Author: Yuri Gagarin

Firefox and Cloudflare have enabled ECH support to hide domain names in HTTPS traffic.

Mozilla has announced the inclusion of support for the Encrypted Client Hello (ECH) mechanism in the stable branch of Firefox for users, continuing the development of the Encrypted Server Name Indication (ESNI) technology and designed to encrypt information about TLS session parameters, such as the requested domain name. Initially, the code for ECH support was added in Firefox version 85 but was disabled by default. In […]

HyperDX: an alternative to Datadog and New Relic

On September 13, HyperDX was released on GitHub — a monitoring and debugging tool that allows users to correlate logs, traces, and sessions in one place. The source code is available and distributed under the MIT license. HyperDX helps engineers understand the reasons for production failures and resolve issues more quickly. It is an open-source alternative to Datadog and New Relic. It can be deployed on your own […]

GNOME 45 'Rīga'

After six months of development, GNOME 45 was released under the codename 'Rīga'. The new release is already available in the experimental builds of Fedora 39 and Ubuntu 23.10. The GNOME project is an international community supported by a non-profit foundation, focusing on user experience quality, top-notch internationalization, and accessibility. Key changes include: • A new virtual desktop indicator and the removal of the […]

Angie 1.3.0 — a fork of Nginx

Angie is an efficient, powerful, and scalable web server built by some of the former core developers of nginx with the intention of expanding functionality far beyond the original version. It is distributed under the BSD license. Angie is a complete replacement for nginx, allowing you to use your existing nginx configuration without significant changes. A key feature of Angie is its acquisition by the project […]

Vulnerability in the NTFS driver from GRUB2 allowing code execution and bypassing UEFI Secure Boot

A vulnerability (CVE-2023-4692) has been identified in the driver handling NTFS filesystem operations in the GRUB2 bootloader, allowing for the execution of arbitrary code at the bootloader level when accessing a specifically crafted filesystem image. This vulnerability can be exploited to bypass the UEFI Secure Boot verified boot mechanism. The vulnerability stems from an error in parsing the NTFS attribute '$ATTRIBUTE_LIST' (grub-core/fs/ntfs.c), which can be used to write […]

fwmx 1.3 — a lightweight window manager for x11

Version 1.3 of the fwmx software suite has been released, which includes the window manager (fwm), an application launcher menu, and a volume control. The layout indicator used is xxkb. What's new since the last release (v1.2): added root daemon for monitoring battery status and managing screen brightness on laptops, along with corresponding elements in the taskbar; improved drag and drop behavior […]

Firefox 119 will change the behavior of session restoration.

In the next Firefox release, some settings related to session recovery after exiting the browser will be changed. Unlike previous versions, information about not only active tabs but also recently closed tabs will be saved between sessions, allowing users to restore accidentally closed tabs after restarting and view their list in Firefox View. More details […]

Vulnerabilities in the ARM GPU driver are already being exploited for attacks

ARM has disclosed information about three vulnerabilities in the drivers for its GPUs used in Android, ChromeOS, and Linux distributions. The vulnerabilities allow an unprivileged local user to execute their code with kernel privileges. The October security report for the Android platform mentions that one of the vulnerabilities (CVE-2023-4211) has already been exploited by attackers in working exploits before a fix is available […]

A vulnerability in Glibc ld.so allows obtaining root privileges on the system.

Qualys has identified a dangerous vulnerability (CVE-2023-4911) in the ld.so linker, included with the system C library Glibc (GNU libc). The vulnerability allows a local user to elevate their privileges in the system by specifying specially crafted data in the GLIBC_TUNABLES environment variable before launching an executable file with the suid root flag, such as /usr/bin/su. Successful exploitation of the vulnerability has been demonstrated in Fedora 37 and 38, […]

Linux Mint Edge 21.2 has been released with a new Linux kernel.

The developers of the Linux Mint distribution have announced the release of a new ISO image called 'Edge', which is based on the July release of Linux Mint 21.2 with a Cinnamon desktop and features the Linux kernel 6.2 instead of 5.15. Additionally, the proposed ISO image restores support for UEFI SecureBoot mode. This build is aimed at users of new hardware experiencing installation and booting issues […]

Release of portable version OpenBGPD 8.2

The portable version of the OpenBGPD routing package 8.2 has been released, developed by the OpenBSD project and adapted for use in FreeBSD and Linux (support is claimed for Alpine, Debian, Fedora, RHEL/CentOS, Ubuntu). To ensure portability, parts of the code from the OpenNTPD, OpenSSH, and LibreSSL projects have been used. The project supports most of the BGP 4 specifications and complies with the requirements of RFC8212, but it does not attempt to cover everything […]

Malicious packages discovered in the Ubuntu Snap Store

Canonical has announced a temporary suspension of the automatic publishing package verification system in the Snap Store due to the appearance of packages with malicious code intended to steal cryptocurrency from users. It is unclear whether the incident is limited to the publication of malicious packages by third-party authors or whether there are security issues directly with the repository, as the situation in the official announcement is characterized by […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster