Category: Internet News

Debian 10 "Buster" has been moved to the archive

Debian 10 'Buster' repositories have been moved to archive.debian.org, after which the distribution will soon become unavailable through the main mirror network. The removal of Debian 10 packages from mirrors for architectures that do not have LTS support is planned for mid-April. The Debian 10 release was presented on July 7, 2019, and was officially supported until September 2022. During the LTS cycle […]

Retrospective on the promotion of the backdoor in the xz package

The backdoor in the xz package is believed to have been implanted by developer Jia Tan, who in 2022 became a maintainer and released versions starting from 5.4.2. In addition to the xz project, the alleged backdoor author also participated in the development of the xz-java and xz-embedded packages, and was included among the maintainers of the XZ Embedded project used in the Linux kernel. In the organization promoting the backdoor […]

A backdoor has been found in the xz code of versions 5.6.0 and 5.6.1

Debian developer and information security researcher Andres Freund reports the discovery of a potential backdoor in the source code of xz versions 5.6.0 and 5.6.1. The backdoor consists of a line in one of the m4 scripts that appends obfuscated malicious code to the end of the configure script. This code then modifies one of the generated Makefiles of the project, ultimately leading to […]

Flatpak 1.15.7: automatic removal of outdated drivers and other improvements

The new version of Flatpak 1.15.7 introduces automatic removal of outdated drivers and improvements for Linux, ranging from the Meson build system to fixes for D-Bus and Wayland. A key feature of this new version is the automatic removal of outdated driver versions and other unused dependencies. This function aims to eliminate unnecessary components that accumulate over time by automatically removing runtimes, such as […]

A backdoor was found in the xz/liblzma library, allowing access through sshd.

A backdoor (CVE-2024-3094) has been discovered in the XZ Utils package, which includes the liblzma library and utilities for working with compressed data in the '.xz' format. This backdoor allows for the interception and modification of data processed by applications connected to the liblzma library. Its primary target is the OpenSSH server, which in some distributions is linked to the libsystemd library that, in turn, uses liblzma. Binding sshd to the vulnerable library […]

PyPI has suspended the registration of new users and projects due to a surge in malicious publications.

The Python Package Index (PyPI) repository has temporarily prohibited new user registrations and the creation of new projects due to an ongoing mass upload of malicious packages during an automated attack. The ban was implemented after 566 malicious packages were uploaded to the repository on March 26 and 27, styled to mimic 16 popular Python libraries. The package names were formed using type squatting, […]

The FuryGpu project develops a GPU based on FPGA.

A working prototype of the FuryGpu project has been presented, which develops a DIY GPU based on the Xilinx Zynq UltraScale+ FPGA, designed as a separate board connected to a PC via a PCIe interface. Descriptions of the hardware blocks are implemented in SystemVerilog, and the board project is prepared in the free KiCAD PCB design automation system. In its current form, the FuryGpu GPU already allows for the game Quake to run […]

Release of GNU Coreutils 9.5 and its Rust variant

The stable version of the GNU Coreutils 9.5 basic system utilities suite has been released, which includes programs such as sort, cat, chmod, chown, chroot, cp, date, dd, echo, hostname, id, ln, ls, etc. Key innovations: The cp, mv, install, cat, and split utilities have been optimized for read and write operations. The size of the minimum readable or writable block has increased […]

Release of VPN Lanemu 0.11.6

The release of Lanemu P2P VPN 0.11.6 has occurred — a decentralized virtual private network operating on a Peer-To-Peer basis, where participants are connected directly to each other rather than through a central server. Network participants can find each other through BitTorrent trackers or BitTorrent DHT, or through other network participants (peer exchange). The application is a free and open-source alternative to VPN Hamachi, developed […]

A vulnerability that allows injecting escape sequences into foreign terminals

A vulnerability (CVE-2024-28085) has been discovered in the wall utility, provided in the util-linux package, which is designed to send messages to terminals, allowing for an attack on other users' terminals through manipulation of escape sequences. The issue arises because the wall utility blocks the use of escape sequences in the input stream but fails to perform this operation for command-line arguments, allowing an attacker to execute escape sequences […]

Release of Samba 4.20.0

After 6 months of development, the release of Samba 4.20.0 has been presented, continuing the development of the Samba 4 branch with a full implementation of domain controller and Active Directory service compatible with the Windows 2008 implementation and capable of servicing all supported Microsoft versions of Windows clients, including Windows 11. Samba 4 is a multifunctional server product that also provides a file server, print service, and server […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster