Posted on Leave a comment

🔒 Starlette 致命漏洞曝光!數百萬 AI 代理面臨被入侵風險

A critical vulnerability called “BadHost” (CVE-2026-48710) has been discovered in Starlette, an open-source Python framework that receives 325 million downloads per week. This affects FastAPI, vLLM, LiteLLM, and thousands of other projects that depend on Starlette.

The bug allows attackers to bypass path-based authorization by injecting a single character into the HTTP Host header. Since Starlette is the routing core of FastAPI and powers many MCP servers that store credentials for AI agent external connections, the exposure includes sensitive user databases, email accounts, and other resources.

Security researchers from X41 D-Sec rated it as “critical severity” (higher than the official 7/10 CVE rating) because it can lead to authentication bypass, SSRF exploits, and in some cases remote code execution. The vulnerability affects all Starlette versions prior to 1.0.1.

X41 D-Sec partnered with Nemesis to create an online scanner to check if servers are vulnerable. Researchers strongly recommend anyone running FastAPI, vLLM, or LiteLLM run the scanner immediately and upgrade to Starlette 1.0.1 or later.

Source: https://arstechnica.com/information-technology/2026/05/millions-of-ai-agents-imperiled-by-critical-vulnerability-in-open-source-package/

Posted on Leave a comment

🚨 美國執法機構警告「反科技極端主義」!AI 仇恨情勢升溫

Federal intelligence agencies and domestic law enforcement are circulating reports identifying “anti-technology extremists” as an emerging domestic threat category, according to over 1,000 pages of unpublished reports from DHS, FBI, and fusion centers obtained by WIRED.

This new focus follows President Trump’s National Security Presidential Memo 7, which instructs targeting of “anti-American,” “anti-Christian,” and “anti-capitalism” beliefs. A New York Intelligence Bureau report warns that AI adoption could fuel “large-scale protests that devolve into civil unrest and anti-tech violent extremist activity,” especially in major urban areas.

The reports also describe threats linked to extreme rationalists like Ziz Laota, whose ideology focused on existential AI risk. Meanwhile, 80 fusion centers across the country are gathering “intelligence” about alleged threats to data centers, flagging activities like photography and surveillance observation as suspicious.

Civil rights experts warn that overly broad categories like “anti-tech extremism” could ensnare peaceful protesters and AI skeptics, similar to the surveillance of Black Lives Matter and environmental movements in recent decades.

Source: https://arstechnica.com/ai/2026/05/us-law-enforcement-warns-of-anti-tech-extremism-as-ai-hatred-grows/

Posted on Leave a comment

🎬 YouTube 自動標記 AI 影片!這個標籤一旦出現就無法取消

YouTube is moving beyond voluntary AI disclosure to automatic detection and labeling of AI-generated content. Starting this month, the platform will use “new internal signals” to flag videos showing “significant photorealistic AI use.”

The system detects C2PA metadata indicating AI sources and Google watermarked tools like Veo. Creators can appeal incorrect labels, but those two triggers are permanent and non-appealable.

Previously, AI labels were hidden deep in video descriptions. Now they appear prominently: landscape videos show the tag below the player, while Shorts display an overlay at the bottom of the video.

However, animated AI content and videos with only minor AI elements will still only show labels in the expanded description. As AI video generation becomes more realistic, distinguishing real from synthetic content is becoming increasingly critical.

Source: https://arstechnica.com/google/2026/05/youtube-to-begin-automatically-labeling-ai-videos/

Posted on Leave a comment

🇺🇸 Illinois 通過全美最強 AI 安全法!OpenAI 和 Anthropic 居然都支持?

Illinois has become the first US state to pass a comprehensive AI safety law, requiring frontier AI companies to submit safety plans, undergo independent testing, and report critical incidents within 72 hours (24 hours for imminent threats).

The landmark bill SB 315 was signed by Governor J.B. Pritzker despite opposition from the Trump administration. Both OpenAI and Anthropic support the law, saying it establishes a needed baseline for AI safety testing.

The law will be enforced starting January 2027, with the Big Four accounting firms (Deloitte, EY, KPMG, PwC) expected to serve as independent auditors. Civil penalties will apply for violations.

Critics warn the law could create a patchwork of state regulations, while supporters say federal inaction has left states with no choice but to act.

Source: https://arstechnica.com/tech-policy/2026/05/trump-loses-more-control-over-ai-regulation-as-illinois-passes-landmark-law/

Posted on Leave a comment

🍎 Apple 密練「壓縮版 Gemini」塞進 iPhone!Siri 即將大改版,但隱私派用戶可能要失望了

Apple is trying to distill Google’s massive Gemini model onto the iPhone to power the next Siri – but cloud offloading means your data leaves the device.

According to The Information, Apple’s Gemini-powered Siri will run both on-device AND in the cloud, relying on Google and Nvidia infrastructure. Apple has long touted on-device AI as a privacy advantage, but the reality is phone hardware simply cannot handle multi-trillion parameter models.

The approach: distillation – making smaller models mimic larger ones. This works for basic tasks, but complex queries still go to the cloud via Nvidia’s Confidential Computing platform.

Bottom line: your Siri conversations will leave your phone. Once data leaves your device, it is no longer “on-device” AI.

Source: https://arstechnica.com/ai/2026/05/apple-reportedly-trying-to-distill-googles-multi-trillion-parameter-gemini-ai-to-run-on-iphone/

Posted on Leave a comment

輝達豪砸 1500 億美元押注台灣!黃仁勳:這裡才是 AI 革命的「絕對核心」

輝達(Nvidia)執行長黃仁勳最近丟出一個令全場震撼的宣布 ——每年砸 1,500 億美元投資台灣,確保這個島嶼繼續穩坐全球 AI 革命的「絕對核心」。

“這裡是晶片生產的地方、封裝的地方、系統組裝的地方、AI 超級電腦誕生的地方。我們在台灣的合作伙伴數量,令人難以置信。” —— 黃仁勳

從 2021 年的 100 多億到如今的 1,500 億美元,這不僅是數字上的變化,更是一個強烈訊號:台灣在全球 AI 供應鏈中的位置,幾乎無人可取代。

台灣:黃仁勳眼中的 AI 製造王國

根據路透社報導,這筆天價投資將用來打造輝達全新台灣總部。黃仁勳預期,這項合作將鞏固台灣作為「全球科技製造中心」的地位,而且這份榮耀將持續很久。

輝達目前是全球市值最高的公司,2025 年成為首家突破 5 兆美元市值 的企业。但黃仁勳說,台灣總部將確保輝達未來 3 到 5 年的市值「只增不減」。

美國 vs 台灣:AI 製造的拉鋸戰

去年 4 月,輝達首次在美國本土生產 AI 晶片 — 表面上看來是向川普妥協,畢竟增加國內製造業是川普「AI 行動計劃」的重要核心。

但現實很殘酷:輝達的晶片依然需要運回台灣進行先進封裝。現在,黃仁勳選擇了直視現實,把更多資源投入台灣,同時宣稱 Agentic AI 的龐大需求正在加速全球 AI 工廠的建設。

晶片巨頭的 7,500 億美元大戰

今年各大科技巨頭合計將斥資 7,500 億美元 投入 AI 基礎設施建設,其中「顯著部分」將用於資料中心晶片。輝達還必須為全新的 Vera Rubin AI 系統做準備,黃仁勳稱其將是「世代的跨越」,並會啟動「史上最大規模的基礎設施建設浪潮」。

輝達擔心 Vera Rubin 的整個生命週期中都會面臨供應鏈瓶頸。

川普的中國晶片計劃:意外受挫

另一方面,川普要求輝達晶片向中國出售時收取 25% 稅費的計劃,似乎適得其反。中國拒絕購買這些晶片 — 原因不是願意支付稅費,而是要求所有晶片必須經過美國轉運,北京擔心美國可能在晶片上動手腳。

輝達在最近一次投資人大會上坦承,他們已「基本上放棄」中國市場,轉向華為。黃仁勳更直言:

“放棄像中國這麼大的市場,從策略上看並不明智。”

未來:關稅陰霾

目前半導體被豁免於關稅之外,但這可能很快改變。川普政府正考慮對進口半導體徵收關稅,以促進本土晶片生產。

截至上周,美國貿易代表 Jamieson Greer 表示「沒有任何立即實施新規費的計劃」,但強調了「利用進口關稅將晶片生產帶回美國」的重要性。

原文來源:Ars Technica — Nvidia bets $150B on Taiwan(作者:Ashley Belanger,2026 年 5 月 28 日)

Posted on Leave a comment

🧠 科技老總的 AI 焦慮症:矽谷 CEO 集體失眠的地緣政治

然而,AI 的狂飆突進並非沒有代價。知名科技記者 Julie Bort 近日撰文指出,許多科技公司的 CEO 們正遭受「AI 精神病(AI Psychosis)」的折磨。這是一種因為長期處於高速競爭、害怕錯過下一個技術奇點(FOMO),以及過度依賴 AI 決策而產生的極度焦慮、失眠甚至偏執狀態。這種現象在矽谷尤其普遍。許多科技新創公司的創辦人為了跟上 AI 的發展步伐,不惜犧牲睡眠和健康,導致整個產業的心理健康危機日益嚴重。這也引發了對科技產業文化的深刻反思:我們是否應該重新思考「快速迭代」的價值觀?在地緣政治方面,局勢同樣緊張。中國正日益嚴格地限制其頂尖 AI 人才流向海外,試圖將最優秀的大腦留在國內,以加速本土 AI 基礎設施的發展。這場「AI 人才戰」正在改變全球矽谷的人才流動版圖。美國方面,川普總統則以部分條款「可能成為阻礙」為由,暫緩簽署此前承諾的 AI 安全行政命令。這反映出美國內部在「促進 AI 發展」與「確保 AI 監管」之間的巨大拉鋸戰。這些問題無法單純靠演算法解決,需要政策制定者、企業領袖和我們每個人共同面對。AI 是工具,也是放大器。它既能創造前所未有的生產力,也能放大既有的人類焦慮。或許,當我們沉迷於技術進步時,更應該思考的是:如何確保 AI 的發展不會以犧牲從業人員的心理健康為代價?如何在創新與可持續發展之間找到平衡?這才是 2026 年 AI 產業真正需要面對的挑戰。