Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All/All+Images) (Single Column)

LinuxSecurity - Security Advisories






  • Debian: vlc Critical Denial of Service and Code Execution DSA-6082-1
    Multiple vulnerabilities were discovered in the VLC media player, which could result in denial of service or potentially the execution of arbitrary code if a malformed video file is opened. For the oldstable distribution (bookworm), this problem has been fixed in version 3.0.22-0+deb12u1.


LWN.net

  • Announcing Vojtux: a Fedora-based accessible Linux distribution
    Vojtěch Polášek has announcedan unofficial effort to create a Fedora-based distribution designedfor visually impaired users:

    My ultimate vision for this project is "NO VOJTUX NEEDED!" becauseI believe Fedora should eventually be fully accessible out of thebox. We aren't there yet, which is where Vojtux comes in to fill thegap. [...]

    Key Features:
    -Speaks out of the box: When the live desktop is ready, Orca startsautomatically. After installation, it is configured so that it startson the login screen and also after logging in.
    -Batteries included: Comes with LIOS , Ocrdesktop, Tesseract,Audacity, and command-line tools like Git and Curl. There are alsomany preconfigured keyboard shortcuts.

    See the repositoryfor instructions on getting the image.



  • [$] Better development tools for the kernel
    Despite depending heavily on tools, the kernel project often seems tounder-invest in the development of those tools. There has been progress inthat area, though. At the 2025 Maintainers Summit, Konstantin Ryabitsev,who is (among other things) the author of b4, led a session on waysin which the kernel's tools could be improved to make the developmentprocess more efficient and accessible.


  • Security updates for Monday
    Security updates have been issued by AlmaLinux (firefox, grafana, kernel, libsoup3, mysql8.4, and wireshark), Debian (ruby-git, ruby-sidekiq, thunderbird, and vlc), Fedora (apptainer, chromium, firefox, golangci-lint, libpng, and xkbcomp), Mageia (golang), SUSE (binutils, chromium, firefox, gegl, go1.25, govulncheck-vulndb, hauler, kernel, keylime, libpng12, pgadmin4, postgresql16, python, python-Django, python-django, python3, python311, rhino, thunderbird, unbound, and xkbcomp), and Ubuntu (usbmuxd).



  • Kernel prepatch 6.19-rc1
    Linus has released 6.19-rc1, perhaps a bitearlier than expected.
    So it's Sunday afternoon in the part of the world where I am now, so if somebody was looking at trying to limbo under the merge window timing with one last pull request and is taken by surprise by the slightly unusual timing of the rc1 release, that failed.
    Teaching moment, or random capricious acts? You be the judge.


  • Conill: Rethinking sudo with object capabilities
    Ariadne Conill isexploring a capability-based approach to privilege escalation on Linuxsystems.
    Inspired by the object-capability model, I've been working on a project named capsudo. Instead of treating privilege escalation as a temporary change of identity, capsudo reframes it as a mediated interaction with a service called capsudod that holds specific authority, which may range from full root privileges to a narrowly scoped set of capabilities depending on how it is deployed.


  • [$] The state of the kernel Rust experiment
    The ability to write kernel code in Rust was explicitly added as anexperiment — if things did not go well, Rust would be removed again. Atthe 2025 Maintainers Summit, a session was held to evaluate the state ofthat experiment, and to decide whether the time had come to declare theresult to be a success. The (arguably unsurprising) conclusion was thatthe experiment is indeed a success, but there were some interesting pointsmade along the way.


  • Three new stable kernels
    Greg Kroah-Hartman has released the 6.18.1, 6.17.12, and 6.12.62 stablekernels. Each contains important fixes; users of those kernelsare advised to upgrade.


  • [$] Best practices for linux-next
    One of the key components in the kernel's development process is thelinux-next repository. Every day, a large number of branches, eachcontaining commits intended for the next kernel development cycle, ispulled into linux-next and integrated. If there are conflicts betweenbranches, the linux-next process will reveal them. In theory, many othertypes of problems can be found as well. Some developers feel thatlinux-next does not work as well as it could, though. At the 2025Maintainers Summit, Mark Brown, who helps to keep linux-next going, led asession on how it could be made to work more effectively.


  • KDE Gear 25.12 released
    KDE has announced therelease of KDE Gear 25.12. This release adds more"extractors" to the Itinerary travel-assistantapplication, improved Git support in the Kate text editor, better PDFexport in Konqueror, andmuch more. See the changelogfor all new features, improvements, and bug fixes.




LXer Linux News




  • 9to5Linux Weekly Roundup: December 14th, 2025
    The 270th installment of the 9to5Linux Weekly Roundup is here for the week ending on December 14th, 2025, keeping you updated with the most important things happening in the Linux world.








Linux Insider"LinuxInsider"












Slashdot

  • US Tech Force Aims To Recruit 1,000 Technologists
    The Trump administration announced Monday the United States Tech Force, a new program to recruit around 1,000 technologists for two-year government stints starting as soon as March -- less than a year after dismantling several federal technology teams and driving thousands of tech workers out of their jobs. The program will primarily recruit early-career software engineers and data scientists, paying between $150,000 and $200,000 annually. About 20 companies have signed on to participate, including Palantir, Meta, Oracle and Elon Musk's xAI. Some engineering managers will be allowed to take leaves of absence from their private-sector employers to join the program without divesting their stock holdings. The initiative follows the March closure of 18F, General Services Administration's internal tech consultancy, and the shuttering of the Social Security Administration's Office of Transformation in February. The IRS had lost over 2,000 tech workers by June.


    Read more of this story at Slashdot.


  • Scientists Thought Parkinson's Was in Our Genes. It Might Be in the Water
    For decades, Parkinson's disease research has overwhelmingly focused on genetics -- more than half of all research dollars in the past two decades flowed toward genomic studies -- but a growing body of evidence now points to something far more mundane as a primary culprit: contaminated drinking water. A landmark study by epidemiologist Sam Goldman compared Marines stationed at Camp Lejeune in North Carolina, where trichloroethylene (TCE) had contaminated the water supply for approximately 35 years, against those at Camp Pendleton in California, which has clean water. Marines exposed to TCE at Lejeune were 70% more likely to develop Parkinson's. The latest research suggests only 10 to 15 percent of Parkinson's cases can be fully explained by genetics. Parkinson's rates in the US have doubled in the past 30 years -- a pattern inconsistent with an inherited genetic disease. The EPA moved to ban TCE in December 2024. The Trump administration moved to undo the ban in January.


    Read more of this story at Slashdot.


  • How Did the CIA Lose a Nuclear Device?
    Sixty years after a team of American and Indian climbers abandoned a plutonium-powered generator on the slopes of Nanda Devi, one of the world's most forbidding Himalayan peaks, the U.S. government still refuses to acknowledge that the mission ever happened. The device, a SNAP-19C portable generator containing plutonium isotopes including Pu-239 -- the same material used in the Nagasaki bomb -- was left behind in October 1965 when a sudden blizzard forced climbers to retreat from Camp Four, just below the summit. The mission originated from a cocktail party conversation between General Curtis LeMay and National Geographic photographer Barry Bishop, who had summited Everest in 1963. China had just detonated its first atomic bomb in October 1964, and the CIA wanted to intercept radio signals from Chinese missile tests by placing an unmanned listening station atop the Himalayas. Barry Bishop recruited elite American climbers and coordinated with Indian intelligence to haul surveillance equipment up the mountain. Captain M.S. Kohli, the Indian naval officer commanding the mission, ordered climbers to secure the equipment and descend when the blizzard struck. Jim McCarthy, the last surviving American climber, recalled warning Kohli he was making a mistake. "You can't leave plutonium by a glacier feeding into the Ganges!" he recalled. "Do you know how many people depend on the Ganges?" When teams returned in spring 1966, the entire ice ledge where the gear had been stashed was gone -- sheared off by an avalanche. Search missions in 1967 and 1968 found nothing. The device remains buried somewhere in the glaciers that feed tributaries of the Ganges River.


    Read more of this story at Slashdot.


  • Electricity Is Now Holding Back Growth Across the Global Economy
    Grid constraints that were once a hallmark of developing economies are now plaguing the world's richest nations, and new research from Bloomberg Economics finds that rising electricity system stress is directly hurting investment. The analysis examined all G20 countries and found that a one-standard-deviation increase in grid stress relative to a country's historical average lowers the investment share of GDP by around 0.33 percentage points -- a 1.5% to 2% hit to capital outlays. The Netherlands is a case in point: 12,000 businesses are waiting for grid connections, congestion issues are expected to persist for a decade despite $9.4 billion in annual investments, and the country is already consuming as much electricity as was projected for 2030. ASML, the chip equipment maker whose fortunes can sway the Dutch economy, has no guarantee it will secure power for a new campus planned to employ 20,000 people. Data centers are particularly affected. Google canceled plans near Berlin, a Frankfurt facility cannot expand until 2033, Microsoft has shifted investments from Ireland and the UK to the Nordics, and a Digital Realty Trust data center in Santa Clara that was applied for in 2019 may sit empty for years.


    Read more of this story at Slashdot.


  • LG's Software Update Forces Microsoft Copilot Onto Smart TVs
    LG smart TV owners discovered over the weekend that a recent webOS software update had quietly installed Microsoft Copilot on their devices, and the app cannot be uninstalled. Affected users report the feature appears automatically after installing the latest webOS update on certain models, sitting alongside streaming apps like Netflix and YouTube. LG's support documentation confirms that certain preinstalled or system apps can only be hidden, not deleted. At CES 2025, LG announced plans to integrate Copilot into webOS as part of its "AI TV" strategy, describing it as an extension of its AI Search experience. The current implementation appears to function as a shortcut to a web-based Copilot interface rather than a native application. Samsung TVs include Google's Gemini in a similar fashion. Users wanting to avoid the feature entirely are left with one option: disconnecting their TV from the internet.


    Read more of this story at Slashdot.


  • Security Researcher Found Critical Kindle Vulnerabilities That Allowed Hijacking Amazon Accounts
    The Black Hat Europe hacker conference in London included a session titled "Don't Judge an Audiobook by Its Cover" about a two critical (and now fixed) flaws in Amazon's Kindle. The Times reports both flaws were discovered by engineering analyst Valentino Ricotta (from the cybersecurity research division of Thales), who was awarded a "bug bounty" of $20,000 (£15,000 ).He said: "What especially struck me with this device, that's been sitting on my bedside table for years, is that it's connected to the internet. It's constantly running because the battery lasts a long time and it has access to my Amazon account. It can even pay for books from the store with my credit card in a single click. Once an attacker gets a foothold inside a Kindle, it could access personal data, your credit card information, pivot to your local network or even to other devices that are registered with your Amazon account." Ricotta discovered flaws in the Kindle software that scans and extracts information from audiobooks... He also identified a vulnerability in the onscreen keyboard. Through both of these, he tricked the Kindle into loading malicious code, which enabled him to take the user's Amazon session cookies — tokens that give access to the account. Ricotta said that people could be exposed to this type of hack if they "side-load" books on to the Kindle through non-Amazon stores. Ricotta donated his bug bounties to charity...


    Read more of this story at Slashdot.


  • Are Warnings of Superintelligence 'Inevitability' Masking a Grab for Power?
    Superintelligence has become "a quasi-political forecast" with "very little to do with any scientific consensus, emerging instead from particular corridors of power." That's the warning from James O'Sullivan, a lecturer in digital humanities from University College Cork. In a refreshing 5,600-word essay in Noema magazine, he notes the suspicious coincidence that "The loudest prophets of superintelligence are those building the very systems they warn against..." "When we accept that AGI is inevitable, we stop asking whether it should be built, and in the furor, we miss that we seem to have conceded that a small group of technologists should determine our future." (For example, OpenAI CEO Sam Altman "seems determined to position OpenAI as humanity's champion, bearing the terrible burden of creating God-like intelligence so that it might be restrained.")The superintelligence discourse functions as a sophisticated apparatus of power, transforming immediate questions about corporate accountability, worker displacement, algorithmic bias and democratic governance into abstract philosophical puzzles about consciousness and control...Media amplification plays a crucial role in this process, as every incremental improvement in large language models gets framed as a step towards AGI. ChatGPT writes poetry; surely consciousness is imminent..." Such accounts, often sourced from the very companies building these systems, create a sense of momentum that becomes self-fulfilling. Investors invest because AGI seems near, researchers join companies because that's where the future is being built and governments defer regulation because they don't want to handicap their domestic champions... We must recognize this process as political, not technical. The inevitability of superintelligence is manufactured through specific choices about funding, attention and legitimacy, and different choices would produce different futures. The fundamental question isn't whether AGI is coming, but who benefits from making us believe it is... We do not yet understand what kind of systems we are building, or what mix of breakthroughs and failures they will produce, and that uncertainty makes it reckless to funnel public money and attention into a single speculative trajectory. Some key points:"The machines are coming for us, or so we're told. Not today, but soon enough that we must seemingly reorganize civilization around their arrival...""When we debate whether a future artificial general intelligence might eliminate humanity, we're not discussing the Amazon warehouse worker whose movements are dictated by algorithmic surveillance or the Palestinian whose neighborhood is targeted by automated weapons systems. These present realities dissolve into background noise against the rhetoric of existential risk...""Seen clearly, the prophecy of superintelligence is less a warning about machines than a strategy for power, and that strategy needs to be recognized for what it is... ""Superintelligence discourse isn't spreading because experts broadly agree it is our most urgent problem; it spreads because a well-resourced movement has given it money and access to power...""Academic institutions, which are meant to resist such logics, have been conscripted into this manufacture of inevitability... reinforcing industry narratives, producing papers on AGI timelines and alignment strategies, lending scholarly authority to speculative fiction...""The prophecy becomes self-fulfilling through material concentration — as resources flow towards AGI development, alternative approaches to AI starve..."The dominance of superintelligence narratives obscures the fact that many other ways of doing AI exist, grounded in present social needs rather than hypothetical machine gods. [He lists data sovereignty movements "that treat data as a collective resource subject to collective consent," as well as organizations like Canada's First Nations Information Governance Centre and New Zealand's's Te Mana Raraunga, plus "Global South initiatives that use modest, locally governed AI systems to support healthcare, agriculture or education under tight resource constraints."] "Such examples... demonstrate how AI can be organized without defaulting to the superintelligence paradigm that demands everyone else be sacrificed because a few tech bros can see the greater good that everyone else has missed...""These alternatives also illuminate the democratic deficit at the heart of the superintelligence narrative. Treating AI at once as an arcane technical problem that ordinary people cannot understand and as an unquestionable engine of social progress allows authority to consolidate in the hands of those who own and build the systems..."He's ultimately warning us about "politics masked as predictions..." "The real political question is not whether some artificial superintelligence will emerge, but who gets to decide what kinds of intelligence we build and sustain. And the answer cannot be left to the corporate prophets of artificial transcendence because the future of AI is a political field — it should be open to contestation. "It belongs not to those who warn most loudly of gods or monsters, but to publics that should have the moral right to democratically govern the technologies that shape their lives."


    Read more of this story at Slashdot.


  • SpaceX Alleges a Chinese-Deployed Satellite Risked Colliding with Starlink
    "A SpaceX executive says a satellite deployed from a Chinese rocket risked colliding with a Starlink satellite," reports PC Magazine:On Friday, company VP for Starlink engineering, Michael Nicolls, tweeted about the incident and blamed a lack of coordination from the Chinese launch provider CAS Space. "When satellite operators do not share ephemeris for their satellites, dangerously close approaches can occur in space," he wrote, referring to the publication of predicted orbital positions for such satellites... [I]t looks like one of the satellites veered relatively close to a Starlink sat that's been in service for over two years. "As far as we know, no coordination or deconfliction with existing satellites operating in space was performed, resulting in a 200 meter (656 feet) close approach between one of the deployed satellites and STARLINK-6079 (56120) at 560 km altitude," Nicolls wrote... "Most of the risk of operating in space comes from the lack of coordination between satellite operators — this needs to change," he added. Chinese launch provider CAS Space told PCMag that "As a launch service provider, our responsibility ends once the satellites are deployed, meaning we do not have control over the satellites' maneuvers." And the article also cites astronomer/satellite tracking expert Jonathan McDowell, who had tweeted that CAS Space's response "seems reasonable." (In an email to PC Magazine, he'd said "Two days after launch is beyond the window usually used for predicting launch related risks." But "The coordination that Nicolls cited is becoming more and more important," notes Space.com, since "Earth orbit is getting more and more crowded."In 2020, for example, fewer than 3,400 functional satellites were whizzing around our planet. Just five years later, that number has soared to about 13,000, and more spacecraft are going up all the time. Most of them belong to SpaceX. The company currently operates nearly 9,300 Starlink satellites, more than 3,000 of which have launched this year alone. Starlink satellites avoid potential collisions autonomously, maneuvering themselves away from conjunctions predicted by available tracking data. And this sort of evasive action is quite common: Starlink spacecraft performed about 145,000 avoidance maneuvers in the first six months of 2025, which works out to around four maneuvers per satellite per month. That's an impressive record. But many other spacecraft aren't quite so capable, and even Starlink satellites can be blindsided by spacecraft whose operators don't share their trajectory data, as Nicolls noted. And even a single collision — between two satellites, or involving pieces of space junk, which are plentiful in Earth orbit as well — could spawn a huge cloud of debris, which could cause further collisions. Indeed, the nightmare scenario, known as the Kessler syndrome, is a debris cascade that makes it difficult or impossible to operate satellites in parts of the final frontier.


    Read more of this story at Slashdot.


  • Roomba Maker 'iRobot' Files for Bankruptcy After 35 Years
    Roomba manufacturer iRobot filed for bankruptcy today, reports Bloomberg. After 35 years, iRobot reached a "restructuring support agrement that will hand control of the consumer robot maker to Shenzhen PICEA Robotics Co, its main supplier and lender, and Santrum Hong Kong Compny."Under the restructuring, vacuum cleaner maker Shenzhen PICEA will receive the entire equity stake in the reorganised company... The plan will allow the debtor to remain as a going concern and continue to meet its commitments to employees and make timely payments in full to vendors and other creditors for amounts owed throughout the court-supervised process, according to an iRobot statement... he company warned of potential bankruptcy in December after years of declining earnings. Roomba says it's sold over 50 million robots, the article points out, but earnings "began to decline since 2021 due to supply chain headwinds and increased competition. "A hoped-for by acquisition by Amazon.com in 2023 collapsed over regulatory concerns."


    Read more of this story at Slashdot.


  • Like Australia, Denmark Plans to Severely Restrict Social Media Use for Teenagers
    "As Australia began enforcing a world-first social media ban for children under 16 years old this week, Denmark is planning to follow its lead," reports the Associated Press, "and severely restrict social media access for young people."The Danish government announced last month that it had secured an agreement by three governing coalition and two opposition parties in parliament to ban access to social media for anyone under the age of 15. Such a measure would be the most sweeping step yet by a European Union nation to limit use of social media among teens and children. The Danish government's plans could become law as soon as mid-2026. The proposed measure would give some parents the right to let their children access social media from age 13, local media reported, but the ministry has not yet fully shared the plans... [A] new "digital evidence" app, announced by the Digital Affairs Ministry last month and expected to launch next spring, will likely form the backbone of the Danish plans. The app will display an age certificate to ensure users comply with social media age limits, the ministry said. The article also notes Malaysia "is expected to ban social media accounts for people under the age of 16 starting at the beginning of next year, and Norway is also taking steps to restrict social media access for children and teens. "China — which manufacturers many of the world's digital devices — has set limits on online gaming time and smartphone time for kids."


    Read more of this story at Slashdot.


The Register

  • Apple blocks dev from all accounts after he tries to redeem bad gift card
    Paris Buttfield-Addison literally wrote books on Swift
    Apple has blocked a long-time developer from his Apple ID after he failed to redeem what support suggested was a dodgy $500 gift card, leaving him unable to work, cut off from personal files, and barred from what he calls his "core digital identity." …




  • Hyperscalers fuel $112B server spending spree in Q3
    IDC's latest tracker numbers were brought to you by the letters A and I
    The global server market went into overdrive in the third quarter of 2025, racking up a record $112.4 billion in revenue as AI demand pushed vendor sales up 61 percent year-on-year, according to the latest figures from IDC.…



  • Roomba maker iRobot gets cleaned out in Chapter 11
    Company vacuumed up by its own manufacturer
    iRobot, the company behind autonomous vacuum cleaner brand Roomba, has filed for Chapter 11 bankruptcy protection, telling investors that its Chinese manufacturer will assume control going forward.…


  • Delay to European Central Bank messaging project cost the Bank of England £23M
    Watchdog links schedule change to replanning of UK payments system overhaul
    The European Central Bank's (ECB) decision to delay its move to a new messaging standard in 2022 ended up costing the Bank of England £23 million as it was forced to adjust migration to a new settlement system to avoid compounding risks.…


  • JLR: Payroll data stolen in cybercrime that shook UK economy
    Automaker admits raid that crippled its factories in August led to the theft of sensitive info
    Jaguar Land Rover (JLR) has reportedly told staff the cyber raid that crippled its operations in August didn't just bring production to a screeching halt – it also walked off with the personal payroll data of thousands of employees.…


  • Apple, Google forced to issue emergency 0-day patches
    Both admit attackers were already exploiting the bugs, with scant detail and hints of spyware-grade abuse
    Apple and Google have both issued emergency patches after zero-day bugs were caught being actively exploited in what the companies describe as "sophisticated" real-world attacks.…


  • Denmark takes a Viking swing at VPN-enabled piracy
    Minister insists 'modest' bill is not an assault on privacy-preserving tech
    The Danish government wants the public to weigh in on its proposed laws restricting use of VPNs to access certain corners of the internet.…



Linux.com









  • Xen 4.19 is released
    Xen Project 4.19 has been officially out since July 31st, 2024, and it brings significant updates. With enhancements in performance, security, and versatility across various architectures like Arm, PPC, RISC-V, and x86, this release is an important milestone for the Xen community. Read more at XCP-ng Blog

    The post Xen 4.19 is released appeared first on Linux.com.


  • Advancing Xen on RISC-V: key updates
    At Vates, we are heavily invested in the advancement of Xen and the RISC-V architecture. RISC-V, a rapidly emerging open-source hardware architecture, is gaining traction due to its flexibility, scalability and openness, which align perfectly with our ethos of fostering open development ecosystems. Although the upstream version of Xen for RISC-V is not yet fully [0]

    The post Advancing Xen on RISC-V: key updates appeared first on Linux.com.


Phoronix


  • AmpereOne M Finally Appears - In The Oracle Cloud With A4
    Back in July 2024, Ampere Computing announced AmpereOne M on their road-map for Q4'2024 to provide AmpereOne with 12 channel DDR5 memory compared to eight memory channels with the original AmpereOne processors. Then this past May the AmpereOne M SKUs were announced while Ampere Computing stated these "M" processors had been shipping since Q4 of last year. Since then we haven't seen or heard anything more about AmpereOne M nor the AmpereOne MX processors with up to 256 cores. Since then, the acquisition of Ampere Computing by SoftBank also was completed that made us wonder more about impacts to the roadmap and what hardware may or may not make it out to market. Well, today, we are finally seeing AmpereOne M availability in the public cloud with the new Oracle Cloud A4 instances...




  • Igalia's Work Improving The Linux Kernel For Helping Steam Play Gaming On ARM64
    Besides Valve funding FEX-Emu for x86_64 binaries to run on AArch64 Linux as part of their Steam Play (Proton) efforts in being able to get Windows x86/x64 games running on AArch64 SteamOS for the Snapdragon-powered Steam Frame, there is also work happening in kernel-space to help this emulated gaming experience on AArch64...




  • The Opt-In Proactive & Crash Time Data Collection On Valve9s Steam Deck
    Valve's Steam Deck with SteamOS features built-in crash data collection as well as for logging other system events worth having knowledge about like the split-lock detection and other events. This is all opt-in by users for data collection by Steam, but for those curious about a bit more insight into this Steam Deck data collection, a presentation at this past week's Linux Plumbers Conference dove into the matter...





Engadget"Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics"

  • In 2025, tech giants decided smart glasses are the next big thing
    There9s a growing sentiment that gadgets have gotten boring. And while I don9t fully agree, I understand why people might feel that way. Just think about some of the novel device types that companies have tried to push since the original iPhone came out. 

    3D TVs were a massive flop and tablets still feel like extra-large smartphones despite Apple9s efforts to prop them up as laptop replacements. Meanwhile, even with huge technological advancements over the last decade, VR headsets remain relatively niche due to factors like high prices and a lack of compelling content. And although big names like Google, Microsoft, Meta and others continue to dump billions into AI development, the first wave of dedicated AI devices was an abject failure

    When you think about it, the only new(ish) class of gadget that has made major inroads to the mainstream market is smartwatches. That said, because they9ve evolved into wearable health and fitness sensors instead of the wrist-based computers that many once thought they would be, they haven9t really disrupted our lives like the personal computer and smartphone did. But that seems poised to change because the tech giants have decided that smart glasses are going to be the next big thing. 
    Headsets versus smart glasses, what’s the difference?Google is planning to support both smart glasses and headsets with Android XR, though the increased size and weight of devices like the Galaxy XR means it9s not a great choice for all-day functionality. Sam Rutherford for Engadget
    At this point, you might be saying, "Wait, hold on. Aren9t VR headsets and smart glasses kind of the same thing?" Well, yes and no. Both types of gadgets require similar software and hardware, but they utilize them in very different ways. Not only are VR goggles typically much bigger and heavier, they also provide a more isolated experience that can make it feel like you9ve been transported to another world. 

    Sure, most modern headsets have exterior cameras that support some level of mixed reality (blending virtual graphics with physical objects) or let you peek quickly into meatspace (passthrough view) for when you need to get a drink or acknowledge other humans in the room. But in many respects, that closed-off feeling is the goal because it creates the ideal environment for playing games, taking virtual meetings or modeling 3D objects without real-world distractions. Furthermore, while many headsets like the Vision Pro and the Meta Quest 3 can function as standalone systems and support accessories like controllers or other motion trackers, they can also be tethered to a nearby PC for enhanced functionality.  

    On the other hand, the default use case for smart glasses is a mixed reality environment where the spectacles can overlay helpful info or messages while you stay active and aware of your surroundings. Notably, while smart glasses might come with lenses or clip-on attachments that allow them to get darker or serve as sunglasses when you9re outside, there typically isn9t a way to completely block out the world like you can with a headset, mostly because that9s simply not the point. And even though most smart spectacles can be paired with a phone to get access to mobile data or notifications, they9re generally not meant to be tethered to a PC full-time (though there are some exceptions). The goal for smart glasses is more to provide a mobile-first heads-up display that augments what you see with your eyes instead of replacing things entirely with a digital environment. 
    OK, but what makes you so sure that smart glasses are "it?"
    Now that we9ve discussed what separates smart glasses from headsets, what makes it so obvious that they are going to be the next big thing? This one is a bit easier to answer because we can simply look at the sheer number of companies that have released smart glasses or are planning to do so in the future. If we skip past the Google Glass from 2013 as forward-thinking specs that were ahead of their time, the most well-known example of modern smart glasses is the Meta Ray-Ban (or the even earlier Ray-Ban Stories from back when Facebook was still Facebook). 
    While they are a bit chunky, the Meta Ray-Ban Display are some of the most sophisticated smart glasses on the market right now due in large part to their single full-color screen. Karissa Bell for Engadget
    Even though they don9t have built-in displays, the ability to capture photos and videos and play audio via built-in speakers brought the idea of smart glasses into the mainstream without making the concept look or feel completely ridiculous. Those earlier models then paved the way for even more sophisticated iterations like the Meta Ray-Ban Display from earlier this fall, which features a stunning RGB HUD (though only in the right lens) that has gotten us tantalizingly close to a true wearable display that doesn9t make you look like a cyborg. Of course, Meta isn9t the only game in town: there9s a rapidly growing number of competitors from companies like Even Realities, Rokkid, TCL, Xreal, Viture and more. 

    But for an even clearer sign of where the tech giants are heading, we can just look at Meta9s two biggest competitors: Apple and Google. While Apple hasn9t publicly announced plans to make its own smart glasses, Bloomberg9s Mark Gurman — who is one of the company9s most reliable analysts — provided inside info earlier this fall that Tim Cook and Co. are planning to pivot away from a proper follow-up to the Vision Pro in favor of more lightweight spectacles with greater mass appeal.

    This shouldn9t really come as a major surprise, as sales of Apple9s $3,500 headset have been lackluster. But more importantly, for a company that9s extremely cautious about entering new product categories (foldable iPhone anyone?), it feels very telling to hear that Apple is shifting to smart glasses instead of abandoning the idea of wearable displays entirely. This is a company that doesn9t swing and miss very often, so the idea of two flops in a row seems preposterous. If this pivot is real, there must be some Apple execs who are big believers that glasses and not goggles are the right choice for future development. 
    Here are two of Google9s reference design smart glasses. The one in the front features dual RGB waveguide displays while the one in the back relies on a single monocular screen.Sam Rutherford for Engadget
    Meanwhile, Google is taking a two-pronged approach. In addition to releasing a new mixed reality OS — Android XR — on Samsung9s Galaxy XR headset in October, the company has also teased upcoming smart glasses along with a handful of partners including glasses makers Gentle Monster and Warby Parker.  Just this week, the company also added a number of new features to Android XR designed to support a wide range of upcoming devices while simultaneously making it easier for developers to port existing apps over to smart glasses and headsets. And if you still need additional evidence regarding Google9s desire to get into smart glasses, consider that even with its ongoing collaboration, the company also spent $100 million to acquire a 4 percent stake in Gentle Monster

    Regardless of who is making them though, the big draw for these companies is the idea that smart glasses will become a new piece of core personal computing, similar to how people rely on smartphones and laptops today (or to a lesser extent wireless headphones and smartwatches). If true, that could become a trillion-dollar market in the next 10 to 15 years (or sooner, who knows), which not only makes it a natural avenue for expansion but possibly a future existential crisis for certain companies. After all, none of these organizations want to be the next Microsoft after it failed to develop a successful smartphone or mobile OS.
    Fine, the smart glasses trend is real, but why would we even want them?
    At this point, I hope it9s clear that the push for smart glasses is very real and very serious. But so far, we9ve only addressed why companies are betting big on them. So what9s in it for us, the people who might actually buy and use them? Well, to answer that, we need to separate the current models into three main categories.
    A great use case for smart glasses would be to provide heads-up mapping without the need to constantly look down at your phone as seen in this demo clip of Android XR. Google
    First, there are the most basic smart glasses that don9t come with built-in displays and typically rely on cameras and built-in speakers for enhanced functionality. The best example of this class of devices is the Meta Ray-Ban smart glasses (or the original Ray-Ban Stories) along with rivals like the Bose Sound Frames, which, believe it or not, have been on the market since 2019.

    However, before anyone gets attached to these early models, the simplest smart glasses already kind of feel like dinosaurs and will probably, in the not-too-distant future, go extinct. They were an interesting attempt to add things like music playback or photo and video capture to regular-looking sunglasses, but their limited feature set puts a clear ceiling on what they can do. Plus, if this is what people really wanted, they would have taken off already. 
    Waveguides like the ones built into the Even Realities G2 project images directly onto their lenses allowing for super sleek glasses featuring a heads-up display. Sam Rutherford for Engadget
    This brings us to more recent offerings like the Meta Ray-Ban Display, Even Realities G2, the Halliday glasses and others which add some type of built-in display to the mix. Most often, these models rely on waveguide displays as they enable thinner and lighter designs while propagating images onto the glasses9 lenses. Currently, most of these smart glasses feature single-color optics (usually green) to reduce complexity and power draw, but there are others like the Meta Ray-Ban Display and both the TCL RayNeo X2 and X3 that support full color.

    In this day and age when everyone is surrounded by screens, the idea of yet another display mounted inches away from your eyeballs might sound like the last thing you want. However, because modern smart glasses are much more discreet and less awkward-looking, I find that they can actually help cut down on distractions. That9s because instead of having to peek down at your phone or smartwatch to check notifications, reply to messages or look up directions, you can do many or all of these things using smart glasses — all in the middle of a conversation without anyone noticing. 

    Not only does this keep your focus where it should be — on people instead of gadgets — the glasses are also just as easy to wear as a smartwatch and far more comfortable than bulky VR headsets. Then, when you consider some other features of modern smart glasses like on-the-fly translation, the ability to function as a teleprompter hidden in plain sight or additional support from AI, suddenly you have a wearable that allows you to keep all of your other devices neatly stashed away. In many respects, smart glasses could be the portable displays that people might not even know they want.
    Compared to rivals with waveguides, glasses featuring "birdbath" optics are often significantly thicker and bulkier. Sam Rutherford for Engadget
    Speaking of portable displays: If you recall, I mentioned above how most smart glasses generally don9t need to be tethered to other devices. The exception to that comes from a subclass of specs that are primarily designed to function as wearable monitors capable of supporting one or more virtual screens that can be in excess of 100 inches in size, relatively speaking. 

    The most well-known smart glasses in this category come from Xreal and Viture, with both companies offering a range of models with varying levels of performance. One interesting thing to note is instead of waveguides, some of these smart glasses rely on birdbath optics. This means instead of projecting an image into the lens itself, they use a beamsplitter and mirror to reflect images into your eye. The benefit of this is that you get good image quality from components that cost less than an equivalent waveguide setup, with the downside being increased light loss, potentially lower brightness and a much thicker design. This results in chunky frames that often look like they are sitting too far away from your face, which might not be immediately apparent if you see someone using them from afar. But up close, they don9t look quite right. Or at least they don’t look like a pair of "normal" glasses.

    Another issue is that due to more light loss, birdbath smart glasses require darker lenses (similar to sunglasses), which means they aren9t great for wearing all day in a variety of environments. And because we still don9t really have a great protocol for wireless displays (though it looks like Valve may be cooking up something with the Steam Frames), most of these  need to be connected by wire to a nearby PC. So you plug them in, put them on, get your work done and then you take them off. 
    Project Aura is Xreal9s next-gen smart glasses and they feature a large 70-degree field of view and fancy electrochromic lenses. Sam Rutherford for Engadget
    That said, for those who need a ton of screen real estate, this type of smart glasses can be a very attractive alternative to traditional portable monitors. On top of being smaller and more portable, they provide additional privacy when working in public spaces like a cafe or plane, which is what prompted a doctor friend of mine to get a pair instead of going with a portable display. And for the gamers out there, because they can be connected to a phone or even a portable PC or Switch 2 (with the proper dock, of course), they9re great for people who might not have room for or access to a big screen TV.
    So where do we go from here?
    Ultimately, I think all three types of smart glasses will merge into one as engineers perfect the tech and steal ideas from one another, though there will surely be plenty of room for more niche designs. But more importantly, if we consider the types of gadgets most people carry around today, it boils down to just a handful of devices: a smartphone, some type of wireless audio (either earbuds or headphones) and maybe a health and fitness tracker of some kind (typically a smartwatch or smart ring). 
    Even tough they didn9t have a built-in display, the Meta Ray-Ban smart glasses from 2023 raised a ton of awareness for the category.Sam Rutherford for Engadget
    Smart glasses have the potential to really round out that kit by allowing us to keep most of those devices in our pocket while the wearables serve up helpful info when we need it, but without being overly intrusive or distracting. In the short term, you9ll still need a laptop for work, but smart glasses may have a role to play there too, as they can provide way more screen space than a traditional physical display (even the new-fangled flexible ones). It might never happen, but I wouldn’t rule out a future scenario where your next employer gives you a company-issued phone and a pair of smart glasses and that9s it. 

    Before that happens though, there are still a bunch of other things that need to be figured out. Without help from a mouse or keyboard, navigating a virtual display is a bit of a challenge. AI combined with hand and eye tracking can help, but no one has really nailed that combo yet. Not even Apple could do so on the much bulkier Vision Pro. To address this, Meta created abracelet (they call it a neural band) that pairs with the Ray-Ban Display that can detect subtle movements so you can type or navigate menus practically anywhere. Even Realities opted for a ring accessory that does some basic health monitoring and comes with a tiny touchpad. In the more distant future, this hurdle may be solved by BCIs (brain-computer interfaces), but even the most optimistic view suggests that those aren9t going to be mainstream for a long time.
    Even though we9re still a long ways away, one day everyone might be able to have something like Tony Stark9s E.D.I.T.H. smart glasses from the Marvel Universe. Marvel
    The issue for Meta is that it9s pretty obvious that its wristband really ought to be incorporated into a smartwatch. The idea of a single-purpose bracelet that doesn9t track your health or do anything else sort of feels like a step backwards. And there9s the problem of Meta9s glasses being largely tied down to its own platforms (i.e. Instagram, Whatsapp and Facebook), which may end up being a major hindrance after rivals like Google and Apple catch up.

    And then there9s the cost. Right now, a pair of Meta Ray-Ban Displays (which thankfully come with the wristband) costs $800. That9s a lot for what is basically a publicly available beta test. But when you consider that an Even Realties G2 and an R2 ring costs even more at $850, it9s clear that wearing smart glasses is going to be a very expensive hobby for at least the next few years. And while more single-purpose smart glasses from Xreal and Viture are a bit more affordable, with models ranging from $400 to $550 or $600, they still aren9t cheap. On top of that, getting prescription lenses for smart glasses can often be a major pain in the ass and may not even be an option for people with more limited eyesight. 

    But those are problems for another day. And just because tech giants are pouring billions into the development of smart glasses doesn9t mean they will be a guaranteed hit. If you care about tech, alongside AI and possibly EVTOL aircraft (aka flying taxis), pay attention to the advancements in smart glasses. Otherwise, you could miss out on what might be the next major wave in sci-fi gadgetry made real.






    This article originally appeared on Engadget at https://www.engadget.com/wearables/in-2025-tech-giants-decided-smart-glasses-are-the-next-big-thing-163000812.html?src=rss


  • The 11 best gifts under $25 for 2025
    So you want to give someone a gift but you don’t have a ton of cash to spare. Don’t fret because first, you’re not alone, and second, there are tons of options to choose from. Especially if you’re looking in the tech space, it can feel especially daunting to find a gadget that’s affordable but also worth gifting — in other words, not a piece of junk that will eventually take up residence at the bottom of a drawer. But you don’t have to drain your wallet to get someone a cool gadget that will both be useful and make their lives easier. We’ve collected our favorite pieces of tech under $25 that make great gifts and help you to stick to a budget.
    Best gifts under $25






















    Check out the rest of our gift ideas here.
    This article originally appeared on Engadget at https://www.engadget.com/computing/accessories/the-11-best-gifts-under-25-for-2025-140042203.html?src=rss


  • Swallowing the Moon and other new indie games worth checking out
    Welcome to our latest roundup of what9s going on in the indie game space. Between The Game Awards and showcases like Day of the Devs, Wholesome Snack, Latin American Games and Women-Led Games, there’s been a ton of video game news over the last week (I need Blood Cultures and John Fio crafting a killer soundtrack I know I’ll be listening to for a long time to come. 

    Skate Story is out now on Nintendo Switch 2, Steam and PS5 for $20. PlayStation Plus Extra and Premium members can play it at no extra cost
    New releases
    Unbeatable is another game I’ve had on my radar for some time, though I haven’t had a chance to jump in yet. This is another stylish game in which you play as Beat, who sings in a band. However, music is outlawed in this world (oh no!). Through rhythm-based minigames and battles with cops, Beat tries to bring back the music. There9s a separate arcade mode with a dedicated progression system too.

    I9m a sucker for stories about rebellious underdogs, and this rhythm adventure could well hook me in. Unbeatable — from D-Cell Games and publisher Playstack — is available on Steam and PS5 for $28 (there’s a 10 percent discount on Steam until December 23). It9s set to hit Xbox Series X/S very soon too.

    Speaking of games I9ve been keeping an eye on, Adrift (from solo developer S.K.9.8 and co-publisher Secret Sauce) was one of the first games I covered when I started doing this weekly roundup earlier this year. It9s a driving game in which your aim is to deliver a volatile energy core. Since you9re traversing a hot desert, you9ll need to be careful to prevent the core from overheating and blowing up. Thankfully, there are safe spots and cooling stations where you can bring down the temperature.

    The vaporwave aesthetic of Adrift caught my eye and although I dig the presentation, the game isn9t quite clicking for me in the early going. It didn9t take long before my vehicle got stuck and I had to reset, and I9m finding the top-down world a little confusing to navigate. I9ll stick with it for at least a little longer, though. Adrift is out now on Steam. It usually costs $13 though there9s a 25 percent discount until December 23. 

    I9ve very happy that a game like Drywall Eating Simulator can exist. Peripheral Playbox9s satirical walking sim sees your character trying to deal with the maddening realities of daily life and the frustration that one may find in dealing with other people. Get mad enough and you9ll be able to punch through a wall (something you9ll have to do to move through the levels anyway). Then, you can munch on some drywall to calm yourself down.

    I had a good time with it and there’s some pointedly funny writing here. “I thought AI sucks but it told me that was wrong and I believed it,” says one person. That9s all well and good, but I mainly just want the NPCs to leave me alone so I can eat drywall in peace. Drywall Eating Simulator is out now on Steam. It9ll usually run you $10, but there9s a 10 percent discount until December 17.

    Planet of Lana was one of my favorite games of 2023 and now it9s available on iOS and Android for $9. It sees teenage Lana and her cute companion Mui making their way through a world that9s been taken over by alien robots as they try to rescue Lana9s sister.

    This is a puzzle platformer in the vein of Inside and Limbo, and despite the pretty and often bright presentation, it9s just as dystopian as those games. It sounds gorgeous too, thanks in large part to a beautiful score from The Last Guardian composer Takeshi Furukawa. I9m very much looking forward to the sequel from Wishfully and publisher Thunderful. That9s set to arrive next year.

    A Game About Digging A Hole is one of this year9s real indie success stories. It’s a game that a developer started making in their spare time that has sold more than 1.2 million copies since February. After landing on PC and mobile, the $5 game from Doublebee and publisher Rokaplay is now on Nintendo Switch, Xbox Series X/S and PS5. It9s on Game Pass Ultimate, Game Pass Premium and PC Game Pass.

    It9s a straightforward loop. Start digging a hole in your backyard, sell the stuff you find, upgrade your equipment and keep going. Just, uh, be careful down there. You never quite know what you9ll run into.
    Upcoming 
    Vampire Therapist developer Little Bat Games has revealed its latest project, Better Than Us, which is coming to Steam in 2026. It9s a narrative-driven sci-fi narrative game in which you9ll infiltrate swanky parties thrown by wealth hoarders in the future to steal spoils back from them. 

    Violence isn9t the solution here, as you9ll need to charm the ultra-rich, who buy elections and have "monopolized AI development to ensure machines serve their interests" (I dunno, this all seems extremely far-fetched). You can spin up a web of lies about things like how your husband died and how much Worldcoin you have. To maintain your ruse, you9ll need to keep your story straight by remembering what you said and to which characters. 

    Okomotive (Steam in January, with the full game set to arrive late in 2026.

    AudioMech is a neat-looking game that popped up for the first time during the pre-show of The Game Awards. This is a rhythm-based action title from Dylan Fitterer, the creator of Audiosurf. It taps into whatever music you have playing on your computer (even something that you9re streaming or playing through a microphone) to customize both your weapons and opponents.

    A track that9s heavy on bass might give you a longer sword, while vocals and lead instruments can power a cannon. There are several ways to play, including a mode in which you don9t take damage and a boss rush option. AudioMech is coming to Steam and there9s a demo available now. 

    Let9s wrap things up with something a little more relaxing. Lost and Found Co. is a hidden object game from Bit Egg Inc. and co-publisher Gamirror Games. During the latest Wholesome Snack showcase, it was revealed that the game is coming to Steam on February 11.

    It9s little wonder that more than 170,000 Steam users have wishlisted this game. It looks absolutely lovely. The developers sought to recapture the "magic" of childhood puzzle books in their hand-drawn world. Here, you9ll help Ducky, a duck-turned-human intern at a startup that hunts for items that townspeople have lost. There9s a demo available that features the option to decorate a part of the world using items you find.
    This article originally appeared on Engadget at https://www.engadget.com/gaming/swallowing-the-moon-and-other-new-indie-games-worth-checking-out-154937071.html?src=rss




  • New users can get half off one of our favorite budgeting apps right now
    If you have a resolution in the new year to get more acquainted with your finances, a good budgeting app can help with that. One of our favorites is a bit cheaper to sign up for right now: Monarch Money is offering 50 percent off annual subscriptions for new users. Use the code MONARCHVIP at checkout to get half off, so you9ll pay just $50 for one year of access.



    Monarch Money was the runner-up in our guide to the best budgeting apps in 2025, and it was definitely a grower. Initially we found the experience of using the app to be needlessly complicated compared to some of its rivals, but get over that hurdle and it’s impressively fully-featured. There are plenty of customization options, a helpful “goals” feature and a thorough month-in-review recap that beats out similar features from some of its competitors. We also like how you can grant account access to others.

    Besides the steep learning curve, we also noted that the mobile app is less intuitive to use than the web version, which might pose a problem if you were hoping to do most of your accounting on the go. We also had some issues with the app failing to distinguish between bills and other recurring expenses, as well as a few bugs along the way.

    All things considered, Monarch is definitely one of our favorite budgeting apps, only being beaten out by Quicken Simplifi. As you might expect, the biggest strength of Simplifi is its simplicity, and how it eases you into using its various features. If you value that kind of user experience, it might be a better choice for you, but there’s unfortunately no free trial to take advantage of.

    Follow @EngadgetDeals on X for the latest tech deals and buying advice.
    This article originally appeared on Engadget at https://www.engadget.com/deals/new-users-can-get-half-off-one-of-our-favorite-budgeting-apps-right-now-154056942.html?src=rss


  • The Meta Quest 3S is back down to its Cyber Monday all-time low of $250
    The Meta Quest 3S is back on sale at its all-time low price of $250. That9s $50 off, or a discount of 17 percent, and matches a deal we saw on Cyber Monday. You can get the deal at Amazon and Best Buy, and the latter offers a $50 gift card with purchase.

    The 3S is the more affordable model in the company9s current VR headset lineup. It features the same Snapdragon XR2 processor as the more expensive Meta Quest 3, but with lower resolution per eye and a slightly narrower field of view.



    In our hands-on review, we gave the Meta Quest 3S a score of 90, noting how impressive the tech was compared to its price. The headset was comfortable to wear during longer gaming periods, and the performance was quick and responsive thanks largely to the upgraded processor and increased RAM from the Quest 2.

    We were big fans of the new controllers, which the 3S shares with the more expensive Quest 3. This new generation of controller sports a more refined design, shedding the motion tracking ring and leaving behind a sleek form factor that fits in your hand like a glove.

    We did miss the headphone jack, though most users are probably fine with the built-in speakers. You can wirelessly connect headphones for higher quality sound if you feel the need. The Quest 3S also recycles the old Fresnel lenses from the Quest 2, which can lead to some artifacts.

    If you were considering a VR headset for yourself or a loved one this holiday season, the Meta Quest 3S offers an excellent value alongside impressive performance.

    Follow @EngadgetDeals on X for the latest tech deals and buying advice.
    This article originally appeared on Engadget at https://www.engadget.com/deals/the-meta-quest-3s-is-back-down-to-its-cyber-monday-all-time-low-of-250-144027382.html?src=rss



  • MasterClass subscriptions are on sale for 40 percent off for the holidays
    If learning a new skill is one of your New Year9s resolutions, then you might want to know that MasterClass subscriptions are currently 40 percent off. This brings the top-tier subscription with offline mode and use on up to six devices down from $240 annually to $144. The entry-level plan, which supports just one device and doesn9t offer offline viewing, is marked down to $72 from $120.



    Over the past few years, MasterClass has grown to over 200 classes, sessions and original series. You can learn about entrepreneurship from Richard Branson, screenwriting from Aaron Sorkin, cooking from Gordon Ramsay and heaps more. Each of these offers classes in a one-on-one format with slick instructional videos and often workbooks to accompany them.

    MasterClass also appears on our list of the best subscription gifts for this Christmas. Loved ones will enjoy superb production quality and a rich library where they are sure to find something that piques their interest. Gift subscriptions can also be scheduled, so you can take advantage of the current sale even for future gifts. If you9re buying it for yourself, know that MasterClass offers a 30-day money-back guarantee.

    Whether you9re looking to learn about business from Kim Kardashian or basketball skills from Steph Curry, MasterClass can help you expand your horizons in 2026. The "Holiday Head Start Offer" is available through December 15.

    Follow @EngadgetDeals on X for the latest tech deals and buying advice.
    This article originally appeared on Engadget at https://www.engadget.com/deals/masterclass-subscriptions-are-on-sale-for-40-percent-off-for-the-holidays-150520454.html?src=rss



OSnews

  • Haiku gets new Go port
    Theres a new Haiku monthly activity report, and this ones a true doozy. Lets start with the biggest news. The most notable development in November was the introduction of a port of the Go programming language, version 1.18. This is still a few years old (from 2022; the current is Go 1.25), but it’s far newer than the previous Go port to Haiku (1.4 from 2014); and unlike the previous port which was never in the package repositories, this one is now already available there (for x86_64 at least) and can be installed via pkgman. ↫ Haiku activity report As the project notes, theyre still a few versions behind, but at least its a lot more modern of an implementation than they had before. Now that its in the repositories for Haiku, it might also attract more people to work on the port, potentially bringing even newer versions to the BeOS-inspired operating system. Welcome as it may be, this new Go port isnt the only big ticket item this month. Haiku can now gracefully recover from an app_server crash, something it used to be able to do a long time ago, but which was broken for a long time. The app_server is Haikus display server and window manager, so the ability to restart it at runtime after a crash, and have it reconnect with still-running applications, is incredibly welcome. As far as I can tell, all modern operating systems can do this by now, so its great to have this functionality restored in Haiku. Of course, aside from these two big improvements, theres the usual load of fixes and changes in applications, drivers, and other components of the operating system.


  • Rethinking sudo with object capabilities
    Alpine Linux maintainer Ariadne Conill has published a very interesting blog post about the shortcomings of both sudo and doas, and offers a potential different way of achieving the same goals as those tools. Systems built around identity-based access control tend to rely on ambient authority: policy is centralized and errors in the policy configuration or bugs in the policy engine can allow attackers to make full use of that ambient authority. In the case of a SUID binary like doas or sudo, that means an attacker can obtain root access in the event of a bug or misconfiguration. What if there was a better way? Instead of thinking about privilege escalation as becoming root for a moment, what if it meant being handed a narrowly scoped capability, one with just enough authority to perform a specific action and nothing more? Enter the object-capability model. ↫ Ariadne Conill To bring this approach to life, they created a tool called capsudo. Instead of temporarily changing your identity, capsudo can grant far more fine-grained capabilities that match the exact task youre trying to accomplish. As an example, Conill details mounting and unmounting  with capsudo, you can not only grant the ability for a user to mount and unmount whatever device, but also allow the user to only mount or unmount just one specific device. Another example given is how capsudo can be used to give a service account user to only those resources the account needs to perform its tasks. Of course, Conill explains all of this way better than I ever could, with actual example commands and more details. Conill happens to be the same person who created Wayback, illustrating that they have a tendency to look at problems in a unique and interesting way. Im not smart enough to determine if this approach makes sense compared to sudo or doas, but the way its described it does feel like a superior, more secure solution.


  • One too many words on AT8Ts $2000 Korn shell and other Usenet topics
    Unix has been enormously successful over the past 55 years. It started out as a small experiment to develop a time-sharing system (i.e., a multi-user operating system) at AT8T Bell Labs. The goal was to take a few core principles to their logical conclusion. The OS bundled many small tools that were easy to combine, as it was illustrated by a famous exchange between Donald Knuth and Douglas McIlroy in 1986. Today, Unix lives on mostly as a spiritual predecessor to Linux, Net/Free/OpenBSD, macOS, and arguably, ChromeOS and Android. Usenet tells us about the height of its early popularity. ↫ Gábor Nyéki There are so many amazing stories in this article, I honestly have no idea what to highlight. So first and foremost, I want you to read the whole thing yourself, as everyones bound to have their own personal favourite section that resonates the most. My personal favourite story from the article  which is just an aside, to illustrate that even the asides are great  is that when Australia joined Usenet in 1983, new posts to Usenet were delivered to the country by airmail. On magnetic tape. Once per week. The overarching theme here is that the early days of UNIX, as documented on Usenet, were a fascinating wild west of implementations, hacks, and personalities, which, yes, clashed with each other, but also spread untold amounts of information, knowledge, and experience to every corner of the world. I hope Nyéki will write more of these articles.


  • COSMIC Desktop reaches first stable release
    System76, creator of Pop!_OS and prominent Linux OEM, has just announced the release of Pop!_OS 24.04 LTS  normally not something I particularly care about, but in this case, it comes with the first stable release of COSMIC Desktop. COSMIC is a brand new desktop environment by System76, written in Rust, and after quite some time in development, its now out in the wild as a stable release. Today is special not only in that it’s the culmination of over three years of work, but even more so in that System76 has built a complete desktop environment for the open source community. We’re proud of this contribution to the open source ecosystem. COSMIC is built on the ethos that the best open source projects enable people to not only use them, but to build with them. COSMIC is modular and composable. It’s the flagship experience for Pop!_OS in its own way, and can be adapted by anyone that wants to build their own unique user experience for Linux. ↫ Carl Richell You dont need to run Pop!_OS to try out COSMIC, as its already available on a variety of other distributions (although it may take a bit for this stable version to land in the respective repositories).


  • Windows 3.1s infamous Hot Dog Stand! colour scheme was not a joke
    Im sure most of us here are aware of the bright red-and-yellow colour scheme called Hot Dog Stand!, included in Windows 3.1. While its not the only truly garish colour scheme included in Windows 3.1, its name probably did a lot to make it stand out from the others. Theres been a ton of speculation about the origins of the colour scheme, and why it was included in Windows 3.1, but it seems nobody ever bothered to look for someone who actually worked on the Windows 3.1 user interface  until now. PC Gamers Wes Fenlon contacted Virginia Howlett, Microsofts first user interface designer who joined the company in 1985, and asked her about the infamous colour scheme. It turns out that the origin story for the infamous colour scheme is rather mundane. In Howletts own words: I do remember some discussion about whether we should include it, and some snarky laughter. But it was not intended as a joke. It was not inspired by any hot dog stands, and it was not included as an example of a bad interface—although it was one. It was just a garish choice, in case somebody out there liked ugly bright red and yellow. ↫ Virginia Howlett, quoted by Wes Fenlon in PC Gamer Howlett then lists a few other included colour schemes that were just as garish, or even more so, as examples to underline her point. Personally, Im a huge proponent of allowing users to make their interfaces as ugly and garish as they want, as the only arbiter on whats on your screen is you, and nobody else. Hot Dog Stand and similar garish themes need to make a comeback, because theres bound to be some people out there whose vibes align with it.


  • Using AI! to manage your Fedora system seems like a really bad idea
    IBM owns Red Hat which in turn runs Fedora, the popular desktop Linux distribution. Sadly, shit rolls downhill, so were starting to see some worrying signs that Fedora is going to be used a means to push AI!. Case in point, this article in the Fedora Magazine: Generative AI systems are changing the way people interact with computers. MCP (model context protocol) is a way that enables generate AI systems to run commands and use tools to enable live, conversational interaction with systems. Using the new linux-mcp-server, let’s walk through how you can talk with your Fedora system for understanding your system and getting help troubleshooting it! ↫ Máirín Duffy and Brian Smith at Fedora Magazine This linux-mcp-server! tool is developed by IBMs Red Hat, and of course, IBM has a vested interest in further increasing the size of the AI! bubble. As such, it makes sense from their perspective to start pushing AI! services and tools all the way down to the Fedora community, ending up with articles like this one. Whats sad is that even in this article, which surely uses the best possible examples, its hard to see how any of it could possibly be any faster than doing the example tasks without the help! of an AI!. In the first example, the AI! is supposed to figure out why the computer is having Wi-Fi connection issues, and while it does figure that out, the solutions it presents are really dumb and utterly wrong. Most notably, even though this is an article about running these tools on a Fedora system, written for Fedora Magazine, the AI! stubbornly insists on using apt for every solution, which is a basic, stupid mistake that doesnt exactly instill confidence in any of its other findings being accurate. The second example involves asking the AI! to explain how much disk space the system is using, and why. The prompt! (the human-created question! the AI! is supposed to answer!) is bonkers long  its a 117 words long monstrosity, formatted into several individual questions  and the output is so verbose and it takes such a scattershot approach that following-up on everything is going to take a huge amount of time. Within that same time frame, it wouldve been not only much faster, but also much more user-friendly to just open Filelight (installed by default as part of KDE), which creates a nice diagram which instantly shows you what is taking up space, and why. The third example is about creating an update readiness report for upgrading from Fedora 42 to Fedora 43, and its prompt! is even longer at 190 words, and writing that up with all those individual questions mustve taken more time than to just0 Do a simple dry-run of a dnf system upgrade which gets you like 90% of the way there. Here, too, the AI! blurts out so much information, much of which entirely useless, that going through it all takes more time than just manually checking up on a dnf dry run and peaking at your disk space usage. All this effort to set all of this up, and so much effort to carefully craft complex prompts!, only to end up with clearly wrong information, and way too much superfluous information that just ends up distracting you from the task you set out to accmplish. Is this really the kind of future of computing were supposed to be rooting for? Is this the kind of stuff Fedoras new AI! policy is supposed to enable? If so, Im afraid the disconnect between Fedoras leadership and whatever its users actually use Fedora for is far, far wider than I imagined.


  • FreeBSD debates sunsetting power64/power64le support
    I have some potentially devastating news for POWER users interested in using FreeBSD, uncovered late last month by none other than Cameron Kaiser. FreeBSD is considering retiring powerpc64 prior to branching 16, which would make FreeBSD 15 the last stable version to support the architecture. (32-bit PowerPC is already dropped as of FreeBSD 14, though both OpenBSD and NetBSD generally serve this use case, and myself I have a Mac mini G4 running a custom NetBSD kernel with code from FreeBSD for automatic restart.) Although the message says powerpc64 and powerpc64le! it later on only makes specific reference to the big-endian port, whereas both endiannesses appear on the FreeBSD platform page and on the download server. ↫ Cameron Kaiser Theres two POWER9 systems in my office, so this obviously makes me quite sad. At the same time, though, its hard not to understand any possible decision to drop powerpc64/powerpc64le at this point in time. Raptors excellent POWER9 systems  the Blackbird, which I reviewed a few years ago, and the Talos II, which I also have  are very long in the tooth at this point and still quite expensive, and thanks to IBM royally screwing up POWER10, we never got any timely successors. There were rumblings about a possible POWER11-based successor from Raptor back in July 2025, but its been quiet on that front since. In other words, there are no modern powerpc64 and powerpc64le systems available. POWER10 and brand new POWER11 hardware are strictly IBM and incredibly expensive, so unless IBM makes some sort of generous donation to the FreeBSD Foundation, I honestly dont know how FreeBSD is supposed to keep their powerpc64 and powerpc64le ports up-to-date with the latest generation of POWER hardware in the first place. Its important to note that no final decision has been made yet, and since that initial report by Kaiser, several people have chimed in to argue the case that at least powerpc64le (the little endian variant) should remain properly supported. In fact, Timothy Pearson from Raptor Engineering stepped up the place, and stated hes willing to take over maintainership of the port, as Raptor has been contributing to it for years anyway. Raptor remains committed to the architecture as a whole, and we have resources to assist with development. In fact, we sponsor several FreeBSD build machines already in our cloud environment, and have kernel developers working on expanding and maintaining the FreeBSD codebase. If there is any concern regarding hardware availability or developer resources, Raptor is willing and able to assist. ↫ Timothy Pearson Whatever decision the FreeBSD project makes, the Linux world will be fine for a while yet as IBM contributes to its development, and popular distributions still consider POWER a primary target. However, unless either IBM moves POWER hardware downmarket (extremely unlikely) or the rumours around Raptor have merit, I think at least the FreeBSD powerpc64 (big endian) port is done for, with the powerpc64le port hopefully being saved by people hearing these alarm bells.


  • US government switches to Times New Roman because Calibri is woke!
    Secretary of State Marco Rubio waded into the surprisingly fraught politics of typefaces on Tuesday with an order halting the State Department’s official use of Calibri, reversing a 2023 Biden-era directive that Mr. Rubio called a “wasteful” sop to diversity. While mostly framed as a matter of clarity and formality in presentation, Mr. Rubio’s directive to all diplomatic posts around the world blamed “radical” diversity, equity, inclusion and accessibility programs for what he said was a misguided and ineffective switch from the serif typeface Times New Roman to sans serif Calibri in official department paperwork. ↫ Michael Crowley and Hamed Aleaziz at The New York Times


  • What do Linux kernel version numbers mean?
    If youre old enough, you no doubt remember that up until the 2.6.0 release of the Linux kernel, an odd number after the first version number indicated a pre-release, development version of the kernel. Even though this scheme was abandoned with the 2.6.0 release in 2003 and since then every single release has been a stable release, it seems the ghosts of this old versioning scheme still roam the halls, because prominent Linux kernel developer Greg Kroah-Hartman just published an explainer about Linux kernel versions. Despite having a stable release model and cadence since December 2003, Linux kernel version numbers seem to baffle and confuse those that run across them, causing numerous groups to mistakenly make versioning statements that are flat out false. So let’s go into how this all works in detail. ↫ Greg Kroah-Hartman I genuinely find it difficult to imagine what could possibly be unclear about Linux kernel version numbers. The Linux kernel uses a very generic major.minor scheme, but thats not where the problems lie  its the actual development process of each of these numbered release thats a bit more complex. This is where we have to talk about things like the roughly 10-week release cycle, containing a 2-week merge window, as well as Torvalds handing off the stable branch to the stable kernel maintainers. The other oddity is when the major version number gets incremented  the first number in the version number. Theres no real method to this, as Kroah-Hartman admits Torvalds increments this number whenever the remaining numbers get too high and unwieldy to deal with. Very practical, but it does mean that going from, say, 5.x to 6.x doesnt really imply theres any changes in there that are any bigger or more disruptive than when going from 6.8.x to 6.9.x or whatever. Theres a few more important details in here, of course, like where LTS releases come from, but thats really it  nothing particularly groundbreaking or confusing.


  • Microsoft will allow you to remove AI! actions from Windows 11s context menus
    With the current, rapidly deteriorating state of the Windows operating system, you have to take the small wins you can get: Microsoft is now offering the option of removing AI! actions from Windows 11s context menus. buried deep in the Windows 11 Insider Preview Build 26220.7344 release notes, theres this nugget: If there are no available or enabled AI Actions, this section will no longer show in the context menu. ↫ Windows Insider Preview release notes If you then go to Settings > Apps > Actions and uncheck all the AI! actions, the entire submenu in Windows 11s context menus will vanish. While this is great news for those Windows users who dont want to be bothered by all the AI! nonsense, I wish Microsoft would just give users a proper way to edit the context menu that doesnt involve third party hackery. KDEs Dolphin file manager gives me full control over what does and does not appear in its context menu, and I cant imagine living without this functionality  theres so many file-related operations I never use, and having them clutter up the context menu is annoying and just slows me down. Theres more substantial and important changes in this Insider Preview Build too, most notably the rollout of the Update Orchestration Platform, which should make downloading and installing application updates less cumbersome, but since its a new feature, application wont support it right away. This release also brings the new Windows MIDI Services, and Microsoft hopes this will improve the experience for musicians using MIDI 1.0 or MIDI 2.0 on Windows. Theres a slew of smaller changes, too, of course. Im not exactly sure when these new features will make their way to production installations  who does, honestly, with Microsofts convoluted release processes  but I hope its sooner rather than later.



Linux Journal News

  • EU OS: A Bold Step Toward Digital Sovereignty for Europe
    Image
    A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem.
    What Is EU OS?
    EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.

    Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments.
    The Vision Behind EU OS
    The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.

    Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.

    However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty.
    Conclusion
    EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.

    Source: It's FOSS
    European Union


  • Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.

    In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.

    On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.

    Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.

    The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.

    Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.

    You can download the latest kernel here.
    Linus Torvalds kernel


  • AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
    Image
    AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.

    This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.

    Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.

    Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.

    Source: 9to5Linux
    AerynOS


  • Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
    Image
    Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.

    Here’s a quick overview of what’s new in Xojo 2025r1:
    1. Linux ARM IDE Support
    Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started.
    2. Web Drag and Drop
    One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required!
    3. Direct App Store Publishing
    Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process.
    4. New Desktop and Mobile Features
    This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection.
    5. Performance and IDE Enhancements
    Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced.
    What Does This Mean for Developers?
    Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution.
    How to Get Started
    Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.

    Download Xojo 2025r1 today at xojo.com.
    Final Thoughts
    With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you.
    Xojo ARM


  • New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux

    Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.

    Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.

    Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest. 

    Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.

    Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.

    Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.

    By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem.
    Windows


  • Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities

    The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally. 

    As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.

    In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions. 

    After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.

    The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.

    At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.

    The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca.
    Security


  • Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges

    The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.

    A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.

    This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem. 

    The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.

    On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.

    In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers.
    kernel


  • Linux Celebrates 32 Years with the Release of 6.6-rc2 Version

    Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.

    The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.

    Here is what Linus Torvalds had to say in today's announcement:
    Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds


  • Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction

    Want to interact with ChatGPT from your Linux desktop without using a web browser?

    Bavarder, a new app, allows you to do just that.

    Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.

    With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.

    During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.

    At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.

    As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!

    Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring.
    ChatGPT AI


  • LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite

    Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.

    Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.

    LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.

    You can download LibreOffice 7.5.3 directly from the LibreOffice websiteor from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.

    All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.

    In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.

    Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.

    The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners.
    LibreOffice


Linux Magazine News (path: lmi_news)











Page last modified on November 17, 2022, at 06:39 PM