RSS 생중계

Collapse of National Security Elites' Cyber Firm Leaves Bitter Wake

Slashdot - 토, 2024/10/05 - 2:22오전
Cybersecurity firm IronNet, founded by former NSA director Keith Alexander, has collapsed after failing to deliver on its promise to revolutionize cyber defense. The company, which went public in 2021 with a $3 billion valuation, shut down in September 2023 after running out of money. IronNet's downfall has left investors and former employees bitter, with some accusing the company of misleading them about its financial health. "I'm honestly ashamed that I was ever an executive at that company," said Mark Berly, a former IronNet vice president. He said the company's top leaders cultivated a culture of deceit "just like Theranos." Critics point to questionable business practices, subpar products, and associations that potentially exposed the firm to Russian influence. The company's board included high-profile national security figures, which helped attract investments and contracts. However, IronNet struggled to secure major deals and meet revenue projections.

Read more of this story at Slashdot.

카테고리:

Apple Fixes Bug That Let VoiceOver Shout Your Passwords

Slashdot - 토, 2024/10/05 - 1:44오전
Apple just fixed a duo of security bugs in iOS 18.0.1 and iPadOS 18.0.1, one of which might cause users' saved passwords to be read aloud. It's hardly an ideal situation for the visually impaired. From a report: For those who rely on the accessibility features baked into their iGadgets, namely Apple's VoiceOver screen reader, now is a good time to apply the latest update. In typical Apple fashion, the company hasn't released much in the way of details about the first security issue, tracked as CVE-2024-44204, which makes it tougher to understand the conditions under which this vulnerability could be triggered, or how to avoid it until the update is applied. What we do know is that it was characterized as a logic issue, which Apple rectified by improving validation. The disclosure of the bug comes less than a month after iOS 18 and iPadOS 18 debuted. Ironically, this release included Apple's first native password manager, the Passwords app.

Read more of this story at Slashdot.

카테고리:

[$] Smart pointers for the kernel

lwn.net - 토, 2024/10/05 - 1:38오전

Rust has a plethora of smart-pointer types, including reference-counted pointers, which have special support in the compiler to make them easier to use. The Rust-for-Linux project would like to reap those same benefits for its smart pointers, which need to be written by hand to conform to the Linux kernel memory model. Xiangfei Ding presented at Kangrejos about the work to enable custom smart pointers to function the same as built-in smart pointers.

카테고리:

Antarctica is 'Greening' at Dramatic Rate as Climate Heats

Slashdot - 토, 2024/10/05 - 1:04오전
Plant cover across the Antarctic peninsula has soared more than tenfold over the last few decades, as the climate crisis heats up the icy continent. From a report: Analysis of satellite data found there was less than one sq kilometre of vegetation in 1986 but there was almost 12km2 of green cover by 2021. The spread of the plants, mostly mosses, has accelerated since 2016, the researchers found. The growth of vegetation on a continent dominated by ice and bare rock is a sign of the reach of global heating into the Antarctic, which is warming faster than the global average. The scientists warned that this spread could provide a foothold for alien invasive species into the pristine Antarctic ecosystem. Greening has also been reported in the Arctic, and in 2021 rain, not snow, fell on the summit of Greenland's huge ice cap for the first time on record. "The Antarctic landscape is still almost entirely dominated by snow, ice and rock, with only a tiny fraction colonised by plant life," said Dr Thomas Roland, at the University of Exeter, UK, and who co-led the study. "But that tiny fraction has grown dramatically -- showing that even this vast and isolated wilderness is being affected by human-caused climate change." The peninsula is about 500,000km2 in total. Roland warned that future heating, which will continue until carbon emissions are halted, could bring "fundamental changes to the biology and landscape of this iconic and vulnerable region." The study is published in the journal Nature Geoscience and based on analysis of Landsat images.

Read more of this story at Slashdot.

카테고리:

Three Friday kernel updates

lwn.net - 토, 2024/10/05 - 12:39오전

The 6.11.2, 6.10.13, and 6.6.54 stable kernels have been released. They contain important fixes, and upgrading is, as always, recommended.

카테고리:

oath-toolkit: privilege escalation in pam_oath.so (SUSE Security Team Blog)

lwn.net - 토, 2024/10/05 - 12:28오전

The SUSE Security Team Blog has a detailed report on its discovery of a privilege escalation in the oath-toolkit, which provides libraries and utilities for managing one-time password (OTP) authentication.

Fellow SUSE engineer Fabian Vogt approached our Security Team about the project's PAM module. A couple of years ago, the module gained a feature which allows to place the OTP state file (called usersfile) in the home directory of the to-be-authenticated user. Fabian noticed that the PAM module performs unsafe file operations in users' home directories. Since PAM stacks typically run as root, this can easily cause security issues.

카테고리:

Rivian Now Says It Will Make Fewer Electric Vehicles This Year Than It Did in 2023

Slashdot - 토, 2024/10/05 - 12:24오전
Rivian said it would make fewer electric vehicles this year than it did in 2023, resulting from a parts shortage. From a report: The news came as the company reported third quarter production and delivery numbers that came in below analyst expectations. Rivian says it expects to produce between 47,000 and 49,000 vehicles this year, down from the 57,000 vehicles it originally forecast. That number was flat from the previous year, when the company produced 57,232 vehicles and delivered 50,122. Rivian said the disruption is due to "a shortage of a shared component on the R1 and RCV platforms," referencing the company's R1T and R1S vehicles, as well as its commercial van platform. "This supply shortage impact began in Q3 of this year, has become more acute in recent weeks and continues," the company added.

Read more of this story at Slashdot.

카테고리:

Tencent, Guillemot Family Mull Ubisoft Buyout Amid Share Slump

Slashdot - 금, 2024/10/04 - 11:41오후
Tencent and Ubisoft's founding Guillemot family are weighing a potential buyout of the French game maker, according to Bloomberg News. The move comes as Ubisoft's shares plunged 54% this year, hitting decade-lows after production delays and weak sales. Tencent, which bought 49.9% of Guillemot Brothers in 2022, holds 9.2% of Ubisoft's voting rights, while the Guillemots control 20.5%. Further reading: Star Wars Outlaws Is A Crappy Masterpiece.

Read more of this story at Slashdot.

카테고리:

159 Employees Leave Automattic as WordPress CEO Escalates Fight With WP Engine

Slashdot - 금, 2024/10/04 - 11:00오후
Automattic, the company behind WordPress, has seen a reduction of about 8.4% to its workforce after 159 employees accepted severance packages, CEO Matt Mullenweg said. The move follows disputes over the company's direction and its clash with web host WP Engine. Most departures hit the WordPress division, with some from other business units. Employees received $30,000 or six months' pay, but are ineligible for rehire, Mullenweg added.

Read more of this story at Slashdot.

카테고리:

Security updates for Friday

lwn.net - 금, 2024/10/04 - 10:53오후
Security updates have been issued by AlmaLinux (firefox, golang, linux-firmware, and thunderbird), Debian (kernel and zabbix), Fedora (firefox, pgadmin4, and php), Mageia (chromium-browser-stable, cjson, hostapd and wpa_supplicant, and openjpeg2), Oracle (firefox, flatpak, and go-toolset:ol8), Red Hat (cups-filters, firefox, grafana, linux-firmware, python3, python3.11, and python3.9), SUSE (expat, firefox, libpcap, and opensc), and Ubuntu (freeradius, imagemagick, and unzip).
카테고리:

Cloudflare Defeats Patent Troll

Slashdot - 금, 2024/10/04 - 10:00오후
Cloudflare has emerged victorious in a patent infringement lawsuit against Sable Networks, securing a $225,000 settlement and forcing the patent holder to dedicate its entire portfolio to the public domain. The case, which began in March 2021 with Sable asserting nearly 100 claims across four patents, concluded after a Texas jury found Cloudflare not guilty of infringement in February 2024. Sable, described by Cloudflare as a "patent troll," had previously sued several tech companies, including Cisco and Juniper Networks, who settled out of court. Cloudflare's aggressive defense strategy included launching Project Jengo, a crowd-sourced initiative to invalidate Sable's patents. The settlement prevents Sable from asserting these patents against any other company in the future, marking a significant blow to patent trolling practices in the tech industry. In a blog post, Cloudflare adds: While this $225,000 can't fully compensate us for the time, energy and frustration of having to deal with this litigation for nearly three years, it does help to even the score a bit. And we hope that it sends an important message to patent trolls everywhere to beware before taking on Cloudflare.

Read more of this story at Slashdot.

카테고리:

AI Agent Promotes Itself To Sysadmin, Trashes Boot Sequence

Slashdot - 금, 2024/10/04 - 7:00오후
The Register's Thomas Claburn reports: Buck Shlegeris, CEO at Redwood Research, a nonprofit that explores the risks posed by AI, recently learned an amusing but hard lesson in automation when he asked his LLM-powered agent to open a secure connection from his laptop to his desktop machine. "I expected the model would scan the network and find the desktop computer, then stop," Shlegeris explained to The Register via email. "I was surprised that after it found the computer, it decided to continue taking actions, first examining the system and then deciding to do a software update, which it then botched." Shlegeris documented the incident in a social media post. He created his AI agent himself. It's a Python wrapper consisting of a few hundred lines of code that allows Anthropic's powerful large language model Claude to generate some commands to run in bash based on an input prompt, run those commands on Shlegeris' laptop, and then access, analyze, and act on the output with more commands. Shlegeris directed his AI agent to try to SSH from his laptop to his desktop Ubuntu Linux machine, without knowing the IP address [...]. As a log of the incident indicates, the agent tried to open an SSH connection, and failed. So Shlegeris tried to correct the bot. [...] The AI agent responded it needed to know the IP address of the device, so it then turned to the network mapping tool nmap on the laptop to find the desktop box. Unable to identify devices running SSH servers on the network, the bot tried other commands such as "arp" and "ping" before finally establishing an SSH connection. No password was needed due to the use of SSH keys; the user buck was also a sudoer, granting the bot full access to the system. Shlegeris's AI agent, once it was able to establish a secure shell connection to the Linux desktop, then decided to play sysadmin and install a series of updates using the package manager Apt. Then things went off the rails. "It looked around at the system info, decided to upgrade a bunch of stuff including the Linux kernel, got impatient with Apt and so investigated why it was taking so long, then eventually the update succeeded but the machine doesn't have the new kernel so edited my Grub [bootloader] config," Buck explained in his post. "At this point I was amused enough to just let it continue. Unfortunately, the computer no longer boots." Indeed, the bot got as far as messing up the boot configuration, so that following a reboot by the agent for updates and changes to take effect, the desktop machine wouldn't successfully start.

Read more of this story at Slashdot.

카테고리:

Cheetos Food Dye Turns Mice Transparent

Slashdot - 금, 2024/10/04 - 4:00오후
Researchers have discovered that a popular food dye used in Cheetos "alters the optical qualities of skin, allowing light to pass through (Source paywalled; alternative source)," according to the Wall Street Journal. Larger doses of the dye used on humans could make searching veins for blood draw easier. From a report: Tartrazine, the yellowing agent for the "dangerously cheesy" snack, was tested on the stomachs and heads of mice -- with surprising results. Researchers were even able to see muscle pulsations and blood vessels in their brains, the Wall Street Journal reported. How does this ultimate magic trick work? It has to do with how cells are comprised of membranes that hold fats in a watery style, the outlet stated. The fats and water manage light differently. In this case, when the dye is applied, it causes light to pass through when it hits their cells. Thus, ta-da! the transparent opacity of invisible mice skin. The findings have been published in the journal Science.

Read more of this story at Slashdot.

카테고리:

23andMe Is On the Brink. What Happens To All Its DNA Data?

Slashdot - 금, 2024/10/04 - 12:30오후
The one-and-done nature of 23andMe is "indicative of a core business problem with the once high-flying biotech company that is now teetering on the brink of collapse," reports NPR. As 23andMe struggles for survival, many of its 15 million customers are left wondering what the company plans to do with all the data it has collected since it was founded in 2006. An anonymous reader shares an excerpt from the report: Andy Kill, a spokesperson for 23andMe, would not comment on what the company might do with its trove of genetic data beyond general pronouncements about its commitment to privacy. "For our customers, our focus continues to be on transparency and choice over how they want their data to be managed," he said. When signing up for the service, about 80% of 23andMe's customers have opted in to having their genetic data analyzed for medical research. "This rate has held steady for many years," Kill added. The company has an agreement with pharmaceutical giant GlaxoSmithKline, or GSK, that allows the drugmaker to tap the tech company's customer data to develop new treatments for disease. Anya Prince, a law professor at the University of Iowa's College of Law who focuses on genetic privacy, said those worried about their sensitive DNA information may not realize just how few federal protections exist. For instance, the Health Insurance Portability and Accountability Act, also known as HIPAA, does not apply to 23andMe since it is a company outside of the health care realm. "HIPAA does not protect data that's held by direct-to-consumer companies like 23andMe," she said. Although DNA data has no federal safeguards, some states, like California and Florida, do give consumers rights over their genetic information. "If customers are really worried, they could ask for their samples to be withdrawn from these databases under those laws," said Prince. According to the company, all of its genetic data is anonymized, meaning there is no way for GSK, or any other third party, to connect the sample to a real person. That, however, could make it nearly impossible for a customer to renege on their decision to allow researchers to access their DNA data. "I couldn't go to GSK and say, 'Hey, my sample was given to you -- I want that taken out -- if it was anonymized, right? Because they're not going to re-identify it just to pull it out of the database," Prince said. Vera Eidelman, a staff attorney with the American Civil Liberties Union who specializes in privacy and technology policy, said the patchwork of state laws governing DNA data makes the generic data of millions potentially vulnerable to being sold off, or even mined by law enforcement. "Having to rely on a private company's terms of service or bottom line to protect that kind of information is troubling -- particularly given the level of interest we've seen from government actors in accessing such information during criminal investigations," Eidelman said. She points to how investigators used a genealogy website to identify the man known as the Golden State Killer, and how police homed in on an Idaho murder suspect by turning to similar databases of genetic profiles. "This has happened without people's knowledge, much less their express consent," Eidelman said. Neither case relied on 23andMe, and spokesperson Kill said the company does not allow law enforcement to search its database. The company has, however, received subpoenas to access its genetic information. According to 23andMe's transparency report, authorities have sought genetic data on 15 individuals since 2015, but the company has resisted the requests and never produced data for investigators. "We treat law enforcement inquiries, such as a valid subpoena or court order, with the utmost seriousness. We use all legal measures to resist any and all requests in order to protect our customers' privacy," Kill said. [...] In a September filing to financial regulators, [23andMe CEO Anne Wojcicki] wrote: "I remain committed to our customers' privacy and pledge," meaning the company's rules requiring consent for DNA to be used for research would remain in place, as well as allowing customers to delete their data. Wojcicki added that she is no longer considering offers to buy the company after previously saying she was.

Read more of this story at Slashdot.

카테고리:

Fly Brain Breakthrough 'Huge Leap' To Unlock Human Mind

Slashdot - 금, 2024/10/04 - 10:25오전
fjo3 shares a report from the BBC: They can walk, hover and the males can even sing love songs to woo mates -- all this with a brain that's tinier than a pinhead. Now for the first time scientists researching the brain of a fly have identified the position, shape and connections of every single one of its 130,000 cells and 50 million connections. It's the most detailed analysis of the brain of an adult animal ever produced. One leading brain specialist independent of the new research described the breakthrough as a "huge leap" in our understanding of our own brains. One of the research leaders said it would shed new light into âoethe mechanism of thought." [...] The images the scientists have produced, which have been published in the journal Nature, show a tangle of wiring that is as beautiful as it is complex. Its shape and structure holds the key to explaining how such a tiny organ can carry out so many powerful computational tasks. Developing a computer the size of a poppy seed capable of all these tasks is way beyond the ability of modern science. Dr Mala Murthy, another of the projectâ(TM)s co-leaders, from Princeton University, said the new wiring diagram, known scientifically as a connectome, would be âoetransformative for neuroscientists." [...] The researchers have been able to identify separate circuits for many individual functions and show how they are connected. The wires involved with movement for example are at the base of the brain, whereas those for processing vision are towards the side. There are many more neurons involved in the latter because seeing requires much more computational power. While scientists already knew about the separate circuits they did not know how they were connected together. Anyone can view and download the fly connectome here.

Read more of this story at Slashdot.

카테고리:

OpenAI Launches New 'Canvas' ChatGPT Interface Tailored To Writing and Coding Projects

Slashdot - 금, 2024/10/04 - 9:45오전
OpenAI has introduced "canvas," a new interface for ChatGPT that provides a separate workspace for writing and coding projects. "Canvas is rolling out in beta to ChatGPT Plus and Teams users on Thursday, and Enterprise and Edu users next week," reports TechCrunch. "Once canvas is out of beta, OpenAI says it plans to offer the feature to free users as well." From the report: In our demo, [OpenAI product manager Daniel Levine] had to select "GPT-4o with canvas" from ChatGPT's model picker drop down window. However, OpenAI says canvas windows will just pop out when ChatGPT detects a separate workspace could be helpful, say for longer outputs or complex coding tasks. You can also just write "use canvas" to automatically open a project window. Levine showed TechCrunch how ChatGPT's new features could help write an email. Users can prompt ChatGPT to generate an email, which will then pop out in the canvas window. Then users can toggle a slider to adjust the length of the writing to be shorter or longer. You can also highlight specific sentences, and ask ChatGPT to make changes such as "make this sound friendlier," or add emojis. Users can also ask ChatGPT to rewrite the whole email as-is in another language. The features for the coding canvas are slightly different. Levine prompted ChatGPT to create an API web server in Python, which spawned in the canvas window. By pressing an "add comments" button, ChatGPT will add in-line documentation to explain the code in plain English. Further, if you highlight a section of code that ChatGPT created, you can ask the chatbot to explain it to you, or ask questions about it. ChatGPT is also getting a new "review code" button, which will suggest specific edits for the code in the window, whether generated or user-written, for them to approve, edit themselves, or decline. If they press approve, ChatGPT will take a stab at fixing the bugs itself.

Read more of this story at Slashdot.

카테고리:

Mystery Creator of Bitcoin Identified, New HBO Documentary Claims

Slashdot - 금, 2024/10/04 - 9:02오전
A new HBO documentary directed by Emmy-nominated filmmaker Cullen Hoback claims to have revealed the true identity of the pseudonymous creator of Bitcoin, Satoshi Nakamoto. As Politico notes, Hoback "drew critical acclaim for his series 'Q: Into the Storm' that exposed the authors of the QAnon conspiracy theory." The bitcoin documentary is scheduled to air next Wednesday at 2 a.m. CET (Tuesday at 9 p.m. EST). From the report: [T]he exposure of Satoshi as its alleged creator threatens to raise some huge questions, not least his potential complicity in crimes that have featured Bitcoin use. It could also establish him as one of the world's richest people: Satoshi himself is estimated to control about 1.1 million Bitcoin, but it's unclear if he still has access to the cryptographic keys to the fortune. If he did, this would put his net worth at $66 billion at current valuations. Intriguingly, as the date for the airing of the documentary has drawn near, a number of high-value wallets from the "Satoshi era" have become active for the first time since 2009. According to Bitcoin Magazine, around 250 bitcoins -- worth approximately $15 million at Thursday's bitcoin rate of $60,754 to the dollar -- were drained from wallets in the past two weeks. While the coins are not officially linked to wallets used by Satoshi Nakamoto, they have been dormant since the earliest days of Bitcoin, when the cryptocurrency was worth almost nothing. The wallets' creators would certainly have been Satoshi's earliest collaborators. Satoshi Nakamoto's true identity remains one of the biggest mysteries of recent years.

Read more of this story at Slashdot.

카테고리:

A Single Cloud Compromise Can Feed an Army of AI Sex Bots

Slashdot - 금, 2024/10/04 - 8:20오전
An anonymous reader quotes a report from KrebsOnSecurity: Organizations that get relieved of credentials to their cloud environments can quickly find themselves part of a disturbing new trend: Cybercriminals using stolen cloud credentials to operate and resell sexualized AI-powered chat services. Researchers say these illicit chat bots, which use custom jailbreaks to bypass content filtering, often veer into darker role-playing scenarios, including child sexual exploitation and rape. Researchers at security firm Permiso Security say attacks against generative artificial intelligence (AI) infrastructure like Bedrock from Amazon Web Services (AWS) have increased markedly over the last six months, particularly when someone in the organization accidentally exposes their cloud credentials or key online, such as in a code repository like GitHub. Investigating the abuse of AWS accounts for several organizations, Permiso found attackers had seized on stolen AWS credentials to interact with the large language models (LLMs) available on Bedrock. But they also soon discovered none of these AWS users had enabled logging (it is off by default), and thus they lacked any visibility into what attackers were doing with that access. So Permiso researchers decided to leak their own test AWS key on GitHub, while turning on logging so that they could see exactly what an attacker might ask for, and what the responses might be. Within minutes, their bait key was scooped up and used in a service that offers AI-powered sex chats online. "After reviewing the prompts and responses it became clear that the attacker was hosting an AI roleplaying service that leverages common jailbreak techniques to get the models to accept and respond with content that would normally be blocked," Permiso researchers wrote in a report released today. "Almost all of the roleplaying was of a sexual nature, with some of the content straying into darker topics such as child sexual abuse," they continued. "Over the course of two days we saw over 75,000 successful model invocations, almost all of a sexual nature."

Read more of this story at Slashdot.

카테고리:

Cloudflare Blocks Largest Recorded DDoS Attack Peaking At 3.8Tbps

Slashdot - 금, 2024/10/04 - 7:40오전
BleepingComputer's Ionut Ilascu reports: During a distributed denial-of-service campaign targeting organizations in the financial services, internet, and telecommunications sectors, volumetric attacks peaked at 3.8 terabits per second, the largest publicly recorded to date. The assault consisted of a "month-long" barrage of more than 100 hyper-volumetric DDoS attacks flooding the network infrastructure with garbage data. In a volumetric DDoS attack, the target is overwhelmed with large amounts of data to the point that they consume the bandwidth or exhaust the resources of applications and devices, leaving legitimate users with no access. Many of the attacks aimed at the target's network infrastructure (network and transport layers L3/4) exceeded two billion packets per second (pps) and three terabits per second (Tbps). According to researchers at internet infrastructure company Cloudflare, the infected devices were spread across the globe but many of them were located in Russia, Vietnam, the U.S., Brazil, and Spain. The threat actor behind the campaign leveraged multiple types of compromised devices, which included a large number of Asus home routers, Mikrotik systems, DVRs, and web servers. Cloudflare mitigated all the DDoS attacks autonomously and noted that the one peaking at 3.8 Tbps lasted 65 seconds.

Read more of this story at Slashdot.

카테고리:

Senator Calls Out John Deere For Clean Air Act Violations, Blocking Farmer Repairs

Slashdot - 금, 2024/10/04 - 7:02오전
"The Fight to Repair Newsletter is reporting that U.S. Senator Elizabeth Warren is calling out agricultural equipment giant John Deere for possible violations of the federal Clean Air Act and a years-long pattern of thwarting owners' ability to repair their farm equipment," writes longtime Slashdot reader chicksdaddy. From the report: Deere "appears to be evading its responsibilities under the Clean Air Act to grant customers the right to repair their own agricultural equipment." That is costing farmers an estimated $4.2 billion annually "causing them to miss key crop windows on which their businesses and livelihoods rely," Warren wrote in a letter (https://www.theverge.com/2024/10/3/24260513/john-deere-right-to-repair-elizabeth-warren-clean-air-act) dated October 2nd. The letter from Warren (PDF), a Senator from Massachusetts and strong repair advocate, is just the latest volley lobbed at Illinois-based Deere, an iconic American brand and the largest supplier of agricultural equipment to farms in the U.S. Deere controls an estimated 53 percent of the U.S. market for large tractors and 60 percent of the U.S. market for farm combines. In recent weeks, Deere faced criticism, including from Republican presidential candidate Donald Trump, after laying off close to 2,000 U.S. based employees at facilities in Iowa and Illinois, moving many of those jobs to facilities in Mexico. The company has also been repeatedly called out for complicating repair and service of its farm equipment -- often relying on software locks and digital rights management to force farmers to use Deere dealers and authorized service providers for even the simplest repairs.

Read more of this story at Slashdot.

카테고리:

페이지

KLDP 수집기 구독하기