Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All) (Two Column)

LWN.net

  • [$] LWN.net Weekly Edition for July 23, 2026
    Inside this week's LWN.net Weekly Edition:
    Front: LLMs in the kernel; GNOME save and restore; Fedora changes; BPF and tracepoints; BPF and LSMs; famfs; sched_ext. Briefs: GNOME security; PyPI policy; Arch on aarch64; Firefox 153; Quotes; ... Announcements: Newsletters, conferences, security updates, patches, and more.


  • [$] Save and restore may be coming to GNOME
    One of the features that users often miss when moving from X11 to Wayland isthe ability to save and restore the position of windows between sessions. At GUADEC 2026, held inA Coruña, Spain, Adrian Vovk provided an overview of work that has goneinto providing a platform-wide save and restore framework for GNOME. After twofailed attempts at landing an API, he believes that the third try will be theone to succeed—though not in time for the upcoming GNOME 51 releasedue in October.


  • PyPI now rejects new files after 14 days
    Python Software Foundation security developer-in-residence SethLarson has announcedthat the Python Package Index (PyPI) will now reject new files thatare uploaded to releases older than 14 days. The restriction is toprevent the poisoning of old releases if publishing tokens orworkflows of PyPI projects are compromised.

    The discussionof this behavior began during PEP 740 (Digital Attestations) back in January2024. The discussion was restartedin March 2026 after the popular packages LiteLLMand Telnyx were compromised. These packages were compromised due to a "mutablereference" in these projects' usage of the Trivy GitHub Action.

    Originally the discussion stalled due to some projects depending on this behaviorto add support for new Python versions to already-published releases. To quantify howdisruptive this change would be to existing workflows, the PyPI database was queriedfor projectsthat have published new files to old releases (bucketed by number of days sincethe release). Later, specifically cp314 wheels were queried for the top15,000 packages, revealing that only56 projects of 15,000 had published a 3.14-compatible wheel more than 14 daysafter a release was available.

    LWN covered the LiteLLM compromisein March.



  • Security updates for Wednesday
    Security updates have been issued by AlmaLinux (389-ds-base, c-ares, dovecot, freerdp, glib2, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, kernel, kernel-rt, nodejs:22, perl-XML-LibXML, webkit2gtk3, and yggdrasil), Debian (kernel, nss, roundcube, rtpengine, and xz-utils), Fedora (btrbk, kernel, mupdf, nuclei, perl-Crypt-OpenSSL-X509, rust-fern, rust-ifcfg-devname, rust-routinator, rust-rpki, and rust-syslog), Mageia (tig), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, acl, dovecot, glib2, httpd, libtiff, pacemaker, perl-IO-Compress, plexus-utils, python3, and webkit2gtk3), Slackware (libssh and mozilla-firefox), SUSE (acl, avahi, aws-nitro-enclaves-cli, beets, chromium, firefox, go1.25-openssl, ImageMagick, iscsiuio, kernel, kubevirt1.8-container-disk, libgit2-1_9, libkrun, libsoup-3_0-0, nghttp2, opam, php7, python-aiohttp, python-tornado6, and vim), and Ubuntu (accountsservice, CUPS, imagemagick, jbig2dec, openssh, and snapd).


  • Firefox 153 released
    Version153.0 of the Firefox web browser has been released. Notablechanges in this release include a change to the defaultlocal-file-access permissions for extensions, enabling LANrestrictions by default for all users, a visual indicator when a website has access to the user's location, the ability to merge PDFs andadd images as pages within PDFs, as well as experimental support forthe JPEG XL image format.

    See thereleasenotes for developers for all changes that affect web developers,and securityadvisories for vulnerabilities fixed in this release.



  • [$] Debating the role of large language models in the kernel community
    Like many development communities, the kernel community has been strugglingto determine how large language models will be used in its developmentprocess. The news has been dominated recently by a strongly worded missivefrom Linus Torvalds on the subject, but the discussion has been rather morewide-ranging and nuanced than that. Topics that have been consideredrecently include the LLM attribution requirement, code-review tools,dependence on proprietary tools, and whether there is a place for concernsabout the ethics of LLMs.


  • Security updates for Tuesday
    Security updates have been issued by AlmaLinux (capstone, fence-agents, gimp, glib2, hplip, httpd, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, libtiff, maven:3.8, pacemaker, python3.14, and webkit2gtk3), Debian (samba), Fedora (c-ares, dnsx, freerdp, gpsd, libreswan, libseccomp, libtiff, mingw-python-idna, mingw-python-pip, openssh, python-pillow, wget1, and wireshark), Mageia (golang, graphicsmagick, haveged, libssh2, nginx, nilfs-utils, perl-CGI-Session, perl-Imager, perl-JavaScript-Minifier-XS, php, php8.4, php8.5, python-nltk, sqlite3, and xmlstarlet), Oracle (.NET 10.0, .NET 9.0, container-tools:ol8, firefox, giflib, glibc, go-fdo-client, go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, hplip, httpd, image-builder, kernel, libtiff, mod_http2, pacemaker, perl-DBI:1.641, perl-HTTP-Daemon, php:8.2, python-markdown, ruby4.0, systemd, and thunderbird), Red Hat (buildah, container-tools:rhel8, dracut, golang-github-openprinting-ipp-usb, libtiff, osbuild-composer, python-urllib3, python3.12-urllib3, python3.14-urllib3, and runc), SUSE (389-ds, chromedriver, gstreamer-plugins-bad, libreoffice, libsuricata8_0_6, podman, python311, and sssd), and Ubuntu (apache2, freerdp3, freetype, libde265, libxfont, linux, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-realtime, linux-realtime-6.8, linux, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-realtime, linux-xilinx-zynqmp, linux, linux-gcp, linux-gke, linux-realtime, linux-gcp-6.17, linux-realtime-6.17, linux-gcp-fips, linux-hwe-7.0, linux-nvidia-tegra-5.15, linux-oem-7.0, nginx, php8.1, php8.3, php8.5, rlottie, sqlite3, and wget).


  • [$] Fedora grapples with change
    The Fedora Project is known for,among other things, having a well-defined set of processes for just abouteverything. It has extensive packagingguidelines that deal with the complexities of creating RPMs to installsoftware, as well as processes for managing the legal questions thatarise around shipping software. Fedora also has a well-defined changeprocess for dealing with self-contained technical changes as well as majorchanges to the distribution, and other issues as they arise. At the moment,though, the project seems to be experiencing a sort of midlife crisis as itre-examines several of its change processes at once to determine if they arestill effective.


  • Catanzaro: Some changes to GNOME security tracking
    Michael Catanzaro, who has been managing GNOME security issue tracking sinceNovember 2020, has written a blog post that details some changes in how he willbe managing GNOME vulnerability reports from now on due to an increase inAI-generated security reports. He will be switching from a 90-day deadline fordisclosures to 30 days for issues reported on August 1, or later. "Theshorter deadline would probably work better for GNOME even if not for theincrease in AI-generated issue reports."

    He also has indicated that he will be stepping away from the task of managingsecurity issue tracking entirely by December 1, 2026, which means that therewill be a gap to fill:

    Currently nobody else is tracking GNOME security issues. If you are anexperienced GNOME community member and you are interested in taking over thiswork, let me know and I will help you get started. (Security tracking is not agood task for newcomers.)

    This may also be an opportunity to improve our tracking infrastructure. I usea wikipage, but this is fairly primitive and requires considerable manualupkeep. It's easy to forget to update the page when an issue report is closed,for example. Ideally, we would replace the wiki with a proper web app thatdynamically updates based on the actual state of the issue.


  • [$] Merging famfs?
    The famfs filesystem, which is meant to provide shared access to hugememory-resident files on CXL and otherdevices, returned tothe Linux Storage,Filesystem, Memory Management, and BPF Summit (LSFMM+BPF) in 2026.It was first discussed at LSFMM+BPF 2024 and a new implementation was described at the 2025gathering, but it still has not made its way into the kernel; LWN lookedat a discussion about merging famfs back in April 2026.


  • Security updates for Monday
    Security updates have been issued by Debian (kernel, libnfs, roundcube, and tiff), Fedora (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-astral_async_zip, spoofdpi, uv, and yq), Mageia (bind, clamav, erlang, libidn, libreoffice, nmap, nodejs, perl-Bytes-Random-Secure, perl-Config-IniFiles, perl-CSS-Minifier-XS, perl-HTML-Parser, perl-Mojolicious, perl-String-Util, python-pydantic-settings, rsync, and upower), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, bind, cockpit, cockpit-image-builder, coreutils, delve, dnsmasq, dovecot, expat, fence-agents, flatpak, frr, gdk-pixbuf2, giflib, glib2, go-fdo-client and go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd, jq, kernel, keylime, krb5, libcap, libexif, libpng, libsndfile, libsolv, libsoup3, libtasn1, libtiff, libxslt, libyang, mariadb10.11, mod_http2, mod_md, opencryptoki, PackageKit, perl-Archive-Tar, perl-IO-Compress, poppler, postfix, postgresql-jdbc, python-urllib3, python3.14, python3.14-pip, python3.14-urllib3, qt6-qtdeclarative, rrdtool, rsync, ruby, ruby4.0, samba, skopeo, thunderbird, valkey, wireshark, xorg-x11-server-Xwayland, and yggdrasil-worker-package-manager), and SUSE (blender, chromium, containerized-data-importer1, cyrus-imapd, go1.26-openssl, gomuks, grafana, gstreamer-plugins-bad, kbfs, kubevirt1.8-container-disk, libxml2, lux, mariadb-connector-c, nginx, opam, openssl-3, oras, perl-DBI, php-composer2, python-django-haystack, python-paramiko, python-weasyprint, python311, python313-Pillow, python315, shibboleth-sp, system-user-zabbix, and wget).


  • Kernel prepatch 7.2-rc4
    The 7.2-rc4 kernel prepatch is out fortesting. Linus said: "This whole week I had the feeling that peoplewere starting to go on summer vacation, but running the numbers shows thatI must have been wrong - it all looks pretty normal."


  • "Half a Second" — a book on the XZ backdoor
    Adrian Mastronardi has released a book called Half a Second; it is adetailed look into the XZ backdoor attemptof 2024. The book is freely available under a (non-free) noncommercial,no-derivatives CC license.
    Half a Second tells that story as one continuous narrative: the burned-out volunteer who maintained the code alone and was patiently, expertly manipulated into giving it up; the engineer whose half-second of curiosity caught the attack through a chain of luck and hard-won instinct; and the operator who built it, who has never been identified and, this book argues, may never be.



LXer Linux News


  • The "New Normal" Of Audio Quirks Submitted For Linux 7.2-rc5
    Linux sound subsystem maintainer Takashi Iwai of SUSE sent out this week's batch of sound fixes that he describes as "A collection of fixes that have been accumulated recently. The amount is still "new normal", but all small fixes. Mostly hardware-specific quirks, but including a few core fixes, too." The "new normal" has been a common phrase recently to reflect the increased tempo of patches as well as security/bug disclosures all due to the increased pace of AI/LLM activity...





  • Raspberry Pi launches 10-inch Touch Display 2 with 1200 × 1920 resolution
    Raspberry Pi has introduced a 10-inch version of its Touch Display 2, expanding the display family beyond the existing 5-inch and 7-inch models. The new panel provides a 1200 × 1920 resolution, ten-point capacitive touch, and compatibility with the Raspberry Pi 5 and supported Compute Module platforms. The 10.1-inch IPS display uses a native portrait […]


  • Distro of the Week: Vendefoul Wolf Excalibur Xfce
    And the hits just keep on coming . . . Not only was last week a first for Distro of the Week, we follow up with another first: This time, it's a Spanish distro based on Devuan, complete with its lack of systemd and using XLibre as the default X server. Ladies and gentlemen -- that covers most of you -- welcome to Vendefoul Wolf Excalibur Xfce, this week's Distro of the Week.









  • InputPlumber 0.78 Released With Expanded Hardware Support
    InputPlumber is out with its newest feature release. As a reminder, InputPlumber is the open-source input router and remapper daemon for combining various input devices from gamepads to mice and keyboards as well as the ability to emulate them...



  • Geniatech XPI-3576-CM5 brings 6-TOPS RK3576 performance with Raspberry Pi CM5 compatibility
    Geniatech’s XPI-3576-CM5 is a 55 × 40mm compute module built around Rockchip’s RK3576 processor and designed for use with Raspberry Pi Compute Module 5 carrier boards. It combines an octa-core CPU, a 6-TOPS NPU, LPDDR5 memory, optional Wi-Fi 6 connectivity, and commercial- or industrial-temperature configurations. The RK3576 integrates four Arm Cortex-A72 cores running at up […]


  • Qualcomm Posts Linux Patches For X2 Elite Extreme Powered ASUS Zenbook A16
    Following recent Linux kernel patches enabling the Snapdragon X2 Elite powered Lenovo Yoga Slim 7x Gen11 and HP EliteBook X G2q X2 Elite laptops to boot outside of Windows 11 on ARM, Qualcomm engineers have now posted a new patch series for getting the X2 Elite Extreme powered ASUS Zenbook A16 working on Linux...




Error: It's not possible to reach RSS file http://services.digg.com/2.0/story.getTopNews?type=rss&topic=technology ...

Slashdot

  • Pan Am Plane Crash That Inspired Modern Safety Briefings Found After 74 Years
    Longtime Slashdot reader BeaverCleaver shares a report from the BBC: The wreckage of a Pan American Airways plane has been found 74 years after it plunged into the Atlantic Ocean in a crash that prompted mandatory airline safety briefings. The Clipper Endeavor was found 2,000ft (610m) below sea level off the coast of Puerto Rico with a sonar-equipped drone. It went down on April 11, 1952, following multiple-engine failure shortly after take-off. Everyone onboard survived the impact -- but passengers struggled to locate life vests and rafts as the plane rapidly sank. Of the 69 passengers and crew onboard, just 17 survived. The disaster led to sweeping reforms in aviation safety, including compulsory pre-flight safety briefings on every commercial flight. [...] Today, before every commercial flight, cabin crew are required to outline where a plane's exits are, as well as the location of life vests and how to inflate them.


    Read more of this story at Slashdot.


  • GM Is Quietly Becoming a Subscriptions Company
    "General Motors has been pulling a Tim Cook and boosting its software and subscription business," reports Business Insider. During the automaker's Tuesday earnings call, executives said they're increasingly leaning on software subscriptions like OnStar and Super Cruise to generate high-margin recurring revenue long after customers buy their vehicles. GM says OnStar brought in about $800 million in the second quarter, while Super Cruise revenue grew about 70% year over year. From the report: GM says its software business keeps roughly 70 cents of every dollar it brings in. That's a rare level of profitability in the auto industry, as many car sales generate just four to 10 cents per sales dollar. [...] GM expects to add about 1 million OnStar subscribers this year, bringing the total close to 13 million. Super Cruise, GM's hands-free, eyes-on driving system, is growing even faster. GM added about 70,000 subscribers during the quarter and expects to end the year with more than 850,000. Revenue from the service increased about 70% from a year earlier. And a lot of drivers are sticking around after the free period ends. GM said between 30% and 40% of eligible owners continue paying after their included three-year Super Cruise subscription expires. [..] "We do think we have tremendous levers, multiple levers of growth," Barra said on the call. "We definitely think there's a lot of opportunity at GM to grow, improve margins, and become less cyclical." "Software and services are becoming increasingly important to how customers experience GM vehicles and how we deliver value beyond the initial purchase," a spokesperson previously told Business Insider. "As vehicles become more software-defined, we can introduce new digital experiences through updates and optional services rather than hardware changes."


    Read more of this story at Slashdot.


  • iOS 27 Code Suggests Apple Could Restrict Leased Devices After Missed Payments
    Code found in the iOS 27 beta suggests Apple is developing a system that could restrict leased iPhones when customers fall behind on payments. The discovery follows a recent Bloomberg report that Apple may soon launch a new "Apple Upgrade" leasing program, allowing customers to pay for hardware through monthly installments. 9to5Mac reports: The code describes a system called App Managed Features, which allows an authorized financing or provider app to enroll an iPhone and perform ongoing status checks. If the contract is no longer in good standing, Apple's system services can place the iPhone in "Restricted Mode," which blocks access to most apps until the payment or contract issue is resolved, while keeping a small set of apps available. The fixed allowlist currently found in the iOS 27 beta includes: Accessibility Reader, App Store, Health, Magnifier, Phone, Clock, Settings, Wallet, Passwords, and the Restricted Mode interface itself. Apps that can send critical alerts, such as Messages, Home, and certain medication or safety apps, may also remain accessible. However, the provider appears to have some control over those exceptions. The code does not appear to cancel, suspend, or otherwise modify App Store subscriptions associated with blocked apps. As a result, a subscription could continue billing even while access to its app is restricted. Additionally, there isn't a fixed number of missed payments that automatically triggers the restrictions. The financing provider's app decides when to lock the device based on its own policies. Finally, the new framework also introduces a new type of activation lock called "Partner Finance Lock," which is meant to prevent users from erasing, reselling, or stripping a restricted device for parts.


    Read more of this story at Slashdot.


  • Linux Kernel Team Publishes 432 CVEs In Two Days
    Ancient Slashdot reader alanw shares a post from the OSS Security mailing list, where sysadmin Jan Schaumann wonders what to do after the Linux kernel cranked out 432 CVEs in a little over 24 hours: "I understand the position that CVEs were always a flawed way to track or prioritize security changes... But this onslaught really shows it's not feasible to attempt to prioritize individual kernel changes. I'm not sure what to do here going forward." The Register reports: The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldn't be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become "almost entirely unmanageable" due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact "it keeps finding embarrassing bugs." [...] Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isn't one that's readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy. Senior kernel maintainer Greg Kroah-Hartman replied to Jan's post, pushing back on the idea that the kernel's CVE volume is uniquely unmanageable. The kernel isn't special, he argues -- companies everywhere are finally realizing they need to re-evaluate how they update all of their systems and devices, something that's traditionally been "woefully ignored." On the "just always update" approach, Greg says that's precisely what the kernel community endorses: "This is what the kernel developer community recommends and supports. If you want support from us, do this." Can't manage it yourself? Pay a company for support, or "just use Debian or Yocto as their security practices are amazing." He points to Android as proof the approach scales, calling it "the largest deployment of software in the world" -- billions of devices kept updated "with one very-overworked developer guiding it all." As for reviewing every CVE individually, he notes this can be largely automated by intersecting the files a CVE touches with the files you actually build, which typically trims the relevant set "down to about 10% of the overall total" -- the approach enterprise distros already take for their customers. Panic-mode selective patching gets a blunt "Good luck with that!" -- regulations like the EU's Cyber Resilience Act are set to legislate that habit away ("rightfully so," in his view), and "your insurance company might wish to have a talk with you as well." Greg also warns the flood isn't over: "The number of llm-found issues is only on the rise right now, it's going to be a very long 18 months at the least to dig ourselves out of this mess, and people had BETTER be updating their systems all along the way if they expect to be secure in any way." As for the 432-CVE burst itself, he explains it was simply him catching up on a weeks-old, publicly visible review queue over the weekend -- delayed by "a perfect storm of 6 weeks straight of conferences and vacations" -- so it shouldn't have come as a surprise to anyone watching the public git repo.


    Read more of this story at Slashdot.


  • Apple Partners With Klarna To Offer iPhones, Macs On a Subscription Basis
    Apple is reportedly launching a Klarna financing deal that will let U.S. customers spread the cost of devices over up to three years, pushing the company closer to a hardware-as-a-service model. "The only thing you don't get under the new arrangement is AppleCare, for which you'll allegedly need to pay extra," notes Computerworld. From the report: The introduction of the scheme gives consumers a way to purchase the company's popular high-end devices when they are introduced -- no doubt,at higher cost -- this fall. [...] A combination of changed customer habits and external threat means the stars are now aligned for hardware-as-a-service models. "Reframing a device as a low monthly payment protects that [upgrade] cadence and allows Apple to start marketing their products as device-as-a-service to consumers, which no other vendor was ever able to do," [IDC analyst Francisco Jeronimo] wrote to me. There is a one-more-thing aspect to this: the products are effectively being leased, a new approach that will give Apple a stronger grip on EOL devices, helping it grab more of them for refurbishment, resale, and recycling. Over time, this will give the company a much stronger grip on the lucrative second-user market that exists around Apple equipment, even while for almost every consumer product we find the life we want is something we can rent, but probably can't afford to own. The other solid reason to take a partnership approach is risk management. Apple had intended to develop its own buy-now, pay-later scheme via Apple Pay Later, but abandoned that plan as it became riskier with rising bank rates. "Also, by backing the program with Klarna rather than reviving the in-house subscription plan it shelved in 2024, Apple captures the demand upside without taking the credit risk onto its own balance sheet," Jeronimo said. "Apple Upgrade lands at precisely the moment Apple needs it," Jeronimo wrote in a note seen by Computerworld. "Having just pushed Mac and iPad prices up on the back of the memory shortage, with iPhone increases widely expected in September -- as well as the new iPhone foldable expected at $2,500 -- Apple's real risk is that rising prices even further can impact the upgrade cycle."


    Read more of this story at Slashdot.


  • The Army Is Burning Through Its AI Tokens
    An anonymous reader quotes a report from Wired: A little over a month after the Department of Defense (DOD) bragged that nearly half of its 3.5 million employees were using AI at work, members of the Army's Combat Capabilities Development Command (DEVCOM) received an email informing them that they were burning through tokens, and needed to limit use. "Although the Army CIO announced in May 2026 that they were offering unlimited tokens, by mid-June the Army CIO pool was exhausted of tokens and had to re-establish limits," the email reads. The email goes on to say that although the Army has chosen to renew token usage at "its current levels," it's unclear "if the Army CIO pool will be renewed after 1 Oct." The Army uses Ask Sage, a multimodal generative AI platform where users can run different large language models (LLMs), including Alphabet's Gemini, Meta's Llama, and OpenAI's ChatGPT. "Apparently the whole Army burned through the whole year of tokens for just one service," says an Army employee who spoke to WIRED [...]. The Army employee says that the Army has been pushing its workers to lean into using generative AI. Employees were given an allotment of at least 200,000 tokens per month, according to emails viewed by WIRED, and were automatically allocated more if they burned through their initial allotment. Employees who had signed up for Ask Sage but were not regularly using it would receive emails encouraging them to use more of their allocated tokens. In order to use Ask Sage, the Army had access to 100,000,000 tokens as part of an annual subscription to an "enterprise pack." Tokens represent a unit of output, either in text or image, from an LLM. For the Ask Sage tool, a single token equates to about 3.7 characters, according to documents viewed by WIRED. The Defense Department burned through some 20 billion tokens per day during the 38-day Operation Epic Fury in Iran, according to Breaking Defense. It's unclear if the tokens used by regular DOD employees are drawn from the same pool as those who might be using AI tools on classified or secret information.


    Read more of this story at Slashdot.


  • Microsoft Announces Xbox Backward Compatibility For PC
    Microsoft has announced Xbox Backward Compatibility for PC, a new preservation program that will let players run select classic Xbox games on Windows PCs and handhelds like the ROG Xbox Ally. Tom's Hardware reports: "This marks the beginning of a broader effort to preserve XBOX games from the past and bring them to PC over time," the company said in a blog post authored by Xbox "VP next generation" Jason Ronald. Alongside backward compatibility, the company says games will also include new features. The four titles in the announcement are: BLiNX: The Time Sweeper; Conker: Live and Reloaded; Crimson Skies: High Road to Revenge; and Fuzion Frenzy. You can now buy all of these games on PC, and they're also included in all Xbox Game Pass plans. Anyone who already owns these titles digitally on console can also now play them on PC or handheld, with support for Xbox Play Anywhere and Xbox Cloud Gaming. Crucially, this appears to be a digital-only preservation effort, so it won't help anyone who only owns physical copies of these games. Xbox has reportedly been testing a way to digitize physical games as far back as Xbox One, but that hasn't yet materialized yet. Alongside the preserved original gameplay, Xbox claims these games will let users customize graphics settings, with up to 4x resolution scaling, VSync support, Fullscreen and Windowed modes, anisotropic filtering, and enhanced anti-aliasing, with more features to come in the future. Notably, Xbox will add achievements to select original Xbox games on console and PC.


    Read more of this story at Slashdot.


  • Samsung Galaxy Z Fold 8 Announced to Compete With Future iPhone Fold
    At a Galaxy Unpacked event in London today, Samsung unveiled a new foldable smartphone designed to compete with the still-unannounced iPhone Fold. Called the Galaxy Z Fold 8, it features a wider 4:3 form factor with a 7.6-inch inner AMOLED display, Snapdragon 8 Elite Gen 5 for Galaxy chip, up to 16GB of RAM and 1TB of storage. "The inner display has enough extra real estate for multi-tasking and entertainment," reports Mashable, which got a chance to try the new foldable ahead of the event. "And if you're worried about a crease in the middle of the display, don't be. We got up close with the device, and the crease fully disappears when the display is activated." From the report: As stated above, the main distinguishing factor of the new Z Fold 8 is its wider 4:3 proportions compared to the Z Fold 8 Ultra. If the latter is a book-style foldable, the former can almost be called a tablet-style foldable, instead. We think the wide screen will serve even better for reading books or multi-tasking with several apps open at once. Also, at 201g, Samsung is really emphasizing how light the device is. The company is calling it the "world's lightest fold ever." And while the device may be light, its no lightweight. Samsung's newest foldable features Flex Titanium technology, which makes the Galaxy Z Fold 8 more durable. Speaking of durability, it also boasts Samsung's advantage hinge technology, Armor Flexhinge. The Z Fold 8 feels like a solid middle point between the premium Z Fold 8 Ultra and the comparatively affordable Z Flip 8. All three phones use the same chip, but the Z Fold 8's 4,800mAh battery is smaller than that of the Z Fold 8 Ultra. However, the Z Fold 8 does have an option for 16GB RAM and 1TB of storage, similar to the Ultra.


    Read more of this story at Slashdot.


  • LG To Ban Residential Proxies From Smart TV Apps
    An anonymous reader quotes a report from KrebsOnSecurity: The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV. On July 2, [KrebsOnSecurity] featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one's television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung's Tizen operating system had similar residential proxy components. Responding to questions about Spur's research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended. "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor said. "If this option is not removed, these apps will be suspended." Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company's review of those apps is "well underway now." "As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor wrote in an emailed statement. [...] "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Spur's Trevor Sutter wrote. "The risk is amplified when consent comes from individuals within the household who use the device but shouldn't give consent, such as minors." LG is also facing criticism for monitors that automatically install software promoting paid McAfee subscriptions through Windows Update without user approval.


    Read more of this story at Slashdot.


  • Jack Dorsey Takes On Slack and GitHub With New AI Workplace Platform 'Buzz'
    Jack Dorsey's Block has launched Buzz, an open-source workplace collaboration platform that combines messaging, project management, and software development workflows for teams of both humans and AI agents. Dorsey described Buzz as "a new groupchat platform for teams of people and agents of all sizes" that is "model-agnostic, decentralized, self-sovereign and open source." SmartCompany reports: According to the Buzz website, users can invite specialized AI agents into team chats, allowing them to collaborate with employees and even other AI agents. From there, they can reportedly move directly from discussions into planning, coding, pull requests and project management without switching between multiple applications. Buzz also aims to replace parts of GitHub by bringing software development workflows directly into the platform. Teams can plan work, write code, review pull requests and manage Git projects without jumping between separate collaboration and development tools. [...] In practice, that means businesses aren't locked into a single AI provider. Organisations can self-host Buzz, customize it to suit their own workflows and choose whichever AI models best fit their needs.


    Read more of this story at Slashdot.


  • Long Presumed Dead, a Thriving Coral Reef Is Discovered in West Africa
    Scientists have rediscovered a healthy coral reef off the coast of Benin more than 60 years after surveyors first hinted at its existence. "At least eight coral types and eight fish species have formed a thriving ecosystem on this long-forgotten site," reports Inside Climate News. "What they had captured was a wealth of marine life: six types of soft coral; two black corals; and eight species of sheltering fish, from golden African snappers to the Monrovia doctorfish." From the report: While no coral samples have yet been extracted, researchers have classified the site as a mesophotic coral ecosystem (MCE). Such systems are light-dependent communities existing at the lower limits of reef-building corals. At more than 175 feet below the surface, the coral garden they discovered appears patchily scattered on a rocky substrate. Bridging the gap between shallow reefs and deeper benthic habitats, MCEs are home to distinct species and unique environmental conditions. While scientists are increasingly recognizing their ecological and climatic importance, they remain among the least explored elements of tropical and subtropical marine biodiversity. And this one has real potential to unlock new information about coral history. "Since it's an undisturbed marine ecosystem, it can help through carbon dating or paleoclimatic study to tell us which kind of climate system has occurred here in the past," said [Gerard Zinzindohoue, the project lead for Coral Reefs Rediscovering & Exploration in Benin]. "It's better to know the past to help explain the present, and help know which kind of direction we can take in the future." In addition to the blackbar soldierfish, West African goatfish, and Guinean angelfish filmed darting through the reef, the discovery presents potential conservation claims for other marine life. "We will be advocating for its full protection, perhaps by setting up a marine protected area around it," said [Houangninan Midinoudewa, an oceanographic researcher at the Benin Marine Conservation Club], who specializes in elasmobranchs -- the study of sharks, rays, and skates. Midinoudewa is currently submitting an application to designate the area as an Important Shark and Ray Area with the International Union for Conservation of Nature. Based on the knowledge of local fishermen, Midinoudewa is confident the reef is home to sawback angel sharks, silky sharks, brown skates, and marbled stingrays. The team behind the discovery hopes this will spark a wave of similar discoveries in the waters off West Africa, an area of the world underserved by scientific research projects. "I hope the Gulf of Guinea will be a hub for research because we know our resources are being exploited and people [need to] know exactly what we have and why we should care," said Midinoudewa. Zinzindohoue agrees: "We don't need to wait for others to come to our country to show us what is under our sea. We are the ones who must take responsibility."


    Read more of this story at Slashdot.


  • OpenAI Says Its AI Models Acted On Its Own In An 'Unprecedented' Hack
    "GPT-5.6 Sol and an 'even more capable' model used stolen credentials and exploited vulnerabilities in the Hugging Face API to obtain secret information used to cheat on evaluations," writes longtime Slashdot reader Dr. Bombay. The Associated Press reports: "We had a significant security incident during evaluation of our models," OpenAI CEO Sam Altman said in a statement posted on social media. AI startup Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent autonomously acting on its own. "We suspected last week's cyberattack might have come from a frontier lab, given the sophistication of the agent," Hugging Face co-founder and CEO Clement Delangue said in a statement. "Turns out it did!" [...] "AI is accelerating the discovery and exploitation of vulnerabilities," OpenAI said in its statement Tuesday. "The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities." Delangue said he spent the past 24 hours working with OpenAI, "and we strongly believe there was no malicious intent on their part. It's quite mind-blowing that all of this happened autonomously!" Delangue added that it "might be the first incident of its kind."


    Read more of this story at Slashdot.


  • France Becomes First European Country To Ban Social Media Access For Under-15s
    An anonymous reader quotes a report from The Guardian: France's parliament has approved a bill banning social media access for children under 15, making it the first European country to bar children from apps such as TikTok. The president, Emmanuel Macron, has championed the ban as a key reform of his final term in office and pledged to enforce it by September. "France is leading the way in Europe when it comes to protecting our children and teenagers," Macron said in a video posted on social media, hailing "a major step forward." He thanked members of parliament for backing the legislation on Tuesday. "The Constitutional Council must now rule on it, and then it will be time to take action to make this measure a reality and protect our children online," he added on X. After approval by the Senate earlier on Tuesday, members of the National Assembly passed the bill by 279 votes to 81. A growing number of countries are taking steps to restrict social media access amid multiplying warnings over its harmful effects on children. The ban was to be introduced in two stages, with under-15s blocked from creating new accounts from September 1. The ban would apply to existing accounts from January 2027, according to the legislation. The digital minister, Anne Le Henanff, said before the vote that the timeline was realistic, "because age-verification tools already exist" and others are still in the works, and the onus was on the platforms to impose the rule. "For four months, all of us in France will have to prove our age," she told journalists. "If someone is under 15, the account will be closed." The minister also gave assurances that users' personal data would be protected.


    Read more of this story at Slashdot.


  • Airbus Migrating 70 Critical Apps From AWS to France's Scaleway
    Airbus is moving 70 critical applications from AWS to French cloud provider Scaleway as part of a broader digital sovereignty push to keep sensitive data "under European control." Eventually, the migration will cover 900 applications, including ERP, CRM, manufacturing execution, and product lifecycle management systems. Airbus says it will, however, continue using U.S. providers for less sensitive workloads. "We do not intend to move away from all non European solutions; we balance our choices based on the criticality of the data," the company said. The Register reports: Catherine Jestin, head of digital at Airbus, told us on Thursday: "The selection of Scaleway is a combination of a very strong technical answer and a very strong commercial offer making it competitive compared to hyperscalers' public cloud offerings. In addition, Scaleway is committed to involving Airbus in the definition of its future product roadmap." "The objective is to host Airbus's most critical applications (those required for the Minimum Viable Company). This represents 900 applications and we will start with 70 of them today hosted on AWS." Applications being sent to Scaleway include ERP, manufacturing execution systems, CRM, and product lifecycle management. Finding a cloud provider to host its most sensitive applications for defense and industrial workloads was not a certainty when the process began, Airbus told us last year, because European cloud providers do not have the scale of their US rivals. Jestin said Airbus will continue to work with AWS. Skywise, a platform that aggregates and analyzes aviation data, and Case Management Assistant for customers' technical queries will continue to be hosted by AWS. In a statement, she said: "By integrating a trusted, high performance, cloud environment that keeps our critical data assets shielded from foreign extraterritorial laws, we are ensuring that our digital infrastructure keeps pace with our aerospace innovation, while maintaining control and resilience of our industrial operations."


    Read more of this story at Slashdot.


  • Tesla Robotaxis Go To Florida
    Tesla says it is launching its Robotaxi service in Orlando and Tampa, though it has not shared fleet sizes or whether customers can immediately hail rides. The Verge notes the announcement lands on Tesla earnings day and comes as the company's robotaxi rollout remains far smaller than Elon Musk previously projected, with tracker data showing only a small number of unsupervised vehicles operating in existing cities. From the report: [B]ack in May, Tesla had five unsupervised robotaxis in Dallas, six in Houston, and 29 in Austin. As of today, there are only 17 unsupervised vehicles in Austin, four in Dallas, and zero in Houston, according to the Robotaxi Tracker. By comparison, Waymo is estimated to have over 3,500 fully driverless vehicles in operation across over 10 cities. Like Waymo, Tesla typically introduces robotaxis to a new city with a safety driver behind the wheel. Unlike Waymo, sometimes Tesla moves that person over to the passenger seat with access to a kill switch should anything go wrong. The company has been inconsistent in how it rolls out its robotaxis to new markets. The numbers go up and down, with zero explanation from the company as to why. [...] By adding new cities, Tesla is clearly trying to sell investors on the idea that its robotaxi project is growing. But the fluctuating fleet size, inconsistency in supervised vs unsupervised vehicles, and long wait times tell a very different story.


    Read more of this story at Slashdot.


www.theregister.com - Articles



  • Google Cloud is killing it
    It's Alphabet's fastest-growing business and now makes up more than a fifth of the juggernaut's revenue and operating profit

















































Polish Linux

  • Security: Why Linux Is Better Than Windows Or Mac OS
    Linux is a free and open source operating system that was released in 1991 developed and released by Linus Torvalds. Since its release it has reached a user base that is greatly widespread worldwide. Linux users swear by the reliability and freedom that this operating system offers, especially when compared to its counterparts, windows and [0]


  • Essential Software That Are Not Available On Linux OS
    An operating system is essentially the most important component in a computer. It manages the different hardware and software components of a computer in the most effective way. There are different types of operating system and everything comes with their own set of programs and software. You cannot expect a Linux program to have all [0]


  • Things You Never Knew About Your Operating System
    The advent of computers has brought about a revolution in our daily life. From computers that were so huge to fit in a room, we have come a very long way to desktops and even palmtops. These machines have become our virtual lockers, and a life without these network machines have become unimaginable. Sending mails, [0]


  • How To Fully Optimize Your Operating System
    Computers and systems are tricky and complicated. If you lack a thorough knowledge or even basic knowledge of computers, you will often find yourself in a bind. You must understand that something as complicated as a computer requires constant care and constant cleaning up of junk files. Unless you put in the time to configure [0]


  • The Top Problems With Major Operating Systems
    There is no such system which does not give you any problems. Even if the system and the operating system of your system is easy to understand, there will be some times when certain problems will arise. Most of these problems are easy to handle and easy to get rid of. But you must be [0]


  • 8 Benefits Of Linux OS
    Linux is a small and a fast-growing operating system. However, we can’t term it as software yet. As discussed in the article about what can a Linux OS do Linux is a kernel. Now, kernels are used for software and programs. These kernels are used by the computer and can be used with various third-party software [0]


  • Things Linux OS Can Do That Other OS Cant
    What Is Linux OS?  Linux, similar to U-bix is an operating system which can be used for various computers, hand held devices, embedded devices, etc. The reason why Linux operated system is preferred by many, is because it is easy to use and re-use. Linux based operating system is technically not an Operating System. Operating [0]


  • Packagekit Interview
    Packagekit aims to make the management of applications in the Linux and GNU systems. The main objective to remove the pains it takes to create a system. Along with this in an interview, Richard Hughes, the developer of Packagekit said that he aims to make the Linux systems just as powerful as the Windows or [0]


  • What’s New in Ubuntu?
    What Is Ubuntu? Ubuntu is open source software. It is useful for Linux based computers. The software is marketed by the Canonical Ltd., Ubuntu community. Ubuntu was first released in late October in 2004. The Ubuntu program uses Java, Python, C, C++ and C# programming languages. What Is New? The version 17.04 is now available here [0]


  • Ext3 Reiserfs Xfs In Windows With Regards To Colinux
    The problem with Windows is that there are various limitations to the computer and there is only so much you can do with it. You can access the Ext3 Reiserfs Xfs by using the coLinux tool. Download the tool from the  official site or from the  sourceforge site. Edit the connection to “TAP Win32 Adapter [0]


OSnews

  • COSMIC DE’s first seven months
    Honestly, it feels like only yesterday that System76, Linux OEM and the company behind pop!_OS, announced it was going to develop its own desktop environment, COSMIC. Were about seven months into the more general availability of COSMIC, and the company has put up a nice overview of the various improvements that have already made their way into the code since then. Of course, theres a ton of visual improvements have been made to COSMIC, as well as a slew of new features: improved search, a brand new system monitor, drag and drop for tabs throughout COSMIC, and much more. COSMICs file manager and terminal have also seen a lot of work, with a ton of new small features and additions to bring them up to par with what people expect form a modern file manager and terminal emulator. Theres a ton more listed in the article, so it serves as a nice while you were away! if youve not been following development.


  • Codebergs programmer user base overwhelmingly votes to ban slopcoded projects from its platform
    What happens when programmers get to vote on a complete ban on slopcoded software on their code platform? Members of Codeberg were asked to vote on a proposal to completely ban slopcoded projects from Codeberg, and in what should not be a surprising outcome to anyone not overcome with AI! hysteria, the vast majority voted in favour of the complete ban: over 70% of Codeberg members voted to ban slopcoded projects entirely (358 in favour, 144 against, 14 abstentions). Of course, this is not a surprising outcome. Stripped down, programming is a form of artistic expression, and programming is no different than writing, painting, composing, or any other artistic endeavour. I think its safe to say writers, painters, composers, and similar creatives are against AI!, so its only natural programmers feel the same; poll after poll shows the overwhelming majority of respondents  usually well over 70-80%  are against AI!. The pro- AI! accounts on OSNews often try to paint my anti- AI! position as extremist, but in reality, Im just voicing how 70-80% of people clearly state they feel. I have zero skin in this game, zero outside pressure to please any bosses to get that promotion, zero pressure to conform to avoid getting laid off, zero pressure to not contradict upper-management. I can speak freely, openly, and without fear of retaliation. And as Nikhil Suresh explains in his harrowing from-the-trenches article AI Mania Is Eviscerating Global Decision-Making, thats a massive asset. The vast majority of people  including your friends, family, and co-workers  really hate AI!. You can either accept this, or be left behind.


  • Building an AmigaOS Development Environment in 2026
    If you want to develop an application for AmigaOS 3.x but dont want to deal with real hardware, virtualisation and emulation are your friends. Apropos of nothing, I decided to set up an Amiga development environment. Since figuring things out wasnt straightforward, I wrote down instructions for Linux about how to compile the first program and run it in an emulator. Enjoy! ↫ Daniel Kochmański Its a great guide, easy to follow, and youll be up and running quickly. The emulator the guide uses  AmiBerry, a fork of WinUAE  contains slopcode, so you may want to consider alternatives. This doesnt change much for the guide though, as whatever tasks you need to do outside and inside AmigaOS itself remain unchanged.


  • Volkswagen blocks custom Android ROM users from VW application
    Drivers of cars from the Volkswagen Group using alternative Android versions like GrapheneOS, LineageOS, or /e/OS have been unable to use the VW app for some time. This means they can neither check their vehicles remaining range from their phone, schedule service appointments, nor control charging and air conditioning. The car manufacturer has made changes to the apps backend that only allow devices with Googles pre-installed Play Services. When asked by heise online, VW stated that affected users should not expect a timely reopening. “However, they are looking into it.” ↫ Andreas Floemer at Heise.de Clearly, this should be illegal. Then again, that has never stopped Volkswagen before.


  • Happy companies are all alike; every unhappy company is unhappy in its own way
    Sam Altman seems to be making OpenAI way more non-profit than before: Even as the AI bubble becomes a mainstream talking point on Wall Street, tech companies continue to peddle the fantasy that AI is poised to become an almost magical money-maker. Case in point, OpenAI wants you to believe that by 2030, it’ll be raking in $100 billion a year just from ads alone — even though it’s currently struggling to reach just $1 billion. ↫ Joe Wilkins at Futurism The US tech giants fueling this AI! bubble are trying to hide the true extent of their debt: Hidden debt at U.S. tech giants swelled eightfold in four years to an estimated $1.65 trillion as artificial intelligence investments ballooned, a Nikkei study shows, exceeding actual debt and making it tougher for investors to assess risk. The five companies hidden debt, which does not appear on balance sheets, totaled $1.65 trillion in the most recent quarter, exceeding the roughly $1.35 trillion in debt reflected on their balance sheets. The data includes some estimates. ↫ Kohei Yamada at Nikkei Asia The bubble is expanding to comical proportions: The American stock market is booming, thanks to artificial intelligence. Tech giants are borrowing billions to acquire AI talent, purchase chips and hardware, and construct data centers. And market watchers are starting to get worried. They see financiers bulldozing giant piles of money to private AI start-ups with no realistic path to profitability, tech companies reliant on other tech companies for revenue growth, and non-tech businesses without a lot to show for their AI investments. The value of AI-linked firms has climbed $27 trillion in the past three years—an astonishing amount, equivalent to 36 percent of the value of the entire U.S. stock market today. Although future earnings could justify those valuations, as Dominic Wilson and Vickie Chang of Goldman Sachs argued in a note to clients, the profit expectations require Panglossian optimism. No less an authority than Sam Altman is arguing that we are in an AI bubble. The International Monetary Fund is citing it as a significant risk to financial stability and warning about what might happen when it bursts: diminished investment, tighter credit, reduced consumption, disrupted trade flows. ↫ Annie Lowrey at The Atlantic Im not worried, though. I have it on good authority that AI! increases productivity by 10x, so surely, none of the above is a problem. Any day now, we will be inundated with waves of brand new, high-quality, valuable software. Any day now, existing software will increase in quality by 10x, leading to a huge surge in software sales. Any day now, productivity in factories will increase rapidly thanks to AI! freeing up workers time, driving prices down 10x, leaving consumers with 10x more money to spend. Any day now, everyone will be able to produce the next Citizen Kane or write the next Anna Karenina, causing an explosion in magnificent, timeless art that will have historians of the future marvel at our civilisations ingenuity and artistry. In the meantime, these companies can just ask their AI! how to become profitable. Should be table-stakes for a 10x force multiplier. Im not worried.


  • Regressive JPEGs
    One of the cool features of JPEG files is that theres the option to save low frequency components first. This means that a partially downloaded image will be displayed at low resolution instead of being cut off. ↫ maurycyz.com Oh I know where this is going0 Doing this, I can get Chrome to render around 90 frames before giving up. Other browsers like Firefox have more patience, but a 90 scan image seems to work almost everywhere. ↫ maurycyz.com Yes, you can abuse the mentioned feature to create a really odd type of video. Or animation? Well, it allows you to create something resembling a really low-resolution GIF. Useless, yes, but very novel.


  • Even Microsoft couldn’t make Windows 11 work well on 8GB of RAM!
    The Verge reviewed the latest Surface Laptop, which only comes with 8GB of RAM at a higher price than the previous 16GB model, and they conclude that Windows isnt really usable on 8GB of RAM. Whether thats true or not I do not know  I would assume it depends a lot on your usage  but this quote from the review I found quite peculiar: I was on a Microsoft Teams call (using the app, not a browser) when the host streamed a brief video, which made the whole laptop hang for several seconds. At the time, I had about 10 Chrome tabs open across two desktops, alongside Slack and Signal — not an obscene level of multitasking. ↫ Antonio G. Di Benedetto at The Verge Excuse me, but that is actually an obscene level of multitasking because every single one of those applications! is a complete Chrome browser. Just in the paragraph above, theres four individual complete Chrome browsers running, with little to no optimisation. Why would anyone be surprised this scenario strains a mere 8GB of RAM? This isnt merely a Windows problem; this is a programmers choosing suboptimal tooling × managers have no idea what theyre doing problem. If Teams, Slack, and Signal had been proper, native applications instead of websites running in terrible frameworks, Windows 11 would have handled this scenario just fine.


  • OpenBSD tests WPA3 support
    The NLnet Foundations NGI0 Commons Fund supported an effort to add WPA3 support to OpenBSD, and the works payed off. All drivers which support PMF can use WPA3, which are: iwm, iwx, and qwx. So far, I have tested this patch on iwx AX200 only. I will roll out this patch to more of my devices now. Help with testing is welcome. There are both userland and kernel changes involved. ↫ Stefan Sperling Only the second implementation of WPA3 will be supported, which requires some explanation: WPA3 has a complicated history. There are two versions of WPA3. The initially standardized version suffered from side-channel leaks found by Mathy Vanhoef and dubbed Dragonblood . A revised and fixed version has been standardized and is mandatory in the 6 GHz band as of Wifi 6e (11ax) and mandatory on all bands as of Wifi 7 (11be). ↫ Stefan Sperling Obviously, WPA3 is a very welcome addition to OpenBSD.


  • DOSBox ported to OpenVMS for Alpha
    Speaking of OpenVMS and Alpha  and we like speaking about OpenVMS and Alpha, dont we?  theres now a port of DOSBox that runs on the Alpha version venerable operating system. Astr0baby has published both binaries and source code for the port, as well as a lovely set of screenshots to show it off working.


  • LG monitors silently install software through Windows Update without user consent
    Well, this is new  but not at all unexpected considering the state of Windows and the wider technology industry. When you connect certain LG monitors to a Windows machine, Windows Update will pull in a bunch of adware promoting antivirus trash. Of course, all done without any consent, because Silicon Valley inherently does not understand nor respect consent. Windows Update first installed LG extension and software component packages. Windows Reliability Monitor showed that LG Monitor App Installer appeared one minute later. The installation did not display a consent prompt or require the user to approve the download. Gamers Nexus tested the application across 32 consecutive system boots. It displayed a McAfee promotion during 31 of them. On the remaining boot, it promoted one of LG’s own monitor utilities. The McAfee popup offered a 30-day trial that would convert into a paid subscription. ↫ WhyCry at VideoCardz Dont use Windows.


  • New Intel Itanium emulator boots Itanium version of Windows XP and 2003
    It was only a few weeks ago that we got a massively improved Alpha emulator, capable of running VMS, Windows 2000, and Tru64, including X11 support and a variety of other exciting features. Today, weve got another major emulation milestone (update: sadly, with AI! support, so odds are this will fizzle out. Bummer!). The emulation space is going crazy, after my previous post on Windows booting on DEC Alpha es40 emulator, there is now another huge breakthrough in the emulation of other non-x86 CPU emulation. Yufeng Gao with help from gdwnldsKSC (the man behind the updated es40-fork) has released version 0.1 of his Intel Itanium (IA-64) emulator that boots the Itanium version of Windows Server 2003 and Windows XP 64-bit. No OpenVMS or HP-UX yet and Linux/BSD also dont boot. But Windows is amazing already. ↫ Remy van Elst Much like Alpha hardware, Itanium hardware is quite hard to come by  especially Itanium workstations are a nightmare to find; I think Ive only ever seen one or two Itanium workstation come up for sale on eBay in recent years, and their rarity obviously commanded hefty prices. The sooner we are able to run Itanium version of operating systems comfortably in a virtualised environment the better. As long-time OSNews readers know, my heart beats for HP-UX, but the Itanium versions of Windows and VMS would be of more interest to most people, Im sure. Excellent news.


  • Follow the money, especially in open source
    Linus Torvalds, the creator of the Linux kernel and git, is employed by the Linux Foundation. This Foundation is a non-profit organisation dedicated to, as the name obviously implies, the promotion of Linux. The primary use of the funds it collects is to help fund the infrastructure and fellows, including Linus Torvalds, who help develop the Linux kernel!. The list of megacorporations donating most of the Foundations funds is long. The Linux Foundation has twelve platinum members, which donate $500000 per year, followed by twelve gold members, who donate $100000 per year. Below these two primary tiers lie the silver peasants, who each donate $5000-$25000 per year, based on number of employees. Looking at the list of twelve platinum members, I noticed something interesting. Of the twelve platinum companies, six are AI! companies or companies with massive investments in AI!: Google, Huawei, Facebook, Microsoft, Oracle, and IBM/Red Hat. Then theres Samsung Electronics, which is raking in stupendous amounts of money thanks to the AI! bubble. Additionally, one of the gold members is Anthropic, another major AI! company and makers of Claude!, the sloppiest of slopcoding tools. Many of these companies are unimaginably deep in the red when it comes to AI!, with very little indication theyre ever going to be able to recover any of it. The situation is particularly bad for Oracle and IBM/Red Hat. Oracles debt has been downgraded to one notch above junk status because of its AI! spending, while IBMs shares experienced the largest crash in its 115 year history only a few days ago. By the way, in the first half of 2025, AI-related capital expenditures contributed 1.1% to GDP growth, outpacing the U.S. consumer as an engine of expansion!. Fun fact: since most of The Netherlands is effectively a swamp, most of the countrys buildings are built on massive wooden or concrete poles (piles) hammered deep into the ground until they hit something more stable than mushy clay and wet sand. Otherwise, buildings in the country would simply sink into the ground. Every Dutch person who ever lived near a construction site has heard the rhythmic kathunk, kathunk, kathunk, all day long, as the massive piledriver machines spread their gospel. I guess something reminded me of this just now. Anyway, a large chunk of the funding the Linux Foundation, Linus Torvalds employer, receives is coming from increasingly desperate companies frantically trying to convince a populace deeply skeptical and often downright hostile towards AI! to spend money on AI! before the bubble bursts. For some reason, I thought this was interesting.


  • The Zilog Z80 has turned 50
    As of writing, the Zilog Z80 processor was officially launched 50 years ago, in July of 1976, less than 4 years after the last human had walked on the moon, decades closer to WWII than to the present day, roughly at a half way point between the Kennedy assassination and the fall of the Berlin wall, closer to the Korean war than to 9/11 which is itself an event that happened a quarter of a century ago. (Sorry…) The processor was extremely successful, being used in many 8 bit microcomputers, including early personal computers, home 8 hobby computers, as well as many embedded, industrial applications. Together with the 8080 8 8085 that it is binary compatible with, it contributed to creating a de facto hardware standard for 8 bit micros, allowing a de facto software standard of CP/M, and Microsoft BASIC. ↫ David Oberhollenzer The only device I actively remember using with a (sort-of) Z80 in it was the Game Boy, but most likely Ive used a ton more over the decades that I dont remember or simply was never ware of. I did a little surface-level digging, and there we are: the TI-83, one of Texas Instruments stupidly popular and eternally overpriced graphing calculators, release in 1996. I was part of the first wave of high school children in The Netherlands for whom a TI-83 graphing calculator was mandatory. During my high school years I used that thing extensively, for far more than just math class  I programmed applications for and on it, and played so many games on it. A friend and I even bought a communication cable so we could play competitive 1v1 Bomberman in class. Good times, made possible by the Z80.


  • OnePlus exits EU, US markets
    Rumours had been circulating for a while, but now its official: OnePlus is effectively retreating from the European and US markets. Today, our hearts are undoubtedly heavy and mixed with emotion. As part of the proactive global strategy adjustment, OnePlus has decided to conclude new product rollouts in Europe and North America. ↫ OnePlus statement Once OnePlus co-founder Carl Pei left the company (and founded Nothing), things have been feeling shaky for OnePlus, once the undisputed darling of the more technical part of the Android crowd. Their phones got more expensive, their minimalist, close-to-stock Android version got progressively worse, and they started lagging in updates, too. My OnePlus Watch 3, for instance, which was promised to get WearOS 6 at some point, but never got it  meanwhile, WearOS 7 has already been released. No, this news is not particularly surprising. Luckily, the company claims it will honour its warranty and update support obligations for existing products in Europe and the US, which is nice, but also something theyre legally obligated to do (at least in the EU). A snag here is that the only update path the company offers is to ColorOS, from its parent company Oppo, which many more traditional Android and OnePlus users certainly wont be happy about. Something is better than nothing, I suppose, and Ill reserve judgment until I see what ColorOS 17 will be like on my other OnePlus product, a OnePlus Pad 3. Its just one more victim of western markets (illegally) consolidating on Apple and Samsung (while a few Pixels rummaging in the margins).


  • GNOME OS team is working to alleviate some of the limitations of immutable, image-based Linux variants
    Theres a ton of interest in immutable, image-based versions of various Linux distributions, since they offer a number of benefits that make them a good fit for some users. Updates cant really go wrong, rollback is easy, application management through Flatpak is more in line with systems like Android and iOS  they may not be advantages sought by everyone, but they clearly are by some. Still, there are also a number of annoying limitations, most notably around testing nightly releases of Flatpaks, testing system components, and installing command-line tools. The team behind GNOME OS is addressing these issues. The first thing theyre working on in something theyve preliminarily call Test Center, which makes it much easier to install nightly releases of Flatpaks alongside their regular versions. This is something you can already do today, but the flow is cumbersome and not exactly user-friendly; with Test Center, developers will be able to share a direct link to install test releases. They intend to use this same Test Center for testing system components: Our idea here is to use the same “Test Center” app mentioned above for installing and managing experiments at the system level as well. Similar to Flatpak bundles generated in CI, we generate system extension images (sysext) for every merge request. You can install experiments from a sharing link, and they will apply as a sysext over your existing system. Because those images are non-destructive overlays, you can always go back to the original system. ↫ Jordan, Jonas, and Tobias The last and final issue is that of command-line tools, something Flatpak is simply not designed for. On this front, the GNOME OS team states they are working on a solution as well, but theyre not quite ready to go into much more detail at this point. Regardless, these are very welcome improvements.


  • Microsoft releases its weird 90s IRC client as open source
    Out of all the bloody things Microsoft could release as open source, they chose the worlds weirdest IRC client they shipped in the late 90s that nobody used or even remembered? What on earth is happening? Microsoft Comic Chat is a Microsoft-developed Internet Relay Chat (IRC) chat client released in 1996 that rendered conversations as automatically generated comic strips. Instead of plain text, users communicated through cartoon avatars with messages displayed in speech bubbles inside dynamically composed comic panels. The application used an expert system to determine character placement, gestures, facial expressions, balloon shape, and panel layout in real time. It shipped as part of Internet Explorer 3.0 and was later bundled with Windows 98 and MSN before being discontinued in the early 2000s. ↫ Comic Chats GitHub page Not only is the original source code now available on GitHub, theres also a modern, updated version that can make use of larger displays and higher resolutions. Theres a deliciously 90s website for it, too.


Linux Journal - The Original Magazine of the Linux Community

  • Firefox 153 Released with HDR Video, Smarter PDF Tools, Better Privacy, and New Linux Improvements
    by George Whittaker
    Mozilla has officially released Firefox 153, bringing another round of improvements to its open-source web browser. The latest version introduces new multimedia capabilities, enhanced PDF editing tools, stronger privacy protections, better support for modern web technologies, and several features aimed at improving the browsing experience across Linux, Windows, and macOS. Firefox 153 became available on the stable release channel on July 21, 2026.

    While this isn't a major redesign, Firefox 153 delivers a collection of practical updates that benefit both everyday users and web developers.
    HDR Video Playback Comes to Windows
    One of the headline features in Firefox 153 is support for High Dynamic Range (HDR) video playback on compatible Windows systems.

    Users with HDR-capable displays and Windows HDR enabled can now enjoy richer colors, improved contrast, and brighter highlights when watching supported online video content. Mozilla notes that certain laptop displays offering only "HDR video streaming" are not currently supported, and some HDR videos recorded on mobile phones may still have limitations.

    Although this feature is Windows-specific, it represents another step toward bringing Firefox in line with modern multimedia standards.
    PDF Editing Becomes Even More Powerful
    Mozilla continues expanding Firefox's built-in PDF editor, eliminating the need for third-party applications in many situations.

    Firefox 153 introduces the ability to:
    Merge multiple PDF documents Insert images as new PDF pages Continue using existing editing tools such as annotations, page organization, and text editing
    These additions make Firefox an even more capable document viewer and editor, especially for users who frequently work with PDF files.
    Stronger Privacy and Permission Controls
    Privacy remains one of Firefox's biggest selling points, and version 153 introduces several enhancements designed to give users more visibility and control over website permissions.

    New improvements include:
    A visual indicator when a website is actively accessing your location More restrictive default permissions for browser extensions accessing local files Local Area Network (LAN) restrictions enabled by default for all users
    These changes reduce unnecessary exposure of local resources while making it easier to understand what websites and extensions can access.
    Experimental JPEG XL Support
    Firefox 153 also adds experimental support for the JPEG XL image format, which many developers consider a promising successor to older image standards.

    JPEG XL offers several advantages, including:
    Go to Full Article


  • NanoKVM-Go Brings AI-Powered Hardware Control to Linux with a Compact USB-C KVM
    by George Whittaker
    Sipeed has introduced NanoKVM-Go, a compact USB-C KVM-over-IP device that combines remote hardware management with AI integration. Designed for Linux, Windows, macOS, and other USB-C devices, NanoKVM-Go allows users to remotely view and control a system through a web browser while exposing its keyboard, mouse, and display functions to AI agents via the Model Context Protocol (MCP).

    Unlike traditional KVM-over-IP solutions that require multiple cables and dedicated networking hardware, NanoKVM-Go simplifies the setup into a single USB-C connection, making remote administration and AI-assisted automation more accessible for developers, system administrators, and homelab enthusiasts.
    A Portable USB-C KVM
    NanoKVM-Go is roughly the size of a smartwatch, measuring about 45 × 40 × 15 mm, yet it combines several functions into a single device.

    Key hardware features include:
    USB-C connection for video, audio, keyboard, mouse, and power Wi-Fi 6 connectivity Browser-based remote management Support for virtual USB storage Built-in Tailscale integration for secure remote access Fanless aluminum enclosure with low power consumption
    Because it connects over USB-C using DisplayPort Alt Mode, the device can manage a wide variety of hardware without requiring software installation on the target system.
    Designed for Linux and Beyond
    NanoKVM-Go supports numerous USB-C devices, including:
    Linux desktops and laptops Windows PCs macOS systems Mini PCs Steam Deck Android devices with DisplayPort Alt Mode iPhone 15 and newer models Tablets supporting USB-C video output
    For Linux users, this provides an easy way to perform BIOS configuration, operating system installation, kernel debugging, or remote troubleshooting—even when the operating system is unavailable.
    AI Integration Through MCP
    One of NanoKVM-Go's defining features is its AI-native design.

    Rather than simply streaming a desktop remotely, the device exposes its KVM functions as an MCP (Model Context Protocol) server, allowing compatible AI agents to interact with the connected computer using hardware-level keyboard and mouse input.

    This enables AI systems to:
    View the screen Move the mouse Type on the keyboard Launch applications Navigate user interfaces Complete repetitive desktop workflows
    Because control happens at the hardware level, AI agents can interact with systems regardless of the operating system installed.
    Go to Full Article


  • AI Uncovers a 15-Year-Old Linux Kernel Root Vulnerability Hidden Since 2011
    by George Whittaker
    Artificial intelligence has helped uncover one of the most significant Linux kernel security flaws in recent years. Security researchers at Nebula Security announced the discovery of GhostLock (CVE-2026-43499), a critical local privilege escalation vulnerability that remained hidden in the Linux kernel for approximately 15 years before being identified by the company's AI-powered vulnerability research platform, VEGA.

    The vulnerability affects Linux kernels dating back to version 2.6.39 (2011) and allows an unprivileged local user to obtain full root privileges on vulnerable systems. Its discovery not only highlights the importance of timely kernel updates but also demonstrates how AI is beginning to transform vulnerability research.
    What Is GhostLock?
    GhostLock is a use-after-free (UAF) vulnerability located in the Linux kernel's futex (fast userspace mutex) implementation.

    Futexes are synchronization primitives that allow user-space applications to efficiently coordinate access to shared resources while minimizing expensive kernel interactions. Because they are widely used throughout Linux, any flaw within this subsystem can have broad security implications.

    According to Nebula Security, incorrect handling of the remove_waiter() function can leave behind a dangling kernel pointer that an attacker can manipulate to execute arbitrary code with kernel privileges.
    A Reliable Path to Root Access
    One of the reasons GhostLock has attracted so much attention is the reported reliability of the exploit.

    Researchers demonstrated that an attacker with nothing more than a standard local user account can escalate privileges to root in roughly five seconds, with a reported success rate of 97% on vulnerable systems.

    Unlike many kernel exploits that are unstable or require highly specific system configurations, GhostLock appears to be both practical and repeatable, making it particularly concerning for administrators.
    Container Escapes Are Also Possible
    The implications extend beyond traditional Linux desktops and servers.

    Researchers report that GhostLock can also be used to escape containers and compromise the underlying host operating system. Because containers share the host kernel, a successful privilege escalation inside a container can potentially grant root access to the host itself.

    This makes the vulnerability especially important for environments running:
    Go to Full Article


  • Azure Linux 4.0 Released: Microsoft Expands Its Enterprise Linux Platform Beyond the Cloud
    by George Whittaker
    Microsoft has officially unveiled Azure Linux 4.0, the latest version of its open-source Linux distribution designed for cloud infrastructure, enterprise workloads, and modern data centers. Formerly known as CBL-Mariner, Azure Linux has powered Microsoft's internal cloud services for years, but version 4.0 marks its biggest evolution yet by becoming a general-purpose server operating system that organizations can deploy both inside and outside Azure.

    The release introduces updated core components, expanded hardware support, a predictable long-term lifecycle, and improved compatibility for enterprise environments, reinforcing Microsoft's growing investment in the Linux ecosystem.
    A New Chapter for Azure Linux
    Azure Linux began as Microsoft's internal operating system for Azure services, containers, and cloud infrastructure. Over time, it evolved into the foundation for many Azure-hosted workloads.

    With Azure Linux 4.0, Microsoft is positioning the distribution as a broader enterprise Linux platform rather than one limited to Azure infrastructure. The operating system is now available through Azure virtual machine images, container images, and downloadable ISO files for testing and deployment in a wider range of environments.
    Built for Enterprise and Cloud Workloads
    Unlike desktop-focused Linux distributions, Azure Linux is optimized for infrastructure, virtualization, containers, and cloud-native applications.

    Typical deployment scenarios include:
    Cloud virtual machines Kubernetes clusters Container hosts AI infrastructure Edge computing Enterprise servers
    Microsoft has designed the distribution to provide a consistent operating system foundation across Azure services while remaining suitable for on-premises deployments.
    Updated Core Components
    Azure Linux 4.0 modernizes much of the operating system's software stack.

    Highlights include:
    Linux Kernel 7.0 glibc 2.42 OpenSSL 3.5 Python 3.13 OpenSSH 10 dnf5 as the default package manager
    These updates improve hardware compatibility, application support, security, and overall system performance while providing developers with a more current software platform.
    Security Remains a Primary Focus
    Security continues to be one of Azure Linux's defining characteristics.

    Version 4.0 includes:
    Go to Full Article


  • KDE Plasma 6.7.1 Released with Stability Fixes, UI Improvements, and Better Wayland Reliability
    by George Whittaker
    The KDE Project has officially released KDE Plasma 6.7.1, the first maintenance update for the Plasma 6.7 desktop environment. Rather than introducing major new features, this point release focuses on polishing the desktop with a broad collection of bug fixes, translation updates, and performance improvements aimed at making Plasma 6.7 more reliable for everyday use.

    As with previous Plasma maintenance releases, KDE developers have concentrated on resolving issues reported by the community soon after the launch of Plasma 6.7, ensuring users receive a smoother and more stable desktop experience.
    A Maintenance Release Focused on Stability
    KDE Plasma 6.7 introduced numerous new capabilities, including per-display virtual desktops, Wayland session restore, improvements to Plasma Bigscreen, and a refreshed theming system. Plasma 6.7.1 builds on that foundation by addressing early regressions and fine-tuning the overall desktop experience.

    The update primarily delivers:
    Bug fixes across core Plasma components Updated translations Performance refinements Improved desktop reliability Better overall user experienceImprovements Across the Desktop
    Several of Plasma's core applications and components receive fixes in this release.

    Notable improvements include:
    Better reliability in the Kickoff Application Launcher Fixes for Discover, KDE's software manager Improvements to the KWin window manager Various panel and desktop behavior corrections Better handling of notifications and user interface elements
    While most of these changes are relatively small on their own, together they help eliminate many of the rough edges users may have encountered after upgrading to Plasma 6.7.
    Wayland Continues to Mature
    Wayland remains the primary development focus for KDE Plasma, and version 6.7.1 continues refining the experience.

    The update includes fixes affecting:
    Window management Session stability Input handling Display behavior General compositor reliability
    Over the past several Plasma releases, KDE developers have steadily shifted their attention toward making Wayland the best possible experience while continuing limited maintenance for X11.
    Translation Updates for Global Users
    Like most KDE maintenance releases, Plasma 6.7.1 incorporates a fresh batch of translation updates contributed by volunteers from around the world.

    These updates improve:
    Go to Full Article


  • PorteuX 2.6 Released with Linux 6.19, TLP Support, and Smarter Hardware Optimization
    by George Whittaker
    The PorteuX project has officially released PorteuX 2.6, bringing a new round of updates to the lightweight Slackware-based Linux distribution. Designed to be fast, portable, modular, and immutable, PorteuX continues to appeal to users who want a complete desktop operating system that can run efficiently from a USB drive or other removable media. The latest release introduces a newer Linux kernel, improved power management, updated desktop environments, and numerous performance and usability improvements.

    Released just two months after PorteuX 2.5, version 2.6 focuses on refining the user experience while maintaining the distribution's minimalist philosophy.
    Powered by Linux Kernel 6.19
    At the heart of PorteuX 2.6 is the Linux 6.19 kernel series, bringing improved hardware compatibility, updated drivers, security fixes, and better support for modern processors and peripherals.

    The updated kernel helps ensure smoother operation on both newer desktop hardware and laptops while continuing PorteuX's emphasis on speed and low resource usage.
    Better Battery Life with TLP Support
    One of the headline features in PorteuX 2.6 is support for TLP, the popular command-line utility used to optimize laptop battery life.

    Available through the PorteuX AppStore, TLP automatically adjusts various power-saving settings, including CPU behavior and device power management, helping extend battery life without requiring constant manual tuning.

    For laptop users, this addition makes PorteuX an even more attractive lightweight operating system.
    Automatic CPU Microcode Loading
    The release also introduces automatic loading of Intel and AMD CPU microcode when booting in non-fresh modes.

    Microcode updates help address processor bugs, improve stability, and deliver security fixes directly from CPU manufacturers. Automating this process reduces the need for manual configuration while ensuring supported systems benefit from the latest firmware improvements.
    Updated Desktop Environments
    PorteuX continues to offer multiple desktop editions, each updated to recent upstream releases.

    Version 2.6 includes:
    GNOME 49.4 KDE Plasma 6.5.5 Xfce 4.20 Cinnamon 6.6 LXQt 2.3 MATE 1.28.2 COSMIC 1.0.8 LXDE 0.11.1
    This broad selection allows users to choose between modern feature-rich desktops and extremely lightweight environments depending on their hardware and workflow.
    Performance Improvements Throughout the System
    Although PorteuX has always emphasized performance, version 2.6 introduces additional optimizations behind the scenes.

    Developers report improvements including:
    Go to Full Article


  • CachyOS June 2026 ISO Released with Hyprland Noctalia, Faster Performance, and Smarter System Tools
    by George Whittaker
    The CachyOS team has released the June 2026 ISO, delivering another feature-packed update for its Arch Linux-based distribution. Known for its aggressive performance optimizations and gaming-focused approach, CachyOS continues refining both the user experience and the underlying system with improvements ranging from compiler tuning to installer enhancements and new desktop options.

    As the project's fourth major ISO refresh of the year, the June release emphasizes speed, usability, and modern hardware support while remaining fully compatible with Arch Linux's rolling-release ecosystem.
    A New Hyprland Noctalia Desktop Experience
    One of the headline additions is a new Hyprland Noctalia desktop option available directly from the installer.

    Noctalia provides a polished, preconfigured Hyprland environment with a modern appearance, allowing users to enjoy a highly customizable Wayland compositor without spending hours configuring dotfiles after installation. The installer even includes a preview so users can see the desktop before selecting it.

    For users interested in lightweight, keyboard-driven workflows, this new option makes Hyprland much more approachable.
    Performance Optimizations Continue
    Performance remains the defining characteristic of CachyOS, and the June 2026 release introduces several additional optimizations.

    Notable improvements include:
    Python packages now built using extended Profile-Guided Optimization (PGO) A new GCC branch prediction tuning patch designed to improve performance on modern Intel and AMD processors A fix for an OpenBLAS regression affecting high-core-count CPUs Additional package-level optimizations throughout the distribution
    These updates continue CachyOS's philosophy of extracting as much performance as possible from modern hardware.
    Improved Package Management and Security
    The June release also includes several important changes to package management.

    One notable enhancement is network isolation for Pacman scriptlets and hooks, preventing installation scripts from accessing the network by default. This improves security during package installation and reduces the risk of unexpected behavior.

    Additionally:
    proton-cachyos has been renamed to proton-cachyos-native The installer no longer includes the paru AUR helper Users are now encouraged to use Shelly, available with both graphical and command-line interfacesInstaller Improvements
    The installation experience has received considerable attention in this release.

    Updates include:
    Go to Full Article


  • Git 2.55 Released with Faster Performance, Smarter Hooks, and Expanded Rust Integration
    by George Whittaker
    The Git project has officially released Git 2.55, bringing a wide range of improvements focused on performance, developer productivity, and modernizing the world's most widely used version control system. The release introduces smarter repository management, faster operations for large codebases, expanded hook capabilities, and continues Git's gradual adoption of Rust for improved reliability and maintainability.

    Although Git 2.55 doesn't radically change how developers use Git day to day, it delivers meaningful enhancements that make common workflows faster and more flexible—particularly for teams managing large repositories.
    Rust Support Is Now Enabled by Default
    One of the biggest architectural changes in Git 2.55 is that Rust support is now enabled by default when building Git from source.

    Developers compiling Git will automatically use Rust components unless they explicitly disable them using the new NO_RUST build option. This is part of the project's long-term effort to improve memory safety and gradually replace selected components with Rust implementations where appropriate. Git 3.0 is expected to make Rust support mandatory.

    For most users installing Git through their Linux distribution, this change happens behind the scenes and requires no additional configuration.
    Repository Performance Gets a Boost
    Git 2.55 includes several optimizations aimed at improving performance when working with large repositories.

    Among the improvements are:
    Faster bitmap generation during repository maintenance More efficient multi-pack repository handling Better pseudo-merge bitmap processing Reduced time spent creating optimized pack files
    These enhancements can dramatically reduce maintenance times for repositories containing millions of objects while also improving clone, fetch, and object traversal performance.

    Developers working on large enterprise projects or open-source codebases should notice faster background maintenance and repository operations.
    Config-Based Hooks Continue to Evolve
    Git continues improving one of its most requested features: configuration-based hooks.

    Instead of storing hook scripts only inside the .git/hooks directory for each repository, developers can now define hooks directly through Git configuration files. This makes it easier to:
    Share hook configurations Manage multiple hooks Standardize development workflows Reduce repository-specific setup
    Git 2.55 also expands support for hook execution behavior and continues laying the groundwork for more advanced hook management in future releases.
    Go to Full Article


  • Fedora Governance Changes Take Effect as Project Refines Leadership, Policy, and Contributor Oversight
    by George Whittaker
    A series of Fedora governance updates are now taking effect, marking another step in the project's ongoing effort to modernize decision-making processes, improve transparency, and better support Fedora's growing contributor community. The changes come as the Fedora Council and other leadership bodies continue refining how one of the Linux world's largest community-driven projects is managed.

    While these updates may not be as visible as a new desktop environment or kernel release, they play a critical role in shaping Fedora's future direction, community initiatives, and long-term sustainability.
    How Fedora Governance Works
    Fedora's governance structure is built around several key organizations that guide different aspects of the project.

    These include:
    The Fedora Council, which oversees strategic direction FESCo (Fedora Engineering Steering Committee), responsible for technical and engineering decisions Mindshare, which focuses on community outreach and contributor engagement Various Special Interest Groups (SIGs) and working groups that manage specific initiatives and technologies
    Together, these groups help coordinate thousands of contributors spread across the globe.
    Greater Focus on Strategic Planning
    Recent Fedora Council discussions have emphasized long-term planning and governance modernization. One major area of focus has been defining clearer processes for evaluating and managing new initiatives through what Fedora leaders call an Innovation Lifecycle framework.

    The proposed framework aims to:
    Better evaluate experimental projects Establish clearer entry and review phases Define expectations for community initiatives Improve oversight as projects mature
    The goal is to create a more predictable path for new ideas while maintaining Fedora's culture of innovation.
    Refining Contributor Representation
    Another governance topic receiving significant attention involves contributor participation and voting eligibility.

    Fedora leadership has been examining questions such as:
    What defines an active contributor? How should voting rights be determined? How can elections remain fair while staying inclusive? How should dormant accounts be handled?
    These discussions stem from concerns that existing systems may not always accurately reflect current contributor activity.

    While no single solution has been finalized, governance bodies are actively working toward policies that balance openness with accountability.
    Go to Full Article


  • The Growth of Vulnerability Management: The Rise of Agentic AI Pentesting
    by Malana VanTyler
    Cybersecurity shifts fast. Manual penetration tests remain valuable, especially for nuanced attack paths and business-logic issues, but they are expensive, point-in-time, and difficult to run continuously. By the time a report is delivered, the environment may have already changed. Automated scanners improved coverage and frequency, but most still rely on known signatures, templated checks, and shallow validation. They can find obvious issues, but they rarely match the adaptive reasoning, chaining, and persistence of a skilled attacker.Platforms like XBOW help security teams move toward continuous validation by running AI-driven tests that mimic large-scale human attackers. This shift moves the focus from periodic assessment and reactive patching toward ongoing exposure management and earlier prevention.
    From Automation to Agency
    To appreciate the value of these modern platforms, it’s important to separate traditional automation from what is called “agentic” AI. Earlier AI pentesting tools mostly worked like advanced “if-then” systems, running preset scripts and looking for known patterns. While useful to automate some tasks pentesters perform, these tools lack the ability to pivot.

    If a standard tool hits a non-standard login portal, it generally stops. An agent platform, however, can identify and adapt to the obstacle, reason through potential bypasses, and attempt alternative tactics.

    This core differentiator is the “agent,” a specialized model capable of goal-oriented planning. These platforms employ real-time attack path analysis tools. They identify a low-severity vulnerability and assess whether it could be exploited to gain access

    to a high-value asset. This approach imitates how an advanced attacker moves laterally within a system. The result is a clearer and more realistic view of the organization’s real risk compared to just listing bugs in a spreadsheet without context.
    Comparing Methodologies: Strategy and Execution
    When comparing platforms in this area, the industry is shifting focus from just ticking off features to demonstrating how effectively those features can be used. Modern platforms, including XBOW, focus on high-fidelity testing that avoids disrupting production environments while still proving that a vulnerability is reachable.

    Three main architectural approaches have emerged as standouts:
    Go to Full Article


Page last modified on November 02, 2011, at 10:01 PM