新聞Claude Code程式碼外洩引發GitHub供應鏈攻擊風險,駭客散布惡意程式鎖定開發者3月底AI程式開發工具Claude Code驚傳NPM儲存庫的Java程式來源映射檔(Source Map File)被公開,引起許多開發人員下載及流傳,Anthropic坦承確實有內部原始碼外流的情況,是人為疏失造成。值得留意的是,駭客也看上開發人員好奇的心理,假借提供相關檔案的名義,散布惡意程式。資安…
業界新聞
Ofcom finds social media participation dropping as skepticism about digital life growsBritish adults are now less active on social media, according to Ofcom, with just half of users actively posting, …
Intel is going all-in on advanced chip packaging Intel is hoping to cash in on the AI boom. https://arstechnica.com/gadgets/2026/04/intel-is-going-all-in-on-advanced-chip-packaging/?utm_brand=arstechn…
新聞3月底受到廣泛採用的HTTP用戶端程式庫Axios遭遇供應鏈攻擊,北韓駭客UNC1069(也被稱為Sapphire Sleet、Stardust Chollima、BlueNoroff)挾持知名維護者Jason Saayman的NPM憑證而得逞,後續該名開發人員透露,因遭遇社交工程攻擊而被騙走上述資料。Jason Saayman起初於3月31日的資安公告透露,Axios的維護團隊成員大約在兩週…
China Flies World's First Megawatt-Class Hydrogen Turboprop Engine https://tech.slashdot.org/story/26/04/06/2242242/china-flies-worlds-first-megawatt-class-hydrogen-turboprop-engine?utm_source=rss1.0m…
新聞4月4日資安公司Fortinet發布公告,指出旗下的端點管理平臺FortiClient EMS存在資安漏洞CVE-2026-35616,未通過身分驗證的攻擊者可使用特製的請求,執行未經授權的程式碼或命令,影響7.4.5至7.4.6版FortiClient EMS,CVSS風險評為9.1分(滿分10分),屬重大等級風險,該公司特別提及,已掌握漏洞遭到利用的情況,他們在即將推出的7.4.7版發布之…
新聞去年12月React開發工程團隊揭露重大漏洞CVE-2025-55182(React2Shell),此為遠端程式碼執行(RCE)漏洞,出現在伺服器元件(React Server Components),CVSS風險評分達到滿分10分,很快就有中國與北韓國家級駭客、勒索軟體、殭屍網路將其用於實際攻擊,如今傳出有人用於大規模搜刮應用系統的憑證。思科旗下的威脅情報團隊Talos指出,他們發現名為UA…
新聞OpenAI近日發布政策文件,試圖從更宏觀的角度回應AI帶來的經濟與社會變化。指出AI正快速從提升單一任務效率,邁向能處理長時間、複雜工作的超級智慧(Superintelligence)階段,未來對產業與勞動市場的影響,可能相當於甚至超過過去的工業革命。同時,OpenAI也面臨來自各國日益升高的監管壓力,包括AI安全、模型透明度、市場集中,以及對就業與資料使用影響的關注,使AI治理框架仍在快速…
Astronauts set distance record, revealing the Moon as a place to be explored "Humans have probably not evolved to see what we’re seeing. It is truly hard to describe. It is amazing." https://arstechni…
新聞微軟正式發布Microsoft Agent Framework 1.0版,這是該公司將旗下兩大AI代理開發專案Semantic Kernel與AutoGen整合後的統一開源SDK,同時支援.NET與Python兩種語言,作為企業級多代理應用的生產環境就緒框架。 微軟於2025年10月首次對外揭露Agent Framework,當時宣布要將Semantic Kernel的企業級基礎架構,與Mic…
新聞微軟週五(4/3)宣布,將於2026年至2029年間在日本投資100億美元,擴大AI基礎設施、資安合作與人才培育,進一步深化其在亞洲AI市場的布局。微軟說明,此次投資是基於技術(Technology)、信任(Trust)與人才(Talent)三大主軸,包括在日本境內擴建雲端與AI基礎設施,並與在地業者合作提供GPU算力,確保資料可留在日本境內運作,以回應企業及政府對資料主權的需求。在基礎設施上…
新聞AI新創Anthropic週一(4/6)宣布,擴大與Google及Broadcom的合作,預計自2027年起上線,以支撐其Claude模型與企業客戶需求。根據路透社(Reuters)報導,此一協議涉及約3.5GW的AI算力。在合作架構上,Google將提供TPU算力資源,Broadcom則參與相關晶片的開發與供應。TPU為Google自研的AI加速晶片,主要用於機器學習模型的訓練與推論。Bro…
New Jersey Cannot Regulate Kalshi's Prediction Market, US Appeals Court Rules https://yro.slashdot.org/story/26/04/06/2214217/new-jersey-cannot-regulate-kalshis-prediction-market-us-appeals-court-rule…
Customizations are causing pain so new cloud will stick to upstream cuts of the open source stackLY Corporation, the Japanese web giant that dominates messaging, e-commerce and payments in many Asian …
Broadcom's building the silicon and is chuffed about that, but also notes Anthropic remains a riskBroadcom has announced that Google has asked it to build next-generation AI and datacenter networking …
After court loss, RFK Jr. gives himself more power over CDC vaccine panel The charter renewal gives Kennedy broad authority to pick anyone for the panel. https://arstechnica.com/health/2026/04/after-c…
CUPS server shown spilling out remote code execution and root accessIn the latest chapter on leaky CUPS, a security researcher and his band of bug-hunting agents have found two flaws that can be chain…
OpenAI Calls For Robot Taxes, Public Wealth Fund, and 4-Day Workweek To Tackle AI Disruption https://yro.slashdot.org/story/26/04/06/2154206/openai-calls-for-robot-taxes-public-wealth-fund-and-4-day-w…
Mesa Developers Decide On Two Gen AI Policies For Development Moving Forward Building on prior Mesa contributor guidelines and discussions among upstream Mesa developers, there are two generative AI "…
Once AI bug reports become plausible, someone still has to verify themIf AI does more of the work but humans still have to check it, you need more reviewers. Now that AI models have gotten better at w…