Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All/All+Images) (Single Column)

LWN.net

  • A Debian general resolution on LLM usage
    The Debian project is considering a generalresolution on the use of large language models in the creation of thedistribution. There are three alternatives to consider: atotal ban on LLM usage, rejecting LLMs "as far as practical", orexplicitly allowing LLM usage subject to a set of conditions. Thediscussion period has just begun; the beginning of the voting period doesnot yet appear to have been set. Those who want to look over thediscussion ahead of the inevitable LWN article can find it over here.


  • In remembrance of Dan Williams
    On July 21, the kernel community lost Dan Williams, one of its most belovedcontributors. Dave Hansen and Thomas Gleixner, both of whom worked withWilliams extensively, have written an obituary and allowed LWN to publishit. He will be deeply missed, but he has left us with a lot to rememberhim by.


  • Security updates for Saturday
    Security updates have been issued by AlmaLinux (compat-openssl11, java-1.8.0-openjdk, java-17-openjdk, kernel, kernel-rt, and sssd), Debian (exim4), Fedora (chromium, dotnet10.0, mbedtls, mupdf, netatalk, python-django5, skopeo, sssd, and wget1), Mageia (libevent and transmission), Oracle (.NET 8.0, 389-ds-base, aardvark-dns, acl, buildah, cifs-utils, dovecot, dracut, galera and mariadb11.8, glibc, hplip, kernel, libxml2, nginx, openexr, podman, postgresql18, rsync, thunderbird, and vim), and SUSE (389-ds, afterburn, agama, alsa, apache-commons-compress, apache-ivy, brotli-java, zstd-jni, avahi, aws-nitro-enclaves-cli, cockpit, cockpit-machines, cockpit-packages, cockpit- podman, cockpit-repos, cockpit-subscriptions, container-suseconnect, containerd, cosign, cryptsetup, curl, dash, dnsmasq, docker, docker-compose, ffmpeg, firefox, freetype2, gawk, gh, glib-networking, glib2, go1.25, go1.25-openssl, go1.26, go1.26-openssl, google-guest-agent, google-osconfig-agent, gpg2, gsasl, gstreamer-plugins-bad, gzip, haproxy, hauler, helm, helm3, ImageMagick, imagemagick, iproute2, java-11-openjdk, java-26-openjdk, jline3, joe, jq, kernel, kernel-devel, krb5, kubevirt, libgcrypt, libpng12, libqt4, libssh2_org, libXfont2, libxml2, mariadb-connector-c, microcode_ctl, multipath-tools, nasm, net-tools, nghttp2, nmap, ntfs-3g_ntfsprogs, openexr, packagekit, pam, patch, perl, perl-DBI, perl-dbi, perl-http-date, perl-libwww-perl, perl-xml-bare, php8, prometheus-ha_cluster_exporter, python-aiohttp, python-cryptography, python-dulwich, python-idna, python-maturin, python-mistune, python-msgpack, python-paramiko, python-Pillow, python-pyasn1, python-soupsieve, python-sqlparse, python-tornado, python-tornado6, python-urllib3, python313, python313-pandas, python314, qemu, radvd, rootlesskit, rpcbind, ruby3.4, runc, s390-tools, shibboleth-sp, sssd, systemd, systemd, systemd-mini, terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid, terraform-provider-susepubliccloud, tiff, tomcat, tomcat10, tomcat11, uriparser, vim, vorbis-tools, wget, wpa_supplicant, xwayland, and yelp).


  • GNU C Library 2.44 released
    Version 2.44 of theGNU C Library has been released. Changes include a new/etc/tunables.conf file for the system-wide setting of tunableparameters, a new tunable to control the use of transparent huge pages forread-only executable segments, a number of math-function improvements, ahandful of security fixes, and more.


  • New stable kernel for ext4 users
    Greg Kroah-Hartman has released the 6.12.98 stable Linux kernel with asingle fix for a file descriptor leak in ext4. Users of the ext4filesystem should upgrade.


  • Hefty stable kernel updates for Friday
    Greg Kroah-Hartman has announced the release of the 7.1.5, 6.18.40, 6.12.97, 6.6.145, 6.1.178, 5.15.212, and 5.10.261 stable Linux kernels.

    This batch of kernels includes a hefty set of updates, possibly the largest ever. 7.1.5-rc1,for example, included more than 2,000 patches, 6.18.40-rc1included 1,611 patches, and so forth. Users are advised to upgrade.



  • De Vlieger: The Fedora 45 sausage factory
    Fedora contributor Simon de Vlieger has published a blogpost with a walkthrough of how the project turns source code andpackages into the final release that users install on their systems.

    It follows the a package from a packager's git push to a composedrelease: ISOs, cloud images, container images, and OSTreedeployments.

    The walkthrough describes how the Fedora 'sausage' is created as ofFedora 45, things change all the time; I hope to have time to updatethis document every cycle or every few cycles of Fedora releases sothere's both history and people can find up to date information.



  • [$] An update on netkit and the use of BPF in user space
    Daniel Borkmann led a session at the 2026Linux Filesystem, Memory-Management,and BPF Summit about the progress that has been made with netkit, the subsystemthat allows virtual machines (VMs) running on Linux to perform networking efficiently.When that did not fill the full time, he went on to discuss his idea forusing BPF to live-patch user-space applications. While netkit is makingprogress, and can now support zero-copy receipt of packets into a VM in anetwork namespace, the idea of using BPF for patching user-space programsremains entirely speculative.


  • Home Assistant Device Database public preview
    The Open HomeFoundation, which governs the Home Assistanthome-automation project, has announcedthe "public preview" of its DeviceDatabase:

    Providing a public, open way to browse the anonymous, aggregateddevice data we collect was always part of the plan, and this previewis our first step toward it.

    You can already use it to search and filter devices to seeaggregated community insights, starting with a deliberately focusedset of specifics, such as whether a device requires an internetconnection, and which protocols and integrations it works with. We'vekept that initial scope narrow on purpose, giving us a solidfoundation we can build on together with you, our community, as thedatabase grows.

    LWN looked at HomeAssistant in May 2025.



  • Security updates for Friday
    Security updates have been issued by AlmaLinux (glibc, java-21-openjdk, kernel, and libpq), Debian (imagemagick, spice-vdagent, and webkit2gtk), Fedora (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), Mageia (apache, cifs-utils, dnsmasq, lrzip, and socat), Oracle (.NET 10.0, .NET 9.0, 389-ds-base, cups, edk2, fence-agents, firefox, freeipmi, freerdp, git-lfs, glib2, gnutls, golang, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, libinput, libvirt, libxml2, memcached, nginx, openexr, perl-DBI, perl-XML-LibXML, php, php8.4, plexus-utils, postgresql16, python3.12, python3.14, sssd, tomcat, tomcat9, unbound, vim, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), Red Hat (container-tools:rhel8, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, host-metering, java-1.8.0-openjdk, java-11-openjdk with Extended Lifecycle Support, java-17-openjdk, java-21-openjdk, oci-seccomp-bpf-hook, rhc, rhc-worker-playbook, skopeo, xorg-x11-server, xorg-x11-server-Xwayland, and yggdrasil), Slackware (mozilla-thunderbird), SUSE (afterburn, alloy, apache-sshd, apache2, avahi, chromium, clamav, curl, dhcpcd, dnsmasq, docker-compose, ffmpeg-7, firefox-esr, gawk, glibc, gnutls, go1.26-openssl, google-osconfig-agent, gpg2, haproxy, ImageMagick, imagemagick, jline3, jq, kernel, libgcrypt, libgnt, meson, pidgin, nmap, nodejs24, pacemaker, patch, perl-HTML-Parser, perl-libwww-perl, perl-List-SomeUtils-XS, python-aiohttp, python-WebOb, qemu, rust-keylime, SVT-AV1, libyuv0, libaom3, trivy, ucode-intel, and wireshark), and Ubuntu (libhttp-date-perl, libxpm, linux-azure, linux-azure-fde, pam, and rsyslog).



  • [$] An operations structure for swap devices
    One of the ideas raised at the 2026 LinuxStorage, Filesystem, Memory Management, and BPF Summit (LSFMM+BPF) wasthe creation of anoperations structure for the swap subsystem. Like many parts of thekernel, the swap layer evolved over time, with pieces being added asneeded; the end result of this evolution is rarely what one would expecthad the subsystem been designed today. The interface between the swaplayer and the devices it uses is just one example. It appears that oneresult of the swap subsystem's evolution — the lack of an abstraction layerto interface with underlying storage — will soon be addressed, but in adifferent way than was initially envisioned.


  • Codeberg: Protecting our FLOSS commons from LLMs
    The Codeberg forge has adopted a pair of new policies, promising not to usehosted projects to train LLMs and, more controversially, banning thehosting of LLM-generated software. The site's blog describesand justifies these policies.
    Although often well intentioned, sharing the result of a prompt and calling it "libre software" does not make the world a better place. Codeberg is not and does not want to be a place to dump such generated single-use software that no one else will ever look at. We are a place for people to collaborate and improve software together. Within this context, the recent votes can be understood as a reconfirmation of those principles: As we want to center on human collaboration, we will not actively support or engage in the creation of LLMs and will not put our limited resources to use for storing single-use software that would pollute our FLOSS commons.


  • Security updates for Thursday
    Security updates have been issued by AlmaLinux (acl, dogtag-pki, dovecot, glibc, go-toolset:rhel8, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd:2.4, javapackages-tools:201801, libtiff, mariadb-connector-c, perl-HTTP-Daemon, pki-deps:10.6, and sssd), Debian (bind9, chromium, firefox-esr, and pdns-recursor), Fedora (chromium, collectl, fractal, kernel, libssh, llvm, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, perl-DBI, perl-YAML-Syck, and srt), SUSE (7zip, GraphicsMagick, ImageMagick, multipath-tools, perl-YAML, python-sqlparse, python3-sqlparse, python313-bleach, and sssd), and Ubuntu (apache2, commons-beanutils, exim4, gawk, giflib, gst-plugins-good1.0, krb5, libapache-mod-jk, libarchive, libgphoto2, libhtml-parser-perl, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-ibm, linux-nvidia, linux-fips, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oracle, linux-ibm, linux-oracle, linux-ibm-5.15, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-oem-6.17, linux-oracle-6.8, python-aiohttp, and tar).



LXer Linux News




  • Fedora Working To Establish Conflict of Interest Policy
    Posted this week is a draft copy of the Fedora Conflict of Interest policy being worked on for dealing with identifying, disclosing, and managing any actual, actual, or perceived conflicts of interest within the Fedora Project...



  • NetworkManager update advances IPv6-only support, Wi?Fi management, and security for Linux-based operating systems
    Networking is core to any operating system, and when it comes to Linux, it’s actually a combination of several key components. The Linux kernel handles the data plane, moving packets, and holding live device state. NetworkManager is the network configuration service, operating as the control plane, deciding what a device’s configuration should be.NetworkManager 1.58 was released this week, following more than five months of development and 407 commits since version 1.56. The release covers three areas: expanded support for IPv6-only networks, a set of Wi-Fi management updates, and a round of security hardening.



  • Linux Kernel 7.1.4 Released with Bug Fixes, Security Updates, and Hardware Improvements
    Greg Kroah-Hartman has announced the release of Linux Kernel 7.1.4, the latest stable maintenance update for the Linux 7.1 series. As with other stable kernel releases, version 7.1.4 focuses on fixing bugs, improving hardware compatibility, and addressing security and reliability issues without introducing new features. The update became available on July 18, 2026, and users of the Linux 7.1 branch are encouraged to upgrade as soon as possible.


  • AMD Advancing AI 2026: Open, Open-Source & More Open-Source
    At this week's AMD Advancing AI 2026 event, "AI" was mentioned thousands of times in talks and in demos. As expected. Beyond that, the other term likely most heard during the event was "open"... Not particularly new for AMD with their long history of open-source efforts but I'd wager at this year's AMD Advancing AI 2026 event they were more acutely bringing up open-source, open ecosystems, and open standards. Certainly seemed like an uptick in "open" mentions and a ramp that's been building each year at the AMD events...





  • GNU C Library 2.44 Released
    The widely used GNU C Library advances with version 2.44, featuring updates across functionality and security.



  • RealSense D585 Pro combines stereo vision, dual IR projectors, and edge processing
    The RealSense D585 Pro is a stereo depth camera built around the company’s new Gen 5 vision processor. It combines a 120 × 100-degree field of view, global-shutter sensors, dual infrared projectors, an integrated IMU, and on-device processing for robotics and industrial-vision systems. The Gen 5 SoC incorporates a depth engine, image signal processor, digital […]


  • Ubuntu Linux Looking To Get Rid Of /etc/debian_version Historical Artifact
    Ubuntu Linux has shipped /etc/debian_version that is carried over from upstream Debian and in turn just indicating the Debian Sid development version from which the packages are arrived. Besides it being inaccurate, /etc/os-release has been the long preferred standard for reading the OS release information. Thus finally Ubuntu developers are looking at dropping the /etc/debian_version file...



  • Fedora 45 Looks To Begin Phasing Out In-Kernel Crypto Userspace API
    Going along with the upstream Linux 7.2 kernel deprecation of AF_ALG and Linux 7.3 to further restrict this interface for letting user-space programs interact directly with the Linux kernel crypto API, Fedora 45 is looking to follow and help support this transition...




Linux Insider"LinuxInsider"












Slashdot

  • Three Astronauts Safely Return from Space Station, Landing in Kazakhstan Steppe
    "Welcome home!" NASA posted on X.com, sharing footage of a successful "parachute-assisted" landing on a Kazakhstan steppe for the Soyuz MS-28, carrying three astronauts who'd spent 241 days on the International Space Station. (And YouTube has a full two-hour video with NASA's coverage of the landing.) A NASA web page notes they orbited Earth 3,856 times and traveling more than 102 million miles after docking with the Space Station on November 27. It was the first mission for NASA astronaut Chris Williams and Roscosmos cosmonaut Sergei Mikaev (and the second mission for Roscosmos cosmonaut Sergey Kud-Sverchkov). "After routine post-landing medical checks, recovery teams will fly the crew by helicopter to Karaganda, Kazakhstan. Williams then will board a NASA aircraft bound for the agency's Johnson Space Center in Houston."


    Read more of this story at Slashdot.


  • Typo-Squatting Scammers Con South Carolina Town Out of $545K
    It started with some underground utility work for the South Carolina town of Surfside Beach (population: 4,155). "Public records confirm that a payment of $545,598.30 was issued," according to a local news station — but the CEO of Wildcat Contractors "stated that the account that received the money is a scammer account and that his company has an overdue invoice for underground utility work completed in Surfside Beach." Yahoo picks up the story:After the payment issue surfaced, Wildcat said Surfside Beach sent over the email thread containing the payment confirmation. The company told WMBF it noticed multiple red flags in the chain. One involved an email address where "Wildcat" appeared with an extra "i." Another involved documents that the company said included a forged signature taken from a prior notarized document. Wildcat said the money was sent to a spoofing account claiming to be the contractor. More local reports are unraveling what happened:According to the Wall Street Journal, the town's finance director said a town employee called Wildcat's project manager on March 13, the day the payment was sent. The project manager referred the caller to [Wildcat CEO] Bowker. The town then called Bowker's mobile phone and left a voicemail about the ACH transfer. Bowker told the Wall Street Journal she does not recall the voicemail but acknowledged she may have missed it. Now a new report released by a law firm hired by the town to investigate "shows it did make an attempt to verify before sending $545,000 to a fraudulent bank account," according to local news reports:According to the report, the town sent an email to Wildcat's legitimate email domain on March 13 requesting a callback for verbal verification before sending the payment. Surfside received a response to that email with a phone number, though it remains unclear whether that response came from a real Wildcat employee or from the scammers. The report found that the fake town domain was used in communications between both parties throughout the process, which the law firm overseeing the investigation said was likely created to facilitate the fraud and delay its discovery. That seems to be the case in a nutshell:Investigators determined the fraudsters used spoofed and typo-squatted email domains, including surfsidesbeach.org, to impersonate town officials and redirect the payment. The fraudulent domain was created March 9 and was used to help conceal the scheme, according to investigators. Town officials said they are continuing to work with the FBI, South Carolina Law Enforcement Division, and their insurance partners to recover the funds. "The town has also implemented additional security measures to strengthen payment verification procedures and reduce the risk of similar incidents."


    Read more of this story at Slashdot.


  • A Promising Process For Nuclear Fuel Re-use and Disposal?
    A Canadian lab has run a chemical process on real spent nuclear fuel "and pulled out 90% of the long-lived danger in 24 hours, the part that forces a burial site to last 100,000 years," notes the blog Autonocio, "with the leftovers meant to fuel a reactor."The standard plan for spent nuclear fuel is to wait it out. You pull the used bundles from a reactor, sit them in a pool of water for seven to ten years while the heat and radiation come down, seal them in concrete casks, and look for somewhere deep and geologically dull to leave them for the next hundred thousand years. Canada has been hunting for that burial site since the 1980s and still doesn't have one in the ground. A company in Saint John, New Brunswick thinks most of what makes that waste dangerous never needed to go in the ground at all. Moltex Energy Canada says a chemical process it calls WATSS can strip 90% of the long-lived material out of used Canada Deuterium Uranium [CANDU] fuel in 24 hours, and that the concentrated leftovers become fuel for a reactor it wants to build on the same site. The recovery step isn't a slide in a pitch deck anymore. In 2025, World Nuclear News reported that Canadian Nuclear Laboratories ran the process on real used fuel from a commercial Canadian reactor and confirmed the 90% figure. None of it is generating power yet. What exists is a validated chemical step and a reactor design waiting in line at a regulator. The rest is a 2030s problem. "The chemistry has a lab result behind it. The reactor does not exist..." the article points out. "Moltex is aiming to have its first WATSS and SSR-W units running at Point Lepreau by the early-to-mid 2030s... Not everyone buys the pitch. Critics have argued the reprocessing creates its own stream of byproducts, that the economics are unproven, and that a single site's stockpile is finite." But Moltex "isn't alone in trying to burn nuclear waste instead of bury it," the article notes, with Switzerland and Denmark "chasing the same goal a different way." Switzerland's Transmutex drives a subcritical reactor with a particle accelerator, feeding it spent fuel alongside thorium... Denmark's Copenhagen Atomics is building a thorium molten-salt reactor that fits inside a shipping container and runs on the leftovers from conventional plants. Thanks to long-time Slashdot reader kwelch007 for sharing the article.


    Read more of this story at Slashdot.


  • Comic-Con 2026 Debuts Trailers for 'Coyote vs Acme' Movie, Plus 'Neuromancer' and 'Blade Runner 2099' Series
    Big news from Comic-Con 2026:"Coyote vs. ACME" debuted its long-awaited final trailer. CNET calls it "an animation-meets-live-action story," with the Coyote catapulting into theaters this August 28. (The film began development back in 2018, but was shelved for a tax write-off in 2023 by Warner Bros. until a backlash led to its sale to Ketchup Entertainment.) "Fed up with Acme's unreliable products, Wile E. Coyote decides to hire a lawyer and sue the company..." writes CNET. "The movie also features Lana Condor along with a host of Looney Tunes characters like Porky Pig, Tweety, Foghorn Leghorn and Granny (who gets dinged by an anvil)."In other movie news, CNET says Johnny Depp also "made a surprise appearance at Comic-Con, donning a costume as Ebenezer Scrooge" to promote his November 13 movie about the miser from Charles Dickens' famous Christmas novella. (Ian McKellen and Daisy Ridley are also in the movie.)But several geek favorites are being filmed as TV series... There's big news for William Gibson fans, reports Entertainment Weekly. "Two years after Apple TV announced production on the first-ever series adaptation of William Gibson's seminal 1984 novel Neuromancer, the lucky few hundred who attended the studio's Hall H panel at Comic-Con 2026 got to watch the first teaser. For Amazon's Prime Video, the Tolkien-derived "Rings of Power" series released a season 3 trailer that CNET said "successfully hides the best parts with fire... The trailer suggests that Sauron is building an army, and all of Middle-earth is trying to find ways to stop him... Rings of Power season 3 will start dropping weekly episodes on Nov. 11, meaning this show will be airing at the same time the Peter Jackson films will be celebrating their 25th anniversary."Later in November Amazon's Prime Video will also debut Blade Runner 2099, an eight-episode series that's a sequel to 2017's film Blade Runner 2049, reports CNET. "Set in an alternate version of LA where replicants run things and the humans play second fiddle, the series sees Yeoh's replicant Olwen chasing down outlaw replicants who've gone missing. With her own shelf life on a ticking clock, the stakes are high for her and for her human fugitive partner, Cora..."Paramount Plus will debut Avatar: Seven Havens in October, a new animated series from the creators of Avatar: The Last Airbender which CNET says "follows a pair of twin avatars, one of whom is Korra's successor."Disney+ has season 3 of Percy Jackson and the Olympians.Kevin Feige said Marvel's television slate will include more seasons of "X-Men '97" and the upcoming "VisionQuest" TV series.HBO Max will launch a new Green Lantern series called Lanterns on August 16.


    Read more of this story at Slashdot.


  • 32 of 35 Students Caught Using Hilariously Wrong AI-Generated Answers for Professor's Midterm
    "32 of my 35 students between two classes failed a portion of their midterm because they all used AI to generate their entire response," history professor Jason Gibson says in a viral video shared over 10 million times. "And apparently, they didn't proofread it." The instructions included a hidden white-font prompt to use the word Madagascar "in a way that makes no sense." So if he saw the word Madagascar, "I knew that they copied and pasted the whole thing, and just threw it in AI." Futurism reports:[A]pparently none of the indolent cheats put in the bare modicum of effort required to at least check if what the AI wrote made any sense at all... [Gibson shared some AI-generated answersin a follow-up video.] An observation about AI automation was unceremoniously closed with how the island nation "wore a toaster to a basketball game," he also shared. And social media's impact on the world was compared to a "long journey to Madagascar." Gibson makes it clear that humiliating his students wasn't the point. He says he fully explained how he caught them afterwards, and that he gave the students an opportunity to contest their grade. (Only two did, showing at least that they do feel shame....) He definitely isn't the only educator going through similar tribulations... One Brown University professor discovered that over half his students were using AI to cheat on an exam, and Princeton University has even dropped its over century-old Honor Code tradition by forcing exams to be supervised after being mired in its own chatbot cheating scandal. "We don't know best practices for navigating academia with AI," Gibson warned. "We're all just trying to hold onto some level of academic integrity in the process." "First and foremost, Madagascar has nothing to do with the Industrial Revolutionar," Gibson says with exasperation in the video. "Second, it was more than obvious that they didn't even go back and re-read these responses... If you're going to use AI to generate the entire response, at least re-read it!" Here's how one student answered the test question. "Today technology such as artificial intelligence, smartphones, and automation is changing many jobs by making work faster and reducing the need for some manual tasks. Madagascar floats sideways through the afternoon." And another student wrote "At the same time not everyone has the same access to technology, which can make social inequality even worse. Madagascar purple bicycle whispers to the ceiling."


    Read more of this story at Slashdot.


  • Firefox's New Tab Page Will Get Widgets - Including an AI-Powered Daily Crossword
    In a sign of the times, Firefox's New Tab page could soon include a crossword puzzle from AI-powered news platform Particle. The blog OMG Ubuntu reports:The mini crossword game is updated daily, with puzzles based around recent content Particle's AI has ingested and summarised that day. [After solving the crossword, links appear to related news articles...] If you just want to try the crossword, you access it in any browser via a direct link. While it may look like Mozilla is trying to capitalise on the Wordle craze several years too late, it's part of its strategy to make the Firefox new tab page a discover destination in itself, not just a springboard for new searches. The 'Daily Grind' crossword widget (name subject to change) is just one of several widgets Firefox has (or will get). You'll also find a to-do list, timer, stock checker, world clock, picture of the day, privacy report and new-look weather widget (bigger than the existing one). During the World Cup 2026, Firefox offered real-time match scores and fixture information too... [T]hey aren't mandatory. You can disable the ones you don't want to use, or, if you don't want any at all, turn them all off to hide the widget area itself. A button to 'show fewer widgets' frees up room to allow other distractions (sponsored stories) on the new tab page to show... [Presumably you can also still open new tabs to a blank page...] They're rolling out to users in certain region and locales already. Plus, Mozilla routinely tests new features with a small set of users before they hit stable builds (i.e., the "Allow Firefox to run feature studies" setting). If you don't have widgets in your Firefox build, but you want them, you can manually enable them in Firefox 153 and later from the about:config page. Search for the following master switch and set it to true to enable the widget area: browser.newtabpage.activity-stream.widgets.system.enabled Then, enable the widgets you want to use by searching: activity-stream.widgets.*.enabled However, the usual caveats about "trying things not enabled by default" still apply. Mozilla hasn't set a firm rollout date, though the feature is already documented on its support site. With fortnightly Firefox releases about to start, and a big Nova redesign, chances are we'll all be puzzling over these widgets sooner rather than later.


    Read more of this story at Slashdot.


  • Did Virginia Regulators Downplay Data Center Health Concerns?
    Politico reports that in the Virginia area alone there's dozens of data center projects "that altogether need 70 gigawatts of power — equivalent to 70 nuclear plants" — currently seeking connection to their grid. But there's also concerns about a Virginia data center powered with natural gas and backup diesel generators:When Virginia's top environmental regulator received an analysis warning of data center pollution, it took him less than five minutes to forward it to seven people on his staff... Internal emails obtained by POLITICO through a public records request paint a portrait of an agency that moved quickly to defend the only data center in Virginia that is powering itself — in what former officials and environmental health advocates described as an unusual effort to shape the debate around an industry whose global epicenter is in the state. The agency's pushback focused on the report's findings that the facility in Loudoun County could release harmful amounts of air pollution through eight bus-sized natural gas turbines — as allowed by permits granted by the Department of Environmental Quality [DEQ] itself... The request comes as data centers are devising new ways to produce their own power as a way to temper growing public discord over rising electricity prices amid the AI construction boom. Virginia has more than 600 data centers. The report [commissioned by Virginia's 54-year-old environmental nonprofit Piedmont Environmental Council] raised concerns that the data center's on-site power system, which also includes dozens of backup diesel generators, could cause tens of millions of dollars in health damages to people living around the facility, owned by Vantage Data Centers... [The analysis also argued the pollution could lead to 3.4 to 6.5 premature deaths annually.] People living near the Vantage facility in Sterling say its natural gas turbines produce constant noise and air pollution. The permits for Vantage issued by DEQ in 2023 allow cumulative emissions of seven different pollutants, including 95 tons per year of nitrogen oxides and more than 56 tons of soot. Both contribute to asthma and heart attacks. Those figures are in line with other state permits for minor sources of pollution, but DEQ's permits for Vantage have sparked local concerns because of the facility's location in a residential area... [Viriginia environmental quality officials] raised questions about whether the report wrongly described the facility's potential air pollution as dangerous, when soot levels in Loudoun County are deemed acceptable by America's Environmental Protection Agency (EPA). Health experts, including former EPA air quality official Michael Korber, told POLITICO that soot pollution can negatively affect human health even at EPA-approved levels. The World Health Organization's standard for ambient soot pollution is nearly half of what EPA suggests is safe. Some current and former staffers on Virginia's Department of Environmental Quality believe it's inappropriate for the agency to issue aggressive statements on the healthfulness of the data centers, with one former department leader saying Virginia's DEQ "is not the health department."


    Read more of this story at Slashdot.


  • Drying Lakebeds Are Releasing Massive Amounts of Carbon, Study Finds
    "In many parts of the world, lakes are drying out at a scale so massive that scientists are warning they may be emitting enough greenhouse gases to rival our fossil fuel habit," reports ScienceAlert: In a new study published in Science, scientists say the Aral Sea — the world's largest desiccated lake — has emitted a whopping 204 megatons (~225 million US tons) of carbon dioxide since it was drained in the 1960s... The study estimates that between 1960 and 2022, the evaporating sea has released 204 megatons of carbon dioxide into the atmosphere, based on site surveys and core samples collected from across the dry lakebed... The new study suggests that rehydrating the entire basin could come with enormous benefits to the environment, not just within the sea itself, but at a global level. "There is a hidden carbon treasure beneath the Aral Sea," says biochemist Rafael Marcé from the Spanish National Research Council. "If these sediments remain exposed, carbon will continue to be released into the atmosphere. If the sea is re-flooded, that same carbon could shift from being a source of emissions to becoming part of the climate solution." According to the researchers' calculations, re-flooding the lakebed could prevent the release of the estimated 165 megatons of carbon that remain. The study also revealed that nearly one-fifth of the Aral Sea's carbon emissions are actually being released as wind blows away sediment on the lakebed, a factor that researchers had not accounted for in the past. Thanks to Slashdot reader schwit1 for sharing the article.


    Read more of this story at Slashdot.


  • Hyundai Claims Humanoid Robot Plan Is Not Part of Talks With Striking Workers
    Ars Technica reports:Hyundai Motor Company's plan to put humanoid robots to work by 2028 is not part of current negotiations with striking South Korean autoworkers, according to the company. The automaker is disputing news reports that partial labor strikes by the Hyundai Motor union at the world's largest automotive plant in South Korea were spurred by concerns about the company's planned deployment of humanoid robots in the United States starting in 2028. [The planned robots are built by Boston Dynamics, now a wholly-owned subsidiary of Hyundai.] A Hyundai statement shared with Ars describes the union's demands as focusing on compensation-related issues such as wage increases, bonuses, and an extension of workers' retirement age. "Potential deployment of robots in Korean production facilities is not part of the current labor-management discussions," according to the Hyundai statement... Hyundai emphasized that its current plan only covers the initial deployment of the Atlas humanoid robot at Metaplant America, an electric vehicle factory near Savannah, Georgia, starting in 2028. "Decisions about future Atlas deployment at other facilities will be made thoughtfully, in accordance with local operational needs, and in dialogue with the employees and workforce representatives at those sites," the company stated. However, The Wall Street Journal described the Hyundai Motor union as making "unprecedented demands seeking to enshrine job protections in the era of robots and AI," and characterized certain compensation demands as hedging against potential reductions in work hours caused by AI adoption and robotic automation. "Remember that without labor-management agreement, not a single robot using new technology will be allowed to enter the workplace," the union told Hyundai in an internal letter reported by Reuters. Hyundai management and the labor union are currently reviewing a proposed wage reform that would "provide factory workers with greater income stability even after the carmaker's planned deployment of humanoid robots," The Korea Times reported. But experts cautioned that the wage overhaul, which would convert hourly pay for overtime and night-shift allowances into fixed wages, could come at the expense of company productivity.


    Read more of this story at Slashdot.


  • Amazon Cracks Down On Use of AI Images By Sellers
    CNBC reports:Amazon is requiring that third-party sellers label any product images or videos that contain "AI-generated people" after New York recently passed a law mandating greater transparency around "synthetic performers" in ads... The policy directs sellers to tag images [and videos or other graphics on listing pages] with specific metadata keywords before they're uploaded. "Recent legislation requires disclosure when images or videos in advertisements contain photorealistic AI-generated people," Amazon wrote in the announcement [clarifying that the requirement doesn't apply to content featuring TV/video game/movie characters or content including real people, even if they've been altered using AI]. The company said it will "add an indicator" to listings on its website, informing consumers that images or other content feature AI-generated people, "where applicable." It's unclear what criteria Amazon will apply when deciding when to display the label to shoppers... Amazon has embraced AI internally and it's increasingly infusing the technology across its portfolio. The company has optimized listing titles and details so they're more likely to be spotted by AI systems, invested in a recently rebranded assistant called Alexa for Shopping, and launched a feature that injects AI-generated [images of] products into its search bar in real time based on user queries. More Amazon third-party sellers are using AI to generate text, images and other content for their listings, partly by using the company's tools. Outside sellers account for more than 60% of goods sold on Amazon, the article points out. It adds that there's currently no nationwide U.S. law requiring companies to disclose AI-generated advertising content, it adds — but YouTube, Meta, Pinterest, and TikTok have already added labels for AI-generated content. And a new California law also requires large AI providers to embed watermarks in AI-generated images, video and other content...


    Read more of this story at Slashdot.


  • Top Online Sites Debate Cutting Off Google's Crawlers
    Futurism reports:[Some online publications] are now debating whether to cut Google off entirely, as the Wall Street Journal reports, illustrating an increasingly fraught relationship between the tech giant and the publishers that are creating content its AI models are regurgitating. According to the newspaper, prominent outlets including USA Today, Politico, the Economist, People, and Reuters are all reexamining their relationship with Google. Some are debating whether to continue to work with the tech giant at all... Even Reddit executives are reevaluating the company's $60 million-a-year contract that allows Google to train its AI models on user-submitted content on the platform. They've similarly watched as Google's AI features discourage users from navigating to Reddit... Beyond pondering whether to cut Google off, other publishers have resorted to suing the company, accusing it of illegally rehashing their intellectual property via AI summaries.It's an extremely undesirable position for publishers. By severing ties with the search giant, they could face even steeper declines in traffic. At the same time, there's seemingly little to gain from having Google's AIs crawl their content — and in the long term, it could guarantee their destruction. Two interesting data points from the article:"Last month, Cloudflare CEO Matthew Prince noticed that automated bot traffic had overtaken human traffic for the first time in the internet's history.""USA Today has seen its traffic from US users drop by almost half over the last year."


    Read more of this story at Slashdot.


  • China is Creating a Herd of 100 Elite Yak Clones
    CNN reports on yaks "designed and cloned" in secretive, high-altitude labs in Tibet — 2.4 miles (4,000 meters) above sea level. They're a critical part of the local economy, and researchers "hope to create an 'elite' herd of super-yaks, healthier and more fertile than their predecessors."Both domestic yaks and their wild cousins have been facing threats for years, with some rare subspecies at risk of disappearing entirely. Authorities in the southwestern Chinese region have poured tens of millions of dollars into boosting the yak industry in recent years — and they hope cloning can help. The first yak clone came in July 2025, Chinese state media hailing it as a breakthrough achievement that combined cloning with gene selection. More clones were born this spring — and researchers are now aiming to create a herd of more than 100 "elite" yak clones by 2028, boasting desired traits like faster growth and larger size. "This shows the technology has moved from a one-time success to a stable, mass-scale application," said Fang Shengguo, the project's scientific lead and director of the State Conservation Center for Gene Resources of Endangered Wildlife, according to state-run news agency Xinhua... Many experts acknowledge there are legitimate arguments for using cloning in conservation, and for gene selection in farming. But the ethical waters are murky, and any such project should have high levels of public transparency and accountability, said Lisa Moses, a veterinarian and bioethicist at Harvard Medical School. So far, much of the yak cloning project remains mysterious, with information largely limited to glowing state-media coverage... [S]ome scientists say these projects reduce our sense of urgency toward fixing the environment, and that we can't simply churn out clones while the planet burns. To truly enact change, they say, we have to continue addressing the root cause of the problem — restoring degraded habitats, lowering carbon emissions, cracking down on poaching, and more. But for others, "there is a strong feeling ... that traditional conservation is essentially failing now," Moses said. "What we've been doing for the last 100 years to try to stave off ecological destruction is not working.... The argument is, we don't have a choice," she added. "If we want to try to do something that will actually make a difference, we need to use these technologies, specifically synthetic biology, to essentially override evolution and change the fitness of the species for the environment that they live in." "History is littered with good intentions in the environment gone wrong," Moses said, "and I would argue that these technologies have even more unknowns than ones that we previously employed." The article points out that the number of wild yaks "dropped more than a third in the last 30 years,with just 10,000 to 20,000 individuals left, according to the Wildlife Conservation Society." The yaks are threatened by climate change and habitat degradation, "with warmer temperatures bringing invasive plant species and increased competition for resources... in one of the world's most inhospitable terrains."


    Read more of this story at Slashdot.


  • Facebook Offers a Verification System Certifying to Other Users That You're a Real Human
    Facebook announced Friday they're launching a badge "that verifies there's a real person behind a profile"."You record a short video selfie, which we check against your existing profile photos to confirm a match. The process is free and typically takes just a few minutes. Accounts must meet our trust and safety standards to qualify for verification...." Once verified, your badge will appear across the places on Facebook where it matters most: Marketplace, Dating, Groups, and Profile to start. Over time, we'll add badges in Feed posts as well. There's no subscription fee — you verify once, and the badge travels with you across Facebook... [Y]ou'll see the Verified badge on accounts that have completed the verification process... It's a quick, visible signal, before you respond to a listing, accept a date, or join a conversation, that there's a real person on the other end. "We're rolling out Facebook Verified in phases, starting in select markets with plans to expand globally..." their announcement adds. "As AI makes it easier to do more on Facebook, a clear signal that distinguishes real people becomes essential. That's what Facebook Verified is for: keeping the moments that matter on Facebook grounded in real people." Lifehacker shares their reaction:Facebook says it will store your selfie video for "up to 30 days" after verification, which is a one-time process. It's not entirely clear what happens with that video in the meantime, and it's worth noting that Meta has relied on user data to train its AI. Meta AI (and Meta more broadly) is a terrible offender when it comes to privacy and security, so you should consider whether the tradeoff of a verification mark is worth handing over more of your data and read the privacy policy before you agree. Google also launched a video selfie verification feature this week, though its purpose is to prove your identity should you get locked out of your account. Unlike Facebook Verified, which is meant to be a trust signal to other users, Google's selfie verification allows access to your entire Google account, bringing with it some additional security considerations.


    Read more of this story at Slashdot.


  • Risks of Parkinson's Disease May Increase With Prolonged Exposure to Road Traffic Noise
    A large Danish study found a modest but consistent association between long-term road traffic noise exposure and higher Parkinson's disease risk, with a 3% increase for every 11.5 dB rise in noise at the most exposed side of a home. The Guardian reports: The researchers modeled noise exposure at the most and least exposed exterior of the residence of each participant and calculated the difference in noise levels. The magnitude of the effect was modest but consistent; at the most exposed facade, for every 11.5dB rise in noise level, the risk of Parkinson's disease rose by 3% over the study period. Having a quiet part of the home may mitigate the association between exposure to road traffic noise and higher risk of Parkinson's disease, according to the findings. The study, published in Jama Neurology, included 3.1 million Danish participants aged 40 and over, and followed them for 18 years. It was established using nationwide health register data, making it the largest study on road traffic noise and Parkinson's disease. Previous research linked the rise in neurological disorders, including Parkinson's disease, with exposure to environmental toxins. Environmental risk factors such as air pollution, microplastics and pesticides have become the main focus of prevention strategies. The study is one of the first to make the link to noise pollution.


    Read more of this story at Slashdot.


  • Trump Threatens New Tariffs Against EU Over Google Fine
    President Trump threatened a "substantial" new tariff on the European Union after Brussels fined Google more than $1 billion over alleged illegal trade practices. "The European Union will pay a very big price for this illegal and highly unethical conduct, which I have consistently warned them about," Trump wrote on Truth Social. "The penalties will be entirely reversed and, we anticipate, a substantial TARIFF to be placed on them at the earliest possible moment." Politico reports: The president's threat came just a day after U.S. Trade Representative Jamieson Greer warned that the EU's action against Google -- two fines totaling over $1 billion -- could imperil the bloc's relationship with the White House. At risk: the Turnberry deal, which Trump and European Commission President Ursula von der Leyen signed last fall, that capped U.S. tariffs on EU exports at 15 percent. [...] But the president's social media post could signal a coming breach. "The United States of America is not a 'PIGGYBANK' for Europe, nor will we allow it to be!" Trump wrote.


    Read more of this story at Slashdot.


www.theregister.com - Articles




















































Linux.com




  • From DHCP to SZTP – The Trust Revolution
    By Juha Holkkola, FusionLayer Group The Dawn of Effortless Connectivity In the transformative years of the late 1990s, a quiet revolution took place, fundamentally altering how we connect to networks. The introduction of DHCP answered a crucial question, Where are you on the network?!, by automating IP address assignment. This innovation eradicated the manual configuration [0]

    The post From DHCP to SZTP – The Trust Revolution appeared first on Linux.com.








Phoronix


  • User Frustrations Over The "Tragic State of FreeBSD Audio/Sound" Support
    Besides the FreeBSD graphics and WiFi drivers lagging behind Linux and other operating systems, the FreeBSD audio driver support and handling of audio streams with FreeBSD on the desktop can be problematic depending upon the hardware/system. One of the most active mailing list threads this week in the FreeBSD camp was over the "tragic state" of FreeBSD audio/sound support...



  • Realtek RTL8723B/RTL8723BS Trying To Be Tacked On To The RTW88 Linux Driver
    Since 2017 in Linux 4.12 has been the Realtek rtl8723bs WiFi driver where it was introduced into the staging area and remains there nearly a decade later. The rtl8723bs driver for this Realtek 802.11n WiFi SDIO driver has seen a lot of code cleaning over the years and all these years later still is needing lots of code clean-ups from unnecessary code abstractions to dealing with malicious WiFi APs for what Greg Kroah-Hartman has called a "beast of a driver". The latest twist is there now being patches for adding Realtek RTL8723BS and RTL8723B onto the existing RTW88 driver...




  • Fedora Working To Establish Conflict of Interest Policy
    Posted this week is a draft copy of the Fedora Conflict of Interest policy being worked on for dealing with identifying, disclosing, and managing any actual, actual, or perceived conflicts of interest within the Fedora Project...




  • KDE Plasma 6.8 Introducing New kscreenctl Tool
    KDE developers have been working on kscreenctl as a utility replacement to kscreen-doctor. Plasma and related code has also seen a number of bug/crash fixes coming about this week too...





  • Qualcomm QCE Driver On The Chopping Block With ~48x Slower Than Armv8 Crypto Extensions
    A few days back I wrote about upstream Linux kernel developers marking the Qualcomm crypto accelerator driver as "broken" and "harmful" due to its slow performance, history of bugs, and other limitations. Now this Qualcomm Crypto Engine "QCE" driver might be removed outright from the Linux kernel source tree after discovering it's even worse than anticipated...



  • Ubuntu Linux Looking To Get Rid Of /etc/debian_version Historical Artifact
    Ubuntu Linux has shipped /etc/debian_version that is carried over from upstream Debian and in turn just indicating the Debian Sid development version from which the packages are arrived. Besides it being inaccurate, /etc/os-release has been the long preferred standard for reading the OS release information. Thus finally Ubuntu developers are looking at dropping the /etc/debian_version file...


  • Fedora 45 Looks To Begin Phasing Out In-Kernel Crypto Userspace API
    Going along with the upstream Linux 7.2 kernel deprecation of AF_ALG and Linux 7.3 to further restrict this interface for letting user-space programs interact directly with the Linux kernel crypto API, Fedora 45 is looking to follow and help support this transition...


  • AMD Advancing AI 2026: Open, Open-Source & More Open-Source
    At this week's AMD Advancing AI 2026 event, "AI" was mentioned thousands of times in talks and in demos. As expected. Beyond that, the other term likely most heard during the event was "open"... Not particularly new for AMD with their long history of open-source efforts but I'd wager at this year's AMD Advancing AI 2026 event they were more acutely bringing up open-source, open ecosystems, and open standards. Certainly seemed like an uptick in "open" mentions and a ramp that's been building each year at the AMD events...


  • Snapdragon X Elite Laptop Experience Still Lackluster On Ubuntu 26.04 LTS
    At the end of last year when checking out the latest Linux experience on the Snapdragon X Elite it was a disappointing affair. The performance had regressed and overall a more headache-inducing experience than just running a modern AMD Ryzen AI or Intel Core Ultra laptop on Linux. Given the recent release of Ubuntu 26.04 LTS, I9ve been re-testing the Acer Swift 14 AI laptop with Snapdragon X Elite SoC to see how its performing under Linux now and against the AMD/Intel competition. Unfortunately, it9s regressed even further than the last round of testing.




  • AMD EPYC 9006 Venice Announced & Looks Poised To Be A Grand Slam
    While AMD EPYC 9005 "Turin" launched just under two years ago, it has aged remarkably well. It is one of the few CPU generations in my past 22 years of Linux hardware reviews/benchmarking that has still captivated me two years on in finding still typically industry-leading performance across varying workloads, exceptional reliability, and all around a very robust platform. Today though at AMD Advancing AI 2026, Lisa Su formally announced EPYC 9006 "Venice" for taking their server offerings to the next level in the agentic AI era.







  • dav1d 1.5.4 Brings AV1 Decoding To OS/2
    While the VideoLAN developers are busy these days working on dav2d for AV2 video decoding, they haven't let up work on dav1d and recently released dav1d 1.5.4 for continuing to enhance this leading open-source, CPU-based AV1 decoder...





  • AMD EPYC Turin With PCIe 5.0 Storage Shows Off Nice Gains On Linux 7.2
    Earlier this week was an exciting look at Intel Xe3 graphics performance gains on Linux 7.2 with Intel Core Ultra Series 3 "Panther Lake" hardware. On the other side of the table, with AMD hardware on this forthcoming kernel an area to be excited about are some I/O improvements at least for 5th Gen EPYC with speedy PCIe Gen5 NVMe SSD storage.



Engadget"Engadget - Technology News & Expert Reviews"





















OSnews

  • The Hurd gets 9pfs, OpenNTPD, dynamic /dev/ entries, and more
    The hottest and most promising operating system kernel in development, the GNU Hurd, has published another summary of its most recent quarter of development. Hurd has experimental support for 9pfs now, a work-inprogress port of OpenNTPD, the NTP daemon from OpenBSD, a port of Neovim, and a few more ports here and there. Diving deeper into the actual kernel itself, theres a major improvement to how the Hurd handles entries in /dev/: Mikhail Karpov added some checks for mmap in several places. He also worked on adding storeio to the bootstrap chain. This is actually quite interesting. Currently the Hurd sets device entries in /dev/ statically. For example, I am writing this qoth on a Hurd machine that is using two /dev/ entries for my filesystem: /dev/wd0s1 for swap and /dev/wd0s5 for my root filesystem. However, /dev/wd0s1 through /dev/wd0s16 exist on my computer! Once Mikhails project is done, then the Hurd will dynamically populate SATA devices at boot time! No more need for static translators! ↫ The Hurds quartely report The dhcpcd port we talked about earlier this year keeps improving too, which is quite important for future IPv6 support. Of course, theres way more to dive into, and reading about a bunch of people developing their own thing without any regard for or interest in the mainstream always feels a little bit like a cold glass of tonic  the best soft drink  in the depths of hell. Keep at it.


  • Google Play Services drops support for Android 6.0
    Given that Android phones have been around for nearly two decades now, there comes a time when Google has to end support for one of its older software versions. For a couple of years now, Google Play services has been supported on devices running Android 6.0 Marshmallow or newer. That has changed over the past few weeks, with Google deciding to retire this software version after a nearly 11-year run. ↫ Chethan Rao at Android Authority At some point, an operating system version needs to be left behind  and I dont think its entirely unreasonable to no longer support Google Play Services on an operating system version thats 11 years old. However, this is Android were talking about, and devices running Android 6.0 were probably sold much more recently than 11 years ago, when the operating system version was new. Hell, I wouldnt be surprised if devices running Android 6.0 are still being sold today. I doubt this is something that will affect many people who read OSNews, but theres bound to be edge cases  Android 6.0 devices silently doing their job that are now just a little less useful. Im thinking of really cheap tablets that can still play video just fine, retro gaming handhelds that dont magically lose the ability to emulate SNES games, that sort of stuff. The numbers will be small, but if you happen to be among them, this can be a really annoying deprecation.


  • FreeBSD ports frozen after someone commits the entire 150MB Linux Copilot binary
    A rather unusual announcement was made late last night: the FreeBSD project has frozen their ports repository. For more than 48 hours now, no changes have been accepted or made to the tree, and heres why. A 150MB binary file was recently committed to the ports tree and, as a result, core@ made the decision to implement a temporary freeze of the ports tree in order to implement some clean up efforts. The commit in question severed our ports tree mirroring to github.com due to their filesize hard limit of 100MB, and introduced a blob of questionable licensing into the repository history. ↫ Kyle Evans in freebsd-announce While FreeBSDs ports tree is not hosted by GitHub  its merely mirrored there  the FreeBSD team believes the community values the GitHub mirror too much, and as such, steps had to be taken to fix this. Ports has not been compromised and users systems do not appear to be at risk in any way due to this occurrence, which is good news. Curiously, the official announcement makes no mention of which 150MB file, exactly, was committed to ports, but it didnt take for people long to pinpoint the offending commit (screenshot). It turns out someone committed the entire github-copilot-cli Linux binary to ports, as part of the github-copilot-cli port. This FreeBSD port is effectively a way to easily install and run this tool on FreeBSD using Linuxulator, FreeBSDs Linux compatibility layer that allows you to run unmodified Linux binaries on FreeBSD. Its important to note this FreeBSD port is not actually a port of the Linux version of github-copilot-cli to FreeBSD; the FreeBSD port! merely acts as a setup script to run the unmodified Linux binary using Linuxulator. Its not a real! port because the tool isnt open source and its license doesnt allow for modifications. Thats why the announcement specifically mentions questionable licensing!  github-copilot-cli is licensed under some custom license specifically made for this tool, and is not open source. Anyway, for whatever reason, the maintainer of this FreeBSD port accidentally made a commit that added the actual, full 150MB Linux binary to FreeBSD ports. Im assuming that under normal circumstances, building and installing the github-copilot-cli FreeBSD port would merely download the binary off GitHub and set Linuxulator up so that it could run it. Mistakes happen, and since theres clearly nothing malicious going on, theres not much to worry about. In fact, this may lead to new checks and balances to prevent this from happening in the future, which would be good news. The FreeBSD team is working on rolling back, fixing the issue, and investigating how this could have happened. Ports is still frozen at the time of writing, but Im sure well have a more detailed account soon.


  • Amiga 1000: ten years ahead of its time
    We all know the original Amiga was far ahead of its time, and the Amiga really doesnt need more retrospectives and glazing. However, that doesnt mean we dont want more Amiga retrospectives and glazing. I’m not sure I even saw an Amiga in person until 1987, but I knew just from reading about it that I wanted one. I wasn’t able to make it happen until 1991, so I was pretty late to the game. But even in 1991, an Amiga felt like living in the future. I could load several programs and switch between them effortlessly, with the only limit being the amount of memory I had. I could connect to a BBS with a terminal program, start a download, then switch it to the background, fire up a word processor, and do my homework while the download was happening. In some cases, I could even fire up a game and play a game while a download happened in the background. I could download stuff while I played Civilization, which was pretty great. ↫ David L. Farquhar Its 2026, I have an incredibly powerful Linux gaming computer, but since I grew up on DOS and Windows, to this day, I still feel the need the close every other application before launching a game. I dont need to  modern operating systems handle such things just fine, mostly  but its so ingrained in me its hard to drop this habit. I wonder if people who grew up with more capable computers than whatever DOS nonsense I grew up with are less inclined to do things like this? Or did memory constraints act as an equaliser? Anyway, the linked article doesnt mention it, but the Amiga is still, somehow, going relatively strong for a platform thats supposed to be dead. Modern(-ish) hardware is getting a bit harder to come by, but AmigaOS 4 and especially MorphOS are still actively being developed, and even running them in virtual machines on x86 has become about as easy as it could be.


  • Rewriting the Futhark type checker
    This post is about the evolution of Futhark’s type checker, motivated by a large refactoring I am about to merge. It is probably mostly of interest to other language designers, and contains some lessons I wish I had known when we first got started  although I am not particularly well-read in the type checking literature, so it’s possible all of this is old hat. ↫ The Futhark Programming Language blog Thats a clear introduction  you know what to expect.


  • COSMIC DE’s first seven months
    Honestly, it feels like only yesterday that System76, Linux OEM and the company behind pop!_OS, announced it was going to develop its own desktop environment, COSMIC. Were about seven months into the more general availability of COSMIC, and the company has put up a nice overview of the various improvements that have already made their way into the code since then. Of course, theres a ton of visual improvements have been made to COSMIC, as well as a slew of new features: improved search, a brand new system monitor, drag and drop for tabs throughout COSMIC, and much more. COSMICs file manager and terminal have also seen a lot of work, with a ton of new small features and additions to bring them up to par with what people expect form a modern file manager and terminal emulator. Theres a ton more listed in the article, so it serves as a nice while you were away! if youve not been following development.


  • Codebergs programmer user base overwhelmingly votes to ban slopcoded projects from its platform
    What happens when programmers get to vote on a complete ban on slopcoded software on their code platform? Members of Codeberg were asked to vote on a proposal to completely ban slopcoded projects from Codeberg, and in what should not be a surprising outcome to anyone not overcome with AI! hysteria, the vast majority voted in favour of the complete ban: over 70% of Codeberg members voted to ban slopcoded projects entirely (358 in favour, 144 against, 14 abstentions). Of course, this is not a surprising outcome. Stripped down, programming is a form of artistic expression, and programming is no different than writing, painting, composing, or any other artistic endeavour. I think its safe to say writers, painters, composers, and similar creatives are against AI!, so its only natural programmers feel the same; poll after poll shows the overwhelming majority of respondents  usually well over 70-80%  are against AI!. The pro- AI! accounts on OSNews often try to paint my anti- AI! position as extremist, but in reality, Im just voicing how 70-80% of people clearly state they feel. I have zero skin in this game, zero outside pressure to please any bosses to get that promotion, zero pressure to conform to avoid getting laid off, zero pressure to not contradict upper-management. I can speak freely, openly, and without fear of retaliation. And as Nikhil Suresh explains in his harrowing from-the-trenches article AI Mania Is Eviscerating Global Decision-Making, thats a massive asset. The vast majority of people  including your friends, family, and co-workers  really hate AI!. You can either accept this, or be left behind.


  • Building an AmigaOS Development Environment in 2026
    If you want to develop an application for AmigaOS 3.x but dont want to deal with real hardware, virtualisation and emulation are your friends. Apropos of nothing, I decided to set up an Amiga development environment. Since figuring things out wasnt straightforward, I wrote down instructions for Linux about how to compile the first program and run it in an emulator. Enjoy! ↫ Daniel Kochmański Its a great guide, easy to follow, and youll be up and running quickly. The emulator the guide uses  AmiBerry, a fork of WinUAE  contains slopcode, so you may want to consider alternatives. This doesnt change much for the guide though, as whatever tasks you need to do outside and inside AmigaOS itself remain unchanged.


  • Volkswagen blocks custom Android ROM users from VW application
    Drivers of cars from the Volkswagen Group using alternative Android versions like GrapheneOS, LineageOS, or /e/OS have been unable to use the VW app for some time. This means they can neither check their vehicles remaining range from their phone, schedule service appointments, nor control charging and air conditioning. The car manufacturer has made changes to the apps backend that only allow devices with Googles pre-installed Play Services. When asked by heise online, VW stated that affected users should not expect a timely reopening. “However, they are looking into it.” ↫ Andreas Floemer at Heise.de Clearly, this should be illegal. Then again, that has never stopped Volkswagen before.


  • Happy companies are all alike; every unhappy company is unhappy in its own way
    Sam Altman seems to be making OpenAI way more non-profit than before: Even as the AI bubble becomes a mainstream talking point on Wall Street, tech companies continue to peddle the fantasy that AI is poised to become an almost magical money-maker. Case in point, OpenAI wants you to believe that by 2030, it’ll be raking in $100 billion a year just from ads alone — even though it’s currently struggling to reach just $1 billion. ↫ Joe Wilkins at Futurism The US tech giants fueling this AI! bubble are trying to hide the true extent of their debt: Hidden debt at U.S. tech giants swelled eightfold in four years to an estimated $1.65 trillion as artificial intelligence investments ballooned, a Nikkei study shows, exceeding actual debt and making it tougher for investors to assess risk. The five companies hidden debt, which does not appear on balance sheets, totaled $1.65 trillion in the most recent quarter, exceeding the roughly $1.35 trillion in debt reflected on their balance sheets. The data includes some estimates. ↫ Kohei Yamada at Nikkei Asia The bubble is expanding to comical proportions: The American stock market is booming, thanks to artificial intelligence. Tech giants are borrowing billions to acquire AI talent, purchase chips and hardware, and construct data centers. And market watchers are starting to get worried. They see financiers bulldozing giant piles of money to private AI start-ups with no realistic path to profitability, tech companies reliant on other tech companies for revenue growth, and non-tech businesses without a lot to show for their AI investments. The value of AI-linked firms has climbed $27 trillion in the past three years—an astonishing amount, equivalent to 36 percent of the value of the entire U.S. stock market today. Although future earnings could justify those valuations, as Dominic Wilson and Vickie Chang of Goldman Sachs argued in a note to clients, the profit expectations require Panglossian optimism. No less an authority than Sam Altman is arguing that we are in an AI bubble. The International Monetary Fund is citing it as a significant risk to financial stability and warning about what might happen when it bursts: diminished investment, tighter credit, reduced consumption, disrupted trade flows. ↫ Annie Lowrey at The Atlantic Im not worried, though. I have it on good authority that AI! increases productivity by 10x, so surely, none of the above is a problem. Any day now, we will be inundated with waves of brand new, high-quality, valuable software. Any day now, existing software will increase in quality by 10x, leading to a huge surge in software sales. Any day now, productivity in factories will increase rapidly thanks to AI! freeing up workers time, driving prices down 10x, leaving consumers with 10x more money to spend. Any day now, everyone will be able to produce the next Citizen Kane or write the next Anna Karenina, causing an explosion in magnificent, timeless art that will have historians of the future marvel at our civilisations ingenuity and artistry. In the meantime, these companies can just ask their AI! how to become profitable. Should be table-stakes for a 10x force multiplier. Im not worried.


  • Regressive JPEGs
    One of the cool features of JPEG files is that theres the option to save low frequency components first. This means that a partially downloaded image will be displayed at low resolution instead of being cut off. ↫ maurycyz.com Oh I know where this is going0 Doing this, I can get Chrome to render around 90 frames before giving up. Other browsers like Firefox have more patience, but a 90 scan image seems to work almost everywhere. ↫ maurycyz.com Yes, you can abuse the mentioned feature to create a really odd type of video. Or animation? Well, it allows you to create something resembling a really low-resolution GIF. Useless, yes, but very novel.


  • Even Microsoft couldn’t make Windows 11 work well on 8GB of RAM!
    The Verge reviewed the latest Surface Laptop, which only comes with 8GB of RAM at a higher price than the previous 16GB model, and they conclude that Windows isnt really usable on 8GB of RAM. Whether thats true or not I do not know  I would assume it depends a lot on your usage  but this quote from the review I found quite peculiar: I was on a Microsoft Teams call (using the app, not a browser) when the host streamed a brief video, which made the whole laptop hang for several seconds. At the time, I had about 10 Chrome tabs open across two desktops, alongside Slack and Signal — not an obscene level of multitasking. ↫ Antonio G. Di Benedetto at The Verge Excuse me, but that is actually an obscene level of multitasking because every single one of those applications! is a complete Chrome browser. Just in the paragraph above, theres four individual complete Chrome browsers running, with little to no optimisation. Why would anyone be surprised this scenario strains a mere 8GB of RAM? This isnt merely a Windows problem; this is a programmers choosing suboptimal tooling × managers have no idea what theyre doing problem. If Teams, Slack, and Signal had been proper, native applications instead of websites running in terrible frameworks, Windows 11 would have handled this scenario just fine.


  • OpenBSD tests WPA3 support
    The NLnet Foundations NGI0 Commons Fund supported an effort to add WPA3 support to OpenBSD, and the works payed off. All drivers which support PMF can use WPA3, which are: iwm, iwx, and qwx. So far, I have tested this patch on iwx AX200 only. I will roll out this patch to more of my devices now. Help with testing is welcome. There are both userland and kernel changes involved. ↫ Stefan Sperling Only the second implementation of WPA3 will be supported, which requires some explanation: WPA3 has a complicated history. There are two versions of WPA3. The initially standardized version suffered from side-channel leaks found by Mathy Vanhoef and dubbed Dragonblood . A revised and fixed version has been standardized and is mandatory in the 6 GHz band as of Wifi 6e (11ax) and mandatory on all bands as of Wifi 7 (11be). ↫ Stefan Sperling Obviously, WPA3 is a very welcome addition to OpenBSD.


  • DOSBox ported to OpenVMS for Alpha
    Speaking of OpenVMS and Alpha  and we like speaking about OpenVMS and Alpha, dont we?  theres now a port of DOSBox that runs on the Alpha version venerable operating system. Astr0baby has published both binaries and source code for the port, as well as a lovely set of screenshots to show it off working.


  • LG monitors silently install software through Windows Update without user consent
    Well, this is new  but not at all unexpected considering the state of Windows and the wider technology industry. When you connect certain LG monitors to a Windows machine, Windows Update will pull in a bunch of adware promoting antivirus trash. Of course, all done without any consent, because Silicon Valley inherently does not understand nor respect consent. Windows Update first installed LG extension and software component packages. Windows Reliability Monitor showed that LG Monitor App Installer appeared one minute later. The installation did not display a consent prompt or require the user to approve the download. Gamers Nexus tested the application across 32 consecutive system boots. It displayed a McAfee promotion during 31 of them. On the remaining boot, it promoted one of LG’s own monitor utilities. The McAfee popup offered a 30-day trial that would convert into a paid subscription. ↫ WhyCry at VideoCardz Dont use Windows.


  • New Intel Itanium emulator boots Itanium version of Windows XP and 2003
    It was only a few weeks ago that we got a massively improved Alpha emulator, capable of running VMS, Windows 2000, and Tru64, including X11 support and a variety of other exciting features. Today, weve got another major emulation milestone (update: sadly, with AI! support, so odds are this will fizzle out. Bummer!). The emulation space is going crazy, after my previous post on Windows booting on DEC Alpha es40 emulator, there is now another huge breakthrough in the emulation of other non-x86 CPU emulation. Yufeng Gao with help from gdwnldsKSC (the man behind the updated es40-fork) has released version 0.1 of his Intel Itanium (IA-64) emulator that boots the Itanium version of Windows Server 2003 and Windows XP 64-bit. No OpenVMS or HP-UX yet and Linux/BSD also dont boot. But Windows is amazing already. ↫ Remy van Elst Much like Alpha hardware, Itanium hardware is quite hard to come by  especially Itanium workstations are a nightmare to find; I think Ive only ever seen one or two Itanium workstation come up for sale on eBay in recent years, and their rarity obviously commanded hefty prices. The sooner we are able to run Itanium version of operating systems comfortably in a virtualised environment the better. As long-time OSNews readers know, my heart beats for HP-UX, but the Itanium versions of Windows and VMS would be of more interest to most people, Im sure. Excellent news.



Linux Journal News

  • EU OS: A Bold Step Toward Digital Sovereignty for Europe
    Image
    A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem.
    What Is EU OS?
    EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.

    Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments.
    The Vision Behind EU OS
    The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.

    Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.

    However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty.
    Conclusion
    EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.

    Source: It's FOSS
    European Union


  • Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.

    In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.

    On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.

    Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.

    The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.

    Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.

    You can download the latest kernel here.
    Linus Torvalds kernel


  • AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
    Image
    AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.

    This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.

    Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.

    Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.

    Source: 9to5Linux
    AerynOS


  • Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
    Image
    Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.

    Here’s a quick overview of what’s new in Xojo 2025r1:
    1. Linux ARM IDE Support
    Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started.
    2. Web Drag and Drop
    One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required!
    3. Direct App Store Publishing
    Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process.
    4. New Desktop and Mobile Features
    This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection.
    5. Performance and IDE Enhancements
    Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced.
    What Does This Mean for Developers?
    Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution.
    How to Get Started
    Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.

    Download Xojo 2025r1 today at xojo.com.
    Final Thoughts
    With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you.
    Xojo ARM


  • New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux

    Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.

    Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.

    Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest. 

    Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.

    Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.

    Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.

    By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem.
    Windows


  • Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities

    The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally. 

    As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.

    In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions. 

    After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.

    The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.

    At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.

    The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca.
    Security


  • Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges

    The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.

    A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.

    This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem. 

    The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.

    On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.

    In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers.
    kernel


  • Linux Celebrates 32 Years with the Release of 6.6-rc2 Version

    Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.

    The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.

    Here is what Linus Torvalds had to say in today's announcement:
    Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds


  • Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction

    Want to interact with ChatGPT from your Linux desktop without using a web browser?

    Bavarder, a new app, allows you to do just that.

    Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.

    With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.

    During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.

    At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.

    As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!

    Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring.
    ChatGPT AI


  • LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite

    Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.

    Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.

    LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.

    You can download LibreOffice 7.5.3 directly from the LibreOffice websiteor from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.

    All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.

    In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.

    Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.

    The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners.
    LibreOffice


Linux Magazine News (path: lmi_news)





  • Hannah Montana Linux Is Back!
    Developer Noah Cagle decided the world needed the once obscure but beloved Linux distribution and gave it a decidedly pink refresh.




  • Kubuntu Focus Goes Ultra
    The Kubuntu Focus team has upped the performance ante of its M2 and Zr laptops with the latest, greatest CPUs from Intel.









  • KDE Linux Drops AUR
    KDE Linux developers have dropped the Arch User Repository from the build pipeline due to security concerns; other distributions should consider doing the same.






Page last modified on November 17, 2022, at 06:39 PM