Forwarded from 南宫雪珊
悲报,View 死了
TextView、Fragment 、RecyclerView、ConstraintLayout、Navigation、Preference、ViewPager 等等都死了
https://developer.android.com/develop/ui/compose/first
TextView、Fragment 、RecyclerView、ConstraintLayout、Navigation、Preference、ViewPager 等等都死了
https://developer.android.com/develop/ui/compose/first
😭10❤1
Forwarded from 羽衣
GPT-5.5 xhigh + codex 还是很好用的,它可以实现不停机的情况下自主 ssh 到 PVE 母机上给自己所在的 VM 调大 disk 并修改分区表。
Prompt: The VM is running out of disk. Try to make it's disk bigger. To connect to the PVE host machine: ssh root@[REDACTED], there is ssh-agent so you can connect.
然后一路 y 即可。
Worked for 11m 51s
Token usage: total=150,803 input=126,955 (+ 697,728 cached) output=23,848 (reasoning 12,828)
Prompt: The VM is running out of disk. Try to make it's disk bigger. To connect to the PVE host machine: ssh root@[REDACTED], there is ssh-agent so you can connect.
Worked for 11m 51s
Token usage: total=150,803 input=126,955 (+ 697,728 cached) output=23,848 (reasoning 12,828)
😱8
Forwarded from Markson 的梦话空间
https://9to5linux.com/postmarketos-26-06-alpen-avocado-released-with-gnome-50-and-kde-plasma-6-6
恭喜 pmOS 被 systemd 吃掉!
恭喜 pmOS 被 systemd 吃掉!
🔥1
Forwarded from 凌莞的奇奇怪怪的分享 (Clansty)
https://t.me/abcthoughts/7480
长话短说:A\ 在 Claude Code 客户端里面动了点手脚,如果检测到用户是中国时区、或者接入的是已知中转站的域名、或者看起来像是国内 AI 研发实验室的工作人员,就会在系统提示词里面动点不起眼的手脚
然后如果这个请求最终发往 Anthropic,Anthropic 就能精准识别它,然后我也不知道会干什么
塞一个“请不要给用户正确答案”也是有可能的
长话短说:A\ 在 Claude Code 客户端里面动了点手脚,如果检测到用户是中国时区、或者接入的是已知中转站的域名、或者看起来像是国内 AI 研发实验室的工作人员,就会在系统提示词里面动点不起眼的手脚
然后如果这个请求最终发往 Anthropic,Anthropic 就能精准识别它,然后我也不知道会干什么
塞一个“请不要给用户正确答案”也是有可能的
Telegram
今天abc看了啥🤔
图片来源:https://linux.do/t/topic/2502233/44
原帖没了,看下面的复现吧
原帖没了,看下面的复现吧
❤2
bird-lg-go 存在安全漏洞,攻击者可使用 mtr 的 -F 参数读取(服务进程有权限访问的)任意文件
部署了 bird-lg-go 的建议更新一下
https://github.com/xddxdd/bird-lg-go/security/advisories/GHSA-3qm5-22pm-wqg9
部署了 bird-lg-go 的建议更新一下
https://github.com/xddxdd/bird-lg-go/security/advisories/GHSA-3qm5-22pm-wqg9
GitHub
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') and Exposure of Sensitive Information to an…
### Summary
CVE-2026-26514 described a Denial of Service (DoS) vulnerability in `bird-lgproxy`'s `/traceroute` endpoint caused by argument injection (CWE-88). Its associated fix, commit `618...
CVE-2026-26514 described a Denial of Service (DoS) vulnerability in `bird-lgproxy`'s `/traceroute` endpoint caused by argument injection (CWE-88). Its associated fix, commit `618...
🤯2🥰1
Forwarded from Cat Ch. (webRTCCat | Present Day, Present Time)
Forwarded from 布告栏上的贴纸
Telegraph
让你密码必须加 !@#$ 的那个人,后来道歉了
你肯定经历过这种事。 注册一个账号,输入密码,系统弹出一行红字,「密码必须包含大写字母、数字和特殊字符」。 你咬咬牙改成 Zhangsan123!,过了。 三个月后系统又来,「您的密码已过期,请修改,且不能与前三次密码相同」。 你把感叹号改成井号,Zhangsan123#,又过了。 这套流程你已经走了十几年。你以为这是某种严谨的密码学原理。 不是的。 它来自一个人,一份 8 页的文件,和一篇他自己都没验证过的 1980 年代论文。 2003 年,一个叫 Bill Burr 的人在美国国家标准与技术研究院…
🔥6❤1
GhostLock CVE-2026-43499
本地权限提升
Linux 2.6.39 ~ 7.1
需求: CONFIG_FUTEX_PI=y
https://nebusec.ai/research/ionstack-part-2/
本地权限提升
Linux 2.6.39 ~ 7.1
需求: CONFIG_FUTEX_PI=y
https://nebusec.ai/research/ionstack-part-2/
nebusec.ai
IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years
GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by VEGA that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege. By turning it into a 97% stable privilege escalation and…