RSS 생중계
OpenAI Unveils o3 and o4-mini Models
Read more of this story at Slashdot.
Trump Administration Plans To End the IRS Direct File Program for Free Tax Filing
Read more of this story at Slashdot.
[$] What's new in APT 3.0
Debian's Advanced Package Tool (APT) is the suite of utilities that handle package management on Debian and Debian-derived operating systems. APT recently received a major upgrade to 3.0 just in time for inclusion in Debian 13 ("trixie"), which is planned for release sometime in 2025. The version bump is warranted; the latest APT has user-interface improvements, switches to Sequoia to verify package signatures, and includes solver3—a new solver that is designed to improve how it evaluates and resolves package dependencies.
Catanzaro: Dangerous arbitrary file read vulnerability in Yelp
GNOME contributor Michael Catanzaro has written a blog post about a noteworthy vulnerability in GNOME's help browser, Yelp.
I don't normally blog about particular CVEs, but Yelp CVE-2025-3155 is noteworthy because it is quite severe, public for several weeks now, and not yet fixed upstream. In short, help files can read your filesystem and execute arbitrary JavaScript code, allowing an attacker to exfiltrate any files your Unix user has access to.The vulnerability was first reported on December 25, and it was made public on March 26 after the 90-day-disclosure deadline was reached. Patches have been proposed to fix the issue. The bug reporter has published a writeup demonstrating the attack. Catanzaro asks that Linux vendors "please consider applying the provided patches even though they have not yet been accepted upstream".
[$] Parallel directory operations
[$] Taking BPF programs beyond one-million instructions
The BPF verifier is not magic; it cannot solve the halting problem. Therefore, it has to err on the side of assuming that a program will run too long if it cannot prove that the program will not. The ultimate check on the size of a BPF program is the one-million-instruction limit — the verifier will refuse to process more than one-million instructions, no matter what a BPF program does. Alexei Starovoitov gave a talk at the 2025 Linux Storage, Filesystem, Memory-Management, and BPF Summit about that limit, why correctly written BPF programs shouldn't hit it, and how to make the user experience of large BPF programs better in the future.
Google To Phase Out Country Code Top-level Domains
Read more of this story at Slashdot.
AI-generated Music Accounts For 18% of All Tracks Uploaded To Deezer
Read more of this story at Slashdot.
Companies Are Slashing Their SaaS Spends, UBS Says
Read more of this story at Slashdot.
CISA extends funding to the CVE program (BleepingComputer)
Sergiu Gatlan reports that the US government has extended funding for the Common Vulnerabilities and Exposures (CVE) program, following yesterday's reports that funding would run out as of April 16.
"The CVE Program is invaluable to cyber community and a priority of CISA," the U.S. cybersecurity agency told BleepingComputer. "Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners' and stakeholders' patience."The article also mentions the launch of a CVE Foundation, to transition the CVE program to a dedicated foundation and eliminate "a single point of failure in the vulnerability management ecosystem", as well as a European vulnerability database (EUVD) backed by the European Union Agency for Cybersecurity (ENISA). Details on these initiatives are scant at the moment, and it is unclear whether restoration of funding will have any impact on these efforts.
[$] Improvements for the contiguous memory allocator
CISA Extends Funding To Ensure 'No Lapse in Critical CVE Services'
Read more of this story at Slashdot.
Immigrant Founders Are the Norm in Key US AI Firms: Study
Read more of this story at Slashdot.
Security updates for Wednesday
Figma Confidentailly Files For IPO After Adobe Deal Collapses
Read more of this story at Slashdot.
Cybersecurity World On Edge As CVE Program Prepares To Go Dark
Read more of this story at Slashdot.
Limited Edition of Doom Includes Game Box That, Itself, Plays Doom
Read more of this story at Slashdot.
Older People Who Use Smartphones 'Have Lower Rates of Cognitive Decline'
Read more of this story at Slashdot.
Free Wi-Fi Is On Its Way To American Airlines
Read more of this story at Slashdot.
Gemini App Rolling Out Veo 2 Video Generation For Advanced Users
Read more of this story at Slashdot.
페이지
