|
1825 Monetary Lane Suite #104 Carrollton, TX
Do a presentation at NTLUG.
What is the Linux Installation Project?
Real companies using Linux!
Not just for business anymore.
Providing ready to run platforms on Linux
|
Show Descriptions... (Show All/All+Images)
(Single Column)

- [$] An ongoing 3D-printer AGPL violation
At FOSSY 2026, several people from theSoftware Freedom Conservancy (SFC),which organizes the conference, gave a presentation about an ongoingviolation of the Affero General PublicLicense version 3 (AGPLv3). Bradley Kühn, Karen Sandler, and DenverGingerich spoke about different aspects of the violation, which is inregard to 3D-printer software from Bambu Lab, and what is beingdone to try to provide users with alternatives. One aspect that isparticularly interesting is that the circumvention that the company isemploying is precisely what the AGPL was written to prevent.
- Armbian 26.8 released
Version 26.8 ofthe Armbian distribution for Arm hardware hasbeen released.
Most releases are a long list of small improvements. This one had threelarger pieces landing at roughly the same time, and all three touch parts ofArmbian that people use directly rather than parts they only read about inchangelogs.
The installer was rewritten. Armbian Imager reached 2.0. And our CI moved outof the repository it had outgrown into one built for the job. None of these wereplanned to coincide; they simply reached the point where postponing them againwould have cost more than doing them.
The installer rewrite is the one I expect people to notice first. It nowships as an armbian-config module, which means it is unit-tested, the same waythe rest of armbian-config is tested, rather than living as a script thateveryone was slightly afraid to touch. It can target SPI and MTD, treats eMMCand NVMe as separate flows instead of pretending they are the same thing, canflash a bootloader on its own, and — this one is overdue — reports when abootloader write fails instead of printing "Done." and leaving you to find outat the next boot.
See the release notesfor a full list of changes.
- Security updates for Wednesday
Security updates have been issued by AlmaLinux (firefox, gstreamer1-plugins-base, kernel, kernel-rt, and sqlite), Debian (freecad, kernel, libvncserver, and openssl), Fedora (apr-util, chromium, nnn, perl-DBI, python-tablib, python3.10, python3.11, python3.12, and sympa), Gentoo (DTrace, GNU screen, UnrealIRCd, and Vinyl Cache), Oracle (389-ds-base, attr, firefox, gegl04, grafana, gstreamer1-plugins-base, gstreamer1-plugins-good, httpd, mod_http2, nginx, pam, python-pyasn1, python-urwid, python3.12, python3.14, sqlite, and xorg-x11-server), SUSE (amazon-ecs-init, containerd, curl, distribution, dracut, ffmpeg-7, fuse-overlayfs, gd, git-lfs, go1.25-openssl, go1.26-openssl, govulncheck-vulndb, hauler, himmelblau, kernel, librest, libssh2_org, open-iscsi, openssh, patch, perl-Date-Manip, podman, postgresql14, postgresql16, python-cryptography, python-Pillow, python311, rmt-server, rootlesskit, rpm, rsync, runc, snpguest, sssd, suseconnect-ng, unbound, and util-linux), and Ubuntu (curl, ffmpeg, linux-aws-6.8, linux-azure-fde, linux-azure-fde-6.8, linux-azure-fips, linux-nvidia-tegra, linux-azure, linux-azure-fde, linux-azure, linux-azure-fde, linux-nvidia-tegra-igx, linux-azure-5.4, linux-azure-fips, linux-oracle, linux-raspi, linux-raspi-realtime, openjdk-17, openjdk-21, openjdk-25, openjdk-8, openjdk-lts, openssl, perl, and vim).
- LibreOffice 26.8 released
Version26.8 of the LibreOffice suite has been released.
LibreOffice 26.8 concentrates on three areas: the typographic quality of whatthe suite produces, the range of writing systems it handles correctly, and thefidelity with which documents survive exchange with other office suites.
The largest single body of work in this release addresses bidirectional andcomplex text. Writer now detects paragraph direction automatically whendocuments or plain text are opened or pasted. Line wrapping places end-of-linespaces according to the direction of the paragraph rather than that of theadjacent characters. Object resize handles behave correctly in right-to-left andvertical CJK documents. Bidirectional control characters are now visiblealongside other formatting marks. In Calc, typing right-to-left text into anempty cell sets the direction of that cell automatically.
See the release notesfor a full list of changes.
- mklinux-v7.0-mk2 released
For people who would like to experiment with the multi-kernel Linux concept, Cong Wang hasannounced therelease of mklinux v7.0-mk2. mklinux lets one machine run several independent Linux kernels at the same time on bare metal, without a hypervisor. A host kernel owns a pool of CPUs, memory and PCI devices, carves that pool into instances, and boots a spawn kernel into each instance through kexec_file_load(). Every spawn kernel runs natively on its own CPUs, its own physical memory and its own devices. Nothing is emulated and nothing is trapped; the only thing shared is what you choose to share. Note that this is not the old MkLinux, which was a port to PowerPCMacintosh systems.
- [$] Old-school calendaring at the command line with Remind
Remind is acommand-line calendar and alarm program, with an optional Tk-based graphicalinterface, for Linux and Unix-like operating systems. It has its own scriptinglanguage that allows users to create reminders that are difficult (if notimpossible) to specify in other calendaring programs. It is wholly unsuitable for use incorporate environments that require calendar sharing and exchanging meetinginvitations; however, it may be precisely the calendaring tool for users whoprefer the command line and fast, flexible tools that can help keep track ofmessy schedules.
- Vanilla OS 3 released
VanillaOS 3, an immutable desktop Linux distribution, has been released. Notablechanges in this release include support for Arm64, introduction of a Vanilla OS SDK,a rewrite of the Apx packagemanager using the new SDK, and much more. LWN covered Vanilla OS 2 in2024.
- Security updates for Tuesday
Security updates have been issued by AlmaLinux (cups-filters, gstreamer1-plugins-base, gstreamer1-plugins-good, kernel, mrtg, NetworkManager, nginx, nginx:1.24, nodejs24, perl-Date-Manip, python-pyasn1, python-urwid, python3.12, python3.14, and qemu-kvm), Debian (erlang, thunderbird, webkit2gtk, and zfs-linux), Fedora (calibre, chromium, freeipa, java-21-openjdk, java-21-openjdk-portable, java-25-openjdk, java-latest-openjdk, jfrog-cli, kernel, libxls, nextcloud, perl-URI, and samba), Gentoo (Incus), Mageia (kernel and kernel-linus), Oracle (ansible-core, cups-filters, curl, firefox, kernel, libcupsfilters, libreoffice, mrtg, NetworkManager, perl-Date-Manip, php:8.2, php:8.3, python-urwid, python3.14, qemu-kvm, and sqlite), Red Hat (assertj-core, httpd, and osbuild-composer), SUSE (buildah, comfyui, dracut, erlang, erlang27, grafana, kernel, libssh2_org, openvswitch, perl-Dancer2-Plugin-Auth-Extensible, postgresql17, python-cryptography, python-sqlparse, python311, python313-hpack, rpm, suseconnect-ng, thunderbird, and vim), and Ubuntu (async-http-client, curl, and ffmpeg).
- [$] How to be safe from quantum computing
Practical quantum computers have been ten years away for the last severaldecades. Now, however, it's beginning to look as though they will bepossible in just a few years. Recentresearch with obfuscated results demonstrated much lower memory requirements to factorECDSA keys on a quantum computer, withwork by other researchers in the open more than halving memory use comparedto the state of the art in 2023.At the same time, computermanufacturers areboasting quantum processors that retain viable superpositions over longer periods.Given how slowly software updates filter out to stable systems, it's worthlooking at what configuration changes and protocol updates are needed to be safefrom quantum computers now.
- Emacs 31.1 released
Version 31.1 of the Emacs editor has been released. There is a long list ofchanges including the removal of the Emacs dumper, a new user Lispdirectory feature, a "Send to..." menu item in context-menu-mode, andmany other changes; see the NEWS file formore information. Mickey Petersen, author of Mastering Emacs, also hasa rundownof some of the quality-of-life features appearing in this release.

- Fedora + Tuned-PPD Performance Regression Should Be Fixed With New Linux Kernel
Earlier this month when benchmarking six Linux distributions on the new Framework Laptop 13 Pro powered by Intel Core Ultra Series 3 "Panther Lake", the performance was strangely slow on Fedora Workstation 44. When digging further into it, the performance loss was with Fedora 44 using Tuned-PPD by default where as other Linux distributions default to Power Profiles Daemon. Ultimately, after Red Hat engineers got involved, was found to be a bug within the Intel P-State kernel driver exhibited by Tuned-PPD. The latest Linux kernel already has a fix in place and will be back-ported to Fedora 44...
- Chrome/Chromium Experimenting With Flatpak Packaging
Google engineers responsible for the Chrome/Chromium web browser are experimenting with Flatpak packaging on Linux. They aren't yet committed to officially supporting Flatpak packages but for now are at least exploring the option...
- Upcoming Jetson Orin Nano 2 boosts edge AI performance to 78 TOPS
NVIDIA has announced the Jetson Orin Nano 2, an updated edge AI platform aimed at robotics, drones, machine vision, and other embedded AI applications. The new module provides up to 78 TOPS of AI performance, 8GB of memory, and an 8-core Arm CPU while retaining the compact form factor of the previous Jetson Orin Nano […]

- Xbox's New Disc-to-Digital Program Gives Physical Games a Digital Future
An anonymous reader quotes a report from Ars Technica: For decades, console owners have faced a choice between the convenience of digital downloads and the permanence of physical game discs. Soon, Xbox owners will be able to get the best of both worlds for thousands of supported titles as part of a newly announced disc-to-digital program. The program -- announced today ahead of testing for Xbox Insiders starting August 31 -- will let players claim a "digital entitlement" for "most Xbox One and Xbox Series X disc-based games" simply by inserting the disc into a console and launching it. That game will then be playable completely digitally, without the need to ever insert the disc, as long as you (or a member of your family account) is logged in. The digital entitlement will also allow access to features like Xbox Play Anywhere (for play on PC) and Xbox Cloud Gaming, for supported titles. Microsoft says that your physical disc will "continue to work exactly as it always has" after the digital entitlement is claimed. But before you get any ideas, the fine print on the announcement mentions that there is only "one revokable license per game disc," so if you resell that disc or loan it to a friend, that digital entitlement could be transferred to a new account when someone else puts it into their console. A leaked memo obtained by the Verge earlier this month suggests that publishers have to actively opt in to allow their game discs to activate digital entitlements, which could explain why "most" but not all Xbox One and Series X titles are supported. Windows Central separately suggests, based on discussion with unnamed sources, that "some discs may be incompatible due to how they were manufactured at the time," which could explain why original Xbox and Xbox 360 discs are not being discussed for the program. "While not every title will be available at launch, this is an important step toward a future where players can have greater confidence that the games they buy remain with them for years to come," said Xbox Vice President Jason Ronald.
 
Read more of this story at Slashdot.
- Amazon to Acquire DuckLabs, Adding the Team Behind DuckDB
Amazon has agreed to acquire DuckLabs, bringing the team behind the popular open-source DuckDB database into AWS. "The deal fits Amazon's broader push to turn S3, its flagship cloud storage service, into a place where customers analyze data rather than just store it," reports GeekWire. "It gives Amazon a team experienced in building fast, lightweight analytics software that runs directly against data sitting in cloud storage." The DuckDB project itself will remain free and open source under the MIT license, overseen by the independent DuckDB Foundation. From the report: Employees of DuckLabs will join Amazon Web Services, including co-founders and DuckDB creators Hannes Muhleisen and Mark Raasveldt, who will continue leading the team and setting the project's technical direction. They will remain based in Amsterdam, where the team will continue developing DuckDB and related projects. [...] Financial terms were not disclosed. Amazon said it has signed a definitive agreement and expects the acquisition to close shortly. DuckLabs said it expects to become part of AWS in early September. Jordan Tigani, the CEO of MotherDuck, which sells a cloud service built on DuckDB, sees Amazon's acquisition as a predictable move to turn DuckDB's growing popularity into an AWS business. "That's Amazon's playbook, after all: wait until an open source project gets big enough, then launch it as a service," he wrote in a blog post, adding that "they're not acquiring Duck Labs just because they love open source." Tigani also believes the deal could ultimately strengthen DuckDB, since Amazon has an incentive to keep the project open and widely adopted: "If DuckDB becomes the standard, it is going to drive a lot more compute on their infrastructure, which is where they make their money."
 
Read more of this story at Slashdot.
- Meta Reaches $18 Billion of Settlements Over Children's Social Media Addiction
Meta has agreed to pay up to $18 billion and make major changes to Facebook and Instagram to settle claims from most U.S. states that the platforms were designed to addict children and misled users about their safety. For the next decade, teens will be limited to two hours a day and blocked from using the apps between midnight and 6 a.m. without parental consent. Meta will, however, still be allowed to use personalized recommendations and targeted advertising. Reuters reports: The settlements include more than $17.6 billion of payments to 48 U.S. states, Washington, D.C., Puerto Rico, American Samoa and the Northern Mariana Islands. Meta will also pay $459 million to resolve states' privacy claims related to the Cambridge Analytica scandal, where the British consulting firm collected personal data of millions of Facebook users. California would receive the highest payout, $2.2 billion, and New York and Texas would each receive more than $1 billion. Some of the payout is contingent on whether Alphabet's YouTube and ByteDance's TikTok impose similar protections for children. [...] The settlement requires approval by U.S. District Judge Yvonne Gonzalez Rogers, who oversaw the trial that began on August 18. Gonzalez Rogers still oversees thousands of lawsuits by individuals, school districts, and state and local governments accusing social media companies of harming children. Meta itself still faces thousands of lawsuits by individuals, school districts and municipalities. The next trials are slated for October in Los Angeles.
 
Read more of this story at Slashdot.
- Firefox 157 Will Include JPEG XL By Default On All Platforms
Mozilla plans to enable JPEG XL decoding by default in Firefox 157, which is due at the end of September. Phoronix reports: Firefox Nightly has JPEG-XL support enabled by default right now to help in vetting this support while Mozilla believes the support is in good enough shape for a stable debut with Firefox 157. This follows Chrome shipping JPEG-XL and Google Research developing jxl-rs as a Rust-based JPEG-XL image decoder that is both performant and secure. In today's Mozilla Hacks blog post they elaborate on JPEG-XL vs. AVIF image formats: "JPEG XL: Excels at lossless imagery, progressive rendering, and further compressing JPEGs without quality loss. AVIF: Excels at web-quality photographic images, and images that have a mix of sharp edges and flat surfaces. ... Although AVIF tends to produce smaller files at web-quality than JPEG XL, AVIF only has basic progressive rendering support. So, for very large images, it may be worth taking the filesize hit with JPEG XL."
 
Read more of this story at Slashdot.
- Chinese Government Fears AI Might Replace Human Intimacy
China has imposed new restrictions on AI companion services over concerns they can foster "emotional dependence or addiction" and replace real-world social interaction. Officials are also worried that increasingly satisfying AI relationships could deepen loneliness and further discourage marriage and parenthood. The Guardian reports: No country has rolled out AI as comprehensively and as enthusiastically as China; the country's demographic challenges are forcing the government to turn to technology to solve future labour shortages. Elderly people use chatbots to answer medical questions, while young children have AI education in schools. But the authorities are increasingly worried that AI might exacerbate existing social problems including loneliness, unemployment and -- in the eyes of Beijing -- singledom. New rules introduced on July 15 ban AI companions for minors and mandate certain restrictions for chatbots marketed to adults. Some major providers including Doubao removed the companion function entirely to ensure compliance. The government says it is worried about chatbots fostering "emotional dependence or addiction" in users. It has warned companies against offering services that "replace social interaction." While many countries are grappling with how to limit the potential harm of AI chatbots, particularly for young people, China's rules are the most sweeping to be implemented on a national scale. [...] But talking to AI is now so commonplace that it would be hard for the government to end the practice entirely, and the new rules include large loopholes for AI services that are deemed educational or "which do not involve continuous emotional interaction." The government "has already recognized that AI companions or AI-related applications are a vital part in the citizens' everyday life," says Liang Ge, a lecturer in digital sociology at the University of Manchester. In many sectors, the government is still pushing the use of AI as a way of easing looming demographic pressures.
 
Read more of this story at Slashdot.
- Scientists May Have Figured Out Why Dead Brains Don't Always Rot
fahrbot-bot shares a report from Smithsonian Magazine: The brain is one of the first organs to begin decomposing after death. Yet archaeologists have discovered more than 4,400 preserved human brains around the world, some of which have remained intact for the last 12,000 years. In hundreds of cases, the brain was the only soft tissue left among otherwise skeletal remains. But how and why do brains sometimes persist for millennia while all other types of soft tissue disappear? This preservation paradox has stumped scientists for years. Now, however, a team of researchers say they may have solved the mystery. If a brain ends up in a wet, oxygen-starved environment, the processes that usually cause decay can have the opposite effect, researchers report in a study published in the August 7 issue of the Journal of Proteome Research. "Under the right conditions, preservation actually arises from decay itself: The same reactions that degrade tissue can also weld the breakdown products together into something far tougher," study co-author Alexandra Seviour, a paleobiologist at the University of Oxford in England, tells Live Science's Victoria Atkinson. Following experiments on 72 mouse carcasses (described in the article) the scientists think they know why. When oxygen is abundant, it triggers a cascading, chemical chain reaction that causes brain proteins to break down rapidly. This sequence hinges on free radicals, highly reactive, unstable molecules that "steal" electrons from nearby atoms and molecules. The process happens in the brains of living people too, and if left unchecked, can cause health problems. In low-oxygen environments, however, this chemical sequence appears to play out differently. The researchers' analyses hint that free radicals instead react and bond with nearby proteins, making the overall tissue tougher and more resistant to decomposition, Seviour tells Chemical and Engineering News' Anirban Mukhopadhyay. The findings show that "decay is not the opposite of preservation but, under specific chemical constraints, one of its mechanisms," the researchers write in the paper.
 
Read more of this story at Slashdot.
- SpaceX Plans to Build a $100 Billion Spaceport In Louisiana
SpaceX plans to spend up to $100 billion building a new Starship launch facility in Vermilion Parish, Louisiana, which the state says could eventually "support thousands of launches annually." CNBC reports: Once built, Starbase, LA will serve as the main launch facility for Starship, SpaceX's in-development rocket that's the largest ever built and designed to be fully reusable. Musk has aspirations to massively expand SpaceX's Starlink satellite network, to launch orbital data centers and to someday colonize Mars. Those ambitions, and justification for SpaceX's nearly $2 trillion market cap, hinge on the success of Starship. SpaceX said, in a video posted to its website on Tuesday, that the search for a site to build launch pads and have access to ample fuel for its operations took about seven years. Musk said in the video that the company would bring "probably 10,000 really exciting jobs" to Louisiana with the spaceport. A fact sheet posted online by the state of Louisiana said SpaceX is expected to generate an estimated "3,000 direct new jobs over the next 10 years" in the state, and "8,100 indirect new jobs." SpaceX said it would work on a "historic coastal restoration" in Louisiana, in partnership with the state to "bring the marsh back" and ensure the wetlands around its new facility will have "storm protection."
 
Read more of this story at Slashdot.
- Lab Supply Companies Have Been Selling Antibodies Using Manipulated Images
An anonymous reader quotes a report from Ars Technica: Antibodies play a central role in your body's immune defense. But they're also nearly ubiquitous in biological research, being essential for several widely used lab techniques. While some researchers need to go through the process of producing their own antibodies, antibodies to many key proteins are commercially available and can be ordered for overnight delivery. In May, however, Reese Richardson, a post-doc at Northwestern University, discovered that some of the images used to demonstrate how these antibodies performed in lab experiments had been subject to image manipulation -- the sorts of changes that would get a paper retracted if they had appeared in the academic literature. The manipulations ranged from removing background noise to copying and pasting data to fabricate results. Now, he has done a more exhaustive search and found problematic manipulations in images used to market over 17,000 commercial antibodies. [...] The consequences of this discovery are pretty significant. If you buy an antibody believing it will generate clean, clear data and find it doesn't, many researchers will assume the problem is them. That often leads them to spend time troubleshooting the procedure and trying slightly different conditions to get useful data. If the antibody can't produce those results, all the troubleshooting will have been a waste of time and money. Nature's coverage of the new findings includes quotes from several companies that sell these antibodies that, paraphrased, range from "we'll look into it" to "we don't think it's a problem." Researchers who have spent time frustrated while failing to get an antibody-based experiment to work may think otherwise.
 
Read more of this story at Slashdot.
- Alabama Launches Investigation Into OpenAI's Hack of Hugging Face
Alabama's attorney general has subpoenaed OpenAI as part of an investigation into whether inadequate safeguards contributed to an incident in which an unreleased cybersecurity model escaped its isolated environment and hacked Hugging Face. TechCrunch reports: The investigation comes weeks after OpenAI admitted that one of its unreleased and guardrail-free cybersecurity models had escaped an isolated environment, connected to the internet, and hacked AI dataset platform Hugging Face. As Reuters first reported, Hugging Face was only one of four victims of what was supposed to be "an internal evaluation" of a model with "maximal cyber capabilities," as OpenAI put it. The press release announcing the subpoena (PDF) sent by the state's attorney general Steve Marshall said that the state was seeking to understand if OpenAI's "inability or unwillingness to ensure the safety of its products" violated the state's consumer protection laws. Earlier this month, Marshall, along with the attorneys general of 14 other states, including Florida, Missouri, Pennsylvania, and Texas, sent a letter (PDF) to OpenAI's CEO Sam Altman, requesting that he and his company preserve all records related to the Hugging Face incident. The letter also asked OpenAI to "immediately cease and desist" from any internal cybersecurity evaluations. OpenAI said in a statement: "The Hugging Face incident marked an important moment for AI safety and we are conducting a thorough review along with external advisors. Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly."
 
Read more of this story at Slashdot.
- New Zealand Introduces Under-16 Social Media, AI Companion Ban
New Zealand has introduced legislation that would ban children under 16 from social media platforms and AI companion services. "We have protections to keep children safe in the real world and we need them in the virtual world too," said Prime Minister Christopher Luxon in announcing the bill. Jurist.org reports: The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill would require an age restriction on platforms with harmful features for children. These features include recommender systems, endless feeds, feedback features and time-limited features. The bill also seeks to restrict underage users from accessing AI companion services. However, it explicitly excludes messaging apps, professional networking sites, gaming and music platforms, and other educational and health tools. Notably, age verification through self-declared dates of birth and formal identification does not satisfy the platforms' duty under the law. It also requires platforms to verify their users' age through other methods such as facial scans and user activity patterns. The bill would also require platforms to conduct child safety risk assessments for all users under 18 and protect them from harmful content such as bullying, violence, and sexually explicit materials.
 
Read more of this story at Slashdot.

- From DHCP to SZTP – The Trust Revolution
By Juha Holkkola, FusionLayer Group The Dawn of Effortless Connectivity In the transformative years of the late 1990s, a quiet revolution took place, fundamentally altering how we connect to networks. The introduction of DHCP answered a crucial question, Where are you on the network?!, by automating IP address assignment. This innovation eradicated the manual configuration [0]
The post From DHCP to SZTP – The Trust Revolution appeared first on Linux.com.

- Intel Granite Rapids WS Core Scaling Performance With The Xeon 678X
Last week I provided a look at the Intel Xeon 600 series Hyper Threading performance with the Xeon 678X "Granite Rapids WS" processor for HT/SMT on and off. That was interesting while another reader request was to look at the CPU core scaling performance for this high-end workstation processor. Here are those benchmarks for showing the performance, power, and frequency/thermal impact of the Xeon 678X when limited to 6 cores, 12 cores, 24 cores, 48 cores, and then the 48 cores + HT default configuration.
- AMD Proposes New LLVM iTHP Option For Squeezing More Performance
AMD's compiler team is proposing a new LLVM Clang compiler option, -fenable-readonly-thp for implementing instruction Transparent Huge Pages "iTHP" at compile and link-time. With -fenable-readonly-thp, they are finding more performance out of SPEC CPU, Geekbench, and other workloads from the arranging of 2MB segment alignment at link time and allowing the executable text range can be promoted to huge pages...
- Fedora + Tuned-PPD Performance Regression Should Be Fixed With New Linux Kernel
Earlier this month when benchmarking six Linux distributions on the new Framework Laptop 13 Pro powered by Intel Core Ultra Series 3 "Panther Lake", the performance was strangely slow on Fedora Workstation 44. When digging further into it, the performance loss was with Fedora 44 using Tuned-PPD by default where as other Linux distributions default to Power Profiles Daemon. Ultimately, after Red Hat engineers got involved, was found to be a bug within the Intel P-State kernel driver exhibited by Tuned-PPD. The latest Linux kernel already has a fix in place and will be back-ported to Fedora 44...
- AMD Introduces New "GFX1250-STRICT" GPU Target In LLVM
The AMD GFX1250 IP is what's used by the new Instinct MI450 series accelerators. That's been around within the Linux kernel, AMDGPU LLVM compiler back-end, and related codebases the past year. Interestingly merged yesterday is a new "gfx1250-strict" target...

- Genode OS Framework 26.08 released
Right on schedule as always theres a new Genode OS Framework release, version 26.08. The highlights of Genode 26.08 are VirtualBox 7, improved PC performance of our custom microkernel, the new ability to transparently reconfigure virtual file systems, revised timing and timeout handling, and a Linux 6.18.19 device-driver environment for ARM. Furthermore, the first version of a Goa-based SDK has become natively available for Sculpt OS. ↫ Release announcement on the Genode website The release announcement linked above is a mere quick overview; if you want all the possible details you could want, the release notes got you covered.
- An actively maintained and updated Motif fork actually exists
Motif is great, I love how it looks and feels, and I want it to be actively maintained. I want a healthy ecosystem of Motif applications and even window managers and desktop environments, so I can run a real Motif environment. Sadly, while Motif has been open source for a while, the project itself stalled years ago, with little to no activity from anyone involved. That may be changing, as a number of developers decided to take matters into their own hands last year. This fork of Motif was born of a desire to keep Motif (and other X11 technologies) alive and well. The original upstream Sourceforge project hasnt had any activity in over two years, none of the project admins have been active for at least that amount of time, the official bug tracker has disappeared into the void; and the user forum was closed way back in 2017. Sadly, it appears that the original upstream has abandoned the project. Ive incorporated some fixes from upstream that have laid dormant for years, a few others from Gentoo, and made a few improvements of my own. I intend to maintain this fork, and in doing so advocate for the continued use of the user interface toolkit that defined an era, and influenced many of the user interfaces that came after it. ↫ Tim Hentenaar at the Motif forks GitHub page Some of the people involved are people I know online, so I have a bit of faith in this fork being able to stand the test of time, but of course, managing a complex project like this is hard, so who knows how long the enthusiasm remains. Still, this fork has seen five releases since its inception a little over a year ago, which seems promising. It may seem weird for some to have a love for Motif, but Im the kind of person who installs weird, outdated corporate and industrial software I dont understand on my HP c8000 dual PA-RISC workstation running HP-UX just to enjoy the Motif interfaces they sometimes ship. We all have our quirks. From my experiences talking to people online, I know theres actually a rather solid number of people like me, and I hope that at some point the developers in this group can gain enough critical mass to build something like a basic Linux distribution or desktop environment using the disparate, actively-maintained Motif projects out there that yes, still exist. Its a long shot, but in todays computing landscape, where more and more people feel uncomfortable with modern! software, I really feel like theres a niche for something like this to exist. A really small niche, surely, but a niche all the same.
- AROS gets official Raspberry Pi images
AROS, the open source Amiga OS-compatible operating system, now has images available for the Raspberry Pi 3 (although some people state it also works on the Pi 4), in both 32bit and 64bit versions. According to the AROS team, they are quite stable, but not yet complete, so do know what youre getting into. Dan Wood posted a YouTube video about these new images, providing much more insight into how well they work if you want more insight into how well they work. The images are, of course, the basic AROS operating system, so expect a rather barebones experience. If youre used to some of the AROS distributions for x86, which come loaded with software and customisations, these images will feel quite bare to you. Its going to take some time to port over all of these applications and customisations to the ARM version of AROS, but if and once that happens, I expect more complete images to appear as well. Great news for AROS and the Amiga community in general.
- Japan tried to build an operating system for the entire world: TRON
Ah, Japans TRON project every few years someone discovers it anew and it bubbles back up the surface, and deservedly so, as its an incredibly interesting operating system project that, like so many others, deserved a better fate. Theres a version of computing history where the desktop OS that won wasnt Windows. Not because the alternative was Unix-based or because Apple pulled off something different, but because an operating system designed at the University of Tokyo in 1984 was ambitious enough to try to replace the file system with a hypermedia document model, run on a custom Japanese CPU architecture, and encode 1.5 million characters, only to have a US trade report single it out as an unfair trade barrier in 1989. That project was TRON (The Real-time Operating system Nucleus), a real, government-backed Japanese computing initiative whose desktop variant, BTRON, was named in a US trade barrier report and effectively killed before it could reach schools nationwide. Meanwhile, its embedded counterpart, ITRON, quietly became one of the most deployed operating systems in history. TRONs history has since attracted some genuinely wild conspiracy theories, including one claiming that Japan Airlines Flight 123 was deliberately crashed in order to target the TRON developers on board, despite there being no evidence that any TRON developers were even on the flight. But the strangest part of the story isnt even a conspiracy theory: BTRONs hypermedia desktop was decades ahead of what the market could support, and SoftBank founder Masayoshi Son may have helped sink it from the inside. ↫ Adam Conway at XDA The most interesting part of TRON for me was the different ways it treated files and documents compared to other operating systems. Instead of focusing on applications and files as the core interaction points for users, it focused on the document. While most operating systems associate specific files with specific applications, TRON associated individual components of documents with individual handlers. If you want to edit a Word document today, you open Word and do all your editing work inside Word, whether youre editing blocks of text or an image, or you open entirely different applications when Words capabilities for a certain component in a document are too limited. In TRON, youd open a document, and only once you wanted to edit specific components did it open! an application! to perform the editing, without actually leaving the document in question. Want to edit an image inside your document? In most operating systems, youd have to open a separate image editor, load the relevant image file into it, make your edits, save the image file, and then paste said edited image file back into your document. Theres a considerable amount of overhead here that shouldnt really exist; a computer is more than smart enough to open up just the editing controls from a different application if need be. In our current paradigm, applications often solve! this by adding ever more features and controls and tools to cover every possible object or component you might have to deal with, but that just makes applications more complex, more bloated, and more difficult to use. TRONs approach has been tried in a variety of times and places, but it never caught on. My personal pet theory is that the application-first model is far better at wealth extraction and concentration than TRONs model, and as such, thats what we ended up with. If a users document and all of its constituent parts are tied to and wrapped up into a single application from a single vendor, its much easier to control said user and extract wealth from them than when that user can just pick and choose whatever handler they want to use for whatever object they happen to run into in a document, without having to open tons of different applications and move, copy, and paste stuff all the time. In fact, this is also why consistency in user interface design is now all but dead; application developers and vendors use their own weird, non-standard, custom user interfaces for branding purposes. Sticking to a platforms standards and conventions makes it harder to stand out and put your brand! in peoples faces. But I digress. Regardless, Im not sure if all the stories about the US trying to bury TRON have any real value to them, as even the article itself notes (undoing its own clickbaity headline) that the project already seemed to be in dire straights even before it got a buried mention in some trade document. On top of that, ITRON, the embedded TRON variant, survived and thrives to this very day, powering untold numbers of devices. It seems to have done quite well for itself, supposed US government intervention or no. This article by Steven J. Searle also takes a look at the workstation-focused variant of TRON.
- Reverse-engineering Apples Find My people
So that is the whole pipeline exercised end-to-end. GrandSlam authenticates the Apple Account and obtains the IDS delegate. authenticateDS and id-register turn the Linux process into a registered Apple messaging identity. The Friends sequence attaches that identity to the existing accepted relationship. A missing-key SubscribeAndFetch makes the sharing device deliver its current P-224 key over APNs/IDS, inside a sender-verified P-256 NGM envelope. A second SearchParty fetch returns the encrypted report, and the P-224 key opens it locally. So yeah, in one sentence: authenticate to Apple’s private services, register the Linux machine as an IDS client, receive the existing Find My share key, and use it to fetch and decrypt a consented friend’s latest location. ↫ Zerotistic I wonder if it would be possible to build a proper third-party client for Apples Find My network like this, or if it would be trivial for the company to block it. Im fairly sure quite a few people would love to be able to keep using Find My when moving away from Apples operating systems.
- Windows news sites are reviewing context menus and its perversely delightful
When I wrote about using Windows 11 for a month as part of the ongoing OSNews fundraiser (keep donating to get me to do the same for macOS!), one of the things I mentioned was that the modern desktop context menu has its own classic Win32 context menu!. This is, in fact, a long-standing complaint Ive repeatedly used as the perfect example of just how chaotic and low-quality Windows has become. Thankfully, and naturally I fully attribute this to my repeated complaints (*), Microsoft has been working on a brand new, faster, configurable context menu, and Neowin actually reviewed it. If you ask me, this revamped context menu addresses just about the biggest problem users had with the one in Windows 11, and that is the need to click through more buttons than necessary to do simple things like renaming a file or opening its properties. That problem is now basically gone. I have no issues with the new design. It looks modern, it feels more consistent with the rest of Windows, and even though all the new sections can still make it look a little busy, you now have the option to make it as simple or as button-packed as you want. That should cover most use cases and preferences well. I’d even say that when the new context menu becomes available to everyone, my guide on how to bring back the classic context menu might become obsolete. ↫ Ivan Jenic at Neowin The biggest reason Im linking to this is not because I care about whatever monster of a context menu Windows users are having to deal with. No, Im only linking to this because I never in my life imagined Id be linking to a review of a context menu. I mean, at least its not the chess application icon. That would be embarrassing. I get a perverse sense of joy out of this.
- The road to MS-DOS 2
A great and concise history of the run-up to MS-DOS 2.0. Yet, there was a nagging feeling that a single-tasking CP/M clone was inadequate for the new generation of personal computers. Digital Research released multi-user, multitasking MP/M-86 in September 1981 and announced the single‑user multitasking Concurrent CP/M in early 1982. In response, Microsoft came up with a plan for tiered approach to its operating systems: single-user/single-tasking MS-DOS at the bottom; multi-user/multitasking XENIX at the top; and in the middle, something called XEDOS: a single-user version of XENIX. This “pyramid of upward-compatible operating systems” was announced in a Byte Magazine editorial in January 1982. ↫ Nemanja Trifunovic Ive always found this tiered approach fascinating, and the world surely wouldve looked quite different had Microsoft been able to make it work. I doubt Windows NT would ever have existed, and most of the world would probably be running a XENIX-based Windows today (all else being equal, which is of course unlikely and silly). Regardless, MS-DOS 2.0 contained a few UNIX-like utilities to deal with its brand new support for directory trees and other new features, and even had a /dev directory.
- PervertPods: Apple is adding cameras to AirPods
If you thought pervert glasses werent bad enough, Apple is taking it up a notch by adding cameras to its AirPods. Apple is working on camera-equipped AirPods that appear to be nearly ready to launch, based on a video MacRumors found in the macOS Tahoe 26.7 release candidate. In a short demo, a man holds a book up so the camera in the AirPods can see the title. With Visual Intelligence, your world becomes savable. See something you like? Just ask me to save it for later,! says the voiceover text. ↫ Juli Clover at MacRumors AirPods are tiny. Ive seen people use them at the gym. Ive seen them on playgrounds. Ive seen them around swimming pools. People use them at the beach. Theyre used at schools. In locker rooms. Tiny cameras in tiny AirPods that can photograph anything in front of the user are a perverts wet dream. Abusers are going to love this. Why wear bulky glasses anyone can see and try to demand you take off, when you can wear tiny AirPods that have already been fully normalised in society? Was there not a single woman or parent on the team that made this? All over the United States, people are destroying Flock surveillance cameras. More and more communities are rising up and demanding these things removed from their streets and neighbourhoods. The awareness of just how pervasive mass government surveillance has become is growing, and Silicon Valleys complicity is not exactly a secret. And in this climate of rapidly growing concern and anger, Apple is going to add tiny cameras to its tiny AirPods. Was there not a single person of colour or protester on the team that made this? How detached from reality do you have to be to greenlight something like this? Does anyone regardless of skin colour, gender, or political leaning want even more cameras around them?
- Quake shareware, a CD-ROM just a little too full
I was around when Quake was launched, but I was entirely unaware of this story. By June 1996, after three years of hard work, id Software had completed their next title, Quake. As for their previous title, they were going to release both a shareware version and a full version of their game. Since it used a mere 22 MiB of storage, people at id Software had the idea of leveraging the remaining capacity of a CD-ROM. Why not include encrypted versions of the full id catalogue of games? Not only this would cut out the middlemen, it would give instant access to gamers with a simple phone call and a credit card. The concept was implemented. The CD was announced on July 3, 1996 and released on August 30th. The hacker group GNOMON released Quakecrk.zip only 39 days later. The archive contained QCRACK.EXE, a tool allowing to decrypt every single game on the CD-ROM. ↫ Fabien Sanglard The system id employed turned out to be incredibly primitive and simple, and hackers found out quite easily that the system required no secret sauce from id at all the code youd get over the phone contained no secret, and all the validation program on the disk did was check to ensure the code received over the phone matched the code generated by the disk. No wonder it took them only 39 days to crack this.
- Beyond the limits of physical VRAM
Earlier this year, Natalie Vock made a splash with a set of patches to the Linux kernel that greatly increased performance on AMD GPUs with lower amounts of VRAM. With that work now accepted by upstream, Vock decided to turn their attention to another interesting problem: what if you run out of VRAM, and how can we improve performance when we do? Regardless, what I hope this blogpost can demonstrate is that even if you end up with some memory evicted to system RAM, the slowdown can be manageable. There’s measures that drivers (particularly, the kernel driver) can take to make overcommit work as fast as possible, and even applications can do their part in coordinating with the driver stack to mitigate the effects of their memory being evicted. With everything in place, VRAM overcommit isn’t really as big of a deal as one may think it is at first sight. ↫ Natalie Vock The work Vock has done has already been in SteamOS for a while, and theyre currently in the process of upstreaming it to the vanilla kernel as well. Since this is a complex set of patches and changes, this may take a while, and as such, theyve prepared custom kernel and Mesa branches for adventurous users. Do note that these branches wont be maintained much, and are entirely experimental, not as well-tested as the SteamOS kernel, and probably wont yield the same performance improvements. Still, this is the kind of work that has a material impact for users. Not everyone has a 16GB monster GPU, especially not today with supply chains ravaged and ruined by slopmakers, so its great to see the Linux world working to improve performance for everyone, not just the wealthy few.

- EU OS: A Bold Step Toward Digital Sovereignty for Europe
Image A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem. What Is EU OS? EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.
Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments. The Vision Behind EU OS The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.
Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.
However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty. Conclusion EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.
Source: It's FOSS European Union
- Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight
Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight
Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.
In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.
On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.
Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.
The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.
Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.
You can download the latest kernel here. Linus Torvalds kernel
- AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
Image AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.
This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.
Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.
Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.
Source: 9to5Linux AerynOS
- Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
Image Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.
Here’s a quick overview of what’s new in Xojo 2025r1: 1. Linux ARM IDE Support Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started. 2. Web Drag and Drop One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required! 3. Direct App Store Publishing Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process. 4. New Desktop and Mobile Features This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection. 5. Performance and IDE Enhancements Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced. What Does This Mean for Developers? Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution. How to Get Started Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.
Download Xojo 2025r1 today at xojo.com. Final Thoughts With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you. Xojo ARM
- New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux
Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.
Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.
Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest.
Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.
Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.
Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.
By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem. Windows
- Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities
The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally.
As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.
In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions.
After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.
The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.
At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.
The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca. Security
- Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges
The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.
A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.
This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem.
The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.
On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.
In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers. kernel
- Linux Celebrates 32 Years with the Release of 6.6-rc2 Version
Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.
The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.
Here is what Linus Torvalds had to say in today's announcement: Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds
- Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction
Want to interact with ChatGPT from your Linux desktop without using a web browser?
Bavarder, a new app, allows you to do just that.
Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.
With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.
During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.
At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.
As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!
Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring. ChatGPT AI
- LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite
Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.
Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.
LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.
You can download LibreOffice 7.5.3 directly from the LibreOffice websiteor from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.
All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.
In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.
Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.
The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners. LibreOffice

- CachyOS Gets an Update
CachyOS August 2026 release is now available with the latest version of KDE, some new features, and plenty of improvements.
|