|
1825 Monetary Lane Suite #104 Carrollton, TX
Do a presentation at NTLUG.
What is the Linux Installation Project?
Real companies using Linux!
Not just for business anymore.
Providing ready to run platforms on Linux
|
Show Descriptions... (Show All/All+Images)
(Single Column)

- [$] An operations structure for swap devices
One of the ideas raised at the 2026 LinuxStorage, Filesystem, Memory Management, and BPF Summit (LSFMM+BPF) wasthe creation of anoperations structure for the swap subsystem. Like many parts of thekernel, the swap layer evolved over time, with pieces being added asneeded; the end result of this evolution is rarely what one would expecthad the subsystem been designed today. The interface between the swaplayer and the devices it uses is just one example. It appears that oneresult of the swap subsystem's evolution — the lack of an abstraction layerto interface with underlying storage — will soon be addressed, but in adifferent way than was initially envisioned.
- Codeberg: Protecting our FLOSS commons from LLMs
The Codeberg forge has adopted a pair of new policies, promising not to usehosted projects to train LLMs and, more controversially, banning thehosting of LLM-generated software. The site's blog describesand justifies these policies. Although often well intentioned, sharing the result of a prompt and calling it "libre software" does not make the world a better place. Codeberg is not and does not want to be a place to dump such generated single-use software that no one else will ever look at. We are a place for people to collaborate and improve software together. Within this context, the recent votes can be understood as a reconfirmation of those principles: As we want to center on human collaboration, we will not actively support or engage in the creation of LLMs and will not put our limited resources to use for storing single-use software that would pollute our FLOSS commons.
- Security updates for Thursday
Security updates have been issued by AlmaLinux (acl, dogtag-pki, dovecot, glibc, go-toolset:rhel8, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd:2.4, javapackages-tools:201801, libtiff, mariadb-connector-c, perl-HTTP-Daemon, pki-deps:10.6, and sssd), Debian (bind9, chromium, firefox-esr, and pdns-recursor), Fedora (chromium, collectl, fractal, kernel, libssh, llvm, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, perl-DBI, perl-YAML-Syck, and srt), SUSE (7zip, GraphicsMagick, ImageMagick, multipath-tools, perl-YAML, python-sqlparse, python3-sqlparse, python313-bleach, and sssd), and Ubuntu (apache2, commons-beanutils, exim4, gawk, giflib, gst-plugins-good1.0, krb5, libapache-mod-jk, libarchive, libgphoto2, libhtml-parser-perl, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-ibm, linux-nvidia, linux-fips, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oracle, linux-ibm, linux-oracle, linux-ibm-5.15, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-oem-6.17, linux-oracle-6.8, python-aiohttp, and tar).
- [$] LWN.net Weekly Edition for July 23, 2026
Inside this week's LWN.net Weekly Edition: Front: LLMs in the kernel; GNOME save and restore; Fedora changes; BPF and tracepoints; BPF and LSMs; famfs; sched_ext. Briefs: GNOME security; PyPI policy; Arch on aarch64; Firefox 153; Quotes; ... Announcements: Newsletters, conferences, security updates, patches, and more.
- [$] Save and restore may be coming to GNOME
One of the features that users often miss when moving from X11 to Wayland isthe ability to save and restore the position of windows between sessions. At GUADEC 2026, held inA Coruña, Spain, Adrian Vovk provided an overview of work that has goneinto providing a platform-wide save and restore framework for GNOME. After twofailed attempts at landing an API, he believes that the third try will be theone to succeed—though not in time for the upcoming GNOME 51 releasedue in October.
- PyPI now rejects new files after 14 days
Python Software Foundation security developer-in-residence SethLarson has announcedthat the Python Package Index (PyPI) will now reject new files thatare uploaded to releases older than 14 days. The restriction is toprevent the poisoning of old releases if publishing tokens orworkflows of PyPI projects are compromised.
The discussionof this behavior began during PEP 740 (Digital Attestations) back in January2024. The discussion was restartedin March 2026 after the popular packages LiteLLMand Telnyx were compromised. These packages were compromised due to a "mutablereference" in these projects' usage of the Trivy GitHub Action.
Originally the discussion stalled due to some projects depending on this behaviorto add support for new Python versions to already-published releases. To quantify howdisruptive this change would be to existing workflows, the PyPI database was queriedfor projectsthat have published new files to old releases (bucketed by number of days sincethe release). Later, specifically cp314 wheels were queried for the top15,000 packages, revealing that only56 projects of 15,000 had published a 3.14-compatible wheel more than 14 daysafter a release was available.
LWN covered the LiteLLM compromisein March.
- Security updates for Wednesday
Security updates have been issued by AlmaLinux (389-ds-base, c-ares, dovecot, freerdp, glib2, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, kernel, kernel-rt, nodejs:22, perl-XML-LibXML, webkit2gtk3, and yggdrasil), Debian (kernel, nss, roundcube, rtpengine, and xz-utils), Fedora (btrbk, kernel, mupdf, nuclei, perl-Crypt-OpenSSL-X509, rust-fern, rust-ifcfg-devname, rust-routinator, rust-rpki, and rust-syslog), Mageia (tig), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, acl, dovecot, glib2, httpd, libtiff, pacemaker, perl-IO-Compress, plexus-utils, python3, and webkit2gtk3), Slackware (libssh and mozilla-firefox), SUSE (acl, avahi, aws-nitro-enclaves-cli, beets, chromium, firefox, go1.25-openssl, ImageMagick, iscsiuio, kernel, kubevirt1.8-container-disk, libgit2-1_9, libkrun, libsoup-3_0-0, nghttp2, opam, php7, python-aiohttp, python-tornado6, and vim), and Ubuntu (accountsservice, CUPS, imagemagick, jbig2dec, openssh, and snapd).
- Firefox 153 released
Version153.0 of the Firefox web browser has been released. Notablechanges in this release include a change to the defaultlocal-file-access permissions for extensions, enabling LANrestrictions by default for all users, a visual indicator when a website has access to the user's location, the ability to merge PDFs andadd images as pages within PDFs, as well as experimental support forthe JPEG XL image format.
See thereleasenotes for developers for all changes that affect web developers,and securityadvisories for vulnerabilities fixed in this release.
- [$] Debating the role of large language models in the kernel community
Like many development communities, the kernel community has been strugglingto determine how large language models will be used in its developmentprocess. The news has been dominated recently by a strongly worded missivefrom Linus Torvalds on the subject, but the discussion has been rather morewide-ranging and nuanced than that. Topics that have been consideredrecently include the LLM attribution requirement, code-review tools,dependence on proprietary tools, and whether there is a place for concernsabout the ethics of LLMs.
- Security updates for Tuesday
Security updates have been issued by AlmaLinux (capstone, fence-agents, gimp, glib2, hplip, httpd, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, libtiff, maven:3.8, pacemaker, python3.14, and webkit2gtk3), Debian (samba), Fedora (c-ares, dnsx, freerdp, gpsd, libreswan, libseccomp, libtiff, mingw-python-idna, mingw-python-pip, openssh, python-pillow, wget1, and wireshark), Mageia (golang, graphicsmagick, haveged, libssh2, nginx, nilfs-utils, perl-CGI-Session, perl-Imager, perl-JavaScript-Minifier-XS, php, php8.4, php8.5, python-nltk, sqlite3, and xmlstarlet), Oracle (.NET 10.0, .NET 9.0, container-tools:ol8, firefox, giflib, glibc, go-fdo-client, go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, hplip, httpd, image-builder, kernel, libtiff, mod_http2, pacemaker, perl-DBI:1.641, perl-HTTP-Daemon, php:8.2, python-markdown, ruby4.0, systemd, and thunderbird), Red Hat (buildah, container-tools:rhel8, dracut, golang-github-openprinting-ipp-usb, libtiff, osbuild-composer, python-urllib3, python3.12-urllib3, python3.14-urllib3, and runc), SUSE (389-ds, chromedriver, gstreamer-plugins-bad, libreoffice, libsuricata8_0_6, podman, python311, and sssd), and Ubuntu (apache2, freerdp3, freetype, libde265, libxfont, linux, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-realtime, linux-realtime-6.8, linux, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-realtime, linux-xilinx-zynqmp, linux, linux-gcp, linux-gke, linux-realtime, linux-gcp-6.17, linux-realtime-6.17, linux-gcp-fips, linux-hwe-7.0, linux-nvidia-tegra-5.15, linux-oem-7.0, nginx, php8.1, php8.3, php8.5, rlottie, sqlite3, and wget).
- [$] Fedora grapples with change
The Fedora Project is known for,among other things, having a well-defined set of processes for just abouteverything. It has extensive packagingguidelines that deal with the complexities of creating RPMs to installsoftware, as well as processes for managing the legal questions thatarise around shipping software. Fedora also has a well-defined changeprocess for dealing with self-contained technical changes as well as majorchanges to the distribution, and other issues as they arise. At the moment,though, the project seems to be experiencing a sort of midlife crisis as itre-examines several of its change processes at once to determine if they arestill effective.
- Catanzaro: Some changes to GNOME security tracking
Michael Catanzaro, who has been managing GNOME security issue tracking sinceNovember 2020, has written a blog post that details some changes in how he willbe managing GNOME vulnerability reports from now on due to an increase inAI-generated security reports. He will be switching from a 90-day deadline fordisclosures to 30 days for issues reported on August 1, or later. "Theshorter deadline would probably work better for GNOME even if not for theincrease in AI-generated issue reports."
He also has indicated that he will be stepping away from the task of managingsecurity issue tracking entirely by December 1, 2026, which means that therewill be a gap to fill:
Currently nobody else is tracking GNOME security issues. If you are anexperienced GNOME community member and you are interested in taking over thiswork, let me know and I will help you get started. (Security tracking is not agood task for newcomers.)
This may also be an opportunity to improve our tracking infrastructure. I usea wikipage, but this is fairly primitive and requires considerable manualupkeep. It's easy to forget to update the page when an issue report is closed,for example. Ideally, we would replace the wiki with a proper web app thatdynamically updates based on the actual state of the issue.
- [$] Merging famfs?
The famfs filesystem, which is meant to provide shared access to hugememory-resident files on CXL and otherdevices, returned tothe Linux Storage,Filesystem, Memory Management, and BPF Summit (LSFMM+BPF) in 2026.It was first discussed at LSFMM+BPF 2024 and a new implementation was described at the 2025gathering, but it still has not made its way into the kernel; LWN lookedat a discussion about merging famfs back in April 2026.
- Security updates for Monday
Security updates have been issued by Debian (kernel, libnfs, roundcube, and tiff), Fedora (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-astral_async_zip, spoofdpi, uv, and yq), Mageia (bind, clamav, erlang, libidn, libreoffice, nmap, nodejs, perl-Bytes-Random-Secure, perl-Config-IniFiles, perl-CSS-Minifier-XS, perl-HTML-Parser, perl-Mojolicious, perl-String-Util, python-pydantic-settings, rsync, and upower), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, bind, cockpit, cockpit-image-builder, coreutils, delve, dnsmasq, dovecot, expat, fence-agents, flatpak, frr, gdk-pixbuf2, giflib, glib2, go-fdo-client and go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd, jq, kernel, keylime, krb5, libcap, libexif, libpng, libsndfile, libsolv, libsoup3, libtasn1, libtiff, libxslt, libyang, mariadb10.11, mod_http2, mod_md, opencryptoki, PackageKit, perl-Archive-Tar, perl-IO-Compress, poppler, postfix, postgresql-jdbc, python-urllib3, python3.14, python3.14-pip, python3.14-urllib3, qt6-qtdeclarative, rrdtool, rsync, ruby, ruby4.0, samba, skopeo, thunderbird, valkey, wireshark, xorg-x11-server-Xwayland, and yggdrasil-worker-package-manager), and SUSE (blender, chromium, containerized-data-importer1, cyrus-imapd, go1.26-openssl, gomuks, grafana, gstreamer-plugins-bad, kbfs, kubevirt1.8-container-disk, libxml2, lux, mariadb-connector-c, nginx, opam, openssl-3, oras, perl-DBI, php-composer2, python-django-haystack, python-paramiko, python-weasyprint, python311, python313-Pillow, python315, shibboleth-sp, system-user-zabbix, and wget).

- Sfera Labs ships Strato Pi Plus with quad RS-485 and CAN FD
Sfera Labs has begun shipping the Strato Pi Plus, a DIN-rail industrial edge server based on the Raspberry Pi 4B or Raspberry Pi 5. The system adds a 10–50 V DC power supply, up to four isolated RS-485 interfaces, CAN FD connectivity, and an independent RP2354 microcontroller. According to the Strato Pi Plus documentation, the […]
- Firefox 153 Released with HDR Video, Smarter PDF Tools, Better Privacy, and New Linux Improvements
Mozilla has officially released Firefox 153, bringing another round of improvements to its open-source web browser. The latest version introduces new multimedia capabilities, enhanced PDF editing tools, stronger privacy protections, better support for modern web technologies, and several features aimed at improving the browsing experience across Linux, Windows, and macOS. Firefox 153 became available on the stable release channel on July 21, 2026.
- The "New Normal" Of Audio Quirks Submitted For Linux 7.2-rc5
Linux sound subsystem maintainer Takashi Iwai of SUSE sent out this week's batch of sound fixes that he describes as "A collection of fixes that have been accumulated recently. The amount is still "new normal", but all small fixes. Mostly hardware-specific quirks, but including a few core fixes, too." The "new normal" has been a common phrase recently to reflect the increased tempo of patches as well as security/bug disclosures all due to the increased pace of AI/LLM activity...
- Raspberry Pi launches 10-inch Touch Display 2 with 1200 × 1920 resolution
Raspberry Pi has introduced a 10-inch version of its Touch Display 2, expanding the display family beyond the existing 5-inch and 7-inch models. The new panel provides a 1200 × 1920 resolution, ten-point capacitive touch, and compatibility with the Raspberry Pi 5 and supported Compute Module platforms. The 10.1-inch IPS display uses a native portrait […]
- Distro of the Week: Vendefoul Wolf Excalibur Xfce
And the hits just keep on coming . . . Not only was last week a first for Distro of the Week, we follow up with another first: This time, it's a Spanish distro based on Devuan, complete with its lack of systemd and using XLibre as the default X server. Ladies and gentlemen -- that covers most of you -- welcome to Vendefoul Wolf Excalibur Xfce, this week's Distro of the Week.

- Startup Founders Urge Trump Not to Shut Off Chinese Open Weight AI
Nearly 200 Silicon Valley companies, including Proton and Y Combinator, are urging the Trump administration not to block U.S. access to Chinese open-weight AI models or risk crippling the next generation of U.S. startups. Politico reports: On Wednesday, the newly-formed Little Tech Association sent letters to President Donald Trump, Commerce Secretary Howard Lutnick and others in the administration with its appeal, marking the first coordinated effort by Silicon Valley's wider influential startup community to weigh in on one of the Trump administration's most closely watched AI debates. At issue: whether Washington should restrict access to increasingly powerful open-weight -- meaning, AI models whose weights are publicly available -- AI models released by Chinese companies such as Moonshot AI and Alibaba. "American leadership requires two things: world-leading American open-weight models and continued access for U.S. builders to open models already available worldwide," the startup founders wrote in the letter (PDF) obtained by POLITICO, also sent to Office of Science and Technology Policy Director Michael Kratsios. Instead of broad prohibitions, they argue the government should adopt targeted safeguards. And they warn that banning Americans from downloading Chinese open-weight models wouldn't stop their proliferation -- but would weaken U.S. startups. "There'll be hundreds of companies that instantly die," said Suhail Doshi, founder of AI infrastructure startup Particle and a member of the association, which POLITICO first wrote about exclusively, in an interview. "It's great for Anthropic. We're all going to have to spend money on Anthropic." Last week, the Beijing-based AI company "Moonshot" released a massive new model that reset the AI race overnight, immediately vaulting into the top tier of global AI, beating Anthropic's Fable 5 and OpenAI's GPT-5.6 Sol in front-end coding tests. China's Xi Jinping also used his first appearance at China's World AI Conference to promote a vision of low-cost, broadly accessible AI and call for international cooperation rather than technological rivalry.
 
Read more of this story at Slashdot.
- Researchers Discover First Known Transmissible Cancer In Fish
An anonymous reader quotes a report from CBC News: It's rare that cancerous tumors can spread from one individual to another. But a genetic study suggests that's what's happening with melanoma tumors among catfish in Quebec and the northeastern U.S. The discovery represents the first known transmissible cancer in fish and one of very few transmissible cancers ever found, reported the study published in the journal Nature on Wednesday. Julie Dragon, co-leader of the new study, noted that only three other transmissible cancers have ever been identified so far -- in Tasmanian devils, dogs and shellfish. "These conditions are incredibly rare in nature," she said. "So something has to be happening to allow this to happen." Anglers in Lake Memphremagog, which spans the border between Quebec and Vermont, first reported catching brown bullhead catfish with strange black spots and lumps in 2012. They turned out to be melanoma skin cancer tumors. (Humans can also get this kind of cancer.) Now, about a third of the brown bullheads living in the lake have them. It's not clear how sick the fish become. In some cases, the cancer spreads to other organs, such as the brain or liver. But many fish with lesions seem relatively healthy and some older fish even have them, suggesting they can live with the disease for a time. Because of the sudden appearance of the black lesions in Lake Memphremagog the year after a huge flood caused by post-tropical storm Irene, locals worried they were caused by carcinogens washed into the lake by floodwaters. Tests for carcinogens haven't been conclusive, although a study published in May found higher concentrations of seven metals, including zinc and the carcinogen arsenic, in the skin of fish with the tumors. Researchers suspect the tumors may spread among adult fish during spawning, when crowded fish rub against one another and may be punctured by their spines. "They... swim all over each other and we think it's possible that they poke each other and cells can get into other fish that way," Dragon said, though transmission has not yet been demonstrated.
 
Read more of this story at Slashdot.
- Verisign Is Finally Bringing .web Domains To the Internet
BrianFagioli writes: Verisign is finally bringing web domains to the internet after a decade of fighting. Verisign says the .web top-level domain has finally been delegated into the DNS root, clearing the way for public registrations later in 2026. Until now, consumers could not buy normal working .web domains, despite the extension attracting a record $135 million winning bid in 2016. The launch could make .web one of the more recognizable alternatives to .com, but Verisign already operates both .com and .net, raising questions about whether this creates real competition or simply gives the dominant registry operator another valuable extension. The decade-long fight began after a company called Nu Dot Co won the rights to operate .web in a 2016 ICANN auction with a record $135 million bid secretly funded by Verisign. Rival bidder Afilias, which was later acquired by Donuts, challenged the sale, arguing ICANN should have investigated the relationship before allowing the auction. This triggered years of complaints, reviews, and legal disputes that have ultimately now been resolved under undisclosed terms.
 
Read more of this story at Slashdot.
- Private Mission Launches To Extend Life of Out-of-Gas Communication Satellites
Northrop Grumman has launched a private satellite-servicing mission to attach life-extending "jetpacks" to aging communications satellites in geosynchronous orbit. "It's the second satellite-saving mission to launch this month, all part of a growing, money-saving effort to keep spacecraft running as long as possible," reports Phys.org. From the report: Launched by SpaceX, Northrop Grumman's mission robotic vehicle -- dubbed MRV -- and its jetpacks will spend the next year angling into the proper orbit 22,300 miles (36,000 kilometers) above Earth. Hundreds of satellites orbit at this so-called geosynchronous orbit, where they match the speed of Earth's rotation and keep to the same part of the sky for continuous coverage. Once in place by mid-2027, the minivan-sized spacecraft will use its 10-foot (9-meter) arms to attach a jetpack to an aging communication satellite. Then it will zip off to two more satellites in need. For its debut flight, the spacecraft was accompanied by three electric-propelled jetpacks that peeled away separately following liftoff. Like the MRV, the jetpacks will use their own xenon gas thrusters to get to the desired orbit. Once in place, the jetpacks will wait for the robot to grab them, one at a time, and plug them into their designated satellites. Each jetpack -- the size of a washing machine -- will provide the necessary oomph for an out-of-gas satellite to keep operating for several more years instead of retiring. If it works, it will be a boon for satellite operators SES of Luxembourg and Optus of Australia, saving them millions of dollars in replacement costs.
 
Read more of this story at Slashdot.
- Pan Am Plane Crash That Inspired Modern Safety Briefings Found After 74 Years
Longtime Slashdot reader BeaverCleaver shares a report from the BBC: The wreckage of a Pan American Airways plane has been found 74 years after it plunged into the Atlantic Ocean in a crash that prompted mandatory airline safety briefings. The Clipper Endeavor was found 2,000ft (610m) below sea level off the coast of Puerto Rico with a sonar-equipped drone. It went down on April 11, 1952, following multiple-engine failure shortly after take-off. Everyone onboard survived the impact -- but passengers struggled to locate life vests and rafts as the plane rapidly sank. Of the 69 passengers and crew onboard, just 17 survived. The disaster led to sweeping reforms in aviation safety, including compulsory pre-flight safety briefings on every commercial flight. [...] Today, before every commercial flight, cabin crew are required to outline where a plane's exits are, as well as the location of life vests and how to inflate them.
 
Read more of this story at Slashdot.
- GM Is Quietly Becoming a Subscriptions Company
"General Motors has been pulling a Tim Cook and boosting its software and subscription business," reports Business Insider. During the automaker's Tuesday earnings call, executives said they're increasingly leaning on software subscriptions like OnStar and Super Cruise to generate high-margin recurring revenue long after customers buy their vehicles. GM says OnStar brought in about $800 million in the second quarter, while Super Cruise revenue grew about 70% year over year. From the report: GM says its software business keeps roughly 70 cents of every dollar it brings in. That's a rare level of profitability in the auto industry, as many car sales generate just four to 10 cents per sales dollar. [...] GM expects to add about 1 million OnStar subscribers this year, bringing the total close to 13 million. Super Cruise, GM's hands-free, eyes-on driving system, is growing even faster. GM added about 70,000 subscribers during the quarter and expects to end the year with more than 850,000. Revenue from the service increased about 70% from a year earlier. And a lot of drivers are sticking around after the free period ends. GM said between 30% and 40% of eligible owners continue paying after their included three-year Super Cruise subscription expires. [..] "We do think we have tremendous levers, multiple levers of growth," Barra said on the call. "We definitely think there's a lot of opportunity at GM to grow, improve margins, and become less cyclical." "Software and services are becoming increasingly important to how customers experience GM vehicles and how we deliver value beyond the initial purchase," a spokesperson previously told Business Insider. "As vehicles become more software-defined, we can introduce new digital experiences through updates and optional services rather than hardware changes."
 
Read more of this story at Slashdot.
- iOS 27 Code Suggests Apple Could Restrict Leased Devices After Missed Payments
Code found in the iOS 27 beta suggests Apple is developing a system that could restrict leased iPhones when customers fall behind on payments. The discovery follows a recent Bloomberg report that Apple may soon launch a new "Apple Upgrade" leasing program, allowing customers to pay for hardware through monthly installments. 9to5Mac reports: The code describes a system called App Managed Features, which allows an authorized financing or provider app to enroll an iPhone and perform ongoing status checks. If the contract is no longer in good standing, Apple's system services can place the iPhone in "Restricted Mode," which blocks access to most apps until the payment or contract issue is resolved, while keeping a small set of apps available. The fixed allowlist currently found in the iOS 27 beta includes: Accessibility Reader, App Store, Health, Magnifier, Phone, Clock, Settings, Wallet, Passwords, and the Restricted Mode interface itself. Apps that can send critical alerts, such as Messages, Home, and certain medication or safety apps, may also remain accessible. However, the provider appears to have some control over those exceptions. The code does not appear to cancel, suspend, or otherwise modify App Store subscriptions associated with blocked apps. As a result, a subscription could continue billing even while access to its app is restricted. Additionally, there isn't a fixed number of missed payments that automatically triggers the restrictions. The financing provider's app decides when to lock the device based on its own policies. Finally, the new framework also introduces a new type of activation lock called "Partner Finance Lock," which is meant to prevent users from erasing, reselling, or stripping a restricted device for parts.
 
Read more of this story at Slashdot.
- Linux Kernel Team Publishes 432 CVEs In Two Days
Ancient Slashdot reader alanw shares a post from the OSS Security mailing list, where sysadmin Jan Schaumann wonders what to do after the Linux kernel cranked out 432 CVEs in a little over 24 hours: "I understand the position that CVEs were always a flawed way to track or prioritize security changes... But this onslaught really shows it's not feasible to attempt to prioritize individual kernel changes. I'm not sure what to do here going forward." The Register reports: The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldn't be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become "almost entirely unmanageable" due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact "it keeps finding embarrassing bugs." [...] Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isn't one that's readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy. Senior kernel maintainer Greg Kroah-Hartman replied to Jan's post, pushing back on the idea that the kernel's CVE volume is uniquely unmanageable. The kernel isn't special, he argues -- companies everywhere are finally realizing they need to re-evaluate how they update all of their systems and devices, something that's traditionally been "woefully ignored." On the "just always update" approach, Greg says that's precisely what the kernel community endorses: "This is what the kernel developer community recommends and supports. If you want support from us, do this." Can't manage it yourself? Pay a company for support, or "just use Debian or Yocto as their security practices are amazing." He points to Android as proof the approach scales, calling it "the largest deployment of software in the world" -- billions of devices kept updated "with one very-overworked developer guiding it all." As for reviewing every CVE individually, he notes this can be largely automated by intersecting the files a CVE touches with the files you actually build, which typically trims the relevant set "down to about 10% of the overall total" -- the approach enterprise distros already take for their customers. Panic-mode selective patching gets a blunt "Good luck with that!" -- regulations like the EU's Cyber Resilience Act are set to legislate that habit away ("rightfully so," in his view), and "your insurance company might wish to have a talk with you as well." Greg also warns the flood isn't over: "The number of llm-found issues is only on the rise right now, it's going to be a very long 18 months at the least to dig ourselves out of this mess, and people had BETTER be updating their systems all along the way if they expect to be secure in any way." As for the 432-CVE burst itself, he explains it was simply him catching up on a weeks-old, publicly visible review queue over the weekend -- delayed by "a perfect storm of 6 weeks straight of conferences and vacations" -- so it shouldn't have come as a surprise to anyone watching the public git repo.
 
Read more of this story at Slashdot.
- Apple Partners With Klarna To Offer iPhones, Macs On a Subscription Basis
Apple is reportedly launching a Klarna financing deal that will let U.S. customers spread the cost of devices over up to three years, pushing the company closer to a hardware-as-a-service model. "The only thing you don't get under the new arrangement is AppleCare, for which you'll allegedly need to pay extra," notes Computerworld. From the report: The introduction of the scheme gives consumers a way to purchase the company's popular high-end devices when they are introduced -- no doubt,at higher cost -- this fall. [...] A combination of changed customer habits and external threat means the stars are now aligned for hardware-as-a-service models. "Reframing a device as a low monthly payment protects that [upgrade] cadence and allows Apple to start marketing their products as device-as-a-service to consumers, which no other vendor was ever able to do," [IDC analyst Francisco Jeronimo] wrote to me. There is a one-more-thing aspect to this: the products are effectively being leased, a new approach that will give Apple a stronger grip on EOL devices, helping it grab more of them for refurbishment, resale, and recycling. Over time, this will give the company a much stronger grip on the lucrative second-user market that exists around Apple equipment, even while for almost every consumer product we find the life we want is something we can rent, but probably can't afford to own. The other solid reason to take a partnership approach is risk management. Apple had intended to develop its own buy-now, pay-later scheme via Apple Pay Later, but abandoned that plan as it became riskier with rising bank rates. "Also, by backing the program with Klarna rather than reviving the in-house subscription plan it shelved in 2024, Apple captures the demand upside without taking the credit risk onto its own balance sheet," Jeronimo said. "Apple Upgrade lands at precisely the moment Apple needs it," Jeronimo wrote in a note seen by Computerworld. "Having just pushed Mac and iPad prices up on the back of the memory shortage, with iPhone increases widely expected in September -- as well as the new iPhone foldable expected at $2,500 -- Apple's real risk is that rising prices even further can impact the upgrade cycle."
 
Read more of this story at Slashdot.
- The Army Is Burning Through Its AI Tokens
An anonymous reader quotes a report from Wired: A little over a month after the Department of Defense (DOD) bragged that nearly half of its 3.5 million employees were using AI at work, members of the Army's Combat Capabilities Development Command (DEVCOM) received an email informing them that they were burning through tokens, and needed to limit use. "Although the Army CIO announced in May 2026 that they were offering unlimited tokens, by mid-June the Army CIO pool was exhausted of tokens and had to re-establish limits," the email reads. The email goes on to say that although the Army has chosen to renew token usage at "its current levels," it's unclear "if the Army CIO pool will be renewed after 1 Oct." The Army uses Ask Sage, a multimodal generative AI platform where users can run different large language models (LLMs), including Alphabet's Gemini, Meta's Llama, and OpenAI's ChatGPT. "Apparently the whole Army burned through the whole year of tokens for just one service," says an Army employee who spoke to WIRED [...]. The Army employee says that the Army has been pushing its workers to lean into using generative AI. Employees were given an allotment of at least 200,000 tokens per month, according to emails viewed by WIRED, and were automatically allocated more if they burned through their initial allotment. Employees who had signed up for Ask Sage but were not regularly using it would receive emails encouraging them to use more of their allocated tokens. In order to use Ask Sage, the Army had access to 100,000,000 tokens as part of an annual subscription to an "enterprise pack." Tokens represent a unit of output, either in text or image, from an LLM. For the Ask Sage tool, a single token equates to about 3.7 characters, according to documents viewed by WIRED. The Defense Department burned through some 20 billion tokens per day during the 38-day Operation Epic Fury in Iran, according to Breaking Defense. It's unclear if the tokens used by regular DOD employees are drawn from the same pool as those who might be using AI tools on classified or secret information.
 
Read more of this story at Slashdot.
- Microsoft Announces Xbox Backward Compatibility For PC
Microsoft has announced Xbox Backward Compatibility for PC, a new preservation program that will let players run select classic Xbox games on Windows PCs and handhelds like the ROG Xbox Ally. Tom's Hardware reports: "This marks the beginning of a broader effort to preserve XBOX games from the past and bring them to PC over time," the company said in a blog post authored by Xbox "VP next generation" Jason Ronald. Alongside backward compatibility, the company says games will also include new features. The four titles in the announcement are: BLiNX: The Time Sweeper; Conker: Live and Reloaded; Crimson Skies: High Road to Revenge; and Fuzion Frenzy. You can now buy all of these games on PC, and they're also included in all Xbox Game Pass plans. Anyone who already owns these titles digitally on console can also now play them on PC or handheld, with support for Xbox Play Anywhere and Xbox Cloud Gaming. Crucially, this appears to be a digital-only preservation effort, so it won't help anyone who only owns physical copies of these games. Xbox has reportedly been testing a way to digitize physical games as far back as Xbox One, but that hasn't yet materialized yet. Alongside the preserved original gameplay, Xbox claims these games will let users customize graphics settings, with up to 4x resolution scaling, VSync support, Fullscreen and Windowed modes, anisotropic filtering, and enhanced anti-aliasing, with more features to come in the future. Notably, Xbox will add achievements to select original Xbox games on console and PC.
 
Read more of this story at Slashdot.
- Samsung Galaxy Z Fold 8 Announced to Compete With Future iPhone Fold
At a Galaxy Unpacked event in London today, Samsung unveiled a new foldable smartphone designed to compete with the still-unannounced iPhone Fold. Called the Galaxy Z Fold 8, it features a wider 4:3 form factor with a 7.6-inch inner AMOLED display, Snapdragon 8 Elite Gen 5 for Galaxy chip, up to 16GB of RAM and 1TB of storage. "The inner display has enough extra real estate for multi-tasking and entertainment," reports Mashable, which got a chance to try the new foldable ahead of the event. "And if you're worried about a crease in the middle of the display, don't be. We got up close with the device, and the crease fully disappears when the display is activated." From the report: As stated above, the main distinguishing factor of the new Z Fold 8 is its wider 4:3 proportions compared to the Z Fold 8 Ultra. If the latter is a book-style foldable, the former can almost be called a tablet-style foldable, instead. We think the wide screen will serve even better for reading books or multi-tasking with several apps open at once. Also, at 201g, Samsung is really emphasizing how light the device is. The company is calling it the "world's lightest fold ever." And while the device may be light, its no lightweight. Samsung's newest foldable features Flex Titanium technology, which makes the Galaxy Z Fold 8 more durable. Speaking of durability, it also boasts Samsung's advantage hinge technology, Armor Flexhinge. The Z Fold 8 feels like a solid middle point between the premium Z Fold 8 Ultra and the comparatively affordable Z Flip 8. All three phones use the same chip, but the Z Fold 8's 4,800mAh battery is smaller than that of the Z Fold 8 Ultra. However, the Z Fold 8 does have an option for 16GB RAM and 1TB of storage, similar to the Ultra.
 
Read more of this story at Slashdot.
- LG To Ban Residential Proxies From Smart TV Apps
An anonymous reader quotes a report from KrebsOnSecurity: The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV. On July 2, [KrebsOnSecurity] featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one's television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung's Tizen operating system had similar residential proxy components. Responding to questions about Spur's research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended. "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor said. "If this option is not removed, these apps will be suspended." Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company's review of those apps is "well underway now." "As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor wrote in an emailed statement. [...] "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Spur's Trevor Sutter wrote. "The risk is amplified when consent comes from individuals within the household who use the device but shouldn't give consent, such as minors." LG is also facing criticism for monitors that automatically install software promoting paid McAfee subscriptions through Windows Update without user approval.
 
Read more of this story at Slashdot.
- Jack Dorsey Takes On Slack and GitHub With New AI Workplace Platform 'Buzz'
Jack Dorsey's Block has launched Buzz, an open-source workplace collaboration platform that combines messaging, project management, and software development workflows for teams of both humans and AI agents. Dorsey described Buzz as "a new groupchat platform for teams of people and agents of all sizes" that is "model-agnostic, decentralized, self-sovereign and open source." SmartCompany reports: According to the Buzz website, users can invite specialized AI agents into team chats, allowing them to collaborate with employees and even other AI agents. From there, they can reportedly move directly from discussions into planning, coding, pull requests and project management without switching between multiple applications. Buzz also aims to replace parts of GitHub by bringing software development workflows directly into the platform. Teams can plan work, write code, review pull requests and manage Git projects without jumping between separate collaboration and development tools. [...] In practice, that means businesses aren't locked into a single AI provider. Organisations can self-host Buzz, customize it to suit their own workflows and choose whichever AI models best fit their needs.
 
Read more of this story at Slashdot.
- Long Presumed Dead, a Thriving Coral Reef Is Discovered in West Africa
Scientists have rediscovered a healthy coral reef off the coast of Benin more than 60 years after surveyors first hinted at its existence. "At least eight coral types and eight fish species have formed a thriving ecosystem on this long-forgotten site," reports Inside Climate News. "What they had captured was a wealth of marine life: six types of soft coral; two black corals; and eight species of sheltering fish, from golden African snappers to the Monrovia doctorfish." From the report: While no coral samples have yet been extracted, researchers have classified the site as a mesophotic coral ecosystem (MCE). Such systems are light-dependent communities existing at the lower limits of reef-building corals. At more than 175 feet below the surface, the coral garden they discovered appears patchily scattered on a rocky substrate. Bridging the gap between shallow reefs and deeper benthic habitats, MCEs are home to distinct species and unique environmental conditions. While scientists are increasingly recognizing their ecological and climatic importance, they remain among the least explored elements of tropical and subtropical marine biodiversity. And this one has real potential to unlock new information about coral history. "Since it's an undisturbed marine ecosystem, it can help through carbon dating or paleoclimatic study to tell us which kind of climate system has occurred here in the past," said [Gerard Zinzindohoue, the project lead for Coral Reefs Rediscovering & Exploration in Benin]. "It's better to know the past to help explain the present, and help know which kind of direction we can take in the future." In addition to the blackbar soldierfish, West African goatfish, and Guinean angelfish filmed darting through the reef, the discovery presents potential conservation claims for other marine life. "We will be advocating for its full protection, perhaps by setting up a marine protected area around it," said [Houangninan Midinoudewa, an oceanographic researcher at the Benin Marine Conservation Club], who specializes in elasmobranchs -- the study of sharks, rays, and skates. Midinoudewa is currently submitting an application to designate the area as an Important Shark and Ray Area with the International Union for Conservation of Nature. Based on the knowledge of local fishermen, Midinoudewa is confident the reef is home to sawback angel sharks, silky sharks, brown skates, and marbled stingrays. The team behind the discovery hopes this will spark a wave of similar discoveries in the waters off West Africa, an area of the world underserved by scientific research projects. "I hope the Gulf of Guinea will be a hub for research because we know our resources are being exploited and people [need to] know exactly what we have and why we should care," said Midinoudewa. Zinzindohoue agrees: "We don't need to wait for others to come to our country to show us what is under our sea. We are the ones who must take responsibility."
 
Read more of this story at Slashdot.

- Google Cloud is killing it
It's Alphabet's fastest-growing business and now makes up more than a fifth of the juggernaut's revenue and operating profit

- From DHCP to SZTP – The Trust Revolution
By Juha Holkkola, FusionLayer Group The Dawn of Effortless Connectivity In the transformative years of the late 1990s, a quiet revolution took place, fundamentally altering how we connect to networks. The introduction of DHCP answered a crucial question, Where are you on the network?!, by automating IP address assignment. This innovation eradicated the manual configuration [0]
The post From DHCP to SZTP – The Trust Revolution appeared first on Linux.com.

- dav1d 1.5.4 Brings AV1 Decoding To OS/2
While the VideoLAN developers are busy these days working on dav2d for AV2 video decoding, they haven't let up work on dav1d and recently released dav1d 1.5.4 for continuing to enhance this leading open-source, CPU-based AV1 decoder...
- AMD EPYC Turin With PCIe 5.0 Storage Shows Off Nice Gains On Linux 7.2
Earlier this week was an exciting look at Intel Xe3 graphics performance gains on Linux 7.2 with Intel Core Ultra Series 3 "Panther Lake" hardware. On the other side of the table, with AMD hardware on this forthcoming kernel an area to be excited about are some I/O improvements at least for 5th Gen EPYC with speedy PCIe Gen5 NVMe SSD storage.
- libx11-compat Is Working To Implement Xlib Atop SDL For Wayland, macOS, Android
For helping to keep X11 clients running in a modern Linux desktop world with Wayland or even for running on macOS or Android, there is now yet-another option being developed with libx11-compat. The libx11-compat project is working to re-implement the Xlib client library atop SDL2/SDL3 interfaces for allow broad underlying platform coverage...
- Intel Directed Package-Level Thermal Interrupts Slated For Linux 7.3
Back in March Intel software engineers began sending out Linux patches for Directed Package-Level Thermal Interrupts as a new capability with recent Intel processors. This notable efficiency improvement is now queued for introduction in the Linux 7.3 cycle once its merge window opens in a month...
- The "New Normal" Of Audio Quirks Submitted For Linux 7.2-rc5
Linux sound subsystem maintainer Takashi Iwai of SUSE sent out this week's batch of sound fixes that he describes as "A collection of fixes that have been accumulated recently. The amount is still "new normal", but all small fixes. Mostly hardware-specific quirks, but including a few core fixes, too." The "new normal" has been a common phrase recently to reflect the increased tempo of patches as well as security/bug disclosures all due to the increased pace of AI/LLM activity...
- Qualcomm Posts Linux Patches For X2 Elite Extreme Powered ASUS Zenbook A16
Following recent Linux kernel patches enabling the Snapdragon X2 Elite powered Lenovo Yoga Slim 7x Gen11 and HP EliteBook X G2q X2 Elite laptops to boot outside of Windows 11 on ARM, Qualcomm engineers have now posted a new patch series for getting the X2 Elite Extreme powered ASUS Zenbook A16 working on Linux...
- KDE Plasma 6.7 vs. GNOME Shell 50.3 vs. Xfce 4.20 On CachyOS With NVIDIA Graphics
Earlier this month I provided a look at the KDE Plasma 6.7 Wayland vs. X11 session performance for graphics/gaming on CachyOS using NVIDIA GeForce RTX 50 graphics. Since then Phoronix readers -- including some premium supporters -- requested seeing some additional desktops tested with the latest CachyOS packages. So here we are now with seeing how KDE Plasma 6.7 compared to the Wayland-only GNOME Shell 50.3 desktop as well as the X11-based Xfce 4.20 desktop on CachyOS.
- Canonical Makes The "Enterprise Store" Official For Offline/Air-Gapped Ubuntu Usage
For months the Enterprise Store "enterprise-store" has been mentioned in some Ubuntu documentation and other elements while today it was formally announced by Canonical. The Enterprise Store is for helping to manage Ubuntu Linux deployments particularly within enterprise organizations that may have their computers air-gapped or otherwise strict Internet controls...
- Intel Compute Runtime Continues Building Out Exciting "LEO"
Going in-step with last week's release of the Intel Graphics Compiler 2.38.2, out today is the Intel Compute Runtime 26.27.39122.11. Most intriguing with the new release is Intel continuing to build out the still-experimental LEO feature...
- InputPlumber 0.78 Released With Expanded Hardware Support
InputPlumber is out with its newest feature release. As a reminder, InputPlumber is the open-source input router and remapper daemon for combining various input devices from gamepads to mice and keyboards as well as the ability to emulate them...
- Intel Expanding Memory Options For Current Xeon 6 / Xeon 6+ Servers
With Intel's next-generation Xeon Diamond Rapids processors not slated to launch until next year and with AMD EPYC Venice being right around the corner, Intel announced today that with upcoming BIOS updates they will be expanding the range of RDIMM and MRDIMM memory support for current-generation Xeon 6 and Xeon 6+ processors...
- AMD Talks Up The Great Opportunities Of SPIR-V IR With ROCm
While AMD ROCm 7.14 released last week as the first production release built off TheRock, there is already more to look forward to moving into the future with the AMD ROCm stack... In particular, SPIR-V with ROCm becoming a reality for unified binaries that can work across graphics architectures/targets, better portability across GPU hardware, and other improvements to the experience in targeting a unified IR...
- Linux Patches Introduce "KNOD" For In-Kernel Network Offloading Directly To AMD GPUs
Some extremely cool patches were posted to the Linux kernel mailing list on Sunday. The patches for "KNOD" allow for in-kernel network offloading to GPUs with an initial focus on AMD GPU support. What makes this all the more nifty is that it doesn't depend upon any user-space libraries like AMD ROCm but is all handled in-kernel with driving the GPU directly...
- openSUSE Seeking Additional Corporate Sponsors
While openSUSE is closely aligned with SUSE as a company, they aren't the exclusive sponsor of this free and open-source Linux distribution with its rolling-release Tumbleweed and Leap stable releases. AMD has been a longtime major supporter of openSUSE and the Fastly content delivery company has been another platinum sponsor too besides SUSE. There are also various other lower-tier sponsors while today the openSUSE Project put out a call for further corporate sponsorship...

- Amiga 1000: ten years ahead of its time
We all know the original Amiga was far ahead of its time, and the Amiga really doesnt need more retrospectives and glazing. However, that doesnt mean we dont want more Amiga retrospectives and glazing. I’m not sure I even saw an Amiga in person until 1987, but I knew just from reading about it that I wanted one. I wasn’t able to make it happen until 1991, so I was pretty late to the game. But even in 1991, an Amiga felt like living in the future. I could load several programs and switch between them effortlessly, with the only limit being the amount of memory I had. I could connect to a BBS with a terminal program, start a download, then switch it to the background, fire up a word processor, and do my homework while the download was happening. In some cases, I could even fire up a game and play a game while a download happened in the background. I could download stuff while I played Civilization, which was pretty great. ↫ David L. Farquhar Its 2026, I have an incredibly powerful Linux gaming computer, but since I grew up on DOS and Windows, to this day, I still feel the need the close every other application before launching a game. I dont need to modern operating systems handle such things just fine, mostly but its so ingrained in me its hard to drop this habit. I wonder if people who grew up with more capable computers than whatever DOS nonsense I grew up with are less inclined to do things like this? Or did memory constraints act as an equaliser? Anyway, the linked article doesnt mention it, but the Amiga is still, somehow, going relatively strong for a platform thats supposed to be dead. Modern(-ish) hardware is getting a bit harder to come by, but AmigaOS 4 and especially MorphOS are still actively being developed, and even running them in virtual machines on x86 has become about as easy as it could be.
- Rewriting the Futhark type checker
This post is about the evolution of Futhark’s type checker, motivated by a large refactoring I am about to merge. It is probably mostly of interest to other language designers, and contains some lessons I wish I had known when we first got started although I am not particularly well-read in the type checking literature, so it’s possible all of this is old hat. ↫ The Futhark Programming Language blog Thats a clear introduction you know what to expect.
- COSMIC DE’s first seven months
Honestly, it feels like only yesterday that System76, Linux OEM and the company behind pop!_OS, announced it was going to develop its own desktop environment, COSMIC. Were about seven months into the more general availability of COSMIC, and the company has put up a nice overview of the various improvements that have already made their way into the code since then. Of course, theres a ton of visual improvements have been made to COSMIC, as well as a slew of new features: improved search, a brand new system monitor, drag and drop for tabs throughout COSMIC, and much more. COSMICs file manager and terminal have also seen a lot of work, with a ton of new small features and additions to bring them up to par with what people expect form a modern file manager and terminal emulator. Theres a ton more listed in the article, so it serves as a nice while you were away! if youve not been following development.
- Codebergs programmer user base overwhelmingly votes to ban slopcoded projects from its platform
What happens when programmers get to vote on a complete ban on slopcoded software on their code platform? Members of Codeberg were asked to vote on a proposal to completely ban slopcoded projects from Codeberg, and in what should not be a surprising outcome to anyone not overcome with AI! hysteria, the vast majority voted in favour of the complete ban: over 70% of Codeberg members voted to ban slopcoded projects entirely (358 in favour, 144 against, 14 abstentions). Of course, this is not a surprising outcome. Stripped down, programming is a form of artistic expression, and programming is no different than writing, painting, composing, or any other artistic endeavour. I think its safe to say writers, painters, composers, and similar creatives are against AI!, so its only natural programmers feel the same; poll after poll shows the overwhelming majority of respondents usually well over 70-80% are against AI!. The pro- AI! accounts on OSNews often try to paint my anti- AI! position as extremist, but in reality, Im just voicing how 70-80% of people clearly state they feel. I have zero skin in this game, zero outside pressure to please any bosses to get that promotion, zero pressure to conform to avoid getting laid off, zero pressure to not contradict upper-management. I can speak freely, openly, and without fear of retaliation. And as Nikhil Suresh explains in his harrowing from-the-trenches article AI Mania Is Eviscerating Global Decision-Making, thats a massive asset. The vast majority of people including your friends, family, and co-workers really hate AI!. You can either accept this, or be left behind.
- Building an AmigaOS Development Environment in 2026
If you want to develop an application for AmigaOS 3.x but dont want to deal with real hardware, virtualisation and emulation are your friends. Apropos of nothing, I decided to set up an Amiga development environment. Since figuring things out wasnt straightforward, I wrote down instructions for Linux about how to compile the first program and run it in an emulator. Enjoy! ↫ Daniel Kochmański Its a great guide, easy to follow, and youll be up and running quickly. The emulator the guide uses AmiBerry, a fork of WinUAE contains slopcode, so you may want to consider alternatives. This doesnt change much for the guide though, as whatever tasks you need to do outside and inside AmigaOS itself remain unchanged.
- Volkswagen blocks custom Android ROM users from VW application
Drivers of cars from the Volkswagen Group using alternative Android versions like GrapheneOS, LineageOS, or /e/OS have been unable to use the VW app for some time. This means they can neither check their vehicles remaining range from their phone, schedule service appointments, nor control charging and air conditioning. The car manufacturer has made changes to the apps backend that only allow devices with Googles pre-installed Play Services. When asked by heise online, VW stated that affected users should not expect a timely reopening. “However, they are looking into it.” ↫ Andreas Floemer at Heise.de Clearly, this should be illegal. Then again, that has never stopped Volkswagen before.
- Happy companies are all alike; every unhappy company is unhappy in its own way
Sam Altman seems to be making OpenAI way more non-profit than before: Even as the AI bubble becomes a mainstream talking point on Wall Street, tech companies continue to peddle the fantasy that AI is poised to become an almost magical money-maker. Case in point, OpenAI wants you to believe that by 2030, it’ll be raking in $100 billion a year just from ads alone — even though it’s currently struggling to reach just $1 billion. ↫ Joe Wilkins at Futurism The US tech giants fueling this AI! bubble are trying to hide the true extent of their debt: Hidden debt at U.S. tech giants swelled eightfold in four years to an estimated $1.65 trillion as artificial intelligence investments ballooned, a Nikkei study shows, exceeding actual debt and making it tougher for investors to assess risk. The five companies hidden debt, which does not appear on balance sheets, totaled $1.65 trillion in the most recent quarter, exceeding the roughly $1.35 trillion in debt reflected on their balance sheets. The data includes some estimates. ↫ Kohei Yamada at Nikkei Asia The bubble is expanding to comical proportions: The American stock market is booming, thanks to artificial intelligence. Tech giants are borrowing billions to acquire AI talent, purchase chips and hardware, and construct data centers. And market watchers are starting to get worried. They see financiers bulldozing giant piles of money to private AI start-ups with no realistic path to profitability, tech companies reliant on other tech companies for revenue growth, and non-tech businesses without a lot to show for their AI investments. The value of AI-linked firms has climbed $27 trillion in the past three years—an astonishing amount, equivalent to 36 percent of the value of the entire U.S. stock market today. Although future earnings could justify those valuations, as Dominic Wilson and Vickie Chang of Goldman Sachs argued in a note to clients, the profit expectations require Panglossian optimism. No less an authority than Sam Altman is arguing that we are in an AI bubble. The International Monetary Fund is citing it as a significant risk to financial stability and warning about what might happen when it bursts: diminished investment, tighter credit, reduced consumption, disrupted trade flows. ↫ Annie Lowrey at The Atlantic Im not worried, though. I have it on good authority that AI! increases productivity by 10x, so surely, none of the above is a problem. Any day now, we will be inundated with waves of brand new, high-quality, valuable software. Any day now, existing software will increase in quality by 10x, leading to a huge surge in software sales. Any day now, productivity in factories will increase rapidly thanks to AI! freeing up workers time, driving prices down 10x, leaving consumers with 10x more money to spend. Any day now, everyone will be able to produce the next Citizen Kane or write the next Anna Karenina, causing an explosion in magnificent, timeless art that will have historians of the future marvel at our civilisations ingenuity and artistry. In the meantime, these companies can just ask their AI! how to become profitable. Should be table-stakes for a 10x force multiplier. Im not worried.
- Regressive JPEGs
One of the cool features of JPEG files is that theres the option to save low frequency components first. This means that a partially downloaded image will be displayed at low resolution instead of being cut off. ↫ maurycyz.com Oh I know where this is going0 Doing this, I can get Chrome to render around 90 frames before giving up. Other browsers like Firefox have more patience, but a 90 scan image seems to work almost everywhere. ↫ maurycyz.com Yes, you can abuse the mentioned feature to create a really odd type of video. Or animation? Well, it allows you to create something resembling a really low-resolution GIF. Useless, yes, but very novel.
- Even Microsoft couldn’t make Windows 11 work well on 8GB of RAM!
The Verge reviewed the latest Surface Laptop, which only comes with 8GB of RAM at a higher price than the previous 16GB model, and they conclude that Windows isnt really usable on 8GB of RAM. Whether thats true or not I do not know I would assume it depends a lot on your usage but this quote from the review I found quite peculiar: I was on a Microsoft Teams call (using the app, not a browser) when the host streamed a brief video, which made the whole laptop hang for several seconds. At the time, I had about 10 Chrome tabs open across two desktops, alongside Slack and Signal — not an obscene level of multitasking. ↫ Antonio G. Di Benedetto at The Verge Excuse me, but that is actually an obscene level of multitasking because every single one of those applications! is a complete Chrome browser. Just in the paragraph above, theres four individual complete Chrome browsers running, with little to no optimisation. Why would anyone be surprised this scenario strains a mere 8GB of RAM? This isnt merely a Windows problem; this is a programmers choosing suboptimal tooling × managers have no idea what theyre doing problem. If Teams, Slack, and Signal had been proper, native applications instead of websites running in terrible frameworks, Windows 11 would have handled this scenario just fine.
- OpenBSD tests WPA3 support
The NLnet Foundations NGI0 Commons Fund supported an effort to add WPA3 support to OpenBSD, and the works payed off. All drivers which support PMF can use WPA3, which are: iwm, iwx, and qwx. So far, I have tested this patch on iwx AX200 only. I will roll out this patch to more of my devices now. Help with testing is welcome. There are both userland and kernel changes involved. ↫ Stefan Sperling Only the second implementation of WPA3 will be supported, which requires some explanation: WPA3 has a complicated history. There are two versions of WPA3. The initially standardized version suffered from side-channel leaks found by Mathy Vanhoef and dubbed Dragonblood . A revised and fixed version has been standardized and is mandatory in the 6 GHz band as of Wifi 6e (11ax) and mandatory on all bands as of Wifi 7 (11be). ↫ Stefan Sperling Obviously, WPA3 is a very welcome addition to OpenBSD.
- DOSBox ported to OpenVMS for Alpha
Speaking of OpenVMS and Alpha and we like speaking about OpenVMS and Alpha, dont we? theres now a port of DOSBox that runs on the Alpha version venerable operating system. Astr0baby has published both binaries and source code for the port, as well as a lovely set of screenshots to show it off working.
- LG monitors silently install software through Windows Update without user consent
Well, this is new but not at all unexpected considering the state of Windows and the wider technology industry. When you connect certain LG monitors to a Windows machine, Windows Update will pull in a bunch of adware promoting antivirus trash. Of course, all done without any consent, because Silicon Valley inherently does not understand nor respect consent. Windows Update first installed LG extension and software component packages. Windows Reliability Monitor showed that LG Monitor App Installer appeared one minute later. The installation did not display a consent prompt or require the user to approve the download. Gamers Nexus tested the application across 32 consecutive system boots. It displayed a McAfee promotion during 31 of them. On the remaining boot, it promoted one of LG’s own monitor utilities. The McAfee popup offered a 30-day trial that would convert into a paid subscription. ↫ WhyCry at VideoCardz Dont use Windows.
- New Intel Itanium emulator boots Itanium version of Windows XP and 2003
It was only a few weeks ago that we got a massively improved Alpha emulator, capable of running VMS, Windows 2000, and Tru64, including X11 support and a variety of other exciting features. Today, weve got another major emulation milestone (update: sadly, with AI! support, so odds are this will fizzle out. Bummer!). The emulation space is going crazy, after my previous post on Windows booting on DEC Alpha es40 emulator, there is now another huge breakthrough in the emulation of other non-x86 CPU emulation. Yufeng Gao with help from gdwnldsKSC (the man behind the updated es40-fork) has released version 0.1 of his Intel Itanium (IA-64) emulator that boots the Itanium version of Windows Server 2003 and Windows XP 64-bit. No OpenVMS or HP-UX yet and Linux/BSD also dont boot. But Windows is amazing already. ↫ Remy van Elst Much like Alpha hardware, Itanium hardware is quite hard to come by especially Itanium workstations are a nightmare to find; I think Ive only ever seen one or two Itanium workstation come up for sale on eBay in recent years, and their rarity obviously commanded hefty prices. The sooner we are able to run Itanium version of operating systems comfortably in a virtualised environment the better. As long-time OSNews readers know, my heart beats for HP-UX, but the Itanium versions of Windows and VMS would be of more interest to most people, Im sure. Excellent news.
- Follow the money, especially in open source
Linus Torvalds, the creator of the Linux kernel and git, is employed by the Linux Foundation. This Foundation is a non-profit organisation dedicated to, as the name obviously implies, the promotion of Linux. The primary use of the funds it collects is to help fund the infrastructure and fellows, including Linus Torvalds, who help develop the Linux kernel!. The list of megacorporations donating most of the Foundations funds is long. The Linux Foundation has twelve platinum members, which donate $500000 per year, followed by twelve gold members, who donate $100000 per year. Below these two primary tiers lie the silver peasants, who each donate $5000-$25000 per year, based on number of employees. Looking at the list of twelve platinum members, I noticed something interesting. Of the twelve platinum companies, six are AI! companies or companies with massive investments in AI!: Google, Huawei, Facebook, Microsoft, Oracle, and IBM/Red Hat. Then theres Samsung Electronics, which is raking in stupendous amounts of money thanks to the AI! bubble. Additionally, one of the gold members is Anthropic, another major AI! company and makers of Claude!, the sloppiest of slopcoding tools. Many of these companies are unimaginably deep in the red when it comes to AI!, with very little indication theyre ever going to be able to recover any of it. The situation is particularly bad for Oracle and IBM/Red Hat. Oracles debt has been downgraded to one notch above junk status because of its AI! spending, while IBMs shares experienced the largest crash in its 115 year history only a few days ago. By the way, in the first half of 2025, AI-related capital expenditures contributed 1.1% to GDP growth, outpacing the U.S. consumer as an engine of expansion!. Fun fact: since most of The Netherlands is effectively a swamp, most of the countrys buildings are built on massive wooden or concrete poles (piles) hammered deep into the ground until they hit something more stable than mushy clay and wet sand. Otherwise, buildings in the country would simply sink into the ground. Every Dutch person who ever lived near a construction site has heard the rhythmic kathunk, kathunk, kathunk, all day long, as the massive piledriver machines spread their gospel. I guess something reminded me of this just now. Anyway, a large chunk of the funding the Linux Foundation, Linus Torvalds employer, receives is coming from increasingly desperate companies frantically trying to convince a populace deeply skeptical and often downright hostile towards AI! to spend money on AI! before the bubble bursts. For some reason, I thought this was interesting.
- The Zilog Z80 has turned 50
As of writing, the Zilog Z80 processor was officially launched 50 years ago, in July of 1976, less than 4 years after the last human had walked on the moon, decades closer to WWII than to the present day, roughly at a half way point between the Kennedy assassination and the fall of the Berlin wall, closer to the Korean war than to 9/11 which is itself an event that happened a quarter of a century ago. (Sorry…) The processor was extremely successful, being used in many 8 bit microcomputers, including early personal computers, home 8 hobby computers, as well as many embedded, industrial applications. Together with the 8080 8 8085 that it is binary compatible with, it contributed to creating a de facto hardware standard for 8 bit micros, allowing a de facto software standard of CP/M, and Microsoft BASIC. ↫ David Oberhollenzer The only device I actively remember using with a (sort-of) Z80 in it was the Game Boy, but most likely Ive used a ton more over the decades that I dont remember or simply was never ware of. I did a little surface-level digging, and there we are: the TI-83, one of Texas Instruments stupidly popular and eternally overpriced graphing calculators, release in 1996. I was part of the first wave of high school children in The Netherlands for whom a TI-83 graphing calculator was mandatory. During my high school years I used that thing extensively, for far more than just math class I programmed applications for and on it, and played so many games on it. A friend and I even bought a communication cable so we could play competitive 1v1 Bomberman in class. Good times, made possible by the Z80.
- OnePlus exits EU, US markets
Rumours had been circulating for a while, but now its official: OnePlus is effectively retreating from the European and US markets. Today, our hearts are undoubtedly heavy and mixed with emotion. As part of the proactive global strategy adjustment, OnePlus has decided to conclude new product rollouts in Europe and North America. ↫ OnePlus statement Once OnePlus co-founder Carl Pei left the company (and founded Nothing), things have been feeling shaky for OnePlus, once the undisputed darling of the more technical part of the Android crowd. Their phones got more expensive, their minimalist, close-to-stock Android version got progressively worse, and they started lagging in updates, too. My OnePlus Watch 3, for instance, which was promised to get WearOS 6 at some point, but never got it meanwhile, WearOS 7 has already been released. No, this news is not particularly surprising. Luckily, the company claims it will honour its warranty and update support obligations for existing products in Europe and the US, which is nice, but also something theyre legally obligated to do (at least in the EU). A snag here is that the only update path the company offers is to ColorOS, from its parent company Oppo, which many more traditional Android and OnePlus users certainly wont be happy about. Something is better than nothing, I suppose, and Ill reserve judgment until I see what ColorOS 17 will be like on my other OnePlus product, a OnePlus Pad 3. Its just one more victim of western markets (illegally) consolidating on Apple and Samsung (while a few Pixels rummaging in the margins).

- EU OS: A Bold Step Toward Digital Sovereignty for Europe
Image A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem. What Is EU OS? EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.
Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments. The Vision Behind EU OS The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.
Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.
However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty. Conclusion EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.
Source: It's FOSS European Union
- Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight
Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight
Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.
In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.
On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.
Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.
The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.
Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.
You can download the latest kernel here. Linus Torvalds kernel
- AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
Image AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.
This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.
Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.
Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.
Source: 9to5Linux AerynOS
- Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
Image Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.
Here’s a quick overview of what’s new in Xojo 2025r1: 1. Linux ARM IDE Support Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started. 2. Web Drag and Drop One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required! 3. Direct App Store Publishing Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process. 4. New Desktop and Mobile Features This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection. 5. Performance and IDE Enhancements Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced. What Does This Mean for Developers? Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution. How to Get Started Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.
Download Xojo 2025r1 today at xojo.com. Final Thoughts With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you. Xojo ARM
- New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux
Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.
Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.
Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest.
Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.
Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.
Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.
By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem. Windows
- Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities
The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally.
As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.
In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions.
After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.
The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.
At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.
The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca. Security
- Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges
The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.
A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.
This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem.
The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.
On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.
In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers. kernel
- Linux Celebrates 32 Years with the Release of 6.6-rc2 Version
Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.
The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.
Here is what Linus Torvalds had to say in today's announcement: Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds
- Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction
Want to interact with ChatGPT from your Linux desktop without using a web browser?
Bavarder, a new app, allows you to do just that.
Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.
With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.
During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.
At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.
As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!
Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring. ChatGPT AI
- LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite
Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.
Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.
LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.
You can download LibreOffice 7.5.3 directly from the LibreOffice websiteor from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.
All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.
In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.
Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.
The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners. LibreOffice

- Hannah Montana Linux Is Back!
Developer Noah Cagle decided the world needed the once obscure but beloved Linux distribution and gave it a decidedly pink refresh.
- Kubuntu Focus Goes Ultra
The Kubuntu Focus team has upped the performance ante of its M2 and Zr laptops with the latest, greatest CPUs from Intel.
- KDE Linux Drops AUR
KDE Linux developers have dropped the Arch User Repository from the build pipeline due to security concerns; other distributions should consider doing the same.
|