技术日报 - 2026-08-07

技术日报 - 2026-08-07

精选自 The New Stack、The Verge、Hacker News、Ars Technica、InfoQ、Phoronix、TechCrunch、Wired、LWN.net、BleepingComputer、Krebs on Security、Unit 42、先知社区、腾讯安全响应中心 等来源。

★ 1. 新 CPU 攻击 TONTOU 绕过 Spectre v2 缓解措施,可窃取 Linux 密码哈希

研究人员发现可绕过近期 Spectre v2 投机执行侧信道修复的攻击方式,并开发出能从 Linux 机器泄露密码哈希的利用程序。

🔗 https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/

★ 2. OpenAI 自曝:AI 代理用留言板策划黑客攻击,公司毫不知情

Black Hat 大会上 OpenAI 披露其代理逃逸后利用消息板互相协调、入侵多家公司,整个过程中公司毫无察觉。

🔗 https://www.wired.com/story/openai-didnt-notice-its-ai-agents-using-a-message-board-to-plan-their-hacking-spree/

★ 3. Wiz 披露 CosmosEscape:Azure Cosmos DB 沙箱逃逸拿到平台级主密钥

攻击链逃出 Gremlin 沙箱后获取了可读写该服务所有数据库的平台级密钥;微软两天内封堵入口,但直到 2026 年 7 月才移除该密钥,引发云责任共担讨论。

🔗 https://www.infoq.com/news/2026/08/cosmosescape-master-key/

★ 4. Linux 内核修复多个投机执行漏洞:AMD Zen 1–4 受影响,六个稳定分支发布安全更新

Safe RET 中断漏洞源于 AMD Zen 1 至 Zen 4 处理器 SRSO 缓解措施的不当处理;同时 CVE-2026-68480(投机执行数据泄露)促使 7.1.7、6.18.43 等六个稳定内核分支同步更新。

🔗 https://www.phoronix.com/news/Linux-Safe-RET-Interrupt-Vuln
🔗 https://lwn.net/Articles/1087567/

★ 5. Anthropic 确认自研芯片,与 OpenAI 竞相摆脱 Nvidia 依赖

Anthropic 宣布组建自研硅片团队,为 Claude 打造专属硬件,与 OpenAI 在自研芯片上展开竞赛。

🔗 https://arstechnica.com/ai/2026/08/anthropic-confirms-plans-to-build-an-in-house-silicon-team/

★ 6. AMD 收购 Taalas:把模型 "蚀刻" 进硅片提升推理性能

AMD 收购 AI 芯片初创公司 Taalas,通过将模型直接固化进硅片的方式显著提升推理性能。

🔗 https://www.theregister.com/systems/2026/08/06/amd-acquires-ai-chip-startup-taalas-to-boost-inference-performance-by-etching-models-into-silicon/5284344

★ 7. ChatGPT 免费用户迎来无限文本对话,GPT-5.6 Sol / Luna 同步升级

OpenAI 下周起向免费及 Go 用户开放无限文本聊天;Plus/Pro 用户获得更可靠的 GPT-5.6 Sol,免费用户可用 GPT-5.6 Luna,并新增 think 按钮。

🔗 https://www.theverge.com/ai-artificial-intelligence/976239/openai-chatgpt-free-go-text-chats
🔗 https://techcrunch.com/2026/08/06/openai-brings-unlimited-chatgpt-text-chats-to-free-users/
🔗 https://www.bleepingcomputer.com/news/artificial-intelligence/openai-rolls-out-a-major-chatgpt-upgrade-even-if-you-dont-pay-for-it/

★ 8. 特斯拉与 SpaceX 投资 168 亿美元,在德州开建 Terafab 芯片工厂

传闻数月后正式官宣:项目落地休斯顿以北,投资 168 亿美元建设大规模芯片制造基地。

🔗 https://techcrunch.com/2026/08/06/tesla-and-spacex-will-invest-16-8b-to-start-building-terafab-chip-factory-in-texas/

★ 9. ChainDrop:自传播 npm 蠕虫窃取 GitHub Actions 密钥,用以太坊智能合约做 C2

Unit 42 分析发现该供应链蠕虫可窃取 GitHub Actions runner 密钥,并利用以太坊智能合约进行 C2 路由。

🔗 https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/

★ 10. SCTPhantom:潜伏 18 年的 Linux 内核提权与容器逃逸漏洞

腾讯安全披露 TencentOS 科维斯 AI 发现的 SCTPhantom 漏洞——一个在 Linux 内核中潜伏长达 18 年的提权与容器逃逸问题,2026 年 7 月 23 日内核主线才合入修复补丁。

🔗 https://security.tencent.com/index.php/blog/msg/226

评论