One clear difference between @OpenAI Codex and @AnthropicAI@ClaudeDevs is the transparency. Claude was down for a long period, with no prompt and official communication yet (just the status page).
๐กRecent insight: gaslighting @claudeai seems to improve code quality >90% of the time.
โYou overengineered this, there is a simpler wayโ
โThere is a smaller delta that buys us most of the benefitsโ
โThere is a more elegant wayโ
โThis is not architecturally coherentโ
โฆbefore I even read its code. ๐
๐จ BREAKING: Active supply chain attack across npm, PyPI, and Crates.โio.
Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems.
TrapDoor targets #crypto, #DeFi, AI, and security developers, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, env vars, and API keys.
Socket detected releases with a median detection time of 5 minutes, 27 seconds. The fastest detection occurred 58 seconds after publication.
We just shipped NVIDIA-Verified Agent Skills ๐
Skills make your agent more capable, but can also introduce vulnerabilities. Verified skills give you transparency into what a skill does, where it came from, what risks it carries, and whether it's been modified.
Every verified skill carries a skill card and is built on the https://t.co/ijhll6w6yh open specification to work reliably across @claudeai Code, @openai Codex, and @cursor_ai.
Deleting a Google API key doesn't revoke it immediately.
Our research found successful authentications up to 23 minutes after deletion across Google's infrastructure. During that window, attackers with a leaked key can still access enabled APIs, including Gemini.
Google closed our report as "won't fix."
We're benchmarking every model, every quant, on every different hardware setup for every price point.
All developers, companies, and people will have access to local, open source intelligence.
Releasing soon.
๐ญ
VS Code extensions are no different than browser extensions - high risk that you should be controlling with an allowlist
Yes, review and approval processes suck, but IR sucks even more
https://t.co/zsxhBhUsZN
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
We are investigating unauthorized access to GitHubโs internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHubโs internal repositories (such as our customersโ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.