Author: ProHoster

Vulnerability in Intel processors leading to data leakage through third-party channels

A group of researchers from Chinese and American universities has identified a new vulnerability in Intel processors that leads to the leakage of information about the result of speculative operations through third-party channels, which can be used, for example, to organize a hidden communication channel between processes or detect leaks during Meltdown attacks. The essence of the vulnerability is that the change in the EFLAGS processor register, […]

Microsoft to add Rust code to Windows 11 core

David Weston, Microsoft vice president responsible for the security of the Windows operating system, in his report at the BlueHat IL 2023 conference, shared information on the development of Windows protection mechanisms. Among other things, the progress in using the Rust language to improve the security of the Windows kernel is mentioned. Moreover, it is stated that the code written in Rust will be added to the Windows 11 kernel, possibly in […]

Release of the Nitrux 2.8 distribution with NX Desktop user environments

The release of the Nitrux 2.8.0 distribution kit, built on the Debian package base, KDE technologies and the OpenRC initialization system, has been published. The project offers its own NX Desktop, which is an add-on to KDE Plasma. Based on the Maui library for the distribution, a set of typical user applications is developed that can be used on both desktop systems and mobile devices. For installation […]

Fedora 39 proposes to publish an atomically updatable build of Fedora Onyx

Joshua Strobl, a key contributor to the Budgie project, has published a proposal to include Fedora Onyx, an atomically updatable variant of Fedora Linux with a Budgie custom environment, that complements the classic Fedora Budgie Spin build and is reminiscent of the Fedora Silverblue, Fedora Sericea, and Fedora Kinoite editions, in official builds. , shipped with GNOME, Sway and KDE. The Fedora Onyx edition is offered to ship starting […]

A project to implement the sudo and su utilities in Rust

The ISRG (Internet Security Research Group), which is the founder of the Let's Encrypt project and promotes HTTPS and the development of technologies to increase the security of the Internet, presented the Sudo-rs project to create implementations of sudo and su utilities written in Rust that allow you to execute commands on behalf of others users. A pre-release version of Sudo-rs has already been published under the Apache 2.0 and MIT licenses, […]

The Genode Project has published the Sculpt 23.04 General Purpose OS release

The release of the Sculpt 23.04 project is presented, within the framework of which, based on the technologies of the Genode OS Framework, a general-purpose operating system is being developed that can be used by ordinary users to perform everyday tasks. The source texts of the project are distributed under the AGPLv3 license. A LiveUSB image is offered for download, 28 MB in size. Work is supported on systems with Intel processors and graphics subsystem with […]

Release of Linguist 5.0, a browser add-on for translating pages

The Linguist 5.0 browser add-on was released, providing a full-featured translation of pages, selected and manually entered text. The add-on also includes a bookmarked dictionary and extensive configuration options, including adding your own translation modules on the settings page. The code is distributed under the BSD license. Work is supported in browsers based on the Chromium engine, Firefox, Firefox for Android. Key changes in the new version: […]

General Motors has joined the Eclipse Foundation and provided the uProtocol protocol

General Motors announced that it has joined the Eclipse Foundation, a non-profit organization that oversees the development of more than 400 open source projects and coordinates more than 20 thematic working groups. General Motors will participate in the Software Defined Vehicle (SDV) working group, which focuses on the development of automotive software stacks built using open source code and open specifications. The group includes […]

Release of the GCC 13 compiler suite

After a year of development, the release of the free GCC 13.1 compiler suite has been released, the first significant release in the new GCC 13.x branch. Under the new release numbering scheme, version 13.0 was used during development, and shortly before the release of GCC 13.1, the GCC 14.0 branch was already forked, from which the next significant release of GCC 14.1 will be formed. Major changes: In […]

Solus 5 distribution will be built on SerpentOS technologies

As part of the ongoing reorganization of the Solus distribution, in addition to moving to a more transparent management model concentrated in the hands of the community and independent of one person, the decision was announced to use technologies from the SerpentOS project, developed by the old team of developers of the Solus distribution, which include Aiki Doherty, in the development of Solus 5 (Ikey Doherty, creator of Solus) and Joshua Strobl (Joshua Strobl, key […]

Vulnerabilities in Git that allow you to overwrite files or execute your own code

Corrective releases of Git 2.40.1, 2.39.3, 2.38.5, 2.37.7, 2.36.6, 2.35.8, 2.34.8, 2.33.8, 2.32.7, 2.31.8 and 2.30.9 have been published .XNUMX, which fixed five vulnerabilities. You can follow the release of package updates in distributions on the Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch, FreeBSD pages. As a workaround to protect against vulnerabilities, it is recommended to avoid executing the […]

67% of public Apache Superset servers use the access key from the configuration example

Researchers at Horizon3 have noticed security issues in most installations of the Apache Superset data analysis and visualization platform. On 2124 out of 3176 Apache Superset public servers studied, the use of the generic encryption key specified by default in the sample configuration file was detected. This key is used by the Flask Python library to generate session cookies, which allows a knowledgeable […]