You are here
News
DSA-5986-1 node-cipher-base - security update
Nikita Skorovoda discovered that Node cipher-base, an abstract base
class for crypto-streams, performed incomplete type checks.
Categories: Security
DSA-5985-1 ffmpeg - security update
Several vulnerabilities have been discovered in the FFmpeg multimedia
framework, which could result in denial of service or potentially the
execution of arbitrary code if malformed files/streams are processed.
Categories: Security
DSA-5984-1 thunderbird - security update
Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.
Categories: Security
DSA-5983-1 qemu - security update
This update removes the usage of the C (Credential) flag for the
binfmt_misc registration within the qemu-user package, as it allowed for
privilege escalation when running a suid/sgid binary under qemu-user.
This means suid/sgid foreign-architecture binaries are not running with
elevated privileges under qemu-user anymore. If you relied on this
behavior of qemu-user in the past (running suid/sgid foreign-arch
binaries), this will require changes to your deployment.
In Bookworm the affected packages are qemu-user-static (and qemu-user-binfmt) instead of qemu-user.
Additionally, two security issues were fixed the in SR-IOV support of QEMU system emulation.
Categories: Security
DSA-5982-1 squid - security update
Two security issues were discovered in the Squid proxy caching server,
which could result in the execution of arbitrary code, information
disclosure or denial of service.
Categories: Security
DSA-5981-1 chromium - security update
A security issues was discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Categories: Security
Amazon Cloud Chief Says Replacing Junior Staff With AI is 'Dumbest' Idea
Matt Garman, Amazon's cloud boss, has a warning for business leaders rushing to swap workers for AI: Don't ditch your junior employees. From a report: The Amazon Web Services CEO said on an episode of the "Matthew Berman" podcast published Tuesday that replacing entry-level staff with AI tools is "one of the dumbest things I've ever heard."
"They're probably the least expensive employees you have. They're the most leaned into your AI tools," he said. "How's that going to work when you go like 10 years in the future and you have no one that has built up or learned anything?" Garman said companies should keep hiring graduates and teaching them how to build software, break down problems, and adopt best practices.
He also said the most valuable skills in an AI-driven economy aren't tied to any one college degree. "If you spend all of your time learning one specific thing and you're like, 'That's the thing I'm going to be expert at for the next 30 years,' I can promise you that's not going to be valuable 30 years from now," he said.
Read more of this story at Slashdot.
Categories: Technology
Mark Zuckerberg Plans To Shake Up Meta's AI Efforts, Again
Meta announced today that it is splitting its Meta Superintelligence Labs into four divisions focused on AI research, superintelligence development, products, and infrastructure. The reorganization accompanies potential downsizing of the AI division's thousands of employees and executive departures, according to New York Times.
Vice President of Generative AI Loredana Crisan is expected to announce her departure Tuesday. The company is exploring third-party AI models for its products rather than relying solely on internal technology. Chief AI Officer Alexandr Wang's team has abandoned Meta's previous frontier model Behemoth and is developing a new model from scratch, the report added.
Read more of this story at Slashdot.
Categories: Technology
