Laws and regulations:
    • Ban on installing non-registered apps on Android;
    • Use of AI in Fedora;
    • Threats to the GrapheneOS project due to refusal to embed a backdoor;
    • Eric Raymond against codes of conduct.
  • Licenses:
    • AI model for analyzing the licensing purity of code;
    • Maintenance Fee — fee for supporting open source code;
    • Open WebUI has switched to a proprietary license;
    • PHP is transitioning to the BSD license;
    • Planka has moved to a non-free license;
    • Redis has reverted to an open license;
    • The Apertis distribution is without code under the GPLv3 license;
    • Criteria for the openness of AI models from Debian;
    • Copyleft-next license;
    • Firefox terms of use.
  • Promotion of FOSS:
    • Research on developer burnout in FOSS;
    • Open source software in the corporate environment;
    • Open Source principles by the UN;
    • GitHub statistics.
  • Development platforms:
    • Collaborative development service Fedora Forge;
    • Flathub is proposed for use in Fedora;
    • The resilience of public repositories such as PyPI, Crates.io, Packagist, and Maven.
  • Programming languages and compilers:
    • Crystal 1.16;
    • GCC 15;
    • Go 1.24, 1.25;
    • Hare 0.25.2;
    • Java 24, 25;
    • ZJIT just-in-time compiler in Ruby;
    • LLVM 20, 21;
    • Lua 5.5;
    • Microsoft is rewriting the TypeScript compiler in Go;
    • Mono 6.14.0;
    • Perl 5.42;
    • PHP 8.5;
    • Ruby 4.0;
    • Programming language Gauntlet.
  • Development tools:
    • CMake 4.0.0;
    • Emscripten 4.0;
    • GDB 17;
    • Git 2.48-2.52;
    • TPDE-LLVM backend;
    • Reproducible builds in Fedora;
    • End of support for Bazaar in Launchpad.
  • Python:
    • Python 3.14;
    • Comment-based attack in Python scripts;
    • CPython performance over 5 years;
    • The PyXL processor for Python bytecode.
  • Secure programming:
    • Memsafe for safe memory handling in C++;
    • Bjarne Stroustrup urged standardization of C++ profiles;
    • Buffer overflow protection based on Clang.
  • Rust:
    • 8% of src packages in Debian Sid depend on Rust;
    • Chrome has switched to Skrifa, written in Rust;
    • Fish has been rewritten in Rust;
    • GotaTun — implementation of VPN WireGuard in Rust;
    • Moss — Linux-compatible kernel in Rust;
    • Rust 1.84-1.92;
    • Rust 2024;
    • Rust in Git;
    • Rust in GRUB2;
    • Rust as a dependency in CPython;
    • Rust has been moved to core Linux kernel functions;
    • sudo-rs in Ubuntu;
    • Ubuntu replaces GNU Coreutils with uutils;
    • Authorship of Rust bindings for the DRM subsystem;
    • Inclusion of Rust code in the kernel bypassing maintainers;
    • Inclusion of the Nova driver for NVIDIA GPU in the Linux kernel;
    • Binder written in Rust accepted into the kernel;
    • Greg Kroah-Hartman on Rust in the kernel;
    • Nova driver for NVIDIA GPU;
    • Tyr driver for Mali GPU;
    • Rust code in APT;
    • FreeBSD components in Rust;
    • Conflict in promoting Rust in the kernel;
    • Linus Torvalds' position on accepting changes in Rust;
    • Rust specification;
    • Progress of Rust in Android;
    • Departure of DMA Mapping and ConfigFS maintainer due to Rust.
  • System components:
    • Bash 5.3;
    • Nitro initialization system;
    • Glibc 2.41, 2.42;
    • Kexec HandOver;
    • Live Update Orchestrator;
    • systemd 258, 259;
    • Loading images via HTTP in systemd;
    • Kernel reboot without stopping devices;
    • Strengthening GNOME's dependency on systemd.
  • Hardware:
    • Open Printer;
    • WebThings Gateway 2.0;
    • Raspberry Pi 500+ Computer Keyboard;
    • Issues with AMD Zen 5 CPU when using GNU MP.
  • Firmwares:
    • Coreboot 25.03-25.12, Libreboot 25.06, and Canoeboot 25.06;
    • Rockbox 4.0 firmware for audio players.
  • Network infrastructure:
    • The share of IPv6 is estimated at 40%;
    • Turris Omnia NG router;
    • State of the internet in 2025.
  • Standards:
    • PNG 3;
    • Adding JPEG XL to the PDF specification;
    • CVE Foundation organization established;
    • Shortening TLS certificate validity to 47 days;
    • OpenDocument Standard 1.4;
    • WebAssembly Standard 3.0;
    • Spectral JPEG XL image format.
  • Protection mechanisms:
    • capsudo to replace sudo;
    • FlippyRAM;
    • Intel and AMD standardize ChkTag;
    • Suricata 8.0;
    • Backdoor protection through reproducible builds;
    • Xous microkernel and Baochip-1x SoC;
    • CHERIoT 1.0 hardware-software platform for creating secure programs;
    • Enhancing security in Clang.
  • New operating systems and distributions:
    • Debian Libre;
    • KDE Linux Testing Edition;
    • KDE Ni! OS.
  • Embox OS.
  • Distribution and OS updates:
    • Debian 13;
    • Debian GNU/Hurd 2025;
    • Deepin 25;
    • Devuan 6.0;
    • elementary OS 8.1;
    • Fedora Linux 42, 43;
    • FreeDOS 1.4;
    • Linux Mint 22.2;
    • NixOS 25.05, 25.11;
    • OpenMandriva Lx 6.0;
    • openSUSE Leap 16.0;
    • OpenWrt 24.10;
    • Pop!_OS 24.04;
    • Qubes 4.3.0;
    • ReactOS 0.4.15;
    • Red Hat Enterprise Linux 10, 10.1;
    • SUSE 16;
    • Ubuntu 25.04, 25.10;
    • Whonix 18.0;
    • KDE Linux distribution;
    • Changes in distributions:
      • Intel has discontinued Clear Linux development;
      • Free RHEL for enterprises;
      • Fedora ends support for i686;
      • Ensured reproducible builds of Debian Live images;
      • Transition of openSUSE Tumbleweed to SELinux;
      • Support for RISC-V in RHEL, CentOS, and Rocky Linux.
    • BSD:
      • FreeBSD 13.5, 14.3, 15.0;
      • Running FreeBSD programs on Linux;
      • MinC;
      • OpenBSD 7.7;
      • Reproducible builds of FreeBSD.
    • Mobile platforms:
      • /e/OS 3.0;
      • KDE Plasma Bigscreen;
      • KDE Plasma Mobile 6.5;
      • Librephone by the Free Software Foundation;
      • Marathon OS and Marathon Shell;
      • postmarketOS 25.06 switched to systemd, postmarketOS 25.12;
      • ROSA Mobile 2.0;
      • PinePhone Pro folding;
      • FLX1s smartphone based on Debian and Phosh;
      • Liberux NEXX smartphone;
      • Watches based on PebbleOS.
    • Android:
      • Android 16, 16 QPR2;
      • LineageOS 23;
      • Linux terminal in Android;
      • Support for running graphical Linux applications added in Android;
      • Continuously updated Android Canary branch;
      • Restricting information about vulnerabilities fixed in Android;
      • Transition to closed-door Android development;
      • Android support in Swift;
      • Discontinuation of code publication for Google Pixel in Android AOSP.
    • Package management:
      • AerynOS;
      • apk 3.0;
      • APT 3.0.0;
      • Debusine — an analogue of PPA for Debian;
      • FAIR — decentralized package manager for WordPress;
      • RPM 6.0.
    • New user environments and projects
      • COSMIC 1.0;
      • MicroPythonOS;
      • Orbitiny;
      • QNX Developer Desktop;
      • XLibre 25.0 — a fork of X.Org Server;
      • X server Phoenix;
      • Gershwin desktop environment from GhostBSD.
      • New login manager for KDE;
      • Desktop environments:
        • Cinnamon 6.6;
        • GNOME 48, 49;
        • KDE Gear 25.04, 25.08, 25.12;
        • KDE Plasma 6.3, 6.4, 6.5;
        • LXQt 2.2.0, 2.3.0;
        • MaXX Interactive Desktop 2.2;
        • Sway 1.11;
        • Trinity 14.1.5;
        • Ubuntu stops supporting X11 sessions in GNOME;
        • Fedora retains only GNOME based on Wayland;
        • End of NX Desktop development;
      • Composite server updates:
        • Arcan 0.7.1;
        • Cairo-Dock 3.6;
        • Enlightenment 0.27;
        • Hyprland 0.53;
        • labwc 0.9.0;
        • miracle-wm 0.8;
        • Niri 25.11;
        • Regolith 3.2;
        • Wayfire 0.10.
      • GUI:
        • GTK 4.18, 4.20;
        • Qt 6.9, 6.10;
        • SDL 3;
        • wxWidgets 3.3.0;
        • X11 marked as deprecated in GTK;
        • KiCad CAD developers recommended using X11.
      • Cosmoe graphics library.
      • GPU and drivers:
        • Mesa 25.0, 25.1, 25.2, 25.3;
        • NVIDIA opened Flow GPU;
        • ZLUDA 4.
        • AMD ceased AMDVLK development in favor of Mesa RADV;
        • Replacing Nouveau with Zink in Mesa.
      • Promoting Wayland:
        • KDE Plasma 6.8 will be left only with Wayland;
        • Term.Everything to launch GUI in the terminal;
        • Wayback to launch X11 desktops in Wayland environments;
        • Wayback — Wayland composite server for running X11 environments;
        • Wayland 1.24;
        • Wayland in NVIDIA drivers;
        • GNOME removed code for X11 support;
        • Plan for X11 support in KDE;
        • Segregation of X11 and Wayland support in kwin;
        • Removal of X11 support in GNOME.
        • Multimedia:
          • FFmpeg 8.0;
          • OBS Studio 31.1, 32.0;
          • PipeWire 1.4;
          • Development of the OpenCut video editor has begun.
        • Codecs:
          • AV2 is 30% more efficient than AV1;
          • FLAC 1.5;
          • OpenAPV 0.2;
          • Opus 1.6;
          • AV2 video codec;
          • Theora 1.2 video codec;
          • Eclipsa spatial audio format.
        • Graphics:
          • Android switches to Vulkan;
          • Darktable 5.4.0;
          • GIMP 3.0.0;
          • Pinta 3.1.
        • Modeling and 3D:
          • Blender 5.0;
          • OpenUSD 1.0;
          • Newton physics simulation engine;
          • KiCad CAD 9.0;
          • A cartoon created in Blender won an Oscar.
        • Games:
          • Doom for KiCAD CAD and oscilloscope;
          • Godot 4.4, a fork of Redot;
          • Lossless Scaling Frame Generation for Linux;
          • Open 3D Engine 25.10;
          • Proton 10.0;
          • SteamOS 3.7;
          • Wine 10;
          • Lenovo gaming console based on SteamOS;
          • OrangePi Neo gaming console with Manjaro Linux;
          • The code for Team Fortress 2 has been published;
          • Steam Machine console with Linux.
        • New open projects:
          • Apple opened Swift Build assembly system;
          • Google opened Pebble OS for smartwatches;
          • Intel opened iaprof;
          • OpenZL for compressing structured data sets;
          • Qualcomm opened ELD composer;
          • TuxTape — live patch infrastructure for the Linux kernel;
          • Intel Tofino P4 opened;
          • Opened missing code for Pebble Watch smartwatches;
          • Toolkit for VST and ASIO opened;
          • Code for Windows Subsystem for Linux opened;
          • Code for Command & Conquer series games opened;
          • Code for Blitzkrieg game opened;
          • Code for BlueOS kernel opened;
          • Open humanoid robot;
          • Yandex opened Perforator.
        • DBMS:
          • Apache Cloudberry 2.0.0;
          • FerretDB 2.0;
          • MariaDB 12.0;
          • Microsoft has opened the source code of the DocumentDB DBMS;
          • OpenSearch 3.0;
          • PostgreSQL 18;
          • Redis 8.0-8.4;
          • TidesDB 1.0;
          • Valkey 9.0;
          • ZeroDay Cloud;
          • Playing DOOM on SQL;
          • Citus DBMS 13.0;
          • The EdgeDB DBMS has been renamed to Gel.
        • Web:
          • Micro QuickJS;
          • Node.js 24, 25.
        • Browsers:
          • Dillo 3.2.0.
          • Firefox 134-146;
          • Firefox as an AI browser;
          • Firefox has moved from Mercurial to Git;
          • Enabling WebGPU in Firefox and Safari;
          • Mozilla's business diversification;
          • New requirements for Firefox extensions;
          • Mozilla phishing.
          • Chrome 132-143;
          • The return of JPEG-XL in Chrome;
          • Dropping third-party cookie blocking in Chrome;
          • Ending support for XSLT in Chromium.
        • Office suites:
          • LibreOffice 25.2, 25.8;
          • ONLYOFFICE 9.0, 9.1, 9.2;
          • OpenCloud 1.0;
          • Thunderbird Pro and Thundermail styled like Gmail;
          • Open office suite Collabora Office;
          • GNU Taler payment system 1.0.
        • Machine learning:
          • AI capabilities in Chrome;
          • Devstral AI model for code;
          • Zonos speech synthesis AI model;
          • Google has introduced open NPU Coral;
          • Using AI to port the ftape driver;
          • AI limitations in GNOME;
          • Estimating the number of bugs in AI code;
          • AI usage rules in Fedora development;
          • Applying AI slows down software development.
        • File systems:
          • Bcachefs as a DKMS module;
          • ntfsplus — new NTFS driver for Linux;
          • OpenZFS 2.3, 2.4;
          • TernFS;
          • Distributed FS 3FS;
          • Theodore Ts'o on file systems and the Linux kernel;
          • Bcachefs has been removed from the Linux kernel.
        • Virtualization and containers:
          • AMD has opened a module for GPU virtualization;
          • Flatpak 1.16;
          • IncusOS;
          • Linux as Dom0 in Hyper-V;
          • Proxmox Datacenter Manager;
          • Proxmox VE 9.0;
          • QEMU 10.0, 10.1, 10.2;
          • TinyKVM for process virtualization;
          • VirtualBox 7.2;
          • Xen 4.20, 4.21;
          • Running graphical Linux applications on Android;
          • Multikernel mechanism;
          • SEAPATH virtualization platform;
          • Container support for Linux in macOS;
          • Sandbox isolation system Landrun.
        • Server applications:
          • ClamAV 1.5.0;
          • DHCP server Kea 3.0;
          • Dovecot 2.4.0;
          • Exim 4.99;
          • macOS has been transitioned to openrsync;
          • nginx 1.28.0;
          • Postfix 3.10;
          • PowerDNS 5.0;
          • Samba 4.22, 4.23.
        • Linux kernel:
          • Parker for launching multiple Linux kernels;
          • Intention to remove i486 from the Linux kernel;
          • Linux kernel port for WebAssembly;
          • Removing DCCP from the Linux kernel.
        • LKRG 1.0.0 for protecting against exploitation vulnerabilities in the Linux kernel;
        • Unbreakable Enterprise Kernel 8;
        • Key changes in the kernel:
          • 6.13: lazy eviction mode in the task scheduler, support for atomic writes in XFS and Ext4, multigrain timestamps mechanism, adaptive polling mode in the networking subsystem, ability to build with AutoFDO optimizations, support for ARM65 Guarded Control Stack protection mechanism, isolation of virtual machines using the ARM CCA extension, separate stacks in BPF, removal of ReiserFS, virtual-cpufreq driver, netlink API net-shaper, tmpfs mount mode with case-insensitive considerations, support for POSIX extensions in SMB3, AMD Cache Optimizer driver.
          • 6.14: Driver ntsync with synchronization primitives for Windows NT, configuration of read operation balancing in Btrfs RAID1, support for reflink in XFS in realtime mode, the possibility of non-cached buffered I/O, dmem cgroup for limiting GPU memory, use of io_uring in FUSE, delegating attributes in NFS, support for atomic writes in Device mapper, acceleration of symbolic links, management of script execution capabilities, support for Qualcomm Snapdragon 8 Elite chips, driver for AMD NPU.
          • 6.15: Audit mechanism in Landlock, memory mapping pinning mode, fwctl subsystem, Nova driver for NVIDIA GPU, implementation of host system for Hyper-V hypervisor, support for zoned storage devices in XFS, network subsystem optimization, removal of HIGHMEM64G option, scrub check in Bcachefs, the ability to control operations through io_uring.
          • 6.16: Driver for accelerating OpenVPN, Kexec HandOver mechanism, default enabling of five-level page tables for x86, removal of DCCP protocol, block driver zloop, ability to send core dumps via UNIX socket, support for atomic writes in XFS, offload processing of sound for USB devices, optimizations in Ext4, virtual TPM (Trusted Platform Module) driver, full implementation of Device Memory TCP, support for unnamed pipes in io_uring, preparation for integration of Asahi DRM driver, 'usermode queue' mechanism in AMDGPU driver, support for Intel TDE (Trusted Domain Extensions) and Intel APE (Advanced Performance Extensions).
          • 6.17: Performance improvement for Btrfs, system calls file_getattr() and file_setattr(), unification of single-core and multi-core configurations in the task scheduler, DAMON_STAT module with memory access statistics, support for Live patches on ARM64 systems, sending core dumps via AF_UNIX socket, SCHED_EXT limiting via cgroup, simplified configuration for CPU vulnerability protection, building in Clang with stack variable initialization, protection against modification of /proc, expansion of RV (Runtime Verification) subsystem, limiting AF_UNIX sockets through AppArmor, TCP overload control algorithm DualPI2.
          • 6.18: dm-pcache for disk caching in non-volatile memory (PMEM), removal of Bcachefs, online XFS checking mode, Binder (Android IPC) and Tyr (Mali GPU) drivers in Rust, ability to create USB drivers in Rust, caching optimization in the SLUB memory allocator, space addressing by file descriptors, swap performance enhancement, BPF program verification via digital signature, Intel CET virtualization in KVM, PSP network protocol (hybrid of TLS and IPsec), support for IP extension AccECN, UDP stack optimization.
        • Encryption:
        • Vulnerabilities in processors:
          • GPURowhammer attack on GPU memory;
          • Training Solo attack on Intel CPU;
          • VMScape attack on AMD and Intel CPU;
          • TSA attack on AMD CPU;
          • Access to SMM in AMD CPU;
          • RDSEED issues in AMD Zen 5.
        • Attack methods:
          • CDC attack on backup systems;
          • Clickjacking attack on password managers;
          • MadeYouReset — DoS on HTTP/2;
          • Phoenix — attack on DDR5 chips;
          • Pixnapping for screen content determination;
          • Whisper Leak attack;
          • Attack on GitHub Copilot;
          • Access to private GitHub repositories;
          • Using io_uring to bypass syscall analyzers.
        • Research:
          • 12 thousand API keys and passwords in Common Crawl;
          • AI as a new attack vector on software;
          • Undocumented commands in ESP32 chips;
          • Quantitative assessment of a computer to crack RSA-2048;
          • Hidden shell in Yamaha synthesizer accessed via MIDI.
        • Local vulnerabilities:
          • apport, systemd-coredump;
          • Exim;
          • Glibc;
          • GRUB2;
          • KDE LightDM Greeter;
          • Kea DHCP, cyrus-imapd;
          • libxml2;
          • MSG_OOB;
          • Nix, Lix, Guix;
          • pam-u2f;
          • PAM and udisks;
          • screen;
          • smb4k;
          • sudo;
          • sudo-rs;
          • vsock;
          • Bypassing user namespace protection in Ubuntu.
        • Remote vulnerabilities:
          • ADOdb;
          • ClamAV;
          • ConnMan, c-ares;
          • Erlang/OTP SSH;
          • Exim;
          • FreeBSD rtsold;
          • FreeType;
          • Git;
          • GitLab and ruby-saml;
          • GNOME Help, GIMP;
          • GnuPG;
          • Gogs;
          • KDE Konsole;
          • ksmbd;
          • Ladybird;
          • libpng;
          • LibreOffice;
          • libsoup;
          • MITM in OpenSSH;
          • Musl;
          • Net-SNMP;
          • Nixpkgs;
          • OpenH264;
          • OpenSSL 3.6.0;
          • OpenVPN;
          • OpenVPN;
          • Perl;
          • React;
          • Red Hat OpenShift AI;
          • Redis, Valkey;
          • rsync;
          • Rust libraries for TAR;
          • Samba;
          • SUSE Manager;
          • tar-fs, 7-Zip;
          • Bypassing quote escaping in psql;
          • SQL query injection in Exim.
        • Hacks:
          • Pwn2Own 2025;
          • Pwn2Own Automotive 2025;
          • Pwn2Own Ireland 2025;
          • HaveIBeenPwned author became a phishing victim;
          • Hack of Red Hat GitLab server;
          • Hack of Xubuntu site;
          • Compromise of changed-files;
          • Report on hack of Xubuntu.org.
        • Privacy:
          • 17 out of 20 VPN services report incorrect information about countries;
          • Facebook and Yandex caught de-anonymizing sessions in browsers;
          • Google will maintain the ability to install unverified third-party applications in Android;
          • KDE is dropping TLS and reforming telemetry;
          • Analysis of telemetry sent by browsers;
          • Browser extensions engage in building a distributed content delivery network for AI bots;
          • Details on verifying Android app developers;
          • StarDict privacy in Debian;
          • Winding down Privacy Sandbox;
          • Leak of the Great Chinese Firewall code;
          • Oniux utility from Tor.
        • Vulnerabilities in routers and hardware:
          • Security issues in Bluetooth SoC Airoha;
          • Vulnerability in the Android Bluetooth stack;
          • Vulnerabilities in Zyxel, Netgear, and D-Link.
        • Vulnerabilities in firmware and bootloaders:
          • Vulnerability in finit;
          • Issues in GRUB2;
          • Toolkit for modifying AMD microcode;
          • Bypassing disk encryption based on TPM2;
          • Bypassing SEV-SNP isolation in AMD CPUs;
          • Vulnerability in AMD CPU microcode bootloader.
        • Issues in repositories:
          • 3.1 million inflated stars on GitHub;
          • 4 malicious packages in crates.io;
          • OSS Rebuild to detect malicious changes in packages;
          • Malicious packages in AUR;
          • Malicious packages in AUR;
          • Malicious packages in crates.io;
          • Second worm attack on NPM;
          • Security incidents in PyPI and crates.io;
          • Compromise of 18 NPM packages with over 2 billion downloads per week;
          • Compromise of the NPM package xrpl;
          • Compromise of DuckDB NPM packages;
          • False blocking of the NPM package Stylus;
          • 817 repositories compromised on GitHub;
          • Vulnerability from deleting a dependency in PyPI;
          • Phishing on crates.io;
          • Phishing accompaniments for packages in PyPI;
          • Worm in NPM.
        • Failures:
          • Incompatibility issue between Windows Server and Samba;
          • Failures due to an influx of AI indexers;
          • Cloudflare failure due to unwrap;
          • Cloudflare failure due to Lua handler shutdown.
        • Attacks on infrastructures:
          • Malicious 3D models for attacking Blender;
          • Control over Kubernetes cluster via vulnerabilities in ingress-nginx;
          • Leak of 400,000 secrets due to the Shai-Hulud 2 worm;
          • Vulnerabilities for compromising Fedora and openSUSE packages;
          • Vulnerability in SSL.com that allowed obtaining a certificate for someone else's domain;
          • Phishing attack on accompanying NPM packages.
        • Incidents:
          • Blocking WinRing0 in Windows;
          • Incident with DNS server interception at MasterCard;
          • Compromise of Subaru's service interface;
          • Substitution of iVentoy root certificate in Windows;
          • Threat of CVE winding down;
          • Removal of Deepin from openSUSE;
          • DeepSeek Database Leak.

          In the past year, OpenNET published 1,520 news articles, receiving 173 thousand comments. In the autumn of 2025, the OpenNET project will celebrate its 29th anniversary.

          Source: opennet.ru

        • Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster