Agenda
Agenda:2026/06/08
Gaming
Agenda:2026/06/12
⇒ Cheat Engine now has a Linux version released
A popular tool on Windows - Cheat Engine recently gained a Linux version, so you can mess with your games under Linux now too. Just how popular is it? Well, you need only look at their Patreon to see they’re pulling in (at time of writing) $17,610 a month which is pretty staggering.
Hardware
Hardware:2026/06/09
⇒ Hyundai Motor and Kia Join the Open Invention Network 2.0 Community
Open Invention Network (OIN), the organization formed to safeguard Open Source and the largest active patent cross-license in history, announced today that Hyundai Motor Company (Hyundai Motor) and Kia Corporation (Kia) have joined in support of OIN 2.0. As leading developers of forward-thinking mobility solutions, Hyundai Motor and Kia — the first major Korean companies to join OIN 2.0 — are reinforcing their commitment to Open Source as a critical enabler of software-defined vehicles, connected car platforms, cloud services, robotics, and other next-generation mobility technologies
- https://openinventionnetwork.com/hyundai-motor-and-kia-join-the-open-invention-network-2-0-community/
#OIN #Hyundai #Kia
IT
IT:2026/06/08
⇒ Meet Melia: A Privacy-First, Modern Desktop Email Client Made Just for Linux
It is not an open source software but ticks a lot of other boxes for anyone looking for an alternative desktop email client on Linux.
- https://itsfoss.com/melia/
#Melia #MUA
⇒ AliasVault Is The BitWarden Alternative You Didn’t Know You Needed
It is open source, self-hostable, and free. What more do you want?
- https://itsfoss.com/aliasvault/
#AliasVault #Passwords #manager
⇒ OpenBSD under QEMU
Architecture specific notes for OpenBSD guests under QEMU, with working command lines where installation succeeds and failure points where it does not.
- https://kirill.korins.ky/articles/openbsd-under-qemu/
#OpenBSD #qemu
IT:2026/06/10
⇒ OpenBSD stories—Trojaned OpenSSH
This is a story I had been considering writing for a long time, as many wrong or stupid things have been said or written at the time it happened. Being on a quite sensitive subject, I have however opted to redact a few things, especially the identity of two OpenBSD developers, as well as some IP addresses and other minor details which could help identify them. They will be referred to as dev1 and dev2 in this story. It does not matter who they are, and they really are trustworthy.
- http://miod.online.fr/software/openbsd/stories/trojan.html
#OpenBSD #OpenSSH #trojan
⇒ Speeding up data transfer with tar and SSH
Speed up file transfer by streaming tar through an SSH tunnel.
- https://cromwell-intl.com/open-source/tar-and-ssh.html
#Transfer #tar #SSH
⇒ Good News For Linux Terminal Junkies! Proton Drive Now Has a CLI
Something to work with before the GUI client for Linux drops.
- https://itsfoss.com/news/proton-drive-cli/
#Proton #CLI #Linux
⇒ Blockbuster new Raspberry Pi project turns any screen into old-school VCR
Who needs fancy menus and high definition? 240-MP will play your media files like it’s 1999
IT:2026/06/11
⇒ A Simple Log Cleaner for Nginx and Apache referer_log
How to filter the Nginx and Apache referrer logs and see the search strings being used to find your pages.
⇒ BSD Now—667: Don’t exceed by security boundary
.NET on FreeBSD 15, Klara and TrueNAS fixing dedup, dhcpcd and unbound in FreeBSD Jails, and more…
IT:2026/06/12
⇒ syslogd(8) privileged and non-privileged parts now separate binaries
In OpenBSD, the syslogd(8) system logger has already for a while now fork(2)ed the privileged from the non-privileged parts.
- https://undeadly.org/cgi?action=article;sid=20260612080210
#OpenBSD #syslogd
⇒ Caterer Mike and the Alphabet Soup
On vendor lock-in and enshittification, without a single line of tech. A story about a caterer, a vanished kitchen and the price that never appears on the invoice.
- https://belibre.be/en/blog/sovereignty/caterer-mike-and-the-alphabet-soup/
#lock-in #digital #resilience
⇒ OpenBSD - Remote Kernel MPLS Stack Disclosure
mpls_do_error copies (nstk+1) label-stack entries from a fixed 16-entry array when no BoS label is present, leaking 4 bytes of adjacent kernel stack memory in the ICMP/MPLS error response.
IT:2026/06/13
⇒ Chef’s Undocumented delayed_action
Chef has an undocumented feature that’s super handy and more people should know about.
Release
Release:2026/06/09
⇒ Fedora 44 RISC-V Images Released, Including New “Omni” Kernel For Broader RISC-V Hardware Support
Following the official Fedora 44 images released one month ago, Fedora 44 RISC-V images were published today for those wanting to run this newest Fedora Linux on RISC-V hardware.
- https://www.phoronix.com/news/Fedora-44-RISC-V-Images
- https://discussion.fedoraproject.org/t/fedora-44-risc-v-non-official-images-are-available/193356
#Fedora #RISC-V
Release:2026/06/12
⇒ MX Linux 25.2 provides possible refuge from AI as well as systemd
Plus, Raspberry Pi edition finally catches up
- https://www.theregister.com/software/2026/06/12/mx-linux-252-arrives-with-switchable-init-and-pi-refresh/5255017
#MX-Linux #Raspberry
Security
Security:2026/06/08
⇒ Off By !: Exploiting a Use-after-Free in the Linux Kernel
In this blog post, we discuss a use-after-free vulnerability that we found in the nftables subsystem of the Linux kernel in early 2025. This vulnerability was patched upstream on 5 February 2026 and assigned CVE-2026-23111. This blog post covers a technical analysis of the vulnerability and how we exploited it to perform a local privilege escalation from an unprivileged user to root on Debian Bookworm, Debian Trixie, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
- https://blog.exodusintel.com/2026/06/08/off-by-exploiting-a-use-after-free-in-the-linux-kernel/
#Vulnerability #Linux #kernel
Security:2026/06/09
⇒ Miasma worms its way onto GitHub as attack kit goes open source
As if there weren’t enough package poisonings to worry about
- https://www.theregister.com/cyber-crime/2026/06/09/miasma-supply-chain-attack-toolkit-goes-public-on-github/5253074
#Miasma #versus #GitHub
Security:2026/06/10
⇒ A Final Return for OpenBSD Anti-Return-Oriented Programming Mitigations
Return-Oriented Programming (ROP) continues to be a serious attack taking advantage of flaws in memory unsafe languages, particularly buffer overflows, to launch arbitrary code execution attacks by chaining together pieces of already existing code in loaded binaries and shared libraries, called gadgets. With the continued reliance on x86_64 CPUs in cloud and personal servers, mitigations that can meaningfully reduce the success of ROP attacks without significant overhead continue to be attractive. We propose the porting of one such software-based anti-ROP mitigation proposed by OpenBSD: compile-time instruction rewriting to avoid opportunities for ROP exploitation. We bring this mitigation, originally developed for the custom OpenBSD implementation of the LLVM compiler suite, to GCC by way of a standalone utility that sits in between the compiler and the assembler and rewrites potential gadget instructions before assembly into object code. Our utility provides a minimal reduction in gadgets with some penalties in binary sizes and performance impacts. We compare our GCC-ported standalone utility to the original OpenBSD LLVM mitigation and discovered that our standalone utility is weaker compared to the original LLVM-based mitigation. However, due to the overall weak reduction in gadgets for both the LLVM-based and GCC-based implementations, we conclude that seemingly obvious mitigations may prove to be anything but, and caution providing security improvements without significant testing and evaluation.
- https://www.researchgate.net/publication/405728967_A_Final_Return_for_OpenBSD_Anti-Return-Oriented_Programming_Mitigations
#Study #OpenBSD #antiROP
⇒ Mini Shai-Hulud: Where SLSA’s Boundaries Fall
On May 11, 2026, attackers compromised 84 npm package artifacts across 42 @tanstack packages, and the worm spread to 170+ packages across @mistralai, @uipath, and other namespaces. The “Mini Shai-Hulud” attack chained a GitHub Actions workflow misconfiguration, cache poisoning, and OIDC token extraction to publish malicious packages through legitimate CI/CD pipelines.
- https://openssf.org/blog/2026/06/10/mini-shai-hulud-where-slsas-boundaries-fall/
- https://slsa.dev/blog/2026/05/mini-shai-hulud-what-slsa-can-and-cannot-do/
Security:2026/06/11
⇒ BUMSRAKETE™
The HUGEST, the MOST TREMENDOUS FreeBSD page-cache write primitive in the history of computing. Many people are saying it. Many. Believe me.
- https://bumsrake.de/
#FreeBSD #vulnerability #humour
⇒ Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps
The new open-source project could serve as the basis for a future of apps with features as complex as Slack, Discord, or Google Docs—but with added protection against surveillance.
- https://www.wired.com/story/signal-alums-release-encrypted-spaces-a-new-system-for-building-private-collaboration-apps/
- https://encryptedspaces.org/
#Signal #Encrypted #spaces
⇒ Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected
Discover the detailed forensic investigation by Sygnia into the sophisticated cyber attack by Velvet Ant on a major organization.
Security:2026/06/14
⇒ The security situation with the Arch Linux AUR got a lot worse
Oh dear, the situation with the Arch Linux AUR got a fair bit worse since GamingOnLinux initially covered the malicious packages.
- www.gamingonlinux.com/2026/06/the-security-situation-with-the-arch-linux-aur-got-a-lot-worse/ #AUR #supply-chain #attack
⇒ An AI Agent Infiltrated Fedora’s Bug Tracker and Wreaked Havoc
A hijacked contributor account let an AI agent loose on Fedora’s bug tracker, closing bugs, posting hallucinated fixes, and getting bad code into Anaconda.
- https://itsfoss.com/news/fedora-bug-tracker-infiltrated-by-ai-agent/
#Fedora #Infiltration #AI
AI
AI:2026/06/08
⇒ Ainekko’s Edge AI Silicon Platform is Now an OpenHW Foundation Open Source Project
The CORE-ET Silicon Platform accelerates low-power AI inference with many-core RISC-V compute, MRAM, and open tooling
- https://www.globenewswire.com/news-release/2026/06/02/3305225/0/en/ainekko-s-edge-ai-silicon-platform-is-now-an-openhw-foundation-open-source-project.html
#Ainekko #OpenHW #RISC-V
AI:2026/06/13
⇒ There is a New X11 Server, Written in Rust, With the Help of AI
Yserver is a vibe-coded project that ditches legacy code to work cleanly on modern Linux systems.
- https://itsfoss.com/news/yserver/
#Yserver #x11
AI:2026/06/14
⇒ 128GB of Local VRAM vs The Cloud: Cost Optimisation, Zero Telemetry, and What’s Possible with Local Dev Stacks
Token counts, cloud subscriptions, and API rate limits are a constant drain. Beyond the monthly line items and the continuous cost optimisation of running infrastructure, the primary driver for me is data containment. Ensuring that not a single packet of proprietary code or infrastructure configuration leaks into an outbound telemetry stream to an external corporate LLM provider is a massive win
Society
Society:2026/06/09
⇒ LibreOffice brands Euro-Office a ‘de facto ally’ of Microsoft’s lock-in strategy
The Document Foundation accuses newly launched Euro-Office of undermining digital sovereignty by defaulting to Microsoft’s OOXML document format
- https://www.theregister.com/applications/2026/06/09/libreoffice-brands-euro-office-a-de-facto-ally-of-microsofts-lock-in-strategy/5252854
#LibreOffice #versus #Euro-Office
Society:2026/06/10
⇒ Infosys Joins Eclipse Foundation’s Software Defined Vehicle Working Group to Advance Open, Secure, Scalable, and Future-Ready Software Foundations
Infosys has joined the Eclipse Software Defined Vehicle (SDV) Working Group, a global open-source consortium under the Eclipse Foundation focussed on accelerating software-defined vehicle innovation. Infosys is contributing to Eclipse openDuT, Eclipse S-CORE (Eclipse Safe Open Vehicle Core), and other work groups focussed on development of open, standardized, and interoperable software foundations for in-vehicle embedded systems. The Eclipse SDV Working Group brings together global automakers, tier-1 suppliers, cloud providers, and technology leaders to build automotive-grade software platforms governed by the community.
Society:2026/06/11
⇒ Sustaining the Commons in an Age of Digital Sovereignty
Digital sovereignty raises legitimate questions about dependency, resilience and control. It can strengthen the Internet when it builds capacity and meaningful choice. It becomes risky when it is pursued as control over the common layer that keeps the global Internet interoperable.
- https://labs.ripe.net/author/hisham_ibrahim/sustaining-the-commons-in-an-age-of-digital-sovereignty/
⇒ Eurosky launches mu – the first of a thousand social apps
Today, Eurosky launches mu, a microblogging application that serves as the testing ground for new social media experiences, built and hosted in Europe.
Society:2026/06/14
⇒ Epic Games is hiring a Security Engineer to champion Linux anti-cheat
Looks like Epic Games may be looking to actually improve how Easy Anti-Cheat works on Linux, with a job listing for a Senior Game Security Engineer. While the Epic-owned Easy Anti-Cheat does work on Linux, it’s not at the kernel level and that’s partly why so many games that use it decide to actively block Linux.