Unbiased AI-powered news
Cybersecurity firms reported that hackers took control of developer accounts and published malicious versions of widely used open source packages. The packages are relied on by software developers worldwide. The attack aims to steal credentials from downstream users.
medianama.comCybersecurity firms StepSecurity and SafeDep warned on Tuesday of an ongoing supply chain attack that has compromised dozens of popular open source packages. Hackers took over one developer account and released more than 630 malicious versions across 317 packages in roughly 20 minutes, according to SafeDep.
The packages are used by software developers around the world. The goal of the attack is to steal credentials for services including password managers, according to the firms. Malicious updates were also published on GitHub in some cases, JFrog Security reported.
One compromised package is Antv, a library developed by Alibaba. The current wave is part of a campaign researchers have named Mini Shai-Hulud. Last week, hackers compromised the computers of two OpenAI employees after gaining access through the open source library TanStack.
OpenAI was one of several victims in that wave. The attacks target open source projects and the developers who incorporate the code into their own applications.
Single source — no framing comparison available.
moneycontrol.comSony Music Entertainment sued AI music generator Udio in New York court on Monday. The complaint targets unauthorized use of more than 30,000 recordings to train the company's models.
sbs.com.auFrench lawmakers reached a compromise Monday on a bill that would bar children under 15 from social media accounts. The measure is expected to pass Tuesday and take effect in stages starting September.
newatlas.comZ.ai's GLM-5.2, released in June 2025, ranks as the top open-source model by some benchmarks and fifth on OpenRouter usage. DeepSeek's earlier R1 release in January 2025 triggered a trillion-dollar drop in U.S. tech values and calls for bans.