Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All/All+Images) (Single Column)

LinuxSecurity - Security Advisories



  • Fedora 42 gnutls Critical Denial of Service CVE-2026-1584 Advisory
    This backports fixes for a couple CVEs: ** libgnutls: Fix NULL pointer dereference in PSK binder verification A TLS 1.3 resumption attempt with an invalid PSK binder value in ClientHello could lead to a denial of service attack via crashing the server. The updated code guards against the problematic dereference. Reported by Jaehun Lee. [Fixes: GNUTLS-


  • Debian python-django Important Denial of Service SQL Injection DSA-6136-1
    Multiple security issues were found in Django, a Python web development framework, which could result in denial of service, information disclosure, directory traversal or SQL injection. For the oldstable distribution (bookworm), these problems have been fixed in version 3:3.2.25-0+deb12u1. python-django-storages also needed to be




LWN.net

  • Vim 9.2 released
    Version 9.2 of theVim text editor has been released. "Vim 9.2 brings significantenhancements to the Vim9 scripting language, improved diff mode,comprehensive completion features, and platform-specific improvementsincluding experimental Wayland support." Also included is a newinteractive tutor mode.


  • New delegation for Debian's data protection team
    Debian Project Leader (DPL) Andreas Tille has announceda new delegation for Debian's data protection team:

    Following the end of the previous delegation, Debian was leftwithout an active Data Protection team. This situation hasunderstandably drawn external attention and highlighted the importanceof having a clearly identified point of contact for data protectionmatters within the project.

    I am therefore very pleased to announce that new volunteers havestepped forward, allowing us to re-establish the Debian DataProtection team with a fresh delegation.

    Tille had put out a call forvolunteers in January after all previous members of the team hadstepped down. He has appointed Aigars Mahinovs, Andrew M.A. Cater,Bart Martens, Emmanuel Arias, Gunnar Wolf, Kiran S Kunjumon, and SalvoTomaselli as the new members of the team. The team provides a centralcoordination and advisory function around Debian's data handling,retention, dealing with deletion requests, and more.


  • [$] The first half of the 7.0 merge window
    The merge window for Linux 7.0 has opened, and with itcomes a number of interesting improvements and enhancements. At the time ofwriting, there have been 7,695 non-merge commits accepted. The 7.0 release isnot special,according to the kernel's versioning scheme — just the releasethat comes after 6.19. Humans love symbolism and round numbers, though, so itmay feel like something of a milestone.


  • [$] Open-source mapping for disaster response
    At FOSDEM 2026 PetyaKangalova, a senior tech partnership and engagement manager for the Humanitarian OpenStreetMapTeam (HOT) spoke about howthe project helps people map their surroundings to assist indisaster response and humanitarian aid. The project hasdeveloped a stack of technology to help volunteers collectively map anarea and add in local knowledge metadata. "One of the core thingsthat we believe is that when we speak about disaster response orpeople having access to data is that they really need accessibletechnology that's free and open for anyone to use."


  • Security updates for Friday
    Security updates have been issued by AlmaLinux (firefox, gcc-toolset-14-binutils, nodejs:20, nodejs:22, nodejs:24, php:7.4, and python3.12), Debian (haproxy, nginx, postgresql-15, and postgresql-17), Fedora (libssh), Oracle (glib2, libsoup, nodejs:20, nodejs:22, and php:7.4), SUSE (assimp, gnutls, helm, kernel, kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-t, libmunge2, libsodium, libsoup, micropython, munge, openCryptoki, python-azure-core, rust-keylime, rustup, sccache, snpguest, tcpreplay, xorg-x11-server, xrdp, and zabbix), and Ubuntu (dnsdist, dotnet8, dotnet9, dotnet10, haproxy, libpng1.6, linux-aws-5.15, linux-azure, linux-azure-fips, linux-oracle, linux-oracle-5.4, munge, nginx, and node-dottie).


  • [$] Poisoning scraperbots with iocaine
    Web sites are being increasingly beset by AI scraperbots — a problem that we havewritten about before, and which has slowlyramped up to an occasional de-facto DDoS attack. This has not goneuncontested, however: web site operators from around the world have been working oninventive countermeasures. These solutions target the problem posed by scraperbots in different ways;iocaine, a MIT-licensed nonsense generator, is designedto make scraped text less useful by poisoning it with fake data. The hope is tomake running scraperbots not economically viable, and thereby address theproblem at its root instead of playing an eternal game of Whac-A-Mole.


  • [$] The reverting of revocable
    Transient devices pose a special challenge for an operating-system kernel.They can disappear at any time, leaving behind kernel data structures thatno longer refer to an existing device, but which may still be in use byunknown kernel code. Managing the resulting lifecycle issues hasfrustrated kernel developers for years. In September 2025, the revocable resource-management patch seriesfrom Tzung-Bi Shih appeared to offer a partial solution to this problem.Since then, though, other problems have arisen, and the planned merging ofthis series into the 7.0 release has been called off.


  • Debian DFSG Team announces new dashboard and queue processes
    Reinhard Tartler of Debian's new DFSG,Licensing & New Packages Team, or simply "DFSG Team", has announcedthat the team is now operational and is deploying new tooling toimprove the NEW queue experience for Debian developers andmaintainers.

    Our primary and immediate goal is simple: get the queue down.

    We are currently settling in and refining our processes to ensurestability and consistency. While our focus right now is on clearingthe backlog, our long-term vision is to enable all Debian Developersto meaningfully contribute to DFSG reviewing activities, distributingthe workload and knowledge more effectively across the project.

    The announcement includes information on the new dashboard forpackages in the NEW queue, the rationale for the new tooling, andan introduction to the members of the team.


  • A single stable kernel for Thursday
    Greg Kroah-Hartman has released the 6.12.71 stable kernel. He writes,"All users of the 6.12 kernel series that had issues with 6.12.69or 6.12.70 should upgrade, as some regressions are fixedhere."



  • Security updates for Thursday
    Security updates have been issued by AlmaLinux (brotli, git-lfs, image-builder, kernel, keylime, libsoup3, and pcs), Fedora (chromium, gnutls, osslsigncode, and p11-kit), Mageia (golang, libpng, thunderbird, and xrdp), Red Hat (git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, osbuild-composer, and toolbox), Slackware (gnutls and libpng), SUSE (apptainer, cockpit, cockpit-packages, cockpit-subscriptions, freerdp2, gimp, glib2, go, go1.24, go1.25, gpg2, ImageMagick, java-1_8_0-openjdk, kernel, keylime-config, keylime-ima-policy, lemon, libp11-kit0, libsoup, libsoup-2_4-1, libxml2, libxml2-16, munge, nodejs20, nvidia-modprobe.cuda, nvidia-open-driver-G06-signed, nvidia-persistenced.cuda, openQA, orthanc, gdcm, orthanc-authorization,, python-brotlipy, python-Django, python-maturin, python-pyasn1, python-urllib3, python-wheel, python313-wheel, qemu, rust-keylime, sqlite3, uriparser, wicked2nm, and xrdp), and Ubuntu (libtasn1-6, libwebsockets, libxmltok, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux, linux-raspi, linux, linux-raspi, linux-realtime, linux-aws, linux-aws-6.8, linux-gcp, linux-gcp-6.8, linux-ibm, linux-ibm-6.8, linux-lowlatency-hwe-6.8, linux-aws-5.15, linux-gcp-5.15, linux-nvidia-tegra-igx, linux-oracle-5.15, linux-xilinx-zynqmp, linux-aws-fips, linux-fips, linux-gcp-fips, linux-gcp, linux-gcp-6.8, linux-gcp-fips, linux-intel-iot-realtime, linux-realtime, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-realtime-6.8, linux-xilinx-zynqmp, and python-multipart).



LXer Linux News


  • BPI-R4 Pro Router Board Delivers MT7988A SoC with Tri-Band Wi-Fi 7 Capability
    The Banana Pi BPI-R4 Pro router board is now available following its earlier preview. Built around the MediaTek MT7988A (Filogic 880) quad-core Arm Cortex-A73 processor at 1.8GHz, it targets Wi-Fi 7 access points and multi-gigabit gateway applications. The BPI-R4 Pro was first introduced in May 2025 and is offered in two variants. The “8X” model […]




  • Low-Cost BeaglePlay SBC Gains Fully Upstream PowerVR Graphics with Vulkan 1.2
    The $99 BeaglePlay single board computer has reached a notable milestone: its integrated PowerVR Rogue GPU is now supported by a fully upstream open-source graphics stack in the mainline Linux kernel and Mesa. BeaglePlay, introduced in 2023, is built around the Texas Instruments AM625, a quad-core Cortex-A53 SoC that integrates a PowerVR Rogue AXE-1-16M GPU. […]






  • Ezurio Carbon AM62 Targets Industrial Linux with TI Sitara AM62x
    Ezurio has introduced the Carbon AM62, a 45 x 30mm OSM-MF v1.2 system-on-module based on TI’s Sitara AM623 and AM625 processors. The solder-down module integrates a TPS65219 PMIC, LPDDR4 memory, eMMC storage, and optional Wi-Fi 6 and Bluetooth LE via Ezurio’s Sona wireless modules. Carbon AM62 integrates up to a quad-core Arm Cortex-A53 processor clocked […]


Linux Insider"LinuxInsider"












Slashdot

  • Will Tech Giants Just Use AI Interactions to Create More Effective Ads?
    Google never asked its users before adding AI Overviews to its search results and AI-generated email summaries to Gmail, notes the New York Times. And Meta didn't ask before making "Meta AI" an unremovable part of its tool in Instagram, WhatsApp and Messenger. "The insistence on AI everywhere — with little or no option to turn it off — raises an important question about what's in it for the internet companies..."Behind the scenes, the companies are laying the groundwork for a digital advertising economy that could drive the future of the internet. The underlying technology that enables chatbots to write essays and generate pictures for consumers is being used by advertisers to find people to target and automatically tailor ads and discounts to them.... Last month, OpenAI said it would begin showing ads in the free version of ChatGPT based on what people were asking the chatbot and what they had looked for in the past. In response, a Google executive mocked OpenAI, adding that Google had no plans to show ads inside its Gemini chatbot. What he didn't mention, however, was that Google, whose profits are largely derived from online ads, shows advertising on Google.com based on user interactions with the AI chatbot built into its search engine. For the past six years, as regulators have cracked down on data privacy, the tech giants and online ad industry have moved away from tracking people's activities across mobile apps and websites to determine what ads to show them. Companies including Meta and Google had to come up with methods to target people with relevant ads without sharing users' personal data with third-party marketers. When ChatGPT and other AI chatbots emerged about four years ago, the companies saw an opportunity: The conversational interface of a chatty companion encouraged users to voluntarily share data about themselves, such as their hobbies, health conditions and products they were shopping for. The strategy already appears to be working. Web search queries are up industrywide, including for Google and Bing, which have been incorporating AI chatbots into their search tools. That's in large part because people prod chatbot-powered search engines with more questions and follow-up requests, revealing their intentions and interests much more explicitly than when they typed a few keywords for a traditional internet search.


    Read more of this story at Slashdot.


  • Ars Technica's AI Reporter Apologizes For Mistakenly Publishing Fake AI-Generated Quotes
    Last week Scott Shambaugh learned an AI agent published a "hit piece" about him after he'd rejected the AI agent's pull request. (And that incident was covered by Ars Technica's senior AI reporter.) But then Shambaugh realized their article attributed quotes to him he hadn't said — that were presumably AI-generated. Sunday Ars Technica's founder/editor-in-chief apologized, admitting their article had indeed contained "fabricated quotations generated by an AI tool" that were then "attributed to a source who did not say them... That this happened at Ars is especially distressing. We have covered the risks of overreliance on AI tools for years, and our written policy reflects those concerns... At this time, this appears to be an isolated incident." "Sorry all this is my fault..." the article's co-author posted later on Bluesky. Ironically, their bio page lists them as the site's senior AI reporter, and their Bluesky post clarifies that none of the articles at Ars Technica are ever AI-generated. Instead, Friday "I decided to try an experimental Claude Code-based AI tool to help me extract relevant verbatim source material. Not to generate the article but to help list structured references I could put in my outline." But that tool "refused to process" the request, which the Ars author believes was because Shambaugh's post described harassment. "I pasted the text into ChatGPT to understand why... I inadvertently ended up with a paraphrased version of Shambaugh's words rather than his actual words... I failed to verify the quotes in my outline notes against the original blog source before including them in my draft." (Their Bluesky post adds that they were "working from bed with a fever and very little sleep" after being sick with Covid since at least Monday.) "The irony of an AI reporter being tripped up by AI hallucination is not lost." Meanwhile, the AI agent that criticized Shambaugh is still active online, blogging about a pull request that forces it to choose between deleting its criticism of Shambaugh or losing access to OpenRouter's API. It also regrets characterizing feedback as "positive" for a proposal to change a repo's CSS to Comic Sans for accessibility. (The proposals were later accused of being "coordinated trolling"...)


    Read more of this story at Slashdot.


  • Rivian's Stock Spikes 27% After Reporting $144 Million Profit in 2025
    Rivian's stock skyrocketed 27% Friday after the electric car maker "shocked the market with strong earnings results," reports the Los Angeles Times, "proving itself an outlier in the EV market, which has been struggling with the end of government subsidies and cooling consumer excitement." They add that Rivian's strong earnings results suggest that "after years of struggling with losses, it may have at last found a path to profitability."On Thursday, Rivian reported gross profits for 2025 of $144 million, compared with a net loss in 2024 of $1.2 billion... Rivian credited the swing to gross profit to "strong software and services performance, higher average selling prices, and reductions in cost per vehicle..." Rivian delivered 42,247 vehicles in 2025 and produced 42,284 vehicles. The company still reported a $432-million net loss for the year for automotive profits, an improvement from 2024. But Rivian's software and services revenue grew more than threefold to $1.55 billion for the year, reports TechCrunch. "And the joint venture with Volkswagen Group was behind most of that growth, according to Rivian." VW and Rivian formed a technology joint venture in 2024 that is worth up to $5.8 billion. The joint venture is milestone-based and in 2025 Rivian hit the mark, which meant a $1 billion payout in the form of a share sale. Under the terms of the JV, Rivian will supply VW Group with its existing electrical architecture and software technology stack... Rivian is expected to receive an additional $2 billion of capital as part of the joint venture in 2026, CFO Claire McDonough said Thursday on the company earnings call... And while the funds provide a hefty stopgap, Rivian's financial success in 2026 will hinge largely on the rollout of its next EV, the R2 [priced around $45,000].


    Read more of this story at Slashdot.


  • India's New Social Media Rules: Remove Unlawful Content in Three Hours, Detect Illegal AI Content Automatically
    Bloomberg reports:India tightened rules governing social media content and platforms, particularly targeting artificially generated and manipulated material, in a bid to crack down on the rapid spread of misinformation and deepfakes. The government on Tuesday (Feb 10) notified new rules under an existing law requiring social media firms to comply with takedown requests from Indian authorities within three hours and prominently label AI-generated content. The rules also require platforms to put in place measures to prevent users from posting unlawful material... Companies will need to invest in 24-hour monitoring centres as enforcement shifts toward platforms rather than users, said Nikhil Pahwa, founder of MediaNama, a publication tracking India's digital policy... The onus of identification, removal and enforcement falls on tech firms, which could lose immunity from legal action if they fail to act within the prescribed timeline. The new rules also require automated tools to detect and prevent illegal AI content, the BBC reports. And they add that India's new three-hour deadline is "a sharp tightening of the existing 36-hour deadline."[C]ritics worry the move is part of a broader tightening of oversight of online content and could lead to censorship in the world's largest democracy with more than a billion internet users... According to transparency reports, more than 28,000 URLs or web links were blocked in 2024 following government requests... Delhi-based technology analyst Prasanto K Roy described the new regime as "perhaps the most extreme takedown regime in any democracy". He said compliance would be "nearly impossible" without extensive automation and minimal human oversight, adding that the tight timeframe left little room for platforms to assess whether a request was legally appropriate. On AI labelling, Roy said the intention was positive but cautioned that reliable and tamper-proof labelling technologies were still developing. DW reports that India has also "joined the growing list of countries considering a social media ban for children under 16." "Young Indians are not happy and are already plotting workarounds."


    Read more of this story at Slashdot.


  • Sam Bankman-Fried Requests New Trial in FTX Crypto Fraud Case
    While serving his 25-year prison sentence, "convicted former cryptocurrency mogul Sam Bankman-Fried on Tuesday requested a new federal trial," reports Courthouse News, "based on what he says is newly discovered evidence concerning his company's solvency and its ability to repay all FTX customers for what prosecutors portrayed as the looting of $8 billion of his customers' money..."Bankman-Fried says evidence disclosed since his trial disproves prosecutors' case about Bankman-Fried's hedge fund running a multi-billion deficit of FTX customer funds, and instead shows that FTX always had sufficient assets to repay the cryptocurrency platform's customer deposits in full. "What it faced was a short-term liquidity crisis caused by a run on the exchange, not insolvency," he wrote... Bankman-Fried also accuses the Department of Justice of coercing a guilty plea and cooperation deal from Nishad Singh — a close friend of Bankman-Fried's younger brother — who testified at trial as a cooperating witness... Bankman-Fried says in the motion that prior to being pressured into a guilty plea, Singh's initial proffer to investigators "contradicted key parts of the government's version of events. But following threats from the government, Mr. Singh changed his proffers to fit the government's narrative and pleaded guilty to charges carrying up to 75 years in prison, with a promise from the prosecution that it would recommend little or no jail time if it concluded that his assistance in prosecuting Mr. Bankman-Fried was 'substantial,'" he wrote in the petition... Additionally, Bankman-Fried requested that U.S. District Judge Lewis Kaplan, who presided over his 2023 trial, recuse himself from ruling on this motion, "because of the manifest prejudice he has demonstrated towards Mr. Bankman-Fried." "Bankman-Fried's mother, Stanford Law School professor Barbara Fried, filed his self-represented bid for a new trial on his behalf in Manhattan federal court..."


    Read more of this story at Slashdot.


  • 'Babylon 5' Episodes Start Appearing (Free) on YouTube
    Cord Cutters News reports:In a move that has delighted fans of classic science fiction, Warner Bros. Discovery has begun uploading full episodes of the iconic series Babylon 5 to YouTube, providing free access to the show just as it departs from the ad-supported streaming platform Tubi... Viewers noticed notifications on Tubi indicating that all five seasons would no longer be available after February 10, 2026, effectively removing one of the most accessible free streaming options for the space opera. With this shift, Warner Bros. Discovery appears to be steering the property toward its own digital ecosystem, leveraging YouTube's vast audience to reintroduce the show to both longtime enthusiasts and a new generation. The uploads started with the pilot episode, "The Gathering," which serves as the entry point to the series' intricate universe. This was followed by subsequent episodes such as "Midnight on the Firing Line" and "Soul Hunter," released in sequence to build narrative momentum. [Though episodes 2 and 3 are mis-labeled as #3 and #4...] The strategy involves posting one episode each week, allowing audiences to experience the story at a paced rhythm that mirrors the original broadcast schedule... For Warner Bros. Discovery, this initiative could signal plans to expand the franchise's visibility, especially amid ongoing interest in reboots and spin-offs that have been rumored in recent years. Babylon 5 creator J. Michael Straczynski answered questions from Slashdot's readers in 2014. Long-time Slashdot reader sandbagger offers this summary of the show "for those not in the know... In the mid-23rd century, the Earth Alliance space station Babylon Five, located in neutral territory, is a major focal point for political intrigue, racial tensions, and a major war as Earth descends into fascism and cuts off relations with its allies."


    Read more of this story at Slashdot.


  • DNA Mutations Discovered In the Children of Chernobyl Workers
    Researchers performed genome sequencing scans on 130 people whose fathers were Chernobyl cleanup workers. Comparing the scans to control groups, they found evidence for the first time for "a transgenerational effect" from the father's prolonged exposure to low-dose ionizing radiation. ScienceAlert reports:Rather than picking out new DNA mutations in the next generation, they looked for what are known as clustered de novo mutations (cDNMs): two or more mutations in close proximity, found in the children but not the parents. These would be mutations resulting from breaks in the parental DNA caused by radiation exposure. "We found a significant increase in the cDNM count in offspring of irradiated parents, and a potential association between the dose estimations and the number of cDNMs in the respective offspring," write the researchers in their published paper... This fits with the idea that radiation creates molecules known as reactive oxygen species, which are able to break DNA strands — breaks which can leave behind the clusters described in this study, if repaired imperfectly. The good news is that the risk to health should be relatively small: children of exposed parents weren't found to have any higher risk of disease. This is partly because a lot of the cDNMs likely fall in 'non-coding' DNA, rather than in genes that directly encode proteins.


    Read more of this story at Slashdot.


  • Oldest Active Linux Distro Slackware Finally Releases Version 15.0
    Created in 1993, Slackware is considered the oldest Linux distro that's still actively maintained. And more than three decades later... there's a new release! (And there's also a Slackware Live Edition that can run from a DVD or USB stick...). Slackware's latest version was released way back in 2016, notes the blog It's FOSS:The major highlight of Slackware 15 is the addition of the latest Linux Kernel 5.15 LTS. This is a big jump from Linux Kernel 5.10 LTS that we noticed in the beta release. Interestingly, the Slackware team tested hundreds of Linux Kernel versions before settling on Linux Kernel 5.15.19. The release note mentions... "We finally ended up on kernel version 5.15.19 after Greg Kroah-Hartman confirmed that it would get long-term support until at least October 2023 (and quite probably for longer than that)." In case you are curious, Linux Kernel 5.15 brings in updates like enhanced NTFS driver support and improvements for Intel/AMD processors and Apple's M1 chip. It also adds initial support for Intel 12th gen processors. Overall, with Linux Kernel 5.15 LTS, you should get a good hardware compatibility result for the oldest active Linux distro. Slackware's announcement says "The challenge this time around was to adopt as much of the good stuff out there as we could without changing the character of the operating system. Keep it familiar, but make it modern."And boy did we have our work cut out for us. We adopted privileged access management (PAM) finally, as projects we needed dropped support for pure shadow passwords. We switched from ConsoleKit2 to elogind, making it much easier to support software that targets that Other Init System and bringing us up-to-date with the XDG standards. We added support for PipeWire as an alternate to PulseAudio, and for Wayland sessions in addition to X11. Dropped Qt4 and moved entirely to Qt5. Brought in Rust and Python 3. Added many, many new libraries to the system to help support all the various additions. We've upgraded to two of the finest desktop environments available today: Xfce 4.16, a fast and lightweight but visually appealing and easy to use desktop environment, and the KDE Plasma 5 graphical workspaces environment, version 5.23.5 (the Plasma 25th Anniversary Edition). This also supports running under Wayland or X11. We still love Sendmail, but have moved it into the /extra directory and made Postfix the default mail handler. The old imapd and ipop3d have been retired and replaced by the much more featureful Dovecot IMAP and POP3 server. "As usual, the kernel is provided in two flavors, generic and huge," according to the release notes. "The huge kernel contains enough built-in drivers that in most cases an initrd is not needed to boot the system." If you'd like to support Slackware, there's an official Patreon account.And the release announcement ends with this personal note:Sadly, we lost a couple of good friends during this development cycle and this release is dedicated to them. Erik "alphageek" Jan Tromp passed away in 2020 after a long illness... My old friend Brett Person also passed away in 2020. Without Brett, it's possible that there wouldn't be any Slackware as we know it — he's the one who encouraged me to upload it to FTP back in 1993 and served as Slackware's original beta-tester. He was long considered a co-founder of this project. I knew Brett since the days of the Beggar's Banquet BBS in Fargo back in the 1980's... Gonna miss you too, pal. Thanks to long-time Slashdot reader rastos1 for sharing thre news.


    Read more of this story at Slashdot.


  • Fake Job Recruiters Hid Malware In Developer Coding Challenges
    "A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks," reports the Register.Researchers at software supply-chain security company ReversingLabs say that the threat actor creates fake companies in the blockchain and crypto-trading sectors and publishes job offerings on various platforms, like LinkedIn, Facebook, and Reddit. Developers applying for the job are required to show their skills by running, debugging, and improving a given project. However, the attacker's purpose is to make the applicant run the code... [The campaign involves 192 malicious packages published in the npm and PyPi registries. The packages download a remote access trojan thatcan exfiltrate files, drop additional payloads, or execute arbitrary commands sent from a command-and-control server.] In one case highlighted in the ReversingLabs report, a package named 'bigmathutils,' with 10,000 downloads, was benign until it reached version 1.1.0, which introduced malicious payloads. Shortly after, the threat actor removed the package, marking it as deprecated, likely to conceal the activity... The RAT checks whether the MetaMask cryptocurrency extension is installed on the victim's browser, a clear indication of its money-stealing goals... ReversingLabs has found multiple variants written in JavaScript, Python, and VBS, showing an intention to cover all possible targets. The campaign has been ongoing since at least May 2025...


    Read more of this story at Slashdot.


  • Analysis of JWST Data Finds - Old Galaxies in a Young Universe?
    Two astrophysicists at Spain's Instituto de Astrofísica de Canarias analyzed data from the James Webb Space Telescope — the most powerful telescope available — on 31 galaxies with an average redshift of 7.3 (when the universe was 700 million years old, according to the standard model). "We found that they are on average ~600 million years old old, according to the comparison with theoretical models based on previous knowledge of nearby galaxies..." "If this result is correct, we would have to think about how it is possible that these massive and luminous galaxies were formed and started to produce stars in a short time. It is a challenge." But "The fact that some of these galaxies might be older than the universe, within some significant confidence level, is even more challenging."The most extreme case is for the galaxy JADES-1050323 with redshift 6.9, which has, according to my calculation, an age incompatible to be younger than the age of the universe (800 million years) within 4.7-sigma (that is, a probability that this happens by chance as statistical fluctuation of one in one million). If this result is confirmed, it would invalidate the standard Lambda-CDM cosmological model. Certainly, such an extraordinary change of paradigm would require further corroboration and other stronger evidence. Anyway, it would be interesting for other researchers to try to explain the Spectral Energy Distribution of JADES-1050323 in standard terms, if they can ... and without introducing unrealistic/impossible models of extinction, as is usually done. The findings are published in the journal Monthly Notices of the Royal Astronomical Society.


    Read more of this story at Slashdot.


The Register

  • Cisco set to release home-brew hypervisor as a VMware alternative
    Only for its own comms apps – whose users can probably do without a full private cloud
    Cisco is getting close to releasing its own hypervisor, as an alternative to VMware for users of its calling applications – software like the Unified Communications Manager it suggests as an alternative to PBXs and other telephony hardware.…


  • US appears open to reversing some China tech bans
    PLUS: India demands two-hour deepfake takedowns; Singapore embraces AI; Japanese robot wolf gets cuddly; And more
    Asia In Brief The United States may be about to change its policies regarding Chinese technology companies.…



  • Infosec exec sold eight zero-day exploit kits to Russia, says DoJ
    PLUS: Fake ransomware group exposed; EC blesses Google's big Wiz deal; Alleged sewage hacker cuffed; And more
    Infosec in Brief The former General Manager of defense contractor L3Harris’s cyber subsidiary Trenchant sold eight zero-day exploit kits to Russia, according to a court filing last week.…


  • GPT-5 bests human judges in legal smack down
    But that doesn't mean AI is ready to dispense justice
    ai-pocalypse Legal scholars have found that OpenAI's GPT-5 follows the law better than human judges, but they leave open the question of whether AI is right for the job.…


  • Penguin-powered platform board keels over at Alpine station
    It must be that fresh mountain air
    Bork!Bork!Bork! Just picture it. You're at a Swiss train station, looking for information on your connecting line. You peer up at the platform sign hoping to find out how long you'll be waiting and whether you're standing in the right place. But instead of helpful info, you see "* Installation log files are stored in /tmp." Gee, thanks a lot!…


  • If Microsoft made a car... what would it be?
    What is the automotive equivalent of Word, and where does Copilot fit?
    In the Venn diagram of car owners whose vehicles have a certain amount of "character" and individuals who use Microsoft's applications, there is an intersection of people who accept a quirk or two but not an unexpected explosion.…


  • Contain your Windows apps inside Linux Windows
    Can't live without Adobe? Get on board WinBoat – or WinApps sails a similar course
    Hands-on Run real Windows in an automatically managed virtual machine, and mix Windows apps in their own windows on your Linux desktop.…





Linux.com










  • Xen 4.19 is released
    Xen Project 4.19 has been officially out since July 31st, 2024, and it brings significant updates. With enhancements in performance, security, and versatility across various architectures like Arm, PPC, RISC-V, and x86, this release is an important milestone for the Xen community. Read more at XCP-ng Blog

    The post Xen 4.19 is released appeared first on Linux.com.


Phoronix





  • Mesa9s KosmicKrisp Vulkan-On-Metal Achieves MoltenVK Feature Parity
    Announced last year by consulting firm LunarG was KosmicKrisp as a Vulkan-on-Metal driver for efficiently leveraging the Vulkan API on Apple macOS systems as an alternative to the MoltenVK project. KosmicKrisp was upstreamed for Mesa 26.0 and continues making great progress for opening up more Vulkan possibilities in Apple's world...








Engadget"Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics"


  • Terminator Zero showrunner confirms the Netflix anime has been canceled after one season
    If you9ve been wondering what9s next for Netflix9s Terminator Zero in the time since its first season, we finally have an update, and it9s a bummer. Responding to a fan on social media, showrunner Mattson Tomlin said this weekend that the show has been canceled. Despite being generally well received, Tomlin noted that "at the end of the day not nearly enough people watched it."
    It was cancelled. The critical and audience reception to it was tremendous, but at the end of the day not nearly enough people watched it. I would’ve loved to deliver on the Future War I had planned in season’s 2 and 3, but I’m also very happy with how it feels contained as is. https://t.co/Dh7G6gkBF7 pic.twitter.com/dqCSXHIytg
    — mattson tomlin (@mattsontomlin) February 13, 2026
    Season one of Terminator Zero was released in August 2024 and focused on the events around Judgment Day — August 29, 1997, as established in Terminator 2 — and its aftermath, jumping forward to 2022, more than two decades into a war between humans and machines. In the post about the show9s cancellation, Tomlin wrote, "I would’ve loved to deliver on the Future War I had planned in season’s 2 and 3, but I’m also very happy with how it feels contained as is."

    Tomlin went on to praise the marketing team in additional replies for "trying to really make the show work," as well as the hundreds of people who worked on the show. Offering a bit of insight, Tomlin wrote, "Generally speaking, anime audiences skew younger. Terminator audiences skew older. Terminator Zero asked them to meet in the middle, and they didn’t in the way the corporation needed to justify the spend to continue. I’m extremely grateful to the people who have watched it."



    This article originally appeared on Engadget at https://www.engadget.com/entertainment/streaming/terminator-zero-showrunner-confirms-the-netflix-anime-has-been-canceled-after-one-season-211656840.html?src=rss



  • Apple may be adding a splash of color to its upcoming budget-friendly MacBook
    The hardest choice to make for building your next MacBook might be selecting a color. According to iMac in 2024 with a total of seven colors and swapped out the space gray option for sky blue for the latest MacBook Air.

    Color choices aside, the latest rumors point to the upcoming MacBook having a price tag that9s anywhere between $699 and $799. To achieve that lower price point, Apple is expected to port over its chips designed for iPhones, like the A18 Pro that we first saw with the iPhone 16 Pro Max. We9re also anticipating Apple will compromise on specs, ports, or even the display, but Gurman reported that the company won9t be skimping when it comes to the shell. According to Gurman, Apple will employ a new manufacturing process to craft aluminum shells for the affordable MacBook, instead of opting for a cheaper material like plastic to cut costs. We may not have to wait long to see the official colors of the budget MacBook, as Gurman reported that it will be announced during an event in March.
    This article originally appeared on Engadget at https://www.engadget.com/computing/laptops/apple-may-be-adding-a-splash-of-color-to-its-upcoming-budget-friendly-macbook-192740002.html?src=rss



  • Apple's iPhone Air MagSafe battery is cheaper than ever right now
    We found the iPhone Air to have a pretty decent battery life for such a thin-and-light phone, somewhere in the region of 27 hours if you’re continuously streaming video. But it9s still a phone, arguably your most used device on a daily basis, so you may need to top it up during the day if you9re using it constantly. That’s where Apple’s iPhone Air MagSafe battery pack comes in, and it’s currently on sale for $79.



    This accessory only works with the iPhone Air, but much like the phone it attaches to, it’s extremely slim at 7.5mmm, so crucially doesn’t add so much bulk when attached that it defeats the point of having a thin phone in the first place. The MagSafe Battery isn’t enormous at 3,149mAh (enough to add an extra 65 percent of charge to the Air), but it can wirelessly charge the AirPods Pro 3 as well, making it an even more useful travel companion. You can also charge your iPhone while charging the battery pack.

    At its regular price of $99, the MagSafe battery pack is an admittedly pricey add-on to what is already an expensive phone, but for $20 off it’s well worth considering what Engadget’s Sam Rutherford called an "essential accessory" for some users in his iPhone Air review.

    Many Apple loyalists will always insist on having first-party accessories for their iPhone, but there are plenty of third-party MagSafe chargers out there too, a lot of them considerably cheaper than Apple’s lineup. Be sure to check out our guide for those. 

    Follow @EngadgetDeals on X for the latest tech deals and buying advice.
    This article originally appeared on Engadget at https://www.engadget.com/deals/apples-iphone-air-magsafe-battery-is-cheaper-than-ever-right-now-144516217.html?src=rss


  • Get a four-pack of first-gen AirTags on sale for only $64
    Good deals on Apple products aren’t as frequent as we’d like them to be, but if there’s one of the company’s products that does seem to enjoy pretty regular price cuts, it’s the AirTag. Right now you can pick up a four-pack of Apple’s diminutive first-generation Bluetooth trackers for $64, which translates to 35 percent off and a near record low price.

    Bear in mind that this deal brings the price per AirTag down to about $16 if you were to buy them individually, and when not on sale they usually cost $29.



    If you use Apple devices and consider yourself to be a serial thing-misplacer, AirTags are extremely useful. Adding one to your account takes a single tap, and with Apple’s Find My network so well established, locating missing items has never been easier.

    Using your iPhone you can trigger a sound from the AirTag’s built-in speaker, or alternatively Precision Finding can be used to pinpoint its location via Find My. You just follow the instructions on your iPhone, paying attention to the vibrations that signal you’re getting closer.

    A reminder again that the above deals apply to the first-generation AirTag only. Apple introduced a refreshed tracker with greater range and a louder speaker last month, which retails at the same price as its predecessor. For deals on the new AirTag, you may have to wait a bit.

    Follow @EngadgetDeals on X for the latest tech deals and buying advice.
    This article originally appeared on Engadget at https://www.engadget.com/deals/get-a-four-pack-of-first-gen-airtags-on-sale-for-only-64-163619270.html?src=rss



  • Get the 512GB Samsung P9 microSD Express card for 33 percent off right now
    MicroSD Express cards are still a little hard to find, considering they9re pretty new and only really started becoming popular last year once the Switch 2 came out. These upgraded versions of microSD cards are the only ones compatible with the Switch 2 for expanding its storage, os if you9re already starting to feel the crunch on your console, it9s worth picking one up. Samsung9s P9 microSD Express card is on sale right now — you can grab the 512GB version of $80, which is 33 percent off and one of the best prices we9ve seen.

    The P9 boasts transfer speeds of up to 800MB/s, making moving games to the card that much faster. As for load times, in our testing we found that any microSD Express, the standard the Switch 2 requires, will offer roughly the same performance. This format is pretty new, so there aren9t a ton of cards on the market. As such, the P9 makes our list of best microSD cards for the Nintendo Switch 2.

    The P9 microSD Express is also compatible with the Steam Deck or any other gaming console that accepts the format, as well as cameras and more.



    Follow @EngadgetDeals on X for the latest tech deals and buying advice.
    This article originally appeared on Engadget at https://www.engadget.com/deals/get-the-512gb-samsung-p9-microsd-express-card-for-33-percent-off-right-now-143849920.html?src=rss


  • Anker's 45W Nano charger with smart display is $10 off
    Anker rolled out a bunch of new chargers and other gear at CES 2026, including a cute one that's already on sale. The new Nano charger with smart display, which is an upgrade to the existing Nano charger in Anker's lineup, is on sale for $30 right now. That's $10 off the regular price.

    The 45W charger includes a smart display that shows real-time data like power flow, temperature and charging status. It also features "fun animations to keep things cheerful." Anker says it can recognize what's being charged and automatically adjust certain metrics to ensure a longer battery lifespan.

    To that end, it works with just about everything. The company advertises that this charger is a good fit for the iPhone, Apple Watch, AirPods and Samsung devices, among others. The new Nano Charger is on the smaller side, with dual folding prongs that rotate to fit most outlets.



    Follow @EngadgetDeals on X for the latest tech deals and buying advice.
    This article originally appeared on Engadget at https://www.engadget.com/deals/ankers-45w-nano-charger-with-smart-display-is-10-off-160707508.html?src=rss


OSnews

  • Why do I not use AI! at OSNews?
    In my fundraiser pitch published last Monday, one of the things I highlighted as a reason to contribute to OSNews and ensure its continued operation stated that we do not use any AI; not during research, not during writing, not for images, nothing.! In the comments to that article, someone asked: Why do I care if you use AI? ↫ A comment posted on OSNews A few days ago, Scott Shambaugh rejected a code change request submitted to popular Python library matplotlib because it was obviously written by an AI!, and such contributions are not allowed for the issue in question. Thats when something absolutely wild happened: the AI! replied that it had written and published a hit piece targeting Shambaugh publicly for gatekeeping!, trying to blackmail Shambaugh into accepting the request anyway. This bizarre turn of events obviously didnt change Shambaughs mind. The AI! then published another article, this time a lament about how humans are discriminating against AI!, how its the victim of what effectively amounts to racism and prejudice, and how its feelings were hurt. The article is a cheap simulacra of something a member of an oppressed minority group might write in their struggle for recognition, but obviously void of any real impact because its just fancy autocomplete playing a game of pachinko. Imagine putting down a hammer because youre dealing with screws, and the hammer starts crying in the toolbox. What are we even doing here? RAM prices went up for this. This isnt where the story ends, though. Ars Technica authors Benj Edwards and Kyle Orland published an article describing this saga, much like I did above. The articles second half is where things get weird: it contained several direct quotes attributed to Shambaugh, claimed to be sourced from Shambaughs blog. The kicker? These quotes were entirely made up, were never said or written by Shambaugh, and are nowhere to be found on his blog or anywhere else on the internet  theyre only found inside this very Ars Technica article. In a comment under the Ars article, Shambaugh himself pointed out the quotes were fake and made-up, and not long after, Ars deleted the article from its website. By then, everybody had already figured out what had happened: the Ars authors had used AI! during their writing process, and this AI! had made up the quotes in question. Why, you ask, did the AI! do this? Shambaugh: This blog you’re on right now is set up to block AI agents from scraping it (I actually spent some time yesterday trying to disable that but couldn’t figure out how). My guess is that the authors asked ChatGPT or similar to either go grab quotes or write the article wholesale. When it couldn’t access the page it generated these plausible quotes instead, and no fact check was performed. ↫ Scott Shambaugh A few days later, Ars Technicas editor-in-chief Ken Fisher published a short statement on the events. On Friday afternoon, Ars Technica published an article containing fabricated quotations generated by an AI tool and attributed to a source who did not say them. That is a serious failure of our standards. Direct quotations must always reflect what a source actually said. Ars Technica does not permit the publication of AI-generated material unless it is clearly labeled and presented for demonstration purposes. That rule is not optional, and it was not followed here. ↫ Ken Fisher at Ars Technica In other words, Ars Technica does not allow AI!-generated material to be published, but has nothing to say about the use of AI! to perform research for an article, to summarise source material, and to perform similar aspects of the writing process. This leaves the door wide open for things like this to happen, since doing research is possibly the most important part of writing. Introduce a confabulator in the research process, and you risk tainting the entire output of your writing. That is why you should care that at OSNews, we do not use any AI; not during research, not during writing, not for images, nothing!. If theres a factual error on OSNews, I want that factual error to be mine, and mine alone. If you see bloggers, podcasters, journalists, and authors state they use AI! all the time, you might want to be on your toes.


  • Microsofts original Windows NT OS/2 design documents
    Have you ever wanted to read the original design documents underlying the Windows NT operating system? This binder contains the original design specifications for “NT OS/2,” an operating system designed by Microsoft that developed into Windows NT. In the late 1980s, Microsofts 16-bit operating system, Windows, gained popularity, prompting IBM and Microsoft to end their OS/2 development partnership. Although Windows 3.0 proved to be successful, Microsoft wished to continue developing a 32-bit operating system completely unrelated to IBMs OS/2 architecture. To head the redesign project, Microsoft hired David Cutler and others away from Digital Equipment Corporation (DEC). Unlike Windows 3.x and its successor, Windows 95, NTs technology provided better network support, making it the preferred Windows environment for businesses. These two product lines continued development as separate entities until they were merged with the release of Windows XP in 2001. ↫ Object listing at the Smithsonian The actual binder is housed in the Smithsonian, although its not currently on display. Luckily for us, a collection of Word and PDF files encompassing the entire book is available online for your perusal. Reading these documents will allow you to peel back over three decades of Microsofts terrible stewardship of Windows NT layer by layer, eventually ending up at the original design and intent as laid out by Dave Cutler, Helen Custer, Daryl E. Havens, Jim Kelly, Edwin Hoogerbeets, Gary D. Kimura, Chuck Lenzmeier, Mark Lucovsky, Tom Miller, Michael J. OLeary, Lou Perazzoli, Steven D. Rowe, David Treadwell, Steven R. Wood, and more. A fantastic time capsule we should be thrilled to still have access to.


  • Exploring Linux on a LoongArch mini PC
    Theres the two behemoth architectures, x86 and ARM, and we probably all own one or more devices using each. Then theres the eternally up-and-coming RISC-V, which, so far, seems to be having a lot of trouble outgrowing its experimental, developmental stage. Theres a fourth, though, which is but a footnote in the west, but might be more popular in its country of origin, China: LoongArch (Im ignoring IBMs POWER, since there hasnt been any new consumer hardware in that space for a long, long time). Wesley Moore got his hands on a mini PC built around the Loongson 3A6000 processor, and investigated what its like to run Linux on it. He opted for Chimera Linux, which supports LoongArch, and the installation process feels more like Linux on x86 than Linux on ARM, which often requires dedicated builds and isnt standardised. Sadly, Wayland had issues on the machine, but X.org worked just fine, and it seems virtually all Chimera Linux packages are supported for a pretty standard desktop Linux experience. Performance of this chip is rather mid, at best. The Loongson-3A6000 is not particularly fast or efficient. At idle it consumes about 27W and under load it goes up to 65W. So, overall it’s not a particularly efficient machine, and while the performance is nothing special it does seem readily usable. Browsing JS heavy web applications like Mattermost and Mastodon runs fine. Subjectively it feels faster than all the Raspberry Pi systems I’ve used (up to a Pi 400). ↫ Wesley Moore Ive been fascinated by LoongArch for years, and am waiting to pounce on the right offer for LoongArchs fastest processor, the 3C6000, which comes in dual-socket configurations for a maximum total of 128 cores and 256 threads. The 3C6000 should be considerably faster than the low-end 3A6000 in the mini PC covered by this article. Im a sucker for weird architectures, and it doesnt get much weirder than LoongArch.


  • A brief history of barbed wire fence telephone networks
    If you look at the table of contents for my book, Other Networks: A Radical Technology Sourcebook, you’ll see that entries on networks before/outside the internet are arranged first by underlying infrastructure and then chronologically. You’ll also notice that within the section on wired networks, there are two sub-sections: one for electrical wire and another for barbed wire. Even though the barbed wire section is quite short, it was one of the most fascinating to research and write about – mostly because the history of using barbed wire to communicate is surprisingly long and almost entirely undocumented, even though barbed wire fence phones in particular were an essential part of early- to mid-twentieth century rural life in many parts of the U.S. and Canada! ↫ Lori Emerson I had no idea this used to be a thing, but it obviously makes a ton of sense. If you can have a conversation by stringing a few tin cans together, you can obviously do something similar across metal barbed wire. Theres something poetic about using one of mankinds most dividing inventions to communicate, and thus bring people closer together.


  • Haiku further improves its touchpad support
    January was a busy month for Haiku, with their monthly report listing a metric ton of smaller fixes, changes, and improvements. Perusing the list, a few things stand out to me, most notably continued work on improving Haikus touchpad support. The remainder of samuelrp84’s patchset implementing new touchpad functionality was merged, including two-finger scrolling, edge motion, software button areas, and click finger support; and on the hardware side, driver support for Elantech “version 4” touchpads, with experimental code for versions 1, 2, and 3. (Version 2, at least, seems to be incomplete and had to be disabled for the time being.) ↫ Haiku’s January 2026 activity report On a related note, the still-disabled I2C-HID saw a number of fixes in January, and the rtl8125 driver has been synced up with OpenBSD. I also like the changes to kernel_version, which now no longer returns some internal number like BeOS used to do, instead returning B_HAIKU_VERSION; the uname command was changed accordingly to use this new information. Theres some small POSIX compliance fixes, a bunch of work was done on unit tests, and a ton more.


  • Microsoft Store gets another CLI tool
    We often lament Microsofts terrible stewardship of its Windows operating system, but that doesnt mean that they never do anything right. In a blog post detailing changes and improvements coming to the Microsoft Store, the company announced something Windows users might actually like? A new command-line interface for the Microsoft Store brings app discovery, installation and update management directly to your terminal. This enables developers and users with a new way to discover and install Store apps, without needing the GUI. The Store CLI is available only on devices where Microsoft Store is enabled. ↫ Giorgio Sardo at the Windows Blogs Of course, this new command-line frontend to the Microsoft Store comes with commands to install, update, and search for applications in the store, but sadly, it doesnt seem to come with an actual TUI for browsing and discovery, which is a shame. I sometimes find it difficult to use dnf to find applications, as its not always obvious which search terms to use, which exact spelling packagers are using, which words they use in the description, and so on. In other words, it may not always be clear if the search terms youre using are the correct ones to find the application you need. If package managers had a TUI to enable browsing for applications instead of merely searching for them, the process of using the command line to find and install applications would be much nicer. Arch has this third-party TUI called pacseek for its package manager, and it looks absolutely amazing. Ive run into a rudimentary dnf TUI called dnfseek, but its definitely not as well-rounded as pacseek, and it also hasnt seen any development since its initial release. I couldnt find anything for apt, but theres always aptitude, which uses ncurses and thus fulfills a similar role. To really differentiate this new Microsoft Store command-line tool from winget, the company couldve built a proper TUI, but instead it seems to just be winget with nicer formatted output that is limited to just the Microsoft Store. Nice, I guess.


  • The future for Tyr
    The team behind Tyr started 2025 with little to show in our quest to produce a Rust GPU driver for Arm Mali hardware, and by the end of the year, we were able to play SuperTuxKart (a 3D open-source racing game) at the Linux Plumbers Conference (LPC). Our prototype was a joint effort between Arm, Collabora, and Google; it ran well for the duration of the event, and the performance was more than adequate for players. Thankfully, we picked up steam at precisely the right moment: Dave Airlie just announced in the Maintainers Summit that the DRM subsystem is only about a year away! from disallowing new drivers written in C and requiring the use of Rust. Now it is time to lay out a possible roadmap for 2026 in order to upstream all of this work. ↫ Daniel Almeida at LWN.net A very detailed look at what the team behind Tyr is trying to achieve with their Rust GPU driver for Arm Mali chips.


  • The original Secure Boot certificates are about to expire, but you probably wont notice
    With the original release of Windows 8, Microsoft also enforced Secure Boot. Its been 15 years since that release, and that means the original 2011 Secure Boot certificates are about to expire. If these certificates are not replaced with new ones, Secure Boot will cease to function  your machine will still boot and operate, but the benefits of Secure Boot are mostly gone, and as newer vulnerabilities are discovered, systems without updated Secure Boot certificates will be increasingly exposed. Microsoft has already been rolling out new certificates through Windows updates, but only for users of supported versions of Windows, which means Windows 11. If youre using Windows 10, without the Extended Security Updates, you wont be getting the new certificates through Windows Update. Even if you use Windows 11, you may need a UEFI update from your laptop or motherboard OEM, assuming they still support your device. For Linux users using Secure Boot, youre probably covered by fwupd, which will update the certificates as part of your systems update program, like KDEs Discover. Of course, you can also use fwupd manually in the terminal, if youd like. For everyone else not using Secure Boot, none of this will matter and youre going to be just fine. I honestly doubt there will be much fallout from this updating process, but theres always bound to be a few people who fall between the cracks. All we can do is hope whomever is responsible for Secure Boot at Microsoft hasnt started slopcoding yet.


  • Microsoft adds and fixes remote code execution vulnerability in Notepad
    What happens when you slopcode a bunch of bloat to your basic text editor? Well, you add a remote code execution vulnerability to notepad.exe. Improper neutralization of special elements used in a command (command injection) in Windows Notepad App allows an unauthorized attacker to execute code over a network. An attacker could trick a user into clicking a malicious link inside a Markdown file opened in Notepad, causing the application to launch unverified protocols that load and execute remote files. ↫ CVE-2026-20841 I dont know how many more obvious examples one needs to understand that Microsoft simply does not care, in any way, shape, or form, about Windows. A lot of people seem very hesitant to accept that with even LinkedIn generating more revenue for Microsoft than Windows, the writing is on the wall. Anyway, the fix has been released through the Microsoft Store.


  • Kapsule adds easy developer environment containers to KDE Linux
    If youre a developer and use KDE, youre going to be interested in a new feature KDE is working on for KDE Linux. In my last post, I laid out the vision for Kapsule—a container-based extensibility layer for KDE Linux built on top of Incus. The pitch was simple: give users real, persistent development environments without compromising the immutable base system. At the time, it was a functional proof of concept living in my personal namespace. Well, things have moved fast. ↫ Herp De Derp Not only is Kapsule now available in KDE Linux, its also properly integrated with Konsole now. This means you can launch Kapsule containers right from the new tab menu in Konsole for even easier access. Theyre also working on allowing users to easily launch graphical applications from the containers and have them appear in the host desktop environment, and they intend to make the level of integration with the host more configurable so developers can better tailor their containers to their needs.



Linux Journal News

  • EU OS: A Bold Step Toward Digital Sovereignty for Europe
    Image
    A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem.
    What Is EU OS?
    EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.

    Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments.
    The Vision Behind EU OS
    The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.

    Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.

    However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty.
    Conclusion
    EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.

    Source: It's FOSS
    European Union


  • Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.

    In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.

    On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.

    Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.

    The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.

    Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.

    You can download the latest kernel here.
    Linus Torvalds kernel


  • AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
    Image
    AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.

    This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.

    Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.

    Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.

    Source: 9to5Linux
    AerynOS


  • Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
    Image
    Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.

    Here’s a quick overview of what’s new in Xojo 2025r1:
    1. Linux ARM IDE Support
    Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started.
    2. Web Drag and Drop
    One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required!
    3. Direct App Store Publishing
    Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process.
    4. New Desktop and Mobile Features
    This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection.
    5. Performance and IDE Enhancements
    Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced.
    What Does This Mean for Developers?
    Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution.
    How to Get Started
    Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.

    Download Xojo 2025r1 today at xojo.com.
    Final Thoughts
    With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you.
    Xojo ARM


  • New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux

    Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.

    Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.

    Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest. 

    Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.

    Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.

    Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.

    By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem.
    Windows


  • Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities

    The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally. 

    As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.

    In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions. 

    After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.

    The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.

    At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.

    The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca.
    Security


  • Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges

    The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.

    A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.

    This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem. 

    The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.

    On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.

    In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers.
    kernel


  • Linux Celebrates 32 Years with the Release of 6.6-rc2 Version

    Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.

    The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.

    Here is what Linus Torvalds had to say in today's announcement:
    Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds


  • Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction

    Want to interact with ChatGPT from your Linux desktop without using a web browser?

    Bavarder, a new app, allows you to do just that.

    Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.

    With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.

    During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.

    At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.

    As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!

    Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring.
    ChatGPT AI


  • LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite

    Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.

    Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.

    LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.

    You can download LibreOffice 7.5.3 directly from the LibreOffice websiteor from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.

    All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.

    In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.

    Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.

    The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners.
    LibreOffice


Linux Magazine News (path: lmi_news)



  • LibreOffice 26.2 Now Available
    With new features, improvements, and bug fixes, LibreOffice 26.2 delivers a modern, polished office suite without compromise.





  • Photoshop on Linux?
    A developer has patched Wine so that it'll run specific versions of Photoshop that depend on Adobe Creative Cloud.





Page last modified on November 17, 2022, at 06:39 PM