systemd 262 has been released with Live Update Orchestrator (LUO) session support, enabling integration with Linux live-update workflows designed to reduce disruption during host maintenance. LUO is also being explored in experimental kernel work to keep KVM guests running while a host kernel is offline for an update or reboot; that orphaned-VM design remains an early, non-production RFC tested across Intel, AMD, and Arm server systems.
The release adds signed systemd-report output using Ed25519, configfs TSM, or TPM2 PCR-based signing; FIDO2 PIN support; and a systemd-journald Forward Secure Sealing implementation based on OpenSSL rather than libgcrypt. Other changes include expanded systemd-sysupdate controls, dm-clone provisioning support, static or multicall build options, restart randomization, slice activation-concurrency limits, enhanced NUMA policies, and an AI/LLM canary intended to flag unreviewed AI-generated code contributions.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
systemd 262 was released as a feature update for the Linux init system and service manager. It added embedded fallback unit files, static/multicall build support, dm-clone and sysupdate enhancements, LUO session integration, signed reporting, FIDO2 PIN support, and an AI/LLM code-review canary.
Google engineer Pasha Tatashin proposed a 46-patch RFC for Orphaned VMs, intended to let KVM guests continue executing while the host kernel is offline during a reboot or live security update. The early, non-production design uses LUO and a privileged Caretaker layer, and has been tested on Intel, AMD, and Arm server processors.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
opennet.me
Open sourceopennet.ru
Open sourcephoronix.com
Open sourcephoronix.com
Open sourcefreedesktop.org
Open sourcefreedesktop.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.