3. DeepSeek-V4-Flash 意味著大型語言模型(LLM)的引導技術再次引起關注 DeepSeek-V4-Flash means LLM steering is interesting again (www.seangoedecke.com)
7. 多語言Lisp:Common Lisp、Racket、Clojure、Emacs Lisp Hyperpolyglot Lisp: Common Lisp, Racket, Clojure, Emacs Lisp (hyperpolyglot.org)
11. Tomy Tutor 與 1983 年的家用電腦現狀 The Tomy Tutor and the state of 1983 home computers (oldvcr.blogspot.com)
18. triad:面向 River Wayland 合成器的數據導向型窗口管理器 triad: data-oriented window manager for the River Wayland compositor (github.com)
19. 近期內核漏洞利用、攻擊面縮減、IPSEC示例 Recent Kernel exploits, attack surface reduction, example IPSEC (www.openwall.com)
20. 《系統編程入門》第一部分:程序員編寫程序(2025) Starting Systems Programming, Pt 1: Programmers Write Programs (2025) (eblog.fly.dev)
21. 一款適用於 Unix/Linux 系統的 X11 平臺、風格類似 90 年代 Keygen 的工具 A 90''s era Keygen-like for X11 for Unix/Linux (github.com)
24. 第13屆“Virtual Bevy”線上聚會的錄像現已發佈在YouTube上 Virtual Bevy Meetup 13 Recordings now on YouTube (rustunit.com)
26. 廉價智能門鈴存在全車隊賬戶接管和通話劫持漏洞 Cheap smart doorbell allows fleet-wide account takeover and call hijacking (www.abgeo.dev)
30. 使用 Rust 解析 Godot 的 .tres 文件並遍歷資源圖 Using Rust to parse Godot .tres files and walk the resource graph (assethoard.com)
34. CVE-2026-40369:通過 NtQuerySystemInformation 實現內核地址任意遞增 CVE-2026-40369: Arbitrary Kernel Address Increment via NtQuerySystemInformation (github.com)
40. 針對 Pixel 10 的零點擊漏洞利用鏈:一扇門關上,另一扇窗打開 A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens (projectzero.google)
42. 錯誤考古學:藉助大型語言模型破解一個長達十年的 Swift/C 謎題 Bug Archeology: Solving a decade-old Swift/C mystery (with LLMs) (samkhawase.com)
47. 舊的科技世界正在消亡,而新的卻無法誕生 The old world of tech is dying and the new cannot be born (www.baldurbjarnason.com)
51. claude-for-legal:一套用於法律工作流的插件 claude-for-legal: A suite of plugins for legal workflows (github.com)
52. Volkswagen——可檢測測試在持續集成(CI)服務器上運行時的情況,並確保測試通過(2015) Volkswagen- detects when your tests are being run in a CI server, and makes them pass (2015) (github.com)
57. ssh-keysign-pwn:以無特權用戶身份讀取 root 擁有的文件 ssh-keysign-pwn: Read root-owned files as an unprivileged user (github.com)
59. 在保持對科技工作的熱愛的同時,你是否以某種方式踐行著科技極簡主義? In what way if any are you a tech minimalist while maintaining your job/love for tech? (lobste.rs)
64. “這是由法學碩士寫的”這類評論應被標記為跑題 "This is written by an LLM" comments should be flagged as off-topic (lobste.rs)
69. 首個針對 Apple M5 的公開 macOS 內核內存損壞漏洞利用 First public macOS kernel memory corruption exploit on Apple M5 (blog.calif.io)
70. Linux 安全漏洞、禁運令的破裂以及日益縮短的補丁窗口期 Linux Compromises, Broken Embargoes, and the Shrinking Patch Window (www.askbaize.com)
85. Classic 7 是一款 Windows 10 LTSC 修改版,其外觀與 Windows 7 完全一致 Classic 7 is a Windows 10 LTSC mod to look 1:1 to Windows 7 (classic7.lol)
90. 5年過去,耗資500萬美元:為Web開發發明一種新編程語言是個錯誤 Wasp 5 Years and 5M Later: Inventing a New Programming Language for Web Development Was a Mistake Wasp (wasp.sh)
92. 利用一個存在18年的漏洞實現NGINX遠程代碼執行 Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability (depthfirst.com)
94. rqlite 是如何(以及為何)接管 SQLite 的預寫日誌的 How (and why) rqlite takes control of the SQLite Write-Ahead Log (philipotoole.com)
100. 撤銷 Python 3.14 和 3.15 中的增量垃圾回收 Reverting the incremental GC in Python 3.14 and 3.15 (discuss.python.org)
106. Sovereign Tech Fund 向 KDE 軟件開發投資逾 100 萬歐元 Sovereign Tech Fund invests over 1 million in KDE software development (kde.org)
108. Claude Code RCE:通過設置注入利用深度鏈接處理程序 Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection (0day.click)
111. Dart Live:一款通過 Wasm 在網頁端實現的編譯器、虛擬機、分析器及熱重載工具 Dart Live, a compiler, VM, analyzer and hot reload on the web via Wasm (modulovalue.github.io)
112. MacBook Neo 評測:專為普通用戶打造的筆記本電腦 MacBook Neo Review: The Laptop For The Rest Of Us (fireborn.mataroa.blog)
113. Tolaria、Rust,以及關於“什麼樣的 Mac 應用能讓我感到舒適”的思考 Tolaria, Rust, and Questions About What Makes a Mac App Feel Good to Me (shapeof.com)
114. 不依賴啟發式的確定性全靜態二進制文件翻譯 Deterministic Fully-Static Whole-Binary Translation without Heuristics (arxiv.org)
115. 面向有志成為高級用戶的用戶,關於Kakoune的詳細介紹 A detailed introduction to Kakoune for the aspiring power user (ficd.sh)
117. Stack Overflow 上那 262,715 個正則表達式問題未能解答的究竟是什麼 what 262,715 regex questions on stack overflow haven''t answered (iev.ee)
119. Pycco:一款支持100行文本的文學風格並排文檔渲染器 Pycco: 100-line literate-style side-by-side documentation renderer (pycco-docs.github.io)
120. 壓縮 OxCaml js_of_ocaml 軟件包:從 285 MB 縮減至 4 MB Shrinking the OxCaml js_of_ocaml bundle: 285 MB to 4 MB (kcsrk.info)
121. BeBox:BeOS 硬件、照片以及那樁未成行的蘋果交易 The BeBox: BeOS Hardware, Photos, and the Apple Deal That Wasn''t (www.jdhodges.com)
122. 很快,我們終於可以將 JavaScript 驅逐到“陰影領域”了 Soon We Can Finally Banish JavaScript to the ShadowRealm (css-tricks.com)
124. “dnsmasq 中存在六個嚴重安全漏洞的 CVE” "six CVEs for serious security vulnerabilities in dnsmasq" (lists.thekelleys.org.uk)
127. 枚舉轉字符串的開銷:C26 反射與傳統方法的對比 cost of enum-to-string: C26 reflection vs the old ways (vittorioromeo.com)
129. Bambu Lab 正在濫用開源社會契約 Bambu Lab is abusing the open source social contract (www.jeffgeerling.com)
132. “殺死一隻Cow”讓我的 JSON 格式化器速度提升了 42% Killing a Cow made my JSON formatter 42% faster (jacobasper.com)
133. Rockstar是如何將整座城市塞進PlayStation 2內存中的 How Rockstar fit an entire city into PlayStation 2 memory (www.youtube.com)
135. 在較新版本的 Android 系統上,任何應用都可能洩露某些流量 Any app on recent Android versions can leak certain traffic (mullvad.net)
140. 《在 Linux 和 Unix 系統上編譯 Emacs 以提升性能的技術指南》 A Technical Guide to Compiling Emacs for Performance on Linux and Unix systems (www.jamescherti.com)
142. Kettle:用於可驗證軟件溯源的經過驗證的構建方案 Kettle: Attested builds for verifiable software provenance (arxiv.org)
144. floci:輕量、靈活,且完全免費——AWS Local Emulator 的替代方案 floci: Light, fluffy, and always free - The AWS Local Emulator alternative (github.com)
145. 熱門 Go 庫 fsnotify 因維護者訪問權限變更引發供應鏈安全警報 Popular Go library fsnotify raises supply chain alarms after maintainer access changes (socket.dev)
148. 第12屆Plan 9國際研討會註釋摘要 An annotated digest of the 12th International Workshop on Plan 9 (n-gate.com)
158. 反極簡主義的反撲,才是Oxygen重振雄風背後的真正原因 The anti-minimalist backlash is the bigger story behind Oxygen’s revival (filipfila.wordpress.com)
160. devenv 2.1:通過 libghostty 支持 zsh、fish 和 nushell 的 Nix - devenv devenv 2.1: Nix with zsh, fish, and nushell via libghostty - devenv (devenv.sh)
167. omlx:一款支持連續批處理和 SSD 緩存的 LLM 推理服務器,專為 Apple Silicon 設計——可通過 macOS 菜單欄進行管理 omlx: LLM inference server with continuous batching & SSD caching for Apple Silicon — managed from the macOS menu bar (github.com)
168. 基於可編程白名單的配置:在 Go 中嵌入 Rye Programmable Whitelist-based Configs: Embedding Rye in Go (ryelang.org)
171. 使用 systemfd 將終端輸出重定向到瀏覽器 Piping terminal output to the browser using systemfd (blog.izissise.net)
174. 最高支持 256 MB 的 FERRIT 模塊化 F-RAM 存儲設備,可將關鍵數據保存長達 200 年 Up to 256 MB FERRIT modular F-RAM storage device preserves critical data for up to 200 years (www.cnx-software.com)
175. 《Factorio》如何通過網絡同步上百萬個物體 How Factorio Syncs A Million Objects over the network (www.youtube.com)
180. 在不使用 TIOCSTI 的情況下替換 Bash 中的 Ctrl-R Replacing Ctrl-R in Bash without TIOCSTI (blog.rickardlindberg.me)
182. Tiny-Lua-Compiler:可能是迄今為止最小的 Lua 編譯器 Tiny-Lua-Compiler: Possibly the smallest Lua compiler ever (github.com)
183. ClaudeBleed:Claude瀏覽器擴展中的一個漏洞允許任何擴展程序劫持它 ClaudeBleed: A Flaw In Claude''s Browser Extension Allows Any Extension to Hijack It (layerxsecurity.com)
190. 使用 Swift 訓練大型語言模型(LLM),第一部分:將矩陣乘法性能從 Gflop/s 提升至 Tflop/s Training an LLM in Swift, Part 1: Taking matrix multiplication from Gflop/s to Tflop/s (www.cocoawithlove.com)
191. wayland.fyi 極簡主義 Wayland 特別興趣小組 wayland.fyi minimalist wayland special interest group (wayland.fyi)
197. 宇宙射線是量子計算機的剋星——軟件或許能解決這一難題 Cosmic Rays Are Quantum Computers'' Kryptonite—Software might just solve the problem (spectrum.ieee.org)
198. 《雙重迪菲-赫爾曼問題及其應用》(2009) The Twin Diffie-Hellman Problem and Applications (2009) (eprint.iacr.org)
201. 用一個 10 MB 的 FST(有限狀態轉換器)二進制文件替換一個 3 GB 的 SQLite 數據庫 Replacing a 3 GB SQLite database with a 10 MB FST (finite state transducer) binary (til.andrew-quinn.me)
203. 《優質的首個問題:提交你的首個開源貢獻》 Good First Issue: Make your first open-source contribution (goodfirstissue.dev)
214. Aurora:一種適用於矩形矩陣的考慮權重關係的優化器 Aurora: A Leverage-Aware Optimizer for Rectangular Matrices (blog.tilderesearch.com)
216. 讓大型語言模型“喝醉”以發現遠程 Linux 內核 OOB 寫入(及其他) Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More) (heyitsas.im)
217. 那些複雜的 Windows 惡意軟件及其分析都去哪兒了? Where Have All the Complex Windows Malware and Their Analyses Gone? (r136a1.dev)
220. 在非標準 shell 環境中使用 GNU Emacs 的 Tramp 系統的注意事項 Notes on using GNU Emacs'' Tramp system in an unusual shell environment (utcc.utoronto.ca)
222. FFmpeg:互聯網視頻背後的非凡技術 FFmpeg: The Incredible Technology Behind Video on the Internet (www.youtube.com)
225. 我對代理的信任問題:從提示符注入到 gemini-cli 的供應鏈漏洞 My Agentic Trust Issues: From Prompt Injection to Supply-Chain Compromise on gemini-cli (www.pillar.security)
230. 你給了我一個u32,我給了你root權限。(io_uring ZCRX freelist LPE) You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE) (ze3tar.github.io)
231. Inflorescence – Pijul 的跨平臺原生圖形用戶界面 Inflorescence – A cross-platform native GUI for Pijul (nest.pijul.com)
232. Chrome 的 AI 功能可能會佔用你電腦中 4GB 的存儲空間 Chrome’s AI features may be hogging 4GB of your computer storage (www.theverge.com)
233. killswitch:添加按函數的短路緩解原語 [LWN.net] killswitch: add per-function short-circuit mitigation primitive [LWN.net] (lwn.net)
236. 一種具有發現缺陷概率保證的隨機調度器 A Randomized Scheduler with Probabilistic Guarantees of Finding Bugs (www.microsoft.com)
237. CADara - 我開發了一款開源的、完全基於瀏覽器的CAD軟件 CADara - I made an open-source fully in-browser CAD (cadara.app)
241. Let''s Encrypt 因潛在安全事件暫停證書籤發 Let''s Encrypt Stopping Issuance for Potential Incident (letsencrypt.status.io)
243. 漏洞花園:一份不斷更新的已命名漏洞、攻擊技術和利用程序清單 Vulnerability Garden: A growing list of named vulnerabilities, attack techniques and exploits (vulnerability.garden)
244. Linux 內核中的漏洞發現與驗證(第一部分):CAN 釋放後使用競爭條件 Discovery & Validation in the Linux Kernel (Part 1): CAN Use-After-Free Race (www.bynar.io)
249. 在完全運行於內存中的樹莓派 Zero 上託管網站 Serving a Website on a Raspberry Pi Zero Running Entirely in RAM (btxx.org)
250. 通往支持文本選擇的客戶端生成PDF文件的意外複雜歷程 The surprisingly complex journey to text-selectable client-side generated PDFs (sdocs.dev)
254. 在首次 SSH 連接時阻止中間人攻擊,適用於任何 VPS 或雲服務提供商 Stop MITM on the first SSH connection, on any VPS or cloud provider (www.joachimschipper.nl)
255. 用 aarch64 彙編語言構建一個 Web 服務器,以此賦予我(本已空虛的)生命以意義 building a web server in aarch64 assembly to give my life (a lack of) meaning (imtomt.github.io)
256. hpke-ng:更快、更小、更強大的 Rust 版 HPKE hpke-ng: Faster, Smaller, Harder HPKE for Rust (symbolic.software)
258. blaise:一款專為2020年代打造的現代自託管Object Pascal編譯器。零遺留代碼、全自動引用計數(ARC)及統一的UTF-8編碼 blaise: A modern, self-hosting Object Pascal compiler built for the 2020s. Zero legacy, full ARC, and unified UTF-8 (github.com)
262. 《兩個世界的故事:WireGuard 混合模式的正式闡述》 A Tale of Two Worlds, a Formal Story of WireGuard Hybridization (www.usenix.org)
265. cuda-oxide:cuda-oxide 是一個實驗性的 Rust 到 CUDA 編譯器 cuda-oxide: cuda-oxide is an experimental Rust-to-CUDA compiler (github.com)
268. 為什麼在ASCII字符集中,小寫字母不會緊跟在大寫字母后面?——泰勒·希勒裡 Why Don’t Lowercase Letters Come Right After Uppercase Letters in ASCII? – Tyler Hillery (tylerhillery.com)
274. 一夜之間格式化整個2500萬行代碼庫:rubyfmt的故事 Formatting an entire 25 million line codebase overnight: the rubyfmt story (stripe.dev)
277. 幕後花絮:藉助 Claude Mythos 預覽版強化 Firefox Behind the Scenes Hardening Firefox with Claude Mythos Preview (hacks.mozilla.org)
281. .de 域名遭遇重大 DNS 故障:2026 年 5 月 5 日發生 DNSSEC 故障 Major DNS Outage Hits .de Domains: DNSSEC Failure on May 5, 2026 (www.ip.network)
286. 創建自己的編程語言比你想象的要容易(但也更難) Making your own programming language is easier than you think (but also harder) (lisyarus.github.io)
289. “氛圍編碼”和“能動性工程”的發展速度,比我預期的還要快 Vibe coding and agentic engineering are getting closer than I’d like (simonwillison.net)
292. cursed_browser:一款沒有渲染引擎的網頁瀏覽器——VLM 會讀取 HTML 代碼,並“憑空想象”出頁面 cursed_browser: A web browser with no rendering engine — the VLM reads the HTML and hallucinates the page (github.com)
299. 未平倉合約正在悄然減少——這成了個問題 Open weights are quietly closing up - and that''s a problem (martinalderson.com)