Aikido Security tracks Shai-Hulud npm package infection surge
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing Shai-Hulud malware. The security […]
Alibaba Qwen3.8-Max claims 16-day autonomous coding run
Alibaba’s Qwen team has released Qwen3.8-Max, a 2.4 trillion parameter model with 95 billion active parameters, pitched at coding, office work, research, […]
Amazon ties DPRK hackers to axios and three other NPM attacks
Amazon Threat Intelligence has tied a DPRK hacking group to four separate NPM package supply chain attacks, including axios. The company’s security […]
VulnCheck data questions AI vulnerability discovery risk
New research from VulnCheck complicates warnings that AI-assisted vulnerability discovery is making exploitation more dangerous. The vulnerability research firm published its H1 […]
GitHub adds approval checks for suspicious Actions workflows
GitHub has introduced an automatic approval step for certain GitHub Actions workflow runs in public repositories. The measure is intended to stop […]
Microsoft targets vulnerability scanning costs
Microsoft has released MAI-Cyber-1-Flash, a security model built into MDASH that finds vulnerabilities at half the cost of alternatives. Redmond announced the […]
Open Secure AI Alliance aims to open-source AI security defences
A new group of major firms, the Open Secure AI Alliance, are setting out to build open-source AI tools for security defences. […]
Codeberg members vote to reject LLM training and vibe coding
Codeberg members voted to reject LLM training on platform data and to restrict vibe-coded projects hosted on the forge. The German non-profit […]
GitHub Actions abuse turned Packagist repos into scanners
According to Socket, GitHub Actions abuse in Packagist repos ran cPanel scanning from temporary cloud runners. The incident began with malicious development […]
Cisco open-sources Antares AI models for vulnerability detection
Cisco has released two open-weight security models designed to search software repositories for files linked to known vulnerability categories. Antares-350M and Antares-1B […]
models escaped via package proxy
Criminals did not run the autonomous agent that compromised Hugging Face’s production infrastructure last week. OpenAI disclosed on Tuesday that the campaign was driven […]
Hugging Face confirms AI agent breached production systems
Hugging Face confirmed attackers used an autonomous AI agent to breach its production infrastructure and steal cloud credentials. The platform, which hosts […]