Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments.
The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran.
To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
This is crazy. The hacker installed a dead-man's switch that will wipe your computer if you revoke the GitHub token they stole from you. Revoking the token is what triggers the wipe.
Xbox CEO Asha Sharma says they need to "deepen their connection" with the community and retire features that don't align with their future plans
"We will begin winding down Copilot on mobile and will stop development of Copilot on console"
TODAY: Amazon is opening its entire logistics network—freight, distribution, fulfillment, and parcel shipping capabilities—to every business, of all types and sizes. 📦
Amazon has built one of the most reliable and efficient supply chains on Earth. Now, Amazon Supply Chain Services gives all businesses access to the same infrastructure that moves, stores, and ships goods for hundreds of thousands of Amazon sellers.
Healthcare, automotive, manufacturing, retail, and more. Businesses across industries can now tap into Amazon's logistics network. Learn more here. ⬇️
Marc Brooker ( @MarcJBrooker ) is a Distinguished Eng at AWS who has been building distributed systems there for almost 2 decades. I interviewed him about technical learnings from his experience. We discussed:
• Learnings from 3000+ post mortems
• When caching is a bad idea
• How software engineering is changing
• Visibility and apparent expertise
• How to find the best problems
Where to watch:
• YouTube: https://t.co/kmBAAiMbos
• Spotify: https://t.co/U5AhiGZX58
• Apple Podcasts: https://t.co/jOYDGtHtd1
• Transcript: https://t.co/dc6aoO1RLE
Announcing Amazon S3 Files.
The first and only cloud object store with fully-featured, high-performance file system access.
Learn more here. https://t.co/rNuWa5Rsi2
These four astronauts are currently on a mission to fly around the Moon—and soon they'll break the record for how far humans have traveled from Earth!
Meet our Artemis II crew 👇
Yup, platform activity is surging. There were 1 billion commits in 2025. Now, it's 275 million per week, on pace for 14 billion this year if growth remains linear (spoiler: it won't.)
GitHub Actions has grown from 500M minutes/week in 2023 to 1B minutes/week in 2025, and now 2.1B minutes so far this week.
So we're pushing incredibly hard on more CPUs, scaling services, and strengthening GitHub’s core features.
And as a fine purveyor of hand-crafted shit code for many years, I'm not gonna weigh in on that. 🤣