Category: Internet News

A self-replicating worm has been integrated into 42 TanStack NPM packages

As a result of the compromise of the release process based on GitHub Actions, attackers were able to publish 84 malicious versions covering 42 NPM packages from the TanStack stack in the NPM repository. Some of the compromised packages had over 10 million downloads per week. Access to publishing releases was gained due to an incorrect configuration of pull_request_target 'Pwn Request' in GitHub Actions (indicating […]

Vulnerabilities in dnsmasq allowing DNS cache poisoning and execution of code with root privileges

The Dnsmasq package, which includes a caching DNS resolver, DHCP server, service for announcing IPv6 routes, and network booting system, has revealed 6 vulnerabilities that allow for code execution with root privileges, domain redirection to another IP, memory content exposure of the process, and service crashing. Issues have been resolved in dnsmasq 2.92rel2. Fixes are also available in the form of patches. Identified issues: […]

The first release of the TLS 1.3 protocol implementation in Java with GOST algorithms according to RFC 9367

The crypto-gost-tls13 module contains an implementation of TLS 1.3 (RFC 8446 + RFC 9367) with GOST cryptography. This release is an initial version of the library and is ready for internal use. A unique feature of the library is its implementation in pure Java. All cryptographic operations are performed using the library's built-in mechanisms — with no external dependencies. This is arguably one of the first open implementations of TLS 1.3 with GOST […]

Release of fidoip 2.0.5 - a suite of programs for working in Fidonet

An update of fidoip 2.0.5 has been released — a set of programs for working within the Fidonet network. The package includes the latest versions of classic FIDO programs (all open-source software): a mailer for receiving emails via the Internet, a tosser for processing messages, and a message editor. Here are the main changes in this version: improved loading of node and point list updates, with the package utilizing over 10 mirrors. If […]

Updates for Tor 0.4.8.25 and 0.4.9.8 addressing vulnerabilities. Release of Arti 2.3.0

Corrective releases of the Tor toolkit 0.4.8.25 and 0.4.9.8 have been published, which are used for organizing the functioning of the anonymous Tor network. In the Tor 0.4.9.8 release, 6 vulnerabilities were fixed: TROVE-2026-011 — a bug that led to reading data from outside the buffer area when processing specially formatted messages (cell) END, TRUNCATE, and TRUNCATED; TROVE-2026-008 — improper handling of BEGIN_DIR messages when using the conflux mechanism. TROVE-2026-010 […]

OpenZL 0.2.0

After seven months of development, version 0.2.0 of the OpenZL framework, designed for creating lossless data compressors, has been released. The framework consists of a base library and tools for creating specialized compressors, described in the SDDL language. There are two stages to creating a good specialized compressor: Analyzing data to extract structure. Utilizing good backend compressors that use the obtained structure to achieve effective compression. […]

Google has increased the reward for identifying vulnerabilities in Android to $1.5 million, and in Chrome – to $500 thousand.

Google has announced an expansion of its vulnerability reward program for the Android platform, Chrome browser, and their underlying components. The maximum reward for creating an exploit for the Android platform that achieves code execution at the Pixel Titan M2 chip level without requiring special actions from the user (zero-click) is set at $1.5 million, if the attacker manages to […]

OpenWrt 25.12.3

On May 7, OpenWrt 25.12.3 was released – an operating system based on the Linux kernel, designed for embedded devices. Security fixes: Linux Kernel: fixed vulnerability CVE-2026-31431 (“Copy Fail”). In previous releases, this only affected users of the StarFive platform and those who had the kmod-crypto-user module installed. mbedtls: updated to version 3.6.6 (fixes for several CVEs). OpenSSL: updated to version 3.5.6 […]

The new reCAPTCHA will not allow verification on Android devices without Google services.

Google has announced a new generation of the reCAPTCHA bot filtering system, used on many websites to verify human interaction. In the new version of reCAPTCHA, instead of selecting images that fit a specific question, confirmation is done by scanning a QR code with a smartphone. The issue is that among the requirements for smartphones that can be used to complete the CAPTCHA are relatively new versions of iPhone/iPad, as well as […]

Microsoft has released the Azure Linux 3.0.20260506 distribution.

Microsoft has published the monthly update for the Azure Linux distribution 3.0.20260506. The distribution is evolving as a universal base platform for Linux environments used in cloud infrastructure, edge systems, and various Microsoft services. The project's own developments are distributed under the MIT license. Package builds are created for aarch64 and x86_64 architectures. The size of the installation image is 770 MB. Changes in the new version include: In the repository (SPECS […]

libgit2 1.9.3

On May 5, after five months of development, the release of version 1.9.3 of the cross-platform library libgit2, which implements core Git methods, took place. The library is written in C and is distributed under the GNU GPL 2 license with a special exception for linking that allows not to disclose source code. As examples, the project also provides console utilities lg2 and git2-experimental. There are a large number of bindings to libgit2 […]

Debian has approved mandatory support for reproducible package builds.

The team responsible for Debian releases has announced that reproducible builds of packages will become a mandatory feature. Changes were made to the build system yesterday, blocking the transfer of new packages that do not support reproducible builds into the repository. Updating existing packages in the testing repository, where regressions in build reproducibility are found, is also prohibited. In Debian 13, which has 36,427 source packages, support for […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster