1 393
Subscribers
No data24 hours
-37 days
-1830 days
Posts Archive
1 393
מירנטיס משתפת קוד פתוח לפלטפורמת קורדנט (K0rdent) לניהול קוברנטס (Kubernetes)
מאת | סיליקון ANGLE |
[...] "הראשון הוא כלי הנקרא K0rdent Cluster Manager.
הוא אחראי על הגדרת אשכולות
ה- Kubernetes של החברה, הורדת עדכונים וביצוע משימות תחזוקה אחרות. תכונת התאוששות מאסון מובנית מאפשרת למשתמשים לגבות את נתוני הכלי לתשתית חיצונית ולשחזר אותם במקרה של הפסקה.
מרכיב שני,
מנהל המדיניות (State Manager) הקבוע, מנהל את קבצי התצורה המגדירים את ההתנהגות של אשכול Kubernetes. זה גם מאפשר לחברות להתקין תוכנות חיצוניות באשכולות Kubernetes שלהן.
מרכיב הליבה השלישי
של k0rdent הוא כלי צפייה שעוקב אחר בעיות טכניות ושומר יומני פעילות מערכת. כמה מהתכונות של k0rdent מופעלות על ידי Cluster API, תת-פרויקט בבסיס הקוד של Kubernetes.
ה-אי.פי.איי קלוסטר (Cluster API) הופך אוטומטית חלק מהעבודה הידנית הכרוכה בשינוי הגדרות התצורה של מיכל האשכול (container cluster’s) זה חוסך זמן למנהלים ומפחית את הסיכון לטעויות אנוש.
מירנטיס (Mirantis) אומרת ש-k0rdent יכול לנהל אשכולות Kubernetes הפרוסים בענן, במקום ובמיקומי קצה.
החברה בדקה את הפלטפורמה במספר שירותי אינטרנט של אמזון ושירותי Azure, כמו גם היפרוויזר vSphere של VMware LLC
ו- OpenStack.
לפי מירנטיס, ל- k0rdent עיצוב הניתן להרחבה המאפשר למשתמשים להוסיף תמיכה עבור סוגי תשתית נוספים בקלות יחסית.
"בזמן שבו ארכיטקטורת התוכנה, כלי הפיתוח והשירותים הופכים מורכבים יותר ויותר, אנו חולקים את פרויקט הקוד הפתוח k0rdent כדי לספק יכולות שמאיצות חדשנות עבור עומסי עבודה מבוזרים מודרניים." אמר מנכ"ל מירנטיס אלכס פרידלנד.צילום: Unsplash" [...] דרך | @OSPopenSourcePlanet |
1 393
Mirantis open-sources k0rdent Kubernetes management platform
By | SiliconANGLE |
[...] "The first is a tool called the k0rdent Cluster Manager. It’s responsible for configuring a company’s Kubernetes clusters, downloading updates and performing other maintenance tasks.
A built-in disaster recovery feature allows users to back up the tool’s data to external infrastructure and recover it in the event of an outage.
A second component, the k0rdent State Manager,
manages the configuration files that define a Kubernetes cluster’s behavior.
It also enables companies to install external software on their Kubernetes clusters.
The third core component of k0rdent is an observability tool that monitors for technical issues and saves system activity logs.
Several of k0rdent’s features are powered by Cluster API, a sub-project in the Kubernetes code base.
Cluster API automates some of the manual work involved in changing a container cluster’s configuration settings. That saves time for administrators and reduces the risk of human error.
Mirantis says k0rdent can manage Kubernetes clusters deployed in the cloud, on-premises and at edge locations.
The company has tested the platform on multiple Amazon Web Services and Azure services, as well as VMware LLC’s vSphere hypervisor and OpenStack.
According to Mirantis, k0rdent has an extensible design that enables users to add support for more infrastructure types with relative ease.
“At a time when software architecture, development tools, and services are becoming increasingly complex, we are sharing the k0rdent open source project to deliver capabilities that accelerates innovation for modern distributed workloads,” said Mirantis Chief Executive Officer Alex Freedland.Photo: Unsplash " [...] Via | @OSPopenSourcePlanet |
1 393
באד-די.אנ.אס (BadDNS): כלי קוד פתוח בודק תת-דומיין
השתלטות
מאת | עזרה נט אבטחה |
[...] " באד-די.אנ.אס (BadDNS) מטפל בפער הזה על ידי אוטומציה של עדכוני חתימות מהמקורות הידועים ביותר.
הגדרנו צינורות (pipelines) לגיט-האב כדי למשוך אוטומטית חתימות חדשות מ-Nuclei ו- DNS Reaper, המרנו אותם לפורמטים תואמים באד-די.אנ.אס (BadDNS), בדקנו אותם, ויצרנו בקשות משיכה לבדיקה.
זה מאפשר לנו לא לפגר, אבל גם לא לקחת על עצמנו את האחריות (שאין לנו כוח אדם לה) להיות הסמכות הבלעדית לחתימות האחרונות.
בנוסף לטכניקות השתלטות מאושרות, באד-די.אנ.אס (BadDNS) מסמן כל רשומה משתלשלת - בין אם קיימת טכניקת ניצול ידועה או לא.
זה מספק בסיס למחקר נוסף על השתלטויות חדשות שאולי עדיין אין להם חתימות, או שעשויים להתקיים בתשתיות פנימיות מותאמות אישית של החברה", סיכם.
תוכניות עתידיות והורדה
"סביר להניח שבסופו של דבר נתמוך בסוגי רשומות DNS נוספים, כגון רשומות PTR ,CAA ו- SRV, כדי לטפל בסיכונים הייחודיים הקשורים לסוגי רשומות שגובשו בצורה שגויה.
אנו עשויים גם להוסיף תכונות כדי לזהות פגיעויות הקשורות ל-DNSSEC
כמו חתימות DNSSEC חלשות או שאינן מוגדרות כהלכה",
סיכם מולר.
באד-די.אנ.אס (BadDNS) זמין בחינם ב- גיט-האב (GitHub)." [...]
דרך | @OSPopenSourcePlanet |
1 393
BadDNS: Open-source tool checks for subdomain
takeovers
By | HELP NET SECURITY |
[...] "BadDNS addresses this gap by automating signature updates from the best-known sources.
We’ve set up GitHub pipelines to automatically pull new signatures from Nuclei and DNS Reaper, convert them to BadDNS-compatible formats, test them, and create pull requests for review.
This allows us to not fall behind, but also not take on the responsibility ourselves (which we don’t have the manpower for) of being the sole authority for the latest signatures.
In addition to confirmed takeover techniques, BadDNS flags any dangling records—whether a known exploitation technique exists or not.
This provides a foundation for further research into new takeovers which might not have signatures yet,
or which may exist in custom internal company infrastructures,” he concluded.
Future plans and download
“We will likely eventually support additional DNS record types, such as PTR, CAA, and SRV records, to address the unique risks associated with misconfigured record types.
We may also add features to detect DNSSEC-related vulnerabilities
like weak or improperly configured DNSSEC signatures,”
Mueller concluded.
BadDNS is available for free on GitHub." [...]
Via | @OSPopenSourcePlanet |
1 393
האקרים מלזרוס הצפון קוריאנים משיקים מתקפת סייבר בקנה מידה גדול על ידי שיבוט תוכנות קוד פתוח
מאת | Sead Fadilpašić |
[...] "המאגרים שהשתנו כללו ככל הנראה Codementor, CoinProperty, Web3 E-Store, מנהל סיסמאות מבוסב פייתון, ו"אפליקציות אחרות הקשורות למטבעות קריפטוגרפיים, חבילות אימות, ותכנולוגיות ווב3 (web3)", מצוטט ריאן שרסטוביטוף, סמנכ"ל בכיר למחקר ומודיעין איומים ב- SecurityScorecard.החוקרים לא אמרו אם לזרוס השתמשו בגונב-מידע (infostealer) ידוע בקמפיין הזה, או יצרו קוד חדש מאפס. הקבוצה ידועה בשימוש במגוון רחב של כלים בהתקפות שלה. לזרוס מכוונת לעיתים קרובות לחברות מטבעות קריפטוגרפיים. כמה חוקרים אומרים שהמדינה עוסקת בגניבת קריפטו כדי לממן את מנגנון המדינה שלה, כמו גם את תוכנית הנשק שלה." [...] דרך | @OSPopenSourcePlanet |
1 393
North Korean Lazarus hackers launch large-scale cyberattack by cloning open source software
By | Sead Fadilpašić |
[...] "The modified repositories apparently included Codementor, CoinProperty, Web3 E-Store, a Python-based password manager, and “other cryptocurrency-related apps, authentication packages, and web3 technologies”, citing Ryan Sherstobitoff, senior VP of research and threat intelligence at SecurityScorecard.The researchers did not say if Lazarus used any known infostealer in this campaign, or created new code from scratch. The group is known for using a wide variety of tools in their attacks. Lazarus often targets cryptocurrency companies. Some researchers are saying the country is engaging in crypto theft to fund its state apparatus, as well as its weapons program." [...] Via | @OSPopenSourcePlanet |
1 393
עסקת כלי פוטוניקה של OpenLight בקוד פתוח...
מאת | ניק פלהרטי |
[...] "על ידי מתן פלטפורמה מקיפה לתכנון, אב טיפוס וייצור של PICs, אנו מרחיבים את המערכת האקולוגית של סיליקון פוטוניקת על ידי ייעול וצמצום זמן תהליך התכנון, שיפור הדיוק והבטחת התקנים עומדים בדרישות הביצועים והייצור שהן משנות"."הפלטפורמה הטכנולוגית של אופן-לייט (OpenLight) מספקת בסיס חזק לדור הבא של מכשירים בעלי ביצועים גבוהים וחסכוניים באנרגיה", אמר מנכ"ל DoplayDo, טרוי טמאס. "ערכת העיצוב והכלים המתקדמים שלנו יאפשרו לחברות להתחיל בקלות רבה יותר לבנות איתה, עם ביטחון של הצלחה במעבר ראשון. צוות GDSFactory, יחד עם OpenLight, מאפשרים לחברות לעצב בביטחון ולהאיץ את זמן היציאה לשוק בתחום זה המתפתח במהירות." www.openlightphotonics.com ; www.gdsfactory.com ." [...] דרך | @OSPopenSourcePlanet |
1 393
OpenLight in open source photonics tool deal ...
By | Nick Flaherty |
[...] “By providing a comprehensive platform for the design, prototyping and manufacturing of PICs, we’re expanding the silicon photonics ecosystem by streamlining and reducing design process time, improving accuracy and ensuring devices meet performance and manufacturability requirements that are transformative.”“OpenLight’s technology platform provides a strong foundation for the next generation of high-performance, energy-efficient devices,” said DoplayDo’s CEO Troy Tamas. “Our design kit and advanced tooling will enable companies to more easily get started building with it, with the confidence of first-pass success. The GDSFactory team, together with OpenLight, is enabling companies to design with confidence and accelerate their time to market in this rapidly evolving field.” www.openlightphotonics.com; www.gdsfactory.com. " [...] Via | @OSPopenSourcePlanet |
1 393
מסגרת תוכנת השעון החכם של פיבל (Pebble) מייסד פיבל, אריק מיגיקובסקי, צופה לקאמבק
מאת | אלפונסו מרוצ'יה |
[...] " התמונה הגדולה: למרות שפבל כבר מזמן חדלה מלהתקיים כישות מסחרית מתפקדת, המותג ממשיך ליהנות מקהל עוקב נאמן ומקהילה מקוונת תוססת. חובבים השקיעו שנים בשיקום ותחזוקה של פונקציונליות עבור מכשירי פיבל (Pebble), וכעת יש להם אפילו גישה לקוד מערכת ההפעלה המקורי כדי לתמוך במאמצים שלהם.גוגל הודיעה כי PebbleOS זמין כעת להורדה תחת רישיון קוד פתוח, מה שמסמל את תמיכתה למתנדבים שממשיכים לתחזק מכשירי פיבל (Pebble devices). בטוויסט מפתיע, המייסד המקורי של תכנולוגיות פיבל (Pebble Technology) אישר גם הוא את העניין שלו להיכנס מחדש ל"משחק הפיבל" ("Pebble game") במוקדם ולא במאוחר." [...] דרך | @OSPopenSourcePlanet |
1 393
Pebble smartwatch software framework
Pebble founder Eric Migicovsky is eyeing a comeback
By | Alfonso Maruccia |
[...] "THE BIG PICTURE: Though Pebble has long ceased to exist as a functioning commercial entity, the brand continues to enjoy a loyal following and a vibrant online community. Enthusiasts have spent years restoring and maintaining functionality for Pebble devices, and now they even have access to the original OS code to support their efforts.Google has announced that PebbleOS is now available for download under an open-source license, signaling its support for volunteers who continue to maintain Pebble devices. In a surprising twist, Pebble Technology's original founder has also confirmed his interest in re-entering the "Pebble game" sooner rather than later." [...] Via | @OSPopenSourcePlanet |
1 393
אל תתנו לכלי אבטחת הסייבר הללו בקוד פתוח לחמוק מתחת לרדאר שלכם
מאת | HELP NET SECURITY |
"מאמר זה מציג כלי אבטחת סייבר בחינם בקוד פתוח שעוזרים לכםלזהות ולטפל בפרצות, לזהות חדירה, להגן על אתרים מפני התקפות סייבר, לפקח ולזהות פעילויות חשודות ברחבי הרשת שלך." [...] דרך | @OSPopenSourcePlanet |
1 393
Don’t let these open-source cybersecurity tools slip under your radar
By | HELP NET SECURITY |
"This article showcases free, open-source cybersecurity tools that help youIdentify and address vulnerabilities, detect intrusion, Protect websites from cyber attacks, monitor and detect suspicious activities across your network." [...] Via | @OSPopenSourcePlanet |
1 393
שוט-קאט (Shotcut 25.01) עורך וידאו בקוד פתוח מביא תכונות חדשות
נכתב על ידי | מייקל לרבל |
"עורך הווידאו של שוט-קאט (Shotcut) בקוד פתוח יצא עם המהדורה החדשה הראשונה שלו לשנת 2025. עורך הווידאו חוצה הפלטפורמות של שוט-קאט (Shotcut) שבנוי על גבי FFmpeg וכעת בפיתוח לשנתו ה-21 יצא עם מהדורה נחמדה לפתיחת 2025.הגרסה של שוט-קאט (Shotcut 25.01) בעקבות Shotcut 24.11 מביאה את הרעיון של פלייליסט בינס (Playlist Bins) לעורך הווידאו יחד עם סוג מדיה וחיפוש טקסט. ישנה גם יכולת סינון וידאו חדשה של מפת שיפוע, חלונית View-Files, פריימריז חדשים של HSL ומסנני וידאו מטווחי HSL, תמיכה משופרת עבור MLT XML קליפ/תתי פרויקטים ועוד. בנוסף המבחר הרגיל של תיקוני באגים ושיפורים קלים אחרים. אפשרות הייצוא H.265 High Profile של Shotcut 25.01 נמצאת כעת כברירת מחדל להגדרה קבועה מראש באיכות גבוהה יותר.
שוט-קאט 25.01 (Shotcut 25.01) בנוי מעל MLT 7.30 ,Qt 6.8.1 ,OpenCV 4.10 , ועוד מגוון תלויות מעודכנות.הורדות ופרטים נוספים על מהדורת היום של שוט-קאט 25.01 (Shotcut 25.01) של עורך וידאו בקוד פתוח דרך Shotcut.org ." | דרך | @OSPopenSourcePlanet
1 393
Shotcut 25.01 Open-Source Video Editor Brings New Features
Written by | Michael Larabel |
"The Shotcut open-source video editor is out with its first new release of 2025. The Shotcut cross-platform video editor that is built atop FFmpeg and now in development for its 21st year is out with a nice release to kick off 2025.The Shotcut 25.01 release succeeding Shotcut 24.11 brings the notion of Playlist Bins to the video editor along with media type and text searching. There is also a new gradient map video filter capability, a View-Files panel, new HSL primaries and HSL range video filters, improved support for MLT XML clip/sub-projects, and more. Plus the usual assortment of bug fixes and other minor enhancements. Shotcut 25.01's H.265 High Profile export option is also now defaulting to a higher quality preset.
Shotcut 25.01 is built atop MLT 7.30, Qt 6.8.1, OpenCV 4.10, and a variety of other updated dependencies.Downloads and more details on today's Shotcut 25.01 open-source video editor release via Shotcut.org ." | Via | @OSPopenSourcePlanet
1 393
Repost from cRyPtHoN™ INFOSEC (EN)
Fleet: Open-source platform for IT and security teams
Fleet is an open-source platform for IT and security teams managing thousands of computers. It’s designed to work seamlessly with APIs, GitOps, webhooks, and YAML configurations.
Fleet provides a single platform to secure and maintain all computing devices over the air. It offers a centralized solution, from mobile device management (MDM) to patching and verifying systems. It’s trusted in production environments. Deployments range from tens of thousands of hosts to large-scale environments supporting over 400,000 hosts.
https://github.com/fleetdm/fleet
📡@cRyPtHoN_INFOSEC_IT
📡@cRyPtHoN_INFOSEC_FR
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_DE
📡@BlackBox_Archiv
1 393
Repost from A2ZAPK Mod APPS & Mod Games Android - A2ZAPK
NewPipe (Lightweight YouTube) 0.27.5 (XLite Mod)👇
🌚Category: Tools Apps
🌝Size: 5.9 MB
🌚Version: 0.27.5 (XLite Mod)
🌝Requires: 5.0+
📥 Download:👇
https://a2zapk.io/1362210-newpipe-lightweight-youtube-0-27-5-xlite-mod-a2z.html
◉ ACRA (Tracker/Analytics/DataCollection) REMOVED Completely ★
◉ Automatic Update(consent also) DISABLED ★
◉ License REMOVED Completely ★
◉ Privacy Policy Button (& Link) REMOVED
◉ Ads Xml files Patched
◉ No TRACKERS/Analytics and ADS Remains ★
◉ DEBUG Codes REMOVED (including source tags)
◉ LOGGING Classes & Codes REMOVED
◉ Some Kotlin Invocations REMOVED
◉ Apk Root Path Completely CLEANED
◉ Starting at Boot REMOVED - Cleaned Manifest ★
◉ Trash Classes including R and BuildClasses REMOVED
◉ Debugging-Logging & Update Check at Startup REMOVED
◉ CLEANED/OPTIMIZED Startup Method - FASTER App Opening ★
◉ No Obsfuscation added in Nativ
1 393
Repost from Hacker News
F-Droid's Progress and What's Coming in 2025 (Score: 155+ in 9 hours)
Link: https://readhacker.news/s/6mHmW
Comments: https://readhacker.news/c/6mHmW
1 393
Repost from cRyPtHoN™ INFOSEC (EN)
Web Cache Vulnerability Scanner: Open-source tool for detecting web cache poisoning
The Web Cache Vulnerability Scanner (WCVS) is an open-source command-line tool for detecting web cache poisoning and deception.
The scanner, developed by Maximilian Hildebrand, offers extensive support for various web cache poisoning and deception techniques. It features a built-in crawler to discover additional URLs for testing. The tool is designed to adapt to specific web caches for enhanced testing efficiency, is customizable, and integrates into existing CI/CD pipelines.
https://github.com/Hackmanit/Web-Cache-Vulnerability-Scanner
📡@cRyPtHoN_INFOSEC_IT
📡@cRyPtHoN_INFOSEC_FR
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_DE
📡@BlackBox_Archiv
