Tech Wire
62 subscribers
2.54K photos
1 video
242K links
Technology news
Supporting these networks


TechCrunch
Cnet
Letstalkbitcoin
TheHackersNews
EnGadget
PCMag
Defcon
Bitcoin
Coindesk
Wired
Wisprtech
KaliLinux
BBC
SecruityFocus
Cisco
Qubes-OS
Google
Wikileaks
TorProject
GameStop
IGN
E3
Download Telegram
Samsung Galaxy Watch 9 vs Galaxy Watch Ultra 2: Smartwatch Head-to-Head
https://www.cnet.com/tech/mobile/samsung-galaxy-watch-9-vs-galaxy-watch-ultra-2-smartwatch-head-to-head/

Samsung’s new wearables get upgrades and price bumps over their predecessors.
Make Something Awesome With the $54 Fanttik F2 Master Mini
https://www.cnet.com/uncategorized/fanttik-f2-master-mini-tool-kit-2026-07-27/

Snag a sweet $26 discount on this lightweight Cordless Rotary Tool Kit with our code.
Should You Spend $429 on a Fan? Here’s My Take After Testing
https://www.cnet.com/home/smart-home/copy-of-should-you-spend-429-on-a-fan-heres-my-take-after-testing/

The Balmuda NatureWind Studio proves the value of an intuitive design.
Switch to a Refurbished Roborock Vacuum and Shorten Your To-Do List for Good
https://www.cnet.com/deals/woot-refurbished-roborock-vacuum-sale-2026-07-27/

Woot has over a dozen used models on sale for today only, with prices starting at just $100.
The 34-Hour Laptop Is Here. Here’s Why Battery Life Has Exploded in Recent Years
https://www.cnet.com/tech/computing/why-laptop-battery-life-has-exploded-in-recent-years/

We’ve tracked laptop battery performance for decades, and we’ve never seen a jump like this. Here’s why you can ditch your charger for longer, and which laptops go the distance.
Peacock and YouTube to Bundle Up in 2027
https://www.cnet.com/tech/services-and-software/peacock-and-youtube-to-bundle-up-in-2027/

NBCUniversal and YouTube are also broadening their collaboration in the US and beyond.
The Oura Ring 5 Is Way Smaller, and That’s a Huge Deal
https://www.cnet.com/videos/the-oura-ring-5-is-way-smaller-and-thats-a-huge-deal/

I tested the Oura Ring 5 for two months to see if its smaller design lives up to the hype and whether it’s worth the higher price.
Get a Brand-New Samsung Galaxy Z Fold 8 on T-Mobile
https://www.cnet.com/deals/get-a-brand-new-samsung-galaxy-z-fold-8-on-t-mobile/

Get Samsung’s latest foldable when you trade in an eligible device on T-Mobile’s Experience Beyond plan.
Stay Safe in Severe Weather With Up to $1,800 Off EcoFlow Power Stations
https://www.cnet.com/deals/ecoflow-summer-sale-2026-07-27/

They’re a must-have for blackouts and emergencies, and this sale is your chance to snag one at a lower price.
Walmart Deals of the Day: Over $200 Off a Roborock Vacuum for Effortlessly Spotless Floors
https://www.cnet.com/deals/walmart-deals-of-the-day-july-27-2026/

Plus, record-low prices on a Razer Xbox controller and JBL’s newest pocket-sized speaker.
Xbox Live Is Down Monday: Microsoft Says It’s Working on a Resolution
https://www.cnet.com/tech/gaming/xbox-live-is-down-monday-microsoft-says-its-working-on-a-resolution/

Players may not be able to sign in, find games or launch apps, and might be disconnected while logged in.
Forget the New Z Fold Ultra, Samsung’s Galaxy A57 5G Just Hit a Record-Low Price
https://www.cnet.com/deals/samsung-galaxy-a57-5g-deal-2026-07-27/

This feature-packed midrange phone just got a $125 price cut.
Give Your Lumbar Some Love With a LiberNovo Chair While They’re Down by up to 44%
https://www.cnet.com/deals/give-your-lumbar-some-love-with-a-libernovo-chair-while-theyre-down-by-up-to-44/

Upgrade your home office or gaming setup without having to break the bank.
Apple Delays Smart Glasses Launch Over Privacy Issues, Report Says
https://www.cnet.com/tech/services-and-software/apple-delays-smart-glasses-launch-over-privacy-issues-report-says/

The company is working to reassure people that the glasses won’t be used to record them surreptitiously.
Rivian Sues US Government for Tariff Refund
https://www.cnet.com/home/electric-vehicles/rivian-sues-us-government-for-tariff-refund/

The EV maker says a Supreme Court ruling striking down “Liberation Day” tariffs isn’t enough — it wants a guaranteed refund with interest.
‘Demon Slayer: Infinity Castle’: How to Stream the Movie Today
https://www.cnet.com/culture/entertainment/demon-slayer-infinity-castle-how-to-stream-the-movie-today/

One of the top anime movies in the world is now available to stream.
Sales Tax Holidays 2026: Here’s What You Need to Know
https://www.cnet.com/tech/sales-tax-holidays-2026-heres-all-what-you-need-to-know/

Don’t fret if you missed out on recent back-to-school deals. Sales tax holidays can help you save on laptops, school supplies, clothing and more. Learn more about it here.
I Don’t Travel Without These Online Safety Tools and Tricks
https://www.cnet.com/tech/services-and-software/travel-tips-for-online-safety/

Traveling can expose you to various online threats, but you can protect yourself with the right tools and security practices.
Apple Upgrade Program Will Let You Lease an iPhone Without Sticker Shock
https://www.cnet.com/tech/apple-upgrade-program-available-now-us-lease-iphone-2/

The program will take the sting out of owning Apple devices, including Macs, iPads and Apple Watches.
XSAs released on 2026-07-28
https://www.qubes-os.org/news/2026/07/28/xsas-released-on-2026-07-28/

The Xen Project (https://xenproject.org/) has released one or more Xen security advisories (XSAs) (https://xenbits.xen.org/xsa/).
The security of Qubes OS is affected.

XSAs that DO affect the security of Qubes OS

The following XSAs do affect the security of Qubes OS:


XSA-500 (https://xenbits.xen.org/xsa/advisory-500.html): See QSB-116 (https://www.qubes-os.org/news/2026/07/28/qsb-116/).
XSA-505 (https://xenbits.xen.org/xsa/advisory-505.html): See QSB-116 (https://www.qubes-os.org/news/2026/07/28/qsb-116/).
XSA-506 (https://xenbits.xen.org/xsa/advisory-506.html): See QSB-116 (https://www.qubes-os.org/news/2026/07/28/qsb-116/).
XSA-507 (https://xenbits.xen.org/xsa/advisory-507.html): See QSB-116 (https://www.qubes-os.org/news/2026/07/28/qsb-116/).


XSAs that DO NOT affect the security of Qubes OS

The following XSAs do not affect the security of Qubes OS, and no user action is necessary:


XSA-495 (https://xenbits.xen.org/xsa/advisory-495.html): Denial of service only. Shadow paging is disabled in Qubes OS at build time.
XSA-496 (https://xenbits.xen.org/xsa/advisory-496.html): Denial of service only. Affects only Xen 4.21 and higher; Qubes OS 4.3 uses Xen 4.19.
XSA-497 (https://xenbits.xen.org/xsa/advisory-497.html): Qubes OS does not use pygrub.
XSA-499 (https://xenbits.xen.org/xsa/advisory-499.html): Denial of service only.
XSA-501 (https://xenbits.xen.org/xsa/advisory-501.html): Qubes OS has grant tables v2 disabled.
XSA-502 (https://xenbits.xen.org/xsa/advisory-502.html): Qubes OS does not use vnuma.
XSA-503 (https://xenbits.xen.org/xsa/advisory-503.html): Allows leaking internal information about a qube only to itself, not other qubes.
XSA-504 (https://xenbits.xen.org/xsa/advisory-504.html): Viridian is not enabled in Qubes OS.
XSA-508 (https://xenbits.xen.org/xsa/advisory-508.html): Qubes OS does not use pygrub.


About this announcement

Qubes OS uses the Xen hypervisor (https://wiki.xenproject.org/wiki/Xen_Project_Software_Overview) as part of its architecture (https://doc.qubes-os.org/en/latest/developer/system/architecture.html). When the Xen Project (https://xenproject.org/) publicly discloses a vulnerability in the Xen hypervisor, they issue a notice called a Xen security advisory (XSA) (https://xenproject.org/developers/security-policy/). Vulnerabilities in the Xen hypervisor sometimes have security implications for Qubes OS. When they do, we issue a notice called a Qubes security bulletin (QSB) (https://www.qubes-os.org/security/qsb/). (QSBs are also issued for non-Xen vulnerabilities.) However, QSBs can provide only positive confirmation that certain XSAs do affect the security of Qubes OS. QSBs cannot provide negative confirmation that other XSAs do not affect the security of Qubes OS. Therefore, we also maintain an XSA tracker (https://www.qubes-os.org/security/xsa/), which is a comprehensive list of all XSAs publicly disclosed to date, including whether each one affects the security of Qubes OS. When new XSAs are published, we add them to the XSA tracker and publish a notice like this one in order to inform Qubes users that a new batch of XSAs has been released and whether each one affects the security of Qubes OS.
QSB-116: Multiple Xen issues (XSA-500, XSA-505, XSA-506, XSA-507)
https://www.qubes-os.org/news/2026/07/28/qsb-116/

We have published Qubes Security Bulletin (QSB) 116: Multiple Xen issues (XSA-500, XSA-505, XSA-506, XSA-507) (https://github.com/QubesOS/qubes-secpack/blob/f9001423ffb11de26bdcf0b4478838739cc3f6b3/QSBs/qsb-116-2026.txt). The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.

Qubes Security Bulletin 116


---===[ Qubes Security Bulletin 116 ]===---

2026-07-28

Multiple Xen issues (XSA-500, XSA-505, XSA-506, XSA-507)

User action
------------

Continue to update normally [1] in order to receive the security updates
described in the "Patching" section below. No other user action is
required in response to this QSB.

Summary
--------

On 2026-07-28, the Xen Project published the security advisories below.

XSA-500 [3] "grant-table: type confusion in grant-copy":

| When grant-copy operations are processed, the respective grant may or
| may not already be in use by another operation (a mapping or another
| copy). For all copy operations the referenced guest frame is looked
| up. When another operation is already active for the grant (the grant
| is "pinned"), what is being supplied back to actually carry out
| permission checks and copy operation may not be consistent: The
| permission check may be carried out on a page different from the one
| involved in the copy.


XSA-505 [4] "evtchn: Race between FIFO expand and reset":

| The EVTCHNOP_expand_array hypercall checks for whether FIFO event
| channels are enabled, but without holding the correct lock. It can
| race with EVTCHNOP_reset, resulting in deferencing a NULL pointer.


XSA-506 [5] "correct buffer checks for DM_OP hypercalls":

| Parts of the DM_OP handling code assumes the caller has provided the
| required number of buffers for the given operation without any
| checking being done. As a result, certain operations might access
| stack rubble as structures are possibly uninitialized.

XSA-507 [6] "PoD: Don't try to reclaim special pages":

| A guest started with Populated on Demand enabled (PoD) can attempt to
| reclaim pages which aren't regular guest RAM. This can cause
| corruption of memory management state in Xen.

Impact
-------

XSA-500 and XSA-507: A malicious qube may be able to compromise
Qubes OS.

XSA-505: A malicious PV qube [7] may be able to compromise Qubes OS. The
same impact applies to stubdomains for HVM qubes [8], but in this case
an attacker would first have to discover and exploit an independent
vulnerability (in QEMU) in order to gain access to the stubdomain.

XSA-506: The stubdomain for an HVM qube may be able to leak data from
other qubes in the system. In order to exploit this vulnerability, an
attacker would first have to discover and exploit an independent
vulnerability (in QEMU) in order to gain access to the stubdomain.

Affected systems
-----------------

XSA-500: All systems are affected.

XSA-505: Systems with either PV qubes or stubdomains for HVM qubes (or
both) are affected, but the vulnerability is easier to exploit on
systems with PV qubes. In the default Qubes OS configuration, there are
no PV qubes, but sys-net and sys-usb are HVM qubes that have
stubdomains. This means that the vulnerability is more difficult to
exploit in the default Qubes OS configuration, but if a user has
manually created PV qubes in a particular system, the vulnerability will
be easier to exploit on that system.

XSA-506: Systems with untrusted HVM qubes are affected. In the default
configuration of Qubes OS, sys-net and sys-usb are HVM qubes and are
considered to be untrusted.

XSA-507: Systems are affected if they have qubes that are included in
memory balancing but that don't advertise memory hotplug support. This