Bonum Certa Men Certa

Leftover Links 05/08/2023: Rust Holes and More Layoffs



  • Leftovers

    • Education

      • Parents accuse Bellevue School District of favoring rich kids in school closures

        When the Bellevue School District (BSD) opened its newest, state of the art elementary school on pristine wetlands and powered by geothermal energy in 2018, at a cost of $49 million, its principal did a welcoming dance in a video to show off the school.

        As she led the camera through the Microsoft Showcase school, showing classrooms that could be converted to learning pods for smaller or larger groups, she also pointed to teachers in a large group, waiting to teach kids.

        Today, however, issues of equity are dampening the shining reputation of the school—and raising questions about the district’s commitment to fairness.

    • Hardware

    • Proprietary/Artificial Intelligence (AI)

      • Bruce SchneierPolitical Milestones for AI

        ChatGPT was released just nine months ago, and we are still learning how it will affect our daily lives, our careers, and even our systems of self-governance.

        But when it comes to how AI may threaten our democracy, much of the public conversation lacks imagination. People talk about the danger of campaigns that attack opponents with fake images (or fake audio or video) because we already have decades of experience dealing with doctored images.

    • Security

      • InfoSecurity MagazineThreat Actors Use AWS SSM Agent as a Remote Access Trojan

        Threat actors have been observed using Amazon Web Services ( AWS ) 's System Manager (SSM) agent as a Remote Access Trojan (RAT) on Linux and Windows machines.

      • Rust BlogThe Rust Programming Language Blog: Security advisory for Cargo (CVE-2023-38497)

        This is a cross-post of the official security advisory. The official advisory contains a signed version with our PGP key, as well.

        The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.

      • SUSE's Corporate BlogSUSE and IBM: Enhancing Data Security (a Technical Reference Documentation Getting Started guide) [Ed: "confidential computing" is a sham that encourages companies and governments to outsource their operations and data based on false premises of confidentiality]

        The Essence of Confidential Computing At its core, confidential computing addresses the vital need of safeguarding data while it is in use. SUSE and IBM work together to deliver advanced technical capabilities, like confidential computing. IBM Z€® and LinuxONE systems provide key hardware capabilities for the trusted execution environment.

      • Bleeping ComputerHackers can abuse Microsoft Office executables to download malware

        The list of LOLBAS files – legitimate binaries and scripts present in Windows that can be abused for malicious purposes...

      • SANSFrom small LNK to large malicious BAT file with zero VT score, (Thu, Aug 3rd)

        Last week, my spam trap caught an e-mail with LNK attachment, which turned out to be quite interesting.

      • IT WireTenable chief says no way to verify Microsoft claims about fixing Azure flaw

        Microsoft claims it has completely fixed a critical security issue in its Azure cloud platform, found in March by researchers from security firm Tenable, who then told Microsoft about it. Tenable chief executive and chairman Amit Yoran had claimed in a blog post on Wednesday that it took more than 90 days for Microsoft to effect a partial fix.

      • SANSAre Leaked Credentials Dumps Used by Attackers, (Fri, Aug 4th)

        This is a classic problem: One day, you create an account on a website (ex: an online shop), and later, this website is compromised. All credentials are collected and shared by the attacker. To reduce this risk, a best practice is to avoid password re-use (as well as to not use your corporate email address for non-business-related stuff).

      • Security WeekExploitation of Ivanti EPMM Flaw Picking Up as New Vulnerability Is Disclosed

        Exploitation of the Ivanti EPMM flaw CVE-2023-35078 is picking up as a new critical vulnerability tracked as CVE-2023-35082 is disclosed.

      • Security WeekFive Eyes Agencies Call Attention to Most Frequently Exploited Vulnerabilities

        Five Eyes government agencies have published a list of the software vulnerabilities that were most frequently exploited in malicious attacks in 2022.

      • Security Week670 ICS Vulnerabilities Disclosed by CISA in First Half of 2023: Analysis

        CISA disclosed 670 ICS vulnerabilities in the first half of 2023, but roughly one-third have no patches or mitigations from the vendor.

      • LWNSecurity updates for Friday

        Security updates have been issued by CentOS (bind and kernel), Debian (cjose, firefox-esr, ntpsec, and python-django), Fedora (chromium, firefox, librsvg2, and webkitgtk), Red Hat (firefox), Scientific Linux (firefox and openssh), SUSE (go1.20, ImageMagick, javapackages-tools, javassist, mysql-connector-java, protobuf, python-python-gflags, kernel, openssl-1_1, pipewire, python-pip, and xtrans), and Ubuntu (cargo, rust-cargo, cpio, poppler, and xmltooling).

      • USDOJNigerian National Pleads Guilty to $1.25 Million Business Email Compromise Scam Impacting U.S. Company

        Onwuchekwa Nnanna Kalu, 39, a Nigerian National from Rivers State, Nigeria, pleaded guilty today to stealing $1.25 million from an investment firm located in Boston, through a business email compromise (“BEC”) scam. The plea was announced by U.S. Attorney Matthew M. Graves and Acting Special Agent in Charge David Geist, of the FBI Washington Field Office's Criminal and Cyber Division.

        Nnanna Kalu pleaded guilty in the District of Columbia to one count of wire fraud. U.S. District Court Judge Randolph D. Moss scheduled a sentencing hearing for November 29, 2023. Kalu was arrested in 2022 and has been detained by the Court as a risk of flight.

      • Gray Media GroupMassive data breach could impact many who attended or worked for public schools in Colorado

        A news release issued by the Colorado Department of Higher Education is notifying the public of a “data incident.”

        KKTV 11 News is working to learn more about the situation, but the release reads as follows:

        The Colorado Department of Higher Education (“CDHE”) is providing notice of a cybersecurity incident that may involve the personal information of certain individuals. CDHE is providing information about the measures it has taken in response to the incident, and steps impacted individuals may take to protect themselves against possible misuse of information.

    • Defence/Aggression

      • JURISTSingapore executes second prisoner in one week despite international outcry

        Singaporean authorities executed Mohamed Shalleh Bin Abdul Latiff, a 39-year-old former delivery driver, Thursday for trafficking 54.04 grams of diamorphine, a controlled drug, which is four times the amount required to trigger the mandatory death penalty under Singapore’s Misuse of Drugs Act. Shalleh is the second person executed by the country in the last week.

      • Federal News NetworkUS military may put armed troops on commercial ships in Strait of Hormuz to stop Iran seizures

        The U.S. military is considering putting armed personnel on commercial ships traveling through the Strait of Hormuz, in what would be an unheard of action aimed at stopping Iran from seizing and harassing civilian vessels. That's what five American officials told The Associated Press on Thursday. If implemented, it would be an extraordinary step by the Pentagon as it grapples with a renewed effort by Iran to harass and seize ships traveling in the strait, through which 20% of all the world’s crude oil passes. Iran’s mission to the United Nations did not immediately respond to a request for comment from the AP about the U.S. proposal.

      • War in Ukraine

    • Environment

    • Finance

      • AxiosHackerOne lays off 12% of workforce

        Popular bug bounty program HackerOne is laying off 12% of its workforce, CEO MÃ¥rten Mickos told employees earlier this week.

      • Daniel PocockDaniel Pocock: Conflicts of Interest: Extinction Rebellion & Rishi Sunak, Greenpeace & Donald Trump

        There have been many rumors about conflicts of interest in the Debian Google Summer of Code and Outreachy internships. The only case where evidence has appeared is the former leader himself, the very person who started rumors about other mentors and I included.

        Yet conflicts of interest can come in many forms. One of the most bizarre cases I've seen was a pensions industry meeting in the UK.

        Representatives of pension administrators and government officials gathered in the town of Swindon. Rishi Sunak, who has recently become Prime Minister, attended the meeting in his former role as local authorities minister.

      • AxiosThe lesson for the Fed in "early hiker" monetary policy

        One reason to be optimistic that U.S. inflation can fall without a recession: Many smaller nations that did move earlier than the Federal Reserve to hike interest rates have done exactly that.

        Why it matters: The unusual dynamics of a post-pandemic global economy appear to be making a so-called "immaculate disinflation" — one with minimal pain — more plausible than it once seemed based on the historical record.


        What they're saying: "There are other economies we can also look to to get some sense of what's likely to happen in the U.S. — other economies that were actually a lot faster in tightening monetary policy," Jan Hatzius, chief economist at Goldman Sachs, said on a call with reporters last month.

      • BloombergTech Giants Slash Marketing Budgets, Bruising Major Ad Firms

        After massive layoffs earlier this year, technology giants have found one more item to slash: marketing budgets.

        Several large advertising companies reported a sharp cutback in spending from US tech and telecom companies, which had recently become some of the largest marketers in the world.

      • Telus slashing 6,000 jobs in order to remain competitive

        According to news outlets, including CBC News, the company plans to cut approximately 6,000 jobs. 4,000 roles will be eliminated at Telus’ main business, with the remaining 2,000 affecting Telus International.

        President and CEO Darren Entwistle claimed that the reduction is being made with “a very heavy heart” and was prompted by the “evolving regulatory, competitive and macroeconomic environment.”

        “Against the backdrop of rapid transformation in our industry and the ways in which our customers want to engage with us, today we are announcing a significant investment in an extensive efficiency and effectiveness initiative across Telus,” Entwistle said in a news release obtained by CBC News.

      • Study after study shows that working from home leads to more efficiency and higher quality work — so why do companies want people back in the office? Here are 3 possible reasons

        Employees overwhelmingly love the option to work from home. More than nine in 10 prefer it exclusively or as a hybrid arrangement, a Gallup study shows.

        Employers, on the other hand, don't appear fully on board, as many are calling employees back into the office.

        In some ways, employers' resistance to remote work is a mystery. After all, eliminating commutes gives the average U.S. employee almost one extra hour to work each day, according to research from the University of Chicago’s Becker Friedman Institute. Plus, staff forced to work in-office are more likely to experience burnout and low engagement, per Gallup.

    • AstroTurf/Lobbying/Politics

    • Censorship/Free Speech

    • Freedom of Information / Freedom of the Press

    • Monopolies



Recent Techrights' Posts

Rudeness and Vulgarity Won't Stop Journalism About Free Software
we seem to be on the right path
IBM Plans for Layoffs Becoming Clearer With "Employee Reviews"
Of course this impacts Red Hat as well
If You Don't Want "Linux" to Become "Windows", Then Follow GNU
GAFAM isn't a friend of Linux; it's only a user in the same sense clients are "users" of a brothel
 
Windows and Slop Declining While Microsoft Silences Critics
Microsoft tries to suppress facts while faking 'demand' by imposing slop on everybody, everywhere
openai.com Traffic Said to Have Fallen 50% in the Past Three Months, Reports Say It Nearly Ran Out of Money to Borrow
After the slop frenzy all we'll have left is environmental destruction
IBM Kills OzLabs, Signalling An Attack on Free Software (a Sign for Red Hat)
ibiblio also appears to have died (or experiences critical issues)
Red Hat Vice President Leaving After Nearly Two Decades
IBM's culture of secrecy is not compatible with Free software
Links 20/01/2026: "ChatGPT Health" (Latest Distraction From Being Insolvent) Flops and Raises Concerns, "The U.S. Military Faces a Reckoning on Greenland"
Links for the day
Readers Pleased With Layout Changes
Two days ago we began improving clarity and accessibility in the site
IBM is Outsourcing Red Hat's Fedora to Slop to 'Save Money'
If IBM cared about quality rather than alleged "cost savings" (cutting corners), it would assign more IBM staff to Fedora, but instead the exact opposite happened, with the likes of Cotton and Miller removed from the project
European Patent Office (EPO) Industrial Actions Formally Start in Two Hours
As per the latest (revised) action plan, today workers will slow down their work and limit patent grants
Microsoft Under Fresh Investigation by the Italian Competition Authority
In 2025 we kept a running tally of 30,000+ Microsoft layoffs, so 40k this year would not be unthinkable
The "Alicante Mafia" - Part VI - More Strikes Planned at the EPO, Starting This Month
Yesterday we said that friends of Berenguer or inside Berenguer's circle may have left
Gemini Links 20/01/2026: New Tea, Using a Roku at a Hotel, and "Voltage-Based Power Management for Any Raspberry Pi"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, January 19, 2026
IRC logs for Monday, January 19, 2026
Links 19/01/2026: National Broadcasters on World or Local Affairs Up to a Week Ago
Links for the day
Gemini Links 19/01/2026: Game Boy and "The Lounge" (IRC) for the Elderly
Links for the day
Slopfarms in Google News (at Least Three Today) With Fake 'Articles' About "Linux"
Google itself is trying to promote its own slop ("Overview") at the expense of original and credible sources
Links 19/01/2026: ChatGPT’s Defects and The Guardian on Why So-called "AI Companies Will Fail"
Links for the day
This is What the Slop Bubble Popping Can Look Like
Maybe not an overnight collapse, but getting there gradually
IBM Quiet About Its Plan for Red Hat Amid Accelerated Bluewashing
Something is going on at Red Hat
The "Alicante Mafia" - Part V - It Seems Like Some People Are Already Leaving "The Mafia"
they have a rough idea of what's coming
Microsoft Means War, Microsoft is on the Side of ICE
Microsoft, people-ready
More Confirmatory Rumours Regarding "Massive" Red Hat Layoffs
Ecosystem and sales said to be targeted
Proprietary UNIX is What We'll Have If IBM Red Hat Gets Its Way
IBM Red Hat wants to control everything, even if that means killing everybody
Free Software in Times of Peace (and Times of War, Too)
GAFAM and IBM are war companies
Founder of GNU/Linux (RMS) Speaks in US University (College) This Week
The auditorium has very high capacity and this is his "college comeback" talk in the United States
Office Meetings Are Most Useful to the Least Productive Workers
In my "office life" days I really didn't like meetings
LinuxSecurity and Linuxiac Are Still Slopfarms, Even Anthony Pell Does It
We suppose waiting another month or another year won't change a thing
Claim That the Board of Directors at IBM Isn't Happy With How the Company is Run
IBM tries to project an image of strength to the whole world, especially to its clients
Links 18/01/2026: Legal Trouble for xAI, Climate Concerns, Data Breaches and More
Links for the day
'Vibe Coding', Chatbots, and Other Bots (e.g. "Agents" Disguised as "Superintelligence") Aren't Saving You Time
False marketing, FOMO marketing tactics
Gemini Links 19/01/2026: Analog Cameras and Plucker in 2026, US Losing Acceptability in Europe
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, January 18, 2026
IRC logs for Sunday, January 18, 2026
Links 18/01/2026: The "Deepfake Porn Site Formerly Known as Twitter" and Turkey to Block Kids' Access to Social Control Media
Links for the day
Gemini Links 18/01/2026: Against English as Language of the Net, "Symposium of Destruction"
Links for the day
You Would Expect This Kind of Misleading Narrative Shortly Before Microsoft (or GAFAM) Mass Layoffs
misleading PR
FOSDEM 2026: democracy panel, GNOME & Sonny Piers modern slavery experiment
Reprinted with permission from Daniel Pocock
Pump-and-Dump With IBM Shares, Courtesy of People Who Stand to Gain From the 'Pump'
"3 Reasons to Buy IBM Stock Right Now"
IBM: Spying on Staff Like Never Before and Implementing Silent Layoffs This Month, Say Insiders
what we heard from whistleblowers seems to corroborate
'Cancel Culture' Doesn't Work (in the Long Run)
Despite all the attacks, I'm enjoying life, I'm keeping productive, and our audience continues to grow
IBM is Not a Free Software Company (It Never Was)
Red Hat's main product, RHEL, is full of secret sauce and has 'secret recipes' (it is basically proprietary)
IBM Turning Up the 'RTO' (Stress) and 'PIP' (Fear) Heat on Workers, Rebellion May be Brewing
Sometimes it feels like today's executives at IBM view IBM workers as a liability
Links 18/01/2026: Indonesia Against Comedy, Media-Hostile (Censors Comedians) Convicted Felon in White House Defecting to Opponents of NATO
Links for the day
GNU/Linux Still up (statCounter Says to 6%) in Bosnia And Herzegovina
Let's see where it is at year's end
Making Layout Changes
Feedback can be sent to us
Behind an Economy of Fake 'Worths' and Fictional 'Valuations' or 'Market Caps'
They normalise white-collar crime and say "everyone is doing it!"
Links 18/01/2026: "South Africa is Running Out of Software Developers", Companies Spooked to Find Slop is a Major Liability
Links for the day
Eventually the Joke (and Financial Fraud) is on Microsoft, Stigmatised for Slop
Is Microsoft trying to commit suicide?
GNU/Linux Leaps to All-time Highs in Virgin Islands
it seems to have started around the "end of 10"
Place Your Bets: Who Will Die First? Microsoft or IBM?
Not even joking; make a guess
Making and Keeping the Sites Accessible
Sometimes less does mean "more" (or "MOAR")
The "Alicante Mafia" - Part IV - How Europe's Largest Patent Office Recruited Drug Addicts, Antisemites, and People Who Absolutely Cannot Do the Job (But Know the 'Right' People)
To better overlap industrial actions we might delay/postpone/pause this series for a bit
Restoring Professional Pride in the Tech Sector
Rejecting slop isn't being a Luddite
Benefiting by Adding Presence in Geminispace
As the Web gets worse, not limited to bloat as a factor, people seek alternatives
Google News Recently Started Syndicating Another Slopfarm, Linuxiac
Even if Google is aware that there is slop there, it's hard to believe that Google will mind
Slop Bubble "Is Worse Than The Dot Com Bubble"
Edward Zitron Says It like it is
Software Patents and USMCA (or NAFTA)
We recently pondered going back to issuing 2-3 articles per day about patents and common issues with them
IBM Sued Over PIPs
PIPs are "performance improvement plans"
Sites With "Linux" in Their Name That Are in Effect Slopfarms and Issue Fake Articles
We try to name some of the prolific culprits
Gemini Links 18/01/2026: Raising Notifications From Terminal and Environmental Sanity
Links for the day
IRC Proceedings: Saturday, January 17, 2026
IRC logs for Saturday, January 17, 2026
Over at Tux Machines...
GNU/Linux news for the past day