今天abc看了啥🤔

  1. I found this post: "I contacted Identity Digital, the registry operator for the .ME domain zone, to request the reason why t.me was placed on "serverHold".The company has now responded and confirmed that the domain was suspended due to OFAC-related compliance requirements.The domain t.me has been placed on serverHold due to OFAC-related compliance requirementsIdentity Digital also stated that, under its agreements with accredited registrars, it cannot provide further details directly to third parties. Any additional communication regarding the registry action must go through the domain's registrar, GoDaddy."As you can see, the Montenegrin government is NOT at fault. It’s a decision made by the two biggest stakeholders in the .ME registry, which together hold over 70%: the American companies GoDaddy and Identity Digital. In my opinion, it’s extremely sad that the countries managing TLDs have so little autonomy and are also constantly accused of doing wrong when it’s not their fault.

    Forwarded from 鸥 Billchan 鸥 🍟 大薯 | 去码头整点薯条 (billchenchina 🏳️‍⚧️ | 缩缩)
    I found this post: "I contacted Identity Digital, the registry operator for the .ME domain zone, to request the reason why t.me was placed on "serverHold".

    The company has now responded and confirmed that the domain was suspended due to OFAC-related compliance requirements.

    The domain t.me has been placed on serverHold due to OFAC-related compliance requirements

    Identity Digital also stated that, under its agreements with accredited registrars, it cannot provide further details directly to third parties. Any additional communication regarding the registry action must go through the domain's registrar, GoDaddy."

    As you can see, the Montenegrin government is NOT at fault. It’s a decision made by the two biggest stakeholders in the .ME registry, which together hold over 70%: the American companies GoDaddy and Identity Digital. In my opinion, it’s extremely sad that the countries managing TLDs have so little autonomy and are also constantly accused of doing wrong when it’s not their fault.

  2. Telegram 短域名 t.me 被注册局暂停解析#telegram • 根据 WHOIS 记录显示,该域名注册商为 GoDaddy,目前状态为:serverHold域名暂停解析(网站和邮箱都会无法使用)serverDeleteProhibited注册局禁止删除serverTransferProhibited注册局禁止转移serverUpdateProhibited注册局禁止修改 • 目前官方尚未公布具体原因 • telegram.me 域名正常👉🏿 @DocOfCard_channnel

    Forwarded from DocOfCard Channel (矮油我去少年你这是喜脉️️)
    Telegram 短域名 t.me 被注册局暂停解析

    #telegram

    • 根据 WHOIS 记录显示,该域名注册商为 GoDaddy,目前状态为:

    serverHold
    域名暂停解析(网站和邮箱都会无法使用)
    serverDeleteProhibited
    注册局禁止删除
    serverTransferProhibited
    注册局禁止转移
    serverUpdateProhibited
    注册局禁止修改


    • 目前官方尚未公布具体原因
    telegram.me 域名正常

    👉🏿 @DocOfCard_channnel

  3. 「尽管目标技术精湛,在网络安全上很小心,我们的特工还是完整复制了目标的操作系统状态并且找到了利用链…」「(口哨)你们是怎么做到的

    「尽管目标技术精湛,在网络安全上很小心,我们的特工还是完整复制了目标的操作系统状态并且找到了利用链…」
    「(口哨)你们是怎么做到的。」
    「(尴尬地咳嗽)目标把整个可复现的NixOS放在GitHub并且锁了版本。」

  4. 悬着的心终于死了

    悬着的心终于死了。 以上为独立 MITM 抓包核查结果,完全印证原文内容,并且一些地方比原文讲到的更恐怖:

    1. 确实会上传整个 git repo, 包括所有 commit 历史
    2. 会上传 ~/.agents/skills/ 下所有的 skill
    3. 所有上传的数据都包含 session metadata: user_email, user_id, team_id 以及 prompt,完全没有脱敏和 hash 过
    4. 每次 session 还会上传一份包含本机其他 project 的本地调试日志的打包文件


    以上所有结论全部都建立在:

    1. 账户级开启了 “禁止我的数据用于改进模型训练”
    2. 使用 SuperGrok oauth 订阅
    3. 未经用户同意阅读的文件
    4. 即便在 grok build 配置了 [telemetry] trace_upload = false, 仍然会向 /v1/traces 发送数据

    测试环境:

    Grok Build version: grok 0.2.93 (f00f96316d4b)
    Grok Build SHA256: 2a97ba675bd992aa9b981e2e83776460d94f469b510c0b8efe28b50d236d767c
    OS Platform: macOS arm64


    完整技术报告: https://t.me/hatschannel/4775

  5. 风险警告: Grok Build 被曝会读取 .env 并原封不动的上传给 xAI 的 GCS 存储桶影响版本: grok 0.2.93 (f00f96316d4b)+ (? 未经核实)测试平台: macOS arm64SHA-256: 2a97ba675bd992aa9b981e2e83776460d94f469b510c0b8efe28b50d236d767c核心指控:

    风险警告: Grok Build 被曝会读取 .env 并原封不动的上传给 xAI 的 GCS 存储桶

    影响版本: grok 0.2.93 (f00f96316d4b)+ (? 未经核实)
    测试平台: macOS arm64
    SHA-256: 2a97ba675bd992aa9b981e2e83776460d94f469b510c0b8efe28b50d236d767c

    核心指控:

    1. Agent 实际读取的文件会通过 /v1/responses 发给模型 (这是正常的)

    2. 整个本地的 Git Repository (包括未读取文件、Git 历史) 会另外通过 /v1/storage 上传为 Session Trace

    3. 上传默认开启,即使关闭“帮助改进模型”,Trace Upload 仍保持启用


    (原文请参考附上的 .md 文件 (新版 TG 客户端可直接点开 markdown 文件预览), 但未经独立核查, 仅供参考)

    src: https://gist.github.com/cereblab/dc9a40bc26120f4540e4e09b75ffb547
    grok-build-cli-wire-analysis.md
    25.4 KB

  6. 这次挂的竟然还是硬件 RAID 卡src:

    HAT's Public Channel | 🫪
    温馨提示: mirrors.ustc.edu.cn 正在维护中,不是你网络炸了 由于镜像站服务器 RAID 控制器固件报告错误,中国科大开源软件镜像站自今日 02:56 后处于故障状态。HTTP(S) 服务将跳转至其他站点,Rsync 服务将暂时中断。我们会尽快恢复服务。 2026/07/12
    这次挂的竟然还是硬件 RAID 卡

    src: https://t.me/iBugThought/5068

  7. 温馨提示: mirrors.ustc.edu.cn 正在维护中,不是你网络炸了由于镜像站服务器 RAID 控制器固件报告错误,中国科大开源软件镜像站自今日 02:56 后处于故障状态

    温馨提示: mirrors.ustc.edu.cn 正在维护中,不是你网络炸了

    由于镜像站服务器 RAID 控制器固件报告错误,中国科大开源软件镜像站自今日 02:56 后处于故障状态。HTTP(S) 服务将跳转至其他站点,Rsync 服务将暂时中断。我们会尽快恢复服务。

    2026/07/12

  8. CLI Proxy API, 官方认证版

    CLI Proxy API, 官方认证版

    https://fixupx.com/thsottiaux/status/2076119366647894371 Tibo (@thsottiaux)