Red Hat has acquired Chatterbox Labs, a company specializing in AI model testing and safety guardrails, to enhance its open-source AI platform and address the growing need for AI security and model monitoring in enterprise applications. The company plans to open-source Chatterbox Labs' technology over time.
IBM plans to cut thousands of jobs this quarter as it shifts focus towards higher-growth software and services, particularly expanding its software division fueled by acquisitions like Red Hat and HashiCorp, while maintaining overall US employment levels.
IBM's Q3 revenue growth slowed in key software segments, including Red Hat, with a 14% increase in hybrid cloud sales below expectations, leading to a 5.5% drop in shares. Despite overall revenue rising 9.1% to $16.3 billion, concerns about organic software growth persist, though AI bookings and infrastructure sales show strong momentum.
Red Hat and Debian issued urgent warnings after a backdoor access code was discovered in recent versions of Fedora operating systems. The exploit was accidentally stumbled upon by a Microsoft developer, who noticed unusually high CPU usage by an SSH process.
A malicious backdoor has been discovered in the xz data compression library, affecting versions 5.6.0 and 5.6.1, which may be present in upcoming Fedora Linux 40 and Fedora Rawhide. The backdoor provides remote access via OpenSSH and systemd, potentially allowing unauthorized access to affected systems. Red Hat has issued warnings and advised users to check and remove any backdoored builds of xz, with Debian Unstable and Kali Linux also affected. The supply-chain compromise may mainly impact bleeding-edge distributions, and efforts are being made to prevent widespread exploitation.
Red Hat issued an urgent security alert warning of malicious code embedded in certain versions of XZ Utils, impacting certain Fedora Linux distribution versions and potentially allowing unauthorized access to systems. The affected versions are 5.6.0 and 5.6.1, present in Fedora 41 and Fedora Rawhide. Red Hat advised users to stop using Fedora Rawhide instances and downgrade to a safe version. No versions of Red Hat Enterprise Linux are affected, but other distributions like Debian unstable may also be impacted. CISA recommended downgrading XZ Utils to a safe version and hunting for any malicious activity.
Red Hat has warned users to stop using systems running Fedora development and experimental versions due to a backdoor found in the latest XZ Utils data compression tools and libraries. The backdoor, present in XZ versions 5.6.0 and 5.6.1, could potentially enable unauthorized access to systems running affected versions. Red Hat has reverted to 5.4.x versions of XZ in Fedora 40 beta and is tracking the issue as CVE-2024-3094 with a critical severity score. Users are advised to downgrade to an uncompromised XZ version and to monitor their systems for any malicious activity.
Red Hat issued an urgent security alert for Fedora 41 and Fedora Rawhide users due to a security vulnerability in XZ 5.6.0/5.6.1 that could allow unauthorized remote system access. The malicious code interferes with sshd authentication via systemd, potentially enabling unauthorized access to the entire system. No fixed version has been released yet, and Debian has also issued a similar security warning. Users are advised to ensure they do not have XZ 5.6.0/5.6.1 on their systems.
IBM's fourth-quarter financial results show a 4.1% increase in revenues, reaching $17.38 billion, with gross profits up 6.6% to $10.27 billion and net income up by 21.3% to $3.29 billion. The company's Infrastructure group, which sells servers, storage, operating systems, and tech support for the Power and Z lines, saw sales rise by 2.7% to $4.6 billion. IBM's Software group had $7.51 billion in sales, up 3.1% year on year. The acquisition of Red Hat has helped rejuvenate IBM's systems business, with Red Hat revenue continuing to grow faster than global IT spending. Additionally, IBM's AI bookings doubled in Q4, and the company is expected to focus on startup acquisitions to build up its AI software stack.
IBM's stock surged 5% after beating profit expectations and reporting increased demand for artificial intelligence, with net income reaching $3.3 billion and revenue rising to $17.4 billion. The company saw growth in software, consulting, and infrastructure revenue, particularly from Red Hat. IBM's strategic realignment towards AI software and a platform-centric hybrid cloud strategy, including the integration of Red Hat OpenShift, has been well-received. CEO Arvind Krishna highlighted accelerating client demand for AI, with the company expecting consistent revenue growth and approximately $12 billion in free cash flow by 2024, surpassing Wall Street's expectations.
Red Hat has stopped publishing the source code to everything that's a part of Red Hat Enterprise Linux (RHEL) on git.centos.org, where it has traditionally been published to fulfill the requirements of the GPL license. Red Hat has decided to use the Customer Portal to share source code with its partners and customers, while treating CentOS Stream as the venue for collaboration with the community. This move has raised concerns about the health of the GPL and has caused uncertainty about the future of bug-for-bug compatible RHEL clones.
Red Hat has announced that CentOS Stream will be the only repository for RHEL-related source code releases, which will affect RHEL-based distros like Rocky Linux and AlmaLinux. Red Hat's existing customers and partners will still be able to access RHEL sources via the customer/partner portals. AlmaLinux has assured its users that they are looking into the situation and will keep them updated.
Mesa 23.1 has enabled Rusticl Rust-written OpenCL driver support for RadeonSI, thanks to a merge request by Red Hat's Karol Herbst. This modern OpenCL support for RadeonSI is an alternative to using the ROCm OpenCL stack or the aging "Clover" Gallium3D OpenCL driver. Rusticl has previously outperformed ROCm OpenCL in benchmarks, and going the Rusticl route should be easier for running open-source Radeon OpenCL on non-enterprise Linux distributions where ROCm isn't officially certified/tested.