Aggregator
赵长鹏自费出版了自己的自传
2 months 1 week ago
币安创始人赵长鹏自费出版了自己的中英文自传《Freedom of Money: A Memoir of Protecting Users, Resilience, and the Founding of Binance》。赵长鹏在书中讲述了币安与美国监管机构的长期对抗,币安因助长洗钱活动而支付创纪录的 43 亿美元和解金,他在加州服刑四个月期间开始撰写本书,以及去年底获得特朗普总统的赦免——他此前被永久禁止涉足加密货币银行业务,赦免意味着他可以继续从事这项业务。他创办的币安是全球最大的加密货币交易所,与特朗普家族的加密货币业务 World Liberty Financial 有深度合作。本书最有意思的可能是他的监狱生活。赵长鹏写道,他一度担心在狱中会被人勒索,因为媒体报道他是美国监狱关押的最富有的人,结果是根本没人认识他,因为监狱关押的人没人会去看华尔街日报或彭博社。他与一名因杀害两人而被判 30 年监禁的男性关住一间牢房,他发现狱友最致命的不是他杀过人而是他雷鸣般的鼾声。他还在书中提到了 FTX 创始人 Sam Bankman-Fried,币安曾持有 FTX 五分之一的股份,以及 5.8 亿美元的 FTT 代币。2022 年 FTX 濒临破产之际 Bankman-Fried 曾打电话给他索取数十亿美元,他的语气漫不经心,仿佛是要一份三明治。
«Конечно, вот ваш вирус». Как заставить нейросеть согласиться на что угодно одной строкой кода
2 months 1 week ago
Исследователи описали технику sockpuppeting, которая помогает обходить ограничения 11 крупных языковых моделей через подставное «согласие» ассистента.
敬畏与驾驭:系统复杂性视角下的软件智能化研发体系演进
2 months 1 week ago
彭鑫老师观点文章:驾驭AI的能力决定了我们能走多快,敬畏复杂性的智慧决定了我们能走多远
Как одна цифра в ссылке разрушает бизнес: разбираем уязвимость IDOR
2 months 1 week ago
Почему зайти в систему - еще не значит получить право на все данные.
Fixing vulnerability data quality requires fixing the architecture first
2 months 1 week ago
In this Help Net Security interview, Art Manion, Deputy Director at Tharros, examines why vulnerability data across repositories stays inconsistent and hard to trust. The problem starts with systems not designed to collect or manage that data well. They introduce the idea of Minimum Viable Vulnerability Enumeration (MVVE), a minimum set of assertions needed to confirm two systems describe the same vulnerability, and find no true minimum exists. Assertions vary by case and change over … More →
The post Fixing vulnerability data quality requires fixing the architecture first appeared first on Help Net Security.
Mirko Zorz
Claude Code Windows环境避坑指南
2 months 1 week ago
把 AI 工具链标准化成可重复执行的环境基础设施
CVE-2024-2256 | oik Plugin up to 4.10.0 on WordPress Shortcode cross site scripting
2 months 1 week ago
A vulnerability was found in oik Plugin up to 4.10.0 on WordPress. It has been rated as problematic. This impacts an unknown function of the component Shortcode Handler. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2024-2256. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2024-1795 | Husky Plugin up to 1.3.5.2 on WordPress sql injection
2 months 1 week ago
A vulnerability identified as critical has been detected in Husky Plugin up to 1.3.5.2 on WordPress. The affected element is an unknown function. This manipulation causes sql injection.
This vulnerability is tracked as CVE-2024-1795. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2024-1796 | Husky Plugin up to 1.3.5.1 on WordPress Shortcode cross site scripting
2 months 1 week ago
A vulnerability marked as problematic has been reported in Husky Plugin up to 1.3.5.1 on WordPress. This affects an unknown function of the component Shortcode Handler. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2024-1796. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-2399 | Premium Addons for Elementor Pro Plugin up to 4.10.23 on WordPress cross site scripting (ID 3051259)
2 months 1 week ago
A vulnerability classified as problematic has been found in Premium Addons for Elementor Pro Plugin up to 4.10.23 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2024-2399. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2024-2294 | Backuply Plugin up to 1.2.7 on WordPress path traversal
2 months 1 week ago
A vulnerability was found in Backuply Plugin up to 1.2.7 on WordPress. It has been rated as critical. This affects an unknown function. Performing a manipulation results in path traversal.
This vulnerability is known as CVE-2024-2294. Access to the local network is required for this attack. No exploit is available.
vuldb.com
CVE-2024-2308 | Elementvader Addons for Elementor Plugin up to 1.2.2 on WordPress cross site scripting
2 months 1 week ago
A vulnerability identified as problematic has been detected in Elementvader Addons for Elementor Plugin up to 1.2.2 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-2308. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2024-1685 | Social Media Share Buttons Plugin up to 2.1.0 on WordPress code injection
2 months 1 week ago
A vulnerability was found in Social Media Share Buttons Plugin up to 2.1.0 on WordPress. It has been declared as critical. This affects an unknown function. Executing a manipulation can lead to code injection.
This vulnerability is registered as CVE-2024-1685. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2024-1857 | wpswings Ultimate Gift Cards for WooCommerce Plugin up to 2.6.6 on WordPress wps_wgm_preview_email_template authorization
2 months 1 week ago
A vulnerability marked as problematic has been reported in wpswings Ultimate Gift Cards for WooCommerce Plugin up to 2.6.6 on WordPress. The affected element is the function wps_wgm_preview_email_template. This manipulation causes missing authorization.
This vulnerability is registered as CVE-2024-1857. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2024-1787 | Contests by Rewards Fuel Plugin up to 2.0.64 on WordPress update_rewards_fuel_api_key cross site scripting
2 months 1 week ago
A vulnerability was found in Contests by Rewards Fuel Plugin up to 2.0.64 on WordPress and classified as problematic. The affected element is the function update_rewards_fuel_api_key. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2024-1787. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2024-1785 | Contests by Rewards Fuel Plugin up to 2.0.62 on WordPress cross-site request forgery
2 months 1 week ago
A vulnerability was found in Contests by Rewards Fuel Plugin up to 2.0.62 on WordPress. It has been classified as problematic. The impacted element is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-1785. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2024-1995 | Smart Custom Fields Plugin up to 4.2.2 on WordPress Post authorization
2 months 1 week ago
A vulnerability, which was classified as problematic, was found in Smart Custom Fields Plugin up to 4.2.2 on WordPress. The impacted element is an unknown function of the component Post Handler. Executing a manipulation can lead to missing authorization.
This vulnerability appears as CVE-2024-1995. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2024-2387 | nasirahmed Advanced Form Integration Plugin up to 1.82.0 on WordPress integration_id sql injection
2 months 1 week ago
A vulnerability classified as critical was found in nasirahmed Advanced Form Integration Plugin up to 1.82.0 on WordPress. This issue affects some unknown processing. Executing a manipulation of the argument integration_id can lead to sql injection.
The identification of this vulnerability is CVE-2024-2387. The attack may be launched remotely. There is no exploit available.
vuldb.com
Linux 7.0 释出
2 months 1 week ago
Linus Torvalds 在内核邮件列表上宣布释出 Linux 7.0,它将会是支持 i486 CPU 的最后一个版本。Linux 7.0 的主要新特性包括:Rust 代码不再是实验性;io_uring 操作的新过滤机制,CPU 调度器默认启用延迟抢占,支持时间片扩展,nullfs 文件系统,XFS 文件系统支持自我修复,新的文件 I/O 错误报告 API,支持 Clang 静态分析,默认启用 AccECN 支持以更好处理 TCP 拥塞,Btrfs 实验性支持重映射树(remap tree),新驱动,等等。更多可浏览 KernelNewbies 7.0。