You are here

Agreguesi i feed

MCP Toolbox Flaw Could Expose Google Service Tokens

LinuxSecurity.com - Mër, 23/09/2026 - 9:45md
A September 23 advisory describes a flaw in the Python SDK used with MCP Toolbox: a shared cache could send a Google ID token to a service it was not meant for.

Emacs Security Flaw Could Run Code From an Untrusted File

LinuxSecurity.com - Mër, 23/09/2026 - 9:45md
A September 22 advisory on an Emacs vulnerability says opening a crafted file could run code on the reader's computer, even with the editor's default settings.

Linux HID Flaw Could Leak Kernel Memory Through Input Events

LinuxSecurity.com - Mër, 23/09/2026 - 9:30md
A newly merged Linux HID fix addresses a Wacom input-device path that could read beyond a short report and pass a value to local software.

Linux DAMON Page-Table Bug Could Corrupt Arm64 System Memory

LinuxSecurity.com - Mër, 23/09/2026 - 9:25md
Linux DAMON, the kernel's Data Access Monitor, samples memory use to show which pages a workload touches.

GitHub Enterprise Server Flaw Could Let Attackers Run Code

LinuxSecurity.com - Mër, 23/09/2026 - 8:15md
A GitHub Enterprise Server security fix addresses a way to turn the appliance's notebook viewer into a route to its own internal services.

Andreessen Horowitz Launches AI/Company-Building School As a College Alternative

Slashdot - Mër, 23/09/2026 - 6:04md
TechCrunch quipped it was like if startup school Y Combinator and Peter Thiel's build-a-company-instead of-college Fellowship Program had a baby. Silicon Valley venture capital firm Andreessen Horowitz is investing $35 million to launch a private school in San Francisco "aimed at turning high school graduates into founders," writes the SF Standard. Or, as CBS News describes it, "One blue-chip Silicon Valley investor has a proposal for young people who are questioning whether to attend college — enroll in AI school instead...." Specifically, the academy will provide instruction geared to subjects such as designing AI systems, fundraising for startups, selling businesses and storytelling. Students won't take tests or be assigned homework but will instead focus on building real projects. Courses will be taught by tech entrepreneurs, with the academy naming OpenAI CEO Sam Altman as either an instructor or guest lecturer. From the SF Standard: "There will be no traditional grades, tests, or homework," said the announcement. Instead, students will be encouraged to "build" in SF and work with partners from Anthropic, OpenAI, Google, Meta, and other firms. They'll be encouraged to live in campus housing in San Francisco. "The #1 goal is to help students learn to build, which is the most important skill in the AI era," Gagan Biyani, chief executive of the academy, wrote on X. Biyani cofounded the ed-tech startup Udemy... The school is opening applications for a Founding Class Fellowship a one-year, tuition-free program for around 50 students... The academy said it will bring in notable Silicon Valley names, like OpenAI's Sam Altman, as guest speakers and faculty. Students in the founding class will receive about $50,000 worth of computing credit — the sought-after currency in Silicon Valley to run AI models — as well as a $5,000 travel and research budget. The school is receiving funding from tech executives, including Fidji Simo, formerly of OpenAI and Instacart; Garry Tan, CEO of Y Combinator; and Tobi Lütke, CEO of Shopify. "In the AI era, it's more important to come out with a portfolio of projects that you worked on and work experience than it is to have a diploma or certificate," Biyani told the San Francisco Chronicle: Biyani said the academy plans to grow its enrollment and open a two-year program, pending regulatory approval, starting in the fall of 2028. Tuition is expected to be on par with the cost of an elite private university... The academy raised $42 million in funding led by Andreessen Horowitz. The ten founding partners are Anduril, Anthropic, Coinbase, Google, Meta, Nvidia, OpenAI, Palantir, Replit and Stripe. A network of hundreds of instructors, hiring partners and guest speakers includes OpenAI co-founder Sam Altman, Nvidia CEO Jensen Huang, neuroscientist Andrew Huberman and Microsoft chairman and CEO Satya Nadella, according to the academy's website. The FAQ describes a typical week by saying "Most of your time is yours to build. Each week, you share your progress with peers and practitioners, get direct feedback, and decide where to take your work next." Q: Can I use AI to help with my application? A: Yes. Use AI the way you'd use it on any project: to move faster, test ideas, and get past a blank page.... "The best assignments now are problems so hard they cannot be solved without AI," Andreessen Horowitz argued on X.com. "The Academy courses follow the same logic and will be taught by world-class leaders... The next generation will not be taught the way the last one was. The Academy is built for that world, and it begins in San Francisco." Thanks to long-time Slashdot reader theodp for sharing the news.

Read more of this story at Slashdot.

Bitcoin Surges to $86,455, an 8-Month High, After America's SEC Announces Tokenized Stock Experiment

Slashdot - Mër, 23/09/2026 - 1:34md
August 15: $62,991 September 23: $86,456 Bitcoin shot up 37% over the last 39 days, reaching an eight-month high on Monday. "Bitcoin is back," declares Yahoo Finance: The token held near $86,000 on Tuesday after a stunning multisession rally... [Fundstrat head of digital assets Sean Farrell told Yahoo Finance on Monday] "I think the crypto winter is over, although that does not necessarily mean the path higher will be linear." For now, momentum is on crypto's side, with bitcoin jumping more than 5% on Friday and another 6% on Monday. "We believe crypto is in the early innings of a new bull market and we see few signs of overheating," Compass Point analyst Ed Engel wrote on Tuesday. The move looks "like a combination of renewed ETF demand and a large short squeeze," Nicolai Søndergaard, senior research analyst at Nansen, said as traders betting against bitcoin are forced to buy it back, adding further fuel to the rally. Bitcoin got bad news and then good news last week. After the U.S. Congress failed Thursday to pass a cryptocurrency 'Clarity Act', America's Securities and Exchange Commission instead announced a tokenized-stock experiment. It's a five-year "innovation exemption" that "creates a path for tokenized U.S. stocks to trade through automated market makers on public blockchain," according to CoinDesk. Yahoo Finance notes that Bitcoin and other altcoins surged after the announcement.

Read more of this story at Slashdot.

Microsoft Helps Take Down Massive Automated, AI-Powered Phishing-as-a-Service Platform

Slashdot - Mër, 23/09/2026 - 9:04pd
Microsoft's security blog describes the fight against a new "AI-powered cybercrime platform" offering phishing-as-a-service, with AI-tailored lures and analyses of compromised inboxes (to identify high-value targets). The site compromised more than 12,000 inboxes in over 10,000 organizations around the world, compromising business accounts "at scale" with automated attacks and prebuilt phishing templates. AI tools could even sift through a victim's mailbox to help engineer better phishing messages. To disrupt EvilTokens Microsoft worked with other organizations, including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver Foundation, and TRM Labs to Health-ISAC (a non-profit helping health sector organizations share cyber threat information). "Fifty sites seized and 150 domains disabled in a single action is only possible when the hosting providers, the exchanges, the model providers and the data holders all move at the same time," security company SpyCloud told The Hacker News. From Microsoft's security blog: Microsoft also notified affected customers, helped remediate compromised accounts, and shared intelligence to support further defensive and investigative action... Microsoft worked closely with specialist officers from the Metropolitan Police Service's cybercrime team, sharing intelligence that enabled officers to take operational action in the United Kingdom. On September 11, 2026, officers arrested two men, aged 32 and 38, and seized digital devices and other items for examination... While EvilTokens used AI to identify targets and prioritize fraud opportunities, Microsoft investigators used reverse engineering and AI-powered tools to analyze evidence, accelerate the investigation, and identify the infrastructure supporting the service... Campaigns leveraging EvilTokens have impacted organizations in various industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with the highest concentrations of observed victim activity in the United States, Canada, the United Kingdom, Australia, India, and France. Working with partners, Microsoft's Digital Crimes Unit (DCU) facilitated a coordinated disruption of infrastructure used to operate the EvilTokens service. Sometimes stolen tokens were used to give new devices access to a victim's inbox. (A code authenticating the new device was sent to the targeted user, who unknowingly authorize the threat actor's session and grants access to their account...) But "AI was not simply helping attackers write more convincing messages," says another Microsoft blog post. "It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible." The significance of EvilTokens extends beyond its rapid growth and global reach. It offers an early warning of what happens when cybercriminals combine stolen access with AI capable of understanding how an organization works... Its AI tools could summarize and translate emails, surface financial conversations, map organizational roles, identify trusted relationships, and recommend potential targets. Preset prompts offered to find wire-transfer discussions, identify the organization's "money movers," locate vendor invoices, and determine the best people to impersonate. Sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service. Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface. Investigators found evidence that large portions of EvilTokens had been "vibe coded," with AI helping its creators build the platform itself. They also determined that EvilTokens drew on capabilities from multiple AI models. The result was more than a collection of attack tools. EvilTokens packaged much of the fraud process into a commercially run service, complete with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.

Read more of this story at Slashdot.

Jordan Petridis: The GNOME LLM Policy That I Want

Planet GNOME - Mër, 23/09/2026 - 8:02pd

KDE is on the news because of a controversial proposal to define an official “AI” (LLM) policy. Other projects have tried their hand at similar policies and stances but, in my opinion, they miss the mark about the goal of such initiatives. I think that the point of these statements is shaping social norms and not micro-managing developer workflows. They should be about signalling what kind of behavior we want, and what kind we reject.

This proposal does not go into detail about the many problems that LLM have caused to society, workers, the environment. It goes without saying that all these ills are fundamentally opposed to the humanist spirit of GNOME.

With all that in mind, here is what I personally think a GNOME LLM policy could be:

A GNOME Project LLM Policy The GNOME Project prioritizes the social and human aspects of collective software creation. Therefore: 1. LLMs ("AI") can not be used to create or modify code submitted to GNOME, or hosted on GNOME infrastructure. You might be asked to prove your code meets this requirement. You might be banned for trying to circumvent this policy. Example Guidelines for Contributors

These are just a draft of the kind of criteria one could use to evaluate if a submission fits the policy.

  • You must be able to personally reason and explain your changes
  • You must be able to demonstrate knowledge of the problem space you are working on
  • You must solve the underlying issue, not just its symptoms
  • You must respect the time of fellow contributors
  • You must not impersonate yourself through chatbots, agents, or other automated systems
This Is About The Future Of GNOME

GNOME is not just software that happens to ship every six months. That is just a delusion we have been holding up for the last 30 years to keep our loose group of colleagues, friends, and acquaintances, together.

GNOME exists as a collective that find joy in reaching beyond our individual limitations to achieve something bigger. These people, this joy, are the whole point of the project. Contributors are not payroll, a liability, that we hope to downsize next quarter.

“Come do free labor for a handful of corporations by reviewing chatbot output in your free time” is not an attractive proposition to young talented people in 2026. If we want GNOME to continue we need to create an attractive and inviting social space where people are valued as people.

Just like the Foundation is moving to individual donations to stop depending on just a handful of companies, we need to look for the next 100 people that will donate a tiny bit of their time, instead of hoping that corporations will keep 10 overworked engineers on staff. We already have seen how companies will happily abandon a whole chunk of GNOME on a whim.

GNOME is not just software, and it should protect the social and human aspects that make it special. Our success metric is the community and social bonds we create. In the most literal sense GNOME is about the journey and the friends we make along the way.

Free Palestine.

FAQ How do you enforce this?

You can not. People will still send LLM generated code. This policy makes it explicit that we do not welcome these careless submissions. We have a Code of Conduct that is 80% about telling other people what our values are, and 20% about handling unwanted behavior (“enforcing”). This is similar.

What if people simply lie about not using LLMs?

This is the same problem as authorship, in the copyright sense. Whenever we receive new code we have to assume that “beyond a reasonable doubt” said code has been authored by the person contributing it. We make our best guess. The attached guidelines are a suggestion to make these new guesses.

Ok. But what if people are really good at lying?

This policy is about the majority that will not even try to lie. See previous questions.

Trump Denounces Attempts to Control AI, Wants It Renamed 'Super Intelligence' in US Documents

Slashdot - Mër, 23/09/2026 - 4:34pd
U.S. President Trump addressed the United Nations on Tuesday. And a half hour in, after decrying immigration, Trump pivoted to add that "The United States also totally rejects any attempt to construct a globalist scheme to control for the artificial intelligence being spoken of so much now." But then he added "hereinafter officially called super intelligence, changing the name, in that the use of the word artificial makes intelligence fake. It makes it sound fake, and it is not fake. It's actually... amazing. But we have to be careful — in fact, it is exactly the opposite of what it purports. From this point forward, all of United States documents and hopefully the world's will be changed to use the much more accurate term super as opposed to artificial. So it's super intelligence." TRUMP: In other words, welcome to the new world of super intelligence — SI. SI. Let's see if that goes. It sounds much better. It is much better, and it's much more accurate. Let's see if I have any power. Maybe I do and maybe I don't. We're going to find out pretty soon. Super intelligence. Every major new technology brings challenges, and super intelligence is no exception. Yet the very same people who said we'll all be dead in 12 years because of global warming, a name since reborn to climate change because the planet was cooling not warming, and nobody was dead — these are the same people that are now saying that AI is going to kill us all. That robots are going to attack us, and that everything is going to be a total disaster — same group of people. This is the group that came up with the Russia Russia Russia hoax, the Ukraine Ukraine Ukraine hoax. Climate change, open borders. Whoever wins AI — you have to remember this — and now I say, whoever wins SI, whoever wins super intelligent [sic] — wins. That's the group that wins. And we're leading now over China by a lot, and everyone else, and we're going to keep it that way. We're going to keep it very — very straight and very strong. I'm not going to stifle growth of something that will be bigger than the Industrial Revolution. Many say, bigger than the Industrial Revolution or the internet itself. And we will be very careful, and that's why we have a Department of Justice that we've already used it, having to do with this very subject, and used it very powerfully. Everything worked out very well and very quickly. And other law enforcement bodies that will rein things in if we have to do that. But we will only encourage super intelligence. We're gonna encourage it, not rein it in. We're gonna watch it closely, through the Department of Justice. The United States leads the world in Super Intelligence, and will continue to do so, safely and responsibly. Thanks to long-time Slashdot reader ArchieBunker for suggesting the story.

Read more of this story at Slashdot.

Why Seccomp Must Be Rechecked After Container Restore

LinuxSecurity.com - Mër, 23/09/2026 - 3:25pd
Seccomp limits which Linux system calls a process can make.

How Container Restore Can Reopen Privilege Escalation Paths

LinuxSecurity.com - Mër, 23/09/2026 - 3:15pd
Privilege escalation in a container does not always begin with a new exploit.

What CRIU Restores Beyond Application Memory in Linux Containers

LinuxSecurity.com - Mër, 23/09/2026 - 3:15pd
Linux containers can be paused, checkpointed, and rebuilt later with CRIU.

Why Container Security Needs a Separate Restore Boundary

LinuxSecurity.com - Mër, 23/09/2026 - 2:59pd
A container normally starts under the security rules of the system receiving it.

CRI-O Restore Flaw Can Bypass Kubernetes Security Policies

LinuxSecurity.com - Mër, 23/09/2026 - 2:45pd
Kubernetes groups one or more containers into a pod, the basic unit it deploys.

PH4NTXM Linux Builds a Disposable Identity at Every Boot

LinuxSecurity.com - Mër, 23/09/2026 - 2:25pd
A live Linux distribution runs from removable media, usually a USB drive, without requiring a permanent installation.

Hylke Bons: Bobby 51

Planet GNOME - Mër, 23/09/2026 - 2:00pd

With the imminent release of GNOME 51, I realised I hadn’t released an update to Bobby in a few months.

The long tail of crash reports after a release just doesn’t seem to happen anymore when working with Rust. It’s just done and I moved on to other things.


Screenshot of a SQLite table being searched in Bobby Search

Bobby follows the GNOME version number scheme for convenience, but I did not want to let a major version bump go by without at least one new useful feature. So I’ve added search.

It uses case-insensitive fuzzy matching to filter out rows and highlight cells using the system accent colour as you type.

Simple yet effective!

Future

There are now two big features left that I want to implement:

  • Encrypted file support
  • Updating values in place

I’m not sure which one to work on in the next cycle, so let me know in this poll on the Fediverse which is most useful to you.

Happy equinox and don’t forget to sanitise your database inputs!

Are Students Suddenly Losing Interest in Computer Science as AI Coding Takes Off?

Slashdot - Mër, 23/09/2026 - 12:04pd
On academic mentoring platform Nova Learning, Computer Science and AI, "once the dominant choice among students... is losing ground fast, while Engineering has nearly doubled its share." It's a small survey, but "The steepest proportional decline is in Software & Data Science, the most traditional 'learn to code' pathway, which lost 44% of its 2025 share. AI saw the largest absolute drop of any single subject in the survey, down 6.2 points. "The category did not decline uniformly. Students moved away fastest from the pathway most associated with entry-level software work, while the more applied and human-facing subfields held their ground better." Slashdot reader BrianFagioli writes: Nova Learning says the share of surveyed middle and high school students naming Computer Science and AI as their primary academic interest fell from 42.3 percent in 2025 to 27.9 percent in 2026, while Engineering rose from 11.9 percent to 23 percent. The biggest gains came from Mechanical and Aerospace Engineering... [B]roader enrollment data points in the same direction. The National Student Clearinghouse Research Center reported declines in Computer and Information Science enrollment at four year institutions, even as Engineering grew. AI coding tools are not proven to be the cause, but as software development changes and AI handles more coding tasks, students may be starting to rethink what a future in technology should look like. [Undergraduate enrollment in CS programs at four-year institutions fell 8.1%, to approximately 606,000 students.]

Read more of this story at Slashdot.

'Coyote vs. Acme' Outgrosses All But 3 WB Movies This Year, Heads To Profit

Slashdot - Mar, 22/09/2026 - 7:34md
The movie Coyote vs. Acme earned more than Warner Bros.' $30 million tax write-off in just two weeks. And last week the movie officially earned more than its production budget of $70 million. But today the movie passed the $100 million mark. "You asked for it, we delivered, and you showed up!" distributor Ketchup Entertainment posted on social media (adding "Thank you to the fans for making this a massive hit!") With a break-even number of $120 million, the movie "will probably make up any theatrical deficit (should there be any) with its impending releases on video on demand and streaming," writes ScreenRant. Almost three years after the completed film was initially shelved for a $30 million write-off, its cumulative domestic box office has apparently even beat Warner Bros. dinosaur movie The End of Oak Street: In addition to officially joining the chart of the Top 30 movies of the year so far at the domestic box office, by surpassing The End of Oak Street, Coyote vs. Acme has outgrossed five of the eight movies that Warner Bros. has put out in domestic theaters this year.... [It's just $17.6 million behind Supergirl, and within $30 million of Mortal Kombat II and Wuthering Heights.] Their anticipated sci-fi sequel Dune: Part Three also seems guaranteed to land higher than 2026's Coyote vs. Acme on the chart (2021's Dune earned $108.9 million in domestic theaters, while Dune: Part Two earned $282.1 million). With its a small marketing budget of just $10 million, the movie seems to be relying on oddball marketing stunts like their AMA on Reddit's r/movies. And commemorating the spirit of the movie, Crayon-maker Crayola even released a special "Coyote Secret Plan" web page for children to print and color — and partnered with the film's stars for a video on the importance of creativity: Lana Condor: Crayola is all about encouraging kids and grown-ups to turn imagination into action. Will Forte: Which is exactly what Coyote does in Coyote versus Acme. He sees a problem and thinks, "Could this be solved with a rocket, a catapult, or a suspiciously affordable mail order anvil?" Lana Condor: Usually no. Will Forte: Usually very no.

Read more of this story at Slashdot.

next-20260922: linux-next

Kernel Linux - Mar, 22/09/2026 - 3:23md
Version:next-20260922 (linux-next) Released:2026-09-22

Faqet

Subscribe to AlbLinux agreguesi