🧵 What if you could search your own memories? That’s the vision behind #NTCIR19 Lifelog-7. The task features four subtasks, including the new CASTLE collection with audio, video, chat transcripts, and interaction logs supporting three retrieval challenges. (1/5)
We just shipped NVIDIA-Verified Agent Skills 🔐
Skills make your agent more capable, but can also introduce vulnerabilities. Verified skills give you transparency into what a skill does, where it came from, what risks it carries, and whether it's been modified.
Every verified skill carries a skill card and is built on the https://t.co/ijhll6w6yh open specification to work reliably across @claudeai Code, @openai Codex, and @cursor_ai.
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments.
The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran.
To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
‼️🚨 UPDATE: The TanStack npm attack is now a full campaign.
'Mini' Shai-Hulud has hit:
- OpenSearch
- Mistral AI
- Guardrails AI
-UiPath
- Squawk packages across npm and PyPI
The malware specifically targets AI developer tooling. It hooks into Claude Code (.claude/settings.json) and VS Code (.vscode/tasks.json) to re-execute on every tool event, long after the infected package is gone. npm uninstall does not fix this.
✏️News Release
Release of New Japanese LLMs, "LLM-jp-4 8B" and "LLM-jp-4 32B-A3B", Trained on a High-Quality Corpus of Approximately 12 Trillion Tokens under an Open-Source License
Surpassing GPT-4o and Qwen3-8B on Several Standard Benchmarks
https://t.co/7bYEojGhWc
Dear Friends, this is Masato's wife Lynn typing. It is with a heavy heart that I share that Masato passed away peacefully yesterday. Thank you for keeping him in your thoughts. You can follow this page for memorial details: https://t.co/0Fgqa1RCaE
Introducing TurboQuant: Our new compression algorithm that reduces LLM key-value cache memory by at least 6x and delivers up to 8x speedup, all with zero accuracy loss, redefining AI efficiency. Read the blog to learn how it achieves these results: https://t.co/CDSQ8HpZoc