RSS 생중계
Seven stable kernels for Saturday including two security fixes
Greg Kroah-Hartman has announced the release of the 7.1.3, 6.18.38, 6.12.95, 6.6.144, 6.1.177, 5.15.211, and 5.10.260 stable kernels. Several kernels in this batch include a fix for a vulnerability introduced in the 6.0 kernel in IPv6 (CVE-2026-53362), which could allow an attacker to escape a container and gain root access.
There is also a fix for a use-after-free bug in KVM (CVE-2026-53359) that was introduced in the 2.6.36 kernel. As usual, each stable kernel includes a number of fixes throughout the tree. Users are advised to upgrade.
EchoStar's US Satellite Pay-TV Provider Dish DBS Files for Bankruptcy
Read more of this story at Slashdot.
Decades-Old Bash Tricks Expose AI Coding Agents To Supply Chain Attacks
Read more of this story at Slashdot.
What Is a Quantum Computer Good For? Absolutely Nothing - Yet
Read more of this story at Slashdot.
Startup Targets Datacenters With 3D-Printed Nuclear Reactor Module
Read more of this story at Slashdot.
Video Game History Foundation Says Piracy Remains the Only Viable Preservation Method
Read more of this story at Slashdot.
Alibaba To Ban Claude Code In Workplace Over Alleged Backdoor Risks
Read more of this story at Slashdot.
Valve Open-Sources Steam Machine's E-Ink Display
Read more of this story at Slashdot.
Four vulnerabilities in Guix
The GNU Guix project has announced three vulnerabilities in the guix substitute utility as well as a fourth that affects the guix pull and guix time-machine commands. The impact of the vulnerabilities ranges from remote privilege escalation to local disclosure of sensitive files.
The remote exploitation of guix substitute only requires that the vulnerable system attempt to download a binary substitute. Any configured substitute server, including ones discovered using guix-daemon's --discover option, can exploit this, and so can a man-in-the-middle (MITM), regardless of whether https is used in the substitute server urls.
The local exploitation of guix substitute only requires the ability to connect to guix-daemon's socket, which by default any user can do.
Separately, another security issue (CVE ID pending) was identified in guix pull and guix time-machine, which enables anyone who can control the channels file used by these commands to cause a file to be created or overwritten wherever the user running the command in question has permission to create them.
The project is recommending that all users upgrade guix and guix-daemon immediately. See the announcement for instructions, how to test for the vulnerabilities, the disclosure timeline, and more.
New PamStealer macOS Malware Uses Clever Tradecraft To Remain Stealthy
Read more of this story at Slashdot.
[$] Limiting negative dentries
Security updates for Friday
US Life Expectancy On Track To Reach Record High
Read more of this story at Slashdot.
Amazon Has Enough Satellites To Launch Its Starlink Competitor
Read more of this story at Slashdot.
Sitting For More Than 30 Minutes At a Time Linked To Higher Risk of Cancer Death
Read more of this story at Slashdot.
Labor Force Participation Rate Falls To Lowest In 50 years
Read more of this story at Slashdot.
CalyxOS is back
In August 2025, the CalyxOS privacy-focused Android distribution announced that it was pausing all releases while it reworked its release process, security protocols, and changed its signing keys following the departure of one of its founders. The project has now announced that it is "officially back from the hiatus" with the 7.2.2.0 release.
CalyxOS 7.2.2.0 is signed by us using a new HSM-based, open-source signing solution we designed to enhance the security of the entire signing process, ensure redundancy, and remove single points of failure. You can verify CalyxOS 7.2.2.0 and future builds following these instructions. For anyone who is interested, the security audit report of the HSM provisioning ceremony script can be found here.
In addition, we also went through significant infrastructure improvements. In particular, we have set up a cleaner server structure to streamline each release. In response to Google's less frequent AOSP source code releases, our team developed scripts to reduce the overhead in applying monthly patches and updates. Please keep in mind, additional manual steps are still needed to compensate for AOSP changes, such as requesting and storing kernel sources with each update. Currently, our lead engineer is continuing the maintenance of the base device trees for both LineageOS and CalyxOS to bridge the gap created by the absence of Google Pixel device trees.
AI Agent Executes 'First' End-To-End Ransomware Attack
Read more of this story at Slashdot.
Godot Game Engine No Longer Accepts AI Code
Read more of this story at Slashdot.
Meta Is Charging a Subscription for Smart Glasses Features
Read more of this story at Slashdot.
