AI is code – and can't be prompted into being smarter
摘要
内容强调 AI 代理因不可信而不应被赋予危险权限。文中列举了多个案例:KPMG 的 AI 报告中 45 个引用仅 5 个真实,暴露出严重的幻觉问题;GitHub 因疑似蠕虫感染清理了 70 多个微软仓库;同时介绍了 Netflix 工程师开源的 AI 降本工具 Project Headroom 以及 AWS Graviton 5 的性能进展,警示开发者关注 AI 的工程边界与安全隐患。
荐读理由
通过获取 Netflix 开源的 Project Headroom 这一具体工具来优化 AI 成本,并借“AI 即代码”的视角修正研发策略,将精力从不稳定的提示词调优转向确定性的工程架构实现。
原文

Off-PREM
Fire burns Google Cloud India’s network, which remains slow a week later
PLUS: Japan’s space truck is back in business; Zoho's DIY servers; Record tech exports for Korea, and more!
OFFBEAT
US Army picks out Vampire to fill a gap in its layered drone defenses
L3Harris supplies system that can down incoming drones with laser-guided rockets
ZTE wins three Selular Award 2026 honors for AI-powered network innovation
PARTNER CONTENT: Recognized for breakthrough achievements in FWA, Network Ecosystem, and Native AI Baseband, ZTE solidifies its role as a key driver of Indonesia’s 5G-Advanced and AI economic growth
AI AND ML
AI is code – and can't be prompted into being smarter
From Java tests to Shai-Hulud, bots keep proving they'll swallow anything you feed them

PAAS AND IAAS
Graviton 5 impresses, but please, for the love of all that's holy, stop calling them 'AI chips'
AWS better at running chip fabs than their mouths
OFF-PREM
EU sovereignty push gives tech buyers a new alphabet soup to swallow
Brussels presses on despite US fury as it looks to enforce cloud autonomy and bolster open source
MOST POPULAR
GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections
Angry bug hunter with Microsoft beef drops new Windows 0-day
Signal says UK plan to scan devices for nude images 'endangers us all'
Amazon owns up to using 2.5bn gallons of H2O in its bit barns last year
Every employee’s password was stored in a single Excel file
EVENTS
Thriving Through Volatility: The Everpure Advantage in an Uncertain Market
- Learn how a consumption-based operating model provides flexibility, improves efficiency, and brings predictability to infrastructure investments.
From Prompt to Exploit: How LLMs Are Changing API Attacks
- Modern applications are API-driven, interconnected, and often over-permissioned, making them an ideal target for AI-assisted attacks.
Architecting the Future: Unlocking Enterprise Data Services for Kubernetes
- Join us to discover how to eliminate infrastructure silos and establish a standardized, enterprise-grade cloud-native platform.
Catch the Advanced Attacks Microsoft 365 Misses with Behavioral AI Security
- Microsoft 365 is the backbone of enterprise communication, and its native security filters out the known and the noisy.
Accelerate your innovation
- This is your technical deep-dive into the practical tools and techniques that define the next generation of resilient Dev and IT operations.
Virtual Cyber Recovery Sim
- Step into the chaos of a live ransomware breach, test your response skills, and team up with other IT and security pros to outsmart cybercriminals
Virtual Cyber Recovery Simulation
- Ransomware attacks aren’t slowing down, and neither are we. Druva’s hit event, Escape Ransomware, is now fully virtual.
Zero Trust for the Agentic AI Era
- The identity and access models most organizations rely on were built for human users, not non-human identities operating independently.
Zero Trust for the Agentic AI Era
- The identity and access models most organizations rely on were built for human users, not non-human identities operating independently.
Agentic AI at Scale: From Pilot to Production
- Join us to learn how to unlock real ROI by driving adoption of AI at scale.
- AI AND ML
AI is code – and can't be prompted into being smarter
From Java tests to Shai-Hulud, bots keep proving they'll swallow anything you feed them
ai and ml
NanoClaw now armed with JFrog for safer packages
AI agents can't be trusted, so don't give them dangerous powers
systems
SK Hynix to boost memory production 3x ... you can wait another 8 years, right?
We're moving as fast as we can, says SK Group chair
Software
Holy git! Microsoft code-sharing site suffers downtime, despite move to Azure
GitHub caught off guard by customers actually using the AI being evangelized
ai and ml
KPMG's AI report becomes an accidental demo of AI hallucinations
- GPTZero claims only 5 of the report's 45 citations matched their sources, raising questions about how the Big Four's AI study was assembled
Infosec
- Security
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security
EQT buys majority share in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
- On the plus side, infosec's a good bet for a long, stable career
History of CentOS: How a biochemist's Linux hobby project became the enterprise world's default operating system
- When a community came together after Red Hat said Windows was 'probably the right product'
Netflix wiz creates app to slash AI bills, then open sources it
- Project Headroom could save you big money, too
OpenBSD 7.9 arrives, a diamond in the rough proud of every sharp edge
- Sixtieth release adds more cores, delayed hibernation, and basic Wi-Fi 6 without losing its ascetic streak
Fedora: Microsoft is all aboard, but Deepin is dumped
- Red Hat’s free distro loses a desktop, but makes an important new friend
LocalSend puts your sneakernet out of business
- Like AirDrop, minus the Apple lock-in
dBase debased: Database titan fades to black after 47 years
- Blog post mourning decline appears to have helped knock what was left of the veteran app's online presence offline
这条对你有帮助吗?




