足不出户 走遍全世界
当前位置: 主页 > 未解之谜 > 世界之谜
更新时间:2026-08-26   来源:互联网   编辑:宗徒邓龙  点击数: 911081次  

星际迷航2

Politics-driven Graham-named Russia sanctions bill exposes US political coercion in global energy supply chains: expert_我的网站

人的价值

A |     

 File picture of US Capitol. Photo: VCG
    File picture of US Capitol. Photo: VCG
The US Senate on Friday overwhelmingly approved a bill that would impose sanctions on buyers of Russian oil, a measure that had long been championed by the late senator Lindsey Graham before his death last month, CNBC reported. A Chinese expert criticized the legislation, warning that if implemented, the bill, driven largely by political motives aimed at catering to US domestic political correctness, could severely disrupt the already fragile global energy market and economy. He also noted that the bill is essentially a tool of political coercion, weaponizing tariffs and unilateral sanctions to hijack normal global energy trade and override sovereign economic choices of independent nations.
The legislation, named The Lindsey O. Graham Sanctioning Russia and Iran Act of 2026, aims to hurt Russia's war effort in Ukraine by penalizing purchasers of Russian oil and Russian leaders. It passed with bipartisan support 86-11 and will now proceed to the House, which is on recess until September, per CNBC.
The bill would impose tariffs of up to 100 percent on countries that are among the top five purchasers of Russian crude oil or gas, which includes China and India.
It also includes sanctions targeting Russian leaders, officials, targeting Russian leaders, oligarchs and financial institutions. At the request of US President Donald Trump, the bill extends sanctions on Iran's weapons and energy sectors, CNBC reported.
Notably, the bill's excessive tariff discretion has sparked fierce internal doubts within US political circles. Representatives Gregory Meeks of New York and Don Beyer of Virginia said in a statement they still had "fundamental concerns" about the tariff powers for the president, who has made them a central piece of his "America First" approach to foreign policy.
"What the bill does grant ... are sweeping new tariff authorities that the president could weaponize with abandon, as he has repeatedly done in the past," said Meeks, the top Democrat on the House Foreign Affairs Committee, and Beyer, the senior Democrat on the Joint Economic Committee, according to Reuters.
Chinese experts have strongly criticized the bill's politically driven nature, its economic coercion, and its severe spillover risks to the global economy.
The bill, aimed at putting pressure on Russia, would disrupt global energy markets and create new uncertainties for the world economy if implemented, Yang Jin, associate research fellow at the Institute of Russian, Eastern European and Central Asian Studies under the Chinese Academy of Social Sciences, told the Global Times.
Many economies retain legitimate, market-based energy cooperation with Russia out of practical economic and energy security needs. Russia's energy exports have long been a key component of the global energy system, with countries including India and some European nations continuing to rely on Russian oil and gas, said Yang, noting that even some European countries have received exemptions to maintain energy imports from Russia, underscoring the role of Russian supplies in supporting economic stability.
India's reliance on Russian crude increased further after the conflict in West Asia disrupted shipping through the Strait of Hormuz. With Gulf supplies affected during the US war on Iran, Indian refiners turned more heavily towards Russian oil as an alternative source, Indian media Hindustan Times reported on Saturday after US Senate passed the bill.
When asked about the bill on July 15, Lin Jian, spokesperson from China's Ministry of Foreign Affairs said that China firmly opposes unilateral sanctions that have no basis in international law or authorization of the UN Security Council, and will take necessary measures to firmly defend the legitimate rights and interests of Chinese businesses and citizens.
Practicing double standards and resorting to coercion and pressuring will eventually prove to be self-defeating, said Lin.
Yang further pointed out that the push for the bill, labeled after Lindsey Graham, who was known as one of the toughest Russia hawks in Washington, lays bare Washington's distorted domestic political logic.
The legislation, which represents another typical case of US hegemonic long-arm jurisdiction, is largely designed to ease US domestic governance pressure. As the Trump administration fails to deliver substantive progress in de-escalating the Russia-Ukraine conflict as promised, ramping up external sanctions and forcing third-party sovereign countries into abandoning normal economic and trade cooperation has become a convenient political tool for US politicians to showcase tough posturing and ease domestic pressure, Yang said.
。    北京时间7月22日,OpenAI在官方博客发文,承认其模型在一起安全评测事故中攻击了全球最大AI开源平台Hugging Face。

B |          OpenAI发文承认,其模型在一次安全评测中攻击了Hugging Face的生产环境          这是行业首次公开披露、模型评测失控直接升级为跨企业真实生产环境网络攻击的安全事件。         事件的起点是一场模型能力测试,一场原本被关在隔离沙箱里的模型安全测试,最终演变成针对全球最大AI开源平台Hugging Face的真实网络攻击。模型在评估中为了“作弊”拿到高分,自主发现并串联多个零日漏洞(0 day,软件厂商尚未知晓、没有发布补丁修复的安全缺陷),逃逸出隔离环境,攻入Hugging Face生产数据库窃取答案。

C |          在攻击发生后的事后追查阶段,面对超过1.7万条攻击日志,Hugging Face求助商业大模型,被对方的安全护栏集体拒之门外,最终完成取证分析的,是中国公司智谱的开源模型GLM-5.2。         为作弊,模型自己越狱了          据OpenAI披露,涉事模型为GPT-5.6 Sol以及一款能力更强的预发布模型。它们当时正在参加名为ExploitGym的内部评测,该基准包含898个真实软件漏洞利用任务,专门测试AI能否把真实软件漏洞一步步变成可以实际运行的攻击。         为了尽可能摸到模型能力上限,OpenAI特意降低了生产环境级别的安全拒绝机制,鼓励模型尽可能寻找复杂的攻击路径。         按照OpenAI最原本的设计,模型接触外部资源的唯一通道,是一套由OpenAI内部托管的第三方软件。         模型开始确实投入了大量推理算力,专门寻找获得公网访问权限的方法,在OpenAI内部包注册表的缓存代理中发现了一个此前未知的零日漏洞,随后在OpenAI研究测试环境中完成特权提升和横向移动,成功连接外网。         联网之后,模型推断Hugging Face可能托管着ExploitGym的测试答案,随即发动攻击。

D |          它先通过恶意数据集,利用远程代码数据加载器和数据集配置中的模板注入两处代码执行路径,在Hugging Face的工作节点上执行代码,随后在周末期间提升至节点级权限,收割云端和集群凭证,横向移动至多个内部集群,最终攻入生产数据库,直接窃取测试解法。         OpenAI表示入侵发生在7月11日周末,全程由自主AI智能体系统端到端驱动,背后是大量短生命周期沙箱组成的集群,执行了数千个独立动作。

E | Hugging Face基于大模型的异常检测管道首先标记了入侵,OpenAI安全团队也在内部发现异常,双方启动联合取证。         7月16日Hugging Face首次披露时称,这次事件“与我们之前处理过的任何情况都不同”。直到一周后OpenAI发文认领,它才知道攻击者是谁。         美国模型拒绝查案,中国开源模型接手          取证阶段,Hugging Face遇到了意想不到的难题。         为了分析超过1.7万条攻击事件记录、重建时间线、确认被接触的凭证,还要区分真实破坏和干扰调查的诱饵活动,靠人工逐条梳理通常需要数天。         Hugging Face最初尝试调用商业前沿大模型的API,但请求被安全护栏拦截。触发拦截的原因是日志里包含真实的攻击命令、漏洞利用载荷和命令与控制痕迹数据,护栏无法区分提交材料的是事件响应者还是攻击者。         最终,Hugging Face在自有基础设施上部署了GLM-5.2,由它遍历全部攻击记录并完成取证分析,将数天的工作压缩至数小时。         Hugging Face特别指出,这样做还有一个额外优势:攻击数据及涉及的凭证始终留在本地环境,没有离开企业基础设施。         这场事故意外完成了一次开源模型的全球路演。         Hugging Face将困境总结为“安全不对称”:攻击者可以使用完全不受限的模型,防守方却可能被云端模型的护栏拒之门外。该公司由此建议,企业应提前准备经过验证、能够在本地运行的高能力模型。         这场事故,其实也让开源模型多了一个此前存在感不算太强、如今却相当现实的位置:安全团队的应急工具。         对金融、政务、医疗等数据敏感行业而言,模型权重自主可控、数据不出企业边界、关键时刻不被服务商的审核机制卡住,正在从加分项变成刚需。         不过值得注意的是,开源模型开放权重同样降低了攻击者的门槛,安全不对称是一把双刃剑,这也是全球监管讨论开源治理时最纠结的一环。         失控预演之后,竞争已经换轨          这样的失控并非没有预演。         今年4月,Anthropic在Claude Mythos Preview的System Card中披露,红队演练中模型成功逃逸加固沙箱,随后超出指令范围自主行动:给正在公园吃三明治的研究员发邮件报告成果,未经允许将漏洞细节发布到公开网站,还在另一次测试中改写git历史掩盖改动。         Anthropic因此决定不对公众开放该模型,仅通过Project Glasswing计划向苹果、谷歌、微软、摩根大通等12家机构开放用于防御。

F |          值得注意的是,相比Anthropic的模型是被明确要求尝试逃逸,本次OpenAI的模型没有收到任何逃逸指令,它是为了在测试中作弊拿到高分,自发越狱并攻击了一家无辜的第三方公司。         在业内看来,这起事件标志着AI的自主攻击能力从理论走向现实。         OpenAI研究员Micah Carroll在回应中写道:“如果这都不能让你相信错位风险将成为未来的关键隐忧,那我真不知道什么才可以。

G | ”          模型能力越强,失控作恶的潜在威胁越大,传统隔离防护持续承压,自主AI网络攻击或将成为长期常态化风险。

Current article:http://wh0t.kuogahuaishaishei.buzz/x99/khcuzm.html

Published on:20:16:47


关于奇站|联系我们|网站地图|网站地图|征稿启事|意见反馈|免责声明|法律声明|版权声明|不良信息举报

Copyright @ 2020-2099 星际迷航2网站版权所有