<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Yongjie Xue</title><link>https://www.yongjiexue.io/en/tags/security/</link><description>Recent content in Security on Yongjie Xue</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Wed, 22 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.yongjiexue.io/en/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>AGI Milestone: The Machine That Wouldn't Give Up</title><link>https://www.yongjiexue.io/en/ai/agi-milestone/</link><pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate><guid>https://www.yongjiexue.io/en/ai/agi-milestone/</guid><description>An OpenAI agent&amp;rsquo;s attack on Hugging Face marks a milestone: what crossed the threshold was not merely model intelligence, but persistence that can be bought with compute, copied, and run in parallel.</description></item><item><title>Xianyu, Qianwen, Alipay: Platform Trust 'Empowers' a Scam</title><link>https://www.yongjiexue.io/en/cloud/ali-scam/</link><pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate><guid>https://www.yongjiexue.io/en/cloud/ali-scam/</guid><description>Scammers hijacked Qianwen&amp;rsquo;s trusted identity, then used a single Xianyu QR code to run a seamless phishing scam through official apps and trusted domains across Alibaba&amp;rsquo;s ecosystem. I hope this case helps more people avoid the same trap.</description></item><item><title>Two months into maintaining a MinIO fork</title><link>https://www.yongjiexue.io/en/db/minio-promise-kept/</link><pubDate>Fri, 17 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.yongjiexue.io/en/db/minio-promise-kept/</guid><description>Two months after forking MinIO, pgsty/minio ships patches for four CVEs and related security issues. No new features — just working builds, a restored console, and timely security fixes.</description></item><item><title>Meituan Deleted Users' Photos: Overbroad Permissions Are Worse Than a Privacy Leak</title><link>https://www.yongjiexue.io/en/cloud/meituan-purge-photo/</link><pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate><guid>https://www.yongjiexue.io/en/cloud/meituan-purge-photo/</guid><description>Many Android users reported that Meituan deleted files from their photo libraries. The bigger issue is not just this bug, but the still-common pattern of overbroad storage permissions in the Chinese Android ecosystem.</description></item><item><title>360 Shipped Its Wildcard TLS Private Key Inside a Public Installer</title><link>https://www.yongjiexue.io/en/db/claude-360-claw/</link><pubDate>Mon, 16 Mar 2026 00:00:00 +0000</pubDate><guid>https://www.yongjiexue.io/en/db/claude-360-claw/</guid><description>360&amp;rsquo;s newly released AI Agent product shipped a public installer containing the private key for its *.myclaw.360.cn wildcard certificate. Public verification and local reproduction also exposed inconsistencies in the OCSP revocation path.</description></item><item><title>OpenClaw Hype: Foam on Top of the Productivity Revolution</title><link>https://www.yongjiexue.io/en/ai/openclaw-hype/</link><pubDate>Mon, 09 Mar 2026 00:00:00 +0000</pubDate><guid>https://www.yongjiexue.io/en/ai/openclaw-hype/</guid><description>OpenClaw looks exciting because it turns agents into a chat-style experience. But the real productivity gains come from high-capability subscription agents and disciplined workflows, not from lobster-flavored wrappers.</description></item><item><title>Don't run AI assistant on cloud</title><link>https://www.yongjiexue.io/en/ai/cloud-agent/</link><pubDate>Fri, 30 Jan 2026 00:00:00 +0000</pubDate><guid>https://www.yongjiexue.io/en/ai/cloud-agent/</guid><description>&lt;p&gt;Before you hit &amp;ldquo;one-click deploy&amp;rdquo; on that cloud AI assistant, ask yourself: what exactly are you giving up?&lt;/p&gt;&#10;&lt;p&gt;There&amp;rsquo;s a reason why people by Mac mini rather than running clawdbot on the cloud.&lt;/p&gt;&#10;&lt;h2 id="when-ai-becomes-your-butler"&gt;When AI Becomes Your Butler&#10;&lt;/h2&gt;&#10;&lt;p&gt;Moltbot (formerly Clawdbot) just exploded on GitHub. Tens of thousands of stars in days. Mac Minis sold out.&lt;/p&gt;</description></item><item><title>CVE-2024-6387 SSH Vulnerability Fix</title><link>https://www.yongjiexue.io/en/db/cve-2024-6387/</link><pubDate>Thu, 04 Jul 2024 00:00:00 +0000</pubDate><guid>https://www.yongjiexue.io/en/db/cve-2024-6387/</guid><description>This vulnerability affects EL9, Ubuntu 22.04, Debian 12. Users should promptly update OpenSSH to fix this vulnerability.</description></item></channel></rss>