Category: Blog

Gaphor 2.23

The release of Gaphor 2.23 has occurred. Gaphor is a cross-platform application within the GNOME Circle for modeling UML, SysML, RAAML, and C4 diagrams. The application is designed with a focus on ease of use and feature richness. Gaphor can be used for quick visualization of various system aspects as well as for creating complex and sophisticated models. In the new version: […]

Release of the memory testing system Memtest86+ 7.0

The release of the Memtest86+ 7.0 memory testing program is now available. The program is not tied to an operating system and can be launched directly from the BIOS/UEFI firmware or from a boot loader for a complete memory check. In case of identifying issues, the fault map generated in Memtest86+ can be used in the Linux kernel to exclude problematic areas using the memmap option. […]

Linux kernel release 6.7

After two months of development, Linus Torvalds has released Linux kernel 6.7. Among the most notable changes: integration of the Bcachefs file system, discontinuation of Itanium architecture support, Nouvea support for GSP-R firmware, support for TLS encryption in NVMe-TCP, the ability to use exceptions in BPF, support for futex in io_uring, optimization of the scheduler's performance (Fair Queuing), support for the TCP-AO (TCP Authentication Option) extension, and the ability to […]

Oxide Cloud Computer: reinventing the cloud

Public clouds are very popular, but they do not always meet the goals and objectives of the company. At the same time, traditional server infrastructure is costly to maintain, cumbersome to configure, and not always secure — largely due to the fragmentation of software and hardware architectures rooted in the distant past. The company Oxide Computer has announced that it has developed […]

Release of the firewalld 2.1 firewall

The release of the dynamically managed firewall firewalld 2.1 has been formed, implemented as a wrapper over the packet filtering tools nftables and iptables. Firewalld runs as a background process, allowing dynamic modification of packet filter rules through D-Bus, without the need to reload the filter rules or interrupt established connections. The project is already in use in many Linux distributions, including RHEL 7+, Fedora 18+ [...]

YAFL-0.30.2 has been released

Today marks the third release of the YAFL library. YAFL is a library written in C that includes several Kalman filtering algorithms and is distributed under the Apache-2.0 license. The library is designed for use in embedded systems based on microcontrollers with hardware support for floating-point calculations. An extension named python yaflpy has been created for prototyping and evaluating the library. The following changes have occurred compared to YAFL-0.20.0: [...]

The compromise of the account led to the failure of BGP routing for Orange Espagne.

The compromise of the administrator account led to nearly four hours of downtime for the second-largest Spanish telecom operator, Orange Espagne, which serves 11 million subscribers. A predictable password, "ripeadmin," was used to access the RIPE NCC registrar interface in Orange Espagne, and two-factor authentication was not enabled. The RIPE password was intercepted during a security breach affecting one of the employees […]

A vulnerability in the Perl module Spreadsheet::ParseExcel was exploited to compromise Barracuda ESG.

A critical vulnerability (CVE-2023-7101) has been identified in the Perl module Spreadsheet::ParseExcel, which provides functions for parsing Excel files. The vulnerability allows for arbitrary code execution when processing XLS or XLSX files containing specially crafted number formatting rules. The issue arises from using data obtained from the processed file in the construction of an "eval" call. The problem has been fixed in Spreadsheet::ParseExcel 0.66 update. An exploit prototype exists. Vulnerable code: if […]

A vulnerability in the Qt implementation of the HTTP/2 protocol.

A vulnerability (CVE-2023-51714) has been discovered in the Qt library's implementation of the HTTP/2 protocol, allowing data to be written beyond the allocated buffer. This vulnerability is caused by an integer overflow in the code handling packed headers (HPack) and manifests when receiving more than 4 GB of total HTTP header data or 2 GB for a single header. The problem has been addressed in Qt updates 5.15.17, 6.2.11, 6.5.4, and 6.6.2. […]

Issues arising from vulnerability reports prepared by AI tools

Daniel Stenberg, the author of the curl utility for transferring data over networks, criticized the use of AI tools in generating vulnerability reports. Such reports may include detailed information, be written in plain language, and appear to be high-quality; however, without thoughtful analysis, they can mislead by substituting real issues with superficially presentable garbage content. The Curl project […]

An experiment to create an NPM package dependent on all packages in the repository.

One of the developers of JavaScript packages conducted an experiment by creating and publishing a package called ‘everything’ in the NPM repository, which encompasses dependencies for all existing packages in the repository. To implement such a capability, the ‘everything’ package is directly dependent on five packages ‘@everything-registry/chunk-N’, which in turn are linked with dependencies to over 3000 packages ‘sub-chunk-N’, each of which refers to 800 […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster