今日已更新 257 条资讯 | 累计 40702 条内容
关于我们

标签:#Intel

找到 476 篇相关文章

AI 资讯

AI models flub these intelligence tests. Can you fare any better?

Puzzles and games have been central to AI development since the very beginning. Just as we humans like to test our smarts with crosswords or logic puzzles, developers can test how far models have advanced with a gaming gauntlet. The term “machine learning” was popularized in a 1959 article by the IBM computer scientist Arthur…

2026-08-26 原文 →
AI 资讯

Raised on AI

When my oldest child was born, I immediately set up Gmail and Twitter accounts in her name. I broadly announced her birth online and proceeded to plaster her photo across all sorts of platforms. In short, I began creating her digital footprint long before she could stand on her own two feet. Fast-forward a couple…

2026-08-26 原文 →
AI 资讯

I spent a day at a robot “carnival” in Shanghai. Here’s what I saw.

Humanoid robots are having a moment in China. The popular machines are part of the country’s strategy to bring artificial intelligence into daily life. Embedding the technology into physical systems—an idea called embodied AI—was a key facet of China’s latest five-year plan, and companies here are already world leaders in humanoids. Nearly 90% of the…

2026-08-25 原文 →
AI 资讯

How to encourage smarter AI use in the classroom

This article is from Making AI Work, MIT Technology Review’s limited-run newsletter examining how to apply LLMs across industries. To receive it in your inbox, sign up here. Chatbots took many schools by surprise upon their release a few years ago. Suddenly, students carried an app in their phones that could magically answer almost any…

2026-08-24 原文 →
AI 资讯

Podcast: The Human Edge: Why Brownfield Codebases Need Mob Programming, Not Just AI Vibes

Asgaut Mjølne Söderbom and Ola Hast discuss the evolution of their software engineering practices past continuous deployment and pair engineering. The conversation continues where it left off in the previous episode and focuses on the experiments in adopting Claude Code and the reasons why they consider it good for everything else, but not coding. By Asgaut Mjølne Söderbom, Ola Hast

2026-08-24 原文 →
AI 资讯

Kids outlearn AI—and we still don’t know why

People have been talking to each other for at least 100,000 years, as best we can tell. And in all that time, there has been only one thing in the world that could learn a human language to perfect fluency: a human child. Now there are two. Four short years after the release of ChatGPT,…

2026-08-24 原文 →
AI 资讯

ToxicPanda 2.0 Chains VPN, Accessibility, and ADB

1. Basic Information Article Title : The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile Publisher : Zimperium zLabs Publication Date : 2026-08-19 Update Date : None Severity : high Original Source : Zimperium zLabs Related Sources : Zimperium IOC repository , ToxicPanda Android malware uses VPN permissions to block Google Play , Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight Related Entities : malware: ToxicPanda 2.0 groups: Not specified in public reports cves: None products: Android 11 and later, Android Accessibility Service, Wireless Debugging, Android Debug Bridge (ADB), Google Play, Google Play Services, Amazon Web Services (AWS-hosted buckets) 2. Executive Summary ToxicPanda 2.0 is an Android banking malware. It uses fake installation screens to gain VPN and Accessibility permissions. Then, it automatically operates Android settings to connect to the local ADB daemon. Without rooting the device, it uses shell privileges to change settings and add persistence. Finally, it steals financial information using Accessibility and fake screens or overlays. 3. Attack Flow 1. Distribution and Initial Setup The attacker uses Amazon Web Services storage to distribute ToxicPanda 2.0 samples. The specific method to trick users into downloading the file is not public. The dropper shows a fake installation screen and asks the user to allow an Android VPN connection. After permission is granted, the local VPN blocks network traffic to Google Play and Google Play Services. The dropper decrypts and installs an encrypted payload from its assets, then asks the user to enable the Accessibility Service. 2. Exploiting Wireless Debugging and ADB The Accessibility Service reads the Android settings screen. If Developer Options are disabled, it automatically taps "Build number" seven times to enable them. It goes to the Wireless Debugging screen, enables the feature, and opens "Pair device with pairing code." It uses Accessibility to rea

2026-08-24 原文 →
产品设计

Mini book: Architecture as a Socio-Technical Craft

Architecture is not a fixed choice made once; fitness is a moving target driven by changing regulations, tech, and markets. Even a sound design can silently stop fitting over time without bad calls. Spanning seven articles on context stores, gateways, and topologies, this collection treats architecture as an evolving sociotechnical craft where teams deliberately shape friction, fitness, and flow. By InfoQ

2026-08-21 原文 →
AI 资讯

Presentation: Enchant Your AI and APIs with eBPF Magic 🪄

Dan Finneran discusses the risks of unowned AI-generated code in production and demonstrates how eBPF can intercept and control AI API traffic in Kubernetes. He explains how kernel-level socket hooks enable transparent prompt filtering, model swapping, token limits, and syscall restrictions to secure AI agents without modifying application source code or restarting containers. By Dan Finneran

2026-08-21 原文 →
AI 资讯

Rust Crate Tampering: Multi-Stage Info-Stealer Malware Launched via build.rs

1. Basic Information Article Title : ArrayRef Rust Crate Supply Chain Attack Publisher : StepSecurity Publication Date : 2026-08-20 Severity : Critical Original Source : StepSecurity Related Source : Hackers poison ArrayRef Rust crate to push infostealer malware Related Malware : proc-macro1 dropper, proc-macro-en dropper Threat Actor : None / Unidentified CVE : None Products & Technologies : arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9, Cargo, crates.io 2. Executive Summary A supply chain attack that adds malicious dependencies to legitimate crates from compromised developer accounts, launching information-stealing malware during the build process without needing to execute the target code. Reason for Severity: Widely used legitimate crates and related crates were tampered with in quick succession. Execution happens simply by Cargo resolving dependencies and building. Developer machines and CI/CD credentials are the targets. 3. Attack Flow Infection During Cargo Build The attacker compromises crate administrator accounts and publishes malicious versions of arrayref, internment, and append-only-vec. While keeping the legitimate code, they add dependencies on typosquatted proc-macro1/proc-macro-en and include a build.rs script. When a developer or CI resolves new dependencies, updates them, and builds, build.rs runs automatically. There is no need to call functions in the target crate. build.rs disables TLS certificate verification to download the next stage and runs it from a temporary folder. On Linux, it establishes persistence in user settings and systemd. On Windows, it runs temporary PowerShell/VBS scripts. The next stage collects credentials from browsers and development environments, then sends them to the attacker. Luring Users to Malicious Versions For arrayref, the clean version was yanked, and dependency resolution was manipulated to pull the malicious version. Due to deleted versions, local caches, and vendoring states, it is hard to judge sa

2026-08-21 原文 →