Author: Yuri Gagarin

Vulnerability in FreeBSD Exploited via Malicious USB Device

A vulnerability in the USB stack (CVE-2020-7456) has been addressed in FreeBSD, which allows code execution at the kernel level or in user space when a malicious USB device is connected to the system. USB HID (Human Interface Device) descriptors can place and extract the current state, allowing the consolidation of element descriptions into multilevel groups. FreeBSD supports up to 4 such levels of extraction. If a level is not specified, it defaults to the highest one.

UBports 16.04 OTA-12

The UBports team has released an update for its mobile operating system — UBports 16.04 OTA-12. Ubuntu Touch is the mobile operating system of UBports, ensuring privacy and freedom. UBports OTA-12 is available for many supported devices running Ubuntu Touch. New features: The main highlight of this new version is the import of the latest changes from Canonical into Unity 8. This transition began in April 2019 and […]

Microsoft has added GPU support for Linux GUI applications in WSL.

Microsoft has taken a giant step towards supporting Linux in Windows 10. In addition to incorporating a full Linux kernel in WSL version 2, the ability to run GUI applications with GPU acceleration has been added. Previously, a third-party X Server was used, but its speed received complaints from users. Currently, according to insiders, a new technology is being tested, with its release in Windows 10 […]

The problem of outdated root certificates. Let's Encrypt and smart TVs are next in line.

For a browser to authenticate a website, it presents a valid certificate chain. A typical chain is shown above, which may contain more than one intermediate certificate. The minimum number of certificates in a valid chain is three. The root certificate is the heart of the certification authority. It is literally embedded in your OS or browser and physically exists on your device. It cannot be changed with […]

10 common mistakes when using Kubernetes

Note from the authors: the authors of this article are engineers from a small Czech company, Pipetail. They managed to compile a remarkable list of [somewhat trivial yet still] highly relevant issues and misconceptions related to the operation of Kubernetes clusters. Over the years of using Kubernetes, we have had the opportunity to work with a large number of clusters (both managed and unmanaged — on GCP, AWS, and Azure). […]

In-memory architecture for web services: fundamentals of technology and principles

In-Memory — a set of data storage concepts where data is stored in the application’s RAM, while the disk is used for backup. In traditional approaches, data is stored on the disk, and memory is used for caching. For instance, a web application with a backend for processing data requests them from the storage: retrieves, transforms, and transmits a large amount of data over the network. In In-Memory computing, processing occurs closer to the data — […]

The microkernel seL4 is mathematically verified for the RISC-V architecture.

The RISC-V Foundation has reported the verification of the seL4 microkernel on RISC-V instruction set architecture systems. The verification consists of a mathematical proof of the reliability of seL4, which indicates full compliance with specifications defined in formal language. The proof of reliability allows using seL4 in mission-critical systems based on RISC-V RV64 processors, which require a higher level of reliability and guarantee the absence of […]

Release of the Linux sound subsystem — ALSA 1.2.3

The release of the ALSA 1.2.3 sound subsystem has been announced. The new version involves updates to libraries, utilities, and plugins that operate at the user level. Drivers are developed in sync with the Linux kernel. Notable changes, apart from numerous driver fixes, include support for Linux kernel 5.7, expanded PCM, Mixer, and Topology APIs (loading handlers from user space by drivers). A relocatable version of snd_dlopen has been implemented […]

The second beta release of the Haiku R1 operating system

The second beta release of the Haiku R1 operating system has been published. The project was originally created in response to the closure of BeOS and was developed under the name OpenBeOS, but was renamed in 2004 due to trademark concerns with the name BeOS. Several bootable Live images (x86, x86-64) have been prepared to evaluate the performance of the new release.

The first edition of the Peer-to-Peer client for the federated Matrix network

The experimental Riot P2P client has been released. Riot was originally a client for the Matrix federated network. The P2P modification adds server implementation and federation without using centralized DNS by integrating libp2p, which is also used in IPFS. This is the first version of the client that retains sessions after reloading the page, but in future major updates (e.g., 0.2.0), the data will still […]

Elastic Under Lock: Enabling Security Options for Elasticsearch Cluster Access from Inside and Outside

Elastic Stack is a well-known tool in the SIEM systems market (indeed, not just for them). It can gather diverse data, both sensitive and non-sensitive. It is not entirely correct if access to the Elastic Stack components themselves is not secured. By default, all out-of-the-box Elastic components (Elasticsearch, Logstash, Kibana, and Beats collectors) operate over open protocols. And […]

Remote Desktop from the attacker's perspective

1. Introduction Companies that had not organized remote access systems were urgently deploying them a couple of months ago. Not all administrators were prepared for such "heat"; as a consequence, there were security oversights: incorrect service configurations or even the installation of outdated software versions with previously known vulnerabilities. Some of these oversights have already come back to haunt them, while others have been luckier, […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster