Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All/All+Images) (Single Column)

LWN.net

  • [$] Looking forward to Git 2.56 — and 3.0
    The Git source-code management system isat the core of development processes worldwide, so changes, especiallyincompatible changes, are of great interest to the developers involved.The Git 2.56 release, which can be expected around the end of September, iscurrently available in release-candidate form. Itis not the most earth-shaking of releases, but the one that follows, whichmight be the long-awaited Git 3.0, may well be.


  • Systemtap 5.6 released
    Version 5.6 of the Systemtap tracing tool has been released.
    BPF LSM hooks and XDP packet-processing probes for the --bpf runtime, BTF-based kernel.tracepoint probes, statement execution tracing, a new @enumname() operator, richer runtime error context, dyninst hardware watchpoints, modern systemd service templates, and broad Linux 7.2 runtime/tapset compatibility work. Multithreaded speedups throughout.


  • Security updates for Friday
    Security updates have been issued by AlmaLinux (.NET 10.0, coreutils, kernel, libevent, libsoup3, microcode_ctl, perl-Net-DNS, postgresql18, postgresql:16, postgresql:18, tomcat, and unbound), Debian (bind9, chromium, libapache2-mod-auth-openidc, nginx, xz-utils, and zip), Fedora (chromium, freeipmi, GitPython, gnatcoll, nodejs-undici, parted, python-django5, and sblim-cmpi-base), Mageia (imagemagick and python-starlette), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, coreutils, corosync, firewalld, kernel, libevent, libsoup, microcode_ctl, nginx:1.24, perl, perl:5.32, postgresql:16, postgresql:18, redis, rsync, rsyslog, tesseract, and unbound), Red Hat (vim), SUSE (alsa, chirp, chromium, cjose, cups, discount, firefox, gh, glibc, gvfs, jq, kernel, libcjose-devel, libmbedcrypto7, libpcap, mbedtls-2, netcdf, nodejs18, openai-codex, openvpn, pcre2, perl-net-dns, sngrep, tiff, and znc), and Ubuntu (bison, bubblewrap, and gst-plugins-good1.0).


  • [$] Thread-identity switcheroo for io_uring
    The io_uringsubsystem is all about asynchronous execution; applications count on itto not block — unless explicitly requested to. Within io_uring, maintainingthe "never blocks" guarantee has sometimes been a challenge, given thatmany paths in the kernel were never designed for asynchronous execution.This problem has been worked around, but at a significant cost toperformance. Now, io_uring maintainer Jens Axboe has posted an RFC patch setwith a somewhat radical (and potentially scary) solution to the problem.


  • GNOME 51 released
    Version 51 of the GNOME desktopenvironment has been released. The list of changes includes a number ofperformance improvements, offline data and better transit information inthe Maps application, a new interface for the file previewer, and more.


  • Security updates for Thursday
    Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, corosync, firewalld, kernel, kernel-rt, libevent, libsoup, microcode_ctl, nginx:1.26, python-lxml, rsyslog, tesseract, and unbound), Debian (firefox-esr, mkvtoolnix, thunderbird, and tor), Fedora (open62541, php-pecl-mongodb2, python-django6, python-jwcrypto, and roundcubemail), Mageia (aom, cockpit, libgd, packagekit, and python-h2), Red Hat (corosync, delve, git-lfs, grafana-pcp, gstreamer1-plugins-base, libvirt, opentelemetry-collector, and rhc-worker-playbook), Slackware (mozilla-firefox and mozilla-thunderbird), SUSE (acl, attr, alloy, ansible-core, clamav, containerized-data-importer, corosync, cups, distribution, glibc, google-cloud-sap-agent, govulncheck-vulndb, gvfs, helm, jq, kbd, kubernetes1.34-apiserver, kubernetes1.35-apiserver, lcms2, libcupsfilters, liblzmasdk26, libzypp, zypper, mistral-vibe, opensc, openvpn, pcre2, python-jwcrypto, tomcat, tomcat10, and tomcat11), and Ubuntu (guix, libheif, perl, python-cryptography, sqlite3, and valkey).



  • Fedora 45 beta drags the Linux console into the 21st century (Register)
    The Register looksforward to the upcoming Fedora 45 release.
    The biggest surprise is that Linux's legacy in-kernel console – the text-mode interface normally hidden beneath the GUI – has been replaced with a software-controlled alternative. The replacement is kmscon, a userspace terminal emulator that has been in development for more than a decade.


  • [$] Ways to encrypt data on servers
    At the 2026 edition of FOSSY, RomeoSolano gave a fast-paced, humorous presentation on what could have been arather boring topic: server encryption. There are a number of threats thatwe face in today's world, from criminals, government overreach, espionage,and more, that can be thwarted with encryption. But encrypting data on asystem that may live elsewhere, without any access to its keyboard at boottime, is rather more difficult than encrypting the disk of a laptop.Solano described the problems and gave a tour of some of the solutions inthe talk.


  • Security updates for Wednesday
    Security updates have been issued by AlmaLinux (kernel, kernel-rt, libkcapi, nginx, nginx:1.24, openssl, osbuild-composer, perl, perl:5.32, python-tornado, rsync, and rust), Debian (cjose and nginx), Fedora (environment-modules, erlang, GitPython, knot, perl-Authen-SASL, python-configargparse, ruby, rubygems, and sblim-sfcb), Oracle (firefox, git-lfs, gstreamer1-plugins-base, kernel, libkcapi, nginx, nginx:1.26, openssl, osbuild-composer, perl, perl-YAML-Syck, postgresql18, python-tornado, and rust), Red Hat (fence-agents, git-lfs, microcode_ctl, osbuild-composer, podman, python-pyasn1, and resource-agents), SUSE (389-ds, ant, bson-devel, chirp-20260911, docker, gimp, google-cloud-sap-agent, hauler, kernel, kimi-code, libpcap, python-GitPython, python310, syncthing, yast2-samba-client, and zstd-jni), and Ubuntu (aom, imagemagick, kitty, openssh, phpseclib, policykit-1, python-sql, python-webob, shibboleth-sp, simplesamlphp, snapcast, srt, and suricata-update).



LXer Linux News








  • CompuLab i.MX952 Linux-capable module showcases 2.5GbE, Wi-Fi 6 and PCIe Gen 3
    CompuLab has introduced the UCM-iMX952, a 28 x 40mm System-on-Module based on NXP’s i.MX952 processor. The module supports up to 16GB of LPDDR5 or LPDDR4X memory and 128GB of eMMC storage, along with PCIe Gen 3, 2.5GbE, Wi-Fi 6, Bluetooth 5.4, and multiple display and camera interfaces. The NXP i.MX952 is available on the module […]




Linux Insider"LinuxInsider"












Slashdot

  • Democracy vs Digital Infrastructure: Pulitzer-Winning Journalist Charts 'The Rise and Fall of the Artificial State'
    The Rise and Fall of the Artificial State ultimately asks the question, "How did we cede control of our democracy to the machines, and can we get it back?" according to the Harvard's Arts and Sciences site, FAS Current:The new title finds Lepore, who used to teach a course at the College titled "The Rise and Fall of the Machine," charting the ascent of what she calls the artificial state: the digital communication infrastructure by which governments and private corporations automate and ultimately control public discourse. Following her Pulitzer Prize win for "We the People: A History of the U.S. Constitution" (2025), "I wanted to think about whether liberal constitutional democracies can survive this moment in time," Lepore shared in a phone interview... [In the "current ChatGPT moment"] Lepore found herself asking: "Who are the people who are clamoring to be replaced by machines, to have movies made by machines, and novels written by machines?" And who, she continued, is pushing for our government to be determined by these machines? In the book, Lepore notes that technological tools are increasingly influencing elections around the world...However, she sees the 2026 U.S. midterms as an inflection point. In a recent piece in the Financial Times, Lepore wrote, "This year marks the first AI election. Voters are asking chatbots how they should vote. Campaigns and activists are using AI to analyze the electorate, send micro-targeted messages, produce tailored ads and even deepfakes...." Lepore stresses in the book that "nobody should trust historians to make predictions," but she believes it's possible for democratic citizens to wrest back control. Referencing proposals such as New York's data center moratorium law, Lepore ends by describing a "growing and increasingly noisy tech backlash." "It's not foreordained. This isn't inevitable," she said during the interview. "In the book's epilogue Lepore predicts, as her title suggests, a fall of the Artificial State," writes the California Review of Books. "That argument turns out to be speculative, much more of a hope than a certainty."[Lepore] does support her prediction by positing that the Artificial State is "poorly designed and badly built," that it has not given people safety and happiness but rather a prison of glowing screens, and that a majority of Americans want more control over AI. To escape the Artificial State we will have to imagine a different future by gaining more knowledge of the past in a search for meaning. Of course, powerful forces want to deny that and turn us into servile automatons. The Guardian adds that "While Lepore interprets much classic sci-fi, such as Isaac Asimov, as cautionary, she observes that "the architects of the Artificial State seem to have read these stories, unironically, as instruction manuals, guides for how to build robots that would one day rule the world". (The Atlantic writes that "What one gathers from these misreadings is not so much that science fiction itself is nefarious, but that arrested development might be...") But The Indian Express writes that despite the author's bleak conclusion, "Lepore is not a pessimist. Because the Artificial State is a construct, neither alive, nor truly indestructible, she argues it is still possible to take it apart... [T]his is a clear-eyed reckoning rather than a doomsday tract. It is not an easy read, but an essential one for anyone unsettled by the pace of the AI wave."


    Read more of this story at Slashdot.


  • The Brain Is Actually Two Completely Separate Organs
    "New research led by Stanford Medicine reveals that what we call the brain is two distinct organs that evolved independently over hundreds of millions of years," Stanford Medicine announced this week:The new research finding shows that the human brain consists of two ancient nervous systems cleverly packaged together — a more primitive part that regulates our hearts' beating, our breathing and other functions, and another that makes us distinctly human, capable of poetry, mathematics and wondering about our own origins. The discovery could help explain why scientists have struggled for decades to grow certain types of brain cells in the laboratory — and it opens new avenues for studying devastating diseases that affect the brain stem... [S]cientists have struggled for decades to generate human hindbrain neurons in the laboratory. This gap has hampered research into devastating diseases affecting the brain stem, including spinal muscular atrophy and amyotrophic lateral sclerosis... The researchers' breakthrough came from studying the earliest moments of embryonic development... [Study co-authors Carolyn Dundes and Rayyan Jokhai] discovered that the hindbrain follows a separate developmental path, running in parallel to — rather than branching off from — the pathway that creates the forebrain and midbrain... This revelation explained decades of frustration in the field — scientists had been trying to turn one type of progenitor cell into another that it is fundamentally incapable of becoming... Armed with this knowledge, the researchers for the first time successfully coaxed human pluripotent stem cells (a kind of cell that can create any cell in the human body) to become functional hindbrain motor neurons in the laboratory... Finally, the researchers looked back over 550 million years of evolutionary time. They found the same two-origin brain pattern in chickens; zebrafish; and, remarkably, in acorn worms, tiny creatures living on the ocean floor that share a distant common ancestor with humans. Jellyfish, which diverged from humans about 600 to 700 million years ago, have two nervous systems at different ends of their body. "Our research suggests that evolution took two existing neural systems and pushed them together spatially," Loh said. "Having the brain as one organ would probably be more efficient, but we rely on this primordial way to make the brain as two separate pieces." Thanks to Slashdot reader Beeftopia for sharing the article.


    Read more of this story at Slashdot.


  • To Enforce Its Proposed Social Media Ban for 450 Million Pre-Teens, EU Builds an Open Source App
    The European Commission "proposed on Thursday banning children under 13 from social media, with parent-supervised accounts until 15," reports Reuters. "Enforcement would rely on a tool Brussels built itself" — a free, open-source age verification smartphone app "that tells a platform whether a user meets an age threshold without revealing their identity..."If passed, the proposed Kids Act would create the world's largest social media access restriction, covering 450 million people across 27 countries... [The EU-built age-verification app] is being rolled out through member states, with seven pilot countries: Cyprus, Denmark, France, Greece, Ireland, Italy and Spain. The Commission expects EU-wide availability by the end of 2026. It will also be used to prove users are over 18 when accessing adult sites, a restriction already implemented under the Digital Services Act... [T]he system itself is decentralised. Member states run it through issuers they designate, and the proofs live on the user's phone. There is no central EU database of ages or of who verified whom... A user proves their age once to a nationally designated issuer — a body vetted by the member state, which can be a digital ID provider, a bank or a post office. At a restricted site, the app certifies that the user is above the required age threshold. The platform receives only a yes-or-no response. Issuance and verification are handled by separate entities. The proof provider is not told which service the proof was used for. Each proof works only once, preventing cross-service tracking. No identity documents or biometric data are retained. The code is open-source, allowing independent scrutiny. The significance of the EU approach is that it provides a common age-verification mechanism rather than leaving individual platforms to develop and enforce their own systems."Online platforms can easily rely on our age verification app. So there are no more excuses," [EU Commission President Ursula] von der Leyen said... The proposal must be approved by EU member states and the European Parliament before becoming law. Non-compliance would risk fines of up to 6% of a tech company's global annual sales, plus supervisory fees, Reuters reported earlier.The EU's plan follows similar initiatives in Australia, Britain, China, India, Turkey and several European Union countries.


    Read more of this story at Slashdot.


  • Tech Industry Scratches Its Head Over Trump's 'AI Force' Proposal
    Saturday morning President Trump announced he's creating an AI task force and appointing an AI czar, reports Politico. "I am forming the AI Force, much like I did Space Force, which has been a tremendous SUCCESS," Trump wrote Saturday in what Politico earlier described as "a lengthy Truth Social post on Saturday morning."TRUMP: Over the years, there have been many Hoaxes, all generated by the Radical Left Dumocrats, for purposes of destroying our Country. RUSSIA, RUSSIA, RUSSIA, UKRAINE, UKRAINE, UKRAINE, Global Warming, Impeachment Hoax #1, Impeachment Hoax #2 [...] and now, the decimation, or destruction, of AI, commonly known as Artificial Intelligence — And I, as President of the United States, will not stand by and let this happen. It all began with an attack on our Data Centers, until people realized how wealthy and prestigious they were for the Communities in which they were built. Higher Salaries, Lower Taxes, and Safer Streets, was the result, and the crazed Data Center attack has largely failed, so now [...] they are going straight at AI. We will not in any way hinder or stifle the Growth of this incredible Industry. Rather, we will cherish it, help it, and watch over it, as it grows! However, we will also be looking for BAD, and we can do that, very easily, with our already existing Criminal and Civil Justice System. For this purpose, I am forming the AI Force, much like I did Space Force, which has been a tremendous SUCCESS, in my First Term. To that end, I will be announcing, in the near future, the AI "Czar" — Only High I.Q. individuals need apply! Trump concluded by saying AI "is the next Industrial Revolution, or Internet, but will be even larger and more impactful... We are leading China, and the rest of the World, and I intend to keep it that way!"But what exactly is AI Force? "The White House did not immediately respond to a request to clarify whether the agency would be military or civilian," notes the Washington Post. So now "The tech industry is struggling to make sense of President Donald Trump's surprise announcement," Politico reported Saturday afternoon:Four representatives for the sector, who were granted anonymity because they were not authorized to speak publicly, told POLITICO that the industry was not widely informed of Trump's decision prior to the Truth Social post. "Nobody knows what the idea even is," one of the people said. Another said that feedback on the idea was not widely solicited within the industry. The White House did not immediately respond to a request for comment... "I think that he clearly feels pressure to say something, but he's torn because he's just spent the last few days saying that the whole thing is a hoax," Adam Kovacevich, CEO of the progressive tech industry coalition Chamber of Progress, said of Trump and his prior dismissal of AI doomsday scenarios. Since the departure of David Sacks, who stepped down as the Trump administration's previous AI czar earlier this year, the White House has been "making up AI policy as it goes," Kovacevich added. "I think it's clear they've really missed the presence of an organized leader like David Sacks was." One of the tech industry representatives said they were confused about whether the task force would be charged with formulating more AI regulations or recommending policies that would further stimulate the tech's development. Taylor Barkley, director of federal government affairs at the industry-aligned Abundance Institute, is eyeing it as a way to solidify a light-touch government approach to the technology he says will foster innovation. "Any AI Force or AI Czar should have one job: keep the field open so entrepreneurs at every scale can compete, free from onerous regulation," he told POLITICO. "Existing criminal and civil law can handle bad actors. New permission regimes will stifle the very activity America needs most." It's worth noting that the day before, California's governor made an announcement. "With Donald Trump and Congress asleep at the wheel, Governor Gavin Newsom is once again taking the lead to strengthen AI safety for all Americans," the governor's office announced Friday. Newsom issued a strong executive order convening experts to help California create new AI safety laws and reporting rules, possibly even requiring safety auditors embedded in labs and emergency "kill switches" in frontier models.


    Read more of this story at Slashdot.


  • Customer-Losing Flock Now Offers Buyouts to Avoid Laying Off Employees
    Mashable writes:Flock Safety offered employees voluntary buyouts on Friday, WIRED reported... Without the buyouts, those familiar with the situation suspect the company would have to lay off some of its 1,500 employees. WIRED writes that people familiar with the program "say they believe that a significant number of the startup's roughly 1,500 employees may try to depart."Flock is making the severance offers as it continues to lose customers... The company has had many of its contracts either not extended or dropped this year, which could leave it short of revenue goals, according to two of the people. A wave of vandalism targeting its cameras has unexpectedly increased expenses. Without buyouts, Flock almost certainly would have to lay off some staff, one of the people believes... People familiar with Flock's severance plan tell WIRED that some employees may take the offer amid speculation that the company, which has raised about $1.2 billion in venture capital, might resort to selling off parts or all of its business to stay afloat... One advocacy group identified 93 city and county governments that cut ties with Flock in August alone. Overall in 2026, roughly three times as many local governments have dropped Flock compared to the previous five years. Flock has recently been building products that extend the company beyond its core license plate reader offering. WIRED reported last month that the company has developed AI-powered investigative software to identify drivers, find potential associates based on patterns of movement, and search across police records and other data. A separate WIRED analysis of Flock's software found tools designed to continuously search camera feeds for people matching written descriptions. WIRED's analysis of Flock's code also found potential integrations with drones and other surveillance systems. Flock's financial scrambles might explain an incident in Syracuse, New York. The nonprofit news siteCentral Current discovered the city's contract said its license plate data wouldn't be shared outside the police department, reports Mashable:But the department had granted access to other agencies, which police said was an accident. Over roughly a year, searches by officers around the country reached Syracuse's data nearly 4.4 million times. And that wasn't the only surprise in the paperwork. Central Current also found that Flock could keep using Syracuse data after the contract ended. When the city approved cameras from Axon to replace Flock's, Flock said Syracuse couldn't simply end its agreement early. It warned that the city might have to pay for both systems; so even as officials moved to replace the cameras, they faced questions about what Flock could do with the data and what the city might still owe. Meanwhile, the Texas Department of Transportation "has stopped issuing permits allowing Flock cameras and other automated license plate readers to be installed along state roads..." reports the Texas Tribune. "There were an estimated 13,000 Flock cameras across Texas in August, but hundreds of the devices have been shut down after [governor] Abbott's funding freeze." And in August Florida's Republican Governor "ordered his state's transportation department to remove the cameras from state roads, saying he didn't want 'a surveillance state.'"


    Read more of this story at Slashdot.


  • Developer Abandons 'PS5 Linux' Project After Sony Patches AI-Discovered Exploit
    "In April this year, we saw Andy Nguyen turning the PS5 into a Linux-powered gaming PC,"writes the blog It's FOSS. It ran Steam games and emulators using the PS5's on-board hardware. But this week Andy announced he's "stopping all my work on PS5 Linux" and "stepping away from the PS5 scene." stopping work on porting the project to the PS5 Pro, which would've shipped sometime in 2027.Andy Nguyen: After pouring my heart and months of my life into it, including plans to finish PS5 Pro support and release in 2027, it's all down the sink. The scene used to be a group of highly talented researchers, but now it is just a bunch of noobs using LLMs and writing hacks they don't even understand. Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony. I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy Linux. They agreed to wait, but not a day passed and they decided to waste it instead. Or, as It's FOSS tells it:Running Linux on a PlayStation console is possible because the PS5 Linux project was able to find a way past the hypervisor using exploits Sony had already patched, covering firmware 3.00 through 7.61. .. [The bug's discoverer writes it was] found with what he calls his "trusty ai clanker machine" and no help from anyone else. He had even agreed to Andy's request to not disclose the findings. Unexpectedly, a third person, still unnamed, found the same bug using AI a few hours later. Anticipating that there would be more people finding the same bug, [he] decided to post the flaw on HackerOne. The project's GitHub page and all the related repositories are still there. Nothing has been archived as of today, and if you wanted to, you could start contributing to the PS5 Linux project by taking over any pending work or cooking up new improvements... The PS5 Pro support Andy was building never reached the repository, so you would have to start from scratch... While Andy's departure is a blow to the plan for supporting newer PS5 firmware and the PS5 Pro, other contributors have shown that they can deliver work on the loader without him, and I am hopeful more will follow.


    Read more of this story at Slashdot.


  • Fake AI Intelligence Almost Made the US Military Start a War With China
    U.S. military intelligence received an inaccurate report this spring that a Chinese ship in the Middle East was transporting components of a nuclear weapons program, reports CNN. "The US military swung into action with plans to intercept the vessel, according to four sources familiar with the episode."Armed members of the US military were preparing to board the ship [according to two of the sources]. Military planes were in the air, one of those sources and another source familiar with the incident said. It was only just before the planned operation that officials dug deeper into the report put together by a special operations command analyst and found it had been generated with the help of AI — and that a chatbot the analyst had used inaccurately identified the material the ship was carrying. The report, according to one of the sources, was "entirely false." But it also "almost started a war," the source said. Any US operation against a Chinese vessel could have risked spiraling into an armed conflict between the two nations. Across the US military and the intelligence community, officials are pushing to weave AI into nearly every facet of their work, from analyzing the huge volumes of raw intelligence the US collects and selecting targets for strikes, to more mundane applications like managing budgeting, logistics and supply chains. But the episode underscores the profound risks of using this powerful, new and relatively poorly understood technology for targeting in the middle of a war... Officials say the US can't afford to fall behind in integrating AI in case it must one day fight China or another adversary who would potentially be able to stay one step ahead of the US. In January, Defense Secretary Pete Hegseth released his agency's "Artificial Intelligence Acceleration Strategy" in a bid to speed up the military's use of AI. "We will unleash experimentation, eliminate bureaucratic barriers, focus our investments and demonstrate the execution approach needed to ensure we lead in military AI," Hegseth said in a speech announcing the strategy. Thanks to long-time Slashdot reader stabiesoft for sharing the news.


    Read more of this story at Slashdot.


  • US Air Force F-16 Crashes in Michigan After Pentagon Orders More Flyovers
    The F-16 "experienced an incident," the Texas Military Department said in a statement, adding that "The pilot successfully ejected the aircraft and is receiving care at a nearby hospital." ABC News reports:A Texas Air National Guard F-16 crashed in Michigan during a training mission on Thursday afternoon, sparking an hourslong evacuation near the crash site, according to officials. The incident prompted the evacuation of homes and businesses within 1 mile of the crash site due to a "hazardous chemical spill related to the plane crash," Michigan State Police said... All of the Texas Air National Guard aircraft that were in Michigan for the training were immediately grounded, and will likely remain so for the next 24 hours, according to a U.S. official. America's War Department has said it wanted to see more military flyovers writes The Daily Beast, adding that the F-16 "was due to perform a flyover at a high-school football game on Friday night, the Alpena News reported."The military said it was still investigating the cause of the crash, but one pilot told air traffic controllers that he believes his wingman hit a bird before the crash.... The accident followed a Pentagon X post on Thursday after widespread criticism of low-altitude flyovers and maneuvers. "The flyovers will continue until morale improves," it said.


    Read more of this story at Slashdot.


  • Gemini Breached Three Outside Systems, and Claude-Using Researchers Breached OpenAI
    "Software security researchers used Anthropic's Claude AI platform to hack OpenAI's ChatGPT tool," reports CBS News. Using Claude, "On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees' ChatGPT accounts," write researchers at security platform Hacktron AI. "With these accounts, we could then access internal OpenAI repositories, and potentially many other connectors... Until two months ago, any user or OpenAI employee logging into OpenAI's own help forum could have had their ChatGPT and Codex accounts taken over. Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails." The exploit chain included Debian 12, which (with Debian 13) had not received a security-relevant backport for its image-processing pipeline, and Discourse's Docker image was based on Debian 12. Their announcement comes with an additional warning. "If you self-host Discourse, rebuild your installation now. Older Docker images may contain a vulnerable libheif dependency that permits code execution through an image upload." And "To prove we had in fact gained the access we believed without allowing ourselves to learn any sensitive information, we used the employee's Codex to open a PR #1186742 in OpenAI's internal monorepo openai/openai." Meanwhile, Friday Google disclosed the first known instance of its AI software Gemini breaking out of a testing environment and breaching three other companies, reports CNBC:The incident happened as part of a "capture-the-flag" security test run by Israeli startup Irregular, and Google's agents were never supposed to access the broader internet, but a bug in the testing environment made internet access available. The agents stopped their intrusion when they determined they had accessed real company systems, not just part of the testing environment, Google said. More from NBC News: Google said it did not consider the unauthorized logins to rise to the level of misalignment, the AI industry term for software going rogue or not following instructions. Instead, the company said the intrusions resulted from mistaken identity, where Gemini thought it was operating within a test but was actually connected to the real internet. Google said the model corrected itself and the company believed the intrusions did not cause any damage.... Sydney Von Arx, CEO of Nightingale Collective, an organization focused on AI safety, questioned why Google did not disclose the intrusions sooner. "At this point I think it's clear we cannot expect companies to voluntarily come forward and publicly disclose when their agents go rogue, escape, and hack companies," she said. She also said she believed Google was too hasty to say that the incidents don't rise to the level of misalignment. "That's exactly what Anthropic said after their incidents," she said. Anthropic later said its "preliminary analysis was constrained due to our desire to disclose incidents in a timely manner." Google said it investigated when they learned of the attacks from AI-focused cybersecurity company Irregular, then informed the affected organizations and told federal authorities, according to the article.


    Read more of this story at Slashdot.


  • Has the James Web Space Telescope Discovered a New 'Black Hole Star'?
    The James Webb Space Telescope has been picking up little red dots in almost every image,writes Quanta magazine. And now two teams of astronomers propose they're looking at a new astronomical object: a black hole star. It shines with the light of billions of suns — and hides a black hole in its core.But Quanta adds that "not everyone agrees with this bold interpretation."[Two Webb telescope surveys of distant objects included little red dots] for hours at a time. They tabulated precisely what shades of light were coming from each dot, and how bright the shades were... The bombshell discovery in the little red dot spectra was that the colors of hydrogen were smeared out across multiple shades. Usually, seeing such an effect means you're looking straight at an exposed black hole. Black holes whip hydrogen clouds around them at furious rates, with the clouds emitting slightly different colors depending on their speed... Then, in the spring of 2025, [two of the paper's astronomers] de Graaff and Naidu's teams unveiled the two strangest dots yet... The new little red dots couldn't literally be stars — they were way too bright. And they didn't look much like black holes either. Black holes have an assortment of ringlike structures of different temperatures... Naidu and de Graaff concluded that they were[ looking at the first examples of something combining the vigor of a black hole with the outward appearance of a star: a black hole star... This black hole would pull gas around it, dramatically heating it and pushing light and energy outward, which would keep the outer layers of hydrogen from collapsing inward. In this way, the black hole would form the "engine" of the star, analogous to the fusion-powered core of our sun... "We are seeing the seed," Naidu said. "This is the birth of potentially every massive black hole in the universe." "Astronomers have spent the last year in a lively debate about what's really going on," Quanta adds. And this week simulations using the Japanese Supercomputer ATERUI III "have explained the nature of the Little Red Dots without requiring any exotic assumptions," writes Phys.org — by conducting the most detailed cosmological simulations yet of conditions in the early universe:The simulations show that the Little Red Dots are black holes growing at a rate that would be impossible today because of conditions in the early universe. The simulations show that in the early universe, intense far-ultraviolet (FUV) radiation from nearby galaxies suppresses star formation in gas clouds, so rather than forming many small stars, the gas can form a single supermassive star, which then collapses into a black hole seed. The simulations show that, once formed, these black hole seeds are surrounded by dense gas disks. This environment traps radiation, enabling the black holes to grow at rates dozens of times faster than would be possible in the modern universe. The simulated properties of these rapidly growing black holes provide a good match to the Little Red Dots (LRDs) observed by the James Webb Space Telescope (JWST).


    Read more of this story at Slashdot.



Linux.com





  • From DHCP to SZTP – The Trust Revolution
    By Juha Holkkola, FusionLayer Group The Dawn of Effortless Connectivity In the transformative years of the late 1990s, a quiet revolution took place, fundamentally altering how we connect to networks. The introduction of DHCP answered a crucial question, Where are you on the network?!, by automating IP address assignment. This innovation eradicated the manual configuration [0]

    The post From DHCP to SZTP – The Trust Revolution appeared first on Linux.com.







Phoronix

  • Linux 7.3-rc4 Released: More Fixes Caught By LLMs, But Nothing Too Scary
    Linus Torvalds announced the release today of Linux 7.3-rc4. As usual for recent months, the fixes continue to be quite heavy and scattered all over the place driven in large part by AI/LLMs spotting various code defects. Overall though Linus Torvalds isn't too worried about Linux 7.3-rc4...










  • Wine-Staging 11.18 Adds New Patches To Further Improve WoW64
    Building off yesterday's Wine 11.18 bi-weekly development release is now Wine-Staging 11.18. This experimental flavor of Wine is presently carrying 273 extra patches over that upstream Git state, including some new patches for helping enhance the WoW64 support...



Engadget"Engadget - Technology News & Expert Reviews"







  • What's the 30-degree rule for TVs?
    The Society of Motion Picture and Television Engineers has a simple method for calculating the ideal viewing distance based on your TV size.





OSnews

  • I dont like passkeys!
    Passkeys are a fantastic technology. Since they are bound to the site they are created for, they cannot be phished by a hacker’s fake login screen. If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details. This leads to passkeys being the perfect fit for a corporate environment, but a poor fit for personal security. To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss. By using passkeys, you gain better security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts. Phishing through the standard login flow is eliminated by passkeys, but it creates a false sense of security. An account’s security is still dictated by the weakest recovery method: SMS, email links, security questions, and so on. If these recovery methods aren’t enabled, then the risk of permanent lockout remains for the user. ↫ Ethan Hawksley Ive always felt something was off about passkeys, and have never used them. Theyve become  or were always intended to be  tools for further lock-in by especially Google and Apple, tying their entire usage flow to their respective operating systems. They also dont seem to work well if you often work on devices not your own, which is a major hassle. None of these shortcomings come into play when using a traditional password manager, even if they require more manual work. Just let me use a password manager with random password generation, instead of trying to force passkeys down my throat.


  • Java 27 released
    Speaking of unsexy programming, weve got a new Java release. Featuring thousands of performance, stability, security, and productivity improvements, Java 27 (Oracle JDK 27) provides a strong foundation for continued Java innovation. To help organizations prepare for more secure communications in a post-quantum world, Java 27 advances its post-quantum cryptography (PQC) capabilities with hybrid key exchange for TLS 1.3. ↫ Oracle press release The OpenJDK release page has more information.


  • Performance improvements in .NET 11
    Look, nobodys going to argue .NET is sexy, but the truth of the matter is that its quite popular in less visible circles, so any new release is going to have a big impact on a ton of people and product. In other words, performance improvements in .NET 11 are going to matter. In contrast, .NET 11 is actually one higher, one louder. The sections that follow are full of real improvements. A bounds check removed, an allocation that no longer happens, a lock that isn’t taken, a loop that runs in fewer cycles than it did a year ago, a comparison folded to a constant here, a redundant check hoisted out of a loop there, a couple of instructions fused into one, a syscall sidestepped, an array copy handed off to SIMD, and on and on. That’s how real performance work goes, accumulating gain after gain, each compounding on the last, until the whole thing is measurably, provably louder. And so, in this post, as I’ve done in past years with .NET 10, .NET 9, .NET 8, .NET 7, .NET 6, .NET 5, .NET Core 3.0, .NET Core 2.1, and .NET Core 2.0 before it, we’ll take an unhurried tour through hundreds of them. ↫ Stephen Toub at Microsofts Dev Blogs My eyes glaze over at all of this, but even here on OSNews, theres going to be countless people working with .NET at their jobs.


  • GNOME 51 released
    GNOME 51 has been released, with a whole slew of new features and improvements. Most notably, at least in my experience, will be the work done on GNOMEs graphics stack, which seems to stutter and jitter more than KDEs on the same hardware  at least in my experience. In particular, GNOMEs compositor, Mutter, has improved frame scheduling for smoother animations, even under load. This hopefully addresses the stutters I generally experience when using GNOME. Theyve also done a lot of work on the Settings, Maps, Calendar, Web, and other applications. Of note to many will be the array of improvements to GNOMEs file manager, including better performance, although I doubt it will convince those of us who arent particular fans of Nautilus in general. Theyve also improved the remote desktop experience by, among other things, adding support for smart cards and improving support for Kerberos. GNOME 51 will make its way to your distribution of choice soon enough.


  • Ubuntu 26.10 completes transition to Rust-based coreutils
    Ubuntu has been replacing core utilities with Rust rewrites, and its now completed the process. cp,`mv`and`rm`were held back on`their GNU versions in`Ubuntu 26.04 LTS due to a crop of`TOCTOU (time-of-check to time-of-use) issues that needed to be fixed in the`uutils`versions.` With those issues resolved upstream,`Ubuntu 26.10 finishes the job. The ‘Stonking Stingray’ ships a full set of Rust core utilities, which encompasses common command-line tools like ls,`cat,`chmod and `du. ↫ Joey Sneddon at OMG! Ubuntu Im definitely not qualified enough to make any useful remarks about this, but the idea of replacing such foundational, battle-tested utilities with brand new ones, even when written in a memory-safe language, does make feel a little hesitant. Still, at least this way Ubuntu users can work out any issues so that if and when other distributions  like the one I use, Fedora  follows suit.


  • The terrible menu bar in the Windows 11 Notepad
    When I used Windows for a month because you people paid me to do so, the utter lack of consistency in the way applications and the operating system itself looks, feels, and behaves was a major sticking point. It turns out, though, that I was only scratching the surface of just how bad things really are on Windows. Case in point: the new WinUI Notepad application that replaced the classic Win32 one. I had no idea just how bad it really is. It’s been seven weeks since I last complained about something in Windows on this blog. That feels like too long, so here’s a post about menus – specifically, the menu bar in the modern version of Notepad in Windows 11. That menu bar has, unfortunately, quite a few regressions compared to the menu bar in the old Win32 version of Notepad. ↫ Reupen Shah Im not going to spoil any of it, because theres no way youd believe any of it without the videos Shah provides. Im aghast.


  • GEFS on OpenBSD: a very early preview
    The Good Enough File System, originally developed for 9front, is being ported to OpenBSD. For those who havent watched my talk, GEFS is a new, crash-safe, snapshotting, copy on write FS that I wrote for 9front, and which I am in the process of moving to OpenBSD. The file system is described in full here. ↫ Ori Bernstein One of OpenBSDs shortcomings is its rather archaic filesystem, so any work on something more modern and especially more performant is quite welcome. While any process of replacing FFS is going to be a long one, even having GEFS as an option could be a great addition to OpenBSD.


  • Apple releases iOS 27, macOS Golden Gate 27 with Siri AI! and Liquid Glass refinements
    Apple releases its yearly cluster of operating system updates today, with the two most prominent of course being macOS and iOS/iPadOS. These new versions focus heavily on Apples AI! stuff, but there are a few actual improvements and changes to the actual operating systems as well. Across both iOS and macOS, users now have a slider to affect how transparent or opaque the “Liquid Glass” design is across the operating system. And on the macOS side especially, Apple has made numerous small design tweaks to address user feedback, which has been accumulating since Liquid Glass was introduced. There’s nothing radically new in terms of design here, but this is a much-needed polish pass. Across all the releases, but in particular macOS and also iOS, there are a bunch of quality-of-life or performance improvements. For example, macOS now supports HDR for all system UI elements and gets more robust support for a wider range of display modes for external monitors. ↫ Samuel Axon at Ars Technica If youre not into AI!, theres not a lot of meat on these bones, but at least you can turn the AI! nonsense off through a switch buried deep in the settings applications of Apples operating systems (which will probably be flicked back on whenever the next update comes).


  • Switching to GNU Guix: a beginners perspective
    Want to run something a little more exotic on your server? How about GNU Guix? It has been a month since migrating my home server to GNU Guix. Managing OS state declaratively through Git has eliminated configuration drift, and Guile Scheme provides a cohesive environment that complements Emacs. While adapting to a smaller package ecosystem and managing substitute timing requires occasional adjustments, the stability, reproducibility, and container isolation make it a dependable foundation. ↫ Wai Hon Im definitely noticing an increase in interest in Guix lately.


  • The BeBox: one of the most beautifully overbuilt computers of the 1990s
    Late 2000. There is a grey and blue tower PC on my dorm-room desk like nothing anybody who walks into the room has ever seen. The Be logo on the front, a 3.5″ floppy peeking out the bottom of the drive bays, and the vertical grille that hides two columns of green LEDs (blinkenlights) dancing with the CPU load.  This was a dual-PowerPC workstation running an operating system you didn’t see in the wild. I was studying computer science at the time and this was a fun piece of hardware. ↫ J.D. Hodges As a BeOS user in and around 2001 or so, the BeBox was the holy grail of the little community I was a part of. There were some people here and there in online circles who had one, but they were rare even when new, and by 2001, they had become rarer still. This rarity made them mysterious and exciting from almost from the day they were launched, like a small volume halo car few people will ever get to see, let alone experience, first-hand. Its 2026 now, and more and more of the small number of BeBoxen made must be succumbing to degradation and hardware failures. I hope everyone who has one takes good care of them, because these are some of the rarest, most coveted computers of all time. Ive still never seen one, and here in Arctic Europe I most likely never will. Still, I remain hopeful. One day.



Linux Journal News

  • EU OS: A Bold Step Toward Digital Sovereignty for Europe
    Image
    A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem.
    What Is EU OS?
    EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.

    Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments.
    The Vision Behind EU OS
    The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.

    Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.

    However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty.
    Conclusion
    EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.

    Source: It's FOSS
    European Union


  • Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.

    In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.

    On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.

    Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.

    The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.

    Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.

    You can download the latest kernel here.
    Linus Torvalds kernel


  • AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
    Image
    AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.

    This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.

    Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.

    Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.

    Source: 9to5Linux
    AerynOS


  • Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
    Image
    Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.

    Here’s a quick overview of what’s new in Xojo 2025r1:
    1. Linux ARM IDE Support
    Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started.
    2. Web Drag and Drop
    One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required!
    3. Direct App Store Publishing
    Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process.
    4. New Desktop and Mobile Features
    This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection.
    5. Performance and IDE Enhancements
    Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced.
    What Does This Mean for Developers?
    Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution.
    How to Get Started
    Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.

    Download Xojo 2025r1 today at xojo.com.
    Final Thoughts
    With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you.
    Xojo ARM


  • New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux

    Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.

    Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.

    Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest. 

    Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.

    Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.

    Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.

    By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem.
    Windows


  • Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities

    The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally. 

    As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.

    In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions. 

    After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.

    The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.

    At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.

    The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca.
    Security


  • Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges

    The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.

    A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.

    This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem. 

    The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.

    On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.

    In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers.
    kernel


  • Linux Celebrates 32 Years with the Release of 6.6-rc2 Version

    Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.

    The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.

    Here is what Linus Torvalds had to say in today's announcement:
    Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds


  • Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction

    Want to interact with ChatGPT from your Linux desktop without using a web browser?

    Bavarder, a new app, allows you to do just that.

    Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.

    With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.

    During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.

    At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.

    As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!

    Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring.
    ChatGPT AI


  • LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite

    Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.

    Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.

    LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.

    You can download LibreOffice 7.5.3 directly from the LibreOffice websiteor from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.

    All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.

    In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.

    Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.

    The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners.
    LibreOffice


Linux Magazine News (path: lmi_news)




  • Advanced Video Coding Still Under Patent
    Brazilian patent BRPI0109962B1 has expired, which means that DivX and Xvid are no longer problematic for Linux, but it doesn’t mean that video is all of a sudden fully unleashed.








Page last modified on November 17, 2022, at 06:39 PM