Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All/All+Images) (Single Column)

LWN.net

  • [$] Analyzing Rust programs with Charon
    Nadrieril is a long-time Rust contributor, and the maintainer of the rustcpattern-matching infrastructure. During his involvement with Rust, he hasnoticed a problem with the usability of the language: it is difficult toautomatically extract information from a Rust crate for use with other tooling.The Charon project aims to fix that by providing a stable API for accessinginternal information from the Rust compiler.



  • A new Raspberry Pi Desktop release is finally available for x86-64
    Simon Long has announceda long-awaited release of Raspberry Pi OS, based on Debian 13 ("trixie"),for x86-64 systems.

    We managed to find the time to update the Desktop for the Buster and Bullseyereleases of Debian, but then we all just got too busy with other things, and,while we left the Bullseye version on the website for anyone who wanted it, wesimply didn't have time to release any newer versions. But people kept on askingfor it – we get two or three emails every week asking when the PC Desktop willbe updated, and we haven't had an answer, because we honestly didn't know whenwe might get a chance to do it. We've continually tried to allocate time to beable to work on this, but it hasn't been easy. [...]

    Earlier this year, we (or rather Serge) finally got the latest version of theDesktop running on top of a Debian Trixie image. It's now based on 64-bit Debian(the amd64 architecture) rather than the older 32-bit version, as Debian itselfhas stopped supporting 32-bit for PC architectures. This shouldn't be a majorproblem – most PCs made in the last 15 years or so will quite happily run the64-bit version of Debian, as will most Intel-based Macs. (Debian support forApple Silicon is still experimental, so unfortunately those of you with thelatest and greatest shiny fruit products will not be able to run this.)



  • Security updates for Wednesday
    Security updates have been issued by AlmaLinux (bind, dovecot, freerdp, kernel, mariadb-connector-c, mod_auth_openidc, nodejs22, nodejs:22, sudo, and vim), Debian (node-shell-quote, puma, rails, ruby-jwt, and suricata-update), Fedora (chromium, cockpit, flocq, freerdp, gappalib-coq, golang-x-mod, httpd, janus, libical, musescore, python3-docs, python3.14, python3.15, rocq, rocq-stdlib, tesseract, why3, and zenon), Mageia (srt and tor), Oracle (freerdp, kernel, libpcap, mariadb-connector-c, nodejs22, sudo, and vim), Red Hat (expat and grafana), Slackware (openssh), SUSE (chromium, docker-stable, firefox, jupyter-jupyterlab, libtcnative-1-0, tomcat, tomcat10, libtcnative-1-0, tomcat11, openexr, python310, python313-azure-storage-queue, python313-langchain-anthropic, python313-sglang, python313-Werkzeug, and valkey), and Ubuntu (fluidsynth, freerdp3, freetype, golang-1.18, golang-1.21, golang-1.24, gst-plugins-good1.0, libsoup2.4, libsoup3, libwebsockets, linux, linux-aws, linux-gcp, linux-gke, linux-ibm, linux-oracle, linux-realtime, linux-azure, linux-azure-fde, linux-nvidia-tegra, linux-oem-7.0, redis, sg3-utils, tesseract, and u-boot).


  • [$] Python's two modules for random numbers
    Python's randomand secretsmodules both include utilities for obtaining random values, but only one of them is suitable for generating passwords and security tokens.For much of Python's history, random was used for passwords and tokens anyway, despite documentation that called it unsuitable for cryptography.In 2015, Python's core team debated whether to fix that misuse by making random secure by default.Instead, in 2016, Python 3.6 added a second module: secrets. Therandom module is still misused at times, so it is instructiveto look into how the random-number modules should be used.


  • [$] Last rites for Gentoo's Chromium package
    Chromium, the open-sourceupstream project for Google's Chrome web browser, is the browser of choice formany Linux users. It has also gained a reputation as being difficult for Linux distributions topackage and build: Chromium has a complex build system, the project bundlesmany of its dependencies, and it has frequent releases. All of that, plus usercomplaints, has led the maintainers of the Gentoo Chromiumpackage to give up on trying to maintain the package.


  • OpenSSH 10.6 released
    Version 10.6 of OpenSSHhas been released. The announcement notes that the OpenSSH team has beenreceiving a large number of AI-assisted security bug reports. "We very muchwelcome these reports, especially when combined with human triage, analysis,test-cases and particularly when accompanied by proposed fixes". As aresult, the project expects to be making more frequent releases to get updatesto users more quickly rather than batching the bug fixes until the next plannedrelease.

    Notable changes in this release include enabling the hybrid post-quantumssh-mldsa44-ed25519 signature algorithm, addition of a -p option for sftp's lmkdir/mkdir commands, as wellas disabling the LZ77 dictionary coder in ssh and sshd to mitigate side-channelleaks (which will result in reduced effectiveness of the Compressionoption). The scp -R option, whichallows copies between two remote hosts, is being deprecated due to securityrisks; the option will be ignored in the future. See the announcement for fulldetails of all changes and bug fixes.



  • Security updates for Tuesday
    Security updates have been issued by AlmaLinux (gd, gimp, kernel, kernel-rt, libpcap, librabbitmq, mariadb-connector-c, osbuild-composer, ruby:2.5, and sudo), Debian (libmodule-cpants-analyse-perl, libpng1.6, libreoffice, roundcube, ruby-oauth2, and sabnzbdplus), Fedora (0install, alt-ergo, apron, brltty, chromium, coccinelle, cri-o1.36, emacs-common-tuareg, flocq, frama-c, freetennis, gappalib-coq, guestfs-tools, haxe, hevea, hivex, kernel, lem, libguestfs, libnbd, nbdkit, not-ocamlfind, ocaml, ocaml-afl-persistent, ocaml-alcotest, ocaml-astring, ocaml-atd, ocaml-augeas, ocaml-b0, ocaml-base, ocaml-base64, ocaml-benchmark, ocaml-bin-prot, ocaml-biniou, ocaml-bisect-ppx, ocaml-bos, ocaml-cairo, ocaml-calendar, ocaml-camlbz2, ocaml-camlidl, ocaml-camlimages, ocaml-camlp-streams, ocaml-camlp5, ocaml-camlp5-buildscripts, ocaml-camlpdf, ocaml-camomile, ocaml-capitalization, ocaml-cinaps, ocaml-cmdliner, ocaml-compiler-libs-janestreet, ocaml-cpdf, ocaml-cppo, ocaml-crowbar, ocaml-cryptokit, ocaml-csexp, ocaml-csv, ocaml-ctypes, ocaml-cudf, ocaml-curl, ocaml-curses, ocaml-dbus, ocaml-domain-name, ocaml-dose3, ocaml-dune, ocaml-easy-format, ocaml-expat, ocaml-extlib, ocaml-facile, ocaml-fieldslib, ocaml-fileutils, ocaml-findlib, ocaml-fmt, ocaml-fpath, ocaml-gen, ocaml-gettext, ocaml-graphics, ocaml-gsl, ocaml-integers, ocaml-intrinsics-kernel, ocaml-jane-street-headers, ocaml-jsonm, ocaml-jst-config, ocaml-lablgl, ocaml-lablgtk, ocaml-lablgtk3, ocaml-labltk, ocaml-lacaml, ocaml-lambda-term, ocaml-libvirt, ocaml-linenoise, ocaml-logs, ocaml-luv, ocaml-lwt, ocaml-mccs, ocaml-mdx, ocaml-menhir, ocaml-merlin, ocaml-mew, ocaml-mew-vi, ocaml-mlgmpidl, ocaml-mlmpfr, ocaml-monolith, ocaml-mtime, ocaml-mysql, ocaml-num, ocaml-obuild, ocaml-ocamlbuild, ocaml-ocamlgraph, ocaml-ocamlnet, ocaml-ocp-indent, ocaml-ocplib-endian, ocaml-ocplib-simplex, ocaml-omake, ocaml-omd, ocaml-opam-0install-cudf, ocaml-opam-file-format, ocaml-ounit, ocaml-parmap, ocaml-parsexp, ocaml-patch, ocaml-pcre2, ocaml-perl4caml, ocaml-postgresql, ocaml-pp, ocaml-pprint, ocaml-ppx-assert, ocaml-ppx-base, ocaml-ppx-bench, ocaml-ppx-bin-prot, ocaml-ppx-cold, ocaml-ppx-compare, ocaml-ppx-custom-printf, ocaml-ppx-derivers, ocaml-ppx-deriving, ocaml-ppx-deriving-yaml, ocaml-ppx-deriving-yojson, ocaml-ppx-enumerate, ocaml-ppx-expect, ocaml-ppx-fields-conv, ocaml-ppx-globalize, ocaml-ppx-hash, ocaml-ppx-here, ocaml-ppx-inline-test, ocaml-ppx-let, ocaml-ppx-optcomp, ocaml-ppx-sexp-conv, ocaml-ppx-stable-witness, ocaml-ppx-variants-conv, ocaml-ppxlib, ocaml-ppxlib-jane, ocaml-psmt2-frontend, ocaml-ptmap, ocaml-pyml, ocaml-qcheck, ocaml-qtest, ocaml-re, ocaml-react, ocaml-res, ocaml-result, ocaml-rresult, ocaml-SDL, ocaml-sedlex, ocaml-sexplib, ocaml-sexplib0, ocaml-sha, ocaml-spdx-licenses, ocaml-sqlite, ocaml-ssl, ocaml-stdcompat, ocaml-stdio, ocaml-stdlib-random, ocaml-store, ocaml-swhid-core, ocaml-testo, ocaml-time-now, ocaml-topkg, ocaml-trie, ocaml-unionfind, ocaml-uucd, ocaml-uucp, ocaml-uunf, ocaml-uuseg, ocaml-uutf, ocaml-variantslib, ocaml-version, ocaml-xml-light, ocaml-xmlm, ocaml-xmlrpc-light, ocaml-yaml, ocaml-yamlx, ocaml-yojson, ocaml-zarith, ocaml-zed, ocaml-zip, ocaml-zmq, ocamlify, ocamlmod, opam, perl-DBI, planets, plplot, prooftree, python3.12, rocq, rocq-stdlib, supermin, unison, utop, virt-top, virt-v2v, why3, xen, z3, and zenon), Oracle (bind, expat, gawk, gdb, ghostscript, gimp, gvfs, kernel, libpcap, libvirt, mod_auth_openidc, openssh, rsync, thunderbird, and webkit2gtk3), Red Hat (vim), Slackware (cups), SUSE (apache-sshd, binutils, cups, docker-stable, java-11-openjdk, libraw-devel, libX11, pcre2, perl-DBI, python-msgpack, python312, python313-tokenizers, rpcbind, rpm, rubygem-rails-html-sanitizer, squid, sssd, terraform-provider-susepubliccloud, valkey, and wpa_supplicant), and Ubuntu (aodh, watcher, edk2, libreoffice, libxmltok, linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-azure, linux-azure-5.15, linux-azure-fde-5.15, linux-azure-fips, linux-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iot-realtime, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle, linux-realtime, linux-xilinx-zynqmp, linux-azure-5.4, linux-azure-fde, linux-gcp, linux-gcp-fips, linux-gcp-5.15, linux-oracle-5.15, linux-raspi, rabbitmq-server, and unbound).



  • [$] An update on the Sashiko patch-review system
    Patch review has long been one of the limiting constraints for the kernelproject (and most others); there just aren't enough people to properlyreview all of the code that is submitted for inclusion. The Sashikosystem, which uses a large language model (LLM) to generate reviewsautomatically, offers the prospect of some relief, and has already becomean important part of the kernel's development process. At the 2026 editionof Kernel Recipes, RomanGushchin, the maintainer of Sashiko, provided an overview of howthe system works and what is being done to improve it.



LXer Linux News


  • Canonical Reaffirms Plans For Ubuntu 27.04 To Use ntpd-rs By Default
    Back in March Canonical announced switching to ntpd-rs was its next target as part of transitioning more Ubuntu Linux system components to Rust-based implementations. This time synchronization package is available for testing in the upcoming Ubuntu 26.10 release while it aims to be the default for Ubuntu 27.04...




  • New Patches For Linux's Zswap Show Major Improvements
    Amid multiple ongoing innovations being pursued in the Linux memory management space amid sky high RAM prices, a new patch series posted on Monday aim to enhance the Zswap performance for this compressed RAM cache for swap pages...







Linux Insider"LinuxInsider"












Slashdot

  • Xbox Secures Exclusive GTA 6 Streaming Rights
    Microsoft has reportedly secured exclusive cloud-streaming rights for Grand Theft Auto VI, meaning Xbox Cloud Gaming will be the only service able to stream the game at launch. "Rockstar Games still hasn't announced a PC version of Grand Theft Auto VI, so this deal will allow Xbox to market its Xbox Cloud Gaming service to PC players who would otherwise need an Xbox Series X / S or PS5 console," reports The Verge. From the report: News of the streaming rights comes around a month after Microsoft announced some major changes to Xbox Cloud Gaming. From November, the same month Grand Theft Auto VI releases, Microsoft is limiting streaming hours to just 15 hours for Xbox Game Pass Ultimate subscribers, 10 hours for Premium subscribers, and just five hours for Game Pass Essential.Microsoft is also opening up access to Xbox Cloud Gaming with a pay-as-you-go option next month, rather than being limited to Game Pass subscriptions. The pay-as-you-go option is perfectly timed for Grand Theft Auto VI, allowing those who don't own an Xbox, or who primarily play from a phone, to stream the game by paying for a bundle of hours.


    Read more of this story at Slashdot.


  • Francis Halzen Wins Nobel Physics Prize For Antarctic 'Ghost Particle' Hunt
    University of Wisconsin-Madison physicist Francis Halzen has been awarded the 2026 Nobel Prize in Physics for his contributions to understanding astrophysical neutrinos. Halzen led the development of the IceCube Neutrino Observatory beneath the Antarctic ice, which has helped trace high-energy neutrinos back to cosmic sources such as supermassive black holes and opened a new era of "multi-messenger" astronomy. Longtime Slashdot reader schwit1 shares a report from UW-Madison: Embedded in a cubic kilometer of Antarctic ice, IceCube uses thousands of light sensors to survey the universe for neutrinos, nearly massless particles that rarely interact with other matter. Neutrinos provide information about the workings of black holes, galaxies and other objects in the cosmos. "IceCube is like no other telescope in the world," says UW-Madison interim Chancellor Eric M. Wilcots. "And there is no other scientist quite like Francis Halzen, whose idea to create a neutrino detector under almost a mile of ice has led to a remarkable multinational and multi-institutional scientific collaboration and a fundamental shift in how we think about the universe." Unlike the neutral neutrino, cosmic rays are charged particles whose paths cannot be traced directly back to their sources. But the powerful cosmic accelerators that produce them, like supermassive black holes, will also produce neutrinos. These so-called "ghost particles" travel nearly undisturbed from their accelerators, giving scientists an almost direct pointer to their source. Along with observations by other telescopes, the neutrino first detected by IceCube provided the first-ever evidence of a source of high-energy cosmic rays, whose origins have been notoriously difficult to pinpoint since their discovery over 100 years ago by 1936 physics Nobel laureate Victor Hess.


    Read more of this story at Slashdot.


  • Google Enters Massive 3.6-GW Power Deal With Constellation Energy
    An anonymous reader quotes a report from Reuters: Google has contracted for 3,590 megawatts of power from Constellation Energy on the largest US power grid, with new nuclear energy accounting for about a quarter of that supply, the companies said on Tuesday. Constellation will make more than $4.3 billion of new investments in its fleet as part of the agreement, which involves adding capacity at several of the power company's nuclear reactors in the Midwest and Mid-Atlantic regions, the companies said. [...] Over the last two years, Constellation unveiled an agreement to restart its Three Mile Island reactor in Pennsylvania to serve Microsoft data centers, while Google contracted to restart NextEra Energy's nuclear power plant in Iowa. In the latest arrangement, Google entered into a 20-year power purchase agreement for 890 megawatts of electricity from multiple Constellation-owned nuclear power plants, which would be upgraded to produce more electricity from existing reactors. Electricity from the first of the upgraded plants is expected to be delivered in 2028, the companies said. Google also entered into a 15-year supply agreement for an additional 2,700 megawatts of power from Constellation in the PJM power grid. That power is not tied to a specific generation source and serves as long-term revenue certainty for Constellation's operating plants, Google said. Maryland-based Constellation is the largest US nuclear power plant operator and owns a major fleet of natural-gas-fired power plants as well as geothermal energy following its acquisition of electricity producer Calpine Corp earlier this year. [...] The 11 nuclear units expected to be upgraded as part of the arrangement with Google are in Illinois, Pennsylvania, and New Jersey, within the footprint of the largest US electric grid -- PJM Interconnection. Joe Dominguez, chairman, president and CEO of Constellation, said the arrangement with Google is a "model for how technology companies and the energy industry can work together to responsibly develop the digital economy and invest in our nation's energy infrastructure in a way that delivers grid-wide benefits for all, funded by private entities."


    Read more of this story at Slashdot.


  • South Korea Says AI Agents May Have Been Used to Hack the Country's Banks
    South Korean President Lee Jae Myung says there are signs AI models may have been used in recent cyberattacks against several major banks. "In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety," Lee said during a cabinet meeting. "Please establish the circumstances swiftly and clearly, and concentrate personnel and resources on minimizing the damage." Reuters reports: South Korea's police have launched a full-scale investigation into the hacking attacks against commercial banks that led to a breach of customers' personal information, the Yonhap news agency reported on Tuesday. Shinhan Bank, KB Kookmin Bank and others had reported cyberattacks, the Financial Services Commission (FSC) said on Friday, while Yonhap reported that Hana Bank and Woori Bank also suffered breaches. Authorities have not yet disclosed details on what kind of AI tools were used in the hacking incidents or the full scale of the breaches. On Sunday, FSC Chairman Lee Eog-weon convened an emergency meeting with financial industry associations, regulators and executives from affected institutions, warning that the sector must respond with the highest level of vigilance. Financial watchdog the Financial Supervisory Service (FSS) and the Financial Security Institute shared data about 28 unique IP addresses and some country information linked to the recent hacking attempts with the financial sector, the FSS said on Tuesday.


    Read more of this story at Slashdot.


  • Canadian Analysis: Permanent Daylight Saving Harms Sleep and Mental Health
    "With the push to eliminate the twice yearly clock change, Permanent Daylight Savings Time has emerged as the favorite for most states and provinces," writes longtime Slashdot reader kbahey, sharing the findings from a recent analysis published in the Canadian Medical Association Journal. Sci.News reports: "Ending the clock change solves one problem, but it creates another decision: which time should we live on year-round?" said University of British Columbia's Professor Raymond Lam, lead author of the study. "The health evidence points to standard time, largely because morning light matters for our body clocks, sleep, and mood." Professor Lam and colleagues examined the health consequences of the two possible permanent systems rather than the broader question of whether seasonal clock changes should be abolished. They concluded that the accumulated evidence favors permanent standard time, which keeps the clock more closely aligned with human circadian biology. This distinction, according to the team, becomes particularly important during winter. Permanent daylight saving time would push sunrise an hour later. In cities such as Toronto, for example, the latest winter sunrise would occur at 8:51 a.m., compared with 7:51 a.m. under permanent standard time. In Calgary, the corresponding times would be 9:40 a.m. and 8:40 a.m. The extra hour of morning darkness could leave people traveling to work or school before sunrise, while shifting more daylight into the evening. The change could have consequences for sleep, mood, learning and productivity, particularly among people who already have difficulty sleeping or who must follow early schedules. The reason is rooted in the body's internal clock. "Our biological clocks need morning light to stay synchronized with the 24-hour day," said Simon Fraser University's Professor Ralph Mistlberger, co-author of the study. "Permanent daylight saving time moves that light an hour later just when winter mornings are already darkest." The analysis also highlights concerns about seasonal depression. [...] By delaying natural morning light, permanent daylight saving time would act in the opposite direction, potentially weakening an important circadian signal.


    Read more of this story at Slashdot.


  • HubSpot Cuts 660 Jobs In AI Restructuring
    HubSpot is cutting about 7% of its workforce, or roughly 660 employees, as it restructures into what CEO Yamini Rangan described as a "flatter organization" with fewer management layers. Rangan said the layoffs were "not driven by AI-related efficiencies," though AI remains central to HubSpot's strategy as the company adjusts its organization around AI-driven customer outcomes. Fast Company reports: The layoffs come as investors have spent months questioning whether AI will reduce the need for businesses to pay for software like HubSpot's, a fear dubbed the "SaaSpocalypse." HubSpot's platform helps companies manage their customers, sales, and marketing. The company was removed from the FTSE All-World Index (USD) last month after a decline in its stock price, a report from Simply Wall St noted. The stock is down more than 43% this year as of this writing. Yamini Rangan, CEO of HubSpot, explicitly told employees in a memo that the layoffs were "not driven by AI-related efficiencies." Rather, the aim was to focus on "aligning our organization with our strategy and how we need to operate going forward," Rangan wrote. She added that the goal is to "build a flatter organization with fewer layers" by cutting back on management. Still, artificial intelligence has been central to the company's concerns. In August, Rangan blamed AI for why the company "got off to a slow start" in April as HubSpot was trying to adjust its product and pricing. "We're in the middle of a real transition to AI, and we are making deliberate choices to lead in it," she said on an earnings call. The restructuring is estimated to cost between $65 and $75 million, mostly in severance packages. The company said that laid-off employees will receive 20 weeks of base pay, one week per year of service (capped at 30 weeks), five months of COBRA and Modern Health healthcare benefits, and they will be allowed to keep their laptops.


    Read more of this story at Slashdot.


  • Alexa Can't Control the AUX Input On Amazon Echo Speakers Anymore
    Amazon has removed Alexa voice control for the 3.5mm aux input on several older Echo speakers, meaning users can no longer ask Alexa to play or pause audio coming through the wired connection. It's unclear why the feature was removed. The Verge reports: Ars Technica points to this Reddit poster claiming they received a message from Amazon and says an unnamed spokesperson confirmed the change. When contacted by The Verge, Amazon did not provide an on-the-record statement. The message does not include any explanation for why the feature was removed. It also doesn't mention any changes to audio output functionality like connecting an external speaker to an Echo Dot, and it appears that control of the port from within the app's settings menu still works.


    Read more of this story at Slashdot.


  • Asos Confirms Hackers Sent 'Unauthorized' Notification to App Users
    ASOS says hackers gained unauthorized access to third-party platforms it uses and sent an "ASOS HACKED" push notification directly to customers, apparently as part of an extortion attempt. The clothing and beauty store says some basic personal information may have been accessed but does not believe payment-card data or passwords were affected. The BBC reports: In an email to customers on Tuesday night, the company apologized and urged customers not to engage with the notification. And it said the website and app are "operating as usual" promising customers they can "shop with confidence" while it investigates the incident. The company has not as of yet informed the UK's data watchdog, the Information Commission's Office (ICO), about any breach. Exactly how many Asos customers received the notification on Tuesday remains unclear, but Google's Play store says the ASOS app has been downloaded to android devices more than 10 million times. The British retailer has a substantial global footprint -- serving around 17 million customers each year across more than 150 markets. Some Asos app users in Australia, France, Sweden and the Republic of Ireland had also received the notification, according to local reports on Tuesday. [...] Users of the Asos app appeared to have received the alarming notification at around 10:00 BST on Tuesday. Headlined "ASOS HACKED" and addressed to the company's data protection officer and IT teams, it said: "We have fully compromised the Snowflake instance." "Engage with us, or we will leak it," it added, before linking to a Telegram channel. The message left many ASOS customers confused. [...] Meanwhile Snowflake -- whose tools are used by dozens of firms to collect, analyze and store data -- told the BBC its investigation was ongoing, but it had so far found "no compromise" of its platform.


    Read more of this story at Slashdot.


  • IBM and Red Hat Find More Than 400 New Vulnerabilities In Popular Java Code
    IBM and Red Hat say their AI-powered Lightwell initiative has identified and helped remediate more than 400 previously unknown vulnerabilities across widely used Java libraries. Phoronix reports: They announced this feat today as part of their promoting Lightwell Clearinghouse to GA, which is an enterprise service for their customers to submit open-source software dependencies for priority review and remediation. From today's announcement: "The milestone addresses a growing business risk. As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications."


    Read more of this story at Slashdot.


  • Licensing Costs Driving 90% of VMware Users To Explore Options, Survey Finds
    An anonymous reader quotes a report from Ars Technica: VMware customers face multiple obstacles as they rethink their virtualization strategy to reduce dependence on VMware. Today, Rimini Street published its "2026 IT Virtualization Survey -- What's Next for VMware Users." The survey examined 300 organizations worldwide that use VMware. Notably, Rimini sells third-party support for VMware and other software, including Oracle and SAP. That means there's an incentive for Rimini to portray VMware users as experiencing obstacles. However, the survey was also conducted by a third-party research company, Unisphere Research, and the results align with other recent reports about VMware customers. For example, 90 percent of participants in Rimini's survey said they're exploring VMware alternatives due to VMware's higher licensing costs, while 54 percent pointed to Broadcom killing support for perpetual license holders. Since Broadcom took over VMware, customers have said that their VMware costs increased by as much as 1,000 percent, with many more pointing to more modest price hikes of around 100 to 300 percent. In Rimini's survey, 73 percent of participants pointed to cost savings as a top priority in their virtualization roadmap decisions. In today's announcement, Rimini pointed to "significant barriers to progress" for organizations exploring virtualization options, with the most cited barriers being operational complexity (named by 40 percent of respondents), multi-vendor management challenges (38 percent), securing the increased attack surface (37 percent), and team skills requirements (37 percent). "These findings suggest that while organizations are actively pursuing change, they are also looking for ways to reduce risk and avoid unnecessary disruption," Rimini's announcement said. [...] Rimini reported that 60 percent of the organizations it surveyed are considering a multi-hypervisor strategy, which is indicative of "growing interest in more flexible, mixed environments that support both operational and financial goals." "In addition, 47 percent are favoring a hybrid IT virtualization environment consisting of hypervisors and containers for 'best of both worlds' workload placement," the announcement said. Rimini noted that 48 percent of respondents aren't planning to move any of their assets to VMware's hybrid cloud platform, Cloud Foundation.


    Read more of this story at Slashdot.



Linux.com







  • From DHCP to SZTP – The Trust Revolution
    By Juha Holkkola, FusionLayer Group The Dawn of Effortless Connectivity In the transformative years of the late 1990s, a quiet revolution took place, fundamentally altering how we connect to networks. The introduction of DHCP answered a crucial question, Where are you on the network?!, by automating IP address assignment. This innovation eradicated the manual configuration [0]

    The post From DHCP to SZTP – The Trust Revolution appeared first on Linux.com.





Phoronix

  • Star Labs StarFighter Ultra: A Modern High-End Linux Laptop With Coreboot
    When it comes to Linux pre-loaded laptops, I have looked at hardware from most of these vendors over the past 22+ years of Phoronix. One vendor I haven9t had the chance to personally test until now is the UK-based Star Labs. That changed recently and over the past few weeks I have been testing out their new StarFighter laptop that offers great Linux support and comes pre-loaded with Coreboot and streamlined firmware updates via LVFS. For those after a high-end mobile workstation, the Star Labs StarFighter offers a lot of performance potential while being open-source friendly and with Coreboot in tow.







  • AMD Engineer Talks Up New IBS Memory Profiler Feature Found On Zen 6
    One of the AMD Zen 6 CPU features that hasn't been talked about too widely beyond appearing in a public AMD tech doc is the IBS Memory Profiler. This week in Prague at LPC 2026 an AMD engineer talked up Zen 6's IBS Memory Profiler and its benefits for hot page detection and promotion on Linux systems...



  • New Patches For Linux9s Zswap Show Major Improvements
    Amid multiple ongoing innovations being pursued in the Linux memory management space amid sky high RAM prices, a new patch series posted on Monday aim to enhance the Zswap performance for this compressed RAM cache for swap pages...


  • Canonical Reaffirms Plans For Ubuntu 27.04 To Use ntpd-rs By Default
    Back in March Canonical announced switching to ntpd-rs was its next target as part of transitioning more Ubuntu Linux system components to Rust-based implementations. This time synchronization package is available for testing in the upcoming Ubuntu 26.10 release while it aims to be the default for Ubuntu 27.04...



Engadget"Engadget - Technology News & Expert Reviews"











OSnews

  • KDE developer takes a look at COSMIC
    KDE contributor and developer Niccolò Venerandi has published an article about COSMIC, System76s brand new desktop environment. Its been almost a year since Ive last tried COSMIC; though development since then has mostly been centered around stability (going from late alpha to stable releases now!) there have been a fair bit of user-facing changes too which I adore. I thus have to ask myself: should I switch to COSMIC? The answer obviously is no, but thats just because I got addicted to KDE Plasma, so lets try to be more objective here. ↫ Niccolò Venerandi Honestly, this is one of the best reviews! Ive seen of COSMIC, and paints System76s hard work in a really positive light. Venerandi spots countless really nice touches hed love to see adopted by KDE, while also hitting on what I agree is COSMICs biggest shortcoming at this point: theres basically no ecosystem around it. COSMIC uses its own Rust-based toolkit instead of GTK or Qt, but of course, theres very few other applications that actually use said toolkit. The end result is that if you run COSMIC, youre going to have to supplement it with countless GTK and Qt application, none of which will inherit all the nice features, touches, and graphics from COSMIC. This isnt really a complaint about COSMIC itself or the work its developers are putting into it, but more a fact of life for such a new desktop environment using an otherwise unpopular (as of right now) toolkit. This may very well change in the future, but for now, if you choose to run COSMIC, youre going to have to accept a very inconsistent and messy desktop. This wont matter to everyone, but it sure does matter to me, and its the one reason why at this point I have zero interest in running COSMIC. I really hope this changes in the future  competition is good  but its going to be a long road.


  • Microsoft claims its optimising Windows for 8GB of RAM
    Speaking of Windows and performance, how about that RAM crisis? Microsoft is feeling the squeeze too, and is apparently doing work up and down the Windows stack to improve its memory consumption. Microsoft’s Windows chief Pavan Davuluri has admitted that the rising cost of memory is pushing the company to make Windows 11 use less RAM. Microsoft is working on the Windows memory manager, memory compression, WinUI 3 and WebView2, and has made “memory optimization for 8GB and above” an official priority for the rest of 2026. ↫ Abhijith M B at Windows Latest This might be the only positive consequence of the RAM crisis.


  • Windows legacy 8.3 filename support actually negatively affects performance
    To this day, Windows retains full support for the old MS-DOS 8.3 filename limitation, and it does this by creating 8.3 aliases for files with longer names. Apparently, this has a measurable effect on performance, so naturally, people are going to turn it off to make their Windows installations perform better. According to the user, this resulted in noticeably smoother scrolling in Tile view. They subsequently repeated the process on several folders they regularly use and reported that searching through files became much faster. The user also claimed that external hard drives became faster and that browsing an Android directory over USB or FTP behaved more like a regular Windows folder, including when copying large numbers of music files. ↫ Sayan Sen at Neowin You can disable this legacy feature in Windows per volume or globally, but Microsoft is warning users not to do so. Even in 2026, applications and registry entries may depend on 8.3 filenames being available, so removing them can lead to unexpected outcomes. Its just one of those things you wouldnt expect to still be around or have a measurable impact in the days of fast SSDs, but theres enough credibly evidence out there to suggest that yes, it actually does negatively affect performance. If youre doing a lot of file operations in Windows, it might be worthwhile to do some testing of your own to see if you can speed things up. Or, you know, you can just not use a house of cards disguised as a serious operating system.


  • Apple changes Full Disk Access permission in macOS
    Apples macOS has a Full Disk Access permission, designed to allow backup applications full access to, well, the disk, so they can perform their job properly. Apple posted a notice on its website that its going to further restrict this permission, because some applications were abusing this permission to gain access to users messages, emails, and so on, which it obviously isnt intended for. What kind of applications, you may ask? Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy. ↫ Announcement from Apple This was prompted by a story a few weeks ago, where Facebooks Muse AI! tool was apparently reading peoples private messages and other data, and even sent messages on users behalf, without informing its users. Its incredibly naive to think Facebook software in 2026 would not do creepy things, so Im honestly not at all surprised. It makes sense in Apples worldview to further restrict permissions in response, but Im sure more experienced macOS users are not going to like this.


  • Klassik brings KDE3s look and feel to KDE Plasma 6
    The KDE project recently brought back its classic Oxygen and Air themes, but what if you prefer something0 A little older? A modern recreation of the classic KDE 3 desktop experience for KDE Plasma 6, built entirely using Qt 6 and Qt Quick, with full support for Wayland and fractional scaling. ↫ Klassik GitHub page Neat.


  • SquirrelOS is an operating system named after the squirrel
    I like squirrels. Apparently, theres a SquirrelOS. Its a small hobby OS learning project from five years ago, developed by Immanuel Daviel A. Garcia. A simple DOS like OS made in Assembly and C with a ported version of Stephen Brennans Shell. ↫ SquirrelOS GitHub page Why do I like squirrels? I dont know man, theyre just cute.


  • Google breaks promise to provide 10 years of updates to Chromebooks
    Google launched its Googlebooks platform a week ago, and a lot of people were wondering what this meant for Chrome OS and Chromebooks. Since Googlebooks and its Android-based Googlebook OS lack the management frameworks markets like schools require, Chromebooks will continue to be available for now, until such time Googlebooks catch up in that regard. However, in a support document, Google states that update support for all Chromebook devices will end in 2034: ChromeOS devices will continue to receive regular updates and security patches through mid-2034. For qualifying devices purchased today whose 10-year support lifecycle extends beyond 2034, Google is committed to supporting your transition to Googlebook OS, with many devices offering direct migration paths. ↫ Google support document Google promised 10 years of updates for all Chromebooks, and its now breaking that promise for anyone buying a Chromebook between now and whenever the last Chromebook rolls off the production line. Sadly, we live in a world where corporations are free to make and break whatever promises they want virtually free of consequences, and as society were so used to it that anti-consumer behaviour like this barely elicits a shrug. Google does state that many newer commercial Chromebook models will be capable of upgrading to Googlebook OS!, but that, too, is just another promise  and a vague, one at that  so who knows how many devices will actually be capable of upgrading out in the real world. On top of that, we have no idea if Googlebooks will just be yet another in a long line of quickly abandoned Google tablet/laptop projects, further adding to the uncertainty. Stuff like this should not be legal.


  • macOS Golden Gate is a buggy mess!
    In June 2008 Apple announced Mac OS X Snow Leopard, proudly boasting that it would have no new features!. Instead of piling on new things, Snow Leopard aimed to build on the success of its predecessor, Leopard, opting to focus on under-the-hood performance and stability improvements throughout the system. 18 years later, Apple is taking a similar approach with macOS 27. Golden Gate aims to fix the missteps of last years Tahoe, promising an expansive set of improvements and a more responsive and delightful experience!. Does it hold up? Here are just some of the bugs I’ve encountered in my daily use over the past couple of weeks. ↫ Chester at SquareOrbits Im getting some real Windows 11 vibes from this long list of bugs and issues, further underlining my perception that Apple completely lost the plot when it comes to Mac OS X (in the past) and MacOS (today). These are not the kind of things youd find in the heydays of Mac OS X, back when I was a devout user, and makes me glad I abandoned ship long, long ago (around the time of the Intel transition). I dont see stuff like this in GNOME or KDE, and while not nearly as bad as Windows 11, the cracks are obvious. I am by no means an expert at how Apple is run and how it organises itself, but as a layperson I do wonder if the company is simply trying to do too much  too many different platforms, too many different crucial components it all develops internally, too many different markets to please. Things are going to fall through the cracks when you try to keep this many plates spinning.


  • Tcl/Tk 9.1 released
    A brand new Tcl/Tk release, in the form of Tcl/Tk 9.1. The new features in Tcl are a bit difficult for me to properly parse as a non-developer, but Tks improvements are easy to understand: it brings supports for screen readers, initial supports for bidirectional and RTL scripts, improved listbox selection colours, and more. It also happens to drop support for Windows XP appearances, if thats something that matters to you.


  • WSL containers are now generally available
    Microsoft has announced WSL containers for developers who arent already using Docker, Podman, or Rancher on their Windows workstations. WSL containers is now generally available! Check out this blog post to learn more about this overall feature enabling seamless access to Linux containers on Windows via the new “wslc.exe” command. This new Linux container platform comes with multiple architectures changes compared to WSL, which we’ll detail in this post. ↫ Pierre Boulay at the Microsoft Dev Blogs If you already have WSL installed, you can run wsl -update to get this new container feature, or you can download it straight from GitHub.



Linux Journal News

  • EU OS: A Bold Step Toward Digital Sovereignty for Europe
    Image
    A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem.
    What Is EU OS?
    EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.

    Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments.
    The Vision Behind EU OS
    The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.

    Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.

    However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty.
    Conclusion
    EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.

    Source: It's FOSS
    European Union


  • Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.

    In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.

    On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.

    Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.

    The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.

    Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.

    You can download the latest kernel here.
    Linus Torvalds kernel


  • AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
    Image
    AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.

    This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.

    Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.

    Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.

    Source: 9to5Linux
    AerynOS


  • Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
    Image
    Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.

    Here’s a quick overview of what’s new in Xojo 2025r1:
    1. Linux ARM IDE Support
    Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started.
    2. Web Drag and Drop
    One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required!
    3. Direct App Store Publishing
    Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process.
    4. New Desktop and Mobile Features
    This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection.
    5. Performance and IDE Enhancements
    Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced.
    What Does This Mean for Developers?
    Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution.
    How to Get Started
    Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.

    Download Xojo 2025r1 today at xojo.com.
    Final Thoughts
    With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you.
    Xojo ARM


  • New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux

    Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.

    Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.

    Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest. 

    Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.

    Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.

    Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.

    By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem.
    Windows


  • Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities

    The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally. 

    As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.

    In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions. 

    After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.

    The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.

    At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.

    The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca.
    Security


  • Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges

    The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.

    A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.

    This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem. 

    The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.

    On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.

    In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers.
    kernel


  • Linux Celebrates 32 Years with the Release of 6.6-rc2 Version

    Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.

    The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.

    Here is what Linus Torvalds had to say in today's announcement:
    Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds


  • Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction

    Want to interact with ChatGPT from your Linux desktop without using a web browser?

    Bavarder, a new app, allows you to do just that.

    Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.

    With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.

    During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.

    At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.

    As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!

    Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring.
    ChatGPT AI


  • LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite

    Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.

    Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.

    LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.

    You can download LibreOffice 7.5.3 directly from the LibreOffice website or from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.

    All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.

    In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.

    Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.

    The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners.
    LibreOffice


Linux Magazine News (path: lmi_news)









  • Advanced Video Coding Still Under Patent
    Brazilian patent BRPI0109962B1 has expired, which means that DivX and Xvid are no longer problematic for Linux, but it doesn’t mean that video is all of a sudden fully unleashed.



Page last modified on November 17, 2022, at 06:39 PM