RSS 생중계

Chegg To Lay Off 22% of Workforce as AI Tools Shake Up Edtech Industry

Slashdot - 화, 2025/05/13 - 1:49오전
Chegg said on Monday it would lay off about 22% of its workforce, or 248 employees, to cut costs and streamline its operations as students increasingly turn to AI-powered tools such as ChatGPT over traditional edtech platforms. From a report: The company, an online education firm that offers textbook rentals, homework help and tutoring, has been grappling with a decline in web traffic for months and warned that the trend would likely worsen before improving. Google's expansion of AI Overviews is keeping web traffic confined within its search ecosystem while gradually shifting searches to its Gemini AI platform, Chegg said, adding that other AI companies including OpenAI and Anthropic were courting academics with free access to subscriptions. As part of the restructuring announced on Monday, Chegg will also shut its U.S. and Canada offices by the end of the year and aim to reduce its marketing, product development efforts and general and administrative expenses.

Read more of this story at Slashdot.

카테고리:

Climate Crisis Threatens the Banana, the World's Most Popular Fruit

Slashdot - 화, 2025/05/13 - 1:00오전
The climate crisis is threatening the future of the world's most popular fruit, as almost two-thirds of banana-growing areas in Latin America and the Caribbean may no longer be suitable for growing the fruit by 2080, new research has found. From a report: Rising temperatures, extreme weather and climate-related pests are pummeling banana-growing countries such as Guatemala, Costa Rica and Colombia, reducing yields and devastating rural communities across the region, according to Christian Aid's new report, Going Bananas: How Climate Change Threatens the World's Favourite Fruit. Bananas are the world's most consumed fruit -- and the fourth most important food crop globally, after wheat, rice and maize. About 80% of bananas grown globally are for local consumption, and more than 400 million people rely on the fruit for 15% to 27% of their daily calories.

Read more of this story at Slashdot.

카테고리:

Guix project migrating to Codeberg

lwn.net - 화, 2025/05/13 - 12:32오전

The Guix project has announced that it is migrating all of its Git repositories, as well as bug tracking and patch tracking, from Savannah to the Codeberg Git forge.

As a user, the main change is that your channels.scm configuration files, if they refer to the git.savannah.gnu.org URL, should be changed to refer to https://codeberg.org/guix/guix.git once migration is complete. But don't worry: guix pull will tell you if/when you need to update your config files and the old URL will remain a mirror for at least a year anyway.

The motivation for the move, which is spelled out in a Guix Consensus Document (GCD), is to improve the contribution experience and improve quality assurance efforts. Migration of Git repositories should be completed by June 7, though they will continue to be mirrored on Savannah until "at least" May 2026. LWN covered Guix in February 2024.

카테고리:

Western Digital Invests in Ceramic Storage Firm That Claims 5,000-Year Data Retention

Slashdot - 화, 2025/05/13 - 12:20오전
Western Digital has made a strategic investment in German startup Cerabyte, a company developing nearly indestructible ceramic-based data storage technology. The partnership aims to accelerate commercialization of Cerabyte's ceramic-on-glass material, which the company claims can preserve data for 5,000 years. Cerabyte recently demonstrated its technology's resilience by boiling storage devices in salt water and subjecting them to oven-level heat. The company states its ceramic storage withstands fire, moisture, UV light, radiation, corrosion, and EMP bursts. Beyond durability, Cerabyte aims to enable massive capacity increases as the industry moves toward what it calls the "Yottabyte era," while targeting storage costs below $1 per TB by 2030.

Read more of this story at Slashdot.

카테고리:

[$] The last of YaST?

lwn.net - 월, 2025/05/12 - 11:56오후

The announcement of the openSUSE Leap 16.0 beta contained something of a surprise—along with the usual set of changes and updates, it informed the community of the retirement of "the traditional YaST stack" from Leap. The YaST ("Yet another Setup Tool") installation and configuration utility has been a core part of the openSUSE distribution since its inception in 2005, and part of SUSE Linux since 1996. It will not, immediately, be removed from the openSUSE Tumbleweed rolling-release distribution, but its future is uncertain and its fate is up to the larger community to decide.

카테고리:

Apple Considering Raising iPhone Prices

Slashdot - 월, 2025/05/12 - 11:40오후
Apple is weighing price increases for its fall iPhone lineup, a step it is seeking to couple with new features and design changes, according to WSJ, which cited people familiar with the matter. From the report: The company is determined to avoid any scenario in which it appears to attribute price increases to U.S. tariffs on goods from China, where most Apple devices are assembled, the people said. The U.S. and China agreed Monday to suspend most of the tariffs they had imposed on each other in a tit-for-tat trade war.

Read more of this story at Slashdot.

카테고리:

Security updates for Monday

lwn.net - 월, 2025/05/12 - 11:37오후
Security updates have been issued by Debian (libbson-xs-perl, postgresql-13, redis, and simplesamlphp), Fedora (chromium, deluge, epiphany, golang-github-nats-io-nkeys, libxmp, nodejs22, perl-Compress-Raw-Lzma, php-adodb, python-h11, and xz), Gentoo (firefox, NVIDIA Drivers, Orc, PAM, and thunderbird), Mageia (libreoffice, python-django, and transfig), Red Hat (emacs, firefox, python39:3.9, and thunderbird), SUSE (bird3, freetype2, ldap-proxy, libmosquitto1, and ruby3.4-rubygem-rack), and Ubuntu (linux, linux-aws, linux-kvm, linux-aws, and linux-fips).
카테고리:

Is There Water on Mars?

Slashdot - 월, 2025/05/12 - 8:34오후
Evidence is mounting for "a vast reservoir of liquid water" on Mars, according to a new article by Australian National University professor Hrvoje TkalÄiÄ and geophysics associate professor Weijia Sun from the Chinese Academy of Geological Sciences, announcing their recently published paper. "Using seismic data from NASA's InSight mission, we uncovered evidence that the seismic waves slow down in a layer between 5.4 and 8 kilometres below the surface, which could be because of the presence of liquid water at these depths." Mars is covered in traces of ancient bodies of water. But the puzzle of exactly where it all went when the planet turned cold and dry has long intrigued scientists... Billions of years ago, during the Noachian and Hesperian periods (4.1 billion to 3 billion years ago), rivers carved valleys and lakes shimmered. As Mars' magnetic field faded and its atmosphere thinned, most surface water vanished. Some escaped to space, some froze in polar caps, and some was trapped in minerals, where it remains today. But evaporation, freezing and rocks can't quite account for all the water that must have covered Mars in the distant past. Calculations suggest the "missing" water is enough to cover the planet in an ocean at least 700 metres deep, and perhaps up to 900 metres deep. One hypothesis has been that the missing water seeped into the crust. Mars was heavily bombarded by meteorites during the Noachian period, which may have formed fractures that channelled water underground. Deep beneath the surface, warmer temperatures would keep the water in a liquid state — unlike the frozen layers nearer the surface. In 2018, NASA's InSight lander touched down on Mars to listen to the planet's interior with a super-sensitive seismometer. By studying a particular kind of vibration called "shear waves", we found a significant underground anomaly: a layer between 5.4 and 8 kilometres down where these vibrations move more slowly. This "low-velocity layer" is most likely highly porous rock filled with liquid water, like a saturated sponge. Something like Earth's aquifers, where groundwater seeps into rock pores. We calculated the "aquifer layer" on Mars could hold enough water to cover the planet in a global ocean 520-780m deep. InSight's seismometer captured vibrations between the crust of Mars and its lower layers from two meteorite impacts in 2021 and a Marsquake in 2022. "These signatures let us pinpoint boundaries where rock changes, revealing the water-soaked layer 5.4 to 8 kilometres deep." It's an exciting possibility. "Purified, it could provide drinking water, oxygen, or fuel for rockets." And since microbes thrives on earth in deep rocks filled with water, "Could similar life, perhaps relics of ancient Martian ecosystems, persist in these reservoirs?"

Read more of this story at Slashdot.

카테고리:

US and China Agree To Temporarily Slash Tariffs

Slashdot - 월, 2025/05/12 - 5:26오후
The United States and China said Monday they reached an agreement to temporarily reduce the tariffs [non-paywalled source] they have imposed on each other in an attempt to defuse the trade war threatening the world's two largest economies. From a report: In a joint statement, the countries said they would suspend their respective tariffs for 90 days while they negotiate. Under the agreement, the United States would reduce the tariff on Chinese imports to 30 percent from its current 145 percent, while China would lower its import duty on American goods to 10 percent from 125 percent. "We concluded that we have a shared interest," said Treasury Secretary Scott Bessent at a news conference in Geneva where U.S. and Chinese officials met over the weekend. "The consensus from both delegations is that neither side wanted a decoupling," he said. The agreement breaks an impasse that had brought trade between China and the United States to a halt. Many American businesses had suspended orders, holding out hope that the two countries could strike a deal to bring down the tariff rates while raising the spectre of price increases.

Read more of this story at Slashdot.

카테고리:

US Copyright Office to AI Companies: Fair Use Isn't 'Commercial Use of Vast Troves of Copyrighted Works'

Slashdot - 월, 2025/05/12 - 4:34오후
Business Insider tells the story in three bullet points: - Big Tech companies depend on content made by others to train their AI models. - Some of those creators say using their work to train AI is copyright infringement. - The U.S. Copyright Office just published a report that indicates it may agree. The office released on Friday its latest in a series of reports exploring copyright laws and artificial intelligence. The report addresses whether the copyrighted content AI companies use to train their AI models qualifies under the fair use doctrine. AI companies are probably not going to like what they read... AI execs argue they haven't violated copyright laws because the training falls under fair use. According to the U.S. Copyright Office's new report, however, it's not that simple. "Although it is not possible to prejudge the result in any particular case, precedent supports the following general observations," the office said. "Various uses of copyrighted works in AI training are likely to be transformative. The extent to which they are fair, however, will depend on what works were used, from what source, for what purpose, and with what controls on the outputs — all of which can affect the market." The office made a distinction between AI models for research and commercial AI models. "When a model is deployed for purposes such as analysis or research — the types of uses that are critical to international competitiveness — the outputs are unlikely to substitute for expressive works used in training," the office said. "But making commercial use of vast troves of copyrighted works to produce expressive content that competes with them in existing markets, especially where this is accomplished through illegal access, goes beyond established fair use boundaries." The report says outputs "substantially similar to copyrighted works in the dataset" are less likely to be considered transformative than when the purpose "is to deploy it for research, or in a closed system that constrains it to a non-substitutive task." "A day after the office released the report, President Donald Trump fired its director, Shira Perlmutter, a spokesperson told Business Insider."

Read more of this story at Slashdot.

카테고리:

Videogame's Players Launch Boycott Over Bugs, Story Changes, Monetization

Slashdot - 월, 2025/05/12 - 1:34오후
It's been a mobile-only game for decades. Then a little more than a week ago Infinity Nikkireleased its 1.5 update (which introduced multiplayer and customization options) and launched the game on Steam. But it "didn't go over as planned," writes the worker-owned gaming site Aftermath, citing some very negative reactions on Reddit. (Some players say that in response the game's publisher is now even censoring the word "boycott" on its official forums and community spaces...) Infinity Nikki players were immediately incensed by a bevy of bugs and general game instability, and made even more angry by several baffling changes to both the story and its monetization structure... Players globally are vowing to stay off the game until Infold Games addresses their concerns, including at least one Infinity Nikki creator who is part of the game's partner program... [T]he Chinese Infinity Nikki community — as well as others — has been flooding Steam with negative reviews of the game... [T]he complaints are also impacting Infinity Nikki's review score on the Google Play Store... The company said it's working to fix the patch's performance issues, which have caused game-breaking bugs for some players.... [T]he Infinity Nikki team also gave players some free currency, but there's been problems there, too: Players say Infold had a bug in this distribution, which awarded players too much free currency. Instead of letting players keep that — it was Infold's mistake, after all — they deducted the currency, some of which players had already spent, putting them in the negative. But the community is looking for more from the studio; it wants an acknowledgement of the "dumpster fire" of a situation, as one Infinity Nikki player told Aftermath, but also wants some of the biggest problems reversed... Beyond the problematic monetization strategy, players Aftermath spoke with said they're also pissed off at a major change to the start of the game... Infold Games removed the game's original start with the update; the new intro drops players into Infinity Nikki with little context and a new, unexplained character who is supposed to be a guide as Nikki is dropped into intergalactic limbo. While the spend-to-upgrade-your-character model has always been inherently predatory, as one player put it, the new update pushed the system "much too far for a lot of players," according to the article — "something made more egregious by the numerous bugs and strange gameplay changes." The article now describes some players as "upset that the trust they've given Infold Games thus far has been broken." "Infold Games has not responded to a request for comment."

Read more of this story at Slashdot.

카테고리:

Kernel prepatch 6.15-rc6

lwn.net - 월, 2025/05/12 - 1:22오후
Linus has released 6.15-rc6 for testing.

Everything still looks fairly normal - we've got a bit more commits than we did in rc5, which isn't the trend I want to see as the release progresses, but the difference isn't all that big and it feels more like just the normal noise in timing fluctuation in pull requests of fixes than any real signal.

So I won't worry about it. We've got another two weeks to go in the normal release schedule, and it still feels like everything is on track.

카테고리:

Apple's iPhone Plans for 2027: Foldable, or Glass and Curved. (Plus Smart Glasses, Tabletop Robot)

Slashdot - 월, 2025/05/12 - 10:46오전
An anonymous reader shared this report from the Verge: This morning, while summarizing an Apple "product blitz" he expects for 2027, Bloomberg's Mark Gurman writes in his Power On newsletter that Apple is planning a "mostly glass, curved iPhone" with no display cutouts for that year, which happens to be the iPhone's 20th anniversary... [T]he closest hints are probably in Apple patents revealed over the years, like one from 2019 that describes a phone encased in glass that "forms a continuous loop" around the device. Apart from a changing iPhone, Gurman describes what sounds like a big year for Apple. He reiterates past reports that the first foldable iPhone should be out by 2027, and that the company's first smart glasses competitor to Meta Ray-Bans will be along that year. So will those rumored camera-equipped AirPods and Apple Watches, he says. Gurman also suggests that Apple's home robot — a tabletop robot that features "an AI assistant with its own personality" — will come in 2027... Finally, Gurman writes that by 2027 Apple could finally ship an LLM-powered Siri and may have created new chips for its server-side AI processing. Earlier this week Bloomberg reported that Apple is also "actively looking at" revamping the Safari web browser on its devices "to focus on AI-powered search engines." (Apple's senior VP of services "noted that searches on Safari dipped for the first time last month, which he attributed to people using AI.")

Read more of this story at Slashdot.

카테고리:

Researchers Just Solved a Big, 70-Year-Old Problem for Fusion Energy

Slashdot - 월, 2025/05/12 - 8:26오전
Fusion energy "took one step closer to reality," announced the University of Texas at Austin, as their researchers joined with a team from Los Alamos National Laboratory and Type One Energy Group and "solved a longstanding problem in the field" — how to contain high-energy particles inside fusion reactors. When high-energy alpha particles leak from a reactor, that prevents the plasma from getting hot and dense enough to sustain the fusion reaction. To prevent them from leaking, engineers design elaborate magnetic confinement systems, but there are often holes in the magnetic field, and a tremendous amount of computational time is required to predict their locations and eliminate them. In their paper published in Physical Review Letters, the research team describes having discovered a shortcut that can help engineers design leak-proof magnetic confinement systems 10 times as fast as the gold standard method, without sacrificing accuracy... "What's most exciting is that we're solving something that's been an open problem for almost 70 years," said Josh Burby, assistant professor of physics at UT and first author of the paper. "It's a paradigm shift in how we design these reactors...." This new method also can help with a similar but different problem in another popular magnetic fusion reactor design called a tokamak. In that design, there's a problem with runaway electrons — high-energy electrons that can punch a hole in the surrounding walls. This new method can help identify holes in the magnetic field where these electrons might leak.

Read more of this story at Slashdot.

카테고리:

Over 3,200 Cursor Users Infected by Malicious Credential-Stealing npm Packages

Slashdot - 월, 2025/05/12 - 7:26오전
Cybersecurity researchers have flagged three malicious npm packages that target the macOS version of AI-powered code-editing tool Cursor, reports The Hacker News: "Disguised as developer tools offering 'the cheapest Cursor API,' these packages steal user credentials, fetch an encrypted payload from threat actor-controlled infrastructure, overwrite Cursor's main.js file, and disable auto-updates to maintain persistence," Socket researcher Kirill Boychenko said. All three packages continue to be available for download from the npm registry. "Aiide-cur" was first published on February 14, 2025... In total, the three packages have been downloaded over 3,200 times to date.... The findings point to an emerging trend where threat actors are using rogue npm packages as a way to introduce malicious modifications to other legitimate libraries or software already installed on developer systems... "By operating inside a legitimate parent process — an IDE or shared library — the malicious logic inherits the application's trust, maintains persistence even after the offending package is removed, and automatically gains whatever privileges that software holds, from API tokens and signing keys to outbound network access," Socket told The Hacker News. "This campaign highlights a growing supply chain threat, with threat actors increasingly using malicious patches to compromise trusted local software," Boychenko said. The npm packages "restart the application so that the patched code takes effect," letting the threat actor "execute arbitrary code within the context of the platform."

Read more of this story at Slashdot.

카테고리:

How Spaceport America Will Grow

Slashdot - 월, 2025/05/12 - 6:02오전
18 years ago Slashdot covered the creation of Spaceport America. Today Space.com hails it as "the first purpose-built commercial spaceport in the world." But engineer/executive director Scott McLaughlin has plans to grow even more. Already home to an array of commercial space industry tenants, such as Virgin Galactic, SpinLaunch, Up Aerospace, and Prismatic, Spaceport America is a "rocket-friendly environment of 6,000 square miles of restricted airspace, low population density, a 12,000-foot by 200-foot runway, vertical launch complexes, and about 340 days of sunshine and low humidity," the organization boasts on its website... Space.com: What changes do you see that make Spaceport America even more viable today? McLaughlin: I think opening ourselves up to doing different kinds of work. We're more like a civilian test range now. We've got high-altitude UAVs [Unmanned Aerial Vehicles]. We're willing to do engine production. We believe we're about to sign a data center, one that's able to provide services to our customers who want low-latency, artificial intelligence, or high-powered computing. You'll be able to rent some virtual machines and do your own thing and have it be instantaneous at the spaceport. So I think being more broadminded about what we can do at the spaceport is helping generate customers and revenue... Our goal is to see Virgin Galactic fly in a year or so, hopefully flying twice a week, and that will have a big impact on the spaceport... [W]e're trying to be open-minded as we're partnered with White Sands Missile Range to use that airspace. We're even looking at things like an electromagnetic pulse facility. It's a customer that I can't identify yet... We are working on a "reentry" license too. We recently discussed this with specialists and we think we have a site relatively close to the spaceport that's flat and free of mesquite bushes and such, so we can do capsule return and other types of return. And of course we have the runway. So I'd think we'd be the only spaceport that does vertical and horizontal launch and reentry.... We're never going to have the throughput that the Cape in Florida has. But we'll be a good alternative especially if you're going to do a small to medium-sized launch, and you need to do it quickly, and perhaps do it more securely than you would if you were to fly over water. That's why the Department of Defense is showing interest in the inland spaceport.

Read more of this story at Slashdot.

카테고리:

Whoop Promises Free Upgrades - But Some Users Will Have to Pay to Extend Their Subscriptions

Slashdot - 월, 2025/05/12 - 5:02오전
Whoop fitness trackers had promised free upgrades to anyone who'd been a member for at least six months — and then reneged. "After customers began complaining, the company responded with a Reddit post, according to a report from TechCrunch: Now, anyone with more than 12 months remaining on their subscription is eligible for a free upgrade to Whoop 5.0 (or a refund if they've already paid the fee). And customers with less than 12 months can extend their subscription to get the upgrade at no additional cost. Whoop acknowledged that they'd previously said anyone who'd been a member for six months would receive a free upgrade. Friday they described that blog article as "incorrect". ("This was never our policy and should never have been posted... We removed that blog article... We're sorry for any confusion this may have caused.") TechCrunch explains: While the company said it's making these changes because it "heard your feedback," it also suggested that its apparent stinginess was tied to its transition from a [2021] model focused on monthly or six-month subscription plans to one where it only offers 12- and 24-month subscriptions... There's been a mixed response to these changes on the Whoop subreddit, with one moderator describing it as a "win for the community." Other posters were more skeptical, with one writing, "You don't publish a policy by accident and keep it up for years. Removing it after backlash doesn't erase the fact [that] it is real." Other changes announced by Whoop: "If you purchased or renewed a WHOOP 4.0 membership in the last 30 days before May 8, your upgrade fee will be automatically waived at checkout..." "If you've already upgraded to WHOOP 5.0 on Peak and paid a one-time upgrade fee despite having more than 12 months remaining, we'll refund that fee." "Thank you for your feedback. We remain committed to delivering the best technology, experience, and value to our community."

Read more of this story at Slashdot.

카테고리:

OpenAI Enters 'Tough Negotiation' With Microsoft, Hopes to Raise Money With IPO

Slashdot - 월, 2025/05/12 - 4:01오전
OpenAI is currently in "a tough negotiation" with Microsoft, the Financial Times reports, citing "one person close to OpenAI." On the road to building artificial general intelligence, OpenAI hopes to unlock new funding (and launch a future IPO), according to the article, which says both sides are at work "rewriting the terms of their multibillion-dollar partnership in a high-stakes negotiation...." Microsoft, meanwhile, wants to protect its access to OpenAI's cutting-edge AI models... [Microsoft] is a key holdout to the $260bn start-up's plans to undergo a corporate restructuring that moves the group further away from its roots as a non-profit with a mission to develop AI to "benefit humanity". A critical issue in the deliberations is how much equity in the restructured group Microsoft will receive in exchange for the more than $13bn it has invested in OpenAI to date. According to multiple people with knowledge of the negotiations, the pair are also revising the terms of a wider contract, first drafted when Microsoft first invested $1bn into OpenAI in 2019. The contract currently runs to 2030 and covers what access Microsoft has to OpenAI's intellectual property such as models and products, as well as a revenue share from product sales. Three people with direct knowledge of the talks said Microsoft is offering to give up some of its equity stake in OpenAI's new for-profit business in exchange for accessing new technology developed beyond the 2030 cut off... Industry insiders said a failure of OpenAI's new plan to make its business arm a public benefits corporation could prove a critical blow. That would hit OpenAI's ability to raise more cash, achieve a future float, and obtain the financial resources to take on Big Tech rivals such as Google. That has left OpenAI's future at the mercy of investors, such as Microsoft, who want to ensure they gain the benefit of its enormous growth, said Dorothy Lund, professor of law at Columbia Law School. Lund says OpenAI's need for investors' money means they "need to keep them happy." But there also appears to be tension from how OpenAI competes with Microsoft (like targeting its potential enterprise customers with AI products). And the article notes that OpenAI also turned to Oracle (and SoftBank) for its massive AI infrastructure project Stargate. One senior Microsoft employee complained that OpenAI "says to Microsoft, 'give us money and compute and stay out of the way: be happy to be on the ride with us'. So naturally this leads to tensions. To be honest, that is a bad partner attitude, it shows arrogance." The article's conclusion? Negotiating new deal is "critical to OpenAI's restructuring efforts and could dictate the future of a company..."

Read more of this story at Slashdot.

카테고리:

'Who Needs Rust's Borrow-Checking Compiler Nanny? C++ Devs Aren't Helpless'

Slashdot - 월, 2025/05/12 - 3:01오전
"When Rust developers think of us C++ folks, they picture a cursed bloodline," writes professional game developer Mamadou Babaei (also a *nix enthusiast who contributes to the FreeBSD Ports collection). "To them, every line of C++ we write is like playing Russian Roulette — except all six chambers are loaded with undefined behavior." But you know what? We don't need a compiler nanny. No borrow checker. No lifetimes. No ownership models. No black magic. Not even Valgrind is required. Just raw pointers, raw determination, and a bit of questionable sanity. He's created a video on "how to hunt down memory leaks like you were born with a pointer in one hand and a debugger in the other." (It involves using a memory leak tracker — specifically, Visual Studio's _CrtDumpMemoryLeaks, which according to its documentation "dumps all the memory blocks in the debug heap when a memory leak has occurred," identifying the offending lines and pointers.) "If that sounds unreasonably dangerous — and incredibly fun... let's dive into the deep end of the heap." "The method is so easy, it renders Rust's memory model (lifetimes, ownership) and the borrow checker useless!" writes Slashdot reader NuLL3rr0r. Does anybody agree with him? Share your own experiences and reactions in the comments. And how do you feel about Rust's "borrow-checking compiler nanny"?

Read more of this story at Slashdot.

카테고리:

Chinese Hackers Exploit SAP NetWeaver RCE Flaw

Slashdot - 월, 2025/05/12 - 1:34오전
"A China-linked unnamed threat actor dubbed Chaya_004 has been observed exploiting a recently disclosed security flaw in SAP NetWeaver," reports The Hacker News: Forescout Vedere Labs, in a report published Thursday, said it uncovered a malicious infrastructure likely associated with the hacking group weaponizing CVE-2025-31324 (CVSS score: 10.0) since April 29, 2025. CVE-2025-31324 refers to a critical SAP NetWeaver flaw that allows attackers to achieve remote code execution (RCE) by uploading web shells through a susceptible "/developmentserver/metadatauploader" endpoint. The vulnerability was first flagged by ReliaQuest late last month when it found the shortcoming being abused in real-world attacks by unknown threat actors to drop web shells and the Brute Ratel C4 post-exploitation framework. According to [SAP cybersecurity firm] Onapsis, hundreds of SAP systems globally have fallen victim to attacks spanning industries and geographies, including energy and utilities, manufacturing, media and entertainment, oil and gas, pharmaceuticals, retail, and government organizations. Onapsis said it observed reconnaissance activity that involved "testing with specific payloads against this vulnerability" against its honeypots as far back as January 20, 2025. Successful compromises in deploying web shells were observed between March 14 and March 31. "In recent days, multiple threat actors are said to have jumped aboard the exploitation bandwagon to opportunistically target vulnerable systems to deploy web shells and even mine cryptocurrency..." Thanks to Slashdot reader bleedingobvious for sharing the news.

Read more of this story at Slashdot.

카테고리:

페이지

KLDP 수집기 구독하기