The xz/liblzma vulnerability was introduced by an attacker who offered to help a struggling solo maintainer following community pressure to implement changes.
https://robmensching.com/blog/posts/2024/03/30/a-microcosm-of-the-interactions-in-open-source-projects/
A supply-chain attack involving obfuscated malicious code in the xz package was discovered by a developer at Microsoft who noticed a small 600ms delay with SSH processes when doing some routine micro-benchmarking. The account that made the offending commits seemingly played the long game, slowly gaining the trust of xz's developer before injecting the attack. The attack allows for the interception and modification of data used with the library, allowing malicious actors to break sshd authentication and gain access to affected systems. The situation is developing and more vulnerabilities could be discovered. https://www.techspot.com/news/102456-linux-could-have-brought-down-backdoor-found-widely.html
https://restic.net is a modern backup program that can back up your files:
from Linux, BSD, Mac and Windows
This article looks at how GitHub entered the market, what existed before, and what gap GitHub filled.
https://graphite.dev/blog/github-monopoly-on-code-hosting
In a study, students who learned to code with AI made more progress during training sessions, had significantly higher correctness scores, and retained more of what they learned compared to students who didn't learn with AI.
https://austinhenley.com/blog/learningwithai.html
https://mojocss.com The Atomic CSS Framework for crafting gorgeous UIs without shipping any CSS.
Читать полностью…