Bonum Certa Men Certa

Jim Zemlin/Linux Foundation Selling Anthropic Slop After Getting Bribed for Slop Marketing ('Linux' Foundation is a Pay-to-Say For-Profit Marketing Company That Buys and Manipulates the Media Based on False Pretences)

posted by Roy Schestowitz on May 12, 2026,
updated May 12, 2026

Last month: Latest Example of False Marketing by Anthropic | Anthropic and Claude Are National Security Risks Not Because of Politics But False Marketing and Vandalism, Plagiarism Sold as Innovation

Earlier this month: The NHS is Under Attack by Anthropic and Microsoft (or Their Lemmings That Infect the NHS)

We not only knew this would happen but warned it would happen, knowing what sort of person Jim Zemlin is married to (securities fraud; no technical knowledge at all, just money-chasing fanaticism). Jim Zemlin publicly boasts that his wife controls him and tells how she belittled him if he did not focus on money (on their first date).

Now we see the people who claim to speak for "Linux" (but don't even use it) speaking against Linux to promote a scam. They peddle FUD as a form of marketing.

As Akira Urushibata put it in recent days (with permission granted to reproduce):


The following article describes a security expert's effort to determine whether Anthropic's claim of "thousands of severe vvlnerabilies" is true. He examined the CVE registry.
Researchers Are Trying to Determine How Many Vulnerabilities Claude Mythos Has Discovered https://hackmag.com/news/mythos-cves
VulnCheck specialist Patrick Garrity tried to determine how many vulnerabilities Anthropic's new AI model Claude Mythos actually discovered as part of the Project Glasswing initiative. Recall that the developers had claimed it found thousands of 0-days.
...
Gerrity decided to put Anthropic's bold claims to the test and examined the CVE registry, which contains more than 327,000 entries. He searched for all records containing the word "Anthropic" starting from February 2026 and manually analyzed the results.
---
On April 7th Jim Zemlin of the Linux Foundation made a statement on Project Glasswing.
https://www.linuxfoundation.org/blog/project-glasswing-gives-maintainers-advanced-ai-to-secure-open-source
The message is addressed primarily to "open source" developers. Zemlin understands that they suffer from limited resources and says that Project Glasswing would be a blessing because "AI" would assist arduous security-related work. He speaks of providing Claude access to "open source" developers, even going on to suggest that such access would entice people to accept maintainer roles.
There are several problems. The above was posted on April 7th. A month has passed but maintainers are generally unaware of this proclamation. The Linux Foundation has not issued any further statements, indicating an absence of notable progress.
There are many free software projects that maintain critical system components. Compiling a comprehensive list is a significant task. Any attempt to determine who shall be let in and who shall be kept out should lead to noisy debate, which we currently do not observe.
I believe Jim Zemlin's plan to make Claude available to a large number of "open source" developers is at odds with the desires of Project Glasswing member firms. Glasswing is promoted as a small and tight group while Zemlin calls for throwing the gates wide open. Without resolving this conflict the Linux Foundation cannot make progress.
Linux is the name of a kernel, and the Linux Foundation is built around kernel developers. Many people wrongly believe that "Linux" is the whole OS and do not understand that the Linux Foundation has absolutely no authority over developers of other OS components. In fact many developers are not interested in the Linux Foundation and pay scant or no attention to announcements on their official website.
In contrast when ordinary people hear that the Linux Foundation is a Glasswing member, they assume that developers of the "Linux OS" would be given ample time and resources to deal with security issues. Unfortunately this is not the case. A dangerous gap between reality and perception thereof exists.
---
If we want to compile a list of critical system components, where do we start? The Debian Popularity Contest may be the starting point: https://popcon.debian.org/

Two days later:


Trying to determine what the Linux Foundation is doing to identify "critical" system packages I found this page:
https://insights.linuxfoundation.org/
Discover the world's most critical open source projects
So what are they?
Top 30 Open Source Projects https://insights.linuxfoundation.org/collection/details/top-open-source-projects
A curated list of the most essential open source projects based on the OpenSSF Criticality Score, representing foundational infrastructure and frameworks relied upon globally across industries.
Note: although it says "Top 30" actually there are 46 projects listed.
There is little overlap between this list and the Debian base system and essential packages which naturally rank high in the popularity contest (popcon) list. Many projects in the "Top 30 Open Source Projects" list rank low in Debian popcon or don't appear at all, while Debian's base system and essential packages don't appear in the Linux Foundation's list. Here I examine two examples:
Second in Linux Foundation's "Top 30 Open Source Projects" list is Flutter.
Flutter https://flutter.dev/
Flutter is powered by the dart language. If flutter is critical, dart should be at least equally so but it does not appear in the "Top 30" list.
Debian does not provide a package for dart. It seems a package named "dart" is available from an outside source: it appears low in the popcon list. This .deb package may be for the Dynamic Animation and Robotics Toolkit which has no relation with the dart language.
DART (Dynamic Animation and Robotics Toolkit) https://dartsim.github.io/
Eighth in the "Top 30" list is Godot Engine.
Godot Engine https://godotengine.org/ja/
Godot Engine is a game engine with editor. It makes developing 2D and 3D games easy. The godot3 package is provided by Debian. It ranks low in popcon.
The Linux Foundation considers a game engine "most essential" and "relied upon globally across industries."
We can see that the "critical projects" list is poorly focused. It doesn't serve its stated purpose and as such gets little attention.
---
So how did Linux Foundation produce the list?
The criticality ranking is produced by an algorithm provided by the Open Source Security Foundation (OpenSSF), which is affiliated with the Linux Foundation. The OpenSSF site has a page explaining the formula:
Understanding and Applying the OpenSSF Criticality Score in Open Source Projects https://openssf.org/blog/2023/07/28/understanding-and-applying-the-openssf-criticality-score-in-open-source-projects/
The algorithm has three variables, a[i], S[i], and T[i]. a[i] is the weight of the i'th signal, S[i] is the value of the i'th signal, and T[i] is the threshold of the i'th signal.
The person running the algorithm arbitrarily selects the input factors (or "signals"). The weight a[i] is an arbitrary scalar. As such this model gives the person in charge much room for tampering.
For example should someone desire to produce a list with Emacs ranking high, he could do so by making "number of supported human languages" "age of project" "percentage of code written in Lisp" input factors and assigning large weights to them.
The input factors and weights used by the Linux Foundation are not published. I haven't found a complete list of projects surveyed. Neither have I seen criticality scores in the "Top 30" list or elsewhere.
My guess is that the Linux Foundation needed to produce a criticality ranking with Linux kernel ranking high, and tweaked around with S[i] and a[i] to get the desired outcome. I have seen that kind of tweaking with multiple regression analysis.
---
Wikipedia provides a compilation of free software directories:
List of free software project directories https://en.wikipedia.org/wiki/List_of_free_software_project_directories
Linux Foundation is not mentioned in this article.
Akira Urushibata

In relation to the Linux Foundation, whose management is financially controlled not by kernel stakeholders but "slop bros" and other scammers (or scam varieties with the lion's share of the financial leverage).


On 5/8/26 02:31, Akira Urushibata via libreplanet-discuss wrote:
... and the Linux Foundation is built around kernel developers.

I wish that were still the case with the Linux Foundation (LF). While, the LF /was/ built around kernel developers, growing out of the OSDL, nowadays about the only Linux there is in the name. Both it and the OSI have been taken over by microsofters who steer both organizations away from their original goals. See also the similar situations at the companies Canonical and IBM. However, that is just the start of a very long list even if one constrains the scope of the complaint to just ICT.
The financial statements for the LF show, and have shown for years, that only about 2% to 3% of the technical portion of the budget is actually spent on Linux. See page 20 of the latest report¹. On page 58, you see the full numbers:
$8,410,114 2.95% Linux Kernel Project $6,750,480 2.37% International Operations $15,726,845 5.52% Community Tooling $15,834,749 5.56% Corporate operations $16,813,013 5.90% Even Services $17,733,121 6.23% Project Infrastructure $21,637,925 7.60% Training $181,889,435 63.87% Project Support
Most of the non-kernel line items are spent on some really odd things, not Linux related things. Those odd things include Glasswing and other boondoggles.
A dangerous gap between reality and perception thereof exists.

Yes, good call there. A very dangerous gap between reality and perceptions exists. The late Pieter Hintjens used to assert in his writings that organizations cannot be reformed once they have gone bad. Instead he called for outright replacement when they do turn corrupt. However, in the case of LF that'd be quite hard unless Linus himself were to take his trademark² and walk. I don't know him but from the decades of interviews and articles, he gives the strong impression that he avoids bureaucracy. So that would need some really special circumstances and support in order to even be considered.
Back when Red Hat was a thing that worked out well for him, but now even Red Hat is gone in all but name. So some solution needs to be worked out which will just let him hack on Linux while keeping the microsofters and other saboteurs out of his hair and his project.
/Lars
¹ https://www.linuxfoundation.org/hubfs/Publications/2025%20Linux%20Foundation%20Annual%20Report_122225a_lr.pdf
² https://www.linuxfoundation.org/legal/the-linux-mark

Anthropic is a truly terrible company and a key participant in a giant Ponzi scheme. Zemlin is destroying the credibility of Linux (the brand) because he profits from it. At whose expose? All of us.

Look what they've done to Steven Vaughan-Nichols (SJVN), the 'mentor' of Spamnil (according to Spamnil; both are marketing operatives of Zemlin, on his payroll). This is his latest:

Steven Vaughan-Nichols: Slop image; Slop promotion, sponsored by the company it's about

How much closer are they willing to bring the "Linux" brand to pedophilia and sex trafficking? The disrepute severely hurts the community, not GAFAM et al (controlling the brand, an act of predation).

We need a safe space and a CoC; That's why we partner with Bill Gates -Jim Zemlin

Other Recent Techrights' Posts

Google "Hey Hi" (Slop) Having a Stroke, Thinks I am Married to the Grandmother of My Grandfather
Seriously!
Beehiiv and Substack Are Platform Lock-in (Similar to Vendor Lock-in), Don't Use Beehiiv and Substack (and the Likes of These)
Proprietary platforms are a problem. Some people "get it" sooner than others.
Jim Zemlin/Linux Foundation Selling Anthropic Slop After Getting Bribed for Slop Marketing ('Linux' Foundation is a Pay-to-Say For-Profit Marketing Company That Buys and Manipulates the Media Based on False Pretences)
Look what they've done to Steven Vaughan-Nichols (SJVN)
The Corrupt Lecture the Non-Corrupt - Part XX - EPO Management's Unified (One) Voice or Policy is, Doing Cocaine is OK When You're a Friend and/or Family of President Campinos
The management needs to resign to save the Office
 
Gemini Links 12/05/2026: On Astronomy and Stargazing, Coyote Time, and Freenom
Links for the day
Links 12/05/2026: Data Centres Destroying Neighbourhoods, "Care Workers Are Saying No to 24-Hour Workdays"
Links for the day
Richard Stallman to Give Public Talk in Erlangen, Germany (Next European Tour)
Seems like a large room
If IBM Suddenly Vanished in the 1980s, There Would be Chaos. Not Anymore.
IBM's management has rendered IBM more irrelevant than ever before
Gitlab is in Trouble and Its Shares Have Collapsed
Down almost 80% since it began [...] The real issue has nothing to do with slop, it is a lack/loss of customers and erosion of the company's theoretical "value"
Microsoft: Mass Layoffs Are "Offers" (Like "Job Offers"), Culling Experienced and Highly-Paid Staff is "Softer Workforce-reduction Strategy"
Media sites that play along with those lies don't do journalism, they're in the PR industry
Under IBM, Mass Layoffs at Red Hat No Better Than Oracle Under Larry Ellison (Treating Workers Like Disposables - Even Enemies - Overnight)
under IBM the respect for the worker (or peer) does not exist
The Slop-Amplified Fear of Privilege Escalation (Local, Not Remote) in Linux, the Kernel
we are meant to assume this is no better and no worse than Microsoft intentionally putting back doors in everything, even encryption
GitLab the Latest Company to Do Mass Layoffs and Use Slop as the Go-to Excuse (GitLab Users Should Worry Too)
This round of layoffs (disguised as something else) has nothing to do with slop ("hey hi"). It's about commercial problems.
Technology Not Meant to Last
A society apathetic towards declining production (or manufacturing) standards will end up ripped off
statCounter Cannot 'See' Chinese Operating Systems That Gain Many Millions of Users Per Month
There is no way for statCounter to recognise or show the market share of HarmonyOS
SLAPP Censorship - Part 74 Out of 200: The Basis of My Lawsuit Against Alex Graveley, Who Helps Garrett Stack the Docket in Another Continent
claim against the Serial Strangler from Microsoft
Update on Slop About "Linux"
"Linux" is a term many people are interested it, so it's not shocking that slopfarms target it
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, May 11, 2026
IRC logs for Monday, May 11, 2026
GAFAM (Microsoft) "Cloud Computing" Means Another Country's Military Accesses All Your Data
reminder that confidentiality and Clown Computing are complete opposites
Another Discrimination Lawsuit Against IBM and Workers Say IBM Culls Older Workers (Just Like Microsoft)
If IBM fails to retain some of the smartest people, then what is the future of IBM?
Gemini Links 12/05/2026: Android Nostalgia and Switching to Guix
Links for the day
Links 11/05/2026: Another Oracle Setback and Mass Layoffs in Iran
Links for the day
Gemini Links 11/05/2026: Older Can Be Faster and Textmode Workflow
Links for the day
Links 11/05/2026: The Solicitors Regulation Authority (SRA) Admits It Only Reacts When It's Too Late (Damage Already Done), Ombudsman’s Animal Cruelty HK Report
Links for the day
If It Takes You a Second to Serve (or Receive) a Page, That's Definitely Too Slow
For speeds at milliseconds (e.g. for pages to fully load in a tenth of a second) the pages must be ready to be sent as soon as they're requested
It's Not About Speed, It is About Patience and Adherence to Truth, Principles, Scientific Integrity
attacks on us only ever made us stronger - a lesson that our adversaries have learned the hard way
Cyber Show Does it Like Techrights: Static and Gemini Protocol as 'First-Class Citizen'
HTML and GemText (over Gemini Protocol) would be rendered in tandem
Libya's Share on the Web: 5.2% GNU/Linux
GNU/Linux has hit an all-time high there
SLAPP Censorship - Part 73 Out of 200: Microsoft's Graveley and Garrett Remain Closely Connected in May 2026 ("Tag-Teaming" Against Bloggers in Another Continent)
The phrase "judge a person by their friends" seems applicable here
Codecs and Software Patents - Part VI - The European Patent Office, Nokia, Microsoft, Sisvel, and More
Whatever Nokia used to be, it's certainly not an ally and a lot of the turmoil at the EPO is the fault of companies like Nokia
Discussions About When the Axe Falls at IBM/Kyndryl (11,000 Layoffs Estimated)
"Kyndryl restructuring should reduce overhead functions and reduce the number of managers that lack technical knowledge"
A World After Microsoft (and GAFAM) and After GitHub Shuts Down
the only growth area is debt
Fake News, Propaganda, and Misinformation: Microsoft Investing Money It Does Not Have in "Hey Hi" (for "Entertainment Purposes" Only)
This will not end well
Today the Whole European Patent Office (EPO) is on Strike and Next Monday an Even Bigger Strike
the media refuses to cover these and is thus complicit
The Corrupt Lecture the Non-Corrupt - Part IXX - EPO Management Speaks of Reputation and Integrity While Putting Cocaine Addicts in Management
If the EPO values its "reputation", then it needs to start by ousting the management
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, May 10, 2026
IRC logs for Sunday, May 10, 2026
Links 11/05/2026: Security Breaches, Politics, and Energy Crunch
Links for the day
Gemini Links 10/05/2026: "Accidental Cameras" and "Addictive" Interfaces in Social Control Media
Links for the day
Codecs and Software Patents - Part V - A Reminder That GAFAM and the European Patent Office (Which Serves American Monopolists) Do Considerable Harm to the Commons and Culture
some 'breaking' developments
Gemini Links 10/05/2026: Inkscape, Guix, and Alhena 5.5.8
Links for the day
The "Alicante Mafia" at the European Patent Office (EPO) Experiments With New Methods for Crushing Industrial Actions
Open letter to VP1 and the COO [...] What does this tell us about the status quo at the European Patent Office, Europe's second-largest institution?
The Corrupt Lecture the Non-Corrupt - Part XVIII - "The European Patent Office (EPO) has a zero-tolerance policy for fraud" (except when managers do it)
The guidebook of the EPO says fraud is not to be tolerated, but who enforces or revisits such "Red Lines"?
Links 10/05/2026: Hantavirus Brings Back 'Contact Tracing' Surveillance, "Staple Food Prices Soar in Iran"
Links for the day
Microsoft XBox Staff Know They're in Trouble, They Try to Unionise Ahead of Mass Layoffs
As the slang goes, it's going to be a "bloodbath"
Links 10/05/2026: Fake Suicide Notes and New EU Restrictions on Slop
Links for the day
SLAPP Censorship - Part 72 Out of 200: Microsoft's Graveley and Garrett Signed Documents That Hold Them Accountable to Truth and Liable for Lies
Such collaborations are unsavoury and apparently unprofessional, too
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, May 09, 2026
IRC logs for Saturday, May 09, 2026
Gemini Links 10/05/2026: Travelling to Van and "Dark Mode" as Passing Fad
Links for the day