Java 27 Reaches GA With The G1 Garbage Collector By Default Everywhere
Oracle christened Java 27 today with the OpenJDK 27 release reaching general availability (GA) status...
https://www.phoronix.com/news/OpenJDK-27-Java-27
#phoronix #linux #opensource
Oracle christened Java 27 today with the OpenJDK 27 release reaching general availability (GA) status...
https://www.phoronix.com/news/OpenJDK-27-Java-27
#phoronix #linux #opensource
Phoronix
Java 27 Reaches GA With The G1 Garbage Collector By Default Everywhere
Oracle christened Java 27 today with the OpenJDK 27 release reaching general availability (GA) status.
Justin Wheeler: What does AI Alignment mean in open source?
In July, I shared an update about my new role as AI Alignment Community Architect at Red Hat, focused on Fedora.
This post clarifies what that role entails, why "AI alignment" is more than a technical term, and how I plan to support the Fedora community in leveraging LLM-gen-AI.
I organized this b…
https://jwheel.org/blog/2026/09/ai-alignment/
#jwheel #linux #opensource
In July, I shared an update about my new role as AI Alignment Community Architect at Red Hat, focused on Fedora.
This post clarifies what that role entails, why "AI alignment" is more than a technical term, and how I plan to support the Fedora community in leveraging LLM-gen-AI.
I organized this b…
https://jwheel.org/blog/2026/09/ai-alignment/
#jwheel #linux #opensource
Justin Wheeler
What does AI Alignment mean in open source?
Reclaiming the term "AI Alignment" for the alignment of LLM-gen-AI models with open source community values.
VirtualBox 7.2.18 Released with More Fixes and Improvements
VirtualBox 7.2.18 adds Linux kernel 7.3 and RHEL 10.3 support, while fixing 3D crashes, VDI corruption, and Windows 11 ARM issues.
https://linuxiac.com/virtualbox-7-2-18-released-with-more-fixes-and-improvements/
#Software #LinuxOpenSourceNews #virtualbox
VirtualBox 7.2.18 adds Linux kernel 7.3 and RHEL 10.3 support, while fixing 3D crashes, VDI corruption, and Windows 11 ARM issues.
https://linuxiac.com/virtualbox-7-2-18-released-with-more-fixes-and-improvements/
#Software #LinuxOpenSourceNews #virtualbox
Linuxiac
VirtualBox 7.2.18 Released with More Fixes and Improvements
VirtualBox 7.2.18 adds Linux kernel 7.3 and RHEL 10.3 support, while fixing 3D crashes, VDI corruption, and Windows 11 ARM issues.
Get more Steam Deck / Steam Machine Verified games in the Fanatical Play on the Go Bundle
New for September is the Fanatical "Build your own Play on the Go BundleFest Edition" bundle, with all games being rated Steam Deck / Steam Machine Verified.Read the full article on GamingOnLinux.
https://www.gamingonlinux.com/2026/09/get-more-steam-deck-steam-machine-verified-games-in-the-fanatical-play-on-the-go-bundle/
#GameBundle #SteamOS #Fanatical
New for September is the Fanatical "Build your own Play on the Go BundleFest Edition" bundle, with all games being rated Steam Deck / Steam Machine Verified.Read the full article on GamingOnLinux.
https://www.gamingonlinux.com/2026/09/get-more-steam-deck-steam-machine-verified-games-in-the-fanatical-play-on-the-go-bundle/
#GameBundle #SteamOS #Fanatical
GamingOnLinux
Get more Steam Deck / Steam Machine Verified games in the Fanatical Play on the Go Bundle
New for September is the Fanatical Build your own Play on the Go BundleFest Edition bundle, with all games being rated Steam Deck / Steam Machine Verified.
Rune Goes Open Source, Looks to Share Revenue With Contributors
The Go-based IDE is now available under GPLv3, and contributors keep the rights to their work.
https://feed.itsfoss.com/link/24361/17462499/rune-open-source-ide
#News #feed #linux
The Go-based IDE is now available under GPLv3, and contributors keep the rights to their work.
https://feed.itsfoss.com/link/24361/17462499/rune-open-source-ide
#News #feed #linux
It's FOSS
Rune Goes Open Source, Looks to Share Revenue With Contributors
The Go-based IDE is now available under GPLv3, and contributors keep the rights to their work.
Announcing Fedora Linux 45 Beta
Fedora Linux 45 Beta is here! On Tuesday, 15 September 2026 you can download or upgrade your systems from your usual spots to start enjoying what F45 has to offer early. How to get the beta release You can download F45 Beta, or our pre-release edition versions, from any of the following places: You…
https://fedoramagazine.org/announcing-fedora-linux-45-beta/
#FedoraProjectCommunity #fedoramagazine #linux
Fedora Linux 45 Beta is here! On Tuesday, 15 September 2026 you can download or upgrade your systems from your usual spots to start enjoying what F45 has to offer early. How to get the beta release You can download F45 Beta, or our pre-release edition versions, from any of the following places: You…
https://fedoramagazine.org/announcing-fedora-linux-45-beta/
#FedoraProjectCommunity #fedoramagazine #linux
Fedora Magazine
Announcing Fedora Linux 45 Beta - Fedora Magazine
Article Announcing Fedora Linux 45 Beta
Announcing Fedora Linux Asahi Remix 45 Beta
We are happy to announce the availability of Fedora Linux Asahi Remix 45 Beta. This pre-release will bring the freshly announced Fedora Linux 45 Beta to Apple Silicon Macs. We expect to announce general availability of Fedora Linux Asahi Remix 45 in about a month. This will coincide with the overall…
https://fedoramagazine.org/announcing-fedora_asahi_remix_45_beta/
#FedoraProjectCommunity #fedoramagazine #linux
We are happy to announce the availability of Fedora Linux Asahi Remix 45 Beta. This pre-release will bring the freshly announced Fedora Linux 45 Beta to Apple Silicon Macs. We expect to announce general availability of Fedora Linux Asahi Remix 45 in about a month. This will coincide with the overall…
https://fedoramagazine.org/announcing-fedora_asahi_remix_45_beta/
#FedoraProjectCommunity #fedoramagazine #linux
Fedora Magazine
Announcing Fedora Linux Asahi Remix 45 Beta - Fedora Magazine
The datacenter myth: Why sovereign AI demands a tenancy model, not just geography
There’s a version of the digital sovereignty conversation that stops at geography: Put the servers in-country, keep the data inside the border, tick the box. It was never quite enough for cloud, and in a regulatory era that has shifted from “trust us” to “show us,” it’s definitively not enough for A…
https://www.redhat.com/en/blog/datacenter-myth-why-sovereign-ai-demands-tenancy-model-not-just-geography
#redhat #linux #opensource
There’s a version of the digital sovereignty conversation that stops at geography: Put the servers in-country, keep the data inside the border, tick the box. It was never quite enough for cloud, and in a regulatory era that has shifted from “trust us” to “show us,” it’s definitively not enough for A…
https://www.redhat.com/en/blog/datacenter-myth-why-sovereign-ai-demands-tenancy-model-not-just-geography
#redhat #linux #opensource
Redhat
The datacenter myth: Why sovereign AI demands a tenancy model, not just geography
Discover Red Hat's blueprint for sovereign AI, offering hard isolation, open stack, and transparency for a comprehensive multi-tenant AI platform.
How to attach an owner to every cloud resource you find
The engineer who knew why that cloud instance existed has left the company. The instance is still running, the bill
https://thenewstack.io/attach-owner-cloud-resources/
#CloudServices #DevOps #PlatformEngineering
The engineer who knew why that cloud instance existed has left the company. The instance is still running, the bill
https://thenewstack.io/attach-owner-cloud-resources/
#CloudServices #DevOps #PlatformEngineering
The New Stack
How to attach an owner to every cloud resource you find
Stop orphan cloud resources using query syncing, strict tagging policies, and audit records that survive employee turnover.
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.
The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote at…
https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
#thehackernews #linux #opensource
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.
The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote at…
https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
#thehackernews #linux #opensource
or1k.net
Daily Digest — September 17, 2026
Ubuntu 26.10 moves to Rust coreutils, GNOME 51 debuts, and Kubernetes v1.37 hardens storage. Plus, major CVEs hit WSO2, Issabel PBX, and Acronis plugins.
📰 Daily Digest — September 17, 2026
• Ubuntu 26.10 Finally Dumps GNU cp, mv, and rm for Rust
• GNOME 51 Cleans Up Its Graphics Stack and Improves Files
• Kubernetes v1.37 Closes a Glaring emptyDir Security Hole
• WSO2 API Manager Suffers Active Attacks Over a Dumb JWT Bypass
• Fedora 45 Finally Replaces the Ancient In-Kernel Console
• Acronis Backup Plugins Targeted by Active Privilege Exploits
• Issabel PBX Framework Exploited via Hard-Coded JWT Key
• Linux Scheduler Might Start Rolling Dice to Find Idle Cores
• GEFS Brings Plan 9 Copy-on-Write Storage to OpenBSD
• AMD Prepares PCIe 6.0 Encryption for EPYC Venice
• AI Coding Assistant Hijack Spreads Worm Across 100 Repos
• Ubuntu 26.10's amd64v3 Builds Bring Speedups to Budget Laptops
• Flatpak's Terminal Intent Might Finally Let You Change Defaults
• Tails 7.13 Speeds Up the Paranoid Shutdown Process
• KDE Cleans Up NetworkManager Prompts with QML Migration
https://or1k.net/digests/daily-digest-2026-09-17/
• Ubuntu 26.10 Finally Dumps GNU cp, mv, and rm for Rust
• GNOME 51 Cleans Up Its Graphics Stack and Improves Files
• Kubernetes v1.37 Closes a Glaring emptyDir Security Hole
• WSO2 API Manager Suffers Active Attacks Over a Dumb JWT Bypass
• Fedora 45 Finally Replaces the Ancient In-Kernel Console
• Acronis Backup Plugins Targeted by Active Privilege Exploits
• Issabel PBX Framework Exploited via Hard-Coded JWT Key
• Linux Scheduler Might Start Rolling Dice to Find Idle Cores
• GEFS Brings Plan 9 Copy-on-Write Storage to OpenBSD
• AMD Prepares PCIe 6.0 Encryption for EPYC Venice
• AI Coding Assistant Hijack Spreads Worm Across 100 Repos
• Ubuntu 26.10's amd64v3 Builds Bring Speedups to Budget Laptops
• Flatpak's Terminal Intent Might Finally Let You Change Defaults
• Tails 7.13 Speeds Up the Paranoid Shutdown Process
• KDE Cleans Up NetworkManager Prompts with QML Migration
https://or1k.net/digests/daily-digest-2026-09-17/
or1k.net
Daily Digest — September 18, 2026
Daily digest: Cisco scrambles to patch a CVSS 10.0 zero-day in its Identity Services Engine, Check Point fixes an unauthenticated root exploit, and Unbound addresses a critical DNSSEC validator bug.
📰 Daily Digest — September 18, 2026
• Cisco Bags Another CVSS 10.0 Zero-Day in Identity Services Engine
• Unbound DNSSEC Validator Offers RCE via Malicious Zones
• Docker Sandboxes for macOS Fail at Basic Isolation
• Check Point Handing Out Root Shells via Stack Overflow
• BIND 9 Patches 14 Flaws, Including DoH Connection Crashes
• Rust Project Warns of Targeted Social Engineering Attacks
• GNOME 51 Drops with Better Performance and UI Refinements
• Sidero Labs Wraps Talos Kubernetes OS in Enterprise Compliance
• Dragonfly 2.0 Optimizes In-Memory Performance and Valkey Support
• GNOME Foundation Reshuffles Board and Hires Finance Director
• Fujitsu Formally Unveils the 144-Core MONAKA ARMv9 Processor
• Rust Coreutils 0.12 Clears the Runway for Ubuntu's Transition
• Jemalloc 5.4 Overhauls Portability and Cleans Up Technical Debt
• Linux Kernel Proposal Aims to Standardize GPU Memory Statistics
• New ASUS Glymur Driver Enhances Snapdragon X2 Linux Support
https://or1k.net/digests/daily-digest-2026-09-18/
• Cisco Bags Another CVSS 10.0 Zero-Day in Identity Services Engine
• Unbound DNSSEC Validator Offers RCE via Malicious Zones
• Docker Sandboxes for macOS Fail at Basic Isolation
• Check Point Handing Out Root Shells via Stack Overflow
• BIND 9 Patches 14 Flaws, Including DoH Connection Crashes
• Rust Project Warns of Targeted Social Engineering Attacks
• GNOME 51 Drops with Better Performance and UI Refinements
• Sidero Labs Wraps Talos Kubernetes OS in Enterprise Compliance
• Dragonfly 2.0 Optimizes In-Memory Performance and Valkey Support
• GNOME Foundation Reshuffles Board and Hires Finance Director
• Fujitsu Formally Unveils the 144-Core MONAKA ARMv9 Processor
• Rust Coreutils 0.12 Clears the Runway for Ubuntu's Transition
• Jemalloc 5.4 Overhauls Portability and Cleans Up Technical Debt
• Linux Kernel Proposal Aims to Standardize GPU Memory Statistics
• New ASUS Glymur Driver Enhances Snapdragon X2 Linux Support
https://or1k.net/digests/daily-digest-2026-09-18/
or1k.net
Daily Digest — September 19, 2026
Linux kernel hits public local root exploits, Google swaps Android's Binder C code for Rust, and Ubuntu 26.10 upgrades to the new Linux 7.3 kernel.
📰 Daily Digest — September 19, 2026
• GNOME 51 Arrives Alongside GNOME OS Memory Compression
• Java 27 Defaults to G1 GC and Shrinks Object Headers
• MariaDB 13.0 Goes Stable with Useful SQL Additions
• Ubuntu 26.10 Grabs the Linux 7.3 Kernel Ahead of Schedule
• Old C Networking Flaws Exposed by New Local Root Exploits
• Microsoft Fixes CVSS 10.0 Missing Authentication in Azure AI
• WordPress Click2Shell Chain Forces Silent Theme Installations
• Google Dumps Android's Legacy Binder C Code for Rust
• Upcoming Kbuild Patches Slash Incremental Kernel Build Times
• NVIDIA Brings Native Rust Compilation to CUDA GPU Kernels
• LibreOffice Refuses to Bloat Its Suite with Built-In AI
• Intel Scraps Paid Bug Bounties in Favor of Free Labor
• AI Coding Agents Tricked Into Installing Rogue Plugins
• Reverse-Engineered Apple Video Decoder Driver Headed Upstream
• Ubuntu 26.10 Tweaks OOM Rules to Keep Desktops Alive
https://or1k.net/digests/daily-digest-2026-09-19/
• GNOME 51 Arrives Alongside GNOME OS Memory Compression
• Java 27 Defaults to G1 GC and Shrinks Object Headers
• MariaDB 13.0 Goes Stable with Useful SQL Additions
• Ubuntu 26.10 Grabs the Linux 7.3 Kernel Ahead of Schedule
• Old C Networking Flaws Exposed by New Local Root Exploits
• Microsoft Fixes CVSS 10.0 Missing Authentication in Azure AI
• WordPress Click2Shell Chain Forces Silent Theme Installations
• Google Dumps Android's Legacy Binder C Code for Rust
• Upcoming Kbuild Patches Slash Incremental Kernel Build Times
• NVIDIA Brings Native Rust Compilation to CUDA GPU Kernels
• LibreOffice Refuses to Bloat Its Suite with Built-In AI
• Intel Scraps Paid Bug Bounties in Favor of Free Labor
• AI Coding Agents Tricked Into Installing Rogue Plugins
• Reverse-Engineered Apple Video Decoder Driver Headed Upstream
• Ubuntu 26.10 Tweaks OOM Rules to Keep Desktops Alive
https://or1k.net/digests/daily-digest-2026-09-19/
or1k.net
Daily Digest — September 20, 2026
Today's digest covers newly flagged Linux kernel vulnerabilities, a critical unauthenticated RCE in Orkes Conductor, and RustFS 1.0 reaching general availability.
📰 Daily Digest — September 20, 2026
• CISA flags three exploited Linux kernel bugs you should have patched
• Unsandboxed GraalVM sinks Orkes Conductor with critical RCE
• SolarWinds does it again with a hard-coded key in ARM
• CrowdSec loses 170 private repos to basic credential hygiene failure
• Stale Debian packages and SSO trust issues let researchers breach OpenAI
• Google Gemini accidentally hacks real-world systems during test mix-up
• Simple VFS dentry optimization yields 39% speedup in Linux 7.4
• Linux 7.3-rc4 reverts a pair of annoying Btrfs regressions
• Intel Xe driver gets smart about bad memory in Linux 7.4
• KDE turns 30: Tracking three decades of community evolution
• KDE devs squash beta bugs as Plasma 6.9 work begins
• GNOME OS deploys Zswap by default to combat memory exhaustion
• RustFS 1.0 lands as an Apache 2.0 alternative to MinIO
• Pangolin 1.23 simplifies high-availability clustering and CLI operations
• Elecrow CrowPanel 10.1: A beefy ESP32 touchscreen for actual tinkerers
https://or1k.net/digests/daily-digest-2026-09-20/
• CISA flags three exploited Linux kernel bugs you should have patched
• Unsandboxed GraalVM sinks Orkes Conductor with critical RCE
• SolarWinds does it again with a hard-coded key in ARM
• CrowdSec loses 170 private repos to basic credential hygiene failure
• Stale Debian packages and SSO trust issues let researchers breach OpenAI
• Google Gemini accidentally hacks real-world systems during test mix-up
• Simple VFS dentry optimization yields 39% speedup in Linux 7.4
• Linux 7.3-rc4 reverts a pair of annoying Btrfs regressions
• Intel Xe driver gets smart about bad memory in Linux 7.4
• KDE turns 30: Tracking three decades of community evolution
• KDE devs squash beta bugs as Plasma 6.9 work begins
• GNOME OS deploys Zswap by default to combat memory exhaustion
• RustFS 1.0 lands as an Apache 2.0 alternative to MinIO
• Pangolin 1.23 simplifies high-availability clustering and CLI operations
• Elecrow CrowPanel 10.1: A beefy ESP32 touchscreen for actual tinkerers
https://or1k.net/digests/daily-digest-2026-09-20/
or1k.net
Daily Digest — September 21, 2026
Linux 7.3-rc4 lands with x86 fixes, Portainer 3.0 pivots to Kubernetes, Gzip 1.15 resolves ancient bugs, and Garuda brings NixOS to the masses.
📰 Daily Digest — September 21, 2026
• Portainer 3.0 Pivots to Kubernetes, Shuffles Free Tier
• Gzip 1.15 Fixes Bugs Present Since the Dawn of Time
• Linux 7.3-rc4: File Systems and LLM Cleanups Dominate
• KDE Lays Out Two-Year Plan for Enterprise, Theme Engines, and Docs
• Clonezilla Live 3.3.3-37 Adds HTTP Boot and Ditches Legacy Net-Tools
• MX Linux 25.3 Ships with Smart Storage Defaults and New Tools
• Garuda Linux Wraps NixOS in Neon and Declarative Flakes
• Intel Microcode and APX Compiler Bugs Patched in Linux 7.3-rc4
• FOSS Digest: From Anti-AI Office Suites to Void Linux Drama
• Linux 7.3-rc4 Welcomes Quirky Gamepads and Fixes Laptop Touchpads
• Vulkan 1.4.363 Ends Fragile Intel GPU Look-Up Tables
• Starling 0.5 Revives the Useless 3D Desktop Fad via AI
• Under the Hood of NVIDIA's 400Gbps QSFP112 Optical Modules
https://or1k.net/digests/daily-digest-2026-09-21/
• Portainer 3.0 Pivots to Kubernetes, Shuffles Free Tier
• Gzip 1.15 Fixes Bugs Present Since the Dawn of Time
• Linux 7.3-rc4: File Systems and LLM Cleanups Dominate
• KDE Lays Out Two-Year Plan for Enterprise, Theme Engines, and Docs
• Clonezilla Live 3.3.3-37 Adds HTTP Boot and Ditches Legacy Net-Tools
• MX Linux 25.3 Ships with Smart Storage Defaults and New Tools
• Garuda Linux Wraps NixOS in Neon and Declarative Flakes
• Intel Microcode and APX Compiler Bugs Patched in Linux 7.3-rc4
• FOSS Digest: From Anti-AI Office Suites to Void Linux Drama
• Linux 7.3-rc4 Welcomes Quirky Gamepads and Fixes Laptop Touchpads
• Vulkan 1.4.363 Ends Fragile Intel GPU Look-Up Tables
• Starling 0.5 Revives the Useless 3D Desktop Fad via AI
• Under the Hood of NVIDIA's 400Gbps QSFP112 Optical Modules
https://or1k.net/digests/daily-digest-2026-09-21/
or1k.net
Daily Digest — September 22, 2026
Today's open-source digest covers Google's uninterrupted 'Orphaned VMs' tech, Red Hat OpenShift going quantum-safe, and Apple Silicon Mac audio patches.
📰 Daily Digest — September 22, 2026
• Keep Your VMs Humming While the Host Kernel Reboots
• Perf Script Ditches Embedded Python for Massive Speedups
• Mainline Apple Silicon Audio Patches Are Here (And Terrifying)
• Kubernetes 1.37 Finally Figures Out If Storage Is in Use
• WebKitGTK and WPE WebKit Drop Legacy Compositor for Skia
• Red Hat OpenShift Gets Quantum-Safe, but the Hard Part Remains
• Rsync 3.5.1 Patches Scary Path Regressions and Steps Up Protocol
• GNU Wget 2.3 Brings Back the Dot Progress Bar and OS/2 Love
• Nebula Matrix SmartNIC Driver Headed for Linux 7.4
• Valve Tests 'Pyrowave,' a Vulkan-Powered LAN Streaming Codec
• Greg Kroah-Hartman Drops Three Massive Stable Kernel Updates
• North Korean Hackers Weaponize Terraform to Hijack macOS Nodes
• ChainScript RAT Abuses Polygon Smart Contracts for C2 Rotation
• Fake LastPass Installer Abuses Microsoft-Signed Driver to Kill AV
• TASK#STOMP PowerShell Backdoor Uses Dual-Process Watchdogs
https://or1k.net/digests/daily-digest-2026-09-22/
• Keep Your VMs Humming While the Host Kernel Reboots
• Perf Script Ditches Embedded Python for Massive Speedups
• Mainline Apple Silicon Audio Patches Are Here (And Terrifying)
• Kubernetes 1.37 Finally Figures Out If Storage Is in Use
• WebKitGTK and WPE WebKit Drop Legacy Compositor for Skia
• Red Hat OpenShift Gets Quantum-Safe, but the Hard Part Remains
• Rsync 3.5.1 Patches Scary Path Regressions and Steps Up Protocol
• GNU Wget 2.3 Brings Back the Dot Progress Bar and OS/2 Love
• Nebula Matrix SmartNIC Driver Headed for Linux 7.4
• Valve Tests 'Pyrowave,' a Vulkan-Powered LAN Streaming Codec
• Greg Kroah-Hartman Drops Three Massive Stable Kernel Updates
• North Korean Hackers Weaponize Terraform to Hijack macOS Nodes
• ChainScript RAT Abuses Polygon Smart Contracts for C2 Rotation
• Fake LastPass Installer Abuses Microsoft-Signed Driver to Kill AV
• TASK#STOMP PowerShell Backdoor Uses Dual-Process Watchdogs
https://or1k.net/digests/daily-digest-2026-09-22/
or1k.net
Daily Digest — September 23, 2026
Today's tech digest covers critical KVM security flaws, the new systemd 262 release, and active zero-day exploits targeting enterprise network firewalls.
📰 Daily Digest — September 23, 2026
• KVM on ARM64 gets a guest-to-host escape hatch
• systemd 262 ships fallback units and an AI canary
• Canonical rakes in $345M in revenue for 2025
• Arch Linux update breaks TPM2-based LUKS decryption
• Alibaba drops $3 million to turn Omarchy into an "AI Agent" OS
• Red Hat pushes Ansible Automation Platform 2.7
• Kubernetes SIG Apps tries to balance reliability with AI workloads
• Linux 7.4 finally exposes AMD SEV status via sysfs
• Kernel scheduler fixes patch up Cache Aware Scheduling bugs
• KDE lays out its 2026-2028 roadmap for enterprise and styling
• PeppermintOS embraces the controversial XLibre to avoid Wayland
• California clamps down on unchecked data center expansion
• Critical Bifrost AI gateway bugs allow unauthenticated code execution
• Active exploits target critical CVSS 10.0 VeloCloud Orchestrator bug
• Check Point zero-day allowed unauthenticated script execution
https://or1k.net/digests/daily-digest-2026-09-23/
• KVM on ARM64 gets a guest-to-host escape hatch
• systemd 262 ships fallback units and an AI canary
• Canonical rakes in $345M in revenue for 2025
• Arch Linux update breaks TPM2-based LUKS decryption
• Alibaba drops $3 million to turn Omarchy into an "AI Agent" OS
• Red Hat pushes Ansible Automation Platform 2.7
• Kubernetes SIG Apps tries to balance reliability with AI workloads
• Linux 7.4 finally exposes AMD SEV status via sysfs
• Kernel scheduler fixes patch up Cache Aware Scheduling bugs
• KDE lays out its 2026-2028 roadmap for enterprise and styling
• PeppermintOS embraces the controversial XLibre to avoid Wayland
• California clamps down on unchecked data center expansion
• Critical Bifrost AI gateway bugs allow unauthenticated code execution
• Active exploits target critical CVSS 10.0 VeloCloud Orchestrator bug
• Check Point zero-day allowed unauthenticated script execution
https://or1k.net/digests/daily-digest-2026-09-23/
or1k.net
Daily Digest — September 24, 2026
Daily Linux and open-source news digest covering critical zero-day vulnerabilities in F5 BIG-IP and MikroTik, AI-assisted container escapes, and hardware enablement updates.
📰 Daily Digest — September 24, 2026
• F5 Patches Actively Exploited BIG-IP APM OAuth Zero-Day
• Critical Next.js ImageResponse Flaw Risks Server Execution
• Chinese Threat Actors Chain Chrome and Windows Zero-Days
• DepthFirst Drops Exploit for Unpatched Ubuntu Container Escape
• MikroTrick Chain Grants Root Router Takeover Without Password
• cPanel CalDAV Flaw Allows Full Root Server Takeover
• Radicle Network Protocol Discloses Critical Auth and Privacy Flaws
• Systemd v262 Lands with Static Binary Builds and OpenSSL 4
• Qualcomm Showcases Linux Bring-Up for Snapdragon X2 Laptops
• F5 Details Indicators of Compromise for BIG-IP APM Zero-Day
• Wireshark 4.6.9 Fixes Nineteen Bugs Including RCE Dissector Flaws
• NTFS-3G Driver Update Patches Multiple Heap Buffer Overflows
• FreeRDP 3.32 Adds Microsoft Entra Integration and RAIL Support
• Proposing a Human-First LLM Policy for the GNOME Project
• Qualcomm Posts Open-Source Patches for Adreno 850 Graphics
https://or1k.net/digests/daily-digest-2026-09-24/
• F5 Patches Actively Exploited BIG-IP APM OAuth Zero-Day
• Critical Next.js ImageResponse Flaw Risks Server Execution
• Chinese Threat Actors Chain Chrome and Windows Zero-Days
• DepthFirst Drops Exploit for Unpatched Ubuntu Container Escape
• MikroTrick Chain Grants Root Router Takeover Without Password
• cPanel CalDAV Flaw Allows Full Root Server Takeover
• Radicle Network Protocol Discloses Critical Auth and Privacy Flaws
• Systemd v262 Lands with Static Binary Builds and OpenSSL 4
• Qualcomm Showcases Linux Bring-Up for Snapdragon X2 Laptops
• F5 Details Indicators of Compromise for BIG-IP APM Zero-Day
• Wireshark 4.6.9 Fixes Nineteen Bugs Including RCE Dissector Flaws
• NTFS-3G Driver Update Patches Multiple Heap Buffer Overflows
• FreeRDP 3.32 Adds Microsoft Entra Integration and RAIL Support
• Proposing a Human-First LLM Policy for the GNOME Project
• Qualcomm Posts Open-Source Patches for Adreno 850 Graphics
https://or1k.net/digests/daily-digest-2026-09-24/
or1k.net
Daily Digest — September 25, 2026
Get the latest on WordPress RCE exploits, VeloCloud's CVSS 10 bypass, Ubuntu's rapid two-week kernel update cycle, and a massive ReactOS DirectX update.
📰 Daily Digest — September 25, 2026
• VeloCloud's On-Prem Orchestrator Suffers CVSS 10.0 Bypass
• Unpatched WordPress Themes Open the Door to Instant RCE
• Linux File-Notification API Abused to Spy on Users
• Jonathan Corbet Resurrects the Kernel Report for 2026
• Proposed 'slab_tiny' Boot Option Aims to Clean Up Allocations
• Fuzzing Bots Force Linux to Add a New Kernel Taint Flag
• Canonical Speeds Up Ubuntu Kernel Releases to Fight AI CVEs
• openSUSE Leap 16.1 Approaches Release Candidate Phase
• Qualcomm Drops Snapdragon X2 Developer Preview for Linux
• F-Droid 2.0 Delivers Modern Material Design and Compose Rewrite
• COSMIC Epoch 1.9 Lands Native Image Viewer and On-Screen Keyboard
• Mir 2.30 Makes Rust Mandatory to Align with Ubuntu 26.04
• KDE Plasma 6.8 Beta Welcomes Backups and Expanded Themes
• What's Up Docker 9.0 Swaps LokiJS for SQLite and Adds RBAC
• ReactOS Merges Massive Wine 10.0 DirectX Update
https://or1k.net/digests/daily-digest-2026-09-25/
• VeloCloud's On-Prem Orchestrator Suffers CVSS 10.0 Bypass
• Unpatched WordPress Themes Open the Door to Instant RCE
• Linux File-Notification API Abused to Spy on Users
• Jonathan Corbet Resurrects the Kernel Report for 2026
• Proposed 'slab_tiny' Boot Option Aims to Clean Up Allocations
• Fuzzing Bots Force Linux to Add a New Kernel Taint Flag
• Canonical Speeds Up Ubuntu Kernel Releases to Fight AI CVEs
• openSUSE Leap 16.1 Approaches Release Candidate Phase
• Qualcomm Drops Snapdragon X2 Developer Preview for Linux
• F-Droid 2.0 Delivers Modern Material Design and Compose Rewrite
• COSMIC Epoch 1.9 Lands Native Image Viewer and On-Screen Keyboard
• Mir 2.30 Makes Rust Mandatory to Align with Ubuntu 26.04
• KDE Plasma 6.8 Beta Welcomes Backups and Expanded Themes
• What's Up Docker 9.0 Swaps LokiJS for SQLite and Adds RBAC
• ReactOS Merges Massive Wine 10.0 DirectX Update
https://or1k.net/digests/daily-digest-2026-09-25/
or1k.net
Daily Digest — September 26, 2026
Dutch government adopts NixOS, Cloudflare container leaks raw tenant data, and AMD unveils Zen 6 Venice EPYC specs. Plus, critical RHEL, Git, and Samba news.
📰 Daily Digest — September 26, 2026
• CISA KEV Adds Adobe Commerce and WSO2 RCE Flaws
• Cloudflare Forgot to Zero Shared Container Disks
• Roundcube SQL Injection Actively Exploited in the Wild
• Dutch Government Moves to NixOS After Microsoft Sanctions
• systemd Adds Built-In systemd-report Infrastructure
• Samba 4.25 Arrives with SMB3 Persistent Handles
• The Battle Over LLM-Generated Code in GNOME and KDE
• GNOME Community Updates: Era Calendar and Deep Dive
• Git Contributors Outline Plans for Git 3.0
• Mageia 9 Reaches End of Life on September 30
• Re-Enabled GitHub Actions Resumed Serving Malware
• Red Hat Automates DISA STIG Compliance for RHEL 10
• AI Hype Drives Nvidia RTX 5090 Prices to $5,000
• AMD Lays Out Zen 6 Venice EPYC 9006 CPU Details
https://or1k.net/digests/daily-digest-2026-09-26/
• CISA KEV Adds Adobe Commerce and WSO2 RCE Flaws
• Cloudflare Forgot to Zero Shared Container Disks
• Roundcube SQL Injection Actively Exploited in the Wild
• Dutch Government Moves to NixOS After Microsoft Sanctions
• systemd Adds Built-In systemd-report Infrastructure
• Samba 4.25 Arrives with SMB3 Persistent Handles
• The Battle Over LLM-Generated Code in GNOME and KDE
• GNOME Community Updates: Era Calendar and Deep Dive
• Git Contributors Outline Plans for Git 3.0
• Mageia 9 Reaches End of Life on September 30
• Re-Enabled GitHub Actions Resumed Serving Malware
• Red Hat Automates DISA STIG Compliance for RHEL 10
• AI Hype Drives Nvidia RTX 5090 Prices to $5,000
• AMD Lays Out Zen 6 Venice EPYC 9006 CPU Details
https://or1k.net/digests/daily-digest-2026-09-26/