[赞助商] exe.dev
exe.dev 是一款面向智能体时代的云服务。它提供默认开启 SSH、root 权限和网络认证的虚拟机池,在网络边缘注入的密钥不会触及大语言模型。可用于持久化服务器、内部工具、Vibe Coding、一次性开发环境等场景——本质上就是一台计算机。
exe.dev 是一款面向智能体时代的云服务。它提供默认开启 SSH、root 权限和网络认证的虚拟机池,在网络边缘注入的密钥不会触及大语言模型。可用于持久化服务器、内部工具、Vibe Coding、一次性开发环境等场景——本质上就是一台计算机。
A new wave of the Shai-Hulud malware campaign has compromised approximately 600 NPM packages, targeting developers by embedding malicious code into open-source dependencies to steal credentials and sensitive data.
Researchers discovered a critical authentication bypass vulnerability (CVE-2026-9058) in Poland's Social Insurance (ZUS), eCourt, and eHealth systems. The flaw, linked to improper e-signature validation, could allow unauthorized access to sensitive citizen and medical data. Security experts warn that unpatched systems pose a serious risk of cyber chaos.
Patrick McKenzie notes that an LLM-produced blog post analyzing supply chain attack clusters, published by msuiche, is the first AI-generated public artifact he finds professionally relevant and complete enough that the lack of a human author does not materially compromise its utility.
The FTC fined Cox Media $4.5 million for claiming it could use AI to eavesdrop on phone microphones to target ads, a practice the company marketed to clients but never actually deployed.
A developer describes being targeted in a sophisticated malware campaign likely linked to North Korea (DPRK), involving fake job offers and malicious code designed to compromise their system.