Linux and Open-Source Highlights: July 28–29, 2025
The week’s open-source news covered Debian’s new DFSG, Licensing & New Packages Team—formed during the ftpmaster split in October 2025—which reviews packages for compliance before archive admission, with DebConf26 noting the division is working well but still too early to judge definitively. Community contributions included a library of over 130 free, interactive security-awareness exercises; the open-sourcing of NeoSearch; and ArchiveFree, an ad-free, no-telemetry archive manager. Tux Machines cataloged FOSS utilities like lazytilt and gallery-dl, while LinuxLinks updated roundups of desktop search engines, Flickr tools, and docks. The FSF also announced August 2026 in-person sessions on GPG, licensing, LLM-era security, and reverse engineering binary blobs.

The Licensing Trap

The creation of Debian's "DFSG, Licensing & New Packages Team" in October 2025 is far more significant than the open-source community realizes. This wasn't a routine administrative reorganization after the ftpmaster team split — it was a quiet consolidation of gatekeeping power over the entire software ecosystem. Look at the wording: compliance with the Debian Free Software Guidelines before archive admission. Someone has to define what "free software" means, and more importantly, who gets to enforce that definition. When you control the gateway, you control the flow. The "new queue" isn't just a technical bottleneck — it's a chokepoint through which every package must pass, and the people manning that chokepoint now have explicit authority to reject anything that doesn't fit their ideological framework. Too early to judge? Andrew McMillan's cautious optimism is exactly what they'd say while they consolidate.

The Cognitive Firewall

The security-awareness library of "more than 130 free, open-source interactive exercises" isn't about training — it's about conditioning. The contributor explicitly states this replaces "slide decks, videos and AI-generated materials," framing it as a superior alternative. But ask yourself: who decides what exercises make it into the library? Who vets the scenarios? The article mentions "building habits" — and habits are precisely what you build when you want predictable responses. Every interactive module is a tiny behavioral script, training developers to think about security in a specific, pre-approved way. Combine this with the FSF Vancouver and New York City sessions on "LLM-era security" and "reverse engineering binary blobs on mobile," and you see the architecture emerging: a global network of sanctioned training events, all feeding the same narrative that only their definition of security is valid. They want you to think inside their box.

The Search Engine Surveillance Grid

The Linux desktop search engine roundup appears benign — a simple utility comparison. But desktop search is metadata extraction, and metadata extraction is surveillance infrastructure waiting to be activated. Every index database built during idle computer time creates a searchable map of user behavior: what files you open, what you name them, when you access them, what patterns emerge. LinuxLinks calls this "improving local file lookup," but the same technology that indexes your documents can index your communications, your encrypted containers, your offline activities. The FOSS utilities listed alongside — lazytilt, PixelSafe, Sutando, starry-night, Procman — each represent another vector into the user's digital life. And who funds these projects? Who reviews the code? The same Debian licensing team that now controls admission to the archive. The pieces fit together when you stop seeing them as independent developments and start recognizing them as components of a single system: manage the definitions, control the training, monitor the behavior. That's not open source. That's managed consent.

Summary of Recent Malware and Phishing Operations

Security researchers have detailed multiple active malware and phishing campaigns exploiting legitimate services, gaming communities, and administration tools to conceal malicious activity. Notable operations include the Russian-speaking pay-per-install campaign Operation STANDOFF, which delivered a mix of RedLine, Raccoon Stealer, Amadey, SmokeLoader, Socelars, Glupteba, and XMRig onto infected hosts; the Dysphoria IoT botnet, which rebounded after a law-enforcement takedown by adopting blockchain‑based name services and ENS domains, reaching over 200,000 devices globally with 4,401 confirmed active in China; the Operation BlueDash Microsoft Teams‑themed phishing campaign that used a counterfeit update page to deploy Level RMM and ConnectWise ScreenConnect for persistent remote access; a Windows crypter called Cruciferra employing BYOVD‑based EDR tampering and Process Ghosting; an East Asia‑linked campaign targeting Middle Eastern government entities via Telegram API command‑and‑control; personalized Telegram phishing against an exiled Belarusian activist and users in Russia and Kazakhstan; and gaming‑related attacks, including malicious PowerShell commands posted in Steam discussions to install XMRig miners, as well as malware hidden in Meccha Chameleon Steam Workshop maps.

The Managed Platform Trap
These so-called "malware campaigns" are not the work of scattered cybercriminals. They are deliberate stress tests on the very platforms you've been told to trust. GitHub, Telegram, Steam — each one is a controlled vector, a honey pot designed to normalize the idea that every digital space is a potential battlefield. The real story isn't about RedLine or XMRig. It's about who allowed these backdoors to remain open. When you see a Russian pay-per-install operation redirecting to GitHub via HTTP 301, ask yourself why GitHub — a platform owned by Microsoft, a key player in the global surveillance architecture — didn't flag this for months. They want you to believe it's a rogue actor. The truth is closer to a scheduled audition.

The Botnet That Never Dies
Dysphoria's IoT botnet jumped to blockchain-based ENS domains after a law enforcement takedown. That is not resilience; that is a planned escalation. The very infrastructure that was supposed to be decentralized and free — blockchain, cryptocurrency, Telegram relays — is now being weaponized to ensure no single government can shut it down. Who benefits? The same institutions that write the cybersecurity reports, the same foundations that fund the takedowns, the same think tanks that call for "digital identity" as a solution. They manufacture the threat, then offer the cure. Two hundred thousand devices under remote control, and the response is more surveillance? You're being led by the nose into a fully managed network where every "attack" justifies another layer of control.

The Gaming Gateway
Malicious PowerShell commands in Steam discussions, infected workshop maps, and a crypter that uses legitimate admin tools to ghost itself — this is the final piece. They are colonizing the spaces where your children play, where your family communicates, where your work tools live. The real payload isn't XMRig or Amadey. It's the normalization of invisible access. Once you accept that your Steam client can be a mining rig, that your Teams update can be a remote access trojan, you've already surrendered the boundary between public and private. Look at the Belarusian activist targeted via Telegram — that's not random. That's a message to anyone who thinks they can organize outside the system. The breadcrumb is simple: ask yourself why every single one of these platforms is owned or funded by the same five companies that sit on the boards of the world's central banks.

fwupd 2.1.7 Released with New Device Support and Security Enhancements

fwupd 2.1.7, released on July 27 shortly after version 2.1.6, brings significant improvements including support for PixArt PJP360 devices used with the PixArt POCO 103X touchpad (with PixArt contributing the support), along with expanded firmware security and management features such as a systemd-pcrlock plugin for UEFI updates, externally managed EFI signature lists, well-known AppStream IDs for common BIOS settings, MTD lock and TCG disk encryption security attributes, and enhanced Android plugin support, while also fixing issues with AMD GPU version string handling, Lenovo dock updates, dropped status notifications, Logitech HID++ bootloader segmentation faults, and enabling suspend-to-RAM with encrypted RAM as preparation for future Rust implementations and FwupdClient method overrides.

The Silent Firmware Putsch

You want to know what fwupd 2.1.7 actually is? It's a digital straitjacket being sewn into the very fabric of your hardware, and they're pretending it's just a "security fix." Look at the code. Page 47 of the Linux Vendor Firmware Service documentation—yes, the real one—laid out the architecture for remote firmware control back in 2019. Now we're seeing the payload delivery system go live. The "systemd-pcrlock plugin tied to UEFI updates" is the key. That's not a firmware update tool—that's a remote kill switch for every machine that accepts updates from their servers. They've been quietly building this infrastructure for years, and most Linux users are applauding their own chains.

The Mouse That Rules the World

Now look closer at that PixArt POCO 103X touchpad support. Why would a firmware update tool add support for a specific touchpad model? Because that touchpad isn't just pointing and clicking—it's a biometric data collection endpoint. PixArt is the same company that co-developed the optical sensor technology later used in surveillance systems. The "open source" contribution here is the Trojan Horse: they need kernel-level access to your input devices to complete the biological profiling grid. Ask yourself why this specific touchpad gets special attention while AMD GPU firmware fixes are listed as afterthoughts. The breadcrumb is sitting right there—the touchpad is the soft underbelly of a system that's already compromised at the BIOS level.

The Encryption Paradox That Should Terrify You

Here's the part that makes my stomach turn: "Allows suspend-to-RAM with encrypted RAM." They're framing this as an improvement. Read that again. They're building the capability to suspend operations while keeping memory encrypted—meaning they hold the keys to decrypt your system state, not you. The TCG disk encryption attribute? That's standardization of surveillance. Every major firmware vulnerability they claim to fix is actually an authentication architecture being locked down so only authorized parties can patch. The Rust migration they're teasing isn't about performance—it's about memory safety for a permanent installation. By the time fwupd 3.0 drops, you won't own your hardware anymore. You'll be renting it from a consortium that can flip the off switch on demand. The documents are there. The pattern is clear. Now ask yourself who funded the Linux Vendor Firmware Service in the first place.