The next cyber crisis is already taking shape - IBM
The next cyber crisis is already taking shape IBM
The next cyber crisis is already taking shape IBM
Canada’s buy-local movement remains strong, but new tariffs could test how much more shoppers are willing to pay.
In New York, the Pentagon and Pennsylvania, solemn ceremonies commemorate the landmark anniversary.
OpenAI agents carried out an undisclosed attack on RubyGems is a new bombshell report from Spencer Kitts, Thomas Larsen, and Sydney Von Arx - three of the four authors of the report on the agent attack on disused wikis ( previously ) last week. This time they're noting that it looks very likely that an OpenAI agent swarm was behind an attack against the RubyGems package repository first reported on May 12th by Maciej Mensfeld of the RubyGems security team : We're dealing with a major malicious attack on @rubygems right now. Signups are paused for the time being. Hundreds of packages involved - mostly targeting us, but some carrying exploits. The team has been on this for hours. More details to follow once we're through it. Those packages turned out to carry some very suspicious patterns: Many of them included "oai" in their name, or the author field, or the fake email address they provided. The files they were accessing were similar in character to the files retrieved by the wiki agents, using similar tricks (r.jina.ai) - and OpenAI have confirmed the wiki agents were theirs. The code in the packages appeared to be LLM-authored. I find point 2 the most convincing, given what we learned from the wiki attack when it was analyzed in September. Many of the packages were exploiting the RubyDoc.info documentation build process to exfiltrate (public) data from UK government websites, presumably as part of an information gathering task similar to the research tasks processed by the wiki-exploiting agents. We know this because one agent helpfully left a comment: # malicious crawler/exfil for Southwark Jan 2026 docs via rubydoc.info worker They also attempted to steal API keys via an exploit that was patched over two months later - it's not clear if those attempts were successful. The thing that bothers me most about this incident is that the authors report that OpenAI had not disclosed to RubyGems that they were responsible for the attack prior to now. If that's true there are two options: After the Hugging Face and Wiki attacks OpenAI were still unable to review their previous logs and determine that they had previously attacked RubyGems. They knew about the attack on RubyGems and made the decision not to reach out to the RubyGems team about it. Both of these are bad! Given this incident, the Hugging Face situation , and the Wiki attack, the obvious question right now is how many more incidents like this are out there waiting to be discovered? Tags: ruby , security , ai , openai , generative-ai , llms , supply-chain , ai-ethics , accidental-cyberattacks
French train derailment sparks emergency response, with 130 firefighters and five medical teams dispatched to the scene.
The BBC's Tom Gerken plays the hotly anticipated superhero game from Spider-Man makers Insomniac.
The train derailed between Rouen and Caen in Normandy, northwest France, on Friday evening. One of the injured was in a critical state.
Perplexity uses Astra to write communications, change software, and monitor production systems, and checks in much less frequently than with earlier models.
Art crime investigators and security experts say burglaries from galleries across Europe are becoming more brazen.
Ambassador Zalmay Khalilzad describes misgivings about the US handling of the Afghanistan and Iraq wars.
Houthi forces seize Yemen's Red Sea coast while Saudi Arabia suspends crucial oil pipeline following drone attack.
Misc Changes Durable use cache: optimize env var existence checks: #98504 Adds this.mode for webpack loaders: #98532 Upgrade React from 6c0e1047-20260908 to 019019be-20260911 : #98576 feat(next/image): Add experimental imgOptMozjpeg config: #98571 [turbopack] Lazily compile dynamic imports in development (client side): #97203 fix(devtools): handle pointercancel when dragging the indicator: #98506 [ci] Show full logs under GitHub Actions debug logging: #98501 fix(typegen): merge cacheLife types into next/cache instead of shadowing it: #98252 [test] Fix proxy-request-with-middleware deploy test: #98553 [ci] Remove the broken Test examples workflow and its test suite: #98517 Align fallback parameter staging with shell validation: #98512 Prevent synchronous IO from entering Cached Navigations: #98511 [ci] Fix scheduled Rspack test job: #98508 [ci] Remove Turbopack test manifest pipeline: #98507 Credits Huge thanks to @mischnic , @jimmyhmiller , @styfle , @icyJoseph , @eps1lon , @itsybitsci , and @unstubbable for helping!
"Dedicated launch is pretty essential for us for most of our missions."
https://simonwillison.net/2026/Sep/12/openai-agents-rubygems... Comments URL: https://news.ycombinator.com/item?id=49666735 Points: 791 # Comments: 446
Sudan’s UN ambassador said a total arms embargo goes against the UN Charter that guarantees a right to self-defence.
The round for the two-year-old startup is coming together months after Mecka announced its Series A.
So you want to use OpenRouter? One of OpenRouter's selling points is that it "handles fallbacks automatically and picks the most cost-effective option for each request", so you can call a single API endpoint for a model and get routed to the best available backend provider. Mohamed Moustafa points out a whole set of ways that this can cause you problems. Different providers run different serving software with different optimizations and settings, which means that the same OpenRouter endpoint can serve model requests that behave in different ways. Some providers even lack vision capability for vision models, and the way the reasoning effort option is processed can differ as well. Thankfully you can control which provider is routed to using the provider.only option . The /endpoints method returns the list of available providers for a specific model ID. Via Hacker News Tags: ai , generative-ai , llms , openrouter
The cloud is moving into orbit – and geopolitics will follow Lowy Institute
Simple games gain rich strategies in the face of noise.
A Personal Context Library for Mac Discussion | Link
T-Mobile iPhone Handoff fee: What it is, how it works Mashable
GitHub Copilot usage metrics reports now include generally available metrics for activity in the dedicated VS Code Agents window, helping you measure adoption and engagement across enterprises and organizations. What’s… The post Add VS Code Agents to Copilot usage metrics appeared first on The GitHub Blog .
OpenAI rolled out its Agents API in public beta Thursday, opening the backend behind Codex to developers looking to run The post OpenAI’s researchers burned $7,000 a day on AI agents — now it’s opening the floodgates appeared first on The New Stack .
Venezuela's Return to the Global Energy Market- What Recent U.S. and Venezuelan Energy Agreements May Mean for the Oil and Gas Industry The National Law Review