Anthropic 发文回应开放权重模型公开信,再次强调中国威胁论。
- 上周,一篇发布在微软网站上的公开信呼吁美国政府支持开放权重模型 [1]。
- 除 Anthropic 外的超过 130 家科技公司,包括英伟达、谷歌、Meta、英格尔、Amazon 等,均参与了此公开信的联署。
- 和以往一样,Anthropic 的回应中表达了对开放权重模型安全性的担忧,以及对中国共产党利用或蒸馏强大 AI 模型以达成威权政府目的的担忧。
anthropic.com/~
1. microsoft.com/~
#Anthropic #LLM
- 上周,一篇发布在微软网站上的公开信呼吁美国政府支持开放权重模型 [1]。
- 除 Anthropic 外的超过 130 家科技公司,包括英伟达、谷歌、Meta、英格尔、Amazon 等,均参与了此公开信的联署。
- 和以往一样,Anthropic 的回应中表达了对开放权重模型安全性的担忧,以及对中国共产党利用或蒸馏强大 AI 模型以达成威权政府目的的担忧。
anthropic.com/~
1. microsoft.com/~
#Anthropic #LLM
Anthropic
Our position on open-weights models
Anthropic CEO Dario Amodei on open-weights models
🤡82😁18🖕10👍6👎3
OpenAI 及 Anthropic 发公开信呼吁美国政府推动措施控制 AI 发展速度。
公开信中提到,AI 发展速度越来越快且过于强大;社会需要时间来为 AI 带来的潜在威胁做准备。
https://pacingthefrontier.com/
#OpenAI #Anthropic
公开信中提到,AI 发展速度越来越快且过于强大;社会需要时间来为 AI 带来的潜在威胁做准备。
https://pacingthefrontier.com/
#OpenAI #Anthropic
Pacingthefrontier
Pacing the Frontier
A statement from over 1000 employees of frontier AI companies
🤡58😁12👍4👎3🖕2
数个虚假的 SQLite 漏洞报告被分配 CVE 编号。
- JFrog 团队发现, GitHub repo programmervuln/cveadvisory- 中发布了大量的漏洞报告,绝大多数为 AI 生成的错误内容。
- MITRE 在未对其进行验证的情况下就为这些虚假漏洞报告分配了 CVE 编号;目前编号已被撤回。
https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
#SQLite #CVE
- JFrog 团队发现, GitHub repo programmervuln/cveadvisory- 中发布了大量的漏洞报告,绝大多数为 AI 生成的错误内容。
- MITRE 在未对其进行验证的情况下就为这些虚假漏洞报告分配了 CVE 编号;目前编号已被撤回。
https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
#SQLite #CVE
Jfrog
SQLite Critical CVEs or LLM Slop? | JFrog
The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or…
🤡32😁2
Jeff Dean 离开 Google 创立新公司 Discovery Loop AI。
Jeff Dean 在 Google 供职 27 年,据称是 Google 的第 30 名雇员。
twitter.com/JeffDean/~
#JeffDean #Google
Jeff Dean 在 Google 供职 27 年,据称是 Google 的第 30 名雇员。
twitter.com/JeffDean/~
#JeffDean #Google
X (formerly Twitter)
Jeff Dean (@JeffDean) on X
Announcing Discovery Loop!
I am very excited to announce that, along with my longtime friends and collaborators @Sanjay_Ghemawat, @OriolVinyalsML and @quocleix, we are founding Discovery Loop (@DiscoLoopAI), a Public Benefit Corporation whose mission is…
I am very excited to announce that, along with my longtime friends and collaborators @Sanjay_Ghemawat, @OriolVinyalsML and @quocleix, we are founding Discovery Loop (@DiscoLoopAI), a Public Benefit Corporation whose mission is…
👏11
🔴 Linux 内核 sctp 模块本地提权漏洞 SCTPhantom。
- 腾讯朱雀实验室利用 AI 辅助发现了一个于 2008 年引入的 sctp 模块的漏洞。
- Kernel 上游和 Debian Trixie/Sid 已经发布修复版本。
CVE: CVE-2026-64564
CVSS: 8.5 (作者自评)
Fixed-In: 6.6.148, 6.12.101, 6.18.42, 7.1.6, 7.2-rc5
matrix.tencent.com/~
[感谢一位匿名订户提供信息。]
#SCTPhantom #Kernel
- 腾讯朱雀实验室利用 AI 辅助发现了一个于 2008 年引入的 sctp 模块的漏洞。
- Kernel 上游和 Debian Trixie/Sid 已经发布修复版本。
CVE: CVE-2026-64564
CVSS: 8.5 (作者自评)
Fixed-In: 6.6.148, 6.12.101, 6.18.42, 7.1.6, 7.2-rc5
matrix.tencent.com/~
[感谢一位匿名订户提供信息。]
#SCTPhantom #Kernel
腾讯朱雀实验室
SCTPhantom: 潜伏18年的Linux内核提权与容器逃逸漏洞 · 腾讯朱雀实验室
SCTPhantom 是 Linux 内核 SCTP 动态地址重配置功能中的一个释放后使用漏洞。
👏7
🔴 Linux 内核 Open vSwitch 模块本地提权漏洞 OVSwrap。
- 在用户命名空间有 CAP_NET_ADMIN 权限的进程 (
- 大多主流发行版均受到影响。
- Mitigation 是禁用
- Kernel 上游和 Debian 各支持版本已经发布修复。
heyitsas.im/~
CVE: CVE-2026-64531
CVSS: 7.8 (kernel.org)
Fixed-In: 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, 7.1.5
[感谢一位匿名订户提供信息。]
EDIT 8/7: 修正对利用此漏洞条件的描述。
#OpenvSwitch #Kernel
- 在用户命名空间有 CAP_NET_ADMIN 权限的进程 (
unshare -Urn) 即可以利用此漏洞提权。- 大多主流发行版均受到影响。
- Mitigation 是禁用
openvswitch 模块或 unprivileged user namespace 。- Kernel 上游和 Debian 各支持版本已经发布修复。
heyitsas.im/~
CVE: CVE-2026-64531
CVSS: 7.8 (kernel.org)
Fixed-In: 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, 7.1.5
[感谢一位匿名订户提供信息。]
EDIT 8/7: 修正对利用此漏洞条件的描述。
#OpenvSwitch #Kernel
Nixpkgs 规模两人的 core team 解散;原因是工作量过大导致 burnout。
- 这并不代表 NixOS/Nixpkgs 项目结束运作!
- 作者认为由少数受信任人士为社区做出决策效率更高。Steering Committee 的多数投票模式导致决策低效,甚至产生反效果。
https://discourse.nixos.org/t/-/79413
seealso: HackerNews:49217993
EDIT 8/12: 修正描述。
#NixOS
- 这并不代表 NixOS/Nixpkgs 项目结束运作!
- 作者认为由少数受信任人士为社区做出决策效率更高。Steering Committee 的多数投票模式导致决策低效,甚至产生反效果。
https://discourse.nixos.org/t/-/79413
seealso: HackerNews:49217993
EDIT 8/12: 修正描述。
#NixOS
NixOS Discourse
The Nixpkgs core team has disbanded
The Nixpkgs core team has unfortunately decided to disband. We’re proud to have had the opportunity to lead by example in bottom‐up, consensus‐focused governance for Nixpkgs, and of our achievements over the past 10 months, including reforming the committer…
😁19
Microsoft Entra ID 宣布自 2027/2/1 起停用短信/电话 2FA,并鼓励用户转而使用 Passkey。
- 9/1 起 Passkey 将为所有用户默认启用;用户在登录后会被提示为账户添加 Passkey。
- 依然需要短信/电话 2FA 的 tenant 可自 10/30 起自行选购第三方服务。
microsoft.com/~
#Microsoft #Passkey #Security
- 9/1 起 Passkey 将为所有用户默认启用;用户在登录后会被提示为账户添加 Passkey。
- 依然需要短信/电话 2FA 的 tenant 可自 10/30 起自行选购第三方服务。
microsoft.com/~
#Microsoft #Passkey #Security
Microsoft News
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
Starting September 1, 2026, passkeys will become the default authentication experience in Microsoft Entra. Read more about how to prepare.
👍18🤡4❤1😁1
[旧闻] GitHub 发布 8/17 outage 的 postmortem;问题起源是 autoscaling 配置不当。
- 整体故障自 8/17 晚九时半起约持续八小时。
- VS Code 的重试逻辑问题导致 Copilot token 端点流量激增,使得端点恢复所需时间较久。
https://www.githubstatus.com/incidents/zkxwbgr0cnmx
#Outage #GitHub
- 整体故障自 8/17 晚九时半起约持续八小时。
- VS Code 的重试逻辑问题导致 Copilot token 端点流量激增,使得端点恢复所需时间较久。
https://www.githubstatus.com/incidents/zkxwbgr0cnmx
#Outage #GitHub
Githubstatus
Incident with GitHub.com
GitHub's Status Page - Incident with GitHub.com.
🤡11😁2
🔴 crates.io 发现恶意包
- 受影响的包包括 [email protected]、[email protected]、[email protected]。
- 恶意包则是 proc-macro1, proc-macro-en, aovine, arone, aronenao 及 tinymember 的所有版本。
blog.rust-lang.org/~
#Rust #Ecosystem
proc-macro1;arrayref 部分版本受影响。- 受影响的包包括 [email protected]、[email protected]、[email protected]。
- 恶意包则是 proc-macro1, proc-macro-en, aovine, arone, aronenao 及 tinymember 的所有版本。
blog.rust-lang.org/~
#Rust #Ecosystem
blog.rust-lang.org
Supply chain attack on arrayref | Rust Blog
Empowering everyone to build reliable and efficient software.
😈19😱7😁5
OpenRouter 宣布被 Stripe 收购。
OpenRouter 是 LLM 网关/路由服务提供商;Stripe 是支付服务提供商。
openrouter.ai/~
#OpenRouter #Stripe
OpenRouter 是 LLM 网关/路由服务提供商;Stripe 是支付服务提供商。
openrouter.ai/~
#OpenRouter #Stripe
OpenRouter Blog
OpenRouter is Joining Stripe — OpenRouter Blog
OpenRouter is joining forces with Stripe. Same mission, same name, same product, same roadmap, and routing that stays driven by what's best for you.
👎18🤔6🥴1
教育网联合镜像站发布;使用 MirrorZ 系统。
地址是 https://mirrors.cernet.edu.cn 。
linksrc: https://t.iss.one/abcthoughts/7669
#OpenSource
地址是 https://mirrors.cernet.edu.cn 。
linksrc: https://t.iss.one/abcthoughts/7669
#OpenSource
🥰12😁4🎉2🤡1