Author: Yuri Gagarin

Vulnerability in home routers, affecting 17 manufacturers

A massive attack on home routers has been recorded, where the firmware uses an implementation of the HTTP server from Arcadyan. A combination of two vulnerabilities is employed to gain control over the devices, allowing arbitrary code execution with root privileges. The issue affects a wide range of ADSL routers from companies like Arcadyan, ASUS, and Buffalo, as well as devices supplied under the Beeline brand (the issue has been confirmed […]

The official Elasticsearch clients have blocked the ability to connect to forks.

Elasticsearch has released elasticsearch-py 7.14.0, the official client library for Python, which includes a change that blocks connections to servers using a non-original commercial Elasticsearch platform. The client library will now output an error if the other side presents itself in the 'X-Elastic-Product' header as anything other than 'Elasticsearch' for new releases, or fails to convey the tagline and […]

A vulnerability in the network libraries of Rust and Go that allows bypassing IP address checks.

Vulnerabilities have been identified in the standard libraries of Rust and Go, related to the improper handling of IP addresses containing octal digits in address parsing functions. These vulnerabilities allow bypassing acceptable address checks in applications, for instance, to access loopback interface addresses (127.x.x.x) or intranet subnets during SSRF (Server-side request forgery) attacks. These vulnerabilities continue the cycle of problems previously identified in the node-netmask libraries […]

Release of Bottlerocket 1.2, a distribution based on isolated containers

The release of the Linux distribution Bottlerocket 1.2.0 is available, developed in collaboration with Amazon for efficient and secure deployment of isolated containers. The tools and management components of the distribution are written in Rust and distributed under MIT and Apache 2.0 licenses. Bottlerocket supports deployment in Amazon ECS, VMware, and AWS EKS Kubernetes clusters, as well as the creation of custom builds and editions that allow for the use of […]

Release of Nmap 7.92 network security scanner

The release of Nmap 7.92, a network security scanner designed for network auditing and identifying active network services, is now available. This new version addresses issues noted by the Fedora project regarding compatibility with NPSL open-source license criteria (based on GPLv2), under which the Nmap code is distributed. In this new license version, there is a mandatory requirement to purchase a separate commercial license when using the code in proprietary […]

Google is porting Chrome for Fuchsia OS

Google is working on providing full builds of the Chrome browser for Fuchsia OS. Fuchsia already offers a browser engine based on the Chromium codebase for running isolated web applications, but the browser as a standalone full product for Fuchsia has not been available, and the platform has primarily been developed for IoT and consumer devices like the Nest Hub. The latest […]

Release of Latte Dock 0.10, an alternative panel for KDE

After two years of development, the release of Latte Dock 0.10 has been presented, offering an elegant and simple solution for managing tasks and plasmoids. It also supports a parabolic zoom effect for icons similar to macOS or the Plank dock. The Latte dock is built on the KDE Frameworks and Qt libraries. Integration with the KDE Plasma desktop is supported. The project's code is distributed […]

A new attack on front-end and back-end systems that allows interception of requests.

Web systems where the front end receives connections via HTTP/2 and transmits to the backend over HTTP/1.1 have been vulnerable to a new variant of the "HTTP Request Smuggling" attack. This allows attackers to inject specially crafted client requests into the content of requests from other users being handled in the same stream between the front end and backend. The attack can be used to inject malicious JavaScript code into a session with a legitimate […]

Pwnie Awards 2021: The Most Significant Vulnerabilities and Security Failures

Winners of the annual Pwnie Awards 2021 have been announced, highlighting the most significant vulnerabilities and absurd failures in computer security. The Pwnie Awards are considered the equivalent of the Oscars and Golden Raspberries in the field of computer security. Main winners (list of nominees): Best vulnerability leading to privilege escalation. The award goes to Qualys for identifying the CVE-2021-3156 vulnerability in the sudo utility, which allows obtaining root privileges. […]

Release of the EdgeX 2.0 platform for the Internet of Things.

The release of EdgeX 2.0 has been announced, an open modular platform designed for interoperability between IoT devices, applications, and services. The platform is hardware- and operating system-agnostic and is developed by an independent working group under the auspices of the Linux Foundation. The platform's components are written in Go and distributed under the Apache 2.0 license. EdgeX enables the creation of gateways that integrate existing IoT devices and […]

Release of multimedia server PipeWire 0.3.33

The release of PipeWire 0.3.33 has been published, which is developing a next-generation multimedia server intended to replace PulseAudio. PipeWire extends the capabilities of PulseAudio by providing tools for handling video streams, enabling audio processing with minimal latency, and introducing a new security model for access control at the level of individual devices and streams. The project is supported in GNOME and is already applied by default in Fedora Linux. […]

Kis Cook from Google has called for modernization of the bug fixing process in the Linux kernel.

Kees Cook, former chief system administrator at kernel.org and leader of the Ubuntu Security Team, now working at Google on securing Android and ChromeOS, expressed concern about the current process of fixing bugs in stable kernel branches. Approximately one hundred fixes are included in stable branches each week, and after the closure of the change acceptance window, the next release approaches one thousand […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster