Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All/All+Images) (Single Column)

LWN.net


  • [$] Reports from OSPM 2026, day three
    The Power Managementand Scheduling in the Linux Kernel Summit, which still goes by thehistorical acronym OSPM, was held in Cambridge, UK, in mid-April. As hasbecome traditional, the presenters at that event have since writtensummaries of their sessions, and this work has kindly been made availableto LWN for publication. The third day's sessions covered a wide range oftopics, including GPU affinity, profile-guided scheduling,paravirtualization scheduling, quality of service, and more.


  • [$] Initiating writeback earlier
    Writeback is the process of ensuring that dirty pages or folios in the pagecache are flushed to the disk, so that changes to those files are madepersistent. In a filesystem-track session at the 2026 Linux Storage,Filesystem, Memory Management, and BPF Summit, Jeff Layton wanted todiscuss whether the writeback operation should be initiated earlier than itis today. The consensus seemed to be that it should be done earlier, butthe path toward making that happen was less clear.


  • Lots of stories about systemd v261
    Lennart Poettering has posted alist of Mastodon posts about the changes in the systemd v261 release.The Mastodon format makes the reading harder, but there is a lot of usefulinformation there.


  • [$] What's coming in Git 2.55
    The Git v2.55.0-rc2testing release appeared on June 23, suggesting that the final Git2.55 release can be expected in the near future. While this Git updatelacks radical new features, it does include a number of improvements thatregular Git users will appreciate, including commands to easily edit thecommit history, more formatting options, fsmonitor support for Linux, andmore.


  • Security updates for Friday
    Security updates have been issued by AlmaLinux (buildah, coreutils, evince, libpng, libreoffice, libtasn1, libxml2, libxslt, nginx, nginx:1.24, nginx:1.26, postgresql:12, python-urllib3, python3.12-urllib3, python3.14, python3.14-urllib3, skopeo, tigervnc, tomcat, and vim), Debian (chromium, dnsdist, giflib, libdbi-perl, libssh2, libtext-csv-xs-perl, pdns, pdns-recursor, python-urllib3, and sogo), Fedora (goose, httpd, librabbitmq, perl-Compress-Raw-Bzip2, perl-DBI, perl-IO-Compress, perl-Socket, python-django-allauth, rsync, and strongswan), Oracle (389-ds-base, buildah, containernetworking-plugins, coreutils, evince, fence-agents, giflib, git-lfs, hplip, krb5, libcap, libexif, libtasn1, memcached, opencryptoki, podman, postfix, postgresql:12, postgresql:13, postgresql:15, postgresql:16, python-urllib3, python3.12-urllib3, python3.14-urllib3, python3.9, runc, skopeo, tigervnc, vim, webkit2gtk3, xorg-x11-server, and xorg-x11-server-Xwayland), SUSE (apache-commons-configuration2, apache-commons-text, apache2, containerd, kernel, libnilfs3, libopenbabel8, libtar, libzypp, lrzip, nodejs24, ofono, perl-Net-Dropbox-API, podman, python-pip, python-PyJWT, python311-aiohttp, python311-nltk, python311-python-multipart, python312, and python315), and Ubuntu (amd64-microcode, containerd, containerd-app, containerd-stable, cpp-httplib, imagemagick, mina2, node-pbkdf2, NSD, and xrdp).


  • The "Akrites" vulnerability-mitigation project launches
    The Linux Foundation, in aletter co-signed by a large range of organizations and companies, hasannounced the launch of "Akrites", a project to fast-track vulnerabilityfixes into projects.
    As Akrites works upstream to fix projects at the source, we commit to support downstream efforts to secure critical infrastructure before it can be exploited. When patches are released to the public, adversaries are able to utilize AI to rapidly reverse engineer the underlying vulnerabilities, develop exploits, and launch attacks. The success of our efforts therefore will be measured in patch deployment, not publication. We will partner with critical infrastructure owners and operators, civil society efforts, and governments as they increase coordination to achieve these goals.
    Confidentiality is non-negotiable: An undisclosed flaw in a widely deployed package is, in effect, a weapon, and the program is built first to prevent leaks. Fixes flow back into each project's own home, working with the maintainers. The engineering resources and other capabilities provided by Akrites participants contribute to this effort. Additionally, when a critical package has no one maintaining it, Akrites will stand as the maintainer of last resort so a fix can still reach everyone in a timely fashion. We will also align with government efforts so that public and private defenders move together, rather than in a disjointed fashion.


  • [$] A look at MinIO alternatives: Ceph and Garage
    MinIO is a popular object-storage server that offered compatibility with the Amazon Simple Storage Service (S3)API. In December 2025, the company behind the project (also named MinIO)announcedthat the project was in maintenance mode and would not accept new changes; itwas archivedcompletely in February 2026. MinIO users have been hunting for alternativessince then, but the array of choices can be baffling. While many other projectsaim to fill the space, their strengths and areas of focus tend to vary. Two ofthe alternatives—Ceph and Garage—are particularly compelling,and both offer solid S3 compatibility.


  • Podman 6.0 released
    Version 6.0.0 of the Podmancontainer-management tool has been released. Notable new featuresinclude the ability to set multiple static IP addresses forcontainers, improvements in network isolation that make Podman morecompatible with Docker, changes to the way Quadletcommands function, many new options for many existing podmancommands, and arewrite of Podman's configuration file handling. There are manybreaking changes; see the releasenotes for a full list of all new features, changes, and bug fixes.


  • [$] Hardening the kernel with allocation tokens and bootpatch-SLR
    There is a lot of work going into eliminating exploitable bugs from thekernel and preventing the addition of new ones. Even if this work ismaximally successful, though, there is no chance that the kernel will befree of these bugs anytime soon. Thus, there is also ongoing interest inhardening the kernel to make the existing bugs more difficult to exploit.The upcoming 7.2 kernel release will include a change to how dynamicallyallocated structures are placed in memory to make them harder to overwrite,while a project to randomize structure layout at boot time has a ratherlonger timeline.


  • Security updates for Thursday
    Security updates have been issued by AlmaLinux (libpng, libsolv, libtasn1, libxml2, libxslt, python3.14, tigervnc, and vim), Debian (cloud-init, postgresql-13, and yelp), Mageia (nats-server), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, bind9.18, cockpit, compat-openssl11, dnsmasq, dovecot, evince, expat, flatpak, freerdp, gimp, golang, grafana, grafana-pcp, httpd, jmc, jq, kernel, libsndfile, libsoup, libtiff, mod_http2, mysql:8.0, nginx, nginx:1.24, openexr, php:8.2, poppler, pyOpenSSL, python-markdown, redis:7, samba, thunderbird, tigervnc, unbound, and vim), Red Hat (libpng, libpng12, and libpng15), SUSE (apptainer, bind, crun, freeipmi, ghc-crypton-x509-store, ghc-crypton-x509-system, google-guest-agent, google-osconfig-agent, GraphicsMagick, gstreamer-plugins-bad, hamlib, iproute2, java-1_8_0-openjdk, kubevirt1, libarchive, libheif, libpng15, mbedtls, mbedtls-2, openssl-1_1, python-biopython, python-PyJWT, tar, webkit2gtk3, and xen), and Ubuntu (ffmpeg, libdbi-perl, and perl).


  • [$] LWN.net Weekly Edition for June 25, 2026
    Inside this week's LWN.net Weekly Edition:
    Front: Free-threaded Python; AUR attacks; Fedora 2FA; 7.2 merge window; BPF arenas; BPF coroutines; BPF JIT; RMR and BRMR; OSPM. Briefs: Tor deprecations; GIMP 0.54.1 flatpak; Mastodon 4.6; Systemd v261; Xfce on Wayland; Quotes; ... Announcements: Newsletters, conferences, security updates, patches, and more.


  • [$] Fedora: 2FA, or not 2FA, that is the question
    Compromised accounts are one of the most common ways that attackerscan sneak malware into the open-source supply chain. One way toreduce account compromise is for projects to require two-factorauthentication (2FA) or multi-factor authentication (MFA), but that iseasier said than done. However, Fedora is currently discussing putting2FA requirements in place soon, following an an alleged accountcompromise that led to an AI agent causing a number of problemsfor the project. After some discussion, Fedora will begin by requiringpackagers in the "provenpackager"group to enable 2FA within the next three months or so.


  • [$] A helper library for BPF arenas
    BPF arenas are areas of memory (potentially shared with user space)where programs have free reign to build theirown data structures, unburdened by the verifier's bounds checks. Many of thosedata structures are potentially usable in multiple programs. Emil Tsalapatisbrought his work on libarena, a library containing generic utilities for use inBPF arenas, to the 2026Linux Storage, Filesystem, Memory-Management, and BPFSummit. Although the library is already available as part of the kernel, itis still in its early stages and he has more work planned.


  • [$] Reports from OSPM 2026, day two
    The Power Managementand Scheduling in the Linux Kernel Summit, which still goes by thehistorical acronym OSPM, was held in Cambridge, UK, in mid-April. As hasbecome traditional, the presenters at that event have since writtensummaries of their sessions, and this work has kindly been made availableto LWN for publication. The second day's sessions covered a wide range oftopics, including device frequency scaling, using time-slice duration forCPU selection, scheduling domains on multi-cluster Arm systems, the LAVDscheduler, and more.



LXer Linux News



  • Linux 7.2 Surpasses More Than 43 Million Lines In The Kernel Tree
    Today marks the last day of the Linux 7.2 merge window with Linux 7.2-rc1 due out later today. With the many new features and improvements merged over the past week since the Linux 7.1 stable debut, the Linux kernel source tree now exceeds 43 million lines...






  • WCH CH32V006EVT board supports Zephyr for low-cost RISC-V development
    Olimex recently featured the WCH CH32V006EVT, a low-cost evaluation board for the RISC-V-based CH32V006K8U6 microcontroller. The board is designed around WCH’s CH32V006 family and provides a compact platform for experimenting with the QingKe V2C 32-bit RISC-V core, Zephyr support, and basic embedded development features. The CH32V006K8U6 integrates a QingKe V2C processor using the RV32EmC instruction […]


  • Experimental Code Enables Per-Monitor Backgrounds For GNOME Shell
    One of the limitations of GNOME's current multi-monitor handling is that the same background is used across the displays. For those that want to enjoy per-monitor background selection, some experimental / proof-of-concept code is now working to allow such per-monitor backgrounds to work with the modern GNOME desktop...






  • Linux MD RAID5 Seeing Scalability Improvements Up To 17%
    Posted to the Linux kernel mailing list this week was a new patch series working on scalability enhancements to the MD RAID5 software RAID code. Up to a 10~17% improvement was observed in some configurations with these RAID5 scalability patches...


  • GNOME AI Assistant Adds Image Generation Support
    In development over the past three years has been Newelle as a GNOME-aligned AI virtual assistant. Out this week is Newelle 1.4.5 and it now adds AI image generation support and a redesigned chat interface...


  • Sparky-aptus-upgrade on Sparky Linux 2026 06 instance in UEFI mode
    One of the most recent sparky-aptus-upgrade wipes out old boot-loader and prompts you to install new boot-loader . It suggests the options vda, vda2 (/boot ext4), vda3 ("/" btrfs) , neither one of options suggested is correct due to /boot/efi is mounted on /dev/vda1. The workaround is to reject install new boot-loader and wait until sparky-aptus-upgrade would exit warning you that boot-loader is missing. Then initiate ssh session to instance of Sparky Linux and issue . . . .






Linux Insider"LinuxInsider"












Slashdot

  • US Agency Cancels Contract For Warrantless Tracking of Mobile Devices
    America's Bureau of Alcohol, Tobacco, Firearms and Explosives has "canceled its contract for a surveillance tool that enables warrantless tracking of mobile devices," reports the Associated Press. They note the move comes "after lawmakers, a prosecutor and a judge raised concerns about the legality of the tool in criminal investigations."ATF, the federal agency responsible for enforcing the nation's gun laws, told The Associated Press that it discontinued what it called a "pilot" program using a tool called Webloc after Rep. Michael Cloud, a Republican from Texas, and Sen. Ron Wyden, a Democrat from Oregon, expressed reservations about the agency's use of bulk commercial location data. Webloc, which is made by a vendor called Penlink, sources data from consumer apps and advertising networks, which collect the location of mobile devices from consumers who download apps or browse the web... The U.S. Supreme Court ruled in 2018 that police needed a warrant to obtain historic movement data from cellphone companies on a criminal suspect. But it has never addressed the growing practice of commercially acquired data. Other users of Webloc include the U.S. military and U.S. Immigration and Customs Enforcement but also local law enforcement agencies such as police in places like Elk Grove, Calif. and Durham, N.C. The technology has also expanded around the world, with the national police in El Salvador and Hungarian intelligence agencies as customers, according to a report from earlier this year from Citizen Lab, a group of researchers at the University of Toronto who investigate digital threats to civil society. The article notes that other U.S. law enforcement agencies continue to buy commercial geolocation data, "including the FBI and the Department of Homeland Security."


    Read more of this story at Slashdot.


  • Students Around the World are Using AI-Powered Smart Glasses to Cheat on Tests
    Students are using AI-powered smart glasses to cheat on tests, reports CNN. "And in East Asia's test-obsessed societies, where a single exam could impact the trajectory of a student's future career and social status, educators are scrambling to get ahead of the problem."Already, countries are stepping up inspections for test-takers. For China's grueling annual college entrance exam earlier this month — which more than 10 million hopefuls take each year — authorities required screening of all glasses. In the United Kingdom, the head of England's exam watchdog warned earlier this month that AI glasses and smart devices like earpieces could worsen cheating in exams... [T]wo incidents in South Korea were the country's first reported cases of cheating with AI glasses... In Taiwan, the university where a prospective student was caught cheating is now reviewing rules and standard operating procedures for AI eyewears during examinations. But experts worry these individual cases point to a more widespread issue. "If we're seeing a few cases being reported, we're seeing a lot more cases not being reported," said Thomas Corbin, lecturer at Deakin University in Australia, who has conducted research around the usage of AI-powered glasses and other smart devices in academic assessment. With the rapid development of AI technology, however, smart glasses are becoming slimmer, less noticeable, while integrating AI models that can operate independently with connectivity, raising concerns not only about exam integrity, but also about broader privacy risks... "Wearable AI is as much of a challenge to exams as ChatGPT was to essays in 2022 and I just don't think there is any real way that we can reliably have exam practices moving forward," Corbin said.


    Read more of this story at Slashdot.


  • 'Supergirl' Movie Criticized for Script, Poor Visual Effects
    The Onion joked the new movie Supergirl is about a hero who must single-handedly save the world "after the catastrophic collapse of interest in the genre." Unfortunately, The Hollywood Reporter says the film's reviews "range from negative to tepid praise (averaging a 58 percent Rotten Tomatoes score)." Many point fingers at the film's script, with Variety's line — "a comic-book movie with the worst script I can remember" — going viral... Not to pile on, but there's another recurring gripe from the reviews that stood out: Critics bashed the film as being murky, dark and gray, with poor VFX: "Muddy CG sludge" wrote one. Another said the film was full of "sludgy browns and grays" and "the visual murkiness of the settings makes it hard to follow the already unintelligible action sequences." A third wrote the "VFX is so rough it makes The Flash look like Avatar." Moviegoers increasingly despise murky, dark visuals (often used to hide weak effects), along with obvious CGI and incoherent action. They've seen it so many times they've become allergic. The Bulwark agrees that the action sequences are "terribly lit, incoherently staged, and just generally weightless and ugly... [I]t's reminiscent of the disaster that was The Flash: It's just very obvious during certain sequences that everyone was in a big green-screen warehouse and the camera was whipping around with the knowledge that everything would be painted in later, so who really gives a crap how anything looks on the day of." But they also call the movie "a tremendous slog of a film, a real step backwards for the James Gunn-overseen DC Universe of movies and TV shows" that's "neither fun nor exciting" and "feels empty." The film does have one bright spot: Lobo, who is played by Jason Momoa as something like Michael Keaton's Beetlejuice by way of Jason Momoa's Aquaman. He's blustery and cantankerous and saucy and just a little menacing; it's a perfect piece of casting and a really nice performance. Unfortunately, it's the only spark of life in what is otherwise a deeply dour, deeply boring piece of filmmaking... Supergirl is just a misfire on nearly every level, one that lacks the sincerity and fun of last year's reboot of this universe or the comic pathos present in Gunn's Peacemaker series on HBO Max. Reason calls it "dark, depressive, and dull" and "a downer of a movie in nearly every way." It's not fun. It's barely even righteous. It's just miserable. At one point, Supergirl flat-out murders a guy by pushing a giant sword through his neck. Somehow, I suspect even Zack Snyder would be appalled. Time argued fans of last decade's superhero movies "should be demanding more, not less." Though "Will there be rioting in the streets once audiences get some idea of how lousy Supergirl is? Probably not."


    Read more of this story at Slashdot.


  • Developer AI Token Costs Could Exceed Their Salaries in Two Years
    "Enterprises may soon be paying as much for their developers' AI token usage as they do for their salaries," writes InfoWorld:According to Gartner, these costs will meet, or even exceed, the typical software engineer's monthly salary within the next two years. This is not only because developers are increasingly adopting generative AI and agentic tools, it reflects a trend toward consumption-based licensing models as vendors balance infrastructure investments with profitability... Gartner senior principal analyst Nitish Tyagi explained that it's important to note that Gartner's prediction is based on a global average salary of $2,000 per month; it doesn't mean AI token usage will exceed all salaries. For instance, in the US, yearly pay rates can be six digits or more. However, that kind of spend is not out of the realm of possibility, Tyagi emphasized. "I have heard scary numbers like 'My developer consumed $20K last month,' or 'A business user consumed $32K'." If these amounts sound shocking, that's the point. "The goal is to alarm the industry about the impact of token cost if it is not governed and controlled," he said... AI coding vendors have yet to deliver "mature, built-in cost optimization capabilities," Tyagi said, and prices will likely only continue to rise as vendors further build out their models while at the same time trying to remain profitable. Thus, enterprises struggle to forecast and control costs, and, because AI is moving so fast, many organizations lack the "maturity and frameworks" to determine ROI, he noted. Agent-driven workflows are difficult to govern, context windows become bloated, budgets are wiped out earlier than anticipated, and token spend becomes hard to justify.... "Without a governed engineering operating model, costs can escalate faster than the productivity gains these tools are designed to deliver," Tyagi said.


    Read more of this story at Slashdot.


  • An Amazon Seller Says They Were Offered a Way to Bribe an Amazon Employee
    Jack Nekhala had a business selling on Amazon — and in December he received an unusual offer, reports Bloomberg. A woman said she could bribe an Amazon employee "to help him retrieve $90,000 in funds that the e-commerce giant had frozen after suspending him over an alleged violation of review policy."Hoping to ingratiate himself with the company and restart his business, Nekhala offered to provide evidence, including recorded conversations and screen shots, that he said proved Amazon personnel were peddling inside information and influence. The smoking gun, Nekhala told the representative: information about his seller account. Only certain Amazon employees are supposed to have access to such details, but Nekhala had received them from the woman on WeChat, the Chinese messaging app. Nekhala's experience, which he documented and shared with Bloomberg, provides a rare glimpse into an international black market that has been a persistent scourge of Amazon's online store. On one side are sellers looking for a variety of favors: a competitive edge over their rivals, information on how to boost sales, a way to get themselves unsuspended. On the other are middlemen who lurk on message apps like Telegram, WeChat and WhatsApp offering access to people inside Amazon who can get things done for a price... It's impossible to determine the scope of the illicit activity, but it's an open secret among Amazon sellers and consultants, who are frequently approached on social-media platforms and messaging apps. "The message is always the same: 'I'm going to show you screenshots to prove I have inside access,'" said Chris McCabe, a former Amazon employee who runs a seller consulting firm... In 2020, federal prosecutors exposed an international bribery scheme involving Amazon sellers and employees. The ring allegedly extracted about $100 million in unfair advantages by bribing Amazon employees in Asia to help them sell more products and sabotage their competitors. Five people in the US were convicted and received jail terms or probation. Last year, law enforcement officials in India began investigating more than 20 former Amazon employees suspected of accepting bribes from trucking companies in exchange for routes, according to The Times of India. After Nekhala reported his own experience to Amazon, the representative committed to "do some digging" and to email him instructions on how his evidence could be shared, according to a recording of the conversation. But Nekhala said he never heard back. The employee who leaked his personal information had already been fired for unrelated misconduct, according to Amazon. Amazon told Bloomberg employee involvement was "very rare," and that "We invest heavily in this area and have dedicated teams and systems in place to prevent all types of fraud, including by our own employees."


    Read more of this story at Slashdot.


  • IBM is Getting Ready to Scale Quantum Computing
    IBM spent a decade "building, testing and improving" quantum computing, reports the Wall Street Journal. "This year, the company is laying the groundwork to turn that technology into a fully-fledged, scalable business from an expensive science project."IBM said last month it plans to form a new independent subsidiary called Anderon, a foundry to produce the silicon wafers needed to make quantum-computing processors. The venture is seeded by a $1 billion investment from the Trump administration and another $1 billion of IBM's own cash.Anderon will give the company a new line of business in selling wafers to other quantum-computing companies. It will also provide a steady stream of wafers to continue developing its own quantum technology, positioning IBM to capture part of what the Boston Consulting Group projects will be a $90 billion to $170 billion market for quantum-computing providers by 2040... The company also plans to spend an additional $9 billion over five years to advance the final stages of its quest to build a quantum-mechanics-powered computer capable and reliable enough for widespread use, a goal known as fault tolerance. That computer, named Starling, is being targeted for 2029. With Anderon, IBM is thinking beyond Starling, or even a more powerful quantum computer planned for 2033.


    Read more of this story at Slashdot.


  • Renewable Energy Just Hit 30% of America's Electricity Generation
    America generated 10.06% more energy with renewables in the first four months of 2026 than it did in the same period the year before. That's according to new figures from America's Energy Information Administration, cited in this report from Electrek:The growth was led by utility-scale solar (+21.3%), hydropower (+15.7%), small-scale solar In April alone, wind and solar each produced more electricity than US coal plants, while the combination of solar and wind produced 57.0% more electricity than nuclear power. The mix of all renewables, including biomass and geothermal, accounted for 30.0% of total US electrical generation during the first third of 2026 — up from 27.8% a year earlier... EIA reported that, in April, utility-scale solar capacity surpassed wind capacity for the first time (160,208.1 MW vs. 160,100.6 MW). Further, utility-scale battery energy storage capacity increased by 17,703.5 MW, or 58.1%. Nuclear added just 18.4 MW.The combined capacity growth of all utility-scale renewable energy sources for the 12-month period (55,980.3 MW) is two-thirds more (i.e., 67.6%) than that added during the previous 12 months (33,392.0 MW). "EIA projects no new nuclear generating capacity and a net decline of 5,200.5 MW in fossil fuel capacity."


    Read more of this story at Slashdot.


  • How a Seemingly Harmless Image Can Jailbreak Vision-Language AI Models
    Slashdot reader BrianFagioli writes: Florida International University researchers have developed a technique called JaiLIP (Jailbreaking with Loss-guided Image Perturbation) that uses subtle image modifications to bypass AI safety guardrails. Unlike traditional jailbreaks that rely on carefully crafted prompts, the attack works through images that appear normal to human viewers. The researchers tested the technique against BLIP-2, a multimodal AI model, and found that manipulated images significantly increased the likelihood of harmful responses. According to the study, the approach outperformed previous image-based jailbreak methods and nearly doubled the number of unsafe outputs generated during testing. The findings highlight a potential security risk for businesses deploying AI systems that process both images and text. While most discussions about AI safety focus on prompts, the research suggests that seemingly harmless images may also serve as an attack vector.


    Read more of this story at Slashdot.


  • France's Heat This Week Was Worse Than a Dire Scenario Imagined For 2050
    There's a deadly, record-breaking heat wave spreading east across Europe, reports the Washington Post — and it's even worse than a dire earlier forecast:The forecast was recorded in 2014 as part of a campaign coordinated by the World Meteorological Organization (WMO) that invited about 60 presenters worldwide to imagine a weather report from the year 2050. In one clip, Ãvelyne Dhéliat from French television network TF1 presented a hypothetical scenario of high temperatures 36 years into the future — during a heat wave in a warmer climate in 2050... One of the maps that Dhéliat shared was lit up in shades of orange, filled with temperature predictions of 40 degrees Celsius (104 degrees Fahrenheit), reaching as high as 43 degrees Celsius (109.4 degrees Fahrenheit). But it turns out, it didn't take 36 years for those imagined temperatures to be reached — and even exceeded. The heat on Wednesday alone, when the temperature soared as high as 112.3 degrees Fahrenheit (44.3 degrees Celsius), exceeded the 2050 projections in 19 out of 34 locations across mainland France — far sooner than some may have expected. Some places surpassed those hypothetical future temperatures by more than 20 degrees Fahrenheit. It's part of a dramatic shift in heat wave frequency across the country. Half of the heat waves observed since 1947 have occurred since 2010. "By 2100, heat waves could last up to two months continuously," the country's weather agency, Météo-France, said this week. It was hotter in France on Wednesday than in Las Vegas and Phoenix and just two degrees Fahrenheit shy of what was observed in Death Valley, California. An estimated less than one percent of the planet was hotter than France's hottest place... [T]he heat dome, which will linger into early next week, is only part of the story. This type of extreme heat is becoming more common as the planet warms, especially in Europe. Climate scientist Robert Rohde said in a post explaining the heat wave's causes that France and Western Europe should expect many more heat waves like this over the coming decades. "This isn't a fluke, but simply part of the new normal," he said. Thanks to Slashdot reader fjo3 for sharing the news.


    Read more of this story at Slashdot.


  • Max Planck Slapped With Two Paper Retractions By Suspected Rogue Algorithm
    Max Planck won 1918's Nobel Prize for physics. Yet two of his papers were retracted — a move now being criticized by Yves Gingras, a historian of physics at the University of Quebec and Mahdi Khelfaoui, a fellow historian of science at UQ Trois-Rivières. Science reports:The papers, both quietly retracted in 2011, originally appeared in the early 1940s in Naturwissenschaften, a German journal now owned by publishing giant Springer Nature. After some sleuthing, Khelfaoui determined one of the Planck pieces, a philosophical essay from 1942 titled "Sinn und Grenzen der exakten Wissenschaft" ("Meaning and Limits of Exact Science"), about how to achieve certainty in scientific knowledge, had also appeared in two other journals and been reprinted twice in books. Repackaging the same work multiple times is considered "self-plagiarism" and frowned upon today — the practice produces copyright conflicts and inflates scholars' publication records. The Naturwissenschaften site gives "copyright violation" as the reason for the retraction. Yet publishing identical material in multiple journals was widespread before the internet. "Science was more fragmented" then, Khelfaoui says. "You wanted different audiences ... to have access to your work." The practice was especially common for luminaries like Planck. Albert Einstein did the same (but escaped retractions). Springer Nature's "anachronistic" application of modern standards to a 1942 paper "distort[s] the historical record," Gingras and Khelfaoui argue in a preprint posted last month on arXiv. Any concerns about copyright violations are largely moot anyway: Because Planck died in 1947, his works are in the public domain in most countries. Gingras was especially incensed that Springer Nature deviated from the normal practice of merely slapping the word RETRACTED across the digital version of the paper while still allowing scholars to read the text. Instead, the publisher posted a blank white page with the cryptic phrase, "This article has been withdrawn due to article violation." Springer Nature is nevertheless still selling the empty PDF for $39.95. Suzanne Scarlata, a chemist and biochemist at the Worcester Polytechnic Institute and editor-in-chief of The Science of Nature, as Naturwissenschaften is now known, had not heard about the retractions before being contacted for this story... Scarlata suspects Springer Nature's internal policing software removed the paper and posted the retraction notice unilaterally, without human supervision: "I think it just happened with their algorithm," she says. "It's a mistake they should probably rectify." A second Planck paper was apparently removed because its response to a 1940 paper had used an identical title. Thanks to our long-time Slashdot reader He Who Has No Name for sharing the article.


    Read more of this story at Slashdot.


  • Scroll Burned in 79 AD Volcanic Eruption Finally Deciphered Using AI
    When Mt. Vesuvius erupted in 79 A.D., it buried hundreds of papyrusscrolls. They were rediscovered in the mid-1700s, remembers Smithsonian magazine, "the onlysurviving collection of its kind from the Greco-Romanworld..." "But when scholars tried to unroll them, the carbonized manuscriptscrumbled to dust."Every generation that followed faced the same dilemma: They could wait fortechnology to advance, abandoning hope of reading the ancient textsin their own lifetime. Or they could try to open the scrollsthemselves — and risk destroying them. In recent years, researchers have settled on a third option. Usingadvanced imaging and artificial intelligence, they're decipheringthe scrolls without needing to unroll them at all. The Vesuvius Challengehas accelerated the process by turning it into a public competition,complete with cash prizes. In 2023, a student won $40,000 fordeciphering asingle word — "purple" — from an unopened scroll. Later,contestants would identify 2,000 Greek characters from one scroll ($700,000) and the title of another ($60,000). Now, for the very first time,researchers have recovered allsurviving text from a single scroll. The nearly five-foot-longsegment includes roughly 20 columns of ancient Greek philosophy,accessible for the first time in nearly 2,000 years. "The tech actually does look like magic, but it's not," BrentSeales, a computer scientist at the University of Kentucky, saidat a pressconference. (The article points out that Seales partnered with two Silicon Valley investors in 2023 to launch the Vesuvius Challenge, and is now hailing "the restoration of lost voices from the ancient world."Seales has been working on virtually unwrapping thescrolls since the early 2000s. The process involved imaging thebundles of papyrus using technology similar to CT scanners, isolatingthin layers and then stitching them together.... "We've developeda systematic and a repeatable approach," Seales told the audience."Now it's only a matter of time until we read all of thescrolls."


    Read more of this story at Slashdot.


  • California Sheriff Says Their Drone Disarmed a Suspect, Shares Video on Instagram
    The Los Angeles Police Department says about 1,500 police agencies across America have drone programs, reports SFGate, and 58 of those drone-using police agencies are in California. The Sacramento County sheriff's office recently posted drone footage on Instagram set to theme from "Mission: Impossible," claiming "a nationwide first" where their drone successfully disarmed a felon "seen earlier with a firearm" (though now not moving, but holding a knife while lying face down in a garage). In the video the "not responding" suspect continues not moving as the drone dangles a magnet which catches on the knife. The drone then pulls multiple times until it comes out of the unmoving suspect's hand. The sheriff's office says their footage shows their drone "disarm an armed suspect, helping bring the incident to a safe resolution," in their post on Instagram, "rather than rush into a potentially deadly encounter..."Was he pretending to be dead or simply lying in wait for deputies to approach...? It's also worth noting that our drones are labeled as "military equipment" (even though anyone can purchase them at their local Walmart), but are really just another piece of technology helping deputies resolve dangerous situations safely. Their use protects both law enforcement personnel and suspects. SFGate offers more reports from around California:In Yucaipa, officials launched a Drone as First Responder (DFR) pilot program on May 28, the San Bernardino County Sheriff's Department announced this month. According to the release, drones have already been used to respond to over 100 calls for service, arriving before deputies for 71% of them. "The drones also contributed to 12 arrests, assisted in locating persons of interest on 37 occasions, and provided aerial overwatch during 44 incidents," it continues, though details on how they assisted the police are unclear. The drones, manufactured by Skydio, were also used to locate a young person experiencing a mental health crisis and another person launching illegal fireworks.


    Read more of this story at Slashdot.


  • Non-Invasive Stimulation of the Brain Ended Opioid Addiction, Cigarette Craving
    The Jerusalem Post reports that doctors at Haifa's Rambam Health Care Campus "have successfully treated their first Israeli opioid addiction patient using an experimental noninvasive brain technology, easing him through withdrawal in just 20 minutes..."[T]he team of specialists at the Haifa medical center intervened in the electrical activity of an area of the patient's brain called the nucleus accumbens, the core of the brain system responsible for feelings of satisfaction, pleasure, and reward. The treatment, based on technology from the Israeli company Insightec, is similar to the one used to treat symptoms of essential tremor and Parkinsonian tremor, under MRI control. In this case, the treatment was carried out with the help of a new technology that performs noninvasive neuromodulation, without heating or burning tissue, and allows stimulation in the same area of the brain to increase or suppress activity... "Tests carried out a week later produced negative results for opioids and other substances," [said Dr. Lior Lev-Tov, director of the functional neurosurgery unit in Rambam's neurosurgery division and the one leading the new study at the medical center.] "The patient himself reported a craving score of zero out of 10 for using the drug, and even another side effect, a drastic drop in the desire for cigarettes, from three packs a day to just a few cigarettes, and with no urge to use alcohol. In other words, in a treatment that lasted about 20 minutes net, our patient was completely freed from an extreme dependence that had accompanied him every day for years. This is nothing less than a medical and therapeutic revolution." Dr. Lev-Tov added that "This experience opens doors for us to treat a wide range of very serious illnesses such as PTSD, OCD, eating disorders, other addictions, severe depression, severe pain disorders, and I hope we will also be able to reach cognitive areas and treat attention deficit disorders, Alzheimer's, Parkinson's, and more." Thanks to Slashdot reader Bruce66423 for sharing the article.


    Read more of this story at Slashdot.


  • FSF 'LibreLocal' Organized From Prison by Iranian Man Jailed for 'Cyber-Crimes' After Promoting Free Software
    Thursday the Free Software Foundation blogged about this year's 47 'LibreLocal 2026' meetups, highlighting 10 that took place in Australia, Mexico, the United States, New Zealand, Cameroon, Switzerland, Spain, Argentina, China, and Iran. "Far from each other in many parts of the world, they came together around one unifying belief: free software."We envisioned LibreLocal as a collage of in-person community meetups that would bring people together to swap ideas, learn from each other, and celebrate free software. When we asked the free software community to organize LibreLocals last year, the response was very inspirational: 29 different meetups were hosted. After we made the global call this year, we were greeted with an even more enthusiastic response... Organizers hosted LibreLocals in cafes, bars, restaurants, libraries, universities, a computer repair shop, and even as part of a field trip to the System Source Museum, a museum dedicated to the history of computing in Hunt Valley, Maryland, USA. We also learned that a LibreLocal was organized inside Vakil Abad Prison in Mashhad, Iran by a free software supporter. Originally planned to be held in Shiraz, we were informed of this change in location on the LibreLocal wiki page set up for listing all LibreLocals. The updated entry, by another free software supporter in Iran, reads: "This year, one of our dedicated activists organized a LibrePlanet event from within prison in Iran. Currently serving a sentence for "cyber-crimes" related to his promotion of free software, he continues to introduce the principles of software freedom to his fellow inmates. We have placed this banner to honor his resilience and the community of individuals in prison who continue to stand for technological freedom. His identity will be revealed when it is safe to do so." Advocating for user freedom should never result in a prison sentence. We especially admire and respect the bravery and strength of those who fight for software freedom in the most dangerous and oppressive of environments. 50 people attended the LibreLocal meetup in Switzerland, according to one of the organizers, "forging connections between several local free software stakeholders and strengthening their cohesion." But the FSF's blog post stresses these are "ten stories among many more of free software supporters from across the globe... We also thank you our donors and associate members for the support that makes such meetups possible." The GNU Press Shop is now open through July 19 for their biannual fundraiser, offering a variety of freedom-respecting novelties including an FSF-branded antisurveillance webcam guard and both technical and philosophical books, like Richard Stallman's Free as in Freedom (which allegedly has turned up in Anthropic's training data). Other items include a slick new FSF logo sticker, a brass and zinc GNU "emblem" pin with real gold plating, and a cheeky sticker reminding everyone that "There is no cloud." And there's even a plush GNU toy.


    Read more of this story at Slashdot.


  • Forget Prompt Engineering: 'Loop Engineering' Is All the Rage Now
    An anonymous reader quotes a report from Business Insider: For the most powerful voices in AI, it's all about being in the loop. Claude Code creator Boris Cherny recently said he doesn't write his own AI prompts much anymore. Thanks to loops, he doesn't have to. "It's an agent that prompts Claude," Cherny recently told CNBC, adding, "I don't write the prompt anymore. Claude writes the prompt, and now I'm talking to that new Claude that is kind of coordinating." In the same interview, Cherny said that loops and a similar feature were examples of the kind of work he would be proudest of in a decade. Cherny isn't the only one embracing "loop engineering." OpenAI engineer Peter Steinberger, the creator of the viral OpenClaw project, wrote a public reminder to users who are still writing out prompts for AI agents. "Here's your monthly reminder that you shouldn't be prompting coding agents anymore," Steinberger wrote recently on X. "You should be designing loops that prompt your agents." [...] Steinberger shared an example of a loop he uses: "Tell codex to maintain your repos, wake up every 5 minutes and direct work to threads. That makes it easy to parallelize+steer work as needed." Claire Vo, founder of ChatPRD and host of the "How I AI," said, "it's really just reminding people that you don't have to use your human fingers to type in a prompt in order for your agent to do work on your behalf." The days of directly prompting generative AI coding tools are "kind of over, or at least some think it's going to be," Addy Osmani, director of Google Cloud, wrote in his post explaining the concept.


    Read more of this story at Slashdot.


www.theregister.com - Articles




















































Linux.com



  • From DHCP to SZTP – The Trust Revolution
    By Juha Holkkola, FusionLayer Group The Dawn of Effortless Connectivity In the transformative years of the late 1990s, a quiet revolution took place, fundamentally altering how we connect to networks. The introduction of DHCP answered a crucial question, Where are you on the network?!, by automating IP address assignment. This innovation eradicated the manual configuration [0]

    The post From DHCP to SZTP – The Trust Revolution appeared first on Linux.com.









Phoronix


  • Linux 7.3 To Introduce DRM "Color Format" Property With AMD GPU Driver Support
    While the Linux 7.2 kernel merge window is only ending later today to cap off the feature work on this next version of the Linux kernel, already for the Linux 7.3 kernel cycle later in the year there is one notable feature on the way: the DRM color format property is being introduced and being first supported by the AMDGPU kernel graphics driver...



  • Linux 7.2 Surpasses More Than 43 Million Lines In The Kernel Tree
    Today marks the last day of the Linux 7.2 merge window with Linux 7.2-rc1 due out later today. With the many new features and improvements merged over the past week since the Linux 7.1 stable debut, the Linux kernel source tree now exceeds 43 million lines...





  • Linux MD RAID5 Seeing Scalability Improvements Up To 17%
    Posted to the Linux kernel mailing list this week was a new patch series working on scalability enhancements to the MD RAID5 software RAID code. Up to a 10~17% improvement was observed in some configurations with these RAID5 scalability patches...


  • GNOME AI Assistant Adds Image Generation Support
    In development over the past three years has been Newelle as a GNOME-aligned AI virtual assistant. Out this week is Newelle 1.4.5 and it now adds AI image generation support and a redesigned chat interface...





  • New Intel Linux Driver Patches Enable HDR Over DP MST Connections
    One of the limitations of the Intel Linux driver's high dynamic range (HDR) display support is that it currently doesn't work for any DisplayPort Multi-Stream Transport "DP MST" connections, such as for daisy chaining monitors or multi-monitor docking stations. But the good news is patches are being worked on to address this Intel Linux kernel display driver shortcoming...


  • How NVIDIA GB10 CPU Performance Compares To Vera
    Since delivering NVIDIA Vera CPU benchmarks one month ago and follow-ups like how the ARM Linux server performance has evolved in 8 years or how Vera compares to Ampere Altra that is still quite common in the marketplace, another frequent discussion point and inquiry is about the performance of NVIDIA Vera relative to NVIDIA9s GB10 chip. For those curious about the per-core performance and the like, here are some benchmarks of the GB10 up against those initial Vera results.



  • Experimental Code Enables Per-Monitor Backgrounds For GNOME Shell
    One of the limitations of GNOME's current multi-monitor handling is that the same background is used across the displays. For those that want to enjoy per-monitor background selection, some experimental / proof-of-concept code is now working to allow such per-monitor backgrounds to work with the modern GNOME desktop...


  • Intel ANV Vulkan Driver Now Enables Descriptor Heaps By Default
    Back in early May was the experimental enabling of Vulkan descriptor heaps for the Intel ANV open-source driver. After nearly two months of continued testing and improvements, the VK_EXT_descriptor_heap support for Intel graphics on Linux is now enabled by default...







  • Linux Foundation & Others Launch "Akrites" To Defend Open-Source Software From AI-Enabled Exploits
    The Linux Foundation along with others like Amazon, Anthropic, OpenAI, NVIDIA, Microsoft, Red Hat, and others have joined forces to launch Akrites. The Akrites project is aiming to help defend critical open-source software from the brisk pace of new AI/LLM-discovered software bugs and vulnerabilities in ensuring that said issues are effectively addressed before they can be exploited by bad actors...




  • Updated Raspberry Pi OS With Linux 6.18 LTS Delivers Some Performance Benefits
    Last week marked the release of an updated Raspberry Pi OS that moved to Linux 6.18 LTS from its former Linux 6.12 kernel base along with making a number of other package updates. Given the jump to the newer Long Term Support kernel and other improvements, I ran some fresh benchmarks on the Raspberry Pi 5 (Raspberry Pi 500+) to see the performance difference out of the updated operating system.


  • Servo 0.3 Released With The Demo Browser Becoming More Useful
    Servo 0.3 released today as the latest version of this modern browser engine developed in Rust. With Servo 0.3 the demo servoshell browser is becoming more useful and supporting additional modern web features while Servo also continues to possess much potential moving forward on the embedded front as an alternative to the likes of the Chromium Embedded Framework (CEF)...


  • Linux 7.2 Drops Ancient PROFIBUS Driver: Ported From SCO Unix In 1998, Unused For Years
    Linux 7.2 is continuing the trend of removing obsolete hardware drivers for which the code hasn't seen any maintenance in years and there are no believed users left of said drivers, especially those that would be running modern mainline versions of the Linux kernel. The char/misc changes merged dropped two more obsolete drivers from the Linux source tree...



  • AMD Contributes ONNX Runtime Backend To FFmpeg DNN Filter
    An AMD engineer has contributed to the upstream FFmpeg library an ONNX Runtime back-end for its DNN filter. The FFmpeg Deep Neural Network (DNN) filters allow for running AI models natively inside the video processing pipeline for upscaling, object detection, background segmentation, and more. This ONNX Runntime back-end support is notable in that it expands the GPU and NPU capabilities with FFmpeg...


  • Linux 7.2 Staging Still Working To Tame The Realtek RTL8723BS "Beast Of A Driver"
    Way back in 2017 for the Linux 4.12 kernel the Realtek rtl8723bs WiFi driver was added to the kernel's staging area. Nearly a decade later, it's still being cleaned-up to suit the more rigorous non-staging area of the kernel in the formal networking subsystem. For Linux 7.2, the staging pull request is once again dominated by clean-ups to this Realtek WiFi driver...


  • KSMBD Adds SMB2 Compression Support In Linux 7.2
    Merged back in Linux 5.15 in 2021 was KSMBD as an in-kernel SMB3 file server. There hasn't been much KSMBD news to report on recently but for Linux 7.2 there is now SMB2 compression support...



Engadget"Engadget - Technology News & Expert Reviews"





















OSnews

  • Microsoft capitulates again, extends Windows 10 support by another year
    Its been quiet for a few days since Ive been sick, but Im feeling a bit better since today marks the official end of my one month of using Windows 11 that you people donated for. An article about my experience is definitely upcoming, including whether or not Ill actually stick with Windows 11 on my laptop or go back to Linux, but before we get there, lets talk about Microsoft once again capitulating to the reality that a lot of people really dont want to let go of Windows 10. In a surprising move, Microsoft has quietly confirmed that it’s extending Windows 10 support until October 12, 2027, which is one full year beyond the October 2026 cutoff that home users had been planning around. ↫ Abhijith M B at Windows Latest Hundreds of millions of people are still using Windows 10, and with the AI! techbros buying up all the RAM and other chips for their pachinko machines  making this whole thing a bit of an own goal for prime AI! booster Microsoft  buying new PCs that are actually compatible with Windows 11 isnt exactly a fun prospect for the vast majority of us normal folk dealing with the cost-of-living crisis. As such, Microsoft really doesnt have any other choice but to keep extending support for Windows 10. It aint much, but Ill take any morsel of justice I can get. While everyone else has to pay for getting access to these Windows 10 updates, users in the European Union get them entirely for free thanks to the Digital Markets Act. This additional year, too, can be partially attributed to the DMA, as the very same consumer rights organisations who pressured Microsoft into giving EU users truly free access to the Extended Security Updates also put pressure on the company to offer these for more than just one year. Basic consumer protection legislation works.


  • In memory of the man who put red and green squiggles under words
    Every little thing in a graphical user interface that we take for granted today, no matter how small, was thought up by someone, at some point. Case in point: the little red squiggly lines underneath misspelled words. In one form or another, these are everywhere now, and have just become a regular staple of every single text editing field we encounter every single day and dont stop to think about. Still, they were invented by someone, and we happen to know exactly who that was: Tony Krueger. In early versions of Word, the Spell Check feature was something that you explicitly invoked, and then you had to sit and wait while the program looked for all your potentially-misspelled words, and then showed them to you one at a time for a decision on what to do for each one. Word did introduce an Auto Spell Check feature to run spell check when the user was idle, so that when you hit the Spell Check button, the results were ready to go. However, the Auto Spell Check was still a blocking operation. As a result, a lot of users turned it off because it always seemed to decide “Now would be a good time to spell-check the document” just as you wanted to do something, forcing you to wait for the spell check pass to complete before you could, say, save and exit. Tony made the spell checker much more unobtrusive so that it didn’t interfere with your foreground work. And when it found a problem, instead of waiting for you to trigger a spell check, it immediately drew red squiggles under potentially-misspelled words (and later green squiggles under potential grammatical errors). ↫ Raymond Chen at The Old New Thing Tony Krueger passed away recently, after, among other things, having worked on an dizzying number of Microsoft Word releases. Imagine coming up with something that seems to basic and elementary to us now, and seeing it spread pretty much everywhere. I wonder what it must feel like to have invented something that seems so simple, most people dont even realise they use it every single day.


  • KDE is going to fix network shares
    Ive had my share of issues with network shares on any operating system, but since I mostly use KDE these days I found this deep dive into how, exactly, network shares work in KDE quite interesting. It turns out that while network shares in KDEs Dolphin mostly work, it does involves a few layers that sometimes dont interact well with each other, leading to really curious and annoying problems with mounted shares not appearing, permission issues, and so on. The biggest cause of problems is when using a non-KDE application in KDE that also happens to use a non-KDE save/open dialog. Such a non-KDE save/open dialog wont be able to see any network shared mounted by KDE, and sadly, quite a few applications youre likely to use on a KDE installation use non-KDE open/save dialogs, like Blender, GIMP, LibreOffice, OnlyOffice, Inkscape, Audacity, DaVinci Resolve, and more. Thats one hell of a list of applications to offer inconsistent or outright broken access to network shares youve set up and mounted in KDE. Luckily, this issue seems to be getting a ton of attention soon. All is not lost. Happily, KDE just received an investment of over €1.2 million from the Sovereign Tech Fund, and it includes funding for improvements to KDE’s network share handling! ↫ Nate Graham The project is in the planning phases at the moment, but theyre considering a whole slew of possible changes, fixes, and workarounds to make this stupid and annoying problem just go away. In 2026, nobody should be dealing with manually editing /etc/fstab or getting frustrated over supposedly disappearing network shares.


  • Xfces new Wayland compositor sees first alpha release
    The developer working on Xfwl4, the Wayland compositor for Xfce, has published the new compositors very first alpha release. Considering its only been six months or so of work, its impressive to see the effort reach this state already. The end goal of xfwl4 is to behave as closely as possible to an Xfce desktop running on an X server. Ideally a user could switch between the two without even knowing there’s a difference. In reality, of course, it won’t be quite that seamless, and there’s still more work to be done to get as close as possible to that ideal. This is a first solid cut at it, at the very least. ↫ Brian Tarricone Being the very first alpha release, it wont surprise you theres a few things missing or broken at this point. Still, if youre brave, you can download and build the release and try it out.


  • Valve opens Steam Machine waitlist
    Valve officially made the Steam Machine available (sort of but not really) today, and if you were hoping for the president of the Yacht Collectors Club to have found a loophole through the RAM and storage crisis, Ill be the bearer of bad news: the base Steam Machine model with 512GB of storage and no controller costs $1049 or €1039. Its clear that this price is significantly higher than Valve had originally anticipated, as the company dedicates the first part of its press announcement to this sticker shock. Steam Machine,`like our other hardware products, is made up of many components that we source from manufacturers around the world. The price at which we sell our hardware is a direct result of the cost of these components. We felt like we had a good understanding of how those costs might change over time when we first started sourcing them for Steam Machine back in 2023. That understanding was born from the many years of data we all have about the evolution of PC hardware prices – primarily, that it tends to get cheaper over time as new technology arrives. Over the past year or so, that has changed quickly and significantly, most visibly for RAM and storage components. There are a variety of reasons, all of which are affecting hardware products everywhere. The overall effect is that our original goal for the price of Steam Machine is no longer viable. So the prices were sharing today reflect the state of the world for manufacturing; or, more accurately, it reflects the price of the components as weve secured them over the past 6 months. Price wasnt the only thing impacted by all of this: availability was as well. There were periods where we found we couldnt source some of our components at all, at any price. More than anything else, this has impacted the number of units weve been able to produce for launch. ↫ Valve press announcement As Valve mentions, availability is also going to be an issue, and thus theyve had to settle on a complex reservation and lottery system. Between now and 25 June, you can sign up for a model, after which the entire pool of reservations will be randomised to determine a waitlist order. As machines become available, they will simply go down the list from first to last as determined by that randomisation. In other words, you cant just go out and buy one right away. At this price and for the hardware the Steam Machine contains  an AMD Zen 4 CPU with 6c/12t up to 4.8 Ghz, a custom RDNA3 GPU, and 16GB of DDR5 RAM and 8GB of DDR6 video RAM  youre probably better off sticking with what you already have. Until the AI! bubble pops and prices come down again, that is. Thanks, AI! techbros. Everybody despises you.


  • A tale of two path separators
    In macOS, you can apparently create files and directories in the Finder with names that include slashes. If you then go into the terminal and take a look with ls, youll see that the slashes are actually colons. I don’t understand all the nuances, but I know this is a side-effect of the fact that macOS has not one but`two`path separators: the slash (/) and the colon (:). The two separators are used in different contexts, and the system will translate between them as needed. These two separators reflect the two parent systems of modern macOS:`classic Mac OS`and the`Unix-like NeXTSTEP. When they were joined together, Apple’s engineers had to build a file system that was compatible with both the classic Mac’s file system (the Mac OS Extended File System, aka HFS+), and with NeXTSTEP’s file system (the Unix file system, aka UFS). Among other differences, these systems had different path separators: HFS+ used a colon, while UFS used a slash. ↫ Alex Chan (article from 2021) I had no idea macOS worked this way, but it makes sense considering the platforms dual history. Whats interesting is that when Apple moved to APFS almost a decade ago, this duality in path separators remained, most likely for backwards compatibility reasons. In a sense, this is somewhat similar to Windows supporting both backward and forward slashes, with the former being a leftover from DOS, and the latter an addition (to Windows) from the UNIX world. None of that beats Windows when using the Japanese or Korean locale, though. Because Japanese and Korean Windows use different codepages than Windows in the Americas and Western Europe, these versions of Windows render the backslash as the yen sign (¥) and and won (₩) sign respectively. As such, something like the Program Files directory actually renders like C:¥Program Files¥ and C:₩Program Files₩. Similar issues occurred in other Windows locales as well, but the impact of this in Japan and South Korea were so widespread that people just expect it to be that way, even if its easily fixed today. I cant find if Windows 11 still uses ¥/₩ in Japan/South Korea, since the last references of it I can quickly uncover all point to Windows 10.


  • Apple internals: Swift in the kernel
    Apples Swift has become the de-facto language for Apples own developers for a while now, and it seems that with the new operating system releases from the company unveiled during WWDC, Switch is now also being used in the kernel. Naturally I dropped what I was doing and went grepping through the iOS 27 kernelcache. Alas, nothing came of it. All is not lost though: I found the Embedded Swift runtime in macOS 27, sitting in`com.apple.kec.pthread`of all places. Then I went poking around the root filesystem and it turns out Apple gave the whole effort a name: KernelKit. Lets dissect it. ↫ Josh Maine Its still quite limited at this time, which makes sense  you dont want to be too crazy with the core of the operating system that runs on god knows how many PCs, smartphones, and other devices. Its also entirely contained within a few kexts as embedded runtimes, and the XNU kernel itself remains entirely C and C++.


  • I stored a website in a favicon!
    Every website has a favicon. Its that little icon in your browser tab. Usually you upload it once and then never think about it again. But. A favicon is just an image. An image is just pixels. And pixels are just bytes. So of course I wondered if I could store something inside one. ↫ Tim Wehrle I love it when people do something useless just for fun.


  • What was nice about the UI of Windows 2000
    I mean, this is preaching to the choir, but lets go anyway. I liked the UIs of the entire era from 3.0 to 2000, really. Im mostly using Windows 2000 as an example here because it runs so well in QEMU/KVM and that allows me to easily take screenshots. Some of the following will sound absolutely trivial, but I think its worth pointing out. ↫ movq.de blog Just a series of observations about how much better graphical user interfaces were back in the 90s and early 2000s. Weve lost so many affordances based on both common sense and scientific study, and what we ended up with is a confusing, inconsistent mess. It doesnt really matter where you look  user interface design has deteriorated since the early 2000s, a decline that only accelerated thanks to the arrival of the iPhone, where consistency is a dirty word, and the web, where the advertising people took prominence over the design people. I just want my buttons to look like buttons man.


  • To study how chips really work, MIT researchers built their own operating system
    A fascinating novel approach by researchers at MIT, called Fractal, to study in-depth how processors actually work. A team at MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL) decided to build something different. Fractal, an operating system kernel written from the ground up, treats the hardware itself as the object of study. Its first major use, a deep look at branch predictors — a CPU’s way of guessing what code to run next, before it knows for certain, so it doesn’t have to waste time waiting to find out — inside Apple’s M1 processor, has already turned up findings that prior work missed, including the first evidence that a class of speculative attack known as “Phantom” affects Apple Silicon. “We’re using hardware in ways it wasn’t designed for,” says Joseph Ravichandran, the MIT PhD student in electrical engineering and computer science (EECS) who led the project. “It’s not even obvious that this is a possible thing you could do with the hardware. But we found a way to pull all these different primitives off. It’s like a microscope. If you’ve got a hand magnifying glass, you can see a little bit. But if you had an electron microscope, now we’re really talking. That’s what Fractal is. The electron microscope of operating systems.” ↫ Rachel Gordon at MIT News While Fractal is small, its creators also added POSIX system calls, a C library, vim, GCC, a shell, and more. This way, it feels more familiar, and makes it easier for researchers to get started with the tool. Fractal is open source and hosted on GitHub, it has its own website, and theres a detailed research paper with more in-depth information.


  • AmigaOS 2: the greatest upgrade
    Five years after releasing the Amiga 1000, Commodore was about to launch the Amiga 3000, their first real high-end Amiga. With a 68030 processor, on-board SCSI and a slightly updated graphics chipset, all in a sleek desktop case, the Amiga was truly ready for the era of professional 32-bit computing. But Moores law wasnt the only thing thad had been pressuring Commodore since the release of the Amiga 1000: The desktop metaphor had matured even further, and the competition had been hard at work. IBM had launched OS/2, Windows 3.0 had turned Microsofts offering from a proof of concept into something actually usable, and new players had entered the scene  among them NeXTStep, with its polished 3D look. It was time to bring AmigaOS, too, into the 1990s. ↫ Carl Svensson Its interesting  theres a lot of focus on the first version of the Amiga operating system and the third one, but you dont hear a lot about AmigaOS 2.x. It turns out this is rather odd, because as Svensson details, this version came with an absolute ton of changes and improvements, from an entirely new widget toolkit to a brand new file system, and so much more. The new widget toolkit and accompanying style guide also ensured that the operating system looked, felt, and behaved consistently. Remember when we cared about that? Theres so much more cool features, though, like command history, line editing, universal clipboard support and more just for the CLI, as well as something called Commodities. These were tiny little programs managed from a central location, which didnt even need a GUI to work. Commodities included by default were things like ClickToFront, a focus-follows-mouse option, and more. Oh and of course, BASIC was replaced by ARexx. The list just keeps going, and you should really read Svenssons article.


  • Oracle Solaris 11.4 SRU93 released
    Oracle is sticking to its promise of more regular Solaris updates with the release of Oracle Solaris 11.4 SRU93. This release, like other SRU releases, is for paying Solaris customers, as the CBE releases for enthusiasts are on a different cadence. With Solaris focus being on enterprise server environments, it should come as no surprise that most of the changes and improvements are focused on things like enterprise networking and security, such as changes to how policy settings for the Kernel Crypto Framework (KCF) are stored, moving from using RPC over sockets instead of STREAMS, and more.  Of course, theres also the long list of updated open source packages. SRU 93.221.2 updates a broad set of platform, runtime, developer, networking, desktop, and open source components. Notable updates include Apache Tomcat to 9.0.116, bash to 5.3 patch 9, BIND to 9.20.18 and 9.20.21, Django 4.2 to 4.2.30, Django 5.2 to 5.2.13, Firefox to 140.8.0esr, Golang to 1.25.8, Node.js 20 to 20.20.2, Node.js 22 to 22.22.2, Node.js 24 to 24.14.1, NSS to 3.119.1, Perl to 5.42, Python 3.11 to 3.11.15, Python 3.13 to 3.13.12, RabbitMQ to 4.2.4, Thunderbird to 140.8.0esr, vim to 9.2.0340, and zlib to 1.3.2. Additional updates include development tools, Python modules, X11 utilities, printing components, libraries, cryptographic packages, networking tools, and desktop-related packages. ↫ Colin Kavanagh at the Oracle Solaris Blog Existing Oracle Solaris customers can update to the new release through pkg update.


  • Android 17 released for Pixel devices with very few interesting improvements
    Yesterday, Google released Android 17 to Pixel devices, so late last night I updated my Pixel 10 Pro with the intent to write a news item about the release today. The reality is that that I totally forgot I even upgraded last night, because Android 17 is about the biggest nothingburger Ive ever seen. Virtually all of the new features listed in the upgrade blurb on my phone were AI! nonsense I dont encounter, so over the course of the day, I didnt really notice anything new about my phones operating system. The only interesting feature that I think will be particularly useful on tablets and perhaps foldable devices is something called App Bubbles!. Basically, you can turn any application into an overlay that can be minimised into a bubble, which then lives anywhere on your screen. Tap it, and you can maximise the overlay again. This little multitasking bubble can contain multiple applications, effectively making it a dock or taskbar. Neat, but I didnt see much use for it on my phone. The remainder of the new non- AI! features are hard to spot, at best. I guess the ability to turn one half of a foldable display into a gamepad is neat if you can deal with gaming on glass buttons (I cannot), and the changes to location access (you can now grant it for just one time) and contacts access (its more fine-grained and temporary now instead of granting access to everything forever) are welcome, but thats about it for user-facing features. Under the hood, the one thing that stands out is that Google is enforcing stricter memory limits for applications, based on how much RAM a device has. The idea is that this should prevent memory leaks from getting out of control and leading to crashes, which is nice, especially for devices with less RAM. Android 17 is available for Pixel devices now, and will probably find its way to non-Pixel devices over the coming months or years. With how little meat there is on Android 17s bones, this might be the first release where Androids update woes dont really matter.


  • KDE Plasma 6.7 released
    The KDE team released KDE Plasma 6.7 today, and with it comes a long list of improvements, new features, bug fixes, new old themes, and so much more. A new feature that is sure to please those among us who use virtual desktops: you can now have different virtual desktop setups per display. Its been a long-requested feature, so its great to see it makes its way to the KDE users. I despise virtual desktops, but Im happy to see something that I assumed was already part of KDE to finally actually become available. Another major feature in KDE Plasma 6.7 is something weve already talked about: the return of the classic Oxygen and Air themes from the KDE 4.x days. These themes have seen extensive work over the past year or so to make them usable on the latest KDE release, which includes tons of bug fixes, visual nips and tucks, and countless additions to the collection of assets required to make a modern KDE theme look complete. This includes a ton of new icons in the old styles, light and dark modes, accent colour support, and much more. Theres still work left here, including adding support for QtQuick/Kirigami applications  which brings us to the next major new addition to KDE 6.7 This is also something weve already talked about: Union. I wont repeat what I already explained last time Union came up, but suffice it to say that Union effectively unifies the various different ways KDE applications are themed, allowing theme designers to use relatively standard CSS to create themes that cover every aspect of the KDE user experience. Before Union, theme designers had to create individual, unique themes for a variety of parts of KDE  the Plasma desktop, QtWidgets using QStyle, QtQuick/Kirigami  which was a ton of work, and in the case of QtQuick/Kirigami, wasnt really possible at all. As such, without Union, KDEs theming is essentially broken, and Union fixes that. For now, Union is not enabled by default, and must be installed and enabled separately for testing. Of course, theres a ton of other smaller new features, changes, and bug fixes as well. KDE Plasma 6.7 will find its way to your distribution soon enough.


  • Apple adds keylogger to iOS App Store for targeted advertising: tied to your account and unencrypted
    A week or so ago, Apple announced a bunch of features for the App Store on iOS, including personalised recommendations based on your activity and usage of iOS. It turns out this includes a keylogger (taplogger?) in the App Store, which records every single tap you make, every single letter you enter, and a lot of other information. All of this information is unencrypted and sent to Apple. Now Apple is putting the extensive identifiable analytics they collect in the App Store in action. They record every tap and there’s no way to turn it off. They can even calculate your typing speed. ↫ Michael Tsai, quoting Mysk The provided screenshots of the data collected are terrifying, especially because the data is unencrypted, sent to Apple, and fully tied to your user account. Apple clearly wants a slice of that big, juicy advertising pie, and they, too, are discovering that the easiest and best way to serve targeted ads is to collect as much data as they can about you. Of course, this is something the entire internet (but not OSNews!) and several megacorporations are built on by now, but Apple has been incredibly sanctimonious about how it supposedly actually cares about user privacy, making this keylogger yet another case of Apples hypocrisy on full display. Of course, if you care about privacy, youre entirely free to download your iOS applications from somewhere other than the App Store and install them yours0 Oh, wait.


  • The time the Windows x86 emulator team found code so bad that they fixed it during emulation
    Another story from the good old days from Raymond Chen. During an exchange of war stories, a colleague of mine told one from back in the days when Windows included a processor emulator for x86-32 on systems that natively ran some other processor. (This has happened many times. And no, I don’t know which processor this particular story applied to.) ↫ Raymond Chen at The Old New Thing So the core of the story comes down to this: All in all, it took this program 256 kilobytes of code to initialize 64 kilobytes of data. ↫ Raymond Chen at The Old New Thing The people working on Windows were so offended by this, they added code to the processor emulator just to fix this program.



Linux Journal News

  • EU OS: A Bold Step Toward Digital Sovereignty for Europe
    Image
    A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem.
    What Is EU OS?
    EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.

    Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments.
    The Vision Behind EU OS
    The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.

    Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.

    However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty.
    Conclusion
    EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.

    Source: It's FOSS
    European Union


  • Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.

    In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.

    On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.

    Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.

    The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.

    Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.

    You can download the latest kernel here.
    Linus Torvalds kernel


  • AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
    Image
    AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.

    This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.

    Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.

    Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.

    Source: 9to5Linux
    AerynOS


  • Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
    Image
    Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.

    Here’s a quick overview of what’s new in Xojo 2025r1:
    1. Linux ARM IDE Support
    Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started.
    2. Web Drag and Drop
    One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required!
    3. Direct App Store Publishing
    Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process.
    4. New Desktop and Mobile Features
    This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection.
    5. Performance and IDE Enhancements
    Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced.
    What Does This Mean for Developers?
    Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution.
    How to Get Started
    Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.

    Download Xojo 2025r1 today at xojo.com.
    Final Thoughts
    With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you.
    Xojo ARM


  • New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux

    Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.

    Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.

    Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest. 

    Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.

    Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.

    Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.

    By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem.
    Windows


  • Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities

    The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally. 

    As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.

    In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions. 

    After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.

    The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.

    At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.

    The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca.
    Security


  • Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges

    The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.

    A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.

    This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem. 

    The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.

    On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.

    In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers.
    kernel


  • Linux Celebrates 32 Years with the Release of 6.6-rc2 Version

    Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.

    The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.

    Here is what Linus Torvalds had to say in today's announcement:
    Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds


  • Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction

    Want to interact with ChatGPT from your Linux desktop without using a web browser?

    Bavarder, a new app, allows you to do just that.

    Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.

    With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.

    During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.

    At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.

    As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!

    Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring.
    ChatGPT AI


  • LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite

    Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.

    Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.

    LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.

    You can download LibreOffice 7.5.3 directly from the LibreOffice websiteor from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.

    All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.

    In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.

    Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.

    The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners.
    LibreOffice


Linux Magazine News (path: lmi_news)







  • KDE Linux Drops AUR
    KDE Linux developers have dropped the Arch User Repository from the build pipeline due to security concerns; other distributions should consider doing the same.















Page last modified on November 17, 2022, at 06:39 PM