Author: ProHoster

Vulnerabilities in Dell devices that allow a MITM attack to replace the firmware

Vulnerabilities have been identified in the implementation of remote OS recovery and firmware update technologies promoted by Dell (BIOSConnect and HTTPS Boot) that allow replacing installed BIOS / UEFI firmware updates and remotely executing code at the firmware level. Running code can change the initial state of the operating system and be used to bypass applicable security mechanisms. Vulnerabilities affect 129 models of various laptops, tablets and […]

Vulnerability in eBPF allowing execution of code at the Linux kernel level

A vulnerability (CVE-2021-3600) has been identified in the eBPF subsystem, which allows running handlers inside the Linux kernel in a special virtual machine with JIT, that allows a local unprivileged user to execute their code at the Linux kernel level. The problem is caused by incorrect truncation of 32-bit registers when performing "div" and "mod" operations, which can lead to reading and writing data outside the allocated memory area. […]

Chrome's end of third-party cookie support delayed until 2023

Google has announced a change in plans to end Chrome's support for third-party cookies that are set when accessing sites other than the current page's domain. Such cookies are used to track user movements between sites in the code of advertising networks, social network widgets and web analytics systems. Chrome originally planned to stop supporting third-party cookies by 2022, but […]

The first release of an independent Russian-language branch of Linux From Scratch

Linux4yourself or "Linux for yourself" is presented - the first release of an independent Russian-language offshoot of Linux From Scratch - a guide to creating a Linux system using only the source texts of the necessary software. All project sources are hosted on GitHub under the MIT license. The user is offered the use of a multilib system, EFI support and a small set of additional software for […]

Sony Music succeeded in court blocking pirate sites at the Quad9 DNS resolver level

The recording company Sony Music obtained an order in the district court of Hamburg (Germany) to block pirated sites at the Quad9 project level, which provides free access to the publicly available DNS resolver “9.9.9.9”, as well as “DNS over HTTPS” services (“dns.quad9 .net/dns-query/") and "DNS over TLS" ("dns.quad9.net"). The court decided to block domain names found to be distributing music content that violates copyright, despite […]

6 malicious packages found in PyPI (Python Package Index) catalog

In the PyPI (Python Package Index) catalog, several packages have been identified that include code for hidden cryptocurrency mining. Problems were present in the packages maratlib, maratlib1, matplatlib-plus, mllearnlib, mplatlib and learninglib, the names of which were chosen to be similar in spelling to popular libraries (matplotlib) with the expectation that the user would make a mistake when writing and not notice the differences (typesquatting). The packages were placed in April under the account […]

SUSE Linux Enterprise 15 SP3 distribution available

After a year of development, SUSE presented the release of the SUSE Linux Enterprise 15 SP3 distribution. Based on the SUSE Linux Enterprise platform, products such as SUSE Linux Enterprise Server, SUSE Linux Enterprise Desktop, SUSE Manager and SUSE Linux Enterprise High Performance Computing are formed. The distribution is free to download and use, but access to updates and patches is limited to 60 days […]

NumPy Scientific Computing Python Library 1.21.0 Released

A release of the Python library for scientific computing NumPy 1.21 is available, focused on working with multidimensional arrays and matrices, and also providing a large collection of functions with the implementation of various algorithms related to the use of matrices. NumPy is one of the most popular libraries used for scientific calculations. The project code is written in Python using optimizations in C and is distributed […]

Firefox Update 89.0.2

A maintenance release of Firefox 89.0.2 is available, which fixes hangs that occur on the Linux platform when using the software rendering mode of the WebRender compositing system (gfx.webrender.software in about:config). Software rendering is used on systems with old video cards or problematic graphics drivers, which have stability problems or cannot be transferred to the GPU side for rendering page content (WebRender uses […]

OASIS Consortium Approves OpenDocument 1.3 as Standard

OASIS, an international consortium dedicated to the development and promotion of open standards, has approved the final version of the OpenDocument 1.3 specification (ODF) as an OASIS standard. The next stage will be the promotion of OpenDocument 1.3 as an international ISO/IEC standard. ODF is an XML-based, application- and platform-independent file format for storing documents containing text, spreadsheets, charts, and graphics. […]

The Brave project began testing its own search engine

The Brave company, which develops a web browser of the same name focused on protecting user privacy, presented a beta version of the search.brave.com search engine, which is closely integrated with the browser and does not track visitors. The search engine is aimed at preserving privacy and is built on technologies from the search engine Cliqz, which closed last year and was acquired by Brave. To ensure confidentiality when accessing a search engine, search queries, clicks […]

ClamAV free antivirus package update 0.103.3

A release of the free anti-virus package ClamAV 0.103.3 has been created, which proposes the following changes: The mirrors.dat file has been renamed to freshclam.dat since ClamAV has been switched to using a content delivery network (CDN) instead of a mirror network and the specified dat file no longer contains information about mirrors Freshclam.dat stores the UUID used in the ClamAV User-Agent. The need for renaming is due to the fact that in scripts […]