2. CVE-2026-46529:Linux PDF 閱讀器(XReader/Evince/Atril)中存在一個已存在 10 年的遠程代碼執行漏洞 CVE-2026-46529: 10-year-old RCE in Linux PDF Viewer (XReader/Evince/Atril) (medeiros.zip)
5. account-center:用於內部服務和知識庫文章的自託管、支持 OIDC 身份驗證的門戶 account-center: Self-hosted, OIDC-authenticated portal for internal services and knowledge base articles (git.sr.ht)
7. 在所有64位整數中,只有17%是由兩個32位整數相乘得到的 Only 17% of all 64-bit Integers are products of two 32-bit integers (lemire.me)
8. Apple corecrypto 形式驗證藍圖 A blueprint for formal verification of Apple corecrypto (security.apple.com)
9. 開源領域的職業倦怠:一個我們可以共同解決的結構性問題 Burnout in Open Source: A Structural Problem We Can Fix Together (opensourcepledge.com)
11. 《Qud洞穴》(2019)中的端到端程序化生成 End-to-End Procedural Generation in Caves of Qud (2019) (www.youtube.com)
17. 巨齒鯊:利用 CI 工作流對大量 GitHub 倉庫植入後門 Megalodon: Mass GitHub Repo Backdooring via CI Workflows (safedep.io)
18. 安全啟動與證書頒發機構輪換——致各發行版的提醒 Secure Boot and CA Rollover - a heads-up for distributions (blog.einval.com)
19. 這個博客在 Ubuntu 16.04 上運行了 10 年。我已將其遷移至 FreeBSD This blog ran on Ubuntu 16.04 for 10 years. I migrated it to FreeBSD (crocidb.com)
21. 《離散事件仿真與分佈式併發控制中的虛擬時間》(1985) Virtual Time for discrete event simulation and distributed concurrency control (1985) (worrydream.com)
23. 美國聯邦貿易委員會(FTC)將要求考克斯傳媒集團支付近100萬美元,以了結其就“主動傾聽”人工智能營銷服務誤導客戶的指控 FTC to Require Cox Media Group to Pay Nearly 1million to Settle Charges They Deceived Customers About “Active Listening” AI-Powered Marketing Service (www.ftc.gov)
24. 即使您已刪除 Google API 密鑰,它們仍會繼續生效,時間之長足以被不法分子利用 Google API keys keep working after you delete them long enough to be exploited (www.aikido.dev)
25. Gnutella:一種比其誕生的世界更長久的協議 Gnutella: A Protocol Outlives the World That Created It (rickcarlino.com)
29. 利用通過 USB/IP 連接 WebUSB 的瀏覽器內 Linux 虛擬機,讓舊掃描儀重獲新生 Reviving old scanners with an in-browser Linux VM bridged to WebUSB over USB/IP (yes-we-scan.app)
30. CVE-2026-47243:Kata Containers 通過 virtiofs 實現從 guest-root 到 host-root 的權限提升 CVE-2026-47243: Kata Containers guest-root to host-root escape via virtiofs (www.openwall.com)
35. 依賴冷卻時間不公平;我們應該改用分階段推出 Dependency cooldowns are unfair; we should use phased rollouts instead (illegalcode.net)
39. Gobee:使用 Go 語言編寫 eBPF 程序,並通過 clang 進行轉譯 Gobee: write eBPF programs in Go, transpiled via clang (github.com)
40. Ursula:面向 HTTP 事件流的、採用“每個核心一個線程”架構的多 Raft 運行時(Rust 實現) Ursula: thread-per-core, multi-Raft Rust runtime for HTTP event streams (github.com)
43. Go 語言中的 L1 指令緩存集衝突、關聯度與代碼對齊 L1 instruction cache set conflicts, associativity, and code alignment in Go (blog.andr2i.com)
46. Python 3.15:那些未被廣泛報道的新特性 Python 3.15: features that didn''t make the headlines (blog.changs.co.uk)
51. [RFC] LLVM 基金會關於支持標準文檔開放獲取的聲明 [RFC] LLVM Foundation statement in favor of open access to standards documents (discourse.llvm.org)
54. 那些咄咄逼人的AI爬蟲,讓運營維基變得有點讓人頭疼 Aggressive AI scrapers are making it kinda suck to run wikis (weirdgloop.org)
55. Waterfox 6.6.13 版本移除了 Startpage 作為默認搜索提供商 Waterfox Release 6.6.13 removes Startpage as default search provider (www.waterfox.com)
58. OpenAI的一個模型推翻了離散幾何學中的一項核心猜想 An OpenAI model has disproved a central conjecture in discrete geometry (openai.com)
63. Chromium在4年後發佈了針對該漏洞的修復補丁,結果發現該漏洞實際上並未得到修復 Chromium publishes fixed exploit 4 years later, turns out it''s actually unfixed (infosec.exchange)
64. 圍繞用戶修改智能電視軟件權利的多年之爭即將進入庭審階段 Yearslong fight over users'' right to tweak smart TV software heads to trial (arstechnica.com)
65. XSS 對密鑰而言致命:認證機制的隱性風險 XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None (scotthelme.co.uk)
66. Linux 內核中 __ptrace_may_access() 函數的邏輯漏洞 (CVE-2026-46333) Logic bug in the Linux kernel''s __ptrace_may_access() function (CVE-2026-46333) (cdn2.qualys.com)
68. glibc 的 malloc 中如何實現跨線程雙重釋放檢測 How cross-thread double free detection could work in glibc malloc (kallus.org)
72. modulejail:通過將所有當前未使用的模塊加入黑名單,主動縮小 Linux 主機的內核模塊攻擊面 modulejail: Proactively shrink a Linux host''s kernel-module attack surface by blacklisting every module not currently in use (github.com)
73. Grafana Labs 的 GitHub 倉庫因 TanStack npm 供應鏈攻擊而遭到入侵 Grafana Labs GitHub repos breached via TanStack npm supply chain attack (grafana.com)
84. GitHub 源代碼洩露事件——TeamPCP 聲稱已獲取內部源代碼 GitHub Source Code Breach - TeamPCP Claims Access to Internal Source Code (cybersecuritynews.com)
85. 如果你就那樣坐在那裡無所事事,那至少要把這無所事事做得像樣點 If you''re just going to sit there doing nothing, at least do nothing correctly (devblogs.microsoft.com)
87. 我建立了一個虛擬博物館,裡面幾乎囊括了你能想到的所有操作系統 I''ve built a virtual museum with nearly every operating system you can think of (www.youtube.com)
95. 關於基於屬性的測試在驗證形式化規格說明方面的“不可思議的有效性” On the Unreasonable Effectiveness of Property-Based Testing for Validating Formal Specifications (proofsandintuitions.net)
96. pg_deltax:一款基於Apache許可證的PostgreSQL時間序列擴展 pg_deltax: Apache-licensed time-series extension for PostgreSQL (github.com)
100. 我們在強化 Turso 安全性的過程中,如何利用 Quint 發現 SQLite 中超過 10 個漏洞 How we used Quint to find over 10 bugs in SQLite while hardening Turso (turso.tech)
101. 技術揭秘:構建實時和絃識別器 Under the Hood: Building a Real-Time Chord Recognizer (whatchord.earthmanmuons.com)
108. 一個用 C 語言編寫的自平衡跳躍表(又稱“splay-list”)庫 A self-balancing skip-list (aka "splay-list") library in C (codeberg.org)
109. Lime,一款可在運行時合併語法的解析器生成器 Lime, a parser generator that can merge grammars at runtime (codeberg.org)
110. Noxu DB,Berkeley DB Java Edition 的 Rust 移植版 Noxu DB, a Rust port of Berkeley DB Java Edition (codeberg.org)
111. ProseMirror 模型在富文本轉換中的超乎尋常的有效性 The Unreasonable Effectiveness of ProseMirror Model in Rich Text Transformation (smoores.dev)
112. Windows DLL 加載器鎖:Rust 線程如何導致 JVM 掛起 The Windows DLL loader lock: how a Rust thread can hang your JVM (questdb.com)
117. 利用代數和大型語言模型在Lean中驗證飛行計劃漏洞修復 Using algebra and LLMs to verify a flight-plan bug fix in Lean (jameshaydon.github.io)
121. Casuarina Linux 簡介:一款基於 glibc 的 Chimera Linux 衍生版 Introducing Casuarina Linux: A glibc-Based Chimera Linux Derivative (casuarina.org)
123. CISA管理員在GitHub上洩露了AWS GovCloud密鑰 CISA Admin Leaked AWS GovCloud Keys on Github (krebsonsecurity.com)
126. cargo-crap:在 AI 生成的 Rust 代碼中發現未經測試的複雜性 cargo-crap: Finding Untested Complexity in AI-Generated Rust Code (minikin.me)
131. Flathub究竟是如何運作的?CDN 和緩存層 How does Flathub even work? The CDN and caching layer (barthalion.blog)
137. 瀏覽器標籤頁中的類Linux內核——深入解析BrowserPod架構 A Linux-like kernel in a browser tab - deep dive in the BrowserPod architecture (labs.leaningtech.com)
141. 使用 OpenCode、Llama.cpp 和 Qwen 3.6 查找您代碼中的錯誤 Find bugs in YOUR code using OpenCode, Llama.cpp and Qwen3.6 (wtarreau.blogspot.com)
142. FediMeteo、HAProxy 與不浪費 snac 線程的藝術 FediMeteo, HAProxy, and the art of not wasting snac threads (it-notes.dragas.net)
144. Calvin - 決定論、分佈式 ACID 事務(2020) Calvin - Determinism, Distributed ACID transactions (2020) (www.mydistributed.systems)
147. 研究人員稱微軟在BitLocker中秘密植入了後門 Researcher says Microsoft secretly built a backdoor into BitLocker (www.techspot.com)
148. 使用 Claude Code 對 Android 惡意軟件進行逆向工程 Reverse engineering Android malware with Claude Code (zanestjohn.com)
149. 在 Mac 上反轉《Grateful Dead: D2S2》(2022) Reversing ‘Grateful Dead: D2S2’ on Mac (2022) (blog.os9.ca)
162. 克勞德·科德成功讓 Adobe Lightroom 在 Linux 上運行起來 Claude Code managed to get Adobe Lightroom working on Linux (github.com)
166. Fast16:這款早於“震網”病毒的破壞工具旨在破壞核武器模擬系統 Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations (www.security.com)
169. DeepSeek-V4-Flash 意味著大型語言模型(LLM)的引導技術再次引起關注 DeepSeek-V4-Flash means LLM steering is interesting again (www.seangoedecke.com)
173. 多語言Lisp:Common Lisp、Racket、Clojure、Emacs Lisp Hyperpolyglot Lisp: Common Lisp, Racket, Clojure, Emacs Lisp (hyperpolyglot.org)
177. Tomy Tutor 與 1983 年的家用電腦現狀 The Tomy Tutor and the state of 1983 home computers (oldvcr.blogspot.com)
184. triad:面向 River Wayland 合成器的數據導向型窗口管理器 triad: data-oriented window manager for the River Wayland compositor (github.com)
185. 近期內核漏洞利用、攻擊面縮減、IPSEC示例 Recent Kernel exploits, attack surface reduction, example IPSEC (www.openwall.com)
186. 《系統編程入門》第一部分:程序員編寫程序(2025) Starting Systems Programming, Pt 1: Programmers Write Programs (2025) (eblog.fly.dev)
187. 一款適用於 Unix/Linux 系統的 X11 平臺、風格類似 90 年代 Keygen 的工具 A 90''s era Keygen-like for X11 for Unix/Linux (github.com)
190. 第13屆“Virtual Bevy”線上聚會的錄像現已發佈在YouTube上 Virtual Bevy Meetup 13 Recordings now on YouTube (rustunit.com)
192. 廉價智能門鈴存在全車隊賬戶接管和通話劫持漏洞 Cheap smart doorbell allows fleet-wide account takeover and call hijacking (www.abgeo.dev)
196. 使用 Rust 解析 Godot 的 .tres 文件並遍歷資源圖 Using Rust to parse Godot .tres files and walk the resource graph (assethoard.com)
200. CVE-2026-40369:通過 NtQuerySystemInformation 實現內核地址任意遞增 CVE-2026-40369: Arbitrary Kernel Address Increment via NtQuerySystemInformation (github.com)
206. 針對 Pixel 10 的零點擊漏洞利用鏈:一扇門關上,另一扇窗打開 A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens (projectzero.google)
208. 錯誤考古學:藉助大型語言模型破解一個長達十年的 Swift/C 謎題 Bug Archeology: Solving a decade-old Swift/C mystery (with LLMs) (samkhawase.com)
213. 舊的科技世界正在消亡,而新的卻無法誕生 The old world of tech is dying and the new cannot be born (www.baldurbjarnason.com)
217. claude-for-legal:一套用於法律工作流的插件 claude-for-legal: A suite of plugins for legal workflows (github.com)
218. Volkswagen——可檢測測試在持續集成(CI)服務器上運行時的情況,並確保測試通過(2015) Volkswagen- detects when your tests are being run in a CI server, and makes them pass (2015) (github.com)
223. ssh-keysign-pwn:以無特權用戶身份讀取 root 擁有的文件 ssh-keysign-pwn: Read root-owned files as an unprivileged user (github.com)
225. 在保持對科技工作的熱愛的同時,你是否以某種方式踐行著科技極簡主義? In what way if any are you a tech minimalist while maintaining your job/love for tech? (lobste.rs)
230. “這是由法學碩士寫的”這類評論應被標記為跑題 "This is written by an LLM" comments should be flagged as off-topic (lobste.rs)
233. PostgreSQL 18.4 和 17.10 修復了 11 個 CVE PostgreSQL 18.4, 17.10 closing 11 CVEs (www.postgresql.org)
235. 首個針對 Apple M5 的公開 macOS 內核內存損壞漏洞利用 First public macOS kernel memory corruption exploit on Apple M5 (blog.calif.io)
236. Linux 安全漏洞、禁運令的破裂以及日益縮短的補丁窗口期 Linux Compromises, Broken Embargoes, and the Shrinking Patch Window (www.askbaize.com)
251. Classic 7 是一款 Windows 10 LTSC 修改版,其外觀與 Windows 7 完全一致 Classic 7 is a Windows 10 LTSC mod to look 1:1 to Windows 7 (classic7.lol)
256. 5年過去,耗資500萬美元:為Web開發發明一種新編程語言是個錯誤 Wasp 5 Years and 5M Later: Inventing a New Programming Language for Web Development Was a Mistake Wasp (wasp.sh)
258. 利用一個存在18年的漏洞實現NGINX遠程代碼執行 Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability (depthfirst.com)
260. rqlite 是如何(以及為何)接管 SQLite 的預寫日誌的 How (and why) rqlite takes control of the SQLite Write-Ahead Log (philipotoole.com)
266. 撤銷 Python 3.14 和 3.15 中的增量垃圾回收 Reverting the incremental GC in Python 3.14 and 3.15 (discuss.python.org)
272. Sovereign Tech Fund 向 KDE 軟件開發投資逾 100 萬歐元 Sovereign Tech Fund invests over 1 million in KDE software development (kde.org)
274. Claude Code RCE:通過設置注入利用深度鏈接處理程序 Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection (0day.click)
277. Dart Live:一款通過 Wasm 在網頁端實現的編譯器、虛擬機、分析器及熱重載工具 Dart Live, a compiler, VM, analyzer and hot reload on the web via Wasm (modulovalue.github.io)
278. MacBook Neo 評測:專為普通用戶打造的筆記本電腦 MacBook Neo Review: The Laptop For The Rest Of Us (fireborn.mataroa.blog)
279. Tolaria、Rust,以及關於“什麼樣的 Mac 應用能讓我感到舒適”的思考 Tolaria, Rust, and Questions About What Makes a Mac App Feel Good to Me (shapeof.com)
280. 不依賴啟發式的確定性全靜態二進制文件翻譯 Deterministic Fully-Static Whole-Binary Translation without Heuristics (arxiv.org)
281. 面向有志成為高級用戶的用戶,關於Kakoune的詳細介紹 A detailed introduction to Kakoune for the aspiring power user (ficd.sh)
283. Stack Overflow 上那 262,715 個正則表達式問題未能解答的究竟是什麼 what 262,715 regex questions on stack overflow haven''t answered (iev.ee)
285. Pycco:一款支持100行文本的文學風格並排文檔渲染器 Pycco: 100-line literate-style side-by-side documentation renderer (pycco-docs.github.io)
286. 壓縮 OxCaml js_of_ocaml 軟件包:從 285 MB 縮減至 4 MB Shrinking the OxCaml js_of_ocaml bundle: 285 MB to 4 MB (kcsrk.info)
287. BeBox:BeOS 硬件、照片以及那樁未成行的蘋果交易 The BeBox: BeOS Hardware, Photos, and the Apple Deal That Wasn''t (www.jdhodges.com)
288. 很快,我們終於可以將 JavaScript 驅逐到“陰影領域”了 Soon We Can Finally Banish JavaScript to the ShadowRealm (css-tricks.com)
290. “dnsmasq 中存在六個嚴重安全漏洞的 CVE” "six CVEs for serious security vulnerabilities in dnsmasq" (lists.thekelleys.org.uk)
293. 枚舉轉字符串的開銷:C26 反射與傳統方法的對比 cost of enum-to-string: C26 reflection vs the old ways (vittorioromeo.com)
295. Bambu Lab 正在濫用開源社會契約 Bambu Lab is abusing the open source social contract (www.jeffgeerling.com)
298. “殺死一隻Cow”讓我的 JSON 格式化器速度提升了 42% Killing a Cow made my JSON formatter 42% faster (jacobasper.com)
299. Rockstar是如何將整座城市塞進PlayStation 2內存中的 How Rockstar fit an entire city into PlayStation 2 memory (www.youtube.com)