Agregátor RSS

Cisco scores a perfect CVSS 10 with critical flaw in its wireless system

The Register - Anti-Virus - 7 Listopad, 2024 - 12:48
Ultra-Reliable Wireless Backhaul doesn't live up to its name

Cisco is issuing a critical alert notice about a flaw that makes its so-called Ultra-Reliable Wireless Backhaul systems easy to subvert.…

Kategorie: Viry a Červi

AMD rolls out open-source OLMo LLM, to compete with AI giants

Computerworld.com [Hacking News] - 7 Listopad, 2024 - 12:47

AMD has launched its first open-source large language models (LLMs) under the OLMo brand, aiming to strengthen its position in the competitive AI landscape led by giants like Nvidia, Intel, and Qualcomm.

AMD OLMo is a series of 1-billion parameter large language models trained from scratch using trillions of tokens on a cluster of AMD Instinct MI250 GPUs. They are designed to excel in reasoning, instruction-following, and chat while embracing an open-source ethos that allows developers access to data, weights, training recipes, and code.

“Continuing AMD tradition of open-sourcing models and code to help the community advance together, we are excited to release our first series of fully open 1 billion parameter language models, AMD OLMo,” AMD said in a statement.

AMD’s open-source approach positions OLMo as an accessible and scalable option for companies seeking alternatives in AI technology. The model can be deployed in data centers or on AMD Ryzen AI PCs equipped with neural processing units (NPUs), allowing developers to leverage advanced AI directly on personal devices, the statement added.

“AMD is following Nvidia’s lead by expanding into the large language model (LLM) space alongside its well-established strength in computing hardware — a direction that Intel and Qualcomm have not yet fully embraced,” said Abhigyan Malik, practice director at Everest Group. “By fostering an open ecosystem, AMD enables developers to innovate and build diverse applications through a network effect.”

According to Malik, this strategy amplifies AMD’s core value proposition, particularly in driving demand for its underlying hardware, including AMD Instinct MI250 GPUs and Ryzen CPUs, where “AMD seeks to create lasting market impact.”

Extensive training and fine-tuning

The OLMo series follows a detailed three-phase training and fine-tuning process, according to AMD.

Initially, OLMo 1B was pre-trained on a subset of the Dolma v1.7 dataset using a transformer model focused on next-token prediction. This helped the model grasp general language patterns. In its second phase, the OLMo 1B was supervised and fine-tuned (SFT) on multiple datasets to refine its capabilities in science, coding, and mathematics.

The final model, OLMo 1B SFT DPO, was optimized with Direct Preference Optimization (DPO) based on human feedback, resulting in a model that effectively aligns its responses with typical user expectations.

Competitive performance and benchmark success

In internal benchmarks, AMD’s OLMo models performed well against similarly sized open-source models, such as TinyLlama-1.1B and OpenELM-1_1B, in multi-task and general reasoning tests, the company claimed. Specifically, its performance increased by over 15% on tasks in GSM8k, a substantial gain attributed to AMD’s multi-phase supervised fine-tuning and Direct Preference Optimization (DPO). ‘

In multi-turn chat tests, AMD claimed, OLMo showed a 3.41% edge in AlpacaEval 2 Win Rate and a 0.97% gain in MT-Bench over its closest open-source competitors.

However, when looking at the broader LLM landscape, Nvidia’s GH200 Grace Hopper Superchip and H100 GPU remain leaders in LLM processing, particularly for large, multi-faceted AI workloads. Nvidia’s focus on innovations like C2C link, which accelerates data transfer between its CPU and GPU, gives it an edge, providing a speed advantage for high-demand inference tasks such as recommendation systems.

Intel, while slightly behind in peak speed, leverages its Habana Gaudi2 accelerator for cost-effective yet robust performance, with future upgrades planned for increased precision. ‘

Meanwhile, Qualcomm’s Cloud AI100 emphasizes power efficiency, meeting the needs of organizations seeking high AI performance without the extensive energy demands associated with Nvidia’s high-end systems.

AMD’s OLMo models also showed strong performance on responsible AI benchmarks, such as ToxiGen (for toxic language detection), crows_pairs (bias assessment), and TruthfulQA-mc2 (accuracy). These scores reflect AMD’s commitment to ethical AI, an essential focus as AI integration scales across industries.

AMD’s position in the AI market

With its first open-source LLM series, AMD is positioned to make significant inroads in the AI industry, offering a compelling balance of capability, openness, and versatility to compete in a market currently led by Nvidia, Intel, and Qualcomm.

However, AMD’s ability to close the gap will depend on how well its open-source initiative and hardware enhancements keep pace with rivals’ advances in performance, efficiency, and specialized AI capabilities.

“AMD’s entry into the open-source LLM space strengthens the ecosystem, potentially lowering the operational costs associated with adopting generative AI,” said Suseel Menon, practice director at Everest Group.

AMD’s move into LLMs places it against established players like Nvidia, Intel, and Qualcomm, who have gained market prominence with their proprietary models.

“This move also puts pressure on proprietary LLMs to continually innovate and justify their pricing structures,” Menon added.

Analysts believe AMD’s unique open-source strategy and accessibility aim to attract enterprises and developers looking for flexible, affordable AI solutions without proprietary constraints.

“For large enterprises with long-term data privacy concerns, AMD’s open-source model offers a compelling alternative as they navigate AI integration,” Menon added. “By building a cohesive, full-stack AI offering that spans hardware, LLMs, and ecosystem tools, AMD is positioning itself with a distinct competitive edge among leading silicon vendors.”

Kategorie: Hacking & Security

Podíl Windows 10 klesá, ale Jedenáctky ještě mají co dohánět

Živě.cz - 7 Listopad, 2024 - 12:45
**Windows 10 v posledním půl roce klesá tržní podíl **Na jejich úrok naopak rostou Jedenáctky **Ty po třech letech na trhu dosáhly na téměř 36% podíl
Kategorie: IT News

Sestříhané videozáznamy z konference OpenAlt 2024

AbcLinuxu [zprávičky] - 7 Listopad, 2024 - 12:36
Na YouTube byly zveřejněny sestříhané videozáznamy přednášek z letošního OpenAltu. Dostupné jsou také přímo z programu po kliknutí na přednášku.
Kategorie: GNU/Linux & BSD

Netflix a 30 nejoblíbenějších filmů a seriálů v listopadu 2024. Třeba vražedná Monstra, Emily in Paris, nová řada Outer Banks

Živě.cz - 7 Listopad, 2024 - 12:15
Tyto filmy a seriály jsou teď na českém Netflixu nejoblíbenější. Nerozlišujeme žánr, stáří ani hodnocení na filmových webech. Jde o souhrnnou oblíbenost za poslední týdny, kterou zjišťuje web FlixPatrol.
Kategorie: IT News

Počasí&radar je trošku jiná domácí meteostanice. Namísto hromady čidel všechno stahuje z internetu

Živě.cz - 7 Listopad, 2024 - 11:45
** Meteostanička Počasí&radar Home 3 sama o sobě skoro nic neměří ** Všechna data totiž stahuje z internetu ** Její animovaná mapka vydá za tisíc slov
Kategorie: IT News

Nositelnosti se nabíjí z lidského těla. Mezi první funkční koncepty patří prsten, e-ink displej a teploměr

Živě.cz - 7 Listopad, 2024 - 11:15
** Jako by nestačilo nabíjení smartphonů... **...ještě musíme řešit nabíjení hodinek, náramků, sluchátek a prstenů. ** U jednoduchých nositelností by to však mohla změnit nová technologie
Kategorie: IT News

IT certifications for cloud architects, data security engineers, and ethical hackers yield the biggest pay boosts

Computerworld.com [Hacking News] - 7 Listopad, 2024 - 11:00

Cloud architects, data security engineers, and ethical hackers are among the highest-paying skills that can be attained through IT certifications — and AI technology didn’t even make the list.

Online learning platform Skillsoft analyzed the top reported salaries of IT professionals around the world to find the highest-paying certifications and developed a list of more than 20.

This year’s list shows that cloud computing skills remain in high demand and can be quite lucrative. The AWS Certified Security Specialty training jumped from sixth-highest to the top-paying certification this year to now command a $204,000 annual salary on average — a up 22% or $40,000 over last year.

The presence of certifications for Google Cloud Platform (GCP), AWS, Azure, and Nutanix also highlights the value of a diverse cloud skillset, as organizations adopt multi-cloud or hybrid cloud strategies, according to Skillsoft.

Its list is similar to one published earlier this year by job search platform Indeed, which also placed an AWS certification in the No. 1 slot. (Indeed found AWS Certified Solutions Architects could earn from $133,200 to $246,900 a year at some firms.)

“So, are they worth it? For those looking for any of the above, it’s a resounding yes,” Skillsoft said a blog post. “But, earning a certification takes time, effort, and often money.”

Are certifications worth the price?

Earning a certification led to pay raises, promotions and new jobs, according to Skillsoft. In addition to AWS training, rounding out the top five certifications were:

  1. Google Cloud – Professional Cloud Architect, averages $190,204.
  2. Nutanix Certified Professional – Multicloud Infrastructure (NCP-MCI) v6.5, averages $175,409.
  3. CCSP – Certified Cloud Security Professional, averages $171,524.
  4. CCNP Security, averages $168,159.

Indeed’s list of 17 top certifications had these top five:

  1. AWS Certified Solutions Architect – Associate
  2. Certified Data Privacy Solutions Engineer (CDPSE)
  3. Certified Cloud Security Professional (CCSP)
  4. Certified Data Professional (CDP)
  5. Certified Ethical Hacker (CEH)

Gartner Research, in an August report, also found that AWS Certified Cloud Practitioners and Microsoft Certified Azure Fundamentals certifications were top upskilling opportunities for tech workers. Other IT certifications with fast-growing demand this year are in cybersecurity, including the CISSP certification, CISA, and CompTIA Security+, according to Gartner. (The latter — IT certifications from the Computing Technology Industry Association (CompTIA), a non-profit trade association — were also among the general class of top certifications on multiple lists.)

“While learning new technology skills is vital, the ability for employees to demonstrate practical expertise through industry-recognized certifications is increasingly valued,” Gartner said. “Though they may not be a mandatory prerequisite for every position, certifications can empower individuals and organizations alike.”

“Our data suggests that tech professionals skilled in cloud computing, security, data privacy, and risk management, as well as able to handle complex, multi-faceted IT environments, will be well positioned for success,” said Greg Fuller, vice president of online learning platform Codecademy Enterprise. “Overall, the IT job market is characterized by a significant imbalance between supply and demand, which continues to drive salaries higher.”

What’s happening with AI training?

While AI certifications have not yet to the top of IT certification lists, the increasing emphasis on data privacy and compliance is closely tied to the rollout of AI technologies. And while AI skills are gaining popularity, it often takes time for certifications to gain traction, Fuller said.

“Right now, what we see with areas like AWS Security at the top is that organizations are still preparing for large scale AI rollouts,” he said. “So more adjacent skills are on this year’s list. Ultimately, it’s a mix of certifications being a bit slower to evolve and adjacent skills rising in criticality.

“In the meantime, the backbone of AI is cloud, so getting cloud certified is a good first step. Then, look at some of the more specialized Cloud AI certifications,” Fuller added.

Recruitment and talent consulting firm WilsonHCG released a report this week indicating that while AI certifications might not be on the top 20 lists, there is rising demand for AI skills across sectors. The market for AI-skilled workers is expanding, too, with 5,898 average monthly job postings in October, according to WilsonHCG.

The rise in the number AI-focused certifications reflects a significant increase from the 12-month average of 5,147, driven by heightened interest in roles like data scientist, AI research engineer, and machine learning engineer.

Companies such as TikTok, Apple, Google, Amazon, and Deloitte are among the most active in AI recruitment, underscoring the technology’s growing adoption in sectors from tech to finance and professional services, according to WilsonHCG.

The need for AI skills extends beyond traditional tech positions. Companies are seeking professionals across a range of roles, including Founding AI Engineer and Senior Software Engineer for AI products,” WilsonHCG said in its report. “This trend is reshaping hiring practices and job titles as more organizations prioritize data-driven and AI-enabled functions across departments.”

Skills continue to matter more than formal education

Skills-based hiring approaches that emphasize strong work backgrounds, certifications, assessments, and endorsements, continue to dominate the tech industry. And soft skills are becoming a key focus of hiring managers, even over hard skills.

Elise Smith, co-founder and CEO of Praxis Labs, an AI-based learning platform, said she has worked with enterprises like Google, Uber, and ServiceNow to help senior leaders develop the skillsets needed for “new-age talent retention” and collaboration in the workplace.

“As workplaces continue to transform — whether its emerging technologies like genAI transforming how we work or sociopolitical conflicts that cause disruption to our workflows — human skills will become more and more important,” Smith said.

What’s often missing from higher education is a focus on skills building around interpersonal communication, conflict resolution, critical reasoning, and the ability to determine fact from opinion or misinformation. “What once may have been called soft skills will be seen as power skills, and workforces who focus and develop these skills will differentiate in market outcomes,” Smith said.

While building relations and moving beyond “transactional trust” in the workplace can be challenging — especially for a hybrid global workforce — it’s important to build skills around workplace connection.

“When managers are skilled in asking open-ended questions, coaching disengaged team members, learning more about individuals’ backstories and contexts, and encouraging them in their work, teams thrive,” she said. “These are the skillsets we help our clients and their people leaders develop.”

Kategorie: Hacking & Security

5 Most Common Malware Techniques in 2024

The Hacker News - 7 Listopad, 2024 - 10:48
Tactics, techniques, and procedures (TTPs) form the foundation of modern defense strategies. Unlike indicators of compromise (IOCs), TTPs are more stable, making them a reliable way to identify specific cyber threats. Here are some of the most commonly used techniques, according to ANY.RUN's Q3 2024 report on malware trends, complete with real-world examples. Disabling of Windows Event Logging
Kategorie: Hacking & Security

5 Most Common Malware Techniques in 2024

The Hacker News - 7 Listopad, 2024 - 10:48
Tactics, techniques, and procedures (TTPs) form the foundation of modern defense strategies. Unlike indicators of compromise (IOCs), TTPs are more stable, making them a reliable way to identify specific cyber threats. Here are some of the most commonly used techniques, according to ANY.RUN's Q3 2024 report on malware trends, complete with real-world examples. Disabling of Windows Event Logging The Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

ChatGPT s kratší adresou. OpenAI koupila lukrativní doménu chat.com

Živě.cz - 7 Listopad, 2024 - 10:45
Společnost OpenAI je novým majitelem internetové domény chat.com . Tu loni koupil spoluzakladatel a technické šéf HubSpotu Dharmesh Shah za 15,5 milionu dolarů, ale letos na jaře oznámil, že ji zase obratem prodal. Až nyní potvrdil , že se na obchodu dohodl se Samem Altmanem. Ten krátce před ním ...
Kategorie: IT News

SteelFox and Rhadamanthys Malware Use Copyright Scams, Driver Exploits to Target Victims

The Hacker News - 7 Listopad, 2024 - 10:42
An ongoing phishing campaign is employing copyright infringement-related themes to trick victims into downloading a newer version of the Rhadamanthys information stealer since July 2024. Cybersecurity firm Check Point is tracking the large-scale campaign under the name CopyRh(ight)adamantys. Targeted regions include the United States, Europe, East Asia, and South America. "The campaign
Kategorie: Hacking & Security

SteelFox and Rhadamanthys Malware Use Copyright Scams, Driver Exploits to Target Victims

The Hacker News - 7 Listopad, 2024 - 10:42
An ongoing phishing campaign is employing copyright infringement-related themes to trick victims into downloading a newer version of the Rhadamanthys information stealer since July 2024. Cybersecurity firm Check Point is tracking the large-scale campaign under the name CopyRh(ight)adamantys. Targeted regions include the United States, Europe, East Asia, and South America. "The campaign Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait

The Hacker News - 7 Listopad, 2024 - 10:40
The China-aligned threat actor known as MirrorFace has been observed targeting a diplomatic organization in the European Union, marking the first time the hacking crew has targeted an entity in the region. "During this attack, the threat actor used as a lure the upcoming World Expo, which will be held in 2025 in Osaka, Japan," ESET said in its APT Activity Report for the period April to
Kategorie: Hacking & Security

China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait

The Hacker News - 7 Listopad, 2024 - 10:40
The China-aligned threat actor known as MirrorFace has been observed targeting a diplomatic organization in the European Union, marking the first time the hacking crew has targeted an entity in the region. "During this attack, the threat actor used as a lure the upcoming World Expo, which will be held in 2025 in Osaka, Japan," ESET said in its APT Activity Report for the period April to Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

UK launches platform to help businesses manage AI risks, build trust

Computerworld.com [Hacking News] - 7 Listopad, 2024 - 10:22

The UK government has introduced an AI assurance platform, offering British businesses a centralized resource for guidance on identifying and managing potential risks associated with AI, as part of efforts to build trust in AI systems.

About 524 companies now make up the UK’s AI sector, supporting more than 12,000 jobs and generating over $1.3 billion in revenue, the UK government said. Official projections estimate the market could grow to $8.4 billion by 2035.

Kategorie: Hacking & Security

Cisco Releases Patch for Critical URWB Vulnerability in Industrial Wireless Systems

The Hacker News - 7 Listopad, 2024 - 10:08
Cisco has released security updates to address a maximum severity security flaw impacting Ultra-Reliable Wireless Backhaul (URWB) Access Points that could permit unauthenticated, remote attackers to run commands with elevated privileges. Tracked as CVE-2024-20418 (CVS score: 10.0), the vulnerability has been described as stemming from a lack of input validation to the web-based management
Kategorie: Hacking & Security

Cisco Releases Patch for Critical URWB Vulnerability in Industrial Wireless Systems

The Hacker News - 7 Listopad, 2024 - 10:08
Cisco has released security updates to address a maximum severity security flaw impacting Ultra-Reliable Wireless Backhaul (URWB) Access Points that could permit unauthenticated, remote attackers to run commands with elevated privileges. Tracked as CVE-2024-20418 (CVS score: 10.0), the vulnerability has been described as stemming from a lack of input validation to the web-based management Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Malicious PyPI Package ‘Fabrice’ Found Stealing AWS Keys from Thousands of Developers

The Hacker News - 7 Listopad, 2024 - 10:07
Cybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) that has racked up thousands of downloads for over three years while stealthily exfiltrating developers' Amazon Web Services (AWS) credentials. The package in question is "fabrice," which typosquats a popular Python library known as "fabric," which is designed to execute shell commands remotely over
Kategorie: Hacking & Security

Malicious PyPI Package ‘Fabrice’ Found Stealing AWS Keys from Thousands of Developers

The Hacker News - 7 Listopad, 2024 - 10:07
Cybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) that has racked up thousands of downloads for over three years while stealthily exfiltrating developers' Amazon Web Services (AWS) credentials. The package in question is "fabrice," which typosquats a popular Python library known as "fabric," which is designed to execute shell commands remotely over Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah