Author: Yuri Gagarin

GitHub Implements Machine Learning System to Identify Vulnerabilities in Code

GitHub has announced the addition of an experimental machine learning system for detecting common types of vulnerabilities in code to its Code scanning service. In the testing phase, this new functionality is currently available only for repositories with code in JavaScript and TypeScript. It is noted that the use of the machine learning system has significantly expanded the range of issues detected, as the system no longer limits itself to […]

Local root vulnerabilities in the Snap package management toolkit

Qualys has identified two vulnerabilities (CVE-2021-44731, CVE-2021-44730) in the snap-confine utility, shipped with the SUID root flag and called by the snapd process to create an execution environment for applications delivered in self-contained snap packages. The vulnerabilities allow a local unprivileged user to execute code with root privileges on the system. The issues have been fixed in today's snapd package update for Ubuntu 21.10, […]

Firefox 97.0.1 Update

A corrective release of Firefox 97.0.1 is available, which resolves several issues: Fixed a problem that caused crashes when attempting to download videos from TikTok selected on the user profile page. Fixed an error preventing videos from the Hulu service from being viewed in picture-in-picture mode. Resolved a crash that caused rendering issues when using WebRoot SecureAnywhere antivirus. Fixed the problem with […]

Release of KaOS 2022.02 Distribution

The release of KaOS 2022.02 has been announced, a distribution with a rolling update model aimed at providing a desktop based on the latest KDE releases and applications using Qt. Among the distribution-specific design features is the placement of a vertical panel on the right side of the screen. The distribution develops with an eye on Arch Linux but maintains its own independent repository with over 1500 packages, and […]

Critical vulnerability in Magento e-commerce platform

A critical vulnerability (CVE-2022-24086) has been discovered in the open-source e-commerce platform Magento, which accounts for about 10% of the market for online store creation systems, allowing code execution on the server through the submission of a specific request without going through authentication. The vulnerability has been assigned a severity level of 9.8 out of 10. The issue arises from improper validation of user-supplied parameters in the order processing handler. Details on exploiting the vulnerability […]

Google has increased the rewards for identifying vulnerabilities in the Linux and Kubernetes kernels.

Google has announced an expansion of its initiative to pay monetary rewards for identifying security issues in the Linux kernel, the container orchestration platform Kubernetes, the GKE (Google Kubernetes Engine), and the environment for vulnerability hunting competitions kCTF (Kubernetes Capture the Flag). The rewards program has introduced additional bonus payments of $20,000 for 0-day vulnerabilities, […]

The Unredacter has been introduced, a tool for identifying pixelated text.

The Unredacter tool has been introduced, allowing the recovery of original text after it has been obscured using pixelation filters. For example, the program can be used to identify confidential data and passwords that have been pixelated in screenshots or document images. It is claimed that the algorithm implemented in Unredacter outperforms previously available similar utilities, such as Depix, and has even been successfully used to pass the test […]

Release XWayland 21.2.0, a component for running X11 applications in Wayland environments

XWayland 21.2.0 has been released, a DDX component (Device-Dependent X) that enables the operation of the X.Org Server for running X11 applications in Wayland-based environments. Key changes include the addition of support for the DRM Lease protocol, which allows the X server to function as a DRM (Direct Rendering Manager) controller, providing DRM resources to clients. Practically, the protocol is used to form stereo images with different buffers for the left and right […]

Valve has released Proton 7.0, a package for running Windows games on Linux

Valve has released Proton 7.0, which is based on the Wine project's codebase and aims to enable the running of Windows-developed games on Linux, available in the Steam catalog. The project's developments are distributed under a BSD license. Proton allows the direct launching of Windows-only game applications in the Linux Steam client. The package includes […]

A version of LibreOffice, compiled in WebAssembly and running in a web browser

Thorsten Behrens, one of the leaders of the LibreOffice graphical subsystem development team, has released a demonstration version of a LibreOffice variant compiled to WebAssembly, capable of running in a web browser (about 300 MB of data is downloaded to the user's system). The Emscripten compiler is used for conversion to WebAssembly, and to organize output, a VCL backend (Visual Class Library) based on a modified […]

The release of Kali Linux 2022.1, designed for testing systems for vulnerabilities, conducting audits, analyzing residual information, and identifying the consequences of attacks by malicious actors.

The release of the compact distribution for creating firewalls and network gateways, pfSense 2.6.0, has been published. The distribution is based on the FreeBSD codebase with contributions from the m0n0wall project and active use of pf and ALTQ. An ISO image for the amd64 architecture, sized at 430 MB, is prepared for download. The distribution is managed through a web interface. It allows users to access both wired and wireless networks […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster