Author: Yuri Gagarin

Google will fund a security audit of 8 important open-source projects.

The OSTIF (Open Source Technology Improvement Fund), established to enhance the security of open projects, has announced a partnership with Google, which has expressed its willingness to fund an independent security audit of 8 open projects. The funds received from Google will be used to audit Git, the JavaScript library Lodash, the PHP framework Laravel, the Java framework Slf4j, the JSON libraries Jackson (Jackson-core and Jackson-databind), and Java components of Apache Httpcomponents […]

Firefox is conducting an experiment to use Bing as the default search engine

Mozilla is conducting an experiment to switch 1% of Firefox users to use Microsoft's Bing search engine by default. The experiment began on September 6 and will last until the end of January 2022. Users can assess their participation in Mozilla's experiments on the 'about:studies' page. For users who prefer other search engines, settings will still allow choosing a search engine of their liking. Reminder: […]

Release of Ubuntu 18.04.6 LTS distribution

An update for Ubuntu 18.04.6 LTS has been released. This release includes only accumulated package updates related to addressing vulnerabilities and issues affecting stability. The kernel and software versions correspond to version 18.04.5. The main goal of the new release is to update the installation images for amd64 and arm64 architectures. The installation image addresses issues related to key revocation during the resolution of […]

Oracle has removed the restriction on using JDK for commercial purposes

Oracle has changed the license agreement for the JDK 17 package (Java SE Development Kit), which provides reference builds of tools for developing and running applications in the Java language (utilities, compiler, class library, and JRE execution environment). Starting with JDK 17, the package is offered under a new NFTC license (Oracle No-Fee Terms and Conditions), which permits free use […]

A new interface layout for LibreOffice 8.0 with tab support is available

Rizal Muttaqin, one of the designers of the LibreOffice office suite, published a blog post outlining a plan for the potential development of the LibreOffice 8.0 user interface. The most notable innovation is the built-in tab support, which allows for quick switching between different documents, similar to how users switch between websites in modern browsers. Each tab can also be detached if needed […]

Remote vulnerability in OMI Agent deployed in Microsoft Azure Linux environments

Clients of the Microsoft Azure cloud platform using Linux in virtual machines have encountered a critical vulnerability (CVE-2021-38647) that allows remote code execution with root privileges. The vulnerability, codenamed OMIGOD, is notable because the issue exists within the OMI Agent application, which is quietly installed in Linux environments. The OMI Agent is automatically installed and activated when using services such as […]

The release of Apache HTTP Server 2.4.49 has been published, featuring 27 changes and addressing 5 vulnerabilities: CVE-2021-33193 - vulnerability of mod_http2 to a new variant of the 'HTTP Request Smuggling' attack.

In the Travis CI continuous integration service designed for testing and building projects developed on GitHub and Bitbucket, a security issue (CVE-2021-41077) has been identified that allows the content of sensitive environment variables in public repositories using Travis CI to be exposed. The vulnerability also allows exposure of the keys used in Travis CI for generating digital signatures, access keys, and tokens for accessing […]

Release of Apache HTTP Server 2.4.49 with vulnerability fixes

The release of Apache HTTP Server 2.4.49 has been published, featuring 27 changes and fixing 5 vulnerabilities: CVE-2021-33193 — mod_http2 is susceptible to a new variant of the "HTTP Request Smuggling" attack, which allows crafted client requests to interject into the content of requests made by other users through mod_proxy (for example, malicious JavaScript code could be injected into another user's session on the site). CVE-2021-40438 — SSRF vulnerability (Server […]

Release of the open billing system ABillS 0.91

The release of the open billing system ABillS 0.91 is now available, with components provided under the GPLv2 license. Key updates include: Paysys: all modules have been revamped. Paysys: payment system tests have been added. Client API introduced. Triplay: the management mechanism for sub-services Internet/TV/Telephony has been reworked. Cams: integration with the cloud-based video surveillance system Forpost. Ureports: the ability to send notifications simultaneously through multiple types has been added. Maps2: new layers added: Visicom Maps, 2GIS. […]

Mozilla has introduced Firefox Suggest and a new interface for the Firefox Focus browser.

Mozilla has introduced a new recommendation system, Firefox Suggest, which provides additional suggestions while typing in the address bar. Unlike recommendations based on local data and search engine queries, this new feature can include information from third-party partners, which may be non-profit projects like Wikipedia as well as paid sponsors. For example, when you start typing in […]

Release of Java SE 17

After six months of development, Oracle has released Java SE 17 (Java Platform, Standard Edition 17), with the open project OpenJDK serving as its reference implementation. Except for the removal of some outdated features, Java SE 17 maintains backward compatibility with previous versions of the Java platform — most previously written Java projects will run without modification on […]

Vulnerabilities in Matrix clients that allow the exposure of end-to-end encryption keys.

Vulnerabilities (CVE-2021-40823, CVE-2021-40824) have been identified in most client applications for the decentralized communication platform Matrix, allowing access to keys used for transmitting messages in end-to-end encrypted (E2EE) chats. An attacker, having compromised one user in the chat, can decrypt messages that were previously sent to that user from vulnerable client applications. Successful exploitation requires access to the recipient's account […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster