Infostealers are draining Claude subscribers’ paid token allowances
Infostealer malware is being used to steal active Claude login sessions, letting attackers consume subscribers’ paid token allowances without their knowledge. Anthropic says the attacks begin on users’ devices rather than with a breach of Claude’s infrastructure, but the resulting session hijacking can still trigger exhausted quotas, unauthorized charges, and account suspensions.
Source
👉@sysadminoff
https://4sysops.com/archives/infostealers-are-draining-claude-subscribers-paid-token-allowances/
Infostealer malware is being used to steal active Claude login sessions, letting attackers consume subscribers’ paid token allowances without their knowledge. Anthropic says the attacks begin on users’ devices rather than with a breach of Claude’s infrastructure, but the resulting session hijacking can still trigger exhausted quotas, unauthorized charges, and account suspensions.
Source
👉@sysadminoff
https://4sysops.com/archives/infostealers-are-draining-claude-subscribers-paid-token-allowances/
📰 KDE Plasma 6.7.5 Desktop Environment Is Out with Many Improvements and Fixes
KDE Plasma 6.7.5 is now available as the fifth maintenance update to the KDE Plasma 6.7 desktop environment series with more improvements and bug fixes.
🔗 Source: https://9to5linux.com/kde-plasma-6-7-5-desktop-environment-is-out-with-many-improvements-and-fixes
#kde #plasma
👉@sysadminoff
KDE Plasma 6.7.5 is now available as the fifth maintenance update to the KDE Plasma 6.7 desktop environment series with more improvements and bug fixes.
🔗 Source: https://9to5linux.com/kde-plasma-6-7-5-desktop-environment-is-out-with-many-improvements-and-fixes
#kde #plasma
👉@sysadminoff
AxonOS - real-time ОС для нейрокомпьютерных интерфейсов
Представлен открытый проект AxonOS, развивающий программную инфраструктуру для систем с нейрокомпьютерным интерфейсом, предназначенную для построения детерминированного слоя выполнения между нейронным оборудованием и AI. Ядро AxonOS разрабатывается на языке Rust в режиме "no_std" с акцентом на предсказуемое real-time выполнение, формализованный ABI системных вызовов, capability-модель доступа, обходящийся без блокировок IPC и контроль времени выполнения. Исходный код открыт под лицензиями MIT или Apache 2.0.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=66241
Представлен открытый проект AxonOS, развивающий программную инфраструктуру для систем с нейрокомпьютерным интерфейсом, предназначенную для построения детерминированного слоя выполнения между нейронным оборудованием и AI. Ядро AxonOS разрабатывается на языке Rust в режиме "no_std" с акцентом на предсказуемое real-time выполнение, формализованный ABI системных вызовов, capability-модель доступа, обходящийся без блокировок IPC и контроль времени выполнения. Исходный код открыт под лицензиями MIT или Apache 2.0.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=66241
PostGREShell: в PostgreSQL обнаружили существовавшую 12 лет возможность запуска произвольного кода
1 сентября исследователи Cyera Research раскрыли подробности уязвимости PostGREShell — CVE-2026-6471, позволявшей пользователю PostgreSQL с привилегией REPLICATION загружать произвольные нативные библиотеки в процесс СУБД. Ошибка появилась вместе с механизмом логического декодирования ещё в PostgreSQL 9.4 и оставалась незамеченной около 12 лет. Само исправление было выпущено раньше — 13 августа в PostgreSQL 18.6, 17.11, 16.15, 15.19 и 14.24.
PostgreSQL оценил CVE-2026-6471 в 7,2 балла CVSS. Согласно официальному описанию, пользователь, не являющийся суперпользователем, но имеющий атрибут REPLICATION, мог через механизм логического декодирования заставить сервер выполнить dlopen() произвольного файла, доступного системной учётной записи PostgreSQL. В результате код из библиотеки выполнялся уже не с SQL-правами атакующего, а непосредственно внутри процесса сервера БД.
( читать дальше... )
cve, postgresql, replication
👉@sysadminoff
https://www.linux.org.ru/news/security/18377200
1 сентября исследователи Cyera Research раскрыли подробности уязвимости PostGREShell — CVE-2026-6471, позволявшей пользователю PostgreSQL с привилегией REPLICATION загружать произвольные нативные библиотеки в процесс СУБД. Ошибка появилась вместе с механизмом логического декодирования ещё в PostgreSQL 9.4 и оставалась незамеченной около 12 лет. Само исправление было выпущено раньше — 13 августа в PostgreSQL 18.6, 17.11, 16.15, 15.19 и 14.24.
PostgreSQL оценил CVE-2026-6471 в 7,2 балла CVSS. Согласно официальному описанию, пользователь, не являющийся суперпользователем, но имеющий атрибут REPLICATION, мог через механизм логического декодирования заставить сервер выполнить dlopen() произвольного файла, доступного системной учётной записи PostgreSQL. В результате код из библиотеки выполнялся уже не с SQL-правами атакующего, а непосредственно внутри процесса сервера БД.
( читать дальше... )
cve, postgresql, replication
👉@sysadminoff
https://www.linux.org.ru/news/security/18377200
🔥1
📰 New Patches Provide HDMI 1.4 3D Mode Support For AMD Radeon Graphics On Linux
It turns out one of the feature limitations of the AMDGPU Linux graphics driver is HDMI 1.4 3D output support with frame packing, top-and-bottom, and side-by-side options for transmitting simultaneous video streams. I wasn't aware of this limitation for the lack of any 3D displays and many Linux enthusiasts/gamers as well, but if you happen to have a compatible HDMI 1.4 3D display, there are pending patches to finally make this a reality...
🔗 Source: https://www.phoronix.com/news/AMDGPU-HDMI-1.4-3D-Mode
#amd #linux
👉@sysadminoff
https://phoronix.com/news/AMDGPU-HDMI-1.4-3D-Mode
It turns out one of the feature limitations of the AMDGPU Linux graphics driver is HDMI 1.4 3D output support with frame packing, top-and-bottom, and side-by-side options for transmitting simultaneous video streams. I wasn't aware of this limitation for the lack of any 3D displays and many Linux enthusiasts/gamers as well, but if you happen to have a compatible HDMI 1.4 3D display, there are pending patches to finally make this a reality...
🔗 Source: https://www.phoronix.com/news/AMDGPU-HDMI-1.4-3D-Mode
#amd #linux
👉@sysadminoff
https://phoronix.com/news/AMDGPU-HDMI-1.4-3D-Mode
Phoronix
New Patches Provide HDMI 1.4 3D Mode Support For AMD Radeon Graphics On Linux
It turns out one of the feature limitations of the AMDGPU Linux graphics driver is HDMI 1.4 3D output support with frame packing, top-and-bottom, and side-by-side options for transmitting simultaneous video streams
📰 CHUWI UniBook With Intel Wildcat Lake For A $449 Linux-Friendly Laptop
CHUWI recently launched the UniBook laptop powered by the Intel Core 3 304 "Wildcat Lake" SOC and priced at just $449 USD. Especially with today's high component pricing, a brand new sub-$500 laptop is extremely rare. Rather than using some dated SoC, it uses Wildcat Lake as Intel's new value option alternative to the Core 3 Series Ultra "Panther Lake" SoCs.
🔗 Source: https://www.phoronix.com/review/chuwi-unibook-wildcat-lake
#intel #linux
👉@sysadminoff
https://phoronix.com/review/chuwi-unibook-wildcat-lake
CHUWI recently launched the UniBook laptop powered by the Intel Core 3 304 "Wildcat Lake" SOC and priced at just $449 USD. Especially with today's high component pricing, a brand new sub-$500 laptop is extremely rare. Rather than using some dated SoC, it uses Wildcat Lake as Intel's new value option alternative to the Core 3 Series Ultra "Panther Lake" SoCs.
🔗 Source: https://www.phoronix.com/review/chuwi-unibook-wildcat-lake
#intel #linux
👉@sysadminoff
https://phoronix.com/review/chuwi-unibook-wildcat-lake
Phoronix
CHUWI UniBook With Intel Wildcat Lake For A $449 Linux-Friendly Laptop
CHUWI recently launched the UniBook laptop powered by the Intel Core 3 304 'Wildcat Lake' SOC and priced at just $449 USD.
Выпуск альтернативного X-сервера yserver 1.5
Состоялся выпуск X11-сервера yserver 1.5.0, написанного с нуля на языке Rust и поддерживающего актуальные расширения протокола X11. Проект не ставит перед собой цель повторить все возможности Xorg Server и ограничивается только функциональностью, необходимой для запуска современных сред рабочего стола, оконных менеджеров, приложений и графических библиотек (GTK, Qt, SDL, GLFW). Из протестированных окружений отмечены MATE, Xfce, Cinnamon, Sonic и Enlightenment, а также оконные менеджеры, такие как icewm, FVWM3, openbox, i3 и wmaker. Код проекта распространяется под лицензией MIT.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=66242
Состоялся выпуск X11-сервера yserver 1.5.0, написанного с нуля на языке Rust и поддерживающего актуальные расширения протокола X11. Проект не ставит перед собой цель повторить все возможности Xorg Server и ограничивается только функциональностью, необходимой для запуска современных сред рабочего стола, оконных менеджеров, приложений и графических библиотек (GTK, Qt, SDL, GLFW). Из протестированных окружений отмечены MATE, Xfce, Cinnamon, Sonic и Enlightenment, а также оконные менеджеры, такие как icewm, FVWM3, openbox, i3 и wmaker. Код проекта распространяется под лицензией MIT.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=66242
📰 Open CAD Studio Is a New Rust-Based Open-Source CAD App for Linux
Open CAD Studio is a new GPL-licensed CAD app for Linux with native DWG/DXF editing, 2D drafting, 3D modeling, and a browser-based version.
🔗 Source: /
#linux #opensource #rust
👉@sysadminoff
https://linuxiac.com/open-cad-studio-is-a-new-rust-based-open-source-cad-app-for-linux
Open CAD Studio is a new GPL-licensed CAD app for Linux with native DWG/DXF editing, 2D drafting, 3D modeling, and a browser-based version.
🔗 Source: /
#linux #opensource #rust
👉@sysadminoff
https://linuxiac.com/open-cad-studio-is-a-new-rust-based-open-source-cad-app-for-linux
Linuxiac
Open CAD Studio Is a New Rust-Based Open-Source CAD App for Linux
Open CAD Studio is a new GPL-licensed CAD app for Linux with native DWG/DXF editing, 2D drafting, 3D modeling, and a browser-based version.
📰 DaVinci Resolve 21.1 Released - Now With AI Assistant Integration
For those using the Linux-friendly DaVinci Resolve video editing and color correction/grading and visual effects software, DaVinci Resolve 21.1 is out today as a major update to this cross-platform solution...
🔗 Source: https://www.phoronix.com/news/DaVinci-Resolve-21.1
#linux
👉@sysadminoff
https://phoronix.com/news/DaVinci-Resolve-21.1
For those using the Linux-friendly DaVinci Resolve video editing and color correction/grading and visual effects software, DaVinci Resolve 21.1 is out today as a major update to this cross-platform solution...
🔗 Source: https://www.phoronix.com/news/DaVinci-Resolve-21.1
#linux
👉@sysadminoff
https://phoronix.com/news/DaVinci-Resolve-21.1
Phoronix
DaVinci Resolve 21.1 Released - Now With AI Assistant Integration
For those using the Linux-friendly DaVinci Resolve video editing and color correction/grading and visual effects software, DaVinci Resolve 21.1 is out today as a major update to this cross-platform solution.
В ядре Linux 7.4 намечена значительная чистка устаревших ARM-систем
Арнд Бергман (Arnd Bergmann), отвечающий за пакеты с ядром в SUSE, подготовил патчи, удаляющие из ядра около 55 тысяч строк кода, связанного с поддержкой устаревших платформ ARM, которые почти не используются и мешают сопровождению актуальных подсистем. К удалению намечены платформы sa1100, omap24xx, i.MX31, samv7, lpc18xx, riscpc, axxia, footbridge, старые платы pxa, orion, dove и mv78xx0, чипы без блока управления памятью (MMU) и микроконтроллеры stm32f4/f7/h7. Указанные платформы намечены для удаления в ядре 7.5, ожидаемом в первом квартале 2027 года, чтобы не проводить удаление в LTS-ядре и дать время пользователям заявить о продолжении использования каких-то систем для предотвращения их удаления.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=66243
Арнд Бергман (Arnd Bergmann), отвечающий за пакеты с ядром в SUSE, подготовил патчи, удаляющие из ядра около 55 тысяч строк кода, связанного с поддержкой устаревших платформ ARM, которые почти не используются и мешают сопровождению актуальных подсистем. К удалению намечены платформы sa1100, omap24xx, i.MX31, samv7, lpc18xx, riscpc, axxia, footbridge, старые платы pxa, orion, dove и mv78xx0, чипы без блока управления памятью (MMU) и микроконтроллеры stm32f4/f7/h7. Указанные платформы намечены для удаления в ядре 7.5, ожидаемом в первом квартале 2027 года, чтобы не проводить удаление в LTS-ядре и дать время пользователям заявить о продолжении использования каких-то систем для предотвращения их удаления.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=66243
🔥1
Zuckerberg pitches Muse as a privacy-first AI agent
Mark Zuckerberg says Meta’s Muse is designed to move beyond chatbots by giving each user a persistent AI agent that can operate a virtual machine, pursue long-running goals, and interact with services on the user’s behalf. Its proposed security model includes confidential computing, least-privilege access, approval gates, and monitoring agents intended to detect prompt injection and unsafe data movement.
Source
👉@sysadminoff
https://4sysops.com/archives/zuckerberg-pitches-muse-as-a-privacy-first-ai-agent/
Mark Zuckerberg says Meta’s Muse is designed to move beyond chatbots by giving each user a persistent AI agent that can operate a virtual machine, pursue long-running goals, and interact with services on the user’s behalf. Its proposed security model includes confidential computing, least-privilege access, approval gates, and monitoring agents intended to detect prompt injection and unsafe data movement.
Source
👉@sysadminoff
https://4sysops.com/archives/zuckerberg-pitches-muse-as-a-privacy-first-ai-agent/
👎1
Microsoft Viva Glint export APIs for survey data integration
Microsoft has announced Viva Glint export APIs that let you pull employee survey response data out of Viva Glint through Microsoft Graph instead of downloading reports manually. Viva Glint is Microsoft's employee listening platform where organizations run engagement surveys and collect feedback. The APIs use OAuth 2.0 application permissions and require both Microsoft Entra app registration and configuration inside Glint. They are available only in a limited private preview as of September 2026. This article covers what the APIs do, what you need to set them up, and what limitations apply.
Source
👉@sysadminoff
https://4sysops.com/archives/microsoft-viva-glint-export-apis-for-survey-data-integration/
Microsoft has announced Viva Glint export APIs that let you pull employee survey response data out of Viva Glint through Microsoft Graph instead of downloading reports manually. Viva Glint is Microsoft's employee listening platform where organizations run engagement surveys and collect feedback. The APIs use OAuth 2.0 application permissions and require both Microsoft Entra app registration and configuration inside Glint. They are available only in a limited private preview as of September 2026. This article covers what the APIs do, what you need to set them up, and what limitations apply.
Source
👉@sysadminoff
https://4sysops.com/archives/microsoft-viva-glint-export-apis-for-survey-data-integration/
📰 BleachBit 6.0.4 Cleaner and Privacy Tool Released with Faster Scanning
BleachBit 6.0.4 is out with faster startup and scanning, new cleaners for fish, Zsh, Android Studio, Gradle, and Python, plus major security fixes.
🔗 Source: /
#android #python
👉@sysadminoff
https://linuxiac.com/bleachbit-6-0-4-cleaner-and-privacy-tool-released-with-faster-scanning
BleachBit 6.0.4 is out with faster startup and scanning, new cleaners for fish, Zsh, Android Studio, Gradle, and Python, plus major security fixes.
🔗 Source: /
#android #python
👉@sysadminoff
https://linuxiac.com/bleachbit-6-0-4-cleaner-and-privacy-tool-released-with-faster-scanning
Linuxiac
BleachBit 6.0.4 Cleaner and Privacy Tool Released with Faster Scanning
BleachBit 6.0.4 is out with faster startup and scanning, new cleaners for fish, Zsh, Android Studio, Gradle, and Python, plus major security fixes.
📰 The Linux Kernel Planning To Remove Around ~55k Lines Of Old ARM Platform Code
For the current Linux 7.3 kernel many older 32-bit ARM platforms are deprecated and in turn orphaning hundreds of drivers only relevant to those out-of-date ARM platforms. The removal of that now deprecated code is planned for the next kernel cycle or two...
🔗 Source: https://www.phoronix.com/news/Linux-Dropping-Old-ARM-Ahead
#arm #kernel #linux
👉@sysadminoff
https://phoronix.com/news/Linux-Dropping-Old-ARM-Ahead
For the current Linux 7.3 kernel many older 32-bit ARM platforms are deprecated and in turn orphaning hundreds of drivers only relevant to those out-of-date ARM platforms. The removal of that now deprecated code is planned for the next kernel cycle or two...
🔗 Source: https://www.phoronix.com/news/Linux-Dropping-Old-ARM-Ahead
#arm #kernel #linux
👉@sysadminoff
https://phoronix.com/news/Linux-Dropping-Old-ARM-Ahead
Phoronix
The Linux Kernel Planning To Remove Around ~55k Lines Of Old ARM Platform Code
For the current Linux 7.3 kernel many older 32-bit ARM platforms are deprecated and in turn orphaning hundreds of drivers only relevant to those out-of-date ARM platforms
📰 KDE's KWin Merges Wayland Commit-Timing Protocol Support
Merged today to the latest KDE KWin compositor development code is support for Wayland's important commit-timing protocol that is useful for video playback as well as for gamers relying on Adaptive-Sync/FreeSync support...
🔗 Source: https://www.phoronix.com/news/KDE-KWin-Wayland-Commit-Timing
#kde #wayland
👉@sysadminoff
https://phoronix.com/news/KDE-KWin-Wayland-Commit-Timing
Merged today to the latest KDE KWin compositor development code is support for Wayland's important commit-timing protocol that is useful for video playback as well as for gamers relying on Adaptive-Sync/FreeSync support...
🔗 Source: https://www.phoronix.com/news/KDE-KWin-Wayland-Commit-Timing
#kde #wayland
👉@sysadminoff
https://phoronix.com/news/KDE-KWin-Wayland-Commit-Timing
Phoronix
KDE's KWin Merges Wayland Commit-Timing Protocol Support
Merged today to the latest KDE KWin compositor development code is support for Wayland's important commit-timing protocol that is useful for video playback as well as for gamers relying on Adaptive-Sync/FreeSync support.
Выпуск драйвера NVIDIA 615. В драйвере Nouveau реализована поддержка NVIDIA DGX Spark
Компания NVIDIA опубликовала выпуск проприетарного драйвера NVIDIA 615.71.09 (первый стабильный выпуск новой ветки 615). Драйвер доступен для Linux (ARM64, x86_64), FreeBSD (x86_64) и Solaris (x86_64). NVIDIA 615.x стала четырнадцатой стабильной веткой после открытия компанией NVIDIA компонентов, работающих на уровне ядра. Исходные тексты модулей ядра nvidia.ko, nvidia-drm.ko (Direct Rendering Manager), nvidia-modeset.ko и nvidia-uvm.ko (Unified Video Memory) из новой ветки NVIDIA, а также используемые в них общие компоненты, не привязанные к операционной системе, размещены на GitHub. Прошивки и используемые в пространстве пользователя библиотеки, такие как стеки CUDA, OpenGL и Vulkan, остаются проприетарными.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=66244
Компания NVIDIA опубликовала выпуск проприетарного драйвера NVIDIA 615.71.09 (первый стабильный выпуск новой ветки 615). Драйвер доступен для Linux (ARM64, x86_64), FreeBSD (x86_64) и Solaris (x86_64). NVIDIA 615.x стала четырнадцатой стабильной веткой после открытия компанией NVIDIA компонентов, работающих на уровне ядра. Исходные тексты модулей ядра nvidia.ko, nvidia-drm.ko (Direct Rendering Manager), nvidia-modeset.ko и nvidia-uvm.ko (Unified Video Memory) из новой ветки NVIDIA, а также используемые в них общие компоненты, не привязанные к операционной системе, размещены на GitHub. Прошивки и используемые в пространстве пользователя библиотеки, такие как стеки CUDA, OpenGL и Vulkan, остаются проприетарными.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=66244
Для FreeBSD развивают новый системный менеджер rcd
Батист Даруссен (Baptiste Daroussin), член FreeBSD Core Team и автор пакетного менеджера pkg, развивает новый системный менеджер для FreeBSD - rcd. Системный менеджер rcd вызывается init-процессом вместо /etc/rc, читает файлы конфигурации сервисов (/etc/rcd.d/*.ucl), строит дерево зависимостей и запускает сервисы по возможности параллельно друг с другом, после чего отслеживает работу сервисов и при необходимости их перезапускает.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=66245
Батист Даруссен (Baptiste Daroussin), член FreeBSD Core Team и автор пакетного менеджера pkg, развивает новый системный менеджер для FreeBSD - rcd. Системный менеджер rcd вызывается init-процессом вместо /etc/rc, читает файлы конфигурации сервисов (/etc/rcd.d/*.ucl), строит дерево зависимостей и запускает сервисы по возможности параллельно друг с другом, после чего отслеживает работу сервисов и при необходимости их перезапускает.
👉@sysadminoff
https://www.opennet.ru/opennews/art.shtml?num=66245
OpenSSL 4.1.0 alpha brings DTLS 1.3 and faster post-quantum crypto
OpenSSL 4.1.0 alpha 1 gives security teams an early test build with DTLS 1.3 and hardware-accelerated post-quantum cryptography. The release improves performance on several server architectures, but it also removes legacy platform and configuration options that may affect existing build pipelines.
Source
👉@sysadminoff
https://4sysops.com/archives/openssl-4-1-0-alpha-brings-dtls-1-3-and-faster-post-quantum-crypto/
OpenSSL 4.1.0 alpha 1 gives security teams an early test build with DTLS 1.3 and hardware-accelerated post-quantum cryptography. The release improves performance on several server architectures, but it also removes legacy platform and configuration options that may affect existing build pipelines.
Source
👉@sysadminoff
https://4sysops.com/archives/openssl-4-1-0-alpha-brings-dtls-1-3-and-faster-post-quantum-crypto/
Ex-Anthropic insider warns AI could kill humans by 2030
CNN host Boris and former Anthropic and OpenAI researcher Jacob Coxon discuss why AI researchers privately fear that rapidly advancing systems could cause catastrophic harm by the end of the decade. Coxon says current models are not yet capable of extinction-level actions, but recursive self-improvement could soon allow AI to outpace human oversight.
Source
👉@sysadminoff
https://4sysops.com/archives/ex-anthropic-insider-warns-ai-could-kill-humans-by-2030/
CNN host Boris and former Anthropic and OpenAI researcher Jacob Coxon discuss why AI researchers privately fear that rapidly advancing systems could cause catastrophic harm by the end of the decade. Coxon says current models are not yet capable of extinction-level actions, but recursive self-improvement could soon allow AI to outpace human oversight.
Source
👉@sysadminoff
https://4sysops.com/archives/ex-anthropic-insider-warns-ai-could-kill-humans-by-2030/