7-Zip 26.02 patches RCE flaw triggered by malicious XZ archives
7-Zip version 26.02 addresses a remote code execution vulnerability tracked as CVE-2026-14266 that stems from a heap-based buffer overflow when processing specially crafted XZ-compressed data. An attacker can trigger the flaw if a user opens a malicious archive or visits a page delivering a crafted XZ payload, allowing arbitrary code to run with the privileges of the logged-in user. The issue was disclosed by researcher Landon Peng and detailed in a Zero Day Initiative advisory, with the patch adding checks to prevent the decoder from writing beyond available buffer space.
Source
👉@sysadminoff
https://4sysops.com/archives/7-zip-26-02-patches-rce-flaw-triggered-by-malicious-xz-archives/
7-Zip version 26.02 addresses a remote code execution vulnerability tracked as CVE-2026-14266 that stems from a heap-based buffer overflow when processing specially crafted XZ-compressed data. An attacker can trigger the flaw if a user opens a malicious archive or visits a page delivering a crafted XZ payload, allowing arbitrary code to run with the privileges of the logged-in user. The issue was disclosed by researcher Landon Peng and detailed in a Zero Day Initiative advisory, with the patch adding checks to prevent the decoder from writing beyond available buffer space.
Source
👉@sysadminoff
https://4sysops.com/archives/7-zip-26-02-patches-rce-flaw-triggered-by-malicious-xz-archives/
Microsoft makes passkeys default and retires SMS MFA by 2027
Microsoft Entra ID will make passkeys the default authentication method beginning September 1, while Microsoft-provided SMS and voice multifactor authentication will be retired in February 2027. Organizations that still require telephony-based MFA after that date must obtain it from a third-party telecom provider. The shift requires tenants to revise MFA rollout and migration plans well ahead of the cutoffs.
Source
👉@sysadminoff
https://4sysops.com/archives/microsoft-makes-passkeys-default-and-retires-sms-mfa-by-2027/
Microsoft Entra ID will make passkeys the default authentication method beginning September 1, while Microsoft-provided SMS and voice multifactor authentication will be retired in February 2027. Organizations that still require telephony-based MFA after that date must obtain it from a third-party telecom provider. The shift requires tenants to revise MFA rollout and migration plans well ahead of the cutoffs.
Source
👉@sysadminoff
https://4sysops.com/archives/microsoft-makes-passkeys-default-and-retires-sms-mfa-by-2027/
Опубликован исходный код мессенджера MeetVap
Опубликован исходный код MeetVap, кроссплатформенного мессенджера с клиентами для Android, iOS и Web. Помимо клиентских компонентов также открыта и серверная часть. Проект ориентирован на обеспечение конфиденциальности пользователей. Сообщения не хранятся на сервере после доставки, регистрация не требует номера телефона или адреса электронной почты. Поддерживаются личные и групповые чаты, голосовые и видеозвонки, обмен файлами, голосовыми сообщениями и геопозицией. Код доступен под лицензией AGPLv3.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=65933
Опубликован исходный код MeetVap, кроссплатформенного мессенджера с клиентами для Android, iOS и Web. Помимо клиентских компонентов также открыта и серверная часть. Проект ориентирован на обеспечение конфиденциальности пользователей. Сообщения не хранятся на сервере после доставки, регистрация не требует номера телефона или адреса электронной почты. Поддерживаются личные и групповые чаты, голосовые и видеозвонки, обмен файлами, голосовыми сообщениями и геопозицией. Код доступен под лицензией AGPLv3.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=65933
Ubuntu’s desktop icons extension completes its GTK4 port
The Desktop Icons NG (aka DING) GNOME Shell extension Ubuntu uses to put icons on your literal desktop, has had a busy month – it finished its port to GTK4, patched memory leaks and improved some of its lesser-known features. The GTK4 port landed in v51.0.0, released this month, alongside early support for GNOME 51 (since that’s the GNOME version Ubuntu 26.10 will ship with in October). Prior to that, there were other, smaller in June with fixes for memory leaks and buffs to usability. DING’s GTK4 port – not to be confused with a separate GTK4 fork I covered back […]
You're reading Ubuntu’s desktop icons extension completes its GTK4 port, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.
👉@sysadminoff
https://www.omgubuntu.co.uk/2026/07/ubuntu-desktop-icons-extension-gtk4-port
The Desktop Icons NG (aka DING) GNOME Shell extension Ubuntu uses to put icons on your literal desktop, has had a busy month – it finished its port to GTK4, patched memory leaks and improved some of its lesser-known features. The GTK4 port landed in v51.0.0, released this month, alongside early support for GNOME 51 (since that’s the GNOME version Ubuntu 26.10 will ship with in October). Prior to that, there were other, smaller in June with fixes for memory leaks and buffs to usability. DING’s GTK4 port – not to be confused with a separate GTK4 fork I covered back […]
You're reading Ubuntu’s desktop icons extension completes its GTK4 port, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.
👉@sysadminoff
https://www.omgubuntu.co.uk/2026/07/ubuntu-desktop-icons-extension-gtk4-port
Доступен wiyci - сервис по анализу логов сборки пакетов
Запущен сервис wiyci (The World Is Your CI) от автора проекта Repology. Сервис агрегирует логи сборки свободных проектов, находит в них индикаторы проблем, включая предупреждения компилятора и сломанные тесты, и представляет результат в виде, напоминающем интерфейс систем непрерывной интеграции. Идея в том, что сборка пакетов настоящих дистрибутивов покрывает большее разнообразие окружений, нежели обычные CI (которые, кроме того, используются не всеми проектами) и может выявить больше проблем, и закрыть слепое пятно в экосистеме СПО.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=65934
Запущен сервис wiyci (The World Is Your CI) от автора проекта Repology. Сервис агрегирует логи сборки свободных проектов, находит в них индикаторы проблем, включая предупреждения компилятора и сломанные тесты, и представляет результат в виде, напоминающем интерфейс систем непрерывной интеграции. Идея в том, что сборка пакетов настоящих дистрибутивов покрывает большее разнообразие окружений, нежели обычные CI (которые, кроме того, используются не всеми проектами) и может выявить больше проблем, и закрыть слепое пятно в экосистеме СПО.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=65934
Claude Code Skills: Automate Repetitive Linux Tasks with Custom Skills
The post Claude Code Skills: Automate Repetitive Linux Tasks with Custom Skills first appeared on Tecmint: Linux Howtos, Tutorials & Guides .This walks through what a Claude Code Skill actually is, how to install pre-built skills from Anthropic’s marketplace, how to
The post Claude Code Skills: Automate Repetitive Linux Tasks with Custom Skills first appeared on Tecmint: Linux Howtos, Tutorials & Guides.
👉@sysadminoff
https://www.tecmint.com/claude-code-skills-linux/
The post Claude Code Skills: Automate Repetitive Linux Tasks with Custom Skills first appeared on Tecmint: Linux Howtos, Tutorials & Guides .This walks through what a Claude Code Skill actually is, how to install pre-built skills from Anthropic’s marketplace, how to
The post Claude Code Skills: Automate Repetitive Linux Tasks with Custom Skills first appeared on Tecmint: Linux Howtos, Tutorials & Guides.
👉@sysadminoff
https://www.tecmint.com/claude-code-skills-linux/
Claude Code Skills: Automate Repetitive Linux Tasks with Custom Skills
Claude Code Skills: Install, Create, and Test Custom Skills
Learn how to install, create, test, and troubleshoot Claude Code Skills on Linux to automate repetitive tasks using custom SKILL.md files and Anthropic's marketplace.
❤1
Critical nginx heap overflow risks worker crashes and possible RCE
F5 has patched a critical vulnerability tracked as CVE-2026-42533 in NGINX that lets unauthenticated remote attackers trigger a heap buffer overflow via crafted HTTP requests. The issue affects both open-source NGINX and NGINX Plus under specific configurations and can crash or restart worker processes to cause denial of service. Where address space layout randomization is disabled or bypassable, the flaw may also permit remote code execution.
Source
👉@sysadminoff
https://4sysops.com/archives/critical-nginx-heap-overflow-risks-worker-crashes-and-possible-rce/
F5 has patched a critical vulnerability tracked as CVE-2026-42533 in NGINX that lets unauthenticated remote attackers trigger a heap buffer overflow via crafted HTTP requests. The issue affects both open-source NGINX and NGINX Plus under specific configurations and can crash or restart worker processes to cause denial of service. Where address space layout randomization is disabled or bypassable, the flaw may also permit remote code execution.
Source
👉@sysadminoff
https://4sysops.com/archives/critical-nginx-heap-overflow-risks-worker-crashes-and-possible-rce/
Выпуск композитного сервера Hyprland 0.56
Доступен композитный сервер Hyprland 0.56, использующий протокол Wayland. Проект ориентирован на мозаичную (tiling) компоновку окон, но поддерживает и классическое произвольное размещение окон, группировку окон в форме вкладок, псевдомозаичный режим и полноэкранное раскрытие окон. Код написан на языке С++ и распространяется под лицензией BSD.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=65938
Доступен композитный сервер Hyprland 0.56, использующий протокол Wayland. Проект ориентирован на мозаичную (tiling) компоновку окон, но поддерживает и классическое произвольное размещение окон, группировку окон в форме вкладок, псевдомозаичный режим и полноэкранное раскрытие окон. Код написан на языке С++ и распространяется под лицензией BSD.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=65938
Видеокодеки divx/xvid теперь свободны от патентов
Последний патент на MPEG-4 Part 2 истек 19.07.26. Это был бразильский патент BRPI0109962B1 - «процесс хранения и обработки информации об изображениях, полученных последовательно во времени»
divx, mpeg4, xvid
👉@sysadminoff
https://www.linux.org.ru/news/multimedia/18342115
Последний патент на MPEG-4 Part 2 истек 19.07.26. Это был бразильский патент BRPI0109962B1 - «процесс хранения и обработки информации об изображениях, полученных последовательно во времени»
divx, mpeg4, xvid
👉@sysadminoff
https://www.linux.org.ru/news/multimedia/18342115
AI uncovers pre-auth WordPress RCE chain dubbed wp2shell in ten hours
Security researchers tasked the frontier model GPT-5.6 Sol Ultra with probing the WordPress core codebase to locate a full pre-authentication remote code execution chain. The model quickly discovered a read-only SQL injection and confirmed it by extracting an administrator email address from a stock installation within minutes. Completing the end-to-end exploit required just over ten hours of automated work and roughly $25 in compute.
Source
👉@sysadminoff
https://4sysops.com/archives/ai-uncovers-pre-auth-wordpress-rce-chain-dubbed-wp2shell-in-ten-hours/
Security researchers tasked the frontier model GPT-5.6 Sol Ultra with probing the WordPress core codebase to locate a full pre-authentication remote code execution chain. The model quickly discovered a read-only SQL injection and confirmed it by extracting an administrator email address from a stock installation within minutes. Completing the end-to-end exploit required just over ten hours of automated work and roughly $25 in compute.
Source
👉@sysadminoff
https://4sysops.com/archives/ai-uncovers-pre-auth-wordpress-rce-chain-dubbed-wp2shell-in-ten-hours/
Japan builds world’s first national AI factory for robotics using Nvidia Rubin GPUs
Japan is establishing a state-funded AI factory to serve as the primary compute infrastructure for the national FRONTia program. The facility will utilize 382 Vera Rubin NVL72 racks, integrating 27,500 Nvidia Rubin GPUs and 13,750 Vera CPUs. This massive deployment is designed to draw 140 megawatts of power, placing it among the largest single-site AI training clusters globally.
Source
👉@sysadminoff
https://4sysops.com/archives/japan-builds-worlds-first-national-ai-factory-for-robotics-using-nvidia-rubin-gpus/
Japan is establishing a state-funded AI factory to serve as the primary compute infrastructure for the national FRONTia program. The facility will utilize 382 Vera Rubin NVL72 racks, integrating 27,500 Nvidia Rubin GPUs and 13,750 Vera CPUs. This massive deployment is designed to draw 140 megawatts of power, placing it among the largest single-site AI training clusters globally.
Source
👉@sysadminoff
https://4sysops.com/archives/japan-builds-worlds-first-national-ai-factory-for-robotics-using-nvidia-rubin-gpus/
Hugging Face turns to Chinese open model after US LLMs block breach forensics
Hugging Face disclosed that an autonomous AI agent system breached its production infrastructure in mid-July by abusing code-execution paths in its dataset processing pipeline. The attacker escalated to node-level access, harvested cloud and cluster credentials, and moved laterally across internal clusters using short-lived sandboxes and self-migrating command-and-control. Investigation found no evidence of tampering with public models, datasets, Spaces, or the software supply chain, though users were advised to rotate access tokens.
Source
👉@sysadminoff
https://4sysops.com/archives/hugging-face-turns-to-chinese-open-model-after-us-llms-block-breach-forensics/
Hugging Face disclosed that an autonomous AI agent system breached its production infrastructure in mid-July by abusing code-execution paths in its dataset processing pipeline. The attacker escalated to node-level access, harvested cloud and cluster credentials, and moved laterally across internal clusters using short-lived sandboxes and self-migrating command-and-control. Investigation found no evidence of tampering with public models, datasets, Spaces, or the software supply chain, though users were advised to rotate access tokens.
Source
👉@sysadminoff
https://4sysops.com/archives/hugging-face-turns-to-chinese-open-model-after-us-llms-block-breach-forensics/
Microsoft adopts AMD Helios on Azure as Anthropic tests AMD chips
Microsoft will deploy AMD's Helios rack-scale AI platform on Azure beginning in the second half of 2026 to run large AI models for its own use, customers, and Azure AI services. Helios combines AMD GPUs, CPUs, networking chips, and software as a full-system alternative to Nvidia's dominant rack-scale offerings. AMD CEO Lisa Su called the expanded deal a major milestone, while Microsoft CEO Satya Nadella stressed that customers need more choices in AI infrastructure.
Source
👉@sysadminoff
https://4sysops.com/archives/microsoft-adopts-amd-helios-on-azure-as-anthropic-tests-amd-chips/
Microsoft will deploy AMD's Helios rack-scale AI platform on Azure beginning in the second half of 2026 to run large AI models for its own use, customers, and Azure AI services. Helios combines AMD GPUs, CPUs, networking chips, and software as a full-system alternative to Nvidia's dominant rack-scale offerings. AMD CEO Lisa Su called the expanded deal a major milestone, while Microsoft CEO Satya Nadella stressed that customers need more choices in AI infrastructure.
Source
👉@sysadminoff
https://4sysops.com/archives/microsoft-adopts-amd-helios-on-azure-as-anthropic-tests-amd-chips/
📰 Ubuntu’s desktop icons extension completes its GTK4 port
The Desktop Icons NG (aka DING) GNOME Shell extension Ubuntu uses to put icons on your literal desktop, has been busy – it finished its port to GTK4, patched memory leaks and improved a few of its lesser-known features. The GTK4 port landed in v51.0.0, released this month, alongside early support for GNOME 51 (since that’s the GNOME version Ubuntu 26.10 will ship with in October).
🔗 Source:
#gnome #ubuntu
👉@sysadminoff
https://www.omgubuntu.co.uk/2026/07/ubuntu-desktop-icons-extension-gtk4-port
The Desktop Icons NG (aka DING) GNOME Shell extension Ubuntu uses to put icons on your literal desktop, has been busy – it finished its port to GTK4, patched memory leaks and improved a few of its lesser-known features. The GTK4 port landed in v51.0.0, released this month, alongside early support for GNOME 51 (since that’s the GNOME version Ubuntu 26.10 will ship with in October).
🔗 Source:
#gnome #ubuntu
👉@sysadminoff
https://www.omgubuntu.co.uk/2026/07/ubuntu-desktop-icons-extension-gtk4-port
OMG! Ubuntu
Ubuntu’s desktop icons extension completes its GTK4 port
The Desktop Icons NG (aka DING) GNOME Shell extension Ubuntu uses to put icons on your literal desktop, has been busy – it finished its port to GTK4,
📰 GNOME Changes Security Disclosure Policies Due To AI-Generated Reports
The GNOME project is changing its handling of security reports due to the influx of AI/LLM-generated security findings...
🔗 Source:
#gnome
👉@sysadminoff
https://www.phoronix.com/news/GNOME-Security-Changes-2026
The GNOME project is changing its handling of security reports due to the influx of AI/LLM-generated security findings...
🔗 Source:
#gnome
👉@sysadminoff
https://www.phoronix.com/news/GNOME-Security-Changes-2026
Phoronix
GNOME Changes Security Disclosure Policies Due To AI-Generated Reports
The GNOME project is changing its handling of security reports due to the influx of AI/LLM-generated security findings.
📰 NetworkManager 1.58 Officially Released with New Features and Improvements
NetworkManager 1.58 open-source network connection manager for Linux-based operating systems is now available for download as a major update with many new features and improvements.
🔗 Source: https://9to5linux.com/networkmanager-1-58-officially-released-with-new-features-and-improvements
#linux #linuxbased #opensource
👉@sysadminoff
NetworkManager 1.58 open-source network connection manager for Linux-based operating systems is now available for download as a major update with many new features and improvements.
🔗 Source: https://9to5linux.com/networkmanager-1-58-officially-released-with-new-features-and-improvements
#linux #linuxbased #opensource
👉@sysadminoff
📰 Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
The vulnerability, disclosed by Lunbun researcher Landon Peng, exists in 7-Zip's processing of XZ-compressed data.
🔗 Source:
👉@sysadminoff
https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives/
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
The vulnerability, disclosed by Lunbun researcher Landon Peng, exists in 7-Zip's processing of XZ-compressed data.
🔗 Source:
👉@sysadminoff
https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives/
BleepingComputer
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
📰 Flathub’s AI slop ban looks like it was the right call
When Flathub banned AI-coded app submissions last month, some critics warned the platform was denying the future by dismissing a new wave of “vibe-coded” software as out-and-out “slop”. Well, new data suggests otherwise, as nearly three-quarters of the rejected apps are already dead, existing only a few months. Linux developer Evangelos Paterakis, developer of Tuba, Turntable and others, did the digging, looking at 120 code repositories whose...
🔗 Source:
#linux
👉@sysadminoff
https://www.omgubuntu.co.uk/2026/07/flathub-ai-slop-ban-data
When Flathub banned AI-coded app submissions last month, some critics warned the platform was denying the future by dismissing a new wave of “vibe-coded” software as out-and-out “slop”. Well, new data suggests otherwise, as nearly three-quarters of the rejected apps are already dead, existing only a few months. Linux developer Evangelos Paterakis, developer of Tuba, Turntable and others, did the digging, looking at 120 code repositories whose...
🔗 Source:
#linux
👉@sysadminoff
https://www.omgubuntu.co.uk/2026/07/flathub-ai-slop-ban-data
OMG! Ubuntu
Flathub’s AI slop ban looks like it was the right call
When Flathub banned AI-coded app submissions last month, some critics warned the platform was denying the future by dismissing a new wave of
Fake GitHub repos turn AI agents into malware delivery tools
Malicious GitHub activity dubbed FakeGit has spread across nearly 7,600 repositories, with more than 800 impersonating AI skills or Model Context Protocol (MCP) servers. The campaign uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP files to lure victims into downloading SmartLoader. SmartLoader then establishes persistence and can deploy StealC to steal credentials, sessions, and other sensitive data.
Source
👉@sysadminoff
https://4sysops.com/archives/fake-github-repos-turn-ai-agents-into-malware-delivery-tools/
Malicious GitHub activity dubbed FakeGit has spread across nearly 7,600 repositories, with more than 800 impersonating AI skills or Model Context Protocol (MCP) servers. The campaign uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP files to lure victims into downloading SmartLoader. SmartLoader then establishes persistence and can deploy StealC to steal credentials, sessions, and other sensitive data.
Source
👉@sysadminoff
https://4sysops.com/archives/fake-github-repos-turn-ai-agents-into-malware-delivery-tools/
📰 Linux Patches Introduce "KNOD" For In-Kernel Network Offloading Directly To AMD GPUs
Some extremely cool patches were posted to the Linux kernel mailing list on Sunday. The patches for "KNOD" allow for in-kernel network offloading to GPUs with an initial focus on AMD GPU support. What makes this all the more nifty is that it doesn't depend upon any user-space libraries like AMD ROCm but is all handled in-kernel with driving the GPU directly...
🔗 Source:
#amd #kernel #linux
👉@sysadminoff
https://www.phoronix.com/news/KNOD-Network-Offload-AMD-GPUs
Some extremely cool patches were posted to the Linux kernel mailing list on Sunday. The patches for "KNOD" allow for in-kernel network offloading to GPUs with an initial focus on AMD GPU support. What makes this all the more nifty is that it doesn't depend upon any user-space libraries like AMD ROCm but is all handled in-kernel with driving the GPU directly...
🔗 Source:
#amd #kernel #linux
👉@sysadminoff
https://www.phoronix.com/news/KNOD-Network-Offload-AMD-GPUs
Phoronix
Linux Patches Introduce "KNOD" For In-Kernel Network Offloading Directly To AMD GPUs
Some extremely cool patches were posted to the Linux kernel mailing list on Sunday