lingo.lol is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for linguists, philologists, and other lovers of languages.

Server stats:

60
active users

#apt

1 post1 participant0 posts today

This week's Linux and FOSS news:

LINUX NEWS

Debian 13 is now in hard freeze, MIPS (MIPS64EL) architecture support dropped, RISC-V is promoted as a release architecture:
phoronix.com/news/Debian-13-Ha

Debian installer Trixie RC1 adds rescue support on Btrfs, Linux kernel 6.12, spice-vdagent is installed automatically on QEMU/KVM, Ext2 file system on PPC64EL architecture instead of Ext4, etc.:
phoronix.com/news/Debian-Insta

APT package manager 3.1 released with why/why-not commands, new solver default on Ubuntu, include/exclude options, HTTPS support for dselect, etc.:
phoronix.com/news/Debian-APT-3

KDE Plasma 6.4 will include time-of-day wallpapers, adaptive-sync disabled by default:
phoronix.com/news/KDE-Plasma-T

NixOS 25.05 released with Linux kernel 6.12 LTS and 6.14, GNOME 48, initial COSMIC support, new `nixos-rebuild build-image` sub-command, nixos-rebuild-ng, rewritten nixos-option etc.:
9to5linux.com/nixos-25-05-rele

Ubuntu 25.10 switches Chrony for Network Time Protocol (NTP) for better security:
phoronix.com/news/Ubuntu-25.10

GNOME 50 dropping X11 support causes complications for Ubuntu 26.04 LTS:
omgubuntu.co.uk/2025/05/gnome-

Tails 6.15.1 released with fixes for critical Tor browser vulnerabilities:
alternativeto.net/news/2025/5/

Wine 10.8 released with TIFF support, progress on PDB backend, boosted performance:
alternativeto.net/news/2025/5/

New Linux phone upcoming by the Divine D. project:
liliputing.com/divine-d-projec
(Hopefully it will be a relatively cheap phone to replace the aging PinePhone)

Phosh 0.47.0 released with status page for feedback quick settings, mobile data quick settings disabled when SIM is locked, bug fixes:
phosh.mobi/releases/rel-0.47.0

(FOSS news in comments)

www.phoronix.comDebian 13 "Trixie" Now In Hard Freeze: MIPS64EL Demoted, RISC-V 64-bit Promoted

An important alert from CISA today (Advisory AA25-141A) details active targeting by the Russian GRU's 85th GTsSS against Western logistics and technology companies. This cyber espionage campaign particularly focuses on entities involved in coordinating foreign assistance to Ukraine.

💡 For those in logistics, IT, or related sectors, this advisory serves as a crucial reminder:

👉 Expect persistent and sophisticated threats.
🛡️ Review your defenses against known TTPs (Tactics, Techniques, and Procedures).
🔄 Prioritize proactive threat hunting and robust monitoring.
🚨 A heightened state of vigilance is warranted.

This situation underscores the continuous evolution of state-sponsored cyber threats. What strategies are proving most effective for your organizations in defending against such advanced persistent threats? Your insights are invaluable. 👇

#CISA #Cybersecurity #APT #RussianThreats #InfoSec #security #privacy #cloud #infosec
cisa.gov/news-events/cybersecu

Cybersecurity and Infrastructure Security Agency CISARussian GRU Targeting Western Logistics Entities and Technology Companies | CISAExecutives and network defenders should recognize the elevated threat of unit 26165 targeting, increase monitoring and threat hunting for known TTPs and IOCs, and posture network defenses with a presumption of targeting.

Hackergruppen, die die IT einer Gemeinde lahmlegen, sich in das Datennetz einer Hochschule einschleusen oder Unternehmen aus bestimmten Wirtschaftszweigen mit Malware infizieren, verfolgen häufig strategische Ziele.

Da es sich bei solchen Angriffen nicht um rein opportunistische Zufallsereignisse handelt, sondern Muster erkennbar sind, lassen sich viele Attacken Angreifergruppen zuordnen, den Advanced Persistent Threats #APT.

bsi.bund.de/dok/1108344

When can we declare IP Geo location / country code blocking practically dead as a mitigation strategy?

Sure it is still useful blocking script kiddies from Iran and other low hanging fruit, but do any serious APT crews actually launch attacks from their home country anymore?

With the use of zero trust, distributed attack and delivery networks (looking at you Cloudflare), and VPN usage country blocking feels less useful than in the past.

Better late than never: The government of #France attributes a wide range of #cyberattacks dating back ten years, targeting the French-hosted 2024 Olympics, prior elections, and against entities like television networks, to Russia's GRU (#APT28), and condemns them, officially, in a statement posted to their website.

A machine-translated-to-English screenshot of the statement is shown below.

"Together with its partners, France is determined to use all the means at its disposal to anticipate, deter and respond to Russia’s malicious behaviour in cyberspace where appropriate."

Someone has to.

diplomatie.gouv.fr/fr/dossiers

🎙️✨ Here is a new Brand Story!

Guest: John Stigerwalt & Gregory Hatcher
Episode Title: No Manuals, No Shortcuts: Inside the Offensive Security Mindset at White Knight Labs

🚀 Marco Ciappelli and Sean Martin, CISSP are back — and this time, they’re chatting with the founders of White Knight Labsfor their first Brand Story with ITSPmagazine!

From learning on the field to building red teams to one of the toughest certification programs — John and Greg aren’t just playing the cybersecurity game. They’re rewriting it.

They don’t believe in cookie-cutter pen tests.
They simulate real ransomware attacks.
They write their own loaders.
And they only resell products they’ve personally tested in the wild.

🔥 Passion.
🔍 Precision.
🤝 Purpose.

🎧 Listen or watch now — and meet the team that’s raising the bar for offensive security:
📺 Video Teaser: youtu.be/VdGyPFhLAvU
👉 Full Podcast: brand-stories-podcast.simpleca

📌 Learn more about White Knight Labs on their Brand Page on ITSPmagazine:
itspmagazine.com/directory/whi

🎉 Join us in welcoming White Knight Labs to the ITSPmagazine family!
We already have three more conversations scheduled with them — you won’t want to miss what’s coming next.

Be sure to follow White Knight Labs and the Brand Stories with Sean and Marco podcast to stay connected with this exciting journey.

brand-stories-podcast.simpleca

우분투에서 snap 으로 docker 를 설치했다가 후회한 얘기

hackers.pub/@arkjun/2025/ubunt

hackers.pub · 우분투에서 snap 으로 docker 를 설치했다가 후회한 얘기우분투를 쓸때는 apt 로만 패키지 관리를 해왔는데 작년 처음 snap 을 써봤다. 작년 사내 테스트용 (물리) 서버에 우분투 24.04.1 LTS 설치하고 snap 으로 docker 설치해서 여러 모니터링 올리고 어제까지도 잘 쓰고 있었는데, 갑자기 오늘 docker ps 명령이 오류가 나서 봤더니, $ docker ps Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running? docker -D ps # 디버깅 time="2025-03-12T11:22:58+09:00" level=debug msg="otel error" error="1 errors occurred detecting resource:\n\t* conflicting Schema URL: https://opentelemetry.io/schemas/1.21.0 and https://opentelemetry.io/schemas/1.26.0" 실행도 안되고, 모든 컨테이너는 날라간 상태이고 도커또한 동작하지 않는다. 디버깅 메시지 보면 스키마 버전 충돌이라고 나온다. 자세한 원인분석을 위해 ChatGPT 의 도움을 받았더니 Docker 데몬이 OTel(OpenTelemetry)과 충돌하여, 스키마 버전(1.21.0 vs. 1.26.0)이 일치하지 않아 발생하는 문제입니다. 주로 Snap의 자동 업데이트 중, Docker의 내부 OTel 설정이 깨졌을 때 나타나는 문제입니다. snap 자동 업뎃중에 OTel 충돌로 스키마 버전 불일치 문제라고 한다. 스냅 방식 대신 apt 기반 설치가 더욱 안정적이라고 권장해주길래, (새로운 방식이라 일부러 snap 으로 선택했었는데) 다음부터는 그냥 apt 방식으로 설치하기로 했다. (docker 한정) 물론 이번에도 apt 방식으로 변경해서 설치. sudo snap remove docker sudo apt update sudo apt install -y docker.io sudo systemctl start docker sudo systemctl enable docker sudo systemctl status docker 테스트 서버 관리에 시간을 빼앗긴 후에야, 테스트 서버도 백업해 둬야겠다 싶다. 모니터링 설정이랑 빌드 설정이랑 도커 설정 다 백업해 놔야겠다.
#Ubuntu#snap#apt

Hi #Linux laptop users!

I'm curious about what you do to extend your laptop's battery life on Linux. Whether it's using tools like auto-cpufreq, using a lightweight desktop environment/tiling window manager, changing brightness settings, or just spending less time on your laptop, I want to know what works for you.

I run Debian on all my machines, so I’m interested in anything that helps with battery life for Debian and Debian-based distros.

My Laptop is a ThinkPad E14 Gen 4 with an AMD Ryzen 3 5425U CPU.

Looking forward to your suggestions!