2026-04-28 08:51:23
Starlette, an open-source Python framework underpinning FastAPI, has a vulnerability, called BadHost, that can allow hackers to bypass authorization (Dan Goodin/Ars Technica)
https://arstechnica.com/information-te
Open source isn’t free. We’re just not paying for it: Who maintains the maintainers?
A lot of things don’t add up in the world of software. The skills gap remains stubbornly wide, with IT and data skills the hardest to recruit for five consecutive years. Yet, at the same time, entry level roles are declining as employers redeploy existing employees rather than hiring new ones.
🧑💻
I'm trying to build a fork if Ghidra, and depending on what version of Gradle I use, I get different errors.
Using the minimum version gives me this:
https://discuss.gradle.org/t/could-not-open-cp-init-generic-class-cache-for-in…
Keine Alterskontrolle für Linux
Gesetze, die eine Altersverifikation in Betriebssystemen vorsehen, nehmen zumindest in Kalifornien und Colorado wohl Open-Source aus.
https://www.heise.de/news/Keine-Alterskont…
This has been on my mind for *weeks*. I've been saying for a long time that it's possible to have an AI that only uses consensually-gathered content, is open source open weights, runs on your own machine, and is designed to empower creators instead of exploit them. Well, we've finally got one. https://www.
#superproductivity app is great. There aren't many apps I can run on my locked down computer at work. But this one is possible to sync via webdav so I installed a minimal webdav just to syncronize the json and md file the app generates. It work flawlessly! I have finally found a way to take my todo's between work and home.
Age makes remembering things more and more tr…
OpenAI releases Symphony, an open-source spec for agent orchestration that turns a project-management board like Linear into a control plane for coding agents (OpenAI)
https://openai.com/index/open-source-codex-orchestration-symphony
Wie informieren Solawis ihre Mitglieder digital über den Inhalt und die Verwendung des Ernteanteils?
Wie können Ernteteilende ihren Anteil online anpassen oder pausieren?
Wir stellen beim Online-Stammtisch im Juni Open Source Web-Apps vor, die Solawis nutzen können.
🗓️ 17.06., 19:30 Uhr | ohne Anmeldung
Open source has become critical digital infrastructure over the past 25 years, but its future depends on human resilience as much as code. Contributor burnout, funding gaps, and new regulations are real challenges, and Ruth has spent nearly two decades at the heart of open source communities working through exactly these kinds of problems. It's a session to look forward to!
Join us for Berlin Buzzwords on June 7-9 at Kulturbrauerei or online. Get your tickets! https://2026.berlinbuzzwords.de/
Since his first years as a top player, Jannik Sinner has long had one major weakness.
The hotter it is, the more vulnerable he becomes.
It nearly toppled him at January’s Australian Open, before Novak Djokovic did the job instead.
On Thursday, with temperatures climbing toward the 90s at Roland Garros, Sinner could not endure.
In the second round of the French Open, the world No. 1 fell victim to Juan Manuel Cerúndolo of Argentina, the world No. 56.
He grew dizzy…
I like to think this is due to the single email I sent to my state representative.
https://ostechnix.com/colorado-california-age-verification-law-open-source-exempt/
For the #ttrpg bubble
Oh, did I even tell you that I've put the scripts I'm using for my TranscriptOMatic #roleplaying session transcription proof-of-concept into a Git repository?
👥 This isn't just open source for show. Nearly 1M developers told the #Warp team: "If you open this up, we will help you build it." Five years after the initial preview — and with a working business model in place — they finally made it happen. #opensource
OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s MythoOpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos
https://www.wired.com/story/openai-launche
🇺🇦 #NowPlaying on BBCRadio3's #TheEarlyMusicShow
George Frideric Handel, Crispian Steele‐Perkins, James Bowman & The King's Consort:
🎵 Eternal Source of Light Divine Ode for the Birthday of Queen Anne, HWV.74]
https://open.spotify.com/track/0drHxdDHQr20RWySE9TM7I
Don’t Do Team Meetings
Regular team meetings are often treated as a default part of work. They are seen as a sign of coordination, alignment, and healthy communication. In practice, they often reveal the opposite.
A recurring team meeting where everyone goes around the room to explain what they did last week is usually not a good use of time. It turns communication into a performance instead of a real exchange of useful information. If the team needs a formal meeting just to lear…
Xiaomi open sources MiMo-V2.5 and MiMo-V2.5-Pro under the MIT License, saying both models are among the most efficient available for agentic "claw" tasks (Carl Franzen/VentureBeat)
https://venturebeat.com/ai/open-source…
What if we're making the wrong bet about progress?
Just watched someone crack open a million-year-old fossil like it was nothing. Made me think: we open ancient things believing we'll get the most value NOW. Not later.
Same with AI. We're betting progress will speed up AND slow down at the same time.
Weird, right?
New post explores why we value personal forever but trade away our collective future for almost nothing.
Read more: [link]
Fortune: #DeepSeek unveils V4 model, with rock-bottom prices and close integration with Huawei’s chips https://fortune.com/2026/04/24/deepseek-v4-ai-model-price-perfor…
RE: https://dice.camp/@realms/116459545804565917
I'd argue that "AI"-based development creates a bigger attack surface on closed source/proprietary software than open source software:
1. It's more likely that internal software development uses LLMs as they're most affordable to companies; leaving them more vulnerable to prompt injection and other types of attacks targeting LLM use.
2. It's more likely that internal commits aren't vetted as much (or even purely vibe-coded) as ones in open source projects.
3. It's more likely that attacks on open source projects are discovered quicker.
Also a reminder that the "Mythos" thing—like all the other doomerist things coming out of "AI" companies—is a marketing stunt to get Anthropic free press coverage.
RE: https://mastodon.social/@hyc/116816916444068291
This entirely unnecessary NDA culture has been commercial poison for me for the past 15 years and also a huge problem for the open source projects themselves. NDAs are a legalese subversion of open so…
from my link log —
Gecko: a fast GLR parser with automatic syntax error recovery.
https://vnmakarov.github.io/parsing/compilers/c/open-source/2026/04/22/gecko-glr.html
saved 2026-04-23
Insurance tech startup Corgi denies accusations that it used Papermark's open source software code to develop its software and present it as its own (Julie Bort/TechCrunch)
https://techcrunch.com/2026/06/26/corg
➡️ Scrapy - Open-source framework for efficient web scraping and data extraction
#bookmarks
«Zum 45. Geburtstag — Microsoft stellt MS-DOS 1.0 als #OpenSource bereit:
Zum 45. Jahrestag des Betriebssystems hat Microsoft den Quellcode der allerersten MS-DOS-Version für den #IBM PC freigegeben. Dieses wurde zum Zeitpunkt seines Erscheinens offiziell noch als 86-DOS 1.00 bezeichnet und
Occasionally I get asked why I don't use so-called permissive licenses like BSD or MIT.
These are free software licenses,
but they do not require that forked versions of the code be free and open source software.
In other words, you can take something written with a BSD or MIT license,
put it in the next version of Windows and no one will ever know.
If you did that with GPL code, you'd be in for big legal trouble if found out.
What I don't u…
No idea if this looks reasonable, but it's a start. objdump from Synopsys' open source toolchains looks similar.
Ref:
https://foss-for-synopsys-dwc-arc-processors.github.io/documentation/2024.06/toolchain/
Addendum: also r…
Fiktives Vertriebsgespräch eines Dienstleisters für $OPEN_SOURCE: "Sie müssen wissen, Herr $KUNDE, bei uns arbeitet einer der drei Haupt-Entwickler der Software. Wissen und Support sozusagen aus erster Hand." – "Schön und gut. Aber wenn ich $CLOSED_SOURCE beim $HERSTELLER kaufe, dann arbeiten ALLE Entwickler da, nicht nur einer der Haupt-Entwickler." #justthinkin
#Zürich hat geprüft, ob #OpenDesk #Microsoft365 in der Verwaltung ersetzen kann.
Das Ergebnis: Für viele Büroaufgaben reicht die Open-Source-Lösung bereits aus, etwa bei Mail, Kalender, …
We're beyond excited to announce that @suehle, Director of Open Source at SAS and President of the Apache Software Foundation, is joining #bbuzz26 as the keynote speaker!
Learn more on our blog post: https://2026.berlinbuzzwords.de/2026/05/13/ruth-suehle-to-hold-keynote/
EOLE Evento europeo sul diritto all'open source e al software libero. Workshop di apertura online domani 25 giugno 2026 (dalle 15:00 alle 17:30 CEST)
L'Europa ha riscoperto la "sovranitŠ" attraverso un'ondata di nuove regolamentazioni - Legge sulla resilienza informatica, Legge sull'IA, gare d'appalto per la sovranitŠ del cloud. EOLE 2026 adotta un punto di partenza opposto: il Software Libero, l'Open Source e l'IA aperta perseguono l'autonomia…
My neurologist advised that I should try EEG Neurofeedback. Unfortunately public health insurance doesn't cover it.
Well, I'm just going to DIY it. I just ordered an open source Neurofeedback device with some electrodes.
https://www.olimex.com/Products/EEG/OpenEE
This AI Tool Rips Off Open Source Software Without Violating Copyright https://www.404media.co/this-ai-tool-rips-off-open-source-software-without-violating-copyright/
🇺🇦 #NowPlaying on KEXP's #VarietyMix
Jump Source ft. Loukeman:
🎵 Affect
#JumpSourceftLoukeman
https://jumpsource.bandcamp.com/track/affect-ft-loukeman
https://open.spotify.com/track/2Qd5NnEFHNh1qAeiPenjnu
{tesseract} allows you to read text from images https://docs.ropensci.org/tesseract/ it can also be combined with {magick} https://ropen…
https://open-source-wettbewerb.de/
> das Bundesministerium für Digitales und Staatsmodernisierung übernimmt erneut die Schirmherrschaft für den Open Source Wettbewerb.
> Der Wettbewerb zeichnet Projekte aus, die digitale Verwaltungsprozesse verbessern, die Zusammenarbeit in der Verwaltung …
Einige der zuletzt hier besonders häufig geteilten #News:
Bund in der Abhängigkeitsfalle: Kostenexplosion bei Microsoft-Lizenzen
RTP-LLM: High-Performance Alibaba LLM Inference Engine
Boyu Tan, Jiarui Guo, Zongwei Lv, Hanbo Sun, Tong Yang, Kan Liu, Xinfei Shi, Zetao Hu, Yaxin Yu, Chi Zhang, Jianning Zhang, Xi Yang, Wei Zhang, Bo Cai, Silu Zhou, Xiyu Wang, Na He, Yinghao Yu, Wending Bao, Guiyang Huang, Yuxing Yuan, Juncheng Yin, Nan Wang, Lin Yang, Zechao Zhang, Lu Chen, Guoding Li, Tao Lan, Lin Qu
https://arxiv.org/abs/2605.29639 https://arxiv.org/pdf/2605.29639 https://arxiv.org/html/2605.29639
arXiv:2605.29639v1 Announce Type: new
Abstract: Large Language Models (LLMs) have revolutionized AI applications, but deploying them at scale presents significant challenges. We present RTP-LLM, a high-performance inference engine for industrial-scale LLM deployment, successfully deployed across Alibaba Group serving over 100 million users. RTP-LLM addresses fundamental bottlenecks through integrated design. It optimizes model loading via file-order-driven I/O and parallel I/O-communication overlapping. The Prefill-Decode Disaggregation architecture decouples compute-intensive prefill from memory-bound decode phases, combined with hierarchical multi-tiered KV cache management enabling efficient cache reuse. In addition, RTP-LLM incorporates modular speculative decoding supporting multiple algorithms, adaptive KV cache quantization, and decoupled multimodal processing, with support for multi-level parallelism.
Comprehensive evaluations across diverse model architectures (8B-235B parameters) have been conducted, where both controlled benchmarks and real production workloads are used. The results demonstrate RTP-LLM's superior performance against vLLM and SGLang: 4.7x-6.3x model loading speedup, 35-37% TTFT P95 latency reduction with 215% cache reuse improvement in production traffic scheduling, 1.12x-2.48x and 1.86x-2.52x throughput improvements in speculative decoding and multimodal inference, respectively, and 35-40% batch latency reduction with 1.9x-3.0x TTFT improvement in quantized inference. RTP-LLM's production-proven architecture and open-source availability make it a comprehensive solution for industrial LLM deployment.
toXiv_bot_toot
from my link log —
Open access to standards documents.
https://discourse.llvm.org/t/rfc-open-access-to-standards-documents/90856
saved 2026-05-21
On May 26, 2026, at 14:00 UTC, the CrowdStrike Counter Adversary Operations team executed a coordinated takedown of the Glassworm botnet, a global threat targeting software developers through the open-source supply chain.
https://www.crowdstrike.com/en-us/blog/ins…
No puede haber una IA de código abierto si todas sus partes no son de código abierto, y eso significa que también deben de ser accesibles los datos utilizados para entrenarla https://opensource.org/ai/open-source-ai-definition
Are they right? 🤔
"Euro-Office defaults to the fully proprietary OOXML document format, developed and controlled solely by Microsoft. This makes it a de facto ally of Microsoft in its content lock-in strategy, with control remaining firmly in Redmond and far from Europe."
https://blog.do…
OpenPINT: Open-source Planning for Isoeffective Nuclear Treatments in BNCT research
Ian Postuma, Sara J. Gonz\'alez, Setareh Fatemi, Cristina Pezzi, Carolina Ruzzon, Oreste Nicrosini, Valerio Vercesi, Silva Bortolussi
https://arxiv.org/abs/2606.21476 https://arxiv.org/pdf/2606.21476 https://arxiv.org/html/2606.21476
arXiv:2606.21476v1 Announce Type: new
Abstract: Objective: Present OpenPINT (Open-source Planning for Isoeffective Nuclear Treatments), an open-source treatment planning system for nuclear therapies that integrates Monte Carlo dose calculations with modular dosimetric and radiobiological models for photon-isoeffective dose evaluation.
Approach: We describe the software architecture, implementation choices, and data flow from segmented geometry and source configuration to NIfTI dose outputs. We define BNCT-relevant dosimetric metrics and evaluate the workflow with reproducible analytic and voxelized cylindrical-phantom benchmarks, supplemented by a geometric patient-positioning example.
Main results: The module provides a reproducible and scriptable path for generating MCNP-ready inputs, extracting component-wise BNCT dose maps, and computing analysis-ready outputs for quality checks and decision support. Fine-resolution voxelized configurations reproduced the 1 mm analytic reference within 0.13% for the brain-limited irradiation-time endpoint, whereas the full voxelized sweep exposed deviations up to 4.42% in coarse 8--10 mm configurations. Patient-wide gamma pass rates were at least 99.60% for the evaluated mesh/interpolation cases, while low-dose DVH-tail quantities remained sensitive to boundary discretization.
Significance: This first paper isolates and validates the simulation-preparation and dosimetric-analysis core of an open-source BNCT treatment-planning platform. It establishes a foundation for subsequent work on optimization, biological weighting, and clinical workflow integration.
toXiv_bot_toot
OpenAI unveils an updated GPT-5.5-Cyber model, launches the Patch the Planet initiative in partnership with Trail of Bits to fix open source bugs, and more (Lily Hay Newman/Wired)
https://www.wired.com/story/openai-launche
I like to think this is due to the single email I sent to my state representative.
https://ostechnix.com/colorado-california-age-verification-law-open-source-exempt/
The Irish Council for Civil Liberties (#ICCL) has released an open source tool designed to reduce LLM hallucinations.
If my 15-year-old PC had a GPU I'd be tempted to give it a try.
https://www.
Una lettera aperta agli utenti di suite per ufficio, poco prima dell'annuncio di Euro-Office
«Negli ultimi giorni avrete letto diversi articoli che annunciano l'arrivo di EuroOffice, presentato come la prima suite per ufficio open source sviluppata in Europa. Ci sentiamo in dovere – seppur a malincuore, poiché l'open source dovrebbe basarsi sulla trasparenza e non sull'inganno – di correggere questa affermazione. La prima suite per ufficio open source sviluppata in Euro…
Einige der zuletzt hier besonders häufig geteilten #News:
Bund in der Abhängigkeitsfalle: Kostenexplosion bei Microsoft-Lizenzen
How tech companies are using open source initiatives to achieve critical strategic goals and how such efforts are reshaping industries like AI, AVs, and more (Bill Gurley/Bill's Substack)
https://p3institute.substack.com/p/from-open-source-software-to-open…
from my link log —
Can we trust Microsoft with Open Source?
https://dusted.codes/can-we-trust-microsoft-with-open-source
saved 2021-10-23
🇺🇦 #NowPlaying on KEXP's #MidnightInAPerfectWorld
Jump Source ft. POiSON GiRL FRiEND:
🎵 Close
#JumpSourceftPOiSONGiRLFRiEND
https://jumpsource.bandcamp.com/track/close-ft-poison-girl-friend
https://open.spotify.com/track/6CVubsu8aHYG5QztcKmsLz
«#Zürich will sich von teurer #Microsoft-Software lösen – doch da gibt es ein Problem:
Die Zürcher Stadtverwaltung soll sich aus dem #M365-Würgegriff lösen und auf eine europäische
Einige der zuletzt hier besonders häufig geteilten #News:
Stringman: Fest montierter Open-Source-Roboter räumt einzelne Räume auf
Some organizations are doing panicky things over Mythos.
NHS Goes To War Against Open Source
https://shkspr.mobi/blog/2026/05/nhs-goes-to-war-against-open-source/
Microsoft has locked the lead developers of two prominent open source security projects out of their accounts.
https://www.computing.co.uk/news/2026/microsoft-locks-open-so…
Datacurve releases the DeepSWE coding benchmark, a 113-task test across 91 open-source repositories and five languages, and says GPT-5.5 is the leader at 70% (Michael Nuñez/VentureBeat)
https://venturebeat.com/technology/dee…
«Ladybird-Browser stoppt öffentliche Code-Beiträge:
Wegen KI-generierter Beiträge schließt das Open-Source-Projekt Ladybird seine öffentlichen Pull-Requests, um die Sicherheit des Browsers zu garantieren.»
Da sehen wir wie KI das Gegenteil von sicherer Produktion ist, wenn es blind als unstrukturiertes Pull-Request eingesetzt wird.
🌐
How hacker group TeamPCP exploited the open source trust model and distribution method to compromise and inject malware into over 1,000 software packages (Matt Kapko/CyberScoop)
https://cyberscoop.com/teampcp-breaks-open-source-software-trust-model/
«AI Slop oder besserer Code — GCC-Arbeitsgruppe für KI-Richtlinien gestartet:
Die Working Group for GCC AI Policy soll festlegen, inwiefern Contributors KI-Tools beim Entwickeln der GNU Compiler Collection nutzen dürfen.»
Da bin ich mal gespannt wie sich das auswirkt und ob dadurch die IT-Sicherheit im Open-Source Bereich wirklich erhöht wird.
🧑💻
Don't miss today's Metacurity for the most critical cybersecurity developments you might have missed over the weekend, including
--White House opens backchannel to Anthropic as Pentagon fight simmers,
--Anthropic gave NSA access to Mythos Preview,
--Anthropic's donation to open source developers highlights how under-sourced they are,
--Asian regulators urge banks to use Mythos,
--LayerZero-powered cross-chain bridge Kelp DAO lost $292m in DPRK exploit…
Cal.com, which provides scheduling software, is moving its core open-source codebase to a closed repository, citing the dangers of AI hacking its open code (Steven Vaughan-Nichols/ZDNET)
https://www.zdnet.com/article/ai-security-worries-force-company-t…
After EV maker Fisker's collapse, ~4,000 car owners formed a nonprofit to keep their cars working by reverse-engineering software and building open-source tools (Fred Lambert/Electrek)
https://electrek.co/2026/05/16/fisker-ocean-open-source-ev-story-aft…
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
Münchens IT-Wende: Open Source ist für die neue Koalition der Normalfall
Meta: Neue KI-Modelle sollen teils Open-Source werden
Meta plant, neue KI-Modelle zu veröffentlichen. Die sollen in Teilen unter Open-Source-Lizenzen herausgegeben werden.
https://www.heis…
Moonshot introduces Kimi K2.6, an open-weight model that it says shows strong improvements in long-horizon coding tasks, available under a modified MIT License (Kimi AI)
https://www.kimi.com/blog/kimi-k2-6
As the US House probes Airbnb's use of Chinese AI models, CEO Brian Chesky says the company is not sharing data with Chinese firms and uses open-source models (Natalie Lung/Bloomberg)
https://www.bloomberg.com/news/articles/20
Mirendil, founded by former Anthropic researchers and seeking to build self-improving AI for open-source developers, raised a $200M seed at a $1B valuation (Tina Li/Wall Street Journal)
https://www.wsj.com/tech/ai…
OpenDesk kann vieles, aber halt nicht alles. Das ist das Fazit einer Studie aus Zürich, die die Open-Source-Lösung als Microsoft 365-Alternative unter die Lupe genommen hat. 🔍
Zum Artikel: https://heise.de/-11303065?wt_mc=sm.red.…
Sources: Meta is preparing to release the first AI models developed under Alexandr Wang, with plans to offer versions of those models via an open source license (Ina Fried/Axios)
https://www.axios.com/2026/04/06/meta-open-source-ai-models
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Einige der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Anthropic commits up to $100M in usage credits for Project Glasswing, along with $4M in direct donations to open-source security organizations (Greg Otto/CyberScoop)
https://cyberscoop.com/project-glasswing-anthropic-ai-open-source-software-vulnera…
Europa hat jetzt sein eigenes Office – und das ist auch noch Open Source! 🚀
Zum Artikel: https://heise.de/-11320254?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
Servus, freie Software! 🥨 In München weht ein neuer Wind durchs Rathaus – und der riecht verdächtig nach Open Source.
Zum Artikel: https://heise.de/-11292444?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_sou…