Author: Erik Peterson

Updates for Tor 0.4.8.25 and 0.4.9.8 addressing vulnerabilities. Release of Arti 2.3.0

Corrective releases of the Tor toolkit 0.4.8.25 and 0.4.9.8 have been published, which are used for organizing the functioning of the anonymous Tor network. In the Tor 0.4.9.8 release, 6 vulnerabilities were fixed: TROVE-2026-011 — a bug that led to reading data from outside the buffer area when processing specially formatted messages (cell) END, TRUNCATE, and TRUNCATED; TROVE-2026-008 — improper handling of BEGIN_DIR messages when using the conflux mechanism. TROVE-2026-010 […]

OpenZL 0.2.0

After seven months of development, version 0.2.0 of the OpenZL framework, designed for creating lossless data compressors, has been released. The framework consists of a base library and tools for creating specialized compressors, described in the SDDL language. There are two stages to creating a good specialized compressor: Analyzing data to extract structure. Utilizing good backend compressors that use the obtained structure to achieve effective compression. […]

Google has increased the reward for identifying vulnerabilities in Android to $1.5 million, and in Chrome – to $500 thousand.

Google has announced an expansion of its vulnerability reward program for the Android platform, Chrome browser, and their underlying components. The maximum reward for creating an exploit for the Android platform that achieves code execution at the Pixel Titan M2 chip level without requiring special actions from the user (zero-click) is set at $1.5 million, if the attacker manages to […]

OpenWrt 25.12.3

On May 7, OpenWrt 25.12.3 was released – an operating system based on the Linux kernel, designed for embedded devices. Security fixes: Linux Kernel: fixed vulnerability CVE-2026-31431 (“Copy Fail”). In previous releases, this only affected users of the StarFive platform and those who had the kmod-crypto-user module installed. mbedtls: updated to version 3.6.6 (fixes for several CVEs). OpenSSL: updated to version 3.5.6 […]

The new reCAPTCHA will not allow verification on Android devices without Google services.

Google has announced a new generation of the reCAPTCHA bot filtering system, used on many websites to verify human interaction. In the new version of reCAPTCHA, instead of selecting images that fit a specific question, confirmation is done by scanning a QR code with a smartphone. The issue is that among the requirements for smartphones that can be used to complete the CAPTCHA are relatively new versions of iPhone/iPad, as well as […]

Microsoft has released the Azure Linux 3.0.20260506 distribution.

Microsoft has published the monthly update for the Azure Linux distribution 3.0.20260506. The distribution is evolving as a universal base platform for Linux environments used in cloud infrastructure, edge systems, and various Microsoft services. The project's own developments are distributed under the MIT license. Package builds are created for aarch64 and x86_64 architectures. The size of the installation image is 770 MB. Changes in the new version include: In the repository (SPECS […]

libgit2 1.9.3

On May 5, after five months of development, the release of version 1.9.3 of the cross-platform library libgit2, which implements core Git methods, took place. The library is written in C and is distributed under the GNU GPL 2 license with a special exception for linking that allows not to disclose source code. As examples, the project also provides console utilities lg2 and git2-experimental. There are a large number of bindings to libgit2 […]

Debian has approved mandatory support for reproducible package builds.

The team responsible for Debian releases has announced that reproducible builds of packages will become a mandatory feature. Changes were made to the build system yesterday, blocking the transfer of new packages that do not support reproducible builds into the repository. Updating existing packages in the testing repository, where regressions in build reproducibility are found, is also prohibited. In Debian 13, which has 36,427 source packages, support for […]

OpenCL 3.1

On May 5, the Khronos consortium presented the OpenCL 3.1 specification — another update to the open standard for cross-platform computing on CPUs, GPUs, DSPs, NPUs, and other accelerators. The release is timed to the IWOCL 2026 conference and advances the OpenCL 3.x model, where some capabilities are initially tested as extensions before being integrated into the mandatory core of the standard. The main change in OpenCL 3.1 is […]

Release of the Hyprland 0.55 composite server.

The composite server Hyprland 0.55 is available, utilizing the Wayland protocol. The project focuses on a tiling window layout, but also supports classic arbitrary window placement, window grouping in tab form, a pseudo-tiling mode, and fullscreen window expansion. The code is written in C++ and is distributed under the BSD license. Options are provided for creating visually appealing interfaces: gradients in window frames, blurring […]

A vulnerability in the execve system call that provides root access in FreeBSD

A vulnerability (CVE-2026-7270) has been discovered in FreeBSD, allowing an unprivileged user to execute code with kernel rights and gain root access to the system. The vulnerability affects all FreeBSD releases created since 2013. An exploit has been publicly released, verified to work on systems with FreeBSD versions 11.0 to 14.4. The vulnerability has been fixed in the updates FreeBSD 15.0-RELEASE-p7, 14.4-RELEASE-p3, 14.3-RELEASE-p12, and 13.5-RELEASE-p13. For older […]

A killswitch has been proposed for the emergency disabling of vulnerable functionality in the Linux kernel.

Sasha Levin from NVIDIA, who works on maintaining the LTS branches of the Linux kernel and is a member of the Linux Foundation advisory board, has prepared a set of patches implementing a killswitch mechanism for the Linux kernel. The proposed feature allows for the instant disabling of access to specific functionality of the running kernel. It is expected that the killswitch will be useful for temporarily blocking vulnerabilities until an update is installed […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster