{
  "id": 11001028,
  "title": "openSUSE Leap adds a new security layer: Immutable mode",
  "url": "https://urgent.news/2026/09/30/opensuse-leap-adds-a-new-security-layer-immutable-mode",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-30T17:58:06.000Z",
  "source": {
    "name": "ZDNet",
    "slug": "zdnet",
    "url": "https://www.zdnet.com/tech/opensuse-leap-immutable-mode-security/"
  },
  "original_language": "en",
  "account": "openSUSE Leap, a popular Linux distribution, has introduced a new security feature called \"Immutable Mode\" in version 16.1. This feature provides a transactionally updated system with a read-only root filesystem, making it a \"transactionally updated system.\" The official openSUSE blog explains that this is similar to Leap Micro, a specialized operating system designed for containerized workloads, edge computing, and virtualized environments, but integrated directly into Leap.\n\nImmutable Mode is designed not only for specialized deployments but also for anyone who prefers atomic updates on the desktop. When enabled, the root file system is mounted as read-only, preventing alterations to directories like /usr and /etc. This security improvement ensures that even after a malicious script is executed, it cannot modify anything in those immutable directories, enhancing system security. Additionally, openSUSE Leap already includes several security-focused features such as SELinux, firewalld, binary hardening, permission profiles, and Btrfs snapshots.",
  "summary": "One of the more secure Linux distributions has added another feature to help further lock it down.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}