%

Echoes #202620: y2026, w20

Weekly Echoes #2026W20: IT news, round-up, week 20; from 05/11 to 05/17.

Details about this article

Article published the ; modified the
7 minutes to read

This article has 1357 words.

Uniq IDentifiant: tag:,2026-05-17:/en/echoes/week-20-2026/


RAW source of the article:
Commit version: 592f8b6


This article is available too, on Gemini protocol:
gemini://gmi.huc.fr.eu.org/en/echoes/week-20-2026.gmi


Agenda

⇒ (05/14) Home Assistant: Rome HA Meetup hosted by Nabu Casa

Join us in Rome for a vibrant Home Assistant meetup hosted by Nabu Casa, partners of the Open Home Foundation.

App

⇒ (05/12) Game of Trees 0.125 released

Version 0.125 of Game of Trees has been released (and the port updated).

⇒ (05/13) NetBSD 11.0 RC4 available!

The NetBSD project is pleased to announce the fourth (and this time hopefully final) release candidate of the upcoming 11.0 release, please help testing! See the release announcement for details.

⇒ (05/13) DokuWiki Markdown Support

The next release of DokuWiki will support parsing and rendering Markdown.


Documentation

⇒ (05/12) Secure Coding Guide for Python (pyscg) First Release

New developers require a single, framework-independent resource to establish a baseline in secure coding practices.

IT

⇒ (05/11) Mythos finds a curl vulnerability

Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead trickle it out to a selected few companies for a while to allow a few good ones(?) to get a head start and fix the most pressing problems first, before the general populace would get their hands on it…

⇒ (05/11) Let’s Learn Linux: Customize and use the shell environment

⇒ (05/11) Better Shell Scrollback with Timestamps

Last week I noticed a pattern in some of my shell workloads: run something in a shell, go change some code, run it again. And often I’m looking for some sort of change between runs…

⇒ (05/11) OpenBSD and slopcode: raindrop to a torrent?

Every single software product is dealing with the question about what to do with “AI”-generated code, but the question is particularly difficult to answer for open source operating systems like Linux distributions and the various BSDs, which often consist of a wide variety of software packages from hundreds to thousands of different developers. On top of that, they also have to ask the “AI” question for every layer of their offering, from the base install, to the official repositories, to community-run ones.


⇒ (05/12) Let’s find out how to get predictable IPv6 addresses assigned to OpenBSD VMs

Every single software product is dealing with the question about what to do with “AI”-generated code, but the question is particularly difficult to answer for open source operating systems like Linux distributions and the various BSDs, which often consist of a wide variety of software packages from hundreds to thousands of different developers. On top of that, they also have to ask the “AI” question for every layer of their offering, from the base install, to the official repositories, to community-run ones…

⇒ (05/12) FreeBSD Resource Monitoring, Accounting, and Troubleshooting

“The server feels slow.” It is the most common ticket text in the world, and the least useful. Before you can fix anything you need to know whether the box is CPU bound, memory pressured, waiting on disk, saturating a NIC, or simply running a runaway process in one jail that is starving everyone else. On jail hosts, the second half of the problem is attribution: not just what is overloaded, but which jail is responsible…

⇒ (05/12) Automatic expiry at timeout for pf(4) overload tables

Network-oriented readers will be familiar with the concept of overload tables, commonly used with state tracking options to create adaptive rulesets for such things as punishing password-guessing botnets. A downside to tables that would tend to fill up indefinitely is that at some point they will be quite full, and the administrator would need to either manually run pfctl expire or set up a crontab entry to weed out old entries at intervals.

⇒ (05/12) OpenZFS 2.4.2 Released With Linux 7.0 Kernel Support, Many Bug Fixes

For those making use of OpenZFS on Linux or FreeBSD, OpenZFS 2.4.2 is out today as the newest stable release of this ZFS file-system implementation…

⇒ (05/12) Tailscale SSH Server Access on FreeBSD

Simple and secure steps to run tailscaled for Tailscale SSH server access to a FreeBSD server with ipfw.

⇒ (05/12) Bambu Lab is abusing the open source social contract

Last year I said I’d probably never recommend another Bambu Lab printer again. I still use my P1S, but after Bambu Lab started pushing their always-connected cloud solution as the new default:


⇒ (05/13) OpenBSD stories—OpenBSD/zaurus: pocket-sized BSD


⇒ (05/14) BSDNow: 663: Proxhyve

Switching from Proxmox to Sylve, FreeBSD Quarterly report, FreeBSD’s laptop program, Migrating ZFS, Haiku and OpenSSL news, and more…

⇒ (05/14) minwm: An extremely minimal window manager

⇒ (05/14) Browsers Treat Big Sites Differently

Safari and Firefox change how big sites render based on the domain. TikTok, Netflix, Instagram… even SeatGuru. Chrome doesn’t. Why is that?


⇒ (05/15) OpenSMTPD Is The Mail Server For The Future

The SMTP mail server for the 21st century and onwards is OpenSMTPD, which is developed as an integral part of OpenBSD, but available in a portable variety too. It was one of those things that I had fully intended to do years ago, but I only got around to actually doing once there was a definite deadline to get it done. The time has come, as OpenBSD 7.9 will leave the exim package behind, and exim users will need to find a replacement before upgrading. This article describes my transition to OpenBSD’s own OpenSMTPD mail server.


⇒ (05/16) When the Vendor Forgets Linux Exists

Last week I bought a Rode Interview PRO wireless microphone. It is a beautiful piece of hardware-properly wireless, with onboard storage so I can record street interviews without worrying about signal drops. I have been waiting for sunny weather to take it out for its first real test. On paper, Linux support should be a non-issue. Plug it in, it shows up as USB mass storage, copy your WAV files off, done. And that part works perfectly. I pulled my first recordings off, edited them, everything was fine.

RetroComputing

⇒ (05/17) LEGO Amiga 4000 build: Commodore classic reimagined as the Amiga CD3200

Retro Connoisseur is building the Amiga 4000 into a LEGO block case, and the project already feels like the kind of wonderfully unlikely machine that could

Society

⇒ (05/11) Nissan and Red Hat Co-Engineer the Future of Software-Defined Vehicles

Nissan selects Red Hat In-Vehicle Operating System as the foundation for its next-generation Central Vehicle Computer. This collaboration will involve Red Hat In-Vehicle Operating System to provide a standardized, scalable Linux foundation for Nissan Scalable Open Software Platform (SW PF), accelerating Nissan’s transition toward flexible, software-defined mobility architectures.

Security

⇒ (05/12) Malware found in Linux builds of Cemu (Wii U emulator)

If you’ve downloaded the Cemu Wii U emulator for Linux from the project’s official GitHub in the past few weeks, bad news: it added malware to your system when you ran it.

⇒ (05/12) AMD CPU OP Cache Corruption

AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level.

⇒ (05/13) Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub

Where it’s been well and truly forked, seemingly without Microsoft’s code locker noticing. Notorious malware crew TeamPCP appears to have open-sourced its Shai-Hulud worm.

⇒ (05/13) NGINX Rift

An 18 year old memory corruption flaw in NGINX Plus and NGINX Open Source lets an unauthenticated attacker crash worker processes or execute remote code with crafted HTTP requests.