<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>安全与治理 on 海风自语 · 技术与教育笔记</title><link>https://www.szlanmin.com/tags/%E5%AE%89%E5%85%A8%E4%B8%8E%E6%B2%BB%E7%90%86/</link><description>Recent content in 安全与治理 on 海风自语 · 技术与教育笔记</description><generator>Hugo</generator><language>zh-CN</language><lastBuildDate>Fri, 09 Oct 2026 23:20:00 +0800</lastBuildDate><atom:link href="https://www.szlanmin.com/tags/%E5%AE%89%E5%85%A8%E4%B8%8E%E6%B2%BB%E7%90%86/index.xml" rel="self" type="application/rss+xml"/><item><title>AI 接物理设备前的停机权：LMCache 9.8 分漏洞与 Anthropic 新使用条款</title><link>https://www.szlanmin.com/tech/ai/ai-emergency-stop/</link><pubDate>Fri, 09 Oct 2026 23:20:00 +0800</pubDate><guid>https://www.szlanmin.com/tech/ai/ai-emergency-stop/</guid><description>JFrog 于 2026 年 10 月 7 日披露 LMCache 的 CVE-2026-105192，CVSS 9.8 分且至今无修复版本；同周 Pwn2Own 用参数注入打穿 OpenAI Codex。Anthropic 则把「物理行动须有合格操作员能监视并停机」写进使用条款。本文从架构师视角拆解：自托管推理栈的攻击面，以及停机权该落在哪一层。</description></item></channel></rss>