Author: Yuri Gagarin

NetBSD 10.0

The release of NetBSD 10.0 has been announced. Changes in the new version include: Hardware Support: Added support for Apple M1. Added support for Raspberry Pi 4. The rkv1crypto driver is included for PINE64 Rock64 and NanoPi R2S. spiflash support has been added for Rockchip RK3328. compat_linux support for the AArch64 architecture has been included. Kernel Changes: Added WireGuard support. Adiantum encryption implementation is introduced for efficient disk encryption […]

Release of the NetBSD 10.0 operating system

A year and a half after the last update, the release of NetBSD 10 has been published. Installation images sized 630 MB are available for download in builds for 57 system architectures and 16 different CPU families. The new branch includes several significant improvements, such as support for access control lists in the FFS file system, substantial performance optimization, and disk encryption with […]

Analysis of the activation logic and operation of the backdoor in the xz package

Preliminary results of reverse engineering a malicious object file embedded in liblzma as part of a backdoor promotion campaign in the xz package are now available. The backdoor affects only x86_64 systems running on the Linux kernel and the Glibc C library, with an additional patch applied to sshd that links to the libsystemd library for sd_notify support. It was initially thought that the backdoor allows bypassing authentication […]

Debian 10 "Buster" has been moved to the archive

Debian 10 'Buster' repositories have been moved to archive.debian.org, after which the distribution will soon become unavailable through the main mirror network. The removal of Debian 10 packages from mirrors for architectures that do not have LTS support is planned for mid-April. The Debian 10 release was presented on July 7, 2019, and was officially supported until September 2022. During the LTS cycle […]

Retrospective on the promotion of the backdoor in the xz package

The backdoor in the xz package is believed to have been implanted by developer Jia Tan, who in 2022 became a maintainer and released versions starting from 5.4.2. In addition to the xz project, the alleged backdoor author also participated in the development of the xz-java and xz-embedded packages, and was included among the maintainers of the XZ Embedded project used in the Linux kernel. In the organization promoting the backdoor […]

A backdoor has been found in the xz code of versions 5.6.0 and 5.6.1

Debian developer and information security researcher Andres Freund reports the discovery of a potential backdoor in the source code of xz versions 5.6.0 and 5.6.1. The backdoor consists of a line in one of the m4 scripts that appends obfuscated malicious code to the end of the configure script. This code then modifies one of the generated Makefiles of the project, ultimately leading to […]

Flatpak 1.15.7: automatic removal of outdated drivers and other improvements

The new version of Flatpak 1.15.7 introduces automatic removal of outdated drivers and improvements for Linux, ranging from the Meson build system to fixes for D-Bus and Wayland. A key feature of this new version is the automatic removal of outdated driver versions and other unused dependencies. This function aims to eliminate unnecessary components that accumulate over time by automatically removing runtimes, such as […]

A backdoor was found in the xz/liblzma library, allowing access through sshd.

A backdoor (CVE-2024-3094) has been discovered in the XZ Utils package, which includes the liblzma library and utilities for working with compressed data in the '.xz' format. This backdoor allows for the interception and modification of data processed by applications connected to the liblzma library. Its primary target is the OpenSSH server, which in some distributions is linked to the libsystemd library that, in turn, uses liblzma. Binding sshd to the vulnerable library […]

PyPI has suspended the registration of new users and projects due to a surge in malicious publications.

The Python Package Index (PyPI) repository has temporarily prohibited new user registrations and the creation of new projects due to an ongoing mass upload of malicious packages during an automated attack. The ban was implemented after 566 malicious packages were uploaded to the repository on March 26 and 27, styled to mimic 16 popular Python libraries. The package names were formed using type squatting, […]

The FuryGpu project develops a GPU based on FPGA.

A working prototype of the FuryGpu project has been presented, which develops a DIY GPU based on the Xilinx Zynq UltraScale+ FPGA, designed as a separate board connected to a PC via a PCIe interface. Descriptions of the hardware blocks are implemented in SystemVerilog, and the board project is prepared in the free KiCAD PCB design automation system. In its current form, the FuryGpu GPU already allows for the game Quake to run […]

Release of GNU Coreutils 9.5 and its Rust variant

The stable version of the GNU Coreutils 9.5 basic system utilities suite has been released, which includes programs such as sort, cat, chmod, chown, chroot, cp, date, dd, echo, hostname, id, ln, ls, etc. Key innovations: The cp, mv, install, cat, and split utilities have been optimized for read and write operations. The size of the minimum readable or writable block has increased […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster