❌

Reading view

There are new articles available, click to refresh the page.

Linux Kernel Team Publishes 432 CVEs In Two Days

Ancient Slashdot reader alanw shares a post from the OSS Security mailing list, where sysadmin Jan Schaumann wonders what to do after the Linux kernel cranked out 432 CVEs in a little over 24 hours: "I understand the position that CVEs were always a flawed way to track or prioritize security changes... But this onslaught really shows it's not feasible to attempt to prioritize individual kernel changes. I'm not sure what to do here going forward." The Register reports: The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldn't be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become "almost entirely unmanageable" due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact "it keeps finding embarrassing bugs." [...] Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isn't one that's readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy. Senior kernel maintainer Greg Kroah-Hartman replied to Jan's post, pushing back on the idea that the kernel's CVE volume is uniquely unmanageable. The kernel isn't special, he argues -- companies everywhere are finally realizing they need to re-evaluate how they update all of their systems and devices, something that's traditionally been "woefully ignored." On the "just always update" approach, Greg says that's precisely what the kernel community endorses: "This is what the kernel developer community recommends and supports. If you want support from us, do this." Can't manage it yourself? Pay a company for support, or "just use Debian or Yocto as their security practices are amazing." He points to Android as proof the approach scales, calling it "the largest deployment of software in the world" -- billions of devices kept updated "with one very-overworked developer guiding it all." As for reviewing every CVE individually, he notes this can be largely automated by intersecting the files a CVE touches with the files you actually build, which typically trims the relevant set "down to about 10% of the overall total" -- the approach enterprise distros already take for their customers. Panic-mode selective patching gets a blunt "Good luck with that!" -- regulations like the EU's Cyber Resilience Act are set to legislate that habit away ("rightfully so," in his view), and "your insurance company might wish to have a talk with you as well." Greg also warns the flood isn't over: "The number of llm-found issues is only on the rise right now, it's going to be a very long 18 months at the least to dig ourselves out of this mess, and people had BETTER be updating their systems all along the way if they expect to be secure in any way." As for the 432-CVE burst itself, he explains it was simply him catching up on a weeks-old, publicly visible review queue over the weekend -- delayed by "a perfect storm of 6 weeks straight of conferences and vacations" -- so it shouldn't have come as a surprise to anyone watching the public git repo.

Read more of this story at Slashdot.

Amazon cuts jobs in AGI group as it puts more focus on customer-facing AI

GeekWire File Photo

Amazon confirmed Wednesday that it laid off an unspecified number of employees in its artificial general intelligence (AGI) organization, the division working on the company’s advanced AI models.

The move, first reported by Reuters, comes as the company invests heavily in programs to help businesses implement AI effectively, including a $1 billion initiative to embed AWS engineers with customers building agentic AI systems.

It’s part of a larger shift in the industry as tech giants and AI frontier labs look to make sure the enormous sums they’re spending on AI pay off in tools businesses actually use.

In a statement, an Amazon spokesperson said building large AI models remains β€œone of the most important things we’re working on,” but said the company is also β€œsharpening our focus on the initiatives that matter most for customers, so we can move faster on what counts.”

β€œThat focus means some difficult decisions, including eliminating some roles within parts of our AGI organization, even as we continue to invest in the areas most important to our customers’ future,” the spokesperson said.

It’s the latest in a series of changes in Amazon’s AGI group, which despite its name has always been focused more on frontier models than on what the industry considers AGI, the still-theoretical systems that would match or surpass human intelligence.

Rohit Prasad, the senior executive who oversaw Amazon’s AGI work, left the company late last year, and AGI Lab head David Luan departed in February. In December, Amazon folded the AGI group into a larger organization led by senior vice president Peter DeSantis that also includes chip development and quantum computing.

The cuts are the latest in a series of smaller reductions since January, when Amazon eliminated 16,000 jobs across the company. Amazon said U.S. employees whose jobs are cut will receive 90 days of pay and benefits, outplacement support and transitional health coverage, along with eligibility for severance.

Yope raises $12.3M to build a private social network without algorithms or ads

Yope, a fast-growing social app focused on private groups of friends and family, has raised $12.3 million in seed funding. Instead of chasing creators and algorithmic feeds, the startup is betting that the future of social networking lies in small, private communities powered by messaging, photo sharing, and AI features designed to strengthen real-world relationships.

Hyundai claims humanoid robot plan is not part of talks with striking workers

Hyundai Motor Company’s plan to put humanoid robots to work by 2028 is not part of current negotiations with striking South Korean autoworkers, according to the company.

The automaker is disputing news reports that partial labor strikes by the Hyundai Motor union at the world’s largest automotive plant in South Korea were spurred by concerns about the company's planned deployment of humanoid robots in the United States starting in 2028. A company statement shared with Ars describes the union’s demands as focusing on compensation-related issues such as wage increases, bonuses, and an extension of workers’ retirement age.

β€œPotential deployment of robots in Korean production facilities is not part of the current labor-management discussions,” according to the Hyundai statement. β€œHyundai Motor Company remains committed to constructive engagement with the union and to reaching an agreement that supports the long-term interests of both employees and the company.”

Read full article

Comments

Β© Boston Dynamics

OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face

OpenAI says an agent powered by its LLM models escaped its sandboxed testing environment to infiltrate Hugging Face's servers as part of an overzealous attempt to obtain solutions to a benchmark test. The company says it considers the unintended infiltration an "an unprecedented cyber incident" and is working with Hugging Face on new protections to prevent a recurrence.

Hugging Face disclosed an intrusion last week that it said involved "unauthorized access to a limited set of internal datasets and to several credentials used by our services." The AI data clearinghouse said it used its own LLM-driven analysis to identify "a swarm of tens of thousands of automated actions" from an "autonomous agent framework." That agentic swarm exploited a flaw in Hugging Face's data-processing pipeline to gain the ability to run code as a processing worker, eventually escalating to high-level access to the company's cloud and server clusters.

At the time, Hugging Face said the LLM being used in the attack was "still not known." But OpenAI took responsibility for the intrusion Tuesday evening, saying it came about during an internal test involving the recently released GPT-5.6 Sol and "an even more capable pre-release model." The models were being tested against the ExploitGym benchmark, an independent testing suite based on hundreds of real-world security vulnerabilities.

Read full article

Comments

Β© Getty Images

❌