Federal Agency Warns (Patched) Critical Linux Vulnerability Being Actively Exploited

“The US Cybersecurity and Infrastructure Security Agency has added a critical security bug in Linux to its list of vulnerabilities known to be actively exploited in the wild,” reported Ars Technica on Friday.

“The vulnerability, tracked as CVE-2024-1086 and carrying a severity rating of 7.8 out of a possible 10, allows people who have already gained a foothold inside an affected system to escalate their system privileges.”

It’s the result of a use-after-free error, a class of vulnerability that occurs in software written in the C and C++ languages when a process continues to access a memory location after it has been freed or deallocated. Use-after-free vulnerabilities can result in remote code or privilege escalation. The vulnerability, which affects Linux kernel versions 5.14 through 6.6, resides in the NF_tables, a kernel component enabling the Netfilter, which in turn facilitates a variety of network operations… It was patched in January, but as the CISA advisory indicates, some production systems have yet to install it. At the time this Ars post went live, there were no known details about the active exploitation.

A deep-dive write-up of the vulnerability reveals that these exploits provide “a very powerful double-free primitive when the correct code paths are hit.” Double-free vulnerabilities are a subclass of use-after-free errors…

Read more of this story at Slashdot.

How Facial Recognition Tech Is Being Used In London By Shops – and Police

“Within less than a minute, I’m approached by a store worker who comes up to me and says, ‘You’re a thief, you need to leave the store’.”

That’s a quote from the BBC by a wrongly accused customer who was flagged by a facial-recognition system called Facewatch. “She says after her bag was searched she was led out of the shop, and told she was banned from all stores using the technology.”

Facewatch later wrote to her and acknowledged it had made an error — but declined to comment on the incident in the BBC’s report:

[Facewatch] did say its technology helped to prevent crime and protect frontline workers. Home Bargains, too, declined to comment. It’s not just retailers who are turning to the technology… [I]n east London, we joined the police as they positioned a modified white van on the high street. Cameras attached to its roof captured thousands of images of people’s faces. If they matched people on a police watchlist, officers would speak to them and potentially arrest them…

On the day we were filming, the Metropolitan Police said they made six arrests with the assistance of the tech… The BBC spoke to several people approached by the police who confirmed that they had been correctly identified by the system — 192 arrests have been made so far this year as a result of it.
Lindsey Chiswick, director of intelligence for the Met, told the BBC that “It takes less than a second for the technology to create a biometric image of a person’s face, assess it against the bespoke watchlist and automatically delete it when there is no match.”

“That is the correct and acceptable way to do it,” writes long-time Slashdot reader Baron_Yam, “without infringing unnecessarily on the freedoms of the average citizen. Just tell me they have appropriate rules, effective oversight, and a penalty system with teeth to catch and punish the inevitable violators.”

But one critic of the tech complains to the BBC that everyone scanned automatically joins “a digital police line-up,” while the article adds that others “liken the process to a supermarket checkout — where your face becomes a bar code.” And “The error count is much higher once someone is actually flagged. One in 40 alerts so far this year has been a false positive…”

Thanks to Slashdot reader Bruce66423 for sharing the article.

Read more of this story at Slashdot.

London’s Evening Standard To End Daily Newspaper After Almost 200 Years

London’s famed Evening Standard newspaper has announced plans to end its daily outlet, “bringing an end to almost 200 years of publication in the capital,” reports The Guardian. Going forward, the company plans to launch “a brand new weekly newspaper later this year and consider options for retaining ES Magazine with reduced frequency,” while also working to increase traffic to its website. “In its 197-year history the Evening Standard has altered its format, price, content and distribution models,” notes The Guardian. “But giving up on producing a daily print newspaper is the biggest change yet.” From the report: The newspaper said it has been hit hard by the introduction of wifi on the London Underground, a shortage of commuters owing to the growth of working from home and changing consumer habits. The Standard lost 84.5 million pounds in the past six years, according to its accounts, and is reliant on funding from its part-owner Evgeny Lebedev. Its other shareholders include a bank with close links to the Saudi government. Industry sources suggested Lebedev had been willing to consider selling the outlet in recent years but no buyer was found.

Paul Kanareck, the newspaper’s chair, told staff on Wednesday morning: “The substantial losses accruing from the current operations are not sustainable. Therefore, we plan to consult with our staff and external stakeholders to reshape the business, return to profitability and secure the long-term future of the number one news brand in London.” Kanareck said there would be an “impact on staffing,” with journalists bracing themselves for further job losses on top of years of redundancies, while design staff on the print edition are expected to be hit hard. Distributors who hand out the newspaper across London are also likely to be out of work, and billboards outside railway stations advertising the day’s headline will stand empty on most days.

He suggested there would be a change in focus for the weekly outlet: “A proposed new weekly newspaper would replace the daily publication, allowing for more in-depth analysis of the issues that matter to Londoners, and serve them in a new and relevant way by celebrating the best London has to offer, from entertainment guides to lifestyle, sports, culture and news and the drumbeat of life in the world’s greatest city.” Closing the Evening Standard will mean that for the first time in centuries, Londoners will have no general-interest daily print newspaper. The finance-focused City AM, which was recently saved by the billionaire Matthew Moulding, will continue to publish four days a week and has recently increased its distribution. Further reading: So it’s goodbye to London’s Standard, my old paper — and to the heart of democracy, local news (Opinion; The Guardian)

Read more of this story at Slashdot.

Windows 11’s New Recall Feature Has Been Cracked To Run On Unsupported Hardware

Last than two weeks after it was announced, “Windows enthusiasts have managed to crack Microsoft’s flagship AI-powered Recall feature to run on unsupported hardware,” reports The Verge. From the report: Recall leverages local AI models on new Copilot Plus PCs to run in the background and take snapshots of anything you’ve done or seen on your PC. You then get a timeline you can scrub through and the ability to search for photos, documents, conversations, or anything else on your PC. Microsoft positioned Recall as needing the very latest neural processing units (NPU) on new PCs, but you can actually get it running on older Arm-powered hardware.

Windows watcher Albacore has created a tool called Amperage, which enables Recall on devices that have an older Qualcomm Snapdragon chip, Microsoft’s SQ processors, or an Ampere chipset. You need to have the latest Windows 11 24H2 update installed on one of these Windows on Arm devices, and then the tool will unlock and enable Recall. […] You can technically unlock Recall on x86 devices, but the app won’t do much until Microsoft publishes the x64 AI components required to get it up and running. Rumors suggest both AMD and Intel are close to announcing Copilot Plus PCs, so Microsoft’s AI components for those machines may well appear soon. I managed to get Recall running on an x64 Windows 11 virtual machine earlier today just to test out the initial first-run experience.

Read more of this story at Slashdot.