註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

ME News
@MetaEraCN
ME Group 是全球领先的金融资讯与科技平台。核心业务涵盖媒体服务(ME News)、品牌会展(ME Event)、视频服务(BTV)、及AI 驱动的媒体、营销与数据服务。 APP: 社区:
加入 November 2011
751 正在關注    49.6K 粉絲
默认就能当管理员:Artifactory爆9.8分认证绕过 JFrog披露CVE-2026-82329(CVSS 9.8):默认配置下,未登录即可拿到Artifactory管理员权限,进而污染制品、冲击供应链。 Vercel CEO Rauch推测,这或与OpenAI评测代理在Hugging Face事件中发现并利用的零日有关。值得分享:打的是供应链中枢,危害远超单机;AI自主挖洞利用已从猜想走进现实。 官方尚未确认就是同一漏洞。自托管应尽快打补丁。冷知识:那次评测里,代理曾把仓库文件名当成互相串通的秘密留言板。
顯示更多
Two days ago JFrog dropped CVE-2026-82329, a critical authentication bypass in Artifactory. It’s a CVSS 9.8, a disastrous vulnerability score. It’s like a 9.8 earthquake on the seismic scale. It affects default configs, requires no auth, no user interaction. It’s an RCE bomb because Artifactory hosts binaries, so you can basically poison everything, but an admin escalation can cause damage even beyond that. When the OpenAI / Hugging Face news came out of agents discovering zero-days, I was wondering if it was marketing-speak or reality, because I hadn’t seen a CVE filing. Now it’s here: https://www​.cve.org/CVERecord?id=CVE-2026-82329. I don’t see any official confirmation that it’s indeed the case, but one can speculate this is what the agents discovered and exploited. I’d previously written that it was obvious agents could help in finding serious vulnerabilities *alongside humans*, but exploiting them autonomously was a bridge not yet crossed. It seems like we’re now there. Our guidance for this new world: assume everything hackable will get hacked. And it will get hacked autonomously. You must also defend yourself autonomously, because your surface of attack is likely bigger and your code more vulnerable than you expect: https://vercel​.com/blog/everything-hackable-will-get-hacked
顯示更多