Linux
2.15K subscribers
3.82K photos
20 videos
16.5K links
Новости Линукс Linux

По всем вопросам @evgenycarter
Download Telegram
📰 Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as.

🔗 Source: https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html

#ubuntu

👉@sysadminoff
📰 Lemonade 11.5 Local AI Server Released With Completed Lemonade Router

Just one week after releasing Lemonade 11.0, the Lemonade 11.5 local AI server was released today for this open-source AMD backed project during their AMD Advancing AI event...

🔗 Source:

#amd #opensource

👉@sysadminoff

https://www.phoronix.com/news/AMD-Lemonade-11.5
Hardware-secured Windows KMS activation with TPM attestation

Microsoft is introducing a new security feature called KMS Hardware-Secured to protect Key Management Service (KMS) activation. This feature uses Trusted Platform Module (TPM) attestation to verify the hardware integrity of your activation servers. Starting with Windows Server 2025, you can assess your infrastructure's readiness for this change. In a future Long-Term Servicing Channel (LTSC) release, this hardware-based verification will become mandatory. This article explains the technical requirements and how you can prepare your environment.
Source

👉@sysadminoff

https://4sysops.com/archives/hardware-secured-windows-kms-activation-with-tpm-attestation/
Дерево портов FreeBSD временно заморожено из-за добавления в порты слишком большого файла

Разработчики FreeBSD объявили о решении временно заморозить репозиторий с деревом портов в связи с инцидентом, вызванным помещением в порты бинарного файла, размером 150 МБ. Данная операция привела к нарушению зеркалирования портов на GitHub из-за превышения ограничения на максимальный размер файла, которое на GitHub составляет 100 МБ. Для проведения чистки и удаления из истории репозитория бинарных данных с сомнительной лицензией введена заморозка от внесения изменений, которая продолжается уже около двух суток. Информация о том, как подобный файл был помещён в дерево портов пока не приводится, но утверждается, что нет оснований считать репозиторий скомпрометированным.

👉@sysadminoff

https://www.opennet.ru/opennews/art.shtml?num=65966
AMD unveils Zen 6 EPYC Venice processors with up to 256 cores

AMD has officially detailed its upcoming EPYC "Venice" server processor lineup, which is built on the Zen 6 architecture and manufactured using a 2nm process. The flagship EPYC 9996 model features 256 cores and 512 threads, utilizing a dense Zen 6c design to maximize throughput for high-concurrency workloads. The platform introduces significant architectural upgrades, including support for 16-channel memory and PCIe Gen 6 connectivity.
Source

👉@sysadminoff

https://4sysops.com/archives/amd-unveils-zen-6-epyc-venice-processors-with-up-to-256-cores/
Выпуск дистрибутива Альт Рабочая станция 11.2

Опубликовано обновление дистрибутива Linux "Альт Рабочая станция 11.2", предлагающего среду рабочего стола GNOME и ориентированного для работы в офисе и дома. Сборки подготовлены для архитектур x86_64 и aarch64, и построены на 11 платформе ALT. Для загрузки сформирован установочный iso-образ (8.2 ГБ).

👉@sysadminoff

https://www.opennet.ru/opennews/art.shtml?num=65967
Cloudflare introduces cache response rules for granular edge control

Cloudflare has launched Cache Response Rules, a new feature that allows administrators to modify HTTP response headers after they leave the origin server but before they are processed by the edge cache. This capability addresses common caching inefficiencies, such as accidental "Set-Cookie" headers or overly restrictive "Cache-Control" directives that prevent static assets from being cached. By applying these rules at the response phase, teams can resolve configuration conflicts without needing to modify origin server code or infrastructure.
Source

👉@sysadminoff

https://4sysops.com/archives/cloudflare-introduces-cache-response-rules-for-granular-edge-control/
📰 Codeberg takes its side in the open-source scene's AI debate by banning vibe-coded projects

As AI coding tools evolve over time, the open-source scene has been drawing its lines in the sand as to how much AI is too much. On one side of the debate, Linus Torvalds has stated that he thinks AI tools are useful (which has attracted backlash). On the other side, we saw Fedora's community tear down the plans for an AI Developer Desktop spin.

🔗 Source:

#fedora #opensource

👉@sysadminoff

https://www.xda-developers.com/codeberg-takes-its-side-in-the-open-source-scenes-ai-debate-by-banning-vibe-coded-projects/
📰 Someone built a Raspberry Pi bot to catch their ISP lying about their speeds, and you can download it too

It can be annoying when you're convinced that your ISP is throttling your speeds, but it won't own up to its actions. Fortunately, there are ways to double-check if it is, in fact, your ISP that's causing the issues. One person decided to take matters into their own hands with a Raspberry Pi speed tester, and it did, in fact, prove that the ISP was at fault.

🔗 Source:

#raspberry

👉@sysadminoff

https://www.xda-developers.com/someone-built-a-raspberry-pi-bot-to-catch-their-isp-lying-about-their-speeds-and-you-can-download-it-too/
Microsoft tracks every Windows PC through a secret key

Microsoft embeds a persistent Global Device Identifier (GDID) into every Windows installation to uniquely track specific OS instances. This 64-bit identifier is generated by Microsoft servers and stored locally within the registry under the LID entry in the IdentityCRL key. While the company maintains that the GDID is for internal use, it is deeply integrated into various system features, including Windows activation, app licensing, and diagnostic data collection.
Source

👉@sysadminoff

https://4sysops.com/archives/microsoft-tracks-every-windows-pc-through-a-secret-key/
📰 Tails 7.10 Anonymous OS Released with Improved Data-Loss Protection

Tails 7.10 adopts GNOME’s standard shutdown process, replaces GNOME Videos with Celluloid, and updates Tor Browser.

🔗 Source:

#gnome

👉@sysadminoff

https://linuxiac.com/tails-7-10-anonymous-os-released-with-improved-data-loss-protection/
📰 Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access.Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation.The company demonstrated the race.

🔗 Source: https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html

#fedora #kernel #linux

👉@sysadminoff
Codeberg bans hosting ‘mostly’ AI-generated code

Codeberg, the nonprofit alternative to GitHub used by FLOSS projects, will no longer host software that’s mostly AI-generated. A vote closed yesterday (22 July, 2026), passing 358 to 144 with 14 abstentions on roughly 50% turnout to stop hosting software that’s largely vibe-coded. A second motion, also passed, commits Codeberg to never training AI models on hosted code or user data. Not that it was ever likely to. A Terms of Use amendment now prohibits projects that “mostly consist of code written by” generative AI tools. In a blog post, Codeberg explains the economic need for a ban, explaining that […]
You're reading Codeberg bans hosting ‘mostly’ AI-generated code, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.

👉@sysadminoff

https://www.omgubuntu.co.uk/2026/07/codeberg-bans-ai-generated-code
Jensen Huang on the future of AI and the American industrial build-out

NVIDIA CEO Jensen Huang argues that the rapid advancement of AI is a positive force for global industry, rejecting the "doomer" narrative that the technology will destroy jobs or humanity. He emphasizes that AI is fundamentally an infrastructure-driven shift, requiring a massive, multi-year build-out of data centers and hardware that will ultimately increase productivity and create new employment opportunities. Huang maintains that the United States remains the premier environment for innovation and that open-source models are essential for cybersecurity, safety, and global technological diffusion.
Source

👉@sysadminoff

https://4sysops.com/archives/jensen-huang-on-the-future-of-ai-and-the-american-industrial-build-out/