Aggregator
LGPL 授权代码用 AI 重写后改用 MIT 授权
3 weeks 6 days ago
重新授权开源项目的许可协议在开源领域是非常困难的,因为这通常需要所有曾贡献过一行代码的人一致同意,这对历史悠久的项目而言是几乎不可能完成的任务。Python 字符编码检测器项目 chardet 移植自用 C++ 开发的 Mozilla 项目,采用了与原项目相同的 LGPL 许可证,LGPL 许可对商业使用不是太友好。维护者最近在 Claude Code 的帮助下重写了库发布了 v7.0.0 版本,将许可协议从 LGPL 更改为 MIT。项目原作者 a2mark 认为此举构成了潜在的 GPL 违反,因为开发者已经接触过原代码,并非是净室实现,因此完全重写代码的说法是没有意义的。
Grammarly 从文字纠错转向文学模仿
3 weeks 6 days ago
安全客
Cisco Secure FMC曝出10分高危漏洞 攻击者可获取企业防火墙Root权限
3 weeks 6 days ago
安全客
pac4j-jwt 曝出10.0分高危漏洞 攻击者可伪造管理员令牌
3 weeks 6 days ago
安全客
埃森哲为何重金以12亿美元收购Ookla来为AI未来押注
3 weeks 6 days ago
安全客
Pear
3 weeks 6 days ago
You must login to view this content
cohenido
CVE-2026-2331 | SICK Lector85x/Lector83x up to 2.7.0 file access
3 weeks 6 days ago
A vulnerability has been found in SICK Lector85x and Lector83x up to 2.7.0 and classified as critical. This vulnerability affects unknown code. This manipulation causes files or directories accessible.
The identification of this vulnerability is CVE-2026-2331. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-2330 | SICK Lector85x/Lector83x up to 2.7.x CROWN REST Interface file access
3 weeks 6 days ago
A vulnerability, which was classified as critical, was found in SICK Lector85x and Lector83x up to 2.7.x. This affects an unknown part of the component CROWN REST Interface. The manipulation results in files or directories accessible.
This vulnerability was named CVE-2026-2330. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
The MSP Guide to Using AI-Powered Risk Management to Scale Cybersecurity
3 weeks 6 days ago
Scaling cybersecurity services as an MSP or MSSP requires technical expertise and a business model that delivers measurable value at scale.
Risk-based cybersecurity is the foundation of that model. When done right, it builds client trust, increases upsell opportunities, and drives recurring revenue. But to deliver this consistently and efficiently, you need the right technology and processes.
The Hacker News
数字迷雾中的暗战:英国智库解析美以伊冲突中网络空间的七个关键维度
3 weeks 6 days ago
七重视角下的网络战场:英国智库解读美以伊冲突的隐形较量
2025年至少90个零日漏洞遭滥用,企业软件及设备占比近一半
3 weeks 6 days ago
共发现90个已被实际利用的零日漏洞
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
3 weeks 6 days ago
New research from Broadcom's Symantec and Carbon Black Threat Hunter Team has discovered evidence of an Iranian hacking group embedding itself in several U.S. companies' networks, including banks, airports, non-profit, and the Israeli arm of a software company.
The activity has been attributed to a state-sponsored hacking group called MuddyWater (aka Seedworm). It's affiliated with the Iranian
The Hacker News
勒索月报 |360发布勒索态势分析:NAS攻击量明显抬头,数据存储设施或成勒索“富矿”
3 weeks 6 days ago
360披露2月勒索软件流行态势:Wmansvcs多IP战术改写传播格局
2026两会观察 | 周鸿祎为智能体人才培养献策,360先行落地
3 weeks 6 days ago
周鸿祎两会提案锚定智能体人才培养,360三位一体打造培育标杆
水滴公司首推「水守 AI 助手」ClawSquare 构建 Agent 协同办公新范式
3 weeks 6 days ago
用分布式的 Agent 网络重构组织基因。
Очки н-нада? Как кенийские рабочие стали невольными зрителями вашей интимной жизни
3 weeks 6 days ago
Расследование шведских СМИ утверждает, что сотрудники подрядчика Meta разбирали видео, аудио и расшифровки с бытовыми и интимными моментами.
Hexnode IdP brings device-aware authentication and zero trust to enterprise access
3 weeks 6 days ago
Hexnode has announced the launch of Hexnode IdP. By introducing this native identity layer, Hexnode delivers enterprise-grade authentication and identity management within a single, unified framework. While debuting as a dedicated Identity Provider (IdP), the solution marks a significant expansion of the Hexnode ecosystem, acting as a comprehensive identity engine that integrates directly into the Hexnode UEM fabric. This integration enables organizations to leverage Hexnode’s proprietary Device Trust Engine to enforce context-aware policies based on … More →
The post Hexnode IdP brings device-aware authentication and zero trust to enterprise access appeared first on Help Net Security.
Industry News
观点 | 汽车数据出境新规实施面临的挑战与应对策略
3 weeks 6 days ago
2月3日,工业和信息化部等八部门联合发布《汽车数据出境安全指引(2026版)》,标志着我国在智能网联汽车数据跨境流动治理方面迈出关键一步。这项新规既是对数据安全法、个人信息保护法等法律的行业化落地,也是应对汽车产业全球化与数据安全挑战的重要方式。
国家安全部提醒:“高端局”可别出现低级错误
3 weeks 6 days ago
当前以人工智能为代表的新技术的发展和应用正呈井喷之势。前沿科技的浪潮正以前所未有的力量改变社会形态。在这场“高端局”的竞赛背后,隐蔽战线的较量也日趋激烈。