







As Qubes OS users, promoters, and developers, we understand how essential it is to be aware of the latest developments in maintaining the security of your favorite operating system. We're excited to share our plans to integrate the TrenchBoot Project into Qubes OS's new Anti-Evil Maid (AEM) implementation. As you may know, traditional firmware security measures like UEFI Secure Boot and measured boot, even with a Static Root of Trust (SRT), may only sometimes be enough to ensure a completely secure environment for your operating system. Compromised firmware may allow for the injection of malicious software into your system, making it difficult to detect. To overcome these limitations, many silicon vendors have started implementing Dynamic Root of Trust (DRT) technologies to establish a secure environment for operating system launch and integrity measurements. We're excited to take advantage of these advancements through integration with the TrenchBoot Project.
New physical attacks are quickly diluting secure enclave defenses from Nvidia, AMD, and Intel
On-chip TEEs withstand rooted OSes but fall instantly to cheap physical attacks.

Introducing Deno Sandbox | Deno
Instant Linux microVMs with defense-in-depth security for running untrusted code.

Genode - Genode Operating System Framework
We understand the complexity of code and policy as the most fundamental security problem shared by modern general-purpose operating systems. Because of high functional demands and dynamic workloads, however, this complexity cannot be avoided. But it can be organized. Genode is a novel OS architecture that is able to master complexity by applying a strict organizational structure to all software components including device drivers, system services, and applications. The Genode OS framework is an open-source tool kit for building highly secure component-based operating systems. It scales from embedded devices to dynamic general-purpose computing.
Tock OS A Rust Based Open Platform for Transparent and Secure Root of Trust Devices
Why AVF?
AVF and pKVM: next-generation Trustworthy Execution Environment for connected products

Solene'% : Introduction to Qubes OS when you do not know what it is
In this article, you will learn about major features of the Qubes OS operating system and what makes it unique.

SGX.Fail
Intel's Software Guard Extension (SGX) promises an isolated execution environment, protected from all software running on the machine. In the past few years, however, SGX has come under heavy fire, threatened by numerous side channel attacks. With Intel repeatedly patching SGX to regain security, we set out to explore the effectiveness of SGX's update mechanisms to prevent attacks on real-world deployments.
oss-security - Dirty Frag: Universal Linux LPE
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Xous: A Pure-Rust Rethink of the Embedded Operating System
Xous is a message-passing microkernel implemented in pure Rust, targeting secure embedded applications. This talk covers three novel aspe...

An Update on OpenTitan
Joanna Rutkowska (@rootkovska) on X
Distrusts computers. Keeps embracing them anyway. Previously: Golem Foundation/Wildland, Qubes OS, hardware/virtualization/OS security research.

TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition
Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition

Smarter Operating Systems Will Use Wasm - The Coming OS Revolution by Jonas Kruckenberg @ Wasm I/O
nbdkit now supports LUKS encryption
nbdkit, our permissively licensed plugin-based Network Block Device server can now transparently decode encrypted disks, for both reading and writing: qemu-img create -f luks –object secret,d…

Sooraj on Twitter / X
IronClaw (@near_ai, Rust) is the most architecturally serious alternative. Built by @ilblackdragon as a direct response to OpenClaw's security failures. Tools and channels run in isolated WASM containers with capability-based permissions. Credentials live in an encrypted vault… https://t.co/3VkLn4f0Ai— Sooraj (@iAnonymous3000) February 16, 2026
so that new Mac Studio and M5 Ultra have me thinking about 2030 now the wildcard on the $1200ish 2030 Mac Mini is RAM. who knows what the…

MercuryOS
inanimate-tech/resident

Television

Flipper One — we need your help

A Linux Distribution for RISC-V | openRuyi