Pelastuslaitos muistuttaa: Huoltotunneli ei ole oikotie
@yleuutiset uutisoi tänään 3.6.26 Helsingin keskustan huoltotunnelista, jossa osa autoilijoista ajaa ilman lupaa läpi keskustan oikaisten.
Pelastuslaitos harjoitteli samassa tunnelissa hiljattain, ja harjoitus muistutti konkreettisesti, miksi läpiajo on kielletty.
⚠️ Tunnelissa riskit ovat poikkeuksellisen suuret:
👉vanhassa tunnelin päässä ajotila on kapea ja mutkainen
👉ohitusmahdollisuutta ei ole vanhalla osuudella
👉osassa tunnelia puuttuu pelastusteitä
Suljetussa tilassa pienikin liikenneonnettomuus voi nopeasti muuttua vakavaksi, sekä osallisille että pelastustoiminnalle.
Katso harjoituksen kuvat pelastuslaitoksen Facebookista. Ne näyttävät hyvin, millaisessa ympäristössä pelastajat työskentelevät. Huomatkaa myös, sekä Ylen että meidän kuvat ovat tunnelin leveältä uudemmalta osalta.
https://t.co/7iy4SW0glY
Kuvituskuva harjoituksesta.
Oracle's dramatic firing of 30,000 people was a semiotic gesture aimed at endorsing and legitimizing AI (never mind the actual costs). The point was the grand public endorsement. The actual reality is that the company may go down. It can't run without those 30,000 people.
I can't properly describe to anyone under the age of 30 just how cool the Internet was before Amazon, Google, Meta, and Apple turned it all into a walled garden of garbage and commerce.
I'm not gonna lie, the @Meta layoffs are some of the most dystopian I've ever seen. They got told to work from home, they were sent the emails at 4AM in the morning. Those who weren't impacted have software on their computer that tracks their every move, preparing AI to take their job as well. They're literally training the AI that will eliminate their position as well.
Meanwhile, Meta is raking in RECORD PROFITS.
I am a massive, unapologetic AI enthusiast. Yet, this is NOT the future I had in mind.
I wish for Meta to crash and burn. This is not the way. Literally nobody benefits from this.
🚨 GitHub source code allegedly offered for sale: Internal orgs and private repositories claimed
A threat actor using the alias TeamPCP claims to be selling GitHub source code and internal organization data.
The actor claims the dataset includes around 4,000 private repositories and says samples can be provided to interested buyers to verify authenticity.
━━━━━━━━━━━━━━━━━━━━
Target: GitHub
Country: United States
Sector: Technology / Software Development / Source Code
Incident Type: Alleged Source Code Sale
Claimed Exposure: Around 4,000 private repositories
Actor: TeamPCP
Price: Offers over $50,000
━━━━━━━━━━━━━━━━━━━━
According to the post, the actor claims the material includes source code and internal organization data tied to GitHub’s main platform. The post also references a public file list and includes screenshots showing numerous repository archive names.
Why it matters:
If authentic, exposed source code and internal repository data could increase the risk of code review by hostile actors, vulnerability discovery, supply chain targeting, impersonation, phishing, and follow-on attacks against developer infrastructure.
Status:
This remains an unverified underground forum claim. The actor states this is not a ransom attempt and claims the data may be leaked publicly if no buyer is found.
Stop guessing what's redacted. Subscribers see everything → https://t.co/281Qjc6WSh
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
EXCLUSIVE: Several Chinese tech companies have recently stopped updating previously open AI models, which could indicate they're moving development behind closed doors, Germany’s cyber chief has warned.
🔗 https://t.co/UGRATdvk4V
The Google Threat Intelligence Group has detected the first known instance of a threat actor using an AI-developed zero-day exploit in the wild. While the attackers planned a wide-scale strike, our proactive counter-discovery may have prevented that from happening. This finding is part of our new report on AI-powered threats.
This is crazy. The shai hulud exploit is embedding itself in Claude and VSCode to re-execute itself, even after the original packages have been uninstalled.
I'm never installing anything ever again.
❗️ UPDATE on today's npm supply-chain attack:
• Per Socket Security: 121 more compromised package artifacts found across 84 additional package names. 64 of them are UiPath artifacts.
• Combined with the earlier TanStack hits, the current known total is 205 affected npm package artifacts.
• Reach now spans enterprise automation, AI/MCP, auth, workflow, and dev tooling.
The worm is still propagating.
⚠️ RubyGems has suspended new signups after a major malicious attack involving hundreds of packages, some reportedly carrying exploits.
The incident raises fresh concerns over open-source supply chain security.
Details here: https://t.co/TaeGx9MTz3
‼️🚨 UPDATE: The TanStack npm attack is now a full campaign.
'Mini' Shai-Hulud has hit:
- OpenSearch
- Mistral AI
- Guardrails AI
-UiPath
- Squawk packages across npm and PyPI
The malware specifically targets AI developer tooling. It hooks into Claude Code (.claude/settings.json) and VS Code (.vscode/tasks.json) to re-execute on every tool event, long after the infected package is gone. npm uninstall does not fix this.
🚨 Update: @mistralai npm packages are now confirmed compromised as part of the ongoing Mini Shai Hulud attack.
Affected versions:
@mistralai/mistralai 2.2.2, 2.2.3, 2.2.4@mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3@mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3If you use the Mistral SDK in any CI pipeline, treat your environment as compromised. Rotate npm tokens, GitHub PATs, and cloud credentials immediately.