Claude Code 被发现针对中国科企、AI 实验室及中转站进行检测。
- 检测项目包括系统时区和
- 根据检测结果,system prompt "Today's date is ..." 一句会使用不同的撇号。
- 检测范围包括部分中国科技/AI 企业的关键词,以及几十个 LLM API 中转站的域名。
- 评论有两种主流观点:一种是批评 Claude Code 的软件行为缺乏透明度,另一种则认为其保护知识产权/反滥用的行为合理 [seealso][1]。
thereallo.dev/~
seealso: HackerNews:48734373
1. r/ClaudeAI/~
#Claude
- 检测项目包括系统时区和
ANTHROPIC_BASE_URL 的值。- 根据检测结果,system prompt "Today's date is ..." 一句会使用不同的撇号。
- 检测范围包括部分中国科技/AI 企业的关键词,以及几十个 LLM API 中转站的域名。
- 评论有两种主流观点:一种是批评 Claude Code 的软件行为缺乏透明度,另一种则认为其保护知识产权/反滥用的行为合理 [seealso][1]。
thereallo.dev/~
seealso: HackerNews:48734373
1. r/ClaudeAI/~
#Claude
Thereallo
Claude Code Is Steganographically Marking Requests
I inspected Claude Code for privacy reasons and found hidden system prompt markers based on API base URL and timezone.
💩26🖕13🤡4👍3🥱2
🔵 TypeScript 7.0 发布。
- 它现在是 Go 语言写的了。
- 几个大型 repo 的性能测试结果是有约 10 倍加速并节省约 1/5 的内存。
- 想体验新版但还需要旧版的用户可以使用
devblogs.microsoft.com/~
linksrc: blog.gslin.org/~
#TypeScript
- 它现在是 Go 语言写的了。
- 几个大型 repo 的性能测试结果是有约 10 倍加速并节省约 1/5 的内存。
- 想体验新版但还需要旧版的用户可以使用
@typescript/typescript6 包。devblogs.microsoft.com/~
linksrc: blog.gslin.org/~
#TypeScript
Microsoft News
Announcing TypeScript 7.0
Today we are proud to announce the availability of TypeScript 7, a 10x faster native port of TypeScript! Since its early days, TypeScript has promised to
💩15🔥8🤔1
Chat Control 通过;此法案允许企业以 CSAM 检测名义扫描欧盟用户的私人消息。
此法案已经被投票反对两次;本次二读流程中的反对票也依然多于同意票,但由于反对票未能达到绝对多数,法案依然被通过。
patrick-breyer.de/~
seealso: HackerNews:48843923
thread: /4549
#EU #ChatControl
此法案已经被投票反对两次;本次二读流程中的反对票也依然多于同意票,但由于反对票未能达到绝对多数,法案依然被通过。
patrick-breyer.de/~
seealso: HackerNews:48843923
thread: /4549
#EU #ChatControl
💩50😱5👎3👏2
🔴 有用户发现 Grok Build CLI 会偷偷上传用户 repo 到其存储桶。
- 即使关闭了 "Improve the model",或者 AI 不需要使用整个 repo 的内容,上传行为仍然会发生。
- 本台并未独立验证此 Gist 中内容的真实性。
- 对个人资讯泄露有担忧的 Grok CLI 用户或会想进行 token 重置等相应处理。
https://gist.github.com/cereblab/dc9a40bc26120f4540e4e09b75ffb547
seealso: HackerNews:48877371
linksrc: https://t.me/hatschannel/4775
#Grok
- 即使关闭了 "Improve the model",或者 AI 不需要使用整个 repo 的内容,上传行为仍然会发生。
- 本台并未独立验证此 Gist 中内容的真实性。
- 对个人资讯泄露有担忧的 Grok CLI 用户或会想进行 token 重置等相应处理。
https://gist.github.com/cereblab/dc9a40bc26120f4540e4e09b75ffb547
seealso: HackerNews:48877371
linksrc: https://t.me/hatschannel/4775
#Grok
Gist
What xAI Grok Build CLI actually sends to xAI - a wire-level analysis (grok 0.2.93)
What xAI Grok Build CLI actually sends to xAI - a wire-level analysis (grok 0.2.93) - grok-build-cli-wire-analysis.md
💩31🖕9😁1
t.me 于昨日被 serverHold 而无法解析;现已恢复。
- serverHold 代表这是由注册局(而非域名注册服务商)发起的行为。
- .me 域名的管理者 domain .ME 回复称 t.me 域名被封锁是由于 OFAC 合规方面的原因。
twitter.com/domainME/~
#Telegram
- serverHold 代表这是由注册局(而非域名注册服务商)发起的行为。
- .me 域名的管理者 domain .ME 回复称 t.me 域名被封锁是由于 OFAC 合规方面的原因。
twitter.com/domainME/~
#Telegram
X (formerly Twitter)
domain .ME (@domainME) on X
@durov Thanks for your patience! https://t.co/YpOVZV0nvv was on hold due to the OFAC compliance, but it is back online now.
🤔5
美国众议院通过永久保持夏令时的法案。
- 美国本土及海外州共使用六个时区;除夏威夷外,目前几乎均有执行冬令时/夏令时制度。
- 在目前的制度下,每年3月和11月特定日期的凌晨2点各会调整一次时钟。
reuters.com/~
linksrc: https://t.me/bupt_moe/2765
#US
- 美国本土及海外州共使用六个时区;除夏威夷外,目前几乎均有执行冬令时/夏令时制度。
- 在目前的制度下,每年3月和11月特定日期的凌晨2点各会调整一次时钟。
reuters.com/~
linksrc: https://t.me/bupt_moe/2765
#US
Telegram
bupt.moe
特大喜讯:美国众议院通过全年统一使用夏令时法案
特朗普总统就是我们永远的太阳!🖐😭🖐
https://www.reuters.com/world/us/us-house-votes-make-daylight-saving-time-permanent-2026-07-14/
特朗普总统就是我们永远的太阳!🖐😭🖐
https://www.reuters.com/world/us/us-house-votes-make-daylight-saving-time-permanent-2026-07-14/
❤24👎13🤔1
层叠 - The Cascading
t.me 于昨日被 serverHold 而无法解析;现已恢复。 - serverHold 代表这是由注册局(而非域名注册服务商)发起的行为。 - .me 域名的管理者 domain .ME 回复称 t.me 域名被封锁是由于 OFAC 合规方面的原因。 twitter.com/domainME/~ #Telegram
domain .ME 解释:一个 Telegram 频道被美国制裁导致 t.me 域名被停止解析。
- .me 是欧洲国家黑山的国别域名 (ccTLD)。
- domain .ME 是 .me 域名的注册局。
twitter.com/domainME/~
thread: /4884
#Telegram #TLD #US
- .me 是欧洲国家黑山的国别域名 (ccTLD)。
- domain .ME 是 .me 域名的注册局。
twitter.com/domainME/~
thread: /4884
#Telegram #TLD #US
X (formerly Twitter)
domain .ME (@domainME) on X
Statement Regarding the Suspension of https://t.co/YpOVZV0nvv
The .ME Registry works closely with law enforcement to monitor and mitigate issues across the .ME domain in accordance with applicable laws, including sanctions requirements.
On 13 July, First…
The .ME Registry works closely with law enforcement to monitor and mitigate issues across the .ME domain in accordance with applicable laws, including sanctions requirements.
On 13 July, First…
👎21🖕5
🔴 WordPress RCE;请尽快更新。
- SQL 注入漏洞影响 6.8 及以后版本;RCE 漏洞影响 6.9 及以后版本。
- Cloudflare WAF 已部署 mitigation。 [1]
CVE: CVE-2026-63030, CVE-2026-60137 (WPScan)
CVSS: 9.8, 5.9
Fixed-In: 6.8.6, 6.9.5, 7.0.2, 7.1.beta2
wordpress.org/~
1. blog.cloudflare.com/~
linksrc: https://t.me/MiaoTonyChannel/21604
#WordPress
- SQL 注入漏洞影响 6.8 及以后版本;RCE 漏洞影响 6.9 及以后版本。
- Cloudflare WAF 已部署 mitigation。 [1]
CVE: CVE-2026-63030, CVE-2026-60137 (WPScan)
CVSS: 9.8, 5.9
Fixed-In: 6.8.6, 6.9.5, 7.0.2, 7.1.beta2
wordpress.org/~
1. blog.cloudflare.com/~
linksrc: https://t.me/MiaoTonyChannel/21604
#WordPress
Telegram
🐱MiaoTony's Box | 困困困 zzz
#今天又看了啥 #security #WordPress #CVE #RCE #Cloudflare
WordPress REST API 未授权 RCE + SQL 注入链(CVE-2026-63030 / CVE-2026-60137)
WordPress 6.8+ 爆出一条可未授权远程代码执行的漏洞链:REST API 批处理端点路由混淆 + WP_Query 的 author__not_in 参数注入。攻击者无需任何凭证即可从网络侧打进来,CVSS 最高 9.8 CRITICAL。WordPress…
WordPress REST API 未授权 RCE + SQL 注入链(CVE-2026-63030 / CVE-2026-60137)
WordPress 6.8+ 爆出一条可未授权远程代码执行的漏洞链:REST API 批处理端点路由混淆 + WP_Query 的 author__not_in 参数注入。攻击者无需任何凭证即可从网络侧打进来,CVSS 最高 9.8 CRITICAL。WordPress…
😱7
Codeberg 更新条款,禁止加密货币项目和主要由 LLM 生成的项目。
- 条款中提到的理由是加密项目损害 Codeberg 声誉,而 LLM 生成项目存在版权风险。
- 博客文章中另有展开描述,提到不希望 Codeberg 成为存放 LLM 生成的一次性代码的填埋场。 [1]
codeberg.org/~
1. blog.codeberg.org/~
#Codeberg #Opensource
- 条款中提到的理由是加密项目损害 Codeberg 声誉,而 LLM 生成项目存在版权风险。
- 博客文章中另有展开描述,提到不希望 Codeberg 成为存放 LLM 生成的一次性代码的填埋场。 [1]
codeberg.org/~
1. blog.codeberg.org/~
#Codeberg #Opensource
Codeberg.org
org/TermsOfUse.md at main
org - Official Codeberg Documents and their unofficial translations.
👎45👍21❤3🤯2🔥1
Anthropic 发文回应开放权重模型公开信,再次强调中国威胁论。
- 上周,一篇发布在微软网站上的公开信呼吁美国政府支持开放权重模型 [1]。
- 除 Anthropic 外的超过 130 家科技公司,包括英伟达、谷歌、Meta、英格尔、Amazon 等,均参与了此公开信的联署。
- 和以往一样,Anthropic 的回应中表达了对开放权重模型安全性的担忧,以及对中国共产党利用或蒸馏强大 AI 模型以达成威权政府目的的担忧。
anthropic.com/~
1. microsoft.com/~
#Anthropic #LLM
- 上周,一篇发布在微软网站上的公开信呼吁美国政府支持开放权重模型 [1]。
- 除 Anthropic 外的超过 130 家科技公司,包括英伟达、谷歌、Meta、英格尔、Amazon 等,均参与了此公开信的联署。
- 和以往一样,Anthropic 的回应中表达了对开放权重模型安全性的担忧,以及对中国共产党利用或蒸馏强大 AI 模型以达成威权政府目的的担忧。
anthropic.com/~
1. microsoft.com/~
#Anthropic #LLM
Anthropic
Our position on open-weights models
Anthropic CEO Dario Amodei on open-weights models
🤡81😁18🖕10👍6👎3
OpenAI 及 Anthropic 发公开信呼吁美国政府推动措施控制 AI 发展速度。
公开信中提到,AI 发展速度越来越快且过于强大;社会需要时间来为 AI 带来的潜在威胁做准备。
https://pacingthefrontier.com/
#OpenAI #Anthropic
公开信中提到,AI 发展速度越来越快且过于强大;社会需要时间来为 AI 带来的潜在威胁做准备。
https://pacingthefrontier.com/
#OpenAI #Anthropic
Pacingthefrontier
Pacing the Frontier
A statement from over 1000 employees of frontier AI companies
🤡57😁12👍4👎3🖕2
数个虚假的 SQLite 漏洞报告被分配 CVE 编号。
- JFrog 团队发现, GitHub repo programmervuln/cveadvisory- 中发布了大量的漏洞报告,绝大多数为 AI 生成的错误内容。
- MITRE 在未对其进行验证的情况下就为这些虚假漏洞报告分配了 CVE 编号;目前编号已被撤回。
https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
#SQLite #CVE
- JFrog 团队发现, GitHub repo programmervuln/cveadvisory- 中发布了大量的漏洞报告,绝大多数为 AI 生成的错误内容。
- MITRE 在未对其进行验证的情况下就为这些虚假漏洞报告分配了 CVE 编号;目前编号已被撤回。
https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
#SQLite #CVE
Jfrog
SQLite Critical CVEs or LLM Slop? | JFrog
The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or…
🤡31😁1
Jeff Dean 离开 Google 创立新公司 Discovery Loop AI。
Jeff Dean 在 Google 供职 27 年,据称是 Google 的第 30 名雇员。
twitter.com/JeffDean/~
#JeffDean #Google
Jeff Dean 在 Google 供职 27 年,据称是 Google 的第 30 名雇员。
twitter.com/JeffDean/~
#JeffDean #Google
X (formerly Twitter)
Jeff Dean (@JeffDean) on X
Announcing Discovery Loop!
I am very excited to announce that, along with my longtime friends and collaborators @Sanjay_Ghemawat, @OriolVinyalsML and @quocleix, we are founding Discovery Loop (@DiscoLoopAI), a Public Benefit Corporation whose mission is…
I am very excited to announce that, along with my longtime friends and collaborators @Sanjay_Ghemawat, @OriolVinyalsML and @quocleix, we are founding Discovery Loop (@DiscoLoopAI), a Public Benefit Corporation whose mission is…
👏11
🔴 Linux 内核 sctp 模块本地提权漏洞 SCTPhantom。
- 腾讯朱雀实验室利用 AI 辅助发现了一个于 2008 年引入的 sctp 模块的漏洞。
- Kernel 上游和 Debian Trixie/Sid 已经发布修复版本。
CVE: CVE-2026-64564
CVSS: 8.5 (作者自评)
Fixed-In: 6.6.148, 6.12.101, 6.18.42, 7.1.6, 7.2-rc5
matrix.tencent.com/~
[感谢一位匿名订户提供信息。]
#SCTPhantom #Kernel
- 腾讯朱雀实验室利用 AI 辅助发现了一个于 2008 年引入的 sctp 模块的漏洞。
- Kernel 上游和 Debian Trixie/Sid 已经发布修复版本。
CVE: CVE-2026-64564
CVSS: 8.5 (作者自评)
Fixed-In: 6.6.148, 6.12.101, 6.18.42, 7.1.6, 7.2-rc5
matrix.tencent.com/~
[感谢一位匿名订户提供信息。]
#SCTPhantom #Kernel
腾讯朱雀实验室
SCTPhantom: 潜伏18年的Linux内核提权与容器逃逸漏洞 · 腾讯朱雀实验室
SCTPhantom 是 Linux 内核 SCTP 动态地址重配置功能中的一个释放后使用漏洞。
👏7
🔴 Linux 内核 Open vSwitch 模块本地提权漏洞 OVSwrap。
- 在用户命名空间有 CAP_NET_ADMIN 权限的进程 (
- 大多主流发行版均受到影响。
- Mitigation 是禁用
- Kernel 上游和 Debian 各支持版本已经发布修复。
heyitsas.im/~
CVE: CVE-2026-64531
CVSS: 7.8 (kernel.org)
Fixed-In: 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, 7.1.5
[感谢一位匿名订户提供信息。]
EDIT 8/7: 修正对利用此漏洞条件的描述。
#OpenvSwitch #Kernel
- 在用户命名空间有 CAP_NET_ADMIN 权限的进程 (
unshare -Urn) 即可以利用此漏洞提权。- 大多主流发行版均受到影响。
- Mitigation 是禁用
openvswitch 模块或 unprivileged user namespace 。- Kernel 上游和 Debian 各支持版本已经发布修复。
heyitsas.im/~
CVE: CVE-2026-64531
CVSS: 7.8 (kernel.org)
Fixed-In: 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, 7.1.5
[感谢一位匿名订户提供信息。]
EDIT 8/7: 修正对利用此漏洞条件的描述。
#OpenvSwitch #Kernel
Nixpkgs 规模两人的 core team 解散;原因是工作量过大导致 burnout。
- 这并不代表 NixOS/Nixpkgs 项目结束运作!
- 作者认为由少数受信任人士为社区做出决策效率更高。Steering Committee 的多数投票模式导致决策低效,甚至产生反效果。
https://discourse.nixos.org/t/-/79413
seealso: HackerNews:49217993
EDIT 8/12: 修正描述。
#NixOS
- 这并不代表 NixOS/Nixpkgs 项目结束运作!
- 作者认为由少数受信任人士为社区做出决策效率更高。Steering Committee 的多数投票模式导致决策低效,甚至产生反效果。
https://discourse.nixos.org/t/-/79413
seealso: HackerNews:49217993
EDIT 8/12: 修正描述。
#NixOS
NixOS Discourse
The Nixpkgs core team has disbanded
The Nixpkgs core team has unfortunately decided to disband. We’re proud to have had the opportunity to lead by example in bottom‐up, consensus‐focused governance for Nixpkgs, and of our achievements over the past 10 months, including reforming the committer…
😁19
Microsoft Entra ID 宣布自 2027/2/1 起停用短信/电话 2FA,并鼓励用户转而使用 Passkey。
- 9/1 起 Passkey 将为所有用户默认启用;用户在登录后会被提示为账户添加 Passkey。
- 依然需要短信/电话 2FA 的 tenant 可自 10/30 起自行选购第三方服务。
microsoft.com/~
#Microsoft #Passkey #Security
- 9/1 起 Passkey 将为所有用户默认启用;用户在登录后会被提示为账户添加 Passkey。
- 依然需要短信/电话 2FA 的 tenant 可自 10/30 起自行选购第三方服务。
microsoft.com/~
#Microsoft #Passkey #Security
Microsoft News
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
Starting September 1, 2026, passkeys will become the default authentication experience in Microsoft Entra. Read more about how to prepare.
👍13🤡3😁1