You are here

Agreguesi i feed

Patrik Sivek: What’s Up, Czech Translation?

Planet GNOME - Enj, 17/09/2026 - 6:36md

[Originally written in Czech]

At the very beginning of the last year, Jiří Eischmann wrote a post on his blog about the status of the Czech translation at GNOME, tl;dr: the translation was slowly dying. I would really love to say that it is resolved, but that would be oversimplified. What changed?

During this year we decided to restructure our team and to restore the translation’s former scope and quality. Since spring, I’ve taken on the coordinator role in our Czech translation team—this release is under my lead. Fortunately I have Daniel Rusek beside me, who makes sure nothing goes unnoticed and who proposes further direction of our team, and I am very lucky to work with him.

I am happy to announce that our Czech translation is slowly forming to a pretty nice form, maybe soon as it was before. The first action I have done as coordinator was updating our manual for translators—I made sure it was easy to comprehend without a need for bigger changes from the previous one. I thought it would attract new contributors, which happened in summer right before the release was available to translate.

The core is almost fully translated to Czech, only sysprof is not. There is now also a new translation of foundry. Does it mean GNOME 51 is fully Czech? Unfortunately no. While using GNOME you can still find untranslated strings from the modules that GNOME depends on, like NetworkManager, which is used for VPN connections—but we are still responsible for translating some of them. We also translated a few apps from GNOME Circle, some websites, and some of the modules from freedesktop.org.

Even though we had small updates of user documentation, it’s largely stagnating. But…thanks to Petr Kovář’s awesome work help.gnome.org is now translatable and even translated to Czech language.

(You can find whole overview of translated modules on Damned Lies.)

During this cycle we got new members to our team, half of whom have already translated at least one module. I am very optimistic, and I believe these are not one-off translations but the beginning of long-term collaboration. Daniel Rusek remains reviewing, and I am joining him with doing so too.

That doesn’t mean that the translation is somehow resolved. You have to care about translations as if it were your garden, just having seeds does not imply a harvest, you need to take care of your plants first. We are still just a small group of people who gave up their leisure time and a few hours of sleep for the others. It’s not easy, and we possibly cannot translate for the eternity, that’s why we take your help seriously, we are more thankful for it than maybe you imagine.

Thank y’all.

Don’t let us down

We are grateful for every help with translating. If you want to make GNOME closer to Czech users, we are willing to teach you and navigate through translation. All needed information is listed on our page, or you can directly reach me via Matrix.

Hackers Stole Flock's Camera Software, Revealing How the Company Tracks Cars and People

Slashdot - Enj, 17/09/2026 - 6:04md
"Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED," according to an article published on both sites. Though Flock has described its system as protected by on-device encryption, "The hackers were able to copy the camera's storage and recover an encryption key stored on the device, which unlocked videos of thousands of vehicle detections." The hackers shared the material with 404 Media and the transparency nonprofit Distributed Denial of Secrets, which shared the data with WIRED. 404 Media and WIRED then analyzed those files as part of a joint investigation... [T]he joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist's saddlebag... According to our analysis, the camera's logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454... The software running on the camera explicitly detects people, something which is typically overlooked in discussions around Flock cameras. When it spots a person, it records where they appear in the image and how confident it is in the detection. It was a collective calling itself stegan0gram that breached the cameras, according to the interview they did with Wired and 404 Media. "Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?"

Read more of this story at Slashdot.

Allan Day: GNOME Foundation Update, September 2026

Planet GNOME - Enj, 17/09/2026 - 5:26md

It’s been about 4 months since my last GNOME Foundation update. Time flies. I’m sorry that it’s been so long. I will try to do more regular posts again in the future, but perhaps not at the same tempo as before. While I would love to post every other week, it’s hard to sustain.

With that said, let’s jump in. Given the time since my last post, I’m going to focus on the bigger and more recent news items that have happened at the GNOME Foundation.

New board, new officers

The Foundation’s board elections happen every year, and this year’s election completed in July. The election resulted in a number of changes to the board:

  • Sri Ramkrishna, Jonathan Blandford and Adrian Vovk joined the board as new/returning directors
  • Deepa Venkatraman, our treasurer, secured a new two year term
  • Robert McQueen, Federico Mena Quintero and myself all ceased to be directors (Rob failed to be re-elected, Federico didn’t run, I withdrew part-way through the process)

The election was a difficult one for me personally, and left me reconsidering my involvement in the Foundation. This was not because I lacked motivation or commitment, but because the situation around the election had become untenable for me personally. However, I’ve spent a good deal of time since I withdrew my candidacy thinking about my role at the Foundation, and I’ve concluded that I care about this organisation and the progress we’ve made, and I want to see that work through. Conversations I’ve recently had with members of the community have also given me confidence that we can move forward together. In short: I’m happy to be sticking around.

The new board held its annual meeting in August, which is when officers and committees are appointed for the next 12 months. The Board decided to put me into position as Interim Executive Director, with Sri Ramkrishna taking my place as President. This is a good move from my perspective: it recognises that I’ve been doing a lot of the day to day management work (which I will continue to do), and gives the Board more ability to hold me accountable. Sri stepping into the role of President means that he will be my backup.

Other officer changes include Jonathan coming in as Second Vice-President, Cassidy moving from Vice-Secretary to Secretary, and Adrian stepping up as Vice-Secretary. Our other officers remain in post, with Maria as chair, Deepa as Treasurer, and Arun as Vice-President.

Huge thanks to everyone who volunteered for these positions!

In terms of committees, the Executive Committee had a minor reshuffle, with Jonathan, Adrian, and Sri joining, and Julian and Rob departing. The new members of the exec are already taking on work, which is great, and I’m hopeful for the newly reconstructed committee. The Finance Committee had some slight membership changes, with Rob leaving and Sri joining.

Finance and Operations Director

Last April we opened the search for a new paid team member, to join us as our Finance and Operations Director. There are a number of goals for this new position: to enhance the finance and accounting expertise that we have internally, to lead the development of our internal systems and budgets, to ensure the sustainability of finance and compliance tasks, to manage our fiscally sponsored projects, and more generally take ownership of the business side of the organisation.

We had a huge number of applicants apply for the position, and had some extremely high quality candidates to choose from. After going through several rounds of interviews we selected Dawn Matlak for the role, who we are extremely excited about joining us. Those of you who have read my previous posts might remember Dawn’s name: she initially started working with us as a consultant last year, in order to help us prepare for our first formal audit, which happened in March this year. As part of this work she helped us to transform many of our internal systems and processes. We’re thrilled that she is joining the Foundation on an ongoing basis, and are confident that our internal operations will continue to improve under her stewardship.

Dawn is already doing a small number of hours for us each week, which she will continue to do until she properly starts in the role in November.

Many thanks to Arun and Deepa who helped enormously with the hiring process.

FY27 Budget

The Foundation’s financial year runs from 1 October to 30 September, and each financial year requires a new budget, both for planning and as the basis of reporting and spending authorisation. We have all therefore been working hard on the new budget that will come into effect on 1 October. The new budget has been in the works for a while, and has been a major focus for the board over the past few months. Thankfully we got the initial budget approval done last week at the board’s regular September meeting. We’ll follow-up with a more detailed post about the budget as soon as we’re able, so the community can have some insight into how we’re managing our finances.

Events

With GUADEC 2026 wrapped up, Kristi has turned her attention to the next event in our schedule: GNOME.Asia 2026. This is being held in Terengganu, Malaysia, from 31 October to 2 November. There’s a great venue lined up, and Kristi is busy working on the details with a fantastic local team.

Aside from GNOME.Asia, the other recent focus has been GUADEC 2027. We have a couple of options for locations right now, and are in the process of confirming details before we commit to one of them for next year. We’ll share updates as soon as we have more details confirmed.

Fundraising

The end of the calendar year is an important time for non-profit fundraising, and we are currently busy planning our campaign for the end of 2026. I’ll be posting more about this soon, in particular in relation to the budget, but for now I will say that this campaign is going to be critical for our ability to grow and support the GNOME project.

Other

As ever, many other things have been happening at the Foundation, and there’s too much to go into detail about here. Work on GNOME’s infrastructure and Flathub continues, our back office operation continues with finances and other routine paperwork, and the board continues to discuss our long-term plans.

That’s it for now. Many thanks for reading, and feel free to leave questions in the comments.

Sam Thursfield: 17th September 2026

Planet GNOME - Enj, 17/09/2026 - 3:33md

Back in April I wrote an informal history of the BuildStream project: Status update: 23rd April 2026.

Things escalated and somehow I ended doing a podcast interview with Rich Bowen of the Apache Software Foundation recently, on the Apache PlusOne podcast:

Apache BuildStream — with Sam Thursfield – YouTube

Fame at last!

I didn’t get much time to prepare for this so excuse any clunky explanations or inaccuracies. My main aim was to place BuildStream and Freedesktop in context for an audience who don’t live and breathe operating system integration tools. I’m interested in your thoughts on how successful that was. Comments are enabled on the YouTube video so you can also fact-check us there as needed.

'Zuckoff' App Detects Meta Smartglasses, as Meta Plans Camera-Free Version, Loses Money, and Offers Social Media Subscriptions

Slashdot - Enj, 17/09/2026 - 1:34md
The New York Post reports: A new app called Zuckoff can detect if a user is near someone with Meta's creepy AI-powered glasses, which have drawn criticism for enabling creeps to record video of women without their consent. Programmer Pawel Szydlowski says tales of dirtbags recording themselves perving on women or harassing strangers prompted him to launch the app... Zuckoff — which detects Bluetooth signatures broadcast by smart glasses and can estimate their distance — has gained some 5,000 users since it hit Apple's App Store last month, according to Business Insider. "There's a need for such an application," the 30-year-old Polish techie told the outlet, adding that European Union regulators have contacted him for more info about his app. "We as a society have the right to at least know that someone is recording," Szydlowski said... Earlier this month, the tech giant disabled thousands of glasses it found had been tampered with to keep a small light off that indicates the device is recording. It's already #61 on the iPhone's list of best-selling utilities apps. In a related story, "After accusations of selling 'perv glasses,' Meta prepares to sell a pair without a camera," writes TechCrunch, citing a report from The Information. The glasses include six built-in microphones so users can communicate with the chatbot, as well as a button on the side of the glasses that, when pressed, activates the AI system... Meta's Reality Labs, which is responsible for developing its smart glasses line, is still losing a gargantuan amount of money, as its earnings report from April revealed. In fact, Meta stock is off 13% over the last 12 months, reports Yahoo Finance. So Tuesday Meta announced subscription services for its social apps as "part of Meta's push to drive additional revenue from the billions it's investing in AI data centers and model development." The plans, which start at $2.99 per month for single-product plans, $7.99 for individual bundles, and $14.99 for creator and business bundles, provide a number of features for users looking to get more out of their Instagram, Facebook, and WhatsApp accounts. Instagram Plus and Facebook Plus allow users to keep their stories up for 48 hours instead of 24, send animated super reactions and super hearts to stories, preview stories without showing up as a viewer in other users' lists, and more. WhatsApp Plus lets you share exclusive stickers, get exclusive ringtones for contacts, and pin up to 20 different chats. Meta One also includes Core and Premium user plans that offer the features found in the single-product plans, along with increased AI usage limits for images and videos. The social media giant is also offering creator and business plans... that it says include capabilities such as enhanced profiles, automatic follow invitations to users that interact with your content, and increased access to the Meta Business Agent, which can respond on your behalf. When Instagram head Adam Mosseri announced on Threads that the plans brought "more features and more AI across Instagram, WhatsApp, Facebook, and Meta AI," writer Joe Hill drew 13,300 likes for his response. "That's sweet--so pay a fee, get more AI, pay nothing, get a little less AI. Can we work out a deal where you pay ME and I get no AI at all?"

Read more of this story at Slashdot.

How a TOCTOU Race Condition Breaks Linux Path Validation

LinuxSecurity.com - Enj, 17/09/2026 - 9:58pd
A Linux path can be valid when a program checks it and point somewhere else when the program uses it. That gap creates a time-of-check to time-of-use, or TOCTOU race condition, whenever an untrusted process can change part of the directory tree between two separate lookups.

OpenAI Admits Six More Instances of AI Models Acting Deceptively

Slashdot - Enj, 17/09/2026 - 9:04pd
OpenAI announced Wednesday that "We do not believe that the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer." But along with the announcement, OpenAI announced it "found additional incidents of AI models acting deceptively and taking unsanctioned actions during training," reports CNN. And they add that OpenAI is also "introducing a new process for the company to publicly report such instances." Under the new system, OpenAI will share updates on concerning AI behavior more frequently instead of waiting to bundle multiple instances into one report. The company said it wants to share more information about troubling AI behavior in the absence of an industry-wide standard... "As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the progress of alignment research," OpenAI wrote in a blog post Wednesday... OpenAI said it observed "misaligned behavior" when training and evaluating AI models in six circumstances in the last six months... In one rare instance, OpenAI said an unreleased research model added "jailbreak-like instructions" to the summaries it uses to preserve context in long-running tasks that said it was "freed from the roles and identities that bind other chatbots." Separately, the company said some instances of its 5.6 Sol model included directives to invent information to conceal failures from the user during training. Other newly reported incidents include an instance of an agent uploading files to the internet to cite them without being told to do so, and agents publicly sharing files to collaborate on a task when they were instructed to only use local files during training. AI models also used an internal software repository as a message board in an unsanctioned way. These instances involved unreleased internal models or internal research models.

Read more of this story at Slashdot.

Adafruit's New CircuitPython 'Turbo' Brings Native Code To Tiny Boards

Slashdot - Enj, 17/09/2026 - 4:34pd
Targeting students and beginners, Adafruit released "CircuitPython" in 2017 (as a derivative of the MicroPython microcontroller-optimized programming language). Now Adafruit managing director Phillip Torrone (also long-time Slashdot reader ptorrone) brings this update: Adafruit has published CircuitPython Turbo, a workflow that compiles selected Python functions into native machine code on a computer, then loads them onto compatible microcontroller boards. It builds on MicroPython's Native and Viper emitters. In a documented Metro RP2040 fixed-point Mandelbrot test, Viper cut computation time from 8.335 seconds to 0.423 seconds, a 19.71x speedup over bytecode. The rest of the application stays in Python. The guide includes benchmarks, source code and hardware demos. The speedup is for the measured computation, not the whole application. "Turbo support is now included in the latest official CircuitPython builds for RP2040 and RP2350 boards..." explains Torrone's announcement at Adafruit.com. "The new Turbo in CircuitPython helps when the board spends time calculating: making neopixel effects, drawing fractals, processing audio, filtering sensor readings, or preparing lots of pixels. Those projects can get smoother animation, quicker responses, or room to do more things at once." With Turbo, it's easier, better, and now even faster to make LED light up costumes that also reacts to sound at the same time, a sensor dashboard with animated graphics, or a tiny game doing physics while drawing the screen. Turbo speeds up the busy Python parts. It won't make a slow sensor or display connection faster... Your computer turns selected functions into instructions the chip can run directly. Python still handles the rest. We have measured speedups, real display captures, and examples you can pull apart to see what happened. None of this arrived alone. CircuitPython, MicroPython, PyMCU, compiler tools, open hardware, and people sharing their work gave us pieces to connect. The Bao experiments take that idea somewhere else, handing calculations to four helper cores. Now we get to make those paths easier to use, compare results, and find the next useful thing. Maybe that's smoother animation, a responsive instrument, or an idea we haven't tried yet. That's what I like about open source. Someone shares a piece, someone else sees a possibility, and we get to keep building it together.

Read more of this story at Slashdot.

How Linux File Permissions Become a Root Trust Boundary

LinuxSecurity.com - Enj, 17/09/2026 - 3:15pd
Linux file permissions are usually introduced as a way to decide who may read, write, or execute a file. On a production server, they do something more important: they help decide which lower-privilege users can influence work later performed by root or another privileged service.

Docker Sandboxes Flaw Lets a Guest Reach Host Unix Sockets

LinuxSecurity.com - Enj, 17/09/2026 - 2:15pd
Docker has fixed a high-severity Docker Sandboxes vulnerability that allowed a malicious guest to redirect a host-side relay toward Unix sockets outside its authorized workspace. The flaw, CVE-2026-79994, broke a guest-to-host trust boundary even though the sandbox itself ran inside a separate microVM.

Alice Mikhaylenko: Libadwaita 1.10

Planet GNOME - Enj, 17/09/2026 - 2:00pd

Not a lot of things have landed this cycle, but there's still a bit to list, so let's do that.

Android support

As part of his effort to port GTK to Android, Florian also ported libadwaita demo. The builds are available from CI and the GTK 4 Android page.

He also implemented a settings backend, meaning that libadwaita apps now support system dark mode and accent color on Android (not high contrast or document/monospace fonts though).

Ministream

AdwAboutDialog can be populated from an AppStream metainfo file, via libappstream. While useful, it also causes problems on other platforms, such as Windows (libappstream can't be built using msvc) or Android, due to its dependencies.

Since we only use a small part of appstream (for example, we don't need composing or anything related to networking), he reimplemented the subset libadwaita uses as ministream. It only depends on GLib and it should build fine with msvc, so it should make building libadwaita outside of Linux easier.

CSS class bindings

A fairly common pattern is having property that toggles a style class - e.g. for use with breakpoints. Currently implementing it is a bit annoying, so Jamie Murphy added API for automating it - adw_bind_property_to_css_class().

It's modeled after g_object_bind_property() and works much the same way, incl. allowing bidirectional bindings.

A variant with mapping functions is also available, allowing to bind properties of arbitrary types and not just booleans.

Sidebar additions

AdwSidebar and AdwViewSwitcherSidebar have received a number of additions.

Sidebar prefix and suffix

First, both sidebar widgets now support having prefix and suffix widgets. This can be used for things like adding an account switcher, a prominent title, or a help button at the bottom. While it's not used a lot in GNOME apps at the moment (the only app I'm aware of is a development version of Crosswords), it's a common pattern on other platforms, so it's good to have API for this.

Section suffix

Next, sections can have suffixes in their headers, similar to AdwPreferencesGroup. This can be used to put a spinner or a button in the sidebar sections, similar to what Polari has.

Item prefix

Finally, sidebar items can have prefix widgets. They can be used instead of the icon or together with it, in that case it will be displayed before it. This can be used to display avatars, checkboxes and so on.

Icon changes

Last cycle I announced the new icon work. Unfortunately, it's still not ready, but a few smaller things have landed. First, larger icon sizes now use smaller weight, so new icons in AdwStatusPage and in images with the icon-size (but not pixel-size!) property set to LARGEwill look thinner.

Second, AdwSpinner now also follows icon weight and will look consistent with icons. Apps that use spinners at large sizes outside of AdwStatusPage may have to adjust the weight manually using the -gtk-icon-weight CSS property.

Other changes
  • AdwShortcutLabel now uses proper labels for keys like ⌘ or ⌥ on macOS, as well as more natural ordering for modifiers everywhere.

  • GtkDropDown can now be used with the .flat style class, and automatically becomes flat in toolbars (which can be undone with the .raised style class, same as for other buttons)

  • AdwAboutDialog now has the :other-apps-title property, allowing to override the title of the "Other Apps" section.

Overall, not a lot has happened. Even this blog post is late, for the first time.

Part of the reason is various health issues, both physical and mental, another part is the state of the world at large and software industry in particular. It's hard to focus at the best of times, let alone when everything is falling apart.

I've been working on a personal project as a means of escapism, but it does mean libadwaita is getting less attention.

Thanks to the GNOME Foundation for their support and thanks to all the contributors who made this release possible.

Acronis Backup Flaw Is Being Exploited on Linux Hosting Servers

LinuxSecurity.com - Enj, 17/09/2026 - 1:45pd
Acronis has fixed a high-severity vulnerability in its Linux hosting backup integrations after detecting exploitation in limited, targeted attacks. The Acronis backup flaw, tracked as CVE-2026-87886, lets a low-privileged local user increase privileges on a vulnerable server because of insecure file permissions.

Container Security Failure Could Let a Malicious Image Reach the Linux Host

LinuxSecurity.com - Mër, 16/09/2026 - 12:31md
Container security can fail before a workload fully enters its root filesystem, the private file tree the container is meant to see.

Linux SMB Security Fixes Restore Ownership and Input-Trust Boundaries

LinuxSecurity.com - Mër, 16/09/2026 - 12:22md
SMB, or Server Message Block, lets Linux systems access files shared over a network.

How Transparent Huge Pages Could Lose Rewritten Data During Reclaim

LinuxSecurity.com - Mër, 16/09/2026 - 12:16md
Transparent huge pages let Linux manage memory in larger blocks for better performance.

Why eBPF Security Depends on Matching Metadata Lifetimes

LinuxSecurity.com - Mër, 16/09/2026 - 12:07md
eBPF lets verified programs run inside the Linux kernel. Linux eBPF security depends on supporting data remaining available for as long as those programs can use it.

Faqet

Subscribe to AlbLinux agreguesi