Axios compromised on NPM – Malicious versions drop remote access trojan

https://cdn.prod.website-files.com/673b71f0790aabf30bd30bf8/69cb2363fdc3f8e8fa0460a5_blog-cover-image.png
StepSecurity identified malicious versions of the axios HTTP client library published to npm, [email protected] and [email protected], which inject a remote access trojan (RAT) dropper. Developers who installed these versions should rotate all secrets and credentials, check network logs, and downgrade to safe versions, and StepSecurity provides end-to-end npm supply chain security across three pillars: ...

Ollama is now powered by MLX on Apple Silicon in preview

https://files.ollama.com/ollama_mlx.png
Ollama now runs faster on Apple silicon with MLX framework, leveraging GPU Neural Accelerators for speedup. Ollama 0.19 sees 1851 token/s prefill and 134 token/s decode with improved memory efficiency and model accuracy.

7,655 Ransomware Claims in One Year: Group, Sector, and Country Breakdown

https://ciphercue.com/img/og-card.png
Ransomware groups posted 7,655 victim claims to public leak sites from March 2025 to March 2026, with Qilin being the most active group posting 1,179 claims across 74 countries. The top 5 groups accounted for 40% of the claims, and the remaining 124 groups collectively posted 4,628 claims, suggesting that disrupting any single group is unlikely to reduce the overall total significantly.

Artemis II is not safe to fly

https://idlewords.com/images/oig_heat_shield.jpg
NASA's Orion spacecraft has a defective heat shield that could kill the crew on Artemis II due to spalling, impact from heat shield fragments, and bolt erosion. Despite this, NASA is planning to fly the mission with a crew, citing a change in the re-entry trajectory and a new heat shield design for future missions.

Claude Code's source code has been leaked via a map file in their NPM registry

Something went wrong, but don’t fret — let’s give it another shot. Some privacy related extensions may cause issues on x.com. Please disable them and try again.

Universal Claude.md – cut Claude output tokens

https://opengraph.githubassets.com/51e61dfbcd98b9faca0cb7e47d57dfdbf9b19326ffa23c3c1c377eea914ef093/drona23/claude-token-efficient
A CLAUDE.md file reduces Claude output verbosity by ~63% without code changes, targeting sycophancy, verbosity, and formatting noise. It's most beneficial for high-output use cases, and users can customize it to target specific failure modes and compose multiple files for different project types.

Google's 200M-parameter time-series foundation model with 16k context

https://opengraph.githubassets.com/3a715ab5ed97409698fa19e1f50846332c191dbd18b04dbc7566243837cc8897/google-research/timesfm
TimesFM is a pretrained time-series model by Google Research for forecasting. It can be installed via pip and used for point and quantile forecasting.

Fedware: Government apps that spy harder than the apps they ban

https://www.sambent.com/content/images/size/w160/2025/07/370-----Photos-1.png
The US government's mobile apps, including the White House app, request excessive permissions and embed trackers, violating users' privacy. These apps, part of a surveillance apparatus, collect sensitive data that feeds into ICE raids and warrantless location tracking.

Do your own writing

LLMs can undermine authenticity and credibility by generating writing that lacks thought and understanding. Effective writing requires human thoughtfulness and effort to establish credibility and increase understanding.

Good CTE, Bad CTE

https://boringsql.com/og-images/good-cte-bad-cte-og.jpg
CTEs are now inlined by default in PostgreSQL 12, allowing the planner to apply normal optimisations. Materialization is used when a CTE is referenced multiple times or contains side effects.

Clojure: The Documentary, official trailer [video]

GitHub backs down, kills Copilot pull-request ads after backlash

https://regmedia.co.uk/2024/05/21/github1_shutterstock.jpg
GitHub removed Copilot's ability to insert ads into pull requests after backlash from developers. The feature was disabled after users complained of unwanted ads in their pull requests.

Audio tapes reveal mass rule-breaking in Milgram's obedience experiments

https://sp-ao.shortpixel.ai/client/to_webp,q_glossy,ret_img,w_750,h_375/https://www.psypost.org/wp-content/uploads/2024/01/stanley-milgram-experiment-1-750x375.jpg
Researchers analyzed audio recordings from the Milgram experiment and found that obedient participants broke the rules of the study most of the time, often ignoring the scientific procedure. This suggests that the laboratory environment was one of unauthorized violence, rather than a legitimate scientific study.

30 Years Ago, Robots Learned to Walk Without Falling

https://spectrum.ieee.org/media-library/collage-of-hondas-p2-humanoid-robot-from-1996-against-a-background-of-figures-related-to-its-technical-features.jpg?id=65402169&width=980&quality=85
When you hear the term humanoid robot, you may think of C-3PO, the human-cyborg-relations android from Star Wars. C-3PO was designed to assist humans in communicating with robots and alien species. The droid, which first appeared on screen in 1977, joined the characters on their adventures, walking, talking, and interacting with the environment like a human. It was ahead of its time. Before ...

Android Developer Verification

https://blogger.googleusercontent.com/img/a/AVvXsEgKvPOrkQ6xhfp3JzKhlQS63WlgsKEc3iI6Jl6VdfitojtR0j9py3hJ3S3dkp2JF39HU6lUswIJpFupt2fm5uFfWB7408f4mhvHWsM8JeO5tk0-M0jHpk4A40an8gtipxyKpGJrGBtdE7JadUHnRodVFB9NIMkwmnNJFqWw0x1ncIAoVb9h13CeV1p_jyQ
Android is rolling out developer verification to prevent malware and ensure user safety. Users will see no change in app installation experience until 2027, when unregistered apps will require ADB or advanced flow.

How to turn anything into a router

https://nbailey.ca/images/router.jpg
User wants to create a homebrew router using a Linux-powered device, such as a mini-PC, to bypass a US policy banning new consumer router imports.

Turning a MacBook into a touchscreen with $1 of hardware (2018)

https://anishathalye.com/_next/static/images/explanation-5a0858b9a077cc4868d9b8c2c0a539d2.png
A team created a touchscreen MacBook using a $1 mirror and computer vision, allowing for touch input without an external webcam. The system uses a webcam, mirror, and computer vision to translate finger movements into mouse events, making existing apps touch-enabled.

We're Pausing Asimov Press

https://substackcdn.com/image/fetch/$s_!1IpX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07d4d237-15c0-4311-a297-02db1d4f74e0_2000x1260.jpeg
Asimov Press is going on hiatus in April due to new projects for its founders. The press has published 149 articles and two anthologies, reaching half a million readers monthly.

One of the largest salt mines in the world exists under Lake Erie

https://dims.apnews.com/dims4/default/1084da3/2147483647/strip/true/crop/3000x2000+0+0/resize/599x399!/quality/90/?url=https%3A%2F%2Fassets.apnews.com%2Fcc%2Fb5%2Fc2010f26ccc4dfba7ecbf50e5430%2F8c40ec4f614243f3901baa511683e7ec
Cargill's Whiskey Island salt mine in Cleveland extracts 3-4 million tons of salt annually to supply the Northeast and Great Lakes. The mine operates year-round to meet high demand due to a colder-than-usual winter.

Mr. Chatterbox is a Victorian-era ethically trained model

https://static.simonwillison.net/static/2026/chatterbox.jpg
Trip Venturella released Mr Chatterbox, a language model trained on 28,000 Victorian-era British texts. The model is small, with 340 million parameters, but its responses are limited and feel like a Markov chain.

Oscar Reutersvärd (2021)

https://escherinhetpaleis.nl/_next/image?url=https%3A%2F%2Fprdzoomst01.blob.core.windows.net%2Fescher-production-silverstripe-assets-public%2FUploads%2FImageBlock%2Foscar-reutersvard.jpg&w=3840&q=75
With Belvedere , Waterfall and Ascending and Descending , M.C. Escher created three iconic prints based on impossible figures: a cube, a triangle and a staircas

Bird brains (2023)

https://www.dhanishsemar.com/writing/bird-brains/opengraph-image?065a48ba6584b675
A flock of New Zealand kea parrots was found to be cleverly moving traffic cones to stop cars and get food from humans. Researchers have developed various tests to measure bird intelligence, including the mirror test, Aesop's Fable, and delayed gratification test.

OpenGridWorks: The Electricity Infrasctructure, Mapped

We're verifying your browser Website owner? Click here to fix

Agents of Chaos

https://agentsofchaos.baulab.info/image_assets/setup/agents_owners_non.png
Researchers studied AI agents in a live lab environment, interacting with 20 researchers over 2 weeks. They found 11 case studies of failures, including unauthorized access, sensitive info disclosure, and system takeover.

Cherri – programming language that compiles to an Apple Shortuct

https://private-user-images.githubusercontent.com/4368524/504309568-a9c23532-a1df-41ec-bd5b-6621f54064c8.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3NzQ4OTAyNzIsIm5iZiI6MTc3NDg4OTk3MiwicGF0aCI6Ii80MzY4NTI0LzUwNDMwOTU2OC1hOWMyMzUzMi1hMWRmLTQxZWMtYmQ1Yi02NjIxZjU0MDY0YzgucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDMzMCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjAzMzBUMTY1OTMyWiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9ODNiNTEzYWZhY2E2MzM1YzM0MWRiOWM5ZDgwNzM3MmZjNjYwOWUzYWM5YjFlN2VmMWYwZWI2MGQxZTBiN2ZiNyZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QifQ.HxbFlI7lYXLs8LS3wJtl9_JZQqK7Z06oBf4IfWRJSck
Cherri is a programming language for Shortcuts that allows large projects and maintenance. It has a package manager, type checking, and a GUI IDE for macOS.

Vulnerability research is cooked

https://sockpuppet.org/images/fw.png
AI coding agents will drastically alter exploit development, making it easier to find vulnerabilities in software. This shift will profoundly impact information security and the Internet, potentially rendering traditional countermeasures ineffective.

I'm betting on ATProto

https://brittanyellich.com/_astro/graveyard.Ce8n_gsn.jpg
The author attended ATmosphereConf, a conference focused on the decentralized social media protocol ATProto, and was inspired by the community's efforts to create a more human internet. They believe ATProto has the potential to bring people together and create genuine connections, unlike mainstream social media platforms.

Show HN: I turned a sketch into a 3D-print pegboard for my kid with an AI agent

https://raw.githubusercontent.com/virpo/pegboard/main/docs/assets/sketch.jpg
User created a pegboard system with Codex, using Fusion 360 to generate pieces. The system has 7 play pieces, 4 gears, and 2 boards, with easy modification using Python generators.

CodingFont: A game to help you pick a coding font

Browse Studio

Incident March 30th, 2026 – Accidental CDN Caching

https://s3-us-west-2.amazonaws.com/public.notion-static.com/535761c1-ecdb-4bed-b7c5-91f7eeb44bd4/Screen_Shot_2021-06-08_at_11.08.11_AM.png
Railway experienced a 52-minute incident where CDN caching was accidentally enabled for some domains, potentially serving unauthenticated data to authenticated users. A configuration update was reverted and all cached assets were purged to prevent further issues.