Category: internet news

Analysis of sensitive data captured by the Shai-Hulud 2 worm

Компания Wiz опубликовала результаты анализа следов деятельности червя Shai-Hulud 2, в ходе активности которого в репозитории NPM были опубликованы вредоносные выпуски более 800 пакетов, насчитывающих в сумме более 100 млн загрузок. После установки поражённого пакета, активизировавшийся червь выполняет поиск конфиденциальных данных, публикует новые вредоносные релизы (при обнаружении токена подключения к каталогу NPM) и размещает в […]

Release of geoip 0.1.0, a REST API implementation for IP location

Состоялся первый релиз проекта geoip, реализующего сервис для получения информации о местоположении IP-адресов через REST API. Проект ориентирован на упрощение интеграции GeoIP-функциональности в различные приложения, освобождая разработчика от необходимости самостоятельно управлять обновлениями баз данных и работать с форматом MMDB. Код написан на языке Rust и распространяется под лицензией MIT. Поддерживается работа в Linux и macOS, […]

Alpine Linux 3.23 and APK 3.0 are now available.

The release of Alpine Linux 3.23 is available, a minimalistic distribution built on the basis of the Musl system library and the BusyBox set of utilities. The distribution has increased security requirements and is built with SSP (Stack Smashing Protection) protection. OpenRC is used as the initialization system, and its own apk package manager is used to manage packages. Alpine is used to build official Docker container images and […]

MinIO has discontinued its open source code base in favor of a proprietary product.

The developers of the MinIO project, which develops high-performance object storage compatible with the Amazon S3 API, announced the transition of their repository to maintenance mode. From now on, only critical vulnerability fixes will be included in the open source codebase, while changes related to new functionality and bug fixes will remain in the private repository, which is the basis for the commercial version. Users who require support or […]

A vulnerability in React server-side components allows for server-side code execution.

A vulnerability (CVE-2025-55182) has been fixed in the server components of the React web framework (RSC) that could allow arbitrary code execution on the server by sending a request to a server handler. The vulnerability has been rated critical (10 out of 10). The vulnerability affects the experimental components react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack, which are used to execute functions and generate interface elements on the server, rather than on the server […]

The OASIS Consortium has approved OpenDocument (ODF) 1.4 as a standard.

The OASIS International Consortium, a global consortium dedicated to developing and promoting open standards, has approved the final version of the OpenDocument 1.4 (ODF) specification as an OASIS standard. The next step will be the promotion of OpenDocument 1.4 as an international ISO/IEC standard. OpenDocument 1.4 has been supported in LibreOffice since LibreOffice 25.2. ODF is an XML-based, application- and platform-independent file format […]

Linux kernel 6.18 is classified as a long-term support release

The Linux kernel 6.18 has been given the status of a long-term support branch. Updates for the 6.18 branch will be released until at least December 2027, but it is possible that, as with previous LTS branches, the maintenance period will be extended to six years. For regular kernel releases, updates are released only until the next stable branch is released (for example, updates for […]

Android 16 QPR2 platform release with support for running graphical Linux applications

Google has released the second quarterly release of its open-source mobile platform, Android 16 (QPR2). The source code for the new release is available in the project's Git repository (branch android-16.0.0_r4). Firmware builds are available for the Pixel 6/6a/6 Pro, Pixel 7/7a/7 Pro, Pixel 8/8a/8 Pro, Pixel 9/9a/9 Pro/9 Pro XL/9 Pro Fold, Pixel Fold, and Pixel Tablet. Firmware builds with […]

JavaScript platform Bun acquired by Anthropic

Anthropic, the developer of the Claude family of large language models, has acquired Bun, a startup developing the open-source JavaScript platform, marketed as a high-performance alternative to Node.js and Deno. The primary reason cited for the acquisition is the desire to ensure the stable development of the Bun platform, which powers the Claude Code and Claude Agent SDK products. Following the acquisition, the project will remain open-source and publicly developed on GitHub and will continue to be delivered […]

Gitmal 1.0, a generator of static web views of Git repositories, is now available.

The first release of the Gitmal project has been published. It generates static websites for navigating Git repositories. Repository contents are converted into a visual web representation in the style of GitHub (example), consisting only of static HTML pages and requiring no server-side scripting. This approach allows for the creation of websites for browsing Git repositories that require minimal server resources. The project code is written […]

Developing AlmaLinux for Professional Video Studios

The developers of the AlmaLinux distribution announced the creation of the "Media & Entertainment SIG" working group, which will focus on developing AlmaLinux for professional studios creating visual effects and animation, as well as post-production. The working group's stated goal is to transform AlmaLinux into a Linux platform suitable for professional use in studios of all sizes. The group will be used to organize […]

Let's Encrypt will reduce the validity of certificates to 45 days.

Let's Encrypt, a community-run, non-profit certificate authority that provides free certificates to anyone, announced a gradual reduction in the validity period of its TLS certificates from 90 to 45 days. On February 10, 2027, the certificate validity will be reduced to 64 days, and on February 16, 2028, to 45 days. The option to obtain certificates valid for 45 days […]