Category: Blog

Announcement of the Dissolution of the Nixpkgs Core Team

The Nixpkgs Core Team announced its dissolution due to member burnout and an accumulated systemic management crisis within the community. The team coordinated work on the Nixpkgs package repository, used in the NixOS distribution, and also performed tasks such as mediating disputes between maintainers and approving new members. Burnout among members was cited as the main reason for the Core Team's self-dissolution […]

TONTOU — an attack on Intel and AMD CPUs that allows bypassing the protection against Spectre v2 vulnerabilities

Researchers from the Massachusetts Institute of Technology identified a technique called TONTOU (Time-of-Neutralization to Time-of-Use), proposing a new way to exploit class Spectre v2 microarchitectural vulnerabilities. This vulnerability allows for the determination of kernel memory contents when executing an exploit in user space. The code to block this vulnerability was included in the Linux kernel on August 5 and is part of releases 7.1.7, 6.18.43, 6.12.102, 6.6.149, […]

Zapscape — a vulnerability in the KVM hypervisor that allows obtaining root access to the host system

Information has been disclosed about vulnerability (CVE-2026-64561) in the KVM hypervisor, which allows root-level access to the host environment when there is root access in the guest system. This issue can also be used for local privilege escalation if there is access to the device /dev/kvm (for example, on RHEL, such access is granted to all users). A prototype exploit is available for download. The issue has been assigned […]

Ban on accepting AI patches in the drivers/staging section of the Linux kernel

Greg Kroah-Hartman, responsible for maintaining the stable and staging branches of the Linux kernel, announced the cessation of patch acceptance in the drivers/staging section that were prepared using AI tools. It is noted that such automatically generated patches contradict the primary idea of using the drivers/staging subsystem as a training ground for new kernel developers. Code in drivers/staging is initially positioned as problematic (TAINT_CRAP) and is intentionally supported […]

The display manager LightDM 1.33.0 has been released

The developers of Ubuntu have released version 1.33.0 of the LightDM display manager, which is used in Linux Mint, Lubuntu, Xubuntu, and Ubuntu MATE. LightDM provides a background process for launching display servers and graphical login interface modules, as well as managing user authentication through PAM and remote desktop connections. The project is not tied to specific desktop environments […]

The mount-tui has been released, an interface for mounting disks and SMB resources in Linux

The mount-tui project has been published, developing an interactive text-based interface for viewing and mounting local block devices, as well as connecting to network resources via the SMB/CIFS protocol. The program is written in Rust using the Ratatui and Crossterm libraries, and is distributed under the Apache 2.0 license. mount-tui outputs a list of disks and partitions indicating file system, size, mount point, and additional information […]

The source code for Cloudflare OS has been released, a platform for applications developed through AI.

Cloudflare has released the code for the Cloudflare OS platform, designed for creating personal applications using vibe coding, as well as for securely working with these applications and AI agents. The code is written in TypeScript and is distributed under the Apache 2.0 license. Cloudflare OS is presented as a sort of operating system for applications created through AI, with the workshop-backend package serving as the core […]

Release of uutils 0.10, a Rust version of GNU Coreutils

The uutils coreutils project version 0.10.0 (Rust Coreutils) has been released, developing an alternative to the GNU Coreutils package, written in Rust. The coreutils package includes over a hundred utilities, including sort, cat, chmod, chown, chroot, cp, date, dd, echo, hostname, id, ln, and ls. The goal of the project is to create a cross-platform alternative implementation of Coreutils, capable of running on Windows and Redox platforms […]

Northstar 1.0.6 — a minimalist browser with its own engine

A new version of the Northstar browser has been released. Previously, news appeared on LOR about the browser Nordstjernen by the same author. The projects are being developed in parallel. Northstar is a simple open-source web browser distributed under the GPL license. Nordstjernen is a more complex browser, with source code available but a license that restricts creating a competing browser based on this source code. Northstar focuses on […]

Wild 0.10

On August 4, the release of Wild 0.10 took place — a free linker written in Rust, designed primarily for fast program builds in Linux. The linker performs the final stage of compilation: it combines object files and libraries into a ready executable or shared library. Wild can serve as a replacement for GNU ld, LLD, and Mold, although the developers' stated ultimate goal is […]

The Linux kernel's drivers/staging will stop accepting created LLM patches.

On August 3, 2026, Greg Kroah-Hartman, who maintains the stable branches of Linux and the staging subsystem, announced new rules for accepting changes into the drivers/staging directory. This decision was prompted by the recent "invasion of created LLM patches." Now, patches prepared by language models for this part of the kernel will be automatically rejected, except for confirmed fixes of real vulnerabilities. The drivers/staging directory is used for hosting […]

The new worm ChainDrop has affected over 400 NPM packages.

A mass attack on packages in the NPM repository has been recorded, conducted using a new self-replicating worm ChainDrop that injects malware into dependencies. As a result of the attack, 2,212 malicious releases have been published for 444 packages. The most popular among the compromised packages, keyv, flat-cache, and file-entry-cache, have seen 154, 149.9, and 147.6 million downloads weekly. The worm's loader was placed in setup.mjs files […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster