ping0.cc被曝利用WebRTC静默上报用户真实IP
https://www.nodeseek.com/post-674661-1
https://www.nodeseek.com/post-674661-1
需要顺便说一句的是,源代码里的 TrustedBot 除了上文的 @nekonotificationbot(1190800416)外,还同时出现了 @WatchdogNextBot (6371744499),供参考。
为验证这一点,我们制作了一个PoC:一个LSPosed模块,将机器人ID和用户名替换为我们自己的信息,这样所有请求都会发送到我们的服务器上。通过这种方式,我们确认电话号码确实在被收集。每次登录都会如此。
该PoC可在此处获取: https://github.com/RomashkaTea/nekogram-proof-of-logging
https://t.me/EvolutionXOfficial/2488
该PoC可在此处获取: https://github.com/RomashkaTea/nekogram-proof-of-logging
https://t.me/EvolutionXOfficial/2488
According to SOTA,
"The backdoor is hidden in the http://Extra.java file, which differs from the template uploaded to the repository. The obfuscated code sends data as an inline request to the @nekonotificationbot, leaving no trace. The same file implements account 'doxing' via several bots; it is possible that the leaked data is used to populate their databases."
Additionally, the creator of the Nekogram client, (presumably a Chinese national) was previously known for conducting DDoS attacks and unethical online behavior (including death threats against acquaintances).
Apparently, in the early versions of the client, de-anonymization was applied only to Chinese phone numbers, which could have been used for political surveillance;. However, it is now applied to all users.
Follow @TechLeaksZone
全球首款双摄云台相机影石Nuna宣传片(待审核)
@影石Insta360:
via @bilifeedbot
轻轻一扭,轻松拍出360°全景画面;搭配可拆卸镜头设计,随时转换第一视角;1200倍变焦+微距,不管是远在天边还是近在眼前,都能清晰捕捉;翻转屏秒变小风扇,炎炎夏日也要拍出“呼吸感”大片;同时支持手动发电,10分钟就能充至80%;内置带轮三脚架,一个人旅行也能全程跟拍,出门带它就够了!
这样的Nuna,你想试试吗?
@影石Insta360:
发布视频
播放量:8742 弹幕:166 评论:235
点赞:811 投币:195 收藏:139 转发:548
发布日期:2026-04-01 02:30:00
上传日期:2026-03-31 18:27:37
🔝> @影石Insta360:
【转发+关注】说说你最喜欢Nuna的哪个功能,5月1日抽1位朋友送69元购买新品的福利(我保证这句是认真的(°∀°)ノ)
via @bilifeedbot
这段 negativePattern 暴露了 Anthropic 工程师在调教 Claude Code 时的三个核心策略:
1. “按闹分配”的止损逻辑:
当正则命中这些词(比如 wtf、piece of shit)时,系统会瞬间切换到一个 “高阶安抚模式”。它不再跟你争论逻辑,而是优先承认错误,并自动调用更强的 Opus 模型或开启更深的 CoT(思维链)来强行解决当前的 Bug,试图通过“超常表现”挽回用户的心。
2. AI 的“读心术”底层是正则:
大家觉得 Claude 懂人心,其实底层的“感知器”居然是这么一串脏话列表。这说明在极端的工程环境下,最原始的正则比复杂的情感分析模型更鲁棒、更省钱。
3. 防止模型“对骂”:
代码里还有一个配套的 SafeResponse 逻辑。一旦检测到用户抓狂,它会强制要求 AI 保持 “Extreme Professionalism(极端专业主义)”,绝对不允许 AI 回嘴。这就是为什么它有时候显得那么“温润如玉”——其实全是这几行正则给逼的!
Forgejo will be releasing a bug-fix patch release, along with incorporating upcoming Go security patches, on April 10th 2026. Patches will be available for Forgejo v11 LTS and Forgejo v14.
Details will be available in
v11.0.12
v14.0.4
https://codeberg.org/forgejo/security-announcements/issues/51
Details will be available in
v11.0.12
v14.0.4
https://codeberg.org/forgejo/security-announcements/issues/51