VMware patches vulnerability with 9.8/10 severity rating in Cloud Foundation

VMware patches vulnerability with 9.8/10 severity rating in Cloud Foundation

Enlarge (credit: Getty Images)

Exploit code was released this week for a just-patched vulnerability in VMware Cloud Foundation and NSX Manager appliances that allows hackers with no authentication to execute malicious code with the highest system privileges.

VMware patched the vulnerability, tracked as CVE-2021-39144, on Tuesday and issued it a severity rating of 9.8 out of a possible 10. The vulnerability, which resides in the XStream open source library that Cloud Foundation and NSX Manager rely on, posed so much risk that VMware took the unusual step of patching versions that were no longer supported. The vulnerability affects Cloud Foundation versions 3.11 and lower. Versions 4.x aren’t at risk.

“VMware Cloud Foundation contains a remote code execution vulnerability via XStream open source library,” the company’s advisory, published Tuesday, read. “Due to an unauthenticated endpoint that leverages XStream for input serialization in VMware Cloud Foundation (NSX-V), a malicious actor can get remote code execution in the context of ‘root’ on the appliance.”

Read 4 remaining paragraphs | Comments



Source: Ars Technica – VMware patches vulnerability with 9.8/10 severity rating in Cloud Foundation

Decade-old Pebble smartwatches gain Pixel 7 support in 'one last update'

It’s been nearly a decade since the Pebble smartwatch started shipping to backers of its wildly successful initial Kickstarter campaign, but there’s still life in the ol’ dog yet. The wearables are now compatible with Pixel 7 and Pixel 7 Pro, as well as 64-bit-only Android devices that will arrive later.

As noted by Ars Technica, Katharine Berry, who works on Wear OS and is a prominent member of the Rebble group that’s keeping the Pebble ecosystem alive, wrote that the latest Pebble update comes four years after the previous one. The last update allowed for many of the Pebble app’s functions to run on independent servers. Fitbit, which Google has since bought, shut down Pebble’s servers in 2018, two years after buying some of the smartwatch maker’s assets.

Along with Pixel 7 compatibility, the latest update also improves Caller ID reliability on recent versions of Android. While the app isn’t available on the Google Play Store, the APK is signed with official Pebble keys and retains Google Fit integration, Berry noted.

On the surface, this might finally appear to be the end of the line for Pebble in terms of official support. “Thanks to Google for providing us with one last update,” Berry wrote on Reddit. However, as Ars Technica points out, it looks like a Pebble hackathon is set to take place next month. So if your Pebble’s e-ink screen and battery are still holding up, it might be useful for a while longer yet.



Source: Engadget – Decade-old Pebble smartwatches gain Pixel 7 support in ‘one last update’

Three Ways to Cook Big Mushrooms so They Don't Get Mushy

Stuffed mushrooms are a classic holiday appetizer, but the bigger your shroom, the more moisture you have to contend with while cooking it. Stuffing a raw mushroom with filling blocks the water’s escape route, and you risk turning your mushroom into a mushy-room (ha ha ha). Here are three ways to keep wetness from…

Read more…



Source: LifeHacker – Three Ways to Cook Big Mushrooms so They Don’t Get Mushy

The Creators of ONI: Thunder God's Tale on Stop-Motion Inspiration and Overcoming Fear

The new Netflix-produced animated show from Tonko House, ONI: Thunder God’s Tale, is a wonderful, four-episode story about found family, community, identity, and outsiders. On October 18, Sara Sampson, Robert Kondo, and Daisuke “Dice” Tsutsumi sat down with io9 to talk about their animation process and how they…

Read more…



Source: Gizmodo – The Creators of ONI: Thunder God’s Tale on Stop-Motion Inspiration and Overcoming Fear

Rural Areas To Get $759 Million in Grants for High-Speed Internet

The Agriculture Department announced this week that it is making available $759 million in grants and loans to enable rural communities to access high-speed internet, part of the broader $65 billion push for high-speed connectivity from last year’s infrastructure law. From a report: Agriculture Secretary Tom Vilsack and White House senior adviser Mitch Landrieu unveiled the grants during a visit to North Carolina. There are 49 recipients in 24 states. One is North Carolina’s AccessOn Networks, which will receive $17.5 million to provide broadband service to 100 businesses, 76 farms and 22 educational facilities in the state’s Halifax and Warren counties. Both counties are rural and have predominantly Black populations.

“Rural America needs this,” Vilsack said. “Rural America deserves this.” He made the announcement in front of John Deere equipment, noting that rural areas tend to be where the electricity for cities is generated and where city dwellers and suburbanites go for vacations. The announcement and visit to North Carolina, a state with an open U.S. Senate seat, come as President Joe Biden and other top Democratic officials are trying to sell their achievements to voters before the Nov. 8 midterm elections. Landrieu, the infrastructure coordinator and former New Orleans mayor, told reporters on a Wednesday call that the Biden administration has already released $180 billion for various infrastructure projects.

Read more of this story at Slashdot.



Source: Slashdot – Rural Areas To Get 9 Million in Grants for High-Speed Internet

Amazon's Echo Show 5 is available for $30 apiece when you buy two

We recommend Amazon’s Echo Show 5 for those looking to adopt a smarter type of alarm clock, and as of this writing Amazon is running a sale that brings two of the diminutive smart displays down to $60 when you use the code SHOW52PK at checkout. We’ve seen individual deals bring the device as low as $35 in recent months, so this offer represents a slightly better value if you know you want multiple displays around the house (or if you want to grab one for multiple people). The Echo Show 5 technically has an MSRP of $85, but its average street price has typically sat in the $40-50 range in recent months.

We gave the Echo Show 5 a review score of 85 when it launched last year, praising its solid-for-its-size sound quality, compact design, and usual suite of Alexa-aided smart features. Its most natural home is on a bedside table, as the device is fitted with features like a “sunrise” alarm that gradually brightens its screen to more gently wake you up in the morning and the ability to tap the top of the display to snooze an alarm. The device’s 960 x 480 resolution display isn’t exactly high-end, but it’s competent enough given the device’s small stature, and an ambient light sensor lets it automatically dim when you turn the lights off at night.

The device still has its uses outside of the bedroom, as it can tell you the weather, play music, display recipes, show Ring security cam feeds and control compatible smart home gear like any other Alexa machine. But that smaller display naturally won’t be as pleasing for video as the panel on a larger device like the Echo Show 8, and the included camera is only 2MP, so it’s best used in a pinch, not for extended video calls. (It does come with a privacy shutter, however.) This also isn’t the most performant device, so it’s better off sticking to simpler Alexa commands, casual music streaming, and that alarm clock functionality. 

All of that is easier to accept when the device is deeply discounted, though. Google’s Nest Hub is a fine alternative for those who prefer to use the Google Assistant or just want a bedside display with no camera at all. If you’re looking to add a couple of smart displays to your home and are already onboard with Alexa, though, this is a solid chance to save a few bucks.

Follow @EngadgetDeals on Twitter and subscribe to the Engadget Deals newsletter for the latest tech deals and buying advice.



Source: Engadget – Amazon’s Echo Show 5 is available for apiece when you buy two

One of the World's Biggest Killers Is on the Rise Again

One of the deadliest diseases in the world is once again gaining steam. A new report this week by the World Health Organization shows that global cases of tuberculosis and drug-resistant tuberculosis increased in 2021—the first such jump in years. A major reason for its resurgence is the covid-19 pandemic.

Read more…



Source: Gizmodo – One of the World’s Biggest Killers Is on the Rise Again

Report: Google will graciously let Android OEMs build Amazon Fire devices

The logo for the board game Monopoly, complete with Uncle Pennybags, has been transformed to say Google.

Enlarge / Let’s see, you landed on my “Google Ads” space, and with three houses… that will be $1,400. (credit: Ron Amadeo / Hasbro)

Can Android manufacturers ship devices that run Android forks? That’s a tough and scary question for OEMs to ask, and Google has probably liked it that way. The contracts Android OEMs sign with Google—which are needed to license the Play Store and other Google apps—says, flatly, “no forks.” Google says forking Android would damage the Android ecosystem, so OEMs must pledge to never be involved in the production of a device that runs a fork of Android. Some regulatory bodies—namely in the EU—have ruled that the “no forks” clause of the Android contract is not legal and that Google can’t punish OEMs that stray outside the walled garden. The EU doesn’t control the whole world, though, so while Google can’t punish manufacturers inside the EU, what happens in the rest of the world?

Google’s anti-fork clause has always been a big problem for Amazon, whose Fire OS is the No. 1 Android fork out there. With most of the major tech manufacturers somehow involved in producing Android phones, tablets, TVs, laptops, cars, or watches, Amazon has always had to claw and scrape to find someone willing to make Fire devices. Amazon complained about this to the Competition Commission of India last week, saying, “At least seven OEMs have indicated that their ability to enter into a manufacturing relationship of this kind with Amazon is either blocked entirely or significantly limited (e.g., in terms of geographic scope) by their contractual commitments to Google.” India is Android’s biggest market, so any rulings there will be worth paying attention to.

A new report from Protocol’s Janko Roettgers says that Google is caving on this restriction, at least for televisions. The report says that Google and Amazon have “struck a deal” allowing Android manufacturers to make TVs that run Fire TV OS, and that TCL, Xiaomi, and Hisense will offer products in both ecosystems. TCL has already announced the lovingly named “CF63K Fire TV series” of televisions—4K, 60 Hz Fire TV displays with Amazon Alexa. The company also makes sets with Android TV and Roku software. Xiaomi, a stalwart Android OEM, also announced a Fire TV set this May.

Read 2 remaining paragraphs | Comments



Source: Ars Technica – Report: Google will graciously let Android OEMs build Amazon Fire devices

Telegram nixes paid posts on iOS after blowback from Apple

Telegram and its users are looking into ways to make more money from the platform. One method users have tried is using third-party payment bots to sell paid individual posts on their channels. However, Telegram CEO Pavel Durov says the company had to shut down paid posts on iOS due to a complaint from Apple.

Durov said it “was great” that creators were receiving nearly the full sum of what their fans or subscribers paid for one of their posts. “Unfortunately, we received word from Apple that they were not happy with content creators monetizing their efforts without paying a 30 percent tax to Apple,” he wrote. “Since Apple has complete control over its ecosystem, we had no alternative but to disable such paid posts on iOS devices.”

The “30 percent tax” refers to the cut that Apple takes from in-app payments and app purchases. The company’s App Store fees have been the target of criticism from many corners, including news publishers, Spotify and, perhaps most famously, Epic Games.

Durov took a swipe at Apple, claiming it was a monopoly that “abuses its market dominance at the expense of millions of users who are trying to monetize their own content.” He expressed hope that regulators in various jurisdictions will take action “before Apple destroys more dreams and crushes more entrepreneurs.”

The Telegram CEO added that his team is working on ways to provide creators with easy-to-use options to make money from their content. He aims to help them do so “outside of Apple’s restrictive ecosystem.”

Telegram introduced paid features in June with a $5 per month Premium subscription. That opens up larger file upload sizes, faster downloads, the ability to follow many more channels and the option to pin chats. While the company itself hasn’t embraced paid posts as yet, it’s intriguing to see creators trying to find their own ways of making money from Telegram — even if Apple isn’t too happy about it.



Source: Engadget – Telegram nixes paid posts on iOS after blowback from Apple

White House Warns Russia Against Shooting Down U.S. Satellites

The National Security Council is having to respond to comments made earlier this week by a senior Russian foreign ministry official who warned that commercial satellites operated by the U.S. and its allies, if used to support the Ukrainian war effort, could become legitimate targets.

Read more…



Source: Gizmodo – White House Warns Russia Against Shooting Down U.S. Satellites

Venom 3 Forms Symbiotic Relationship With Kelly Marcel

We’ve got quite a while before the third Venom movie oozes its way onscreen, but the goopy anti-hero played by Tom Hardy has made a tentacle-pulled leap forward. The Hollywood Reporter has announced that screenwriter Kelly Marcel will do double-duty as director for Venom 3.

Read more…



Source: Gizmodo – Venom 3 Forms Symbiotic Relationship With Kelly Marcel

The Marvel Snap World Record For Most Points Is Absolutely Bonkers

Marvel Snap players everywhere are sharing end-of-game match results with eye-popping numbers. But no matter what your scorecard says at the end, I’m willing to bet it’s child’s play compared to what I’m about to show you. Ladies and gentlemen, there’s a limit to how high your Marvel Snap score can go. And one man has…

Read more…



Source: Kotaku – The Marvel Snap World Record For Most Points Is Absolutely Bonkers

Why Other Devices Put Your Laptop to Sleep

Like smartphones and other battery-powered devices, laptops go to sleep to conserve energy. But you might notice your machine hitting the sack in the middle of work, for no apparent reason other than bringing another device too close. No, the battery didn’t die; it’s much simpler.

Read more…



Source: LifeHacker – Why Other Devices Put Your Laptop to Sleep

Nothing's Ear Stick Earbuds Are Up For Preorder And They Wreck Apple's AirPods On Price

Nothing's Ear Stick Earbuds Are Up For Preorder And They Wreck Apple's AirPods On Price
After leaving OnePlus behind, co-founder Carl Pei started Nothing—that’s a company called “Nothing,” not the state of nonexistence. Its first product was a set of true wireless earbuds, and it followed that up with a mid-range smartphone. Now, Nothing is taking another swing at wireless earbuds with the poorly named Nothing Ear Stick. These

Source: Hot Hardware – Nothing’s Ear Stick Earbuds Are Up For Preorder And They Wreck Apple’s AirPods On Price

Joe Belfiore, the Former Head of Windows Phone, To Leave Microsoft After 32 Years

Microsoft Corporate Vice President Joe Belfiore will leave Microsoft after 32 years with the company. From a report: Belfiore has served in several roles at Microsoft but is currently the CVP of Office. His plans to retire were announced internally in an email sent out to employees and later shared publicly on Twitter. Belfiore will be a senior advisor and coach to aid the transition until summer 2023. The Office Group will be led by CVP Ales Holecek, who has led the division alongside Belfiore for several years, and CVP Sumit Chauhan, who will move up from their role as head of Office Organization. Many of our readers know Belfiore best for his time in charge of Windows Phone. He co-led that division from 2009 to 2013, which included Microsoft’s acquisition of Nokia. Belfiore then went on to lead the Windows 10 team for almost five years.

Read more of this story at Slashdot.



Source: Slashdot – Joe Belfiore, the Former Head of Windows Phone, To Leave Microsoft After 32 Years