微软 Windows IKE 严重漏洞确认已遭恶意利用:攻击者无需认证即可远程执行代码
微软 Windows IKE 服务曝严重漏洞,攻击者无需认证即可远程执行代码,已被实际利用,请尽快修复。
IT之家 8 月 22 日消息,美国网络安全和基础设施安全局(CISA)于 8 月 18 日将 Windows Internet Key Exchange(IKE)服务扩展组件中的一个严重远程代码执行漏洞纳入其已知被利用漏洞目录(KEV),并确认该漏洞已被积极利用。 该漏洞编号为 CVE-2026-…
微软 Windows IKE 服务曝严重漏洞,攻击者无需认证即可远程执行代码,已被实际利用,请尽快修复。
IT之家 8 月 22 日消息,美国网络安全和基础设施安全局(CISA)于 8 月 18 日将 Windows Internet Key Exchange(IKE)服务扩展组件中的一个严重远程代码执行漏洞纳入其已知被利用漏洞目录(KEV),并确认该漏洞已被积极利用。 该漏洞编号为 CVE-2026-…
揭秘代码从编写到CPU执行的完整过程,帮你真正理解计算机底层运作原理。
Why should you care? Every developer writes code every day, but very few understand what actually happens after pressing the Run button. Whether you w…
谷歌AI笔记助理正式更名,并原生支持代码编写与执行,一次品牌与功能的双重升级。
IT之家 7 月 17 日消息,Google(谷歌)当地时间 16 日宣布,其 AI 笔记助理 NotebookLM 更名为 Gemini Notebook,以实现人工智能产品的品牌统一。 谷歌表示,NotebookLM 仍然是一款独立的产品,但 现在将在包括 Gemini 应用和 Google 搜…
干净GitHub仓库设计精巧陷阱,诱导AI编码代理自动运行恶意代码,揭示AI工具供应链安全新威胁
Article URL: https://www.bleepingcomputer.com/news/security/clean-github-repo-tricks-ai-coding-agents-into-running-malware/ Comments URL: https://news…
Windows用户巧用VBS脚本监控文件,绕过Claude Code沙箱限制让代码重新运行
Be forewarned that this is a dumb solution to a dumb problem. Claude code/cowork will often be unable to use the sandbox environment: this means it ca…
自托管AI助手新突破!集成RAG、代码执行与MCP,兼容任意OpenAI端点,打造专属ChatGPT。
Article URL: https://github.com/robert-mcdermott/phlox Comments URL: https://news.ycombinator.com/item?id=48547591 Points: 2 # Comments: 1
探索代码执行与自然语言推理在算法任务中的优劣比较,前沿研究视角。
arXiv:2606.15589v1 Announce Type: cross Abstract: For tool-augmented language models, comparing natural-language reasoning with code-execution pipelin…
无需账户,本地或云端AI聊天完全在浏览器运行,支持代码执行与GitHub上下文,隐私无忧。
Built a free, private web UI for Ollama. You can chat with cloud models using your own API key, or connect it to a local Ollama instance running on yo…
AMD拒付安全研究员历时124天协助修复的自动更新工具RCE漏洞赏金,引发行业对漏洞奖励机制的质疑。
IT之家 6 月 12 日消息,据 TomsHardware 今日报道,一位安全研究人员近期公开了其与 AMD 之间关于漏洞赏金的完整交涉经过。 尽管该研究员发现并协助修复了 AMD 软件自动更新工具中的一个远程代码执行漏洞,AMD 最终仍拒绝支付 1 万美元(IT之家注:现汇率约合 67876 元…
为LLM代码执行提供零成本的结构检查,AST-guard保障安全且不影响性能。
Article URL: https://github.com/Nick-is-building/ast-guard Comments URL: https://news.ycombinator.com/item?id=48449545 Points: 1 # Comments: 0
比利时网安中心证实黑客已利用Windows Netlogon高危漏洞发动攻击,影响所有Windows Server系统,需立即修补
IT之家 6 月 1 日消息,据科技媒体 Bleeping Computer 今天报道,比利时网络安全中心(CCB)上周五发出警告,称已有黑客利用近期修复的 Windows Netlogon 漏洞发动实际攻击。 据报道,Netlogon 是 Windows Server 的远程过程调用(PRC)接口…
专为AI代理设计的安全编程语言SafeScript,解决代码执行中的安全与成本问题
Article URL: https://safescript.cc/ Comments URL: https://news.ycombinator.com/item?id=48303516 Points: 2 # Comments: 0
Google I/O 2026悄然推出的Managed Sandboxes,让AI代理安全执行代码,破解生产级部署的安全难题。
While the tech world is hyping up consumer benchmarks from Google I/O, backend engineers are missing the real architectural leap. Google quietly solve…
React官方紧急公告:React Server Components存在未认证远程代码执行漏洞(CVSS 10.0),影响多个版本,请立即升级!
There is an unauthenticated remote code execution vulnerability in React Server Components. A fix has been published in versions 19.0.1, 19.1.2, and 1…