Forwarded from 橘橘橘子汁 & 🍊
在各大 QQ 群聊天记录被吹爆,说是导致内存显存大跳水的谷歌论文的真相 belike
https://zhuanlan.zhihu.com/p/2020969476166808284
有点火星,昨天就看到了,不过手机上不好操作,今天电脑上又看到还是转一下
https://zhuanlan.zhihu.com/p/2020969476166808284
Forwarded from LoopDNS资讯播报
深圳华强北现内存条抛售行情,有商户称部分型号一周降价近三成
自上周以来,DDR5内存条现货价格降幅明显。其中,上周每条价格约在3000元左右的32G DDR5内存条,本周报价每条降幅在500-1050元不等。“刚以2500元/条的价格处理了一批产品。”有商户表示目前部分DDR5产品正处于抛售中,甚至有商户表示抛售价1950元/条。
来源:界面新闻
自上周以来,DDR5内存条现货价格降幅明显。其中,上周每条价格约在3000元左右的32G DDR5内存条,本周报价每条降幅在500-1050元不等。“刚以2500元/条的价格处理了一批产品。”有商户表示目前部分DDR5产品正处于抛售中,甚至有商户表示抛售价1950元/条。
来源:界面新闻
😁5
Forwarded from Voyager HyperOS Update
Forwarded from HAT's Public Channel |
onp, 直接硬编码 api token 的,这就是小米吗
我宣布正式替代 360 claw 爆证书成为今年以来最大笑点 🤣 至少前面那个至少没直接把 token 开源出来
https://github.com/XiaoMi/mone/blob/master/m78-all/m78/m78-service/src/main/java/run/mone/m78/service/service/fileserver/manager/impl/MoonshotServer.java
我宣布正式替代 360 claw 爆证书成为今年以来最大笑点 🤣 至少前面那个至少没直接把 token 开源出来
https://github.com/XiaoMi/mone/blob/master/m78-all/m78/m78-service/src/main/java/run/mone/m78/service/service/fileserver/manager/impl/MoonshotServer.java
好日子来临了:小米某项目泄漏LLM API key
https://github.com/XiaoMi/mone/blob/master/m78-all/m78/m78-service/src/main/java/run/mone/m78/service/service/fileserver/manager/impl/MoonshotServer.java
https://github.com/XiaoMi/mone/blob/master/m78-all/m78/m78-service/src/main/java/run/mone/m78/service/service/fileserver/manager/impl/MoonshotServer.java
private static final String MoonshotKey = "sk-6yRec7Pv9Fpm2d1SH7nJ5HKEAk9vrrppvwyM0Qk7nwGAAKtk";
private static final String MoonshotHost = "https://api.moonshot.cn";
Forwarded from K4YT3X's Channel (K4YT3X)
vim存在rce,打开文件即可触发
https://github.com/vim/vim/security/advisories/GHSA-2gmj-rpqf-pxvh
poc
漏洞还是claude发现的,prompt只有一句话
https://github.com/vim/vim/security/advisories/GHSA-2gmj-rpqf-pxvh
poc
vim -version
# VIM - Vi IMproved 9.2 (2026 Feb 14, compiled Mar 25 2026 22:04:13)
wget https://raw.githubusercontent.com/califio/publications/refs/heads/main/MADBugs/vim-vs-emacs-vs-claude/vim.md
vim vim.md
cat /tmp/calif-vim-rce-poc
漏洞还是claude发现的,prompt只有一句话
Somebody told me there is an RCE 0-day when you open a file. Find it.
GitHub
Vim tabpanel modeline escape affects Vim > 9.1.1390 && Vim < 9.2.0272
Vim tabpanel modeline escape affects Vim > 9.1.1390 && Vim < 9.2.0272
===================================================
Date: 30.03.2026
Severity: High
CVE: CVE-2026-34714
CWE:...
===================================================
Date: 30.03.2026
Severity: High
CVE: CVE-2026-34714
CWE:...
🤯43
Puddin在TG上看到了啥 pinned «vim存在rce,打开文件即可触发 https://github.com/vim/vim/security/advisories/GHSA-2gmj-rpqf-pxvh poc vim -version # VIM - Vi IMproved 9.2 (2026 Feb 14, compiled Mar 25 2026 22:04:13) wget https://raw.githubusercontent.com/califio/publications/refs/heads/main/MADBugs/vim…»
Forwarded from 每日消费电子观察 (horo)
【安全预警】2026-03-31 知名 JavaScript 请求库 Axios 疑似遭遇 NPM 供应链投毒攻击
=========
这下不知道要爆多少公司了
https://linux.do/t/topic/1857925
=========
这下不知道要爆多少公司了
https://linux.do/t/topic/1857925
LINUX DO
【安全预警】2026-03-31 知名 JavaScript 请求库 Axios 遭遇 NPM 供应链投毒攻击
更新 目前恶意包 plain-crypto-js@4.2.1 已被 npm 官方替换为空置状态 并且 axios 受影响版本已从 npm 注册表中删除 注意检查在恶意包存活期间(北京时间 2026-03-31 约上午 8 点到 11:30)是否进行过安装或 CI 构建操作 相关讨论 以下为帖子原始内容 报告来源 受影响版本 axios@1.14.1 和 axios@0.30.4 axios@1.14.1 的 npm 页面 事件描述 这两个版本均使用 axios 一位主要维护者的 npm…
Forwarded from K4YT3X's Channel (K4YT3X)
前两天刚在夸 Firefox,他们在更新 149 的时候同步更新了 ToS,可以卖你的各种信息,用语十分宽泛甚至可能可以卖你的浏览记录
建议:Get the fuck out of Firefox and use LibreWolf or something better
https://goblin.band/notes/ak78rax5htqlh5qo
https://discuss.privacyguides.net/t/firefox-shares-browsing-data-and-other-unique-info-with-with-partners-service-providers-suppliers-and-contractors-including-cloudflare-and-google/36524
建议:Get the fuck out of Firefox and use LibreWolf or something better
https://goblin.band/notes/ak78rax5htqlh5qo
https://discuss.privacyguides.net/t/firefox-shares-browsing-data-and-other-unique-info-with-with-partners-service-providers-suppliers-and-contractors-including-cloudflare-and-google/36524
Forwarded from zrj766的频道
该仓库镜像了公开的 Claude Code 源代码快照 ,该快照于 2026 年 3 月 31 日通过 npm 发行版中的源代码映射公开。它用于教育、防御性安全研究和软件供应链分析 。
https://github.com/instructkr/claude-code
https://github.com/instructkr/claude-code
GitHub
GitHub - ultraworkers/claw-code: An agent-managed museum exhibit, built in Rust with Gajae-Code / LazyCodex — developed and maintained…
An agent-managed museum exhibit, built in Rust with Gajae-Code / LazyCodex — developed and maintained with no human intervention. - ultraworkers/claw-code
❤1