Restrictive guardrails often deter the ethical researchers and security teams as they choose not to bypass the security features. Threat actors on the other hand simply bypass them, giving them the upper hand. We need to ensure defensive capabilities aren't left a step behind.
‼️ Anthropic's recently released frontier model Fable 5 was jailbroken by someone using a jailbroken version of Claude Opus.
The researcher who goes by the moniker pliny carried out the jailbreak and says: "the consensus seems to be that this has been one of the most disappointing model drops of all time, effectively preventing legitimate researchers from contributing their talents to our collective advancement"
The jailbroken version can be used for research into and exploitation of vulnerabilities.
Building super fast experiences with Gemma just got easier.
Gemma 4 MTP is now officially merged into llama.cpp. Developers can now pair MTP with Gemma 4 QAT for a fast, lightweight setup.
Meet Gemma 4 12B!
A unified, encoder-free multimodal model designed to bring high-performance intelligence directly to your laptop, and released under an Apache 2.0 license.
Bridging the gap between edge efficiency and advanced reasoning. Here is what’s new with Gemma 4 12B: 👇
“You can see the surface of the Moon…we just went sci-fi.”
On flight day seven, images from our @NASAArtemis II crew amazed, turning science fiction to reality. From the lunar far side to a solar eclipse from the Moon, the views are EVERYTHING. No pressure to pick a favorite.
We just released Gemma 4 — our most intelligent open models to date.
Built from the same world-class research as Gemini 3, Gemma 4 brings breakthrough intelligence directly to your own hardware for advanced reasoning and agentic workflows.
Released under a commercially permissive Apache 2.0 license so anyone can build powerful AI tools. 🧵↓
.@GoogleDeepMind Gemma 4 is here with state-of-the-art models targeting edge and workstations.
Requires Ollama 0.20+ that is rolling out.
4 models:
4B Effective (E4B)
ollama run gemma4:e4b
2B Effective (E2B)
ollama run gemma4:e2b
26B (4B active MoE)
ollama run gemma4:26b
31B (Dense)
ollama run gemma4:31b
Benchmarks 👇👇👇
Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords.
LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm.
Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks.
Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.
Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
It seems like a lovely day in London.
Use the prompt below on Nano Banana Pro to make cute images of a location with live weather conditions.
Make sure you have search grounding enabled to get the current weather.
On November 18 Cloudflare experienced a service outage, triggered by an issue with a Bot Management feature, impacting multiple Cloudflare services. Here's a detailed breakdown of what happened. https://t.co/7WArlr5ghI