因广告机器人出没,评论区禁止使用频道身份发言,发送垃圾信息可能会被bot封禁。如果你想匿名、被误封或是在海外生活,欢迎PM @MizuhashiZ 添加白名单
不公正 不客观 不理性
投稿 / 反馈 / 闲聊 / 发傻 / 和动物成为朋友 / USB Type-C
不收快科技的稿源
子频道 @Hearse_Drifting
除上述讨论群及子频道外,本频道与其他频道 / 讨论群无任何关联
头像 shorturl.at/XQE9r
不公正 不客观 不理性
投稿 / 反馈 / 闲聊 / 发傻 / 和动物成为朋友 / USB Type-C
不收快科技的稿源
子频道 @Hearse_Drifting
除上述讨论群及子频道外,本频道与其他频道 / 讨论群无任何关联
头像 shorturl.at/XQE9r
小米 14 Ultra 钛金属版手机维修备件价格公布:主板 3030 元,屏幕 1690 元
https://www.ithome.com/0/759/078.htm
———
主板 3030 / 6499 ≈ 46%
屏幕 1690 / 6999 ≈ 24% (钛金属版)
屏幕 1350 / 6499 ≈ 20%
后置摄像头(广角)1000 / 6499 ≈ 15%
https://www.ithome.com/0/759/078.htm
———
主板 3030 / 6499 ≈ 46%
屏幕 1690 / 6999 ≈ 24% (钛金属版)
屏幕 1350 / 6499 ≈ 20%
后置摄像头(广角)1000 / 6499 ≈ 15%
15 秒语音片段就能合成某人声音,OpenAI 小规模开放 Voice Engine 模型 - IT之家
https://www.ithome.com/0/759/095.htm
https://www.ithome.com/0/759/095.htm
美国警方示警:盗车团伙日益猖獗,滥用苹果 AirTag 追踪目标车辆
https://www.ithome.com/0/759/060.htm
美国佛蒙特州当局表示已经收到多起车主报告,偷车团队开始滥用苹果的 AirTag,标记想要偷窃的汽车目标,追踪到目标汽车之后偷窃转运到其它国家和地区实现销赃。
———
2024-03-17 美加州法院裁定,苹果必须面对 AirTag 是“跟踪者武器”的集体诉讼
2024-03-16 苹果败诉:AirTag被指助长跟踪行为,隐私安全争议升级
2023-10-16 苹果遭集体诉讼:AirTag 跟踪已导致“多起谋杀案”,可低成本跟踪受害者
2023-05-03 汽车盗窃案上升 548%,纽约市免费发放 500 个苹果 AirTag 遏制态势
2022-06-13 美国警方使用苹果 AirTag 追踪北卡罗来纳州的连环窃贼
攻守转换
https://www.ithome.com/0/759/060.htm
美国佛蒙特州当局表示已经收到多起车主报告,偷车团队开始滥用苹果的 AirTag,标记想要偷窃的汽车目标,追踪到目标汽车之后偷窃转运到其它国家和地区实现销赃。
———
2024-03-17 美加州法院裁定,苹果必须面对 AirTag 是“跟踪者武器”的集体诉讼
2024-03-16 苹果败诉:AirTag被指助长跟踪行为,隐私安全争议升级
2023-10-16 苹果遭集体诉讼:AirTag 跟踪已导致“多起谋杀案”,可低成本跟踪受害者
2023-05-03 汽车盗窃案上升 548%,纽约市免费发放 500 个苹果 AirTag 遏制态势
2022-06-13 美国警方使用苹果 AirTag 追踪北卡罗来纳州的连环窃贼
攻守转换
微软重发 Edge 浏览器 123 稳定版:修复兼容性问题和 4 个零日漏洞
https://www.ithome.com/0/759/082.htm
微软 Edge 浏览器 123 稳定版修复以下 4 个漏洞:
CVE-2024-2887:WebAssembly 中的类型混乱
CVE-2024-2886:WebCodecs 中的 Use after free
CVE-2024-2885:Dawn 中的 Use after free
CVE-2024-2883:ANGLE 中的 Use after free
———
2024-03-28 谷歌紧急发布 Chrome 更新,修复 Pwn2Own 大赛中报告的两个零日漏洞
https://www.ithome.com/0/759/082.htm
微软 Edge 浏览器 123 稳定版修复以下 4 个漏洞:
CVE-2024-2887:WebAssembly 中的类型混乱
CVE-2024-2886:WebCodecs 中的 Use after free
CVE-2024-2885:Dawn 中的 Use after free
CVE-2024-2883:ANGLE 中的 Use after free
———
2024-03-28 谷歌紧急发布 Chrome 更新,修复 Pwn2Own 大赛中报告的两个零日漏洞
106 款受影响,Brother 打印机暂不兼容微软 Win11 更新:无法识别 USB 连接、无法调整设置
https://www.ithome.com/0/759/087.htm
Brother 近日发布支持文档,表示旗下的 106 款打印机并不兼容 Windows 11 系统更新,系统无法识别通过 USB 连接的打印机,此前已连接打印机在更新之后无法更改打印机设置。
https://www.ithome.com/0/759/087.htm
Brother 近日发布支持文档,表示旗下的 106 款打印机并不兼容 Windows 11 系统更新,系统无法识别通过 USB 连接的打印机,此前已连接打印机在更新之后无法更改打印机设置。
俄罗斯 启动游戏和娱乐设备开发计划,用来顶替索尼/微软/Steam等
https://www.landiannews.com/archives/103142.html
https://www.landiannews.com/archives/103142.html
XZ 维护者之一 Jia Tan 在 GitHub 上发布的 XZ Utils 5.6.0 and 5.6.1 tarball 中包含了恶意后门代码。
如非特别标注,以下链接中内容均为英文。
==== XZ 方面的信息,以及漏洞分析 ====
oss-security 邮件列表: https://www.openwall.com/lists/oss-security/2024/03/29/4
debian-security-announce 邮件列表: https://lists.debian.org/debian-security-announce/2024/msg00057.html
XZ 主要维护者 Lasse Collin 的声明: https://tukaani.org/xz-backdoor/
FAQ by Sam James: https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27
Evan Boehs 的博客: https://boehs.org/node/everything-i-know-about-the-xz-backdoor
Filippo Valsorda: https://bsky.app/profile/filippo.abyssdomain.expert/post/3kowjkx2njy2b
Gynvael Coldwind: https://gynvael.coldwind.pl/?id=782
RHEA 关于时区的分析: https://rheaeve.substack.com/p/xz-backdoor-times-damned-times-and
==== 新闻报道 ====
LWN: https://lwn.net/Articles/967180/
==== 供应商方面的信息,主要是各大发行版和安全公告板 ====
CVE: https://www.cve.org/CVERecord?id=CVE-2024-3094
NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-3094
MSRC: https://techcommunity.microsoft.com/t5/microsoft-defender-vulnerability/microsoft-faq-and-guidance-for-xz-utils-backdoor/ba-p/4101961
GitHub Advisory Database: https://github.com/advisories/GHSA-rxwq-x6h5-x525
Red Hat Customer Portal: https://access.redhat.com/security/cve/CVE-2024-3094
Red Hat Blog: https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users
Red Hat Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-3094
Debian Security Bug Tracker: https://security-tracker.debian.org/tracker/CVE-2024-3094
Debian Bug: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024
Kali Linux Blog: https://www.kali.org/blog/about-the-xz-backdoor/
SUSE blog: https://www.suse.com/c/suse-addresses-supply-chain-attack-against-xz-compression-library/
SUSE Security: https://www.suse.com/security/cve/CVE-2024-3094.html
SUSE Bugzilla: https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-3094
openSUSE News: https://news.opensuse.org/2024/03/29/xz-backdoor/
Gentoo's Bugzilla: https://bugs.gentoo.org/show_bug.cgi?id=CVE-2024-3094
Arch Linux News: https://archlinux.org/news/the-xz-package-has-been-backdoored/
Arch Linux Advisories: https://security.archlinux.org/ASA-202403-1
OpenWrt: https://forum.openwrt.org/t/project-statement-about-xz-5-6-1-cve-2024-3094/193250
==== 忙着查资料的被子饼 ====
目前的证据表明这个后门仅影响部分 Debian/Ubuntu/Fedora/openSUSE 的预发布版本,且均已发布回退更新
目前确定曾受影响的发行版:
Debian unstable/testing/experimental between 2024-02-01 and 2024-03-29
Kali Linux between 2024-03-26 and 2024-03-29
Ubuntu noble-proposed/noble-release between 2024-02-26 and 2024-03-29
Fedora 40/41(Rawhide) between 2024-02-27 and 2024-03-29
openSUSE Tumbleweed/MicroOS between 2024-03-07 and 2024-03-28
如非特别标注,以下链接中内容均为英文。
==== XZ 方面的信息,以及漏洞分析 ====
oss-security 邮件列表: https://www.openwall.com/lists/oss-security/2024/03/29/4
debian-security-announce 邮件列表: https://lists.debian.org/debian-security-announce/2024/msg00057.html
XZ 主要维护者 Lasse Collin 的声明: https://tukaani.org/xz-backdoor/
FAQ by Sam James: https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27
Evan Boehs 的博客: https://boehs.org/node/everything-i-know-about-the-xz-backdoor
Filippo Valsorda: https://bsky.app/profile/filippo.abyssdomain.expert/post/3kowjkx2njy2b
Gynvael Coldwind: https://gynvael.coldwind.pl/?id=782
RHEA 关于时区的分析: https://rheaeve.substack.com/p/xz-backdoor-times-damned-times-and
==== 新闻报道 ====
LWN: https://lwn.net/Articles/967180/
==== 供应商方面的信息,主要是各大发行版和安全公告板 ====
CVE: https://www.cve.org/CVERecord?id=CVE-2024-3094
NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-3094
MSRC: https://techcommunity.microsoft.com/t5/microsoft-defender-vulnerability/microsoft-faq-and-guidance-for-xz-utils-backdoor/ba-p/4101961
GitHub Advisory Database: https://github.com/advisories/GHSA-rxwq-x6h5-x525
Red Hat Customer Portal: https://access.redhat.com/security/cve/CVE-2024-3094
Red Hat Blog: https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users
Red Hat Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-3094
Debian Security Bug Tracker: https://security-tracker.debian.org/tracker/CVE-2024-3094
Debian Bug: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024
Kali Linux Blog: https://www.kali.org/blog/about-the-xz-backdoor/
SUSE blog: https://www.suse.com/c/suse-addresses-supply-chain-attack-against-xz-compression-library/
SUSE Security: https://www.suse.com/security/cve/CVE-2024-3094.html
SUSE Bugzilla: https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-3094
openSUSE News: https://news.opensuse.org/2024/03/29/xz-backdoor/
Gentoo's Bugzilla: https://bugs.gentoo.org/show_bug.cgi?id=CVE-2024-3094
Arch Linux News: https://archlinux.org/news/the-xz-package-has-been-backdoored/
Arch Linux Advisories: https://security.archlinux.org/ASA-202403-1
OpenWrt: https://forum.openwrt.org/t/project-statement-about-xz-5-6-1-cve-2024-3094/193250
==== 忙着查资料的被子饼 ====
目前的证据表明这个后门仅影响部分 Debian/Ubuntu/Fedora/openSUSE 的预发布版本,且均已发布回退更新
目前确定曾受影响的发行版:
Debian unstable/testing/experimental between 2024-02-01 and 2024-03-29
Kali Linux between 2024-03-26 and 2024-03-29
Ubuntu noble-proposed/noble-release between 2024-02-26 and 2024-03-29
Fedora 40/41(Rawhide) between 2024-02-27 and 2024-03-29
openSUSE Tumbleweed/MicroOS between 2024-03-07 and 2024-03-28
Redis 更改开源协议引争议,Linux 基金会宣布创建 Valkey 分支“单干” - IT之家
https://www.ithome.com/0/759/001.htm
https://www.ithome.com/0/759/001.htm
https://www.ithome.com/0/758/981.htm
设计真的难看,价格倒是还行
在引起巨大争议之后,云服务器主机 Vultr 从服务条款中删除用户数据所有权相关条款
https://www.theregister.com/2024/03/28/vultr_content_controversy/
We're very focused on being responsive to the community and the concerns people have and we believe the strongest thing we can do to demonstrate that there is no bad intent here is to remove it.
https://www.theregister.com/2024/03/28/vultr_content_controversy/
耗时 4 年时间,从零开始打造的 FuryGPU 显卡亮相:运行《雷神之锤》可 60 FPS
https://www.tomshardware.com/~
https://www.ithome.com/~
基于 Xilinx Zynq UltraScale+ FPGA 设计,开源。
为现代 Windows 版本提供完整的软件和驱动程序栈。
可以在 Windows 上运行旧版游戏软件。
https://www.tomshardware.com/~
https://www.ithome.com/~
基于 Xilinx Zynq UltraScale+ FPGA 设计,开源。
为现代 Windows 版本提供完整的软件和驱动程序栈。
可以在 Windows 上运行旧版游戏软件。
小米回应SU7无法退定金:消费者主动锁单就退不了
https://www.autohome.com.cn/news/202403/1294884.html
有网友在社交平台发文称:“10点抢了首发小米汽车,误锁配置,在订单外面点击按钮,提示按钮并没有明显告知不给退”,还有网友称“ 小米汽车的配置锁定按钮没有二次提示,误触了才知道5千退不了”。
———
一晚收到1亿元定金!小米汽车创始版售罄
https://finance.sina.cn/stock/relnews/hk/2024-03-29/detail-inapyiey0626297.d.html
根据官方消息,小米汽车SU7 4分钟大定破万,7分钟破2万,27分钟破5万为真。
https://www.autohome.com.cn/news/202403/1294884.html
有网友在社交平台发文称:“10点抢了首发小米汽车,误锁配置,在订单外面点击按钮,提示按钮并没有明显告知不给退”,还有网友称“ 小米汽车的配置锁定按钮没有二次提示,误触了才知道5千退不了”。
———
一晚收到1亿元定金!小米汽车创始版售罄
https://finance.sina.cn/stock/relnews/hk/2024-03-29/detail-inapyiey0626297.d.html
根据官方消息,小米汽车SU7 4分钟大定破万,7分钟破2万,27分钟破5万为真。
爆破现场违规用微信文字沟通,现场未解除警戒就起爆致3人殒命,8人被追责
==========
这就是喜欢用 微信 办公的后果(
https://www.bjnews.com.cn/detail/1711592877129128.html
==========
这就是喜欢用 微信 办公的后果(
https://www.bjnews.com.cn/detail/1711592877129128.html
Proxmox VE 推出工具可以直接导入和迁移 ESXi 虚拟机
https://www.landiannews.com/archives/103124.html
https://www.landiannews.com/archives/103124.html
Telegram 测试 P2PL 服务,利用用户手机向其他用户发送验证码
用户可能每个月要发送多达 150 条短信,作为回报 Telegram 会向用户提供价值5美元的 Telegram Premium 兑换码。
这个功能的争议在于无法阻止验证码接收者看到您的电话号码,泄露自己的手机号码会带来潜在隐私问题。
因为报酬是以兑换码形式提供的,因此存在转卖的空间。或许 Telegram 的目标就不是普通用户。
https://www.landiannews.com/archives/103118.html
用户可能每个月要发送多达 150 条短信,作为回报 Telegram 会向用户提供价值5美元的 Telegram Premium 兑换码。
这个功能的争议在于无法阻止验证码接收者看到您的电话号码,泄露自己的手机号码会带来潜在隐私问题。
因为报酬是以兑换码形式提供的,因此存在转卖的空间。或许 Telegram 的目标就不是普通用户。
https://www.landiannews.com/archives/103118.html
开发者请注意: .NET 7 将在5月14日结束支持,请尽快升级到后续版本
https://www.landiannews.com/archives/103108.html
怎么感觉一些老应用还在用 .net 3.5 来着
https://www.landiannews.com/archives/103108.html
怎么感觉一些老应用还在用 .net 3.5 来着
Intel 透露能离线执行 Copilot 的 Windows AI PC 需 40 TOPS NPU 性能,Meteor Lake 与 Ryzen 8040 都不及格
https://www.cool3c.com/article/212774
如果只能由NPU来提供AI算力,那他们连及格线一半都没到
https://www.cool3c.com/article/212774
如果只能由NPU来提供AI算力,那他们连及格线一半都没到
中国移动宣布 5G-A 正式商用
https://www.yicai.com/news/102045847.html
中国移动 5G-A 正式商用,但要大范围落地仍需迈过这些坎
https://www.jiemian.com/article/10978172.html
https://www.yicai.com/news/102045847.html
中国移动 5G-A 正式商用,但要大范围落地仍需迈过这些坎
https://www.jiemian.com/article/10978172.html
LockBit 引领勒索软件进入下个时代
https://www.secrss.com/articles/64805
https://www.secrss.com/articles/64805
传社交平台 X 正在测试“成人内容”社群
https://techcrunch.com/~
https://techcrunch.com/~