Category: Internet News

A violation of backward compatibility in a popular NPM package has caused failures in various projects.

The NPM repository is experiencing another massive failure affecting projects due to issues arising from a new version of one of the popular dependencies. The source of the problems is the new release of the mini-css-extract-plugin 2.5.0 package, designed to extract CSS into separate files. The package has over 10 million weekly downloads and is used as a direct dependency by more than 7,000 projects. In […]

In Chromium and Chromium-based browsers, the removal of search engines is limited.

Google has removed the option to delete default search engines from the Chromium codebase. In the 'Manage Search Engines' section of the configurator (chrome://settings/searchEngines), elements from the list of default search engines (Google, Bing, Yahoo) can no longer be deleted. This change has been in effect since the release of Chromium 97 and has also affected all browsers based on it, including the latest releases of Microsoft […]

A vulnerability in cryptsetup that allows disabling encryption on LUKS2 partitions.

A vulnerability (CVE-2021-4122) has been discovered in the Cryptsetup package, which is used for encrypting disk partitions in Linux. This vulnerability allows an attacker to disable encryption in partitions formatted with LUKS2 (Linux Unified Key Setup) through metadata modification. To exploit the vulnerability, the attacker must have physical access to the encrypted medium, meaning this method is primarily useful for attacking encrypted external drives, such as flash drives, […]

Release of the Qbs build tool 1.21 and the start of testing Qt 6.3

The Qbs build toolchain version 1.21 has been released. This is the eighth release since the Qt Company ceased development of the project, prepared by a community interested in continuing Qbs development. Qt is required for building Qbs, although Qbs itself is designed to organize the building of any projects. Qbs uses a simplified version of the QML language to define build scripts, which allows […]

The Tor project has released Arti 0.0.3, a Tor client implementation in Rust.

The developers of the anonymous Tor network have announced the release of the Arti 0.0.3 project, which is developing a Tor client written in Rust. The project is in experimental development, lacking the functionality of the main Tor client written in C, and is not yet ready to replace it fully. The release of version 0.1.0 is expected in March, which is positioned as the first beta release of the project, and a 1.0 release with API stabilization is planned for the fall, […]

Release of the NetworkManager 1.34.0 network configurator

A stable release of the interface for simplifying network configuration - NetworkManager 1.34.0 is now available. Plugins for supporting VPN, OpenConnect, PPTP, OpenVPN, and OpenSWAN are being developed within their own development cycles. Key innovations of NetworkManager 1.34 include the introduction of a new service, nm-priv-helper, designed to facilitate operations that require elevated privileges. Currently, the use of this service is limited, but there are plans to eliminate […]

Firefox 96.0.1 Update. Firefox Focus has introduced Cookie Isolation Mode.

In response to recent events, a corrective release of Firefox 96.0.1 has been issued, which fixes a bug in Firefox 96 related to parsing the "Content-Length" header when using HTTP/3. The issue was that the search for the string "Content-Length:" was case sensitive, which did not account for variations like "content-length:". This new version also addresses a specific issue […]

Vulnerability in XFS allowing raw data to be read from a block device

A vulnerability has been found in the XFS filesystem code (CVE-2021-4155) that allows a local unprivileged user to read data from unused blocks directly from the block device. All significant Linux kernel versions above 5.16 that contain the XFS driver are affected by this issue. The fix was included in version 5.16, as well as in updates for kernels 5.15.14, 5.10.91, 5.4.171, 4.19.225, and so on. The state of the updates addressing the issue […]

An experiment simulating a full-size Tor network

Researchers from the University of Waterloo and the U.S. Naval Research Laboratory have unveiled results from the development of a Tor network simulator, comparable in the number of nodes and users to the main Tor network, allowing for experiments that closely resemble real-world conditions. The toolkit and methodology prepared during the experiment enabled simulation of a network with 6,489 nodes on a computer with 4 TB of RAM […]

The LLVM project is transitioning from mailing lists to the Discourse platform.

The LLVM project has announced a transition from its mailing list system to the llvm.discourse.group site based on the Discourse platform for developer communication and announcements. By January 20, all archives of past discussions will be transferred to the new platform. The mailing lists will switch to a read-only mode on February 1. This transition will simplify communication and make it more familiar for […]

Another vulnerability in the eBPF subsystem that allows privilege escalation

Another vulnerability has been identified in the eBPF subsystem (CVE is not assigned), similar to yesterday's issue that allows a local unprivileged user to execute code at the Linux kernel level. The problem has been present since Linux kernel 5.8 and remains unpatched for now. A working exploit is expected to be released on January 18. The new vulnerability is caused by incorrect validation of eBPF programs being executed. In particular, the eBPF verifier does not appropriately […]

The leader of Apache PLC4X has shifted to a model of paid feature development.

Christofer Dutz, the creator and lead developer of the free library set for industrial automation Apache PLC4X, who holds the position of Vice President at the Apache Software Foundation overseeing the Apache PLC4X project, has issued an ultimatum to corporations, expressing his willingness to cease development if he cannot resolve funding issues. His dissatisfaction stems from the fact that the usage of Apache PLC4X […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster