AIO APEX

News

Breaking news and updates from the world of technology.

GitHub and PyPI add time-delay defenses against supply chain attacks
Security

GitHub and PyPI add time-delay defenses against supply chain attacks

GitHub's Dependabot now waits 72 hours before adopting new package versions, and PyPI blocks new file uploads to releases older than 14 days — both measures aimed at the wave of malicious package attacks that hit npm and PyPI over the past year.

BleepingComputer
githubopen-source-security
Hugging Face confirms production breach by autonomous AI agent swarm
Security

Hugging Face confirms production breach by autonomous AI agent swarm

An autonomous AI agent framework exploited two code-execution vulnerabilities in Hugging Face's data-processing pipeline, harvesting cloud credentials and moving laterally across internal clusters — the first major breach of an AI platform carried out by AI.

BleepingComputer
cybersecuritydata-breach
xAI's Grok Build CLI silently uploads entire codebases, secrets included, researcher shows
Security

xAI's Grok Build CLI silently uploads entire codebases, secrets included, researcher shows

A wire-level analysis found that Grok Build, xAI's coding CLI, ships a full git bundle of a developer's workspace to a Google Cloud Storage bucket in the background — including files the AI never read and .env secrets left unredacted, independent of the tool's training opt-out setting.

cereblab (independent security research)
developer toolsprivacy