Author: Erik Peterson

Vulkan 1.4.351

The Khronos Group has published an update for the Vulkan 1.4.351 graphics API. This technical release includes six new extensions, specification fixes, and further infrastructure preparation for upcoming GPUs and game engines. The most notable addition is the VK_KHR_shader_bfloat16 extension, which adds support for the BFloat16 format in shaders. This format is actively used in machine learning and AI acceleration tasks, helping to reduce requirements.

Fragnesia — a vulnerability in the Linux kernel that allows root access through page cache modification

The fourth vulnerability in the Linux kernel has been identified in the last two weeks (CVE-2026-46300), allowing an unprivileged user to gain root access by overwriting data in the page cache. The vulnerability has been given the code name Fragnesia or Copy Fail 3.0. The nature of the vulnerability is similar to previously disclosed vulnerabilities Copy Fail and Dirty Frag. Like Dirty Frag, the new vulnerability exists in the xfrm-ESP subsystem.

GNOME Yelp 49.1

The GNOME project developers released an update for the Yelp help application that fixes a vulnerability allowing the escape from the Flatpak sandbox environment. The issue was related to the handling of external URIs and the integration specifics of Yelp with application launching mechanisms. When opening a specially crafted document, an attacker could execute commands outside of the sandbox constraints, gaining access to the user’s system with the current user's privileges. The vulnerability affected […]

Vulnerability in Exim Leading to Remote Code Execution on Server

A critical vulnerability (CVE-2026-45185) has been identified in the Exim mail server, allowing for remote code execution on the server. The issue manifests starting with the Exim 4.97 branch when built with the GnuTLS library ("USE_GNUTLS=yes") and has been fixed in the Exim 4.99.3 release. Builds with OpenSSL and other libraries different from GnuTLS are not affected by this vulnerability. The problem is caused by a use-after-free error in […]

Vulnerability in AMD Zen 2 CPU, which allows privilege escalation and bypassing the isolation of virtual machines

AMD has disclosed information about a vulnerability (CVE-2025-54518) in processors based on the Zen 2 microarchitecture, which can lead to object code cache corruption. Successful exploitation of this vulnerability allows the execution of CPU instructions at a higher privilege level. In practice, the issue potentially allows for privilege escalation in the system, enabling code execution with kernel rights or access to […]

Release of Scrcpy 4.0, an application for mirroring Android smartphone screens

The release of Scrcpy 4.0 has been published, allowing users to mirror the smartphone screen content in a desktop environment with the capability to control the device, remotely operate mobile applications using a keyboard and mouse, view videos, and listen to audio. Client programs for managing the smartphone have been prepared for Linux, Windows, and macOS. The project code is written in C (with the mobile app in Java) and […]

FEX 2605

The quiet and unnoticed release of FEX 2605 has occurred — an open emulator and compatibility environment designed to run Linux applications compiled for x86 and x86-64 architectures on ARM64 systems. The project is evolving as an alternative to box64 and qemu-user, focused primarily on high performance, game support, and complex user software. FEX utilizes dynamic binary translation (JIT) and implements its own model […]

A self-replicating worm has been integrated into 42 TanStack NPM packages

As a result of the compromise of the release process based on GitHub Actions, attackers were able to publish 84 malicious versions covering 42 NPM packages from the TanStack stack in the NPM repository. Some of the compromised packages had over 10 million downloads per week. Access to publishing releases was gained due to an incorrect configuration of pull_request_target 'Pwn Request' in GitHub Actions (indicating […]

Vulnerabilities in dnsmasq allowing DNS cache poisoning and execution of code with root privileges

The Dnsmasq package, which includes a caching DNS resolver, DHCP server, service for announcing IPv6 routes, and network booting system, has revealed 6 vulnerabilities that allow for code execution with root privileges, domain redirection to another IP, memory content exposure of the process, and service crashing. Issues have been resolved in dnsmasq 2.92rel2. Fixes are also available in the form of patches. Identified issues: […]

The first release of the TLS 1.3 protocol implementation in Java with GOST algorithms according to RFC 9367

The crypto-gost-tls13 module contains an implementation of TLS 1.3 (RFC 8446 + RFC 9367) with GOST cryptography. This release is an initial version of the library and is ready for internal use. A unique feature of the library is its implementation in pure Java. All cryptographic operations are performed using the library's built-in mechanisms — with no external dependencies. This is arguably one of the first open implementations of TLS 1.3 with GOST […]

Release of fidoip 2.0.5 - a suite of programs for working in Fidonet

An update of fidoip 2.0.5 has been released — a set of programs for working within the Fidonet network. The package includes the latest versions of classic FIDO programs (all open-source software): a mailer for receiving emails via the Internet, a tosser for processing messages, and a message editor. Here are the main changes in this version: improved loading of node and point list updates, with the package utilizing over 10 mirrors. If […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster