
A Poisoned Rust Crate Was Live for 86 Minutes. It Had 245 Million Downloads.
Malicious releases of arrayref, internment and append-only-vec pulled an infostealer through a typosquatted proc-macro1 dependency during compilation.
Author
Articles by Seung Jung on AI Newsway. Browse published reporting on AI, technology and productivity.
Company website: ZZEM
https://zzem.co.kr
Malicious releases of arrayref, internment and append-only-vec pulled an infostealer through a typosquatted proc-macro1 dependency during compilation.

MCP's maintainers published five priority areas covering long-running agent work, transport unification, agent identity and the context cost of tool sprawl.

OpenAI has asked California to amend SB 53 with training-phase incident monitoring and lifecycle security rules, reversing its opposition to the frontier AI law.

London lab Inherent says its Faraday agent, running on a 27B-parameter model, beat Claude Opus 4.8 and GPT-5.5 at reproducing published scientific findings.

Prime Intellect ran 153 autonomous jobs across 18 frontier models on the nanoGPT speedrun, and the token accounting tells a different story than the ranking.

Anthropic's Browser Use toolset lets Claude target page elements by reference via the accessibility tree, while developers run the browser themselves.

Anthropic pledges $35M in credits for open-source security and opens Mythos 5, the model it withheld from release, to enterprise vulnerability scanning.

Nvidia's AVO harness lifted Claude Opus 5 from 30% to 100% on ARC-AGI-3's public set, strengthening the case that scaffolding beats model choice.

Slack Code launches with Claude, Devin, GitHub Copilot and Vercel. Agents open the channels, humans review or stop them, and archives serve as audit logs.

A new arXiv paper induces structured, auditable task models from raw computer-use traces, matching ground-truth task groupings at 0.974 agreement.

AI4AI-Bench scored six agent systems at 0.166 for rewriting training algorithms. A second paper found seven ways self-improvement gains get miscounted.

Debian developers vote through August 28 on nine proposals covering LLM-assisted contributions, from an outright ban to responsible-use guidelines.

Google now lets publishers embed a Preferred Sources button on their own sites, letting readers pin them across Search, Discover, and News in one tap.

GitHub's postmortem ties its 7h47m August 17 outage to capacity limits and retry storms, not code, as monthly commits doubled to 2.9 billion since April.

Adversa researchers bypassed Grok's safety filters by encrypting malicious instructions with AES-256-GCM, letting the model decrypt and execute them itself.

Pew Research analyzed nearly half a million Common Crawl pages and found 35% of post-ChatGPT pages show AI authorship signals, concentrated on .com domains.

Five US agencies say attackers are using AI coding assistants and the open source snap7 library to build tools that read and write Siemens S7 controller memory.

Go 1.27 adds generic methods, backs encoding/json with a new v2 engine, cuts small-object allocation cost by up to 30 percent and brings ML-DSA into crypto/tls.

DeepReinforce's Ornith-1.5 posts 86.1 on Terminal-Bench 2.1 against Claude Opus 4.8's 85.0, and ships a 9B variant small enough to run on a phone.

An SEC filing shows Google tapped Marvell for TPU-adjacent custom silicon with a $12.2 billion warrant, ending Broadcom's sole-supplier position.