Meta has released the first two models from its multimodal Llama 4 suite: LLama 4 Scout and Llama 4 Maverick. Maverick is “the workhorse” of the two and excels at image and text understanding for “general assistant and chat use cases,” the company said in a blog post, while the smaller model Scout could tackle things like “multi-document summarization, parsing extensive user activity for personalized tasks, and reasoning over vast codebases.” The company also introduced Llama 4 Behemoth, an upcoming model it says is “among the world’s smartest LLMs” — and CEO Mark Zuckerberg said we’ll be hearing about a fourth model, LLama 4 Reasoning, “in the next month.”
Both Maverick and Scout are available to download now from the LLama website and Hugging Face, and they’ve been added to Meta AI, including for WhatsApp, Messenger and Instagram DMs.
Meta
Scout has 17 billion active parameters with 16 experts, Meta says. According to Zuckerberg, “It’s extremely fast, natively multimodal, and has an industry leading, nearly infinite 10 million token context length, and it is designed to run on a single GPU.” Maverick on the other hand has 17 billion active parameters with 128 experts. The company says it beats competitors like GPT-4o and Gemini 2.0 on coding, reasoning, multilingual, long-context and image benchmarks, and stacks up against DeepSeek v3.1 on reasoning and coding.
Zuckerberg is already calling the upcoming Behemoth model, which is still training, “the highest performing base model in the world,” with 288 billion active parameters, according to the company. It may not be here yet, but it’s likely we’ll be hearing a lot more about that and the Reasoning model soon; Meta’s big AI developer conference, LlamaCon, is just a few weeks away.
This article originally appeared on Engadget at https://www.engadget.com/ai/meta-introduces-llama-4-with-two-new-models-available-now-and-two-more-on-the-way-214524295.html?src=rss
Over on Reddit’s “selfhosted” subreddit for alternatives to popular services, long-time Slashdot reader Zoup described a pain point:
– Landlock is a Linux Security Module (LSM) that lets unprivileged processes restrict themselves.
– It’s been in the kernel since 5.13, but the API is awkward to use directly.
– It always annoyed the hell out of me to run random binaries from the internet without any real control over what they can access.
So they’ve rolled their own solution, according to Thursday’s submission to Slashdot:
I just released Landrun, a Go-based CLI tool that wraps Linux Landlock (5.13+) to sandbox any process without root, containers, or seccomp. Think firejail, but minimal and kernel-native. Supports fine-grained file access (ro/rw/exec) and TCP port restrictions (6.7+). No daemons, no YAML, just flags.
Example (where –rox allows read-only access with execution to specified path):
With day 1 of Zwift Community Live 2025 done and dusted (read about it here), I was looking forward to day 2 and the prospects of a longer, harder group ride. The weather looked to be beautiful in Mallorca, the ZCL vibes were good, and I was excited to roll on new roads. Here’s how the day unfolded for me…
Ride Plan
Today’s ride was called the Uber Pretzel as it was the longest of the three ride options. We would ride from our resort in Platja de Muro to the top of Sant Salvador, then loop back for a total distance of 115km and a bit over 1000 meters of elevation:
I was looking for a ride group that would push a bit harder than the previous day’s, with fewer and shorter stops along the way. And I was looking for some epic roads. This route looked like it would tick all the boxes.
Getting Started
The dining room was buzzing when I arrived around 7:15am. Clearly, lots of riders were planning on doing the Uber Pretzel as well (which wasn’t a surprise given how the week’s routes were planned), and everyone was eating early since we would be starting at 8:30.
After another tasty granola bowl, some fruit, and a smoothie, I headed back to my room to kit up and meet Monica at the starting area. (She’s a stupendous sidekick, by the way: fetching bikes and forgotten gloves and filling bottles to help make my experience even better.)
Riders are grouped into packs of 12 which leave a few minutes apart. (The goal is that the faster packs leave sooner, so packs stay separated and large groups of cyclists don’t clog up the roads.) I looked around for a group to join, and saw that the first group would definitely be too spicy for my taste. It contained the likes of Nathan Guerra, Jeff from NorCal Cycling, Zwift Academy 2024 winners Noah Ramsay and Emily Dixon, and Freddy Ovett… among others.
But just behind them a group was forming up that included Zwift CEO Eric Min, VP of Marketing Steve Beckett, and the great Kristin Armstrong. This looked like the group for me, so I hopped in, along with Zwift Academy 2023 winner Louis Kitzki and a few others.
Soon enough, we were off. Two abreast, we quickly got up to a nice cruising pace on the flattish lead-in to the centerpiece climb of the day. Chugging along at ~35 kph, we quickly spun our way toward Sant Salvador, upping the power on the inclines to keep our speed rolling without going so hard that our legs would burn out early. A sensible tempo pace.
Riding two abreast gives you the chance to get to know your ridemates. Along with those already mentioned we had an Olympic runner, a coach/triathlete from the UK, a man who was an early investor in Zwift, a woman who helps lead Rocacorba Cycling, the guy who heads up the CORE sensor team, Tim Perkin from Mountain Massif, and others!
It didn’t take long for us to arrive at the big climb of the day. As the road ramped up, around half the group fell off while the other half pushed on ahead at a higher pace. I was one who fell off – no surprise there – and I was perfectly fine with it. With another 60km left to ride, I wasn’t interested in blowing up on the slopes of Sant Salvador. I wanted to enjoy the ride and take in this beautiful climb, hairpin by hairpin. And that’s what I did!
It really is a nice climb, with lots of shade, smooth pavement, and gorgeous views over the edge as you negotiate the turns. I love climbs like this that alternate between a sort of walled-in tunnel of trees and wide open vistas that let you see all the way to the ground and be surprised again and again at how high you’ve climbed.
Soon enough, I was at the top, having averaged 308W for 21:53. (This rocketed me to 29,209th out of 69,900 on the Strava segment. The best time on the day? ZCL attendee Beast On A Bike | Louis Hatchwell at 14:30. His average power? 432W.)
View from the top!My ride crew atop Sant Salvador
We took some photos at the top, admired the near-360-degree views, refilled bidons from the support van, and headed downhill knowing our coffee stop was 30km ahead. (Eric Min was hungry, so we weren’t waiting around!)
The way home was a nice mix of flats and slight downhills, many of which were narrow country roads with very little traffic. Once again we churned through the kilometers, stopping only for a bit of coffee and cake in Sineau before winding our way home.
After just over 4 hours of riding we were back at the hotel, enjoying a beer and a snack in comfortable couches overlooking the Mediterranean beach. 118km, 1000m of elevation, and an average speed of 28.8 kph. Another good day out on the bike in beautiful Mallorca!
Today ended much like yesterday: kickstarting recovery with good nutrition and Normatec boots, eating a tasty dinner with some new Zwift friends from Austria and Germany, then sitting on the night’s fireside chats. (Monica and I also took some time to cool our feet in the ocean and enjoy the beautiful beach just outside our door.)
The first chat was hosted by Matt Stephens and featured Zwift’s Director of Women’s Strategy Kate Veronneau along with the 4 winners of Zwift Academy from 2023 and 2024. The discussion centered around the Academy winners’ experiences, and what Zwift Academy is doing to change how riders get into the sport.
The night ended with Matt calling a surprise guest to the stage: Mark Cavendish! He and Matt chatted about Cav’s life now that he’s retired, along with obscure topics like how eating cheese late at night can affect one’s dreams. I’m sure many Zwifters were just as starstruck as I was to see Cav in person. What a legend!
Coming Up Tomorrow
Tomorrow’s ride will be the biggest of ZCL: the Uber Pretzel featuring Sa Calobra! It’s essentially the same distance as today’s ride, but twice the elevation. Here’s the route:
“The third James Bond novel was published on this day in 1955,” writes long-time Slashdot reader sandbagger.
Film buff Christian Petrozza shares some history:
In 1979, the market was hot amid the studios to make the next big space opera. Star Wars blew up the box office in 1977 with Alien soon following and while audiences eagerly awaited the next installment of George Lucas’ The Empire Strikes Back, Hollywood was buzzing with spacesuits, lasers, and ships that cruised the stars. Politically, the Cold War between the United States and Russia was still a hot topic, with the James Bond franchise fanning the flames in the media entertainment sector. Moon missions had just finished their run in the early 70s and the space race was still generationally fresh. With all this in mind, as well as the successful run of Roger Moore’s fun and campy Bond, the time seemed ripe to boldly take the globe-trotting Bond where no spy has gone before.
Thus, 1979’s Moonraker blasted off to theatres, full of chrome space-suits, laser guns, and jetpacks, the franchise went full-boar science fiction to keep up with the Joneses of current Hollywood’s hottest genre. The film was a commercial smash hit, grossing 210 million worldwide. Despite some mixed reviews from critics, audiences seemed jazzed about seeing James Bond in space.
When it comes to adaptations of the novella that Ian Flemming wrote of the same name, Moonraker couldn’t be farther from its source material, and may as well be renamed completely to avoid any association… Ian Flemming’s original Moonraker was more of a post-war commentary on the domestic fears of modern weapons being turned on Europe by enemies who were hired for science by newer foes. With Nazi scientists being hired by both the U.S. and Russia to build weapons of mass destruction after World War II, this was less of a Sci-Fi and much more of a cautionary tale.
They argue that filming a new version of Moonraker “to find a happy medium between the glamor and the grit of the James Bond franchise…”
This week NASA “issued a solicitation for the next two private astronaut missions to the International Space Station,” reports Space News. Scheduled after May of 2026 and then mid-2027, “These will be the fifth and sixth such missions to the ISS, part of a broader low Earth orbit commercialization effort by NASA with the ultimate goal of replacing the International Space Station with one or more commercial stations.”
NASA’s Space Station program manager calls the missions “a key part” of helping industry partners “gain the experience needed to train and manage crews, conduct research, and develop future destinations.” In short, they see the missions “providing companies with hands-on opportunities to refine their capabilities and build partnerships that will shape the future of low Earth orbit.”
[NASA’s call for proposals] offers an opportunity to have future missions commanded by someone other than a former NASA astronaut. While companies must propose a commander who meets current requirements, it can also propose an alternate commander who is a former astronaut from the Canadian Space Agency, European Space Agency or Japan Aerospace Exploration Agency with similar ISS experience requirements… [“Broadening of this requirement is not guaranteed,” NASA warns.]
That could allow some former astronauts already working with commercial spaceflight companies an opportunity to command private astronaut missions. Axiom Space, for example, announced in July 2024 that former ESA astronaut Tim Peake had joined its astronaut team. That came after Axiom and the U.K. Space Agency signed a memorandum of understanding in October 2023 to study the feasibility of a private astronaut mission crewed exclusively by U.K. astronauts.
So far Axiom Space has been awarded all four private astronaut missions, according to the article, “flying one mission each in 2022, 2023 and 2024. Its next mission, Ax-4, is scheduled for no earlier than May.”
But “While Axiom has little or no competition for previous PAM awards, it will likely face stiffer competition this time. Vast, a company also planning to develop commercial space stations, has previously stated its intent to submit proposals…”
All the hubbub the last couple of days has been about the Switch 2’s preorder date, and how that’s been delayed due to Trump’s tariffs, but something else caught our ear during Nintendo Direct this past week. The company talked about “compatible” original Switch games working with the new system, in addition to the paid upgrades for certain
Slashdot reader zlives shared this report from BleepingComputer:
Microsoft used its AI-powered Security Copilot to discover 20 previously unknown vulnerabilities in the GRUB2, U-Boot, and Barebox open-source bootloaders.
GRUB2 (GRand Unified Bootloader) is the default boot loader for most Linux distributions, including Ubuntu, while U-Boot and Barebox are commonly used in embedded and IoT devices. Microsoft discovered eleven vulnerabilities in GRUB2, including integer and buffer overflows in filesystem parsers, command flaws, and a side-channel in cryptographic comparison. Additionally, 9 buffer overflows in parsing SquashFS, EXT4, CramFS, JFFS2, and symlinks were discovered in U-Boot and Barebox, which require physical access to exploit.
The newly discovered flaws impact devices relying on UEFI Secure Boot, and if the right conditions are met, attackers can bypass security protections to execute arbitrary code on the device. While exploiting these flaws would likely need local access to devices, previous bootkit attacks like BlackLotus achieved this through malware infections.
Miccrosoft titled its blog post “Analyzing open-source bootloaders: Finding vulnerabilities faster with AI.” (And they do note that Micxrosoft disclosed the discovered vulnerabilities to the GRUB2, U-boot, and Barebox maintainers and “worked with the GRUB2 maintainers to contribute fixes… GRUB2 maintainers released security updates on February 18, 2025, and both the U-boot and Barebox maintainers released updates on February 19, 2025.”)
They add that performing their initial research, using Security Copilot “saved our team approximately a week’s worth of time,” Microsoft writes, “that would have otherwise been spent manually reviewing the content.”
Through a series of prompts, we identified and refined security issues, ultimately uncovering an exploitable integer overflow vulnerability. Copilot also assisted in finding similar patterns in other files, ensuring comprehensive coverage and validation of our findings…
As AI continues to emerge as a key tool in the cybersecurity community, Microsoft emphasizes the importance of vendors and researchers maintaining their focus on information sharing. This approach ensures that AI’s advantages in rapid vulnerability discovery, remediation, and accelerated security operations can effectively counter malicious actors’ attempts to use AI to scale common attack tactics, techniques, and procedures (TTPs).
This week Google also announced Sec-Gemini v1, “a new experimental AI model focused on advancing cybersecurity AI frontiers.”
An AI program enters the real world in TRON: Ares.
It’s difficult to underestimate the massive influence that Disney’s 1982 cult science fiction film, TRON, had on both the film industry—thanks to combining live action with what were then groundbreaking visual effects, rife with computer-generated imagery—and on nerd culture at large. Over the ensuing decades there has been one sequel, an animated TV series, a comic book miniseries, video games, and theme park attractions, all modeled on director Steve Lisberg’s original fictional world.
Now we’re getting a third installment in the film franchise: TRON: Ares, directed by Joachim Rønning (Pirates of the Caribbean: Dead Men Tell No Tales, Maleficent: Mistress of Evil), that serves as a standalone sequel to 2010’s TRON: Legacy. Disney just released the first trailer and poster art, and while the footage is short on plot, it’s got the show-stopping visuals we’ve come to expect from all things TRON.
The cryptography subsystem updates for the in-development Linux 6.15 merge window are quite exciting with some optimizations for modern x86_64 Intel/AMD processors enticing us the most…
Amazon’s new feature could make it easier to get into the latest release in a series, especially if it’s been some time since you’ve read the previous books. The new Recaps feature is part of the latest software update for the Kindle, and the company compares it to “Previously on…” segments you can watch for TV shows. Amazon announced Recaps in a blog post, where it said that you can get access to it once you receive the software update over the air or after you download and install it from Amazon’s website. Amazon didn’t talk about the technology behind the feature in its post, but a spokesperson has confirmed to TechCrunch that the recaps will be AI generated.
Shortly after the feature rolled out, users talked about it on social media, wondering if Amazon is using generative AI to write series summaries. They expressed concerns about the use of generative AI, especially about the possibility of the technology hallucinating plot elements that aren’t actually in the books. “We use technology, including GenAI and Amazon moderators, to create short recaps of books that accurately reflect book content,” Amazon spokesperson Ale Iraheta told the publication. Iraheta assured TechCrunch that Amazon’s recaps are accurate, but of course, use it at your own risk.
At the moment, the Recaps feature is available for best-selling English-language book series on all Kindle devices in the US. To know if your favorite series has one, look for the “View Recaps” button within the series page in your Kindle library. It will soon be available for the Kindle app on iOS, as well.
This article originally appeared on Engadget at https://www.engadget.com/ai/amazon-will-use-ai-to-generate-recaps-for-book-series-on-the-kindle-170018503.html?src=rss
The advent of LLMs and machine learning-based applications “opened the door to a new wave of security threats,” argues Google’s security blog. (Including model and data poisoning, prompt injection, prompt leaking and prompt evasion.)
So as part of the Linux Foundation’s nonprofit Open Source Security Foundation, and in partnership with NVIDIA and HiddenLayer, Google’s Open Source Security Team on Friday announced the first stable model-signing library (hosted at PyPI.org), with digital signatures letting users verify that the model used by their application “is exactly the model that was created by the developers,” according to a post on Google’s security blog.
[S]ince models are an uninspectable collection of weights (sometimes also with arbitrary code), an attacker can tamper with them and achieve significant impact to those using the models. Users, developers, and practitioners need to examine an important question during their risk assessment process: “can I trust this model?”
Since its launch, Google’s Secure AI Framework (SAIF) has created guidance and technical solutions for creating AI applications that users can trust. A first step in achieving trust in the model is to permit users to verify its integrity and provenance, to prevent tampering across all processes from training to usage, via cryptographic signing… [T]he signature would have to be verified when the model gets uploaded to a model hub, when the model gets selected to be deployed into an application (embedded or via remote APIs) and when the model is used as an intermediary during another training run. Assuming the training infrastructure is trustworthy and not compromised, this approach guarantees that each model user can trust the model…
The average developer, however, would not want to manage keys and rotate them on compromise. These challenges are addressed by using Sigstore, a collection of tools and services that make code signing secure and easy. By binding an OpenID Connect token to a workload or developer identity, Sigstore alleviates the need to manage or rotate long-lived secrets. Furthermore, signing is made transparent so signatures over malicious artifacts could be audited in a public transparency log, by anyone. This ensures that split-view attacks are not possible, so any user would get the exact same model. These features are why we recommend Sigstore’s signing mechanism as the default approach for signing ML models.
Today the OSS community is releasing the v1.0 stable version of our model signing library as a Python package supporting Sigstore and traditional signing methods. This model signing library is specialized to handle the sheer scale of ML models (which are usually much larger than traditional software components), and handles signing models represented as a directory tree. The package provides CLI utilities so that users can sign and verify model signatures for individual models. The package can also be used as a library which we plan to incorporate directly into model hub upload flows as well as into ML frameworks.
“We can view model signing as establishing the foundation of trust in the ML ecosystem…” the post concludes (adding “We envision extending this approach to also include datasets and other ML-related artifacts.”)
Then, we plan to build on top of signatures, towards fully tamper-proof metadata records, that can be read by both humans and machines. This has the potential to automate a significant fraction of the work needed to perform incident response in case of a compromise in the ML world…
To shape the future of building tamper-proof ML, join the Coalition for Secure AI, where we are planning to work on building the entire trust ecosystem together with the open source community. In collaboration with multiple industry partners, we are starting up a special interest group under CoSAI for defining the future of ML signing and including tamper-proof ML metadata, such as model cards and evaluation results.
UK-based Jaguar Land Rover says it’s pausing shipments to the US after President Donald Trump imposed a 25 percent tariff on passenger vehicles and other auto imports. The pause will be in effect this month, the Associated Press reports. While the full impact of the tariffs remains to be seen, analysts have said the move could ultimately drive up the cost of new and even used cars.
“The USA is an important market for JLR’s luxury brands,” Jaguar Land Rover said in a statement to AP. “As we work to address the new trading terms with our business partners, we are taking some short-term actions including a shipment pause in April, as we develop our mid- to longer-term plans.”
Trump’s tariffs go well beyond the auto industry, and we’re only seeing the beginning of how the US’ trading partners will respond. The president announced a 10 percent baseline tariff on “all countries” this week, and some will face even higher “reciprocal” tariffs. Among the immediate effects, Nintendo has delayed pre-orders of the new Switch 2 in the US.
This article originally appeared on Engadget at https://www.engadget.com/transportation/jaguar-land-rover-pauses-us-shipments-while-it-figures-out-a-plan-for-trumps-tariffs-172512506.html?src=rss
This week, the big Switch 2 reveal dominated online gaming conversations, with people gushing about their excitement for games like Mario Kart World on one hand (and falling in love with a playable cow in particular), and recoiling from the price on the other. Also, with season two of HBO’s The Last of Us almost upon…
Wouldn’t you know it, just days after Nintendo revealed more details about its Switch 2 console and hot on the heels of us posting a preorder guide to give you a leg up over scalpers and bots, Nintendo and its retail partners are putting the word out that the preorder date in the United States has been delayed indefinitely. The reason? Uncertainty
For individuals that read lots of weblogs, a news aggregator makes keeping track of them effortless, and particularly useful if the weblogs are only updated occasionally.
Finally this week, Nintendo pulled back the curtain on the Switch 2 in a big way, giving us details about its screen, specs, and some of the games we can expect to see at launch and in the months that follow. A few days later, however, the company announced that preorders, previously set to go live on April 9, were…