Post Syndicated from xkcd.com original https://xkcd.com/2911/

Post Syndicated from xkcd.com original https://xkcd.com/2911/

Post Syndicated from Explosm.net original https://explosm.net/comics/frog-prince
New Cyanide and Happiness Comic
Post Syndicated from jake original https://lwn.net/Articles/966525/
The 6.9-rc1 kernel prepatch is out for
testing. Linus Torvalds described some rather large updates to the core
kernel code that are coming for 6.9:
The timer subsystem had a fairly big rewrite, to have per-cpu timer
wheels to improve performance of timers, which can be a big deal
particularly for networking. The other fairly notable core update is
to the workqueue subsystem, where one notable addition is for BH
workqueue support. That’s notable mainly because it means we finally
have a way away from tasklets. The tasklet interface has basically
been deprecated for a long while, but we’ve never really had any good
alternatives (with threaded interrupt handlers being one suggested
use-case, but not realistic in many cases).
Post Syndicated from Editor original https://nebosystems.eu/dora-regulation-compliance-requirements/
The Digital Operational Resilience Act (DORA) is a EU regulation that entered into force on 16 January 2023 and will apply as of 17 January 2025. DORA (EU) 2022/2554 is a regulatory framework established by the European Union to enhance the digital operational resilience of the financial sector. It aims to ensure that all participants in the financial system have the necessary safeguards and measures in place to withstand, respond to, and recover from ICT (Information and Communication Technology) related disruptions and threats.
DORA affects a wide range of entities within the EU financial sector, including:
These entities encompass a broad spectrum of the financial sector within the EU, each playing a critical role in maintaining the stability and integrity of financial markets, and are thus subject to DORA’s regulatory framework aimed at enhancing their operational resilience against ICT risks.
DORA, the Digital Operational Resilience Act empowers competent authorities to impose administrative penalties and remedial measures for breaches of its regulations. This includes issuing orders to cease breaches, requiring the cessation of practices contrary to DORA provisions, adopting measures to ensure ongoing compliance with legal requirements, requiring existing data traffic records from telecommunication operators under suspicion of a breach, and issuing public notices or statements about the breach and responsible parties . The imposition of penalties considers the breach’s materiality, gravity, duration, the responsible party’s degree of responsibility, financial strength, profits gained or losses avoided due to the breach, losses caused to third parties, and the level of cooperation with the competent authority.
By adhering to these requirements, financial entities and their ICT third-party service providers will contribute to a more resilient and stable financial system capable of withstanding and responding effectively to digital disruptions and threats.
Navigating DORA’s requirements can be complex, but you don’t have to do it alone. Nebosystems offers tailored cybersecurity measures and consulting to ensure your compliance. Ready to secure your digital resilience? Contact us today.
Reference: Digital Operational Resilience Act (EU) 2022/2554. EUR-Lex.
Post Syndicated from Talks at Google original https://www.youtube.com/watch?v=VyIMzVsE1CI
Post Syndicated from turnoff.us original http://turnoff.us/geek/at-malloc-room/

Post Syndicated from Editor original https://nebosystems.eu/what-is-gdpr-key-requirements-guide/
In the digital landscape where data breaches and privacy concerns are increasingly prevalent, understanding the General Data Protection Regulation (GDPR) is essential for businesses and individuals alike. Implemented on May 25, 2018, GDPR represents a significant overhaul of data protection laws, setting a new global benchmark for privacy rights, security, and compliance.
The GDPR is a comprehensive data protection law that came into effect in the European Union (EU) but has far-reaching implications for companies worldwide. It represents a significant shift in the way personal data of individuals within these regions is collected, stored, processed, and protected by organizations worldwide. It aims to give individuals more control over their personal data and to unify data protection regulations across the EU, thereby simplifying the regulatory environment for international business
The GDPR affects:
The GDPR is built around several key principles that dictate how personal data should be handled, processed, and protected. Understanding these requirements is crucial for any organization striving for compliance:
The GDPR enhances and introduces new rights for data subjects, including:
By adhering to these requirements, organizations can ensure compliance with the GDPR, thereby enhancing the protection of personal data and potentially avoiding significant penalties for non-compliance. Non-compliance with the GDPR can result in hefty fines, with penalties reaching up to €20 million or 4% of the annual worldwide turnover of the preceding financial year, whichever is greater, for the most serious infringements.
The GDPR’s impact extends beyond the borders of the EU and EEA, affecting any organization worldwide that processes the personal data of individuals within these regions. Its implementation marks a significant step towards enhancing individuals’ privacy rights and setting a new global standard for data protection.
For organizations seeking to fortify their data protection measures in line with GDPR standards, our Comprehensive GDPR Compliance Cybersecurity Solutions provide a robust framework tailored to meet the unique challenges of your business.
Whether you’re looking to enhance your cybersecurity measures or seeking expert consulting to navigate GDPR compliance, reach out Nebosystems today. Let us help you transform GDPR compliance from a daunting obligation into an opportunity for enhanced data security and trust building.
Reference: General Data Protection Regulation (2016/679). EUR-Lex.
Post Syndicated from Explosm.net original https://explosm.net/comics/productive
New Cyanide and Happiness Comic
Post Syndicated from digiblur DIY original https://www.youtube.com/watch?v=2xLIOYpBQJY
Post Syndicated from turnoff.us original http://turnoff.us/geek/pair-programming-vibe-2/

Post Syndicated from Techmoan original https://www.youtube.com/watch?v=Aqo3kug8pPg
Post Syndicated from Надежда Радулова original https://www.toest.bg/sedmitsata-18-23-mart/

„Понеделник беше, ситен дъжд валеше. Вторник си замина влажен през комина“. Ето така, като в детско стихотворение, започна седмицата след Сирни заговезни: с неделната изцепка на ГЕРБ, която на моменти изглеждаше като кьорфишек, но постепенно набра скорост и доведе до голямо бум. При което отдавна разхлопаната сглобка се разпадна на ръждясали винтчета и гайки със слаби шансове за повторно сглобяване.
На фона на това бум-тряс падна голямо замазване с добре познатата ни гербаджийска маламашка. То не бяха ритуални разходки с папки до Президентството, напред-назад, иди ми – дойди ми и дай си ми куклите, мои са си! То не бяха сръдни и обиди, ти мен уважаваш ли ме, тук ме почеши, там ме погъделичкай, а сега да се извиниш, ама много трябва да се извиниш, пу – ти гониш и пр. Политически цирк, който всички сме арестувани да гледаме от първия ред вече шести ден… А междувременно ротацията става все по-голям мираж. С всички производни от него миражи.
В такива моменти не ни остава друго, освен да си кажем като Волтеровия Кандид: „… но трябва да работим градината си“. Това и продължаваме да правим в новия ни брой… Макар да сме напълно убедени, че не живеем – пак по Волтер – в „най-добрия от възможните светове“.
На тази простряна пред очите ни и все още неизсъхнала от дъжда и преговорните плюнки политическа седмица е посветен анализът на Емилия Милчева „Ще се сглобяват ли? Кой е на ход?“. Текст, в който се проследява алогическата нишка, свързваща действията на преговарящите политически „мъже“ и особения статут на жените папкоприносителки.
Светла Енчева продължава „мигрантската тема“ от предишния брой със статията си „Как думата „мигрант“ стана дехуманизираща“. Този път Светла ни представя не конкретен казус, а по-скоро разисква юридическите параметри на понятия като „мигрант“, „бежанец“, „търсещ убежище“ и прочее, включително социалния и политическия пълнеж, с който раздуваме и деформираме значенията им в България. Истински образователен текст – струва си да го прочетем внимателно, преди да формулираме позицията си по горещата в последните седмици тема.
Оставаме с проблемите на образованието в поредното интервю на Надежда Цекулова „От промяна в училищната среда към промяна в обществената“. Този път се срещаме с Мария Стайнова и Виолетка Славова от архитектурно студио „Лусио“, които се занимават с проектиране на съвременни образователни пространства в контекста на училищните сгради. Ключов процес в реформирането на цялата система, невъзможен без активното участие на ученици и учители.
След прочитането на поредната доза „научни новини“ от Михаил Ангелов, както обикновено, се чувстваме малко по-умни и обнадеждени за бъдещето. Този път това се дължи на данните от „Вояджър 1“, според които има шанс комуникацията с апарата да бъде подновена; на възможността да се произвежда човешки инсулин от крави; на иновациите в сферата на соларните панели и прочее градивни вести от светлата страна на човешката деятелност.
Още едно продължение тази седмица – „Малайзия по стените“ от Петя Кокудева. Пътешествието продължава сред градски рисунки по стените, из пъстри будистки храмове, нощни пазари, разкошни дърворезби и местни обичаи и легенди. Поражда спонтанни желания за незабавно отпътуване натам!
„Госпожо, Вие май сте били затруднена от учтивата форма“ е новата статия на Павлина Върбанова, сервирана в рубриката ѝ „Порция език“. Главната буква и съгласуването понякога се оказват препъникамък дори и за най-грамотните, особено в случаите, когато решенията на кодификатора са несистемни и лишени от логика.
„Ще полети ли България в Космоса?“ пита Александър Нуцов, докато „всичката Мара втасала“ в страната. Във въпроса му обаче има резон предвид факта, че в световен мащаб високотехнологичната космическа индустрия формира все по-голям дял от бизнеса. Една от първите стъпки в тази посока е създаването на космическа агенция в България – има шанс това да се случи до края на годината. Планира се и магистърска програма в областта на космическите изследвания в поне три университета у нас.
В крайна сметка се оказва, че изучаването на Космоса често разрешава напълно земни проблеми, свързани със същата онази градина, която Кандид ни призовава да обработваме. А и кой знае, един ден градината може да се окаже част от съвсем друг пейзаж – марсиански или лунен?
Приятно четене!
P.S. В края на тази седмица дойде пролетта и си отиде големият писател Алек Попов. Ще го помним. Ще го помни езикът ни. Светъл път и памет!
Post Syndicated from Talks at Google original https://www.youtube.com/watch?v=jL_LBwgbAyI
Post Syndicated from Explosm.net original https://explosm.net/comics/shakespeare
New Cyanide and Happiness Comic
Post Syndicated from Oglaf! -- Comics. Often dirty. original https://www.oglaf.com/cookies/
Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2024/03/friday-squid-blogging-new-species-of-squid-discovered.html
A new species of squid was discovered, along with about a hundred other species.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Post Syndicated from Patrick Kennedy original https://www.servethehome.com/ai-is-rocking-5-key-takeaways-from-nvidia-gtc-2024/
NVIDIA GTC 2024 was rocking this week. Here are my five key takeaways and perhaps hot takes on what I observed this week
The post AI is Rocking 5 Key Takeaways from NVIDIA GTC 2024 appeared first on ServeTheHome.
Post Syndicated from Bhargavi Sagi original https://aws.amazon.com/blogs/big-data/run-trino-queries-2-7-times-faster-with-amazon-emr-6-15-0/
Trino is an open source distributed SQL query engine designed for interactive analytic workloads. On AWS, you can run Trino on Amazon EMR, where you have the flexibility to run your preferred version of open source Trino on Amazon Elastic Compute Cloud (Amazon EC2) instances that you manage, or on Amazon Athena for a serverless experience. When you use Trino on Amazon EMR or Athena, you get the latest open source community innovations along with proprietary, AWS developed optimizations.
Starting from Amazon EMR 6.8.0 and Athena engine version 2, AWS has been developing query plan and engine behavior optimizations that improve query performance on Trino. In this post, we compare Amazon EMR 6.15.0 with open source Trino 426 and show that TPC-DS queries ran up to 2.7 times faster on Amazon EMR 6.15.0 Trino 426 compared to open source Trino 426. Later, we explain a few of the AWS-developed performance optimizations that contribute to these results.
In our testing, we used the 3 TB dataset stored in Amazon S3 in compressed Parquet format and metadata for databases and tables is stored in the AWS Glue Data Catalog. This benchmark uses unmodified TPC-DS data schema and table relationships. Fact tables are partitioned on the date column and contained 200-2100 partitions. Table and column statistics were not present for any of the tables. We used TPC-DS queries from the open source Trino Github repository without modification. Benchmark queries were run sequentially on two different Amazon EMR 6.15.0 clusters: one with Amazon EMR Trino 426 and the other with open source Trino 426. Both clusters used 1 r5.4xlarge coordinator and 20 r5.4xlarge worker instances.
Our benchmarks show consistently better performance with Trino on Amazon EMR 6.15.0 compared to open source Trino. The total query runtime of Trino on Amazon EMR was 2.7 times faster compared to open source. The following graph shows performance improvements measured by the total query runtime (in seconds) for the benchmark queries.
Many of the TPC-DS queries demonstrated performance gains over five times faster compared to open source Trino. Some queries showed even greater performance, like query 72 which improved by 160 times. The following graph shows the top 10 TPC-DS queries with the largest improvement in runtime. For succinct representation and to avoid skewness of performance improvements in the graph, we’ve excluded q72.
Now that we understand the performance gains with Trino on Amazon EMR, let’s delve deeper into some of the key innovations developed by AWS engineering that contribute to these improvements.
Choosing a better join order and join type is critical to better query performance because it can affect how much data is read from a particular table, how much data is transferred to the intermediate stages through the network, and how much memory is needed to build up a hash table to facilitate a join. Join order and join algorithm decisions are typically a function performed by cost-based optimizers, which uses statistics to improve query plans by deciding how tables and subqueries are joined.
However, table statistics are often not available, out of date, or too expensive to collect on large tables. When statistics aren’t available, Amazon EMR and Athena use S3 file metadata to optimize query plans. S3 file metadata is used to infer small subqueries and tables in the query while determining the join order or join type. For example, consider the following query:
The syntactical join order is store_sales joins store_returns joins call_center. With the Amazon EMR join type and order selection optimization rules, optimal join order is determined even if these tables don’t have statistics. For the preceding query if call_center is considered a small table after estimating the approximate size through S3 file metadata, EMR’s join optimization rules will join store_sales with call_center first and convert the join to a broadcast join, speeding-up the query and reducing memory consumption. Join reordering minimizes the intermediate result size, which helps to further reduce the overall query runtime.
With Amazon EMR 6.10.0 and later, S3 file metadata-based join optimizations are turned on by default. If you are using Amazon EMR 6.8.0 or 6.9.0, you can turn on these optimizations by setting the session properties from Trino clients or adding the following properties to the trino-config classification when creating your cluster. Refer to Configure applications for details on how to override the default configurations for an application.
Configuration for Join type selection:
Configuration for Join reorder:
With Amazon EMR 6.8.0 and later, you can run queries on Trino significantly faster than open source Trino. As shown in this blog post, our TPC-DS benchmark showed a 2.7 times improvement in total query runtime with Trino on Amazon EMR 6.15.0. The optimizations discussed in this post, and many others, are also available when running Trino queries on Athena where similar performance improvements are observed. To learn more, refer to the Run queries 3x faster with up to 70% cost savings on the latest Amazon Athena engine.
In our mission to innovate on behalf of customers, Amazon EMR and Athena frequently release performance and reliability enhancements on their latest versions. Check the Amazon EMR and Amazon Athena release pages to learn about new features and enhancements.
Bhargavi Sagi is a Software Development Engineer on Amazon Athena. She joined AWS in 2020 and has been working on different areas of Amazon EMR and Athena engine V3, including engine upgrade, engine reliability, and engine performance.
Sushil Kumar Shivashankar is the Engineering Manager for EMR Trino and Athena Query Engine team. He has been focusing in the big data analytics space since 2014.
Post Syndicated from John Lee original https://www.servethehome.com/amd-epyc-7c13-is-a-surprisingly-cheap-and-good-cpu/
The AMD EPYC 7C13 is a surprisingly good and cheap CPU offering 64 cores at cloud instead of enterprise pricing
The post AMD EPYC 7C13 is a Surprisingly Cheap and Good CPU appeared first on ServeTheHome.
Post Syndicated from Egor Kalinichev original https://blog.rapid7.com/2024/03/22/metasploit-weekly-wrap-up-03-22-2024/

Author: Erik Wynter
Type: Exploit
Pull request: #18618 contributed by ErikWynter
Path: linux/http/opennms_horizon_authenticated_rce
AttackerKB reference: CVE-2023-0872
Description: This module exploits built-in functionality in OpenNMS Horizon in order to execute arbitrary commands as the opennms user. For versions 32.0.2 and higher, this module requires valid credentials for a user with ROLE_FILESYSTEM_EDITOR privileges and either ROLE_ADMIN or ROLE_REST. For versions 32.0.1 and lower, credentials are required for a user with ROLE_FILESYSTEM_EDITOR, ROLE_REST, and/or ROLE_ADMIN privileges.
runc_cwd_priv_esc module. Prior to this fix, the module would incorrectly report some of the versions that the patch had been back ported to as vulnerable.sessions command so that both Meterpreter and the top level Metasploit prompt support sessions -i -1.help command wording when interacting with basic shells.exploits/windows/local/wmi_persistence module when Powershell obfuscation was applied.dns command.README.md to remove a stale documentation link.You can always find more documentation on our docsite at docs.metasploit.com.
As always, you can update to the latest Metasploit Framework with msfupdate
and you can get more details on the changes since the last blog post from
GitHub:
If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest.
To install fresh without using git, you can use the open-source-only Nightly Installers or the
commercial edition Metasploit Pro