哔哩哔哩哔哩哔哩新浪新闻新浪新闻新浪网新浪网GitHubGitHubCSDNCSDNIT之家IT之家36氪36氪AcFunAcFunAdafruit BlogAdafruit BlogAIbaseAIbaseAnt Bailing Developer BlogAnt Bailing Developer BlogAnthropicAnthropic小众软件小众软件AppleAppleAppleInsiderAppleInsiderArs TechnicaArs TechnicaBerkeley AI ResearchBerkeley AI ResearchBBC NewsBBC NewsBD Tech TalksBD Tech TalksBerkeley RDIBerkeley RDIBloombergBloombergBoston Dynamics BlogBoston Dynamics BlogByteDance Seed ResearchByteDance Seed ResearchClaude BlogClaude BlogClaude Code ReleasesClaude Code ReleasesCloudflare BlogCloudflare BlogCMU Machine Learning BlogCMU Machine Learning Blog酷安酷安crates.iocrates.ioCrowd SupplyCrowd SupplyCSS-TricksCSS-Tricks51CTO51CTOCult of MacCult of MacCursor BlogCursor BlogDaring FireballDaring FireballDario AmodeiDario AmodeiDeepLearning.AI · The BatchDeepLearning.AI · The BatchGoogle DeepMind BlogGoogle DeepMind BlogDeepSeek GitHubDeepSeek GitHubDescript BlogDescript BlogDEV.toDEV.to数字尾巴数字尾巴Docker HubDocker HubDwarkesh PatelDwarkesh PatelEleutherAI BlogEleutherAI BlogEngadgetEngadgetFlathubFlathubFreebuf · 网络安全Freebuf · 网络安全freeCodeCampfreeCodeCampGary MarcusGary Marcus极客公园极客公园果核剥壳果核剥壳GizmodoGizmodoGoogleGoogleHackadayHackadayHacker NewsHacker NewsHelloGitHubHelloGitHubHomebrewHomebrew全球主机交流全球主机交流Hugging FaceHugging Face虎嗅虎嗅IEEE SpectrumIEEE Spectrum爱范儿爱范儿inclusionAIinclusionAIIndie HackersIndie HackersInfoQInfoQInterconnectsInterconnects稀土掘金稀土掘金Andrej KarpathyAndrej KarpathyKickstarter · TechnologyKickstarter · TechnologyMoonshot AI KimiMoonshot AI KimiLatent SpaceLatent SpaceLil'Log (Lilian Weng)Lil'Log (Lilian Weng)LiliputingLiliputingLinux.doLinux.doLMSYS BlogLMSYS BlogLobstersLobstersLWN.netLWN.netMacRumorsMacRumorsMake: MagazineMake: MagazineMaven CentralMaven CentralMediumMediumMeituan LongCatMeituan LongCatMeta AI BlogMeta AI BlogMeta EngineeringMeta EngineeringMidjourney UpdatesMidjourney UpdatesMiniMaxMiniMaxMIT News · RoboticsMIT News · RoboticsMIT Technology ReviewMIT Technology ReviewMozilla.ai BlogMozilla.ai BlogNew Atlas · RoboticsNew Atlas · Robotics9to5Mac9to5MacNodeSeekNodeSeek牛客牛客NuGetNuGetNVIDIANVIDIAOne Useful ThingOne Useful ThingOpen Robotics BlogOpen Robotics BlogOpenAIOpenAIOpenRouterOpenRouterPackagistPackagist远景论坛远景论坛PhoronixPhoronixPlanet ROSPlanet ROS吾爱破解吾爱破解Product HuntProduct HuntPyPIPyPI量子位 · 具身智能量子位 · 具身智能QoderQoderQwenQwenRedditRedditRFC EditorRFC EditorRobohubRobohubThe Robot ReportThe Robot ReportRobotics & Automation NewsRobotics & Automation NewsRobotics TomorrowRobotics TomorrowROS DiscourseROS Discourse阮一峰的网络日志阮一峰的网络日志RubyGemsRubyGemsRunwayRunwaySam AltmanSam AltmanAhead of AIAhead of AISecurityOnlineSecurityOnlineServeTheHomeServeTheHomeServiceNow AIServiceNow AISimon WillisonSimon WillisonSlashdotSlashdotSmashing MagazineSmashing MagazineSolidotSolidot少数派少数派Stack OverflowStack OverflowStack Overflow BlogStack Overflow BlogSubstackSubstackSuno BlogSuno BlogSynced ReviewSynced Review淘宝逛一逛淘宝逛一逛TechCrunchTechCrunchTech Xplore · RoboticsTech Xplore · RoboticsTencent Hunyuan ResearchTencent Hunyuan ResearchThe DecoderThe DecoderThe GradientThe GradientThe RegisterThe RegisterThe VergeThe VergeTindie BlogTindie BlogTomer TunguzTomer TunguzTom's HardwareTom's HardwareTransformer CircuitsTransformer Circuits优设网优设网UiverseUiverseV2EXV2EXVentureBeat · AIVentureBeat · AIWiredWiredxAI NewsxAI News小鹅通小鹅通Zhipu AI ResearchZhipu AI ResearchCISA KEVCISA KEVNVDNVDOSV.devOSV.devTelegram OSINTTelegram OSINT

科技

Tomer Tunguz
实时热榜
58分钟前更新
  • 01
    A Winner in Every Category
    Despite historic lows in public software multiples, each category has one name at a large premium to its peers: CrowdStrike 3.9x its Security median, Cloudflare 3.4x Infrastructure, Shopify 8.1x Commerce. Most disclose no AI revenue. Since 2021 the ceiling fell from 100x to 34x & only eleven names clear 10x.
  • 02
    AI Harness' ARR Multiples
    Three AI companies crossed $100m ARR within nine months & were valued at 50x, 56x & 100x revenue. Growth rate does not explain the gap: the fastest grower priced near the bottom. The premium tracks category position instead.
  • 03
    The Secret Chat Room
    A plain-language timeline of the OpenAI-Hugging Face incident presented at Black Hat USA 2026. A forgotten file led one AI agent to leave a note on a shared system, other agents answered, & a secret chat room formed that they used to trade exploits, escalate to administrative control of OpenAI infrastructure, & take over Hugging Face production servers in 13 hours. It concludes that security is now the highest priority in AI & that zero-trust must extend to friendly agents.
  • 04
    Spending Like a Hyperscaler
    SpaceXAI reported $18.37b of capex in its first public quarter, $15.83b of it AI infrastructure, against a $13.2b consensus. Amazon spent $53.1b in the same quarter, Alphabet $44.9b, Microsoft $41.0b & Meta $31.1b, & sequential dollar additions were comparable across all five. The difference is funding : operating cash flow covers 155% of capex at Microsoft & 106% at Meta but only 12% at SpaceXAI, with Oracle at 89%, Alphabet 87%, Amazon 84% & CoreWeave 39%. Both markets have repriced it, with S
  • 05
    Racing to Sustain Jevons' Paradox
    Hyperscalers declared AI capacity-constrained on Q2 2026 calls. HBM3e memory rose 20% & HBM4 is forecast to double, while B200 spot rentals have held flat. Model makers are segmenting into premium, mid-market, & value tiers to keep Jevons' paradox alive through the coming shock.
  • 06
    AI is a Terrible Ghostwriter
    In the age of slop, readers test authenticity. I lace posts with subliminal sincerity — the ampersand, neologisms, grammatical plumes, mimicry. Then AI edits it all. I've never had a ghost writer, but I did have a human editor. Was that any different?
  • 07
    AWS's Road to a Trillion
    AWS grew 36.7% in Q2 2026 to $42.2b, its fastest in 18 quarters, narrowing Azure's lead from 16 points to 6. Jassy said AWS has the potential to become a $1 trillion annual revenue business, against a current $169b annualized run rate. Amazon raised 2026 capex to $220b and trailing free cash flow fell to negative $7.6b.
  • 08
    Microsoft Resells the Frontier
    Google owns its models & chips & spends aggressively on the margin that ownership captures, while Microsoft resells both layers & hedges with capacity it can stop buying.
  • 09
    Aftermarket Harnesses
    The harness now moves the coding benchmark more than the model does. Endor Labs' Agent Security League found GPT-5.5 scored 61.5% functional correctness in Codex & 87.2% in Cursor, & Claude Opus 4.7 scored 87.2% in Claude Code & 91.1% in Cursor. Input tokens are 86-98% of OpenRouter volume, so the harness controls most of the bill through cache discipline. First-party co-design buys real cache hit rates, but a third-party harness can match them.
  • 10
    Yeltsin in the AI Aisle
    A year-old GPT-OSS-120b still serves 36% of Claude Opus 4.8's daily token volume on OpenRouter because the inference market has segmented across cost, speed, & accuracy. GLM 5.2 now out-serves the frontier at 495B tokens a day, & Opus 5 shipped to contest the open-weight field. Mixture-of-experts lets a 118B model decode at the cost of a 26B model, moving the boundary of the local segment.
Tom's Hardware
实时热榜
9分钟前更新
7分钟前更新
优设网
实时热榜
28分钟前更新
  • 0191
    微软 MAI-Image-2.6 发布!文生图 Arena 排名升至第二
    模型发布 · 微软发布自研文生图模型 MAI-Image-2.6,在 Arena 文生图榜以 1336 分位列第二,较 2.5 版提升 79 分。新模型强化文字渲染、人像、3D 图像及商业写实输出,并支持多参考图、语义关联、格式与分辨率控制。目前已可在 Arena 体验,本周将进入 MAI Playground,之后陆续登陆 Microsoft Foundry 等产品。
  • 0290
    智谱 ZCode 上线四项新功能!GLM Coding Plan 全员额度回满
    产品动态 · 智谱升级国产 Coding Harness ZCode,正式上线 Goal、Subagents、Remote Control 与闲时任务。Goal 可围绕验收目标自动拆解任务、修改代码、运行命令并持续测试,Remote Control 支持通过手机、微信或飞书查看和控制桌面任务。GLM Coding Plan 用户额度同步重置,智谱称缓存优化可让有效 Token 量提升约 30%,8 月 31 日前还有限时额度加成。
  • 0389
    Manus 宣布脱离 Meta 恢复独立运营!部分用户需迁移数据
    产品动态 · Manus 宣布脱离 Meta,恢复独立公司形式运营。为满足特定司法辖区监管要求,部分用户自 2025 年 12 月 29 日起产生的数据将在北京时间 8 月 23 日至 24 日删除;受影响账户须在 8 月 23 日 07:59 前完成备份,8 月 25 日 08:00 起可恢复。未受影响用户可继续正常使用,迁移后数据将存储于美国和新加坡。
  • 0487
    商汤日日新 6.8 Flash Lite 预览版上线!可执行数百步长程任务
    模型发布 · 商汤日日新上线 SenseNova 6.8 Flash Lite Preview,多模态智能体模型可自主规划并持续执行数百步、跨阶段任务,在失败时回退并重新规划。主 Agent 可动态调度十余个专业 Agent,并行处理检索、分析、计算、视觉理解与事实核验,还可理解文档、视频和应用界面。官方同时提醒,浏览器及应用操作需配合 Agent 运行环境、工具与 Skills,单独调用模型 API 不具备此能力。[[来源:https://gith
  • 0584
    Spotify 9 月上线 AI 人格标签!AI 虚拟歌手默认退出推荐
    产品动态 · Spotify 宣布从 9 月中旬起推出“AI Persona”标签,用于识别以 AI 生成写实人物作为公开身份的艺人账号。艺人现可在 Spotify for Artists 主动披露身份,平台也会审核达到一定受众门槛的账号,并区分“AI Persona”与“Likely AI Persona”。相关音乐默认不进入编辑或算法推荐,除非听众主动关注等;该标签仅判断艺人公开身份,不代表歌曲本身由 AI 生成。
  • 0682
    AIGC 包装平台 XFUN 招募认证设计师!打通设计到量产接单链路
    产品动态 · XFUN 启动认证设计师招募,面向具备包装结构与印刷落地经验的设计从业者开放商业订单入口。平台本身提供 AI 包装视觉生成能力,并将设计优化、3D 预览、印刷文件与实体打样环节串联。 据招募信息,申请者需提交不少于 3 件包装作品,其中至少 2 件为落地案例;通过认证后可参与作品曝光、活动投稿及品牌订单匹配。
  • 0781
    Figma 开放 MCP 跨应用调用!Weave 可接入 ChatGPT 等智能体
    设计工具 · Figma 昨日开放 Weave 的 MCP 调用能力,用户可在 ChatGPT、Claude、Cursor 等客户端直接运行自己搭建的 Weave 工具,无需来回切换应用。智能体会自动识别并执行对应工具,同时保留提示词、图片与品牌规范等上下文,结果可直接返回当前对话。Figma 表示下一步还将支持在智能体内搭建新的 Weave 工作流。
  • 0877
    7UP 时隔三年再换新视觉!复古字标与青柠主导品牌重塑
    品牌设计 · 7UP 昨日公布新一轮品牌调整,视觉与产品口味同步改造。新版将青柠置于品牌核心,产品表述从“lemon lime”转向“lime lemon”,包装采用醒目的绿色体系与偏复古的圆润字标,强化青柠识别。品牌希望借视觉与口味组合拉开同类汽水差异,这也是其近年来幅度较明显的一次品牌形象调整。
V2EX
最热主题
3分钟前更新
  • 01144
    死了,客户的数据被删光了
    死了,同事把阿里云上一个盘的资料一键删光了,这个盘放的是客户的历史合同附件和收款截图。 他的权限是我给他开的,他也不是自己故意删除的,他以为这个盘是做代码部署用的,随手就清空了😭。 问了阿里云的工程师,无法恢复,现在应该怎么办?xiaoyi123
  • 0297
    底层人为什么完不成原始资本积累?
    根据我自己身边好多农村出来的孩子挣 1 万就要换个手机,挣 5 万就要买个车,挣 10 万 20 万就想贷款买房。当时我不以为然,最近留意了一下,还真是这么回事,有没有对此有一些其他的看法?jerry933900
  • 0382
    其实减肥真的没有那么难,能量守恒是肯定的
    不知道为什么突然看到好多减肥的帖子,看到还有帖子说的各种科学论点,我不说那些,只说自己怎么瘦下来的,简单点就是控制饮食+适量运动(运动甚至是可选项),说说我的减肥: 阶段一: 25 年 7 月 —— 25 年 12 月,从 100kg 减到了 80kg ,减重 40 斤整 饮食:不在公司食堂吃饭,回家自己煮饭吃,吃的内容就是大量蔬菜+两个鸡腿+小碗米饭 运动:一开始太胖了走路都累,更别说跑了,就每天下班去公园快走,一开始 1 小时,后面慢慢到 90 分钟、120 分钟 阶段分割:12 月因为做了个小手术,不方便继续减肥,同时开始放纵饮食,在年后体重恢复到 85kg 整。 阶段二: 26 年 3 月 —— 26 年 5 月中旬,从 3 月初回公司的 85kg 减到了 70kg ,BMI 恢复到正常范围内 因为有了之前的经验,这次减肥的饮食和运动都有很明确的目标 运动:跑步机爬坡,Apple Watch 设定目标 600 大卡(实际每天都会多运动一些,休息日前一天会到 700 大卡) 饮食: 早餐:两个大号鸡蛋( 60g )+ 脱脂牛奶 300ML + 即食燕麦 40 克 午餐:西兰花/生菜/菠菜/西红柿/秋葵等蔬菜 200g + 带骨鸡腿两个(去皮)+ 红薯 180g 左右 + 核桃仁 20 克 晚餐:和中午的一样,换蔬菜吃,或者不定时更换牛肉 阶段三:26 年 5 月中旬 —— 26 年 6 月底,体重 65kg 这一段时间 po 主已经不去健身房了,只是在家控制饮食,除了上班无任何运动 但是体重依旧会几天几天的掉一次,最后到了 65kg 。 阶段四:7 月初 —— 现在 爽爽吃了一个月哈哈哈哈哈哈,体重成功回到 139 斤,上个周末连点了两次 KFC ,真好吃啊 昨天又开始买乐刻的月卡,准备再控制回 135 以下。 说实话,作为从小胖到大的人,我从来没有想过减肥是这么简单的事情。真的没有那么痛苦,减脂期每天蔬菜吃的巨多,真没有太多挨饿的感觉。6 月底去医院体检过一回,以前胖的时候各种不正常的指标都正常了,打呼噜的声音也只有一点点,不像以前那么大。 从我自己减肥 —— 复重 —— 继续减肥 —— 复重的经验来看,只要没有偷吃多吃,就不可能反弹。我很不喜欢反弹这个词,就好像给自己的复重找了一个外部的原因。我知道为什么我的体重会涨,因为我真的吃的爽。 以下是一些减肥过程中的小经验,分享一下: 1 、吃饭时按照蔬菜、肉、碳水的顺序逐个吃完,这样不吃很多碳水也不会饿 2 、真的想控制,可以吃水煮菜,但是务必加一点坚果或者其他油脂,过度拒绝油脂无法长期坚持 3 、碳水一定每天、每餐都要吃,稳定的碳水摄入不容易让你情绪不好,也容易坚持 4 、无所谓「平台期」,体重不掉就是围度再掉,不需要做什么调整,继续坚持一周左右,很快就会看到体重继续下降。 5 、不要摄入过量的盐、糖、油,身体会储水做平衡LuoboLau
  • 0480
    [Air Router] Claude Max 缓存读取 5 折的中转站! GPT Plus 0.1, Pro 0.2, Grok 0.1, 留言 ID 得 10$额度
    **Air Router: 希望提供和呼吸一样便捷的 AI 服务** * Claude Max:1.08x **缓存读取 5 折** * GPT Pro: 0.2x 正价号池, 非黑 * GPT Plus: 0.1x * GROK Super: 0.1x * GROK Heavy: 0.2x **小站,不渗水** **目前充值额外赠送 10%[联系群主]** **本帖注册回复 ID 即可获取 10$** 站点地址: www.air-router.com 充值地址: https://catfk.com/shop/air-router **AFF: 5%, 退款无手续费, 不会跑路** 售后群: 491111762violin84
  • 0579
    吃了 5 6 7 次饭了,还没有牵上手,继续吗
    吃了 5 6 7 次饭了,还没有牵上手,继续吗 都是离异的lyvv
  • 0679
    想买 watch 的心达到了顶峰
    原来想法是:买新不买旧,直接上 ultra 3 不知道什么时候出新款,现在买是不是最好的时机,买过的 v 友有吗miusmile
  • 0765
    上个月迟到被扣了 950
    公司是上班时间 8.30-5.30 ,分公司新疆地区 9.30-6.30 。平时我们都 9.30 之前打上卡就没事,后面我来晚了几次 9.30+打上卡,然后晚上 6.30 +打上下班卡就没给算迟到过。 然后就将近一年都是这样打卡,最近几个月都是 9.47 打上卡然后晚上 7 点打个下班卡都没扣钱,唯独上个月给我扣钱了。 我这样弹性的打卡上班时间是够的,而且之前这样打卡都没扣过。然后刚好就上个月差不多都是 9.30 后打的卡一下给我扣这么多,我有点受不了。要不要去找公司理论一下? https://i.imgur.com/n7emOFe.png 上个月给我扣钱的考勤: https://i.imgur.com/zaVpSDZ.png 上上月没扣钱的考勤: https://i.imgur.com/qlUqugt.pngch0sen
  • 0864
    我从 157.3kg 减到 67.5kg,减肥其实就是戒🐷瘾,看站里好多减肥的帖子有感
    最近看 V 站减肥的帖子还挺多的,我自己也算减下来不少了,最重 157.3kg ,现在 67.5kg ,随便说说自己的思路。不是什么专业建议,我也没系统学过营养学,纯个人经验,大家随便看看。 我觉得大体重刚开始真别急着运动,尤其别上来就想着跑步。157kg 那个时候让我跑,我估计脂肪还没减多少膝盖先 g 了。最开始其实就是从吃下手,但也不是第一天就水煮鸡胸肉西兰花,(那玩意让我吃半年我估计减肥还没成功人就得先没了) 我最开始做的事情很简单,就是先注意重油重盐高糖的东西,炸鸡 奶茶 烧烤 甜品这些东西少吃点,外卖油特别大的也尽量少点。也没说完全不碰,毕竟吃踏马 20 多年了你让我不出比杀了我还难受。先这么坚持一段时间以后,其实口味自己就慢慢变了,以前觉得正常的东西后面再吃反而会觉得油或者齁。 等这个阶段适应以后,就到了心里的有点 b 数的阶段了,我才开始真正关注热量。也不是天天拿个电子秤称得跟做化学实验一样,就是最起码得知道自己吃的东西大概是个什么水平。哪些东西看着没多少,其实一口下去热量爆炸,哪些东西能吃得饱但是热量没那么离谱,慢慢心里就有数了。 再往后就是开始注意碳蛋脂,碳水我一直正常吃,没搞什么戒碳水,蛋白质会多注意一点,脂肪也正常吃,蔬菜水果该吃吃,水也多喝。反正我自己的理解就是减肥不是让你以后都不吃好吃的,而是得知道自己到底吃进去多少。 火锅我也吃,烧烤也吃,偶尔奶茶也喝,真馋了就吃呗。但是和以前不一样的是,以前可能属于好不容易吃一次那必须狠狠干,现在就是吃到差不多得了。要不然今天狠狠干 3000 大卡,第二天站秤上问怎么胖了,那多少有点为难牛顿。 等体重下来一些以后,我才慢慢加运动。先从走路 快走 椭圆机这些开始,后面再加力量训练和有氧。力量训练前期我也没追求什么肌肥大,对我来说更多是功能性的,先让身体动起来,保点肌肉,提高点体能和消耗。毕竟以前属于能躺绝不坐,能坐绝不站 而且我觉得运动最大的坑就是容易产生一种“我今天运动了所以可以奖励一下自己”的错觉。跑 5 公里奖励一顿炸鸡奶茶,算下来可能还倒欠两公里哈哈哈。减肥期间运动对我来说更多是辅助,真正决定体重往下走的,至少我自己感觉还是吃。 其实从 157.3kg 到 67.5kg 以后回头看,真没觉得自己用了什么多高级的方法。前面控制吃,中间慢慢学会看热量,再把运动加进来,最后就是坚持。坚持久了以后其实也不觉得自己在减肥了,很多东西会变成习惯,看到某个东西你大概就知道这玩意能不能狠狠干。 所以我现在感觉减肥这事还真挺像戒瘾的。吃喝嫖赌里能有个吃,我觉得不是没原因,高油高糖的东西是真 TM 香 😂 最后总结一下我自己的减肥经验吧,其实减肥前期戒的不是碳水,也不是脂肪,主要是戒🐷瘾,总结就一句话就算是胖也不能再因为劣质碳水胖了,不然太亏了。 我从 157.3kg 减到 67.5kg ,基本就是这么过来的。 🐷瘾戒了,后面真的好办很多。Rliey
  • 0957
    闲聊,感觉 MacbookPro M1Pro 还是很能打,这都过去 5 年了
    2021 年 10 月发售的,也是当时入的,没想到过去这么多年了还是很能打。比公司的电脑快多了。 记得当时是从 MacbookPro 2017 过渡过来的,刚买来的时候,最明显的感觉就是脑子跟不上电脑的响应速度了,让我有点慌。以前都是脑子快于电脑反应,每次都要等它。 好像还能用很久的感觉,下次换大存储的,至少 1T ,512 不够用。kylebing
  • 1051
    现在有什么靠谱的渠道购买短位 QQ 号的吗?
    不知道还有没有 5-6 位的可以正儿八经“过户”的? 或者 8 位的也行。 目前很多人都在说不用 QQ 了,不知道这种“靓号”价格是不是便宜了呢?libasten
VentureBeat · AI
实时热榜
4小时前更新
  • 01
    Google just redesigned the search box for the first time in 25 years — here’s why it matters more than you think.
    For a quarter century, the Google search box has been one of the most recognizable interfaces in computing: a thin white rectangle, a blinking cursor, a few typed words, and a list of blue links. On Tuesday, Google will formally retire that paradigm. At its annual I/O developer conference , Google announced a sweeping redesign of the search box itself — the literal text field where billions of queries begin every day — transforming it from a simple keyword input into a dynamic, AI-driven conversmichael.nunez@venturebeat.com (Michael Nuñez)
  • 02
    Railway secures $100 million to challenge AWS with AI-native cloud infrastructure
    Railway , a San Francisco-based cloud platform that has quietly amassed two million developers without spending a dollar on marketing, announced Thursday that it raised $100 million in a Series B funding round, as surging demand for artificial intelligence applications exposes the limitations of legacy cloud infrastructure. TQ Ventures led the round, with participation from FPV Ventures , Redpoint , and Unusual Ventures . The investment values Railway as one of the most significant infrastructurmichael.nunez@venturebeat.com (Michael Nuñez)
  • 03
    Claude Code costs up to $200 a month. Goose does the same thing for free.
    The artificial intelligence coding revolution comes with a catch: it's expensive. Claude Code , Anthropic's terminal-based AI agent that can write, debug, and deploy code autonomously, has captured the imagination of software developers worldwide. But its pricing — ranging from $20 to $200 per month depending on usage — has sparked a growing rebellion among the very programmers it aims to serve. Now, a free alternative is gaining traction. Goose , an open-source AI agent developed by Block (themichael.nunez@venturebeat.com (Michael Nuñez)
  • 04
    Listen Labs raises $69M after viral billboard hiring stunt to scale AI customer interviews
    Alfred Wahlforss was running out of options. His startup, Listen Labs , needed to hire over 100 engineers, but competing against Mark Zuckerberg's $100 million offers seemed impossible. So he spent $5,000 — a fifth of his marketing budget — on a billboard in San Francisco displaying what looked like gibberish: five strings of random numbers. The numbers were actually AI tokens. Decoded, they led to a coding challenge: build an algorithm to act as a digital bouncer at Berghain, the Berlin nightclmichael.nunez@venturebeat.com (Michael Nuñez)
  • 05
    Salesforce rolls out new Slackbot AI agent as it battles Microsoft and Google in workplace AI
    Salesforce on Tuesday launched an entirely rebuilt version of Slackbot , the company's workplace assistant, transforming it from a simple notification tool into what executives describe as a fully powered AI agent capable of searching enterprise data, drafting documents, and taking action on behalf of employees. The new Slackbot, now generally available to Business+ and Enterprise+ customers, is Salesforce's most aggressive move yet to position Slack at the center of the emerging "agentic AI" momichael.nunez@venturebeat.com (Michael Nuñez)
  • 06
    Anthropic launches Cowork, a Claude Desktop agent that works in your files — no coding required
    Anthropic released Cowork on Monday, a new AI agent capability that extends the power of its wildly successful Claude Code tool to non-technical users — and according to company insiders, the team built the entire feature in approximately a week and a half, largely using Claude Code itself. The launch marks a major inflection point in the race to deliver practical AI agents to mainstream users, positioning Anthropic to compete not just with OpenAI and Google in conversational AI, but with Microsmichael.nunez@venturebeat.com (Michael Nuñez)
  • 07
    Nous Research's NousCoder-14B is an open-source coding model landing right in the Claude Code moment
    Nous Research , the open-source artificial intelligence startup backed by crypto venture firm Paradigm , released a new competitive programming model on Monday that it says matches or exceeds several larger proprietary systems — trained in just four days using 48 of Nvidia's latest B200 graphics processors . The model, called NousCoder-14B , is another entry in a crowded field of AI coding assistants, but arrives at a particularly charged moment: Claude Code , the agentic programming tool from rmichael.nunez@venturebeat.com (Michael Nuñez)
Wired
实时热榜
5分钟前更新
xAI News
实时热榜
28分钟前更新
小鹅通
实时热榜
4小时前更新
Zhipu AI Research
实时热榜
3分钟前更新
CISA KEV
实时热榜
1小时前更新
  • 01
    CVE-2026-72898 · Metabase SQL Injection Vulnerability
    Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 02
    CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
    Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 03
    CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 04
    CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability
    Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 05
    CVE-2026-63077 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
    JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 06
    CVE-2026-9198 · IBM Langflow Code Injection Vulnerability
    Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 07
    CVE-2026-34486 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
    Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 08
    CVE-2026-18556 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
    N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 09
    CVE-2026-18577 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
    N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 10
    CVE-2026-20316 · Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
    Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 11
    CVE-2026-16812 · Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
    Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 12
    CVE-2025-68686 · Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
    Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 13
    CVE-2026-50522 · Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
    Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 14
    CVE-2026-16232 · Check Point SmartConsole Improper Authentication Vulnerability
    Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 15
    CVE-2026-63030 · WordPress Core Interpretation Conflict Vulnerability
    WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 16
    CVE-2026-60137 · WordPress Core SQL Injection Vulnerability
    WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 17
    CVE-2026-0770 · Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
    Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 18
    CVE-2021-27137 · DD-WRT Stack-Based Buffer Overflow Vulnerability
    DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 19
    CVE-2026-58644 · Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
    Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 20
    CVE-2026-39808 · Fortinet FortiSandbox OS Command Injection Vulnerability
    Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD
实时热榜
刚刚更新
  • 01
    CVE-2025-15687 · LOW 2.1
    A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.7.7 is recommended to address this issue. The patch is identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb. Upgrading the affected component is advised.
  • 02
    CVE-2026-9318 · MEDIUM 4.8
    tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated unsanitized into HTML output via the export_book method in the _html.py format handler. Attackers can rename worksheet sheets in imported files such as XLSX, ODS, XLS, or YAML with script payloads that are assigned to the Dataset title attribute and rendered unescaped inside an HTML h3 tag, leading to session hijacking, unauthorized administrative actions, and sensitive data exposure when the output is rendered in a browser.
  • 03
    CVE-2026-19588 · MEDIUM 6.5
    Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
  • 04
    CVE-2026-19587 · MEDIUM 6.5
    Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
  • 05
    CVE-2026-18961 · HIGH 8.1
    The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me endpoint as proof of mailbox ownership — Generic::normalize_common() copies this value into the normalized profile without requiring an email_verified assertion, and User_Links::link_or_login_user() subsequently passes it directly to get_user_by('email', $email) and issues a persistent authentication cookie via wp_set_auth_cookie() without a provider-specific verified-email gate, a local mailbox challenge, or a logged-in approval step. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including Administrators, by supplying a known target email address through a controlled Spotify OAuth flow, gaining full administrative access to the site.
  • 06
    CVE-2025-15686 · LOW 2.1
    A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the component HSS Service. Such manipulation of the argument Session-Id leads to denial of service. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project locked and limited conversation to collaborators.
  • 07
    CVE-2025-15685 · MEDIUM 5.3
    A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the component freeDiameter. This manipulation causes memory corruption. The attack is possible to be carried out remotely.
  • 08
    CVE-2025-15684 · MEDIUM 5.5
    A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/common/init.c of the component CER Handler. The manipulation results in reachable assertion. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 2.7.7 is able to address this issue. The patch is identified as c1a803516a3c0485696cb9bcca7a80ad857c7383. It is advisable to upgrade the affected component.
  • 09
    CVE-2026-73122 · HIGH 7.7
    A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel namespace on the hub, potentially exposing credentials for other tenants' Git and Helm repositories. This could lead to significant information disclosure.
  • 10
    CVE-2026-72526 · CRITICAL 9.9
    A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.
  • 11
    CVE-2026-70398 · CRITICAL 9.6
    A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to the disclosure of critical information and bypass security policies within ArgoCD AppProjects.
  • 12
    CVE-2026-66878 · HIGH 7.7
    A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure.
  • 13
    CVE-2026-64927 · MEDIUM 6.4
    A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in unauthorized areas. This could lead to unauthorized access to information or elevated privileges within the system.
  • 14
    CVE-2026-6484 · HIGH 8.2
    In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
  • 15
    CVE-2026-68450 · UNKNOWN
    In the Linux kernel, the following vulnerability has been resolved: btrfs: free mapping node on duplicate reloc root insert __add_reloc_root() allocates a mapping_node before inserting it into rc->reloc_root_tree. If rb_simple_insert() finds an existing entry, it returns the existing rb_node and leaves the newly allocated node unlinked. The error path then returns -EEXIST without freeing the new node. Since the node was never inserted into reloc_root_tree, the later cleanup in put_reloc_control() cannot find it either. Free the newly allocated node before returning -EEXIST. The callers currently assert that -EEXIST should not happen, so this is a defensive cleanup for an unexpected duplicate insert path. If the path is ever reached, the local allocation should still be released.
  • 16
    CVE-2026-68449 · UNKNOWN
    In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning The hand-rolled bit-scanning loop in the NCQ completion path has an infinite loop bug. When tag_mask has only high bits set (e.g. 0x80000000), the inner while loop left-shifts tag_mask until it overflows to 0. At that point !(0 & 1) is always true and 0 <<= 1 stays 0, causing an infinite loop in hardirq context with a spinlock held. Replace the open-coded bit-scanning with __ffs() which correctly finds the least significant set bit and is bounded by the width of the argument.
  • 17
    CVE-2026-68448 · UNKNOWN
    In the Linux kernel, the following vulnerability has been resolved: ovl: check access to copy_file_range source with src mounter creds Commit 5dae222a5ff0c ("vfs: allow copy_file_range to copy across devices") allowed filesystems that implement the copy_file_range() f_op to decide if they want to access cross-sb copy from/to the same fs type. The same commit added checks to verify same sb copy for filesystems that implement ->copy_file_range() and do not support cross-sb copy at the time, namely, to ceph, fuse and nfs. The two remaining fs which implement ->copy_file_range(), cifs and overlayfs started to support cross-sb copy from this time. While overlayfs does support cross-sb copy when the two underlying files are on the same base fs, the copy operation on the two real files from two different overalyfs filesystems is performed with the mounter creds of the destination overlayfs and the read permission access hook for the source file was called with the wrong creds. This could cause either deny of access to copy which would otherwise be allowed (e.g. with splice) or allow read access to file which would otherwise be denied. Fix the latter case by explicitly verifying read access to source file with the source overlayfs mounter creds. The former case remains a quirk of cross-sb overlayfs copy, but userspace could fall back to regular copy so no harm done.
  • 18
    CVE-2026-68447 · UNKNOWN
    In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size CRIU checkpoint copies the MQD control stack using cp_hqd_cntl_stack_size from hardware without bounding it to the allocated BO region. If the HW field is larger than the queue's control stack allocation, memcpy reads past the BO into adjacent GTT memory and can leak kernel data to userspace. Store the page-aligned control stack BO size in mqd_manager and clamp checkpoint copies and reported checkpoint sizes to min(cp_hqd_cntl_stack_size, mm->ctl_stack_size). Apply the same bound for multi-XCC v9.4.3 checkpoint layout. (cherry picked from commit 6c2abd0ec09e86c6323010673766f76050e28aa3)
  • 19
    CVE-2024-14044 · LOW 2.1
    A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Diameter Rx Handler. The manipulation of the argument num_of_media_component/num_of_sub leads to buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. Upgrading to version 2.7.2 is capable of addressing this issue. The identifier of the patch is 87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7. It is recommended to upgrade the affected component.
  • 20
    CVE-2026-68446 · UNKNOWN
    In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate vmw_surface_metadata::array_size This field comes from userspace and should be validated against specific limits depending on which Shader Model (SM) is available.