Security, BSD, IBM, and more
-
Bruce Schneier ☛ New iPhone Exploit Uses Four Zero-Days
Kaspersky researchers are detailing “an attack that over four years backdoored dozens if not thousands of iPhones, many of which belonged to employees of Moscow-based security firm Kaspersky.” It’s a zero-click exploit that makes use of four iPhone zero-days.
-
Windows TCO
-
The Register UK ☛ Court hearings become ransomware concern after justice system breach
Different courts within the system were affected to varying degrees. The Supreme Court of Victoria, aside from two regional hearings in November, only had recordings accessed between December 1 and 21, for example.
-
-
Openwashing
-
The Atlantic ☛ There Was Never Such a Thing as ‘Open’ AI
There is no better illustration of the tension than Llama 2, the most prominent and controversial AI system professing “openness”—which was created by Meta, the titanic owner of Facebook, Instagram, WhatsApp, and Threads. Released last summer, Llama 2 is a large language model that, although less powerful than those underlying ChatGPT and Google’s Bard, is free for both research and commercial uses. But although the model’s final code is available to download, Meta forbids certain uses of that code. Developers cannot leverage Llama 2 to improve any other language model, and they need Meta’s express permission to integrate Llama 2 into products with more than 700 million monthly users—a policy that would bar TikTok from freely using the technology, for example. And much of Llama’s development pipeline is secret—in particular, nobody outside of Meta knows what data the model was trained on. Independent programmers and advocates have said that it does not qualify as open.
-
-
Canonical/Ubuntu Family
-
Ubuntu ☛ Automotive at CES 2024: What to expect
In anticipation of CES 2024, automotive enthusiasts and professionals are eagerly awaiting the unveiling of cutting-edge technologies that will shape the future of the industry. From autonomous vehicles to electric cars, CES has consistently been at the forefront of revolutionising the automotive landscape. This event serves as a hub for industry experts to analyse upcoming trends and collaborate on the development of groundbreaking solutions.
-
-
Fedora Family / IBM
-
Red Hat Official ☛ Red Hat Enterprise Linux 9 STIG automation released
Red Hat’s compliance automation profile for RHEL 9 is aligned with the Version 1, Release 1 (V1R1) of the STIG. Using this profile, organizations can more swiftly increase their systems compliance status by utilizing the scap-security-guide package with its pre-built Ansible Playbooks and the OpenSCAP scanner, Red Hat Insights or Red Hat Satellite for existing RHEL installations. This content can also be used with the RHEL Installer and Image Builder for new RHEL installations.
-
-
BSD
-
The BSD Now Podcast ☛ BSD Now 540: Terrapin Attacks SSH
Terrapin Attack, SSH Hardening with ssh-audit, MidnightBSD 3.1.2, syscall(2) removed from -current, 2024 FreeBSD Community Survey is Here
-