link1s.site

Google extends Linux kernel support to 4 years

According to AndroidAuthority, the Linux kernel used by Android devices is mostly derived from Google's Android Universal Kernel (ACK) branch, which is created from the Android mainline kernel branch when new LTS versions are released upstream. For example, when kernel version 6.6 is announced as the latest LTS release, an ACK branch for Android15-6.6 appears shortly after, with the "android15" in the name referring to the Android version of the kernel (in this case, Android 15).

Google maintains its own set of LTS kernel branches for three main reasons. First, Google can integrate upstream features that have not yet been released into the ACK branch by backporting or picking, so as to meet the specific needs of Android. Second, Google can include some features that are being developed upstream in the ACK branch ahead of time, making it available for Android devices as early as possible. Finally, Google can add some vendor or original equipment manufacturer (OEM) features for other Android partners to use.

Once created, Google continues to update the ACK branch to include not only bug fixes for Android specific code, but also to integrate the LTS merge content of the upstream kernel branch. For example, the Linux kernel vulnerability disclosed in the July 2024 Android security bulletin will be fixed through these updates.

However, it is not easy to distinguish a bug fix from other bug fixes, as a patch that fixes a bug may also accidentally plug a security vulnerability that the submitter did not know about or chose not to disclose. Google does its best to recognize this, but it inevitably misses the mark, resulting in bug fixes for the upstream Linux kernel being released months before Android devices. As a result, Google has been urging Android vendors to regularly update the LTS kernel to avoid being caught off guard by unexpectedly disclosed security vulnerabilities.

Clearly, the LTS version of the Linux kernel is critical to the security of Android devices, helping Google and vendors deal with known and unknown security vulnerabilities. The longer the support period, the more timely security updates Google and vendors can provide to devices.

The largest password leak in history exposes nearly 10 billion credentials
The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews. This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords. Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum. “In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.” Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems. Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said. This could affect online services, cameras and hardware This could affect various targets, from online services to internet-facing cameras and industrial hardware. “Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded. However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades. This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak. Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information. That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms. Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security. Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.
Poland and Ukraine sign bilateral security agreement
On July 8, Ukrainian President Zelensky, who was visiting Poland, and Polish Prime Minister Tusk signed a bilateral security agreement in Warsaw, the capital of Poland. The agreement clearly states that Poland will provide support to Ukraine in air defense, energy security and reconstruction. After signing the agreement, Tusk said that the agreement includes actual bilateral commitments, not "empty promises." Previously, the United States, Britain, France, Germany and other countries as well as the European Union signed similar agreements with Ukraine.
Stanford AI project team apologizes for plagiarizing Chinese model
An artificial intelligence (AI) team at Stanford University apologized for plagiarizing a large language model (LLM) from a Chinese AI company, which became a trending topic on the Chinese social media platforms, where it sparked concern among netizens on Tuesday. We apologize to the authors of MiniCPM [the AI model developed by a Chinese company] for any inconvenience that we caused for not doing the full diligence to verify and peer review the novelty of this work, the multimodal AI model Llama3-V's developers wrote in a post on social platform X. The apology came after the team from Stanford University announced Llama3-V on May 29, claiming it had comparable performance to GPT4-V and other models with the capability to train for less than $500. According to media reports, the announcement published by one of the team members quickly received more than 300,000 views. However, some netizens from X found and listed evidence of how the Llama3-V project code was reformatted and similar to MiniCPM-Llama3-V 2.5, an LLM developed by a Chinese technology company, ModelBest, and Tsinghua University. Two team members, Aksh Garg and Siddharth Sharma, reposted a netizen's query and apologized on Monday, while claiming that their role was to promote the model on Medium and X (formerly Twitter), and that they had been unable to contact the member who wrote the code for the project. They looked at recent papers to validate the novelty of the work but had not been informed of or were aware of any of the work by Open Lab for Big Model Base, which was founded by the Natural Language Processing Lab at Tsinghua University and ModelBest, according to their responses. They noted that they have taken all references to Llama3-V down in respect to the original work. In response, Liu Zhiyuan, chief scientist at ModelBest, spoke out on the Chinese social media platform Zhihu, saying that the Llama3-V team failed to comply with open-source protocols for respecting and honoring the achievements of previous researchers, thus seriously undermining the cornerstone of open-source sharing. According to a screenshot leaked online, Li Dahai, CEO of ModelBest, also made a post on his WeChat moment, saying that the two models were verified to have highly similarity in terms of providing answers and even the same errors, and that some relevant data had not yet been released to the public. He said the team hopes that their work will receive more attention and recognition, but not in this way. He also called for an open, cooperative and trusting community environment. Director of the Stanford Artificial Intelligence Laboratory Christopher Manning also responded to Garg's explanation on Sunday, commenting "How not to own your mistakes!" on X. As the incident became a trending topic on Sina Weibo, Chinese netizens commented that academic research should be factual, but the incident also proves that the technology development in China is progressing. Global Times
Russian military launches massive missile attack, Kiev children's hospital hit; President Biden issues statement condemning Russia's "brutalism"
A children's hospital in the Ukrainian capital was hit by a Russian missile on Monday as part of a wave of airstrikes across Ukraine that has killed at least 31 people and injured 154 others. "Russian terrorists have once again launched a massive missile attack on Ukrainian cities - Kiev, Dnipro, Kryvyi Rih, Slaviansk, Kramatorsk," said Ukrainian President Volodymyr Zelenskyy. Zelensky said Russia fired more than 40 missiles of different types at the five cities in daytime attacks, hitting residential buildings and public infrastructure. The Ukrainian air force said it intercepted 30 missiles. Authorities said the attack on Kiev killed seven people, while the attack on Kryvyi Rih, Zelensky's birthplace in central Ukraine, killed 10 and injured 47. United Nations Secretary-General António Guterres condemned the attacks, calling the assault on the Kiev hospital and another medical facility in the capital's Dniprovsky district "particularly egregious," said his spokesman, Stephane Dujarric. "Direct attacks on civilians and civilian objects are prohibited under international humanitarian law. Any such attacks are unacceptable and must cease immediately," Dujarric said. The U.N. Security Council will meet Tuesday to discuss the Russian strikes, diplomats said. The Russian Defense Ministry said the strikes targeted Ukrainian defense factories and a military aviation base and were successful. It denied striking any civilian facilities and claimed, without evidence, that photos from Kiev showed the damage was caused by a Ukrainian anti-aircraft missile. Ukrainian Air Force Colonel Yurii Ignat said Russia has been improving the effectiveness of its air strikes by equipping its missiles with enhanced features, including so-called heat decoys that can throw air defense systems off target. In comments sent to The Associated Press, he said the cruise missiles flew low in Monday's attack -- just 50 meters off the ground -- making them harder to hit. Western countries, led by the United States, have provided Ukraine with billions of dollars in arms support. They will hold a three-day NATO summit in Washington starting Tuesday to work out how to reassure Kiev of NATO's strong support and give Ukrainians hope that their country can survive the largest conflict in Europe since World War II. "Today's Russian missile strike that killed dozens of Ukrainian civilians and caused damage and loss of life to Kyiv's largest children's hospital is a horrifying reminder of Russia's brutality," U.S. President Joe Biden said in a statement Monday. "It is critical that the world continues to stand with Ukraine at this important moment and that we do not ignore Russian aggression." Biden said in the statement that he will meet with President Zelensky during the NATO summit in Washington this week "to make clear our unwavering support for Ukraine." Biden continued: "We will join our allies in announcing new measures to strengthen Ukraine's air defenses and help protect their cities and civilians from Russian attacks. The United States stands with the Ukrainian people." Czech President Petr Pavel said the hospital attack was "inexcusable" and he hoped the NATO summit would reach a consensus that Russia is "the greatest threat and we must be fully prepared to deal with it." Zelensky said during a visit to Poland that he hoped the NATO summit would provide Ukraine with more air defense systems. The Ukrainian leader said rescuers were digging through the rubble of the Ohmatdit Children's Hospital in Kyiv and that the number of casualties was not yet known. Kyiv Mayor Vitali Klitschko said at least 16 people were injured, including seven children, and the attack caused a two-story wing of the hospital to partially collapse. Doors and windows were blown off the hospital's 10-story main building, and the walls were charred. The floor of one room was splattered with blood. Hospital officials said the intensive care unit, operating room and oncology department were damaged.
Could a $600 billion funding gap crush the AI industry?
On July 5, Microsoft co-founder Bill Gates appeared on the Next Big Idea podcast to discuss his vision for Superhuman artificial intelligence and technological progress. At the same time, it said that the enthusiasm of the AI market is far more than the Internet bubble. Gates believes that the current threshold for entry in the AI field is very low, and the entire market is in a fever period, AI startups can easily get hundreds of millions of dollars in financing, and even have raised $6 billion (about 43.734 billion yuan) in cash for a company. "Never before has so much capital poured into a new area, and the entire AI market has fallen into a 'frenzy' in terms of market capitalization and valuation, which dwarfs the frenzy of the Internet and automotive periods in history." Gates said. At this stage, the rapid development of the artificial intelligence industry is a veritable gold industry, and Nvidia's market value is therefore soaring, and the total market value reached 3.34 trillion US dollars on June 18 local time, surpassing Microsoft and Apple in one fell fell, becoming the world's most valuable listed enterprise. But in fact, doubts about the field of artificial intelligence have also risen one after another and have never stopped.