正在加载视频...

视频加载失败

The CertiK Skyfall team identified and collaborated with Apple to fix a vulnerability (CVE-2024-27801) in the low-level implementation of NSXPC, affecting all Apple platforms. This vulnerability could have potentially allowed malicious apps to gain unauthorized access to system services or steal user data from certain third-party applications, particularly those...

341,505 次观看 • 2 年前 •via X (Twitter)

6 条评论

CertiK 的头像
CertiK2 年前

Acknowledgement🔒

FOUR | Crypto Spaces 的头像
FOUR | Crypto Spaces2 年前

@CertiKSkyfall @Apple Nice catch! Glad they squashed that bug before any troublemakers got busy with it. Always good to have a team keeping an eye out for us.

Murtaza⚡ 的头像
Murtaza⚡2 年前

@CertiKSkyfall @Apple Amazing Certik!

André Destro 的头像
André Destro2 年前

@CertiKSkyfall @Apple a

Sanders Olive 的头像
Sanders Olive2 年前

@CertiKSkyfall @Apple 👍

lamor gigi 的头像
lamor gigi2 年前

@CertiKSkyfall @Apple good news

相关视频

Multiple Americans are saying that someone has gained access to their iPhones While in the YouTube app, she suddenly hears on her phone typing, breathing, her ‘camera on’ indicator is lit up, she says the man was a foreign man speaking and typing Multiple other people have said recently similar things have happened while in YouTube I’ve looked into this and from what I can find it’s extremely rare, especially for the level of security Apple has For this to work for a hacker to take control of your phone or app - You would have had to have installed a malicious app or clicked a phishing link earlier. Something like a fake “YouTube update” or adult site redirect - Or physical access to your phone at some point to install spyware - Spyware or Remote Access Tool Once inside, the malware could request or silently use your camera and mic permission - It could run in the background and disguising itself as a legitimate process in your phone The “typing, clicking, breathing, man’s voice” she described could be the attacker live-monitoring or testing controls Even if you accidentally got this on your phone, the hacker would still likely be limited Likely saying in YouTube with background access only to your camera and mic while YouTube plays normally Even still, this is extremely creepy and not something you want to happen. This is exactly the type of thing you’d expect from an Indian scammer or something Down click bad links or ever grant permissions to things not trustworthy Luckily likelihood is very low on Apple iPhones with their security and sandboxing

Wall Street Apes

311,745 次观看 • 21 天前

This is a big update! visionOS 2.4 Beta is now available and I’m genuinely excited! The public release hits in April, but here’s the rundown of what’s available in visionOS 2.4 Beta today: • Apple Intelligence is coming to Vision Pro! All those rumors that said the first model wouldn’t get it. Dead wrong. We’re getting Image Playground to whip up fun images, Genmoji for custom emojis, and my personal favorite, Writing Tools. This is just the start of Apple Intelligence on Vision Pro and I’m excited to see where it takes us. • Guest User feature! Hand your Vision Pro to someone, and your nearby iPhone or iPad pings with an 'Allow Guest User' option. You pick their apps from your device, kick off View Mirroring with AirPlay to see what they’re seeing, and guide them through the experience. It’s clean, easy, and something many of us have been asking for. • A new Spatial Gallery app! Apple’s curating a stunning lineup of spatial photos, videos, and panoramas from artists, filmmakers, and brands like Cirque du Soleil and Porsche. Can’t wait to dive into that. • A new Vision Pro app for iPhone! Browse and queue up apps or games to download, discover spatial content from Apple TV and Spatial Gallery, and grab handy tips—all from your iPhone. It’ll roll out with iOS 18.4 wherever Vision Pro’s sold. I think it’ll be super useful. visionOS 2.4 is a big step up and it’s another strong signal that we have a lot to look forward to with spatial computing from Apple. We are just getting started.

Justin Ryan ᯅ

83,414 次观看 • 1 年前

New course: MCP: Build Rich-Context AI Apps with Anthropic. Learn to build AI apps that access tools, data, and prompts using the Model Context Protocol in this short course, created in partnership with Anthropic Anthropic and taught by Elie Schoppik Elie Schoppik, its Head of Technical Education. Connecting AI applications to external systems that bring rich context to LLM-based applications has often meant writing custom integrations for each use case. MCP is an open protocol that standardizes how LLMs access tools, data, and prompts from external sources, and simplifies how you provide context to your LLM-based applications. For example, you can provide context via third-party tools that let your LLM make API calls to search the web, access data from local docs, retrieve code from a GitHub repo, and so on. MCP, developed by Anthropic, is based on a client-server architecture that defines the communication details between an MCP client, hosted inside the AI application, and an MCP server that exposes tools, resources, and prompt templates. The server can be a subprocess launched by the client that runs locally or an independent process running remotely. In this hands-on course, you'll learn the core architecture behind MCP. You’ll create an MCP-compatible chatbot, build and deploy an MCP server, and connect the chatbot to your MCP server and other open-source servers. Here’s what you’ll do: - Understand why MCP makes AI development less fragmented and standardizes connections between AI applications and external data sources - Learn the core components of the client-server architecture of MCP and the underlying communication mechanism - Build a chatbot with custom tools for searching academic papers, and transform it into an MCP-compatible application - Build a local MCP server that exposes tools, resources, and prompt templates using FastMCP, and test it using MCP Inspector - Create an MCP client inside your chatbot to dynamically connect to your server - Connect your chatbot to reference servers built by Anthropic’s MCP team, such as filesystem, which implements filesystem operations, and fetch, which extracts contents from the web as markdown - Configure Claude Desktop to connect to your server and others, and explore how it abstracts away the low-level logic of MCP clients - Deploy your MCP server remotely and test it with the Inspector or other MCP-compatible applications - Learn about the roadmap for future MCP development, such as multi-agent architecture, MCP registry API, server discovery, authorization, and authentication MCP is an exciting and important technology that lets you build rich-context AI applications that connect to a growing ecosystem of MCP servers, with minimal integration work. Please sign up here!

Andrew Ng

142,010 次观看 • 1 年前