Scan to download
BTC $74,801.92 -0.36%
ETH $2,325.73 -1.40%
BNB $628.22 +0.41%
XRP $1.43 +1.41%
SOL $87.73 +2.65%
TRX $0.3259 +0.07%
DOGE $0.0969 +0.32%
ADA $0.2530 +1.13%
BCH $448.70 +1.30%
LINK $9.36 +0.65%
HYPE $43.55 -4.10%
AAVE $112.32 +5.43%
SUI $0.9787 +0.36%
XLM $0.1648 +2.71%
ZEC $331.13 -3.12%
BTC $74,801.92 -0.36%
ETH $2,325.73 -1.40%
BNB $628.22 +0.41%
XRP $1.43 +1.41%
SOL $87.73 +2.65%
TRX $0.3259 +0.07%
DOGE $0.0969 +0.32%
ADA $0.2530 +1.13%
BCH $448.70 +1.30%
LINK $9.36 +0.65%
HYPE $43.55 -4.10%
AAVE $112.32 +5.43%
SUI $0.9787 +0.36%
XLM $0.1648 +2.71%
ZEC $331.13 -3.12%

mal

The Ministry of Industry and Information Technology of China: Explore innovative businesses such as "computing power banks" and "computing power supermarkets" to support small and medium-sized enterprises in depositing idle computing power resources

According to a report by Jinshi Data, the General Office of the Ministry of Industry and Information Technology has issued a notice on launching a special action to empower the development of small and medium-sized enterprises (SMEs) through inclusive computing power, mentioning the innovative service model of computing power.Improve the SME section of the China Computing Power Platform, the computing resource docking section of the China SME Service Network, and the national computing internet service node section (hereinafter collectively referred to as the SME platform section), to promote the precise matching of SME demand and computing resource supply, and implement flexible payment models such as "card time," "calculated time," and Token billing.Explore innovative businesses such as "computing power banks" and "computing power supermarkets," supporting SMEs to deposit idle computing resources and achieve flexible use through cross-regional and cross-cycle scheduling. Implement an artificial intelligence SME entrepreneurship support plan, encouraging local relevant departments to subsidize "computing power vouchers," "storage vouchers," and "transportation vouchers" to SMEs that meet industrial orientation through the SME platform section, simplifying the acquisition and usage process.

Slow Fog: Pay attention to checking for malicious versions of axios and the exposure risk of global installation history for OpenClaw npm

Slow Fog has once again issued a security reminder stating to pay attention to checking for malicious versions of axios and the exposure risk of OpenClaw npm global installation history. [email protected] and [email protected] have been confirmed as malicious versions, both of which have injected the dependency [email protected], delivering cross-platform malicious payloads through the postinstall script.The impact of OpenClaw is assessed based on scenarios: source code builds are not affected, as the locked versions in the lock file are 1.13.5/1.13.6; however, users who installed via npm install -g [email protected] face historical exposure risks due to the presence of optionalDependencies.axios@^1.7.4 in the dependency chain, which may resolve to [email protected] during the time window when the malicious version is still online. Currently, npm has reverted the resolution to [email protected], but environments that were installed during the attack window are still advised to be checked. Slow Fog has provided inspection commands and IoC paths for various platforms; if the plain-crypto-js directory is found, even if the package.json has been cleaned, it should still be regarded as high-risk execution traces. It is recommended that affected hosts immediately rotate credentials and conduct host-side inspections. Previously, Slow Fog founder Yu Xian reminded that OpenClaw version 3.28 may introduce a toxic version of axios, and users need to urgently check.
app_icon
ChainCatcher Building the Web3 world with innovations.