新聞隨著AI代理自動執行程式碼與工具呼叫的應用升溫,Google Cloud宣布,專為這類任務設計、可部署於Google Kubernetes Engine(GKE)的沙箱環境GKE Agent Sandbox正式開放使用,並同步提出開源基礎架構專案Agent Substrate,以因應超大規模AI代理在執行與排程上的需求。Google Cloud指出,AI代理已從早期聊天介面,進一步發展到可呼叫…
業界新聞
Analyst firm Gartner thinks at least half of all generative AI projects “will overrun their budgeted costs due to poor architectural choices and lack of operational know-how,” and most organizations t…
新聞5月27日美國網路安全暨基礎設施安全局(CISA)將CVE-2026-8398、CVE-2026-45321、CVE-2026-48027等3個漏洞列入已遭利用的漏洞名單(KEV),要求聯邦機構限期採取行動,值得留意的是,這些漏洞並非一般的軟體弱點,而是因供應鏈攻擊導致軟體被植入惡意程式碼的情況。值得留意的是,CISA給予聯邦機構因應威脅的期限有所不同,其中最短的是虛擬光碟機軟體Daemon …
新聞Meta產品主管Naomi Gleit周三(5/27)透過Instagram及Threads發表全新的服務品牌Meta One,準備集結Meta旗下各種付費訂閱服務,首波已開始於全球市場推出的是Instagram Plus、WhatsApp Plus與Facebook Plus。Gleit並未詳細揭露這些付費服務的功能,只說這些訂閱功能將會強化使用者喜愛的功能,開放更多容量、能力、創作空間,並…
新聞開發社群平臺GitHub本周釋出GitHub Enterprise Server(GHES)3.20.3,修補多項重大及高風險漏洞,包括2個SSRF漏洞,以及和上周資安事件與Linux Dirty Frag有關的問題。最新版更新修補的兩項重大漏洞,其一為編號CVE-2026-9312,為存在上傳端點的前驗證(pre-authentication)伺服器端請求偽造(server-side req…
Salesforce's decapitated response to the SaaS-pocalypse has quickly won adoption, as Headless 360 – which allows customers to access all of their Salesforce data from Cursor, WhatsApp, ChatGPT, Claude…
Hyperscalers’ purchasing power means bare metal servers offered by major clouds can now be cheaper and easier to acquire than on-prem servers, according to Nutanix CEO Rajiv Ramaswami. The CEO told Th…
Websites Have a New Way To Spy On Visitors: Analyzing Their SSD Activity https://hardware.slashdot.org/story/26/05/27/2153246/websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity?ut…
新聞上週網頁伺服器系統開發商LiteSpeed揭露與修補權限提升漏洞CVE-2026-48172,此漏洞存在於該公司提供cPanel用戶的外掛程式,CVSS v4.0風險達到滿分10分,LiteSpeed強調已被積極利用,呼籲用戶儘速採取行動,如今美國政府也證實這樣的情形。5月26日美國網路安全暨基礎設施安全局(CISA)發出公告,表示他們已掌握CVE-2026-48172遭積極利用的跡象,將其加…
新聞醫療健康產業資安情資分享組織Health-ISAC於5月發布報告,警告AI模型開發商Anthropic的Claude Mythos Preview已展現高度自主攻擊能力,能用於發現與利用零時差漏洞,可能改變醫療健康產業面對漏洞管理與攻擊防禦的時間壓力。Health-ISAC指出,這類模型若維持在受控環境,可協助防禦方更快找出並修補弱點;但一旦外流或遭濫用,也可能像Cobalt Strike與B…
新聞Anthropic公開說明Claude代理產品的安全設計,指出當AI代理取得檔案、命令列、網路與外部工具存取能力後,不能只依賴模型判斷或人工批准,而要透過執行環境隔離、檔案系統邊界與網路出口管制,限制代理遭誤用、遭攻擊或執行非預期動作時的損害範圍。在Claude網頁服務中,程式執行被放在伺服器端的暫時性隔離容器,檔案系統只存在於單一工作階段,代理不會直接接觸使用者本機環境。如此,降低單次執行可…
Mesa 26.0.8 Released To End Out The Series Eric Engestrom announced the release of Mesa 26.0.8 today as the latest stable point release of that Q1'2026 driver series and the last planned update for th…
Websites have a new way to spy on visitors: analyzing their SSD activity Telltale SSD activity can be measured in the browser using simple JavaScript. https://arstechnica.com/security/2026/05/websites…
Nvidia CEO wants Taiwan to be center of “AI revolution,” not US Nvidia will invest $150 billion a year to make Taiwan an AI “epicenter.” https://arstechnica.com/tech-policy/2026/05/nvidia-ceo-wants-ta…
Roku OS’s home screen now features a large, permanent ad “I don't want recommendations! I know what I want to watch." https://arstechnica.com/gadgets/2026/05/roku-oss-home-screen-now-features-a-large-…
AI algorithms exhibit racial bias in job candidate screening, and they discriminate more frequently against those applying for multiple jobs at different companies, according to Stanford-led researche…
The Internet Corporation for Assigned Names and Numbers (ICANN) has again intervened in the affairs of the African Network Information Centre (AFRINIC), the regional internet registry for 54 nations a…
Boffins at the Department of Energy’s (DoE) Argonne National Laboratory near Chicago on Tuesday unveiled a new AI inference service cobbled together from spare supercomputing capacity. The hope is tha…
An npm-slop package “mouse5212-super-formatter” targeting Claude users and acting as a stealer reached 676 downloads before being removed from the registry - and after making a major vibe coding blund…
Another Starship launch, another Federal Aviation Administration-mandated grounding and mishap investigation that couldn’t come at a worse time as SpaceX attempts to court investors for what could be …