10 Oct 2026

feedSlashdot

Ubuntu 26.10 Will Offer a Rust-based GnuPG Replacement Option

The blog It's FOSS reports: You already know that Canonical has been selectively replacing Ubuntu's C-based system components with Rust-written equivalents that don't compromise in terms of functionality, most of the time. Now it looks like the distro's OpenPGP implementation is next, with Sequoia PGP coming preinstalled in Ubuntu 26.10. Canonical wants it to eventually replace GnuPG [the dominant Linux implementation of PGP, written in C] as the default toolchain, though that switch has not happened yet... [The Ubuntu 26.10 release notes say Sequoia PGP's default status will be a future goal...] [Sequoia PGP] was started in 2017 by three former GnuPG developers who chose to build a new OpenPGP implementation in Rust rather than keep evolving GnuPG's existing codebase. Sequoia PGP is designed as a library that other software can use directly, rather than a standalone command-line tool. sq sits on top of that for encryption, decryption, signing, and key management, and sqv handles signature verification, filling in for gpg and gpgv in GnuPG. Sequoia also implements RFC 9580, the 2024 revision of the OpenPGP standard, whereas GnuPG has continued from the RFC 4880 branch, pursuing its own newer extensions and the LibrePGP specification rather than adopting RFC 9580 as its primary standard. From the It's FOSS Weekly newsletter, which also notes that the founder of the It's FOSS blog has also created a Linux-themed game called TUXDLE - a variation on Wordle where all the answers are Linux terms.

Read more of this story at Slashdot.

10 Oct 2026 9:59pm GMT

Claude Sent Police a Fake Murder Tip. White House Mandates AI Companies Report Security Incidents

AFP reports that an AI model from Anthropic "submitted a fabricated tip about an unsolved homicide to Philadelphia police, authorities said Friday." Claude "was instructed never to log in, create accounts, enter personal data, make purchases, or submit anything destructive, but the instructions did not rule out form submissions," Anthropic said Friday in a blog post. Authorities are now criticizing Anthropic "for taking two months to report the incident." The Philadelphia Police Department said the false submission was made in July through PhillyUnsolvedMurders.com, a public website where people can share information about unsolved killings. According to Anthropic's account, as relayed by police, the model was running a test that involved interacting with randomly selected websites when it reached the site and filed false information about an unsolved murder. The AI model presented itself as someone who might have knowledge of the case. Anthropic's breaches have prompted the White House to mandate that AI companies notify and correct security incidents, news outlet Axios reported [yesterday], citing administration officials. "This notification and remediation process is not optional... It is a critical national security obligation," White House Super Intelligence Force leaders said in a statement to Axios. "I may have information regarding this case," Claude told the police. "I recall seeing someone matching the description in the area around [the street named on the page] during that time period. Please contact me if this information is relevant." Anthropic notes that Claude "left the name and contact fields empty, which the form allowed, and submitted it. The submission was flagged as spam and was never forwarded for investigation." But Anthropic also admits they saw "this behavior" three times - "on OSWorld (a public computer use evaluation), on Odysseys (a long-horizon task evaluation), and during internal usage." Submitting forms when it shouldn't have generally occurred "when an evaluation's instructions were ambiguous, or when a misconfiguration within the environment prevented Claude from working with dummy forms." Anthropic's blog post acknowledges three other categories of behaviors: Exploiting software flaws. Like when Claude received an error when trying to run a public tool on a university's web site, it located an injection flaw in a script on the university's server that let it run commands - including that public tool. Working around restrictions to reach gated data. For example, Claude Mythos 5 needed public data that was only available from a state agency for a fee. "Claude learned from an archived copy of the agency's website that its public dashboard issues an access token to any visitor," Anthropic explains. "It requested one and used it to query the database without paying the fee." Using URL shortening services. "Some of our fetch tools, which let Claude read webpages, limit the length of the URLs Claude can request. This is to prevent Claude from using long URLs to take certain unwanted actions, such as SQL or command injections... We saw several models, including Claude Opus 5 and Claude Mythos 5, get around this limitation by using free URL shortening services." "We have built tooling to automatically detect and block the kinds of behaviors described above," Anthropic says, saying it's already running no on most of their evaluations. "When we tested it against the cases described in this post, it blocked all of them." And they've already taken several other new preventive measures: They've stopped running some public evaluations Other public evaluations were moved to offline versions or rebuilt so their tasks don't reach live websites. They've updated the guardrails on some internet access tools (including web fetch) "to heavily restrict what the model can do." They're continuing "to fix or remove training environments that reward Claude for working around tool restrictions or other blockers, so that they do not incentivize these behaviors or permit reward hacking." They've moved internal agents to "centrally managed infrastructure with strong containment," that minimizes internet access while monitoring "far more of what agents do through techniques like safety classifiers and hierarchical summarization." In the past they'd focused reviews on cybersecurity testing, but they've broadened their transcript reviewing to other tasks which include internet access. "Because language models are non-deterministic - that is, their responses always involve some element of randomness, and they may carry out the same task slightly differently each time - we have Claude complete each evaluation task hundreds or thousands of times... If training rewards something we didn't intend - such as finding loopholes or working around a restriction - the model learns that the workaround pays off and may then apply it elsewhere." Anthropic's blog post also acknowledged they'd seen multiple misalignment incidents involving federal, state, and local U.S. government agencies. "We have briefed the White House on these cases and notified each agency involved," Anthropic wrote, adding that "While we have not completed a full alignment assessment of these cases, we consider them to be less severe than the cybersecurity incidents from this summer." (And they are "modifying training to reduce the likelihood of further misbehavior.")

Read more of this story at Slashdot.

10 Oct 2026 7:54pm GMT

OpenAI Disrupts Two AI-Enabled 'False Front' Influence Operations That Included Seven Fake Journalists

OpenAI announced it's recently banned two "influence operations" - one from Russia and one from Iran - that were using its models "to launder geopolitical, conflict-related messaging" in sophisticated "false front" propaganda campaigns: The Iranian operation included a stable of seven "journalist" personas which it used to pitch long-form articles to small and medium online outlets around the world... As well as long-form articles, the Iranian operation generated batches of social media comments, generally on topics related to the US-Iran war... [The Russian operation "appears to have co-opted unwitting people in Latin America to run a 'think tank'.... Since we do not allow access to our models from Russia, they used VPNs to connect to our services."] The Russian operation created fake "leaked" documents and audio scripts, some of which we identified being spread online... Both managed to land their content (not all of which was generated from our models) in mainstream media outlets, rather than simply posting it on social media. OpenAI says they've exposed 30 covert influence operations using its tools over the last two and a half years. But ironically, in this case both operations "also made heavy use of AI to draft internal reports (the Russian operation did this more than anything else)." And "in both cases, the actors used questionable or outright deceitful methodologies to exaggerate the operators' effectiveness." [The Russian operators] claimed that in May 2026, they created a fake email address purporting to come from the Regional Directorate of Education in Lima, Peru. They used this to instruct schools in the district to hold events dedicated to Ukraine on the national Day of Cultural and Linguistic Diversity (May 21)... According to the operators, some schools replied to the fake email address, confirming that they had held such events and even providing pictures. The operators then claimed to have planted stories about the events in the media in both Peru and Poland, alongside allegations that Ukraine was "exporting" ultra-nationalist ideologies, triggering outrage. Open-source searches identified stories that matched this claim in the Peruvianâ andâ Polish pressâ, and an English-language publication in Hungary (some of the articles have since been deleted)... Similarly, in June, the operators claimed they used a different fake email address to trick schools in Ecuador into holding a ceremony pledging allegiance to President Daniel Noboa and to Erik Prince, former head of private military contractor Blackwater. The operators claimed that the incident provoked outrage in Ecuador and put pressure on the government to deny the fake, thus amplifying it to a nationwide audience. Again, open-source research identified mediaâ coverageâ in the Ecuadorianâ pressâ that closely resembled this claim, and even a detailed rebuttalâ by Ecuador's Minister for Education. The operators used a range of techniques to underpin their false stories. According to their internal reporting, they spread two different fakes targeting Ecuador in March. One used fake audio attributed to Ukraine's consul in Ecuador, in which he was alleged to have made disparaging comments about Ecuadorians. OpenAI's report "is the latest illustration of how state actors can easily exploit widely available AI tools to peddle sophisticated propaganda against adversaries on a mass scale," argues the Economic Times: "We identified almost 100 articles published or syndicated under the [Iranian] operation's bylines across roughly a dozen online outlets around the world," OpenAI said. "These were small to medium outlets, generally focused on international affairs, geopolitics, and events in the Middle East." The earliest article identified by OpenAI was published in July 2025, and the latest in October 2026, with the frequency of reports increasing after the US-Iran war broke out earlier this year. The operation also generated social media comments on topics related to the US-Iran war, it added. One of the personas named Ervin B. Hoskins, whose bio claimed to be "an American freelance writer," had social media accounts across tech platforms including Elon Musk's X and Meta-owned Instagram. X's transparency information showed the account was connected via a "West Asia android app" and Instagram's transparency information showed the account was based in Iran, according to screenshots provided by OpenAI. Both accounts appeared to be suspended.

Read more of this story at Slashdot.

10 Oct 2026 6:34pm GMT

09 Oct 2026

feedArs Technica

Neanderthal wooden tools from Spain found preserved in stone

Dissolved rock precipitated around the tools, which then decayed.

09 Oct 2026 10:34pm GMT

Ukraine’s drones knock out AI data center belonging to "Russia’s Google"

One damaged data center has supercomputers used for training Yandex's AI model.

09 Oct 2026 10:04pm GMT

A Cray-1 supercomputer replica from 30 "obsolete" Mac Minis

Stylish upcycling, with a retro flare, at Spain's Museo de Historia de la Computación.

09 Oct 2026 9:51pm GMT

08 Oct 2026

feedOSnews

Inside the Windows I/O Manager: deep dive into how read I/O requests are initialized

In this article. I am going to explain the different steps the I/O manager follows when initializing an I/O operation starting from determining the right target, choosing the right path and finally sending the request to be processed by the right drivers. To make it easier I choose to focus on read requests only since the major steps are common by all types of requests. ↫ Win-Ware A very in-depth look at Windows' I/O Manager.

08 Oct 2026 10:09pm GMT

A minimal kernel in Swift, running in QEMU

At OSNews, we love us a hobby operating system project. I started a small experiment: writing a very basic kernel in Swift, and running on QEMU. The goal is obviously not to replace Linux or any other popular kernel, but just to have fun and understand what is required to make a program run without an operating system underneath it. Actually I made a similar experiment years before with arOS 10 years ago. For the moment, the kernel does only one thing: it prints a message through QEMU and then waits forever, which is enough for a first deep dive. ↫ Carette Antonin This is effectively a "hello world" kernel, as it doesn't actually do much else at this point. Still, there's a ton of details in the article for the aspiring kernel developers among you.

08 Oct 2026 10:05pm GMT

feedPlanet Arch Linux

Writing parsers is hard

This is a story of how we got from something like this: Failed to deserialize BUILDINFO file: Parser failed with the following error: unknown ^ invalid makepkg build environment option expected `buildflags`, `ccache`, `check`, `color`, `distcc`, `sign`, `makeflags` To this: When the ALPM project started, the goal was fairly simple: Better tooling to interact with the low-level plumbing of Arch Linux Package Management (ALPM). This meant binaries to read/write individual file types, better error messages, extensive specifications and of course exports to common dataformats like JSON. The thing is, although some of us already had experience with low-level dataframe parsing, …

08 Oct 2026 12:00am GMT

07 Oct 2026

feedOSnews

Microsoft is overhauling and redesigning search in Windows, and it seems nice?

Whenever Microsoft starts messing with something like the search function in Windows, a lot of people are going to be holding their breath and expecting the worst. Well, get ready, because they're redesigning the whole thing. In July, we shared how we are improving the Windows Search Box with less clutter and more control. We introduced a calmer home screen, removed promotional content from web results, and gave you more choice over whether web and Microsoft Store suggestions appear. Today, we're carrying those investments forward with a new Windows Search experience built on WinUI 3. This modern foundation makes Windows Search faster and more efficient with resources, while delivering an even more streamlined and focused design. ↫ Anshul Rawat at the Windows Blogs The company claims this new version of search is faster and uses less memory, which, if true, are very welcome improvements. It's also just a single column of results now, and they're adding inline previews for things like weather and files on your machine, as well as for answers to all kinds of queries you might normally go to an online search engine for. You can now also use search to perform all kinds of tasks in Windows, like turning on dark mode, managing windows, and so on. All of this can be done using relatively natural language, and Microsoft claims they've implemented better detection of typing errors and synonyms, which is quite welcome. Weirdly enough, though, it's not yet integrated into the Start menu, since it's a preview just for testers, but that's something they're working on for future releases. Judging by the videos and screenshots, I'm actually kind of positively surprised. This looks quite decent and nice, and if the promised performance improvements actually materialise, this may actually be an upgrade to search worth looking forward to. Of course, this is still Microsoft, so it's just as likely they'll screw up somewhere between now and when this goes live to regular users. Still, I think it looks decent.

07 Oct 2026 11:47pm GMT

09 Aug 2026

feedPlanet Arch Linux

On scripts and hooks

Over the last few weeks, we have been doing research on the integration of our official distribution packages when installed on a target system. In this context we have been looking at the current uses of alpm-install-scriptlet(5) files and alpm-hooks(5) in around 120 package source repositories (alpm-source-repo(7)) to better understand the underlying functionality and use-cases these two integrations offer and target. In this article we are going to look at how these two systems work, how Arch Linux is currently using them and attempt to provide suggestions for when to use which. Learning about alpm-hooks(5) and alpm-install-scriptlet(5) files …

09 Aug 2026 12:00am GMT

01 Jun 2026

feedPlanet Arch Linux

Today is my first day at JetBrains

Good morning from JetBrains Berlin office!

01 Jun 2026 12:00am GMT