2026-05-27 16:50:55
Starlette, an open-source Python framework underpinning FastAPI, has a vulnerability, called BadHost, that can allow hackers to bypass authorization (Dan Goodin/Ars Technica)
https://arstechnica.com/information-te
Starlette, an open-source Python framework underpinning FastAPI, has a vulnerability, called BadHost, that can allow hackers to bypass authorization (Dan Goodin/Ars Technica)
https://arstechnica.com/information-te
Keine Alterskontrolle für Linux
Gesetze, die eine Altersverifikation in Betriebssystemen vorsehen, nehmen zumindest in Kalifornien und Colorado wohl Open-Source aus.
https://www.heise.de/news/Keine-Alterskont…
I like to think this is due to the single email I sent to my state representative.
https://ostechnix.com/colorado-california-age-verification-law-open-source-exempt/
Insurance tech startup Corgi denies accusations that it used Papermark's open source software code to develop its software and present it as its own (Julie Bort/TechCrunch)
https://techcrunch.com/2026/06/26/corg
#superproductivity app is great. There aren't many apps I can run on my locked down computer at work. But this one is possible to sync via webdav so I installed a minimal webdav just to syncronize the json and md file the app generates. It work flawlessly! I have finally found a way to take my todo's between work and home.
Age makes remembering things more and more tr…
Wie informieren Solawis ihre Mitglieder digital über den Inhalt und die Verwendung des Ernteanteils?
Wie können Ernteteilende ihren Anteil online anpassen oder pausieren?
Wir stellen beim Online-Stammtisch im Juni Open Source Web-Apps vor, die Solawis nutzen können.
🗓️ 17.06., 19:30 Uhr | ohne Anmeldung
Fortune: #DeepSeek unveils V4 model, with rock-bottom prices and close integration with Huawei’s chips https://fortune.com/2026/04/24/deepseek-v4-ai-model-price-perfor…
RE: https://mastodon.social/@hyc/116816916444068291
This entirely unnecessary NDA culture has been commercial poison for me for the past 15 years and also a huge problem for the open source projects themselves. NDAs are a legalese subversion of open so…
Fiktives Vertriebsgespräch eines Dienstleisters für $OPEN_SOURCE: "Sie müssen wissen, Herr $KUNDE, bei uns arbeitet einer der drei Haupt-Entwickler der Software. Wissen und Support sozusagen aus erster Hand." – "Schön und gut. Aber wenn ich $CLOSED_SOURCE beim $HERSTELLER kaufe, dann arbeiten ALLE Entwickler da, nicht nur einer der Haupt-Entwickler." #justthinkin
RE: https://dice.camp/@realms/116459545804565917
I'd argue that "AI"-based development creates a bigger attack surface on closed source/proprietary software than open source software:
1. It's more likely that internal software development uses LLMs as they're most affordable to companies; leaving them more vulnerable to prompt injection and other types of attacks targeting LLM use.
2. It's more likely that internal commits aren't vetted as much (or even purely vibe-coded) as ones in open source projects.
3. It's more likely that attacks on open source projects are discovered quicker.
Also a reminder that the "Mythos" thing—like all the other doomerist things coming out of "AI" companies—is a marketing stunt to get Anthropic free press coverage.
OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s MythoOpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos
https://www.wired.com/story/openai-launche
OpenAI releases Symphony, an open-source spec for agent orchestration that turns a project-management board like Linear into a control plane for coding agents (OpenAI)
https://openai.com/index/open-source-codex-orchestration-symphony
from my link log —
Gecko: a fast GLR parser with automatic syntax error recovery.
https://vnmakarov.github.io/parsing/compilers/c/open-source/2026/04/22/gecko-glr.html
saved 2026-04-23
Don’t Do Team Meetings
Regular team meetings are often treated as a default part of work. They are seen as a sign of coordination, alignment, and healthy communication. In practice, they often reveal the opposite.
A recurring team meeting where everyone goes around the room to explain what they did last week is usually not a good use of time. It turns communication into a performance instead of a real exchange of useful information. If the team needs a formal meeting just to lear…
🇺🇦 #NowPlaying on KEXP's #VarietyMix
Jump Source ft. Loukeman:
🎵 Affect
#JumpSourceftLoukeman
https://jumpsource.bandcamp.com/track/affect-ft-loukeman
https://open.spotify.com/track/2Qd5NnEFHNh1qAeiPenjnu
{tesseract} allows you to read text from images https://docs.ropensci.org/tesseract/ it can also be combined with {magick} https://ropen…
#Zürich hat geprüft, ob #OpenDesk #Microsoft365 in der Verwaltung ersetzen kann.
Das Ergebnis: Für viele Büroaufgaben reicht die Open-Source-Lösung bereits aus, etwa bei Mail, Kalender, …
➡️ Scrapy - Open-source framework for efficient web scraping and data extraction
#bookmarks
Xiaomi open sources MiMo-V2.5 and MiMo-V2.5-Pro under the MIT License, saying both models are among the most efficient available for agentic "claw" tasks (Carl Franzen/VentureBeat)
https://venturebeat.com/ai/open-source…
«#Zürich will sich von teurer #Microsoft-Software lösen – doch da gibt es ein Problem:
Die Zürcher Stadtverwaltung soll sich aus dem #M365-Würgegriff lösen und auf eine europäische
On May 26, 2026, at 14:00 UTC, the CrowdStrike Counter Adversary Operations team executed a coordinated takedown of the Glassworm botnet, a global threat targeting software developers through the open-source supply chain.
https://www.crowdstrike.com/en-us/blog/ins…
EOLE Evento europeo sul diritto all'open source e al software libero. Workshop di apertura online domani 25 giugno 2026 (dalle 15:00 alle 17:30 CEST)
L'Europa ha riscoperto la "sovranitŠ" attraverso un'ondata di nuove regolamentazioni - Legge sulla resilienza informatica, Legge sull'IA, gare d'appalto per la sovranitŠ del cloud. EOLE 2026 adotta un punto di partenza opposto: il Software Libero, l'Open Source e l'IA aperta perseguono l'autonomia…
This AI Tool Rips Off Open Source Software Without Violating Copyright https://www.404media.co/this-ai-tool-rips-off-open-source-software-without-violating-copyright/
Einige der zuletzt hier besonders häufig geteilten #News:
Bund in der Abhängigkeitsfalle: Kostenexplosion bei Microsoft-Lizenzen
Right, time to crank out some open source PR's out
The Irish Council for Civil Liberties (#ICCL) has released an open source tool designed to reduce LLM hallucinations.
If my 15-year-old PC had a GPU I'd be tempted to give it a try.
https://www.
My neurologist advised that I should try EEG Neurofeedback. Unfortunately public health insurance doesn't cover it.
Well, I'm just going to DIY it. I just ordered an open source Neurofeedback device with some electrodes.
https://www.olimex.com/Products/EEG/OpenEE
@… my context was:
― the The AI/ML Security Working Group.
The working group is an Open Source Security Foundation project. The OpenSSF is a project of the Linux Foundation.
If you must use extreme, inflammatory phrases such as "the beast" and "shitcan" in the future:
― be clearer about the meanings.
Cc
from my link log —
Open access to standards documents.
https://discourse.llvm.org/t/rfc-open-access-to-standards-documents/90856
saved 2026-05-21
I like to think this is due to the single email I sent to my state representative.
https://ostechnix.com/colorado-california-age-verification-law-open-source-exempt/
https://open-source-wettbewerb.de/
> das Bundesministerium für Digitales und Staatsmodernisierung übernimmt erneut die Schirmherrschaft für den Open Source Wettbewerb.
> Der Wettbewerb zeichnet Projekte aus, die digitale Verwaltungsprozesse verbessern, die Zusammenarbeit in der Verwaltung …
JAX-SCM v1.0: a modern atmospheric single-column model for boundary layer research
Maximilian Pierzyna
https://arxiv.org/abs/2605.24544 https://arxiv.org/pdf/2605.24544 https://arxiv.org/html/2605.24544
arXiv:2605.24544v1 Announce Type: new
Abstract: We present JAX-SCM v1.0, an open-source atmospheric single-column model for boundary layer research, implemented in Python using the JAX computing library. The model solves for horizontal wind, potential temperature, and specific humidity, combined with prognostic turbulent kinetic energy and turbulent statistics parameterized by the Mellor-Yamada-Nakanishi-Niino level-2.5 (MYNN-2.5) turbulence closure. We verify the implementation against three well-established benchmark cases covering neutral (turbulent Ekman layer), stable (GABLS1), and convective (Wangara Day 33) conditions. Close agreement with reference solutions is demonstrated across all regimes. By building on JAX, the model benefits from just-in-time compilation and native GPU support. While JAX-SCM is not yet fully differentiable, basing it on JAX also lays the foundation for future integration with machine learning components. The model is designed for simplicity and modularity, lowering the barrier to entry for users and developers alike.
toXiv_bot_toot
No puede haber una IA de código abierto si todas sus partes no son de código abierto, y eso significa que también deben de ser accesibles los datos utilizados para entrenarla https://opensource.org/ai/open-source-ai-definition
Are they right? 🤔
"Euro-Office defaults to the fully proprietary OOXML document format, developed and controlled solely by Microsoft. This makes it a de facto ally of Microsoft in its content lock-in strategy, with control remaining firmly in Redmond and far from Europe."
https://blog.do…
I believe that we in the US will begin to face a hard question:
We will soon, I hope, begin cleaning up the trump/maga mess.
Given that the trump/maga actors have engaged in inhumane, unlawful, and racist destruction of people and institutions I wonder about the following:
Should those people be protected by our Constitutional norms or will we want to, or need to, bypass our legal protections and procedures as we pursue punishment, disgorgement of ill gains, and compensatio…
Part 1 of a new short story by Linda Teppler is out! Free to read on Substack #writingcommunity #banskolife #writing
"PostgreSQL, MySQL, Cassandra, and other popular open source systems are not measured in and of themselves – only as part of commercial services."
What is the purpose of essentially delisting #PostgreSQL, #MySQL,
Datacurve releases the DeepSWE coding benchmark, a 113-task test across 91 open-source repositories and five languages, and says GPT-5.5 is the leader at 70% (Michael Nuñez/VentureBeat)
https://venturebeat.com/technology/dee…
«AI Slop oder besserer Code — GCC-Arbeitsgruppe für KI-Richtlinien gestartet:
Die Working Group for GCC AI Policy soll festlegen, inwiefern Contributors KI-Tools beim Entwickeln der GNU Compiler Collection nutzen dürfen.»
Da bin ich mal gespannt wie sich das auswirkt und ob dadurch die IT-Sicherheit im Open-Source Bereich wirklich erhöht wird.
🧑💻
Every modern digital technology
– from AI to quantum computing
– is based on foundational open source software building blocks.
Open source code is embedded in almost all products and services,
enabling economic growth and ensuring the resilience of our society and government.
While open source software has become the backbone of our digital infrastructure,
these essential components do not receive adequate support and investment.
Targeted and long…
IResearch is an Apache 2.0 C search engine built to live inside databases.
Andrey Abramov is joining #bbuzz26 to benchmark it against leading open-source search engines, and explore how database-native search fits modern query execution.
Learn more: https://2026.berlinbuzzwords.de/session/c-search-for-database-kernels-built-in-not-bolted-on/
Am 5. Mai gibt es wieder ein lokales "Free Software Foundation Europe"-Treffen in Wien! Komm vorbei, wenn dich die gesellschaftlichen und politischen Aspekte von Freier Software/Open Source Software interessieren und du dich mit anderen austauschen möchtest!
Wann?
Dienstag, 5. Mai 2026
Ab 18:30 Uhr gemütliches Ankommen
Um 19:00 Uhr Start
Wo?
Im @…
OpenAI unveils an updated GPT-5.5-Cyber model, launches the Patch the Planet initiative in partnership with Trail of Bits to fix open source bugs, and more (Lily Hay Newman/Wired)
https://www.wired.com/story/openai-launche
Einige der zuletzt hier besonders häufig geteilten #News:
Bund in der Abhängigkeitsfalle: Kostenexplosion bei Microsoft-Lizenzen
🇺🇦 #NowPlaying on KEXP's #MidnightInAPerfectWorld
Jump Source ft. POiSON GiRL FRiEND:
🎵 Close
#JumpSourceftPOiSONGiRLFRiEND
https://jumpsource.bandcamp.com/track/close-ft-poison-girl-friend
https://open.spotify.com/track/6CVubsu8aHYG5QztcKmsLz
Una lettera aperta agli utenti di suite per ufficio, poco prima dell'annuncio di Euro-Office
«Negli ultimi giorni avrete letto diversi articoli che annunciano l'arrivo di EuroOffice, presentato come la prima suite per ufficio open source sviluppata in Europa. Ci sentiamo in dovere – seppur a malincuore, poiché l'open source dovrebbe basarsi sulla trasparenza e non sull'inganno – di correggere questa affermazione. La prima suite per ufficio open source sviluppata in Euro…
«Ladybird-Browser stoppt öffentliche Code-Beiträge:
Wegen KI-generierter Beiträge schließt das Open-Source-Projekt Ladybird seine öffentlichen Pull-Requests, um die Sicherheit des Browsers zu garantieren.»
Da sehen wir wie KI das Gegenteil von sicherer Produktion ist, wenn es blind als unstrukturiertes Pull-Request eingesetzt wird.
🌐
from my link log —
Can we trust Microsoft with Open Source?
https://dusted.codes/can-we-trust-microsoft-with-open-source
saved 2021-10-23
How tech companies are using open source initiatives to achieve critical strategic goals and how such efforts are reshaping industries like AI, AVs, and more (Bill Gurley/Bill's Substack)
https://p3institute.substack.com/p/from-open-source-software-to-open…
Einige der zuletzt hier besonders häufig geteilten #News:
Stringman: Fest montierter Open-Source-Roboter räumt einzelne Räume auf
Just over a week after Mosaic 1.0 was released, CERN gifted the Web to the world as open source software. As of 30 April 1993, the still relatively new Internet communications platform was suddenly free for anyone to use, with no strings attached.
https://cybercultural.com/p/1993-mosai
Some organizations are doing panicky things over Mythos.
NHS Goes To War Against Open Source
https://shkspr.mobi/blog/2026/05/nhs-goes-to-war-against-open-source/
Microsoft has locked the lead developers of two prominent open source security projects out of their accounts.
https://www.computing.co.uk/news/2026/microsoft-locks-open-so…
How hacker group TeamPCP exploited the open source trust model and distribution method to compromise and inject malware into over 1,000 software packages (Matt Kapko/CyberScoop)
https://cyberscoop.com/teampcp-breaks-open-source-software-trust-model/
After EV maker Fisker's collapse, ~4,000 car owners formed a nonprofit to keep their cars working by reverse-engineering software and building open-source tools (Fred Lambert/Electrek)
https://electrek.co/2026/05/16/fisker-ocean-open-source-ev-story-aft…
Don't miss today's Metacurity for the most critical cybersecurity developments you might have missed over the weekend, including
--White House opens backchannel to Anthropic as Pentagon fight simmers,
--Anthropic gave NSA access to Mythos Preview,
--Anthropic's donation to open source developers highlights how under-sourced they are,
--Asian regulators urge banks to use Mythos,
--LayerZero-powered cross-chain bridge Kelp DAO lost $292m in DPRK exploit…
Mirendil, founded by former Anthropic researchers and seeking to build self-improving AI for open-source developers, raised a $200M seed at a $1B valuation (Tina Li/Wall Street Journal)
https://www.wsj.com/tech/ai…
FediSuite: Open-Source Social-Media-Management fürs Fediverse — Alle deine Fediverse-Accounts an einem Ort.
FediSuite ist eine kostenlose Open-Source-Plattform zum Planen von Beiträgen, automatischen Aufteilen langer Posts in Threads, Verwalten von Benachrichtigungen und dem Handling mehrerer Accounts auf 14 Fediverse-Plattformen — @…,
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
Münchens IT-Wende: Open Source ist für die neue Koalition der Normalfall
Cal.com, which provides scheduling software, is moving its core open-source codebase to a closed repository, citing the dangers of AI hacking its open code (Steven Vaughan-Nichols/ZDNET)
https://www.zdnet.com/article/ai-security-worries-force-company-t…
As the US House probes Airbnb's use of Chinese AI models, CEO Brian Chesky says the company is not sharing data with Chinese firms and uses open-source models (Natalie Lung/Bloomberg)
https://www.bloomberg.com/news/articles/20
Meta: Neue KI-Modelle sollen teils Open-Source werden
Meta plant, neue KI-Modelle zu veröffentlichen. Die sollen in Teilen unter Open-Source-Lizenzen herausgegeben werden.
https://www.heis…
Moonshot introduces Kimi K2.6, an open-weight model that it says shows strong improvements in long-horizon coding tasks, available under a modified MIT License (Kimi AI)
https://www.kimi.com/blog/kimi-k2-6
OpenDesk kann vieles, aber halt nicht alles. Das ist das Fazit einer Studie aus Zürich, die die Open-Source-Lösung als Microsoft 365-Alternative unter die Lupe genommen hat. 🔍
Zum Artikel: https://heise.de/-11303065?wt_mc=sm.red.…
Sources: Meta is preparing to release the first AI models developed under Alexandr Wang, with plans to offer versions of those models via an open source license (Ina Fried/Axios)
https://www.axios.com/2026/04/06/meta-open-source-ai-models
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
SpaceX signs a computing deal worth up to $6.3B with Reflection AI for access to Nvidia GB300s at Colossus 2; Reflection will pay $150M per month through 2029 (Deirdre Bosa/CNBC)
https://www.cnbc.com/2026/06/22/spacex-ai-colossus-data-center-reflection.html
Einige der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Anthropic commits up to $100M in usage credits for Project Glasswing, along with $4M in direct donations to open-source security organizations (Greg Otto/CyberScoop)
https://cyberscoop.com/project-glasswing-anthropic-ai-open-source-software-vulnera…
Inference cloud startup DeepInfra raised a $107M Series B co-led by 500 Global and Georges Harik; it currently supports more than 190 open models (Mike Wheatley/SiliconANGLE)
https://siliconangle.com/2026/05/04/deepinfra-la…
Servus, freie Software! 🥨 In München weht ein neuer Wind durchs Rathaus – und der riecht verdächtig nach Open Source.
Zum Artikel: https://heise.de/-11292444?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_sou…
Europa hat jetzt sein eigenes Office – und das ist auch noch Open Source! 🚀
Zum Artikel: https://heise.de/-11320254?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon