RSS 생중계
[$] A free and open-source rootkit for Linux
While there are several rootkits that target Linux, they have so far not fully embraced the open-source ethos typical of Linux software. Luckily, Matheus Alves has been working to remedy this lack by creating an open-source rootkit called Singularity for Linux systems. Users who feel their computers are too secure can install the Singularity kernel module in order to allow remote code execution, disable security features, and hide files and processes from normal administrative tools. Despite its many features, Singularity is not currently known to be in use in the wild — instead, it provides security researchers with a testbed to investigate new detection and evasion techniques.
Verizon Offers $20 Credit After Nationwide Outage Stranded Users in SOS Mode For Hours
Read more of this story at Slashdot.
AI Has Made Salesforce Engineers More Productive, So the Company Has Stopped Hiring Them, CEO Says
Read more of this story at Slashdot.
Ruby on Rails Creator Says AI Coding Tools Still Can't Match Most Junior Programmers
Read more of this story at Slashdot.
China Clamps Down on High-Speed Traders, Removing Servers
Read more of this story at Slashdot.
Hard Drive Prices Have Surged By an Average of 46% Since September
Read more of this story at Slashdot.
Security updates for Friday
Code.org: Use AI In an Interview Without Our OK and You're Dead To Us
Read more of this story at Slashdot.
Amazon Is Buying America's First New Copper Output In More Than a Decade
Read more of this story at Slashdot.
'Star Wars' Boss Kathleen Kennedy Steps Down From Lucasfilm
Read more of this story at Slashdot.
US Carbon Pollution Rose In 2025, a Reversal From Prior Years
Read more of this story at Slashdot.
Study Finds Weak Evidence Linking Social Media Use to Teen Mental Health Problems
Read more of this story at Slashdot.
Amazon Is Making a Fallout Shelter Competition Reality TV Show
Read more of this story at Slashdot.
New York Introduces Legislation To Crack Down On 3D Printers That Make Ghost Guns
Read more of this story at Slashdot.
Iran's Internet Shutdown Is Now One of the Longest Ever
Read more of this story at Slashdot.
A 0-click exploit chain for the Pixel 9 (Project Zero)
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One effect of this change is increased 0-click attack surface, as efficient analysis often requires message media to be decoded before the message is opened by the user. One such feature is audio transcription. Incoming SMS and RCS audio attachments received by Google Messages are now automatically decoded with no user interaction. As a result, audio decoders are now in the 0-click attack surface of most Android phones.
The blog entry does not question the wisdom of directly exposing audio decoders to external attackers, but it does provide a lot of detail showing how it can go wrong. The first part looks at compromising the codec; part two extends the exploit to the kernel, and part three looks at the implications:
It is alarming that it took 139 days for a vulnerability exploitable in a 0-click context to get patched on any Android device, and it took Pixel 54 days longer. The vulnerability was public for 82 days before it was patched by Pixel.
Astronauts Splash Down To Earth After Medical Evacuation From ISS
Read more of this story at Slashdot.
ASUS Stops Producing Nvidia RTX 5070 Ti and 5060 Ti 16GB
Read more of this story at Slashdot.
Italy's Privacy Watchdog, Scourge of US Big Tech, Hit By Corruption Probe
Read more of this story at Slashdot.
Oracle Trying To Lure Workers To Nashville For New 'Global' HQ
Read more of this story at Slashdot.
