‼️ Update: Elon Musk says SpaceXAI will delete all user data uploaded to the company "before now" as a precautionary measure, one day after a researcher's wire-level analysis showed the Grok Build CLI shipping entire private repos, unredacted secrets included, to a Google Cloud bucket.
The pledge came in an X post. Still no advisory, no timeline, and no way for affected developers to verify deletion. And deleted or not, any credentials that left the machine still need to be rotated.
AMERICANS ARE FALLING BEHIND ON LOAN AND CREDIT CARD PAYMENTS AT THE FASTEST PACE SINCE THE 2008 FINANCIAL CRISIS, WITH CREDIT CARD DEFAULTS HITTING NEAR-15 YEAR HIGHS
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you.
The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads.
The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate.
Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.
🤯 Ollama now supports Claude Desktop via Claude’s built-in third party inference.
ollama launch claude-desktop
This allows all models from Ollama's Cloud to be used across Claude Cowork and Claude Code from the Claude Desktop app.
🦞👾 LM Studio is now an official @openclaw provider!
Run:
openclaw onboard --auth-choice lmstudio
Use your local models with your OpenClaw - it's private and free.
Works on Mac, Windows, and Linux.
Let's Claw 🦞🦀
Today, our Board of Directors approved a proposed rule that would establish requirements under the GENIUS Act for FDIC-supervised stablecoin issuers.
https://t.co/VAnMhwyGo5