Launching Astro Pi 2026/27: Code your way to the International Space Station

Post Syndicated from Fergus Kirkpatrick original https://www.raspberrypi.org/blog/launching-astro-pi-2026-27-code-your-way-to-the-international-space-station/

Strap yourselves in for an out-of-this-world journey! The European Astro Pi Challenge 2026/27 officially launches today, 14 September 2026!

Young people across Europe and Canada are invited to participate in two fun coding missions, offering them the amazing opportunity to run their programs on the Astro Pi computers aboard the International Space Station (ISS). Every successful team will receive official certificates complete with runtime details and orbital coordinates, along with their very own space data and image sets to download and keep.

The European Astro Pi Challenge is an ESA Education project run in collaboration with the Raspberry Pi Foundation, and implemented by ESEROs at a national level. It gives young people the chance to learn how to code and conduct real space science in orbit.

Which mission will your teams launch this year?

Pixel art images from the Mission Zero project guide for this year’s Astro Pi challenge.
New Mission Zero code examples

Mission Zero: Art in orbit

Send your art to orbit and create colorful pixel art with code! Mission Zero is a beginner-friendly Python activity, perfect for young people aged 9 to 16 with no prior coding experience.

Participants use our web-based code editor to set image colors and capture live light readings to adapt their artwork. In our step-by-step project guide, you’ll find a selection of starter examples to modify and make your own, all chosen directly from entries from the 2025/26 season.

Because so many teams love bringing their artwork to life, Mission Control has included step-by-step worked code examples in our project guide: one that creates a static image, and another that outputs a two-frame animation. Your team can modify the colours, add extra frames, or design an entirely original piece. We can’t wait to see what participants create.

Photos of Earth’s surface captured by Astro Pi cameras on board the ISS.
Earth observation images captured by Mission Space Lab teams

Mission Space Lab: Real orbital science

Calling all aspiring space scientists! Mission Space Lab gives young people aged 12 to 19 the chance to capture real sensor data and Earth observation images while the ISS orbits 400km above us.

Working in teams of between two and six young people, participants write a Python program to log sensor or camera data to explore life on Earth or orbital mechanics. Teams can design an entirely original space science project or use our ready-made guides to analyse vegetation using NDVI imaging, or calculate the speed of the ISS. Every eligible program is guaranteed a ten-minute flight slot on the ISS.

This year, you’ll find a template for a basic data capture submission in the Mission Space Lab Creator Guide. It provides a great starting point for teams to predict the output of their program, test their logic, and customise their code. What will your team choose to investigate?

An astronaut operating the Astro Pi computer inside the International Space Station.
Astro Pi computers aboard the ISS

Meet our ambassador

We are excited to announce that ESA astronaut Thomas Pesquet will be the ambassador for the European Astro Pi Challenge this year. Having worked aboard the ISS, Thomas knows how important it is to conduct scientific experiments in space. Plus, Thomas is no stranger to the European Astro Pi Challenge. In fact, he has been our ambassador twice before, during the 2016/2017 and 2020/2021 editions. He is currently preparing for his next mission, having been selected to command a private astronaut mission, planned for 2027.

An astronaut inside the International Space Station.
Credit: ESA/NASA

Get in touch with Mission Control

The Astro Pi Mission Control team is here to support you every step of the way. Visit our website to learn how to book a support call with our team, or reach out to us directly at [email protected].

We’ll also be hosting interactive support sessions and livestreams for both missions throughout the year. Make sure you stay connected by signing up for our official newsletter.

In the meantime, look to the stars and see how far your young people can reach!

The post Launching Astro Pi 2026/27: Code your way to the International Space Station appeared first on Raspberry Pi Foundation.

More than 9,000 patches total in the seven stable kernels for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1093985/

Greg Kroah-Hartman has announced the 7.2.6,
6.18.52, 6.12.110, 6.6.157, 6.1.188,
5.15.221, 5.10.270 stable kernels.

According to
Kroah-Hartman
, this batch may set a record for the number of patches with
more than 9,000 in total between them. There are more than 1,800
patches
in 7.2.6 alone. Users of these kernels are, of course, advised to
upgrade.

Microsoft’s Patching

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2026/09/microsofts-patching.html

Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record:

Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.

It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out unprecedented numbers of patches in their software.

This is the result of AI-powered vulnerability finding, and a good example of AI helping the defenders more than the attackers.

What will be interesting to watch is how the number of vulnerabilities changes over the next few months. My prediction is that it will continue to increase as the AIs get better at finding software vulnerabilities, and then decrease as they run out of vulnerabilities to find. How high the number gets, how fast the trend reverses, and how quickly it declines after that are all unknown.

And Microsoft is right: The window to patch has shrunk to “immediately.” AIs are also good at reverse-engineering exploits from patches, which means that these vulnerabilities will be weaponized as soon as the update is published.

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

Post Syndicated from Rapid7 original https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild

Overview

On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.

On September 11, 2026, CVE-2026-85706 was added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. CISA set a remediation due date of September 14, 2026, for affected Federal Civilian Executive Branch agencies and marked the vulnerability as subject to forensic triage requirements under Binding Operational Directive 26-04.

Organizations running affected self-managed GitLab instances should remediate CVE-2026-85706 on an emergency basis, outside of normal patch cycles.

Mitigation guidance

A vendor-supplied update is available to remediate CVE-2026-85706. Organizations running affected self-managed GitLab CE or EE instances should upgrade to a fixed version immediately.

Affected GitLab CE/EE versions

Fixed version

All versions from 18.7 before 19.1.8

19.1.8

All versions from 19.2 before 19.2.6

19.2.6

All versions from 19.3 before 19.3.2

19.3.2

GitLab.com is already running a patched version, and GitLab Dedicated customers do not need to take action. Per GitLab, all self-managed deployment types are affected, including Omnibus, source code, and Helm chart deployments.

The updates include database migrations. Single-node installations will experience downtime while the migrations run; multi-node deployments can use GitLab’s zero-downtime upgrade procedure. Of the fixed releases, only 19.3.2 includes post-deployment migrations.

The patch release also addresses 17 other vulnerabilities. These include CVE-2026-87719, a critical insecure deserialization vulnerability (CWE-502) in GitLab EE with a CVSSv3.1 score of 9.9. GitLab states that, under certain conditions, an authenticated user with Duo Chat access could obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument. At the time of publication, only CVE-2026-85706 is known to be exploited in the wild.

Given the confirmed exploitation, Rapid7 strongly recommends looking for signs of compromise even after the update has been applied. Organizations subject to CISA’s BOD 26-04 should also follow the forensic triage requirements associated with the KEV entry.

For the latest mitigation guidance, please refer to the vendor’s security advisory.

Rapid7 customers

Exposure Command, InsightVM, and Nexpose

Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-85706 with a vulnerability check available in the September 15 content release.

Updates

  • September 14, 2026: Initial publication.

Must be surreal

Post Syndicated from Боян Юруков original https://yurukov.net/blog/2026/must-be-surreal/

Must be surreal to live history all over
repeating the same lies of self-defense,
superiority, destiny and final solution
watching passively as everyone –
yourself included – prays, votes, kills,
burns and rebuilds atop graves.

Must be heartbreaking to watch
your bloodline relive what you endured
now from the perpetrator’s desk
history forgotten, repeated, rebranded
uttering those exact excuses and hate
following through as orders are followed.

Must be difficult to face the tape rolling
once ashes and truth settle alike,
to explain once more, eighty years later,
to insist common folk didn’t know,
only sought safety and promised destiny,
to feel the shame once those lies crumble.

Must be painful for the witness and learned
to watch events unfold and reconstruct
what was once labeled as „never again“
knowing that in eighty more years
the bloodline of those who now slay
will emerge from the shame and lead yet again.

Must be terrifying to entertain the thought
that what remains of a charred people –
scattered across, but not at home –
will rise to hunt the monsters down
one by one, as decades past,
to end, to seek justice, to avenge.

Must be certain some labels will be named:
terror, and stench of decaying foe
or truth seekers and retribution
for a humanity failing yet again.

Must be up to the scribes or those
who will still utter „never again“
and still fail to know how or what,
yet dream of safety and promised destiny.

The collective thoughts of the interwebz