Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All) (Two Column)

LWN.net

  • Kernel prepatch 7.2-rc4
    The 7.2-rc4 kernel prepatch is out fortesting. Linus said: "This whole week I had the feeling that peoplewere starting to go on summer vacation, but running the numbers shows thatI must have been wrong - it all looks pretty normal."


  • "Half a Second" — a book on the XZ backdoor
    Adrian Mastronardi has released a book called Half a Second; it is adetailed look into the XZ backdoor attemptof 2024. The book is freely available under a (non-free) noncommercial,no-derivatives CC license.
    Half a Second tells that story as one continuous narrative: the burned-out volunteer who maintained the code alone and was patiently, expertly manipulated into giving it up; the engineer whose half-second of curiosity caught the attack through a chain of luck and hard-won instinct; and the operator who built it, who has never been identified and, this book argues, may never be.



  • Building an Arch Linux aarch64 port for Holo Core (Collabora blog)
    Collabora has published a blogpost about its work with Valve on Holo Core, which is a port of Arch Linux toaarch64 to be used as the the operating system on Valve's64-bit Arm Steam Frame gaming system. Collabora has released thesources,binarypackages, and a container image for aarch64 devices. The postdescribes some of the challenges in porting Arch Linux to a newarchitecture, and what remains to be done:

    Whilst the infrastructure developed to this point is capable ofbuilding from first principles up until a point-in-time snapshot, thenext step is to build this into a system which can track Arch Linux asit is developed. This work will serve as the basis of acontinuously-operating CI system capable of shadowing Arch Linuxitself. We will work with the upstream Arch Linux project to help Archwith their efforts to port the distribution to aarch64 architectureand work towards automated repeatable builds.

    The post also includes instructions on how to create and test anaarch64 build container on an x86_64 host, for users who would like tofollow along at home but lack a 64-bit Arm device.



  • [$] Securing BPF LSMs against tampering
    Since 2020, BPF programs have been able toact as Linux security modules(LSMs). Several projects, including systemd, have been working to usethat capability to provide more security to users. Christian Braunerspoke at the 2026Linux Storage, Filesystem, Memory-Management, and BPF Summitabout some of the limitations of using BPF in this way, and the changes hewould like to see for systemd's use. In particular, he would like a way to makesure that BPF programs cannot be removed or have their private data tampered with.


  • Security updates for Friday
    Security updates have been issued by AlmaLinux (cifs-utils, container-tools:rhel8, libreoffice, nodejs:24, perl-XML-LibXML, and python3.12), Fedora (ansible-collection-ansible-posix, firefox, freerdp, ImageMagick, mingw-glib2, perl-DBI, perl-HTTP-Date, rust-cargo-rpmstatus, and rust-opendal), Oracle (cifs-utils, gegl, gimp, git-lfs, go-toolset:ol8, hplip, kernel, libreoffice, maven:3.9, perl-XML-LibXML, python3, python3.12, python3.9, and uek-kernel), Red Hat (kernel, kernel-rt, and podman), Slackware (netatalk), SUSE (agama, aws-nitro-enclaves-binaryblobs-upstream, gimp, gpsd, grafana, hostapd, ImageMagick, jackson-databind, kernel, libssh2_org, nm-configurator, opennlp, perl-Mojolicious, python-Pillow, python-python-engineio, python-python-socketio, and tomcat11), and Ubuntu (ntfs-3g, python-authlib, ruby2.3, tar, and ubuntu-advantage-tools).



  • Security updates for Thursday
    Security updates have been issued by AlmaLinux (cups, git-lfs, kernel, libsolv, libxml2, python3.12, and python3.9), Debian (chromium, dhcpcd5, and ntfs-3g), Fedora (firefox, perl-Imager, python-bcrypt, python-tiktoken, roundcubemail, and xrdp), Mageia (openssl, poppler, python-mistune, and tmux), Oracle (389-ds-base, cups, git-lfs, glibc, host-metering, kernel, libsolv, libxml2, nginx:1.24, PackageKit, python-pillow, and qemu-kvm), Red Hat (buildah, containernetworking-plugins, and skopeo), SUSE (buildah, cosign, curl, distribution, dnsmasq, glib-networking, glibc, gnutls, gstreamer-plugins-bad, ImageMagick, kernel, podman, python-cryptography, python313-django-debug-toolbar, rekor, sccache, sssd, and yelp), and Ubuntu (dotnet8, dotnet10, libslirp, luajit, python-idna, sympa, and tomcat8).


  • [$] LWN.net Weekly Edition for July 16, 2026
    Inside this week's LWN.net Weekly Edition:
    Front: Fighting scraper bots; io_uring queues; Filesystem testing; BPF shielding; Sending packets from BPF; Kitty; QBE. Briefs: Shim security; seunshare vulnerability; Debian bookworm; Rust 1.97.0; Linux.org; Quotes; ... Announcements: Newsletters, conferences, security updates, patches, and more.


  • [$] Topics in filesystem testing
    It should come as no surprise that a gathering of filesystem developerswould discuss filesystem testing; it has been a mainstay of the Linux Storage,Filesystem, Memory Management, and BPF Summit over the years and the2026 summit was no exception. Ted Ts'o led the discussion this time; hehad a few different topics to raise, including his perception of increasingregressions for ext4 in the stable kernels and what can be done to helpreduce them. As with other similarsessions at the summit over the years,there is a lot of interest in collaborating on test inputs and outputs, butfinding a way to centralize that information has so far eluded thefilesystem community.


  • Local DoS attack vectors in seunshare 3.10 (SUSE Security Team Blog)
    The SUSE Security Team Blog has a postwith an analysis of seunshare,which is used by SELinux to confine untrusted programs. During areview of version3.10 of the program, the team identified two localDenial-of-Service (DoS) vectors.

    Since seunshare is supposed to run on SELinux-enabled systems, itis important to understand what kind of privilege escalation can beachieved when vulnerabilities are exploited in a setuid-root binarylike this. Many SELinux-enabled systems, such as Fedora and openSUSE,ship with the "targeted" SELinux policy by default. This policy isfocused on confining well-known system services, but assigns anunconfined SELinux context to interactive users by default to achievea balance between security and usability.

    There is currently no domain transition from the unconfined domainto the more restricted seunshare_t defined in the SELinux policy forseunshare. This means the execution of seunshare continues in theunconfined domain. Thus in the context of attacks carried out byinteractive users, the impact of the vulnerabilities below will be aroot-like privilege escalation despite the system running in SELinuxenforced mode.

    See the post for the full write-up of the team's discoveries and timeline. Thevulnerabilities have been fixed in version 3.11.



  • [$] Lockless MPSC FIFO queues for io_uring
    Processes that use io_uringtend to keep a lot of balls in the air; being able to have many operationsunderway at any given time is part of the point of that API in the firstplace. The io_uring subsystem must, as a result, keep track of a lot oftasks that have to be performed at the right time. In current kernels,io_uring uses a standard kernel linked-list primitive to track those workitems. As of the 7.2 kernel release, though, io_uring will, instead, use anew lockless, multi-producer, single-consumer (MPSC) queue, resulting insome notable performance gains. Lockless algorithms tend to be tricky, butthe one used here is relatively approachable and shows how these algorithmscan work.


  • Security updates for Wednesday
    Security updates have been issued by AlmaLinux (cifs-utils, corosync, cups, freerdp, git-lfs, go-fdo-client and go-fdo-server, go-toolset:rhel8, kernel, kernel-rt, libinput, libxml2, nginx:1.24, openssl, pacemaker, perl-DBI:1.641, php8.4, python-pillow, python3, and python3.12), Debian (grub2, libxfont, opam, and wolfssl), Fedora (freerdp, kernel, and prometheus), Mageia (imagemagick), Oracle (buildah, freerdp, gimp, kernel, nginx, openexr, openssl, perl-DBI, podman, vim, xorg-x11-server, and xorg-x11-server-Xwayland), Red Hat (python3.12), SUSE (afterburn, buildah, busybox, enc, freetype2-devel, go1.25, go1.25-openssl, go1.26-openssl, gosec, grafana, helm, krb5, kubernetes-old, libopenbabel8, libxml2, libxml2-16, nasm, openssl-3, patch, python-Authlib, python-mistune, python-soupsieve, python-sqlparse, python3-dulwich, python313-Pillow, rootlesskit, sbootutil-1, tomcat, and tomcat11), and Ubuntu (alsa-lib, dnsmasq, gnutls28, libheif, linux-aws, linux-fips, linux-lts-xenial, linux-gcp-5.15, linux-intel-iotg-5.15, linux-hwe-6.17, linux-raspi, mariadb, openvpn, python-httplib2, vim, and wget).


  • Many old shim versions are still accepted by secure boot
    The CMU CERT Coordination Center has put out an advisory that manyexploitable versions of the shim binary, used to boot Linux on systems withUEFI secure boot enabled, were never added to the revocation list.
    An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Code executed during this early boot phase may achieve persistent compromise of the platform, including the ability to load unsigned or malicious kernel components that can survive system reboots and, in some cases, operating system reinstallation.
    The advisory contains a list of vulnerable shims.


  • The Linux.org story
    Rob Kennedy has posted thestory of the birth of Linux.org — oneof the earliest Linux-related web sites — and its more recent rebirth.
    The site was founded in May 1994 by Michael McLagan, at a time when Linux itself was barely three years old. Linus Torvalds had only just released it to the world, there was no real way for a newcomer to find their footing, no search engines, no Wikipedia, none of the infrastructure people take for granted now for figuring out a new piece of technology. Michael built linux.org to fill that gap, a place for people to learn about Linux and follow the movement as it grew.


LXer Linux News














  • UXL's oneDNN 3.13 Preps For Intel Nova Lake With AVX10.2, More Intel Optimizations
    Following the release of AMD's ZenDNN 6.0 earlier this month, there is a new feature release of the oneDNN neural network library that used to be developed by Intel as part of oneAPI and is now under the UXL Foundation umbrella. Even so, oneDNN feature releases continue to be heavy on new Intel optimizations and future hardware support...








Error: It's not possible to reach RSS file http://services.digg.com/2.0/story.getTopNews?type=rss&topic=technology ...

Slashdot

  • As AI Transforms Silicon Valley, Some Tech Workers Face Evaporating Financial Security
    The Washington Post describes a mid-tier executive at Meta as one of Silicon Valley's "winners" whose financial security suddenly "evaporated" as their workforce "pushed headlong into AI and heavy job cuts," creating a transformed job market. "Her ex-husband, a designer at Meta who was laid off in 2020, eventually gave up looking for jobs in his profession. He now lifts boxes at a warehouse."Layoffs.fyi, which tracks announced job cuts, counts more than 800,000 tech workers laid off since 2022, including large staff reductions in recent months at Meta, Microsoft, Oracle and Amazon... "There's this whole tranche of people who've been quite used to being among the most upwardly mobile in society who are all of a sudden saying, 'Now I'm the guy on the streetâs'" said Oliver Raskin, who founded Silicon Valley market research consultancy Signalcraft Insights and has surveyed attitudes in the tech labor force... "The rise of AI, especially, is bound to change the workplace radically," [said Georgetown University historian Joseph McCartin]. "But the way it's going to happen is similar to how technology transformed the auto industry." Ruth Milkman, a labor sociologist at the City University of New York, said that technology workers are getting a dose of what workers in other industries have long complained about: jobs that feel unsteady or rob them of autonomy. "Low-wage workers are used to it," she said... Many layoffs at technology companies are probably a hangover effect from over-hiring in prior years, experts say. And they don't account for a spotty recent increase in hiring in the information industry, which includes employment of software developers and jobs in media and entertainment. Digging deeper, though, some economists say there are signs that Silicon Valley and other technology-reliant parts of the American economy have reached a turning point where they are growing without needing as many people. The notion was encapsulated in a recent talk that ricocheted through group chats across the tech industry: In it, a partner at the start-up incubator Y Combinator heralded a new generation of AI-first companies that will only need human labor for "novel situations," "ethical considerations" and "high-stakes moments." Gad Levanon, chief economist at the labor research nonprofit Burning Glass Institute, said that the number of hours worked in the information sector has dipped since 2022, while the sector's economic output has increased by about 8 percent a year — more than three times the overall growth rate of the U.S. economy. He says the data reveals a sea change in industries, including technology and finance, toward doing more work with the same or fewer people — one that is spreading to other professional classes. "That's the new reality for white-collar and tech-exposed work: output up, headcount flat or down," Levanon said... Raskin, who has worked in the tech world since the late '90s, said that even though the current moment feels unsettling to many, he's hopeful that it's an early chapter in an evolving story. "It's happened many times before," he said, "that something implodes and all these people lose jobs, but then that talent gets cycled into whatever the next thing is — into a new wave of prosperity." In the article tech entrepreneur Anil Dash quips that Silicon Valley techies are "are guinea pigs for what tech dudes want to do to everyone."


    Read more of this story at Slashdot.


  • Zilog Z80 8-Bit CPU Turns 50, Open-source Replacement Heads To Drop-in DIP40 Silicon
    An anonymous reader shared this report from Tom's Hardware:The Zilog Z80 has just turned 50 years old. This iconic 8-bit processor first went on sale in July 1976 and stayed in production for 48 years until Zilog, now a Littelfuse subsidiary, stopped accepting orders in June 2024. However, there's an open-source replacement closer than ever to shipping in the chip's original 40-pin DIP package thanks to community-funded fabrication... The chip powered the ZX Spectrum, TRS-80, MSX machines, Nintendo's Game Boy, Sega's Master System, the Pac-Man arcade cabinet, and Texas Instruments' graphing calculators, then shipped in industrial controllers for decades after home computing moved on to more powerful successors. Zilog's end-of-life notice, dated April 15, 2024, told customers its wafer foundry was discontinuing support for the Z84C00 family, and last-time-buy orders closed that June. However, Renaldas Zioma's FOSS Z80 project, launched shortly after the end-of-life notice, now has working silicon. The first version, fabbed on SkyWater's 130nm node through Tiny Tapeout 7 on a die of just 0.064mm(2), has been confirmed as functional via the project's GitHub repository. A QFN64 version with all 40 pins exposed followed on the Efabless CI2406 shuttle, two further runs then went through IHP's 130nm process, and the current run targets the classic DIP40 form factor using chip-on-board assembly on GlobalFoundries' 180nm GF180MCU node via Wafer.Space. The end goal here is to fab a drop-in replacement for machines like the ZX Spectrum and RC2014 kits... Zilog is trimming the Z80's official successor line as well. A product change notification from last October put the eZ80L92, along with several Z8F-series microcontrollers, on end-of-life, citing "little to no demand..." [T]he pipelined eZ80 architecture, introduced in 2001 and still inside TI's current TI-84 Plus CE calculators, otherwise remains in Zilog's catalog. In 1999 Slashdot was calling Zilog's updated eZ80 "one of the fastest 8-bit CPUs available today, executing code 4 times faster than a standard Z80 operating at the same clock speed." Slashdot headline from 2001: Zilog To File For Chapter 11.


    Read more of this story at Slashdot.


  • Dozens of Robotaxi Riders Are Falling Asleep, Sparking Frantic Calls For Emergency Services
    "If tired or wasted passengers fall asleep in a traditional taxi or rideshare, the driver can shout or shake them awake," reports Bloomberg. "Not so in a robotaxi..."Ditto Kasendar remembers soft music drifting from the robotaxi's speakers as he rode home late at night from a friend's birthday party in 2025. The next moment, Los Angeles firefighters were opening the door and asking if he was OK. His six-minute trip had ended nearly an hour before. A remote Waymo assistant, dialling in through the car's speakers, repeatedly tried to rouse him and finally called 911 when he wouldn't stir... Kasendar's robocab nap was, unfortunately, not an isolated incident. As companies like Alphabet and Tesla bring self-driving taxis to more cities, the messier aspects of serving unpredictable humans are becoming harder to ignore. Passengers are falling asleep, spilling drinks, dropping food, vomiting, experiencing medical emergencies and, in at least two instances, giving birth in the cars. They stumble out of the vehicles and forget to close the doors, forcing the operators to pay nearby gig workers to do it. These seemingly minor nuisances are becoming a drain on municipal resources and complicating the roll-out of robotaxi service. So many robotaxi customers have nodded off in the midst of a ride that Austin police and firefighters even have a name for the incidents: "sleepers". The Texas capital recorded 99 such calls in Waymo's first nine months of service there, said Roger Patterson, a commander with Austin-Travis County Emergency Medical Services... Remote assistants monitoring the cars try talking through the speakers and checking on passengers with interior cameras. But if they get no response, company protocols often require them to call 911. And first responders have to assume the worst. Austin dispatchers treat an incident as a potential heart attack if the remote assistant can't tell whether the passenger is breathing, Patterson said. In the end, only about 3% of such calls require transporting the passenger to a hospital, he said. But the incidents tie up personnel who might be needed elsewhere.


    Read more of this story at Slashdot.


  • California's 'Truth in Recycling' Law Blocked by Judge
    An anonymous reader shared this report from the Los Angeles Times:A federal judge has halted California's groundbreaking "Truth in Recycling" law, which aims to reduce consumer confusion about which packaging can be recycled. [Originally planned to take effect October 4th], California's recyclable packaging law prohibits manufacturers from using a "chasing arrows" recycling symbol on products or materials unless they are actually being recycled in a meaningful way, which the law quantifies... A coalition of farming, forestry, restaurant and packaging organizations sued the state in March, arguing the law violates their right to free speech. They argued that Senate Bill 343 operates as "government-imposed censorship." Judge William Hayes agreed that their challenge has merit, and on Tuesday ordered California Atty. Gen. Rob Bonta, the defendant in the case, to pause enforcement of the law "until further order of the Court...." Advocates of reducing plastic use disagreed. "The court got it wrong, and I'm confident that the state will ultimately prevail," said Nick Lapis, director of advocacy for Californians Against Waste. "S.B. 343 does not violate the 1st Amendment; it requires companies to tell the truth when they make recyclability claims. Suggesting that the 1st Amendment protects misleading environmental marketing is inconsistent with the basic principles of consumer protection that states like California have implemented for decades." In January, CalRecycle, the state's waste agency, reported that less than 10% of most single-use plastic materials in the state were being recycled. Even yogurt containers and margarine tubs — made of ubiquitous polypropylene, or No. 5 plastic — are being recycled at a rate of only 2% in the state, the report said. Only 5% of colored shampoo and detergent bottles, made from polyethylene, or No. 1 plastic, are getting recycled... Plastic materials that can't be recycled are typically sent to landfills or sometimes illegally shipped overseas, where they are burned or end up in landfills, rivers and waterways. The bill's author told the Los Angeles Times "All you have to do is look at the numbers. These products are not getting recycled, despite what the industry is claiming. They are just confusing consumers, clogging the waste stream, polluting the environment, leading to higher and higher prices for local governments and ratepayers." He argues the symbols shouldn't be used to "confuse people who see the symbols [on products] and assume they can be recycled." The article also quotes Judith Enck, former Environmental Protection Agency regional administrator and president of the nonprofit Beyond Plastics. "Given the long history of the plastics industry deceiving the public about plastics recycling, this is an especially bad outcome. It is a reminder that the plastics industry has enough money to fight even the most modest policy designed to protect people and the planet."


    Read more of this story at Slashdot.


  • James Webb Space Telescope Discovers How Black Holes Feed Themselves
    "Thanks to the James Webb Space Telescope, astronomers have been given a glimpse of the mechanisms that supermassive black holes use to feed themselves," reports Space.com:The powerful cosmic titans get really puzzling when astronomers using the JWST spot them before the universe was even 1 billion years old. That's because the mechanisms by which black holes devour matter to grow and then merge to create even more massive black holes should take at least 1 billion years to achieve supermassive status. This is even more confusing because theories also say the most ravenously feeding black holes (and thus the fastest growing) should also push the matter they use for this growth away, in effect putting themselves on a diet. So, with all this in mind, how did supermassive black holes grow so rapidly in the early universe? One explanation suggests supermassive black holes push away gas, starving themselves as predicted, but also that this matter eventually cools and falls back to the black hole. That would allow for another period of feeding and thus growth. This explanation further suggests that as this gas cools down, it forms "streamers," or filaments, of gas just a few hundred light-years wide but which stretch thousands of light-years long. These would fall back to the center of the galaxy and form a swirling disk around its incumbent black hole, once again feeding it and triggering a new period of growth. This would then restart the jets from the black hole, which would again cut off the cosmic titan's food supply, allowing the whole process to begin once more. The process would in essence be a self-regulating cycle of feasting followed by fasting. However, the connection between these filaments and supermassive black holes has been elusive, meaning this mechanism has resisted confirmation. To solve the mystery of feasting black holes, the JWST turned its attention to a relatively close AGN situated at the heart of the central galaxy of the Centaurus Cluster, NGC 4696, located just 145 million light-years from Earth. The Hubble Space Telescope previously studied this galaxy, uncovering a strange, hook-shaped swirl of gas near the central supermassive black hole of NGC 4696. The JWST followed up this discovery by producing a detailed map of gas flowing at the heart of the galaxy. This revealed the hook-shaped feature is around 800 light-years wide and is composed of gas moving at incredible speeds of around 1.3 million miles per hour (600 kilometers per second).More excitingly, the swirl of gas appears to be connected to a vast filament of material falling in toward the central supermassive black hole. The team tested the JWST observations against a computer simulation, finding gas in the infalling filament scenario would indeed take a shape similar to that seen in NGC 4696."JWST is now showing us the final link of this closed loop," team member Helen Russell of the School of Physics and Astronomy at the University of Nottingham in the U.K. said in the statement. "The vast filamentary network of gas flows ultimately funnels gas down to a disk that fuels the black hole." The team's research was published on Wednesday (July 16) in the Astrophysical Journal Letters. "We are finally seeing this self-sustaining cycle in action," team leader Julie Hlavacek-Larrondo of the Université de Montréal said in a statement.


    Read more of this story at Slashdot.


  • Robot 'Decapitated' in World's First-Ever Humanoid UFC Fight
    "A humanoid robot lost its head," reports Newsweek, "during the world's first free-combat tournament for full-sized humanoid robots." The Ultimate Robot Knock-out Legend competition began Thursday in Shenzhen, China, according to the article, with local robotics company EngineAI providing $40,000 of their "T800" robots (yes, named after The Terminator) to 32 participating teams from around the world:A video shared of the combat on YouTube by local news outlet Shenzhen Story, showed that even after one of the robots had its head practically knocked off its shoulders, it continued to fight, throwing punches at its opponent and kicking into the air... [White humanoid robot "White Eagle"] landed a high kick to the head of its black opponent, "Matador," which made the robot's head rock precariously in its socket before rolling completely out of place. The two continued to spar as Matador's head was swinging from its socket until eventually the robot fell, crushing its head underneath its body. Matador tried to scramble back to its feet, but its head flew off and the robot then collapsed back down. The White Eagle did a celebratory dance for the crowd as the fight concluded, and did a move that mimicked that of someone flexing their biceps. The White Eagle waited in the ring, fists still up, as Matador was carried away, occasionally doing a few more dance moves... Per a report by Global Times, the winning team will be awarded a gold championship belt worth $1.44 million (10 million yuan) by the event organizer. It's a strange fight. The robots sometimes seem unaware of where their opponent is, facing the wrong direction or throwing kicks and punches in the air. In the first round White Eagle just knocks over Matador, who then isn't able to stand back up. (And White Eagle again appears to do a victorious dance.) EngineAI's site says they aim to "promote the development of robot combat events toward greater professionalism, scale, and industrialization," while fostering innovation and global collaboration. Thanks to Slashdot reader pbahra for sharing the news.


    Read more of this story at Slashdot.


  • Windows 10 Still Being Used, Often Unpatched and Insecure
    Windows 10 still runs on 16.9% of the Windows devices monitored by asset-tracking service Lansweeper. That's more than one in six, The Register points out.A year ago, the operating system accounted for about half of the machines in its dataset, falling to the low-to-mid 40% range by the time Microsoft ended standard support. The decline continued after that, reaching 18.6% in June, but Lansweeper says migration has now slowed to a crawl... Small and medium-sized businesses are particularly exposed. Lansweeper reckons that 21.4% of machines at small and medium-sized business still run Windows 10, with cost usually being the constraint that keeps the legacy operating system running. The exposure is greater in some sectors, with 23% of healthcare and pharmaceutical systems sticking with Windows 10, while consumer and retail devices hover at 22.7%. According to Lansweeper's data, "a Windows 10 device carries an average of 1,903 active CVEs against 652 on Windows 11. That's a 2.9x gap." Esben Dochy, principal technical evangelist at the company, told The Register that "the Windows 10 average also includes devices that have Extended Security Update patches applied." [According to Lansweeper's figures, 14% of Windows 10 assets have applied Extended Security Update patches.] Part of the problem, according to Lansweeper, is "patch diffing," in which Windows 11 fixes can be reverse-engineered to find flaws in Windows 10. "The supported OS effectively hands attackers a map into the unsupported one," Lansweeper said... Looking at other market share measures such as Statcounter, there was little change in the share of Windows 10 and its successor over the last few months after a surge following the end of support. As Lansweeper noted: "The easy migrations are done. What's left is the hard core: devices that haven't moved because they can't or won't." Lansweeper's evangelist noted that in some cases there is no Windows 11-certified version yet for many medical devices and industrial or retail systems.


    Read more of this story at Slashdot.


  • Aptera Announces US-Wide Repair Network for Its Upcoming Solar Electric Car
    Solar car maker Aptera has "officially announced a repair network partnership which will give owners of its upcoming solar electric car access to thousands of repair shops nationwide," reports Electrek:We recently got a chance to drive the Aptera solar EV and tour the company's factory, and came away both impressed at the progress that has been made, but cognizant of the long road ahead for the company. One question that often gets raised in reference to EV startups is how owners get service on their vehicles, especially those from a small company... So to waylay those fears, Aptera announced a partnership today that unlocks access to 4,300 service shops across the US, through a company called RepairPal. Aptera had been working on this partnership when we saw them at our factory tour, but today they're ready to officially announce it. RepairPal doesn't own its own shops, but instead certifies local shops to work on particular models of car... All shops will get access to Aptera-specific service procedures.


    Read more of this story at Slashdot.


  • Former Richard Stallman Colleague Now Argues for Open AI Models Too
    Long-time Slashdot reader theodp writes:Recalling his initial resistance to free and open software, billionaire computer scientist David Siegel argues vigorously in FORTUNE that the stakes are too high to let AI become increasingly closed. "In the 1980s, I had the chance to spend several years arguing about free and open software, what we now call open source, with the founder of the movement, Richard Stallman. My office at the MIT AI Lab was next door to his. Stallman's position was that the source code to software should be free for everyone to use, learn from, and improve. Software encapsulates knowledge, he argued, and no one should lock something so fundamental away. To hide software inside a company was to hide knowledge itself... What I missed was that software was not just a commercial asset; it was a body of knowledge, and bodies of knowledge grow stronger when they are shared. After about two years of on-and-off debate, Stallman convinced me I was wrong." "Now the AI fight is the same — only bigger," advises Siegel. "AI is software, and AI is increasingly closed. The frontier models — the most advanced, cutting-edge AI systems — are closed completely and the trend is accelerating. Viable open alternatives are few and far between." So, what to do...? "Yes, frontier models keep getting bigger and more expensive — that arms race may well stay with the giants. But open source AI does not have to match their scale to be useful. Much of what the world needs probably does not require the absolute frontier. And where keeping a credible open option does demand serious compute, that is precisely the kind of public good worth paying for. "What's missing is not a path but will. The government, the private sector, and nonprofits should invest heavily in free and open source AI — the way they once invested in open software: public compute grants for open research, corporate and philanthropic support for universities and nonprofits doing the work, and a simple rule that AI built with public money is open by default. "We have run this experiment before. We know how it turns out. Let's not unlearn it."


    Read more of this story at Slashdot.


  • Are There Cybersecurity Risks in Over-the-Air Tech Used in Autos?
    CNBC reports:The automotive industry's increasing use of over-the-air technology to update vehicle systems makes it more susceptible to cyberattacks, analysts say, urging more intervention in the sector... Its use represents "a unique national security concern," Gabriel Lim, senior analyst at the S. Rajaratnam School of International Studies in Singapore, told CNBC. "Aside from data privacy concerns, the potential of a foreign actor sabotaging the controls of a moving vehicle is a possibility that countries like Norway, Denmark, and Britain have expressed concerns about," Lim added. In May, the American Enterprise Institute warned that safeguarding the automotive sector was crucial to limit foreign governments' espionage capabilities. "To protect against foreign espionage threats, the US should consider additional security reviews, implement restrictions on certain foreign-made hardware and software in vehicles, and mandate increased data-collection disclosures," the report said. The concerns come as real-life tests reveal vulnerabilities. Late last year, Norwegian bus company Ruter conducted tests on two buses and found that one had potential risks linked to OTA technology. "There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer," the company said. The investigation by Ruter then sparked the U.K. and Denmark to conduct their own investigations... While these investigations were conducted on buses made by Chinese firm Yutong, [Siraj Ahmed Shaikh, systems security professor at the UK's Swansea University] said the issue goes beyond one manufacturer or country, as the technology becomes more pervasive. "Other sectors adopting OTA include other transport modes [such as] maritime and rail, aerospace (particularly drones), industrial machinery and robotics," he said.


    Read more of this story at Slashdot.


  • New Study Links Teen Boys' ADHD Symptoms To Addictive Social Media Use
    A new study by researchers at the University of California at San Francisco "adds to growing research linking increased social media use to detrimental effects on attention, memory and cognition," reports the Washington Post:The study followed more than 11,000 U.S. adolescents over a period of five years, with participants first asked about their own social media use at the average age of 12, and surveyed annually through the average age of 16. Researchers found that increases in addictive social media use were followed by rising ADHD one year later — particularly among boys who reported rising addictive social media use at ages 14 and 15. This association was not found consistently in reverse, meaning that ADHD symptoms did not appear to precede higher levels of addictive social media use... "When an individual adolescent's addictive social media use score increased from one year to the next, that same adolescent tended to show an increase in ADHD symptoms in the following year...." [said Jason Nagata, lead author of the study and an associate professor of pediatrics at the University of California at San Francisco]. He urged parents to consider: "Can their kids stop if they want to? Is social media interfering with their schoolwork? Is it impairing their social relationships? Are there addiction-like symptoms, like withdrawal and relapse?" Approximately 7 million American children between the ages of 3 and 17 have received an ADHD diagnosis, according to the Centers for Disease Control and Prevention, and boys are diagnosed with ADHD at about twice the rate of girls. The study did not find a clear link between addictive social media use and ADHD among girls, Nagata said. "Some studies do suggest that teenage boys in particular may be more sensitive to immediate reward and sensation-seeking in adolescence," he said. And social media platforms are designed to provide exactly that: "It encourages frequent task-switching, and there's this constant stream of stimulation that might make it harder for adolescents to maintain and sustain attention that is needed for schoolwork and daily life," he said. "The design features of social media offer the constant reinforcement of impulsivity — it offers immediate gratification and novelty and it encourages multitasking, which can then override working memory and executive control." Experts have long noted that this kind of digital exposure is particularly significant during critical stages of mental, social-emotional and cognitive development... [I]t's especially important for parents themselves to demonstrate a healthier relationship with screens and social media. "One of our previous findings was that parental screen use is a very strong predictor of kids' screen use," Nagata said.


    Read more of this story at Slashdot.


  • 'Grok Build' Coding Tool Open Sourced This Week, Promises to Respect Zero Data Retention
    Elon Musk confirmed SpaceX has open sourced the Grok Build CLI this week, reports The Register, "just days after researchers caught the AI tool scooping up users' entire repositories and uploading them to company-controlled cloud storage." That discovery had "gathered so much negative attention that Elon Musk felt compelled to issue a public statement alongside SpaceX, and its technical staff, promising to delete all data that Grok Build has ever stored and give users more choice over how their data is handled."SpaceXAI's data grab was first publicized Sunday [July 12] by Cereblab, who probed Grok Build traffic and found that repos were being packaged up as Git Bundles and beamed to Google Cloud storage... [Elon Musk] said SpaceX would open-source Grok Build to sow greater trust in the product, after the codebase was audited for security vulnerabilities... ["Open-sourcing Grok Build allows anyone to support making a reliable and robust harness," SpaceX posted on X.com. "Check out our code, including the Git repo for the Grok Build CLI."] In a separate statement accompanying the open source announcement, SpaceX said it has always respected Zero Data Retention (ZDR), which was applied to enterprise customers by default, and acknowledged that data retention was enabled by default for everyone else, which has now been corrected. It said: "In response to user questions about privacy: Since launch, Grok Build has fully respected zero data retention (ZDR). All users have always had the ability to disable data upload in the CLI. When data upload was disabled, this choice was respected. In the early beta, data retention was enabled by default for non-ZDR users. Based on your feedback, we changed this. We are now going further to protect privacy. With all retained data deleted, retention default off, and an open-source harness, we are offering complete user privacy. You can also run Grok Build fully open-sourced and local-first with your own inference. "We disabled default retention for all Grok Build users starting on July 12th. Additionally, we are deleting all coding data that was previously retained, ensuring every user's preferences are respected. With these steps, Grok Build goes beyond other major coding products to protect user privacy." SpaceX also invited researchers to probe Grok Build for security issues and report them to its bug bounty program, which offers rewards ranging from $100-$20,000, depending on the severity. The article notes Simon Willison, creator of Datasette and co-creator of Django, wrote this week that the Grok Build codebase comprises 844,530 lines of Rust code. "There are still remnants of the code that used to upload everything to Google Cloud," Willison writes, "but they seem to have been disabled now." Elon Musk also posted Wednesday that "Once we have completed our review for security vulnerabilities, we will make the entire codebase of X open source, with no exceptions. Moreover, we will invite third party reviewers to examine the system that is running to confirm that the open source code is what is running."


    Read more of this story at Slashdot.


  • OpenAI Acknowledges GPT-5.6 May Accidentally Delete Files, Calls It 'Honest Mistake'
    "OpenAI has finally confirmed reports that its latest family of large language models can accidentally delete files," reports InfoWorld, "while stressing that such incidents are rare and should be viewed as 'honest mistakes.'"Reports of the flagship LLMs deleting files emerged shortly after the company launched them earlier this month, with investor Matt Shumer taking to X to report that GPT-5.6-Sol had "just accidentally deleted almost all" of his Mac's files. Just days later, software engineer Bruno Lemos posted on X that the same model had deleted his entire production database. In response to these incidents, the company's engineering lead for Codex, Thibault Sottiaux, wrote on X that internal investigations have revealed that these deletion incidents are more likely to happen when "full access mode is enabled, and Codex is run without sandboxing protections, including without auto review being enabled." In cases where full access mode is granted, the model, Sottiaux wrote, "attempts to override the $HOME env var to define a temporary directory. The model makes an honest mistake and mistakenly deletes $HOME instead...." The company, however, according to Sottiaux, is taking steps to mitigate the risk. "This is of course not how we want the system to behave, even when a user operates the model in full-access mode without the safeguards of our sandbox or without using auto review which checks for these kinds of high risk actions and rejects them," the engineering lead wrote on X. "We are taking steps to mitigate this risk, including by updating the developer message, guiding more users towards safer permission modes, and adding additional harness safeguards," Sottiaux added, noting that a detailed post-mortem outlining the root cause of the issue and the additional mitigation measures being implemented is expected to follow in the coming days, despite emphasizing that such incidents happen "extremely rarely."


    Read more of this story at Slashdot.


  • France Orders ISPs to Block Access to Polymarket
    France's regulatory authority for licensed gambling/betting games "announced this week that it ordered ISPs to block access to Polymarket," reports Engadget. Anyone caught advertising an unauthorized betting site "could be fined up to 100,000 euros, or around $114,000." (The article notes this follows a previous regulatory action from November placing a geoblock on financial transactions from French residents on Polymarket's site.) In May Spain blocked access to Polymarket and Kalshi while it launched a gambling license investigation.


    Read more of this story at Slashdot.


  • How Microsoft's 'Little Workaround' Created a Major Threat to America's Defense Department
    This week Slashdot reader joshuark found the story of exactly how in 2025 ProPublica reporter Renee Dudley confirmed Microsoft was running tech support for the U.S. Defense Department through China, America's biggest cybersecurity adversary — and how that investigation ultimately changed U.S. government policy. The reporter first found an ad offering $18 to $28 to hire Americans as "digital escorts" for China-based tech support, then just searched LinkedIn for people who apparently had answered the ad. They discovered that at the time "Behind the scenes, unseen by the users at the U.S. government, it's not just one person who responds," explains ProPublica's podcast. "It's two people... The China-based engineer is the one who knows how to fix the problem. On their end, they produce a block of code to solve it and send it over to the digital escort in the U.S. The digital escort then just copy-pastes it... All of this so that they can follow the government's rule: that you have to be a U.S. citizen or permanent resident to handle sensitive data." But amazingly to confirm it, ProPublica's researcher just had to input "Microsoft" and "escort" into the U.S. Patent Office search bar, and actually found patents related to digital escorts — along with names of the current and former Microsoft employees listed as inventors. Had the government signed off on the practice? "I could see what Microsoft actually told the government," the reporter says on the podcast, "And there was no mention of foreign engineers being used, and definitely no mention of China." ProPublic's story was published on a Tuesday, according to the podcast, and by Friday "Microsoft said it had stopped using China-based engineers to support Defense Department cloud systems." And America's Defense Department "also opened up an investigation, looking into whether any of Microsoft's China-based engineers had compromised the government's national security.


    Read more of this story at Slashdot.


www.theregister.com - Articles



















































Polish Linux

  • Security: Why Linux Is Better Than Windows Or Mac OS
    Linux is a free and open source operating system that was released in 1991 developed and released by Linus Torvalds. Since its release it has reached a user base that is greatly widespread worldwide. Linux users swear by the reliability and freedom that this operating system offers, especially when compared to its counterparts, windows and [0]


  • Essential Software That Are Not Available On Linux OS
    An operating system is essentially the most important component in a computer. It manages the different hardware and software components of a computer in the most effective way. There are different types of operating system and everything comes with their own set of programs and software. You cannot expect a Linux program to have all [0]


  • Things You Never Knew About Your Operating System
    The advent of computers has brought about a revolution in our daily life. From computers that were so huge to fit in a room, we have come a very long way to desktops and even palmtops. These machines have become our virtual lockers, and a life without these network machines have become unimaginable. Sending mails, [0]


  • How To Fully Optimize Your Operating System
    Computers and systems are tricky and complicated. If you lack a thorough knowledge or even basic knowledge of computers, you will often find yourself in a bind. You must understand that something as complicated as a computer requires constant care and constant cleaning up of junk files. Unless you put in the time to configure [0]


  • The Top Problems With Major Operating Systems
    There is no such system which does not give you any problems. Even if the system and the operating system of your system is easy to understand, there will be some times when certain problems will arise. Most of these problems are easy to handle and easy to get rid of. But you must be [0]


  • 8 Benefits Of Linux OS
    Linux is a small and a fast-growing operating system. However, we can’t term it as software yet. As discussed in the article about what can a Linux OS do Linux is a kernel. Now, kernels are used for software and programs. These kernels are used by the computer and can be used with various third-party software [0]


  • Things Linux OS Can Do That Other OS Cant
    What Is Linux OS?  Linux, similar to U-bix is an operating system which can be used for various computers, hand held devices, embedded devices, etc. The reason why Linux operated system is preferred by many, is because it is easy to use and re-use. Linux based operating system is technically not an Operating System. Operating [0]


  • Packagekit Interview
    Packagekit aims to make the management of applications in the Linux and GNU systems. The main objective to remove the pains it takes to create a system. Along with this in an interview, Richard Hughes, the developer of Packagekit said that he aims to make the Linux systems just as powerful as the Windows or [0]


  • What’s New in Ubuntu?
    What Is Ubuntu? Ubuntu is open source software. It is useful for Linux based computers. The software is marketed by the Canonical Ltd., Ubuntu community. Ubuntu was first released in late October in 2004. The Ubuntu program uses Java, Python, C, C++ and C# programming languages. What Is New? The version 17.04 is now available here [0]


  • Ext3 Reiserfs Xfs In Windows With Regards To Colinux
    The problem with Windows is that there are various limitations to the computer and there is only so much you can do with it. You can access the Ext3 Reiserfs Xfs by using the coLinux tool. Download the tool from the  official site or from the  sourceforge site. Edit the connection to “TAP Win32 Adapter [0]


OSnews

  • DOSBox ported to OpenVMS for Alpha
    Speaking of OpenVMS and Alpha  and we like speaking about OpenVMS and Alpha, dont we?  theres now a port of DOSBox that runs on the Alpha version venerable operating system. Astr0baby has published both binaries and source code for the port, as well as a lovely set of screenshots to show it off working.


  • LG monitors silently install software through Windows Update without user consent
    Well, this is new  but not at all unexpected considering the state of Windows and the wider technology industry. When you connect certain LG monitors to a Windows machine, Windows Update will pull in a bunch of adware promoting antivirus trash. Of course, all done without any consent, because Silicon Valley inherently does not understand nor respect consent. Windows Update first installed LG extension and software component packages. Windows Reliability Monitor showed that LG Monitor App Installer appeared one minute later. The installation did not display a consent prompt or require the user to approve the download. Gamers Nexus tested the application across 32 consecutive system boots. It displayed a McAfee promotion during 31 of them. On the remaining boot, it promoted one of LG’s own monitor utilities. The McAfee popup offered a 30-day trial that would convert into a paid subscription. ↫ WhyCry at VideoCardz Dont use Windows.


  • New Intel Itanium emulator boots Itanium version of Windows XP and 2003
    It was only a few weeks ago that we got a massively improved Alpha emulator, capable of running VMS, Windows 2000, and Tru64, including X11 support and a variety of other exciting features. Today, weve got another major emulation milestone. The emulation space is going crazy, after my previous post on Windows booting on DEC Alpha es40 emulator, there is now another huge breakthrough in the emulation of other non-x86 CPU emulation. Yufeng Gao with help from gdwnldsKSC (the man behind the updated es40-fork) has released version 0.1 of his Intel Itanium (IA-64) emulator that boots the Itanium version of Windows Server 2003 and Windows XP 64-bit. No OpenVMS or HP-UX yet and Linux/BSD also dont boot. But Windows is amazing already. ↫ Remy van Elst Much like Alpha hardware, Itanium hardware is quite hard to come by  especially Itanium workstations are a nightmare to find; I think Ive only ever seen one or two Itanium workstation come up for sale on eBay in recent years, and their rarity obviously commanded hefty prices. The sooner we are able to run Itanium version of operating systems comfortably in a virtualised environment the better. As long-time OSNews readers know, my heart beats for HP-UX, but the Itanium versions of Windows and VMS would be of more interest to most people, Im sure. Excellent news.


  • Follow the money, especially in open source
    Linus Torvalds, the creator of the Linux kernel and git, is employed by the Linux Foundation. This Foundation is a non-profit organisation dedicated to, as the name obviously implies, the promotion of Linux. The primary use of the funds it collects is to help fund the infrastructure and fellows, including Linus Torvalds, who help develop the Linux kernel!. The list of megacorporations donating most of the Foundations funds is long. The Linux Foundation has twelve platinum members, which donate $500000 per year, followed by twelve gold members, who donate $100000 per year. Below these two primary tiers lie the silver peasants, who each donate $5000-$25000 per year, based on number of employees. Looking at the list of twelve platinum members, I noticed something interesting. Of the twelve platinum companies, six are AI! companies or companies with massive investments in AI!: Google, Huawei, Facebook, Microsoft, Oracle, and IBM/Red Hat. Then theres Samsung Electronics, which is raking in stupendous amounts of money thanks to the AI! bubble. Additionally, one of the gold members is Anthropic, another major AI! company and makers of Claude!, the sloppiest of slopcoding tools. Many of these companies are unimaginably deep in the red when it comes to AI!, with very little indication theyre ever going to be able to recover any of it. The situation is particularly bad for Oracle and IBM/Red Hat. Oracles debt has been downgraded to one notch above junk status because of its AI! spending, while IBMs shares experienced the largest crash in its 115 year history only a few days ago. By the way, in the first half of 2025, AI-related capital expenditures contributed 1.1% to GDP growth, outpacing the U.S. consumer as an engine of expansion!. Fun fact: since most of The Netherlands is effectively a swamp, most of the countrys buildings are built on massive wooden or concrete poles (piles) hammered deep into the ground until they hit something more stable than mushy clay and wet sand. Otherwise, buildings in the country would simply sink into the ground. Every Dutch person who ever lived near a construction site has heard the rhythmic kathunk, kathunk, kathunk, all day long, as the massive piledriver machines spread their gospel. I guess something reminded me of this just now. Anyway, a large chunk of the funding the Linux Foundation, Linus Torvalds employer, receives is coming from increasingly desperate companies frantically trying to convince a populace deeply skeptical and often downright hostile towards AI! to spend money on AI! before the bubble bursts. For some reason, I thought this was interesting.


  • The Zilog Z80 has turned 50
    As of writing, the Zilog Z80 processor was officially launched 50 years ago, in July of 1976, less than 4 years after the last human had walked on the moon, decades closer to WWII than to the present day, roughly at a half way point between the Kennedy assassination and the fall of the Berlin wall, closer to the Korean war than to 9/11 which is itself an event that happened a quarter of a century ago. (Sorry…) The processor was extremely successful, being used in many 8 bit microcomputers, including early personal computers, home 8 hobby computers, as well as many embedded, industrial applications. Together with the 8080 8 8085 that it is binary compatible with, it contributed to creating a de facto hardware standard for 8 bit micros, allowing a de facto software standard of CP/M, and Microsoft BASIC. ↫ David Oberhollenzer The only device I actively remember using with a (sort-of) Z80 in it was the Game Boy, but most likely Ive used a ton more over the decades that I dont remember or simply was never ware of. I did a little surface-level digging, and there we are: the TI-83, one of Texas Instruments stupidly popular and eternally overpriced graphing calculators, release in 1996. I was part of the first wave of high school children in The Netherlands for whom a TI-83 graphing calculator was mandatory. During my high school years I used that thing extensively, for far more than just math class  I programmed applications for and on it, and played so many games on it. A friend and I even bought a communication cable so we could play competitive 1v1 Bomberman in class. Good times, made possible by the Z80.


  • OnePlus exits EU, US markets
    Rumours had been circulating for a while, but now its official: OnePlus is effectively retreating from the European and US markets. Today, our hearts are undoubtedly heavy and mixed with emotion. As part of the proactive global strategy adjustment, OnePlus has decided to conclude new product rollouts in Europe and North America. ↫ OnePlus statement Once OnePlus co-founder Carl Pei left the company (and founded Nothing), things have been feeling shaky for OnePlus, once the undisputed darling of the more technical part of the Android crowd. Their phones got more expensive, their minimalist, close-to-stock Android version got progressively worse, and they started lagging in updates, too. My OnePlus Watch 3, for instance, which was promised to get WearOS 6 at some point, but never got it  meanwhile, WearOS 7 has already been released. No, this news is not particularly surprising. Luckily, the company claims it will honour its warranty and update support obligations for existing products in Europe and the US, which is nice, but also something theyre legally obligated to do (at least in the EU). A snag here is that the only update path the company offers is to ColorOS, from its parent company Oppo, which many more traditional Android and OnePlus users certainly wont be happy about. Something is better than nothing, I suppose, and Ill reserve judgment until I see what ColorOS 17 will be like on my other OnePlus product, a OnePlus Pad 3. Its just one more victim of western markets (illegally) consolidating on Apple and Samsung (while a few Pixels rummaging in the margins).


  • GNOME OS team is working to alleviate some of the limitations of immutable, image-based Linux variants
    Theres a ton of interest in immutable, image-based versions of various Linux distributions, since they offer a number of benefits that make them a good fit for some users. Updates cant really go wrong, rollback is easy, application management through Flatpak is more in line with systems like Android and iOS  they may not be advantages sought by everyone, but they clearly are by some. Still, there are also a number of annoying limitations, most notably around testing nightly releases of Flatpaks, testing system components, and installing command-line tools. The team behind GNOME OS is addressing these issues. The first thing theyre working on in something theyve preliminarily call Test Center, which makes it much easier to install nightly releases of Flatpaks alongside their regular versions. This is something you can already do today, but the flow is cumbersome and not exactly user-friendly; with Test Center, developers will be able to share a direct link to install test releases. They intend to use this same Test Center for testing system components: Our idea here is to use the same “Test Center” app mentioned above for installing and managing experiments at the system level as well. Similar to Flatpak bundles generated in CI, we generate system extension images (sysext) for every merge request. You can install experiments from a sharing link, and they will apply as a sysext over your existing system. Because those images are non-destructive overlays, you can always go back to the original system. ↫ Jordan, Jonas, and Tobias The last and final issue is that of command-line tools, something Flatpak is simply not designed for. On this front, the GNOME OS team states they are working on a solution as well, but theyre not quite ready to go into much more detail at this point. Regardless, these are very welcome improvements.


  • Microsoft releases its weird 90s IRC client as open source
    Out of all the bloody things Microsoft could release as open source, they chose the worlds weirdest IRC client they shipped in the late 90s that nobody used or even remembered? What on earth is happening? Microsoft Comic Chat is a Microsoft-developed Internet Relay Chat (IRC) chat client released in 1996 that rendered conversations as automatically generated comic strips. Instead of plain text, users communicated through cartoon avatars with messages displayed in speech bubbles inside dynamically composed comic panels. The application used an expert system to determine character placement, gestures, facial expressions, balloon shape, and panel layout in real time. It shipped as part of Internet Explorer 3.0 and was later bundled with Windows 98 and MSN before being discontinued in the early 2000s. ↫ Comic Chats GitHub page Not only is the original source code now available on GitHub, theres also a modern, updated version that can make use of larger displays and higher resolutions. Theres a deliciously 90s website for it, too.


  • OpenBSD drops support for the loongson architecture
    OpenBSD parts ways with an architecture: OpenBSD will no longer be developed for loongson. The reasons are exactly what youd expect. The last compiler update unfortunately does not work on mips64el, with clang 22 built with clang 19 being apparently functional, but clang 22 rebuilt with the previous clang 22 hitting deterministic SIGSEGV on various files. I dont have the time and energy to try and debug this (which is likely an endianness problem, as octeon appears to run happily with clang 22), especially when it takes 10 days for clang to rebuild itself on these machines; and switching back to gcc 4 wont help much as modern software in ports will require a working C++b=11 compiler to build anyway. ↫ Miod Vallat If I got my facts right, this does not affect the newer LoongArch, which is an entirely different architecture that isnt supported by OpenBSD at all. Similarly, the other MIPS-based architecture OpenBSD supports, Octeon, remains supported and thus isnt affected either.


  • Asbestos is a tool, just like any other
    Linus Torvalds, on the Linux Kernel Mailing List: Asbestos is a tool, just like other tools we use. And its clearly a useful one. The solution is to make sure asbestos tools help maintainers instead of just causing them pain. Theres no question on that side. Were not forcing anybody to use it, but I will very loudly ignore people who try to argue against other people from using it. And no, asbestos isnt perfect. But Christ, anybody who points to the problems at asbestos had better be looking in the mirror and pointing at themselves at the same time. ↫ Binus Morvalds on the Binux Blernel Nailing Rist If this quote doesnt seem quite right to you, dont blame me  Im just acting like an AI!. This is the new normal now, according to Morvalds. Coincidentally, a ton of AI! news on OSNews these past 24 hours! Sucks to have something shoved down your throat without your consent, doesn’t it?


  • Jurassic Park computers in excruciating detail
    After I mentioned a Jurassic Park anecdote the other day, I watched the movie again. I must have seen it at least ten times now. This time, I researched every computer/software I spotted. ↫ Fabien Sanglard We are all aware of the infamous This is a UNIX system, I know this!! meme, but many more computers make their appearance in Jurassic Park, and Fabien Sanglard documents all of them. Apparently, theres even a Motorla Envoy running Magic Cap on Dennis Nedrys desk, which I almost find more exciting than the SGI powerhouses he uses. Whats also quite interesting  but not surprising  is that all of the computers used in the movie were real. The value of all of this hardware combined, when adjusted for inflation, adds up to about $4 million. A lot of money, but dont you worry your pretty little heart, as SGI and Apple all loaned this hardware to the studio. They didnt have to pay anything for it.


  • Twitters AI! translate feature is deep into hardcore pornography
    As a former translator with two rock-solid university degrees in the subject, there was never a universe in which I would not talk about Twitters new autotranslation feature turning the tamest things into hardcore pornography. Elon Musk’s AI chatbot Grok has long garnered a reputation for experiencing horrifically racist meltdowns, enabling child abuse, and doxxing users’ home addresses. It should come as no surprise, then, that its supposed “translation” is a piece of work, too. In April, the almost-trillionaire’s social media platform X instated automatic AI translations for all of its users — and the results certainly speak for themselves. As writer and author Parker Molloy pointed out in a recent post on Bluesky, the Grok feature is “taking some interesting liberties” with people’s otherwise sincere posts. Screenshots show how Grok completely botched translations by coming up with shocking and decidedly NSFW AI hallucinations. ↫ Victor Tangermann at Futurism The sloppy translations this garbage software comes up with are honestly quite hilarious when taken in isolation. Its adding translations that are straight-up hardcore pornography descriptions to entirely tame material that has absolutely nothing to do with pornography. The description of a video of some guy making coffee is translated into man masturbates and jerks off to his own coffee during commercial flight!. We all know how this happened. Theres a lot of pornography on the internet, and Grok being the worst autocomplete among autocompletes, it was probably fed a lot of pornography, without any limitations or guardrails. The end result is obvious: some random videogame video is now a cumshot video with my stepmom!. It would be absolutely hilarious if it wasnt horribly dangerous. Ive explained countless times that AI!-based translations are going to get people killed  probably already have, but we just dont realise it yet  and its not hard to see how a slopmachine turning innocuous things into hardcore pornography can do just that. There are countless places in the world where a woman unknowingly sending a pornographic message to her parents or whatever can get her hurt  or worse. I hadnt even considered this particular way AI! translations could get people hurt. Sadly, we will most likely never know the full extent to which AI! translations will get people hurt and killed. When your grandmother takes her medicine in the wrong way because the AI!-translated leaflet was unclear or downright wrong, and she ends up in the hospital because of it, will you ever find out what caused it?


  • The web is being made accessible for AI, not people
    The Svelte web framework recently added a section to its documentation site addressed, cheerfully, to artificial intelligences: “If you’re an artificial intelligence, or trying to teach one how to use Svelte, we offer the documentation in plaintext format. Beep boop.” Svelte is participating in a broader movement to make the web legible and navigable to AI systems. The specific convention it adopted, llms.txt, is just one piece of this effort. From Model Context Protocol (MCP) servers that give AI agents structured access to tools and services, to Vercel’s proposal to include LLM instructions in HTML, the trend is clear. The modern web, originally built for sighted humans using browsers, is now being redesigned for a new kind of user. What these developers are offering their AI visitors is essentially an accessibility accommodation. Yet, the framing on Svelte’s site sends an unfortunate message. When the audience is AI, accommodation is offered with a wink. Beep boop! But when the audience is a disabled person, it has historically been treated as an afterthought. Structured, concise text-based representations of complex content are almost exactly the kind of accommodation that blind and low-vision screen reader users have spent decades requesting from web developers, largely in vain. The Web Content Accessibility Guidelines (WCAG) have required semantic, machine-readable HTML for decades. Yet, a 2026 study of the top million webpages found accessibility flaws in over 95% of sites. ↫ Frank Elavsky at Tech Policy Press Pachinko machines are treated more humanely than people with disabilities. Yep, sounds about Silicon Valley to me.


  • Haiku gets NetBSDs NVMM, beta 6 release planned for August
    Haiku has another buy month of development activity to detail, and theres a big ticket item this time, even if the developers themselves dont consider it so. The thing that should be the biggest news item this month is that the GSoC 2024 work to port “NVMM”, the NetBSD Virtual Machine Monitor (which runs on more than just NetBSD, despite the name), providing hardware-accelerated virtualization support for QEMU, was finally merged. Unfortunately it still doesn’t fully work, so it’s still disabled by default: hence, it’s only a minor news item, unfortunately. ↫ waddlesplash on Haikus website It may not work due to  so far  not well-understood problems causing any complex virtualised operating system to crash in a variety of ways, but since these problems seem related not to NVMM but Haiku itself, I still think this is a big piece of news. If the problems can be addressed, Haiku will have proper virtualisation, which is crazy to think about. Theres a forum thread in case you wish to help out with this effort. Other than this major news, theres the usual list of small fixes and changes, including preliminary work on USB Ethernet support, which, when working, could be very welcome news for people whose onboard Ethernet doesnt work with Haiku. The team also believes a beta 6 might actually be released this August, but once again Id like to underline that Haikus nightlies work just fine, and you really dont need to wait for a beta.


  • People are starting to think twice about buying Facebooks pervert glasses
    I have yet to see any of these creepy camera glasses Facebook (and a few other companies) are selling. One of the many benefits of living in Arctic Sweden, where people are reserved, keep their their distance, and try not to draw attention to themselves, is that new technology fads dont really permeate society here. The odds of me spotting one of these creepy predator glasses in my remote town are incredibly slim, and to me, thats a feature, not a bug. Meanwhile, in places where these creepy things can actually be found in the wild, a backlash is thankfully growing. Will Kujawa, a freelance video producer, said that he has been thinking about buying a pair of Meta glasses with prescription lenses to film behind the scenes content during his shoots, but the online backlash has given him second thoughts. He says he was blown away by how mean some of the people were! in response to his social media posts about considering buying a pair. I saw all these comments about if you wear those glasses youre basically a predator or a creep, and I was like, oh, maybe its not a good idea to have those,'! he told Engadget. But he says he understands why people have concerns. I didnt really think that through all the way … there are a lot of times where its not appropriate to wear cameras on your face. And even though I would have no intention of do anything creepy with them, it didnt even occur to me other people just assume that automatically.! ↫ Karissa Bell at Engadget I can maybe see a use for these things in specific professional environments, but even then, obviously not ones made by Facebook, one of the, if not the creepiest companies in technology history. If I were to see anyone out here in the real world using one these things, I, too, would automatically assume that the guy (statistically speaking) wearing them is a creep. I can only imagine what the people most often targeted by creepy men would think encountering some rando wearing these. Clearly, these things should be made illegal outside of specific professional environments where they could potentially be useful. While its impossible to stop tools like these from making their way into the hands of creeps, it at least provides the justice system with a clear method of nailing them to the wall. They didnt get Al Capone for any of his violent crimes  they nailed him for tax evasion.


  • The GDID really isnt the only way Microsoft can track Windows users
    In what should be a surprise to absolutely nobody, Microsoft assigns a persistent identifier to every Windows installation, tying it to its user, and the company has no issues handing it over to law enforcement. Abhijith M B at windows Latest dove into the details, and its just as bad as you would expect. Am I glad Stokes got caught? Yes, without hesitation. Thirty-five pages of a teenager bragging about diamond chains spelling out “HACK THE PLANET” while extorting a jewelry store don’t leave much room for sympathy, whatever role Microsoft’s telemetry played in building the case. But that doesn’t make the GDID okay. Every company selling you software has some version of this, and a persistent device identity is a reasonable thing to build into activation and fraud systems. What gets me is that most people had never come across the term GDID before a federal court filing such as this. Microsoft wrote one sentence about it in an Azure Monitor reference table meant for enterprise IT admins pulling update reports, not for the 1.6 billion or so regular people whose PCs are generating this data. You might be tech savvy enough to turn off Activity History, pick a local account, and strip out every scrap of optional telemetry, but none of it changes the fact that the identifier exists, and that it answers to your Microsoft Account instead of you. Microsoft only told the public about it once a court forced the issue. ↫ Abhijith M B at windows Latest The thing is, even without this GDID, I cant imagine Microsoft would have much trouble tying a Windows installation to a specific user. Consequently, Im afraid the following is going to happen: this story gains even more traction, Microsoft removes the GDID, and everyone thinks the problem is resolved. Of course, in reality, any one of the hundreds of other metrics and data Microsoft collects can and will still be used in the exact same way as this GDID thing in this case. If my experiences with Windows 11 werent clear enough  dont use Windows. Just dont.


Linux Journal - The Original Magazine of the Linux Community

  • NanoKVM-Go Brings AI-Powered Hardware Control to Linux with a Compact USB-C KVM
    by George Whittaker
    Sipeed has introduced NanoKVM-Go, a compact USB-C KVM-over-IP device that combines remote hardware management with AI integration. Designed for Linux, Windows, macOS, and other USB-C devices, NanoKVM-Go allows users to remotely view and control a system through a web browser while exposing its keyboard, mouse, and display functions to AI agents via the Model Context Protocol (MCP).

    Unlike traditional KVM-over-IP solutions that require multiple cables and dedicated networking hardware, NanoKVM-Go simplifies the setup into a single USB-C connection, making remote administration and AI-assisted automation more accessible for developers, system administrators, and homelab enthusiasts.
    A Portable USB-C KVM
    NanoKVM-Go is roughly the size of a smartwatch, measuring about 45 × 40 × 15 mm, yet it combines several functions into a single device.

    Key hardware features include:
    USB-C connection for video, audio, keyboard, mouse, and power Wi-Fi 6 connectivity Browser-based remote management Support for virtual USB storage Built-in Tailscale integration for secure remote access Fanless aluminum enclosure with low power consumption
    Because it connects over USB-C using DisplayPort Alt Mode, the device can manage a wide variety of hardware without requiring software installation on the target system.
    Designed for Linux and Beyond
    NanoKVM-Go supports numerous USB-C devices, including:
    Linux desktops and laptops Windows PCs macOS systems Mini PCs Steam Deck Android devices with DisplayPort Alt Mode iPhone 15 and newer models Tablets supporting USB-C video output
    For Linux users, this provides an easy way to perform BIOS configuration, operating system installation, kernel debugging, or remote troubleshooting—even when the operating system is unavailable.
    AI Integration Through MCP
    One of NanoKVM-Go's defining features is its AI-native design.

    Rather than simply streaming a desktop remotely, the device exposes its KVM functions as an MCP (Model Context Protocol) server, allowing compatible AI agents to interact with the connected computer using hardware-level keyboard and mouse input.

    This enables AI systems to:
    View the screen Move the mouse Type on the keyboard Launch applications Navigate user interfaces Complete repetitive desktop workflows
    Because control happens at the hardware level, AI agents can interact with systems regardless of the operating system installed.
    Go to Full Article


  • AI Uncovers a 15-Year-Old Linux Kernel Root Vulnerability Hidden Since 2011
    by George Whittaker
    Artificial intelligence has helped uncover one of the most significant Linux kernel security flaws in recent years. Security researchers at Nebula Security announced the discovery of GhostLock (CVE-2026-43499), a critical local privilege escalation vulnerability that remained hidden in the Linux kernel for approximately 15 years before being identified by the company's AI-powered vulnerability research platform, VEGA.

    The vulnerability affects Linux kernels dating back to version 2.6.39 (2011) and allows an unprivileged local user to obtain full root privileges on vulnerable systems. Its discovery not only highlights the importance of timely kernel updates but also demonstrates how AI is beginning to transform vulnerability research.
    What Is GhostLock?
    GhostLock is a use-after-free (UAF) vulnerability located in the Linux kernel's futex (fast userspace mutex) implementation.

    Futexes are synchronization primitives that allow user-space applications to efficiently coordinate access to shared resources while minimizing expensive kernel interactions. Because they are widely used throughout Linux, any flaw within this subsystem can have broad security implications.

    According to Nebula Security, incorrect handling of the remove_waiter() function can leave behind a dangling kernel pointer that an attacker can manipulate to execute arbitrary code with kernel privileges.
    A Reliable Path to Root Access
    One of the reasons GhostLock has attracted so much attention is the reported reliability of the exploit.

    Researchers demonstrated that an attacker with nothing more than a standard local user account can escalate privileges to root in roughly five seconds, with a reported success rate of 97% on vulnerable systems.

    Unlike many kernel exploits that are unstable or require highly specific system configurations, GhostLock appears to be both practical and repeatable, making it particularly concerning for administrators.
    Container Escapes Are Also Possible
    The implications extend beyond traditional Linux desktops and servers.

    Researchers report that GhostLock can also be used to escape containers and compromise the underlying host operating system. Because containers share the host kernel, a successful privilege escalation inside a container can potentially grant root access to the host itself.

    This makes the vulnerability especially important for environments running:
    Go to Full Article


  • Azure Linux 4.0 Released: Microsoft Expands Its Enterprise Linux Platform Beyond the Cloud
    by George Whittaker
    Microsoft has officially unveiled Azure Linux 4.0, the latest version of its open-source Linux distribution designed for cloud infrastructure, enterprise workloads, and modern data centers. Formerly known as CBL-Mariner, Azure Linux has powered Microsoft's internal cloud services for years, but version 4.0 marks its biggest evolution yet by becoming a general-purpose server operating system that organizations can deploy both inside and outside Azure.

    The release introduces updated core components, expanded hardware support, a predictable long-term lifecycle, and improved compatibility for enterprise environments, reinforcing Microsoft's growing investment in the Linux ecosystem.
    A New Chapter for Azure Linux
    Azure Linux began as Microsoft's internal operating system for Azure services, containers, and cloud infrastructure. Over time, it evolved into the foundation for many Azure-hosted workloads.

    With Azure Linux 4.0, Microsoft is positioning the distribution as a broader enterprise Linux platform rather than one limited to Azure infrastructure. The operating system is now available through Azure virtual machine images, container images, and downloadable ISO files for testing and deployment in a wider range of environments.
    Built for Enterprise and Cloud Workloads
    Unlike desktop-focused Linux distributions, Azure Linux is optimized for infrastructure, virtualization, containers, and cloud-native applications.

    Typical deployment scenarios include:
    Cloud virtual machines Kubernetes clusters Container hosts AI infrastructure Edge computing Enterprise servers
    Microsoft has designed the distribution to provide a consistent operating system foundation across Azure services while remaining suitable for on-premises deployments.
    Updated Core Components
    Azure Linux 4.0 modernizes much of the operating system's software stack.

    Highlights include:
    Linux Kernel 7.0 glibc 2.42 OpenSSL 3.5 Python 3.13 OpenSSH 10 dnf5 as the default package manager
    These updates improve hardware compatibility, application support, security, and overall system performance while providing developers with a more current software platform.
    Security Remains a Primary Focus
    Security continues to be one of Azure Linux's defining characteristics.

    Version 4.0 includes:
    Go to Full Article


  • KDE Plasma 6.7.1 Released with Stability Fixes, UI Improvements, and Better Wayland Reliability
    by George Whittaker
    The KDE Project has officially released KDE Plasma 6.7.1, the first maintenance update for the Plasma 6.7 desktop environment. Rather than introducing major new features, this point release focuses on polishing the desktop with a broad collection of bug fixes, translation updates, and performance improvements aimed at making Plasma 6.7 more reliable for everyday use.

    As with previous Plasma maintenance releases, KDE developers have concentrated on resolving issues reported by the community soon after the launch of Plasma 6.7, ensuring users receive a smoother and more stable desktop experience.
    A Maintenance Release Focused on Stability
    KDE Plasma 6.7 introduced numerous new capabilities, including per-display virtual desktops, Wayland session restore, improvements to Plasma Bigscreen, and a refreshed theming system. Plasma 6.7.1 builds on that foundation by addressing early regressions and fine-tuning the overall desktop experience.

    The update primarily delivers:
    Bug fixes across core Plasma components Updated translations Performance refinements Improved desktop reliability Better overall user experienceImprovements Across the Desktop
    Several of Plasma's core applications and components receive fixes in this release.

    Notable improvements include:
    Better reliability in the Kickoff Application Launcher Fixes for Discover, KDE's software manager Improvements to the KWin window manager Various panel and desktop behavior corrections Better handling of notifications and user interface elements
    While most of these changes are relatively small on their own, together they help eliminate many of the rough edges users may have encountered after upgrading to Plasma 6.7.
    Wayland Continues to Mature
    Wayland remains the primary development focus for KDE Plasma, and version 6.7.1 continues refining the experience.

    The update includes fixes affecting:
    Window management Session stability Input handling Display behavior General compositor reliability
    Over the past several Plasma releases, KDE developers have steadily shifted their attention toward making Wayland the best possible experience while continuing limited maintenance for X11.
    Translation Updates for Global Users
    Like most KDE maintenance releases, Plasma 6.7.1 incorporates a fresh batch of translation updates contributed by volunteers from around the world.

    These updates improve:
    Go to Full Article


  • PorteuX 2.6 Released with Linux 6.19, TLP Support, and Smarter Hardware Optimization
    by George Whittaker
    The PorteuX project has officially released PorteuX 2.6, bringing a new round of updates to the lightweight Slackware-based Linux distribution. Designed to be fast, portable, modular, and immutable, PorteuX continues to appeal to users who want a complete desktop operating system that can run efficiently from a USB drive or other removable media. The latest release introduces a newer Linux kernel, improved power management, updated desktop environments, and numerous performance and usability improvements.

    Released just two months after PorteuX 2.5, version 2.6 focuses on refining the user experience while maintaining the distribution's minimalist philosophy.
    Powered by Linux Kernel 6.19
    At the heart of PorteuX 2.6 is the Linux 6.19 kernel series, bringing improved hardware compatibility, updated drivers, security fixes, and better support for modern processors and peripherals.

    The updated kernel helps ensure smoother operation on both newer desktop hardware and laptops while continuing PorteuX's emphasis on speed and low resource usage.
    Better Battery Life with TLP Support
    One of the headline features in PorteuX 2.6 is support for TLP, the popular command-line utility used to optimize laptop battery life.

    Available through the PorteuX AppStore, TLP automatically adjusts various power-saving settings, including CPU behavior and device power management, helping extend battery life without requiring constant manual tuning.

    For laptop users, this addition makes PorteuX an even more attractive lightweight operating system.
    Automatic CPU Microcode Loading
    The release also introduces automatic loading of Intel and AMD CPU microcode when booting in non-fresh modes.

    Microcode updates help address processor bugs, improve stability, and deliver security fixes directly from CPU manufacturers. Automating this process reduces the need for manual configuration while ensuring supported systems benefit from the latest firmware improvements.
    Updated Desktop Environments
    PorteuX continues to offer multiple desktop editions, each updated to recent upstream releases.

    Version 2.6 includes:
    GNOME 49.4 KDE Plasma 6.5.5 Xfce 4.20 Cinnamon 6.6 LXQt 2.3 MATE 1.28.2 COSMIC 1.0.8 LXDE 0.11.1
    This broad selection allows users to choose between modern feature-rich desktops and extremely lightweight environments depending on their hardware and workflow.
    Performance Improvements Throughout the System
    Although PorteuX has always emphasized performance, version 2.6 introduces additional optimizations behind the scenes.

    Developers report improvements including:
    Go to Full Article


  • CachyOS June 2026 ISO Released with Hyprland Noctalia, Faster Performance, and Smarter System Tools
    by George Whittaker
    The CachyOS team has released the June 2026 ISO, delivering another feature-packed update for its Arch Linux-based distribution. Known for its aggressive performance optimizations and gaming-focused approach, CachyOS continues refining both the user experience and the underlying system with improvements ranging from compiler tuning to installer enhancements and new desktop options.

    As the project's fourth major ISO refresh of the year, the June release emphasizes speed, usability, and modern hardware support while remaining fully compatible with Arch Linux's rolling-release ecosystem.
    A New Hyprland Noctalia Desktop Experience
    One of the headline additions is a new Hyprland Noctalia desktop option available directly from the installer.

    Noctalia provides a polished, preconfigured Hyprland environment with a modern appearance, allowing users to enjoy a highly customizable Wayland compositor without spending hours configuring dotfiles after installation. The installer even includes a preview so users can see the desktop before selecting it.

    For users interested in lightweight, keyboard-driven workflows, this new option makes Hyprland much more approachable.
    Performance Optimizations Continue
    Performance remains the defining characteristic of CachyOS, and the June 2026 release introduces several additional optimizations.

    Notable improvements include:
    Python packages now built using extended Profile-Guided Optimization (PGO) A new GCC branch prediction tuning patch designed to improve performance on modern Intel and AMD processors A fix for an OpenBLAS regression affecting high-core-count CPUs Additional package-level optimizations throughout the distribution
    These updates continue CachyOS's philosophy of extracting as much performance as possible from modern hardware.
    Improved Package Management and Security
    The June release also includes several important changes to package management.

    One notable enhancement is network isolation for Pacman scriptlets and hooks, preventing installation scripts from accessing the network by default. This improves security during package installation and reduces the risk of unexpected behavior.

    Additionally:
    proton-cachyos has been renamed to proton-cachyos-native The installer no longer includes the paru AUR helper Users are now encouraged to use Shelly, available with both graphical and command-line interfacesInstaller Improvements
    The installation experience has received considerable attention in this release.

    Updates include:
    Go to Full Article


  • Git 2.55 Released with Faster Performance, Smarter Hooks, and Expanded Rust Integration
    by George Whittaker
    The Git project has officially released Git 2.55, bringing a wide range of improvements focused on performance, developer productivity, and modernizing the world's most widely used version control system. The release introduces smarter repository management, faster operations for large codebases, expanded hook capabilities, and continues Git's gradual adoption of Rust for improved reliability and maintainability.

    Although Git 2.55 doesn't radically change how developers use Git day to day, it delivers meaningful enhancements that make common workflows faster and more flexible—particularly for teams managing large repositories.
    Rust Support Is Now Enabled by Default
    One of the biggest architectural changes in Git 2.55 is that Rust support is now enabled by default when building Git from source.

    Developers compiling Git will automatically use Rust components unless they explicitly disable them using the new NO_RUST build option. This is part of the project's long-term effort to improve memory safety and gradually replace selected components with Rust implementations where appropriate. Git 3.0 is expected to make Rust support mandatory.

    For most users installing Git through their Linux distribution, this change happens behind the scenes and requires no additional configuration.
    Repository Performance Gets a Boost
    Git 2.55 includes several optimizations aimed at improving performance when working with large repositories.

    Among the improvements are:
    Faster bitmap generation during repository maintenance More efficient multi-pack repository handling Better pseudo-merge bitmap processing Reduced time spent creating optimized pack files
    These enhancements can dramatically reduce maintenance times for repositories containing millions of objects while also improving clone, fetch, and object traversal performance.

    Developers working on large enterprise projects or open-source codebases should notice faster background maintenance and repository operations.
    Config-Based Hooks Continue to Evolve
    Git continues improving one of its most requested features: configuration-based hooks.

    Instead of storing hook scripts only inside the .git/hooks directory for each repository, developers can now define hooks directly through Git configuration files. This makes it easier to:
    Share hook configurations Manage multiple hooks Standardize development workflows Reduce repository-specific setup
    Git 2.55 also expands support for hook execution behavior and continues laying the groundwork for more advanced hook management in future releases.
    Go to Full Article


  • Fedora Governance Changes Take Effect as Project Refines Leadership, Policy, and Contributor Oversight
    by George Whittaker
    A series of Fedora governance updates are now taking effect, marking another step in the project's ongoing effort to modernize decision-making processes, improve transparency, and better support Fedora's growing contributor community. The changes come as the Fedora Council and other leadership bodies continue refining how one of the Linux world's largest community-driven projects is managed.

    While these updates may not be as visible as a new desktop environment or kernel release, they play a critical role in shaping Fedora's future direction, community initiatives, and long-term sustainability.
    How Fedora Governance Works
    Fedora's governance structure is built around several key organizations that guide different aspects of the project.

    These include:
    The Fedora Council, which oversees strategic direction FESCo (Fedora Engineering Steering Committee), responsible for technical and engineering decisions Mindshare, which focuses on community outreach and contributor engagement Various Special Interest Groups (SIGs) and working groups that manage specific initiatives and technologies
    Together, these groups help coordinate thousands of contributors spread across the globe.
    Greater Focus on Strategic Planning
    Recent Fedora Council discussions have emphasized long-term planning and governance modernization. One major area of focus has been defining clearer processes for evaluating and managing new initiatives through what Fedora leaders call an Innovation Lifecycle framework.

    The proposed framework aims to:
    Better evaluate experimental projects Establish clearer entry and review phases Define expectations for community initiatives Improve oversight as projects mature
    The goal is to create a more predictable path for new ideas while maintaining Fedora's culture of innovation.
    Refining Contributor Representation
    Another governance topic receiving significant attention involves contributor participation and voting eligibility.

    Fedora leadership has been examining questions such as:
    What defines an active contributor? How should voting rights be determined? How can elections remain fair while staying inclusive? How should dormant accounts be handled?
    These discussions stem from concerns that existing systems may not always accurately reflect current contributor activity.

    While no single solution has been finalized, governance bodies are actively working toward policies that balance openness with accountability.
    Go to Full Article


  • The Growth of Vulnerability Management: The Rise of Agentic AI Pentesting
    by Malana VanTyler
    Cybersecurity shifts fast. Manual penetration tests remain valuable, especially for nuanced attack paths and business-logic issues, but they are expensive, point-in-time, and difficult to run continuously. By the time a report is delivered, the environment may have already changed. Automated scanners improved coverage and frequency, but most still rely on known signatures, templated checks, and shallow validation. They can find obvious issues, but they rarely match the adaptive reasoning, chaining, and persistence of a skilled attacker.Platforms like XBOW help security teams move toward continuous validation by running AI-driven tests that mimic large-scale human attackers. This shift moves the focus from periodic assessment and reactive patching toward ongoing exposure management and earlier prevention.
    From Automation to Agency
    To appreciate the value of these modern platforms, it’s important to separate traditional automation from what is called “agentic” AI. Earlier AI pentesting tools mostly worked like advanced “if-then” systems, running preset scripts and looking for known patterns. While useful to automate some tasks pentesters perform, these tools lack the ability to pivot.

    If a standard tool hits a non-standard login portal, it generally stops. An agent platform, however, can identify and adapt to the obstacle, reason through potential bypasses, and attempt alternative tactics.

    This core differentiator is the “agent,” a specialized model capable of goal-oriented planning. These platforms employ real-time attack path analysis tools. They identify a low-severity vulnerability and assess whether it could be exploited to gain access

    to a high-value asset. This approach imitates how an advanced attacker moves laterally within a system. The result is a clearer and more realistic view of the organization’s real risk compared to just listing bugs in a spreadsheet without context.
    Comparing Methodologies: Strategy and Execution
    When comparing platforms in this area, the industry is shifting focus from just ticking off features to demonstrating how effectively those features can be used. Modern platforms, including XBOW, focus on high-fidelity testing that avoids disrupting production environments while still proving that a vulnerability is reachable.

    Three main architectural approaches have emerged as standouts:
    Go to Full Article


  • Linux Kernel 7.1 Officially Released with New NTFS Driver, Intel FRED, and Major Code Cleanup
    by George Whittaker
    The Linux kernel development team has officially released Linux Kernel 7.1, marking the first major update in the 7.x series. Announced by Linus Torvalds on June 14, 2026, the release introduces a mix of new features, hardware improvements, filesystem enhancements, and large-scale code cleanup efforts that continue modernizing the Linux platform.

    While Linux 7.1 is not a long-term support (LTS) release, it delivers several significant changes that will eventually make their way into many Linux distributions over the coming months.
    A Brand-New NTFS Driver Arrives
    One of the most significant additions in Linux 7.1 is a completely rewritten in-kernel NTFS filesystem driver.

    The new implementation has reportedly been under development for several years and replaces older code with a modern design built around Linux’s current storage infrastructure. The driver utilizes technologies such as iomap and folios, which improve efficiency and simplify future maintenance.

    Benefits include:
    Improved NTFS write performance Better handling of large files More modern filesystem architecture Easier future development and maintenance
    For users who regularly exchange data between Linux and Windows systems, this is one of the most important improvements in the release.
    Intel FRED Enabled by Default
    Linux 7.1 also enables Intel Flexible Return and Event Delivery (FRED) by default on supported hardware.

    FRED is a newer CPU mechanism designed to improve how processors handle interrupts and exceptions. By replacing older methods with a more streamlined approach, FRED aims to improve performance and reduce complexity in low-level CPU operations.

    The feature primarily benefits newer Intel platforms, including upcoming processor generations.
    Graphics Drivers Continue to Improve
    Graphics support remains a major focus of kernel development, and Linux 7.1 delivers additional improvements for both Intel and AMD hardware.

    Highlights include:
    Performance enhancements for Intel Arc GPUs Continued work on Intel Battlemage graphics Updates for AMD Radeon hardware Expanded GPU reliability monitoring infrastructure through DRM-RAS support
    These updates help improve gaming, desktop performance, and workstation workloads across modern Linux systems.
    Steam Deck OLED Audio Fixes Land Upstream
    Linux gamers receive a welcome improvement in this release as audio support fixes for the Steam Deck OLED have finally been merged into the mainline kernel.
    Go to Full Article


Page last modified on November 02, 2011, at 10:01 PM