Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
Introduction
Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continu…
https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html
#thehackernews #linux #opensource
Introduction
Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continu…
https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html
#thehackernews #linux #opensource
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access.
In one instance highlighted by…
https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html
#thehackernews #linux #opensource
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access.
In one instance highlighted by…
https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html
#thehackernews #linux #opensource
Latest Raspberry Pi OS Release Brings Dock Support and New Screenshot Tool
Raspberry Pi OS 2026-09-15 is now available for download with dock support, new screenshot tool, updated Labwc Wayland compositor, and many other enhancements.
https://9to5linux.com/latest-raspberry-pi-os-release-brings-dock-support-and-new-screenshot-tool
#Distros #News #Debian
Raspberry Pi OS 2026-09-15 is now available for download with dock support, new screenshot tool, updated Labwc Wayland compositor, and many other enhancements.
https://9to5linux.com/latest-raspberry-pi-os-release-brings-dock-support-and-new-screenshot-tool
#Distros #News #Debian
Security updates for Tuesday
Security updates have been issued by Debian (network-manager-l2tp and urwid), Fedora (perl-Dancer2, perl-Data-Entropy, perl-DBI, perl-Protocol-HTTP2, podman-tui, rust-lru, and rust-lru0.16), Mageia (bzip2, cups-filters, libcupsfilters, libssh2, perl-Authen-SASL, perl-HTML-FormFu, tar, unzip, and zip…
https://lwn.net/Articles/1094469/
#lwn #linux #opensource
Security updates have been issued by Debian (network-manager-l2tp and urwid), Fedora (perl-Dancer2, perl-Data-Entropy, perl-DBI, perl-Protocol-HTTP2, podman-tui, rust-lru, and rust-lru0.16), Mageia (bzip2, cups-filters, libcupsfilters, libssh2, perl-Authen-SASL, perl-HTML-FormFu, tar, unzip, and zip…
https://lwn.net/Articles/1094469/
#lwn #linux #opensource
Vondra: PostgreSQL development activity
PostgreSQL contributor Tomas Vondra has published a blog
post looking at development activity in the project, with data from the late
1990s to today.
We're doing ~50 commits per week, give or take. In ~2010 we were doing maybe
25/week, and the trend seems to be a slow and consistent growth. The mo…
https://lwn.net/Articles/1094470/
#lwn #linux #opensource
PostgreSQL contributor Tomas Vondra has published a blog
post looking at development activity in the project, with data from the late
1990s to today.
We're doing ~50 commits per week, give or take. In ~2010 we were doing maybe
25/week, and the trend seems to be a slow and consistent growth. The mo…
https://lwn.net/Articles/1094470/
#lwn #linux #opensource
LWN.net
Vondra: PostgreSQL development activity
PostgreSQL contributor Tomas Vondra has published a blog post looking at development activity i [...]
Sound Open Firmware 2.15 Released With AMD ACP 7.x Support, Intel UAOL
Sound Open Firmware as the open-source, vendor-independent audio DSP firmware stack and driver framework is out today with a new feature update...
https://www.phoronix.com/news/Sound-Open-Firmware-2.15
#phoronix #linux #opensource
Sound Open Firmware as the open-source, vendor-independent audio DSP firmware stack and driver framework is out today with a new feature update...
https://www.phoronix.com/news/Sound-Open-Firmware-2.15
#phoronix #linux #opensource
Phoronix
Sound Open Firmware 2.15 Released With AMD ACP 7.x Support, Intel UAOL
Sound Open Firmware as the open-source, vendor-independent audio DSP firmware stack and driver framework is out today with a new feature update.
113 Void Linux Packages Orphaned Following AI Policy Dispute
More than 100 Void Linux packages are now orphaned after a contributor stepped away following a dispute over AI-generated content.
https://linuxiac.com/113-void-linux-packages-orphaned-following-ai-policy-dispute/
#LinuxDistros #LinuxOpenSourceNews #ai
More than 100 Void Linux packages are now orphaned after a contributor stepped away following a dispute over AI-generated content.
https://linuxiac.com/113-void-linux-packages-orphaned-following-ai-policy-dispute/
#LinuxDistros #LinuxOpenSourceNews #ai
Linuxiac
113 Void Linux Packages Orphaned Following AI Policy Dispute
More than 100 Void Linux packages are now orphaned after a contributor stepped away following a dispute over AI-generated content.
Achieving data sovereignty for SaaS with confidential containers and quantum-safe networking
Independent software vendors (ISVs) that host services in the public cloud face growing scrutiny from customers who need assurance that their data remains secure when processed outside their direct control. This often leads customers to demand that vendors deploy services on premise, within infrastr…
https://www.redhat.com/en/blog/achieving-data-sovereignty-saas-confidential-containers-and-quantum-safe-networking
#redhat #linux #opensource
Independent software vendors (ISVs) that host services in the public cloud face growing scrutiny from customers who need assurance that their data remains secure when processed outside their direct control. This often leads customers to demand that vendors deploy services on premise, within infrastr…
https://www.redhat.com/en/blog/achieving-data-sovereignty-saas-confidential-containers-and-quantum-safe-networking
#redhat #linux #opensource
Redhat
Achieving data sovereignty for SaaS with confidential containers and quantum-safe networking
See how Red Hat and Arqit can help you achieve data sovereignty for Software-as-a-Service with confidential containers and quantum-safe networking.
Opening the black box: Profiling a secured agentic pipeline on Red Hat OpenShift AI
As enterprises move to autonomous agentic pipelines, 2 critical questions emerge: Can I add security to my agents without killing performance? And, Where should I focus optimization effort to get the most out of my agentic system?Most inference benchmarks test the model in isolation—a raw request to…
https://www.redhat.com/en/blog/opening-black-box-profiling-secured-agentic-pipeline-red-hat-openshift-ai
#redhat #linux #opensource
As enterprises move to autonomous agentic pipelines, 2 critical questions emerge: Can I add security to my agents without killing performance? And, Where should I focus optimization effort to get the most out of my agentic system?Most inference benchmarks test the model in isolation—a raw request to…
https://www.redhat.com/en/blog/opening-black-box-profiling-secured-agentic-pipeline-red-hat-openshift-ai
#redhat #linux #opensource
Redhat
Opening the black box: Profiling a secured agentic pipeline on Red Hat OpenShift AI
Learn how to profile secured pipelines for better resource planning so you can optimize agentic AI performance on Red Hat OpenShift AI.
Kubernetes 1.36 restores a lost guarantee for database backups
It’s 2 a.m., and you’re restoring a PostgreSQL cluster from last night’s backup. Its data directory lives on one PersistentVolumeClaim
https://thenewstack.io/kubernetes-volume-group-snapshots/
#Databases #Kubernetes #Storage
It’s 2 a.m., and you’re restoring a PostgreSQL cluster from last night’s backup. Its data directory lives on one PersistentVolumeClaim
https://thenewstack.io/kubernetes-volume-group-snapshots/
#Databases #Kubernetes #Storage
The New Stack
Kubernetes 1.36 restores a lost guarantee for database backups
Kubernetes 1.36 fixes multi-volume database backups with VolumeGroupSnapshot, bringing back point-in-time consistency group protection.
Zen Internet expand Wi-Fi 7 routers and launch 2.5Gbps broadband via MS3’s UK fibre
Rochdale-based UK ISP Zen Internet, which began selling packages via MS3’s full fibre (FTTP) network in parts of Hull (East Yorkshire) and Lincolnshire in June 2026, has now revealed that they’ve made even faster speeds of 2.5Gbps (2.3Gbps average) available to new residential and business customers…
https://www.ispreview.co.uk/index.php/2026/09/zen-internet-expand-wi-fi-7-routers-and-launch-2-5gbps-broadband-via-ms3s-uk-fibre.html
#ISPNews #FTTP #ZenInternet
Rochdale-based UK ISP Zen Internet, which began selling packages via MS3’s full fibre (FTTP) network in parts of Hull (East Yorkshire) and Lincolnshire in June 2026, has now revealed that they’ve made even faster speeds of 2.5Gbps (2.3Gbps average) available to new residential and business customers…
https://www.ispreview.co.uk/index.php/2026/09/zen-internet-expand-wi-fi-7-routers-and-launch-2-5gbps-broadband-via-ms3s-uk-fibre.html
#ISPNews #FTTP #ZenInternet
ISPreview
Zen Internet expand Wi-Fi 7 routers and launch 2.5Gbps broadband via MS3’s UK fibre
Rochdale-based UK ISP Zen Internet, which began selling packages via MS3’s full fibre (FTTP) network in parts of Hull (East Yorkshire) and Lincolnshire in Jun
Java 27 Reaches GA With The G1 Garbage Collector By Default Everywhere
Oracle christened Java 27 today with the OpenJDK 27 release reaching general availability (GA) status...
https://www.phoronix.com/news/OpenJDK-27-Java-27
#phoronix #linux #opensource
Oracle christened Java 27 today with the OpenJDK 27 release reaching general availability (GA) status...
https://www.phoronix.com/news/OpenJDK-27-Java-27
#phoronix #linux #opensource
Phoronix
Java 27 Reaches GA With The G1 Garbage Collector By Default Everywhere
Oracle christened Java 27 today with the OpenJDK 27 release reaching general availability (GA) status.
Justin Wheeler: What does AI Alignment mean in open source?
In July, I shared an update about my new role as AI Alignment Community Architect at Red Hat, focused on Fedora.
This post clarifies what that role entails, why "AI alignment" is more than a technical term, and how I plan to support the Fedora community in leveraging LLM-gen-AI.
I organized this b…
https://jwheel.org/blog/2026/09/ai-alignment/
#jwheel #linux #opensource
In July, I shared an update about my new role as AI Alignment Community Architect at Red Hat, focused on Fedora.
This post clarifies what that role entails, why "AI alignment" is more than a technical term, and how I plan to support the Fedora community in leveraging LLM-gen-AI.
I organized this b…
https://jwheel.org/blog/2026/09/ai-alignment/
#jwheel #linux #opensource
Justin Wheeler
What does AI Alignment mean in open source?
Reclaiming the term "AI Alignment" for the alignment of LLM-gen-AI models with open source community values.
VirtualBox 7.2.18 Released with More Fixes and Improvements
VirtualBox 7.2.18 adds Linux kernel 7.3 and RHEL 10.3 support, while fixing 3D crashes, VDI corruption, and Windows 11 ARM issues.
https://linuxiac.com/virtualbox-7-2-18-released-with-more-fixes-and-improvements/
#Software #LinuxOpenSourceNews #virtualbox
VirtualBox 7.2.18 adds Linux kernel 7.3 and RHEL 10.3 support, while fixing 3D crashes, VDI corruption, and Windows 11 ARM issues.
https://linuxiac.com/virtualbox-7-2-18-released-with-more-fixes-and-improvements/
#Software #LinuxOpenSourceNews #virtualbox
Linuxiac
VirtualBox 7.2.18 Released with More Fixes and Improvements
VirtualBox 7.2.18 adds Linux kernel 7.3 and RHEL 10.3 support, while fixing 3D crashes, VDI corruption, and Windows 11 ARM issues.
Get more Steam Deck / Steam Machine Verified games in the Fanatical Play on the Go Bundle
New for September is the Fanatical "Build your own Play on the Go BundleFest Edition" bundle, with all games being rated Steam Deck / Steam Machine Verified.Read the full article on GamingOnLinux.
https://www.gamingonlinux.com/2026/09/get-more-steam-deck-steam-machine-verified-games-in-the-fanatical-play-on-the-go-bundle/
#GameBundle #SteamOS #Fanatical
New for September is the Fanatical "Build your own Play on the Go BundleFest Edition" bundle, with all games being rated Steam Deck / Steam Machine Verified.Read the full article on GamingOnLinux.
https://www.gamingonlinux.com/2026/09/get-more-steam-deck-steam-machine-verified-games-in-the-fanatical-play-on-the-go-bundle/
#GameBundle #SteamOS #Fanatical
GamingOnLinux
Get more Steam Deck / Steam Machine Verified games in the Fanatical Play on the Go Bundle
New for September is the Fanatical Build your own Play on the Go BundleFest Edition bundle, with all games being rated Steam Deck / Steam Machine Verified.
Rune Goes Open Source, Looks to Share Revenue With Contributors
The Go-based IDE is now available under GPLv3, and contributors keep the rights to their work.
https://feed.itsfoss.com/link/24361/17462499/rune-open-source-ide
#News #feed #linux
The Go-based IDE is now available under GPLv3, and contributors keep the rights to their work.
https://feed.itsfoss.com/link/24361/17462499/rune-open-source-ide
#News #feed #linux
It's FOSS
Rune Goes Open Source, Looks to Share Revenue With Contributors
The Go-based IDE is now available under GPLv3, and contributors keep the rights to their work.
Announcing Fedora Linux 45 Beta
Fedora Linux 45 Beta is here! On Tuesday, 15 September 2026 you can download or upgrade your systems from your usual spots to start enjoying what F45 has to offer early. How to get the beta release You can download F45 Beta, or our pre-release edition versions, from any of the following places: You…
https://fedoramagazine.org/announcing-fedora-linux-45-beta/
#FedoraProjectCommunity #fedoramagazine #linux
Fedora Linux 45 Beta is here! On Tuesday, 15 September 2026 you can download or upgrade your systems from your usual spots to start enjoying what F45 has to offer early. How to get the beta release You can download F45 Beta, or our pre-release edition versions, from any of the following places: You…
https://fedoramagazine.org/announcing-fedora-linux-45-beta/
#FedoraProjectCommunity #fedoramagazine #linux
Fedora Magazine
Announcing Fedora Linux 45 Beta - Fedora Magazine
Article Announcing Fedora Linux 45 Beta
Announcing Fedora Linux Asahi Remix 45 Beta
We are happy to announce the availability of Fedora Linux Asahi Remix 45 Beta. This pre-release will bring the freshly announced Fedora Linux 45 Beta to Apple Silicon Macs. We expect to announce general availability of Fedora Linux Asahi Remix 45 in about a month. This will coincide with the overall…
https://fedoramagazine.org/announcing-fedora_asahi_remix_45_beta/
#FedoraProjectCommunity #fedoramagazine #linux
We are happy to announce the availability of Fedora Linux Asahi Remix 45 Beta. This pre-release will bring the freshly announced Fedora Linux 45 Beta to Apple Silicon Macs. We expect to announce general availability of Fedora Linux Asahi Remix 45 in about a month. This will coincide with the overall…
https://fedoramagazine.org/announcing-fedora_asahi_remix_45_beta/
#FedoraProjectCommunity #fedoramagazine #linux
Fedora Magazine
Announcing Fedora Linux Asahi Remix 45 Beta - Fedora Magazine
The datacenter myth: Why sovereign AI demands a tenancy model, not just geography
There’s a version of the digital sovereignty conversation that stops at geography: Put the servers in-country, keep the data inside the border, tick the box. It was never quite enough for cloud, and in a regulatory era that has shifted from “trust us” to “show us,” it’s definitively not enough for A…
https://www.redhat.com/en/blog/datacenter-myth-why-sovereign-ai-demands-tenancy-model-not-just-geography
#redhat #linux #opensource
There’s a version of the digital sovereignty conversation that stops at geography: Put the servers in-country, keep the data inside the border, tick the box. It was never quite enough for cloud, and in a regulatory era that has shifted from “trust us” to “show us,” it’s definitively not enough for A…
https://www.redhat.com/en/blog/datacenter-myth-why-sovereign-ai-demands-tenancy-model-not-just-geography
#redhat #linux #opensource
Redhat
The datacenter myth: Why sovereign AI demands a tenancy model, not just geography
Discover Red Hat's blueprint for sovereign AI, offering hard isolation, open stack, and transparency for a comprehensive multi-tenant AI platform.
How to attach an owner to every cloud resource you find
The engineer who knew why that cloud instance existed has left the company. The instance is still running, the bill
https://thenewstack.io/attach-owner-cloud-resources/
#CloudServices #DevOps #PlatformEngineering
The engineer who knew why that cloud instance existed has left the company. The instance is still running, the bill
https://thenewstack.io/attach-owner-cloud-resources/
#CloudServices #DevOps #PlatformEngineering
The New Stack
How to attach an owner to every cloud resource you find
Stop orphan cloud resources using query syncing, strict tagging policies, and audit records that survive employee turnover.
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.
The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote at…
https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
#thehackernews #linux #opensource
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.
The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote at…
https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
#thehackernews #linux #opensource