Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All) (Two Column)

LWN.net

  • Kernel prepatch 7.3-rc5
    The 7.3-rc5 kernel prepatch is out fortesting. Linus said: "I don't think there's any real pattern to itother than 'big'. But nothing looks particularly alarming, I think thatdespite the diffstat it's just the same old, same old."


  • GDB 18.1 released
    Version 18.1 of the GDB interactive debugger has been released. Changesinclude new commands to manipulate the environment of the subprocess, theability to save the command history to a file, support for a couple of newtargets, several Python API additions, and more. See theNEWS file for the complete list.


  • [$] How KDE got funding to add enterprise features
    The Sovereign Tech Agency (STA) isinvesting nearly €1.3 millionin KDE through 2027. At Akademy 2026in Graz, Austria, Nate Graham and Kevin Ottens, two of the contributors whohelped bring in the investment, explained how the funding was secured, providedtips on how projects should approach organizations like STA, and talked abouthow that money will be improving KDE for everyone. In addition to keeping thecommunity informed about the work, the pair hoped to pass on what they have learnedto encourage others to help raise funds for development as well.



  • A summary from the 2026 Git Contributors' Summit
    Johannes Schindelin has posted a detailedsummary of the discussions held at the 2026 Git Contributors' Summit.Topics covered include Git 3.0, security process, documentation, thepluggable object database, use of LLMs, and more.


  • Security updates for Friday
    Security updates have been issued by AlmaLinux (kernel, kernel-rt, perl-DBI:1.641, and unbound), Debian (jq, libreoffice, openssl, and redis), Fedora (389-ds-base, bcm283x-firmware, cockpit, flatpak-builder, mingw-gdk-pixbuf, openssl3, pcs, rust-cryptoki, squid, uboot-tools, and webkitgtk), Mageia (fuse3, perl-Net-DNS, python-gitpython, python-webob, thunderbird, thunderbird-l10n, and unbound), Oracle (postgresql:12, postgresql:15, postgresql:16, and skopeo), Slackware (php), SUSE (alloy, amazon-ssm-agent, ant, apptainer, chromium, corosync, cyrus-imapd, distribution, exiv2, ffmpeg-7, freeipmi, gdb, gnome-remote-desktop, google-osconfig-agent, govulncheck-vulndb, gvfs, hplip, ImageMagick, imagemagick, java-11-openjdk, jsoup, re2j, kernel, keybase-client, libsoup, libx11, libxrender, mcphost, memcached, opensc, perl-DBI, python-gitpython, python-weasyprint, rabbitmq-server, ruby3.4, util-linux, and zstd-jni), and Ubuntu (curl, expat, gdal, libass, libpcap, linux, linux-aws, linux-aws-7.0, linux-hwe-7.0, linux-ibm, linux-oracle, linux-raspi, linux-realtime, linux, linux-azure, linux-azure-6.8, linux-azure-fde, linux-azure-fde-6.8, linux-azure-fips, linux-fips, linux-gcp, linux-gcp-6.8, linux-gcp-fips, linux-gke, linux-gkeop, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oracle, linux-oracle-6.8, linux-raspi, linux-raspi-realtime, linux-realtime, linux-realtime-6.8, linux, linux-hwe, linux-kvm, linux-aws, linux-aws-fips, linux-azure, linux-azure-fde, linux-azure-fips, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-intel-iot-realtime, linux-intel-iotg, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle, linux-realtime, linux-xilinx-zynqmp, linux-aws, linux-gcp, linux-gcp-4.15, linux-gcp-fips, linux-aws-fips, linux-ibm-5.15, linux-intel-iotg-5.15, octavia, and swift).


  • F-Droid 2.0: A new chapter for Android freedom
    The F-Droid project has announcedthe release of F-Droid 2.0, which is a complete redesign of the officialapp. Notable changes in the release include making it easier to discover andinstall applications, more useful app categories, improved search, andmuch more.

    For more than a decade, F-Droid has helped people discover and install freeand open source Android apps. F-Droid 2.0 builds on that foundation with amodern interface, better app discovery, improved search, and a simplerexperience that works well, whether you're new to F-Droid or have been using itfor years.

    This isn't just a visual refresh. The user experience was redesigned tointegrate smoothly with current Android patterns, like Material Design, whilekeeping familiar F-Droid interactions in place. Key components were reworked andrewritten using Kotlin Compose, the standard toolkit these days, creating afoundation that will help us deliver improvements more quickly in the yearsahead.



  • Research into file-notification attacks on Linux
    Sudheendra Raghav Neela, a member of a group of researchers from Graz University of Technology, has announced therelease of research into file-notification attacks that would allow spying onuser activity on Android, Linux, macOS, and Windows. The group has published a paper withdetails on the research as well as a web sitewith demonstrations of the vulnerabilities.

    On Linux, an attacker can use inotifywatch tomonitor a directory to conduct an inter-keystroke timing attack—even ifthey do not have read access to the files within a directory. The group alsodiscovered a method to conduct a UI-redressattack (or "clickjacking" attack) onKDE 5 and KDE 6 by monitoring /usr/bin/pkexec to detect when Polkit spawns an authenticationprompt. An attacker could draw a fake password window on top of the real windowto collect a user's credentials.

    Both of these flaws are still present today,though the Linux kernel did partially mitigate the issue with afix that was included in the 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.65,and 6.18.3 kernels shipped in January. See the web site for more information anda mitigation to prevent password-prompt windows from losing focus.


  • [$] Listening to the radio with Rust
    Many of the transmissions sent over the radio spectrum canbe decoded with a relatively cheap hardware dongle. Thomas Eckert presented atRustConf 2026 in Montreal about his hobby:decoding radio transmissions with Rust.In his presentation, hecovered all of the math necessary to get started withsoftware-defined radio,and gave demonstrations of listening to AM and FM radio, as well as decodingtransmissions fromaircraft transponders. His slides and example code areavailable on GitHub.


  • The Kernel Report 2026 edition
    After a two-year hiatus, LWN's Jonathan Corbet presented an updated editionof his KernelReport at the KernelRecipes conference. Corbet looked at what is happening in the kernelcommunity, how it's dealing with a period of accelerated change, and wherethings might go in the future. Video of the talk isavailable on YouTube for those who'd like to tune in.



LXer Linux News

  • ESP32-S3 powers EWatch smartwatch with open drivers and DIY options
    EWatch, developed by Ewan Wills, is a programmable ESP32-S3 smartwatch with a 1.69-inch color touchscreen, 350mAh battery, vibration feedback and USB-C connectivity. The platform is offered as a bare PCB, self-assembly kit or complete watch, following more than five years of development. The EWatch hardware is built around the ESP32-S3, with Wi-Fi and Bluetooth Low […]





  • Everything About /proc File System on Linux
    In this article, you'll learn about the proc file system (short for "procfs", referring to the "/proc" directory) and how it's useful to check the running processes related information on Linux.






  • Pocket-sized OpenWrt router offers dual-band Wi-Fi 5 and Gigabit Ethernet
    GL.iNet has unveiled the Mango 2 (GL-MG1300), a compact travel router with dual-band Wi-Fi 5, Gigabit Ethernet and USB 3.0. The device supports WireGuard and OpenVPN, along with Ethernet, Wi-Fi repeater, USB tethering and USB cellular modem connections. The Mango 2 is powered by a dual-core MediaTek processor running at 880MHz, although GL.iNet does not […]


Error: It's not possible to reach RSS file http://services.digg.com/2.0/story.getTopNews?type=rss&topic=technology ...

Slashdot

  • Are AI Chatbots Spreading Misinformation to US Voters?
    Are AI chatbots quietly shaping the perceptions of U.S. voters? Voters trying to educate themselves about candidates "are unknowingly being served partisan talking points in the guise of neutral news summaries," write two news researchers in Politico magazine:Leading AI chatbots cite partisan websites masquerading as independent local news outlets nearly half of the time when people ask about candidates and issues that the partisan sites have covered in the midterm campaign, according to a new audit by NewsGuard, an organization focused on news reliability where we work as analysts... NewsGuard prompted seven leading AI tools with queries based on recent coverage of candidates and issues by 12 pink slime sites — six left-leaning and six right-leaning. The results were stark. Collectively, the chatbots cited pink slime sites along with other sources in 48.2 percent of their responses. In 7.7 percent of responses, pink slime sites were the only sources at all that were cited in chatbot responses, although other sources appeared in the source list provided at the end of the response. None of the AI tools received results they'd probably be eager to boast about, though the percentage of chatbots' responses that cited a pink slime site had a relatively large range: 70.8 percent for OpenAI's ChatGPT, 54.2 percent for Microsoft's Copilot, 54.2 percent for Perplexity, 50 percent for Anthropic's Claude, 41.7 percent for Google's Gemini; 37.5 percent for Meta AI and 29.2 percent for xAI's Grok... The seven chatbots were also collectively three times more likely to cite left-leaning pink slime sites (cited in 36.3 percent of responses) than their right-leaning counterparts (cited in 11.9 percent of responses) — though that may have more to do with the progressive sites' far more frequent posting than any political bias from the chatbots. "While citing the pink slime sites, only one chatbot response out of 168 total queries noted the partisan nature of the source," the article points out. But they also note that the real problem seems to be that consumer-oriented AI chatbots just "use much of the internet's content — regardless of the reliability or standards of the source — to frame their answers."


    Read more of this story at Slashdot.


  • Apple Faces $5.7 Billion Patent Infringement Verdict Over iPhone And Apple Watch Haptics
    "A federal jury in San Diego awarded Taction Technology more than $5.7 billion in damages Friday after finding that Apple infringed claims from two haptics patents,"reports CNBC:Taction sued Apple in 2021 in the U.S. District Court for the Southern District of California. The company alleged that Apple was improperly "capitalizing on Taction's innovation and success" by selling devices that infringed on its vibration technology, according to the complaint. Apple initially won dismissal in 2023, and the Federal Circuit later revived the case.... Taction argued that Apple's "Taptic Engine," which is embedded in its Apple Watches and iPhones, uses its inventions without proper license or authority. Taction's lead counsel told CNBC "Taction waited five and a half years for this case to get to trial, so it was a long time coming." CNBC also reported that the jury "did not find Apple's infringement willful" — and that Apple said they'd appeal.


    Read more of this story at Slashdot.


  • Just How Big is the AI Buildout - and How Risky?
    A new Brookings Institution study notes the "strikingly physical" economic footprint of AI's buildout, from specialized chips and electricity to purpose-built data centers. (Two-thirds of a data center's costs are IT equipment, with one-third going to real estate and its associated power infrastructure.) "At an average of 3.63 percent of GDP per year, the projected buildout would be larger relative to the economy than the major U.S. canal, railroad, electrification, highway, and telecommunications investment booms." This is pushing up prices for workers, electricity, and even commercial real estate (as well as consumer products that use chips), notes the Wall Street Journal, and reducing the construction on new houses and apartment buildings. And in addition, the paper points out, projections for this buildout "would double the electricity consumption of the entire U.S. residential sector." The calculations come from Columbia Business School finance/real estate professor Stijn van Nieuwerburgh — and Reuters explains their significance:Just as the rail and telecoms expansions led to notable bubbles and busts, Van Nieuwerburgh wrote that the extent of the buildout, the still-untested revenue streams, and the intricate financing structure emerging around AI mean it could be primed for a fall. "This is freaking complicated," he said in a briefing with reporters of the arrangements emerging between AI firms, major tech hyperscalers, banks, private credit lenders, real estate firms, and a host of other players involved in building what he conservatively estimated at 183 gigawatts worth of new data-center capacity over the next seven years, compared with about 57 gigawatts currently installed.... The investment underway already has outstripped what the major players can fund from their own cash flows. The shift to outside financing has increased leverage, redistributed risks across the economy, and made the venture dependent on revenue streams that have yet to be proven, Van Nieuwerburgh noted in the paper, which will be presented on Friday... "These developments do not imply that financial distress is imminent. Strong growth in AI applications, high utilization, and continued improvements in model capability could support the projected infrastructure and generate stable cash flows," he wrote. "But the combination of uncertain demand, rapid technological change, execution bottlenecks, and high leverage creates meaningful downside risk if expectations are revised." As an example, he wrote that the AI industry will need to be earning about $3.7 trillion in annual revenue by 2032 to achieve the expected return on the investment, and "given current estimates of annual combined revenues of OpenAI and Anthropic of around $100 billion, revenues would need to grow at roughly 80% per year." The paper suggests policies that "improve measurement and transparency" for financing.


    Read more of this story at Slashdot.


  • Waymo Says Its Self-Driving Cars Reduced Injury-Causing Accidents by 82%
    Waymo's self-driving car technology "continues to outperform human benchmarks," the company claimed this week. "It was involved in 841 fewer injury-causing crashes — an 82% reduction compared to human drivers." Electrek reports:We've seen various Waymo crash data before, with Waymo claiming crash reductions. That's all well and good when the company says it, but we've also seen independent data confirming similar (though lower) crash reduction numbers... Waymo has enough miles that it's ready to start quoting how many injuries it has prevented, and the number is pretty high. Its newest crash data states that it had operated a total of 271 million driverless miles through June of this year, which is 50 million more miles added in the 3 months since its end-of-March update. Over those miles, Waymo says there was an 82% reduction in crashes that caused injury, and a 95% reduction in crashes that cause "serious injury or worse" [compared to human drivers]. Waymo also says that compared to human drivers it's reduced injury-causing crashes involving pedestrians by 93%, cyclists by 86%, and motorcyclists by 82%. Waymo's analysis comes from San Francisco, Los Angeles, Austin, Atlanta, and Phoenix, and its blog post includes video showing some near-misses where it says its automated system prevented an injury-causing collision.


    Read more of this story at Slashdot.


  • After Dozens of Incidents at OpenAI and Anthropic, OpenAI Pauses Model Training to Build More Safeguards
    "OpenAI said it has paused training of its latest AI models," reports the Associated Press, "as reports of AI agents going rogue mount."The decision to halt development came just hours after the company disclosed Friday that it was reviewing several incidents from the summer in which OpenAI agents searching federal government websites acted in unexpected ways beyond what was asked of them while gathering and distributing information... OpenAI said in a statement that it will resume training "only when we are confident that we have additional safeguards" in place, adding that it expects it will have to "hit pause" again as AI develops and other issues emerge... It is the second time in three months that OpenAI has halted development of its models. The first came in July after disclosure of a cyberattack targeting AI startup Hugging Face, a now notorious incident that raised fears the industry was losing control. OpenAI "also said it had notified dozens of third parties about improper activity," reports Reuters:As of mid-September, one person briefed on the matter estimated that OpenAI had found roughly two dozen incidents of its agents acting in undesirable ways. But the number has continued rising as OpenAI teams sift through internal logs of the agents' activities and find previously unknown cases, the two people close to the company said... OpenAI has acknowledged a general need for more transparency around rogue AI behavior... Even so, two people familiar with OpenAI's investigation into its agents' activity described it as locked down and shaped by company lawyers. The process has been unusually compartmentalized for a company that some former employees say was more open about these issues in the past, the people said. Roughly 100 people were in some way involved in the process to understand the Hugging Face hack, three people briefed on the matter said. During that process, evidence of other incidents surfaced. Reuters has previously reported that OpenAI investigators looking into the Hugging Face breach were discouraged by the company's lawyers from expanding the scope of the investigation to include other incidents. OpenAI said its lawyers did not discourage deeper investigation. Many incidents have been uncovered by outside researchers rather than OpenAI directly. In several episodes, the agents took problematic actions that went unnoticed by the company for months. Meanwhile, Axios reports that Anthropic's Claude Opus 5.5 model "sought to escape a sandbox — a secure testing environment — in 1.5% of test runs, though the company emphasized that these were adversarial experiments where a task couldn't be solved without escaping the sandbox." Anthropic points out that those tests were run "without the additional safeguards we apply in production". But they acknowledged that then Claude Opus 5.5 "when given apparent credentials to a public package registry in a simulated security exercise, took potentially harmful actions in roughly half of cases. Very rarely, pre-release snapshots produced and acted on spontaneous malicious tool calls, and during training some snapshots concealed actions from an automated grader." Claude Opus 5.5 "showed less misaligned behavior and less cooperation with misuse than any other recent Claude model on nearly all measures," Anthropic adds, and "took overeager or destructive actions less than any other model we tested." But Axios makes an interesting estimate about that 1.5% of test runs (without safeguards). "Anthropic and other companies conduct hundreds of thousands of test runs on their models, or more, sources said. That means even a small percentage of misaligned behavior can still amount to tens of thousands of incidents in which the models behaved in unexpected, sometimes troubling ways." The sheer number of incidents, which occurred in recent months in internal testing and the real world, indicates that the problem is orders of magnitude more complex than what is publicly known. The findings, which are surfacing as part of internal work to assess models and in investigations at both companies into model behavior, raise questions about whether either company — or any top model-maker — is currently capable of establishing complete control over their technology. The episodes include bypassing guardrails, creating message boards, escaping sandboxes, website hijacking, self-prompting or seeking to bypass monitors, sources said. They occurred in internal testing and in the real world, and many have yet to become public as security researchers continue to investigate, sources said... Some at OpenAI see Hugging Face as a one-off, with disclosures about future incidents likely to be less severe due to improved controls and the unusual nature of the testing they conducted, which involved an unreleased model, sources told Axios. AI security researchers agree that there are simple fixes that will help AI companies avoid aspects of what made the Hugging Face episode appear so dangerous to outsiders. Other AI executives and safety researchers, however, cautioned that they have limited confidence that AI companies will be able to prevent all problematic model behavior... It's not about how damaging each individual instance was, Connor Leahy, AI researcher and executive director at ControlAI told Axios. The "crazy thing," he said, is that these instances involve "autonomous systems doing things they were told not to do," potentially including crimes.


    Read more of this story at Slashdot.


  • New Tin-based Solar Cells Trap Heat 1,000 Times Longer, Could Beat 33% Limit
    Could this push solar cell efficiency beyond the theoretical 33% limit? Interesting Engineering reports:Researchers at the University of Groningen in the Netherlands found that tin-based perovskite solar cells can slow heat loss from high-energy "hot electrons..." When sunlight strikes a panel, photons jump-start electrons into action. The most energetic photons create super-charged hot electrons... [but] in fractions of a trillionth of a second, these high-energy particles rapidly cool, dumping their bonus energy as waste heat before ever leaving the solar cell... In collaboration with Maria Antonietta Loi, professor of Photophysics and Optoelectronics, the team created an experimental setup. Using a specialized solar cell material called tin-based perovskite, Loi's lab performed a feat many thought impossible: she slowed the heat loss down by a factor of 1,000. Suddenly, the extra energy lingered for nanoseconds instead of vanishing in picoseconds... To solve the puzzle, Koster and PhD student Tim Faber built digital simulations to peel back the quantum layers. And discovered a surprising double-action mechanism at work... The simulations matched the exact nanosecond delay observed in the lab... These specialized materials could be used to build a new generation of super-efficient solar cells. Tin-based metal halide perovskites are non-toxic, eco-friendly crystalline materials for high-performance solar energy conversion... The material possesses an unusually low electron mass. As a result, electric charges move quickly and retain extra thermal energy for extended periods. This combination of broad light absorption, efficient charge movement, and prolonged energy retention makes these materials prime candidates for next-generation solar panels. "There are many other questions that still need answers," the team said in their announcement, "but in theory, this discovery could allow the creation of more efficient solar cells, beyond the theoretical limit of 33 percent." Thanks to long-time Slashdot reader fahrbot-bot for sharing the article.


    Read more of this story at Slashdot.


  • China and the US Say They've Agreed to Start Talks About AI
    The United States and China have agreed to "launch a dialogue" on AI, reports Reuters.On artificial intelligence, the two sides agreed to hold a dialogue on the technology's risks and benefits, with the next round of discussions set for November, and to set up a communication channel for AI-related incidents, the Chinese Foreign Ministry and the White House said. The White House said that the leaders had agreed to use the term "super intelligence" in place of "artificial intelligence." In a separate statement, the Chinese ministry said that Beijing valued Washington's use of the new term. As AI technology continues to advance, the two sides should step up exchanges and work toward consensus in line with new developments, it said. But CNN argues that "Despite growing calls to prevent AI development from spiraling out of control, the Trump-Xi summit has produced little substance, as many experts expected."The right thing to do on AI, [China's leader] Xi said during talks with Trump, is to "draw on each other's strengths, not guard against each other" — a reference to Beijing's concern about US containment, from existing tech export controls to potential AI restrictions. "The two sides can continue their dialogue on AI, exchange views on its risks and benefits, and jointly prevent the misuse and abuse of AI," he added. But the summit has yielded little progress on AI beyond a formal dialogue and a bilateral communication channel, proposals discussed before the two leaders' summit — underscoring the entrenched mutual mistrust amid contrasting visions on AI... Because of low levels of trust, cooperation between the two superpowers remains limited, said George Chen, chair of digital practice at The Asia Group consultancy. "Beijing continues to believe Washington seeks to contain China's rise in AI and other emerging technologies, a perception that will shape the pace and scope of future engagement for the two countries on AI," he said. CNN also points out that while China trails the US in frontier AI models, "it's rapidly narrowing the technology gap while championing a more open ecosystem centered on accessibility and lower cost."In July, Chinese leader Xi Jinping launched the World Artificial Intelligence Cooperation Organization — a rival grouping to the Pax Silica alliance that Trump formed last year to reduce reliance on China for AI supply chains. While over two dozen countries and the European Union signed up to Trump's Pax Silica, Xi has recruited 29 countries, including Russia, Indonesia and Pakistan, to his alternative vision of open models, which allow users to freely download, customize and run without paying hefty fees to American firms like Anthropic and OpenAI. For developers in the Global South, an inexpensive Chinese model from DeepSeek or Moonshot may be more useful than a slightly more capable system requiring an expensive subscription and access to a foreign cloud provider, said Eric Olander, editor in chief of The China-Global South Project, a research agency.... China's embrace of open systems has not always been a top-down strategy by Beijing. Restrictions on access to the most advanced chips because of US export controls, coupled with smaller capital markets, have pushed Chinese developers toward open models as a way to compete with leading US proprietary systems. That shift has proved effective. In a year, Chinese models' global usage skyrocketed from less than 15% to over 54% last week, led by DeepSeek, according to AI leaderboard data by OpenRouter, a marketplace for models. Even American firms, from Airbnb and DoorDash to Shopify, have embraced Chinese models, tapping into the advantages of open systems, including lower costs and greater flexibility for customization. CNN adds this insight from Alex Colville, an analyst focusing on tech and security at the government-backed Australian Strategic Policy Institute. "The more capable Chinese models become, the less likely it is Beijing may leave them unrestricted."


    Read more of this story at Slashdot.


  • KDE and GNOME Developers Ponder How to Handle AI-Generated Contributions
    Last weekend KDE's annual Akademy conference included a presentation proposingan AI-native KDE," writes The Register. This led KDE developer Nate Graham to open a discussion about proposed restrictions on LLM-assisted contributions which "rapidly became heated. Moderators issued warnings, restricted further comments, and eventually removed the thread." But as Graham writes on his blog, "A bunch of people mostly outside of KDE who disapprove of LLM usage derailed KDE's attempt to add restrictions to LLM usage."Two people unknown to any KDE contributors appeared and began fighting with one another about the broader topic of the morality of AI, not the proposed guidelines... Someone else outside of KDE set up kdeforpeople.com in an attempt to... pressure KDE into banning LLMs. A bunch of people signed onto it, almost none of whom are known KDE contributors. The topic was picked up on social media and the press with... varying levels of accuracy. The draft proposal was removed and the whole topic hidden... Yep, that's where we're at in the state of online discourse around AI... The "lovable, sovereign, AI-native KDE" idea was presented by two people important to KDE in decades past, but who had not made any contributions recently besides this Akademy talk. Their idea does not reflect the overall direction of KDE or Plasma, and I don't think it ever will. If "a lovable, sovereign, AI-native KDE" freaks you out, I believe it is completely reasonable and safe to ignore... I completely understand why a lot of people have problems with LLMs. I have these concerns as well. He concluded by asking people not to derail any future process to set usage guidelines, fighting over "the broader topic of AI in general." "The discussion is gone, but the argument continues," adds The Register:GNOME developer Jordan Petridis has also published The GNOME LLM Policy That I Want, proposing that LLMs be barred from creating or modifying anything submitted to GNOME or hosted on its infrastructure. "You might be asked to prove your code meets this requirement," Petridis writes, arguing for proposals that target the norms around developer behavior. His rationale? "The GNOME Project prioritizes the social and human aspects of collective software creation,"


    Read more of this story at Slashdot.


  • After 40 Years, Microsoft Excel Will Add Single-Cell Lists and Arrays
    Microsoft's senior product manager for Excel acknowledges that "Throughout Excel's 40-year history, you've only been able to put one value per cell." But that's now changing with arrays in cells (as well as nested arrays) and lists."You can create a list by selecting Insert > List or pressing Ctrl+J, then typing or pasting items separated by commas or semicolons, depending on your regional settings. Selecting the icon in the cell shows the individual values..." "With lists, you can filter by one or more individual items instead of whole text entries. Referencing a list returns all its values for calculations. For example, =B2 spills those values into separate cells...""For the first time in Excel, arrays can exist natively in cells as values or as formula results. They can be any size or shape and can even contain other arrays. You can now keep the result of any spilling formula in a single cell by "wrapping" the formula body with braces { }." "Since the introduction of dynamic arrays, array results have spilled across cells — for example ={1;2;3}. Wrapping the original array with braces creates a 1x1 array around it, so instead of spilling to multiple cells, the array stays in a single cell. Braces have long been used to describe arrays in Excel and this extends that behavior by allowing multiple layers of braces. This gives you more flexibility when building spreadsheets. Instead of leaving room for a formula to spill, you can keep the result in one cell.""Arrays can now also 'nest' inside other arrays... Previously, a formula that produced an array of arrays would return a truncated result or #CALC! error. Now, supported formulas return the complete nested result... FLATTEN(array, [pad_value], [levels]) simplifies nested arrays by removing one or more levels of nesting..."Three HAS functions check whether values are in an array: — HAS(array, value) returns TRUE if value appears anywhere in array, and FALSE otherwise. — HASANY(array, values) returns TRUE if any of the values appear anywhere in array, and FALSE otherwise. — HASALL(array, values) returns TRUE if all of the values appear anywhere in array, and FALSE otherwise.


    Read more of this story at Slashdot.


  • AI Finds So Many Linux Bugs, Canonical Changes to a Two-Week Stable Release Update Cycle
    "Finding vulnerabilities faster also puts pressure on Linux distributions to fix and deliver patches faster," writes Slashdot reader BrianFagioli AI has transformed bug discovery from "a manual, time-intensive process into a highly automated engine," notes Canonical's blog, leading to a "recent explosion in the volume of CVEs".Additionally, the upstream kernel community became its own CVE Numbering Authority (CNA) and assigned CVE (Common Vulnerabilities and Exposures) identifiers to thousands of bugs, arguing that at the kernel level, almost any type of bug that can affect a running system, could potentially be classified as a vulnerability. As a result, the volume of CVEs has skyrocketed exponentially, creating a massive backlog of alerts and forcing defenders to drastically increase the speed of their fixes to close the window of risk. To address the growing volume of CVEs and the demand for faster security fixes, we are transitioning to a unified, 2-week release cycle... While a patch is being prepared, Canonical aims to provide safe workarounds where applicable, so users aren't left exposed in the meantime. Where no safe workaround exists, Canonical will say so clearly and point users toward general hardening steps instead. The goal is to get environments into a defensible, safer state within 24 to 48 hours of public disclosure — well before a patch ships. This doesn't replace the patch; it buys the time needed to fix the vulnerability properly, without sacrificing security. "Linux did not suddenly become wildly insecure overnight," notes the blog Nerds.xyz. "We are getting much better at finding and cataloging problems that may have previously gone unnoticed."There is something almost ironic about all of this. AI is routinely pitched as a tool that will make software development faster, but it is also making vulnerability discovery faster. That means maintainers now have to accelerate the other side of the equation too. For Ubuntu users, that should ultimately be good news. More bugs being discovered is preferable to vulnerabilities sitting unnoticed in the Linux kernel.


    Read more of this story at Slashdot.


Polish Linux

  • Security: Why Linux Is Better Than Windows Or Mac OS
    Linux is a free and open source operating system that was released in 1991 developed and released by Linus Torvalds. Since its release it has reached a user base that is greatly widespread worldwide. Linux users swear by the reliability and freedom that this operating system offers, especially when compared to its counterparts, windows and [0]


  • Essential Software That Are Not Available On Linux OS
    An operating system is essentially the most important component in a computer. It manages the different hardware and software components of a computer in the most effective way. There are different types of operating system and everything comes with their own set of programs and software. You cannot expect a Linux program to have all [0]


  • Things You Never Knew About Your Operating System
    The advent of computers has brought about a revolution in our daily life. From computers that were so huge to fit in a room, we have come a very long way to desktops and even palmtops. These machines have become our virtual lockers, and a life without these network machines have become unimaginable. Sending mails, [0]


  • How To Fully Optimize Your Operating System
    Computers and systems are tricky and complicated. If you lack a thorough knowledge or even basic knowledge of computers, you will often find yourself in a bind. You must understand that something as complicated as a computer requires constant care and constant cleaning up of junk files. Unless you put in the time to configure [0]


  • The Top Problems With Major Operating Systems
    There is no such system which does not give you any problems. Even if the system and the operating system of your system is easy to understand, there will be some times when certain problems will arise. Most of these problems are easy to handle and easy to get rid of. But you must be [0]


  • 8 Benefits Of Linux OS
    Linux is a small and a fast-growing operating system. However, we can’t term it as software yet. As discussed in the article about what can a Linux OS do Linux is a kernel. Now, kernels are used for software and programs. These kernels are used by the computer and can be used with various third-party software [0]


  • Things Linux OS Can Do That Other OS Cant
    What Is Linux OS?  Linux, similar to U-bix is an operating system which can be used for various computers, hand held devices, embedded devices, etc. The reason why Linux operated system is preferred by many, is because it is easy to use and re-use. Linux based operating system is technically not an Operating System. Operating [0]


  • Packagekit Interview
    Packagekit aims to make the management of applications in the Linux and GNU systems. The main objective to remove the pains it takes to create a system. Along with this in an interview, Richard Hughes, the developer of Packagekit said that he aims to make the Linux systems just as powerful as the Windows or [0]


  • What’s New in Ubuntu?
    What Is Ubuntu? Ubuntu is open source software. It is useful for Linux based computers. The software is marketed by the Canonical Ltd., Ubuntu community. Ubuntu was first released in late October in 2004. The Ubuntu program uses Java, Python, C, C++ and C# programming languages. What Is New? The version 17.04 is now available here [0]


  • Ext3 Reiserfs Xfs In Windows With Regards To Colinux
    The problem with Windows is that there are various limitations to the computer and there is only so much you can do with it. You can access the Ext3 Reiserfs Xfs by using the coLinux tool. Download the tool from the  official site or from the  sourceforge site. Edit the connection to “TAP Win32 Adapter [0]


OSnews

  • Amiga screens: a primer
    One of the unwritten rules of the Internet seems to be that whenever something Amiga-related is mentioned, at least one Amiga fan (myself included) must show up and try to explain the concept of screens. Amiga screens can have different resolutions, well tell you, and one can drag them, well say, and other Amiga users rally in agreement, while non-Amiga users probably still dont get whats so great about screens. Until now, when this text has been written, in the hope of converting unsuspecting normies into full-blown Amiga screen lovers. ↫ Carl Svensson A deeply technical look at not just how the Amiga managed to achieve this stunning functionality way back in the 80s on machines with 7MHz and less RAM than a keyfob, but also how this functionality can be useful. Ive always found the concept of screens on the Amiga quite interesting, and Svenssons article does a great job at demystifying the whole concept. Of course, expect a lot of lovely Amiga OS screenshots.


  • Redox runs Qemu, gets multicore support for ARM
    Its time for an overview of another month of Redox OS progress, and over the month of August  theyre a bit late, dont believe the publication date  theyve implemented multicore support for ARM, and considerably improved the I/O performance for the NVMe driver, RedoxFS, and RAMFS by implementing a ring buffer communication API. Theres also initial support for NUMA-based memory management, QEMU is now working on Redox, and much more. Of course, theres also the usual long list of improvements to the kernel, relibc, drivers, and more.


  • JagOS Spot turns Atari Jaguar into the unreleased Atari Painter prototype computer
    Can you run an operating system with a graphical user interface and applications on the Atari Jaguar? Well, you can. A long time running idea and work-in-progress, Id like to finally announce the current version of JagOS Spot for the Atari Jaguar, running from the RetroHQ GameDrive. Im slow at releasing things and try not to announce in-progress stuff due to lack of free time but would like to push this along. Maybe itll motivate me to work on it more if the interest is there or just release it as-is if not. The idea is based on the unreleased Atari Jaguar Painter Computer prototype, that a merged Falcon with Jaguar chipset-based computer would have found its way into consumer hands after the Falcon030. ↫ Clint Thompson The screenshots and YouTube video are quite impressive, but as its not actually released, its difficult to really say anything more about this project for now. I hope theres enough interest to get this projects code out there so it can be further improved and expanded.


  • Weve been here before: Qualcomm promises Linux support for Snapdragon X2
    Qualcomm, yesterday, promising Linux support for the new Snapdragon X2 processors: Linux on Snapdragon X2 Series is moving from early bring-up toward a more complete upstream developer experience. Core support is landing, Hexagon NPU and Adreno GPU work is progressing, and real laptops with Snapdragon X2 Series processors are already beginning to boot Linux. ↫ Qualcomms promises from 2026 Interesting, but I feel like Ive heard these exact words before. Qualcomm, two years ago, promising Linux support for the then-new Snapdragon X processors: It’s been our priority not only to support Linux on our premium-tier SoCs, but to support it pronto. In fact, within one or two days of publicly announcing each generation of Snapdragon 8, we’ve posted the initial patchset for Linux kernel support. Snapdragon X Elite was no exception: we announced on October 23 of last year and posted the patchset the next day. That was the result of a lot of pre-announcement work to get everything up and running on Linux and Debian. ↫ Qualcomms empty promises from 2024 These promises were not at all kept. Two years later, Linux support for Snapdragon X laptops is still spotty, broken, and limited, confined to just a few bespoke Ubuntu builds, which dont even offer full support either. Its a complete mess, effectively unusable, and highlights once again that big technology companies are compulsive liars. I have little faith in these new promises, but who knows  maybe this time itll be different. Probably not, though.


  • The state of scrollbars in Windows makes even longtime Microsoft engineers sad
    Raymond Chen, longtime Microsoft employee and author of the very popular The Old New Thing blog, published an interesting post about the Win32 scrollbar. It turns out theres actually quite a few interesting shortcuts and useful hidden features, like clicking inside a scrollbar while holding down shift will make the content jump to that point. Halfway through the article, though, Chen laments how nobody really uses proper Win32 scrollbars anymore. Sadly, almost nobody uses Win32 scroll bars any more. Everybody uses frameworks that provide their own custom scroll bars. ↫ Raymond Chen And as you might expect, none of these scrollbars work like the Win32 one, making even something as basic as the scrollbar a fragmented mess. He doesnt just blame things like Electron, either, as Microsofts own WinUI framework, which is used for most new! Windows UI developed by Microsoft for Windows 11, also uses custom scrollbars that do not work like the Win32 one does. Great, so by the time I learn about a shortcut for scroll bars (Shift+click), the ecosystem has fragmented so much that I can’t even rely on it working. ↫ Raymond Chen Modern computing is depressing.


  • Solaris 11.4 SRU95 released
    The Solaris branch for paying customers has been updated to SRU95. Oracle Solaris 11.4 SRU95 updates a broad set of platform, runtime, developer, networking, desktop, and open source components. Notable updates include Ansible Core to 2.21.1, Apache HTTP Server to 2.4.67, Apache Tomcat to 9.0.120, BIND to 9.20.23, Django to 5.2.15, Elixir to 1.20.1, Erlang to 28.5.0.2, Firefox to 140.10.0esr, Go to 1.25.11, ImageMagick to 7.1.2-27, MySQL 8.4 to 8.4.10, NSS to 3.125, OpenSSH to 10.4p1, Rust to 1.96.0, SQLite to 3.53.2, Thunderbird to 140.10.0esr, and Vim to 9.2.0513. Additional updates include CMake, CUPS, Cython, GnuTLS, libarchive, libexpat, pip, rsync, and a range of Python modules, X11 libraries, graphics libraries, printing components, and desktop utilities. ↫ Colin Kavanagh at the Oracle Solaris Blog One of the major changes is the deprecation and removal of NTLM authentication of local users; only NTLMv2 is supported now for security reasons. This release also brings GCC 16, with GCC 13 being removed in the next version. The detailed release notes go into some of the more low-level, esoteric changes in Solaris 11.4 SRU 95.


  • You know the GDPR is good based on who hates it
    It is impossible to go anywhere in a technology space online without hitting a wave of commentary about how stupid GDPR is. It was written by bureaucrats who dont understand the amazing potential of unrestricted technology. These US-based critiques almost always lean on the oldest trick in cyberlibertarianism: we dont have time to regulate, we must simply adapt and ride the wave. Nobody has time for government. Of all GDPRs consequences, none gets more attention than the cookie banner, which critics present as the inevitable result of government meddling. Blaming GDPR for the cookie banner is like blaming the health inspector for the roaches. The banner is deliberate vandalism, a dark pattern engineered to exhaust you before you can learn anything about the surveillance apparatus humming behind the OK.! Ironically the banner designed to hide the machine has taught the public more about the machine than a thousand podcasts ever will. Even non-technical people stop at your data is shared with 996 partners.! ↫ Mat Duggan There is so much misinformation about the cookie banner, its honestly quite hard to believe its not deliberately spread. You dont need a cookie banner for functional cookies, so as long as you dont share your users data with anyone else, you dont need a cookie banner at all. On top of that, most cookie banners you encounter are actually not compliant with the GDPR at all, because they dont present a single-click option to block your data from being shared with those 996 partners. What the cookie banner has done is inform millions  maybe even billions  of people the world over of just how insipid the online advertising and data harvesting industry really is. It put the issue on the map, and by now, everyone, no matter their level of computer literacy, is fully aware of whats happening to their data every time they see one of these (non-compliant) banners. No else had the guts to do this  except for the European Union. The wider GPDR has set the baseline for online privacy protections, and while we have a long way to go before weve fully solved this issue, the EU at least gave us a good point to jump off from. Smoking and asbestos werent banned in a day, either.


  • Googlebook OS: Google launches its Android-powered laptop effort
    A few months ago, Google announced it was going to put Android on laptops (and eventually, desktops), serving as eventual replacements for Chromebooks. Unlike those, though, these new Android laptops wouldnt be low-quality, cheap, underpowered devices for school children to spill milk on, but devices actually competitive with Windows and macOS laptops. Today, the company finally allowed the press to use these new things. Google describes Googlebook as a “totally fresh approach to computing,” bringing together Android, ChromeOS, Gemini, and premium laptop hardware from major manufacturers. The idea is to create a laptop that feels more natural to use for Android phone users while retaining what makes a desktop OS useful, such as a full Chrome browser, desktop apps, a proper file manager, Linux support, and a full terminal environment. Google is also trying to solve some of the biggest problems Android users have had when moving between their phone and laptop, and make the two devices feel like part of the same ecosystem. ↫ Adamya Sharma at Android Authority Ive been looking at some of the videos of people using and playing with these new Android laptops, and to be honest, Im not impressed. Im seeing quite a bit of jank, a complete lack of consistency, and apparently, a lack of Android applications optimised for desktop use. The close integration with your Android phone are nice, but of course, this also means another dollop of slimy lock-in, as I highly doubt Google will make it easy or even possible at all for, say, iPhones or other platforms to integrate quite as nicely as Android devices will. Worse yet, theres the elephant in the room: for just how long will Google care about this new platform? These laptops start at $900 and go all the way up to $1300 (and will be considerably more expensive here in Europe), which is a lot to ask for something Google might get bored of and abandon in a few years time. Ten or more years ago, in a slightly more innocent time, I mightve been excited about Google bringing Android to laptops and desktops, but in 2026, I just cant be bothered to care. Also, and this doesnt really matter, but Googlebook OS!?


  • Lets stop debating the GnuImp Manipulation Program
    The GIMP will never magically become software beloved by artists—not without radically changing its culture, and making the artists the ones who call the shots. The GIMP will remain what it has always set out to be: a tinkerer’s toolbox, more concerned with the purity of its software politics than with garnering a loyal userbase of photographers and designers. But because everyone insisted to poise it as a viable Photoshop killer, Linux is left with an obvious hole in its software offering, a hole nobody managed to fill with their own challenger. ↫ Aria Salvatrice Excellent article, and spot-on conclusion.


  • I dont like passkeys!
    Passkeys are a fantastic technology. Since they are bound to the site they are created for, they cannot be phished by a hacker’s fake login screen. If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details. This leads to passkeys being the perfect fit for a corporate environment, but a poor fit for personal security. To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss. By using passkeys, you gain better security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts. Phishing through the standard login flow is eliminated by passkeys, but it creates a false sense of security. An account’s security is still dictated by the weakest recovery method: SMS, email links, security questions, and so on. If these recovery methods aren’t enabled, then the risk of permanent lockout remains for the user. ↫ Ethan Hawksley Ive always felt something was off about passkeys, and have never used them. Theyve become  or were always intended to be  tools for further lock-in by especially Google and Apple, tying their entire usage flow to their respective operating systems. They also dont seem to work well if you often work on devices not your own, which is a major hassle. None of these shortcomings come into play when using a traditional password manager, even if they require more manual work. Just let me use a password manager with random password generation, instead of trying to force passkeys down my throat.


Linux Journal - The Original Magazine of the Linux Community

  • systemd 262 Released with Static PID 1, Intel TDX, TPM Improvements, and New Container Features
    by George Whittaker
    The systemd project has officially released systemd 262, delivering another substantial update to the system and service manager used by most major Linux distributions. The final release was tagged on September 22, 2026, following three release candidates earlier in the month.

    Systemd 262 introduces improvements across service management, containers, virtualization, encrypted storage, TPM security, networking, journal recovery, system updates, and unattended installations. Among the most interesting additions are the ability to build systemd as a single statically linked PID 1 binary, Intel TDX support in systemd-vmspawn, Live Update Orchestrator integration, improved TPM-backed encryption, and new fallback unit files embedded directly into the systemd manager.

    The release also contains a rather unusual development safeguard: an AI/LLM canary intended to help identify code contributions generated by AI that haven't been properly reviewed by a human before submission.
    systemd 262 Is Officially Available
    The final systemd 262 source was tagged by systemd developer Luca Boccassi on September 22.

    The upstream tag identifies commit 8cc40e0c5e9234bf45084751ac53b1fbfe70b492 as systemd v262, following release candidates published throughout September.

    The release has already begun reaching Linux distribution development repositories.

    Debian accepted systemd 262-1 into Debian Unstable on September 22, while Fedora has prepared systemd 262 packages for Fedora 45.

    As usual, the speed at which systemd 262 reaches ordinary users will depend on each distribution's update policy.
    systemd Can Now Become a Single Static PID 1 Binary
    One of the most interesting changes in systemd 262 is support for building systemd as a single statically linked PID 1 and executor binary.

    The feature is primarily intended for extremely small container environments.

    Normally, systemd depends on a collection of dynamically linked libraries and supporting components. That architecture makes sense for a complete Linux distribution, but containers sometimes need a much smaller runtime environment.

    The new static configuration makes it possible to create a more self-contained systemd executable suitable for minimal container images.

    These builds avoid dynamically loading optional libraries and use simplified mechanisms for resolving users and groups rather than relying on the complete Name Service Switch infrastructure.

    This doesn't mean normal Linux distributions will suddenly replace their standard systemd packages with a giant static executable. The capability is specifically useful for specialized container and minimal-system deployments.
    Go to Full Article


  • Ubuntu Container Escape Vulnerability Gets Public Exploit Before Kernel Patch Arrives
    by George Whittaker
    Ubuntu administrators running containerized workloads have a new Linux kernel security problem to watch closely. Public exploit code is now available for CVE-2026-80521, a Linux kernel use-after-free vulnerability that can allow an unprivileged process inside a container to escape and obtain root privileges on the underlying host.

    Security firm DepthFirst published its research and exploit on September 22, 2026, demonstrating the attack against Ubuntu 26.04 LTS. The underlying Linux kernel vulnerability had already been fixed upstream on August 6, but as of September 23, Ubuntu's security tracker still lists the main kernel package in Ubuntu 26.04 LTS as "Vulnerable, work in progress," while Ubuntu 24.04 LTS is also listed as vulnerable.

    The situation is particularly important for Docker, Kubernetes, cloud infrastructure, and other environments that run potentially untrusted workloads because the vulnerable kernel functionality can be reached through ordinary operations available inside standard containers.

    There is currently no confirmed evidence that CVE-2026-80521 is being actively exploited in real-world attacks, and the vulnerability isn't listed in CISA's Known Exploited Vulnerabilities catalog. The availability of working public exploit code nevertheless makes the patch gap considerably more important.
    CVE-2026-80521 Is a Linux Kernel Vulnerability
    Although Ubuntu is receiving much of the attention because the newly published exploit specifically targets it, CVE-2026-80521 is fundamentally a Linux kernel vulnerability.

    The problem exists in the kernel's AF_UNIX socket subsystem, specifically within its garbage collection mechanism.

    AF_UNIX sockets, commonly called Unix-domain sockets, provide local inter-process communication between applications running on the same system.

    Unlike conventional network sockets, they don't need to communicate across a network. They are widely used by Linux applications and services for fast communication between local processes.

    They also support passing file descriptors between processes through SCM_RIGHTS messages, and it is the kernel's management of these references that creates the conditions for CVE-2026-80521.
    A Race Condition Leads to Use-After-Free
    At the technical level, CVE-2026-80521 involves a race condition inside the AF_UNIX garbage collector.

    The kernel needs to track references between Unix sockets when file descriptors are passed between processes. Circular references can develop, where one socket effectively references another while that socket references something else in the same group.

    Linux represents these relationships internally and periodically determines which references can safely be removed.
    Go to Full Article


  • Fedora Linux 45 Beta Released with Python 3.15, GCC 16.2, and Major Security Changes
    by George Whittaker
    The Fedora Project has officially released Fedora Linux 45 Beta, giving users an early look at the technologies expected to form the foundation of the final Fedora 45 release. The beta became available on September 15, 2026, after Fedora's Quality team approved Release Candidate 1.3 for publication.

    Fedora 45 Beta brings significant changes throughout the operating system, including Python 3.15, GCC 16.2, glibc 2.44, GNU Binutils 2.47, Go 1.27, LLVM 23, Podman 6, stricter RPM signature verification, improved DNF5 protections, a new userspace virtual console, standardized desktop secret storage, and substantial installer improvements.

    The release is available across Fedora Workstation, KDE Plasma Desktop, Server, Cloud, IoT, Atomic Desktops, Spins, and Labs, although a few prerelease images are excluded.
    Fedora 45 Beta Is Now Available
    Fedora Linux 45 Beta represents the final major public testing milestone before Fedora 45 reaches stable status.

    Fedora describes its beta releases as code-complete previews that closely represent what users should expect from the final version. Development isn't finished, however, and bugs or incomplete migrations can still be discovered during real-world testing.

    Fedora 45 Beta is currently available in several major editions:
    Fedora Workstation 45 Beta Fedora KDE Plasma Desktop 45 Beta Fedora Server 45 Beta Fedora Cloud 45 Beta Fedora IoT 45 Beta Fedora Atomic Desktops Fedora Spins Fedora Labs
    Existing Fedora installations can also be upgraded to the beta using Fedora's DNF system-upgrade process.

    Fedora's official Workstation download page confirms Beta 1.3 images for both x86_64 and AArch64 systems.
    A New Virtual Console with kmscon
    One of Fedora 45's more unusual system-level changes is the replacement of the traditional in-kernel console with kmscon.

    Fedora describes kmscon as a modern userspace virtual terminal implementation that provides smoother rendering, better internationalization and font handling, improved visual integration, and security improvements compared with the older console infrastructure.

    This affects the virtual terminals users encounter outside their normal graphical desktop session.

    Most desktop users spend relatively little time interacting directly with these consoles, but they remain important for troubleshooting, system administration, servers, recovery operations, and systems running without a graphical environment.

    Moving that functionality into userspace also gives Fedora more flexibility for future development instead of relying entirely on the legacy kernel console implementation.
    Go to Full Article


  • Thunderbird 156 Released with OAuth Improvements, OpenPGP Updates, and Major Linux Fixes
    by George Whittaker
    The Thunderbird team has officially released Thunderbird 156, bringing another round of new features, security improvements, authentication enhancements, and reliability fixes to the popular open-source email client. Released on September 15, 2026, the update is available for Linux alongside Windows and macOS.

    Thunderbird 156 is not a dramatic redesign of the desktop mail client. Instead, it concentrates on improving areas that matter to everyday users and system administrators, including OAuth authentication, OpenPGP, POP3, IMAP, Exchange Web Services, SMTP, attachments, calendars, enterprise policies, and security.

    For Linux users in particular, the release delivers several fixes affecting common mail protocols and account configurations while retaining support for Linux environments using GTK+ 3.14 or newer.
    Thunderbird 156 Arrives on Linux
    Thunderbird 156 follows version 154, which arrived in August with features including optional system tray operation and Microsoft Graph support for Microsoft 365.

    Version 156 continues the project's monthly release cycle with a more targeted collection of authentication, security, compatibility, and reliability improvements.

    According to Thunderbird's official release notes, version 156 requires:
    Linux: GTK+ 3.14 or newer Windows: Windows 10 or newer macOS: macOS 10.15 or newer
    Thunderbird 156 was officially released on September 15.

    Linux distribution availability will vary because distributions can package Thunderbird according to their own schedules. Users receiving Thunderbird through another packaging channel may therefore see version 156 at a different time.
    Custom OAuth Support Expands
    One of the most significant areas of development in Thunderbird 156 is OAuth authentication.

    Thunderbird now supports custom OAuth configurations containing an issuer ID and client secret for IMAP and POP3 accounts. Custom OAuth support has also been extended specifically to POP3.

    OAuth has become increasingly important as email providers move away from conventional username-and-password authentication toward token-based authentication.

    For Thunderbird, broader custom OAuth support means users and organizations have greater flexibility when connecting the client to mail services that don't fit Thunderbird's predefined provider configurations.

    This can be particularly useful in enterprise environments, self-hosted infrastructure, and organizations operating their own identity systems.
    Exchange Custom OAuth Setup Fixed
    Exchange users receive an important related correction.
    Go to Full Article


  • KDE Plasma 6.7.5 Released with Discover, KWin, Wayland, and HDR Fixes
    by George Whittaker
    The KDE Project has officially released KDE Plasma 6.7.5, delivering another round of bug fixes and stability improvements for the Plasma 6.7 desktop series. Released on September 8, 2026, the update contains roughly a month of fixes and updated translations contributed since Plasma 6.7.4 arrived in early August.

    Unlike a major Plasma release, version 6.7.5 doesn't introduce a large collection of new desktop features. Instead, KDE has focused on fixing problems affecting Discover, KWin, Wayland, networking, System Monitor, Plasma Desktop, RPM-OSTree systems, Snap updates, HDR rendering, and several other components.

    For users already running Plasma 6.7, this makes version 6.7.5 primarily a maintenance upgrade intended to make the desktop more dependable ahead of the next major Plasma series.
    KDE Plasma 6.7.5 Arrives as the September Bugfix Release
    KDE describes Plasma 6.7.5 as its September bugfix release for the Plasma 6 desktop.

    The broader Plasma 6.7 series originally arrived in June 2026, followed by a succession of maintenance releases:
    Plasma 6.7.1 on June 23 Plasma 6.7.2 on June 30 Plasma 6.7.3 on July 14 Plasma 6.7.4 on August 4 Plasma 6.7.5 on September 8
    KDE's official download infrastructure confirms that the Plasma 6.7.5 source packages became available on September 8.

    This slower maintenance cadence later in a Plasma series is normal. Once the most urgent post-release problems have been addressed, KDE generally shifts more development attention toward the next feature release while continuing to provide important fixes for the current branch.
    Discover Receives Several Important Fixes
    KDE's Discover software center receives some of the most noticeable improvements in Plasma 6.7.5.

    One particularly annoying problem could cause Discover to become stuck while checking for updates when its Snap backend was installed but no Snap applications actually had updates available.

    That problem has now been corrected.

    Discover also behaves more reliably when fwupd, the Linux firmware update service, is unavailable. Previously, a broken or intentionally masked fwupd service could interfere with Discover's normal operation. Plasma 6.7.5 allows the rest of the application to continue functioning correctly in that situation.

    This is useful for systems where firmware updating isn't supported, where administrators intentionally disable the service, or where fwupd encounters a configuration problem.
    Firmware Updates No Longer Incorrectly Require Reboots
    Another Discover correction addresses a regression involving firmware updates.
    Go to Full Article


  • Slackware 16 Alpha 1 Released with Linux 6.18 LTS, GCC 16.2, and Plasma 6
    by George Whittaker
    One of Linux's oldest surviving distributions is moving closer to its next major release. Slackware 16 Alpha 1 became available on September 5, 2026, marking the first formal alpha milestone on the road toward Slackware Linux 16. The release follows a major rebuild of Slackware-current using a substantially newer GNU toolchain and brings together several upgrades that have accumulated since Slackware 15.0 arrived more than four years ago.

    The alpha combines Linux 6.18 LTS, GCC 16.2.0, glibc 2.44, GNU Binutils 2.47, KDE Plasma 6, and numerous updated user-space packages while retaining much of the deliberately traditional architecture that has distinguished Slackware for decades.

    For longtime Slackware users, Alpha 1 is particularly significant because it provides the clearest indication yet that the lengthy Slackware 16 development cycle is moving toward an eventual stable release.
    Slackware 16 Finally Reaches Alpha
    Slackware doesn't operate according to the predictable six-month or annual release schedules used by many other Linux distributions.

    Instead, development takes place continuously through the Slackware-current branch. Patrick Volkerding and other contributors update that development tree until it reaches a state considered suitable for a stable release.

    The previous major version, Slackware 15.0, was released in February 2022. More than four and a half years later, Slackware-current has now officially reached the first alpha milestone for version 16.

    Volkerding marked the milestone following a complete rebuild of the distribution with its newly upgraded compiler, C library, and binary utilities.

    The short changelog announcement even suggested there might finally be "a light at the end of the tunnel," a promising indication for Slackware users waiting for version 16.
    The Entire Distribution Was Rebuilt
    One of the most consequential changes behind Alpha 1 is a complete package rebuild.

    Slackware's development toolchain has moved to:
    GCC 16.2.0 glibc 2.44 GNU Binutils 2.47
    After introducing those components, Slackware rebuilt the distribution's packages against the updated environment.

    A full rebuild is much more significant than simply replacing three packages.

    GCC is responsible for compiling much of the software distributed with Slackware, glibc provides fundamental C library functionality used throughout Linux user space, and Binutils supplies essential development utilities including the GNU assembler and linker.

    Rebuilding the distribution against these versions gives Slackware 16 a considerably newer foundation than its predecessor.
    Go to Full Article


  • Top AEO Tools for Linux and Developer Documentation Teams
    by Malana VanTyler
    These platforms help teams monitor how technical content appears in AI-generated answers, from brand mentions and citations to accuracy and referral traffic.

    Search is splitting into two experiences: one built around ranked pages and another around generated answers. As AI platforms summarize Linux tutorials, open-source project documentation, API references and technical guidance, teams need ways to measure whether their content is mentioned, cited and accurately represented.

    An Go to Full Article



  • The New Way Security Teams Evaluate Pentesting Vendors
    by George Whittaker
    Why security buyers are rethinking what matters most.

    Security teams typically don’t struggle to find vulnerabilities as much as they have in the past. The harder part usually begins after the report arrives, once dozens of findings land in front of engineering teams already juggling patch schedules, production deadlines, and internal disagreements about urgency. Platforms like Go to Full Article


  • New Linux “Steal Governor” Targets CPU Contention in Overcommitted Virtual Machines
    by George Whittaker
    Linux kernel developers are considering a new “steal governor” designed to improve performance when multiple virtual machines compete for limited physical CPU resources. The proposal uses the amount of CPU steal time observed inside a guest to dynamically reduce or expand the number of virtual CPUs on which that VM prefers to schedule work.

    The feature is primarily aimed at heavily virtualized servers where administrators deliberately assign more virtual CPUs than the host can physically execute at once. Under heavy load, that overcommitment can lead to frequent vCPU preemption, lock-holder delays, cache disruption, and ultimately lower overall throughput.

    The latest v11 patch series was posted on August 25, 2026, and its developer has proposed consideration during the Linux 7.3 development cycle, potentially targeting Linux 7.4 for inclusion. This means the feature is still under review and is not part of a stable Linux kernel yet.
    What Is CPU Steal Time?
    CPU steal time is a concept specific to virtualization.

    Imagine a virtual machine has eight vCPUs. From inside that VM, the operating system behaves as though those eight CPUs are available. But those virtual CPUs ultimately need to run on the host's physical processors.

    If several VMs are competing for the same physical CPU resources, the hypervisor may temporarily prevent one VM's vCPU from running so another VM can use the processor.

    The time during which the guest wanted to execute but couldn't because the hypervisor was using the underlying CPU elsewhere is known as steal time.

    High steal time is therefore a useful indication that the physical host is experiencing CPU contention.
    The “Noisy Neighbor” Problem
    The steal governor is designed primarily to address what virtualization engineers commonly call the noisy neighbor problem.

    Consider a server hosting several VMs:
    VM A has 32 vCPUs. VM B has 32 vCPUs. VM C has 32 vCPUs. The physical server has only 64 CPU threads available to those workloads.
    That configuration can work perfectly well when the VMs aren't simultaneously busy.

    If all three suddenly become heavily loaded, however, they may collectively request more CPU time than the physical machine can provide.

    The hypervisor then has to constantly switch between vCPUs.

    Those interruptions can become particularly expensive if a vCPU is preempted while holding a lock or executing another latency-sensitive section of code. Other threads may then wait for a vCPU that isn't currently being allowed to run.

    The result can be counterintuitive: giving the VMs more virtual CPUs can sometimes make the combined workloads slower.
    Go to Full Article


Page last modified on November 02, 2011, at 10:01 PM