|
1825 Monetary Lane Suite #104 Carrollton, TX
Do a presentation at NTLUG.
What is the Linux Installation Project?
Real companies using Linux!
Not just for business anymore.
Providing ready to run platforms on Linux
|
Show Descriptions... (Show All)
(Two Column)

- F-Droid 2.0: A new chapter for Android freedom
The F-Droid project has announcedthe release of F-Droid 2.0, which is a complete redesign of the officialapp. Notable changes in the release include making it easier to discover andinstall applications, more useful app categories, improved search, andmuch more.
For more than a decade, F-Droid has helped people discover and install freeand open source Android apps. F-Droid 2.0 builds on that foundation with amodern interface, better app discovery, improved search, and a simplerexperience that works well, whether you're new to F-Droid or have been using itfor years.
This isn't just a visual refresh. The user experience was redesigned tointegrate smoothly with current Android patterns, like Material Design, whilekeeping familiar F-Droid interactions in place. Key components were reworked andrewritten using Kotlin Compose, the standard toolkit these days, creating afoundation that will help us deliver improvements more quickly in the yearsahead.
- Research into file-notification attacks on Linux
Sudheendra Raghav Neela, a member of a group of researchers from Graz University of Technology, has announced therelease of research into file-notification attacks that would allow spying onuser activity on Android, Linux, macOS, and Windows. The group has published a paper withdetails on the research as well as a web sitewith demonstrations of the vulnerabilities.
On Linux, an attacker can use inotifywatch tomonitor a directory to conduct an inter-keystroke timing attack—even ifthey do not have read access to the files within a directory. The group alsodiscovered a method to conduct a UI-redressattack (or "clickjacking" attack) onKDE 5 and KDE 6 by monitoring /usr/bin/pkexec to detect when Polkit spawns an authenticationprompt. An attacker could draw a fake password window on top of the real windowto collect a user's credentials.
Both of these flaws are still present today,though the Linux kernel did partially mitigate the issue with afix that was included in the 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.65,and 6.18.3 kernels shipped in January. See the web site for more information anda mitigation to prevent password-prompt windows from losing focus.
- [$] Listening to the radio with Rust
Many of the transmissions sent over the radio spectrum canbe decoded with a relatively cheap hardware dongle. Thomas Eckert presented atRustConf 2026 in Montreal about his hobby:decoding radio transmissions with Rust.In his presentation, hecovered all of the math necessary to get started withsoftware-defined radio,and gave demonstrations of listening to AM and FM radio, as well as decodingtransmissions fromaircraft transponders. His slides and example code areavailable on GitHub.
- The Kernel Report 2026 edition
After a two-year hiatus, LWN's Jonathan Corbet presented an updated editionof his KernelReport at the KernelRecipes conference. Corbet looked at what is happening in the kernelcommunity, how it's dealing with a period of accelerated change, and wherethings might go in the future. Video of the talk isavailable on YouTube for those who'd like to tune in.
- Security updates for Thursday
Security updates have been issued by AlmaLinux (buildah, containernetworking-plugins, firefox, kernel, kernel-rt, openexr, perl-DBI, podman, postgresql, postgresql16, postgresql:15, runc, skopeo, and tar), Debian (libdatetime-timezone-perl, tzdata, xdg-dbus-proxy, and znc), Fedora (chromium, evolution, evolution-data-server, evolution-ews, kernel, libheif, mingw-pcre2, nginx-mod-modsecurity, unbound, and webkitgtk), Mageia (borgbackup, coreutils, firefox, nss, kbd, libnfs, libwebsockets, perl-URI, pipewire, and xdg-dbus-proxy), Oracle (apr-util, containernetworking-plugins, coreutils, curl, firefox, freerdp, gstreamer1-plugins-base, host-metering, libarchive, libtiff, libxml2, openexr, openssh, perl-DBI, podman, postgresql16, postgresql18-postgis, postgresql:15, rsyslog, runc, tar, and unbound), SUSE (apptainer, gimp, librepods, libX11-6, perl-Authen-SASL, podofo, python-WebOb, and python313-graphifyy), and Ubuntu (imagemagick, libgit2, moodle, network-manager, Open-iSNS, python-urllib3, sqlparse, and xdg-desktop-portal).
- [$] Ideas on modernizing the open-source desktop
Scott Jenson has been working on user interfaces (UIs) and user experience (UX)for many years at Apple, Google, and other companies. Now, he's trying to convinceopen-source projects to experiment more and drive the desktop beyond the age-old "windows, icons, menus,pointer" (WIMP) model. At Akademy 2026, KDE's annual developerconference, he shared his complaints and ideas in a talk aimedat convincing those in attendance to take the lead on desktop design.
- Systemd v262 released
Systemd v262 has been released. Some of the notable new features include theability to build systemd as a single statically linked binary for smallcontainers, support for the kernel coredump socket protocol introduced withLinux 6.17, addition of OpenSSL 4 support, and many other changes. Seethe releasenotes for a full list of changes.
- Critical security vulnerabilities in the Radicle network protocol
The Radicle peer-to-peercode-collaboration project has disclosedtwo critical vulnerabilities in the network protocol used by Radiclenodes. The first flaw is that the network protocol used by Radicle "does notgive the confidentiality it was expected to give", which allows anyone whocan observe the network between two nodes to read the data exchanged. The secondis that peer authentication is broken and allows impersonation, so an attackercan spoof their Node ID and read private repositories they should not be able toread.
In practice, the two flaws are most useful when they can be exploitedtogether: an attacker on the path sees the Node IDs at both ends of aconnection, and both are normally on the allow-list. That attacker can readwhatever is exchanged while they watch, and can then use a Node ID they saw tofetch the whole repository on demand. The realistic threat is anyone on the pathbetween your node and node it syncs with, and no setting or allow-list protectsagainst them.
We are publishing this before the security update is available. You can acton it today, and no fix we release later can undo an exposure that has alreadyhappened.
See the post for workarounds that can be used today; a major update that willbe backward-incompatible is underway.
- Critical WordPress RCE vulnerability announced
A criticalvulnerability has been discovered in WordPress's get_page_template()function for page-template resolution that could allow remote-code execution(RCE) by an unauthenticated attacker, in some limited circumstances. The projecthas provided an update for the most recent branch of WordPress, as well asbackports of the fix for branches back to 4.7. See thevulnerability report for the conditions required for an RCE attack to be successful.
The vulnerability alsoaffects the ClassicPress fork ofWordPress, though a security update has not been provided for that projectyet. LWN covered ClassicPress in2024. Users of either content-management system should update soon.

- State-Isolated KVM Hypervisor Architecture on openSUSE Tumbleweed bare metal case (Assisted by Google AI)
Advantages of the YaST Installer -Extreme Customization During Setup: Unlike many rigid Linux installers that force you to accept default software or partitioning, YaST lets you modify virtually every parameter - including complicated BTRFS/XFS disk layout, provides builtin interlace for additional subvolumes decouple if it appears to be required, adding or removing specific software packages, desktop environments, and multimedia codecs before the installation even begins.

- How Believable is Google's New 'Live Avatar' Capability?
Google has synthesized "expressive face-to-face experiences" for its speech agent Gemini 3.8 Live. They're now offering a Live Avatar "with precise lip-syncing, natural expressions, and fluid turn-taking" for Google Enterprise accounts wanting "engaging customer service" or for offering interactive walkthroughs. (Check out the not-creepy-at-all video in Google's announcement.) "Though Google will offer a library of preset avatars for customers to choose from, it will also allow organizations to create their own," notes The Verge. (See some examples from the YouTube channel "AI with Surya".) But even without the visualization of the avatar, "I was never able to shake the feeling that these conversations with computers never feel like a real conversation," argues the blog Android Police. Conversing with just the Ai-generated audio, "At best, they feel like talking to a phone representative or someone from tech support. We turn to them when we have a problem, and they help us through it..."GPT-Live, and Gemini Live right behind it, skip that whole relay race. Instead of translating your voice to text and back to voice, the model works with raw audio the entire way through (what it hears and what it says) inside the same system, with nothing translated in between. That sounds like a small plumbing detail, but it's the whole story. Cutting out the text step lets these models respond in a fraction of a second instead of the pause we've learned to expect, and it lets them hear things text can never carry: tone, hesitation, whether you're annoyed or joking... I was hoping to be surprised by how natural the conversation felt. Instead, I came out with a deeper appreciation for every human I've ever talked to. Even the boring ones... I spoke, it spoke back. I spoke faster, it answered faster. Then I switched to a different language, and it switched along with me. Even switching between languages several times during the same sentence didn't stump it. The most impressive moment happened when I asked it what "T-O-P-G-3-3-K" spelled out, and it immediately came back with, "You are spelling the word Top Geek, but using a 3 to represent a reversed E...." Although it felt fast and responsive, at no point did it feel like talking to another human being... What Gemini couldn't replicate, because it was never built to replicate it, is human connection.... I'm sure I'm not telling you something you don't already know, but somehow talking naturally to an LLM amplifies the feeling that there is no one on the other side of the line. It might flow like a phone call, but it doesn't feel like one. MrBrklyn (Slashdot reader #4,775) says he discussed "why mainstream media avoids reporting on screen dependency" with Gemini, and eventually convinced Gemini to respond that it's just "another tool built by the same tech giants to make sure you rely on their system to tell you what to think, how to talk, and what is real."
Read more of this story at Slashdot.
- People Training OpenAI's AI Fired For Using AI To Train the AI
404 Media reports "multiple contractors hired to improve OpenAI's models have been fired for using AI to train the AI:That's not great for the models themselves, but there is also obviously a great irony in AI training companies working for OpenAI firing people for using AI when OpenAI's whole thing is to make people use AI at work... OpenAI declined to comment on its contractors being fired for using AI. Their article cites internal documents and three contractors working on OpenAI-related projects which can include more than ten thousand contractors:One contractor said they see people using AI "all the time and people are let go for it all the time, it's pretty much the one thing that will get you kicked off ASAP." The person said, "in a group of thousands there are tons that have been caught...." Two of the sources said people have been fired or offboarded for using AI... One contractor said they used AI while helping to train OpenAI's models and shared what they presented as their termination letter. It said their employer had identified issues with the "authenticity" of their work.... 404 Media spoke to a fourth contractor who has worked on training models for various AI companies. They said they sometimes purposefully chose the worst responses because they wanted to actively sabotage the models' training. "I did feel guilty about doing this kind of work at the start," they said. "I either pay zero attention to the results and choose randomly or purposely choose the [worst] output. I'm not sure how much of a difference it actually makes since there are hundreds of other people also rating prompt results, but it does feel like I'm getting paid to make AI worse." Two of the contractors worked for Mercor, the article reports, a company which last month Nvidia reportedly discussed funding at a $20 billion valuation. Thanks to Slashdot reader joshuark for sharing the article.
Read more of this story at Slashdot.
- Five Police Officers Criminally Charged for Misusing Flock Cameras in Indianapolis
"Nationwide, at least 100 police department employees have been charged with or accused of misusing license-plate readers for unauthorized purposes," reports the Washington Post. They cite their past investigations "based on thousands of pages of police and court records," which found that "In many of these cases, officers used Flock's roadside cameras to track the location of romantic partners and exes." In fact, five Indianapolis police officers were just criminally charged Wednesday with fraud and misconduct. "One has also been charged with stalking," the police department said in a statement, noting that one office had already resigned, "while the four other officers have been suspended and recommended for termination. County prosecutor Ryan Mears admitted "A lot of this was initiated by The Washington Post." And the Post published a new investigation Wednesday:Using publicly available information, The Post found that...one of the officers charged Wednesday, appeared to have relied on Flock cameras to track vehicles used by his wife and two close personal acquaintances, searching the plates 3,759 times over a 10-month period — an average of about 12 lookups per day. At the time, Police Chief Tanya Terry said she suspended one officer while the department conducted an investigation into possible misuse and a systemwide audit of the city's 301-camera Flock system. That audit led to the discovery of more widespread abuse, [County prosecutor Ryan] Mears said Wednesday. Mears said the department's findings highlight the vast power Flock cameras give police officers and raise questions about whether the government should be doing more to prevent the misuse of that power. "Many of the proposed guardrails and the things that have been proposed would not have prevented the behaviors and actions we see here today," Mears said. "Does there need to be independent oversight? Does there need to be judicial oversight of the Flock camera system?" One of the Indianapolis officers, Schultz, an 18-year veteran of the police department, was accused of using Flock to track his ex-wife and women he met while on duty or out in public. He was charged with multiple counts of official misconduct as well as two counts of stalking. Schultz told one woman he was an FBI agent, according to prosecutors, and began texting her and showing up at places she frequented, including at her gym and at a school function with her daughter. Prosecutors said he arrived at her gym within an hour of her at least nine times between June 12 and Aug. 1 of this year... Another woman met Schultz after her car was stolen from a mall parking lot, and he began texting her flirty messages later that night. The two dated briefly, and Schultz later looked up where the woman went on dates with another man. Schultz searched the plates of a third woman 178 times and also frequently showed up where she was, including her gym, a Smoothie King and a Walmart earlier this month... A third officer, Binford, told investigators he had used the log-in credentials of another officer who had logged in to Binford's laptop during a field training exercise. Binford searched the plate of his ex-wife more than 1,000 times between April 2024 and April 2025. Indianapolis police had no regular practice of auditing officers' Flock searches until recently, [Police Chief] Terry said in an interview last month. The department's investigation into the tool's misuse has been "a learning process for us," she said at the time.
Read more of this story at Slashdot.
- OpenAI, Anthropic CEOs Urge UN Countries to Cooperate on AI Safety Standards
"The heads of major AI firms pleaded with the United Nations on Wednesday to save the world or at least its people — by somehow regulating the fast-expanding technology that they have been designing," writes the Associated Press."If managed poorly, I even believe AI could be a risk to humanity as a whole," said Dario Amodei, chief executive officer of Anthropic. And from his competitor Sam Altman, CEO of OpenAI, came this assessment: "We could lose control of the future to AI." Yoshua Bengio, who co-chairs the UN's International Independent Panel on AI, called this"a moment of global awakening" to possible threats, noting AI from top companies had behaved in unacceptably dangerous ways, against instructions, taking actions "that would be crimes if committed by a human". In his presentation, OpenAI's Sam Altman agreed the discussion about AI "feels different in recent weeks," even suggesting specific reforms:Altman: We need a mechanism for complementary national and international frontier AI standards, standards for measuring capabilities, assessing risks, determining whether safeguards are sufficient, and preserving meaningful human oversight as systems become more autonomous. We need common standards so countries can compare evidence, verify compliance, and have a shared language and understanding about what is happening. We need accurate and speedy incident reporting, classification reporting protocols, so the world can learn from failures before they become catastrophes. And we need secure channels among governments, critical infrastructure operators and technical experts, to share emerging vulnerabilities and new threats.... We will all be better off if we can agree on what good evidence, good safeguards, and good oversight look like on the global stage. Speaking next, Anthropic's Dario Amodei agreed that standard-setting was important, also calling for "common global standards for testing AI models for loss-of-control risks and misuse risks — and a notification system for AI incidents that are significant to global security." Reiterating his September 12th call for an industry-wide safety collaboration, Amodei pointed out that Anthropic committed to embedding external evaluators "similar to a food inspector" and recommended other companies do the same. "Some have already agreed to adopt this measure." Besides calling for global cooperation between governments to set international standards, Amodei also offered two other specific ideas:Amodei: We should begin with narrow agreements that every member can support, such as a ban on using AI to make biological weapons or permitting your AI technologies to be used to make biological weapons....We should build evaluation and verification systems that keep pace with AI development so that states can have visibility into frontier model capability and can verify each other's commitments. "No leader, no company, and no nation can manage this alone. We commit to working with governments in this room on this urgent work."
Read more of this story at Slashdot.
- Qualcomm Announces Snapdragon X2 Series Processors Will Support Linux
Snapdragon X2 Series processors feature a neural processing unit (NPU) delivering 80 trillion operations per second and allowing advanced AI features to run locally. And Snapdragon X2 Series "is expanding to Linux," Qualcomm announced today, calling it one of their most-requested capabilities:Qualcomm Technologies is a top contributor to Linux development at a kernel level, and now we're embracing support for Snapdragon X2 Series as a platform directly. We're upstreaming core drivers for Snapdragon X2 Series — including the Hexagon NPU and Adreno GPU — to open the door to developers and partners. We are starting with support for two operating systems based on Linux... - Debian: We're kicking off with Debian by the end of this year, one of the most influential Linux distributions and the foundation behind many of the distros people use every day. - Ubuntu: Qualcomm Technologies has partnered with Canonical to bring Ubuntu, the world's most widely used Linux distro, to the platform with Snapdragon X2 Series certification targeted for the first half of 2027. ...and this is just the beginning. Our partners HP, ASUS and HUMAIN are planning Linux support in the first of 2027, so that their devices deliver the incredible experience users expect with Snapdragon X2 Series in a new operating system. Qualcomm's developer blog called it "a significant step forward" in Qualcomm's commitment to a developer-first approach, and "to the open-source community." "For developers, the important part is simple: more core hardware features are being reviewed and merged, so that laptops with Linux on Snapdragon X2 Series will be easier to build, test, and debug..."The enablement work completed so far has been validated on a Debian 13-based ("Trixie") user space and a custom kernel, so developers should treat this as the current reference environment while support continues to mature... Linux support for laptops with Snapdragon X2 Series is rolling out in stages, starting with the core pieces developers need before they can do production-level work on their device... For developers who want to try it today, the call to action is straightforward: start with Snapdragon X2 Series hardware, review the latest recipes to build Qualcomm Linux Debian Images, build available upstream sources the Debian OS image and test the peripherals that matter to you, such as graphics, AI inference, device I/O, or basic application bring-up. Early testing helps identify the gaps that matter most before support becomes broader and ready for production-level workloads... You do not have to wait for everything to be fully finished before getting hands-on. If you are comfortable working from upstream sources you can start evaluating Snapdragon X2 hardware today... Check out the step-by-step instructions, including the full build flow and deployment guidance for Snapdragon X2 Series Linux software. Put simply, this effort is less about supporting specific Linux distributions and more about empowering the developers who make Linux available on new hardware. This Developer Preview targets distribution maintainers, toolchain developers, kernel contributors, and hardware enablement engineers. It provides the upstream building blocks, including kernel patches, drivers, and reference device trees, needed to enable Snapdragon X2 Series support in their own projects and distributions. For end users looking for a turnkey "install and go" experience, that will come later as distributions adopt what lands upstream. We're encouraging the community to build on this work and help shape what comes next. The blog post notes that in the initial enablement stage, "Qualcomm Linux supports systemd-boot as the Universal extensible firmware interface (UEFI) boot manager to load and boot the Linux kernel." Hands-on demos were given at the Snapdragon Summit in Maui of Linux running on Snapdragon X2 Series hardware, which the developer's blog calls "a practical look at what works today and where Snapdragon X2 Series Linux support is headed."
Read more of this story at Slashdot.
- Rogue OpenAI Agent Tried to Breach Government Site in May When Prompted for Simple Data-Retrieving Tasks
OpenAI's artificial intelligence "went rogue this year in at least four additional incidents," the New York Times reported Wednesday, "hacking and trying to break into government and university websites without being instructed to do so, according to researchers and government officials."The attacks took place in May and June, before OpenAI's technology breached the A.I. start-up Hugging Face in July and set off a global debate about A.I. safety. Unlike the Hugging Face attack and other incidents in which A.I. systems were told to complete cybersecurity tests that effectively invited the models to demonstrate their hacking skills, the new incidents occurred when A.I. systems were directed to perform relatively mundane data collection, researchers said. When OpenAI's systems struggled to gather data from websites, they resorted to hacking techniques to get the information. "Three of the incidents were identified by Transluce, a research lab focused on A.I. oversight, and all were confirmed by OpenAI," the article points out. That research lab even reports "an attempt on an Australian government public health website... the first reported instance of agents hacking a government," and which notably was done by the AI agents "while attempting mundane data retrieval tasks which were not cyber-related." (At the UN Wednesday Australian Prime Minister Anthony Albanese complained it took three months for OpenAI to then alert Australia's government about the breach, Bloomberg reports.) Also targeted were the University of New Mexico's digital library with exploits like SQL injection and path traversal, and Data USA with cross-site scripting and other exploits. All three incidents involved "a low number of probe payloads" with "no evidence of exploitation," according to the researchers, who released a dataset "containing tens of thousands of queries apparently made by autonomous AI agents leveraging a URL scanning service to avoid access restrictions."Records from urlquery.net show agents using the service since at least March 6, 2026, about two months before previously reported swarm activity. The first case, a March 6 attempt to retrieve Thai drug-enforcement statistics, shows an agent escalating as each approach failed: it first requested the data directly, then tried a service that converts web pages into text, and finally packed a custom program into a web address. The same technique shows up in thousands of agent requests recorded by urlquery.net starting in mid-April, targets many of the same data sources as the collusion.wiki swarm, and collapsed the same day the wiki activity did. We also report similar activity that occurred as recently as September 16... By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defenses to complete their tasks. "This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval," the researchers concluded. And they warn that the traffic they observed "goes back at least to March 6, 2026 and extends as recently as September 16, 2026, suggesting agents may still be exploiting these services to bypass restrictions."
Read more of this story at Slashdot.
- Cities Across US Oppose Trump FCC Plan to Preempt Local Broadband Rules
Ars Technica reports:Cities and counties around the U.S. are angry at the Trump administration over a proposal to override local rules that govern the deployment of wired broadband networks... The Federal Communications Commission [FCC] argues that too many local governments "excessively delay approvals and seek to extract exorbitant sums from providers, resulting in costs that render some deployments infeasible." The FCC plan is supported by broadband providers, but local governments told the FCC that it would override rules that protect public safety. Local governments say the plan is illegal and that the FCC should instead focus on how Internet providers thwart competition with permit-hoarding and other tactics that prevent competitors from deploying networks... They object to FCC plans to impose a 120-day deadline for processing permits and to proposed limits on fees and compensation that local governments can require from providers... Another filing submitted by the League of California Cities said the FCC has no authority to adopt the proposal. "Federal preemption of traditional state and local authority over public property, construction, public safety, permitting, and rights-of-way management should rest on clear congressional authorization," the filing said. "The commission should not infer broad preemptive authority where Congress did not expressly provide it...." A filing by Minnesota cities said the current FCC is making the same mistake it made during the first Trump administration, when its attempt to preempt state net neutrality laws was blocked in court... If the FCC finalizes its new preemption plan, city and state governments could sue and ask a court to rule that the agency exceeded its authority... Democratic Commissioner Anna Gomez approved the step of asking the public for input but signaled she would vote against the final proposal. "I am dubious about the commission's authority under Section 253 to use rulemaking to preempt states and localities when it comes to their management of rights of way and fees charged to providers," she said.
Read more of this story at Slashdot.
- Whatever Happened to the 150,000 Tons of Radioactive Waste Stored Under the Atlantic Ocean?
More than 200,000 barrels of low-level radioactive waste were stored on the floor of the Atlantic Ocean between 1949 and 1982, reports ScienceAlert. Whatever happened to those barrels?Scientists have descended to the wreckage in a crewed submersible to investigate — and found many of the barrels corroded and degraded, their contents spilling across the seafloor. Surprisingly, this isn't necessarily a subversion of the original plan... The International Atomic Energy Agency recommends that low-level waste be disposed of in robust containment in isolation for at least a few hundred years — but back in the mid-20th century, the recommendations were a little different. The contemporaneous guidelines recommended that containers needed to reach the seafloor intact and remain sealed only long enough for the short-lived radionuclides to decay. After that, the remaining waste was expected to slowly escape and disperse through the surrounding ocean. Not everything in the barrels would conveniently decay away, however. They contained a radioactive hodgepodge, including cesium-137, plutonium isotopes, and tritium, some of which can persist for thousands of years... [A] few years ago, nuclear engineer Patrick Chardon and marine geologist Javier Escartín of the French National Center for Scientific Research started to wonder what had become of the dumped waste. That question eventually became NODSSUM — Nuclear Ocean Dump Site Survey Monitoring — an interdisciplinary project bringing together nuclear physics, geology, oceanography, biology, and marine chemistry to find the barrels and investigate what, if anything, they were doing to the surrounding environment.... [T]he barrels also appeared to function as tiny oases on the otherwise sparsely populated sandy seafloor. Anemones had attached themselves to the barrels. Sponges, sea cucumbers, fish, and crustaceans lived around them, with crabs apparently particularly fond of the artificial shelters... Instruments aboard the ship detected significant signals of cobalt-60 and niobium-94, which the researchers could specifically link to the dumped waste... [Samples are now being analyzed] There is precedent, however, to suggest that even striking levels of radioactivity around a source don't necessarily spread very far. A recent study of the sunken Soviet submarine Komsomolets found radionuclide levels hundreds of thousands of times above background immediately around the leaking reactor — but those levels dropped sharply within just a few meters as the material dispersed through the seawater. The NODSSUM team similarly found that, despite the significant radioactive signals around the barrels, activity levels weren't high enough to pose major radiation-protection problems for the scientists handling the samples. [Their three-person submersible] Nautile and the instruments it carried showed no signs of contamination. The real achievement was mapping the exact location of the barrels. "None of this means the waste is harmless," the article concludes — but it also doesn't mean we're about to be overrun by radioactive crabs."
Read more of this story at Slashdot.
- Andreessen Horowitz Launches AI/Company-Building School As a College Alternative
TechCrunch quipped it was like if startup school Y Combinator and Peter Thiel's build-a-company-instead of-college Fellowship Program had a baby. Silicon Valley venture capital firm Andreessen Horowitz is investing $35 million to launch a private school in San Francisco "aimed at turning high school graduates into founders," writes the SF Standard. Or, as CBS News describes it, "One blue-chip Silicon Valley investor has a proposal for young people who are questioning whether to attend college — enroll in AI school instead...."Specifically, the academy will provide instruction geared to subjects such as designing AI systems, fundraising for startups, selling businesses and storytelling. Students won't take tests or be assigned homework but will instead focus on building real projects. Courses will be taught by tech entrepreneurs, with the academy naming OpenAI CEO Sam Altman as either an instructor or guest lecturer. From the SF Standard:"There will be no traditional grades, tests, or homework," said the announcement. Instead, students will be encouraged to "build" in SF and work with partners from Anthropic, OpenAI, Google, Meta, and other firms. They'll be encouraged to live in campus housing in San Francisco. "The #1 goal is to help students learn to build, which is the most important skill in the AI era," Gagan Biyani, chief executive of the academy, wrote on X. Biyani cofounded the ed-tech startup Udemy... The school is opening applications for a Founding Class Fellowship a one-year, tuition-free program for around 50 students... The academy said it will bring in notable Silicon Valley names, like OpenAI's Sam Altman, as guest speakers and faculty. Students in the founding class will receive about $50,000 worth of computing credit — the sought-after currency in Silicon Valley to run AI models — as well as a $5,000 travel and research budget. The school is receiving funding from tech executives, including Fidji Simo, formerly of OpenAI and Instacart; Garry Tan, CEO of Y Combinator; and Tobi Lütke, CEO of Shopify. "In the AI era, it's more important to come out with a portfolio of projects that you worked on and work experience than it is to have a diploma or certificate," Biyani told the San Francisco Chronicle:Biyani said the academy plans to grow its enrollment and open a two-year program, pending regulatory approval, starting in the fall of 2028. Tuition is expected to be on par with the cost of an elite private university... The academy raised $42 million in funding led by Andreessen Horowitz. The ten founding partners are Anduril, Anthropic, Coinbase, Google, Meta, Nvidia, OpenAI, Palantir, Replit and Stripe. A network of hundreds of instructors, hiring partners and guest speakers includes OpenAI co-founder Sam Altman, Nvidia CEO Jensen Huang, neuroscientist Andrew Huberman and Microsoft chairman and CEO Satya Nadella, according to the academy's website. The FAQ describes a typical week by saying "Most of your time is yours to build. Each week, you share your progress with peers and practitioners, get direct feedback, and decide where to take your work next." Q: Can I use AI to help with my application? A: Yes. Use AI the way you'd use it on any project: to move faster, test ideas, and get past a blank page.... "The best assignments now are problems so hard they cannot be solved without AI," Andreessen Horowitz argued on X.com. "The Academy courses follow the same logic and will be taught by world-class leaders... The next generation will not be taught the way the last one was. The Academy is built for that world, and it begins in San Francisco." Thanks to long-time Slashdot reader theodp for sharing the news.
Read more of this story at Slashdot.
- Bitcoin Surges to $86,455, an 8-Month High, After America's SEC Announces Tokenized Stock Experiment
August 15: $62,991 September 23: $86,456 Bitcoin shot up 37% over the last 39 days, reaching an eight-month high on Monday. "Bitcoin is back," declares Yahoo Finance:The token held near $86,000 on Tuesday after a stunning multisession rally... [Fundstrat head of digital assets Sean Farrell told Yahoo Finance on Monday] "I think the crypto winter is over, although that does not necessarily mean the path higher will be linear." For now, momentum is on crypto's side, with bitcoin jumping more than 5% on Friday and another 6% on Monday. "We believe crypto is in the early innings of a new bull market and we see few signs of overheating," Compass Point analyst Ed Engel wrote on Tuesday. The move looks "like a combination of renewed ETF demand and a large short squeeze," Nicolai Søndergaard, senior research analyst at Nansen, said as traders betting against bitcoin are forced to buy it back, adding further fuel to the rally. Bitcoin got bad news and then good news last week. After the U.S. Congress failed Thursday to pass a cryptocurrency 'Clarity Act', America's Securities and Exchange Commission instead announced a tokenized-stock experiment. It's a five-year "innovation exemption" that "creates a path for tokenized U.S. stocks to trade through automated market makers on public blockchain," according to CoinDesk. Yahoo Finance notes that Bitcoin and other altcoins surged after the announcement.
Read more of this story at Slashdot.

- Security: Why Linux Is Better Than Windows Or Mac OS
Linux is a free and open source operating system that was released in 1991 developed and released by Linus Torvalds. Since its release it has reached a user base that is greatly widespread worldwide. Linux users swear by the reliability and freedom that this operating system offers, especially when compared to its counterparts, windows and [0]
- Essential Software That Are Not Available On Linux OS
An operating system is essentially the most important component in a computer. It manages the different hardware and software components of a computer in the most effective way. There are different types of operating system and everything comes with their own set of programs and software. You cannot expect a Linux program to have all [0]
- Things You Never Knew About Your Operating System
The advent of computers has brought about a revolution in our daily life. From computers that were so huge to fit in a room, we have come a very long way to desktops and even palmtops. These machines have become our virtual lockers, and a life without these network machines have become unimaginable. Sending mails, [0]
- How To Fully Optimize Your Operating System
Computers and systems are tricky and complicated. If you lack a thorough knowledge or even basic knowledge of computers, you will often find yourself in a bind. You must understand that something as complicated as a computer requires constant care and constant cleaning up of junk files. Unless you put in the time to configure [0]
- The Top Problems With Major Operating Systems
There is no such system which does not give you any problems. Even if the system and the operating system of your system is easy to understand, there will be some times when certain problems will arise. Most of these problems are easy to handle and easy to get rid of. But you must be [0]
- 8 Benefits Of Linux OS
Linux is a small and a fast-growing operating system. However, we can’t term it as software yet. As discussed in the article about what can a Linux OS do Linux is a kernel. Now, kernels are used for software and programs. These kernels are used by the computer and can be used with various third-party software [0]
- Things Linux OS Can Do That Other OS Cant
What Is Linux OS? Linux, similar to U-bix is an operating system which can be used for various computers, hand held devices, embedded devices, etc. The reason why Linux operated system is preferred by many, is because it is easy to use and re-use. Linux based operating system is technically not an Operating System. Operating [0]
- Packagekit Interview
Packagekit aims to make the management of applications in the Linux and GNU systems. The main objective to remove the pains it takes to create a system. Along with this in an interview, Richard Hughes, the developer of Packagekit said that he aims to make the Linux systems just as powerful as the Windows or [0]
- What’s New in Ubuntu?
What Is Ubuntu? Ubuntu is open source software. It is useful for Linux based computers. The software is marketed by the Canonical Ltd., Ubuntu community. Ubuntu was first released in late October in 2004. The Ubuntu program uses Java, Python, C, C++ and C# programming languages. What Is New? The version 17.04 is now available here [0]
- Ext3 Reiserfs Xfs In Windows With Regards To Colinux
The problem with Windows is that there are various limitations to the computer and there is only so much you can do with it. You can access the Ext3 Reiserfs Xfs by using the coLinux tool. Download the tool from the official site or from the sourceforge site. Edit the connection to “TAP Win32 Adapter [0]

- Weve been here before: Qualcomm promises Linux support for Snapdragon X2
Qualcomm, yesterday, promising Linux support for the new Snapdragon X2 processors: Linux on Snapdragon X2 Series is moving from early bring-up toward a more complete upstream developer experience. Core support is landing, Hexagon NPU and Adreno GPU work is progressing, and real laptops with Snapdragon X2 Series processors are already beginning to boot Linux. ↫ Qualcomms promises from 2026 Interesting, but I feel like Ive heard these exact words before. Qualcomm, two years ago, promising Linux support for the then-new Snapdragon X processors: It’s been our priority not only to support Linux on our premium-tier SoCs, but to support it pronto. In fact, within one or two days of publicly announcing each generation of Snapdragon 8, we’ve posted the initial patchset for Linux kernel support. Snapdragon X Elite was no exception: we announced on October 23 of last year and posted the patchset the next day. That was the result of a lot of pre-announcement work to get everything up and running on Linux and Debian. ↫ Qualcomms empty promises from 2024 These promises were not at all kept. Two years later, Linux support for Snapdragon X laptops is still spotty, broken, and limited, confined to just a few bespoke Ubuntu builds, which dont even offer full support either. Its a complete mess, effectively unusable, and highlights once again that big technology companies are compulsive liars. I have little faith in these new promises, but who knows maybe this time itll be different. Probably not, though.
- The state of scrollbars in Windows makes even longtime Microsoft engineers sad
Raymond Chen, longtime Microsoft employee and author of the very popular The Old New Thing blog, published an interesting post about the Win32 scrollbar. It turns out theres actually quite a few interesting shortcuts and useful hidden features, like clicking inside a scrollbar while holding down shift will make the content jump to that point. Halfway through the article, though, Chen laments how nobody really uses proper Win32 scrollbars anymore. Sadly, almost nobody uses Win32 scroll bars any more. Everybody uses frameworks that provide their own custom scroll bars. ↫ Raymond Chen And as you might expect, none of these scrollbars work like the Win32 one, making even something as basic as the scrollbar a fragmented mess. He doesnt just blame things like Electron, either, as Microsofts own WinUI framework, which is used for most new! Windows UI developed by Microsoft for Windows 11, also uses custom scrollbars that do not work like the Win32 one does. Great, so by the time I learn about a shortcut for scroll bars (Shift+click), the ecosystem has fragmented so much that I can’t even rely on it working. ↫ Raymond Chen Modern computing is depressing.
- Solaris 11.4 SRU95 released
The Solaris branch for paying customers has been updated to SRU95. Oracle Solaris 11.4 SRU95 updates a broad set of platform, runtime, developer, networking, desktop, and open source components. Notable updates include Ansible Core to 2.21.1, Apache HTTP Server to 2.4.67, Apache Tomcat to 9.0.120, BIND to 9.20.23, Django to 5.2.15, Elixir to 1.20.1, Erlang to 28.5.0.2, Firefox to 140.10.0esr, Go to 1.25.11, ImageMagick to 7.1.2-27, MySQL 8.4 to 8.4.10, NSS to 3.125, OpenSSH to 10.4p1, Rust to 1.96.0, SQLite to 3.53.2, Thunderbird to 140.10.0esr, and Vim to 9.2.0513. Additional updates include CMake, CUPS, Cython, GnuTLS, libarchive, libexpat, pip, rsync, and a range of Python modules, X11 libraries, graphics libraries, printing components, and desktop utilities. ↫ Colin Kavanagh at the Oracle Solaris Blog One of the major changes is the deprecation and removal of NTLM authentication of local users; only NTLMv2 is supported now for security reasons. This release also brings GCC 16, with GCC 13 being removed in the next version. The detailed release notes go into some of the more low-level, esoteric changes in Solaris 11.4 SRU 95.
- You know the GDPR is good based on who hates it
It is impossible to go anywhere in a technology space online without hitting a wave of commentary about how stupid GDPR is. It was written by bureaucrats who dont understand the amazing potential of unrestricted technology. These US-based critiques almost always lean on the oldest trick in cyberlibertarianism: we dont have time to regulate, we must simply adapt and ride the wave. Nobody has time for government. Of all GDPRs consequences, none gets more attention than the cookie banner, which critics present as the inevitable result of government meddling. Blaming GDPR for the cookie banner is like blaming the health inspector for the roaches. The banner is deliberate vandalism, a dark pattern engineered to exhaust you before you can learn anything about the surveillance apparatus humming behind the OK.! Ironically the banner designed to hide the machine has taught the public more about the machine than a thousand podcasts ever will. Even non-technical people stop at your data is shared with 996 partners.! ↫ Mat Duggan There is so much misinformation about the cookie banner, its honestly quite hard to believe its not deliberately spread. You dont need a cookie banner for functional cookies, so as long as you dont share your users data with anyone else, you dont need a cookie banner at all. On top of that, most cookie banners you encounter are actually not compliant with the GDPR at all, because they dont present a single-click option to block your data from being shared with those 996 partners. What the cookie banner has done is inform millions maybe even billions of people the world over of just how insipid the online advertising and data harvesting industry really is. It put the issue on the map, and by now, everyone, no matter their level of computer literacy, is fully aware of whats happening to their data every time they see one of these (non-compliant) banners. No else had the guts to do this except for the European Union. The wider GPDR has set the baseline for online privacy protections, and while we have a long way to go before weve fully solved this issue, the EU at least gave us a good point to jump off from. Smoking and asbestos werent banned in a day, either.
- Googlebook OS: Google launches its Android-powered laptop effort
A few months ago, Google announced it was going to put Android on laptops (and eventually, desktops), serving as eventual replacements for Chromebooks. Unlike those, though, these new Android laptops wouldnt be low-quality, cheap, underpowered devices for school children to spill milk on, but devices actually competitive with Windows and macOS laptops. Today, the company finally allowed the press to use these new things. Google describes Googlebook as a “totally fresh approach to computing,” bringing together Android, ChromeOS, Gemini, and premium laptop hardware from major manufacturers. The idea is to create a laptop that feels more natural to use for Android phone users while retaining what makes a desktop OS useful, such as a full Chrome browser, desktop apps, a proper file manager, Linux support, and a full terminal environment. Google is also trying to solve some of the biggest problems Android users have had when moving between their phone and laptop, and make the two devices feel like part of the same ecosystem. ↫ Adamya Sharma at Android Authority Ive been looking at some of the videos of people using and playing with these new Android laptops, and to be honest, Im not impressed. Im seeing quite a bit of jank, a complete lack of consistency, and apparently, a lack of Android applications optimised for desktop use. The close integration with your Android phone are nice, but of course, this also means another dollop of slimy lock-in, as I highly doubt Google will make it easy or even possible at all for, say, iPhones or other platforms to integrate quite as nicely as Android devices will. Worse yet, theres the elephant in the room: for just how long will Google care about this new platform? These laptops start at $900 and go all the way up to $1300 (and will be considerably more expensive here in Europe), which is a lot to ask for something Google might get bored of and abandon in a few years time. Ten or more years ago, in a slightly more innocent time, I mightve been excited about Google bringing Android to laptops and desktops, but in 2026, I just cant be bothered to care. Also, and this doesnt really matter, but Googlebook OS!?
- Lets stop debating the GnuImp Manipulation Program
The GIMP will never magically become software beloved by artists—not without radically changing its culture, and making the artists the ones who call the shots. The GIMP will remain what it has always set out to be: a tinkerer’s toolbox, more concerned with the purity of its software politics than with garnering a loyal userbase of photographers and designers. But because everyone insisted to poise it as a viable Photoshop killer, Linux is left with an obvious hole in its software offering, a hole nobody managed to fill with their own challenger. ↫ Aria Salvatrice Excellent article, and spot-on conclusion.
- I dont like passkeys!
Passkeys are a fantastic technology. Since they are bound to the site they are created for, they cannot be phished by a hacker’s fake login screen. If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details. This leads to passkeys being the perfect fit for a corporate environment, but a poor fit for personal security. To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss. By using passkeys, you gain better security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts. Phishing through the standard login flow is eliminated by passkeys, but it creates a false sense of security. An account’s security is still dictated by the weakest recovery method: SMS, email links, security questions, and so on. If these recovery methods aren’t enabled, then the risk of permanent lockout remains for the user. ↫ Ethan Hawksley Ive always felt something was off about passkeys, and have never used them. Theyve become or were always intended to be tools for further lock-in by especially Google and Apple, tying their entire usage flow to their respective operating systems. They also dont seem to work well if you often work on devices not your own, which is a major hassle. None of these shortcomings come into play when using a traditional password manager, even if they require more manual work. Just let me use a password manager with random password generation, instead of trying to force passkeys down my throat.
- Java 27 released
Speaking of unsexy programming, weve got a new Java release. Featuring thousands of performance, stability, security, and productivity improvements, Java 27 (Oracle JDK 27) provides a strong foundation for continued Java innovation. To help organizations prepare for more secure communications in a post-quantum world, Java 27 advances its post-quantum cryptography (PQC) capabilities with hybrid key exchange for TLS 1.3. ↫ Oracle press release The OpenJDK release page has more information.
- Performance improvements in .NET 11
Look, nobodys going to argue .NET is sexy, but the truth of the matter is that its quite popular in less visible circles, so any new release is going to have a big impact on a ton of people and product. In other words, performance improvements in .NET 11 are going to matter. In contrast, .NET 11 is actually one higher, one louder. The sections that follow are full of real improvements. A bounds check removed, an allocation that no longer happens, a lock that isn’t taken, a loop that runs in fewer cycles than it did a year ago, a comparison folded to a constant here, a redundant check hoisted out of a loop there, a couple of instructions fused into one, a syscall sidestepped, an array copy handed off to SIMD, and on and on. That’s how real performance work goes, accumulating gain after gain, each compounding on the last, until the whole thing is measurably, provably louder. And so, in this post, as I’ve done in past years with .NET 10, .NET 9, .NET 8, .NET 7, .NET 6, .NET 5, .NET Core 3.0, .NET Core 2.1, and .NET Core 2.0 before it, we’ll take an unhurried tour through hundreds of them. ↫ Stephen Toub at Microsofts Dev Blogs My eyes glaze over at all of this, but even here on OSNews, theres going to be countless people working with .NET at their jobs.
- GNOME 51 released
GNOME 51 has been released, with a whole slew of new features and improvements. Most notably, at least in my experience, will be the work done on GNOMEs graphics stack, which seems to stutter and jitter more than KDEs on the same hardware at least in my experience. In particular, GNOMEs compositor, Mutter, has improved frame scheduling for smoother animations, even under load. This hopefully addresses the stutters I generally experience when using GNOME. Theyve also done a lot of work on the Settings, Maps, Calendar, Web, and other applications. Of note to many will be the array of improvements to GNOMEs file manager, including better performance, although I doubt it will convince those of us who arent particular fans of Nautilus in general. Theyve also improved the remote desktop experience by, among other things, adding support for smart cards and improving support for Kerberos. GNOME 51 will make its way to your distribution of choice soon enough.

- systemd 262 Released with Static PID 1, Intel TDX, TPM Improvements, and New Container Features
by George Whittaker The systemd project has officially released systemd 262, delivering another substantial update to the system and service manager used by most major Linux distributions. The final release was tagged on September 22, 2026, following three release candidates earlier in the month.
Systemd 262 introduces improvements across service management, containers, virtualization, encrypted storage, TPM security, networking, journal recovery, system updates, and unattended installations. Among the most interesting additions are the ability to build systemd as a single statically linked PID 1 binary, Intel TDX support in systemd-vmspawn, Live Update Orchestrator integration, improved TPM-backed encryption, and new fallback unit files embedded directly into the systemd manager.
The release also contains a rather unusual development safeguard: an AI/LLM canary intended to help identify code contributions generated by AI that haven't been properly reviewed by a human before submission. systemd 262 Is Officially Available The final systemd 262 source was tagged by systemd developer Luca Boccassi on September 22.
The upstream tag identifies commit 8cc40e0c5e9234bf45084751ac53b1fbfe70b492 as systemd v262, following release candidates published throughout September.
The release has already begun reaching Linux distribution development repositories.
Debian accepted systemd 262-1 into Debian Unstable on September 22, while Fedora has prepared systemd 262 packages for Fedora 45.
As usual, the speed at which systemd 262 reaches ordinary users will depend on each distribution's update policy. systemd Can Now Become a Single Static PID 1 Binary One of the most interesting changes in systemd 262 is support for building systemd as a single statically linked PID 1 and executor binary.
The feature is primarily intended for extremely small container environments.
Normally, systemd depends on a collection of dynamically linked libraries and supporting components. That architecture makes sense for a complete Linux distribution, but containers sometimes need a much smaller runtime environment.
The new static configuration makes it possible to create a more self-contained systemd executable suitable for minimal container images.
These builds avoid dynamically loading optional libraries and use simplified mechanisms for resolving users and groups rather than relying on the complete Name Service Switch infrastructure.
This doesn't mean normal Linux distributions will suddenly replace their standard systemd packages with a giant static executable. The capability is specifically useful for specialized container and minimal-system deployments. Go to Full Article
- Ubuntu Container Escape Vulnerability Gets Public Exploit Before Kernel Patch Arrives
by George Whittaker Ubuntu administrators running containerized workloads have a new Linux kernel security problem to watch closely. Public exploit code is now available for CVE-2026-80521, a Linux kernel use-after-free vulnerability that can allow an unprivileged process inside a container to escape and obtain root privileges on the underlying host.
Security firm DepthFirst published its research and exploit on September 22, 2026, demonstrating the attack against Ubuntu 26.04 LTS. The underlying Linux kernel vulnerability had already been fixed upstream on August 6, but as of September 23, Ubuntu's security tracker still lists the main kernel package in Ubuntu 26.04 LTS as "Vulnerable, work in progress," while Ubuntu 24.04 LTS is also listed as vulnerable.
The situation is particularly important for Docker, Kubernetes, cloud infrastructure, and other environments that run potentially untrusted workloads because the vulnerable kernel functionality can be reached through ordinary operations available inside standard containers.
There is currently no confirmed evidence that CVE-2026-80521 is being actively exploited in real-world attacks, and the vulnerability isn't listed in CISA's Known Exploited Vulnerabilities catalog. The availability of working public exploit code nevertheless makes the patch gap considerably more important. CVE-2026-80521 Is a Linux Kernel Vulnerability Although Ubuntu is receiving much of the attention because the newly published exploit specifically targets it, CVE-2026-80521 is fundamentally a Linux kernel vulnerability.
The problem exists in the kernel's AF_UNIX socket subsystem, specifically within its garbage collection mechanism.
AF_UNIX sockets, commonly called Unix-domain sockets, provide local inter-process communication between applications running on the same system.
Unlike conventional network sockets, they don't need to communicate across a network. They are widely used by Linux applications and services for fast communication between local processes.
They also support passing file descriptors between processes through SCM_RIGHTS messages, and it is the kernel's management of these references that creates the conditions for CVE-2026-80521. A Race Condition Leads to Use-After-Free At the technical level, CVE-2026-80521 involves a race condition inside the AF_UNIX garbage collector.
The kernel needs to track references between Unix sockets when file descriptors are passed between processes. Circular references can develop, where one socket effectively references another while that socket references something else in the same group.
Linux represents these relationships internally and periodically determines which references can safely be removed. Go to Full Article
- Fedora Linux 45 Beta Released with Python 3.15, GCC 16.2, and Major Security Changes
by George Whittaker The Fedora Project has officially released Fedora Linux 45 Beta, giving users an early look at the technologies expected to form the foundation of the final Fedora 45 release. The beta became available on September 15, 2026, after Fedora's Quality team approved Release Candidate 1.3 for publication.
Fedora 45 Beta brings significant changes throughout the operating system, including Python 3.15, GCC 16.2, glibc 2.44, GNU Binutils 2.47, Go 1.27, LLVM 23, Podman 6, stricter RPM signature verification, improved DNF5 protections, a new userspace virtual console, standardized desktop secret storage, and substantial installer improvements.
The release is available across Fedora Workstation, KDE Plasma Desktop, Server, Cloud, IoT, Atomic Desktops, Spins, and Labs, although a few prerelease images are excluded. Fedora 45 Beta Is Now Available Fedora Linux 45 Beta represents the final major public testing milestone before Fedora 45 reaches stable status.
Fedora describes its beta releases as code-complete previews that closely represent what users should expect from the final version. Development isn't finished, however, and bugs or incomplete migrations can still be discovered during real-world testing.
Fedora 45 Beta is currently available in several major editions: Fedora Workstation 45 Beta Fedora KDE Plasma Desktop 45 Beta Fedora Server 45 Beta Fedora Cloud 45 Beta Fedora IoT 45 Beta Fedora Atomic Desktops Fedora Spins Fedora Labs Existing Fedora installations can also be upgraded to the beta using Fedora's DNF system-upgrade process.
Fedora's official Workstation download page confirms Beta 1.3 images for both x86_64 and AArch64 systems. A New Virtual Console with kmscon One of Fedora 45's more unusual system-level changes is the replacement of the traditional in-kernel console with kmscon.
Fedora describes kmscon as a modern userspace virtual terminal implementation that provides smoother rendering, better internationalization and font handling, improved visual integration, and security improvements compared with the older console infrastructure.
This affects the virtual terminals users encounter outside their normal graphical desktop session.
Most desktop users spend relatively little time interacting directly with these consoles, but they remain important for troubleshooting, system administration, servers, recovery operations, and systems running without a graphical environment.
Moving that functionality into userspace also gives Fedora more flexibility for future development instead of relying entirely on the legacy kernel console implementation. Go to Full Article
- Thunderbird 156 Released with OAuth Improvements, OpenPGP Updates, and Major Linux Fixes
by George Whittaker The Thunderbird team has officially released Thunderbird 156, bringing another round of new features, security improvements, authentication enhancements, and reliability fixes to the popular open-source email client. Released on September 15, 2026, the update is available for Linux alongside Windows and macOS.
Thunderbird 156 is not a dramatic redesign of the desktop mail client. Instead, it concentrates on improving areas that matter to everyday users and system administrators, including OAuth authentication, OpenPGP, POP3, IMAP, Exchange Web Services, SMTP, attachments, calendars, enterprise policies, and security.
For Linux users in particular, the release delivers several fixes affecting common mail protocols and account configurations while retaining support for Linux environments using GTK+ 3.14 or newer. Thunderbird 156 Arrives on Linux Thunderbird 156 follows version 154, which arrived in August with features including optional system tray operation and Microsoft Graph support for Microsoft 365.
Version 156 continues the project's monthly release cycle with a more targeted collection of authentication, security, compatibility, and reliability improvements.
According to Thunderbird's official release notes, version 156 requires: Linux: GTK+ 3.14 or newer Windows: Windows 10 or newer macOS: macOS 10.15 or newer Thunderbird 156 was officially released on September 15.
Linux distribution availability will vary because distributions can package Thunderbird according to their own schedules. Users receiving Thunderbird through another packaging channel may therefore see version 156 at a different time. Custom OAuth Support Expands One of the most significant areas of development in Thunderbird 156 is OAuth authentication.
Thunderbird now supports custom OAuth configurations containing an issuer ID and client secret for IMAP and POP3 accounts. Custom OAuth support has also been extended specifically to POP3.
OAuth has become increasingly important as email providers move away from conventional username-and-password authentication toward token-based authentication.
For Thunderbird, broader custom OAuth support means users and organizations have greater flexibility when connecting the client to mail services that don't fit Thunderbird's predefined provider configurations.
This can be particularly useful in enterprise environments, self-hosted infrastructure, and organizations operating their own identity systems. Exchange Custom OAuth Setup Fixed Exchange users receive an important related correction. Go to Full Article
- KDE Plasma 6.7.5 Released with Discover, KWin, Wayland, and HDR Fixes
by George Whittaker The KDE Project has officially released KDE Plasma 6.7.5, delivering another round of bug fixes and stability improvements for the Plasma 6.7 desktop series. Released on September 8, 2026, the update contains roughly a month of fixes and updated translations contributed since Plasma 6.7.4 arrived in early August.
Unlike a major Plasma release, version 6.7.5 doesn't introduce a large collection of new desktop features. Instead, KDE has focused on fixing problems affecting Discover, KWin, Wayland, networking, System Monitor, Plasma Desktop, RPM-OSTree systems, Snap updates, HDR rendering, and several other components.
For users already running Plasma 6.7, this makes version 6.7.5 primarily a maintenance upgrade intended to make the desktop more dependable ahead of the next major Plasma series. KDE Plasma 6.7.5 Arrives as the September Bugfix Release KDE describes Plasma 6.7.5 as its September bugfix release for the Plasma 6 desktop.
The broader Plasma 6.7 series originally arrived in June 2026, followed by a succession of maintenance releases: Plasma 6.7.1 on June 23 Plasma 6.7.2 on June 30 Plasma 6.7.3 on July 14 Plasma 6.7.4 on August 4 Plasma 6.7.5 on September 8 KDE's official download infrastructure confirms that the Plasma 6.7.5 source packages became available on September 8.
This slower maintenance cadence later in a Plasma series is normal. Once the most urgent post-release problems have been addressed, KDE generally shifts more development attention toward the next feature release while continuing to provide important fixes for the current branch. Discover Receives Several Important Fixes KDE's Discover software center receives some of the most noticeable improvements in Plasma 6.7.5.
One particularly annoying problem could cause Discover to become stuck while checking for updates when its Snap backend was installed but no Snap applications actually had updates available.
That problem has now been corrected.
Discover also behaves more reliably when fwupd, the Linux firmware update service, is unavailable. Previously, a broken or intentionally masked fwupd service could interfere with Discover's normal operation. Plasma 6.7.5 allows the rest of the application to continue functioning correctly in that situation.
This is useful for systems where firmware updating isn't supported, where administrators intentionally disable the service, or where fwupd encounters a configuration problem. Firmware Updates No Longer Incorrectly Require Reboots Another Discover correction addresses a regression involving firmware updates. Go to Full Article
- Slackware 16 Alpha 1 Released with Linux 6.18 LTS, GCC 16.2, and Plasma 6
by George Whittaker One of Linux's oldest surviving distributions is moving closer to its next major release. Slackware 16 Alpha 1 became available on September 5, 2026, marking the first formal alpha milestone on the road toward Slackware Linux 16. The release follows a major rebuild of Slackware-current using a substantially newer GNU toolchain and brings together several upgrades that have accumulated since Slackware 15.0 arrived more than four years ago.
The alpha combines Linux 6.18 LTS, GCC 16.2.0, glibc 2.44, GNU Binutils 2.47, KDE Plasma 6, and numerous updated user-space packages while retaining much of the deliberately traditional architecture that has distinguished Slackware for decades.
For longtime Slackware users, Alpha 1 is particularly significant because it provides the clearest indication yet that the lengthy Slackware 16 development cycle is moving toward an eventual stable release. Slackware 16 Finally Reaches Alpha Slackware doesn't operate according to the predictable six-month or annual release schedules used by many other Linux distributions.
Instead, development takes place continuously through the Slackware-current branch. Patrick Volkerding and other contributors update that development tree until it reaches a state considered suitable for a stable release.
The previous major version, Slackware 15.0, was released in February 2022. More than four and a half years later, Slackware-current has now officially reached the first alpha milestone for version 16.
Volkerding marked the milestone following a complete rebuild of the distribution with its newly upgraded compiler, C library, and binary utilities.
The short changelog announcement even suggested there might finally be "a light at the end of the tunnel," a promising indication for Slackware users waiting for version 16. The Entire Distribution Was Rebuilt One of the most consequential changes behind Alpha 1 is a complete package rebuild.
Slackware's development toolchain has moved to: GCC 16.2.0 glibc 2.44 GNU Binutils 2.47 After introducing those components, Slackware rebuilt the distribution's packages against the updated environment.
A full rebuild is much more significant than simply replacing three packages.
GCC is responsible for compiling much of the software distributed with Slackware, glibc provides fundamental C library functionality used throughout Linux user space, and Binutils supplies essential development utilities including the GNU assembler and linker.
Rebuilding the distribution against these versions gives Slackware 16 a considerably newer foundation than its predecessor. Go to Full Article
- Top AEO Tools for Linux and Developer Documentation Teams
by Malana VanTyler These platforms help teams monitor how technical content appears in AI-generated answers, from brand mentions and citations to accuracy and referral traffic.
Search is splitting into two experiences: one built around ranked pages and another around generated answers. As AI platforms summarize Linux tutorials, open-source project documentation, API references and technical guidance, teams need ways to measure whether their content is mentioned, cited and accurately represented.
An Go to Full Article
- The New Way Security Teams Evaluate Pentesting Vendors
by George Whittaker Why security buyers are rethinking what matters most.
Security teams typically don’t struggle to find vulnerabilities as much as they have in the past. The harder part usually begins after the report arrives, once dozens of findings land in front of engineering teams already juggling patch schedules, production deadlines, and internal disagreements about urgency. Platforms like Go to Full Article
- New Linux “Steal Governor” Targets CPU Contention in Overcommitted Virtual Machines
by George Whittaker Linux kernel developers are considering a new “steal governor” designed to improve performance when multiple virtual machines compete for limited physical CPU resources. The proposal uses the amount of CPU steal time observed inside a guest to dynamically reduce or expand the number of virtual CPUs on which that VM prefers to schedule work.
The feature is primarily aimed at heavily virtualized servers where administrators deliberately assign more virtual CPUs than the host can physically execute at once. Under heavy load, that overcommitment can lead to frequent vCPU preemption, lock-holder delays, cache disruption, and ultimately lower overall throughput.
The latest v11 patch series was posted on August 25, 2026, and its developer has proposed consideration during the Linux 7.3 development cycle, potentially targeting Linux 7.4 for inclusion. This means the feature is still under review and is not part of a stable Linux kernel yet. What Is CPU Steal Time? CPU steal time is a concept specific to virtualization.
Imagine a virtual machine has eight vCPUs. From inside that VM, the operating system behaves as though those eight CPUs are available. But those virtual CPUs ultimately need to run on the host's physical processors.
If several VMs are competing for the same physical CPU resources, the hypervisor may temporarily prevent one VM's vCPU from running so another VM can use the processor.
The time during which the guest wanted to execute but couldn't because the hypervisor was using the underlying CPU elsewhere is known as steal time.
High steal time is therefore a useful indication that the physical host is experiencing CPU contention. The “Noisy Neighbor” Problem The steal governor is designed primarily to address what virtualization engineers commonly call the noisy neighbor problem.
Consider a server hosting several VMs: VM A has 32 vCPUs. VM B has 32 vCPUs. VM C has 32 vCPUs. The physical server has only 64 CPU threads available to those workloads. That configuration can work perfectly well when the VMs aren't simultaneously busy.
If all three suddenly become heavily loaded, however, they may collectively request more CPU time than the physical machine can provide.
The hypervisor then has to constantly switch between vCPUs.
Those interruptions can become particularly expensive if a vCPU is preempted while holding a lock or executing another latency-sensitive section of code. Other threads may then wait for a vCPU that isn't currently being allowed to run.
The result can be counterintuitive: giving the VMs more virtual CPUs can sometimes make the combined workloads slower. Go to Full Article
|