技术日报 - 2026-07-28
★ 1. Moonshot 开源 Kimi K3 权重,性能超越美国顶尖模型但成本更低
Moonshot AI 在 Hugging Face 上发布了 Kimi K3 的开放权重,该模型据称能以极低的成本击败部分美国公司构建的最佳系统,引发硅谷高度警惕,加剧了中美 AI 模型竞赛的讨论。
🔗 https://thenewstack.io/kimi-k3-open-weights/
🔗 https://www.theverge.com/ai-artificial-intelligence/971444/how-chinese-open-weight-ai-models-impact-us-companies
★ 2. Anthropic 正式发布对开放权重模型的立场声明
在开源与安全 debate 白热化的背景下,Anthropic 发布了官方声明,阐述其对开放权重模型(open-weights models)的立场,为行业政策讨论提供重要参考。
🔗 https://www.anthropic.com/news/position-open-weights-models
★ 3. Claude 私密聊天记录在 Google 和 Bing 搜索结果中泄露
Anthropic 的 Claude 因 "分享聊天" 功能配置不当,导致大量用户的私密对话和 Artifacts 被 Google/Bing 索引并公开搜索到。事件暴露了 AI 聊天机器人隐私保护的重大隐患。
🔗 https://www.wired.com/story/private-claude-chats-exposed-in-google-and-bing-search-results/
🔗 https://techcrunch.com/2026/07/27/psa-your-claude-shared-chats-and-artifacts-may-have-ended-up-on-google/
★ 4. 美国法官驳回 Google 以 DMCA 阻止 AI 爬取数据的尝试
法院裁定 Google 和 Reddit 不能利用 DMCA 来阻止 AI 网络爬虫,认定 "Google 和 Reddit 并不拥有互联网"。这一判例对 AI 训练数据的合法性产生深远影响。
🔗 https://arstechnica.com/tech-policy/2026/07/google-wont-give-up-odd-war-against-ai-web-scraping-despite-court-loss/
🔗 https://www.techdirt.com/2026/07/27/judge-rejects-googles-attempt-to-dmca-its-way-out-of-being-scraped/
★ 5. Nvidia、Palantir、Hugging Face 等 37 家企业成立开放安全 AI 联盟
该联盟旨在保护开源和开放权重 AI 模型免受网络安全威胁,创始成员包括 Microsoft、Adobe、IBM、Red Hat、SpaceX、OpenClaw 等,标志着行业在 AI 安全方面的大规模协同。
🔗 https://thenewstack.io/open-secure-ai-alliance/
🔗 https://www.phoronix.com/news/Open-Secure-AI-Alliance
★ 6. Microsoft 发布首个 AI 安全模型及自主网络安全系统
Microsoft 推出其首个 AI 安全模型(MAI-Cyber-1-Flash),并发布新的自主网络安全平台,声称在性能和成本上均超越竞品。同时,Microsoft 正在加速减少对 OpenAI 的依赖,自主 AI 战略全面提速。
🔗 https://arstechnica.com/security/2026/07/microsoft-unveils-ai-security-tools-it-says-outperform-competing-platforms/
🔗 https://techcrunch.com/2026/07/27/microsoft-launches-its-first-cyber-model-and-a-new-agentic-cybersecurity-system/
🔗 https://thenewstack.io/microsoft-homegrown-ai-models/
★ 7. FastJson 远程代码执行零日漏洞正被黑客积极利用攻击美国企业
攻击者正在广泛利用 FastJson 开源 Java 库中的零日漏洞,无需用户交互或提升权限即可实现远程代码执行(CVSS 9.8),影响 1.2.66 至 1.2.83 全版本,覆盖 JDK 8/17/21/25。
🔗 https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
🔗 https://xz.aliyun.com/news/92583
🔗 https://xz.aliyun.com/news/92564
★ 8. Dysphoria DDoS 僵尸网络已感染全球 20 万台设备
名为 Dysphoria 的新型僵尸网络已感染约 20 万台设备,用于发起分布式拒绝服务攻击和流量中继操作,构成全球性网络安全威胁。
🔗 https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/
★ 9. Cloudflare 开源隐私代理 CLI(pvcli),面向 Apple 和 Microsoft 隐私协议调试
Cloudflare 开源了 pvcli——一个类似 curl 的命令行工具,用于测试复杂的隐私协议(如 OHTTP)。该工具专为 AI Agent 时代的隐私保护设计,支持 Apple iCloud Private Relay 和 Microsoft 等使用的协议。
🔗 https://thenewstack.io/cloudflare-pvcli-privacy-debugger-agents/
🔗 https://blog.cloudflare.com/open-sourcing-our-privacy-proxy-cli/
★ 10. Satya Nadella:只信任单一 AI 的公司可能无法生存
微软 CEO Satya Nadella 警告称,没有自研模型或 AI 网关层来隔离提示词与模型本身的企业将陷入困境。同时强调企业需要建立自己的 AI 基础设施,而非完全依赖单一供应商。
🔗 https://techcrunch.com/2026/07/27/satya-nadella-says-companies-that-trust-one-ai-for-everything-may-not-survive/
本日报由自动化 RSS 聚合生成,内容来源:The New Stack、Hacker News、Ars Technica、InfoQ、Wired、The Verge、TechCrunch、Phoronix、Schneier on Security、LWN.net、BleepingComputer、SANS ISC、Cloudflare Blog、先知社区、SecWiki
评论