Heading: Blog

Vulnerability in AMI MegaRAC firmware caused by shipping an old version of lighttpd

A vulnerability has been identified in MegaRAC firmware from American Megatrends (AMI), which is used in BMC (Baseboard Management Controller) controllers used by server manufacturers to organize autonomous equipment management, allowing an unauthenticated attacker to remotely read the contents of the memory of the process that provides the functioning of the web interface. The vulnerability appears in firmware released since 2019 and is caused by shipping an old version of the Lighttpd HTTP server containing an unpatched vulnerability. […]

Open, enter: more than 80 thousand Palo Alto Networks firewalls contain a critical zero-day vulnerability

Palo Alto Networks announced the identification of a critical zero-day vulnerability in its firewalls running Pan-OS. The gap that Volexity information security specialists discovered is already being exploited by cybercriminals. The issue described in bulletin CVE-2024-3400 received a maximum severity rating of 10 out of 10. The vulnerability allows an unauthenticated attacker to execute arbitrary program code with root privileges on a device [...]

Petabyte on wheels: Fujifilm releases stand-alone tape storage Kangaroo

Fujifilm has announced Kangaroo tape storage for large enterprise users who need to archive large amounts of information. A modification of Kangaroo Lite, aimed at small and medium-sized businesses, is also being prepared for release. Kangaroo is a completely self-contained all-in-one solution with all components enclosed in a wheeled housing for easy movement. Dimensions are 113 Γ— 60,4 Γ— 104 […]

Muen SK 1.1.0

The separation kernel Muen, developed by the Swiss company Codelabs, has been released. Muen only supports Intel x86_64 platforms and ensures that OS kernels and applications running on it cannot access resources beyond their allocated quota. This applies, among other things, to RAM, CPU time and access to I/O devices. As […]

Frouting 10

The dynamic routing program frrouting 10.0 was released. Here are the main innovations: Ability to advertise IP addresses added via redistribute local; minimum version of libyang increased to 2.1.128; VRF support for rpki; eBGP-OAD support; much more. Source: linux.org.ru

Ardor 8.6

Version 8.6 of the free digital audio workstation (DAW) Ardor has been released. The release does not include any particularly major changes, mainly because the developers are still busy working on future major releases. The new version, among other things, fixes a bug from version 8.4 with a crash when opening the file selection dialog on Linux under certain circumstances. Brief list of changes: […]

Release of transport company simulators OpenTTD 14.0 and OpenLoco 24.04

The release of OpenTTD 14.0 is available, a free strategy game that simulates the work of a transport company in real time. The release is timed to celebrate the 20th anniversary of the project. The OpenTTD code is written in C++ and distributed under the GPLv2 license. Installation packages are prepared for Linux, Windows and macOS. Initially, OpenTTD developed as an analogue of the commercial game Transport Tycoon Deluxe, but later turned into a self-sufficient project […]

Bitcoin fell below $66 thousand due to events in the Middle East

Last Friday, a sharp drop in Bitcoin (BTC) was recorded, whose value dropped below $66 thousand in the afternoon. At the same time, a few hours earlier, the rate reached $71 thousand. Along with Bitcoin, other cryptocurrencies also fell in price. The collapse of the cryptocurrency market came along with a decline in stock markets amid growing fears of a wider conflict […]

Release of http servers Lighttpd 1.4.76 and Apache httpd 2.4.59

The release of the lightweight http server lighttpd 1.4.76 has been published, focused on a combination of high performance, security, compliance with standards and configuration flexibility. Lighttpd is suitable for use on highly loaded systems and is aimed at low memory and CPU consumption. The project code is written in C and distributed under the BSD license. In the new version: The detection of the β€œContinuation flood” attack carried out through […]