733 Tech Tips (Public)
前往频道在 Telegram
733 的个人频道 主推:AI 新闻、AI 技巧、程序员梗图/乐子
显示更多未指定国家未指定类别
322
订阅者
+124 小时
+77 天
+1630 天
帖子存档
Repost from N/a
速报: DSv4 Flash Vision Exp (deepseek-v4-flash-vision-exp) 现已上线 DeepSeek 官方 API Platform!
{
"object": "list",
"data": [
{
"id": "deepseek-v4-flash",
"object": "model",
"owned_by": "deepseek"
},
{
"id": "deepseek-v4-pro",
"object": "model",
"owned_by": "deepseek"
},
{
"id": "deepseek-v4-flash-vision-exp",
"object": "model",
"owned_by": "deepseek"
}
]
}+1
现在 OpenAI 会根据 ChatGPT 的搜索内容判断你处在的国家
在最近的一次研究中,我们用了七个 ChatGPT Pro 账号来测试。在统一 IP 环境(同一个日本 ASN)、订阅日期、订阅卡头的情况下,对每个号发出了不同地区指向的搜索请求。
图中这个号是在发出了七十余次,针对华为鸿蒙系统文档的搜索请求后被封禁的,间隔仅一小时。其他账号目前均没有被封号。
#OpenAI #RNM退钱
+2
发掘了一个 ChatGPT Task 的新用法
Read all emails from both Gmail and Microsoft Outlook received during the previous daily window from 06:00 yesterday to 06:00 today in Asia/Shanghai (UTC+8). Identify actionable items that belong on my Google Calendar, especially invoice/payment due dates, contest/application deadlines, form/submission deadlines, registration deadlines, renewals, expirations, appointments, and similar time-sensitive obligations. Create calendar entries on my main Google Calendar for the actual due date/time stated in the email. Include a concise title, the relevant deadline or amount when useful, and enough source-email context in the description to identify the sender and subject. Avoid creating duplicates when an equivalent calendar entry already exists. Ignore newsletters, promotions, FYI messages, and items with no actionable deadline.然后每天早上 ChatGPT 会读你的 Gmail 和 Outlook,然后把 VPS 账单、各种 ddl 写到 Google Calendar 去。
OpenAI 写的 codex-security plugin 挺不错的,给出的报告在其他 session 中也会影响到 gpt 的行为。
比如在新 session 中引用 report.md,然后 gpt 在写测试用例时,会先复现问题再修。
#Codex
Repost from N/a
+2
GPT-Image-2.5 疑似上架 Arena 竞技场,代号为
mona-lisa-1
人物一致性相比 GPT-Image-2 进步显著,由 SynthID 带来的画面撕裂感也大大降低
更多证明材料和信源: https://linux.do/t/topic/2725870Repost from 在花🎗️科技圈
sub2api 曝 OAuth 高危漏洞,仅凭邮箱即可接管账户
sub2api v0.1.171 及之前版本存在一个 CVSS 8.8 的高危 OAuth 账户接管漏洞。攻击者仅需知道受害者注册邮箱,无需密码或验证码、无需用户交互,即可通过接口将自己的 OAuth 身份绑定到受害者账户,完全控制其 API 密钥、账单余额与订阅配额。
攻击者利用 pending session 流程中 existingUser 分支不校验密码和验证码的缺陷,将目标用户 ID 设为受害者后完成 OAuth 身份绑定。此后攻击者每次 OAuth 登录均会解析为受害者账户。
Github Issues
🌸 在花频道 · 茶馆水群 · 投稿通道
