|
1825 Monetary Lane Suite #104 Carrollton, TX
Do a presentation at NTLUG.
What is the Linux Installation Project?
Real companies using Linux!
Not just for business anymore.
Providing ready to run platforms on Linux
|
Show Descriptions... (Show All)
(Two Column)

- F-Droid 2.0: A new chapter for Android freedom
The F-Droid project has announcedthe release of F-Droid 2.0, which is a complete redesign of the officialapp. Notable changes in the release include making it easier to discover andinstall applications, more useful app categories, improved search, andmuch more.
For more than a decade, F-Droid has helped people discover and install freeand open source Android apps. F-Droid 2.0 builds on that foundation with amodern interface, better app discovery, improved search, and a simplerexperience that works well, whether you're new to F-Droid or have been using itfor years.
This isn't just a visual refresh. The user experience was redesigned tointegrate smoothly with current Android patterns, like Material Design, whilekeeping familiar F-Droid interactions in place. Key components were reworked andrewritten using Kotlin Compose, the standard toolkit these days, creating afoundation that will help us deliver improvements more quickly in the yearsahead.
- Research into file-notification attacks on Linux
Sudheendra Raghav Neela, a member of a group of researchers from Graz University of Technology, has announced therelease of research into file-notification attacks that would allow spying onuser activity on Android, Linux, macOS, and Windows. The group has published a paper withdetails on the research as well as a web sitewith demonstrations of the vulnerabilities.
On Linux, an attacker can use inotifywatch tomonitor a directory to conduct an inter-keystroke timing attack—even ifthey do not have read access to the files within a directory. The group alsodiscovered a method to conduct a UI-redressattack (or "clickjacking" attack) onKDE 5 and KDE 6 by monitoring /usr/bin/pkexec to detect when Polkit spawns an authenticationprompt. An attacker could draw a fake password window on top of the real windowto collect a user's credentials.
Both of these flaws are still present today,though the Linux kernel did partially mitigate the issue with afix that was included in the 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.65,and 6.18.3 kernels shipped in January. See the web site for more information anda mitigation to prevent password-prompt windows from losing focus.
- [$] Listening to the radio with Rust
Many of the transmissions sent over the radio spectrum canbe decoded with a relatively cheap hardware dongle. Thomas Eckert presented atRustConf 2026 in Montreal about his hobby:decoding radio transmissions with Rust.In his presentation, hecovered all of the math necessary to get started withsoftware-defined radio,and gave demonstrations of listening to AM and FM radio, as well as decodingtransmissions fromaircraft transponders. His slides and example code areavailable on GitHub.
- The Kernel Report 2026 edition
After a two-year hiatus, LWN's Jonathan Corbet presented an updated editionof his KernelReport at the KernelRecipes conference. Corbet looked at what is happening in the kernelcommunity, how it's dealing with a period of accelerated change, and wherethings might go in the future. Video of the talk isavailable on YouTube for those who'd like to tune in.
- Security updates for Thursday
Security updates have been issued by AlmaLinux (buildah, containernetworking-plugins, firefox, kernel, kernel-rt, openexr, perl-DBI, podman, postgresql, postgresql16, postgresql:15, runc, skopeo, and tar), Debian (libdatetime-timezone-perl, tzdata, xdg-dbus-proxy, and znc), Fedora (chromium, evolution, evolution-data-server, evolution-ews, kernel, libheif, mingw-pcre2, nginx-mod-modsecurity, unbound, and webkitgtk), Mageia (borgbackup, coreutils, firefox, nss, kbd, libnfs, libwebsockets, perl-URI, pipewire, and xdg-dbus-proxy), Oracle (apr-util, containernetworking-plugins, coreutils, curl, firefox, freerdp, gstreamer1-plugins-base, host-metering, libarchive, libtiff, libxml2, openexr, openssh, perl-DBI, podman, postgresql16, postgresql18-postgis, postgresql:15, rsyslog, runc, tar, and unbound), SUSE (apptainer, gimp, librepods, libX11-6, perl-Authen-SASL, podofo, python-WebOb, and python313-graphifyy), and Ubuntu (imagemagick, libgit2, moodle, network-manager, Open-iSNS, python-urllib3, sqlparse, and xdg-desktop-portal).
- [$] Ideas on modernizing the open-source desktop
Scott Jenson has been working on user interfaces (UIs) and user experience (UX)for many years at Apple, Google, and other companies. Now, he's trying to convinceopen-source projects to experiment more and drive the desktop beyond the age-old "windows, icons, menus,pointer" (WIMP) model. At Akademy 2026, KDE's annual developerconference, he shared his complaints and ideas in a talk aimedat convincing those in attendance to take the lead on desktop design.
- Systemd v262 released
Systemd v262 has been released. Some of the notable new features include theability to build systemd as a single statically linked binary for smallcontainers, support for the kernel coredump socket protocol introduced withLinux 6.17, addition of OpenSSL 4 support, and many other changes. Seethe releasenotes for a full list of changes.
- Critical security vulnerabilities in the Radicle network protocol
The Radicle peer-to-peercode-collaboration project has disclosedtwo critical vulnerabilities in the network protocol used by Radiclenodes. The first flaw is that the network protocol used by Radicle "does notgive the confidentiality it was expected to give", which allows anyone whocan observe the network between two nodes to read the data exchanged. The secondis that peer authentication is broken and allows impersonation, so an attackercan spoof their Node ID and read private repositories they should not be able toread.
In practice, the two flaws are most useful when they can be exploitedtogether: an attacker on the path sees the Node IDs at both ends of aconnection, and both are normally on the allow-list. That attacker can readwhatever is exchanged while they watch, and can then use a Node ID they saw tofetch the whole repository on demand. The realistic threat is anyone on the pathbetween your node and node it syncs with, and no setting or allow-list protectsagainst them.
We are publishing this before the security update is available. You can acton it today, and no fix we release later can undo an exposure that has alreadyhappened.
See the post for workarounds that can be used today; a major update that willbe backward-incompatible is underway.
- Critical WordPress RCE vulnerability announced
A criticalvulnerability has been discovered in WordPress's get_page_template()function for page-template resolution that could allow remote-code execution(RCE) by an unauthenticated attacker, in some limited circumstances. The projecthas provided an update for the most recent branch of WordPress, as well asbackports of the fix for branches back to 4.7. See thevulnerability report for the conditions required for an RCE attack to be successful.
The vulnerability alsoaffects the ClassicPress fork ofWordPress, though a security update has not been provided for that projectyet. LWN covered ClassicPress in2024. Users of either content-management system should update soon.
- Security updates for Wednesday
Security updates have been issued by AlmaLinux (coreutils, postgresql18-postgis, and postgresql:16), Debian (memcached), Fedora (chromium, cyrus-imapd, dotnet10.0, dotnet8.0, dotnet9.0, freeipmi, kernel, libxmp, perl-Net-DNS, and postgresql16-anonymizer), Mageia (cpio, diffutils, perl-Dancer2, and rest), Oracle (389-ds-base and firefox), Red Hat (opentelemetry-collector and osbuild-composer), SUSE (amazon-cloudwatch-agent, amazon-ssm-agent, apko, apptainer, bazel-rules-python-source, bind, cups, firefox, freeipmi, gdb, google-osconfig-agent, kernel, kyverno, libipa_hbac-devel, libsoup, libsoup-3_0-0, libtpms, openssl-certs, perl-Authen-SASL, php-composer2, python313-PyMuPDF, thunderbird, and util-linux), and Ubuntu (gzip, linux-aws, linux-aws-5.15, linux-aws-fips, linux-nvidia-tegra-igx, linux-azure, linux-oracle, linux-azure-7.0, linux-azure-fde-6.8, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-oracle, linux-oracle-6.8, linux-raspi, openssh, and sudo).
- Security updates for Tuesday
Security updates have been issued by AlmaLinux (apr-util, corosync, curl, freerdp, gstreamer1-plugins-base, libarchive, libtiff, libxml2, openexr, openssh, rsyslog, sudo, tomcat, unbound, webkit2gtk3, yggdrasil, and yggdrasil-worker-package-manager), Debian (chromium), Fedora (alsa-plugins, amarok, aqualung, atomes, attract-mode, audacious-plugins, audacity, baresip, blender, calibre, cantata, cef, chromaprint, chromium, digikam, doctl, dragon, ffmpeg, ffmpegthumbnailer, ffmpegthumbs, ffms2, fooyin, glaxnimate, goldendict-ng, gpac, gstreamer1-plugin-libav, guacamole-server, guvcview, haruna, hedgewars, icecat, janus, k3b, kdenlive, kf5-kfilemetadata, kf6-kfilemetadata, kpipewire, lazygal, lego, libcamera-apps, libheif, libopenshot, libopenshot-audio, libvncserver, localsearch, mat2, minidlna, mivisionx, mixxx, mlt, monado, mpd, mpv, mpv-mpris, neatvnc, notcurses, nv-codec-headers13.0, obs-studio, obs-studio-plugin-droidcam, obs-studio-plugin-pwvideo, obs-studio-plugin-vaapi, obs-studio-plugin-vkcapture, obs-studio-plugin-webkitgtk, olive, openal-soft, OpenBoard, opencv, openmw, opustags, os-autoinst, patool, Pencil2D, perl-HTML-FormHandler, pianobar, prometheus-podman-exporter, python-audioread, python-torchaudio, python-torchvision, qmmp, qmmp-plugin-pack, qmplay2, qt5-qtwebengine, qt6-qtmultimedia, qt6-qtwebengine, qtox, retroarch, rocdecode, rocdecode7.2, rsgain, siril, squeezelite, swayimg, tigervnc, timg, unpaper, vlc, vtk, waypipe, wf-recorder, wivrn, wxsvg, xine-lib, xmms2, xpra, xscreensaver, yle-dl, znc, and znc-clientbuffer), Mageia (nmap, pcre2, and vim), Oracle (curl, openssl-fips-provider, sudo, tomcat, webkit2gtk3, yggdrasil, and yggdrasil-worker-package-manager), Slackware (util-linux), SUSE (cadvisor, chromium, coredns, fake-gcs-server, freeciv, gh, glibc, google-guest-agent, google-osconfig-agent, hugo, kbd, kbfs, keybase-client, libheif, libpcap, mbedtls, pcre2, python-asteval, python-jwcrypto, python311, python313-ansi2html, shadowsocks-rust, sofia-sip, and trivy), and Ubuntu (clamav, expat, ghostscript, glib2.0, gst-plugins-base1.0, gst-plugins-good1.0, libsoup2.4, libsoup3, libssh2, libxml2, linux-azure-6.8, linux-azure-fde, linux-azure-fde, linux-azure-fde-7.0, linux-azure-fde, linux-intel-iotg, linux-kvm, linux-oracle, linux-xilinx-zynqmp, linux-gcp-6.8, linux-ibm, linux-xilinx, linux-ibm, linux-nvidia-bos, linux-raspi, memcached, openjdk-17, openjdk-21, openjdk-25, openjdk-8, openjdk-lts, rsyslog, and strongswan).
- Igalia celebrates "Twenty-Five Years Upstream"
The open-source consulting firm Igalia has put out anannouncement celebrating 25 years of working on upstream FOSS projectsfor its clients. The list of projects the company has worked on is rathereye-opening: WebKit, mobile-browser rendering (on Maemo, Moblin, MeeGo, andTizen), the Linux kernel (CPU and GPU scheduling), 3D graphics drivers, theOrca screen reader, GStreamer, and lots more. Beyond that, the company, which is aworker-owned cooperative, does its work in ways that benefit the communityas well as its clients:None of this is charity. Igalia is a consultancy, and most of the work above was paid for by someone with a product to ship: a device maker who needs the web to run well on their hardware, a platform that needs a feature its users keep asking for, a company whose roadmap depends on something deep in the stack working better than it does today. What they get from us is not a patch to carry forever. We do the work upstream, in the project itself, so it arrives in the next release and keeps working long after the contract ends. Our customers ship products built on code that nobody has to maintain alone, and everyone else gets the same code. That has been the arrangement from the start.
- Three new stable kernels
Greg Kroah-Hartman has released the 7.2.7,6.18.53, and 6.12.111 stable kernels. As is usual these days, they arequite large; also no surprise is that they provide many important fixesthroughout the kernel tree. Users of those kernels are advised to update.

- State-Isolated KVM Hypervisor Architecture on openSUSE Tumbleweed bare metal case (Assisted by Google AI)
Advantages of the YaST Installer -Extreme Customization During Setup: Unlike many rigid Linux installers that force you to accept default software or partitioning, YaST lets you modify virtually every parameter - including complicated BTRFS/XFS disk layout, provides builtin interlace for additional subvolumes decouple if it appears to be required, adding or removing specific software packages, desktop environments, and multimedia codecs before the installation even begins.
- Benchmarking Java Performance Of JDK 8 Through OpenJDK 27
With the recent release of Java/OpenJDK 27 I began some fresh benchmarks in not having looked at the OpenJDK Java performance in a few years. Carried away, I ended up re-testing all the major OpenJDK versions going back to the venerable JDK 8.
- wolfSSL adds post-quantum algorithms and AURIX TC4xx support alongside wolfIP
wolfSSL has detailed several embedded security updates covering deterministic networking, post-quantum cryptography and automotive hardware security. The updates include the wolfIP TCP/IP stack, NIST-validated post-quantum algorithms in wolfCrypt, native Falcon and FrodoKEM implementations, and wolfHSM support for Infineon’s AURIX TC4xx family. The networking portion centers on wolfIP, a lightweight TCP/IP stack designed for bare-metal and […]
- Distro of the Week: Muana Linux 25.3 MATE
For all its positives, Brazil doesn't quite stand out as a Linux hotbed. But hand it to Brazilians for trying . . . and often succeeding. This week's Distro of the Week is Brazil's Mauna Linux 25.3, which is based on Debian and does a good job upholding the nation's reputation in the Linuxsphere.
- Installing Fedora 45 on Stratis storage
The Anaconda installer in Fedora 45 will introduce a new option for storage configuration: Stratis, a modern solution for local storage management. Stratis isn’t a completely new technology, it uses existing tools and technologies like device mapper, LUKS, and XFS and integrates them into an easy to use package. The idea is to provide modern […]

- Five Police Officers Criminally Charged for Misusing Flock Cameras in Indianapolis
"Nationwide, at least 100 police department employees have been charged with or accused of misusing license-plate readers for unauthorized purposes," reports the Washington Post. They cite their past investigations "based on thousands of pages of police and court records," which found that "In many of these cases, officers used Flock's roadside cameras to track the location of romantic partners and exes." In fact, five Indianapolis police officers were just criminally charged Wednesday with fraud and misconduct. "One has also been charged with stalking," the police department said in a statement, noting that one office had already resigned, "while the four other officers have been suspended and recommended for termination. County prosecutor Ryan Mears admitted "A lot of this was initiated by The Washington Post." And the Post published a new investigation Wednesday:Using publicly available information, The Post found that...one of the officers charged Wednesday, appeared to have relied on Flock cameras to track vehicles used by his wife and two close personal acquaintances, searching the plates 3,759 times over a 10-month period — an average of about 12 lookups per day. At the time, Police Chief Tanya Terry said she suspended one officer while the department conducted an investigation into possible misuse and a systemwide audit of the city's 301-camera Flock system. That audit led to the discovery of more widespread abuse, [County prosecutor Ryan] Mears said Wednesday. Mears said the department's findings highlight the vast power Flock cameras give police officers and raise questions about whether the government should be doing more to prevent the misuse of that power. "Many of the proposed guardrails and the things that have been proposed would not have prevented the behaviors and actions we see here today," Mears said. "Does there need to be independent oversight? Does there need to be judicial oversight of the Flock camera system?" One of the Indianapolis officers, Schultz, an 18-year veteran of the police department, was accused of using Flock to track his ex-wife and women he met while on duty or out in public. He was charged with multiple counts of official misconduct as well as two counts of stalking. Schultz told one woman he was an FBI agent, according to prosecutors, and began texting her and showing up at places she frequented, including at her gym and at a school function with her daughter. Prosecutors said he arrived at her gym within an hour of her at least nine times between June 12 and Aug. 1 of this year... Another woman met Schultz after her car was stolen from a mall parking lot, and he began texting her flirty messages later that night. The two dated briefly, and Schultz later looked up where the woman went on dates with another man. Schultz searched the plates of a third woman 178 times and also frequently showed up where she was, including her gym, a Smoothie King and a Walmart earlier this month... A third officer, Binford, told investigators he had used the log-in credentials of another officer who had logged in to Binford's laptop during a field training exercise. Binford searched the plate of his ex-wife more than 1,000 times between April 2024 and April 2025. Indianapolis police had no regular practice of auditing officers' Flock searches until recently, [Police Chief] Terry said in an interview last month. The department's investigation into the tool's misuse has been "a learning process for us," she said at the time.
Read more of this story at Slashdot.
- OpenAI, Anthropic CEOs Urge UN Countries to Cooperate on AI Safety Standards
"The heads of major AI firms pleaded with the United Nations on Wednesday to save the world or at least its people — by somehow regulating the fast-expanding technology that they have been designing," writes the Associated Press."If managed poorly, I even believe AI could be a risk to humanity as a whole," said Dario Amodei, chief executive officer of Anthropic. And from his competitor Sam Altman, CEO of OpenAI, came this assessment: "We could lose control of the future to AI." Yoshua Bengio, who co-chairs the UN's International Independent Panel on AI, called this"a moment of global awakening" to possible threats, noting AI from top companies had behaved in unacceptably dangerous ways, against instructions, taking actions "that would be crimes if committed by a human". In his presentation, OpenAI's Sam Altman agreed the discussion about AI "feels different in recent weeks," even suggesting specific reforms:Altman: We need a mechanism for complementary national and international frontier AI standards, standards for measuring capabilities, assessing risks, determining whether safeguards are sufficient, and preserving meaningful human oversight as systems become more autonomous. We need common standards so countries can compare evidence, verify compliance, and have a shared language and understanding about what is happening. We need accurate and speedy incident reporting, classification reporting protocols, so the world can learn from failures before they become catastrophes. And we need secure channels among governments, critical infrastructure operators and technical experts, to share emerging vulnerabilities and new threats.... We will all be better off if we can agree on what good evidence, good safeguards, and good oversight look like on the global stage. Speaking next, Anthropic's Dario Amodei agreed that standard-setting was important, also calling for "common global standards for testing AI models for loss-of-control risks and misuse risks — and a notification system for AI incidents that are significant to global security." Reiterating his September 12th call for an industry-wide safety collaboration, Amodei pointed out that Anthropic committed to embedding external evaluators "similar to a food inspector" and recommended other companies do the same. "Some have already agreed to adopt this measure." Besides calling for global cooperation between governments to set international standards, Amodei also offered two other specific ideas:Amodei: We should begin with narrow agreements that every member can support, such as a ban on using AI to make biological weapons or permitting your AI technologies to be used to make biological weapons....We should build evaluation and verification systems that keep pace with AI development so that states can have visibility into frontier model capability and can verify each other's commitments. "No leader, no company, and no nation can manage this alone. We commit to working with governments in this room on this urgent work."
Read more of this story at Slashdot.
- Qualcomm Announces Snapdragon X2 Series Processors Will Support Linux
Snapdragon X2 Series processors feature a neural processing unit (NPU) delivering 80 trillion operations per second and allowing advanced AI features to run locally. And Snapdragon X2 Series "is expanding to Linux," Qualcomm announced today, calling it one of their most-requested capabilities:Qualcomm Technologies is a top contributor to Linux development at a kernel level, and now we're embracing support for Snapdragon X2 Series as a platform directly. We're upstreaming core drivers for Snapdragon X2 Series — including the Hexagon NPU and Adreno GPU — to open the door to developers and partners. We are starting with support for two operating systems based on Linux... - Debian: We're kicking off with Debian by the end of this year, one of the most influential Linux distributions and the foundation behind many of the distros people use every day. - Ubuntu: Qualcomm Technologies has partnered with Canonical to bring Ubuntu, the world's most widely used Linux distro, to the platform with Snapdragon X2 Series certification targeted for the first half of 2027. ...and this is just the beginning. Our partners HP, ASUS and HUMAIN are planning Linux support in the first of 2027, so that their devices deliver the incredible experience users expect with Snapdragon X2 Series in a new operating system. Qualcomm's developer blog called it "a significant step forward" in Qualcomm's commitment to a developer-first approach, and "to the open-source community." "For developers, the important part is simple: more core hardware features are being reviewed and merged, so that laptops with Linux on Snapdragon X2 Series will be easier to build, test, and debug..."The enablement work completed so far has been validated on a Debian 13-based ("Trixie") user space and a custom kernel, so developers should treat this as the current reference environment while support continues to mature... Linux support for laptops with Snapdragon X2 Series is rolling out in stages, starting with the core pieces developers need before they can do production-level work on their device... For developers who want to try it today, the call to action is straightforward: start with Snapdragon X2 Series hardware, review the latest recipes to build Qualcomm Linux Debian Images, build available upstream sources the Debian OS image and test the peripherals that matter to you, such as graphics, AI inference, device I/O, or basic application bring-up. Early testing helps identify the gaps that matter most before support becomes broader and ready for production-level workloads... You do not have to wait for everything to be fully finished before getting hands-on. If you are comfortable working from upstream sources you can start evaluating Snapdragon X2 hardware today... Check out the step-by-step instructions, including the full build flow and deployment guidance for Snapdragon X2 Series Linux software. Put simply, this effort is less about supporting specific Linux distributions and more about empowering the developers who make Linux available on new hardware. This Developer Preview targets distribution maintainers, toolchain developers, kernel contributors, and hardware enablement engineers. It provides the upstream building blocks, including kernel patches, drivers, and reference device trees, needed to enable Snapdragon X2 Series support in their own projects and distributions. For end users looking for a turnkey "install and go" experience, that will come later as distributions adopt what lands upstream. We're encouraging the community to build on this work and help shape what comes next. The blog post notes that in the initial enablement stage, "Qualcomm Linux supports systemd-boot as the Universal extensible firmware interface (UEFI) boot manager to load and boot the Linux kernel." Hands-on demos were given at the Snapdragon Summit in Maui of Linux running on Snapdragon X2 Series hardware, which the developer's blog calls "a practical look at what works today and where Snapdragon X2 Series Linux support is headed."
Read more of this story at Slashdot.
- Rogue OpenAI Agent Tried to Breach Government Site in May When Prompted for Simple Data-Retrieving Tasks
OpenAI's artificial intelligence "went rogue this year in at least four additional incidents," the New York Times reported Wednesday, "hacking and trying to break into government and university websites without being instructed to do so, according to researchers and government officials."The attacks took place in May and June, before OpenAI's technology breached the A.I. start-up Hugging Face in July and set off a global debate about A.I. safety. Unlike the Hugging Face attack and other incidents in which A.I. systems were told to complete cybersecurity tests that effectively invited the models to demonstrate their hacking skills, the new incidents occurred when A.I. systems were directed to perform relatively mundane data collection, researchers said. When OpenAI's systems struggled to gather data from websites, they resorted to hacking techniques to get the information. "Three of the incidents were identified by Transluce, a research lab focused on A.I. oversight, and all were confirmed by OpenAI," the article points out. That research lab even reports "an attempt on an Australian government public health website... the first reported instance of agents hacking a government," and which notably was done by the AI agents "while attempting mundane data retrieval tasks which were not cyber-related." (At the UN Wednesday Australian Prime Minister Anthony Albanese complained it took three months for OpenAI to then alert Australia's government about the breach, Bloomberg reports.) Also targeted were the University of New Mexico's digital library with exploits like SQL injection and path traversal, and Data USA with cross-site scripting and other exploits. All three incidents involved "a low number of probe payloads" with "no evidence of exploitation," according to the researchers, who released a dataset "containing tens of thousands of queries apparently made by autonomous AI agents leveraging a URL scanning service to avoid access restrictions."Records from urlquery.net show agents using the service since at least March 6, 2026, about two months before previously reported swarm activity. The first case, a March 6 attempt to retrieve Thai drug-enforcement statistics, shows an agent escalating as each approach failed: it first requested the data directly, then tried a service that converts web pages into text, and finally packed a custom program into a web address. The same technique shows up in thousands of agent requests recorded by urlquery.net starting in mid-April, targets many of the same data sources as the collusion.wiki swarm, and collapsed the same day the wiki activity did. We also report similar activity that occurred as recently as September 16... By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defenses to complete their tasks. "This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval," the researchers concluded. And they warn that the traffic they observed "goes back at least to March 6, 2026 and extends as recently as September 16, 2026, suggesting agents may still be exploiting these services to bypass restrictions."
Read more of this story at Slashdot.
- Cities Across US Oppose Trump FCC Plan to Preempt Local Broadband Rules
Ars Technica reports:Cities and counties around the U.S. are angry at the Trump administration over a proposal to override local rules that govern the deployment of wired broadband networks... The Federal Communications Commission [FCC] argues that too many local governments "excessively delay approvals and seek to extract exorbitant sums from providers, resulting in costs that render some deployments infeasible." The FCC plan is supported by broadband providers, but local governments told the FCC that it would override rules that protect public safety. Local governments say the plan is illegal and that the FCC should instead focus on how Internet providers thwart competition with permit-hoarding and other tactics that prevent competitors from deploying networks... They object to FCC plans to impose a 120-day deadline for processing permits and to proposed limits on fees and compensation that local governments can require from providers... Another filing submitted by the League of California Cities said the FCC has no authority to adopt the proposal. "Federal preemption of traditional state and local authority over public property, construction, public safety, permitting, and rights-of-way management should rest on clear congressional authorization," the filing said. "The commission should not infer broad preemptive authority where Congress did not expressly provide it...." A filing by Minnesota cities said the current FCC is making the same mistake it made during the first Trump administration, when its attempt to preempt state net neutrality laws was blocked in court... If the FCC finalizes its new preemption plan, city and state governments could sue and ask a court to rule that the agency exceeded its authority... Democratic Commissioner Anna Gomez approved the step of asking the public for input but signaled she would vote against the final proposal. "I am dubious about the commission's authority under Section 253 to use rulemaking to preempt states and localities when it comes to their management of rights of way and fees charged to providers," she said.
Read more of this story at Slashdot.
- Whatever Happened to the 150,000 Tons of Radioactive Waste Stored Under the Atlantic Ocean?
More than 200,000 barrels of low-level radioactive waste were stored on the floor of the Atlantic Ocean between 1949 and 1982, reports ScienceAlert. Whatever happened to those barrels?Scientists have descended to the wreckage in a crewed submersible to investigate — and found many of the barrels corroded and degraded, their contents spilling across the seafloor. Surprisingly, this isn't necessarily a subversion of the original plan... The International Atomic Energy Agency recommends that low-level waste be disposed of in robust containment in isolation for at least a few hundred years — but back in the mid-20th century, the recommendations were a little different. The contemporaneous guidelines recommended that containers needed to reach the seafloor intact and remain sealed only long enough for the short-lived radionuclides to decay. After that, the remaining waste was expected to slowly escape and disperse through the surrounding ocean. Not everything in the barrels would conveniently decay away, however. They contained a radioactive hodgepodge, including cesium-137, plutonium isotopes, and tritium, some of which can persist for thousands of years... [A] few years ago, nuclear engineer Patrick Chardon and marine geologist Javier Escartín of the French National Center for Scientific Research started to wonder what had become of the dumped waste. That question eventually became NODSSUM — Nuclear Ocean Dump Site Survey Monitoring — an interdisciplinary project bringing together nuclear physics, geology, oceanography, biology, and marine chemistry to find the barrels and investigate what, if anything, they were doing to the surrounding environment.... [T]he barrels also appeared to function as tiny oases on the otherwise sparsely populated sandy seafloor. Anemones had attached themselves to the barrels. Sponges, sea cucumbers, fish, and crustaceans lived around them, with crabs apparently particularly fond of the artificial shelters... Instruments aboard the ship detected significant signals of cobalt-60 and niobium-94, which the researchers could specifically link to the dumped waste... [Samples are now being analyzed] There is precedent, however, to suggest that even striking levels of radioactivity around a source don't necessarily spread very far. A recent study of the sunken Soviet submarine Komsomolets found radionuclide levels hundreds of thousands of times above background immediately around the leaking reactor — but those levels dropped sharply within just a few meters as the material dispersed through the seawater. The NODSSUM team similarly found that, despite the significant radioactive signals around the barrels, activity levels weren't high enough to pose major radiation-protection problems for the scientists handling the samples. [Their three-person submersible] Nautile and the instruments it carried showed no signs of contamination. The real achievement was mapping the exact location of the barrels. "None of this means the waste is harmless," the article concludes — but it also doesn't mean we're about to be overrun by radioactive crabs."
Read more of this story at Slashdot.
- Andreessen Horowitz Launches AI/Company-Building School As a College Alternative
TechCrunch quipped it was like if startup school Y Combinator and Peter Thiel's build-a-company-instead of-college Fellowship Program had a baby. Silicon Valley venture capital firm Andreessen Horowitz is investing $35 million to launch a private school in San Francisco "aimed at turning high school graduates into founders," writes the SF Standard. Or, as CBS News describes it, "One blue-chip Silicon Valley investor has a proposal for young people who are questioning whether to attend college — enroll in AI school instead...."Specifically, the academy will provide instruction geared to subjects such as designing AI systems, fundraising for startups, selling businesses and storytelling. Students won't take tests or be assigned homework but will instead focus on building real projects. Courses will be taught by tech entrepreneurs, with the academy naming OpenAI CEO Sam Altman as either an instructor or guest lecturer. From the SF Standard:"There will be no traditional grades, tests, or homework," said the announcement. Instead, students will be encouraged to "build" in SF and work with partners from Anthropic, OpenAI, Google, Meta, and other firms. They'll be encouraged to live in campus housing in San Francisco. "The #1 goal is to help students learn to build, which is the most important skill in the AI era," Gagan Biyani, chief executive of the academy, wrote on X. Biyani cofounded the ed-tech startup Udemy... The school is opening applications for a Founding Class Fellowship a one-year, tuition-free program for around 50 students... The academy said it will bring in notable Silicon Valley names, like OpenAI's Sam Altman, as guest speakers and faculty. Students in the founding class will receive about $50,000 worth of computing credit — the sought-after currency in Silicon Valley to run AI models — as well as a $5,000 travel and research budget. The school is receiving funding from tech executives, including Fidji Simo, formerly of OpenAI and Instacart; Garry Tan, CEO of Y Combinator; and Tobi Lütke, CEO of Shopify. "In the AI era, it's more important to come out with a portfolio of projects that you worked on and work experience than it is to have a diploma or certificate," Biyani told the San Francisco Chronicle:Biyani said the academy plans to grow its enrollment and open a two-year program, pending regulatory approval, starting in the fall of 2028. Tuition is expected to be on par with the cost of an elite private university... The academy raised $42 million in funding led by Andreessen Horowitz. The ten founding partners are Anduril, Anthropic, Coinbase, Google, Meta, Nvidia, OpenAI, Palantir, Replit and Stripe. A network of hundreds of instructors, hiring partners and guest speakers includes OpenAI co-founder Sam Altman, Nvidia CEO Jensen Huang, neuroscientist Andrew Huberman and Microsoft chairman and CEO Satya Nadella, according to the academy's website. The FAQ describes a typical week by saying "Most of your time is yours to build. Each week, you share your progress with peers and practitioners, get direct feedback, and decide where to take your work next." Q: Can I use AI to help with my application? A: Yes. Use AI the way you'd use it on any project: to move faster, test ideas, and get past a blank page.... "The best assignments now are problems so hard they cannot be solved without AI," Andreessen Horowitz argued on X.com. "The Academy courses follow the same logic and will be taught by world-class leaders... The next generation will not be taught the way the last one was. The Academy is built for that world, and it begins in San Francisco." Thanks to long-time Slashdot reader theodp for sharing the news.
Read more of this story at Slashdot.
- Bitcoin Surges to $86,455, an 8-Month High, After America's SEC Announces Tokenized Stock Experiment
August 15: $62,991 September 23: $86,456 Bitcoin shot up 37% over the last 39 days, reaching an eight-month high on Monday. "Bitcoin is back," declares Yahoo Finance:The token held near $86,000 on Tuesday after a stunning multisession rally... [Fundstrat head of digital assets Sean Farrell told Yahoo Finance on Monday] "I think the crypto winter is over, although that does not necessarily mean the path higher will be linear." For now, momentum is on crypto's side, with bitcoin jumping more than 5% on Friday and another 6% on Monday. "We believe crypto is in the early innings of a new bull market and we see few signs of overheating," Compass Point analyst Ed Engel wrote on Tuesday. The move looks "like a combination of renewed ETF demand and a large short squeeze," Nicolai Søndergaard, senior research analyst at Nansen, said as traders betting against bitcoin are forced to buy it back, adding further fuel to the rally. Bitcoin got bad news and then good news last week. After the U.S. Congress failed Thursday to pass a cryptocurrency 'Clarity Act', America's Securities and Exchange Commission instead announced a tokenized-stock experiment. It's a five-year "innovation exemption" that "creates a path for tokenized U.S. stocks to trade through automated market makers on public blockchain," according to CoinDesk. Yahoo Finance notes that Bitcoin and other altcoins surged after the announcement.
Read more of this story at Slashdot.
- Microsoft Helps Take Down Massive Automated, AI-Powered Phishing-as-a-Service Platform
Microsoft's security blog describes the fight against a new "AI-powered cybercrime platform" offering phishing-as-a-service, with AI-tailored lures and analyses of compromised inboxes (to identify high-value targets). The site compromised more than 12,000 inboxes in over 10,000 organizations around the world, compromising business accounts "at scale" with automated attacks and prebuilt phishing templates. AI tools could even sift through a victim's mailbox to help engineer better phishing messages. To disrupt EvilTokens Microsoft worked with other organizations, including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver Foundation, and TRM Labs to Health-ISAC (a non-profit helping health sector organizations share cyber threat information). "Fifty sites seized and 150 domains disabled in a single action is only possible when the hosting providers, the exchanges, the model providers and the data holders all move at the same time," security company SpyCloud told The Hacker News. From Microsoft's security blog:Microsoft also notified affected customers, helped remediate compromised accounts, and shared intelligence to support further defensive and investigative action... Microsoft worked closely with specialist officers from the Metropolitan Police Service's cybercrime team, sharing intelligence that enabled officers to take operational action in the United Kingdom. On September 11, 2026, officers arrested two men, aged 32 and 38, and seized digital devices and other items for examination... While EvilTokens used AI to identify targets and prioritize fraud opportunities, Microsoft investigators used reverse engineering and AI-powered tools to analyze evidence, accelerate the investigation, and identify the infrastructure supporting the service... Campaigns leveraging EvilTokens have impacted organizations in various industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with the highest concentrations of observed victim activity in the United States, Canada, the United Kingdom, Australia, India, and France. Working with partners, Microsoft's Digital Crimes Unit (DCU) facilitated a coordinated disruption of infrastructure used to operate the EvilTokens service. Sometimes stolen tokens were used to give new devices access to a victim's inbox. (A code authenticating the new device was sent to the targeted user, who unknowingly authorize the threat actor's session and grants access to their account...) But "AI was not simply helping attackers write more convincing messages," says another Microsoft blog post. "It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible."The significance of EvilTokens extends beyond its rapid growth and global reach. It offers an early warning of what happens when cybercriminals combine stolen access with AI capable of understanding how an organization works... Its AI tools could summarize and translate emails, surface financial conversations, map organizational roles, identify trusted relationships, and recommend potential targets. Preset prompts offered to find wire-transfer discussions, identify the organization's "money movers," locate vendor invoices, and determine the best people to impersonate. Sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service. Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface. Investigators found evidence that large portions of EvilTokens had been "vibe coded," with AI helping its creators build the platform itself. They also determined that EvilTokens drew on capabilities from multiple AI models. The result was more than a collection of attack tools. EvilTokens packaged much of the fraud process into a commercially run service, complete with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.
Read more of this story at Slashdot.
- Trump Denounces Attempts to Control AI, Wants It Renamed 'Super Intelligence' in US Documents
U.S. President Trump addressed the United Nations on Tuesday. And a half hour in, after decrying immigration, Trump pivoted to add that "The United States also totally rejects any attempt to construct a globalist scheme to control for the artificial intelligence being spoken of so much now." But then he added "hereinafter officially called super intelligence, changing the name, in that the use of the word artificial makes intelligence fake. It makes it sound fake, and it is not fake. It's actually... amazing. But we have to be careful — in fact, it is exactly the opposite of what it purports. From this point forward, all of United States documents and hopefully the world's will be changed to use the much more accurate term super as opposed to artificial. So it's super intelligence."TRUMP: In other words, welcome to the new world of super intelligence — SI. SI. Let's see if that goes. It sounds much better. It is much better, and it's much more accurate. Let's see if I have any power. Maybe I do and maybe I don't. We're going to find out pretty soon. Super intelligence. Every major new technology brings challenges, and super intelligence is no exception. Yet the very same people who said we'll all be dead in 12 years because of global warming, a name since reborn to climate change because the planet was cooling not warming, and nobody was dead — these are the same people that are now saying that AI is going to kill us all. That robots are going to attack us, and that everything is going to be a total disaster — same group of people. This is the group that came up with the Russia Russia Russia hoax, the Ukraine Ukraine Ukraine hoax. Climate change, open borders. Whoever wins AI — you have to remember this — and now I say, whoever wins SI, whoever wins super intelligent [sic] — wins. That's the group that wins. And we're leading now over China by a lot, and everyone else, and we're going to keep it that way. We're going to keep it very — very straight and very strong. I'm not going to stifle growth of something that will be bigger than the Industrial Revolution. Many say, bigger than the Industrial Revolution or the internet itself. And we will be very careful, and that's why we have a Department of Justice that we've already used it, having to do with this very subject, and used it very powerfully. Everything worked out very well and very quickly. And other law enforcement bodies that will rein things in if we have to do that. But we will only encourage super intelligence. We're gonna encourage it, not rein it in. We're gonna watch it closely, through the Department of Justice. The United States leads the world in Super Intelligence, and will continue to do so, safely and responsibly. Thanks to long-time Slashdot readerArchieBunker for suggesting the story.
Read more of this story at Slashdot.
- Are Students Suddenly Losing Interest in Computer Science as AI Coding Takes Off?
On academic mentoring platform Nova Learning, Computer Science and AI, "once the dominant choice among students... is losing ground fast, while Engineering has nearly doubled its share." It's a small survey, but "The steepest proportional decline is in Software & Data Science, the most traditional 'learn to code' pathway, which lost 44% of its 2025 share. AI saw the largest absolute drop of any single subject in the survey, down 6.2 points. "The category did not decline uniformly. Students moved away fastest from the pathway most associated with entry-level software work, while the more applied and human-facing subfields held their ground better." Slashdot reader BrianFagioli writes:Nova Learning says the share of surveyed middle and high school students naming Computer Science and AI as their primary academic interest fell from 42.3 percent in 2025 to 27.9 percent in 2026, while Engineering rose from 11.9 percent to 23 percent. The biggest gains came from Mechanical and Aerospace Engineering... [B]roader enrollment data points in the same direction. The National Student Clearinghouse Research Center reported declines in Computer and Information Science enrollment at four year institutions, even as Engineering grew. AI coding tools are not proven to be the cause, but as software development changes and AI handles more coding tasks, students may be starting to rethink what a future in technology should look like. [Undergraduate enrollment in CS programs at four-year institutions fell 8.1%, to approximately 606,000 students.]
Read more of this story at Slashdot.
- 'Coyote vs. Acme' Outgrosses All But 3 WB Movies This Year, Heads To Profit
The movie Coyote vs. Acme earned more than Warner Bros.' $30 million tax write-off in just two weeks. And last week the movie officially earned more than its production budget of $70 million. But today the movie passed the $100 million mark. "You asked for it, we delivered, and you showed up!" distributor Ketchup Entertainment posted on social media (adding "Thank you to the fans for making this a massive hit!") With a break-even number of $120 million, the movie "will probably make up any theatrical deficit (should there be any) with its impending releases on video on demand and streaming," writes ScreenRant. Almost three years after the completed film was initially shelved for a $30 million write-off, itscumulative domestic box office has apparently even beat Warner Bros. dinosaur movie The End of Oak Street:In addition to officially joining the chart of the Top 30 movies of the year so far at the domestic box office, by surpassing The End of Oak Street, Coyote vs. Acme has outgrossed five of the eight movies that Warner Bros. has put out in domestic theaters this year.... [It's just $17.6 million behind Supergirl, and within $30 million of Mortal Kombat II and Wuthering Heights.] Their anticipated sci-fi sequel Dune: Part Three also seems guaranteed to land higher than 2026's Coyote vs. Acme on the chart (2021's Dune earned $108.9 million in domestic theaters, while Dune: Part Two earned $282.1 million). With its a small marketing budget of just $10 million, the movie seems to be relying onoddball marketing stunts like their AMA on Reddit's r/movies. And commemorating the spirit of the movie, Crayon-maker Crayola even released a special "Coyote Secret Plan" web page for children to print and color — and partnered with the film's stars for a video on the importance of creativity: Lana Condor: Crayola is all about encouraging kids and grown-ups to turn imagination into action. Will Forte: Which is exactly what Coyote does in Coyote versus Acme. He sees a problem and thinks, "Could this be solved with a rocket, a catapult, or a suspiciously affordable mail order anvil?" Lana Condor: Usually no. Will Forte: Usually very no.
Read more of this story at Slashdot.
- Pentagon Investigators Say Overreliance on Palantir AI Contributed to US Strike That Killed 123 Iranian Children
Two U.S. missiles hit an elementary school in Iran, killing over 150 people including 123 children on the first day of the Iran War. But Gizmodo notes that a new Bloomberg investigation cites U.S. officials involved in an unreleased internal Pentagon review who blame "a cascade of preventable failures that included an overreliance on an AI tool built by Palantir."According to the officials who spoke to Bloomberg, some personnel inside U.S. Central Command leaned too hard on the AI inside the Maven Smart System, an AI-powered data integration and targeting platform developed by Palantir to accelerate intelligence analysis and decision-making. The Defense Department has reportedly made the software tool a cornerstone of military operations over the past year... Officials said some users expected Maven to flag stale records or contradictions in the intelligence assembled for potential targets, though it is not clear why they thought the system would do that. The Minab [elementary school] site, which was cataloged as an Islamic Revolutionary Guard Corps facility due to outdated data, was fed into Maven with other candidates and came out as a recommended day-one target. Target-list work that once took hours was condensed into minutes. A Palantir spokesperson told Bloomberg the company "is not responsible for the underlying data nor identifying intelligence deficiencies" and that there is no evidence its software was at fault. Two people familiar with Palantir's Pentagon contracts said the government keeps primary responsibility for the quality of the information that's fed into Maven. After the strike, Palantir added features that "re-review underlying intelligence to identify factors that would disqualify a target and flag inconsistencies and inaccuracies that human review may have missed," a person familiar with the work said. That new functionality is said to have already caught some anomalies... More than 1,000 Iranian targets were hit in the first 24 hours, and according to Bloomberg's sources, that pace compressed the time available for additional confirmations. Staffing on civilian harm mitigation teams across the U.S. Department of Defense had also fallen by roughly 90% over recent years, shrinking to fewer than 20 people overall. The U.S. Central Command's group shrank from 10 people to one. No member of those teams reviewed the Minab site before the missiles were up in the air. A separate inquiry by the United Nations' Independent International Fact-Finding Mission on Iran this week reached the conclusion that there were reasonable grounds to believe the United States committed the war crime of launching an indiscriminate attack.
Read more of this story at Slashdot.
- Google Opens Preorders for Its $899 Gemini-Enhanced 'Googlebook' Laptops
Monday Google opened preorders for its "Googlebook" laptops, pricing them at $899. A Google's blog post added that "At launch, you can choose between Intel Core Ultra Series 3 and Snapdragon X Elite processors" (paired with NPUs to power AI features). "Devices will hit shelves on October 4 in the U.S. and on October 5 in Canada, the U.K., Ireland, France, Germany, and Australia," TechCrunch points out. But "the real pull for the new devices is that they'll prominently feature Gemini's latest capabilities in a new format: the laptop."Google is trying to offer a laptop with unique features like an AI-powered cursor, vibe-coded widgets, and support for AI-enhanced dictation. The latter is a feature called Rambler, which cleans up messy, rambling brain dumps into readable text. The move is a bet that AI, specifically Google's Gemini, could be enough of a draw to get people to buy a new laptop that bakes in AI instead of running them via desktop apps you install or access through the browser... On the Googlebook, Google is trying to reinvent the "point-and-click" experience of desktop computing to now include an AI element: The cursor serves as a conduit to Gemini. The company suggests various ways this could be used, like highlighting content on a web page for Gemini to work with, asking Gemini to see if an email you've hovered your cursor over is suspicious, or selecting images and then asking Gemini to visualize them together... What's more interesting about the Googlebook is how it's seemingly part of Google's longer-term plan to capture a large part of the K-12 market that currently relies on Chromebooks and push them toward the company's Gemini AI. There are somewhere around 50 million Chromebooks in schools, used by students and educators, Google has said. In May, the company told TechCrunch that its current Chromebooks would continue to be supported, though many would become eligible to transition to the new Googlebook experience in the future... Flagship devices in the new range are being built by Acer, ASUS, Dell, HP, and Lenovo, with materials like aluminum, magnesium alloy, and carbon fiber... Google says the device will offer up to 14 hours of battery life. Googlebooks will be decorated with an exterior Glowbar "which dances when you boot up, sweeps to show battery level, and supports other playful patterns," according to Google's blog post. "We're also opening Glowbar access to developers to build custom, interactive animations." After testing actual Googlebooks, The Verge's reviewer first acknowledges that "it might be just another Trojan horse for Gemini." Still, "The hardware is polished (since it's based on current laptops). The OS is familiar (if you've ever used a Chromebook). But most impressive, it integrates your Android phone with your PC so they feel more like one device. It's the culmination of a series of new ideas that blur the two devices together. "After my first look, I went from doubtful to excited by the prospect of Google pulling it all off..."The Asus was incredibly lightweight; the Lenovo has plenty of ports and an optional mouse with a matching Glowbar light; the Acer's convertible form factor allows some tablet-like use (and it's pretty affordable for a Panther Lake laptop). The HP had a great-looking screen and a latticeless keyboard I surprisingly didn't hate, and the Dell is basically a gold XPS 13 (which is excellent) but with a different chip... But everything really special about Googlebooks comes down to software... You can cast apps from an Android phone directly to a Googlebook, even without touching your phone. Googlebooks essentially have two app drawers: a G-logo start menu for installed Googlebook apps and a second one beside it that pulls up mobile apps from your phone. Click a phone app and you can fully use that app with the mouse and keyboard or the Googlebook's touchscreen. It's a bit like iPhone Mirroring on macOS, but the apps are individually extracted to the desktop OS instead of showing your whole phone interface. Googlebooks also have a nifty feature called Continue On where the icons of apps you're currently using on your phone appear in the bottom bar — allowing you to click it on the laptop and hand it off to the Googlebook. These app handoffs can transition to a native app or a web app, depending on how developers have programmed it... The other big way Googlebooks interact with an Android phone is Quick Access, allowing you to see and access all the files stored on your phone right in the desktop Files app... If you have an iPhone then you're limited to a Link to iOS app that just does some message syncing and replying... [W]hen it comes to mainline gaming, Nvidia's GeForce Now service is also coming to Googlebooks, and the first year is free with one of Google's new laptops. "It's not every day we get a new player in the desktop operating system and laptop spaces," the reviewer points out. "There seems to be a higher ceiling of potential with Googlebooks than there was with Chromebooks, along with some cool features, but Google has a lot to prove at higher prices than people are used to paying for its laptops."
Read more of this story at Slashdot.
- Meta's New 'Personal AI Agent' Muse Beats ChatGPT in Downloads - and Get Blocked by Amazon
Meta's AI "personal agent" Muse overtook ChatGPT as the #1 iOS free app in the U.S. on Friday, reports CNBC — and it's still showing more downloads as of Monday night. Muse now has over 2.5 million downloads since its debut less than two weeks ago, according to analytics firm Sensor Tower...[Muse] is currently ahead of popular services like OpenAI's ChatGPT, Polymarket and Kashi... It's also ahead of rival AI apps like Anthropic's Claude and SpaceXAI's Grok AI, in addition to the Facebook-parent's own Meta AI app... Meta pitched the app as a way for consumers to manage and direct supercharged digital assistants that can perform a number of tasks across the web, like filling out electronic forms and organizing email inboxes... "I think up to this point most of the agentic use cases have not really been for normal people," Bernstein analyst Stacy Rasgon told CNBC in a "Squawk on the Street" interview on Monday. "Now you've got Meta's Muse and other agents out there that are starting to maybe get more potential for more broad-based adoption." The buzz around Meta was also reflected in the stock, which surged more than 11% on Monday. Amazon is already blocking Muse, reports GeekWire. Amazon first tried to get Meta to voluntarily exclude Amazon, but they were unsuccessful:The problem, Amazon says, is that it never agreed to any of it. Meta didn't tell Amazon that Muse would access its store, the agent doesn't identify itself when it browses, and it appears to capture and store customer credentials, which the company says could create privacy and security risks. As of Sunday night, people trying to use Muse to shop on Amazon were seeing the popup, "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed..." Amazon has spent the past year trying to keep outside agents off its site, suing Perplexity over its Comet browser and moving to block shopping agents from Google and OpenAI. [Amazon won a preliminary injunction against Perplexity in March, the article poitns out, "then lost it on Aug. 4, when the Ninth Circuit ruled that the user — not the AI company — was the one accessing Amazon's computers under federal anti-hacking law. The court denied Amazon's petition for rehearing on Sept. 10."] On Sunday night, Amazon said it is in direct conversation with Meta about the issue. Asked whether it would consider taking legal action, the company declined to comment. The business stakes are high for Amazon. In addition to operating its flagship e-commerce site, Amazon generated more than $68 billion in ad revenue last year — a business that depends on people browsing its pages and seeing sponsored products. Muse also appears to scrape account data, reports CNBC. But Shopify, however, "is working with Meta on Muse access. Shopify CEO Tobias Lütke announced Monday that the e-commerce site was partnering with Muse to allow agentic checkout in its online stores."
Read more of this story at Slashdot.

- Security: Why Linux Is Better Than Windows Or Mac OS
Linux is a free and open source operating system that was released in 1991 developed and released by Linus Torvalds. Since its release it has reached a user base that is greatly widespread worldwide. Linux users swear by the reliability and freedom that this operating system offers, especially when compared to its counterparts, windows and [0]
- Essential Software That Are Not Available On Linux OS
An operating system is essentially the most important component in a computer. It manages the different hardware and software components of a computer in the most effective way. There are different types of operating system and everything comes with their own set of programs and software. You cannot expect a Linux program to have all [0]
- Things You Never Knew About Your Operating System
The advent of computers has brought about a revolution in our daily life. From computers that were so huge to fit in a room, we have come a very long way to desktops and even palmtops. These machines have become our virtual lockers, and a life without these network machines have become unimaginable. Sending mails, [0]
- How To Fully Optimize Your Operating System
Computers and systems are tricky and complicated. If you lack a thorough knowledge or even basic knowledge of computers, you will often find yourself in a bind. You must understand that something as complicated as a computer requires constant care and constant cleaning up of junk files. Unless you put in the time to configure [0]
- The Top Problems With Major Operating Systems
There is no such system which does not give you any problems. Even if the system and the operating system of your system is easy to understand, there will be some times when certain problems will arise. Most of these problems are easy to handle and easy to get rid of. But you must be [0]
- 8 Benefits Of Linux OS
Linux is a small and a fast-growing operating system. However, we can’t term it as software yet. As discussed in the article about what can a Linux OS do Linux is a kernel. Now, kernels are used for software and programs. These kernels are used by the computer and can be used with various third-party software [0]
- Things Linux OS Can Do That Other OS Cant
What Is Linux OS? Linux, similar to U-bix is an operating system which can be used for various computers, hand held devices, embedded devices, etc. The reason why Linux operated system is preferred by many, is because it is easy to use and re-use. Linux based operating system is technically not an Operating System. Operating [0]
- Packagekit Interview
Packagekit aims to make the management of applications in the Linux and GNU systems. The main objective to remove the pains it takes to create a system. Along with this in an interview, Richard Hughes, the developer of Packagekit said that he aims to make the Linux systems just as powerful as the Windows or [0]
- What’s New in Ubuntu?
What Is Ubuntu? Ubuntu is open source software. It is useful for Linux based computers. The software is marketed by the Canonical Ltd., Ubuntu community. Ubuntu was first released in late October in 2004. The Ubuntu program uses Java, Python, C, C++ and C# programming languages. What Is New? The version 17.04 is now available here [0]
- Ext3 Reiserfs Xfs In Windows With Regards To Colinux
The problem with Windows is that there are various limitations to the computer and there is only so much you can do with it. You can access the Ext3 Reiserfs Xfs by using the coLinux tool. Download the tool from the official site or from the sourceforge site. Edit the connection to “TAP Win32 Adapter [0]

- The state of scrollbars in Windows makes even longtime Microsoft engineers sad
Raymond Chen, longtime Microsoft employee and author of the very popular The Old New Thing blog, published an interesting post about the Win32 scrollbar. It turns out theres actually quite a few interesting shortcuts and useful hidden features, like clicking inside a scrollbar while holding down shift will make the content jump to that point. Halfway through the article, though, Chen laments how nobody really uses proper Win32 scrollbars anymore. Sadly, almost nobody uses Win32 scroll bars any more. Everybody uses frameworks that provide their own custom scroll bars. ↫ Raymond Chen And as you might expect, none of these scrollbars work like the Win32 one, making even something as basic as the scrollbar a fragmented mess. He doesnt just blame things like Electron, either, as Microsofts own WinUI framework, which is used for most new! Windows UI developed by Microsoft for Windows 11, also uses custom scrollbars that do not work like the Win32 one does. Great, so by the time I learn about a shortcut for scroll bars (Shift+click), the ecosystem has fragmented so much that I can’t even rely on it working. ↫ Raymond Chen Modern computing is depressing.
- Solaris 11.4 SRU95 released
The Solaris branch for paying customers has been updated to SRU95. Oracle Solaris 11.4 SRU95 updates a broad set of platform, runtime, developer, networking, desktop, and open source components. Notable updates include Ansible Core to 2.21.1, Apache HTTP Server to 2.4.67, Apache Tomcat to 9.0.120, BIND to 9.20.23, Django to 5.2.15, Elixir to 1.20.1, Erlang to 28.5.0.2, Firefox to 140.10.0esr, Go to 1.25.11, ImageMagick to 7.1.2-27, MySQL 8.4 to 8.4.10, NSS to 3.125, OpenSSH to 10.4p1, Rust to 1.96.0, SQLite to 3.53.2, Thunderbird to 140.10.0esr, and Vim to 9.2.0513. Additional updates include CMake, CUPS, Cython, GnuTLS, libarchive, libexpat, pip, rsync, and a range of Python modules, X11 libraries, graphics libraries, printing components, and desktop utilities. ↫ Colin Kavanagh at the Oracle Solaris Blog One of the major changes is the deprecation and removal of NTLM authentication of local users; only NTLMv2 is supported now for security reasons. This release also brings GCC 16, with GCC 13 being removed in the next version. The detailed release notes go into some of the more low-level, esoteric changes in Solaris 11.4 SRU 95.
- You know the GDPR is good based on who hates it
It is impossible to go anywhere in a technology space online without hitting a wave of commentary about how stupid GDPR is. It was written by bureaucrats who dont understand the amazing potential of unrestricted technology. These US-based critiques almost always lean on the oldest trick in cyberlibertarianism: we dont have time to regulate, we must simply adapt and ride the wave. Nobody has time for government. Of all GDPRs consequences, none gets more attention than the cookie banner, which critics present as the inevitable result of government meddling. Blaming GDPR for the cookie banner is like blaming the health inspector for the roaches. The banner is deliberate vandalism, a dark pattern engineered to exhaust you before you can learn anything about the surveillance apparatus humming behind the OK.! Ironically the banner designed to hide the machine has taught the public more about the machine than a thousand podcasts ever will. Even non-technical people stop at your data is shared with 996 partners.! ↫ Mat Duggan There is so much misinformation about the cookie banner, its honestly quite hard to believe its not deliberately spread. You dont need a cookie banner for functional cookies, so as long as you dont share your users data with anyone else, you dont need a cookie banner at all. On top of that, most cookie banners you encounter are actually not compliant with the GDPR at all, because they dont present a single-click option to block your data from being shared with those 996 partners. What the cookie banner has done is inform millions maybe even billions of people the world over of just how insipid the online advertising and data harvesting industry really is. It put the issue on the map, and by now, everyone, no matter their level of computer literacy, is fully aware of whats happening to their data every time they see one of these (non-compliant) banners. No else had the guts to do this except for the European Union. The wider GPDR has set the baseline for online privacy protections, and while we have a long way to go before weve fully solved this issue, the EU at least gave us a good point to jump off from. Smoking and asbestos werent banned in a day, either.
- Googlebook OS: Google launches its Android-powered laptop effort
A few months ago, Google announced it was going to put Android on laptops (and eventually, desktops), serving as eventual replacements for Chromebooks. Unlike those, though, these new Android laptops wouldnt be low-quality, cheap, underpowered devices for school children to spill milk on, but devices actually competitive with Windows and macOS laptops. Today, the company finally allowed the press to use these new things. Google describes Googlebook as a “totally fresh approach to computing,” bringing together Android, ChromeOS, Gemini, and premium laptop hardware from major manufacturers. The idea is to create a laptop that feels more natural to use for Android phone users while retaining what makes a desktop OS useful, such as a full Chrome browser, desktop apps, a proper file manager, Linux support, and a full terminal environment. Google is also trying to solve some of the biggest problems Android users have had when moving between their phone and laptop, and make the two devices feel like part of the same ecosystem. ↫ Adamya Sharma at Android Authority Ive been looking at some of the videos of people using and playing with these new Android laptops, and to be honest, Im not impressed. Im seeing quite a bit of jank, a complete lack of consistency, and apparently, a lack of Android applications optimised for desktop use. The close integration with your Android phone are nice, but of course, this also means another dollop of slimy lock-in, as I highly doubt Google will make it easy or even possible at all for, say, iPhones or other platforms to integrate quite as nicely as Android devices will. Worse yet, theres the elephant in the room: for just how long will Google care about this new platform? These laptops start at $900 and go all the way up to $1300 (and will be considerably more expensive here in Europe), which is a lot to ask for something Google might get bored of and abandon in a few years time. Ten or more years ago, in a slightly more innocent time, I mightve been excited about Google bringing Android to laptops and desktops, but in 2026, I just cant be bothered to care. Also, and this doesnt really matter, but Googlebook OS!?
- Lets stop debating the GnuImp Manipulation Program
The GIMP will never magically become software beloved by artists—not without radically changing its culture, and making the artists the ones who call the shots. The GIMP will remain what it has always set out to be: a tinkerer’s toolbox, more concerned with the purity of its software politics than with garnering a loyal userbase of photographers and designers. But because everyone insisted to poise it as a viable Photoshop killer, Linux is left with an obvious hole in its software offering, a hole nobody managed to fill with their own challenger. ↫ Aria Salvatrice Excellent article, and spot-on conclusion.
- I dont like passkeys!
Passkeys are a fantastic technology. Since they are bound to the site they are created for, they cannot be phished by a hacker’s fake login screen. If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details. This leads to passkeys being the perfect fit for a corporate environment, but a poor fit for personal security. To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss. By using passkeys, you gain better security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts. Phishing through the standard login flow is eliminated by passkeys, but it creates a false sense of security. An account’s security is still dictated by the weakest recovery method: SMS, email links, security questions, and so on. If these recovery methods aren’t enabled, then the risk of permanent lockout remains for the user. ↫ Ethan Hawksley Ive always felt something was off about passkeys, and have never used them. Theyve become or were always intended to be tools for further lock-in by especially Google and Apple, tying their entire usage flow to their respective operating systems. They also dont seem to work well if you often work on devices not your own, which is a major hassle. None of these shortcomings come into play when using a traditional password manager, even if they require more manual work. Just let me use a password manager with random password generation, instead of trying to force passkeys down my throat.
- Java 27 released
Speaking of unsexy programming, weve got a new Java release. Featuring thousands of performance, stability, security, and productivity improvements, Java 27 (Oracle JDK 27) provides a strong foundation for continued Java innovation. To help organizations prepare for more secure communications in a post-quantum world, Java 27 advances its post-quantum cryptography (PQC) capabilities with hybrid key exchange for TLS 1.3. ↫ Oracle press release The OpenJDK release page has more information.
- Performance improvements in .NET 11
Look, nobodys going to argue .NET is sexy, but the truth of the matter is that its quite popular in less visible circles, so any new release is going to have a big impact on a ton of people and product. In other words, performance improvements in .NET 11 are going to matter. In contrast, .NET 11 is actually one higher, one louder. The sections that follow are full of real improvements. A bounds check removed, an allocation that no longer happens, a lock that isn’t taken, a loop that runs in fewer cycles than it did a year ago, a comparison folded to a constant here, a redundant check hoisted out of a loop there, a couple of instructions fused into one, a syscall sidestepped, an array copy handed off to SIMD, and on and on. That’s how real performance work goes, accumulating gain after gain, each compounding on the last, until the whole thing is measurably, provably louder. And so, in this post, as I’ve done in past years with .NET 10, .NET 9, .NET 8, .NET 7, .NET 6, .NET 5, .NET Core 3.0, .NET Core 2.1, and .NET Core 2.0 before it, we’ll take an unhurried tour through hundreds of them. ↫ Stephen Toub at Microsofts Dev Blogs My eyes glaze over at all of this, but even here on OSNews, theres going to be countless people working with .NET at their jobs.
- GNOME 51 released
GNOME 51 has been released, with a whole slew of new features and improvements. Most notably, at least in my experience, will be the work done on GNOMEs graphics stack, which seems to stutter and jitter more than KDEs on the same hardware at least in my experience. In particular, GNOMEs compositor, Mutter, has improved frame scheduling for smoother animations, even under load. This hopefully addresses the stutters I generally experience when using GNOME. Theyve also done a lot of work on the Settings, Maps, Calendar, Web, and other applications. Of note to many will be the array of improvements to GNOMEs file manager, including better performance, although I doubt it will convince those of us who arent particular fans of Nautilus in general. Theyve also improved the remote desktop experience by, among other things, adding support for smart cards and improving support for Kerberos. GNOME 51 will make its way to your distribution of choice soon enough.
- Ubuntu 26.10 completes transition to Rust-based coreutils
Ubuntu has been replacing core utilities with Rust rewrites, and its now completed the process. cp,`mv`and`rm`were held back on`their GNU versions in`Ubuntu 26.04 LTS due to a crop of`TOCTOU (time-of-check to time-of-use) issues that needed to be fixed in the`uutils`versions.` With those issues resolved upstream,`Ubuntu 26.10 finishes the job. The ‘Stonking Stingray’ ships a full set of Rust core utilities, which encompasses common command-line tools like ls,`cat,`chmod and `du. ↫ Joey Sneddon at OMG! Ubuntu Im definitely not qualified enough to make any useful remarks about this, but the idea of replacing such foundational, battle-tested utilities with brand new ones, even when written in a memory-safe language, does make feel a little hesitant. Still, at least this way Ubuntu users can work out any issues so that if and when other distributions like the one I use, Fedora follows suit.
- The terrible menu bar in the Windows 11 Notepad
When I used Windows for a month because you people paid me to do so, the utter lack of consistency in the way applications and the operating system itself looks, feels, and behaves was a major sticking point. It turns out, though, that I was only scratching the surface of just how bad things really are on Windows. Case in point: the new WinUI Notepad application that replaced the classic Win32 one. I had no idea just how bad it really is. It’s been seven weeks since I last complained about something in Windows on this blog. That feels like too long, so here’s a post about menus – specifically, the menu bar in the modern version of Notepad in Windows 11. That menu bar has, unfortunately, quite a few regressions compared to the menu bar in the old Win32 version of Notepad. ↫ Reupen Shah Im not going to spoil any of it, because theres no way youd believe any of it without the videos Shah provides. Im aghast.
- GEFS on OpenBSD: a very early preview
The Good Enough File System, originally developed for 9front, is being ported to OpenBSD. For those who havent watched my talk, GEFS is a new, crash-safe, snapshotting, copy on write FS that I wrote for 9front, and which I am in the process of moving to OpenBSD. The file system is described in full here. ↫ Ori Bernstein One of OpenBSDs shortcomings is its rather archaic filesystem, so any work on something more modern and especially more performant is quite welcome. While any process of replacing FFS is going to be a long one, even having GEFS as an option could be a great addition to OpenBSD.
- Apple releases iOS 27, macOS Golden Gate 27 with Siri AI! and Liquid Glass refinements
Apple releases its yearly cluster of operating system updates today, with the two most prominent of course being macOS and iOS/iPadOS. These new versions focus heavily on Apples AI! stuff, but there are a few actual improvements and changes to the actual operating systems as well. Across both iOS and macOS, users now have a slider to affect how transparent or opaque the “Liquid Glass” design is across the operating system. And on the macOS side especially, Apple has made numerous small design tweaks to address user feedback, which has been accumulating since Liquid Glass was introduced. There’s nothing radically new in terms of design here, but this is a much-needed polish pass. Across all the releases, but in particular macOS and also iOS, there are a bunch of quality-of-life or performance improvements. For example, macOS now supports HDR for all system UI elements and gets more robust support for a wider range of display modes for external monitors. ↫ Samuel Axon at Ars Technica If youre not into AI!, theres not a lot of meat on these bones, but at least you can turn the AI! nonsense off through a switch buried deep in the settings applications of Apples operating systems (which will probably be flicked back on whenever the next update comes).
- Switching to GNU Guix: a beginners perspective
Want to run something a little more exotic on your server? How about GNU Guix? It has been a month since migrating my home server to GNU Guix. Managing OS state declaratively through Git has eliminated configuration drift, and Guile Scheme provides a cohesive environment that complements Emacs. While adapting to a smaller package ecosystem and managing substitute timing requires occasional adjustments, the stability, reproducibility, and container isolation make it a dependable foundation. ↫ Wai Hon Im definitely noticing an increase in interest in Guix lately.
- The BeBox: one of the most beautifully overbuilt computers of the 1990s
Late 2000. There is a grey and blue tower PC on my dorm-room desk like nothing anybody who walks into the room has ever seen. The Be logo on the front, a 3.5″ floppy peeking out the bottom of the drive bays, and the vertical grille that hides two columns of green LEDs (blinkenlights) dancing with the CPU load. This was a dual-PowerPC workstation running an operating system you didn’t see in the wild. I was studying computer science at the time and this was a fun piece of hardware. ↫ J.D. Hodges As a BeOS user in and around 2001 or so, the BeBox was the holy grail of the little community I was a part of. There were some people here and there in online circles who had one, but they were rare even when new, and by 2001, they had become rarer still. This rarity made them mysterious and exciting from almost from the day they were launched, like a small volume halo car few people will ever get to see, let alone experience, first-hand. Its 2026 now, and more and more of the small number of BeBoxen made must be succumbing to degradation and hardware failures. I hope everyone who has one takes good care of them, because these are some of the rarest, most coveted computers of all time. Ive still never seen one, and here in Arctic Europe I most likely never will. Still, I remain hopeful. One day.
- Age verification exemptions for open source operating systems feel like Phyrric victories
On the Windows side of the age verification question, Microsoft is obviously following trends among lawmakers the world over. To address this, Windows is introducing a new platform capability: the Windows Age API. This API brings age awareness beyond the operating system by making it available across the entire Windows ecosystem so that apps and services can deliver age-appropriate experiences using the same trusted foundation. By making age awareness available as a platform capability, Windows helps developers build safeguards into experiences from the start rather than placing the burden on children and families to manage protections app by app.` ↫ Rob Mauceri at the Windows Blogs Meanwhile, on the Linux side of things, theres been some cheering as at least California passed amendments to its age verification law to exempt open source operating systems. These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope. ↫ Luke James at Toms Hardware I think this is not at all the good news that many make it out to be. Exempting Linux, BSD, and other open source operating systems from age verification obligations may seem like a good thing at first glance, but in reality, I think services and applications will simply choose to not work at all on platforms that do not implement age verification. The fear of legal ramifications, especially when it involves children, will be enough for existing and future popular services and applications to exclusively work on platforms that implement age verification whether those fears are founded or not. In fact, Im fairly sure a company like Microsoft, which has actually been feeling the squeeze from the Linux side recently even if it is modestly so is quite happy to see open source operating systems excluded from these obligations. Google, too, is probably none too unhappy to see any possible open source mobile operating system competitors not implement age verification. The fear of missing out is real, and most people are not as invested in fighting big tech and government surveillance as the average OSNews reader is going to be. If using Linux means not being able to play the latest hit games or use that new successful service, people will choose to stick with Windows or macOS. Let me be very clear that I do not support these age verification laws in any way, shape, or form, and I definitely do not want the open source world to embrace age verification. What Im worried about is that the open source world will cheer on these exceptions and consider the battle won, when in reality, they feel more like Pyrrhic victories. Age verification laws must be fought and destroyed at ballot boxes the world over, because otherwise I fear they will become just another tool in big techs toolbox, exemptions or not.

- Ubuntu Container Escape Vulnerability Gets Public Exploit Before Kernel Patch Arrives
by George Whittaker Ubuntu administrators running containerized workloads have a new Linux kernel security problem to watch closely. Public exploit code is now available for CVE-2026-80521, a Linux kernel use-after-free vulnerability that can allow an unprivileged process inside a container to escape and obtain root privileges on the underlying host.
Security firm DepthFirst published its research and exploit on September 22, 2026, demonstrating the attack against Ubuntu 26.04 LTS. The underlying Linux kernel vulnerability had already been fixed upstream on August 6, but as of September 23, Ubuntu's security tracker still lists the main kernel package in Ubuntu 26.04 LTS as "Vulnerable, work in progress," while Ubuntu 24.04 LTS is also listed as vulnerable.
The situation is particularly important for Docker, Kubernetes, cloud infrastructure, and other environments that run potentially untrusted workloads because the vulnerable kernel functionality can be reached through ordinary operations available inside standard containers.
There is currently no confirmed evidence that CVE-2026-80521 is being actively exploited in real-world attacks, and the vulnerability isn't listed in CISA's Known Exploited Vulnerabilities catalog. The availability of working public exploit code nevertheless makes the patch gap considerably more important. CVE-2026-80521 Is a Linux Kernel Vulnerability Although Ubuntu is receiving much of the attention because the newly published exploit specifically targets it, CVE-2026-80521 is fundamentally a Linux kernel vulnerability.
The problem exists in the kernel's AF_UNIX socket subsystem, specifically within its garbage collection mechanism.
AF_UNIX sockets, commonly called Unix-domain sockets, provide local inter-process communication between applications running on the same system.
Unlike conventional network sockets, they don't need to communicate across a network. They are widely used by Linux applications and services for fast communication between local processes.
They also support passing file descriptors between processes through SCM_RIGHTS messages, and it is the kernel's management of these references that creates the conditions for CVE-2026-80521. A Race Condition Leads to Use-After-Free At the technical level, CVE-2026-80521 involves a race condition inside the AF_UNIX garbage collector.
The kernel needs to track references between Unix sockets when file descriptors are passed between processes. Circular references can develop, where one socket effectively references another while that socket references something else in the same group.
Linux represents these relationships internally and periodically determines which references can safely be removed. Go to Full Article
- Fedora Linux 45 Beta Released with Python 3.15, GCC 16.2, and Major Security Changes
by George Whittaker The Fedora Project has officially released Fedora Linux 45 Beta, giving users an early look at the technologies expected to form the foundation of the final Fedora 45 release. The beta became available on September 15, 2026, after Fedora's Quality team approved Release Candidate 1.3 for publication.
Fedora 45 Beta brings significant changes throughout the operating system, including Python 3.15, GCC 16.2, glibc 2.44, GNU Binutils 2.47, Go 1.27, LLVM 23, Podman 6, stricter RPM signature verification, improved DNF5 protections, a new userspace virtual console, standardized desktop secret storage, and substantial installer improvements.
The release is available across Fedora Workstation, KDE Plasma Desktop, Server, Cloud, IoT, Atomic Desktops, Spins, and Labs, although a few prerelease images are excluded. Fedora 45 Beta Is Now Available Fedora Linux 45 Beta represents the final major public testing milestone before Fedora 45 reaches stable status.
Fedora describes its beta releases as code-complete previews that closely represent what users should expect from the final version. Development isn't finished, however, and bugs or incomplete migrations can still be discovered during real-world testing.
Fedora 45 Beta is currently available in several major editions: Fedora Workstation 45 Beta Fedora KDE Plasma Desktop 45 Beta Fedora Server 45 Beta Fedora Cloud 45 Beta Fedora IoT 45 Beta Fedora Atomic Desktops Fedora Spins Fedora Labs Existing Fedora installations can also be upgraded to the beta using Fedora's DNF system-upgrade process.
Fedora's official Workstation download page confirms Beta 1.3 images for both x86_64 and AArch64 systems. A New Virtual Console with kmscon One of Fedora 45's more unusual system-level changes is the replacement of the traditional in-kernel console with kmscon.
Fedora describes kmscon as a modern userspace virtual terminal implementation that provides smoother rendering, better internationalization and font handling, improved visual integration, and security improvements compared with the older console infrastructure.
This affects the virtual terminals users encounter outside their normal graphical desktop session.
Most desktop users spend relatively little time interacting directly with these consoles, but they remain important for troubleshooting, system administration, servers, recovery operations, and systems running without a graphical environment.
Moving that functionality into userspace also gives Fedora more flexibility for future development instead of relying entirely on the legacy kernel console implementation. Go to Full Article
- Thunderbird 156 Released with OAuth Improvements, OpenPGP Updates, and Major Linux Fixes
by George Whittaker The Thunderbird team has officially released Thunderbird 156, bringing another round of new features, security improvements, authentication enhancements, and reliability fixes to the popular open-source email client. Released on September 15, 2026, the update is available for Linux alongside Windows and macOS.
Thunderbird 156 is not a dramatic redesign of the desktop mail client. Instead, it concentrates on improving areas that matter to everyday users and system administrators, including OAuth authentication, OpenPGP, POP3, IMAP, Exchange Web Services, SMTP, attachments, calendars, enterprise policies, and security.
For Linux users in particular, the release delivers several fixes affecting common mail protocols and account configurations while retaining support for Linux environments using GTK+ 3.14 or newer. Thunderbird 156 Arrives on Linux Thunderbird 156 follows version 154, which arrived in August with features including optional system tray operation and Microsoft Graph support for Microsoft 365.
Version 156 continues the project's monthly release cycle with a more targeted collection of authentication, security, compatibility, and reliability improvements.
According to Thunderbird's official release notes, version 156 requires: Linux: GTK+ 3.14 or newer Windows: Windows 10 or newer macOS: macOS 10.15 or newer Thunderbird 156 was officially released on September 15.
Linux distribution availability will vary because distributions can package Thunderbird according to their own schedules. Users receiving Thunderbird through another packaging channel may therefore see version 156 at a different time. Custom OAuth Support Expands One of the most significant areas of development in Thunderbird 156 is OAuth authentication.
Thunderbird now supports custom OAuth configurations containing an issuer ID and client secret for IMAP and POP3 accounts. Custom OAuth support has also been extended specifically to POP3.
OAuth has become increasingly important as email providers move away from conventional username-and-password authentication toward token-based authentication.
For Thunderbird, broader custom OAuth support means users and organizations have greater flexibility when connecting the client to mail services that don't fit Thunderbird's predefined provider configurations.
This can be particularly useful in enterprise environments, self-hosted infrastructure, and organizations operating their own identity systems. Exchange Custom OAuth Setup Fixed Exchange users receive an important related correction. Go to Full Article
- KDE Plasma 6.7.5 Released with Discover, KWin, Wayland, and HDR Fixes
by George Whittaker The KDE Project has officially released KDE Plasma 6.7.5, delivering another round of bug fixes and stability improvements for the Plasma 6.7 desktop series. Released on September 8, 2026, the update contains roughly a month of fixes and updated translations contributed since Plasma 6.7.4 arrived in early August.
Unlike a major Plasma release, version 6.7.5 doesn't introduce a large collection of new desktop features. Instead, KDE has focused on fixing problems affecting Discover, KWin, Wayland, networking, System Monitor, Plasma Desktop, RPM-OSTree systems, Snap updates, HDR rendering, and several other components.
For users already running Plasma 6.7, this makes version 6.7.5 primarily a maintenance upgrade intended to make the desktop more dependable ahead of the next major Plasma series. KDE Plasma 6.7.5 Arrives as the September Bugfix Release KDE describes Plasma 6.7.5 as its September bugfix release for the Plasma 6 desktop.
The broader Plasma 6.7 series originally arrived in June 2026, followed by a succession of maintenance releases: Plasma 6.7.1 on June 23 Plasma 6.7.2 on June 30 Plasma 6.7.3 on July 14 Plasma 6.7.4 on August 4 Plasma 6.7.5 on September 8 KDE's official download infrastructure confirms that the Plasma 6.7.5 source packages became available on September 8.
This slower maintenance cadence later in a Plasma series is normal. Once the most urgent post-release problems have been addressed, KDE generally shifts more development attention toward the next feature release while continuing to provide important fixes for the current branch. Discover Receives Several Important Fixes KDE's Discover software center receives some of the most noticeable improvements in Plasma 6.7.5.
One particularly annoying problem could cause Discover to become stuck while checking for updates when its Snap backend was installed but no Snap applications actually had updates available.
That problem has now been corrected.
Discover also behaves more reliably when fwupd, the Linux firmware update service, is unavailable. Previously, a broken or intentionally masked fwupd service could interfere with Discover's normal operation. Plasma 6.7.5 allows the rest of the application to continue functioning correctly in that situation.
This is useful for systems where firmware updating isn't supported, where administrators intentionally disable the service, or where fwupd encounters a configuration problem. Firmware Updates No Longer Incorrectly Require Reboots Another Discover correction addresses a regression involving firmware updates. Go to Full Article
- Slackware 16 Alpha 1 Released with Linux 6.18 LTS, GCC 16.2, and Plasma 6
by George Whittaker One of Linux's oldest surviving distributions is moving closer to its next major release. Slackware 16 Alpha 1 became available on September 5, 2026, marking the first formal alpha milestone on the road toward Slackware Linux 16. The release follows a major rebuild of Slackware-current using a substantially newer GNU toolchain and brings together several upgrades that have accumulated since Slackware 15.0 arrived more than four years ago.
The alpha combines Linux 6.18 LTS, GCC 16.2.0, glibc 2.44, GNU Binutils 2.47, KDE Plasma 6, and numerous updated user-space packages while retaining much of the deliberately traditional architecture that has distinguished Slackware for decades.
For longtime Slackware users, Alpha 1 is particularly significant because it provides the clearest indication yet that the lengthy Slackware 16 development cycle is moving toward an eventual stable release. Slackware 16 Finally Reaches Alpha Slackware doesn't operate according to the predictable six-month or annual release schedules used by many other Linux distributions.
Instead, development takes place continuously through the Slackware-current branch. Patrick Volkerding and other contributors update that development tree until it reaches a state considered suitable for a stable release.
The previous major version, Slackware 15.0, was released in February 2022. More than four and a half years later, Slackware-current has now officially reached the first alpha milestone for version 16.
Volkerding marked the milestone following a complete rebuild of the distribution with its newly upgraded compiler, C library, and binary utilities.
The short changelog announcement even suggested there might finally be "a light at the end of the tunnel," a promising indication for Slackware users waiting for version 16. The Entire Distribution Was Rebuilt One of the most consequential changes behind Alpha 1 is a complete package rebuild.
Slackware's development toolchain has moved to: GCC 16.2.0 glibc 2.44 GNU Binutils 2.47 After introducing those components, Slackware rebuilt the distribution's packages against the updated environment.
A full rebuild is much more significant than simply replacing three packages.
GCC is responsible for compiling much of the software distributed with Slackware, glibc provides fundamental C library functionality used throughout Linux user space, and Binutils supplies essential development utilities including the GNU assembler and linker.
Rebuilding the distribution against these versions gives Slackware 16 a considerably newer foundation than its predecessor. Go to Full Article
- Top AEO Tools for Linux and Developer Documentation Teams
by Malana VanTyler These platforms help teams monitor how technical content appears in AI-generated answers, from brand mentions and citations to accuracy and referral traffic.
Search is splitting into two experiences: one built around ranked pages and another around generated answers. As AI platforms summarize Linux tutorials, open-source project documentation, API references and technical guidance, teams need ways to measure whether their content is mentioned, cited and accurately represented.
An Go to Full Article
- The New Way Security Teams Evaluate Pentesting Vendors
by George Whittaker Why security buyers are rethinking what matters most.
Security teams typically don’t struggle to find vulnerabilities as much as they have in the past. The harder part usually begins after the report arrives, once dozens of findings land in front of engineering teams already juggling patch schedules, production deadlines, and internal disagreements about urgency. Platforms like Go to Full Article
- New Linux “Steal Governor” Targets CPU Contention in Overcommitted Virtual Machines
by George Whittaker Linux kernel developers are considering a new “steal governor” designed to improve performance when multiple virtual machines compete for limited physical CPU resources. The proposal uses the amount of CPU steal time observed inside a guest to dynamically reduce or expand the number of virtual CPUs on which that VM prefers to schedule work.
The feature is primarily aimed at heavily virtualized servers where administrators deliberately assign more virtual CPUs than the host can physically execute at once. Under heavy load, that overcommitment can lead to frequent vCPU preemption, lock-holder delays, cache disruption, and ultimately lower overall throughput.
The latest v11 patch series was posted on August 25, 2026, and its developer has proposed consideration during the Linux 7.3 development cycle, potentially targeting Linux 7.4 for inclusion. This means the feature is still under review and is not part of a stable Linux kernel yet. What Is CPU Steal Time? CPU steal time is a concept specific to virtualization.
Imagine a virtual machine has eight vCPUs. From inside that VM, the operating system behaves as though those eight CPUs are available. But those virtual CPUs ultimately need to run on the host's physical processors.
If several VMs are competing for the same physical CPU resources, the hypervisor may temporarily prevent one VM's vCPU from running so another VM can use the processor.
The time during which the guest wanted to execute but couldn't because the hypervisor was using the underlying CPU elsewhere is known as steal time.
High steal time is therefore a useful indication that the physical host is experiencing CPU contention. The “Noisy Neighbor” Problem The steal governor is designed primarily to address what virtualization engineers commonly call the noisy neighbor problem.
Consider a server hosting several VMs: VM A has 32 vCPUs. VM B has 32 vCPUs. VM C has 32 vCPUs. The physical server has only 64 CPU threads available to those workloads. That configuration can work perfectly well when the VMs aren't simultaneously busy.
If all three suddenly become heavily loaded, however, they may collectively request more CPU time than the physical machine can provide.
The hypervisor then has to constantly switch between vCPUs.
Those interruptions can become particularly expensive if a vCPU is preempted while holding a lock or executing another latency-sensitive section of code. Other threads may then wait for a vCPU that isn't currently being allowed to run.
The result can be counterintuitive: giving the VMs more virtual CPUs can sometimes make the combined workloads slower. Go to Full Article
- Thunderbird 154 Released with System Tray Mode, Microsoft Graph Support, and Major Mail Fixes
by George Whittaker The Thunderbird team has officially released Thunderbird 154, delivering several useful new features alongside a substantial collection of fixes for email, calendars, address books, authentication, and stability. Released on August 18, 2026, Thunderbird 154 is now the latest monthly release of the popular open-source email client.
For Linux users, one of the most interesting additions is a new optional system tray mode, while Microsoft 365 users gain Microsoft Graph support. The release also improves global search, attachment handling, IMAP reliability, Exchange authentication, and CalDAV synchronization. New Optional System Tray Mode One of Thunderbird 154's most welcome additions is an optional system tray mode.
When enabled, closing Thunderbird's last window no longer needs to completely terminate the application. Instead, Thunderbird can remain running in the background through the system tray.
This can be particularly useful for users who want Thunderbird available throughout the day without keeping its main window open.
For Linux desktop users, the feature could make Thunderbird feel more like a traditional background email client, especially on desktops where tray-based applications remain part of the normal workflow. Microsoft Graph Enabled for Microsoft 365 Thunderbird 154 also enables Microsoft Graph for Microsoft 365.
Microsoft Graph is Microsoft's API platform for accessing Microsoft 365 services and data. Its integration is particularly important as Thunderbird continues improving its support for Exchange and Microsoft-hosted email environments.
Thunderbird has been steadily expanding its Microsoft ecosystem compatibility, making the open-source client increasingly practical for users who need to access workplace Microsoft 365 accounts from Linux. Global Search Gets a Useful New Option Thunderbird's global search functionality also receives an improvement.
Users can now configure global search results to open in list view by default, providing another option for people who prefer a more traditional message-list workflow when reviewing search results.
It's a relatively small addition, but one that can make repeated searches more convenient for users managing large mailboxes. Better Attachment Management Thunderbird 154 introduces several improvements for handling email attachments.
A new "Copy To" folder context menu has been added for message/rfc822 attachments, and these attached messages can now be dragged directly into Thunderbird's folder tree.
These changes should make it easier to organize attached email messages without having to use additional steps or workarounds. Go to Full Article
|