“无法阻止”的安全漏洞,只发生在这一种编程语言中
OpenSSL 3.5.7 版本修复了一个由 C 语言编写的 PKCS7_verify() 函数中的堆释放后使用漏洞(CVE-2026-45447)。该漏洞再次引发对 C 语言内存安全问题的讨论——过去 50 年间全球 90% 的内存安全漏洞均源于此,且 C 语言项目的安全漏洞概率是其他语言的 20 倍。尽管开发者普遍表示“无能为力”,但问题根源在于语言本身缺乏内存安全保障机制。
OpenSSL 3.5.7 版本修复了一个由 C 语言编写的 PKCS7_verify() 函数中的堆释放后使用漏洞(CVE-2026-45447)。该漏洞再次引发对 C 语言内存安全问题的讨论——过去 50 年间全球 90% 的内存安全漏洞均源于此,且 C 语言项目的安全漏洞概率是其他语言的 20 倍。尽管开发者普遍表示“无能为力”,但问题根源在于语言本身缺乏内存安全保障机制。
The article argues that export controls on the Fable obfuscation tool are ineffective because the technology has already proliferated widely, making late-stage restrictions unlikely to slow its spread.
A U.S. government ban on Anthropic's AI models has sparked debate, but the article argues the restriction was never truly motivated by concerns over a jailbreak exploit. Instead, the decision reflects broader regulatory and policy tensions around AI safety and control.
The article argues that US export controls on Fable 5, a cryptographic tool, are weakening domestic cyber defense by limiting access for American researchers and security professionals while foreign adversaries face no such restrictions. The author claims these regulations hinder innovation and leave US infrastructure more vulnerable.
Legal tech company Fable has sued the U.S. government over a new order restricting foreign nationals' access to certain advanced legal AI models, arguing the rules unfairly limit competition and harm cross-border business operations.
U.S. export controls on cybersecurity tools under the Wassenaar Arrangement hinder American cyber defense by restricting security researchers from sharing vulnerability detection tools internationally, weakening collective security.