0 Comments
0 Shares
151 Views
Directory
Directory
-
Please log in to like, share and comment!
-
9TO5MAC.COMDevelopers behind F1 app Lapz for Vision Pro forced to remove it from TestFlightCompared to the iPhone and iPad, Apple Vision Pro has a limited number of apps available in the App Store. Even so, developers have been exploring the devices capabilities with different projects, one of which is the Formula 1 app Lapz. Unfortunately, the app may not even make it to the App Store.Developers create F1 app for Vision Pro, butFor those unfamiliar, Lapz is an app that lets Apple Vision Pro users watch F1 races on a virtual big screen while also being able to see the position of the drivers on a floating 3D model. The app was based on a concept video made by VFX artist John LePore to show what Vision Pro is capable of.Lapz has been distributed via TestFlight, as the developers still want to improve the app before making it available to everyone. Even so, the app has gotten a lot of attention since the beta version was released. However, as reported by UploadVR, the dream seems to be over or at least put on hold.Thats because the developers have been asked to pull the app from TestFlight. Not by Apple, but by Formula One Group. The most likely reason is the unlicensed use of F1 content and branding even though the app uses web views to let users log in to the official F1TV stream.The team behind Lapz say theyre working on securing a digital license to get the app working again. But for now, Lapz has been removed from TestFlight and current users will no longer have access to the app after February 8 when the current build will expire. The developers say they plan to license the app to other motorsport groups if they dont reach a deal with Formula One Group.Although Formula One Group has the right to ask for the app to be removed, its unfortunate that Vision Pro owners will lose another option for streaming content on the headset. Last month, the popular YouTube client Juno for Vision Pro was removed from the App Store after a request from Google.Its worth noting that neither F1 nor YouTube have official apps for visionOS.Add 9to5Mac to your Google News feed. FTC: We use income earning auto affiliate links. More.Youre reading 9to5Mac experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Dont know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel0 Comments 0 Shares 135 Views
-
9TO5MAC.COMpCloud offers lifetime cloud storage, client-side encryption, more in big Black Friday specialpCloud is a Switzerland-based cloud storage company with a security specialty. It offers lifetime options for its storage plans, and in an early Black Friday special its bundling cloud storage with client-side encryption and a truly encrypted password manager at a heavy discount.Features of the security-focused pCloud file storage, encryption, and password managerAmong cloud storage providers, pCloud has built a base of more than 20 million users with its high focus on security and ease of use.Every cloud storage plan includes 256-bit AES encryption for all files, plus TLS/SSL channel protection. pCloud runs two data centers, one in the US and the other in Luxembourg.Fortunately, you dont have to sacrifice convenience for the sake of security with pCloud. pCloud includes key features with its file storage service like:dedicated desktop apps for Mac, Windows, and Linuxmobile apps for iOS and Android with automatic upload featuresweb accessautomatic backupsrobust collaboration and file sharing optionsinstant sync across all platformsFor users who want an extra layer of protection, the add-on pCloud Encryption offers client-side encryption that locks your files right on your device. That means even pCloud itself cant access them.To test its client-side encryption software, pCloud held a hacking challenge with a $100,000 prize. The challenge ran six months, involved nearly 3,000 participants, and resulted in zero hacks.pClouds expertise in security also lends itself well to pCloud Pass, the companys dedicated password manager. pCloud Pass comes with autofill, browser extensions, a military-grade encryption algorithm, and easy access across all devices and platforms.Limited time Black Friday deals on lifetime plansBlack Friday is coming up, and from November 13-30 pCloud is running an extended offer on its services lifetime plans.The best offer is a 3-in-1 bundle of pClouds 5TB storage plan plus pCloud Encryption and pCloud Pass. You can get a lifetime package of all three for just $599, a massive 60% off.Alternately, these lifetime pCloud storage plans are also on sale:1TB: $199 (-54%)2TB: $279 (-53%)10TB: $799 (-58%)You can learn more about pClouds products and access these special offers via the companys website.Add 9to5Mac to your Google News feed. FTC: We use income earning auto affiliate links. More.Youre reading 9to5Mac experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Dont know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel0 Comments 0 Shares 129 Views
-
FUTURISM.COMElon Musk Throws Support Behind Man Accused of Sex With Underage Girl"Our Hammer of Justice." He Said, She SaidFreshly-minted politico Elon Musk is throwing his weight behind Donald Trump's attorney general nominee amid damning allegations related to his sexual conduct.In a post on the social network he purchased and subsequently tanked, the billionaire referenced but did not namethe accusations against former Florida congressman Matt Gaetz: that he paid for sex from two young women on multiple occasions, and that one of them was 17 at the time of the first encounter (Gaetz has vehemently denied reports of his sexual misconduct for years.)"As for these accusations against him, I consider them worth less than nothing," Musk tweeted. "Under our laws, a man is considered innocent until proven guilty."That's true, of course but it seems reasonable to fully investigate the allegations before putting Gaetz, or anyone else, in charge of the Justice Department.Open and ShutMusk went on to reference, again without spelling it out, that Gaetz has been under investigation for years regarding these allegations."If AG [Eric] Garland (an unprincipled douchebag) could have secured a conviction against Gaetz, he would have, but he knew he could not," the multi-hyphenate business owner tweeted. "Case closed."That bit does seem partially true. Last February, the Department of Justice under Garland reportedly told Gaetz's attorneys that he would not be charged with any crimes related to its investigation into sex trafficking claims against him.To refer to that case as "closed," however, is likely inaccurate given that the DOJ hasn't announced any such closure.It also ignores theother investigation into Gaetz by the House Ethics Committee, which saw the two women at the heart of these allegations testifying behind closed doors earlier this year. That investigation is also, per the lack of any announcement of closure, seemingly still open as well.With an attorney for the two Gaetz accusers agitating for the House Ethics Committee to release its report on Gaetz to the public amid news that a hacker had obtained copies of the allegedly damning testimonies, no less all of Musk's attempts to sway the court of public opinion may soon be nil.Nevertheless, he insists that the Florida Republican is the right guy for the job."Gaetz will be," Musk enthused, "our Hammer of Justice."Share This Article0 Comments 0 Shares 123 Views
-
FUTURISM.COMNvidia's New AI Chips Are Reportedly Overheating in Server FarmsCustomers are pissed.Graphic Pushback UnitNvidia's unreleased AI chips are reportedly overheating, with customers worrying that their already-delayed shipment may be pushed back yet again.As The Information reports,the company's uber-powerful Blackwell graphics processing units (GPUs) are overheating when connected in server racks that can hold up to 72 of them.According to Nvidia employees who've been working on releasing the chips, as well as customers and vendors with knowledge of the issue, the firm has repeatedly asked its suppliers to redesign the racks to head off the overheating problem.The issue is so problematic that the company informed Microsoft this week that shipment will be delayed at least another three months the latest development in a series of pushbacks that have haunted the company since the Blackwell chips were first unveiled back in March.And that doesn't bode well, considering the astronomical resources AI companies are allocating to building out server farms, nagging growing pains that could hold back their efforts to train and roll out the next AI product.Design and DemandNvidia claims its next-generation GPUs are extremely powerful and30 times as fast as preceding models when it comes to AI applications. As CEO Jensen Huang toldCNBC last month, demand for Blackwell chips has been "insane" as people rush to pre-order the chips that cost tens of thousands of dollars apiece.Amid all that hype, however, rumors of design flaws have plagued the release of the Blackwell chips for months. Eventually, Huang admittedin part that some of the hearsay was true."We had a design flaw in Blackwell, it was functional, but the design flaw caused the yield to be low," the CEO said during an October 23 press conference, per Reuters. "It was 100 percent Nvidia's fault."While that admission seems to have been related to another production issue, it nevertheless seems to have caused yet another unnecessary delay in the shipment process.In the meantime, a Nivida spokesperson claimed that the latest overheating issue was nothing to worry about and that "the engineering iterations are normal and expected."The massive rack of 72 GPUs weighs a whopping 3,000 pounds and needs to be cooled using water, a departure from the air-cooling many AI data centers have come to rely upon. According to The Information, Nvidia was struggling with even a much smaller 36-GPU rack overheating.As the immense hype surrounding the release of new AI products continues to grow, the pressure is rising considerably for Nvidia.Customers have already been hit withdelays of the new Blackwell chips the latest development likely won't sit well with him either.More on AI computing power: AI Expert Warns Crash Is Imminent As AI Improvements Hit Brick WallShare This Article0 Comments 0 Shares 132 Views
-
THEHACKERNEWS.COMDecades-Old Security Vulnerabilities Found in Ubuntu's Needrestart PackageNov 20, 2024Ravie LakshmananLinux / VulnerabilityMultiple decade-old security vulnerabilities have been disclosed in the needrestart package installed by default in Ubuntu Server (since version 21.04) that could allow a local attacker to gain root privileges without requiring user interaction.The Qualys Threat Research Unit (TRU), which identified and reported the flaws early last month, said they are trivial to exploit, necessitating that users move quickly to apply the fixes. The vulnerabilities are believed to have existed since the introduction of interpreter support in needrestart 0.8, which was released on April 27, 2014."These needrestart exploits allow Local Privilege Escalation (LPE) which means that a local attacker is able to gain root privileges," Ubuntu said in an advisory, noting they have been addressed in version 3.8. "The vulnerabilities affect Debian, Ubuntu, and other Linux distributions."Needrestart is a utility that scans a system to determine the services that need to be restarted after applying shared library updates in a manner that avoids a complete system reboot.The five flaws are listed below -CVE-2024-48990 (CVSS score: 7.8) - A vulnerability that allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variableCVE-2024-48991 (CVSS score: 7.8) - A vulnerability that allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreterCVE-2024-48992 (CVSS score: 7.8) - A vulnerability that allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variableCVE-2024-11003 (CVSS score: 7.8) and CVE-2024-10224 (CVSS score: 5.3) - Two vulnerabilities that allows a local attacker to execute arbitrary shell commands as root by taking advantage of an issue in the libmodule-scandeps-perl package (before version 1.36)Successful exploitation of the aforementioned shortcomings could allow a local attacker to set specially crafted environment variables for PYTHONPATH or RUBYLIB that could result in the execution of arbitrary code pointing to the threat actor's environment when needrestart is run."In CVE-2024-10224, [...] attacker-controlled input could cause the Module::ScanDeps Perl module to run arbitrary shell commands by open()ing a 'pesky pipe' (such as by passing 'commands|' as a filename) or by passing arbitrary strings to eval()," Ubuntu noted."On its own, this is not enough for local privilege escalation. However, in CVE-2024-11003 needrestart passes attacker-controlled input (filenames) to Module::ScanDeps and triggers CVE-2024-10224 with root privilege. The fix for CVE-2024-11003 removes needrestart's dependency on Module::ScanDeps."While it's highly advised to download the latest patches, Ubuntu said users can disable interpreter scanners in needrestart the configuration file as a temporary mitigation and ensure that the changes are reverted after the updates are applied."These vulnerabilities in the needrestart utility allow local users to escalate their privileges by executing arbitrary code during package installations or upgrades, where needrestart is often run as the root user," Saeed Abbasi, product manager of TRU at Qualys, said."An attacker exploiting these vulnerabilities could gain root access, compromising system integrity and security."Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.SHARE0 Comments 0 Shares 126 Views
-
THEHACKERNEWS.COMChina-Backed Hackers Leverage SIGTRAN, GSM Protocols to Infiltrate Telecom NetworksNov 20, 2024Ravie LakshmananCyber Espionage / Telecom SecurityA new China-linked cyber espionage group has been attributed as behind a series of targeted cyber attacks targeting telecommunications entities in South Asia and Africa since at least 2020 with the goal of enabling intelligence collection.Cybersecurity company CrowdStrike is tracking the adversary under the name Liminal Panda, describing it as possessing deep knowledge about telecommunications networks, the protocols that undergird telecommunications, and the various interconnections between providers.The threat actor's malware portfolio includes bespoke tools that facilitate clandestine access, command-and-control (C2), and data exfiltration."Liminal Panda has used compromised telecom servers to initiate intrusions into further providers in other geographic regions," the company's Counter Adversary Operations team said in a Tuesday analysis."The adversary conducts elements of their intrusion activity using protocols that support mobile telecommunications, such as emulating global system for mobile communications (GSM) protocols to enable C2, and developing tooling to retrieve mobile subscriber information, call metadata, and text messages (SMS)."It's worth noting that some aspects of the intrusion activity were documented by the cybersecurity company back in October 2021, attributing it then to a different threat cluster dubbed LightBasin (aka UNC1945), which also has a track record of targeting telecom entities since at least 2016.CrowdStrike noted that its extensive review of the campaign revealed the presence of an entirely new threat actor, and that the misattribution three years ago was the result of multiple hacking crews conducting their malicious activities on what it said was a "highly contested compromised network."Some of the custom tools in its arsenal are SIGTRANslator, CordScan, and PingPong, which come with the following capabilities -SIGTRANslator, a Linux ELF binary designed to send and receive data using SIGTRAN protocolsCordScan, a network-scanning and packet-capture utility containing built-in logic to fingerprint and retrieve data relating to common telecommunication protocols from infrastructure such as the Serving GPRS Support Node (SGSN)PingPong, a backdoor that listens for incoming magic ICMP echo requests and sets up a TCP reverse shell connection to an IP address and port specified within the packetLiminal Panda attacks have been observed infiltrating external DNS (eDNS) servers using password spraying extremely weak and third-party-focused passwords, with the hacking crew using TinyShell in conjunction with a publicly available SGSN emulator called sgsnemu for C2 communications."TinyShell is an open-source Unix backdoor used by multiple adversaries," CrowdStrike said. "SGSNs are essentially GPRS network access points, and the emulation software allows the adversary to tunnel traffic via this telecommunications network."The end goal of these attacks is to collect network telemetry and subscriber information or to breach other telecommunications entities by taking advantage of the industry's interoperation connection requirements."Liminal Panda's known intrusion activity has typically abused trust relationships between telecommunications providers and gaps in security policies, allowing the adversary to access core infrastructure from external hosts," the company said.The disclosure comes as U.S. telecom providers like AT&T, Verizon, T-Mobile, and Lumen Technologies have become the target of another China-nexus hacking group dubbed Salt Typhoon. If anything, these incidents serve to highlight how telecommunications and other critical infrastructure providers are vulnerable to compromise by state-sponsored attackers.French cybersecurity company Sekoia has characterized the Chinese offensive cyber ecosystem as a joint enterprise that includes government-backed units such as the Ministry of State Security (MSS) and the Ministry of Public Security (MPS), civilian actors, and private entities to whom the work of vulnerability research and toolset development is outsourced."China-nexus APTs are likely to be a mix of private and state actors cooperating to conduct operations, rather than strictly being associated with single units," it said, pointing out the challenges in attribution."It ranges from the conduct of operations, the sale of stolen information or initial access to compromised devices to providing services and tools to launch attacks. The relationships between these military, institutional and civilian players are complementary and strengthened by the proximity of the individuals part of these different players and the CCP's policy."Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.SHARE0 Comments 0 Shares 133 Views
-
WEWORKREMOTELY.COMToggl: Senior Product Marketing Manager Toggl WorkTime zones: SBT (UTC +11), GMT (UTC +0), CET (UTC +1), EET (UTC +2), MSK (UTC +3)Were looking for a highly motivated Senior Product Marketing Manager to join the Toggl Work team, our newest product aimed at revolutionising People Operations. This is your chance to shape the future of a product designed to save our users time, money, and sanity.The ideal candidate will have experience crafting and executing user acquisition strategies in a SaaS environment, with a strong emphasis on customer onboarding, user engagement, experimentation, data-driven decision-making, and process creation. If youre someone who thrives in building from scratch and can take ownership of growth strategy while navigating the challenges of a new product launch, this could be the perfect role for you.The salary for this position is 60,000 annually.You can work from anywhere in Europe.About the TeamWe are a global team of 130+ awesome people working from over 40 countries around the globe. We hire globally, you work locallyin the heart of London, a beach outside of Ro de Janeiro, or a quiet village near Florence, the choice is yours. Every few months we travel to meet up somewhere in the world and spend some quality time together. We place a huge amount of trust in our people, and we measure the outcomes rather than the work itself. Our values fuel our results.The RoleToggl Work is our latest addition to the Toggl suite of products, focusing on expense management, invoicing, budgeting, reporting, and workforce operations.As our Senior Product Marketing Manager, youll play a critical role in defining and executing our Go-to-Market (GTM) strategies, focussed on acquisition, onboarding, engagement, and retention.You will play a pivotal role in identifying target audiences, crafting compelling messaging, and executing strategic initiatives that position Toggl Work as the go-to solution.This role will have you owning key KPIs, collaborating cross-functionally, and continuously optimizing the customer journey to ensure measurable success. Experience with people operations tools is a strong plus.Your main responsibilities will be:Drive Go-to-Market strategies, owning KPI for acquisition, and co-owning the KPIs of onboarding, retention, and engagement with the Product Manager.Identify, target, and onboard high-value audiences to maximize user growth and engagement.Develop and refine onboarding processes and customer journeys to ensure seamless experiences.Collaborate with cross-functional teams (Product, Marketing, Sales) to co-own user retention and engagement metrics.Conduct market research, competitive analysis, and experimentation to optimize growth strategies.About YouWed love to hear from you if:You are a self-starter with the ability to take ownership of complex projects and drive them to completion.You have experience in customer success or user acquisition roles, particularly in a SaaS environment.You have experience in the people operations software industry or familiarity with people operations tools, which is a huge plus.You have a proven track record of creating and implementing successful GTM strategies that emphasize customer acquisition and retention.You are data-driven and comfortable creating and analysing KPIs to inform decision-making.You thrive in an environment where you can build processes from scratch and iterate on them quickly.You are excited about the challenge of launching a new product and have a strong understanding of the SaaS landscape.You are a generalist who can adapt to the evolving needs of an early-stage startup and do whatever it takes to reach the goal.BenefitsFreedom to choose when and how much you work - we only measure results24 days of paid time off a year, plus your local holidaysIn-person meetups for team-building (expenses covered)4-6 weeks paid sabbatical (depending on the tenure)Laptop budget up to 2,500 and it renews every 3 years2,000 budget to set up your home office, and additional 300 every year after 3 years of tenure3000 per year for co-working space membership and/or internet service at home4,000 per year contribution to use for training, workshops, and conferences2,000 per year contribution for any equipment or services to improve and/or maintain your physical and mental healthSupport for buying tools you need for doing your best work (even eyeglasses if you need a new pair) Related Jobs See more All Other Remote jobs0 Comments 0 Shares 143 Views
-
WEWORKREMOTELY.COMToggl: Senior Backend EngineerTime zones: ART (UTC -3), UTC -4, UTC -3, UTC -2, GMT (UTC +0), MSK (UTC +3), CEST (UTC +2), BST (UTC +1), GST (UTC +4)We are looking for experienced Senior Backend Engineers who bring unique skills to our team and help us shape the future of the time tracking industry.The salary for this position is 80,000 annually.You can work from anywhere in the world as long as your main location is between UTC-4 and UTC+4.About the TeamWe are a global team of 100+ awesome people working from over 40 countries around the globe. We hire globally, you work locallyin the heart of London, a beach outside of So Paulo, or a quiet village near Florence, the choice is yours. Every few months we travel to meet up somewhere in the world and spend some quality time together. We place a huge amount of trust in our people, and we measure the outcomes rather than the work itself. Our values fuel our results.The RoleAs a Senior Backend Engineer, you will be taking ownership of one or more domains of our product and will work closely with other Backend and Frontend engineers using cutting-edge open source frameworks to develop highly-available RESTful services and back-end systems.The main technologies you will be working with are Go, PostgreSQL and Google Cloud Infrastructure.Our team meetings are scheduled between 11:00 and 16:00 UTC. Your availability and commitment to participate in these sessions are essential for effective collaboration and team alignment.Your main responsibilities will be:developing, scaling and maintaining some of our backend services including the API, reports and other infrastructure services that manage our product and logistics worldwideworking with multiple teams day to day to bring more value to Toggls users, covering customer-facing web and native applications and public APIsdesigning, breaking down, and completing projects of a medium to large scope with high-level productivitylooking for technical problems of existing system/product without guidance and offering solutionsleading projects with a small group of people, such as hosting weekly meetings, communicating with other partners and stakeholdersAbout youWe would love to hear from you if you strive to solve technical problems of high scope and complexity and have long-standing experience programming in Go.In particular, we are looking for:Strong backend engineering experience in GoSignificant professional experience with distributed systems, PostgreSQL, and Google Cloud InfrastructureExperience with software engineering best practices (e.g. unit testing, code reviews, design documentation)Experience with performance and optimisation problems, particularly at large scale, and a demonstrated ability to both diagnose and prevent these problemsAbility to work cross-teams and improve cross-functional relationships which will facilitate ongoing projectsEffective communication skills, ensuring regular consensus with peers and clear status updates.Strong collaboration skills across the company to define, design, build, and improve the product.Experience with data warehouse, analytics systems, Kubernetes at scale, and system architecture at scale.Eagerness to contribute to the engineering team's growth, including interviewing and mentoring junior engineers, and providing precise, actionable feedback to peers.Proficiency in the English language, both written and verbal, is required for success in a remote and largely asynchronous work environmentBenefitsFreedom to choose when and how much you work - we only measure results24 days of paid time off a year, plus your local holidaysIn-person meetups for team-building (expenses covered)4-6 weeks paid sabbatical (depending on the tenure)Laptop budget up to 2,500 and it renews every 3 years2,000 budget to set up your home office, and additional 300 every year after 3 years of tenure250 per month for co-working space membership and/or internet service at home4,000 per year contribution to use for training, workshops, and conferences2,000 per year contribution for any equipment or services to improve and/or maintain your physical and mental healthSupport for buying tools you need for doing your best work (even eyeglasses if you need a new pair)0 Comments 0 Shares 138 Views
-