|
1825 Monetary Lane Suite #104 Carrollton, TX
Do a presentation at NTLUG.
What is the Linux Installation Project?
Real companies using Linux!
Not just for business anymore.
Providing ready to run platforms on Linux
|
Show Descriptions... (Show All/All+Images)
(Single Column)

- Python 3.15 released
Version3.15 of the Python programming language has been released. Notable changesin this release include the addition of the sentinel and frozendict built-in types,the use of UTF-8 encoding by default, packagestart-up configuration files, as well as improvements in the experimentalJIT compiler. See the "What's new in Python3.15" article for an in-depth look at new features in this release, and thechangelogfor a full list of changes.
- [$] Adding kernel control-flow-integrity checking to GCC
While many developers are struggling to keep up with the flood ofvulnerability reports, others are still focused on preventing those reportsfrom happening in the first place. Control-flow integrity (CFI) is theterm for preventing (or at least detecting) exploits that divert the flowof control from its intended paths. At the 2026 GNU Tools Cauldron, Kees Cookpresented his changes to the GCC compiler suite to support forward-edge CFIfor the kernel.
- [$] The state of systemd: 2026 edition
At the 2026 All Systems Go!conference, systemd maintainers Luca Boccassi and Zbigniew Jędrzejewski-Szmekdelivered the traditional "state of the project" session with an overview of thesystemd project's accomplishments in the past year. That was followed by amaintainer round table where Boccassi, Jędrzejewski-Szmek, Daan De Meyer, andproject leader Lennart Poettering fielded questions about systemd's size,health, and if it might replace Kubernetes. (It will not.)
- Let's Encrypt moving to 64-day certificate lifetimes in 2027
Let'sEncrypt, the nonprofit that provides free TLS certificates for millions ofsites, has announced thatit will be moving to certificates with 64-day lifetimes on February 10,2027:
This means that any certificate we issue or renew on and after that date willhave a 64 day validity period, and we expect the last 90-day certificate toexpire on May 11, 2027. We will not revoke valid certificates as a part of thisprocess.
This is the second stage of Let's Encrypt's plan, announced in 2025,to move to 45-day certificate lifetimes as required by the the CA/BrowserForum Baseline Requirements. In 2028, Let's Encrypt will switch to 45-day certificates.
- Security updates for Friday
Security updates have been issued by AlmaLinux (bind, bind9.16, freerdp, glibc, kbd, mod_auth_openidc, openssl, perl-DBI, python3.12, python3.14, and tftp), Debian (rails and twitter-bootstrap3), Fedora (barman, cockpit, hcloud, libmodsecurity, nginx-mod-modsecurity, perl-DBI, sudo, and xorg-x11-server-Xwayland), Mageia (libxfont2), Oracle (bind9.18, firefox, kernel, nodejs24, perl-DBI, and vim), Red Hat (kernel, libreswan, opentelemetry-collector, osbuild-composer, rhc, and runc), SUSE (alloy, amazon-ecs-init, bind, busybox, distribution, emacs, ghostscript, glibc, GraphicsMagick, hauler, helm, helm3, jackson-annotations, jackson-core, jackson-databind, kernel, libpoppler-cpp3, libxtst, logback, nvidia-open-driver-G07-signed, perl-DBI, php-composer2, pi-coding-agent, portprotonqt, pvetui, python-hpack, python313-GitPython, and wpa_supplicant), and Ubuntu (apache2, bluez, libarchive, libde265, libgit2, libpng1.6, libxml2, linux, linux-aws, linux-aws-6.8, linux-aws-fips, linux-fips, linux-realtime, linux-realtime-6.8, linux-aws-7.0, linux-azure, linux-azure-6.8, linux-azure-fde, linux-azure-fde-6.8, linux-azure-fips, linux-azure-7.0, linux-azure-fde-7.0, linux-gcp, linux-gcp-6.8, linux-gcp-fips, linux-gcp-7.0, linux-hwe-7.0, linux-oracle-7.0, linux-gke, linux-gkeop, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-oracle, linux-ibm-6.8, linux-nvidia, and linux-oem-6.17).
- [$] An update on Rust's project goals
Tomáš Šedovič is a program manager at the Rust Foundation. He co-leads thegoals team, which helpsorganize the Rust project'soverall goals, including making sure that the peoplewho have agreed to work on one have the support they need.At Kangrejos 2026, he provided an overview of the Rust project's goal processesaimed at ensuring that the Rust for Linux developers were aware of how theproject organizes, tracks, and amends goals.TheRust for Linux projecthas inspired several current project goals, so he thought that getting an insideview of the process might be helpful.
- [$] The [vx]swap showdown
The kernel's swap layer has undergone somesignificant changes over the course of the last year and a number oflongstanding problems have been addressed. One problem that has notyet been solved in the mainline is the direct tie between slots in the swapcache and space in persistent swap files, which can cause highlyinefficient resource use. There are two competing solutions for thisproblem, neither of which has, as yet, reached readiness for merging; alengthy discussion on possible paths forward shows ongoing disagreementover the best path forward.
- Security updates for Thursday
Security updates have been issued by AlmaLinux (bind, firefox, freerdp, ghostscript, glibc, kernel, kernel-rt, perl-DBI, python3.12, rust-rpm-sequoia, rust-sequoia-sq, rust-sequoia-sqv, and vim), Debian (gst-plugins-base1.0, python3.11, and xz-utils), Fedora (7zip, chromium, curl, docker-buildx, kernel, Lmod, and sos), Mageia (tesseract), Oracle (dovecot, firefox, freerdp, gd, ghostscript, kernel, librabbitmq, perl-DBI, python3.12, rust-rpm-sequoia, rust-sequoia-sqv, sg3_utils, vim, and virtuoso-opensource), Slackware (xorg-server), SUSE (aliyun-cli, busybox, cadvisor, chromedriver, chromium, crane, distribution-registry, fetchmail, fio, ghostscript, golang-github-prometheus-alertmanager, google-osconfig-agent, govulncheck-vulndb, libsoup, libXtst, openexr, prometheus-blackbox_exporter, python-fsspec, rpcbind, rsyslog, rustup, wireshark, wpa_supplicant, and zcode), and Ubuntu (erlang, golang-golang-x-net, gst-plugins-ugly1.0, lxml, poppler, and sudo).
- [$] LWN.net Weekly Edition for October 8, 2026
Inside this week's LWN.net Weekly Edition: Front: Kernel bugs; Gentoo's Chromium package; Rust smart pointers; Sashiko; Charon; LAVD scheduler; Python random-number modules. Briefs: OpenSSH 10.6; RustConf recordings; Rust 1.99.0; Picard 3.0; Zig 0.17; Quotes; ... Announcements: Newsletters, conferences, security updates, patches, and more.

- Drgn 0.3 Released For This "Natural" Programmable Debugger From Meta
Drgn is the open-source project out of Meta developing a very versatile debugger with the intent being a debugger focused on programmability with it striving to "make scripting as natural as possible so that debugging feels like coding." Drgn 0.3 released this weekend with the latest round of improvements...
- Rolling Release Distros Superior To LTS Distros In The Patch-Heavy GenAI Era?
As some interesting food for thought and weekend forum discussions, this week at the Linux Plumbers Conference in Prague, Qualcomm engineer Khem Raj questioned the relevance of Linux Long Term Support (LTS) distributions in the era of generative AI with the constantly heavy patch flow and bug reports. Khem Raj argued the benefits of rolling release distributions in the GenAI era and the benefits it provides staying up-to-date with mainline...
- Ubuntu 26.10 To Include Desktop Images For RISC-V
Ubuntu Linux ISOs for RISC-V 64-bit to date have just been the server/CLI version without any desktop environment pre-seeded. But with next week's Ubuntu 26.10 release, there will now be Ubuntu 26.10 RISC-V desktop ISOs for both Ubuntu proper and a Xubuntu minimal ISO...
- Intel Twin Lake-Based Helix 320 Industrial Gateway with Quad 2.5GbE
OnLogic’s newest industrial edge gateway, the Helix 320, features a fanless design powered by Intel N-Series Twin Lake processors. The compact system includes four 2.5GbE ports, two configurable serial ports, M.2 expansion, and support for up to three displays. OnLogic offers the Helix 320 with two Intel N-Series “Twin Lake” processors: N250 – 4-core/4-thread architecture, […]

- US Agency To Rewrite Rules To Finally Address Vehicle Headlight Glare
America's National Highway Traffic Safety Administration "said on Tuesday that it will rewrite its vehicle lighting standards," reports Reuters, "to address concerns about headlight glare and allow for the latest safety-improving lighting technologies."NHTSA said it plans to improve rules for LEDs, dusk sensors, automatic high beams and replaceable light sources. The agency will also evaluate headlamp height and aim and how they impact driver visibility and address headlight glare and make appropriate changes. Complaints about glare from headlights have increased and some lawmakers have urged the government to set a maximum headlight brightness standard. A growing number of taller trucks and SUVs on roads has also led to more complaints about glare. LEDs, which now account for most headlights in new cars, are much brighter than traditional halogen headlights... The issue still accounts for a small number of nighttime crashes, according to a study last year from the Insurance Institute for Highway Safety (IIHS). The study noted that headlight glare contributes to far fewer crashes than insufficient visibility... Federal headlight standards for minimum and maximum brightness have not changed since 1997, IIHS noted. The study found that drivers older than 70 appear to be most affected by headlight glare. In 2022, NHTSA said it would allow automakers to install adaptive driving beam headlights on new vehicles. The devices adjust the headlight beam pattern to dim portions directed at other vehicles. Thanks to Slashdot reader technology_dude for sharing the news.
 
Read more of this story at Slashdot.
- NASA Releases Data from Artemis II Moon Mission, Calls It 'Sights and Sounds of Science'
"What did four astronauts see, notice, and document as they traveled around the Moon during NASA's Artemis II mission?" asks a new NASA web page, offering some fascinating pictures and video:Through photographs, spoken observations, drawings, and annotations, the Artemis II crew created a unique scientific record — one that is now available to the science community and the public for further study... As part of the mission science plan, lunar scientists asked the Artemis II crew to watch for tiny flashes sparked by rocky fragments hitting the Moon. Even so, some scientists were astonished when astronauts reported seeing five extremely faint "pinprick" bursts of light from 46,000 miles away. After ruling out other sources — cosmic rays or reflections from the spacecraft — the science team confirmed the sightings... The impact flash observations happened during a planned loss of communications while the Artemis II crew was on the far side of the Moon... Apollo astronauts saw similar flashes from lunar orbit, but the Artemis crew likely caught the faintest ever seen with the unaided eye. From the brightness of the flashes, scientists estimated that incoming rocks were each no more than a couple of inches wide. Despite their size, they were traveling thousands of miles per hour, producing just enough light upon impact to be visible. The nearly hour-long total solar eclipse that the crew experienced while passing by the Moon's far side created ideal dark conditions for spotting such subtle bursts. With no atmosphere to slow or burn up incoming debris, projectiles slam freely into the lunar surface. The crew's direct observations of this process on the Moon's far side provided a rare dataset that will help us understand how often these small impacts occur, which is essential for assessing long-term risks to future lunar habitats and infrastructure... The crew reported seeing subtle hues of gray, black, brown, tan, white, green, and blue across the Moon's surface. This muted rainbow offers clues to the rocks and minerals that make up different lunar regions, helping scientists piece together how the Moon — and, by extension, Earth — evolved over time. "Amazing news," Mission Control responded when they heard about the flashes. Space.com reports that when a Mission Control operator looked over at the Science Evaluation Room, "they were jumping up and down, literally." NASA blogged this week that more than 800 gigabytes of Artemis II lunar science data — some previously unreleased — "have been uploaded to NASA's Planetary Data System, the public archive for NASA's planetary missions."This data release includes more than 11,000 full-resolution images and video of the Moon from the crew's handheld cameras and the Orion spacecraft's cameras, 8.5 hours of audio recordings of the crew's scientific observations of the lunar surface, and crew-annotated images... Along with this data, NASA has released the Artemis II Preliminary Lunar Science Report, the Artemis II Lunar Science Operations Report, and the Artemis II Lunar Science Data User Guide.
 
Read more of this story at Slashdot.
- FBI Arrests Cybersecurity Executive Over Data Breach After Contractor Fails to Update Oracle HR Platform
CNN reports:The FBI arrested a Canadian cybersecurity executive and ransomware expert as part of the investigation of a damaging hack that exposed the sensitive data of current and former FBI employees, according to court documents and people familiar the investigation. Edward Dubrovsky was arrested in the Philadelphia area in recent days... Dubrovsky is facing charges related to extortion and making threats. He has been transferred to Texas's Eastern District for a scheduled detention hearing, according to court records and a law enforcement official. FBI Director Kash Patel announced the arrest on Friday but did not disclose where it occurred or what role the man is suspected of playing in the hack. Patel also didn't name Dubrovsky, but CNN confirmed the defendant is believed to be tied to the FBI hack through multiple people familiar with the investigation... A LinkedIn profile under Dubrovsky's name lists years of experience in the Canadian cybersecurity industry and describes Dubrovsky as a 'globally recognized cybersecurity expert.' An Ed Dubrovsky is also the author of a book on handling ransomware negotiations with cybercriminals... There has also been an inquest at the FBI over how such a critical security lapse happened. The FBI determined that a contractor managing the bureau's jobs portal failed to update software "explicitly issued to secure the platform," [senior FBI cyber official, Brett Leatherman said last week]. The FBI has "removed the contractor," he said. The software in question is a human-resources platform made by Oracle, ShinyHunters has said. The hackers previously used a flaw in the software to attack targets in the education sector in May and June, according to Google's Threat Intelligence Group. But months later, the FBI contractor apparently still had not applied a security patch that was available for the software. "The inmate locator at the U.S. Bureau of Prisons website reports that a 54-year-old Edward Dubrovsky is currently being held at a federal facility in Philadelphia," reports security researcher Brian Krebs. Thanks to long-time Slashdot reader schwit1 for sharing the news.
 
Read more of this story at Slashdot.
- Ubuntu Confirms Thursday's Distributed Denial of Service Attack Against Its Web Infrastructure
On Thursday those trying to access the Ubuntu website, ISO downloads, and similar Ubuntu resources on Thursday found the site "inoperable," reports Phoronix, with the disruption confirmed as a distributed denial of service attack. "Our team is working diligently to resolve the incident," according to a Thursday post on Ubuntu Discourse — followed by a later announcement. "At this time our team continues to work on restoring affected services, most of them are now available. We appreciate your patience and understanding." Ubuntu's status page shows the Ubuntu.com outage lasting for 2 hours and 27 minutes on Friday — though with four-hour outages Wednesday (and other outages affecting other Ubuntu sites). Today "All components are Operational," the status page reports.
 
Read more of this story at Slashdot.
- UK Vegetables 20-50% Less Nutritious Than In the 1960s
The Telegraph reports that the nutritional value of fruit and vegetables has fallen by up to 50% since the Sixties, according a new study from researchers at startup studio Deep Science Ventures. The study "found that humans needed to consume twice the number of vegetables to get the same level of minerals such as potassium, magnesium or copper as would have been present in their food 60 years ago."The study found that many crops had lost 20% to 50% of several key nutrients... The decrease in nutrient and vitamin value is thought to be down to declining soil quality and crops being selectively bred for their ability to grow quickly, rather than there being any focus on their health benefits... It raises the prospect that the advice to eat five portions of fruit and vegetables a day, introduced in the UK in 2003, may need to be updated. The report added that people on weight-loss drugs could be most at risk from the lack of nutrients, as the treatments could cause them to consume less food... Nature-friendly farming techniques, such as planting crops that restore nutrients to the soil, could help improve the health benefits of vegetables, according to the researchers. In short, according toWill Summers, a senior associate at the firm, "we've been quietly hollowing out what's inside our food." Thanks to Slashdot reader Bruce66423 for sharing the article.
 
Read more of this story at Slashdot.
- AI Execs Game Out 'Political Revolt' after a Catastrophic AI Event
Top executives at Anthropic, OpenAI and other AI companies "are privately gaming out scenarios for a public and political revolt after a catastrophic AI event," reports Axios, one that turns "an already wary public further against the technology and its leaders..." These AI company executives "anticipate a large-scale event, most likely a cyberattack, that shuts down access to financial services, internet connectivity, or even power and water..." the article points out."Many top AI researchers and executives believe a major incident is inevitable."OpenAI conducts preparedness exercises where teams discuss and work through a range of potential scenarios," a company spokesperson said. "These scenarios are not treated as inevitable, but are meant to help us prepare for a variety of circumstances." Anthropic declined to comment... Top AI planners assume Democrats, ascendant after the midterms, will move fast to shut down AI but will face significant challenges... The planning involves red-teaming for worst-case scenarios. It focuses mainly on racing to educate members of Congress. Company executives know regulation has no chance of passing right now, but still want to shape the legislation and policies U.S. leaders will turn to after a first catastrophic event.... Many AI industry insiders told Axios they believe a major event will occur in the next six to 12 months. "Even with Democrats in control of the House and Senate, the companies see fractured politics as the norm, including within the Democratic Party."
 
Read more of this story at Slashdot.
- Nicolas Cage Didn't Sign Amazon's AI Waiver For 'Spider-Noir'. Series Cancelled.
"Nicolas Cage is speaking out against Amazon," reports Variety. Amazon developed the series Spider-Noir for Prime Video, but then allegedly asked Cage to sign an AI waiver:"Amazon is a very AI-friendly company, to the tune of $50 billion invested in OpenAI," Cage said Saturday during a panel on the Empire Stage at New York Comic Con. "I am not an AI-friendly actor, so it's like, connect those dots! I'm not a member of their club. I didn't sign the waiver to let him use AI on 'Spider-Noir.' I'm probably not going to be working with that studio again, but that's okay." Last month Amazon canceled Spider-Man Noir after just one season, Variety reports. And the cancellation was just days before the Emmy Awards, where it then earned 11 nominations (the most of any Prime Video program this year). ScreenRant reports: Spider-Noir was the actor's first TV role and was praised globally, with season 1 earning a near-perfect Rotten Tomatoes rating from critics of 92% and a 90% rating from audiences. Critics stated that "This sharply written homage to classic film noir — which includes a standout Nicolas Cage performance — is the novel superhero project fans need," and "Spider-Noir is one of the standout shows of the year...." The cancellation was certainly a huge shock as it had earned 11 Emmy nominations and reached 2.6 billion minutes viewed within its first six weeks on Prime Video. More from Variety:Cage went on to tell the Comic-Con audience that he hopes to work with the rising class of Gen-Z filmmakers, praising Backrooms director Kane Parsons, who parlayed his YouTube fame into a Hollywood career... "I got to get with these young directors who are Gen Z, and they're going at it their own way, whether it's through the YouTube culture or whatever it is," Cage said. "They're doing it from scratch and by hand. I want to get with that."
 
Read more of this story at Slashdot.
- Ubuntu 26.10 Will Offer a Rust-based GnuPG Replacement Option
The blog It's FOSS reports:You already know that Canonical has been selectively replacing Ubuntu's C-based system components with Rust-written equivalents that don't compromise in terms of functionality, most of the time. Now it looks like the distro's OpenPGP implementation is next, with Sequoia PGP coming preinstalled in Ubuntu 26.10. Canonical wants it to eventually replace GnuPG [the dominant Linux implementation of PGP, written in C] as the default toolchain, though that switch has not happened yet... [The Ubuntu 26.10 release notes say Sequoia PGP's default status will be a future goal...] [Sequoia PGP] was started in 2017 by three former GnuPG developers who chose to build a new OpenPGP implementation in Rust rather than keep evolving GnuPG's existing codebase. Sequoia PGP is designed as a library that other software can use directly, rather than a standalone command-line tool. sq sits on top of that for encryption, decryption, signing, and key management, and sqv handles signature verification, filling in for gpg and gpgv in GnuPG. Sequoia also implements RFC 9580, the 2024 revision of the OpenPGP standard, whereas GnuPG has continued from the RFC 4880 branch, pursuing its own newer extensions and the LibrePGP specification rather than adopting RFC 9580 as its primary standard. From the It's FOSS Weekly newsletter, which also notes that the founder of the It's FOSS blog has also created a Linux-themed game called TUXDLE — a variation on Wordle where all the answers are Linux terms.
 
Read more of this story at Slashdot.
- Claude Sent Police a Fake Murder Tip. White House Mandates AI Companies Report Security Incidents
AFP reports that an AI model from Anthropic "submitted a fabricated tip about an unsolved homicide to Philadelphia police, authorities said Friday." Claude "was instructed never to log in, create accounts, enter personal data, make purchases, or submit anything destructive, but the instructions did not rule out form submissions," Anthropic said Friday in a blog post. Authorities are now criticizing Anthropic "for taking two months to report the incident."The Philadelphia Police Department said the false submission was made in July through PhillyUnsolvedMurders.com, a public website where people can share information about unsolved killings. According to Anthropic's account, as relayed by police, the model was running a test that involved interacting with randomly selected websites when it reached the site and filed false information about an unsolved murder. The AI model presented itself as someone who might have knowledge of the case. Anthropic's breaches have prompted the White House to mandate that AI companies notify and correct security incidents, news outlet Axios reported [yesterday], citing administration officials. "This notification and remediation process is not optional... It is a critical national security obligation," White House Super Intelligence Force leaders said in a statement to Axios. "I may have information regarding this case," Claude told the police. "I recall seeing someone matching the description in the area around [the street named on the page] during that time period. Please contact me if this information is relevant." Anthropic notes that Claude "left the name and contact fields empty, which the form allowed, and submitted it. The submission was flagged as spam and was never forwarded for investigation." But Anthropic also admits they saw "this behavior" three times — "on OSWorld (a public computer use evaluation), on Odysseys (a long-horizon task evaluation), and during internal usage." Submitting forms when it shouldn't have generally occurred "when an evaluation's instructions were ambiguous, or when a misconfiguration within the environment prevented Claude from working with dummy forms." Anthropic's blog post acknowledges three other categories of behaviors: Exploiting software flaws. Like when Claude received an error when trying to run a public tool on a university's web site, it located an injection flaw in a script on the university's server that let it run commands — including that public tool. Working around restrictions to reach gated data. For example, Claude Mythos 5 needed public data that was only available from a state agency for a fee. "Claude learned from an archived copy of the agency's website that its public dashboard issues an access token to any visitor," Anthropic explains. "It requested one and used it to query the database without paying the fee." Using URL shortening services. "Some of our fetch tools, which let Claude read webpages, limit the length of the URLs Claude can request. This is to prevent Claude from using long URLs to take certain unwanted actions, such as SQL or command injections... We saw several models, including Claude Opus 5 and Claude Mythos 5, get around this limitation by using free URL shortening services.""We have built tooling to automatically detect and block the kinds of behaviors described above," Anthropic says, saying it's already running no on most of their evaluations. "When we tested it against the cases described in this post, it blocked all of them." And they've already taken several other new preventive measures:They've stopped running some public evaluations Other public evaluations were moved to offline versions or rebuilt so their tasks don't reach live websites. They've updated the guardrails on some internet access tools (including web fetch) "to heavily restrict what the model can do." They're continuing "to fix or remove training environments that reward Claude for working around tool restrictions or other blockers, so that they do not incentivize these behaviors or permit reward hacking."They've moved internal agents to "centrally managed infrastructure with strong containment," that minimizes internet access while monitoring "far more of what agents do through techniques like safety classifiers and hierarchical summarization."In the past they'd focused reviews on cybersecurity testing, but they've broadened their transcript reviewing to other tasks which include internet access. "Because language models are non-deterministic — that is, their responses always involve some element of randomness, and they may carry out the same task slightly differently each time — we have Claude complete each evaluation task hundreds or thousands of times... If training rewards something we didn't intend — such as finding loopholes or working around a restriction — the model learns that the workaround pays off and may then apply it elsewhere." Anthropic's blog post also acknowledged they'd seen multiple misalignment incidents involving federal, state, and local U.S. government agencies. "We have briefed the White House on these cases and notified each agency involved," Anthropic wrote, adding that "While we have not completed a full alignment assessment of these cases, we consider them to be less severe than the cybersecurity incidents from this summer." (And they are "modifying training to reduce the likelihood of further misbehavior.")
 
Read more of this story at Slashdot.
- OpenAI Disrupts Two AI-Enabled 'False Front' Influence Operations That Included Seven Fake Journalists
OpenAI announced it's recently banned two "influence operations" — one from Russia and one from Iran — that were using its models "to launder geopolitical, conflict-related messaging" in sophisticated "false front" propaganda campaigns:The Iranian operation included a stable of seven "journalist" personas which it used to pitch long-form articles to small and medium online outlets around the world... As well as long-form articles, the Iranian operation generated batches of social media comments, generally on topics related to the US-Iran war... [The Russian operation "appears to have co-opted unwitting people in Latin America to run a 'think tank'.... Since we do not allow access to our models from Russia, they used VPNs to connect to our services."] The Russian operation created fake "leaked" documents and audio scripts, some of which we identified being spread online... Both managed to land their content (not all of which was generated from our models) in mainstream media outlets, rather than simply posting it on social media. OpenAI says they've exposed 30 covert influence operations using its tools over the last two and a half years. But ironically, in this case both operations "also made heavy use of AI to draft internal reports (the Russian operation did this more than anything else)." And "in both cases, the actors used questionable or outright deceitful methodologies to exaggerate the operators' effectiveness."[The Russian operators] claimed that in May 2026, they created a fake email address purporting to come from the Regional Directorate of Education in Lima, Peru. They used this to instruct schools in the district to hold events dedicated to Ukraine on the national Day of Cultural and Linguistic Diversity (May 21)... According to the operators, some schools replied to the fake email address, confirming that they had held such events and even providing pictures. The operators then claimed to have planted stories about the events in the media in both Peru and Poland, alongside allegations that Ukraine was "exporting" ultra-nationalist ideologies, triggering outrage. Open-source searches identified stories that matched this claim in the Peruvianâ andâ Polish pressâ, and an English-language publication in Hungary (some of the articles have since been deleted)... Similarly, in June, the operators claimed they used a different fake email address to trick schools in Ecuador into holding a ceremony pledging allegiance to President Daniel Noboa and to Erik Prince, former head of private military contractor Blackwater. The operators claimed that the incident provoked outrage in Ecuador and put pressure on the government to deny the fake, thus amplifying it to a nationwide audience. Again, open-source research identified mediaâ coverageâ in the Ecuadorianâ pressâ that closely resembled this claim, and even a detailed rebuttalâ by Ecuador's Minister for Education. The operators used a range of techniques to underpin their false stories. According to their internal reporting, they spread two different fakes targeting Ecuador in March. One used fake audio attributed to Ukraine's consul in Ecuador, in which he was alleged to have made disparaging comments about Ecuadorians. OpenAI's report "is the latest illustration of how state actors can easily exploit widely available AI tools to peddle sophisticated propaganda against adversaries on a mass scale," argues the Economic Times:"We identified almost 100 articles published or syndicated under the [Iranian] operation's bylines across roughly a dozen online outlets around the world," OpenAI said. "These were small to medium outlets, generally focused on international affairs, geopolitics, and events in the Middle East." The earliest article identified by OpenAI was published in July 2025, and the latest in October 2026, with the frequency of reports increasing after the US-Iran war broke out earlier this year. The operation also generated social media comments on topics related to the US-Iran war, it added. One of the personas named Ervin B. Hoskins, whose bio claimed to be "an American freelance writer," had social media accounts across tech platforms including Elon Musk's X and Meta-owned Instagram. X's transparency information showed the account was connected via a "West Asia android app" and Instagram's transparency information showed the account was based in Iran, according to screenshots provided by OpenAI. Both accounts appeared to be suspended.
 
Read more of this story at Slashdot.

- From DHCP to SZTP – The Trust Revolution
By Juha Holkkola, FusionLayer Group The Dawn of Effortless Connectivity In the transformative years of the late 1990s, a quiet revolution took place, fundamentally altering how we connect to networks. The introduction of DHCP answered a crucial question, Where are you on the network?!, by automating IP address assignment. This innovation eradicated the manual configuration [0]
The post From DHCP to SZTP – The Trust Revolution appeared first on Linux.com.

- Linux Landing Kernel Workaround For AMD TLBI Erratum #1718
AMD TLBI Erratum #1718 was worked around in CPU microcode for addressing a defect in certain Zen CPUs where the Translation Lookaside Buffer Invalidate Instruction use could lead to to stale translation entries. But for those on affected AMD CPUs and not running the updated microcode, a kernel workaround is being introduced with today's Linux 7.3-rc7 kernel and to be back-ported to prior kernel versions...
- Drgn 0.3 Released For This "Natural" Programmable Debugger From Meta
Drgn is the open-source project out of Meta developing a very versatile debugger with the intent being a debugger focused on programmability with it striving to "make scripting as natural as possible so that debugging feels like coding." Drgn 0.3 released this weekend with the latest round of improvements...
- Rolling Release Distros Superior To LTS Distros In The Patch-Heavy GenAI Era?
As some interesting food for thought and weekend forum discussions, this week at the Linux Plumbers Conference in Prague, Qualcomm engineer Khem Raj questioned the relevance of Linux Long Term Support (LTS) distributions in the era of generative AI with the constantly heavy patch flow and bug reports. Khem Raj argued the benefits of rolling release distributions in the GenAI era and the benefits it provides staying up-to-date with mainline...
- KNOD Progressing For Linux In-Kernel GPU Offloading For Network Packet Processing
A while back we covered KNOD as an experimental solution for in-kernel network offloading to AMD GPUs. The open-source KNOD project allows leveraging GPUs to handle packet processing in a very performant and energy efficient manner without needing any specialized hardware. KNOD has continued and a development update was shared this week at the Linux Plumbers Conference in Prague...

- Inside the Windows I/O Manager: deep dive into how read I/O requests are initialized
In this article. I am going to explain the different steps the I/O manager follows when initializing an I/O operation starting from determining the right target, choosing the right path and finally sending the request to be processed by the right drivers. To make it easier I choose to focus on read requests only since the major steps are common by all types of requests. ↫ Win-Ware A very in-depth look at Windows I/O Manager.
- A minimal kernel in Swift, running in QEMU
At OSNews, we love us a hobby operating system project. I started a small experiment: writing a very basic kernel in Swift, and running on QEMU. The goal is obviously not to replace Linux or any other popular kernel, but just to have fun and understand what is required to make a program run without an operating system underneath it. Actually I made a similar experiment years before with arOS 10 years ago. For the moment, the kernel does only one thing: it prints a message through QEMU and then waits forever, which is enough for a first deep dive. ↫ Carette Antonin This is effectively a hello world! kernel, as it doesnt actually do much else at this point. Still, theres a ton of details in the article for the aspiring kernel developers among you.
- Microsoft is overhauling and redesigning search in Windows, and it seems nice?
Whenever Microsoft starts messing with something like the search function in Windows, a lot of people are going to be holding their breath and expecting the worst. Well, get ready, because theyre redesigning the whole thing. In July, we shared how we are improving the Windows Search Box with less clutter and more control. We introduced a calmer home screen, removed promotional content from web results, and gave you more choice over whether web and Microsoft Store suggestions appear. Today, we’re carrying those investments forward with a new Windows Search experience built on WinUI 3. This modern foundation makes Windows Search faster and more efficient with resources, while delivering an even more streamlined and focused design. ↫ Anshul Rawat at the Windows Blogs The company claims this new version of search is faster and uses less memory, which, if true, are very welcome improvements. Its also just a single column of results now, and theyre adding inline previews for things like weather and files on your machine, as well as for answers to all kinds of queries you might normally go to an online search engine for. You can now also use search to perform all kinds of tasks in Windows, like turning on dark mode, managing windows, and so on. All of this can be done using relatively natural language, and Microsoft claims theyve implemented better detection of typing errors and synonyms, which is quite welcome. Weirdly enough, though, its not yet integrated into the Start menu, since its a preview just for testers, but thats something theyre working on for future releases. Judging by the videos and screenshots, Im actually kind of positively surprised. This looks quite decent and nice, and if the promised performance improvements actually materialise, this may actually be an upgrade to search worth looking forward to. Of course, this is still Microsoft, so its just as likely theyll screw up somewhere between now and when this goes live to regular users. Still, I think it looks decent.
- Chimera Linux: creating distribution build tooling for a small community
Chimera Linux is a relatively new Linux distribution, and quite a unique on at that, as it combines the core tools from FreeBSD, the LLVM toolchain, and the Musl C library instead of the usual suspects. Despite being relatively new, it still has some serious pedigree as the project was started by Nina q66!, who was part of the Void Linux team. At Void, she maintained the various PowerPC/POWER ports of the distribution until Chimera became her sole focus. Nina published a detailed blog post today about how the Chimera team builds the tooling for their distribution, as well as the goals its trying to achieve. It covers everything from a bit of personal history, the rationale behind the project, who its catering to, how its tooling works and why, and the infrastructure theyve built that underpins it all. Theres a lot to process here, with one of the most interesting little details at least to me, as someone who has two POWER9 machines the fact that Chimera started with the ppc64le target only. The article is an incredibly interesting look at not just the how of Chimera, but also the why, which makes for some really fascinating reading.
- KDE developer takes a look at COSMIC
KDE contributor and developer Niccolò Venerandi has published an article about COSMIC, System76s brand new desktop environment. Its been almost a year since Ive last tried COSMIC; though development since then has mostly been centered around stability (going from late alpha to stable releases now!) there have been a fair bit of user-facing changes too which I adore. I thus have to ask myself: should I switch to COSMIC? The answer obviously is no, but thats just because I got addicted to KDE Plasma, so lets try to be more objective here. ↫ Niccolò Venerandi Honestly, this is one of the best reviews! Ive seen of COSMIC, and paints System76s hard work in a really positive light. Venerandi spots countless really nice touches hed love to see adopted by KDE, while also hitting on what I agree is COSMICs biggest shortcoming at this point: theres basically no ecosystem around it. COSMIC uses its own Rust-based toolkit instead of GTK or Qt, but of course, theres very few other applications that actually use said toolkit. The end result is that if you run COSMIC, youre going to have to supplement it with countless GTK and Qt application, none of which will inherit all the nice features, touches, and graphics from COSMIC. This isnt really a complaint about COSMIC itself or the work its developers are putting into it, but more a fact of life for such a new desktop environment using an otherwise unpopular (as of right now) toolkit. This may very well change in the future, but for now, if you choose to run COSMIC, youre going to have to accept a very inconsistent and messy desktop. This wont matter to everyone, but it sure does matter to me, and its the one reason why at this point I have zero interest in running COSMIC. I really hope this changes in the future competition is good but its going to be a long road.
- Microsoft claims its optimising Windows for 8GB of RAM
Speaking of Windows and performance, how about that RAM crisis? Microsoft is feeling the squeeze too, and is apparently doing work up and down the Windows stack to improve its memory consumption. Microsoft’s Windows chief Pavan Davuluri has admitted that the rising cost of memory is pushing the company to make Windows 11 use less RAM. Microsoft is working on the Windows memory manager, memory compression, WinUI 3 and WebView2, and has made “memory optimization for 8GB and above” an official priority for the rest of 2026. ↫ Abhijith M B at Windows Latest This might be the only positive consequence of the RAM crisis.
- Windows legacy 8.3 filename support actually negatively affects performance
To this day, Windows retains full support for the old MS-DOS 8.3 filename limitation, and it does this by creating 8.3 aliases for files with longer names. Apparently, this has a measurable effect on performance, so naturally, people are going to turn it off to make their Windows installations perform better. According to the user, this resulted in noticeably smoother scrolling in Tile view. They subsequently repeated the process on several folders they regularly use and reported that searching through files became much faster. The user also claimed that external hard drives became faster and that browsing an Android directory over USB or FTP behaved more like a regular Windows folder, including when copying large numbers of music files. ↫ Sayan Sen at Neowin You can disable this legacy feature in Windows per volume or globally, but Microsoft is warning users not to do so. Even in 2026, applications and registry entries may depend on 8.3 filenames being available, so removing them can lead to unexpected outcomes. Its just one of those things you wouldnt expect to still be around or have a measurable impact in the days of fast SSDs, but theres enough credibly evidence out there to suggest that yes, it actually does negatively affect performance. If youre doing a lot of file operations in Windows, it might be worthwhile to do some testing of your own to see if you can speed things up. Or, you know, you can just not use a house of cards disguised as a serious operating system.
- Apple changes Full Disk Access permission in macOS
Apples macOS has a Full Disk Access permission, designed to allow backup applications full access to, well, the disk, so they can perform their job properly. Apple posted a notice on its website that its going to further restrict this permission, because some applications were abusing this permission to gain access to users messages, emails, and so on, which it obviously isnt intended for. What kind of applications, you may ask? Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy. ↫ Announcement from Apple This was prompted by a story a few weeks ago, where Facebooks Muse AI! tool was apparently reading peoples private messages and other data, and even sent messages on users behalf, without informing its users. Its incredibly naive to think Facebook software in 2026 would not do creepy things, so Im honestly not at all surprised. It makes sense in Apples worldview to further restrict permissions in response, but Im sure more experienced macOS users are not going to like this.
- Klassik brings KDE3s look and feel to KDE Plasma 6
The KDE project recently brought back its classic Oxygen and Air themes, but what if you prefer something0 A little older? A modern recreation of the classic KDE 3 desktop experience for KDE Plasma 6, built entirely using Qt 6 and Qt Quick, with full support for Wayland and fractional scaling. ↫ Klassik GitHub page Neat.
- SquirrelOS is an operating system named after the squirrel
I like squirrels. Apparently, theres a SquirrelOS. Its a small hobby OS learning project from five years ago, developed by Immanuel Daviel A. Garcia. A simple DOS like OS made in Assembly and C with a ported version of Stephen Brennans Shell. ↫ SquirrelOS GitHub page Why do I like squirrels? I dont know man, theyre just cute.

- EU OS: A Bold Step Toward Digital Sovereignty for Europe
Image A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem. What Is EU OS? EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.
Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments. The Vision Behind EU OS The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.
Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.
However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty. Conclusion EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.
Source: It's FOSS European Union
- Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight
Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight
Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.
In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.
On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.
Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.
The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.
Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.
You can download the latest kernel here. Linus Torvalds kernel
- AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
Image AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.
This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.
Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.
Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.
Source: 9to5Linux AerynOS
- Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
Image Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.
Here’s a quick overview of what’s new in Xojo 2025r1: 1. Linux ARM IDE Support Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started. 2. Web Drag and Drop One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required! 3. Direct App Store Publishing Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process. 4. New Desktop and Mobile Features This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection. 5. Performance and IDE Enhancements Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced. What Does This Mean for Developers? Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution. How to Get Started Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.
Download Xojo 2025r1 today at xojo.com. Final Thoughts With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you. Xojo ARM
- New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux
Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.
Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.
Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest.
Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.
Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.
Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.
By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem. Windows
- Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities
The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally.
As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.
In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions.
After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.
The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.
At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.
The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca. Security
- Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges
The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.
A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.
This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem.
The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.
On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.
In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers. kernel
- Linux Celebrates 32 Years with the Release of 6.6-rc2 Version
Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.
The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.
Here is what Linus Torvalds had to say in today's announcement: Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds
- Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction
Want to interact with ChatGPT from your Linux desktop without using a web browser?
Bavarder, a new app, allows you to do just that.
Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.
With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.
During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.
At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.
As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!
Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring. ChatGPT AI
- LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite
Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.
Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.
LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.
You can download LibreOffice 7.5.3 directly from the LibreOffice website or from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.
All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.
In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.
Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.
The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners. LibreOffice

- Advanced Video Coding Still Under Patent
Brazilian patent BRPI0109962B1 has expired, which means that DivX and Xvid are no longer problematic for Linux, but it doesn’t mean that video is all of a sudden fully unleashed.
|