Author: ProHoster

Release of Latte Dock 0.10, alternative dashboard for KDE

After two years of development, Latte Dock 0.10 is released, offering an elegant and simple solution for managing tasks and plasmoids. This includes support for the effect of parabolic magnification of icons in the style of macOS or the Plank panel. The Latte panel is built on the basis of the KDE Frameworks and the Qt library. Integration with the KDE Plasma desktop is supported. The project code is distributed […]

Release of Free Heroes of Might and Magic II (fheroes2) - 0.9.6

The fheroes2 0.9.6 project is now available, attempting to recreate the Heroes of Might and Magic II game. The project code is written in C++ and distributed under the GPLv2 license. To run the game, files with game resources are required, which can be obtained, for example, from the demo version of Heroes of Might and Magic II. Main changes: Full support for Russian, Polish and French localizations. Automatic detection […]

A new attack on front-end-backend systems that allows you to wedge into requests

Web systems in which the front end accepts connections via HTTP/2 and transmits them to the backend via HTTP/1.1 have been exposed to a new variant of the “HTTP Request Smuggling” attack, which allows, by sending specially designed client requests, to wedge into the contents of requests from other users processed in the same flow between frontend and backend. The attack can be used to insert malicious JavaScript code into a session with legitimate […]

Pwnie Awards 2021: Most Significant Security Vulnerabilities and Failures

The winners of the annual Pwnie Awards 2021 have been announced, highlighting the most significant vulnerabilities and absurd failures in computer security. Pwnie Awards is considered the equivalent of the Oscars and Golden Raspberries in the field of computer security. Main winners (list of contenders): Best vulnerability leading to privilege escalation. The victory was awarded to Qualys for identifying the vulnerability CVE-2021-3156 in the sudo utility, which allows you to gain root privileges. […]

IoT platform release EdgeX 2.0

Introduced the release of EdgeX 2.0, an open, modular platform for enabling interoperability between IoT devices, applications and services. The platform is not tied to specific vendor hardware and operating systems, and is developed by an independent working group under the auspices of the Linux Foundation. The platform components are written in Go and distributed under the Apache 2.0 license. EdgeX allows you to create gateways that connect your existing IoT devices and […]

PipeWire Media Server 0.3.33 Release

The release of the PipeWire 0.3.33 project has been published, developing a new generation multimedia server to replace PulseAudio. PipeWire extends PulseAudio's capabilities with video streaming capabilities, low-latency audio processing, and a new security model for device- and stream-level access control. The project is supported in GNOME and is already used by default in Fedora Linux. […]

Google's Kees Cook urged to modernize the process of working on errors in the Linux kernel

Kees Cook, former chief system administrator of kernel.org and leader of the Ubuntu Security Team who now works at Google to secure Android and ChromeOS, expressed concern about the current process of fixing bugs in the stable branches of the kernel. Every week, about a hundred fixes are included in stable branches, and after the window for accepting changes is closed, the next release is approaching a thousand […]

Assessing the use of vulnerable open components in commercial software

Osterman Research has published the results of a test of the use of open source components with unpatched vulnerabilities in proprietary custom-made software (COTS). The study examined five categories of applications - web browsers, email clients, file sharing programs, instant messengers and platforms for online meetings. The results were disastrous - all applications studied were found to use open source […]

Recruitment to a free online school for Open Source developers is open

Until August 13, 2021, enrollment is underway for a free online school for those who want to start working in Open Source - “Community of Open Source Newcomers” (COMMoN), organized as part of the Samsung Open Source Conference Russia 2021. The project is aimed at helping young developers to begin their journey as a contributor. The school will allow you to gain experience interacting with the open source developer community [...]

Release of Mesa 21.2, a free implementation of OpenGL and Vulkan

After three months of development, the release of a free implementation of the OpenGL and Vulkan API - Mesa 21.2.0 - was published. The first release of the Mesa 21.2.0 branch has an experimental status - after the final stabilization of the code, a stable version 21.2.1 will be released. Mesa 21.2 includes full support for OpenGL 4.6 for the 965, iris (Intel), radeonsi (AMD), zink and llvmpipe drivers. OpenGL 4.5 support […]

New version of music player DeaDBeeF 1.8.8

The release of music player DeaDBeeF 1.8.8 is available. The source code of the project is distributed under the GPLv2 license. The player is written in C and can work with a minimal set of dependencies. The interface is built using the GTK+ library, supports tabs and can be expanded through widgets and plugins. Features include: automatic recoding of text encoding in tags, equalizer, support for cue files, minimum dependencies, […]

Nightly builds of Ubuntu Desktop have a new installer

In the nightly builds of Ubuntu Desktop 21.10, testing has begun of a new installer, implemented as an add-on to the low-level installer curtin, which is already used in the Subiquity installer used by default in Ubuntu Server. The new installer for Ubuntu Desktop is written in Dart and uses the Flutter framework to build the user interface. The design of the new installer is designed taking into account the modern style [...]